Data processing method and device, secure isolation chip and computer device
Patent Information
- Application Number
- CN202610805661.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-05
- Publication Date
- 2026-09-15
AI Technical Summary
[0003]然而,从通信隔离的视角审视,当前设备终端在与外围实体交互时,相关技术中的隔离方式,攻击者可能伪装成合法节点接入终端设备,进而窃取或篡改数据,导致物联网终端在与外围实体进行通信时,交互数据安全性较低
[0038] The aforementioned data processing method, apparatus, security isolation chip, and computer equipment receive data interaction requests sent by the target terminal through the security isolation chip. If the target terminal meets the preset authentication conditions, the data to be interacted corresponding to the data interaction request is converted based on the preset data conversion strategy to obtain converted interaction data. The converted interaction data is then stored in a preset cache queue, or the converted interaction data is sent to the target terminal. This achieves security authentication and data transmission of the target terminal through the security isolation chip, improving the security level of the data transmission process, decoupling the coupling relationship between business data and encrypted communication, and ensuring the confidentiality, integrity, and availability of local terminal data throughout its entire lifecycle. At the same time, by storing the converted interaction data in the preset cache queue, asynchronous communication between the two communicating parties is realized, improving the adaptability and reliability for large-scale IoT deployments.
Smart Images

Figure CN122764569A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular to a data processing method, apparatus, security isolation chip, and computer equipment. Background Technology
[0002] With the ubiquitous deployment of IoT technology, the interconnection of massive terminal devices has become an inevitable trend, posing severe challenges to the data security and physical trustworthiness of device communication links. Security chips, as the core unit for building hardware-level trust anchors, are a key technological path to address these challenges. This chip integrates a cryptographic algorithm engine, physical protection mechanisms, and secure storage units, forming an independent trusted execution environment. Its core security features are reflected in two dimensions: First, through a built-in true random number generator and a national cryptographic algorithm accelerator, it achieves isolated storage of key materials and sensitive data, and supports end-to-end encryption of data, thus evolving encryption technology from pure software implementation to hardware acceleration solutions, significantly improving computational efficiency and confidentiality; Second, through physical defense technologies such as voltage detection and active shielding layers, it effectively combats side-channel attacks and fault injection, ensuring the chip's integrity under physical attacks.
[0003] However, from the perspective of communication isolation, when current device terminals interact with external entities, the isolation methods in related technologies allow attackers to impersonate legitimate nodes to access the terminal device, thereby stealing or tampering with data, resulting in low data security when IoT terminals communicate with external entities. Summary of the Invention
[0004] Therefore, it is necessary to provide a data processing method, apparatus, security isolation chip, and computer equipment that can improve the security of interactive data when IoT terminals communicate with peripheral entities, in order to address the above-mentioned technical problems.
[0005] In a first aspect, this application provides a data processing method applied to a security isolation chip, comprising:
[0006] Receive data interaction requests sent by the target terminal;
[0007] If the target terminal meets the preset authentication conditions, the data to be interacted corresponding to the data interaction request is converted based on the preset data conversion strategy to obtain converted interaction data, and the converted interaction data is stored in a preset cache queue, or the converted interaction data is sent to the target terminal.
[0008] In one embodiment, the target terminal is a non-local terminal, and the method further includes:
[0009] When the data interaction request is a data read request, identify the digital envelope in the data interaction request, and identify the activation token, data access token and address information carried by the digital envelope;
[0010] The security protection level corresponding to the launch token is determined. If the data access token meets the preset security policy corresponding to the security protection level and the address information is in the preset security list, then the non-local terminal is determined to meet the preset authentication conditions.
[0011] In one embodiment, the step of converting the data to be interacted corresponding to the data interaction request based on a preset data conversion strategy to obtain converted interaction data includes:
[0012] The system retrieves the data to be interacted corresponding to the data interaction request from the preset cache queue corresponding to the local terminal, and decrypts the data to be interacted to obtain plaintext data.
[0013] Based on the encryption strategy corresponding to the non-local terminal, the plaintext data is encrypted to obtain encrypted transmission data, and the encrypted transmission data is encapsulated according to a preset format to obtain converted interactive data.
[0014] In one embodiment, the target terminal is a local terminal, and the method further includes:
[0015] If the data interaction request is a data read request, then the security protection level corresponding to the start token in the data read request is determined, and if the data access token in the data read request satisfies the preset security policy corresponding to the security protection level, then the local terminal is determined to meet the preset authentication conditions.
[0016] In one embodiment, the step of converting the data to be interacted corresponding to the data interaction request based on a preset data conversion strategy to obtain converted interaction data includes:
[0017] The system retrieves the data to be interacted corresponding to the data interaction request from the preset cache queue corresponding to the non-local terminal, and decrypts the data to be interacted to obtain plaintext data; the plaintext data is then identified as the conversion interaction data.
[0018] In one embodiment, the data to be interacted corresponding to the data interaction request is transformed based on a preset data transformation strategy to obtain transformed interaction data.
[0019] When the data interaction request is a data transmission request, the data to be interacted is encrypted based on the encryption strategy corresponding to the target terminal to obtain the converted interaction data.
[0020] In one embodiment, storing the conversion interaction data in a preset cache queue, or sending the conversion interaction data to the target terminal, includes:
[0021] If the data interaction request is a data read request, the converted interaction data is sent to the target terminal;
[0022] If the data interaction request is a data transmission request, the conversion interaction data is stored in a preset cache queue.
[0023] Secondly, this application also provides a data processing apparatus for use in a security isolation chip, comprising:
[0024] The receiving module is used to receive data interaction requests sent by the target terminal;
[0025] The processing module is configured to, if the target terminal meets the preset authentication conditions, convert the data to be interacted corresponding to the data interaction request based on the preset data conversion strategy to obtain converted interaction data, and store the converted interaction data in a preset cache queue, or send the converted interaction data to the target terminal.
[0026] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:
[0027] Receive data interaction requests sent by the target terminal;
[0028] If the target terminal meets the preset authentication conditions, the data to be interacted corresponding to the data interaction request is converted based on the preset data conversion strategy to obtain converted interaction data, and the converted interaction data is stored in a preset cache queue, or the converted interaction data is sent to the target terminal.
[0029] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, performs the following steps:
[0030] Receive data interaction requests sent by the target terminal;
[0031] If the target terminal meets the preset authentication conditions, the data to be interacted corresponding to the data interaction request is converted based on the preset data conversion strategy to obtain converted interaction data, and the converted interaction data is stored in a preset cache queue, or the converted interaction data is sent to the target terminal.
[0032] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, performs the following steps:
[0033] Receive data interaction requests sent by the target terminal;
[0034] If the target terminal meets the preset authentication conditions, the data to be interacted corresponding to the data interaction request is converted based on the preset data conversion strategy to obtain converted interaction data, and the converted interaction data is stored in a preset cache queue, or the converted interaction data is sent to the target terminal.
[0035] Sixthly, this application also provides a security isolation chip, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:
[0036] Receive data interaction requests sent by the target terminal;
[0037] If the target terminal meets the preset authentication conditions, the data to be interacted corresponding to the data interaction request is converted based on the preset data conversion strategy to obtain converted interaction data, and the converted interaction data is stored in a preset cache queue, or the converted interaction data is sent to the target terminal.
[0038] The aforementioned data processing method, apparatus, security isolation chip, and computer equipment receive data interaction requests sent by the target terminal through the security isolation chip. If the target terminal meets the preset authentication conditions, the data to be interacted corresponding to the data interaction request is converted based on the preset data conversion strategy to obtain converted interaction data. The converted interaction data is then stored in a preset cache queue, or the converted interaction data is sent to the target terminal. This achieves security authentication and data transmission of the target terminal through the security isolation chip, improving the security level of the data transmission process, decoupling the coupling relationship between business data and encrypted communication, and ensuring the confidentiality, integrity, and availability of local terminal data throughout its entire lifecycle. At the same time, by storing the converted interaction data in the preset cache queue, asynchronous communication between the two communicating parties is realized, improving the adaptability and reliability for large-scale IoT deployments. Attached Figure Description
[0039] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0040] Figure 1 This is a diagram illustrating the application environment of a data processing method in one embodiment.
[0041] Figure 2 This is a flowchart illustrating a data processing method in one embodiment;
[0042] Figure 3 This is a timing diagram illustrating the interaction between a peripheral entity and the firewall of a security isolation chip to read local messages in one embodiment.
[0043] Figure 4 This is a schematic diagram illustrating the process of a peripheral entity reading local messages through the firewall of a security isolation chip in one embodiment.
[0044] Figure 5 This is an interaction diagram in one embodiment where data to be transmitted from a peripheral entity is asynchronously saved to a peripheral message queue.
[0045] Figure 6 This is an interaction diagram in one embodiment where a local terminal sends a message and asynchronously saves it to a local message queue.
[0046] Figure 7 This is an interaction diagram of a local terminal reading peripheral messages from a peripheral message queue in one embodiment;
[0047] Figure 8 This is a schematic diagram of a defense-in-depth architecture for a dedicated protective isolation security chip in one embodiment;
[0048] Figure 9 This is a structural block diagram of a data processing device in one embodiment;
[0049] Figure 10 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation
[0050] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0051] The IoT security architecture in related technologies includes terminal devices and peripheral entities. Terminal devices may include security chips, a main control MCU, and a main control device. In this architecture, end-to-end communication security generally adopts a hardware collaboration model between the main control MCU and the security chip. The security processing logic consists of two core functional modules: key negotiation and security processing flow. Key negotiation relies on the security capabilities of the security chip to execute the key negotiation protocol, perform cryptographic operations, and manage the fusion of input key parameters with pre-set key parameters within the chip, completing encryption and decryption functions. The security processing flow covers the secure interaction protocol, the two-way authentication handshake process between the terminal and peripheral entities, and clarifies the security parameters such as random numbers and identity identifiers carried during the handshake, as well as the data to be authenticated. Simultaneously, this security processing flow also defines the encapsulation and parsing logic of business data packets, identifies sensitive fields that need to be encrypted, and determines the key fields requiring authentication codes or signature calculations and the cryptographic algorithms used, establishing a trust foundation for subsequent communication.
[0052] During the business data processing phase, after the business processing modules within the main control device (such as metering and billing, data maintenance, message format processing, and security processing logic) generate plaintext data, they call the security isolation chip through the security processing logic to complete the key negotiation process. The security processing logic parses the plaintext data message, calls the security isolation chip to perform encryption operations on sensitive fields requiring encryption (such as business payload) to obtain ciphertext, and calls the security isolation chip to perform calculations on fields requiring authentication codes or signatures (such as message headers and ciphertext). In a physically isolated trusted execution environment, the main control MCU may sequentially call the national cryptographic algorithms (SM2 / SM3 / SM4) multiple times to perform encryption, signing, and other processes on specified fields, returning the result to the main control MCU each time. The main control MCU then encapsulates the ciphertext, authentication code, and signature calculated by the security isolation chip multiple times into the final business message for IoT transmission.
[0053] Based on this, in terms of related technologies, when current IoT terminal devices communicate with external entities, most devices rely on the main control MCU to directly perform key negotiation and session management. The key operation input parameters are generated and exchanged in the general processor software stack, which is vulnerable to malicious code infiltration, leading to leakage of session information or tampering with the process, thus introducing serious security risks.
[0054] Based on the aforementioned traditional technologies, embodiments of this application provide a data processing method that improves the security of data interaction between local terminals and non-local terminals by designing a security isolation chip and authenticating data interaction requests through the security isolation chip.
[0055] It should be noted that the beneficial effects or technical problems solved by the embodiments of this application are not limited to this one, but may also be other implicit or related problems. For details, please refer to the description of the embodiments below.
[0056] The data processing method provided in this application embodiment can be applied to, for example... Figure 1 In the application environment shown, terminals are divided into local terminals and non-local terminals. Local terminals integrate a security isolation chip, and data interaction between local and non-local terminals is completed through the security isolation chip. Non-local terminals are deployed independently. Local terminals may also include a main control module, which includes a main control MCU and a main control device. The security isolation chip can be a security chip with isolation function, possessing physical defense technology and national cryptographic algorithms. The physical defense technology is the physical shielding protection layer of the security chip. The security isolation chip may include a hardware cryptographic layer, a basic software layer, a core isolation layer, and an application interaction layer, with a dual message queue module. The hardware cryptographic layer can be a security chip hardware platform. The basic software layer and the core isolation layer can be security authentication and security protection isolation layers. The basic software layer supports the hardware cryptographic layer function through the chip operating system managing file components (COS) and secure operations. The chip operating system managing file components includes a security chip protection control service unit, which is the security chip's core component. The internally running logic control unit, as the core functional module of security control in COS, is responsible for the unified scheduling of security operations during data access, including permission verification, authentication code verification, digital envelope unsealing and encapsulation, encryption and decryption operations, and signature verification. This service runs in the chip's trusted execution environment. The application interaction layer design includes a dual message queue module, which may include an embedded peripheral entity interaction message component and an embedded local message component. The embedded peripheral entity interaction message component may include a peripheral interaction message cache queue (peripheral message queue), and the embedded local message component may include a local data message cache queue (local message queue). The security chip hardware platform may include random number circuits and encryption / decryption algorithms, which may be national cryptographic algorithms. The security chip hardware platform has physical defense technology. Non-local terminals can be peripheral entities. Terminals can be, but are not limited to, various personal computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices can include smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, projection devices, etc. Portable wearable devices can include smartwatches, smart bracelets, head-mounted devices, etc. Head-mounted devices can include virtual reality (VR) devices, augmented reality (AR) devices, smart glasses, etc.
[0057] In one exemplary embodiment, such as Figure 2 As shown, a data processing method is provided, which can be applied to... Figure 1Taking the security isolation chip in the example, the explanation includes the following steps:
[0058] Step 201: Receive the data interaction request sent by the target terminal.
[0059] The target terminal can be a terminal to which data interaction is to be performed; optionally, the target terminal can be a local terminal or a non-local terminal; data interaction is a process of transmitting data or a process of receiving data; data interaction requests can include data reading requests and data transmission requests; a data reading request is a request to read data from the security isolation chip, and a data transmission request is a request to transmit data to other terminals through the security isolation chip.
[0060] Specifically, when the target terminal is a local terminal, the local terminal's main control module sends a data transmission request to the security isolation chip when it generates data to be interacted with. The main control module can also send a data transmission request to the communication module upon reaching a preset transmission cycle. This data transmission includes at least the data to be interacted with. The data to be interacted with can be service data in a state awaiting transmission.
[0061] When the target terminal is a local terminal, the local terminal sends a data read request to the security isolation chip after receiving a communication request from a non-local device and the local terminal is online.
[0062] Step 202: If the target terminal meets the preset authentication conditions, the data to be interacted corresponding to the data interaction request is converted based on the preset data conversion strategy to obtain converted interaction data, and the converted interaction data is stored in the preset cache queue, or the converted interaction data is sent to the target terminal.
[0063] The specific judgment conditions for the preset authentication conditions are related to the type of the target terminal and the type of data interaction request sent by the target terminal. The preset authentication conditions are a pre-defined set of standardized verification rules used to determine the legality of items and access permissions of the target terminal. The preset data conversion strategy is determined based on the target terminal and the data interaction request, and is used to perform data conversion processing on the data to be interacted in the interaction request. Data conversion is a process of at least one of encrypting, decrypting, or encapsulating the data to be interacted, and the specific processing process is related to the type of the target terminal and the type of data interaction request. The preset cache queue can include an external interaction message cache queue and a local data message cache queue. The external interaction message cache queue stores the data to be interacted sent by non-local terminals, and the local data message cache queue stores the data to be interacted sent by local terminals.
[0064] Specifically, the terminal can predetermine the preset authentication conditions corresponding to each type of terminal and each type of data interaction request. Based on the data interaction request sent by the target terminal, the terminal can determine the preset authentication conditions corresponding to the target terminal and the data interaction request. Based on these preset authentication conditions, the terminal verifies the target terminal. If the target terminal meets the preset authentication conditions, a corresponding preset data conversion strategy is determined from the preset correspondence between terminals, data interaction requests, and data conversion strategies. Based on this preset data conversion strategy, the data to be interacted in the data interaction request is converted to obtain interactive converted data. The converted interactive data is then stored in a preset cache queue, or the converted interactive data is sent to the target terminal. It should be understood that the specific process of determining whether the target terminal meets the preset authentication conditions and the conversion of the data to be interacted will be described in detail in subsequent embodiments and will not be repeated here.
[0065] In one example, if the target terminal does not meet the preset authentication conditions, the security isolation chip will proactively shut down its own services and block the data interaction requests sent by the target terminal.
[0066] Optionally, when the data interaction request is a data read request, the converted interaction data is sent to the target terminal; when the data interaction request is a data transmission request, the converted interaction data is stored in a preset cache queue. For example, when the target terminal is a local terminal, the converted interaction data is stored in a local data message cache queue; when the target terminal is a non-local terminal, the converted interaction data is stored in an external interaction message cache queue. In this case, the converted interaction data stored in the preset cache queue can be data to be interacted with. This data to be interacted with is stored in the corresponding preset cache queue in chronological order, and the security isolation chip reads the data to be interacted with in the preset cache queue in a cyclical manner based on the order of arrangement. In one example, when the target terminal is a local terminal and the data interaction request is a data transmission request, the data interaction request can carry the terminal ID of the transmitting terminal corresponding to the data to be interacted with. The data status of the converted interaction data stored in the preset cache queue can be a pending-send status.
[0067] In one example, if the target terminal meets the preset authentication conditions and the data interaction request is a data read request, the security isolation chip can match the corresponding cached data in the corresponding preset cache queue based on the data read request. If no match is found, a data read failure message is sent to the corresponding target terminal. Optionally, the security isolation chip can obtain the terminal ID in the data read request. If an ID similar to the terminal ID is matched, the match is considered successful; otherwise, the match fails, meaning that the corresponding preset cache queue does not store the corresponding cached data.
[0068] It should be understood that the peripheral interaction message cache queue (peripheral message queue) refers to the temporary data storage structure managed by the embedded peripheral entity interaction message component in the security isolation chip. It is used to cache the original interactive encrypted message data (converted interactive data) received from non-local terminals (such as handheld terminals and IoT platforms). The queue supports asynchronous message writing, queuing, and data status marking, providing data buffering for subsequent security authentication, encryption encapsulation, and firewall penetration processing.
[0069] The local data message cache queue (local message queue) refers to a circular buffer or linked list structure in the embedded local message component inside the security isolation chip used to store data to be processed or forwarded (interactive conversion data). This queue is responsible for caching the business data exchanged between the main control module in the local terminal and the security isolation chip, supporting asynchronous writing, reading and status management of messages, and completing the time decoupling and security isolation of data in the local processing flow.
[0070] The embedded local messaging component refers to the data processing unit within the security isolation chip used to manage the interaction between the main control module and the local terminal. It includes a local data message cache queue, message status maintenance and data exchange interfaces, as well as security processing logic. This security processing logic can include key negotiation, session management, secure interaction processes, and business message processing logic. This component is responsible for receiving business data from the master device, caching it in the local queue, and after security authentication and encryption, handing it over to the core isolation layer for subsequent forwarding, thus achieving controllable scheduling and secure isolation of the internal data flow.
[0071] The embedded peripheral entity interaction message component refers to a modular subsystem within a secure isolation chip dedicated to managing communication and interaction with non-local terminals (such as handheld terminals, IoT platforms, edge gateways, etc.). This system includes a peripheral interaction message cache queue, a message state management mechanism and communication interface, as well as security processing logic (including key negotiation, session management, secure interaction processes, and business message processing logic). It is responsible for receiving request data from external entities, caching it in the peripheral queue, and delivering it to the core isolation layer for authentication, decryption, and policy verification, achieving spatial isolation and asynchronous decoupling between external input and internal chip processing.
[0072] A secure channel is established between the security isolation chip and the non-local terminal. That is, when the security isolation chip receives data interaction requests from the non-local terminal and sends corresponding data interaction data to the non-local terminal, it needs to transmit data through the secure channel.
[0073] The aforementioned data processing method receives data interaction requests sent by the target terminal through a secure isolation chip. If the target terminal meets preset authentication conditions, the data to be interacted corresponding to the data interaction request is converted based on a preset data conversion strategy to obtain converted interaction data. The converted interaction data is then stored in a preset cache queue, or the converted interaction data is sent to the target terminal. This method enables secure authentication and data transmission of the target terminal through the secure isolation chip, improving the security level of the data transmission process. It decouples business data and encrypted communication, ensuring the confidentiality, integrity, and availability of local terminal data throughout its entire lifecycle. Furthermore, by storing the converted interaction data in a preset cache queue, asynchronous communication between the two parties is achieved, improving the adaptability and reliability for large-scale IoT deployments.
[0074] In one exemplary embodiment, the target terminal is a non-local terminal, and the data processing method further includes:
[0075] When the data interaction request is a data read request, identify the digital envelope in the data interaction request and identify the start token, data access token and address information in the digital envelope; determine the security protection level corresponding to the start token; if the data access token meets the preset security policy corresponding to the security protection level and the address information is in the preset security list, then determine that the non-local terminal meets the preset authentication conditions.
[0076] The digital envelope is a data encapsulation method used to encapsulate request and response messages between a non-local terminal and the security isolation chip. The encapsulation method of this digital envelope can conform to the national cryptographic standard (GM / T0010) and the international standard (PKCS#7). The digital envelope can also be carried in the data interaction request. The non-local terminal's data read request needs to penetrate the firewall of the security isolation chip to read messages in the local message queue. The preset authentication conditions ensure that the non-local terminal's data read request meets the requirements of digital envelope authentication and firewall penetration authentication. The activation token is used to determine the security protection level of the security isolation chip corresponding to the non-local terminal. This security protection level determines the data interaction level of the non-local terminal within the security isolation chip; different security levels correspond to different authentication strengths, encryption algorithms, key lifecycles, and access permissions. The data access token is a credential authorized to perform read / write operations on the corresponding cache queue and / or requests after a session with the security isolation chip is established. The data access token can include read and write permissions. The activation token and data access token can be security tokens, which are digital credentials used to identify the terminal's identity and permissions. The security token can be an SM4 checksum and / or SM2 signature data. Address information can be a MAC address. The security policy refers to the set of access control rules within the security isolation chip, used to determine permissions and verify the legitimacy of read and write operations on each terminal.
[0077] Specifically, when the digital interaction request is a data read request, the communication interface between the security isolation chip and the non-local terminal triggers an interrupt signal for data interaction. This interrupt signal is used to inform the security isolation chip to perform data interaction. The security isolation chip identifies the digital envelope carried in the data read request, as well as the activation token, data access token, and address information carried in the digital envelope. The security isolation chip pre-stores a correspondence between activation tokens and security protection levels. The security isolation chip can perform security verification on the activation token. After verification, it determines the security protection level corresponding to the activation token in the correspondence. For example, the security protection level can be level A, level B, and level C. Optionally, the activation token may include an SM4 checksum and / or SM2 signature data. If the SM2 signature data is a valid signature and / or the SM4 checksum is valid, then the activation token is deemed to have completed verification. The security isolation chip can pre-store valid signatures and valid checksums.
[0078] In one example, when the security isolation chip receives a data read request, it can authenticate the digital envelope in the request. The authentication process can involve determining that if a preset key can decrypt the data envelope to obtain the activation token, data access token, and MAC address, the authentication of the digital envelope is complete. Subsequent firewall penetration authentication is then performed based on the activation token, data access token, and MAC address. After successful digital envelope authentication and firewall penetration authentication, the non-local terminal is determined to meet the preset authentication conditions. The preset key can be an SM2 signature value (asymmetric key).
[0079] The preset security list is predetermined and is a whitelist. The security isolation chip can determine whether the address information is in the preset security list and not in the blacklist, and performs security verification on the security access token. The security isolation chip can determine the preset security policy corresponding to the security protection level, and whether the data access token meets the preset security policy. Optionally, the specific content of the preset security policy is related to the corresponding security protection level, and the security isolation chip predetermines the preset security policy corresponding to each security protection level.
[0080] The security policy includes at least one or more of the following: authentication code generation and verification method, whether an authentication code is included, whether a signature value is supported, encryption / decryption algorithm, digital envelope structure, signature verification algorithm, key used, and certificate conventions for signature and verification. In one example, if access is initiated by a non-local terminal, the following checks are made: whether the data access token contains a signature value; whether the SM2 signature verification algorithm is consistent with the security policy; whether the digital envelope structure and encryption / decryption algorithm of the data access token comply with the policy constraints; whether the key and signature certificate used by the data access token are valid keys / certificates as stipulated in the security policy; and whether the data access token is verified using the corresponding public key to confirm that the token has not been tampered with and its source is trustworthy. If all the above conditions are met, the data access token is determined to meet the preset security policy, and the non-local terminal is determined to meet the preset authentication conditions. It should be understood that this is only an example; the specific preset security policies corresponding to different security protection levels may vary and can be adjusted according to actual circumstances. No specific limitations are made here.
[0081] In addition, the security isolation chip can also store an address blacklist. If an address belongs to the blacklist, it will not be included in the preset security list. The blacklist contains MAC addresses that are prohibited from access, and devices on the list will be directly blocked. The collaborative operation of the blacklist and whitelist constitutes the chip's hardware-level access control and prevention for external entities.
[0082] In one example, if any of the start token, data access token, and address information does not meet the corresponding conditions, the non-local terminal is determined to be an illegitimate terminal, and the security isolation chip's own services are shut down.
[0083] Optionally, the digital envelope may carry a device identifier of a non-local terminal, and the digital envelope may be sent to the non-local terminal corresponding to the device identifier based on the device identifier.
[0084] In this embodiment, digital envelope authentication and firewall penetration authentication are performed on non-local terminals using a startup token, a data access token, and address information. This multi-token approach provides fine-grained control over non-local terminal access, enabling dynamic binding between non-local devices and security protection levels. The data access token strictly controls access permissions, and in conjunction with MAC blacklists / whitelists and preset security policies, a three-dimensional firewall model of "token + policy + whitelist" is constructed. This enhances security authentication protection before non-local terminals read local messages, thereby ensuring security during data interaction with non-local terminals and significantly improving the security of local data.
[0085] In an exemplary embodiment, the specific implementation process of step 202, "based on a preset data conversion strategy, converting the data to be interacted corresponding to the data interaction request to obtain converted interaction data," may include:
[0086] The system retrieves the data to be interacted corresponding to the data interaction request from the preset cache queue of the local terminal, and decrypts the data to obtain plaintext data. Based on the encryption strategy corresponding to the non-local terminal, the plaintext data is encrypted to obtain encrypted transmission data. The encrypted transmission data is then encapsulated according to a preset format to obtain converted interaction data.
[0087] The encryption strategy for the non-local terminal refers to the encryption strategy pre-negotiated between the security isolation chip and the non-local terminal. This encryption strategy can involve determining an external protection key, which can be determined by the security isolation chip's national cryptographic algorithm hardware accelerator performing asymmetric encryption operations. The encryption strategy can be related to the security protection level. The preset format can be the digital envelope's encapsulation format. For example, the preset format can be the GM / T 0010 or PKCS#7 digital envelope specification.
[0088] Specifically, the security isolation chip can identify the terminal identifier of a non-local terminal from the data interaction request, and retrieve the data to be interacted that matches the terminal identifier from the preset cache queue corresponding to the local terminal. It then decrypts the data to be interacted using a local protection key to obtain plaintext data, determines the peripheral protection key corresponding to the non-local terminal, encrypts the plaintext data using the peripheral protection key to obtain encrypted transmission data, and encapsulates the encrypted transmission data according to a preset format to obtain a digital envelope. This digital envelope is used to convert the interaction data. Additionally, the security isolation chip can transmit the data to the non-local terminal through a firewall. Optionally, the data to be interacted in the preset cache queue is arranged in storage order, and the security isolation chip can cyclically extract the data to be interacted corresponding to the non-local data from the preset cache queue.
[0089] In this embodiment, a secure isolation chip is used to negotiate session keys with non-local terminals, complete the conversion of data to be interacted with, and achieve asynchronous data communication. This decouples time and space in the communication process between local and non-local terminals. Furthermore, a double-layer encapsulation method is used to encapsulate the interaction between local and non-local terminals. Data encryption uses the protection key from the data conversion process for inner-layer encryption, and the ciphertext data is then filled into the requester's digital envelope as the outer layer of encapsulation. The encapsulation and decapsulation of the digital envelope are both completed within the secure isolation chip, ensuring the confidentiality and integrity of the data throughout the entire transmission link.
[0090] In an exemplary embodiment, the target terminal is a local terminal, and the data processing method further includes:
[0091] When the data interaction request is a data read request, determine the security protection level corresponding to the start token in the data read request, and if the data access token in the data read request meets the preset security policy corresponding to the security protection level, then determine that the local terminal meets the preset authentication conditions.
[0092] The data read request from the local terminal can be an interactive command. This interactive command can carry a startup token and a data access token. The preset authentication conditions can be firewall traversal authentication conditions.
[0093] Specifically, when the data interaction request is a data read request, the security isolation chip can determine the security protection level corresponding to the start token in the data read request, and determine the preset security policy corresponding to the security protection level. If the data access token in the data read request meets the preset security policy corresponding to the security protection level, then it is determined that the local terminal meets the preset authentication conditions. The preset authentication conditions can be firewall authentication. The determination of the security protection level corresponding to the start token and the determination of the preset security policy corresponding to the security protection level are consistent with the description in the above embodiments and will not be repeated here.
[0094] Optionally, if it is a local terminal, verify whether the data access token carries an authentication code as required by the security policy, and whether the authentication code generation method matches the security policy; verify whether the SM4 encryption / decryption algorithm of the data access token complies with the policy constraints; verify that the symmetric key used by the data access token is a legitimate key agreed upon by the security policy, and complete the integrity verification.
[0095] In this embodiment, a token is used to complete the strong authentication of the local terminal by the security isolation chip, thereby ensuring the security and controllability of the downlink data acquisition process.
[0096] In an exemplary embodiment, the specific implementation process of step 202, "based on a preset data conversion strategy, converting the data to be interacted corresponding to the data interaction request to obtain converted interaction data," may include:
[0097] The system retrieves the data to be interacted corresponding to the data interaction request from the preset cache queue corresponding to the non-local terminal, and decrypts the data to be interacted to obtain plaintext data; the plaintext data is then identified as the conversion interaction data.
[0098] This plaintext data can be plaintext external messages.
[0099] Specifically, the security isolation chip can read data from the preset cache queue corresponding to the non-local terminal in a loop according to the order of the data to be interacted; for each piece of data to be interacted read, the chip decrypts the data based on the external protection key to obtain plaintext data, identifies the plaintext data as the conversion interaction data, and sends the plaintext data to the main control module of the local terminal.
[0100] In this embodiment, by reading data from a preset cache queue corresponding to a non-local terminal, authentication of the local terminal is achieved, asynchronous reading of data from the non-local terminal is realized, and time and space decoupling between the two communicating parties is achieved, thereby further improving the security and controllability of the interaction process.
[0101] In an exemplary embodiment, the specific implementation process of step 202, "based on a preset data conversion strategy, converting the data to be interacted corresponding to the data interaction request to obtain converted interaction data," may include:
[0102] When the data interaction request is a data transmission request, the data to be interacted is encrypted based on the encryption strategy corresponding to the target terminal to obtain the converted interaction data.
[0103] Specifically, when the target terminal is a non-local terminal and the data interaction request is a data transmission request, the security isolation chip can obtain the data to be interacted corresponding to the data transmission request, which is carried in the data transmission request. The security isolation chip can encrypt the data to be interacted based on the peripheral protection key to obtain the converted interaction data. The security isolation chip can store the converted interaction data in a preset cache queue corresponding to the non-local terminal.
[0104] When the target terminal is a local terminal and the data interaction request is a data transmission request, the security isolation chip can obtain the data to be interacted corresponding to the data transmission request, which is carried in the data transmission request. The security isolation chip can encrypt the data to be interacted based on a local protection key to obtain the converted interaction data. The security isolation chip can store the converted interaction data in a preset cache queue corresponding to the local terminal. Optionally, the message status of the converted interaction data that has not been transmitted is a pending send status.
[0105] In this embodiment, by using storage encryption and asynchronous queues, queue decoupling and local encryption are achieved, ensuring the confidentiality and integrity of messages during storage and waiting, thus improving the security and efficiency of terminal communication. It also ensures the confidentiality and legitimacy of downlink messages, achieving secure isolation between external communication and terminal services.
[0106] In one exemplary embodiment, the data processing method further includes:
[0107] When the target terminal is a local terminal and the data interaction request is a data transmission request, the system identifies the local terminal's MAC address and a random number encrypted with a pre-shared key carried in the data transmission request. If the MAC address is in a preset security list and the random number obtained after decryption using the pre-shared key satisfies the consistency requirement, the data transmission request is deemed to meet preset authentication conditions. The random number is generated randomly by the security isolation chip and sent to the local terminal via a random number transmitter. Determining that the data transmission request meets the preset authentication conditions involves the completion of local interaction authentication between the local terminal's main control module and the security isolation chip. For example, the pre-shared key can be a symmetric key or a hash algorithm.
[0108] When the target terminal is a non-local terminal and the data interaction request is a data transmission request, the MAC address of the non-local terminal and a random number encrypted with an asymmetric key carried in the data transmission request are identified. If the MAC address is in a preset security list and the random number obtained after decryption with the asymmetric key satisfies the consistency requirement, the data transmission request is determined to meet the preset authentication conditions. The random number is generated randomly by the security isolation chip and sent to the non-local terminal by a random number transmitter. Determining that the data transmission request meets the preset authentication conditions signifies the completion of peripheral interaction authentication between the non-local terminal and the security isolation chip.
[0109] In this embodiment, two-way security authentication is performed on the target terminal before data transmission, which improves the security and reliability of data transmission.
[0110] In one instance, such as Figure 3 and Figure 4 As shown, Figure 3 This is a sequence diagram showing the interaction between external entities and the firewall of the security isolation chip when reading local messages. Figure 4 This is a schematic diagram illustrating the process by which an external entity reads local messages through the firewall of a security isolation chip.
[0111] like Figure 3As shown, the peripheral entity sends a digital envelope to the security isolation chip. This digital envelope includes an activation token, a digital access token, and a MAC address. The chip protection control service unit in the security isolation chip authenticates the data envelope and performs firewall penetration authentication on the activation token, digital access token, and MAC address. After the authentication conditions are met, it cyclically reads local messages (data to be exchanged) matching the peripheral entity from the local message queue of the security isolation chip. Based on the local protection key, it decrypts the data to be exchanged to obtain plaintext data, encrypts the plaintext data using the negotiated peripheral protection key to obtain encrypted transmission data (ciphertext message), encapsulates the encrypted transmission data into a digital envelope, sends the digital envelope to the peripheral entity, and the peripheral entity sends a fully confirmed communication message to the local terminal. The digital envelope is the encrypted local message.
[0112] like Figure 4 As shown, the security isolation chip first verifies the activation token of the peripheral entity to initiate the corresponding security level interaction prevention and control service (security protection level). This verifies the legitimacy of the peripheral entity, checks whether the data access token conforms to the preset security policy, and verifies whether the entity's MAC address is in the blacklist or whitelist. If any verification fails, the security isolation chip will proactively shut down its own service to block access. After successful verification, the chip continuously extracts decrypted local messages (data to be interacted with) from the local message queue. Based on the peripheral entity ID, the security isolation chip negotiates the corresponding security level interaction prevention and control service and activates the session key (peripheral protection key). The local message is then encrypted using the [peripheral protection key]. The encrypted data is encapsulated in a specific format, containing the peripheral entity identifier, ultimately forming a digital envelope, which is then transmitted to the peripheral entity through the firewall.
[0113] like Figure 5 The above, Figure 5 This is an interaction diagram where the data to be transmitted from a peripheral entity is asynchronously saved to a peripheral message queue. The peripheral entity and the local terminal initiate communication. The security isolation chip authenticates the peripheral entity. If preset authentication conditions are met, the chip obtains the peripheral message (data to be transmitted) sent by the peripheral entity, encrypts the message using the peripheral protection key to obtain the ciphertext (converted interaction data), and sends this ciphertext message to the peripheral message queue. Messages in the queue are in a pending reception state. The local terminal sends a communication completion confirmation response to the peripheral entity. The data to be transmitted can be data to be sent.
[0114] In this embodiment, access authentication, storage encryption, and asynchronous queues are used to ensure the confidentiality and legitimacy of downlink messages, thereby achieving secure isolation between external communication and terminal services.
[0115] like Figure 6 As shown, Figure 6This is an interaction diagram showing the asynchronous saving of messages sent locally by the local terminal to the local message queue. After the main control module of the local terminal performs local interactive authentication with the chip protection control service component, the chip protection control service component saves the local message, encrypts the local message using the local protection key to obtain the local message ciphertext, and saves it to the local message queue. The main control module and the chip protection control service component communicate to complete the confirmation.
[0116] In this embodiment, the message is first asynchronously stored in a local queue, authenticated by a security isolation chip, encrypted using a local key, and then stored in a ciphertext queue awaiting transmission. At this time, the message status is set to "pending transmission." Through queue decoupling and local encryption, the confidentiality and integrity of the message are ensured during storage and waiting. Furthermore, during data transmission, it is not necessary to wake up non-local terminals, thus achieving asynchronous message transmission and improving the security and efficiency of terminal communication.
[0117] like Figure 7 As shown, Figure 7 This is an interaction diagram of a local terminal reading peripheral messages from a peripheral message queue. The main control module of the local terminal initiates an interaction command (data read request) with a token and security policy. After authentication by the firewall, the security isolation chip reads the ciphertext of the peripheral messages in a loop and decrypts them using the peripheral protection key, returns plaintext data to the terminal, and confirms that the communication is complete.
[0118] In this embodiment, the security and controllability of the downlink data acquisition process are ensured by actively pulling data, strong authentication, and hardware decryption isolation.
[0119] like Figure 8 As shown, Figure 8This is a defense-in-depth architecture based on a dedicated security isolation chip, derived from the "hardware isolation and proactive defense" design in embedded terminal systems. The main control module directly interacts with the security isolation chip, and peripheral entities also directly interact with the security isolation chip. The security isolation chip architecture is divided into four layers from bottom to top: the hardware cryptographic layer integrates a true random number generator and national cryptographic algorithms (SM1 / SM2 / SM3 / SM4) to provide the system with high-strength cryptographic services and a root of trust; the basic software layer manages the file system and secure operations through COS to support upper-layer functions; the core isolation layer is the execution center of security policies, achieving forced isolation and conversion of internal and external data through security authentication, token maintenance, firewall isolation, and digital envelope technology; the application interaction layer designs a dual message queue system to handle data exchange between peripheral entities and local business separately, achieving asynchronous decoupling through independent cache queues. The system includes a security authentication and security protection isolation layer, which can pre-set security policies for different security protection levels. It maintains security tokens (updating the security protection level corresponding to the activation token within the security token), provides a message security conversion service (calling encryption algorithms and random number circuits to encrypt and decrypt the data to be interacted with), performs firewall security isolation (authenticating terminals that need to read data before firewall penetration), secures key certificates, and specifies the format of digital envelopes for communication with external entities. A true random number generator circuit generates unpredictable random numbers based on physical noise sources (such as thermal noise and oscillator jitter) for session key derivation, challenge value generation, and the construction of temporary keys in digital envelopes. This hardware circuit operates independently within the chip, and the key materials and random number generation process are never exposed to the external bus, providing physical-level entropy sources and algorithmic support for the cryptographic operations of the secure isolation chip.
[0120] In this embodiment, all security-related operations are completed within the secure isolation chip. The main control MCU is only responsible for business processing and does not access any plaintext keys or sensitive data. By offloading communication security responsibilities from the main control chip to the dedicated isolation chip, a logical and physical dual isolation boundary for internal and external data exchange is constructed within the secure isolation chip through a hardware and software collaborative mechanism. Specifically, the secure isolation chip acts as the sole trusted proxy between the terminal device and external entities, forcing all cross-domain interactions to be processed through the chip's built-in firewall, authentication module, and encryption / decryption engine. This ensures that sensitive data, key materials, and security processes are completely separated from the main control MCU and external networks, thereby blocking unauthorized access and potential attack paths, and constructing a trusted execution boundary. This not only significantly improves the system's security level but also decouples the tight coupling between business processing and encrypted communication, ensuring the confidentiality, integrity, and availability of terminal data throughout its entire lifecycle. It establishes a hardware-level trust foundation for IoT terminals and has broad application prospects in fields such as smart metering and industrial control.
[0121] In one instance, a data processing method may include the following steps:
[0122] The local terminal receives communication requests from non-local terminals;
[0123] The chip protection control service component in the security isolation chip can receive data transmission requests sent by non-local terminals; and identify the start token, data access token and address information carried in the data transmission request, determine the security protection level corresponding to the start token, and if the data access token meets the preset security policy corresponding to the security protection level and the address information is in the preset security list, then it is determined that the non-local terminal meets the preset authentication conditions and obtains the data to be transmitted in the data transmission request;
[0124] The data to be transmitted is encrypted using the peripheral protection key to obtain the encrypted data to be transmitted. The encrypted data to be transmitted and the terminal ID corresponding to the non-local terminal are stored in the peripheral message queue. At this time, the data status of the encrypted data to be transmitted is the terminal to be sent.
[0125] The main control module of the local terminal sends a data read request to the chip protection control service component; the chip protection control service component identifies the start token in the data read request and determines the security protection level corresponding to the start token. If the data access token in the data read request meets the preset security policy corresponding to the security protection level, it is determined that the local terminal meets the preset authentication conditions.
[0126] The chip protection control service component can, based on the data read request, cyclically read matching data to be transmitted from the external message queue, decrypt the data to be transmitted based on the external protection password to obtain plaintext data, and then send the plaintext data to the main control module. After receiving the plaintext data, the main control module sends a communication completion confirmation message to the chip protection control service component.
[0127] Optionally, when the chip protection control service component reads the matching data to be transmitted, it sends a message to the main control module to read the identification message.
[0128] In one example, if the main control module and / or non-local terminals do not meet the preset authentication conditions, the security isolation chip's own services are shut down.
[0129] Optionally, this embodiment describes the process of a non-local terminal transmitting data to a local terminal. It should be understood that the transmission of data from a non-local terminal to a local terminal and the reception of data from a local terminal to a non-local terminal can be asynchronous.
[0130] In one instance, a data processing method may include the following steps:
[0131] The main control module of the local terminal can send data transmission requests to the chip protection control service component;
[0132] The chip protection control service component can decrypt the data transmission request based on the key, obtain the random number and address information carried in the data transmission request, and determine that the main control module meets the preset authentication conditions if the random number matches the stored random number and the address information meets the whitelist. It then uses the local key to encrypt the data to be transmitted carried in the data transmission request to obtain the local message ciphertext, and stores the local message ciphertext in the local message queue. The local message ciphertext is in the pending transmission state in the local message queue. The local message ciphertext carries the terminal ID of the non-local terminal to be transmitted or the security protection level corresponding to the non-local terminal that can be accessed.
[0133] Non-local terminals can send data read requests to the chip protection control service component, with the data read request carrying a digital envelope; the communication interface between the security isolation chip and the non-local terminal triggers an interrupt signal for data interaction, which is used to inform the security isolation chip to perform data interaction;
[0134] The chip protection control service component decrypts the digital envelope based on a preset key, which can be a symmetric key. It identifies the activation token, data access token, and address information carried in the digital envelope, determines the security protection level corresponding to the activation token, and if the data access token meets the preset security policy corresponding to the security protection level, and the address information is in the preset security list, then the non-local terminal is determined to meet the preset authentication conditions. It then reads the local message queue cyclically to obtain the matching local message ciphertext (terminal ID matching or security protection level matching), decrypts the local message ciphertext based on the local protection key to obtain plaintext data, and encrypts the plaintext data using the peripheral protection key negotiated with the non-local terminal to obtain local message ciphertext. The local message ciphertext carries the non-local terminal's terminal ID and is then encapsulated in the digital envelope before being sent to the non-local terminal. Upon receiving the digital envelope, the non-local terminal sends a communication completion confirmation message to the local terminal.
[0135] In this embodiment, data transmission from the local terminal to the non-local terminal is achieved through a security isolation chip, enabling asynchronous transmission. Furthermore, the terminal is authenticated using a negotiated key, and messages during transmission are encrypted, thus achieving strong authentication, access control, and encrypted transmission, ensuring the data security and legitimacy of the external reading process.
[0136] In one instance, the data processing method may also include:
[0137] The target terminal sends a data interaction request to a preset edge device. The preset edge device performs security authentication on the data interaction request and stores the conversion interaction data in a preset cache queue, or sends the conversion interaction data to the target terminal. Optionally, the preset edge device can be a dedicated AI edge device.
[0138] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0139] Based on the same inventive concept, this application also provides a data processing apparatus for implementing the data processing method described above. The solution provided by this apparatus is similar to the implementation scheme described in the above method; therefore, the specific limitations in one or more data processing apparatus embodiments provided below can be found in the limitations of the data processing method described above, and will not be repeated here.
[0140] In one exemplary embodiment, such as Figure 9 As shown, a data processing device 90 is provided, applied to a security isolation chip, including: a receiving module 91 and a processing module 92, wherein:
[0141] The receiving module 91 is used to receive data interaction requests sent by the target terminal;
[0142] The processing module 92 is configured to, if the target terminal meets the preset authentication conditions, convert the data to be interacted corresponding to the data interaction request based on the preset data conversion strategy to obtain converted interaction data, and store the converted interaction data in a preset cache queue, or send the converted interaction data to the target terminal.
[0143] In one embodiment, the target terminal is a non-local terminal, and the data processing device further includes:
[0144] The identification module is used to identify the digital envelope in the data interaction request when the data interaction request is a data read request, and to identify the activation token, data access token and address information carried by the digital envelope;
[0145] The determination module is used to determine the security protection level corresponding to the launch token. If the data access token meets the preset security policy corresponding to the security protection level and the address information is in the preset security list, then it is determined that the non-local terminal meets the preset authentication conditions.
[0146] In one embodiment, the processing module 92 is used to obtain the data to be interacted corresponding to the data interaction request from the preset cache queue corresponding to the local terminal, and to decrypt the data to be interacted to obtain plaintext data.
[0147] Based on the encryption strategy corresponding to the non-local terminal, the plaintext data is encrypted to obtain encrypted transmission data, and the encrypted transmission data is encapsulated according to a preset format to obtain converted interactive data.
[0148] In one embodiment, the target terminal is a local terminal, and the data processing device further includes:
[0149] The judgment module is used to determine the security protection level corresponding to the start token in the data read request when the data interaction request is a data read request, and to determine that the local terminal meets the preset authentication conditions if the data access token in the data read request meets the preset security policy corresponding to the security protection level.
[0150] In one embodiment, the processing module 92 is used to obtain the data to be interacted corresponding to the data interaction request from a preset cache queue corresponding to the non-local terminal, and to decrypt the data to be interacted to obtain plaintext data; and to determine the plaintext data as the conversion interaction data.
[0151] In one embodiment, the processing module 92 is configured to, when the data interaction request is a data transmission request, encrypt the data to be interacted based on the encryption strategy corresponding to the target terminal to obtain converted interaction data.
[0152] In one embodiment, the processing module 92 is configured to send the converted interaction data to the target terminal when the data interaction request is a data read request;
[0153] If the data interaction request is a data transmission request, the conversion interaction data is stored in a preset cache queue.
[0154] Each module in the aforementioned data processing device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the operations corresponding to each module.
[0155] In one exemplary embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 10 As shown, the computer device includes a processor, memory, input / output interfaces, a communication interface, a display unit, and an input device. The processor, memory, and input / output interfaces are connected via a system bus, and the communication interface, display unit, and input device are also connected to the system bus via the input / output interfaces. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The input / output interfaces are used for exchanging information between the processor and external devices. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, Near Field Communication (NFC), or other technologies. When the computer program is executed by the processor, it implements a data processing method. The display unit is used to form a visually visible image and can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be an LCD screen or an e-ink screen. The input device of the computer device can be a touch layer covering the display screen, or buttons, trackballs, or touchpads set on the casing of the computer device, or external keyboards, touchpads, or mice, etc.
[0156] Those skilled in the art will understand that Figure 10 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0157] In one embodiment, a chip is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above method embodiments.
[0158] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above-described method embodiments.
[0159] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the steps in the above method embodiments.
[0160] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.
[0161] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.
[0162] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.
[0163] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0164] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A data processing method, characterized in that, The method, applied to a security isolation chip, includes: Receive data interaction requests sent by the target terminal; If the target terminal meets the preset authentication conditions, the data to be interacted corresponding to the data interaction request is converted based on the preset data conversion strategy to obtain converted interaction data, and the converted interaction data is stored in a preset cache queue, or the converted interaction data is sent to the target terminal.
2. The method according to claim 1, characterized in that, The target terminal is a non-local terminal, and the method further includes: When the data interaction request is a data read request, identify the digital envelope in the data interaction request, and identify the activation token, data access token and address information carried by the digital envelope; The security protection level corresponding to the launch token is determined. If the data access token meets the preset security policy corresponding to the security protection level and the address information is in the preset security list, then the non-local terminal is determined to meet the preset authentication conditions.
3. The method according to claim 2, characterized in that, The process of converting the data to be interacted corresponding to the data interaction request based on a preset data conversion strategy to obtain converted interaction data includes: The system retrieves the data to be interacted corresponding to the data interaction request from the preset cache queue corresponding to the local terminal, and decrypts the data to be interacted to obtain plaintext data. Based on the encryption strategy corresponding to the non-local terminal, the plaintext data is encrypted to obtain encrypted transmission data, and the encrypted transmission data is encapsulated according to a preset format to obtain converted interactive data.
4. The method according to claim 1, characterized in that, The target terminal is a local terminal, and the method further includes: If the data interaction request is a data read request, determine the security protection level corresponding to the start token in the data read request, and if the data access token in the data read request satisfies the preset security policy corresponding to the security protection level, then determine that the local terminal satisfies the preset authentication conditions.
5. The method according to claim 4, characterized in that, The process of converting the data to be interacted corresponding to the data interaction request based on a preset data conversion strategy to obtain converted interaction data includes: The system retrieves the data to be interacted corresponding to the data interaction request from the preset cache queue corresponding to the non-local terminal, and decrypts the data to be interacted to obtain plaintext data; the plaintext data is then identified as the conversion interaction data.
6. The method according to claim 1, characterized in that, The process of converting the data to be interacted corresponding to the data interaction request based on a preset data conversion strategy to obtain converted interaction data includes: When the data interaction request is a data transmission request, the data to be interacted is encrypted based on the encryption strategy corresponding to the target terminal to obtain the converted interaction data.
7. The method according to claim 1, characterized in that, The step of storing the conversion interaction data in a preset cache queue, or sending the conversion interaction data to the target terminal, includes: If the data interaction request is a data read request, the converted interaction data is sent to the target terminal; If the data interaction request is a data transmission request, the conversion interaction data is stored in a preset cache queue.
8. A data processing apparatus, characterized in that, The device, used in a security isolation chip, includes: The receiving module is used to receive data interaction requests sent by the target terminal; The processing module is configured to, if the target terminal meets the preset authentication conditions, convert the data to be interacted corresponding to the data interaction request based on the preset data conversion strategy to obtain converted interaction data, and store the converted interaction data in a preset cache queue, or send the converted interaction data to the target terminal.
9. A security isolation chip, comprising an internally integrated memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 7.
10. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 7.