IoV Security: Why Start with an Automotive-Grade Security SoC?
With the formal implementation of GB 44495-2024 "Technical Requirements for Vehicle Cybersecurity" and the release of GB/T 47324-2026 "Cybersecurity Protection Requirements for IoV Platforms," China's IoV cybersecurity is evolving from point-based protection toward a systematic architecture spanning "vehicle–communication–platform." On the vehicle side, regardless of whether it is identity authentication, Secure Boot, OTA signature verification, key protection, or sensitive data isolation, the underlying security capabilities must ultimately be anchored in a trusted hardware root.
In the era of intelligent connected vehicles, cybersecurity continues to rise in strategic importance, with IoV standing as a priority battleground. An intelligent connected vehicle is essentially a high-speed mobile computing node that simultaneously connects to V2X, OTA, digital keys, and eSIM. It continuously performs identity authentication, firmware integrity attestation, and location exchange with roadside units, the cloud, and neighboring vehicles. All of these trust judgments are underpinned by cryptographic algorithms. An standalone security chip can provide a hardware-isolated trusted execution boundary for keys, device identities, and critical cryptographic operations, ensuring that sensitive keys are never exposed to the general-purpose execution environment of the main processor. The Jahport JA700 is purpose-built for exactly this.
Pain Points: The Triple Quandary of Link, Protocol, and Data in IoV Security
From theory to mass production, security threats ultimately converge into three hard requirements that must be addressed one by one: communication links, in-vehicle protocol stacks, and tiered data protection.
Untrusted Communication Links
Intelligent vehicles interact with the outside world simultaneously through cellular, V2X, Bluetooth, Wi-Fi, USB, and many other links, each of which can become an attacker's entry point. Rogue base stations can intercept vehicle-to-cloud traffic, malicious APs can launch man-in-the-middle attacks, forged roadside units can inject fake V2X messages into vehicles, and even replay remote vehicle-control commands to achieve illegal unlocking. More challenging, jamming and flooding attacks targeting cellular or V2X RF links can cause a vehicle to "lose contact" or misjudge surrounding traffic conditions at high speed.
Undefended In-Vehicle Protocols
Inside a modern vehicle, heterogeneous networks coexist with multiple protocols including CAN/CAN FD, LIN, Ethernet, TSN, and in-vehicle wireless. Gateways, domain controllers, and dozens or even hundreds of ECUs exchange thousands of messages per second. Some legacy ECUs and early in-vehicle networks were designed with a focus on real-time performance and reliability, and the protocols themselves lack native identity authentication, message integrity protection, and anti-replay mechanisms. If Bootloader, diagnostic permissions, or firmware signature-verification mechanisms are misconfigured, the risks of illegal reflashing and firmware tampering are further exposed. Typical scenarios include:
- CAN bus injection: Injecting malicious messages into powertrain, steering, and braking buses via OBD-II or a compromised ECU.
- ECU firmware tampering: Exploiting Bootloader vulnerabilities to flash malicious firmware and turn critical controllers "rogue."
- Diagnostic protocol abuse: Using UDS services to bypass security restrictions, read sensitive data, or execute sensitive actions.
Unisolated Sensitive Data
As cockpit, intelligent driving, and body control continue to converge, growing volumes of data at varying sensitivity levels are aggregated within the same computing platform. Relying solely on OS permissions or software logic for isolation, a compromise of any high-privilege component or system software may cause keys, identity credentials, and sensitive data to leak across security domains. Therefore, critical data still requires tiered protection combining hardware access control, a Trusted Execution Environment, and isolated secure storage.
Solution
IoV security must be addressed simultaneously across three dimensions—link encryption, protocol stack hardening, and data tiering—which all ultimately point to the same hardware foundation: a high-specification, high-reliability automotive security chip. The JA700 delivers a complete solution that systematically addresses the three core needs of regulatory compliance, mass-production deployment, and future evolution.
Solution Overview: An End–Road–Cloud Three-Layer Architecture
- Trusted vehicle endpoint. The JA700 (Grade 1) is embedded as an standalone security chip in key nodes such as T-Box, V2X OBU, central gateway, cockpit/intelligent-driving domain controller, and digital key module, providing each node with a hardware root of trust, cryptographic engine, and key vault; Secure Boot establishes the chain of trust starting from the very first line of code executed at chip power-up.
- Roadside collaboration. In roadside RSU and edge computing devices, security chips/security modules with hardware root-of-trust capabilities can be deployed to join a unified certificate and identity trust system together with the vehicle side. Roadside and vehicle endpoints can join a unified or compatible PKI trust framework, establishing trusted communication relationships through certificate chain verification, identity authentication, and secure key negotiation.
- Cloud-side management. Paired with an IoV security platform, it fully supports the Chinese cryptographic algorithm system, providing secure cryptographic distribution, secure issuance and registration, terminal device management, standardized access authentication links, and system-level security situational awareness. The platform supports multiple device types, offers elastic scaling and two-factor authentication, and enables auditable and traceable management of certificate renewal, revocation, and OTA security policy delivery.
End-to-End Protection, Full-Scenario Deployment
Three-dimensional protection covering the entire computing workflow, centered on True Random Number Generator (TRNG), side-channel and fault injection protection, anti-tamper design, trusted computing, and confidential computing mechanisms, builds a complete security closed loop from key generation to execution environment.
- Hardware configuration. Equipped with a 32-bit in-house secure CPU core, 128KB SRAM and 2MB Flash provide ample local resources for cryptographic operations and trusted applications. A heterogeneous multi-core design coordinates multiple processor cores of different types, making it difficult for vulnerabilities targeting a single instruction set or architecture to propagate laterally, further strengthening chip-level security protection.
- Automotive-grade reliability. Strictly compliant with automotive-grade reliability standards, with a design lifetime of up to 20 years, moisture sensitivity level MSL3, and ESD protection of HBM ±2kV and CDM 500V.
- Interfaces and deployment. Supports a wide supply range of 1.8V to 3.6V, and provides master/slave configurable interfaces including SPI, QSPI, I²C, UART, and SDIO. Compact QFN32/QFN40 packages enable flexible deployment in space-constrained board environments such as T-Box, gateways, and domain controllers, and help shorten board-level routing for critical security interfaces.
- Security certification. Security capabilities have passed CC EAL5+ international certification and commercial cryptography Class 2 certification.
Delivered Are Not Bare Dies, but a Mass-Production Toolchain
Two things matter most for solution rollout: security functions that cannot be integrated into existing software architectures, and inability to ramp to mass production after certification. The JA700 IoV security solution addresses both:
- Software layer, the Bothnia secure operating system provides foundational security capabilities including TEE, secure boot, and key management, and can be adapted to different application frameworks such as GlobalPlatform, Android StrongBox, eSE, TPM, and AUTOSAR HSM. It can integrate into existing software architectures through the AUTOSAR cryptographic service interface and adaptation layer, reducing the migration and integration costs of legacy HSM solutions.
- Engineering layer, a high-fidelity development platform based on GEM5 is provided, along with chip personalization and issuance management systems. From part selection, development, and certification through to mass production and issuance, the toolchain across the entire flow is complete.
Half a Step Ahead: The Technical Inevitability of Early PQC Deployment Against Post-Quantum Threats
The JA700 covers three categories of algorithms with one unified hardware:
Chinese cryptographic algorithms: SM2/SM3/SM4/SM9.
International: RSA/ECC/ECDSA/ECDH/Curve25519, etc.
PQC: ML-KEM (Kyber), ML-DSA (Dilithium), SLH-DSA (SPHINCS+).
Classical public-key and post-quantum algorithms are co-designed within the cryptographic coprocessor, making "crypto agility" a native capability of the chip rather than an add-on feature. In the face of Harvest Now, Decrypt Later (HNDL) risks, data with long-term confidentiality value requires the early introduction of quantum-resistant cryptographic protection. Once today's communications protected by traditional public-key cryptography are intercepted and stored long-term by attackers, even if the system completes a PQC upgrade in the future, the decryption risk to historical data cannot be retroactively eliminated.
The JA700 approach is to build PQC directly into the hardware coprocessor, with native support for the three major algorithms standardized by NIST in 2024:
- ML-KEM (Kyber): A key encapsulation mechanism used to establish quantum-secure symmetric keys, which can build quantum-resistant key establishment mechanisms and provide a post-quantum migration path for traditional ECDH-based public-key key agreement systems.
- ML-DSA (Dilithium): A digital signature for quantum-secure upgrades of V2X message authentication, certificate issuance, and OTA signature verification.
- SLH-DSA (SPHINCS+): NIST itself explicitly describes SLH-DSA as following a different mathematical route, serving as a backup in case issues arise with ML-DSA.
At the vehicle business level, the convergence of the three algorithm systems delivers tangible value: core scenarios such as V2X vehicle-road collaborative message authentication, certificate system management, and OTA upgrade package signing can all migrate smoothly to the quantum-resistant track. Hybrid key agreement and dual-signature mechanisms that simultaneously support traditional and post-quantum algorithms not only maintain compatibility with existing infrastructure but also reserve a hardware-level channel for future algorithm replacement. Beyond the algorithm layer, the JA700 simultaneously deploys runtime active defense capabilities through dynamic heterogeneous redundancy. Beyond meeting baseline security, identity authentication, access control, and cryptographic protection requirements, vehicles must also face unknown vulnerabilities, anomalous behaviors, and new types of attacks throughout their long-term operation. Therefore, runtime active defense and system resilience can serve as further enhancements above baseline compliance. On top of static compliance, the JA700 enhances the system's sustained defense and fault-tolerance capabilities against unknown attacks and runtime anomalies.
Closing Remarks
The implementation of GB 44495-2024 marks the transition of China's intelligent connected vehicle security from "industry self-discipline" to "national mandate." For the security chip industry, this is a moment to step into the spotlight under mandatory national standards: the four roles of root of trust, cryptographic engine, key vault, and compliance evidence carrier are all indispensable. The significance of the JA700 extends beyond a single chip: native chip-level support for Chinese cryptographic algorithms takes "autonomy and controllability" beyond mere software replacement; holding both AEC-Q100 automotive-grade certification and CC EAL5+ security certification also provides foundational support for vehicle exports facing UN R155/R156 and ISO/SAE 21434 compliance requirements. If you are planning mass-production projects for T-BOX, central gateways, V2X OBU/RSU, digital keys, or eSIM, please feel free to contact us.

