






















Vehicle video is evidence. Evidence travels two exposed paths: a public radio network in transit and a removable card at rest. SM4 is the national block cipher the Chinese commercial cryptography system provides for exactly this duty. Implementing it on a monitoring fleet is a bounded engineering job: two encryption surfaces, a hardware engine that keeps the cost near zero, a key lifecycle the fleet manages on paper, plus an acceptance test that proves the whole chain. The implementation changes none of the recording mechanics this series has established. It wraps them.
The cipher itself is settled standard. SM4 is the block cipher of the national commercial cryptography family, published as standard GB/T 32907 in 2016 after years as the commercial algorithm under the designation GM/T 0002. It works on 128-bit blocks with a 128-bit key across 32 rounds, the same block and key sizes the international AES-128 occupies. It entered the international register in 2021 through an amendment to ISO/IEC 18033-3. The algorithm choice is the one decision a fleet does not make, because the ecosystem made it.
The family around the cipher divides the labour. SM2 is the elliptic-curve public-key algorithm, the signer of certificates and the carrier of key exchanges. SM3 is the hash, the integrity check of the family, in the same class as SHA-256. SM4 is the bulk worker: the symmetric cipher that turns video bytes into ciphertext at line speed. An implementation touches all three, with SM4 carrying the volume and the other two carrying the trust around it.
The implementation reads in the order a project meets it: why this cipher, the two surfaces, the hardware that makes it cheap, the keys, the compatibility with the recording machinery, the acceptance numbers, the specification lines.
Two surfaces, one cipher, one key ledger.
The pull is regulatory ecosystem before it is cryptography. The public-security video networking standard, GB 35114, builds its security requirements on the national SM family: SM2 for identity and signatures, SM3 for integrity, SM4 for the video stream itself. Systems that feed government and public-security platforms meet SM-family requirements as a condition of connection, written into procurement after procurement across the regulated classes. A commercial fleet choosing its cipher today chooses the one its future interconnections already speak, on both the device side and the platform side of every docking.
The technical case stands on its own beside the regulatory one. SM4 is a modern 128-bit block cipher with two decades of public analysis, international standardisation and silicon support across the SoC catalogue the terminal market builds on. For the bulk encryption of video at vehicle bitrates, it does the same class of work AES-128 does elsewhere, at the same class of computational cost. Nothing about the duty is exotic. The cipher is a commodity part of the national stack.
The international standing closes the interoperability question for export-touching fleets. With SM4 listed in ISO/IEC 18033-3 since the 2021 amendment, a system built on it cites an international register as readily as a national one. Cross-border operations that meet European or other regional security reviews present the cipher as a registered ISO algorithm with public analysis behind it, the paperwork posture that keeps a Chinese-market terminal saleable in mixed fleets.
The compliance reviews of the commercial cryptography system add the standing audience. Deployments in regulated classes face periodic security assessments of how cryptography is applied: which algorithms, which key custody, which records. A fleet running the national suite with a written ledger walks into that review with its answers on one page. A fleet running an ad-hoc mix reconstructs its answers under deadline, the difference between an audit morning and an audit season.
Procurement language is the remaining pull. Tenders in regulated transport classes name national-algorithm support as a scored or required line, the same way they name protocol compliance and device standards. A terminal maker that ships SM4 in hardware answers the line with a datasheet row and a certificate reference. A fleet that specifies it today avoids re-opening the hardware question when a client or a regulator names the requirement mid-contract, the cheapest time to meet a mandate being the purchase before it lands.
The first surface is transit. Every byte that leaves the vehicle crosses a public mobile network, the path the dropout and billing pages map: carrier radio, carrier core, public internet, platform port. Transit encryption wraps the whole session so the bytes that cross those segments read as ciphertext to everything sitting between the terminal and the platform port. The common implementations carry the protocol session inside an encrypted channel using national-algorithm cipher suites, with SM2 doing the handshake and certificate work and SM4 carrying the stream. What it protects is plain: interception anywhere along the public path yields nothing readable, no live view frames, no alarm stills, no parcel contents, no position stream. The protection covers the campus network gate as readily as the 4G path, the same wrapped session over a different bearer. The second surface is rest. The recording lives on a removable card in a parked vehicle, the exposure the storage pages price in their own terms: theft of the vehicle, theft of the card alone, a card pulled during a dispute by someone holding a screwdriver and a motive. At-rest encryption writes the clip files as SM4 ciphertext, so a card in the wrong reader yields file names and sizes at best. The decrypt lives with the key. The key is not on the card. The two surfaces fail independently, which is the reason both exist. Transit encryption does nothing for a stolen card. Storage encryption does nothing for an intercepted stream. A specification that names only one surface has answered half the exposure, the half-answer one scope line closes. Common deployments stage the two surfaces in that order, transit first on the platform connection, rest second with the terminal generation that carries the engine, with the scope line recording which stage the fleet has reached and which generation closes the gap. The surfaces also price differently. Transit encryption costs a handshake at session start and a per-byte transform both ends already do at line speed. Rest encryption costs the same transform on the write path the recording loop already drives. On hardware engines, both costs sit below the noise floor of the power and thermal budgets the series prices elsewhere. The two surfaces also serve two different readers of the specification: the transit line answers the network security review, the rest line answers the physical security review, with one cipher and one key registry behind both. The implementation decision is scope. Affordability is settled before the question opens.

The arithmetic settles the performance question early. A four-channel terminal writes video at single-digit megabits per second, the recording-tier figures the codec pages carry. A software SM4 implementation on the terminal-class processors of this market moves tens of megabytes per second and more. The cipher outruns the camera by two orders of magnitude before any hardware help arrives. Encryption at vehicle bitrates is a rounding error on the processor budget, the same conclusion the heartbeat page reached for its bytes.
The hardware engine moves the work off the processor entirely. SoC families built for the Chinese device market carry national-algorithm engines beside their video encoders: dedicated blocks that run SM4 at line speed with their own registers and their own power island. The encode-encrypt-write path runs as a pipeline in silicon, with the main cores untouched. The datasheet line to read is the engine’s presence and its throughput, one row beside the encoder’s. Engines and elements in this market ship with commercial-cryptography product certificates, the reference number a procurement office checks against the issuing authority’s register before signing.
The software fallback needs naming because budget terminals ship it. A terminal that runs SM4 on its main cores still encrypts comfortably at vehicle bitrates, on the arithmetic above. The cost moves from silicon to the processor budget: cycles shared with the encoder pipeline, a measurable bump in load and current, headroom taken from the hottest summer afternoons the thermal pages plan for. The acceptance bench below reads the difference directly. The specification decides whether the fallback is acceptable for the duty or whether the engine row is mandatory.
The secure element carries the keys, with the throughput left to the engine. A dedicated key-storage part, the class of chip a bank card carries, holds the device’s keys in hardware that resists extraction: no debug port reads them, no firmware dump includes them, the cipher operations that need the raw key run inside the element. The split is standard design: the engine does the fast work with session keys, the element guards the long-lived keys that derive them.
The power and heat budgets absorb the engine without a line item. A hardware block doing streaming SM4 at vehicle bitrates draws a fraction of what the encoder beside it draws, inside thermal budgets the codec page already walks. The parked-recording budget the power pages reserve sees no measurable change. The acceptance section below still measures it, because the series measures everything it claims.
The fleet manages keys as paperwork, with the cryptography underneath handled by the parts. The lifecycle has five stations: generation, injection, use, rotation, revocation. Each station has an owner and a record, named in the contract before the first terminal ships. The fleet’s job is the ledger, the same discipline the SIM and configuration pages set for their own assets, applied to a key column.
Generation and injection happen before the vehicle meets the road. Device keys are generated and injected at manufacture or at commissioning under controlled process, landing in the secure element where they stay for their working life. The commissioning record names which device carries which key identity, the row the platform’s key management consults at registration. A fleet receives terminals with keys aboard the way it receives them with device identities aboard, one more field in the acceptance paperwork and one more column in the commissioning record.

The platform side mirrors the element with heavier hardware. Master keys and the per-device key registry live in the platform’s key management, backed by hardware security modules in serious deployments, the data-centre counterpart of the card-sized element riding in every vehicle. Session keys derive per connection and expire with it, leaving nothing long-lived on the wire. Stored-footage keys map to devices and dates in the registry, the lookup every authorised decrypt walks through and an unauthorised one cannot reach.
Rotation rides the channels the series already built. Session keys rotate themselves by living one session. Longer-lived keys rotate on schedule or on suspicion, pushed through the same configuration machinery every parameter page uses, with the secure element verifying the push’s signatures before accepting any new key into its store. The rotation record joins the ledger: which fleet, which date, which key generation, three columns an audit reads in one pass.
Revocation is the lifecycle’s reason for the registry. A terminal stolen with its vehicle holds keys the registry can mark dead: the platform refuses its sessions, its stored ciphertext stays sealed to whoever holds the card, the replacement terminal arrives with fresh keys and a fresh row. The loss costs hardware. The keys, managed this way, cost nothing beyond the marking, the failure mode the whole lifecycle exists to buy.
The recording loop gains one stage and loses nothing. The pipeline the recording page walks, camera to encoder to writer, becomes camera to encoder to cipher to writer, with the cipher stage running in the hardware engine at line speed beside the encode. Pre-allocated clip files fill with ciphertext at the same cadence they filled with plaintext on unencrypted designs. The flush rhythm, the clip boundaries and the power-loss behaviour carry over unchanged, because the cipher sits inside the write path, ahead of everything the storage design already survives.
The queue and resume machinery never sees plaintext and never needs to. Alarm parcels queue as ciphertext, resume from byte offsets in ciphertext, then arrive at the platform where the session terminates and the decrypt happens under platform keys. A transfer interrupted at any offset resumes at that offset, the property the recording and campus pages rely on, untouched because the cipher does not change byte counts in the streaming modes these systems run.
The evidential chain comes out stronger. A clip that only decrypts under registry keys carries an access story an investigator can state in one sentence: every readable copy of this footage passed through controlled decryption, logged at the platform with a case number. The event timestamps, the device identity and the alarm records ride inside the ciphertext with the video. SM3 adds the tamper line: a hash over each sealed clip, checked at decrypt, so an altered ciphertext fails loudly before any frame plays. The series’ local-first design held the evidence on the vehicle. The encryption holds it sealed as well as held.
The metadata stays readable by design, the one deliberate gap in the seal. Clip names, sizes, dates and the index the platform queries stay in clear on the card, because the stored-footage query has to find minutes by time and channel before any decrypt happens. The design seals the frames and leaves the catalogue open, the same split a sealed evidence locker keeps with its labels on the outside. The specification states the split so the physical-security review reads it as a decision.
The platform-side decrypt is a workflow, with a log as its product. An authorised reader opens a parcel or a pulled stretch through the platform interface, the platform fetches the device key from the registry, the decrypt runs server-side under the platform’s controls, the access lands in the audit log with reader, time and case number. The investigator receives playable video. The auditor receives a line. The fleet receives a chain it can recite at acceptance and in any later dispute, the same three-column readability every ledger in this series aims at.
The transit surface stops the outside listener. Interception on the radio path, the carrier middle or the public internet yields ciphertext, on any bearer, for live views and parcels alike. It does nothing against a compromised platform account, which reads decrypted video by design. Account discipline stays where the trade-off page put it, in the platform’s own access controls, with encryption guarding the path and accounts guarding the door, two controls with two owners.
The rest surface stops the card reader. A pulled card, a stolen vehicle, a depot break-in that nets a box of swapped cards: each yields sealed files. It does nothing against a party that controls the platform’s keys. It does not hide that recording happened, file sizes and dates being visible structure. The protection is precise: the video content itself stays sealed to anyone outside the key registry.
The honest list of what neither surface stops is short and stable. A compromised platform, a coerced credential, a camera pointed at the wrong thing, a terminal modified before commissioning. Each belongs to a different control: account governance, personnel process, installation review, supply-chain acceptance.
The campus network inherits the same posture without a special case. The wrapped session crosses the depot’s access points as ciphertext the way it crosses the carrier’s masts, so a misconfigured or borrowed access point yields nothing readable either. The depot segment isolation the campus page specifies stays in place as defence in depth. The encryption makes the segment’s compromise unproductive. The segmentation keeps the compromise inconvenient. Encryption carries the two surfaces it carries. The specification names them so nobody bills it for the rest.
The bench test measures the cost the arithmetic predicts. Run the standard recording duty with encryption off, then on, on the same vehicle and the same afternoon: processor load, frame completeness, write rate, supply current, case temperature, the same meters the codec and power pages read. The deltas at vehicle bitrates sit near the meters’ noise on hardware-engine terminals, the result that goes into acceptance as measured fact. A delta that is not near zero names a software fallback doing hardware’s job, the finding that reopens the datasheet.
The chain test proves the seal both ways. Pull a card from the test vehicle and confirm the clips read as ciphertext in an ordinary reader. Decrypt through the platform under a logged request and confirm the same clips play with timestamps intact. Intercept the test vehicle’s own session upstream of the platform and confirm ciphertext. Three reads, one afternoon, with the resume test from the recording page run once more over the encrypted path to confirm byte-offset recovery. The numbers and screenshots go into the acceptance file beside every other measured mechanism in this series.
The interoperability read closes the test set where two systems share evidence. A parcel decrypted at the fleet’s platform and forwarded to an insurer or a provincial system arrives as ordinary video with its chain log attached. A connection that hands ciphertext onward under shared-key arrangements gets tested against the receiving side’s reader once at docking. One test parcel, both directions where both exist, filed with the rest.
The cadence matches the rest of the series. Both tests run at acceptance, then after firmware updates, because cipher integration lives in firmware along with everything else that has moved under an update before. The key ledger gets its own quarterly read: rotations on schedule, revocations closed, commissioning rows matching the fleet list. Fifteen minutes a quarter keeps the cryptography a managed asset, on the same calendar the data review already owns.
The scope line names both surfaces in one sentence: video encrypted in transit and at rest under SM4, with SM2 and SM3 carrying handshake and integrity, on all bearers including the campus network. The hardware line names the engine and the secure element as datasheet items with throughput stated. The key line names custody: who generates, who injects, who holds the registry, who may decrypt, where the ledger lives. The acceptance line names the two tests above with their thresholds, re-run on the firmware cadence every mechanism page sets.
Each line carries a signature. The scope line is the security officer’s, the hardware line is procurement’s against the datasheet, the key line is the operations owner’s with the ledger location stated, the acceptance line is the technician’s with the file reference. Four signatures turn the cryptography from a vendor claim into the fleet’s own documented control, the form an assessment reads without a meeting.
The four lines close the question the campus page left open with its one-sentence pointer. Where the bytes flow was that page’s subject. That the bytes read as nothing to everyone outside the registry, wherever they flow and wherever they rest, is this one’s. A fleet that writes both pages’ lines has a monitoring system whose evidence is held, sealed and accountable, on paper a procurement office can sign.
Specify SM4 with the family around it, both surfaces, on all bearers the vehicle uses. Require the hardware engine and the secure element as named datasheet rows with throughput stated. Put the key ledger’s custody columns in the contract before the first terminal is commissioned. Run the bench deltas and the chain test at acceptance, with the resume test repeated over the encrypted path.
The fleet’s video then crosses public networks and sits on removable cards with the same standing in both places: sealed to everyone outside the registry, open to every authorised reader under a logged decrypt, at a running cost the bench meters cannot find. The mechanics of this series carry on underneath, unchanged and now wrapped.
SM4 is the block cipher of the Chinese national commercial cryptography family, standardised as GB/T 32907 in 2016 after serving as the commercial algorithm under GM/T 0002 since 2012, with earlier service under the SMS4 name before that. It encrypts 128-bit blocks under a 128-bit key across 32 rounds, the same size class as AES-128. It entered ISO/IEC 18033-3 by amendment in 2021, which gives export-touching fleets an international register to cite. SM2 handles public-key work and SM3 handles hashing in the same family, with SM4 carrying the bulk video volume between them. The family entered service together under the commercial cryptography administration’s standards, and terminals implement the three as one suite.
The regulated video ecosystem runs on it, by standard and by procurement. The public-security video networking standard GB 35114 builds on the SM family. Tenders in regulated transport classes name national-algorithm support as a required or scored line. The technical case matches: a modern 128-bit cipher with broad silicon support, doing AES-class bulk work at AES-class cost on the SoCs the terminal market already uses. The ISO listing since 2021 covers the export-touching paperwork as well, and the periodic cryptography assessments in regulated classes read a national-suite deployment off one page.
No, on hardware-engine terminals, and only marginally on software fallbacks. Vehicle recording runs at single-digit megabits per second. Software SM4 alone moves tens of megabytes per second on terminal-class processors. The hardware engine runs the cipher beside the encoder at line speed with the main cores untouched, inside the existing power and thermal budgets. The acceptance bench measures load, write rate, current and temperature with encryption off and on. The deltas sit near the meters’ noise on engine hardware, with a visible bump naming a software fallback doing silicon’s job.
The card yields sealed files. At-rest encryption writes clips as SM4 ciphertext, with the keys in the terminal’s secure element and the registry at the platform, neither of them on the card. The registry marks the stolen terminal’s keys dead, the platform refuses its sessions from that hour, the replacement arrives with fresh keys and a fresh commissioning row. The loss costs hardware. The footage stays sealed to whoever holds it, with the registry’s marking logged as part of the case record. Clip names and dates stay visible structure. The frames stay sealed.
No. The cipher stage sits inside the write path ahead of everything the storage design survives, so pre-allocated clips, flush cadence and power-loss behaviour carry over without redesign. Parcels queue and resume as ciphertext at byte offsets, the same mechanism the recording and campus pages rely on for holes and gates alike. The platform decrypts under its registry keys where the session terminates. Event times and device identity ride inside the ciphertext, so the record reads in order after decryption exactly as the recording pages promise. The catalogue the playback query searches stays readable by design.
A compromised platform account reads decrypted video by design, so account governance stays its own control with its own owner and its own review. A coerced credential, a mispointed camera and a terminal tampered before commissioning each belong to personnel, installation and supply-chain controls with their own owners. Encryption holds two surfaces, transit and rest, on every bearer the vehicle uses. The specification names them in one scope line so the remaining controls keep their own owners and budgets, with the decrypt log covering the accountable middle.