System and method for supporting court cross-network audio and video signaling two-way interaction

Through the multi-protocol access adaptation and security isolation module, combined with signaling conversion and identity authentication, the equipment compatibility and security risks in court cross-net audio and video communication are solved, stable and efficient remote judicial activities are achieved, and judicial convenience and security are improved.

CN120583075APending Publication Date: 2025-09-02南京通达海软件有限公司
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510729279.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-03
Publication Date
2025-09-02

AI Technical Summary

Technical Problem

The court has problems of network instability, poor equipment compatibility and data security risks in cross-network audio and video communications, which affect the normal progress of judicial activities.

Method used

Multi-protocol access adaptation module, security isolation module, signaling conversion module, signaling processing module and identity authentication and authorization module are adopted to realize device protocol compatibility, physical isolation and signaling security detection, combining multi-factor identity authentication and fine-grained authorization management.

Benefits of technology

It solves the equipment compatibility problem, improves the stability and security of audio and video communication, reduces travel costs, improves the convenience and efficiency of judicial services, and supports remote court trials and online mediation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120583075A_ABST
    Figure CN120583075A_ABST
Patent Text Reader

Abstract

The invention discloses a court cross-network audio and video signaling two-way interaction system and method. The system comprises a multi-protocol access adaptation module, a security isolation module and the like. The multi-protocol access adaptation module is provided with a special access adaptation unit for multiple protocols; the security isolation module realizes physical isolation through a security data exchange platform and a one-way audio and video optical shutter, and a built-in signaling security detection unit detects signaling; the signaling conversion module converts the signaling into an internal uniform format and adapts to the internal uniform format; the signaling processing module processes signaling, extracts information, schedules resources and feeds back a result; the network adaptation module adjusts transmission parameters; the identity authentication and authorization module uses multi-factor authentication and fine-grained authorization. The method comprises the steps of signaling initiating and receiving, identity authentication and authorization, multi-protocol access adaptation, signaling conversion processing and the like. The system solves the problems of cross-network communication protocol compatibility and the like, and improves the convenience and safety of judicial services.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of audio and video communications, and in particular to a system and method for supporting bidirectional interaction of court cross-network audio and video signaling. Background Art

[0002] With the development of social economy, people's pace of life has accelerated and their scope of activities has expanded. Parties may find it difficult to attend court hearings, mediation and other judicial activities on time due to being in different places or having poor health. The application of cross-network audio and video technology breaks the limitations of space and time, allowing parties to participate in litigation through the Internet without having to go to the court. This effectively solves problems such as "time difference" and "difficulty in being in different places", provides parties with more convenient and efficient judicial services, and meets the people's demand for convenient judicial services. Through remote court hearings and online mediation, some cases with clear facts and minor disputes can be handled quickly, easing the pressure on the courts, allowing judges to devote more energy to the trial of complex cases, and improving the quality of justice.

[0003] The application of cross-network audio and video technology in courts also faces the following challenges: there are differences in network infrastructure in different regions. Some remote areas or places with poor network conditions may experience network instability and insufficient bandwidth, resulting in audio and video freezes, delays or even interruptions, affecting the normal progress of judicial activities; courts may use a variety of devices of different brands and models for cross-network audio and video communications. These devices have compatibility issues, resulting in the inability to collect and play or blurred images and distorted sounds; the court's judicial data involves the privacy of the parties and the confidentiality of the case. Cross-network transmission carries the risk of data leakage, tampering or illegal acquisition. Summary of the Invention

[0004] The purpose of the present invention is to provide a system and method for supporting two-way interaction of audio and video signaling across networks in courts, so as to solve the problems raised in the above-mentioned background technology.

[0005] To achieve the above objectives, the present invention provides the following technical solutions: a court cross-network audio and video signaling two-way interactive system, comprising a multi-protocol access adaptation module, a security isolation module, a signaling conversion module, a signaling processing module, a network adaptation module, and an identity authentication and authorization module. The multi-protocol access adaptation module is used to respectively set up dedicated access adaptation units for various device terminal protocols of the court intranet and the Internet, including but not limited to RTSP access adaptation units, RTMP access adaptation units, SIP access adaptation units, WebRTC access adaptation units, H.323 access adaptation units, and GB28181 access adaptation units; The security isolation module uses a secure data exchange platform and two one-way audio and video optical switches to achieve physical isolation between the court's internal network and the external network, and has a built-in signaling security detection unit to perform real-time detection of audio and video signaling transmitted across the network; The signaling conversion module has multiple protocol conversion functions and signaling format adaptation functions, specifically used to convert signaling of different audio and video protocols into a unified format within the court, and adjust the signaling format according to different network environments and equipment requirements; The signaling processing module includes a signaling receiving submodule, a signaling analysis submodule, a signaling scheduling submodule, and a signaling feedback submodule, which are used to receive signaling, extract key information, schedule resources according to judicial rules, and feedback processing results to the initiator; The network adaptation module is used to automatically adjust signaling transmission parameters according to different network characteristics within the court; The identity authentication and authorization module adopts a multi-factor identity authentication mechanism, which includes but is not limited to user name and password, digital certificate, biometric recognition and SMS verification code, to strictly authenticate the identities of all parties involved in the communication and perform fine-grained authorization management based on different identity roles and business needs.

[0006] Preferably, the RTSP access adapter unit listens to RTSP requests on a designated port, parses RTSP messages, and maintains a reliable TCP connection; the RTMP access adapter unit processes the RTMP handshake and connection establishment process, parses RTMP command messages and data messages, and processes block streams; the SIP access adapter unit listens to UDP and TCP ports simultaneously, parses SIP request and response messages, and manages SIP transactions; the WebRTC access adapter unit assists in establishing a signaling channel, processes ICE negotiation-related information, and ensures a DTLS secure connection; the H.323 access adapter unit is responsible for device registration and authentication, processes call control messages, and coordinates media control with the H.245 protocol; the GB28181 access adapter unit manages device access, parses GB28181 signaling messages, and coordinates media stream transmission.

[0007] Preferably, the signaling security detection unit performs legality, integrity and security detection on audio and video signaling transmitted across the network, intercepts unqualified signaling, generates an alarm and records information.

[0008] Preferably, the signaling security detection unit specifically implements the following steps: Signaling Capture: Probes are deployed in the one-way optical switch between the court's intranet and the internet to capture all audio and video signaling transmitted across the network in real time. Signaling flows from the internet to the court's intranet and from the court's intranet to the internet are monitored simultaneously, and the system supports the identification and analysis of multiple audio and video protocols, including but not limited to SIP, RTSP, and WebRTC. Legality Check: Checks whether the signaling conforms to the standard protocol format and verifies whether the signaling contains the required fields specified by the court. Confirms whether the protocol version used in the signaling is within the scope permitted by the court, rejects the use of unverified protocol extensions, and checks whether the signaling type complies with judicial procedures. Integrity check: Calculate the hash value of the signaling content and compare it with the hash value provided by the sender to ensure that the data has not been tampered with during transmission. For signaling transmitted in blocks, verify the continuity of the block sequence number to prevent data loss or replay attacks. Then, associate the signaling with the session identifier, check whether the signaling sequence conforms to the protocol state machine, and verify whether the audio and video parameters in the signaling are consistent with the previous negotiation. Security Detection: Based on a pre-set threat signature library, the system scans signaling for malicious code snippets and detects abnormal IP addresses or port numbers. It uses machine learning models to identify abnormal signaling behavior and check whether the operational permissions in the signaling match the user role. It also scans signaling for sensitive judicial data. Security response: The signaling security detection unit combines the results of the legitimacy test and integrity test to comprehensively determine the risk level. Based on the type and severity of the detected problem, the risk level is mapped to the preset high, medium, and low risk levels. The corresponding interception and feedback measures are then called from the response strategy corresponding to the preset risk level. Audit and tracking: Record the signaling source IP, destination IP, protocol type, and detected security issues in the detection results of the security response, and organize them into alert information; Linkage mechanism: When the signaling security detection unit detects high-risk signaling, the security isolation module temporarily closes the optical gate channel in the corresponding direction to prevent the spread of the attack; when the signaling security detection unit detects user signaling that fails identity authentication, the identity authentication module directly intercepts it without the need for subsequent testing; when the signaling security detection unit detects qualified signaling, it adds a security tag to it, and the signaling processing module gives priority to high-security signaling.

[0009] Preferably, the signaling receiving submodule receives signaling data packets from different protocols by monitoring multiple network ports, and simultaneously processes multiple signaling requests from different sources; the signaling analysis submodule extracts key information from the received signaling, wherein the key information includes but is not limited to the source address and destination address of the signaling, the signaling type, audio and video parameters, and additional information related to judicial business; the signaling scheduling submodule reasonably schedules the signaling according to the results of the signaling analysis and the judicial business rules of the court, obtains appropriate trial lines and equipment allocation according to resource conditions, establishes or adjusts audio and video communication links, and passes relevant parameter setting information to the signaling feedback submodule; the signaling feedback submodule feeds back the results of the signaling processing to the signaling initiator in a signaling format, wherein the feedback content includes but is not limited to whether the signaling request is successfully processed, detailed information on the processing results, and prompts for subsequent operations.

[0010] Preferably, the signaling scheduling submodule specifically implements the logic as follows: Construct a comprehensive scheduling objective function to maximize the overall satisfaction , balancing business needs, service quality and resource costs: ,in is the weight coefficient, and , is the fitness function, which depends on the source , destination and business information , is the quality of service function, which depends on resource allocation and parameter configuration , is the resource cost function; the fitness function, service quality function and resource cost function are explained below respectively; The service adaptability function evaluates whether the signaling complies with the judicial process. Specifically: ,in is the role suitability, defined as: , For case suitability, based on the standard resource requirements of case types: ,in To actually allocate resources, Require resources for standards; is a time-dependent function that decays over time: ,in is the time sensitivity parameter; The quality of service function ensures the smoothness of the trial video through bandwidth satisfaction rate and jitter control. ,in is the sub-item weight, and , is the bandwidth satisfaction rate, To allocate bandwidth, To request bandwidth; is the jitter ratio, For actual jitter, is the threshold, Adjust parameters for the curve; The resource cost function calculates the number of server instances and storage capacity used to avoid resource waste. ,in For the Unit cost of class resources, For the Class resource allocation, is the storage cost coefficient; The key information extracted by the signaling analysis submodule is then input into the comprehensive scheduling objective function to generate appropriate courtroom lines and equipment allocations, and to establish or adjust audio and video communication links.

[0011] Preferably, a bidirectional interactive method of court cross-network audio and video signaling is characterized by comprising the following steps: Step 1: Signaling initiation and reception: Internal or external users of the court initiate audio and video signaling requests through specific audio and video application terminals. The signaling requests contain the source and target identification information, the signaling type, and necessary audio and video parameter information. The network adaptation module first receives the signaling request, determines the transmission direction and network type of the signaling based on the source and target addresses of the signaling, performs a preliminary format check and network parameter adaptation adjustment on the signaling, and then transmits the signaling to the identity authentication and authorization module. Step 2: Identity authentication and authorization: After receiving the signaling, the identity authentication and authorization module extracts the identity information in the signaling and processes it according to the preset authentication process and authorization rules. If the identity authentication fails, it directly generates an authentication failure signaling feedback to the signaling initiator and records the relevant information; if the identity authentication succeeds and the signaling initiator has the corresponding authorization, the signaling is transmitted to the security isolation module; Step 3: Multi-protocol access adaptation: When a signaling request is initiated by internal or external clients of the court using different terminals or devices, after identity authentication, the multi-protocol access adaptation module parses the message content according to the dedicated access adaptation module for each terminal protocol and transmits the signaling to the signaling conversion module; Step 4: Signaling conversion and processing: The signaling conversion module, after receiving the parsed formatted message, converts it into an internal unified data format; the signaling receiving submodule of the signaling processing module receives the signaling, and the signaling analysis submodule analyzes it and extracts key information; the signaling scheduling submodule performs signaling scheduling operations based on the analysis results and judicial business rules; The signaling feedback submodule generates feedback signaling from the signaling processing results. Following the reverse path of the signaling initiation, it passes through the signaling conversion module, the identity authentication and authorization module, and the network adaptation module in sequence, and finally sends the feedback signaling back to the signaling initiator; The signaling initiator performs corresponding operations based on the content of the feedback signaling; when a signaling request that requires cross-network transmission is parsed, the signaling is transmitted to the security isolation module.

[0012] Compared with the prior art, the present invention has the following beneficial effects: Full-protocol access adaptation solves the problem of device fragmentation: By deploying protocol access adaptation units such as RTSP, RTMP, SIP, and WebRTC, the system can be compatible with professional courtroom equipment (such as RTSP cameras, GB28181 monitoring) and Internet terminals (such as WebRTC browsers and RTMP applets) on the court's intranet, solving the problem of device intercommunication caused by protocol incompatibility in traditional systems; the signaling conversion module converts signaling from different protocols into the court's internal format, and adjusts parameters according to the network environment.

[0013] Dual protection of physical isolation and signaling detection: The security isolation module uses two one-way optical switches and a secure data exchange platform to achieve physical isolation between the intranet and the Internet, complying with the FYB_T_53001 standard. The signaling security detection unit monitors the legitimacy, integrity, and security of signaling in real time. High-risk signaling (such as those containing SQL injection instructions) is immediately intercepted and the optical switch channel is closed. Medium-risk signaling (such as format errors) is returned and recorded with an error response. Low-risk signaling (such as resolution mismatch) is automatically corrected and released. Multi-objective algorithms improve resource utilization: The signaling scheduling submodule balances service adaptability, QoS, and resource costs through a comprehensive scheduling objective function, while the network adaptation module dynamically adjusts transmission parameters based on bandwidth, latency, and other characteristics. Intranets use a high verification frequency to ensure data accuracy, while internet environments automatically reduce resolution and enable redundant transmission. Role-based authorization control ensures the boundaries of business permissions: Different signaling operation permissions are assigned to different roles, such as judges, parties, and clerks. Judges can control the trial process, parties can only operate audio and video equipment, and clerks can manage and record signaling. This mechanism prevents unauthorized operations.

[0014] Breaking spatial limitations and enabling remote litigation: Parties can participate in court hearings via the internet, eliminating the need to travel back and forth to the court, thus reducing travel costs. The time cost of participating in court hearings in remote areas has been reduced from traditional methods to online methods, significantly improving judicial convenience. Furthermore, the system supports parallel scheduling of trial signals for multiple cases, allowing judges to handle remote mediation for 3-5 simple cases simultaneously, improving case handling efficiency and allowing judges to focus more on hearing complex cases. Through multi-protocol integration, multi-layer security protection, intelligent resource scheduling and deep adaptation of judicial services, this invention solves the problems of protocol compatibility, security risks, resource waste and so on in the cross-network audio and video communications of courts, and significantly improves the stability, security and efficiency of services such as remote trials and online mediation, providing technical support for the construction of smart courts. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 Schematic diagram of the system structure of the present invention; Figure 2 A schematic diagram of a two-way audio and video data transmission application mode of the present invention; Figure 3 Schematic diagram of the signaling interaction process between the Internet and the court intranet of the present invention; Figure 4 This is a working logic diagram of the signaling security detection unit of the present invention; Figure 5 Schematic diagram of the method of the present invention. DETAILED DESCRIPTION

[0016] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0017] Example 1 See also Figure 1-4The present invention provides a technical solution: a court cross-network audio and video signaling two-way interactive system, including a multi-protocol access adaptation module, a security isolation module, a signaling conversion module, a signaling processing module, a network adaptation module and an identity authentication and authorization module. The multi-protocol access adaptation module is used to set up special access adaptation units for various device terminal protocols of the court intranet and the Internet, including but not limited to RTSP access adaptation unit, RTMP access adaptation unit, SIP access adaptation unit, WebRTC access adaptation unit, H.323 access adaptation unit and GB28181 access adaptation unit; the specific RTSP access adaptation unit listens for RTSP requests on a designated port, parses RTSP messages, and maintains The RTMP access adapter unit handles the RTMP handshake and connection establishment process, parses RTMP command messages and data messages, and processes block streams; the SIP access adapter unit monitors UDP and TCP ports at the same time, parses SIP request and response messages, and manages SIP transactions; the WebRTC access adapter unit assists in establishing signaling channels, processes ICE negotiation-related information, and ensures DTLS secure connections; the H.323 access adapter unit is responsible for device registration and authentication, processes call control messages, and coordinates media control with the H.245 protocol; the GB28181 access adapter unit manages device access, parses GB28181 signaling messages, and coordinates media stream transmission.

[0018] The security isolation module uses a secure data exchange platform and two one-way audio and video optical switches to achieve physical isolation between the court's intranet and the external network. Specifically, it complies with FYB_T_53001-2020 "Requirements for the Construction of Security Isolation and Information Exchange Platforms", and uses a secure data exchange platform and two one-way audio and video optical switches to achieve physical isolation between the court's intranet and the Internet. The audio and video optical switch physically switches the electrical connection between the internal and external networks and uses optical signals for data transmission. During a single transmission, access rules can be set according to the network security level. For example, when the court's intranet transmits signals to the Internet, it must undergo strict security review and filtering to prevent the leakage of sensitive information; when the Internet transmits signals to the court's intranet, only specific types of response signals are allowed to enter, and multiple security processes such as virus detection and content compliance checks are required.

[0019] Follow the two-way audio and video data transmission application mode in FYB_T_59006-2020 "Security Isolation and Information Exchange Platform Use and Management Requirements" ( Figure 2The court's intranet and external network use the SIP protocol (compliant with GB / T28181) for two-way interaction between audio and video services and the court's intranet. The streaming interface is only open for business interactions, and no ports are open to the outside world during non-business transmissions, ensuring the security of business interactions. A built-in signaling security detection unit performs real-time detection of audio and video signaling transmitted across networks. It should also be noted that the security isolation module complies with GB / T 20279-2006 "Information Security Technology Network and Terminal Isolation Product Technical Requirements" and GB / T 20275-2006 "Information Security Technology Intrusion Detection System Technical Requirements and Test Evaluation Methods" standards; the signaling security detection unit performs legality, integrity and security detection on audio and video signaling transmitted across the network, intercepts unqualified signaling, generates alarms and records information; the specific implementation steps of the signaling security detection unit are as follows (such as Figure 4 ): Signaling Capture: Probes are deployed in the one-way optical switch between the court's intranet and the internet to capture all audio and video signaling transmitted across the network in real time. Signaling flows from the internet to the court's intranet and from the court's intranet to the internet are monitored simultaneously, and the system supports the identification and analysis of multiple audio and video protocols, including but not limited to SIP, RTSP, and WebRTC. Legality Check: Checks whether the signaling conforms to the standard protocol format and verifies whether the signaling contains the required fields specified by the court. Confirms whether the protocol version used in the signaling is within the scope permitted by the court, rejects the use of unverified protocol extensions, and checks whether the signaling type complies with judicial procedures. Integrity check: Calculate the hash value of the signaling content and compare it with the hash value provided by the sender to ensure that the data has not been tampered with during transmission. For signaling transmitted in blocks, verify the continuity of the block sequence number to prevent data loss or replay attacks. Then, associate the signaling with the session identifier, check whether the signaling sequence conforms to the protocol state machine, and verify whether the audio and video parameters in the signaling are consistent with the previous negotiation. Security Detection: Based on a pre-set threat signature library, the system scans signaling for malicious code snippets and detects abnormal IP addresses or port numbers. It uses machine learning models to identify abnormal signaling behavior and check whether the operational permissions in the signaling match the user role. It also scans signaling for sensitive judicial data. Security response: The signaling security detection unit combines the results of the legitimacy test and integrity test to comprehensively determine the risk level. Based on the type and severity of the detected problem, the risk level is mapped to the preset high, medium, and low risk levels. The corresponding interception and feedback measures are then called from the response strategy corresponding to the preset risk level. The following are examples of risk classification standards and response strategies based on specific actual situations: 1. High-risk signaling (immediate interception): Classification standards: Threats to judicial data security: including risks of malicious code, viruses, illegal instructions or sensitive information leakage; Damage to system stability: signaling that may lead to service denial, resource exhaustion or excessive authority; Violation of the bottom line of judicial procedures: such as unauthenticated users initiating trial control instructions, cross-network violations (the Internet actively initiating INVITE requests).

[0020] Response Strategy: Signaling Processing: Immediately discard the signaling and terminate the current communication connection (e.g., disconnect the SIP session, close the RTSP stream). Clear all session states associated with the signaling (e.g., delete ICE candidate information). Security Interaction: Trigger the security isolation module to temporarily close the corresponding optical gate channel (for 5-10 minutes). Send a red alert to the security management system, including the complete (decrypted) content of the signaling.

[0021] 2. Medium-risk signaling (rejection and feedback): Classification criteria: Protocol format violation: The signaling format does not comply with standard protocols or court-defined rules, but does not contain malicious content. Permission boundary violation: The user's operation permissions do not match the role, but does not pose a substantial security threat (for example, a party attempts to adjust the parameters of the trial video). Process sequence error: The signaling interaction sequence violates the protocol state machine (for example, receiving ACK before INVITE in SIP).

[0022] Response Strategy: Signaling Processing: Reject the signaling and return a protocol-specific error response (e.g., 400 BadRequest for SIP, 403 Forbidden for RTSP). The error cause should be clearly stated in the response message (e.g., "Missing Call-ID header"). Security Logging: Record warning-level logs containing signaling snippets, error type, and timestamps. Send a yellow alert to operations personnel, alerting them to potential protocol compatibility issues.

[0023] 3. Low-risk signaling (release after correction): Classification criteria: Parameter adaptation issue: Signaling parameters (such as resolution and bit rate) do not match the current network environment or device capabilities, but do not pose a security threat. Non-critical format defect: Signaling contains format errors in optional fields (such as redundant spaces), which do not affect protocol parsing. Minor resource conflict: Requested resources (such as bandwidth) approach but do not exceed the system's carrying capacity.

[0024] Response Strategy: Signaling Correction: Automatically adjust parameters to compatible ranges (e.g., reducing 1080p resolution to 720p and bitrate from 4Mbps to 2.5Mbps). Complete missing non-mandatory fields (e.g., adding the standard SIP header "Via: SIP / 2.0 / UDP"). Release and Monitoring: Forward the corrected signaling to the target network with the "X-Corrected: True" tag. Record information-level logs to monitor whether subsequent interactions with the corrected signaling are normal.

[0025] Audit and tracking: Record the signaling source IP, destination IP, protocol type, and detected security issues in the detection results of the security response, and organize them into alert information; Linkage mechanism: When the signaling security detection unit detects high-risk signaling, the security isolation module temporarily closes the optical gate channel in the corresponding direction to prevent the spread of the attack; when the signaling security detection unit detects user signaling that fails identity authentication, the identity authentication module directly intercepts it without the need for subsequent testing; when the signaling security detection unit detects qualified signaling, it adds a security tag to it, and the signaling processing module gives priority to high-security signaling.

[0026] The signaling conversion module has multiple protocol conversion functions and signaling format adaptation functions. It is specifically used to convert signaling of different audio and video protocols into a unified format within the court, and adjust the signaling format according to different network environments and equipment requirements; The signaling processing module includes a signaling receiving submodule, a signaling analysis submodule, a signaling scheduling submodule, and a signaling feedback submodule, which are used to receive signaling, extract key information, schedule resources according to judicial rules, and feedback processing results to the initiator; The signaling receiving submodule receives signaling data packets from different protocols by monitoring multiple network ports, and simultaneously processes multiple signaling requests from different sources; the signaling analysis submodule extracts key information from the received signaling, wherein the key information includes but is not limited to the source address and destination address of the signaling, the signaling type, audio and video parameters, and additional information related to judicial business; the signaling scheduling submodule reasonably schedules the signaling based on the results of the signaling analysis and the judicial business rules of the court, obtains appropriate trial lines and equipment allocation based on resource conditions, establishes or adjusts audio and video communication links, and passes relevant parameter setting information to the signaling feedback submodule; the signaling feedback submodule feeds back the results of the signaling processing to the signaling initiator in a signaling format, wherein the feedback content includes but is not limited to whether the signaling request is successfully processed, detailed information on the processing results, and prompts for subsequent operations; It should be specifically noted that the resources described above include but are not limited to network communication resources, computing and storage resources, audio and video media resources and judicial business resources; network communication resources specifically include: bandwidth resources: network bandwidth capacity for transmitting audio and video data (unit: Mbps / Kbps), for example, allocating 2.8Mbps bandwidth for remote court trial video streaming; network link: transmission channel between different security domains (such as a one-way optical switch link between the court intranet and the Internet), which must meet security isolation requirements; IP address and port: network identification and data transmission port of the communication terminal (such as the public IP and RTSP service port 554 of the court trial server); computing and storage resources include: server / computing power resources: physical / virtual servers (such as the "court-server-01" instance) used to process audio and video encoding and signaling scheduling, and CPU load, memory usage, etc., need to be considered; storage resources: storage space (unit: GB) used to cache audio and video data and case records, For example, a 1024GB storage quota is reserved for major cases; audio and video media resources specifically include: encoding and decoding resources: the processing capacity of audio and video codecs (such as H.264, OPUS), which needs to adapt to the encoding format requirements of different terminals; media stream channels: independent data stream channels used to transmit audio and video (such as RTP / RTCP media stream channels), which need to ensure real-time and synchronization; judicial business resources specifically include trial resources: the online status of judges, clerks and other roles, the occupancy of the trial room (such as whether "Court No. 2" is idle), case-related resources: case-related permission configuration, data access permission (such as only allowing judges to access case evidence materials).

[0027] The specific implementation logic of the signaling scheduling submodule is as follows: Construct a comprehensive scheduling objective function to maximize the overall satisfaction , balancing business needs, service quality and resource costs: ,in is the weight coefficient, and , is the fitness function, which depends on the source , destination and business information , is the quality of service function, which depends on resource allocation and parameter configuration , is the resource cost function; the fitness function, service quality function and resource cost function are explained below respectively; The service adaptability function evaluates whether the signaling complies with the judicial process. Specifically: ,in is the role suitability, defined as: , For case suitability, based on the standard resource requirements of case types: ,in To actually allocate resources, Require resources for standards; is a time-dependent function that decays over time: ,in is the time sensitivity parameter; The quality of service function ensures the smoothness of the trial video through bandwidth satisfaction rate and jitter control. ,in is the sub-item weight, and , is the bandwidth satisfaction rate, To allocate bandwidth, To request bandwidth; is the jitter ratio, For actual jitter, is the threshold, Adjust parameters for the curve; The resource cost function calculates the number of server instances and storage capacity used to avoid resource waste. ,in For the Unit cost of class resources, For the Class resource allocation, is the storage cost coefficient; The key information extracted by the signaling analysis submodule is then input into the comprehensive scheduling objective function to generate appropriate courtroom lines and equipment allocations, and to establish or adjust audio and video communication links.

[0028] The network adaptation module is used to automatically adjust signaling transmission parameters according to the different network characteristics within the court. In the court's intranet, due to the high requirements for data security and stability, the network adaptation unit can appropriately reduce the transmission speed and increase the number of data verifications to ensure the accuracy of signaling transmission. In the internal office network, while ensuring security, the signaling transmission rate can be flexibly adjusted according to the network load to improve communication efficiency.

[0029] The identity authentication and authorization module adopts a multi-factor identity authentication mechanism, which includes but is not limited to username and password, digital certificate, biometric recognition and SMS verification code, to strictly authenticate the identities of all parties involved in the communication and perform fine-grained authorization management based on different identity roles and business needs; It's important to note that the identity authentication and authorization module strictly authenticates all parties involved in the court's cross-network audio and video communications. For example, when logging into the remote trial system, judges are required to enter their username and password, verify their biometrics using a fingerprint recognition device, and receive a text message verification code for secondary confirmation. Only after all authentication factors are verified are they allowed to participate in audio and video communications and initiate related signaling operations. Fine-grained authorization management is implemented based on different identity roles and judicial business needs. For example, during a trial, judges are authorized to control signaling operations such as pausing, resuming, and ending the trial, while parties are only authorized to perform signaling operations such as turning audio and video on and off and presenting evidence. Clerks are authorized to record the trial, record signaling, and manage it. This authorization management mechanism ensures that users with different identities can only interact with each other within their authorized scope, preventing unauthorized operations and illegal access to judicial data.

[0030] The following describes a specific example: In a remote court hearing scenario, a party located remotely accesses the court's remote hearing client via the internet. After entering their username and password and completing identity verification via SMS text message verification, they select the corresponding case number in the client and initiate a video call signaling request. This signaling request includes the party's identity information, case number, the number of the target hearing judge, and the desired video resolution (e.g., 720p) and audio encoding format (e.g., AAC).

[0031] After receiving the signaling request, the network adapter module determines that it originates from the external internet and is destined for the trial network. It performs a preliminary format check and adjusts network parameters before transmitting the signaling to the identity authentication and authorization module. The module verifies the identity information and authorization status of the parties involved and, upon confirmation, transmits the signaling to the security isolation module.

[0032] The security isolation module performs security checks on signaling, including virus detection, signaling legitimacy, and integrity checks. If the signaling passes these checks, it is transmitted to the signaling conversion module. This module converts the signaling into the court's internally standardized signaling format, adapts the format to the requirements of the trial network, and then transmits the converted signaling to the signaling processing center.

[0033] The signaling processing module's signaling reception submodule receives the signaling, and the signaling analysis submodule extracts key information, such as the signaling type being a video call request, the source address being the client of the party involved, and the destination address being the judge's terminal. The signaling scheduling submodule checks the current court resources and, upon discovering that the judge is online and the courtroom is idle, allocates audio and video resources, establishes a video connection between the party involved and the judge, and sets parameters such as video resolution to 720p and audio encoding format to AAC.

[0034] The signaling feedback submodule generates a successful connection feedback signal, which is then processed and transmitted through each module in reverse order. Ultimately, the client receives the successful connection feedback signal, allowing the parties to enter the remote hearing interface and begin audio and video communication and interaction during the trial. Throughout the trial, operational signals from all parties (such as pausing the video, switching audio devices, and presenting evidence) are accurately transmitted and processed across different networks according to the aforementioned signaling interaction method, ensuring the smooth progress of the remote trial.

[0035] Example 2 like Figure 5 A bidirectional interactive method for court cross-network audio and video signaling includes the following steps: Step 1. Signaling initiation and reception: Internal or external users of the court initiate audio and video signaling requests through specific audio and video application terminals. The signaling request contains the source's identity information (such as user account, digital certificate, etc.), the target's identification information (such as the court's internal department code, judge number, trial room number, etc.), the signaling type (such as call request, data transmission request, status query request, etc.) and necessary audio and video parameter information (such as the desired video resolution, audio encoding format, etc.); the network adaptation module first receives the signaling request, determines the transmission direction and network type of the signaling based on the source address and target address of the signaling, performs a preliminary format check and network parameter adaptation adjustment on the signaling, and then transmits the signaling to the identity authentication and authorization module; Step 2: Identity Authentication and Authorization: After receiving the signaling, the identity authentication and authorization module extracts the identity information in the signaling and processes it according to the preset authentication process and authorization rules. If the identity authentication fails, it directly generates an authentication failure signaling feedback to the signaling initiator and records the relevant information; if the identity authentication succeeds and the signaling initiator has the corresponding authorization, the signaling is transmitted to the security isolation module; Step 3: Multi-protocol access adaptation: When a signaling request is initiated by internal or external clients of the court using different terminals or devices, after identity authentication, the multi-protocol access adaptation module parses the message content according to the dedicated access adaptation module for each terminal protocol and transmits the signaling to the signaling conversion module; Step 4: Signaling conversion and processing: The signaling conversion module, after receiving the parsed formatted message, converts it into an internal unified data format; the signaling receiving submodule of the signaling processing module receives the signaling, and the signaling analysis submodule analyzes it and extracts key information; the signaling scheduling submodule performs signaling scheduling operations based on the analysis results and judicial business rules; The signaling feedback submodule generates feedback signaling from the signaling processing results. Following the reverse path of the signaling initiation, it passes through the signaling conversion module (which converts the feedback signaling into a format suitable for the source network), the identity authentication and authorization module (which performs necessary identity authentication and authorization checks), and the network adaptation unit (which adjusts network parameters and transmits them). Finally, the feedback signaling is sent back to the signaling initiator. The signaling initiator performs corresponding operations based on the content of the feedback signaling; when a signaling request that requires cross-network transmission is parsed, the signaling is transmitted to the security isolation module.

[0036] The present invention discloses a court cross-network audio and video signaling two-way interactive system and method thereof, which aims to solve the protocol compatibility, security isolation and resource scheduling problems of audio and video communication in the court cross-network environment. The system includes a multi-protocol access adaptation module, a security isolation module, a signaling conversion module, a signaling processing module, a network adaptation module and an identity authentication and authorization module. Among them, the multi-protocol access adaptation module supports unified access of protocols such as RTSP, SIP, WebRTC, etc.; the security isolation module adopts a one-way audio and video optical gate and a signaling security detection unit to achieve physical isolation and signaling legality, integrity, and security detection; the signaling processing module balances business adaptability, service quality and resource cost through a comprehensive scheduling objective function; the identity authentication and authorization module adopts a multi-factor authentication mechanism and fine-grained authority management.

[0037] The interaction method includes signaling initiation and reception, identity authentication, multi-protocol adaptation, signaling conversion processing, and security isolation. Dynamic adjustment of audio and video parameters and resource allocation ensures efficient cross-network signaling transmission. The system supports judicial scenarios such as remote trials and online mediation, addressing issues such as network instability, poor device compatibility, and data security risks. It improves the convenience and security of judicial operations and provides technical support for the development of smart courts.

[0038] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. A court cross-network audio and video signaling two-way interactive system, comprising a multi-protocol access adaptation module, a security isolation module, a signaling conversion module, a signaling processing module, a network adaptation module, and an identity authentication and authorization module, characterized by: The multi-protocol access adaptation module is used to set up special access adaptation units for various device terminal protocols of the court intranet and the Internet, including but not limited to RTSP access adaptation unit, RTMP access adaptation unit, SIP access adaptation unit, WebRTC access adaptation unit, H.323 access adaptation unit and GB28181 access adaptation unit; The security isolation module uses a secure data exchange platform and two one-way audio and video optical switches to achieve physical isolation between the court's internal network and the external network, and has a built-in signaling security detection unit to perform real-time detection of audio and video signaling transmitted across the network; The signaling conversion module has multiple protocol conversion functions and signaling format adaptation functions, specifically used to convert signaling of different audio and video protocols into a unified format within the court, and adjust the signaling format according to different network environments and equipment requirements; The signaling processing module includes a signaling receiving submodule, a signaling analysis submodule, a signaling scheduling submodule, and a signaling feedback submodule, which are used to receive signaling, extract key information, schedule resources according to judicial rules, and feedback processing results to the initiator; The network adaptation module is used to automatically adjust signaling transmission parameters according to different network characteristics within the court; The identity authentication and authorization module adopts a multi-factor identity authentication mechanism, which includes but is not limited to user name and password, digital certificate, biometric recognition and SMS verification code, to strictly authenticate the identities of all parties involved in the communication and perform fine-grained authorization management based on different identity roles and business needs.

2. A court cross-network audio and video signaling two-way interactive system according to claim 1, characterized in that: The RTSP access adapter unit listens to RTSP requests on a designated port, parses RTSP messages, and maintains a reliable TCP connection; the RTMP access adapter unit handles the RTMP handshake and connection establishment process, parses RTMP command messages and data messages, and processes block streams; the SIP access adapter unit listens to both UDP and TCP ports, parses SIP request and response messages, and manages SIP transactions; the WebRTC access adapter unit assists in establishing a signaling channel, processes ICE negotiation-related information, and ensures a DTLS secure connection; the H.323 access adapter unit is responsible for device registration and authentication, processes call control messages, and coordinates media control with the H.245 protocol; the GB28181 access adapter unit manages device access, parses GB28181 signaling messages, and coordinates media stream transmission.

3. The court cross-network audio and video signaling two-way interactive system according to claim 1 is characterized by: The signaling security detection unit performs legality, integrity and security detection on audio and video signaling transmitted across the network, intercepts unqualified signaling, generates alarms and records information.

4. The court cross-network audio and video signaling two-way interactive system according to claim 1 is characterized by: The signaling security detection unit specifically implements the following steps: Signaling Capture: Probes are deployed in the one-way optical switch between the court's intranet and the internet to capture all audio and video signaling transmitted across the network in real time. Signaling flows from the internet to the court's intranet and from the court's intranet to the internet are monitored simultaneously, and the system supports the identification and analysis of multiple audio and video protocols, including but not limited to SIP, RTSP, and WebRTC. Legality Check: Checks whether the signaling conforms to the standard protocol format and verifies whether the signaling contains the required fields specified by the court. Confirms whether the protocol version used in the signaling is within the scope permitted by the court, rejects the use of unverified protocol extensions, and checks whether the signaling type complies with judicial procedures. Integrity check: Calculate the hash value of the signaling content and compare it with the hash value provided by the sender to ensure that the data has not been tampered with during transmission; for signaling transmitted in blocks, verify the continuity of the block sequence number to prevent data loss or replay attacks; Then, the signaling is correlated through the session identifier, the signaling sequence is checked to see if it complies with the protocol state machine, and the audio and video parameters in the signaling are verified to be consistent with the previous negotiation; Security Detection: Based on a pre-set threat signature library, the system scans signaling for malicious code snippets and detects abnormal IP addresses or port numbers. It uses machine learning models to identify abnormal signaling behavior and check whether the operational permissions in the signaling match the user role. It also scans signaling for sensitive judicial data. Security response: The signaling security detection unit combines the results of the legitimacy test and integrity test to comprehensively determine the risk level. The risk level is mapped to the preset high, medium, and low risk levels based on the type and severity of the detected problem. Then, the corresponding interception and feedback measures are retrieved from the response strategy corresponding to the preset risk level; Audit and tracking: Record the signaling source IP, destination IP, protocol type, and detected security issues in the detection results of the security response, and organize them into alert information; Linkage mechanism: When the signaling security detection unit detects high-risk signaling, the security isolation module temporarily closes the optical gate channel in the corresponding direction to prevent the attack from spreading; When the signaling security detection unit detects user signaling that fails identity authentication, the identity authentication module directly intercepts it without the need for subsequent detection; when the signaling security detection unit detects qualified signaling, it adds a security tag to it, and the signaling processing module gives priority to high-security signaling.

5. The court cross-network audio and video signaling two-way interactive system according to claim 1 is characterized by: The signaling receiving submodule receives signaling data packets from different protocols by monitoring multiple network ports and processes multiple signaling requests from different sources at the same time; The signaling analysis submodule extracts key information from the received signaling, wherein the key information includes but is not limited to the source address and destination address of the signaling, the signaling type, audio and video parameters, and additional information related to judicial business; The signaling scheduling submodule rationally schedules signaling based on the results of signaling analysis and the court's judicial business rules, obtains appropriate courtroom circuit and equipment allocation based on resource conditions, establishes or adjusts audio and video communication links, and transmits relevant parameter setting information to the signaling feedback submodule; The signaling feedback submodule feeds back the signaling processing result to the signaling initiator in a signaling format, wherein the feedback content includes but is not limited to whether the signaling request is successfully processed, detailed information of the processing result, and subsequent operation prompts.

6. A court cross-network audio and video signaling two-way interactive system according to claim 5, characterized in that: The specific implementation logic of the signaling scheduling submodule is as follows: Construct a comprehensive scheduling objective function to maximize the overall satisfaction , balancing business needs, service quality and resource costs: ,in is the weight coefficient, and , is the fitness function, which depends on the source , destination and business information , is the quality of service function, which depends on resource allocation and parameter configuration , is the resource cost function; the fitness function, service quality function and resource cost function are explained below respectively; The service adaptability function evaluates whether the signaling complies with the judicial process. Specifically: ,in is the role suitability, defined as: , For case suitability, based on the standard resource requirements of case types: ,in To actually allocate resources, Require resources for standards; is a time-dependent function that decays over time: ,in is the time sensitivity parameter; The quality of service function ensures the smoothness of the trial video through bandwidth satisfaction rate and jitter control. ,in is the sub-item weight, and , is the bandwidth satisfaction rate, To allocate bandwidth, To request bandwidth; is the jitter ratio, For actual jitter, is the threshold, Adjust parameters for the curve; The resource cost function calculates the number of server instances and storage capacity used to avoid resource waste. ,in For the Unit cost of class resources, For the Class resource allocation, is the storage cost coefficient; The key information extracted by the signaling analysis submodule is then input into the comprehensive scheduling objective function to generate appropriate courtroom lines and equipment allocations, and to establish or adjust audio and video communication links.

7. A two-way interactive method for court cross-network audio and video signaling according to any one of claims 1 to 6, characterized in that: The following steps are involved: Step 1: Signaling initiation and reception: A user inside or outside the court initiates an audio or video signaling request through a specific audio or video application terminal. The signaling request contains the source end's identity information, the target end's identity information, the signaling type, and necessary audio or video parameter information; The network adaptation module first receives the signaling request, determines the transmission direction and network type of the signaling based on the source and destination addresses of the signaling, performs a preliminary format check and network parameter adaptation adjustment on the signaling, and then transmits the signaling to the identity authentication and authorization module; Step 2: Identity authentication and authorization: After receiving the signaling, the identity authentication and authorization module extracts the identity information in the signaling and processes it according to the preset authentication process and authorization rules. If the identity authentication fails, it directly generates an authentication failure signaling feedback to the signaling initiator and records the relevant information; If the identity authentication is successful and the signaling initiator has the corresponding authorization, the signaling is transmitted to the security isolation module; Step 3: Multi-protocol access adaptation: When a signaling request is initiated by internal or external clients of the court using different terminals or devices, after identity authentication, the multi-protocol access adaptation module parses the message content according to the dedicated access adaptation module for each terminal protocol and transmits the signaling to the signaling conversion module; Step 4: Signaling conversion and processing: The signaling conversion module converts the formatted message after receiving the parsed message into an internal unified data format; the signaling receiving submodule of the signaling processing module receives the signaling, and the signaling analysis submodule analyzes it and extracts key information; The signaling scheduling submodule performs signaling scheduling operations based on the analysis results and judicial business rules; The signaling feedback submodule generates feedback signaling from the signaling processing results. Following the reverse path of the signaling initiation, it passes through the signaling conversion module, the identity authentication and authorization module, and the network adaptation module in sequence, and finally sends the feedback signaling back to the signaling initiator; The signaling initiator performs corresponding operations based on the content of the feedback signaling; When a signaling request that needs to cross the network is parsed, the signaling is transmitted to the security isolation module.

Citation Information

Cited By

  • Unified identity authentication system and method for scientific research collaboration

    CN121486100A

  • Audio and video transmission system and method

    CN121567931A

  • Data exchange method and system based on one-way optical shutter

    CN121841767A