Safety transmission system based on multimedia short message
By reconstructing the MMS protocol stack in layers and using hybrid encryption algorithms, combined with a machine learning monitoring module, the security issues in multimedia SMS transmission were solved. This resulted in a highly efficient and secure protocol stack with an inherent security foundation, resistant to quantum computing threats, and improved attack detection rate and bandwidth utilization efficiency.
Patent Information
- Application Number
- CN202511202593.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-26
- Publication Date
- 2025-10-31
AI Technical Summary
Existing multimedia SMS transmission protocols are vulnerable to plaintext transmission and content tampering, and their protocol stacks contain high-risk vulnerabilities such as buffer overflows and remote code execution, making it difficult to achieve secure and reliable communication in low-bandwidth or specific industries.
By reconstructing the MMS protocol stack in layers, including security hardening of the preprocessing layer, parsing layer, and execution layer, combining hybrid encryption algorithms and lightweight hash trees for message integrity verification, and embedding a machine learning-based real-time vulnerability monitoring module to dynamically identify abnormal behavior.
It achieves efficient and secure transmission of multimedia text messages, reduces the success rate of memory-based vulnerability exploitation, maintains low latency while possessing resistance to quantum computing threats, improves the identification rate of new APT attacks, and reduces bandwidth consumption and data volume.
Smart Images

Figure CN120880767A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication and network security technology, specifically to a secure transmission system based on multimedia SMS. Background Technology
[0002] MMS, as a traditional communication method, is still used in scenarios such as industrial automation (e.g., substation control under the IEC 61850 standard) and emergency communication. However, its transmission protocol was not designed with modern security threats in mind, leading to risks such as plaintext transmission and content tampering.
[0003] Rich Communication Services (RCS) are gradually replacing MMS through end-to-end encryption and IP transmission, but MMS remains irreplaceable in low-bandwidth or specific industries. For example, while China Mobile's MMS specification (CMAP2002-MMS) emphasizes content adaptation and privacy protection, it has not addressed core security vulnerabilities.
[0004] Early solutions (such as public-key cryptosystems) relied on CAs and pre-allocated keys, resulting in high implementation costs. Emerging technologies such as hierarchical encryption optimize resource allocation, but require a balance between encryption efficiency and real-time performance.
[0005] Therefore, there is still room for improvement in existing technologies, primarily in terms of protocol stack security. The MMS protocol (such as the Manufacturing Message Specification) has high-risk vulnerabilities such as buffer overflow (CVE-2022-2970) and null pointer dereference, which could lead to device crashes or remote code execution. Summary of the Invention
[0006] To address the aforementioned technical issues, this technical solution provides a secure transmission system based on multimedia SMS. It resolves the problems of insufficient implicit feature extraction capabilities and difficulties in multi-source data fusion.
[0007] To achieve the above objectives, the technical solution adopted by the present invention is as follows: A secure transmission system based on multimedia messaging includes: Protocol stack security hardening module: The MMS protocol stack is reconstructed in layers, including a preprocessing layer, which is used to intercept and filter illegal characters and verify the legality of message structure through a finite state machine; a parsing layer, which adopts a dynamic memory allocation strategy and predicts memory requirements based on message type and length; and an execution layer, which integrates a null pointer checking mechanism to force verification of pointer validity before calling functions in the protocol stack. Encryption and Signature Module: Employs a hybrid encryption algorithm to perform end-to-end encryption of the message body and metadata, and uses a lightweight hash tree to verify message integrity; Real-time vulnerability monitoring module: Embedded with a machine learning-based abnormal behavior detection model, dynamically identifying abnormal memory usage and high-risk operations such as illegal instruction calls during protocol stack runtime.
[0008] Preferably, the protocol stack security hardening module specifically includes: Preprocessing layer: Illegal character filtering engine: Employs a regular expression matching engine and a custom rule base to intercept illegal characters in real time, including automatically detecting the difference between the Content-Length declaration value and the actual payload, forcibly truncating data exceeding the limit and issuing alarms; eliminating unclosed tags through DOM tree parsing, and performing normalized escaping on XML / HTML entity encoding; controlling character stripping and filtering non-printable characters in the ASCII 0-31 range; Unicode security measures include glyph merging for combined character sequences. Finite state machine protocol compliance verification: enforce state transition constraints, define a 7-stage state machine for MMS protocol messages, and reject non-standard transitions; semantic-level field validation, verify the matching of Content-Type with the actual load type; identify non-standard boundary characters and refuse to process them.
[0009] Preferably, the protocol stack security hardening module specifically includes: Parsing layer: Memory pre-allocation mechanism: Type-driven resource reservation, divided into text / short message pre-allocation strategy of base pool 4KB and step expansion according to length, with canary markers inserted between pools; image / video pre-allocation strategy of block mapping, page boundary write protection; composite message pre-allocation strategy of tree memory structure, sub-block hash verification to prevent tampering. Anti-vulnerability release protocol: Triple protection for memory release, including random padding (using AES-CTR to generate a pseudo-random sequence to overwrite the original data before release); delayed release (delaying the release of memory related to high-risk operations by 300ms to block the Double-Free attack window); and obfuscation of release addresses (dynamically shuffling the release order).
[0010] Preferably, the protocol stack security hardening module specifically includes: Execution layer: Null pointer defense, three-dimensional verification of pointer validity, including null pointer checks, lower bound out-of-bounds checks, upper bound out-of-bounds checks, and triggering hardware page fault exceptions; the PMT table is compressed using a Bloom filter; Function execution sandboxing: critical functions are hardened, code segments are made read-only, and the protocol stack function entry point is locked by mprotect(PROT_READ); return address encryption is used, and the return address is encrypted using round-robin key XOR to defend against ROP attacks; secure stack frames are used to separate the protocol stack from the system stack and isolate the scope of stack overflow damage.
[0011] Preferably, the encryption and signature module specifically includes: End-to-end encryption using hybrid encryption algorithms: The key is dynamically generated, creating a unique session key for each session, including a root key, which is a 256-bit entropy value generated based on the hardware fingerprints of both devices; a forward secret key, which is rotated periodically using a modified ECDH protocol; and a session key, which is derived from the root key and forward key using HKDF-SHA3, outputting the key required for AES-256-GCM. Layered encryption strategies include message body encryption, direct AES-256-GCM encryption for text / small files; block encryption for large media to accelerate parallel processing; and metadata encryption, where sensitive fields use FPE to maintain data structure compliance, while non-sensitive fields retain plaintext to optimize routing efficiency.
[0012] Preferably, the encryption and signature module specifically includes: Lightweight hash tree integrity verification: Tree structure: Dynamic block partitioning strategy, including text processed as a whole block using BLAKE3-128; images divided into 64KB / block using BLAKE3-256; videos divided into 1MB / block using KangarooTwelve; optimized tree construction, parallel hash calculation, and GPU / NPU acceleration of multi-block hash generation; sparse tree structure, storing only the hash of the rightmost node at each level; Integrity verification mechanism: At the sending end, a set of data block hashes is generated; a lightweight hash tree is constructed, and a root hash value is generated; the sender's private key is used to sign the RootHash; At the receiving end, the signature validity is verified using the sender's public key; the hash tree is recalculated based on the received data block, and the root hash is compared for consistency; partial verification is supported, requiring only the download of path nodes.
[0013] Preferably, the encryption and signature module specifically includes: Quantum-resistant: Post-quantum cryptography compatible, dual-mechanism hybrid encryption, the current layer is AES-256-ECC; the quantum-resistant layer is a nested NTRU algorithm to encrypt the session key; seamless protocol switching, automatically switching to CRYSTALS-Kyber key encapsulation when a quantum computing threat is detected; Physical layer security hardening: Time blinding technology, random delays are injected into encryption operations to resist power analysis attacks; encrypted memory storage, plaintext keys are stored only in the hardware security area, and keys in external memory are all in AES-GCM-SIV encrypted state; Metadata obfuscation mechanism: dynamic relay routing, messages pass through at least 3 relay nodes, stripping away the original IP and device fingerprint; timestamp perturbation, adding a random offset of ±30 seconds to the sending time, blocking communication pattern analysis; Zero-knowledge credential verification: anonymous identity authentication using the zk-SNARKs protocol, verifying without exposing the user ID, ensuring the legitimacy of the recipient while concealing the sender's identity.
[0014] Preferably, the real-time vulnerability monitoring module specifically includes: Multi-dimensional runtime monitoring probe: The memory behavior profiling engine captures three-dimensional memory metrics in real time, monitors stack level, and periodically samples heap / stack pointer offsets to establish a dynamic baseline model; it identifies fragmentation attacks by calculating memory block distribution entropy values to detect abnormal fragmentation patterns; and it detects hidden channels by scanning for residual data in shared memory areas to intercept CacheBank side-channel attacks. Deep instruction stream auditing, illegal call chain tracing, sensitive API hooking, hooking critical system calls, and blocking remote code execution paths; instruction sequence signing, establishing an N-gram instruction fingerprint library for legitimate protocol stack functions, and judging anomalies when the deviation exceeds a predetermined proportion; ROP defense wall, real-time detection of return address continuity violations, and freezing execution threads.
[0015] Preferably, the real-time vulnerability monitoring module specifically includes: Lightweight machine learning anomaly detection model: A dual-stream hybrid neural network is used for LSTM feature extraction based on the temporal flow of memory metrics, frequency domain features of the instruction flow, and 1D-CNN convolutional layers. The feature fusion layer is obtained through LSTM feature extraction and 1D-CNN convolutional layers, and anomaly scoring is output. Temporal modeling is performed by LSTM units to process temporal metrics such as memory occupancy and pointer activity. Spatial modeling is performed by 1D-CNN convolutional kernels scanning the instruction flow histogram. Edge optimization and knowledge distillation compression compress the ResNet-34 teacher model into a miniature student model; binarized neural network, binarizing weights and activation values; incremental online learning, federated learning framework, local training of threat features on the device, and aggregation of the global model in the cloud; adversarial example defense, injecting gradient mask noise to prevent model theft attacks.
[0016] Preferably, the real-time vulnerability monitoring module specifically includes: Tiered Response: Threat handling strategy matrix, divided into high-risk level, immediately freezing processes and uploading memory snapshots; medium-risk level, limiting CPU quotas and closing high-risk protocol ports; low-risk level, audit log marking and dynamically adjusting detection thresholds; Automated forensics and remediation: Memory forensics sandbox, suspicious processes are replayed in a hardware isolation zone to extract attack chain evidence; hot patch injection, dynamically replacing vulnerable functions via kprobe.
[0017] Compared with the prior art, the beneficial effects of the present invention are as follows: This invention constructs an intrinsic security foundation for the protocol stack through the collaboration of preprocessing layer state machine verification, parsing layer dynamic memory isolation, and execution layer pointer three-dimensional verification. The semantic-level structured filtering of the preprocessing layer can intercept 90% of malformed message attacks; the parsing layer memory block mapping and gold ant marking achieve hardware-level overflow protection; and the execution layer null pointer defense combined with PMT table compression technology reduces the success rate of memory-related vulnerability exploits to near zero.
[0018] By employing a hybrid encryption architecture, combining dynamic session key derivation, metadata FPE format preservation encryption, and lightweight hash tree verification, the system maintains a latency of 15ms in 4K video encryption scenarios while achieving resistance to quantum computing threats. The layered encryption strategy reduces bandwidth consumption by 45%, while the sparse Merkle tree structure compresses integrity verification data by 80%.
[0019] By overcoming the limitations of single-dimensional detection through dual-stream neural networks, and by cross-modal analysis of instruction stream frequency domain features and memory timing behavior, combined with threat intelligence sharing under the federated learning framework, the identification rate of new APT attacks is improved.
[0020] An adaptive security closed loop is constructed through cross-layer linkage mechanisms such as memory exception event-driven encryption key rotation, hash tree root value constraint protocol stack behavior baseline, and vulnerability feature reverse optimization parsing strategy. Attached Figure Description
[0021] Figure 1 This is an internal framework diagram of a secure transmission system based on multimedia SMS. Detailed Implementation
[0022] The following description is intended to disclose the invention and enable those skilled in the art to implement it. The preferred embodiments described below are merely examples, and other obvious variations will occur to those skilled in the art.
[0023] Reference Figure 1 As shown, a secure transmission system based on multimedia messaging includes: Protocol stack security hardening module: The MMS protocol stack is reconstructed in layers, including a preprocessing layer, which is used to intercept and filter illegal characters and verify the legality of message structure through a finite state machine; a parsing layer, which adopts a dynamic memory allocation strategy and predicts memory requirements based on message type and length; and an execution layer, which integrates a null pointer checking mechanism to force verification of pointer validity before calling functions in the protocol stack. Encryption and Signature Module: Employs a hybrid encryption algorithm to perform end-to-end encryption of the message body and metadata, and uses a lightweight hash tree to verify message integrity; Real-time vulnerability monitoring module: Embedded with a machine learning-based abnormal behavior detection model, dynamically identifying abnormal memory usage and high-risk operations such as illegal instruction calls during protocol stack runtime.
[0024] It should be noted that the attack interception chain reaction occurs as follows: Preprocessing layer: As the first line of defense, it intercepts illegal message structures, such as nested malicious tags, through a finite state machine (FSM), blocking 90% of attacks before protocol parsing; Parsing layer: Dynamic memory allocation strategy to specifically eliminate buffer overflow conditions: When the message type is identified as video, block memory mapping (each 64KB independent page) is automatically enabled, canary markers (0xDEADBEEF) are inserted at the boundary, and a hardware-level SIGSEGV signal is triggered the moment an overflow write occurs; Execution layer: Null pointer check mechanism (PMT pointer mapping table + Bloom filter compression) to handle residual risks and link with vulnerability monitoring module in real time: if abnormal pointer jump is detected, the thread is immediately frozen and a security sandbox is started for evidence collection.
[0025] Interoperability between encryption and surveillance: The lightweight hash tree of the encryption module provides a trusted data source for the monitoring module, and the BLAKE3 hash value of message blocks serves as the baseline input for behavior detection, preventing attackers from polluting the training data. The federated learning framework of the vulnerability monitoring module enhances encryption security in reverse. Metadata protection strategies, such as timestamp perturbation parameters, trained locally on edge devices are synchronized to the cloud through encrypted channels to optimize the global obfuscation algorithm.
[0026] Resource conflict arbitration: When the encryption module processes 4K video (consuming 80% of the NPU's computing power), the monitoring module automatically switches to low-power mode: The LSTM timing analysis window was expanded from 500ms to 2; the instruction stream scan granularity was increased from 5 instructions / time to 20 instructions / time; ensuring that the total system latency remained stable at <50ms (within the human perception threshold). The preprocessing layer of the protocol stack hardening module implements traffic shaping, prioritizing the protection of text message channels and delaying video segmentation in DDoS attack scenarios.
[0027] Lightweight technology: Memory optimization: The parsing layer uses a SLAB allocator to reduce memory fragmentation to below 3%; the monitoring module's circular buffer reuse technology keeps resident memory <800KB. The computing power is offloaded, and the hash tree construction is accelerated by HexagonNPU, reducing power consumption by 70%; the AES-GCM instructions for encryption operations are executed through ARMSVE2 vectorization, increasing throughput by 8 times.
[0028] The protocol stack security hardening module specifically includes: Preprocessing layer: Illegal character filtering engine: Employs a regular expression matching engine and a custom rule base to intercept illegal characters in real time, including automatically detecting the difference between the Content-Length declaration value and the actual payload, forcibly truncating data exceeding the limit and issuing alarms; eliminating unclosed tags through DOM tree parsing, and performing normalized escaping on XML / HTML entity encoding; controlling character stripping and filtering non-printable characters in the ASCII 0-31 range; Unicode security measures include glyph merging for combined character sequences. Finite state machine protocol compliance verification: enforce state transition constraints, define a 7-stage state machine for MMS protocol messages, and reject non-standard transitions; semantic-level field validation, verify the matching of Content-Type with the actual load type; identify non-standard boundary characters and refuse to process them.
[0029] Parsing layer: Memory pre-allocation mechanism: Type-driven resource reservation, divided into text / short message pre-allocation strategy of base pool 4KB and step expansion according to length, with canary markers inserted between pools; image / video pre-allocation strategy of block mapping, page boundary write protection; composite message pre-allocation strategy of tree memory structure, sub-block hash verification to prevent tampering. Anti-vulnerability release protocol: Triple protection for memory release, including random padding (using AES-CTR to generate a pseudo-random sequence to overwrite the original data before release); delayed release (delaying the release of memory related to high-risk operations by 300ms to block the Double-Free attack window); and obfuscation of release addresses (dynamically shuffling the release order).
[0030] Execution layer: Null pointer defense, three-dimensional verification of pointer validity, including null pointer checks, lower bound out-of-bounds checks, upper bound out-of-bounds checks, and triggering hardware page fault exceptions; the PMT table is compressed using a Bloom filter; Function execution sandboxing: critical functions are hardened, code segments are made read-only, and the protocol stack function entry point is locked by mprotect(PROT_READ); return address encryption is used, and the return address is encrypted using round-robin key XOR to defend against ROP attacks; secure stack frames are used to separate the protocol stack from the system stack and isolate the scope of stack overflow damage.
[0031] It should be noted that the preprocessing layer includes: Defense design for filtering illegal characters: Adversarial optimizations to DOM tree parsing, targeting new types of tag nesting and obfuscation attacks: For example, < <script>>alert()<< / script> >; An asymmetric label matching algorithm is used to force the left label ( <tag> ) and right label (< / tag> Closing at the same nesting level prevents cross-level injection; addressing the ambiguity of entity encoding (such as...) (amp#x41; can be parsed as A or a malicious instruction) Implements three-stage decoding normalization: Phase 1: Standardized escape characters; Phase 2: Standard HTML decoding; Phase 3: Forced conversion of numeric encoding to characters; Unicode security hardening: The combined character merging algorithm merges é (U+0065U+0301) into é (U+00E9) using the Unicode normalized form (NFC), eliminating stack overflow caused by glyph overlap; Zero-width character watermark detection: scan zero-width characters from U+200B to U+200F, and implant behavioral markers to trace the source of the attack (such as identifying the fingerprint of APT organization tools).
[0032] Vulnerability discovery capabilities of Finite State Machines (FSMs): Capturing hidden vulnerabilities in state transition paths: Defining a 7-stage state machine (START→HEADER→BODY→ATTACH→ENCRYPT→SIGN→END) with nonlinear constraints: Pre-signature attack: Reject requests that redirect to SIGN before attachment encryption is completed (blocking CVE-2024-31901 vulnerability); Encryption rollback vulnerability patch: Prevent rollback from ENCRYPT to BODY (defending against key negotiation downgrade attacks).
[0033] AI-enhanced semantic verification: A ResNet-18-based file type sniffer compares the Content-Type declaration with the actual Magic Number in the file header to identify disguised ELF executables (99.2% accuracy); boundary character entropy analysis calculates the information entropy of the boundary=parameter and rejects high-randomness boundary characters with entropy values > 4.5 (defending against format string attacks).
[0034] Parsing layer: Zero-trust practices for memory pre-allocation mechanisms: Hardware coordination for image / video block mapping: each 64KB memory page is bound to ARMMTE (Memory Tag Extension), and a 4-bit random tag (such as 0b1101) is written to the high bit of the pointer during allocation; during access, the hardware automatically checks the tag consistency, and SIGSEGV is triggered immediately if the memory goes out of bounds. Write protection bits are dynamically managed. They are read-only by default and are temporarily switched when writing is required. They are locked immediately after writing is complete. Blockchain-based protection for complex messages, with sub-block Merkle tree verification: The parent node stores a hash (H_left||H_right); modifying any child block requires reconstructing the root hash, and the cost of tampering increases exponentially. Cross-process sharing protection uses the memfd_secret() system call to protect the shared memory area from being visible to unauthorized processes.
[0035] Anti-vulnerability release protocol: The cryptographic strength of random padding, the entropy source enhancement of the AES-CTR generator, the seed sourced from a hardware TRNG (True Random Number Generator), and the padding value per byte satisfying: ; In the formula, i is the index variable for summation, ranging from 0 to n, representing each byte in the byte sequence; n is the total length of the byte sequence, i.e., the total number of bytes in the sequence; P is the probability function, representing the probability of a certain event occurring; Let be the i-th byte in the sequence; x is the possible value of the byte, ranging from 0 to 255. Since a byte consists of 8 bits, each bit can be 0 or 1, so there are a total of 2^8 = 256 possible values. A game-theoretic model for releasing addresses with dynamic adjustment of the release order based on Stackelberg equilibrium: The memory blocks are divided into k groups (k changes randomly every day), and the release order is executed in a pseudo-random sequence of G3→G1→G4→..., so that the attacker's prediction error rate is >83% (MIT adversarial experiment data).
[0036] Execution layer: Null pointer defense: Bloom filter compression algorithm for PMT table; space efficiency optimization, traditional hash table requires O(n) space, Bloom filter only requires O(1) (fixed 128KB memory), using 12 hash functions (SHA3-256 derivative) to achieve a false positive rate of <10-7; Hardware-accelerated query, integrated into the SoC's NPU coprocessor, with a query latency of <50ns; The page fault redirection during 3D verification triggers SIGSEGV. The kernel then forwards the exception to a secure enclave (such as IntelSGX). Within the enclave, the audit logs are decrypted and a vulnerability fingerprint is generated, all of which are invisible to attackers.
[0037] Function sandboxing: The cryptographic mechanism for address encryption uses a round-key scheme, a timestamp-based key, and stores the key in the high 16 bits. During decryption, the high 16 bits of the key are extracted, and the real address is obtained by performing an inverse XOR operation. Silicon-based isolation for secure stack frames, dual-stack hard isolation: The protocol stack, dedicated register set R12-R15, is stored in the CPU L1 cache secure partition; System stack, traditional RBP / RSP register set; Cross-stack call cost: Explicit switching via the CALL_SECURE instruction increases the time by 12 cycles; A deep defense chain that integrates multiple layers: Preprocessing layer → intercepts malformed messages and blocks the initial cause of memory corruption; Parsing layer → MTE hardware protection, crushing overflow attacks; Execution layer → Return address encryption, dismantling the ROP attack chain; Crushing overflow attacks → memory anomaly events, forensic evidence collection via monitoring module; Dismantle the ROP attack chain → Security audit logs, iterate on hardening strategies.
[0038] Combating AI-Driven Attacks: Adversarial example immunity training involves injecting gradient masking noise (noise~N(0,0.1)) into the LSTM model of the monitoring module, making it impossible for attackers to reverse engineer the model. Quantum heuristic attack defense, pointer verification introduces the lattice cryptography problem (LWE problem): ; In the formula, The result of the Post-quantum Multi-target query is the result after processing by the Lattice Weaving (LWE) problem; A is the public key matrix, s is the private key vector, and the query result needs to be decrypted and verified, resistant to quantum algorithm cracking; For error vectors; The modulus is a large prime number used to define the modulo operation space for lattice cryptography.
[0039] The encryption and signature module specifically includes: End-to-end encryption using hybrid encryption algorithms: The key is dynamically generated, creating a unique session key for each session, including a root key, which is a 256-bit entropy value generated based on the hardware fingerprints of both devices; a forward secret key, which is rotated periodically using a modified ECDH protocol; and a session key, which is derived from the root key and forward key using HKDF-SHA3, outputting the key required for AES-256-GCM. Layered encryption strategies include message body encryption, direct AES-256-GCM encryption for text / small files; block encryption for large media to accelerate parallel processing; and metadata encryption, where sensitive fields use FPE to maintain data structure compliance, while non-sensitive fields retain plaintext to optimize routing efficiency.
[0040] Lightweight hash tree integrity verification: Tree structure: Dynamic block partitioning strategy, including text processed as a whole block using BLAKE3-128; images divided into 64KB / block using BLAKE3-256; videos divided into 1MB / block using KangarooTwelve; optimized tree construction, parallel hash calculation, and GPU / NPU acceleration of multi-block hash generation; sparse tree structure, storing only the hash of the rightmost node at each level; Integrity verification mechanism: At the sending end, a set of data block hashes is generated; a lightweight hash tree is constructed, and a root hash value is generated; the sender's private key is used to sign the RootHash; At the receiving end, the signature validity is verified using the sender's public key; the hash tree is recalculated based on the received data block, and the root hash is compared for consistency; partial verification is supported, requiring only the download of path nodes.
[0041] Quantum-resistant: Post-quantum cryptography compatible, dual-mechanism hybrid encryption, the current layer is AES-256-ECC; the quantum-resistant layer is a nested NTRU algorithm to encrypt the session key; seamless protocol switching, automatically switching to CRYSTALS-Kyber key encapsulation when a quantum computing threat is detected; Physical layer security hardening: Time blinding technology, random delays are injected into encryption operations to resist power analysis attacks; encrypted memory storage, plaintext keys are stored only in the hardware security area, and keys in external memory are all in AES-GCM-SIV encrypted state; Metadata obfuscation mechanism: dynamic relay routing, messages pass through at least 3 relay nodes, stripping away the original IP and device fingerprint; timestamp perturbation, adding a random offset of ±30 seconds to the sending time, blocking communication pattern analysis; Zero-knowledge credential verification: anonymous identity authentication using the zk-SNARKs protocol, verifying without exposing the user ID, ensuring the legitimacy of the recipient while concealing the sender's identity.
[0042] It should be noted that the hybrid encryption algorithm is as follows: Key lifecycle: Hardware fingerprint entropy enhancement is achieved by using PUF (Physically Unclonable Function) to generate the root key and extracting a 256-bit entropy value by exploiting chip manufacturing differences (such as SRAM power-on noise), with an error rate of <0.001ppm; a laser injection attack detection circuit is added, which immediately destroys the key storage area upon triggering. A zero-trust strategy for forward key rotation, improving the ECDH protocol to achieve "key-unaware updates": Clients A and B each generate a temporary key pair (Curve448) and compute the shared secret using bilinear pairing: ; In the formula, This is a bilinear pairing mapping function, which is a mapping from points on two elliptic curves to points on a finite field. These are two points on the elliptic curve; For each base point G, a bilinear pair mapping to itself is performed, and then the result is raised to... and The product of the powers of , where G is a base point on the elliptic curve. and These are the private keys of the two users; For the public keys of the two users; The key rotates automatically every 300 seconds, and the old key is physically destroyed after being overwritten three times (0xFF→0x00→random noise). Layered encryption: Hardware collaboration for large-scale media segmentation and encryption, heterogeneous computing architecture: The CPU schedules AES-NI instructions to process metadata. GPU, parallel encrypted video blocks (CUDA kernel functions implement 128-way concurrency). NPU accelerates BLAKE3 hash generation (throughput > 240GB / s). Zero-copy memory technology allows video data to pass directly to the DMA controller, avoiding the overhead of copying between user space and kernel space. Syntax preservation of metadata FPE (Format Preservation Encryption): Type-aware encryption engine: Mobile phone numbers are encrypted using the FF1 algorithm (NISTSP800-38G), retaining the +86 prefix and 11-digit number structure; GPS coordinates are encrypted separately for longitude and latitude, maintaining 6 decimal places of precision. Compliance self-verification: encrypted fields are automatically verified using the regular expression ^[0-9+]{15}$. If the verification fails, communication is interrupted. Lightweight hash tree: Information theory compression of sparse tree structures: storage optimization principle. Traditional Merkle trees store O(n) nodes, while sparse trees store only O(logn) right nodes. For a tree of height h, the number of nodes S(h) = h + 1 (e.g., when h = 20, only 21 hash values are needed). Completeness proof of path verification: The receiver calculates layer by layer using the hash value Hsib of the sibling nodes: ; In the formula, Parent represents the hash value of the parent node, which is the result of hashing by concatenating the hash value of the current node and the hash value of the sibling node; Hash represents the hash function, a function that converts an input (regardless of length) into a fixed-length output, which usually has a high degree of irreversibility and collision resistance. This is the hash value of the current node, which is the hash representation of the data of the current node during the path verification process; This is the hash value of the current node, which is the hash representation of the data of the current node during the path verification process; Data integrity can be proven if and only if the reconstructed root hash matches the signature value (error probability < 2-128). Partially verified cross-domain acceleration: In satellite communication applications, the receiver only needs to download the target block (e.g., the k-th frame of a video) and its verification path. The formula for the path data volume is: (Example: A 1GB video only requires 20 x 32 = 640B). In the formula, Size is the size of the path data, that is, the amount of data that the receiver needs to download; The number of hashes required to verify a data block; HashLen is the length of a single hash value; Quantum-resistant signature binding: the root hash uses SPHINCS+ signature (quantum-safe after hashing) to prevent forgery by quantum computers.
[0043] The real-time vulnerability monitoring module specifically includes: Multi-dimensional runtime monitoring probe: The memory behavior profiling engine captures three-dimensional memory metrics in real time, monitors stack level, and periodically samples heap / stack pointer offsets to establish a dynamic baseline model; it identifies fragmentation attacks by calculating memory block distribution entropy values to detect abnormal fragmentation patterns; and it detects hidden channels by scanning for residual data in shared memory areas to intercept CacheBank side-channel attacks. Deep instruction stream auditing, illegal call chain tracing, sensitive API hooking, hooking critical system calls, and blocking remote code execution paths; instruction sequence signing, establishing an N-gram instruction fingerprint library for legitimate protocol stack functions, and judging anomalies when the deviation exceeds a predetermined proportion; ROP defense wall, real-time detection of return address continuity violations, and freezing execution threads.
[0044] Lightweight machine learning anomaly detection model: A dual-stream hybrid neural network is used for LSTM feature extraction based on the temporal flow of memory metrics, frequency domain features of the instruction flow, and 1D-CNN convolutional layers. The feature fusion layer is obtained through LSTM feature extraction and 1D-CNN convolutional layers, and anomaly scoring is output. Temporal modeling is performed by LSTM units to process temporal metrics such as memory occupancy and pointer activity. Spatial modeling is performed by 1D-CNN convolutional kernels scanning the instruction flow histogram. Edge optimization and knowledge distillation compression compress the ResNet-34 teacher model into a miniature student model; binarized neural network, binarizing weights and activation values; incremental online learning, federated learning framework, local training of threat features on the device, and aggregation of the global model in the cloud; adversarial example defense, injecting gradient mask noise to prevent model theft attacks.
[0045] Tiered Response: Threat handling strategy matrix, divided into high-risk level, immediately freezing processes and uploading memory snapshots; medium-risk level, limiting CPU quotas and closing high-risk protocol ports; low-risk level, audit log marking and dynamically adjusting detection thresholds; Automated forensics and remediation: Memory forensics sandbox, suspicious processes are replayed in a hardware isolation zone to extract attack chain evidence; hot patch injection, dynamically replacing vulnerable functions via kprobe.
[0046] It should be noted that the runtime probe: Memory behavior profiling, dynamic baseline self-evolution algorithm, the stack water level baseline is not a fixed threshold, but dynamically adjusted through a sliding window L2 regularization model; entropy attack detection, Shannon entropy-Kolmogorov complexity dual-factor verification of memory block distribution, when Hshannon>7.2 and Kcomplexity<0.3, it is judged as a fragmentation attack; CacheBank side-channel defense: Color-coded isolation is implemented in the shared memory area, and sensitive data is forcibly allocated to a specific CacheBank (such as Bank7); Access frequency circuit breaker mechanism: When the access rate of a single Bank exceeds 2000 times / microsecond, a hardware-level fuse is triggered for power-off protection.
[0047] Instruction flow auditing: Dynamic learning of the N-gram fingerprint database is used, and the legal function instruction flow is modeled with long-distance dependencies through Transformer-XL to generate a 768-dimensional feature vector. The deviation threshold is adaptive and dynamically adjusted based on historical attack data (initially 15% → latest 9.7%) to achieve a false alarm rate of <0.1%. The silicon-based implementation of ROP defense uses a shadow return stack, with each thread maintaining an encrypted shadow stack (the XOR key changes every millisecond); LBR (LastBranchRecord) hardware verification: the thread is frozen if the number of non-continuous jumps exceeds 3. Lightweight AI models: Channel fusion in a two-stream neural network, cross-modal alignment of spatiotemporal features, and residual compression module: reducing 2048-dimensional fused features to 256-dimensional features, and reducing inference latency by 63%; Edge optimization: Adversarial robustness of knowledge distillation, the teacher model (ResNet-34) is injected with adversarial examples for training, so that the student model inherits the ability to resist interference; The micro-model architecture, a 50KB model containing a 4-layer Depthwise convolution + GRU hybrid structure, achieves an accuracy loss of only 2.8%. Differential privacy enhancement in federated learning involves adding Gaussian noise (σ=0.5) to the device-side gradient to satisfy... =2.0 differential privacy constraint; dynamic gradient mask selection, only the top 10% of important gradients are uploaded, reducing communication overhead by 89%.
[0048] Response and Fix: Zero-trust handling in high-risk scenarios, lightning-fast memory snapshot forensics, utilizing PCIe 5.0 x4 channels, a 128GB memory image can be uploaded to the secure cloud in 1.2 seconds; Hardware coordination for process freezing involves calling IntelVT-x instructions to forcibly suspend the CPU pipeline, and the instruction pointer is automatically corrected after resumption. Reinforcement learning with dynamic threshold control, DQN (Deep Q-Network) decision engine: State space = threat level + system load; action space = threshold adjustment range; reward function = false positive rate × 0.7 + false negative rate × 0.3.
[0049] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the claimed invention. The scope of protection claimed by the appended claims and their equivalents is defined.
Claims
1. A secure transmission system based on multimedia SMS, characterized in that, include: Protocol stack security hardening module: The MMS protocol stack is reconstructed in layers, including a preprocessing layer, which is used to intercept and filter illegal characters and verify the legality of message structure through a finite state machine; a parsing layer, which adopts a dynamic memory allocation strategy and predicts memory requirements based on message type and length; and an execution layer, which integrates a null pointer checking mechanism to force verification of pointer validity before calling functions in the protocol stack. Encryption and Signature Module: Employs a hybrid encryption algorithm to perform end-to-end encryption of the message body and metadata, and uses a lightweight hash tree to verify message integrity; Real-time vulnerability monitoring module: Embedded with a machine learning-based abnormal behavior detection model, dynamically identifying abnormal memory usage and high-risk operations such as illegal instruction calls during protocol stack runtime.
2. The secure transmission system based on multimedia SMS as described in claim 1, characterized in that, The protocol stack security hardening module specifically includes: Preprocessing layer: Illegal character filtering engine: Employs a regular expression matching engine and a custom rule base to intercept illegal characters in real time, including automatically detecting the difference between the Content-Length declaration value and the actual payload, forcibly truncating data exceeding the limit and issuing alarms; eliminating unclosed tags through DOM tree parsing, and performing normalized escaping on XML / HTML entity encoding; controlling character stripping and filtering non-printable characters in the ASCII 0-31 range; Unicode security measures include glyph merging for combined character sequences. Finite state machine protocol compliance verification: enforce state transition constraints, define a 7-stage state machine for MMS protocol messages, and reject non-standard transitions; semantic-level field validation, verify the matching of Content-Type with the actual load type; identify non-standard boundary characters and refuse to process them.
3. The secure transmission system based on multimedia SMS according to claim 2, characterized in that, The protocol stack security hardening module specifically includes: Parsing layer: Memory pre-allocation mechanism: Type-driven resource reservation, divided into text / short message pre-allocation strategy of base pool 4KB and step expansion according to length, with canary markers inserted between pools; image / video pre-allocation strategy of block mapping, page boundary write protection; composite message pre-allocation strategy of tree memory structure, sub-block hash verification to prevent tampering. Anti-vulnerability release protocol: Triple protection for memory release, including random padding (using AES-CTR to generate a pseudo-random sequence to overwrite the original data before release); delayed release (delaying the release of memory related to high-risk operations by 300ms to block the Double-Free attack window); and obfuscation of release addresses (dynamically shuffling the release order).
4. The secure transmission system based on multimedia SMS according to claim 3, characterized in that, The protocol stack security hardening module specifically includes: Execution layer: Null pointer defense, three-dimensional verification of pointer validity, including null pointer checks, lower bound out-of-bounds checks, upper bound out-of-bounds checks, and triggering hardware page fault exceptions; the PMT table is compressed using a Bloom filter; Function execution sandboxing: critical functions are hardened, code segments are made read-only, and the protocol stack function entry point is locked by mprotect(PROT_READ); return address encryption is used, and the return address is encrypted using round-robin key XOR to defend against ROP attacks; secure stack frames are used to separate the protocol stack from the system stack and isolate the scope of stack overflow damage.
5. The secure transmission system based on multimedia SMS according to claim 4, characterized in that, The encryption and signature module specifically includes: End-to-end encryption using hybrid encryption algorithms: The key is dynamically generated, creating a unique session key for each session, including a root key, which is a 256-bit entropy value generated based on the hardware fingerprints of both devices; a forward secret key, which is rotated periodically using a modified ECDH protocol; and a session key, which is derived from the root key and forward key using HKDF-SHA3, outputting the key required for AES-256-GCM. Layered encryption strategies include message body encryption, direct AES-256-GCM encryption for text / small files; block encryption for large media to accelerate parallel processing; and metadata encryption, where sensitive fields use FPE to maintain data structure compliance, while non-sensitive fields retain plaintext to optimize routing efficiency.
6. The secure transmission system based on multimedia SMS according to claim 5, characterized in that, The encryption and signature module specifically includes: Lightweight hash tree integrity verification: Tree structure: Dynamic block partitioning strategy, including text processed as a whole block using BLAKE3-128; images divided into 64KB / block using BLAKE3-256; videos divided into 1MB / block using KangarooTwelve; optimized tree construction, parallel hash calculation, and GPU / NPU acceleration of multi-block hash generation; sparse tree structure, storing only the hash of the rightmost node at each level; Integrity verification mechanism: At the sending end, a set of data block hashes is generated; a lightweight hash tree is constructed, and a root hash value is generated; the sender's private key is used to sign the RootHash; At the receiving end, the signature validity is verified using the sender's public key; the hash tree is recalculated based on the received data block, and the root hash is compared for consistency; partial verification is supported, requiring only the download of path nodes.
7. The secure transmission system based on multimedia SMS according to claim 6, characterized in that, The encryption and signature module specifically includes: Quantum-resistant: Post-quantum cryptography compatible, dual-mechanism hybrid encryption, the current layer is AES-256-ECC; the quantum-resistant layer is a nested NTRU algorithm to encrypt the session key; seamless protocol switching, automatically switching to CRYSTALS-Kyber key encapsulation when a quantum computing threat is detected; Physical layer security hardening: Time blinding technology, random delays are injected into encryption operations to resist power analysis attacks; encrypted memory storage, plaintext keys are stored only in the hardware security area, and keys in external memory are all in AES-GCM-SIV encrypted state; Metadata obfuscation mechanism: dynamic relay routing, messages pass through at least 3 relay nodes, stripping away the original IP and device fingerprint; timestamp perturbation, adding a random offset of ±30 seconds to the sending time, blocking communication pattern analysis; Zero-knowledge credential verification: anonymous identity authentication using the zk-SNARKs protocol, verifying without exposing the user ID, ensuring the legitimacy of the recipient while concealing the sender's identity.
8. The secure transmission system based on multimedia SMS according to claim 7, characterized in that, The real-time vulnerability monitoring module specifically includes: Multi-dimensional runtime monitoring probe: The memory behavior profiling engine captures three-dimensional memory metrics in real time, monitors stack level, and periodically samples heap / stack pointer offsets to establish a dynamic baseline model; it identifies fragmentation attacks by calculating memory block distribution entropy values to detect abnormal fragmentation patterns; and it detects hidden channels by scanning for residual data in shared memory areas to intercept CacheBank side-channel attacks. Deep instruction stream auditing, illegal call chain tracing, sensitive API hooking, hooking critical system calls, and blocking remote code execution paths; instruction sequence signing, establishing an N-gram instruction fingerprint library for legitimate protocol stack functions, and judging anomalies when the deviation exceeds a predetermined proportion; ROP defense wall, real-time detection of return address continuity violations, and freezing execution threads.
9. The secure transmission system based on multimedia SMS according to claim 8, characterized in that, The real-time vulnerability monitoring module specifically includes: Lightweight machine learning anomaly detection model: A dual-stream hybrid neural network is used for LSTM feature extraction based on the temporal flow of memory metrics, frequency domain features of the instruction flow, and 1D-CNN convolutional layers. The feature fusion layer is obtained through LSTM feature extraction and 1D-CNN convolutional layers, and anomaly scoring is output. Temporal modeling is performed by LSTM units to process temporal metrics such as memory occupancy and pointer activity. Spatial modeling is performed by 1D-CNN convolutional kernels scanning the instruction flow histogram. Edge optimization and knowledge distillation compression compress the ResNet-34 teacher model into a miniature student model; binarized neural network, binarizing weights and activation values; incremental online learning, federated learning framework, local training of threat features on the device, and aggregation of the global model in the cloud; adversarial example defense, injecting gradient mask noise to prevent model theft attacks.
10. The secure transmission system based on multimedia SMS according to claim 9, characterized in that, The real-time vulnerability monitoring module specifically includes: Tiered Response: Threat handling strategy matrix, divided into high-risk level, immediately freezing processes and uploading memory snapshots; medium-risk level, limiting CPU quotas and closing high-risk protocol ports; low-risk level, audit log marking and dynamically adjusting detection thresholds; Automated forensics and remediation: Memory forensics sandbox, suspicious processes are replayed in a hardware isolation zone to extract attack chain evidence; hot patch injection, dynamically replacing vulnerable functions via kprobe.
Citation Information
Cited By
Hierarchical nested data encryption method supporting fine-grained access control
CN121217463A
Business message abnormal delay diagnosis system and method based on multi-source data
CN121418324A
Ground unloading system for load data of unmanned aerial vehicle
CN121691613A
Scloud+ anti-side channel matrix multiplication acceleration method based on avx2 instruction set
CN122372182A