A method and system for upgrading and transforming a GB28181 monitoring system based on the GB35114 protocol
By introducing a protocol proxy module between the GB28181 monitoring system and the FDWSF device, device identity authentication and control signaling authentication are realized, which solves the problem that existing systems are difficult to access FDWSF devices, and achieves safe and reliable system upgrades and device access.
Patent Information
- Application Number
- CN202111554560.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-17
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2041-12-17
AI Technical Summary
The existing GB28181 monitoring system is difficult to access front-end devices with security functions (FDWSF) and cannot meet the device identity authentication and control signaling security authentication requirements in the GB35114 standard.
A protocol proxy module is added between the GB28181 monitoring system and the FDWSF device, through which the module provides device identity authentication and control signaling authentication based on digital certificates for communication between the video monitoring system and the FDWSF device.
It has realized the upgrade and transformation of the GB28181 monitoring system, supports the access and security certification of FDWSF equipment, is simple and efficient in operation, has a small upgrade range and is cheap.
Smart Images

Figure CN114286051B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technology, and in particular to an upgrading and reconstruction method and system of a GB28181 monitoring system based on the GB35114 protocol. Background Art
[0002] As the public security video surveillance network system has higher and higher requirements for audio and video information security, the "GB35114 Public Security Video Surveillance Network Information Security Technical Requirements" came into being, which clearly requires that the network video surveillance system needs to achieve access to front-end devices with security functions (hereinafter referred to as FDWSF), that is, the current network video surveillance system needs to have security functions such as device identity authentication based on digital certificates and control signaling security authentication. How to transform the current GB28181 monitoring system in accordance with the GB35114 standard to complete FDWSF access has become a problem that each monitoring system needs to solve. Summary of the invention
[0003] In view of the technical defects and disadvantages in the prior art, the embodiments of the present invention provide a method and system for upgrading and transforming a GB28181 monitoring system based on the GB35114 protocol to overcome the above problems or at least partially solve the above problems. The specific scheme is as follows:
[0004] As a first aspect of the present invention, a method for upgrading and reconstructing a GB28181 monitoring system based on the GB35114 protocol is provided, the method comprising:
[0005] Step 1, add a protocol proxy module between the video surveillance system based on GB28181 protocol and the FDWSF device;
[0006] Step 2: Provide digital certificate-based device identity authentication and control signaling authentication for the communication between the video surveillance system and the FDWSF device through the protocol proxy module.
[0007] Furthermore, in step 2, the identity authentication process includes:
[0008] Send a registration message to the protocol proxy module through the FDWSF device, the registration message carries the Authorization header field of the GB35114 protocol, and the Capability item in the Authorization header field describes the security capability of the FDWSF device;
[0009] After receiving the registration message of the FDWSF device, the protocol proxy module registers the FDWSF device based on the registration message to complete the identity authentication.
[0010] Furthermore, the method further comprises:
[0011] If the identity authentication between the protocol proxy module and the FDWSF device is passed, the protocol proxy module copies the registration message and modifies the copied registration message to remove the security capability of the FDWSF device carried in the registration message, that is, converts the registration message into a GB28181 registration message, and transmits the generated registration message after modification to the SIP server of the video surveillance system. After receiving the modified registration message, the SIP server of the video surveillance system verifies the data of this registration, and records the successful registration of the current FDWSF device in the video surveillance system, prompts the user to go online and complete the identity authentication of this FDWSF device, wherein the SIP server verifies the data of this registration through the ID of the FDWSF device in the registration message.
[0012] Furthermore, the method further comprises:
[0013] If the identity authentication between the protocol proxy module and the FDWSF device fails, the protocol proxy module does not copy the registration message, replies with an authentication error message to the FDWSF device, and records the current FDWSF identity authentication failure in the monitoring system to complete the identity authentication of this device.
[0014] Furthermore, in step 2, the control signaling authentication includes:
[0015] After the FDWSF device is successfully registered, the client sends control signals with signaling security to the SIP server of the video surveillance system, such as video browsing, pan / tilt rotation, device parameter settings, etc. The control signaling enables the Date field and adds Note information to the Date field. The Note information carries the value after hashing the message body.
[0016] After receiving the control signaling, the SIP server transparently transmits the control signaling to the protocol proxy module, and the protocol proxy module verifies the hash value in the received control signaling;
[0017] If the check passes, the protocol proxy module copies the control signaling, and transforms the copied control signaling, replaces the original hash value in the control signaling with the hash value corresponding to the SIP server, and then transmits the transformed control signaling to the FDWSF device. After the FDWSF device verifies the hash value in the control signaling, it completes the authentication of this control signaling and completes the recording of the current operation in the monitoring system;
[0018] If the verification fails, the protocol proxy module replies with an error message to the SIP server, completes the authentication of the control signaling, and completes the recording of the current operation in the monitoring system.
[0019] The specific steps of hash value verification include:
[0020] 1) The SIP server sends a control signaling to the protocol proxy module (the control signaling is transmitted by the client to the SIP server), and the message body of the control signaling carries a hash value 1 (hereinafter referred to as nonce1). The specific production method of the nonce1 value is to hash the string composed of [Method+from+to+callid+date+vkek1+message body] using the SM3 algorithm, and then generate it after Base64 encoding. (The above-mentioned vkek1 is the video key encryption key regularly updated and generated by the protocol proxy module, and the new value will be notified to the client after each update);
[0021] 2) After receiving the control signaling, the protocol proxy module extracts the key information in the control signaling, including Method, from, to, callid, date, message body, and nonce1. The protocol proxy module uses the hash algorithm to generate the hash value 2 (hereinafter referred to as nonce2). The specific production method of the nonce2 value is to hash the string composed of [Method+from+to+callid+date+vkek2+message body] using the SM3 algorithm, and then generate it after Base64 encoding. (The above-mentioned vkek2 is the video key encryption key regularly updated and generated by the protocol proxy module). The protocol proxy module compares the values of nonce1 and nonce2. If the values are equal, the verification passes.
[0022] 3) After the protocol proxy module successfully verifies the control signaling, it modifies the control signaling. The modified control signaling contains key information such as Method, from1, to1, callid1, date, and hash value 3 (hereinafter referred to as nonce3). The specific production method of the nonce3 value is to hash the string composed of [Method+from1+to1+callid1+date+vkek2+message body] using the SM3 algorithm, and then generate it after Base64 encoding. The protocol proxy module sends the modified control signaling to the FDWSF device.
[0023] 4) After receiving the control signaling from the protocol proxy module, the FDWSF device extracts the key information in the control message, including Method, from1, to1, callid1, date, message body, and nonce3. The FDWSF device uses a hash algorithm to generate a hash value 4 (hereinafter referred to as nonce4). The specific production method of the nonce4 value is to hash the string composed of [Method+from1+to1+callid1+date+vkek3+message body] using the SM3 algorithm, and then generate it after Base64 encoding. (The above-mentioned vkek3 is the video key encryption key that is regularly updated and generated by the protocol proxy module. After each update, the new value will be notified to the FDWSF device). The FDWSF device compares the values of nonce3 and nonce4. If the values are equal, the verification passes.
[0024] It should be noted that as long as the users and devices have legal access to the GB35114 system, their VKEK values are consistent with the VKEK values of the server, and the values are updated synchronously. That is, as long as the identity authentication is successful, the values of the above vkek1, vkek2, and vkek3 are equal.
[0025] As a second aspect of the present invention, a system for upgrading and reconstructing a GB28181 monitoring system based on the GB35114 protocol is provided, the system comprising a protocol proxy module and a video monitoring system and a FDWSF device based on the GB28181 protocol, the video monitoring system and the FDWSF device communicating through the protocol proxy module, and the protocol proxy module providing device identity authentication and control signaling authentication based on digital certificates for the communication between the video monitoring system and the FDWSF device.
[0026] Furthermore, the identity authentication process includes:
[0027] Send a registration message to the protocol proxy module through the FDWSF device, the registration message carries the Authorization header field of the GB35114 protocol, and the Capability item in the Authorization header field describes the security capability of the FDWSF device;
[0028] After receiving the registration message of the FDWSF device, the protocol proxy module registers the FDWSF device based on the registration message to complete the identity authentication.
[0029] Furthermore, the identity authentication process also includes:
[0030] If the identity authentication between the protocol proxy module and the FDWSF device is successful, the protocol proxy module copies the registration message, and modifies the copied registration message, removes the security capability of the FDWSF device carried in the registration message, that is, converts the registration message into a GB28181 registration message, and transmits the registration message generated after the modification to the SIP server of the video surveillance system. After receiving the modified registration message, the SIP server of the video surveillance system performs data verification of the registration, and records the successful registration of the current FDWSF device in the video surveillance system, prompts the user to go online, and completes the identity authentication of the FDWSF device.
[0031] If the identity authentication between the protocol proxy module and the FDWSF device fails, the protocol proxy module does not copy the registration message, replies with an authentication error message to the FDWSF device, and records the current FDWSF identity authentication failure in the monitoring system to complete the identity authentication of this device.
[0032] Furthermore, the control signaling authentication includes:
[0033] After the FDWSF device is successfully registered, the client sends control signals with signaling security to the SIP server of the video surveillance system, such as video browsing, pan / tilt rotation, device parameter settings, etc. The control signaling enables the Date field and adds Note information to the Date field. The Note information carries the value after hashing the message body.
[0034] After receiving the control signaling, the SIP server transparently transmits the control signaling to the protocol proxy module, and the protocol proxy module verifies the hash value in the received control signaling;
[0035] If the check passes, the protocol proxy module copies the control signaling, and transforms the copied control signaling, replaces the original hash value in the control signaling with the hash value corresponding to the SIP server, and then transmits the transformed control signaling to the FDWSF device. After the FDWSF device verifies the control signaling, it completes the authentication of this control signaling and completes the recording of the current operation in the monitoring system;
[0036] If the verification fails, the protocol proxy module replies with an error message to the SIP server, completes the authentication of the control signaling, and completes the recording of the current operation in the monitoring system.
[0037] The present invention has the following beneficial effects:
[0038] Based on the requirements of the GB35114 protocol for the access and use of FDWSF equipment, the present invention proposes an upgrade and transformation method for the GB28181 monitoring system based on the GB35114 protocol. The method can realize the current network video monitoring system transformation and FDWSF access without changing the original software architecture. The method is simple and efficient to operate, with a very small upgrade scope and low cost. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Figure 1 A schematic diagram of the deployment of a protocol proxy module provided in an embodiment of the present invention;
[0040] Figure 2 A schematic diagram of the protocol proxy module according to an embodiment of the present invention authenticating the identity of the FDWSF device;
[0041] Figure 3 A schematic diagram of a protocol proxy module provided in an embodiment of the present invention performing security authentication on control signaling. DETAILED DESCRIPTION
[0042] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0043] It should be noted that the protocol proxy module is implemented as a front-end module and deployed between the FDWSF and the SIP server, thereby realizing the central signaling control function with security functions of the old system and enabling rapid access and use of GB35114 equipment.
[0044] See also Figure 1 , which is a deployment diagram of the protocol proxy module provided in an embodiment of the present invention. The protocol proxy module is deployed as a front-end module between the FDWSF and the SIP server, thereby realizing the central signaling control function of the old system with security functions, and enabling rapid access and use of GB35114 equipment.
[0045] Specifically, the protocol proxy module, as the front-end module of the GB28181 video surveillance system, is responsible for connecting the GB28181 system and the FDWSF as a "bridge". As shown in the figure, a set of protocol proxy modules can manage multiple SIP servers and multiple FDWSF devices. In actual applications, the specific number of protocol proxy modules to be deployed can be determined based on the system's business volume.
[0046] See also Figure 2The protocol proxy module provided in the embodiment of the present invention provides an FDWSF identity authentication method, comprising the following steps:
[0047] The FDWSF device sends a Register registration message to the protocol proxy module, which carries the security capability set of the FDWSF device. After receiving the request, the protocol proxy module replies to the device with a random number R1 and the identity data of the protocol proxy module. The FDWSF device generates a random number R2, and uses R1+R2+the identity data of the protocol proxy module to perform a digital signature according to the SM2 algorithm, and returns the signature results S1 and R2 to the protocol proxy module. The protocol proxy module uses R1+R2+the identity data of the proxy module to perform a digital signature according to the SM2 algorithm to generate S2. The protocol proxy module performs identity authentication by comparing whether the values of S1 and S2 are equal.
[0048] If the values are equal, it means that the identity authentication is successful. Then the protocol proxy module transforms the registration message into a GB28181 message and sends it to the SIP server. The SIP server authenticates the FDWSF device information in the registration message. After the authentication is successful, the status of the current FDWSF device is updated in the database, and the online status of the FDWSF device is notified to the user and management platform.
[0049] If the values are not equal, it means that the authentication has failed. The protocol proxy module returns an error code to the FDWSF device and records the authentication failure in the database;
[0050] See also Figure 3 The method for performing security authentication on control signaling by the protocol proxy module provided in the embodiment of the present invention comprises the following steps:
[0051] After receiving the client's device control signaling, the SIP server transparently transmits the control signaling to the protocol proxy module;
[0052] After receiving the control signaling, the protocol proxy module extracts the hash value n1 in the control message and verifies it; that is, the protocol proxy module generates the hash value n2 after Base64 encoding the message header + message body + protocol proxy module vkek through SM3. If the values of n1 and n2 are equal, the authentication is successful;
[0053] After the authentication is successful, the protocol proxy module transforms the control signaling, modifies the from field, the to field, and modifies the hash value n1 to n3, where the value of n3 is the modified message header + message body + protocol proxy module vkek generated by Base64 encoding through SM3; after the message is transformed, the protocol proxy module transmits the control message to the FDWSF device;
[0054] After receiving the message, the FDWSF device performs Base64 encoding on the message header + message body + FDWSF vkek through SM3 to generate n4. The FDWSF device compares the values of n3 and n4 to see if they are equal to authenticate the control signaling.
[0055] If the values of n3 and n4 are equal, it means that the control signaling authentication is successful. FDWSF returns the authentication result 200ok of successful authentication, which also carries the hash value n5. The protocol proxy module receives 200ok and generates the hash value n6 according to the message header + message body + protocol proxy module vkek of 200ok, and compares the values of n5 and n6. If the values are equal, the 200ok message is modified, that is, the from field and to field are modified, and the hash value n5 is modified to n7. The modified message header + message body + proxy module vkek of n7 is generated by Base64 encoding through SM3. After the replacement is successful, it is forwarded to the SIP server, and the SIP server records the operation record and results in the database.
[0056] If the values of n3 and n4 are not equal, it means that the control signaling authentication fails. The FDWSF device returns an authentication failure message to the protocol proxy module. The protocol proxy module replies to the SIP server that the control signaling operation failed. At the same time, the protocol proxy module records the control signaling authentication failure in the database.
[0057] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present invention should be included in the protection scope of the present invention.
Claims
1. A method for upgrading and reconstructing a GB28181 monitoring system based on the GB35114 protocol. It is characterized in that The method comprises: Step 1, add a protocol proxy module between the video surveillance system based on GB28181 protocol and the FDWSF device; Step 2: Provide device identity authentication and control signaling authentication based on digital certificates for the communication between the video surveillance system and the FDWSF device through the protocol proxy module; Among them, in step 2, the identity authentication process includes: Send a registration message to the protocol proxy module through the FDWSF device, the registration message carries the Authorization header field of the GB35114 protocol, and the Capability item in the Authorization header field describes the security capability of the FDWSF device; After receiving the registration message of the FDWSF device, the protocol proxy module registers the FDWSF device based on the registration message and completes the identity authentication; Wherein, the method further comprises: If the identity authentication between the protocol proxy module and the FDWSF device is passed, the protocol proxy module copies the registration message and modifies the copied registration message to remove the security capability of the FDWSF device carried in the registration message, that is, converts the registration message into a GB28181 registration message, and transmits the generated registration message after modification to the SIP server of the video surveillance system. After receiving the modified registration message, the SIP server of the video surveillance system performs data verification on the registration, and records the successful registration of the current FDWSF device in the video surveillance system, prompting the user to go online and complete the identity authentication of the FDWSF device.
2. The upgrading and transformation method of the GB28181 monitoring system based on the GB35114 protocol according to claim 1, It is characterized in that The method further comprises: If the identity authentication between the protocol proxy module and the FDWSF device fails, the protocol proxy module does not copy the registration message, replies with an authentication error message to the FDWSF device, and records the current FDWSF identity authentication failure in the monitoring system to complete the identity authentication of this device.
3. The upgrading and transformation method of the GB28181 monitoring system based on the GB35114 protocol according to claim 2, It is characterized in that In step 2, control signaling authentication includes: After the FDWSF device is successfully registered, a control signaling with signaling security is sent to the SIP server of the video surveillance system through the client. The control signaling enables the Date field and adds Note information to the Date field. The Note information carries the value after the message body is hashed. After receiving the control signaling, the SIP server transparently transmits the control signaling to the protocol proxy module, and the protocol proxy module verifies the hash value in the received control signaling; If the check passes, the protocol proxy module copies the control signaling, and transforms the copied control signaling, replaces the original hash value in the control signaling with the hash value corresponding to the SIP server, and then transmits the transformed control signaling to the FDWSF device. After the FDWSF device verifies the control signaling, the authentication of this control signaling is completed; If the verification fails, the protocol proxy module replies with an error message to the SIP server to complete the authentication of this control signaling.
4. An upgrade and transformation system for GB28181 monitoring system based on GB35114 protocol, It is characterized in that The system includes a protocol proxy module and a video surveillance system and a FDWSF device based on the GB28181 protocol, wherein the video surveillance system and the FDWSF device communicate through the protocol proxy module, and the protocol proxy module is used to provide device identity authentication and control signaling authentication based on digital certificates for the communication between the video surveillance system and the FDWSF device; The identity authentication process includes: Send a registration message to the protocol proxy module through the FDWSF device, the registration message carries the Authorization header field of the GB35114 protocol, and the Capability item in the Authorization header field describes the security capability of the FDWSF device; After receiving the registration message of the FDWSF device, the protocol proxy module registers the FDWSF device based on the registration message and completes the identity authentication; The identity authentication process also includes: If the identity authentication between the protocol proxy module and the FDWSF device is successful, the protocol proxy module copies the registration message, and modifies the copied registration message, removes the security capability of the FDWSF device carried in the registration message, that is, converts the registration message into a GB28181 registration message, and transmits the registration message generated after the modification to the SIP server of the video surveillance system. After receiving the modified registration message, the SIP server of the video surveillance system performs data verification of the registration, and records the successful registration of the current FDWSF device in the video surveillance system, prompts the user to go online, and completes the identity authentication of the FDWSF device. If the identity authentication between the protocol proxy module and the FDWSF device fails, the protocol proxy module does not copy the registration message, replies with an authentication error message to the FDWSF device, and records the current FDWSF identity authentication failure in the monitoring system to complete the identity authentication of this device.
5. The upgrading and transformation system of the GB28181 monitoring system based on the GB35114 protocol according to claim 4, It is characterized in that Control signaling authentication includes: After the FDWSF device is successfully registered, a control signaling with signaling security is sent to the SIP server of the video surveillance system through the client. The control signaling enables the Date field and adds Note information to the Date field. The Note information carries the value after the message body is hashed. After receiving the control signaling, the SIP server transparently transmits the control signaling to the protocol proxy module, and the protocol proxy module verifies the hash value in the received control signaling; If the check passes, the protocol proxy module copies the control signaling, and transforms the copied control signaling, replaces the original hash value in the control signaling with the hash value corresponding to the SIP server, and then transmits the transformed control signaling to the FDWSF device. After the FDWSF device verifies the control signaling, the authentication of this control signaling is completed; If the verification fails, the protocol proxy module replies with an error message to the SIP server to complete the authentication of this control signaling.
Citation Information
Patent Citations
Data security protection system and method for video monitoring system
CN111274578A