Video front-end device authentication method and system based on SM9 algorithm
By using the national cryptographic algorithm SM9 and encryption technology SM4, the system achieves identity authentication and data encryption for front-end devices in the video surveillance system, solving the problem of poor security performance in the video surveillance system and ensuring the authenticity of devices and data security.
Patent Information
- Application Number
- CN202311516761.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-14
- Publication Date
- 2026-01-23
- Estimated Expiration
- 2043-11-14
AI Technical Summary
Existing video surveillance systems cannot guarantee the authenticity of user identities, device identities, the integrity of signaling content, and the integrity of video content, leading to security risks such as unauthorized access, unauthorized access, unauthorized manipulation, and video content leakage.
The SM9 national cryptographic algorithm is used for front-end video device authentication, including downloading the SM9 identification key, two-way authentication, SM4 algorithm encryption and decryption of video data, and key management and transmission through a unified cryptographic service platform.
Ensure the authenticity of front-end video devices, prevent malicious access and unauthorized control, protect the security of video data transmission, and avoid data leakage and theft.
Smart Images

Figure CN117528194B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of video authentication technology, and in particular to a video front-end device authentication method and system based on the national cryptographic SM9 algorithm. Background Technology
[0002] With the development of information technology, video surveillance is evolving into network monitoring and intelligent monitoring, and related applications have spread to various scenarios in cities and daily life. However, the IP-based, networked, and standardized nature of video surveillance makes it more vulnerable to cyberattacks. Once hackers gain control of video surveillance equipment and management service platforms, they can intercept video data and even take over device control by forging identities, launching continuous cyberattacks against specific targets, causing serious crises such as network paralysis, business disruption, and privacy breaches.
[0003] However, most current video surveillance systems do not employ video security authentication and video signaling / data encryption, which presents the following problems:
[0004] 1. Unauthorized access by unauthorized users: Because current video surveillance systems cannot guarantee the authenticity of user identities or the controllability of user access, unauthorized access by unauthorized users can lead to the leakage of sensitive video content;
[0005] 2. Illegal access to video surveillance front-end devices: Because current video surveillance systems cannot guarantee the authenticity of the identity of video surveillance front-end devices accessing the system, counterfeit devices can illegally access the video surveillance front-end, which can lead to the implantation of fake videos. It cannot be guaranteed that the video accessed by the user is from the requested device and not from other counterfeit devices, and the credibility of the source cannot be guaranteed.
[0006] 3. Unauthorized access to video surveillance management platform server equipment: Since current video surveillance systems cannot guarantee the authenticity of the identity of the platform server equipment in the surveillance video system, unauthorized access to the surveillance video system server equipment can lead to the transfer of sensitive video content;
[0007] 4. Unauthorized manipulation of video surveillance front-end equipment: Because current video surveillance systems cannot guarantee the integrity of signaling content, that is, they cannot guarantee that the signaling content can be detected after it has been tampered with, unauthorized manipulation of equipment can lead to incorrect monitoring angles, malfunctions, and transmission of collected video to unauthorized locations.
[0008] 5. Illegally tampering with video content generated by front-end video surveillance equipment: Since current video surveillance systems cannot guarantee the integrity of video content or prevent it from being tampered with, illegally tampering with the video content of front-end video surveillance equipment can lead to changes in the video content.
[0009] 6. Illegally obtaining video content generated by video surveillance front-end equipment: Since current video surveillance systems cannot guarantee the confidentiality of video content and cannot ensure that audio and video content is not stolen or leaked, illegally obtaining video content can lead to the leakage of sensitive video content.
[0010] Based on the above security risks, there is an urgent need to build a secure video surveillance system to protect the security of video data throughout its entire lifecycle. Summary of the Invention
[0011] The purpose of this invention is to provide a video front-end device authentication method and system based on the national cryptographic SM9 algorithm, so as to solve the problem of poor security performance of existing video surveillance systems.
[0012] To address the aforementioned technical problems, this invention provides a video front-end device authentication method based on the national cryptographic SM9 algorithm, comprising:
[0013] The front-end video device downloads the SM9 identification key and uses security encryption measures to complete the key request, download, transmission, and storage of the front-end video SM9 private key;
[0014] The front-end video device and the video encryption subsystem perform two-way authentication based on identifier cryptography technology;
[0015] The front-end video equipment uses the SM4 algorithm to encrypt the monitoring video data and transmits the encrypted monitoring video data to the video encryption subsystem;
[0016] The video encryption subsystem decrypts the encrypted surveillance video data and transmits the decrypted surveillance video data to the video user terminal.
[0017] Optionally, in the video front-end device authentication method based on the national cryptographic SM9 algorithm, the method for the front-end video device to download the SM9 identifier key includes:
[0018] The front-end video device initiates an SM9 key request to the unified cryptographic service platform and uses security encryption measures to complete the key request, download, transmission, and storage of the front-end video SM9 private key;
[0019] The unified cryptographic service platform verifies the MAC value, requests KGC to generate SM9 key ciphertext data, and uses security encryption measures to transmit the SM9 key ciphertext data from the video front end.
[0020] The front-end video device obtains the SM9 key ciphertext data and decrypts it to obtain the video front-end SM9 private key;
[0021] The front-end video device employs security encryption measures to store the SM9 private key for the video front-end.
[0022] Optionally, in the video front-end device authentication method based on the national cryptographic SM9 algorithm, the method by which the front-end video device initiates an SM9 key request to the unified cryptographic service platform includes:
[0023] The front-end video device integrates an SDK, which already stores the device root key;
[0024] The front-end video device calls the SDK's SM2 temporary public / private key generation interface to obtain the SM2 temporary public key;
[0025] The front-end video device establishes an access token with the unified cryptographic service platform to initiate an SM9 key request to the unified cryptographic service platform.
[0026] Optionally, in the video front-end device authentication method based on the national cryptographic SM9 algorithm, the method by which the unified cryptographic service platform verifies the MAC value and requests the KGC to generate SM9 key ciphertext data includes:
[0027] The front-end video device calls the SDK's HMAC algorithm to calculate the MAC value;
[0028] The front-end video device requests an SM9 key from the unified cryptographic service platform, carrying the SM2 temporary public key, device MAC+ID, and MAC value.
[0029] The unified cryptographic service platform verifies the MAC value and generates an SM9 private key based on the device's MAC+ID;
[0030] The Unified Cryptography Service Platform uses the SM2 temporary public key to encrypt the SM9 private key in order to obtain the SM9 key ciphertext data.
[0031] Optionally, in the video front-end device authentication method based on the national cryptographic SM9 algorithm, the method for the front-end video device and the video encryption subsystem to perform two-way authentication based on identifier cryptography includes:
[0032] The front-end video device initiates a registration request to the video encryption subsystem;
[0033] The video encryption subsystem generates a first random number and sends the first random number to the front-end video device;
[0034] The front-end video device obtains the first signature value based on the first random number and then sends a registration request to the video encryption subsystem again.
[0035] The video encryption subsystem verifies the first signature value to obtain the second signature value;
[0036] The front-end video device obtains the second signature value and verifies the second signature value.
[0037] Optionally, in the video front-end device authentication method based on the national cryptographic SM9 algorithm, the method by which the front-end video device obtains a first signature value based on a first random number and then initiates a registration request to the video encryption subsystem again includes:
[0038] The front-end video device generates a second random number;
[0039] The front-end video device uses the SM9 private key to digitally sign the first random number, the second random number, and the server ID to obtain the first signature value;
[0040] The front-end video device sends a registration request to the video encryption subsystem again, carrying a first random number, a second random number, a first signature value, and a server ID.
[0041] Optionally, in the video front-end device authentication method based on the national cryptographic SM9 algorithm, the method by which the video encryption subsystem verifies the first signature value to obtain the second signature value includes:
[0042] The video encryption subsystem verifies the validity of the first random number, the server ID, and the first signature value.
[0043] The video encryption subsystem calls the unified cryptographic service platform to verify the first signature value.
[0044] The unified cryptographic service platform uses the SM9 private key to digitally sign the first random number, the second random number, and the front-end video device to obtain the second signature value;
[0045] The unified cryptography service platform returns the signature verification result and the second signature value to the video encryption subsystem.
[0046] Optionally, in the video front-end device authentication method based on the national cryptographic SM9 algorithm, the method of encrypting the monitoring video data using the SM4 algorithm and transmitting the encrypted monitoring video data to the video encryption subsystem includes:
[0047] The front-end video device randomly generates a 128-bit video encryption key;
[0048] The front-end video device uses an encryption key to encrypt the monitoring video data to obtain the encrypted monitoring video data;
[0049] The front-end video device calls the unified cryptographic service platform and uses the SM9 public key provided by the unified cryptographic service platform to encrypt the video encryption key;
[0050] The front-end video device uses a stream key to symmetrically encrypt the video stream data, so as to transmit the encrypted monitoring video data to the video encryption subsystem.
[0051] Optionally, in the video front-end device authentication method based on the national cryptographic SM9 algorithm, the method by which the video encryption subsystem decrypts the encrypted monitoring video data and transmits the decrypted monitoring video data to the video user terminal includes:
[0052] The video encryption subsystem calls the unified cryptographic service platform to download the SM9 private key corresponding to the national cryptographic public key;
[0053] The video encryption subsystem uses the SM9 private key to decrypt the encrypted encryption key to obtain the encryption key;
[0054] The video encryption subsystem uses an encryption key to decrypt the surveillance video data to obtain the surveillance video data.
[0055] The video encryption subsystem transmits the decrypted surveillance video data to the video user terminal.
[0056] To address the aforementioned technical problems, this invention also provides a video front-end device authentication system based on the national cryptographic algorithm SM9, used to implement the video front-end device authentication method based on the national cryptographic algorithm SM9 as described in any of the preceding claims. The video front-end device authentication system based on the national cryptographic algorithm SM9 includes a front-end video device, a video encryption subsystem, a video user terminal, and a unified cryptographic service platform. The video user terminal communicates with the front-end video device through the video encryption subsystem to obtain the monitoring video from the front-end video device. The video encryption subsystem is used to decrypt, store, access, and manage the monitoring video from the front-end video device through the unified cryptographic service platform. The unified cryptographic service platform includes a cryptographic resource pool, which is used to create keys and manage and monitor the data generated by the unified cryptographic service platform.
[0057] This invention provides a video front-end device authentication method and system based on the national standard cryptographic algorithm SM9. The method includes: the front-end video device downloading the SM9 identifier key and employing security encryption measures to complete key request, download, transmission, and storage of the front-end video SM9 private key; the front-end video device and the video encryption subsystem performing bidirectional authentication based on identifier cryptography; the front-end video device encrypting the monitoring video data using the SM4 algorithm and transmitting the encrypted monitoring video data to the video encryption subsystem; and the video encryption subsystem decrypting the encrypted monitoring video data and transmitting the decrypted monitoring video data to the video user terminal. By selecting national standard cryptographic technology, the method achieves a high degree of standardization and fewer technical weaknesses. By performing bidirectional authentication between the front-end video device and the video encryption subsystem based on the SM9 algorithm, the authenticity of the connected devices is ensured, effectively preventing video leakage and malicious video injection caused by malicious device access and unauthorized control of the front-end device. By encrypting and transmitting the monitoring video data using the national standard cryptographic algorithm, the method effectively prevents malicious video theft, avoids data leakage risks, and solves the problem of poor security performance in existing video surveillance systems. Attached Figure Description
[0058] Figure 1 A flowchart of the video front-end device authentication method based on the national cryptographic SM9 algorithm provided in this embodiment;
[0059] Figure 2 This embodiment provides a schematic diagram of the method for downloading national cryptographic keys to front-end video devices.
[0060] Figure 3 A detailed logical diagram illustrating the method for downloading the national cryptographic key to the front-end video device provided in this embodiment;
[0061] Figure 4 A schematic diagram illustrating the method for two-way authentication between the front-end video device and the video encryption subsystem provided in this embodiment;
[0062] Figure 5 A detailed schematic diagram illustrating the method logic for two-way authentication between the front-end video device and the video encryption subsystem provided in this embodiment;
[0063] Figure 6 This is a schematic diagram illustrating the logic of the method for encrypting and decrypting surveillance video data provided in this embodiment;
[0064] Figure 7 This is a detailed logical diagram illustrating the method for encrypting and decrypting surveillance video data provided in this embodiment;
[0065] Figure 8 This is a schematic diagram of the structure of the video front-end device authentication system based on the national cryptographic SM9 algorithm provided in this embodiment. Detailed Implementation
[0066] The following detailed description, in conjunction with the accompanying drawings and specific embodiments, provides a further detailed explanation of the video front-end device authentication method and system based on the national cryptographic algorithm SM9 proposed in this invention. It should be noted that the accompanying drawings are all in a very simplified form and use non-precise proportions, intended only to facilitate and clarify the illustration of the embodiments of this invention. Furthermore, the structures shown in the drawings are often part of the actual structure. In particular, different figures may emphasize different aspects and sometimes use different proportions.
[0067] It should be noted that the terms "first," "second," etc., used in the specification, claims, and drawings of this invention are used to distinguish similar objects in order to describe embodiments of the invention, and are not used to describe a specific order or sequence. It should be understood that such uses of terminology are interchangeable where appropriate. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0068] SM9 is a tokenization cryptography algorithm based on asymmetric cryptography, similar to SM2. Like other tokenization cryptography algorithms, SM9's security is based on the property of elliptic curve bilinear mapping. Unlike the traditional SM2 algorithm, SM9 does not require digital certificates, thus offering many advantages over traditional public-key cryptography by eliminating certificate management and other associated costs. Under the same security conditions, it not only saves significant expenses but also greatly improves authentication efficiency, making it more suitable for authenticating massive numbers of endpoints.
[0069] Based on this, this embodiment provides a video front-end device authentication method based on the national cryptographic SM9 algorithm, such as... Figure 1 As shown, it includes:
[0070] S1, the front-end video device downloads the SM9 identification key and uses security encryption measures to complete the key request, download, transmission and storage of the front-end video SM9 private key;
[0071] S2, the front-end video device and the video encryption subsystem perform two-way authentication based on identity cryptography technology;
[0072] S3: The front-end video device uses the SM4 algorithm to encrypt the monitoring video data and transmits the encrypted monitoring video data to the video encryption subsystem.
[0073] S4, the video encryption subsystem, decrypts the encrypted surveillance video data and transmits the decrypted surveillance video data to the video user terminal.
[0074] The video front-end device authentication method based on the national standard SM9 algorithm provided in this embodiment has a high degree of standardization and fewer technical weaknesses by selecting national standard cryptographic technology. By using the SM9 algorithm to perform two-way authentication between the front-end video device and the video encryption subsystem, the authenticity of the front-end video device access is ensured, effectively preventing video leakage and malicious implantation of irrelevant videos caused by malicious device access and unauthorized control of the front-end device. By encrypting and transmitting the monitoring video data based on the SM4 algorithm, the malicious theft of video can be effectively prevented, avoiding the risk of data leakage and solving the problem of poor security performance in existing video surveillance systems.
[0075] Furthermore, in this embodiment, as Figure 2 As shown, step S1, the method for the front-end video device to download the SM9 identifier key includes:
[0076] S11, the front-end video device initiates an SM9 key request to the unified cryptographic service platform and uses security encryption measures to complete the key request, download, transmission and storage of the front-end video SM9 private key.
[0077] Specifically, in this embodiment, the method for the front-end video device to initiate an SM9 key request to the unified cryptographic service platform includes: first, the front-end video device integrates an SDK, wherein the SDK has stored the device root key; then, the front-end video device calls the SDK's SM2 temporary public-private key generation interface to obtain the SM2 temporary public key; finally, the front-end video device establishes an access token with the unified cryptographic service platform to initiate an SM9 key request to the unified cryptographic service platform.
[0078] S12, the unified cryptographic service platform verifies the MAC value, requests KGC to generate SM9 key ciphertext data, and uses security encryption measures to transmit the SM9 key ciphertext data of the video front end.
[0079] Specifically, in this embodiment, the method for transmitting the SM9 key ciphertext data from the video front-end by verifying the MAC value, requesting the KGC to generate SM9 key ciphertext data, and employing secure encryption measures includes: First, the front-end video device calls the SDK's HMAC algorithm to calculate the MAC value. In this embodiment, this step uses the SM3 national cryptographic algorithm, and the HMAC algorithm is SM3-HMAC. Then, the front-end video device requests the SM9 key from the unified cryptographic service platform, carrying the SM2 temporary public key, the device MAC+ID, and the MAC value. The device MAC+ID includes the device MAC value and the device ID. At this time, the national cryptographic algorithm is requested based on the SM9 algorithm to obtain the SM9 private key. Next, the unified cryptographic service platform verifies the MAC value and generates the SM9 private key based on the device MAC+ID. Finally, the unified cryptographic service platform uses the SM2 temporary public key to encrypt the SM9 private key to obtain the SM9 key ciphertext data.
[0080] S13, the front-end video device obtains the SM9 key ciphertext data and decrypts it to obtain the video front-end SM9 private key.
[0081] Specifically, the front-end video device uses the SM2 temporary private key to decrypt the SM9 key ciphertext data. The SM2 temporary private key is the SM2 temporary private key obtained by the front-end video device calling the SDK's SM2 temporary public-private key generation interface, which corresponds to the SM2 temporary public key.
[0082] S14, the front-end video device uses security encryption measures to store the private key of the video front-end SM9.
[0083] The method for downloading SM9 keys provided in this embodiment uses an SM2 temporary key based on the national cryptographic algorithm to encrypt and transmit the required key, ensuring the security of key transmission and achieving a higher and more reliable security environment.
[0084] In one specific embodiment, to implement step S1, the front-end video device needs to register the front-end video device (such as a camera) in the video encryption subsystem first, including information such as the location, device name, and industry code of the front-end video device; then, the video encryption subsystem generates a national standard ID (device ID) based on the registration information and corresponding rules; subsequently, the registration information of the front-end video device is imported into the unified cryptographic service platform, including information such as device name, national standard ID, salt value, and server ID (such as SIP server ID); and, in the SDK integrated by the front-end video device, the national standard ID, salt value, SIP ID, and other information are passed in, and the key download interface of the cryptographic SDK is called to save the key to the security chip of the front-end video device, so as to send an access request to the video encryption subsystem.
[0085] like Figure 3As shown, in a specific embodiment, step S1, the method for the front-end video device to download the SM9 identifier key, includes:
[0086] First, the embedded SDK generates an SM2 temporary key pair (Pk, Sk), where Pk is the SM2 public key and Sk is the SM2 private key. The SM2 public key Pk is encapsulated in a JSON structure within the request body. An HMAC operation is performed on some important information in the request body (such as the device identifier, i.e., the national standard ID) using a preset root key to obtain a message authentication code, which is then encapsulated in a JSON structure within the request body. An HMAC operation is also performed on some important information in the request header using the default key of the unified cryptographic service platform to obtain a message authentication code, which is then encapsulated in the data of the request header. Finally, a request to download the SM9 key is sent to the unified cryptographic service platform using the HTTP POST protocol.
[0087] Then, after receiving the SM9 key request from the embedded SDK, the unified cryptography service platform first verifies it using the message authentication code in the request header. If the verification fails, an error is returned. Next, it verifies the message authentication code in the request body using the corresponding preset root key of the embedded SDK. If the verification fails, an error is returned. After successful verification, the unified cryptography service platform extracts the SM2 public key Pk from the request body and, in conjunction with the platform identifier of the embedded SDK (including device identifiers such as the national standard ID of the front-end video device), requests the corresponding SM9 private key data from the KGC.
[0088] Then, KGC uses the corresponding SM9 master private key to generate the user's SM9 private key based on the SM9 identifier (including the national standard ID) of the front-end video device; KGC then uses the SM2 public key Pk to encrypt the user's SM9 private key data and sends the encrypted SM9 private key data back to the unified cryptographic service platform.
[0089] Finally, the unified cryptography service platform sends the encrypted SM9 private key data back to the SDK; the embedded SDK uses the generated SM2 private key Sk to decrypt the returned SM9 private key data; based on the user's password, it uses an SM4-based password protection algorithm to encrypt and protect the decrypted SM9 private key data; and finally, it stores the encrypted SM9 private key data, thus completing the distribution and download of the SM9 private key.
[0090] Furthermore, in this embodiment, as Figure 4 As shown, step S2, the method for two-way authentication between the front-end video device and the video encryption subsystem based on identity cryptography technology includes:
[0091] S21, the front-end video device initiates a registration request to the video encryption subsystem.
[0092] S22, the video encryption subsystem generates a first random number R1 and sends the first random number R1 to the front-end video device.
[0093] S23, the front-end video device obtains the first signature value sign1 based on the first random number R1, and sends a registration request (register) to the video encryption subsystem again.
[0094] Specifically, in this embodiment, the method by which the front-end video device obtains a first signature value based on a first random number and initiates a registration request to the video encryption subsystem again includes: first, the front-end video device generates a second random number R2; then, the front-end video device uses an SM9 private key to digitally sign the first random number R1, the second random number R2, and the server ID (such as a SIP server ID) to obtain a first signature value sign1; finally, the front-end video device carries the first random number R1, the second random number R2, the first signature value sign1, and the server ID to initiate a registration request to the video encryption subsystem again.
[0095] S24, the video encryption subsystem verifies the first signature value sign1 to obtain the second signature value sign2.
[0096] Specifically, in this embodiment, the method by which the video encryption subsystem verifies the first signature value to obtain the second signature value includes: first, the video encryption subsystem verifies the validity of the first random number R1, the server ID, and the first signature value sign1; then, the video encryption subsystem calls the unified cryptographic service platform to verify the first signature value sign1; and the unified cryptographic service platform uses the SM9 private key to digitally sign the first random number R1, the second random number R2, and the front-end video device (national standard ID) to obtain the second signature value sign2; finally, the unified cryptographic service platform returns the verification result and the second signature value sign2 to the video encryption subsystem.
[0097] S25, the front-end video device obtains the second signature value sign2 and verifies the second signature value sign2.
[0098] Specifically, in this embodiment, the method for the front-end video device to obtain the second signature value and verify the second signature value includes: First, the video encryption subsystem sends a response to the front-end video device carrying the second random number R2, the device ID, and the second signature value sign2. In this embodiment, the video encryption subsystem responds to the front-end video device with a 200 OK SDP. Then, the front-end video device verifies the validity of the second random number R2, the device ID, and the second signature value sign2. Finally, the front-end video device verifies the second signature value sign2.
[0099] The method for two-way authentication between front-end video devices and video encryption subsystems based on the SM9 identifier cryptographic algorithm provided in this embodiment differs from the traditional one-way / two-way identity authentication based on digital certificates provided by RSA and SM2. It is a lightweight authentication method that is more suitable for a large number of video front-end devices, ensuring the authenticity of access devices while also saving a lot of investment costs for enterprises or individuals.
[0100] In one specific embodiment, to achieve step S2, the front-end video device and the video encryption subsystem perform two-way authentication based on identifier cryptography. This requires synchronizing the front-end video device identifier (including the national standard ID and SIP server ID) and the unified cryptographic service platform identifier (including the SIP server ID) before downloading the key. In practical applications, this synchronization is generally completed before step S1.
[0101] like Figure 5 As shown, in a specific embodiment, step S2, the method for two-way authentication between the front-end video device and the video encryption subsystem based on identifier cryptography technology, specifically includes:
[0102] First, the front-end video device initiates a REGISTER registration request to the video encryption subsystem; after receiving the REGISTER request from the front-end video device, the video encryption subsystem calls the smart password middleware (terminal JAVA SDK) to generate a random number R1; the smart password middleware returns the random number R1 to the front-end video device.
[0103] Then, after the front-end video device receives the returned random value R1, the smart cryptography middleware (embedded SDK) generates a random number R2, decrypts it using the SM4 key to obtain the SM9 private key, and uses the SM9 private key to digitally sign R1+R2+signaling server ID, which is recorded as the first signature value Sign1. The front-end video device then sends a REGISTER request to the video encryption subsystem again, carrying information such as R1, R2, signaling server ID, and Sign1.
[0104] Subsequently, the video encryption subsystem calls the terminal SDK to verify the transmitted values of the front-end video device, verifying the validity of R1, the signaling server ID, and the signature value Sign1. The video encryption subsystem calls the cryptographic capabilities of the unified cryptographic service platform, using the front-end video device identifier (the front-end video device's public key) to verify the signature value sign1, and using the unified cryptographic service platform's SM9 private key to digitally sign R1+R2+device identifier (including the front-end video device's national standard ID and SIP server ID) to obtain the signature value sign2. The unified cryptographic service platform returns the verification result of the signature value sign1 and the digital signature value sign2 to the video encryption subsystem. The video encryption subsystem replies to the front-end video device with a 200 OK response, carrying an SDP message body containing R1, R2, the front-end video device identifier (the front-end video device's national standard ID + SIP server ID), and Sign2.
[0105] Finally, for the message returned by the video encryption subsystem, the front-end video device uses the capabilities of the embedded SDK of the smart cryptographic middleware to perform signature verification; it verifies the validity of sign2, the validity of R2, and the national standard ID + SIP server ID of the front-end video device; and calls the unified cryptographic service platform identifier (SIP server ID and public key) to verify sign2.
[0106] Furthermore, in this embodiment, as Figure 6 As shown, step S3, the method of encrypting the monitoring video data using the SM4 algorithm by the front-end video device and transmitting the encrypted monitoring video data to the video encryption subsystem includes:
[0107] S31, the front-end video device randomly generates a 128-bit video encryption key.
[0108] Specifically, in this embodiment, the SM4 block cipher algorithm is used to generate a 128-bit encryption key, which is a random key denoted as DK.
[0109] S32, the front-end video device uses an encryption key to encrypt the monitoring video data to obtain the encrypted monitoring video data.
[0110] S33: The front-end video device calls the unified cryptographic service platform and uses the SM9 public key provided by the unified cryptographic service platform to encrypt the video encryption key.
[0111] Specifically, in this embodiment, the video encryption key DK is encrypted using the SM9 public key corresponding to the SM9 private key provided by the unified cryptographic service platform.
[0112] S34, the front-end video device uses a stream key to symmetrically encrypt the video stream data, so as to transmit the encrypted monitoring video data to the video encryption subsystem.
[0113] And, in step S4, the method by which the video encryption subsystem decrypts the encrypted surveillance video data and transmits the decrypted surveillance video data to the video user terminal includes:
[0114] S41, The video encryption subsystem calls the unified cryptographic service platform to download the SM9 private key corresponding to the SM9 public key;
[0115] S42, the video encryption subsystem uses the national cryptographic private key to decrypt the encrypted encryption key to obtain the encryption key;
[0116] S43, The video encryption subsystem uses the encryption key to decrypt the monitoring video data to obtain the monitoring video data;
[0117] S44, the video encryption subsystem transmits the decrypted surveillance video data to the video user terminal.
[0118] The method of encrypting and decrypting video stream data using encryption keys is existing technology, which can be obtained by those skilled in the art, and will not be described in detail here.
[0119] The encryption and decryption method for monitoring video data provided in this embodiment also encrypts and decrypts the video encryption key, thereby improving the reliability of video data through double encryption and preventing video data from being leaked or stolen.
[0120] In one specific embodiment, to implement step S3, the front-end video device uses the SM4 algorithm to encrypt the monitoring video data and transmits the encrypted monitoring video data to the video encryption subsystem. The maximum valid duration of the video encryption key DK is 1 hour. Since the same DK is used in the same GOP, when encrypting the video, it is necessary to determine whether the current DK is valid and whether a new DK has been generated. If the GOP period ends and a new DK is available, the new DK is replaced; otherwise, the current DK is used.
[0121] like Figure 7 As shown, in a specific embodiment, step S3, the method of encrypting the monitoring video data using the SM4 algorithm by the front-end video device and transmitting the encrypted monitoring video data to the video encryption subsystem includes:
[0122] First, the video encryption subsystem initiates an Invite access request to the signaling server, carrying an SDP message body. The SDP message body contains user identification information, such as the national standard ID of the front-end video device, the sequence number of the sending media stream, and the ID and sequence number of the receiving media stream. Upon receiving the request, the signaling server sends an Invite access request to the media server. Upon receiving the Invite request from the signaling server, the media server replies with a 200 OK response, carrying an SDP message body describing the IP address, port, and media format of the media stream it receives. Upon receiving the reply, the signaling server initiates an Invite request to the front-end video device, carrying the SDP message body returned by the media server. Upon receiving the request, the front-end video device replies with a 200 OK response to the signaling server, carrying an SDP message body containing the IP address, port, and media format of the sending video stream. Upon receiving the 200 OK response from the front-end video device, the signaling server initiates an ACK request to the media server, carrying the message body from the front-end video device's 200 OK response, thus completing the Invite session establishment process between the signaling server and the media server.
[0123] Then, after receiving the ACK request, the front-end video device calls the capabilities of the smart cryptography middleware (embedded C SDK) to encrypt the video data. After receiving the ACK request, the embedded SDK front-end video device randomly generates a 128-bit random key for video encryption, denoted as DK. The DK is used to encrypt the video data. The DK is encrypted using the SM9 public key, denoted as E(DK), and the encrypted DK is encapsulated in the protocol header of the video stream transmission. The front-end video device then encrypts and transmits the video stream to the media server.
[0124] And, such as Figure 7 As shown, step S4, the method by which the video encryption subsystem decrypts the encrypted surveillance video data and transmits the decrypted surveillance video data to the video user terminal includes:
[0125] First, the signaling server sends an Invite request to the media server, carrying an SDP message body that describes the IP address, port, and media format for receiving the media stream. Upon receiving the request, the media server replies with a 200 OK response, also carrying an SDP message body that describes the media stream sender's ID, port, and media stream format. The signaling server then replies with a 200 OK response to the video encryption subsystem, carrying the media server's SDP message body. Upon receiving the response, the video encryption subsystem sends an ACK request to the signaling server. The signaling server forwards the ACK request to the media server. Upon receiving the ACK request, the media server establishes a video transmission channel and transmits the video to the video encryption subsystem.
[0126] Then, after receiving the video stream, the video encryption subsystem uses its own SM9 private key to decrypt it and obtain the video encryption key DK; then it uses DK to decrypt the video data to obtain the video data.
[0127] This embodiment also provides a video front-end device authentication system based on the Chinese national cryptographic SM9 algorithm, used to implement the video front-end device authentication method based on the Chinese national cryptographic SM9 algorithm as described above, such as... Figure 8 As shown, the video front-end device authentication system based on the national cryptographic algorithm SM9 includes a front-end video device, a video encryption subsystem, a video user terminal, and a unified cryptographic service platform. The video user terminal communicates with the front-end video device through the video encryption subsystem to obtain the monitoring video of the front-end video device. The video encryption subsystem is used to decrypt, store, access, and manage the monitoring video of the front-end video device through the unified cryptographic service platform. The unified cryptographic service platform includes a cryptographic resource pool, which is used to create keys and manage and monitor the data generated by the unified cryptographic service platform.
[0128] Specifically, in this embodiment, the end video device has a built-in security chip and an integrated SDK, providing functions such as identity authentication and video stream encryption. The video encryption subsystem consists of a web server, a video signaling gateway, a media server, and their security components, supporting basic streaming media services such as video decryption, video surveillance, video device access, video platform access, video device and channel management, video storage, and video playback. End users can log in via QR code scanning on the video user terminal. This QR code login can be based on national cryptographic algorithms to authenticate the end user's identity, thereby enabling operations such as video playback and download. The unified cryptographic service platform manages and monitors the cryptographic machine pool through a cryptographic resource pool, including creating persistent key pairs in the cryptographic machines and monitoring the status of cryptographic devices. Specifically, in this embodiment, the unified cryptographic service platform can provide key distribution and signature verification capabilities through the intelligent cryptographic middleware RCE interface.
[0129] The video front-end device authentication system based on the national cryptographic algorithm SM9 provided in this embodiment is used to solve problems such as video data leakage, video data tampering, and theft caused by malicious replacement and illegal control of current front-end video access. It adopts SM9-based legitimate access of front-end video devices, effectively ensuring the authenticity of the front-end video device's identity and preventing risks such as video data leakage and replacement caused by unauthorized device access and malicious device replacement. It employs cryptographic technology to encrypt the video data source, effectively ensuring the security of video data transmission and preventing risks such as theft and leakage during video transmission. This forms a business system security solution centered on front-end video devices and a video encryption subsystem, meeting the application scenario requirements for secure interaction of important business data such as signaling messages and video data in the transmission link.
[0130] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Similar or identical parts between embodiments can be referred to mutually. In addition, different parts between embodiments can also be combined with each other, and this invention does not limit this.
[0131] This embodiment provides a video front-end device authentication method and system based on the national standard SM9 algorithm, including: the front-end video device downloading the SM9 identifier key and employing security encryption measures to complete key request, download, transmission, and storage of the front-end video SM9 private key; the front-end video device and the video encryption subsystem performing two-way authentication based on identifier cryptography; the front-end video device encrypting the monitoring video data using the SM4 algorithm and transmitting the encrypted monitoring video data to the video encryption subsystem; and the video encryption subsystem decrypting the encrypted monitoring video data and transmitting the decrypted monitoring video data to the video user terminal. By selecting national standard cryptographic technology, the system achieves a high degree of standardization and fewer technical weaknesses. The two-way authentication between the front-end video device and the video encryption subsystem based on the SM9 algorithm ensures the authenticity of the connected devices, effectively preventing malicious device access and illegal control of the front-end device, which could lead to video leakage and malicious implantation of irrelevant videos. Encrypting and transmitting monitoring video data using the national standard algorithm effectively prevents malicious video theft, avoids data leakage risks, and solves the problem of poor security performance in existing video surveillance systems.
[0132] The above description is merely a description of preferred embodiments of the present invention and is not intended to limit the scope of the present invention in any way. Any changes or modifications made by those skilled in the art based on the above disclosure shall fall within the protection scope of the claims.
Claims
1. A video front-end device authentication method based on the Chinese national cryptographic SM9 algorithm, characterized in that, include: The front-end video device downloads the SM9 identification key and uses security encryption measures to complete the key request, download, transmission, and storage of the front-end video SM9 private key; The front-end video device and the video encryption subsystem perform two-way authentication based on identifier cryptography technology; The front-end video equipment uses the SM4 algorithm to encrypt the monitoring video data and transmits the encrypted monitoring video data to the video encryption subsystem; The video encryption subsystem decrypts the encrypted surveillance video data and transmits the decrypted surveillance video data to the video user terminal. The method for two-way authentication between the front-end video device and the video encryption subsystem based on identity cryptography includes: The front-end video device initiates a registration request to the video encryption subsystem; The video encryption subsystem generates a first random number and sends the first random number to the front-end video device; The front-end video device obtains the first signature value based on the first random number and then sends a registration request to the video encryption subsystem again. The video encryption subsystem verifies the first signature value to obtain the second signature value; The front-end video device obtains the second signature value and verifies the second signature value; The method by which the front-end video device obtains a first signature value based on a first random number and then initiates a registration request to the video encryption subsystem again includes: The front-end video device generates a second random number; The front-end video device uses the SM9 private key to digitally sign the first random number, the second random number, and the server ID to obtain the first signature value; The front-end video device sends a registration request to the video encryption subsystem again, carrying a first random number, a second random number, a first signature value, and a server ID.
2. The video front-end device authentication method based on the national cryptographic SM9 algorithm according to claim 1, characterized in that, The method for downloading the SM9 identifier key by the front-end video device includes: The front-end video device initiates an SM9 key request to the unified cryptographic service platform and uses security encryption measures to complete the key request, download, transmission, and storage of the front-end video SM9 private key; The unified cryptographic service platform verifies the MAC value, requests KGC to generate SM9 key ciphertext data, and uses security encryption measures to transmit the SM9 key ciphertext data from the video front end. The front-end video device obtains the SM9 key ciphertext data and decrypts it to obtain the video front-end SM9 private key; The front-end video device employs security encryption measures to store the SM9 private key for the video front-end.
3. The video front-end device authentication method based on the national cryptographic SM9 algorithm according to claim 2, characterized in that, The method by which the front-end video device initiates an SM9 key request to the unified cryptographic service platform includes: The front-end video device integrates an SDK, which already stores the device root key; The front-end video device calls the SDK's SM2 temporary public / private key generation interface to obtain the SM2 temporary public key; The front-end video device establishes an access token with the unified cryptographic service platform to initiate an SM9 key request to the unified cryptographic service platform.
4. The video front-end device authentication method based on the national cryptographic SM9 algorithm according to claim 3, characterized in that, The method by which the unified cryptographic service platform verifies the MAC value and requests the KGC to generate SM9 key ciphertext data includes: The front-end video device calls the SDK's HMAC algorithm to calculate the MAC value; The front-end video device requests an SM9 key from the unified cryptographic service platform, carrying the SM2 temporary public key, device MAC+ID, and MAC value. The unified cryptographic service platform verifies the MAC value and generates an SM9 private key based on the device's MAC+ID; The Unified Cryptography Service Platform uses the SM2 temporary public key to encrypt the SM9 private key in order to obtain the SM9 key ciphertext data.
5. The video front-end device authentication method based on the national cryptographic SM9 algorithm according to claim 1, characterized in that, The method by which the video encryption subsystem verifies the first signature value to obtain the second signature value includes: The video encryption subsystem verifies the validity of the first random number, the server ID, and the first signature value. The video encryption subsystem calls the unified cryptographic service platform to verify the first signature value. The unified cryptographic service platform uses the SM9 private key to digitally sign the first random number, the second random number, and the front-end video device to obtain the second signature value; The unified cryptography service platform returns the signature verification result and the second signature value to the video encryption subsystem.
6. The video front-end device authentication method based on the national cryptographic SM9 algorithm according to claim 1, characterized in that, The method for encrypting the monitoring video data using the SM4 algorithm by the front-end video device and transmitting the encrypted monitoring video data to the video encryption subsystem includes: The front-end video device randomly generates a 128-bit video encryption key; The front-end video device uses an encryption key to encrypt the monitoring video data to obtain the encrypted monitoring video data; The front-end video device calls the unified cryptographic service platform and uses the SM9 public key provided by the unified cryptographic service platform to encrypt the video encryption key; The front-end video device uses a stream key to symmetrically encrypt the video stream data, so as to transmit the encrypted monitoring video data to the video encryption subsystem.
7. The video front-end device authentication method based on the national cryptographic SM9 algorithm according to claim 6, characterized in that, The method by which the video encryption subsystem decrypts the encrypted surveillance video data and transmits the decrypted surveillance video data to the video user terminal includes: The video encryption subsystem calls the unified cryptographic service platform to download the SM9 private key corresponding to the national cryptographic public key; The video encryption subsystem uses the SM9 private key to decrypt the encrypted encryption key to obtain the encryption key; The video encryption subsystem uses an encryption key to decrypt the surveillance video data to obtain the surveillance video data. The video encryption subsystem transmits the decrypted surveillance video data to the video user terminal.
8. A video front-end device authentication system based on the national cryptographic SM9 algorithm, used to implement the video front-end device authentication method based on the national cryptographic SM9 algorithm as described in any one of claims 1 to 7, characterized in that, The video front-end device authentication system based on the national cryptographic algorithm SM9 includes a front-end video device, a video encryption subsystem, a video user terminal, and a unified cryptographic service platform. The video user terminal communicates with the front-end video device through the video encryption subsystem to obtain the monitoring video of the front-end video device. The video encryption subsystem is used to decrypt, store, access, and manage the monitoring video of the front-end video device through the unified cryptographic service platform. The unified cryptographic service platform includes a cryptographic resource pool, which is used to create keys and manage and monitor the data generated by the unified cryptographic service platform.
Citation Information
Patent Citations
Video encryption system
CN109218825A
Mobile video conference encryption method
CN113347215A