Sdp-based information publishing system and method

By using an SDP-based information publishing system, dynamic encrypted connections are established through SDP clients, controllers, and gateways, solving the network attack problem of the information publishing system, realizing real-time information management and efficient playback control, and improving security and efficiency.

CN119544288BActive Publication Date: 2025-11-11西交网络空间安全研究院 +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411650342.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-19
Publication Date
2025-11-11
Estimated Expiration
2044-11-19

AI Technical Summary

Technical Problem

Information publishing systems are vulnerable to cyberattacks, offline display methods are difficult to manage and inefficient, and manual content review and monitoring consume a lot of manpower.

Method used

An SDP-based information publishing system is adopted, which establishes dynamic two-way encrypted connections through SDP clients, controllers, gateways, servers, networks, and players. It isolates network resources from insecure networks as needed, publishes or modifies information in real time, and manages and controls it uniformly through the SDP controller.

Benefits of technology

Effectively defend against cyberattacks, reduce information management workload, improve work efficiency, enable real-time editing and review of playback content, and reduce security risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119544288B_ABST
    Figure CN119544288B_ABST
Patent Text Reader

Abstract

This invention discloses an SDP-based information publishing system, including an SDP client, an SDP controller, an SDP gateway, a server, a network, a player, and a display device. The operator station (i.e., the SDP client) sends SPA data packets to the SDP controller. The SDP controller receives and verifies the authentication information in the SPA data packets. After successful verification, it notifies the SDP gateway to accept the operator station's connection request and sends a list of SDP gateways to the operator station. The operator station sends SPA data packets to the SDP gateways in the list. After successful verification, a bidirectional encrypted connection is established. The operator station sends multimedia information to the server through the SDP gateway and using a bidirectional encrypted data channel. The server receives and stores the multimedia information sent by the operator station. The player receives the multimedia information sent by the server, combines it, and sends it to the display device. This invention uses SDP technology to control server access, enabling the dynamic creation of security boundaries on demand, isolating network resources from insecure networks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of information security technology, and in particular relates to an information publishing system and method based on SDP. Background Technology

[0002] The information publishing system mainly consists of a server, a network, a player, and a display device. The server sends information to the player via the network, and the player then combines audio, video, images, text, and other information (including playback position and content) and sends it to a display device such as an LCD TV that can accept audio and video input to form an audio and video file for playback.

[0003] In recent years, display devices in many public places (such as restaurants, shopping malls, and schools) have frequently suffered cyberattacks, resulting in the playback of inappropriate content. Even worse, during live conferences, live streaming websites have been attacked by Trojan viruses, causing them to become uncontrollable. The security problems of information publishing systems are becoming increasingly serious, and security incidents occur frequently.

[0004] Currently, common methods for defending against cyberattacks include offline display and manual content review and monitoring. Offline display means that the information publishing device is not connected to the network. Because the information publishing device is not connected to the network, it avoids cyberattacks. However, offline display requires manual uploading or modification of display content on each device. Offline display methods have problems such as difficult information management and a large workload, while manual content review and monitoring methods require a lot of time and manpower. Summary of the Invention

[0005] To overcome the shortcomings of the existing technologies, this invention proposes an information publishing system and method based on SDP, which solves the problem that information publishing systems are vulnerable to network attacks and avoids the inefficiencies of offline display methods and manual content review and monitoring methods.

[0006] To achieve the above objectives, the present invention employs the following technical means:

[0007] In a first aspect, the present invention provides an SDP-based information publishing system, including an SDP client, an SDP controller, an SDP gateway, a server, a network, a player, and a display device;

[0008] The SDP client is deployed on the operator station, and the SDP client sends SPA data packets to the SDP controller;

[0009] The SDP controller receives and verifies the authentication information in the SPA data packet. After successful verification, it notifies the SDP gateway to accept the connection request from the operator station and sends the SDP gateway list to the operator station. The operator station sends SPA data packets to the SDP gateways in the list. After successful verification, a bidirectional encrypted connection is established.

[0010] The operator station sends multimedia information to the server via an SDP gateway and a bidirectional encrypted data channel. The server receives and stores the multimedia information sent by the operator station. The player receives the multimedia information sent by the server, combines it, and sends it to the display device. The display device is used to display the multimedia information sent by the player.

[0011] A second aspect of the present invention also provides an information publishing method utilizing the SDP-based information publishing system of the first aspect, comprising:

[0012] An SDP client is deployed on the operator station, and the SDP client sends SPA data packets to the SDP controller;

[0013] The SDP controller receives and verifies the authentication information in the SPA data packet. After successful verification, it notifies the SDP gateway to accept the connection request from the operator station and sends the SDP gateway list to the operator station. The operator station sends SPA data packets to the SDP gateways in the list. After successful verification, a bidirectional encrypted connection is established.

[0014] The SDP client sends multimedia information to the server through the SDP gateway and uses a bidirectional encrypted data channel. The server receives and stores the multimedia information. The player receives the multimedia information sent by the server, combines it, and sends it to the display device. The display device then displays the multimedia information sent by the player.

[0015] Compared to existing technologies, this invention uses SDP (Software Defined Perimeter) technology for server access control, enabling the dynamic creation of security boundaries on demand. This isolates network resources from insecure networks, preventing network resources and devices from being directly exposed to the internet, thus avoiding external security threats and mitigating network attacks. Furthermore, the SDP-based information publishing system can publish or modify information in real time, avoiding the difficulties and heavy workload associated with offline display methods.

[0016] Furthermore, the workstation of the present invention is also used for playback control functions such as user management, resource management, display device management, player management, and playback settings, and can edit, review, and publish playback content, and perform unified management and control of the player.

[0017] Furthermore, the method for establishing a bidirectional encrypted connection according to the present invention is as follows: The operator station first sends an SPA data packet to the SDP controller. This SPA data packet contains authentication information. After receiving the SPA data packet, the SDP controller verifies the authentication information in the SPA data packet. Once the operator station is verified, the SDP controller determines a list of SDP gateways that the operator station can connect to. The SDP controller then instructs the SDP gateways to accept communication from the operator station and sends the SDP gateway list to the operator station. The operator station sends SPA data packets to the authorized SDP gateways, i.e., the SDP gateways in the SDP gateway list. The SDP gateways also verify the SPA data packets. Once the verification is successful, the operator station (i.e., the SDP client) and these verified SDP gateways establish a bidirectional encrypted connection. Through the two verifications by the SDP controller and the SDP gateways, network resources can be isolated from insecure networks, preventing network attacks.

[0018] Furthermore, the SDP controller of the present invention determines the list of SDP gateways that the operator station can connect to. The implementation method is as follows: the SDP controller groups users and resources according to the configuration and configures different policies for different user groups. That is, the SDP controller determines the resources that users can access based on the user's role or user group. At the same time, it can adjust the user's resource access permissions in real time based on the analysis results given by the risk assessment, generate a security tunnel policy, and send it to the SDP client and the SDP gateway.

[0019] Furthermore, the present invention sets a timeout retransmission mechanism in the operator station. The SDP security framework uses single packet authorization and authentication technology. After the operator station sends an SPA data packet to the SDP controller, it starts its timer. When the value of the timer is equal to the time threshold, and the operator station has not received the SDP gateway list sent by the SDP controller, the operator station retransmits the SPA data packet to the SDP controller until the transmission is successful.

[0020] Furthermore, the information publishing system based on SDP of the present invention can push or modify information on the terminal display device in real time, and the implementation method is as follows:

[0021] Multimedia information stored on the server is sent to the player via the network. The player combines the multimedia information (such as images, sounds, and text) and then sends the combined information to a display device that can accept audio and video input to form an audio and video file for playback.

[0022] Furthermore, the SDP gateway of the server in this invention is set to discard all data packets, so that unauthorized operating stations cannot scan the server port.

[0023] Furthermore, in this invention, the SDP controller and SDP gateway do not respond to any connection requests before the client is authenticated and authorized. Attached Figure Description

[0024] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0025] Figure 1 This is a schematic diagram of the information publishing system framework based on SDP of the present invention.

[0026] Figure 2 This is a flowchart of the information publishing system based on SDP of the present invention. Detailed Implementation

[0027] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0028] refer to Figure 1 As shown, the information publishing system based on SDP of the present invention includes an SDP client, an SDP controller, an SDP gateway, a server, a network, a player, and a display device.

[0029] In the information publishing system, the operator station is used for main functions such as user management, resource management, display device management, player management, and playback settings. It also performs operations such as editing, reviewing, and publishing playback content, thereby providing unified management and control of the player. Specific methods include adding, modifying, deleting, and searching.

[0030] refer to Figure 2As shown, the SDP client of this invention is deployed on the operator station. This system uses SDP (Software-Defined Perimeter) technology for server access control. The operator station sends SPA data packets to the SDP controller. After receiving the SPA data packets, the SDP controller verifies the authentication information in the received SPA data packets. Upon successful verification, the SDP controller determines a list of SDP gateways that the operator station can connect to based on the user's identity. The SDP controller notifies the SDP gateways to accept the operator station's connection request and sends the SDP gateway list to the operator station. The operator station sends SPA data packets to the SDP gateways in the list. The SDP gateways also verify the authentication information in the received SPA data packets, and only after successful verification do they establish a bidirectional encrypted connection with the operator station.

[0031] In this invention, the SPA data packets sent by the operator station to the SDP controller and SDP gateway are all connection request packets, used by the SDP controller and SDP gateway to authenticate the SDP client. The SPA data packet mainly includes information such as username, password, and target service identifier. Before the operator station (SDP client) is authenticated and authorized, the SDP controller and SDP gateway will not respond to any connection requests. The two SPA data packet transmissions are sequential: the SPA data packet is sent to the SDP controller first. After successful authentication by the SDP controller, it sends the SDP gateway list to the operator station, which then sends the SPA data packet to the SDP gateway. This separates access control from the data channel, which helps to hide and protect data servers and infrastructure, thereby preventing potential network attacks.

[0032] Next, the operator station sends multimedia information to the server through the SDP gateway and using a two-way encrypted data channel. The server receives and stores the multimedia information sent by the operator station. The player receives the multimedia information sent by the server, combines it, and sends it to the display device. The display device is used to display the multimedia information sent by the player.

[0033] Because the SDP controller has policy management capabilities, it can group users and resources according to configuration and adjust user resource access permissions in real time based on the analysis results provided by risk assessment. The SDP controller's policy management function supports configuring different policies for different user groups, including roles, user groups, and accessible resources. Simultaneously, the SDP controller uses risk information provided by the environment awareness system to perform risk assessments on the operator station (SDP client) and dynamically adjusts policies based on the assessment results, thereby generating fine-grained access control policies. The SDP controller generates user access permissions based on user permissions and policy specifications, generates secure tunnel policies, and distributes them to the operator station and SDP gateway.

[0034] In some embodiments of the present invention, a timeout retransmission mechanism can be set at the operator station. Specifically, a timer and a time threshold are set at the operator station. The SDP security framework uses single-packet authorization and authentication technology. After the operator station sends an SPA data packet to the SDP controller, it starts its timer. When the timer value equals the time threshold, and the operator station has not received the SDP gateway list sent by the SDP controller, the operator station retransmits the SPA data packet to the SDP controller and resets the timer until successful transmission. In network communication, data packets may be lost or delayed due to network congestion, equipment failure, etc. Therefore, the present invention sets a timeout retransmission mechanism at the operator station (SDP client) to improve the reliability of data transmission. By reasonably configuring the timeout period, the efficiency and reliability of network transmission can be improved.

[0035] In some embodiments of the present invention, the information publishing system can push or modify information on the terminal display device in real time, and the implementation method is as follows:

[0036] Multimedia information (text, images, audio, video, etc.) stored on the server is sent to the player via the network. The player combines the various media information and then sends the combined information to a display device that can accept audio and video input to form an audio and video file for playback. This method facilitates information management, reduces workload, and improves work efficiency. Furthermore, it allows for timely handling of security incidents occurring on display devices.

[0037] One of the most critical and core components of the SDP architecture is the mandatory implementation of a "authenticate before connection" security model. In this invention, the SDP controller and SDP gateway will not respond to any connection requests until the operator station (SDP client) has been authenticated and authorized. This reduces the server's visibility to unauthorized entities, minimizes the attack surface, and thus reduces security risks.

[0038] In some embodiments of the present invention, the server's SDP gateway is set to drop all data packets, so that unauthorized operating stations cannot scan the server port.

Claims

1. An information publishing system based on Software-Defined Boundary (SDP), characterized in that, This includes SDP clients, SDP controllers, SDP gateways, servers, networks, players, and display devices; The SDP client is deployed on the operator station and sends SPA data packets to the SDP controller; The SDP controller receives and verifies the authentication information in the SPA data packet. After successful verification, it notifies the SDP gateway to accept the connection request from the operator station and sends the SDP gateway list to the operator station. The operator station sends SPA data packets to the SDP gateways in the list. After successful verification, a bidirectional encrypted connection is established. The operator station sends multimedia information to the server through an SDP gateway and using a bidirectional encrypted data channel. The server receives and stores the multimedia information sent by the operator station. The player receives the multimedia information sent by the server, combines it, and sends it to the display device. The display device is used to display the multimedia information sent by the player. The operator station first sends an SPA data packet to the SDP controller. The SPA data packet contains authentication information. After receiving the SPA data packet, the SDP controller verifies the authentication information in the data packet. After the operator station is verified, the SDP controller determines the list of SDP gateways that the operator station can connect to. The SDP controller notifies the SDP gateway to accept communication from the operator station. The SDP controller sends a list of SDP gateways to the operator station. The operator station sends SPA packets to the authorized SDP gateways. The SDP gateway verifies the SPA packets. After successful verification, the SDP client and these SDP gateways establish a two-way encrypted connection. The SDP controller determines the list of SDP gateways that the operator station can connect to, and the implementation method is as follows: The SDP controller groups users and resources according to their configurations and configures different policies for different user groups. That is, the SDP controller determines the resources that users can access based on their roles or user groups, and adjusts users' resource access permissions in real time based on the analysis results given by the risk assessment, generates security tunnel policies, and distributes them to SDP clients and SDP gateways.

2. The SDP-based information publishing system according to claim 1, characterized in that, Use SDP technology to control access to the server.

3. The SDP-based information publishing system according to claim 1, characterized in that, The operation station is used for user management, resource management, display device management, player management, and playback settings. It also edits, reviews, and publishes playback content, and provides unified management and control of the player.

4. The SDP-based information publishing system according to claim 1, characterized in that, A timeout retransmission mechanism is set up at the operator station. The SDP system uses single-packet authorization and authentication technology. After the operator station sends an SPA data packet to the SDP controller, it starts its timer. When the timer value equals the time threshold, and the operator station has not received the SDP gateway list sent by the SDP controller, the operator station retransmits the SPA data packet to the SDP controller until it is successfully sent.

5. The SDP-based information publishing system according to claim 1, characterized in that, The system can push or modify information on the terminal display device in real time. The method is as follows: The multimedia information stored on the server is sent to the player via the network. The player combines various media information and then sends the combined information to a display device that can accept audio and video input to form an audio and video file for playback.

6. The SDP-based information publishing system according to claim 1, characterized in that, The server's SDP gateway is set to drop all data packets, preventing unauthorized operating stations from scanning the server port.

7. The SDP-based information publishing system according to claim 1, characterized in that, The SDP controller and SDP gateway do not respond to any connection requests until the client is authenticated and authorized.

8. The information publishing method using the SDP-based information publishing system as described in claim 1, characterized in that, include: An SDP client is deployed on the operator station, and the SDP client sends SPA data packets to the SDP controller; The SDP controller receives and verifies the authentication information in the SPA data packet. After successful verification, it notifies the SDP gateway to accept the connection request from the operator station and sends the SDP gateway list to the operator station. The operator station sends SPA data packets to the SDP gateways in the list. After successful verification, a bidirectional encrypted connection is established. The operator station sends multimedia information to the server through an SDP gateway and using a bidirectional encrypted data channel. The server receives and stores the multimedia information, and the player receives the multimedia information sent by the server, combines it, and sends it to the display device. The multimedia information sent by the player is displayed on the display device.

Citation Information

Patent Citations

  • Network access method and device, equipment and storage medium

    CN113890767A

  • CoAP network security access method based on software defined boundary

    CN115834211A