A security protection method for an intelligent video surveillance system
By verifying firmware blockchain data in the video surveillance system and monitoring the network and device status during the firmware update process in real time, security risks and stability problems during the firmware update process are solved, and high security and stability updates of the video surveillance device cluster are achieved.
Patent Information
- Application Number
- CN202510142425.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-10
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-02-10
AI Technical Summary
The prior art has limitations in the equipment security protection of video surveillance systems, especially during firmware updates, it is difficult to effectively identify the source of firmware and prevent intrusion behavior, resulting in safety hazards and stability problems.
A security protection method for intelligent video surveillance system is proposed. By receiving unified firmware update instructions for video surveillance equipment clusters, the authenticity and integrity of the blockchain data of the firmware to be updated, and the network and equipment environment status is monitored in real time during the firmware update process, the potential risk coefficient is evaluated, corresponding control measures are taken, and stability and compatibility tests are finally carried out.
Effectively eliminate false or tampered firmware entering the update process, improve the security and stability of firmware updates, and ensure that the video surveillance equipment cluster can work together after firmware updates, and seamlessly connect to the existing monitoring system.
Smart Images

Figure CN119622674B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of video surveillance security protection, and relates to a security protection method for an intelligent video surveillance system. Background Art
[0002] With the rapid development of Internet of Things technology and artificial intelligence technology, intelligent video surveillance devices have been widely used in the fields of public security, traffic management, commercial surveillance, and personal property protection. However, the high degree of networking and popularity of these devices also bring new security challenges. Events such as cyberattacks, data leaks, and unauthorized access occur frequently, seriously threatening public and personal security and triggering widespread concern about privacy protection. Therefore, researching and implementing effective security protection methods for intelligent video surveillance systems has become an urgent problem to be solved currently.
[0003] In the prior art, there are also solutions related to the security protection of video surveillance systems. For example, a video surveillance system information security protection method and system with the Chinese patent publication number CN118158361A collects internal and external information of the video surveillance system through the internal and external information collection units of the security information collection module, generates an internal security information set and an external security information set, and performs associated calculations to obtain a comprehensive security information coefficient Zhxs. Through the authentication of multiple external security information, the security of the first - level protection is relatively improved when external information is logged in. At the same time, through the virus monitoring software and security scanning software set inside its video surveillance system, the internal environment of the video surveillance system can be monitored in real - time, thus ensuring the security of the video surveillance data storage environment and realizing a dual - system protection mechanism inside and outside.
[0004] Another video surveillance system based on a video security access path with the Chinese patent publication number CN108377365A includes several ports for information access or output. Each port forms a communication path through an open / closed network. The ports include a server port, several monitoring data input ports, and several other device ports. Among them, a gateway module A is set between the server port and the open / closed network, and a gateway module B is set between the open / closed network and the monitoring data input ports. Through the one - way comparison / verification / audit processing of information from gateway module A to gateway module B, an effective information transmission path between the server port and the monitoring data input ports is formed, realizing the classification of effective and invalid paths of network information transmission and one - way transmission locking, and achieving low - cost and high - security network protection.
[0005] However, there are still certain limitations in the existing technologies, which are specifically manifested as follows: The existing technologies focus on data security protection and network security protection of video surveillance systems, lacking the exploration of device security protection for video surveillance systems or only staying at the shallow physical security protection level. They fail to effectively consider the security risks existing in the process of regular firmware updates for video surveillance devices in video surveillance systems. For example, they cannot effectively identify whether the firmware source is legal and reliable, it is difficult to detect whether there is an intrusion behavior during the firmware update, which may cause abnormalities in the video working or network environment, and after the firmware update is completed, there is a complete lack of effective evaluation and countermeasures for the impact on the stability and compatibility of the device monitoring capabilities, undoubtedly posing huge potential risks to the safe and stable operation of video surveillance systems. Summary of the Invention
[0006] In view of this, to solve the problems raised in the above background technology, a security protection method for an intelligent video surveillance system is proposed.
[0007] The object of the present invention can be achieved through the following technical solutions: The present invention provides a security protection method for an intelligent video surveillance system, including: S1. Receive a unified firmware update instruction for a target video surveillance device cluster, verify the authenticity and integrity of the data associated with the firmware blockchain to be updated. If the verification passes, execute step S2; if the verification fails, reject the unified firmware update instruction.
[0008] S2. Start the firmware update process for the target video surveillance device cluster, and monitor the network environment status of the firmware update for the target video surveillance device cluster and the device environment status of the firmware update in real time during the firmware update process, and evaluate the potential risk coefficients of the firmware update partitions of the target video surveillance device cluster at each monitoring time point.
[0009] S3. Monitor the video surveillance working status of each video surveillance device in the target video surveillance device cluster in real time during the firmware update process, and evaluate the potential risk coefficients of the firmware working partitions of the target video surveillance device cluster at each monitoring time point.
[0010] S4. Synthesize the potential risk coefficients of the firmware working partitions and the firmware update partitions, evaluate the firmware update risk levels of the target video surveillance device cluster at each monitoring time point, and take corresponding control measures.
[0011] S5. After the unified firmware update of the target video surveillance device cluster is completed, conduct stability tests and compatibility tests on the target video surveillance device cluster, screen out each abnormal video surveillance device and place it in a security isolation mode and report it to the management center.
[0012] Compared with the prior art, the beneficial effects of the present invention are as follows: (1) Before the unified firmware update of the target video surveillance device cluster, the present invention verifies the authenticity and integrity of the data associated with the firmware blockchain to be updated, which not only effectively prevents false or tampered firmware from entering the update process, but also reduces problems such as update failures or device anomalies caused by data errors, greatly enhancing the security and stability of the firmware update of the video surveillance device cluster.
[0013] (2) During the unified firmware update process of the firmware video surveillance device cluster, the present invention comprehensively considers the potential risk coefficients of the firmware working partition and the firmware update partition, dynamically evaluates the firmware update risk level of the target video surveillance device cluster at each monitoring time point, and takes corresponding control measures to comprehensively and deeply understand the risk situation in the entire update process, greatly improving the security and controllability of the firmware update process of the video surveillance device cluster.
[0014] (3) After the unified firmware update of the firmware video surveillance device cluster is completed, the present invention conducts stability tests and compatibility tests on the target video surveillance device cluster to screen and report each abnormal video surveillance device. This not only helps improve the maintenance efficiency of the devices and reduce the maintenance cost, but also ensures that the video surveillance device cluster can work together after the firmware update, seamlessly connect to the existing monitoring system, and fully exert its due monitoring effectiveness. Description of the Drawings
[0015] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0016] Figure 1 It is a flowchart of the method implementation steps of the present invention.
[0017] Figure 2 It is a logical schematic diagram for evaluating the potential risk coefficient of the firmware update partition of the target video surveillance device cluster at each monitoring time point in step S2 of the present invention.
[0018] Figure 3 It is a logical schematic diagram for screening each abnormal video surveillance device in step S5 of the present invention. Detailed Embodiments
[0019] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0020] Please refer to Figure 1 As shown, the present invention provides a security protection method for an intelligent video surveillance system, including: S1. Receive a unified firmware update instruction for a target video surveillance device cluster, verify the authenticity and integrity of the data associated with the firmware blockchain to be updated. If the verification passes, execute step S2; if the verification fails, reject the unified firmware update instruction.
[0021] It should be noted that the above-mentioned target video surveillance device cluster specifically refers to an integrated group composed of each video surveillance device within the same target video surveillance system. Among them, the video surveillance device adopts a dual-partition design, so that it can still continuously execute video surveillance tasks during the firmware update process.
[0022] Specifically, the verification of the authenticity and integrity of the data associated with the firmware blockchain to be updated includes: performing digital signature verification and hash value verification on the final node of the firmware blockchain to be updated. If both the digital signature and the hash value are verified successfully, output the authenticity verification index of the data associated with the firmware blockchain to be updated as 1; otherwise, output 0.
[0023] It should be noted that the above hash value verification process is as follows: Use an existing mature hash algorithm, such as SHA-256, to calculate the content of the firmware to be updated to convert it into a hash value of a fixed length, and compare it with the reference hash value carried by the firmware blockchain to be updated. If the two are exactly the same, it means that the hash value verification is successful; if the two are different, it means that the hash value verification fails.
[0024] The above digital signature verification process includes a hash value verification process, that is, the reference hash value carried by the firmware blockchain to be updated is obtained by decrypting the digital signature carried by the firmware blockchain to be updated with the public key of the publisher. The successful digital signature verification also includes the verification of the public key of the publisher, and it is necessary to check the validity period of the public key certificate, the integrity of the certificate chain, and whether it has been revoked. If the hash value verification is successful and the public key verification is successful, it means that the digital signature verification is successful; otherwise, it means that the digital signature verification fails.
[0025] According to the hash pointer carried by the end node of the firmware blockchain to be updated, perform an upward node tracing operation, and verify one by one whether the memory hash value of the hash pointer of each node is consistent with the hash value calculated corresponding to the data content of its previous node. If there is an inconsistency, output that the integrity verification index of the data associated with the firmware blockchain to be updated is 0. If there is no inconsistency, count the identifiers of each tracing node of the firmware blockchain to be updated, and compare them with the preset authorized node white list for firmware update operations of the target video surveillance device cluster stored in the WEB cloud. If the identifiers of each tracing node of the firmware blockchain to be updated are all within the authorized node white list for firmware update operations of the target video surveillance device cluster, output that the integrity verification index of the data associated with the firmware blockchain to be updated is 1.
[0026] Specifically, the conditions for verifying the authenticity and integrity of the data associated with the firmware blockchain to be updated are that the output verification indexes for the authenticity and integrity of the data associated with the firmware blockchain to be updated are both 1.
[0027] Before the unified firmware update of the target video surveillance device cluster in the embodiment of the present invention, verifying the authenticity and integrity of the data associated with the firmware blockchain to be updated not only effectively prevents false or tampered firmware from entering the update process, but also reduces problems such as update failures or device anomalies caused by data errors, greatly enhancing the security and stability of the firmware update of the video surveillance device cluster.
[0028] S2. Start the firmware update process of the target video surveillance device cluster, and during the firmware update process, monitor the network environment status and firmware update device environment status of the target video surveillance device cluster in real time, and evaluate the potential risk coefficient of the firmware update partition of the target video surveillance device cluster at each monitoring time point.
[0029] Please refer to Figure 2 As shown, specifically, evaluating the potential risk coefficient of the firmware update partition of the target video surveillance device cluster at each monitoring time point includes: using the time span between adjacent monitoring time points as the inspection period corresponding to the later monitoring time point in terms of time sequence.
[0030] Collect the number of connection interruptions, network bandwidth occupancy rate, network latency, network jitter, and network packet loss rate of the firmware update network of the target video surveillance device cluster during the inspection period corresponding to each monitoring time point during the firmware update process, and compare them with the preset connection interruption number permission threshold, network bandwidth occupancy rate reasonable range, network latency permission threshold, network jitter permission threshold, and network packet loss rate permission threshold of the firmware update network specification standard stored in the WEB cloud to analyze the potential risk degree of the firmware update network environment of the target video surveillance device cluster at each monitoring time point , where is the number of each monitoring time point, .
[0031] Collect the update progress, the number of update breakpoints, the positions of each update breakpoint, and the resume transmission response duration of each video surveillance device in the target video surveillance device cluster during the inspection period corresponding to each monitoring time point during the firmware update process, and analyze the potential risk degree of the firmware update device environment of the target video surveillance device cluster at each monitoring time point 。
[0032] Accumulate the potential risk degrees of the firmware update network environment and the firmware update device environment of the target video surveillance device cluster at each monitoring time point to obtain the potential risk coefficient of the firmware update partition of the target video surveillance device cluster at each monitoring time point.
[0033] Specifically, the specific analysis process includes: separately obtaining the ratio of the number of connection interruptions, network bandwidth occupancy rate, network latency, network jitter, and network packet loss rate of the firmware update network of the target video surveillance device cluster during the inspection period corresponding to each monitoring time point during the firmware update process to the over-specification standard, and accumulating them to obtain the potential risk degree of the firmware update network environment of the target video surveillance device cluster at each monitoring time point.
[0034] It should be noted that the methods for obtaining the ratios of the number of connection interruptions, network latency, network jitter, and network packet loss rate of the firmware update network of the target video surveillance device cluster during the inspection period corresponding to each monitoring time point during the firmware update process to the over-specification standard are the same. Taking the ratio of the number of connection interruptions to the over-specification standard as an example, it mainly involves subtracting the number of connection interruptions of the firmware update network of the target video surveillance device cluster during the inspection period corresponding to each monitoring time point during the firmware update process from the preset connection interruption number permission threshold of the firmware update network specification standard, comparing the calculated difference with 0. If the calculated difference is greater than 0, then the calculated difference is further subjected to ratio analysis with the preset connection interruption number permission threshold of the firmware update network specification standard to obtain the ratio of the number of connection interruptions to the over-specification standard. Conversely, if the calculated difference is less than or equal to 0, then the ratio of the number of connection interruptions to the over-specification standard is directly set to 0, thereby obtaining the ratio of the number of connection interruptions of the firmware update network of the target video surveillance device cluster during the inspection period corresponding to each monitoring time point during the firmware update process to the over-specification standard.
[0035] The specific analysis process of the ratio of the network bandwidth occupancy rate of the firmware update network of the target video surveillance device cluster exceeding the specification standard during each monitoring time point in the above firmware update process is as follows: Extract the upper limit value and the lower limit value of the reasonable range of the network bandwidth occupancy rate preset in the firmware update network specification standard for average calculation to obtain the reasonable reference network bandwidth occupancy rate preset in the firmware update network specification standard. Subtract the lower limit value of the reasonable range of the network bandwidth occupancy rate from the reasonable reference network bandwidth occupancy rate preset in the firmware update network specification standard to obtain the reasonable deviation network bandwidth occupancy rate preset in the firmware update network specification standard. Subtract the network bandwidth occupancy rate of the firmware update network of the target video surveillance device cluster during each monitoring time point in the corresponding inspection period from the reasonable reference network bandwidth occupancy rate preset in the firmware update network specification standard. Further perform ratio analysis on the calculated difference result with the reasonable deviation network bandwidth occupancy rate preset in the firmware update network specification standard. Further compare the calculated difference between the ratio analysis result and 1 with 0. If the calculated difference is greater than 0, then use the calculated difference as the ratio of the network bandwidth occupancy rate exceeding the specification standard. If the calculated difference is less than or equal to 0, then set the ratio of the network bandwidth occupancy rate exceeding the specification standard to 0. Thus, the ratio of the network bandwidth occupancy rate of the firmware update network of the target video surveillance device cluster exceeding the specification standard during each monitoring time point in the corresponding inspection period is obtained.
[0036] Specifically, the specific analysis process includes: Retrieving the maximum difference update process among the video surveillance devices in the target video surveillance device cluster during each monitoring time point in the corresponding inspection period of the firmware update process, and comparing it with the preset permission difference update process among the video surveillance devices stored in the WEB cloud. If the comparison relationship is less than or equal to, then output that the continuous risk degree of the impact process of the firmware update device environment of the target video surveillance device cluster is 0. If the comparison relationship is greater than, then output that the continuous risk degree of the impact process of the firmware update device environment of the target video surveillance device cluster is 1. Thus, the continuous risk degree of the impact process of the firmware update device environment of the target video surveillance device cluster at each monitoring time point is output.
[0037] Based on the number of update breakpoints of each video surveillance device in the target video surveillance device cluster during each monitoring time point in the corresponding inspection period of the firmware update process , where is the number of each video surveillance device in the target video surveillance device cluster, , is the number of each update breakpoint, , obtain the preset influence weights corresponding to the positions of each unit at each point in the firmware update process of the video surveillance device stored in the WEB cloud, and obtain the preset influence weights corresponding to the positions of each update breakpoint of each video surveillance device in the target video surveillance device cluster during the firmware update process for each inspection period corresponding to each monitoring time point. , from the formula output the stable risk degree of the influence process of the firmware update device environment of the target video surveillance device cluster at each monitoring time point, where is the number of update breakpoints, is the number of video surveillance devices in the target video surveillance device cluster, are respectively the preset permitted number of update breakpoints and the preset reasonable resume transmission response duration threshold during the firmware update process of the video surveillance devices in the target video surveillance device cluster stored in the WEB cloud.
[0038] Take the cumulative value of the continuous risk degree of the influence process and the stable risk degree of the influence process as the potential risk degree, and thus obtain the potential risk degree of the firmware update device environment of the target video surveillance device cluster at each monitoring time point.
[0039] S3. During the firmware update process, real-time monitor the video surveillance working status of each video surveillance device in the target video surveillance device cluster, and evaluate the potential risk coefficient of the firmware working partition of the target video surveillance device cluster at each monitoring time point.
[0040] Specifically, the evaluation of the potential risk coefficient of the firmware working partition of the target video surveillance device cluster at each monitoring time point includes: retrieving the working monitoring videos of each video surveillance device in the target video surveillance device cluster during the inspection period corresponding to each monitoring time point, and analyzing the display parameters of the working monitoring videos, including the normal display video frame ratio , the comparison video corner area of each normal display video frame , image resolution , image brightness and image contrast , where is the number of each normal display video frame, , analyze the working monitoring video acquisition quality coefficient of each video surveillance device in the target video surveillance device cluster during the inspection period corresponding to each monitoring time point, compare it with the preset standard working monitoring video acquisition quality coefficient compliance threshold stored in the WEB cloud, count the number of video surveillance devices in the target video surveillance device cluster whose working monitoring video acquisition quality fails to meet the standard during the inspection period corresponding to each monitoring time point, and perform a ratio analysis with the total number of video surveillance devices in the target video surveillance device cluster to obtain the potential risk coefficient of the firmware working partition of the target video surveillance device cluster at each monitoring time point.
[0041] It should be noted that the specific analysis formula for the working monitoring video acquisition quality coefficient of each video monitoring device in the target video monitoring device cluster corresponding to each monitoring time point within the inspection period is as follows: , where is the number of video frames displayed normally, are respectively the standard comparison video corner area, standard image resolution, standard image brightness, and standard image contrast preset by the working monitoring video display specification of the video monitoring devices in the target video monitoring device cluster stored in the WEB cloud.
[0042] S4. Combine the potential risk coefficients of the firmware working partition and the firmware update partition, evaluate the firmware update risk level of the target video monitoring device cluster at each monitoring time point, and take corresponding control measures.
[0043] Specifically, evaluating the firmware update risk level of the target video monitoring device cluster at each monitoring time point includes: accumulating the products of the potential risk coefficients of the firmware working partition and the firmware update partition of the target video monitoring device cluster at each monitoring time point and their corresponding preset weights respectively to obtain the firmware update comprehensive risk coefficient of the target video monitoring device cluster at each monitoring time point.
[0044] According to the firmware update comprehensive risk coefficient intervals corresponding to the high, medium, and low risk levels preset for the firmware update of the target video monitoring device cluster stored in the WEB cloud, classify the interval where the firmware update comprehensive risk coefficient of the target video monitoring device cluster at each monitoring time point is located to evaluate the firmware update risk level of the target video monitoring device cluster at each monitoring time point.
[0045] It should be noted that the specific process of taking corresponding control measures for the firmware update risk level of the target video monitoring device cluster at each monitoring time point is as follows: If the firmware update risk level of the target video monitoring device cluster at a certain monitoring time point is a low risk level, continue the firmware update process, but increase the monitoring frequency; if the firmware update risk level of the target video monitoring device cluster at a certain monitoring time point is a medium risk level, suspend the firmware update process, and each video monitoring device in the target video monitoring device cluster conducts a detailed self-check of the current state and generates a report to upload to the management center; if the firmware update risk level of the target video monitoring device cluster at a certain monitoring time point is a high risk level, immediately terminate the firmware update and start the device's security rollback mechanism to restore the device firmware to the stable version before the update.
[0046] In the embodiment of the present invention, during the unified firmware update process of the firmware video surveillance device cluster, the potential risk coefficients of the firmware working partition and the firmware update partition are comprehensively considered, and the firmware update risk level of the target video surveillance device cluster at each monitoring time point is dynamically evaluated, so as to take corresponding control measures, comprehensively and deeply understand the risk situation in the entire update process, and greatly improve the security and controllability of the firmware update process of the video surveillance device cluster.
[0047] Please refer to Figure 3 As shown in the figure, after the unified firmware update of the target video surveillance device cluster is completed, stability testing and compatibility testing are performed on the target video surveillance device cluster, and each abnormal video surveillance device among them is screened and placed in the security isolation mode and reported to the management center.
[0048] Specifically, the stability testing and compatibility testing of the target video surveillance device cluster include: sending stability self-test data packets and compatibility self-test data packets to each video surveillance device in the target video surveillance device cluster, where the stability self-test data packet contains video stream simulation data, network pressure simulation data, and control instruction test data, and the compatibility self-test data packet contains storage device identification instruction data and operation unit identification instruction data, parsing the stability self-test performance and compatibility self-test performance of each video surveillance device in the target video surveillance device cluster, and outputting the stable operation level index and compatible operation level index of each video surveillance device in the target video surveillance device cluster after the firmware update, so as to achieve the stability testing and compatibility testing of the target video surveillance device cluster.
[0049] It should be noted that the above video stream simulation data includes video streams under various video configuration parameter combinations, where each video configuration parameter combination is mainly randomly combined by each preset resolution, each preset frame rate, and each preset coding format. Exemplarily, each preset resolution is such as 720p, 1080p, 4K, each preset frame rate is such as 15fps, 30fps, 60fps, and each coding format is such as H.264, H.265. The network pressure simulation data includes network pressure scenarios under various network configuration parameter combinations, where each network configuration parameter combination is mainly randomly combined by each preset network bandwidth, each preset network delay, and each preset network packet loss rate. Exemplarily, each preset network bandwidth is such as 1Mbps, 10Mbps, 100Mbps, each preset network delay is such as 100ms, 500ms, 1000ms, and each preset network packet loss rate is such as 1%, 5%, 10%. The control instruction test data includes various device control function instructions, such as pan-tilt control instructions, video parameter adjustment instructions, video recording instructions, and video playback instructions.
[0050] The above storage device identification instruction data includes various storage device simulated driver interface data. The various storage devices include SATA hard disks, NVMe solid-state drives, and network storage devices. The operation unit identification instruction data includes various operation unit simulated call data. The various operation units include Linux and Windows Embedded.
[0051] It should also be noted that the specific output process of the stable operation level indicators of each video surveillance device in the above target video surveillance device cluster after firmware update is as follows: After each video surveillance device in the target video surveillance device cluster receives the stability self-test data packet, it collects the test performance content of each video surveillance device for video stream simulation data, including the smoothness index and display quality index of playing the video stream under each video configuration parameter combination. The cumulative value of the smoothness index and the display quality index is used as the basic stable playback index. The product of the basic stable playback index of the video stream under each video configuration parameter combination and its corresponding preset weight is accumulated respectively to obtain the stable playback index of each video surveillance device for video stream simulation data. It should be particularly noted that the above smoothness index mainly examines the actual frame rate fluctuation degree, the actual playback stuttering degree, and the actual number of dropped frames, and the display quality index mainly examines the number of times the playback screen has a mosaic and the area ratio of each mosaic.
[0052] Collect the test performance content of each video surveillance device for network pressure simulation data, including the connection stability, data transmission accuracy, and data transmission integrity of running the network pressure scenario under each network configuration parameter combination. The cumulative value of the connection stability, data transmission accuracy, and data transmission integrity is used as the basic network operation stability index. The product of the basic network operation stability index under each network configuration parameter combination and its corresponding preset weight is accumulated respectively to obtain the stable operation index of each video surveillance device for network pressure simulation data.
[0053] Collect the test performance content of each video surveillance device for control instruction test data, including the response timeliness and response accuracy for various device control function instructions. The cumulative value of the response timeliness and response accuracy is used as the basic response stability index. The product of the basic response stability index of various device control function instructions and its corresponding preset weight is accumulated respectively to obtain the stable response index of each video surveillance device for control instruction test data.
[0054] The stable playback index of each video surveillance device for video stream simulation data, the stable operation index for network pressure simulation data, and the stable response index for control instruction test data are accumulated and normalized to output the stable operation level indicators of each video surveillance device in the target video surveillance device cluster after firmware update.
[0055] The specific output process of the compatible operation level indicators of each video surveillance device in the above-mentioned target video surveillance device cluster after firmware update is as follows: After each video surveillance device in the target video surveillance device cluster receives the compatibility self-test data packet, it collects the test performance content of each video surveillance device for the storage device identification instruction data, including the connection success rate, identification success rate, and data read / write operation accuracy for the analog driver interface data of various storage devices. The product of the connection success rate, identification success rate, and data read / write operation accuracy is used as the basic driver compatibility indicator. The products of the basic driver compatibility indicators of the analog driver interface data of various storage devices and their corresponding preset weights are accumulated respectively to obtain the test compatibility indicators of each video surveillance device for the storage device identification instruction data.
[0056] Collect the test performance content of each video surveillance device for the operation unit identification instruction data, including the normal response degree and normal operation degree for the analog call data of various operation units. The product of the normal response degree and normal operation degree is used as the basic operation compatibility indicator. The products of the basic operation compatibility indicators of the analog call data of various operation units and their corresponding preset weights are accumulated respectively to obtain the test compatibility indicators of each video surveillance device for the operation unit identification instruction data.
[0057] Accumulate and standardize the test compatibility indicators of each video surveillance device for the storage device identification instruction data and the operation unit identification instruction data to output the compatible operation level indicators of each video surveillance device in the target video surveillance device cluster after firmware update.
[0058] Specifically, the screening conditions for each abnormal video surveillance device are that the stable operation level indicator after firmware update is less than the preset benchmark stable operation level indicator compliance threshold stored in the WEB cloud or the compatible operation level indicator is less than the preset benchmark compatible operation level indicator compliance threshold stored in the WEB cloud.
[0059] After the unified firmware update of the firmware video surveillance device cluster in the embodiment of the present invention, stability testing and compatibility testing are performed on the target video surveillance device cluster to screen and report each abnormal video surveillance device, which not only helps to improve the maintenance efficiency of the device and reduce the maintenance cost, but also ensures that the video surveillance device cluster can work together after firmware update, seamlessly connect to the existing monitoring system, and fully exert its due monitoring effectiveness.
[0060] The above content is only an example and explanation of the concept of the present invention. Those skilled in the art of this technology can make various modifications, supplements, or use similar methods to replace the specific embodiments described, as long as they do not deviate from the concept of the invention or exceed the scope defined by the present invention, they should all belong to the protection scope of the present invention.
Claims
1. A security protection method for an intelligent video surveillance system, characterized in that: include: S1. Receive the unified firmware update instruction of the target video surveillance device cluster, verify the authenticity and integrity of the data associated with the firmware blockchain to be updated, and if the verification passes, execute step S2; if the verification fails, reject the unified firmware update instruction; S2. Start the firmware update process of the target video surveillance device cluster, monitor the network environment status and the firmware update device environment status of the target video surveillance device cluster in real time during the firmware update process, and evaluate the potential risk factor of the firmware update partition of the target video surveillance device cluster at each monitoring time point; S3. Real-time monitoring of the video surveillance working status of each video surveillance device in the target video surveillance device cluster during the firmware update process, and evaluation of the potential risk factor of the target video surveillance device cluster firmware work partition at each monitoring time point; The time span between adjacent monitoring time points is taken as the inspection period corresponding to the later monitoring time point in the time series; Collect the number of connection interruptions, network bandwidth occupancy, network delay, network jitter and network packet loss rate of the target video surveillance equipment cluster firmware update network during the inspection period at each monitoring time point during the firmware update process, and compare them with the connection interruption number allowance threshold, network bandwidth occupancy reasonable range, network delay allowance threshold, network jitter allowance threshold and network packet loss rate allowance threshold preset in the firmware update network specification standard stored in the WEB cloud, and analyze the potential risk of the target video surveillance equipment cluster firmware update network environment at each monitoring time point ,in is the number of each monitoring time point, ; Collect the update progress, update breakpoint times, location of each update breakpoint and response time of each video surveillance device in the target video surveillance device cluster during the inspection period at each monitoring time point during the firmware update process, and analyze the potential risk of the firmware update device environment of the target video surveillance device cluster at each monitoring time point ; Will and The potential risk coefficient of the firmware update partition of the target video surveillance device cluster at each monitoring time point is accumulated; S4. Comprehensively consider the potential risk factors of the firmware working partition and the firmware update partition, assess the firmware update risk level of the target video surveillance device cluster at each monitoring time point, and take corresponding control measures; S5. After the unified firmware update of the target video surveillance device cluster is completed, stability test and compatibility test are performed on the target video surveillance device cluster, and each abnormal video surveillance device is screened, placed in a safe isolation mode and reported to the management center.
2. The intelligent video surveillance system security protection method according to claim 1, characterized in that: The verification of the authenticity and integrity of the data associated with the blockchain of the firmware to be updated includes: performing digital signature verification and hash value verification on the terminal node of the blockchain of the firmware to be updated, and if both the digital signature and the hash value are verified successfully, the authenticity verification index of the data associated with the blockchain of the firmware to be updated is output as 1, otherwise the output is 0; According to the hash pointer carried by the terminal node of the blockchain of the firmware to be updated, the upward node tracing operation is performed, and the hash value of the hash pointer memory of each node is verified one by one to see if it is consistent with the calculated hash value corresponding to the data content of the previous node. If there is any inconsistency, the integrity verification index of the data associated with the blockchain of the firmware to be updated is output as 0. If there is no inconsistency, the identifiers of the traceability nodes in the blockchain of the firmware to be updated are counted and compared with the preset authorized node whitelist of the target video surveillance device cluster firmware update operation stored in the WEB cloud. If the identifiers of the traceability nodes in the blockchain of the firmware to be updated are all in the authorized node whitelist of the target video surveillance device cluster firmware update operation, the integrity verification index of the data associated with the blockchain of the firmware to be updated is output as 1.
3. The intelligent video surveillance system security protection method according to claim 2, characterized in that: The authenticity and integrity verification of the data associated with the to-be-updated firmware blockchain passes the condition that the output verification indicators of the authenticity and integrity of the data associated with the to-be-updated firmware blockchain are both 1.
4. The intelligent video surveillance system security protection method according to claim 1, characterized in that: Said The specific analysis process includes: obtaining the number of connection interruptions, network bandwidth occupancy, network delay, network jitter and network packet loss rate of the target video surveillance device cluster firmware update network during the inspection period at each monitoring time point during the firmware update process, and the corresponding excess standard ratios, and accumulating them to obtain the potential risk degree of the target video surveillance device cluster firmware update network environment at each monitoring time point.
5. The intelligent video surveillance system security protection method according to claim 1, characterized in that: Said The specific analysis process includes: retrieving the maximum difference update process between the video surveillance devices in the target video surveillance device cluster during the inspection period at each monitoring time point during the firmware update process, comparing it with the preset permission difference update process between the video surveillance devices stored in the WEB cloud, and outputting the continuous risk degree of the impact process of the firmware update device environment of the target video surveillance device cluster at each monitoring time point; According to the update breakpoint times, positions of each update breakpoint and the response time of the retransmission of each video surveillance device in the target video surveillance device cluster during the inspection period corresponding to each monitoring time point during the firmware update process, the impact process stability risk of the firmware update device environment of the target video surveillance device cluster at each monitoring time point is output; The accumulated value of the risk affecting the continuity of the process and the risk affecting the stability of the process is taken as the potential risk, thereby obtaining the potential risk of the firmware update device environment of the target video surveillance device cluster at each monitoring time point.
6. The intelligent video surveillance system security protection method according to claim 4, characterized in that: The method for evaluating the potential risk coefficient of the firmware working partition of the target video surveillance device cluster at each monitoring time point includes: retrieving the working surveillance video of each video surveillance device in the target video surveillance device cluster within the inspection period corresponding to each monitoring time point, parsing the display parameters of the working surveillance video, including the normal display video frame rate ratio, the comparison video angle area of each normal display video frame, the image resolution, the image brightness and the image contrast, analyzing the working surveillance video acquisition quality coefficient of each video surveillance device in the target video surveillance device cluster within the inspection period corresponding to each monitoring time point, comparing it with the preset standard working surveillance video acquisition quality coefficient reaching threshold of the target video surveillance device cluster stored in the WEB cloud, counting the number of video surveillance devices in the target video surveillance device cluster whose working surveillance video acquisition quality does not reach the standard within the inspection period corresponding to each monitoring time point, and performing ratio analysis with the total number of video surveillance devices in the target video surveillance device cluster to obtain the potential risk coefficient of the firmware working partition of the target video surveillance device cluster at each monitoring time point.
7. The intelligent video surveillance system security protection method according to claim 6, characterized in that: The step of assessing the firmware update risk level of the target video surveillance device cluster at each monitoring time point includes: accumulating the potential risk coefficients of the firmware working partition and the firmware update partition of the target video surveillance device cluster at each monitoring time point and multiplying them by their corresponding preset weights to obtain the comprehensive firmware update risk coefficient of the target video surveillance device cluster at each monitoring time point; According to the preset high, medium and low risk levels of the target video surveillance device cluster firmware update stored in the WEB cloud, the firmware update comprehensive risk coefficient intervals are respectively corresponded, and the firmware update comprehensive risk coefficient of the target video surveillance device cluster at each monitoring time point is arranged in the interval to assess the firmware update risk level of the target video surveillance device cluster at each monitoring time point.
8. The intelligent video surveillance system security protection method according to claim 1, characterized in that: The stability test and compatibility test for the target video surveillance device cluster include: sending a stability self-test data packet and a compatibility self-test data packet to each video surveillance device in the target video surveillance device cluster, wherein the stability self-test data packet contains video stream simulation data, network pressure simulation data and control instruction test data, and the compatibility self-test data packet contains storage device identification instruction data and operation unit identification instruction data, parsing the stability self-test performance and compatibility self-test performance of each video surveillance device in the target video surveillance device cluster, and outputting the stable operation level index and compatible operation level index of each video surveillance device in the target video surveillance device cluster after the firmware is updated, so as to realize the stability test and compatibility test of the target video surveillance device cluster.
9. The intelligent video surveillance system security protection method according to claim 8, characterized in that: The screening condition for each abnormal video surveillance device is that the stable operation level index after the firmware update is less than the preset benchmark stable operation level index reaching the standard threshold of the WEB cloud storage or the compatible operation level index is less than the preset benchmark compatible operation level index reaching the standard threshold of the WEB cloud storage.
Citation Information
Patent Citations
Video monitoring system based on video safety access path
CN108377365A
Video monitoring system information security protection method and system
CN118158361A
Firmware updating method, unit and equipment and storage medium
CN117908937A
Baseboard management controller cluster firmware upgrading method, product, equipment and medium
CN118484219A