Video conference system intercommunication signaling transmission method in network isolation environment

By configuring firewall, VPN tunnel, DMZ and other technologies in the video conferencing system and establishing an identity authentication system, the security and stability of signaling transmission in a network isolation environment are solved, and the secure, reliable and efficient signaling transmission of the video conferencing system is achieved.

CN119995924AActive Publication Date: 2025-05-13STATE GRID INFORMATION & TELECOMM BRANCH
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202411910181.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-24
Publication Date
2025-05-13
Estimated Expiration
2044-12-24

Smart Images

  • Figure CN119995924A_ABST
    Figure CN119995924A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of signal processing, and discloses a signaling transmission method for intercommunication of a video conference system in a network isolation environment, which comprises the following steps: configuring the network isolation environment, and distributing an independent address and a port for the video conference system; deploying a video conference system; establishing an identity verification system; conference details are created and set through the management system, and a safety invitation signaling is generated and sent to the predicted participant terminal; participants log in through the conference terminal and provide identity verification information; monitoring the states of participants in real time; signaling of the video conference content is transmitted to conference participant terminals through an encryption technology, and cell time delay evaluation is carried out; and the conference server detects an abnormal behavior and triggers an alarm. Signaling is filtered and limited through network isolation technologies such as a firewall or a VPN, and communication faults are reduced; the signaling is encrypted, so that data leakage or tampering is prevented; the decryption and decoding processes are fast and efficient, and real-time playing of video and audio contents is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of signal processing technology, and more specifically, to a signaling transmission method for intercommunication of video conferencing systems in a network isolation environment. Background Art

[0002] In a network isolation environment, the security of the video conferencing system is particularly important. As part of the video conferencing system, signaling transmission also needs to have corresponding security measures. Through security mechanisms such as encryption and authentication, the security and privacy of signaling transmission can be ensured to prevent sensitive information from being leaked or tampered with. Signaling is the key to the interoperability of video conferencing systems. In a network isolation environment, video conferencing systems need to use signaling to establish, maintain, and terminate connections. The accuracy and timeliness of signaling transmission directly affect the stability and reliability of the video conferencing system. If there is a problem with signaling transmission, it may result in the inability to establish a connection, reduced call quality, and call interruption.

[0003] The document with the prior art publication number CN110213029A provides a signaling transmission method. The method includes: the host device sends a communication instruction to N slave devices in a transmission time slot; the host device receives information sent by each slave device through at least one fixed delay in the first receiving time slot to the Nth receiving time slot. The communication instruction is sent to N slave devices in the transmission time slot, and the information sent by each slave device is received through at least one fixed delay in the first receiving time slot to the Nth receiving time slot. The signaling transmission method allows one host device to support any number of slave devices, and up to N slave devices can speak at the same time.

[0004] Although the above-mentioned prior art solutions can achieve relevant beneficial effects through the structure of the prior art, they still have the following defects: 1. Communication security issues: The communication between video conferencing systems may not be strictly controlled, and there is a risk of illegal intrusion and data leakage. The signaling may not be encrypted during the transmission process, which makes the signaling data easy to be stolen or tampered with. 2. The lack of an effective identity authentication system allows illegal participants to sneak into the meeting, reducing the security of the meeting. 3. Communication instability issues: The communication path is unclear, which increases the risk of communication failure. The conference server cannot monitor the status of the participants in real time, affecting the smooth progress of the meeting. 4. Insufficient signaling filtering and restriction: During the signaling transmission process, there is a lack of effective filtering and restriction of network isolation technologies such as firewalls or VPNs, which leads to the passage of illegal signaling and increases the possibility of communication failures. Even if the signaling is encrypted, the configuration of the firewall and VPN may not be perfect enough to effectively prevent the entry of illegal signaling or attacks.

[0005] In view of this, we propose a signaling transmission system and method for intercommunication between video conferencing systems in a network isolation environment. Summary of the invention

[0006] 1. Technical issues to be solved

[0007] The purpose of this application is to provide a signaling transmission method for intercommunication of video conferencing systems in a network isolation environment, solve the technical problems raised in the above-mentioned background technology, and realize strict control of communication between video conferencing systems by using firewalls, VPN tunnels, DMZ and other technologies, effectively preventing illegal intrusion and data leakage; through the identity authentication system, ensure that only legal participants can join the meeting, improve the security of the meeting; in the process of signaling transmission, filter and restrict signaling through network isolation technologies such as firewalls or VPNs, ensure that only legal signaling can pass, and reduce communication failures. The signaling is encrypted to prevent data leakage or tampering; the decryption and decoding process is fast and efficient, ensuring the technical effect of real-time playback of video and audio content.

[0008] 2. Technical solution

[0009] The technical solution of the present application provides a signaling transmission method for intercommunication of video conferencing systems in a network isolation environment, comprising the following steps:

[0010] S1. Configure network isolation environment: Establish network isolation boundaries, use advanced firewall technology, deep packet inspection (DPI) and behavior-based threat detection (BTD) systems to ensure that communication between video conferencing systems is strictly controlled. Use SDN (software defined network) technology to achieve dynamic allocation and configuration of network resources to ensure that the video conferencing system can flexibly adapt to different network environments and needs. Allocate independent IP addresses and ports to each video conferencing system, use IPv6 address space, and increase address richness and security.

[0011] S2. Deployment of video conferencing system: Deploy the video conferencing system in each subnet or area of ​​the network isolation environment, including conference servers, conference terminals and other components. Ensure that the network connection between the video conferencing systems is normal, and configure the necessary network isolation and access control policies. Use containerization technology and Kubernetes cluster management to achieve rapid deployment and automatic expansion of the video conferencing system. Combined with micro-isolation technology, provide fine-grained access control policies for each component of the video conferencing system.

[0012] S3. Establish an identity authentication system: Establish an identity authentication system that contains key data such as the image information, identity information, expected meeting time, etc. of the participants. Ensure data synchronization and real-time update between the identity authentication system and the video conferencing system.

[0013] S4. Meeting creation and invitation sending: The meeting organizer creates a meeting through the video conference management system and sets the meeting details, including the list of participants, meeting time, etc. The system generates a meeting invitation signal and sends it to the meeting terminals of the expected participants through a secure communication channel.

[0014] S5. Authentication of participants: After receiving the conference invitation, participants log in to the video conferencing system through the conference terminal. The system requires participants to provide authentication information, such as user name, password, biometrics (such as facial recognition), etc. The conference terminal collects the image information of the participants and sends it to the authentication system for comparison. The authentication system compares the image information of the participants with the information stored in the database to confirm whether the identities match. If the authentication system confirms that the identity of the participant matches, it allows them to join the meeting and grants them the corresponding meeting rights. If the authentication system finds that the participant does not match the expected person, it immediately refuses to allow them to join the meeting and notifies the meeting organizer and relevant managers.

[0015] S6. Conference status monitoring: The conference server monitors the status of participants in real time, including whether they are online, speaking, or leaving the meeting.

[0016] S7, signaling transmission: The conference server transmits the video conference content to the conference terminals of all participants through signaling to ensure the real-time and accuracy of the information. During the signaling transmission process, encryption technology (such as TLS / SSL) is used to encrypt the signaling to ensure the security of the signaling during transmission. The signaling is filtered and restricted through network isolation technologies such as firewalls or VPNs to ensure that only legal signaling can pass. The cell delay autocorrelation evaluation is performed.

[0017] S8. Abnormal handling and alarm: If the conference server detects abnormal behavior of the participants, the alarm mechanism will be triggered immediately. The system records the relevant information of the abnormal behavior and notifies the conference organizer and relevant managers to handle it.

[0018] S9, End of meeting and release of resources: When the meeting ends, the conference server sends a conference end signal to the conference terminals of all participants. After receiving the end signal, the conference terminals of the participants release local resources and exit the meeting. The conference server releases the conference resources and updates the conference status information in the database. The system records key information during the meeting (such as the list of participants, meeting duration, abnormal behavior, etc.) and stores it in the log file for subsequent audit and analysis.

[0019] The above technical solution can ensure the security, reliability and efficiency of signaling transmission between video conferencing systems in a network isolation environment. At the same time, it also provides a safe and controllable video conferencing environment for participants, and realizes the identity verification of participants and real-time monitoring of the conference status.

[0020] As an optional solution of the present invention, step S1 includes the following steps:

[0021] S11. Establish the boundaries of network isolation: Determine which video conferencing systems need to be isolated and where they are located in the network. Analyze the functions and requirements of these systems to determine the level and method of isolation.

[0022] S12. Plan isolation strategy: Develop an isolation strategy based on the sensitivity and importance of the video conferencing system. Determine the use of firewalls, VPN tunnels, or DMZ to achieve isolation.

[0023] S13. Deploy firewalls: Deploy firewall devices at the network boundary to ensure that communication between video conferencing systems is controlled. Configure firewall rules to allow legitimate signaling and data transmission while blocking unauthorized access. Regularly check firewall logs to analyze abnormal traffic and potential threats. Update firewall rules to respond to new threats and vulnerabilities.

[0024] S14. Establish VPN tunnel: Establish VPN tunnel between video conferencing systems that need to communicate. Configure VPN tunnel parameters, such as tunnel protocol, encryption algorithm, key, etc.

[0025] Test and optimize VPN performance: Test the connectivity and bandwidth of the VPN tunnel. Adjust the VPN configuration based on the test results to optimize performance and security.

[0026] S15. Configure DMZ (demilitarized zone): Create a DMZ in the network to place the servers and terminals of the video conferencing system. Configure access control policies for the DMZ to ensure that only legitimate users and devices can access it. Use an intrusion detection system (IDS) and an intrusion prevention system (IPS) to monitor the security of the DMZ. Regularly check the systems and devices in the DMZ to ensure their security.

[0027] S16. Assign independent IP addresses and ports: Assign independent IP addresses and ports to each video conferencing system. Ensure that the assignment of IP addresses and ports complies with the Network Address Translation (NAT) and port forwarding rules. Configure the corresponding routing rules and port forwarding rules on network devices and routers. Ensure that the communication paths between video conferencing systems are clear and secure.

[0028] S17. Verification and testing: Use network scanning tools and security testing tools to verify the effectiveness of network isolation. Ensure that the isolation strategy can effectively prevent unauthorized access and attacks. Test the communication function of the video conferencing system in a network isolation environment. Ensure that the signaling and data between video conferencing systems can be transmitted and received correctly.

[0029] As an optional solution of the present invention, step S3 includes the following steps:

[0030] S31. Determine the verification method: Determine the key data of the participants that need to be collected, including image information, identity information, and expected meeting time. According to business needs, determine whether other additional information needs to be collected, such as mobile phone number, email address, etc. Select the appropriate identity verification method, such as face recognition, fingerprint recognition, password verification, etc. Consider the security and ease of use of the system to ensure that participants can easily authenticate their identities.

[0031] S32. Design the architecture of the authentication system: Design the database table structure to store the key data of the participants. Determine the storage format and encryption method of the data to protect personal privacy and data security. Design the interface between the authentication system and the video conferencing system to ensure that the data can be synchronized and updated in real time. Determine the data format and communication protocol of the interface, such as RESTful API, WebSocket, etc.

[0032] S33. Build an identity authentication system: Develop a front-end interface for the identity authentication system for participants to enter their identity information and perform identity authentication. Ensure that the front-end interface is user-friendly and easy to operate, and provide clear error prompts and feedback. Develop the back-end logic of the identity authentication system, including data processing, identity authentication algorithms, etc. Implement interface docking with the video conferencing system to ensure that data can be synchronized accurately and in real time. Create a database and import key data of participants. Implement data addition, deletion, modification and query operations to ensure data integrity and consistency.

[0033] S34. Test the identity authentication system: Test the various functions of the identity authentication system, including identity authentication, data synchronization, etc. Ensure that the system can correctly identify the participants and update the data of the video conferencing system in real time. Test the performance of the identity authentication system, including response time, concurrent processing capabilities, etc. Ensure that the system can run stably under high concurrency and meet business needs. Test the security of the identity authentication system, including data encryption, SQL injection prevention, etc. Ensure that the system can protect the personal privacy and data security of the participants.

[0034] S35. Deploy the online authentication system: Deploy the authentication system to the server or cloud platform to ensure the stability and scalability of the system. Configure the necessary network and security settings to ensure that the system can operate normally and prevent unauthorized access. Connect the authentication system with the video conferencing system to ensure that participants can successfully authenticate and participate in the meeting. Monitor the operating status of the system to promptly identify and handle potential problems and failures.

[0035] S36. Continuous optimization and maintenance: Regularly update the key data of participants to ensure the accuracy and timeliness of the data. Timely handle problems and exceptions that occur during data synchronization and update. Continuously optimize the performance and functions of the identity authentication system based on business needs and technological development. Introduce new identity authentication technologies and algorithms to improve the security and usability of the system. Establish a fault handling mechanism to promptly respond to and handle faults and problems in the identity authentication system. Regularly back up and restore data to ensure system reliability and data security.

[0036] Through the above technical solution, an identity authentication system containing key data such as participant image information, identity information, expected meeting time, etc. is established, and data synchronization and real-time update between the system and the video conferencing system are ensured. This helps to improve the security and efficiency of the video conferencing system and protect the personal privacy and data security of participants.

[0037] As an optional solution of the present invention, step S5 includes the following steps:

[0038] 1. Receive meeting invitation and log in to the video conference system: Participants receive the meeting invitation sent by the meeting organizer. Participants log in to the video conference system through the designated conference terminal (such as computer, mobile phone, tablet or dedicated video conference equipment) according to the information in the meeting invitation.

[0039] 2. Provide identity verification information: The system interface prompts participants to enter identity verification information. Participants follow the prompts and enter basic information such as user name and password. The system identifies biometric features, including facial recognition or fingerprint recognition and other biometric verification.

[0040] 3. Collect and send image information: The built-in or external camera of the conference terminal collects real-time image information of the participants. The system encrypts the collected image information and sends it to the identity verification server for comparison.

[0041] 4. Identity verification system compares information: The identity verification system receives and decrypts the image information. The system compares the received image information with the participant information stored in the database. The comparison content includes but is not limited to: facial features, user name, password, etc. The system determines whether the identity of the participant matches based on the comparison results.

[0042] 5. Authentication result processing: If the authentication system confirms that the identity of the participant matches, the system immediately generates a participant permission token, sends the participant permission token to the conference terminal, and allows the participant to join the meeting. Based on the permission token, the participant enjoys the corresponding rights to speak, watch, share files, etc. in the meeting. If the authentication system finds that the participant does not match the expected person, the system immediately refuses to let him join the meeting. The system also generates an authentication failure notification and sends it to the conference organizer and relevant managers. After receiving the notification, the conference organizer and relevant managers can take further measures according to the actual situation, such as contacting the participant to confirm the identity, resending the meeting invitation, etc.

[0043] 6. Meeting records and follow-up processing: The system records the entire identity verification process, including the login time, identity verification results, and permission granted of the participants. After the meeting, the system generates a meeting report containing key information such as identity verification results for the meeting organizer and relevant managers to review. If any abnormality or security issues are found during the identity verification process, the system will immediately alert the meeting organizer and relevant managers and take appropriate security measures.

[0044] As an optional solution of the present invention, step S6 includes the following steps:

[0045] 1. Configure monitoring software: Configure the conference server and ensure that it is correctly configured and running. Check the network connection to ensure that the communication between the server and the devices of the participants is unimpeded. Install professional conference status monitoring software on the conference server. Configure the software parameters so that the status information of the participants can be accurately identified.

[0046] 2. Real-time monitoring of participants’ status:

[0047] Online status monitoring: The online status of participants is obtained in real time through monitoring software. If a participant logs in to the conference system and remains connected, it is marked as "online". If a participant is disconnected or does not perform any operation for a long time, it is marked as "offline".

[0048] Speech status monitoring: Use the audio recognition function of the conference system to monitor the speech status of participants. When a participant speaks, the software will automatically capture and mark his / her speech status as "speaking". When a participant stops speaking, the software will update his / her speech status to "not speaking".

[0049] Leaving meeting monitoring: monitor whether the participants have actively exited the conference system or closed the conference window. If the participant is detected to have left the meeting, the software will automatically update their status to "left".

[0050] 3. Data processing: Collect the status information of participants in real time and store it in the server database. Ensure the accuracy and completeness of the data for subsequent data analysis. Perform statistical analysis on the collected data to understand the attendance and activity of the participants. Generate reports or charts to intuitively display the status distribution of participants.

[0051] 4. Exception handling: If an abnormal state is detected (such as a large number of participants going offline at the same time, frequent interruptions in speaking, etc.), the alarm mechanism will be triggered. After receiving the alarm, the administrator should take timely measures to solve the problem and ensure the smooth progress of the meeting.

[0052] 5. Data backup: Regularly maintain and upgrade the conference server and monitoring software to ensure that the system is stable and reliable and can continue to provide accurate monitoring services. Regularly back up the collected participant status data to ensure that data can be quickly restored when lost or damaged.

[0053] Through the above technical solution, the status of participants can be monitored in real time, including whether they are online, speaking, leaving the meeting, etc. This helps administrators to understand the progress of the meeting in a timely manner and take corresponding measures to ensure the smooth progress of the meeting.

[0054] As an optional solution of the present invention, step S7 includes the following steps:

[0055] 1. Video conference content collection: The conference server collects video and audio content from the video conference equipment. Ensure that the collected content is clear, coherent, and meets the meeting requirements.

[0056] 2. Video conference content encoding: Encode the collected video and audio content into a format suitable for network transmission (such as H.264 video encoding and AAC audio encoding). During the encoding process, attention should be paid to the selection of parameters such as bit rate, resolution and frame rate to ensure a balance between transmission efficiency and video quality.

[0057] 3. Establish a connection: Select a transmission protocol suitable for real-time communication (such as TCP / IP or UDP) and configure the corresponding port. Make sure that the selected protocol can support the real-time transmission of video conference content and the reliable transmission of signaling. The conference server establishes a network connection with the conference terminals of all participants. Use the handshake protocol to ensure the reliability and stability of the connection.

[0058] 4. Generate signaling: The conference server generates signaling containing video and audio data packets based on the encoding results of the video conference content and the list of participants. The signaling should contain information such as the sequence number, timestamp, and checksum of the data packet to ensure the integrity and order of the data.

[0059] 5. Encrypted signaling: Encryption technology (such as TLS / SSL) is used to encrypt signaling. The security and privacy of the key should be ensured during the encryption process to prevent the key from being leaked or cracked.

[0060] 6. Transmission signaling: The conference server transmits the encrypted signaling to the conference terminals of all participants through the network. During the transmission process, the stability of the network and the adequacy of the bandwidth should be ensured to avoid data packet loss or delay.

[0061] 7. Signaling filtering and restriction: Configure a firewall between the conference server and the conference terminals of the participants. The firewall setting rules are: allow legal signaling to pass through and block illegal signaling or attacks. You can use IP filtering, port filtering, or protocol filtering to limit the transmission of signaling. Establish a virtual private network (VPN) to provide a secure communication channel for the conference server and the conference terminals of the participants. VPN uses encryption technology (such as IPsec) to ensure the security of signaling during transmission. Restrict the transmission path and access rights of signaling by configuring the VPN's access control list (ACL). Perform cell delay autocorrelation evaluation.

[0062] 8. Receive and decode video conference content: The conference terminal of the participants receives the signaling sent by the conference server and uses the corresponding decryption algorithm and key to decrypt the signaling.

[0063] Decoding video and audio: The conference terminal decodes the video and audio data packets according to the packet sequence number, timestamp, checksum and other information in the signaling. During the decoding process, attention should be paid to the selection of parameters such as bit rate, resolution and frame rate to ensure the playback quality of video and audio.

[0064] 9. Play video and audio: Play the decoded video and audio content through the display and speakers of the conference terminal. Ensure that the played content is consistent with the content collected by the conference server and meets the requirements of real-time and accuracy.

[0065] In this technical solution, the conference server can transmit the video conference content to the conference terminals of all participants through signaling, and ensure the real-time and accuracy of the information. At the same time, encryption technology and network isolation technology are used to encrypt and filter the signaling to ensure the security of the signaling during transmission.

[0066] As an optional solution of the present invention, signaling filtering and restriction includes the following steps:

[0067] 1. Configure the firewall for signaling filtering and restriction: Identify the types of legal signaling required for communication between the conference server and the participating terminals, such as SIP, RTP, etc. Determine the IP address range, port number, and protocol type used by these signals. Log in to the management interface of the firewall device with administrator privileges. Select the appropriate login method and interface based on the brand and model of the firewall device. In the firewall management interface, create IP filtering rules. Set the allowed or denied IP address segments based on the IP address range of legal signaling. Create port filtering rules. Set the allowed or denied port range based on the port number used by legal signaling. Configure protocol filtering rules and set the allowed or denied protocol list based on the protocol type used by legal signaling. Apply the configured filtering rules to the corresponding interfaces or areas of the firewall. Ensure that the filtering rules are effective and monitor the firewall logs to check whether any illegal signaling is blocked.

[0068] 2. Establish a virtual private network (VPN): Determine the type of VPN, such as IPsec VPN. Select the appropriate encryption algorithm and key management method. Configure the VPN server on the conference server, including setting the VPN authentication method, encryption method, etc. Ensure that the VPN server can correctly identify and allow legal signaling to pass. Configure the VPN client on the conference terminals of the participants to connect to the conference server via VPN. Ensure that the VPN client can be correctly configured and connected to the VPN server. Configure the access control list (ACL) and configure the ACL on the VPN server to limit the transmission path and access rights of the signaling. Set access rules to allow or deny based on the IP address, port number, and protocol type of the legal signaling.

[0069] After the configuration is complete, perform a VPN connection test to ensure that the conference server and the conference terminals of the participants can communicate normally through VPN. Check the performance indicators such as the stability, security, and bandwidth of the VPN connection.

[0070] 3. Perform cell delay autocorrelation evaluation: Collect cell transmission delay data on the communication link between the conference server and the participating terminals. Ensure the accuracy and completeness of the data. Calculate the delay autocorrelation coefficient: Use the autocorrelation function to calculate the autocorrelation coefficient of the cell delay. Analyze the changing trend and characteristics of the autocorrelation coefficient to evaluate the stability and predictability of the cell delay.

[0071] The cell delay autocorrelation is evaluated according to the following formula:

[0072] Where R(τ) is the autocorrelation function, which is used to evaluate the similarity of the delay sequence under different time delays τ. τ is the time delay, which represents the time interval of the delay similarity that we want to analyze. In the autocorrelation function, τ usually takes different values ​​to observe the similarity of the signal under different time delays. M is the total number of cells in the delay sequence. This value determines how many delay values ​​we need to consider when calculating the autocorrelation function. 1 is the adjustment coefficient used to control the sensitivity of the autocorrelation function to the delay difference. 1 The value of can change the response of the autocorrelation function to the delay change. 2 is the decay coefficient, which is used to control the decay rate of delay similarity over time. i is the delay measurement value of the ith cell. This is an element in the delay sequence, indicating the transmission delay of the signal from the sender to the receiver. d is the time delay sequence d i This value is used to subtract from each time delay value when calculating the autocorrelation function to eliminate the influence of the average level of the time delay sequence on the autocorrelation result. 2 |i-(i+|τ|)|] is a decay function, which is used to reflect the decay effect of delay similarity over time.

[0073] Analysis results: Analyze the characteristics and rules of cell delay based on the calculation results of the autocorrelation coefficient. If the autocorrelation coefficient is high, it means that the cell delay is highly stable and predictable; if the autocorrelation coefficient is low, it may be necessary to further optimize the network configuration or take other measures to reduce delay fluctuations. Based on the analysis results, optimize the network configuration, such as adjusting router settings, increasing bandwidth, etc., to reduce cell delay and improve communication quality.

[0074] 3. Beneficial effects

[0075] One or more technical solutions provided in the technical solution of this application have at least the following technical effects or advantages:

[0076] 1. The present invention strictly controls the communication between video conference systems by using technologies such as firewalls, VPN tunnels, and DMZ, effectively preventing illegal intrusion and data leakage. Encrypt the signaling (such as TLS / SSL) to ensure the security of the signaling during transmission. Through the identity authentication system, it is ensured that only legitimate participants can join the meeting, thereby improving the security of the meeting.

[0077] 2. Assign independent IP addresses and ports to each video conferencing system to ensure the clarity and stability of the communication path. The conference server monitors the status of participants in real time, including whether they are online and speaking, to ensure the smooth progress of the meeting.

[0078] 3. During the signaling transmission process, the signaling is filtered and restricted through network isolation technologies such as firewalls or VPNs to ensure that only legal signaling can pass through and reduce communication failures. The signaling is encrypted to ensure security during transmission and prevent data leakage or tampering. The configuration of firewalls and VPNs further enhances the security of the conference system and limits the entry of illegal signaling or attacks.

[0079] 4. The decryption and decoding process is fast and efficient, ensuring real-time playback of video and audio content. The calculation of decoding time takes into account multiple factors, which helps to optimize the decoding process and improve playback efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0080] Figure 1 This is a flow chart of a signaling transmission method for intercommunication between video conferencing systems in a network isolation environment disclosed in this application. DETAILED DESCRIPTION

[0081] The present application is further described in detail below in conjunction with the accompanying drawings.

[0082] Reference Figure 1 The embodiment of the present application provides a signaling transmission method for intercommunication between video conferencing systems in a network isolation environment, comprising the following steps:

[0083] S1. Configure network isolation environment: Establish network isolation boundaries, use advanced firewall technology, deep packet inspection (DPI) and behavior-based threat detection (BTD) systems to ensure that communication between video conferencing systems is strictly controlled. Use SDN (software defined network) technology to achieve dynamic allocation and configuration of network resources to ensure that the video conferencing system can flexibly adapt to different network environments and needs. Allocate independent IP addresses and ports to each video conferencing system, use IPv6 address space, and increase address richness and security.

[0084] S2. Deployment of video conferencing system: Deploy the video conferencing system in each subnet or area of ​​the network isolation environment, including conference servers, conference terminals and other components. Ensure that the network connection between the video conferencing systems is normal, and configure the necessary network isolation and access control policies. Use containerization technology and Kubernetes cluster management to achieve rapid deployment and automatic expansion of the video conferencing system. Combined with micro-isolation technology, provide fine-grained access control policies for each component of the video conferencing system.

[0085] S3. Establish an identity authentication system: Establish an identity authentication system that contains key data such as the image information, identity information, expected meeting time, etc. of the participants. Ensure data synchronization and real-time update between the identity authentication system and the video conferencing system.

[0086] S4. Meeting creation and invitation sending: The meeting organizer creates a meeting through the video conference management system and sets the meeting details, including the list of participants, meeting time, etc. The system generates a meeting invitation signal and sends it to the meeting terminals of the expected participants through a secure communication channel.

[0087] S5. Authentication of participants: After receiving the conference invitation, participants log in to the video conference system through the conference terminal. The system requires participants to provide authentication information, such as user name, password, biometrics (such as facial recognition), etc.

[0088] The conference terminal collects the image information of the participants and sends it to the identity verification system for comparison. The identity verification system compares the image information of the participants with the information stored in the database to confirm whether the identity matches.

[0089] If the identity authentication system confirms that the participant's identity matches, they are allowed to join the meeting and are granted corresponding meeting rights.

[0090] If the identity verification system finds that the attendee does not match the expected person, it will immediately deny them access to the meeting and notify the meeting organizer and relevant managers.

[0091] S6. Conference status monitoring: The conference server monitors the status of participants in real time, including whether they are online, speaking, or leaving the meeting.

[0092] S7, signaling transmission: The conference server transmits the video conference content to the conference terminals of all participants through signaling to ensure the real-time and accuracy of the information. During the signaling transmission process, encryption technology (such as TLS / SSL) is used to encrypt the signaling to ensure the security of the signaling during transmission. The signaling is filtered and restricted through network isolation technologies such as firewalls or VPNs to ensure that only legal signaling can pass. The cell delay autocorrelation evaluation is performed.

[0093] S8. Abnormal handling and alarm: If the conference server detects abnormal behavior of participants (such as unauthorized speech, attempt to access sensitive information, etc.), the alarm mechanism will be triggered immediately. The system records the relevant information of the abnormal behavior and notifies the conference organizer and relevant managers to handle it.

[0094] S9, End of meeting and release of resources: When the meeting ends, the conference server sends a conference end signal to the conference terminals of all participants. After receiving the end signal, the conference terminals of the participants release local resources and exit the meeting. The conference server releases the conference resources and updates the conference status information in the database. The system records key information during the meeting (such as the list of participants, meeting duration, abnormal behavior, etc.) and stores it in the log file for subsequent audit and analysis.

[0095] This technical solution can ensure the security, reliability and efficiency of signaling transmission between video conferencing systems in a network isolation environment. At the same time, it also provides a safe and controllable video conferencing environment for participants, and realizes the identity verification of participants and real-time monitoring of their conference status.

[0096] Further, step S1 includes the following steps:

[0097] S11. Establish the boundaries of network isolation: Determine which video conferencing systems need to be isolated and where they are located in the network. Analyze the functions and requirements of these systems to determine the level and method of isolation.

[0098] S12. Plan isolation strategy: Develop an isolation strategy based on the sensitivity and importance of the video conferencing system. Determine the use of firewalls, VPN tunnels, or DMZ to achieve isolation.

[0099] S13. Deploy firewalls: Deploy firewall devices at the network boundary to ensure that communication between video conferencing systems is controlled. Configure firewall rules to allow legitimate signaling and data transmission while blocking unauthorized access. Regularly check firewall logs to analyze abnormal traffic and potential threats. Update firewall rules to respond to new threats and vulnerabilities.

[0100] S14. Establish VPN tunnel: Establish VPN tunnel between video conferencing systems that need to communicate. Configure VPN tunnel parameters, such as tunnel protocol, encryption algorithm, key, etc.

[0101] Test and optimize VPN performance: Test the connectivity and bandwidth of the VPN tunnel. Adjust the VPN configuration based on the test results to optimize performance and security.

[0102] S15. Configure DMZ area (demilitarized zone): Divide a DMZ area in the network to place the server and terminals of the video conferencing system. Configure the access control policy of the DMZ area to ensure that only legitimate users and devices can access it.

[0103] Use intrusion detection systems (IDS) and intrusion prevention systems (IPS) to monitor the security status of the DMZ area. Regularly check the systems and devices in the DMZ area to ensure their security.

[0104] S16. Assign independent IP addresses and ports: Assign independent IP addresses and ports to each video conferencing system. Ensure that the assignment of IP addresses and ports complies with the Network Address Translation (NAT) and port forwarding rules. Configure the corresponding routing rules and port forwarding rules on network devices and routers. Ensure that the communication paths between video conferencing systems are clear and secure.

[0105] S17. Verification and testing: Use network scanning tools and security testing tools to verify the effectiveness of network isolation. Ensure that the isolation strategy can effectively prevent unauthorized access and attacks.

[0106] Test the communication function of the video conferencing system in a network isolation environment. Ensure that the signaling and data between the video conferencing systems can be transmitted and received correctly.

[0107] Further, step S3 includes the following steps:

[0108] S31. Determine the verification method: Determine the key data of the participants that need to be collected, including image information (such as photos), identity information (such as name, department, position, etc.) and expected meeting time. Based on business needs, determine whether other additional information needs to be collected, such as mobile phone numbers, email addresses, etc.

[0109] Choose an appropriate identity verification method, such as face recognition, fingerprint recognition, password verification, etc. Consider the security and usability of the system and ensure that participants can easily authenticate their identities.

[0110] S32. Design the architecture of the identity authentication system: Design the database table structure to store the key data of the participants. Determine the storage format and encryption method of the data to protect personal privacy and data security.

[0111] Design the interface between the authentication system and the video conferencing system to ensure data synchronization and real-time update. Determine the data format and communication protocol of the interface, such as RESTful API, WebSocket, etc.

[0112] S33. Build an identity authentication system: Develop a front-end interface for the identity authentication system for participants to enter their identity information and perform identity authentication. Ensure that the front-end interface is user-friendly and easy to operate, and provide clear error prompts and feedback. Develop the back-end logic of the identity authentication system, including data processing, identity authentication algorithms, etc. Implement interface docking with the video conferencing system to ensure that data can be synchronized accurately and in real time.

[0113] The identity verification system is built on a multi-factor authentication model, including knowledge factors and biometric factors;

[0114] Knowledge factors: such as passwords, PIN codes, etc., information that participants need to know.

[0115] Biological factors: such as fingerprints, facial features, etc., the inherent biological characteristics of the participants.

[0116] Create a database and import key data of participants. Implement data addition, deletion, modification and query operations to ensure data integrity and consistency.

[0117] S34. Test the identity authentication system: Test the various functions of the identity authentication system, including identity authentication, data synchronization, etc. Ensure that the system can correctly identify the participants and update the data of the video conferencing system in real time. Test the performance of the identity authentication system, including response time, concurrent processing capabilities, etc. Ensure that the system can run stably under high concurrency and meet business needs. Test the security of the identity authentication system, including data encryption, prevention of SQL injection, etc. Ensure that the system can protect the personal privacy and data security of the participants. Evaluate the security of the system according to the following formula:

[0118] CSES=α×(w KL ×KLS+w SI ×SIS)+β×(ETS+DTS) / 2; where CSES is the comprehensive security efficiency score, which is a comprehensive indicator used to evaluate the overall performance of the encryption algorithm in terms of security and efficiency. α is the security efficiency weight coefficient, which is the relative importance of security to efficiency. KL is the key length adjustment weight factor, which indicates the relative importance of a specific adjusted or optimized key length score in the overall security score. KLS is the specific key length score. This score indicates the specific performance or advantage of the key length in the encryption algorithm. SI is the security strength weight coefficient, which indicates the relative importance of the security strength score in the total security score. SIS is the enhanced security strength score. This score indicates the enhanced performance or advantage of the encryption algorithm in terms of security strength. β is the efficiency-security balance weight coefficient. This coefficient indicates the relative importance of efficiency to security in the comprehensive score. ETS and DTS are the encryption time score and decryption time score, which indicate the time performance of the encryption algorithm during the encryption and decryption processes, respectively.

[0119] S35. Deploy the online authentication system: Deploy the authentication system to the server or cloud platform to ensure the stability and scalability of the system. Configure the necessary network and security settings to ensure that the system can operate normally and prevent unauthorized access. Connect the authentication system with the video conferencing system to ensure that participants can successfully authenticate and participate in the meeting. Monitor the operating status of the system to promptly identify and handle potential problems and failures.

[0120] S36. Continuous optimization and maintenance: Regularly update the key data of participants to ensure the accuracy and timeliness of the data. Timely handle problems and exceptions that occur during data synchronization and update. Continuously optimize the performance and functions of the identity authentication system based on business needs and technological development. Introduce new identity authentication technologies and algorithms to improve the security and usability of the system. Establish a fault handling mechanism to promptly respond to and handle faults and problems in the identity authentication system. Regularly back up and restore data to ensure system reliability and data security.

[0121] In this technical solution, an identity authentication system is established that contains key data such as the participant's image information, identity information, and expected meeting time, and ensures data synchronization and real-time updates between the system and the video conferencing system. This helps to improve the security and efficiency of the video conferencing system and protect the personal privacy and data security of the participants.

[0122] Further, step S5 includes the following steps:

[0123] 1. Receive meeting invitation and log in to the video conference system: Participants receive the meeting invitation sent by the meeting organizer. Participants log in to the video conference system through the designated conference terminal (such as computer, mobile phone, tablet or dedicated video conference equipment) according to the information in the meeting invitation.

[0124] 2. Provide identity verification information: The system interface prompts participants to enter identity verification information. Participants follow the prompts and enter basic information such as user name and password. The system identifies biometric features, including facial recognition or fingerprint recognition and other biometric verification.

[0125] 3. Collect and send image information: The built-in or external camera of the conference terminal collects real-time image information of the participants. The system encrypts the collected image information and sends it to the identity verification server for comparison.

[0126] 4. Identity verification system compares information: The identity verification system receives and decrypts the image information. The system compares the received image information with the participant information stored in the database. The comparison content includes but is not limited to: facial features, user name, password, etc. Based on the comparison results, the system determines whether the identity of the participant matches. The identity verification efficiency is evaluated according to the following formula:

[0127] Where AVI is the Authentication Verification Index, which is used to comprehensively evaluate the performance of the authentication system. true_passis the number of participants who have actually passed identity authentication, that is, the number of participants who are correctly identified as legitimate users by the system; from all participants who have attempted identity authentication, the number of participants who are correctly identified as legitimate users by the system is screened out. N total Is the total number of authentication attempts, including both successful and failed attempts. Counts all people who attempt to use the authentication system, regardless of whether they are correctly identified by the system or not. 1 is the weight coefficient used to adjust the relative importance of identity verification accuracy in AVI. max is the maximum acceptable authentication time, representing the lower limit of system performance. min is the expected minimum (or optimal) authentication time, which may be an ideal value, but may not be achieved in actual applications. According to the technical level of the authentication system and user needs, set an expected minimum authentication time. avg is the actual time it takes for each participant to complete authentication on average. Add up all successful and failed authentication times and divide by the total number of authentication attempts. 2 Weight coefficient used to adjust the relative importance of time efficiency in AVI.

[0128] 5. Authentication result processing: If the authentication system confirms that the identity of the participant matches, the system immediately generates a participant authorization token, sends the participant authorization token to the conference terminal, and allows the participant to join the conference. Based on the authorization token, the participant enjoys the corresponding rights to speak, watch, share files, etc. in the conference.

[0129] If the identity verification system finds that the participant does not match the expected person, the system immediately refuses to allow them to join the meeting. The system also generates an identity verification failure notification and sends it to the meeting organizer and relevant managers. After receiving the notification, the meeting organizer and relevant managers can take further measures according to the actual situation, such as contacting the participant to confirm the identity, resending the meeting invitation, etc.

[0130] 6. Meeting records and follow-up processing: The system records the entire identity verification process, including the login time, identity verification results, and permission granted of the participants. After the meeting, the system generates a meeting report containing key information such as identity verification results for review by the meeting organizers and relevant managers.

[0131] If any anomalies or security issues are found during the identity verification process, the system will immediately alert the meeting organizer and relevant managers and take corresponding security measures.

[0132] In this technical solution, the identities of participants can be accurately verified, thereby ensuring the security and effectiveness of video conferencing.

[0133] Further, step S6 includes the following steps:

[0134] 1. Configure monitoring software: Configure the conference server and ensure that it is correctly configured and running. Check the network connection to ensure that the communication between the server and the devices of the participants is unimpeded. Install professional conference status monitoring software on the conference server. Configure the software parameters so that the status information of the participants can be accurately identified.

[0135] 2. Real-time monitoring of participants’ status:

[0136] Online status monitoring: The online status of participants is obtained in real time through monitoring software. If a participant logs in to the conference system and remains connected, it is marked as "online". If a participant is disconnected or does not perform any operation for a long time, it is marked as "offline".

[0137] Speech status monitoring: Use the audio recognition function of the conference system to monitor the speech status of participants. When a participant speaks, the software will automatically capture and mark his / her speech status as "speaking". When a participant stops speaking, the software will update his / her speech status to "not speaking".

[0138] Leaving meeting monitoring: monitor whether the participants have actively exited the conference system or closed the conference window. If the participant is detected to have left the meeting, the software will automatically update their status to "left".

[0139] 3. Data processing: Collect the status information of participants in real time and store it in the server database. Ensure the accuracy and completeness of the data for subsequent data analysis. Perform statistical analysis on the collected data to understand the attendance and activity of the participants. Generate reports or charts to intuitively display the status distribution of participants.

[0140] 4. Exception handling: If an abnormal state is detected (such as a large number of participants going offline at the same time, frequent interruptions in speaking, etc.), the alarm mechanism will be triggered. After receiving the alarm, the administrator should take timely measures to solve the problem and ensure the smooth progress of the meeting.

[0141] 5. Data backup: Regularly maintain and upgrade the conference server and monitoring software to ensure that the system is stable and reliable and can continue to provide accurate monitoring services. Regularly back up the collected participant status data to ensure that data can be quickly restored when lost or damaged.

[0142] In this technical solution, the status of participants can be monitored in real time, including whether they are online, speaking, leaving the meeting, etc. This helps administrators to understand the progress of the meeting in a timely manner and take corresponding measures to ensure the smooth progress of the meeting.

[0143] Further, step S7 includes the following steps:

[0144] 1. Video conference content collection: The conference server collects video and audio content from video conference equipment (such as cameras and microphones). Ensure that the collected content is clear, coherent, and meets the meeting requirements.

[0145] 2. Video conference content encoding: Encode the collected video and audio content into a format suitable for network transmission (such as H.264 video encoding and AAC audio encoding). During the encoding process, attention should be paid to the selection of parameters such as bit rate, resolution and frame rate to ensure a balance between transmission efficiency and video quality.

[0146] 3. Establish a connection: Select a transmission protocol suitable for real-time communication (such as TCP / IP or UDP) and configure the corresponding port. Make sure that the selected protocol can support real-time transmission of video conference content and reliable transmission of signaling.

[0147] The conference server establishes a network connection with the conference terminals of all participants, and uses a handshake protocol (such as TCP three-way handshake) to ensure the reliability and stability of the connection.

[0148] 4. Generate signaling: The conference server generates signaling containing video and audio data packets based on the encoding results of the video conference content and the list of participants. The signaling should contain information such as the sequence number, timestamp, and checksum of the data packet to ensure the integrity and order of the data.

[0149] Calculate the size of the packet as follows:

[0150] P size =u 1 *Enc(V)+u 2 *Comp(A)+u 3 *Hdr(H)+u 4 *Redundancy; where P size Indicates the total size of each data packet. This is the total number of bytes or bits that the data packet occupies during transmission. 1 Indicates the weight coefficient of the video data part. This coefficient is used to adjust the relative importance of the video data in the data packet. A larger u 1 The value means that the video data accounts for a large proportion of the data packet. Enc(V) indicates the effective size of the video data after encoding. Here Enc is a function representing the encoding process, including compression, quantization, color space conversion and other steps to reduce the size of the video data while maintaining the video quality as much as possible. V is the original representation of the video data, and Enc(V) is the encoded video data. 2Indicates the weight coefficient of the audio data part. This coefficient is used to adjust the relative importance of the audio data in the data packet. A larger u 2 A value means that the audio data accounts for a large proportion of the data packet. Comp(A) indicates the effective size of the audio data portion after compression. Comp is a function that represents the compression process, which involves steps such as sampling rate adjustment, bit rate control, and audio format conversion to reduce the size of the audio data while maintaining the audio quality as much as possible. A is the original representation of the audio data, and Comp(A) is the compressed audio data. 3 Indicates the weight coefficient of the header information, which is used to adjust the relative importance of the header information in the data packet. Although the header information is usually small, it is crucial for the parsing and reassembly of the data packet. Hdr(H) represents the effective size of the header information. Hdr is a function that represents the generation process of the header information. The header information contains key information such as sequence number, timestamp, checksum, protocol identifier, etc., which is used to ensure the correct transmission and parsing of the data packet. H is the original representation of the header information, and Hdr(H) is the generated header information. U 4 Represents the redundancy coefficient, which is used to adjust the amount of redundant data in a data packet. Redundancy data includes checksums, retransmission request information, etc., which are used to improve the robustness and reliability of transmission. Redundancy represents the size of redundant data added to a data packet, which can increase the reliability of transmission. For example, when an error is encountered during transmission, the receiver can use redundant data to detect and correct the error.

[0151] 5. Encrypted signaling: Encryption technology (such as TLS / SSL) is used to encrypt signaling. The security and privacy of the key should be ensured during the encryption process to prevent the key from being leaked or cracked.

[0152] 6. Transmission signaling: The conference server transmits the encrypted signaling to the conference terminals of all participants through the network. During the transmission process, the stability of the network and the adequacy of the bandwidth should be ensured to avoid data packet loss or delay.

[0153] The encryption time is calculated as follows:

[0154] Where, T encrypt is the encryption processing time. This is the target that the formula calculates and represents the total time required to complete the encryption operation. 1 is the complexity coefficient of the encryption algorithm. This is an experimentally determined constant that describes the computational complexity of the encryption algorithm itself. It reflects the basic time overhead required by the encryption algorithm under a fixed data packet size and parallel processing capability. sizeis the packet size. This is the amount of data that the encryption operation has to process, and has a direct impact on the encryption processing time. The larger the packet, the longer it usually takes to encrypt. η is the coefficient of the impact of packet size on encryption processing time. This is an experimentally determined index that describes how packet size affects encryption processing time. As η increases, it means that the impact of packet size on encryption time is more significant. K 2 It is the efficiency factor of the encryption algorithm under parallel processing. This is a constant between 0 and 1, which is used to describe the execution efficiency of the encryption algorithm in a parallel environment. 2 The closer it is to 1, the higher the parallel efficiency is, that is, increasing the parallel processing capability can more effectively reduce the encryption time. parallel Is the actual parallel processing capability. This can be the number of processors, threads, cores, or other measures of parallel processing capability, reflecting the number of tasks or computing power that the system can handle simultaneously. max It is the processing power corresponding to the maximum parallel processing speedup ratio that the encryption algorithm can achieve on a given hardware. This is an experimentally determined constant used to describe the maximum parallel processing power that the encryption algorithm can utilize under optimal conditions. 3 is the fixed overhead factor in the encryption process. This is a constant term used to represent the fixed overhead that will not drop to zero for encryption processing time even when there is no parallel processing capability or the packet size is zero, including the overhead of algorithm initialization, memory allocation, data copying, etc.

[0155] The playback delay is calculated as follows:

[0156] D play =(T 收 +ΔT 网 )+(T 解密 +ΔT 解密-延迟 )+(T 解码 +ΔT 解码-延迟 )+T 缓冲 -T 发 Where D play This is the target value of the formula, which represents the playback delay. The playback delay is the total time difference from the signaling receiving the data until the data is decoded and played out. 收 ΔT is the data reception time. It indicates the time when the data packet is received from the network or other transmission medium. This time point is usually the moment when the data packet arrives at the receiving end and is recorded by the receiving software or hardware. 网 It is the network transmission delay, which indicates the time required for a data packet to be transmitted from the sender to the receiver on the network path. This time includes various transmission delays of the data packet in the network, such as queuing delay, propagation delay, etc. 解密It is the time required for the decryption operation. It indicates the time required from the beginning of the data being decrypted to the completion of the decryption. This time depends on the complexity of the decryption algorithm and the processing power of the hardware. 解密-延迟 It is the additional delay of decryption processing, which means that in the decryption process, in addition to the pure decryption algorithm execution time, it also includes other processing time related to decryption, such as data preparation, memory access, CPU scheduling, etc. 解码 It is the time required for the decoding operation. It indicates the time required from the beginning of the data being decoded to the completion of the decoding. This time depends on the complexity of the decoding algorithm and the processing power of the hardware. 解码-延迟 It is the additional delay of decoding processing. It means that in addition to the pure decoding algorithm execution time, other processing time related to decoding is also included in the decoding process. 缓冲 It is the buffering delay. It indicates the time that data needs to wait in the buffer before playing. This time is set to ensure the continuity and smoothness of data to avoid lag or interruption during playback. 发 The data transmission time indicates the time when the sender starts to send the data packet. This time point is usually the moment when the data packet is recorded by the sending software or hardware and begins to be transmitted to the network.

[0157] 7. Signaling filtering and restriction: Configure a firewall between the conference server and the conference terminals of the participants. The firewall setting rules are: allow legal signaling to pass through and block illegal signaling or attacks. You can use IP filtering, port filtering, or protocol filtering to limit the transmission of signaling. Establish a virtual private network (VPN) to provide a secure communication channel for the conference server and the conference terminals of the participants. VPN uses encryption technology (such as IPsec) to ensure the security of signaling during transmission. Restrict the transmission path and access rights of signaling by configuring the VPN's access control list (ACL). Perform cell delay autocorrelation evaluation.

[0158] 8. Receive and decode video conference content: The conference terminal of the participants receives the signaling sent by the conference server and uses the corresponding decryption algorithm and key to decrypt the signaling.

[0159] Decoding video and audio: The conference terminal decodes the video and audio data packets according to the packet sequence number, timestamp, checksum and other information in the signaling. During the decoding process, attention should be paid to the selection of parameters such as bit rate, resolution and frame rate to ensure the playback quality of video and audio.

[0160] Calculate the decryption time as follows:

[0161] Where, T decode is the total time required for decoding. k 4 and k6 is a constant factor used to adjust the formula to match the actual situation, including some additional time overhead or efficiency loss that has not been taken into account. η′ is the processing efficiency of the decoder, which indicates the amount of data that can be processed per second under ideal conditions. k 5 is a factor that adjusts the effect of parallel processing on decoding time. It may depend on the specific implementation of the decoder and the effectiveness of parallel processing. parallel ′ is the number of packets or tasks that the decoder can process in parallel. This depends on the hardware and software implementation of the decoder, as well as possible parallel processing strategies. max ′ is the maximum number of packets or tasks that the decoder can handle at one time. This is usually limited by the decoder's internal buffer size or processing power. size is the total size of the data packet that needs to be decoded. K 7 It is a constant term, which represents the proportional factor of the additional time overhead required in the decoding process in addition to the packet processing, including initialization time, error handling time, etc.

[0162] 9. Play video and audio: Play the decoded video and audio content through the display and speakers of the conference terminal. Ensure that the played content is consistent with the content collected by the conference server and meets the requirements of real-time and accuracy.

[0163] In this technical solution, the conference server can transmit the video conference content to the conference terminals of all participants through signaling, and ensure the real-time and accuracy of the information. At the same time, encryption technology and network isolation technology are used to encrypt and filter the signaling to ensure the security of the signaling during transmission.

[0164] Furthermore, signaling filtering and restriction includes the following steps:

[0165] 1. Configure the firewall for signaling filtering and restriction: Identify the types of legal signaling required for communication between the conference server and the participating terminals, such as SIP, RTP, etc. Determine the IP address range, port number, and protocol type used by these signals. Log in to the management interface of the firewall device with administrator privileges. Select the appropriate login method and interface based on the brand and model of the firewall device. In the firewall management interface, create IP filtering rules. Set the allowed or denied IP address segments based on the IP address range of legal signaling. Create port filtering rules. Set the allowed or denied port range based on the port number used by legal signaling. Configure protocol filtering rules and set the allowed or denied protocol list based on the protocol type used by legal signaling. Apply the configured filtering rules to the corresponding interfaces or areas of the firewall. Ensure that the filtering rules are effective and monitor the firewall logs to check whether any illegal signaling is blocked.

[0166] 2. Establish a virtual private network (VPN): Determine the type of VPN, such as IPsec VPN. Select the appropriate encryption algorithm and key management method. Configure the VPN server on the conference server, including setting the VPN authentication method, encryption method, etc. Ensure that the VPN server can correctly identify and allow legal signaling to pass. Configure the VPN client on the conference terminals of the participants to connect to the conference server via VPN. Ensure that the VPN client can be correctly configured and connected to the VPN server. Configure the access control list (ACL) and configure the ACL on the VPN server to limit the transmission path and access rights of the signaling. Set access rules to allow or deny based on the IP address, port number, and protocol type of the legal signaling.

[0167] After the configuration is complete, perform a VPN connection test to ensure that the conference server and the conference terminals of the participants can communicate normally through VPN. Check the performance indicators such as the stability, security, and bandwidth of the VPN connection.

[0168] 3. Perform cell delay autocorrelation evaluation: Collect cell transmission delay data on the communication link between the conference server and the participating terminals. Ensure the accuracy and completeness of the data. Calculate the delay autocorrelation coefficient: Use the autocorrelation function to calculate the autocorrelation coefficient of the cell delay. Analyze the changing trend and characteristics of the autocorrelation coefficient to evaluate the stability and predictability of the cell delay.

[0169] The cell delay autocorrelation is evaluated according to the following formula:

[0170] Where R(τ) is the autocorrelation function, which is used to evaluate the similarity of the delay sequence under different time delays τ. τ is the time delay, which represents the time interval of the delay similarity that we want to analyze. In the autocorrelation function, τ usually takes different values ​​to observe the similarity of the signal under different time delays. M is the total number of cells in the delay sequence. This value determines how many delay values ​​we need to consider when calculating the autocorrelation function. 1 is the adjustment coefficient used to control the sensitivity of the autocorrelation function to the delay difference. 1 The value of can change the response of the autocorrelation function to the delay change. 2 is the decay coefficient, which is used to control the decay rate of delay similarity over time. i is the delay measurement value of the ith cell. This is an element in the delay sequence, indicating the transmission delay of the signal from the sender to the receiver. d is the time delay sequence d i This value is used to subtract from each time delay value when calculating the autocorrelation function to eliminate the influence of the average level of the time delay sequence on the autocorrelation result. 2|i-(i+|τ|)|] is a decay function, which is used to reflect the decay effect of delay similarity over time.

[0171] According to the calculation results of the autocorrelation coefficient, analyze the characteristics and rules of the cell delay. If the autocorrelation coefficient is high, it means that the cell delay is highly stable and predictable; if the autocorrelation coefficient is low, it may be necessary to further optimize the network configuration or take other measures to reduce the delay fluctuation. According to the analysis results, optimize the network configuration, such as adjusting router settings, increasing bandwidth, etc., to reduce the cell delay and improve communication quality.

[0172] The present invention strictly controls the communication between video conference systems by using technologies such as firewalls, VPN tunnels, and DMZ, effectively preventing illegal intrusion and data leakage. The signaling is encrypted (such as TLS / SSL) to ensure the security of the signaling during transmission. The identity authentication system ensures that only legal participants can join the meeting, thereby improving the security of the meeting. An independent IP address and port are allocated to each video conference system to ensure the clarity and stability of the communication path. The conference server monitors the status of the participants in real time, including whether they are online, whether they are speaking, etc., to ensure the smooth progress of the meeting. During the signaling transmission process, the signaling is filtered and restricted by network isolation technologies such as firewalls or VPNs to ensure that only legal signaling can pass and reduce communication failures. The signaling is encrypted to ensure security during transmission and prevent data leakage or tampering. The configuration of firewalls and VPNs further enhances the security of the conference system and limits the entry of illegal signaling or attacks. The decryption and decoding process is fast and efficient, ensuring the real-time playback of video and audio content. The calculation of the decoding time takes into account multiple factors, which helps to optimize the decoding process and improve playback efficiency.

[0173] As described above, the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features thereof may be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A signaling transmission method for intercommunication between video conference systems in a network isolation environment, characterized in that: The following steps are involved: S1. Configure network isolation environment: Configure network isolation environment, use firewall, deep packet inspection DPI and behavior-based threat detection BTD system to strictly control video conference communication; use SDN technology to realize dynamic allocation of network resources and allocate independent IPv6 address and port for video conference system; S2. Deployment of video conferencing system: Deploy the video conferencing system in a subnet or region of a network isolation environment, and use containerization, Kubernetes, and micro-isolation technologies to achieve rapid deployment, automatic expansion, and fine-grained access control; S3. Establish an identity authentication system: Establish an identity authentication system that includes the images, identities, and expected meeting time data of participants, and synchronize and update data in real time with the video conferencing system; S4, conference creation and invitation sending: the conference organizer creates and sets the conference details through the management system, and the system generates a secure invitation signaling and sends it to the terminals of the expected participants; S5. Authentication of participants: Participants log in through the conference terminal and provide authentication information. If the system verifies that the information matches, the participants are allowed to attend the conference. If the information does not match, the participants are rejected and the relevant personnel are notified. S6. Conference status monitoring: The conference server monitors the status of participants in real time; S7, signaling transmission: The conference server uses encryption technology to transmit the signaling of the video conference content to the terminals of the participants securely, in real time, and accurately, uses network isolation technology to filter illegal signaling, and performs cell delay evaluation; S8, abnormal handling and alarm: the conference server triggers an alarm when it detects abnormal behavior, records the information and notifies the conference organizer and management personnel to handle it; S9. End of meeting and release of resources: When the meeting ends, the server sends an end signal to the participating terminals, releases resources and updates the status; records key information of the meeting and stores logs for subsequent audit analysis.

2. The signaling transmission method for intercommunication between video conference systems in a network isolation environment according to claim 1 is characterized in that: Step S1 includes the following steps: S11. Establish the boundaries of network isolation: determine which video conferencing systems need to be isolated and their locations in the network; analyze the functions and requirements of the systems to determine the level and method of isolation; S12. Plan isolation strategy: Develop an isolation strategy based on the sensitivity and importance of the video conferencing system; S13. Deploy firewalls: Deploy firewall devices at the network boundary to ensure that communications between video conferencing systems are controlled; configure firewall rules to allow legitimate signaling and data transmission while preventing unauthorized access; S14. Establish VPN tunnel: Establish VPN tunnel between video conferencing systems that need to communicate, configure VPN tunnel parameters, including tunnel protocol, encryption algorithm and key; test the connectivity and bandwidth of VPN tunnel; adjust VPN configuration according to test results to optimize performance and security; S15. Configure the DMZ area: divide a DMZ area in the network to place the server and terminals of the video conferencing system; configure the access control policy of the DMZ area to ensure that only legitimate users and devices can access it; use the intrusion detection system IDS and the intrusion prevention system IPS to monitor the security status of the DMZ area; S16. Allocate independent IP addresses and ports: Allocate independent IP addresses and ports to each video conferencing system; configure corresponding routing rules and port forwarding rules on network devices and routers; S17. Verification and testing: Use network scanning tools and security testing tools to verify the effectiveness of network isolation.

3. The signaling transmission method for intercommunication between video conference systems in a network isolation environment according to claim 1 is characterized in that: Step S3 includes the following steps: S31. Determine the verification method: determine the key data of the participants that need to be collected, including image information, identity information, and expected meeting time; select the appropriate identity verification method, including face recognition, fingerprint recognition, and password verification; S32. Design the architecture of the identity authentication system: Design the database table structure to store the key data of the participants; determine the storage format and encryption method of the data; design the interface between the identity authentication system and the video conferencing system, and determine the data format and communication protocol of the interface; S33. Build an identity authentication system: Develop the front-end interface of the identity authentication system for participants to input identity information and perform identity authentication; develop the back-end logic of the identity authentication system, including data processing and identity authentication algorithms; implement interface docking with the video conferencing system to ensure that data can be synchronized accurately and in real time; S34. Test the identity authentication system: Test the various functions of the identity authentication system, including identity authentication and data synchronization; ensure that the system can correctly identify the participants and update the data of the video conferencing system in real time; test the performance of the identity authentication system to ensure that the system can operate stably under high concurrency and meet business needs; test the security of the identity authentication system to ensure that the system can protect the personal privacy and data security of the participants; S35. Deploy the online identity authentication system: Deploy the identity authentication system to the server or cloud platform to ensure the stability and scalability of the system; configure the necessary network and security settings, connect the identity authentication system with the video conferencing system, and ensure that participants can successfully authenticate and participate in the meeting; S36. Continuous optimization and maintenance: Regularly update key data of participants to ensure data accuracy and timeliness; continuously optimize the performance and functionality of the identity authentication system based on business needs and technological development.

4. The signaling transmission method for intercommunication between video conference systems in a network isolation environment according to claim 3 is characterized in that: In step S34, the system security is evaluated according to the following formula: CSES=α×(w KL ×KLS+w SI ×SIS)+β×(ETS+DTS) / 2; where CSES is the comprehensive safety efficiency score; α is the safety efficiency weight coefficient; w KL is the key length adjustment weight coefficient; KLS is the specific key length score; w SI is the security strength weight coefficient; SIS is the Enhanced Security Strength Score; β is the efficiency-security balance weight coefficient; ETS and DTS are the encryption time score and decryption time score, which respectively represent the time performance of the encryption algorithm during the encryption and decryption processes.

5. The signaling transmission method for intercommunication between video conference systems in a network isolation environment according to claim 1, characterized in that: Step S5 includes the following steps: S51, receiving a conference invitation and logging into the video conference system: the conference participant receives a conference invitation from the conference organizer; according to the information in the conference invitation, the participant logs into the video conference system through a designated conference terminal; S52. Provide identity verification information: The participant follows the prompts and enters basic information such as username and password; the system identifies biometric features, including facial recognition or fingerprint recognition; S53, collecting and sending image information: collecting real-time image information of the participants; encrypting the collected image information and sending it to the identity authentication server for comparison; S54, the identity verification system compares information: the identity verification system receives and decrypts the image information; compares the received image information with the information of the participants stored in the database; and determines whether the identities of the participants match based on the comparison results; S55, identity verification result processing: when it is confirmed that the identity of the participant matches, a participant authorization token is generated and sent to the conference terminal, allowing the participant to attend the conference and granting the corresponding authorization; when it does not match, the participant is refused to join and the conference organizer and manager are notified so that further measures can be taken; S56, meeting records and subsequent processing: The system records the entire identity authentication process and generates a report containing the identity authentication results for review after the meeting. When anomalies or security issues are found, the system immediately issues an alarm and takes measures.

6. The signaling transmission method for intercommunication between video conference systems in a network isolation environment according to claim 1, characterized in that: Step S7 includes the following steps: S71, video conference content collection: the conference server collects video and audio content; S72, video conference content encoding: encoding the collected video and audio content into a format suitable for network transmission; S73, establishing a connection: selecting a TCP / IP real-time communication transmission protocol and configuring a corresponding port to ensure that the selected protocol can support real-time transmission of video conference content and reliable transmission of signaling; the conference server establishes a network connection with the conference terminals of all participants; S74, generating signaling: generating signaling containing video and audio data packets according to the encoding result of the video conference content and the list of participants; the signaling contains the sequence number, timestamp and check code information of the data packet; S75, Encrypted signaling: Use TLS / SSL encryption technology to encrypt signaling, ensure the security and privacy of the key during the encryption process, and avoid key leakage or cracking; S76, transmitting signaling: transmitting the encrypted signaling to the conference terminals of all participants through the network; S77, signaling filtering and restriction: configure a firewall between the conference server and the participating terminals, restrict signaling transmission through IP, port, and protocol filtering, establish VPN encrypted communication, configure ACL to restrict access, and evaluate cell delay; S78, receiving and decoding video conference content: the participating terminal receives and decrypts the server signaling, decodes the video and audio according to the data packet information, and pays attention to parameter selection to ensure playback quality; S79, play video and audio: play the decoded video and audio content through the display and speaker of the conference terminal.

7. The signaling transmission method for intercommunication between video conference systems in a network isolation environment according to claim 6 is characterized in that: In step S74, the size of the data packet is calculated according to the following formula: P size =u1*Enc(V)+u2*Comp(A)+u3*Hdr(H)+u4*Redundancy; where P size Indicates the total size of each data packet; u1 indicates the weight coefficient of the video data part; Enc(V) indicates the effective size of the video data part after encoding; V is the original representation of the video data, and Enc(V) is the encoded video data; U2 indicates the weight coefficient of the audio data part; Comp is a function that represents the compression process; A is the original representation of the audio data, Comp(A) is the compressed audio data; U3 is the weight coefficient of the header information; Hdr(H) is the effective size of the header information; H is the original representation of the header information; U4 is the redundancy coefficient; Redundancy is the size of the redundant data added to the data packet.

8. The signaling transmission method for intercommunication between video conference systems in a network isolation environment according to claim 6, characterized in that: In step S76, the encryption time is calculated according to the following formula: Where, T encrypt is the encryption processing time; K1 is the complexity coefficient of the encryption algorithm; P size is the packet size; η is the coefficient of influence of data packet size on encryption processing time; K2 is the efficiency factor of encryption algorithm under parallel processing; P parallel is the actual parallel processing capability; P max It is the processing capacity corresponding to the maximum parallel processing speedup ratio that the encryption algorithm can achieve on a given hardware; K3 is the fixed overhead coefficient in the encryption process; The playback delay is calculated as follows: D play = (T 收 + ΔT 网 ) + (T 解密 + ΔT 解密-延迟 ) + (T 解码 + ΔT 解码-延迟 ) + T 缓冲 - T 发 ; wherein, D play Indicates playback delay; T 收 is the data receiving time; ΔT 网 is the network transmission delay; T 解密 is the time required for the decryption operation; T 解密-延迟 is the additional delay of decryption processing; T 解码 is the time required for the decoding operation; T 解码-延迟 is the additional delay of decoding processing; T 缓冲 is the buffer delay; T 发 It is the time when the data is sent.

9. The signaling transmission method for intercommunication between video conference systems in a network isolation environment according to claim 6, characterized in that: In step S78, the decryption time is calculated according to the following formula: Where, T decode is the total time required for decoding; k4 and k6 are constant factors; η′ is the processing efficiency of the decoder; k5 is a coefficient used to adjust the impact of parallel processing on decoding time; P parallel ′ is the number of packets or tasks that the decoder can process in parallel; P max ′ is the maximum number of packets or tasks that the decoder can process at one time; K7 is a constant term.

10. The signaling transmission method for intercommunication between video conference systems in a network isolation environment according to claim 1, characterized in that: Step S77 includes the following steps: S771. Configure the firewall for signaling filtering and restriction: Identify the legal signaling between the conference server and the participating terminals, determine its IP, port and protocol, log in to the firewall management interface, apply IP, port and protocol filtering rules, ensure that the rules are effective and monitor the logs to block illegal signaling; S772. Establish a virtual private network (VPN): determine the VPN type and encryption algorithm, configure the VPN server and client of the conference server and the participating terminals, set ACL to restrict signaling access, and perform connection test after completing the configuration to ensure that the communication stability, security and bandwidth meet the requirements; S773, performing cell delay autocorrelation evaluation: collecting cell delay data of the communication link between the conference server and the participating terminals, calculating the autocorrelation coefficient and analyzing its trend and characteristics, and evaluating the stability and predictability of the delay; The cell delay autocorrelation is evaluated according to the following formula: Where R(τ) is the autocorrelation function, which is used to evaluate the similarity of the delay sequence under different time delays τ; τ is the time delay; M is the total number of cells in the delay sequence; C1 is the adjustment coefficient; C2 is the attenuation coefficient; d i is the measured delay value of the ith cell; μ d is the time delay sequence d i ; Exp[-C2|i-(i+|τ|)|] is the decay function, which is used to reflect the decay effect of delay similarity over time.

Citation Information

Patent Citations

  • Signaling transmission method

    CN110213029A

  • Information internal and external network video conference intercommunication system and method based on isolation device

    CN114553509A

  • Storage network management device for cloud video conference

    CN213187056U

  • Methods and systems for HUB high availability and network load and scaling

    US20160080268A1

  • Communication protocols over internet protocol (IP) networks

    US20230216864A1