A signaling transmission method for intercommunication of a video conference system in a network isolation environment

By using technologies such as firewalls, VPN tunnels, and DMZs in a network-isolated environment, and an authentication system, the communication security and stability issues of the video conferencing system were resolved. This enabled secure and reliable signaling transmission and participant authentication, ensuring the smooth operation of video conferences.

CN119995924BActive Publication Date: 2025-12-26STATE GRID INFORMATION & TELECOMM BRANCH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411910181.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-24
Publication Date
2025-12-26
Estimated Expiration
2044-12-24

AI Technical Summary

Technical Problem

In a network-isolated environment, video conferencing systems face communication security issues, including risks of unauthorized intrusion and data leakage, insufficient authentication, communication instability, and inadequate signaling filtering restrictions, which affect the security and stability of the meeting.

Method used

The system employs technologies such as firewalls, VPN tunnels, and DMZ to strictly control communication between video conferencing systems, establishes an authentication system to ensure the identity verification of legitimate participants, filters and encrypts signaling through firewalls or VPNs, monitors the status of participants in real time, and uses SDN technology to achieve dynamic allocation and configuration of network resources.

Benefits of technology

It effectively prevents unauthorized intrusion and data leakage, ensures that only legitimate signals pass through, improves the security and stability of meetings, enables real-time authentication and status monitoring, and ensures real-time playback of video and audio content.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995924B_ABST
    Figure CN119995924B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of signal processing, and discloses a signaling transmission method for intercommunication of a video conference system in a network isolation environment, comprising the following steps: configuring a network isolation environment, allocating independent addresses and ports for the video conference system; deploying the video conference system; establishing an identity authentication system; creating and setting conference details through a management system, generating a secure invitation signaling and sending it to a terminal of an expected participant; the participant logs in through a conference terminal and provides identity authentication information; real-time monitoring of the participant state; transmitting the signaling of the video conference content to the terminal of the participant through encryption technology, and performing cell delay evaluation; the conference server detects abnormal behavior and triggers an alarm. The application filters and limits the signaling through network isolation technologies such as firewalls or VPNs, reduces communication failures, encrypts the signaling, prevents data leakage or tampering, and ensures the real-time playing of video and audio content through fast and efficient decryption and decoding processes.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of signal processing, more particularly, to a signaling transmission method for intercommunication of a video conference system in a network isolation environment. BACKGROUND

[0002] In a network isolation environment, the security of a video conference system is particularly important. As part of the video conference system, signaling transmission also needs to have corresponding security measures. Through security mechanisms such as encryption and authentication, the security and privacy of the signaling transmission process can be ensured, and sensitive information can be prevented from being leaked or tampered with. Signaling is the key to realizing the intercommunication of a video conference system. In a network isolation environment, a video conference system needs to use signaling to establish, maintain, and terminate connections. The accuracy and timeliness of signaling transmission directly affect the stability and reliability of the video conference system. If there are problems in signaling transmission, it may result in consequences such as the inability to establish a connection, a decrease in call quality, and call interruption.

[0003] The prior art document with publication number CN110213029A provides a signaling transmission method. The method includes: a host device sends a communication instruction to N slave devices in a transmission time slot; and the host device receives information sent by each slave device in a first reception time slot to an Nth reception time slot through at least one with a fixed delay. The communication instruction is sent to N slave devices in the transmission time slot, and the information sent by each slave device is received in the first reception time slot to the Nth reception time slot through at least one with a fixed delay. The signaling transmission method allows one host device to support any number of slave devices, and at most N slave devices can speak at the same time.

[0004] The prior art solution in the above has the following defects although the related beneficial effects can be achieved by the structure of the prior art: 1. Communication security problem: the communication between video conference systems may not be strictly controlled, and there is a risk of illegal intrusion and data leakage. The signaling may not be encrypted during transmission, resulting in signaling data being easily stolen or tampered with. 2. Lack of effective identity verification system, which allows illegal participants to mix into the conference, reducing the security of the conference. 3. Communication instability problem: the communication path is not clear, increasing the risk of communication failure. The conference server cannot monitor the status of the participants in real time, affecting the smooth progress of the conference. 4. Insufficient signaling filtering and limiting: in the signaling transmission process, there is a lack of effective filtering and limiting of network isolation technologies such as firewalls and VPNs, resulting in the passage of illegal signaling and increasing the likelihood of communication failure. Even if the signaling is encrypted, the configuration of the firewall and VPN may not be perfect enough to effectively prevent illegal signaling or attacks from entering.

[0005] In view of this, we propose a signaling transmission system and method for video conference system intercommunication in a network isolation environment. SUMMARY

[0006] 1. Technical problem to be solved

[0007] The purpose of the present application is to provide a signaling transmission method for video conference system intercommunication in a network isolation environment, which solves the technical problems raised in the background art and achieves strict control of communication between video conference systems by using firewall, VPN tunnel, DMZ, etc., effectively preventing illegal intrusion and data leakage; through an identity verification system, only legal participants can join the conference, improving the security of the conference; in the signaling transmission process, the signaling is filtered and limited through firewall or VPN network isolation technology, ensuring that only legal signaling can pass through, reducing communication failures. The signaling is encrypted to prevent data leakage or tampering; the decryption and decoding process is fast and efficient, ensuring the real-time playback of video and audio content.

[0008] 2. Technical solution

[0009] The technical solution of the present application provides a signaling transmission method for video conference system intercommunication in a network isolation environment, including the following steps:

[0010] S1, configure a network isolation environment: establish a network isolation boundary, use advanced firewall technology, deep packet inspection (DPI), and behavior-based threat detection (BTD) system to ensure that communication between video conference systems is strictly controlled. Use SDN (Software Defined Network) technology to achieve dynamic allocation and configuration of network resources, ensuring that the video conference system can adapt to different network environments and requirements. Assign each video conference system an independent IP address and port, use IPv6 address space to increase the richness and security of the address.

[0011] S2, deploy video conference system: deploy video conference system including conference server, conference terminal and other components in each subnet or area of the network isolation environment. Ensure that the network connection between video conference systems is normal, and configure necessary network isolation and access control policies. Use containerization technology and Kubernetes cluster management to achieve fast deployment and automatic expansion of video conference system. Combine micro-isolation technology to provide fine-grained access control policies for each component of the video conference system.

[0012] S3, establish an identity verification system: establish an identity verification system containing key data such as participant image information, identity information, and expected participation time. Ensure data synchronization and real-time update between the identity verification system and the video conference system.

[0013] S4, Conference creation and invitation sending: The conference organizer creates a conference through the video conference management system and sets the detailed information of the conference, including the list of participants, conference time, etc. The system generates conference invitation signaling and sends it to the conference terminals of the expected participants through a secure communication channel.

[0014] S5, Participant identity verification: After receiving the conference invitation, the participant logs in to the video conference system through the conference terminal. The system requires the participant to provide identity verification information, such as username, password, biometric features (such as facial recognition), etc. The conference terminal collects the image information of the participant and sends it to the identity verification system for comparison. The identity verification system compares the image information of the participant with the information stored in the database to confirm whether the identity matches. If the identity verification system confirms that the participant's identity matches, it allows him / her to join the conference and grants the corresponding participant rights. If the identity verification system finds that the participant does not match the expected participant, it immediately denies him / her to join the conference and notifies the conference organizer and relevant management personnel.

[0015] S6, Conference state monitoring: The conference server monitors the state of the participants in real time, including whether they are online, whether they are speaking, whether they are leaving the conference, etc.

[0016] S7, Signaling transmission: The conference server transmits the video conference content to all participants' conference terminals through signaling to ensure real-time and accuracy of information. During the signaling transmission process, encryption technology (such as TLS / SSL) is used to encrypt the signaling to ensure the security of the signaling during transmission. Network isolation technologies such as firewalls or VPNs are used to filter and limit the signaling to ensure that only legitimate signaling can pass. Perform signaling delay autocorrelation evaluation.

[0017] S8, Abnormal handling and alarm: If the conference server detects abnormal behavior of the participant, it immediately triggers the alarm mechanism. The system records the relevant information of the abnormal behavior and notifies the conference organizer and relevant management personnel for handling.

[0018] S9, Conference end and resource release: When the conference ends, the conference server sends the conference end signaling to all participants' conference terminals. After receiving the end signaling, the participants' conference terminals release local resources and exit the conference. The conference server releases conference resources and updates conference state information in the database. The system records key information (such as participant list, conference duration, abnormal behavior, etc.) during the conference and stores it in the log file for subsequent audit and analysis.

[0019] Through the technical scheme, the safety, reliability and high efficiency of signaling transmission between video conference systems in a network isolation environment can be ensured. Meanwhile, a safe and controllable video conference environment is provided for participants, and identity authentication of the participants and real-time monitoring of the participation state are realized.

[0020] As an optional solution of the present application, step S1 comprises the following steps:

[0021] S11, establishing the boundary of network isolation: determining which video conference systems need to be isolated and their positions in the network. Analyzing the functions and requirements of these systems to determine the level and manner of isolation.

[0022] S12, planning the isolation strategy: according to the sensitivity and importance of the video conference systems, formulating the isolation strategy. Determining to use firewalls, VPN tunnels or DMZs to realize isolation.

[0023] S13, deploying firewalls: deploying firewall devices at the network boundary to ensure that the communication between video conference systems is controlled. Configuring firewall rules to allow legal signaling and data transmission while preventing unauthorized access. Regularly checking firewall logs to analyze abnormal traffic and potential threats. Updating firewall rules to address new threats and vulnerabilities.

[0024] S14, establishing VPN tunnels: establishing VPN tunnels between video conference systems that need to communicate. Configuring VPN tunnel parameters such as tunnel protocol, encryption algorithm, key, etc.

[0025] Testing and optimizing VPN performance: testing the connectivity and bandwidth of the VPN tunnel. Adjusting the VPN configuration according to the test results to optimize performance and security.

[0026] S15, configuring DMZ area (isolation area): dividing a DMZ area in the network for placing servers and terminals of video conference systems. Configuring access control policies for the DMZ area to ensure that only legal users and devices can access it. Using intrusion detection systems (IDS) and intrusion prevention systems (IPS) to monitor the security status of the DMZ area. Regularly checking the systems and devices in the DMZ area to ensure their security.

[0027] S16, assigning independent IP addresses and ports: assigning independent IP addresses and ports to each video conference system. Ensure that the allocation of IP addresses and ports complies with network address translation (NAT) and port forwarding rules. Configuring corresponding routing rules and port forwarding rules on network devices and routers. Ensure that the communication path between video conference systems is clear and secure.

[0028] S17. Verification and testing: Use network scanning tools and security testing tools to verify the effectiveness of network isolation. Ensure that the isolation strategy can effectively prevent unauthorized access and attacks. Test the communication functions of the video conference system in the network isolation environment. Ensure that the signaling and data between the video conference systems can be correctly transmitted and received.

[0029] As an optional solution of the present application, step S3 comprises the following steps:

[0030] S31. Determine the verification method: Determine the key data of the participants that need to be collected, including image information, identity information, and expected participation time. According to business needs, determine whether additional information such as mobile phone number, email address, etc. needs to be collected. Choose the appropriate identity verification method, such as face recognition, fingerprint recognition, password verification, etc. Consider the security and ease of use of the system to ensure that participants can easily perform identity verification.

[0031] S32. Design the architecture of the identity verification system: Design the database table structure to store the key data of the participants. Determine the storage format and encryption method of the data to protect personal privacy and data security. Design the interface between the identity verification system and the video conference system to ensure data synchronization and real-time update. Determine the data format and communication protocol of the interface, such as RESTful API, WebSocket, etc.

[0032] S33. Build the identity verification system: Develop the front-end interface of the identity verification system for participants to input identity information and perform identity verification. Ensure that the front-end interface is friendly, easy to operate, and provides clear error prompts and feedback. Develop the back-end logic of the identity verification system, including data processing, identity verification algorithms, etc. Implement the interface connection with the video conference system to ensure accurate and real-time data synchronization. Create a database and import the key data of the participants. Implement data addition, deletion, modification, and query operations to ensure data integrity and consistency.

[0033] S34. Test the identity verification system: Test the functions of the identity verification system, including identity verification, data synchronization, etc. Ensure that the system can correctly identify participants and update the data of the video conference system in real time. Test the performance of the identity verification system, including response time, concurrent processing capacity, etc. Ensure that the system can run stably under high concurrency and meet business needs. Test the security of the identity verification system, including data encryption, prevention of SQL injection, etc. Ensure that the system can protect the personal privacy and data security of the participants.

[0034] S35, deploy the online identity verification system: deploy the identity verification system to the server or cloud platform, ensure the stability and scalability of the system. Configure the necessary network and security settings to ensure that the system can run normally and prevent unauthorized access. Integrate the identity verification system with the video conference system to ensure that the participants can smoothly perform identity verification and participate in the meeting. Monitor the running status of the system and timely discover and handle potential problems and failures.

[0035] S36, continuous optimization and maintenance: regularly update the key data of the participants to ensure the accuracy and timeliness of the data. Timely handle problems and exceptions in the data synchronization and update process. According to the business needs and technological development, continuously optimize the performance and functions of the identity verification system. Introduce new identity verification technologies and algorithms to improve the security and ease of use of the system. Establish a failure handling mechanism to respond and handle failures and problems in the identity verification system in a timely manner. Regularly backup and restore data to ensure the reliability of the system and the security of the data.

[0036] Through the above technical scheme, an identity verification system containing image information, identity information, and expected participation time of participants is established, and data synchronization and real-time update between the system and the video conference system are ensured. It helps to improve the security and efficiency of the video conference system and protect the personal privacy and data security of the participants.

[0037] As an optional solution of the present application, step S5 includes the following steps:

[0038] 1, receiving meeting invitation and logging into video conference system: the participants receive the meeting invitation sent by the meeting organizer. According to the information in the meeting invitation, the participants log into the video conference system through the designated conference terminal (such as computer, mobile phone, tablet computer or special video conference equipment).

[0039] 2, provide identity verification information: the system interface prompts the participants to input identity verification information. The participants input the basic information such as username and password according to the prompt. The system identifies the biological characteristics, including face recognition or fingerprint recognition and other biological characteristic verification.

[0040] 3, collect and send image information: the camera built-in or externally connected in the conference terminal collects the real-time image information of the participants. The system encrypts the collected image information and sends it to the identity verification server for comparison.

[0041] 4, identity verification system compares information: the identity verification system receives and decrypts the image information. The system compares the received image information with the participant information stored in the database. The comparison content includes but is not limited to: facial features, username, password, etc. The system judges whether the identity of the participant matches according to the comparison result.

[0042] 5. Identity verification result processing: If the identity verification system confirms that the participant's identity matches, the system immediately generates a participation permission token. The system sends the participation permission token to the conference terminal and allows the participant to join the conference. The participant can enjoy corresponding speaking, viewing, and file sharing permissions in the conference according to the permission token. If the identity verification system finds that the participant's identity does not match the expected identity, the system immediately denies the participant's access to the conference. The system also generates an identity verification failure notification and sends it to the conference organizer and relevant management personnel. After receiving the notification, the conference organizer and relevant management personnel can take further measures according to the actual situation, such as contacting the participant to confirm the identity or resending the conference invitation.

[0043] 6. Conference record and subsequent processing: The system records the entire identity verification process, including the participant's login time, identity verification result, and permission granting situation. After the conference ends, the system generates a conference report containing key information such as the identity verification result for the conference organizer and relevant management personnel to review. If any abnormalities or security issues are found during the identity verification process, the system immediately alerts the conference organizer and relevant management personnel and takes appropriate security measures.

[0044] As an optional solution of the present application, step S6 comprises the following steps:

[0045] 1. Configuration monitoring software: Configure the conference server to ensure that the conference server has been correctly configured and is running. Check the network connection to ensure smooth communication between the server and the participant's device. Install professional conference status monitoring software on the conference server. Configure software parameters to accurately identify the participant's status information.

[0046] 2. Real-time monitoring of participant status:

[0047] Online status monitoring: Real-time acquisition of participant's online status through monitoring software. If the participant logs in to the conference system and maintains the connection, it is marked as "online". If the participant disconnects or has not performed any operation for a long time, it is marked as "offline".

[0048] Speaking status monitoring: Use the audio recognition function of the conference system to monitor the participant's speaking situation. When the participant speaks, the software automatically captures and marks the speaking status as "speaking". When the participant stops speaking, the software updates the speaking status to "not speaking".

[0049] Leaving the conference monitoring: Monitor whether the participant actively exits the conference system or closes the conference window. If the participant's behavior of leaving the conference is detected, the software automatically updates the participant's status to "has left".

[0050] 3. Data processing: Collect the state information of the participants in real time and store it in the database of the server. Ensure the accuracy and completeness of the data for subsequent data analysis. Conduct statistical analysis on the collected data to understand the participation and activity level of the participants. Generate reports or charts to visually display the state distribution of the participants.

[0051] 4. Abnormality handling: If an abnormal state is detected (such as a large number of participants offline at the same time, frequent speech interruptions, etc.), trigger the alarm mechanism. The administrator should take timely measures to solve the problem after receiving the alarm to ensure the smooth progress of the meeting.

[0052] 5. Data backup: Regularly maintain and upgrade the conference server and monitoring software. Ensure system stability and reliability to continuously provide accurate monitoring services. Regularly backup the collected participant state data. Ensure quick recovery in case of data loss or damage.

[0053] Through the above technical solutions, the state of the participants can be monitored in real time, including whether they are online, whether they are speaking, whether they are leaving the meeting, etc. This helps the administrator to understand the progress of the meeting in a timely manner and take appropriate measures to ensure the smooth progress of the meeting.

[0054] As an optional solution of the present application, step S7 comprises the following steps:

[0055] 1. Video conference content collection: The conference server collects video and audio content from the video conference equipment. Ensure that the collected content is clear, coherent, and meets the requirements of the meeting.

[0056] 2. Video conference content encoding: Encode the collected video and audio content into a format suitable for network transmission (such as H.264 video encoding and AAC audio encoding). Pay attention to the selection of parameters such as code rate, resolution, and frame rate during encoding to ensure the balance between transmission efficiency and video quality.

[0057] 3. Connection establishment: Select a transmission protocol suitable for real-time communication (such as TCP / IP or UDP) and configure the corresponding port. Ensure that the selected protocol can support real-time transmission of video conference content and reliable transmission of signaling. The conference server establishes network connections with all participant meeting terminals. Use a handshake protocol to ensure the reliability and stability of the connection.

[0058] 4. Signaling generation: The conference server generates signaling containing video and audio data packets based on the encoding results of the video conference content and the participant list. The signaling should include sequence numbers, timestamps, and checksums of the data packets to ensure data integrity and order.

[0059] 5. Encryption of signaling: Use encryption technology (such as TLS / SSL) to encrypt the signaling. Ensure the security and privacy of the key during encryption to avoid key leakage or cracking.

[0060] 6. Transmission of signaling: The conference server transmits the encrypted signaling to all participants' conference terminals through the network. Ensure the stability of the network and the sufficiency of the bandwidth during transmission to avoid packet loss or delay.

[0061] 7. Signaling filtering and limiting: Configure a firewall between the conference server and the participants' conference terminals. Set the firewall rules to allow legitimate signaling to pass through and block illegal signaling or attacks. Use IP filtering, port filtering, or protocol filtering to limit the transmission of signaling. Establish a virtual private network (VPN) to provide a secure communication channel for the conference server and the participants' conference terminals. Use encryption technology (such as IPsec) to ensure the security of the signaling during transmission. Configure the access control list (ACL) of the VPN to limit the transmission path and access rights of the signaling. Perform cell delay autocorrelation evaluation.

[0062] 8. Receiving and decoding video conference content: The participants' conference terminals receive the signaling sent by the conference server. Use the corresponding decryption algorithm and key to decrypt the signaling.

[0063] Decode video and audio: The conference terminal decodes the video and audio data packets according to the packet sequence number, timestamp, and check code in the signaling. Pay attention to the selection of parameters such as code rate, resolution, and frame rate during decoding to ensure the playback quality of video and audio.

[0064] 9. Play video and audio: Play the decoded video and audio content through the display and speaker of the conference terminal. Ensure that the played content is consistent with the content collected by the conference server and meets the requirements of real-time and accuracy.

[0065] In this technical solution, the conference server can transmit the video conference content to all participants' conference terminals through the signaling and ensure the real-time and accuracy of the information. At the same time, use encryption technology and network isolation technology to encrypt and filter the signaling to ensure the security of the signaling during transmission.

[0066] As an optional solution of the present application, the signaling filtering and limiting includes the following steps:

[0067] 1. Configure firewall for signaling filtering and restriction: Identify the legal signaling types required for communication between the conference server and the participant terminals, such as SIP, RTP, etc. Determine the IP address range, port number, and protocol type used by these signaling. Log in to the management interface of the firewall device using administrator privileges. Choose the appropriate login method and interface according to the brand and model of the firewall device. In the firewall management interface, create IP filtering rules. Set the allowed or denied IP address segments according to the IP address range of the legal signaling. Create port filtering rules. Set the allowed or denied port range according to the port number used by the legal signaling. Configure protocol filtering rules, and set the allowed or denied protocol list according to the protocol type used by the legal signaling. Apply the configured filtering rules to the corresponding interfaces or areas of the firewall. Ensure that the filtering rules take effect, and monitor the firewall logs to check whether any illegal signaling has been blocked.

[0068] 2. Establish a virtual private network (VPN): Determine the type of VPN, such as IPsec VPN. Choose appropriate encryption algorithms and key management methods. Configure the VPN server on the conference server, including setting the authentication method, encryption method, etc. Ensure that the VPN server can correctly identify and allow legal signaling to pass through. Configure the VPN client on the conference terminals of the participants to connect to the conference server through the VPN. Ensure that the VPN client can be correctly configured and connected to the VPN server. Configure the access control list (ACL) on the VPN server to limit the transmission path and access rights of the signaling. Set the allowed or denied access rules according to the IP address, port number, and protocol type of the legal signaling.

[0069] After configuration, perform VPN connection testing to ensure that the conference server and the conference terminals of the participants can normally communicate through the VPN. Check the stability, security, and bandwidth performance indicators of the VPN connection.

[0070] 3. Perform cell delay autocorrelation evaluation: Collect the transmission delay data of the cells on the communication link between the conference server and the participant terminals. Ensure the accuracy and completeness of the data. Calculate the autocorrelation coefficient of the cell delay: use the autocorrelation function to calculate the autocorrelation coefficient of the cell delay. Analyze the trend and characteristics of the autocorrelation coefficient to evaluate the stability and predictability of the cell delay.

[0071] Perform cell delay autocorrelation evaluation according to the following formula:

[0072] In the formula, R(τ) is the autocorrelation function, which is used to evaluate the similarity of the delay sequence at different time delays τ. τ is the time delay, representing the time interval of the delay similarity that we want to analyze. In the autocorrelation function, τ usually takes different values to observe the similarity of the signal at different time delays. M is the total number of cells in the delay sequence. This value determines how many delay values we need to consider when calculating the autocorrelation function. C1 is the adjustment coefficient, which is used to control the sensitivity of the autocorrelation function to the delay difference. By adjusting the value of C1, we can change the degree of response of the autocorrelation function to the delay change. C2 is the attenuation coefficient, which is used to control the decay rate of the delay similarity over time.d i is the delay measurement value of the ith cell. It is an element in the delay sequence, representing the transmission delay of the signal from the sender to the receiver. μ d is the mean value of the delay sequence d i . This value is used to subtract from each delay value when calculating the autocorrelation function, to eliminate the influence of the average level of the delay sequence on the autocorrelation result. Exp[-C2∣i-(i+∣τ∣)∣] is the attenuation function, which reflects the decay effect of the delay similarity over time.

[0073] Analysis results: According to the calculation results of the autocorrelation coefficient, analyze the characteristics and rules of the cell delay. If the autocorrelation coefficient is high, it means that the cell delay has strong stability and predictability; if the autocorrelation coefficient is low, it may need to further optimize the network configuration or take other measures to reduce the delay fluctuation. According to the analysis results, optimize the network configuration, such as adjusting the router settings, increasing the bandwidth, etc., to reduce the cell delay and improve the communication quality.

[0074] 3. Beneficial effects

[0075] The one or more technical solutions provided in the technical scheme of the present application have at least the following technical effects or advantages:

[0076] 1. The application uses firewall, VPN tunnel, DMZ and other technologies to strictly control the communication between video conference systems, effectively preventing illegal intrusion and data leakage. The signaling is encrypted (such as TLS / SSL), ensuring the security of the signaling during transmission. Through the identity verification system, only legitimate participants can join the meeting, improving the security of the meeting.

[0077] 2. Assign an independent IP address and port to each video conference system to ensure the clarity and stability of the communication path. The conference server monitors the status of the participants in real time, including whether they are online, whether they are speaking, etc., to ensure the smooth progress of the meeting.

[0078] 3、In the process of signaling transmission, the signaling is filtered and limited through network isolation technologies such as firewall or VPN, to ensure that only legal signaling can pass through and reduce communication failures. The signaling is encrypted to ensure the security of the transmission process and prevent data leakage or tampering. The configuration of firewall and VPN further enhances the security of the conference system and limits the entry of illegal signaling or attacks.

[0079] 4、The decryption and decoding process is fast and efficient, ensuring real-time playback of video and audio content. The calculation of decoding time takes into account multiple factors, helping to optimize the decoding process and improve playback efficiency. BRIEF DESCRIPTION OF DRAWINGS

[0080] Figure 1 Flowchart of the signaling transmission method for intercommunication of video conference systems in a network isolation environment disclosed in the present application. DETAILED DESCRIPTION

[0081] The present application is further described in detail below in conjunction with the accompanying drawings.

[0082] REFERENCE Figure 1 The embodiments of the present application provide a signaling transmission method for intercommunication of video conference systems in a network isolation environment, comprising the following steps:

[0083] S1, configure the network isolation environment: establish the network isolation boundary, use advanced firewall technology, deep packet inspection (DPI) and behavior-based threat detection (BTD) system to ensure that the communication between video conference systems is strictly controlled. Utilize SDN (Software Defined Network) technology to realize dynamic allocation and configuration of network resources, ensuring that the video conference system can flexibly adapt to different network environments and requirements. Assign independent IP addresses and ports to each video conference system, use IPv6 address space to increase the richness and security of the address.

[0084] S2, deploy the video conference system: deploy the video conference system including conference server, conference terminal and other components within each subnet or area of the network isolation environment. Ensure that the network connection between video conference systems is normal, and configure necessary network isolation and access control policies. Utilize containerization technology and Kubernetes cluster management to realize fast deployment and automatic expansion of the video conference system. Combine micro-isolation technology to provide fine-grained access control policies for each component of the video conference system.

[0085] S3, establish an identity verification system: establish an identity verification system containing image information, identity information, expected attendance time and other key data of participants. Ensure data synchronization and real-time update between the identity verification system and the video conference system.

[0086] S4, Conference creation and invitation sending: The conference organizer creates a conference through the video conference management system and sets the detailed information of the conference, including the list of participants, conference time, etc. The system generates conference invitation signaling and sends it to the conference terminals of the expected participants through a secure communication channel.

[0087] S5, Participant identity verification: After receiving the conference invitation, the participant logs in to the video conference system through the conference terminal. The system requires the participant to provide identity verification information, such as username, password, biometric features (such as facial recognition), etc.

[0088] The conference terminal collects the image information of the participant and sends it to the identity verification system for comparison. The identity verification system compares the image information of the participant with the information stored in the database to confirm whether the identity matches.

[0089] If the identity verification system confirms that the participant's identity matches, it allows them to join the conference and grants them the corresponding participant permissions.

[0090] If the identity verification system finds that the participant does not match the expected participant, it immediately denies their entry into the conference and notifies the conference organizer and relevant management personnel.

[0091] S6, Conference state monitoring: The conference server monitors the status of the participants in real time, including whether they are online, whether they are speaking, whether they are leaving the conference, etc.

[0092] S7, Signaling transmission: The conference server transmits the video conference content to all participant conference terminals through signaling, ensuring real-time and accuracy of information. During the signaling transmission process, encryption technology (such as TLS / SSL) is used to encrypt the signaling to ensure the security of the signaling during transmission. Network isolation technologies such as firewalls or VPNs are used to filter and limit signaling, ensuring that only legitimate signaling can pass. Perform signal cell delay autocorrelation evaluation.

[0093] S8, Abnormal handling and alarm: If the conference server detects abnormal behavior of the participant (such as unauthorized speech, attempts to access sensitive information, etc.), it immediately triggers the alarm mechanism. The system records relevant information about the abnormal behavior and notifies the conference organizer and relevant management personnel for handling.

[0094] S9, Conference end and resource release: When the conference ends, the conference server sends a conference end signaling to all participant conference terminals. After receiving the end signaling, the participant's conference terminal releases local resources and exits the conference. The conference server releases conference resources and updates conference state information in the database. The system records key information during the conference (such as participant list, conference duration, abnormal behavior, etc.) and stores it in log files for subsequent audit and analysis.

[0095] In this technical solution, the security, reliability and efficiency of signaling transmission between video conference systems in a network isolation environment can be ensured. At the same time, a safe and controllable video conference environment is provided for participants, realizing real-time monitoring of participant identity verification and participation status.

[0096] Further, step S1 includes the following steps:

[0097] S11, establish the boundary of network isolation: determine which video conference systems need to be isolated and their location in the network. Analyze the functions and needs of these systems to determine the level and method of isolation.

[0098] S12, plan the isolation strategy: according to the sensitivity and importance of the video conference system, formulate the isolation strategy. Determine the use of firewall, VPN tunnel or DMZ, etc. to realize isolation.

[0099] S13, deploy firewall: deploy firewall devices at the network boundary to ensure that communication between video conference systems is controlled. Configure firewall rules to allow legitimate signaling and data transmission while preventing unauthorized access. Regularly check firewall logs to analyze abnormal traffic and potential threats. Update firewall rules to address new threats and vulnerabilities.

[0100] S14, establish VPN tunnel: establish a VPN tunnel between video conference systems that need to communicate. Configure VPN tunnel parameters such as tunnel protocol, encryption algorithm, key, etc.

[0101] Test and optimize VPN performance: test the connectivity and bandwidth of the VPN tunnel. Adjust the VPN configuration based on test results to optimize performance and security.

[0102] S15, configure DMZ area (isolation area): divide a DMZ area in the network for placing servers and terminals of video conference systems. Configure access control policies for the DMZ area to ensure that only legitimate users and devices can access it.

[0103] Use intrusion detection systems (IDS) and intrusion prevention systems (IPS) to monitor the security status of the DMZ area. Regularly check systems and devices within the DMZ area to ensure their security.

[0104] S16, assign independent IP addresses and ports: assign independent IP addresses and ports to each video conference system. Ensure that the allocation of IP addresses and ports complies with network address translation (NAT) and port forwarding rules. Configure corresponding routing rules and port forwarding rules on network devices and routers. Ensure that the communication path between video conference systems is clear and secure.

[0105] S17, Verification and Testing: Use network scanning tools and security testing tools to verify the effectiveness of network isolation. Ensure that the isolation strategy can effectively prevent unauthorized access and attacks.

[0106] Test the communication function of the video conference system in the network isolation environment. Ensure that the signaling and data between the video conference systems can be correctly transmitted and received.

[0107] Further, step S3 includes the following steps:

[0108] S31, Determine the verification method: Determine the key data of the participants that need to be collected, including image information (such as photos), identity information (such as name, department, position, etc.), and expected attendance time. According to business needs, determine whether to collect additional information such as mobile phone number and email address.

[0109] Select the appropriate identity verification method, such as face recognition, fingerprint recognition, password verification, etc. Consider the security and ease of use of the system to ensure that participants can easily perform identity verification.

[0110] S32, Design the architecture of the identity verification system: Design the database table structure to store the key data of the participants. Determine the storage format and encryption method of the data to protect personal privacy and data security.

[0111] Design the interface between the identity verification system and the video conference system to ensure that the data can be synchronized and updated in real time. Determine the data format and communication protocol of the interface, such as RESTful API, WebSocket, etc.

[0112] S33, Build the identity verification system: Develop the front-end interface of the identity verification system for participants to input identity information and perform identity verification. Ensure that the front-end interface is friendly, easy to operate, and provides clear error prompts and feedback. Develop the back-end logic of the identity verification system, including data processing, identity verification algorithms, etc. Implement the interface connection with the video conference system to ensure that the data can be accurately and timely synchronized.

[0113] The identity verification system is built based on a multi-factor authentication model, including knowledge factors and biological factors.

[0114] Knowledge factors: such as password, PIN code, etc., information that participants need to know.

[0115] Biological factors: such as fingerprint, facial features, etc., inherent biological characteristics of participants.

[0116] Create a database and import the key data of the participants. Implement data addition, deletion, modification, and query operations to ensure data integrity and consistency.

[0117] S34, test the identity verification system: test the functions of the identity verification system, including identity verification, data synchronization, etc. Ensure that the system can correctly identify the participants and update the data of the video conference system in real time. Test the performance of the identity verification system, including response time, concurrent processing capacity, etc. Ensure that the system can run stably under high concurrency and meet the business needs. Test the security of the identity verification system, including data encryption, prevention of SQL injection, etc. Ensure that the system can protect the personal privacy and data security of the participants. Evaluate the system security according to the following formula:

[0118] CSES = α × (w KL × KLS + w SI × SIS) + β × (ETS + DTS) / 2; In the formula, CSES is the comprehensive security efficiency score, which is a comprehensive index for evaluating the overall performance of the encryption algorithm in terms of security and efficiency. α is the security efficiency weight coefficient, which is the relative importance of security relative to efficiency. w KL is the key length adjustment weight coefficient, which represents the relative importance of the key length score after specific adjustment or optimization in the total security score. KLS is the specific key length score. This score represents the specific performance or advantage of the key length in the encryption algorithm. w SI is the security strength weight coefficient, which represents the relative importance of the security strength score in the total security score. SIS is the enhanced security strength score. This score represents the enhanced performance or advantage of the encryption algorithm in terms of security strength. β is the efficiency security balance weight coefficient. This coefficient represents the relative importance of efficiency relative to security in the comprehensive score. ETS and DTS are the encryption time score and decryption time score, respectively, representing the time performance of the encryption algorithm in the encryption and decryption processes.

[0119] S35, deploy the identity verification system online: deploy the identity verification system to the server or cloud platform, ensure the stability and scalability of the system. Configure the necessary network and security settings to ensure that the system can run normally and prevent unauthorized access. Integrate the identity verification system with the video conference system to ensure that the participants can smoothly perform identity verification and participate in the meeting. Monitor the running state of the system and timely discover and handle potential problems and failures.

[0120] S36. Continuous Optimization and Maintenance: Regularly update key data of meeting participants to ensure accuracy and timeliness. Promptly address problems and anomalies arising during data synchronization and updates. Continuously optimize the performance and functionality of the identity verification system based on business needs and technological advancements. Introduce new identity verification technologies and algorithms to improve system security and usability. Establish a fault handling mechanism to promptly respond to and resolve faults and problems occurring in the identity verification system. Regularly back up and restore data to ensure system reliability and data security.

[0121] This technical solution establishes an identity verification system that includes key data such as participant image information, identity information, and expected meeting time, and ensures data synchronization and real-time updates between this system and the video conferencing system. This helps improve the security and efficiency of the video conferencing system and protects the personal privacy and data security of participants.

[0122] Furthermore, step S5 includes the following steps:

[0123] 1. Receiving a Meeting Invitation and Logging into the Video Conferencing System: Participants receive a meeting invitation from the meeting organizer. Based on the information in the invitation, participants log into the video conferencing system using the designated meeting terminal (such as a computer, mobile phone, tablet, or dedicated video conferencing equipment).

[0124] 2. Provide identity verification information: The system interface prompts participants to enter identity verification information. Participants enter basic information such as username and password as prompted. The system then performs biometric verification, including facial recognition or fingerprint recognition.

[0125] 3. Image Acquisition and Transmission: The conference terminal's built-in or external camera captures real-time image information of the participants. The system encrypts the acquired image information and sends it to the authentication server for comparison.

[0126] 4. Identity Verification System: The identity verification system receives and decrypts image information. The system compares the received image information with the participant information stored in the database. The comparison includes, but is not limited to, facial features, username, and password. Based on the comparison results, the system determines whether the participant's identity matches. The identity verification efficiency is evaluated using the following formula:

[0127] In the formula, AVI is the Authentication Verification Index, used to comprehensively evaluate the performance of an authentication system. N true_passN is the number of participants who are truly authenticated, i.e., the number of participants correctly identified by the system as legitimate users. From all participants who attempt authentication, those who are correctly identified by the system as legitimate users are filtered out. total T is the total number of authentication attempts, including both successful and failed attempts. The number of participants who attempt to use the authentication system is counted, regardless of whether they are correctly identified by the system or not.a1 is a weight coefficient used to adjust the relative importance of authentication accuracy in AVI. max T is the maximum acceptable authentication time, representing the lower limit of system performance. min T is the desired minimum (or optimal) authentication time, which may be an ideal value but may not be achievable in practical applications. Depending on the technical level of the authentication system and user needs, a desired minimum authentication time is set. avg T is the actual time required for each participant to complete authentication. The total authentication time of all successful and failed attempts is added and then divided by the total number of authentication attempts.a2 is a weight coefficient used to adjust the relative importance of time efficiency in AVI.

[0128] 5、Authentication result processing: If the authentication system confirms that the participant's identity matches, the system immediately generates a participant permission token, and the system sends the participant permission token to the conference terminal, allowing the participant to join the conference. Participants can enjoy corresponding speaking, viewing, and sharing files in the conference according to the permission token.

[0129] If the authentication system finds that the participant does not match the expected participant, the system immediately denies the participant to join the conference. The system also generates an authentication failure notification and sends it to the conference organizer and relevant management personnel. After receiving the notification, the conference organizer and relevant management personnel can take further measures according to the actual situation, such as contacting the participant to confirm the identity, re-sending the conference invitation, etc.

[0130] 6、Conference records and subsequent processing: The system records the entire authentication process, including the login time of the participant, the authentication result, the permission granting situation, etc. After the conference ends, the system generates a conference report containing key information such as authentication results for the conference organizer and relevant management personnel to review.

[0131] If any abnormalities or security issues are found during the authentication process, the system immediately alerts the conference organizer and relevant management personnel and takes appropriate security measures.

[0132] In this technical solution, the identity of the participant can be accurately verified, thereby ensuring the security and effectiveness of the video conference.

[0133] Further, step S6 includes the following steps:

[0134] 1. Configure monitoring software: Configure the conference server to ensure that the conference server is properly configured and running. Check the network connection to ensure smooth communication between the server and the devices of the participants. Install professional conference status monitoring software on the conference server. Configure software parameters to accurately identify the status information of the participants.

[0135] 2. Real-time monitoring of participant status:

[0136] Online status monitoring: Real-time acquisition of the online status of participants through monitoring software. If the participant logs in to the conference system and maintains the connection, it is marked as "online". If the participant disconnects or has not performed any operation for a long time, it is marked as "offline".

[0137] Speech status monitoring: Use the audio recognition function of the conference system to monitor the speech of the participants. When the participant speaks, the software automatically captures and marks the speech status as "speaking". When the participant stops speaking, the software updates the speech status to "not speaking".

[0138] Leaving the conference monitoring: Monitor whether the participant voluntarily exits the conference system or closes the conference window. If the participant's behavior of leaving the conference is detected, the software will automatically update his status to "has left".

[0139] 3. Data processing: Collect the status information of the participants in real time and store it in the database of the server. Ensure the accuracy and integrity of the data for subsequent data analysis. Conduct statistical analysis on the collected data to understand the participation and activity of the participants. Generate reports or charts to visually display the status distribution of the participants.

[0140] 4. Abnormal handling: If an abnormal state is detected (such as a large number of participants offline at the same time, frequent speech interruptions, etc.), an alarm mechanism is triggered. After receiving the alarm, the administrator should take timely measures to solve the problem and ensure the smooth progress of the conference.

[0141] 5. Data backup: Regularly maintain and upgrade the conference server and monitoring software. Ensure system stability and reliability to continuously provide accurate monitoring services. Regularly backup the collected participant status data. Ensure quick recovery in case of data loss or damage.

[0142] In this technical solution, the status of the participants can be monitored in real time, including whether they are online, whether they are speaking, whether they are leaving the conference, etc. This helps the administrator to understand the progress of the conference in a timely manner and take appropriate measures to ensure the smooth progress of the conference.

[0143] Further, step S7 includes the following steps:

[0144] 1. Video conference content acquisition: The conference server acquires video and audio content from video conference devices such as cameras and microphones. Ensure that the acquired content is clear, coherent, and meets the requirements of the conference.

[0145] 2. Video conference content encoding: Encode the acquired video and audio content into a format suitable for network transmission, such as H.264 video encoding and AAC audio encoding. Pay attention to the selection of parameters such as code rate, resolution, and frame rate during encoding to ensure a balance between transmission efficiency and video quality.

[0146] 3. Establish connection: Select a transmission protocol suitable for real-time communication, such as TCP / IP or UDP, and configure the corresponding port. Ensure that the selected protocol can support real-time transmission of video conference content and reliable transmission of signaling.

[0147] The conference server establishes a network connection with all participants' conference terminals. Use a handshake protocol such as TCP three-way handshake to ensure the reliability and stability of the connection.

[0148] 4. Generate signaling: The conference server generates signaling containing video and audio data packets based on the encoding results of the video conference content and the list of participants. The signaling should contain information such as data packet sequence number, timestamp, and check code to ensure data integrity and order.

[0149] Calculate the size of the data packet as follows:

[0150] P size = u1 * Enc(V) + u2 * Comp(A) + u3 * Hdr(H) + u4 * Redundancy; where P sizeThe total size of each data packet. This is the sum of the number of bytes or bits occupied by the data packet during transmission. ui represents the weight coefficient of the video data part. This coefficient is used to adjust the relative importance of video data in the data packet. A larger ui value means that video data occupies a larger proportion in the data packet. Enc(V) represents the effective size of the video data part after encoding. Here, Enc is a function representing the encoding process, including compression, quantization, color space conversion, etc., to reduce the size of video data while maintaining the video quality as much as possible. V is the original representation of video data, and Enc(V) is the encoded video data. U2 represents the weight coefficient of the audio data part. This coefficient is used to adjust the relative importance of audio data in the data packet. A larger u2 value means that audio data occupies a larger proportion in the data packet. Comp(A) represents the effective size of the audio data part after compression processing. Comp is a function representing the compression process, involving sampling rate adjustment, bit rate control, audio format conversion, etc., to reduce the size of audio data while maintaining the audio quality as much as possible. A is the original representation of audio data, and Comp(A) is the compressed audio data. U3 represents the weight coefficient of the header information, used to adjust the relative importance of the header information in the data packet. Although the header information is usually small, it is crucial for the parsing and recombination of the data packet. Hdr(H) represents the effective size of the header information. Hdr is a function representing the generation process of the header information. The header information contains sequence numbers, timestamps, checksums, protocol identifiers, etc., key information to ensure the correct transmission and parsing of the data packet. H is the original representation of the header information, and Hdr(H) is the generated header information. U4 represents the redundancy coefficient, used to adjust the amount of redundant data in the data packet. Redundant data includes check codes, retransmission request information, etc., to improve the robustness and reliability of transmission. Redundancy represents the size of the redundant data added to the data packet, which can increase the reliability of transmission. For example, when an error is encountered during transmission, the receiving party can use the redundant data to detect and correct errors.

[0151] 5. Encryption signaling: Use encryption technology (such as TLS / SSL) to encrypt the signaling. During the encryption process, the security and privacy of the key should be ensured to avoid key leakage or cracking.

[0152] 6. Transmission signaling: The conference server transmits the encrypted signaling to all conference terminals of the participants through the network. During the transmission process, the stability of the network and the sufficiency of the bandwidth should be ensured to avoid data packet loss or delay.

[0153] The encryption time is calculated as follows:

[0154] In the formula, T encryptP is the encryption processing time. This is the target value that the formula calculates, representing the total time required to complete the encryption operation. K1 is the complexity coefficient of the encryption algorithm. This is a constant determined experimentally to describe the computational complexity of the encryption algorithm itself. It reflects the basic time overhead required by the encryption algorithm under fixed packet size and parallel processing capabilities. size This refers to the data packet size. This is the amount of data that the encryption operation needs to process, and it directly affects the encryption processing time. The larger the data packet, the longer the encryption time usually takes. η is the coefficient of influence of data packet size on encryption processing time. This is an exponential function determined experimentally to describe how data packet size affects encryption processing time. As η increases, it indicates that the impact of data packet size on encryption time becomes more significant. K2 is the efficiency factor of the encryption algorithm under parallel processing. This is a constant between 0 and 1, used to describe the execution efficiency of the encryption algorithm in a parallel environment. The closer k2 is to 1, the higher the parallel efficiency, meaning that increasing parallel processing capability can more effectively reduce encryption time. P parallel This refers to actual parallel processing capability. This can be the number of processors, threads, cores, or other measures of parallel processing capability, reflecting the number of tasks or computing power the system can handle simultaneously. max K0 represents the processing power corresponding to the maximum parallel processing speedup that the encryption algorithm can achieve on a given hardware. This is a constant determined experimentally, used to describe the maximum parallel processing power that the encryption algorithm can utilize under optimal conditions. K3 is a fixed overhead coefficient in the encryption process. This is a constant term used to represent the fixed overhead that prevents the encryption processing time from dropping to zero even without parallel processing power or when the data packet size is zero. This includes the overhead of operations such as algorithm initialization, memory allocation, and data copying.

[0155] Calculate playback delay using the following formula:

[0156] D play =(T 收 +ΔT 网 )+(T 解密 +ΔT 解密-延迟 )+(T 解码 +ΔT 解码-延迟 )+T 缓冲 -T 发 In the formula, D play This is the target value of the formula, representing the playback delay. Playback delay is the total time difference from when the signaling receives data until the data is decoded and played back. T 收 This is the data reception time. It represents the point in time when a data packet is received from the network or other transmission medium. This point in time is usually the moment the data packet arrives at the receiving end and is recorded by the receiving software or hardware. ΔT 网Network transmission delay, which represents the time required for a data packet to travel through the network path from the sender to the receiver. This time includes various transmission delays in the network, such as queuing delay, propagation delay, etc. 解密 Decryption time, which represents the time required for a data packet to be decrypted from the beginning to the end. This time depends on the complexity of the decryption algorithm and the processing power of the hardware. 解密-延迟 Decryption processing additional delay, which represents the time required for additional processing related to decryption, such as data preparation, memory access, CPU scheduling, etc. 解码 Decoding time, which represents the time required for a data packet to be decoded from the beginning to the end. This time depends on the complexity of the decoding algorithm and the processing power of the hardware. 解码-延迟 Decoding processing additional delay, which represents the time required for additional processing related to decoding. 缓冲 Buffering delay, which represents the time required for a data packet to be buffered before being played. This time is set to ensure the continuity and smoothness of the data, to avoid stuttering or interruption during playback. 发 Data sending time, which represents the time point when the sender starts to send a data packet. This time point is usually recorded by the sending software or hardware, and the data packet starts to be transmitted to the network.

[0157] 7. Signaling filtering and limiting: Configure a firewall between the conference server and the conference terminals of the participants. Set the firewall rules to allow legitimate signaling to pass through and block illegal signaling or attacks. Use IP filtering, port filtering, or protocol filtering to limit the transmission of signaling. Establish a virtual private network (VPN) to provide a secure communication channel for the conference server and the conference terminals of the participants. Use encryption technology (such as IPsec) to ensure the security of the signaling during transmission. Configure the access control list (ACL) of the VPN to limit the transmission path and access rights of the signaling. Perform signal delay autocorrelation evaluation.

[0158] 8. Receive and decode video conference content: The conference terminals of the participants receive the signaling sent by the conference server. Use the corresponding decryption algorithm and key to perform decryption processing on the signaling.

[0159] Decode video and audio: The conference terminals decode the video and audio data packets according to the sequence number, timestamp, and check code in the signaling. Pay attention to the selection of parameters such as code rate, resolution, and frame rate during decoding to ensure the playback quality of video and audio.

[0160] Calculate the decryption time as follows:

[0161] where T decode is the total time required for decoding. k4 and k6 are constant factors used to adjust the formula to match the actual situation, including some additional time overhead or efficiency loss that is not considered. η' is the processing efficiency of the decoder, representing the amount of data that can be processed per second under ideal conditions. k5 is a coefficient to adjust the impact of parallel processing on decoding time. It can depend on the specific implementation of the decoder and the effectiveness of parallel processing. parallel ' is the number of data packets or tasks that the decoder can process in parallel. This depends on the hardware and software implementation of the decoder, as well as the possible parallel processing strategy. max ' is the maximum number of data packets or tasks that the decoder can process at a time. This is usually limited by the size of the internal buffer or processing capacity of the decoder. size is the total size of the data packets that need to be decoded. K7 is a constant term representing the proportion factor of additional time overhead required in the decoding process besides packet processing, including initialization time, error handling time, etc.

[0162] 9. Play video and audio: Play the decoded video and audio content through the display and speakers of the conference terminal. Ensure that the played content is consistent with the content collected by the conference server and meets the requirements of real-time and accuracy.

[0163] In this technical solution, the conference server can transmit the video conference content to all participants' conference terminals through signaling and ensure the real-time and accuracy of the information. At the same time, encryption technology and network isolation technology are used to encrypt and filter the signaling, ensuring the security of the signaling in the transmission process.

[0164] Further, the signaling filtering and limiting includes the following steps:

[0165] 1. Configure firewall for signaling filtering and restriction: Identify the legal signaling types required for communication between the conference server and the participating terminals, such as SIP, RTP, etc. Determine the IP address range, port number, and protocol type used by these signaling. Log in to the management interface of the firewall device using administrator privileges. Choose the appropriate login method and interface according to the brand and model of the firewall device. In the firewall management interface, create IP filtering rules. Set the allowed or denied IP address segments according to the IP address range of the legal signaling. Create port filtering rules. Set the allowed or denied port range according to the port number used by the legal signaling. Configure protocol filtering rules, and set the allowed or denied protocol list according to the protocol type used by the legal signaling. Apply the configured filtering rules to the corresponding interfaces or areas of the firewall. Ensure that the filtering rules take effect, and monitor the firewall logs to check whether any illegal signaling has been blocked.

[0166] 2. Establish a virtual private network (VPN): Determine the type of VPN, such as IPsec VPN. Choose appropriate encryption algorithms and key management methods. Configure the VPN server on the conference server, including setting the authentication method, encryption method, etc. Ensure that the VPN server can correctly identify and allow legal signaling to pass through. Configure the VPN client on the conference terminals of the participants to connect to the conference server through the VPN. Ensure that the VPN client can be correctly configured and connected to the VPN server. Configure the access control list (ACL) on the VPN server to limit the transmission path and access rights of the signaling. Set the allowed or denied access rules according to the IP address, port number, and protocol type of the legal signaling.

[0167] After configuration, perform VPN connection testing to ensure that the conference server and the conference terminals of the participants can normally communicate through the VPN. Check the stability, security, and bandwidth performance indicators of the VPN connection.

[0168] 3. Perform cell delay autocorrelation evaluation: Collect the transmission delay data of the cells on the communication link between the conference server and the participating terminals. Ensure the accuracy and completeness of the data. Calculate the autocorrelation coefficient of the cell delay: use the autocorrelation function to calculate the autocorrelation coefficient of the cell delay. Analyze the trend and characteristics of the autocorrelation coefficient to evaluate the stability and predictability of the cell delay.

[0169] Perform cell delay autocorrelation evaluation according to the following formula:

[0170] In the formula, R(τ) is the autocorrelation function, which is used to evaluate the similarity of the delay sequence at different time delays τ. τ is the time delay, representing the time interval of the delay similarity to be analyzed. In the autocorrelation function, τ usually takes different values to observe the similarity of the signal at different time delays. M is the total number of cells in the delay sequence. This value determines how many delay values we need to consider when calculating the autocorrelation function. C1 is the adjustment coefficient, which is used to control the sensitivity of the autocorrelation function to the delay difference. By adjusting the value of C1, we can change the degree of response of the autocorrelation function to the delay change. C2 is the attenuation coefficient, which is used to control the decay rate of the delay similarity over time.d i is the delay measurement value of the ith cell. It is an element in the delay sequence, representing the transmission delay of the signal from the sender to the receiver. μ d is the mean value of the delay sequence d i . This value is used to subtract from each delay value when calculating the autocorrelation function, to eliminate the influence of the average level of the delay sequence on the autocorrelation result. Exp[-C2∣i-(i+∣τ∣)∣] is the attenuation function, which reflects the decay effect of the delay similarity over time.

[0171] According to the calculation result of the autocorrelation coefficient, the characteristics and laws of the cell delay are analyzed. If the autocorrelation coefficient is high, it means that the cell delay has strong stability and predictability; if the autocorrelation coefficient is low, it may need to further optimize the network configuration or take other measures to reduce the delay fluctuation. According to the analysis result, the network configuration is optimized, such as adjusting the router settings, increasing the bandwidth, etc., to reduce the cell delay and improve the communication quality.

[0172] The application strictly controls the communication between video conference systems by using firewall, VPN tunnel, DMZ and other technologies, effectively preventing illegal intrusion and data leakage. The signaling is encrypted (such as TLS / SSL), ensuring the security of the signaling during transmission. Through the identity verification system, only legitimate participants can join the meeting, improving the security of the meeting. Each video conference system is assigned an independent IP address and port, ensuring the clarity and stability of the communication path. The conference server monitors the status of the participants in real time, including whether they are online, whether they are speaking, etc., to ensure the smooth progress of the meeting. During the signaling transmission process, the signaling is filtered and limited through network isolation technologies such as firewall or VPN, ensuring that only legitimate signaling can pass through and reducing communication failures. The signaling has been encrypted, ensuring the security of the transmission process and preventing data leakage or tampering. The configuration of the firewall and VPN further enhances the security of the conference system, limiting the entry of illegal signaling or attacks. The decryption and decoding process is fast and efficient, ensuring the real-time playback of video and audio content. The calculation of decoding time takes into account multiple factors, helping to optimize the decoding process and improve playback efficiency.

[0173] The above-described embodiments are only used to illustrate the technical solutions of the present application, but not to limit the present application; although the present application has been described in detail with reference to the foregoing embodiments, it should be understood by those skilled in the art that the technical solutions recorded in the foregoing embodiments can be modified, or some technical features can be replaced by equivalent features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A signaling transmission method for intercommunication of video conference systems in a network isolation environment, characterized in that, The method comprises the following steps: S1, configuring a network isolation environment: configuring a network isolation environment, using a firewall, deep packet inspection DPI and behavior-based threat detection BTD system to strictly control video conference communication; using SDN technology to realize dynamic allocation of network resources, and allocating independent IPv6 addresses and ports for the video conference system; S2, deploying a video conference system: deploying a video conference system in a subnet or area of the network isolation environment, using containerization, Kubernetes and micro-isolation technology to realize rapid deployment, automatic expansion and fine-grained access control; S3, establishing an identity verification system: establishing an identity verification system containing the images, identities and expected attendance time data of the attendees, and realizing data synchronization and real-time update with the video conference system; S4, creating and sending invitations: the conference organizer creates and sets the conference details through the management system, and the system generates a secure invitation signaling and sends it to the terminals of the expected attendees; S5, attendee identity verification: the attendees log in through the conference terminal and provide identity verification information, and the system allows the attendees to attend if the verification is matched, and notifies the relevant personnel if the verification is not matched; S6, monitoring the conference state: the conference server monitors the state of the attendees in real time; S7, signaling transmission: the conference server transmits the video conference content signaling to the attendees' terminals in a secure, real-time and accurate manner through encryption technology, filters illegal signaling using network isolation technology, and evaluates the cell delay; S8, abnormality processing and alarm: the conference server detects abnormal behavior and triggers an alarm, records the information and notifies the conference organizer and management personnel to handle; S9, conference end and resource release: when the conference ends, the server sends an end signaling to the attendees' terminals, releases the resources and updates the state; records the key information of the conference and stores the log for subsequent audit analysis; Step S1 comprises the following steps: S11, determining the boundary of network isolation: determining which video conference systems need to be isolated and their location in the network; analyzing the functions and requirements of the system to determine the level and method of isolation; S12, planning the isolation strategy: developing an isolation strategy based on the sensitivity and importance of the video conference system; S13, deploying a firewall: deploying a firewall device at the network boundary to ensure that the communication between video conference systems is controlled; configuring firewall rules to allow legal signaling and data transmission while blocking unauthorized access; S14, establishing a VPN tunnel: establishing a VPN tunnel between the video conference systems that need to communicate, configuring VPN tunnel parameters including tunnel protocol, encryption algorithm and key; testing the connectivity and bandwidth of the VPN tunnel; adjusting the VPN configuration based on the test results to optimize performance and security; S15, configuring a DMZ area: dividing a DMZ area in the network for placing servers and terminals of the video conference system; configuring access control policies for the DMZ area to ensure that only legitimate users and devices can access; using an intrusion detection system IDS and an intrusion prevention system IPS to monitor the security status of the DMZ area; S16, assign independent IP address and port: assign independent IP address and port for each video conference system; configure corresponding routing rules and port forwarding rules on network equipment and router; S17, verification and test: use network scanning tools and security testing tools to verify the effect of network isolation.

2. The signaling transmission method for intercommunication of video conference systems in a network isolation environment according to claim 1, characterized in that: Step S3 includes the following steps: S31, determine the verification method: determine the key data of participants that need to be collected, including image information, identity information and expected attendance time; select the identity verification method, including face recognition, fingerprint recognition and password verification; S32, design the architecture of the identity verification system: design the database table structure for storing the key data of participants; determine the storage format and encryption method of data; design the interface between the identity verification system and the video conference system, and determine the data format and communication protocol of the interface; S33, build the identity verification system: develop the front-end interface of the identity verification system for participants to input identity information and perform identity verification; develop the back-end logic of the identity verification system, including data processing and identity verification algorithm; realize the interface connection with the video conference system to ensure accurate and real-time data synchronization; S34, test the identity verification system: test the functions of the identity verification system, including identity verification and data synchronization; ensure that the system can correctly identify participants and update the data of the video conference system in real time; test the performance of the identity verification system to ensure that the system can stably run under high concurrency and meet business requirements; test the security of the identity verification system to ensure that the system can protect the personal privacy and data security of participants; S35, deploy the identity verification system online: deploy the identity verification system to the server or cloud platform to ensure the stability and scalability of the system; configure network and security settings to connect the identity verification system with the video conference system to ensure that participants can smoothly perform identity verification and attend the meeting; S36, continuous optimization and maintenance: regularly update the key data of participants to ensure the accuracy and timeliness of the data; continuously optimize the performance and functions of the identity verification system according to business requirements and technological development.

3. The signaling transmission method for intercommunication of video conference systems in a network isolation environment according to claim 2, characterized in that: In step S34, the system security is evaluated as follows: CSES = a x (w KL KLS + w SI SIS) + b x (ETS + DTS) / 2; wherein CSES is a comprehensive security efficiency score; a is a security efficiency weight coefficient; w KL KLS is a key length adjustment weight coefficient; KLS is a key length score; w SI SIS is a security strength weight coefficient; SIS is the enhanced security strength score; β is the efficiency and security balance weight coefficient; ETS and DTS are encryption time score and decryption time score, respectively representing the time performance of encryption algorithm in encryption and decryption process.

4. The signaling transmission method for intercommunication of video conference systems in a network isolation environment according to claim 1, characterized in that: Step S5 includes the following steps: S51, receive meeting invitation and log in to video conference system: participants receive the meeting invitation sent by the meeting organizer; according to the information in the meeting invitation, log in to the video conference system through the designated meeting terminal; S52, provide identity verification information: participants input username and password basic information according to prompts; the system identifies biological characteristics, including face recognition or fingerprint recognition; S53, collect and send image information: collect real-time image information of participants; encrypt the collected image information and send it to the identity verification server for comparison; S54, the identity authentication system compares the information: the identity authentication system receives and decrypts the image information; compares the received image information with the participant information stored in the database; according to the comparison result, judges whether the identity of the participant is matched or not; S55, identity authentication result processing: when confirming that the identity of the participant is matched, generating and sending the participant permission token to the conference terminal, allowing the participant to join and giving corresponding permissions; if not matched, refusing to join and notifying the conference organizer and the management personnel, so as to take further measures; S56, conference record and subsequent processing: the system records the whole process information of identity authentication, generates a report containing the identity authentication result for reference after the conference ends, and immediately alarms and takes measures when abnormal or security problems are found.

5. The signaling transmission method for intercommunication of video conference systems in a network isolation environment according to claim 1, characterized in that: Step S7 includes the following steps: S71, video conference content collection: the conference server collects video and audio content; S72, video conference content coding: coding the collected video and audio content into a format suitable for network transmission; S73, connection establishment: selecting a transmission protocol for real-time communication of TCP / IP, and configuring the corresponding port to ensure that the selected protocol can support real-time transmission of video conference content and reliable transmission of signaling; the conference server establishes a network connection with all participant terminals; S74, signaling generation: generating signaling containing video and audio data packets according to the coding result of the video conference content and the participant list; the signaling contains sequence number, timestamp and check code information of the data packet; S75, encrypting the signaling: using TLS / SSL encryption technology to encrypt the signaling; in the encryption process, the security and privacy of the key are ensured to avoid key leakage or cracking; S76, transmitting the encrypted signaling: transmitting the encrypted signaling to all participant terminals through the network; S77, signaling filtering and limiting: configuring a firewall between the conference server and the participant terminal, limiting the transmission of signaling through IP, port and protocol filtering, establishing VPN encrypted communication, configuring ACL to limit access, and evaluating the cell delay; S78, receiving and decoding video conference content: the participant terminal receives and decrypts the server signaling, decodes the video and audio according to the data packet information, and pays attention to parameter selection to ensure the playback quality; S79, playing video and audio: playing the decoded video and audio content through the display and speaker of the conference terminal.

6. The signaling transmission method for intercommunication of video conference systems in a network isolation environment according to claim 5, characterized in that: In step S74, the size of the data packet is calculated as follows: P size = u1*Enc(V) + u2*Comp(A) + u3*Hdr(H) + u4*Redundancy; where P size represents the total size of each packet; u1 represents the weight coefficient of the video data portion; Enc(V) represents the effective size of the encoded video data portion; V is the original representation of the video data, and Enc(V) is the encoded video data; u2 represents the weight coefficient of the audio data portion; Comp is a function representing the compression process; A is the original representation of audio data, Comp(A) is the compressed audio data; U3 represents the weight coefficient of header information; Hdr(H) represents the effective size of header information; H is the original representation of header information; U4 represents the redundancy coefficient; Redundancy represents the size of the redundant data added to the data packet.

7. The signaling transmission method for intercommunication of video conference systems in a network isolation environment according to claim 5, characterized in that: In step S76, the encryption time is calculated as follows: where T encrypt is the encryption processing time; K1 is the complexity coefficient of the encryption algorithm; P size is the data packet size; η is the influence coefficient of data packet size on encryption processing time; K2 is the efficiency factor of encryption algorithm under parallel processing; P parallel is the actual parallel processing capability; P max is the maximum parallel processing speedup ratio of encryption algorithm on given hardware corresponding to the processing capability; K3 is the fixed overhead coefficient in encryption processing The playback delay is calculated as follows: D play = (T 收 + ΔT 网 ) + (T 解密 + ΔT 解密-延迟 ) + (T 解码 + ΔT 解码-延迟 ) + T 缓冲 - T 发 ; where D play represents the play delay; T 收 is the data reception time; ΔT 网 is the network transmission delay; T 解密 is the time required for decryption operation; T 解密-延迟 is the decryption processing extra delay; T 解码 is the time required for decoding operation; T 解码-延迟 is the decoding processing extra delay; T 缓冲 is the buffering delay; and T 发 is the data transmission time.

8. The signaling transmission method for intercommunication of video conference systems in a network isolation environment according to claim 5, characterized in that: In step S78, the decryption time is calculated as follows: where T decode is the total time required for decoding; k4 and k6 are constant factors; η' is the processing efficiency of the decoder; k5 is a coefficient to adjust the influence of parallel processing on decoding time; P parallel η' is the processing efficiency of the decoder; k5 is a coefficient to adjust the influence of parallel processing on decoding time; P max η' is the processing efficiency of the decoder; k5 is a coefficient to adjust the influence of parallel processing on decoding time; P 9. The signaling transmission method for intercommunication of video conference systems in a network isolation environment according to claim 1, characterized in that: Step S77 includes the following steps: S771, configure firewall for signaling filtering and limiting: identify the legal signaling between the conference server and the participating terminal, determine its IP, port and protocol, log in the firewall management interface, apply IP, port and protocol filtering rules, ensure that the rules take effect and monitor the log to prevent illegal signaling; S772, establish a virtual private network (VPN): determine the type of VPN and encryption algorithm, configure the VPN server and client of the conference server and the participating terminal, set ACL to limit signaling access, perform connection test after configuration to ensure communication stability, security and bandwidth meet the requirements; S773, perform cell delay autocorrelation evaluation: collect cell delay data of communication link between conference server and participating terminal, calculate autocorrelation coefficient and analyze its trend and characteristics, evaluate the stability and predictability of the delay; The cell delay autocorrelation evaluation is performed according to the following formula: where R(τ) is an autocorrelation function used to evaluate the similarity of the delay sequence at different time delays τ; τ is a time delay; M is the total number of cells in the delay sequence; C1is an adjustment coefficient; C2is a decay coefficient; d i is the delay measurement value of the i-th cell; μ d is the mean value of the delay sequence d i ; Exp[-C2| i-(i+ |τ|) |] is a decay function used to reflect the decay effect of the delay similarity over time.

Citation Information

Patent Citations

  • Signaling transmission method

    CN110213029A

  • Storage network management device for cloud video conference

    CN213187056U

  • Communication protocols over internet protocol (IP) networks

    US20230216864A1