Low-delay high-security data transmission method and system for video platform
By determining the key update association information and generation and execution strategies of each mobile terminal in the video platform, and building a key pair update list based on the user's dynamic feature set, the problem of low-latency and high-security data transmission in high-density communications is solved, and the dual optimization of security and delay is achieved.
Patent Information
- Application Number
- CN202510468788.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-15
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-04-15
AI Technical Summary
Existing video platforms are difficult to achieve low latency and high security data transmission in high-density communication applications, especially in the complex situations of key replacement frequency and data volume transmission requirements, resulting in communication delays and security risks.
By obtaining the planned transmission content in the data transmission task, determining the key update association information of each mobile terminal, and updating the data based on network bandwidth parameters and historical keys, generating a key update execution policy and a key cache execution policy. The key pair update list is constructed using the user's dynamic feature set, and after the encrypted tunnel is established, the key cache of the video platform and the key update of the target mobile terminal are performed.
It realizes the security of encrypted communication between the video platform and multiple mobile terminals, while reducing video latency and ensuring low latency and high security of data transmission.
Smart Images

Figure CN120018123A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication security technology, and in particular to a low-latency and high-security data transmission method and system for a video conferencing platform. Background Art
[0002] A videoconferencing platform is a software system or platform based on network technology that is used to implement various video interaction functions such as video communication, video conferencing, video live broadcast, and video on demand. It usually integrates multiple functional modules such as video encoding and decoding, audio processing, network transmission, user management, conference control, and data sharing, allowing users to conduct real-time video communication and interaction through various terminal devices (such as computers, mobile phones, tablets, etc.). The communication between existing videoconferencing platforms and terminal devices is usually transmitted in an encrypted form to protect user privacy, ensure the integrity of communication content, and prevent information leakage, but the process of data encryption transmission still faces the following limitations: (1) In some high-level communication application fields (such as financial transaction video, government department video, and conference video involving major commercial secrets), higher requirements are placed on the security and accuracy of data transmission. While increasing the complexity of the encryption algorithm, it is also necessary to replace the communication encryption key used in the video process to ensure that even if the key is cracked in a short period of time, the attacker cannot obtain a large amount of valid data. Videos of different levels of confidentiality are usually configured with different key replacement frequencies to reduce unnecessary hardware resource consumption of the system. This requires reasonable arrangements for key replacement of each terminal device to minimize system hardware resource consumption while improving communication security.
[0003] (2) In actual applications, there may be multiple terminal devices in a certain area connected to the video platform through a communication network (for example, multiple video mobile terminals under the same enterprise are connected to the video platform through the enterprise network gateway). In this case, different terminal devices have different key replacement frequency requirements (determined by the video security level) and data transmission requirements (determined by the video transmission content) at different time periods. When executing the key replacement of each mobile terminal, it is necessary not only to consider the replacement frequency requirement, but also to consider the impact of the data transmission limit brought by the shared communication network on key distribution (when the data transmission volume is large and the network bandwidth is limited, network resources will be occupied by a large amount of data transmission, affecting the timeliness of key distribution and replacement), which makes it difficult to plan the key replacement time for each terminal device.
[0004] (3) Caching the key to be replaced in advance on each terminal device can solve the impact of network bandwidth on key distribution to a certain extent. However, the practice of storing the key on the terminal device for a long time increases the probability of the key being stolen, which in turn threatens the security of encrypted communications. Therefore, when implementing the key distribution and caching of each terminal device on the video conferencing platform, it is necessary to consider the storage time of the key on the mobile terminal.
[0005] (4) When the terminal device is changing the key, it needs to cache the transmitted data and wait for the key to be switched before transmitting it to the video platform. The different data transmission volumes of the terminal device at different time periods will result in different amounts of cached transmission data required to perform key changes at different time points. The different hardware resources of different terminal devices (mainly CPU processing power and memory reading speed) will affect the time it takes for the terminal device to perform key switching and cache data processing. If the amount of cached transmission data and the time it takes to perform key switching and cache data processing cannot be reduced, the video will experience obvious delays and freezes.
[0006] (5) The encryption keys used by existing video platforms and terminal devices are static keys, that is, the video platform stores the generated keys, distributes the keys at the corresponding time and realizes encrypted communication. The use of static keys poses a greater security risk and increases the possibility of keys being cracked and stolen. It cannot provide sufficient security protection. Once leaked, attackers can use the keys for illegal access and data theft for a long time.
[0007] Therefore, how to improve the security of encrypted communications between a video platform and multiple mobile terminals while reducing video latency and achieving low-latency and high-security data transmission for the video platform is a technical problem that needs to be solved urgently. Summary of the invention
[0008] The main purpose of the present invention is to provide a low-latency and high-security data transmission method and system for a video platform, aiming to solve at least one of the above-mentioned technical problems.
[0009] To achieve the above object, the present invention provides a low-latency and high-security data transmission method for a video conferencing platform, comprising the following steps: Obtaining a data transmission task for a target area, and determining key update association information for each mobile terminal in the target area according to the planned transmission content in the data transmission task; querying the network bandwidth parameters of the regional communication network, taking into account the historical key update data of each mobile terminal, and generating a key update execution strategy and a key cache execution strategy for each mobile terminal; According to the key update execution strategy and the key cache execution strategy, a key pair update list for each mobile terminal is constructed by using the user dynamic feature set collected and uploaded by each mobile terminal; After establishing an encrypted tunnel between the videoconferencing platform and the target mobile terminal, the key update execution policy of the target mobile terminal is sent to the target mobile terminal, and based on the key cache execution policy and the key update execution policy, the key cache of the videoconferencing platform and the key update of the target mobile terminal are respectively executed; Each mobile terminal is driven to perform data transmission tasks according to the key updated in real time.
[0010] Optionally, the step of obtaining a data transmission task in the target area and determining key update association information of each mobile terminal in the target area according to the planned transmission content in the data transmission task specifically includes: Acquire a data transmission task for a target area, and extract the data transmission plan content of each transmission cycle of a plurality of mobile terminals in the target area in the data transmission task within the target task period; wherein the plurality of mobile terminals use the same regional communication network to connect to the video conferencing platform; According to the data plan transmission content, the data transmission sensitivity level and data transmission volume per unit time of each transmission cycle within the target task period are estimated, and the key update association information of each mobile terminal is generated.
[0011] Optionally, obtain the data transmission task steps for the target area, including: Acquire data transmission requirements sent in advance by a number of mobile terminals in the target area to the video conferencing platform; wherein the data transmission requirements include a planned data transmission period and planned data transmission content; According to the transmission cycles included in the planned data transmission period within the target task period, the planned transmission period in the data transmission demand of each mobile terminal is replaced with a number of transmission cycles to construct a data transmission task for the target area.
[0012] Optionally, the step of estimating the data transmission sensitivity level and the data transmission volume per unit time of each transmission cycle in the target task period according to the data plan transmission content, and generating the key update association information of each mobile terminal specifically includes: According to the data transmission content of each transmission cycle, the data transmission sensitivity level and the data transmission volume per unit time of each transmission cycle in the target period are estimated by using a text keyword matching method in a relation comparison table between a preset keyword set, a data sensitivity level and a data transmission type; Based on the data transmission sensitivity level, a key update frequency requirement for each transmission cycle is determined, and key update association information of each mobile terminal in each transmission cycle is generated by using the key update frequency requirement and the data transmission volume per unit time.
[0013] Optionally, querying the network bandwidth parameters of the regional communication network, considering the historical key update data of each mobile terminal, and generating the key update execution strategy and key cache execution strategy steps for each mobile terminal specifically include: Query the network bandwidth parameters of the regional communication network, and extract the estimated time and upper limit of cached data volume of the key update in the historical key update data of each mobile terminal; Calculate the total amount of cached data for a single key update when each mobile terminal performs a key update in different transmission cycles according to the estimated key update time of each mobile terminal and the data transmission volume per unit time in the key update association information of each transmission cycle; Calculate the redundant bandwidth parameter of the regional communication network in each transmission cycle according to the network bandwidth parameter of the regional communication network and the data transmission volume per unit time of each mobile terminal in each transmission cycle, and determine the key cache period based on all transmission cycles in which the redundant bandwidth parameter is higher than a preset bandwidth parameter threshold; The total amount of cached data for a single key update, the upper limit of the amount of cached data and the key cache period are used to respectively solve the key update execution strategy and the key cache execution strategy of each mobile terminal using an optimization algorithm.
[0014] Optionally, solving the key update execution strategy step of each mobile terminal specifically includes: The first constraint condition is that the interval between any two consecutive key updates performed by each mobile terminal within the target task period does not exceed the key update period duration corresponding to the key update frequency requirement of the mobile terminal in the corresponding transmission period, and the second constraint condition is that the total amount of cached data for a single key update when each mobile terminal performs each key update is less than the preset cached data amount upper limit value according to the mobile terminal; Taking the minimum number of key updates within the target task period as the optimization goal, the update execution time of each key update within the target task period is optimized and solved to generate the key update execution strategy.
[0015] Optionally, solving the key cache execution strategy step of each mobile terminal specifically includes: The constraint condition is that the cache time of each key cache execution is earlier than the update execution time of all key updates in the key cache; The optimization goal is to minimize the sum of the product of all key caching times and the first weight factor, the sum of the difference between the cache time of each key cache execution and the update execution time of each key update in the key cache, and the second weight factor, and optimize the cache execution time of each key cache in the key cache period to generate a key cache execution strategy.
[0016] Optionally, according to the key update execution strategy and the key cache execution strategy, the key pair update list step of each mobile terminal is constructed by using the user dynamic feature set collected and uploaded by each mobile terminal, specifically including: Extracting several cache execution times in the key cache execution strategy and several update execution times in the key update execution strategy of each mobile terminal, and digitizing the update execution time of each key update execution and the cache execution time of the corresponding key execution key cache as the retrieval coordinates of the corresponding key; Acquire the first dynamic feature and the second dynamic feature in the user dynamic feature set pre-collected and uploaded by each mobile terminal, normalize the first dynamic feature and the second dynamic feature into digital feature vectors, use the combination of the digits in the digital feature vectors corresponding to the first dynamic feature and the second dynamic feature as table coordinates, and use the sum of the values in the digital feature vectors corresponding to the first dynamic feature and the second dynamic feature as table elements to construct a key update parameter matrix; Based on the retrieval coordinates of the key corresponding to each key update, matching the key update parameters of each mobile terminal for several key updates in the key update parameter matrix, dynamically updating the initial key pair of each mobile terminal with associated user characteristics using the key update parameters, obtaining several dynamically updated key pairs, and constructing a key pair update list for each mobile terminal; Among them, the dynamic update of the associated user characteristics of the initial key pair of each mobile terminal includes: using the sum of the values corresponding to the key update parameters as the binary value bit embedding position of the initial key, and using the concatenated combination of the digital feature vectors corresponding to the first dynamic feature and the second dynamic feature as the embedded binary value to dynamically update the initial key of each mobile terminal.
[0017] Optionally, after establishing an encrypted tunnel between the videoconferencing platform and the target mobile terminal, the key update execution policy of the target mobile terminal is sent to the target mobile terminal, and based on the key cache execution policy and the key update execution policy, the key cache of the videoconferencing platform and the key update steps of the target mobile terminal are respectively executed, specifically including: After establishing an encrypted tunnel between the videoconferencing platform and the target mobile terminal, sending the key update execution policy of the target mobile terminal to the target mobile terminal, and determining the key pair data set for executing each key cache from the key pair update list based on the key cache execution policy; The videoconferencing platform caches the key pair data set of each key cache execution to the target mobile terminal at the corresponding cache execution time according to the key cache execution strategy. The target mobile terminal updates the key at the corresponding update execution time according to the cached key pair data set and the received key update execution strategy.
[0018] In addition, in order to achieve the above-mentioned purpose, the present invention also provides a low-latency and high-security data transmission system for a video conferencing platform, the system comprising: A determination module, used to obtain a data transmission task in a target area, and determine key update association information of each mobile terminal in the target area according to the planned transmission content in the data transmission task; A query module, used to query the network bandwidth parameters of the regional communication network, consider the historical key update data of each mobile terminal, and generate a key update execution strategy and a key cache execution strategy for each mobile terminal; A construction module, used to construct a key pair update list for each mobile terminal according to a key update execution strategy and a key cache execution strategy, using a user dynamic feature set collected and uploaded by each mobile terminal; A sending module, used to send the key update execution policy of the target mobile terminal to the target mobile terminal after establishing an encrypted tunnel between the videoconferencing platform and the target mobile terminal, and execute the key cache of the videoconferencing platform and the key update of the target mobile terminal respectively based on the key cache execution policy and the key update execution policy; The execution module is used to drive each mobile terminal to execute the data transmission task according to the key updated in real time.
[0019] The beneficial effects of the present invention are as follows: a low-delay high-security data transmission method and system for a video platform is proposed, the key update associated information of each mobile terminal is determined through the planned transmission content in the data transmission task, the historical key update data of each mobile terminal is considered according to the key update associated information and the network bandwidth parameter, the total amount of cached data of a single key update, the upper limit of the cached data amount and the determined key cache period are used, and the key update execution strategy and key cache execution strategy of each mobile terminal are respectively solved by an optimization algorithm, while meeting the key replacement frequency of different mobile terminals in different periods, the influence of data transmission delay caused by key switching is reduced and the risk caused by key cache is reduced as much as possible. At the same time, the generated key update execution strategy and key cache execution strategy are converted into key update parameter retrieval coordinates, and the update mode of each dynamic key compared with the original key is determined in the key update parameter matrix constructed by the user dynamic feature set, and the immediacy and complexity of the key are improved by embedding the data words associated with the user's own dynamic features and the key update and cache strategy generated in real time, and the cracking difficulty is increased. Therefore, while improving the security of encrypted communication between the video platform and multiple mobile terminals, the video delay is reduced, and low-delay high-security data transmission for the video platform is realized. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Figure 1 It is a flow chart of a low-latency and high-security data transmission method for a video conferencing platform according to the present invention; Figure 2 It is a structural diagram of the low-latency and high-security data transmission system for a video conferencing platform of the present invention. DETAILED DESCRIPTION
[0021] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0022] The embodiment of the present invention provides a low-delay and high-security data transmission method for a video conferencing platform, referring to Figure 1 , Figure 1 The present invention is a flowchart of an embodiment of a low-latency and high-security data transmission method for a video conferencing platform.
[0023] In this embodiment, a low-latency and high-security data transmission method for a video conferencing platform includes the following steps: S100: Acquire a data transmission task for a target area, and determine key update association information for each mobile terminal in the target area according to the planned transmission content in the data transmission task; S200: querying the network bandwidth parameters of the regional communication network, considering the historical key update data of each mobile terminal, and generating a key update execution strategy and a key cache execution strategy for each mobile terminal; S300: constructing a key pair update list for each mobile terminal according to the key update execution strategy and the key cache execution strategy, using the user dynamic feature set collected and uploaded by each mobile terminal; S400: after establishing an encrypted tunnel between the videoconferencing platform and the target mobile terminal, sending the key update execution policy of the target mobile terminal to the target mobile terminal, and executing the key cache of the videoconferencing platform and the key update of the target mobile terminal respectively based on the key cache execution policy and the key update execution policy; S500: driving each mobile terminal to perform a data transmission task according to the key updated in real time.
[0024] It should be noted that the communication between the existing video conferencing platform and the terminal device is usually transmitted in an encrypted form to protect user privacy, ensure the integrity of the communication content and prevent information leakage. However, the process of data encryption transmission still faces the following limitations: (1) In some high-level communication application fields (such as financial transaction video, government department video, and conference video involving major commercial secrets), higher requirements are placed on the security and accuracy of data transmission. While increasing the complexity of the encryption algorithm, it is also necessary to replace the communication encryption key used in the video process to ensure that even if the key is cracked in a short period of time, the attacker cannot obtain a large amount of valid data. Videos of different levels of confidentiality are usually configured with different key replacement frequencies to reduce unnecessary hardware resource consumption of the system. This requires reasonable arrangements for key replacement of each terminal device to minimize system hardware resource consumption while improving communication security.
[0025] (2) In actual applications, there may be multiple terminal devices in a certain area connected to the video platform through a communication network (for example, multiple video mobile terminals under the same enterprise are connected to the video platform through the enterprise network gateway). In this case, different terminal devices have different key replacement frequency requirements (determined by the video security level) and data transmission requirements (determined by the video transmission content) at different time periods. When executing the key replacement of each mobile terminal, it is necessary not only to consider the replacement frequency requirement, but also to consider the impact of the data transmission limit brought by the shared communication network on key distribution (when the data transmission volume is large and the network bandwidth is limited, network resources will be occupied by a large amount of data transmission, affecting the timeliness of key distribution and replacement), which makes it difficult to plan the key replacement time for each terminal device.
[0026] (3) Caching the key to be replaced in advance on each terminal device can solve the impact of network bandwidth on key distribution to a certain extent. However, the practice of storing the key on the terminal device for a long time increases the probability of the key being stolen, which in turn threatens the security of encrypted communications. Therefore, when implementing the key distribution and caching of each terminal device on the video conferencing platform, it is necessary to consider the storage time of the key on the mobile terminal.
[0027] (4) When the terminal device is changing the key, it needs to cache the transmitted data and wait for the key to be switched before transmitting it to the video platform. The different data transmission volumes of the terminal device at different time periods will result in different amounts of cached transmission data required to perform key changes at different time points. The different hardware resources of different terminal devices (mainly CPU processing power and memory reading speed) will affect the time it takes for the terminal device to perform key switching and cache data processing. If the amount of cached transmission data and the time it takes to perform key switching and cache data processing cannot be reduced, the video will experience obvious delays and freezes.
[0028] (5) The encryption keys used by existing video platforms and terminal devices are static keys, that is, the video platform stores the generated keys, distributes the keys at the corresponding time and realizes encrypted communication. The use of static keys poses a greater security risk and increases the possibility of keys being cracked and stolen. It cannot provide sufficient security protection. Once leaked, attackers can use the keys for illegal access and data theft for a long time.
[0029] In order to solve the above problems, this embodiment considers the historical key update data of each mobile terminal based on the key update association information and network bandwidth parameters, and adopts an optimization algorithm to solve the key update execution strategy and key cache execution strategy of each mobile terminal respectively, while meeting the key replacement frequency of different mobile terminals in different time periods, reducing the impact of data transmission delay caused by key switching and minimizing the risk caused by key cache. At the same time, the key update execution strategy and key cache execution strategy are converted into key update parameter retrieval coordinates, and the update method of each dynamic key compared to the original key is determined in the key update parameter matrix constructed by the user dynamic feature set. By embedding the user dynamic features and the data words of the key update and cache strategy, the immediacy and complexity of the key are improved, and the difficulty of cracking is increased.
[0030] In a preferred embodiment, the step of obtaining a data transmission task for a target area and determining key update associated information for each mobile terminal in the target area according to the planned transmission content in the data transmission task specifically includes: S110: Acquire a data transmission task in a target area, and extract the data transmission plan content of each transmission cycle of a plurality of mobile terminals in the target area in the data transmission task within the target task period; wherein the plurality of mobile terminals use the same regional communication network to connect to the video conferencing platform; S120: Estimate the data transmission sensitivity level and data transmission volume per unit time of each transmission cycle within the target task period according to the data plan transmission content, and generate key update association information for each mobile terminal.
[0031] Furthermore, the data transmission task steps for the target area are obtained, including: S111: Acquire data transmission requirements sent in advance by a number of mobile terminals in the target area to the video conferencing platform; wherein the data transmission requirements include a planned data transmission period and planned data transmission content; S112: According to the transmission cycles included in the planned data transmission period within the target task period, the planned transmission period in the data transmission demand of each mobile terminal is replaced with a number of transmission cycles to construct a data transmission task for the target area.
[0032] Furthermore, according to the data plan transmission content, the data transmission sensitivity level and the data transmission volume per unit time of each transmission cycle in the target task period are estimated, and the key update association information step of each mobile terminal is generated, which specifically includes: S121: according to the data transmission content of each transmission cycle, the data transmission sensitivity level and the data transmission volume per unit time of each transmission cycle in the target period are estimated by using a text keyword matching method in a relation comparison table between a preset keyword set, a data sensitivity level and a data transmission type; S122: Determine the key update frequency requirement for each transmission cycle based on the data transmission sensitivity level, and generate key update association information for each mobile terminal in each transmission cycle by using the key update frequency requirement and the data transmission amount per unit time.
[0033] In this embodiment, the data plan transmission content of each transmission cycle of several mobile terminals in the target area in the data transmission task during the target task period is determined, and the corresponding data sensitivity level and data transmission type are determined in a pre-determined relationship comparison table in accordance with the text keyword matching method according to the data plan transmission content. The data sensitivity level is used to determine the key update frequency of each mobile terminal in each transmission cycle, and the data transmission type is used to determine the data transmission volume per unit time, thereby generating key update association information to provide basic data for the key update planning of each mobile terminal.
[0034] In a preferred embodiment, querying the network bandwidth parameters of the regional communication network, considering the historical key update data of each mobile terminal, and generating the key update execution strategy and key cache execution strategy steps for each mobile terminal specifically include: S210: querying the network bandwidth parameters of the regional communication network, extracting the estimated time and cached data volume upper limit of the key update in the historical key update data of each mobile terminal; S220: Calculate the total amount of cached data for a single key update when each mobile terminal performs key update in different transmission cycles according to the estimated key update time of each mobile terminal and the data transmission volume per unit time in the key update association information of each transmission cycle; S230: Calculate the redundant bandwidth parameter of the regional communication network in each transmission cycle according to the network bandwidth parameter of the regional communication network and the data transmission volume per unit time of each mobile terminal in each transmission cycle, and determine the key cache period based on all transmission cycles in which the redundant bandwidth parameter is higher than a preset bandwidth parameter threshold; S240: Using the total amount of cached data for a single key update, the upper limit of the amount of cached data, and the key cache period, an optimization algorithm is used to respectively solve the key update execution strategy and the key cache execution strategy of each mobile terminal.
[0035] In this embodiment, by querying the obtained network bandwidth parameters and the historical key update data of each mobile terminal, the estimated key update time (usually obtained by calculating the average completion time of multiple key updates) and the upper limit of the cache data amount (usually obtained by analyzing the amount of data cached when the mobile terminal has obvious delays and freezes) in the historical key update data of each mobile terminal are calculated, and the total amount of cache data for a single key update when each mobile terminal performs key update in different transmission cycles (usually obtained by calculating the product of the estimated key update time and the data transmission amount per unit time) is calculated, and the key cache period consisting of all transmission cycles with redundant bandwidth parameters higher than the preset bandwidth parameter threshold is determined (usually determined by the period consisting of the union of all transmission cycles with redundant bandwidth parameters higher than the preset bandwidth parameter threshold). Finally, the key update execution strategy and key cache execution strategy of each mobile terminal are solved respectively using an optimization algorithm.
[0036] Furthermore, the key update execution strategy steps for each mobile terminal are solved, including: S241: The first constraint condition is that the interval between any two consecutive key updates performed by each mobile terminal within the target task period does not exceed the key update period duration corresponding to the key update frequency requirement of the mobile terminal in the corresponding transmission period, and the second constraint condition is that the total amount of cached data for a single key update when each mobile terminal performs each key update is less than a preset cached data amount upper limit value according to the mobile terminal; S242: Taking the minimum number of key updates within the target task period as the optimization goal, optimizing and solving the update execution time of each key update within the target task period, and generating a key update execution strategy.
[0037] Furthermore, the key cache execution strategy steps of each mobile terminal are solved, including: S243: The cache time of each execution of the key cache is earlier than the update execution time of all key updates in the key cache as a constraint condition; S244: Taking the minimum sum of the product of the total number of key caching times and the first weight factor, the sum of the difference between the cache time of each key cache execution and the update execution time of each key update in the key cache and the second weight factor as the optimization goal, optimize and solve the cache execution time of each key cache in the key cache period, and generate a key cache execution strategy.
[0038] In this embodiment, the key update associated information of each mobile terminal is determined through the planned transmission content in the data transmission task. According to the key update associated information and the network bandwidth parameter, the historical key update data of each mobile terminal is considered, and the total amount of cached data for a single key update, the upper limit of the cached data amount and the determined key cache period are used. An optimization algorithm is used to solve the key update execution strategy and the key cache execution strategy of each mobile terminal respectively, while meeting the key replacement frequency of different mobile terminals in different time periods, reducing the impact of data transmission delay caused by key switching and minimizing the risk of key caching.
[0039] In a preferred embodiment, according to the key update execution strategy and the key cache execution strategy, the key pair update list step of each mobile terminal is constructed by using the user dynamic feature set collected and uploaded by each mobile terminal, specifically including: S310: extracting a number of cache execution times in the key cache execution strategy and a number of update execution times in the key update execution strategy of each mobile terminal, and digitizing the update execution time of each key update execution and the cache execution time of the key cache of the corresponding key execution as the retrieval coordinate of the corresponding key; S320: Acquire the first dynamic feature and the second dynamic feature in the user dynamic feature set pre-collected and uploaded by each mobile terminal, normalize the first dynamic feature and the second dynamic feature into digital feature vectors, use the combination of the digits in the digital feature vectors corresponding to the first dynamic feature and the second dynamic feature as table coordinates, and use the sum of the values in the digital feature vectors corresponding to the first dynamic feature and the second dynamic feature as table elements to construct a key update parameter matrix; S330: matching key update parameters of each mobile terminal for several key updates in the key update parameter matrix based on the search coordinates of the key corresponding to each key update, dynamically updating the initial key pair of each mobile terminal with associated user characteristics using the key update parameters, obtaining several dynamically updated key pairs, and constructing a key pair update list for each mobile terminal; Among them, the dynamic update of the associated user characteristics of the initial key pair of each mobile terminal includes: using the sum of the values corresponding to the key update parameters as the binary value bit embedding position of the initial key, and using the concatenated combination of the digital feature vectors corresponding to the first dynamic feature and the second dynamic feature as the embedded binary value to dynamically update the initial key of each mobile terminal.
[0040] In this embodiment, the generated key update execution strategy and key cache execution strategy are converted into key update parameter retrieval coordinates, and the update method of each dynamic key compared to the original key is determined in the key update parameter matrix constructed by the user's dynamic feature set. By embedding data words associated with the user's own dynamic features and the key update and cache strategy generated in real time, the immediacy and complexity of the key are improved, and the difficulty of cracking is increased.
[0041] In a preferred embodiment, after establishing an encrypted tunnel between the videoconferencing platform and the target mobile terminal, the key update execution policy of the target mobile terminal is sent to the target mobile terminal, and based on the key cache execution policy and the key update execution policy, the key cache of the videoconferencing platform and the key update steps of the target mobile terminal are respectively executed, specifically including: S410: after establishing an encrypted tunnel between the videoconferencing platform and the target mobile terminal, sending the key update execution policy of the target mobile terminal to the target mobile terminal, and determining a key pair data set for executing each key cache from a key pair update list based on the key cache execution policy; S420: The videoconferencing platform caches the key pair data set for each key cache execution to the target mobile terminal at the corresponding cache execution time according to the key cache execution strategy. The target mobile terminal performs key update at the corresponding update execution time based on the cached key pair data set and the received key update execution strategy.
[0042] In this embodiment, after establishing an encrypted tunnel between the video platform and the target mobile terminal, the corresponding number of keys are distributed at the corresponding time on the video platform and the keys are updated at the corresponding time on the mobile terminal according to the key cache execution strategy and key update execution strategy generated by the solution. This can improve the security of encrypted communications between the video platform and multiple mobile terminals while reducing video delays, thereby achieving low-latency and high-security data transmission for the video platform.
[0043] Reference Figure 2 , Figure 2 It is a structural block diagram of an embodiment of a low-latency and high-security data transmission system for a video conferencing platform according to the present invention.
[0044] like Figure 2 As shown, the low-latency and high-security data transmission system for a video conferencing platform proposed in an embodiment of the present invention includes: A determination module 10 is used to obtain a data transmission task in a target area, and determine key update association information of each mobile terminal in the target area according to the planned transmission content in the data transmission task; A query module 20, for querying the network bandwidth parameters of the regional communication network, taking into account the historical key update data of each mobile terminal, and generating a key update execution strategy and a key cache execution strategy for each mobile terminal; A construction module 30 is used to construct a key pair update list for each mobile terminal according to a key update execution strategy and a key cache execution strategy, using a user dynamic feature set collected and uploaded by each mobile terminal; The sending module 40 is used to send the key update execution policy of the target mobile terminal to the target mobile terminal after establishing the encrypted tunnel between the videoconferencing platform and the target mobile terminal, and execute the key cache of the videoconferencing platform and the key update of the target mobile terminal respectively based on the key cache execution policy and the key update execution policy; The execution module 50 is used to drive each mobile terminal to execute the data transmission task according to the key updated in real time.
[0045] Other embodiments or specific implementations of the low-latency and high-security data transmission system for a video conferencing platform of the present invention may refer to the above-mentioned method embodiments and will not be described in detail here.
[0046] It is understood that, in the description of this specification, the description with reference to the terms "one embodiment", "another embodiment", "other embodiments", or "first to Nth embodiments" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner.
[0047] It should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or system including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or system. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the existence of other identical elements in the process, method, article or system including the element.
[0048] The above are only preferred embodiments of the present invention, and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.
Claims
1. A low-latency and high-security data transmission method for a video conferencing platform, characterized in that: The following steps are involved: Obtaining a data transmission task for a target area, and determining key update association information for each mobile terminal in the target area according to the planned transmission content in the data transmission task; querying the network bandwidth parameters of the regional communication network, taking into account the historical key update data of each mobile terminal, and generating a key update execution strategy and a key cache execution strategy for each mobile terminal; According to the key update execution strategy and the key cache execution strategy, a key pair update list for each mobile terminal is constructed by using the user dynamic feature set collected and uploaded by each mobile terminal; After establishing an encrypted tunnel between the videoconferencing platform and the target mobile terminal, the key update execution policy of the target mobile terminal is sent to the target mobile terminal, and based on the key cache execution policy and the key update execution policy, the key cache of the videoconferencing platform and the key update of the target mobile terminal are respectively executed; Each mobile terminal is driven to perform data transmission tasks according to the key updated in real time.
2. The low-latency and high-security data transmission method for a video conferencing platform as claimed in claim 1, characterized in that: The step of obtaining a data transmission task for a target area and determining key update associated information for each mobile terminal in the target area according to the planned transmission content in the data transmission task specifically includes: Acquire a data transmission task for a target area, and extract the data transmission plan content of each transmission cycle of a plurality of mobile terminals in the target area in the data transmission task within the target task period; wherein the plurality of mobile terminals use the same regional communication network to connect to the video conferencing platform; According to the data plan transmission content, the data transmission sensitivity level and data transmission volume per unit time of each transmission cycle within the target task period are estimated, and the key update association information of each mobile terminal is generated.
3. The low-latency and high-security data transmission method for a video conferencing platform as claimed in claim 2, characterized in that: The steps for obtaining the data transmission task of the target area include: Acquire data transmission requirements sent in advance by a number of mobile terminals in the target area to the video conferencing platform; wherein the data transmission requirements include a planned data transmission period and planned data transmission content; According to the transmission cycles included in the planned data transmission period within the target task period, the planned transmission period in the data transmission demand of each mobile terminal is replaced with a number of transmission cycles to construct a data transmission task for the target area.
4. The low-latency and high-security data transmission method for a video conferencing platform as claimed in claim 2, characterized in that: According to the data transmission plan content, the data transmission sensitivity level and the data transmission volume per unit time of each transmission cycle in the target task period are estimated, and the key update association information of each mobile terminal is generated, specifically including: According to the data transmission content of each transmission cycle, the data transmission sensitivity level and the data transmission volume per unit time of each transmission cycle in the target period are estimated by using a text keyword matching method in a relation comparison table between a preset keyword set, a data sensitivity level and a data transmission type; Based on the data transmission sensitivity level, a key update frequency requirement for each transmission cycle is determined, and key update association information of each mobile terminal in each transmission cycle is generated by using the key update frequency requirement and the data transmission volume per unit time.
5. The low-latency and high-security data transmission method for a video conferencing platform as claimed in claim 1, characterized in that: The network bandwidth parameters of the regional communication network are queried, the historical key update data of each mobile terminal is considered, and the key update execution strategy and key cache execution strategy steps of each mobile terminal are generated, specifically including: Query the network bandwidth parameters of the regional communication network, and extract the estimated time and upper limit of cached data volume of the key update in the historical key update data of each mobile terminal; Calculate the total amount of cached data for a single key update when each mobile terminal performs key update in different transmission cycles according to the estimated key update time of each mobile terminal and the data transmission volume per unit time in the key update association information of each transmission cycle; Calculate the redundant bandwidth parameter of the regional communication network in each transmission cycle according to the network bandwidth parameter of the regional communication network and the data transmission volume per unit time of each mobile terminal in each transmission cycle, and determine the key cache period based on all transmission cycles in which the redundant bandwidth parameter is higher than a preset bandwidth parameter threshold; The total amount of cached data for a single key update, the upper limit of the amount of cached data and the key cache period are used to respectively solve the key update execution strategy and the key cache execution strategy of each mobile terminal using an optimization algorithm.
6. The low-latency and high-security data transmission method for a video conferencing platform as claimed in claim 5, characterized in that: Solve the key update execution strategy steps for each mobile terminal, including: The first constraint condition is that the interval between any two consecutive key updates performed by each mobile terminal within the target task period does not exceed the key update period duration corresponding to the key update frequency requirement of the mobile terminal in the corresponding transmission period, and the second constraint condition is that the total amount of cached data for a single key update when each mobile terminal performs each key update is less than the preset cached data amount upper limit value according to the mobile terminal; Taking the minimum number of key updates within the target task period as the optimization goal, the update execution time of each key update within the target task period is optimized and solved to generate the key update execution strategy.
7. The low-latency and high-security data transmission method for a video conferencing platform as claimed in claim 6, characterized in that: Solve the key cache execution strategy steps for each mobile terminal, including: The constraint condition is that the cache time of each key cache execution is earlier than the update execution time of all key updates in the key cache; The optimization goal is to minimize the sum of the product of all key caching times and the first weight factor, the sum of the difference between the cache time of each key cache execution and the update execution time of each key update in the key cache, and the second weight factor, and optimize the cache execution time of each key cache in the key cache period to generate a key cache execution strategy.
8. The low-latency and high-security data transmission method for a video conferencing platform as claimed in claim 1, characterized in that: According to the key update execution strategy and the key cache execution strategy, the key pair update list steps for each mobile terminal are constructed by using the user dynamic feature set collected and uploaded by each mobile terminal, specifically including: Extracting several cache execution times in the key cache execution strategy and several update execution times in the key update execution strategy of each mobile terminal, and digitizing the update execution time of each key update execution and the cache execution time of the corresponding key execution key cache as the retrieval coordinates of the corresponding key; Acquire the first dynamic feature and the second dynamic feature in the user dynamic feature set pre-collected and uploaded by each mobile terminal, normalize the first dynamic feature and the second dynamic feature into digital feature vectors, use the combination of the digits in the digital feature vectors corresponding to the first dynamic feature and the second dynamic feature as table coordinates, and use the sum of the values in the digital feature vectors corresponding to the first dynamic feature and the second dynamic feature as table elements to construct a key update parameter matrix; Based on the retrieval coordinates of the key corresponding to each key update, matching the key update parameters of each mobile terminal for several key updates in the key update parameter matrix, dynamically updating the initial key pair of each mobile terminal with associated user characteristics using the key update parameters, obtaining several dynamically updated key pairs, and constructing a key pair update list for each mobile terminal; Among them, the dynamic update of the associated user characteristics of the initial key pair of each mobile terminal includes: using the sum of the values corresponding to the key update parameters as the binary value bit embedding position of the initial key, and using the concatenated combination of the digital feature vectors corresponding to the first dynamic feature and the second dynamic feature as the embedded binary value to dynamically update the initial key of each mobile terminal.
9. The low-latency and high-security data transmission method for a video conferencing platform as claimed in claim 1, characterized in that: After establishing an encrypted tunnel between the videoconferencing platform and the target mobile terminal, the key update execution policy of the target mobile terminal is sent to the target mobile terminal. Based on the key cache execution policy and the key update execution policy, the key cache of the videoconferencing platform and the key update steps of the target mobile terminal are respectively executed, specifically including: After establishing an encrypted tunnel between the videoconferencing platform and the target mobile terminal, sending the key update execution policy of the target mobile terminal to the target mobile terminal, and determining the key pair data set for executing each key cache from the key pair update list based on the key cache execution policy; The videoconferencing platform caches the key pair data set of each key cache execution to the target mobile terminal at the corresponding cache execution time according to the key cache execution strategy. The target mobile terminal updates the key at the corresponding update execution time according to the cached key pair data set and the received key update execution strategy.
10. A low-latency and high-security data transmission system for a video conferencing platform, characterized in that: include: A determination module, used to obtain a data transmission task in a target area, and determine key update association information of each mobile terminal in the target area according to the planned transmission content in the data transmission task; A query module, used to query the network bandwidth parameters of the regional communication network, consider the historical key update data of each mobile terminal, and generate a key update execution strategy and a key cache execution strategy for each mobile terminal; A construction module, used to construct a key pair update list for each mobile terminal according to a key update execution strategy and a key cache execution strategy, using a user dynamic feature set collected and uploaded by each mobile terminal; A sending module, used to send the key update execution policy of the target mobile terminal to the target mobile terminal after establishing an encrypted tunnel between the videoconferencing platform and the target mobile terminal, and execute the key cache of the videoconferencing platform and the key update of the target mobile terminal respectively based on the key cache execution policy and the key update execution policy; The execution module is used to drive each mobile terminal to execute the data transmission task according to the key updated in real time.
Citation Information
Patent Citations
End-to-end key generation method based on queue polling in quantum metropolitan area network
CN113067698A
Quantum key scheduling method for cloud computing platform
CN114499864A
End-to-end key generation method based on dynamic adjustment in quantum metropolitan area network
CN114598462A
Dynamic encryption method and system, computer equipment and storage medium
CN117131484A
Security encryption communication method and system based on quantum key management
CN119316138A