A low-latency and high-security data transmission method and system for a video platform

By determining the key update association information and generating execution strategies of each mobile terminal in the video platform, building a key pair update list based on the user's dynamic feature set, and performing key cache and update in the encrypted tunnel, the problem of data transmission security and delay in high-density communication of the video platform is solved, and low-latency and high-security data transmission is achieved.

CN120018123BActive Publication Date: 2025-06-17TROY INFORMATION TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510468788.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-06-17
Estimated Expiration
2045-04-15

AI Technical Summary

Technical Problem

Existing video platforms face the problems of data transmission security and delay in high-density communication applications, especially under the differences in key replacement frequency and data volume transmission requirements and network bandwidth limitations, which affect the timeliness and security of key distribution and replacement.

Method used

By obtaining the data transmission task of the target area, the key update association information of each mobile terminal is determined, and the key update execution policy and key cache execution policy of each mobile terminal are generated according to the network bandwidth parameters and historical key update data. The key pair update list is constructed using the user's dynamic feature set, and after the encrypted tunnel is established, the key cache of the video platform and the key update of the target mobile terminal are performed.

Benefits of technology

It realizes that while improving the security of encrypted communication between the video platform and multiple mobile terminals, it reduces video latency, ensures the timeliness and security of key replacement, reduces system hardware resource consumption, improves the immediacy and complexity of keys, and increases the difficulty of cracking.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120018123B_ABST
    Figure CN120018123B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of communication security technology, and discloses a low-latency and high-security data transmission method and system for a video platform. According to the key update association information and network bandwidth parameters, considering the historical key update data of each mobile terminal, an optimization algorithm is used to solve the key update execution strategy and key cache execution strategy of each mobile terminal respectively. While meeting the key replacement frequencies of different mobile terminals at different time periods, it reduces the impact of data transmission delay caused by key switching and minimizes the risks brought by key caching as much as possible. At the same time, the key update execution strategy and key cache execution strategy are converted into key update parameter retrieval coordinates, and the update method of each dynamic key compared with the original key is determined in the key update parameter matrix constructed by the user dynamic feature set. By embedding the data words of user dynamic features and key update and cache strategies, the instantaneity and complexity of the key are improved, and the cracking difficulty is increased.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication security technology, and particularly to a low-latency and high-security data transmission method and system for a video platform. Background Art

[0002] A video platform is a software system or platform based on network technology for realizing various video interaction functions such as video communication, video conferencing, video live streaming, and video on demand. It usually integrates multiple functional modules such as video encoding and decoding, audio processing, network transmission, user management, conference control, and data sharing, enabling users to conduct real-time video communication and interaction through various terminal devices (such as computers, mobile phones, tablets, etc.). The communication between existing video platforms and terminal devices is usually transmitted in an encrypted form to protect user privacy, ensure the integrity of communication content, and prevent information leakage. However, the process of data encrypted transmission still faces the following limitations:

[0003] (1) In some application fields with high-level communication security requirements (such as financial transaction videos, government department videos, and conference videos involving major business secrets, etc.), higher requirements are put forward for the security and accuracy of data transmission. While increasing the complexity of encryption algorithms, it is also necessary to replace the communication encryption keys used during the video process to ensure that even if the key is cracked in a short time, attackers cannot obtain a large amount of valid data. Different levels of video usually configure different key replacement frequencies to reduce unnecessary hardware resource consumption of the system. This requires a reasonable arrangement of key replacement for each terminal device, minimizing the hardware resource consumption of the system while enhancing communication security.

[0004] (2) In practical applications, there will be a situation where multiple terminal devices within a region are connected to the video platform through a communication network (for example, multiple video mobile terminals under the same enterprise communicate with the video platform through the enterprise network gateway). In such a case, different terminal devices have different key replacement frequency requirements (determined by the video security level) and data volume transmission requirements (determined by the video transmission content) at different times. When performing key replacement for each mobile terminal, not only the replacement frequency requirements need to be considered, but also the impact of the data volume transmission upper limit brought by the shared communication network on key distribution needs to be considered (when the data transmission volume is large and the network bandwidth is limited, a large amount of network resources will be occupied by data transmission, affecting the timeliness of key distribution and replacement), which poses a high difficulty for the planning of key replacement time for each terminal device.

[0005] (3) Caching the keys to be replaced in each terminal device in advance can, to a certain extent, address the impact of network bandwidth on key distribution. However, the practice of storing keys in terminal devices for a long time increases the probability of key theft, thereby threatening the security of encrypted communication. Therefore, when implementing key distribution and caching for each terminal device in the video platform, the storage time of keys in mobile terminals needs to be considered.

[0006] (4) When a terminal device replaces keys, it needs to cache the transmitted data and wait until the key switch is completed before transmitting it to the video platform. Different data transmission volumes at different times of the terminal device will result in differences in the amount of transmitted data that needs to be cached when performing key replacement at different time points. Different hardware resources of different terminal devices (mainly CPU processing power and memory reading speed) will affect the time-consuming of the terminal device to perform key switching and cached data processing. If the amount of transmitted data cached and the time-consuming of key switching and cached data processing cannot be reduced, it will lead to obvious video delay and stuttering.

[0007] (5) The encryption keys adopted by the existing video platform and terminal devices are static keys, that is, the video platform stores the generated keys, distributes the keys at corresponding times, and realizes encrypted communication. The use of static keys has significant security risks, increasing the possibility of key cracking and theft, and cannot provide sufficient security protection. Once leaked, attackers can use the key for illegal access and data theft for a long time.

[0008] Therefore, how to improve the security of encrypted communication between the video platform and multiple mobile terminals while reducing video latency and realizing low-latency and high-security data transmission for the video platform is a technical problem that urgently needs to be solved. Summary of the Invention

[0009] The main object of the present invention is to provide a low-latency and high-security data transmission method and system for a video platform, aiming to solve at least one of the above technical problems.

[0010] To achieve the above object, the present invention provides a low-latency and high-security data transmission method for a video platform, including the following steps:

[0011] Obtain the data transmission tasks in the target area, and determine the key update association information of each mobile terminal in the target area according to the planned transmission content in the data transmission tasks;

[0012] Query the network bandwidth parameters of the regional communication network, consider the historical key update data of each mobile terminal, and generate a key update execution policy and a key caching execution policy for each mobile terminal;

[0013] Execute the key update execution policy and the key cache execution policy, and construct a key pair update list for each mobile terminal by using the user dynamic feature sets collected and uploaded by each mobile terminal.

[0014] After establishing an encrypted tunnel between the video platform and the target mobile terminal, send the key update execution policy of the target mobile terminal to the target mobile terminal, and respectively execute the key cache of the video platform and the key update of the target mobile terminal based on the key cache execution policy and the key update execution policy.

[0015] Drive each mobile terminal to perform data transmission tasks according to the real-time updated keys.

[0016] Optionally, the steps of obtaining the data transmission task of the target area and determining the key update association information of each mobile terminal in the target area according to the planned transmission content in the data transmission task specifically include:

[0017] Obtain the data transmission task of the target area, and extract the data planned transmission content of several mobile terminals in the target area within each transmission cycle during the target task period; wherein, the several mobile terminals are connected to the video platform using the same area communication network.

[0018] Estimate the data transmission sensitivity level and the data transmission volume per unit time of each transmission cycle during the target task period according to the data planned transmission content, and generate the key update association information of each mobile terminal.

[0019] Optionally, the steps of obtaining the data transmission task of the target area specifically include:

[0020] Obtain the data transmission requirements pre-sent by several mobile terminals in the target area to the video platform; wherein, the data transmission requirements include the data planned transmission period and the data planned transmission content.

[0021] According to the transmission cycles included in the data planned transmission period during the target task period, replace the planned transmission period in the data transmission requirements of each mobile terminal with several transmission cycles, and construct the data transmission task of the target area.

[0022] Optionally, the steps of estimating the data transmission sensitivity level and the data transmission volume per unit time of each transmission cycle during the target task period according to the data planned transmission content and generating the key update association information of each mobile terminal specifically include:

[0023] According to the data planned transmission content of each transmission cycle, estimate the data transmission sensitivity level and the data transmission volume per unit time of each transmission cycle during the target period by using the method of text keyword matching in the pre-set relationship comparison table between the keyword set and the data sensitivity level and the data transmission type.

[0024] Based on the data transmission sensitivity level, a key update frequency requirement for each transmission cycle is determined, and key update association information of each mobile terminal in each transmission cycle is generated by using the key update frequency requirement and the data transmission volume per unit time.

[0025] Optionally, querying the network bandwidth parameters of the regional communication network, considering the historical key update data of each mobile terminal, and generating the key update execution strategy and key cache execution strategy steps for each mobile terminal specifically include:

[0026] Query the network bandwidth parameters of the regional communication network, and extract the estimated time and upper limit of cached data volume of the key update in the historical key update data of each mobile terminal;

[0027] Calculate the total amount of cached data for a single key update when each mobile terminal performs a key update in different transmission cycles according to the estimated key update time of each mobile terminal and the data transmission volume per unit time in the key update association information of each transmission cycle;

[0028] Calculate the redundant bandwidth parameter of the regional communication network in each transmission cycle according to the network bandwidth parameter of the regional communication network and the data transmission volume per unit time of each mobile terminal in each transmission cycle, and determine the key cache period based on all transmission cycles in which the redundant bandwidth parameter is higher than a preset bandwidth parameter threshold;

[0029] The total amount of cached data for a single key update, the upper limit of the amount of cached data and the key cache period are used to respectively solve the key update execution strategy and the key cache execution strategy of each mobile terminal using an optimization algorithm.

[0030] Optionally, solving the key update execution strategy step of each mobile terminal specifically includes:

[0031] The first constraint condition is that the interval between any two consecutive key updates performed by each mobile terminal within the target task period does not exceed the key update period duration corresponding to the key update frequency requirement of the mobile terminal in the corresponding transmission period, and the second constraint condition is that the total amount of cached data for a single key update when each mobile terminal performs each key update is less than the preset cached data amount upper limit value according to the mobile terminal;

[0032] Taking the minimum number of key updates within the target task period as the optimization goal, the update execution time of each key update within the target task period is optimized and solved to generate the key update execution strategy.

[0033] Optionally, solving the key cache execution strategy step of each mobile terminal specifically includes:

[0034] With the constraint that the caching time of each execution of the key cache is earlier than the update execution time of all key updates in the key cache;

[0035] Taking the sum of the product of the total number of key caches and the first weight factor, and the difference between the caching time of each execution of the key cache and the update execution time of each key update in the key cache and the second weight factor as the optimization objective, optimizing and solving the caching execution time of each key cache within the key cache period to generate a key cache execution strategy.

[0036] Optionally, according to the key update execution strategy and the key cache execution strategy, using the user dynamic feature sets collected and uploaded by each mobile terminal, the steps of constructing a key pair update list for each mobile terminal specifically include:

[0037] Extract several caching execution times in the key cache execution strategy of each mobile terminal and several update execution times in the key update execution strategy, and numerically convert the update execution time of each execution of the key update and the caching execution time of the corresponding key execution of the key cache as the retrieval coordinates of the corresponding key;

[0038] Obtain the first dynamic feature and the second dynamic feature in the user dynamic feature set pre-collected and uploaded by each mobile terminal, normalize and convert the first dynamic feature and the second dynamic feature into a digital feature vector, use the bit combination in the digital feature vector corresponding to the first dynamic feature and the second dynamic feature as the table coordinates, and use the sum of the values in the digital feature vector corresponding to the first dynamic feature and the second dynamic feature as the table elements to construct a key update parameter matrix;

[0039] Based on the retrieval coordinates of the key corresponding to each execution of the key update, match the key update parameters of each mobile terminal for several key updates in the key update parameter matrix, and use the key update parameters to perform dynamic updates of the initial key pairs of each mobile terminal associated with user features to obtain several dynamically updated key pairs, and construct a key pair update list for each mobile terminal;

[0040] Among them, the dynamic update of the initial key pair of each mobile terminal associated with user features includes: using the sum of the values corresponding to the key update parameters as the embedding position of the binary numerical digits of the initial key, and using the concatenated combination of the digital feature vectors corresponding to the first dynamic feature and the second dynamic feature as the embedded binary numerical value to perform dynamic updates on the initial keys of each mobile terminal.

[0041] Optionally, after establishing an encrypted tunnel between the video platform and the target mobile terminal, send the key update execution policy of the target mobile terminal to the target mobile terminal, and respectively execute the key caching of the video platform and the key update of the target mobile terminal based on the key caching execution policy and the key update execution policy, specifically including:

[0042] After establishing an encrypted tunnel between the video platform and the target mobile terminal, send the key update execution policy of the target mobile terminal to the target mobile terminal, and determine the key pair data set for each key caching from the key pair update list based on the key caching execution policy;

[0043] The video platform caches the key pair data set for each key caching to the target mobile terminal at the corresponding caching execution time according to the key caching execution policy, and the target mobile terminal performs key update at the corresponding update execution time according to the cached key pair data set and the received key update execution policy.

[0044] In addition, to achieve the above object, the present invention further provides a low-latency and high-security data transmission system for a video platform, the system includes:

[0045] A determination module, configured to obtain a data transmission task in a target area, and determine key update association information of each mobile terminal in the target area according to the planned transmission content in the data transmission task;

[0046] A query module, configured to query network bandwidth parameters of the regional communication network, and generate a key update execution policy and a key caching execution policy for each mobile terminal in consideration of the historical key update data of each mobile terminal;

[0047] A construction module, configured to construct a key pair update list for each mobile terminal by using the user dynamic feature set collected and uploaded by each mobile terminal according to the key update execution policy and the key caching execution policy;

[0048] A sending module, configured to send the key update execution policy of the target mobile terminal to the target mobile terminal after establishing an encrypted tunnel between the video platform and the target mobile terminal, and respectively execute the key caching of the video platform and the key update of the target mobile terminal based on the key caching execution policy and the key update execution policy;

[0049] An execution module, configured to drive each mobile terminal to perform a data transmission task according to the real-time updated key.

[0050] The beneficial effects of the present invention are as follows: A low-latency and high-security data transmission method and system for a video platform are proposed. By the planned transmission content in the data transmission task, the key update association information of each mobile terminal is determined. According to the key update association information and network bandwidth parameters, considering the historical key update data of each mobile terminal, using the calculated total amount of single-key update cache data, the upper limit value of the cache data volume, and the determined key cache period, an optimization algorithm is used to solve the key update execution strategy and key cache execution strategy of each mobile terminal respectively. While meeting the key replacement frequencies of different mobile terminals at different times, the impact of data transmission latency caused by key switching is reduced and the risks brought by key caching are minimized as much as possible. At the same time, the generated key update execution strategy and key cache execution strategy are converted into key update parameter retrieval coordinates, and the update method of each dynamic key compared with the original key is determined in the key update parameter matrix constructed by the user dynamic feature set. By embedding data words associated with the dynamic features of the user itself and the real-time generated key update and cache strategies, the timeliness and complexity of the key are improved, and the cracking difficulty is increased. Thus, while improving the security of encrypted communication between the video platform and multiple mobile terminals, the video latency is reduced, and low-latency and high-security data transmission for the video platform are achieved. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Figure 1 is a flowchart of the low-latency and high-security data transmission method for a video platform according to the present invention;

[0052] Figure 2 is a structural diagram of the low-latency and high-security data transmission system for a video platform according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0053] In order to make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0054] An embodiment of the present invention provides a low-latency and high-security data transmission method for a video platform. Refer to Figure 1 , Figure 1 is a schematic flowchart of an embodiment of the low-latency and high-security data transmission method for a video platform according to the present invention.

[0055] In this embodiment, a low-latency and high-security data transmission method for a video platform includes the following steps:

[0056] S100: Obtain the data transmission task in the target area, and determine the key update association information of each mobile terminal in the target area according to the planned transmission content in the data transmission task;

[0057] S200: Query the network bandwidth parameters of the regional communication network, consider the historical key update data of each mobile terminal, and generate the key update execution policy and key cache execution policy for each mobile terminal;

[0058] S300: According to the key update execution policy and key cache execution policy, use the user dynamic feature set collected and uploaded by each mobile terminal to construct the key pair update list for each mobile terminal;

[0059] S400: After establishing an encrypted tunnel between the video platform and the target mobile terminal, send the key update execution policy of the target mobile terminal to the target mobile terminal, and respectively execute the key cache of the video platform and the key update of the target mobile terminal based on the key cache execution policy and key update execution policy;

[0060] S500: Drive each mobile terminal to perform data transmission tasks according to the keys updated in real time.

[0061] It should be noted that the communication between the existing video platform and the terminal device is usually transmitted in an encrypted form to protect user privacy, ensure the integrity of the communication content, and prevent information leakage. However, the process of data encrypted transmission still faces the following limitations:

[0062] (1) In some application fields of high-level communication (such as financial transaction videos, government department videos, and conference videos involving major business secrets, etc.), higher requirements are put forward for the security and accuracy of data transmission. While increasing the complexity of the encryption algorithm, it is also necessary to replace the communication encryption keys used during the video process to ensure that even if the key is cracked in a short time, the attacker cannot obtain a large amount of valid data. Different levels of videos usually configure different key replacement frequencies to reduce unnecessary hardware resource consumption of the system. This requires a reasonable arrangement of the key replacement for each terminal device to minimize the hardware resource consumption of the system while improving communication security.

[0063] (2) In practical applications, multiple terminal devices within a region may be connected to a video platform through a communication network (for example, multiple video mobile terminals under the same enterprise communicate with the video platform through the enterprise network gateway). In such a case, different terminal devices have different key replacement frequency requirements (determined by the video confidentiality level) and data volume transmission requirements (determined by the video transmission content) at different time periods. When performing key replacement for each mobile terminal, not only the replacement frequency requirements need to be considered, but also the impact of the data volume transmission upper limit brought by the shared communication network on key distribution needs to be considered (when the data transmission volume is large and the network bandwidth is limited, a large amount of network resources will be occupied by data transmission, affecting the timeliness of key distribution and replacement), which poses a high difficulty for the planning of the key replacement time for each terminal device.

[0064] (3) Caching the keys to be replaced in advance on each terminal device can, to a certain extent, solve the impact of network bandwidth on key distribution. However, the practice of storing keys on terminal devices for a long time increases the probability of key theft, thereby threatening the security of encrypted communication. Therefore, when implementing key distribution and caching for each terminal device by the video platform, the storage time of keys on mobile terminals needs to be considered.

[0065] (4) When the terminal device performs key replacement, it needs to cache the transmitted data and wait until the key is successfully switched before transmitting it to the video platform. Different data transmission volumes of the terminal device at different time periods will result in differences in the amount of transmitted data that needs to be cached when performing key replacement at different time points. Moreover, different hardware resources of different terminal devices (mainly CPU processing power and memory reading speed) will affect the time-consuming of the terminal device to perform key switching and cached data processing. If the amount of cached transmitted data and the time-consuming of key switching and cached data processing cannot be reduced, it will lead to obvious video delay and stuttering phenomena.

[0066] (5) The encryption keys adopted by existing video platforms and terminal devices are static keys, that is, the keys generated and stored by the video platform, and key distribution is performed at the corresponding time to achieve encrypted communication. The use of static keys has relatively high security risks, increasing the possibility of key cracking and theft, and cannot provide sufficient security protection. Once leaked, attackers can use the key for illegal access and data theft for a long time.

[0067] To solve the above problems, in this embodiment, the key update association information and network bandwidth parameters are used, the historical key update data of each mobile terminal is considered, and an optimization algorithm is adopted to solve the key update execution strategy and key caching execution strategy of each mobile terminal respectively. While meeting the key replacement frequencies of different mobile terminals at different time periods, the impact of data transmission delay caused by key switching is reduced and the risk brought by key caching is minimized as much as possible. At the same time, the key update execution strategy and key caching execution strategy are converted into key update parameter retrieval coordinates, and the update method of each dynamic key compared with the original key is determined in the key update parameter matrix constructed by the user dynamic feature set. By embedding the user dynamic features and the data words of the key update and caching strategies, the timeliness and complexity of the key are improved, and the cracking difficulty is increased.

[0068] In a preferred embodiment, the steps of obtaining the data transmission task in the target area and determining the key update association information of each mobile terminal in the target area according to the planned transmission content in the data transmission task specifically include:

[0069] S110: Obtain the data transmission task in the target area, and extract the data planned transmission content of each transmission cycle of several mobile terminals in the target area within the target task time period in the data transmission task; wherein, the several mobile terminals are connected to the video platform using the same area communication network;

[0070] S120: According to the data planned transmission content, estimate the data transmission sensitivity level and the data transmission volume per unit time of each transmission cycle within the target task time period, and generate the key update association information of each mobile terminal.

[0071] Furthermore, the steps of obtaining the data transmission task in the target area specifically include:

[0072] S111: Obtain the data transmission requirements pre-sent by several mobile terminals in the target area to the video platform; wherein, the data transmission requirements include the data planned transmission time period and the data planned transmission content;

[0073] S112: According to the transmission cycles included in the target task time period of the data planned transmission time period, replace the planned transmission time period in the data transmission requirements of each mobile terminal with several transmission cycles, and construct the data transmission task in the target area.

[0074] Furthermore, the steps of estimating the data transmission sensitivity level and the data transmission volume per unit time of each transmission cycle within the target task time period according to the data planned transmission content and generating the key update association information of each mobile terminal specifically include:

[0075] S121: According to the data planned for transmission in each transmission cycle, estimate the data transmission sensitivity level and the data transmission volume per unit time in each transmission cycle within the target time period by using the method of text keyword matching in the pre-set relation comparison table of the keyword set with the data sensitivity level and the data transmission type.

[0076] S122: Based on the data transmission sensitivity level, determine the key update frequency requirement for each transmission cycle, and use the key update frequency requirement and the data transmission volume per unit time to generate the key update association information for each mobile terminal in each transmission cycle.

[0077] In this embodiment, it is determined that by extracting the data planned for transmission in each transmission cycle of a number of mobile terminals within the target area during the target task time period in the data transmission task, the corresponding data sensitivity level and data transmission type are determined in the pre-set relation comparison table according to the data planned for transmission by using the method of text keyword matching. The key update frequency of each mobile terminal in each transmission cycle is determined by using the data sensitivity level, and the data transmission volume per unit time is determined by using the data transmission type, so as to generate the key update association information and provide basic data for the key update planning of each mobile terminal.

[0078] In a preferred embodiment, query the network bandwidth parameters of the regional communication network, consider the historical key update data of each mobile terminal, and generate the key update execution policy and key cache execution policy steps for each mobile terminal, specifically including:

[0079] S210: Query the network bandwidth parameters of the regional communication network, and extract the key update estimated time and the upper limit value of the cached data volume in the historical key update data of each mobile terminal.

[0080] S220: According to the key update estimated time of each mobile terminal and the data transmission volume per unit time in the key update association information of each transmission cycle, calculate the total amount of cached data for a single key update when each mobile terminal performs key update in different transmission cycles.

[0081] S230: According to the network bandwidth parameters of the regional communication network and the data transmission volume per unit time of each mobile terminal in each transmission cycle, calculate the redundant bandwidth parameter of the regional communication network in each transmission cycle, and determine the key cache time period based on all transmission cycles in which the redundant bandwidth parameter is higher than the preset bandwidth parameter threshold.

[0082] S240: Use the total amount of cached data for a single key update, the upper limit value of the cached data volume, and the key cache time period, and adopt an optimization algorithm to solve the key update execution policy and key cache execution policy of each mobile terminal respectively.

[0083] In this embodiment, by querying the obtained network bandwidth parameters and the historical key update data of each mobile terminal, the estimated key update time (usually obtained by calculating the average completion time of multiple key updates) and the upper limit of the cache data amount (usually obtained by analyzing the amount of data cached when the mobile terminal has obvious delays and freezes) in the historical key update data of each mobile terminal are calculated, and the total amount of cache data for a single key update when each mobile terminal performs key update in different transmission cycles (usually obtained by calculating the product of the estimated key update time and the data transmission amount per unit time) is calculated, and the key cache period consisting of all transmission cycles with redundant bandwidth parameters higher than the preset bandwidth parameter threshold is determined (usually determined by the period consisting of the union of all transmission cycles with redundant bandwidth parameters higher than the preset bandwidth parameter threshold). Finally, the key update execution strategy and key cache execution strategy of each mobile terminal are solved respectively using an optimization algorithm.

[0084] Furthermore, the key update execution strategy steps for each mobile terminal are solved, including:

[0085] S241: The first constraint condition is that the interval between any two consecutive key updates performed by each mobile terminal within the target task period does not exceed the key update period duration corresponding to the key update frequency requirement of the mobile terminal in the corresponding transmission period, and the second constraint condition is that the total amount of cached data for a single key update when each mobile terminal performs each key update is less than a preset cached data amount upper limit value according to the mobile terminal;

[0086] S242: Taking the minimum number of key updates within the target task period as the optimization goal, optimizing and solving the update execution time of each key update within the target task period, and generating a key update execution strategy.

[0087] Furthermore, the key cache execution strategy steps of each mobile terminal are solved, including:

[0088] S243: The cache time of each execution of the key cache is earlier than the update execution time of all key updates in the key cache as a constraint condition;

[0089] S244: Taking the minimum sum of the product of the total number of key caching times and the first weight factor, the sum of the difference between the cache time of each key cache execution and the update execution time of each key update in the key cache and the second weight factor as the optimization goal, optimize and solve the cache execution time of each key cache in the key cache period, and generate a key cache execution strategy.

[0090] In this embodiment, the key update association information of each mobile terminal is determined through the planned transmission content in the data transmission task. According to the key update association information and network bandwidth parameters, considering the historical key update data of each mobile terminal, using the calculated total amount of single-key update cache data, the upper limit value of cache data volume, and the determined key cache period, an optimization algorithm is adopted to solve the key update execution strategy and key cache execution strategy of each mobile terminal respectively, while meeting the key replacement frequencies of different mobile terminals at different times, reducing the impact of data transmission delay caused by key switching, and minimizing the risk brought by key caching as much as possible.

[0091] In a preferred embodiment, according to the key update execution strategy and key cache execution strategy, using the user dynamic feature set collected and uploaded by each mobile terminal, the steps of constructing the key pair update list for each mobile terminal specifically include:

[0092] S310: Extract several cache execution times in the key cache execution strategy of each mobile terminal and several update execution times in the key update execution strategy, and numerically convert the update execution time for each key update and the cache execution time for the corresponding key to perform key caching as the retrieval coordinates for the corresponding key;

[0093] S320: Obtain the first dynamic feature and the second dynamic feature in the user dynamic feature set collected and uploaded in advance by each mobile terminal, normalize and convert the first dynamic feature and the second dynamic feature into digital feature vectors, use the combination of the number of digits in the digital feature vectors corresponding to the first dynamic feature and the second dynamic feature as the table coordinates, and use the sum of the values in the digital feature vectors corresponding to the first dynamic feature and the second dynamic feature as the table elements to construct a key update parameter matrix;

[0094] S330: Based on the retrieval coordinates of the key corresponding to each key update execution, match the key update parameters for several key updates of each mobile terminal in the key update parameter matrix, and use the key update parameters to perform dynamic updates of the associated user features on the initial key pairs of each mobile terminal to obtain several dynamically updated key pairs, and construct the key pair update list for each mobile terminal;

[0095] Among them, the dynamic update of the associated user features for the initial key pairs of each mobile terminal includes: using the sum of the values corresponding to the key update parameters as the embedding position of the binary digit number of the initial key, and using the concatenated combination of the digital feature vectors corresponding to the first dynamic feature and the second dynamic feature as the embedded binary number to perform dynamic updates on the initial keys of each mobile terminal.

[0096] In this embodiment, the generated key update execution policy and key caching execution policy are converted into key update parameter retrieval coordinates, and the update method of each dynamic key compared to the original key is determined in the key update parameter matrix constructed by the user dynamic feature set. By embedding data words associated with the user's own dynamic features and real-time generated key update and caching policies, the immediacy and complexity of the key are improved, and the cracking difficulty is increased.

[0097] In a preferred embodiment, after establishing an encrypted tunnel between the video platform and the target mobile terminal, the key update execution policy of the target mobile terminal is sent to the target mobile terminal. Based on the key caching execution policy and the key update execution policy, the key caching of the video platform and the key update steps of the target mobile terminal are respectively executed, specifically including:

[0098] S410: After establishing an encrypted tunnel between the video platform and the target mobile terminal, the key update execution policy of the target mobile terminal is sent to the target mobile terminal, and the key pair data set for each key caching is determined from the key pair update list based on the key caching execution policy;

[0099] S420: The video platform caches the key pair data set for each key caching to the target mobile terminal at the corresponding cache execution time according to the key caching execution policy, and the target mobile terminal performs key update at the corresponding update execution time according to the cached key pair data set and the received key update execution policy.

[0100] In this embodiment, after establishing an encrypted tunnel between the video platform and the target mobile terminal, according to the solved key caching execution policy and key update execution policy, the distribution of the corresponding number of keys is performed at the corresponding time on the video platform and the key update is performed at the corresponding time on the mobile terminal, which can improve the encryption communication security between the video platform and multiple mobile terminals while reducing the video delay, and realize low-latency and high-security data transmission for the video platform.

[0101] Refer to Figure 2 , Figure 2 which is the structural block diagram of the embodiment of the low-latency and high-security data transmission system for the video platform of the present invention.

[0102] As Figure 2 shown, the low-latency and high-security data transmission system for the video platform proposed by the embodiment of the present invention includes:

[0103] A determination module 10, configured to obtain a data transmission task in a target area, and determine key update association information of each mobile terminal in the target area according to the planned transmission content in the data transmission task;

[0104] A query module 20, configured to query network bandwidth parameters of a regional communication network, consider historical key update data of each mobile terminal, and generate a key update execution policy and a key cache execution policy for each mobile terminal;

[0105] A construction module 30, configured to construct a key pair update list for each mobile terminal according to the key update execution policy and the key cache execution policy, using the user dynamic feature set collected and uploaded by each mobile terminal;

[0106] A sending module 40, configured to, after establishing an encrypted tunnel between the video platform and a target mobile terminal, send the key update execution policy of the target mobile terminal to the target mobile terminal, and respectively execute key caching of the video platform and key update of the target mobile terminal based on the key cache execution policy and the key update execution policy;

[0107] An execution module 50, configured to drive each mobile terminal to perform data transmission tasks according to the keys updated in real time.

[0108] For other embodiments or specific implementation manners of the low-latency and high-security data transmission system for a video platform according to the present invention, reference may be made to the above method embodiments, which will not be elaborated herein.

[0109] It can be understood that in the description of this specification, the descriptions referring to terms such as "one embodiment", "another embodiment", "other embodiments", or "the first embodiment to the Nth embodiment" mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples.

[0110] It should be noted that in this article, the term "comprising", "including", or any other variant thereof is intended to cover a non-exclusive inclusion, such that a process, method, article, or system including a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article, or system. Without further limitation, an element defined by the phrase "including a..." does not exclude the existence of additional identical elements in the process, method, article, or system including the element.

[0111] The above are only the preferred embodiments of the present invention, and thus do not limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present invention, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present invention.

Claims

1. A low-latency and high-security data transmission method for a video conferencing platform, characterized in that: The following steps are involved: Obtaining a data transmission task for a target area, and determining key update association information for each mobile terminal in the target area according to the planned transmission content in the data transmission task; Query the network bandwidth parameters of the regional communication network, consider the historical key update data of each mobile terminal, and generate the key update execution strategy and key cache execution strategy for each mobile terminal; specifically include: query the network bandwidth parameters of the regional communication network, extract the key update estimated time and the upper limit of the cached data volume in the historical key update data of each mobile terminal; calculate the total amount of single key update cached data of each mobile terminal when performing key update in different transmission cycles according to the key update estimated time of each mobile terminal and the data transmission volume per unit time in the key update association information of each transmission cycle; calculate the redundant bandwidth parameters of the regional communication network in each transmission cycle according to the network bandwidth parameters of the regional communication network and the data transmission volume per unit time of each mobile terminal in each transmission cycle, and determine the key cache period based on all transmission cycles where the redundant bandwidth parameters are higher than the preset bandwidth parameter threshold; use the total amount of cached data for a single key update, the upper limit of the cached data volume and the key cache period, and adopt an optimization algorithm to solve the key update execution strategy and key cache execution strategy of each mobile terminal respectively; Among them, the step of solving the key update execution strategy of each mobile terminal specifically includes: taking the interval time between any two adjacent key updates performed by each mobile terminal within the target task period not exceeding the key update period duration corresponding to the key update frequency requirement of the mobile terminal in the corresponding transmission period as the first constraint condition, and taking the total amount of cached data of a single key update when each mobile terminal performs each key update as the second constraint condition less than the preset cache data amount upper limit value according to the mobile terminal; taking the minimum number of key updates within the target task period as the optimization goal, optimizing and solving the update execution time of each key update within the target task period, and generating a key update execution strategy; The step of solving the key cache execution strategy of each mobile terminal specifically includes: taking the cache time of each key cache execution earlier than the update execution time of all key updates in the key cache as a constraint condition; taking the product of the sum of the total number of key cache times and the first weight factor, the cache time of each key cache execution and the update execution time of each key update in the key cache and the second weight factor as the minimum as the optimization goal, optimizing and solving the cache execution time of each key cache in the key cache period, and generating the key cache execution strategy; According to the key update execution strategy and the key cache execution strategy, a key pair update list for each mobile terminal is constructed by using the user dynamic feature set collected and uploaded by each mobile terminal; specifically, the following steps are performed: extracting a number of cache execution times in the key cache execution strategy and a number of update execution times in the key update execution strategy of each mobile terminal, and digitizing the update execution time of each key update and the cache execution time of the corresponding key cache as the retrieval coordinates of the corresponding key; obtaining the first dynamic feature and the second dynamic feature in the user dynamic feature set collected and uploaded in advance by each mobile terminal, normalizing the first dynamic feature and the second dynamic feature into a digital feature vector, using the combination of the digits in the digital feature vector corresponding to the first dynamic feature and the second dynamic feature as the table coordinates, and digitizing the first dynamic feature and the second dynamic feature as the table coordinates. The sum of the values ​​in the digital feature vectors corresponding to the features is used as a table element to construct a key update parameter matrix; based on the retrieval coordinates of the key corresponding to each key update, the key update parameters of each mobile terminal for several key updates are matched in the key update parameter matrix, and the initial key pair of each mobile terminal is dynamically updated with the associated user features using the key update parameters to obtain several dynamically updated key pairs, and a key pair update list for each mobile terminal is constructed; wherein the dynamic update of the associated user features for the initial key pair of each mobile terminal includes: using the sum of the values ​​corresponding to the key update parameters as the binary value bit embedding position of the initial key, using the concatenation combination of the digital feature vectors corresponding to the first dynamic feature and the second dynamic feature as the embedded binary value, and dynamically updating the initial key of each mobile terminal; After establishing an encrypted tunnel between the videoconferencing platform and the target mobile terminal, the key update execution policy of the target mobile terminal is sent to the target mobile terminal, and based on the key cache execution policy and the key update execution policy, the key cache of the videoconferencing platform and the key update of the target mobile terminal are respectively executed; Each mobile terminal is driven to perform data transmission tasks according to the key updated in real time.

2. The low-latency and high-security data transmission method for a video conferencing platform as claimed in claim 1, characterized in that: The step of obtaining a data transmission task for a target area and determining key update associated information for each mobile terminal in the target area according to the planned transmission content in the data transmission task specifically includes: Acquire a data transmission task for a target area, and extract the data transmission plan content of each transmission cycle of a plurality of mobile terminals in the target area in the data transmission task within the target task period; wherein the plurality of mobile terminals use the same regional communication network to connect to the video conferencing platform; According to the data plan transmission content, the data transmission sensitivity level and data transmission volume per unit time of each transmission cycle within the target task period are estimated, and the key update association information of each mobile terminal is generated.

3. The low-latency and high-security data transmission method for a video conferencing platform as claimed in claim 2, characterized in that: The steps for obtaining the data transmission task of the target area include: Acquire data transmission requirements sent in advance by a number of mobile terminals in the target area to the video conferencing platform; wherein the data transmission requirements include a planned data transmission period and planned data transmission content; According to the transmission cycles included in the planned data transmission period within the target task period, the planned transmission period in the data transmission demand of each mobile terminal is replaced with a number of transmission cycles to construct a data transmission task for the target area.

4. The low-latency and high-security data transmission method for a video conferencing platform as claimed in claim 2, characterized in that: According to the data transmission plan content, the data transmission sensitivity level and the data transmission volume per unit time of each transmission cycle in the target task period are estimated, and the key update association information of each mobile terminal is generated, specifically including: According to the data transmission content of each transmission cycle, the data transmission sensitivity level and the data transmission volume per unit time of each transmission cycle in the target period are estimated by using a text keyword matching method in a relation comparison table between a preset keyword set, a data sensitivity level and a data transmission type; Based on the data transmission sensitivity level, a key update frequency requirement for each transmission cycle is determined, and key update association information of each mobile terminal in each transmission cycle is generated by using the key update frequency requirement and the data transmission volume per unit time.

5. The low-latency and high-security data transmission method for a video conferencing platform as claimed in claim 1, characterized in that: After establishing an encrypted tunnel between the videoconferencing platform and the target mobile terminal, the key update execution policy of the target mobile terminal is sent to the target mobile terminal. Based on the key cache execution policy and the key update execution policy, the key cache of the videoconferencing platform and the key update steps of the target mobile terminal are respectively executed, specifically including: After establishing an encrypted tunnel between the videoconferencing platform and the target mobile terminal, sending the key update execution policy of the target mobile terminal to the target mobile terminal, and determining the key pair data set for executing each key cache from the key pair update list based on the key cache execution policy; The videoconferencing platform caches the key pair data set of each key cache execution to the target mobile terminal at the corresponding cache execution time according to the key cache execution strategy. The target mobile terminal updates the key at the corresponding update execution time according to the cached key pair data set and the received key update execution strategy.

6. A low-latency and high-security data transmission system for a video conferencing platform, characterized in that: include: A determination module, used to obtain a data transmission task in a target area, and determine key update association information of each mobile terminal in the target area according to the planned transmission content in the data transmission task; A query module is used to query the network bandwidth parameters of the regional communication network, consider the historical key update data of each mobile terminal, and generate the key update execution strategy and key cache execution strategy of each mobile terminal; specifically comprising: querying the network bandwidth parameters of the regional communication network, extracting the estimated key update time and the upper limit of the cached data volume in the historical key update data of each mobile terminal; calculating the total amount of single key update cached data of each mobile terminal when performing key update in different transmission cycles according to the estimated key update time of each mobile terminal and the data transmission volume per unit time in the key update association information of each transmission cycle; calculating the redundant bandwidth parameters of the regional communication network in each transmission cycle according to the network bandwidth parameters of the regional communication network and the data transmission volume per unit time of each mobile terminal in each transmission cycle, and determining the key cache period based on all transmission cycles where the redundant bandwidth parameters are higher than the preset bandwidth parameter threshold; using the total amount of cached data for a single key update, the upper limit of the cached data volume and the key cache period, using an optimization algorithm to respectively solve the key update execution strategy and the key cache execution strategy of each mobile terminal; Among them, solving the key update execution strategy for each mobile terminal specifically includes: taking the interval time between any two adjacent key updates performed by each mobile terminal within the target task period not exceeding the key update period duration corresponding to the key update frequency requirement of the mobile terminal in the corresponding transmission period as the first constraint condition, and taking the total amount of cached data of a single key update when each mobile terminal performs each key update as the second constraint condition less than the preset cache data amount upper limit value according to the mobile terminal; taking the minimum number of key updates within the target task period as the optimization goal, optimizing and solving the update execution time of each key update within the target task period, and generating the key update execution strategy; Wherein, solving the key cache execution strategy of each mobile terminal specifically includes: taking the cache time of each key cache execution earlier than the update execution time of all key updates in the key cache as a constraint condition; taking the product of the sum of the total number of key caches and the first weight factor, the cache time of each key cache execution and the update execution time of each key update in the key cache and the second weight factor as the minimum as the optimization goal, optimizing and solving the cache execution time of each key cache in the key cache period, and generating the key cache execution strategy; A construction module is used to construct a key pair update list for each mobile terminal based on a key update execution strategy and a key cache execution strategy, using a user dynamic feature set collected and uploaded by each mobile terminal; specifically comprising: extracting a number of cache execution times in the key cache execution strategy of each mobile terminal and a number of update execution times in the key update execution strategy, digitizing the update execution time of each key update and the cache execution time of the corresponding key cache as retrieval coordinates of the corresponding key; obtaining a first dynamic feature and a second dynamic feature in a user dynamic feature set collected and uploaded in advance by each mobile terminal, normalizing the first dynamic feature and the second dynamic feature into a digital feature vector, using a combination of the digits in the digital feature vector corresponding to the first dynamic feature and the second dynamic feature as table coordinates, and digitizing the first dynamic feature and the second dynamic feature as table coordinates. The sum of the values ​​in the digital feature vectors corresponding to the two dynamic features is used as a table element to construct a key update parameter matrix; based on the retrieval coordinates of the key corresponding to each key update, the key update parameters of each mobile terminal for several key updates are matched in the key update parameter matrix, and the initial key pair of each mobile terminal is dynamically updated with the associated user characteristics using the key update parameters to obtain several dynamically updated key pairs, and a key pair update list for each mobile terminal is constructed; wherein, the dynamic update of the associated user characteristics of the initial key pair of each mobile terminal includes: using the sum of the values ​​corresponding to the key update parameters as the binary value bit embedding position of the initial key, using the concatenated combination of the digital feature vectors corresponding to the first dynamic feature and the second dynamic feature as the embedded binary value, and dynamically updating the initial key of each mobile terminal; A sending module, used to send the key update execution policy of the target mobile terminal to the target mobile terminal after establishing an encrypted tunnel between the videoconferencing platform and the target mobile terminal, and execute the key cache of the videoconferencing platform and the key update of the target mobile terminal respectively based on the key cache execution policy and the key update execution policy; The execution module is used to drive each mobile terminal to execute the data transmission task according to the key updated in real time.

Citation Information

Patent Citations

  • Quantum key scheduling method for cloud computing platform

    CN114499864A

  • Electronic book file secondary encryption method based on MD5 encryption and asynchronous request

    CN119341844A