Multilayer safe real-time audio and video method and system

By monitoring user behavior and the characteristics of the device environment in real time, the mapping relationship between identity authentication and device identification is constructed, and the verification strength of identity authentication is dynamically adjusted, the security risks existing in the audio and video transmission process in the existing technology are solved, and information security and user experience are improved.

CN120074873APending Publication Date: 2025-05-30SHENZHEN XINGYIMEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510086501.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-20
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Existing audio and video transmission technologies have security risks in complex application environments, such as the device being controlled by malware or the environment being monitored by unauthorized third parties, resulting in audio and video data leakage.

Method used

By obtaining the user's normal behavior and feature set of device environment, we can monitor in real time whether the user's behavior and device environment comply with the predefined security feature set, and issue information leakage security warning when an exception is detected. At the same time, a mapping relationship between identity authentication and device identification is constructed, the verification strength of identity authentication is dynamically adjusted, and the identity authentication process is adjusted according to the comprehensive risk score of user behavior and device environment.

Benefits of technology

It improves the information security during audio and video transmission, promptly detects and warns of potential information leakage risks, reduces the risk of internal personnel leaks, and simplifies the user's identity authentication process while ensuring security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074873A_ABST
    Figure CN120074873A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-layer safe real-time audio and video method and system, and relates to the field of information safety, and the method comprises the steps: obtaining a normal behavior of a user and a feature set of an equipment environment; sending a request instruction for acquiring the environment detection permission to login equipment participating in real-time audio and video; obtaining identification information of login equipment in response to opening of the environment detection obtaining permission; if the behavior characteristics of the user and the equipment environment characteristics conform to the characteristic set, constructing a corresponding relation between identity authentication and the identification information; otherwise, information leakage safety early warning is carried out; and when the user logs in the connection again, if it is detected that the identity authentication does not accord with the identification information, information leakage safety early warning is carried out. By implementing the method, the security feature set can be constructed, and the abnormal change of the user behavior and the equipment environment is continuously monitored in the process of transmitting the real-time audio data in the user login process, so that the information security in the real-time audio and video communication process is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security, and particularly to a multi-layer security real-time audio and video method and system. Background Art

[0002] In modern society, information security has become an increasingly important issue, especially the security problem in the process of audio and video transmission. Audio and video communication technologies are widely used in various scenarios such as distance education, telemedicine, and monitoring systems. With the development of technology, users have higher requirements for the security and real-time performance of audio and video communication.

[0003] Current audio and video transmission technologies generally use encryption technologies to ensure the security of data during transmission. For example, the TLS / SSL protocol is used to encrypt the transmitted audio and video data to prevent the data from being intercepted and tampered with during transmission. In addition, some systems also implement authentication measures to ensure that only authorized users can access the audio and video content.

[0004] However, despite the use of encryption and authentication technologies, there are still some security risks in the existing technologies in complex application environments. For example, if the device is controlled by malware or the environment is monitored by an unauthorized third party, the leakage of audio and video data may occur. Summary of the Invention

[0005] This application provides a multi-layer security real-time audio and video method and system, which is used to, after the user passes the identity authentication, monitor and verify in real time whether the user's behavior characteristics and device environment characteristics both conform to a pre-defined security feature set, so as to improve the information security during the audio and video transmission process.

[0006] In a first aspect, this application provides a multi-layer security real-time audio and video method, which is applied to a real-time audio system. The method includes: Obtain the feature set of the user's normal behavior and device environment, where the feature set includes the behavior characteristics and device environment characteristics of the user during the normal use of the login device for real-time audio in multiple scenarios; After detecting that the user passes the identity authentication, send a request instruction for obtaining the environment detection permission to the login device participating in the real-time audio and video; In response to enabling the acquisition of the environment detection permission, obtain the identification information of the login device; During the user's use process, monitor in real time whether the user's behavior characteristics and device environment characteristics both conform to the feature set; If not, then perform an information leakage security warning; If so, then establish a correspondence relationship between the identity authentication and the identification information, and simplify the identity authentication process of the users with the correspondence relationship, where the identity authentication process includes multiple different identity verification steps; When the user logs in and connects again, if it is detected that the identity authentication does not match the identification information, an information leakage security warning is issued.

[0007] Through the above embodiments, the real-time audio system obtains the feature set of the user's normal behavior and device environment as a benchmark. After the user logs in and passes the identity authentication, it continuously monitors whether the user's behavior and device environment conform to the feature set. If an abnormality is detected, an information leakage warning is issued; if there is no abnormality, a mapping relationship between the identity authentication and the device identification is constructed. And when the user logs in again, it determines whether there is a risk of information leakage by comparing the consistency between the identity authentication and the device identification. This method can construct a security feature set of the user's normal behavior and device environment, continuously monitor the abnormal changes of the user's behavior and device environment during the process of the user logging in and based on real-time audio data transmission, and improves the information security during the real-time audio and video communication process.

[0008] In some embodiments, before the step of issuing an information leakage security warning when it is detected that the identity authentication does not match the identification information when the user logs in and connects again, it further includes: Obtain the authorized users set by the management personnel and one or more identification information corresponding to each authorized user; Update the corresponding relationship between the identity authentication and the identification information based on one or more identification information corresponding to each authorized user.

[0009] Through the above embodiments, the real-time audio system introduces the setting of the administrator for the authorized users and their corresponding device identifications, enabling the mapping relationship between the identity authentication and the device identification to be flexibly adjusted. This not only allows a user to log in on multiple authorized devices, but also can timely remove the login permissions of departing personnel, further improving the identity permission management mechanism and reducing the risk of internal personnel leaking secrets.

[0010] In some embodiments, after the step of continuously monitoring whether the user's behavior characteristics and device environment characteristics conform to the feature set during the user's use, it further includes: If it is monitored that the user's behavior characteristics do not conform to the feature set, an abnormal behavior feature sequence is output; If it is monitored that the user's device environment characteristics do not conform to the feature set, an abnormal environment feature sequence is output.

[0011] Through the above embodiments, the real-time audio system can output an abnormal feature sequence when detecting an abnormality in the user's behavior or device environment, providing more detailed information for the abnormal situation and facilitating the user to make adaptive adjustments based on the abnormal situation.

[0012] In some embodiments, before the step of obtaining the feature set of the user's normal behavior and device environment, it further includes: Collect the test data of multiple test users, where the test data includes behavioral data parameters and device environment parameters; Perform behavioral recognition and anomaly detection on the test data to determine the normal behavioral characteristics and device environment characteristics during the user's connection to real-time audio and video; Establish a feature set of normal behaviors and device environments based on the normal behavioral characteristics and device environment characteristics.

[0013] Through the above embodiments, the real-time audio system collects the behavioral data and device environment parameters of test users during use, and establishes a feature set reflecting the normal use state through behavioral recognition and anomaly detection algorithms, which can more accurately depict normal behaviors and improve the accuracy of anomaly judgment.

[0014] In some embodiments, after the step of constructing the correspondence between identity authentication and identification information, it further includes: Calculate a comprehensive risk score based on the user's behavioral characteristics and device environment characteristics; Adjust the verification level of the identity authentication process according to the comprehensive risk score, and the verification level is proportional to the comprehensive risk score.

[0015] Through the above embodiments, the real-time audio system adjusts the verification intensity of identity authentication according to the comprehensive risk calculation of user behavior and device environment. When the comprehensive risk score is relatively high, more stringent identity verification is enabled, such as requiring the user to provide additional biometric features, etc.; otherwise, the verification level is reduced and the verification process is simplified. This solution can minimize the burden on normal users while ensuring security, making the authentication process more intelligent and dynamic.

[0016] In some embodiments, before the step of sending a request instruction to obtain environmental detection permission to the logged-in device participating in real-time audio and video after detecting that the user has passed identity authentication, it further includes: Authenticate the user through the user account and biometric technology; If it is detected that the number of times of user identity authentication failure exceeds a preset quantity threshold, obtain the user's face information through the camera for manual recognition.

[0017] Through the above embodiments, after detecting that the user fails to verify multiple times, the real-time audio system captures the user's face through the camera and hands it over to the administrator for manual review. This avoids denial of service caused by unstable biometric features and improves the reliability of identity authentication.

[0018] In some embodiments, after the step of constructing the correspondence between identity authentication and identification information, it further includes: Obtain the permission list of each user account; Set the operation permissions of each user account according to the permission list.

[0019] Through the above embodiments, the real-time audio system sets corresponding operation permissions according to the privilege level of the user account. Data with different security levels corresponds to different user permissions, and sensitive data is only open to accounts with high privileges. By restricting permissions, the scope of users' access to sensitive data can be minimized, and the risk of internal personnel leaking secrets can be reduced.

[0020] In a second aspect, the present application provides a real-time audio system, which includes: one or more processors and a memory; The memory is coupled to the one or more processors, and the memory is used to store computer program code. The computer program code includes computer instructions, and the one or more processors call the computer instructions so that the real-time audio system can implement a multi-layer secure real-time audio and video method provided by the above embodiments, which will not be elaborated here.

[0021] In a second aspect, the present application provides a computer-readable storage medium, including instructions that, when running on a real-time audio system, enable the real-time audio system to implement a multi-layer secure real-time audio and video method provided by the above embodiments, which will not be elaborated here.

[0022] In a third aspect, the present application provides a computer program product that, when running on a real-time audio system, enables the real-time audio system to implement a multi-layer secure real-time audio and video method provided by the above embodiments, which will not be elaborated here.

[0023] One or more technical solutions provided in the embodiments of the present application have at least the following technical effects or advantages: 1. Continuously monitor whether the user behavior and device environment conform to a pre-established feature set, rather than being limited to identity authentication at login. By comparing the deviation degree between the actual state and the normal mode in real time during use, abnormal behaviors caused by device compromise or credential theft can be discovered in a timely manner, improving the proactive defense ability of the system. At the same time, the system can also output a detailed abnormal feature sequence to facilitate users to understand and handle abnormal situations.

[0024] 2. Dynamically adjust the verification intensity of identity authentication according to the comprehensive risk score of user behavior and device environment. When the comprehensive risk is high, the system will enable more stringent identity verification means; otherwise, the verification intensity will be reduced. This method integrates multiple factors such as user behavior information and device status, and determines the authentication method by quantifying the risk level, which maximizes the reduction of the burden on normal users while improving the security of the system, reflecting intelligence and dynamic adaptability.

[0025] 3. Associate the sensitivity level of data with the user privilege level, and implement different access controls for data of different security levels. Ensure that users can only access the data within the minimum privilege range required for their job responsibilities, minimize the exposure surface of sensitive information, and thus reduce the risk of insider leaks. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Figure 1 is a schematic flowchart of a multi-layer security real-time audio and video method in an embodiment of the present application; Figure 2 is another schematic flowchart of a multi-layer security real-time audio and video method in an embodiment of the present application; Figure 3 is a schematic structural diagram of an entity device of a real-time audio system in an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0027] The terms used in the following embodiments of the present application are only for the purpose of describing specific embodiments and are not intended to limit the present application. As used in the specification and appended claims of the present application, the singular forms "a", "an", "the", "above", "said", "this" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used in the present application refers to any and all possible combinations including one or more of the listed items.

[0028] Hereinafter, the terms "first" and "second" are only used for descriptive purposes and cannot be construed as implying or indicating relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the embodiments of the present application, unless otherwise specified, the meaning of "a plurality" is two or more.

[0029] For ease of understanding, the method provided in this embodiment will be described in terms of a process in combination with the above scenario. Please refer to Figure 1 , which is a schematic flowchart of a multi-layer security real-time audio and video method in an embodiment of the present application.

[0030] S101. Obtain the feature set of the user's normal behavior and the device environment.

[0031] Specifically, the real-time audio system establishes connections with the terminal devices (such as mobile phones, computers, etc.) of multiple test users, reads the work logs during the remote video process of the terminal devices, and thus obtains the behavior data and device internal environment data during the real-time audio data transmission process of the users. Among them, the behavior data are some typical operation behaviors of the users during the video call, such as whether the screen recording software is turned on, whether a screen capture is performed, whether file transfer is carried out with other application programs, etc. The device internal environment data is the internal operating state of the user's terminal device, such as whether there are malicious programs running in the background, whether high-risk applications from unknown sources are installed, whether the usage of system resources is abnormal, etc., which is not limited here.

[0032] The real-time audio system extracts key features reflecting the normal operation state of the user from the above-mentioned behavior data and device internal environment data through machine learning algorithms. For example, the user will not turn on the external screen recording function during the video call; the system resource occupancy of the user is generally stable during the call, and there will be no frequent soaring of CPU or memory usage rates; the user's terminal device generally will not automatically connect to strange external hardware or network storage devices during the call, etc., which is not limited here.

[0033] Next, the real-time audio system integrates the extracted normal features of the user behavior and device environment into a benchmark feature set (that is, the feature set of the user's normal behavior and device environment) to depict the security normality in the remote video scenario. When the system detects that the behavior or environment data of a new user is significantly different from this feature set, it can be determined that there is an abnormal risk in the communication of this user, and further verification and warning are required.

[0034] S102. After detecting that the user passes the identity authentication, send a request instruction for obtaining the environment detection permission to the logged-in devices participating in the real-time audio and video.

[0035] After the user successfully logs in to the real-time audio system through identity authentication (such as password, fingerprint, etc.), in order to further verify the security of the current session, the real-time audio system will send a request for obtaining the environment detection authorization to the user's logged-in device.

[0036] In response to the user authorizing the real-time audio system to obtain the environment detection permission of the logged-in device, the system collects various parameters of the software and hardware environment of the logged-in device, including but not limited to the unique identifier of the device (such as IMEI, MAC address, device serial number, etc.), the installation and running status of security protection software (such as antivirus software), the connection status of external devices (such as cameras, microphones, etc.), and the running status of background programs, etc., which is not limited here.

[0037] In addition, after the real-time audio system detects that the user refuses to grant the environmental detection permission, the real-time audio system conducts a security warning for information leakage in the background, and the specific warning form is not limited here.

[0038] It should be noted that the permission request instruction can be displayed in the form of a pop-up window, and it is determined whether to grant the real-time audio system detection permission based on the control clicked by the user. Of course, it can also be displayed in other forms, which is not limited here.

[0039] S103. In response to enabling the acquisition of the environmental detection permission, acquire the identification information of the logged-in device.

[0040] After the user's logged-in device allows the system to perform environmental detection, the security protection system will acquire the unique identification information of the logged-in device while performing environmental detection. Among them, the unique identification information varies depending on the logged-in device, including but not limited to the IMEI (International Mobile Equipment Identity) and MEID (Mobile Equipment Identifier) of mobile devices; the serial number and motherboard serial number of general computing devices; the MAC address (physical address) of network devices. Of course, other unique identification information can also be added according to the actual application scenario, which is not limited here.

[0041] S104. Whether both the behavioral characteristics and the device environmental characteristics conform to the feature set.

[0042] After the user passes the identity authentication and logs in to the real-time audio system, the user starts to operate specific services. During this process, the real-time audio system starts a continuous monitoring program. This program records the user's behavioral information and the device's environmental information in a concealed and transparent manner, and compares them with the normal feature set established in step S101 in real time to promptly detect abnormal states of the logged-in device.

[0043] The real-time audio system uses algorithms such as statistical tests and machine learning classification to calculate the similarity between the characteristic data of the user's behavior and the device environment and the benchmark feature set in real time with a small performance overhead. Once it detects that the deviation degree between the two exceeds the preset security threshold, it determines that there is an abnormal risk and enters step S107 for information leakage security warning. On the contrary, if it detects that the deviation degree between the two does not exceed the preset security threshold, it continues to execute subsequent steps such as step S105.

[0044] For example, in some embodiments, a certain government department uses the real-time audio system provided by this application to strengthen the protection of the internal system. The account of civil servant Li usually is only used during the specified working hours and in the office. One day, the real-time audio system detected that Li's account logged in through the home network in the middle of the night and started downloading a large number of files. The system immediately marked this behavior as abnormal and conducted an information leakage warning in the system background to promptly discover potential data leakage risks.

[0045] S105. Establish the correspondence between identity authentication and identification information.

[0046] After detecting that the similarity between the characteristic data of the user behavior and device environment and the benchmark characteristic set does not exceed the preset security threshold, the real-time audio system binds the identity authentication credentials successfully passed by the user with the device identification information collected in step S103 to form a set of trusted account-device mapping relationships.

[0047] Among them, the account-device mapping relationship is usually stored in the security context database of the system in the form of key-value pairs, and the account information (such as username, employee number, etc.) is the key, and the device identification information (such as serial number, MAC address, etc.) is the value.

[0048] S106. Check whether the identity authentication and identification information match during subsequent logins.

[0049] Based on the account-device mapping relationship established in step S105, the real-time audio system adds a legality check every time a user logs in subsequently. Once it is found that the login request of the newly logged-in device uses a bound account, but the used device identification does not match the record, it is determined that an abnormal security event such as account theft or session hijacking has occurred, and the warning mechanism in step S107 is immediately started. On the contrary, if it is detected that the identity authentication and identification information match during subsequent logins, the subsequent steps such as normal steps S102 to S104 are performed.

[0050] S107. Conduct security warnings for information leakage.

[0051] The real-time audio system monitors during the process of the user transmitting real-time audio data, including but not limited to login monitoring, user behavior monitoring, device environment monitoring, identity authentication monitoring, etc. If abnormal situations are detected, security warnings for information leakage are carried out in the background of the real-time audio system. In addition, the warning channels include but are not limited to in-site messages, push notifications, emails and other channels, which are not limited here.

[0052] In the above embodiments, the real-time audio system obtains the feature set of the user's normal behavior and device environment as a benchmark. After the user logs in and passes the identity authentication, it continuously monitors whether the user's behavior and device environment conform to the feature set. If an anomaly is detected, an information leakage warning is issued; if there is no anomaly, a mapping relationship between identity authentication and device identification is constructed. And when the user logs in again, it determines whether there is a risk of information leakage by comparing the consistency of identity authentication and device identification. This method not only verifies the user's identity at the login stage, but also continuously monitors the abnormal changes in the user's behavior and device environment during use, improving the information security during real-time audio and video communication. At the same time, establishing a binding relationship between the identity and the device avoids data leakage caused by the user's credentials being stolen and logged in on other devices.

[0053] The following further describes the more specific process of the method provided in this embodiment. Specifically, as Figure 2 shown, it is another process schematic diagram of a multi-layer secure real-time audio and video method in an embodiment of the present application.

[0054] S201. Perform behavior recognition and anomaly detection on the test data of multiple test users to determine the normal behavior characteristics and device environment characteristics during the process of the users connecting to the real-time audio and video.

[0055] Specifically, multiple test users respectively use different terminal devices to log in to the real-time audio system and conduct voice and video communications. And during the process of voice and video communication, arrange for the test users to perform various preset behavior operations or adjust the device environment to preset parameters to simulate various behavior data and device environments that may occur during the process of voice and video communication.

[0056] During the process of the test users conducting voice and video communication, the real-time audio system obtains the user's behavior data and the internal environment data of the device during the real-time audio data transmission by reading the working logs of the logged-in device. Then, after performing preprocessing operations such as data cleaning and data aggregation on the behavior data and environment data, key indicators reflecting the characteristics of the user's behavior and device environment are extracted, such as the user's operation frequency, volume distribution, average CPU occupancy, etc. Then, based on the key indicators, key features reflecting the user's normal operation state are generated. Then, clustering algorithms (such as K-means, DBSCAN, etc.) are used to group the user behavior characteristics to determine the behavior patterns of different user groups. By analyzing the characteristics of each cluster, typical user behavior characteristics and environment characteristics are obtained, such as the user will not turn on the external screen recording function during a video call; the system resource occupancy of the user is generally relatively stable during the call, and there will be no frequent soaring of the CPU or memory usage rate; the user's terminal device generally will not automatically connect to strange external hardware or network storage devices during the call, etc., which is not limited here.

[0057] S202. Establish a feature set of normal behaviors and device environments based on normal behavior characteristics and device environment characteristics.

[0058] By analyzing the characteristics of each cluster, the real-time audio system obtains typical user behavior characteristics and environment characteristics, extracts the common characteristics among them, and forms a feature set describing the conventional usage pattern. For example, in one embodiment, the system detects that the vast majority of test users do not actively turn on the screen recording software during a video call. Even if a few people have a need for screen recording, they will inform the other party in advance and obtain consent. Therefore, "whether to turn on the screen recording" is regarded as a feature of the user's normal behavior by the device and incorporated into the feature set. Similarly, by comparing and analyzing the resource occupancy of the CPU, memory, etc. when the test users log in to the device, it is detected that the system overhead of the terminal usually remains stable during a video call, and there is rarely a sudden spike in the resource usage rate. Thus, "whether the system resource occupancy is stable" can be extracted as one of the features for judging the normal environment of the logged-in device. Similarly, other normal behavior characteristics or device environment characteristics in the feature set can be obtained, which will not be elaborated here.

[0059] In the above embodiment, the real-time audio system collects the behavior data and device environment parameters of test users during use, and through behavior recognition and anomaly detection algorithms, establishes a feature set reflecting the normal use state, which can more accurately depict normal behaviors and improve the accuracy of anomaly judgment.

[0060] S203. Authenticate the user through the user account and biometric technology.

[0061] Account password verification, as a traditional identity authentication method, has the advantages of simple implementation and easy use. Users only need to provide the account name and password to quickly log in to the system. This application introduces biometric technology as an auxiliary verification means on the basis of account password verification. Including but not limited to fingerprints, irises, voiceprints, faces, etc., to improve the security level of identity authentication.

[0062] S204. In response to the opening of the environmental detection permission, perform environmental detection on the logged-in device.

[0063] In response to the user authorizing the real-time audio system to obtain the environmental detection permission of the logged-in device, the system collects various parameters of the software and hardware environment of the logged-in device, including but not limited to the unique identifier of the device (such as IMEI, MAC address, device serial number, etc.), the installation and running status of security protection software (such as antivirus software), the connection status of external devices (such as cameras, microphones, etc.), and the running status of background programs, etc., which are not limited here.

[0064] S205. Whether the behavior characteristics and device environment characteristics both conform to the feature set.

[0065] This step is the same as step S104 and will not be elaborated here.

[0066] S206. Establish the correspondence between identity authentication and identification information.

[0067] This step is the same as step S105 and will not be elaborated here.

[0068] S207. Obtain the authorized users set by the administrator and one or more identification information corresponding to each authorized user.

[0069] The real-time audio system introduces a centralized control mechanism for the system user permissions by the administrator. In addition to binding the user identity authentication with the logged-in device when the user logs in, the real-time audio system can also directly set by the administrator in the system background interface which user accounts are granted the permission to use the system, and the device identification information that each authorized user account is allowed to use when logging in. The device identification information here can include the unique hardware serial number of the device, MAC address, IMEI, etc. that can be used to uniquely identify a device.

[0070] S208. Update the correspondence between identity authentication and identification information based on one or more identification information corresponding to each authorized user.

[0071] After obtaining the authorization relationship between the accounts and device identifications set by the administrator, the real-time audio system synchronizes this information to the identity authentication module to update the original account and device binding relationship.

[0072] Specifically, the system will map each authorized account to one or more device identifications specified by the administrator. In this way, when the user logs in, the system will not only verify the correctness of the account password but also check whether the hardware identification of the currently logged-in device is the authorized device of this account. Once it is found that the account and the device do not match, even if the account password verification passes, the system will determine that there is a risk of account theft and give a timely warning.

[0073] In the above embodiment, the real-time audio system introduces the setting of the authorized users and their corresponding device identifications by the administrator, enabling the mapping relationship between identity authentication and device identification to be flexibly adjusted. This not only allows a user to log in on multiple authorized devices but also can timely remove the login permission of the departing personnel, further improving the identity permission management mechanism and reducing the risk of internal personnel leaking secrets.

[0074] S209. Calculate the comprehensive risk score based on the user's behavior characteristics and device environment characteristics.

[0075] Among them, the comprehensive risk score calculation formula is as follows: Score = ∑α × i + ∑β × j; Among them, Score is the comprehensive risk score, α represents the degree of abnormality of the α-th user behavior feature (the value range can be from 0 to 10 points, and the higher the score, the more abnormal the behavior), i is the weight coefficient corresponding to α, β is the degree of abnormality of the β-th device environment feature (the value range can be from 0 to 10 points, and the higher the score, the higher the device environment risk), and j is the weight coefficient corresponding to β.

[0076] For example, in a specific embodiment, the system can set a threshold for the comprehensive risk score (such as 60 points). When the comprehensive risk score of the user exceeds this threshold, it is considered that there is a relatively large abnormal risk in the current session, and a more stringent identity verification process needs to be initiated.

[0077] It is known that the user initiates a login at 6 pm (non-working hours), and the risk sub-score of the behavior feature = 5 points; the user initiates a login at the registered address, and the risk sub-score of the behavior feature = 0 points; the user logs in using an old mobile phone that is 2 years old, and the risk sub-score of the device environment feature = 8 points; the user's mobile phone operating system is the latest version, and the risk sub-score of the device environment feature = 1 point; the weight coefficient for abnormal login time = 0.1; the weight coefficient for abnormal login location = 0.3; the weight coefficient for old device model = 0.2; the weight coefficient for operating system vulnerabilities = 0.4; Then the comprehensive risk score for this user's login is: Comprehensive risk score = (5 * 0.1 + 0 * 0.3) + (8 * 0.2 + 1 * 0.4) = 2.5. Since 2.5 points is much lower than the system-set threshold of 60 points, although the user uses an older mobile phone, the system still determines that the risk level of this login is relatively low and no additional identity verification is required.

[0078] S210. Adjust the verification level of the identity authentication process according to the comprehensive risk score.

[0079] When the comprehensive risk score of the user's current login is relatively high (such as exceeding 80 points), the real-time audio system automatically enables more stringent identity verification means, such as requiring the user to perform secondary verification, providing additional biometric features (such as face, fingerprint, etc.), or answering some preset security questions. Only after passing these additional verifications can the user finally log in to the system.

[0080] When the comprehensive risk score of the user is relatively low (such as below 20 points), the real-time audio system will correspondingly reduce the complexity of the identity authentication and simplify the login process. For example, it can reduce the required verification elements, extend the session holding time, and allow the user to resume the session across devices. This can maximize the user experience and save the time cost of normal users while ensuring security.

[0081] S211. When the user logs in and connects again, if it is detected that the identity authentication does not match the identification information, a security warning for information leakage is issued.

[0082] After the user successfully logs in to the real-time audio system for the first time, the system binds the user's identity authentication credentials (such as account password) to the identification of the current login device. When the user logs in next time, the system will first verify whether the account password entered by the user is correct according to the regular identity authentication process. However, at the same time, the system will also compare whether the hardware identification of the current login device is a device authorized for this account. Once the comparison result shows a mismatch, even if the account password verification passes, the system will immediately determine that there is an abnormal risk in the current session and issue a security warning for information leakage.

[0083] S212. If it is detected that the number of times of user identity verification failures exceeds the preset quantity threshold, the system obtains the user's face information through the camera for manual identification.

[0084] In the real-time audio system, the user authenticates their identity through biometric features such as account password, fingerprint, and voiceprint. However, biometric identification is not 100% accurate and sometimes verification fails due to environmental noise, dry fingers, etc. To improve the usability of the system while ensuring security, the real-time audio system sets a tolerance threshold for the number of identity verification failures. After authenticating the user through the user account and biometric technology in step S203, when it is detected that the number of verification failures of the same user exceeds this threshold (such as 5 consecutive times), the system obtains the user's face information through the camera and sends it to the back-end staff for manual identification.

[0085] In the above embodiment, after the real-time audio system detects that the user has failed verification multiple times, it captures the user's face through the camera and hands it over to the administrator for manual review. This avoids denial of service caused by unstable biometric features and improves the reliability of identity authentication.

[0086] S213. Output the abnormal behavior feature sequence or abnormal environment feature sequence.

[0087] After the judgment in step S104 on whether both the behavior features and the device environment features conform to the feature set, if it is detected that either the user's behavior features or the device environment features conform to the feature set, the abnormal behavior feature sequence or abnormal environment feature sequence is output.

[0088] Specifically, when the system detects abnormal operation behaviors of the user (such as sensitive actions like screen recording, screenshot taking, copying, etc.), the system captures this series of suspicious operations in real time and generates a time series reflecting the abnormal behaviors of the user. For example, "The screen recording software was started at 15:32:08 on September 23, 2022, the screen image was captured at 15:33:15 on September 23, 2022, and the file was transferred to an external device at 15:35:41 on September 23, 2022".

[0089] Similarly, when the system detects that the operating environment of the user device does not conform to the security policy (such as malware, external hardware, abnormal traffic, etc.), the system also collects relevant data in real time and generates a sequence of abnormal environment characteristics. For example, "Trojan virus activity was detected at 15:30:11 on September 23, 2022, the contacts in the address book were read at 15:34:25 on September 23, 2022, and a suspicious WIFI hotspot was connected at 15:36:09 on September 23, 2022", etc., which is not limited here.

[0090] In the above embodiment, the real-time audio system can output the abnormal feature sequence when detecting abnormal user behaviors or device environments, providing more detailed information for abnormal situations and facilitating users to make adaptive adjustments based on the abnormal situations.

[0091] S214. Obtain the permission list of each user account.

[0092] After establishing the correspondence between identity authentication and identification information in step S206, the system reads the pre-configured account-permission mapping relationship table from the permission management database, and lists the function modules, data resources, and corresponding operation permissions that each user account can access for subsequent operation permission configuration.

[0093] S215. Set the operation permissions of each user account according to the permission list.

[0094] After obtaining the permission list of each user account, the real-time audio system sets the operation permissions of each user according to the permission list, ensuring that the user can only perform operations within the permissions and cannot access unauthorized sensitive data or functions. For example, if a user does not have the permission to record the screen, then this user cannot record the screen after logging in to the real-time audio system. If an external screen recording software is used, it will be determined as an abnormal behavior and a security warning for information leakage will be issued.

[0095] In the above embodiment, the real-time audio system sets the corresponding operation permissions according to the permission level of the user account. Data with different security levels corresponds to different user permissions, and sensitive data is only open to accounts with high permissions. Through permission constraints, the scope of users' access to sensitive data can be minimized, reducing the risk of internal personnel leaking secrets.

[0096] The real-time audio system according to an embodiment of the present invention is applied to an electronic device. Figure 3 The schematic architecture diagram of the electronic device suitable for implementing the embodiment of the present invention is shown.

[0097] It should be noted that Figure 3 The shown electronic device is only an example and should not impose any limitation on the functions and usage scope of the embodiment of the present invention.

[0098] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructions (computer programs), or the relevant hardware can be controlled by instructions (computer programs). The instructions can be stored in a computer-readable storage medium and loaded and executed by a processor. The electronic device of this embodiment includes a storage medium and a processor. Among them, multiple instructions are stored in the storage medium, and the instructions can be loaded by the processor to execute any step of the method provided by the embodiment of the present invention.

[0099] Specifically, the storage medium and the processor are directly or indirectly electrically connected to achieve data transmission or interaction. For example, these components can be electrically connected to each other through one or more signal lines. The computer execution instructions for implementing the data access control method are stored in the storage medium, including at least one software function module that can be stored in the storage medium in the form of software or firmware. The processor executes various functional applications and data processing by running the software programs and modules stored in the storage medium. The storage medium can be, but is not limited to, a random access storage medium (Random Access Memory, abbreviated as RAM), a read-only storage medium (Read Only Memory, abbreviated as ROM), a programmable read-only storage medium (Programmable Read-Only Memory, abbreviated as PROM), an erasable read-only storage medium (Erasable Programmable Read-Only Memory, abbreviated as EPROM), an electrically erasable read-only storage medium (Electric Erasable Programmable Read-Only Memory, abbreviated as EEPROM), etc. Among them, the storage medium is used to store programs, and the processor executes the programs after receiving the execution instructions.

[0100] Furthermore, the software programs and modules in the above storage medium may also include an operating system, which may include various software components and / or drivers for managing system tasks (such as memory management, storage device control, power management, etc.), and may communicate with various hardware or software components to provide a running environment for other software components. The processor may be an integrated circuit chip with signal processing capabilities. The above-mentioned processor may be a general-purpose processor, including a central processing unit (Central Processing Unit, abbreviated as CPU), a network processor (Network Processor, abbreviated as NP), etc., which can implement or execute the various methods, steps, and logic flow block diagrams disclosed in this embodiment. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0101] Since the instructions stored in this storage medium can execute the steps in any of the methods provided by the embodiments of the present invention, the beneficial effects of any of the methods provided by the embodiments of the present invention can be achieved. For details, please refer to the previous embodiments and will not be repeated here.

[0102] The above is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A multi-layer secure real-time audio and video method, applied to a real-time audio system, characterized in that: The method comprises: Obtain a feature set of the user's normal behavior and device environment, wherein the feature set includes the behavior features and device environment features of the user in a normal process of using the login device for real-time audio in multiple scenarios; After detecting that the user has passed the identity authentication, a request instruction for obtaining the environment detection permission is sent to the login device participating in the real-time audio and video; In response to enabling the permission to obtain environment detection, obtaining identification information of the login device; During the user's use, real-time monitoring is performed to determine whether the user's behavior characteristics and device environment characteristics conform to the characteristic set; If not, a security warning of information leakage will be issued; If so, a corresponding relationship between the identity authentication and the identification information is established to simplify the identity authentication process for the user with the corresponding relationship, the identity authentication process including a plurality of different identity authentication steps; When the user logs in again, if it is detected that the identity authentication does not match the identification information, an information leakage security warning is issued.

2. The method according to claim 1, characterized in that When the user logs in again, if it is detected that the identity authentication does not match the identification information, before the step of issuing an information leakage security warning, the method further includes: Obtain the authorized users set by the administrator and one or more identification information corresponding to each authorized user; The correspondence between the identity authentication and the identification information is updated based on the one or more identification information corresponding to each authorized user.

3. The method according to claim 1, characterized in that After the step of monitoring in real time during the user's use whether the user's behavior characteristics and device environment characteristics are consistent with the feature set, the method further includes: If it is detected that the behavior characteristics of the user do not conform to the characteristic set, an abnormal behavior characteristic sequence is output; If the monitored device environment characteristics of the user do not conform to the characteristic set, an abnormal environment characteristic sequence is output.

4. The method according to claim 1, characterized in that Before the step of obtaining the feature set of the user's normal behavior and the device environment, the method further includes: Collecting test data of multiple test users, wherein the test data includes behavior data parameters and device environment parameters; Performing behavior recognition and anomaly detection on the test data to determine normal behavior characteristics and device environment characteristics of the user in the process of connecting to real-time audio and video; A feature set of normal behavior and device environment is established based on the normal behavior features and device environment features.

5. The method according to claim 1, characterized in that After the step of establishing the corresponding relationship between the identity authentication and the identification information, the method further includes: Calculate a comprehensive risk score based on the user's behavioral characteristics and device environment characteristics; The verification level of the identity authentication process is adjusted according to the comprehensive risk score, and the verification level is proportional to the comprehensive risk score.

6. The method according to claim 1, characterized in that Before the step of sending a request instruction for obtaining environment detection authority to a login device participating in real-time audio and video after detecting that the user has passed identity authentication, the step further includes: Authenticate users through user accounts and biometrics; If it is detected that the number of times the user's identity authentication fails exceeds a preset threshold, the user's facial information is obtained through a camera for manual recognition.

7. The method according to claim 1, characterized in that After the step of establishing the corresponding relationship between the identity authentication and the identification information, the method further includes: Get a list of permissions for each user account; The operation permissions of each user account are set according to the permission list.

8. A real-time audio system, characterized in that: The real-time audio system includes: one or more processors and memory; The memory is coupled to the one or more processors, and the memory is used to store computer program codes, wherein the computer program codes include computer instructions, and the one or more processors call the computer instructions to enable the real-time audio system to perform the method according to any one of claims 1 to 7.

9. A computer-readable storage medium comprising instructions, characterized in that: When the instructions are executed on a real-time audio system, the real-time audio system is caused to execute the method according to any one of claims 1 to 7.

10. A computer program product, characterized in that When the computer program product is run on a real-time audio system, the real-time audio system is caused to perform the method according to any one of claims 1 to 7.