Efficient video transmission and request security aggregation method based on forwarding cache table
By building cache forwarding tables in the router, optimizing data cache and forwarding decisions, combining intelligent detection and signature mechanisms, the router's efficiency and security problems under high concurrency and security threats are solved, and efficient video transmission and secure aggregation is achieved.
Patent Information
- Application Number
- CN202510417792.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-03
- Publication Date
- 2025-07-08
AI Technical Summary
When existing routers face high concurrent traffic and complex security threats, it is difficult for them to optimize transmission paths, resulting in a decline in user experience, repeated transmission increases the burden on the network, and traditional protection measures are inefficient in DDoS attacks.
Build a cache forwarding table in the router, optimize data cache and forwarding decisions through the request aggregation mechanism, integrate intelligent detection modules to identify and filter malicious traffic, and combine the signature mechanism to ensure data transmission security.
Effectively reduce duplicate transmission traffic by 65%, improve video transmission efficiency by 30%-40%, save bandwidth by 45%, block abnormal traffic by 95% during DDoS attacks, ensuring data integrity and confidentiality.
Smart Images

Figure CN120281531A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an efficient video transmission and request security aggregation method based on a forwarding cache table, belonging to the field of network transmission in computer networks. Background Art
[0002] With the rapid development of the Internet, in the current network environment, routers are facing major challenges: with the popularization of 4K / 8K video streams, real-time interactive applications, and a large number of Internet of Things devices, data traffic has shown an explosive growth; in the face of high-concurrency traffic, a single core router needs to process millions of QPS requests, and the fixed rule forwarding mechanism is difficult to cope with dynamic loads; in the face of complex security threats, traditional IP blacklist-based protection schemes are prone to failure. In these complex scenarios, the design of traditional routers has gradually revealed deficiencies and is difficult to meet the high efficiency and security requirements of modern networks. The deficiencies of the current technology are as follows:
[0003] (1) In terms of performance, traditional routers rely on fixed forwarding rules, and the request processing mechanism is rigid. It is difficult to adjust data transmission strategies according to dynamic network conditions (such as bandwidth fluctuations and latency changes). In high-concurrency or network congestion scenarios, it is impossible to effectively optimize the transmission path, resulting in a decline in user experience.
[0004] (2) In terms of network security, existing protection measures mainly adopt a centralized protection architecture, and its core protection measures are mostly deployed on the server side. This architecture has significant defects in the face of large-scale DDoS attacks and is difficult to solve the network link congestion problem; secondly, when the server side faces pulse attacks with dynamic traffic characteristics, it will occupy a large amount of computing resources of the host and affect the normal business performance.
[0005] (3) In terms of bandwidth, the existing router architecture lacks an efficient caching mechanism in content distribution. When distributing popular videos, the proportion of requests for the same content exceeds 65%, but the existing solutions cannot effectively utilize router caches. This repeated transmission not only increases the burden on the network but also significantly reduces the data transmission efficiency, especially in high-bandwidth demand scenarios such as video streaming or large file distribution, which is particularly prominent. In addition, with the growth of Internet of Things devices and content distribution requirements, this architecture defect may be further amplified and become the main obstacle to network performance optimization.
[0006] In summary, there is currently a lack of a routing table mechanism in the field of network transmission that can combine content caching and dynamic forwarding. The present invention proposes a method for constructing and using a cache forwarding table, realizing the efficient transmission of video content and the secure aggregation of network requests, and providing new technical support for efficient data services and security guarantees in complex network environments. Summary of the Invention
[0007] To solve the problems of "resource waste caused by repeated requests" and "inability to effectively defend against DDoS attacks" in the existing technology for network video transmission, the purpose of the present invention is to provide an efficient video transmission and request security aggregation method based on a forwarding cache table. This method constructs a cache forwarding table in the router to optimize data caching and forwarding decisions, reduce bandwidth waste caused by repeated requests, and improve data transmission efficiency at the same time. For high-concurrency request scenarios, the cache forwarding table effectively alleviates network congestion through a request aggregation mechanism. For the threat of malicious traffic, the cache forwarding table integrates an intelligent detection module, and identifies and filters attack traffic through the cache forwarding table to ensure the stability and security of network resources.
[0008] To achieve the above object, the technical solution of the present invention is as follows:
[0009] An efficient video transmission and request security aggregation method based on a forwarding cache table disclosed by the present invention. The router detects and processes user requests to generate a standardized request packet; the host responds to the request and securely signs the data packet; a cache forwarding table is constructed in the router to optimize data caching and forwarding decisions, reduce bandwidth waste caused by repeated requests, and improve data transmission efficiency at the same time. For high-concurrency request scenarios, the cache forwarding table effectively alleviates network congestion through a request aggregation mechanism. For the threat of malicious traffic, the cache forwarding table integrates an intelligent detection module, and the router periodically executes an intelligent cache replacement decision, identifies and filters attack traffic through the cache forwarding table to ensure the stability and security of network resources; that is, efficient video transmission and security aggregation are achieved based on the cache forwarding table.
[0010] An efficient video transmission and request security aggregation method based on a forwarding cache table disclosed by the present invention includes the following steps:
[0011] Step 1: The router detects and processes user requests to generate a standardized request packet;
[0012] Sub-step 1.1: The router receives a user request packet, performs a security check, and checks for requests with abnormal formats. If an abnormality is detected, the request is discarded; if no abnormality is detected, sub-step 1.2 is executed;
[0013] Sub-step 1.2: Parse the user request packet and generate a content identifier C R , C R includes a video identifier, a shard index, and a bitrate level; query the cache table. If the cache corresponding to C R is found, directly respond to the user request; if not found, continue with sub-step 1.3;
[0014] Sub-step 1.3: Fill C R into the router's forwarding table in the format of a standardized aggregated request packet H R ; HR Contains the hashed content identifier C R , the requester IP list and version requirements; fill in C R When filling in C R already exists in the forwarding table, fill the source IP of the request into the requester IP list, otherwise create a new H R table entry;
[0015] Sub-step 1.4: The router creates a new H R After the table entry, forward the content identifier C to the host R , and request the corresponding video content;
[0016] Step 2: The host responds to the request and securely signs the data packet;
[0017] Sub-step 2.1: The host responds to the request, generates video frame data D and encrypts and signs it. The video frames can be divided into I-frames, P-frames, and B-frames;
[0018] For I-frame data, first encrypt it using the AES algorithm, and then use the RSA-3072 full-frame signature method S I = Sign RSA (H(D I )) to sign it, and this signature satisfies the security condition P right [S I mod n = H(D I )] ≥ 1 - negl(k);
[0019] For P-frame or B-frame data, do not encrypt it, and directly use the lightweight HMAC signature S P,B = HMAC(D P,B , K session ) method to sign it, where K session is the session key;
[0020] Sub-step 2.2: The host constructs a signed data packet D sig = (D, S, T resp , V), where D ∈ {D I , D P , D B}, S ∈ {S I , S P , S B}, T resp is the timestamp, and V is the version number; send D sig to the router, and the transmission process needs to carry C R for route matching;
[0021] Step 3: Router forwarding and intelligent caching;
[0022] Sub-step 3.1: The router verifies the security of D. sig For I-frames, the router requests the public key from the host and uses the public key (e, n) to decrypt and verify the security of the authentication packet. For P / B-frames, the session key K is used to session recalculate the HMAC-SHA256 signature to verify the data security. If the packet verification fails, the packet is discarded and a request is sent to the host again. If the verification is successful, proceed to Sub-step 3.2.
[0023] Sub-step 3.2: According to the list of requester IPs in H, send the packet D to all requesting users. R After completion of the forwarding, delete H. sig R
[0024] Sub-step 3.3: The router caches the packet using a probabilistic caching strategy. For each packet D, sig generate a random number r ∈ (0, 1). When the random number r ≤ p, cache the (C, D, T) triple in the cache table, where p is related to the frame type of the packet, i.e., p ∈ {p R , p resp , p I , p P , p B}}.
[0025] Step 4: The router periodically executes intelligent cache replacement decisions.
[0026] Sub-step 4.1: The router calculates the basic popularity of all packets D in the cache table respectively. sig
[0027]
[0028] Among them, REQ(D) represents the number of requests for packet D received by the router within the time interval T m , and REQ total represents the total number of requests received by the router within the time interval T m .
[0029] To prevent the impact of sudden growth of data requests at a certain moment on data popularity, the exponential weighted moving average EWMA of the popularity sample is used for the basic popularity to obtain the weighted average popularity P m (D):
[0030]
[0031] Among them, α is a preset coefficient, and the value of the coefficient α ranges from 0.1 to 0.3.
[0032] Sub-step 4.2: When the utilization rate of the router cache space exceeds the threshold θ ∈ (85%, 95%), sort according to the weighted average popularity and preferentially eliminate the packets with the lowest popularity.
[0033] Step 5: The client verifies and decrypts the data.
[0034] Sub-step 5.1: When the client receives an I-frame packet, calculate Hash(D I )′ = S e mod n, and compare Hash(D I )′ with Hash(D I ). If the two are equal, the security verification passes, extract the data D I , and request the key from the host to decrypt the data; if the verification fails, mark it as an illegal packet and delete it.
[0035] Sub-step 5.2: When the client receives P-frame and B-frame packets, use the session key K session to recalculate HMAC-SHA256 for the received packet D P,B to obtain the signature S′, and compare S′ with S. If the two are equal, it means the data has not been tampered with, otherwise mark it as an illegal packet and delete it.
[0036] So far, according to Steps 1 to 5, an efficient and secure video transmission is achieved between the user and the host.
[0037] Beneficial effects
[0038] The efficient video transmission and request security aggregation method based on the forwarding cache table proposed by the present invention has the following beneficial effects compared with the existing technical solutions:
[0039] 1. An efficient video transmission and request security aggregation method based on the forwarding cache table disclosed by the present invention can aggregate requests for the same data by deploying a forwarding cache table in the router, reduce the repeated transmission traffic by about 65%, improve the overall video transmission efficiency by 30% - 40%, and save more than 45% of the core link bandwidth consumption at the same time.
[0040] 2. An efficient video transmission and request security aggregation method based on the forwarding cache table disclosed by the present invention can effectively identify and filter malicious requests through the request aggregation mechanism and the two-level detection strategy for abnormal traffic. When dealing with large-scale DDoS attacks, the system can block more than 95% of the abnormal traffic and shorten the service interruption time caused by the attack to 12% of the original level, significantly improving the network anti-attack ability.
[0041] 3. An efficient video transmission and request security aggregation method based on a forwarding cache table disclosed by the present invention realizes end-to-end data anti-tampering through a signature mechanism. At the same time, by encrypting I-frames, the risk of data leakage is effectively prevented. While maintaining the transmission efficiency, this mechanism ensures that the integrity and confidentiality of key frame data meet the security requirements of the ISO / IEC 23001-7 standard. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 It is a schematic diagram of the overall system architecture and data flow of the efficient video transmission and request security aggregation method based on a forwarding cache table of the present invention.
[0043] Figure 2 It is a detailed diagram of the request aggregation and DDoS protection module of the efficient video transmission and request security aggregation method based on a forwarding cache table of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0044] The present invention will be described in detail below in conjunction with the drawings and embodiments, and at the same time, the technical problems solved by the technical solution of the present invention and the beneficial effects will be discussed. It should be noted that the described embodiments are only for facilitating the understanding of the present invention and do not impose any limitation on the present invention.
[0045] Embodiment 1
[0046] This embodiment discusses the application of the efficient video transmission and request security aggregation method based on a forwarding cache table in video encrypted transmission.
[0047] This embodiment requires that there should be a host acting as a video server in the system, providing the function of separating and outputting I / P / B frames; a core router, deploying a forwarding cache table module; several independent clients, installing a dedicated video player, supporting RSA-3072 decryption and HMAC verification; an attack simulator, deployed in an independent network segment, generating DDoS attack traffic and abnormal requests. In this embodiment, the user requests video data from the host.
[0048] As Figure 1 shown, an efficient video transmission and request security aggregation method based on a forwarding cache table disclosed in this embodiment is specifically implemented as follows:
[0049] Step I. The router detects and processes the user request, generating a standardized request packet, which specifically includes the following sub-steps:
[0050] Step I.1 After receiving the request packet, the router checks for requests with abnormal formats. If an abnormality is detected, it discards the packet and triggers an alarm.
[0051] Step I.2 The router parses the video identifier, fragment index, and bitrate level parameters in the user request packet to generate a content identifier CR = SHA256(f"{video_id}|{fragment_idx}|{resolution}".encode()).hexdigest().
[0052] The router queries the cache table entry. When there is a cache entry that meets the version requirements, it directly responds to the request.
[0053] Step I.3 The router sends C R Fill in the router's forwarding table according to the format of the standardized aggregation request packet H R ; The structure of the forwarding table is shown in Table 1: including the hashed content identifier C R , the list of requester IPs, and the version requirements
[0054] Field Name Data Type Description CR BINARY(64) Primary key, content identifier hash value IP_List INET_ARRAY Dynamic array, stores the requester's IP address Version INT Minimum version requirement (default = 1)
[0055] Table 1 Forwarding table format
[0056] When filling in C R , if C R already exists in the forwarding table, append the source IP of the request to the IP_List field; otherwise, create a new H R table entry and initialize IP_List as a single-element array.
[0057] After creating a new forwarding table entry, the router sends a standardized request message to the video server through the Backend Interface, and the format conforms to the IETF draft draft-httpbis-semantics-latest specification.
[0058] Step II. The host responds to the request and securely signs the data packet, which specifically includes the following sub-steps:
[0059] Step II.1 The host responds to the request, generates video frame data D, and performs frame processing according to the policy in Table 2:
[0060] Frame Type Encryption Method Signature Algorithm Security Attribute I Frame AES-256-GCM RSA-3072 full-frame signature Confidentiality, Integrity, Anti-replay P Frame, B Frame No Encryption HMAC-SHA256 lightweight signature Integrity, Source Authentication
[0061] Table 2 Video frame processing method
[0062] Step II.2 The host constructs a signed data packet D sig , and the data packet encapsulation format is as follows:
[0063] Field Length (bytes) Description Header 8 Magic number 0x46574352 ("FWCR") C_R 32 Content identifier in binary form D Variable Select encryption / plaintext format according to frame type S 384 (RSA) / 32 (HMAC) Signature Data T_resp 8 IEEE 1588v2 Precision Time Protocol V 2 Version number (big endian)
[0064] Table 3 Data packet encapsulation format
[0065] Step II.3 When the video frame data is updated, the host generates an encryption invalidation instruction BroadcastMsg = AESEncrypt ("INVALIDATE", V old ,K group ). Where V old is the invalid version number, K group This command completes the cache synchronization of the entire network within 200ms through the PIM-SSM protocol to ensure version consistency.
[0066] Step III: Router intelligent cache decision and forwarding, specifically including the following sub-steps:
[0067] Step III.1 The router performs signature verification on the data packet. The exception handling strategy is shown in the following table:
[0068] Error Type Processing Action Log Code Signature Mismatch Discard the packet, send a NAK retransmission request SEC_ERR_101 Version Inconsistency Clear the local cache, initiate a full request CACHE_ERR_201
[0069] Table 4 Exception handling strategy
[0070] Step III.2 Send the signed data packet D to all requesting users according to the requester IP list in the forwarding table sig , delete H after completing the forwarding R .
[0071] Step III.3 The router defines the cache probability function:
[0072]
[0073] For each data packet D, generate a random number r∈(0,1), when r≤p, (C R ,D,T resp )Triple cache and cache table.
[0074] Step IV: The router periodically executes the intelligent cache replacement decision, which specifically includes the following sub-steps:
[0075] Step IV.1 The router is based on the time window T m = 60s, maintain the cache table for all packets D in the cache table. The structure of the cache table is shown in Table 1: including packet name, version number, number of requests, and weighted average popularity. Among them, the weighted average popularity of the packet is calculated according to Formula 2 (α = 0.3). When the router decides to cache a packet, it stores the packet in the cache and creates a new table entry.
[0076] Packet Name Version Number Request Count Weighted Average Popularity / web / videos / I-frame / c version[3] 10 0.8 / web / videos / P-frame / e version[1] 4 0.4 / web / videos / E-frame / g version[1] 2 0.2
[0077] Table 5 Cache table structure
[0078] Step IV.2 When the utilization rate of the router's cache space exceeds the threshold θ = 90%, packets with the lowest popularity are preferentially eliminated according to the weighted average popularity ranking.
[0079] Step V. The client verifies and decrypts the data, which specifically includes the following sub-steps:
[0080] Step V.1 Perform signature verification and decryption on I frames: The client calculates and compares it with the local hash H(D I ). If the verification passes, request K AES from the key management server through the KMIP protocol and execute decryption D′ I = AES-GCM-Decrypt(D I , K AES , IV); if the verification fails, record the security event and discard the packet, and at the same time send a security alert to the router and request the packet again.
[0081] Step V.2 Verify the integrity of P / B frames, and recalculate HMAC using the session key K session :
[0082] S′ P,B = HMAC-SHA256(D P,B K session )
[0083] If S′ P,B = S P,B , the verification passes; if S′ P,B ≠ S P,B , record the security event and discard the packet, and at the same time send a security alert to the router and request the packet again.
[0084] So far, the efficient video transmission and request security aggregation method based on the forwarding cache table ends.
[0085] An efficient video transmission and request security aggregation method based on the forwarding cache table disclosed in this embodiment aggregates requests for the same data by deploying a forwarding cache table in the router, reducing the backbone network traffic by 47.3%, improving the overall transmission efficiency, and achieving a blocking rate of 97.3% for DDOS attacks.
[0086] The above specific description further details the purpose, technical solution, and beneficial effects of the invention. It should be understood that the above is only a specific embodiment of the present invention and is not used to limit the protection scope of the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention should be included in the protection scope of the present invention.
Claims
1. An efficient video transmission and request security aggregation method based on a cache forwarding table, characterized in that: The router detects and processes user requests, generating standardized request packets; the host responds to the requests and securely signs the data packets; a cache forwarding table is constructed in the router to optimize data caching and forwarding decisions, reduce bandwidth waste caused by repeated requests, and improve data transmission efficiency at the same time; for high-concurrency request scenarios, the cache forwarding table effectively alleviates network congestion through a request aggregation mechanism; for the threat of malicious traffic, the cache forwarding table integrates an intelligent detection module, and the router periodically executes intelligent cache replacement decisions to identify and filter attack traffic through the cache forwarding table, ensuring the stability and security of network resources; the user side verifies and decrypts the data, that is, realizes efficient video transmission and secure aggregation based on the cache forwarding table.
2. An efficient video transmission and request security aggregation method based on a cache forwarding table according to claim 1, characterized in that: including the following steps, Step 1, the router detects and processes user requests, generating standardized request packets; Sub-step 1.1, the router receives the user request packet, performs security detection, and checks for requests with abnormal formats; If an abnormality is detected, the request is discarded; if no abnormality is detected, sub-step 1.2 is executed; Sub-step 1.2: Parse the user request packet and generate a content identifier C R , C R includes a video identifier, a shard index, and a bitrate level; query the cache table, if the cache corresponding to C R is found, directly respond to the user request; if not found, continue with sub-step 1.3; Sub-step 1.3: Place C R into the forwarding table of the router in the format of the standardized aggregation request packet H R ; H R contains the hashed content identifier C R , the list of requester IPs and the version requirements; when placing C R , first check the existing H R entries. If there is a duplicate request, add the requester IP to the list; if there is no duplicate, create a new H R entry. Sub-step 1.4: After the router establishes a new H R entry, it forwards the content identifier C R to the host to request the corresponding video content; Step 2, the host responds to the request and securely signs the data packet; Step 3, the router forwards and intelligently caches; Step 4, the router periodically executes intelligent cache replacement decisions; Step 5, the user side verifies and decrypts the data; Thus, efficient and secure video transmission between the user and the host is realized based on Steps 1 to 5.
3. An efficient video transmission and request security aggregation method based on a cache forwarding table according to claim 2, characterized in that: The implementation method of Step 2 is, Sub-step 2.1, the host responds to the request, generates video frame data D and encrypts and signs it. The video frames can be divided into I frames, P frames, and B frames; For I-frame data, first, it is encrypted using the AES algorithm, and then the RSA-3072 full-frame signature method S I = Sign RSA (Hash(D I )) is used to sign it, and this signature satisfies the security condition P right [S i mod n = Hash(D I )] ≥ 1 - negl(k); For P-frame or B-frame data, no encryption is performed, and the lightweight HMAC signature S P,B = HMAC(D P,B , K session ) method is used for signing, where K session is the session key; Sub-step 2.2, Main Structure Signature Data Packet D sig =(D, S, T resp , V), where D ∈ {D I , D P , D B}}, S ∈ {S I , S P , S B}}, T resp is a timestamp, and V is a version number; Send D sig to the router, and C R should be carried during the transmission for routing matching.
4. The efficient video transmission and request security aggregation method based on a cache forwarding table according to claim 3, wherein: The implementation method of Step 3 is, Sub-step 3.1: The router verifies D sig security; for I-frames, the router requests the public key from the host and uses the public key (e, n) to decrypt and verify the security of the verification packet; for P / B-frames, the session key K session is used to recalculate the HMAC-SHA256 signature to verify the data security; if the packet verification fails, the packet is discarded and a request is sent to the host again; if the verification is successful, proceed to Sub-step 3.2; Sub-step 3.2: According to the list of requester IPs in H R send data packet D to all requesting users sig and delete H after forwarding is completed R ; Sub-step 3.3: The router caches data packets using a probabilistic caching strategy; for each data packet D sig , a random number r ∈ (0, 1) is generated. When the random number r ≤ p, the (C R , D, T resp ) triple is cached in the cache table, where p is related to the frame type of the data packet, i.e., p ∈ {p I , p P , p B}.
5. An efficient video transmission and request security aggregation method based on a cache forwarding table according to claim 4, characterized in that: The implementation method of Step 4 is, Sub-step 4.1: The router calculates the basic popularity of all the data packets D in the cache table respectively sig where REQ(D) represents the number of requests for packet D received by the router within the time interval T m and REQ total represents the total number of requests received by the router within the time interval T m ; To prevent the impact of a sudden increase in data requests at a certain moment on data popularity, the exponentially weighted moving average EWMA of the popularity samples is used for the basic popularity to obtain the weighted average popularity P m (D): where α is a preset coefficient; Sub-step 4.2, when the utilization rate of the router cache space exceeds the threshold θ ∈ (85%, 95%), according to the weighted average popularity ranking, the data packet with the lowest popularity is preferentially eliminated.
6. An efficient video transmission and request security aggregation method based on a cache forwarding table as claimed in claim 5, characterized in that: The implementation method of Step 5 is, Sub-step 5.1: When the client receives the I-frame data packet, calculate Hash(D I )′ = S e mod n, and compare Hash(D I )′ with Hash(D I ); if the two are equal, the security verification passes, extract the data D I , and request the key from the host to decrypt the data; if the verification fails, mark it as an illegal data packet and delete it; Sub-step 5.2: When the client receives P and B frame data packets, use the session key K session to recalculate HMAC-SHA256 for the received data packet D P,B to obtain the signature S'. Compare S' with S. If the two are equal, it indicates that the data has not been tampered with; otherwise, mark it as an illegal data packet and delete it.
7. An efficient video transmission and request security aggregation method based on a cache forwarding table according to claim 6, characterized in that: When the video frame data D described in step 2 is updated, the host generates an encryption invalidation instruction BroadcastMsg = AESEncrypt("INVALIDATE", V, K group ); where V is the updated version number, and K group is the multicast key.
8. The efficient video transmission and request security aggregation method based on a cache forwarding table according to claim 7, wherein: When the router receives the invalidation instruction, it clears the corresponding expired cache and forwards the invalidation instruction to adjacent nodes to achieve cascaded update.
9. The efficient video transmission and request security aggregation method based on a cache forwarding table according to claim 5, wherein: The value of the coefficient α ranges from 0.1 to 0.3.