Camera automatic networking method and system based on dynamic encryption identifier

Through the automatic networking method of cameras based on dynamic encryption identification, the problems of low device authentication efficiency, poor network adaptability and insufficient security are solved, and efficient and secure automatic networking and network resource optimization are achieved, which significantly reduces manual maintenance costs.

CN120342625APending Publication Date: 2025-07-18四川长虹新网科技有限责任公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510482399.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-17
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The existing camera networking technology has problems such as low equipment certification efficiency, poor dynamic network adaptability, insufficient security and high maintenance costs. It is especially difficult to achieve dynamic expansion and automated management when the number of equipment surges.

Method used

The camera automatic networking method based on dynamic encryption identification is adopted to generate encrypted data packets through device ID, timestamp and digital signature, and combine the two-factor verification mechanism of whitelist and hash value to realize rapid authentication of device identity and automatic networking. Through dynamic IP allocation and heartbeat packet monitoring, it supports large-scale concurrent access to devices and real-time updates of network topology.

Benefits of technology

It realizes efficient device identity authentication and automatic networking, reduces authentication delay, improves resource utilization and network stability, enhances security, and reduces manual maintenance costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342625A_ABST
    Figure CN120342625A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of camera networking, in particular to an automatic camera networking method and system based on a dynamic encryption identifier, and the method comprises the following steps: networking equipment generates a data packet; the networking equipment broadcasts the data packet; the gateway receives a data packet broadcasted by the networking device, performs identity verification on the networking device, and dynamically allocates an IP address to the networking device in the current subnet if the identity verification is passed; and the gateway generates an access token and feeds back the access token to the networking equipment. By adopting the scheme, the security of the networking system can be guaranteed while automatic networking is realized, and the manual maintenance cost is greatly reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of camera networking, and particularly to a method and system for automatic camera networking based on dynamic encryption identifiers. Background Art

[0002] With the rapid development of Internet of Things technology, intelligent cameras are increasingly widely used in fields such as security and smart cities. However, the existing camera networking technology still has the following problems:

[0003] Low device authentication efficiency: Traditional networking relies on static device identifiers (such as fixed MAC addresses), which are easily forged or tampered with, and complex authentication relying on a centralized server is required, resulting in high networking latency and difficulty in dynamically expanding, especially when the number of devices surges. Poor dynamic network adaptability: Existing IP address allocation mechanisms are mostly static or rely on the DHCP protocol, lacking the ability to respond in real time to the dynamic joining / leaving of devices from the network, which easily causes IP conflicts or resource waste. Insufficient security: Communication between devices during the networking process is not fully encrypted, posing risks such as identity forgery and data theft, and lacking a dynamic control mechanism for device permissions. High maintenance cost: Manual intervention is required when the network topology changes, and automatic subnet expansion and real-time monitoring of device status cannot be achieved, resulting in low operation and maintenance efficiency.

[0004] Therefore, there is an urgent need for a camera networking method that can balance security, dynamics, and automated management. Summary of the Invention

[0005] The present invention provides a method and system for automatic camera networking based on dynamic encryption identifiers, which can achieve rapid authentication of device identities and automatic networking.

[0006] The first basic solution provided by the present invention:

[0007] A method and system for automatic camera networking based on dynamic encryption identifiers, comprising the following steps:

[0008] The networking device broadcasts a data packet;

[0009] The gateway receives the data packet broadcast by the networking device and authenticates the identity of the networking device. If the identity authentication is passed, the gateway dynamically allocates an IP address for the networking device in the current subnet;

[0010] The gateway generates an access token and feeds it back to the networking device.

[0011] Further, it further includes:

[0012] The networking device generates a data packet; the data packet stores a device ID, a timestamp, and a digital signature.

[0013] Further, the networking device generating a data packet includes:

[0014] The networking device locally generates a unique device ID and obtains the current timestamp;

[0015] Using a preset splicing method, splice the device ID and the timestamp, and perform a hash operation on the spliced string to generate an original hash value;

[0016] The preset private key is stored in the networking device, and the original hash value is encrypted using the preset private key to generate a digital signature;

[0017] Generate a data packet according to the device ID, the timestamp, and the digital signature.

[0018] Furthermore, the gateway receives the data packet broadcast by the networking device and authenticates the networking device, including:

[0019] Receive the data packet broadcast by the networking device;

[0020] A whitelist is stored in the gateway, and the whitelist records several device IDs and the device public keys corresponding to each device ID; the gateway queries the device public key corresponding to the device ID in the data packet with reference to the whitelist according to the device ID in the data packet;

[0021] Decrypt the digital signature in the data packet according to the device public key to generate a decrypted original hash value;

[0022] Using a preset splicing method, splice the device ID and the timestamp in the data packet, and perform a hash operation on the spliced string to generate a parsed hash value;

[0023] Compare the original hash value with the parsed hash value and generate a hash value comparison result;

[0024] Obtain the current time, analyze the difference between the generation time of the data packet and the current time according to the timestamp in the data packet and the current time, and generate a time difference analysis result;

[0025] Generate an authentication result according to the hash value comparison result and the time difference analysis result.

[0026] Furthermore, the access token includes a device ID, an assigned IP address, the permission level of the networking device, and a digital signature.

[0027] Furthermore, the access token is provided with an expiration time.

[0028] Furthermore, the networking device broadcasts a data packet, including:

[0029] Obtain the current working mode of the networking device, and the current working mode includes a normal working mode and a low power consumption mode;

[0030] Generate a broadcast frequency according to the current working mode;

[0031] Broadcast the data packet according to the broadcast frequency.

[0032] Furthermore, it also includes:

[0033] The gateway monitors the number of devices in the current subnet in real time, analyzes whether the number of devices exceeds the device quantity threshold. If so, create a new subnet and perform dynamic allocation of IP addresses in the new subnet.

[0034] Furthermore, it also includes:

[0035] The gateway sends heartbeat packets to each networking device in the current subnet and the new subnet, and receives the feedback signals of each networking device; if the number of times the gateway sends heartbeat packets to any networking device exceeds the preset detection times and no feedback signal from the corresponding networking device is received, it is determined that the networking device is in an offline state, and the IP address allocated to the networking device is released.

[0036] Basic Solution 2 provided by the present invention: A camera automatic networking system based on a dynamic encryption identifier uses the above-mentioned camera automatic networking method based on a dynamic encryption identifier.

[0037] The principle and advantages of the present invention are as follows:

[0038] By adopting the networking method in this solution, efficient dynamic networking can be achieved. Specifically, through the dynamic binding of device ID, timestamp and digital signature to generate encrypted data packets, rapid authentication of device identities and automatic networking are realized, without manual configuration or relying on a centralized server. Combining the dual verification mechanisms of the whitelist and hash value, while ensuring security, the authentication delay is significantly reduced, and large-scale device concurrent access is supported.

[0039] Secondly, it can also achieve resource optimization and network stability improvement. Specifically, the dynamic IP allocation and subnet automatic expansion mechanism can adjust network resources in real time according to the number of devices, avoid IP conflicts, and improve resource utilization. The heartbeat packet monitoring and offline IP release functions can ensure the real-time update of the network topology and reduce the occupation of invalid resources.

[0040] In addition, it can also enhance security. Specifically, based on the digital signature and access token of asymmetric encryption, anti-counterfeiting of device identities, integrity verification of communication data and hierarchical control of permissions are realized. The timestamp verification mechanism effectively resists replay attacks, and the preset expiration period of the access token further reduces the long-term hijacking risk.

[0041] In summary, by adopting the networking method in this solution, while realizing automatic networking, the security of the networking system can be guaranteed, and the manual maintenance cost is greatly reduced. Brief Description of the Drawings

[0042] Figure 1 This is a flowchart of an embodiment of an automatic networking method for cameras based on dynamic encryption identifiers according to the present invention. Detailed implementation manners

[0043] The following is a further detailed description through specific implementation manners:

[0044] Embodiment 1:

[0045] An automatic networking method for cameras based on dynamic encryption identifiers, as Figure 1 shown, includes the following steps:

[0046] S100, the networking device generates a data packet; the data packet stores a device ID, a timestamp, and a digital signature. In this embodiment, the networking device is a camera, which uses a customized hardware module equipped with an ESP32-WROVER chip, integrating a Wi-Fi communication module (supporting the 802.11ac protocol to achieve high-frequency wireless broadcast and data transmission) and an encryption coprocessor (built-in hardware-accelerated RSA-2048 and SHA-256 algorithm engines for quickly generating a unique device identifier and an encrypted signature). S100 specifically includes the following steps:

[0047] S101, the networking device locally generates a unique device ID that conforms to the UUIDv4 standard, such as 550e8400-e29b-41d4-a716-446655440000. At the same time, a set of asymmetric key pairs is preset, using the RSA-2048 encryption algorithm, and the current timestamp is obtained.

[0048] S102, using a preset splicing method, splice the device ID and the timestamp, and perform a hash operation on the generated string after splicing using the SHA-256 algorithm to generate an original hash value.

[0049] S103, the networking device stores a preset private key, uses the preset private key to encrypt the original hash value, and generates a digital signature; in this embodiment, the RSA-2048 private key is used.

[0050] S104, generate a data packet according to the device ID, the timestamp, and the digital signature.

[0051] S200, the networking device broadcasts the data packet; specifically includes the following steps:

[0052] S201, obtain the current working mode of the networking device, and the current working mode includes a normal working mode and a low-power mode.

[0053] S202. Generate a broadcast frequency according to the current working mode. In this embodiment, if the current working mode is the normal working mode, the broadcast frequency is once per second. If the current working mode is the low-power mode, the broadcast frequency is once every five seconds. Thus, the broadcast frequency can be reduced in the low-power mode to extend the device's battery life and balance the energy efficiency and network coverage requirements.

[0054] S203. The networking device broadcasts the data packet at the generated broadcast frequency through its integrated Wi-Fi communication module according to the 802.11ac protocol. In this embodiment, the specific format of the data packet is as follows:

[0055] {

[0056] "device_id":"550e8400-e29b-41d4-a716-446655440000",

[0057] "timestamp":1620000000,

[0058] "signature":"Hash value encrypted by RSA-2048"

[0059] }

[0060] {

[0061] "device_id":"550e8400-e29b-41d4-a716-446655440000",

[0062] "timestamp":1620000000,

[0063] "signature":"Hash value encrypted by RSA-2048"

[0064] }

[0065] S300. The gateway receives the data packet broadcast by the networking device and authenticates the networking device. If the authentication is passed, it dynamically assigns an IP address to the networking device in the current subnet. In this embodiment, the gateway is deployed with components such as an SQLite database (storing the whitelist) and a dynamic IP allocation service (realizing the real-time management of the IP address pool based on the improved DHCP protocol). S300 specifically includes the following steps:

[0066] S301. Receive the data packet broadcast by the networking device.

[0067] S302. There is a whitelist stored in the gateway. The whitelist records a number of device IDs, the device public keys corresponding to each device ID, and the permission levels. The gateway queries the device public key and the permission level corresponding to the device ID in the whitelist according to the device ID in the data packet.

[0068] S303. Decrypt the digital signature in the data packet according to the device public key to generate a decrypted original hash value.

[0069] S304. Use a preset splicing method to splice the device ID and the timestamp in the data packet, and perform a hash operation on the generated string after splicing to generate a parsed hash value.

[0070] S305. Compare the original hash value and the parsed hash value, and generate a hash value comparison result.

[0071] S306. Obtain the current time, analyze the difference between the generation time of the data packet and the current time according to the timestamp in the data packet and the current time, and generate a time difference analysis result.

[0072] S307. Generate an authentication result according to the hash value comparison result and the time difference analysis result. Specifically, if the hash value comparison result is that the original hash value is the same as the parsed hash value, and the time difference analysis result is that the difference between the generation time of the data packet and the current time is within the range of ±30 seconds, the generated authentication result is that the authentication is passed, otherwise the authentication is not passed. Thus, a replay attack can be effectively resisted through the timestamp verification mechanism.

[0073] S308. If the authentication is passed, dynamically assign an IP address, such as 192.168.1.x, to the networking device in the current subnet.

[0074] S400. The gateway generates an access token and feedbacks it to the networking device. The access token includes the device ID, the assigned IP address, the permission level of the networking device, and the digital signature, and the access token is set with an access period. In this embodiment, the gateway generates an access token in the JWT format, and the access period is 24 hours. After expiration, the networking device needs to re-authenticate to obtain a new access token. Thus, the long-term hijacking risk can be further reduced through the preset period of the access token.

[0075] S500. The networking device joins the network.

[0076] By using the above networking method, automatic networking can be achieved while ensuring the security of the networking system, and the manual maintenance cost is significantly reduced. And through the test of the access efficiency, with this solution, when 50 cameras are started simultaneously, the average access time ≤ 2 seconds (≥ 30 seconds in the traditional method), which significantly improves the access efficiency of the networking device.

[0077] A camera automatic networking system based on dynamic encryption identification, including networking devices and a gateway, uses the above-mentioned camera automatic networking method based on dynamic encryption identification.

[0078] Embodiment 2:

[0079] The basic principle of Embodiment 2 is the same as that of Embodiment 1. The difference is that in Embodiment 2, it further includes:

[0080] The gateway monitors the number of devices in the current subnet in real time and analyzes whether the number of devices exceeds the device quantity threshold. If so, a new subnet, such as 192.168.2.0 / 24, is created, the corresponding IP address pool and routing policy are initialized, and dynamic allocation of IP addresses is performed in the new subnet. Subsequently, newly connected networking devices will be guided to this newly created subnet. In this embodiment, the device quantity threshold is 50 units. The above-mentioned subnet automatic expansion mechanism can adjust network resources in real time according to the number of devices, avoid IP conflicts, and improve resource utilization.

[0081] When a networking device needs to access resources across subnets, the gateway acts as an agent to verify the access permission of its access token and forwards the request to the target subnet.

[0082] Embodiment 3:

[0083] The basic principle of Embodiment 3 is the same as that of Embodiment 1. The difference is that in Embodiment 3, it further includes:

[0084] In order to timely grasp the online status of networking devices, the gateway sends heartbeat packets to each networking device in the current subnet and the new subnet, and receives the feedback signals from each networking device. In this embodiment, the gateway sends a UDP heartbeat packet to each networking device in the network once every 10 seconds. If the number of times the gateway sends a heartbeat packet to any networking device exceeds the preset detection times and no feedback signal from the corresponding networking device is received, it is determined that the networking device is in an offline state, the IP address assigned to the networking device is released, and the network topology status information is updated in a timely manner to ensure the accuracy and effectiveness of network management. If the networking device goes online again, it needs to rebroadcast data packets and complete the authentication process. The above-mentioned heartbeat packet monitoring and offline IP release functions can ensure the real-time update of the network topology and reduce the occupation of invalid resources.

[0085] The above are only embodiments of the present invention. Common general knowledge such as specific structures and characteristics known in the art are not described in detail herein. Those of ordinary skill in the art know all the general technical knowledge in the technical field to which the invention pertains before the filing date or the priority date, are able to obtain all the prior art in this field, and have the ability to apply the conventional experimental means before this date. Those of ordinary skill in the art can, under the inspiration given by this application, complete and implement this solution in combination with their own abilities. Some typical well-known structures or well-known methods should not become an obstacle for those of ordinary skill in the art to implement this application. It should be noted that for those skilled in the art, without departing from the structure of the present invention, several deformations and improvements can still be made, and these should also be regarded as the protection scope of the present invention, and these will not affect the implementation effect of the present invention and the practicality of the patent. The protection scope claimed in this application should be based on the content of its claims, and the specific implementation manners and the like described in the specification can be used to interpret the content of the claims.

Claims

1. An automatic networking method for cameras based on dynamic encryption identifiers, characterized in that: It includes the following steps: The networking device broadcasts data packets; The gateway receives the data packets broadcast by the networking device, authenticates the networking device. If the authentication is passed, it dynamically assigns an IP address to the networking device in the current subnet; The gateway generates an access token and feeds it back to the networking device.

2. The method for automatically networking cameras based on dynamically encrypted identifiers according to claim 1, wherein: It also includes: The networking device generates data packets; The device ID, timestamp and digital signature are stored in the data packets.

3. The method for automatically networking cameras based on a dynamically encrypted identifier according to claim 2, wherein: The networking device generates data packets, including: The networking device locally generates a unique device ID and obtains the current timestamp; Using a preset splicing method, splice the device ID and timestamp, and perform a hash operation on the spliced string to generate an original hash value; A preset private key is stored in the networking device, and the original hash value is encrypted using the preset private key to generate a digital signature; Generate data packets according to the device ID, timestamp and digital signature.

4. The method for automatically networking cameras based on a dynamically encrypted identifier according to claim 2, wherein: The gateway receives the data packets broadcast by the networking device and authenticates the networking device, including: Receive the data packets broadcast by the networking device; A whitelist is stored in the gateway, and the whitelist records several device IDs and the device public keys corresponding to each device ID; the gateway queries the device public key corresponding to the device ID with reference to the whitelist according to the device ID in the data packet; According to the device public key, decrypt the digital signature in the data packet to generate a decrypted original hash value; Using a preset splicing method, splice the device ID and timestamp in the data packet, and perform a hash operation on the spliced string to generate a parsed hash value; Compare the original hash value and the parsed hash value, and generate a hash value comparison result; Obtain the current time, analyze the difference between the generation time of the data packet and the current time according to the timestamp in the data packet and the current time, and generate a time difference analysis result; Generate an authentication result according to the hash value comparison result and the time difference analysis result.

5. The method for automatically networking cameras based on a dynamic encryption identifier according to claim 1, wherein: The access token includes the device ID, the assigned IP address, the permission level of the networking device and the digital signature.

6. The method for automatically networking cameras based on dynamically encrypted identifiers according to claim 1, characterized in that: The access token is provided with an access period.

7. The method for automatically networking cameras based on a dynamically encrypted identifier according to claim 1, wherein: The networking device broadcasts data packets, including: Obtain the current working mode of the networking device, and the current working mode includes a normal working mode and a low power consumption mode; Generate a broadcast frequency according to the current working mode; Broadcast the data packets according to the broadcast frequency.

8. The method for automatically networking cameras based on dynamic encryption identifiers according to claim 1, characterized in that: It also includes: The gateway monitors the number of devices in the current subnet in real time, analyzes whether the number of devices exceeds the device quantity threshold. If so, create a new subnet and perform dynamic allocation of IP addresses in the new subnet.

9. The method for automatically networking cameras based on dynamic encryption identifiers according to claim 8, wherein: It also includes: The gateway sends heartbeat packets to the networking devices in the current subnet and the new subnet, and receives the feedback signals from each networking device; If the number of times the gateway sends a heartbeat packet to any networking device exceeds the preset detection times and no feedback signal from the corresponding networking device is received, it is determined that the networking device is in an offline state, and the IP address assigned to the networking device is released.

10. An automatic networking system for cameras based on dynamic encryption identifiers, characterized in that: The automatic networking method for cameras based on dynamic encryption identification according to any one of claims 1 to 9 above is used.