Video signal dynamic encryption authentication method and system

Through two-way challenge-response authentication and Diffie-Hellman key exchange algorithm, combined with EDID and HDCP encryption, dynamic security authentication of HDMI video transmission system is realized, solving the problem of vulnerability in traditional systems and ensuring the secure transmission and stability of video signals.

CN120358091AActive Publication Date: 2025-07-22SHENZHEN YUMING INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510841398.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-23
Publication Date
2025-07-22
Estimated Expiration
2045-06-23

AI Technical Summary

Technical Problem

Traditional HDMI video transmission systems lack dynamic verification mechanisms and are susceptible to man-in-the-middle attacks and fake device access. The existing EDID verification solution is simple and has insufficient security.

Method used

The two-way challenge-response authentication mechanism is adopted, and the session key is generated in combination with the Diffie-Hellman key exchange algorithm, and through EDID verification and HDCP encryption, a multi-level security protection system is established, the device connection status is monitored in real time, and the transmission is quickly cut off and the link is rebuilt when a threat is detected.

Benefits of technology

Effectively prevent illegal equipment access and video signals from being intercepted, ensure the security and stability of transmission, and improve the fault tolerance and reliability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358091A_ABST
    Figure CN120358091A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of video signal processing, and discloses a video signal dynamic encryption authentication method and system. The method comprises the following steps: executing bidirectional challenge-response authentication on video signal sending equipment and video signal receiving equipment to obtain a bidirectional identity authentication result; performing session key calculation to obtain a session key; performing EDID verification on the video signal receiving equipment to obtain encrypted EDID verification passing information; performing encryption transmission and video signal encryption processing on the HDCP key to obtain an encrypted video signal; carrying out equipment heartbeat response detection to obtain a connection state confirmation result; and controlling the video signal transmission state of the video signal sending device and the HDMI receiving channel of the video signal receiving device to obtain a reconstruction instruction of the video signal transmission link. According to the invention, the real-time monitoring of the equipment connection state is realized, the video transmission can be quickly cut off when the security threat is detected, and the security link is automatically reestablished.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of video signal processing, and in particular, to a method and system for dynamic encryption authentication of video signals. Background Art

[0002] With the rapid development of video signal transmission technology, the security protection of video content has become an increasingly prominent issue. The traditional HDMI video transmission system lacks a perfect authentication mechanism, resulting in illegal devices being able to easily intercept and copy high-definition video content. Although the HDCP encryption technology provides protection to a certain extent, a single encryption scheme cannot cope with the increasingly complex security threats.

[0003] Currently, most connections between HDMI devices lack a dynamic verification mechanism. Once the connection is established, no further identity authentication is performed, which gives attackers the opportunity to disrupt the security of video transmission through man-in-the-middle attacks or replay attacks. At the same time, the existing EDID verification scheme is too simple to effectively prevent the access of forged devices, presenting serious security risks. Summary of the Invention

[0004] The present invention provides a method and system for dynamic encryption authentication of video signals. The present invention realizes real-time monitoring of the device connection status, can quickly cut off the video transmission when detecting a security threat, and automatically rebuilds a secure link.

[0005] In a first aspect, the present invention provides a method for dynamic encryption authentication of video signals. The method for dynamic encryption authentication of video signals includes: Performing two-way challenge-response authentication on a video signal transmitting device and a video signal receiving device to obtain a two-way identity authentication result; Based on the two-way identity authentication result, calculating a session key for the video signal transmitting device and the video signal receiving device to obtain a session key; Performing EDID verification on the video signal receiving device to obtain encrypted EDID verification passed information; According to the encrypted EDID verification passed information, performing encrypted transmission of the HDCP key and encrypting the video signal to obtain an encrypted video signal; Performing device heartbeat response detection according to the encrypted video signal to obtain a connection status confirmation result; According to the connection status confirmation result, controlling the video signal transmission status of the video signal transmitting device and the HDMI receiving channel of the video signal receiving device to obtain a reconstruction instruction for the video signal transmission link.

[0006] In a second aspect, the present invention provides a video signal dynamic encryption and authentication system, which includes: An authentication module, configured to perform two-way challenge-response authentication on a video signal sending device and a video signal receiving device to obtain a two-way identity authentication result; A key calculation module, configured to calculate a session key for the video signal sending device and the video signal receiving device based on the two-way identity authentication result; A verification module, configured to perform EDID verification on the video signal receiving device to obtain encrypted EDID verification passed information; An encryption transmission module, configured to encrypt and transmit an HDCP key and perform video signal encryption processing according to the encrypted EDID verification passed information to obtain an encrypted video signal; A response detection module, configured to perform device heartbeat response detection according to the encrypted video signal to obtain a connection status confirmation result; A reconstruction module, configured to control the video signal transmission status of the video signal sending device and the HDMI receiving channel of the video signal receiving device according to the connection status confirmation result to obtain a reconstruction instruction for the video signal transmission link.

[0007] In the technical solution provided by the present invention, by establishing a two-way challenge-response authentication mechanism, two-way identity verification of the video signal sending device and the receiving device is achieved, effectively preventing the access of illegal devices and man-in-the-middle attacks. The Diffie-Hellman key exchange algorithm is used to dynamically generate a session key, improving the security of the key and ensuring the encryption strength of the subsequent communication process. Combining EDID verification and HDCP encryption, a multi-level security protection system is constructed, effectively preventing the illegal interception and copying of video signals. Through the heartbeat detection mechanism, real-time monitoring of the device connection status is achieved, and abnormal situations can be detected and processed in a timely manner. A complete exception handling and link reconstruction mechanism is designed, which can quickly cut off video transmission and automatically reconstruct a secure link when a security threat is detected. A segmented data processing and verification scheme is adopted, improving the fault tolerance and reliability of the system and ensuring the continuity and stability of video signal transmission. Description of the Drawings

[0008] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0009] Figure 1Schematic flowchart of the video signal dynamic encryption and authentication method provided by the embodiment of the present application; Figure 2 Schematic block diagram of the structure of the video signal dynamic encryption and authentication system provided by the embodiment of the present application. Detailed implementation manners

[0010] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0011] The flowchart shown in the accompanying drawings is only an example illustration, and does not necessarily include all contents and operations / steps, nor does it necessarily execute in the described order. For example, some operations / steps can be decomposed, combined, or partially merged, so the actual execution order may change based on the actual situation.

[0012] It should also be understood that the terms used in the specification of the present application are only for the purpose of describing specific embodiments and are not intended to limit the present application. As used in the specification of the present application and the appended claims, unless otherwise clearly specified in the context, the singular forms "a", "an", and "the" are intended to include the plural forms.

[0013] It should be further understood that the term " / and" as used in the specification of the present application and the appended claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.

[0014] The following will describe in detail some embodiments of the present application with reference to the accompanying drawings. Without conflict, the features in the following embodiments and the embodiments can be combined with each other.

[0015] Please refer to Figure 1 , Figure 1 which is a schematic flowchart of the video signal dynamic encryption and authentication method provided by the embodiment of the present application. As Figure 1 shown, the video signal dynamic encryption and authentication method provided by the embodiment of the present application includes steps S100 to S600.

[0016] Step S100: Perform two-way challenge-response authentication on the video signal sending device and the video signal receiving device to obtain a two-way identity authentication result; It can be understood that the execution subject of the present invention can be a video signal dynamic encryption and authentication system, or a terminal or a server. Specifically, it is not limited here. The embodiment of the present invention is described by taking the server as the execution subject as an example.

[0017] Specifically, the public-private key pairs preset in the video signal sending device and the public-private key pairs preset in the video signal receiving device are initialized to obtain two independent pairs of asymmetric keys. The video signal sending device generates a first random number, which serves as the core content of the authentication challenge information and is used to test the authenticity of the receiving device's identity. To enhance security, the sending device encapsulates the first random number and converts it into the first authentication challenge information through encryption or specific format processing. The first authentication challenge information is sent to the video signal receiving device. After receiving the first authentication challenge information, the video signal receiving device digitally signs the information using its preset private key. The digital signature process encrypts the content in the first authentication challenge information using the receiving device's private key to generate the first signature information. The video signal receiving device sends the first signature information back to the video signal sending device, and the latter verifies the first signature information using the public key of the receiving device preset in the sending device. The core of the verification is to decrypt the signature information using the public key of the receiving device, extract the original first authentication challenge information from it, and compare it with the sent random number. If the decryption result is consistent with the original information, it indicates that the receiving device indeed holds the corresponding private key, thus completing the verification in the first stage and obtaining the first verification result. At the same time, to achieve two-way authentication, the video signal receiving device generates an independent second random number. This second random number also serves as the core content of the authentication challenge information, which is encapsulated by the receiving device to generate the second authentication challenge information and sent to the video signal sending device. After receiving this information, the video signal sending device digitally signs the second authentication challenge information using its preset private key to generate the second signature information. The sending device transmits the generated second signature information back to the receiving device, and the receiving device verifies the signature information using the public key of the sending device. The receiving device decrypts the second signature information using the public key of the sending device and compares the decrypted content with the previously generated second random number. If the decryption result is consistent with the original content, it indicates that the sending device indeed holds the corresponding private key, and the verification passes, obtaining the second verification result. The video signal sending device and the receiving device respectively perform a logical AND operation based on the first verification result and the second verification result. In this way, both parties jointly confirm each other's identity, ensuring that both devices are legal and trusted devices, and obtaining the two-way identity authentication result.

[0018] Step S200: Based on the two-way identity authentication result, calculate the session key for the video signal sending device and the video signal receiving device to obtain the session key; Specifically, after completing the two-way identity authentication, conditional judgment is performed based on the authentication result. When the two-way identity authentication result is true, a key exchange start instruction is triggered. If the authentication result is false, subsequent steps are terminated, thereby preventing unauthenticated devices from participating in the key exchange process and enhancing overall security. After the key exchange is started, the preset large prime number and the primitive root are initialized. These two parameters are the basis of the entire key exchange process, where is a publicly known large prime number, and is the primitive root of this large prime number, satisfying specific mathematical properties under modular arithmetic. After initialization, and are respectively sent to the video signal sending device and the receiving device as the common parameters for both parties to perform key exchange. The video signal sending device generates an integer , which serves as the first private key of the sending device. The sending device uses the received primitive root and the generated first private key to perform modular exponentiation, that is, calculate mod to generate a first random key parameter. Meanwhile, the video signal receiving device generates another integer as the second private key, and in the same way performs modular exponentiation on and to calculate mod to obtain a second random key parameter. These two random key parameters are the core of the shared information between the sending device and the receiving device during the key exchange process. The video signal sending device sends the generated first random key parameter to the receiving device through a secure channel. After receiving this parameter, the receiving device uses its second private key and the received first random key parameter to perform modular exponentiation, that is, calculate mod . Through the mathematical properties of exponentiation operations, it can be proven that this calculation result is actually equivalent to mod to generate a first session key. Similarly, the video signal receiving device sends its generated second random key parameter to the sending device through a secure channel. After receiving this parameter, the sending device uses its first private key and the received second random key parameter to perform modular exponentiation, that is, calculate mod , and also obtains mod This process ensures that the sending device and the receiving device can generate the same session key without directly transmitting the private key. To ensure the security and accuracy of the key exchange process, consistency verification is performed on the generated first session key and second session key. The two session keys are compared. If they are consistent, the verification passes, indicating that the key exchange process is successful and not interfered with. If the consistency verification fails, it means that there are security issues or calculation errors in the key exchange process. At this time, the operation is terminated to prevent potential security threats. On the premise that the consistency verification passes, the first session key or the second session key is selected as the final session key according to the preset rules to complete the entire key calculation process.

[0019] Step S300: Perform EDID verification on the video signal receiving device to obtain the encrypted EDID verification passed information; Specifically, in order to access the EDID data of the video signal receiving device, the DDC (Display Data Channel) channel of HDMI is initialized. The DDC channel of HDMI is a standardized data exchange interface based on the I2C communication protocol, which is used to transmit the configuration information of the display device. By initializing the DDC channel, a stable I2C communication link is established between the video signal transmitting device and the receiving device, and a DDC channel read instruction for reading the EDID data is generated. After the communication link is established, the video signal transmitting device reads the complete original EDID data from the EDID register of the video signal receiving device by sending the DDC channel read instruction. These data are the set of display parameters supported by the receiving device, including key information such as resolution, refresh rate, manufacturer identification, and product identification. The read original EDID data is parsed and processed to extract the key fields, obtaining the standardized EDID information. To verify the EDID information more efficiently, the video signal transmitting device segments the parsed EDID information into a resolution information segment, a manufacturer identification information segment, and a product identification information segment. Through a structured processing method, the main feature data of the receiving device is identified. At the same time, the video signal transmitting device reads the pre-stored device feature information from its memory. These information are the reference data stored during the initial configuration of the system for verification. Similar to the processing of the EDID information of the receiving device, the video signal transmitting device also segments the pre-stored device feature information, extracts the expected resolution information segment, the expected manufacturer identification information segment, and the expected product identification information segment, forming the expected feature data. Enter the feature data comparison stage. The video signal transmitting device compares the resolution information segment extracted from the receiving device with the pre-stored expected resolution information segment. If the two information segments are exactly the same, it is considered that the resolution supported by the receiving device meets the expected requirements of the system, and the resolution matching result is generated as true. The video signal transmitting device compares the manufacturer identification information segment and the product identification information segment with the expected manufacturer identification information segment and the expected product identification information segment respectively to verify whether the brand and model of the receiving device are consistent with the system's expectations. If the comparison results are consistent, the device identification matching result is generated as true. After completing all comparison operations, the video signal transmitting device performs a logical AND operation based on the resolution matching result and the device identification matching result. Only when both matching results are true, will the EDID verification passed information be generated, indicating that the receiving device meets the system requirements and can safely perform subsequent signal transmission. To protect the integrity and anti-tampering of the verification passed information, the video signal transmitting device encrypts the EDID verification passed information using the previously generated session key. The encryption process uses a symmetric encryption algorithm, such as the AES algorithm, to convert the verification passed information into the encrypted EDID verification passed information, ensuring that only the receiving device with the correct session key can decrypt and use this information.

[0020] Step S400: According to the encrypted EDID verification passed information, perform encrypted transmission of the HDCP key and encrypted processing of the video signal to obtain an encrypted video signal; Specifically, the video signal receiving device decrypts the received encrypted EDID verification passed information using the session key negotiated previously. After decryption, the receiving device extracts the original EDID verification passed information and verifies the integrity and correctness of the decryption result to ensure that the information has not been tampered with during transmission. If the verification is successful, the receiving device generates an HDCP start instruction to direct both devices to enter the HDCP protection mode. Based on the HDCP start instruction, an HDMI connection is established between the video signal transmitting device and the receiving device. After the connection is established, the transmitting device performs an HDCP enabling operation on the HDMI link to ensure that the data is protected by the HDCP protocol during transmission, generating an HDCP physical link. This physical link is the basis for subsequent signal encryption and key negotiation, ensuring the integrity and security of data transmission. After the HDCP physical link is established, the video signal transmitting device actively sends an HDCP capability negotiation request to the receiving device through this link to obtain the HDCP version information of the receiving device. The transmitting device completes the HDCP version matching process by comparing its own HDCP version with the version information returned by the receiving device, obtaining the HDCP version negotiation result. If the version matching is successful, the two parties continue with key negotiation; otherwise, the connection will be terminated to ensure compatibility and security. The video signal transmitting device generates an HDCP key for data encryption based on the HDCP version negotiation result. For the convenience of transmission and processing, the transmitting device segments the generated HDCP key and splits the key into multiple key data segments. To ensure the security of key transmission, the transmitting device encrypts each key data segment using the session key to obtain the encrypted key data segments. After encryption is completed, these encrypted key data segments are transmitted to the video signal receiving device through the HDCP physical link. After receiving the encrypted key data segments, the receiving device decrypts these data segments one by one using the session key to restore the original HDCP key data segments. The receiving device recombines these decrypted data segments to fully restore the HDCP key. To verify the correctness of the HDCP key transmission and recombination process, the video signal transmitting device generates an HDCP key verification code. This verification code is calculated by the transmitting device according to the generated HDCP key through a specific algorithm and is encrypted using the session key before being transmitted to the receiving device. After receiving the encrypted HDCP key verification code, the receiving device decrypts it using the session key and calculates the local HDCP key verification code through the same algorithm. The receiving device compares the locally calculated verification code with the verification code transmitted by the transmitting device. If the two are consistent, the verification passes, indicating that both the HDCP key transmission and recombination are successful, generating an HDCP key verification result. When the HDCP key verification result is true, the video signal transmitting device enables its video data input channel, thereby allowing subsequent video data to enter the encryption process.The sending device encrypts the input video signal using the generated HDCP key to ensure that the video content remains encrypted during transmission. The encrypted video signal is transmitted to the receiving device via an HDCP-protected physical link.

[0021] Step S500: Detect the device heartbeat response based on the encrypted video signal to obtain the connection status confirmation result; Specifically, the preset heartbeat detection time interval is read, which is the trigger condition for heartbeat detection and is used to periodically start the connection status confirmation mechanism between devices. Based on the read heartbeat detection time interval, the video signal sending device generates a heartbeat detection trigger instruction, indicating it to start constructing the heartbeat detection information. After the heartbeat detection trigger instruction is sent, the video signal sending device generates a random sequence as the core content of the heartbeat detection information. The randomness and unpredictability of this random sequence are important factors to ensure the security of heartbeat detection and can effectively resist replay attacks and forgery behaviors. After the generated random sequence is encapsulated, it is transformed into a complete heartbeat detection information for subsequent encryption and transmission. After the heartbeat detection information is prepared, the video signal sending device encrypts this information using the previously negotiated session key to obtain the encrypted heartbeat detection information. The encryption process ensures that the heartbeat detection information is not eavesdropped on or tampered with during transmission. The video signal sending device transmits the encrypted heartbeat detection information to the video signal receiving device through a secure communication channel. After receiving the encrypted information, the receiving device decrypts it using the session key to restore the decrypted heartbeat detection information. The decrypted information contains the random sequence generated by the sending device, which is used in the response generation process of the receiving device. After the receiving device completes decryption, it performs a digital signature operation on the decrypted heartbeat detection information. The digital signature encrypts the heartbeat detection information using the private key preset in the receiving device to generate a unique heartbeat response information. Through the digital signature, the receiving device confirms the source of the heartbeat detection information and prevents the response information from being tampered with. To ensure the security of transmission, the receiving device encrypts the generated heartbeat response information again using the session key to obtain the encrypted heartbeat response information. The receiving device sends the encrypted response information back to the video signal sending device through the secure communication channel. After receiving the encrypted heartbeat response information, the sending device also uses the session key to perform a decryption operation to restore the decrypted heartbeat response information. At this time, the sending device verifies the digital signature in the decrypted information. The core of the verification is to decrypt the signature using the public key of the receiving device and compare it with the original heartbeat detection information. If the signature verification is successful, it indicates that the response of the receiving device is trustworthy and the connection status between the devices is normal, thus generating a connection status confirmation result of true.

[0022] Step S600: According to the connection status confirmation result, control the video signal transmission status of the video signal sending device and the HDMI receiving channel of the video signal receiving device, and obtain a reconstruction instruction for the video signal transmission link.

[0023] Specifically, the video signal transmitting device performs abnormal state detection on multiple core verification information according to the connection status confirmation result, including the first signature information, the second signature information, the EDID verification passed information, the HDCP key verification result, and the heartbeat response information. By detecting these data, the transmitting device can identify whether there are abnormal phenomena such as transmission interruption, verification failure, or data tampering, and generate the transmitting end abnormal state information. This information serves as the main identifier of the current state of the transmitting device and is used to indicate whether the transmission channel needs to be reconfigured. At the same time, the video signal receiving device detects the relevant core verification information, including the first signature information, the second signature information, the EDID verification passed information, the HDCP key verification code, and the heartbeat detection information. By analyzing these data, the receiving device can determine whether it has an abnormal state, such as incomplete data reception, key verification failure, or link mismatch. After the detection is completed, the receiving device generates the receiving end abnormal state information, which, together with the abnormal state information of the transmitting end, forms a complete abnormal state feedback. Based on the abnormal state information of the transmitting end and the receiving end, these data are comprehensively analyzed and an abnormal state identification bit is generated. The generation of the abnormal state identification bit is achieved through logical operations, aiming to determine the health status of the current video signal transmission link. If the identification bit indicates the existence of an abnormal state, the system will further execute the state judgment logic to generate an abnormal handling trigger instruction. This trigger instruction is the core of the entire abnormal handling process and is used to coordinate the state adjustment of the transmitting device and the receiving device. When the abnormal handling trigger instruction is generated, it controls the video signal transmission channel of the video signal transmitting device to ensure that data will not continue to be transmitted in an abnormal state. Specifically, the trigger instruction closes the video signal transmission channel of the transmitting device and generates a video signal transmission interruption instruction, thereby stopping any potential unsafe signal transmission. At the same time, the trigger instruction controls the HDMI receiving channel of the video signal receiving device to prevent the receiving device from continuing to process abnormal signals. The closing of the receiving channel is achieved by generating an HDMI receiving interruption instruction, thereby ensuring that the signal link of the receiving device is in a safe state. After the channels of the transmitting device and the receiving device are closed, the status of the channels is confirmed. By checking the execution status of the video signal transmission interruption instruction and the HDMI receiving interruption instruction, the channel closing status information is generated. This status information is used to confirm whether the transmission channel and the receiving channel have been successfully closed. If the closing status information indicates that the channels have been correctly closed, the system considers that the current abnormal state has been initially isolated. Based on the channel closing status information, a reconstruction instruction for the video signal transmission link is generated. This instruction is used to re-initialize the connection between the transmitting device and the receiving device and re-execute operations such as authentication, key negotiation, and link configuration during the reconstruction process to ensure the security and stability of the new link. Through the above steps, the system can quickly interrupt the existing link when an abnormal state is detected and restore the normal transmission of video signals by re-establishing the transmission link.

[0024] In an embodiment of the present invention, by establishing a two-way challenge-response authentication mechanism, two-way authentication of the video signal sending device and the receiving device is achieved, effectively preventing the access of illegal devices and man-in-the-middle attacks. The Diffie-Hellman key exchange algorithm is used to dynamically generate a session key, improving the security of the key and ensuring the encryption strength of the subsequent communication process. Combining EDID verification and HDCP encryption, a multi-level security protection system is constructed, effectively preventing the illegal interception and copying of video signals. Through the heartbeat detection mechanism, real-time monitoring of the device connection status is achieved, and abnormal situations can be detected and processed in a timely manner. A complete exception handling and link reconstruction mechanism is designed, which can quickly cut off the video transmission and automatically reconstruct a secure link when a security threat is detected. A segmented data processing and verification scheme is adopted to improve the fault tolerance and reliability of the system, ensuring the continuity and stability of video signal transmission.

[0025] In a specific embodiment, the process of executing step S100 may specifically include the following steps: Initialize the public-private key pairs preset in the video signal sending device and the public-private key pairs preset in the video signal receiving device to obtain two pairs of independent asymmetric keys; The video signal sending device generates a first random number, encapsulates the first random number to obtain a first authentication challenge message; Send the first authentication challenge message. The video signal receiving device receives the first authentication challenge message and uses the private key preset in the video signal receiving device to digitally sign the first authentication challenge message to obtain a first signature message; Transmit the first signature message. The video signal sending device uses the public key preset in the video signal receiving device to verify the first signature message to obtain a first verification result; The video signal receiving device generates a second random number, encapsulates the second random number to obtain a second authentication challenge message; Send the second authentication challenge message. The video signal sending device receives the second authentication challenge message and uses the private key preset in the video signal sending device to digitally sign the second authentication challenge message to obtain a second signature message; Transmit the second signature message. The video signal receiving device uses the public key preset in the video signal sending device to verify the second signature message to obtain a second verification result; Perform a logical AND operation based on the first verification result and the second verification result to obtain a two-way identity authentication result.

[0026] Specifically, initialize the asymmetric key pairs in the video signal sending device and the receiving device. The asymmetric key pair consists of a public key and a private key. The public key is used for encryption or signature verification, while the private key is used for decryption or signature generation. Assume that the public key and private key of the sending device are denoted as and respectively, and the public key and private key of the receiving device are denoted as and respectively. These two pairs of keys are independently generated and satisfy the mathematical properties of the asymmetric encryption algorithm, such as those in RSA or ECC, that is, for any plaintext , there are the following relationships: ; where represents encrypting the plaintext using the public key , and represents decrypting the encrypted ciphertext using the corresponding private key . After completing the key initialization, perform the authentication process. The video signal sending device generates a random number , which serves as the core of the first authentication challenge information. The random number is an unpredictable integer used to ensure the uniqueness of each authentication. The sending device encapsulates to form the first authentication challenge information . Assume that the encapsulation function is , then there is: ; The video signal sending device sends to the receiving device through a secure channel. After receiving , the receiving device uses its own private key to digitally sign to generate the first signature information . The role of digital signature is to prove that the response of the receiving device to this authentication challenge information is unique and cannot be forged. The signature process is expressed as: ; The receiving device transmits back to the sending device. After receiving , the sending device uses the pre-set public key of the receiving device to verify the signature to ensure the legality of its source. The verification process is: ; If the verification result is true, the first verification result True is obtained. After completing the first-phase authentication, the receiving device generates another random number​ As the core of the second authentication challenge information. Similar to the operation of the sending device, the receiving device will encapsulate it to form the second authentication challenge information : ; The receiving device will send it to the sending device. After the sending device receives , it uses its own private key to perform digital signature to generate the second signature information : ; The sending device will return it to the receiving device. The receiving device uses the pre-set public key of the sending device to verify the signature . The verification process is as follows: ; If the verification result is true, the second verification result True is obtained. The video signal sending device and the receiving device respectively perform a logical AND operation based on the first verification result and the second verification result to ensure that the authentication of both parties is successful. The result of the logical operation is expressed as: ; If True, it indicates that the mutual authentication is successful, and the sending device and the receiving device securely establish a trust connection.

[0027] In a specific embodiment, the process of executing step S200 may specifically include the following steps: Perform a conditional judgment based on the mutual identity authentication result. When the mutual identity authentication result is true, execute the key exchange start instruction; Based on the key exchange start instruction, initialize the preset large prime number p and the primitive root g, and send the large prime number p and the primitive root g to the video signal sending device and the video signal receiving device respectively to obtain the key exchange parameters; The video signal sending device generates an integer e as the first private key, and performs modular exponentiation on the primitive root g and the first private key a to obtain the first random key parameter; The video signal receiving device generates an integer f as the second private key, and performs modular exponentiation on the primitive root g and the second private key b to obtain the second random key parameter; Send the first random key parameter, which is received by the video signal receiving device. Then, perform modular exponentiation on the first random key parameter and the second private key b to obtain the first session key. Send the second random key parameter, which is received by the video signal transmitting device. Then, perform modular exponentiation on the second random key parameter and the first private key to obtain the second session key. Perform consistency verification on the first session key and the second session key to obtain the consistency verification result, and select either the first session key or the second session key based on the consistency verification result to obtain the session key.

[0028] Specifically, after completing the mutual authentication, perform a conditional judgment on the authentication result. If the mutual authentication result is true, that is, the identities of both parties are verified, then trigger the key exchange start instruction. The core function of this instruction is to initialize the public parameters required for the key exchange between both parties, namely a preset large prime number and its primitive root . Among them, is a prime number large enough to define the range of modular operations within the finite field; is 's primitive root, satisfying that under the modulus , the powers of can generate distinct values. After initialization, send and to the video signal transmitting device and the receiving device respectively, providing public parameter support for the subsequent key exchange. After receiving the key exchange parameters, the video signal transmitting device randomly generates an integer as the first private key, and this integer needs to be randomly selected within the range to ensure its confidentiality. The transmitting device uses the primitive root and the private key to perform modular exponentiation to calculate the first random key parameter , and its formula is: ; Among them, is an intermediate value calculated by the transmitting device based on the private key and the public parameters, and is used for the subsequent key exchange. At the same time, the video signal receiving device also randomly generates an integer as the second private key. Similar to the transmitting device, the receiving device uses and to perform modular exponentiation to calculate the second random key parameter : ; At this time, the sending device and the receiving device each hold their own private keys and random key parameters. To complete the key exchange, the sending device will send to the receiving device, while the receiving device will send to the sending device. After the receiving device receives , it uses its private key to perform modular exponentiation on to calculate the first session key : ; Combined with mod we can get: ; Similarly, after the sending device receives , it uses its private key to perform modular exponentiation on to calculate the second session key : ; Combined with mod we can get: ; Since the exponentiation operation satisfies the commutative law, that is , therefore and are equal, that is . This indicates that both parties have successfully generated a consistent session key . To ensure the reliability of key generation and transmission, consistency verification is performed on the first session key and the second session key. The verification process is achieved by comparing whether and are equal. If the verification passes, the consistency verification result is true, indicating that the key exchange process is successful. Based on the consistency verification result, the first session key or the second session key is selected as the final session key.

[0029] In a specific embodiment, the process of executing step S300 may specifically include the following steps: Initialize the DDC channel of HDMI, establish an I2C communication link between the video signal sending device and the video signal receiving device, and obtain a DDC channel read instruction; Read the EDID raw data from the EDID register of the video signal receiving device based on the DDC channel read instruction, and parse the EDID raw data to obtain the EDID information; Segment the EDID information, extract the resolution information segment, the manufacturer identification information segment, and the product identification information segment from the EDID information to obtain the characteristic data of the video signal receiving device; Read the pre-stored device characteristic information from the memory, segment the pre-stored device characteristic information, and extract the expected resolution information segment, the expected manufacturer identification information segment, and the expected product identification information segment to obtain the expected characteristic data; Compare the resolution information segment in the characteristic data with the expected resolution information segment in the expected characteristic data to obtain the resolution matching result; Compare the manufacturer identification information segment and the product identification information segment in the characteristic data with the expected manufacturer identification information segment and the expected product identification information segment in the expected characteristic data to obtain the device identification matching result; Perform a logical AND operation based on the resolution matching result and the device identification matching result to generate the EDID verification passed information, and encrypt the EDID verification passed information using the session key to obtain the encrypted EDID verification passed information.

[0030] Specifically, by initializing the DDC (Display Data Channel) channel in the HDMI interface, an I2C communication link is established between the video signal transmitting device and the receiving device. I2C is a two-way serial communication protocol. The DDC channel connects the transmitting device and the receiving device through the SCL (clock line) and SDA (data line) for transmitting device information. After initialization, the transmitting device generates a DDC channel read instruction , whose function is to extract the display capability data of the device from the EDID register of the receiving device. Based on the read instruction , the transmitting device reads the EDID raw data of the receiving device through the DDC channel. EDID (Extended Display Identification Data) is the configuration information of the display device, stored in a specific register by the receiving device and represented in a data format of 128 bytes or 256 bytes. The read EDID raw data is denoted as , whose content includes keyword fields such as resolution support information, manufacturer identification, and product identification. The transmitting device performs a parsing operation on to extract the structured information therein and generate the EDID information , expressed as: ; Among them, represents the parsing function that converts the raw byte data into recognizable device information. To further verify the authenticity and capabilities of the receiving device, the transmitting device will Perform segmentation processing to extract the resolution information segment and the manufacturer identification information segment and the product identification information segment . This segmentation operation is expressed as: ; wherein is a segmentation function that extracts the resolution information, manufacturer identification, and product identification supported by the device respectively. These segmented information constitute the characteristic data of the receiving device : ; At the same time, the sending device reads the pre-stored device characteristic information from its memory . These information are the expected values stored during the initial configuration of the system and also need to be segmented to extract the expected resolution information segment and the expected manufacturer identification information segment and the expected product identification information segment : ; These segmented information constitute the expected characteristic data : ; After the extraction of the characteristic data is completed, the receiving device characteristic data and the expected characteristic data are compared item by item. The sending device compares the resolution information segment of the receiving device with the expected resolution information segment to generate a resolution matching result : ; wherein represents the comparison function. If the two are the same, then , otherwise . The sending device compares the manufacturer identification information segment and the product identification information segment of the receiving device with the expected and to generate a device identification matching result : ; The system performs a logical AND operation based on the resolution matching result and the device identification matching result to generate an EDID verification passed information : ; If If it is True, it indicates that the EDID information of the receiving device meets the expectation. To ensure the security of the verified information, the session key is used to encrypt it to generate the encrypted EDID verification passed information : ; wherein, represents the encryption function to ensure that it will not be tampered with during transmission.

[0031] In a specific embodiment, the process of executing step S400 may specifically include the following steps: The video signal receiving device uses the session key to decrypt the encrypted EDID verification passed information, obtains the decrypted EDID verification passed information, and verifies the decrypted EDID verification passed information to obtain the HDCP start instruction; Based on the HDCP start instruction, an HDMI connection is established between the video signal sending device and the video signal receiving device, and the HDMI connection is enabled for HDCP to obtain the HDCP physical link; The video signal sending device sends an HDCP capability negotiation request through the HDCP physical link, obtains the HDCP version information of the video signal receiving device and performs version matching to obtain the HDCP version negotiation result; Based on the HDCP version negotiation result, an HDCP key is generated, the HDCP key is segmented to obtain key data segments, and the key data segments are encrypted using the session key to obtain encrypted key data segments; The encrypted key data segments are transmitted, the video signal receiving device receives the encrypted key data segments and decrypts them using the session key, and recombines them to obtain the HDCP key; The video signal sending device generates an HDCP key verification code, encrypts and transmits the HDCP key verification code, and the video signal receiving device verifies it to obtain the HDCP key verification result; Based on the HDCP key verification result, the video data input channel of the video signal sending device is enabled, and the input video signal is encrypted using the HDCP key to obtain the encrypted video signal.

[0032] Specifically, the video signal receiving device uses the previously negotiated session key to decrypt the encrypted EDID verification passed information received from the sending device to obtain the decrypted EDID verification passed information . The decryption process is expressed as: ; Among them, represents the decryption operation using the session key to ensure that the decrypted information is consistent with the original verification information. The receiving device performs integrity verification on to confirm whether the EDID verification passed information has been tampered with. If the verification passes, an HDCP start instruction is generated, instructing the receiving device to enter the HDCP protection mode. Based on the HDCP start instruction , an HDMI connection is established between the transmitting device and the receiving device. After the connection is established, the transmitting device performs an HDCP enabling operation on the HDMI link to activate the content protection mechanism to generate an HDCP physical link . The establishment of the HDCP physical link is the basis for the entire video signal encryption process, used to ensure the secure transmission of video content. After the HDCP physical link is established, the video signal transmitting device sends an HDCP capability negotiation request through this link to obtain the HDCP version information of the receiving device . The receiving device returns the HDCP version information it supports . The transmitting device matches its own HDCP version with . The negotiation result ; If the version match is successful, that is True, both parties enter the key negotiation phase. The transmitting device generates an HDCP key based on the negotiation result and segments the key for transmission. Suppose the key is divided into data segments . The generation of each data segment is expressed as: ; Among them, represents the key segmentation function. The transmitting device uses the session key to encrypt each key data segment to obtain the encrypted key data segment : ; These encrypted key data segments are sequentially transmitted to the receiving device through the HDCP physical link . After receiving, the receiving device uses the session key to decrypt each to recover the original key data segment : ; The receiving device reorganizes the decrypted key data segment to recover the complete HDCP key. . The reorganization process is expressed as: ; Wherein, represents a key reorganization function. To verify the integrity of the key transmission, the sending device generates an HDCP key verification code , and the calculation method is: ; Wherein, is a predefined hash function. The sending device encrypts with the session key and sends it to the receiving device: ; After receiving, the receiving device decrypts it to obtain , and independently calculates the local key verification code based on the received . If: ; then generate the HDCP key verification result True. At this time, the sending device enables its video data input channel and uses to encrypt the input video signal to obtain the encrypted video signal : ; The encrypted video signal is transmitted to the receiving device through the HDCP physical link to ensure data security during the transmission process.

[0033] Before generating the HDCP key based on the HDCP version negotiation result, it further includes: collecting the usage data and verification results of historical HDCP keys, extracting feature parameters such as key length, update frequency, and encryption algorithm type therefrom to obtain encrypted feature training data; constructing a first deep neural network including an input layer, a first hidden layer, a second hidden layer, and an output layer, training the model with the encrypted feature training data to obtain an encrypted parameter optimization model; constructing a second deep neural network including an input layer, a first convolutional layer, a second convolutional layer, and an output layer, training the model with the security level evaluation results of encrypted data to obtain a security strength evaluation model; inputting the currently to-be-processed HDCP version negotiation result into the encrypted parameter optimization model to perform dynamic optimization calculation on the generation parameters of the HDCP key, obtaining optimized key generation parameters; generating a candidate HDCP key based on the optimized key generation parameters, inputting the candidate HDCP key into the security strength evaluation model for security evaluation to obtain a security strength evaluation result; comparing the security strength evaluation result with a preset security threshold, when the security strength evaluation result is greater than the preset security threshold, taking the candidate HDCP key as the final HDCP key; when the security strength evaluation result is less than or equal to the preset security threshold, re-executing the calculation process of the encrypted parameter optimization model until an HDCP key meeting the security requirements is obtained; recording the usage data and verification results of the finally determined HDCP key, and adding the recording result to the encrypted feature training data for online incremental learning of the first deep neural network and the second deep neural network.

[0034] In a specific embodiment, the process of executing step S500 may specifically include the following steps: Reading a preset heartbeat detection time interval, and generating a heartbeat detection trigger instruction based on the heartbeat detection time interval; Generating a random sequence by the video signal sending device based on the heartbeat detection trigger instruction, and encapsulating the random sequence to obtain heartbeat detection information; Encrypting the heartbeat detection information with the session key to obtain encrypted heartbeat detection information; Transmitting the encrypted heartbeat detection information, and decrypting the encrypted heartbeat detection information by the video signal receiving device with the session key to obtain decrypted heartbeat detection information; Digitally signing the decrypted heartbeat detection information by the video signal receiving device to obtain a heartbeat response information, and encrypting the heartbeat response information with the session key to obtain encrypted heartbeat response information; Transmitting the encrypted heartbeat response information, and decrypting the encrypted heartbeat response information by the video signal sending device with the session key to obtain decrypted heartbeat response information; Verify the digital signature in the decrypted heartbeat response information to obtain the connection status confirmation result.

[0035] Specifically, read the time parameter from the preset heartbeat detection time interval , which defines the periodic time interval for the sending device to send heartbeat detection information to the receiving device. Based on , generate a heartbeat detection trigger instruction , used to notify the sending device to start the heartbeat detection process at each time interval. The generation of the trigger instruction is expressed as: ; Among them, is the trigger instruction generation function, ensuring that the heartbeat detection is periodically triggered according to the preset time interval. When the heartbeat detection trigger instruction is issued, the video signal sending device generates a random sequence , which is a high-entropy and unpredictable numerical value used to uniquely identify this heartbeat detection. The generation of the random sequence is expressed as: ; Among them, is the random number generation function, ensuring the randomness and uniqueness. The sending device performs encapsulation processing on to generate the complete heartbeat detection information : ; Among them, is the encapsulation function, used to add necessary identification information, such as timestamps and device IDs, to the random sequence to prevent information from being forged. To ensure that the heartbeat detection information is not tampered with or eavesdropped during transmission, the sending device uses the session key to perform an encryption operation on to generate the encrypted heartbeat detection information : ; Among them, is the encryption function, implemented based on a symmetric encryption algorithm (such as AES). The generated is then transmitted to the video signal receiving device through a secure communication channel. After receiving , the receiving device uses the same session key to perform a decryption operation on it to restore the original heartbeat detection information : ; Among them, is the decryption function, which is the same as Are inverse operations. After decryption is completed, the receiving device extracts the random sequence from and performs a digital signature operation on it to generate a heartbeat response message : : ; where is the signature function implemented by the private key of the receiving device, which is used to prove the authenticity and integrity of the response message. To ensure that the heartbeat response message is not tampered with during the return process, the receiving device also uses the session key to encrypt, generating an encrypted heartbeat response message : ; The encrypted heartbeat response message is sent back to the video signal sending device through the communication channel. After receiving , the sending device uses the session key to decrypt it, obtaining the decrypted heartbeat response message : ; The sending device uses the public key of the receiving device to verify the digital signature in the heartbeat response message to ensure the source and integrity. The verification process is expressed as: ; where is the verification function. If the verification passes, it indicates that the signature is legal and the heartbeat detection response message has not been tampered with. The sending device generates a connection status confirmation result according to the verification result: ; If is True, it indicates that the connection status is normal; otherwise, it is considered that there is an abnormality in the connection.

[0036] In a specific embodiment, the process of executing step S600 may specifically include the following steps: According to the connection status confirmation result, the video signal sending device performs abnormal status detection on the first signature information, the second signature information, the EDID verification passed information, the HDCP key verification result, and the heartbeat response message, obtaining the sending end abnormal status information; The video signal receiving device detects the abnormal status of the first signature information, the second signature information, the EDID verification passed information, the HDCP key verification code, and the heartbeat detection information to obtain the receiving end abnormal status information; Generate an abnormal status flag bit based on the sending end abnormal status information and the receiving end abnormal status information, and perform a status judgment on the abnormal status flag bit to obtain an abnormal handling trigger instruction; Based on the abnormal handling trigger instruction, close the video signal sending channel of the video signal sending device to obtain a video signal sending interruption instruction, and based on the abnormal handling trigger instruction, close the HDMI receiving channel of the video signal receiving device to obtain an HDMI receiving interruption instruction; Confirm the status of the video signal sending interruption instruction and the HDMI receiving interruption instruction to obtain the channel closing status information, and generate a reconstruction instruction for the video signal transmission link based on the channel closing status information.

[0037] Specifically, according to the connection status confirmation result , the video signal sending device detects the abnormal status of multiple key verification information. The inputs for detection include the first signature information , the second signature information , the EDID verification passed information , the HDCP key verification result , and the heartbeat response information . The sending device generates the sending end abnormal status information by detecting whether these information meet the expectations . The detection rule is expressed as: ; Among them, is the abnormal detection function of the sending device. If all inputs pass the verification, then Normal; otherwise represents the specific abnormal type, such as signature failure, EDID verification failure, or heartbeat response mismatch. At the same time, the video signal receiving device detects the abnormal status of the verification information related to it. The inputs include the first signature information , the second signature information , the EDID verification passed information , the HDCP key verification code , and the heartbeat detection information . The receiving device generates the receiving end abnormal status information by detecting the integrity and consistency of these information : ; Among them, It is an abnormal detection function of the receiving device. Similar to the sending device, its output is a normal state or a specific abnormal type. Based on and generate an abnormal state identification bit . The abnormal state identification bit is a set of binary bits used to represent the comprehensive abnormal state of the sending end and the receiving end. The generation rule is as follows: ; Among them, is the identification bit generation function. For example, if both the sending end and the receiving end are normal, then If the sending end is abnormal, then If the receiving end is abnormal, then If both sides are abnormal, then . Based on , judge the abnormal state and generate an abnormal handling trigger instruction . The state judgment rule is expressed as: ; If Trigger, it indicates that there is an abnormal state and the system needs to further process. Once the abnormal handling instruction is triggered, the system first closes the video signal sending channel of the video signal sending device and generates a video signal sending interruption instruction : ; At the same time, the HDMI receiving channel of the receiving device will also be closed, generating an HDMI receiving interruption instruction : ; The purpose of the closing operation is to isolate the transmission link and prevent the further spread of the abnormal state. After the sending channel and the receiving channel are closed, the execution status of the interruption instructions and is confirmed, generating channel closing status information : ; Among them, is the status confirmation function. If both channels are successfully closed, then Closed; otherwise, the system will try to close the channels again. After the channel closing status is confirmed, the system generates a reconstruction instruction for the video signal transmission link based on : ; If ​Rebuild, the system will re-initialize the authentication and connection operations between the sending device and the receiving device.

[0038] Please refer to Figure 2 , Figure 2 , which is a schematic block diagram of the structure of the video signal dynamic encryption authentication system 200 provided by the embodiment of the present application. As Figure 2 shown, the video signal dynamic encryption authentication system 200 includes: An authentication module 210, configured to perform two-way challenge-response authentication on the video signal sending device and the video signal receiving device to obtain a two-way identity authentication result; A key calculation module 220, configured to perform session key calculation on the video signal sending device and the video signal receiving device based on the two-way identity authentication result to obtain a session key; A verification module 230, configured to perform EDID verification on the video signal receiving device to obtain encrypted EDID verification passed information; An encryption transmission module 240, configured to perform encrypted transmission of the HDCP key and video signal encryption processing according to the encrypted EDID verification passed information to obtain an encrypted video signal; A response detection module 250, configured to perform device heartbeat response detection according to the encrypted video signal to obtain a connection status confirmation result; A reconstruction module 260, configured to control the video signal transmission status of the video signal sending device and the HDMI receiving channel of the video signal receiving device according to the connection status confirmation result to obtain a reconstruction instruction for the video signal transmission link.

[0039] Through the collaborative cooperation of the above-mentioned components, by establishing a two-way challenge-response authentication mechanism, two-way identity verification of the video signal sending device and the receiving device is realized, effectively preventing the access of illegal devices and man-in-the-middle attacks. The Diffie-Hellman key exchange algorithm is used to dynamically generate session keys, improving the security of the keys and ensuring the encryption strength of the subsequent communication process. Combining EDID verification and HDCP encryption, a multi-level security protection system is constructed, effectively preventing the illegal interception and copying of video signals. Through the heartbeat detection mechanism, real-time monitoring of the device connection status is realized, and abnormal situations can be detected and processed in a timely manner. A complete exception handling and link reconstruction mechanism is designed, which can quickly cut off video transmission when a security threat is detected and automatically reconstruct a secure link. A segmented data processing and verification scheme is adopted to improve the fault tolerance and reliability of the system, ensuring the continuity and stability of video signal transmission.

[0040] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the systems, systems, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0041] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: various media that can store program codes such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.

[0042] The above is the case. The above embodiments are only used to illustrate the technical solutions of the present application and are not intended to limit them. Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments or perform equivalent replacements for some of the technical features. These modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present application.

Claims

1. A dynamic encryption and authentication method for video signals, characterized in that, Including: Performing two-way challenge-response authentication on the video signal sending device and the video signal receiving device to obtain a two-way identity authentication result; Based on the two-way identity authentication result, calculating a session key for the video signal sending device and the video signal receiving device to obtain a session key; Performing EDID verification on the video signal receiving device to obtain encrypted EDID verification passed information; According to the encrypted EDID verification passed information, performing encrypted transmission of the HDCP key and video signal encryption processing to obtain an encrypted video signal; Performing device heartbeat response detection according to the encrypted video signal to obtain a connection status confirmation result; According to the connection status confirmation result, controlling the video signal transmission status of the video signal sending device and the HDMI receiving channel of the video signal receiving device to obtain a reconstruction instruction for the video signal transmission link.

2. The video signal dynamic encryption and authentication method according to claim 1, characterized in that The performing two-way challenge-response authentication on the video signal sending device and the video signal receiving device to obtain a two-way identity authentication result includes: Initializing the public-private key pairs preset in the video signal sending device and the public-private key pairs preset in the video signal receiving device to obtain two independent pairs of asymmetric keys; Generating a first random number by the video signal sending device and encapsulating the first random number to obtain a first authentication challenge message; Sending the first authentication challenge message, receiving the first authentication challenge message by the video signal receiving device, and digitally signing the first authentication challenge message using the private key preset in the video signal receiving device to obtain a first signature message; Transmitting the first signature message, and verifying the first signature message by the video signal sending device using the public key preset in the video signal receiving device to obtain a first verification result; Generating a second random number by the video signal receiving device and encapsulating the second random number to obtain a second authentication challenge message; Sending the second authentication challenge message, receiving the second authentication challenge message by the video signal sending device, and digitally signing the second authentication challenge message using the private key preset in the video signal sending device to obtain a second signature message; Transmitting the second signature message, and verifying the second signature message by the video signal receiving device using the public key preset in the video signal sending device to obtain a second verification result; Performing a logical AND operation based on the first verification result and the second verification result to obtain a two-way identity authentication result.

3. The video signal dynamic encryption and authentication method according to claim 2, characterized in that The calculating a session key for the video signal sending device and the video signal receiving device based on the two-way identity authentication result to obtain a session key includes: Performing a conditional judgment based on the two-way identity authentication result, and executing a key exchange start instruction when the two-way identity authentication result is true; Based on the key exchange start instruction, initialize the preset large prime number p and primitive root g, and send the large prime number p and the primitive root g to the video signal sending device and the video signal receiving device respectively to obtain key exchange parameters; The video signal sending device generates an integer e as the first private key, and performs modular exponentiation on the primitive root g and the first private key a to obtain a first random key parameter; The video signal receiving device generates an integer f as the second private key, and performs modular exponentiation on the primitive root g and the second private key b to obtain a second random key parameter; Send the first random key parameter, and the video signal receiving device receives the first random key parameter, and performs modular exponentiation on the first random key parameter and the second private key b to obtain a first session key; Send the second random key parameter, and the video signal sending device receives the second random key parameter, and performs modular exponentiation on the second random key parameter and the first private key to obtain a second session key; Perform consistency verification on the first session key and the second session key to obtain a consistency verification result, and select the first session key or the second session key based on the consistency verification result to obtain a session key.

4. The video signal dynamic encryption and authentication method according to claim 3, characterized in that, The EDID verification of the video signal receiving device to obtain the encrypted EDID verification passed information includes: Initialize the DDC channel of HDMI, establish an I2C communication link between the video signal sending device and the video signal receiving device, and obtain a DDC channel reading instruction; Based on the DDC channel reading instruction, read the EDID raw data from the EDID register of the video signal receiving device, and parse the EDID raw data to obtain EDID information; Perform segmentation processing on the EDID information, extract the resolution information segment, manufacturer identification information segment, and product identification information segment from the EDID information to obtain the characteristic data of the video signal receiving device; Read the pre-stored device characteristic information from the memory, perform segmentation processing on the pre-stored device characteristic information, and extract the expected resolution information segment, expected manufacturer identification information segment, and expected product identification information segment to obtain expected characteristic data; Compare the resolution information segment in the characteristic data with the expected resolution information segment in the expected characteristic data to obtain a resolution matching result; Compare the manufacturer identification information segment and product identification information segment in the characteristic data with the expected manufacturer identification information segment and expected product identification information segment in the expected characteristic data to obtain a device identification matching result; Perform a logical AND operation based on the resolution matching result and the device identification matching result to generate EDID verification passed information, and encrypt the EDID verification passed information using the session key to obtain the encrypted EDID verification passed information.

5. The video signal dynamic encryption and authentication method according to claim 4, wherein Performing encrypted transmission of the HDCP key and encrypted processing of the video signal according to the encrypted EDID verification passed information, obtaining an encrypted video signal, including: The video signal receiving device decrypts the encrypted EDID verification passed information using the session key, obtains the decrypted EDID verification passed information, and verifies the decrypted EDID verification passed information to obtain an HDCP start instruction; Based on the HDCP start instruction, an HDMI connection is established between the video signal transmitting device and the video signal receiving device, and the HDMI connection is enabled for HDCP to obtain an HDCP physical link; The video signal transmitting device sends an HDCP capability negotiation request through the HDCP physical link, obtains the HDCP version information of the video signal receiving device and performs version matching to obtain an HDCP version negotiation result; Generating an HDCP key based on the HDCP version negotiation result, segmenting the HDCP key to obtain key data segments, and encrypting the key data segments using the session key to obtain encrypted key data segments; Transmitting the encrypted key data segments, the video signal receiving device receives the encrypted key data segments and decrypts them using the session key, and recombines them to obtain the HDCP key; The video signal transmitting device generates an HDCP key verification code, performs encrypted transmission of the HDCP key verification code, and the video signal receiving device verifies it to obtain an HDCP key verification result; Based on the HDCP key verification result, the video data input channel of the video signal transmitting device is enabled, and the input video signal is encrypted using the HDCP key to obtain an encrypted video signal.

6. The video signal dynamic encryption and authentication method according to claim 5, characterized in that, Performing device heartbeat response detection according to the encrypted video signal to obtain a connection status confirmation result, including: Reading a preset heartbeat detection time interval, and generating a heartbeat detection trigger instruction based on the heartbeat detection time interval; Based on the heartbeat detection trigger instruction, the video signal transmitting device generates a random sequence, encapsulates the random sequence to obtain a heartbeat detection message; Encrypting the heartbeat detection message using the session key to obtain an encrypted heartbeat detection message; Transmitting the encrypted heartbeat detection message, the video signal receiving device decrypts the encrypted heartbeat detection message using the session key to obtain a decrypted heartbeat detection message; The video signal receiving device performs digital signature on the decrypted heartbeat detection message to obtain a heartbeat response message, and encrypts the heartbeat response message using the session key to obtain an encrypted heartbeat response message; Transmitting the encrypted heartbeat response message, the video signal transmitting device decrypts the encrypted heartbeat response message using the session key to obtain a decrypted heartbeat response message; Verifying the digital signature in the decrypted heartbeat response message to obtain a connection status confirmation result.

7. The video signal dynamic encryption and authentication method according to claim 6, wherein According to the connection status confirmation result, controlling the video signal transmission status of the video signal sending device and the HDMI receiving channel of the video signal receiving device to obtain a reconstruction instruction for the video signal transmission link, including: According to the connection status confirmation result, the video signal sending device performs abnormal state detection on the first signature information, the second signature information, the EDID verification passed information, the HDCP key verification result, and the heartbeat response information to obtain the sending end abnormal state information; The video signal receiving device performs abnormal state detection on the first signature information, the second signature information, the EDID verification passed information, the HDCP key verification code, and the heartbeat detection information to obtain the receiving end abnormal state information; Generating an abnormal state flag bit based on the sending end abnormal state information and the receiving end abnormal state information, and performing a status judgment on the abnormal state flag bit to obtain an abnormal processing trigger instruction; Based on the abnormal processing trigger instruction, closing the video signal sending channel of the video signal sending device to obtain a video signal sending interruption instruction, and based on the abnormal processing trigger instruction, closing the HDMI receiving channel of the video signal receiving device to obtain an HDMI receiving interruption instruction; Performing a status confirmation on the video signal sending interruption instruction and the HDMI receiving interruption instruction to obtain a channel closing status information, and generating a reconstruction instruction for the video signal transmission link based on the channel closing status information.

8. A video signal dynamic encryption and authentication system, characterized in that For executing the video signal dynamic encryption authentication method according to any one of claims 1-7, including: An authentication module, configured to perform two-way challenge-response authentication on the video signal sending device and the video signal receiving device to obtain a two-way identity authentication result; A key calculation module, configured to perform session key calculation on the video signal sending device and the video signal receiving device based on the two-way identity authentication result to obtain a session key; A verification module, configured to perform EDID verification on the video signal receiving device to obtain encrypted EDID verification passed information; An encryption transmission module, configured to perform encrypted transmission of the HDCP key and video signal encryption processing according to the encrypted EDID verification passed information to obtain an encrypted video signal; A response detection module, configured to perform device heartbeat response detection according to the encrypted video signal to obtain a connection status confirmation result; A reconstruction module, configured to control the video signal transmission status of the video signal sending device and the HDMI receiving channel of the video signal receiving device according to the connection status confirmation result to obtain a reconstruction instruction for the video signal transmission link.

Citation Information

Patent Citations

  • Account password changing method, system and device

    CN110890959A

  • Apparatus and methods for content distribution to packet-enabled devices via a network bridge

    US20130227284A1