Video security access management method and system
Through multi-dimensional checksum intelligent processing, the problem of single logic and low degree of automation in the video secure access management system is solved, efficient illegal access interception and priority transmission of key videos are achieved, and the stability and resource utilization of the system are improved.
Patent Information
- Application Number
- CN202510947524.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-10
- Publication Date
- 2025-08-22
- Estimated Expiration
- 2045-07-10
AI Technical Summary
The existing video secure access management system has a single logic in the access control, and cannot take into account the multi-dimensional verification of protocols and permissions. The abnormal traffic cleaning lacks a hierarchical handling mechanism, the error judgment rate is high, the degree of automation is low, and it is difficult to cope with large-scale network environments.
By verifying that the terminal access rules match the access information, the request frequency and packet loss rate are calculated, the hierarchical link exception is adjusted, and the multi-dimensional checksum intelligent processing is realized.
It improves the interception rate of illegal access, reduces the misjudgment rate, improves transmission stability and resource utilization, ensures priority transmission of key videos, and reduces video lag.
Smart Images

Figure CN120528697A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of video security technology, and in particular to a video security access management method and system. Background Art
[0002] Video surveillance faces various security threats, among which the theft and tampering of video content are the most common security threats faced by video surveillance.
[0003] Patent application CN116846684B discloses a video security access management method and system that acquires access video data and encrypted weather data; decrypts the encrypted weather data to acquire decrypted weather data; acquires verification weather data based on basic access information; performs access verification on the decrypted weather data based on the verification weather data, and plays the access video data after the access verification passes. The system is capable of acquiring access video data and encrypted weather data from the access management data, requiring only decryption and access verification of the encrypted weather data. Once the verification passes, the access video data is played. This eliminates the need to encrypt the entire video surveillance data during video security access management, reducing the workload of encryption processing and eliminating the need for extensive computing resources for encryption and decryption. Furthermore, the system can verify theft and tampering of video, ensuring secure access and use of the access video data.
[0004] However, although existing technologies can achieve basic access control and flow monitoring, they have the following shortcomings: The access matching logic is simple and cannot take into account the multi-dimensional verification of protocols and permissions; Abnormal traffic cleaning lacks a hierarchical handling mechanism, resulting in a high misjudgment rate; Link exception handling relies on manual intervention, has a low degree of automation, and is difficult to cope with large-scale network environments. Summary of the Invention
[0005] In view of the shortcomings of the existing technology, the present invention provides a video security access management method and system, which solves the problem of grading links according to packet loss rate and realizing intelligent adjustment of transmission strategy in combination with MTU and priority.
[0006] To achieve the above objectives, the present invention is implemented through the following technical solutions: a video security access management method, the method comprising the following steps: Verify whether the terminal access rules match the access video information and generate a signal to allow or not allow access; Analyze the access permission signal, calculate the request frequency of the allowed access IP, compare it with the preset value to generate abnormal signals, determine the abnormal level and clean the traffic; Perform dynamic perception analysis on incoming video, classify normal or abnormal links based on packet loss rate, and further classify them into primary and secondary abnormal links based on packet loss rate and threshold value; Analyze abnormal links at the first level. If the link can be skipped, adjust the routing policy. If the link cannot be skipped, generate a priority transmission or fragmentation processing signal based on the relationship between MTU and data volume. The priority transmission analysis signal is processed, and the real-time demand index and bandwidth occupancy index of the real-time video transmission are weighted and summed to obtain the priority index. The priority index is then sorted and transmitted from large to small. The fragmentation processing signal is processed, and the real-time transmission video is fragmented and transmitted based on the transmission mean corresponding to the first-level abnormal link, generating video transmission information. Adapt the secondary abnormal links, and use the maximum transmission unit of the normal link as the standard to screen the normal links that meet the real-time transmission adaptation and record them as links to be analyzed. Adapt them according to the priority index to generate video transmission information.
[0007] As a further solution of the present invention, the specific method of generating the access permission or non-access permission signal is: The terminal access rules and access video information are obtained to determine whether the two match. If any of the access protocols or access permissions is not satisfied, an access-not-allowed signal is generated; otherwise, an access-allowed signal is generated.
[0008] As a further solution of the present invention, the specific method of analyzing the access permission signal is: The IP source of the video to be accessed is obtained, and the corresponding number of requests within the time t is obtained. The corresponding request frequency is calculated and compared with the preset value. If the request frequency is greater than the preset value, an abnormal request analysis signal is generated. Conversely, if the request frequency is less than the preset value, a normal request monitoring signal is generated. Then, the generated abnormal request analysis signal is analyzed to obtain the request frequency. If the frequency exceeds the threshold by 10%, a level one warning signal is generated; if the frequency exceeds the threshold by 50%, a level two warning signal is generated; if the frequency exceeds the threshold by 100%, a level three warning signal is generated. At the same time, abnormal traffic is identified based on the IPS feature library, intercepted, and cleaned.
[0009] As a further solution of the present invention, the specific method of performing dynamic perception analysis on the access video is: The transmission link is labeled i, where i = 1, 2, ..., j, where j represents the number of transmission links. Its packet loss rate is obtained, denoted as Pi, and compared with the packet loss rate threshold. If the packet loss rate Pi is greater than the packet loss rate threshold, the corresponding link is marked as an abnormal link. Otherwise, the corresponding link is marked as a normal link. Abnormal links are labeled as a, where a=1, 2, ..., b, where b represents the number of abnormal links. Links with packet loss rates less than 50% of the packet loss rate threshold are labeled as first-level abnormal links, and links with packet loss rates exceeding 50% of the packet loss rate threshold are labeled as second-level abnormal links. At the same time, first-level abnormal links are obtained and labeled as a1, where a1=1, 2, ..., b1. Second-level abnormal links are labeled as a2, where a2=1, 2, ..., b2, where b1+b2=b.
[0010] As a further solution of the present invention, the specific method of analyzing the first-level abnormal link is: Obtain all first-level abnormal links and their corresponding routing policies, and determine whether transmission can be skipped. If so, generate routing policy adjustment information; otherwise, generate link adjustment signals; The link adjustment signal is analyzed to obtain the MTU value corresponding to the first-level abnormal link a1 and compare it with the data volume corresponding to the real-time transmission video. If the former is greater than the latter, hierarchical transmission is performed according to the priority of the real-time transmission video, and a priority transmission analysis signal is generated. Conversely, if the former is less than the latter, the real-time transmission video is fragmented and a fragmentation processing signal is generated.
[0011] As a further solution of the present invention, the specific method of processing the priority transmission analysis signal is: Obtain the corresponding real-time transmission video in the first-level abnormal link a1 and record it as Qa1, and Q=1, 2, ..., H, where H represents the type of real-time transmission video. According to the formula Calculate the real-time demand index, where T is the allowed delay, according to the formula Calculate broadband occupancy indicators; According to the formula The priority index RQa1 corresponding to the real-time transmission video Qa1 is calculated, where and is the weight coefficient, and the real-time transmission video is transmitted according to the priority index from large to small.
[0012] As a further solution of the present invention, the specific method of adapting the secondary abnormal link is: Obtain the secondary abnormal link, normal link, and their real-time transmission speed, as well as the video transmission volume of the abnormal link. Compare the video transmission volume with the MTU of the normal link to select the link to be analyzed that can carry the load. The links to be analyzed are arranged in descending order according to the real-time transmission speed. The priority index of the abnormal link video is calculated and sorted in descending order. Taking the fastest link to be analyzed as the standard, the abnormal link video with the highest priority is adapted in turn to complete the round-robin processing.
[0013] A video security access management system, the system comprising: Access information collection module, which is used to obtain terminal access rules and access video information, match the two, generate an access permission signal or a non-access permission signal, and transmit the former to the normal access analysis module; Normal access analysis module: This module is used to analyze the access permission signal, calculate the request frequency of the corresponding access IP source, and compare it with the preset value to generate an abnormal request analysis signal. At the same time, it determines the abnormal level corresponding to the request frequency, then identifies abnormal traffic and cleans it. Finally, the cleaned access video is transmitted to the dynamic perception analysis module; Dynamic perception and analysis module, which is used to perform dynamic perception analysis on the incoming video, classify the transmission links into normal links and abnormal links based on the packet loss rate, and perform secondary classification of abnormal links based on the packet loss rate to generate primary abnormal links and secondary abnormal links, and then transmit the two to the link adaptation processing module; The link adaptation processing module is used to adapt and process the first-level abnormal and second-level abnormal links, obtain the first-level abnormal link and skip the transmission to generate link routing policy adjustment information. At the same time, for situations where skipping transmission is not possible, the module compares the real-time transmitted video with the maximum transmission unit value and generates a priority transmission analysis signal or a fragmentation processing signal. The priority transmission analysis signal is processed to analyze the real-time demand index and bandwidth occupancy index of the real-time video transmission, and the priority index is obtained by weighted summation. The signals are then sorted and transmitted from large to small. The fragmentation processing signal is processed and the real-time video transmission is fragmented and transmitted based on the transmission mean value corresponding to the first-level abnormal link. The video transmission information is generated and transmitted to the access management information output module at the same time. Adapt the secondary abnormal links, select the normal links that meet the real-time transmission adaptation standard based on the maximum transmission unit of the normal links, and record them as links to be analyzed. Adapt them according to the priority indicators, generate video transmission information, and transmit it to the access management information output module; The access management information output module is used to transmit the access video according to the acquired video transmission information.
[0014] The present invention provides a video security access management method and system. Compared with the existing technology, it has the following advantages: By integrating four layers of verification, namely terminal type, protocol whitelist, and device / personnel authority, this invention improves the interception rate of illegal access compared to traditional single IP / MAC binding. It calculates the request frequency based on the time window t and accurately identifies the attack level in combination with a three-level early warning mechanism. Compared with fixed threshold strategies, it reduces the false positive rate and integrates security policy blocking with switch hardware linkage to achieve a response from traffic identification to physical blocking in seconds.
[0015] The present invention divides abnormal links into primary / secondary according to the packet loss rate. The primary abnormality gives priority to route jump or MTU adaptation, and the secondary abnormality triggers link reconstruction, thereby improving transmission stability. The priority is calculated based on the weighted real-time demand index and bandwidth occupancy index to ensure the priority transmission of key videos and reduce the video freeze rate. In the secondary abnormal link scenario, the present invention automatically selects the links to be analyzed whose MTU is larger than the video transmission volume of the normal link, adapts in order of speed and priority, improves resource utilization, and dynamically fragments according to the transmission mean of the primary abnormal link. Compared with the fixed fragmentation strategy, the packet loss retransmission rate is reduced. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 It is a diagram of the steps and methods of the present invention; Figure 2 This is a system block diagram of the present invention. DETAILED DESCRIPTION
[0017] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0018] For example 1, please refer to Figure 1 The present application provides a video security access management method, which specifically includes the following steps: Step S1: Obtain terminal access rules, which include terminal type restrictions (e.g., camera, NVR), access protocol whitelists (e.g., RTSP, GB28181), permission levels (e.g., "read-only," "read-write," "management"), and IP / MAC address binding requirements. Video information corresponding to the video to be accessed is obtained, including the access protocol and access permissions. The specific access permissions are specifically represented by the permissions of the corresponding device and personnel. The obtained video information is matched with the terminal access rules. If the two match, specifically indicating that the access protocol (e.g., the RTSP protocol version and port number reported by the device) and the access permissions all include device permissions (e.g., preview / control permissions for "camera 1" and personnel permissions (e.g., role permissions for the account "admin") satisfy the terminal access rules, then an access-allowed signal is generated. Conversely, if the two do not match, specifically indicating that any of the access protocol or access permissions is not satisfied, then an access-denied signal is generated. For the generated access-denied signal, the corresponding exception reason is obtained and transmitted to the corresponding management personnel.
[0019] The specific matching method is as follows: Protocol matching: Checks whether the access protocol is in the protocol whitelist of the access rule (for example, if the rule requires the use of the GB28181 protocol, it will not match if the device uses RTSP).
[0020] Permission matching: Device permissions: Verify whether the device to be connected has the operating permissions required by the rules (for example, if the rule requires that the device must support "pan / tilt control", if the device only supports "preview", it does not match); Personnel permissions: Verify whether the role of the access account meets the rule level (for example, if the rule requires "management" permissions, it will not match if the account is "read-only").
[0021] Comprehensive judgment: When the protocol, device permissions, and personnel permissions all meet the access rules, an access permission signal is generated; If the protocols do not match, or any of the device / personnel permissions are not met, a signal not allowing access is generated.
[0022] Step S2: Analyze the generated access permission signal, obtain the IP source of the video to be accessed, and obtain the number of requests corresponding to the time t. The specific value of time t is set by the operator, and calculate the corresponding request frequency. Request frequency = number of requests within time t / time t. For example, 150 requests within 5 minutes (300 seconds) means a frequency of 0.5 times / second. Compare the request frequency with a preset value. If the request frequency is greater than the preset value, an abnormal request analysis signal is generated. Conversely, if the request frequency is less than the preset value, a normal request monitoring signal is generated. Then, the generated abnormal request analysis signal is analyzed to obtain the request frequency, and the corresponding abnormal level is determined based on the request frequency. Specifically, the request frequency is matched with the level judgment interval. The abnormal level includes three levels. If the frequency exceeds the threshold by 10%, a level 1 warning signal is generated. If the frequency exceeds the threshold by 50%, a level 2 warning signal is generated. If the frequency exceeds the threshold by 100%, a level 3 warning signal is generated. At the same time, abnormal traffic is identified based on the IPS feature library. For example, if the HTTP request contains the string ".. / .. / etc / passwd", it may be a path traversal attack and is intercepted. The obtained abnormal traffic is cleaned and cleaned from the following aspects: Security policy-based cleaning Path: [Access Control] > [Behavior Rules] > [Security Policy] Configuration: Add a new policy "Reject abnormal traffic", set the source area to "External network", the destination IP to "Intranet server", select "All" for service type, and set the action to "Reject".
[0023] Example: Block all access from public IPs to port 80 on the intranet and only allow access from whitelisted IPs. The path is [Terminal Whitelist] > Add Trusted IP.
[0024] Hardware acceleration and linkage cleaning Path: [Admission Control] > [Switch Linkage] Configuration: Enter the SNMP server IP and community name, enable "Switch Link Blocking", and set the timeout to 5 seconds. When an abnormal MAC address is detected, the switch will be linked to add it to the blacklist.
[0025] Example: A terminal's MAC address frequently changes IP address to launch an attack. The device works with the switch to block the MAC address and physically cut off the connection.
[0026] Step S3: Dynamically perceive and analyze the access video, obtain all transmission links and label them as i, where i=1, 2, ..., j, where j represents the number of transmission links. At the same time, obtain the packet loss rate corresponding to transmission link i, which is recorded as Pi, where packet loss rate = number of lost packets / number of sent packets. Then, compare the corresponding packet loss rate Pi with a packet loss rate threshold, which is set by the operator. If the packet loss rate Pi is greater than the packet loss rate threshold, the corresponding transmission link is marked as an abnormal link. Conversely, if the packet loss rate Pi is less than the packet loss rate threshold, the corresponding transmission link is marked as a normal link. Obtain all abnormal links and label them as a, where a=1, 2, ..., b, where b represents the number of abnormal links. Then compare the packet loss rate Pa of abnormal link a with the corresponding packet loss rate threshold. Links with a packet loss rate less than 50% of the packet loss rate threshold are marked as first-level abnormal links, and links with a packet loss rate exceeding 50% of the packet loss rate threshold are marked as second-level abnormal links. At the same time, obtain first-level abnormal links and label them as a1, where a1=1, 2, ..., b1. Label second-level abnormal links as a2, where a2=1, 2, ..., b2, where b1+b2=b.
[0027] Step S4: Acquire all first-level abnormal links and their corresponding routing policies, where the routing policy specifically refers to the corresponding transmission path, and determine whether transmission can be skipped. Skipping transmission specifically refers to directly skipping the corresponding first-level abnormal link when transmitting the video. If skipping transmission is possible, specifically meaning that there is no impact on video transmission, then routing policy adjustment information is generated. Conversely, if skipping transmission is not possible, specifically meaning that there is an impact on video transmission, then a link adjustment signal is generated. Analyze the generated link adjustment signal to obtain the MTU value (maximum transmission unit) corresponding to the first-level abnormal link a1 and the data volume corresponding to the real-time transmission video, and determine the relationship between the two. If the former is greater than the latter, specifically, the MTU value is greater than the data volume, hierarchical transmission is performed according to the priority of the real-time transmission video, and a priority transmission analysis signal is generated. Conversely, if the former is less than the latter, specifically, the MTU value is less than the data volume, the real-time transmission video is fragmented and a fragmentation processing signal is generated. The generated priority transmission analysis signal is then processed to obtain the corresponding real-time transmission video in the first-level abnormal link a1 and recorded as Qa1, where Q = 1, 2, ..., H, where H represents the type of real-time transmission video. The corresponding real-time demand index and bandwidth occupancy index are then calculated and weighted summed to obtain the corresponding priority index. The real-time transmission video is then transmitted in descending order of priority index. The specific method of real-time demand indicators is as follows: Calculate the real-time requirement index, where T is the allowed delay, and the specific value is determined by the maximum delay allowed for real-time video transmission; The specific calculation method of broadband occupancy index is as follows: ; The real-time demand indicators and broadband occupancy indicators Perform weighted summation, according to the formula The priority index RQa1 corresponding to the real-time transmission video Qa1 is calculated, where and are the corresponding weight coefficients respectively; The generated fragmentation processing signal is analyzed to obtain the transmission mean corresponding to the first-level abnormal link a1 within time t1, and the real-time transmission video is fragmented based on the transmission mean, and the fragmented real-time transmission video is transmitted at the same time.
[0028] Step S5: Obtain all secondary abnormal links and all normal links, and simultaneously obtain the real-time transmission speeds corresponding to the normal links, where the real-time transmission speeds are represented as the corresponding transmission speed averages. Then, obtain the real-time transmission video corresponding to the secondary abnormal link and obtain its transmission volume. At the same time, compare the transmission volume of the real-time transmission video with the maximum transmission unit of the normal link, and select the normal link that meets the transmission volume as the link to be analyzed. Here, the link to be analyzed indicates that the maximum transmission unit is greater than the transmission volume. Then, perform adaptive analysis on the real-time transmission video according to the real-time transmission speed corresponding to the link to be analyzed. Obtain all links to be analyzed and their corresponding real-time transmission speeds, and sort them from large to small according to the real-time transmission speeds. Then obtain the secondary abnormal link a2 and the corresponding real-time transmission video, calculate the priority level index corresponding to the real-time transmission video, and sort them from large to small according to the priority index. Then, take the link to be analyzed corresponding to the largest real-time transmission speed as the standard, and adapt it to the real-time transmission video with the largest priority index in the secondary abnormal link a2. Similarly, all secondary abnormal links are adapted in sequence.
[0029] For example 2, please refer to Figure 2 , the present application provides a video security access management system, which includes: an access information collection module, a normal access analysis module, a dynamic perception analysis module, a link adaptation processing module and an access management information output module; An access information collection module is used to obtain terminal access rules and access video information, match the two, generate an access permission signal or a non-access permission signal, and transmit the former to the normal access analysis module. The specific processing method is the same as the processing process of step S1 in embodiment 1; Normal access analysis module, which is used to analyze the access permission signal, calculate the request frequency of the corresponding access IP source, and compare it with the preset value to generate an abnormal request analysis signal. At the same time, it determines the abnormal level corresponding to the request frequency, then identifies abnormal traffic and cleans it. Finally, the cleaned access video is transmitted to the dynamic perception analysis module. The specific processing method is similar to the processing process of step S2 in Example 1; A dynamic perception analysis module is used to perform dynamic perception analysis on the access video, classify the transmission links into normal links and abnormal links based on the packet loss rate, and perform a secondary classification of abnormal links based on the packet loss rate to generate primary abnormal links and secondary abnormal links. The specific processing method is similar to the processing process of step S3 in embodiment 1, and then the two are transmitted to the link adaptation processing module; The link adaptation processing module is used to adapt and process the first-level abnormal and second-level abnormal links, obtain the first-level abnormal link and skip the transmission to generate link routing policy adjustment information. At the same time, for situations where skipping transmission is not possible, the module compares the real-time transmitted video with the maximum transmission unit value and generates a priority transmission analysis signal or a fragmentation processing signal. The priority transmission analysis signal is processed to analyze the real-time demand index and bandwidth occupancy index of the real-time transmission video, and a weighted sum is performed to obtain a priority index. The priority index is then sorted and transmitted from large to small. The fragmentation processing signal is processed, and the real-time transmission video is fragmented and transmitted based on the transmission mean corresponding to the first-level abnormal link. Video transmission information is generated and transmitted to the access management information output module at the same time. The specific processing method is the same as the processing process of step S4 in Example 1. Adapt the secondary abnormal links, select the normal links that meet the real-time transmission adaptation standard based on the maximum transmission unit of the normal links, and record them as links to be analyzed. Adapt them according to the priority index, generate video transmission information, and transmit it to the access management information output module. The specific processing method is the same as the processing process of step S5 in Example 1. The access management information output module is used to transmit the access video according to the acquired video transmission information.
[0030] Some of the data in the above formulas are calculated based on their numerical values and are not substituted into parameter units for calculation. At the same time, the contents not described in detail in this specification belong to the existing technology known to those skilled in the art.
[0031] The above embodiments are only used to illustrate the technical method of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical method of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical method of the present invention.
Claims
1. A video security access management method, characterized in that: The method comprises the following steps: Verify whether the terminal access rules match the access video information and generate a signal to allow or not allow access; Analyze the access permission signal, calculate the request frequency of the allowed access IP, compare it with the preset value to generate abnormal signals, determine the abnormal level and clean the traffic; Perform dynamic perception analysis on incoming video, classify normal or abnormal links based on packet loss rate, and further classify them into primary and secondary abnormal links based on packet loss rate and threshold value; Analyze abnormal links at the first level. If the link can be skipped, adjust the routing policy. If the link cannot be skipped, generate a priority transmission or fragmentation processing signal based on the relationship between MTU and data volume. The priority transmission analysis signal is processed, and the real-time demand index and bandwidth occupancy index of the real-time video transmission are weighted and summed to obtain the priority index. The priority index is then sorted and transmitted from large to small. The fragmentation processing signal is processed, and the real-time transmission video is fragmented and transmitted based on the transmission mean corresponding to the first-level abnormal link, generating video transmission information. Adapt the secondary abnormal links, and use the maximum transmission unit of the normal link as the standard to screen the normal links that meet the real-time transmission adaptation and record them as links to be analyzed. Adapt them according to the priority index to generate video transmission information.
2. A video security access management method according to claim 1, characterized in that: The specific method of generating the access permission or non-access permission signal is: The terminal access rules and access video information are obtained to determine whether the two match. If any of the access protocols or access permissions is not satisfied, an access-not-allowed signal is generated; otherwise, an access-allowed signal is generated.
3. A video security access management method according to claim 1, characterized in that: The specific method of analyzing the access permission signal is as follows: The IP source of the video to be accessed is obtained, and the corresponding number of requests within the time t is obtained. The corresponding request frequency is calculated and compared with the preset value. If the request frequency is greater than the preset value, an abnormal request analysis signal is generated. Conversely, if the request frequency is less than the preset value, a normal request monitoring signal is generated. Then, the generated abnormal request analysis signal is analyzed to obtain the request frequency. If the frequency exceeds the threshold by 10%, a level one warning signal is generated; if the frequency exceeds the threshold by 50%, a level two warning signal is generated; if the frequency exceeds the threshold by 100%, a level three warning signal is generated. At the same time, abnormal traffic is identified based on the IPS feature library, intercepted, and cleaned.
4. A video security access management method according to claim 1, characterized in that: The specific method of performing dynamic perception analysis on the access video is: The transmission link is labeled i, where i = 1, 2, ..., j, where j represents the number of transmission links. Its packet loss rate is obtained, denoted as Pi, and compared with the packet loss rate threshold. If the packet loss rate Pi is greater than the packet loss rate threshold, the corresponding link is marked as an abnormal link. Otherwise, the corresponding link is marked as a normal link. Abnormal links are labeled as a, where a=1, 2, ..., b, where b represents the number of abnormal links. Links with packet loss rates less than 50% of the packet loss rate threshold are labeled as first-level abnormal links, and links with packet loss rates exceeding 50% of the packet loss rate threshold are labeled as second-level abnormal links. At the same time, first-level abnormal links are obtained and labeled as a1, where a1=1, 2, ..., b1. Second-level abnormal links are labeled as a2, where a2=1, 2, ..., b2, where b1+b2=b.
5. A video security access management method according to claim 1, characterized in that: The specific method of analyzing the first-level abnormal link is: Obtain all first-level abnormal links and their corresponding routing policies, and determine whether transmission can be skipped. If so, generate routing policy adjustment information; otherwise, generate link adjustment signals; The link adjustment signal is analyzed to obtain the MTU value corresponding to the first-level abnormal link a1 and compare it with the data volume corresponding to the real-time transmission video. If the former is greater than the latter, hierarchical transmission is performed according to the priority of the real-time transmission video, and a priority transmission analysis signal is generated. Conversely, if the former is less than the latter, the real-time transmission video is fragmented and a fragmentation processing signal is generated.
6. A video security access management method according to claim 1, characterized in that: The specific method of processing the priority transmission analysis signal is: Obtain the corresponding real-time transmission video in the first-level abnormal link a1 and record it as Qa1, and Q=1, 2, ..., H, where H represents the type of real-time transmission video. According to the formula Calculate the real-time demand index, where T is the allowed delay, according to the formula Calculate broadband occupancy indicators; According to the formula The priority index RQa1 corresponding to the real-time transmission video Qa1 is calculated, where and is the weight coefficient, and the real-time transmission video is transmitted according to the priority index from large to small.
7. A video security access management method according to claim 1, characterized in that: The specific method of adapting the secondary abnormal link is: Obtain the secondary abnormal link, normal link, and their real-time transmission speed, as well as the video transmission volume of the abnormal link. Compare the video transmission volume with the MTU of the normal link to select the link to be analyzed that can carry the load. The links to be analyzed are arranged in descending order according to the real-time transmission speed. The priority index of the abnormal link video is calculated and sorted in descending order. Taking the fastest link to be analyzed as the standard, the abnormal link video with the highest priority is adapted in turn to complete the round-robin processing.
8. A video security access management system, configured to execute the video security access management method according to any one of claims 1 to 7, characterized in that: The system includes: Access information collection module, which is used to obtain terminal access rules and access video information, match the two, generate an access permission signal or a non-access permission signal, and transmit the former to the normal access analysis module; Normal access analysis module: This module is used to analyze the access permission signal, calculate the request frequency of the corresponding access IP source, and compare it with the preset value to generate an abnormal request analysis signal. At the same time, it determines the abnormal level corresponding to the request frequency, then identifies abnormal traffic and cleans it. Finally, the cleaned access video is transmitted to the dynamic perception analysis module; Dynamic perception and analysis module, which is used to perform dynamic perception analysis on the incoming video, classify the transmission links into normal links and abnormal links based on the packet loss rate, and perform secondary classification of abnormal links based on the packet loss rate to generate primary abnormal links and secondary abnormal links, and then transmit the two to the link adaptation processing module; The link adaptation processing module is used to adapt and process the first-level abnormal and second-level abnormal links, obtain the first-level abnormal link and skip the transmission to generate link routing policy adjustment information. At the same time, for situations where skipping transmission is not possible, the module compares the real-time transmitted video with the maximum transmission unit value and generates a priority transmission analysis signal or a fragmentation processing signal. The priority transmission analysis signal is processed to analyze the real-time demand index and bandwidth occupancy index of the real-time video transmission, and the priority index is obtained by weighted summation. The signals are then sorted and transmitted from large to small. The fragmentation processing signal is processed and the real-time video transmission is fragmented and transmitted based on the transmission mean value corresponding to the first-level abnormal link. The video transmission information is generated and transmitted to the access management information output module at the same time. Adapt the secondary abnormal links, select the normal links that meet the real-time transmission adaptation standard based on the maximum transmission unit of the normal links, and record them as links to be analyzed. Adapt them according to the priority indicators, generate video transmission information, and transmit it to the access management information output module; The access management information output module is used to transmit the access video according to the acquired video transmission information.
Citation Information
Patent Citations
A video security access management method and system
CN116846684B
Self-healing security scanning method, system and device for video Internet of Things equipment
CN114500116A
Construction safety management system based on big data
CN118690923A
Video monitoring platform software and hardware encryption and decryption method based on dynamic strategy
CN119449494A