Video safety playing method and device based on multi-dimensional protection and medium
By building a four-dimensional integrated protection chain of terminal authentication, transmission optimization, and content security, we solve the problem of isolated protection in the field of large-screen safe broadcasting, achieve full-link security protection, ensure the non-repudiation of the playback source and real-time monitoring of the transmission process, and meet the stable broadcasting needs of radio and television level.
Patent Information
- Application Number
- CN202510880958.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-27
- Publication Date
- 2025-09-19
AI Technical Summary
Currently, the field of large-screen secure broadcasting is in an isolated protection state, lacking overall security protection across the entire chain and unable to meet the needs of secure playback of large-screen videos.
A video security broadcasting method based on multi-dimensional protection is adopted. Through two-factor authentication, network probes, blockchain and dynamic watermark technology, a four-dimensional integrated protection chain of terminal authentication, transmission optimization and content security is constructed to achieve the legitimacy verification of terminal devices, dynamic screening of optimal transmission paths and real-time monitoring of content.
Ensure the non-repudiation of the playback source, dynamically select the optimal transmission path, monitor and switch the transmission process in real time, provide an unalterable traceability digital fingerprint, form a closed-loop verification of content security and terminal behavior, and achieve stable broadcasting and efficient operation and maintenance at the broadcasting and television level.
Smart Images

Figure CN120676205A_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of video transmission technology, and in particular to a video security broadcasting method, device, and medium based on multi-dimensional protection. Background Art
[0002] With the rapid development of internet technology and ultra-high-definition display technology, the dissemination of audio-visual content on outdoor large-screen displays has become a core vehicle for information dissemination, advertising, and public awareness. Outdoor large-screen displays are particularly popular in live streaming scenarios, such as broadcast television, live events, and IPTV, due to their strong visual impact and wide audience reach. However, their open network environment and complex transmission links significantly increase security risks. Live broadcast signals are susceptible to malicious tampering by intermediate nodes during transmission, such as the insertion of illegal content, hotlinking, and unauthorized terminal access, leading to content leakage and bandwidth resource occupation. Network jitter and high packet loss rates can cause broadcasts to freeze or even be interrupted. In the event of a fault, failover times generally exceed broadcast-grade safety standards (≤0.5 seconds), resulting in broadcast accidents.
[0003] The fragmented protection system currently used in the field of large-screen secure broadcasting suffers from systemic security flaws. Security layers such as content encryption, transmission protocols, terminal authentication, and emergency response operate in isolation, lacking a coordinated mechanism. This fragmented protection allows attackers to infiltrate the entire system by simply breaking through a single link. For example, by forging a terminal's MAC address to bypass basic authentication, it is possible to hijack an unverified transmission channel, tamper with plaintext content, or inject illegal signals. At the same time, the data loop between the content layer and the transmission layer is broken, making it difficult to trace the source of tampering. If the encrypted content is stripped of its watermark during transmission, the system cannot block the attack in real time or locate the leaking terminal, leading to the spread of illegal content. After the illegal content spreads, the operations team needs to spend a long time manually tracing the source.
[0004] Therefore, the current security protection in the field of large-screen safe broadcasting is in an isolated protection state, with single-point protection defects and a lack of overall security protection for the entire link, which cannot meet the safe playback needs of large-screen videos. Summary of the Invention
[0005] One or more embodiments of this specification provide a method, device, and medium for secure video broadcasting based on multi-dimensional protection, which is used to solve the following technical problems: the security protection in the current large-screen secure broadcasting field is in an isolated protection state, has single-point protection defects, lacks overall security protection for the entire link, and cannot meet the safe playback requirements of large-screen videos.
[0006] One or more embodiments of this specification adopt the following technical solutions: One or more embodiments of the present specification provide a method for secure video broadcasting based on multi-dimensional protection, the method comprising: upon being triggered by a video playback request of a target broadcasting terminal, obtaining terminal device information, performing two-factor authentication on the target broadcasting terminal based on the terminal device information and terminal registration information pre-stored in a blockchain node, and determining a device authentication result; collecting real-time network indicators of each transmission path through a pre-deployed network probe, and screening a target transmission path from a plurality of transmission paths based on the real-time network indicators; when the device authentication result passes, obtaining watermark fragmentation data corresponding to the target video stream in a pre-constructed blockchain node, transmitting the watermark fragmentation data to the target broadcasting terminal through the target transmission path, and monitoring the transmission process in real time to achieve secure broadcasting of the target video stream.
[0007] One or more embodiments of this specification provide a video security broadcasting device based on multi-dimensional protection, including: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor. The instructions are executed by the at least one processor to enable the at least one processor to perform the above method.
[0008] One or more embodiments of this specification provide a non-volatile computer storage medium storing computer-executable instructions, wherein the computer-executable instructions are configured to execute the above method.
[0009] At least one of the above technical solutions adopted in the embodiments of this specification can achieve the following beneficial effects: through the technical solutions of the embodiments of this specification, by building a four-dimensional integrated protection chain of terminal authentication, transmission optimization, content security, and monitoring response, the problem of lack of full-link security caused by isolated protection status in the field of large-screen safe broadcasting is solved; through two-factor authentication, the legitimacy verification of terminal equipment is bound to the pre-stored registration information in the blockchain, breaking the separation of traditional terminal protection and identity management, ensuring the non-repudiation of the playback source, and the authentication results are synchronized to the content security module in real time, establishing a device trust foundation for subsequent content distribution; the path indicators (packet loss rate / delay / jitter) collected by the network probe are verified by the quality function The optimal transmission path is dynamically screened, and the routing decision log is written into the blockchain, so that the transmission security layer and the content distribution layer form a closed-loop linkage, avoiding the transmission hijacking risk caused by the disconnection between routing and content in traditional solutions; the watermark fragmented data is associated with the terminal device fingerprint in the blockchain to achieve a three-way binding of content, device, time and space, and the dynamic watermark is embedded in the content provider identification and geographic area code to provide an unalterable digital fingerprint for leak tracing; the watermark feature value is verified in real time during terminal playback to form a closed-loop verification of content security and terminal behavior; three-dimensional real-time monitoring of the transmission process drives multi-level emergency switching, and all operation logs and watermark feature values are stored on the chain to provide a cross-module traceability evidence chain for abnormal events. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] In order to more clearly illustrate the embodiments of this specification or the technical solutions in the prior art, the following briefly introduces the drawings required for the embodiments or the description of the prior art. Obviously, the drawings described below are only some of the embodiments described in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without inventive work. In the drawings: Figure 1 A flowchart of a video security broadcasting method based on multi-dimensional protection provided in an embodiment of this specification; Figure 2 A schematic diagram of the structure of a video security broadcasting system based on multi-dimensional protection provided in an embodiment of this specification; Figure 3 This is a structural diagram of a video security broadcasting device based on multi-dimensional protection provided in an embodiment of this specification. DETAILED DESCRIPTION
[0011] To help those skilled in the art better understand the technical solutions in this specification, the following will provide a clear and complete description of the technical solutions in the embodiments of this specification, in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of this specification, not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this specification without creative work should fall within the scope of protection of this specification.
[0012] The embodiments of this specification provide a method for secure video broadcasting based on multi-dimensional protection. It should be noted that the execution subject in the embodiments of this specification can be a server or any device with data processing capabilities. Figure 1 A flowchart of a video security broadcasting method based on multi-dimensional protection provided in an embodiment of this specification is shown as follows: Figure 1 As shown, it mainly includes the following steps: Step S101: When triggered by a video playback request from a target broadcast terminal, terminal device information is obtained to perform two-factor authentication on the target broadcast terminal based on the terminal device information and terminal registration information pre-stored in the blockchain node to determine the device authentication result.
[0013] In one embodiment of the present disclosure, terminal device information is obtained when a video playback request is triggered by a target broadcast terminal. When a broadcast terminal initiates a video playback request, the device probe module deployed in the terminal protection layer is automatically activated, generates an encrypted handshake instruction, sends a feature collection request to the terminal operating system kernel, establishes a secure communication channel, and collects real-time terminal device information from the target broadcast terminal.
[0014] Based on the terminal device information and the reliable source terminal information pre-stored in the blockchain node, a two-factor authentication is performed on the target broadcast terminal to determine the device authentication result, specifically including: generating the hardware fingerprint information and dynamic token of the target broadcast terminal based on the terminal device information; matching the target broadcast terminal with the reliable source terminal information through the hardware fingerprint information and the dynamic token to determine the device authentication result. Based on the terminal device information, the hardware fingerprint information and dynamic token of the target broadcast terminal are generated, specifically including: obtaining the CPU clock characteristics of the target broadcast terminal's CPU executing a fixed instruction sequence, and obtaining the GPU rendering instruction set characteristics and network card MAC address of the GPU executing a nonlinear transformation output; determining the hardware fingerprint information corresponding to the target broadcast terminal based on the variance value of the CPU clock characteristics, the hash value of the GPU rendering instruction set characteristics, and the hash value of the network card MAC address; generating the dynamic token corresponding to the target broadcast terminal based on the hardware fingerprint information and the pre-set seed key parameters.
[0015] In one embodiment of the present specification, three types of hardware features are collected in real time through the device probe module. First, a fixed instruction sequence containing 100 non-privileged assembly instructions is sent to the CPU, and the clock cycle difference of each instruction is recorded using a timestamp counter, and its variance value is calculated as the CPU clock feature. At the same time, a nonlinear transformation shader containing 1000 iterations is loaded, and the low 32-bit value of the final output of the GPU rendering pipeline is intercepted as the GPU rendering fingerprint to determine the GPU rendering instruction set characteristics. Finally, the physical network card MAC address is read, and a random salt value is superimposed to generate a 128-bit hash summary. The process is completed through a kernel-level secure channel. The instruction sequence is dynamically updated every 60 seconds, and clock fluctuation anomalies (>3σ) and GPU output value offsets (Manhattan distance>5) are detected in real time to ensure the authenticity and anti-counterfeiting capabilities of the features.
[0016] Based on the collected original features, an irreversible device fingerprint is generated through the SHA3-256 hash engine. The CPU clock variance value, GPU rendering output value and network card MAC hash value are spliced in a fixed order, and a one-way hash calculation is performed to generate a 256-bit unique fingerprint to determine the hardware fingerprint information. Feature extraction of the CPU: , where Var() is the variance calculation function, (i=1, 2, 3...100) is the clock cycle difference of executing a fixed instruction sequence. The feature extraction method for GPU is to perform 1000 nonlinear transformations in a loop and take the lower 32 bits of the output value as the feature, which is recorded as Finally, the fingerprint features are combined ,in, This is the 128-bit hash value of the MAC address. This execution process is performed within a trusted execution environment, meeting both real-time and security requirements. Hash calculation latency is ≤1ms, and hardware-level isolation prevents memory tampering. The generated hardware fingerprint information is immediately compared with pre-stored registration information on the blockchain to achieve device identity binding.
[0017] Dynamic tokens are generated by combining hardware fingerprint information with a time factor. First, the hardware fingerprint information is used as input to derive a seed key using the PBKDF2 algorithm (10,000 iterations). Then, based on the HMAC-SHA256 algorithm, the seed key, the anti-replay counter, and the timestamp divisibility value are used as input to generate a new token every 60 seconds. The formula for dynamic token generation is as follows: ,where HAMC-SHA256 is the encryption algorithm for generating tokens, t is the time factor, which is calculated by dividing the current timestamp by 60 and rounding down, and Counter is the anti-replay filter. is the key, calculated as: PBKDF2 is a password-based key derivation algorithm that generates encryption keys by performing multiple hash operations on the password, enhancing password strength. Salt is added to the calculated key to further enhance the security of the dynamic token. The token has a strictly limited validity period (60 ± 0.5 seconds) and is synchronized with the GPS clock to prevent time zone tampering. This token serves as a second authentication factor, forming a two-factor authentication system alongside the hardware fingerprint, effectively blocking forgery attacks.
[0018] It should be noted that the video playback terminal device needs to complete fingerprint registration when it is first connected. That is to say, when the video playback terminal device is activated, the hardware characteristics are immediately collected, and a unique terminal device fingerprint is generated according to the above method. The generated unique terminal device fingerprint is bound to the device to generate the source reliable terminal information. At the same time, when the video playback terminal device is first registered, a seed key is generated based on the hardware fingerprint, and the seed key and the source reliable terminal information are stored together in the blockchain node. When the target broadcast terminal triggers a video broadcast request, the hardware fingerprint generated in real time by the target broadcast terminal is extracted and compared with the pre-stored unique terminal device fingerprint. If the Hamming distance is not greater than the preset distance threshold, it is determined that the hardware fingerprint matches.
[0019] A dynamic token is generated in real time by the authentication server when a terminal initiates a play request. Based on the hardware fingerprint stored in the blockchain node, the authentication server iteratively derives a seed key using the PBKDF2 algorithm. This is combined with a 60-second time factor (t = ⌊current timestamp / 60⌋) and a one-way incrementing anti-replay counter to generate a dynamic token using the HMAC-SHA256 algorithm. The token is then transmitted to the terminal via a TLS 1.3 encrypted channel and temporarily stored in an encrypted memory area for 60 seconds. The key never leaves the server's secure environment. The terminal actively submits the token in a play request, and the authentication server performs time window verification, counter validation, key consistency comparison, and clock drift compensation to determine the token verification result. The time window verification checks whether the token is valid in the current period (t) or the previous period (t-1), while maintaining a ±0.5-second network latency. During counter verification, the submitted counter value is ensured to be greater than the most recently recorded value on the server to prevent replay attacks. During key consistency comparison, the token hash value is verified to match the seed key stored in the blockchain node. The timeout token triggers NTP time synchronization, and an offset of more than 500ms is considered abnormal. When the hardware fingerprint matches and the token verification passes, the device authentication result of the target broadcast terminal's two-factor authentication is determined to be authentication passed.
[0020] Through the above technical solution, two-factor authentication provides terminal access security for secure video broadcasting by deeply integrating the physical layer unclonability of hardware fingerprints and the time-sensitive credentials of dynamic tokens. In the authentication process, the hardware fingerprint's physical anchoring of the terminal device's uniqueness fundamentally eliminates the risk of counterfeit access, while the periodically refreshed dynamic token relies on an encrypted channel to accurately control access timeliness. The two work together to form a dynamic protection barrier with an extremely short attack window. At the security linkage level, this mechanism communicates with the emergency response module in real time. Authentication anomalies instantly trigger millisecond-level master-slave switching, building a resilient guarantee for zero-interruption broadcasting. At the same time, the three-way binding of fingerprint, watermark, and blockchain enables accurate tracing and rapid disposal of leakage incidents. In the system performance dimension, two-factor authentication migrates the computing load from the terminal to the server, significantly optimizing the operating efficiency of resource-constrained outdoor equipment. Its low-frequency authentication interaction mode simultaneously reduces bandwidth pressure, ultimately forming a broadcasting-grade security and broadcasting closed loop that takes into account security immunity, stable broadcasting, and efficient operation and maintenance. It can be installed on large-scale outdoor screens with strict requirements for strong security and high availability.
[0021] Step S102 : collecting real-time network indicators of each transmission path through pre-deployed network probes, so as to screen a target transmission path from a plurality of transmission paths based on the real-time network indicators.
[0022] Based on the real-time network indicator, a target transmission path is screened from the multiple transmission paths, specifically comprising: obtaining the real-time network indicator corresponding to each transmission path, wherein the real-time network indicator includes a packet loss rate, an end-to-end delay data, and a jitter variance; determining a real-time path quality parameter corresponding to each transmission path according to the packet loss rate, the end-to-end delay data, and the jitter variance using a predefined path quality function; and dynamically screening the target transmission path from the multiple transmission paths according to the real-time path quality parameter.
[0023] In secure outdoor large-screen broadcasting scenarios, real-time streaming requires stringent network stability. Traditional static routing strategies are unable to cope with sudden network jitter, link congestion, or intermediate node failures. Using a single transmission path can lead to broadcast lag or even interruption if packet loss increases dramatically or latency exceeds limits. Network probes dynamically collect path metrics and select the optimal path in real time. By continuously monitoring multi-path status, they can predict risks before encrypted content is sent, dynamically avoid poor-quality links, and ensure smooth broadcasting from the source.
[0024] In one embodiment of the present specification, the network probe deployed at the CDN edge node actively sends probe packets and monitors the return data in millisecond cycles, capturing the three-dimensional core indicators of each transmission path in real time, including packet loss rate, end-to-end delay and jitter variance. The packet loss rate is determined by counting the proportion of packet loss per unit time, the end-to-end delay is obtained by measuring the round-trip time of the data packet, and the jitter variance is obtained by calculating the fluctuation range of the delay of consecutive data packets. The probe refreshes the data in a period of 200ms and pushes it to the routing decision engine through the secure broadcast control bus. The routing decision engine performs dynamic evaluation through a preset multi-dimensional path quality function, which is as follows:
[0025] Where R is the path packet loss rate (%), D is the end-to-end delay (ms), and J is the jitter variance (ms2). 、 、 is the weight coefficient, which is adjustable. Example values can be 0.3, 0.5, and 0.2 respectively.
[0026] The function uses an exponential decay model to amplify the sensitivity of packet loss rate. A slight increase in packet loss rate will significantly reduce the score. An inverse model is used to strengthen the negative weight of latency and jitter. High latency / jitter causes a sharp drop in the score. The three indicators are integrated into a single quantitative path quality parameter (with a score range of 0-100) to achieve a normalized representation of complex network states. A higher score indicates better path stability.
[0027] Based on the quality parameter ranking updated in seconds, intelligent routing switching decisions are executed. The path with the highest score is selected every three seconds as the main transmission channel. When the quality of the optimal path is detected to have dropped by more than the dynamic threshold twice in a row, the seamless switching mechanism is immediately triggered. The SDN controller sends routing update instructions to all nodes in the network to ensure that the encrypted video stream is always transmitted via the optimal path. At the same time, the blockchain records path switching events in real time, forming an auditable transmission decision chain.
[0028] It's important to note that CDN edge nodes are distributed server nodes closest to end users within a content delivery network (CDN). They are responsible for efficiently distributing central resources. In outdoor large-screen secure broadcast systems, edge nodes serve as the physical carriers of transmission security modules and are deployed directly in densely populated areas, such as urban backbone network equipment rooms. This approach leverages geographic proximity to shorten data transmission paths, enabling ultra-low-latency video streaming. Each edge node has a built-in network probe cluster that monitors the quality of the path to the target broadcast terminal (packet loss rate, latency, and jitter) in real time, providing input for dynamic routing decisions. Nodes collaborate through an SDN controller, switching transmission paths within seconds based on routing engine instructions. Edge nodes function as lightweight blockchain nodes, storing hashed copies of transmission logs to ensure tamper-proof routing switch records. CDN edge nodes also cache encrypted video segments (dynamically watermarked) for direct distribution to terminals after successful authentication, minimizing back-to-source latency.
[0029] Through the three-step closed loop of real-time probe perception, function quantitative evaluation, and dynamic decision-making, a transition from passive response to active defense has been achieved; at the security level, the path switching mechanism is linked with blockchain evidence storage, and any route changes are recorded on the chain, which not only avoids the risk of middlemen hijacking the path, but also provides an auditable traceability chain for transmission failures; at the stability level, dynamic screening shows strong adaptability to network jitter, and can maintain smooth broadcasting even in harsh network environments (such as regional sudden congestion), avoiding broadcasting accidents caused by delayed manual intervention in traditional solutions; at the resource efficiency level, automated path optimization reduces the burden of operation and maintenance, while reducing bandwidth redundancy overhead by avoiding poor-quality links, maximizing transmission resource utilization; upgrading the transmission layer from a channel to an intelligent defense line, becoming a key hub that connects the upper and lower levels of the multi-dimensional protection system.
[0030] Step S103, when the device authentication result is passed, the watermark fragment data corresponding to the target video stream is obtained in the pre-built blockchain node, and the watermark fragment data is transmitted to the target broadcast terminal through the target transmission path, and the transmission process is monitored in real time to achieve the safe broadcast of the target video stream.
[0031] Before obtaining the watermark fragmentation data corresponding to the target video stream in the pre-built blockchain node, the method also includes: obtaining the target video stream, dynamically fragmenting the target video stream, and generating multiple transmission fragments of preset fixed lengths; obtaining a fragmentation timestamp corresponding to each transmission fragment, and generating a fragmentation encryption key corresponding to each transmission fragment based on the fragmentation timestamp and a preset key derivation function; using a layered encryption algorithm, encrypting the video data and electronic program unit data in the transmission fragment according to the fragmentation encryption key, and determining the encrypted transmission fragment; embedding a dynamic watermark in the multiple encrypted transmission fragments to determine the watermark fragmentation data, wherein the dynamic watermark includes a content provider identifier, a geographic area code, and a current timestamp, and the watermark fragmentation data includes an encrypted fragment and a corresponding watermark feature value; after associating the watermark feature value in the watermark fragmentation data with the registered terminal device fingerprint in the terminal registration information, storing it in the blockchain node.
[0032] In the scenario of secure outdoor large-screen broadcasting, real-time streaming media content faces the triple risks of tampering, piracy, and illegal dissemination. Traditional single encryption or static watermark solutions and fixed fragment encryption are easily cracked by brute force, and static watermarks can be stripped and the source of the leak cannot be traced.
[0033] In one embodiment of the present specification, a target video stream inputted by a signal source is received. The encoding format of the video source may be H.264, H.265, AVS3, etc. The video stream is first divided into independent transmission segments (TS segments) according to a preset duration t. Generally, the value of t is 2 to 10 seconds, such as t=2s. Each segment is assigned a unique segment number and timestamp (a nanosecond-level precision time source is obtained from the GPS clock); based on the segment timestamp and the preset key derivation function, an encryption key is dynamically generated for each segment. The key integrates the time factor with the master key through a cryptographic algorithm to ensure that the key of a single segment is unpredictable. For the kth segment, an encryption key is generated. ,in, It is an HMAC-based extract and expand key derivation function used as a key derivation function to derive a longer output key from a shorter input key. The master key is generally provided by the hardware's own security module. is the Unix timestamp of the kth shard, It is the 128-bit hash value of the shard counter.
[0034] The calculated key is split into two parts, serving as encryption keys for the video data and EPG (Electronic Program Guide) metadata. It should be noted that the Electronic Program Guide (EPG) is structured metadata describing video content, containing navigation data such as channel information, program titles, play times, and content categories. EPG metadata and video data use differentiated encryption algorithms to prevent a single algorithm from being compromised, leading to complete link failure. The program ID in the EPG (e.g., Program_ID = 101) is stored bound to the watermark feature value Wm. If the EPG is tampered with (e.g., the program ID is changed), watermark verification will fail.
[0035] The encryption key for the kth video data is: ; The encryption key for the kth piece of metadata is: ; Among them, Truncate() is a truncation function, that is, the key calculated in S2 is truncated according to the length, the first 256 bits are used as video data, and the last 128 bits are used as the encryption key of the EPG metadata.
[0036] A layered encryption strategy is then adopted, with video data encrypted using a high-strength block cipher algorithm and EPG data encrypted using a national secret algorithm, forming a double-encrypted transmission segment. The video data and EPG metadata are encrypted in layers. For video data, the encrypted data for the kth segment is calculated as: , where AES-256 is the video data encryption algorithm, is the original data of the kth video, It is the initialization vector of the AES encryption algorithm.
[0037] For metadata, the encrypted data of the kth slice is calculated as: , where SM4-CRT is the encryption algorithm for EPG metadata, It is the metadata of the kth piece.
[0038] A dynamic watermark is embedded in the encrypted transmission fragment. First, watermark information containing the content provider identifier, geographic area code (generated by IP positioning) and current timestamp is generated, and the watermark feature value is generated through hash calculation. The watermark is injected into the frequency domain of the video frame (the intermediate frequency coefficient of the discrete cosine transform) to ensure that it is visually invisible and resistant to transcoding attacks. After each fragment is embedded with the watermark, a corresponding watermark feature value summary is generated.
[0039] To embed a watermark in the DCT domain of a video frame, first, divide each frame into 8×8 blocks. Then select the intermediate frequency coefficients. The value of the intermediate frequency coefficient reflects the energy distribution within a specific frequency range in the image. The relationship between u and v satisfies The watermark embedding formula is ,in, is the intensity factor, which can be adjusted adaptively and has a value range of 0.05~0.2. is the mth watermark bit, is a pseudo-random sequence used for key control. The calculation method of m is , floor() is the rounding down function, It is the frame number of the current frame. N is generally taken as the frame rate of the video (frames per second). The effect is that the watermark rotates every 1 second.
[0040] The structural information of the watermark is , where Hash128 is the hash calculation function, PID is the provider ID, and GEO is the geographic location. is the current timestamp, It is a one-time password generated by the SM3 algorithm.
[0041] The watermark feature value is associated with the pre-registered hardware fingerprint of the target broadcast terminal (such as the hash combination of CPU clock variance + GPU rendering fingerprint) to construct a content-device-time triplet; the triplet is written to the blockchain through the alliance chain node (such as the CDN edge node). The smart contract automatically verifies the data consistency and then stores it on the chain, forming a publicly verifiable traceability anchor point.
[0042] The evidence data structure is constructed as follows: Block_i = { Header, Body} Header = { PrevHash, MerkleRoot, Timestamp} Body = [Tx_1, Tx_2, ..., Tx_n ] Tx_j = {ChannelID, StartTime, EndTime,WatermarkHash, CDNNodeSig} Among them, prevHash is the hash value of the previous block, MerkleRoot is the Merkle tree root of all transactions in this block, Timestamp is the timestamp generated by this block, ChannelID is the unique identifier of the current channel, StartTime is the start time of the broadcast, EndTime is the end time of the broadcast, WatermarkHash is the watermark feature value hash, and CDNNodeSig is the identity of the CDN node. Then, the improved PBFT consensus is used to build a consensus delay model. ,in, is the network transmission delay, is the signature verification time, which is about 3ms in SM2 signature verification. The maximum transmission time for a block proposal to be broadcast from the primary node to all backup nodes.
[0043] In one embodiment of the present specification, an authentication server sends a query request to a blockchain node, along with a hash value of the terminal's hardware fingerprint. The smart contract verifies whether the fingerprint exists in a list of registered terminals stored on the blockchain and validates the dynamic token. If authentication succeeds, a watermarked fragmented data packet associated with the terminal is returned, containing the encrypted video fragment, watermark feature value, and fragment key index. The watermarked fragmented data packet is then injected into the previously dynamically selected optimal path, with the packet header encapsulating the target terminal's IP address, watermark feature value, and blockchain transaction ID. High-speed transmission is achieved using the UDP protocol, with embedded forward error correction (FEC) encoding. A watermark checksum is appended to each fragment, and the integrity is verified in real time upon receipt by the terminal.
[0044] The transmission process is monitored in real time, specifically including: obtaining real-time transmission indicators during the transmission process, wherein the real-time transmission indicators include real-time network quality data, real-time system load data, and content anomaly indicators; based on the real-time transmission indicators, identifying anomalies in the transmission process, determining the type of transmission anomaly, and matching the current switching strategy with the transmission anomaly type and the preset multi-level emergency switching strategy. Based on the real-time transmission indicators, identifying anomalies in the transmission process, determining the type of transmission anomaly, specifically including: triggering a local master-slave switching mechanism when the number of consecutive heartbeat packet losses in the real-time network quality data exceeds a preset first number threshold, or the packet loss rate continuously exceeds a preset first ratio threshold within a first preset time period; triggering a remote disaster recovery switching mechanism when the number of consecutive watermark verification failures in the content anomaly indicator exceeds a preset second number threshold, or the real-time system load data continuously exceeds a preset second ratio threshold within a second preset time period.
[0045] In the scenario of safe outdoor large-screen broadcasting, under the requirements of real-time monitoring of the transmission process and multi-level emergency switching, traditional solutions rely on manual threshold configuration and passive response. Network jitter may cause video freezes, watermark verification failure indicates that the content has been tampered with, and system overload will directly cause broadcast interruptions. It is difficult to cope with dynamic network attacks, sudden equipment failures or regional network storms, resulting in switching delays exceeding broadcasting standards and failure of leak tracing.
[0046] In one embodiment of the present specification, a probe cluster deployed at a CDN edge node sends encrypted heartbeat packets at a period of 200ms, counts the number of consecutive heartbeat packet losses and the sliding window packet loss rate, for example, calculates the average within 10 seconds, and uploads the data to the monitoring center in real time via a secure broadcast control bus. The CPU occupancy and memory usage of the terminal device are polled through the SNMP protocol, and when it exceeds the threshold for 30 seconds, it is marked as an overload state. The terminal immediately verifies the integrity of the watermark after receiving the fragment. If the verification fails for five consecutive times, it is determined to be a content tampering event. The fragment decryption error rate is synchronously counted and determined by the ratio of the number of erroneous fragments to the total number of fragments.
[0047] Deterministic judgments are made based on preset fixed thresholds. If the number of consecutive heartbeat packet losses exceeds a preset value (for example, three times) or the packet loss rate exceeds a threshold (for example, 0.1%) for 10 seconds, a network transmission failure is determined. If the number of consecutive watermark verification failures exceeds a preset value (for example, five times), the content is determined to have been tampered with. If the CPU usage or memory utilization exceeds a threshold (for example, 90%) for 30 seconds, the terminal device is determined to be overloaded. If a network transmission failure is determined, traffic is switched to a backup node in the same computer room within 200ms, achieving imperceptible interruption. If content tampering or terminal device overload is determined, traffic is switched to a remote disaster recovery center within 800ms to isolate high-risk terminals. All switching events are linked to the terminal device fingerprint and watermark feature value, and written to the blockchain evidence storage network to form a verifiable chain of evidence.
[0048] Through multi-dimensional threshold judgment and regularized response, the judgment rules based on fixed thresholds avoid the black box risks of algorithms and meet the mandatory requirements for logical verifiability in broadcasting and television equipment certification; threshold rules can be directly burned into hardware chips to achieve nanosecond-level anomaly recognition and millisecond-level switching actions, which is more suitable for the embedded environment of outdoor large screens than model solutions requiring complex calculations; preset thresholds provide operation and maintenance personnel with clear tuning anchor points, and they can adapt to different network environments by adjusting the packet loss rate threshold, significantly reducing the operation and maintenance costs of large-scale deployments.
[0049] Real-time monitoring of the transmission process specifically includes: obtaining real-time bit rate fluctuation values, request frequency gradient data and protocol compliance flag data, and combining the real-time bit rate fluctuation values, the request frequency gradient data and the protocol compliance flag data into a multi-dimensional monitoring feature vector; inputting the multi-dimensional monitoring feature vector into a pre-trained long short-term memory neural network model to determine the abnormal behavior level, so as to provide graded warnings based on the abnormal behavior level.
[0050] In one embodiment of this specification, in addition to triggering based on real-time data, this specification embodiment also provides a predictive hierarchical warning method, using the LSTM network structure to establish an AI abnormality prediction model, inputting the feature vector ,in, is the bit rate change rate (%), is the request frequency gradient (times / minute 2 ), is the abnormal agreement ratio (%), is the percentage of visits to high-risk areas (%), and T represents the transpose operation of the matrix. The output layer is , where softmax() is a multi-class probability normalization function, is the output layer weight matrix (mapping hidden states to 4 anomaly levels), is the LSTM hidden state vector, is the output layer bias vector. The output is divided into four levels: normal, attention, warning, and severe.
[0051] The transport security module counts the bitrate differences between adjacent TS segments in real time, calculating the rate of change per unit time, such as the percentage change in the current segment's bitrate compared to the previous segment. This data is refreshed every 200ms. The terminal protection module records device request timestamp sequences and calculates the acceleration of request volume change—the second-order derivative of the number of requests per unit time—using a sliding window (e.g., a 1-minute window length) to identify anomalous access patterns. Probes deployed at CDN edge nodes capture transport layer protocol types (e.g., RTSP / TCP / UDP / HTTP) in real time. These captured protocols are compared against a pre-set whitelist of security protocols, and non-whitelisted protocols are marked as anomalous. The anomalous protocol ratio is determined by counting the number of anomalous protocol packets relative to the total number of transmitted packets within a fixed time window (e.g., 15 minutes). Extract the source IP address of the terminal access request, resolve it into a geographical area through the IP geolocation database, and compare the resolved result with the preset high-risk area library (such as the source of frequent attacks and policy-restricted areas); mark the access records of the hit area as high-risk, count the number of access requests from the high-risk area within the unit time window, calculate its proportion of the total number of access requests, and obtain the proportion of access to high-risk areas.
[0052] Based on the output levels of normal, caution, warning, and severe, a graded alert is issued. A probability of <70% is considered normal, maintaining current transmission; a probability of 70-80% is considered caution, signaling network fluctuations and automatically expanding bandwidth; a probability of 80-90% is considered warning, identifying attack behavior and triggering deep protocol inspection; a probability >90% is considered severe, corresponding to a system-level risk and initiating disaster recovery. The LSTM model's ability to model time series features enables it to capture complex attack patterns that are imperceptible to traditional solutions. For example, a low-rate DDoS attack manifests itself early as a gradual increase in request frequency gradients; the model can identify anomalies before traffic reaches the threshold. Cross-dimensional correlation analysis of protocol compliance and bitrate fluctuations can accurately identify man-in-the-middle attacks, eliminating the problem of misjudgment of single-metric alerts.
[0053] Through the technical solution of the embodiment of this specification, by building a four-dimensional integrated protection chain of terminal authentication, transmission optimization, content security, and monitoring response, the problem of lack of full-link security in the field of large-screen safe broadcasting caused by isolated protection status is solved; through two-factor authentication, the legitimacy verification of the terminal device is bound to the pre-stored registration information of the blockchain, breaking the separation of traditional terminal protection and identity management, ensuring the non-repudiation of the playback source, and synchronizing the authentication results to the content security module in real time, establishing a trust foundation for the device for subsequent content distribution; the path indicators (packet loss rate / delay / jitter) collected by the network probe are dynamically screened for the optimal transmission path through the quality function, and the The routing decision log is written into the blockchain, forming a closed-loop linkage between the transmission security layer and the content distribution layer, avoiding the risk of transmission hijacking caused by the disconnection between routing and content in traditional solutions; the watermark shard data is associated with the terminal device fingerprint in the blockchain to achieve a three-way binding of content, device, time and space, and the dynamic watermark is embedded in the content provider identification and geographic area code to provide an unalterable digital fingerprint for leak tracing; the watermark feature value is verified in real time during terminal playback to form a closed-loop verification of content security and terminal behavior; three-dimensional real-time monitoring of the transmission process drives multi-level emergency switching, and all operation logs and watermark feature values are stored on the chain to provide a cross-module traceability evidence chain for abnormal events.
[0054] Figure 2 This is a schematic diagram of a video security broadcast system based on multi-dimensional protection provided in an embodiment of this specification. Figure 2 As shown, the secure video broadcast system (IPTV secure broadcast system) consists of a content security module, a transmission security module, and an emergency response module. The content security module is used to encrypt media streams in segments and dynamically embed watermarks. The transmission security module includes a blockchain evidence storage node and an intelligent routing controller, which stores broadcast logs on-chain and optimizes real-time paths based on network quality. The terminal protection module deploys a two-factor authentication module and a trusted execution environment to enhance terminal access security. The emergency response module integrates a multi-level redundant architecture and an AI-powered anomaly prediction unit to proactively identify and effectively respond to failures such as downtime and link interruptions, ensuring stable and smooth broadcasting. These four submodules exchange data via a secure broadcast control bus, ultimately forming a closed-loop protection system.
[0055] The content security module utilizes multiple encryption units combining AES-256 and SM4 algorithms; a dynamic watermark generator periodically updates watermark features every 30 seconds. The transport security layer includes a broadcast log storage network built on a consortium blockchain, with each CDN node acting as a blockchain participant; a probe cluster that collects real-time network quality metrics, including packet loss rate, latency, and jitter; and a dynamic routing decision engine that automatically selects the optimal transmission path based on probe data.
[0056] The terminal protection module includes a hardware fingerprint generator and a dynamic token generator. The hardware fingerprint generator is used to collect the terminal device's CPU clock characteristics, GPU rendering fingerprint, and network card MAC hash value; the dynamic token generator is used to update the access token every 60 seconds based on the HMAC-SHA256 algorithm. The emergency response system includes a three-level switching mechanism. When a single node failure is detected, local master-slave switching is completed within 200ms; when the regional network is interrupted, remote resources are enabled within 800ms, corresponding to remote disaster recovery switching; in the event of a system-level failure, the cloud emergency channel is activated within 1.5s, corresponding to cloud-based downgraded broadcast. The AI anomaly prediction unit includes an LSTM neural network model, with input features including bitrate fluctuation values, request frequency gradients, and protocol compliance flags; and an abnormal behavior graded warning module, with output levels including normal (confidence <70%), attention (confidence range 70-80%), warning (confidence range 80-90%), and severe (confidence >90%). The collaborative work of watermark embedding and blockchain evidence storage includes injecting a digital watermark containing a timestamp and node ID during the content encryption stage; associating the watermark feature value with the terminal device fingerprint and writing it into the blockchain; and achieving rapid tracing of leaked content through smart contracts.
[0057] Content security protection is achieved through dynamic sharding encryption and watermark embedding, blockchain evidence storage and intelligent routing optimization are used to ensure transmission credibility, terminal security is enhanced by combining two-factor authentication of hardware fingerprints and dynamic tokens, and a multi-level redundant switching mechanism based on the LSTM prediction model is established. A traceability method that links content fingerprint on-chain evidence storage with terminal watermarks is proposed to achieve trusted traceability of the entire broadcast chain.
[0058] The embodiment of this specification also provides a video security broadcasting device based on multi-dimensional protection, such as Figure 3 As shown, the device includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the above method.
[0059] The embodiments of this specification also provide a non-volatile computer storage medium storing computer executable instructions, wherein the computer executable instructions are configured to execute the above method.
[0060] The various embodiments in this specification are described in a progressive manner. Similar portions between the various embodiments can be referenced to each other, and each embodiment focuses on the differences from the other embodiments. In particular, the device, apparatus, and non-volatile computer storage medium embodiments are generally similar to the method embodiments, so their descriptions are relatively simplified. For relevant details, refer to the descriptions of the method embodiments.
[0061] The foregoing description of this specification describes specific embodiments. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different from that described in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order shown or the sequential order to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0062] The devices and media provided in the embodiments of this specification correspond one-to-one to the methods. Therefore, the devices and media also have similar beneficial technical effects to their corresponding methods. Since the beneficial technical effects of the methods have been described in detail above, the beneficial technical effects of the devices and media will not be repeated here.
[0063] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems, or computer program products. Thus, this specification may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0064] This specification is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of this specification. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0065] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0066] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0067] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0068] Memory may include non-permanent storage in a computer-readable medium, in the form of random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.
[0069] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can be implemented using any method or technology for information storage. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change RAM (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media, such as modulated data signals and carrier waves.
[0070] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0071] The foregoing description is merely one or more embodiments of this specification and is not intended to limit this specification. It will be apparent to those skilled in the art that various modifications and variations may be made to one or more embodiments of this specification. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of one or more embodiments of this specification are intended to be within the scope of the claims of this specification.
Claims
1. A video security broadcasting method based on multi-dimensional protection, characterized in that: The method comprises: When triggered by a video playback request from a target broadcast terminal, terminal device information is obtained to perform two-factor authentication on the target broadcast terminal based on the terminal device information and terminal registration information pre-stored in the blockchain node, and a device authentication result is determined; collecting real-time network indicators of each transmission path through pre-deployed network probes, and screening a target transmission path from a plurality of transmission paths based on the real-time network indicators; When the device authentication result passes, the watermark fragment data corresponding to the target video stream is obtained in the pre-built blockchain node, and the watermark fragment data is transmitted to the target broadcast terminal through the target transmission path, and the transmission process is monitored in real time to achieve the safe broadcast of the target video stream.
2. A video security broadcasting method based on multi-dimensional protection according to claim 1, characterized in that: Before obtaining the watermark fragment data corresponding to the target video stream in the pre-built blockchain node, the method further includes: Obtain a target video stream, dynamically segment the target video stream, and generate multiple transmission segments of preset fixed lengths; Obtaining a slice timestamp corresponding to each of the transmission slices, and generating a slice encryption key corresponding to each of the transmission slices based on the slice timestamp and a preset key derivation function; Using a layered encryption algorithm, the video data and the electronic program unit data in the transmission slice are respectively encrypted according to the slice encryption key to determine the encrypted transmission slice; Embed a dynamic watermark in a plurality of the encrypted transmission fragments, and determine watermark fragment data, wherein the dynamic watermark includes a content provider identifier, a geographic region code, and a current timestamp, and the watermark fragment data includes an encrypted fragment and a corresponding watermark feature value; After associating the watermark feature value in the watermark fragment data with the registered terminal device fingerprint in the terminal registration information, the data is stored in the blockchain node.
3. The video security broadcasting method based on multi-dimensional protection according to claim 1 is characterized in that: Based on the terminal device information and the source reliable terminal information pre-stored in the blockchain node, two-factor authentication is performed on the target broadcast terminal to determine the device authentication result, specifically including: Based on the terminal device information, generate the hardware fingerprint information and dynamic token of the target broadcast terminal; The target broadcast terminal is matched with the source reliable terminal information through the hardware fingerprint information and the dynamic token to determine the device authentication result.
4. The video security broadcasting method based on multi-dimensional protection according to claim 3 is characterized in that: Generating the hardware fingerprint information and dynamic token of the target broadcast terminal based on the terminal device information specifically includes: Obtaining the CPU clock characteristics of the target broadcast terminal's CPU executing a fixed instruction sequence, and obtaining the GPU rendering instruction set characteristics and the network card MAC address of the GPU executing a nonlinear transformation output; Determine the hardware fingerprint information corresponding to the target broadcast terminal based on the variance value of the CPU clock feature, the hash value of the GPU rendering instruction set feature, and the hash value of the network card MAC address; A dynamic token corresponding to the target broadcast terminal is generated according to the hardware fingerprint information and the preset seed key parameters.
5. The video security broadcasting method based on multi-dimensional protection according to claim 1 is characterized in that: Based on the real-time network indicator, selecting a target transmission path from the plurality of transmission paths specifically includes: Obtaining the real-time network indicators corresponding to each of the transmission paths, wherein the real-time network indicators include packet loss rate, end-to-end delay data, and jitter variance; Determining a real-time path quality parameter corresponding to each transmission path according to the packet loss rate, the end-to-end delay data, and the jitter variance using a predefined path quality function; According to the real-time path quality parameter, a target transmission path is dynamically selected from the plurality of transmission paths.
6. The video security broadcasting method based on multi-dimensional protection according to claim 1 is characterized in that: Real-time monitoring of the transmission process, including: Acquiring real-time transmission indicators during the transmission process, wherein the real-time transmission indicators include real-time network quality data, real-time system load data, and content anomaly indicators; According to the real-time transmission index, the transmission process is identified as abnormal, and the type of transmission abnormality is determined, so as to match the current switching strategy with the transmission abnormality type and the preset multi-level emergency switching strategy.
7. The video security broadcasting method based on multi-dimensional protection according to claim 6 is characterized in that: Based on the real-time transmission indicators, anomalies in the transmission process are identified and the type of transmission anomaly is determined, specifically including: When the number of consecutive heartbeat packet losses in the real-time network quality data exceeds a preset first number threshold, or the packet loss rate continues to exceed a preset first ratio threshold within a first preset time period, triggering a local master-slave switching mechanism; When the number of consecutive watermark verification failures in the content anomaly indicator exceeds a preset second number threshold, or when the real-time system load data continues to exceed a preset second ratio threshold within a second preset time period, the off-site disaster recovery switching mechanism is triggered.
8. The video security broadcasting method based on multi-dimensional protection according to claim 1 is characterized in that: Real-time monitoring of the transmission process, including: Acquire a real-time bit rate fluctuation value, request frequency gradient data, and protocol compliance flag data, and combine the real-time bit rate fluctuation value, the request frequency gradient data, and the protocol compliance flag data into a multi-dimensional monitoring feature vector; The multi-dimensional monitoring feature vector is input into a pre-trained long short-term memory neural network model to determine the abnormal behavior level, so as to perform a graded warning based on the abnormal behavior level.
9. A video security broadcasting device based on multi-dimensional protection, characterized in that: The device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor. The instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 8.
10. A non-volatile computer storage medium storing computer executable instructions, characterized in that: The computer executable instructions are configured to execute the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Streaming media program playing method, device and system
CN106303572A
Equipment management method and system and storage medium
CN114417297A
Data transmission method and device, computer equipment and storage medium
CN118590495A
Private domain live broadcast data storage and visitor authentication method and system based on block chain
CN119363316A
Network submission method and system based on UKEY, and storage medium
CN119945745A
Cited By
Data transmission method and device based on hierarchical user permission and hierarchical equipment collaboration
CN121690633A
Ground unloading system for load data of unmanned aerial vehicle
CN121691613A
Comprehensive management method and system for intelligent broadcasting and television stations
CN121728289A