A water conservancy video monitoring safety protection method, system and device

By using smart contracts based on consortium blockchains and asymmetric encryption technology, combined with dynamic key derivation algorithms and hybrid storage strategies, the centralized security vulnerability and data transmission security issues of water conservancy video surveillance systems have been resolved. This has enabled efficient and reliable video surveillance data transmission and storage, thereby improving the system's security and stability.

CN120956853BActive Publication Date: 2026-03-20ANHUI & HUAI RIVER WATER RESOURCES RES INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-11
Publication Date
2026-03-20

AI Technical Summary

Technical Problem

Existing water conservancy video monitoring systems have significant shortcomings in terms of data security and reliability, including the vulnerability of centralized security architecture, weak video data transmission security mechanisms, limited ability to detect abnormal behavior, and imperfect data storage and recovery mechanisms, making it difficult to cope with complex cybersecurity threats and extreme weather conditions.

Method used

The system employs a smart contract-based device authentication mechanism based on a consortium blockchain architecture, combined with asymmetric encryption and digital certificate verification, to achieve decentralized distributed secure access control. An adaptive compression algorithm is selected based on the spatiotemporal characteristics and information entropy analysis of the video content, and the data is stored on the blockchain using a hash algorithm. Layered and segmented encryption processing is performed based on a blockchain consensus mechanism and a dynamic key derivation algorithm using high-precision timestamps. A multi-layered hybrid storage strategy and a time-sensitive cloud-edge collaborative control mechanism are constructed to ensure the security and reliability of data transmission and storage.

Benefits of technology

It significantly improves the anti-attack capability of the water conservancy video monitoring system, reduces the risk of single point of failure, achieves efficient video processing and data anti-tampering, enhances encryption strength and resistance to quantum computing attacks, and ensures the system's stable operation and security around the clock.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120956853B_ABST
    Figure CN120956853B_ABST
Patent Text Reader

Abstract

The application discloses a kind of water conservancy video monitoring safety protection method, system and equipment, and wherein method includes: the smart contract management equipment authentication of alliance block chain architecture, the distributed security access control of decentralization;According to the space-time feature and information entropy analysis of video content Selection adaptive compression algorithm, real-time adjustment compression parameter;Based on the dynamic key derivation algorithm of block chain consensus mechanism and high-precision timestamp, construct double-layer encrypted video transmission mechanism;Based on the distributed hierarchical storage strategy of block chain, execute the hybrid mechanism of local cache and block chain distributed storage;Build timeliness cloud edge collaborative control mechanism.The application realizes the safe access, efficient processing, encrypted transmission, anomaly detection and reliable storage of video monitoring data through the deep integration of edge computing and block chain technology, significantly improves the data credibility, tamper resistance and overall system security of reservoir safety monitoring.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of water conservancy safety monitoring, in particular to a water conservancy video monitoring safety protection method, system and device. BACKGROUND

[0002] As an important water conservancy infrastructure, the safety monitoring of reservoirs is of great significance for flood control, disaster reduction, water resources regulation and engineering safety. Reservoirs are usually located in remote areas and face various natural disasters and man-made threats such as heavy rain, floods, landslides, terrorist attacks, etc. Therefore, an efficient and reliable video monitoring system is crucial for timely detection of abnormal situations and initiation of emergency plans. However, the existing traditional water conservancy video monitoring system has significant shortcomings in data security and reliability, which is difficult to cope with the increasing network security threats and monitoring requirements under extreme weather conditions. The main problems are as follows:

[0003] (1) Centralized security architecture vulnerability: the existing reservoir monitoring system adopts a centralized management mode, which has a single point of failure risk. Once the central node is attacked, the security of the entire system will be seriously threatened;

[0004] (2) Weak video data transmission security mechanism: the traditional system lacks effective encryption mechanisms during video data transmission, which is vulnerable to man-in-the-middle attacks, data theft and tampering, and cannot guarantee the authenticity and integrity of the monitoring data;

[0005] (3) Limited ability to detect abnormal behavior: the existing system mainly relies on fixed rules to detect network traffic anomalies, illegal access and other security threats, which is difficult to cope with complex and variable attack methods, especially when the system load increases dramatically under extreme weather conditions, the security protection capability is more insufficient;

[0006] (4) Incomplete data storage and recovery mechanism: in the case of network interruption or system failure, there is no effective data consistency guarantee and recovery mechanism, which may result in loss or tampering of monitoring data, affecting the accuracy and timeliness of emergency decision-making.

[0007] Therefore, an innovative technical architecture is needed to improve the security protection capability and operational stability of the water conservancy video monitoring system. SUMMARY

[0008] The water conservancy video monitoring safety protection method, system and device provided by the present application can effectively improve the data credibility, tamper-proofing capability and overall security of the reservoir safety monitoring system, and can at least solve one of the above technical problems.

[0009] In order to solve the above technical problems, the present application adopts the following technical solutions:

[0010] A water conservancy video monitoring safety protection method, comprising the following steps:

[0011] S1, a smart contract management device authentication mechanism based on a consortium blockchain architecture, combined with asymmetric encryption digital certificate verification and device unique identifier verification, realizes decentralized distributed security access control;

[0012] S2, according to the spatiotemporal characteristics and information entropy analysis of video content, an adaptive compression algorithm is selected, and the compression parameters are adjusted in real time, a differentiated processing strategy is implemented based on the importance level of the monitoring area, and the processing metadata is stored through a hash algorithm; Chain;

[0013] S3, based on the dynamic key derivation algorithm of the blockchain consensus mechanism and high-precision timestamp, the video stream is processed by hierarchical segmentation encryption, and the feature value is recorded in the blockchain, and a multi-encryption secure transmission channel is constructed;

[0014] S4, based on the distributed hierarchical storage strategy of the blockchain, a hybrid mechanism of local cache and distributed storage of the blockchain is executed, and automatic protection and data consistency synchronization functions based on smart contracts are provided when the network is disconnected;

[0015] S5, build a time-sensitive cloud edge collaborative control mechanism, the cloud platform issues encrypted instructions with ECDSA digital signature and accurate effective period identifier through multiple channels, the edge device performs multi-level cryptography verification and execution according to the instruction priority and timeliness, and the execution result is recorded after hash processing. Chain.

[0016] Further, the S1 further comprises:

[0017] S11, a globally unique identifier is assigned to each monitoring device and a non-symmetric key pair is generated, the device information is submitted to the blockchain network, and after multi-node consensus verification, it is written into the distributed ledger, and at the same time, the consortium chain authentication center issues a digital certificate containing device identity information, establishing a trusted digital identity of the device on the blockchain;

[0018] S12, after the edge node receives the video stream access request of the monitoring device, the device identifier, digital signature and timestamp are extracted, the authentication smart contract is executed, the contract automatically retrieves the device registration information from the blockchain account book, and at least through the verification of the digital certificate validity, signature authenticity and device running state Multi-dimensional factors ensure that the access device identity is real and reliable;

[0019] S13, the smart contract automatically allocates differentiated permission levels according to the importance of the area where the monitoring device is located, generates an access token containing permission information and a valid period, and signs it with a blockchain timestamp, records the authorization event on the chain, realizes decentralized access control based on the blockchain, and ensures the security of key area monitoring data;

[0020] S14, implement certificate life cycle management and exception handling mechanism, support multi-administrator multi-signature certificate regular rotation and real-time synchronization of revocation list, at the same time record the complete authentication process on the chain to form an unalterable audit log, establish authentication event correlation analysis capability, provide cross-domain authentication interoperability support, ensure the safety and controllability of the entire authentication process and the whole process traceability.

[0021] Further, the S2 further comprises:

[0022] S21, according to the spatio-temporal characteristics and information entropy analysis results of the video stream, construct a video content feature vector, evaluate the video complexity through the deep learning model of the edge computing node, automatically select the optimal compression algorithm for different feature types, calculate the optimal compression parameters in real time, and dynamically adjust the encoding configuration according to the network condition and computing resources, to ensure the highest compression efficiency while retaining key visual information;

[0023] S22, to ensure the credibility and unalterability of the video processing process, the system calculates the feature value of the processing metadata of each video stream through the hash algorithm, and submits the feature value together with the processing configuration digest to the blockchain network for storage, and writes it into the distributed ledger after verification by the smart contract, forming a credible timeline of processing history, while establishing a video processing metadata indexing mechanism, supporting the query and verification of the processing history of the video in a specific time period through the blockchain, realizing the traceability of the whole life cycle of the video data, providing technical support for the legal effectiveness and integrity of the subsequent video content, and preventing the video processing process from being tampered maliciously.

[0024] Further, in the S3, based on the dynamic key derivation algorithm of the blockchain consensus mechanism and high-precision timestamp, a double-layer encrypted video transmission mechanism is constructed, the construction process being: the edge device generates a random session key to encrypt the video data, and then uses the cloud platform public key to encrypt the session key, and sends it to the cloud platform in a packaged manner, the cloud platform uses the private key to decrypt the session key and then decrypts the video data, and the entire encryption channel key feature value is recorded in the blockchain to ensure unalterability.

[0025] Further, the S3 further comprises:

[0026] S31, based on the consensus time stamp of the blockchain network and the unique identification of the device, realize the dynamic key derivation algorithm, combine the latest block hash value of the blockchain, the device private key and the high-precision time stamp in a cryptographic operation, generate a master key seed, derive a hierarchical key tree from the master key seed through a key derivation function, including video content encryption key, metadata encryption key and authentication key, realize the key automatic rotation mechanism, ensure that even if a single key is leaked, the overall system security will not be compromised, at the same time, according to the sensitivity level of the video content, different strength encryption algorithms and encryption modes are used to build a layered encryption system that adapts to different security needs, and the key usage record is stored on the chain through zero-knowledge proof, ensuring that the key management process is auditable but does not leak the actual content of the key;

[0027] S32, dynamically segment the video stream according to fixed time intervals or scene change thresholds, independently encrypt each video segment, ensure that even if a single segment is cracked, it will not affect the security of other segments, generate a unique identifier and integrity check value for each encrypted video segment, build segment metadata containing encryption parameters, timestamps and integrity hashes, organize all video segment feature hashes through Merkle tree structure, only submit Merkle root hash and key node hash to the blockchain storage, while reducing the storage pressure of the blockchain, ensure data integrity is verifiable, design smart contract to automatically verify the Merkle proof path of the newly submitted video segment, ensure that the Merkle proof path is consistent with the on-chain root hash, and record the verification result on the blockchain;

[0028] S33, fuse TLS / SSL protocol and blockchain zero-knowledge proof technology, build a multi-level secure transmission channel, with the construction process as follows:

[0029] S331, establish a TLS-based encrypted communication tunnel, use strong cipher suites to ensure transmission layer security,

[0030] S332, implement a two-way authentication mechanism based on blockchain identity at the application layer, verify that both parties hold the correct blockchain identity private key through zero-knowledge proof without exposing the private key itself,

[0031] S333, design a transmission session binding mechanism, associate each transmission session with the authorized record on the blockchain, ensure that only authorized sessions can receive specific video streams,

[0032] S334, realize end-to-end data integrity verification, the receiving end verifies the consistency of the video segment hash and the blockchain record to confirm that the data has not been tampered with.

[0033] Further, the S4 further comprises:

[0034] S41, build a multi-level hybrid storage architecture, the specific construction process is as follows:

[0035] S411, the edge node provides local cache, the regional node is responsible for medium-term storage backup, the cloud realizes long-term archiving, and the blockchain stores key metadata and evidence hash;

[0036] S412, the data flow among the storage levels is automatically coordinated through intelligent strategies;

[0037] S413, a network interruption protection mechanism is realized, and the local emergency storage mode is switched to and the sampling rate is increased when the network is interrupted;

[0038] S414, after the network is restored, the key data is transmitted through incremental synchronization and the integrity is verified;

[0039] S415, a distributed data recovery mechanism is deployed, and the data is reconstructed from the distributed nodes in a disaster scenario by using the blockchain record, so as to ensure the system availability under extreme conditions;

[0040] S42, fine data access control is realized based on the blockchain, the intelligent contract defines the permissions of different roles, all data access operations are recorded on the chain to form an unalterable log, attribute-based encryption access control is realized, sensitive data security is ensured, comprehensive data use audit function is provided, complete access history of the video segment is supported, data operation compliance is automatically checked by the intelligent contract, safety policies and regulations are ensured, and a comprehensive data protection and traceability system is constructed.

[0041] Further, the S5 further comprises:

[0042] S51, the cloud platform generates dynamic security control instructions including temporary authorization credentials, encryption key rotation parameters and security policy updates by using a zero-trust security model, each instruction is embedded with a high-precision timestamp and a validity period limit, and is signed by an elliptic curve digital signature algorithm, so as to ensure that the instruction itself cannot be forged and tampered with;

[0043] S52, after receiving the instruction, the edge device implements a multi-level verification mechanism, first verifies the cryptographic correctness of the instruction digital signature, then checks whether the timestamp is within a trusted time window, and finally verifies whether the instruction conforms to the preset security policy, only the instruction that passes all verifications can be executed, so as to prevent replay attacks and man-in-the-middle attacks;

[0044] S53, after the edge device executes the security instruction, the execution result is recorded in a verifiable encryption manner, including instruction execution time, security configuration change details and system state changes, these records are written into a distributed ledger after being hashed, a complete security operation audit chain is established, and the system regularly performs security instruction compliance checks to ensure that the cloud-edge security configuration always maintains consistency and timeliness.

[0045] A water conservancy video monitoring security protection system suitable for the water conservancy video monitoring security protection method, comprising a three-layer structure of a top layer, a middle layer and a bottom layer, the top layer is a video monitoring device layer, the middle layer is an edge computing layer, and the bottom layer is a cloud platform layer, the video monitoring device layer collects data, which is processed by the edge computing layer and interacts with the cloud platform layer.

[0046] Further, the video monitoring device layer comprises multiple video monitoring devices, which are respectively used for collecting video data of each area of the reservoir and transmitting the video stream to the edge device for processing.

[0047] The edge computing layer serves as a core processing unit and comprises six key function modules, namely a transmission module, an interface module, a computing unit, a storage unit, a clock synchronization module and a security encryption module, the transmission module is used for receiving video stream data, the interface module is used for processing device communication, the computing unit is used for executing data analysis and feature extraction, the storage unit is used for providing local data caching, the clock synchronization module is used for ensuring system time consistency, and the security encryption module is used for protecting data.

[0048] In the cloud platform layer, a bidirectional communication channel is established between the cloud platform and the edge device, the encrypted and compressed video stream and the video early warning information are transmitted upward, and the dynamic instructions and time limit issued by the cloud platform are received downward, the cloud platform layer has three core function components, namely instruction time limit verification, private key management and distributed storage coordinator, the instruction time limit verification is used for ensuring the safety and effectiveness of the instructions, the private key management is used for ensuring the safety of system encrypted communication, and the distributed storage coordinator is used for realizing efficient distributed storage and management of data.

[0049] A computer device comprising a memory and a processor, the memory stores a computer program, and the computer program is executed by the processor to make the processor execute the steps of the above-mentioned water conservancy video monitoring security protection method.

[0050] The beneficial effects of the present application are as follows:

[0051] 1. The present application realizes decentralized security access control by constructing a distributed device authentication mechanism based on alliance block chain and combining asymmetric encryption, which significantly improves the system attack resistance and reduces the single point failure risk compared with the traditional centralized authentication mode.

[0052] 2. The present application dynamically selects an adaptive compression algorithm according to the space-time features and information entropy of the video content, and stores the processed metadata through a hash algorithm, realizes the organic combination of efficient video processing and data tamper-proofing, reduces the transmission bandwidth occupation while ensuring the video quality.

[0053] 3、The application realizes the hierarchical segmentation encryption of video stream by adopting the dynamic key derivation algorithm based on the blockchain consensus mechanism and high-precision timestamp, and significantly improves the encryption strength and anti-quantum computing attack ability compared with the traditional fixed key encryption scheme.

[0054] 4、The application combines advanced cryptography technologies such as high-precision timestamp and ECDSA digital signature with blockchain smart contract, and constructs a complete space-time security proof system, effectively preventing common security threats such as replay attacks and man-in-the-middle attacks.

[0055] 5、The verification execution mechanism based on instruction priority and time effectiveness realized by the application ensures the consistent execution of security control strategies among multi-level edge devices, avoiding the common security strategy conflict and update lag problem in traditional systems.

[0056] 6、The application realizes the distributed hierarchical storage strategy based on blockchain, executes the hybrid mechanism of local cache and blockchain distributed storage, provides the offline automatic protection and data consistency synchronization function based on smart contract, and guarantees the all-weather stable operation of the monitoring system. BRIEF DESCRIPTION OF DRAWINGS

[0057] The drawings described herein are used to provide further understanding of the present application, and constitute a part of the present application, the illustrative embodiments of the present application and the description thereof are used to explain the present application, and do not constitute improper limitation on the present application.

[0058] Figure 1 Fig. 1 is a schematic diagram of the overall architecture of the water conservancy video monitoring security protection system according to the embodiment of the application.

[0059] Figure 2 Fig. 2 is a schematic diagram of the overall process of the water conservancy video monitoring security protection method according to the embodiment of the application.

[0060] Figure 3 Fig. 3 is a schematic diagram of the specific process of the water conservancy video monitoring security protection method according to the embodiment of the application.

[0061] Figure 4 Fig. 4 is a structural block diagram of the computer device according to the embodiment of the application. DETAILED DESCRIPTION

[0062] With reference to the accompanying drawings, the technical solutions in the embodiments of the present application will be clearly and completely described below. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. In the case of no conflict, the embodiments and the features in the embodiments in the present application can be combined with each other. Based on the embodiments in the present application, all the other embodiments obtained by a person of ordinary skill in the art without creative work are within the protection scope of the present application.

[0063] It should be noted that the meaning of "and / or" appearing throughout the text includes three parallel solutions. Taking "A and / or B" as an example, it includes the A solution, or the B solution, or the solution of A and B being satisfied at the same time. In addition, "multiple" means more than two. In addition, the technical solutions of each embodiment can be combined with each other, but it must be based on the fact that a person of ordinary skill in the art can realize it. When the combination of technical solutions appears contradictory or unachievable, it should be considered that the combination of technical solutions does not exist and is not within the protection scope of the present application.

[0064] Referring to Figure 1 The embodiment of the present application provides a water conservancy video monitoring safety protection system, which comprises three layers of top layer, middle layer and bottom layer. The top layer is a video monitoring device layer, the middle layer is an edge computing layer, and the bottom layer is a cloud platform layer. The data collected by the video monitoring device layer is processed by the edge computing layer and then interacts with the cloud platform layer.

[0065] The system fully utilizes the edge computing technology to reduce the network transmission pressure and improve the real-time processing capability. At the same time, through the multi-layer security mechanism, the safety, reliability and efficiency of the water conservancy video monitoring system are guaranteed, which is especially suitable for the safety protection needs of key infrastructures such as reservoirs.

[0066] In the embodiment, the video monitoring device layer comprises multiple video monitoring devices (video monitoring 1 to video monitoring n), which are respectively used for collecting video data of each area of the reservoir and transmitting the video stream to the edge device for processing.

[0067] The edge computing layer serves as a core processing unit and comprises six key functional modules, namely a transmission module, an interface module, a computing unit, a storage unit, a clock synchronization module and a security encryption module. The transmission module is used for receiving video stream data, the interface module is used for processing device communication, the computing unit is used for executing data analysis and feature extraction, the storage unit is used for providing local data caching, the clock synchronization module is used for ensuring system time consistency, and the security encryption module is used for protecting data.

[0068] In the cloud platform layer, a two-way communication channel is established between the cloud platform and the edge devices. Uplink, encrypted and compressed video streams and video warning information are transmitted, while downlink, dynamic instructions and time limits issued by the cloud platform are received. The cloud platform layer has three core functional components: instruction timeliness verification, private key management, and a distributed storage coordinator. The instruction timeliness verification is used to ensure the security and validity of instructions. The private key management is used to ensure the security of encrypted communication in the system. The distributed storage coordinator is used to realize efficient distributed storage and management of data.

[0069] Blockchain technology plays a crucial role in this system. The entire data processing flow begins with a consortium blockchain authentication process, ensuring that all connected devices and data sources are verified in a trusted manner. The system then prioritizes monitoring areas based on their security levels, implementing differentiated monitoring and storage strategies for areas of varying importance. The system generates unique identifiers for video data through hash calculations, guaranteeing data integrity and preventing tampering. The processed data is securely stored using a hybrid distributed storage mechanism, ensuring both high availability and improved access efficiency.

[0070] After the cloud platform issues encrypted commands, the system automatically verifies the validity of the commands from the edge device, forming a two-way verification mechanism. If the verification is successful, the cloud platform confirms receipt and records it on the blockchain, generating an immutable execution proof on the blockchain; if the verification fails, the system refuses to accept the command, reports the anomaly to the cloud platform, and actively requests new commands, forming a complete security loop.

[0071] The introduction of blockchain technology not only solves the problem of ensuring the authenticity and integrity of data in traditional video surveillance systems, but also realizes the trusted verification of the entire process of device authentication, data storage and instruction execution through distributed ledger and smart contract mechanisms, which greatly improves the security protection capabilities and reliability of video surveillance systems for critical infrastructure such as reservoirs.

[0072] See Figures 2-3 This invention also provides a water conservancy video surveillance security protection method, implemented using the aforementioned water conservancy video surveillance security protection system, comprising the following steps:

[0073] S1. A smart contract management device authentication mechanism based on a consortium blockchain architecture, combined with asymmetric encrypted digital certificate verification and device unique identifier verification, to achieve decentralized distributed secure access control.

[0074] S2. Based on the spatiotemporal characteristics and information entropy analysis of the video content, select an adaptive compression algorithm and adjust the compression parameters in real time. Implement differentiated processing strategies based on the importance level of the monitored area, and store the processed metadata on the blockchain through a hash algorithm.

[0075] S3, based on the dynamic key derivation algorithm of the blockchain consensus mechanism and high-precision timestamp, the video stream is encrypted by hierarchical segmentation, and the characteristic value is recorded in the blockchain, and a multi-encrypted secure transmission channel is constructed;

[0076] S4, based on the distributed hierarchical storage strategy of the blockchain, the hybrid mechanism of local cache and distributed storage of the blockchain is executed, and the automatic protection and data consistency synchronization functions based on the smart contract are provided;

[0077] S5, build time-sensitive cloud edge collaborative control mechanism, cloud platform issues encrypted instructions with ECDSA digital signature and accurate effective period identification through multi-channel mode, edge devices perform multi-level cryptography verification and execution according to instruction priority and timeliness, and record the execution results through hash processing and chain record; these dynamic instructions can adjust video processing parameters, update encryption strategies, manage key life cycle and perform remote security repair in real time according to the security situation, which not only ensures the security and controllability of the system in the changing threat environment, but also realizes the verifiable and traceable of all operations through distributed ledger technology, forming a complete security audit chain.

[0078] In the embodiment, the S1 further comprises:

[0079] S11, assign a globally unique identifier to each monitoring device and generate an asymmetric key pair, submit device information (such as GUID, public key, type, location) to the blockchain network, write it into the distributed ledger after multi-node consensus verification, and at the same time, the alliance chain authentication center issues a digital certificate containing device identity information, establishing a trusted digital identity of the device on the blockchain;

[0080] S12, after the edge node receives the video stream access request of the monitoring device, extract the device identifier, digital signature and timestamp, trigger the authentication smart contract to execute, the contract automatically retrieves device registration information from the blockchain account book, and at least verifies the validity of the digital certificate, the authenticity of the signature and the multi-dimensional factors of the device running state, to ensure the identity of the access device is real and reliable;

[0081] S13, the smart contract automatically allocates differentiated permission levels according to the importance of the area where the monitoring device is located (such as the core area of the dam, the general area), generates an access token containing permission information and validity period and signs it with a blockchain timestamp, records the authorization event on the chain, realizes decentralized access control based on the blockchain, and ensures the security of key area monitoring data;

[0082] S14, implement certificate life cycle management and exception handling mechanism, support multi-administrator multi-signature certificate regular rotation and real-time synchronization of revocation list, at the same time record the complete authentication process on the chain to form an unalterable audit log, establish authentication event correlation analysis capability, provide cross-domain authentication interoperability support, ensure the safety and controllability of the entire authentication process and the whole process traceability.

[0083] In this embodiment, the S2 further comprises:

[0084] S21, according to the spatio-temporal characteristics of the video stream (such as scene complexity, motion intensity, lighting conditions) and the information entropy analysis results, construct a video content feature vector, evaluate the video complexity through the deep learning model of the edge computing node, automatically select the optimal compression algorithm (such as H.265 / HEVC, AV1 or special water scene compression algorithm) for different feature types (such as static scene, dynamic water surface, personnel activity area), real-time calculate the best compression parameters (such as quantization parameter, GOP structure, motion estimation accuracy), and dynamically adjust the encoding configuration according to the network condition and computing resource, ensure the highest compression efficiency while retaining the key visual information;

[0085] S22, in order to ensure the credibility and unalterability of the video processing process, the system calculates the feature value of the processing metadata (including original video feature hash, selected compression algorithm parameter, processing timestamp, processing node identifier, etc.) of each video stream through SHA-256 and other hash algorithms, and submits the feature value together with the processing configuration digest to the blockchain network for storage, and writes it into the distributed ledger after verification by the smart contract, forming a credible timeline of processing history, at the same time, establish a video processing metadata index mechanism, support to query and verify the processing history of video in a certain period of time through blockchain, realize the traceability of the whole life cycle of video data, provide technical support for the legal effectiveness and integrity of subsequent video content, effectively prevent the video processing process from being tampered maliciously.

[0086] In this embodiment, in the S3, based on the dynamic key derivation algorithm (DKDA) of the blockchain consensus mechanism and high-precision timestamp, a double-layer encrypted video transmission mechanism is constructed, the construction process is: the edge device generates a random session key to encrypt the video data, and then uses the cloud platform public key to encrypt the session key, and sends it to the cloud platform, the cloud platform uses the private key to decrypt the session key and then decrypts the video data, the whole encryption channel key feature value is recorded in the blockchain to ensure unalterable.

[0087] In this embodiment, the S3 further comprises:

[0088] S31, based on the consensus timestamp of the blockchain network and the unique identification of the device, a dynamic key derivation algorithm is implemented, the latest block hash value of the blockchain, the device private key and the high-precision timestamp (accurate to millisecond level) are combined in a cryptographic operation, a master key seed is generated, a hierarchical key tree is derived from the master key seed through a key derivation function (KDF), including video content encryption key, metadata encryption key and authentication key, a key automatic rotation mechanism is realized, and even if a single key is leaked, the overall system security will not be compromised. At the same time, according to the sensitivity level of the video content, different strength encryption algorithms (such as AES-256, ChaCha20) and encryption modes (such as GCM, CTR) are used to build a layered encryption system that adapts to different security needs, and the key usage record is stored on the chain through zero-knowledge proof, ensuring that the key management process is auditable but does not leak the actual content of the key;

[0089] S32, the video stream is dynamically segmented according to fixed time intervals (such as 5 seconds) or scene change thresholds, each video segment is independently encrypted, ensuring that even if a single segment is cracked, it will not affect the security of other segments, a unique identifier and integrity check value are generated for each encrypted video segment, segment metadata containing encryption parameters, timestamps and integrity hashes are constructed, all video segment feature hashes are organized through a Merkle tree structure, only the Merkle root hash and key node hash are submitted to the blockchain storage, while reducing the storage pressure of the blockchain, ensuring data integrity verification, and designing a smart contract to automatically verify the Merkle proof path of the newly submitted video segment, ensuring that the Merkle proof path is consistent with the on-chain root hash, and recording the verification result on the blockchain;

[0090] S33, fuse TLS / SSL protocol and blockchain zero-knowledge proof technology to build a multi-level secure transmission channel, with the construction process being:

[0091] S331, establish a TLS-based encrypted communication tunnel, use strong cipher suites to ensure transmission layer security,

[0092] S332, implement a two-way authentication mechanism based on blockchain identity at the application layer, verify that both parties hold the correct blockchain identity private key through zero-knowledge proof without exposing the private key itself,

[0093] S333, design a transmission session binding mechanism, associate each transmission session with the authorized record on the blockchain, ensure that only authorized sessions can receive specific video streams,

[0094] S333, implement end-to-end data integrity verification, the receiving end verifies the consistency of the video segment hash and the blockchain record to confirm that the data has not been tampered with.

[0095] In this embodiment, the S4 further comprises:

[0096] S41, a multi-level hybrid storage architecture is constructed, and the specific construction process is:

[0097] S411, the edge node provides local cache, the regional node is responsible for medium-term storage backup, the cloud realizes long-term archiving, and the blockchain stores key metadata and evidence hash;

[0098] S412, the data flow among each storage level is automatically coordinated through intelligent strategy;

[0099] S413, a network interruption protection mechanism is realized, and the system switches to a local emergency storage mode and increases the sampling rate when the network is interrupted;

[0100] S414, after the network is restored, the key data is transmitted through incremental synchronization and the integrity is verified;

[0101] S415, a distributed data recovery mechanism is deployed, and the data is reconstructed from distributed nodes in a disaster scenario by using the blockchain record, to ensure the system availability under extreme conditions;

[0102] S42, fine data access control is realized based on the blockchain, the smart contract defines the permissions of different roles, all data access operations are recorded on the chain to form an unalterable log, attribute-based encryption access control is realized, sensitive data security is ensured, comprehensive data use audit function is provided, complete access history of video clips is supported, data operation compliance is automatically checked by the smart contract, to ensure compliance with safety policies and regulations, and a comprehensive data protection and traceability system is constructed.

[0103] In the embodiment, the S5 further includes:

[0104] S51, the cloud platform generates dynamic security control instructions including temporary authorization credentials, encryption key rotation parameters and security policy updates based on the zero trust security model, each instruction is embedded with high-precision timestamp and validity period limit, and is signed by the elliptic curve digital signature algorithm (ECDSA), to ensure that the instruction itself cannot be forged and tampered with; these dynamic instructions can adjust the protection strategy of the edge device according to the real-time security situation analysis results, such as increasing video encryption strength or changing key generation frequency when potential attacks are detected, so that the system can actively respond to the changing security threat environment;

[0105] S52. After receiving the instruction, the edge device implements a multi-layered verification mechanism. First, it verifies the cryptographic correctness of the instruction's digital signature. Then, it checks whether the timestamp is within the trusted time window. Finally, it verifies whether the instruction conforms to the preset security policy. Only instructions that pass all verifications can be executed, ensuring that the edge device will not execute expired or forged security instructions, thus preventing replay attacks and man-in-the-middle attacks. This verification mechanism supports the cloud platform in implementing full lifecycle management of encryption keys, including periodic key rotation and emergency key revocation, ensuring that key materials are valid within the preset security time window and automatically expire afterward, preventing the risk of key leakage.

[0106] S53. After the edge device executes a security command, the execution result is recorded in a verifiable encrypted manner, including the command execution time, details of security configuration changes, and system status changes. These records are hashed and written to a distributed ledger to establish a complete security operation audit chain. At the same time, the system regularly performs security command compliance checks to ensure that the cloud-edge security configuration remains consistent and timely. This process supports the cloud platform to realize remote security response and repair functions. When vulnerabilities or abnormal behavior are found in the edge device, repair commands can be issued immediately for security updates, including software patch installation, configuration error correction, or abnormal connection blocking. This allows for rapid response to security events without interrupting core monitoring functions, ensuring the safe and stable operation of the reservoir monitoring network.

[0107] In this embodiment, the method of using the blockchain consensus mechanism and the improved blockchain fusion quantum-resistant dynamic key derivation algorithm QR-DKDA with the multidimensional secure transmission channel mathematical model in step S3 specifically includes:

[0108] a. Define the quantum-resistant dynamic key derivation function:

[0109]

[0110] in, Representing the Derived keys for a time window Representative equipment A unique identifier, This represents a high-precision timestamp, accurate to the microsecond level. This represents the hash value of the previous block. Represents the environmental entropy factor, which includes network state characteristics;

[0111] This quantum-resistant dynamic key derivation function is implemented through multi-round hybrid hashing to ensure quantum resistance in key generation.

[0112] To cope with complex security threats, an adaptive multi-level encryption strategy is adopted, that is, first, the encryption efficiency is optimized through a dynamic segmentation mechanism, and then a three-layer cascade encryption is used to ensure data security, which is expressed as:

[0113]

[0114] wherein, represents the security threat evaluation value of time , respectively represents the threat evaluation weight coefficient, represents the network threat evaluation function, represents the device anomaly evaluation function, represents the data sensitivity evaluation function;

[0115] b, the adaptive segmentation mechanism based on content complexity significantly improves the system efficiency, and the video stream segmentation size is determined by the following model:

[0116]

[0117] wherein, represents the size of the th video segment, and represent the segmentation size adjustment parameters, represents the video content complexity evaluation function, represents the video content of the th segment and its adjacent segment;

[0118] The segmented video stream is encrypted by three-layer cascade encryption to ensure data security, which is expressed as:

[0119]

[0120] wherein, represents the lattice encryption algorithm based on quantum security, represents public key, represents the Galois counter mode of the advanced encryption standard, represents a high-performance stream cipher algorithm.

[0121] On the basis of multi-layer encryption, the application further introduces blockchain technology to realize the verifiability of key and data integrity. Specifically, it includes vector commitment Merkle tree and key validity verification based on smart contract:

[0122] Innovatively, the vector commitment Merkle tree structure is proposed:

[0123]

[0124] The root calculation uses a weighted aggregation method:

[0125]

[0126] Verify key validity using blockchain smart contracts:

[0127]

[0128] in, Merkle tree representing vector commitment, and These represent the eigenvalue vector and the weight vector, respectively. Represents the weighting coefficient. Represents a cryptographic hash function. Represents the modulus of a prime number. Representing the The verification value of the derived key within a time window. Represents the execution function of a blockchain smart contract. Representing the The hash value of the derived key for each time window. Represents a high-precision timestamp. Representative equipment A unique identifier.

[0129] In addition to security, this invention also optimizes transmission performance and reliability. Specifically, it includes an adaptive transmission strategy and an error detection and recovery mechanism based on forward error correction.

[0130] Utility function-based transfer strategy selection:

[0131]

[0132] Error detection and recovery using Reed-Solomon codes:

[0133]

[0134] in, Representing time The optimal transmission strategy Represents a set of optional strategies. Represents the data priority function. Represents the utility function. Represents the network state function. Represents the probability of error recovery. Represents the codeword length of the Reed-Solomon code. Represents the number of information symbols in the Reed-Solomon code. This represents the symbol error rate.

[0135] In the S5, the use method of the time-sensitive cloud-edge collaborative control mechanism includes:

[0136] a. The time synchronization between the edge device and the cloud platform adopts an improved network time protocol (NTP) combined with a blockchain timestamp verification, and is formulated as:

[0137]

[0138] wherein, represents a time deviation, represents a cloud platform timestamp, represents an edge device timestamp, represents a round-trip time delay;

[0139] b. The cloud platform generates an encrypted instruction with a time-sensitive verification parameter based on the time synchronization mechanism. Each instruction issued from the cloud platform to the edge device contains a valid time window, which is calculated by the following formula:

[0140]

[0141] wherein, represents an instruction issue timestamp, and TTL represents an instruction survival time, represents a pre-fault tolerance time, represents a post-fault tolerance time (dynamically adjusted according to network conditions);

[0142] c. After receiving the instruction, the edge device first corrects the time deviation, then verifies the instruction validity, if the verification is successful, the cloud platform confirms the reception and prepares to record the result on the chain, otherwise, if the verification fails, the instruction is rejected and an exception is reported, then the edge device waits for the response of the cloud platform and prepares the verification environment for the new instruction.

[0143] In the above entire process, the time sensitivity is guaranteed by the following key technologies:

[0144] (1) Adaptive TTL calculation: dynamically adjust the instruction validity period according to network conditions and threat levels:

[0145]

[0146] wherein, represents a dynamically adjusted instruction validity time, in milliseconds (ms), represents a basic instruction validity time, usually set to 5000 ms as the default value of the system, represents a network condition change factor, represents a security threat level change factor.

[0147] (2) Time-sensitive score: continuously monitor the difference between instruction execution time and expectation:

[0148]

[0149] wherein, represents the time-sensitive score of the instruction, the value range is [0, 1], the higher the value, the better the time sensitivity, represents the actual execution timestamp of the instruction, represents the instruction issue timestamp, represents the maximum delay time allowed by the system, which is usually set according to the importance level of the region.

[0150] (3) Abnormal handling: when the time-sensitive anomaly is detected, the system starts the exponential backoff retry mechanism:

[0151]

[0152] wherein, represents the waiting time for the next retry, represents the basic delay time, represents the current retry count, starting from 0, is a criticality factor, the value range is [0, 1].

[0153] To verify the feasibility and effectiveness of the water conservancy video monitoring security protection method proposed by the present application which fuses edge computing and blockchain technology, the present application establishes a simulation experiment environment in the reservoir of the XX province demonstration area, and deploys a complete video monitoring security protection system which fuses edge computing and blockchain technology. The specific implementation details are as follows:

[0154] 1. System hardware architecture

[0155] Edge device configuration:

[0156] Camera device: uses Hikvision DS-2CD3T86FWDV2-I3S(B) infrared network camera, 8MP high-definition resolution, supports H.265+ encoding;

[0157] Edge computing node: NVIDIA Jetson Xavier NX development kit (16GB memory, 384 CUDA cores), equipped with JetPack 4.6 software package;

[0158] Edge storage: Western Digital WD Purple 4TB monitoring level hard disk (WD40PURZ);

[0159] Network equipment: Cisco Catalyst 9300-24P switches, configured with VLAN isolation and access control lists;

[0160] 2. System software architecture

[0161] 1) Operating system and basic software:

[0162] Edge node: Ubuntu 20.04 LTS, Docker 20.10.8, CUDA 11.4

[0163] Cloud platform: CentOS 8.4, Kubernetes 1.21 cluster management

[0164] Blockchain platform: Consortium blockchain network based on Hyperledger Fabric 2.4

[0165] 2) Security components:

[0166] PKI infrastructure: Certificate management system built with OpenSSL 3.0

[0167] Encryption library: High-performance encryption operations using libsodium 1.0.18

[0168] Smart contract: Chaincode smart contract developed in Go language

[0169] Time synchronization: High-precision time protocol PTP (IEEE 1588) ensures system time deviation <1ms

[0170] 3. Implementation process

[0171] S1, device security access authentication implementation

[0172] This embodiment constructs a distributed security access mechanism based on blockchain, each monitoring device is preloaded with X.509 digital certificate and PUF hardware feature identifier. When the device is online, it establishes a secure channel through TLS 1.3 protocol, submits authentication information to the consortium chain, and performs multiple verification by the "DeviceAuth" smart contract. After verification, the system records the device status on the blockchain and issues a permission token, which the device uses for subsequent operations. Test results show that 10 legal devices all pass the authentication, 3 fake devices are intercepted, the verification mechanism accuracy reaches 100%, effectively preventing unauthorized devices from accessing the system.

[0173] S2, adaptive video processing and differentiated policy implementation

[0174] According to the importance of the reservoir monitoring area, the 25 monitoring points are divided into three levels: the core facilities such as the dam body (5) are the first level, the important facilities such as the power station plant (8) are the second level, and the surrounding area of the reservoir area (12) are the third level. Different levels are treated differently: the first level maintains 4K resolution full-frame analysis and frequent chaining for storage; the second level reduces the resolution under normal circumstances and automatically improves in abnormal conditions; the third level uses low resolution and dynamically adjusts the bit rate. The system evaluates the scene complexity in real time through the information entropy analysis algorithm and automatically adjusts the parameters. Tests prove that this scheme saves 22.3% bandwidth and 18.7% storage space compared to the traditional way, while ensuring the video quality of key scenes.

[0175] S3, double-layer encrypted video transmission mechanism implementation

[0176] The embodiment adopts double-layer encryption to ensure transmission security: the edge device generates a new AES-256-GCM random session key every 30 minutes, and encrypts the video data in slices (every 10 seconds, using different initialization vectors); the session key is encrypted with the RSA-4096 cloud platform public key and sent together with the encrypted video; at the same time, the message hash value is recorded through the blockchain to form an unalterable transmission proof chain. During the 30-day test period, the system processed 46.8TB of video data, with a successful encryption transmission rate of 99.997%, no key leakage or tampering events, and a transmission delay increase of only 7.2ms, which has almost no impact on real-time monitoring.

[0177] S4, distributed hierarchical storage strategy implementation

[0178] The embodiment constructs a three-layer storage architecture: the edge local storage layer uses WD Purple 4TB monitoring hard disk to save complete video for 1-7 days according to the importance of the monitoring area; the cloud platform storage layer uses NetApp system to realize redundant storage, save complete video for 15-90 days and convert it into long-term compressed archive; the blockchain storage layer permanently saves metadata and hash values. The system also implements an intelligent network failure protection mechanism, which automatically adjusts the storage strategy through the "EmergencyBackup" smart contract, prioritizes saving key area data, and automatically synchronizes metadata after network recovery. Tests prove that even in the case of network failure, the system can still save all key monitoring data, and the data consistency verification pass rate is 100% after recovery.

[0179] The embodiment of the application also provides a computer readable storage medium storing a computer program, which, when executed by a processor, causes the processor to perform the steps of the above-mentioned water conservancy video monitoring security protection method.

[0180] Reference Figure 4The present invention also provides a computer device, including a memory and a processor. The memory stores a computer program, and when the computer program is executed by the processor, the processor performs the steps of the above-described water conservancy video monitoring security protection method.

[0181] This invention also provides a computer program product containing instructions that, when run on a computer, causes the computer to perform the steps of the above-described water conservancy video monitoring security protection method.

[0182] It is understood that the system, device and storage medium provided in the embodiments of the present invention correspond to the method provided in the embodiments of the present invention, and the explanation, examples and beneficial effects of the relevant content can be referred to the corresponding parts of the above-mentioned water conservancy video monitoring security protection method.

[0183] It should be noted that those skilled in the art will understand that all or part of the steps implemented in the embodiments of the present invention can be implemented entirely or partially by software, hardware, firmware, or any combination thereof. When implemented in hardware, it can be implemented entirely or partially by purchasing standard parts or modifications. When implemented in software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid state disks (SSDs)).

[0184] In summary, the present application provides a water conservancy video monitoring security protection system and method that integrates edge computing and blockchain technology to address the deficiencies of traditional water conservancy video monitoring systems in terms of security, reliability, and real-time performance. Specifically, the present application uses an intelligent contract management device authentication mechanism based on a consortium blockchain architecture, combined with asymmetric encryption digital certificate verification and device unique identifier checking, to achieve decentralized distributed security access control. By analyzing the spatiotemporal characteristics and information entropy of video content, the present application dynamically selects adaptive compression algorithms and implements differentiated processing strategies based on the importance of the monitoring area, while ensuring data integrity by hashing and storing metadata. The present application innovatively constructs a double-layer encrypted video transmission mechanism based on blockchain consensus mechanisms and high-precision timestamps, with edge devices generating random session keys to encrypt video data and then using cloud platform public keys to encrypt the session keys, achieving high-strength secure transmission. By implementing a distributed hierarchical storage strategy based on blockchain and a hybrid mechanism of local cache and distributed storage, combined with the automatic network disconnection protection function of the intelligent contract, the present application addresses data consistency and reliability issues. Finally, the present application constructs a time-sensitive cloud-edge collaborative control mechanism based on a zero-trust architecture, ensuring instruction security through ECDSA digital signatures and expiration date identifiers, enabling dynamic adjustment of security policies and remote security repair, while forming a complete security audit chain through distributed ledger technology. In this way, the present application, through the deep integration of edge computing, blockchain technology, and advanced cryptography methods, comprehensively improves the security, reliability, and operational efficiency of water conservancy video monitoring systems, providing an innovative technical solution for water conservancy safety monitoring and having good application prospects and market value.

[0185] It should be understood that the examples and embodiments described herein are for illustration only and are not intended to limit the present application, and those skilled in the art can make various modifications or changes based on it, and any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application shall be included in the protection scope of the present application.

Claims

1. A method for security protection of water conservancy video surveillance, characterized in that, Includes the following steps: S1. Edge devices use a smart contract management device authentication mechanism based on a consortium blockchain architecture to perform asymmetric encrypted digital certificate verification and device unique identifier verification on the connected video surveillance devices, thereby achieving decentralized distributed secure access control. S2. The edge device selects an adaptive compression algorithm based on the spatiotemporal characteristics and information entropy analysis of the video content of the video surveillance equipment, and adjusts the compression parameters in real time. It implements a differentiated processing strategy based on the importance level of the monitored area, and the edge device stores the processed metadata on the blockchain through a hash algorithm. S3, the edge device uses a blockchain consensus mechanism and a dynamic key derivation algorithm with high-precision timestamps to perform layered and segmented encryption processing on the video stream of the video surveillance equipment, and records the feature values ​​in the blockchain to build a multi-encrypted secure transmission channel for the cloud platform; S4, Edge devices and cloud platforms adopt a distributed hierarchical storage strategy based on blockchain, implement a hybrid mechanism of local high-speed caching of edge devices and distributed storage of blockchain, and provide automatic protection against network outages and data consistency synchronization functions based on smart contracts. S5. Construct a timely cloud-edge collaborative control mechanism. The cloud platform issues encrypted commands with ECDSA digital signatures and precise validity period identifiers through multiple channels. Edge devices perform multi-level cryptographic verification and execution based on command priority and timeliness, and record the execution results on the blockchain after hash processing. S3 further includes: S31. Based on the consensus timestamp and unique device identifier of the blockchain network, a dynamic key derivation algorithm is implemented. The latest block hash value of the blockchain is cryptographically combined with the device private key and high-precision timestamp to generate a master key seed. A hierarchical key tree is derived from the master key seed through a key derivation function, including video content encryption key, metadata encryption key and authentication key. An automatic key rotation mechanism is implemented to ensure that even if a single key is leaked, it will not endanger the overall system security. At the same time, according to the sensitivity level of the video content, different strength encryption algorithms and encryption modes are adopted to build a layered encryption system that adapts to different security needs. The key usage record is stored on the chain through zero-knowledge proof to ensure that the key management process is auditable but does not disclose the actual content of the key. S32. Dynamically segment the video stream according to fixed time intervals or scene change thresholds, and encrypt each video segment independently to ensure that even if a single segment is cracked, it will not affect the security of other segments. Generate a unique identifier and integrity verification value for each encrypted video segment, construct segment metadata containing encryption parameters, timestamps, and integrity hashes, organize the feature hash values ​​of all video segments through a Merkle tree structure, and submit only the Merkle root hash and key node hashes to the blockchain storage. This reduces the storage pressure on the blockchain while ensuring data integrity and verifiability. Design a smart contract to automatically verify the Merkle proof path of newly submitted video segments, ensure that the Merkle proof path is consistent with the on-chain root hash, and record the verification results on the blockchain. S33. Integrating TLS / SSL protocols and blockchain zero-knowledge proof technology, a multi-layered secure transmission channel is constructed, with the following construction process: S331. Establish a TLS-based encrypted communication tunnel and use strong cryptographic suites to ensure transport layer security; S332. Implement a two-way authentication mechanism based on blockchain identity at the application layer, and verify that both communicating parties hold the correct blockchain identity private key through zero-knowledge proof without exposing the private key itself; S333. Design a transmission session binding mechanism to associate each transmission session with an authorization record on the blockchain, ensuring that only authorized sessions can receive specific video streams; S334. Implement end-to-end data integrity verification. The receiving end verifies the consistency between the video segment hash and the blockchain record to confirm that the data has not been tampered with.

2. The water conservancy video surveillance security protection method as described in claim 1, characterized in that, S1 further includes: S11. Assign a globally unique identifier to each video surveillance device and generate an asymmetric key pair. Submit the video surveillance device information to the blockchain network. After multi-node consensus verification, write it into the distributed ledger. At the same time, the consortium blockchain certification center issues a digital certificate containing the device's identity information to establish a trusted digital identity for the device on the blockchain. S12. After receiving the video stream access request from the video surveillance device, the edge device extracts the device identifier, digital signature and timestamp, triggers the execution of the authentication smart contract, and the contract automatically retrieves the device registration information from the blockchain ledger and ensures that the access device is authentic and trustworthy by verifying at least the validity of the digital certificate, the authenticity of the signature and the device's operating status through multiple dimensions. S13. The smart contract automatically assigns differentiated permission levels based on the importance of the area where the video surveillance equipment is located, generates an access token containing permission information and validity period, signs it with a blockchain timestamp, records the authorization event on the chain, realizes decentralized access control based on blockchain, and ensures the security of monitoring data in key areas. S14. Implement certificate lifecycle management and exception handling mechanisms, support the periodic rotation of certificates with multiple administrators and multi-signatures, and real-time synchronization of revocation lists. At the same time, record the complete authentication process on the blockchain to form an immutable audit log, establish authentication event correlation analysis capabilities, provide cross-domain authentication interoperability support, and ensure that the entire authentication process is secure, controllable, and fully traceable.

3. The water conservancy video surveillance security protection method as described in claim 1, characterized in that, S2 further includes: S21. Based on the spatiotemporal characteristics and information entropy analysis results of the video stream, construct video content feature vectors, evaluate video complexity through the deep learning model of edge devices, automatically select the optimal compression algorithm for different feature types, calculate the best compression parameters in real time, and dynamically adjust the encoding configuration according to network conditions and computing resources to ensure the highest compression efficiency while preserving key visual information. S22. To ensure the credibility and immutability of the video processing process, the system calculates a feature value for the processing metadata of each video stream using a hash algorithm, and submits this feature value along with a processing configuration summary to the blockchain network for notarization. After verification by a smart contract, it is written into the distributed ledger to form a credible timeline of processing history. At the same time, a video processing metadata indexing mechanism is established to support the query and verification of the processing history of videos within a specific time period through the blockchain, realizing the traceability of the entire life cycle of video data, providing technical protection for the legal validity and integrity of subsequent video content, and preventing the video processing process from being maliciously tampered with.

4. The water conservancy video surveillance security protection method as described in claim 1, characterized in that, In S3, a two-layer encrypted video transmission mechanism is constructed based on the blockchain consensus mechanism and the dynamic key derivation algorithm with high-precision timestamps. The construction process is as follows: the edge device generates a random session key to encrypt the video data, then uses the cloud platform's public key to encrypt the session key, packages it and sends it to the cloud platform, the cloud platform uses the private key to decrypt and obtain the session key, and then decrypts the video data. The key feature value of the entire encryption channel is recorded in the blockchain to ensure that it cannot be tampered with.

5. The water conservancy video surveillance security protection method as described in claim 1, characterized in that, S4 further includes: S41. Construct a multi-tiered hybrid storage architecture. The specific construction process is as follows: S411: Edge devices provide local high-speed caching, regional nodes are responsible for medium-term storage backup, cloud platforms realize long-term archiving, and blockchain stores key metadata and evidence hashes. S412: Data flow between different storage tiers is automatically coordinated through intelligent strategies; S413. Implement a network outage protection mechanism, switching to local emergency storage mode and increasing the sampling rate when the network is interrupted; S414. After the network is restored, key data is transmitted incrementally and its integrity is verified. S415. Deploy a distributed data recovery mechanism, using blockchain records to reconstruct data from distributed nodes in disaster scenarios, ensuring system availability under extreme conditions; S42. Based on blockchain, implement fine-grained data access control. Smart contracts define different role permissions. All data access operations are recorded on the chain to form an immutable log, realizing attribute-based encrypted access control, ensuring the security of sensitive data, providing comprehensive data usage auditing functions, supporting the tracking of the complete access history of video clips, automatically checking the compliance of data operations through smart contracts, ensuring compliance with security policies and regulatory requirements, and building a comprehensive data protection and traceability system.

6. The water conservancy video surveillance security protection method as described in claim 1, characterized in that, S5 further includes: S51, the cloud platform uses a zero-trust security model to generate dynamic security control instructions, including temporary authorization credentials, encryption key rotation parameters and security policy updates. Each instruction is embedded with a high-precision timestamp and validity period limit, and is signed by an elliptic curve digital signature algorithm to ensure that the instruction itself cannot be forged or tampered with. S52. After receiving the instruction, the edge device implements a multi-level verification mechanism. First, it verifies the cryptographic correctness of the instruction's digital signature. Then, it checks whether the timestamp is within the trusted time window. Finally, it verifies whether the instruction conforms to the preset security policy. Only instructions that pass all verifications can be executed, ensuring that the edge device will not execute expired or forged security instructions, thereby preventing replay attacks and man-in-the-middle attacks. S53. After the edge device executes the security command, the execution result is recorded in a verifiable encrypted manner, including the command execution time, details of security configuration changes and system status changes. These records are written into the distributed ledger after being hashed to establish a complete security operation audit chain. At the same time, the system regularly performs security command compliance checks to ensure that the cloud-edge security configuration remains consistent and timely.

7. A water conservancy video surveillance security protection system, applicable to the water conservancy video surveillance security protection method as described in any one of claims 1-6, characterized in that, It includes a three-layer structure: top layer, middle layer, and bottom layer. The top layer is the video surveillance equipment layer, the middle layer is the edge device layer, and the bottom layer is the cloud platform layer. The data collected by the video surveillance equipment layer is processed by the edge device layer and then interacts securely with the cloud platform layer.

8. The water conservancy video monitoring security protection system as described in claim 7, characterized in that, The video surveillance equipment layer includes multiple video surveillance devices, which are used to collect video data from various areas of the reservoir and transmit the video streams to edge devices for processing. The edge device layer, as the core processing unit, includes six key functional modules: a transmission module, an interface module, a computing unit, a storage unit, a clock synchronization module, and a security encryption module. The transmission module is used to receive video stream data, the interface module is used to process device communication, the computing unit is used to perform data analysis and feature extraction, the storage unit is used to provide local data caching, the clock synchronization module is used to ensure system time consistency, and the security encryption module is used to protect data. In the cloud platform layer, a two-way communication channel is established between the cloud platform and the edge devices. Uplink, encrypted and compressed video streams and video warning information are transmitted, while downlink, dynamic instructions and time limits issued by the cloud platform are received. The cloud platform layer has three core functional components: instruction timeliness verification, private key management, and a distributed storage coordinator. The instruction timeliness verification is used to ensure the security and validity of instructions. The private key management is used to ensure the security of encrypted communication in the system. The distributed storage coordinator is used to realize efficient distributed storage and management of data.

9. A computer device, characterized in that, It includes a memory and a processor, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor causes the processor to perform the water conservancy video monitoring security protection method as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Steel plant intelligent video monitoring data storage security sharing method based on block chain

    CN119513926A

  • Industrial data secure storage method and system based on block chain

    CN120012134A