Video network security access device based on zero trust
By integrating multiple security technologies through a zero-trust-based video network security access control device, risks such as unauthorized access, equipment backdoors, and network intrusions in substation video surveillance networks are resolved. This enables efficient and secure access to video surveillance equipment and data transmission, ensuring the security and reliability of the power grid network.
Patent Information
- Application Number
- CN202511209938.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-27
- Publication Date
- 2025-11-14
AI Technical Summary
Existing technologies are insufficient to comprehensively address security risks in substation video surveillance networks, such as unauthorized device access, backdoors, network intrusion, and sensitive data leakage. These risks are particularly prevalent after the video surveillance system is connected to the main network.
Employing a zero-trust-based video network security access control device, it integrates a network layer 3 switch, firewall, zero-trust device access control module, zero-trust network intrusion prevention module, zero-trust VPN encryption gateway, SDWAN network controller, and video GB35114 security gateway. Combined with the power system HarmonyOS, TF card, domestic cryptographic chip, GB35114 video security networking protocol, and security situation awareness technology, it achieves strict device access control, network stealth, protocol analysis, and data encryption, among other security protections.
By implementing measures such as multi-layered device access verification, security zoning, protocol standardization, data encryption, and network stealth, the security of video surveillance equipment has been significantly improved, preventing unauthorized access and network intrusion, ensuring the network security of the power grid, reducing operation and maintenance costs, and improving implementation efficiency.
Smart Images

Figure CN120956857A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of video network security access control technology, and in particular to a video network security access control device based on zero trust. Background Technology
[0002] As the core hub of the power system, the safe and stable operation of substations directly affects the reliability and power supply quality of the power system. To ensure substation safety, video surveillance systems use high-definition cameras, NVRs (Network Video Recorders), and intelligent analysis software to achieve comprehensive monitoring of the substation and its surroundings. This allows for the timely detection of safety hazards such as equipment failures, human error, and fires, making it a crucial means of substation safety protection.
[0003] However, as video surveillance systems become increasingly integrated with the main network, their security risks are becoming more prominent, mainly including: Risk of unauthorized device access: Substations have limited physical security conditions and cameras are easily replaced. Attackers can illegally access PCs and other devices by forging IP and MAC addresses and use the video surveillance network to attack the main network. Equipment backdoor risk: If video surveillance cameras, NVRs and other equipment have system backdoors or Trojan programs, they may launch network penetration attacks on other substation equipment in the vertical main network or horizontal network. Network intrusion risk: After the substation is connected to the main network, the power control equipment and NVR in the computer room are vulnerable to malicious attacks such as viruses, Trojans, APT attacks, and DDoS attacks. Risk of sensitive data leakage: Video surveillance image data may be maliciously used by third parties, resulting in the leakage of sensitive information; Application platform risks: The mainnet video surveillance system application platform exposes HTTP, SIP and other application services, making it an easy target for attacks.
[0004] Existing technologies are insufficient to comprehensively address the aforementioned risks, necessitating an integrated, industrial-grade network security device incorporating innovative security technologies to meet the security protection needs of substation video surveillance networks. Summary of the Invention
[0005] To address the aforementioned technical problems, the technical solution adopted by this invention is as follows: According to a first aspect of this application, a zero-trust-based video network security access control device is provided, the device integrating a network layer 3 switch, a firewall, a zero-trust device access control module, a zero-trust network intrusion prevention module, a zero-trust VPN encryption gateway, an SDWAN network controller and a video GB35114 security gateway. The device adopts a zero-trust security technology framework, combining the power HarmonyOS operating system, TF card, domestic cryptographic chip, GB35114 video security networking protocol, VPN and security situation awareness technology to achieve security protection for the substation video monitoring network.
[0006] Furthermore, the zero-trust device access control module adopts a five-layer security access protection mechanism, including the binding and verification of unique ID number, password, IP, MAC and port; Register the camera's unique ID number and password on the secure access gateway, and bind the camera's IP and MAC address to a designated physical port. If the unique ID number is forged and the password does not match, the device will be prohibited from accessing the gateway.
[0007] Furthermore, it also includes a security partitioning module, which is configured such that: the video system, the bearer network, and the video terminals are strictly prohibited from interconnecting across regions; Vertical cross-region interaction requires network aggregation or address translation within the same security zone before horizontal access can be performed; services in low-security zones are prohibited from actively connecting to services in high-security zones, and perception layer devices are prohibited from actively initiating access to the main network.
[0008] Furthermore, it also includes a protocol analysis module, which is configured to: establish a service whitelist based on the GB28181 standard protocol, close non-service ports by default, perform data control on service ports based on the protocol feature library whitelist, identify whether IPCs use the GB28181 standard for access, and alarm and block terminals that do not comply with the national standard. Based on the GB35114-2017 standard, deep identification is performed on registration messages, control messages, and video stream messages. The GB28181 protocol is extended and converted to the GB35114 protocol for transmission. Terminals that do not conform to the GB35114 standard are blocked and alarmed in real time.
[0009] Furthermore, it also includes a data security protection module, which is configured to: verify the transmission and distribution data through digital signatures to ensure the authenticity of the video data source and prevent tampering; and adopt two-way authentication and two-way data encryption, with encryption algorithms being the SM2, SM3, and SM4 national cryptographic algorithms, to ensure data confidentiality and integrity.
[0010] Furthermore, it also includes a network stealth module, which is configured to establish a virtual private network between the secure access gateway and the secure admission gateway, and not expose its IP address and port to the outside world; The secure access gateway, secure admission gateway and video security service platform use SPA technology, which denies all connections by default and opens access channels only after authentication with a single packet authentication token; the secure access gateway and secure admission gateway use private UDP encrypted communication technology.
[0011] Furthermore, it also includes an access control module, which is configured as follows: In terms of vertical control, it only allows cameras and NVRs to interact with specific video servers, and achieves fine-grained control through a combination of IP, port, time, and protocol, prohibiting access to applications outside the designated server; In terms of horizontal control, it prohibits access between cameras and between secure access gateways by default, and achieves pairwise isolation through a combination of IP, port, time, and protocol, blocking east-west attacks.
[0012] Furthermore, the SDWAN network controller is configured to support cameras and NVRs to form self-organizing networks through SD-WAN technology, and to form a self-organizing network based on a dual-protocol virtual private network of IPv6 and IPv4 with zero-trust network stealth. The video server can directly access the camera and NVR addresses and ports without being restricted by region or IP, and select the optimal path through routing policies.
[0013] Furthermore, it also includes a lateral isolation module, which is configured to: prohibit communication between physical interfaces of security access devices; prohibit communication between security access devices between substations; and prohibit communication between monitoring devices.
[0014] Furthermore, it also includes a vertical encryption authentication module, which is configured such that: the security camera with integrated TF password card and the security access device authenticate access through a unique identifier, and after access is granted, the data is transmitted using the national cryptographic algorithm; The identities of video terminals and security access devices are uniformly identified and managed. Security access devices complete two-way identity authentication before interacting with the main network. When video terminals access the main network through security access devices, encrypted authentication is used to achieve IP layer encryption and two-way authentication for data transmission.
[0015] The present invention has at least the following beneficial effects: This invention relates to a zero-trust-based video network security access control device. Addressing the security risks associated with device access in substation video surveillance networks, it employs a zero-trust security framework, combining it with the power grid operating system, domestically produced cryptographic chips, and other technologies to form an integrated security protection solution. Through strict device access control, network stealth, and protocol analysis strategies, it significantly enhances the security access level of video surveillance equipment, effectively defending against threats such as unauthorized access and network intrusion, and ensuring the security of the power grid network.
[0016] Domestically produced and controllable: The device uses domestically produced CPUs, memory, national cryptographic chips, the HarmonyOS operating system for power systems, and zero-trust software with independent intellectual property rights, meeting the security protection requirements of critical power infrastructure.
[0017] Zero Trust Technology Innovation Application: Innovatively apply the zero trust concept of "never trusting, continuous authentication" in IoT scenarios, and integrate the zero trust security client into the HarmonyOS operating system of cameras and NVRs to achieve transparent and secure access.
[0018] Enhanced security situation awareness: By using zero-trust SDWAN intelligent routing technology, the video terminal network data of the substation production equipment room is mirrored to the main station security service resource pool, and APT attack analysis system, honeypot system, etc. are centrally deployed to achieve security situation awareness of all substation production equipment rooms, solving the pain point that substation production equipment rooms cannot be configured with professional security analysis systems.
[0019] Effectively addressing the pain points of existing technologies, this invention achieves secure access control for substation cameras, NVRs, and integrated data network equipment by integrating functions such as switches, firewalls, and zero-trust access control into a security access device. It improves the security protection capabilities of substation terminals and networks, simplifies equipment deployment processes, enhances implementation efficiency, reduces the professional skills required of maintenance personnel, and decreases the probability of network security incidents.
[0020] By optimizing the equipment access process and reducing operation and maintenance costs (up to 70%), this device reduces losses caused by cybersecurity incidents and has a high competitive advantage in the market. As a general-purpose edge security device, it can be extended to various edge IoT environments, providing a one-stop solution to the security pain points of edge IoT construction. It strongly promotes the development of smart grids, ubiquitous power IoT, and other fields, accelerates the process of cloud-edge collaborative applications of IoT in various industries, and improves the performance, security, and reliability of IoT, thus possessing high socio-economic value. Attached Figure Description
[0021] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0022] Figure 1 This is a technical architecture diagram of GB35114 public security video surveillance network information security provided in an embodiment of the present invention; Figure 2 This is a schematic diagram of the system architecture provided in an embodiment of the present invention; Figure 3 This is a schematic diagram of the technical framework provided for an embodiment of the present invention; Figure 4 This is a schematic diagram of the framework of a zero-trust-based video network security access control device provided in an embodiment of the present invention. Detailed Implementation
[0023] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0024] It should be noted that, based on this disclosure, those skilled in the art will understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects set forth herein can be used to implement the device and / or practice the method. Furthermore, this device and / or practice the method can be implemented using other structures and / or functionalities besides one or more of the aspects set forth herein.
[0025] The following section will introduce the zero-trust-based video network security access control device.
[0026] After studying the security of video surveillance within substations, and based on the principles of "dedicated network, security zoning, horizontal isolation, and vertical authentication" for power monitoring system security protection, following the State Grid Corporation's overall IoT network security protection plan and the technical specifications for network security protection of production video systems, and meeting the national standard GB35114 for information security requirements of public safety video surveillance network, an innovative zero-trust security technology framework was adopted. This is the first time in China that zero trust has been innovatively combined with the power system's HarmonyOS operating system, TF cards, domestically produced cryptographic chips, the GB351114 video security network protocol, VPN, and security situation awareness to develop a video security access control device and technical solution integrating a network layer 3 switch, firewall, zero-trust device access control, zero-trust network intrusion protection, zero-trust VPN encryption gateway, SDWAN network controller, and GB35114 video security gateway. The GB35114 public safety video surveillance network information security technology architecture diagram is shown below. Figure 1 As shown, the system architecture is as follows: Figure 2 As shown, the technical framework is as follows Figure 3 As shown.
[0027] like Figure 4 As shown, this zero-trust-based video network security access control device integrates a network layer 3 switch, firewall, zero-trust device access control module, zero-trust network intrusion prevention module, zero-trust VPN encryption gateway, SDWAN network controller and video GB35114 security gateway.
[0028] The device adopts a zero-trust security technology framework, combining the power HarmonyOS operating system, TF card, domestic cryptographic chip, GB35114 video security networking protocol, VPN and security situation awareness technology to achieve security protection for the substation video monitoring network.
[0029] The device integrates seven functional modules, including a network layer 3 switch, firewall, and zero-trust device access control, forming an integrated security protection unit. At the same time, with zero-trust security technology as the core, it integrates the power HarmonyOS operating system (to improve the underlying security of the device), TF card (to store encrypted information), domestic cryptographic chip (to ensure the independent controllability of encryption algorithms), GB35114 protocol (to standardize video network security), VPN (encrypted transmission channel), and security situation awareness (to monitor risks in real time) to achieve full-link security protection for the substation video surveillance network.
[0030] Beneficial effects: Breaking through the limitations of traditional security equipment with its dispersed functions, "integrated design" reduces the number of devices deployed, lowers system complexity, and improves operational efficiency.
[0031] With a zero-trust framework at its core and combined with multiple technologies, a closed-loop security system of "access control-transmission-protection-monitoring" is formed, which comprehensively covers the risks mentioned in the background technology, such as unauthorized access, device backdoors, and network intrusion, and solves the problem of fragmented protection in existing technologies.
[0032] Furthermore, the zero-trust device access control module adopts a five-layer security access protection mechanism, including the binding and verification of unique ID number, password, IP, MAC and port; the unique ID number and password of the camera are registered on the security access gateway, and the camera IP and MAC are bound to the designated physical port. If the unique ID number is forged and the password does not match, the device access is prohibited.
[0033] A five-layer binding and verification strategy of "unique ID + password + IP + MAC + port" is adopted: the unique ID and password of the camera are pre-registered on the secure access gateway, and its IP, MAC address and physical port are forcibly bound. Even if an attacker forges the unique ID, access will still be blocked if the password does not match. Compared with the traditional three-layer strategy of "IP + MAC + port", the addition of the "unique ID + password" two-layer protection completely eliminates device forgery and tampering.
[0034] Beneficial effects: This approach addresses the "risk of unauthorized device access" in the background technology at its root, ensuring the authenticity and legitimacy of access devices through multi-layered verification, preventing attackers from replacing cameras or forging devices to access the network. Compared to traditional access control methods, security is improved exponentially, avoiding network intrusions caused by breaches in a single dimension.
[0035] Furthermore, the device also includes a security partitioning module, which is configured such that the video system, the bearer network, and the video terminals are strictly prohibited from interconnecting across regions. Vertical cross-region interaction requires network aggregation or address translation within the same security zone before horizontal access can be performed; services in low-security zones are prohibited from actively connecting to services in high-security zones, and perception layer devices are prohibited from actively initiating access to the main network.
[0036] It is clearly stipulated that video systems, bearer networks, and video terminals are strictly prohibited from direct interconnection across security zones; if vertical cross-zone interaction is required, it must be accessed horizontally after network aggregation or address translation within the same security zone; at the same time, it is prohibited for low-security zone services to actively connect to high-security zone services, and for perception layer devices (such as cameras) to actively initiate access to the main network, thereby limiting the risk spread path through "zone isolation".
[0037] Beneficial effects: Strictly define security boundaries to prevent the risk from spreading to other areas (especially the main network in high-security zones) after a certain security zone is breached, thus solving the cross-regional transmission problem of "substation network intrusion risk" in the background technology; by restricting the direction of active access, reduce the probability of the main network being attacked after the perception layer equipment is hijacked, and improve the overall risk resistance capability of the system.
[0038] Furthermore, the device also includes a protocol analysis module, which is configured to: establish a service whitelist based on the GB28181 standard protocol, close non-service ports by default, perform data control on service ports based on the protocol feature library whitelist, identify whether IPCs use the GB28181 standard for access, and alarm and block terminals that do not comply with the national standard. Based on the GB35114-2017 standard, deep identification is performed on registration messages, control messages, and video stream messages. The GB28181 protocol is extended and converted to the GB35114 protocol for transmission. Terminals that do not conform to the GB35114 standard are blocked and alarmed in real time.
[0039] The module establishes a service whitelist based on the GB28181 standard, closes non-service ports by default, and only allows packets that conform to the standard to pass through; it also supports the GB35114-2017 standard, performs deep identification of registration, control, and video stream packets, converts the GB28181 protocol to the GB35114 protocol for transmission, and provides real-time alarms and blocks terminals that do not conform to either standard to prevent the abuse of proprietary protocols.
[0040] Beneficial effects: To address the risks of "application platform risks" and "unauthorized control of devices" in the background technology, this approach aims to prevent attackers from bypassing protection by using proprietary protocols through standardized protocol usage; and to ensure the compliance and security of video data transmission by enforcing national standards, thereby preventing the exploitation of vulnerabilities caused by non-standard protocols.
[0041] Furthermore, it also includes a data security protection module, which is configured to: verify the transmission and distribution data through digital signatures to ensure the authenticity of the video data source and prevent tampering; and adopt two-way authentication and two-way data encryption, with encryption algorithms being the SM2, SM3, and SM4 national cryptographic algorithms, to ensure data confidentiality and integrity.
[0042] The authenticity and integrity of video data sources are verified through digital signatures (to prevent tampering); two-way authentication (mutual verification of identity between device and platform) and national cryptographic algorithms (SM2, SM3, SM4) are used to encrypt data in both directions to ensure that data is not leaked or tampered with during transmission.
[0043] Beneficial effects: To address the "risk of sensitive data leakage" in the background technology, encryption and signature are combined to ensure the security of video data throughout the entire process from generation to transmission; the use of national cryptographic algorithms complies with national cryptographic security standards, ensuring that the encryption technology is independently controllable and avoiding security risks caused by reliance on foreign algorithms.
[0044] Furthermore, it also includes a network stealth module, which is configured to establish a virtual private network between the secure access gateway and the secure admission gateway, and not expose its IP address and port to the outside world; The secure access gateway, secure admission gateway and video security service platform use SPA technology, which denies all connections by default and opens access channels only after authentication with a single packet authentication token; the secure access gateway and secure admission gateway use private UDP encrypted communication technology.
[0045] The module establishes a virtual private network through a secure access gateway and a secure admission gateway, hiding its IP address and port from the outside world. It adopts SPA (Single Packet Authorization) technology, which rejects all connections by default and opens channels only after verification by a single packet authentication token. At the same time, it uses private UDP to encrypt communication to prevent data from being eavesdropped on or tampered with, thus achieving network "stealth".
[0046] Beneficial effects: To address the issue of "network vulnerability to scanning and attack" in the background technology, this technology significantly reduces the attack surface by hiding IP addresses and ports, thus defending against hacker scanning and known / unknown attacks. The combination of SPA technology and private encrypted communication ensures that only authorized devices can establish connections, enhancing network concealment and anti-attack capabilities.
[0047] Furthermore, the device also includes an access control module, which is configured as follows: in terms of vertical control, only cameras and NVRs are allowed to interact with specific video servers, and fine-grained control is achieved through combinations of IP, port, time, and protocol to prohibit access to applications outside the designated server; in terms of horizontal control, access between cameras and between secure access gateways is prohibited by default, and pairwise isolation is achieved through combinations of IP, port, time, and protocol to block east-west attacks.
[0048] In terms of vertical control, only cameras and NVRs are allowed to interact with specific video servers, and access is restricted through a combination of policies based on IP, port, time, and protocol. In terms of horizontal control, access between cameras and between security access gateways is prohibited by default, and fine-grained policies are used to achieve pairwise isolation and prevent the spread of attacks.
[0049] Beneficial effects: Vertical control prevents devices from accessing unauthorized servers, thus mitigating the risk of "unauthorized access to the main network." Lateral isolation prevents a compromised device from being used as a springboard to attack other devices (east-west attack), reduces the probability of large-scale intrusion, and improves the system's ability to contain local failures.
[0050] Furthermore, the SDWAN network controller is configured to support cameras and NVRs to form self-organizing networks through SD-WAN technology, and to form a self-organizing network based on a dual-protocol virtual private network of IPv6 and IPv4 with zero-trust network stealth. The video server can directly access the camera and NVR addresses and ports without being restricted by region or IP, and select the optimal path through routing policies.
[0051] It supports cameras and NVRs to form their own networks through SDWAN technology, and builds a virtual private network based on the IPv6 / IPv4 dual protocol stack with zero-trust network stealth, enabling video servers to directly access terminals across regions and IPs, and select the optimal path through routing policies.
[0052] Beneficial effects: It solves the problems of "geographical limitations and rigid routing" in traditional wide area networks, and improves the flexibility and transmission efficiency of distributed substation monitoring networks; dual protocol stacks support adaptation to network upgrade needs, and zero-trust virtual private networks ensure security during the self-organizing process, balancing efficiency and security.
[0053] Furthermore, the device also includes a lateral isolation module, which is configured to: prohibit communication between physical interfaces of security access devices; prohibit communication between security access devices between substations; and prohibit communication between monitoring devices.
[0054] Clearly prohibit direct communication between physical interfaces of security access devices, between security access devices in substations, and between monitoring equipment (such as cameras and NVRs), thereby blocking lateral attack paths through physical and logical isolation.
[0055] Beneficial effects: By severing the lateral attack link at the physical and network layers, the risk of "a compromised node spreading to the entire system" in the background technology is resolved; unnecessary communication between devices is reduced, network load is lowered, the attack surface is reduced, and system stability is improved.
[0056] Furthermore, the device also includes a vertical encryption authentication module, which is configured such that: the security camera with integrated TF password card and the security access device authenticate access through a unique identifier, and after access is granted, the data is transmitted using the national cryptographic algorithm; The identities of video terminals and security access devices are uniformly identified and managed. Security access devices complete two-way identity authentication before interacting with the main network. When video terminals access the main network through security access devices, encrypted authentication is used to achieve IP layer encryption and two-way authentication for data transmission.
[0057] Cameras with integrated TF cryptographic cards and security access devices are authenticated and accessed through a unique identifier. After access, data is transmitted using national cryptographic algorithms. Video terminals and security access devices require unified identity management and must complete two-way authentication before interacting with the main network. When the terminal accesses the main network, it uses encrypted authentication to achieve IP layer data encryption and two-way verification.
[0058] Beneficial effects: To address the risk of "vertical mainnet penetration attacks" in the background technology, the security of vertical transmission is ensured by combining identity authentication and encryption; unique identity identification and two-way authentication prevent identity forgery, and IP layer encryption ensures the security of data transmission throughout the process, which meets the protection requirements of "vertical authentication" in power systems.
[0059] In one exemplary embodiment, device admission: It adopts a five-layer security access protection mechanism, namely: unique ID number + password + IP + MAC + port.
[0060] The security access gateway registers a unique ID number and password for each camera and binds the camera's IP and MAC address to a designated physical port, enabling access control for connected cameras and NVRs. An additional layer of password protection is added on top of the unique ID number. If the camera's unique ID number is forged, even if the ID number is the same, access will be blocked if the authentication password is different. Compared to traditional security access methods (IP + MAC + port), this five-layer security access protection mechanism truly prevents access devices from being forged or tampered with.
[0061] Security partition: Video systems, bearer networks, and video terminals are strictly prohibited from being interconnected across regions.
[0062] Vertical cross-regional access is prohibited. If vertical cross-regional interaction is absolutely necessary, it must be performed through network aggregation or address translation within the same security zone before horizontal cross-regional access can be conducted.
[0063] Low-security zone services are not allowed to proactively connect to high-security zone services, and perception layer devices are not allowed to proactively initiate access to the main network.
[0064] Protocol Analysis: Analysis based on the GB28181 standard protocol: GB28181 serves as the technical requirement for information transmission, exchange, and control in public security video surveillance network systems. Equipment in video transmission networks should adhere to this standard for information transmission and exchange. However, many video transmission network services now use proprietary protocols. The Zero Trust Video Security Protection System establishes a service whitelist based on the protocol characteristics of the GB28181 standard, disables non-service ports by default, and manages data for service ports based on the protocol characteristic whitelist. It supports identifying whether IPCs use the GB28181 standard for access and can alarm and block terminals that do not comply with the national standard to prevent cameras and NVRs from being illegally controlled.
[0065] Analysis based on the GB35114-2017 standard protocol: GB35114-2017, as a requirement for ensuring the security of video and control information in video surveillance networks, must be combined with access control mechanisms. In video private networks that are required to be built in accordance with the GB35114-2017 standard, the security access gateway performs deep identification on registration messages, control messages, and video stream messages. The security access gateway extends the 28181 protocol to the 35114 protocol for transmission. The security access gateway only receives 35114 protocol data transmitted by the security access gateway and blocks and alarms terminals that do not conform to the GB35114 standard in real time.
[0066] Data security protection: Digital signature: By verifying the signatures of the transmission and distribution data, the purpose is to ensure that the video data originates from the real device and to verify whether the video has been tampered with.
[0067] Data encryption and decryption: It adopts two-way authentication and two-way data encryption. The data encryption uses national cryptographic algorithms, supporting SM2, SM3 and SM4, to ensure the confidentiality and integrity of the data.
[0068] Online anonymity: A virtual private network is established between the secure access gateway and the secure admission gateway. The IP address and port are not exposed to the outside world, thus achieving network stealth and defending against network scanning by hackers and Trojans. It can defend against both known and unknown network attacks.
[0069] Communication between the secure access gateway, secure admission gateway, and video security service platform uses SPA (Single Packet Authorization) technology, with a default "deny all" connection. The video security service platform only accepts the first packet containing identity information from the secure access gateway and secure admission gateway. After the video security service platform authenticates the single packet authentication token, the secure access gateway and secure admission gateway can obtain communication parameters. Only after SPA authorization will access channels be opened to authorized clients, eliminating the need to expose IP addresses and ports, thus achieving network anonymity for IP addresses and ports. The secure access gateway and secure admission gateway use proprietary UDP encrypted communication technology to prevent unauthorized personnel from eavesdropping, tampering, or destroying communication data.
[0070] The video security service platform does not open application service ports to the outside world, but only opens UDP single-packet authentication ports; the security access gateway and security admission gateway block all inbound traffic. The security access gateway and security admission gateway can only obtain communication ports and IPs after passing the video security service platform's SPA single-packet authentication. Only after two-way authentication can a virtual stealth communication tunnel be established, and authorization control is performed on each port.
[0071] Access control: Vertical control: By default, only cameras and NVRs are allowed to interact with specific video servers. Fine-grained control over access can be adjusted through combinations of IP, port, time, and protocol. Access to applications outside the specified video server is prohibited.
[0072] Lateral control: By default, access between cameras is prohibited, and access between secure access gateways is prohibited. Fine-grained control of access can be adjusted by combining IP, port, time, protocol, etc., to achieve horizontal isolation between each other, preventing a node from being compromised and used as a springboard to attack other cameras and other secure access gateways, and blocking east-west attacks.
[0073] Routing strategy: SDWAN (Software-Defined Wide Area Network) is a software-defined wide area network management technology. It's a network architecture based on Software-Defined Networking (SDN) technology that enables network virtualization, automation, and centralized management. SDWAN was designed to address the limitations of traditional WAN network topologies and architectures in meeting the demands of cloud computing and network security, and to improve network performance and reliability. SDWAN allows enterprises to centrally manage and utilize network devices in globally distributed locations.
[0074] Cameras and NVRs can form a self-organizing network through SD-WAN technology, realizing a self-organizing network based on the stealth of IPv6 and IPv4 dual-protocol stack virtual private network. The video server can directly access the camera and NVR addresses and ports, without being restricted by region or IP. The optimal routing path can be selected through routing policies.
[0075] Lateral isolation: Communication between physical interfaces of security access devices is prohibited. Communication between security access devices of substations and between monitoring devices is prohibited.
[0076] Vertical encryption authentication: The security camera with integrated TF password card uses a unique identifier for authentication and access control between itself and the security access control device. After access is granted, data is transmitted between them using national cryptographic algorithms.
[0077] The identities of video terminals and security access devices should be uniformly identified and managed. Before interacting with the main network, security access devices should first complete two-way identity authentication and only allow entities that have passed identity authentication to access the network and access system resources.
[0078] When video terminals access the main network through the security access device, they use encrypted authentication, which is used in conjunction with the security gateway to achieve IP layer encryption and two-way authentication for data transmission.
[0079] This device addresses the security risks associated with device access in substation video surveillance networks. Guided by innovation, security, and efficiency, it employs advanced zero-trust security technology to mitigate security access risks for video equipment. Simultaneously, it utilizes multiple security strategies to enhance network intrusion prevention, communication encryption, abnormal behavior analysis, and security situation awareness, strictly controlling device access and improving the security of video surveillance equipment access to ensure the security of the power grid network.
[0080] (1) Domestic production and independent control The device uses domestically produced CPU processors, memory, storage, switch chips, national cryptographic level 2 encryption chips, domestically produced power HarmonyOS operating system, and proprietary zero-trust security protection software, achieving complete localization of the equipment and meeting the security protection requirements of critical power infrastructure.
[0081] (2) Innovative zero-trust security technology The device innovatively applies internationally leading zero-trust security protection technology in the Internet of Things (IoT). It adopts the zero-trust security concept of "never trusting and continuous authentication" and combines the security features of IoT devices such as video surveillance cameras and NVRs. It innovatively integrates a zero-trust security client into the power HarmonyOS operating system of the cameras and NVRs, realizing transparent zero-trust security access to video surveillance cameras and NVRs.
[0082] (3) Security situation awareness and attack blocking capability Given that substation production equipment rooms cannot be equipped with professional network security analysis systems such as APT attack analysis systems and honeypot systems, this technical solution innovatively utilizes zero-trust SDWAN intelligent routing technology. This technology allows for the configuration of intelligent routing to automatically mirror and route network data from video terminals in substation production equipment rooms to the main station's security service resource pool. Professional security analysis systems such as APT attack analysis systems and honeypot systems are then centrally deployed in the main station's IDC center, enabling the realization of security situation awareness capabilities for all substation production equipment rooms.
[0083] In summary, this device innovates in areas such as secure access for video surveillance equipment, and enhances the security protection capabilities of video surveillance equipment through technological innovation and optimization of network equipment security access.
[0084] By employing a zero-trust security framework and HarmonyOS IoT technology, security protection is provided for substation video surveillance equipment. A security access control device with capabilities including switches, firewalls, device access control, network intrusion prevention, VPN encryption gateways, SDWAN network controllers, and video GB35114 security gateways is used to achieve secure access to substation cameras, NVRs, and integrated data network devices. This improves the security protection capabilities of substation terminals and networks, enhances the efficiency of terminal equipment implementation, reduces implementation and maintenance costs, and lowers the professional skill requirements for implementation personnel.
[0085] Economic benefits: 1) Cost savings The application of these results avoids cybersecurity risks caused by unauthorized external devices, optimizes device access procedures, enhances security protection capabilities, reduces cybersecurity risks, and lowers maintenance costs caused by cybersecurity incidents.
[0086] 2) Advantages in operation and maintenance costs This solution uses a SaaS centralized management system to uniformly and centrally manage the video security access control devices of all substations. The access control devices are plug-and-play, require no on-site maintenance, and reduce equipment operation and maintenance costs by 70%, giving it a high competitive advantage in the market.
[0087] Social benefits: In addition to meeting the video security protection requirements of substations, this project's product, as a powerful general-purpose edge security device, can be extended to various edge IoT environments, providing a one-stop solution to the pain points of edge IoT construction. It can effectively promote the construction of various types of edge IoT, such as smart grids and ubiquitous power IoT, accelerate the development of IoT cloud-edge collaborative applications in various industries in my country, improve IoT performance, security, and reliability, and has high socio-economic value.
[0088] While specific embodiments of the invention have been described in detail by way of examples, those skilled in the art should understand that the examples are for illustrative purposes only and are not intended to limit the scope of the invention. Those skilled in the art should also understand that various modifications can be made to the embodiments without departing from the scope and spirit of the invention.
Claims
1. A zero-trust-based video network security access control device, characterized in that, The device integrates a network Layer 3 switch, firewall, zero-trust device access control module, zero-trust network intrusion prevention module, zero-trust VPN encryption gateway, SDWAN network controller and video GB35114 security gateway. The device adopts a zero-trust security technology framework, combining the power HarmonyOS operating system, TF card, domestic cryptographic chip, GB35114 video security networking protocol, VPN and security situation awareness technology to achieve security protection for the substation video monitoring network.
2. The zero-trust-based video network security access control device according to claim 1, characterized in that, The zero-trust device access control module adopts a five-layer security access protection mechanism, including the binding and verification of unique ID number, password, IP, MAC and port; Register the camera's unique ID number and password on the secure access gateway, and bind the camera's IP and MAC address to a designated physical port. If the unique ID number is forged and the password does not match, the device will be prohibited from accessing the gateway.
3. The zero-trust-based video network security access control device according to claim 1, characterized in that, It also includes a security partitioning module, which is configured such that video systems, bearer networks, and video terminals are strictly prohibited from interconnecting across zones. Vertical cross-region interaction requires network aggregation or address translation within the same security zone before horizontal access can be performed; services in low-security zones are prohibited from actively connecting to services in high-security zones, and perception layer devices are prohibited from actively initiating access to the main network.
4. The zero-trust-based video network security access control device according to claim 1, characterized in that, It also includes a protocol analysis module, which is configured to: establish a service whitelist based on the GB28181 standard protocol, close non-service ports by default, perform data control on service ports based on the protocol feature library whitelist, identify whether IPCs use the GB28181 standard for access, and alarm and block terminals that do not comply with the national standard. Based on the GB35114-2017 standard, deep identification is performed on registration messages, control messages, and video stream messages. The GB28181 protocol is extended and converted to the GB35114 protocol for transmission. Terminals that do not conform to the GB35114 standard are blocked and alarmed in real time.
5. The zero-trust-based video network security access control device according to claim 1, characterized in that, It also includes a data security protection module, which is configured to: verify the transmission and distribution data through digital signatures to ensure the authenticity of the video data source and prevent tampering; and adopt two-way authentication and two-way data encryption, with encryption algorithms being the SM2, SM3, and SM4 national cryptographic algorithms, to ensure data confidentiality and integrity.
6. The zero-trust-based video network security access control device according to claim 1, characterized in that, It also includes a network stealth module, which is configured to establish a virtual private network between the secure access gateway and the secure admission gateway, and not expose its IP address and port to the outside world; The secure access gateway, secure admission gateway and video security service platform use SPA technology, which denies all connections by default and opens access channels only after authentication with a single packet authentication token; the secure access gateway and secure admission gateway use private UDP encrypted communication technology.
7. The zero-trust-based video network security access control device according to claim 1, characterized in that, It also includes an access control module, which is configured as follows: In terms of vertical control, it only allows cameras and NVRs to interact with specific video servers, and achieves fine-grained control through a combination of IP, port, time, and protocol, prohibiting access to applications outside the designated server; In terms of horizontal control, it prohibits access between cameras and between secure access gateways by default, and achieves pairwise isolation through a combination of IP, port, time, and protocol, blocking east-west attacks.
8. The zero-trust-based video network security access control device according to claim 1, characterized in that, The SDWAN network controller is configured to support cameras and NVRs to form a self-organizing network through SD-WAN technology. It is a self-organizing network based on a dual-protocol virtual private network of IPv6 and IPv4 with zero-trust network stealth. The video server can directly access the camera and NVR addresses and ports without being restricted by region or IP, and select the optimal path through routing policies.
9. The zero-trust-based video network security access control device according to claim 1, characterized in that, It also includes a lateral isolation module, which is configured to: prohibit communication between physical interfaces of security access devices; prohibit communication between security access devices between substations; and prohibit communication between monitoring devices.
10. The zero-trust-based video network security access control device according to claim 1, characterized in that, It also includes a vertical encryption authentication module, which is configured such that: the security camera with integrated TF password card and the security access device authenticate access through a unique identity identifier, and after access is granted, the data is transmitted using the national cryptographic algorithm; The identities of video terminals and security access devices are uniformly identified and managed. Security access devices complete two-way identity authentication before interacting with the main network. When video terminals access the main network through security access devices, encrypted authentication is used to achieve IP layer encryption and two-way authentication for data transmission.
Citation Information
Patent Citations
Improvements in locking devices for miners' and like electric lamps
GB351114A