A non-invasive image capture and storage device, method

By using a non-intrusive image capture and storage device, image frame data is directly obtained from the host video output, compared and encrypted for storage, solving the problems of blind spots and low data reliability in traditional screenshot technology, and achieving efficient and secure screen content auditing.

CN121078191BActive Publication Date: 2026-02-06WINDEY ENERGY TECHNOLOGY GROUP CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202511574134.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-31
Publication Date
2026-02-06
Estimated Expiration
2045-10-31

AI Technical Summary

Technical Problem

Traditional software-level screenshot technology suffers from blind spots, low data reliability, and redundant invalid data in high-security information systems, making it difficult to meet the requirements of high reliability, high security, and high efficiency in screen content auditing.

Method used

It employs a non-intrusive image capture and storage device, directly acquiring image frame data from the host's video output signal through a video conversion and processing module, comparing and encrypting the data through a control processing module, storing it independently through a controlled storage module, and providing hardware-level protection through a security protection module, thus avoiding reliance on host permissions and protection.

Benefits of technology

It enables the complete capture of key images in a high-security system, ensuring data security and integrity, reducing invalid data, and lowering audit and analysis costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121078191B_ABST
    Figure CN121078191B_ABST
Patent Text Reader

Abstract

The application discloses a non-intrusive image capturing and storing device and method, relates to the technical field of safe data storage, and solves the problems of acquisition blind area, low data reliability and invalid data redundancy caused by traditional software level screenshot technology. A video conversion processing module is directly connected with a target host video output link through a standard video interface, the device is independent of the host system as a whole, does not depend on host permission, does not interact with the host or communicate with the host through a protocol, and thus avoids acquisition blind area caused by insufficient permission or protection interception. A control processing module encrypts the screenshot image, thereby protecting data safety. The control processing module triggers screenshot only when a significant change in the image is detected, thereby avoiding indiscriminate acquisition, reducing redundant data irrelevant to auditing from the source, and reducing storage and operation costs in subsequent auditing analysis. A protection operation of a security protection module is executed through a hardware interface and does not depend on host software logic, thereby avoiding protection failure caused by remote control of the host.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of secure data storage, in particular to a non-intrusive image capturing and storage device and method. BACKGROUND

[0002] In high-security-level information systems (such as wind turbine monitoring systems of wind farms), system-level and network-level security measures are usually adopted to prevent data leakage, remote control and screen capture and the like. At present, the industry relies on traditional software-level screenshot technology for screen content collection. By installing screenshot software or integrating screenshot function modules in the host system, screen pictures are captured at a preset frequency or triggered condition to record and trace the screen content, thereby meeting the basic audit requirements in conventional scenarios.

[0003] However, in high-trust audit scenarios, due to system permissions, security policies or terminal protection mechanisms, the screenshot software often cannot capture key operation interfaces due to insufficient permissions, or is intercepted by terminal protection software as a risky behavior, resulting in the absence of some core pictures. The generation and storage of screenshot data rely on the host system, which is vulnerable to malicious program tampering and forgery, and cannot guarantee data authenticity and integrity. Traditional screenshots are usually indiscriminately collected, which can generate a large amount of redundant data irrelevant to the audit, thereby increasing the cost and difficulty of subsequent audit analysis. It is difficult to meet the high-trust, high-security and high-efficiency requirements of screen content audit in high-security-level information systems.

[0004] Therefore, it is an urgent technical problem for those skilled in the art to solve the problems of collection blind area, low data reliability and redundant invalid data caused by traditional software-level screenshot technology. SUMMARY

[0005] The purpose of the present application is to provide a non-intrusive image capturing and storage device and method to solve the problems of collection blind area, low data reliability and redundant invalid data caused by traditional software-level screenshot technology.

[0006] To solve the above technical problems, the present application provides a non-intrusive image capturing and storage device, which comprises a video conversion processing module, a control processing module, a controlled storage module and a security protection module.

[0007] The video conversion processing module is connected to a target host through a standard video interface, receives a video output signal output by the target host and converts the video output signal into image frame data.

[0008] The control processing module is connected to the output end of the video conversion processing module and is configured to compare continuous image frame data, perform a frame capturing operation when the comparison result meets a frame capturing trigger condition, and encrypt the frame-captured image data.

[0009] The controlled storage module is connected with the control processing module, and is used for storing the frame-cut image data encrypted by the control processing module.

[0010] The security protection module is connected with the control processing module, and the security protection module is connected with the controlled storage module through a hardware interface, and is used for performing a data protection operation through the hardware interface when a security protection trigger signal of the control processing module is monitored.

[0011] Optionally, in the non-invasive image capturing and storage device, the video conversion processing module comprises a video signal splitting module and a video acquisition module.

[0012] The video signal splitting module is connected with a target host through a standard video interface, and is used for accessing a video output signal of the target host and splitting the video output signal into a display signal and an acquisition signal.

[0013] An input end of the video acquisition module is connected with a first output end of the video signal splitting module, and is used for receiving the acquisition signal; and an output end of the video acquisition module is connected with the control processing module, and is used for converting the acquisition signal into image frame data in a digital format.

[0014] Optionally, in the non-invasive image capturing and storage device, the control processing module comprises an image processing unit, an encryption unit and a logic control submodule.

[0015] An input end of the image processing unit is connected with an output end of the video conversion processing module, and is used for performing change detection algorithm comparison on continuous image frame data.

[0016] An output end of the image processing unit is connected with the logic control submodule, and is used for sending a frame-cut instruction to the logic control submodule when a comparison result meets a frame-cut trigger condition.

[0017] The logic control submodule is connected with the image processing unit, the encryption unit, the controlled storage module and the security protection module, respectively, and is used for performing a frame-cut operation after receiving the frame-cut instruction, controlling the encryption unit to encrypt frame-cut image data, sending a storage instruction to the controlled storage module and transmitting a security state signal to the security protection module.

[0018] An input end of the encryption unit is connected with the logic control submodule, and an output end of the encryption unit is connected with the controlled storage module, and is used for performing full encryption on frame-cut image data and associated metadata.

[0019] Optionally, in the non-invasive image capturing and storage device, the video acquisition module is built-in a video acquisition chip and an independent memory area.

[0020] The video acquisition chip is configured to decode or perform analog-digital conversion on the acquisition signal, and if the acquisition signal is a digital video signal, the video acquisition chip is configured to decode the acquisition signal into a digital image frame, and if the acquisition signal is an analog video signal, the video acquisition chip is configured to perform analog-digital conversion on the acquisition signal into a digital image frame.

[0021] The independent memory region is connected to the control processing module for data interaction, and the independent memory region is configured to temporarily store the converted digital image frame data.

[0022] Optionally, in the non-intrusive image capture and storage device, a hardware interface between the security protection module and the controlled storage module includes a chip selection control interface of a storage medium and a voltage detection interface.

[0023] The security protection module monitors a VBUS voltage change of the controlled storage module through the voltage detection interface, and when it is determined that a non-safe removal is currently occurring according to the VBUS voltage change, the security protection module outputs a latch signal to the controlled storage module through the chip selection control interface to disable a chip selection signal of a flash memory chip of the controlled storage module.

[0024] Optionally, in the non-intrusive image capture and storage device, the security protection module internally integrates a physical fuse circuit.

[0025] An output end of the physical fuse circuit is connected to a key storage chip of the controlled storage module, and when the security protection module receives a protection action starting instruction from the control processing module, the security protection module releases a current to the key storage chip through the physical fuse circuit, and performs data overwriting and metadata clearing through the chip selection control interface and the data writing interface.

[0026] Optionally, in the non-intrusive image capture and storage device, the control processing module further includes a watermark embedding unit and a compression encoding unit.

[0027] An input end of the watermark embedding unit is connected to a frame-cutting data output end of the logic control submodule, and an output end of the watermark embedding unit is connected to an input end of the compression encoding unit, and the watermark embedding unit is configured to embed an unforgeable device identifier, a millisecond-level timestamp and geographic location information in the frame-cutting image data.

[0028] An output end of the compression encoding unit is connected to an input end of the encryption unit, and the compression encoding unit is configured to perform lossless compression processing on the frame-cutting image data containing the watermark.

[0029] Optionally, in the non-intrusive image capture and storage device, the image processing unit includes an inter-frame difference analysis submodule, a perceptual hash rapid comparison submodule or a logic gate.

[0030] The inter-frame difference analysis submodule and the perceptual hash fast comparison submodule are connected with the output end of the video conversion processing module, and are used for synchronously receiving the continuous image frame data.

[0031] The inter-frame difference analysis submodule is used for calculating the pixel absolute difference between the adjacent frames of the image frame data block by block, and outputting an image significant change judgment signal when the pixel absolute difference exceeds a preset difference value.

[0032] The perceptual hash fast comparison submodule is used for obtaining the Hamming distance according to the image hash values of the adjacent frames, and outputting an image significant change judgment signal when the Hamming distance is greater than a preset threshold.

[0033] The output end of the OR logic gate is connected with the output end of the inter-frame difference analysis submodule and the perceptual hash fast comparison submodule, and the output end of the OR logic gate is connected with the logic control submodule of the control processing module, which is used for sending a frame-cutting trigger signal to the logic control submodule when the inter-frame difference analysis submodule or the perceptual hash fast comparison submodule outputs an image significant change judgment signal.

[0034] Optionally, in the non-invasive image capturing and storing device, the second output end of the video signal shunt module is connected with an external display, and the external display receives and displays the display signal output by the video signal shunt module.

[0035] To solve the above technical problems, the application further provides a non-invasive image capturing and storing method applied to a non-invasive image capturing and storing device, wherein the non-invasive image capturing and storing device comprises a video conversion processing module, a control processing module, a controlled storage module and a security protection module; the video conversion processing module is connected with a target host through a standard video interface, receives a video output signal output by the target host and converts the video output signal into image frame data; the control processing module is connected with the output end of the video conversion processing module, is used for comparing the continuous image frame data, performs a frame-cutting operation when the comparison result meets a frame-cutting trigger condition, and performs an encryption processing on the frame-cutting image data obtained through the frame-cutting operation; the controlled storage module is connected with the control processing module, and is used for storing the frame-cutting image data encrypted by the control processing module; the security protection module is connected with the control processing module, and the security protection module and the controlled storage module are connected through a hardware interface, and are used for performing a data protection operation through the hardware interface when a security protection trigger signal of the control processing module is monitored.

[0036] The method comprises:

[0037] Receiving the image frame data output by the video conversion processing module.

[0038] The continuous image frame data is compared.

[0039] When the comparison result meets the frame-cut triggering condition, a frame-cut operation is performed, and the frame-cut image data obtained by frame-cut is encrypted.

[0040] The encrypted frame-cut image data is stored in the controlled storage module.

[0041] When an illegal intrusion signal is detected, a security protection triggering signal is sent to the security protection module to control the security protection module to perform a data protection operation through a hardware interface.

[0042] The non-intrusive image capturing and storage device provided in the application directly connects a target host video output link through a standard video interface through a video conversion processing module, the device is independent of the host system as a whole, does not depend on the host permission, and does not perform data interaction or protocol communication with the host, so that the video signal is obtained from the physical layer, and the collection blind area caused by insufficient permission or protection interception is avoided; the control processing module encrypts the frame-cut image to protect data security; the control processing module triggers frame-cut only when a significant change in the image is detected, so that indiscriminate collection is avoided, and the redundant data irrelevant to auditing is reduced from the source, and the storage and operation cost of subsequent auditing analysis is reduced; the protection operation of the security protection module is performed through a hardware interface, and does not depend on the host software logic, so that the protection failure caused by remote control of the host is avoided, and the problems of collection blind area, low data reliability and redundant invalid data caused by traditional software-level screenshot technology are solved.

[0043] In addition, the application also provides a non-intrusive image capturing and storage method, which corresponds to the above-mentioned non-intrusive image capturing and storage device and has the same effect. BRIEF DESCRIPTION OF DRAWINGS

[0044] In order to more clearly illustrate the embodiments of the application, the drawings needed in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative labor.

[0045] Figure 1 A schematic diagram of a non-intrusive image capturing and storage device is provided for the embodiments of the application;

[0046] Figure 2 A flowchart of a non-intrusive image capturing and storage method is provided for the embodiments of the application.

[0047] Reference signs:

[0048] 11-video conversion processing module; 12-control processing module; 13-controlled storage module; 14-security protection module. Detailed Implementation

[0049] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the protection scope of this application.

[0050] The core of this application is to provide a non-invasive image capture and storage device and method.

[0051] To enable those skilled in the art to better understand the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0052] To address the aforementioned technical problems, this application provides a non-invasive image capture and storage device, such as... Figure 1 As shown, it includes: a video conversion processing module 11, a control processing module 12, a controlled storage module 13, and a security protection module 14.

[0053] The video conversion and processing module 11 is connected to the target host through a standard video interface, receives the video output signal output by the target host, and converts it into image frame data.

[0054] The control processing module 12 is connected to the output of the video conversion processing module 11. It is used to compare continuous image frame data. When the comparison result meets the frame capture trigger condition, the frame capture operation is performed, and the captured frame image data is encrypted.

[0055] The controlled storage module 13 is connected to the control processing module 12 and is used to store the frame image data encrypted by the control processing module 12.

[0056] The security protection module 14 is connected to the control processing module 12 and the controlled storage module 13 through a hardware interface. When the security protection trigger signal of the control processing module 12 is detected, the security protection module 14 performs data protection operation through the hardware interface.

[0057] Firstly, the video conversion processing module 11 is the key unit for the device to establish a physical connection with the target host, and its core structural feature is to connect with the target host through a standard video interface. The standard video interface generally includes common interface types such as a high-definition multimedia interface (HDMI), a video graphics array (VGA) interface, and a digital video interface (DVI). The present embodiment does not make strict restrictions, as long as the physical access of the video signal can be realized. It should be noted that the use of the standard video interface is not only to adapt to different host hardware, but also to ensure that the video output can be completely obtained under different security policies and hardware environments. Since the traditional software-level screenshot technology needs to rely on the host system permission to call the screenshot function, it is easy to be intercepted by the security policy or cause the collection blind area due to insufficient permissions. Therefore, the module directly obtains the original signal from the video output link of the host, and does not represent that the device needs to interact with the host or communicate with the host. On the contrary, this design of only receiving the video output signal is to realize the physical isolation with the host system, so that the video signal can be completely received and converted into image frame data even if the host is in a high security protection mode, thereby providing a basic data source for subsequent image comparison and frame capturing.

[0058] It should also be noted that the structural design of converting the video output signal into image frame data is not a simple signal format conversion, and its purpose also includes unifying the data format. Different types of video signals (such as HDMI digital signals and VGA analog signals) are converted into standardized image frame data, which is to ensure that the control processing module 12 can stably receive and perform comparison operations, and to avoid processing errors caused by non-uniform signal formats.

[0059] On the other hand, the control processing module 12 is the brain of the device, and its structural features are reflected in the connection with the output end of the video conversion processing module 11 and the three functions of comparison, frame capturing, and encryption. First, the design of connecting with the output end of the video conversion processing module 11 is to realize the stable transmission of image frame data. Since the video conversion processing module 11 has converted the signal into standardized image frames, the control processing module 12 does not need to perform additional format adaptation and can directly receive data and perform subsequent operations.

[0060] It should be noted that the comparison of continuous image frame data and the structure of frame capturing when the frame capturing trigger condition is met do not mean that the frame capturing trigger condition is fixed. In fact, the specific comparison algorithm (such as inter-frame difference analysis and perceptual hash comparison) is not limited in the upper description. The present embodiment can be flexibly selected according to actual audit requirements. The purpose is to solve the problem of invalid data redundancy caused by indiscriminate collection of traditional software-level screenshots. By comparison, the image frames with content changes are selected, and only the pictures with audit value are subjected to frame capturing, thereby reducing the storage resource occupation and lowering the subsequent audit analysis cost.

[0061] Similarly, the structure for encrypting the screenshot image data obtained by the screenshot is to ensure the security of the data transmission and storage process. It should be noted that the encryption here does not mean only encrypting the image pixel data, but also includes the metadata associated with the image (such as screenshot time, device identification, etc.), i.e. full encryption is implemented to avoid data traceability failure caused by tampering of metadata. Based on the above principle, the control processing module 12 converts the original image data into high-trust and traceable encrypted data through the consecutive operations of comparison-screenshot-encryption, providing a secure data source for the subsequent storage link.

[0062] From the structure, the core feature of the controlled storage module 13 is connected with the control processing module 12 and used for storing the encrypted screenshot image data. Its purpose is to first realize the physical isolation storage of data. Since the traditional software-level screenshot data is stored in the local host or networked storage device, it is easy to be illegally deleted or stolen. Therefore, this module serves as a storage unit independent of the host, and does not only have basic storage functions. More importantly, through the exclusive storage design, it ensures that the encrypted data does not come into contact with the host storage environment, thereby blocking the data leakage path from the physical layer.

[0063] It should also be noted that the specific form of the controlled storage module 13 (such as built-in flash memory, pluggable USB, etc.) is not limited in the above description. The embodiment can be selected according to the actual use scenario. For example, in the Supervisory Control And Data Acquisition (SCADA) of a wind farm data acquisition and monitoring system, a pluggable storage structure is used to facilitate the regular export of data by auditors. However, the core purpose is always to securely store encrypted data and avoid data tampering or loss during storage.

[0064] Finally, the structural feature of the security protection module 14 is embodied in the dual connection design, which is connected with the control processing module 12 and also connected with the controlled storage module 13 through a hardware interface. The purpose of this structure design is to separate and coordinate the trigger signal reception and protection action execution. First, the connection with the control processing module 12 is to receive the security protection trigger signal, and does not mean that the module needs to actively judge the risk event. In fact, the determination of the risk event (such as continuous password input failure, non-secure removal of storage media) is completed by the control processing module 12, and the security protection module 14 is only responsible for executing the operation after receiving the trigger signal. This design of separation of determination and execution can avoid the response delay caused by the complexity of the module.

[0065] It should be noted that the design of connecting the controlled storage module 13 through the hardware interface is not only for transmitting control instructions, but more importantly, to realize the hardware-level protection action. Since the software-level protection can be bypassed by malicious programs, the hardware interface (such as the chip selection control interface, the voltage detection interface) can directly act on the hardware circuit of the controlled storage module 13, such as performing storage medium locking, data overwriting, etc., that is, through physical layer intervention, it is ensured that the protection action cannot be cracked by software. In addition, the specific protection action type is not limited in the above description, and the embodiment can include locking, data self-destruction, etc., and the purpose of all of them is to deal with illegal access behavior and ensure the absolute safety of the stored data.

[0066] The device obtains signals from the physical layer through the video conversion processing module 11, solves the problem of blind area collection in traditional technologies; the control processing module 12 solves the problems of invalid data redundancy and low data reliability through comparison and encryption; the controlled storage module 13 realizes independent storage, solves the problem of weak storage security; and the security protection module 14 further strengthens data protection through hardware-level operation to form a whole-link security guarantee. On the other hand, the connection relationship between the modules (such as the video conversion processing module 11 only outputs data to the control processing module 12, and the security protection module 14 only acts on the controlled storage module 13 through the hardware interface) ensures that the overall device is independent of the target host system, does not depend on the host authority, does not occupy the host resources, and avoids the security risks caused by interaction with the host.

[0067] According to the above embodiment, specifically, the video conversion processing module 11 includes: a video signal splitting module, a video acquisition module.

[0068] The video signal splitting module is connected with the target host through a standard video interface, used for accessing the video output signal of the target host, and splitting the video output signal into a display signal and an acquisition signal.

[0069] The input end of the video acquisition module is connected with the first output end of the video signal splitting module, used for receiving the acquisition signal; and the output end of the video acquisition module is connected with the control processing module 12, and the acquisition signal is converted into digital image frame data.

[0070] Specifically, the video signal splitting module is the front-end unit of the video conversion processing module 11, and the core structural feature is that it is connected with the target host through a standard video interface. Since a standard video interface (such as HDMI, VGA, etc.) is used, the target host does not need to be hardware-reformed or software-adapted, and the physical access of the video output signal can be realized. The interface type is not strictly limited, and can be flexibly selected according to the host configuration in actual application.

[0071] It should be noted that the structure design of splitting the video output signal into a display signal and a collection signal has a dual purpose: on the one hand, the display signal can continue to be transmitted to the original display, ensuring the normal use of the target host is not affected, avoiding the interruption of operation caused by the device access, which is particularly important for high-security level systems such as wind farm SCADA systems that need continuous operation; on the other hand, the collection signal is used for internal processing of the device, realizing parallel processing of display and collection, that is, the video content of the target host can be viewed by the operator and simultaneously captured by the device, solving the picture freezing or delay problem caused by traditional software-level screenshot.

[0072] It should also be noted that the splitting operation is not a simple signal copy, but is realized through a high-precision signal distribution circuit, and its purpose is to ensure the consistency of the two signals in transmission delay and signal quality. In general, the delay difference between the display signal and the collection signal should be controlled within 5ms to avoid the inconsistency between the captured content and the actual operation picture caused by asynchronous signals.

[0073] On the other hand, the video collection module, as the backend unit of the video conversion processing module 11, is connected to the first output end of the video signal splitting module, ensuring the directional transmission of the collection signal. Since only the split collection signal is received, the module does not need to process the transmission logic of the display signal and can focus on the digital conversion of the signal. In fact, the first output end here is only a relative designation and does not mean that its priority is higher than that of the display signal output end. Both are equivalent in electrical characteristics.

[0074] Converting the collection signal into digital image frame data is the core function of the video collection module. It should be noted that this conversion process needs to adapt to different types of collection signals: if the collection signal is a digital video signal (such as HDMI output), decoding operation is performed; if it is an analog video signal (such as VGA output), analog-to-digital conversion is performed. The purpose is to unify different types of signals into standardized digital image frames, that is, to ensure that the subsequent control processing module 12 can receive and analyze them stably, avoiding processing errors caused by signal format differences.

[0075] In addition, the output end of the video collection module is connected to the control processing module 12, forming a coherent link from signal collection to data processing. The converted digital image frame data is transmitted to the control processing module 12 through this connection, providing a standardized data source for subsequent frame comparison and screenshot operation. It should be noted that this connection usually uses a high-speed data bus to ensure real-time transmission of large amounts of image frames and avoid picture loss caused by transmission delay. Based on the above principles, the video collection module realizes signal conversion and standardization, laying a data foundation for subsequent operations of the device.

[0076] In summary, the video signal splitting module solves the problem of not affecting the display during acquisition, ensuring that the device access does not interfere with the normal use of the target host; the video acquisition module solves the problem of signal standardization, providing uniform format data for subsequent processing. On the other hand, the entire module is connected to the target host only through a standard video interface, without any data interaction or protocol communication. This one-way signal receiving design further enhances the physical isolation of the device and the host, avoiding the security risks of traditional software-level screenshots due to interaction with the host.

[0077] According to the above embodiment, specifically, the control processing module 12 includes an image processing unit, an encryption unit, and a logic control submodule.

[0078] The input end of the image processing unit is connected to the output end of the video conversion processing module 11, and is used to perform change detection algorithm comparison on the continuous image frame data.

[0079] The output end of the image processing unit is connected to the logic control submodule, and is used to send a frame capture instruction to the logic control submodule when the comparison result meets the frame capture trigger condition.

[0080] The logic control submodule is connected to the image processing unit, the encryption unit, the controlled storage module 13, and the security protection module 14, respectively, and is used to perform frame capture operation after receiving the frame capture instruction, control the encryption unit to encrypt the frame capture image data, send a storage instruction to the controlled storage module 13, and transmit a security state signal to the security protection module 14.

[0081] The input end of the encryption unit is connected to the logic control submodule, and the output end of the encryption unit is connected to the controlled storage module 13, which is used to fully encrypt the frame capture image data and associated metadata.

[0082] The image processing unit, as the core submodule responsible for image analysis in the control processing module 12, is connected to the output end of the video conversion processing module 11. The essential design of this structure is to directly obtain standardized image frame data. Since the video conversion processing module 11 has uniformly converted the original video signal into digital format image frames, the image processing unit does not need to perform additional format adaptation, and can directly focus on the continuous frame comparison task. However, this does not mean that it can only receive image data of a single resolution. In fact, as long as the image frame format meets the preset standard, such as RGB888 (a 24-bit color encoding format, with 8 bits for each of the red, green, and blue color channels), the algorithm can be normally executed. This embodiment does not strictly limit the resolution of the input image.

[0083] The core function of the image processing unit is to perform a change detection algorithm on the continuous image frame data. It should be noted that the change detection algorithm is not specific to a certain fixed algorithm (such as inter-frame difference, perceptual hashing, etc.), and its purpose is to filter out image frames with audit value. Traditional software-level screenshots use timed non-discriminatory collection, which easily produces a large amount of redundant data. However, this unit uses algorithm comparison to trigger subsequent operations only when the image content changes significantly, thereby reducing invalid data from the source, reducing storage pressure and audit costs. It should also be noted that the comparison result meets the screenshot triggering condition, which is determined by the internal algorithm of the unit, and does not mean that the triggering condition cannot be adjusted. In actual applications, the threshold can be adjusted according to the audit requirements (such as the need to accurately capture static monitoring pictures in the parameter modification picture of the SCADA system in a wind farm), to ensure the accuracy of the screenshots.

[0084] In addition, the design of the output end connected to the logic control submodule forms an analysis-instruction transmission link. When the comparison result meets the condition, the unit sends a screenshot instruction to the logic control submodule. This process is not simply a signal transmission, but more importantly, it synchronously transmits basic information such as the trigger reason (such as triggering a screenshot due to a pixel change of ≥15%) to provide a basis for subsequent encryption unit metadata association and log recording.

[0085] The multi-link structure of the logic control submodule connected to the image processing unit, encryption unit, controlled storage module 13, and security protection module 14 is to realize the core function of instruction distribution and state synchronization. After receiving the screenshot instruction from the image processing unit, the submodule does not directly perform the screenshot operation, but first sends a prepare encryption instruction to the encryption unit and then sends a reserved storage space instruction to the controlled storage module 13. This is to ensure the continuous execution of screenshot-encryption-storage through timing scheduling, avoiding data loss due to asynchronous actions between units.

[0086] It should be noted that the description of performing a screenshot operation after receiving a screenshot instruction does not mean that the logic control submodule directly processes image data. In fact, the essence of the screenshot operation is to obtain image frame data that meets the condition from the image processing unit. The core role of the submodule is to trigger and schedule - control the encryption unit to perform encryption on the image frame and associated metadata (such as screenshot time, trigger reason), and at the same time instruct the controlled storage module 13 to receive the encrypted data. In this process, the submodule always plays the role of coordinator rather than data processor.

[0087] On the other hand, the design of transmitting the security state signal to the security protection module 14 is to realize real-time risk warning. The sub-module will continuously synchronize the running state of the device (such as normal storage module connection stability detection of unauthorized access attempt) to the security protection module 14, and does not mean that the sub-module needs to judge the risk level, but the original state data is transmitted to the protection module, and the protection module decides whether to execute the protection action (such as locking the storage medium) according to the preset rules. Based on the above principle, the logical control sub-module ensures the cooperation between the control processing module 12 and other modules through multi-link connection and time sequence scheduling, and avoids the process break caused by independent running of the unit.

[0088] The encryption unit as a key sub-unit to ensure the credibility of data, its input end is connected with the logical control sub-module, and the output end is connected with the controlled storage module 13. The structure forms a dedicated link for data encryption and secure transmission. First, the purpose of connecting the input end with the logical control sub-module is to receive the data to be encrypted, which includes not only the pixel data of the screenshot image, but also the associated metadata (such as device ID and millisecond timestamp) transmitted by the logical control sub-module.

[0089] The core purpose of fully encrypting the screenshot image data and associated metadata is to solve the pain point of easy tampering of traditional software-level screenshot data. Since the traditional screenshot data is stored in the host and is not encrypted or only partially encrypted, it is easy to modify the timestamp and replace the picture content by malicious programs. However, by using full encryption (usually using high-strength encryption algorithms such as AES-256 (symmetric encryption algorithm)), the data is in an encrypted state after generation. Even if the storage medium is illegally obtained, the data cannot be decrypted, ensuring the authenticity and integrity of the data.

[0090] It should be noted that the output end of the encryption unit is directly connected with the controlled storage module 13, not for simplifying the structure, but for reducing the data transmission links. In the traditional mode, data may pass through the host memory, system bus and other links, increasing the risk of leakage. The direct connection design of the unit and the controlled storage module 13 makes the encrypted data directly written into the storage medium, further reducing the security risks in the transmission process. Compared with the weak encryption or no encryption of traditional software-level screenshots, the full encryption and direct connection design of the encryption unit provide stronger protection for data security.

[0091] In summary, the image processing unit screens effective image frames through a change detection algorithm, solving the problem of redundant invalid data; the logic control submodule ensures the timing matching of each link through multi-link scheduling, avoiding data loss or process disorder; the encryption unit solves the problem of low data reliability through full encryption and direct transmission. On the other hand, all operations of the entire control processing module 12 are based on the standardized image frame data provided by the video conversion processing module 11, and are independent of the target host system, not relying on the computing resources or storage environment of the host. This design continues the core feature of non-intrusive device, avoiding security risks caused by interaction with the host.

[0092] According to the above embodiment, specifically, the video acquisition module is built-in with a video acquisition chip and an independent memory area.

[0093] The video acquisition chip is used for decoding or analog-digital conversion of the acquisition signal. If the acquisition signal is a digital video signal, it is decoded into a digital image frame. If the acquisition signal is an analog video signal, it is converted into a digital image frame.

[0094] The independent memory area is connected with the control processing module 12 for data interaction, and is used for temporarily storing the converted digital image frame data.

[0095] The video acquisition chip, as the signal processing core of the video acquisition module, its core function is to decode or analog-digital convert the acquisition signal. This design is not a simple technical choice, but is based on the diversity of the video output signal of the target host. Since different high-security level information systems (such as wind farm SCADA system) may use different types of video interfaces (HDMI output digital signal, VGA output analog signal), the chip needs to have dual-mode processing capability, which does not mean that it only supports two types of signals. In fact, as long as the signal is output by a standard video interface, the chip can complete the processing through an adaptive circuit. This embodiment does not strictly limit the signal type.

[0096] The operation logic of digital signal decoding and analog signal analog-digital conversion is different. If the acquisition signal is a digital video signal (such as HDMI signal), the chip directly parses the image information in the signal through the built-in digital decoding circuit, and outputs a digital image frame in a standardized format such as RGB888. If it is an analog video signal (such as VGA signal), the analog voltage signal is first quantized into a digital signal through the built-in ADC (analog-digital converter), and then converted into a digital image frame in the same format. Regardless of the type of input signal, the chip ultimately outputs a digital image frame in a unified format. The purpose of this design is to provide a standardized data source for the subsequent continuous frame comparison of the control processing module 12, avoiding comparison errors caused by non-uniform signal formats.

[0097] The performance parameters (such as resolution support, frame rate processing capability) of the video capture chip need to match the high security scene requirements. Generally, it needs to support 1080p and above resolution, 60fps and above frame rate, to ensure that the dynamic operation of the host screen (such as the real-time adjustment of the wind turbine parameter picture in the wind farm SCADA system) can be completely captured. However, the specific parameters are not strictly limited in the embodiment, as long as the core requirement of capturing key pictures without omission can be met.

[0098] On the other hand, the independent memory area is used as the data buffer unit of the video capture module, and its core structural feature is to establish a data interaction connection with the control processing module 12 and temporarily store the converted digital image frame data. Here, independent does not only mean independent packaging at the physical level, but more importantly, it means independent at the logical level. The memory area is only used to store the converted digital image frame of the module, and does not interact with the memory of the target host or other external storage devices. This is to avoid data being tampered with or stolen by malicious programs in the host, and to strengthen the physical isolation characteristics of the device and the host.

[0099] It should be noted that the temporary storage function is not simply temporary storage, and its purpose also includes balancing the difference between data generation and transmission speed. Since the video capture chip continuously outputs digital image frames (such as 60fps frame rate, 60 frames of data per second), the comparison processing of the control processing module 12 requires a certain amount of time. If the data is directly transmitted to the control module, it is easy to cause data accumulation or loss due to processing speed lag. Therefore, the independent memory area can cache a certain amount of image frame data, and then transmit it gradually according to the reading rhythm of the control processing module 12, to ensure the stability and continuity of data transmission.

[0100] It should also be noted that the data interaction connection between the independent memory area and the control processing module 12 usually uses a high-speed interface, such as a serial peripheral interface (SPI), with a transmission rate of not less than 50Mbps. The purpose is to ensure real-time transmission of large amounts of image frames. If the transmission rate is too low, even if the memory area temporarily stores the data, it will also cause the subsequent comparison operation to lag due to transmission delay, affecting the timeliness of the screenshot (such as the key picture of parameter modification in the wind farm SCADA system).

[0101] According to the above embodiment, specifically, the hardware interface between the security protection module 14 and the controlled storage module 13 includes: a chip selection control interface of a storage medium, and a voltage detection interface.

[0102] The security protection module 14 monitors the VBUS voltage change of the controlled storage module 13 through the voltage detection interface, and when it is determined that the non-safe removal occurs at present according to the VBUS voltage change, the security protection module 14 outputs a latch signal to the controlled storage module 13 through the chip selection control interface, and prohibits the chip selection signal of the flash memory chip of the controlled storage module 13.

[0103] The hardware interface between the security protection module 14 and the controlled storage module 13 adopts the combination design of the chip selection control interface + voltage detection interface, which is not a simple interface superposition, but a function complementation formed around the core target of physical layer security protection. It should be noted that the hardware interface here is not a general data interface in the traditional sense, but a special control link directly acting on the bottom hardware of the controlled storage module 13, and its role is to realize the forced protection independent of software logic.

[0104] Firstly, the chip selection control interface is a physical switch of the storage medium access permission, and its core function is to control the chip selection signal (CS signal) of the flash memory chip of the controlled storage module 13. In the working logic of the flash memory chip, the chip selection signal is a necessary condition for starting data read / write operation, and only when the chip selection signal is valid, the chip can respond to the external read / write instruction. Therefore, the security protection module 14 outputs a latch signal through the chip selection control interface, which essentially cuts off the access path of the flash memory chip from the physical layer, and does not represent only a single locking function. In fact, the latch signal can be designed as temporary locking or permanent locking according to the risk level, and the present embodiment does not make strict restrictions, as long as the core purpose of prohibiting illegal access can be achieved.

[0105] On the other hand, the voltage detection interface is a monitoring antenna of the connection state of the storage medium, and its role is to monitor the power supply voltage (VBUS) change of the universal serial bus (USB) interface of the controlled storage module 13 in real time. It should be noted that the VBUS voltage (usually 5V or 3.3V) is the power supply voltage for the normal operation of the storage module, and when the non-safe removal (such as directly plugging and unplugging the storage medium without going through the normal uninstallation process) occurs, the VBUS voltage will drop sharply (from the working voltage to 0V) in a short time. This characteristic change cannot be simulated by software, so the voltage detection interface can accurately determine the abnormal operation at the physical layer, avoiding the problem that the traditional software level detection (such as judging through system log) is easy to be deceived. That is, the design of the voltage detection interface utilizes the characteristic that physical operation must be accompanied by voltage change, and realizes the reliable identification of the non-safe removal behavior.

[0106] In practical applications, when the controlled storage module 13 is removed unsafely, the action of the security protection module 14 performs a consistent logic of monitoring-determining-responding, and each link is seamlessly connected through the cooperation of the hardware interface. First, the voltage detection interface samples the VBUS voltage at a frequency of not less than 1 kHz, and when the voltage is detected to drop from the working value to below 0.5 V for 3 consecutive sampling periods (this threshold value can be adjusted according to the power supply characteristics of the storage module, and this embodiment is only an example), it is determined that it is an unsafe removal, and it needs to be noted that continuous sampling + threshold determination is used instead of single sampling, which is to avoid misjudgment caused by voltage fluctuations (such as transient power instability) and ensure the accuracy of the protection action.

[0107] Once it is determined that it is an unsafe removal, the security protection module 14 will immediately output a latch signal to the controlled storage module 13 through the chip selection control interface. The latch signal here is not a simple level signal, but a control signal that meets the timing requirements of the flash memory chip, and its function is to forcibly pull the chip selection pin (CSpin) of the flash memory chip to an invalid level (usually high level), so that even if the storage module is reconnected later, as long as the latch signal is not released, the chip selection signal will always be invalid. It needs to be noted that this locking is not achieved through software instructions, but through a hardware circuit (such as a latch) to physically fix the control state, so it cannot be cracked by re-powering, flashing firmware, etc., ensuring the absolute nature of the protection.

[0108] It also needs to be noted that the cooperation of the chip selection control interface and the voltage detection interface is not one-way triggering, but there is a feedback mechanism. After the security protection module 14 outputs the latch signal, it will continuously monitor the VBUS voltage through the voltage detection interface, and if it detects that the storage module is reconnected (the voltage returns to the working value), it will maintain the latch signal unchanged until the lock is released through a legal way (such as inputting an administrator key); if it detects that there are multiple unsafe removals (such as more than 3 times in a short period of time), it can trigger a higher level of protection action (such as sending a permanent disable signal through the chip selection control interface), which reflects the progressive nature of the protection logic, and not just a single locking action.

[0109] According to the above embodiment, specifically, the security protection module 14 internally integrates a physical fuse circuit.

[0110] The output end of the physical fuse circuit is connected to the key storage chip of the controlled storage module 13, and when the security protection module 14 receives the protection action start instruction of the control processing module 12, it releases current to the key storage chip through the physical fuse circuit; data overwriting and metadata deletion are performed through the chip selection control interface and the data write interface.

[0111] The physical fuse circuit integrated in the security protection module 14 is a key hardware unit for realizing irreversible data protection. The output end of the physical fuse circuit is connected with the key storage chip of the controlled storage module 13. The structure design is not a simple electrical connection, but a protection link directly acting on the key carrier. It should be noted that the key storage chip is the only storage carrier of the decryption key of the encryption unit. Once the key is destroyed, even if the encrypted data is illegally obtained, it cannot be decrypted by technical means. Therefore, the core function of the physical fuse circuit is to ensure that the key is permanently disabled by physical destruction, and it does not mean that it can only act on a single type of key chip. In fact, as long as the storage chip adopts a fuse structure or an anti-fuse structure, the circuit can realize the fuse operation. The embodiment does not strictly limit the type of chip.

[0112] The design of the physical fuse circuit is in a low-power standby state when the device is normally running, which does not affect the normal work of the key storage chip. Only when the protection action start instruction is received, the fuse operation is activated and executed instantaneously. The purpose of this design is to avoid normal data loss caused by accidental triggering and to ensure the accuracy of the protection action.

[0113] When the security protection module 14 receives the protection action start instruction of the control processing module 12 (for example, detects 10 consecutive password input errors, or the host issues a malicious access alarm), it does not rely solely on the single action of the physical fuse circuit, but forms a protection closed loop through multi-dimensional operations of fuse + overwrite + clear. Each link is seamlessly connected through the cooperation of different hardware interfaces.

[0114] After receiving the start signal, the physical fuse circuit will release a pulse current of a preset intensity (usually 5-10 times the working current) to the key storage chip within 100 ms (this response time can be adjusted according to the safety level requirement, and this embodiment is only an example). It should be noted that this current is not randomly set, but is accurately matched with the fuse blowing threshold of the key storage chip. Excessive current will cause damage to the chip shell and may cause secondary failure. Too small current cannot blow the fuse, resulting in protection failure.

[0115] While the physical fuse circuit is performing the operation, the security protection module 14 synchronously performs data overwriting and metadata clearing through the chip selection control interface and the data writing interface. Specifically, all flash chips of the controlled storage module 13 are activated through the chip selection control interface, and then random binary data is continuously written to the storage area through the data writing interface (usually more than 3 times of overwriting, which meets the national information security standard), so as to completely destroy the physical storage traces of the original encrypted data; at the same time, the metadata (such as file index, access log) stored in the chip specific area is forcibly cleared through a special instruction, so as to avoid that the attacker obtains the data structure information through metadata analysis. It should be noted that the operations of fusing and overwriting are performed in parallel, and there is no time sequence relationship. The role of this design is to compress the attack window to the maximum, that is, even if the fusing operation does not completely take effect due to extreme conditions, the overwriting operation can also provide a second guarantee.

[0116] The design of the physical fuse circuit embodies the core advantages of hardware-level protection: first, irreversibility. The fuse cannot be restored by software repair or hardware replacement after being fused (the key storage chip is a built-in component that cannot be replaced), which ensures the finality of the protection action; second, tamper resistance. The trigger logic of the circuit is realized through hardware logic gates, and does not depend on firmware or operating system, which avoids the risk that software-level protection is easily tampered with; third, instantaneous responsiveness. The entire process from receiving the instruction to completing the fusing is controlled within milliseconds, which is much faster than the data copying speed that the attacker may perform, thereby ensuring the timeliness of the protection.

[0117] From the overall protection system of the device, the physical fuse circuit, the chip selection control interface and the voltage detection interface form a complementary function: the voltage detection interface is responsible for early identification of abnormal behavior, the chip selection control interface realizes immediate access blocking, and the physical fuse circuit executes the final data destruction, which together constitute a progressive protection chain of monitoring-blocking-destruction.

[0118] According to the above embodiment, specifically, the control processing module 12 further includes: a watermark embedding unit, a compression encoding unit.

[0119] The input end of the watermark embedding unit is connected with the frame-cutting data output end of the logic control submodule, and the output end is connected with the input end of the compression encoding unit, for embedding the tamper-proof device identifier, millisecond timestamp and geographic location information in the frame-cutting image data.

[0120] The output end of the compression encoding unit is connected with the input end of the encryption unit, for performing lossless compression processing on the frame-cutting image data containing the watermark.

[0121] The watermark embedding unit is a core subunit responsible for data tracing in the control processing module 12. The input end of the watermark embedding unit is connected to the frame-cutting data output end of the logical control submodule. The essential purpose of this structural design is to intervene in the processing at the first time of generating frame-cutting image data.

[0122] The watermark embedding unit embeds tamper-proof device identification, millisecond-level timestamp, and geographic location information in the frame-cutting image data. The watermark information is hidden in the frequency components of the image, not in the pixel values themselves. Therefore, even if the image undergoes slight compression or format conversion, the watermark will not be lost.

[0123] The device identification (usually a 32-bit unique code) is used to distinguish different collection devices and avoid data confusion in multi-device auditing scenarios. The millisecond-level timestamp is used to accurately record the frame-cutting time and solve the problem of easily modified traditional software-level screenshot timestamps. The geographic location information (latitude and longitude encoding) is suitable for distributed scenarios such as wind farm SCADA systems and facilitates tracing the physical location of image collection. The three together form the tracing information, providing legal compliance support for subsequent auditing and evidence.

[0124] Since encryption operations convert data into random bit streams, if encryption is performed first and then compression, the compression algorithm cannot identify the redundant information in the data, and the compression ratio will be greatly reduced. If compression is performed first and then encryption, the data volume can be reduced through compression, and the security of encryption is not affected. Therefore, the position design of the unit is the optimal choice based on data processing efficiency.

[0125] In summary, the logical control submodule is responsible for instruction scheduling, the image processing unit is responsible for accurate frame-cutting, the watermark embedding unit is responsible for data tracing, the compression and encoding unit is responsible for efficiency optimization, and the encryption unit is responsible for security protection.

[0126] According to the above embodiment, specifically, the image processing unit includes: an inter-frame difference analysis submodule, a perceptual hash rapid comparison submodule, or a logical gate.

[0127] The inter-frame difference analysis submodule and the perceptual hash rapid comparison submodule are arranged in parallel, and the input ends of both are connected to the output end of the video conversion processing module 11 for synchronous reception of continuous image frame data.

[0128] The inter-frame difference analysis submodule is used to calculate the pixel absolute difference between adjacent frames of image frame data block by block, and outputs an image significant change judgment signal when the pixel absolute difference exceeds a preset difference value.

[0129] The perceptual hash rapid comparison submodule is used to obtain the Hamming distance according to the image hash values of adjacent frames. When the Hamming distance is greater than a preset threshold, an image significant change judgment signal is output.

[0130] The input terminals of the OR logic gate are connected to the output terminals of the inter-frame difference analysis submodule and the perceptual hash fast comparison submodule, respectively, and the output terminal of the OR logic gate is connected to the logic control submodule of the control processing module 12. This is used to send a frame-truncation trigger signal to the logic control submodule when the inter-frame difference analysis submodule or the perceptual hash fast comparison submodule outputs a significant image change judgment signal.

[0131] Specifically, the image processing unit adopts a parallel architecture of inter-frame difference analysis submodule + perceptual hash fast comparison submodule + OR logic gates. This design is not simply functional duplication, but rather aims to improve the accuracy of image change detection through algorithmic complementarity. It should be noted that the parallel configuration of the two submodules and their inputs being connected to the video conversion processing module 11 means that they will synchronously receive the same continuous image frame data. However, this does not mean that their processing logic or output results are completely identical. In fact, inter-frame difference analysis focuses on pixel-level detail changes, while perceptual hash comparison focuses on overall structural changes. Together, they cover different types of image changes.

[0132] The core function of the inter-frame difference analysis submodule is to calculate the absolute difference of pixels between adjacent frames block by block. Its processing logic is based on the direct comparison of pixel values: the submodule first divides the image frame into 16×16 or 32×32 pixel blocks (the block size can be adjusted according to the image resolution, and this embodiment is not strictly limited), then calculates the absolute difference of the RGB values ​​of each pixel in the corresponding block of adjacent frames, and finally counts the percentage of pixels whose difference exceeds a preset threshold (such as 15). When the percentage exceeds the preset difference (such as 20%), it is determined that the image has changed significantly and a signal is output.

[0133] Calculate the absolute difference of the RGB values ​​of each pixel in corresponding blocks of adjacent frames:

[0134] .

[0135] in, Represents the i-th row and j-th sub-plot The difference matrix; Indicates the first Frame image in coordinates Pixel value at that location, Then it means the first Frames at the same coordinates The pixel value at that location.

[0136] The difference matrix of the entire image is then normalized to the [0,1] interval:

[0137] .

[0138] in, D represents the normalized difference matrix; D represents the original difference matrix. represents the maximum pixel difference in the original difference matrix D.

[0139] determines whether the normalized difference of each pixel exceeds a threshold :

[0140] .

[0141] wherein, represents a binary matrix of pixel change determination results; represents the difference value of a pixel point with coordinates (x, y) in the image after normalization processing.

[0142] statistics the proportion of the significant change area in the whole image :

[0143] .

[0144] wherein, p represents the proportion of the significant change area in the whole image; WxH represents the total number of pixels in the whole image, wherein W is the image width (number of pixels) and H is the image height (number of pixels); ∑ represents summation operation.

[0145] If more than 15% of the area in the whole image has significant pixel-level change (p>15%), the system determines that the picture has substantial content change.

[0146] The function of the perceptual hash quick comparison submodule is to judge the change through the Hamming distance of the image hash value, and the processing logic is more focused on the overall features: the submodule will first scale the image frame to an 8x8 grayscale image, calculate a 64-bit perceptual hash value (each bit represents the light and dark features of the corresponding area), and then calculate the Hamming distance (the number of different bits) of the hash values of adjacent frames. When the Hamming distance is greater than a preset threshold (such as 8), a change determination signal is output. The advantage of this design is that it is sensitive to overall structural changes, for example, in the SCADA system, the interface is switched from the parameter monitoring page to the fault alarm page, even if the pixel change in some areas is not large, it can also be quickly identified. It should be noted that the calculation amount of hash comparison is much smaller than pixel-by-pixel comparison, so the response speed of the submodule is faster, and it is suitable for processing high frame rate image data.

[0147] For an image block of size N x N, the two-dimensional DCT change is defined as: (an example of 8x8)

[0148] .

[0149] wherein, represents the pixel value of an image block of size N x N at spatial coordinates (x, y) in the original image; denotes the coefficient value of the image block f(x, y) after two-dimensional discrete cosine transform in the frequency domain coordinate (u, v) ; and denotes the normalized coefficient, and is the frequency domain coordinate, ranging from ; N denotes the size parameter of the image block (such as N = 8 in an 8 × 8 pixel block), and x and y respectively denote the horizontal coordinate value and the vertical coordinate value of the spatial coordinate (x, y).

[0150] Further, the 64-bit hash is generated by the median binary method:

[0151] .

[0152] .

[0153] wherein, denotes the i-th row and the j-th binary value in the 64-bit perceptual hash value, taking values of 1 or 0; denotes the i-th row and the j-th column coefficient value in the low-frequency coefficient region after DCT transformation, wherein, denotes the low-frequency coefficient region; denotes the median value of the DCT coefficient, denotes the image frame at time ; and denotes the perceptual hash sequence of the t-th image frame, which is composed of 64 binary values in order. The image similarity is determined by the Hamming distance between the continuous frames. When the Hamming distance exceeds the default threshold of 8 bits, it is also determined that significant changes have occurred, thereby triggering image frame interception.

[0154] The OR gate is used as the result integration unit of the two parallel sub-modules, the input ends of which are respectively connected to the two sub-modules, and the output end is connected to the logic control sub-module. The core function is to realize the logic that any sub-module determines the change to trigger the frame interception. When the frame difference analysis sub-module detects the detail change, or the perceptual hash comparison sub-module detects the overall change, or the OR gate will send a frame interception trigger signal to the logic control sub-module, and it does not mean that both sub-modules need to determine the change to trigger. The purpose of this design is to maximize the coverage of different types of image change scenarios.

[0155] It should be further pointed out that the preset thresholds (difference threshold and Hamming distance threshold) of the two sub-modules are not fixed, but can be dynamically adjusted according to the audit scene requirements.

[0156] According to the above embodiment, specifically, the second output end of the video signal splitting module is connected with an external display, and the external display receives and displays the display signal output by the video signal splitting module.

[0157] The second output end of the video signal splitting module is a dedicated transmission channel for the display signal, and the design of connecting the external display is not a simple functional expansion, but to achieve the core goal of capturing without affecting normal display. It should be noted that the second output end here is relative to the first output end connected to the video capture module, and the two are completely consistent in electrical characteristics and signal quality, and there is no priority difference, only the functional division is different, the first output end is responsible for transmitting the capture signal to the internal device, and the second output end is responsible for transmitting the display signal to the external display. The one-in-two-out structure ensures that the video content of the target host can be captured and displayed at the same time.

[0158] The connection between the second output end and the external display usually adopts a standard interface consistent with the original interface type of the target host (such as the host outputting an HDMI signal, and the second output end also adopting an HDMI interface), which can minimize the signal conversion link.

[0159] The process of the external display receiving and displaying the display signal is essentially a lossless copy of the original display content of the target host, and its core role is reflected in two aspects: on the one hand, it ensures the normal work of the operator, and after the device is connected, the video output of the target host is supplied to the original display (or the designated external display) through the splitting module, and the operator can still view the screen content and perform operations as usual, avoiding work interruption caused by the device connection.

[0160] It should be noted that the display signal and the capture signal are synchronized, and the transmission delay difference should be controlled within 10ms to ensure that the content displayed by the external display is highly consistent with the image frame data captured by the device in time. The role of this synchronization is to avoid the audit deviation caused by the asynchronous operation picture and capture content.

[0161] Finally, the application also provides a non-invasive image capturing and storing method applied to a non-invasive image capturing and storing device, which comprises a video conversion processing module 11, a control processing module 12, a controlled storage module 13 and a security protection module 14. The video conversion processing module 11 is connected with a target host through a standard video interface, receives a video output signal output by the target host and converts the video output signal into image frame data. The control processing module 12 is connected with the output end of the video conversion processing module 11, is used for comparing continuous image frame data, performs a frame capturing operation when a comparison result meets a frame capturing triggering condition, and performs an encryption processing on frame captured image data obtained through the frame capturing operation. The controlled storage module 13 is connected with the control processing module 12 and is used for storing the frame captured image data encrypted by the control processing module 12. The security protection module 14 is connected with the control processing module 12, and the security protection module 14 is connected with the controlled storage module 13 through a hardware interface and is used for performing a data protection operation through the hardware interface when a security protection triggering signal of the control processing module 12 is monitored.

[0162] As shown in Figure 2 the method comprises:

[0163] receiving image frame data output by a video conversion processing module.

[0164] comparing continuous image frame data.

[0165] performing a frame capturing operation when a comparison result meets a frame capturing triggering condition, and performing an encryption processing on frame captured image data obtained through the frame capturing operation.

[0166] storing the frame captured image data after the encryption into a controlled storage module.

[0167] sending a security protection triggering signal to a security protection module when an illegal intrusion signal is detected, so as to control the security protection module to perform a data protection operation through a hardware interface.

[0168] The steps of the method correspond one by one to the module structure of the aforementioned non-intrusive image capture and storage device, are executed by the control processing module 12, and the video conversion processing module 11 is directly connected to the target host video output link through a standard video interface. The device is independent of the host system as a whole, does not depend on the host permission, does not interact with the host for data or protocol communication, obtains the video signal from the physical layer, avoids the acquisition blind area caused by insufficient permission or protection interception; the control processing module 12 encrypts the captured image, protects the data security; the control processing module 12 triggers the capture only when a significant change in the image is detected, avoids indiscriminate acquisition, reduces the redundant data irrelevant to the audit from the source, and reduces the storage and operation cost of subsequent audit analysis; the protection operation of the security protection module 14 is executed through a hardware interface and does not depend on the host software logic, avoiding the protection failure caused by remote control of the host, and solving the problems of acquisition blind area, low data reliability and redundant invalid data caused by traditional software level screenshot technology.

[0169] The non-intrusive image capture and storage device and method provided by the present application are described in detail above. Each embodiment in the specification is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts of each embodiment can be referred to. For the device disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the method part. It should be pointed out that for ordinary skilled in the art, without departing from the principles of the present application, the present application can be improved and modified, and these improvements and modifications also fall within the protection scope of the claims of the present application.

[0170] It should also be noted that in the present specification, the relationship terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between the entities or operations. Moreover, the terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the element defined by the statement "including a" does not exclude the presence of another identical element in the process, method, article or device including the element.

Claims

1. A non-invasive image capturing and storing device, characterized in that, The application relates to a video conversion processing module, a control processing module, a controlled storage module and a security protection module. The video conversion processing module is connected with a target host through a standard video interface, receives a video output signal output by the target host and converts the video output signal into image frame data. The control processing module is connected with the output end of the video conversion processing module, is used for comparing the continuous image frame data, performs a frame capturing operation when a comparison result meets a frame capturing triggering condition, and performs an encryption processing on frame-captured image data. The controlled storage module is connected with the control processing module and is used for storing the frame-captured image data encrypted by the control processing module. The security protection module is connected with the control processing module, is connected with the controlled storage module through a hardware interface, and is used for performing a data protection operation through the hardware interface when a security protection triggering signal of the control processing module is monitored. The control processing module comprises an image processing unit, an encryption unit and a logic control sub-module. The input end of the image processing unit is connected with the output end of the video conversion processing module, is used for performing a change detection algorithm on the continuous image frame data. The output end of the image processing unit is connected with the logic control sub-module, is used for sending a frame capturing instruction to the logic control sub-module when the comparison result meets the frame capturing triggering condition. The logic control sub-module is connected with the image processing unit, the encryption unit, the controlled storage module and the security protection module, is used for performing the frame capturing operation after receiving the frame capturing instruction, controlling the encryption unit to encrypt the frame-captured image data, sending a storage instruction to the controlled storage module and transmitting a security state signal to the security protection module. The input end of the encryption unit is connected with the logic control sub-module, and the output end of the encryption unit is connected with the controlled storage module, and the encryption unit is used for performing full encryption on the frame-captured image data and associated metadata. The image processing unit comprises an inter-frame difference analysis sub-module, a perceptual hash fast comparison sub-module or a logic gate. The input end of the image processing unit is connected with the output end of the video conversion processing module, is used for synchronously receiving the continuous image frame data. The inter-frame difference analysis sub-module is used for calculating the pixel absolute difference value between adjacent frames of the image frame data block by block, and outputs an image significant change judgment signal when the pixel absolute difference value exceeds a preset difference value. The perceptual hash fast comparison sub-module is used for obtaining a Hamming distance according to image hash values of adjacent frames, and outputs an image significant change judgment signal when the Hamming distance is greater than a preset threshold. The input end of the logic gate is connected with the output end of the inter-frame difference analysis sub-module and the perceptual hash fast comparison sub-module, the output end of the logic gate is connected with the logic control sub-module of the control processing module, and the logic gate is used for sending a frame capturing triggering signal to the logic control sub-module when the inter-frame difference analysis sub-module or the perceptual hash fast comparison sub-module outputs the image significant change judgment signal. ​ The hardware interface between the security protection module and the controlled storage module includes a chip select control interface of a storage medium and a voltage detection interface; The security protection module monitors a VBUS voltage change of the controlled storage module through the voltage detection interface, and when it is determined that a non-safe removal is currently occurring according to the VBUS voltage change, the security protection module outputs a latch signal to the controlled storage module through the chip select control interface to disable a chip select signal of a flash memory chip of the controlled storage module. After the security protection module outputs the latch signal, it continuously monitors the VBUS voltage through the voltage detection interface, and if it detects that the storage module is reconnected, the latch signal is maintained unchanged until the latch is released through a legal way; if it detects that the non-safe removal occurs continuously for multiple times, a higher-level protection action is triggered.

2. The non-invasive image capture and storage device of claim 1, wherein, The video conversion processing module includes a video signal splitting module and a video acquisition module. The video signal splitting module is connected with a target host through a standard video interface, and is configured to access a video output signal of the target host and split the video output signal into a display signal and an acquisition signal. An input end of the video acquisition module is connected with a first output end of the video signal splitting module, and is configured to receive the acquisition signal; and an output end of the video acquisition module is connected with the control processing module and is configured to convert the acquisition signal into digital image frame data.

3. The non-invasive image capture and storage device of claim 2, wherein, The video acquisition module is internally provided with a video acquisition chip and an independent memory area. The video acquisition chip is configured to decode or analog-digital convert the acquisition signal, and if the acquisition signal is a digital video signal, the video acquisition chip decodes the digital video signal into a digital image frame, and if the acquisition signal is an analog video signal, the video acquisition chip analog-digital converts the analog video signal into a digital image frame. The independent memory area is connected with the control processing module for data interaction, and is configured to temporarily store the converted digital image frame data.

4. The non-invasive image capture and storage device of claim 1, wherein, The security protection module is internally provided with a physical fuse circuit. An output end of the physical fuse circuit is connected with a key storage chip of the controlled storage module, and when the security protection module receives a protection action starting instruction from the control processing module, the physical fuse circuit releases a current to the key storage chip; and the chip select control interface and a data writing interface are used for data overwriting and metadata clearing.

5. The non-invasive image capture and storage device of claim 1, wherein, The control processing module further includes a watermark embedding unit and a compression encoding unit. An input end of the watermark embedding unit is connected with a frame-cutting data output end of the logic control sub-module, and an output end of the watermark embedding unit is connected with an input end of the compression encoding unit, and is configured to embed an unalterable device identifier, a millisecond-level time stamp and geographic location information in the frame-cutting image data. An output end of the compression encoding unit is connected with an input end of an encryption unit, and is configured to perform lossless compression processing on the frame-cutting image data containing the watermark.

6. The non-invasive image capture and storage device of claim 2, wherein, A second output end of the video signal splitting module is connected with an external display, and the external display receives and displays the display signal output by the video signal splitting module.

7. A non-invasive image capture and storage method, characterized by, The application is applied to a non-invasive image capturing and storage device, which comprises a video conversion processing module, a control processing module, a controlled storage module and a security protection module. The video conversion processing module is connected with a target host through a standard video interface, receives a video output signal output by the target host and converts the video output signal into image frame data. The control processing module is connected with an output end of the video conversion processing module, is used for comparing continuous image frame data, performs a frame capturing operation when a comparison result meets a frame capturing trigger condition, and performs an encryption processing on frame captured image data. The controlled storage module is connected with the control processing module and is used for storing the frame captured image data encrypted by the control processing module. The security protection module is connected with the control processing module and is connected with the controlled storage module through a hardware interface, and is used for performing a data protection operation through the hardware interface when a security protection trigger signal of the control processing module is monitored. The method comprises: receiving image frame data output by the video conversion processing module; comparing continuous image frame data; performing a frame capturing operation when a comparison result meets a frame capturing trigger condition, and performing an encryption processing on frame captured image data; storing the frame captured image data after encryption into the controlled storage module; sending a security protection trigger signal to the security protection module when an illegal intrusion signal is detected, so as to control the security protection module to perform a data protection operation through a hardware interface; further comprising: performing a change detection algorithm on continuous image frame data for comparison; sending a frame capturing instruction to a logic control submodule when a comparison result meets a frame capturing trigger condition; performing a frame capturing operation after receiving the frame capturing instruction, controlling an encryption unit to encrypt frame captured image data, sending a storage instruction to the controlled storage module and transmitting a security state signal to the security protection module; performing full encryption on frame captured image data and associated metadata; specifically comprising: synchronously receiving continuous image frame data; calculating pixel absolute difference values between adjacent frames of the image frame data block by block, and outputting an image significant change determination signal when the pixel absolute difference values exceed a preset difference value; obtaining a Hamming distance according to image hash values of adjacent frames, and outputting an image significant change determination signal when the Hamming distance is greater than a preset threshold value; sending a frame capturing trigger signal to the logic control submodule when an image significant change determination signal is output by a frame difference analysis submodule or a perceptual hash fast comparison submodule; The hardware interface between the security protection module and the controlled storage module comprises a chip select control interface of a storage medium and a voltage detection interface; the security protection module monitors VBUS voltage variation of the controlled storage module through the voltage detection interface; when it is determined that non-safe removal is currently occurring according to the VBUS voltage variation, the security protection module outputs a latch signal to the controlled storage module through the chip select control interface, and prohibits the chip select signal of the flash memory chip of the controlled storage module; after outputting the latch signal, the security protection module continuously monitors the VBUS voltage through the voltage detection interface; if it is detected that the storage module is reconnected, the latch signal is maintained unchanged until the latch is released through a legal way; if it is detected that non-safe removal occurs continuously for multiple times, a higher-level protection action is triggered.

Citation Information

Patent Citations

  • Video line transmission data online extraction and stealth storage control device and working method thereof

    CN109089084A

  • Video file production method, device and apparatus and readable storage medium

    CN110087123A

  • Soft destroying key for different security levels

    CN119885229A