Method and system for dynamic generation and distribution of keys based on unidirectional channels

By using a one-way channel-based key dynamic generation and distribution system, and leveraging video interfaces and one-way transmission links, the problem of low key update efficiency in one-way transmission systems is solved. This enables high-frequency automated updates and multi-terminal support, thereby improving security and efficiency.

CN121485926BActive Publication Date: 2026-05-15ZEN-AI TECH
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ZEN-AI TECH
Filing Date
2025-12-01
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

In high-security scenarios where internal and external networks are isolated, especially when using a unidirectional transmission system, existing technologies cannot achieve efficient and automated dynamic key updates, resulting in cumbersome operations and a high risk of human error, failing to meet the frequent update needs of a large number of terminals on the external network side.

Method used

A key dynamic generation and distribution system based on a one-way channel is adopted. By using a video interface and a one-way transmission link, the key is mapped to a video stream and verified through mechanisms such as digital signature, timestamp, key serial number and check code, so as to realize automated high-frequency update and multi-terminal concurrent support.

Benefits of technology

It enables high-frequency automated key updates in a one-way transmission environment, improving security and efficiency, preventing tampering and replay attacks, and meeting the key synchronization requirements of large-scale cluster systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121485926B_ABST
    Figure CN121485926B_ABST
Patent Text Reader

Abstract

The application relates to a one-way channel-based dynamic key generation and distribution system, which comprises an inner network side key generation module, a key encapsulation and signature module, a video sending module, an outer network side video receiving module, a key analysis and verification module and an outer network security agent module, and a one-way transmission link; the key generation module is used for dynamically generating a key; the key encapsulation and signature module is used for encapsulating, and the encapsulation structure comprises a key serial number, a check code, a frame header, a time stamp and a digital signature; the video sending module is connected with the key encapsulation and signature module and is used for mapping the encapsulated key package into a video signal and outputting the video signal to the one-way transmission link; the one-way transmission link is used for transmitting the video signal from the video sending module to the video receiving module; the video receiving module is used for extracting the key package; and the key analysis and verification module is used for verifying the received key package; and the application can realize dynamic, safe and high-speed distribution of the key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of information security and data transmission technology, and in particular to a method and system for dynamic key generation and distribution based on a one-way channel. Background Technology

[0002] In high-security scenarios involving isolation between internal and external networks (such as military, energy, meteorological, and government private networks), especially when using unidirectional transmission systems (such as unidirectional transmission based on optical gates), the lack of a physical return channel prevents the receiving end from informing the sending end that the key has been "received" or that the key has been "verified successfully." This renders traditional key transmission methods unsuitable for unidirectional transmission systems. Therefore, current technologies typically involve security administrators copying key files between internal and external networks using storage media such as USB drives or CDs. While this method offers high security, it is extremely inefficient, cumbersome, prone to human error, and cannot achieve high-frequency dynamic updates (rolling updates). This is particularly problematic when numerous terminals on the external network require frequent key updates, making manual key updates impossible. Summary of the Invention

[0003] To address the above technical issues, this application proposes a key dynamic generation and distribution system based on a one-way channel.

[0004] According to some embodiments of the present invention, a key dynamic generation and distribution system based on a unidirectional channel includes: a key generation module, a key encapsulation and signing module, and a video transmission module located on the intranet side; a video receiving module, a key parsing and verification module, and an extranet security proxy module located on the extranet side; and a unidirectional transmission link located between the intranet side and the extranet side.

[0005] The key generation module is used to dynamically generate the key body and assign it a key sequence number to form the original key data;

[0006] The key encapsulation and signature module is used to receive raw key data and encapsulate it into a key packet. The encapsulation structure includes a key sequence number, a checksum, a frame header, a timestamp, and a digital signature.

[0007] The video transmission module is connected to the key encapsulation and signature module, which is used to map the encapsulated key packet into a video signal and output it to the unidirectional transmission link.

[0008] A one-way transmission link is used to transmit video signals from the video transmitting module to the video receiving module;

[0009] The video receiving module is used to receive video signals from a one-way transmission link and extract the key packet through decoding and re-timing processing;

[0010] The key parsing and verification module is used to verify the received key packets. The verification includes checking the digital signature, timestamp, password sequence number, and check code. The digital signature check includes using a preset external public key to verify whether the data was sent from a trusted internal network and has not been tampered with; checking the timestamp and password sequence number to discard expired or duplicate old key packets; and checking the check code to eliminate transmission errors.

[0011] The external network security proxy module is used to extract the valid key after the verification is passed, and update it to the external network business system, replacing the original old key.

[0012] According to some embodiments of the present invention, the key encapsulation and signature module is further configured to concatenate and encapsulate the key packets of multiple user terminals into an image frame. The frame header of the image frame includes an index table, which records the identity serial number of each user terminal and the starting offset and length of the key of the user terminal in the image frame. The frame body structure arranges the keys of each user terminal in sequence. After encapsulating an image frame, it is sent to the video sending module or the encapsulated image frame is sent at a predetermined time interval.

[0013] The key parsing and verification module is also used to verify whether the identity serial number matches the identity characteristics of each user terminal it is connected to, and to send the key to the corresponding user terminal after successful verification.

[0014] According to some embodiments of the present invention, the dynamic key generation includes being triggered at predetermined time intervals or at predetermined security events.

[0015] According to some embodiments of the present invention, the video transmission module includes an HDMI, DP, SDI, or LVDS video interface transmitter.

[0016] According to some embodiments of the present invention, the unidirectional transmission link includes: an electro-optical conversion unidirectional optical transmitter for converting an electrical signal into an optical signal; a unidirectional optical fiber; and an opto-optical conversion unidirectional optical receiver for converting the optical signal back into an electrical signal.

[0017] According to some embodiments of the present invention, the unidirectional transmission link includes an electro-optical conversion unidirectional optical transmitter for converting an electrical signal into an optical signal; multiple parallel unidirectional optical fibers; and each photoelectric conversion unidirectional optical receiver connected to each unidirectional optical fiber for converting the optical signal back into an electrical signal.

[0018] According to some embodiments of the present invention, the external network side includes an AI model, which is used to analyze the noise distribution or error patterns of received video frames. If a specific pattern of errors is found, the AI ​​module triggers a defense alarm on the external network side.

[0019] According to some embodiments of the present invention, the key dynamic generation and distribution method based on a one-way channel includes performing the following actions on the intranet side:

[0020] Dynamically generate the key body and assign it a key sequence number to form the original key data;

[0021] Receive raw key data and encapsulate it into a key packet. The encapsulation structure includes a key sequence number, a checksum, a frame header, a timestamp, and a digital signature.

[0022] The encapsulated key packet is mapped into a video signal and output to a one-way transmission link;

[0023] The video signal is transmitted from the intranet side to the extranet side via a one-way transmission link;

[0024] Perform the following actions on the external network side:

[0025] It receives video signals from a one-way transmission link, and extracts the key packet through decoding and re-timing processing;

[0026] The key packet is verified, including checking the digital signature, timestamp, password sequence number, and checksum. The digital signature check includes verifying whether the data was sent from a trusted internal network and has not been tampered with using a preset external public key; checking the timestamp and password sequence number to discard expired or duplicate old key packets; and checking the checksum to eliminate transmission errors.

[0027] After the verification is successful, the valid key is extracted and updated in the business system on the external network, replacing the original old key.

[0028] According to some embodiments of the present invention, receiving raw key data and encapsulating it into a key packet includes: splicing and encapsulating the key packets of multiple user terminals into an image frame, wherein the frame header of the image frame contains an index table, the index table records the identity serial number of each user terminal and the starting offset and length of the key of the user terminal in the image frame, and the frame body structure arranges the keys of each user terminal in sequence.

[0029] The key parsing and verification module is also used to verify whether the identity serial number matches the identity characteristics of each user terminal it is connected to, and to send the key to the corresponding user terminal after successful verification.

[0030] According to some embodiments of the present invention, the dynamic key generation includes being triggered at predetermined time intervals or at predetermined security events.

[0031] The method and system for dynamic key generation and distribution based on a one-way channel provided by this invention have the following significant technical advantages compared with the prior art.

[0032] This invention creatively utilizes video interfaces and unidirectional transmission links as key carriers, breaking the traditional understanding that key distribution must rely on a two-way TCP / IP handshake. With the internal network (source side) acting as an absolutely unidirectional sender and the external network (receiving side) acting as an absolutely unidirectional receiver, the path for reverse communication or attacks from the external network to the internal network is completely severed at the physical layer, greatly enhancing the security of the internal network's core security domain.

[0033] Secondly, this invention eliminates the bottleneck of manual synchronization, enabling automated high-frequency updates. By mapping the key to a continuous video stream, the system can broadcast the latest key to the external network at a frequency of tens or even hundreds of times per second. This completely replaces the inefficient manual copying (USB flash drive) mode, making high-frequency dynamic key strategies of "one-time key" or "minute-level rotation" possible in physically isolated scenarios, significantly increasing the time cost for attackers to crack the key.

[0034] Furthermore, this invention also enables multi-terminal concurrency support and high bandwidth utilization. By utilizing the Gbps-level bandwidth of video interfaces (such as HDMI / DP), the multi-key aggregation frame structure proposed in this invention can simultaneously carry the keys of hundreds or thousands of terminals in a single video frame. Compared to traditional low-speed serial port unidirectional transmission, the key distribution throughput of this solution is increased by several orders of magnitude, which can meet the key synchronization requirements of large-scale cluster systems.

[0035] Finally, this invention provides a secure and reliable verification mechanism. Although it lacks a return confirmation, by introducing digital signatures, timestamps, key serial numbers, identity serial numbers, checksums, and intra-frame indexing mechanisms, the receiving end can independently verify the integrity, freshness, and ownership of the key, ensuring that tampering, forgery, and replay attacks can still be prevented even in a one-way "blind reception" environment. Attached Figure Description

[0036] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used are briefly described below:

[0037] Figure 1 A block diagram of a one-way channel-based key dynamic generation and distribution system is shown according to some embodiments of the present invention;

[0038] Figure 2 A schematic diagram of an image frame structure containing a multi-terminal key is shown (at time t1) according to some embodiments of the present invention.

[0039] Figure 3 A schematic diagram of an image frame structure containing an updated multi-terminal key is shown (at time t2) according to some embodiments of the present invention.

[0040] Figure 4 A flowchart of a key dynamic generation and distribution method according to some embodiments of the present invention is shown;

[0041] Figure 5 This diagram illustrates a timing interaction diagram of one-way key distribution from an intranet to an extranet according to some embodiments of the present invention. Detailed Implementation

[0042] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.

[0043] Terminology Explanation

[0044] Unidirectional transmission link: refers to a channel that only supports one-way physical transmission (such as electrical to optical transmission via optical fiber, and then optical to electrical transmission). This channel physically cuts off any backhaul circuits, ensuring that data can only flow from the source side to the receiver side.

[0045] Dynamic key generation: refers to the generation of new encryption keys periodically or based on events within the intranet security domain by the Hardware Security Module (HSM) or trusted computing environment.

[0046] Distribution: refers to the process of broadcasting data to the external network through a one-way channel. This process does not involve TCP / IP handshake or ACK confirmation, and is similar to broadcast mode.

[0047] Source side / internal network end: refers to a high-security network, which is the key generator and sender.

[0048] Receiving side / external network end: refers to low-security level or external network, which is the recipient and user of the key.

[0049] Key packet: refers to a data unit constructed for transmission over a one-way link, which encapsulates the key body, signature, timestamp, and sequence number, etc.

[0050] like Figure 1 As shown, according to some embodiments of the present invention, the key dynamic generation and distribution system based on a one-way channel includes an intranet-side subsystem, a one-way transmission link 140, and an extranet-side subsystem.

[0051] The intranet-side subsystem includes: a key generation module 110, a key encapsulation and signing module 120, and a video transmission module 130.

[0052] The key generation module 110 dynamically generates the key body using a security algorithm and assigns it a key sequence number (KeyID) to form the original key data. In addition, it can also assign a version number to it.

[0053] According to some embodiments of the present invention, the module may consist of a Hardware Security Module (HSM) or a Trusted Execution Environment (TEE), and generate keys using algorithms such as AES, SM4, ECC, RSA, and SM9. The generation strategy can be configured to be triggered by time slices (e.g., every 10 seconds, every hour) or by specific security events.

[0054] The key encapsulation and signature module 120 receives raw key data from the key generation module 110 and encapsulates it to form a key packet. The encapsulation structure includes: a key sequence number, a checksum, a frame header, a timestamp, and a digital signature. The digital signature can be generated by signing the data using an internal network private key.

[0055] When a large number of terminals on the external network require different keys and update at different frequencies (e.g., terminal group 1 updates every 10 seconds, terminal group 2 every 20 seconds, terminal group 3 every 40 seconds; each group has 1000 hosts), if the video transmission module (e.g., an HDMI transmitter) sends a video frame containing a key to each terminal's password request via a unidirectional transmission link (e.g., an HDMI cable, an electro-optical converter connected to the HDMI cable, a unidirectional optical fiber, and an opto-optical converter to a unidirectional optical receiver), and each frame contains a key, based on the aforementioned number of terminals, 19,000 transmission operations would be required every 2 minutes, resulting in a huge overhead. Therefore, this application further proposes that the key encapsulation and signature module 120 is also used to concatenate and encapsulate the key packets (S1, S2, S3...) of multiple terminals into a single image frame.

[0056] According to some embodiments of the present invention, the module constructs an index table during encapsulation and places it in the frame header of the image frame. The index table records the identity serial number (such as MAC address, CPU ID, TPM chip ID) of each user terminal, as well as the starting offset and length of the terminal key in the image frame. The frame body structure then sequentially and closely arranges the key data of each user terminal.

[0057] After encapsulating an image frame, the module either sends it to the video transmission module or sends the encapsulated image frame at predetermined time intervals. Depending on the actual password update frequency of the user terminal, the module can choose to send the image frame immediately after encapsulation or send it periodically by setting a reasonable time interval, thus making full use of the gap between key transmission actions of a user terminal, which have a very low frequency.

[0058] Figure 2 A schematic diagram of an image frame structure containing a multi-terminal key is shown (at time t1) according to some embodiments of the present invention. Figure 3A schematic diagram of an image frame structure containing an updated multi-terminal key is shown (at time t2) according to some embodiments of the present invention. As shown, multiple key data located by an index table are closely arranged after the frame header.

[0059] The video transmission module 130 is connected to the key encapsulation and signature module 120 and is used to map the encapsulated key packets (including single key packets or multi-key aggregation packets) into video signals. This module can use video interface transmitters such as HDMI, DP, SDI, or LVDS. According to some embodiments of the present invention, this module directly carries key data using the pixel channels (RGB or YCbCr) of the video frame and outputs it to the unidirectional transmission link 140. This mapping method can greatly increase the data transmission bandwidth on the video line. Since the complex encapsulation and index table construction work has been completed in the previous module, this module is mainly responsible for physical layer signal conversion and transmission.

[0060] A unidirectional transmission link 140 is used to physically transmit signals unidirectionally from the intranet side to the extranet side. According to some embodiments of the present invention, this link may include: an electro-optical conversion unidirectional optical transmitter for converting electrical signals into optical signals; a unidirectional optical fiber; and an opto-optical conversion unidirectional optical receiver for converting optical signals back into electrical signals. This structure ensures that there is no physical path from the extranet to the intranet. In this application, the electro-optical conversion unidirectional optical transmitter can convert electrical signals into optical signals, but cannot convert optical signals into electrical signals; the opto-optical conversion unidirectional optical receiver can convert optical signals into electrical signals, but cannot convert electrical signals into optical signals. Depending on the actual situation, there may be a video cable (such as an HDMI cable) preceding the electro-optical conversion unidirectional optical transmitter for connecting the transmitter to the preceding component (such as a video transmission module) that transmits the electrical signals to it. Therefore, the unidirectional transmission link of the present invention also includes some necessary connecting lines. The unidirectional transmission link can also be any link that can realize physically unidirectional signal transmission, including but not limited to unidirectional serial cables.

[0061] The external network subsystem includes: a video receiving module 150, a key parsing and verification module 160, and an external network security proxy module 170.

[0062] The video receiving module 150 is used to receive video signals from a one-way transmission link and extract the original binary bit stream, i.e., the key packet, through decoding (such as HDMI decoding) and re-timing processing.

[0063] The key parsing and verification module 160 is used to verify the received key packet. The verification includes:

[0064] 1. Check digital signature: Use a pre-set public key to verify whether the data was sent from a trusted internal network and has not been tampered with;

[0065] 2. Check timestamps and key serial numbers: Discard expired or duplicate old key packets to prevent replay attacks;

[0066] 3. Check the checksum: Calculate the checksum of the data and compare it with the checksum in the packet to eliminate transmission errors.

[0067] In the aforementioned scenario where multiple user terminals' keys are combined and encapsulated into a single image frame, the key parsing and verification module 160 further parses the index table in the frame header to verify whether the identity sequence number matches the identity characteristics of each user terminal it is connected to. Upon successful verification, the module sends the key to the corresponding user terminal, or, in conjunction with an external network security proxy module, the external network security proxy module sends the key to the corresponding user terminal.

[0068] The external network security proxy module 170 is used to extract the valid key after the verification is passed and update it to the business system on the external network, replacing the original old key.

[0069] This invention also proposes a method for dynamic key generation and distribution based on a unidirectional channel. For example... Figure 4 As shown, the method includes the following steps S1 to S6:

[0070] S1. Dynamically generate the key body and assign it a key sequence number to form the original key data.

[0071] According to some embodiments of the present invention, the internal network HSM periodically (e.g., every 10 seconds) generates a new session key and signs the session key Sig(K) using the internal network root key.

[0072] According to some embodiments of the present invention, the key generation strategy supports "multi-version coexistence", that is, it allows two versions of the key to be valid at the same time during the transition period (e.g., within 5 seconds of switching between the old and new keys) to ensure that the service is not interrupted during the seamless switch.

[0073] S2. Receive the raw key data and encapsulate it into a key packet. The encapsulation structure includes a key sequence number, a checksum, a frame header, a timestamp, and a digital signature.

[0074] The key encapsulation and signature module 120 can perform this step.

[0075] In a multi-terminal distribution scenario, this step specifically includes: concatenating and encapsulating the keys of multiple user terminals into an image frame. When constructing this frame, a frame header containing an index table is generated. The index table records the identity sequence number of each user terminal and the starting offset and length of the key of that user terminal in the image frame; the frame body structure then sequentially arranges the keys of each user terminal.

[0076] S3. Map the encapsulated key packet to a video signal and output it to the unidirectional transmission link.

[0077] The video transmission module 130 can perform this step, converting the logical key data packet into a physical video signal.

[0078] S4. The external network receives video signals from the unidirectional transmission link, and extracts the key packet through decoding and re-timing processing.

[0079] The video receiving module 150 receives optical signals from the unidirectional transmission link, converts them into electrical signals, locks the video timing, and decodes the pixel data of each frame. This process is completely passive, without sending any ACK (acknowledgment character) or NACK (denial character) to the sending end.

[0080] S5. Verify the key packet.

[0081] The verification process includes checking the digital signature, timestamp, key serial number, and checksum.

[0082] Check digital signature: Use a pre-set public key to verify that the data was sent from a trusted internal network and has not been tampered with.

[0083] Check timestamps and key serial numbers to discard expired or duplicate old key packets.

[0084] Check the checksum to rule out transmission errors.

[0085] For multi-terminal aggregation frames, it is also necessary to verify whether the identity sequence number matches the identity characteristics of each user terminal it is connected to.

[0086] S6. After successful verification, extract the valid key and update it in the external business system, replacing the old key.

[0087] In multi-terminal scenarios, after successful verification, the key is sent to the corresponding user terminal based on the index table and identity serial number to complete the replacement.

[0088] The above steps can also be summarized from the preceding steps. Figure 1 The various modules described herein are used for execution and are applicable here; for the sake of simplicity, they will not be elaborated upon further.

[0089] Figure 5 This diagram illustrates a timing interaction diagram of one-way key distribution from an intranet to an extranet according to some embodiments of the present invention.

[0090] First, keys are dynamically generated at the intranet security center (i.e., the intranet side). New master keys or session keys K can be generated periodically according to preset security policies, such as time slices or event triggers.

[0091] Next, the generated key K is encapsulated. The encapsulation structure includes a key sequence number, a checksum, a frame header, a timestamp, and a digital signature (only a portion is shown in the figure).

[0092] After encapsulation, the encapsulated key packet is encoded and converted into image frames. At this point, the key data is mapped to a video signal and transmitted through a unidirectional transmission link, i.e., a unidirectional optical channel. This link uses an electro-optical conversion unidirectional optical transmitter to convert electrical signals into optical signals, which are then transmitted through a unidirectional optical fiber to a photoelectric conversion unidirectional optical receiver. Physically, there is no return circuit, ensuring absolutely unidirectional data flow. According to some embodiments of the present invention, this link includes an HDMI cable, an electro-optical conversion unidirectional optical transmitter connected to the HDMI cable, a unidirectional optical fiber, and a photoelectric conversion unidirectional optical receiver.

[0093] Subsequently, the optical signal travels unidirectionally to the external network encryption node, i.e., the receiving side or the external network side. The video receiving module receives image frames from the unidirectional transmission link and performs decoding and synchronization operations to restore the video signal into data packets. During this process, the receiving end only passively receives data and does not send any handshake signals or acknowledgment information (ACK), thus strictly maintaining physical isolation characteristics.

[0094] Next, the external network encryption node (such as the key parsing and verification module mentioned earlier) verifies the key packet. The verification includes checking the digital signature, timestamp, password sequence number, and checksum. The digital signature check includes using a preset external network public key to verify whether the data was sent from a trusted internal network and has not been tampered with; checking the timestamp and password sequence number to discard expired or duplicate old key packets; and checking the checksum to eliminate transmission errors (only part is shown in the figure).

[0095] Finally, once verification is successful, the external network security proxy module extracts the valid key and updates the local session key, replacing the old key. The entire process is as follows: Figure 5 As shown at the bottom, there is no backhaul signal or network handshake throughout the process, ensuring that the physical isolation security boundary is not compromised while the key is dynamically updated.

[0096] According to other embodiments of the present invention, the system also has the following extended features: Interface adaptability: The unidirectional transmission interface is not limited to HDMI, and can be replaced by DisplayPort (DP), SDI (Serial Digital Interface), or LVDS (Low-Voltage Differential Signaling) interface. These interfaces all have high bandwidth and unidirectional flow characteristics, making them suitable as physical unidirectional carriers.

[0097] According to other embodiments of the present invention, the system also features parallel distribution, i.e., it supports parallel distribution of multiple key channels. By using multiple unidirectional optical fibers or wavelength division multiplexing (WDM) technology, multiple parallel unidirectional channels can be constructed to serve different security zones or extremely large-scale node groups, thereby multiplying the key distribution throughput.

[0098] According to other embodiments of the present invention, the system also incorporates an AI (artificial intelligence) module to detect abnormal key packets and monitor link status. A lightweight AI model is introduced on the receiving side to analyze the noise distribution or error patterns of the received video frames. If a specific pattern of errors is detected (which may indicate a side-channel attack or link aging), the AI ​​module triggers a defense alarm on the external network side. Although it cannot notify the internal network, it can prompt the administrator to check the physical link.

[0099] The method and system for dynamic key generation and distribution based on a one-way channel provided by this invention have the following significant technical advantages compared with the prior art.

[0100] This invention creatively utilizes video interfaces and unidirectional transmission links as key carriers, breaking the traditional understanding that key distribution must rely on a two-way TCP / IP handshake. With the internal network (source side) acting as an absolutely unidirectional sender and the external network (receiving side) acting as an absolutely unidirectional receiver, the path for reverse communication or attacks from the external network to the internal network is completely severed at the physical layer, greatly enhancing the security of the internal network's core security domain.

[0101] Secondly, this invention eliminates the bottleneck of manual synchronization, enabling automated high-frequency updates. By mapping the key to a continuous video stream, the system can broadcast the latest key to the external network at a frequency of tens or even hundreds of times per second. This completely replaces the inefficient manual copying (USB flash drive) mode, making high-frequency dynamic key strategies of "one-time key" or "minute-level rotation" possible in physically isolated scenarios, significantly increasing the time cost for attackers to crack the key.

[0102] Furthermore, this invention also enables multi-terminal concurrency support and high bandwidth utilization. By utilizing the Gbps-level bandwidth of video interfaces (such as HDMI / DP), the multi-key aggregation frame structure proposed in this invention can simultaneously carry the keys of hundreds or thousands of terminals in a single video frame. Compared to traditional low-speed serial port unidirectional transmission, the key distribution throughput of this solution is increased by several orders of magnitude, which can meet the key synchronization requirements of large-scale cluster systems.

[0103] Finally, this invention provides a secure and reliable verification mechanism. Although it lacks a return confirmation, by introducing digital signatures, timestamps, key serial numbers, identity serial numbers, checksums, and intra-frame indexing mechanisms, the receiving end can independently verify the integrity, freshness, and ownership of the key, ensuring that tampering, forgery, and replay attacks can still be prevented even in a one-way "blind reception" environment.

[0104] It should be noted that, for ease of understanding, this application has broken down each step in the method and each module in the system in detail. However, those skilled in the art will understand that, depending on the actual implementation needs, each step and module can be further broken down or reorganized, and these are all within the scope of the present invention.

Claims

1. A key dynamic generation and distribution system based on a one-way channel, characterized in that: include: The key generation module, key encapsulation and signing module, and video transmission module are located on the intranet side; The video receiving module, key parsing and verification module, and external network security proxy module are located on the external network side; And a one-way transmission link located between the internal network side and the external network side; The key generation module is used to dynamically generate the key body and assign it a key sequence number to form the original key data; The key encapsulation and signature module is used to receive raw key data and encapsulate it into a key packet. The encapsulation structure includes a key sequence number, a checksum, a frame header, a timestamp, and a digital signature. The video transmission module is connected to the key encapsulation and signature module, which is used to map the encapsulated key packet into a video signal and output it to the unidirectional transmission link. A one-way transmission link is used to transmit video signals from the video transmitting module to the video receiving module; The video receiving module is used to receive video signals from a one-way transmission link and extract the key packet through decoding and re-timing processing; The key parsing and verification module is used to verify the received key packets. The verification includes checking the digital signature, timestamp, key serial number, and checksum. The digital signature check includes using a preset external public key to verify whether the data was sent from a trusted internal network and has not been tampered with; checking the timestamp and key serial number to discard expired or duplicate old key packets; and checking the checksum to eliminate transmission errors. The external network security proxy module is used to extract the valid key after the verification is passed, and update it to the external network business system, replacing the original old key; The key encapsulation and signature module is also used to concatenate and encapsulate the key packets of multiple user terminals into an image frame. The frame header of the image frame contains an index table, which records the identity serial number of each user terminal and the starting offset and length of the key of the user terminal in the image frame. The frame body structure arranges the keys of each user terminal in sequence. After encapsulating an image frame, it is sent to the video sending module or sent at predetermined time intervals. The key parsing and verification module is also used to verify whether the identity serial number matches the identity characteristics of each user terminal it is connected to, and to send the key to the corresponding user terminal after successful verification.

2. The system according to claim 1, wherein, The dynamically generated key can be triggered at predetermined time intervals or by predetermined security events.

3. The system according to claim 1, wherein, The video transmission module includes HDMI, DP, SDI, or LVDS video interface transmitters.

4. The system according to claim 1, wherein, The unidirectional transmission link includes: an electro-optical conversion unidirectional optical transmitter for converting electrical signals into optical signals; a unidirectional optical fiber; and an opto-optical conversion unidirectional optical receiver for converting optical signals back into electrical signals.

5. The system according to claim 1, wherein, The unidirectional transmission link includes an electro-optical conversion unidirectional optical transmitter for converting electrical signals into optical signals; multiple parallel unidirectional optical fibers; and each photoelectric conversion unidirectional optical receiver connected to each unidirectional optical fiber for converting optical signals back into electrical signals.

6. The system according to claim 1, wherein, The external network side includes an AI model, which is used to analyze the noise distribution or error patterns of received video frames. If a specific pattern of errors is found, the AI ​​module triggers a defense alarm on the external network side.

7. A method for dynamic key generation and distribution based on a one-way channel, characterized in that: This includes performing the following actions on the intranet side: Dynamically generate the key body and assign it a key sequence number to form the original key data; Receive raw key data and encapsulate it into a key packet. The encapsulation structure includes a key sequence number, a checksum, a frame header, a timestamp, and a digital signature. The encapsulated key packet is mapped into a video signal and output to a one-way transmission link; The video signal is transmitted from the intranet side to the extranet side via a one-way transmission link; Perform the following actions on the external network side: It receives video signals from a one-way transmission link, and extracts the key packet through decoding and re-timing processing; The key packet is verified, including checking the digital signature, timestamp, key serial number, and checksum. The digital signature check includes verifying whether the data was sent from a trusted internal network and has not been tampered with using a preset external public key; checking the timestamp and key serial number to discard expired or duplicate old key packets; and checking the checksum to eliminate transmission errors. After the verification is passed, the valid key is extracted and updated to the business system on the external network, replacing the original old key; Receiving raw key data and encapsulating it into a key packet includes: splicing and encapsulating the key packets of multiple user terminals into an image frame. The frame header of the image frame contains an index table, which records the identity serial number of each user terminal and the starting offset and length of the key of the user terminal in the image frame. The frame body structure arranges the keys of each user terminal in sequence. The method further includes verifying whether the identity serial number matches the identity characteristics of each user terminal it is connected to, and sending the key to the corresponding user terminal after successful verification.

8. The method according to claim 7, wherein, The dynamically generated key can be triggered at predetermined time intervals or by predetermined security events.