Cloud gateway routing system for isolating private network service from public network service of smart television

By using a cloud gateway routing system that isolates the smart TV private network from public network services, efficient, secure, and stable traffic transmission is achieved. This solves the traffic management and network security issues of smart TV devices in existing technologies, and improves user experience and network operation efficiency.

CN121508938APending Publication Date: 2026-02-10BEIJING LIUJINSUIYUE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511617034.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-06
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

Existing routing systems are unable to meet the diverse traffic demands of smart TV devices, resulting in issues such as high latency, untimely path switching, and a high risk of privacy information leakage, and they lack dynamic self-healing capabilities.

Method used

By employing a routing hierarchical rotation module, a fingerprint hierarchical distribution module, a dual-path switching control module, and a self-healing control module, and through hierarchical traffic management, dual-path parallel transmission, and an adaptive rollback mechanism, the system achieves efficient isolation and secure transmission of smart TV private network and public network services.

Benefits of technology

Ensure that important and sensitive traffic is transmitted through a dedicated network to reduce the risk of external threats, guarantee traffic continuity and network stability, enhance self-healing capabilities, protect user privacy and data compliance, and optimize the utilization of network resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121508938A_ABST
    Figure CN121508938A_ABST
Patent Text Reader

Abstract

The invention discloses a cloud gateway routing system for isolating private network and public network services of a smart television, which relates to the technical field of network security and routing and specifically comprises the following modules: a routing grading rotation module, a fingerprint grading issuing module, a two-way switching control module, a self-repairing control module and a self-adaptive rollback module. The method comprises the following steps: dividing flow generated by a smart television into three grade groups, establishing a baseline threshold, key management and rotation mechanism, collecting and extracting fingerprint features, mapping grade groups through a decision tree, inputting a grading result into a strategy issuing unit to generate a routing strategy template of each grade, and sending the routing strategy template to a database; the input real-time link state, time delay, bandwidth, congestion and session sensitivity are used for cost function sorting, flow cache is realized in the switching process to ensure sequence and double-path parallel transmission, and after a new link is stable, an old path is stopped immediately and resources are released, so that the switching efficiency is improved. And when a new anomaly is caused by the self-repairing strategy, fast rollback to the last stable state is realized, and the reason is recorded.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security and routing technology, specifically to a cloud gateway routing system that isolates private networks and public network services for smart TVs. Background Technology

[0002] With the increasing prevalence of smart TVs in home entertainment, the interaction between more and more smart devices and the traditional internet and dedicated networks has become an inevitable trend. Smart TVs typically need to transmit large amounts of video streams, audio streams, and other types of data. The security, transmission efficiency, and network resource consumption of this data have become important factors affecting user experience and network operating efficiency.

[0003] The existing technology has the following shortcomings:

[0004] Existing routing systems are relatively simple in terms of traffic classification and priority management, making it difficult to meet the differentiated traffic needs of smart TVs and other devices.

[0005] Secondly, traditional network switching mechanisms often suffer from high latency and untimely path switching, leading to frequent issues such as packet loss and session interruption.

[0006] Existing protection mechanisms often lack the ability to dynamically self-heal from abnormal network behavior, making it difficult to respond quickly and roll back to a stable state in complex network environments.

[0007] In cross-domain data transmission, the risk of privacy information leakage is relatively high.

[0008] The above problems limit the application of existing technologies in terminal devices such as smart TVs, and there is an urgent need for a routing system that is more intelligent, dynamically adjustable, and highly secure.

[0009] The information disclosed in the background section is only intended to enhance the understanding of the background of this disclosure, and therefore may include information that does not constitute prior art known to those skilled in the art. Summary of the Invention

[0010] The purpose of this invention is to provide a cloud gateway routing system that isolates smart TV private networks from public network services, in order to solve the problems mentioned in the background art.

[0011] To achieve the above objectives, the present invention provides the following technical solution: a cloud gateway routing system that isolates smart TV private networks from public network services, specifically including the following modules: a routing hierarchical rotation module, a fingerprint hierarchical distribution module, a dual-path switching control module, a self-repair control module, and an adaptive rollback module;

[0012] Routing hierarchical rotation module: Divides the traffic generated by the smart TV into three levels of groups, deploys core components on the cloud gateway and edge gateway, establishes baseline thresholds to realize abnormal alarms, assigns a unique device certificate to the smart TV, and establishes a key management and rotation mechanism;

[0013] Fingerprint hierarchical distribution module: Collects and extracts fingerprint features, maps hierarchical groups through decision tree, inputs the hierarchical results into the policy distribution unit to generate routing policy templates for each level, and realizes efficient traffic splitting between smart TV private network and public network services;

[0014] Dual-path switching control module: By using the input real-time link status, latency, bandwidth, congestion, and session sensitivity as a cost function for sorting, it achieves traffic buffering to ensure order, parallel transmission of dual paths, and immediate stopping of the old path and release of resources after the new link stabilizes during the switching process;

[0015] Self-healing control module: It detects consistency after switching by modeling baseline normal behavior, rapid collaborative switching between private network and public network and edge localization processing, and realizes rapid rollback to the previous stable state and records the cause when the self-healing strategy causes new anomalies;

[0016] The adaptive rollback module is divided into five risk groups to achieve fingerprint and context fusion to reduce false positives, unified session identification and short-term parallel transmission to reduce packet loss, distributed consistency and auditable logs to maintain cross-domain consistency, multi-level approval and rollback paths for self-healing, and edge localization processing and de-identification aggregation.

[0017] As a preferred embodiment of the cloud gateway routing system for isolating private networks and public network services in smart TVs as described in this invention, wherein:

[0018] Define different tiered groupings of data traffic based on cloud gateway routing, specifically including:

[0019] Level G1: For traffic with high sensitivity requirements, it can only be transmitted through a private network and can only enter through a dedicated line. External access points are forcibly controlled, end-to-end encryption is used and the latest version of the encryption protocol is forcibly enabled. All data streams are monitored in real time, and all access requests and operation behaviors are recorded.

[0020] Level G2: For traffic with high sensitivity requirements, a private network is selected for transmission under specific conditions, and additional authentication, traffic monitoring, and data protection are enforced.

[0021] Level G3: For traffic with low sensitivity requirements, directly select public network transmission and choose encryption and auditing measures based on the minimum security guarantee;

[0022] For each level, define the corresponding allowed entry points and paths;

[0023] Deploy core components in cloud gateways and edge gateways;

[0024] The core components specifically include:

[0025] A cloud gateway that serves as the interface between the private network and the public network;

[0026] Routers and switches used to forward and isolate traffic according to routing policies;

[0027] A firewall used to monitor and control traffic entering or leaving the network;

[0028] A load balancer used to distribute traffic across multiple servers or network paths;

[0029] Set up a monitoring center and establish baseline thresholds for link status, latency, jitter, and packet loss;

[0030] The baseline thresholds for link status are: active state, latency is 50ms, jitter is 10ms, and packet loss is 1%.

[0031] Assign a unique device certificate to the smart TV and establish a key management and rotation mechanism;

[0032] The rotation mechanism specifically includes: randomly selecting n links, with the number of selections within a preset range, and ensuring that the links selected in each round are different and the similarity is less than a threshold a;

[0033] Based on the results of n rounds of selection, obtain the connection status of m current network devices in the n rounds of selection results;

[0034] Construct a stable coordinate system by using the connection performance of m current network devices as the y-axis, the number of selections as the x-axis, and the latency as the z-axis;

[0035] The stability coefficient is calculated by weighting the slope of the equations in the stable coordinate system, and the link with the largest stability coefficient is selected as the optimal rotation result.

[0036] Establish a secure startup and integrity self-check process for smart TV agents.

[0037] As a preferred embodiment of the cloud gateway routing system for isolating private networks and public network services in smart TVs as described in this invention, wherein:

[0038] Collect packet intervals, packet length distribution, traffic burst patterns, session duration, application identifiers, and port and protocol characteristics, and extract fingerprint features locally in a lightweight manner;

[0039] Establish a multimodal, low-latency hierarchical model, interface it with a dynamic triage decision-maker, and output hierarchical labels and a set of optional exits;

[0040] The hierarchical model maps real-time fingerprint features to the aforementioned hierarchical groups via a decision tree; auxiliary rules are added to perform multi-condition judgments based on thresholds.

[0041] The hierarchical results are used as input to link the policy distribution unit and define the routing policy template for each level.

[0042] As a preferred embodiment of the cloud gateway routing system for isolating private networks and public network services in smart TVs as described in this invention, wherein:

[0043] The dynamic splitter inputs tiered results, real-time link status, latency, bandwidth, congestion status, and session sensitivity.

[0044] The decision objectives are defined in hierarchical order based on the cost function as: security constraints, latency constraints, bandwidth utilization constraints, and switching overhead control constraints.

[0045] During the handover process, the order of data packets is maintained through traffic caching;

[0046] When switching paths, a dual-path parallel transmission strategy is adopted, which allows data packets on the old path to still be transmitted when a new path is established.

[0047] Once the new link has completed data transmission and is stable, traffic on the old path should stop immediately, and the resources of the old path should be released.

[0048] The switchover process is divided into four stages, specifically including:

[0049] The warm-up phase is used to initialize the new path and begin packet buffering;

[0050] The switching initiation phase is used to redirect traffic to the new link after a new path has been selected.

[0051] The handover execution phase is used to actually switch traffic when it is transmitted on the new link and the old link stops.

[0052] This is the final stage used to release old path resources, update routing tables, and perform cleanup work.

[0053] As a preferred embodiment of the cloud gateway routing system for isolating private networks and public network services in smart TVs as described in this invention, wherein:

[0054] Establish a baseline normal behavior model, define the feature set of attacks and anomalies, and link the self-healing module for rapid judgment;

[0055] Enables rapid collaborative switching between private and public networks within the same gateway, and notifies edge nodes to perform localized processing and cache optimization;

[0056] By establishing a unified session identifier and state snapshot mechanism, the consistency of session state, flow table entries, and security context after switching can be detected.

[0057] If the self-healing strategy causes a new anomaly, quickly roll back to the previous stable state and record the reason.

[0058] As a preferred embodiment of the cloud gateway routing system for isolating private networks and public network services in smart TVs as described in this invention, wherein:

[0059] Different risk groups and corresponding response strategies are set up, specifically including:

[0060] Risk 1: Fingerprint recognition misjudgment may lead to unnecessary switching or increased exposure.

[0061] Response strategies:

[0062] By fusing application fingerprints, traffic statistics features, time context, and device context, the probability of misjudgment based on a single feature is reduced.

[0063] When the security level boundaries are unclear, prioritize the path with the higher security level and set a soft handover threshold;

[0064] In high-risk scenarios, a manual review entry point is introduced to support rapid rollback to the previous stable state;

[0065] Risk 2: Session errors and packet loss during seamless handover

[0066] Response strategies:

[0067] Each session is bound to a unique identifier, and the binding relationship between the old and new paths is checked during switching, which can be repeated.

[0068] Allow short-term parallel transmission before and after handover, and increase buffering;

[0069] Real-time monitoring of end-to-end latency and jitter before and after the switchover, triggering rollback or degradation strategies when thresholds are exceeded;

[0070] Risk 3: Cross-domain consistency is difficult to guarantee

[0071] Response strategies:

[0072] A simplified implementation of synchronizing critical states in snapshot form is achieved through a distributed consensus algorithm;

[0073] All cross-domain operations generate non-repudiable logs;

[0074] Risk 4: The self-healing strategy is triggered incorrectly, causing new network anomalies.

[0075] Response strategies:

[0076] Set thresholds for triggering self-repair actions and establish a multi-level approval mechanism;

[0077] Retain the rollback path after each self-repair;

[0078] The path is stratified into health scores, and switching only occurs when the overall score meets the threshold.

[0079] Risk 5: Pressure to protect privacy and comply with data regulations

[0080] Response strategies:

[0081] Data processing and feature extraction are performed at edge nodes to reduce the transmission of sensitive information to the cloud.

[0082] The collected data is anonymized and aggregated before being sent, and the transmission of identifiable information is controlled.

[0083] On the other hand, the present invention provides a computer device, including a memory and a processor, wherein the memory stores a computer program, wherein when the computer program is executed by the processor, it implements the steps of a cloud gateway routing system for isolating smart TV private networks and public network services as described above.

[0084] On the other hand, the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program is executed by a processor, it implements the steps of a cloud gateway routing system for isolating smart TV private networks and public network services as described above.

[0085] The technical effects and advantages provided by the present invention in the above technical solution are as follows:

[0086] (1) By using hierarchical routing and fingerprint-based hierarchical distribution, traffic can be scheduled in real time based on its sensitivity and network status, ensuring that important and sensitive traffic is always transmitted through the private network, thus reducing the risk of external threats. This hierarchical mechanism ensures that highly sensitive traffic is not exposed to the public network, maximizing security.

[0087] (2) Ensure the continuity of traffic during network handover by using parallel transmission and caching mechanisms to ensure the order and stability of data. Even if there are problems with the link, data can be prevented from being lost through parallel paths, while ensuring a smooth transition during handover and avoiding session errors and packet loss.

[0088] (3) By using baseline behavior model, anomaly detection and fast rollback mechanism, the system can automatically recover to a stable state when new anomalies or problems occur, thereby enhancing the system’s self-healing ability and ensuring the stability of network operation.

[0089] (4) Data processing and fingerprint extraction are performed at edge nodes to reduce the transmission of sensitive information to the cloud, effectively protecting user privacy and data compliance. Sensitive data is sent after being processed using de-identification and aggregation technologies, improving data security and privacy protection levels.

[0090] (5) Make intelligent decisions based on real-time traffic and link status to ensure data priority and reasonable traffic allocation. This efficient traffic offloading mechanism helps optimize network resource utilization, reduce network congestion, and improve user experience. Attached Figure Description

[0091] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this invention. For those skilled in the art, other drawings can be obtained based on these drawings.

[0092] Figure 1 This is a flowchart of a cloud gateway routing system for isolating private networks and public network services for smart TVs, according to the present invention.

[0093] Figure 2 This is a schematic diagram of a cloud gateway routing system for isolating private networks and public network services for smart TVs, as described in this invention. Detailed Implementation

[0094] Exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, these exemplary embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; rather, they are provided so that the description of this disclosure will be more complete and fully convey the concept of the exemplary embodiments to those skilled in the art.

[0095] Example 1, referring to Figure 1 and Figure 2 This is the first embodiment of the present invention. This embodiment provides a cloud gateway routing system that isolates the private network of a smart TV from public network services. Specifically, it includes the following modules: a routing hierarchical rotation module, a fingerprint hierarchical distribution module, a dual-path switching control module, a self-repair control module, and an adaptive rollback module.

[0096] Routing hierarchical rotation module: Divides the traffic generated by the smart TV into three levels of groups, deploys core components on the cloud gateway and edge gateway, establishes baseline thresholds to realize abnormal alarms, assigns a unique device certificate to the smart TV, and establishes a key management and rotation mechanism;

[0097] Define different tiered groupings of data traffic based on cloud gateway routing, specifically including:

[0098] Level G1: For traffic with high sensitivity requirements, it can only be transmitted through a private network and can only enter through a dedicated line. External access points are forcibly controlled, end-to-end encryption is used and the latest version of the encryption protocol is forcibly enabled. All data streams are monitored in real time, and all access requests and operation behaviors are recorded.

[0099] Level G2: For traffic with high sensitivity requirements, a private network is selected for transmission under specific conditions, and additional authentication, traffic monitoring, and data protection are enforced.

[0100] Level G3: For traffic with low sensitivity requirements, directly select public network transmission and choose encryption and auditing measures based on the minimum security guarantee;

[0101] For each level, define the corresponding allowed entry points and paths;

[0102] Deploy core components in cloud gateways and edge gateways;

[0103] The core components specifically include:

[0104] A cloud gateway that serves as the interface between the private network and the public network;

[0105] Routers and switches used to forward and isolate traffic according to routing policies;

[0106] A firewall used to monitor and control traffic entering or leaving the network;

[0107] A load balancer used to distribute traffic across multiple servers or network paths;

[0108] Set up a monitoring center and establish baseline thresholds for link status, latency, jitter, and packet loss;

[0109] The baseline thresholds for link status are: active state, latency is 50ms, jitter is 10ms, and packet loss is 1%.

[0110] It should also be noted that the link status refers to the health of the connection between devices in the network, which is represented by activity or failure. The baseline threshold of the link status is intended to determine whether the link is working properly. If the link fails at any time, an alarm will be triggered directly.

[0111] The latency is the time required for data to be transmitted from the source node to the target node, and the baseline threshold of the latency is used to determine the network response speed.

[0112] The jitter refers to the degree of fluctuation in network latency, representing the latency variation between different data packets;

[0113] The packet loss rate is the ratio of data packets lost during network transmission to the total number of data packets sent.

[0114] Assign a unique device certificate to the smart TV and establish a key management and rotation mechanism;

[0115] The rotation mechanism specifically includes: randomly selecting n links, with the number of selections within a preset range, and ensuring that the links selected in each round are different and the similarity is less than a threshold a;

[0116] Based on the results of n rounds of selection, obtain the connection status of m current network devices in the n rounds of selection results;

[0117] Construct a stable coordinate system by using the connection performance of m current network devices as the y-axis, the number of selections as the x-axis, and the latency as the z-axis;

[0118] The stability coefficient is calculated by weighting the slope of the equations in the stable coordinate system, and the link with the largest stability coefficient is selected as the optimal rotation result.

[0119] Establish a secure startup and integrity self-check process for smart TV agents.

[0120] Fingerprint hierarchical distribution module: Collects and extracts fingerprint features, maps hierarchical groups through decision tree, inputs the hierarchical results into the policy distribution unit to generate routing policy templates for each level, and realizes efficient traffic splitting between smart TV private network and public network services;

[0121] Collect packet intervals, packet length distribution, traffic burst patterns, session duration, application identifiers, and port and protocol characteristics, and extract fingerprint features locally in a lightweight manner;

[0122] Establish a multimodal, low-latency hierarchical model, interface it with a dynamic triage decision-maker, and output hierarchical labels and a set of optional exits;

[0123] The hierarchical model maps real-time fingerprint features to the aforementioned hierarchical groups via a decision tree; auxiliary rules are added to perform multi-condition judgments based on thresholds.

[0124] The hierarchical results are used as input to link the policy distribution unit and define the routing policy template for each level.

[0125] Dual-path switching control module: By using the input real-time link status, latency, bandwidth, congestion, and session sensitivity as a cost function for sorting, it achieves traffic buffering to ensure order, parallel transmission of dual paths, and immediate stopping of the old path and release of resources after the new link stabilizes during the switching process;

[0126] The dynamic splitter inputs tiered results, real-time link status, latency, bandwidth, congestion status, and session sensitivity.

[0127] The decision objectives are defined in hierarchical order based on the cost function as: security constraints, latency constraints, bandwidth utilization constraints, and switching overhead control constraints.

[0128] It should also be noted that security constraints ensure the security of traffic, such as preventing packet loss and erroneous forwarding. Security constraints typically take precedence over other constraints to guarantee the correctness and integrity of traffic.

[0129] Latency Constraint: Low latency is a critical requirement in network traffic management, especially for real-time applications such as video conferencing and online gaming. This constraint ensures that traffic transmission latency remains within acceptable limits.

[0130] Bandwidth utilization constraints: This refers to how to efficiently utilize network bandwidth, minimize bandwidth waste, and ensure that the bandwidth of each link is fully utilized. Effective bandwidth utilization is particularly important for high-traffic networks.

[0131] Switching overhead control constraints: Switching traffic may incur additional overhead, such as retransmissions, packet loss, and route updates. Therefore, it is necessary to control switching overhead, minimize switching frequency, and avoid negatively impacting user experience.

[0132] During the handover process, the order of data packets is maintained through traffic caching;

[0133] When switching paths, a dual-path parallel transmission strategy is adopted, which allows data packets on the old path to still be transmitted when a new path is established.

[0134] Once the new link has completed data transmission and is stable, traffic on the old path should stop immediately, and the resources of the old path should be released.

[0135] The switchover process is divided into four stages, specifically including:

[0136] The warm-up phase is used to initialize the new path and begin packet buffering;

[0137] The switching initiation phase is used to redirect traffic to the new link after a new path has been selected.

[0138] The handover execution phase is used to actually switch traffic when it is transmitted on the new link and the old link stops.

[0139] This is the final stage used to release old path resources, update routing tables, and perform cleanup work.

[0140] Self-healing control module: It detects consistency after switching by modeling baseline normal behavior, rapid collaborative switching between private network and public network and edge localization processing, and realizes rapid rollback to the previous stable state and records the cause when the self-healing strategy causes new anomalies;

[0141] Establish a baseline normal behavior model, define the feature set of attacks and anomalies (such as abnormal traffic patterns, abnormal path jitter, and abnormal packet loss rate), and link the self-healing module for rapid judgment.

[0142] Enables rapid collaborative switching between private and public networks within the same gateway, and notifies edge nodes to perform localized processing and cache optimization;

[0143] By establishing a unified session identifier and state snapshot mechanism, the consistency of session state, flow table entries, and security context after switching can be detected.

[0144] If the self-healing strategy causes a new anomaly, quickly roll back to the previous stable state and record the reason.

[0145] Adaptive rollback module: Divided into five risk groups to respectively implement fingerprint and context fusion to reduce false judgments, unified session identification and short-term parallel transmission to reduce packet loss, distributed consistency and auditable logs to maintain cross-domain consistency, set multi-level approval and rollback paths for self-repair, and edge localization processing and de-identification aggregation;

[0146] Different risk groups and corresponding response strategies are set up, specifically including:

[0147] Risk 1: Fingerprint recognition misjudgment may lead to unnecessary switching or increased exposure.

[0148] Response strategies:

[0149] By fusing application fingerprints, traffic statistics features, time context, and device context, the probability of misjudgment based on a single feature is reduced.

[0150] When the security level boundaries are unclear, prioritize the path with the higher security level and set a soft handover threshold;

[0151] In high-risk scenarios, a manual review entry point is introduced to support rapid rollback to the previous stable state;

[0152] Risk 2: Session errors and packet loss during seamless handover

[0153] Response strategies:

[0154] Each session is bound to a unique identifier, and the binding relationship between the old and new paths is checked during switching, which can be repeated.

[0155] Allow short-term parallel transmission before and after handover, and increase buffering;

[0156] Real-time monitoring of end-to-end latency and jitter before and after the switchover, triggering rollback or degradation strategies when thresholds are exceeded;

[0157] Risk 3: Cross-domain consistency is difficult to guarantee

[0158] Response strategies:

[0159] A simplified implementation of synchronizing critical states in snapshot form is achieved through a distributed consensus algorithm;

[0160] All cross-domain operations generate non-repudiable logs;

[0161] Risk 4: The self-healing strategy is triggered incorrectly, causing new network anomalies.

[0162] Response strategies:

[0163] Set thresholds for triggering self-repair actions and establish a multi-level approval mechanism;

[0164] Retain the rollback path after each self-repair;

[0165] The path is stratified into health scores, and switching only occurs when the overall score meets the threshold.

[0166] Risk 5: Pressure to protect privacy and comply with data regulations

[0167] Response strategies:

[0168] Data processing and feature extraction are performed at edge nodes to reduce the transmission of sensitive information to the cloud.

[0169] The collected data is anonymized and aggregated before being sent, and the transmission of identifiable information is controlled.

[0170] By employing hierarchical routing and fingerprint-based hierarchical distribution, traffic can be scheduled in real time based on its sensitivity and network status. This ensures that important and sensitive traffic is always transmitted through a dedicated network, reducing the risk of external threats. This hierarchical mechanism guarantees that highly sensitive traffic is not exposed to the public network, maximizing security.

[0171] To ensure traffic continuity during network handover, parallel transmission and caching mechanisms are used to guarantee data order and stability. Even in the event of link problems, parallel paths ensure no data loss, while also ensuring a smooth handover transition and avoiding session corruption and packet loss.

[0172] By employing baseline behavior models, anomaly detection, and rapid rollback mechanisms, the system automatically recovers to a stable state when new anomalies or problems occur, enhancing its self-healing capabilities and ensuring network stability.

[0173] Data processing and fingerprint extraction are performed at edge nodes, reducing the transmission of sensitive information to the cloud and effectively protecting user privacy and data compliance. Sensitive data is processed using anonymization and aggregation technologies before being sent, improving data security and privacy protection.

[0174] Intelligent decision-making based on real-time traffic and link status ensures data prioritization and rational traffic allocation. This efficient traffic offloading mechanism helps optimize network resource utilization, reduce network congestion, and improve user experience.

[0175] The foregoing has only described certain exemplary embodiments of the present invention by way of illustration. Undoubtedly, those skilled in the art can modify the described embodiments in various ways without departing from the spirit and scope of the present invention. Therefore, the foregoing drawings and descriptions are illustrative in nature and should not be construed as limiting the scope of protection of the claims of the present invention.

Claims

1. A cloud gateway routing system that isolates private networks and public network services for smart TVs, characterized in that, Specifically, it includes the following modules: routing hierarchical rotation module, fingerprint hierarchical distribution module, dual-path switching control module, self-repair control module, and adaptive rollback module; Routing hierarchical rotation module: Divides the traffic generated by the smart TV into three levels of groups, deploys core components on the cloud gateway and edge gateway, establishes baseline thresholds to realize abnormal alarms, assigns a unique device certificate to the smart TV, and establishes a key management and rotation mechanism; Fingerprint hierarchical distribution module: Collects and extracts fingerprint features, maps hierarchical groups through decision tree, inputs the hierarchical results into the policy distribution unit to generate routing policy templates for each level, and realizes efficient traffic splitting between smart TV private network and public network services; Dual-path switching control module: By using the input real-time link status, latency, bandwidth, congestion, and session sensitivity as a cost function for sorting, it achieves traffic buffering to ensure order, parallel transmission of dual paths, and immediate stopping of the old path and release of resources after the new link stabilizes during the switching process; Self-healing control module: It detects consistency after switching by modeling baseline normal behavior, rapid collaborative switching between private network and public network and edge localization processing, and realizes rapid rollback to the previous stable state and records the cause when the self-healing strategy causes new anomalies; The adaptive rollback module is divided into five risk groups to achieve fingerprint and context fusion to reduce false positives, unified session identification and short-term parallel transmission to reduce packet loss, distributed consistency and auditable logs to maintain cross-domain consistency, multi-level approval and rollback paths for self-healing, and edge localization processing and de-identification aggregation.

2. The cloud gateway routing system for isolating private networks and public network services for smart TVs according to claim 1, characterized in that: Define different tiered groupings of data traffic based on cloud gateway routing, specifically including: Level G1: For traffic with high sensitivity requirements, it can only be transmitted through a private network and can only enter through a dedicated line. External access points are forcibly controlled, end-to-end encryption is used and the latest version of the encryption protocol is forcibly enabled. All data streams are monitored in real time, and all access requests and operation behaviors are recorded. Level G2: For traffic with high sensitivity requirements, a private network is selected for transmission under specific conditions, and additional authentication, traffic monitoring, and data protection are enforced. Level G3: For traffic with low sensitivity requirements, directly select public network transmission and choose encryption and auditing measures based on the minimum security guarantee; For each level, define the corresponding allowed entry points and paths; Deploy core components in cloud gateways and edge gateways; Set up a monitoring center and establish baseline thresholds for link status, latency, jitter, and packet loss; The baseline thresholds for link status are: active state, latency is 50ms, jitter is 10ms, and packet loss is 1%. Assign a unique device certificate to the smart TV and establish a key management and rotation mechanism; The rotation mechanism specifically includes: randomly selecting n links, with the number of selections within a preset range, and ensuring that the links selected in each round are different and the similarity is less than a threshold a; Based on the results of n rounds of selection, obtain the connection status of m current network devices in the n rounds of selection results; Construct a stable coordinate system by using the connection performance of m current network devices as the y-axis, the number of selections as the x-axis, and the latency as the z-axis; The stability coefficient is calculated by weighting the slope of the equations in the stable coordinate system, and the link with the largest stability coefficient is selected as the optimal rotation result. Establish a secure startup and integrity self-check process for smart TV agents.

3. The cloud gateway routing system for isolating private networks and public network services for smart TVs according to claim 1, characterized in that: Collect packet intervals, packet length distribution, traffic burst patterns, session duration, application identifiers, and port and protocol characteristics, and extract fingerprint features locally in a lightweight manner; Establish a multimodal, low-latency hierarchical model, interface it with a dynamic triage decision-maker, and output hierarchical labels and a set of optional exits; The hierarchical model maps real-time fingerprint features to the aforementioned hierarchical groups via a decision tree; auxiliary rules are added to perform multi-condition judgments based on thresholds. The hierarchical results are used as input to link the policy distribution unit and define the routing policy template for each level.

4. The cloud gateway routing system for isolating private networks and public network services for smart TVs according to claim 1, characterized in that: The dynamic splitter inputs tiered results, real-time link status, latency, bandwidth, congestion status, and session sensitivity. The decision objectives are defined in hierarchical order based on the cost function as: security constraints, latency constraints, bandwidth utilization constraints, and switching overhead control constraints. During the handover process, the order of data packets is maintained through traffic caching; When switching paths, a dual-path parallel transmission strategy is adopted, which allows data packets on the old path to still be transmitted when a new path is established. Once the new link has completed data transmission and is stable, traffic on the old path should stop immediately, and the resources of the old path should be released. The switchover process is divided into four stages, specifically including: The warm-up phase is used to initialize the new path and begin packet buffering; The switching initiation phase is used to redirect traffic to the new link after a new path has been selected. The handover execution phase is used to actually switch traffic when it is transmitted on the new link and the old link stops. This is the final stage used to release old path resources, update routing tables, and perform cleanup work.

5. The cloud gateway routing system for isolating private and public network services for smart TVs according to claim 1, characterized in that: Establish a baseline normal behavior model, define the feature set of attacks and anomalies, and link the self-healing module for rapid judgment; Enables rapid collaborative switching between private and public networks within the same gateway, and notifies edge nodes to perform localized processing and cache optimization; By establishing a unified session identifier and state snapshot mechanism, the consistency of session state, flow table entries, and security context after switching can be detected. If the self-healing strategy causes a new anomaly, quickly roll back to the previous stable state and record the reason.

6. The cloud gateway routing system for isolating private and public network services for smart TVs according to claim 1, characterized in that: Different risk groups and corresponding response strategies are set up, specifically including: Risk 1: Fingerprint recognition misjudgment may lead to unnecessary switching or increased exposure. Response strategies: By fusing application fingerprints, traffic statistics features, time context, and device context, the probability of misjudgment based on a single feature is reduced. When the security level boundaries are unclear, prioritize the path with the higher security level and set a soft handover threshold; In high-risk scenarios, a manual review entry point is introduced to support rapid rollback to the previous stable state; Risk 2: Session errors and packet loss during seamless handover Response strategies: Each session is bound to a unique identifier, and the binding relationship between the old and new paths is checked during switching, which can be repeated. Allow short-term parallel transmission before and after handover, and increase buffering; Real-time monitoring of end-to-end latency and jitter before and after the switchover, triggering rollback or degradation strategies when thresholds are exceeded; Risk 3: Cross-domain consistency is difficult to guarantee Response strategies: A simplified implementation of synchronizing critical states in snapshot form is achieved through a distributed consensus algorithm; All cross-domain operations generate non-repudiable logs; Risk 4: The self-healing strategy is triggered incorrectly, causing new network anomalies. Response strategies: Set thresholds for triggering self-repair actions and establish a multi-level approval mechanism; Retain the rollback path after each self-repair; The path is stratified into health scores, and switching only occurs when the overall score meets the threshold. Risk 5: Pressure to protect privacy and comply with data regulations Response strategies: Data processing and feature extraction are performed at edge nodes to reduce the transmission of sensitive information to the cloud. The collected data is anonymized and aggregated before being sent, and the transmission of identifiable information is controlled.

7. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, it implements a module of a cloud gateway routing system for isolating private and public network services of a smart TV, as described in any one of claims 1 to 6.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, it implements a module of a cloud gateway routing system for isolating private networks and public network services for smart TVs, as described in any one of claims 1 to 6.