Camera security and secrecy reinforcing module and method
The camera security and confidentiality reinforcement module, which employs hardware-level identity authentication and dynamic physical watermarking technology, solves the security protection problem of video surveillance systems, and achieves end-to-end encryption and tamper detection. It is suitable for confidential scenarios such as public security, finance, and government affairs.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- TOEC (GRP) CO LTD
- Filing Date
- 2026-02-03
- Publication Date
- 2026-04-24
AI Technical Summary
Existing video surveillance systems suffer from problems such as plaintext transmission of video data which is easily intercepted and tampered with, lack of reliable mechanisms for device authentication, and difficulty in verifying the authenticity of video, making it difficult to meet the high security requirements of confidential scenarios.
The camera security and confidentiality reinforcement module includes a physical trusted root unit, a dynamic multi-dimensional watermark engine, an adaptive encryption array, and a key management submodule. It achieves full-link security protection through hardware-level identity authentication, dynamic physical watermarking, and adaptive encryption.
It achieves end-to-end security protection for video acquisition, transmission, and verification, improves encryption speed and tamper detection accuracy, supports real-time encrypted transmission of high-definition video, and has high security and compatibility.
Smart Images

Figure CN121924320A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of video surveillance security technology, specifically to a security and confidentiality reinforcement module and method for cameras. Background Technology
[0002] With the advancement of projects such as "smart cities" and "safe cities," cameras have been widely deployed in key areas such as public security, finance, and government affairs, forming a video surveillance network covering urban and rural areas. However, existing video surveillance systems generally have security flaws: video data is mostly transmitted in plaintext, making it easy to intercept and tamper with; devices lack reliable identity authentication mechanisms, allowing unauthorized devices to access them at will; and the authenticity of videos is difficult to verify, with deepfake technology further exacerbating security risks.
[0003] In existing technologies, video security cryptography modules mostly employ a single encryption algorithm for data protection, such as using the SM4 algorithm for video encryption. However, this suffers from a mismatch between encryption speed and video resolution, leading to latency issues during the transmission of high-definition videos such as 4K. Some solutions use digital watermarking technology to ensure video authenticity, but these are mostly software-embedded methods, making them vulnerable to cracking and unable to be linked to device identity. Other solutions use key management systems for key distribution, but lack hardware-level trusted root support, leaving identity authentication at risk of forgery. None of these technologies address the end-to-end security challenges of identity trust, data encryption, and tamper traceability, making it difficult to meet the high security requirements of confidential scenarios. Summary of the Invention
[0004] (a) Technical problems to be solved To address the shortcomings of existing technologies, this invention provides a camera security and confidentiality reinforcement module and method, which solves the problems mentioned in the background technology, achieves full-link security protection for video acquisition, transmission, and verification, and improves encryption speed and tamper detection accuracy.
[0005] (II) Technical Solution To achieve the above objectives, the present invention provides the following technical solution: a camera security and confidentiality reinforcement module, comprising a physical trusted root unit, a dynamic multi-dimensional watermark engine, an adaptive encryption array, a key management submodule, and a device authentication interface; The physical trusted root unit has a built-in independent security chip that supports SM2 / SM3 / SM4 national cryptographic algorithms. It generates non-exportable public-private key pairs in hardware and is authenticated through a commercial cryptographic level 2 cryptographic module, providing a trusted benchmark for device identity. The dynamic multidimensional watermarking engine is based on the shutter effect of CMOS camera. It generates high-dimensional stripe probes that are invisible to the human eye through frequency-modulated LED. It uses 16 frequency combinations to construct 4096 probe modes to achieve real-time embedding of physical watermarks in each frame of video. The adaptive encryption array adopts an FPGA pipeline architecture, supports SM4 OFB / CTR dual encryption mode switching, dynamically adjusts the encryption parallelism according to the video resolution, and has an encryption latency of ≤3ms at 1080P resolution. The key management submodule adopts an autoregressive random coding mechanism to realize dynamic key updates and probe information binding, with an update cycle configured to be 1-60 minutes; The device authentication interface supports the GB35114-2017 Class C specification, providing two-way identity authentication based on digital certificates to prevent unauthorized devices from accessing the network.
[0006] Preferably, the physical trusted root unit adopts a 32-bit high-performance smart security chip, with a built-in VKEK key participating in the hash operation. The hash result is used as signaling authentication data, and the success rate against side-channel attacks is ≥99.9%.
[0007] Preferably, the LED modulation frequency of the dynamic multidimensional watermarking engine is ≤1 / 2Te (Te is the camera exposure time), the stripe width starts at 100 pixels and increases in increments of 5 pixels to ensure that the stripe feature extraction contrast is ≥60%.
[0008] Preferably, the adaptive encryption array is implemented on a Xilinx Artix-7 series FPGA with resource utilization of: LUT≤65%, FF≤30%, BRAM≤20%, and supports 128-bit data encryption processing per clock cycle.
[0009] A method for strengthening the security and confidentiality of a camera, based on a camera security and confidentiality strengthening module as described above, includes the following steps: Step 1: Module Initialization: The physical trusted root unit generates a unique public-private key pair and an initial key for the device, and registers them with the key server through the key management submodule to complete device identity authentication; Step Two: Video Acquisition Stage The dynamic multidimensional watermarking engine adjusts the LED modulation frequency according to the camera exposure time Te to generate a high-dimensional stripe probe, which is then embedded into the real-time video frame through the roller shutter effect. Step 3: Encryption Processing Stage An adaptive encryption array extracts video frame watermark information and binds it with a key. The SM4 algorithm is used to encrypt video data and watermark information synchronously, and the encryption mode is automatically switched according to the video resolution. Step 4: Transmission and Verification Phase The encrypted video stream is transmitted over the network. The receiving end decrypts the stream and extracts the watermark probe. A deep neural network is used to verify the continuity and consistency of the probe and identify tampered frames. Step 5: Key Update Phase The key management submodule generates new keys according to a preset cycle and completes key synchronization updates through an encrypted channel, making old keys invalid immediately.
[0010] Preferably, in step two, the watermark embedding adopts frequency shift keying technology with separation frequency, the probe information is associated with the device key, the watermark data of each frame is 128 bits, and the embedding process does not affect the subjective quality of the video (PSNR≥40dB).
[0011] Preferably, in step three, the adaptive encryption strategy is as follows: when the resolution is ≤1080P, the SM4 OFB mode is used with an encryption rate ≥85Mbps; when the resolution is 4K, the SM4 CTR mode is used with an encryption rate ≥150Mbps.
[0012] Preferably, in step four, the tampering detection uses the exponential minimum implication algorithm, which has a detection response time of ≤50ms for tampering behaviors such as video frame insertion, deletion, and replacement, and an accuracy of ≥99.2%.
[0013] (III) Beneficial Effects This invention provides a security and confidentiality reinforcement module and method for cameras, which has the following beneficial effects: 1. Employing a dual identity binding mechanism of hardware root of trust and dynamic physical watermark, this technology solves the problem of single identity authentication in existing technologies. Device identity is unforgeable, and the video watermark is strongly correlated with the device key, making tampering traceable. Secondly, an innovative adaptive encryption array design dynamically switches encryption modes and parallelism based on video resolution, achieving an encryption rate of 156.7Mbps at 4K resolution, significantly higher than the 50Mbps rate of existing SM4 encryption modules.
[0014] 2. Combining the roller shutter effect with deep neural networks, active physical watermark embedding and tamper detection are achieved, with a detection accuracy of 99.7% and a response time of ≤38ms, outperforming traditional software watermarking solutions. Furthermore, it supports transparent deployment without requiring modifications to existing camera hardware and network structure, adapts to multi-resolution video streams, and boasts strong compatibility, resolving the issues of complex deployment and poor adaptability in existing solutions. Attached Figure Description
[0015] Figure 1 This is a schematic diagram of the reinforcement module structure of the present invention; Figure 2 This is a schematic diagram of the reinforcement method of the present invention. Detailed Implementation
[0016] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0017] Example 1: like Figure 1 As shown in the figure, this embodiment of the invention provides a camera security and confidentiality reinforcement module, which adopts an integrated hardware design and integrates five core units. The specific structure is as follows: Physical Trusted Root Unit: Employs a 32-bit smart security chip compliant with commercial cryptographic level 2 certification. The hardware generates public-private key pairs and a core key. The private key is stored in a secure area of the chip and cannot be exported. The VKEK key participates in hash operations to generate signaling authentication data, resisting side-channel attacks and brute-force attacks, and providing a trusted identity benchmark for the device.
[0018] Dynamic multidimensional watermarking engine: Composed of an LED modulation module and a probe generation unit, it utilizes the shutter effect of a CMOS camera to generate invisible stripe probes through frequency-modulated LEDs. It employs 16 frequencies to construct 4096 probe combinations, combined with frequency shift keying technology to achieve high-dimensional information embedding, ensuring that each video frame carries a unique and traceable physical watermark.
[0019] Adaptive encryption array: Implemented based on FPGA pipeline architecture, supporting SM4 OFB / CTR dual encryption modes. The number of parallel processing units is dynamically adjusted according to the video resolution. At 1080P resolution, 8 parallel processing channels are used, with an encryption rate of 85Mbps; at 4K resolution, this is expanded to 16 parallel processing channels, increasing the encryption rate to 150Mbps, meeting the real-time encryption requirements of high-definition video.
[0020] Key management submodule: Employs an autoregressive random coding mechanism to achieve dynamic key updates and watermark information binding. It supports a configurable update cycle of 1-60 minutes, completes key synchronization through an encrypted channel to ensure secure key transmission, and immediately invalidates old keys to avoid leakage risks.
[0021] Device authentication interface: Compliant with GB35114-2017 Class C standard, providing two-way identity authentication based on digital certificates. When accessing the network, the module verifies its identity with the key server. Only authenticated devices can access the monitoring system, preventing unauthorized device replacement and access attacks.
[0022] Secondly, such as Figure 2As shown, this embodiment of the invention also provides a method for strengthening the security and confidentiality of a camera. This method is based on the above-mentioned modules and includes five steps: module initialization, video acquisition stage, encryption processing stage, transmission and verification stage, and key update stage. The specific process is as follows: Step 1: Module Initialization: After the module powers on, the physical trusted root unit generates a unique public-private key pair and an initial SM4 key, and sends a registration request to the key management server through the device authentication interface. After the server verifies the device's legitimacy, it completes the issuance of digital certificates and key registration, establishing a trusted communication link.
[0023] Step Two: Video Acquisition Stage The dynamic multidimensional watermarking engine detects the camera's exposure time Te and sets the LED modulation frequency to below 1 / 2Te to generate a 128-bit high-dimensional stripe probe. Utilizing the progressive exposure characteristics of CMOS, the probe is embedded into the video frame in a stripe pattern. The embedding process does not affect the subjective quality of the video (PSNR≥40dB) and is imperceptible to the human eye.
[0024] Step 3: Encryption Processing Stage An adaptive encryption array extracts watermark information from video frames and XORs it with the current key to form an encryption key. The encryption mode is automatically selected based on the video resolution: SM4 OFB mode is used for 1080P and below resolutions, and SM4 CTR mode is used for 4K resolution, achieving synchronous encryption of video data and watermark information with an encryption latency of ≤3ms.
[0025] Step 4: Transmission and Verification Phase The encrypted video stream is transmitted to the monitoring center via the network. The receiving end decrypts the stream and extracts the watermark probe. A deep neural network aligns and verifies the probe information of consecutive frames, and uses the exponential minimum implications algorithm to detect probe continuity. If tampering such as frame insertion, deletion, or replacement is detected, it can be identified within 50ms, with a tampering detection accuracy of ≥99.2%.
[0026] Step 5: Key Update Phase The key management submodule generates new SM4 keys at preset intervals and sends them to the module via an encrypted channel to complete key synchronization updates. Old keys become invalid immediately, ensuring that even if a key is leaked, the security of video data is only affected within a very short time window.
[0027] Experimental data and effect verification This invention verifies performance by building an actual test platform. The test environment is as follows: camera resolutions are 1080P (30fps) and 4K (30fps); the module is implemented based on a Xilinx Artix-7 XC7A35TFGG484-2 FPGA; the key management server is deployed within a local area network; and the test tools include a video quality analyzer, a network performance tester, and a tampering attack simulation platform. The test results are as follows:
[0028] Experimental results show that this module outperforms existing technologies in key indicators such as encryption rate and tamper detection accuracy, and its resource consumption is reasonable, which can meet the requirements of real-time secure transmission of high-definition video.
[0029] Example 2: The difference between this embodiment and Embodiment 1 is that, specifically: Hardware implementation of the module: The physical trusted root unit uses the Hitech HT32U374 security chip, which supports SM2 / SM3 / SM4 national cryptographic algorithms and has passed the commercial cryptographic level 2 certification; the dynamic multi-dimensional watermarking engine uses high-brightness LED light-emitting devices with a modulation frequency range of 50-200Hz and supports adaptive frequency adjustment; the adaptive encryption array is implemented based on Xilinx Artix-7 FPGA and uses Verilog HDL to write a pipelined SM4 encryption core; the key management submodule and device authentication interface are implemented through an ARM Cortex-M4 microcontroller, which supports TCP / IP protocol and GB35114-2017 level C specification.
[0030] Software Flow Implementation: During module initialization, the security chip generates a 2048-bit SM2 public-private key pair and a 128-bit SM4 initial key, and sends a registration request to the key server through the device authentication interface. After the server verifies the request, it issues a digital certificate. During video acquisition, the LED modulation module adjusts the frequency according to the camera exposure time Te to generate stripe probes that are embedded in the video frames. During the encryption phase, the FPGA automatically selects the encryption mode according to the video resolution to complete the synchronous encryption of video data and watermark information. After transmission to the monitoring center, the watermark is extracted and verified through a dedicated deep neural network to identify tampered frames. The key update cycle is set to 30 minutes, and key synchronization is completed through an encrypted channel.
[0031] Application Scenario Deployment: In financial branch monitoring scenarios, this module is connected in series between the camera and the switch without altering the existing monitoring network structure. Video data collected by the camera is encrypted and embedded with a physical watermark before being transmitted to the monitoring center. The center can verify the authenticity of the video in real time, and the system will immediately issue an alarm if video tampering or unauthorized device access is detected. This deployment method achieves end-to-end security protection for financial monitoring videos, ensuring the credibility of video evidence.
[0032] In summary, this invention constructs a full-link security protection system with trusted identity, encrypted data, and tamper traceability through the collaborative design of hardware root of trust, dynamic physical watermarking, and adaptive encryption. This addresses the technical pain points of existing camera security modules, such as single identity authentication, insufficient encryption speed, and lagging tamper detection. The module boasts high encryption speed, accurate tamper detection, and flexible deployment, making it widely applicable in confidential scenarios such as public security, finance, and government affairs. It provides high-strength security for video surveillance systems and has significant practical value and promising prospects for widespread adoption.
[0033] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A camera security and confidentiality reinforcement module, characterized in that: It includes a physical trusted root unit, a dynamic multi-dimensional watermarking engine, an adaptive encryption array, a key management submodule, and a device authentication interface; The physical trusted root unit has a built-in independent security chip that supports SM2 / SM3 / SM4 national cryptographic algorithms. It generates non-exportable public-private key pairs in hardware and is authenticated through a commercial cryptographic level 2 cryptographic module, providing a trusted benchmark for device identity. The dynamic multidimensional watermarking engine is based on the shutter effect of CMOS camera. It generates high-dimensional stripe probes that are invisible to the human eye through frequency-modulated LED. It uses 16 frequency combinations to construct 4096 probe modes to achieve real-time embedding of physical watermarks in each frame of video. The adaptive encryption array adopts an FPGA pipeline architecture, supports SM4 OFB / CTR dual encryption mode switching, and dynamically adjusts the encryption parallelism according to the video resolution. The key management submodule adopts an autoregressive random coding mechanism to realize dynamic key updates and probe information binding, with an update cycle configured to be 1-60 minutes; The device authentication interface supports the GB35114-2017 Class C specification, providing two-way identity authentication based on digital certificates to prevent unauthorized devices from accessing the network.
2. The camera security and confidentiality reinforcement module according to claim 1, characterized in that: The physical trusted root unit uses a 32-bit high-performance smart security chip with a built-in VKEK key to participate in hash operations, and the hash result is used as signaling authentication data.
3. The camera security and confidentiality reinforcement module according to claim 1, characterized in that: The LED modulation frequency of the dynamic multidimensional watermark engine is ≤1 / 2Te, where Te is the camera exposure time, and the stripe width starts at 100 pixels and increases in increments of 5 pixels.
4. The camera security and confidentiality reinforcement module according to claim 1, characterized in that: The adaptive encryption array is implemented on a Xilinx Artix-7 series FPGA and supports 128-bit data encryption processing in a single clock cycle.
5. A method for strengthening the security and confidentiality of a camera, based on a camera security and confidentiality strengthening module according to any one of claims 1-4, characterized in that: Includes the following steps: Step 1: Module Initialization: The physical trusted root unit generates a unique public-private key pair and an initial key for the device, and registers them with the key server through the key management submodule to complete device identity authentication; Step Two: Video Acquisition Stage The dynamic multidimensional watermarking engine adjusts the LED modulation frequency according to the camera exposure time Te to generate a high-dimensional stripe probe, which is then embedded into the real-time video frame through the roller shutter effect. Step 3: Encryption Processing Stage An adaptive encryption array extracts video frame watermark information and binds it with a key. The SM4 algorithm is used to encrypt video data and watermark information synchronously, and the encryption mode is automatically switched according to the video resolution. Step 4: Transmission and Verification Phase The encrypted video stream is transmitted over the network. The receiving end decrypts the stream and extracts the watermark probe. A deep neural network is used to verify the continuity and consistency of the probe and identify tampered frames. Step 5: Key Update Phase The key management submodule generates new keys according to a preset cycle and completes key synchronization updates through an encrypted channel, making old keys invalid immediately.
6. The method for strengthening the security and confidentiality of a camera according to claim 5, characterized in that: In step two, the watermark embedding adopts frequency shift keying technology with separation frequency. The probe information is associated with the device key. The watermark data size of each frame is 128 bits. The embedding process does not affect the subjective quality of the video.
7. A method for strengthening the security and confidentiality of a camera according to claim 5, characterized in that: In step three, the adaptive encryption strategy is as follows: when the resolution is ≤1080P, the SM4 OFB mode is used with an encryption rate ≥85Mbps; when the resolution is 4K, the SM4 CTR mode is used with an encryption rate ≥150Mbps.
8. The method for strengthening the security and confidentiality of a camera according to claim 5, characterized in that: In step four, the tampering detection uses the exponential minimum implication algorithm, and the detection response time for tampering behaviors such as video frame insertion, deletion, and replacement is ≤50ms.