Content tamper-proofing and secure playing system and method for public display screen
By combining a secure information publishing system, an auditing terminal, and a secure playback box, the problems of untrustworthy publishing entities and easily tampered content in the content security system of public display screens are solved. This achieves end-to-end integrity protection and proactive defense on the terminal side, preventing unaudited or illegal content from being displayed on the screen.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA RAILWAY XIAN GRP CO LTD
- Filing Date
- 2026-01-23
- Publication Date
- 2026-05-01
AI Technical Summary
The existing content security publishing system for public display screens cannot ensure the credibility of the publishing entity. Content is easily tampered with during circulation and is difficult to detect. Traditional verification methods are easily overridden and cannot prevent unapproved or illegal content from being displayed.
By employing a secure information publishing system, review terminals, a public screen content security publishing platform, and a secure playback box, and through digital signatures, timestamp authentication tokens, an AI content review engine, and environmental detection, the system achieves end-to-end content review and security tag generation and verification, ensuring the integrity and trustworthy dissemination of content.
It achieves end-to-end integrity protection from content creation to playback, ensuring the credibility of the publishing entity, preventing content tampering, enhancing the proactive defense capabilities of the terminal side, and preventing unreviewed or illegal content from being displayed.
Smart Images

Figure CN121966987A_ABST
Abstract
Description
A content anti-tampering and secure playback system and method for public display screens Technical Field
[0001] This invention relates to the field of public information publishing security technology, and in particular to a content anti-tampering and secure playback system and method for public display screens. Background Technology
[0002] Currently, the secure publication of content on public display screens mainly relies on simple login access control, easily tampered digest verification such as MD5, digital watermarking focusing on post-event traceability, and transport layer security measures such as HTTPS. These existing technologies have systemic flaws: First, they cannot ensure the trusted identity of the publishing entity, with weak passwords and shared accounts being common problems; second, they lack integrity protection for the entire chain from content creation to playback, making content easily maliciously tampered with during circulation and difficult to detect; third, traditional verification methods cannot irrefutably bind content to the reviewing entity and review time, and the verification values themselves are easily overwritten and replaced; finally, existing solutions are mostly post-control measures that "block after display," or can only prevent transmission eavesdropping, failing to address the risk of unreviewed content at the source or content being switched after the terminal is controlled, resulting in the continued risk of illegal, inappropriate, or tampered content being displayed. Summary of the Invention
[0003] This invention provides a content anti-tampering and secure playback system and method for public display screens, which addresses the core problems of existing public display screen content security systems, such as the inability to ensure the credibility of the publishing entity, the inability to prevent content from being tampered with during circulation, and the lack of a mandatory pre-broadcast verification mechanism, which leads to unreviewed or illegal content being played on the screen.
[0004] The objective of this invention can be achieved through the following technical solution: The first aspect of this invention is to provide a content anti-tampering and secure playback system for public display screens, comprising: a secure information publishing system for receiving user content uploads, program schedule arrangements, and publishing instructions; an auditing terminal with a built-in cryptographic module and physical confirmation button, used to digitally sign content based on a built-in certificate private key during the content auditing process, generating an authentication token with a timestamp, and submitting it to the secure information publishing system; a public screen content security publishing platform, communicatively connected to the secure information publishing system, used to receive auditing requests and, based on the authentication token, generate a digital signature for the audited content using a commercial cryptographic algorithm to form a security mark; and a secure playback box, connected in series to the front end of the public display screen, used to receive content and security marks from the secure information publishing system or the public screen content security publishing platform, and verify the validity of the security mark before playback. Playback is only allowed after successful verification; playback is refused if verification fails.
[0005] Furthermore, the verification terminal is a cryptographic hardware device in the form of a USB-KEY, Bluetooth KEY, or audio interface KEY with independent computing capabilities.
[0006] Furthermore, the public screen content security publishing platform also includes a certificate management module, which is used to manage the entire lifecycle of digital certificates built into the audit terminal, including issuance, renewal, activation, and revocation.
[0007] Furthermore, the public screen content security publishing platform also includes an AI content review engine, which is used to automatically identify and classify uploaded text, images and video content for violations, inappropriate words and deeds, sensitive scenes and harmful information. The AI content review serves as a pre-process or auxiliary step in the multi-level manual review process within the security information publishing system.
[0008] Furthermore, the AI content review engine processes video content by: extracting keyframes, segmenting shots, performing image recognition on keyframes, and using OCR technology to extract text within the frames. The extracted text, along with the original video subtitles, is then fed into the text review model to achieve a combined risk analysis of the video and subtitles.
[0009] Furthermore, the security tag is a structured data object that includes at least: a hash value of the content, a digital signature of at least one level of auditing terminal, and a tag generation timestamp.
[0010] Furthermore, the secure playback box also includes an environment detection unit, which monitors physical disassembly signals of the box, operating system integrity, and abnormal network port traffic. When an anomaly is detected, an alarm is triggered or a secure lockout state is entered according to a preset strategy.
[0011] Furthermore, the secure information publishing system executes a multi-level content review process. Each level of review requires reviewers with different permissions to perform physical verification and digital signature using their dedicated review terminals. The security tag generated by the public screen content security publishing platform integrates the signature information of the multi-level reviewers. The multi-level review process is as follows: 1) The user connects the review terminal to the computer and uses the computer to access the front end of the secure information publishing system to start the review process. After selecting the file to be reviewed, the user calls the local service through the front end SDK. The local service generates a token using the review terminal and returns it. 2) The front end of the secure information publishing system receives the token, submits a file review request to the back end, and simultaneously sends the token to the back end. 3) After receiving the file review request, the back end of the secure information publishing system calculates the file hash value and then calls the file tag interface of the public screen content security publishing platform, passing the token and the file hash value as parameters. 4) The public screen content security publishing platform parses and verifies the token, uses the corresponding certificate to perform a digital signature on the file based on a commercial cryptographic algorithm, and returns the file signature value.
[0012] Furthermore, the secure playback box supports communication with the secure information publishing system or the public screen content secure publishing platform via at least one of wired network, Wi-Fi, or 4G / 5G mobile communication network.
[0013] The second aspect of this invention provides a method for preventing content tampering and ensuring secure playback on public display screens, comprising: a content upload and AI pre-review step: an administrator uploads materials through the secure information publishing system and triggers the AI content review engine of the public screen content security publishing platform for automatic pre-review; a multi-level review and security tag generation step: after the AI pre-review is passed, the content enters a multi-level manual review process in the secure information publishing system, where reviewers use personal review terminals for physical confirmation and digital signature; after the final review is passed, the public screen content security publishing platform generates a security tag bound to the content; a secure publishing step: the secure information publishing system encrypts and distributes the content and its security tag together to the secure playback box corresponding to the target public display screen; and a terminal verification and playback step: after receiving the content, the secure playback box first verifies the authenticity and integrity of the security tag locally. If the verification is successful, playback is scheduled; if the verification fails, playback is rejected and an alarm is reported.
[0014] Compared with existing technologies, the beneficial effects of this invention are as follows: A secure information publishing system is used to receive user content uploads, program schedule arrangements, and publishing instructions. This design clearly defines the system as using existing business systems as the entry point, achieving centralized and unified control over the entire content publishing process, providing a clear business anchor and operation interface for subsequent security measures. An auditing terminal, with a built-in password module and physical confirmation button, is used to perform digital signatures based on the built-in certificate private key during content auditing, generating a timestamped authentication token and submitting it to the secure information publishing system. Through the mechanism of "physical button triggering password signature," the auditor's physical confirmation action is forcibly bound to the non-repudiation of the digital world, fundamentally ensuring the credibility of the auditing entity, the clarity of intent, and the inability to deny it afterward. A public screen content secure publishing platform communicates with the secure information publishing system, receiving its audit requests and, based on the authentication token... Commercial cryptographic algorithms are used to generate digital signatures for approved content, forming security markers. This platform, acting as the security core, cryptographically binds authentication tokens from the trusted review process to the content itself, generating security markers that combine identity authentication and integrity protection. This provides a unique and tamper-proof "digital ID card" for the trusted dissemination and verification of content in subsequent stages. A secure playback box, connected in series with the front end of the public display screen, receives content and security markers from the secure information publishing system or the public screen content security publishing platform. It verifies the validity of the security markers before playback; only after successful verification can playback be decoded; otherwise, playback is rejected. By using security verification as a mandatory pre-playback threshold, the security defense is pushed directly from the cloud or server room to the front end of the screen, achieving a fundamental shift from "blocking after playback" to "preventing tampered content from ever being played," greatly enhancing the proactive defense capabilities of the terminal side. Ultimately, this invention solves the core problems of existing public display screen content security systems: the inability to ensure the credibility of the publishing entity, the inability to prevent content tampering during circulation, and the lack of a mandatory pre-playback verification mechanism, leading to the final playback of unreviewed or illegal content. Attached Figure Description
[0015] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0016] Figure 1 is a schematic diagram of the execution flow of a content anti-tampering and secure playback system for public display screens provided by the present invention; Figure 2 is a schematic diagram of the steps of a content anti-tampering and secure playback method for public display screens provided by the present invention. Detailed Implementation
[0017] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0018] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0019] To address the problems existing in the background technology, this paper studies and designs a content anti-tampering and secure playback system and method for public display screens, which has important practical significance.
[0020] As shown in Figure 1, the first aspect of the present invention is to provide a content anti-tampering and secure playback system for public display screens, including a secure information publishing system, an auditing terminal, a public screen content secure publishing platform, and a secure playback box.
[0021] The security information publishing system 101 is used to receive user instructions for content uploads, program schedule arrangement, and publishing.
[0022] The review terminal 102 has a built-in password module and a physical confirmation button. It is used to perform digital signature based on the built-in certificate private key during the content review process, generate an authentication token with a timestamp, and submit it to the security information release system.
[0023] The audit terminal is a cryptographic hardware device in the form of a USB-KEY, Bluetooth KEY, or audio interface KEY with independent computing capabilities. The specific process for generating and submitting the authentication token is as follows: 1) Terminal Connection and Initialization: When auditing content, the auditor inserts their personal audit terminal (such as a USB-KEY) into the USB port of their auditing computer. The computer's operating system or dedicated client software recognizes the device and loads the corresponding driver. After powering on, the terminal performs a self-test and is ready; 2) Triggering Audit Signature: The auditor reviews and verifies the submitted audit materials (such as images and videos) on the front-end page of the security information publishing system. Upon confirming the content is correct and deciding to "pass," the auditor presses the physical confirmation button on the audit terminal; 3) Internal Authentication and Triggering: Pressing the physical button triggers the terminal's internal security process. First, the terminal may require the auditor to enter a PIN code (optional, for enhanced security) to unlock and use the built-in password module. After successful verification, the terminal generates a random number or session identifier and binds it to a timestamp obtained from the current system time; 4) Generate signature data: The cryptographic module within the terminal uses its internally stored digital certificate private key, uniquely bound to the auditor's identity, to perform a digital signature operation on a specific data packet composed of a "timestamp," a "random number," and (optionally) a unique identifier for this audit task issued by the platform; 5) Output authentication token: The result of the digital signature operation, along with the original data (or its hash value) used to generate the signature and a copy of the digital certificate built into the terminal, is assembled into a structured data packet, which is the authentication token. The terminal then returns this authentication token to the client software on the auditing computer via a USB interface; 6) Token submission: After receiving the authentication token, the client software submits it along with the audit operation (such as "audit passed") instruction to the backend security information publishing system. The system then forwards this token to the public screen content security publishing platform for verification and use.
[0024] The public screen content security publishing platform 103 is communicatively connected to the security information publishing system, and is used to receive its review requests. Based on the authentication token, it uses commercial cryptographic algorithms to generate digital signatures for the approved content to form a security mark.
[0025] The public screen content security publishing platform also includes a certificate management module, which is used to manage the entire lifecycle of digital certificates built into the review terminal, including issuance, renewal, activation, and revocation.
[0026] The public screen content security publishing platform also includes an AI content review engine, used to automatically identify and classify uploaded text, images, and videos for violations, inappropriate behavior, sensitive scenes, and harmful information. This AI content review serves as a pre-processing or auxiliary step in the multi-level manual review process within the security information publishing system. Specifically, the AI content review engine's processing of video content includes: keyframe extraction, shot segmentation, image recognition of keyframes, and extraction of text within frames using OCR technology. The extracted text, along with the original video subtitles, is then fed into the text review model to achieve a combined risk analysis of the video and subtitles.
[0027] The secure playback box 104 is connected in series to the front end of the public display screen. It is used to receive content and security tags from the security information publishing system or the public screen content security publishing platform, and to verify the validity of the security tags before playback. If the verification is successful, the playback can be decoded; if the verification fails, playback is refused.
[0028] The security tag is a structured data object that includes at least: the hash value of the content, the digital signature of at least one level of auditing terminal, and the tag generation timestamp.
[0029] The secure playback box also includes an environmental detection unit, which monitors physical disassembly signals, operating system integrity, and abnormal network port traffic. When an anomaly is detected, it triggers an alarm or enters a secure lockout state according to a preset policy.
[0030] The secure playback box supports communication with the secure information publishing system or public screen content secure publishing platform via at least one of wired network, Wi-Fi or 4G / 5G mobile communication network.
[0031] The secure information publishing system executes a multi-level content review process. Each level of review requires reviewers with different permissions to perform physical verification and digital signature using their dedicated review terminals. The security tag generated by the public screen content security publishing platform integrates the signature information of the reviewers at each level. The multi-level content review process is as follows: 1) The user connects the review terminal to their computer and uses the computer to access the front-end of the secure information publishing system to begin the review process. After selecting a file to review, the user calls a local service through the front-end SDK. The local service generates a token using the review terminal and returns it. 2) The front-end of the secure information publishing system receives the token, submits a file review request to the back-end, and simultaneously sends the token to the back-end. 3) After receiving the file review request, the back-end of the secure information publishing system calculates the file hash value and then calls the file tag interface of the public screen content security publishing platform, passing the token and the file hash value as parameters. 4) The public screen content security publishing platform parses and verifies the token, uses the corresponding certificate to digitally sign the file based on a commercial cryptographic algorithm, and returns the file signature value.
[0032] This concludes the embodiment.
[0033] As shown in Figure 2, the second aspect of this invention provides a method for preventing content tampering and ensuring secure playback on public display screens, comprising the following steps: S1: Content upload and AI pre-review step: The administrator uploads materials through the secure information publishing system and triggers the AI content review engine of the public screen content security publishing platform for automatic pre-review; S2: Multi-level review and security tag generation step: After the AI pre-review is passed, the content enters a multi-level manual review process in the secure information publishing system, where reviewers use personal review terminals for physical confirmation and digital signature; after the final review is passed, the public screen content security publishing platform generates a security tag bound to the content; S3: Secure publishing step: The secure information publishing system encrypts and distributes the content and its security tag together to the secure playback box corresponding to the target public display screen; S4: Terminal verification and playback step: After receiving the content, the secure playback box first verifies the authenticity and integrity of the security tag locally. If the verification is successful, playback is scheduled; if the verification fails, playback is rejected and an alarm is reported.
[0034] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, optical storage, etc.) containing computer-usable program code.
[0035] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, systems, and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in one or more blocks of the flowchart illustrations and / or one or more blocks of the block diagrams.
[0036] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means that implement the functions specified in one or more flowcharts and / or one or more block diagrams.
[0037] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, such that the instructions, which execute on the computer or other programmable apparatus, provide steps for implementing the functions specified in one or more flowcharts and / or one or more block diagrams.
[0038] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the protection scope of the present invention.
Claims
1. A content anti-tampering and secure playback system for public display screens, characterized in that, include: The secure information publishing system receives user content uploads, program schedules, and publishing instructions. The review terminal, with a built-in cryptographic module and physical confirmation button, performs digital signatures based on a built-in certificate private key during content review, generating a timestamped authentication token and submitting it to the secure information publishing system. The public screen content security publishing platform communicates with the secure information publishing system, receives its review requests, and generates digital signatures for approved content using commercial cryptographic algorithms based on the authentication token, thus forming a security marker. A secure playback box is connected in series to the front end of a public display screen. It is used to receive content and security tags from the security information publishing system or the public screen content security publishing platform, and to verify the validity of the security tags before playback. If the verification is successful, the playback can be decoded; if the verification fails, playback is refused.
2. The content anti-tampering and secure playback system for public display screens according to claim 1, characterized in that, The verification terminal is a cryptographic hardware device in the form of a USB-KEY, Bluetooth KEY, or audio interface KEY with independent computing capabilities.
3. A content anti-tampering and secure playback system for public display screens according to claim 1, characterized in that, The public screen content security publishing platform also includes a certificate management module, which is used to manage the entire lifecycle of digital certificates built into the review terminal, including issuance, renewal, activation, and revocation.
4. A content anti-tampering and secure playback system for public display screens according to claim 1, characterized in that, The public screen content security publishing platform also includes an AI content review engine, which is used to automatically identify and classify uploaded text, images and video content for violations, inappropriate words and deeds, sensitive scenes and harmful information. The AI content review serves as a pre-process or auxiliary step in the multi-level manual review process within the security information publishing system.
5. A content anti-tampering and secure playback system for public display screens according to claim 4, characterized in that, The AI content review engine processes video content by: extracting keyframes, segmenting shots, performing image recognition on keyframes, and using OCR technology to extract text within the frames. The extracted text, along with the original video subtitles, is then fed into the text review model to achieve a combined risk analysis of the video and subtitles.
6. A content anti-tampering and secure playback system for public display screens according to claim 1, characterized in that, The security tag is a structured data object that includes at least: the hash value of the content, the digital signature of at least one level of auditing terminal, and the tag generation timestamp.
7. A content anti-tampering and secure playback system for public display screens according to claim 1, characterized in that, The secure playback box also includes an environmental detection unit, which monitors physical disassembly signals of the box, operating system integrity, and abnormal network port traffic. When an anomaly is detected, an alarm is triggered or a secure lockout state is entered according to a preset strategy.
8. A content anti-tampering and secure playback system for public display screens according to claim 1, characterized in that, The security information publishing system executes a multi-level content review process. Each level of review requires reviewers with different permissions to use their dedicated review terminals for physical confirmation and digital signature. The security mark generated by the public screen content security publishing platform integrates the signature information of the reviewers at multiple levels. The multi-level review process is as follows: 1) The user connects the review terminal to the computer and uses the computer to access the front end of the security information publishing system to start the review process. After selecting the review file, the user calls the local service through the front end SDK. The local service generates a token by using the review terminal and returns it. 2) The front-end of the security information publishing system receives the token, submits a file review request to the back-end, and simultaneously sends the token to the back-end; 3) After receiving the file review request, the back-end of the security information publishing system calculates the file hash value, and then calls the file tagging interface of the public screen content security publishing platform, passing the token and the file hash value as parameters; 4) The public screen content security publishing platform parses and verifies the token, uses the corresponding certificate to digitally sign the file based on commercial cryptographic algorithms, and returns the file signature value.
9. A content anti-tampering and secure playback system for public display screens according to claim 1, characterized in that, The secure playback box supports communication with the secure information publishing system or public screen content secure publishing platform via at least one of wired network, Wi-Fi or 4G / 5G mobile communication network.
10. A method for content anti-tampering publishing and secure playback applied to any of the systems described in claims 1-9, characterized in that, The process includes the following steps: Content upload and AI pre-review: The administrator uploads materials through the security information publishing system and triggers the AI content review engine of the public screen content security publishing platform to perform automatic pre-review; Multi-level review and security mark generation: After the AI pre-review is passed, the content enters the multi-level manual review process in the security information publishing system, and the reviewers use their personal review terminals to perform physical confirmation and digital signature; After the public screen content security publishing platform passes the final review, it generates a security tag that is bound to the content. Secure release steps: The secure information release system encrypts and sends the content and its security tag together to the secure playback box corresponding to the target public display screen; Terminal verification and playback steps: After receiving the content, the secure playback box first verifies the authenticity and integrity of the security mark locally. If the verification is successful, the playback is scheduled; if the verification fails, the playback is rejected and an alarm is reported.