Wireless network camera mainboard safety communication protocol optimization method and system

By dynamically adjusting the encryption density of video data and the link quality score, the computational resource load and signal instability issues of the wireless network camera motherboard during high-resolution video stream transmission are resolved, resulting in smoother wireless video transmission and anti-interference capabilities, meeting the low-latency communication requirements of industrial-grade monitoring.

CN121985351APending Publication Date: 2026-05-05SHENZHEN RUIJIE XUNSHI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHENZHEN RUIJIE XUNSHI TECH CO LTD
Filing Date
2026-02-03
Publication Date
2026-05-05

AI Technical Summary

Technical Problem

Existing wireless network camera motherboard security communication protocols place excessive computational load on the transmission of high-resolution video streams, making them unable to adapt to changes in wireless signal strength. This results in data packet loss and video stuttering, failing to guarantee the integrity and real-time performance of the video stream. In particular, they struggle to meet the low-latency communication requirements of industrial-grade monitoring in scenarios with limited bandwidth or complex electromagnetic environments.

Method used

By reading the signal-to-noise ratio and signal strength, a link quality score is calculated. A dynamic session key is generated using photoelectric shot noise. The encryption density of video data is dynamically adjusted. The link quality score and congestion judgment threshold are combined to perform hierarchical encryption. The encryption strategy index value is embedded in the protocol data frame to build a secure communication protocol.

Benefits of technology

It effectively reduces motherboard computing overhead, eliminates screen interruption issues caused by frequent reconnections, improves the smoothness and anti-interference capability of wireless video transmission, and solves the transmission bottleneck of device disconnection in high-concurrency scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121985351A_ABST
    Figure CN121985351A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security communication, in particular to a wireless network camera mainboard security communication protocol optimization method and system, and the method comprises the following steps: reading a signal-to-noise ratio and a signal intensity numerical value, calculating a link quality score, capturing photoelectric shot noise, converting the photoelectric shot noise into a true random entropy source sequence, and carrying out the real random entropy source sequence; generating a dynamic session key in combination with clock jitter; analyzing the monitoring video stream to separate an I frame and a P frame, when the score is lower than a threshold value, only encrypting the I frame to generate a core ciphertext, and generating an integrity check code for the P frame; and constructing a security protocol data frame according to the error correction coding rate and executing a data transmission action. According to the method, the encryption density of the video data is dynamically adjusted according to the signal-to-noise ratio of a real-time signal by introducing a dynamic fragmentation mechanism of channel state perception, so that the calculation overhead of a mainboard in a weak network environment is effectively reduced, and the traditional complete handshake process is replaced by lightweight re-authentication logic based on hardware noise characteristics; and the problem of picture interruption caused by frequent reconnection is fundamentally eliminated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security communication technology, and in particular to a method and system for optimizing the secure communication protocol of a wireless network camera motherboard. Background Technology

[0002] The field of network security communication technology involves a set of technologies to ensure the confidentiality, integrity, and availability of data in wireless transmission networks, covering encryption algorithms, authentication mechanisms, and the construction and execution of data transmission handshake protocols. Among these, the traditional method for optimizing secure communication protocols on wireless network camera motherboards involves using standard SSL / TLS protocols or pre-installed AES static keys to fully encrypt the acquired video stream data. The general-purpose CPU on the motherboard sequentially executes data packet encapsulation, handshake verification, and encrypted transmission, typically relying on a fixed TCP / IP protocol stack to handle retransmission mechanisms during network congestion.

[0003] Existing technologies employ full encryption, which increases the load on motherboard computing resources, resulting in significant encoding delays during high-resolution video stream transmission. Fixed handshake authentication mechanisms cannot adapt to dynamic changes in wireless signal strength, and frequently trigger the complete reconnection process when channel interference is severe, causing data packet loss and screen stuttering. They cannot guarantee the integrity and real-time performance of video streams in scenarios with limited bandwidth or complex electromagnetic environments, making it difficult to meet the stringent requirements of industrial-grade monitoring for low-latency communication. Summary of the Invention

[0004] The purpose of this invention is to address the shortcomings of existing technologies by proposing an optimization method and system for the secure communication protocol of a wireless network camera motherboard.

[0005] To achieve the above objectives, the present invention adopts the following technical solution: a method for optimizing the secure communication protocol of a wireless network camera motherboard, comprising the following steps: S1: Read the signal-to-noise ratio (SNR) and signal strength values ​​of the radio frequency front-end of the wireless network camera motherboard, calculate the link quality score using the weighted product of the SNR and signal strength values, and construct a congestion judgment threshold based on the fluctuation variance of the link quality score within the time window. S2: Capture the photoelectric shot noise at the bottom layer of the CMOS sensor during the image acquisition interval, map the analog level of the photoelectric shot noise to a preset quantization range and convert it into a true random entropy source sequence, and generate a dynamic session key by performing an XOR logic operation between the true random entropy source sequence and the clock jitter frequency. S3: Parse the monitoring video stream to separate I-frame data and P-frame data, compare the link quality score with the congestion judgment threshold, and when the judgment is lower than the threshold, retrieve the dynamic session key to perform AES encryption on the I-frame data to generate core ciphertext, and perform CRC check on the P-frame data to generate integrity check code. S4: Interweave and reassemble the core ciphertext and the integrity check code according to the error correction coding rate of the link quality score inverse mapping to construct a security protocol data frame. Embed the encryption policy index value in the physical layer header of the security protocol data frame to drive the wireless transmission unit to perform data transmission.

[0006] As a further aspect of the present invention, the execution process of S1 is specifically as follows: S11: Call the RF drive interface to periodically scan the current working frequency band, extract the real-time refreshed signal-to-noise ratio value and the corresponding signal strength value from the physical layer register, normalize the collected raw data to eliminate dimensional differences, and generate a standardized RF feature parameter set. S12: Obtain the standardized signal-to-noise ratio and standardized signal strength from the standardized radio frequency characteristic parameter set, assign corresponding weighting coefficients to the two according to the preset communication quality weight allocation model, calculate the link communication status index at the current moment through the linear weighted summation algorithm, and generate the link quality score; S13: Establish a sliding time window containing several continuous sampling points, store the link quality score in the buffer queue of the time window, calculate the statistical variance of all score data in the queue to characterize the fluctuation of channel stability, dynamically fit the fluctuation variance with the benchmark congestion coefficient, and generate the congestion judgment threshold.

[0007] As a further aspect of the present invention, the process of calculating the link quality score specifically includes: The signal-to-noise ratio (SNR) and signal strength values ​​are obtained. Based on the weighting of the channel environment's impact on communication stability, the link quality score is calculated using the following formula: ; in, This represents the link quality score. This represents the signal-to-noise ratio value currently being read. This represents the theoretical maximum signal-to-noise ratio of the radio frequency chip. This represents the signal strength value currently being read. Represents the standard reference signal strength. This represents the preset signal-to-noise ratio weighting factor. This represents the duration for which the link remains connected.

[0008] As a further aspect of the present invention, the execution process of S2 is specifically as follows: S21: Monitor the vertical synchronization signal of the CMOS image sensor, and activate the bottom noise acquisition circuit in the vertical blanking interval after each frame of image transmission is completed to capture the photoelectric shot noise generated by thermally excited electrons of the photodiode under no light conditions. S22: Acquire the weak analog voltage signal of the photoelectric shot noise, input it into a high-precision analog-to-digital converter, divide it into several nonlinear quantization levels according to the preset voltage amplitude distribution range, map the voltage value of the sampling point into the corresponding binary digital code, and generate the true random entropy source sequence. S23: Obtain the microsecond-level clock jitter frequency data generated by the motherboard crystal oscillator circuit during operation, perform a bit-by-bit XOR logic operation between the true random entropy source sequence and the clock jitter frequency data, use the operation result to break down the correlation of the original sequence, extract a fixed-length bit stream, and generate the dynamic session key.

[0009] As a further aspect of the present invention, the generation process of the true random entropy source sequence specifically includes: The analog voltage amplitude of the photoelectric shot noise is obtained, a set of quantization thresholds containing multiple non-uniform distribution intervals is established, and the analog voltage amplitude is compared with the boundary thresholds of each interval step by step. When the voltage amplitude falls into the high probability density range, it is mapped to a low-bit-width binary code. When the voltage amplitude falls into the long-tail range of the low probability density, it is mapped to a high-bit-width binary code. The true random entropy source sequence is generated by splicing the binary code streams obtained from the conversion at each sampling time.

[0010] As a further aspect of the present invention, the execution process of S3 is specifically as follows: S31: Parse H.264 or H.265 format surveillance video streams, and demultiplex the video stream into I-frame data containing key image information and P-frame data containing differentiated motion vectors by identifying the frame type identifier in the header of the network extraction layer unit. S32: Obtain the link quality score and the congestion determination threshold, compare the values ​​of the two in real time, and if the link quality score is found to be less than the congestion determination threshold, determine that the current channel is in a state of high congestion and high packet loss risk, and generate a strong encryption trigger signal. S33: In response to the strong encryption trigger signal, the dynamic session key is retrieved to initialize the AES encryption engine, and the I-frame data is block-wise encrypted using the cipher block chaining mode to generate the core ciphertext. The polynomial remainder of the P-frame data is calculated using the cyclic redundancy check algorithm to generate the integrity check code.

[0011] As a further aspect of the present invention, the generation process of the core ciphertext specifically includes: The I-frame data to be encrypted is obtained and divided into several 128-bit fixed data blocks. A randomly generated initialization vector is introduced and XORed with the first plaintext data block. The dynamic session key is retrieved and XORed with the result to perform multiple rounds of byte substitution, row shifting, column mixing, and round key addition transformation. The ciphertext output of the previous round is used as the XOR input factor of the plaintext block in the next round. The chain encryption operation of all data blocks is completed in sequence to generate the core ciphertext.

[0012] As a further aspect of the present invention, the execution process of S4 is specifically as follows: S41: Obtain the link quality score, query the preset mapping table between channel quality and forward error correction coding rate, select the redundancy check bit length that is inversely proportional to the current score, and determine the error correction coding rate; S42: Obtain the core ciphertext and the integrity check code, generate redundant check data according to the error correction coding rate, and use a pseudo-random interleaving algorithm to discretize and rearrange the data bit stream and check bit stream to prevent burst errors from causing continuous data loss, and construct the security protocol data frame; S43: Extract the algorithm type identifier and key version number used in this encryption process, combine them to generate the encryption strategy index value, write the index value into the physical layer preamble field of the security protocol data frame, send a transmission command to the radio frequency transmission circuit, and drive the wireless transmission unit to perform data transmission.

[0013] As a further aspect of the present invention, the construction process of the security protocol data frame specifically includes: Obtain the interleaved and reassembled mixed bit stream and establish a link layer frame header structure containing a synchronization word, frame length indicator, source address and destination address; The encryption policy index value is encapsulated into a custom extended frame header field, the mixed bit stream is filled into the data field as payload data, and a cyclic redundancy check code for physical layer frame verification sequence is added to the end of the frame to complete the standardized assembly of the data packet structure and construct the security protocol data frame.

[0014] A wireless network camera motherboard security communication protocol optimization system is provided. The system is used to implement the aforementioned wireless network camera motherboard security communication protocol optimization method. The system includes: The channel state monitoring module is configured to read the signal-to-noise ratio (SNR) and signal strength (SQS) values ​​of the radio frequency front-end of the wireless network camera motherboard, calculate the link quality score using the weighted product of the SNR and SQS values, and construct a congestion judgment threshold based on the fluctuation variance of the link quality score within a time window. The entropy source key extraction module is configured to capture photoelectric shot noise at the bottom layer of the CMOS sensor during the image acquisition interval, map the analog level of the photoelectric shot noise to a preset quantization range and convert it into a true random entropy source sequence, and generate a dynamic session key through the XOR logic operation of the true random entropy source sequence and the clock jitter frequency. An adaptive hierarchical encryption module is configured to parse the monitoring video stream to separate I-frame data and P-frame data, compare the link quality score with the congestion judgment threshold, and when the judgment is lower than the threshold, retrieve the dynamic session key to perform AES encryption on the I-frame data to generate core ciphertext, and perform CRC check on the P-frame data to generate an integrity check code. The protocol frame encapsulation and transmission module is configured to interleave and reassemble the core ciphertext and the integrity check code according to the error correction coding rate that is reverse-mapped by the link quality score to construct a secure protocol data frame. An encryption policy index value is embedded in the physical layer header of the secure protocol data frame to drive the wireless transmission unit to perform data transmission.

[0015] Compared with the prior art, the advantages and positive effects of the present invention are as follows: In this invention, by introducing a channel state-aware dynamic fragmentation mechanism, the encryption density of video data is dynamically adjusted according to the real-time signal-to-noise ratio, effectively reducing the computational overhead of the motherboard in weak network environments. By using lightweight re-authentication logic based on hardware noise characteristics to replace the traditional complete handshake process, the problem of screen interruption caused by frequent reconnection is fundamentally eliminated. While ensuring the security of the communication link, the smoothness and anti-interference capability of wireless video transmission are greatly improved, and the transmission bottleneck of difficulty in quickly restoring connection after device disconnection in high-concurrency scenarios is solved. Attached Figure Description

[0016] Figure 1 This is a flowchart of the wireless network camera motherboard security communication protocol optimization method of the present invention; Figure 2 This is a flowchart of the link quality score and congestion determination threshold calculation process of the present invention; Figure 3 This is a flowchart of the dynamic session key generation process of the present invention; Figure 4 This is a flowchart of the video data encryption and verification process of the present invention; Figure 5 This is a flowchart illustrating the data frame construction and transmission process of the security protocol of this invention. Detailed Implementation

[0017] To make the objectives, technical solutions, and advantages of this invention clearer, the software-based technical solution is described in detail below with reference to system architecture diagrams and embodiments. It should be understood that the specific embodiments described herein are only for explaining the technical solutions of this invention and do not constitute a limitation on the scope of protection.

[0018] In the description of this invention, the system architecture relationships or data processing flows indicated by terms such as "layer," "module," "interface," "data flow," "client," and "server" are all defined based on the architecture diagram or flowchart corresponding to the embodiments. This way of describing is only used to clearly illustrate the logical relationships between the elements in the technical solution, and not to limit the physical deployment form. The term "multiple" includes two or more technical units, including but not limited to multiple data nodes, processing threads, service instances, or functional components and other scalable elements. The specific number is determined according to the actual business scenario and needs to be specifically specified.

[0019] Please see Figure 1 and Figure 2 This invention provides a technical solution: a method for optimizing the secure communication protocol of a wireless network camera motherboard, comprising the following steps: S1: Read the signal-to-noise ratio (SNR) and signal strength values ​​of the RF front-end of the wireless network camera motherboard, calculate the link quality score using the weighted product of the SNR and signal strength values, and construct a congestion judgment threshold based on the fluctuation variance of the link quality score within the time window.

[0020] The execution process of S1 is as follows: S11: Call the RF driver interface to periodically scan the current working frequency band, extract the real-time refreshed signal-to-noise ratio value and the corresponding signal strength value from the physical layer register, normalize the collected raw data to eliminate dimensional differences, and generate a standardized RF characteristic parameter set. S12: Obtain the standardized signal-to-noise ratio and standardized signal strength from the standardized radio frequency characteristic parameter set, assign corresponding weighting coefficients to the two according to the preset communication quality weight allocation model, calculate the link communication status index at the current moment through the linear weighted summation algorithm, and generate the link quality score. S13: Establish a sliding time window containing several continuous sampling points, store the link quality score in the buffer queue of the time window, calculate the statistical variance of all score data in the queue to characterize the fluctuation of channel stability, dynamically fit the fluctuation variance with the benchmark congestion coefficient, and generate a congestion judgment threshold.

[0021] The process of calculating the link quality score specifically includes: Obtain the signal-to-noise ratio (SNR) and signal strength values, and calculate the link quality score using the following formula, based on the weighting of the channel environment's impact on communication stability: ; in, Represents the link quality score. This represents the signal-to-noise ratio value currently being read. This represents the theoretical maximum signal-to-noise ratio of the radio frequency chip. This represents the current signal strength value. Represents the standard reference signal strength. This represents the preset signal-to-noise ratio weighting factor. This represents the duration for which the link remains connected.

[0022] The system periodically scans the current operating frequency band using the RF driver interface, extracts the real-time refreshed signal-to-noise ratio (SNR) and corresponding signal strength (SQL) values ​​from the physical layer registers, and normalizes the acquired raw data to eliminate dimensional differences, generating a standardized RF characteristic parameter set. It accesses the RF front-end chip on the wireless network camera's motherboard via the serial peripheral interface, locks onto the currently operating 5.8GHz frequency band, and reads the baseband processor's status register address with a sampling period of 50 milliseconds. It then obtains the current SNR value and received signal strength indication. Assuming the raw SNR value read at the sampling time is 35dB and the raw SQL value is -65dBm, a minimax normalization algorithm is used to preprocess the data, setting the effective range for SNR to 0dB to 50dB and the effective range for SQL to -95dBm to -30dBm. For a signal-to-noise ratio (SNR) of 35 dB, dividing it by the range of 50 yields a standardized SNR of 0.7; for a signal strength of -65 dBm, mapping it to a scale range of 0 to 100 yields a calculated result of approximately 46. The processed values ​​are then encapsulated and stored in a standardized RF characteristic parameter set.

[0023] The aforementioned minima-maximum normalization algorithm is a method for linearly transforming the original data. By mapping the data to a specified range of values, it eliminates the influence of different physical dimensions on data analysis.

[0024] Obtain the standardized signal-to-noise ratio (SNR) and standardized signal strength from the standardized RF characteristic parameter set. Assign corresponding weighting coefficients to both based on a pre-defined communication quality weighting model. Calculate the link communication status index at the current moment using a linear weighted summation algorithm to generate a link quality score. Considering the impact of multipath effects on demodulation error rate in industrial monitoring scenarios, set the SNR weighting factor to 0.6 and the corresponding signal strength weighting factor to 0.4. Calculate the link quality score using the following formula: ; in, Represents the link quality score; This represents the preset signal-to-noise ratio weighting factor, with a value of 0.6; This represents the current signal-to-noise ratio value, with a value of 35. This represents the theoretical maximum signal-to-noise ratio of the RF chip, with a value of 50. This represents the scale value mapped from the currently read signal strength value, and its value is 46. The standard reference signal strength scale value is 80. This represents the duration the link remains connected, in seconds, and has a value of 100. This represents the rating scaling factor, used to map the calculation results to a standard score range, with a value of 60.

[0025] Substituting the above parameters into the formula for calculation: the first term, signal-to-noise ratio, is 0.6 multiplied by 0.7, resulting in 0.42; the second term, signal strength ratio, is 46 divided by 80, resulting in 0.575; the time logarithm term is the natural logarithm of 101, which is approximately 4.615; multiplying these three terms together yields 1.061; summing the two terms gives 1.481; finally, multiplying by a scaling factor of 60, we obtain the current link quality score of 88.86.

[0026] A sliding time window containing several consecutive sampling points is established. Link quality scores are stored in a buffer queue within this time window. The statistical variance of all score data in the queue is calculated to characterize the fluctuation of channel stability. This variance is dynamically fitted to a baseline congestion coefficient to generate a congestion threshold. A FIFO circular queue of length 20 is allocated in memory as the sliding time window, maintaining 20 sampling points from the most recent second within each window. All score data in the queue are iterated, and their arithmetic mean and sample variance are calculated. Assume the currently calculated variance is 4.0. The congestion threshold is adjusted using a dynamic fitting algorithm, setting the baseline congestion coefficient to 70 points and the sensitivity adjustment coefficient to 0.5. The square root of the variance is multiplied by the sensitivity adjustment coefficient, and then the product is subtracted from the baseline congestion coefficient (70 minus 0.5 multiplied by 2), resulting in 69 points, which is used as the congestion threshold for the current moment.

[0027] Table 1 lists examples of link quality score calculations under different environmental parameters; As shown in Table 1, through formula calculation and scaling transformation, complex radio frequency parameters can be quantified into intuitive quality scores, which accurately reflect the communication degradation in strong interference warehouse scenarios.

[0028] Please see Figure 1 and Figure 3S2: Capture the photoelectric shot noise at the bottom layer of the CMOS sensor during the image acquisition interval, map the analog level of the photoelectric shot noise to a preset quantization range and convert it into a true random entropy source sequence, and generate a dynamic session key by performing an XOR logic operation between the true random entropy source sequence and the clock jitter frequency.

[0029] The S2 execution process is as follows: S21: Monitor the vertical synchronization signal of the CMOS image sensor, and start the bottom noise acquisition circuit in the vertical blanking interval after each frame of image transmission is completed to capture the photoelectric shot noise generated by thermally excited electrons of the photodiode under no light conditions. S22: Acquire the weak analog voltage signal of photoelectric shot noise, input it into a high-precision analog-to-digital converter, divide it into several nonlinear quantization levels according to the preset voltage amplitude distribution range, map the voltage value of the sampling point into the corresponding binary digital code, and generate a true random entropy source sequence. S23: Obtain the microsecond-level clock jitter frequency data generated by the motherboard crystal oscillator circuit during operation, perform a bit-by-bit XOR logic operation between the true random entropy source sequence and the clock jitter frequency data, use the operation result to break down the correlation of the original sequence, extract a fixed-length bit stream, and generate a dynamic session key.

[0030] The generation process of a true random entropy source sequence specifically includes: The analog voltage amplitude of photoelectric shot noise is obtained, a set of quantization thresholds containing multiple non-uniform distribution intervals is established, and the analog voltage amplitude is compared with the boundary thresholds of each interval step by step. When the voltage amplitude falls into the high probability density range, it is mapped to a low-bit-width binary code. When the voltage amplitude falls into the long-tailed range of low probability density, it is mapped to a high-bit-width binary code. By splicing the binary code streams obtained from each sampling time, a true random entropy source sequence is generated.

[0031] The system monitors the vertical sync signal of the CMOS image sensor and activates the underlying noise acquisition circuit during the vertical blanking interval after each frame of image transmission to capture photoelectric shot noise generated by thermally excited electrons in photodiodes under no-light conditions. The circuit is connected to the sensor's vertical sync signal line via the main control chip's general-purpose input / output pins and configured for falling-edge triggered interrupts. When a transition in the vertical sync signal into the approximately 1.2 ms vertical blanking interval is detected, a command is immediately sent to disable automatic gain control and automatic exposure algorithms, and the reset transistors of the pixel array are placed in the off state. The charge accumulation in the dark pixel areas masked by the metal layer is read to obtain a clean thermal noise signal.

[0032] The aforementioned vertical blanking interval refers to the time interval in video signal transmission between the end of scanning from the lower right corner of one frame and the beginning of scanning from the upper left corner of the next frame.

[0033] A weak analog voltage signal with photoelectric shot noise is acquired and input into a high-precision analog-to-digital converter (ADC). Based on a preset voltage amplitude distribution range, several nonlinear quantization levels are defined, mapping the voltage values ​​of the sampled points to corresponding binary digital codes to generate a true random entropy source sequence. First, the weak analog signal is amplified by a 60dB gain using a low-noise amplifier before being input to a 12-bit successive approximation ADC. The center reference voltage is set to 1.650V, and the standard deviation is 0.01V. A set of quantization thresholds containing multiple non-uniform distribution intervals is established. If the sampled voltage value falls within the high probability density interval of 1.645V to 1.655V, it is mapped to a 1-bit binary code; if it falls within the medium probability interval of 1.640V to 1.645V or 1.655V to 1.660V, it is mapped to a 2-bit binary code; if it falls within the long-tail interval of less than 1.640V or greater than 1.660V, it is mapped to a 3-bit binary code. For example, when the sample value is 1.652V, the output is binary code 1, and when the sample value is 1.638V, the output is binary code 100. The code streams obtained from the conversion at each sampling time are concatenated sequentially to generate a true random entropy source sequence.

[0034] The system acquires microsecond-level clock jitter frequency data generated by the motherboard crystal oscillator circuit during operation. A bitwise XOR operation is performed between the true random entropy source sequence and this clock jitter frequency data. The result is used to break down the correlation of the original sequence, and a fixed-length bit stream is extracted to generate a dynamic session key. Utilizing the frequency drift between the 200MHz main system crystal oscillator and the 32.768kHz real-time clock crystal oscillator, the low-order byte of the count value is latched in a high-frequency counter, and clock jitter data sequences are continuously acquired 128 times. A bitwise XOR operation is then performed between the previously generated true random entropy source sequence and this clock jitter data sequence. The result is then SHA-256 hashed, and the first 128 bits are extracted as the AES dynamic session key.

[0035] Please see Figure 1 and Figure 4 S3: Parse the monitoring video stream to separate I-frame data and P-frame data, compare the link quality score with the congestion judgment threshold, and when the judgment is lower than the threshold, retrieve the dynamic session key to perform AES encryption on the I-frame data to generate core ciphertext, and perform CRC check on the P-frame data to generate integrity check code.

[0036] The S3 execution process is as follows: S31: Parse H.264 or H.265 format surveillance video streams, and demultiplex the video stream into I-frame data containing key image information and P-frame data containing differentiated motion vectors by identifying the frame type identifier in the header of the network extraction layer unit. S32: Obtain the link quality score and congestion judgment threshold, compare the two values ​​in real time, and if the link quality score is found to be less than the congestion judgment threshold, determine that the current channel is in a state of high congestion and high packet loss risk, and generate a strong encryption trigger signal. S33: In response to the strong encryption trigger signal, the dynamic session key is retrieved to initialize the AES encryption engine. The I-frame data is divided into blocks for encryption using the cipher block chaining mode to generate the core ciphertext. The polynomial remainder of the P-frame data is calculated using the cyclic redundancy check algorithm to generate the integrity check code.

[0037] The generation process of the core ciphertext specifically includes: The I-frame data to be encrypted is obtained and divided into several 128-bit fixed data blocks. A randomly generated initialization vector is introduced and XORed with the first plaintext data block. The dynamic session key is retrieved and XORed with the result to perform multiple rounds of byte substitution, row shifting, column mixing, and round key addition transformation. The ciphertext output of the previous round is used as the XOR input factor of the plaintext block in the next round. The chain encryption operation of all data blocks is completed in sequence to generate the core ciphertext.

[0038] The system parses H.264 or H.265 format surveillance video streams. By identifying the frame type identifier in the network extraction layer unit header, it demultiplexes the video stream into I-frame data containing key image information and P-frame data containing differential motion vectors. It scans the video stream buffer data, locates the start code, and reads the header bytes of the network extraction layer unit. The frame type identifier is parsed; if the value is 19 or 20, it is determined to be an instant-decoding refresh I-frame, and its payload is extracted to the keyframe buffer; if the value is 0 to 9, it is determined to be a P-frame, and its payload is extracted to the differential frame buffer.

[0039] The system acquires the link quality score and congestion threshold, and compares their values ​​in real time. If the link quality score is lower than the congestion threshold, the current channel is determined to be in a high-congestion, high-packet-loss-risk state, and a strong encryption trigger signal is generated. The system reads the current link quality score, assuming it has dropped to 65 points due to environmental interference; simultaneously, it reads the current congestion threshold, assuming it is 70 points. The comparison shows that 65 is less than 70, indicating the channel is in a high-risk state, and the security control register is set to generate a strong encryption trigger signal.

[0040] In response to a strong encryption trigger signal, the dynamic session key is retrieved to initialize the AES encryption engine. Block-chaining encryption is performed on the I-frame data using ciphertext block chaining mode to generate the core ciphertext. A cyclic redundancy check (CRC) algorithm is used to calculate the polynomial remainder of the P-frame data, generating an integrity check code. A 128-bit dynamic session key is read from the secure storage area, and the hardware accelerator is initialized to ciphertext block chaining mode. A 128-bit random initialization vector is generated, dividing the I-frame data into 16-byte blocks. The first plaintext block is XORed with the initialization vector, and the result is input into the encryption core to perform 10 rounds of byte substitution, row shifting, column mixing, and round key addition transformations. The ciphertext output of the previous round is used as the XOR input factor for the next plaintext block, and this chain encryption of all data blocks is completed sequentially to generate the core ciphertext. Simultaneously, the CRC32 algorithm is used to calculate the 32-bit integrity check code for the P-frame data.

[0041] The aforementioned cipher block chaining mode refers to a block cipher operating mode in which each plaintext block is XORed with the preceding ciphertext block before encryption, so that each ciphertext block depends on all the plaintext blocks preceding it.

[0042] Please see Figure 1 and Figure 5 S4: Interweave and reassemble the core ciphertext and integrity check code according to the error correction coding rate of the link quality score inverse mapping to construct a security protocol data frame. Embed the encryption policy index value in the physical layer header of the security protocol data frame to drive the wireless transmission unit to perform data transmission.

[0043] The S4 execution process is as follows: S41: Obtain the link quality score, query the preset mapping table between channel quality and forward error correction coding rate, select the redundancy check bit length that is inversely proportional to the current score, and determine the error correction coding rate; S42: Obtain the core ciphertext and integrity check code, generate redundant check data according to the error correction coding rate, and use a pseudo-random interleaving algorithm to discretize and rearrange the data bit stream and check bit stream to prevent continuous data loss due to sudden bit errors, and construct a secure protocol data frame. S43: Extract the algorithm type identifier and key version number used in this encryption process, combine them to generate an encryption strategy index value, write the index value into the physical layer preamble field of the security protocol data frame, send a transmission command to the radio frequency transmission circuit, and drive the wireless transmission unit to perform data transmission.

[0044] The process of constructing a security protocol data frame specifically includes: Obtain the interleaved and reassembled mixed bit stream and establish a link layer frame header structure containing a synchronization word, frame length indicator, source address and destination address; The encryption policy index value is encapsulated into a custom extended frame header field, the mixed bit stream is filled into the data field as payload data, and a cyclic redundancy check code for physical layer frame verification sequence is added to the end of the frame to complete the standardized assembly of the data packet structure and construct a secure protocol data frame.

[0045] Obtain the link quality score, query the preset mapping table between channel quality and forward error correction coding rate, select the redundancy check bit length inversely proportional to the current score, and determine the error correction coding rate. For a score of 65, querying the mapping table reveals that it falls within the range of 50 to 70, so a 1 / 2 coding rate is determined. That is, for every 1 bit of valid data, 1 bit of redundant data is generated to enhance error correction capability.

[0046] The core ciphertext and integrity check code are obtained. Redundant check data is generated according to the error correction coding rate. A pseudo-random interleaving algorithm is used to discretize and rearrange the data bitstream and check bitstream to prevent continuous data loss due to burst errors, thus constructing a secure protocol data frame. The merged bitstream is input into a convolutional encoder to generate an encoded stream. A 16x16 interleaving matrix is ​​established, and data is written row by row and read column by column, distributing adjacent bits to different transmission time slots. The interleaved data is then used as payload to fill the data frame.

[0047] The algorithm type identifier and key version number used in this encryption process are extracted and combined to generate an encryption policy index value. This index value is written into the physical layer preamble field of the security protocol data frame, and a transmission command is sent to the radio frequency transmitting circuit to drive the wireless transmitting unit to perform data transmission. An 8-bit encryption policy index value is generated, with the high 4 bits identifying the AES-CBC plus CRC32 policy and the low 4 bits identifying the key version. This index value is encapsulated in a custom extended frame header, and the data frame is moved to the baseband transmit buffer via direct memory access to drive the radio frequency circuit to perform transmission.

[0048] Table 2. Adaptive Error Correction and Interleaving Strategy Configuration Table; As shown in Table 2, the system dynamically adjusts the redundancy and interleaving depth based on the score. In the embodiment with a score of 65, a 1 / 2 coding rate is used in combination with 16x16 interleaving, which can effectively combat the risk of packet loss caused by channel congestion.

[0049] A wireless network camera motherboard security communication protocol optimization system is provided. This system is used to execute the aforementioned wireless network camera motherboard security communication protocol optimization method. The system includes: The channel state monitoring module is configured to read the signal-to-noise ratio (SNR) and signal strength (SQS) values ​​from the radio frequency front-end of the wireless network camera motherboard, calculate the link quality score using the weighted product of the SNR and SQS values, and construct a congestion judgment threshold based on the variance of the link quality score within a time window. The entropy source key extraction module is configured to capture photoelectric shot noise at the bottom layer of the CMOS sensor during image acquisition intervals, map the analog level of the photoelectric shot noise to a preset quantization range and convert it into a true random entropy source sequence, and generate a dynamic session key through the XOR logic operation of the true random entropy source sequence and the clock jitter frequency. The adaptive hierarchical encryption module is configured to parse the monitoring video stream, separate I-frame data and P-frame data, compare the link quality score with the congestion judgment threshold, and when the judgment is lower than the threshold, retrieve the dynamic session key to perform AES encryption on the I-frame data to generate core ciphertext, and perform CRC check on the P-frame data to generate integrity check code. The protocol frame encapsulation and transmission module is configured to interleave and reassemble the core ciphertext and integrity check code according to the error correction coding rate that is reverse-mapped according to the link quality score to construct a secure protocol data frame. The encryption policy index value is embedded in the physical layer header of the secure protocol data frame to drive the wireless transmission unit to perform data transmission.

[0050] The above embodiments illustrate preferred embodiments of the present invention. Any equivalent adjustments to the technical solution based on software engineering methods are within the scope of protection, including but not limited to: implementing algorithm logic using different programming languages, refactoring functional modules into services, adjusting data interaction protocols, and optimizing resource scheduling strategies. Any implementation scheme derived from reasonable modifications to the data processing flow, service call chain, or system architecture layer without departing from the core technology of the present invention should be considered within the protection scope defined by the technical solution of the present invention.

Claims

1. A method for optimizing the secure communication protocol of a wireless network camera motherboard, characterized in that, Includes the following steps: S1: Read the signal-to-noise ratio (SNR) and signal strength values ​​of the radio frequency front-end of the wireless network camera motherboard, calculate the link quality score using the weighted product of the SNR and signal strength values, and construct a congestion judgment threshold based on the fluctuation variance of the link quality score within the time window. S2: Capture the photoelectric shot noise at the bottom layer of the CMOS sensor during the image acquisition interval, map the analog level of the photoelectric shot noise to a preset quantization range and convert it into a true random entropy source sequence, and generate a dynamic session key by performing an XOR logic operation between the true random entropy source sequence and the clock jitter frequency. S3: Parse the monitoring video stream to separate I-frame data and P-frame data, compare the link quality score with the congestion judgment threshold, and when the judgment is lower than the threshold, retrieve the dynamic session key to perform AES encryption on the I-frame data to generate core ciphertext, and perform CRC check on the P-frame data to generate integrity check code. S4: Interweave and reassemble the core ciphertext and the integrity check code according to the error correction coding rate of the link quality score inverse mapping to construct a security protocol data frame. Embed the encryption policy index value in the physical layer header of the security protocol data frame to drive the wireless transmission unit to perform data transmission.

2. The method for optimizing the secure communication protocol of a wireless network camera motherboard according to claim 1, characterized in that, The execution process of S1 is as follows: S11: Call the RF drive interface to periodically scan the current working frequency band, extract the real-time refreshed signal-to-noise ratio value and the corresponding signal strength value from the physical layer register, normalize the collected raw data to eliminate dimensional differences, and generate a standardized RF feature parameter set. S12: Obtain the standardized signal-to-noise ratio and standardized signal strength from the standardized radio frequency characteristic parameter set, assign corresponding weighting coefficients to the two according to the preset communication quality weight allocation model, calculate the link communication status index at the current moment through the linear weighted summation algorithm, and generate the link quality score; S13: Establish a sliding time window containing several continuous sampling points, store the link quality score in the buffer queue of the time window, calculate the statistical variance of all score data in the queue to characterize the fluctuation of channel stability, dynamically fit the fluctuation variance with the benchmark congestion coefficient, and generate the congestion judgment threshold.

3. The method for optimizing the secure communication protocol of a wireless network camera motherboard according to claim 1, characterized in that, The execution process of S2 is as follows: S21: Monitor the vertical synchronization signal of the CMOS image sensor, and activate the bottom noise acquisition circuit in the vertical blanking interval after each frame of image transmission is completed to capture the photoelectric shot noise generated by thermally excited electrons of the photodiode under no light conditions. S22: Acquire the weak analog voltage signal of the photoelectric shot noise, input it into a high-precision analog-to-digital converter, divide it into several nonlinear quantization levels according to the preset voltage amplitude distribution range, map the voltage value of the sampling point into the corresponding binary digital code, and generate the true random entropy source sequence. S23: Obtain the microsecond-level clock jitter frequency data generated by the motherboard crystal oscillator circuit during operation, perform a bit-by-bit XOR logic operation between the true random entropy source sequence and the clock jitter frequency data, use the operation result to break down the correlation of the original sequence, extract a fixed-length bit stream, and generate the dynamic session key.

4. The method for optimizing the secure communication protocol of a wireless network camera motherboard according to claim 1, characterized in that, The execution process of S3 is as follows: S31: Parse H.264 or H.265 format surveillance video streams, and demultiplex the video stream into I-frame data containing key image information and P-frame data containing differentiated motion vectors by identifying the frame type identifier in the header of the network extraction layer unit. S32: Obtain the link quality score and the congestion determination threshold, compare the values ​​of the two in real time, and if the link quality score is found to be less than the congestion determination threshold, determine that the current channel is in a state of high congestion and high packet loss risk, and generate a strong encryption trigger signal. S33: In response to the strong encryption trigger signal, the dynamic session key is retrieved to initialize the AES encryption engine, and the I-frame data is block-wise encrypted using the cipher block chaining mode to generate the core ciphertext. The polynomial remainder of the P-frame data is calculated using the cyclic redundancy check algorithm to generate the integrity check code.

5. The method for optimizing the secure communication protocol of a wireless network camera motherboard according to claim 1, characterized in that, The execution process of S4 is as follows: S41: Obtain the link quality score, query the preset mapping table between channel quality and forward error correction coding rate, select the redundancy check bit length that is inversely proportional to the current score, and determine the error correction coding rate; S42: Obtain the core ciphertext and the integrity check code, generate redundant check data according to the error correction coding rate, and use a pseudo-random interleaving algorithm to discretize and rearrange the data bit stream and check bit stream to prevent burst errors from causing continuous data loss, and construct the security protocol data frame; S43: Extract the algorithm type identifier and key version number used in this encryption process, combine them to generate the encryption strategy index value, write the index value into the physical layer preamble field of the security protocol data frame, send a transmission command to the radio frequency transmission circuit, and drive the wireless transmission unit to perform data transmission.

6. The method for optimizing the secure communication protocol of a wireless network camera motherboard according to claim 2, characterized in that, The process of calculating the link quality score specifically includes: The signal-to-noise ratio (SNR) and signal strength values ​​are obtained. Based on the weighting of the channel environment's impact on communication stability, the link quality score is calculated using the following formula: ; in, This represents the link quality score. This represents the signal-to-noise ratio value currently being read. This represents the theoretical maximum signal-to-noise ratio of the radio frequency chip. This represents the signal strength value currently being read. Represents the standard reference signal strength. This represents the preset signal-to-noise ratio weighting factor. This represents the duration for which the link remains connected.

7. The method for optimizing the secure communication protocol of a wireless network camera motherboard according to claim 3, characterized in that, The generation process of the true random entropy source sequence specifically includes: The analog voltage amplitude of the photoelectric shot noise is obtained, a set of quantization thresholds containing multiple non-uniform distribution intervals is established, and the analog voltage amplitude is compared with the boundary thresholds of each interval step by step. When the voltage amplitude falls into the high probability density range, it is mapped to a low-bit-width binary code. When the voltage amplitude falls into the long-tail range of the low probability density, it is mapped to a high-bit-width binary code. The true random entropy source sequence is generated by splicing the binary code streams obtained from the conversion at each sampling time.

8. The method for optimizing the secure communication protocol of a wireless network camera motherboard according to claim 4, characterized in that, The generation process of the core ciphertext specifically includes: The I-frame data to be encrypted is obtained and divided into several 128-bit fixed data blocks. A randomly generated initialization vector is introduced and XORed with the first plaintext data block. The dynamic session key is retrieved and XORed with the result to perform multiple rounds of byte substitution, row shifting, column mixing, and round key addition transformation. The ciphertext output of the previous round is used as the XOR input factor of the plaintext block in the next round. The chain encryption operation of all data blocks is completed in sequence to generate the core ciphertext.

9. The method for optimizing the secure communication protocol of a wireless network camera motherboard according to claim 5, characterized in that, The construction process of the security protocol data frame specifically includes: Obtain the interleaved and reassembled mixed bit stream and establish a link layer frame header structure containing a synchronization word, frame length indicator, source address and destination address; The encryption policy index value is encapsulated into a custom extended frame header field, the mixed bit stream is filled into the data field as payload data, and a cyclic redundancy check code for physical layer frame verification sequence is added to the end of the frame to complete the standardized assembly of the data packet structure and construct the security protocol data frame.

10. A wireless network camera motherboard security communication protocol optimization system, characterized in that, The system is used to implement the wireless network camera motherboard security communication protocol optimization method according to any one of claims 1-9, the system comprising: The channel state monitoring module is configured to read the signal-to-noise ratio (SNR) and signal strength (SQS) values ​​of the radio frequency front-end of the wireless network camera motherboard, calculate the link quality score using the weighted product of the SNR and SQS values, and construct a congestion judgment threshold based on the fluctuation variance of the link quality score within a time window. The entropy source key extraction module is configured to capture photoelectric shot noise at the bottom layer of the CMOS sensor during the image acquisition interval, map the analog level of the photoelectric shot noise to a preset quantization range and convert it into a true random entropy source sequence, and generate a dynamic session key through the XOR logic operation of the true random entropy source sequence and the clock jitter frequency. An adaptive hierarchical encryption module is configured to parse the monitoring video stream to separate I-frame data and P-frame data, compare the link quality score with the congestion judgment threshold, and when the judgment is lower than the threshold, retrieve the dynamic session key to perform AES encryption on the I-frame data to generate core ciphertext, and perform CRC check on the P-frame data to generate an integrity check code. The protocol frame encapsulation and transmission module is configured to interleave and reassemble the core ciphertext and the integrity check code according to the error correction coding rate that is reverse-mapped by the link quality score to construct a secure protocol data frame. An encryption policy index value is embedded in the physical layer header of the secure protocol data frame to drive the wireless transmission unit to perform data transmission.