File tamper-proof playing method and system of railway public electronic screen
Patent Information
- Application Number
- CN202610616768.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-07
- Publication Date
- 2026-09-22
AI Technical Summary
现有方案多侧重于对人员权限和系统访问的控制,而未能在终端侧对媒体文件的真实性、完整性和审核来源进行可靠校验,导致内容安全仍然存在隐患
[0019](1)本发明构建了铁路公共电子屏媒体文件从制作、审核、下发到播放的全链路防篡改防护体系,通过国密算法生成内容指纹摘要、多级链式的多级签名文件、终端侧逐级验签与指纹对比,从文件本身实现真实性和完整性校验,彻底解决了文件在传输链路被劫持、离线介质被修改、终端侧被替换等问题,同时突破了传统仅依赖物理隔离、权限控制的防护短板,有效杜绝内容篡改、恶意插播等安全事件,保障铁路行车信息、客运公告等权威内容的发布安全,维护车站运营秩序和社会稳定;
Smart Images

Figure CN122802179A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of railway information security technology, and more specifically, to a method and system for preventing file tampering on railway public electronic screens. Background Technology
[0002] With the continuous advancement of urban informatization and intelligent transportation construction, public electronic screens are increasingly widely used in public spaces such as stations, shopping malls, and transportation hubs, becoming an important medium for information dissemination, advertising display, cultural promotion, and emergency guidance. Electronic screens typically feature independent playback sources, diverse multimedia content formats, and frequent information updates. While improving information dissemination efficiency, this also significantly amplifies their potential security risks.
[0003] Among numerous application scenarios, the security management of public electronic screens in railway stations is particularly critical. These screens display highly authoritative content such as train schedules, passenger announcements, and emergency alerts, and their playback directly impacts passenger travel order and social stability. Any security incidents, such as content tampering, misbroadcasting, or malicious interruptions, can severely disrupt normal station operations and potentially cause extremely negative social consequences. However, overall, there are significant differences in the security protection capabilities of electronic screens across different railway bureaus and stations. Stations of different sizes and management levels have varying levels of security investment and technical means. Some older stations or those with insufficient investment still primarily rely on traditional methods such as physical isolation and basic network protection, lacking effective technical protection for the content being broadcast.
[0004] Furthermore, railway public electronic display systems generally suffer from "security silos." The electronic displays and their associated content production, review, publishing, and playback systems are often built by different vendors, employing their own independent technical architectures and security strategies. This lack of a unified trust system and security collaboration mechanism makes cross-system and cross-level security management difficult. Regarding content security, although most railway systems have established manual or semi-automated content review processes, there is a lack of effective technical means to ensure that the content actually played on the terminal is necessarily the original, approved file. Between content production and terminal playback, there is still a risk of file replacement, tampering, or attacks on the transmission link (such as hijacking of the push channel or malicious modification of offline media). Existing solutions mostly focus on controlling personnel permissions and system access, failing to reliably verify the authenticity, integrity, and review source of media files on the terminal side, leaving content security vulnerabilities unresolved. Summary of the Invention
[0005] The purpose of this invention is to provide a method and system for preventing file tampering on railway public electronic display screens, thereby improving the aforementioned problems. To achieve the above objective, the technical solution adopted by this invention is as follows:
[0006] Firstly, this application provides a method for preventing file tampering on railway public electronic screens, including:
[0007] Get the media file to be played;
[0008] After performing digest calculations and file compression on the media files, multi-level content review and signing are performed to obtain multi-level signed files;
[0009] The approved media files and corresponding multi-level signature files will be distributed to the terminal side of the railway public electronic screen;
[0010] On the terminal side, the multi-level signature file is verified level by level based on the authorized trust list to obtain the verification result;
[0011] The media file is played based on the verification result.
[0012] Secondly, this application also provides a document anti-tampering playback system for railway public electronic screens, including:
[0013] The acquisition unit is used to acquire the media file to be played.
[0014] The signature unit is used to perform digest calculation and file compression on the media file, and then perform multi-level content review and signature to obtain a multi-level signed file;
[0015] The distribution unit is used to distribute the approved media files and corresponding multi-level signature files to the terminal side of the railway public electronic screen;
[0016] The signature verification unit is used on the terminal side to perform step-by-step signature verification on the multi-level signature file based on the authorized trust list, and obtain the signature verification result.
[0017] The playback unit is used to play the media file based on the verification result.
[0018] The beneficial effects of this invention are as follows:
[0019] (1) This invention constructs a full-link anti-tampering protection system for railway public electronic screen media files from production, review, distribution to playback. It generates content fingerprint digests through national cryptographic algorithms, multi-level chain signature files, and terminal-side step-by-step signature verification and fingerprint comparison. It realizes the authenticity and integrity verification of the file itself, and completely solves the problems of file hijacking in the transmission link, offline media modification, and terminal-side replacement. At the same time, it breaks through the shortcomings of traditional protection that only relies on physical isolation and access control, effectively prevents security incidents such as content tampering and malicious insertion, ensures the security of the release of authoritative content such as railway traffic information and passenger announcements, and maintains the station operation order and social stability.
[0020] (2) The multi-level review and signature mechanism of this invention can match the railway hierarchical management architecture, avoid the risks of single-point authorization and unauthorized operation, and the responsible party can be traced for each level of signature; the terminal side realizes offline signature verification based on the pre-configured authorized trust list, without relying on the external real-time network, and can be adapted to the no-network / weak-network scenarios such as railway stations and sections along the line. At the same time, the multi-dimensional lossless compression algorithm improves the review and transmission efficiency while ensuring no content loss. The unified signature verification rules also break the security silos of the railway electronic screen system, establish a unified trust system across systems and levels, and improve the standardization and collaboration of the content security management of railway public electronic screens.
[0021] Other features and advantages of the invention will be set forth in the following description, and will be apparent in part from the description, or may be learned by practicing embodiments of the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures particularly pointed out in the written description, claims, and drawings. Attached Figure Description
[0022] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0023] Figure 1 This is a schematic diagram of the file anti-tampering playback method for railway public electronic screens as described in this embodiment of the invention;
[0024] Figure 2 This is a schematic diagram of the file anti-tampering playback system for railway public electronic screens as described in this embodiment of the invention. Detailed Implementation
[0025] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention.
[0026] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this invention, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.
[0027] Example 1:
[0028] This embodiment provides a method for preventing file tampering on railway public electronic screens.
[0029] Understandably, railway public electronic screens are deployed in a wide range of locations and display diverse content. For example, public electronic screens in railway station waiting halls and platforms need to display key passenger service information in real time, such as service suspension announcements and safety notices. Secondly, public electronic screens set up along railway lines, near tunnel entrances, and bridges need to display safety warning slogans (such as "Do not climb over guardrails"), construction notices, and emergency rescue information. Furthermore, public electronic screens set up in railway stations and along railway lines may also display legal commercial advertisements (such as cultural and tourism promotions and public service announcements) or public service announcements.
[0030] In order to prevent electronic screen content accidents from disrupting the normal order of public places, it is necessary to implement security management for railway public electronic screens. Therefore, the file anti-tampering playback method provided in this embodiment can ensure the authenticity, compliance and integrity of the content published on railway public electronic screens, and avoid malicious tampering or illegal content placement.
[0031] See Figure 1 The figure shows that the method includes steps S1, S2, S3, S4 and S5.
[0032] Step S1: Obtain the media file to be played;
[0033] In this step, the media files to be played are media content provided by an authorized entity. The authorized entity uploads the media files to the review platform. The authorized entity can be a railway internal management department, a publicity party authorized by the railway management department, etc. Railway internal management departments provide media files related to train operation information, passenger announcements, emergency notices, or internal management. Publicity parties provide promotional materials for public service announcements, commercial promotions, or image displays. Media files include video files, audio files, image files, or text files.
[0034] Step S2: After performing digest calculation and file compression on the media files, perform multi-level content review and signing to obtain multi-level signed files;
[0035] Step S2 includes:
[0036] Step S21: Perform digest calculation on the media file to generate a corresponding content fingerprint digest;
[0037] Step S21 includes:
[0038] Step S211: Perform format normalization processing on the media file;
[0039] This step involves format standardization, which includes:
[0040] Media files are uniformly converted to preset encoding formats and resolutions. Video files are uniformly framed and aligned with the timeline. Audio files are uniformly sampled, bit-depth, and number of channels. Redundant metadata in media files that do not affect the semantics of the content is removed.
[0041] Step S212: Extract feature data of media content based on the normalized media file. The feature data includes pixel features of video keyframes, temporal features of video frame sequences, spectral features of audio signals, and character sequence features of text content.
[0042] In this step, multiple video keyframes are selected from the video frame sequence, and the corresponding pixel feature vector is calculated for each video keyframe. Then, the pixel feature vectors of all video keyframes are aggregated to obtain the pixel features.
[0043] Based on the differential information between video frames, temporal features of the video frame sequence are extracted. After segmenting the audio signal into frames and performing a short-time Fourier transform, a spectrum matrix is obtained. This spectrum matrix is then input into a spectrum feature convergence function for calculation, yielding spectral features. The spectrum feature convergence function is used to statistically converge the spectrum matrix over time. Text content is segmented into words or encoded into character sequences to obtain character sequence features.
[0044] Step S213: Concatenate multiple feature data in a preset order and convert the concatenated feature data into a standardized byte sequence;
[0045] In this step, the concatenated feature data is quantized, encoded, and serialized into bytes to obtain a standardized byte sequence.
[0046] Step S214: Perform digest calculation on the byte sequence using the national cryptographic algorithm to generate the content fingerprint digest of the media file.
[0047] In this step, the standardized byte sequence is divided into blocks of fixed length to obtain a byte block sequence:
[0048] ;
[0049] In the formula, Represents a sequence of byte blocks. Indicates the first A block of data per byte. , Indicates the total number of byte blocks.
[0050] Then, the national cryptographic algorithm is used, based on byte block sequences. Perform a digest calculation to obtain the content fingerprint digest of the media file.
[0051] Step S22: Compress the acquired media file to be reviewed using a multidimensional lossless image compression algorithm to generate a lossless compressed media file;
[0052] Step S23: Determine the review levels and the review order of each review level according to the railway public electronic screen content management strategy;
[0053] In this step, the content review and playback authorization process is divided into multiple signature levels, such as corresponding to the content production or review department, the railway bureau or station management department, and the authorized publishing department, which are used for initial review, verification, and publication of the content, respectively. Furthermore, the review order is defined according to the railway public electronic screen content management strategy.
[0054] Step S24: In accordance with the review order, conduct content compliance review of the lossless compressed media file at each review level;
[0055] Step S25: If the review fails, the media file will be returned to the file publishing location;
[0056] Step S26: If the review is approved, the content fingerprint digest of the media file is signed to obtain the signature result of the corresponding review level, and then the content review of the next review level is initiated.
[0057] In this step, multi-level signatures can avoid the risk of single point of authorization. No single signature at any level can directly authorize playback. A complete link must be formed, and it must also comply with the hierarchical management of the railway system.
[0058] In step S26, signing the content fingerprint digest of the media file to obtain the signature result for the corresponding review level, and then proceeding to the next review level for content review, includes:
[0059] Step S261: Construct a data object to be signed using the content fingerprint digest, wherein the data object to be signed includes the content fingerprint digest, the approval identifier, and the current approval level identifier;
[0060] In this step, the approval mark indicates that the content has completed compliance review, while the current signature level mark indicates the responsible party for this signature, allowing each level of signature to be traced independently.
[0061] Step S262: Call the digital certificate of the current review level to digitally sign the data object to be signed, obtain the corresponding signature result, and proceed to the next review level for review.
[0062] In this step, a multi-level chain digital signature mechanism is adopted. By introducing the signature results of the previous level in subsequent review levels, an indivisible authorization signature chain is formed, which effectively prevents the risks of unauthorized access, skipping levels, and signature reorganization in the content authorization process.
[0063] Specifically, for the first The approval process has multiple levels, and the signature process is represented as follows:
[0064]
[0065] In the formula, Indicates the first Signature results at each review level Indicates adoption Digital signature algorithm, Indicates the first The private key corresponding to each audit level This indicates serialization processing. Indicates the first Data objects awaiting signature at each review level, This indicates a splicing operation. Indicates the first The signature results of each review level.
[0066] The digital signature algorithm can be RSA, ECDSA, or SM2, and the private key is the private key contained in the corresponding digital certificate. When... hour, This is a predefined empty signature placeholder used to indicate the starting state of a chain of signatures.
[0067] Once the signature at the current review level is completed, the process moves to the next level of signature until all review levels have been completed.
[0068] Step S27: After all review levels have passed the review, generate a multi-level signature file based on the signature results of all review levels.
[0069] The signature results generated at each review level are encapsulated to generate a multi-level signature file.
[0070] Step S3: Distribute the approved media files and corresponding multi-level signature files to the terminal side of the railway public electronic screen;
[0071] Step S4: On the terminal side, the multi-level signature file is verified level by level based on the authorized trust list to obtain the verification result;
[0072] In this step, the multi-level signature files issued on the railway public electronic screen terminal are digitally verified level by level to confirm that the media content being played has indeed undergone review and signature through a complete authorization chain, preventing unauthorized or tampered media files from being played.
[0073] Step S4 includes:
[0074] Step S41: On the terminal side, load a pre-configured authorized trust list, which includes digital certificates that are allowed for multi-level signatures;
[0075] In this process, the digital certificate must include at least a public key, certificate identification information, and certificate validity verification information.
[0076] On the terminal side, an authorized trust list is loaded from the local security zone or cryptographic module. This list can be imported offline by maintenance personnel or updated remotely via a secure channel. Therefore, the authorized trust list prevents the terminal from accepting signatures from unauthorized entities and avoids reliance on external real-time network verification, making it applicable to offline railway scenarios.
[0077] Step S42: Decrypt and verify the multi-level signature file using the authorized trust list;
[0078] Step S43: If decryption fails, generate a signature verification failure result;
[0079] In this step, if the parsed certificate identifier information is not in the authorized trust list, it indicates that the digital certificate used at the current signature level is not authorized and the generated signature is not legitimate. Therefore, a signature verification failure result is generated directly to prevent unauthorized certificates from participating in content signing.
[0080] Step S44: If decryption is successful, the content fingerprint digest is obtained;
[0081] In this step, signature verification is performed at each level, and all review levels must pass the verification before decryption can be successful, resulting in a content fingerprint digest. This ensures that only media content that has been signed through a complete authorization process and has not been tampered with can be played.
[0082] Step S45: Regenerate the real-time content fingerprint digest using the same fingerprint generation algorithm as when generating the content fingerprint digest for the media file received by the terminal side;
[0083] Step S46: Compare the real-time content fingerprint digest with the decrypted content fingerprint digest;
[0084] Step S47: If the comparison matches, generate a successful signature verification result; otherwise, generate a failed signature verification result.
[0085] Step S5: Play the media file based on the verification result.
[0086] Step S5 includes:
[0087] Step S51: When the signature verification result is a signature verification failure, refuse to save the media file locally;
[0088] Step S52: When the signature verification result is successful, save the media file locally;
[0089] Step S53: Arrange the playlist according to the playback plan, and play the media files stored locally based on the playlist.
[0090] Example 2:
[0091] like Figure 2 As shown, this embodiment provides a file anti-tampering playback system for railway public electronic screens, the system comprising:
[0092] The acquisition unit is used to acquire the media file to be played.
[0093] The signature unit is used to perform digest calculation and file compression on the media file, and then perform multi-level content review and signature to obtain a multi-level signed file;
[0094] The distribution unit is used to distribute the approved media files and corresponding multi-level signature files to the terminal side of the railway public electronic screen;
[0095] The signature verification unit is used on the terminal side to perform step-by-step signature verification on the multi-level signature file based on the authorized trust list, and obtain the signature verification result.
[0096] The playback unit is used to play the media file based on the verification result.
[0097] In this embodiment, as Figure 2 As shown, the review module includes an acquisition unit, a signature unit, and a distribution unit, which are used for content review, digest calculation, and document signing. The relevant keys, digital certificates, etc. can be obtained through cryptographic devices / modules.
[0098] The key management module is used to create and distribute authorized trust lists, as well as to create and distribute the keys used, and can be obtained through cryptographic devices / modules.
[0099] The terminal side of the railway public electronic display screen includes a signature verification unit and a playback unit. Signature verification can be performed by importing an authorized trust list, and the keys for signature verification and decryption are stored in the cryptographic module. Meanwhile, the information used to create the authorized trust list is obtained through the digital certificate management module.
[0100] The signature unit includes:
[0101] The summary calculation subunit is used to perform summary calculation on the media file and generate a corresponding content fingerprint summary;
[0102] The compression subunit is used to compress the acquired media files to be reviewed using a multidimensional lossless image compression algorithm to generate lossless compressed media files;
[0103] The sub-units are determined to identify the review levels and the review order of each review level, based on the content management strategy for railway public electronic screens.
[0104] The review subunit is used to review the content compliance of the lossless compressed media file at each review level according to the review order.
[0105] The first processing subunit is used to return the media file to the file publishing location if the review fails.
[0106] The second processing subunit is used to sign the content fingerprint digest of the media file if the review is passed, to obtain the signature result of the corresponding review level, and to proceed to the next review level for content review.
[0107] The first generation subunit is used to generate a multi-level signature file based on the signature results of all review levels after all review levels have passed the review.
[0108] The signature verification unit includes:
[0109] A loading subunit is used on the terminal side to load a pre-configured authorized trust list, the authorized trust list including digital certificates that allow for multi-level signatures;
[0110] The decryption subunit is used to decrypt and verify the multi-level signature file using the authorized trust list.
[0111] The third processing subunit is used to generate a signature verification failure result if decryption fails.
[0112] The fourth processing subunit is used to obtain the content fingerprint digest if the decryption is successful;
[0113] The second generation subunit is used to regenerate the real-time content fingerprint digest by using the same fingerprint generation algorithm as when generating the content fingerprint digest on the media file received by the terminal side.
[0114] The comparison subunit is used to compare the real-time content fingerprint digest with the decrypted content fingerprint digest;
[0115] The fourth processing subunit is used to generate a successful signature verification result when the comparison is consistent, and otherwise generate a signature verification failure result.
[0116] The playback unit includes:
[0117] The fifth processing subunit is used to refuse to store the media file locally when the signature verification result is a signature verification failure result;
[0118] The sixth processing subunit is used to store the media file locally when the signature verification result is successful.
[0119] The playback subunit is used to arrange playlists according to the playback plan and play media files stored locally based on the playlists.
[0120] It should be noted that the specific methods by which each module performs operations in the system described in the above embodiments have been described in detail in the embodiments related to the method, and will not be elaborated here.
[0121] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
[0122] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A method for preventing file tampering on a railway public electronic display screen, characterized in that, include: Get the media file to be played; After performing digest calculations and file compression on the media files, multi-level content review and signing are performed to obtain multi-level signed files; The approved media files and corresponding multi-level signature files will be distributed to the terminal side of the railway public electronic screen; On the terminal side, the multi-level signature file is verified level by level based on the authorized trust list to obtain the verification result; The media file is played based on the verification result.
2. The method for preventing file tampering on railway public electronic screens according to claim 1, characterized in that, After performing digest calculations and file compression on the media files, multi-level content review and signing are performed to obtain multi-level signed files, including: The media file is digested to generate a corresponding content fingerprint digest; The acquired media files to be reviewed are compressed using a multidimensional lossless image compression algorithm to generate lossless compressed media files. Based on the railway public electronic screen content management strategy, determine the review levels and the review order of each level; In accordance with the review order, the lossless compressed media files are subject to content compliance review at each review level; If the review fails, the media file will be returned to the file publishing location; If the review is approved, the content fingerprint digest of the media file is signed to obtain the signature result of the corresponding review level, and then the content review of the next review level is initiated. Once all review levels have passed the review, a multi-level signature file is generated based on the signature results from all review levels.
3. The method for preventing file tampering on railway public electronic screens according to claim 2, characterized in that, The step of performing digest calculation on the media file to generate a corresponding content fingerprint digest includes: The media files are then formatted and standardized. Feature data of media content is extracted based on the normalized media file. The feature data includes pixel features of video keyframes, temporal features of video frame sequences, spectral features of audio signals, and character sequence features of text content. Multiple feature data are concatenated in a preset order, and the concatenated feature data is converted into a standardized byte sequence; The byte sequence is digested using a national cryptographic algorithm to generate a content fingerprint digest of the media file.
4. The method for preventing file tampering on railway public electronic screens according to claim 2, characterized in that, The process of signing the content fingerprint digest of the media file to obtain the signature result for the corresponding review level, and then proceeding to the next review level for content review, includes: A data object to be signed is constructed using the content fingerprint digest, the data object to be signed including the content fingerprint digest, the approval identifier and the current approval level identifier; The digital certificate of the current review level is invoked to digitally sign the data object to be signed, the corresponding signature result is obtained, and the data is then reviewed at the next review level.
5. The method for preventing file tampering playback on railway public electronic screens according to claim 1, characterized in that, On the terminal side, the multi-level signature file is verified level by level based on the authorized trust list to obtain the verification result, including: On the terminal side, a pre-configured authorized trust list is loaded, which includes digital certificates that are allowed for multi-level signatures; The multi-level signature file is decrypted and verified using the authorized trust list; If decryption fails, a signature verification failure result will be generated; If decryption is successful, the content fingerprint digest will be obtained. The same fingerprint generation algorithm used when generating the content fingerprint digest is applied to the media file received by the terminal to regenerate the real-time content fingerprint digest; Compare the real-time content fingerprint digest with the decrypted content fingerprint digest; If the comparison matches, a successful signature verification result is generated; otherwise, a signature verification failure result is generated.
6. The method for preventing file tampering playback on railway public electronic screens according to claim 1, characterized in that, Playing the media file based on the signature verification result includes: When the signature verification result is a signature verification failure, the media file will not be saved locally. When the signature verification result is successful, the media file is saved locally; The playlist is arranged according to the playback plan, and the media files stored locally are played based on the playlist.
7. A file anti-tampering playback system for railway public electronic screens, characterized in that, include: The acquisition unit is used to acquire the media file to be played. The signature unit is used to perform digest calculation and file compression on the media file, and then perform multi-level content review and signature to obtain a multi-level signed file; The distribution unit is used to distribute the approved media files and corresponding multi-level signature files to the terminal side of the railway public electronic screen; The signature verification unit is used on the terminal side to perform step-by-step signature verification on the multi-level signature file based on the authorized trust list, and obtain the signature verification result. The playback unit is used to play the media file based on the verification result.
8. The document anti-tampering playback system for railway public electronic screens according to claim 7, characterized in that, The signature unit includes: The summary calculation subunit is used to perform summary calculation on the media file and generate a corresponding content fingerprint summary; The compression subunit is used to compress the acquired media files to be reviewed using a multidimensional lossless image compression algorithm to generate lossless compressed media files; The sub-units are determined to identify the review levels and the review order of each review level, based on the content management strategy for railway public electronic screens. The review subunit is used to review the content compliance of the lossless compressed media file at each review level according to the review order. The first processing subunit is used to return the media file to the file publishing location if the review fails. The second processing subunit is used to sign the content fingerprint digest of the media file if the review is passed, to obtain the signature result of the corresponding review level, and to proceed to the next review level for content review. The first generation subunit is used to generate a multi-level signature file based on the signature results of all review levels after all review levels have passed the review.
9. The anti-tampering playback system for railway public electronic screens according to claim 7, characterized in that, The signature verification unit includes: A loading subunit is used on the terminal side to load a pre-configured authorized trust list, the authorized trust list including digital certificates that allow for multi-level signatures; The decryption subunit is used to decrypt and verify the multi-level signature file using the authorized trust list. The third processing subunit is used to generate a signature verification failure result if decryption fails. The fourth processing subunit is used to obtain the content fingerprint digest if the decryption is successful; The second generation subunit is used to regenerate the real-time content fingerprint digest by using the same fingerprint generation algorithm as when generating the content fingerprint digest on the media file received by the terminal side. The comparison subunit is used to compare the real-time content fingerprint digest with the decrypted content fingerprint digest; The fourth processing subunit is used to generate a successful signature verification result when the comparison is consistent, and otherwise generate a signature verification failure result.
10. The document anti-tampering playback system for railway public electronic screens according to claim 7, characterized in that, The playback unit includes: The fifth processing subunit is used to refuse to store the media file locally when the signature verification result is a signature verification failure result; The sixth processing subunit is used to store the media file locally when the signature verification result is successful. The playback subunit is used to arrange playlists according to the playback plan and play media files stored locally based on the playlists.