A trusted video acquisition device with active security reinforcement
Patent Information
- Application Number
- CN202611036955.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-13
- Publication Date
- 2026-09-25
AI Technical Summary
[0003]GB/T 28181是公共安全视频监控核心标准,规定了 SIP 信令控制、RTP 媒体传输、H.264/H.265 编码格式,但是其并未解决传输层加密的问题
[0016]根据本发明提供的具备主动安全加固的可信视频采集设备,所述接入式加固模组还用于将所述加固媒体流数据包打乱顺序后,重新生成所述加固媒体流数据包的序列号和时间戳。
Smart Images

Figure CN122824874A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a trusted video capture device with proactive security hardening. Background Technology
[0002] Video data acquisition is a technology that uses devices such as image sensors, cameras, and encoders to convert optical signals into electrical signals, which are then converted into digital video data through analog-to-digital conversion, encoding compression, and network transmission. Its development has gone through three stages: coaxial cable analog transmission → fiber optic transmission → digital networked transmission. Currently, it is evolving towards networking, intelligence, and high definition, and is widely used in key areas such as security monitoring, traffic management, smart cities, financial anti-fraud, and medical imaging.
[0003] GB / T 28181 is a core standard for public security video surveillance, which specifies SIP signaling control, RTP media transmission, and H.264 / H.265 encoding formats, but it does not solve the problem of transport layer encryption.
[0004] Although GB 35114 specifies encryption schemes such as identity authentication (SM2), signaling encryption (SM2), media encryption (SM4), and integrity protection (SM3), it still has drawbacks, such as: 1. the existence of identifiable protocol fingerprints; 2. fixed length characteristics of encrypted packets; 3. lack of anomaly detection capabilities; 4. lack of automatic blocking mechanisms; making the security of this protocol still unable to meet the usage requirements.
[0005] Most existing IPC devices are hardened for security based on GB 35114, which cannot prevent side-channel attacks; cannot identify abnormal SIP signaling requests; cannot detect abnormal RTP stream injection; cannot detect port scanning, brute-force attacks, and vulnerability exploitation attacks; and cannot automatically block attacks after detecting anomalies. Summary of the Invention
[0006] This invention provides a trusted video acquisition device with active security reinforcement to address the shortcomings of existing technologies in terms of protocol exposure, passive defense, identity cloning, and lack of active monitoring. Based on GB / T28181 and GB 35114, the solution of this application can achieve timing decoupling, metadata transformation, and dynamic out-of-order processing through a reinforcement module, which can effectively target side-channel attacks at the protocol layer / traffic layer and improve the security of video image transmission.
[0007] This invention provides a trusted video acquisition device with active security hardening, including a camera, a hardening module, and a video platform; The camera is used to collect video data; The reinforcement module is used to reinforce the video data based on a pre-determined target reinforcement algorithm, and send the reinforced video metadata and reinforcement number to the video platform together. The reinforcement number corresponds to the target reinforcement algorithm, which is used to perform permutation transformation and reordering processing on the video data so that the processed data cannot be restored to its original content without corresponding restoration. The video platform is used to determine the target data restoration algorithm corresponding to the target hardening algorithm based on the target hardening number, and to decrypt the video data based on the target data restoration algorithm.
[0008] According to the trusted video acquisition device with active security hardening provided by the present invention, the hardening module is further used for: The target hardening algorithm is applied to transform each character in the video data into several other characters and to shuffle the characters in the video data.
[0009] According to the trusted video acquisition device with active security hardening provided by the present invention, the hardening module is further used for: The video data captured by the camera is separated into video metadata and media stream data. The video metadata is transmitted to the video platform through a metadata hardening tunnel, and the media stream data is transmitted to the video platform through a media stream data hardening tunnel. The video metadata is hardened through the metadata hardening tunnel, and the media stream data is hardened through the media stream data hardening tunnel.
[0010] According to the trusted video acquisition device with active security hardening provided by the present invention, the hardening module is further used for: The video metadata is divided into several data packets, and these data packets are asynchronously transmitted to the video platform through the metadata-reinforced tunnel.
[0011] According to the trusted video acquisition device with active security reinforcement provided by the present invention, the target reinforcement algorithm includes several reinforcement levels; The hardening module is also used to change the hardening level when triggered by instructions sent by the video platform.
[0012] According to the trusted video acquisition device with active security hardening provided by the present invention, the video platform is further used for: Based on the target reinforcement number, determine the target data restoration algorithm corresponding to the target reinforcement algorithm; The disordered video data is reverse-engineered based on the target data restoration algorithm. The meaningless characters in the video data are restored to the video data captured by the camera.
[0013] According to the trusted video acquisition device with active security hardening provided by the present invention, the hardening module is an embedded hardening module, which is embedded in the trusted video acquisition device in the form of a chip and electrically connected to the camera.
[0014] According to the trusted video acquisition device with active security hardening provided by the present invention, the hardening module is an access-type hardening module, which is connected in series between the camera and the video platform; The access-type hardening module is used to receive video data emitted by the camera, harden the video data, and send it to the video platform.
[0015] According to the trusted video acquisition device with active security reinforcement provided by the present invention, the access-type reinforcement module is further used to separate the video data into video metadata and media stream data; The video metadata is subjected to hardening transformation to obtain hardened metadata data packets; The hardened metadata data packet is sent to the video platform through the metadata hardening tunnel; The media stream data is subjected to hardening transformation to obtain hardened media stream data packets; The hardened media stream data packets are shuffled and then sent to the video platform through the media stream hardening tunnel.
[0016] According to the trusted video acquisition device with active security hardening provided by the present invention, the access hardening module is further used to shuffle the order of the hardened media stream data packets and regenerate the sequence number and timestamp of the hardened media stream data packets.
[0017] The trusted video acquisition device with active security hardening provided by this invention includes a hardening module. This hardening module can transform video data into other characters according to the corresponding relationship in the target hardening algorithm. It can also perform data reordering. Since the hardening module only stores the hardening algorithm but not the data restoration algorithm, even if the data is attacked during transmission, the attacker can only know the hardening number corresponding to the hardening algorithm, but cannot know the corresponding hardening algorithm, let alone obtain the corresponding data restoration algorithm. This ensures the secure transmission of data. Attached Figure Description
[0018] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0019] Figure 1 This is a schematic diagram of the structure of a trusted video acquisition device with active security hardening provided in an embodiment of the present invention; Figure 2 This is a flowchart illustrating the reinforcement algorithm provided in an embodiment of the present invention. Detailed Implementation
[0020] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0021] Currently, there are numerous successful side-channel attack cases targeting video surveillance systems in publicly reported and authoritative research. These include reproducible attack implementations publicly verified by top academic conferences and security vendors, as well as practical cases from red team / blue team exercises and attack-defense drills. At the same time, there are also corresponding attack feasibility verifications and risk disclosures for national cryptographic video surveillance systems that comply with the GB 35114 standard.
[0022] For example, the EM Eye electromagnetic side-channel attack directly restores the real-time image from an encrypted camera. The attack exploits unintentional electromagnetic radiation leakage in the MIP (Multi-Input Transmission) data transmission link between the camera's image sensor and the ISP processor. Using a standard software-defined radio receiver, it captures electromagnetic signals during encryption operations and image data transmission, directly restoring the original image captured by the camera. This completely bypasses the device's software encryption and authentication measures. Even if the video stream is fully encrypted using the SM4 algorithm required by GB35114, the attacker does not need to crack the encryption algorithm; they can directly restore the original video data from the physical layer, completely breaking through the end-to-end encryption barrier.
[0023] Video side-channel attack based on power LED: Remotely extracting the encryption key of monitoring equipment. The attack method involves the power consumption of the encrypted device fluctuating with the key-related operations when performing SM2 / SM4 or other national cryptographic operations, causing subtle changes in the brightness of the device's power LED that are imperceptible to the human eye. Attackers can record the power LED video of the target IPC from 1 to 20 meters away using ordinary surveillance cameras (including the built-in camera of an iPhone and networked monitoring IPCs in public areas). By using rolling shutter technology to increase the sampling rate to 60,000 times per second, the power consumption fluctuation trajectory can be reconstructed, and the device's encryption key can be extracted in reverse. Attack effect: In the experiment, the 256-bit ECDSA key of the smart card reader and the 378-bit post-quantum cryptography key of the mobile phone were successfully extracted through a surveillance camera 1 meter away. This attack is fully applicable to GB 35114 front-end IPC devices. As long as the device performs national cryptographic operations, corresponding power consumption leakage will occur, and the attack can be completed without physically disassembling the device.
[0024] Traffic-side channel attacks on encrypted surveillance video streams: These attacks allow attackers to infer the content of monitored footage without decryption. Even though the video stream is fully encrypted using the SM4 algorithm as required by GB 35114, the variable bitrate encoding characteristics of H.264 and H.265 result in a strong correlation between the size, interval, and burst patterns of the encrypted video traffic packets and the video content. Attackers only need to intercept the encrypted traffic; without cracking the key, they can analyze traffic characteristics to infer whether there is movement, number, or activity trajectories of people in the monitored footage, and even accurately identify specific video content. This attack has an extremely low barrier to entry, requiring only the mirroring of traffic in the network link, without needing to breach any device security protections. The success rate of attacks against public security video surveillance systems exceeds 90%, making it a mainstream method of traffic-side eavesdropping.
[0025] In summary, there are currently numerous cases of side-channel attacks targeting the GB 35114 standard, and the GB 35114 standard lacks effective preventive measures against side-channel attacks. Based on this, the solution proposed in this application provides a novel trusted video acquisition device with active security hardening and a video data hardening method, which can effectively address side-channel attacks.
[0026] Figure 1 This is a schematic diagram of the structure of a trusted video acquisition device with active security hardening provided in an embodiment of the present invention.
[0027] like Figure 1 As shown, this embodiment provides a trusted video acquisition device with active security hardening, including: Cameras, ruggedized modules, and video platforms; The camera is used to collect video data; The reinforcement module is used to reinforce the video data based on a pre-determined target reinforcement algorithm, and send the reinforced video data and reinforcement number together to the video platform. The reinforcement number corresponds to the target reinforcement algorithm, which is used to perform permutation transformation and reordering processing on the video data, so that the processed data cannot be recovered from the original content without corresponding restoration. Specifically, the reinforcement module can apply the target reinforcement algorithm to transform each character in the video data into several other characters and to shuffle the characters in the video data.
[0028] The video platform is used to determine the target data restoration algorithm corresponding to the target hardening algorithm based on the target hardening number, and to decrypt the video data based on the target data restoration algorithm.
[0029] In practical applications, when transmitting data, video data can be divided into video metadata and media stream data for separate hardening and transmission. Specifically, the hardening module can establish metadata hardening tunnels and media stream data hardening tunnels, and transmit video metadata through the metadata hardening tunnels and media stream data through the media stream data transmission.
[0030] In practical applications, the hardening module can first decouple the logical layer, that is, extract the metadata of the video data, such as frame ID, timestamp, frame type, resolution, bitrate, session ID, etc. It is worth noting that the hardening module provided by this application can extract, transform, and reorder all packets of video data. The above packets are just examples and are not limited to extracting and hardening only the examples mentioned above. Then, the video metadata and media stream data are separated; then, metadata hardening tunnels and media stream data hardening tunnels are established separately. The video metadata is hardened and transmitted through the metadata hardening tunnel, and the media stream data is hardened and transmitted through the media stream data hardening tunnel. The metadata hardening tunnel and the media stream data hardening tunnel use different source ports and hardening parameters, thus achieving channel isolation. During application, even if an attacker cracks the hardening of the media stream tunnel (e.g., obtains the RTP key), the signaling remains secure because the video metadata uses completely different hardening parameters (different keys, different algorithm suites). Conversely, while achieving fault / attack isolation, attackers need to crack two independent hardening systems simultaneously, rather than just one. For example, if the media stream data hardening tunnel uses DTLS 1.3+SM4-GCM port 9443 and the metadata hardening tunnel uses TLS 1.3+SM4-GCM port 8443, attackers must have two cracking capabilities, doubling the attack surface.
[0031] Asynchronous transmission can be used when transmitting metadata. Specifically, this means dividing video metadata into multiple data packets, which are not sent simultaneously. This prevents attackers from accurately reconstructing the true metadata after intercepting network traffic; they need to precisely match the time window. The signaling and media of the same call are scattered along the timeline, significantly reducing the success rate of statistical correlation attacks. Furthermore, to reconstruct the complete session, attackers must simultaneously capture multiple metadata packets and time-align them, exponentially increasing the attack cost.
[0032] In practical applications, target hardening algorithms can include several hardening levels. Under different hardening levels, the complexity of character transformation and disorder processing of data can vary. For example, security levels can include level 1 hardening, level 2 hardening, and level 3 hardening. Level 1 hardening is a relatively basic hardening level, while level 3 hardening is a more complex one. In level 1 hardening, each character in the video data can be transformed into 8-bit other characters. In level 2 hardening, each character can be transformed into 16-bit other characters. In level 3 hardening, each character can be transformed into 32-bit other characters.
[0033] In an exemplary embodiment, minute physical differences during the device generation process can also be used to generate a unique physical fingerprint. For example, the SRAM power-on state can be read to extract stable bits; a 256-bit PUF fingerprint can be generated. The same PUF fingerprint must be used to decrypt metadata and media stream data. Since random disturbances during the manufacturing process cannot be reproduced, PUF features are unclonable. Even with design drawings and the same production line, it is impossible to replicate the same PUF features. Based on this, in practical applications, boot integrity measurement, i.e., trusted boot, can be performed. Specifically, before the video capture device boots, the bootloader, kernel, and security-hardened firmware can be hashed. Then, the PUF fingerprint is written to the PCR register for hardware isolation, preventing software changes. After the device boots, a hardware root of trust is used for verification; if any verification fails, boot is rejected and a security alarm is triggered.
[0034] In an exemplary embodiment, system status monitoring and abnormal behavior detection can also be performed to improve the security of video acquisition equipment. System status monitoring can refer to real-time monitoring of CPU usage, memory usage, and network connection status; comparison with baselines to detect anomalies; abnormal behavior detection can refer to detecting port scans exceeding 100 connections per second; detecting brute-force attacks on the same IP authentication failure more than 5 times; detecting vulnerability exploit attempts matching known attack patterns; when the detection determines that there may be a system anomaly, proactive responses can be taken, for example, cutting off abnormal connections and blocking IPs with a firewall; sending security alerts to the platform; and recording attack logs for source tracing.
[0035] In an exemplary embodiment, this application also provides a method for security hardening of video data using a security hardening module, comprising the following steps: Step S1: The ruggedized module receives video data collected by the camera; Step S2: The reinforcement module transforms and scrambles the video data based on the target reinforcement algorithm; Step S3: The reinforcement module sends the reinforced data and the corresponding reinforcement number to the video platform.
[0036] In an exemplary embodiment, this application also provides a method for restoring decrypted data received by a video platform, such as... Figure 2 As shown, it includes: Step 201: Determine the target data restoration algorithm corresponding to the target reinforcement algorithm based on the target reinforcement number; Step 202: Reverse restore the disordered video data based on the target data restoration algorithm; Step 203: Restore the meaningless characters in the video data to the video data captured by the camera.
[0037] In the exemplary embodiment, the hardening module can take two forms: an embedded hardening module and an access hardening module. The embedded hardening module is a chip type that can be directly installed inside the camera to harden the video data one-to-one. The access hardening module is an external device that connects between the camera and the video platform. The access hardening module can connect to multiple cameras at the same time and harden the video data of multiple cameras simultaneously.
[0038] In practical applications, embedded ruggedization modules may include: High-speed bus interface unit: Supports multiple high-speed bus interfaces such as SPI, USB 3.0, and PCIe, enabling high-speed data communication with the IPC host control chip. The interface supports hot-swapping and automatic detection. Protocol stack takeover unit: Directly takes over the protocol stack output (SocketOutput) of the IPC main control chip through the underlying driver, performing preprocessing on the video data before it flows out of the main control chip. The takeover process is transparent to the upper-layer application; Video stream hardening engine: Integrates a high-performance SM4 hardware hardening engine, supporting slice hardening of H.264 / H.265 raw bitstreams and concurrent processing of more than 16 channels of 1080P video. The hardening engine adopts a pipelined architecture, processing 16 bytes of data per clock cycle; RTP encapsulation unit: Completes the encapsulation and packet reordering of the RTP protocol at the hardware level, including RTP header generation, payload format encapsulation, RTCP feedback packet generation, etc., without occupying any CPU computing power of the IPC main control chip; Active security protection unit: Built-in lightweight firewall module, which monitors network traffic entering the IPC in real time, automatically filters and blocks illegal scanning and DDoS attacks, providing the first physical security barrier for IPC devices; Power management unit: Supports independent power supply or power from IPC motherboard, supports low power mode, and supports overcurrent protection and short circuit protection.
[0039] As can be seen, the connection between the ruggedized module and the main control SoC chip of the video acquisition device in this embodiment is not a simple peripheral mounting, but rather a deep coupling and protocol stack takeover. Specifically, the module establishes a physical connection with the main control SoC through the high-speed bus interface inside the IPC (such as SPI, USB 3.0, PCIe, or a proprietary high-speed parallel bus). The choice of bus depends on the IPC's hardware architecture and its bandwidth and latency requirements. PCIe offers the highest bandwidth and lowest latency, making it suitable for high-performance IPCs; SPI and USB are suitable for mid-to-low-end IPCs and have cost advantages. In addition, the ruggedized module installs a customized low-level driver in the IPC's operating system. This driver does not simply recognize the module as an ordinary peripheral, but directly takes over network data packets at the Socket layer or lower by modifying or intercepting the output path of the main control SoC's network protocol stack (such as the TCP / IP protocol stack). This means that all network data originating from the main SoC application (such as video encoders and streaming media servers) is redirected to this security module for processing before actually entering the physical network interface card (NIC). Furthermore, the module intercepts and preprocesses the data before it leaves the main SoC. This preprocessing includes, but is not limited to: Data caching: The module has an internal high-speed cache for temporarily storing raw video data received from the SoC or network data packets to be sent.
[0040] Data parsing and recognition: The module can parse the received data stream and identify key information such as video bitstream (e.g., H.264 / H.265 NALU units), RTP header, and SIP signaling.
[0041] Security and data acquisition functions are decoupled: Through this takeover mechanism, security hardening functions (hardening, signing, traffic filtering) are logically completely separated from core business functions such as video acquisition and encoding, ensuring they do not interfere with each other. The main control SoC is only responsible for video processing tasks that it excels at, while the security module focuses on security protection, achieving a clear division of responsibilities and physical isolation.
[0042] The deep coupling and takeover mechanism described above ensures that the security module can perform mandatory security processing on all critical data flows entering and leaving the IPC, avoiding the bypass risks that application-layer security schemes may have. At the same time, since the data is processed before leaving the SoC, the exposure time of data within the SoC can be minimized, improving overall security.
[0043] In summary, the embedded ruggedization module provided in this embodiment has the following beneficial effects: This achieves physical separation between security hardening and video capture functions, significantly improving resistance to penetration attacks. Specifically: (1) Even if the IPC firmware is tampered with, the security module can still work independently to ensure that the video stream reinforcement is not interrupted; (2) The security module can be upgraded independently without affecting the operation of the IPC main system.
[0044] By using a dedicated hardware engine to process national cryptographic algorithms, the hardening latency is controlled to within 10ms, which is superior to pure software implementation. Specific performance indicators: (1) Single-channel 1080P@30fps video stream hardening latency: ≤5ms; (2) Total delay for 16-channel concurrent hardening: ≤10ms; (3) Enhanced throughput: ≥500Mbps; (4) CPU utilization: 0% (not occupying the CPU of the IPC main control chip).
[0045] This completely solves the problem that existing or low-to-mid-range IPCs cannot support national cryptographic encryption due to insufficient computing power. Specifically: (1) The hardening operation is completed entirely by the module hardware and does not occupy the CPU resources of the IPC main control chip; (2) The RTP encapsulation is completed by the module hardware and does not occupy the CPU resources of the IPC main control chip; (3) The IPC main control chip can focus on core functions such as video acquisition and encoding.
[0046] Existing IPC devices do not require replacement of the main control chip; simply adding a security module will enable them to support Chinese cryptographic encryption. Specific upgrade plan: (1) For IPC devices with reserved interfaces, connect directly to the security module; (2) For IPC devices without reserved interfaces, security modules can be added by replacing the original daughterboard; (3) The transformation cost is low, the transformation time is short, and it does not affect the existing system architecture.
[0047] Provides the first physical security barrier for IPC devices, effectively defending against network attacks. Specific protection capabilities: (1) Port scanning detection and blocking: Detection time ≤ 1 second, blocking rate ≥ 99%; (2) SYN Flood Attack Defense: Can defend against SYN Flood attacks of ≥10Gbps; (3) UDP Flood Attack Defense: Can defend against UDP Flood attacks of ≥10Gbps; (4) Application layer attack defense: Supports SIP protocol anomaly detection and blocking.
[0048] Fully compliant with GB 35114-2017 standard Class C (safety level) requirements, specifically including: (1) Supports national cryptographic algorithms SM2 / SM3 / SM4; (2) Supports identity authentication based on digital certificates; (3) Supports reinforced video stream transmission; (4) Support safe device startup.
[0049] The hardening module can also be a plug-in hardening module. For plug-in hardening modules, it can include: (1) Virtual bridge module: realizes bidirectional transparent proxy between IPC and platform. The module acts as a "virtual platform" internally and as a "proxy IPC" externally. It can be connected without modifying the original configuration of IPC; (2) Signaling interception and parsing module: captures SIP signaling (UDP / 5060) sent by IPC in real time, parses the SIP packet structure, and extracts key metadata such as device ID, intranet IP, port, and SDP descriptor; (3) Metadata hardening and transformation module: The extracted metadata is subjected to secondary hardening and transformation using the SM4-CBC mode to generate hardened metadata data packets, protecting sensitive information from being exposed; (4) Asynchronous transmission control module: It separates the hardened metadata from the original SIP message and sends it to the alignment center on the platform side through an independent hardened tunnel to realize the asynchronous transmission logic of "sending metadata first and then media stream". (5) Platform-side alignment and restoration module: On the platform side, the asynchronously arriving metadata is precisely aligned with the out-of-order RTP packets through session fingerprinting to restore the original timing and signaling structure; (6) Hardware cryptographic acceleration module: integrates SM2 / SM3 / SM4 hardware acceleration engine to achieve high-performance cryptographic operations and ensure that real-time video stream hardening does not affect transmission delay.
[0050] Access-based hardening modules can employ virtual bridge technology to achieve transparent interception at the data link layer: Bridge initialization: Create a virtual bridge, add IPC-side and network-side interfaces, and enable forwarding functionality. Traffic capture: Capture SIP signaling (UDP port 5060) in kernel space using eBPF / XDP technology; capture RTP media streams (UDP dynamic ports) using iptables / nftables rules; and pass packets to user space for processing using zero-copy technology. Two-way proxy: On the IPC side, the module acts as a "virtual platform" and responds to the IPC's registration, heartbeat, and signaling requests; on the network side, the module acts as a "proxy IPC" and communicates with the real platform on behalf of the IPC; neither the IPC nor the platform is aware of the module's existence.
[0051] When using an access-based hardening module to harden video data, the following process may be included: Sensitive field extraction: Parse SIP packets to extract key metadata such as device ID, source IP, source port, call ID, sequence number, media IP, media port, payload type, and timestamp; Metadata transformation: The metadata is subjected to secondary hardening transformation using the SM4-CBC mode to generate random IV and SM3 check codes, which are then encapsulated into hardened metadata data packets; Asynchronous transmission: The hardened metadata is stripped from the original SIP message and sent to the platform-side alignment center first through a separate hardened tunnel (based on TLS 1.3 + SM2 certificate), waiting for platform confirmation; Signaling desensitization: Replace sensitive fields in the original SIP message with desensitized values, such as replacing the media IP in SDP with the module IP, replacing the media port with the module port, removing or obfuscating the device identifier, adding obfuscated parameters, etc.
[0052] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A trusted video acquisition device with active security hardening, characterized in that, This includes cameras, ruggedized modules, and video platforms; The camera is used to collect video data; The reinforcement module is used to reinforce the video data based on a pre-determined target reinforcement algorithm, and send the reinforced video metadata and reinforcement number to the video platform together. The reinforcement number corresponds to the target reinforcement algorithm, which is used to perform permutation transformation and reordering processing on the video data so that the processed data cannot be restored to its original content without corresponding restoration. The video platform is used to determine the target data restoration algorithm corresponding to the target hardening algorithm based on the target hardening number, and to decrypt the video data based on the target data restoration algorithm.
2. The trusted video acquisition device with active security hardening as described in claim 1, characterized in that, The reinforcement module is also used for: The target hardening algorithm is applied to transform each character in the video data into several other characters and to shuffle the characters in the video data.
3. The trusted video acquisition device with active security hardening as described in claim 1, characterized in that, The reinforcement module is also used for: The video data captured by the camera is separated into video metadata and media stream data. The video metadata is transmitted to the video platform through a metadata hardening tunnel, and the media stream data is transmitted to the video platform through a media stream data hardening tunnel. The video metadata is hardened through the metadata hardening tunnel, and the media stream data is hardened through the media stream data hardening tunnel.
4. The trusted video acquisition device with active security hardening as described in claim 3, characterized in that, The reinforcement module is also used for: The video metadata is divided into several data packets, and these data packets are asynchronously transmitted to the video platform through the metadata-reinforced tunnel.
5. The trusted video acquisition device with active security hardening as described in claim 1, characterized in that, The target hardening algorithm includes several hardening levels; The hardening module is also used to change the hardening level when triggered by instructions sent by the video platform.
6. The trusted video acquisition device with active security hardening as described in claim 1, characterized in that, The video platform is also used for: Based on the target reinforcement number, determine the target data restoration algorithm corresponding to the target reinforcement algorithm; The disordered video data is reverse-engineered based on the target data restoration algorithm. The meaningless characters in the video data are restored to the video data captured by the camera.
7. The trusted video acquisition device with active security hardening as described in claim 1, characterized in that, The hardening module is an embedded hardening module, which is embedded in the trusted video acquisition device in the form of a chip and is electrically connected to the camera.
8. The trusted video acquisition device with active security hardening as described in claim 1, characterized in that, The reinforcement module is an access-type reinforcement module, which is connected in series between the camera and the video platform; The access-type hardening module is used to receive video data emitted by the camera, harden the video data, and send it to the video platform.
9. The trusted video acquisition device with active security hardening according to claim 8, characterized in that, The access-based hardening module is also used to separate the video data into video metadata and media stream data; The video metadata is subjected to hardening transformation to obtain hardened metadata data packets; The hardened metadata data packet is sent to the video platform through the metadata hardening tunnel; The media stream data is subjected to hardening transformation to obtain hardened media stream data packets; The hardened media stream data packets are shuffled and then sent to the video platform through the media stream hardening tunnel.
10. The trusted video acquisition device with active security hardening according to claim 8, characterized in that, The access-based hardening module is also used to shuffle the order of the hardened media stream data packets and then regenerate the sequence number and timestamp of the hardened media stream data packets.