A method for implementing host authentication and screen recording data transmission based on national encryption

CN122845310APending Publication Date: 2026-09-29BEIJING DONGFANG JINGHAI ELECTRONIC TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611355593.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-09-03
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

传统的主机认证传输方法往往存在安全漏洞,容易被攻击者截获或篡改,导致敏感信息泄露

Benefits of technology

[0029]1.本发明提供一种基于国密的主机认证及录屏数据传输的实现方法,通过每次录屏会话动态生成SM4通信密钥,实现了“一话一密”,即使某次会话的SM4通信密钥泄露,也不会影响历史或其他会话的录屏数据安全,提高了前向安全性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122845310A_ABST
    Figure CN122845310A_ABST
Patent Text Reader

Abstract

The application relates to the field of information technology, in particular to an implementation method of host authentication and screen recording data transmission based on a national secret, which comprises a trusted screen recording authentication system, the trusted screen recording authentication system adopts a client-server architecture; a host authentication service is arranged on the server, is responsible for identity authentication of a host requesting screen recording, and negotiates a session key; a host screen recording service is arranged on the server, is responsible for receiving and storing encrypted screen recording data; a host authentication screen recording component is arranged on the client, the client is arranged on the authenticated host, is responsible for actively initiating authentication, and performs screen recording and data uploading after the authentication is passed. The implementation method of the host authentication and screen recording data transmission based on the national secret can dynamically generate an SM4 key for each screen recording session, realizes one session one key, even if the SM4 key of a certain session is leaked, the screen recording data safety of historical or other sessions will not be affected, and the forward security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information technology, and in particular to a method for implementing host authentication and screen recording data transmission based on national cryptographic standards. Background Technology

[0002] With the continuous development of information technology, data security issues are becoming increasingly prominent. During host authentication, the security of data transmission is paramount. Traditional host authentication transmission methods often have security vulnerabilities, making them susceptible to interception or tampering by attackers, leading to the leakage of sensitive information. Current host authentication implementations lack operation records after successful authentication, significantly increasing the difficulty of tracing the operation process. Furthermore, current screen recording data transmission mostly uses common protocols, posing a risk of data leakage. Summary of the Invention

[0003] To overcome the shortcomings of existing technologies, this invention provides a method for implementing host authentication and screen recording data transmission based on national cryptographic standards.

[0004] To solve the above technical problems, the present invention provides the following technical solution: a method for implementing host authentication and screen recording data transmission based on national cryptographic standards, which includes a trusted screen recording authentication system, the trusted screen recording authentication system adopting a client-server architecture; and includes a host authentication screen recording component, a host authentication service, and a host screen recording service;

[0005] The host authentication service is set up on the server and is responsible for authenticating the host that requests screen recording and negotiating the session key. The specific steps of the host authentication service include: key generation and broadcasting, authentication request processing and authentication result return.

[0006] The host screen recording service is set up on the server and is responsible for receiving and storing encrypted screen recording data. The specific steps of the host screen recording service include: receiving screen recording data, data decryption and reconstruction, and file generation and storage.

[0007] The host authentication screen recording component is set on the client side, which is deployed on the host being authenticated. The client is responsible for actively initiating authentication and performing screen recording and data upload after successful authentication. The steps of the host authentication screen recording component include service discovery and certificate acquisition, authentication and key negotiation, heartbeat and status maintenance, and screen recording and data transmission.

[0008] Preferably, the steps for key generation and broadcasting of the host authentication service are as follows:

[0009] When the service starts, a temporary SM2 key pair is generated and a signature message is broadcast at fixed time intervals using a separate UDP broadcast port. The signature message includes the service identifier, protocol version, current SM2 public key, and timestamp, and is used to announce the existence of the authentication service to hosts in the network.

[0010] Preferably, the steps for processing authentication requests by the host authentication service are as follows:

[0011] Listening to the specified UDP authentication service port, upon receiving the authentication message from the host authentication screen recording component, first decrypting the encrypted part of the message using the locally stored SM2 private key; after decryption, extracting the SM4 communication key generated by the client, the client certificate information, and the client network card MAC address; verifying the validity of the client certificate; after successful verification, recording the MAC address in the authenticated list and managing its session state;

[0012] The steps for returning the authentication result from the host authentication service are as follows:

[0013] The authentication result is encrypted using the decrypted SM4 communication key, and an authentication result message is generated and returned via UDP to the host authentication screen recording component that initiated the request.

[0014] Preferably, the steps for receiving screen recording data in the host screen recording service are as follows:

[0015] Listens on the specified UDP screen recording transmission port and continuously receives screen recording information messages from the host authentication screen recording component. Each message header contains a session identifier and a sequence number, which are used to distinguish screen recording streams from different hosts and ensure data order.

[0016] Preferably, the data decryption and reconstruction steps for the host screen recording service are as follows:

[0017] Based on the session identifier in the message header, find the SM4 communication key negotiated with the host authentication screen recording component, use the SM4 communication key to decrypt the screen recording data in the message payload, and after decryption, sort and reassemble the data packets according to the sequence number to remove the out-of-order effects caused by network transmission.

[0018] Preferably, the steps for generating and storing files for the host screen recording service are as follows:

[0019] The recombined continuous screen recording data stream is packaged into a standard video file format according to preset rules and stored in a specified storage path; the start and end times of the screen recording, host information and other metadata are recorded.

[0020] Preferably, the service discovery and certificate acquisition steps of the host authentication screen recording component are as follows:

[0021] After startup, it listens on the specified UDP broadcast port, waits to receive characteristic messages sent by the host authentication service; parses the messages to obtain the server's SM2 public key; and reads the national cryptographic digital certificate file stored on the local machine to obtain the MAC address of the currently active network card on the local machine.

[0022] Preferably, the authentication and key negotiation steps of the host authentication screen recording component are as follows:

[0023] The system randomly generates an SM4 communication key for this session, combines the SM4 communication key, local certificate, MAC address, and other information into authentication data, encrypts it using the SM2 public key obtained from the signature message, forms an authentication message, and sends it via UDP to the authentication port of the host authentication service; it waits for and receives the authentication result message, decrypts it using the locally generated SM4 communication key, and confirms whether the authentication was successful.

[0024] Preferably, the steps for maintaining the heartbeat and status of the host authentication screen recording component are as follows:

[0025] After successful authentication, a timer is started to periodically generate heartbeat messages containing a session identifier and a timestamp. These messages are then encrypted using an SM4 communication key and sent to the authentication port of the host authentication service to maintain session activity. Screen recording stops if no heartbeat response is received for several consecutive times or if the authentication server actively terminates the session.

[0026] Preferably, the screen recording and data transmission steps of the host authentication screen recording component are as follows:

[0027] After successful authentication, screen capture begins immediately. The captured raw video data is compressed and encoded, then encapsulated according to a fixed data packet size. Each data packet includes a session identifier and an incrementing sequence number. The entire data packet is then encrypted using the negotiated SM4 communication key to form a screen recording information message, which is sent via UDP to the screen recording port of the host screen recording service.

[0028] The beneficial effects of this invention are:

[0029] 1. This invention provides a method for host authentication and screen recording data transmission based on national cryptographic standards. By dynamically generating an SM4 communication key for each screen recording session, it achieves "one key per session". Even if the SM4 communication key of a certain session is leaked, it will not affect the security of screen recording data in history or other sessions, thus improving forward security.

[0030] 2. This invention provides a method for implementing host authentication and screen recording data transmission based on national cryptographic standards. By using the UDP protocol for broadcasting, authentication, and data transmission, the overhead of TCP connection establishment is avoided, making it suitable for high-concurrency, low-latency screen recording data transmission scenarios within a local area network. The authentication service and screen recording service ports are separated, decoupling the functions and facilitating independent expansion and maintenance.

[0031] 3. This invention provides a method for implementing host authentication and screen recording data transmission based on national cryptographic standards, combining symmetric and asymmetric encryption algorithms to enhance data security during the authentication and screen recording data transmission process.

[0032] 4. This invention provides a method for host authentication and screen recording data transmission based on national cryptographic standards. After successful host authentication, the screen recording data is saved, and operation information is recorded in real time, reducing the difficulty of operation tracing.

[0033] 5. This invention provides a method for implementing host authentication and screen recording data transmission based on national cryptographic standards, which makes the system more compatible with host authentication compared to solutions implemented using link layer protocols. Attached Figure Description

[0034] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Wherein:

[0035] Figure 1 The process of this invention Figure 1 ;

[0036] Figure 2 The process of this invention Figure 2 . Detailed Implementation

[0037] The following is in conjunction with the appendix Figure 1 To be continued Figure 2 The principles and features of the present invention are described, and the examples given are only for explaining the present invention and are not intended to limit the scope of the present invention.

[0038] Please see Figures 1-2 The present invention provides a method for implementing host authentication and screen recording data transmission based on national cryptographic standards, including a trusted screen recording authentication system, which adopts a client-server architecture; and includes a host authentication screen recording component, a host authentication service, and a host screen recording service.

[0039] The host authentication service is set up on the server and is responsible for authenticating the host that requests screen recording and negotiating the session key. The specific steps of the host authentication service include: key generation and broadcasting, authentication request processing and authentication result return.

[0040] The host screen recording service is set up on the server and is responsible for receiving and storing encrypted screen recording data. The specific steps of the host screen recording service include: receiving screen recording data, data decryption and reconstruction, and file generation and storage.

[0041] The host authentication screen recording component is set on the client side, which is deployed on the host being authenticated. The client is responsible for actively initiating authentication and performing screen recording and data upload after successful authentication. The steps of the host authentication screen recording component include service discovery and certificate acquisition, authentication and key negotiation, heartbeat and status maintenance, and screen recording and data transmission.

[0042] The steps for key generation and broadcasting in the host authentication service are as follows:

[0043] When the service starts, a temporary SM2 key pair is generated and a signature message is broadcast at fixed time intervals using a separate UDP broadcast port. The signature message includes the service identifier, protocol version, current SM2 public key, and timestamp, and is used to announce the existence of the authentication service to hosts in the network. A temporary SM2 key pair, including a public key and a private key, is used at fixed time intervals, which can be once per second. The signature message contains the service identifier, protocol version, current SM2 public key, or its hash value, and timestamp.

[0044] The steps for processing authentication requests by the host authentication service are as follows:

[0045] Listening to the specified UDP authentication service port, upon receiving the authentication message from the host authentication screen recording component, first decrypting the encrypted part of the message using the locally stored SM2 private key; after decryption, extracting the SM4 communication key generated by the client, the client certificate information, and the client network card MAC address; verifying the validity of the client certificate; after successful verification, recording the MAC address in the authenticated list and managing its session state;

[0046] The steps for returning the authentication result from the host authentication service are as follows:

[0047] The authentication result is encrypted using the decrypted SM4 communication key, generating an authentication result message, which is returned via UDP to the authentication recording component of the requesting host. The validity of the client certificate is verified, including the certificate chain, validity period, and whether it has been revoked. The authentication result includes success, failure, and the reason for failure.

[0048] The host authentication service generates an authorization certificate and provides it to the host authentication screen recording component; the host authentication service randomly generates an SM2 public key; the host authentication service periodically sends a feature message carrying the SM2 public key; the host authentication service receives the authentication message and decrypts it using the SM2 private key; the host authentication service verifies the parsed authorization certificate, caches the SM4 key, and saves the authentication result; the host authentication service sends the authentication result encrypted using SM4 to the host authentication screen recording component; the host authentication service resets the timeout judgment after receiving the authentication heartbeat.

[0049] The steps for receiving screen recording data from the host screen recording service are as follows:

[0050] Listens on the specified UDP screen recording transmission port and continuously receives screen recording information messages from the host authentication screen recording component. Each message header contains a session identifier and a sequence number, which are used to distinguish screen recording streams from different hosts and ensure data order.

[0051] The steps for data decryption and reconstruction in the host screen recording service are as follows:

[0052] Based on the session identifier in the message header, find the SM4 communication key negotiated with the host authentication screen recording component, use the SM4 communication key to decrypt the screen recording data in the message payload, and after decryption, sort and reassemble the data packets according to the sequence number to remove the out-of-order effects caused by network transmission.

[0053] The steps for generating and storing files in the host screen recording service are as follows:

[0054] The recombined continuous screen recording data stream is packaged into a standard video file format according to preset rules and stored in a specified storage path; the start and end times of the screen recording, host information and other metadata are recorded; preset rules include by host and by time period; after receiving the screen recording information, the host screen recording service sorts the screen recording data; the host screen recording service saves the sorted screen recording information into a video file and generates file records.

[0055] The steps for service discovery and certificate acquisition for the host authentication screen recording component are as follows:

[0056] After startup, it listens on the specified UDP broadcast port, waits to receive characteristic messages sent by the host authentication service; parses the messages to obtain the server's SM2 public key; and reads the national cryptographic digital certificate file stored on the local machine to obtain the MAC address of the currently active network card on the local machine.

[0057] The authentication and key negotiation steps of the host authentication screen recording component are as follows:

[0058] The system randomly generates an SM4 communication key for this session, combines the SM4 communication key, local certificate, MAC address, and other information into authentication data, encrypts it using the SM2 public key obtained from the signature message, forms an authentication message, and sends it via UDP to the authentication port of the host authentication service; it waits for and receives the authentication result message, decrypts it using the locally generated SM4 key, and confirms whether the authentication was successful.

[0059] The steps for maintaining the heartbeat and status of the host authentication screen recording component are as follows:

[0060] After successful authentication, a timer is started to periodically generate heartbeat messages containing a session identifier and a timestamp. These messages are then encrypted using an SM4 communication key and sent to the authentication port of the host authentication service to maintain session activity. Screen recording stops if no heartbeat response is received for several consecutive times or if the authentication server actively terminates the session.

[0061] The steps for screen recording and data transmission using the host authentication screen recording component are as follows:

[0062] Upon successful authentication, screen capture begins immediately. The captured raw video data is compressed and encoded, then encapsulated into packets of a fixed size. Each packet includes a session identifier and an incrementing sequence number. The entire packet is then encrypted using the negotiated SM4 communication key to form a screen recording message, which is sent via UDP to the recording port of the host screen recording service. The fixed packet size is kept under 1400 bytes to avoid IP fragmentation. The host authentication screen recording component imports the authorization certificate. The host authentication screen recording component receives the feature packet, parses it to obtain the SM2 public key, and randomly generates an SM4 communication key. The host authentication screen recording component reads the authorization certificate content and the local MAC address, combines them with the SM4 communication key to form an authentication message, encrypts it using the SM2 public key, and sends it to the host authentication service. Upon receiving a successful authentication result, the host authentication screen recording component starts sending authentication heartbeats periodically. Upon receiving a successful authentication result, the host authentication screen recording component starts screen recording and acquires screen recording data. The host authentication screen recording component then encrypts the screen recording data using SM4 and sends it to the host screen recording service.

[0063] During use, the authentication screen recording service periodically sends characteristic messages via UDP broadcast; the authentication process uses the asymmetric encryption algorithm SM2 for encryption and decryption; after successful authentication, the authentication heartbeat and screen recording data use the symmetric encryption algorithm SM4 for encryption and decryption; and a communication key is randomly generated for each authentication.

[0064] The host authentication service generates an authorization certificate and provides it to the authentication recording component; the host authentication recording component imports the authorization certificate; the host authentication service randomly generates an SM2 public key; the host authentication service periodically sends a signature message carrying the SM2 public key; the host authentication recording component receives the signature message, parses it to obtain the SM2 public key; the host authentication recording component randomly generates an SM4 communication key; the host authentication recording component reads the authorization certificate content and the local MAC address, combines them with the SM4 key to form an authentication message, encrypts it using the SM2 public key, and sends it to the host authentication service; the host authentication service receives the authentication message, decrypts it using the SM2 private key; the host authentication service verifies the parsed authorization. The system executes the following steps: First, it caches the SM4 communication key and saves the authentication result. Second, it sends the SM4-encrypted authentication result to the host authentication screen recording component. Third, upon receiving the successful authentication result, the host authentication screen recording component starts sending authentication heartbeats periodically. Fourth, upon receiving the successful authentication result, the host authentication screen recording component starts screen recording and acquires screen recording data. Fifth, the host authentication screen recording component encrypts the screen recording data using SM4 and sends it to the host screen recording service. Sixth, upon receiving the authentication heartbeat, the host authentication service resets the timeout check. Finally, upon receiving the screen recording information, the host screen recording service sorts the screen recording data. Finally, the host screen recording service saves the sorted screen recording information as a video file and generates a file record.

[0065] Each screen recording session dynamically generates an SM4 communication key, achieving "one key per session." Even if the SM4 communication key for a particular session is leaked, it will not affect the security of screen recording data from previous or other sessions, improving forward security. UDP protocol is used for broadcasting, authentication, and data transmission, avoiding the overhead of TCP connection establishment, making it suitable for high-concurrency, low-latency screen recording data transmission scenarios within a local area network. Simultaneously, the authentication service and screen recording service ports are separated, decoupling functions and facilitating independent expansion and maintenance. The combination of symmetric and asymmetric encryption algorithms enhances data security during authentication and screen recording data transmission. Screen recording data is saved after successful host authentication, and operation information is recorded in real time, reducing the difficulty of operation tracing.

[0066] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A method for implementing host authentication and screen recording data transmission based on national cryptographic standards, characterized in that: This includes a trusted screen recording authentication system, which adopts a client-server architecture; It includes a host authentication and screen recording component, a host authentication service, and a host screen recording service; The host authentication service is set up on the server and is responsible for authenticating the host that requests screen recording and negotiating the session key; The specific steps of the host authentication service include: key generation and broadcasting, authentication request processing, and authentication result return; The host screen recording service is set up on the server and is responsible for receiving and storing encrypted screen recording data. The specific steps of the host screen recording service include: receiving screen recording data, data decryption and reconstruction, and file generation and storage. The host authentication screen recording component is set on the client side, which is deployed on the host being authenticated. The client is responsible for actively initiating authentication and performing screen recording and data upload after successful authentication. The steps of the host authentication screen recording component include service discovery and certificate acquisition, authentication and key negotiation, heartbeat and status maintenance, and screen recording and data transmission.

2. The method for implementing host authentication and screen recording data transmission based on national cryptographic standards according to claim 1, characterized in that: The steps for key generation and broadcasting of the host authentication service are as follows: When the service starts, a temporary SM2 key pair is generated and a signature message is broadcast at fixed time intervals using a separate UDP broadcast port. The signature message includes the service identifier, protocol version, current SM2 public key, and timestamp, and is used to announce the existence of the authentication service to hosts in the network.

3. The method for implementing host authentication and screen recording data transmission based on national cryptographic standards according to claim 2, characterized in that: The steps for processing authentication requests in the host authentication service are as follows: Listen to the specified UDP authentication service port, and when you receive an authentication message from the host authentication screen recording component, first use the locally stored SM2 private key to decrypt the encrypted part of the message; After decryption, extract the SM4 communication key generated by the client, the client certificate information, and the client network card MAC address; verify the legitimacy of the client certificate; Once verification is successful, the MAC address is recorded in the authenticated list, and its session state is managed. The steps for returning the authentication result from the host authentication service are as follows: The authentication result is encrypted using the decrypted SM4 communication key, and an authentication result message is generated and returned via UDP to the host authentication screen recording component that initiated the request.

4. The method for implementing host authentication and screen recording data transmission based on national cryptographic standards according to claim 3, characterized in that: The steps for receiving screen recording data in the host screen recording service are as follows: Listens on the specified UDP screen recording transmission port and continuously receives screen recording information messages from the host authentication screen recording component. Each message header contains a session identifier and a sequence number, which are used to distinguish screen recording streams from different hosts and ensure data order.

5. The method for implementing host authentication and screen recording data transmission based on national cryptographic standards according to claim 4, characterized in that: The data decryption and reconstruction steps of the host screen recording service are as follows: Based on the session identifier in the message header, find the SM4 communication key negotiated with the host authentication screen recording component, use the SM4 communication key to decrypt the screen recording data in the message payload, and after decryption, sort and reassemble the data packets according to the sequence number to remove the out-of-order effects caused by network transmission.

6. The method for implementing host authentication and screen recording data transmission based on national cryptographic standards according to claim 5, characterized in that: The steps for generating and storing files in the host screen recording service are as follows: The recombined continuous screen recording data stream is packaged into a standard video file format according to preset rules and stored in the specified storage path; Record the start and end times of screen recording, host information, and other metadata.

7. The method for implementing host authentication and screen recording data transmission based on national cryptographic standards according to claim 6, characterized in that: The service discovery and certificate acquisition steps of the host authentication screen recording component are as follows: After startup, it listens on the specified UDP broadcast port, waits to receive characteristic messages sent by the host authentication service; parses the messages to obtain the server's SM2 public key; and reads the national cryptographic digital certificate file stored on the local machine to obtain the MAC address of the currently active network card on the local machine.

8. The method for implementing host authentication and screen recording data transmission based on national cryptographic standards according to claim 7, characterized in that: The authentication and key negotiation steps of the host authentication screen recording component are as follows: The SM4 communication key used in this session is randomly generated. The SM4 communication key, local certificate, and MAC address are combined into authentication data, which is then encrypted using the SM2 public key obtained from the signature message to form an authentication message. This message is then sent via UDP to the authentication port of the host authentication service. Wait for and receive the authentication result message, decrypt it using the locally generated SM4 communication key, and confirm whether the authentication was successful.

9. The method for implementing host authentication and screen recording data transmission based on national cryptographic standards according to claim 8, characterized in that: The steps for maintaining the heartbeat and status of the host authentication screen recording component are as follows: After successful authentication, a timer is started to periodically generate heartbeat messages containing a session identifier and a timestamp. These messages are then encrypted using the SM4 communication key and sent to the authentication port of the host authentication service to maintain session activity. If no heartbeat response is received for several consecutive times or the authentication server actively terminates the session, screen recording will stop.

10. The method for implementing host authentication and screen recording data transmission based on national cryptographic standards according to claim 9, characterized in that: The steps for screen recording and data transmission of the host authentication screen recording component are as follows: After successful authentication, screen capture begins immediately. The captured raw video data is compressed and encoded, then encapsulated according to a fixed data packet size. Each data packet includes a session identifier and an incrementing sequence number. The entire data packet is then encrypted using the negotiated SM4 communication key to form a screen recording information message, which is sent via UDP to the screen recording port of the host screen recording service.