Security boundary method and system for video and image database architecture, and storage medium

By introducing Kong gateway and whitelist configurations into the view library architecture, the security and error handling problems of the view library architecture are solved, and higher security and more efficient processing capabilities are achieved, which are suitable for large-scale view library management.

WO2025124155A1PCT designated stage expired Publication Date: 2025-06-19E SURFING VISION TECHNOLOGY CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/135264
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-15
Filing Date
2024-11-28
Publication Date
2025-06-19

AI Technical Summary

Technical Problem

The GAT1400-based view library architecture has problems in data interaction and security protection, including the inability to prevent attacks from malicious subordinate platforms, the limitations of discovering and processing of abnormal push or wrong messages when handling large amounts of data notifications, and the resolution and rating of push messages rely on manual operations, which is inefficient.

Method used

By introducing Kong gateway into the view library architecture, using the whitelist configuration and national standard ID in the firewall for authentication, the filtering and parsing of the view library push notifications is realized. Kong Gateway regularly checks notifications, analyzes and judges abnormalities, saves the abnormal analysis results to the database according to the severity, and handles them in a timely manner through an alarm mechanism.

Benefits of technology

It improves the security of the view library architecture, enhances the ability to identify and handle errors, reduces the dependence on manual operations, improves processing efficiency, and meets the needs of large-scale view library management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024135264_19062025_PF_FP_ABST
    Figure CN2024135264_19062025_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the present invention are a security boundary method for a video and image database architecture, a security boundary system for a video and image database architecture, and a computer-readable storage medium. The security boundary method for a video and image database architecture comprises: in response to a notification pushed by a video and image database, sending the notification to a Kong gateway on the basis that a first whitelist of a firewall is configured with an egress IP corresponding to the video and image database; acquiring a second whitelist of the Kong gateway on the basis of a national standard ID corresponding to the video and image database; and in response to the egress IP corresponding to the video and image database being present in the second whitelist, sending the notification to an upper-level platform. By means of the security boundary method for a video and image database architecture provided in the present invention, higher security, more accurate error identification and a more efficient processing capability can be achieved, thereby meeting requirements for large-scale video and image database architecture management in practical applications.
Need to check novelty before this filing date? Find Prior Art

Description

A security boundary method, system and storage medium for view library architecture Technical Field

[0001] The present invention relates to the field of communications, and in particular to a security boundary method for a view library architecture, a security boundary system for a view library architecture, and a computer-readable storage medium. Background Art

[0002] GAT1400 is a video surveillance technology standard issued by my country's Ministry of Public Security. It not only defines the construction, management, and use of view libraries, but also covers technologies related to data transmission, storage, and query. However, with the rapid growth of data volumes, the GAT1400-based view library has encountered some problems with data interaction and security protection.

[0003] First, in the traditional GAT1400 view library architecture, authentication between upper and lower platforms relies on a registration keepalive mechanism. However, after the keepalive mechanism is established, the upper platform does not authenticate the source of the lower platform, thus failing to prevent attacks from malicious lower platforms to a certain extent.

[0004] Secondly, the existing GAT1400 view library architecture has limitations in detecting and handling abnormal or erroneous push notifications when processing large amounts of data notifications. This can lead to processing delays and even problems with the entire view library architecture, impacting its normal operation. Furthermore, the existing GAT1400 view library architecture relies primarily on manual parsing and grading of push messages, which is inefficient and can result in false positives or omissions, making it unable to meet the needs of large-scale view library management.

[0005] In order to overcome the above-mentioned defects of the existing technology, this field urgently needs a security boundary technology for the view library architecture, which can have higher security, more accurate error identification ability and more efficient processing ability to meet the needs of large-scale view library architecture management in real applications. Summary of the Invention

[0006] The following is a brief summary of one or more aspects to provide a basic understanding of these aspects. This summary is not an exhaustive overview of all conceivable aspects and is neither intended to identify key or critical elements of all aspects nor to define the scope of any or all aspects. Its sole purpose is to present some concepts of one or more aspects in a simplified form as a prelude to the more detailed description that will be provided later.

[0007] In order to overcome the above-mentioned defects of the prior art, the present invention provides a security boundary method for a view library architecture, a security boundary system for a view library architecture, and a computer-readable storage medium, which can have higher security, more accurate error identification capabilities and more efficient processing capabilities to meet the needs of large-scale view library architecture management in real applications.

[0008] Specifically, the security boundary method of the above-mentioned view library architecture provided according to the first aspect of the present invention includes: in response to the notification pushed by the view library, based on the first whitelist in the firewall configured with the exit IP corresponding to the view library, sending the notification to the Kong gateway; obtaining the second whitelist of the Kong gateway according to the national standard ID corresponding to the view library; and in response to the exit IP corresponding to the view library being in the second whitelist, sending the notification to the upper-level platform.

[0009] Preferably, in one embodiment of the present invention, it also includes: according to a preset period, the Kong gateway regularly checks the notification; the Kong gateway parses the checked notification to obtain a parsing result of the notification; and in response to the parsing result being an abnormal parsing result, the abnormal parsing result is saved to a database.

[0010] Preferably, in one embodiment of the present invention, the exception analysis result includes a first level, a second level and a third level with increasing severity, and the security boundary method includes: the Kong gateway determines the level of the exception analysis result according to the notification; in response to the exception analysis result being the first level, the exception analysis result is saved to the database; in response to the exception analysis result being the second level, the exception analysis result is saved to the database and an alarm email is sent to the view library; in response to the exception analysis result being the third level, the exception analysis result is saved to the database, an alarm email is sent to the view library, and the number of exception analysis results of the view library in the database that are the third severity level is queried; and in response to the number exceeding a preset threshold range, the exit IP corresponding to the view library is removed from the first whitelist and / or the second whitelist.

[0011] Preferably, in one embodiment of the present invention, the notification includes a push message and a subscription type, and the step of the Kong gateway determining the level of the exception parsing result based on the notification includes: in response to the push message including redundant fields, determining that the level of the exception parsing result is the first level; in response to the push message not including required fields, determining that the level of the exception parsing result is the second level; and in response to the push message not matching the subscription type, determining that the level of the exception parsing result is the third level.

[0012] Furthermore, according to a second aspect of the present invention, the security boundary system for the view repository architecture includes a memory and a processor. The memory stores computer instructions. The processor is connected to the memory and configured to execute the computer instructions stored in the memory to implement the security boundary method for the view repository architecture provided in any of the above embodiments.

[0013] Furthermore, the computer-readable storage medium provided in accordance with the third aspect of the present invention stores computer instructions, which, when executed by a processor, implement the security boundary method of the view library architecture provided in any one of the above embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] The above features and advantages of the present invention will be better understood after reading the detailed description of the embodiments of the present disclosure in conjunction with the following drawings. In the drawings, the components are not necessarily drawn to scale, and components with similar related properties or characteristics may have the same or similar reference numerals.

[0015] FIG1 shows a flow chart of a security boundary method for a view library architecture according to some embodiments of the present invention; and

[0016] FIG2 shows an architecture diagram of a security boundary system of a view library architecture according to some embodiments of the present invention.

[0017] Figure 1: 100: security boundary method of view library architecture; S110-S130: steps; 200: security boundary system of view library architecture; 210: firewall; 220: Kong gateway; 230: database; 240: monitoring and alarm system; 30: view library; and 40: upper-level platform. DETAILED DESCRIPTION

[0018] The present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. Note that the various aspects described below with reference to the accompanying drawings and specific embodiments are merely exemplary and should not be construed as limiting the scope of protection of the present invention.

[0019] In the description of the present invention, it should be noted that, unless otherwise expressly specified or limited, the terms "mounted," "connected," and "connected" should be understood in a broad sense. For example, they may refer to fixed, detachable, or integral connections; mechanical or electrical connections; direct or indirect connections through an intermediate medium; and internal communication between two components. Those skilled in the art will understand the specific meanings of the above terms in the present invention based on the specific circumstances.

[0020] Furthermore, the terms "upper," "lower," "left," "right," "top," "bottom," "horizontal," and "vertical" used in the following description should be understood to refer to the orientations depicted in that section and the accompanying drawings. These relative terms are used solely for convenience of description and do not necessarily imply that the devices described herein must be manufactured or operated in a specific orientation. Therefore, they should not be construed as limiting the present invention.

[0021] It will be understood that although the terms "first," "second," "third," etc. may be used herein to describe various components, regions, layers, and / or portions, these components, regions, layers, and / or portions should not be limited by these terms, and these terms are merely used to distinguish different components, regions, layers, and / or portions. Thus, a first component, region, layer, and / or portion discussed below may be referred to as a second component, region, layer, and / or portion without departing from some embodiments of the present invention.

[0022] As mentioned above, with the rapid growth of data volumes, the GAT1400-based view library encountered some issues with data interaction and security. It was unable to prevent attacks from malicious lower-level platforms, and when processing large amounts of data notifications, it had certain limitations in detecting and handling abnormal push notifications or erroneous messages.

[0023] In order to overcome the above-mentioned defects of the prior art, the present invention provides a security boundary method for a view library architecture, a security boundary system for a view library architecture, and a computer-readable storage medium, which can have higher security, more accurate error identification capabilities and more efficient processing capabilities to meet the needs of large-scale view library management in real applications.

[0024] In some non-limiting embodiments, the security boundary method for the view library architecture provided in the first aspect of the present invention can be implemented via the security boundary system for the view library architecture provided in the second aspect of the present invention. Specifically, the security boundary system for the view library architecture can be configured with a memory and a processor. The memory includes, but is not limited to, the computer-readable storage medium provided in the third aspect of the present invention, on which computer instructions are stored. The processor is connected to the memory and is configured to execute the computer instructions stored in the memory to implement the security boundary method for the view library architecture provided in the first aspect of the present invention.

[0025] The following will first describe the working principle of the security boundary system of the above-mentioned view library architecture in conjunction with some embodiments of the security boundary method of the view library architecture. Those skilled in the art will understand that the embodiments of the security boundary method of these view library architectures are only some non-restrictive implementation methods provided by the present invention, which are intended to clearly demonstrate the main concept of the present invention and provide some specific solutions that are convenient for the public to implement, rather than to limit all functions or all working methods of the security boundary system of the view library architecture. Similarly, the security boundary system of the view library architecture is also only a non-restrictive implementation method provided by the present invention, and does not constitute a limitation on the execution subject and execution order of each step in the security boundary method of these view library architectures.

[0026] Please refer to FIG1 , which shows a flowchart of a security boundary method for a view library architecture provided according to some embodiments of the present invention.

[0027] As shown in FIG1 , the security boundary method 100 of the view library architecture includes step S110 : in response to a notification pushed by the view library, a notification is sent to the Kong gateway based on the first whitelist in the firewall configured with the exit IP corresponding to the view library.

[0028] Please refer to FIG2 , which shows an architecture diagram of a security boundary system of a view library architecture provided according to some embodiments of the present invention.

[0029] As shown in Figure 2, the security boundary system 200 of the view library architecture receives the notifications pushed by the view library 30. The notifications pushed by the view library 30 can be pushed to the upper-level platform 40 via a dedicated network. Specifically, the view library 30 can accept subscriptions from the upper-level platform 40 and push notifications based on the subscriptions. Preferably, there can be multiple view libraries 30, and the upper-level platform 40 can be a public security upper-level platform. The upper-level platform 40 can receive the notifications pushed by the view library 30 and analyze and display the content contained in the notification (such as pictures in the pushed message). The security boundary system 200, the view library 30 and the upper-level platform 40 of the view library architecture can together constitute the view library architecture. Through the view library architecture, the pictures in the notifications pushed by the view library 30 can be directly stored and pushed to the upper-level platform 40.

[0030] The security boundary system 200 of the view library architecture may include a firewall 210, which is configured with a first whitelist. When the egress IP corresponding to the view library 30 is in the first whitelist, the firewall 210 does not intercept notifications pushed by the view library 30.

[0031] In response to the export IP corresponding to the view library 30 being in the first whitelist, the notification pushed by the view library 30 can continue to be sent to the Kong gateway 220; in response to the export IP corresponding to the view library 30 not being in the first whitelist, the firewall 210 can directly intercept the notification pushed by the view library 30.

[0032] As shown in FIG1 , the security boundary method 100 of the view library architecture further includes step S120 : obtaining a second whitelist of the Kong gateway according to the national standard ID corresponding to the view library.

[0033] Before notifications pushed by the view library 30 are sent to the upper-level platform 40, a Kong gateway 220 is also deployed. This gateway can match and verify the national standard ID and export IP address of the view library 30. Furthermore, the Kong gateway 220 can periodically spot-check and parse notifications to determine if any of them contain any anomalies.

[0034] Specifically, the Kong gateway 220 can obtain the second whitelist of the Kong gateway 220 from the database 230 through the national standard ID corresponding to the view library 30. Here, the national standard ID can be generated based on the administrative region code of the upper-level platform 40 pushed by the view library 30, and the national standard ID can be a dynamic and unique ID. Furthermore, different view libraries 30 may be configured with the same export IP, but not with the same national standard ID. The Kong gateway 220 can confirm whether the export IP of the view library 30 is in the second whitelist obtained based on the national standard ID, so as to achieve matching and combined verification of the national standard ID and the export IP, and further confirm the identity information of the view library 30.

[0035] As shown in FIG1 , the security boundary method 100 of the view library architecture further includes step S130 : in response to the egress IP corresponding to the view library being in the second whitelist, sending a notification to the upper-level platform.

[0036] In response to the export IP of the view library 30 being in the second whitelist, the notification pushed by the view library 30 can continue to be sent to the upper-level platform 40; in response to the export IP of the view library 30 not being in the second whitelist, the Kong gateway 220 can directly intercept the notification pushed by the view library 30.

[0037] In this way, Kong Gateway 220 completes the combined verification of the national standard ID and the export IP address of View Repository 30. By combining the export IP address of View Repository 30 with the verified national standard ID, the View Repository architecture's security boundary system 200 can perform more refined authentication of the lower-level platform View Repository 30, effectively preventing unauthorized access to View Repository 30 and thus protecting data security within the View Repository architecture.

[0038] Furthermore, the Kong gateway 220 can also periodically spot-check notifications. The Kong gateway 220 can periodically spot-check notifications received within a preset period. For example, the Kong gateway 220 spot-checks notifications pushed by the view library 30 every 20 minutes. Afterwards, the Kong gateway 220 can parse the spot-checked notifications and determine whether the spot-checked notifications are abnormal based on the obtained parsing results. In response to the parsing result of the spot-checked notification being an abnormal parsing result, the notification corresponding to the abnormal parsing result can be saved to the database 230.

[0039] Here, the notification may include a push message and a subscription type. The Kong gateway 220 may parse the push message of the randomly checked notification. Preferably, the abnormality parsing result includes a first level, a second level, and a third level with increasing severity.

[0040] In response to the push message including the extra fields, the Kong gateway 220 can determine that the level of the abnormal parsing result is level 1. In a preferred embodiment, the first level can be the abnormal level. When the push message includes the extra fields, the upper-level platform 40 can automatically filter them, thereby not affecting the stability of the view library architecture.

[0041] Furthermore, in response to the exception analysis result being a first level, the Kong gateway 220 can save the notification corresponding to the exception analysis result to the database 230 and record a log through the monitoring and alarm system 240 in the security boundary system 200 of the view library architecture, so that the abnormal problem can be repaired during subsequent inspections and verifications of the view library 30 and / or the upper-level platform 40. Here, the monitoring and alarm system 240 can be a Prometheus system.

[0042] In response to the push message not including the required fields, the Kong gateway 220 may determine that the level of the abnormal analysis result is the second level. In a preferred embodiment, the second level may be a warning level. When the push message does not include the required fields, the pushed data is invalid data, and the upper platform 40 may directly report the abnormality.

[0043] Furthermore, in response to the exception analysis result being the second level, the Kong gateway 220 may save the notification corresponding to the exception analysis result to the database 230 , and then record the log through the monitoring alarm system 240 and send an alarm email to the view library 30 .

[0044] Furthermore, in response to the push message not matching the subscription type, the Kong gateway 220 can determine that the abnormal analysis result is classified as level 3. In a preferred embodiment, level 3 can be a high-risk level. When the push message does not match the subscription type, it indicates a system error (bug) or data anomaly, requiring the security boundary system 200 of the view library architecture to promptly block the notification pushed by the view library 30 to prevent the data in the pushed notification from contaminating the upper-level platform 40.

[0045] The monitoring and alarm system 240 queries the database 230 for the number of consecutive times that the anomaly analysis result of the view library 30 is at the third severity level. In response to the number of consecutive times exceeding a preset threshold range, the corresponding exit IP address of the view library 30 is removed from the first whitelist and / or the second whitelist. For example, if the monitoring and alarm system 240 queries the database 230 and finds that the anomaly analysis result of the view library 30 is high risk more than three times in a row, the monitoring and alarm system 240 records a log and sends an alarm email to the view library 30, and the exit IP address of the view library 30 is removed from the first whitelist and / or the second whitelist.

[0046] By conducting in-depth analysis of notifications pushed by the view library, the view library architecture's security boundary system 200 can more accurately identify and handle errors, improving the stability and reliability of the view library architecture and reducing the likelihood of errors. Furthermore, the view library architecture's security boundary system 200 can efficiently process large amounts of data streams, promptly identifying problems and anomalies in notifications and providing timely alerts and automated processing. This reduces processing time and computing resources.

[0047] In summary, the security boundary method and security boundary system of the view library architecture provided by the present invention effectively solve the problems of the existing view library architecture in terms of security, error identification, and processing efficiency, and have broad application prospects and practical value.

[0048] Although the above methods are illustrated and described as a series of acts for simplicity of explanation, it is to be understood and appreciated that these methods are not limited by the order of the acts, as some acts may occur in a different order and / or concurrently with other acts from those illustrated and described herein or not illustrated and described herein but understandable to those skilled in the art according to one or more embodiments.

[0049] The previous description of the disclosure is provided to enable any person skilled in the art to make or use the disclosure. Various modifications to the disclosure will be apparent to those skilled in the art, and the general principles defined herein may be applied to other variations without departing from the spirit or scope of the disclosure. Thus, the disclosure is not intended to be limited to the examples and designs described herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A security boundary method for a view library architecture, characterized in that: include: In response to the notification pushed by the view library, based on the first whitelist in the firewall configured with the egress IP corresponding to the view library, the notification is sent to the Kong gateway; Obtain the second whitelist of the Kong gateway according to the national standard ID corresponding to the view library; as well as In response to the export IP corresponding to the view library being in the second whitelist, sending the notification to the upper-level platform.

2. The security boundary method according to claim 1, characterized in that: Also includes: According to a preset period, the Kong gateway periodically checks the notification; The Kong gateway parses the randomly selected notification to obtain a parsing result of the notification; as well as In response to the analysis result being an abnormal analysis result, the abnormal analysis result is saved in a database.

3. The security boundary method according to claim 2, characterized in that: The abnormal analysis results include the first level, the second level and the third level with increasing severity, and the safety boundary method includes: The Kong gateway determines the level of the abnormal analysis result according to the randomly checked notification; In response to the abnormality analysis result being the first level, saving the abnormality analysis result to a database; In response to the abnormality analysis result being the second level, saving the abnormality analysis result to a database and sending an alarm email to the view library; In response to the exception analysis result being the third level, saving the exception analysis result to a database, sending an alarm email to the view library, and querying the database for the number of consecutive times that the exception analysis result of the view library is the third severity level; and In response to the continuous number exceeding a preset threshold range, the egress IP corresponding to the view library is removed from the first whitelist and / or the second whitelist.

4. The security boundary method according to claim 3, characterized in that: The notification includes a push message and a subscription type, and the step of the Kong gateway determining the level of the abnormal analysis result according to the notification includes: In response to the push message including a redundant field, determining that the level of the abnormal analysis result is the first level; In response to the push message not including a required field, determining that the level of the abnormal analysis result is the second level; and In response to the push message not matching the subscription type, determining that the level of the abnormal analysis result is the third level.

5. A security boundary system of a view library architecture, characterized in that: include: a memory having computer instructions stored thereon; as well as A processor is connected to the memory and configured to execute computer instructions stored in the memory to implement the security boundary method of the view library architecture according to any one of claims 1 to 4.

6. A computer-readable storage medium having computer instructions stored thereon, characterized in that: When the computer instructions are executed by a processor, the security boundary method of the view library architecture according to any one of claims 1 to 4 is implemented.

Citation Information

Patent Citations

  • Security enhancement equipment for security gateway of rail transit signal system

    CN108183886A

  • Multi-service isolation method and system for micro-service cluster

    CN115567251A

  • National standard-based provincial scheduling system, method and equipment and storage medium

    CN116156191A

  • Security boundary method and system of view library architecture and storage medium

    CN117729020A

  • Methods and systems for identifying data sessions at a VPN gateway

    US20170272554A1