Encryption method, decryption method, device, electronic equipment and storage medium
By decoding and encrypting the video stream, generating a YUV image matrix, and identifying and encrypting feature areas, the problems of video stream expansion and high resource consumption are solved, achieving high security and flexible privacy data protection.
Patent Information
- Application Number
- CN202510780772.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-12
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2045-06-12
AI Technical Summary
Existing video stream encryption methods cause the size of video streams to expand, increase bandwidth consumption and require multiple encoding and decoding, resulting in high resource consumption.
Decode the video stream to generate a YUV image matrix, identify the features to be encrypted and generate a rectangular encryption area, generate a two-dimensional ciphertext matrix through random numbers and video encryption keys, overwrite it to the original image matrix and encode it, and write additional attributes.
Provides highly random and secure encryption solutions, reduces data redundancy, improves privacy data security, and adapts to privacy data encryption needs in different scenarios.
Smart Images

Figure CN120281855B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of image encryption technology, and in particular to an encryption method, a decryption method, a device, an electronic device, and a storage medium. Background Art
[0002] With the rapid development of video surveillance technology, the need to protect private information in video data (such as faces, license plates, and sensitive data) is becoming increasingly urgent. Current methods for visually protecting private information in video streams lack practical application, primarily relying on encryption methods such as mosaics and interpolation. This poses the following risks:
[0003] 1. Data resource expansion: When privacy visual protection is performed through methods such as mosaics and interpolation, the video stream size will expand, resulting in data redundancy and increased bandwidth consumption.
[0004] 2. Low processing efficiency: When using traditional mosaic and other methods for visual privacy protection, multiple encoding and decoding are required, which consumes a lot of resources. Summary of the Invention
[0005] The technical problem to be solved by the embodiments of the present application is to provide an encryption method, a decryption method, an apparatus, an electronic device and a storage medium to solve the problem that the existing encryption method will cause the video stream size to expand, cause data redundancy, increase bandwidth consumption, and require multiple encoding and decoding, resulting in high resource consumption.
[0006] In a first aspect, an embodiment of the present application provides an encryption method, the method comprising:
[0007] Decode the video stream to obtain a YUV image and generate an original image matrix associated with the YUV image;
[0008] Obtaining a rectangular encryption area corresponding to the YUV image according to the identified features to be encrypted in the YUV image;
[0009] Performing position scrambling processing on the matrix corresponding to the rectangular encryption area to obtain a scrambled matrix;
[0010] The scrambled matrix is processed using a random number and a video encryption key to generate a two-dimensional ciphertext matrix, and the random number is SM4 encrypted based on the video encryption key to obtain an encrypted random number;
[0011] Overlaying the two-dimensional ciphertext matrix onto the rectangular encrypted area of the original image matrix to obtain an occluded image matrix, and encoding an occluded video stream obtained by splicing the occluded YUV images in chronological order to obtain an encoded video stream;
[0012] Performing symmetrical encryption processing on the video encryption key based on the video key encryption key obtained by decryption to obtain an encrypted video encryption key;
[0013] The version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number and the rectangular encryption area are written into the additional attributes of the encoded video stream to obtain an encrypted video stream.
[0014] In a second aspect, an embodiment of the present application provides a decryption method, the method comprising:
[0015] Obtaining an encrypted video stream and additional attributes, and decoding the encrypted video stream to obtain a YUV image;
[0016] Extracting the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number and the rectangular encryption area from the additional attributes;
[0017] Determining a video encryption key according to the version number and the encrypted video encryption key;
[0018] Decrypting the encrypted random number based on the video encryption key to obtain a decrypted random number;
[0019] Generate a two-dimensional random matrix according to the size of the rectangular encryption area, and convert the two-dimensional random matrix into a one-dimensional random matrix;
[0020] Determine a two-dimensional restoration matrix based on the random number, the video encryption key, and the one-dimensional random matrix;
[0021] Overlaying the two-dimensional restoration matrix to a position corresponding to the rectangular encrypted area of the YUV image to obtain a decrypted YUV image;
[0022] The decrypted YUV image is encoded to obtain a restored video stream.
[0023] In a third aspect, an embodiment of the present application provides an encryption device, the device comprising:
[0024] The original matrix generation module is used to decode the video stream to obtain a YUV image and generate an original image matrix associated with the YUV image;
[0025] An encryption area acquisition module is used to obtain a rectangular encryption area corresponding to the YUV image according to the identified features to be encrypted in the YUV image;
[0026] A scrambled matrix acquisition module is used to perform position scrambling processing on the matrix corresponding to the rectangular encryption area to obtain a scrambled matrix;
[0027] A random number encryption module, configured to process the scrambled matrix using a random number and a video encryption key to generate a two-dimensional ciphertext matrix, and perform SM4 encryption on the random number based on the video encryption key to obtain an encrypted random number;
[0028] a video stream encoding module, configured to overlay the two-dimensional ciphertext matrix onto the rectangular encrypted area of the original image matrix to obtain an occluded image matrix, and encode an occluded video stream obtained by splicing the occluded YUV images in chronological order to obtain an encoded video stream;
[0029] An encryption key acquisition module is used to perform symmetrical encryption processing on the video encryption key based on the video key encryption key obtained by decryption to obtain an encrypted video encryption key;
[0030] The encrypted video stream acquisition module is used to write the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number and the rectangular encryption area into the additional attributes of the encoded video stream to obtain the encrypted video stream.
[0031] In a fourth aspect, an embodiment of the present application provides a decryption device, the device comprising:
[0032] The video stream decoding module is used to obtain the encrypted video stream and additional attributes, and decode the encrypted video stream to obtain a YUV image;
[0033] An additional information extraction module is used to extract the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number and the rectangular encryption area from the additional attributes;
[0034] an encryption key determination module, configured to determine a video encryption key based on the version number and the encrypted video encryption key;
[0035] A random number decryption module, configured to decrypt the encrypted random number based on the video encryption key to obtain a decrypted random number;
[0036] A random matrix generation module, configured to generate a two-dimensional random matrix according to the size of the rectangular encryption area, and convert the two-dimensional random matrix into a one-dimensional random matrix;
[0037] a restoration matrix determination module, configured to determine a two-dimensional restoration matrix based on the random number, the video encryption key, and the one-dimensional random matrix;
[0038] A YUV image acquisition module, configured to overlay the two-dimensional restoration matrix onto a position corresponding to the rectangular encryption area of the YUV image to obtain a decrypted YUV image;
[0039] The video stream acquisition module is used to encode the decrypted YUV image to obtain a restored video stream.
[0040] In a fifth aspect, an embodiment of the present application provides an electronic device, including:
[0041] A processor, a memory, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the encryption method described in any one of the above items or the decryption method described in any one of the above items is implemented.
[0042] In a sixth aspect, an embodiment of the present application provides a computer-readable storage medium, which, when the instructions in the storage medium are executed by a processor of an electronic device, enables the electronic device to execute any of the encryption methods described above, or any of the decryption methods described above.
[0043] Compared with the prior art, the embodiments of the present application have the following advantages:
[0044] In an embodiment of the present application, a YUV image is obtained by decoding a video stream, and an original image matrix associated with the YUV image is generated. Based on the features to be encrypted in the identified YUV image, a rectangular encryption area corresponding to the YUV image is obtained. The matrix corresponding to the rectangular encryption area is subjected to position scrambling processing to obtain a scrambled matrix. The scrambled matrix is processed using a random number and a video encryption key to generate a two-dimensional ciphertext matrix, and the random number is SM4 encrypted based on the video encryption key to obtain an encrypted random number. The two-dimensional ciphertext matrix is overlaid on the rectangular encryption area of the original image matrix to obtain an occluded image matrix, and the occluded video stream obtained by splicing the occluded image matrix in chronological order is encoded to obtain an encoded video stream. The video encryption key is symmetrically encrypted based on the video key encryption key obtained by decryption to obtain an encrypted video encryption key. The version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number and the rectangular encryption area are written into the additional attributes of the encoded video stream to obtain an encrypted video stream. The embodiments of this application process a scrambled matrix using video encryption keys and random numbers, providing highly random and secure keys for encryption operations, enhancing key scalability and improving the security of private data. Furthermore, random matrix generation and obfuscation techniques are introduced to generate a random matrix that matches the size of the private image block and positionally scramble the associated matrix. This creates a high degree of randomness and irregularity, making the encrypted image difficult to decipher and enhancing the encryption effect. Furthermore, random matrices of corresponding sizes can be flexibly generated based on the size of the private image block, meeting the requirements of private data encryption in different scenarios.
[0045] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] Figure 1 A flowchart of the steps of an encryption method provided in an embodiment of the present application;
[0047] Figure 2 A flowchart of a decryption method provided in an embodiment of the present application;
[0048] Figure 3 A schematic diagram of the structure of an encryption device provided in an embodiment of the present application;
[0049] Figure 4 A schematic diagram of the structure of a decryption device provided in an embodiment of the present application;
[0050] Figure 5 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0051] In order to make the above-mentioned purposes, features and advantages of the present application more obvious and easy to understand, the present application is further described in detail below with reference to the accompanying drawings and specific implementation methods.
[0052] The terms used in the embodiments of the present application are for the purpose of describing specific embodiments only and are not intended to limit the present application. The singular forms "a", "an", "the" and "the" used in the embodiments of the present application and the appended claims are also intended to include plural forms unless the context clearly indicates otherwise.
[0053] Reference Figure 1 , shows a flowchart of the steps of an encryption method provided by an embodiment of the present application. Figure 1 As shown, the encryption method may include: steps 101 to 107.
[0054] Step 101: Decode the video stream to obtain a YUV image, and generate an original image matrix associated with the YUV image.
[0055] In this embodiment, a YUV image is an image format represented in the YUV color space. Essentially, it stores the image's luminance information (Y) separately from its chrominance information (U and V). This unique structure provides significant advantages in video processing and image transmission. In a YUV image, "Y" represents luminance, corresponding to the image's grayscale information, and determines the image's brightness and darkness. "U" and "V" represent chrominance, representing the difference between the blue component and luminance, and the red component and luminance, respectively, and are used to describe the image's color and saturation.
[0056] When encrypting a video stream, the encrypted video stream can be decoded to obtain a YUV image. In a specific implementation, a hardware decoder can be used to decode the video stream to obtain a YUV image. Alternatively, other decoding methods (such as pure software decoding (FFmpeg software decoding)) can be used to decode the video stream to obtain a YUV image.
[0057] When decoding a video stream, if the original video frames of the video stream are all in YUV format, YUV images can be directly obtained through decoding. If the original video frames of the video stream are not in YUV format, the format of the decoded video frames is not in YUV format, and format conversion is required. For example, converting the decoded RGB format or other format frames to YUV format to obtain YUV images.
[0058] After obtaining the YUV image, an original image matrix associated with the YUV image may be generated.
[0059] In a specific implementation of the present application, a chaotic coefficient method may be used to process a YUV image to obtain an original image matrix.
[0060] The chaos coefficient method is an image processing technology based on chaos theory. The generation process can be shown as follows:
[0061] 1. Chaotic system selection and parameter setting.
[0062] First, you need to select a suitable chaotic system, such as Logistic mapping. Then set the parameters. Taking Logistic mapping as an example, you need to set two key parameters: initial value (can be a decimal in the range (0, 1)) and control parameters (Set between 3.57 and 4 to ensure the system is in a chaotic state).
[0063] 2. Random matrix generation process.
[0064] (1) Determine the matrix size: Based on the width and height of the YUV image (i.e., the size of the YUV image), determine that the size of the random matrix needs to match the image pixel matrix.
[0065] (2) Generate chaotic sequence: Use the selected chaotic system to generate the chaotic sequence from the initial value Start iterative calculation, each iteration generates a new value, forming a chaotic sequence.
[0066] (3) Sequence conversion: Map the values in the chaotic sequence (usually between 0 and 1) to the required range (for image encryption, it needs to be mapped to the integer range of 0-255, corresponding to the image pixel value).
[0067] (4) Matrix reshaping: Rearrange the one-dimensional chaotic sequence into a two-dimensional matrix, ensuring that the number of rows and columns of the matrix is consistent with the height and width of the YUV image, thus obtaining the original image matrix.
[0068] In another specific implementation of the present application, a random number method may be used to process the YUV image to obtain the original image matrix. The generation process may be as follows:
[0069] 1. Select a random number generator: a. Use the SM3 algorithm to construct a pseudo-random number generator (PRNG). b. Generate a seed: a) Seed Source: In the digital world, a raw YUV image can be viewed as a unique set of data. The SM3 algorithm is used to calculate a hash value for the raw YUV image. This hash value represents the image's unique digital fingerprint. This hash value is then combined with a timestamp (which reflects the time when the random number was generated and is dynamic) to create a seed. This approach has the advantage of different YUV images having different hash values, and the constantly changing timestamp ensures the uniqueness of each seed. b) Seed Length: Since the SM3 algorithm output is fixed at 256 bits, the seed length is 256 bits. This 256-bit seed contains sufficient information to lay the foundation for subsequent high-quality random number generation.
[0070] 2. Generate a random number sequence: a) Initialize PRNG: Use the SM3-CTR (counter mode) mode generator. CTR mode is a working mode that converts a block cipher into a stream cipher. Here, the generator is initialized with the previously generated 256-bit seed as input. In this way, the internal state of the generator is determined, and based on the image and time-related information contained in the seed, it is prepared for the subsequent generation of a random number sequence. b) Output random bytes: For YUV images, assume that the brightness component Y is to be processed (assuming the size is n×n, where n is the number of pixels of image width or height). At this time, n×n bytes are generated, each byte corresponds to an integer from 0 to 255, forming a random number sequence. These random bytes will be used to construct a random matrix that matches the size of the Y component, and will subsequently be used to process the YUV image.
[0071] 3. Construct a random matrix (i.e., the original image matrix): In row-priority order, Filled to an n×n matrix: , and represent the row elements and column elements of matrix A respectively.
[0072] It can be understood that the above scheme is only a matrix generation method listed for better understanding the technical solution of the embodiment of the present application, and is not the only limitation to this embodiment.
[0073] Step 102: obtaining a rectangular encryption region corresponding to the YUV image according to the identified encryption feature in the YUV image.
[0074] After obtaining the YUV image of the video stream, the encryption feature in the obtained YUV image can be identified. The implementation process can be described in detail in combination with the following specific implementation.
[0075] In a specific implementation of the present application, step 102 can include:
[0076] Sub-step A1: detecting the encryption data in the YUV image.
[0077] In this embodiment, an AI (Artificial Intelligence) model can be used to detect the encryption data in the YUV image, such as detecting private data in the YUV image, such as personal information, license plates, etc.
[0078] The embodiments of the present application can realize accurate positioning of private data, reduce invalid data processing, and improve encryption and decryption efficiency by using an AI model to detect encryption data in the YUV image in real time.
[0079] Of course, in specific implementations, other ways of detecting encryption data in the YUV image can also be used, such as detection methods based on rules and template matching (i.e., matching the visual feature rules or templates of the pre-set private data with the image content). The detection method of the encryption data can be determined according to the business requirements, and the embodiments are not limited in this regard.
[0080] After detecting the encryption data in the YUV image, sub-step A2 is performed.
[0081] Sub-step A2: extracting the encryption feature in the YUV image corresponding to the encryption data.
[0082] After detecting the encryption data in the YUV image, the encryption feature in the YUV image corresponding to the encryption data can be extracted. In this example, the extracted encryption feature is obtained from the private data contained in the YUV image. For example, if the private data is a face in the image, the extracted features include the contour shape features of the face, the color features in the YUV color space, and the skin texture features of the face.
[0083] After extracting the encryption feature in the YUV image corresponding to the encryption data, sub-step A3 is performed.
[0084] Sub-step A3: determining the rectangular encryption region corresponding to the YUV image according to the encryption feature.
[0085] The rectangular encryption area is a Rectangle area, which is used to refer to a specific rectangular range in a video frame and is used for positioning, cropping, encoding, or analyzing image content.
[0086] After extracting the features to be encrypted corresponding to the data to be encrypted in the YUV image, the rectangular encryption area corresponding to the YUV image can be determined based on the features to be encrypted. Specifically, the features to be encrypted in the YUV image can be enclosed into a rectangular area to obtain the rectangular encryption area.
[0087] It is understood that multiple rectangular encryption regions can exist within the same YUV image. For example, if a face and a license plate within a YUV image need to be encrypted, and the features corresponding to the face and license plate are located at different positions within the image, then the face and license plate can form two rectangular encryption regions. Specifically, the number of rectangular encryption regions for a YUV image can be determined based on the specific situation and is not limited in this embodiment.
[0088] In the embodiment of the present application, from detection to feature extraction to area determination, no human intervention is required, and it is adapted to large-scale image privacy protection scenarios.
[0089] After obtaining the rectangular encryption area corresponding to the YUV image according to the identified features to be encrypted in the YUV image, step 103 is executed.
[0090] Step 103: Perform position scrambling processing on the matrix corresponding to the rectangular encryption area to obtain a scrambled matrix.
[0091] After obtaining the rectangular encryption area, a matrix can be generated based on the rectangular encryption area, and the matrix can be subjected to position scrambling processing to obtain a scrambled matrix. This implementation process can be described in detail in conjunction with the following specific implementation method.
[0092] In a specific implementation of the present application, the above step 103 may include:
[0093] Sub-step B1: Generate a two-dimensional random matrix associated with the rectangular encryption area according to the size of the rectangular encryption area.
[0094] In this embodiment, after obtaining the rectangular encryption area, a two-dimensional random matrix associated with the rectangular encryption area can be generated based on the size of the rectangular encryption area. Specifically, the width (W) and height (H) of the rectangular encryption area (i.e., the size of the rectangular encryption area) can be obtained to determine the dimensions of the two-dimensional matrix as W×H. Then, a cryptographically secure pseudo-random number generator is used, using image metadata (such as the capture timestamp and YUV component hash values) as a seed to ensure randomness and reproducibility. Finally, a random integer filling matrix (i.e., a two-dimensional random matrix) in the range of 0-255 can be generated according to the row-major principle, with each element corresponding to an 8-bit binary value (suitable for 8-bit image pixel encryption).
[0095] The embodiment of the present application ensures that subsequent encryption operations correspond pixel by pixel and avoids data misalignment by making the matrix size completely consistent with the encryption area.
[0096] After a two-dimensional random matrix associated with the rectangular encryption area is generated according to the size of the rectangular encryption area, sub-step B2 is performed.
[0097] Sub-step B2: Convert the two-dimensional random matrix into a one-dimensional random matrix.
[0098] After generating a two-dimensional random matrix associated with the rectangular encryption area based on its dimensions, the two-dimensional random matrix can be converted into a one-dimensional random matrix. Specifically, all elements of the two-dimensional matrix can be expanded into a one-dimensional array in row-major order, thereby obtaining a one-dimensional random matrix.
[0099] Sub-step B3: Generate a one-dimensional matrix of the same length as the one-dimensional random matrix.
[0100] After converting the two-dimensional random matrix into a one-dimensional random matrix, a one-dimensional matrix having the same length as the one-dimensional random matrix can be generated. Specifically, a chaotic coefficient method or a random number method can be used to generate a one-dimensional matrix having the same length as the one-dimensional random matrix.
[0101] After generating a one-dimensional matrix having the same length as the one-dimensional random matrix, sub-step B4 is performed.
[0102] Sub-step B4: performing position scrambling processing on the one-dimensional random matrix and the matrix elements in the one-dimensional matrix to obtain the scrambled matrix.
[0103] After generating a one-dimensional matrix of the same length as the one-dimensional random matrix, the matrix elements in the one-dimensional random matrix and the one-dimensional matrix can be scrambled to obtain a scrambled matrix. Specifically, a confusion operation can be performed on the one-dimensional random matrix and the one-dimensional matrix to scramble the coordinate values in the two matrices to exchange the coordinate positions in the two matrices, thereby obtaining a scrambled matrix.
[0104] In the embodiments of this application, random matrix generation and obfuscation technology is introduced. Chaotic coefficients and random numbers are used to generate random matrices that match the size of the private image blocks. The position of the relevant matrices is then scrambled. This creates a high degree of randomness and irregularity, making the encrypted image difficult to decrypt and enhancing the encryption effect. Furthermore, random matrices of corresponding sizes can be flexibly generated based on the size of the private image blocks, meeting the needs of private data encryption in different scenarios.
[0105] After the scrambled matrix is obtained, step 104 is executed.
[0106] Step 104: Use a random number and a video encryption key to process the scrambled matrix to generate a two-dimensional ciphertext matrix, and perform SM4 encryption on the random number based on the video encryption key to obtain an encrypted random number.
[0107] The Video Encryption Key (VEK) is the key used to directly encrypt and decrypt video data. It is the actual key for encrypting video content.
[0108] After obtaining the scrambled matrix, a random number generator can be used to generate a random number S. The random number and the video encryption key are then used to process the scrambled matrix to generate a two-dimensional ciphertext matrix. This implementation process can be described in detail in conjunction with the following specific implementation method.
[0109] In a specific implementation of the present application, the above step 104 may include:
[0110] Sub-step C1: Generate the random number and the video encryption key.
[0111] In this embodiment, a random number generator may be used to generate the random number S.
[0112] The video encryption key generation process can be as follows: obtaining key material (such as user active input, video content hash, current system timestamp, etc.), and then using a key derivation function to derive the key material into an encryption key of fixed length, namely the video encryption key, to ensure the randomness and unpredictability of the key.
[0113] After the random number and the video encryption key are generated, sub-step C2 is performed.
[0114] Sub-step C2: Based on the random number and the video encryption key, generate a one-dimensional target matrix of the same length as the scrambling matrix through a key splitting function.
[0115] A Key Derivation Function (KDF) is a function that derives one or more keys from initial keying material, such as passwords, keys, or shared secrets. The purpose is to transform the input keying material into keys suitable for a particular cryptographic application, while providing key expansion and enhanced security.
[0116] After generating the random number and the video encryption key, a one-dimensional target matrix equal in length to the scrambling matrix can be generated by a key derivation function based on the random number and the video encryption key. Specifically, the key derivation process can be: 1. Parameter configuration: salt value (represented by the random number S), keying material (i.e., the video encryption key VEK), output length (set to the number of elements N of the scrambling matrix), information parameter (optional fixed string, used to distinguish different derivation scenarios, such as the image encryption scenario in this embodiment). 2. Perform KDF calculation: derived key = KDF (salt value = S, input keying material = VEK, output length = N, information = fixed string). 3. Generate a one-dimensional target matrix E, convert the output byte sequence of length N into a numerical array in order, determine the data type of the array (such as uint8, etc.) as needed, and ensure that the array length is exactly the same as the number of elements of the scrambling matrix, to generate a one-dimensional target matrix E.
[0117] Meanwhile, the random number can be encrypted using the video encryption key using SM4 (SM4 is a block cipher algorithm published by the National Cryptography Administration of China, belonging to a symmetric encryption algorithm) to obtain an encrypted random number, which can be attached to the additional attributes of the video stream for transmission to the receiving end for subsequent decryption process.
[0118] After generating the one-dimensional target matrix, sub-step C3 is performed.
[0119] Sub-step C3: Perform a bitwise AND operation on the scrambling matrix and the one-dimensional target matrix to generate a one-dimensional ciphertext matrix.
[0120] AND operation, also known as logical multiplication, is a binary logical operation. Its definition is: only when all logical variables participating in the operation take the value of true (True), the result of the AND operation is true. As long as one logical variable takes the value of false (False), the result is false.
[0121] After generating the one-dimensional target matrix, a bitwise AND operation can be performed on the scrambling matrix and the one-dimensional target matrix to generate a one-dimensional ciphertext matrix.
[0122] Sub-step C4: Convert the one-dimensional ciphertext matrix into the two-dimensional ciphertext matrix.
[0123] After obtaining the one-dimensional ciphertext matrix, the one-dimensional ciphertext matrix can be converted into a two-dimensional ciphertext matrix. The specific process can be: 1. Determine the shape of the two-dimensional ciphertext matrix: assuming that the length of the one-dimensional ciphertext matrix is n, the one-dimensional ciphertext matrix needs to be converted into a two-dimensional ciphertext matrix M with a shape of (row, column), and it needs to satisfy row * column = n. For example, the one-dimensional ciphertext matrix is [4, 2, 3, 0, 5, 7] (length n = 6), and the two-dimensional matrix shape can be selected as (1) row = 2, column = 3, and the two-dimensional matrix shape is 2 * 3. (2) row = 3, column = 2, and the two-dimensional matrix shape is 3 * 2, etc. (which can be selected according to business requirements). 2. Select the element filling order: (1) row priority, that is, fill the elements in turn according to the row, that is, fill the first row first, then fill the second row, and so on. (2) column priority, that is, fill the elements in turn according to the column, that is, fill the first column first, then fill the second column, and so on. After filling, the two-dimensional ciphertext matrix can be obtained.
[0124] The embodiment of the application derives a key matrix with the same length as the scrambling matrix from the VEK and the random number S by using the key splitting technology KDF, can provide a high-randomness, high-security key for encryption operation, enhances the expansibility of the key, and improves the security of the private data.
[0125] Step 105: cover the two-dimensional ciphertext matrix to the rectangular encryption region of the original image matrix to obtain a shielded image matrix, and encode the shielded video stream obtained by splicing the shielded YUV images in time sequence to obtain an encoded video stream.
[0126] After obtaining the two-dimensional ciphertext matrix, the two-dimensional ciphertext matrix can be covered to the rectangular encryption region of the original image matrix, so as to obtain a shielded image matrix, and thus the visual shielding of the private data can be completed. Then, the shielded video stream obtained by splicing the shielded YUV images in time sequence can be encoded, so as to obtain an encoded video stream. The specific process can be: 1. Ciphertext superposition: cover the two-dimensional ciphertext matrix F2 to the Rect region (i.e. the rectangular encryption region) of the original image matrix A, replace the original pixel value, and realize visual shielding (the size of the Rect region is m * m). 2. Video stream encoding: encode the superimposed video stream by using a preset encoding mode (such as H.264, H.265, etc.) to obtain an encoded video stream.
[0127] Step 106: perform symmetric encryption processing on the video encryption key based on the decrypted video key encryption key to obtain an encrypted video encryption key.
[0128] The video key encryption key (Video Key Encryption Key, VKEK) is a key used to encrypt the VEK, and mainly functions to protect the security of the VEK itself.
[0129] Before the encapsulation of the encoded video stream, the video encryption key can be encrypted. Specifically, the video key encryption key can be decrypted first. Then, the video encryption key is symmetrically encrypted using the video key encryption key to obtain the encrypted video encryption key. The encryption process can be described in detail in combination with the following specific implementation manners.
[0130] In a specific implementation of the present application, the step 105 can include:
[0131] Sub-step D1: obtaining the video key encryption ciphertext from the key management center, the video key encryption ciphertext being a ciphertext based on SM2 public key encryption.
[0132] In the embodiment, the key management center is a security system responsible for generating, distributing, storing and managing encryption keys.
[0133] The video key encryption ciphertext is the result of encrypting the "video key encryption key" using the SM2 public key.
[0134] SM2 is an elliptic curve public key cryptography algorithm published by the National Cryptography Administration of China, which is used for digital signature, key exchange and encryption.
[0135] When encrypting the video encryption key, the video key encryption ciphertext based on SM2 public key encryption can be obtained from the key management center.
[0136] Sub-step D2: decrypting the video key encryption ciphertext based on the SM2 private key corresponding to the SM2 public key to obtain the video key encryption key.
[0137] After obtaining the video key encryption ciphertext, the video key encryption ciphertext can be decrypted using the SM2 private key corresponding to the SM2 public key to obtain the video key encryption key.
[0138] In the above process, the key management center can use a hardware security module to generate an SM2 key pair, transmit the SM2 private key to the local device through a secure channel (such as a key agreement protocol), and store the SM2 public key in the key directory in the ciphertext management center, and use it to encrypt the video key encryption ciphertext.
[0139] Sub-step D3: symmetrically encrypting the video encryption key based on the video key encryption key to obtain the encrypted video encryption key.
[0140] The encrypted video encryption key (Encrypted VEK, EVEK) is the ciphertext form of the VEK encrypted by the VKEK.
[0141] After the video key encryption key is obtained, the video encryption key may be symmetrically encrypted using the video key encryption key to obtain an encrypted video encryption key.
[0142] In the embodiment of this application, the national secret SM2 and SM4 algorithms are used to build a full-link national secret compliant privacy visual encryption solution to solve the problem of conflict between traditional encryption and video encoding.
[0143] Step 107: Write the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number and the rectangular encryption area into the additional attributes of the encoded video stream to obtain an encrypted video stream.
[0144] VKEK Version (i.e., the version number of the video key encryption key) is a unique number or label used to identify and manage different VKEK versions. It is designed to support key lifecycle management, rotation strategies, and coexistence of multiple versions, ensuring that encrypted data can still be correctly decrypted after the key is updated.
[0145] In this example, the VKEK Version may be obtained from the ciphertext management center when the video key encrypted ciphertext is obtained.
[0146] The above steps yield the encrypted video encryption key, encrypted random number, and rectangular encryption region. The version number of the video key encryption key, the encrypted video encryption key, the encrypted random number, and the rectangular encryption region can then be written into the additional attributes of the encoded video stream to yield an encrypted video stream. The data in the additional attributes can be used to assist the video stream receiver in completing the video frame decryption process.
[0147] The encryption method provided in the embodiment of the present application obtains a YUV image by decoding the video stream and generates an original image matrix associated with the YUV image. According to the features to be encrypted in the identified YUV image, a rectangular encryption area corresponding to the YUV image is obtained. The matrix corresponding to the rectangular encryption area is subjected to position scrambling processing to obtain a scrambled matrix. The scrambled matrix is processed using a random number and a video encryption key to generate a two-dimensional ciphertext matrix, and the random number is SM4 encrypted based on the video encryption key to obtain an encrypted random number. The two-dimensional ciphertext matrix is overlaid on the rectangular encryption area of the original image matrix to obtain an occluded image matrix, and the occluded video stream obtained by splicing the occluded image matrix in chronological order is encoded to obtain an encoded video stream. The video encryption key is symmetrically encrypted based on the video key encryption key obtained by decryption to obtain an encrypted video encryption key. The version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number and the rectangular encryption area are written into the additional attributes of the encoded video stream to obtain an encrypted video stream. The embodiments of this application process a scrambled matrix using video encryption keys and random numbers, providing highly random and secure keys for encryption operations, enhancing key scalability and improving the security of private data. Furthermore, random matrix generation and obfuscation techniques are introduced to generate a random matrix that matches the size of the private image block and positionally scramble the associated matrix. This creates a high degree of randomness and irregularity, making the encrypted image difficult to decipher and enhancing the encryption effect. Furthermore, random matrices of corresponding sizes can be flexibly generated based on the size of the private image block, meeting the requirements of private data encryption in different scenarios.
[0148] Reference Figure 2 , shows a flowchart of the steps of a decryption method provided by an embodiment of the present application. Figure 2 As shown, the decryption method may include: steps 201 to 208.
[0149] Step 201: Obtain an encrypted video stream and additional attributes, and decode the encrypted video stream to obtain a YUV image.
[0150] In this embodiment, an encrypted video stream and its additional attributes can be obtained and decoded to obtain a YUV image. Specifically, an encrypted video stream encoded in a coding method such as H.264 / H.255 can be obtained and decoded into a frame image in a YUV format, i.e., a YUV image, using a hardware decoder.
[0151] Step 202: extract the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number and the rectangular encryption area from the additional attributes.
[0152] At the same time, the version number (VKEK version) corresponding to the video key encryption key, the encrypted video encryption key (EVEK), the encrypted random number (S1), and the rectangular encryption area (Rect) in the additional attributes can be extracted.
[0153] Step 203: Determine the video encryption key according to the version number and the encrypted video encryption key.
[0154] After obtaining the version number corresponding to the video key encryption key and the encrypted video encryption key, the video encryption key can be determined based on the version number and the encrypted video encryption key. Specifically, the process may include obtaining ciphertext encrypted using the SM2 public key from the key management center based on the version number, decrypting the video key encryption ciphertext using the SM2 private key corresponding to the SM2 public key to obtain the video key encryption key. Finally, symmetrically decrypting the encrypted video encryption key using the video key encryption key to obtain the video encryption key.
[0155] After the video encryption key is obtained, step 204 is executed.
[0156] Step 204: Decrypt the encrypted random number based on the video encryption key to obtain a decrypted random number.
[0157] After the video encryption key is obtained, the encrypted random number S1 may be decrypted using SM4 based on the video encryption key to obtain a decrypted random number S.
[0158] Step 205: Generate a two-dimensional random matrix according to the size of the rectangular encryption area, and convert the two-dimensional random matrix into a one-dimensional random matrix.
[0159] After the rectangular encryption area is extracted, a two-dimensional random matrix can be generated according to the size of the rectangular encryption area, and then the two-dimensional random matrix can be converted into a one-dimensional random matrix.
[0160] It can be understood that the generation and conversion process of the two-dimensional random matrix is similar to that in the above embodiment, and will not be described in detail in this embodiment.
[0161] Step 206: Determine a two-dimensional restoration matrix based on the random number, the video encryption key, and the one-dimensional random matrix.
[0162] The two-dimensional restoration matrix refers to a matrix used to restore the encrypted area in the video image.
[0163] After obtaining a one-dimensional random matrix, a two-dimensional restoration matrix can be determined based on the random number, the video encryption key, and the one-dimensional random matrix. The specific implementation process can be as follows: Based on the random number and the video encryption key, a one-dimensional target matrix of the same length as the one-dimensional random matrix is generated using a key splitting function. Then, a bitwise OR operation (also known as logical addition, a binary logical operation defined as true as long as at least one of the logical variables involved in the operation is true; the result is false only when all logical variables are false) is performed on the one-dimensional random matrix and the one-dimensional target matrix to obtain a one-dimensional ciphertext matrix. The one-dimensional ciphertext matrix is then converted to a two-dimensional ciphertext matrix. Finally, the matrix elements of the two-dimensional ciphertext matrix can be sorted according to the rectangular encryption area to obtain a two-dimensional restoration matrix.
[0164] In the above implementation, the matrix element positions of the two-dimensional ciphertext matrix are sorted by restoring the original indexes according to the permutation rule used during encryption, thereby reordering the element positions. In this process, the permutation rule is implicitly synchronized through the random number S and VEK generated during encryption, as well as the shared algorithmic logic. After the video stream receiver obtains S and VEK through decryption, it regenerates the random sequence using the same chaotic coefficient method or random number method, ensuring that the random sequences generated based on S and VEK are completely consistent. The permutation rule used during encryption can be reproduced based on the same algorithmic logic, without the need to transmit the rule itself.
[0165] Step 207: Overlay the two-dimensional restoration matrix to the position corresponding to the rectangular encrypted area of the YUV image to obtain a decrypted YUV image.
[0166] After obtaining the two-dimensional restoration matrix, the two-dimensional restoration matrix can be overlaid to the position corresponding to the rectangular encrypted area of the YUV image to replace the rectangular encrypted area to obtain the decrypted YUV image.
[0167] Step 208: Encode the decrypted YUV image to obtain a restored video stream.
[0168] After obtaining the decrypted YUV images, the decrypted YUV images can be arranged in chronological order and encoded (such as re-encoding into the original RGB format, etc.) to obtain a restored video stream.
[0169] The decryption method provided by the embodiments of the present application obtains the YUV image by acquiring the encrypted video stream and the additional attribute and performing decoding processing on the encrypted video stream. The version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number and the rectangular encryption region in the additional attribute are extracted. The video encryption key is determined according to the version number and the encrypted video encryption key. The encrypted random number is decrypted based on the video encryption key to obtain the decrypted random number. A two-dimensional random matrix is generated according to the size of the rectangular encryption region, and the two-dimensional random matrix is converted into a one-dimensional random matrix. A two-dimensional restoration matrix is determined based on the random number, the video encryption key and the one-dimensional random matrix. The two-dimensional restoration matrix is overlaid to the position corresponding to the rectangular encryption region of the YUV image to obtain the decrypted YUV image. The decrypted YUV image is encoded to obtain the restored video stream. The embodiments of the present application achieve a good balance between security, performance and flexibility through innovative key management, selective encryption of regions and random matrix confusion. It is particularly suitable for application scenarios that have strict requirements for sensitive information protection and need to ensure video processing efficiency. Compared with the traditional scheme, the calculation overhead, storage efficiency and privacy protection capability are significantly improved.
[0170] In the intelligent monitoring system, the video stream may contain sensitive face information. In order to protect privacy, the face region in the video frame needs to be encrypted to ensure that only authorized users can decrypt and restore the original image. The technical scheme of the embodiments can realize efficient and accurate privacy protection through the following steps:
[0171] I. Encryption process:
[0172] 1. Convert the video stream into a YUV image, and generate an n x n random matrix A using chaotic coefficients according to the image.
[0173] 2. Detect all faces in the image using a pre-trained AI model and perform feature extraction, and the collection is a feature block Rect (i.e., a rectangular encryption region).
[0174] 3. Generate a two-dimensional random matrix B1 according to Rect, and convert the two-dimensional random matrix B1 into a one-dimensional matrix B2.
[0175] 4. Generate a matrix C that is the same length as matrix B2, and perform position scrambling operation on matrix B2 and matrix C to generate matrix D.
[0176] 5. Generate a random number S and a VEK, and use the key splitting function KDF to generate a matrix E that is the same length as matrix D using the random number S and the VEK. Perform AND operation on matrix D and matrix E to generate matrix F1, and convert one-dimensional matrix F1 into two-dimensional matrix F2.
[0177] 6. Superimpose the two-dimensional matrix F2 on the original matrix A to complete the visual occlusion of the private data, and use VEK to perform SM4 encryption on the random number S to obtain S1, obtain VKEK, and use VKEK to symmetric encrypt VEK to obtain EVEK. Write the VKEK version (version number), EVEK, random number S1, and characteristic block Rect into the additional attributes of the video stream encoding, and output the encrypted video stream.
[0178] 2. Decryption process:
[0179] 1. When the authorized user decodes, he extracts the relevant information from the additional attributes, applies for the corresponding encrypted VKEK from the key management center according to the VKEK version, decrypts the encrypted VKEK using the private key to obtain VKEK, decrypts EVEK using the VKEK to obtain VEK, and decrypts the random number S1 using the VEK to obtain the random number S.
[0180] 2. Generate a two-dimensional random matrix G1 based on the characteristic square Rect, and convert the two-dimensional random matrix G1 into a one-dimensional matrix G2.
[0181] 3. Use the key splitting function KDF to generate a matrix H with the same length as the matrix G2 using the random number S and VEK.
[0182] 4. Perform an OR operation on matrix G2 and matrix H to generate a one-dimensional matrix I1, and then convert the one-dimensional matrix I1 into a two-dimensional matrix I2.
[0183] 5. According to the original feature block Rect, the matrix I2 is restored to the original pixel arrangement, and then superimposed on the YUV image to restore the face area.
[0184] It can be understood that the encryption and decryption method of the embodiment of the present application can be applied not only to the scenario of the intelligent monitoring system, but also to other scenarios (such as enterprise information transmission, etc.), and this embodiment does not limit this.
[0185] Reference Figure 3 , shows a schematic diagram of the structure of an encryption device provided by an embodiment of the present application. Figure 3 As shown, the encryption device 300 may include the following modules:
[0186] The original matrix generation module 310 is used to decode the video stream to obtain a YUV image and generate an original image matrix associated with the YUV image;
[0187] The encryption area acquisition module 320 is configured to obtain a rectangular encryption area corresponding to the YUV image according to the identified features to be encrypted in the YUV image;
[0188] A scrambled matrix acquisition module 330 is configured to perform position scrambling processing on the matrix corresponding to the rectangular encryption area to obtain a scrambled matrix;
[0189] A random number encryption module 340 is configured to process the scrambled matrix using a random number and a video encryption key to generate a two-dimensional ciphertext matrix, and perform SM4 encryption on the random number based on the video encryption key to obtain an encrypted random number;
[0190] A video stream encoding module 350 is configured to overlay the two-dimensional ciphertext matrix onto the rectangular encrypted area of the original image matrix to obtain an occluded image matrix, and encode an occluded video stream obtained by splicing the occluded YUV images in chronological order to obtain an encoded video stream;
[0191] An encryption key acquisition module 360 is configured to perform symmetrical encryption processing on the video encryption key based on the video key encryption key obtained by decryption to obtain an encrypted video encryption key;
[0192] The encrypted video stream acquisition module 370 is used to write the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number and the rectangular encryption area into the additional attributes of the encoded video stream to obtain the encrypted video stream.
[0193] Optionally, the encrypted area acquisition module includes:
[0194] An encrypted data detection unit, configured to detect the data to be encrypted in the YUV image;
[0195] A feature extraction unit for extracting features to be encrypted corresponding to the data to be encrypted in the YUV image;
[0196] The encryption area determination unit is used to determine the rectangular encryption area corresponding to the YUV image according to the feature to be encrypted.
[0197] Optionally, the scrambling matrix acquisition module includes:
[0198] A two-dimensional matrix generating unit, configured to generate a two-dimensional random matrix associated with the rectangular encryption area according to the size of the rectangular encryption area;
[0199] A random matrix conversion unit, used for converting the two-dimensional random matrix into a one-dimensional random matrix;
[0200] A one-dimensional matrix generating unit, configured to generate a one-dimensional matrix having the same length as the one-dimensional random matrix;
[0201] The scrambled matrix acquisition unit is used to perform position scrambling processing on the one-dimensional random matrix and the matrix elements in the one-dimensional matrix to obtain the scrambled matrix.
[0202] Optionally, the random number encryption module comprises:
[0203] a random number generation unit configured to generate the random number and the video encryption key;
[0204] a target matrix generation unit configured to generate, by a key splitting function, a one-dimensional target matrix equal in length to the scrambling matrix based on the random number and the video encryption key;
[0205] a ciphertext matrix generation unit configured to perform a bitwise AND operation on the scrambling matrix and the one-dimensional target matrix to generate a one-dimensional ciphertext matrix;
[0206] a ciphertext matrix conversion unit configured to convert the one-dimensional ciphertext matrix into the two-dimensional ciphertext matrix.
[0207] Optionally, the encryption key acquisition module comprises:
[0208] an encrypted ciphertext acquisition unit configured to acquire a video key encryption ciphertext from a key management center, the video key encryption ciphertext being a ciphertext encrypted based on an SM2 public key;
[0209] a video key acquisition unit configured to decrypt the video key encryption ciphertext based on an SM2 private key corresponding to the SM2 public key to obtain the video key encryption key;
[0210] an encryption key acquisition unit configured to perform symmetric encryption processing on the video encryption key based on the video key encryption key to obtain an encrypted video encryption key.
[0211] The encryption device provided in the embodiment of the present application obtains a YUV image by decoding the video stream and generates an original image matrix associated with the YUV image. Based on the features to be encrypted in the identified YUV image, a rectangular encryption area corresponding to the YUV image is obtained. The matrix corresponding to the rectangular encryption area is subjected to position scrambling processing to obtain a scrambled matrix. The scrambled matrix is processed using a random number and a video encryption key to generate a two-dimensional ciphertext matrix, and the random number is SM4 encrypted based on the video encryption key to obtain an encrypted random number. The two-dimensional ciphertext matrix is overlaid on the rectangular encryption area of the original image matrix to obtain an occluded image matrix, and the occluded video stream obtained by splicing the occluded image matrix in chronological order is encoded to obtain an encoded video stream. The video encryption key is symmetrically encrypted based on the video key encryption key obtained by decryption to obtain an encrypted video encryption key. The version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number and the rectangular encryption area are written into the additional attributes of the encoded video stream to obtain an encrypted video stream. The embodiments of this application process a scrambled matrix using video encryption keys and random numbers, providing highly random and secure keys for encryption operations, enhancing key scalability and improving the security of private data. Furthermore, random matrix generation and obfuscation techniques are introduced to generate a random matrix that matches the size of the private image block and positionally scramble the associated matrix. This creates a high degree of randomness and irregularity, making the encrypted image difficult to decipher and enhancing the encryption effect. Furthermore, random matrices of corresponding sizes can be flexibly generated based on the size of the private image block, meeting the requirements of private data encryption in different scenarios.
[0212] Reference Figure 4 , shows a schematic diagram of the structure of a decryption device provided by an embodiment of the present application. Figure 4 As shown, the decryption device 400 may include the following modules:
[0213] The video stream decoding module 410 is used to obtain the encrypted video stream and additional attributes, and decode the encrypted video stream to obtain a YUV image;
[0214] Additional information extraction module 420, used to extract the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number and the rectangular encryption area from the additional attributes;
[0215] an encryption key determination module 430, configured to determine a video encryption key based on the version number and the encrypted video encryption key;
[0216] A random number decryption module 440 is configured to decrypt the encrypted random number based on the video encryption key to obtain a decrypted random number;
[0217] A random matrix generation module 450 is configured to generate a two-dimensional random matrix according to the size of the rectangular encryption area, and convert the two-dimensional random matrix into a one-dimensional random matrix;
[0218] a restoration matrix determination module 460 , configured to determine a two-dimensional restoration matrix based on the random number, the video encryption key, and the one-dimensional random matrix;
[0219] A YUV image acquisition module 470 is configured to overlay the two-dimensional restoration matrix onto a position corresponding to the rectangular encryption area of the YUV image to obtain a decrypted YUV image;
[0220] The video stream acquisition module 480 is used to encode the decrypted YUV image to obtain a restored video stream.
[0221] Optionally, the encryption key determination module includes:
[0222] A ciphertext obtaining unit, configured to obtain, from a key management center according to the version number, a video key encrypted ciphertext, wherein the video key encrypted ciphertext is a ciphertext encrypted based on the SM2 public key;
[0223] A first key acquisition unit is configured to decrypt the video key encrypted ciphertext based on the SM2 private key corresponding to the SM2 public key to obtain a video key encryption key;
[0224] The second key acquisition unit is configured to perform symmetric decryption processing on the encrypted video encryption key based on the video key encryption key to obtain the video encryption key.
[0225] Optionally, the reduction matrix determination module includes:
[0226] a one-dimensional target matrix generating unit, configured to generate a one-dimensional target matrix having the same length as the one-dimensional random matrix by a key splitting function based on the random number and the video encryption key;
[0227] a one-dimensional ciphertext matrix acquisition unit, configured to perform a bitwise OR operation on the one-dimensional random matrix and the one-dimensional target matrix to obtain a one-dimensional ciphertext matrix;
[0228] a one-dimensional ciphertext matrix conversion unit, configured to convert the one-dimensional ciphertext matrix into a two-dimensional ciphertext matrix;
[0229] The restoration matrix acquisition unit is used to sort the positions of the matrix elements of the two-dimensional ciphertext matrix according to the rectangular encryption area to obtain the two-dimensional restoration matrix.
[0230] The decryption device provided in an embodiment of the present application obtains an encrypted video stream and additional attributes, and decodes the encrypted video stream to obtain a YUV image. The device then extracts the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number, and the rectangular encryption area from the additional attributes. The video encryption key is determined based on the version number and the encrypted video encryption key. The encrypted random number is decrypted based on the video encryption key to obtain a decrypted random number. A two-dimensional random matrix is generated based on the size of the rectangular encryption area, and the two-dimensional random matrix is converted into a one-dimensional random matrix. A two-dimensional restoration matrix is determined based on the random number, the video encryption key, and the one-dimensional random matrix. The two-dimensional restoration matrix is overlaid onto the position corresponding to the rectangular encryption area of the YUV image to obtain a decrypted YUV image. The decrypted YUV image is encoded to obtain a restored video stream. Through innovative key management, region-selective encryption, and random matrix obfuscation, the embodiment of the present application achieves an optimal balance between security, performance, and flexibility. This device is particularly suitable for applications that require strict protection of sensitive information while also ensuring efficient video processing. Compared to traditional solutions, it offers significant improvements in computational overhead, storage efficiency, and privacy protection.
[0231] An embodiment of the present application also provides an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program implements the above-mentioned encryption method or the above-mentioned decryption method when executed by the processor.
[0232] Figure 5 FIG. 5 shows a schematic structural diagram of an electronic device 500 according to an embodiment of the present invention. Figure 5 As shown, electronic device 500 includes a central processing unit (CPU) 501, which can perform various appropriate actions and processes according to computer program instructions stored in read-only memory (ROM) 502 or loaded from storage unit 508 into random access memory (RAM) 503. RAM 503 can also store various programs and data required for the operation of electronic device 500. CPU 501, ROM 502, and RAM 503 are connected to each other via bus 504. Input / output (I / O) interface 505 is also connected to bus 504.
[0233] Multiple components in the electronic device 500 are connected to the I / O interface 505, including an input unit 506, such as a keyboard, a mouse, a microphone, etc.; an output unit 507, such as various types of displays, speakers, etc.; a storage unit 508, such as a magnetic disk, an optical disk, etc.; and a communication unit 509, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 509 allows the electronic device 500 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0234] The various processes and processing described above may be performed by the processing unit 501. For example, the method of any of the above embodiments may be implemented as a computer software program, which is tangibly contained in a computer-readable medium, such as the storage unit 508. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 500 via the ROM 502 and / or the communication unit 509. When the computer program is loaded into the RAM 503 and executed by the CPU 501, one or more actions in the method described above may be performed.
[0235] In addition, an embodiment of the present application further provides a computer-readable storage medium on which a computer program is stored, and when the program is executed by a processor, the above-mentioned encryption method or the above-mentioned decryption method is implemented.
[0236] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.
[0237] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, devices, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0238] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of the methods, terminals (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0239] These computer program instructions may also be stored in a computer readable memory capable of directing a computer or other programmable data processing terminal to operate in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0240] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal so that a series of operational steps are executed on the computer or other programmable terminal to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable terminal for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0241] Although preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they become aware of the basic inventive concepts. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present invention.
[0242] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or terminal. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or terminal comprising the element.
[0243] The above is a detailed introduction to an encryption method, decryption method, device, electronic device and computer-readable storage medium provided by the present application. Specific examples are used herein to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea. At the same time, for a person skilled in the art, according to the idea of the present application, there may be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.
Claims
1. An encryption method, characterized in that: The method comprises: Decode the video stream to obtain a YUV image and generate an original image matrix associated with the YUV image; Obtaining a rectangular encryption area corresponding to the YUV image according to the identified features to be encrypted in the YUV image; Performing position scrambling processing on the matrix corresponding to the rectangular encryption area to obtain a scrambled matrix; The scrambled matrix is processed using a random number and a video encryption key to generate a two-dimensional ciphertext matrix, and the random number is SM4 encrypted based on the video encryption key to obtain an encrypted random number; Overlaying the two-dimensional ciphertext matrix onto the rectangular encrypted area of the original image matrix to obtain an occluded image matrix, and encoding an occluded video stream obtained by splicing the occluded YUV images in chronological order to obtain an encoded video stream; Performing symmetrical encryption processing on the video encryption key based on the video key encryption key obtained by decryption to obtain an encrypted video encryption key; Writing the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number, and the rectangular encryption area into the additional attributes of the encoded video stream to obtain an encrypted video stream; The method uses a random number and a video encryption key to process the scrambled matrix to generate a two-dimensional ciphertext matrix, including: generating the random number and the video encryption key; generating a one-dimensional target matrix of the same length as the scrambled matrix through a key splitting function based on the random number and the video encryption key; performing a bitwise AND operation on the scrambled matrix and the one-dimensional target matrix to generate a one-dimensional ciphertext matrix; and converting the one-dimensional ciphertext matrix into the two-dimensional ciphertext matrix.
2. The method according to claim 1, characterized in that Obtaining a rectangular encryption area corresponding to the YUV image according to the identified features to be encrypted in the YUV image includes: Detecting data to be encrypted in the YUV image; Extracting features to be encrypted corresponding to the data to be encrypted from the YUV image; According to the features to be encrypted, a rectangular encryption area corresponding to the YUV image is determined.
3. The method according to claim 1, characterized in that The performing position scrambling processing on the matrix corresponding to the rectangular encryption area to obtain a scrambled matrix includes: generating a two-dimensional random matrix associated with the rectangular encryption area according to the size of the rectangular encryption area; Converting the two-dimensional random matrix into a one-dimensional random matrix; Generate a one-dimensional matrix with the same length as the one-dimensional random matrix; Position scrambling processing is performed on the one-dimensional random matrix and matrix elements in the one-dimensional matrix to obtain the scrambled matrix.
4. The method according to claim 1, wherein The step of performing symmetrical encryption processing on the video encryption key based on the video key encryption key obtained by decryption to obtain an encrypted video encryption key comprises: Obtaining a video key encrypted ciphertext from a key management center, wherein the video key encrypted ciphertext is a ciphertext encrypted based on the SM2 public key; Decrypting the video key encrypted ciphertext based on the SM2 private key corresponding to the SM2 public key to obtain the video key encryption key; The video encryption key is symmetrically encrypted based on the video key encryption key to obtain an encrypted video encryption key.
5. A decryption method, characterized in that: The method comprises: Obtaining an encrypted video stream and additional attributes, and decoding the encrypted video stream to obtain a YUV image; Extracting the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number and the rectangular encryption area from the additional attributes; Determining a video encryption key according to the version number and the encrypted video encryption key; Decrypting the encrypted random number based on the video encryption key to obtain a decrypted random number; Generate a two-dimensional random matrix according to the size of the rectangular encryption area, and convert the two-dimensional random matrix into a one-dimensional random matrix; Determine a two-dimensional restoration matrix based on the random number, the video encryption key, and the one-dimensional random matrix; Overlaying the two-dimensional restoration matrix to a position corresponding to the rectangular encrypted area of the YUV image to obtain a decrypted YUV image; Encoding the decrypted YUV image to obtain a restored video stream; The method of determining a two-dimensional restoration matrix based on the random number, the video encryption key and the one-dimensional random matrix includes: generating a one-dimensional target matrix with the same length as the one-dimensional random matrix through a key splitting function based on the random number and the video encryption key; performing a bitwise OR operation on the one-dimensional random matrix and the one-dimensional target matrix to obtain a one-dimensional ciphertext matrix; converting the one-dimensional ciphertext matrix into a two-dimensional ciphertext matrix; and sorting the matrix element positions of the two-dimensional ciphertext matrix according to the rectangular encryption area to obtain the two-dimensional restoration matrix.
6. The method according to claim 5, characterized in that The determining of the video encryption key according to the version number and the encrypted video encryption key includes: Obtaining, from a key management center, a video key encrypted ciphertext according to the version number, where the video key encrypted ciphertext is a ciphertext encrypted based on the SM2 public key; Decrypting the video key encrypted ciphertext based on the SM2 private key corresponding to the SM2 public key to obtain a video key encryption key; The encrypted video encryption key is symmetrically decrypted based on the video key encryption key to obtain the video encryption key.
7. An encryption device, characterized in that: The device comprises: The original matrix generation module is used to decode the video stream to obtain a YUV image and generate an original image matrix associated with the YUV image; An encryption area acquisition module is used to obtain a rectangular encryption area corresponding to the YUV image according to the identified features to be encrypted in the YUV image; A scrambled matrix acquisition module is used to perform position scrambling processing on the matrix corresponding to the rectangular encryption area to obtain a scrambled matrix; A random number encryption module, configured to process the scrambled matrix using a random number and a video encryption key to generate a two-dimensional ciphertext matrix, and perform SM4 encryption on the random number based on the video encryption key to obtain an encrypted random number; a video stream encoding module, configured to overlay the two-dimensional ciphertext matrix onto the rectangular encrypted area of the original image matrix to obtain an occluded image matrix, and encode an occluded video stream obtained by splicing the occluded YUV images in chronological order to obtain an encoded video stream; An encryption key acquisition module is used to perform symmetrical encryption processing on the video encryption key based on the video key encryption key obtained by decryption to obtain an encrypted video encryption key; an encrypted video stream acquisition module, configured to write the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number, and the rectangular encryption area into the additional attributes of the encoded video stream to obtain an encrypted video stream; The random number encryption module includes: a random number generation unit, used to generate the random number and the video encryption key; a target matrix generation unit, used to generate a one-dimensional target matrix with the same length as the scrambling matrix through a key splitting function based on the random number and the video encryption key; a ciphertext matrix generation unit, used to perform a bitwise AND operation on the scrambling matrix and the one-dimensional target matrix to generate a one-dimensional ciphertext matrix; and a ciphertext matrix conversion unit, used to convert the one-dimensional ciphertext matrix into the two-dimensional ciphertext matrix.
8. A decryption device, characterized in that: The device comprises: The video stream decoding module is used to obtain the encrypted video stream and additional attributes, and decode the encrypted video stream to obtain a YUV image; An additional information extraction module is used to extract the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number and the rectangular encryption area from the additional attributes; an encryption key determination module, configured to determine a video encryption key based on the version number and the encrypted video encryption key; A random number decryption module, configured to decrypt the encrypted random number based on the video encryption key to obtain a decrypted random number; A random matrix generation module, configured to generate a two-dimensional random matrix according to the size of the rectangular encryption area, and convert the two-dimensional random matrix into a one-dimensional random matrix; a restoration matrix determination module, configured to determine a two-dimensional restoration matrix based on the random number, the video encryption key, and the one-dimensional random matrix; A YUV image acquisition module, configured to overlay the two-dimensional restoration matrix onto a position corresponding to the rectangular encryption area of the YUV image to obtain a decrypted YUV image; A video stream acquisition module is used to encode the decrypted YUV image to obtain a restored video stream; The restoration matrix determination module includes: a one-dimensional target matrix generation unit, used to generate a one-dimensional target matrix with the same length as the one-dimensional random matrix through a key splitting function based on the random number and the video encryption key; a one-dimensional ciphertext matrix acquisition unit, used to perform a bitwise OR operation on the one-dimensional random matrix and the one-dimensional target matrix to obtain a one-dimensional ciphertext matrix; a one-dimensional ciphertext matrix conversion unit, used to convert the one-dimensional ciphertext matrix into a two-dimensional ciphertext matrix; and a restoration matrix acquisition unit, used to sort the matrix element positions of the two-dimensional ciphertext matrix according to the rectangular encryption area to obtain the two-dimensional restoration matrix.
9. An electronic device, characterized in that: include: A processor, a memory, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the encryption method according to any one of claims 1 to 4 or the decryption method according to any one of claims 5 to 6 is implemented.
10. A computer-readable storage medium, characterized in that When the instructions in the storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the encryption method according to any one of claims 1 to 4, or the decryption method according to any one of claims 5 to 6.
Citation Information
Patent Citations
Adaptive image encryption domain reversible hiding method based on hybrid encryption mechanism
CN108566500A
Image encryption storage method and device
CN111832035A