Bitstream Encryption Method, Bitstream Decryption Method, Device, Electronic Device and Medium
The central server sends update scrambling information during the key change period, and dynamically updates the encryption and decryption process of the code stream encryption and decryption side, solving the problem of insufficient video transmission security caused by the unchanging key, and achieving higher security and resistance to hijacking.
Patent Information
- Application Number
- CN202110025554.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-01-08
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2041-01-08
AI Technical Summary
In the existing video stream encryption scheme, the key is permanently cracked or hijacked, resulting in insufficient security of video transmission.
The central server sends update scrambling information during the key change period, and the code stream encryption end dynamically updates the ciphertext in the encrypted code stream, and the code stream decrypts the received scrambling information to realize dynamic changes of the scrambling information.
Improves the security of video encryption, reduces the risk of video code streams being cracked or hijacked, and enhances transmission security.
Smart Images

Figure CN114205552B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the technical field of video processing, and in particular, to a method and device for encrypting a bitstream, a method and device for decrypting a bitstream, an electronic device, and a medium. Background Art
[0002] With the increasing popularity of video surveillance, the importance attached to the security of video bitstream transmission is also increasing.
[0003] Currently, in the bitstream encryption transmission solutions supported by each monitoring manufacturer, the bitstream key is generated during the establishment of the service, and the key remains unchanged during the subsequent transmission process. However, from a security perspective, a fixed key is easily cracked or hijacked, and there are security risks in the transmission of video bitstreams. Summary of the Invention
[0004] The embodiments of the present invention provide a method and device for encrypting a bitstream, a method and device for decrypting a bitstream, an electronic device, and a medium to improve the security of encrypted transmission of video bitstreams.
[0005] In a first aspect, an embodiment of the present invention provides a method for encrypting a bitstream, which is executed by a bitstream encryption end, and includes:
[0006] Receiving updated scrambling information sent by a central server during a key change time period;
[0007] If the key change time period has not ended, encrypt the bitstream to be encrypted using the original plaintext, and send the encrypted bitstream carrying the pre-update ciphertext and the updated ciphertext to the bitstream decryption end; wherein, the pre-update ciphertext is obtained by encrypting the original plaintext according to the pre-update scrambling information; the updated ciphertext is obtained by encrypting the original plaintext according to the updated scrambling information;
[0008] If the key change time period has ended, encrypt the bitstream using the original plaintext, and send the encrypted bitstream carrying the updated ciphertext to the bitstream decryption end.
[0009] In a second aspect, an embodiment of the present invention provides a method for decrypting a bitstream, which is executed by a bitstream decryption end, and includes:
[0010] Receiving the encrypted bitstream sent by the bitstream encryption end, determining the number of ciphertexts carried in the encrypted bitstream, and determining the number of scrambling information stored locally; wherein, the scrambling information is sent by the central server;
[0011] Determining the target ciphertext and the target scrambling information according to the number of ciphertexts and the number of scrambling information;
[0012] Using the target scrambling information to decrypt the target ciphertext to obtain the original plaintext, and decrypting the encrypted bitstream based on the original plaintext.
[0013] In a third aspect, an embodiment of the present invention further provides a bitstream encryption device, which is executed by a bitstream encryption end and includes:
[0014] An update information receiving module, configured to receive updated scrambling information sent by a central server within a key change time period;
[0015] A first bitstream encryption module, configured to, if the key change time period has not ended, encrypt the to-be-encrypted bitstream using the original plaintext, and send the encrypted bitstream carrying the pre-update ciphertext and the updated ciphertext to the bitstream decryption end; wherein, the pre-update ciphertext is obtained by encrypting the original plaintext according to pre-update scrambling information; the updated ciphertext is obtained by encrypting the original plaintext according to the updated scrambling information;
[0016] A second bitstream encryption module, configured to, if the key change time period has ended, encrypt the bitstream using the original plaintext, and send the encrypted bitstream carrying the updated ciphertext to the bitstream decryption end.
[0017] In a fourth aspect, an embodiment of the present invention further provides a bitstream decryption device, which is executed by a bitstream decryption end and includes:
[0018] An encrypted bitstream receiving module, configured to receive the encrypted bitstream sent by the bitstream encryption end, determine the number of ciphertexts carried in the encrypted bitstream, and determine the number of scrambling information stored locally; wherein, the scrambling information is sent by the central server;
[0019] A decryption information determining module, configured to determine target ciphertext and target scrambling information according to the number of ciphertexts and the number of scrambling information;
[0020] A bitstream decryption module, configured to decrypt the target ciphertext using the target scrambling information to obtain the original plaintext, and decrypt the encrypted bitstream based on the original plaintext.
[0021] In a fifth aspect, an embodiment of the present invention further provides an electronic device, including:
[0022] One or more processors;
[0023] A storage device, configured to store one or more programs,
[0024] When the one or more programs are executed by the one or more processors, the one or more processors implement the bitstream encryption method or the bitstream decryption method as described in any embodiment of the present invention.
[0025] In a sixth aspect, an embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the code stream encryption method or the code stream decryption method as described in any embodiment of the present invention.
[0026] Based on the updated scrambling information sent by the central server during the key change period, the embodiment of the present invention realizes dynamically updating the ciphertext in the encrypted code stream at the code stream encryption end. The code stream decryption end dynamically determines the scrambling information for decryption according to the received situation of the updated scrambling information sent by the central server and the ciphertext situation in the encrypted code stream sent by the code stream encryption end, and obtains the key of the final encrypted code stream. The embodiment of the present invention improves the security of video encryption by dynamically changing the scrambling information, and reduces the risk of the video code stream being cracked or hijacked. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] Figure 1 is a flowchart of the code stream encryption method in Embodiment 1 of the present invention;
[0028] Figure 2 is a schematic diagram of the negotiation data transmission process for the central server to dynamically change the scrambling information;
[0029] Figure 3 is a flowchart of the code stream decryption method in Embodiment 2 of the present invention;
[0030] Figure 4 is a schematic diagram of the process for the code stream decryption end to decrypt the encrypted code stream;
[0031] Figure 5 is a schematic structural diagram of the code stream encryption device in Embodiment 3 of the present invention;
[0032] Figure 6 is a schematic structural diagram of the code stream decryption device in Embodiment 4 of the present invention;
[0033] Figure 7 is a schematic structural diagram of the electronic device in Embodiment 5 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0034] The present invention will be further described in detail below with reference to the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the present invention, rather than limiting the present invention. In addition, it should be noted that only the parts related to the present invention are shown in the drawings for the convenience of description, rather than all the structures.
[0035] Embodiment 1
[0036] Figure 1It is a flowchart of the bitstream encryption method in Embodiment 1 of the present invention. This embodiment is applicable to the situation of dynamically encrypting transmitted videos. This method can be executed by a bitstream encryption device, which can be implemented in software and / or hardware and can be configured in an electronic device. For example, the electronic device can be a background server or other devices with communication and computing capabilities. As Figure 1 shown, the method specifically includes:
[0037] Step 101, receive the updated scrambling information sent by the central server during the key change time period.
[0038] Among them, the central server refers to the device that manages the bitstream encryption end and the bitstream decryption end. The central server can communicate with the bitstream encryption end and the bitstream decryption end respectively. The key change time period refers to the pre-set time period for dynamically updating the keys in the bitstream encryption end and the bitstream decryption end, which can be set according to a preset time rule. Exemplarily, the central server initiates a scrambling information change every hour and sends the updated scrambling information to the bitstream encryption end and the bitstream decryption end. The bitstream encryption end and the bitstream decryption end need to complete the update of the scrambling information within one minute, and this one minute is the key change time period.
[0039] The scrambling information refers to the data used to encrypt the original plaintext of the bitstream encryption. Specifically, the original plaintext refers to the key for encrypting the bitstream, and the scrambling information refers to the key for encrypting the original plaintext. That is, the original plaintext can be obtained by decrypting the ciphertext with the scrambling information, and then the original plaintext is used to decrypt the encrypted bitstream to obtain the finally playable video data. Encrypting the video data with the original plaintext can improve the security of the video data. Encrypting the original plaintext with the scrambling information can improve the security of the original plaintext. Encrypting the original plaintext with dynamically changing scrambling information can further improve the security of the original plaintext, and thus improve the security of the transmitted video data.
[0040] The video bitstream includes a set of consecutive frames, and each frame corresponds to an image. For the bitstream encryption end, bitstream encryption needs to encrypt each frame of image data. For the bitstream decoding end, it also needs to decrypt each frame of image data. There are two ways to carry the encryption key. One is to carry it in the transmitted bitstream, and the other is to carry it during the negotiation process among the bitstream encryption end, the bitstream decryption end, and the central server. For the encryption method with a fixed key, no matter how the key is transmitted, the bitstream decryption end can perform bitstream decryption after obtaining the key, and then complete the decoding and the process of going on the large screen. In the embodiment of the present invention, the scrambling information is controlled by the central server to change dynamically, so the scrambling information is carried during the negotiation process.
[0041] Specifically, during the negotiation process between the central server and the bitstream encryption end and the bitstream decryption end, the negotiation data carrying the variable scrambling information is respectively sent to the bitstream encryption end and the bitstream decryption end, so as to realize the dynamic change of the scrambling information at both ends. The bitstream encryption end receives the updated scrambling information in the negotiation data. Exemplarily, the central server regularly sends the negotiation data carrying the variable scrambling information to the bitstream encryption end and the bitstream decryption end according to a preset time rule, and the bitstream encryption end and the bitstream decryption end need to complete the update of the scrambling information within the key change time period.
[0042] Step 102: If the key change time period has not ended, then encrypt the plaintext to be encrypted using the original plaintext, and send the encrypted bitstream carrying the pre-update ciphertext and the updated ciphertext to the bitstream decryption end; wherein, the pre-update ciphertext is obtained by encrypting the original plaintext according to the pre-update scrambling information; the updated ciphertext is obtained by encrypting the original plaintext according to the updated scrambling information.
[0043] Since the central server sends variable scrambling information to both ends during the key change time period, but due to interference from external factors such as the network, the time for sending the updated scrambling information to both ends is not synchronized. However, in any case, before the end of the key change time period, the central server will complete the sending to the bitstream encryption end and the bitstream decryption end, that is, both ends receive the updated scrambling information.
[0044] When the key change time period has not ended, the bitstream encryption end cannot timely obtain whether the bitstream decryption end has received the updated scrambling information. Therefore, after the bitstream encryption end receives the updated scrambling information and the current time is within the key change time period, the encrypted bitstream carrying both the pre-update ciphertext and the updated ciphertext is sent to the bitstream decryption end. The pre-update ciphertext is obtained by encrypting the original plaintext by the bitstream encryption end using the pre-update scrambling information according to a preset encryption algorithm, and the updated ciphertext is obtained by encrypting the original plaintext by the bitstream encryption end using the just-received updated scrambling information according to a preset encryption algorithm. Among them, the judgment of whether the key change time period has ended can be determined by a preset time rule, that is, the key change time period is preset according to the preset time rule, so it can be determined whether it is within the key change time period according to the real-time time.
[0045] During the key change time period, the bitstream encryption end encrypts the original plaintext using both the updated scrambling information and the old scrambling information at the same time, and sends the encrypted bitstream carrying the old and new ciphertexts to the bitstream decryption end, so that the bitstream decryption end can decrypt the encrypted bitstream according to the actual situation, ensuring that there will be no decryption exception at the bitstream decryption end during the change of the scrambling information.
[0046] Step 103: If the key change time period has ended, then encrypt the bitstream using the original plaintext, and send the encrypted bitstream carrying the updated ciphertext to the bitstream decryption end.
[0047] At the end of the key change time period, the encrypted end of the bitstream considers that the decrypted end of the bitstream has received the updated scrambling information. Therefore, the encrypted end of the bitstream encrypts the original plaintext according to the preset encryption algorithm based on the received updated scrambling information to obtain the updated ciphertext, and carries the updated ciphertext in the encrypted bitstream encrypted according to the original plaintext, so as to realize the real-time transmission of the dynamic key in the bitstream. If the key change time period ends, it can be considered that the dynamic key change initiated by the central server this time is completed, and the received updated scrambling information is used as the scrambling information before the next update cycle.
[0048] There is a NALU in the video bitstream in H264 format, and its composition includes an F bit, an NRI bit, and a Type bit. In the NALU, the F is the forbidden bit, which is generally 0. The NRI represents the importance level respectively, 11 means very important, and the Type represents the corresponding NAL type. Table 1 shows the NAL types corresponding to each value of the Type.
[0049] In the embodiment of the present invention, the ciphertext is carried by using the Type 6 supplementary enhancement information unit type. The format of the supplementary enhancement information unit (SEI) is shown in Table 2.
[0050] It is preset that when the SEI_SubType is a preset value, it means that the data carried by this type is ciphertext, so as to realize the transmission of the ciphertext carried in the encrypted bitstream.
[0051] Table 1
[0052] nal_unit_type NAL type C 0 Not used 1 Slice of non-partitioned, non-IDR picture 2,3,4 2 Slice partition A 2 3 Slice partition B 3 4 Slice partition C 4 5 Slice in IDR picture 2,3 6 Supplemental enhancement information unit (SEI) 5 7 Sequence parameter set 0 8 Picture parameter set 1 9 Delimiter 6 10 End of sequence 7 11 End of bitstream 8 12 Padding 9 13..23 Reserved
[0053] Table 2
[0054] Start code prefix SEI SEI type SEI length SEISubType SEI payload End code H.264 00 00 00 01 0x06 0x05 xx...xx 0xAB SEIData 0x80
[0055] In a feasible embodiment, the key change time period is determined according to a preset time rule, and the updated scrambling information is dynamically changed and sent by the central server according to the preset time rule;
[0056] Correspondingly, the method further includes:
[0057] Update the scrambling information within the key change time period, and delete the scrambling information before the update at the end of the key change time period.
[0058] The key change time period refers to the pre-set time period for dynamically updating the keys in the stream encryption end and the stream decryption end, which can be set according to the preset time rule. Specifically, the key change time period can be determined according to the device configuration of the central server, the stream encryption end, and the stream decryption end. Exemplarily, the central server initiates a scrambling information change every hour and sends the updated scrambling information to the stream encryption end and the stream decryption end. The stream encryption end and the stream decryption end need to complete the update of the scrambling information within one minute, and this one minute is the key change time period.
[0059] Due to reasons such as equipment or network, the stream encryption end does not receive the updated scrambling information at the beginning of the key change time period. However, since the setting of the key change time period takes into account the specific device configurations of the stream encryption end and the stream decryption end, the stream encryption end will receive the updated scrambling information within the key change time period and complete the update of the scrambling information before the end of the key change time period. Before the end of the key change time period, both the old scrambling information before the update and the new scrambling information after the update will exist in the stream encryption end. Therefore, at the end of the key change time period, the old scrambling information before the update is deleted, and at this time, only the updated scrambling information exists in the stream encryption end, thus completing an update of the scrambling information. Until the next key change time period when new updated scrambling information is received, a new round of scrambling information update is started.
[0060] Such as Figure 2 It is a schematic diagram of the negotiation data transmission process for the central server to dynamically change the scrambling information. Before transmitting the video stream, the central server needs to establish a connection with the encoding device at the stream encryption end and the decoding device at the stream decryption end by sending negotiation data. Taking the sending of SIP messages as an example, when the central server starts to establish a stream, it sends messages to the encoding device and the decoding device respectively based on the Invite call mechanism. After receiving the messages, the encoding device and the decoding device return messages to the central server to indicate that the connection is successfully established. Exemplarily, a message of "200OK" is replied to the central server. After the central server successfully establishes a connection with the encoding device and the decoding device, it carries the scrambling data in the ACK message in the Invite call mechanism and sends it to the encoding device and the decoding device respectively. After receiving the scrambling data, the encoding device encrypts and transmits the video stream to be transmitted, and the decoding device decrypts and plays the encrypted stream received after receiving the scrambling data.
[0061] The central server periodically changes the scrambled data and sends a message about the dynamic change of the scrambled data to the decoding device and the encoding device through the Message message. After receiving the changed scrambled data, the decoding device and the encoding device return a message to indicate successful reception. Exemplarily, a message of "200 OK" is replied to the central server. Exemplarily, the scrambled data can be randomly generated by the central server to ensure the security of the code stream encryption.
[0062] Based on the updated scrambling information sent by the central server to the code stream encryption end during the key change period, the embodiments of the present invention dynamically update the ciphertext carried in the encrypted code stream at the code stream encryption end to achieve dynamic encryption of the original plaintext of the code stream encryption. The embodiments of the present invention improve the security of video encryption by dynamically changing the scrambling information and reduce the risk of the video code stream being cracked or hijacked.
[0063] Embodiment 2
[0064] Figure 3 is a flowchart of the code stream decryption method in Embodiment 2 of the present invention. This embodiment is applicable to the situation of decrypting a dynamically encrypted transmitted video. This method can be executed by a code stream decryption device, which can be implemented in a software and / or hardware manner and can be configured in an electronic device. For example, the electronic device can be a background server or other devices with communication and computing capabilities. As Figure 3 shown, the method specifically includes:
[0065] Step 301, receive the encrypted code stream sent by the code stream encryption end, determine the number of ciphertexts carried in the encrypted code stream, and determine the number of scrambling information stored locally; wherein, the scrambling information is sent by the central server.
[0066] In order to ensure that there is no decryption anomaly at the code stream decryption end during the key change period, after receiving the updated scrambling information, the code stream encryption end will carry two ciphertexts in the encrypted code stream during the key change period, namely the pre-update ciphertext and the updated ciphertext. Therefore, when the code stream decryption end receives the encrypted code stream sent by the code stream encryption end, it is necessary to determine the number of ciphertexts carried in the encrypted code stream, that is, to determine whether the updated ciphertext is carried in the encrypted code stream. And since the central server also sends the updated scrambling value to the code stream decryption end when sending the updated scrambling value to the code stream encryption end, and the sending timing may not be exactly the same, the code stream decryption end needs to determine the number of scrambling information stored locally when decrypting the encrypted code stream, that is, to determine whether the updated scrambling value is received.
[0067] Step 302, determine the target ciphertext and the target scrambling information according to the number of ciphertexts and the number of scrambling information.
[0068] Since the updated ciphertext in the encrypted code stream is encrypted based on the updated scrambling information, and the ciphertext before the update is encrypted based on the scrambling information before the update, at the code stream decryption end, decryption needs to be performed according to the actual ciphertext carried in the code stream and the actual situation of whether the updated scrambling information is received locally, so as to obtain the target ciphertext and target scrambling information for final decryption. Specifically, the code stream decryption end determines whether the code stream encryption end has received the updated scrambling information according to the number of ciphertexts, and at the same time determines whether it has received the updated scrambling information according to the number of its own scrambling information, and determines the target ciphertext and target scrambling information according to the result of whether both ends have received the updated scrambling information, so that the target ciphertext and target scrambling information are matched, and the target ciphertext can be decrypted using the target scrambling information to obtain the original plaintext.
[0069] In a feasible embodiment, step 302 includes:
[0070] If the number of ciphertexts is one and the number of scrambling information is two, it is determined that the ciphertext carried in the encrypted code stream is the target ciphertext, and the scrambling information before the update stored locally is determined as the target scrambling information.
[0071] If the number of ciphertexts is one, it means that the code stream encryption end has not received the updated scrambling information sent by the central server. The code stream encryption end still generates the ciphertext before the update according to the scrambling information before the update, and sends the encrypted code stream carrying the ciphertext before the update to the code stream decryption end. If the number of scrambling information is two, it means that the code stream decryption end has received the updated scrambling information sent by the central server, and at this time it is within the key change time period, so the scrambling information before the update has not been deleted, so there are two pieces of scrambling information at the code stream decryption end.
[0072] When the code stream encryption end has not received the updated scrambling information and the code stream decryption end has received the updated scrambling information, for the code stream decryption end, it still needs to decrypt the ciphertext before the update in the received encrypted code stream according to the scrambling information before the update. Therefore, it is determined that the ciphertext before the update carried in the encrypted code stream is the target ciphertext, and the scrambling information before the update in the code stream decryption end is determined as the target scrambling information, so as to complete the decryption of the target ciphertext by the target scrambling information.
[0073] In a feasible embodiment, step 302 includes:
[0074] If the number of ciphertexts is two and the number of scrambling information is one, it is determined that the ciphertext before the update carried in the encrypted code stream is the target ciphertext, and the scrambling information stored locally is determined as the target scrambling information.
[0075] If the number of ciphertexts is two, it means that the stream encryption end has received the updated scrambling information sent by the central server. During the key change period, the stream encryption end generates the pre-update ciphertext according to the pre-update scrambling information, and at the same time generates the updated ciphertext according to the updated scrambling information, and sends the encrypted ciphertext stream carrying both the pre-update ciphertext and the updated ciphertext to the stream decryption end. If the number of scrambling information is one, it means that the stream decryption end has not received the updated scrambling information sent by the central server. Therefore, there is only one scrambling information in the stream decryption end, that is, the pre-update scrambling information.
[0076] When the stream encryption end has received the updated scrambling information and the stream decryption end has not received the updated scrambling information, if the stream decryption end is to decrypt the encrypted ciphertext stream, it is necessary to use the pre-update scrambling information to decrypt the pre-update ciphertext in the encrypted ciphertext stream. Therefore, it is determined that the pre-update ciphertext carried in the encrypted ciphertext stream is the target ciphertext, and the only scrambling information in the stream decryption end, that is, the pre-update scrambling information, is the target scrambling information, so as to complete the decryption of the target ciphertext by the target scrambling information. Specifically, in the encrypted ciphertext stream, the pre-update ciphertext and the updated ciphertext are stored according to a preset position. For example, the storage position of the updated ciphertext is in front of the pre-update ciphertext. Therefore, the stream decryption end can determine the pre-update ciphertext by judging the storage position.
[0077] In a feasible embodiment, step 302 includes:
[0078] If the number of ciphertexts is two and the number of scrambling information is two, then it is determined that the updated ciphertext carried in the encrypted ciphertext stream is the target ciphertext, and the locally stored updated scrambling information is the target scrambling information.
[0079] If the number of ciphertexts is two, it means that the stream encryption end has received the updated scrambling information sent by the central server. The stream encryption end generates the pre-update ciphertext according to the pre-update scrambling information, and at the same time generates the updated ciphertext according to the updated scrambling information, and sends the encrypted ciphertext stream carrying both the pre-update ciphertext and the updated ciphertext to the stream decryption end. If the number of scrambling information is two, it means that the stream decryption end has received the updated scrambling information sent by the central server, and at this time it is in the key change period. Therefore, the pre-update scrambling information has not been deleted, so there are two scrambling informations in the stream decryption end.
[0080] When the stream encryption end has received the updated scrambling information and the stream decryption end has also received the updated scrambling information, if the stream decryption end is to decrypt the encrypted ciphertext stream, the updated scrambling information is used to decrypt the updated ciphertext in the encrypted ciphertext stream. Therefore, it is determined that the updated ciphertext carried in the encrypted ciphertext stream is the target ciphertext, and the updated scrambling information in the stream decryption end is the target scrambling information, so as to complete the decryption of the target ciphertext by the target scrambling information.
[0081] If the number of ciphertexts is one and the number of scrambling information is one, it means that the update of the scrambling information has been completed. Delete the pre-update scrambling information at both ends and only retain the updated scrambling information. Or it means that the first key change time period has not been reached. Therefore, before reaching the next key change time period, use this scrambling information for encrypted transmission at the encrypted end of the bitstream, and use this scrambling information for decryption at the decrypted end of the bitstream.
[0082] Optionally, use a status flag at the decrypted end of the bitstream to mark the update status of the scrambling information. Specifically, if the number of ciphertexts is two and the number of scrambling information is one, or the number of ciphertexts is one and the number of scrambling information is two, or the number of ciphertexts is one and the number of scrambling information is one, it means that the current scrambling information has not been updated or is not in the update state. Then set the status flag to the unupdated state. Exemplarily, IsScrambleChanged represents the status flag. When IsScrambleChanged = 0, it means the unupdated state. If the number of ciphertexts is two and the number of scrambling information is two, then set the status flag to the updated state. Exemplarily, when IsScrambleChanged = 1, it means the updated state. When in the updated state, the decrypted end of the bitstream releases the pre-update scrambling information, retains the updated scrambling information as the scrambling information for subsequent use, and notifies the encrypted end of the bitstream to release the pre-update scrambling information through the central server to complete the update of this scrambling information.
[0083] As Figure 4 shown is the schematic flowchart of the decryption of the encrypted bitstream at the decrypted end of the bitstream. ScrambleKey represents the scrambling information, ScrambleKey_Old represents the pre-update scrambling information, and ScrambleKey_New represents the updated scrambling information; RandomKey represents the ciphertext, RandomKey_Old represents the pre-update ciphertext obtained by encrypting the original plaintext according to ScrambleKey_Old, and RandomKey_New represents the updated ciphertext obtained by encrypting the original plaintext according to ScrambleKey_New.
[0084] If the encrypted bitstream sent by the bitstream encryption end carries only one RandomKey, it means that the bitstream encryption end has not received the updated scrambling information. Then, for the bitstream decryption end, i.e., the decryption module, it needs to decrypt according to the situation of its own scrambling information. If the ScrambleKey in the decryption module has not changed, it means that there is only one scrambling information in the decryption module and the updated scrambling information has not been received. Then, use the current ScrambleKey to decrypt the RandomKey in the bitstream, and the status flag IsScrambleChanged = 0. If the ScrambleKey in the decryption module has changed, it means that there are two scrambling information in the decryption module and the updated scrambling information ScrambleKey_New has been received. Set the previous ScrambleKey to ScrambleKey_Old. In order to pair with the RandomKey in the encrypted bitstream, still use ScrambleKey_Old to decrypt the RandomKey in the bitstream, and the status flag IsScrambleChanged = 0.
[0085] If the encrypted bitstream sent by the bitstream encryption end carries two ciphertexts, i.e., RandomKey_Old and RandomKey_New, it means that the bitstream encryption end has received the updated scrambling information. Then, for the bitstream decryption end, i.e., the decryption module, it needs to decrypt according to the situation of its own scrambling information. If the ScrambleKey in the decryption module has not changed, it means that there is only one scrambling information in the decryption module and the updated scrambling information has not been received. Then, use the current ScrambleKey to decrypt the RandomKey_Old in the bitstream, and the status flag IsScrambleChanged = 0. If the ScrambleKey in the decryption module has changed, it means that there are two scrambling information in the decryption module and the updated scrambling information ScrambleKey_New has been received. Set the previous ScrambleKey to ScrambleKey_Old. Then, use ScrambleKey_New to decrypt the RandomKey_New in the bitstream, and the status flag IsScrambleChanged = 1. At the same time, release ScrambleKey_Old and set ScrambleKey_New to ScrambleKey until the next updated scrambling information is received. Specifically, when the status flag changes, inform the bitstream encryption end to release ScrambleKey_Old at the same time, that is, only one RandomKey is carried in the subsequent encrypted bitstream.
[0086] In a feasible embodiment, the method further includes:
[0087] Complete the update of the scrambled information within the key change time period, and delete the pre-update scrambled information stored locally at the end of the key change time period;
[0088] Among them, the updated scrambled information is dynamically changed and sent by the central server according to a preset time rule, and the key change time period is determined according to a preset time rule.
[0089] To avoid the problem that the release of the pre-update scrambled information at one end is caused by the message transmission delay at both ends, and the other end has not completed the release, resulting in decryption failure, at the end of the agreed key change time period, both ends release the pre-update scrambled information simultaneously and retain the updated scrambled information, that is, both ends need to complete the update of the scrambled information within the key change time period.
[0090] The key change time period refers to the time period for dynamically updating the keys in the encrypted end of the code stream and the decrypted end of the code stream, which can be set according to a preset time rule. Specifically, the key change time period can be determined according to the device configuration of the central server, the encrypted end of the code stream, and the decrypted end of the code stream. Exemplarily, the central server initiates a change in the scrambled information every hour and sends the updated scrambled information to the encrypted end of the code stream and the decrypted end of the code stream. The encrypted end of the code stream and the decrypted end of the code stream need to complete the update of the scrambled information within one minute, and this one minute is the key change time period. There is no specific limit on the period for the central server to dynamically change the scrambled information.
[0091] Through the embodiments of the present invention, the decoupling of the change order of the scrambled information and the ciphertext is realized, and the flexibility of the dynamic change of the scrambled information is improved, that is, the order of the central server sending the updated scrambled information to the encrypted end of the code stream and the decrypted end of the code stream is not restricted.
[0092] Step 303: Use the target scrambled information to decrypt the target ciphertext to obtain the original plaintext, and decrypt the encrypted code stream based on the original plaintext.
[0093] Since the target scrambling information and the target ciphertext are paired, the target ciphertext can be decrypted according to the target scrambling information to obtain the original plaintext. Exemplarily, the updated ciphertext is obtained by encrypting the original plaintext according to the updated scrambling information. Therefore, when the updated ciphertext is the target ciphertext, the paired target scrambling information is the updated scrambling information. Similarly, when the ciphertext before update is the target ciphertext, the paired target scrambling information is the scrambling information before update. Therefore, the original plaintext is obtained by decrypting the target ciphertext using the target scrambling information based on the agreed decryption algorithm. And since the video stream in the encrypted bitstream is encrypted based on the original plaintext, the video stream can be obtained by decrypting the encrypted bitstream based on the original plaintext and the agreed decryption algorithm, and the playback of the video stream can be realized. In the embodiments of the present invention, there are no restrictions on the encryption algorithm and the decryption algorithm, and an agreement can be reached at the encrypted end and the decrypted end of the bitstream by presetting.
[0094] In the embodiments of the present invention, based on the updated scrambling information sent by the central server to the decrypted end of the bitstream during the key change period, the decrypted end of the bitstream dynamically determines the scrambling information for decryption according to the received updated scrambling information sent by the central server and the ciphertext in the encrypted bitstream sent by the encrypted end of the bitstream, and obtains the original plaintext key of the final encrypted bitstream. The embodiments of the present invention improve the security of video encryption by dynamically changing the scrambling information, and reduce the risk of the video stream being cracked or hijacked.
[0095] Embodiment III
[0096] Figure 5 is a schematic structural diagram of the bitstream encryption device in Embodiment III of the present invention, which is executed by the encrypted end of the bitstream. This embodiment is applicable to the case of dynamically encrypting the transmitted video. As Figure 5 shown, the device includes:
[0097] An update information receiving module 510, configured to receive the updated scrambling information sent by the central server during the key change period;
[0098] A first bitstream encryption module 520, configured to encrypt the to-be-encrypted bitstream using the original plaintext if the key change period has not ended, and send the encrypted bitstream carrying the ciphertext before update and the updated ciphertext to the decrypted end of the bitstream; wherein, the ciphertext before update is obtained by encrypting the original plaintext according to the scrambling information before update; the updated ciphertext is obtained by encrypting the original plaintext according to the updated scrambling information;
[0099] A second bitstream encryption module 530, configured to encrypt the bitstream using the original plaintext if the key change period has ended, and send the encrypted bitstream carrying the updated ciphertext to the decrypted end of the bitstream.
[0100] Based on the updated scrambling information sent by the central server to the stream encryption end during the key change period, the embodiments of the present invention dynamically update the ciphertext carried in the encrypted stream at the stream encryption end to achieve dynamic encryption of the original plaintext of the stream encryption. The embodiments of the present invention improve the security of video encryption by dynamically changing the scrambling information and reduce the risk of the video stream being cracked or hijacked.
[0101] Optionally, the key change period is determined according to a preset time rule, and the updated scrambling information is dynamically changed and sent by the central server according to the preset time rule;
[0102] Correspondingly, the device further includes a scrambling information update module for:
[0103] Update the scrambling information within the key change period and delete the scrambling information before the update at the end of the key change period. The stream encryption device provided by the embodiments of the present invention can execute the stream encryption method provided by any embodiment of the present invention, and has corresponding functional modules and beneficial effects for executing the stream encryption method.
[0104] Embodiment IV
[0105] Figure 6 FIG. 16 is a schematic structural diagram of a stream decryption device in Embodiment IV of the present invention, which is executed by a stream decryption end. This embodiment is applicable to the situation of decrypting a dynamically encrypted transmitted video. As Figure 6 shown, the device includes:
[0106] A ciphertext stream receiving module 610 for receiving the ciphertext stream sent by the stream encryption end, determining the number of ciphertexts carried in the ciphertext stream, and determining the number of scrambling information stored locally; wherein, the scrambling information is sent by the central server;
[0107] A decryption information determination module 620 for determining target ciphertext and target scrambling information according to the number of ciphertexts and the number of scrambling information;
[0108] A stream decryption module 630 for decrypting the target ciphertext using the target scrambling information to obtain the original plaintext and decrypting the ciphertext stream based on the original plaintext.
[0109] Based on the updated scrambling information sent by the central server to the stream decryption end during the key change period, the stream decryption end dynamically determines the scrambling information for decryption according to the received updated scrambling information from the central server and the ciphertext situation in the ciphertext stream sent by the stream encryption end, and obtains the original plaintext key of the final ciphertext stream. The embodiments of the present invention improve the security of video encryption by dynamically changing the scrambling information and reduce the risk of the video stream being cracked or hijacked.
[0110] Optionally, the decryption information determination module includes a first determination unit, specifically configured to:
[0111] If the number of ciphertexts is one and the number of scrambling information is two, determine the ciphertext carried in the encrypted cipher stream as the target ciphertext, and determine the pre-update scrambling information stored locally as the target scrambling information.
[0112] Optionally, the decryption information determination module includes a second determination unit, specifically configured to:
[0113] If the number of ciphertexts is two and the number of scrambling information is one, determine the pre-update ciphertext carried in the encrypted cipher stream as the target ciphertext, and determine the scrambling information stored locally as the target scrambling information.
[0114] Optionally, the decryption information determination module includes a third determination unit, specifically configured to:
[0115] If the number of ciphertexts is two and the number of scrambling information is two, determine the updated ciphertext carried in the encrypted cipher stream as the target ciphertext, and determine the updated scrambling information stored locally as the target scrambling information.
[0116] Optionally, the device further includes a scrambling information update module, configured to:
[0117] Complete the update of the scrambling information during the key change time period, and delete the pre-update scrambling information stored locally at the end of the key change time period;
[0118] Wherein, the updated scrambling information is dynamically changed and sent by the central server according to a preset time rule, and the key change time period is determined according to a preset time rule.
[0119] The code stream decryption device provided by the embodiments of the present invention can execute the code stream decryption method provided by any embodiment of the present invention, and has corresponding functional modules and beneficial effects for executing the code stream decryption method.
[0120] Embodiment 5
[0121] Figure 7 It is a schematic structural diagram of an electronic device provided by Embodiment 5 of the present invention. Figure 7 It shows a block diagram of an exemplary electronic device 12 suitable for implementing the embodiments of the present invention. Figure 7 The displayed electronic device 12 is only an example and should not bring any limitation to the functions and usage scope of the embodiments of the present invention.
[0122] As Figure 7As shown, the electronic device 12 is presented in the form of a general-purpose computing device. The components of the electronic device 12 may include, but are not limited to: one or more processors or processing units 16, a system storage device 28, and a bus 18 that connects different system components (including the system storage device 28 and the processing unit 16).
[0123] The bus 18 represents one or more of several types of bus architectures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processor, or a local bus using any of a variety of bus architectures. By way of example, these architectures include, but are not limited to, Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MAC) bus, Enhanced ISA bus, Video Electronics Standards Association (VESA) local bus, and Peripheral Component Interconnect (PCI) bus.
[0124] The electronic device 12 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by the electronic device 12, including volatile and nonvolatile media, removable and non-removable media.
[0125] The system storage device 28 may include computer system readable media in the form of volatile storage devices, such as random access memory (RAM) 30 and / or a cache storage device 32. The electronic device 12 may further include other removable / non-removable, volatile / nonvolatile computer system storage media. By way of example only, a storage system 34 may be used for reading and writing on non-removable, nonvolatile magnetic media ( Figure 7 not shown, typically referred to as a "hard disk drive"). Although Figure 7 not shown in the figure, a disk drive for reading and writing on a removable nonvolatile disk (such as a "floppy disk"), and an optical disk drive for reading and writing on a removable nonvolatile optical disk (such as a CD-ROM, DVD-ROM, or other optical media) may be provided. In these cases, each drive may be connected to the bus 18 through one or more data media interfaces. The storage device 28 may include at least one program product having a set (e.g., at least one) of program modules that are configured to perform the functions of the embodiments of the present invention.
[0126] A program / utility 40 having a set (at least one) of program modules 42 may be stored, for example, in the storage device 28. Such program modules 42 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. The program modules 42 generally perform the functions and / or methods in the embodiments described in the present invention.
[0127] The electronic device 12 can also communicate with one or more external devices 14 (such as a keyboard, a pointing device, a display 24, etc.), and can also communicate with one or more devices that enable a user to interact with the device 12, and / or communicate with any device that enables the device 12 to communicate with one or more other computing devices (such as a network card, a modem, etc.). Such communication can be carried out through the input / output (I / O) interface 22. Moreover, the electronic device 12 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 20. As Figure 7 shown, the network adapter 20 communicates with other modules of the electronic device 12 through the bus 18. It should be understood that although Figure 7 not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device 12, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.
[0128] The processing unit 16 executes various functional applications and data processing by running programs stored in the system storage device 28, for example, implementing the code stream encryption method provided by the embodiments of the present invention, including:
[0129] Receiving the updated scrambling information sent by the central server during the key change time period;
[0130] If the key change time period has not ended, then use the original plaintext to encrypt the code stream to be encrypted, and send the encrypted code stream carrying the pre-update ciphertext and the updated ciphertext to the code stream decryption end; wherein, the pre-update ciphertext is obtained by encrypting the original plaintext according to the pre-update scrambling information; the updated ciphertext is obtained by encrypting the original plaintext according to the updated scrambling information;
[0131] If the key change time period has ended, then use the original plaintext to encrypt the code stream, and send the encrypted code stream carrying the updated ciphertext to the code stream decryption end.
[0132] Or implement the code stream decryption method provided by the embodiments of the present invention, including:
[0133] Receiving the encrypted code stream sent by the code stream encryption end, determining the number of ciphertexts carried in the encrypted code stream, and determining the number of scrambling information stored locally; wherein, the scrambling information is sent by the central server;
[0134] Determining the target ciphertext and the target scrambling information according to the number of ciphertexts and the number of scrambling information;
[0135] Using the target scrambling information to decrypt the target ciphertext to obtain the original plaintext, and decrypting the encrypted code stream based on the original plaintext.
[0136] Example 6
[0137] Example 6 of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the bitstream encryption method provided by the embodiments of the present invention, including:
[0138] Receiving the updated scrambling information sent by the central server during the key change period;
[0139] If the key change period has not ended, encrypt the bitstream to be encrypted using the original plaintext, and send the encrypted bitstream carrying the pre-update ciphertext and the updated ciphertext to the bitstream decryption end; wherein, the pre-update ciphertext is obtained by encrypting the original plaintext according to the pre-update scrambling information; the updated ciphertext is obtained by encrypting the original plaintext according to the updated scrambling information;
[0140] If the key change period has ended, encrypt the bitstream using the original plaintext, and send the encrypted bitstream carrying the updated ciphertext to the bitstream decryption end.
[0141] Or implement the bitstream decryption method provided by the embodiments of the present invention, including:
[0142] Receiving the encrypted bitstream sent by the bitstream encryption end, determining the number of ciphertexts carried in the encrypted bitstream, and determining the number of scrambling information stored locally; wherein, the scrambling information is sent by the central server;
[0143] Determining the target ciphertext and the target scrambling information according to the number of ciphertexts and the number of scrambling information;
[0144] Using the target scrambling information to decrypt the target ciphertext to obtain the original plaintext, and decrypting the encrypted bitstream based on the original plaintext. The computer storage medium of the embodiments of the present invention can adopt any combination of one or more computer-readable media. The computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the computer-readable storage medium include: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used or combined with an instruction execution system, apparatus, or device.
[0145] A computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take many forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. The computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device.
[0146] The program code contained on a computer-readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0147] The computer program code for performing the operations of the present invention may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0148] Note that the above is only the preferred embodiment of the present invention and the technical principles applied. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein. Various obvious changes, re-adjustments, and substitutions can be made by those skilled in the art without departing from the protection scope of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments. Without departing from the concept of the present invention, more other equivalent embodiments may be included, and the scope of the present invention is determined by the scope of the appended claims.
Claims
1. A bitstream encryption method, characterized in that, Executed by the stream encryption end, including: Receiving the updated scrambling information sent by the central server during the key change time period; wherein, the key change time period refers to the time period preset for the central server to dynamically update the keys in the stream encryption end and the stream decryption end; completing the update of the scrambling information during the key change time period, and deleting the pre-update scrambling information at the end of the key change time period; If the key change time period has not ended, encrypt the plaintext to be encrypted using the original plaintext, and send the encrypted stream carrying the pre-update ciphertext and the updated ciphertext to the stream decryption end; wherein, the pre-update ciphertext is obtained by encrypting the original plaintext according to the pre-update scrambling information; the updated ciphertext is obtained by encrypting the original plaintext according to the updated scrambling information; If the key change time period has ended, encrypt the stream using the original plaintext, and send the encrypted stream carrying the updated ciphertext to the stream decryption end.
2. The method according to claim 1, characterized in that, The key change time period is determined according to a preset time rule, and the updated scrambling information is dynamically changed and sent by the central server according to a preset time rule.
3. A bitstream decryption method, characterized in that, Executed by the stream decryption end, including: Receiving the encrypted stream sent by the stream encryption end, determining the number of ciphertexts carried in the encrypted stream, and determining the number of scrambling information stored locally; wherein, the scrambling information is sent by the central server; completing the update of the scrambling information during the key change time period, and deleting the pre-update scrambling information stored locally at the end of the key change time period; the key change time period refers to the time period preset for the central server to dynamically update the keys in the stream encryption end and the stream decryption end; Determining the target ciphertext and the target scrambling information according to the number of ciphertexts and the number of scrambling information; Decrypting the target ciphertext using the target scrambling information to obtain the original plaintext, and decrypting the encrypted stream based on the original plaintext.
4. The method according to claim 3, characterized in that Determining the target ciphertext and the target scrambling information according to the number of ciphertexts and the number of scrambling information, including: If the number of ciphertexts is one and the number of scrambling information is two, determining the ciphertext carried in the encrypted stream as the target ciphertext, and determining the pre-update scrambling information stored locally as the target scrambling information.
5. The method according to claim 3, wherein Determining the target ciphertext and the target scrambling information according to the number of ciphertexts and the number of scrambling information, including: If the number of ciphertexts is two and the number of scrambling information is one, determining the pre-update ciphertext carried in the encrypted stream as the target ciphertext, and determining the scrambling information stored locally as the target scrambling information.
6. The method according to claim 3, wherein Determining the target ciphertext and the target scrambling information according to the number of ciphertexts and the number of scrambling information, including: If the number of ciphertexts is two and the number of scrambling information is two, determining the updated ciphertext carried in the encrypted stream as the target ciphertext, and determining the updated scrambling information stored locally as the target scrambling information.
7. The method according to claim 3, characterized in that, The updated scrambling information is dynamically changed and sent by the central server according to a preset time rule, and the key change time period is determined according to a preset time rule.
8. A bitstream encryption device, characterized in that, Executed by the stream encryption end, including: An update information receiving module, configured to receive the updated scrambling information sent by the central server during the key change time period; wherein, the key change time period refers to a pre-set time period during which the central server dynamically updates the keys in the code stream encryption end and the code stream decryption end; update the scrambling information during the key change time period, and delete the pre-update scrambling information at the end of the key change time period; A first code stream encryption module, configured to, if the key change time period has not ended, encrypt the to-be-encrypted code stream using the original plaintext, and send the encrypted code stream carrying the pre-update ciphertext and the updated ciphertext to the code stream decryption end; wherein, the pre-update ciphertext is obtained by encrypting the original plaintext according to the pre-update scrambling information; the updated ciphertext is obtained by encrypting the original plaintext according to the updated scrambling information; A second code stream encryption module, configured to, if the key change time period has ended, encrypt the code stream using the original plaintext, and send the encrypted code stream carrying the updated ciphertext to the code stream decryption end.
9. A bitstream decryption device, characterized in that, Performed by the code stream decryption end, including: An encrypted code stream receiving module, configured to receive the encrypted code stream sent by the code stream encryption end, determine the number of ciphertexts carried in the encrypted code stream, and determine the number of locally stored scrambling information; wherein, the scrambling information is sent by the central server; update the scrambling information during the key change time period, and delete the locally stored pre-update scrambling information at the end of the key change time period; the key change time period refers to a pre-set time period during which the central server dynamically updates the keys in the code stream encryption end and the code stream decryption end; A decryption information determination module, configured to determine the target ciphertext and the target scrambling information according to the number of ciphertexts and the number of scrambling information; A code stream decryption module, configured to decrypt the target ciphertext using the target scrambling information to obtain the original plaintext, and decrypt the encrypted code stream based on the original plaintext.
10. An electronic device, characterized in that, Including: One or more processors; A storage device, configured to store one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the code stream encryption method according to any one of claims 1-2 or the code stream decryption method according to any one of claims 3-7.
11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the code stream encryption method according to any one of claims 1-2 or the code stream decryption method according to any one of claims 3-7.
Citation Information
Patent Citations
Video code stream processing method, device and equipment and storage medium
CN111277802A