Image distribution using synthetic re-encrypted images
By using encrypted domain image segmentation and proxy re-encryption technology in the privacy management server, the problem of privacy infringement in the monitoring system is solved, enabling user-specific image reconstruction and privacy-protected data distribution, thereby improving user acceptance.
Patent Information
- Application Number
- CN202180043602.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-07-05
- Filing Date
- 2021-07-06
- Publication Date
- 2026-02-10
- Estimated Expiration
- 2041-07-06
AI Technical Summary
Existing surveillance systems suffer from privacy violations during data processing and fail to effectively protect user privacy, especially in video surveillance in public places, leading to a decline in public acceptance of large-scale surveillance.
The privacy management server uses encrypted domain image segmentation and proxy re-encryption technology to segment the source image into encrypted private masks and public masks, generate encrypted private images and public images, and generate re-encrypted images through a key-changing program. Finally, the images are combined into a synthetic private image and distributed to the client device to ensure that the user's specific plaintext version is reconstructed.
This system enables the protection of user privacy in a multi-user environment while allowing client devices to reconstruct user-specific plaintext image versions, thereby increasing user acceptance of the monitoring system and ensuring effective data distribution while protecting privacy.
Smart Images

Figure CN115868140B_ABST
Abstract
Description
[0001] Related Applications
[0002] This application claims the benefit of the filing date of U.S. Provisional Patent Application No. 62 / 705,604, filed July 7, 2020, entitled “Privacy-Preserving Surveillance Systems and Methods,” the entire contents of which are incorporated herein by reference. BACKGROUND
[0003] The present invention relates to image processing, and in particular, to distributing images to multiple users in a manner that employs cryptographic manipulation to protect the privacy of selected users.
[0004] Recent advances in imaging technology and artificial intelligence have led to an explosion in digital surveillance. Video surveillance of public spaces is often used by police to prevent crime. Surveillance cameras are also increasingly used on private residences, stores, offices, and schools. Data collected by the cameras is often further processed to extract various features, such as license plates or the identity of a person appearing in a particular image.
[0005] In recent years, there has also been a decline in public acceptance of mass surveillance, with increasing numbers viewing it as an invasion of privacy.
[0006] Accordingly, there is important practical value in developing privacy-preserving video surveillance systems and methods. SUMMARY
[0007] According to one aspect, a method of distributing a privacy-protected image to a plurality of users includes employing at least one hardware processor of a privacy management server to perform encrypted domain image segmentation of an encrypted source image in response to receiving the source image decrypted with an available management key to determine a plurality of encrypted private masks. Each mask of the plurality of encrypted private masks indicates a region of the source image selected to reveal a private item of a respective user of the plurality of users. The method further includes employing at least one hardware processor of the privacy management server to transmit the plurality of encrypted private masks to an image distribution server for decryption and, in response, determining a plurality of encrypted private images. Each private image of the plurality of encrypted private images is determined from the source image and further from a respective decrypted mask comprising a respective mask of the plurality of encrypted private masks, the respective decrypted mask received from the image distribution server. The method further includes employing at least one hardware processor of the privacy management server to perform an encrypted domain key change procedure to produce a plurality of re-encrypted images. Each re-encrypted image of the plurality of re-encrypted images comprises a transformation of a respective private image of the plurality of encrypted private images from being decryptable with the management key to being decryptable with a private key of the respective user. The method further includes employing at least one hardware processor of the privacy management server to combine the plurality of re-encrypted images into a composite private image and to transmit the composite private image to the image distribution server for further distribution to a plurality of client devices. Each client device is configured to reconstruct a user-specific plaintext version of the source image from the composite private image.
[0008] According to another aspect, a computer system includes a privacy management server configured to perform encrypted domain image segmentation of the source image in response to receiving an encrypted source image decryptable with a management key to determine a plurality of encrypted private masks. Each of the plurality of encrypted private masks indicates a region of the source image selected to display a private item of a corresponding user among a plurality of users. The privacy management server is further configured to transmit the plurality of encrypted private masks to an image distribution server for decryption and, in response, to determine a plurality of encrypted private images. Each of the plurality of encrypted private images is determined based on the source image and further based on a corresponding decryption mask including the decryption of the corresponding mask among the plurality of encrypted private masks, the corresponding decryption mask being received from the image distribution server. The privacy management server is further configured to perform an encrypted domain key changing procedure to generate a plurality of re-encrypted images. Each of the plurality of re-encrypted images includes a result of transforming a corresponding private image among the plurality of encrypted private images from being decryptable with the management key to being decryptable with the private key of the corresponding user. The privacy management server is further configured to combine the plurality of reencrypted images into a composite private image and transmit the composite private image to the image distribution server for further distribution to multiple client devices. Each client device is configured to reconstruct a user-specific plaintext version of the source image based on the composite private image.
[0009] According to another aspect, a non-transitory computer-readable media storage instruction, when executed by at least one hardware processor of a privacy management server, causes the privacy management server to perform encrypted domain image segmentation of the source image in response to receiving an encrypted source image decryptable with a management key to determine a plurality of encrypted private masks. Each of the plurality of encrypted private masks indicates a region of the source image selected to display a private item of a corresponding user among a plurality of users. The instruction further causes the privacy management server to transmit the plurality of encrypted private masks to an image distribution server for decryption and, in response, determine a plurality of encrypted private images. Each of the plurality of encrypted private images is determined based on the source image and further based on a corresponding decryption mask including the decryption of the corresponding mask among the plurality of encrypted private masks, the corresponding decryption mask being received from the image distribution server. The instruction further causes the privacy management server to perform an encrypted domain key changing procedure to generate a plurality of re-encrypted images. Each of the plurality of re-encrypted images includes a result of transforming a corresponding private image among the plurality of encrypted private images from being decryptable with the management key to being decryptable with the private key of the corresponding user. The instructions further cause the privacy management server to combine the plurality of re-encrypted images into a composite private image and transmit the composite private image to the image distribution server for further distribution to multiple client devices. Each client device is configured to reconstruct a user-specific plaintext version of the source image based on the composite private image. Attached Figure Description
[0010] The foregoing aspects and advantages of the invention will be better understood after reading the following detailed description and referring to the drawings, wherein:
[0011] Figure 1 An exemplary privacy-preserving monitoring system according to some embodiments of the present invention is shown.
[0012] Figure 2 Exemplary components of an input sensor according to some embodiments of the present invention are shown.
[0013] Figure 3 Exemplary components of a client device according to some embodiments of the present invention are shown.
[0014] Figure 4 Exemplary components of an image distribution server according to some embodiments of the present invention are shown.
[0015] Figure 5 Exemplary components of a privacy management server according to some embodiments of the present invention are shown.
[0016] Figure 6 Exemplary source images are shown according to some embodiments of the present invention.
[0017] Figure 7 Description of some embodiments of the present invention includes Figure 6 Exemplary public images within the source images.
[0018] Figure 8 Demonstrating some embodiments of the present invention, including Figure 6 Exemplary private images within the source image.
[0019] Figure 9 Exemplary user masks are shown according to some embodiments of the present invention.
[0020] Figure 10 This demonstrates exemplary data exchange implemented according to some embodiments of the present invention to establish a privacy-preserving monitoring system.
[0021] Figure 11 This document demonstrates exemplary data exchange performed during the operation of a privacy-preserving monitoring system according to some embodiments of the present invention.
[0022] Figure 12 Displayed by the privacy management server Figure 11 The exemplary sequence of steps performed in the embodiments described herein.
[0023] Figure 13 Exemplary data exchange performed in an alternative embodiment of the invention is shown.
[0024] Figure 14 Displayed by the privacy management server Figure 13 Alternative exemplary sequence of steps implemented in the embodiments described herein.
[0025] Figure 15 This describes an exemplary sequence of steps performed by an image distribution server according to some embodiments of the present invention.
[0026] Figure 16 An exemplary sequence of steps for the exchange between an overview client device and a distribution server is shown, according to some embodiments of the present invention.
[0027] Figure 17-A Exemplary reconstructed images, applicable to selected client devices, are shown according to some embodiments of the present invention.
[0028] Figure 17-B This presents another exemplary reconstructed image that can be used in another client device according to some embodiments of the present invention.
[0029] Figure 18 This demonstrates exemplary data exchange in embodiments of the invention configured to perform selected tasks in a privacy-preserving manner.
[0030] Figure 19 This describes exemplary hardware configurations of computing devices configured to operate according to some embodiments of the present invention. Detailed Implementation
[0031] In the following description, it should be understood that all narrative connections between structures can be direct operational connections or indirect operational connections through intermediate structures. A set of elements comprises one or more elements. Any description of an element is understood to refer to at least one element. Multiple elements comprise at least two elements. Unless otherwise specified, any use of "or" refers to a non-exclusive "or". Unless otherwise required, any described method steps are not necessarily performed in a specific order of description. A first element derived from a second element (e.g., data) encompasses a first element equal to the second element as well as a first element produced by processing the second element and optionally processing other data. Making a determination or decision based on parameters encompasses making a determination or decision based on parameters and optionally based on other data. Unless otherwise specified, some quantity / data indicators may be the quantity / data itself or indicators different from the quantity / data itself. A computer program is a sequence of processor instructions that performs a task. The computer program described in some embodiments of the invention may be a separate software entity or sub-entity (e.g., subroutine, library) of other computer programs. The term 'database' is used herein to refer to any structured collection of data. Implementing an encryption domain procedure / operation herein means implementing a corresponding procedure / operation within an encryption domain, i.e., directly applying encryption input to produce an encryption output without involving decryption input. An encryption domain procedure is distinct from a procedure that decrypts input and then encrypts the output of the corresponding procedure. In other words, the entity implementing the encryption domain procedure / operation on an encryption item does not need to know the plaintext version of the item. Computer-readable media encompasses non-transitory media (e.g., magnetic, optical, and semiconductor storage media (e.g., hard disk drives, optical discs, flash memory, DRAM)) and communication links (e.g., conductive cables and fiber optic links). According to some embodiments, the present invention particularly provides hardware (e.g., one or more processors) programmed to perform the methods described herein, and computer systems comprising computer-readable media encoded instructions for performing the methods described herein.
[0032] The following description illustrates embodiments of the invention by way of example and not necessarily by way of limitation.
[0033] Figure 1An exemplary privacy-preserving surveillance system 10 is illustrated according to some embodiments of the present invention. The term "surveillance" is used herein only to clarify the disclosure by focusing on specific exemplary use cases and is not intended to limit it to typical surveillance activities such as crime prevention. Although the following description will focus on video surveillance examples, the disclosed systems and methods are applicable to other applications, such as protecting privacy and / or ensuring confidentiality during collaboration among multiple parties processing the same document, thereby preventing cyberbullying via online messaging, etc.
[0034] System 10 includes, in particular, an input sensor 14, a distribution server 30, a privacy management server 40, and multiple client devices 12a to c, all of which are communicatively coupled through a network 15 that may include the Internet.
[0035] Sensor 14 (e.g., a camera, microphone, etc.) is configured to acquire signals (e.g., encoded images and / or sound), which are further manipulated and transformed as described below. In a video surveillance example, sensor 14 may include a camera positioned to acquire images of public spaces such as a campus or market square. Thus, sensor 14 may include hardware and / or software components for acquiring signals (e.g., a charge-coupled device (CCD) optical sensor), computer-readable media for storing the acquired signals, and components for transmitting the corresponding signals (e.g., physical layer communication hardware, encoder, antenna, etc.). Figure 2 Other exemplary components of the input sensor 14 are shown, which may include dedicated software modules according to some embodiments of the invention. A cryptographic engine 16 encrypts the acquired image / sound recordings. A communication module 18 further transmits the resulting encrypted signals to a privacy management server 40 and / or an image distribution server 30, as detailed below.
[0036] In some embodiments, the cryptographic engine 16 encrypts data according to a homomorphic encryption scheme. Homomorphic encryption is a specific type of encryption that allows certain calculations, such as addition and / or multiplication, of encrypted data, where decrypting such calculations produces the same output as a plaintext version of the same data. In other words, if Enc(p) = c denotes a homomorphic encryption operation, where p represents the plaintext message and c represents its corresponding ciphertext, Dec(c) = p denotes a homomorphic decryption operation that recovers the corresponding plaintext message from its ciphertext, and Eval(F,{c1,...,c...}) = c... k})=C means applying the function F to a set of ciphertexts c i To generate the homomorphic evaluation procedure for ciphertext C, then:
[0037] Dec(C)=F(p1,...,p k ),[1]
[0038] Where pi = Dec(ci), i = 1, ..., k. In formal mathematical language, the encryption and decryption procedures of a homomorphic encryption scheme can be considered as homomorphisms between the plaintext space and the ciphertext space.
[0039] Several homomorphic encryption schemes / cryptographic systems are known in this field. Schemes that maintain homomorphism on any combination of addition and multiplication are generally called fully homomorphic. Examples include the Gentry-Sahai-Waters (GSW) scheme. Other schemes / algorithms are homomorphic only on a certain type of operation; for example, only addition in the Paillier scheme and only multiplication in the Rivest-Shamir-Adelman (RSA) scheme. Such schemes are called partially homomorphic in this field. In contrast, cryptography that does not possess the above homomorphic properties is considered non-homomorphic in this paper. Examples of non-homomorphic cryptography include the Advanced Encryption Standard (AES) used in some Transport Layer Security (TLS) communication protocols.
[0040] Client devices 12a to c generally refer to any end-user electronic device, such as a personal computer, smartphone, television, etc., used for accessing and / or processing (e.g., visualization, playback, etc.) data provided by input sensor 14. Figure 3 In some embodiments described herein, client device 12 may execute monitoring software application 22, which is configured to perform user authentication exchanges (e.g., login procedures) with distribution server 30 and subsequently display reconstructed images to the user. Data reconstruction engine 24 is configured to reconstruct images from a set of plaintext public images and a set of encrypted private images, as described below. Client cryptographic engine 26 is configured to decrypt received encrypted private images. In some embodiments, engine 26 implements a homomorphic decryption algorithm.
[0041] Each of the distribution server 30 and the privacy management server 40 generally represents a group of interconnected computer systems that may or may not be physically close to each other. Exemplary components of servers 30 and 40 are respectively located in... Figure 4 and 5 The illustrated components are shown in the figure. In some embodiments, such components represent computer programs (software) that execute on at least one hardware processor. Not all illustrated components need to execute on the same hardware processor or physical machine. Those skilled in the art will understand that, in alternative embodiments, some illustrated components may be implemented in dedicated hardware (e.g., application-specific integrated circuits (ASICs) and / or field-programmable gate arrays (FPGAs)), firmware, or a combination thereof.
[0042] In some embodiments, the distribution server 30 manages a monitoring service, including, for example, communication with client devices 12a to c for user registration and / or authentication, and the distribution of selectively encrypted data to each client device. Without loss of generality, server 30 may be referred to herein as an image distribution server, i.e., a server configured to distribute images (e.g., video) to clients. Those skilled in the art will appreciate that, depending on the actual embodiment and use case, server 30 may distribute other types of data, such as audio, electronic documents, etc. The user manager component 32 manages a set of user and / or account data (usernames, passwords, various service protocol parameters, etc.) and provides a user interface for user registration and account management.
[0043] Access manager component 38 can selectively store data to and / or retrieve data from data repository 20 based on the identity of the user currently authenticated on the corresponding client device, and selectively forward this data to each client device 12a to c. Access manager 38 may include a web server, etc.
[0044] Key manager 34 may initiate and / or execute key generation and exchange procedures with client devices 12a to c and privacy management server 40. Key manager 34 may further generate a set of proxy re-encryption tokens and selectively associate each of these tokens with a registered user and / or client device 12a to c of the monitoring service. Further details regarding such processes are given below.
[0045] The management cryptographic engine 36 can be configured to perform data encryption and / or decryption operations, as further described below. Engine 36 can implement versions of homomorphic encryption / decryption algorithms.
[0046] In some embodiments, data repository 20 may include computer-readable storage media configured to store databases of both private and public data. Public data may include any data accessible to all users, such as plaintext (i.e., unencrypted) images. Private data may be accessed and / or decrypted only by selected users. Examples of private data include user-specific and synthetically proxies-reencrypted images, as illustrated below. This data may be indexed by user to enable selective insertion and retrieval. The index may take any form known in the art.
[0047] In some embodiments, the privacy management server 40 ( Figure 5This provides services such as passwords and automatic detection of private / confidential items in data provided by input sensor 14. Server 40's re-encryption engine 46 is configured to perform a key exchange procedure on encrypted data, as shown in more detail below. The key exchange procedure, referred to herein as a procedure that transforms ciphertext from being decipherable with one key to being decipherable with another key, is an example of a key exchange procedure known in the field as proxy re-encryption, which allows entity Z to modify ciphertext encrypted with entity X's public key based on some information about another entity Y, thereby making it decryptable by entity Y. In other words, entity Y can decrypt ciphertext encrypted with X's public key using its own key, but only after the corresponding ciphertext has been proxy-re-encrypted by entity Z using a re-encryption key specific to entity Y (also known as a re-encryption notation in the field). This general scheme is translated as... Figure 1 The exemplary participants described herein, some embodiments of the privacy management server 40, proxy re-encrypt data already encrypted with the public key of the distribution server 30 so that the corresponding data can be decrypted by selected users of client devices 12a to c. The proxy re-encryption procedure employs a re-encryption symbol specific to the corresponding user and / or device, such as a symbol generated according to the public encryption key of the corresponding purpose / device.
[0048] In some embodiments, the re-encryption engine 46 operates within the cryptographic domain, i.e., it performs the corresponding key exchange procedure without decrypting the input. To achieve cryptographic domain key exchange, some embodiments of engine 46 implement a proxy re-encryption algorithm compatible with the homomorphic encryption / decryption algorithm implemented by the client devices 12a to c, the distribution server 30, and / or the input sensor 14. Such algorithms are beyond the scope of this description; several such examples are known in the field of cryptography, for example, from the PALISADE codebase available at https: / / gitlab.com / palisade / palisade-development.
[0049] A set of item detectors 42 can be configured to determine whether input data received from sensor 14 (e.g., frames captured by a surveillance camera) contains representations of private / confidential items associated with a selected user. Exemplary private items include people, faces or other body parts, logos / trademarks, license plates, bank cards, personal IDs (e.g., driver's licenses, passports), handwritten text, and personal signatures. In embodiments configured to operate in conjunction with sound, exemplary private items may include any item that allows for the identification of a person, such as any voice quality, such as timbre, vocal fry, pitch, rhythm, voice distortion, etc. In embodiments configured to process text documents and / or electronic messages, exemplary private items include written names, addresses, financial information (e.g., credit card numbers), etc. Other examples include text written by a selected author, text written on a selected topic, and text written in a selected style or conveying a selected emotion.
[0050] Private items can be user-specific. For example, in a school surveillance use case, each parent can define their own child as a private item, so that the child can only be seen by the corresponding parent. In some embodiments, multiple users can share a private item and / or a single user can have multiple private items. In one such instance, all members of a particular user group (e.g., parents of third-grade children) can see the faces of their child's peers, but other users cannot.
[0051] Figure 6 An exemplary source image 70 received from a surveillance camera (input sensor 14) is displayed, showing an exemplary private / confidential item containing people (e.g., children 72a to b), faces 72c, and specific objects 72d. Figures 7-8 Exemplary public and private images are shown within exemplary source image 70. In some embodiments, the private image includes a representation of a private / confidential item (e.g., a digital array). Figure 8 In one example, private image 76a includes displaying Figure 6 The private project 72a contains the source image area. Correspondingly, the public image 74 ( Figure 7 This could include another area of the source image 70 that does not display any private items. For example, public image 74 could display all non-private content of source image 70. Exemplary public images contain the background of a scene (landscape, buildings, trees, courtyard, sky, etc.). In some embodiments, public image 74 and / or private image 76a are represented as a digital array having the same size as source image 70.
[0052] The item detector 42 can be constructed using any methods known in the field. For example, an exemplary item detector 42 may include an artificial intelligence (AI) system 43a, such as a set of artificial neural networks pre-trained to identify examples of corresponding private items within a source image. The exemplary AI system 43a includes a face recognition module and an image segmentation module, etc. The structure and training of such item detectors are beyond the scope of this description; several architectures and training strategies are known in the field.
[0053] In an image processing embodiment, the exemplary item detector 42 may receive a source image 70 and output a user mask indicating a region of the source image that displays a representation of a private item (e.g., a region of the source image that displays the face of a particular person). Figure 9 Display and Figure 6 An exemplary user mask 80a is associated with the private item 72a. The exemplary user mask is characterized by a subset of pixels belonging to the corresponding private item in the image. Another exemplary user mask includes all pixels located within a contiguous area of the source image 70, which displays the private item. For example, in... Figure 9In the embodiments described herein, this region may be defined as the interior of a polygon (e.g., convex hull, bounding box, etc.) enclosing the private item. The user mask's convenient computer-readable encoding comprises a sparse array of numbers having the same size as the source image 70 and wherein all elements except those corresponding to the mask pixels are zero. Multiple user masks may be associated with a single user (i.e., a single re-encryption symbol, see below). Some user masks may overlap.
[0054] In some embodiments, detector 42 operates in a cryptographic domain, i.e., without decrypting the source image. To achieve this cryptographic domain operation, AI system 43a (e.g., a neural network implementing face recognition) may be intentionally structured to be compatible with homomorphic encryption schemes. For example, detector 42 may receive a homomorphically encrypted source image and, in response, output a homomorphically encrypted user mask, which is encrypted using an encryption key identical to the encryption key used to encrypt the source image. Several such AI systems have been described in the art. Examples include cryptoNets described in “CryptoNets: Applying Neural Networks to Encrypted Data with HighThroughput and Accuracy” by N. Dowlin et al. (Proceedings of the 33rd International Conference on Machine Learning, New York, NY, 2016, JMLR: W&CP Vol. 48). In one such example, AI system 43a includes a neural network in which selected layers are equivalent to polynomials of a predetermined degree, and in which typical nonlinear activation functions, such as modified linear units (ReLU), are replaced by polynomial approximations.
[0055] In some embodiments, the AI system 43a is pre-trained by the AI training system 11 (e.g., a machine learning algorithm executed on a processor) using training data provided or otherwise indicated by each user. In one such example, after registering for the service, each user may provide a sample representation of a confidential item belonging to that user, such as an image of a face or a sample of a person's voice. Some embodiments may then train the AI system 43a to recognize the representation of the corresponding private item within a data stream received from the input sensor 14. A relevant example is training face recognition software on a target face provided by each user. The training produces a set of optimized detector parameter values 45a, which are transmitted to the item detector 42. In a neural network embodiment, exemplary parameters 45a include a set of synaptic weights and neuron biases, etc.
[0056] Figure 10This illustrates an exemplary exchange performed according to some embodiments of the present invention to initialize / establish a privacy-preserving monitoring service. In the illustrated example, the distribution server 30 implements a key generation procedure to generate a pair of homomorphic encryption keys (referred to herein as management keys) specific to the distribution server 30 and transmits the public key 52 of the pair to the input sensor 14 for encrypting the acquired signals / images. The server 30 further engages with the client device 12 (generally referred to as...) Figure 1 The key generation and / or exchange protocol of client devices 12a to 12c (in which client device 12 generates a pair of distinct cryptographic keys (referred to herein as user keys) specific to each user accessing the privacy monitoring service via client device 12. Alternative embodiments may generate device-specific cryptographic keys. User and / or device key generation may occur during registration as part of the initial service configuration procedure for each user and may be performed according to a homomorphic encryption key generation algorithm. Client device 12 then sends a public user key 54 to distribution server 30. In response to receiving key 54, key manager 34 may generate a set of proxy re-encryption symbols 50 uniquely associated with each user and / or client device. Some embodiments generate each set of user-specific symbols 50 based on the public key associated with the respective user / device and based on a management key, via a symbol generation algorithm compatible with the homomorphic encryption algorithm used by client device 12 to generate user / device keys. This key generation protocol / procedure is beyond the scope of this description; several examples are known in the field of cryptography. Next, the re-encryption symbol 50 is transmitted to the privacy management server 40 for proxy re-encryption of user-specific private images, as detailed below.
[0057] Figure 11 and 13 This section describes the data exchange implemented in two exemplary embodiments of a privacy-preserving surveillance system. For clarity, the following description will focus on video surveillance, i.e., the relevant source data includes image data. Those skilled in the art will understand that the methods described herein are applicable to other applications where the relevant data includes encoded audio (e.g., voice recordings), text, etc.
[0058] Figure 12 and 14 The privacy management server 40 is displayed separately. Figure 11 and 13 The alternative sequence of steps implemented in the described embodiments. Accordingly, Figure 15 Demonstrative steps implemented by image distribution server 30 are shown.
[0059] In some embodiments, data acquired by input sensor 14 is encoded as a plaintext image I, for example, comprising a digital array, where each number represents the intensity of the corresponding image at a different location / pixel. Some images may have multiple channels (e.g., red, green, and blue); in such embodiments, each channel may be represented by a separate array. Image I is then encrypted by sensor cryptography engine 16 according to a public management key 52 to produce an encrypted data stream 60 transmitted to privacy management server 40. Stream 60 may include, for example, a set of encrypted source images:
[0060]
[0061] Enc(x,k) generally represents encrypting a quantity x using a key k, where k p admin This represents the public management key 52. The asterisk (*) is always used to indicate the number of encryptions. In a video surveillance embodiment, each encrypted source image I* may correspond to a different frame and may be accompanied by an associated timestamp indicating the time when the corresponding frame was acquired.
[0062] In response to receiving data stream 60, for each encrypted source image I*, in step 204 ( Figure 12 In this context, server 40 may apply item detector 42 to determine whether a corresponding image contains private data (i.e., an image of an item that some users consider private). If so, some embodiments of detector 42 return a set of user masks that identify the regions of the source image displaying various private items (see [link to relevant documentation]). Figure 9 (Exemplary mask 80a). Furthermore, such masks are indexed based on the user who has declared the corresponding item as private. Some embodiments may further determine a set of public masks comprising regions of the current frame containing only public data. In an exemplary embodiment, the public mask is determined by inverting all user masks and superimposing the results. In another embodiment, the item detector 42 may be trained to return a set of public masks as well as user masks.
[0063] However, since the privacy management server 40 does not possess the secret management key and therefore cannot decrypt the source image I*, some embodiments of the item detector 42 operate in the encrypted domain (i.e., operate directly on encrypted data) and produce encrypted output (i.e., the user mask is also encrypted). Therefore, in some embodiments, although the item detector 42 executes on the server 40, the server 40 is unaware of the content of the source image or which area of the source image contains private items (if any).
[0064] In some embodiments, a set of steps 206 to 208 ( Figure 12The encrypted domain image segmentation procedure is executed to extract a set of encrypted public and private images from the current source image I* based on the output of the item detector 42. Each private image may include the (encrypted) content of the current source image located within a dissimilar user mask. In some embodiments, the encrypted private image associated with user mask i may be determined based on a pixel-wise multiplication of the encrypted source image and the encrypted mask i:
[0065]
[0066] Where M* i This represents the encrypted user mask i returned by project detector 42:
[0067]
[0068] And M i Indicates the unencrypted / plaintext user mask i.
[0069] The circled dot operator in this article represents pixel-wise multiplication:
[0070]
[0071] The {xy} indexes the position / pixel within the source image and the user mask, respectively. Pixel-by-pixel multiplication is applied to images / arrays of the same size.
[0072] At the same time, the current frame ( Figure 11 The encrypted public image of item 62) can be calculated by element-wise multiplication of the encrypted source image and the encrypted public mask:
[0073] I *PUBLIC =I * ⊙M *PUBLIC [6]
[0074] Where M *PUBLIC This represents the encrypted public mask generated by the project detector 42:
[0075]
[0076] Where M PUBLIC This indicates the corresponding unencrypted / plaintext public mask.
[0077] In some embodiments, in step 210, the privacy management server 40 may employ a re-encryption engine 46 to proxy the re-encryption of a private image determined as seen above (e.g., formula [2]) based on a re-encryption symbol associated with the corresponding user / mask i to generate an individual user-specific re-encrypted private image 66. Figure 11The encrypted public image 62 and the re-encrypted private image 66 are then transmitted to the image distribution server 30. This proxy re-encryption ensures that the corresponding private image can only be deciphered by the holder of the decryption key associated with the user / mask i. In some embodiments, the re-encrypted private image 66 is marked with an indicator of the corresponding user so that the server 30 can selectively insert the image 66 into the data repository 20 and / or retrieve the image 66 from the data repository 20. The additional sequence of steps 212 to 214 transmits the encrypted public image 62 and the re-encrypted private image 66 to the server 60 for further distribution to client devices 12a to 12c.
[0078] exist Figures 13-14 In the alternative embodiment described herein, in step 230, server 40 may transmit the encrypted user mask 64 to image distribution server 30 for decryption and, in response, receive the decrypted user mask 65 from server 30. In some embodiments, the decrypted mask 65 includes a plaintext version of the encrypted user mask determined by item detector 42:
[0079]
[0080] Dec(x,k) generally represents decrypting a quantity x using a key k, where k s admin This represents the secret key held by the image distribution server 30. In such embodiments, even though the privacy management server 40 can clearly see whether the source image displays private items and which area of the source image displays private items, privacy is still protected because the server 40 cannot decrypt any area of the corresponding source image I*.
[0081] Next, step 234 extracts the private image by copying pixels of the encrypted frame located within each decrypted user mask 65. In some embodiments, this may mean determining the encrypted private image associated with mask i as:
[0082]
[0083] Additionally, step 236 may employ a re-encryption engine 46 to proxies the re-encryption of each private image using the user's re-encryption token associated with the corresponding mask i to generate an individual re-encrypted private image. Next, in step 238, some embodiments may compute a composite re-encrypted private image 67 based on the plurality of individual re-encrypted private images determined in step 236. In some embodiments, the composite image 67 comprises a single image assembled from the plurality of private images in a mosaic manner, wherein each individual re-encrypted private image occupies an area corresponding to the corresponding user mask M. i The region of the synthesized image. The computation of the synthesized private image can be facilitated by padding each proxy re-encrypted private image with zeros to the size of the source image. Then, the synthesized re-encrypted private image 67 can be calculated according to the following formula:
[0084]
[0085] ReEnc(x,t) generally represents re-encrypting the ciphertext x using the notation t, and t i This represents the re-encryption notation associated with user / mask i. The circled plus operator in this document represents pixel-by-pixel addition:
[0086]
[0087] The {xy} indexes the position / pixel within the exemplary images I1 and I2, respectively. Pixel-by-pixel summation is applied to images of the same size.
[0088] Next, the calculated composite re-encrypted private image 67 can be transmitted to the image distribution server in step 240. In an alternative embodiment, the privacy management server 40 can calculate individual proxy re-encrypted private images and transmit the corresponding images to the distribution server 30. Accordingly, the server 30 can determine the composite image 67 from the received individual re-encrypted images, for example, using equation
[10] .
[0089] at the same time( Figure 14 In step 226), the privacy management server 40 can calculate the encrypted public image 62 as shown above (e.g., equation [6]). Alternatively, image 62 can be determined based on the plaintext public mask:
[0090] I *PUBLIC =I * ⊙MP UBLIC
[12]
[0091] Where M PUBLIC Received from distribution server 30. In yet another embodiment, this can be achieved by making all plaintext user masks M received from server 30... i To calculate M, reverse and superimpose the results. PUBLIC In any of these scenarios, image 62 is encrypted with the management key by virtue of the fact that server 40 performs image segmentation in the encrypted domain (i.e., without decrypting the source image). In other words, server 40 is unaware of the plaintext content of public image 62. In step 228, the encrypted public image 62 is transmitted to server 30 for decryption and further distributed to the client.
[0092] Figure 15An exemplary operation of an image distribution server 30 according to some embodiments of the present invention is described. In the sequence of steps 252 to 254, server 30 may wait for communication from privacy management server 40. When such communication includes an encrypted user mask (step 256 is returned), image distribution server 30 may use cryptographic engine 36 to decrypt the corresponding mask according to its secret management key (e.g., formula [6] above) and transmit the decrypted mask to privacy management server 40.
[0093] When communication includes the encrypted public image 62, the server 40 can decrypt it to produce the decrypted public image 63.
[0094]
[0095] Image 63 is then saved to data repository 20. Decrypting public image 63 can be done by using a timestamp, frame number, or another indicator that associates image 63 with the source image from which image 63 was extracted.
[0096] When communication received from server 40 includes re-encrypted private images (depending on whether server 40 follows the respective procedures) Figure 12 Alternatively, image distribution server 30 may insert the corresponding private image into data repository 20 when specific to a user / mask (or composite). Re-encrypted private images may also be tagged with timestamps and / or tags that associate the corresponding image with the corresponding source image. Private images may also be tagged to indicate their association with a specific user and / or mask.
[0097] Figure 16 The image distribution server 30 displays the image relative to the general representation. Figure 1 Further exemplary steps performed by client device 12 of any of the client devices 12a to 12c. In step 280, client device 12 may implement a user authentication procedure to identify the current user of device 12 according to distribution server 30. Step 280 may implement any user authentication protocol known in the art (e.g., password, two-factor authentication, biometrics, etc.). In step 282, device 12 may then transmit a query to server 30 to, for example, indicate a request to view images captured from a specific surveillance camera within a specific time frame. In response, in the sequence of steps 284 to 290, image distribution server 30 may selectively retrieve a set of public and private images from data repository 20 according to the query and transmit the corresponding images to client device 12. Depending on whether privacy management server 40... Figure 12Alternatively, as illustrated in flowchart 14, the private images may comprise either individually re-encrypted private images 66 or composite re-encrypted private images 67. For example, such transactions may be implemented via a web interface. In an alternative embodiment, the image distribution server 30 may open a dedicated connection (e.g., a VPN tunnel) with the client device 20 and transmit public and private images via that connection.
[0098] Those skilled in the art will understand that although the public image has been decrypted to plaintext before distribution, step 288 does not necessarily include transmitting the corresponding public image in plaintext. Instead, step 288 may include re-encrypting the transmitted public image, for example, as part of a transmission over TLS / HTTPS. However, this encryption has no effect on image reconstruction at the client device; in a TLS / HTTPS transaction, the receiving client device can always decrypt the payload.
[0099] In response to receiving public and private images, in step 292, the client device 12 can use the client cryptographic engine 26 ( Figure 3 The corresponding private image is decrypted using a secret key associated with the corresponding user of the client device 12. Next, in step 294, the data reconstruction engine 24 can calculate a reconstructed image based on the decrypted private image and further based on the decrypted public image 63 received from the image distribution server 30. For example, the reconstructed image can be calculated via pixel-by-pixel addition of the decrypted public image 63 and the decrypted private image:
[0100]
[0101] Where R i Let k represent the reconstructed image seen by user i, and k s i This represents the secret key of user i. When the source image includes private data of multiple users, formula
[14] may not calculate the entire reconstructed image. In this sense, it corresponds to the user mask M belonging to a user different from the current user i of client device 12. j The regions of the reconstructed image can be empty. In order to obtain a complete reconstructed image, some embodiments can fill the missing regions with pseudo-data (e.g., zeros, random noise, random colors, etc.).
[0102] In cases where masks associated with different users can overlap, such as when some information can be associated with multiple users (e.g., with members of a selected group) while other information is private to each user, reconstructing the frame according to formula
[14] may be preferred. Another instance of this situation may occur in an automatic image segmentation system configured to generate multi-label classification.
[0103] In one embodiment where a reconstructed image is calculated from a synthetic private image, the reconstructed image R iIt is complete, but the secret key k is held by user i. s i Only the private data of the corresponding user can be decrypted. Therefore, the user mask M corresponds to other users. j The reconstructed image will display the scrambled image in the relevant region. This effect is achieved in... Figure 17-A Please refer to section B for further explanation. Figure 17-A B shows how two different users see the reconstruction of the same source image. Figure 17-A Showing the reconstructed image as seen by user A, whose declared item 72a( Figure 6 This is for private use. User A will see the image of private item 72a, but will not be able to see images of other users' private items, such as images of items 72b to 72d (see [link to private item]). Figure 6 ). Figure 17-B The image shown is the reconstructed image seen by another user, B, whose project 72b is private. User B can see the image of project 72b, but cannot see the images of private projects 72a and 72c through d.
[0104] In embodiments where the item detector 42 generates only non-overlapping user masks and / or where dissimilar users do not share private information, frame R can preferably be reconstructed according to formula
[15] . i That is, reconstructing frame R from a synthesized encrypted private image. i Otherwise, regions of the reconstructed image covered by mask overlap cannot be deciphered by any individual user and thus scrambling may occur. Operating with a synthetic private image further saves computational resources because it allows sending the same encrypted private data (i.e., a synthetic private image) to all users, rather than storing, indexing, and selectively delivering individual private images to each user. In such embodiments, server 40 can directly insert private and public images into data repository 20 without further involvement of distribution server 30. A disadvantage of embodiments using synthetic re-encrypted private images is that they ensure a relatively low level of privacy compared to embodiments using individual private images, because server 40 operates with a decryption / plaintext mask when computing the private image. In other words, although server 40 does not know the content of the private image, it knows, for example, whether the source image contains a private item and it also knows the approximate location of the corresponding private item via the corresponding plaintext mask.
[0105] Figure 18 This describes an enhancement to the privacy protection monitoring system according to some embodiments of the present invention. In some embodiments, a privacy management server 40 ( Figure 5The image processing module 44 is further configured to perform specific tasks based on the encrypted data stream 60 received from the input sensor 14. An example of an image processing task includes event detection (determining whether an image or sequence of images indicates a specific event has occurred). In a traffic monitoring embodiment, the task module may automatically determine whether a source image indicates an accident, traffic congestion, etc. Other exemplary tasks include counting people in an image and determining whether the count exceeds a predetermined threshold. Yet another exemplary task generally includes any image classification / labeling task, such as determining whether an image displays a specific type of object (e.g., weapon, personal ID, bank card, license plate, etc.). Those skilled in the art will understand that while the examples above relate to image processing, this is not intended to be limiting, and some embodiments may be adapted to process other types of data, such as audio files, text documents, etc.
[0106] In some embodiments, task module 44 ( Figure 5 This includes an AI system 43b that has been pre-trained to perform the corresponding task. Several such instances are known in the field of computer vision; their architecture and training are beyond the scope of this disclosure. The AI system 43b may be pre-trained by the AI training system 11, in which the system 11 may, for example, determine a set of optimized task module parameter values 45b (e.g., synaptic weights, etc.) via a machine learning process and use the values 45b to exemplify runtime examples of the image task module 44.
[0107] Task module 44 can operate in an encrypted domain, i.e., without decrypting the source data. In such embodiments, module 44 can take an encrypted image as input and produce encrypted output including the result of performing a corresponding task, the output using a public management key associated with distribution server 30. Encryption. For example, the output of task module 44 may include an encrypted version of the decision or label (e.g., yes / no based on whether data stream 60 indicates that a specific event has occurred). Because module 44 is executed in an encrypted domain, the privacy management server 40 is unaware of the task result.
[0108] In some embodiments, the output of task module 44 is generated by engine 46. Figure 5The selected user's re-encryption token is used for proxy re-encryption to produce a re-encryption task result 86, which is sent to the distribution server 30 for delivery to a predetermined notification device 13 (e.g., the selected user's smartphone). In some embodiments, the notification device 13 may also receive decrypted public image 63, allowing the corresponding user to see publicly available image data in addition to being notified of the event or situation. For example, a principal (or security personnel) may receive a notification that a fight is taking place on school grounds, but when this information is considered private, they cannot see who is actually involved in the fight. Furthermore, since the task result 86 can only be deciphered by the selected notification device, all users except the principal will not know that a fight has occurred. Additionally, the owner / operator of the server 40 will also be unaware of such an event.
[0109] Some embodiments further enhance this by adding a superuser, who is allowed to see all private information contained in the source image. This superuser may represent an authoritative figure, such as a school principal or a representative of a company's human resources department. After establishing the monitoring service, the image distribution server 30 can create a pair of keys and a set of re-encryption tokens associated with the superuser. In one of these exemplary embodiments, in response to determining a user mask and extracting a private image, the privacy management server 40 can use the superuser's re-encryption tokens to proxy re-encrypt the extracted private images associated with all users, thus creating a composite private image accessible only to the superuser. The corresponding re-encrypted private data is then sent to the image distribution server 30 and, together with the decrypted public image 63, becomes further accessible to the superuser. The superuser can decrypt the corresponding re-encrypted private image and thus completely reconstruct the source image from the public image 63 and the decrypted composite private image. Meanwhile, users who do not possess the superuser's private encryption key cannot see private data belonging to another user.
[0110] Figure 19 An exemplary computer system 90 is shown, configured to perform some of the methods described herein. Computer system 90 may represent any of client devices 12a to 12c, as well as an image distribution server 30 and a privacy management server 40. The hardware configuration described is that of a personal computer; the configuration of other computing devices (e.g., mobile phones and servers) may be different. Figure 19 The configuration shown is slightly different. Processor 92 includes physical devices (e.g., a microprocessor, a multi-core integrated circuit formed on a semiconductor substrate) configured to perform computations and / or logical operations using a set of signals and / or data. Such signals or data may be encoded and delivered to processor 92 in the form of processor instructions (e.g., machine code). Processor 92 may include an array of central processing units (CPU) and / or graphics processing units (GPUs).
[0111] Memory unit 93 may include volatile computer-readable media (e.g., dynamic random access memory (DRAM)) storing data and / or instruction codes accessed or generated by processor 92 during operation. Input device 94 may include a computer keyboard, mouse, touchpad, microphone, etc., and includes corresponding hardware interfaces and / or adapters that allow users to introduce data and / or instructions into computer system 90. Output device 95 may include display devices (e.g., monitors) and speakers, etc., and hardware interfaces / adapters (e.g., graphics cards) to enable corresponding computing devices to transmit data to users. In some embodiments, input and output devices 94 to 95 share common hardware (e.g., touchscreen). Storage device 96 includes computer-readable media capable of non-volatilely storing, reading, and writing software instructions and / or data. Exemplary storage devices include magnetic disks and optical disks and flash memory devices, as well as removable media such as CDs and / or DVDs and drives. Network adapter 97 includes mechanical, electrical, and signaling circuitry systems for coupling to an electronic communication network (e.g., Figure 1 The adapter 97 can be further configured to use various communication protocols to transmit and / or receive data.
[0112] A controller hub 98 generally refers to multiple systems, peripheral devices, and / or chipset buses and / or all other circuitry that enables communication between the processor 92 and the remaining hardware components of the computer system 90. For example, a controller hub 98 may include a memory controller, an input / output (I / O) controller, and an interrupt controller. Depending on the hardware manufacturer, some of these controllers may be incorporated into a single integrated circuit and / or integrated with the processor 92. In another example, a controller hub 98 may include a northbridge connecting the processor 92 to memory 93 and / or a southbridge connecting the processor 92 to devices 94, 95, 96, and 97.
[0113] The exemplary systems and methods described herein allow data (e.g., videos, photos, audio recordings, digital documents, etc.) to be distributed to multiple users in a manner that protects the privacy of the respective users. Some embodiments employ homomorphic encryption and proxy re-encryption techniques to manipulate the data such that selected portions of it are revealed based on the identity of the user currently accessing the data.
[0114] One exemplary application of some embodiments includes video surveillance, where the distributed data comprises an image stream received from a surveillance camera. Some embodiments employ image recognition technology to determine whether an image contains items considered confidential by a selected user (e.g., a specific person or face, a specific license plate, etc.), and manipulate and selectively encrypt the corresponding image so that only the corresponding user can see the confidential items. Simultaneously, other users may be allowed access to another version of the same image, where the confidential items are obscured (e.g., hidden, cropped, scrambled, etc.).
[0115] In some embodiments, selected users (e.g., parents) can designate certain children as private items. Images of the campus captured by cameras can be distributed to multiple users. However, images distributed to the principal and parents of children designated as private items will show the respective child's face, while in images distributed to all other users, the face may be obscured or scrambled.
[0116] The applications of some embodiments are not limited to surveillance. In another example, a camera records the demonstration of a product or prototype. The images are then transmitted to multiple remote users, for example, in a video conferencing format. However, different users may receive different versions of the same image. For example, a user who has signed a confidentiality agreement may be shown the corresponding product or prototype, while in images distributed to other users, the corresponding item may be obscured / scrambled.
[0117] The nature of projects considered private / confidential can vary significantly between implementations. Artificial Intelligence System 43 ( Figure 5 It can be trained to identify any private items of this type within a source image. Subsequently, some users will see images of the corresponding items, while others will not.
[0118] Many conventional video surveillance systems use encryption to prevent unauthorized access to acquired images. Some of these systems also add automatic image recognition and / or image segmentation functionality. However, conventional surveillance systems first decrypt the source image in preparation for image recognition. For example, a conventional computer system performing image analysis typically also possesses the key used to decrypt the source image. In contrast, by utilizing homomorphic encryption, some embodiments of the present invention perform automatic item detection / masking directly in the encrypted domain, i.e., without first decrypting the source image. Specifically, the privacy management server described herein does not even possess the key used to decrypt the source data. Therefore, in embodiments of the present invention, the computer system performing image recognition and / or segmentation is unaware of the content of the analyzed image, which substantially enhances the privacy of system users.
[0119] Homomorphic encryption, used in some embodiments of the present invention, also allows for the decoupling of user management / image distribution activities from image analysis activities. Figure 1In the exemplary privacy-preserving video surveillance system described herein, servers 30 and 40 can be owned and operated by separate entities. In an exemplary use case scenario illustrating the advantages of some embodiments of the invention, Company A owns and operates input sensor 14 and distribution server 30 and outsources image processing services (i.e., services provided by server 40) to another company, Company B. Sensor 14 can collect images from an office building, and Company A may want to automatically detect events such as unusual office activity, the presence of unidentified individuals, etc., to determine the number of people present at certain office events, to determine when certain employees arrive at or leave work, etc. Company B can provide such services in a privacy-preserving manner because server 40 has no access to unencrypted data and further lacks information to decrypt incoming source data. Instead, image segmentation and / or other tasks are performed in an encrypted domain, and the results of such operations can only be decrypted by a computer system operated by a representative of Company A (e.g., server 30, selected client devices 12a to c). Privacy is further enhanced by the fact that… Figure 11 and 13 In the embodiment described herein, the distribution server 30 is not authorized to access the source data itself, but is limited to accessing its "public portion," that is, the portion of the source image that does not show private / confidential items.
[0120] Some embodiments are not limited to image processing / video surveillance, but can be applied to the processing of audio files, documents, and electronic messages. In one of these exemplary embodiments, the voice of a target person can be selected as a private item. For example, the source data of the recording can be processed as shown herein, i.e., it can be divided into a private portion and a public portion, wherein the private portion can consist of fragments of the source recording including the target person's speech. The private portion can then be re-encrypted using tokens corresponding to a selected subset of users. When the corresponding recording is reconstructed, the selected users can hear the target person's speech, while other users cannot. Another exemplary embodiment can distort / scramble the speech of certain words (e.g., swear words, selected names, etc.).
[0121] In exemplary document or messaging embodiments, private items may include names, addresses, phone numbers, credit card or bank account numbers, etc. In some embodiments, private items may include entire portions of a document, such as specific chapters, sections with specific authors, or sections addressing specific topics. In yet another exemplary embodiment, private items may include portions of dialogue (e.g., electronic messaging exchanges) indicating specific emotions. Item detector 42 may use a set of rules or a pre-trained artificial intelligence system to automatically identify such private items in encrypted source documents. Using the selective proxy re-encryption technique shown herein, the same document can then be distributed to multiple users in a manner where selected users can see the corresponding private items in plaintext, while other users cannot.
[0122] Those skilled in the art will recognize that the embodiments described above can be modified in many ways without departing from the scope of the invention. Therefore, the scope of the invention should be determined by the appended claims and their legal equivalents.
Claims
1. A method for distributing privacy-preserving images to multiple users, the method comprising employing at least one hardware processor of a privacy management server: In response to receiving an encrypted source image that can be decrypted with a management key, an encrypted domain image segmentation of the source image is performed to determine a plurality of encrypted private masks, each of the plurality of encrypted private masks indicating a region of the source image selected to display the private items of the corresponding user among the plurality of users; A plurality of encrypted private images are determined, each of the plurality of encrypted private images being determined according to the following: I * ⊙M, The circled dot symbol indicates pixel-by-pixel multiplication, I * M represents the encrypted source image, and M represents the corresponding decryption mask that includes the corresponding mask among the plurality of encrypted private masks; An encryption domain key change procedure is executed to generate multiple re-encrypted images, each of the multiple re-encrypted images including the result of transforming a corresponding private image in the multiple encrypted private images from one that can be decrypted with the management key to one that can be decrypted with the corresponding user's private key; The multiple re-encrypted images are combined into a synthetic private image; and The synthesized private image is transmitted to an image distribution server for further distribution to multiple client devices, each of which is configured to reconstruct a user-specific plaintext version of the source image based on the synthesized private image.
2. The method of claim 1, wherein combining the plurality of re-encrypted images comprises copying each re-encrypted image to the location indicated by the corresponding decryption mask in the synthesized private image.
3. The method of claim 1, further comprising determining the synthesized private image based on the pixel-by-pixel summation of the plurality of re-encrypted images.
4. The method according to claim 1, wherein: Performing the encrypted domain image segmentation of the source image further includes determining an encrypted public image, the encrypted public image comprising a region of the source image selected to not display private items of any of the plurality of users; The method further includes using at least one hardware processor of the privacy management server to transmit the encrypted public image for decryption and further transmit it to the plurality of client devices; and Each client device is configured to further reconstruct the user-specific plaintext version of the source image based on the decryption of the encrypted public image.
5. The method of claim 4, further comprising determining the encrypted public image based on the corresponding decryption mask.
6. The method according to claim 1, wherein the encrypted source image is encrypted according to a homomorphic encryption scheme.
7. The method of claim 1, wherein the plaintext version of the source image displays the private items of a selected user among the plurality of users and obscures the private items of the other users among the plurality of users.
8. The method of claim 1, wherein the private items include items selected from groups of individuals and faces.
9. The method of claim 1, wherein the private item includes a bank card.
10. A computer system comprising a privacy management server, the privacy management server being configured to: In response to receiving an encrypted source image that can be decrypted with a management key, an encrypted domain image segmentation of the source image is performed to determine a plurality of encrypted private masks, each of the plurality of encrypted private masks indicating a region of the source image selected to display the private items of a corresponding user among a plurality of users; A plurality of encrypted private images are determined, each of the plurality of encrypted private images being determined according to the following: I * ⊙M, The circled dot symbol indicates pixel-by-pixel multiplication, I * M represents the encrypted source image, and M represents the corresponding decryption mask that includes the corresponding mask among the plurality of encrypted private masks; An encryption domain key change procedure is executed to generate multiple re-encrypted images, each of the multiple re-encrypted images including the result of transforming a corresponding private image in the multiple encrypted private images from one that can be decrypted with the management key to one that can be decrypted with the corresponding user's private key; The multiple re-encrypted images are combined into a synthetic private image; and The synthesized private image is transmitted to an image distribution server for further distribution to multiple client devices, each of which is configured to reconstruct a user-specific plaintext version of the source image based on the synthesized private image.
11. The computer system of claim 10, wherein combining the plurality of re-encrypted images includes copying each re-encrypted image to a location in the composite private image indicated by the corresponding decryption mask.
12. The computer system of claim 10, wherein the privacy management server is configured to determine the synthetic private image based on the pixel-by-pixel summation of the plurality of re-encrypted images.
13. The computer system according to claim 10, wherein: Performing the encrypted domain image segmentation of the source image further includes determining an encrypted public image, the encrypted public image comprising a region of the source image selected to not display private items of any of the plurality of users; The privacy management server is further configured to transmit the encrypted public image for decryption and further transmit it to the plurality of client devices; and Each client device is configured to further reconstruct the user-specific plaintext version of the source image based on the decryption of the encrypted public image.
14. The computer system of claim 13, wherein the privacy management server is configured to determine the encrypted public image based on the corresponding decryption mask.
15. The computer system of claim 10, wherein the encrypted source image is encrypted according to a homomorphic encryption scheme.
16. The computer system of claim 10, wherein the plaintext version of the source image displays the private items of a selected user among the plurality of users and obscures the private items of the other users among the plurality of users.
17. The computer system of claim 10, wherein the private items include items selected from groups of people and faces.
18. The computer system of claim 10, wherein the private items include bank cards.
19. A non-transitory computer-readable medium storing instructions that, when executed by at least one hardware processor of a privacy management server, cause the privacy management server to: In response to receiving an encrypted source image that can be decrypted with a management key, an encrypted domain image segmentation of the source image is performed to determine a plurality of encrypted private masks, each of the plurality of encrypted private masks indicating a region of the source image selected to display the private items of a corresponding user among a plurality of users; A plurality of encrypted private images are determined, each of the plurality of encrypted private images being determined according to the following: I * ⊙M, The circled dot symbol indicates pixel-by-pixel multiplication, I * M represents the encrypted source image, and M represents the corresponding decryption mask that includes the corresponding mask among the plurality of encrypted private masks; An encryption domain key change procedure is executed to generate multiple re-encrypted images, each of the multiple re-encrypted images including the result of transforming a corresponding private image in the multiple encrypted private images from one that can be decrypted with the management key to one that can be decrypted with the corresponding user's private key; The multiple re-encrypted images are combined into a synthetic private image; and The synthesized private image is transmitted to an image distribution server for further distribution to multiple client devices, each of which is configured to reconstruct a user-specific plaintext version of the source image based on the synthesized private image.