A privacy video encryption method, device, equipment and storage medium
By obtaining the device type and operating parameters of the monitoring equipment, reading the privacy configuration and encrypting the video stream, and generating encrypted target video frames, the problem of real-time monitoring images not being processed according to privacy requirements is solved, and the security protection of privacy videos is achieved.
Patent Information
- Application Number
- CN202310319301.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-22
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2043-03-22
AI Technical Summary
In existing technologies, due to the real-time requirements of the video footage, real-time monitoring cannot effectively process privacy according to different privacy needs, which makes it easy for private video data to be leaked and causes unpredictable hidden dangers.
By obtaining the device type and operating parameters of the monitoring equipment, reading the corresponding privacy configuration, determining the privacy area, and encrypting the video stream based on the coordinates of the privacy area, an encrypted target video frame is generated, adapting to different device types and privacy requirements.
It enables effective processing of real-time monitoring footage based on different privacy requirements, preventing the leakage of private video data and protecting the security of privacy data.
Smart Images

Figure CN116347168B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data protection, and in particular to a method, apparatus, device, and storage medium for encrypting private videos. Background Technology
[0002] With the development of video surveillance technology, it has been widely applied in various fields. Video surveillance equipment, ubiquitous in daily life, records every detail of people's lives, easily achieving various types of intelligent identification and processing, providing people with a more convenient and safer living environment. However, while video surveillance provides convenience, it also poses risks to people's privacy.
[0003] In the era of big data, the development of information technology has given all human data economic value. Surveillance video data, in particular, has become a scarce resource, especially video data involving privacy. Its significant commercial value often becomes a motivation for privacy violations, and network technology has provided convenience and possibilities for such violations. In an open network environment, once private video data is leaked, the consequences are unpredictable, and the resulting harm is immeasurable. Currently, most technologies only process privacy data based on different privacy needs after the video has been generated. However, due to the real-time requirements of live surveillance, the video data is usually displayed directly on the viewing device, making it difficult to process privacy data according to different privacy requirements. Summary of the Invention
[0004] This invention provides a method, apparatus, device, and storage medium for encrypting privacy videos, in order to solve the problem of privacy processing of real-time monitoring images according to different privacy requirements.
[0005] In a first aspect, the present invention provides a method for encrypting private videos, comprising:
[0006] Obtain the device type of the monitoring device and the video stream captured by the monitoring device;
[0007] Read the privacy configuration corresponding to the device type to obtain the first privacy region in the privacy configuration;
[0008] Based on the first privacy region, the coordinates of the privacy region of the monitoring device are obtained;
[0009] Based on the coordinates of the privacy region, the video stream is encrypted to obtain the encrypted target video frame.
[0010] In one possible implementation, reading the privacy configuration corresponding to the device type to obtain the first privacy region corresponding to the privacy configuration includes:
[0011] Determine whether the monitoring device is a fixed-screen device;
[0012] If it is a fixed screen device, then read the corresponding fixed privacy region in the fixed privacy configuration and use the fixed privacy region as the first privacy region;
[0013] If it is not a fixed-view device, obtain the dynamic privacy configuration and the operating parameters of the monitoring device;
[0014] Read the dynamic privacy region corresponding to the running parameters in the dynamic privacy configuration, and use the dynamic privacy region as the first privacy region.
[0015] In one possible implementation, after reading the dynamic privacy region corresponding to the running parameters in the dynamic privacy configuration, the method further includes:
[0016] If the operating parameters change, obtain the temporary operating parameters after the change;
[0017] Determine whether a second privacy region corresponding to the temporary running parameters exists in the dynamic privacy configuration;
[0018] If it exists, then the second privacy region in the dynamic privacy configuration shall be used as the dynamic privacy region;
[0019] If it does not exist, then read the first region feature value and expected change range corresponding to the running parameters in the dynamic privacy configuration;
[0020] Acquire the device screen before the operating parameters change, and acquire the temporary device screen after the operating parameters change;
[0021] Calculate the feature value of the second region of the temporary screen of the device;
[0022] By comparing the feature values of the first region and the feature values of the second region, a privacy similarity value between the device screen and the temporary device screen is obtained;
[0023] If the privacy similarity value exceeds the expected range of change, the second privacy region is calculated based on the second region feature value, and the second privacy region is used as the dynamic privacy region.
[0024] In one possible implementation, after calculating the second privacy region based on the second region feature value, the method further includes:
[0025] The temporary operating parameters, the second privacy region corresponding to the temporary operating parameters, and the feature value of the second region are added to the dynamic privacy configuration.
[0026] In one possible implementation, before reading the dynamic privacy configuration and the first region feature value and expected change range corresponding to the running parameters, the method further includes:
[0027] Based on the equipment type and the operating parameters, determine the expected range of variation;
[0028] Based on the coordinates of the privacy region, calculate the feature value of the first region;
[0029] The first region feature value and the expected range of change are added to the dynamic privacy configuration.
[0030] In one possible implementation, encrypting the video stream based on the privacy region coordinates to obtain the encrypted target video frame includes:
[0031] Determine whether the monitoring device has video data processing capabilities;
[0032] If available, the video stream is encrypted using the monitoring equipment.
[0033] If not, the video stream is sent to the encryption server to complete the encryption of the video stream.
[0034] In one possible implementation, after obtaining the encrypted target video frame, the method further includes:
[0035] The unencrypted video stream is stored to obtain the original video;
[0036] When a viewing request for the original video is received from a viewing device, the viewing device type of the viewing device is determined;
[0037] If the device being viewed is a dedicated device, then determine whether the device has passed the device self-test;
[0038] If the request fails, a command to check if the device needs repair is sent to the maintenance system.
[0039] After receiving the signal that the maintenance is complete, re-evaluate whether the device has passed the self-test.
[0040] If successful, an instruction to start the operation record and recording is sent to the viewing device, and the two-factor verification rule corresponding to the original video is obtained;
[0041] If the viewing request passes the two-factor authentication rule, the dedicated viewing device is allowed to view the original video.
[0042] Secondly, a privacy video encryption device is provided, comprising:
[0043] The acquisition module is used to acquire the device type of the monitoring device and the video stream captured by the monitoring device.
[0044] The reading module is used to read the privacy configuration corresponding to the device type and obtain the first privacy region corresponding to the privacy configuration.
[0045] The calculation module is used to obtain the coordinates of the privacy area of the monitoring device based on the first privacy area;
[0046] An encryption module is used to encrypt the video stream based on the coordinates of the privacy region to obtain the encrypted target video frame.
[0047] Thirdly, an apparatus is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the aforementioned encryption method for privacy videos.
[0048] Fourthly, a computer-readable storage medium is provided, the computer-readable storage medium storing a computer program, which, when executed by a processor, implements the above-described encryption method for privacy videos.
[0049] The aforementioned encryption method, apparatus, device, and storage medium for privacy videos first obtain the device type of the monitoring device and directly acquire the video stream captured by the monitoring device for subsequent encryption. Next, the privacy configuration corresponding to the device type is read to obtain the first privacy region within the privacy configuration. Then, the coordinates of the privacy region of the monitoring device are obtained based on the first privacy region. Finally, the video stream is encrypted based on the privacy region coordinates to obtain the encrypted target video frame. Different privacy requirements are configured according to different device types to ensure that different device types correspond to different privacy regions. When encrypting the video stream, the corresponding privacy configuration can be obtained through the device type, and then target video frames encrypted in different ways can be generated according to different privacy requirements. These target video frames form the video data displayed on the real-time viewing device, allowing video surveillance personnel to only monitor or view the encrypted video data, effectively protecting privacy data and preventing the harm caused by privacy video leakage. Attached Figure Description
[0050] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0051] Figure 1 This is a schematic diagram of an application environment for a privacy video encryption method according to an embodiment of the present invention;
[0052] Figure 2 This is a flowchart of a privacy video encryption method according to an embodiment of the present invention;
[0053] Figure 3 This is a schematic diagram of another application environment of the encryption method for privacy videos in one embodiment of the present invention;
[0054] Figure 4 This is a schematic diagram of an encryption device for privacy videos according to an embodiment of the present invention;
[0055] Figure 5 This is a schematic diagram of a device in one embodiment of the present invention. Detailed Implementation
[0056] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0057] The privacy video encryption method provided in this embodiment of the invention can be applied to, for example... Figure 1 The application environment shown. Specifically, this privacy video encryption method is applied in video surveillance equipment, which can be used with, for example... Figure 1 The viewing device shown is used to display the encrypted target video frames, thus providing real-time monitoring footage to surveillance personnel. The monitoring device refers to various devices capable of acquiring video data, including but not limited to pan-tilt / zoom cameras, PTZ cameras, and cameras with intelligent analysis capabilities. The viewing device includes, but is not limited to, various personal computers, laptops, smartphones, tablets, and portable wearable devices.
[0058] In one embodiment, such as Figure 2 As shown, a method for encrypting private videos is provided, which can be applied to... Figure 1Taking the monitoring equipment in the example, the following steps are included:
[0059] S10: Obtain the device type of the monitoring device and obtain the video stream captured by the monitoring device.
[0060] When capturing video streams, monitoring equipment simultaneously acquires its device type. Monitoring equipment refers to any device capable of acquiring images of its surroundings, including but not limited to video surveillance equipment and computers with cameras. Device type refers to the classification of equipment based on its location, usage, performance, characteristics, and operating parameters. Device types can be categorized as devices requiring or not requiring privacy protection, devices without pan / tilt / zoom cameras or with pan / tilt / zoom cameras, and monitoring equipment with or without intelligent analysis capabilities. No specific definition is provided here regarding how device types are distinguished. Furthermore, the video stream captured by the monitoring equipment refers to the real-time data traffic captured by the monitoring equipment per unit of time. This real-time data traffic can ultimately form real-time video frames, i.e., real-time video footage. This video stream includes, but is not limited to, raw streams and encoded data streams.
[0061] S20: Read the privacy configuration corresponding to the device type to obtain the first privacy region corresponding to the privacy configuration.
[0062] Before the monitoring equipment is put into operation, corresponding privacy configurations can be pre-set according to different equipment types. Each equipment type has a corresponding privacy configuration. After the monitoring equipment is running, the pre-set privacy configuration is read based on the equipment type to obtain the first privacy area corresponding to the current monitoring equipment. The privacy configuration refers to the privacy protection configuration content corresponding to the monitoring equipment, used to set the privacy protection area of the device screen, calculate the privacy area feature value, and the expected range of changes in the device screen, etc. Therefore, the content of the privacy configuration includes, but is not limited to, the equipment type of the monitoring equipment, the operating parameters of the monitoring equipment, the privacy protection area, the privacy protection area feature value, and the expected range of changes. The device screen refers to the overall screen area captured by the monitoring equipment, generally representing the overall area of the video screen visible on the final monitoring viewing device.
[0063] In this privacy configuration, the operating parameters of the monitoring device refer to the relevant parameters of the video captured by the monitoring device, including but not limited to the focal length, angle, distance, and preset position of the monitoring device. The privacy-protected area refers to the range that can completely cover the content that needs privacy protection, including but not limited to various shapes such as rectangles, circles, and polygons. The area feature value refers to the image feature value of the area in the device screen that needs privacy protection. This feature value includes but is not limited to image reduction features, image dimensionality reduction features, image pixel value and mean comparison features, image subtraction features, geometric features, local binary pattern features, etc. This feature value can be represented by hash values or matrices, which is not limited here. The calculation methods for area feature values include but are not limited to HOG (Histogram of Oriented Gradient) features, LBP (Local Binary Pattern), Haar features, etc.
[0064] In addition, the expected range of change refers to the degree of change in the video image generated before and after the change when the operating parameters of the monitoring equipment change. This expected range of change can include one or more, and different expected ranges of change can be set according to the equipment type and operating parameters.
[0065] After determining the privacy configuration corresponding to the monitoring device, the first privacy region corresponding to the current monitoring device is read from the privacy configuration. The first privacy region refers to the range of the video stream captured by the current monitoring device that needs privacy protection, and can form a variety of different shapes of masking regions in the final generated video frame.
[0066] It should be noted that in this embodiment, the first privacy region is divided according to the different locations of the device or the performance of the device, so that the division of the first privacy region is more in line with the usage scenario and performance of the device, and the occlusion area of the final generated target video frame is more reasonable.
[0067] S30: Based on the first privacy area, obtain the coordinates of the privacy area of the monitoring device.
[0068] After determining the first privacy area, a privacy coordinate set corresponding to the first privacy area is determined. The privacy coordinate set refers to the set of coordinates of the privacy area on the device screen. This set of coordinates identifies the coordinate position of the first privacy area in a coordinate system with the device screen as the coordinate system. The privacy coordinate set consists of the coordinates of one or more vertices of the first privacy area; the coordinate system can be a planar coordinate system with any position on the device screen as the origin. For example, if the current first privacy area is a rectangular block, the coordinates of the four vertices of the rectangular block, or several vertices that can identify the rectangular block, are recorded sequentially. These coordinate sets are the privacy area coordinates of the monitoring device.
[0069] It should be noted that by using coordinate groups to mark the first privacy region, the target video frame is encrypted only within the defined privacy region, without excessively obscuring the normal video footage.
[0070] S40: Based on the coordinates of the privacy region, encrypt the video stream to obtain the encrypted target video frame.
[0071] Once the coordinates of the privacy region are determined, the coordinates in the privacy coordinate group are connected sequentially to mark the first privacy region in the video stream.
[0072] For example, if the first privacy region is a rectangular region, then the coordinates of the privacy region are, for example, the coordinates of the top left corner (x1, y1) and the coordinates of the bottom right corner (x2, y2). If the first privacy region is a polygon, then a set of detailed coordinates is recorded. This set of coordinates is recorded sequentially according to the vertices of the polygon when the region was defined, and then connected in order to form the polygon.
[0073] Next, the tagged video stream is encrypted to obtain the encrypted target video frame. The target video frame refers to the real-time video frame ultimately displayed on the monitoring device; consecutive target video frames constitute the final real-time video presented on the monitoring device. The encryption method involves encrypting the video stream located in the first privacy zone to obtain the encrypted target video frame. This encrypted target video frame is presented on the monitoring device as the privacy-processed video image. Encrypting the first privacy zone prevents simple masking of the video data from being reverse-engineered and leaked. Encryption makes the final generated target video data more secure.
[0074] It should be noted that this embodiment directly acquires the video stream captured by the monitoring device for subsequent encryption. Different privacy requirements are configured according to different device types to ensure that different device types correspond to different privacy zones. When encrypting the video stream, the corresponding privacy configuration can be obtained through the device type. Then, based on different privacy requirements, target video frames encrypted in different ways can be generated. These target video frames form the video data displayed on the real-time viewing device, allowing video surveillance personnel to only monitor or view the encrypted video data, effectively protecting privacy data and preventing the harm caused by the leakage of private video.
[0075] In one embodiment, step S20, namely reading the privacy configuration corresponding to the device type and obtaining the first privacy region corresponding to the privacy configuration, specifically includes the following steps:
[0076] S21: Determine whether the monitoring device is a fixed-screen device.
[0077] S22: If it is the fixed screen device, then read the corresponding fixed privacy region in the fixed privacy configuration and use the fixed privacy region as the first privacy region.
[0078] S23: If it is not the fixed screen device, obtain the dynamic privacy configuration and the operating parameters of the monitoring device.
[0079] S24: Read the dynamic privacy region corresponding to the running parameters in the dynamic privacy configuration, and use the dynamic privacy region as the first privacy region.
[0080] In one embodiment, it is determined whether the monitoring device needs to provide privacy protection. If privacy protection is not required, the unencrypted target video frame is directly output. If privacy protection is required, it is determined whether the monitoring device's screen is fixed, i.e., whether the monitoring device is a fixed-screen device.
[0081] If the monitoring device is a fixed-view device, meaning it cannot adjust operating parameters such as zoom or angle, then the view will not change. Therefore, it's only necessary to obtain the corresponding fixed privacy configuration and read the corresponding fixed privacy area from it. Since the view will not change, the fixed privacy area will also remain unchanged and does not need to be retrieved again subsequently.
[0082] If the monitoring device is not a fixed-view device, meaning it will manipulate operational parameters such as zooming and angle adjustment of the screen, then it's necessary to obtain the dynamic privacy configuration to identify the primary privacy region for the monitoring device. Simultaneously, the device's operational parameters need to be acquired to monitor changes in these parameters. When the monitoring device's operational parameters change, the corresponding privacy region needs to be re-read from the dynamic privacy configuration based on the updated parameters.
[0083] Both fixed and dynamic privacy configurations fall under the category of privacy settings. The difference lies in their settings: fixed privacy configurations only set different privacy profiles based on the device type, while dynamic privacy configurations, after setting corresponding privacy profiles for different device types, also configure specific privacy regions within each profile based on different operating parameters. Therefore, fixed privacy regions remain unchanged if the device type remains the same, while dynamic privacy regions will change based on different operating parameters even with the same device type.
[0084] In another embodiment, the device type of the monitoring device can also be set according to different locations. For example, privacy configurations corresponding to open locations can be set in more open locations, and privacy configurations corresponding to private locations can be set in more private locations.
[0085] It should be noted that by setting different privacy configurations based on changes in the monitoring equipment, different privacy zones can be obtained. This allows for the generation of target video frames encrypted with different privacy zones, depending on the location and fixed status of the monitoring equipment. This makes the encryption of privacy videos more tailored to different privacy needs and equipment conditions, making it more practical and improving the accuracy and precision of privacy video encryption.
[0086] In one embodiment, after step S24, that is, after reading the dynamic privacy region corresponding to the running parameters in the dynamic privacy configuration, the encryption method for the privacy video further includes the following steps:
[0087] S51: If the operating parameters change, obtain the temporary operating parameters after the change.
[0088] S52: Determine whether a second privacy region corresponding to the temporary running parameters exists in the dynamic privacy configuration.
[0089] S53: If it exists, then the second privacy region in the dynamic privacy configuration shall be used as the dynamic privacy region.
[0090] S54: If it does not exist, then read the first region feature value and expected change range corresponding to the running parameters in the dynamic privacy configuration.
[0091] S55: Obtain the device screen before the change of the operating parameters, and obtain the temporary device screen after the change of the operating parameters.
[0092] S56: Calculate the feature value of the second region of the temporary screen of the device;
[0093] S57: Compare the feature values of the first region and the feature values of the second region to obtain the privacy similarity value between the device screen and the temporary device screen;
[0094] S58: If the privacy similarity value exceeds the expected change range, the second privacy region is calculated based on the second region feature value, and the second privacy region is used as the dynamic privacy region.
[0095] In one embodiment, after step S24, that is, after obtaining the dynamic privacy area of the monitoring device, it is necessary to monitor the operating parameters of the monitoring device in real time, that is, whether the device screen changes. If the device screen changes, it is necessary to determine the second area feature value of the screen before and after the change based on the difference of the screen and the first area feature value of the original screen, so as to determine whether to generate a new privacy area to ensure the security of the privacy video.
[0096] Because the dynamic privacy configuration may not contain the second region feature value and the second privacy region corresponding to the temporary operating parameters, it is necessary to determine whether the second privacy region exists in the dynamic privacy configuration after the operating parameters change. If it does not exist, the feature value needs to be calculated by monitoring the current operation of the device to determine the second privacy region.
[0097] Specifically, when the operating parameters change, the temporary operating parameters after the change are first obtained. The temporary device screen refers to the screen obtained after the operating parameters change, that is, the screen corresponding to the temporary operating parameters. Then, it is determined whether there is a second privacy region corresponding to the temporary operating parameters in the dynamic privacy configuration. If it exists, the second privacy region is directly used as the dynamic privacy region; if it does not exist, firstly, according to the dynamic privacy configuration, the first region feature value and expected change range corresponding to the dynamic privacy region are read. The first region feature value refers to the image feature of the privacy region in the video data, that is, the feature region value described in step S20. The expected change range refers to the expected change degree of the region feature value before and after the screen change. Secondly, in step S55, after the operating parameters change, the temporary device screen after the device screen change is obtained. Here, the change in device screen refers to the change in the video screen caused by the operating parameters of the monitoring device, including but not limited to changes in the focal length or angle of the video screen or changes in the preset position of the monitoring device.
[0098] Next, in step S56, based on the degree of change between the device screen before the change and the temporary device screen after the change, and by comparing the first region feature value in the device screen, the same region block in the temporary device screen as the first privacy region is identified, and the second region feature value of the temporary device screen is calculated. In step S57, the first region feature value and the second region feature value are compared to calculate the privacy similarity value between the device screen and the temporary device screen. The privacy similarity value refers to the difference in image features between the first privacy region and the second privacy region. Methods for calculating the privacy similarity value include, but are not limited to, cosine similarity, hash algorithms, histograms, and structural similarity measures.
[0099] Finally, in step S57, after obtaining the privacy similarity value, it is determined whether the calculated privacy similarity value exceeds the expected range of change. If it does not exceed the expected range of change, there is no need to reprocess the temporary image of the device; if it exceeds the expected range of change, the second privacy region is calculated based on the second region feature value. The second privacy region of the video stream is then re-encrypted to obtain the target video frame. The step of encrypting based on the second privacy region after exceeding the expected range of change is referred to steps S30-S40.
[0100] In another embodiment, the expected range of change in step S54 will be obtained from the privacy configuration. The expected range of change set in the privacy configuration is determined based on the device type and operating parameters of the monitoring device. Different types of monitoring devices and different change methods will yield different expected ranges of change.
[0101] It's important to note that detecting the operating parameters of monitoring equipment allows for timely monitoring of changes to the device interface, enabling prompt adjustments to privacy areas. This ensures that even with changes in the view, there are still suitable privacy areas to obscure the image, better preventing privacy leaks. Furthermore, since privacy configurations are pre-set based on device type and operating parameters, some settings may be overlooked in certain situations. For example, if the current operating parameters of the monitoring device are not set in the privacy configuration, calculations must be performed when the corresponding privacy area cannot be found to complete subsequent operations. Additionally, performing similarity comparisons after image changes allows for the avoidance of re-acquiring different privacy areas if the similarity is high, saving computational resources and improving device performance.
[0102] In another embodiment, after step S58, in order to ensure the accuracy of the calculated second privacy area, after determining the second privacy area, it is also necessary to verify and confirm that the privacy area conforms to the device type and operating parameters of the monitoring device, so as to ensure that the second privacy area can accurately meet the privacy protection requirements of the device's temporary screen, thereby ensuring the accuracy of the privacy area.
[0103] In one embodiment, after step S58, that is, after calculating the second privacy region based on the second region feature value, the encryption method for the privacy video further includes the following steps:
[0104] S61: Add the temporary operating parameters, the second privacy region corresponding to the temporary operating parameters, and the feature value of the second region to the dynamic privacy configuration.
[0105] In one embodiment, after the second privacy region is calculated, it is saved into a dynamic privacy configuration based on the correspondence between temporary operating parameters, the second privacy region, and the feature value of the second region. Subsequent privacy similarity calculations and related encryption calculations can be completed by reading the second privacy region and the feature value of the second region from the dynamic privacy configuration.
[0106] It should be noted that adding the calculation results to the privacy configuration allows the corresponding privacy area to be read based on the privacy configuration if the same running parameters occur in the future, reducing the computing power consumption of the device and improving the overall encryption efficiency.
[0107] In one embodiment, before step S54, that is, before reading the first region feature value and expected change range corresponding to the running parameters in the dynamic privacy configuration, the encryption method for the privacy video further includes the following steps:
[0108] S71: Determine the expected range of variation based on the equipment type and the operating parameters.
[0109] S72: Calculate the feature value of the first region based on the coordinates of the privacy region.
[0110] S73: Add the first region feature value and the expected range of change to the dynamic privacy configuration.
[0111] In one embodiment, the expected range of change is determined based on the device type and operating parameters. A first region feature value is calculated based on a first privacy region, and then the first region feature value and the expected range of change are added to the dynamic privacy configuration.
[0112] Specifically, the expected range of variation can be defined based on different device types. For example, when device types are categorized according to location, monitoring equipment installed in more open locations has a larger expected range of variation, while monitoring equipment installed in more private locations has a smaller expected range of variation. Within the same device type, different expected ranges of variation can be defined based on different operating parameters. For example, when the device adjustment angle is less than 10, the expected range of variation is smaller; if the device adjustment angle is greater than 10, the expected range of variation is larger. Furthermore, by pre-calculating the characteristic values of privacy areas and pre-storing these corresponding configurations in the privacy configuration, it is unnecessary to recalculate the characteristic values and expected range of variation every time the operating parameters change, thus saving on device performance overhead.
[0113] It's important to note that using changes in the video feed across different locations and devices as the basis for device type classification, and setting different expected change ranges for each device type, allows monitoring devices to determine different encryption levels based on varying privacy requirements. In more open locations, the requirements for encryption precision and privacy zone definition are lower; therefore, minor changes will not require re-encryption of the video feed, and a larger expected change range can be set. Conversely, in more private locations, the requirements for encryption precision and privacy zone definition are higher; therefore, even minor changes will necessitate re-encryption of the video feed.
[0114] In one embodiment, in addition to setting corresponding privacy configurations based on the device type of the monitoring equipment, privacy configurations are also set for each operating parameter under the same device type, based on different operating parameters. These operating parameters refer to the focal length or angle of the monitoring equipment, different preset positions, and zoom parameters, etc. Thus, when the device's image changes, the privacy configuration corresponding to the temporary operating parameters is directly obtained, and the corresponding privacy area and other relevant content are read from the newly obtained privacy configuration. For example, different privacy areas are defined based on the preset positions of different devices, and the correspondence between the privacy areas and the preset positions is recorded in the privacy configuration. Here, a preset position can be understood as a corresponding privacy area for each preset position the monitoring equipment adjusts to. In one embodiment, all preset positions can be exhaustively enumerated to obtain the corresponding privacy areas, and all of them can be recorded in the privacy configuration to achieve encryption of the privacy video.
[0115] It should be noted that in this embodiment, the expected range of change is set differently based on the device type and operating parameters. This is because the accuracy requirements for privacy protection vary in different locations, i.e., with different device types, thus necessitating different expected ranges of change. In scenarios with high accuracy requirements, the expected range of change is smaller. This ensures that even minor changes to the device screen will trigger a recalculation of the privacy area based on the monitoring device type and operating parameters, improving the accuracy of privacy protection. Conversely, in scenarios with lower accuracy requirements, the expected range of change is larger. This ensures that only significant changes to the device screen will trigger a recalculation of the privacy area based on the monitoring device type and operating parameters, preventing multiple recalculations of the privacy area due to screen changes in scenarios with lower accuracy requirements, thus saving on the performance overhead of the monitoring device.
[0116] In one embodiment, in step S40, i.e., encrypting the video stream based on the coordinates of the privacy region to obtain the encrypted target video frame, the monitoring device can also communicate with the encryption server via the network. The encryption server can be implemented using a standalone server or a server cluster composed of multiple servers, specifically including the following steps:
[0117] S41: Determine whether the monitoring device has video data processing capabilities.
[0118] S42: If available, the video stream is encrypted using the monitoring equipment.
[0119] S43: If not, the video stream is sent to the encryption server to complete the encryption of the video stream.
[0120] In one embodiment, it is determined whether the monitoring device has the ability to process video data, that is, whether the monitoring device has computing power or can load intelligent analysis capabilities.
[0121] If the monitoring equipment has video data processing capabilities, then the privacy area is encrypted within the monitoring equipment, and the target video data and the unencrypted original video data are stored in the monitoring equipment. This means that feature value comparison and privacy area encryption are pre-installed in the monitoring equipment. The video stream, original recording, and the generated encrypted video stream and encrypted recording are stored in the monitoring equipment for subsequent program access or retrieval. If the monitoring equipment layout lacks data processing capabilities, then only the video stream and original recording are stored in the monitoring equipment. Feature comparison and privacy area encryption are performed by the corresponding encryption server. The monitoring equipment only needs to transmit the video stream to the corresponding server to complete the video data encryption.
[0122] It should be noted that steps S41-S43 are to prevent the current monitoring equipment from not having enough computing power, so the encryption process is transferred to the encryption server, which improves the efficiency of the overall encryption process.
[0123] In one embodiment, after step S40, i.e., after obtaining the encrypted target video frame, it can be compared with, for example... Figure 3 The maintenance system shown communicates via a network to handle self-test anomalies of the viewing equipment. The viewing equipment includes a camera to capture and record the personnel using the equipment and their actions. The encryption method for this private video also includes the following steps:
[0124] S81: Store the unencrypted video stream to obtain the original video.
[0125] S82: When a viewing request for the original video is received from a viewing device, determine the viewing device type of the viewing device.
[0126] S83: If the type of the device being viewed is a dedicated device, then determine whether the device being viewed has passed the device self-test.
[0127] S84: If the request fails, send the instruction to the maintenance system indicating that the device needs maintenance.
[0128] S85: After receiving the signal that the maintenance is completed, re-determine whether the device has passed the device self-test.
[0129] S86: If successful, send an instruction to the viewing device to start the operation record and video recording, and obtain the two-factor verification rule corresponding to the original video.
[0130] S87: If the viewing request passes the verification of the two-factor validation rule, then the dedicated viewing device is allowed to view the original video.
[0131] To ensure the security of private video data, in steps S81-S87, viewing devices capable of viewing real-time video data are divided into two types: ordinary devices and dedicated devices. Ordinary devices refer to those accessible to general monitoring personnel, such as property control rooms and video walls. Therefore, ordinary devices only allow viewing of video frames composed of encrypted target video frames and video transmitted by devices that do not require privacy protection. Dedicated devices, on the other hand, refer to devices specifically designed for viewing video streams, including camera units—that is, the unencrypted raw video. After initiating a request to view the video stream, a dedicated device will activate its own camera unit according to the instructions returned by the monitoring equipment to authenticate the user and record the operation.
[0132] Specifically, when the monitoring equipment receives a request to view the video stream, it determines the type of device from which the request originates. If the request does not originate from a dedicated device, the viewing request is rejected, and the monitoring equipment returns a "reject viewing" command to the viewing device, prohibiting the transmission of the video stream. If the request originates from a dedicated device, a command to start operation logging and recording is sent to that dedicated device. Upon receiving the start command, the viewing device activates its camera to record the operator's operation log and record the operation. Simultaneously with sending the start command, the monitoring equipment obtains the two-factor authentication rules for the video stream from the viewing device to determine whether to transmit the video stream. If the operator fails the two-factor authentication, the monitoring equipment rejects the viewing request, returns a "reject" command to the viewing device, and prohibits the transmission of the original video data. If the operator passes the two-factor authentication, the monitoring equipment responds to the viewing request and transmits the video stream to the dedicated device.
[0133] Two-factor authentication (2FA) refers to an additional layer of identity verification beyond account login, ensuring that the person currently operating the dedicated viewing device is the only authorized user. It is an effective means of protecting the security of private videos. 2FA is an account verification process that, as the name suggests, requires a second verification factor to verify the user's login credentials in addition to the username and static password. This includes, but is not limited to, randomly generating a one-time password and sending it to the corresponding mobile phone via SMS gateway for secondary verification, or using a personal token to generate a time-based dynamic password (TOTP) for verification. For example, a dynamic verification code can be randomly generated every 60 seconds by the personal token.
[0134] In one embodiment, during steps S83-85, the dedicated device performs periodic self-checks. The self-check cycle can be hourly or daily, with no limitation here. The self-check determines whether the dedicated device is functioning correctly, whether its corresponding camera is operating properly, etc., to prevent the leakage of private videos due to damage to the dedicated device or human intervention. For example, a device self-check can be initiated every 3 hours.
[0135] Specifically, such as Figure 3 As shown, the monitoring equipment determines whether the dedicated equipment has passed its self-test. If it fails the self-test, the monitoring equipment sends a repair instruction to the maintenance system. Upon receiving the repair instruction, the maintenance system assigns maintenance personnel to repair the equipment. After the maintenance personnel complete the repair, the maintenance system sends a repair completion signal to the monitoring equipment. After receiving the repair completion signal, the monitoring equipment re-determines whether the equipment has passed its self-test. If it passes the self-test, steps S86-S87 are executed. If it still fails the self-test, steps S84-S85 are repeated.
[0136] It should be noted that, to better protect private videos, when there is a special need to view the original video data, the monitoring equipment will detect whether the other party is using a dedicated device, monitor the entire process of viewing the original video, and record it accordingly. This ensures the safe viewing of private videos and prevents video leakage. In addition, the viewing device will perform regular self-checks and conduct two-factor authentication for relevant personnel to prevent video leakage due to equipment or personnel malfunctions, thus enhancing the security of private videos.
[0137] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0138] In one embodiment, a privacy video encryption device is provided, which corresponds one-to-one with the privacy video encryption methods described in the above embodiments. For example... Figure 4 As shown, the encryption device for this private video includes an acquisition module 10, a reading module 20, a calculation module 30, and an encryption module 40. Detailed descriptions of each functional module are as follows:
[0139] The acquisition module 10 is used to acquire the device type of the monitoring device and the video stream captured by the monitoring device.
[0140] Reading module 20 is used to read the privacy configuration corresponding to the device type and obtain the first privacy region corresponding to the privacy configuration;
[0141] The calculation module 30 is used to obtain the coordinates of the privacy area of the monitoring device based on the first privacy area;
[0142] The encryption module 40 is used to encrypt the video stream based on the coordinates of the privacy region to obtain the encrypted target video frame.
[0143] Specific limitations regarding encryption devices for privacy videos can be found in the above description of encryption methods for privacy videos, and will not be repeated here. Each module in the aforementioned encryption device for privacy videos can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the corresponding operations of each module.
[0144] In one embodiment, a computer device is provided, which may be a video surveillance device, and its internal structure diagram may be as follows: Figure 5As shown, the computer device includes a processor, memory, network interface, database, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The database stores unencrypted video stream recordings and target video frame recordings. The network interface communicates with viewing devices and encryption servers via a network connection. When executed by the processor, the computer program implements a privacy video encryption method.
[0145] In one embodiment, a viewing device is provided, which may be a terminal. The computer device includes a processor, memory, a network interface, a display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The network interface is used to communicate with video surveillance equipment via a network connection. When the computer program is executed by the processor, it implements a method for encrypting private video.
[0146] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to perform the following steps:
[0147] Obtain the device type of the monitoring device and the video stream captured by the monitoring device;
[0148] Read the privacy configuration corresponding to the device type to obtain the first privacy region in the privacy configuration;
[0149] Based on the first privacy region, the coordinates of the privacy region of the monitoring device are obtained;
[0150] Based on the coordinates of the privacy region, the video stream is encrypted to obtain the encrypted target video frame.
[0151] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, the computer program performing the following steps when executed by a processor:
[0152] Obtain the device type of the monitoring device and the video stream captured by the monitoring device;
[0153] Read the privacy configuration corresponding to the device type to obtain the first privacy region in the privacy configuration;
[0154] Based on the first privacy region, the coordinates of the privacy region of the monitoring device are obtained;
[0155] Based on the coordinates of the privacy region, the video stream is encrypted to obtain the encrypted target video frame.
[0156] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0157] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is used as an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.
[0158] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.
Claims
1. A method for encrypting private videos, characterized in that, include: Obtain the device type of the monitoring device and the video stream captured by the monitoring device; Read the privacy configuration corresponding to the device type to obtain the first privacy region corresponding to the privacy configuration; wherein, the privacy configuration includes the device type of the monitoring device, the operating parameters of the monitoring device, the privacy protection region, the feature value of the privacy protection region, and the expected change range, wherein, the expected change range is the degree of change of the video image generated before and after the change when the operating parameters of the monitoring device change, and the expected change range includes one or more. Based on the first privacy region, the coordinates of the privacy region of the monitoring device are obtained; The first privacy region is marked in the video stream based on the coordinates of the privacy region, resulting in the marked video stream; The marked video stream is encrypted to obtain the encrypted target video frame; The step of reading the privacy configuration corresponding to the device type to obtain the first privacy region corresponding to the privacy configuration includes: Determine whether the monitoring device is a fixed-screen device, wherein a fixed-screen device is a device whose operating parameters cannot be manipulated on the device screen; If it is a fixed screen device, then read the corresponding fixed privacy region in the fixed privacy configuration and use the fixed privacy region as the first privacy region; If it is not a fixed-view device, obtain the dynamic privacy configuration and the operating parameters of the monitoring device; Read the dynamic privacy region corresponding to the running parameters in the dynamic privacy configuration, and use the dynamic privacy region as the first privacy region; The method further includes, after reading the dynamic privacy region corresponding to the running parameters in the dynamic privacy configuration, the method also includes: If the operating parameters change, obtain the temporary operating parameters after the change; Determine whether a second privacy region corresponding to the temporary running parameters exists in the dynamic privacy configuration; If it exists, then the second privacy region in the dynamic privacy configuration shall be used as the dynamic privacy region; If it does not exist, then read the first region feature value and expected change range corresponding to the running parameters in the dynamic privacy configuration, where the expected change range is the expected change degree of the region feature value before and after the device screen changes; Acquire the device screen before the operating parameters change, and acquire the temporary device screen after the operating parameters change; Calculate the feature value of the second region of the temporary screen of the device; By comparing the feature values of the first region and the feature values of the second region, a privacy similarity value is obtained between the device screen and the temporary device screen. The privacy similarity value is the difference in image features between the first privacy region and the second privacy region. If the privacy similarity value exceeds the expected change range, the second privacy region is calculated based on the second region feature value, and the second privacy region is used as the dynamic privacy region; After obtaining the encrypted target video frame, the method further includes: The unencrypted video stream is stored to obtain the original video; When a viewing request for the original video is received from a viewing device, the viewing device type of the viewing device is determined; If the device being viewed is a dedicated device, then determine whether the device has passed the device self-test; If the request fails, a command to check if the device needs repair is sent to the maintenance system. After receiving the signal that the maintenance is complete, re-evaluate whether the device has passed the self-test. If successful, an instruction to start the operation record and recording is sent to the viewing device, and the two-factor verification rule corresponding to the original video is obtained; If the viewing request passes the two-factor authentication rule, the dedicated device is allowed to view the original video.
2. The encryption method for privacy videos as described in claim 1, characterized in that, After calculating the second privacy region based on the second region feature value, the method further includes: The temporary operating parameters, the second privacy region corresponding to the temporary operating parameters, and the feature value of the second region are added to the dynamic privacy configuration.
3. The encryption method for privacy videos as described in claim 1, characterized in that, Before reading the first region feature value and expected change range corresponding to the running parameters in the dynamic privacy configuration, the method further includes: Based on the equipment type and the operating parameters, determine the expected range of variation; Based on the coordinates of the privacy region, calculate the feature value of the first region; The first region feature value and the expected range of change are added to the dynamic privacy configuration.
4. The encryption method for privacy videos as described in claim 1, characterized in that, The step of encrypting the video stream based on the coordinates of the privacy region to obtain the encrypted target video frame includes: Determine whether the monitoring device has video data processing capabilities; If available, the video stream is encrypted using the monitoring equipment. If not, the video stream is sent to the encryption server to complete the encryption of the video stream.
5. An encryption device for privacy videos, characterized in that, include: The acquisition module is used to acquire the device type of the monitoring device and the video stream captured by the monitoring device. The reading module is used to read the privacy configuration corresponding to the device type and obtain the first privacy region corresponding to the privacy configuration. The calculation module is used to obtain the coordinates of the privacy area of the monitoring device based on the first privacy area; An encryption module is used to encrypt the video stream based on the coordinates of the privacy region to obtain an encrypted target video frame; The reading module is further configured to: Determine whether the monitoring device is a fixed-screen device, wherein a fixed-screen device is a device whose operating parameters cannot be manipulated on the device screen; If it is a fixed screen device, then read the corresponding fixed privacy region in the fixed privacy configuration and use the fixed privacy region as the first privacy region; If it is not a fixed-view device, obtain the dynamic privacy configuration and the operating parameters of the monitoring device; Read the dynamic privacy region corresponding to the running parameters in the dynamic privacy configuration, and use the dynamic privacy region as the first privacy region; The encryption device for the privacy video is further used for: If the operating parameters change, obtain the temporary operating parameters after the change; Determine whether a second privacy region corresponding to the temporary running parameters exists in the dynamic privacy configuration; If it exists, then the second privacy region in the dynamic privacy configuration shall be used as the dynamic privacy region; If it does not exist, then read the first region feature value and expected change range corresponding to the running parameters in the dynamic privacy configuration, where the expected change range is the expected change degree of the region feature value before and after the device screen changes; Acquire the device screen before the operating parameters change, and acquire the temporary device screen after the operating parameters change; Calculate the feature value of the second region of the temporary screen of the device; By comparing the feature values of the first region and the feature values of the second region, a privacy similarity value is obtained between the device screen and the temporary device screen. The privacy similarity value is the difference in image features between the first privacy region and the second privacy region. If the privacy similarity value exceeds the expected change range, the second privacy region is calculated based on the second region feature value, and the second privacy region is used as the dynamic privacy region; The encryption device for the privacy video is further used for: The unencrypted video stream is stored to obtain the original video; When a viewing request for the original video is received from a viewing device, the viewing device type of the viewing device is determined; If the device being viewed is a dedicated device, then determine whether the device has passed the device self-test; If the request fails, a command to check if the device needs repair is sent to the maintenance system. After receiving the signal that the maintenance is complete, re-evaluate whether the device has passed the self-test. If successful, an instruction to start the operation record and recording is sent to the viewing device, and the two-factor verification rule corresponding to the original video is obtained; If the viewing request passes the two-factor authentication rule, the dedicated device is allowed to view the original video.
6. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the encryption method for the privacy video as described in any one of claims 1 to 4.
7. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the encryption method for the privacy video as described in any one of claims 1 to 4.
Citation Information
Patent Citations
Privacy shielding method and device
CN107820041A
Video data recording device, video data playing device, video data recording method, and video data playing method
US20120008915A1