Method and apparatus for compressing signed media data
By identifying and cutting duplicate data units in the media bitstream and including the fingerprint and digital signature of the data units in the signature unit, the problem of waste of storage and transmission resources is solved, and the secure and efficient storage and transmission of data is achieved.
Patent Information
- Application Number
- CN202211572590.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-12-28
- Filing Date
- 2022-12-08
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2042-12-08
AI Technical Summary
The prior art When storing and transmitting media bit streams, frequent insertion of metadata and duplicate data units leads to waste of storage and communication resources.
By identifying and clipping duplicate data units in the media bitstream, only the necessary data units are retained and the fingerprint and digital signature of the data units are included in the signature unit so that the receiver can verify the integrity and authenticity of the data.
Reduces the storage and transmission overhead of media bitstreams, while ensuring data security and integrity, avoiding significant damage to the original data signature.
Smart Images

Figure CN116366912B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of security arrangements for protecting data from unauthorized activities. It proposes a method and apparatus for storing and verifying signed media data, in particular video data, reducing the use of storage space and / or transmission capacity. Background Art
[0002] An audio bitstream, video bitstream, or other media bitstream may be associated with various types of metadata. Metadata may include documents indicating the time, location, content type, and other conditions of its acquisition, which may contain settings to assist in playback of the media bitstream, information about the media coding format that has been used, or other indications of potential interest to the receiver of the media bitstream. A common practice is to make metadata available to the receiver by periodically inserting data units with metadata into the media bitstream. Due to the open nature of the media bitstream, it is difficult to predict whether the receiver will consume short or long fragments of the bitstream (e.g., play, send, or save a copy of the fragment), as well as the temporal position of the fragment in the bitstream. This causes the producer of the media bitstream to insert data units with metadata at relatively short intervals, even if the metadata they contain has not changed during this period. The inserted data units represent an overhead that consumes unnecessary storage and communication resources.
[0003] Besides metadata, similar problems arise for any kind of repeated data units that a bitstream recipient needs to access only once (so-called need-only-once information). Summary of the invention
[0004] It is an object of the present disclosure to provide methods and apparatus that can be used to reduce overhead in a signed media bitstream that contains repeated data units in addition to general data units and signature units. This object may include, in particular, reducing overhead in certain segments of the media bitstream. It may also include achieving overhead reduction without causing any significant damage to the data security of the original signed media bitstream. Another object of the present disclosure is to achieve overhead reduction without re-signing the media bitstream (i.e., without having to obtain access to cryptographic tools for the original signed media bitstream). Yet another object is to provide methods and apparatus that can be used to verify a media bitstream that has undergone overhead reduction in the manner proposed.
[0005] At least some of these objects are achieved by the invention as defined in the independent claims.
[0006] In a first aspect of the present invention, there is provided a storage device composed of data units I, O, P and signature units S kA method for storing a signed media bitstream composed of a plurality of media bits, wherein a signature unit is associated with one or more nearby data units. As used in the present disclosure, "storage" may relate to permanent, long-term and short-term storage, and even transient storage, such as preparing a digital data file suitable for transmission over a communication network. The signature unit enables a recipient of the media bitstream to verify the media bitstream, i.e., to verify with reasonable confidence that the signature unit has not been altered, and to verify that the data unit is consistent with the signature unit. To this end, each signature unit may include at least one fingerprint derived from the associated data unit and a digital signature of the at least one fingerprint. The consistency of the data unit with the signature unit may include that an independent fingerprint calculation at the recipient side will generate a fingerprint that is identical to the fingerprint in the signature unit. The method according to the first aspect comprises: receiving a segment of the media bitstream; identifying N≥2 instances of a repeating data unit O in the received segment; pruning up to N-1 instances of the identified instances of the repeating data unit; and storing the received segment after pruning.
[0007] Because some repeated data units are removed, the size of the fragments of the stored media bitstream will be smaller than the size of the received fragments, which saves memory and communication resources. In addition, because at least one repeated unit is retained in the stored fragments, the recipient's access to metadata is guaranteed. In addition, the inventors have recognized that such a process can be designed by which the recipient can verify the stored fragments of the media bitstream with a security level comparable to that of the received fragments they can verify. This allows the stored fragments to be stored in non-secure storage or shared through non-secure communication channels without introducing new uncertainties about their authenticity or integrity, as long as the verification is successful at the recipient side.
[0008] In a second aspect of the present invention, there is provided a method for verifying a data unit I, O, P and a signature unit S. k A method for storing a segment of a signed media bitstream composed of signature units, wherein signature units are associated with one or more nearby data units. Each signature unit contains at least at least one fingerprint derived from the associated data unit and a digital signature of the at least one fingerprint. The method comprises receiving a stored segment of the media bitstream; and verifying the signature unit using any digital signature contained therein. Then, the received associated data unit is directly or indirectly verified, which can be regarded as a confirmation of the authenticity and / or integrity of the stored segment.
[0009] In one embodiment, at least one signature unit includes: fingerprints of all associated data units, digital signatures of the fingerprints, and secondary digital signatures, the secondary digital signatures being independent of fingerprints of prunable associated data units in the associated data units. In this embodiment, a method includes: receiving a segment of a stored media bitstream; verifying the signature unit using the secondary digital signature; and verifying the received associated data unit against the fingerprint in the verified signature unit.
[0010] In another embodiment, at least one of the signature units includes: a fingerprint of the fingerprints of all associated data units, a secondary fingerprint of the fingerprint, the secondary fingerprint being independent of the fingerprints of the associated data units that may be pruned (recall that the signature unit is typically prepared based on the original media bitstream before any instances of duplicate data units are pruned), and a digital signature of the fingerprint of the fingerprint and a digital signature of the secondary fingerprint of the fingerprint. The verification method includes: receiving a segment of the stored media bitstream; verifying the signature unit using the digital signature; computing the fingerprints of the received associated data units; computing the fingerprint of the computed fingerprint unit; and verifying the computed fingerprint of the fingerprint against the secondary fingerprint of the fingerprint.
[0011] In another embodiment, at least one of the signature units includes: at least one fingerprint of the associated data unit, and a digital signature of the at least one fingerprint. The method then includes: receiving a segment of the stored media bitstream; receiving a pruning log of the stored segment, the pruning log indicating the location of pruned instances of the repeated data unit O in the bitstream; verifying the signature unit using the digital signature; and verifying the received associated data unit relative to the signature unit while ignoring the fingerprints of the missing data units indicated by the pruning log.
[0012] A further development of the embodiment to be described below addresses the case where the at least one fingerprint in the signature unit is the fingerprint of the fingerprints of all associated data units.
[0013] In another embodiment, at least two of the signature units include: fingerprints of all associated data units, and a digital signature of at least one of the fingerprints. The method then suitably includes: receiving a segment of the stored media bitstream; verifying the signature units using the corresponding digital signatures; locating an instance of the repeating data unit O associated with a first signature unit of the signature unit; and verifying the received data unit associated with a second signature unit of the signature unit against the fingerprint in the second signature unit of the signature unit, while ignoring any fingerprint that is consistent with the fingerprint of the located instance of the repeating data unit. Optionally, the embodiment further includes the step of verifying the received data unit associated with the first signature unit of the signature unit against the fingerprint in the first signature unit of the signature unit.
[0014] In yet another embodiment, at least one signature unit comprises: a fingerprint of fingerprints of all associated data units, and a digital signature of the fingerprint of the fingerprint and a digital signature of a secondary fingerprint of the fingerprint. Furthermore, the media bitstream conforms to a format in which the position of the repeated data unit O is fixed (i.e., in the sense of being reproducible at the receiver side). To address this use case, a method comprises: receiving a fragment of a stored media bitstream; verifying the signature unit using the digital signature; computing fingerprints of the received associated data units; computing fingerprints of instances of the repeated data unit that are not associated with the signature unit, and restoring the fingerprint based on the fixed position; computing a fingerprint of the computed fingerprint; and verifying the computed fingerprint of the fingerprint against the fingerprint in the signature unit.
[0015] For a corresponding configuration of the media bitstream format, any of these outlined embodiments ensures that the stored segments of the media bitstream can be verified at the receiver side. Accordingly, the pruning of repeated data units O achieves an overhead reduction without revoking the availability of the signature. The signature-verification chain remains intact.
[0016] In a third aspect of the present invention, a method for generating a signed media bitstream is provided for which data compression is enabled in conjunction with storage of segments of the media bitstream. The method generates a signature unit S consisting of data units I, O, P and associated with one or more nearby data units. k The bit stream is composed of a plurality of signature units, each of which comprises at least one fingerprint derived from an associated data unit and a digital signature of the at least one fingerprint. According to a third aspect, at least one of the signature units comprises:
[0017] (a) fingerprints and secondary signatures of all associated data units, the secondary signatures being independent of the fingerprints of prunable ones of the associated data units, and / or
[0018] (b) The fingerprint of all associated data units and a secondary fingerprint that is independent of the fingerprint of the associated data unit that may be pruned.
[0019] The method supports the execution of the method according to the first aspect and the second aspect. For example, it can be implemented in a video acquisition system.
[0020] The present invention also relates to a device configured to perform the above method, and a computer program comprising instructions for causing a computer to perform these methods. The computer program may be stored or distributed on a data carrier. As used herein, a "data carrier" may be a temporary data carrier, such as a modulated electromagnetic wave or light wave, or a non-temporary data carrier. Non-temporary data carriers include volatile and non-volatile memories, such as permanent and non-permanent storage media of magnetic, optical or solid-state type. Such memory may be fixedly mounted or portable, and still within the scope of a "data carrier".
[0021] Generally, all terms used in the claims are to be interpreted according to their ordinary meaning in the technical field, unless otherwise explicitly defined herein. All references to "one / the element, device, component, means, step, etc." should be interpreted as referring to at least one instance of the element, device, component, means, step, etc., unless otherwise explicitly stated. The steps of any method disclosed herein do not have to be performed in the exact order described, unless explicitly stated. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Various aspects and embodiments will now be described by way of example with reference to the accompanying drawings, in which:
[0023] Figure 1 shows a connection entity exchanging segments of a signed media bitstream;
[0024] Figure 2 is a flow chart of a method for storing a signed media bitstream;
[0025] Figure 3 is a flow chart of a method of verifying a segment of a signed media bitstream;
[0026] Figure 4 The video frame sequence is shown, including the signature unit S 1 , S 2 , S 3 , whose respective contents are shown in the lower part of the figure, and a repeated frame O at a fixed position, embodiment 1A.1 of the present invention is suitable for storing and verifying the video frame sequence;
[0027] Figure 5 The video frame sequence is shown, including the signature unit S 1 , S2 , S 3 , whose respective contents are shown in the lower part of the figure, and a repeated frame O at a fixed position, embodiment 1A.2 of the present invention is suitable for storing and verifying the video frame sequence;
[0028] Figure 6 The video frame sequence is shown, including the signature unit S 1 , S 2 , S 3 , whose respective contents are shown in the lower part of the figure, and a repeated frame O at a fixed position, embodiment 1B of the present invention is suitable for storing and verifying the video frame sequence;
[0029] Figure 7 The video frame sequence is shown, including the signature unit S 1 , S 2 , S 3 , whose respective contents are shown in the lower part of the figure, and a repeated frame O at an arbitrary position, to which embodiment 2A.1 of the present invention is applicable, wherein a data structure LOG is added during storage and is consulted during verification;
[0030] Figure 8 The video frame sequence is shown, including the signature unit S 1 , S 2 , S 3 , whose respective contents are shown in the lower part of the figure, and a repeated frame O at an arbitrary position, Embodiment 2A.2 of the present invention is suitable for storing and verifying the video frame sequence;
[0031] Fig. 9 The video frame sequence is shown, including the signature unit S 1 , S 2 , S 3 , whose respective contents are shown in the lower part of the figure, and a repeated frame O at an arbitrary position, to which embodiment 2B.1 of the present invention is applicable, wherein a data structure LOG is added during storage and is consulted during verification; and
[0032] Fig.10 The video frame sequence is shown, including the signature unit S 1 , S 2 , S 3 , whose respective contents are shown in the lower part of the figure, as well as repeated frames O at arbitrary positions, embodiment 2B.2 of the present invention is suitable for storing and verifying this video frame sequence. DETAILED DESCRIPTION
[0033] Various aspects of the present disclosure will now be described more fully below with reference to the accompanying drawings, in which certain embodiments of the invention are shown. However, these aspects may be implemented in a variety of different forms and should not be construed as limiting; rather, these embodiments are provided by way of example so that the present disclosure will be thorough and complete and fully convey the scope of all aspects of the invention to those skilled in the art. The same reference numerals refer to the same elements throughout the description.
[0034] Methods and apparatus for storing and verifying segments of a media bitstream are valuable in a variety of different contexts and for various types of media data. Figure 1 Connected entities that exchange (eg, store / retrieve, send / receive) segments of a signed media bitstream are shown. Figure 1 A presently contemplated use case is illustrated in which a video acquisition system 110 generates a signed video bitstream, and a first device 120 stores the signed video bitstream in order to make it suitable for use in a channel 130, thereby allowing a recipient to obtain the signed video bitstream. The channel 130 may be comprised of a communication network 131, a portable storage 132, and / or a memory 133. Recall that in some embodiments, the act of "storing" a segment of a bitstream may involve transient storage (such as preparing a digital data file suitable for transmission over the communication network 131) in addition to conventional long-term or short-term storage in the memory 132, 133. The recipient has at its disposal a second device 140 configured to retrieve and verify the stored segment of the video bitstream from the channel 130, and optionally present the video sequence using a playback device 150. Note that, particularly in the use case of storage in the memory 132, 133, the entity performing the video bitstream storage may be consistent with the recipient. In this case, it can be said that when the first device 120 and the second device 140 are consistent, the verification of the video bitstream segment is used to verify that the segment has not been changed after being stored in one of the memories 132, 133.
[0035] More precisely, the video acquisition system 110 includes a camera 111, a metadata insertion stage 112, and a cryptographic element 113. The camera 111 is configured to acquire a video sequence, the output of which is represented as a video bitstream including video data units. At least some of the video data units may correspond to corresponding frames of the video sequence. Such correspondence may require that all data specific to a frame be included in the corresponding video data unit. The video bitstream may further include non-frame data units, such as messages, signature units, or other data structures.
[0036] The camera 111 may be configured to apply various types of data compression (such as lossless or lossy compression), optionally in combination with predictive coding. Before reviewing elements of predictive coding in the next paragraph, it is emphasized that the present invention is applicable to generic media bitstreams (including video bitstreams to which predictive coding is not applied).
[0037] The ability to predict a video frame given past frames depicting a common scene is a basic assumption of predictive coding. Predictive coding can be described as a data compression technique particularly suitable for video data. A fragment of a predictively coded video sequence can consist of I frames and P frames. I frames and P frames cannot be confused with plaintext video frames encoded by these data structures. An I frame is a data structure with independently decodable video data, which can be decoded into a plaintext video frame (or a block of a video frame) by means of predefined associated decoding operations. The P frame itself is a data structure whose associated decoding operations refer not only to the video data of the P frame itself, but also to at least one other I frame or P frame. Conceptually (in short), the video data in a P frame expresses changes or motions relative to the video frame encoded by its previous I frame or P frame. Typically, if the decoding operation is successful, it is impossible to distinguish between video frames decoded from P frames and I frames. An example fragment of a video bitstream may have the following appearance: IPPIPPPPIPPPIPPP. Here, each P frame refers to the I frame or P frame immediately preceding it. If the leading P frame references the previous P frame, then the previous P frame must reference at least one other I frame or P frame. The combination of an I frame and subsequent P frames that directly or indirectly reference the I frame may be referred to as a group of pictures (GOP). In this example, the following GOPs may be identified: IPP, IPPPP, IPPP, and IPPP.
[0038] Two further developments of predictive coding can be illustrated by a second example frame sequence: IBBPBBIBBPBBI. Here, B frames (bidirectionally) reference their nearest I-frame or P-frame neighbors, and each P frame (unidirectionally) references the nearest preceding I-frame. Accordingly, in addition to the forward-predicted P-frame structure, bidirectionally predicted B frames can be used for predictive coding. Potential bidirectional prediction operations may include interpolation (such as smoothing) between reference frames. The second example IBBPBBIBBPBBI further shows that P frames can reference I-frames, P-frames, or B-frames, which do not need to be immediately preceding, but can be located two or more steps away. The segment IBBPBBIBBPBBI of the second example can be characterized as a GOP because it can be decoded without reference to any other I-frame, P-frame, or B-frame. The International Telecommunication Union's recommendation ITU-TH.264 (06 / 2019) "Advanced Video Coding for Generic Audiovisual Services" specifies a video coding standard in which both forward-predicted frames and bidirectionally predicted frames are used.
[0039] Although the same symbols I and P are used for all I frames and P frames in the present disclosure, it should be understood that these frames are not identical copies. Instead, they contain independent video data that may or may not be consistent between frames.
[0040] The metadata insertion stage 112 is configured to insert a data unit O containing metadata applicable to the entire video bitstream. As already mentioned, the metadata may include documentation indicating the time, place and other conditions of the acquisition (start or end) of the video bitstream, which may contain settings for achieving optimal playback, information about the video encoding format that has been used, certificates or (public) keys for verification, or other indications of potential use to the recipient of the video bitstream. As long as none of these indications change, the metadata does not change either, and thus the data unit O can be defined as being repeated. Accordingly, the recipient of the video bitstream can choose to obtain the metadata from any one of the data units O of the recipient's choice. In a running system, there is usually no additional advantage in reading another data unit O from the video bitstream.
[0041] The cryptographic element 113 is configured to 1 , S 2 , S 3 Inserted into the video bitstream. In all embodiments to be described, each signature unit includes at least one fingerprint derived from an associated data unit located before, after or around the signature unit, and a digital signature of the at least one fingerprint. The collection of fingerprints can be referred to as a document. In order to generate a digital signature, the cryptographic element 113 may have stored a private key therein. The recipient can save a public key belonging to the same key pair, which enables the recipient to verify that the signature generated by the cryptographic element 113 is credible, but does not generate a new signature. In the illustrated example, the public key is stored in the cryptographic element 143. The public key can also be included as metadata of the media bitstream, in which case it does not have to be stored at the recipient side. In the ITU-TH.264 format, the signature unit can be included in the video bitstream as a supplementary enhancement information (SEI) message. In the AV1 standard, the signature can be included in the metadata open bitstream unit (OBU).
[0042] Signature Unit S 1 , S 2 , S 3Each of the fingerprints may include a fingerprint of all associated data units, or it may include a fingerprint of the fingerprints of all associated data units. Each of the fingerprints may be a hash or a salted hash. A salted hash may be a hash of a combination of a data unit (or a portion of a data unit) and a cryptographic salt; the presence of a salt may prevent an unauthorized party with access to multiple hashes from guessing what hash function is being used. Potentially available cryptographic salts include the value of an active internal counter, a random number, and the time and place of the signature. The hash may be generated by a hash function (or one-way function) h, which is a cryptographic function that provides a level of security that is considered sufficient, given the sensitivity of the video data to be signed and / or given the value that would be threatened if the video data were manipulated by an unauthorized party. Three examples are SHA-256, SHA3-512, and RSA-1024. The hash function should be predefined (e.g., it should be reproducible) so that the fingerprint can be regenerated when the recipient is about to verify the fingerprint.
[0043] Execution basis Figure 2 The first device 120 for storing the video bitstream segments of the storage method 200 can be any suitable local or distributed processing resource, functionally consisting of a processing circuit 121 and a memory 122. The first device can be a component of a so-called video management system or VMS. In various embodiments, the first device 120 is configured to process a live video bitstream or an offline video bitstream, or both.
[0044] The second device 140 may be implemented as any suitable form of local or distributed processing resource, functionally consisting of a processing circuit 141, a memory 142 and an optional cryptographic element 143, in which the public key is stored. According to any of the embodiments to be described below, the second device 140 is configured to execute Figure 3 Verification method 300.
[0045] As an overview, Table 1 indicates the Figure 2 and Figure 3 Applicability of the embodiments of the storage method 200 and the verification method 300 depicted in FIG.
[0046]
[0047] exist Figure 2 and Figure 3 In the embodiment, the dotted boxes represent optional steps or steps that appear only in certain embodiments. Figure 2 and Figure 3 The order of the steps shown in the drawings is not important. Instead, as will be appreciated by those skilled in the art, the order of certain steps may be modified and / or certain steps may be performed in parallel.
[0048] Example 1A.1
[0049] refer to Figure 4 , consider a media bitstream format containing data units I, P and in which repeated data units O (represented by rectangles) occupy fixed positions. Because the bitstream format specifies such fixed positions, the second device 140 will be able to calculate between which data units in the stored bitstream segments the first device 120 has pruned instances of repeated data unit O (if any). Note that Figure 4 The data units I and P in the associated signature unit S 1 , S 2 , S 3 However, in other embodiments, the data unit I, P may be in the signature unit S 1 , S 2 , S 3 After, or they can be both before and after. Figure 4 It can be seen that the signature unit S 1 , S 2 , S 3 A document containing independent fingerprints (hashes) of associated data units, respectively, and also containing a signature M. The signature unit can be verified at the receiver side using the signature M. Assuming that the media bitstream is a video bitstream, the I and P data units can represent I frames and P frames, and there is one signature unit per GOP.
[0050] Embodiment 1A.1 of the storage method 200 comprises receiving 210 a segment of a media bitstream; identifying 212 N≥2 instances of a repeating data unit O in the received segment; pruning 214 up to N-1 instances of the identified instances of the repeating data unit; and storing 216 the received segment after pruning. It should be understood that the signature unit S 1 , S 2 , S 3 are stored as is, ie in the same state as when they were received 210 .
[0051] The step of receiving 210 the fragment may comprise delivering the fragment in a message sent via a local or external communication network, wherein the communication may be by self-request initiated by an entity different from the entity executing the method 200. "Receiving" in the sense of step 210 may also comprise retrieving the fragment from a memory.
[0052] The step of pruning 214 a plurality of the identified instances of the duplicate data unit O may include deleting the data unit from the segment before the segment is stored. It may also include indirect various types of deletion requests, such as adding markers (flags) to the instances to indicate that they will not be saved and / or transmitted, or that they may be overwritten in memory once stored.
[0053] The step of storing 216 the received fragments after pruning can include instantiating or editing a file, object, database item or another data structure. As already mentioned, it is not necessary for the present invention to maintain the stored fragments in a persistent manner (e.g., in a non-volatile memory). On the contrary, the stored fragments can be short-lived files for upcoming transmission or relaying, which can be discarded thereafter. It is also not necessary to have a file representing the entire fragment at a certain point in time; on the contrary, the network transmission of the early part of the fragment can start before the later part of the fragment is created. This allows the overhead reduction method 200 to be integrated into a processing chain suitable for live streaming and similar applications.
[0054] It can be noted that method 200 can be successfully performed by an entity that is not authorized to generate new digital signatures, i.e., does not need access to a private key. Figure 1 The first device 120 is implemented in.
[0055] Embodiment 1A.1 of verification method 300 includes receiving 310 a segment of a stored media bitstream; verifying 314 a signature unit using a corresponding digital signature; locating 326 an instance of a repeating data unit O associated with a first one of the signature units; verifying 328 the received data unit associated with the first one of the signature units against a fingerprint in the first one of the signature units; and verifying 330 the received data unit associated with a second one of the signature units against a fingerprint in a second one of the signature units. In step 330, any fingerprint that is consistent with the fingerprint of the located instance of the repeating data unit is ignored. From a security perspective, this ignoring is neutral because the repeating data unit O has already been verified. This ignoring also allows verification method 300 to proceed even if some instances of the repeating data unit O have been pruned, whereby the corresponding fingerprints cannot be paired with data units in the received segment of the media bitstream.
[0056] The step of receiving 310 the stored fragments may include receiving the fragments in a message transmitted over the communication network 131 and / or reading the fragments from a memory 132, 133 or the like.
[0057] Verify signature unit S 1 , S 2 , S3 Step 314 may include using the public key of the key pair in a manner known per se to verify that the fingerprint contained therein is authentic. This may be described as an asymmetric signature setup, where signing and verification are different cryptographic operations corresponding to the private / public keys. Other combinations of symmetric and / or asymmetric verification operations are possible without departing from the scope of the present invention.
[0058] The step of verifying 328 and 330 the received data units I, P may comprise replicating the fingerprint operation deemed to have been performed at the source of the media bitstream, i.e. recalculating the fingerprint using the same hash function h. If all fingerprints in a signature unit are successfully verified, it may be concluded that the corresponding data unit of the fragment is authentic (verified).
[0059] Unless otherwise stated, details related to steps such as “receiving”, “pruning”, “verifying”, etc. are also applicable to the embodiments to be described in the later part of the present disclosure, and thus will not be repeated.
[0060] Example 1A.2
[0061] refer to Figure 5 , consider a media bitstream format in which repeated data units O (represented by rectangles) occupy fixed positions. If the first device 120 has pruned an instance of the repeated data unit O, the second device 140 will be able to determine between which data units in the stored bitstream segments these instances are located. Figure 5 It can be seen that the signature unit S 1 , S 2 , S 3 Contains a single hash of the associated data unit. Signature unit S 1 , S 2 , S 3 It further comprises a signature (primary signature) M and a secondary signature m. The primary signature M is used to verify the original signature unit, i.e., the condition when it left the video acquisition system 110. The secondary signature m is independent of the fingerprint of any prunable instance of the repeating data unit O. An instance of the repeating data unit O is usually prunable unless it is the only instance in the segment, in which case the recipient cannot replace it by reading metadata from another instance. The second signature unit S 2 Any fingerprints that do not contain prunable instances of repeated data units do not therefore need to include a secondary signature m, although this may optionally be done to enhance consistency of the bitstream format.
[0062] With the first signature unit S 1 As an example, the way to generate secondary signatures and primary signatures will be briefly discussed. On the one hand, these signatures can be generated as follows:
[0063] M=s({h(O), h(I), h(P), h(P)}),
[0064] m=s({h(I), h(P), h(P)}),
[0065] where {·} denotes concatenation, and s is a signature function that depends on the private key in the key pair. Note that the secondary signature m is independent of h(O). Alternatively, the secondary signature and the primary signature are generated iteratively, and a multi-stage approach may be employed. In the first step, the secondary signature is generated by signing the fingerprints of all data units except the prunable data units:
[0066] m=s({h(I), h(P), h(P)}).
[0067] The secondary signature m is independent of the fingerprint of any prunable instance of the repeating data unit O. In a second step, the primary signature M is generated by signing the combination (e.g., concatenation) of the secondary signature m and the prunable data unit:
[0068] M = s({m, h(O)}).
[0069] The formula of the primary signature M depends on the first signature unit S 1 The fingerprint of all data units associated with it. Since cryptographic signing is a computationally complex operation, the alternative setting can achieve appreciable computational savings. It also establishes a link between the secondary signature and the primary signature, which makes it more difficult for an unauthorized party to replace the secondary signature m to forge a positive verification result.
[0070] Embodiment 1A.2 of the storage method 200 comprises receiving 210 a segment of a media bitstream; identifying 212 N≥2 instances of a repetitive data unit O in the received segment; pruning 214 up to N-1 instances of the identified instances of the repetitive data unit; pruning 214.1 fingerprints of the pruned up to N-1 instances of the repetitive data unit; and storing 216 the received segment after pruning. Alternatively, the primary signature M of those signature units associated with at least one pruned repetitive data unit may be pruned 220 to further reduce overhead.
[0071] Embodiment 1A.2 of verification method 300 comprises receiving 310 a segment of a stored media bitstream; verifying 314 a signature unit using a secondary digital signature m; and verifying 316a the received associated data unit against a fingerprint in the verified signature unit. Signature units that do not include secondary signature m are verified in a conventional manner using primary signature M. A first signature unit S that includes the secondary signature unit and the primary signature unit but is not associated with any pruned instance of the repeating data unit O 1The primary digital signature M may be used for verification. The second device 140 may be configured to initially attempt to verify each signature unit using the secondary signature m; if this fails or the secondary signature m is missing, it attempts to verify the signature unit using the primary signature M; if both attempts are unsuccessful, the signature unit is rejected. Alternatively, the second device 140 is configured to initially attempt to verify each signature unit using the primary signature M; if this fails, it checks whether the secondary signature m exists, and if so, attempts to verify the signature unit using the secondary signature m; if both attempts are unsuccessful, the signature unit is rejected. If the signature units associated with the pruned instances of the repeating data unit O constitute a relatively small portion, the alternative way of configuring the second device 140 may be marginally more efficient. Note that in this embodiment, no knowledge of the fixed position (i.e., the pruned instances of the repeating data unit O are located at fixed positions in the original media bitstream) is exploited.
[0072] Example 1B
[0073] refer to Figure 6 , consider a media bitstream format in which repeated data units O (represented by rectangles) occupy fixed positions. If the first device 120 has pruned an instance of the repeated data unit O, the second device 140 will be able to determine the data units in the stored bitstream segment between which these instances are located. Figure 6 It can be seen that the signature unit S 1 , S 2 , S 3 A fingerprint containing a fingerprint, i.e. a fingerprint obtained by applying the hash function h in a multi-stage manner. For example, the first signature unit S 1 The fingerprint in may be h({h(O), h(I), h(P), h(P)}), where {·} represents a concatenation such as bitwise concatenation. Alternatively, cascaded applications of hash functions are possible: h 1 =h(O),h 2 =h({h 1 , I}), h 3 =h({h 2 , P}) (first P frame), h 4 =
[0074] h({h 2 , P}) (second P frame). Thus, it depends at least indirectly on the fingerprints h of all associated data units O, I, P, P 4 Included in the first signature unit S 1 This is in Figure 6 For the purpose of Example 1B, the signature unit S 1 , S 2 , S3 It is sufficient to include only the primary signature M.
[0075] Embodiment 1B of the storage method 200 comprises receiving 210 a segment of a media bitstream; identifying 212 N≥2 instances of a repeating data unit O in the received segment; pruning 214 up to N-1 instances of the identified instances of the repeating data unit; and storing 216 the received segment after pruning. It should be understood that the signature unit S 1 , S 2 , S 3 are stored as is, ie in the same condition as they were received 210 .
[0076] Embodiment 1B of verification method 300 comprises receiving 310 a segment of a stored media bitstream; verifying 314 a signature unit using a digital signature; computing 318 a fingerprint of the associated data unit received; computing 320b a fingerprint of an instance of a repeating data unit not associated with the signature unit and recovering the fingerprint from said fixed position (as indicated by lower dashed line 601); computing 322 a fingerprint of the computed fingerprint; and verifying 324b the computed fingerprint of the fingerprint against the fingerprint of the fingerprint in the signature unit. An equivalent alternative to computing 320b the fingerprint of said instance of the repeating data unit is to retrieve the fingerprint from its associated signature unit (upper dashed line 602); however, it is uncertain whether the media bitstream format allows this particular fingerprint to be stored in the signature unit, which fingerprint constitutes an intermediate result of the computation of the fingerprint of the fingerprint. If the fingerprint is retrieved along upper dashed line 602, the computation-recovery process illustrated by lower dashed line 601 need not be applied.
[0077] Example 2A.1
[0078] refer to Figure 7 , consider a media bitstream format in which the repeated data unit O occupies a variable position. Figure 7 It can be seen that the signature unit S 1 , S 2 , S 3 Contains the individual hash of the associated data unit and further contains a signature M, using which the signed unit can be verified at the receiver side. The data structure LOG is not part of the media bitstream format.
[0079] Embodiment 2A.1 of the storage method 200 comprises receiving 210 a segment of a media bitstream; identifying 212 N≥2 instances of a repetitive data unit O in the received segment; pruning 214 up to N-1 instances of the identified instances of the repetitive data unit; storing 216 the received segment after pruning; and storing 218 a pruning log LOG indicating the locations of the pruned instances of the repetitive data unit O in the bitstream. It should be understood that the signature unit S 1 , S 2 , S 3 are stored as is, ie in the same condition as when they were received 210. It should also be appreciated that the pruning log will occupy relatively less space than the pruned instances of the duplicate data unit O, thereby achieving a net saving.
[0080] Embodiment 2A.1 of verification method 300 includes receiving 310 a segment of a stored media bitstream; receiving 312 a pruning log of the stored segment, the pruning log indicating locations in the bitstream of pruned instances of repeated data unit O; verifying 314 the signed unit using a digital signature; and verifying 316b the received associated data unit relative to the signed unit while ignoring fingerprints of missing data units indicated by the pruning log, as in Figure 7 As shown in the LOG in the figure.
[0081] Example 2A.2
[0082] refer to Figure 8 , consider a media bitstream format in which the repeated data unit O occupies a variable position. Figure 8 It can be seen that the signature unit S 1 , S 2 , S 3 Contains a single hash of the associated data unit. Signature unit S 1 , S 2 , S 3 It further comprises a signature (primary signature) M and a secondary signature m. The primary signature M is used to verify the original signature unit, i.e., the state when it leaves the video acquisition system 110. The secondary signature m is independent of the fingerprint of any prunable instance of the repeating data unit O. An instance of the repeating data unit O is usually prunable unless it is the only instance in the segment, in which case the recipient cannot replace it by reading metadata from another instance. The second signature unit S 2 Any fingerprint that does not contain prunable instances of repeated data units, therefore, need not include a secondary signature m.
[0083] Embodiment 2A.2 of the storage method 200 comprises receiving 210 a segment of a media bitstream; identifying 212 N≥2 instances of a repetitive data unit O in the received segment; pruning 214 up to N-1 instances of the identified instances of the repetitive data unit; pruning 214.1 fingerprints of the pruned up to N-1 instances of the repetitive data unit; and storing 216 the received segment after pruning. Alternatively, the primary signature M of those signature units associated with at least one pruned repetitive data unit may be pruned 220 to further reduce overhead.
[0084] Embodiment 2A.2 of verification method 300 comprises receiving 310 a segment of a stored media bitstream; verifying 314 a signature unit using a secondary digital signature m; and verifying 316a the received associated data unit against a fingerprint in the verified signature unit. Signature units that do not include secondary signature m are verified in a conventional manner using primary signature M. A first signature unit S that includes the secondary signature unit and the primary signature unit but is not associated with any pruned instances of the repeating data unit O 1 The primary digital signature M may be used for verification. The second device 140 may be configured to initially attempt to verify each signature unit using the secondary signature m; if the secondary signature m fails or is missing, it attempts to verify the signature unit using the primary signature M; if both attempts are unsuccessful, the signature unit is rejected. Alternatively, the second device 140 is configured to initially attempt to verify each signature unit using the primary signature M; if it fails, it checks whether the secondary signature m exists, and if so, attempts to verify the signature unit using the secondary signature m; if both attempts are unsuccessful, the signature unit is rejected.
[0085] Example 2B.1
[0086] refer to Fig. 9 , consider a media bitstream format in which the repeated data unit O occupies a variable position. Fig. 9 It can be seen that the signature unit S 1 , S 2 , S 3 A fingerprint containing a fingerprint, i.e. a fingerprint obtained by applying the hash function h in a multi-stage manner. For example, the first signature unit S 1 The fingerprint in can be h({h(O), h(I), h(P), h(P)}), where {·} denotes concatenation. Alternatively, cascaded application of hash functions is possible, as described above with reference to Figure 6 For the purposes of embodiment 2B.1, the signature unit S 1 , S 2 , S 3 It is sufficient to include only the primary signature M.
[0087] Embodiment 2B.1 of the storage method 200 comprises receiving 210 a segment of a media bitstream; identifying 212 N≥2 instances of a repetitive data unit O in the received segment; pruning 214 up to N-1 instances of the identified instances of the repetitive data unit; storing 216 the received segment after pruning; and storing 218 a pruning log LOG indicating the positions of the pruned instances of the repetitive data unit O in the bitstream. It should be understood that the signature unit S 1 , S 2 , S 3 are stored as is, ie in the same state as when they were received 210. It should also be appreciated that the pruning log will take up relatively less space than the pruned instances of the duplicate data unit O.
[0088] Embodiment 2B.1 of verification method 300 includes receiving 310 a stored segment of a media bitstream; receiving 312 a pruning log of the stored segment, the pruning log indicating the locations in the bitstream of pruned instances of repeated data unit O; verifying 314 the signature unit using a digital signature; and verifying 316b the received associated data units relative to the signature unit while ignoring fingerprints of missing data units indicated by the pruning log; calculating 318 the fingerprints of the received data units associated with the signature unit; calculating 320a the fingerprints of instances of repeated data units not associated with the signature unit, and recovering the calculated fingerprints based on the pruning log (as indicated by the lower dashed line 901); calculating 322 a fingerprint of the calculated fingerprint; and verifying 324b the calculated fingerprint of the fingerprint relative to the fingerprint in the signature unit. Alternatively, as described above with reference to Figure 6 As explained, the fingerprint of the pruned instance of the repeating data unit O may be retrieved from the signature unit associated with the non-pruned instance of the repeating data unit O, as illustrated by the upper dashed line 902 .
[0089] Example 2B.2
[0090] refer to Fig.10 , consider a media bitstream format in which the repeated data unit O occupies a variable position. It can be seen that the signature unit S 1 , S 2 , S 3 A fingerprint containing a fingerprint, i.e. a fingerprint obtained by applying the hash function h in a multi-stage manner. For example, the first signature unit S 1 The fingerprint in can be h(), where {·} denotes concatenation. Alternatively, cascaded application of hash functions is possible, as described above with reference to Figure 6 For the purposes of embodiment 2B.2, the signature unit S 1 , S 2 , S3 It is sufficient to include only the primary signature M. Fig.10 It can also be seen that those signature units S associated with at least one instance of the repeating data unit O 1 , S 3 contains not only the (primary) fingerprint (denoted F) of all associated data units, but also a secondary fingerprint (denoted f) of the fingerprint, which is independent of the fingerprint of the associated prunable instance of the repeating data unit O. The (primary) signature M has been generated based on both F and f, and can therefore be used for simultaneous verification of F and f.
[0091] Embodiment 2B.2 of storage method 200 includes receiving 210 a segment of a media bitstream; identifying 212 N≥2 instances of a repeating data unit (O) in the received segment; pruning 214 up to N-1 instances of the identified instances of the repeating data unit; and storing 216 the received segment after pruning.
[0092] Embodiment 2B.2 of verification method 300 includes receiving 310 a segment of a stored media bitstream; verifying 314 a signature unit using a digital signature; calculating 318 a fingerprint of the received associated data unit; calculating 322 a fingerprint of the calculated fingerprint unit; and verifying 324 a the calculated fingerprint of the fingerprint relative to a secondary fingerprint f of the fingerprint.
[0093] Aspects of the disclosure have mainly been described above with reference to a few embodiments. However, as readily appreciated by a person skilled in the art, other embodiments than the ones disclosed above are equally possible within the scope of the invention, as defined by the appended patent claims.
Claims
1. A method of verifying a segment of a signed media bitstream consisting of a data unit and a signature unit associated with one or more nearby data units, include: The following items are performed by the computing device: Wherein, at least two of the signature units include: The fingerprints of all associated data units, and A digital signature of at least one fingerprint, and wherein the signed media bitstream conforms to a format in which the positions of repeated data units are fixed, The method further comprises: Receiving a stored segment of the signed media bitstream; verifying the at least two signature units using their respective digital signatures; locating an instance of the repeating data unit associated with a first signature unit of the at least two signature units; verifying the received data unit associated with the first of the at least two signature units against the fingerprint in the first of the at least two signature units; and The received data unit associated with a second one of the at least two signature units is verified against a fingerprint in the second one of the at least two signature units while ignoring any fingerprint that is consistent with the fingerprint of the located instance of the duplicate data unit.
2. A method of verifying a segment of a signed media bitstream consisting of a data unit and a signature unit associated with one or more nearby data units, include: The following items are performed by the computing device: Wherein, at least one of the signature units comprises: the fingerprints of all associated data units, and a digital signature of the fingerprint of the fingerprint and a digital signature of a secondary fingerprint of the fingerprint, wherein the secondary fingerprint of the fingerprint is independent of the fingerprint of the prunable associated data unit in the associated data unit, and wherein the signed media bitstream conforms to a format in which the positions of repeated data units are fixed, The method further comprises: Receiving a stored segment of the signed media bitstream; verifying the at least one signature unit using the digital signature; calculating a fingerprint of the received associated data unit; calculating a fingerprint of an instance of the repeated data unit that is not associated with the at least one signature unit, and recovering the repeated data unit based on a fixed position; calculating a fingerprint of the calculated fingerprint; and The calculated fingerprint of the fingerprint is verified against the fingerprint of the fingerprint in the signature unit.
Citation Information
Patent Citations
Device and method for sending and verifying a signature
CN107113305A
Methods, systems, and media for protecting and verifying video files
CN110741650A