Authentication method of video code stream, computer device and storage medium
Patent Information
- Application Number
- CN202311459154.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-02
- Publication Date
- 2026-09-18
- Estimated Expiration
- 2043-11-02
AI Technical Summary
[0004]然而,现有技术的视频码流的认证方法,存在认证方式不规范等问题
[0010] The above scheme obtains target bitstream data by signing the video bitstream. The target bitstream data includes a network abstraction layer unit containing authentication information, and/or authentication information is set at the encoding and decoding ends. The authentication information includes at least one authentication rule among the target signature data format and target authentication validity. Since the target signature data format represents the format information for verifying the signature of the video bitstream, the decoding end can perform signature verification according to the format information of the target signature data format. By specifying the signature data format of the authentication data, the problem of different signature data formats arising in the actual authentication process can be reduced, making the authentication process of signing and verification more standardized. In addition, since the target authentication validity represents the validity of the encoded image frame bitstream and/or decoded image frame bitstream of the video bitstream, even if the frame referenced by the authenticated frame is not authenticated, the validity of the authentication can still be determined, which can make the validity of the authentication of image frames more standardized, and overall improve the efficiency and effectiveness of authentication.
Smart Images

Figure CN117651146B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of video encoding and decoding technology, and in particular to a video stream authentication method, computer device, and computer-readable storage medium. Background Technology
[0002] Because video image data is relatively large, it usually needs to be encoded and compressed. The compressed video image data is called a video stream. The video stream can be transmitted to the user's end via wired or wireless network for decoding and viewing. The entire video encoding and compression process can include prediction, transformation, quantization, and encoding.
[0003] For the security of video stream transmission, the video stream is authenticated. In the specific authentication process, the video stream needs to be signed during the encoding and compression of the video image. Then, after being transmitted to the user's end, the signature is verified to authenticate the video stream.
[0004] However, existing video stream authentication methods suffer from issues such as non-standard authentication procedures. Summary of the Invention
[0005] The main technical problem addressed in this application is to provide a video stream authentication method, computer equipment, and storage medium that can improve the standardization of video stream authentication.
[0006] To address the aforementioned issues, a first aspect of this application provides a video stream authentication method. The method includes: an encoding end acquiring a video stream; performing signature processing on the video stream to obtain target stream data; wherein the target stream data includes a network abstraction layer unit containing authentication information, and / or, authentication information is set at both the encoding and decoding ends; the authentication information includes at least one authentication provision among a target signature data format and a target authentication validity, the target signature data format representing the format information for signature verification processing of the video stream, and the target authentication validity representing the validity of the encoded image frame stream and / or decoded image frame of the video stream; the authentication information is used by the decoding end to perform signature verification processing on the video stream during the decoding process of the target stream data.
[0007] To address the aforementioned issues, a second aspect of this application provides a video stream authentication method. The method includes: a decoding end acquiring target bitstream data, wherein the target bitstream data is obtained by an encoding end performing the aforementioned video stream authentication method; decoding the target bitstream data to obtain a video stream; and performing signature verification processing on the video stream using authentication information. The target bitstream data includes a network abstraction layer unit containing authentication information, and / or authentication information is set at both the encoding and decoding ends. The authentication information includes at least one authentication provision: a target signature data format and a target authentication validity. The target signature data format represents the format information for signature verification processing of the video stream, and the target authentication validity represents the validity of the encoded image frame bitstream and / or decoded image frame bitstream of the video stream. The authentication information is used by the decoding end to perform signature verification processing on the video stream during the decoding process of the target bitstream data.
[0008] To address the aforementioned problems, a third aspect of this application provides a computer device comprising a memory and a processor coupled to each other, wherein the memory stores program data and the processor executes the program data to implement any step of the aforementioned video stream authentication method.
[0009] To address the aforementioned problems, a fourth aspect of this application provides a computer-readable storage medium storing program data executable by a processor, the program data being used to implement any step of the aforementioned video stream authentication method.
[0010] The above scheme obtains target bitstream data by signing the video bitstream. The target bitstream data includes a network abstraction layer unit containing authentication information, and / or authentication information is set at the encoding and decoding ends. The authentication information includes at least one authentication rule among the target signature data format and target authentication validity. Since the target signature data format represents the format information for verifying the signature of the video bitstream, the decoding end can perform signature verification according to the format information of the target signature data format. By specifying the signature data format of the authentication data, the problem of different signature data formats arising in the actual authentication process can be reduced, making the authentication process of signing and verification more standardized. In addition, since the target authentication validity represents the validity of the encoded image frame bitstream and / or decoded image frame bitstream of the video bitstream, even if the frame referenced by the authenticated frame is not authenticated, the validity of the authentication can still be determined, which can make the validity of the authentication of image frames more standardized, and overall improve the efficiency and effectiveness of authentication.
[0011] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this application. Attached Figure Description
[0012] To more clearly illustrate the technical solutions in this application, the accompanying drawings required in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Among them: Figure 1 This is a schematic diagram of the structure of an embodiment of the video encoding and decoding system of this application; Figure 2 This is a flowchart illustrating an embodiment of the encryption and decryption of the video encoding and decoding system of this application; Figure 3 This is a flowchart illustrating an embodiment of the video encoding / decoding system for signature verification in this application; Figure 4 This is a schematic diagram of an embodiment of the tree-structured summary of this application; Figure 5 This is an example schematic diagram of an embodiment of the frame reference relationship and knowledge image of this application; Figure 6 This is a schematic diagram illustrating another embodiment of the frame reference relationship and knowledge image of this application; Figure 7 This is a flowchart illustrating the first embodiment of the video stream authentication method of this application; Figure 8 This is a flowchart illustrating the second embodiment of the video stream authentication method of this application; Figure 9 This is a flowchart illustrating the third embodiment of the video stream authentication method of this application; Figure 10 This is a flowchart illustrating the fourth embodiment of the video stream authentication method of this application; Figure 11 This is a flowchart illustrating the fifth embodiment of the video stream authentication method of this application; Figure 12 This is a flowchart illustrating the sixth embodiment of the video stream authentication method of this application; Figure 13 This is a flowchart illustrating the seventh embodiment of the video stream authentication method of this application; Figure 14 This is a schematic diagram of the structure of an embodiment of the encoding end of this application; Figure 15 This is a schematic diagram of the structure of an embodiment of the decoding end of this application; Figure 16 This is a schematic diagram of the structure of an embodiment of the computer device of this application; Figure 17 This is a schematic diagram of the structure of an embodiment of the computer-readable storage medium of this application. Detailed Implementation
[0013] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of the embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0014] The terms "first" and "second" in this application are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this application, "multiple" means at least two, such as two, three, etc., unless otherwise explicitly specified. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to such processes, methods, products, or apparatus.
[0015] In this application, the reference to "embodiment" means that a specific feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0016] In this document, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Additionally, the character " / " generally indicates that the preceding and following related objects have an "or" relationship. Furthermore, "many" in this document means two or more. Moreover, the term "at least one" in this document means any combination of at least two of any one or more of a plurality of objects. For example, including at least one of A, B, and C can mean including any one or more elements selected from the set consisting of A, B, and C.
[0017] This application provides the following embodiments, and each embodiment is described in detail below.
[0018] Please see Figure 1 , Figure 1 This is a schematic diagram of the structure of an embodiment of the video encoding and decoding system of this application.
[0019] The video encoding / decoding system 100 includes an encoding end 101 and a decoding end 102. The encoding end 101 and the decoding end 102 can be computer equipment, electronic equipment, etc., and can be any device with processing capabilities, such as a computer, server, mobile phone, tablet, etc. This application does not impose any limitations on this. The encoding end 101 and the decoding end 102 can communicate with each other and can be used to perform encoding and / or decoding operations on images / videos.
[0020] Encoding end 101 can be used to perform image / video encoding and compression steps, as well as signature, encryption, and other processing to obtain target bitstream data. Encoding end 101 can transmit the target bitstream data to decoding end 102. Decoding end 102 can receive the target bitstream data from encoding end 101 and perform decoding, decryption, verification, and other related steps containing the target bitstream data. It can also include steps related to backend vision tasks, such as image processing and classification.
[0021] In some implementations, to ensure the security of video stream transmission between the encoding end 101 and the decoding end 102, authentication processing of the video stream is typically required to prevent tampering during transmission. In some application scenarios, encryption processing can also be applied to the video stream to further enhance its security during transmission.
[0022] Please see Figure 2 , Figure 2 This is a flowchart illustrating an embodiment of the encryption and decryption of the video encoding / decoding system of this application. In this embodiment, the video encoding / decoding system can use encryption / decryption authentication technology to process the video stream.
[0023] In some implementations, the encryption process of the video stream at the encoding end may include the following steps: (1) The encoding end periodically generates a key such as a 128-bit VEK (Video Encryption Key). VEK is the encryption key for the video stream. The encoding end can randomly generate a symmetric key that changes according to a certain pattern to encrypt the video stream content and achieve plaintext protection.
[0024] (2) Read the NAL data of the encoded bitstream of the video to be encrypted, which can also be called the raw NAL.
[0025] For example, reading the RBSP (Raw Byte Sequence Payload) data from the NAL (Network Abstraction Layer) of the AVS2 video coding standard. NAL is responsible for formatting the data and providing header information to ensure the data is suitable for transmission on various channels and storage media. RBSP data is the raw data byte stream of the AVS2 video coding standard.
[0026] (3) If the following conditions are met simultaneously: the RBSP is the first coded slice data at the beginning of the GOP (Group of Pictures) and a new VEK is available, the current VEK is invalidated and a new VEK is activated. Otherwise, the current VEK continues to be used.
[0027] During video compression, the video sequence is first divided into several group of images (GOPs), and compression is performed on a GOP-by-GOP basis. A GOP is a group of images in the video, representing the interval between two keyframes (I-frames).
[0028] (4) The encoding end randomly generates a 128-bit IV. Here, the IV is the initialization vector, which is used for the OFB (Output Feed Back) encryption mode of the block cipher. OFB encryption mode is one of the four modes of block cipher. In OFB encryption mode, the output of the cryptographic algorithm is fed back to the input of the cryptographic algorithm.
[0029] (5) The OFB mode of the agreed block cipher algorithm is used to generate the encrypted stream key using VEK and IV.
[0030] (6) The encrypted stream key and the RBSP data to be encrypted are aligned bit by bit and XORed to obtain the encrypted RBSP data, which is also the encrypted NAL.
[0031] (7) Encapsulate this encrypted NAL. This can be achieved by using the code field encryption_idc = 1 in the syntax.
[0032] (8) When a new VEK is activated or a new IV is used, the security extension information NAL can be encapsulated and the NAL output encrypted beforehand.
[0033] In some implementations, during the encryption process described above, the KMS (Key Management Service) key management system can obtain the VKEK version and then the VKEK (VideoVey Encryption Key), which is used to encrypt the VEK key to obtain the EVEK key parameter. The KMS key management system can generate and distribute symmetric keys to front-end devices with security features, which change according to a certain pattern and are used to encrypt the video key, thereby protecting the confidentiality of its transmission.
[0034] Next, the EVEK and VKEK versions of the key parameters are written into the security parameter set, encapsulated with the video bitstream (such as the encrypted NAL of the video bitstream) to obtain the target bitstream data, and the target bitstream data is transmitted to the decoding end.
[0035] In some implementations, the decryption process of the video stream at the decoding end may include the following steps: (1) Receive the target code stream data, obtain the ciphertext of IV and VEK from the security parameter set, denoted as E(VEK), and decrypt E(VEK) with VKEK to obtain VEK.
[0036] In the above process, the KMS key management system can obtain the VKEK based on the VKEK version of the security parameter set. This VKEK is then transmitted to the decoding end for decryption of the E(VEK).
[0037] (2) Read the RBSP data of the target bitstream data to be decrypted.
[0038] (3) The following conditions must be met simultaneously: if this RBSP is the first coded slice data at the start of the GOP, and if a new VEK is available, the current VEK is invalidated and a new VEK is activated; otherwise, the current VEK continues to be used.
[0039] (4) Use the agreed block encryption algorithm in OFB mode and generate the decryption stream key using VEK and IV.
[0040] (5) Align the decrypted stream key and the RBSP data to be decrypted bit by bit, and perform an XOR operation to obtain the decrypted RBSP data, which is the original NAL.
[0041] Please see Figure 3 , Figure 3 This is a flowchart illustrating an embodiment of the video encoding / decoding system for signature verification according to this application. In this embodiment, the video encoding / decoding system can use signature verification authentication technology to process the video stream.
[0042] In some implementations, the signature process for the video bitstream at the encoding end may include the following steps: (1) Read one or more NAL unit data of the video stream to be authenticated.
[0043] (2) Perform hash calculations on the NAL cells according to the algorithm and method agreed upon in the security parameter set to generate primary or secondary hash values. Hash calculations are similar to tree digest calculations.
[0044] (3) Using the device private key, sign the tree-top hash (e.g., SM3) results of one or more images according to the algorithm and method agreed upon by the signature_type field of the security parameter set syntax, and generate authentication data for the video stream.
[0045] (4) Encapsulate the authentication data of the video stream into an authentication data unit, and encapsulate it in the form of an independent NAL.
[0046] In the above process, the security parameter set, the NAL of the video stream, and the authentication data can be encapsulated to obtain the target video encoding. The target video encoding can then be transmitted to the decoding end.
[0047] In some implementations, the signature verification process of the video bitstream at the decoding end may include the following steps: (1) Obtain the source device information from the security parameter set NAL and find the public key of the corresponding source device; (2) Use the signature algorithm specified in the signature_type field of the syntax to decrypt the authentication data with the public key of the source device and generate a verification hash value.
[0048] (3) Locate the first authentication NAL unit of the image corresponding to the authentication data in the video stream.
[0049] (4) Perform initial hash calculation or treetop hash calculation (SM3) on one or more groups of certified NAL units starting from the first certified NAL unit according to the algorithm and method agreed upon in the security parameter set, and use the calculation result as the comparison hash value.
[0050] (5) Compare the verification hash value and the comparison hash value. If they are completely the same, the image corresponding to the video authentication data passes the verification, that is, it passes the authentication; otherwise, it fails the authentication.
[0051] In some implementations, the syntax of the aforementioned security parameter set is specifically as follows: Table 1. Syntax Table of Security Parameter Set
[0052] Specifically, the semantics of the syntax of the security parameter set are as follows: (1) Encryption flag encryption_flag The encryption flag `encryption_flag` is a binary variable. A value of '1' indicates that encryption is supported for display image coded slices, display image sequence parameter sets, display image parameter sets, non-display knowledge image coded slices, display knowledge image coded slices, knowledge image sequence parameter sets, knowledge image parameter sets, or extended data units; that is, RBSPs in NAL units may be encrypted. A value of '0' indicates that encryption of RBSPs in NAL units is not supported.
[0053] (2) Authentication flag The authentication flag `authentication_flag` is a binary variable. A value of '1' indicates support for authentication of access units for the entire image frame. The NAL units for authentication include the coded slices of the displayed or knowledge image, as well as the sequence parameter set, image parameter set, security parameter set, and extended data units transmitted in the frame. When authentication of the above data content is supported, the encoded bitstream must carry absolute time extension information, and the authentication data carried in the encoded bitstream should be Base64 encoded. Authentication data is transmitted through NAL units where `nal_unit_type` equals 10.
[0054] If an image contains encoded slices of a display image or knowledge image with authentication_idc equal to 1, sequence parameter sets of a display image or knowledge image, image parameter sets of a display image or knowledge image, security parameter sets, extended data units, etc., the NAL units with authentication_idc equal to 1 in an image are arranged in decoding order and then authenticated to generate the image's digest data. authentication_flag equal to 0 indicates that image authentication is not supported, and the encoded bitstream should not contain NAL units with nal_unit_type equal to 10.
[0055] (3) Encryption type encryption_type The encryption type, encryption_type, is a 4-bit unsigned integer. It indicates the encryption algorithm used, and the specific correspondence is shown in Table 2 below.
[0056] Table 2. Correspondence between encryption types and specific encryption algorithms
[0057] (4) Video encryption key flag vek_flag The video encryption key flag vek_flag is a binary variable. A value of '1' indicates that vek is included, and a value of '0' indicates that vkek is not included.
[0058] (5) Initial vector flag iv_flag The initialization vector flag iv_flag is a binary variable. A value of '1' indicates that iv is carried, and a value of '0' indicates that iv is not carried.
[0059] (6) Video encryption key encryption type vek_encryption_type This is a 4-bit unsigned integer. It indicates the encryption type of the video encryption key; see Table 41 for the specific correspondence.
[0060] (7) Length of the encrypted video encryption key evek_length_minus1 This is an 8-bit unsigned integer. It can be used to indicate the length of the encrypted video encryption key, in bytes.
[0061] (8) Encryption key for the encrypted video: evek This is an n-bit unsigned integer. It represents the encryption key for the encrypted video, used for encryption calculations, and its length is evek_length_minus1 plus 1 byte.
[0062] (9) Video encryption key version number and length vkek_version length_minus1 An 8-bit unsigned integer. Indicates the length of the video encryption key version number, in bytes.
[0063] (10) Video encryption key version number vkek_version It is an n-bit unsigned integer. It can be used to indicate the video encryption key version number, with a length of vkek_version_length_minus1 plus 1 byte.
[0064] (11) Initial vector length iv_length_minus1 An 8-bit unsigned integer. Indicates the length of the initial vector, in bytes.
[0065] (12) Initial vector iv This is an n-bit unsigned integer. It indicates the initialization vector used for block encryption, with a length of iv_length_minus1 plus 1 byte.
[0066] (13) Hash type hash_type This is a 2-bit unsigned integer. It indicates the algorithm used for authentication, and the specific correspondence can be represented by the table below.
[0067] Table 3. Correspondence between hash types and specific algorithms
[0068] (14) Knowledge Image Hash Authentication Flag hash_discard_library_pictures_flag A binary variable. A value of '1' indicates that the knowledge image is not authenticated; a value of 0 indicates that the knowledge image is authenticated. If hash_discard_library_pictures is not in the bitstream, its default value is 1. In images that are not authenticated, the authentication_idc value of each NAL unit should be equal to 0.
[0069] (15) P / B frame hash authentication flag hash_discard_pb_pictures_flag A binary variable. A value of '1' indicates that no authentication is performed on images other than random access point images and knowledge images; a value of '0' indicates that authentication is performed on images other than random access point images and knowledge images. If hash_discard_pb_pictures is not in the bitstream, its default value is 1. The authentication_idc value for each NAL unit in an image that is not authenticated should be equal to 0.
[0070] (16) Successive number of consecutive authentication image frames: successful_hash_pictures_minus1 An 8-bit unsigned integer. Represents the number of consecutively displayed images or knowledge image slices for digital signing in decoding order, and these consecutively displayed images or knowledge image slices are limited to a single random access image or RLI frame interval. The value of `successive_hash_pictures_minus1` should be between 0 and 255.
[0071] Among them, SuccessiveHashPictures=successive_hash_pictures_minus1+1.
[0072] If successful_hash_pictures_minus1 equals 0, digitally sign the summary data of each certified display image or knowledge image slice.
[0073] If `successive_hash_pictures_minus1` is greater than 0, first, a tree-structured summary is generated from the summary data of `SuccessiveHashPictures` consecutive display image or knowledge image slices in decoding order, and then a digital signature is applied to the top-level summary data. Please refer to [link to relevant documentation]. Figure 4 The treetop summary data of n images is the summary data generated by arranging the treetop summary data of the first n-1 images and the summary data of the nth image according to the method shown by hash_type.
[0074] After the security parameter set is activated, the first image to be authenticated can be the first of a consecutive `SuccessiveHashPictures` display image or knowledge image slice. The first slice of a random access image, RL image, or knowledge image (IDR image) should be the first of a consecutive `SuccessiveHashPictures` images. If the number of images to be authenticated in a random access image or RL / IDR image interval is less than `SuccessiveHashPictures`, the digest data corresponding to the signature data is the digest data of all images contained in the previous random access image or RL / IDR image interval. For a specific description of RL / IDR images, please refer to the following embodiments; further details are omitted here.
[0075] (17) Digital signature type signature_type A 2-bit unsigned integer. This can be used to indicate the algorithm used to digitally sign the image's summary data, as shown in the table below.
[0076] Table 4. Correspondence between digital signature types and specific encryption algorithms
[0077] (18) Camera ID (camera_id) A 152-bit string. The camera ID indicating the source of the image.
[0078] The above embodiments do not restrict the use of customizable or default authentication methods such as algorithms and hashing methods by users for retaining certain parts.
[0079] In some implementations, the syntax of the NAL unit of the encoded slice of the video bitstream specified by SVAC3 is as follows: Table 5. Syntax Table of Security Parameter Set
[0080] Specifically, the semantics of the NAL unit syntax for the encoded slice are as follows: (1) Encryption flag encryption_idc A binary variable. It indicates whether the NAL cell is encrypted. A value of '0' indicates that the RBSP in the NAL cell is not encrypted, and a value of '1' indicates that the RBSP in the NAL cell is encrypted using the encryption method specified in the security parameter set, and the last byte of the RBSP is not encrypted.
[0081] (2) Authentication mark authentication_idc A binary variable. It indicates whether the NAL unit is authenticated. A value of '0' indicates that the NAL unit is not authenticated, and a value of '1' indicates that the NAL unit is authenticated using the authentication method specified in the security parameter set, and the encoded bitstream must carry absolute time extension information to identify the authentication time.
[0082] In some implementations, the syntax of the NAL unit of the authentication data of the video stream described above is specifically as follows: Table 6 Syntax Table of Authentication Data
[0083] Specifically, the semantics of the NAL syntax for authentication data are as follows: (1) Knowledge image authentication data flag is_library_flag A binary variable. A value of "1" indicates that the authentication data is the signature data of a CRR image; a value of "0" indicates that the authentication data is the signature data of a display image. If spactial_el_flag does not exist in the bitstream, its default value is 0.
[0084] (2) Image frame_num containing authentication data An 8-bit unsigned integer. This image is the nearest display image or knowledge image whose frame_num is the same as the frame_num of the authentication data before the NAL unit of the authentication data. When successive_hash_pictures_minus1 equals 0, frame_num indicates the display image and knowledge image corresponding to the authentication data; when it is greater than 0, frame_num indicates the last of all slices of consecutive SuccessiveHashPictures display images or knowledge images. When the scope of the authentication data is a knowledge image, frame_num indicates the patch_idx of the last slice of consecutive SuccessiveHashPictures knowledge image slices.
[0085] (3) Authentication knowledge image index: authentication_library_picture_index n-bit unsigned integer. Indicates the index of the knowledge image corresponding to the knowledge bitstream from which the current authentication data applies; the value ranges from 0 to 511. If `authentication_library_picture_index` does not exist in the bitstream, its default value is 0.
[0086] (4) The length of the signature data: authentication_data_length_minus1 An 8-bit unsigned integer. Adding 1 indicates the length of the signature data in bytes, and the value should be between 0 and 255.
[0087] (5) Number of bytes in the signature data: authentication_data[i] An 8-bit unsigned integer. The i-th byte of a signature data set. The signature data should be Base64 encoded. Base64 encoding is a common method for storing and transmitting binary data over a network. One byte of Base64 can only represent 64 possibilities, and the first two bits of each byte in the encoding format can only be 0, using the remaining 6 bits to represent the content.
[0088] In some implementations, the concept of a knowledge picture (Library Picture) is introduced in the SVAC3 video codec standard described above. A knowledge picture can be a CRR frame or an LTR frame. A CRR frame represents a knowledge picture that is not displayed. A knowledge picture that is transmitted as a complete frame before the RL frame without interleaving fragments with the preceding P frames and is displayed normally is called an LTR frame (Long-Term Reference).
[0089] A knowledge image is a long-term reference frame encoded using I-frames. It serves only as a reference frame and may not be used for display. Knowledge images are identified by their knowledge image index (IDX), rather than the POC (Pic_order_cn) or DOI (Decodeorderindex) of other frames in the bitstream.
[0090] In the above process, RL (reference library) frames are also introduced. RL frames refer to P frames or B frames that only reference knowledge images.
[0091] In some implementations, regarding the structure of knowledge images in the bitstream: knowledge images are usually encoded using I-frame encoding. However, since the bitrate of encoded knowledge images is generally low, the encoding is slow, and the bitrate is generally high, interleaving an entire frame of knowledge image bitstream into the bitstream can cause large bitrate spikes and jitter during decoding. Therefore, the patch mechanism in the existing SVAC3 standard can be used to divide the knowledge image into multiple patches and interleave them with multiple display images. Only one patch is encoded at a time and added to the bitstream, ultimately resulting in an encoded output bitstream that interleaves the knowledge base patch bitstream with the display image bitstream.
[0092] As an example, please refer to Figure 5 With the video stream frame type configured as "IPPP", the knowledge image L is divided into two pieces (patch0, patch1), according to... Figure 5 The positional relationships of each frame and knowledge image in the bitstream can be determined, such as RL, P, P, P... The frame reference relationships between frames can be obtained, such as a P frame following an RL frame referencing an RL frame.
[0093] As an example, please refer to Figure 6 With the video stream frame type configured as "IPPP", the knowledge image L0 is divided into 4 slices (L0patch0, L0patch1, L0patch2, L0patch3). Alternatively, the knowledge image L1 can be divided into 4 slices (L1patch0, L1patch1, L1patch2, L1patch3), which can be distributed among the P frames. Figure 6 The positional relationships of each frame and knowledge image in the bitstream can be represented as RL(poc0), P(poc1), P(poc2), ..., P(poc7), RL(poc8), P(poc9) ... . The frame reference relationships between each frame can be obtained, such as frame P(poc1) referencing frame RL(poc0).
[0094] Through long-term research, the inventors of this application have discovered that existing authentication-related technologies do not provide any regulations or standards for authentication, which means that existing video stream authentication methods suffer from problems such as non-standard authentication, low authentication efficiency, or poor results.
[0095] To address the aforementioned issues, this application provides a video stream authentication method, and specific embodiments of the video stream authentication method are described below.
[0096] Please see Figure 7 , Figure 7 This is a flowchart illustrating the first embodiment of the video stream authentication method of this application. The specific steps of the video stream authentication method in this embodiment can be executed using the aforementioned encoding end. The method may include the following steps: S11: The encoding end acquires the video bitstream.
[0097] A video stream can be a stream of encoded and compressed video or multiple video frames. For example, a video stream can be obtained by encoding and compressing the video captured by a capture device (such as a camera) of the target environment.
[0098] S12: Sign the video stream to obtain target stream data; wherein the target stream data includes a network abstraction layer unit containing authentication information, and / or, authentication information is set at the encoding and decoding ends; the authentication information includes at least one authentication provision among the target signature data format and the target authentication validity.
[0099] The target bitstream data includes a network abstraction layer unit containing authentication information, and / or authentication information is set at the encoding and decoding ends; the authentication information includes at least one authentication provision among the target signature data format and the target authentication validity, the target signature data format representing the format information for verifying the signature of the video bitstream, and the target authentication validity representing the validity of the encoded image frame bitstream and / or decoded image frame of the video bitstream; the authentication information is used by the decoding end to perform signature verification processing on the video bitstream during the decoding process of the target bitstream data.
[0100] The Network Abstraction Layer (NAL) is part of the H.264 / AVC video coding standard, and is used as the unit of operation for the Video Coding Layer (VCL).
[0101] In this application, authentication rules for authentication information can be set in the standard codec files at both the encoding and decoding ends, and / or, authentication information can be marked with syntactic elements at the network abstraction layer unit. If authentication information is set in both, either authentication information can be processed accordingly, or the authentication information marked with syntactic elements at the network abstraction layer unit can be given priority. This application is not limited thereto.
[0102] The target signature data format represents the format information for verifying the signature of a video stream, or it can represent the format information for signing a video stream.
[0103] The encoded image frame bitstream represents the bitstream or bitstream corresponding to the encoded image frame. The validity of the encoded image frame bitstream and / or decoded image frame indicates the correctness and completeness of the encoded image frame bitstream and / or decoded image frame.
[0104] The lack of standardization in the signature data format during the authentication process may lead to different signature data formats in actual authentication. The aforementioned network abstraction layer unit includes the target signature data format, which represents the format information for verifying the video stream, making the signature data format more standardized and improving authentication efficiency and effectiveness.
[0105] During the authentication process, it's possible that the frame referenced by the frame being authenticated may not have been authenticated, meaning the validity of the authentication cannot be determined. For example, P-frames and other frames containing inter-frame predictions need to reference the content of other frames. If the referenced frame is not authenticated, the correctness and integrity of the decoded image of the frame containing inter-frame predictions cannot be guaranteed. If the reference frame is tampered with, it will indirectly affect the decoded image content of subsequent frames that reference it, causing subsequent frames to be authenticated, but the completeness and correctness of their decoded reconstructed images cannot be guaranteed. In other words, the content of the authenticated frame's decoded and reconstructed image cannot be guaranteed to be untampered with; it's possible to tamper with the content of its reference frame by altering it. The aforementioned network abstraction layer unit includes target authentication validity, which represents the validity of the encoded image frame stream and / or decoded image frame of the video bitstream. This makes the authentication validity more standardized, improving authentication efficiency and effectiveness.
[0106] In some implementations, the network abstraction layer unit is at least one of a security parameter set and authentication data. After signing the video stream to obtain authentication data, the security parameter set, video stream, and authentication data can be encapsulated to obtain the target stream data. In this embodiment, encapsulation refers to placing the security parameter set, video stream, and authentication data into the stream in the order of security parameter set, video stream, and authentication data to form the target stream data.
[0107] In some implementations, the video stream can be signed according to a preset authentication method and a preset authentication object to obtain authentication data for the video stream or the target authentication object.
[0108] Authentication can be divided into signature processing and signature verification processing. Both processes require calculating hash values for the same NAL units of the same frame in the same way. After the encoding end transmits the target bitstream data to the decoding end, the decoding end can decode the target bitstream data to obtain the Network Abstraction Layer (NAL) unit (security parameter set, authentication data) and the video bitstream. Then, the target signature data format and target authentication validity in the NAL unit are used to authenticate the video bitstream. The video bitstream can be processed according to the target signature data format to obtain verification data. The verification data is compared with the authentication data to obtain the authentication result of the video bitstream. If they match, the authentication is successful; otherwise, it fails. Furthermore, the target authentication validity is used to determine the authentication validity of the encoded image frame bitstream and / or decoded image frame bitstream of the video bitstream.
[0109] In some implementations, the network abstraction layer unit (NET) is at least one of a security parameter set and authentication data, where the authentication data is obtained by signing the video bitstream. Regarding the target signature data format and target authentication validity mentioned above, syntactic elements can be used in the NET to mark the target signature data format of the video bitstream. And / or, syntactic elements can be used in the NET to mark the target authentication validity.
[0110] The above scheme obtains target bitstream data by signing the video bitstream. The target bitstream data includes a network abstraction layer unit containing authentication information, and / or authentication information is set at the encoding and decoding ends. The authentication information includes at least one authentication rule among the target signature data format and target authentication validity. Since the target signature data format represents the format information for verifying the signature of the video bitstream, the decoding end can perform signature verification according to the format information of the target signature data format. By specifying the signature data format of the authentication data, the problem of different signature data formats arising in the actual authentication process can be reduced, making the authentication process of signing and verification more standardized. In addition, since the target authentication validity represents the validity of the encoded image frame bitstream and / or decoded image frame bitstream of the video bitstream, even if the frame referenced by the authenticated frame is not authenticated, the validity of the authentication can still be determined, which can make the validity of the authentication of image frames more standardized, and overall improve the efficiency and effectiveness of authentication.
[0111] In some embodiments, step S12 of the above embodiments can be further extended. Extended embodiments can be found in the following examples.
[0112] Please see Figure 8 , Figure 8 This is a flowchart illustrating a second embodiment of the video stream authentication method of this application. The specific steps of the video stream authentication method in this embodiment can be executed using the aforementioned encoding end. The method may include the following steps: S21: The target signature data format of the target effective frame is determined by the first syntax element in the security parameter set. The target effective frame is at least a portion of the image frames of the video stream within the effective range of the security parameter set.
[0113] Corresponding syntax elements can be added to the security parameter set and / or authentication data to mark the target signature data format.
[0114] For network abstraction layer units that are security parameter sets, the target signature data format of the target effective frame can be determined by using the first syntax element in the security parameter set. The target effective frame is the image frame of the video bitstream within the effective range of the security parameter set.
[0115] In some implementations, the target bitstream data is encapsulated and transmitted in the order of security parameter set, video bitstream coded slice NAL, and authentication data. The image frame to which the video bitstream coded slice NAL belongs between the current security parameter set and the next security parameter set is considered the image frame within the effective range of the current security parameter set, i.e., the target effective frame in this embodiment.
[0116] The target signature data format includes PLAIN, ASN.1 / DER, and other preset signature data formats. ASN.1 can be an abstract syntax for representation, encoding, transmission, and decoding. DER can represent Distinguished Encoding Rules, which is one of the encoding rules conforming to ASN.1 syntax. Other preset signature formats can be user-defined or other signature formats, such as Basic Encoding Rules (BER), Canonical Encoding Rules (CER), Packed Encoding Rules (PER), and XML Encoding Rules (XER), etc. This application does not impose any restrictions on these.
[0117] To better understand the above implementation methods, this application provides several specific embodiments as examples for illustration.
[0118] Example 1 The target signature data format of the target effective frame is determined using the first syntax element in the security parameter set. Specifically, a first syntax element marked "0" indicates that the target signature data format is PLAIN; a first syntax element marked "1" indicates that the target signature data format is ASN.1 / DER; and a first syntax element marked "2~3" indicates that the target signature data format is another preset signature data format, i.e., a reserved item.
[0119] The relevant syntax elements in the security parameter set corresponding to this embodiment are as follows:
[0120] The specific semantics of other syntactic elements of the security parameter set in this embodiment can be referred to the specific semantics of the above embodiments, and will not be repeated here.
[0121] The specific semantics of the syntactic element signature_fmt are as follows: The signature data format signature_fmt is a 2-bit unsigned integer used to indicate the signature data format, i.e., the target signature data format.
[0122] In this embodiment, the specific specifications of the signature data format signature_fmt are shown in the following table:
[0123] Example 2 The target signature data format of the target effective frame is determined by the first syntax element in the security parameter set. The first syntax element signature_fmt is marked as "0" to indicate that the target signature data format is ASN.1 / DER; the first syntax element signature_fmt is marked as "1" to indicate that the target signature data format is other preset signature data format, which is a reserved item.
[0124] In this embodiment, the specific definition of the signature data format syntax element signature_fmt is shown in the following table:
[0125] The relevant syntax elements in the security parameter set corresponding to this embodiment can be referred to in the specific implementation of the above embodiments, and will not be repeated here.
[0126] Example 3 The target signature data format of the target effective frame is determined by the first syntax element in the security parameter set. The first syntax element signature_fmt is marked as "0" to indicate that the target signature data format is PLAIN; the first syntax element signature_fmt is marked as "1" to indicate that the target signature data format is ASN.1 / DER.
[0127] In this embodiment, the specific definition of the signature data format syntax element signature_fmt is shown in the following table:
[0128] The relevant syntax elements in the security parameter set corresponding to this embodiment can be referred to in the specific implementation of the above embodiments, and will not be repeated here.
[0129] S22: Obtain the target bitstream data using the security parameter set and the video bitstream.
[0130] The target signature data format (i.e., security parameter set) of the aforementioned target effective frame and the video bitstream can be encapsulated into the bitstream to obtain the target bitstream data. Additionally, the authentication data of the video bitstream can also be encapsulated into the bitstream to obtain the target bitstream data.
[0131] Please see Figure 9 , Figure 9This is a flowchart illustrating a third embodiment of the video stream authentication method of this application. The specific steps of the video stream authentication method in this embodiment can be executed using the aforementioned encoding end. The method may include the following steps: S31: Sign the video stream to obtain authentication data; wherein, the second syntactic element is used to determine the target signature data format of the authentication data.
[0132] For network abstraction layer units that serve as authentication data, the video bitstream can be signed to obtain authentication data. The target signature data format can be determined using a second syntactic element within the authentication data. The target signature data format can be PLAIN, ASN.1 / DER, or other preset signature data formats; this application does not impose any restrictions on this.
[0133] To better understand the above implementation methods, specific embodiments are provided below as examples for illustration.
[0134] Example 4 The target signature data format of the authentication data is determined using a second syntactic element in the authentication data. The specific syntactic elements in the authentication data corresponding to this embodiment are as follows:
[0135] The specific semantics of other syntactic elements of the authentication data in this embodiment can be referred to the specific semantics of the above embodiments, and will not be repeated here.
[0136] The specific semantics of the syntactic element auth_data_fmt are as follows: The signature data format `auth_data_fmt` is a 1-bit unsigned integer used to indicate the signature data format, i.e., the target signature data format. The specific rules for the signature data format `auth_data_fmt` are shown in the table below:
[0137] In this context, the syntax element auth_data_fmt marked as "0" indicates that the target signature data format for the authentication data is PLAIN; the syntax element auth_data_fmt marked as "1" indicates that the target signature data format for the authentication data is ASN.1 / DER.
[0138] It is understood that the specific marking implementation process of using the second syntactic element in the authentication data to determine the target signature data format of the authentication data in this application can refer to the specific marking implementation process of using the first syntactic element in the security parameter set to determine the target signature data format of the target effective frame described above. Furthermore, the aforementioned syntactic element can also mark the target signature data format in other ways, which are not limited herein.
[0139] S32: Obtain the target bitstream data using the authentication data and video bitstream.
[0140] The target bitstream data can be obtained by using the authentication data and video bitstream as described above. In other words, the security parameter set, video bitstream and authentication data can be encapsulated into the bitstream to obtain the target bitstream data.
[0141] The above scheme provides a method for determining the signature data format in the security parameter set and / or authentication data. This can standardize the signature data format in the authentication data, that is, it can provide the decoding end with specific format information of the signature data in the signature verification process, reduce the uncertainty of the signature data format in the signature verification process, increase the standardization of the authentication data, and thus improve the efficiency and effectiveness of authentication.
[0142] In some embodiments, the target signature data format can be marked in the network abstraction layer unit or the tag name data format can be pre-set in a standard SVC or similar format. The target signature data format is at least one preset signature data format.
[0143] In some embodiments, authentication rules for authentication information, such as at least one of the target signature data format and target authentication validity, can be set in the standard codec files at the encoding and decoding ends.
[0144] In some implementations, when the target signature data format is a preset signature data format, such as a fixed signature data format, the target signature data format is used by the decoding end to verify the signature according to a preset signature data format during the decoding process of the target bitstream data. If the signature verification is successful, the authentication result of the video bitstream is determined to be successful.
[0145] In some implementations, when the target signature data format is one of multiple preset signature data formats, the target signature data format is used by the decoding end to verify the signature according to the multiple preset signature data formats during the decoding process of the target bitstream data. If at least one preset signature format is successfully verified, the authentication result of the video bitstream is determined to be successful. For example, several allowed preset signature data formats can be specified as the target signature data format. During the signature verification process, the decoding end can perform subsequent signature verification processing on the signature data (authentication data) corresponding to the several allowed preset signature data formats respectively. If one of the data formats is successfully verified, the authentication result of the video bitstream is determined to be successful.
[0146] To better understand the above implementation methods, specific embodiments are provided below as examples for illustration.
[0147] As an example, the target signature data format can be set to PLAIN or ASN.1 / DER. After receiving the target bitstream data, the decoding end decodes it to obtain the authentication data. The authentication data format is identified as PLAIN or ASN.1 / DER, and subsequent signature verification and decryption processes are performed according to the PLAIN and ASN.1 / DER formats respectively. If one of the formats is successfully authenticated, the authentication data of the video bitstream is considered successfully authenticated.
[0148] As an example, the target signature data format can be set to ASN.1 / DER. The signature processing generates authentication data, and the signature verification process verifies the signature according to the ASN.1 / DER format to obtain verification data. That is, all input data for verification data must be in ASN.1 / DER format. If the signature verification is successful, the authentication is successful.
[0149] As an example, the target signature data format can be set to PLAN. The signing process generates authentication data, and the verification process verifies the signature according to the PLAN format to obtain verification data. That is, all input data for the verification data must be in PLAN format. If the verification is successful, authentication is successful. In this process, the signature data generated during signing, the verification data received before verification, and the input data for the verification data all need to be in PLAN format.
[0150] The above scheme can standardize the signature data format in the authentication data, that is, it can provide the decoding end with specific format information of the signature data during the signature verification process, and process it according to the prescribed format during the signing and verification process. In addition, several available signature data formats can be specified, so that the decoding end can perform authentication in different formats during signature verification, or a fixed signature data format can be specified for authentication. This can reduce the uncertainty of the signature data format during the signature verification process, increase the standardization of the authentication data, and thus improve the efficiency and effectiveness of authentication.
[0151] Please see Figure 10 , Figure 10 This is a flowchart illustrating the fourth embodiment of the video stream authentication method of this application. The specific steps of the video stream authentication method in this embodiment can be executed using the aforementioned encoding end. The method may include the following steps: S41: The target authentication validity of the target effective frame is determined by using a third syntax element in the security parameter set. The target effective frame is at least a portion of the image frames of the video stream within the effective range of the security parameter set.
[0152] In some implementations, the network abstraction layer unit includes the target authentication validity. The network abstraction layer unit is at least one of a security parameter set and authentication data. Syntactic elements can be added to the security parameter set and / or authentication data to mark the target authentication validity of the authentication data.
[0153] In some implementations, the target authentication validity of the target effective frame may include: (1) The validity of the encoded image frame bitstream is valid, which means that the bitstream of the target effective frame is complete and correct, but the content of its decoded image frame can refer to other image frames, and it cannot be determined whether its decoded image frame is complete and correct. If the target authentication validity mark of the image frame is that the validity of the encoded image frame bitstream is valid, it means that the encoded image of the image frame, that is, the bitstream, is correct.
[0154] (2) The validity of the encoded image frame bitstream is valid, and the validity of the corresponding decoded image frame is also valid. That is, the bitstream of the target effective frame is complete and correct, and the content of its decoded image frame is also complete and correct. This process needs to consider the reference relationship between frames. Before signing, it is determined that all the reference frames of the authentication frames have corresponding authentication data, or the reference frames of the target effective frame are all authenticated. For example, frames such as P frames that contain inter-frame prediction need to refer to the content of other frames. If the referenced other frames are also authenticated, then the target authentication validity of the P frame can be determined as the validity of the encoded image frame bitstream of the P frame is valid, and the validity of the corresponding decoded image frame is also valid. That is, the reference frames are also authenticated during decoding, which can make the decoded and reconstructed image complete and correct.
[0155] The aforementioned target authentication validity can also represent the level of authentication validity, meaning the encoded image frame bitstream is valid, or both the encoded and decoded image frames are valid. After the authentication data of the target valid frame is successfully authenticated, it can be determined that the encoded image frame bitstream of the target valid frame is complete and correct, or that both the encoded and decoded image frame bitstreams of the target valid frame are complete and correct.
[0156] The target authentication validity of the target effective frame can be marked using a third syntactic element in the security parameter set. The target effective frame is at least a portion of the image frames in the video stream within the effective range of the security parameter set. This embodiment is illustrated using an example that includes all image frames. The target authentication validity of the target effective frame can represent the validity of image frames within the effective range of the security parameter set, and this application does not impose any limitations on this.
[0157] In some embodiments, image frames within the effective range of the security parameter set, such as target effective frames, can be obtained. It is also determined whether the image frame requires authentication. If authentication is required, it is determined whether the reference frames of the image frame require authentication. If all reference frames require authentication, the target validity of the image frame is marked as valid for the encoded image frame bitstream, and the validity of the decoded image frame corresponding to the encoded image frame bitstream is also marked as valid. If there are reference frames that do not require authentication, the target validity of the image frame is marked as valid for the encoded image frame bitstream.
[0158] In some embodiments, the target effective range can also be marked in the security parameter set. The target authentication validity and the target effective range of the target valid frame can be determined using a third syntactic element in the security parameter set. The target effective range includes all or part of the image frames in the video stream that are within the effective interval of the security parameter set. This method can represent the validity and authentication range of image frames within the effective interval of the security parameter set.
[0159] To better understand the above implementation methods, specific embodiments are provided below as examples for illustration.
[0160] Example 5 Adding a third syntactic element, authentication_level_flag, to the security parameter set indicates the target authentication validity of the target effective frame, i.e., the authentication validity level.
[0161] The relevant syntax elements in the security parameter set corresponding to this embodiment are as follows:
[0162] The specific semantics of other syntactic elements of the security parameter set in this embodiment can be referred to the specific semantics of the above embodiments, and will not be repeated here.
[0163] The values and meanings of the `authentication_level_flag` syntax element are as follows: 0: All frames within the effective range of this security parameter set, if authenticated, only guarantee that their bitstream is complete and correct.
[0164] 1. For all frames within the effective range of this security parameter set, if authenticated, the authentication not only guarantees the integrity and correctness of the frame's bitstream, but also the correctness of the content in its decoded image. That is, before signing, it is necessary to ensure that all reference frames for the authenticated frames have corresponding authentication data.
[0165] Example 6 The third syntactic element `authentication_level` in the security parameter set can represent the target authentication validity and the target validity range of the target valid frame. The target validity range includes all or a portion of the image frames in the video stream that fall within the validity interval of the security parameter set.
[0166] The relevant syntax elements in the security parameter set corresponding to this embodiment are as follows:
[0167] The specific semantics of other syntactic elements of the security parameter set in this embodiment can be referred to the specific semantics of the above embodiments, and will not be repeated here.
[0168] The values and meanings of the `authentication_level` syntax element are as follows: 0: All frames within the effective range of this security parameter set participate in authentication; all authenticated frames are guaranteed to have a complete and correct bitstream and a complete and correct decoded image.
[0169] 1: All frames within the effective range of this security parameter set participate in authentication; authentication frames can guarantee the integrity and correctness of the bitstream, but cannot guarantee the integrity and correctness of the decoded image.
[0170] 2: Some frames within the effective range of this security parameter set participate in authentication; all authenticated frames can guarantee that the bitstream is complete and correct and the decoded image is complete and correct.
[0171] 3: Some frames within the effective range of this security parameter set participate in authentication; the authentication frame can guarantee the integrity and correctness of the bitstream, but cannot guarantee the integrity and correctness of the decoded image.
[0172] Furthermore, an example is given for illustration. For instance, it is specified that all frames within a random access interval (RL frame) are authenticated, but knowledge image frames referenced by frames within the random access interval are not authenticated. In this case, the value of the syntax element `authentication_level` in the security parameter set corresponding to the RL frame should be 1, meaning that authentication of all frames within this interval only guarantees that their bitstream is complete and correct.
[0173] S42: Obtain the target bitstream data using the security parameter set and the video bitstream.
[0174] The target authentication validity and video bitstream of the aforementioned target effective frame can be used to obtain the target bitstream data. In other words, the aforementioned security parameter set, video bitstream, and authentication data can be encapsulated into a bitstream to obtain the target bitstream data.
[0175] The above method can mark the target authentication validity of the target effective frame in the security parameter set, so that the validity of the authentication data of the target effective frame can be determined during the signature verification process. In addition, the target effective scope of the target authentication can also be marked, making the marking and authentication processes of validity authentication more flexible.
[0176] Please see Figure 11 , Figure 11 This is a flowchart illustrating the fifth embodiment of the video stream authentication method of this application. The specific steps of the video stream authentication method in this embodiment can be executed using the aforementioned encoding end. The method may include the following steps: S51: Sign the video stream to obtain authentication data; wherein, the fourth syntactic element is used in the authentication data to determine the target authentication validity of the authentication data.
[0177] Syntactic elements can be added to the authentication data of the video stream to mark the target authentication validity of the authentication data, that is, the authentication validity of the image frame to which the authentication data belongs.
[0178] In some implementations, the target authentication validity of the target valid frame may include any of the following: the validity of the encoded image frame bitstream is valid; the validity of the encoded image frame bitstream is valid, and the validity of the decoded image frame corresponding to the encoded image frame bitstream is valid. The target authentication validity mentioned above may also represent a level of authentication validity, such as the validity of the encoded image frame bitstream being valid, or the validity of both the encoded image frame bitstream and the decoded image frame being valid.
[0179] To better understand the above implementation methods, specific embodiments are provided below as examples for illustration.
[0180] Example 7 Adding a fourth syntactic element, authentication_level_flag, to the authentication data indicates the target authentication validity, or authentication validity level.
[0181] The relevant syntactic elements in the authentication data corresponding to this embodiment are as follows:
[0182] The specific semantics of other syntactic elements of the authentication data in this embodiment can be referred to the specific semantics of the above embodiments, and will not be repeated here.
[0183] The values and meanings of the `authentication_level_flag` syntax element are as follows: 0: Subsequent verification data authentication of all frames only indicates that their bitstream is complete and correct.
[0184] 1. Not only is the bitstream of this frame complete and correct, but the content in its decoded image is also correct. That is, before signing, it was determined that all the reference frames of the authentication frames had corresponding authentication data.
[0185] In addition, specific examples are given to illustrate this.
[0186] As an example, the value of the syntax element `authentication_level_flag` can be determined based on the frame authentication and reference relationships in the authentication data. For instance, if the syntax element `hash_discard_library_pictures_flag` in the security parameter set of a video bitstream is marked as 1, it means that knowledge image features are not authenticated. Then, the syntax element `authentication_level_flag` in the authentication data of other frames that subsequently reference this knowledge image frame should be marked as 0, meaning that the authentication validity of the (encoded image frame bitstream) is complete and correct, but the completeness and correctness of the decoded content of these frames cannot be guaranteed.
[0187] For example, if all frames within the random access interval where the IDR frame is located are continuously authenticated together, the authentication_level_flag syntax element in the generated authentication data should be marked as 1, which means that all frames with authentication validity can not only guarantee that the bitstream is correct and complete, but also that their decoded images are correct and complete.
[0188] Among them, the IDR frame (Instantaneous Decoding Refresh) is a special type of I-frame. It is a concept proposed to serve encoding and decoding. The role of the IDR frame is to refresh immediately so that errors do not propagate. Starting from the IDR frame, a new sequence is recalculated and encoding begins. When the decoder receives the IDR frame, it refreshes the reference image buffer. That is to say, frames after the IDR frame will not refer to frames before the IDR frame.
[0189] S52: Obtain the target bitstream data using the authentication data and video bitstream.
[0190] The security parameter set, video stream, and the aforementioned authentication data can be encapsulated into the stream to obtain the target stream data.
[0191] The above scheme can mark the target authentication validity of the target effective frame in the authentication data, so that the validity of the authentication data of the target effective frame can be determined during the signature verification process, making the authentication more standardized.
[0192] In some embodiments, the above embodiments can be combined with or referenced by each other, such as combining the embodiments to obtain other new embodiments. For example, syntactic elements are used to mark the target authentication validity and / or target signature data format in the security parameter set authentication data. The target bitstream data is obtained by following the parameter set, video bitstream, and authentication data. This application does not limit this.
[0193] The above scheme, by adding syntactic elements to mark the validity of the target authentication, can display whether the marked frame authentication can guarantee the correctness of its decoded image, and can provide more standardized and clear information for subsequent display and authentication information feedback functions.
[0194] In some embodiments, for the above-described examples, the authentication validity related to the hierarchical coding technique can also be marked. See the following examples for details.
[0195] Please see Figure 12 , Figure 12 This is a flowchart illustrating the sixth embodiment of the video stream authentication method of this application. The specific steps of the video stream authentication method in this embodiment can be executed using the aforementioned encoding end. The method may include the following steps: S61: Use the fifth syntactic element in the authentication data to determine the hierarchical authentication information of the authentication data; wherein, the hierarchical authentication information includes: whether it is authentication data of an enhancement layer image.
[0196] In some implementations, SVC (Scaled Video Coding) technology can be used for encoding. Scaled Video Coding is a technology that can divide a video stream into multiple layers of resolution, quality, and frame rate, and it is an extension of the H.264 video codec standard used in most video conferencing devices today.
[0197] Layered coding involves dividing the video signal into multiple layers (including a base layer and enhancement layers) based on temporal, spatial, and qualitative dimensions. The base layer data allows the decoder to extract the basic video content. Enhancement layers can be encoded in multiple layers; within the total bitrate of the video stream, a higher received bitrate generally results in better video quality. SVC (Single-Layer Coding) technology encodes the video signal in layers. When bandwidth is insufficient, only the base layer bitrate is transmitted and decoded, resulting in low-quality video. As bandwidth increases, enhancement layer bitrates can be transmitted and decoded, improving the overall video decoding quality.
[0198] The fifth syntactic element can be used in the authentication data to determine the layered authentication information of the authentication data, that is, whether it is authentication data for an enhancement layer image. For example, if the fifth syntactic element is marked as "1", it means that the authentication data is authentication data for an enhancement layer image; if it is marked as "0", it means that the authentication data is not authentication data for an enhancement layer image, but authentication data for a base layer image.
[0199] In some implementations, if the authentication data is the authentication data of the enhancement layer image, then information such as the enhancement layer image data layer ID and the number of consecutive authentication frames is further obtained. In some application scenarios, the authentication status of the base layer image referenced by the enhancement layer image can also be obtained, such as whether the base layer image has been authenticated.
[0200] In some implementations, if the layered authentication information is authentication data for the enhancement layer image, then steps S62 or S63 can be performed.
[0201] S62: In response to the layered authentication information being the authentication data of the enhancement layer image, and the base layer image referenced by the enhancement layer image not being authenticated, the target authentication validity of the authentication data of the enhancement layer image is determined as follows: the validity of the encoded image frame bitstream is valid.
[0202] When the authentication data is the authentication data of the enhancement layer, it can be determined whether the base layer image referenced by the enhancement layer image has been authenticated. If the base layer image referenced by the enhancement layer image is not authenticated, the target authentication validity of the authentication data of the enhancement layer image is determined as follows: the validity of the encoded image frame bitstream is valid, which means that the bitstream (encoded image) of the enhancement layer image is complete and correct.
[0203] S63: In response to the layered authentication information being authentication data for the enhancement layer image, and the basic layer image referenced by the enhancement layer image being authenticated, and other reference frames referenced by the enhancement layer image being authenticated, the target authentication validity of the authentication data for the enhancement layer image is determined as follows: the validity of the encoded image frame bitstream is valid, and the validity of the decoded image frame corresponding to the encoded image frame bitstream is valid.
[0204] When the authentication data is for the enhancement layer, we can determine whether the base layer image referenced by the enhancement layer image has been authenticated, and whether other reference frames have been authenticated. If the base layer image referenced by the enhancement layer image has been authenticated, and other reference frames referenced by the enhancement layer image have been authenticated, then the target authentication validity of the enhancement layer image's authentication data is determined to be: the validity of the encoded image frame bitstream is valid, and the validity of the corresponding decoded image frame is valid. In other words, both the bitstream (encoded image) and the decoded image of the enhancement layer image are complete and correct.
[0205] In some embodiments, the layered authentication information may include: whether the authentication data is the authentication data of the enhancement layer image when the video stream meets the conditions for supporting spatial layered coding. For example, meeting the conditions for supporting spatial layered coding means that the current video stream supports SVC spatial layering technology.
[0206] In some implementations, the layered authentication information may include: whether the video bitstream meets the conditions for supporting spatial layered coding, and whether the authentication data is the authentication data of the enhancement layer image when the video bitstream meets the conditions for supporting spatial layered coding.
[0207] To better understand the above implementation methods, specific embodiments are provided below as examples for illustration.
[0208] Example 8 A fourth syntactic element, `authentication_level_flag`, is added to the authentication data to represent the target authentication validity, i.e., the authentication validity level. A fifth syntactic element, `ssvc_is_independent_authentication`, is used to represent the layered authentication information of the authentication data; this layered authentication information includes whether the authentication data is for an enhancement layer image.
[0209] The relevant syntactic elements in the authentication data corresponding to this embodiment are as follows:
[0210] The specific semantics of other syntactic elements of the authentication data in this embodiment can be referred to the specific semantics of the above embodiments, and will not be repeated here.
[0211] The values and meanings of the `authentication_level_flag` syntax element are as follows: 0: Authentication of all frames of the authentication data only indicates that the bitstream is complete and correct.
[0212] 1. Not only is the bitstream of this frame complete and correct, but the content in its decoded image is also correct. That is, before signing, it was determined that all the reference frames of the authentication frames had corresponding authentication data.
[0213] The `ssvc_is_independent_authentication` syntax element indicates whether the authentication data is authentication data for the enhancement layer image. Additionally, the `SsvcIsIndependentAuthentication` syntax element indicates that the authentication data is authentication data for the enhancement layer image, the `ssvcId` syntax element represents the enhancement layer image data layer ID, and the `successive_hash_pictures_spatial` syntax element represents the number of consecutive authentication frames.
[0214] In some implementations, during enhancement layer image verification, it can be determined whether the referenced base layer image is authenticated. If the referenced base layer image is not authenticated, the value of the `authentication_level_flag` syntax element of the enhancement layer image authentication data should be 0. If the referenced base layer image is authenticated, and other reference frames are also authenticated, the value of the `authentication_level_flag` syntax element of the enhancement layer image authentication data should be 1.
[0215] Example 9 A fourth syntactic element, `authentication_level_flag`, is added to the authentication data to indicate the target authentication validity, i.e., the authentication validity level. A fifth syntactic element, `ssvc_is_independent_authentication`, is used to represent the layered authentication information of the authentication data; this layered authentication information may include whether the authentication data is the authentication data of the enhancement layer image when the video stream supports spatial domain layered coding.
[0216] The relevant syntactic elements in the authentication data corresponding to this embodiment are as follows:
[0217] The specific semantics of other syntactic elements of the authentication data in this embodiment can be referred to the specific semantics of the above embodiments, and will not be repeated here.
[0218] The values and meanings of the `authentication_level_flag` syntax element are as follows: 0: Authentication of all frames of the authentication data only indicates that the bitstream is complete and correct.
[0219] 1. Not only is the bitstream of this frame complete and correct, but the content in its decoded image is also correct. That is, before signing, it was determined that all the reference frames of the authentication frames had corresponding authentication data.
[0220] The spatial_svc_flag syntax element indicates that the current video bitstream meets the conditions for supporting spatial layered coding, and the spatial_el_flag syntax element indicates whether the authentication data is authentication data for the enhancement layer image.
[0221] In some implementations, during enhancement layer image verification, it can be determined whether the referenced base layer image is authenticated. If the referenced base layer image is not authenticated, the value of the `authentication_level_flag` syntax element of the enhancement layer image authentication data should be 0. If the referenced base layer image is authenticated, and other reference frames are also authenticated, the value of the `authentication_level_flag` syntax element of the enhancement layer image authentication data should be 1.
[0222] The above scheme, by combining layered authentication information from the authentication data—such as whether the authentication data is from an enhancement layer image—and marking the layered authentication information and target authentication validity, can authenticate different types of layered images, such as enhancement layer images, and determine the validity of authentication data for enhancement layer images. This increases the standardization of authentication data, thereby improving authentication efficiency and effectiveness. Furthermore, this method allows for flexible configuration of the target authentication validity and target signature data format, adapting to the authentication needs of video streams in various scenarios, demonstrating strong applicability and enhancing the flexibility of video stream authentication.
[0223] Please see Figure 13 , Figure 13 This is a flowchart illustrating the seventh embodiment of the video stream authentication method of this application. The specific steps of the video stream authentication method in this embodiment can be executed using the decoding end described above. The method may include the following steps: S71: The decoding end obtains the target bitstream data, which is obtained by the encoding end through the above-mentioned video bitstream authentication method.
[0224] The encoding end can transmit the target bitstream data to the decoding end, enabling the decoding end to receive the target bitstream data. If the encoding end stores the target bitstream data, it can then be used as a decoding end to perform operations such as decoding, playback, or storage of the target bitstream data.
[0225] The target bitstream data includes a network abstraction layer unit containing authentication information, and / or authentication information is set at the encoding and decoding ends; the authentication information includes at least one authentication provision among the target signature data format and the target authentication validity, the target signature data format representing the format information for verifying the signature of the video bitstream, and the target authentication validity representing the validity of the encoded image frame bitstream and / or decoded image frame of the video bitstream; the authentication information is used by the decoding end to perform signature verification processing on the video bitstream during the decoding process of the target bitstream data.
[0226] The specific implementation method of this step can be referred to the specific implementation process of the decoding end described above, and will not be repeated here.
[0227] S72: Decode the target bitstream data to obtain the video bitstream.
[0228] Parsing or decoding the target bitstream data yields the encapsulated video bitstream and network abstraction layer units (such as authentication data and security parameter sets).
[0229] S73: Use authentication information to verify the signature of the video stream.
[0230] Authentication can be divided into signature processing and signature verification processing. Signature processing and signature verification processing require calculating the hash value of the same NAL for the same frame in the same way.
[0231] The Network Abstraction Layer (NAL) unit contains at least one of a target signature data format and a target authentication validity. The target signature data format represents the format information for verifying the signature of the video stream, and the target authentication validity represents the validity of the encoded image frame stream and / or decoded image frame stream of the video stream.
[0232] The decoding end can perform signature verification on the video stream according to the target signature data format. It compares the verification data (generated in the same way as the authentication data) corresponding to the acquired video stream with the authentication data to obtain the authentication result of the video stream. If the comparison and verification results are consistent, the authentication result of the video stream is successful; otherwise, the authentication fails.
[0233] Specifically, during the comparison and verification process, the authentication data can be decoded to obtain the signed data, which can also be called signature data. The signature data can be decrypted to obtain the hash value 1 corresponding to the video stream. The image frames of the video stream that need to be authenticated are processed using the above authentication data generation method to obtain hash value 2 (verification data). The hash values 1 and 2 are compared to determine whether the verification data and authentication data are consistent based on the comparison consistency.
[0234] In some implementations, after obtaining the authentication result of the authentication data of the image frame, the validity of the image frame can be determined by the target authentication validity corresponding to the image frame. For example, if the validity of the bitstream of the encoded image frame is valid, that is, the encoded image bitstream is complete and correct, or if the validity of the bitstream of the encoded image frame is valid and the validity of the decoded image is valid, that is, both the encoded image bitstream and the decoded image are complete and correct.
[0235] The specific implementation of this embodiment can be referred to the implementation process of the above embodiments, and will not be repeated here.
[0236] In relation to the above embodiments, this application provides an encoding end, which is used to implement the steps of the first embodiment of the video stream authentication method.
[0237] Please see Figure 14 , Figure 14 This is a schematic diagram of the structure of an embodiment of the encoding terminal of this application. The encoding terminal 80 includes an acquisition module 81 and a signature module 82. The acquisition module 81 and the signature module 82 are interconnected.
[0238] The acquisition module 81 is used to acquire the video bitstream.
[0239] The signature module 82 is used to sign the video stream in order to obtain the target stream data.
[0240] The target bitstream data includes a network abstraction layer unit containing authentication information, and / or authentication information is set at the encoding and decoding ends; the authentication information includes at least one authentication provision among the target signature data format and target authentication validity, the target signature data format representing the format information for signature verification processing of the video bitstream, and the target authentication validity representing the validity of the encoded image frame bitstream and / or decoded image frame bitstream of the video bitstream; the authentication information is used by the decoding end to perform signature verification processing on the video bitstream during the decoding process of the target bitstream data.
[0241] The specific implementation of this embodiment can be referred to the implementation process of the above embodiments, and will not be repeated here.
[0242] In accordance with the above embodiments, this application provides a decoding end, which is used to implement the steps of the second embodiment of the video stream authentication method.
[0243] Please see Figure 15 , Figure 15 This is a schematic diagram of the structure of an embodiment of the decoding terminal of this application. The decoding terminal 90 includes a receiving module 91, a decoding module 92, and a signature verification module 93. The receiving module 91, the decoding module 92, and the signature verification module 93 are interconnected.
[0244] The receiving module 91 is used to acquire target bitstream data, wherein the target bitstream data is obtained by the encoding end using the aforementioned video bitstream authentication method.
[0245] The decoding module 92 is used to decode the target bitstream data to obtain the video bitstream.
[0246] The signature verification module 93 is used to perform signature verification processing on the video stream using authentication information.
[0247] The target bitstream data includes a network abstraction layer unit containing authentication information, and / or authentication information is set at the encoding and decoding ends; the authentication information includes at least one authentication provision among the target signature data format and target authentication validity, the target signature data format representing the format information for signature verification processing of the video bitstream, and the target authentication validity representing the validity of the encoded image frame bitstream and / or decoded image frame bitstream of the video bitstream; the authentication information is used by the decoding end to perform signature verification processing on the video bitstream during the decoding process of the target bitstream data.
[0248] The specific implementation of this embodiment can be referred to the implementation process of the above embodiments, and will not be repeated here.
[0249] Regarding the above embodiments, this application provides a computer device; please refer to [link / reference]. Figure 16 , Figure 16 This is a schematic diagram of the structure of a computer device according to an embodiment of the present application. The computer device 200 includes a memory 201 and a processor 202, wherein the memory 201 and the processor 202 are coupled to each other. The memory 201 stores program data, and the processor 202 executes the program data to implement the steps of any embodiment of the video stream authentication method described above. The computer device 200 can serve as the encoding end and / or decoding end in the video encoding / decoding system of the above embodiments, executing the steps of any embodiment of the video stream authentication method described above.
[0250] In this embodiment, processor 202 can also be referred to as CPU (Central Processing Unit). Processor 202 may be an integrated circuit chip with signal processing capabilities. Processor 202 can also be a general-purpose processor, digital signal processor (DSP), application-specific integrated circuit (ASIC), field-programmable gate array (FPGA), or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component. The general-purpose processor can be a microprocessor, or processor 202 can be any conventional processor.
[0251] The methods described in the above embodiments can be implemented as computer programs; therefore, this application proposes a computer-readable storage medium. Please refer to [link to relevant documentation]. Figure 17 , Figure 17 This is a schematic diagram of a computer-readable storage medium according to an embodiment of the present application. The computer-readable storage medium 300 stores program data 301 that can be executed by a processor. The program data 301 can be executed by the processor to implement the steps of any embodiment of the video stream authentication method described above.
[0252] In this embodiment, the computer-readable storage medium 300 can be a USB flash drive, a portable hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, or a medium that can store program data 301. Alternatively, it can be a server that stores the program data 301, which can send the stored program data 301 to other devices for execution, or it can self-run the stored program data 301.
[0253] In the several embodiments provided in this application, it should be understood that the disclosed methods and apparatus can be implemented in other ways. For example, the apparatus implementations described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0254] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment, depending on actual needs.
[0255] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0256] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause an electronic device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods of the various embodiments of this application.
[0257] Obviously, those skilled in the art should understand that the modules or steps of this application described above can be implemented using general-purpose computing devices. They can be centralized on a single computing device or distributed across a network of multiple computing devices. Optionally, they can be implemented using computer-executable program code, and thus stored in a computer-readable storage medium for execution by a computing device, or they can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Therefore, this application is not limited to any particular hardware and software combination.
[0258] The above description is merely an embodiment of this application and does not limit the patent scope of this application. Any equivalent structural or procedural transformations made using the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.
Claims
1. A method for authenticating video streams, characterized in that, include: The encoding end acquires the video bitstream; The video stream is signed to obtain the target stream data; The target bitstream data includes a network abstraction layer unit containing authentication information, and / or authentication information is set at the encoding and decoding ends; The authentication information includes at least one of the following authentication provisions: target signature data format and target authentication validity. The target signature data format represents the format information for verifying the signature of the video stream. The target authentication validity indicates that the validity of the encoded image frame stream in the video stream is valid, or that the validity of the encoded image frame stream is valid and the validity of the corresponding decoded image frame is valid. The authentication information is used by the decoding end to perform signature verification on the video stream during the decoding process of the target stream data.
2. The method according to claim 1, characterized in that, The target signature data format of the video stream is marked with syntactic elements in the network abstraction layer unit; and / or, the target authentication validity is marked with syntactic elements in the network abstraction layer unit; The network abstraction layer unit is at least one of a security parameter set and authentication data, wherein the authentication data is obtained by signing the video stream.
3. The method according to claim 2, characterized in that, The network abstraction layer unit contains the target signature data format, and the network abstraction layer unit is a set of security parameters; The step of signing the video stream to obtain the target stream data includes: The target signature data format of the target effective frame is determined by the first syntactic element in the security parameter set, and the target effective frame is the image frame of the video stream within the effective range of the security parameter set; The target bitstream data is obtained using the security parameter set and the video bitstream.
4. The method according to claim 2, characterized in that, The network abstraction layer unit contains the target signature data format, and the network abstraction layer unit is authentication data; The step of signing the video stream to obtain the target stream data includes: The video stream is signed to obtain the authentication data; The target bitstream data is obtained using the authentication data and the video bitstream; The target signature data format of the authentication data is determined by using a second syntactic element.
5. The method according to any one of claims 1 to 4, characterized in that, The target signature data format is at least one preset signature data format; When the target signature data format is a preset signature data format, the target signature data format is used by the decoding end to verify the signature according to the preset signature data format during the decoding process of the target bitstream data. If the signature verification is successful, the video bitstream is determined to be successfully authenticated. or, When the target signature data format is one of multiple preset signature data formats, the target signature data format is used by the decoding end to verify the signature according to the multiple preset signature data formats during the decoding process of the target bitstream data. If the signature verification of at least one preset signature format is successful, the video bitstream authentication is determined to be successful.
6. The method according to claim 1, characterized in that, The network abstraction layer unit contains the target authentication validity, and the network abstraction layer unit is at least one of a security parameter set and authentication data; the signature processing of the video bitstream to obtain the target bitstream data includes: The target authentication validity of the target effective frame is determined using a third syntactic element in the security parameter set, wherein the target effective frame is at least a portion of the image frames of the video stream within the effective range of the security parameter set; and / or, The video stream is signed to obtain the authentication data; wherein, the fourth syntactic element is used in the authentication data to determine the target authentication validity of the authentication data.
7. The method according to claim 6, characterized in that, The target authentication validity of the target effective frame includes any of the following: The encoded image frame bitstream is valid; The encoded image frame bitstream is valid, and the decoded image frame corresponding to the encoded image frame is also valid.
8. The method according to claim 6, characterized in that, The method further includes: The target authentication validity and the target validity range of the target authentication validity are determined using a third syntactic element in the security parameter set. The target effective range includes all or part of the image frames of the video stream within the effective range of the security parameter set.
9. The method according to claim 6, characterized in that, The method further includes: The fifth syntactic element is used to determine the hierarchical authentication information of the authentication data; wherein, the hierarchical authentication information includes: whether it is authentication data of an enhancement layer image.
10. The method according to claim 9, characterized in that, The method further includes: In response to the layered authentication information being the authentication data of the enhancement layer image, and the base layer image referenced by the enhancement layer image not being authenticated, the target authentication validity of the authentication data of the enhancement layer image is determined as follows: the validity of the encoded image frame bitstream is valid; or, In response to the layered authentication information being the authentication data of the enhancement layer image, and the basic layer image referenced by the enhancement layer image being authenticated, and other reference frames referenced by the enhancement layer image being authenticated, the target authentication validity of the authentication data of the enhancement layer image is determined to be: the validity of the encoded image frame bitstream is valid, and the validity of the decoded image frame corresponding to the encoded image frame is valid.
11. The method according to claim 9, characterized in that, The layered authentication information includes: whether the authentication data is the authentication data of the enhancement layer image when the video bitstream meets the conditions for supporting spatial layered coding.
12. A method for authenticating video streams, characterized in that, include: The decoding end acquires target bitstream data, wherein the target bitstream data is obtained by the encoding end performing the video bitstream authentication method according to any one of claims 1 to 11; The target bitstream data is decoded to obtain the video bitstream; The authentication information is used to verify the signature of the video stream; The target bitstream data includes a network abstraction layer unit containing authentication information, and / or authentication information is set at the encoding end and the decoding end; the authentication information includes at least one authentication provision among a target signature data format and a target authentication validity, the target signature data format representing the format information for signature verification processing of the video bitstream, and the target authentication validity indicating that the validity of the encoded image frame bitstream in the video bitstream is valid, or that the validity of the encoded image frame bitstream is valid and the validity of the corresponding decoded image frame is valid; the authentication information is used by the decoding end to perform signature verification processing on the video bitstream during the decoding process of the target bitstream data.
13. A computer device, characterized in that, It includes a memory and a processor coupled to each other, the memory storing program data, and the processor executing the program data to implement the steps of the method according to any one of claims 1 to 11, and / or, to implement the steps of the method according to claim 12.
14. A computer-readable storage medium, characterized in that, The system stores program data that can be executed by a processor, the program data being used to implement the steps of the method according to any one of claims 1 to 11, and / or to implement the steps of the method according to claim 12.
Citation Information
Patent Citations
Scalable authentication method based on H264 / SVC video streams
CN107172431A
Video signal source encryption and decryption system and method based on AVS2 entropy coding of block encryption
CN112533001A