Coherent image encryption
By modifying the phase value of coherent image data and using mask deformation techniques, secure encryption of coherent image data is achieved, ensuring the feasibility of single-image analysis while preventing coherent image analysis, and providing flexible security level control.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ICE EYE CO
- Filing Date
- 2022-10-10
- Publication Date
- 2026-05-26
AI Technical Summary
Existing technologies struggle to both ensure the analyzability of individual images and prevent information leakage during coherent image analysis when encrypting coherent image data.
By modifying the phase value of the image data to ensure that the phase change rate between adjacent pixels does not exceed the bandwidth of the imaging signal, and by using mask deformation technology for encryption, the feasibility of single-image coherence technology is ensured, while the implementation of multi-image coherence technology is prevented.
It achieves secure encryption of coherent image data, allows single-image analysis while preventing coherent image analysis, and provides flexible security level control.
Smart Images

Figure CN118103842B_ABST
Abstract
Description
Technical Field
[0001] This application relates to a method for encrypting coherent image data. In particular, the present invention relates to a method for encrypting image data without losing coherence within the image. Background Technology
[0002] Information and data security is becoming an increasingly important and ubiquitous part of modern society. The need to maintain the security of data and information is now paramount. Such data can include personal information, company information, state-owned data, and other data. One method used to ensure data security is to encrypt data using encryption keys to prevent access, reading, and / or editing by entities without a copy of the encryption key.
[0003] Image data is one of many forms of data that data owners may wish to keep secure. Image data can refer to any form of data collected by an imaging device and stored in a multidimensional array. Typically, image data is stored in a two-dimensional array, where each element of the array defines the attributes of a pixel in the image. Image data can be encrypted by applying an encryption key to each pixel of the image, thereby randomizing one or more attributes of each pixel's properties.
[0004] In modern systems, it has been recognized that a set of coherent images contains more information than the information contained in each individual image within that set alone. In other words, the coherence between images in a set of coherent images can provide additional information. This information is typically derived using coherence analysis techniques. A set of coherent images can be obtained by periodically imaging the same target from the same distance and orientation. For example, in satellite imaging, a satellite can generate a set of coherent images by producing an image of a specific target each time the satellite completes its orbit around the Earth (i.e., if the satellite images the same location on the Earth's surface every time it passes the same point above the Earth, the set of images obtained by the satellite will be coherent with each other).
[0005] One such coherent technique is coherent change detection (CCD). CCDs detect changes between coherent images that are unlikely to be visible to the human eye. This is because the sensitivity of a CCD is only a fraction of the wavelength of light used to collect the image. For example, in the context of radar imaging, a CCD can resolve centimeter-level changes from images collected by a satellite. In the context of synthetic aperture radar (SAR) imaging, CCDs provide users with the ability to see minute differences between two SAR images at a resolution exceeding that of “naked-eye” analysis.
[0006] Another coherent technique used in SAR imaging is digital elevation model (DEM) generation. A DEM utilizes subtle differences in location between two coherent images. The phase information associated with each pixel in each coherent image is then compared, highlighting variations relative to a reference plane. In other words, in SAR imaging, phase information can be used to infer the height of features in an image relative to a reference "zero" height. DEM generation allows this height data to be obtained from the phase variation information via phase unfolding, forming a three-dimensional digital elevation model of the area.
[0007] The third coherent technique used in SAR imaging is Differential Interferometric Synthetic Aperture Radar (InSAR). InSAR can be considered a combination of the CCD and DEM techniques discussed above. In particular, InSAR facilitates the detection of very subtle changes in altitude over time. Satellite-generated images can be analyzed using InSAR to detect millimeter-level changes in the environment over a month. This can be used to identify a range of hazards and emerging conditions, from landslides to infrastructure collapses, such as the collapse of dams or bridges.
[0008] Given the increasing amount of information available from a set of coherent images via coherent analysis techniques (such as those discussed above), it is clear that new forms of data may require encryption to ensure their security. In some scenarios, data owners may wish to have different security levels or formats for data related to individual image analysis and data related to coherent image analysis. In other words, while data owners may want to allow data users access to each image within a set of coherent images, they may want to restrict their access to information that can be obtained via coherent analysis techniques (such as those discussed above).
[0009] The inventor designed the claimed invention based on the above considerations.
[0010] The embodiments described below are not limited to implementations that address any or all of the drawbacks of the known methods described above. Summary of the Invention
[0011] This summary is provided to introduce, in a simplified form, the concept of the selections that will be further described in the detailed embodiments below. This summary is not intended to identify key or essential features of the claimed subject matter; variations and alternative features that facilitate the work of the invention and / or achieve substantially similar technical effects should be considered to fall within the scope of this invention.
[0012] The invention is defined as set forth in the appended set of claims.
[0013] In a general sense, this invention provides a method for encrypting image data such that, while data users can still analyze individual images without decryption, the images cannot be successfully used for coherent image analysis considering other images in a set without first decrypting the image data. In other words, this invention provides data owners with the flexibility to secure information related to coherent image analysis through encryption without encrypting information related to individual image analysis.
[0014] In a first aspect of the invention, a computer-implemented method for encrypting image data is provided, wherein the image data is generated by collecting a signal having bandwidth, and the image data includes data corresponding to a plurality of pixels of an image, wherein each pixel has an associated phase value; and the method includes the step of modifying each phase value of the phase values associated with each of the plurality of pixels based on a first encryption key, wherein after the step of modifying each phase value of the phase values, the phase change rate between adjacent pixels does not exceed the bandwidth.
[0015] In some examples, images can be further encrypted using "classical" encryption techniques to gain additional security. Based on the disclosure herein, those skilled in the art will understand that any such classical encryption must encrypt the phase information within each image in a reversible manner, i.e., in such a way that the phase information can be retrieved when the classically encrypted image is decrypted. In other words, the coherent encryption method described herein can be combined with additional classical encryption techniques performed after the coherent encryption method described herein, provided that the classical encryption techniques do not irreversibly destroy the phase information encoded in each image.
[0016] In another aspect of the invention, an apparatus is provided, comprising: a processor configured to perform any of the methods disclosed herein.
[0017] In another aspect of the invention, a computer program product is provided, comprising: instructions that, when executed by a computer, cause the computer to perform any of the methods disclosed herein.
[0018] In another aspect of the invention, a computer-readable storage medium is provided, comprising: instructions that, when executed by a computer, cause the computer to perform any of the methods described herein.
[0019] The methods described herein can be executed by software in a machine-readable form on a tangible storage medium, such as a computer program comprising computer program code means adapted to perform all the steps of any of the methods described herein when the program is run on a computer, and wherein the computer program can be embodied on a computer-readable medium. Examples of tangible (or non-transitory) storage media include disks, thumb drives, memory cards, etc. The software can be adapted to execute on a parallel or serial processor, such that the method steps can be performed in any suitable order or simultaneously.
[0020] This application acknowledges that firmware and software can be valuable, separately tradable goods. It is intended to cover software that runs or controls “dumb” or standard hardware to implement desired functions. It is also intended to cover software that “describes” or defines the configuration of hardware, such as HDL (Hardware Description Language) software distributed for designing silicon chips or configuring general-purpose programmable chips to implement desired functions.
[0021] The features and embodiments discussed herein may be suitably combined, as will be apparent to those skilled in the art, and may be combined with any aspect of the invention, unless expressly stated that such combinations are impossible, or that those skilled in the art will understand that such combinations are impossibly impossible. Attached Figure Description
[0022] Embodiments of the invention are described below by way of example with reference to the accompanying drawings.
[0023] Figure 1 A simplified schematic diagram depicts an example image that can be encrypted using the method of the claimed invention.
[0024] Figure 2 This diagram illustrates a satellite collecting SAR image data while orbiting the Earth.
[0025] Figure 3a The steps of the method for the claimed invention are described.
[0026] Figure 3b A method for modifying the phase value of each pixel in an image by deforming a mask, according to some embodiments of the present invention, is described.
[0027] Figure 4a A mask that can be overlaid on an image to be encrypted is described.
[0028] Figure 4b A mask is depicted that defines a polygonal network consisting of multiple nodes, each node defining a vertex of the polygonal network.
[0029] Figure 4cA mask is depicted that deforms by adjusting the height of each node of the mask relative to the plane defined by the mask before its deformation.
[0030] Figure 5 A method is described for encrypting multiple coherent images to remove their coherence.
[0031] Figure 6a An example depicting the results of coherent change detection (CCD) between two coherent images.
[0032] Figure 6b An example depicting the results of a CCD between two images is provided, wherein the image data associated with at least one image has been encrypted according to the method described herein.
[0033] Figure 7 A computer configured to perform a method of the claimed invention is described.
[0034] Common reference numerals are used in all figures to indicate the same or similar features. Detailed Implementation
[0035] The following description illustrates embodiments of the invention by way of example only. These examples represent the best mode of practicing the invention as currently known to the applicant, although they are not the only ways to implement the invention. The description elucidates the function of the examples and the sequence of steps for constructing and operating the examples. However, the same or equivalent functions and sequences can be implemented by different examples.
[0036] Figure 1 A simplified schematic diagram of an example image 10, which can be encrypted using the method of the claimed invention, is depicted. Image 10 comprises multiple pixels, with data associated with each pixel of the image. Image 10 has been generated by detecting imaging signals that have interacted with the imaging target. This can be based on a variety of imaging techniques, including both reflection-based techniques (i.e., imaging techniques where the imaging signal is reflected from the imaging target) and transmission-based techniques (i.e., imaging techniques where the imaging signal propagates through the imaging target to the detector). A specific example of interest discussed below with respect to Figure 3 is SAR imaging performed by a satellite in orbit around the Earth, which is an example of an imaging technique based on the reflection of radar signals.
[0037] The imaging detector captures an imaging signal and its associated image data in the form of an image 10 segmented into multiple pixels. Each pixel has one or more data values associated with it, which capture information contained within the imaging signal. For example, the first pixel 12 has a first associated phase value, a second associated amplitude value, and other values. Similarly, the second pixel 14 has a second associated phase value, a second associated amplitude value, and other values.
[0038] The first and second associated amplitude values can respectively indicate the amplitude of the generated signal received at the first pixel 12 and the second pixel 14. The first and second associated amplitude values can be recorded as the luminance values of the first pixel 12 and the second pixel 14, respectively. Alternatively, the first and second associated amplitude values can be recorded in another format, such as RGB values, CMYK values, or similar values. Additionally or alternatively, in addition to the associated amplitude values, the luminance values, RGB values, and / or CMYK values, or similar values, can be recorded as data associated with each of the pixels 12, 14.
[0039] Correlation amplitude values can be used in imaging analysis to infer various properties of an imaging target. For example, in reflection-based imaging techniques, correlation amplitude values can indicate the reflectivity of the imaging target; for instance, a relatively high correlation amplitude value can indicate high reflectivity compared to a relatively low one. This can be used, for example, in qualitative analysis to determine the type of material constituting the imaging target. For instance, high reflectivity can indicate that the imaging target is formed of a reflective material such as metal. Conversely, low reflectivity can indicate a non-reflective material such as wood, concrete, leaves, or similar materials. Note that for a given material, reflectivity can be a function of the wavelength of the imaging signal, such that the material may have high reflectivity at certain wavelengths and low reflectivity at others.
[0040] Meanwhile, in projection-based imaging techniques, the correlation amplitude value can indicate the attenuation coefficient of the imaging target; for example, a relatively high correlation amplitude value can indicate a low attenuation coefficient compared to a relatively low correlation amplitude value. This can be used, for example, in qualitative analysis to determine the type of material forming the imaging target. For instance, a low attenuation coefficient can indicate that the imaging target is formed of an optically transparent material, such as glass, a transparent liquid (such as water, oil, or similar liquids), or a transparent gas (such as air, carbon dioxide, methane, or another greenhouse gas, oxygen, a rare gas, or similar gas), or any other optically transparent material. Conversely, low reflectivity can indicate an optically dense (or opaque) material, such as lead, aluminum, or any other optically dense material. Note that for a given material, the attenuation coefficient can be a function of the wavelength of the imaging signal, such that the material may have a low attenuation coefficient at certain (typically shorter) wavelengths and a high attenuation coefficient at other (typically longer) wavelengths. Typical examples of this material are greenhouse gases, or in fact many gases, which are optically transparent to visible, UV, and X-ray light, but may be optically dense for long-wavelength infrared light due to their high absorption coefficient in the infrared region of the electromagnetic spectrum.
[0041] The first and second associated phase values can respectively indicate the relative phase of the generated signals received at the first pixel 12 and the second pixel 14. The associated phase values can have values in the range of 0 to 2π, 0 to 360, -π to π, -180 to 180, or any other suitable range. Additionally, data values indicating the “unfolded” phase can be associated with each pixel of image 10. In other words, while phase information is typically encoded cyclically (recognizing that phase is a cyclically repeating property), the phase information can be unfolded to remove cyclic repetition and instead provide more direct information indicating the optical path length between the imaging target and the detector.
[0042] In some examples, the data associated with each pixel 12, 14 of image 10 can be encoded using the complex number z = x + iy. In this way, the amplitude and phase values of each pixel 12, 14 of image 10 can be encoded within a single complex number z. For example, the amplitude value can be determined by determining the amplitude of the complex number z. In other words, the amplitude value can be determined as |z| = (x... 2 +y 2 ) 1 / 2 Furthermore, for example, the phase value can be determined by determining the independent variable of the complex number z. In other words, the phase value can be determined as arg(z) = tan -1 (y / x).
[0043] Correlated phase information can be used in imaging analysis to infer various properties of an imaged target. For example, a technician will recognize that in some instances of images generated from the reflection of a signal from a target, phase information indicates the total signal path length; for instance, phase information can be expanded by the data user to determine the distance between the signal source and / or receiver and the surface from which the signal is reflected. In some practical settings, phase information is used to determine the distance of one reflecting surface relative to another. For example, in the case of aerial imaging, the phase difference between different pixels can indicate the relative height of the reflecting surface captured in each pixel. In other examples, a technician will recognize that in some instances of images generated from the projection of a signal through a target, phase information indicates the density of the target, because changes in density cause changes in the target's refractive index, and thus alter the effective optical path distance or signal path distance.
[0044] In other words, in reflection-based imaging techniques, the associated phase value can indicate the distance between the imaging target and the detector. For example, in the case of aerial imaging, the associated phase value can indicate the relative altitude of the imaging target or a component of the imaging target. This can be used to determine the distance and / or altitude distribution of the imaging target.
[0045] Meanwhile, in transmission-based imaging techniques, correlated phase values can indicate the density distribution of the imaging target. For example, changes in the density of the imaging target will cause changes in the effective optical path length of the imaging signal through the imaging target. In particular, higher-density targets will increase the effective optical path length. This can be used to determine the density distribution of the imaging target.
[0046] In some embodiments, the image, or each image, is generated by synthetic aperture radar (SAR) imaging.
[0047] While the method of the claimed invention is applicable to a wide range of images, its application has proven particularly advantageous in the context of SAR imaging. As discussed above, the claimed invention allows data users to implement single-image coherent techniques, such as autofocus procedures, multi-view processing, and / or other frequency-domain based techniques. Simultaneously, it prevents the same data user from implementing multiple-image coherent techniques, such as CCD, DEM, or InSAR.
[0048] In some embodiments, the image, or each image, is a satellite-generated image.
[0049] Data security for satellite-generated imagery is of particular importance because satellites can collect a wide range of data. It may be necessary to encrypt the data to protect individual privacy from satellite-captured images of their land. For example, inter-image coherence imaging techniques may be able to determine whether land has been occupied by determining if a person has walked across it or by proving a person's presence based on coherence imaging techniques. In other applications, state-owned data may need to be encrypted for security and / or defense purposes; for example, data related to military facilities must be kept secure for the safety of military personnel and others. Additionally, encryption of image data may be necessary to prevent customers or clients of the data owner from accessing information they have not yet been authorized to access (e.g., they may not have purchased or licensed the rights to said information).
[0050] Figure 2 This diagram illustrates satellite 20 collecting SAR image data in its orbit around Earth 22. Satellite 20 is in a repeating orbit around Earth 22, such as a daily repeating orbit. To collect SAR image data, satellite 20 reflects radar signals 24 from the surface of one or more imaging targets on the surface of Earth 22. As satellite 20 repeats its orbit, it periodically revisits the same location relative to Earth 22. Each time satellite 20 images the same imaging target from the same location relative to Earth using its radar signals, it captures another SAR image of the same imaging target. Each of these SAR images will be coherent with each other, meaning that a person or entity possessing a set of coherent images will be able to implement multi-image coherent imaging techniques such as CCD, DEM, or InSAR.
[0051] In such examples, the wavelength of the imaging signal can be a wavelength suitable for radar imaging. For example, the wavelength of imaging signal 24 can be 0.5 cm or greater, 1 cm or greater, 3 cm or greater, 5 cm or greater, or 8 cm or greater. In other examples, the wavelength of the imaging signal can be between 0.5 cm and 10 cm. In one particular embodiment, the wavelength of imaging signal 24 is approximately 3 cm.
[0052] Furthermore, the imaging signal may have an inherent bandwidth commonly found in radar imaging signals. For example, the inherent bandwidth may be 0.5 kHz or greater, 1 kHz or greater, 5 kHz or greater, or 10 kHz or greater. In one particular embodiment, the inherent bandwidth of the imaging signal 24 is approximately 4 kHz.
[0053] Furthermore, due to the Doppler effect caused by the motion of satellite 20 relative to Earth 22, the imaging signal can acquire additional bandwidth. This so-called Doppler bandwidth can be 1 MHz or greater, 10 MHz or greater, 100 MHz or greater, 500 MHz or greater, 1000 MHz or greater, or 5000 MHz or greater. In one particular embodiment, due to the orbit of satellite 20 around Earth 22, the Doppler bandwidth of imaging signal 24 is approximately 300 MHz.
[0054] In some examples, the imaging target of satellite 20 may be a geographic region on the surface of Earth 22. The size of this region may be 10 square kilometers or more, 50 square kilometers or more, 100 square kilometers or more, 1,000 square kilometers or more, 5,000 square kilometers or more, or 10,000 square kilometers or more.
[0055] For example, each image in the image can be 5 km × 5 km or larger, 10 km × 10 km or larger, 50 km × 50 km or larger, or 100 km × 100 km or larger.
[0056] In such examples, a single pixel of image 10 can image an area of 0.1 square meters or larger, 0.5 square meters or larger, 1 square meter or larger, 2 square kilometers or larger, or 5 square kilometers or larger. For example, each pixel of image 10 can correspond to an area of 0.25 meters × 0.25 meters or larger, 0.5 meters × 0.5 meters or larger, 1 meter × 1 meter or larger, 1.5 meters × 1.5 meters or larger, or 2 meters × 2 meters or larger. In one particular embodiment, each pixel of image 10 corresponds to a 1-meter × 1-meter area of the imaging target.
[0057] Figure 3aThe steps of this method are described. In step S300, unencrypted image data in the form of image 10 is provided to the data owner. Image 10 is captured by an imaging signal. The imaging signal includes a range of wavenumbers (the reciprocal of the wavelength), which defines the bandwidth of the imaging signal. The bandwidth can be determined by down-converting the frequency of the imaging signal to effectively remove the carrier frequency associated with the signal. Before down-conversion, the bandwidth of the imaging signal can span from a lower non-zero frequency / wavenumber to a higher non-zero frequency / wavenumber. The bandwidth can be defined as the difference between the higher non-zero frequency / wavenumber and the lower non-zero frequency / wavenumber. After down-conversion, the bandwidth can span from zero frequency / wavenumber to a higher down-converted non-zero frequency / wavenumber. The higher down-converted non-zero frequency / wavenumber can be equal to the value of the bandwidth. In step S310, a first encryption key is provided to the data owner. The first encryption key can be generated by generating a random seed. In step S320, the phase values associated with each pixel 12, 14 in image 10 are modified based on the first encryption key, such that the rate of phase change between adjacent pixels does not exceed the bandwidth of the imaging signal after encryption. This encryption does not prevent data users from performing amplitude-based analysis or single-image coherent image analysis, such as autofocus procedures, multi-view processing, and other frequency-domain based techniques. However, it does prevent those without the first encryption key from performing multi-image coherent image analysis, such as CCD, DEM, or InSAR. Finally, in step S330, an encrypted image is generated as the output of the encryption process.
[0058] Encrypting the phase information associated with image data allows data owners to set different levels of security for the image data. For example, encrypting the phase information can leave other information, such as amplitude information associated with the image data, unaffected. This selective encryption of phase information means that data users are permitted to access and review only a subset of the information associated with the image data. For example, a data user could be permitted to review information indicating the spatial intensity of the imaging signal, which can be encoded by the amplitude value associated with each pixel of the image.
[0059] When the associated phase value of each pixel 12, 14 of image 10 is modified, the rate of phase change between adjacent pixels of the encrypted image does not exceed the bandwidth of the imaging signal. Meeting this criterion means that the sampling wavenumber range is wider than the bandwidth of the imaging signal (including the encrypted phase signal), and that single-image coherent imaging technology as described above can be achieved. In other words, by modifying the phase value of each pixel in this way, the coherence of the image itself is not compromised. Simultaneously, the modification of the phase information encrypts the image data, making the phase difference between the encrypted image and other (unencrypted) images no longer meaningfully calculateable or determinable. In other words, while conventional methods of encrypting phase information result in the destruction of the phase information, making both intra-image and inter-image phase differences impossible to calculate or determine, the claimed invention provides an encryption method that prevents the calculation or determination of inter-image phase differences while allowing the continued calculation or determination of intra-image phase differences. If this criterion is not followed, the phase information is effectively destroyed, and single-image coherent imaging technology becomes impossible.
[0060] This further facilitates increased selective control by the data owner over the encryption level of certain images. For example, by encrypting image data according to the methods described herein, data users will be able to implement certain analytical techniques that rely on calculating or determining phase differences within images. These analytical techniques may include, for example, autofocus procedures, multi-view processing, and / or other frequency-domain based techniques. Such analytical techniques can be more generally described as single-image coherent techniques. Simultaneously, data users will be prevented from implementing multi-image coherent techniques, such as CCD, DEM, or InSAR, that rely on calculating or determining phase differences between images.
[0061] In instances where the signal comprises more than one bandwidth, such as in satellite-based SAR imaging where the imaging signal has both inherent bandwidth and Doppler bandwidth, the phase change rate discussed above may need to not exceed the maximum bandwidth within which the method described herein is operable. In some examples, the phase change rate discussed above may not exceed the minimum bandwidth associated with the signal, so that information encoded in frequencies associated with lower bandwidths may not be lost during the encryption process described herein.
[0062] In some embodiments, encrypting image data associated with the image or each image includes: selecting a portion of the image or each image to be encrypted; and encrypting the portion by modifying each phase value of the phase values associated with each of a plurality of pixels within the selected portion based on a first encryption key.
[0063] In this way, data owners are given selective control over further enhanced levels of encryption for image data. For example, a data owner can choose to encrypt one or more regions of a given image while leaving others unencrypted, thus masking the given region (or regions) of interest. In some examples, a data owner can encrypt data associated with the central region of the image, leaving one or more boundary regions unencrypted. In other examples, a data owner can encrypt data associated with regions of the image that image a specific object of interest, leaving the rest of the image unencrypted.
[0064] Figure 3b The invention describes how, according to some embodiments of the invention, a mask 40 (see below) is made... Figures 4a to 4c The discussion focuses on methods for modifying the phase value of each pixel in an image using deformation. Figure 3b The steps described in the text can replace Figure 3a Step S320 in the process. Figure 3b In step S322, a mask 40 is overlaid on the unencrypted image 10. In step S324, the mask 40 is deformed based on the first encryption key. For example, before deformation, the mask 40 may be a flat plane overlaid on the image 10. Deforming the mask may involve adjusting the height of certain segments of the mask relative to the plane defined by the image 10. Thus, in effect, the deformed mask 46 may be visualized as “wrinkled” or “crimped” relative to the mask 40 before its deformation. In step S326, the phase value of each pixel of the image 10 is modified based on the deformed mask 46. In other words, the phase value of each pixel of the image 10 can be modified by assuming that the relative position of the pixels has been modified according to the deformation of the mask.
[0065] In some examples, the mask may have a zero phase value associated with each point of the mask before deformation. Deforming the mask may involve associating a new phase value with each point of the deformed mask based on the adjusted height of said points. Modifying the phase of each pixel may then involve adding (or subtracting) a new phase value associated with the corresponding pixel of the deformed mask in image 10 to the phase value associated with said pixel.
[0066] In other words, in some embodiments, the method further includes: overlaying a corresponding mask on the image or each image to be encrypted, wherein modifying each phase value among the phase values associated with each pixel of a plurality of pixels in the image or each image to be encrypted involves: deforming the mask based on a first encryption key, and modifying each phase value among the phase values associated with each pixel of a plurality of pixels in the image or each image based on the deformation of the mask. In fact, the mask can be a tool through which the first encryption key is implemented to coherently encrypt one or more images to be encrypted.
[0067] The provision of a mask and its subsequent deformation provide a mechanism by which phase value modification can be gradually varied pixel-by-pixel, such that the rate of phase change across the image does not exceed the wavenumber bandwidth of the imaging signal. Modifying the phase of each pixel of an image based on mask deformation provides data owners with a means to ensure that the degree of modification does not suffer from abrupt discontinuities or high rates of change, as the mask can be continuously deformed to ensure compliance with bandwidth constraints on the rate of phase change across pixels.
[0068] In some embodiments, the deformed mask associated with each of the one or more images to be encrypted may have undergone different deformations.
[0069] By deforming the mask associated with each image differently, the phase information of each image is modified accordingly, and thus any coherence between any pairs of images can be removed, thereby encrypting the information encoded in the images for image coherence analysis (such as CCD, DEM generation, or InSAR).
[0070] In some embodiments, the deformation of the mask or each mask can also be based on a nonlinear function.
[0071] In some embodiments, the corresponding function defining the mask for the deformation or the gradient of each deformed mask may be discontinuous.
[0072] By nonlinearly deforming and / or deforming the mask to create discontinuities in the mask's gradient (also known as "low-order derivative discontinuities"), the phase changes between adjacent pixels (after the phase of each pixel has been modified based on the mask deformation) become significantly less predictable, thus making encryption more secure.
[0073] Figure 4a A mask 40 is depicted that can be overlaid on the image 10 to be encrypted.
[0074] Figure 4b A mask 40 depicts a plurality of interconnected nodes 42 comprising a defined polygonal network 44.
[0075] Figure 4c A deformed mask 46 is depicted, which has been deformed by adjusting the height of each of the plurality of nodes 42 relative to the plane defined by the mask 40 before its deformation.
[0076] In some embodiments, the respective mask or each respective mask includes multiple nodes, and deforming the mask involves adjusting the height of each node relative to the respective image based on a first encryption key.
[0077] In some examples, the mask can be deformed such that it is defined by continuous gradients between the mask's nodes. This can subsequently ensure that there are no discontinuities in the rate of phase change between pixels, allowing intra-image phase differences to be computed or determined, thus facilitating single-image coherence analysis techniques. Additionally, by deforming the mask based on adjusting the corresponding height of each node relative to the plane defined by the mask before its deformation, the computational cost can be reduced, as the degree of deformation of a segment of the mask can be interpolated based on the adjusted node height, which is the opposite of requiring a new adjusted height for each segment of the mask corresponding to the pixels of the image. Therefore, by adjusting the deformation of each node relative to the corresponding height of the plane defined by the mask before its deformation, the computational cost of deformation is reduced, making the overall approach more efficient.
[0078] Other methods are also possible to deform the mask so that the rate of change of phase information between adjacent pixels remains below the bandwidth of the image signal. For example, the mask can be a plane that is continuously deformed based on a mathematical function. The deformation of the mask can include "dents" or other perturbations. Perturbations can be defined by one or more curves and / or by one or more sharp edges. In fact, any kind of parametric deformation can be used as long as the phase change rate requirement is met. The parameters of the parametric surface can then be encrypted to provide security, just as the nodes of the surface described above are encrypted.
[0079] Since the mask deformation is based on the first encryption key, adjusting the node height to deform the mask also allows for a simpler encryption key. In other words, instead of requiring an unreasonably long encryption key, the encryption key can be shortened to an appropriate and manageable length because each pixel of the image needs to be encrypted individually based on the first encryption key. By facilitating the interpolation of the mask between the adjusted nodes, the overall computational cost of encryption is reduced.
[0080] In some embodiments, the position of each of the plurality of nodes in the corresponding mask is determined based on a second encryption key.
[0081] In this way, the security of the encrypted data is further enhanced. Specifically, since the position of each node in the mask is determined based on a second encryption key, no two masks will be identical if they are encrypted using different encryption keys. This means that not only is the phase information of the original image data kept confidential through encryption, but also, any "eavesdropper" or other entity attempting to illegally obtain the phase information data cannot even determine the qualitative nature of the modification to each phase value. In particular, without the second encryption key, once the mask has been deformed, no person or entity will know its structure, thus preventing them from reversing the encryption.
[0082] In some embodiments, the first and second encryption keys are the same.
[0083] In this way, the computational cost and burden of encrypting image data are reduced, because only one encryption key needs to be stored and used as the basis for mask deformation.
[0084] In some embodiments, the first and second encryption keys are different.
[0085] In this way, the security of image data is enhanced because anyone or any entity attempting to illegally obtain phase information data will need to crack not just one, but two separate encryption keys.
[0086] The data owner, or anyone else encrypting the image data, can choose whether the first and second encryption keys are the same or different, as needed. For example, if the data owner has strict requirements regarding processing speed or data storage, the first and second encryption keys can be the same. In other examples, if the data owner has very strict data security requirements, the data owner can choose to have different first and second encryption keys.
[0087] In some embodiments, each of one or more nodes defines a corresponding vertex of a polygonal network defined by a mask.
[0088] In some embodiments, each of one or more nodes defines the corresponding center of a polygon in a polygonal network defined by a mask.
[0089] In this way, the gradient of the deformed mask can be controlled such that when the phase value is modified based on the mask deformation, the rate of phase change between adjacent pixels does not exceed the bandwidth of the wavenumber of the imaging signal. In some examples, the deformation of each edge of each polygon is based on linear interpolation between nodes that define the mutually distant endpoints of the edge. Furthermore, the edges of each polygon can define points of discontinuity in the gradient of the deformed mask. In this way, as discussed above, the phase change between adjacent pixels (after the phase of each pixel has been modified based on the mask deformation) becomes significantly less predictable, and thus the encryption becomes more secure.
[0090] In some embodiments, the edges connecting the vertices of a polygon network are limited to maximize the area of each polygon in the polygon network.
[0091] In this way, discontinuities in phase transitions can be further avoided. In other words, maximizing the area of each polygon in the polygonal network also helps ensure that the rate of phase change between adjacent pixels does not exceed the bandwidth of the wavenumber of the imaging signal. The process of maximizing the area of each polygon in the polygonal network can be achieved through appropriate optimization algorithms. For example, the polygonal network can be constrained by Delaunay triangulation or another similar algorithm or method.
[0092] Each polygon in the polygon network 44 may span a number of pixels in the image 10. For example, the area of each polygon in the polygon network 44 (e.g., each triangle of the network defined by Delaunay triangles) may span an area equivalent to 10 pixels × 10 pixels or larger, 50 pixels × 50 pixels or larger, 100 pixels × 100 pixels or larger, 150 pixels × 150 pixels or larger, or 200 pixels × 200 pixels or larger. In a particular example, the polygon network 44 is defined by Delaunay triangles, and each triangle spans an area equivalent to 100 pixels × 100 pixels or larger.
[0093] In some examples, each polygon of the polygon network can be defined by an alternative method of Delaunay triangulation. For example, the polygon network can be defined by Voronoi tessellation or another similar process, wherein each polygon is defined by referencing one of the nodes of the polygon network. In the case of Voronoi tessellation, each node defines the center of the corresponding polygon of the polygon network, wherein the corresponding polygon defines the trajectory of points for which the corresponding node is the node closest to the trajectory among a plurality of nodes.
[0094] In some embodiments, each of the one or more images to be encrypted is encrypted using a distinct second encryption key.
[0095] In this way, the security of encrypted data is enhanced because each of the multiple coherent images is further encrypted independently. Therefore, even if a person or entity illegally decrypts one of the images, they will not be able to decrypt the other encrypted images and thus cannot recover their coherence.
[0096] In some embodiments, the first encryption key and / or the second encryption key are generated based on a random seed.
[0097] In this way, the confidentiality of the first encryption key and / or the second encryption key is maintained because it is impossible to reliably predict the outcome of the random seed generation process.
[0098] By adding multiple nodes 42 to the mask, the mask 40 can be used to define a polygon network 44. The positions of the nodes 42 can be determined using a second encryption key. The second encryption key can be generated using a random seed. In some instances, the second encryption key can be the same as the first encryption key, while in other instances, the first and second encryption keys can be different.
[0099] Multiple interconnected nodes 42 are connected by a series of edges to define a polygonal network. The polygonal network 44 may include repeating tessellations similar to polygons. For example, in... Figure 4b In the example depicted, the polygon network 44 comprises a series of triangles, in some cases equilateral triangles. The polygon network 44 can be configured to maximize the area of each polygon in the network. Figure 4b In the example, this is achieved by implementing the Delonay triangle procedure. Technicians will realize that other appropriate optimization algorithms may be suitable.
[0100] Deforming mask 40 to generate deformed mask 6 involves adjusting the relative height of each of the plurality of nodes 42 based on a first encryption key. This causes Figure 4c The wrinkled, deformed mask 46 depicted in the image provides a basis for encrypting the image data by adjusting the phase values associated with each pixel 12, 14 of the image 10 when the mask is overlaid on the image 10.
[0101] Figure 5 A method is described for encrypting multiple coherent images to remove their coherence. In step S500, multiple coherent images are provided to the data owner / encryptor. Figure 2 As depicted, multiple coherent images can be collected from satellite 20, which is in a daily repeating orbit around Earth 22, via SAR imaging. In step S520, according to... Figures 3a to 3bThe method(s) described herein encrypts image data of one or more images among a plurality of coherent images such that coherence between each encrypted image and every other image among the plurality of coherent images is removed. In step S530, a stack of coherently encrypted images is output.
[0102] In other words, in some embodiments, the method further includes: providing a plurality of coherent images, wherein each of the plurality of coherent images is associated with corresponding image data; and encrypting the image data associated with one or more of the plurality of coherent images by implementing the method of the first aspect on the image data associated with each of the one or more images respectively, wherein encrypting the one or more images removes the coherence between each of the one or more encrypted images and each other of the plurality of coherent images.
[0103] The method discussed in this paper can ensure that data users are prevented from implementing multi-image coherence techniques, such as CCD, DEM, or InSAR, which rely on calculating or determining the phase difference between images by removing the coherence between each encrypted image and each other in a plurality of coherent images.
[0104] As discussed above, Figure 5 The method described allows data users to implement single-image coherent techniques on each image, such as autofocus procedures, multi-view processing, and / or other frequency-domain based techniques. At the same time, it prevents the same data user from implementing multiple-image coherent techniques, such as CCD, DEM, or InSAR, on a stack of coherently encrypted images unless they are provided with a first encryption key.
[0105] In some embodiments, image data associated with each of the one or more images is encrypted using a distinct first encryption key.
[0106] In this way, the security of encrypted data is enhanced because each of the multiple coherent images is encrypted independently. Therefore, even if a person or entity illegally decrypts one of the images, they cannot decrypt the other encrypted images and thus cannot recover their coherence.
[0107] Figure 6a An example of the CCD results between two coherent images is shown. It can be seen that CCD image 62 depicts the results of successful coherent change detection, including details of several geographic features.
[0108] Figure 6bAn example of the result of a CCD is depicted between two images, where image data associated with at least one image has been encrypted according to the method described herein. It is readily apparent that features identifiable in CCD image 62 are unidentifiable in the "encrypted" CCD image 64. Figure 6b In the example depicted, as discussed above, the encrypted image data has been encrypted using a mask generated by the Delaunay triangle. In the "encrypted" CCD image 64, triangle artifacts, a result of the Delaunay triangle, can be seen. However, it can also be seen that the triangle artifacts do not produce information about the underlying image data accessible when the image is not encrypted.
[0109] Figure 7 An example computer 70 configured to perform the methods of the claimed invention is depicted. Computer 70 includes a communication interface 71, a signal generator module 72, a detector module 73, a memory unit 74, a processor 75, and one or more additional modules 76. Computer 70 may be an onboard computer on a satellite 20 orbiting the Earth 22 that collects SAR image data. Alternatively, computer 70 may be a land-based computer configured to communicate with satellite 20 via communication interface 71. The communication interface may also be configured to facilitate communication between computer 70 and a server or between computer 70 and a user.
[0110] The signal generator module 72 may include instructions or logic that, when executed by the computer 70 or by the satellite 20 which has received the instructions or logic via the communication interface 71, cause the imaging signal 24 to be generated. The detector module 73 may include instructions or logic that, when executed by the computer 70 or by the satellite 20 which has received the instructions or logic via the communication interface 71, cause the computer 70 or the satellite 20 (as the case may be) to detect / receive the imaging signal 24, which includes image data to be encrypted, and to store the image data in the memory unit 74.
[0111] The processor 75 is configured to perform the method of the claimed invention. This may include configuring the processor 75 to perform... Figure 3a , Figure 3b or Figure 5 The image data associated with image 10 may be encrypted using any of the methods described herein. The processor 75 may implement the method by executing instructions or logic contained in a computer-readable medium or computer program product. One or more encrypted images may be stored in memory 74 or transmitted to a data user or data owner via communication interface 71.
[0112] Computer 70 may include one or more additional modules 76. These modules may include, but are not limited to, one or more additional processors configured to analyze image data collected by detector module 73. The one or more additional modules 76 may also include one or more additional processors configured to calibrate the received / detected image data, for example, by calibrating the image data collected by detector module 73 based on the incident angle of imaging signal 24, or they may be configured to perform operations for image analysis, such as InSAR, CCD, or DEM image analysis techniques.
[0113] In some embodiments, the methods for encrypting image data described herein are reversible.
[0114] In this way, data owners gain greater flexibility in determining the security level of their data. For example, a data owner can determine that a data user who previously had no access to phase information related to image-to-image coherence imaging techniques has been authorized. In such cases, the data owner can simply provide the data user with one or more encryption keys needed to reverse encryption (i.e., decrypt the data) instead of recollecting the data to send to the newly authorized user.
[0115] In the above embodiments, the method can be performed on a server. The server may include a single server or a network of servers. In some examples, server functionality may be provided by a network of servers distributed across geographical regions, such as a globally distributed server network, and a user can connect to the appropriate server in the network based on, for example, the user's location.
[0116] For clarity, the above description discusses embodiments of the invention with reference to a single user or data owner. It should be understood that in practice, the system can be shared by multiple users and / or owners, and may be shared simultaneously by a very large number of users and / or owners.
[0117] The above embodiments are fully automated. In some examples, the system user or operator may manually guide some steps of the method to be implemented.
[0118] In the described embodiments of the invention, the method can be performed by a system. This system can be implemented as any form of computing and / or electronic device. Such a device may include one or more processors, which may be a microprocessor, a controller, or any other suitable type of processor for processing computer-executable instructions to control the operation of the device in order to collect and record routing information. In some examples, for instance, when using a system-on-a-chip architecture, the processor may include one or more fixed-function blocks (also referred to as accelerators) that implement a portion of the method in hardware (rather than software or firmware). Platform software, including an operating system or any other suitable platform software, may be provided at the computing-based device to enable application software to execute on that device.
[0119] The various functions described herein can be implemented in hardware, software, or any combination thereof. If implemented in software, these functions can be stored on or transmitted thereon as one or more instructions or code. Computer-readable media can include, for example, computer-readable storage media. Computer-readable storage media can include volatile or non-volatile, removable or non-removable media implemented using any method or technique for storing information such as computer-readable instructions, data structures, program modules, or other data. Computer-readable storage media can be any available storage medium accessible by a computer. For example, and not limitingly, such computer-readable storage media can include RAM, ROM, EEPROM, flash memory or other memory devices, CD-ROM or other optical disc storage, disk storage or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and is accessible by a computer. As used herein, disks and platters include compact discs (CDs), laser discs, optical discs, digital versatile discs (DVDs), floppy discs, and Blu-ray (RTM) discs (BD). Furthermore, the propagation of signals is not included within the scope of computer-readable storage media. Computer-readable media also includes communication media, which includes any medium that facilitates the transfer of computer programs from one place to another. For example, a connection can be a communication medium. For instance, software transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave is included in the definition of communication media. Combinations of the above should also be included within the scope of computer-readable media.
[0120] Alternatively or additionally, the functionality described herein may be performed at least in part by one or more hardware logic components. For example, and not limitingly, the hardware logic components that may be used may include field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), complex programmable logic devices (CPLDs), etc.
[0121] It should be understood that the computing device used to implement the method of the claimed invention can be a distributed system. Thus, for example, several devices can communicate via a network connection and collectively perform tasks described as being performed by the computing device.
[0122] It should be understood that the computing device implementing the method of the claimed invention can be located remotely and accessed via a network or other communication link (e.g., using a communication interface).
[0123] As used herein, the term "computer" refers to any device that has processing power that enables it to execute instructions. Those skilled in the art will recognize that such processing power is incorporated into many different devices, and therefore the term "computer" includes PCs, servers, mobile phones, personal digital assistants, and many other devices.
[0124] Those skilled in the art will recognize that storage devices used to store program instructions can be distributed across a network. For example, a remote computer can store examples of processes described as software. A local or terminal computer can access the remote computer and download part or all of the software to run the program. Alternatively, a local computer can download software fragments as needed, or execute some software instructions on a local terminal and some software instructions on a remote computer (or computer network). Those skilled in the art will also recognize that, by utilizing conventional techniques known to them, all or part of the software instructions can be implemented by dedicated circuitry (such as DSPs, programmable logic arrays, etc.).
[0125] It should be understood that the above benefits and advantages may relate to one embodiment or several embodiments. These embodiments are not limited to those that solve any or all of the stated problems or have any or all of the stated benefits and advantages. Variations should be considered to be included within the scope of this invention.
[0126] Any reference to the term "a" refers to one or more of these terms. As used herein, the term "comprising" means including the identified method steps or elements, but such steps or elements are not included in an exclusive list, and a method or apparatus may include additional steps or elements.
[0127] As used herein, the terms "component" and "system" are intended to cover a computer-readable data storage configured with computer-executable instructions that, when executed by a processor, enable certain functions to be performed. Computer-executable instructions may include routines, functions, etc. It should also be understood that a component or system may reside on a single device or be distributed across several devices.
[0128] Furthermore, as used herein, the term “exemplary” is intended to mean “serving as an illustration or example of something.”
[0129] Furthermore, with regard to the use of the term "includes" in the detailed description or claims, such terms are intended to be inclusive in a manner similar to how the term "comprising" is interpreted when "comprising" is used as a transitional word in a claim.
[0130] Furthermore, the actions described herein may include computer-executable instructions that can be implemented by one or more processors and / or stored on one or more computer-readable media. Computer-executable instructions may include routines, subroutines, programs, threads of execution, etc. Moreover, the results of the actions of these methods may be stored in a computer-readable medium, displayed on a display device, etc.
[0131] The order of steps in the methods described herein is exemplary, but these steps may be performed in any suitable order, or simultaneously where appropriate. Additionally, steps may be added to or substituted in either method, or individual steps may be deleted from either method, without departing from the scope of the subject matter described herein. An aspect of any of the examples described above may be combined with aspects of any other example described to form further examples without losing the desired effect.
[0132] It should be understood that the description of the preferred embodiments above is given by way of example only, and various modifications can be made by those skilled in the art. The content already described above includes examples of one or more embodiments. Of course, it is not possible to describe every possible modification and variation of the above-described apparatus or method for the purpose of describing the foregoing aspects, but those skilled in the art will recognize that many further modifications and arrangements of various aspects are possible. Therefore, the described aspects are intended to cover all such changes, modifications, and variations that fall within the scope of the appended claims.
Claims
1. A computer-implemented method for encrypting image data, wherein, The image data is generated by collecting signals, which have bandwidth, and The image data includes data corresponding to multiple pixels of the image, wherein each pixel has an associated phase value; and The method includes the following steps: Based on the first encryption key, each phase value among the phase values associated with each of the plurality of pixels is modified, wherein after the step of modifying each phase value, the phase change rate between adjacent pixels does not exceed the bandwidth.
2. The method according to claim 1, further comprising: Provide a plurality of coherent images, wherein each of the plurality of coherent images is associated with corresponding image data; and The image data associated with the one or more images is encrypted by implementing the method of claim 1 on the image data associated with each of one or more of the plurality of coherent images. Encrypting the one or more images removes the coherence between each encrypted image and each other image in the plurality of coherent images.
3. The method according to claim 2, wherein, The image data associated with each of the one or more images is encrypted using a different first encryption key.
4. The method according to any one of the preceding claims, wherein, Encrypting the image data associated with the image or each image includes: Select the image or a portion of each image to be encrypted; and The portion is encrypted by modifying each phase value associated with each of the plurality of pixels within the selected portion based on the first encryption key.
5. The method according to claim 4, wherein, The selected portion to be encrypted is the image or the central portion of each image.
6. The method according to claim 1, further comprising: Overlaying a corresponding mask on the image to be encrypted or each image, wherein modifying each of the phase values associated with each of the plurality of pixels of the image to be encrypted or each image involves: The mask is deformed based on the first encryption key, and The phase value associated with each of the phase values, respectively, of the image to be encrypted or each of the plurality of pixels in each image, is modified based on the deformation of the mask.
7. The method according to claim 2 or 3, further comprising: Overlaying a corresponding mask on the image to be encrypted or each image, wherein modifying each of the phase values associated with each of the plurality of pixels of the image to be encrypted or each image involves: The mask is deformed based on the first encryption key, and The phase value associated with each of the phase values, respectively, of the image to be encrypted or each of the plurality of pixels in each image, is modified based on the deformation of the mask.
8. The method according to claim 7, wherein, The deformed mask associated with each of the one or more images to be encrypted has undergone a distinct deformation.
9. The method according to claim 7, wherein, The deformation of the mask, or each mask, is also based on a nonlinear function.
10. The method according to claim 7, wherein, The corresponding function defining the deformation mask or the gradient of each deformation mask is discontinuous.
11. The method according to claim 7, wherein, The respective mask, or each respective mask, comprises multiple nodes, and deforming the mask involves adjusting the height of each node relative to the respective image based on the first encryption key.
12. The method according to claim 11, wherein, The position of each of the plurality of nodes in the corresponding mask is determined based on the second encryption key.
13. The method according to claim 12, wherein, The first encryption key and the second encryption key are the same.
14. The method according to claim 12, wherein, The first encryption key and the second encryption key are different.
15. The method according to claim 12, wherein, Each of the one or more images is encrypted using a distinct second encryption key.
16. The method according to claim 6, wherein, The deformation of the mask, or each mask, is also based on a nonlinear function.
17. The method according to claim 6 or 16, wherein, The corresponding function defining the deformation mask or the gradient of each deformation mask is discontinuous.
18. The method according to claim 6 or 16, wherein, The respective mask, or each respective mask, comprises multiple nodes, and deforming the mask involves adjusting the height of each node relative to the respective image based on the first encryption key.
19. The method according to claim 18, wherein, The position of each of the plurality of nodes in the corresponding mask is determined based on the second encryption key.
20. The method according to claim 19, wherein, The first encryption key and the second encryption key are the same.
21. The method according to claim 19, wherein, The first encryption key and the second encryption key are different.
22. The method according to claim 19, wherein, The second encryption key is generated based on a random seed.
23. The method according to claim 18, wherein, Each of the plurality of nodes defines a corresponding vertex of a polygonal network defined by the mask.
24. The method according to claim 18, wherein, Each of the plurality of nodes defines the corresponding center of a polygon in a polygonal network defined by the mask.
25. The method according to claim 23, wherein, The edges connecting the vertices of the polygon network are defined to maximize the area of each polygon in the polygon network.
26. The method according to any one of claims 1 to 3, 6 and 16, wherein, The images, or each image, are generated through synthetic aperture radar imaging.
27. The method according to any one of claims 1 to 3, 6 and 16, wherein, The image, or each image, is a satellite-generated image.
28. The method according to any one of claims 1 to 3, 6 and 16, wherein, The first encryption key was generated based on a random seed.
29. The method according to any one of claims 1 to 3, 6 and 16, wherein, The method for encrypting image data is reversible.
30. An apparatus comprising: A processor configured to perform the method according to any one of the preceding claims.
31. A computer program product, comprising: Instructions that, when the program is executed by a computer, cause the computer to perform the method according to any one of claims 1 to 29.
32. A computer-readable medium comprising: Instructions, when executed by a computer, cause the computer to perform the method according to any one of claims 1 to 29.
33. A stack of one or more coherent images comprising image data, wherein, Image data associated with at least one of the one or more coherent images is encrypted using the method according to any one of claims 1 to 29.