A Video Stream Encryption Method and Device Based on a Trusted Execution Environment

By adopting an asymmetric algorithm encryption method based on a trusted execution environment in video stream encryption, the key security problem in traditional video encryption solutions is solved, and the secure encryption and decryption of video streams is realized, ensuring the security of user privacy.

CN119094818BActive Publication Date: 2025-06-27HE FEI AN YONG XIN XI KE JI YOU XIAN GONG SI
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311545215.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-11-20
Publication Date
2025-06-27
Estimated Expiration
2043-11-20

AI Technical Summary

Technical Problem

Traditional video encryption solutions have key security issues in cameras, and operators and hackers may obtain encryption keys, resulting in user privacy data breaches.

Method used

Using a video stream encryption method based on a trusted execution environment, the acquisition terminal and the playback terminal pre-generate asymmetric algorithm key pairs, randomly generate stream cipher parameters in the trusted execution environment, and decrypt video stream data using public key encryption and private keys.

Benefits of technology

Ensure that video transmission is more secure and reliable, prevent key leakage, protect user privacy, and realize secure encryption and decryption of video streams.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119094818B_ABST
    Figure CN119094818B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of video data encryption, and specifically relates to a video stream encryption method and device based on a trusted execution environment. The method includes: the acquisition terminal randomly generates stream cipher parameters RP within the trusted execution environment, encrypts the parameters RP with the public key of the corresponding user, and packages them into data packets; the playback terminal generates an encryption key based on a key negotiation algorithm for encrypting frame metadata, where the frame metadata includes video frame timestamps and stream cipher parameters, and sends the encrypted frame metadata to the server module; the acquisition terminal uses the parameter RP as the stream cipher parameter, generates a corresponding stream cipher based on the video frame size, encrypts the video stream data by XORing with the stream cipher, and pushes it to the server module after encryption; the present invention realizes the asymmetric algorithm encryption and stream encryption of the video stream by the acquisition terminal and the playback terminal, ensures that the video transmission is more secure and reliable, and ensures that the user with the device and the corresponding playback terminal can decrypt and view the video.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of video data encryption, and particularly relates to a video stream encryption method and device based on a trusted execution environment. Background Art

[0002] Cameras are used more and more widely and are prone to exposing users' private data, such as home cameras. Since the security of the traditional encryption key cannot be guaranteed, there is still a risk of data leakage. Currently, common solutions are as follows:

[0003] Currently, common video encryption solutions are TLS encryption or frame-by-frame encryption. However, for cameras containing user privacy, such as home bedroom cameras, the above encryption solutions still have the following problems:

[0004] 1. The operator can obtain the encryption key, and the video is unencrypted for the operator's personnel.

[0005] 2. There are security risks in the camera encryption environment. After the camera is hacked, hackers can obtain the encryption key.

[0006] Therefore, for cameras containing user privacy, how the users who own the devices can decrypt the video safely is an urgent problem to be solved by those skilled in the art. Summary of the Invention

[0007] The purpose of the present invention is to provide a video stream encryption method and device based on a trusted execution environment to solve the problems raised in the background art.

[0008] The present invention achieves the above purpose through the following technical solutions:

[0009] A video stream encryption method based on a trusted execution environment is applied to a collection terminal, a playback terminal, and a server module. The collection terminal and the playback terminal pre-generate an asymmetric algorithm key pair including a public key and a private key. The encryption method includes:

[0010] S1: The collection terminal randomly generates a stream cipher parameter RP within the trusted execution environment, encrypts the parameter RP with the public key of the corresponding playback terminal user, and packages it into a data packet; the playback terminal generates an encryption key based on a key negotiation algorithm for encrypting frame metadata, where the frame metadata includes a video frame timestamp and a stream cipher parameter, and sends the encrypted frame metadata to the server module;

[0011] S2: The collection terminal uses the parameter RP as the stream cipher parameter, generates a corresponding stream cipher based on the video frame size, encrypts the video stream data by XORing it with the stream cipher, and pushes it to the server module after encryption;

[0012] S3: The playback terminal obtains the updated frame metadata from the server module. After the playback terminal pulls the video stream from the video server, the playback terminal decrypts the frame metadata with the private key to obtain the stream cipher encryption parameter RP, generates the corresponding stream cipher based on the parameter RP and the video frame size; and decrypts the video stream data after XORing it with the stream cipher.

[0013] As a further optimized solution of the present invention, the acquisition terminal includes a video acquisition module running on Linux and a video encryption module running in a trusted execution environment.

[0014] As a further optimized solution of the present invention, the playback terminal includes a video playback module and a video decryption module. The video playback module runs on Windows, Android, or Linux systems, and the video decryption module runs in a trusted execution environment or on Windows, Android, or Linux systems.

[0015] As a further optimized solution of the present invention, the server module includes a video server and a service system. The video server is used to receive the video stream pushed by the acquisition terminal and forward it to the playback terminal, and the service system is used to control the playback logic of the playback terminal.

[0016] As a further optimized solution of the present invention, the acquisition terminal updates the frame metadata at a set time or at the picture group interval.

[0017] As a further optimized solution of the present invention, the asymmetric algorithm key pair is generated based on a key management system. The key management system issues identity authentication certificates to the acquisition terminal and the playback terminal, and records the public keys of the certificates of the acquisition terminal and the playback terminal.

[0018] As a further optimized solution of the present invention, during the encryption or decryption process, if the video frame size is not a multiple of the stream cipher block size, the number of rounds of generating the stream cipher is rounded up according to the video frame size or the stream cipher block size.

[0019] As a further optimized solution of the present invention, when the acquisition terminal is continuously pushing the stream and there is no playback terminal watching, the acquisition terminal updates the frame metadata based on a set method and pushes it to the server module, encrypts the video stream data based on the updated frame metadata, and pushes the encrypted video stream data to the server module.

[0020] As a further optimized solution of the present invention, when the playback terminal plays a historical video, the playback terminal obtains the historical video and the list of frame metadata through the server module, accumulates all the video data therein through the video frame difference between the current position of the progress bar after dragging and the frame metadata in the list, generates a key of corresponding size using a stream cipher, and discards it. For each frame of video, the above ceiling algorithm is used. After discarding, a random number is generated according to the current frame size of the dragged progress bar, and the data is decrypted by XORing with the frame data, and then the playback starts.

[0021] A video encryption device based on a trusted execution environment includes at least one processor module and a memory module, as well as a logical operation program stored on the memory module and executable on the processor module. When the processor module executes the logical operation program, the method described in any one of the above is implemented.

[0022] The beneficial effects of the present invention are as follows:

[0023] The encryption method and device proposed by the present invention realize the asymmetric algorithm encryption and stream encryption of the video stream by the acquisition terminal and the playback terminal, which can ensure that the video transmission is more secure and reliable, and ensure that the users with this device and the corresponding playback terminals can decrypt and view the video. Description of the Drawings

[0024] Figure 1 It is a schematic diagram of the system for implementing the encryption method in the present invention. Detailed Embodiments

[0025] The following further describes the present application in detail with reference to the drawings. It is necessary to point out here that the following specific embodiments are only used to further illustrate the present application and cannot be understood as limiting the protection scope of the present application. Those skilled in the art can make some non-essential improvements and adjustments to the present application according to the above application content.

[0026] Embodiment 1

[0027] As Figure 1 shown, this embodiment provides a video stream encryption method based on a trusted execution environment, which is applied to an acquisition terminal, a playback terminal, and a server module. The acquisition terminal and the playback terminal pre-generate an asymmetric algorithm key pair including a public key and a private key;

[0028] Among them, the acquisition terminal includes a video acquisition module running on Linux and a video encryption module running in a trusted execution environment. The playback terminal includes a video playback module and a video decryption module. The video playback module runs on Windows, Android, and Linux systems, and the video decryption module runs in a trusted execution environment or on Windows, Android, and Linux systems, or can also rely on the TPM module.

[0029] The server module includes a video server and a service system. The video server is used to receive the video stream pushed by the acquisition terminal and forward it to the playback terminal, and the service system is used to control the playback logic of the playback terminal.

[0030] In this embodiment, the asymmetric algorithm key pair is generated based on a key management system. The key management system issues identity authentication certificates to the acquisition terminal and the playback terminal, and records the public keys of the certificates of the acquisition terminal and the playback terminal.

[0031] I. Before the implementation of the encryption method in this embodiment, it includes the system initialization for implementing the encryption method. Specifically:

[0032] The acquisition terminal completes the initialization process on the device production line:

[0033] (1) Burn the device serial number s1.

[0034] (2) Generate a key pair (SK1, PK1) based on the asymmetric algorithm. SK1 is burned into the device efuse, and PK1 is recorded in the Flash.

[0035] (3) Register (S1, PK1) in the key management system.

[0036] The playback terminal is initialized by the user. The initialization process is as follows:

[0037] (1) The playback terminal generates a user uid.

[0038] (2) The playback terminal generates a key pair (SK2, PK2) based on the asymmetric algorithm. SK2 can be stored using TEE or TCM technology. PK2 is stored in the configuration.

[0039] (3) Register (uid, PK2) in the key management system.

[0040] II. Binding of the acquisition terminal and the playback terminal:

[0041] (1) The playback terminal sends the device serial number s1 and uid to the service system.

[0042] (2) The service system queries the public key PK1 corresponding to s1 from the key management system and sends PK1 to the playback terminal. The playback terminal records PK1.

[0043] The service system queries the public key PK1 corresponding to the uid from the key management system, and sends PK2 to the collection terminal, and the collection terminal records PK2.

[0044] The encryption method includes:

[0045] S1: The collection terminal randomly generates stream cipher parameters RP within the trusted execution environment, encrypts the parameters RP with the public key of the corresponding playback terminal user, and packages them into a data packet; the playback terminal generates an encryption key based on the key negotiation algorithm for encrypting frame metadata, where the frame metadata includes video frame timestamps and stream cipher parameters, and sends the encrypted frame metadata to the server module;

[0046] S2: The collection terminal uses the parameter RP as the stream cipher parameter, generates a corresponding stream cipher based on the video frame size, encrypts the video stream data by XORing with the stream cipher, and pushes it to the server module after encryption;

[0047] S3: The playback terminal obtains the updated frame metadata from the server module. When the playback terminal pulls the video stream from the video server, the playback terminal decrypts the frame metadata with the private key to obtain the stream cipher encryption parameter RP, and generates a corresponding stream cipher based on the parameter RP and the video frame size; decrypts the video stream data by XORing with the stream cipher.

[0048] In this embodiment, the collection terminal updates the frame metadata at a set time or at the GOP interval.

[0049] In this embodiment, during the encryption or decryption process, if the video frame size is not a multiple of the stream cipher block size, the number of rounds of generating the stream cipher is rounded up according to the video frame size or the stream cipher block size.

[0050] Preferably, the encryption method further includes: when the collection terminal is continuously pushing the stream and there is no playback terminal watching, the collection terminal updates the frame metadata based on a set method and pushes it to the server module, encrypts the video stream data based on the updated frame metadata, and pushes the encrypted video stream data to the server module.

[0051] Preferably, the encryption method further includes: when the playback terminal plays a historical video, the playback terminal obtains the historical video and the frame metadata list through the server module, accumulates all the video data therein based on the video frame difference between the current position of the progress bar after dragging and the frame metadata in the list, generates a key of the corresponding size using the stream cipher and discards it. For each frame of video, using the above-mentioned rounding-up algorithm, after discarding, generates a random number according to the current frame size of the dragged progress bar, and XORs it with the frame data to decrypt the data and start playing.

[0052] Based on the above encryption method, the specific implementation scenario one is: the playback terminal plays a live video.

[0053] (1) The playback terminal notifies the service system that the playback terminal needs to watch a live video, and the message contains the user uid of the playback terminal.

[0054] (2) The service system notifies the acquisition terminal that the uid needs to watch a live video.

[0055] (3) The acquisition terminal randomly generates the parameters RP required for the stream cipher within the trusted execution environment, negotiates the key using the public key of the uid, and then packages it into the message MKey. (For example, assume the stream cipher is the chacha20 algorithm, and the randomly generated parameters include a 256-bit random key RK, a 64-bit random counter RC, and a 64-bit random nonce RN.) The playback terminal generates a random encryption key MK (the public key of the playback end) using the key negotiation algorithm. For example, if the ECC algorithm is used, the ECDH key negotiation is used. Then, the frame encryption information MP is encrypted using MK, where the frame encryption information includes the video frame timestamp and the stream cipher parameters. Finally, MP is sent to the service server.

[0056] (4) The acquisition terminal uses the parameters RP generated in the above steps as the stream cipher parameters to generate a stream cipher of the corresponding size according to the video frame size. If the video frame size is not a multiple of the stream cipher block size, the number of rounds of generating the stream cipher is rounded up according to (video frame size / stream cipher block size). The encryption method is to perform an exclusive OR operation between the video stream data and the stream cipher. The extra bits after rounding up are discarded. After encrypting the video stream, the acquisition terminal pushes it to the video server.

[0057] (5) The playback terminal queries the service terminal for the latest MP information and obtains the latest MP.

[0058] (6) The acquisition terminal pulls the stream from the video server. After decrypting the MP information, it obtains the stream cipher encryption parameters RP. Then, it uses RP as the parameter to generate a stream cipher of the corresponding size according to the video frame size. If the video frame size is not a multiple of the stream cipher block size, the number of rounds of generating the stream cipher is rounded up according to (video frame size / stream cipher block size). The decryption method is to perform an exclusive OR operation between the video stream data and the stream cipher.

[0059] (7) The acquisition terminal and the playback terminal update the MP information according to the negotiated strategy, for example, updating MP after every N frames are played. At the same time, MP cannot be updated within a GOP (group of pictures).

[0060] The specific implementation scenario two is: The playback terminal plays a historical video.

[0061] If there is no playback terminal, the push stream scheme of the acquisition terminal is (the acquisition terminal is continuously pushing the stream, and there is no playback terminal watching during the current time period):

[0062] (1) Query the business system to obtain the list of legal video playback devices (uid, PK2) for the current terminal.

[0063] (2) The acquisition terminal updates the MP information according to a fixed policy, such as updating the MP after every N frames are played. At the same time, the MP cannot be updated within a GOP (group of pictures).

[0064] (3) Update the MP information to the business system.

[0065] (4) After updating the MP, encrypt the video using the latest MP and push it to the video server, which saves the video.

[0066] (5) When the playback terminal plays the historical record, it first queries the MP list, selects the appropriate MP according to the video historical record timestamp, and decrypts and plays it.

[0067] Implementation scenario three: The playback terminal plays historical videos and drags the progress bar.

[0068] (1) The playback terminal obtains the historical video.

[0069] (2) The playback terminal obtains the MP list.

[0070] (3) According to the dragged progress bar, select an MP information on the progress bar.

[0071] (4) According to the video frame gap between the current position of the progress bar and the previous MP information, accumulate the sizes of all video data. And generate a key of the corresponding size using the stream cipher and discard it. The above ceiling algorithm should be used for each frame of video.

[0072] (5) After discarding, generate a random number according to the current frame size of the dragged progress bar, and decrypt the data by XORing it with the frame data, and start playing.

[0073] A video encryption device based on a trusted execution environment includes at least one processor module and a memory module, as well as a logical operation program stored on the memory module and executable on the processor module. When the processor module executes the logical operation program, the above method is implemented.

[0074] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A video stream encryption method based on a trusted execution environment, characterized in that, Applied to the acquisition terminal, the playback terminal, and the server module. The acquisition terminal and the playback terminal pre-generate an asymmetric algorithm key pair including a public key and a private key. The encryption method includes: S1: The acquisition terminal randomly generates a stream cipher parameter RP within the trusted execution environment, encrypts the parameter RP with the public key of the corresponding playback terminal user, and packages it into a data packet. The playback terminal generates an encryption key based on the key negotiation algorithm for encrypting the frame metadata. The frame metadata includes the video frame timestamp and the stream cipher parameter, and sends the encrypted frame metadata to the server module; S2: The acquisition terminal uses the parameter RP as the stream cipher parameter, generates a corresponding stream cipher based on the video frame size, encrypts the video stream data by XORing it with the stream cipher, and pushes it to the server module after encryption; S3: The playback terminal obtains the updated frame metadata from the server module. When the playback terminal pulls the video stream from the video server, the playback terminal decrypts the frame metadata with the private key to obtain the stream cipher encryption parameter RP, and generates a corresponding stream cipher based on the parameter RP and the video frame size; decrypts the video stream data by XORing it with the stream cipher; Wherein, the acquisition terminal updates the frame metadata at a set time or at the interval of the picture group; when the acquisition terminal is continuously pushing the stream and there is no playback terminal watching, the acquisition terminal updates the frame metadata based on a set method and pushes it to the server module, encrypts the video stream data based on the updated frame metadata, and pushes the encrypted video stream data to the server module; when the playback terminal plays the historical video, the playback terminal obtains the historical video and the frame metadata list through the server module, accumulates all the video data among them according to the video frame difference between the current position of the dragged progress bar and the frame metadata in the list, generates a key of the corresponding size with the stream cipher, and discards it. For each frame of video, use the above ceiling algorithm. After discarding, generate a random number according to the current frame size of the dragged progress bar, and XOR it with the frame data to decrypt the data and start playing.

2. The video stream encryption method based on a trusted execution environment according to claim 1, wherein: The acquisition terminal includes a video acquisition module running on Linux and a video encryption module running in the trusted execution environment.

3. A video stream encryption method based on a trusted execution environment according to claim 1, characterized in that: The playback terminal includes a video playback module and a video decryption module. The video playback module runs on Windows, Android, and Linux systems, and the video decryption module runs in the trusted execution environment or on Windows, Android, and Linux systems.

4. A video stream encryption method based on a trusted execution environment according to claim 1, characterized in that: The server module includes a video server and a service system. The video server is used to receive the video stream pushed by the acquisition terminal and forward it to the playback terminal, and the service system is used to control the playback logic of the playback terminal.

5. A video stream encryption method based on a trusted execution environment according to claim 1, characterized in that: The asymmetric algorithm key pair is generated based on the key management system. The key management system issues identity authentication certificates to the acquisition terminal and the playback terminal, and records the public keys of the certificates of the acquisition terminal and the playback terminal.

6. The video stream encryption method based on a trusted execution environment according to claim 1, wherein: During the encryption or decryption process, if the video frame size is not a multiple of the stream cipher block size, the number of rounds of generating the stream cipher is rounded up according to the video frame size or the stream cipher block size.

7. A video encryption device based on a trusted execution environment, characterized in that Comprising at least one processor module and one memory module, and a logical operation program stored on the memory module and executable on the processor module, when the processor module executes the logical operation program, the method according to any one of claims 1-6 is implemented.

Citation Information

Patent Citations

  • Video data encryption method and device, storage medium and electronic equipment

    CN112491532A

  • A key negotiation method, system, sender, and receiver

    CN114938273A