A code stream security transmission method based on dynamic data classification and electronic equipment
Through the data dynamically grading code stream security transmission method, the security level is determined based on the target parameters of the data and processed accordingly, the problem of computing resource occupation in data transmission is solved and efficient data transmission is achieved.
Patent Information
- Application Number
- CN202411855393.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-16
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2044-12-16
AI Technical Summary
During the massive data transmission process, encrypting and signature protection of all data in the prior art will occupy too much computing resources, resulting in a reduction in transmission efficiency.
The code stream secure transmission method based on dynamic data hierarchy is adopted to determine the security level according to the target parameters of the data, and only data with high security level is encrypted and signed. Data with low security level is not encrypted or signed, and packets containing security level identification are generated for transmission.
It reduces the computing resource usage of the sending and receiving ends, improves the data transmission efficiency and speed, and reduces the utilization of transmission resources.
Smart Images

Figure CN119316234B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data processing technology, and in particular to a code stream security transmission method based on dynamic data classification and an electronic device. Background Art
[0002] As public awareness of safety grows, data transmission security is increasingly valued. Encrypted transmission is often used to ensure data security, along with integrity checks. However, the massive amount of data transmitted over the network consumes excessive computing resources for both the sender and receiver, reducing transmission efficiency. Summary of the Invention
[0003] The present application provides a code stream security transmission method and electronic device based on dynamic data classification, which can reduce the resource occupation caused by the sending end when encrypting and signing the transmitted data at a low security level, and at the same time reduce the resource occupation caused by the receiving side when decrypting and verifying the transmitted data, thereby improving data processing efficiency.
[0004] To achieve the above technical objectives, this application adopts the following technical solutions:
[0005] In a first aspect, an embodiment of the present application provides a method for securely transmitting a code stream based on dynamic data classification, which is applied to a data sending end and includes:
[0006] Acquire first data to be transmitted, where the first data is video frame data;
[0007] determining a security level of the first data based on a target parameter corresponding to the first data; the target parameter including at least one of a frame type, a frame content, a frame source, a frame generation time, and a frame tag, the frame tag being used to indicate whether the first data is data marked by a user;
[0008] When the security level of the first data is higher than a preset level, performing a processing operation on the first data to obtain second data, the processing operation including an encryption operation and / or a signing operation;
[0009] If the security level of the first data is not higher than the preset level, determining the first data as the second data;
[0010] Generate a message including a level identifier of the security level of the first data and the second data; the level identifier is used by the data receiving end to determine the security level of the first data;
[0011] Send a message to the data receiving end.
[0012] The technical solution provided by this application provides at least the following beneficial effects: Different data to be transmitted have different importance. This application assigns different security levels to these data, and different security levels correspond to different processing operations. Therefore, for some data to be transmitted with low security levels, encryption or signing operations are not required and the data can be transmitted directly to the recipient. In other words, before the data is transmitted, the data sender dynamically classifies the data to be transmitted. The security level of the data to be transmitted changes with its importance. Different security levels correspond to different processing operations, and not all data to be transmitted needs to be encrypted or signed before it can be transmitted. Therefore, when transmitting data to be transmitted, the resource usage caused by encryption and signing on the sender can be reduced, as can the resource usage caused by decryption and signature verification on the receiving side, thereby reducing computing resource consumption on the receiving side. Furthermore, data to be transmitted with low security levels does not carry information related to encryption or signing operations during transmission, which reduces the transmission resources used and increases the data transmission rate.
[0013] In one possible implementation, when the security level of the first data is the second level, a signature operation is performed on the first data to obtain second data containing signature verification information and the first data; the second level is higher than the first level; and / or, when the security level of the first data is the third level, an encryption operation is performed on the first data using a preset encryption algorithm, and a signature operation is performed on the first data to obtain second data containing signature verification information and the encrypted first data; the third level is higher than the second level.
[0014] In one possible implementation, when the security level of the first data is the second level, the first data is encrypted using a preset encryption algorithm, and the encrypted first data is used as the second data; the second level is higher than the first level; and / or, when the security level of the first data is the third level, the first data is encrypted using a preset encryption algorithm, and the first data is signed to obtain second data including signature verification information and the encrypted first data; the third level is higher than the second level.
[0015] In one possible implementation, the frame types include: key frames and / or non-key frames, and the frame contents include: dynamic frames and / or static frames. The dynamic frames are used to characterize the presence of moving targets in the video frame data, and the static frames are used to characterize the absence of moving targets in the video frame data. The method also includes: performing moving target identification on the video frame data to determine whether there is a moving target in the video frame data; if there is a moving target in the video frame data, determining that the frame content corresponding to the video frame data is a dynamic frame; if there is no moving target in the video frame data, determining that the frame content corresponding to the video frame data is a static frame; and / or, based on the video coding standard, determining the frame type corresponding to the video frame data.
[0016] In one possible implementation, a first correspondence is pre-stored in the data sending end, and the first correspondence is used to characterize the correspondence between the target parameter and the security level; the security level of the first data is determined according to the target parameter corresponding to the first data, including: determining the security level of the first data based on the first correspondence and the target parameter corresponding to the first data; wherein, when the target parameter corresponding to the video frame data includes the frame type, the security level of the video frame data corresponding to the key frame is higher than the security level of the video frame data corresponding to the non-key frame; or, when the target parameter corresponding to the video frame data includes the frame content, the security level of the video frame data corresponding to the dynamic frame is higher than the security level of the video frame data corresponding to the static frame. The security level of the data; or, in the case where the target parameters corresponding to the video frame data include the frame type and the frame content: if the frame types corresponding to the video frame data are the same, the security level of the video frame data corresponding to the dynamic frame is higher than the security level of the video frame data corresponding to the static frame; if the frame contents corresponding to the video frame data are the same, the security level of the video frame data corresponding to the key frame is higher than the security level of the video frame data corresponding to the non-key frame; the security level of the video frame data corresponding to the key frame and the dynamic frame is higher than the security level of the video frame data corresponding to the non-key frame and the static frame; the security level of the video frame data corresponding to the key frame and the static frame is the same as the security level of the video frame data corresponding to the non-key frame and the dynamic frame.
[0017] In one possible implementation, the preset coding standard stipulates that the data to be transmitted is written into a data unit, the data unit includes a header position and a data position, the header position includes a first position for writing an importance character, the importance character is used to indicate the importance of the data in the data unit, the data position is used to write the data to be transmitted, and the header position is located before the data position; when the video coding standard is the preset coding standard, a message including a level identifier of the security level of the first data and the second data is generated, including: writing the level identifier of the security level of the first data in the first position of the header position, writing the second data in the data position, and obtaining the message to be transmitted; when the video coding standard is not the preset coding standard, a message including a level identifier of the security level of the first data and the second data is generated, including: constructing a second position for writing the level identifier of the security level of the first data in the format of the message; the format of the message also includes the data position, and the second position is located before the data position; writing the level identifier of the security level of the first data in the second position, writing the second data in the data position, and obtaining the message to be transmitted.
[0018] In one possible implementation, the frame source includes an important source and / or an unimportant source; the frame generation moment includes an important period and / or an unimportant period; the frame tag includes an important tag and / or an unimportant tag; a first correspondence is pre-stored in the data sending end, and the first correspondence is used to characterize the correspondence between the target parameter and the security level; the security level of the first data is determined according to the target parameter corresponding to the first data, including: determining the security level of the first data based on the first correspondence and the target parameter corresponding to the first data; wherein, when the target parameter corresponding to the video frame data includes the frame source, the security level of the video frame data corresponding to the important source is higher than the security level of the video frame data corresponding to the unimportant source; or, when the target parameter corresponding to the video frame data includes the frame generation moment, the security level of the video frame data corresponding to the important period is higher than the security level of the video frame data corresponding to the unimportant period; or, when the target parameter corresponding to the video frame data includes the frame tag, the security level of the video frame data corresponding to the important tag is higher than the security level of the video frame data corresponding to the unimportant tag.
[0019] In a possible implementation, when the second data includes signature verification information, the signature verification information is located at the end of the second data.
[0020] In the second aspect, an embodiment of the present application provides a method for secure transmission of a code stream based on dynamic data classification, which is applied to a data receiving end, and the method includes: receiving a message sent by a data sending end, the message including a level identifier and second data; determining the security level corresponding to the level identifier in the message; when the security level is higher than a preset level, performing a processing operation on the second data to obtain first data, the first data being video frame data; the processing operation includes a decryption operation and / or a signature verification operation; when the security level is not higher than a preset level, determining that the second data is the first data; wherein the security level is the security level of the first data; the security level of the first data is determined by the data sending end based on the target parameters corresponding to the first data, the target parameters including at least one of the frame type, frame content, frame source, frame generation time and frame mark, and the frame mark is used to indicate whether the first data is data marked by the user.
[0021] In one possible implementation, when the security level is the second level, a signature verification operation is performed on the second data to obtain the first data; the second level is higher than the first level; and / or, when the security level is the third level, a preset decryption algorithm is used to perform a decryption operation on the second data, and a signature verification operation is performed on the second data to obtain the first data; the third level is higher than the second level.
[0022] In one possible implementation, when the security level is the second level, a preset decryption algorithm is used to decrypt the second data to obtain the first data; the second level is higher than the first level; and / or, when the security level is the third level, a preset decryption algorithm is used to decrypt the second data, and a signature verification operation is performed on the second data to obtain the first data; the third level is higher than the second level.
[0023] In one possible implementation, the frame types include: key frames and / or non-key frames, and the frame contents include: dynamic frames and / or static frames. The dynamic frames are used to represent the presence of moving targets in the video frame data, and the static frames are used to represent the absence of moving targets in the video frame data. The frame content corresponding to the first data is determined by the data sending end after the data sending end identifies the moving target of the video frame, and the frame type corresponding to the first data is determined by the data sending end based on the video coding standard.
[0024] In one possible implementation, when the target parameters corresponding to the video frame data include frame types, the security level of the video frame data corresponding to key frames is higher than the security level of the video frame data corresponding to non-key frames; or, when the target parameters corresponding to the video frame data include frame content, the security level of the video frame data corresponding to dynamic frames is higher than the security level of the video frame data corresponding to static frames; or, when the target parameters corresponding to the video frame data include frame types and frame content: if the frame types corresponding to the video frame data are the same, the security level of the video frame data corresponding to dynamic frames is higher than the security level of the video frame data corresponding to static frames; if the frame contents corresponding to the video frame data are the same, the security level of the video frame data corresponding to key frames is higher than the security level of the video frame data corresponding to non-key frames; the security level of the video frame data corresponding to key frames and dynamic frames is higher than the security level of the video frame data corresponding to non-key frames and static frames; the security level of the video frame data corresponding to key frames and static frames is the same as the security level of the video frame data corresponding to non-key frames and dynamic frames.
[0025] In one possible implementation, the preset coding standard stipulates that the data to be transmitted is written in the data unit, the data unit includes a header position and a data position, the header position includes a first position for writing an importance character, the importance character is used to indicate the importance of the data in the data unit, the data position is used to write the data to be transmitted, and the header position is located before the data position; when the video coding standard is the preset coding standard, the level identifier of the security level of the first data is written in the first position in the header position, and the second data is written in the data position; when the video coding standard is not the preset coding standard, the message format is constructed with a second position and a data position, the second position is located before the data position, the level identifier of the security level of the first data is written in the second position, and the second data is written in the data position.
[0026] In one possible implementation, the frame source includes an important source and / or a non-important source; the frame generation moment includes an important time period and / or a non-important time period; the frame tag includes an important tag and / or a non-important tag; when the target parameter corresponding to the video frame data includes the frame source, the security level of the video frame data corresponding to the important source is higher than the security level of the video frame data corresponding to the non-important source; or, when the target parameter corresponding to the video frame data includes the frame generation moment, the security level of the video frame data corresponding to the important time period is higher than the security level of the video frame data corresponding to the non-important time period; or, when the target parameter corresponding to the video frame data includes the frame tag, the security level of the video frame data corresponding to the important tag is higher than the security level of the video frame data corresponding to the non-important tag.
[0027] In a possible implementation, when the second data includes signature verification information, the signature verification information is located at the end of the second data.
[0028] In a third aspect, the present application provides a device for securely transmitting a code stream based on dynamic data classification, which is applied to a data sending end, and includes:
[0029] An acquisition module, configured to acquire first data to be transmitted, where the first data is video frame data;
[0030] a processing module, configured to determine a security level of the first data based on a target parameter corresponding to the first data; the target parameter including at least one of a frame type, a frame content, a frame source, a frame generation time, and a frame tag, the frame tag being used to indicate whether the first data is data marked by a user; if the security level of the first data is higher than a preset level, perform a processing operation on the first data to obtain second data, the processing operation including an encryption operation and / or a signing operation; if the security level of the first data is not higher than the preset level, determine the first data as second data; generate a message including a level identifier of the security level of the first data and the second data; the level identifier being used by a data receiving end to determine the security level of the first data;
[0031] The sending module is used to send messages to the data receiving end.
[0032] In one possible implementation, the preset level is the first level; the processing module is specifically used to: when the security level of the first data is the second level, perform a signing operation on the first data to obtain second data containing signature verification information and the first data; the second level is higher than the first level; and / or, when the security level of the first data is the third level, use a preset encryption algorithm to perform an encryption operation on the first data, and perform a signing operation on the first data to obtain second data containing signature verification information and the encrypted first data; the third level is higher than the second level.
[0033] In one possible implementation, the preset level is the first level; the processing module is specifically used to: when the security level of the first data is the second level, use the preset encryption algorithm to encrypt the first data, and use the encrypted first data as the second data; the second level is higher than the first level; and / or, when the security level of the first data is the third level, use the preset encryption algorithm to encrypt the first data, and sign the first data to obtain second data including signature verification information and the encrypted first data; the third level is higher than the second level.
[0034] In one possible implementation, the frame types include: key frames and / or non-key frames, and the frame contents include: dynamic frames and / or static frames. The dynamic frames are used to represent the presence of moving targets in the video frame data, and the static frames are used to represent the absence of moving targets in the video frame data. The processing module is also used to: perform moving target identification on the video frame data to determine whether there is a moving target in the video frame data; if there is a moving target in the video frame data, determine that the frame content corresponding to the video frame data is a dynamic frame; if there is no moving target in the video frame data, determine that the frame content corresponding to the video frame data is a static frame; and / or, based on the video coding standard, determine the frame type corresponding to the video frame data.
[0035] In one possible implementation, a first correspondence is pre-stored in the data sending end, and the first correspondence is used to characterize the correspondence between the target parameter and the security level; the processing module is specifically used to: determine the security level of the first data based on the first correspondence and the target parameter corresponding to the first data; wherein, when the target parameter corresponding to the video frame data includes the frame type, the security level of the video frame data corresponding to the key frame is higher than the security level of the video frame data corresponding to the non-key frame; or, when the target parameter corresponding to the video frame data includes the frame content, the security level of the video frame data corresponding to the dynamic frame is higher than the security level of the video frame data corresponding to the static frame; or In the case where the target parameters corresponding to the video frame data include frame type and frame content: if the frame types corresponding to the video frame data are the same, the security level of the video frame data corresponding to dynamic frames is higher than the security level of the video frame data corresponding to static frames; if the frame contents corresponding to the video frame data are the same, the security level of the video frame data corresponding to key frames is higher than the security level of the video frame data corresponding to non-key frames; the security level of the video frame data corresponding to key frames and dynamic frames is higher than the security level of the video frame data corresponding to non-key frames and static frames; the security level of the video frame data corresponding to key frames and static frames is the same as the security level of the video frame data corresponding to non-key frames and dynamic frames.
[0036] In one possible implementation, the preset coding standard stipulates that the data to be transmitted is written in a data unit, the data unit includes a header position and a data position, the header position includes a first position for writing an importance character, the importance character is used to indicate the importance of the data in the data unit, the data position is used to write the data to be transmitted, and the header position is located before the data position; when the video coding standard is the preset coding standard, the processing module is specifically used to: write a level identifier of the security level of the first data in the first position of the header position, write the second data in the data position, and obtain the message to be transmitted, and the header position is located before the data position; when the video coding standard is not the preset coding standard, the processing module is specifically used to: construct a second position for writing a level identifier of the security level of the first data in the format of the message; the format of the message also includes a data position, and the second position is located before the data position; write the level identifier of the security level of the first data in the second position, write the second data in the data position, and obtain the message to be transmitted.
[0037] In one possible implementation, the frame source includes an important source and / or an unimportant source; the frame generation moment includes an important period and / or an unimportant period; the frame tag includes an important tag and / or an unimportant tag; a first corresponding relationship is pre-stored in the data sending end, and the first corresponding relationship is used to characterize the corresponding relationship between the target parameter and the security level; the processing module is specifically used to: determine the security level of the first data based on the first corresponding relationship and the target parameter corresponding to the first data; wherein, when the target parameter corresponding to the video frame data includes the frame source, the security level of the video frame data corresponding to the important source is higher than the security level of the video frame data corresponding to the unimportant source; or, when the target parameter corresponding to the video frame data includes the frame generation moment, the security level of the video frame data corresponding to the important period is higher than the security level of the video frame data corresponding to the unimportant period; or, when the target parameter corresponding to the video frame data includes the frame tag, the security level of the video frame data corresponding to the important tag is higher than the security level of the video frame data corresponding to the unimportant tag.
[0038] In a possible implementation, when the second data includes signature verification information, the signature verification information is located at the end of the second data.
[0039] In a fourth aspect, the present application provides a device for securely transmitting a code stream based on dynamic data classification, which is applied to a data receiving end, and includes:
[0040] A receiving module, configured to receive a message sent by a data sending end, wherein the message includes a level identifier and second data;
[0041] A processing module is used to determine the security level corresponding to the level identifier in the message; when the security level is higher than the preset level, the second data is processed to obtain the first data, and the first data is video frame data; the processing operation includes a decryption operation and / or a signature verification operation; when the security level is not higher than the preset level, the second data is determined to be the first data; wherein the security level is the security level of the first data; the security level of the first data is determined by the data sending end according to the target parameters corresponding to the first data, and the target parameters include at least one of the frame type, frame content, frame source, frame generation time and frame mark, and the frame mark is used to indicate whether the first data is data marked by the user.
[0042] In one possible implementation, the preset level is the first level; the processing module is specifically used to: when the security level is the second level, perform a signature verification operation on the second data to obtain the first data; the second level is higher than the first level; and / or, when the security level is the third level, use a preset decryption algorithm to perform a decryption operation on the second data, and perform a signature verification operation on the second data to obtain the first data; the third level is higher than the second level.
[0043] In one possible implementation, the preset level is the first level; the processing module is specifically used to: when the security level is the second level, use the preset decryption algorithm to decrypt the second data to obtain the first data; the second level is higher than the first level; and / or, when the security level is the third level, use the preset decryption algorithm to decrypt the second data and perform a signature verification operation on the second data to obtain the first data; the third level is higher than the second level.
[0044] In one possible implementation, the frame types include: key frames and / or non-key frames, and the frame contents include: dynamic frames and / or static frames. The dynamic frames are used to represent the presence of moving targets in the video frame data, and the static frames are used to represent the absence of moving targets in the video frame data. The frame content corresponding to the first data is determined by the data sending end after the data sending end identifies the moving target of the video frame, and the frame type corresponding to the first data is determined by the data sending end based on the video coding standard.
[0045] In one possible implementation, when the target parameters corresponding to the video frame data include frame types, the security level of the video frame data corresponding to key frames is higher than the security level of the video frame data corresponding to non-key frames; or, when the target parameters corresponding to the video frame data include frame content, the security level of the video frame data corresponding to dynamic frames is higher than the security level of the video frame data corresponding to static frames; or, when the target parameters corresponding to the video frame data include frame types and frame content: if the frame types corresponding to the video frame data are the same, the security level of the video frame data corresponding to dynamic frames is higher than the security level of the video frame data corresponding to static frames; if the frame contents corresponding to the video frame data are the same, the security level of the video frame data corresponding to key frames is higher than the security level of the video frame data corresponding to non-key frames; the security level of the video frame data corresponding to key frames and dynamic frames is higher than the security level of the video frame data corresponding to non-key frames and static frames; the security level of the video frame data corresponding to key frames and static frames is the same as the security level of the video frame data corresponding to non-key frames and dynamic frames.
[0046] In one possible implementation, the preset coding standard stipulates that the data to be transmitted is written in the data unit, the data unit includes a header position and a data position, the header position includes a first position for writing an importance character, the importance character is used to indicate the importance of the data in the data unit, the data position is used to write the data to be transmitted, and the header position is located before the data position; when the video coding standard is the preset coding standard, the level identifier of the security level of the first data is written in the first position in the header position, and the second data is written in the data position; when the video coding standard is not the preset coding standard, the message format is constructed with a second position and a data position, the second position is located before the data position, the level identifier of the security level of the first data is written in the second position, and the second data is written in the data position.
[0047] In one possible implementation, the frame source includes an important source and / or a non-important source; the frame generation moment includes an important time period and / or a non-important time period; the frame tag includes an important tag and / or a non-important tag; when the target parameter corresponding to the video frame data includes the frame source, the security level of the video frame data corresponding to the important source is higher than the security level of the video frame data corresponding to the non-important source; or, when the target parameter corresponding to the video frame data includes the frame generation moment, the security level of the video frame data corresponding to the important time period is higher than the security level of the video frame data corresponding to the non-important time period; or, when the target parameter corresponding to the video frame data includes the frame tag, the security level of the video frame data corresponding to the important tag is higher than the security level of the video frame data corresponding to the non-important tag.
[0048] In a possible implementation, when the second data includes signature verification information, the signature verification information is located at the end of the second data.
[0049] In a fifth aspect, the present application provides an electronic device comprising a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement any one of the code stream security transmission methods based on dynamic data classification provided in the first or second aspect above.
[0050] In a sixth aspect, the present application provides a computer-readable storage medium, which stores computer-executable instructions. When the computer instructions are executed by a processor, they implement any one of the code stream security transmission methods based on dynamic data classification provided in the first or second aspects above.
[0051] In a seventh aspect, the present application provides a computer program product, which includes computer instructions. When the computer instructions are executed by a processor, they implement any one of the code stream security transmission methods based on dynamic data classification provided in the first or second aspects above.
[0052] For the specific description of the third to seventh aspects and their various implementations in this application, reference can be made to the detailed description in the first and second aspects and their various implementations; and for the beneficial effects of the third to seventh aspects and their various implementations, reference can be made to the analysis of the beneficial effects in the first and second aspects and their various implementations, which will not be repeated here.
[0053] These and other aspects of the present application will become more readily apparent from the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] Figure 1 A schematic diagram of the architecture of a data processing system provided in an embodiment of the present application;
[0055] Figure 2 A flowchart of a method for securely transmitting a code stream based on dynamic data classification provided in an embodiment of the present application;
[0056] Figure 3 A schematic diagram of a data format provided in an embodiment of the present application;
[0057] Figure 4 A schematic diagram of a NALU header format provided in an embodiment of the present application;
[0058] Figure 5 A schematic diagram of a signing process provided in an embodiment of the present application;
[0059] Figure 6 A schematic diagram of an encryption process provided in an embodiment of the present application;
[0060] Figure 7 A schematic diagram of an interactive process for data transmission provided in an embodiment of the present application;
[0061] Figure 8 A schematic diagram of the composition of a device for securely transmitting a code stream based on dynamic data classification provided in an embodiment of the present application;
[0062] Figure 9 A schematic diagram of the composition of another device for securely transmitting a code stream based on dynamic data classification provided in an embodiment of the present application;
[0063] Figure 10 A schematic diagram of the composition of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0064] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0065] It should be noted that, in the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or design schemes. To be precise, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete way. The terms "first" and "second" are used for descriptive purposes only and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined as "first" and "second" may explicitly or implicitly include one or more of such features.
[0066] In the description of this application, unless otherwise specified, " / " means "or." For example, A / B can mean A or B. "And / or" in this document is simply a description of an association between related objects, indicating that three relationships can exist. For example, "A and / or B" can mean: A exists alone, A and B exist simultaneously, and B exists alone. Furthermore, "at least one" means one or more, and "a plurality" means two or more.
[0067] As described in the background art, in a scenario where massive amounts of data are transmitted over a network, if all data is encrypted and signed for protection, it will undoubtedly occupy more computing resources and increase the computing pressure on the data sender and receiver.
[0068] Based on this, the present application provides a method for secure transmission of a code stream based on dynamic data classification, the method comprising: a data sending end obtaining first data to be transmitted, the first data being video frame data, and determining the security level of the first data according to target parameters corresponding to the first data, the target parameters including at least one of the frame type, frame content, frame source, frame generation time, and frame mark, the frame mark being used to characterize whether the first data is data marked by the user. When the security level of the first data is higher than the preset level, the first data is processed to obtain the second data. When the security level of the first data is not higher than the preset level, the first data is determined to be the second data. The processing operation comprises an encryption operation and / or a signature operation. The data sending end generates a level identifier of the security level of the first data and a message of the second data, and sends the level identifier of the security level of the first data and the message of the second data to the data receiving end. The level identifier is used by the data receiving end to determine the security level of the first data.
[0069] After receiving the message, the data receiving end determines the security level corresponding to the second data based on the level identifier in the message. If the data receiving end determines that the security level of the received message is higher than the preset level, the data receiving end processes the second data to obtain the first data. The processing operation may include a decryption operation and / or a signature verification operation. If the data receiving end determines that the security level of the received message is not higher than the preset level, the second data is determined to be the first data.
[0070] As can be seen from the above, different data to be transmitted in the above method have different target parameters. This application classifies data to be transmitted with different target parameters into different security levels, and the processing operations corresponding to different security levels are also different. Therefore, for some data to be transmitted with low security levels, all encryption or signing operations do not need to be performed and can be transmitted directly to the recipient. In other words, before the data is transmitted, the data sender dynamically classifies the data to be transmitted. The security level of the data to be transmitted changes with the target parameters corresponding to the data to be transmitted. Different security levels correspond to different processing operations. Not all data to be transmitted needs to be encrypted or signed before it can be transmitted. Therefore, when the data to be transmitted is transmitted, the resource usage caused by the encryption and signing of the data to be transmitted on the sender can be reduced, and the resource usage caused by the decryption and signature verification of the data to be transmitted on the receiving side can also be reduced, thereby reducing the computing resource consumption of the receiving side. In addition, the data to be transmitted with low security levels will not carry relevant information about encryption operations or signing operations during transmission, which will reduce the transmission resources occupied and increase the data transmission rate.
[0071] Please refer to Figure 1, which shows a data processing system applicable to a code stream security transmission method based on dynamic data classification provided by this application. Figure 1 As shown, the data processing system 100 includes a data sending end 101 and a data receiving end 102 .
[0072] The data transmitting end 101 and the data receiving end 102 are connected in communication. It should be understood that the connection method can be a wireless connection, such as a Bluetooth connection, a wireless fidelity (Wi-Fi) connection, etc.; or the connection method can also be a wired connection, such as an optical fiber connection, an Ethernet connection, a universal serial bus (USB), a high-speed serial computer expansion bus (Peripheral Component Interconnect Express, PCIE), a serial peripheral interface (SPI), an integrated circuit bus (ICB), etc. 2 C), universal asynchronous receiver / transmitter (URAT), etc., without limitation.
[0073] In some embodiments, the upstream device / equipment of the data transmitting end 101 may be an image acquisition device (of which there may be multiple devices). The image acquisition device may establish a communication connection with the data transmitting end 101. The image acquisition device is configured to output video frame data to the data transmitting end 101. The data transmitting end 101 then processes the video frame data based on the method provided in this application and transmits it to the data receiving end 102. Alternatively, the data transmitting end 101 is integrated into the image acquisition device, that is, the image acquisition device acts as the data transmitting end 101 to encode the captured video frame data and transmit it to the data receiving end 102. Figure 1 , the connection relationship between the image acquisition device as a data sending end 101 and the data receiving end 102 is shown.
[0074] The image acquisition device may be a mobile phone terminal, a smart camera or other electronic device with an image acquisition function. The data sending end 101 may be a mobile phone terminal, a server or other electronic device with a data processing function.
[0075] In some embodiments, the downstream device / equipment of the data receiving end 102 may be a display device (or multiple devices), which may establish a communication connection with the data receiving end 102. The display device is used to display the video frame data parsed by the data receiving end 102. The data receiving end 102 processes the received video frame data based on the method provided in this application and then displays it on the display device. Alternatively, the data receiving end 102 is integrated into the display device, that is, the display device acts as the data receiving end 102 to parse and display the video frame data sent by the data sending end 101. Figure 1 FIG. 3 shows a connection relationship between the display device as a data receiving end 102 and the data sending end 101 .
[0076] The display device may be a mobile phone terminal, a computer, a television, or other electronic device with an image display function. The data receiving end 102 may be a mobile phone terminal, a server, or other electronic device with a data processing function.
[0077] The server can be a server cluster consisting of multiple servers, a single server, or a computer. The data transmitter 101 or the data receiver 102 can specifically be a processor in a server. The embodiments of the present application do not limit the specific device form of the data transmitter 101 or the data receiver 102.
[0078] In some embodiments, the data transmitting end 101 needs to determine the security level of the first data based on the target parameters of the first data to be transmitted, and also needs to determine what processing operations need to be performed on the first data based on the security level of the first data. Therefore, the data transmitting end 101 should include a memory in which the correspondence between the target parameters and the security levels, as well as the correspondence between the security levels and the processing operations, are stored. Then, after receiving the first data and determining the target parameters of the first data, the data transmitting end 101 can determine the security level of the first data based on the pre-stored correspondence between the target parameters and the security levels, and then determine the processing operations that need to be performed on the first data based on the pre-stored correspondence between the security levels and the processing operations, thereby performing the corresponding processing operations on the first data.
[0079] Similarly, data receiving end 102 needs to determine what processing operation to perform on the second data in the message based on the security level in the message. Therefore, data receiving end 102 should include a memory that stores a correspondence between security levels and processing operations. After receiving the message sent by data transmitting end 101, data receiving end 102 determines the security level from the message and, based on the pre-stored correspondence between security levels and processing operations, determines the processing operation to perform on the second data in the message. Then, the corresponding data operation is performed on the second data to obtain the first data.
[0080] In some embodiments, the data sending end 101 and the data receiving end 102 can be as follows Figure 1 The devices shown are independent of each other, or the data sending end 101 and the data receiving end 102 can also be integrated into one electronic device.
[0081] The implementation of the embodiments of the present application will be described in detail below with reference to the accompanying drawings.
[0082] like Figure 2 As shown, the embodiment of the present application provides a code stream security transmission method based on dynamic data classification, which can Figure 1 The data sending end 101 in the embodiment of the present application is executed; it can also be executed by a data processing system. The embodiment of the present application is described with the data sending end as the execution subject. The method includes the following steps:
[0083] S201: Acquire first data to be transmitted.
[0084] The first data to be transmitted is video frame data.
[0085] For example, the image acquisition device may acquire video frame data and transmit the video frame data to the data transmitting end, so that the data transmitting end may obtain the first data to be transmitted.
[0086] S202: Determine a security level of the first data according to a target parameter corresponding to the first data.
[0087] The target parameter may include at least one of a frame type, a frame content, a frame source, a frame generation time, and a frame tag, and the frame tag is used to indicate whether the first data is data marked by a user.
[0088] Frame types include key frames and / or non-key frames. Key frames (Intra-coded frames, I-frames, also known as intra-coded frames) are independent frames that do not rely on information from other frames, contain complete image information, and can be decoded independently. Non-key frames include Predicted frames (P-frames, also known as predicted frames) and Bidirectional frames (B-frames, also known as bidirectional predicted frames). P-frames depend on the previous I or P frame, store the image changes (i.e., the difference from the previous frame), and cannot be decoded independently. B-frames depend on adjacent I or P frames and cannot be decoded independently. Therefore, when video frame data is a key frame, its importance should be higher than that of non-key frame video frame data. When the target parameter corresponding to the video frame data includes the frame type, the security level of the video frame data corresponding to the key frame is higher than that of the video frame data corresponding to the non-key frame.
[0089] The frame content includes: dynamic frames and / or static frames. The dynamic frames are used to represent the presence of moving targets in the video frame data, and the static frames are used to represent the absence of moving targets in the video frame data. When a moving target appears in the scene represented by the video screen, that is, when a screen appears for the user to obtain new information, the user needs to focus on it, and this video screen is a dynamic frame. When no moving target appears in the scene represented by the video screen, it represents that there is no new information for the user to obtain in the scene, and the user does not need to focus on it, and this video screen is a static frame. Therefore, when the video frame data is a dynamic frame, its importance should be higher than the video frame data of a static frame. When the target parameters corresponding to the video frame data include frame content, the security level of the video frame data corresponding to the dynamic frame is higher than the security level of the video frame data corresponding to the static frame.
[0090] The frame source represents the origin of the video frame data ("source" can be understood as the camera that generated the video frame data). Frame sources include important and / or non-important sources. Important sources represent cameras used to capture important locations, while non-important sources represent cameras used to capture non-important locations. Video frame data captured by cameras used to capture important locations that can provide high-value information (such as secure rooms, confidential office areas, and locations with moving objects) contains high-value information, and its loss can have serious consequences. Therefore, this data can be classified as important data and should be processed for higher confidentiality before transmission. Video frame data captured by cameras used to capture non-important locations that can provide low-value information (such as corridors and uninhabited areas) contains little high-value information, and even if lost, it would not cause serious consequences. Therefore, this data can be classified as non-important data, and the confidentiality of processing operations performed on non-important data can be lower than that performed on important data. Therefore, the importance of video frame data taken by cameras used to shoot important places is higher than the importance of video frame data taken by cameras used to shoot unimportant places. When the target parameters corresponding to the video frame data include the frame source, the security level of video frame data corresponding to important sources is higher than the security level of video frame data corresponding to unimportant sources.
[0091] The frame generation time is used to represent the time when the video frame data is generated. The frame generation time includes important time periods and / or non-important time periods. For some important time periods that require user attention, for example, some time periods with people entering and exiting are important time periods, while other time periods without people entering and exiting are non-important time periods. The entry and exit of people requires special attention. Therefore, the importance of video frame data generated during important time periods is higher than that of video frame data generated during non-important time periods. When the target parameters corresponding to the video frame data include the frame generation time, the security level of video frame data corresponding to important time periods is higher than that of video frame data corresponding to non-important time periods.
[0092] Frame tags include important tags and / or non-important tags. The user can customize the video frame data to be transmitted as important or non-important. For video frame data that is important, the user can actively add an important tag before the video frame data. When the data transmitter detects that the frame tag of the video frame data is important, the data transmitter determines that the video frame data is important data actively marked by the user. When the data transmitter detects that the frame tag of the video frame data is non-important, the data transmitter determines that the video frame data is non-important. The importance of video frame data marked as important should be higher than that of video frame data marked as non-important. When the target parameters corresponding to the video frame data include frame tags, the security level of video frame data corresponding to the important tag is higher than that of video frame data corresponding to the non-important tag. The data transmitter can determine the frame tag of the video frame data by having the user control the image acquisition device through the user device to add a character indicating the frame tag of the video frame data to the frame header of the generated video frame data. The data transmitter then obtains the video frame data generated by the image acquisition device and determines the frame tag of the video frame data from the frame header of the video frame data, thereby determining the importance of the video frame data. For example, assuming that 1 represents an important mark and 0 represents an unimportant mark, if the data sending end obtains a frame header of video frame data including a value of 1, it indicates that the frame mark of this video frame data is an important mark, and the data sending end determines that the video frame data is important data. If the data sending end obtains a frame header of video frame data including a value of 0, it indicates that the frame mark of this video frame data is an unimportant mark, and the data sending end determines that the video frame data is unimportant data. Alternatively, the user notifies the data sending end of the frame mark of the video frame data generated by the image acquisition device through the user device, and then the data sending end determines the importance of the video frame data. The user can expand other ways for the data sending end to determine the frame mark of the video frame data according to actual application conditions, and this application does not specifically limit this.
[0093] In summary, the target parameters can be summarized as parameters used to characterize the importance of the first data, not limited to one or more of frame type, frame content, frame source, frame generation time, and frame mark. Users can also expand other specific implementations of the target parameters based on actual application conditions.
[0094] In particular, if the user has actually assigned more than two security levels, the user can further divide the security levels by important sources, important time periods, and important markers, and set the security level corresponding to each target parameter. Taking the frame source as an example, suppose the user has assigned three security levels, with the third level higher than the second level, and the second level higher than the first level. The important sources of the frame sources are divided into the first source and the second source. If the video frame data of the first source is more important, the video frame data of the first source will be assigned to the third level, the video frame data of the second source will be assigned to the second level, and the video frame data of the non-important source will be assigned to the first level. The data transmitter parses the frame source of the video frame data and then determines the security level of the video frame data based on the frame source. Taking the frame generation time as an example, suppose the user has assigned three security levels, with the third level higher than the second level, and the second level higher than the first level. The important time periods of the frame generation time are divided into the first time period and the second time period. If the video frame data of the first time period is more important, the video frame data of the first time period will be assigned to the third level, the video frame data of the second time period will be assigned to the second level, and the video frame data of the non-important time period will be assigned to the first level. The data transmitter parses the frame generation time of the video frame data and then determines the security level of the video frame data based on the frame generation time. The same applies to frame marking, which will not be described here.
[0095] The following describes the correspondence between the target parameters and the security level of the first data by taking the target parameters including the frame type and the frame content as an example.
[0096] If the frame types corresponding to the video frame data are the same, the security level of the video frame data corresponding to the dynamic frame is higher than the security level of the video frame data corresponding to the static frame; if the frame contents corresponding to the video frame data are the same, the security level of the video frame data corresponding to the key frame is higher than the security level of the video frame data corresponding to the non-key frame; the security level of the video frame data corresponding to the key frame and the dynamic frame is higher than the security level of the video frame data corresponding to the non-key frame and the static frame; the security level of the video frame data corresponding to the key frame and the static frame is the same as the security level of the video frame data corresponding to the non-key frame and the dynamic frame.
[0097] In particular, users can set, based on their own needs, the security level of video frame data corresponding to key frames and static frames to be higher than the security level of video frame data corresponding to non-key frames and dynamic frames, or the security level of video frame data corresponding to key frames and static frames to be lower than the security level of video frame data corresponding to non-key frames and dynamic frames.
[0098] When the target parameters include multiple items of frame type, frame content, frame source, frame generation time, and frame mark, the correspondence between the target parameters and the security level of the first data is similar to the specific implementation of the correspondence between the target parameters and the security level of the first data when the target parameters include frame type and frame content, and can be set by the user according to needs. For example, the target parameters include frame generation time and frame source: if the frame generation time corresponding to the video frame data is the same, the security level of the video frame data corresponding to the important time period is higher than the security level of the video frame data corresponding to the non-important time period; if the frame sources corresponding to the video frame data are the same, the security level of the video frame data corresponding to the important source is higher than the security level of the video frame data corresponding to the non-important source; the security level of the video frame data corresponding to the important time period and important source is higher than the security level of the video frame data corresponding to the non-important time period and non-important source; the security level of the video frame data corresponding to the important time period and non-important source is the same as the security level of the video frame data corresponding to the non-important time period and important source. For another example, the target parameters include frame content, frame generation time and frame mark: the security level of video frame data corresponding to dynamic frames, important time periods and important marks is higher than the security level of video frame data corresponding to any two of the dynamic frames, important time periods and important marks; the security level of video frame data corresponding to any two of the dynamic frames, important time periods and important marks is higher than the security level of video frame data corresponding to any one of the dynamic frames, important time periods and important marks; the security level of video frame data corresponding to any one of the dynamic frames, important time periods and important marks is higher than the security level of video frame data corresponding to static frames, non-important time periods and non-important marks; the security levels of video frame data corresponding to any two of the dynamic frames, important time periods and important marks are the same; the security levels of video frame data corresponding to any one of the dynamic frames, important time periods and important marks are the same.
[0099] The above content describes the correspondence between target parameters and the security level of first data. A user can send the determined first correspondence (the correspondence between target parameters and the security level of first data) to a data transmitter via a user device, so that the data transmitter can store the first correspondence. When first data is to be transmitted, the data transmitter determines the target parameters of the first data and then determines the security level of the first data based on the pre-stored first correspondence. For example, the target parameters include a frame tag, which includes a first tag, a second tag, and a non-important tag. The security levels include a first level, a second level, and a third level, with the third level being higher than the second level, and the second level being higher than the first level. The first correspondence includes: the first tag corresponds to the third level, the second tag corresponds to the second level, and the third tag corresponds to the first level. If the data transmitter identifies that the frame tag of the first data to be transmitted is the first tag, the data transmitter can determine, based on the first correspondence, that the security level of the first data is the third level.
[0100] In some embodiments, the data sending end performs moving target identification on the video frame data to determine whether there is a moving target in the video frame data; if there is a moving target in the video frame data, the data sending end determines that the frame content corresponding to the video frame data is a dynamic frame; if there is no moving target in the video frame data, the data sending end determines that the frame content corresponding to the video frame data is a static frame; and / or, the data sending end determines the frame type corresponding to the video frame data based on the video coding standard.
[0101] The data transmitter determines the frame type corresponding to the video frame data based on the video coding standard. Specifically, it can determine whether the video frame data is key frame data based on the time the video frame data is generated. Video coding standards (such as MPEG, H264, and H265) specify the encoding methods and judgment rules for I-frames, P-frames, and B-frames. By consulting the relevant video coding standard documents, the generation rules for I-frames, P-frames, and B-frames can be determined. Combined with the time when the video frame data begins to be generated, the time when I-frames, B-frames, and P-frames are generated can be determined.
[0102] The data transmitting end performs mobile target recognition on the video frame data to determine whether a mobile target exists in the video frame data. This can be specifically implemented as follows: the data transmitting end is configured with a mobile target recognition algorithm, and the mobile target recognition algorithm is used to identify whether a mobile target exists in the picture represented by the video frame data. Alternatively, the data transmitting end is configured with a frame of preset video frame data without a mobile target, and the data transmitting end determines whether a mobile target exists by comparing the video frame data with the preset video frame data. The data transmitting end can also determine whether a mobile target exists in the video frame data by other means, which is not specifically limited in the embodiments of the present application.
[0103] In actual applications, the common code stream encoding formats in the live broadcast and video detection industries are H264 or H265. Coding can compress data. For example, if the resolution of the video played on the display is 1280×720 and the frame rate is 25, the amount of data generated in one second is 1280×720 (pixels) × 25 (pictures) / 8 (1 byte 8 bits) (result: B) / 1024 (result: KB) / 1024 (result: MB) = 2.75MB. The display cannot receive such a large amount of data, so the data needs to be compressed. After the data collected by the image acquisition device is encoded using the encoding standard, the data to be transmitted can be obtained.
[0104] In the H264 architecture, the encoded data of a video image is called a frame. A frame consists of one or more slices, a slice consists of one or more macroblocks (MBs), and a macroblock consists of 16x16 YUV data. Macroblocks are the basic unit of H264 encoding. H264 uses intra-frame and inter-frame compression to improve encoding compression ratios. H264 employs a unique I-frame, P-frame, and B-frame strategy to achieve compression between consecutive frames.
[0105] Specifically, when the target parameters include frame type and frame content, the security level of the data to be transmitted is divided into first, second, and third levels, with the third level being higher than the second level, which is higher than the first level. If the first data to be transmitted is neither keyframe data nor a dynamic frame, the security level of the first data is first level; if the first data is keyframe data and not a dynamic frame, the security level of the first data is second level; if the data to be transmitted is neither keyframe data nor a dynamic frame, the security level of the first data is second level; if the data to be transmitted is neither keyframe data nor a dynamic frame, the security level of the first data is second level; and if the first data is keyframe data and a dynamic frame, the security level of the first data is third level.
[0106] For example, if the current first data video frame is a P frame and is a video captured by a personnel channel camera (non-important data), it can be determined that the security level of the video frame to be transmitted is the first level, that is, the lowest security level.
[0107] The current first data video frame is an I frame and is a video captured from a personnel channel camera (non-important data). It can be determined that the security level of the video frame to be transmitted is the second level, that is, the security level is medium.
[0108] The current first data video frame is a B frame, and is a video captured by a camera inside a cargo warehouse (important data). Therefore, it can be determined that the security level of the video frame to be transmitted is the second level, that is, the security level is medium.
[0109] The current video frame of the first data is an I frame, and is a video captured by a camera inside a cargo warehouse (important data). It can be determined that the security level of the video frame to be transmitted is the third level, which is the highest security level.
[0110] Optionally, the user may set more hierarchical security levels according to their own needs; for example, when the first data is key frame data and not a dynamic frame, the security level of the first data is higher than the security level of the first data when the data to be transmitted is not key frame data and is a dynamic frame; or, when the data to be transmitted is not key frame data and is a dynamic frame, the security level of the first data is higher than the security level of the first data when the first data is key frame data and not a dynamic frame.
[0111] It should be noted that the security level corresponding to a video frame captured by the same camera is not fixed and may change depending on the content of the first data to be transmitted. If there is a dynamic object in the video frame, the security level of the current video frame data is determined to be level 3. If it is detected that the video frame returns from dynamic to static, the security level of the current video frame data is determined to be level 2.
[0112] Exemplarily, if the data of the first video frame received by the data transmitting end corresponds to a key frame and a dynamic frame, the data transmitting end determines the security level of the video frame to be the third level, and during the encoding process of the video frame, both encryption and signing operations are performed on the data of the video frame. If the second video frame received by the data transmitting end corresponds to a non-key frame and a dynamic frame, the data transmitting end determines the security level of the video frame to be the second level, and during the encoding process of the video frame, encryption operations (or signing operations) are performed on the data of the video frame. If the third video frame received by the data transmitting end corresponds to a non-key frame and a static frame, the data transmitting end determines the security level of the video frame to be the first level, and during the encoding process of the video frame, neither encryption operations nor signing operations are performed on the data of the video frame.
[0113] As the target parameters of the data to be transmitted processed by the data sending end change dynamically, the security level of the data to be transmitted also changes dynamically, and the processing operations required for the data to be transmitted also change accordingly. The data sending end does not need to encrypt or sign all the data to be transmitted, which can not only reduce the resources occupied by the data sending end in processing the data to be transmitted, but also save transmission bandwidth and increase the transmission speed.
[0114] S203: When the security level of the first data is higher than the preset level, perform a processing operation on the first data to obtain second data.
[0115] The processing operation includes an encryption operation and / or a signature operation.
[0116] In some embodiments, when the preset level is the first level, if the security level of the first data is the second level, a signature operation is performed on the first data to obtain second data containing signature verification information and the first data; the second level is higher than the first level; and / or, when the security level of the first data is the third level, an encryption operation is performed on the first data using a preset encryption algorithm, and a signature operation is performed on the first data to obtain second data containing signature verification information and the encrypted first data; the third level is higher than the second level.
[0117] In other embodiments, when the security level of the first data is the second level, the first data is encrypted using a preset encryption algorithm, and the encrypted first data is used as the second data; the second level is higher than the first level; and / or, when the security level of the first data is the third level, the first data is encrypted using a preset encryption algorithm, and the first data is signed to obtain second data including signature verification information and the encrypted first data; the third level is higher than the second level.
[0118] That is, for the first data of the second level, the processing operation includes performing an encryption operation or a signature operation on the data to be transmitted; for the first data of the third level, the processing operation includes performing an encryption operation and a signature operation on the data to be transmitted.
[0119] As can be seen from the above, encryption or signing operations can ensure the security of data transmission and prevent tampering. The solution of this application determines the security level of the data to be transmitted and determines whether to perform encryption or signing operations based on the security level. While ensuring the security of important data, it can also take into account the improvement of data transmission efficiency.
[0120] S204: If the security level of the first data is not higher than a preset level, determine the first data as the second data.
[0121] In some embodiments, for the first data to be transmitted at the first level, the processing operation does not include encryption and signing operations on the first data. That is, when the security level of the first data is the first level, the data sending end does not perform any processing on the first data, does not encrypt or sign, and the final transmission is the original first data.
[0122] Based on the above description, a second correspondence can be pre-stored in the data sending end. The second correspondence is used to represent the correspondence between the security level of the first data and the processing operation that the data sending end needs to perform on the first data. The data sending end can then determine what processing operation needs to be performed on the first data based on the security level of the first data and the second correspondence. For example, the security level of the first data includes the first level, the second level, and the third level, where the third level is higher than the second level, and the second level is higher than the first level. The second correspondence includes: when the security level of the first data is the first level, the processing operation on the first data is to directly determine the first data as the second data; when the security level of the first data is the second level, the processing operation on the first data is to encrypt the first data (or sign the first data); when the security level of the first data is the third level, the processing operation on the first data is to encrypt and sign the first data.
[0123] S205: Generate a message including a level identifier of the security level of the first data and the second data.
[0124] The level identifier is used by the data receiving end to determine the security level of the first data.
[0125] In some embodiments, since the preset encoding standard stipulates that the data to be transmitted is written in the data unit, the data unit includes a header position and a data position, the header position includes a first position for writing an importance character, the importance character is used to indicate the importance of the data in the data unit, the data position is used to write the data to be transmitted, and the header position is located before the data position.
[0126] Then, when the video coding standard is the preset coding standard, generating a message containing a level identifier of the security level of the first data and the second data can be specifically implemented as follows: writing the level identifier of the security level of the first data in the first position of the header position, and writing the second data in the data position to obtain the message to be transmitted; when the video coding standard is not the preset coding standard, generating a message containing a level identifier of the security level of the first data and the second data can be specifically implemented as follows: constructing a second position for writing the level identifier of the security level of the first data in the format of the message; the format of the message also includes a data position, and the second position is located before the data position; writing the level identifier of the security level of the first data in the second position, and writing the second data in the data position to obtain the message to be transmitted.
[0127] Here, "before" can be understood as the data in front is generated first, the data receiving end receives this part of data first, and parses this part of data first. For example, the header position is before the data position. When the data sending end generates a message, it first generates the data in the header position, and then generates the data in the data position. When the data receiving end receives the message, it first parses the data in the header position, and then parses the data in the data position. For another example, the second position is before the data position. When the data sending end generates a message, it first generates the data in the second position, and then generates the data in the data position. When the data receiving end receives the message, it first parses the data in the second position, and then parses the data in the data position.
[0128] Optionally, when the second data includes signature verification information, the signature verification information is located at the end of the second data.
[0129] The term "tail" refers to the data at the end of the data that is generated last by the data sender and parsed last by the data receiver. For example, when generating the second data, the data sender first generates the preceding unencrypted or encrypted data, then appends the signature verification information to the preceding data. The data receiver then parses the signature verification information after receiving the second data.
[0130] For example, when the encoding format requires constructing a specific string, the data sender may add a security level identifier to the constructed specific string.
[0131] For example, the encoding format is H264 code stream encoding format or H265 code stream encoding format. The H264 or H265 code stream encoding format is NALU format, and the specific composition is as follows Figure 3 As shown in the figure, it includes the network abstraction layer unit (NALU) header and the raw byte sequence payload (RBSP). The NALU header corresponds to the header position, and the RBSP corresponds to the data position.
[0132] When the data sender uses a preset encoding format (such as H264 or H265 code stream encoding format), it is necessary to construct a NALU header. The NALU header format is as follows: Figure 4 As shown, it includes the F part (forbidden_zero_bit), the NRI part (nal_ref_idc), and the Type part (nal_unit_type). The F part is generally 0 in H264. The NRI part is used to indicate the importance of the NALU, that is, the position of the NRI part in the NALU header is the first position. The Type part is used to identify the data type of the RBSP.
[0133] The data sender can write the "security level" identifier in the NALU header. When the frame needs to complete the data signature, after writing the security level, the data sender uses its own signature private key to complete the NALU signature, and the signature value is written to the end of the RBSP. That is, the NALU composition after writing the signature can be as follows Figure 5 As shown. When the frame needs to complete data encryption, after writing the security level, the data sender can also encrypt the frame and write the decryption parameters required in the code stream to the data receiver. The data receiver can decrypt the code stream according to the decryption parameters in the code stream. The encrypted NALU format is as follows Figure 6 As shown in the figure, the RBSP plaintext is written before encryption, and the RBSP ciphertext is written after encryption.
[0134] S206: Send a message to the data receiving end.
[0135] In some embodiments, a third correspondence may be stored in the data receiving end. The third correspondence is used to represent the correspondence between the security level and the processing operation that the data receiving end needs to perform on the second data. The data receiving end can then determine what processing operation to perform on the second data based on the security level and the third correspondence. For example, the security levels include a first level, a second level, and a third level, where the third level is higher than the second level, and the second level is higher than the first level. The third correspondence includes: when the security level is the first level, the processing operation on the second data is to directly determine the second data as the first data; when the security level is the second level, the processing operation on the second data is to decrypt the second data (or perform a signature verification operation on the second data); and when the security level is the third level, the processing operation on the second data is to decrypt the second data and perform a signature verification operation on the second data.
[0136] In some embodiments, a data receiving end receives a message sent by a data sending end, and determines the security level corresponding to the level identifier in the message; when the security level is higher than a preset level, a processing operation is performed on the second data, and the data receiving end obtains the first data; the processing operation includes a decryption operation and / or a signature verification operation; when the security level is not higher than the preset level, the data receiving end determines that the second data is the first data, that is, the data receiving end directly obtains the first data.
[0137] For example, taking the first data including video frame data as an example, after the data receiving end obtains the code stream, it parses the code stream NALU header to obtain the security level, and performs corresponding signature verification, data decryption or direct decoding and playback according to the security level.
[0138] for example, Figure 7 FIG. 1 shows a schematic diagram of an interactive process of data transmission provided by an embodiment of the present application. Figure 7 As shown, when the data transmitting end is an image acquisition device and the data receiving end is a receiving terminal, the image acquisition device is used to acquire and encode video data, thereby transmitting the video data. The receiving terminal is used to receive and decode the received data, thereby playing the video data.
[0139] The image acquisition device acquires the first video data according to the color coding format. The image acquisition device determines the security level of the first video data based on whether the video data includes key frames and / or dynamic frames. If the first video data does not include key frames and does not include dynamic frames, it can be determined that the security level of the first video data is the first level. At this time, the first video data is determined to be the second video data. If the first video data only includes one of the key frames or dynamic frames, it can be determined that the security level of the first video data is the second level. At this time, the first video data is signed (or encrypted). Figure 7(For example, only signature processing is performed in this example) to obtain second video data. If the first video data includes key frames and dynamic frames, the security level of the first video data can be determined to be level three. In this case, the first video data is encrypted and signed to obtain second video data. After obtaining the second video data, the image acquisition device generates a message containing a security level identifier of the first video data and the second video data, and sends the message to the receiving terminal.
[0140] After receiving the message, the receiving terminal determines the security level of the data contained in the message based on the level identifier included in the message. According to different security levels, different processing operations are performed on the second video data to obtain the first video data. If the security level of the second video data is determined to be the first level, the receiving terminal directly decodes and plays the second video data. If the security level of the second video data is determined to be the second level, the receiving terminal performs corresponding signature verification processing (or decryption processing) on the second video data. Figure 7 In the example of performing only signature verification, the first video data is obtained and played. If the security level of the second video data is determined to be the third level, the receiving terminal performs corresponding signature verification and decryption on the second video data to obtain the first video data and play it.
[0141] Among them, there should be a trusted third-party certificate service between the data sender and the data receiver to facilitate the certificate exchange for signing operations, signature verification operations, encryption operations and decryption operations between the data sender and the data receiver.
[0142] In summary, Figure 2 The technical solution illustrated provides at least the following beneficial effects: Different data to be transmitted have different target parameters. This application assigns different security levels to data with different target parameters, and the processing operations corresponding to different security levels are also different. Therefore, for some data to be transmitted with low security levels, encryption or signing operations do not need to be performed on all data to be transmitted, and the data can be transmitted directly to the recipient. In other words, before the data is transmitted, the data transmitter dynamically classifies the data to be transmitted. The security level of the data to be transmitted changes with the target parameters corresponding to the data to be transmitted. Different security levels correspond to different processing operations, and not all data to be transmitted needs to be encrypted or signed before it can be transmitted. Therefore, when transmitting data to be transmitted, the resource usage caused by encryption and signing on the transmitting end can be reduced, and the resource usage caused by decryption and signature verification on the receiving end can also be reduced, thereby reducing the computing resource consumption of the receiving end. In addition, data to be transmitted with low security levels does not carry information related to encryption operations or signing operations during transmission, which reduces the transmission resources occupied and improves the data transmission rate.
[0143] The above mainly introduces the solution provided by the embodiment of the present application from the perspective of the method. In order to realize the above functions, it includes hardware structures and / or software modules corresponding to the execution of each function. It should be easy to realize that the technical goals in this field are combined with the units and algorithm steps of each example described in the embodiments disclosed herein, and the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technical goals can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0144] like Figure 8 As shown, the embodiment of the present application further provides a device 300 for securely transmitting a code stream based on dynamic data classification, which is applied to a data transmitting end. The device 300 for securely transmitting a code stream based on dynamic data classification includes:
[0145] An acquisition module 301 is configured to acquire first data to be transmitted, where the first data is video frame data;
[0146] Processing module 302 is configured to determine the security level of the first data based on target parameters corresponding to the first data; the target parameters include at least one of a frame type, a frame content, a frame source, a frame generation time, and a frame tag, the frame tag being used to indicate whether the first data is user-tagged data; if the security level of the first data is higher than a preset level, perform a processing operation on the first data to obtain second data, the processing operation including an encryption operation and / or a signing operation; if the security level of the first data is not higher than the preset level, determine the first data as second data; generate a message including a level identifier of the security level of the first data and the second data; the level identifier is used by a data receiving end to determine the security level of the first data;
[0147] The sending module 303 is used to send a message to the data receiving end.
[0148] For example, combined Figure 7 The code stream security transmission device 300 based on data dynamic classification can be applied to Figure 7 The image acquisition device shown.
[0149] In one possible implementation, the preset level is the first level; the processing module 302 is specifically used to: when the security level of the first data is the second level, perform a signing operation on the first data to obtain second data containing signature verification information and the first data; the second level is higher than the first level; and / or, when the security level of the first data is the third level, use a preset encryption algorithm to perform an encryption operation on the first data, and perform a signing operation on the first data to obtain second data containing signature verification information and the encrypted first data; the third level is higher than the second level.
[0150] In one possible implementation, the preset level is the first level; the processing module 302 is specifically used to: when the security level of the first data is the second level, use the preset encryption algorithm to encrypt the first data, and use the encrypted first data as the second data; the second level is higher than the first level; and / or, when the security level of the first data is the third level, use the preset encryption algorithm to encrypt the first data, and sign the first data to obtain second data including signature verification information and the encrypted first data; the third level is higher than the second level.
[0151] In one possible implementation, the frame types include: key frames and / or non-key frames, and the frame contents include: dynamic frames and / or static frames. The dynamic frames are used to represent the presence of moving targets in the video frame data, and the static frames are used to represent the absence of moving targets in the video frame data. The processing module 302 is also used to: perform moving target identification on the video frame data to determine whether there is a moving target in the video frame data; if there is a moving target in the video frame data, determine that the frame content corresponding to the video frame data is a dynamic frame; if there is no moving target in the video frame data, determine that the frame content corresponding to the video frame data is a static frame; and / or, based on the video coding standard, determine the frame type corresponding to the video frame data.
[0152] In one possible implementation, a first correspondence is pre-stored in the code stream security transmission device 300 based on dynamic data classification, and the first correspondence is used to characterize the correspondence between the target parameter and the security level; the processing module 302 is specifically used to: when the target parameter corresponding to the video frame data includes the frame type, determine the security level of the first data based on the first correspondence and the target parameter corresponding to the first data; wherein the security level of the video frame data corresponding to the key frame is higher than the security level of the video frame data corresponding to the non-key frame; or, when the target parameter corresponding to the video frame data includes the frame content, determine the security level of the first data based on the first correspondence and the target parameter corresponding to the first data; wherein the security level of the video frame data corresponding to the dynamic frame is higher than the security level of the video frame data corresponding to the static frame. The security level of the data; or, in a case where the target parameters corresponding to the video frame data include the frame type and the frame content, the security level of the first data is determined based on the first corresponding relationship and the target parameters corresponding to the first data; wherein, if the frame types corresponding to the video frame data are the same, the security level of the video frame data corresponding to the dynamic frame is higher than the security level of the video frame data corresponding to the static frame; if the frame contents corresponding to the video frame data are the same, the security level of the video frame data corresponding to the key frame is higher than the security level of the video frame data corresponding to the non-key frame; the security level of the video frame data corresponding to the key frame and the dynamic frame is higher than the security level of the video frame data corresponding to the non-key frame and the static frame; the security level of the video frame data corresponding to the key frame and the static frame is the same as the security level of the video frame data corresponding to the non-key frame and the dynamic frame.
[0153] In one possible implementation, the preset coding standard stipulates that the data to be transmitted is written into a data unit, the data unit includes a header position and a data position, the header position includes a first position for writing an importance character, the importance character is used to indicate the importance of the data in the data unit, the data position is used to write the data to be transmitted, and the header position is located before the data position; when the video coding standard is the preset coding standard, the processing module 302 is specifically used to: write a level identifier of the security level of the first data in the first position of the header position, write the second data in the data position, and obtain the message to be transmitted, and the header position is located before the data position; when the video coding standard is not the preset coding standard, the processing module 302 is specifically used to: construct a second position for writing a level identifier of the security level of the first data in the format of the message; the format of the message also includes a data position, and the second position is located before the data position; write the level identifier of the security level of the first data in the second position, write the second data in the data position, and obtain the message to be transmitted.
[0154] In one possible implementation, the frame source includes an important source and / or a non-important source; the frame generation time includes an important period and / or a non-important period; the frame tag includes an important tag and / or a non-important tag; a first correspondence is pre-stored in the data sending end, and the first correspondence is used to characterize the correspondence between the target parameter and the security level; the processing module is specifically used to: when the target parameter corresponding to the video frame data includes the frame source, determine the security level of the first data based on the first correspondence and the target parameter corresponding to the first data; wherein the security level of the video frame data corresponding to the important source is higher than the security level of the video frame data corresponding to the non-important source; or, when the target parameter corresponding to the video frame data includes the frame generation time, determine the security level of the first data based on the first correspondence and the target parameter corresponding to the first data; wherein the security level of the video frame data corresponding to the important period is higher than the security level of the video frame data corresponding to the non-important period; or, when the target parameter corresponding to the video frame data includes the frame tag, determine the security level of the first data based on the first correspondence and the target parameter corresponding to the first data; wherein the security level of the video frame data corresponding to the important tag is higher than the security level of the video frame data corresponding to the non-important tag.
[0155] In a possible implementation, when the second data includes signature verification information, the signature verification information is located at the end of the second data.
[0156] like Figure 9 As shown, the embodiment of the present application further provides a device 400 for securely transmitting a code stream based on dynamic data classification, which is applied to a data receiving end. The device 400 for securely transmitting a code stream based on dynamic data classification includes:
[0157] The receiving module 401 is configured to receive a message sent by a data transmitting end, wherein the message includes a level identifier and second data;
[0158] The processing module 402 is used to determine the security level corresponding to the level identifier in the message; when the security level is higher than the preset level, the second data is processed to obtain the first data, and the first data is the video frame data; the processing operation includes a decryption operation and / or a signature verification operation; when the security level is not higher than the preset level, the second data is determined to be the first data; wherein the security level is the security level of the first data; the security level of the first data is determined by the data sending end according to the target parameters corresponding to the first data, and the target parameters include at least one of the frame type, frame content, frame source, frame generation time and frame mark, and the frame mark is used to indicate whether the first data is data marked by the user.
[0159] For example, combined Figure 7The code stream security transmission device 400 based on data dynamic classification can be applied to Figure 7 The receiving terminal is shown.
[0160] In one possible implementation, the preset level is the first level; the processing module 402 is specifically used to: when the security level is the second level, perform a signature verification operation on the second data to obtain the first data; the second level is higher than the first level; and / or, when the security level is the third level, use a preset decryption algorithm to perform a decryption operation on the second data, and perform a signature verification operation on the second data to obtain the first data; the third level is higher than the second level.
[0161] In one possible implementation, the preset level is the first level; the processing module 402 is specifically used to: when the security level is the second level, use the preset decryption algorithm to decrypt the second data to obtain the first data; the second level is higher than the first level; and / or, when the security level is the third level, use the preset decryption algorithm to decrypt the second data and perform a signature verification operation on the second data to obtain the first data; the third level is higher than the second level.
[0162] In one possible implementation, the frame types include: key frames and / or non-key frames, and the frame contents include: dynamic frames and / or static frames. The dynamic frames are used to represent the presence of moving targets in the video frame data, and the static frames are used to represent the absence of moving targets in the video frame data. The frame content corresponding to the first data is determined by the data sending end after the data sending end identifies the moving target of the video frame, and the frame type corresponding to the first data is determined by the data sending end based on the video coding standard.
[0163] In one possible implementation, when the target parameters corresponding to the video frame data include frame types, the security level of the video frame data corresponding to key frames is higher than the security level of the video frame data corresponding to non-key frames; or, when the target parameters corresponding to the video frame data include frame content, the security level of the video frame data corresponding to dynamic frames is higher than the security level of the video frame data corresponding to static frames; or, when the target parameters corresponding to the video frame data include frame types and frame content: if the frame types corresponding to the video frame data are the same, the security level of the video frame data corresponding to dynamic frames is higher than the security level of the video frame data corresponding to static frames; if the frame contents corresponding to the video frame data are the same, the security level of the video frame data corresponding to key frames is higher than the security level of the video frame data corresponding to non-key frames; the security level of the video frame data corresponding to key frames and dynamic frames is higher than the security level of the video frame data corresponding to non-key frames and static frames; the security level of the video frame data corresponding to key frames and static frames is the same as the security level of the video frame data corresponding to non-key frames and dynamic frames.
[0164] In one possible implementation, the preset coding standard stipulates that the data to be transmitted is written in the data unit, the data unit includes a header position and a data position, the header position includes a first position for writing an importance character, the importance character is used to indicate the importance of the data in the data unit, the data position is used to write the data to be transmitted, and the header position is located before the data position; when the video coding standard is the preset coding standard, the level identifier of the security level of the first data is written in the first position in the header position, and the second data is written in the data position; when the video coding standard is not the preset coding standard, the message format is constructed with a second position and a data position, the second position is located before the data position, the level identifier of the security level of the first data is written in the second position, and the second data is written in the data position.
[0165] In one possible implementation, the frame source includes an important source and / or a non-important source; the frame generation moment includes an important time period and / or a non-important time period; the frame tag includes an important tag and / or a non-important tag; when the target parameter corresponding to the video frame data includes the frame source, the security level of the video frame data corresponding to the important source is higher than the security level of the video frame data corresponding to the non-important source; or, when the target parameter corresponding to the video frame data includes the frame generation moment, the security level of the video frame data corresponding to the important time period is higher than the security level of the video frame data corresponding to the non-important time period; or, when the target parameter corresponding to the video frame data includes the frame tag, the security level of the video frame data corresponding to the important tag is higher than the security level of the video frame data corresponding to the non-important tag.
[0166] In a possible implementation, when the second data includes signature verification information, the signature verification information is located at the end of the second data.
[0167] It should be noted that Figure 8 、 Figure 9 The module division described is illustrative and represents only one logical functional division. Actual implementations may employ different divisions. For example, two or more functions may be integrated into a single processing module. These integrated modules may be implemented as either hardware or software functional modules.
[0168] Another embodiment of the present application further provides an electronic device, such as Figure 10 As shown, electronic device 500 includes memory 501 and processor 502; memory 501 and processor 502 are coupled; memory 501 is used to store computer program code, which includes computer instructions. When processor 502 executes the computer instructions, electronic device 500 performs the steps performed by the data transmitter or receiver in the method flow shown in the above method embodiment.
[0169] by Figure 8 Taking the data dynamic classification based code stream security transmission device 300 as an example, in actual implementation, the acquisition module 301, the processing module 302 and the sending module 303 can be composed of Figure 10 The processor 502 is shown to implement the computer program code in the memory 501. The specific execution process can be referred to the description of the data processing method above, which will not be repeated here.
[0170] Another embodiment of the present application also provides a computer-readable storage medium, which stores computer instructions. When the computer instructions are executed on an electronic device, the electronic device executes each step performed by the data sending end or the data receiving end in the method flow shown in the above method embodiment.
[0171] In another embodiment of the present application, a computer program product is also provided. The computer program product includes computer instructions. When the computer instructions are executed on an electronic device, the electronic device executes each step performed by the data sending end or the data receiving end in the method flow shown in the above method embodiment.
[0172] The above embodiments can be implemented in whole or in part using software, hardware, firmware, or any combination thereof. When implemented using a software program, they can be implemented in whole or in part in the form of a computer program product. This computer program product includes one or more computer instructions. When these instructions are loaded and executed on a computer, the processes or functions according to the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media. Available media can include magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), etc.
[0173] The above is only a specific embodiment of the present application. Those skilled in the art may conceive of changes or substitutions based on the specific embodiment provided in this application, and all such changes or substitutions shall fall within the scope of protection of this application.
Claims
1. A code stream secure transmission method based on dynamic data classification, characterized in that: Applied to a data sending end, the method includes: Acquire first data to be transmitted, where the first data is video frame data; Determining a security level of the first data based on a target parameter corresponding to the first data; the target parameter includes a frame type and a frame content; wherein the frame type includes: a key frame and a non-key frame; the frame content includes: a dynamic frame and a static frame; the dynamic frame is used to indicate the presence of a moving target in the video frame data; and the static frame is used to indicate the absence of a moving target in the video frame data; When the first data to be transmitted is neither key frame data nor a dynamic frame, the security level of the first data is the first level; when the first data is key frame data and not a dynamic frame, the security level of the first data is the second level; when the data to be transmitted is neither key frame data nor a dynamic frame, the security level of the first data is the second level; when the first data is a key frame and a dynamic frame, the security level of the first data is the third level; the third level is higher than the second level, and the second level is higher than the first level; When the security level of the first data is higher than a preset level, performing a processing operation on the first data to obtain second data, the processing operation including an encryption operation and / or a signing operation; the preset level is the first level; If the security level of the first data is not higher than the preset level, determining the first data as the second data; generating a message including a level identifier of the security level of the first data and the second data; the level identifier is used by a data receiving end to determine the security level of the first data; Send the message to the data receiving end.
2. The method according to claim 1, It is characterized by: When the security level of the first data is higher than a preset level, processing the first data to obtain second data includes: When the security level of the first data is the second level, performing a signing operation on the first data to obtain the second data including signature verification information and the first data; the second level is higher than the first level; and / or, When the security level of the first data is the third level, the first data is encrypted using a preset encryption algorithm, and the first data is signed to obtain the second data including signature verification information and the encrypted first data; the third level is higher than the second level.
3. The method according to claim 1, It is characterized by: When the security level of the first data is higher than a preset level, processing the first data to obtain second data includes: When the security level of the first data is the second level, encrypting the first data using a preset encryption algorithm and using the encrypted first data as the second data; the second level is higher than the first level; and / or, When the security level of the first data is the third level, the first data is encrypted using a preset encryption algorithm, and the first data is signed to obtain the second data including signature verification information and the encrypted first data; the third level is higher than the second level.
4. The method according to claim 1, wherein The method further comprises: Performing moving target recognition on the video frame data to determine whether a moving target exists in the video frame data; If there is a moving object in the video frame data, determining that the frame content corresponding to the video frame data is a dynamic frame; If there is no moving object in the video frame data, determining that the frame content corresponding to the video frame data is a static frame; and / or, Based on a video coding standard, a frame type corresponding to the video frame data is determined.
5. The method according to claim 4, characterized in that The preset encoding standard stipulates that data to be transmitted is written into a data unit, the data unit includes a header position and a data position, the header position includes a first position for writing an importance character, the importance character is used to indicate the importance of the data in the data unit, the data position is used to write the data to be transmitted, and the header position is located before the data position; When the video coding standard is the preset coding standard, generating a message including a level identifier of a security level of the first data and the second data includes: Writing the security level identifier of the first data into the first position of the header position and writing the second data into the data position to obtain the message to be transmitted; In a case where the video coding standard is not the preset coding standard, generating a message including a level identifier of a security level of the first data and the second data includes: Constructing a second position for writing the level identifier of the security level of the first data in the message format; the message format also includes a data position, and the second position is located before the data position; The security level identifier of the first data is written into the second position, and the second data is written into the data position to obtain the message to be transmitted.
6. The method according to claim 1, wherein The target parameter further includes at least one of a frame source, a frame generation time, and a frame tag, the frame tag being used to indicate whether the first data is user-tagged data, the frame source including an important source and / or a non-important source; the frame generation time including an important period and / or a non-important period; the frame tag including an important tag and / or a non-important tag; the data transmitting end pre-stores a first corresponding relationship, the first corresponding relationship being used to indicate a corresponding relationship between the target parameter and the security level; The determining the security level of the first data according to the target parameter corresponding to the first data includes: determining a security level of the first data based on the first corresponding relationship and a target parameter corresponding to the first data; Wherein, in the case where the target parameter corresponding to the video frame data includes a frame source, the security level of the video frame data corresponding to the important source is higher than the security level of the video frame data corresponding to the non-important source; or In a case where the target parameter corresponding to the video frame data includes a frame generation time, the security level of the video frame data corresponding to the important time period is higher than the security level of the video frame data corresponding to the non-important time period; or In a case where the target parameter corresponding to the video frame data includes a frame tag, the security level of the video frame data corresponding to the important tag is higher than the security level of the video frame data corresponding to the unimportant tag.
7. The method according to claim 2 or 3, characterized in that In the case where the second data includes signature verification information, the signature verification information is located at the end of the second data.
8. A method for secure code stream transmission based on dynamic data classification, characterized in that: Applied to a data receiving end, the method includes: receiving a message sent by a data sending end, wherein the message includes a level identifier and second data; Determining a security level corresponding to the level identifier in the message; When the security level is higher than a preset level, performing a processing operation on the second data to obtain first data, where the first data is video frame data; the processing operation includes a decryption operation and / or a signature verification operation; and the preset level is the first level; If the security level is not higher than the preset level, determining the second data as the first data; Among them, the security level is the security level of the first data; the security level of the first data is determined by the data sending end according to the target parameters corresponding to the first data, and the target parameters include frame type and frame content; wherein, the frame type includes: key frame and non-key frame, and the frame content includes: dynamic frame and static frame, the dynamic frame is used to represent the presence of a moving target in the video frame data, and the static frame is used to represent the absence of a moving target in the video frame data; when the first data is not key frame data and is not a dynamic frame, the security level of the first data is the first level; when the first data is key frame data and is not a dynamic frame, the security level of the first data is the second level; when the data to be transmitted is not key frame data and is a dynamic frame, the security level of the first data is the second level; when the first data is a key frame and is a dynamic frame, the security level of the first data is the third level; the third level is higher than the second level, and the second level is higher than the first level.
9. The method according to claim 8, characterized in that When the security level is higher than the preset level, processing the second data to obtain the first data includes: When the security level is the second level, performing a signature verification operation on the second data to obtain the first data; the second level is higher than the first level; and / or, When the security level is the third level, a preset decryption algorithm is used to decrypt the second data, and a signature verification operation is performed on the second data to obtain the first data; the third level is higher than the second level.
10. The method according to claim 8, It is characterized by: When the security level is higher than the preset level, processing the second data to obtain the first data includes: When the security level is the second level, a preset decryption algorithm is used to decrypt the second data to obtain the first data; the second level is higher than the first level; and / or, When the security level is the third level, a preset decryption algorithm is used to decrypt the second data, and a signature verification operation is performed on the second data to obtain the first data; the third level is higher than the second level.
11. The method according to claim 8, characterized in that The frame content corresponding to the first data is determined by the data sending end after performing moving target recognition on the video frame, and the frame type corresponding to the first data is determined by the data sending end based on a video coding standard.
12. The method according to claim 11, characterized in that The preset encoding standard stipulates that data to be transmitted is written into a data unit, the data unit includes a header position and a data position, the header position includes a first position for writing an importance character, the importance character is used to indicate the importance of the data in the data unit, the data position is used to write the data to be transmitted, and the header position is located before the data position; In a case where the video coding standard is the preset coding standard, a level identifier of a security level of the first data is written into a first position in the header position, and the second data is written into the data position; When the video coding standard is not the preset coding standard, a second position and a data position are constructed in the format of the message, the second position is located before the data position, the level identifier of the security level of the first data is written in the second position, and the second data is written in the data position.
13. The method according to claim 8, characterized in that The target parameter further includes at least one of a frame source, a frame generation time, and a frame tag, wherein the frame tag is used to indicate whether the first data is data marked by a user, and the frame source includes an important source and / or a non-important source; the frame generation time includes an important time period and / or a non-important time period; and the frame tag includes an important tag and / or a non-important tag. In the case where the target parameter corresponding to the video frame data includes a frame source, the security level of the video frame data corresponding to the important source is higher than the security level of the video frame data corresponding to the non-important source; or In a case where the target parameter corresponding to the video frame data includes a frame generation time, the security level of the video frame data corresponding to the important time period is higher than the security level of the video frame data corresponding to the non-important time period; or In a case where the target parameter corresponding to the video frame data includes a frame tag, the security level of the video frame data corresponding to the important tag is higher than the security level of the video frame data corresponding to the unimportant tag.
14. The method according to claim 9 or 10, characterized in that In the case where the second data includes signature verification information, the signature verification information is located at the end of the second data.
15. An electronic device comprising a memory, a processor, and a computer program stored in the memory, wherein: The processor executes the computer program to implement the steps of the method according to any one of claims 1 to 7 or 8 to 13.
Citation Information
Patent Citations
Communication method for bus dispatching system and bus dispatching system
CN113114621A
Vehicle-mounted message safety communication method, system, equipment and medium
CN118764289A