A data encryption processing method, device, and electronic device applied to the AR scenario
By using three-dimensional point cloud data and gaze point data to dynamically identify the privacy domain in AR scenarios, and combining dynamic keys and suitable encryption algorithms for encryption, the problem of inefficient encryption in AR scenarios is solved, and efficient and secure data protection is achieved.
Patent Information
- Application Number
- CN202510386796.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2045-03-31
AI Technical Summary
In AR scenarios, traditional data encryption methods are difficult to efficiently protect multimodal data such as video, audio and three-dimensional point cloud data at the same time, resulting in low encryption processing efficiency.
By obtaining the three-dimensional point cloud data of the AR scene and the user's gaze data, dynamically identify the user's interest areas and high-concern areas, mark these areas as privacy domains, and store sensitive data in the privacy domain, encrypted using dynamic keys and suitable encryption algorithms.
Improve the efficiency and security of data encryption processing, ensure that sensitive data is only associated with content that users care about, reduce the risk of resource waste and data leakage, and adapt to the privacy protection needs of different users.
Smart Images

Figure CN119922012B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of data processing, and in particular, to a data encryption processing method, device, and electronic device applied to an AR scenario. Background Art
[0002] With the rapid development of AR technology, AR applications have gradually penetrated into multiple fields, such as intelligent navigation, virtual meetings, personalized advertising, telemedicine, etc. However, the realization of this experience requires processing privacy data such as geographical location information, user behavior trajectories, facial recognition data, and environmental perception information. These data are not only highly sensitive but also directly related to user privacy and security.
[0003] Currently, existing privacy data protection methods rely on traditional data encryption technologies. However, in an AR scenario, multi-modal data such as video, audio, and 3D point clouds need to be processed simultaneously. Traditional encryption methods are difficult to meet the diverse protection requirements of multi-modal data while ensuring high security, resulting in low data encryption processing efficiency.
[0004] Therefore, there is an urgent need for a data encryption processing method, device, and electronic device applied to an AR scenario. Summary of the Invention
[0005] The present application provides a data encryption processing method, device, and electronic device applied to an AR scenario, which is convenient for improving the data encryption processing efficiency.
[0006] In a first aspect of the present application, a data encryption processing method applied to an AR scenario is provided. The method includes: obtaining 3D point cloud data of a target AR scenario and fixation point data of a user in the target AR scenario, where the user wears AR glasses for presenting the target AR scenario; determining a privacy domain of the target AR scenario according to the 3D point cloud data and the fixation point data; obtaining sensitive data of the target AR scenario; storing the sensitive data in the privacy domain to obtain data to be encrypted; allocating a dynamic key to the data to be encrypted and encrypting the data to be encrypted in combination with a preset encryption algorithm.
[0007] By adopting the above technical solution, through the three-dimensional point cloud data and the user's fixation point data, the user's area of interest and highly concerned area in the target AR scene can be identified in real time, and these areas are marked as privacy domains. This can ensure that sensitive data is only associated with the content that the user cares about, avoiding the waste of resources in global protection. Based on the user's actual interaction behavior, the determination of the privacy domain is dynamic and personalized, adapting to the privacy protection needs of different users and improving the accuracy of data protection. Combining the three-dimensional point cloud information, not only can the geometric structure of the scene be obtained, but also the position of the virtual and real interaction content can be accurately located, providing spatial support for the division of the privacy domain. The use of the fixation point data reflects the user's real-time intention, combining the subjective area of interest with the objective scene data, which helps to improve the rationality and credibility of the privacy domain division. Through the aggregated storage of sensitive data in the privacy domain, data redundancy can be reduced, the risk of sensitive data leakage can be lowered, and at the same time, it provides convenience for subsequent encryption operations. Generating encryption keys dynamically based on the real-time environment improves the flexibility and security of data protection, making the keys more difficult to predict and crack. Combining different types of sensitive data and selecting suitable data encryption algorithms take into account both encryption strength and encryption efficiency. Therefore, it is convenient to improve the efficiency of data encryption processing.
[0008] Optionally, the obtaining of the three-dimensional point cloud data of the target AR scene and the fixation point data of the user in the target AR scene specifically includes: receiving the original scene image data of the target AR scene sent by the depth camera; analyzing the original scene image data by using an environmental perception model to generate the three-dimensional point cloud data; receiving the eye movement data of the user sent by the eye movement tracking sensor; and determining the fixation point data by using a fixation point analysis algorithm according to the eye movement data.
[0009] By adopting the above technical solution, the original scene image data is captured by a depth camera, and the three-dimensional point cloud data is generated through an environmental perception model, which can comprehensively reflect the geometric structure, object position, and depth information of the target AR scene. The eye movement data of the user is obtained through an eye tracking sensor, which can reflect the user's attention distribution and interaction intention in real time, supplementing the subjective interaction data missing in the scene information. Combining the three-dimensional point cloud data with the fixation point data not only provides the objective information of the scene but also integrates the user's subjective region of interest, providing a more comprehensive and dynamic basis for subsequent privacy domain division. Analyzing the original image data using an environmental perception model can intelligently identify the key elements and geometric relationships in the scene to generate high-quality three-dimensional point cloud data. This model has an adaptive ability to handle complex real-world scenes, ensuring the accuracy and integrity of the data. By using a fixation point analysis algorithm to extract the user's fixation points from the eye movement data, the specific positions or targets that the user is interested in can be quickly and accurately located to meet the real-time requirements of the AR scene. Based on the spatial information of the three-dimensional point cloud data and the region of interest of the fixation point data, it is possible to dynamically divide the privacy domain, ensuring that the scope of the privacy domain highly coincides with the user's real-time interaction behavior, thereby precisely protecting the user's sensitive information. The introduction of fixation point data reflects the personalized needs of users. Different users may have different focuses in the same scene. By dynamically identifying fixation points, a privacy domain division strategy that varies from person to person can be achieved. Through multi-modal data fusion and intelligent analysis algorithms, privacy protection is refined to the key areas that the user is interested in, avoiding indiscriminate processing of the entire scene data, thereby optimizing the efficiency and security of privacy protection. As the user's fixation points change, the privacy domain can be updated in real time to ensure that sensitive data is always protected, reducing the possibility of privacy leakage.
[0010] Optionally, determining the privacy domain of the target AR scene according to the three-dimensional point cloud data and the fixation point data specifically includes: determining the virtual elements where the user's line of sight converges from the three-dimensional point cloud data and the fixation point data; determining the virtual elements as the high-privacy domain; determining the environmental objects of the target AR scene from the three-dimensional point cloud data and the fixation point data; determining the environmental objects as the medium-privacy domain; determining the scene background of the target AR scene from the three-dimensional point cloud data and the fixation point data; determining the scene background as the low-privacy domain.
[0011] By adopting the above technical solution, through the combination of three-dimensional point cloud data and gaze point data, it is possible to dynamically capture the virtual elements where the user's line of sight converges, accurately define the content that the user highly concerns as the high-privacy domain, and ensure the accurate protection of sensitive data. The scene is divided into a high-privacy domain, a medium-privacy domain, and a low-privacy domain, and hierarchical protection is implemented according to the importance of the region and the sensitivity of the data, effectively avoiding resource waste while meeting the security requirements of different data. As the user's gaze point moves, the high-privacy domain, the medium-privacy domain, and the low-privacy domain can be updated in real time, enabling the privacy protection to dynamically adapt to the user's interaction behavior, and improving the flexibility and real-time nature of the protection. By differentiating the privacy domains, the overprotection of low-sensitive data is reduced, and the encrypted resources are concentrated on the data protection of the high-privacy domain, significantly improving the operating efficiency and resource utilization rate of the system. The three-dimensional point cloud data is used to provide the structural information of the scene, and the gaze point data is used to reflect the user's focus of attention. The combination of the two realizes the efficient identification of the key privacy areas in the scene. By classifying virtual elements, environmental objects, and scene backgrounds, all components of the AR scene are covered, ensuring the comprehensiveness of privacy protection. The division and dynamic adjustment of the privacy domain are transparent to the user, without interfering with the user's normal operations and experiences, enhancing the immersion and interaction fluency of the AR application. Based on the user's gaze point, the system can automatically adapt to the user's concerned content, implement a privacy protection strategy tailored to each individual, and improve the user's satisfaction and trust.
[0012] Optionally, the storing the sensitive data into the privacy domain to obtain the data to be encrypted specifically includes: splitting the sensitive data into multiple binary data segments by using a secret sharing algorithm; if it is determined that the target binary data segment belongs to the core shard of the sensitive data, then using a texture mapping technique to determine the target texture of the virtual element; adjusting the value corresponding to the target texture according to the value of the target binary data segment to obtain the first data to be embedded; and embedding the first data to be embedded into the high-privacy domain to obtain the data to be encrypted.
[0013] By adopting the above technical solution, the sensitive data is split into multiple binary data segments through the secret sharing algorithm. Even if an attacker obtains some of the data segments, the complete sensitive data cannot be restored, fundamentally improving the security of the data. Even if the data is stolen, this method cannot be cracked due to the lack of complete key information, thus effectively reducing the leakage risk. By determining which data segments belong to the core part of the sensitive data, these key data can be specifically protected, enabling the core data to be strengthened and protected, and further enhancing the overall security. By using the texture mapping technology to embed the core data into the target texture of the virtual element, the encrypted data can be hidden in the texture that is visually imperceptible, making the data embedding process invisible to both users and attackers, and enhancing the concealment of data protection. By adjusting the value of the target texture and embedding the encrypted data, the embedding of sensitive information does not change the visual appearance of the scene, and attackers cannot detect the data change through conventional analysis methods, thus avoiding being discovered by malicious attackers or monitoring systems. By splitting the data into multiple binary data segments and encrypting and protecting them according to their importance, a more fine-grained encryption strategy can be achieved, applying different encryption intensities to different data segments, improving the efficiency and security of the overall encryption process. Storing the data to be encrypted in a specific privacy domain not only improves the security of the data but also reduces the potential risk of data leakage. This hierarchical storage method ensures that sensitive data only exists in high-privacy areas, and other low-privacy areas do not contain sensitive data, reducing the attack surface.
[0014] Optionally, the method further includes: if it is determined that the target binary data segment belongs to the redundant shard of the sensitive data, encoding the target binary data segment into a decimal form to obtain encoded data; using the reference transparency value as the default value and embedding the encoded data into a small offset of the transparency to obtain the second data to be embedded; embedding the second data to be embedded into the low-privacy domain to obtain the data to be encrypted.
[0015] By adopting the above technical solution, by encoding redundant shards in decimal form and embedding tiny offsets of transparency, the embedding of data hardly changes the visual effect. It is difficult for attackers to identify or extract the embedded data through conventional means, thereby enhancing the concealment of data protection. The offset amplitude of the transparency value is very tiny, and the impact on the visual performance of the target AR scene can be ignored, ensuring that users cannot perceive the existence of data embedding while avoiding destroying the immersive experience of users. Encoding the redundant shards of sensitive data in decimal form greatly reduces the storage occupancy of redundant data and optimizes the embedding efficiency. Embedding data using the transparency channel of virtual objects in the AR scene does not require additional storage space, gives full play to the role of existing rendering resources, and saves system resources. Embedding redundant shards into the low-privacy domain for lightweight protection through transparency offset. The low-privacy domain does not contain sensitive content that users highly concern, so using this method can meet the basic privacy protection requirements while reducing the computational complexity. According to the importance of the privacy domain, different encryption and embedding methods are adopted for the core shards and redundant shards respectively to achieve hierarchical privacy protection, ensuring the centralized protection of highly sensitive data under limited resources. The data is split into core shards and redundant shards through the secret sharing algorithm. Even if some data segments are lost or attacked, as long as there are enough redundant shards, the original data can still be restored. This design enhances the robustness and anti-damage ability of the data protection scheme. Even if the embedded data in the low-privacy domain is stolen, since the encoded data in the transparency offset is redundant shards, attackers cannot reconstruct the complete sensitive data by parsing these shards alone, thereby further reducing the risk of data leakage.
[0016] Optionally, a dynamic key is allocated for the data to be encrypted, and the data to be encrypted is encrypted in combination with a preset encryption algorithm, which specifically includes: monitoring risk factors for the data to be encrypted through an edge computing device, where the risk factors include data interception and network fluctuations; if it is determined that the risk factors indicate no data interception and network fluctuations, then obtaining the eye movement pattern of the user; generating a random number using a pseudo-random number generation algorithm according to the eye movement pattern; and randomly generating the dynamic key using the random number.
[0017] By adopting the above technical solutions, the user's eye movement pattern is a highly personalized and difficult-to-replicate biometric behavior data. Combined with the pseudo-random number generation algorithm, it can generate unique and highly random dynamic keys, effectively avoiding security vulnerabilities in traditional key generation methods. The dynamic key depends on the randomly generated numbers in real time and does not need to be stored in the system for a long time, fundamentally reducing the risk of key theft and enhancing the security of overall data encryption. With the help of edge computing devices to monitor risk factors such as data interception and network fluctuations in real time, it can quickly judge the security of the current environment, ensure that key generation and data encryption are carried out in a secure environment, and improve the dynamic response ability of the system. If potential risks such as network fluctuations or interception behaviors are monitored, the key generation or encryption process can be postponed to avoid performing sensitive operations in a high-risk environment, further reducing security risks. The dynamic key is generated according to the user's eye movement pattern and is bound to the user's real-time behavior data, ensuring that the key used for each encryption is unique and effectively avoiding security problems such as replay attacks. The user does not need to perform additional operations, and the system can automatically collect data through the eye tracking device and generate dynamic keys, with strong concealment and without disturbing the user's normal AR usage experience.
[0018] Optionally, the method further includes: if it is determined that the privacy domain is the high-privacy domain, a lattice-based encryption algorithm is used to allocate the dynamic key to the high-privacy domain; if it is determined that the privacy domain is the medium-privacy domain, a medium-strength AES encryption algorithm is used to allocate the dynamic key to the medium-privacy domain; if it is determined that the privacy domain is the low-privacy domain, a lightweight symmetric encryption algorithm is used to allocate the dynamic key to the low-privacy domain.
[0019] By adopting the above technical solutions, different encryption algorithms with different strengths are dynamically selected according to the importance of the privacy domain, avoiding traditional encryption methods, and providing appropriate protection measures for different types of data, which is both secure and efficient. The high-privacy domain adopts a stronger encryption algorithm, such as a lattice-based algorithm, to ensure the security of highly sensitive data; while the low-privacy domain uses a lightweight symmetric encryption algorithm to reduce resource consumption and ensure the efficiency of system operation.
[0020] In a second aspect of the present application, a data encryption processing device for an AR scenario is provided. The data encryption processing device includes an acquisition module and a processing module. Among them, the acquisition module is used to acquire three-dimensional point cloud data of a target AR scenario and gaze point data of a user in the target AR scenario, and the user wears AR glasses for displaying the target AR scenario; the processing module is used to determine a privacy domain of the target AR scenario according to the three-dimensional point cloud data and the gaze point data; the acquisition module is further used to acquire sensitive data of the target AR scenario; the processing module is further used to store the sensitive data in the privacy domain to obtain data to be encrypted; the processing module is further used to allocate a dynamic key to the data to be encrypted and encrypt the data to be encrypted in combination with a preset encryption algorithm.
[0021] In a third aspect of the present application, an electronic device is provided. The electronic device includes a processor, a memory, a user interface, and a network interface. The memory is used to store instructions, and both the user interface and the network interface are used to communicate with other devices. The processor is used to execute the instructions stored in the memory so that the electronic device executes the method described above.
[0022] In a fourth aspect of the present application, a computer-readable storage medium is provided. The computer-readable storage medium stores instructions, and when the instructions are executed, the method described above is executed.
[0023] In summary, one or more technical solutions provided in the present application have at least the following technical effects or advantages:
[0024] Through the three-dimensional point cloud data and the user's gaze point data, the regions of interest and high-concern regions of the user in the target AR scene can be identified in real time, and these regions are marked as privacy domains. This can ensure that sensitive data is only associated with the content that the user cares about, avoiding the waste of resources in global protection. Based on the user's actual interaction behavior, the determination of the privacy domain is dynamic and personalized, adapting to the privacy protection needs of different users and improving the accuracy of data protection. Combining the three-dimensional point cloud information, not only can the geometric structure of the scene be obtained, but also the positions of the virtual and real interaction contents can be accurately located, providing spatial support for the division of the privacy domain. The use of gaze point data reflects the user's real-time intention, combining the subjective region of interest with the objective scene data, which helps to improve the rationality and credibility of the privacy domain division. Through the aggregated storage of sensitive data in the privacy domain, data redundancy can be reduced, the risk of sensitive data leakage can be lowered, and at the same time, it provides convenience for subsequent encryption operations. Generating encryption keys dynamically based on the real-time environment improves the flexibility and security of data protection, making the keys more difficult to predict and crack. Combining different types of sensitive data and selecting suitable data encryption algorithms take into account both encryption strength and encryption efficiency. Therefore, it is convenient to improve the efficiency of data encryption processing. Brief Description of the Drawings
[0025] Figure 1 It is a schematic flowchart of a data encryption processing method applied to an AR scene provided by an embodiment of the present application;
[0026] Figure 2 It is another schematic flowchart of a data encryption processing method applied to an AR scene provided by an embodiment of the present application;
[0027] Figure 3 It is a schematic module diagram of a data encryption processing device applied to an AR scene provided by an embodiment of the present application;
[0028] Figure 4 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application.
[0029] Description of the reference numerals: 31, acquisition module; 32, processing module; 41, processor; 42, communication bus; 43, user interface; 44, network interface; 45, memory. Detailed Embodiments
[0030] In order to enable those skilled in the art to better understand the technical solutions in this specification, the following will clearly and completely describe the technical solutions in the embodiments of this specification with reference to the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments.
[0031] In the description of the embodiments of the present application, words such as "for example" or "for illustration" are used to give examples, illustrations, or explanations. Any embodiment or design solution described as "for example" or "for illustration" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "for example" or "for illustration" is intended to present relevant concepts in a specific manner.
[0032] In the description of the embodiments of the present application, the term "a plurality of" means two or more. For example, a plurality of systems means two or more systems, and a plurality of screen terminals means two or more screen terminals. In addition, the terms "first" and "second" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance or implicitly specifying the technical features indicated. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features. The terms "include", "comprise", "have" and their variants all mean "including but not limited to", unless otherwise specifically emphasized in other ways.
[0033] With the rapid development of augmented reality technology, its applications have been widely penetrated into many fields such as intelligent navigation, virtual meetings, personalized advertising, and telemedicine. The realization of these immersive experiences requires processing a variety of privacy data including geographical location information, user behavior trajectories, facial recognition data, and environmental perception information. These data are not only highly sensitive but also directly related to user privacy and data security.
[0034] Current privacy protection technologies mainly rely on traditional data encryption methods. However, in the AR scenario, the application needs to process multi-modal data such as video, audio, and 3D point clouds at the same time. Due to the complex and interrelated nature of these data forms, traditional encryption methods are difficult to meet the diverse protection requirements of multi-modal data while ensuring high security, often resulting in low encryption processing efficiency and difficulty in meeting the high requirements for real-time and flexibility in the AR scenario.
[0035] To solve the above technical problems, the present application provides a data encryption processing method applied to the AR scenario, referring to Figure 1 , Figure 1 is a schematic flowchart of a data encryption processing method applied to the AR scenario provided by the embodiments of the present application. This method is applied to a server and includes steps S110 to S150. The above steps are as follows:
[0036] S110. Obtain the 3D point cloud data of the target AR scenario and the fixation point data of the user in the target AR scenario. The user wears AR glasses for displaying the target AR scenario.
[0037] Specifically, as the core computing device, the server is responsible for processing and storing the data uploaded from the AR glasses. Its main tasks are to obtain and analyze the three-dimensional point cloud data of the target scene and the user's fixation point data. These data provide the basis for subsequent scene understanding and personalized interaction. The three-dimensional point cloud data is collected by sensors such as depth cameras or lidar on the AR glasses, which can accurately describe the three-dimensional spatial structure of objects and the environment in the target AR scene. The point cloud data is represented in the form of the coordinates of a series of points and is used to reconstruct the three-dimensional model of the scene. The fixation point data is collected by the eye tracking sensor built into the AR glasses. The eye movement sensor tracks the user's eye movements to determine the specific area of interest of the user in the target scene. The role of the fixation point data is to capture the user's points of interest, thus providing a basis for the dynamic processing of data and the division of privacy domains in the scene. Among them, as the main interaction device, the AR glasses are not only used to display the target AR scene, but also responsible for capturing the user's line of sight and scene information in real time and transmitting the data to the server for calculation and storage. It is the bridge between data collection and display.
[0038] In a possible implementation manner, obtaining the three-dimensional point cloud data of the target AR scene and the fixation point data of the user in the target AR scene specifically includes: receiving the original scene image data of the target AR scene sent by the depth camera; analyzing the original scene image data using an environmental perception model to generate three-dimensional point cloud data; receiving the eye movement data of the user sent by the eye tracking sensor; and determining the fixation point data according to the eye movement data using a fixation point analysis algorithm.
[0039] Specifically, the depth camera is used to capture the depth information in the AR scene. The depth information can describe the distance between each object in the scene and the camera, forming the basic data of the three-dimensional scene. The eye tracking sensor tracks the user's eye movements in real time, collects the user's fixation direction and points of interest, and is used to judge the specific position or target that the user is interested in. After the depth camera captures the target scene, the generated original image data includes a two-dimensional color image and depth information. These data are transmitted to the server or computing device as the basic input for subsequent analysis. Through an environmental perception model, such as an algorithm based on machine learning or computer vision, the original image data is analyzed and processed to convert the two-dimensional image data and depth information into three-dimensional point cloud data. The point cloud data represents the three-dimensional coordinates of each object in the scene in the form of discrete points and is used to construct the three-dimensional structure model of the entire scene. The eye tracking sensor monitors the user's eye movements and captures the user's line of sight direction and fixation focus. According to the eye movement data, specific fixation point analysis algorithms, such as geometric mapping and heat map generation, are used to calculate the corresponding positions of the user's fixation points in the three-dimensional scene. These fixation point data can reflect the user's area of interest or points of interest.
[0040] S120. Determine the privacy domain of the target AR scene based on the three-dimensional point cloud data and the gaze point data.
[0041] Specifically, the high-privacy domain is the area where the user's line of sight frequently focuses or continuously stays. For example, virtual objects being gazed at by the user, personal information display areas, etc. The medium-privacy domain is environmental objects that the user may indirectly pay attention to. For example, furniture or environmental objects around the user. The low-privacy domain is the background part of the scene or the area that does not involve privacy, such as distant scenery or a background wall.
[0042] For example, the server analyzes and finds that the user's gaze points mainly concentrate on the virtual memo area, so it is marked as the high-privacy domain. This area may contain the user's private information, such as meeting records, to-do items, etc. The conference table that the user occasionally pays attention to is marked as the medium-privacy domain because it may contain sensitive content such as documents and items. The company logo on the background wall and other un-gazed areas are marked as the low-privacy domain because they do not involve the user's personal privacy.
[0043] In a possible implementation manner, determining the privacy domain of the target AR scene based on the three-dimensional point cloud data and the gaze point data specifically includes: determining, from the three-dimensional point cloud data and the gaze point data, the virtual elements where the user's line of sight converges; determining the virtual elements as the high-privacy domain; determining, from the three-dimensional point cloud data and the gaze point data, the environmental objects of the target AR scene; determining the environmental objects as the medium-privacy domain; determining, from the three-dimensional point cloud data and the gaze point data, the scene background of the target AR scene; determining the scene background as the low-privacy domain.
[0044] Specifically, through the gaze point data, determine the main objects of the user's line of sight attention. These virtual elements may be content that directly interacts with the user or areas containing sensitive information. For example: personal information on a virtual screen, sensitive virtual objects, or content that requires strict protection. Apply high-level privacy protection to these areas, such as strong encryption and access control. The medium-privacy domain is the area where the environmental objects extracted from the three-dimensional point cloud data are areas that the user may indirectly pay attention to. For example, items, furniture around the user, or some objects that are not related to the operation but are related to the scene. The privacy requirements for these areas are relatively low, and medium-strength protection strategies can be adopted. The low-privacy domain includes the scene background that the user does not actively pay attention to and does not contain sensitive information, such as distant scenery, blank walls, or other unimportant scene information. Take basic protection measures for these areas or directly ignore special protection.
[0045] S130. Obtain the sensitive data of the target AR scene.
[0046] Specifically, in an AR scenario, sensitive data refers to specific data types related to user privacy, personal information, or critical content. For example: users' personal identity information, such as names, avatars, account information; users' activity data, such as fixation points, behavioral trajectories; content data in interactions, such as virtual items or interaction records; private data in the environment, such as home layouts, room structures. The server collects the raw data of the target AR scenario through cameras, sensors, and AR glasses. The server extracts information related to user interactions from these raw data. Through preset rules or models, it identifies which data belongs to sensitive data.
[0047] S140. Store the sensitive data in the privacy domain to obtain the data to be encrypted.
[0048] Specifically, the data to be encrypted is the data stored in the privacy domain that is marked as data that needs to be encrypted. According to its privacy level, an appropriate encryption strength and algorithm are selected. After the server collects the sensitive data, based on the privacy domain division model, the data is classified into different privacy domains. It records which data needs to be encrypted and selects the corresponding encryption algorithm according to the privacy level.
[0049] In a possible implementation, storing the sensitive data in the privacy domain to obtain the data to be encrypted specifically includes: using the secret sharing algorithm to split the sensitive data into multiple binary data segments; if it is determined that the target binary data segment belongs to the core shard of the sensitive data, then use the texture mapping technology to determine the target texture of the virtual element; adjust the value corresponding to the target texture according to the value of the target binary data segment to obtain the first data to be embedded; embed the first data to be embedded into the high-privacy domain to obtain the data to be encrypted.
[0050] Specifically, the secret sharing algorithm is an encryption technology that splits sensitive data into multiple binary data segments and distributes these data segments to different storage locations or objects. This makes it impossible for attackers to obtain the complete sensitive data even if a part of the data is leaked, thus increasing security. For example, suppose there is a data block containing sensitive information (such as a payment password). The secret sharing algorithm will split this data block into multiple shards, and each shard only contains partial information of the data. Each shard is meaningless by itself, and only by recombining these shards can the complete sensitive data be restored. The core shard refers to the key part of the sensitive data, which is the most important part of the data and must be protected at the highest level.
[0051] In an augmented reality application, virtual elements refer to visual objects in the AR scene (such as virtual objects or markers). Through texture mapping technology, by embedding data into the appearance (i.e., texture) of these virtual elements, sensitive data can be "invisible" visually but still protected at the technical level. For example, suppose there is a virtual commodity (such as a virtual shoe). Sensitive data can be embedded into the surface pattern of the shoe through texture mapping, so that the appearance of the shoe is associated with the data, but the data cannot be directly seen by the outside world. For the target data of the core shard, attributes such as the color and details of the texture can be adjusted according to the value of the data. This adjustment not only ensures that the data is embedded in the virtual object, but also makes the embedded data information hidden in the virtual scene and can only be extracted through specific decryption techniques. For example, if the shard data is "1101", then the color or transparency of the texture may change accordingly, such as becoming slightly transparent or the hue changing, to covertly represent the data.
[0052] The high-privacy domain refers to those areas with extremely high requirements for user privacy protection (such as sensitive information like user identities and passwords). Sensitive data stored in these areas requires the strongest encryption protection. Store the adjusted embedded data (i.e., the first data to be embedded) in this high-privacy domain to ensure that the data in this area is protected at the highest level. For example, the texture of a virtual object (such as a virtual shoe) is adjusted and embedded with sensitive data (such as a password) and stored in the high-privacy domain of the AR application. This ensures that only authorized users or systems can access this sensitive data.
[0053] For example, assume that the target AR scenario is the protection of sensitive data in AR virtual shopping. The user enters the virtual shopping scenario through AR glasses, browses virtual goods and makes payments. During this process, the system needs to protect sensitive data such as the user's payment password and shopping records. The user's payment password is split into multiple binary data segments by a secret sharing algorithm, such as "1101", "0110", "1001", etc. These data segments are stored in the textures of different virtual goods respectively, and each data segment is embedded into the texture mapping of a specific virtual element (such as virtual shoes, virtual clothes). Among them, a certain key virtual good (such as a pair of shoes) is selected as the target texture of the high-privacy domain. The surface texture of the shoes is adjusted according to the core shard of the payment password (such as "1101"), so that its color and transparency change, but these changes are invisible to ordinary users. For example, the color of the texture may change from the standard blue to a reddish color, or its transparency may change slightly. These changes are only for hiding data, rather than changing the appearance of the object. Finally, these adjusted textures (the first data to be embedded) are stored in the high-privacy domain, that is, the area where the user's payment information and account information are located. In this way, only authorized systems or devices can access the textures of these virtual objects, decrypt and restore the user's sensitive data.
[0054] Through the above steps, the server can use elements in the virtual scenario, such as textures and transparency, to secretly store and protect sensitive data. The combination of encryption and steganography technologies can not only effectively protect user privacy, but also ensure the security of sensitive information in the augmented reality scenario. This method improves the user experience while ensuring the privacy and security of data.
[0055] In a possible implementation, if it is determined that the target binary data segment belongs to the redundant shard of sensitive data, the target binary data segment is encoded into a decimal form to obtain encoded data; the reference transparency value is used as the default value, and the encoded data is embedded into a small offset of transparency to obtain the second data to be embedded; the second data to be embedded is embedded into the low-privacy domain to obtain the data to be encrypted.
[0056] Specifically, during the encryption process of sensitive data, some data may not be critical data but redundant parts. Redundant shards are backup data for data recovery. A single redundant shard is not sufficient to recover sensitive information, but in the complete shards, they play a role in protection and redundancy. Encoding the data of these redundant shards into decimal form aims to store the data in a more concealed way to prevent it from being directly recognized or extracted. This encoding method can make the data look more "blurred", thus increasing the difficulty of data protection. For example, if the redundant shard is the binary data "1101", it may be converted into the decimal "2.75", and this decimal form is less likely to be directly understood and extracted than the original binary data. The transparency value is used to describe the transparency degree of the object surface. The larger the value, the less transparent the object is, and the smaller the value, the more transparent the object is. Here, the reference transparency value is used as the default value, that is, the initial transparency, representing the standard display state of the virtual element. For example, assume the reference transparency value is 0.8, which means the transparency of the virtual object is 80%, that is, only 20% of the part is transparent.
[0057] Among them, by slightly adjusting the transparency value, the redundant data is secretly stored in the texture of the virtual object, and these adjustments are imperceptible to the naked eye. For example, if the encoded data is "2.75", it may correspond to a slight change in the transparency value (for example, from 0.8 to 0.802), and this change is small enough that it cannot be directly detected by the user's vision, but it can secretly store the data. The low-privacy domain refers to the area with lower requirements for data protection. The data in these areas does not involve very sensitive user information and may be some public or sharable data. In the AR scenario, this may be some background information or environmental data that has little association with user privacy. For example, the background of the virtual object, environmental scenery, etc. can be used as the low-privacy domain, and this data is not crucial for protecting user privacy. By embedding the second data to be embedded (i.e., the adjusted transparency data) into the virtual element (such as the background texture) in the low-privacy domain, redundant data can be secretly stored without affecting the user experience. For example, adjusting the transparency on the background texture of the virtual scenery so that it "invisibly" carries the redundant data. What the user's eyes see is still the normal virtual scene, but the data has been encrypted and concealed behind. In this process, the redundant data has been successfully embedded into the virtual element in the low-privacy domain through the transparency fine-tuning method, and the data is invisible. In this way, the data to be encrypted is ready and can be further encrypted when needed to ensure data security. For example, the background texture of the virtual object has been adjusted to secretly store the redundant shard data, waiting for subsequent encryption operations.
[0058] For example, assume that the target AR scenario is the protection of sensitive data in an AR game. The user experiences the game in the virtual game world through AR glasses. Sensitive data of the user, such as account information, game records, etc., are involved in the game, but some data are redundant and do not directly affect the progress of the game. The user's game data (such as "combat power score") is split into multiple data shards, and one of the shards is redundant data. This redundant data may be "1101", which becomes "2.75" after encoding for further concealment. On the texture of the virtual game background, the reference transparency value is set to 0.8. To embed the redundant data "2.75", the transparency value is finely tuned to 0.802, and this change is hardly noticeable to the user. These finely tuned transparency data are embedded into the background texture (low privacy domain) in the virtual game. The transparency values of background objects (such as the sky, the ground, etc.) are slightly adjusted to ensure that the redundant data is stored secretly therein. Although there is a slight change in the transparency of the background texture and the user cannot perceive it, the redundant part of the sensitive data has been concealed in the virtual environment and can be encrypted at any time to ensure the security of the data.
[0059] S150. Allocate a dynamic key for the data to be encrypted, and encrypt the data to be encrypted in combination with a preset encryption algorithm.
[0060] Specifically, in the encryption process, the key is a key factor in protecting data security. A dynamic key refers to a new and temporary key generated each time encryption is performed. Different from a static key, a dynamic key is different each time, which can effectively increase the difficulty of data being cracked. The dynamic key is generated through some random algorithms, user behavior data, or external factors. Such a key generation method not only increases the security of the encryption process but also prevents attackers from obtaining the content of multiple data by cracking the static key. Assume that the user is using AR glasses to browse virtual content, and the server will generate a new dynamic key through a pseudo-random number generation algorithm based on information such as the real-time environment and the user's interaction behavior (such as eye movement data). Each time encryption is performed, this new key is used to encrypt the data.
[0061] Among them, the encryption algorithm is the specific technical solution used to encrypt data. The preset encryption algorithm refers to an encryption algorithm that has been selected and fixed during design, such as a symmetric encryption algorithm (such as AES) or an asymmetric encryption algorithm (such as RSA). When encrypting in combination with a dynamic key, the selected encryption algorithm uses the key to process the data to be encrypted, so that the original data is converted into unrecognizable encrypted data, and only those with the corresponding key can decrypt and restore it. The encryption algorithm can select encryption methods that adapt to different security requirements. For example, some applications may require higher-strength encryption, such as encryption algorithms based on lattice cryptography, or use lighter-weight encryption algorithms, such as the AES encryption algorithm.
[0062] In a possible implementation, a dynamic key is assigned to the data to be encrypted, and the data to be encrypted is encrypted in combination with a preset encryption algorithm. Specifically, it includes: monitoring risk factors for the data to be encrypted through an edge computing device, where the risk factors include data interception and network fluctuations; if it is determined that the risk factors indicate no data interception and network fluctuations, obtaining the user's eye movement pattern; generating a random number using a pseudo-random number generation algorithm according to the eye movement pattern; and randomly generating a dynamic key using the random number.
[0063] Specifically, an edge computing device refers to a computing device or server deployed at the edge of the network and close to the data source. The edge computing device can process data from user devices in real time and make a quick response. Risk factors include factors that may threaten data security, such as data interception and network fluctuations. Data interception refers to malicious attackers intercepting data during transmission, and network fluctuations may affect the stability of data transmission. The edge computing device will monitor these risk factors in real time. If the server detects a risk of data interception or large network fluctuations, it will take measures to prevent data leakage or loss. Suppose a user is browsing virtual reality content through AR glasses, the edge computing device can detect in real time whether the user's network environment is stable. If it is found that the network fluctuations are large or the risk of data interception is high, the server will automatically respond to protect data security.
[0064] When it is monitored that the data has not been intercepted and the network is stable, the server will further analyze the user's behavior pattern. Here, the eye movement pattern refers to the movement trajectory and fixation points of the user's eyes, such as information about the objects the user gazes at and the viewing time in the AR scenario. Eye movement data can provide valuable information about where the user's attention is focused and what content the user is interested in in the AR application. The server can generate a random value related to the user's behavior based on this data. Suppose the user is viewing a car in the AR scenario, the server will capture the user's eye movement data and determine whether the user is continuously gazing at the car. If the user's eye movement pattern indicates that he has a long-term fixation on a certain element (such as a virtual object), the server may generate an encryption key based on this behavior.
[0065] Once the user's eye movement pattern is obtained, the server will use a pseudo-random number generation algorithm (PRNG) to generate a random number based on the eye movement data. The values generated by the pseudo-random number generation algorithm through specific mathematical formulas appear to be random, but are actually predictable. In this step, the pseudo-random number generation algorithm will generate a random number based on the characteristics of the eye movement pattern, such as the speed of eye movement, the fixation time, the type of object being focused on, etc., as the basis for generating the dynamic key in the subsequent step.
[0066] In a possible implementation, referring to Figure 2 ,Figure 2 Another process schematic diagram of a data encryption processing method applied to the AR scenario provided by the embodiment of this application. It includes steps S210 to S230, and the above steps are as follows: S210. If it is determined that the privacy domain is a high-privacy domain, a lattice-based encryption algorithm is used to assign a dynamic key to the high-privacy domain; S220. If it is determined that the privacy domain is a medium-privacy domain, a medium-strength AES encryption algorithm is used to assign a dynamic key to the medium-privacy domain; S230. If it is determined that the privacy domain is a low-privacy domain, a lightweight symmetric encryption algorithm is used to assign a dynamic key to the low-privacy domain.
[0067] Specifically, lattice-based cryptography is a new encryption algorithm with the ability to resist quantum computing attacks. It is currently one of the encryption schemes recognized for designing in the future quantum computing environment. The advantage of lattice-based cryptography is that even for a quantum computer, it is difficult to break the encryption based on lattice problems. The data in the high-privacy domain contains extremely sensitive personal information of users, such as facial recognition data, medical records, financial information, etc. Once these information are leaked, it will seriously threaten the privacy and security of users. Suppose in a medical AR application, the health data of users (such as genetic information, medical record records, etc.) need to be encrypted and stored. These data belong to the high-privacy domain, so a lattice-based encryption algorithm will be selected to ensure the extremely high security of the data and prevent leakage or being cracked.
[0068] The AES algorithm is a symmetric encryption algorithm widely used currently, with high security and low computational complexity, and is suitable for most application scenarios. The security of AES is one of the strongest among the currently known encryption algorithms, especially for data with medium-strength security requirements. The data in the medium-privacy domain may contain the behavior data, communication records, etc. of users. These information also need to be protected in some cases, but their sensitivity is lower than that of the data in the high-privacy domain. In an AR-based intelligent navigation application, the geographical location data of users belongs to the medium-privacy domain because the leakage of these data may affect the privacy of users, but its impact is not as serious as that of facial recognition data. In this case, the AES encryption algorithm can be used to encrypt the location data to ensure the security during data transmission.
[0069] Lightweight symmetric encryption algorithms, such as XTEA, RC4, etc., are relatively simplified and fast encryption methods compared to AES and lattice-based encryption algorithms, and are mainly used for devices with limited resources (such as Internet of Things devices, embedded devices, etc.). These encryption algorithms are suitable for data transmission or storage scenarios with high performance requirements, but compared to AES, etc., their security is lower. Low-privacy domain data is some non-sensitive or public content, such as environmental data, scene background information, etc. Even if this data is leaked, it has little impact on the user's privacy. Therefore, lightweight encryption algorithms can be used. In an AR advertising application, the advertising content or background image data in the scene may belong to the low-privacy domain. The user's interaction behavior with the advertisement, the display data of the advertisement, etc. do not involve personal privacy. Therefore, lightweight encryption algorithms, such as RC4, can be used to quickly encrypt this data to improve the application performance while maintaining a certain level of security.
[0070] This application also provides a data encryption processing device applied to the AR scenario. Refer to Figure 3 , Figure 3 which is a schematic diagram of the modules of a data encryption processing device applied to the AR scenario provided by the embodiments of this application. This data encryption processing device is a server, and the server includes an acquisition module 31 and a processing module 32. Among them, the acquisition module 31 acquires the three-dimensional point cloud data of the target AR scenario and the fixation point data of the user in the target AR scenario. The user wears AR glasses for displaying the target AR scenario; the processing module 32 determines the privacy domain of the target AR scenario according to the three-dimensional point cloud data and the fixation point data; the acquisition module 31 acquires the sensitive data of the target AR scenario; the processing module 32 stores the sensitive data in the privacy domain to obtain the data to be encrypted; the processing module 32 assigns a dynamic key to the data to be encrypted and encrypts the data to be encrypted in combination with a preset encryption algorithm.
[0071] In a possible implementation manner, the acquisition module 31 acquires the three-dimensional point cloud data of the target AR scenario and the fixation point data of the user in the target AR scenario, specifically including: the acquisition module 31 receives the original scene image data of the target AR scenario sent by the depth camera; the processing module 32 analyzes the original scene image data using an environmental perception model to generate three-dimensional point cloud data; the acquisition module 31 receives the eye movement data of the user sent by the eye movement tracking sensor; the processing module 32 determines the fixation point data according to the eye movement data using a fixation point analysis algorithm.
[0072] In a possible implementation, the processing module 32 determines the privacy domain of the target AR scene according to the three-dimensional point cloud data and the fixation point data, specifically including: the processing module 32 determines the virtual elements focused by the user's line of sight from the three-dimensional point cloud data and the fixation point data; the processing module 32 determines the virtual elements as the high-privacy domain; the processing module 32 determines the environmental objects of the target AR scene from the three-dimensional point cloud data and the fixation point data; the processing module 32 determines the environmental objects as the medium-privacy domain; the processing module 32 determines the scene background of the target AR scene from the three-dimensional point cloud data and the fixation point data; the processing module 32 determines the scene background as the low-privacy domain.
[0073] In a possible implementation, the processing module 32 stores the sensitive data into the privacy domain to obtain the data to be encrypted, specifically including: the processing module 32 splits the sensitive data into multiple binary data segments by using the secret sharing algorithm; if the processing module 32 determines that the target binary data segment belongs to the core shard of the sensitive data, it determines the target texture of the virtual element by using the texture mapping technology; the processing module 32 adjusts the value corresponding to the target texture according to the value of the target binary data segment to obtain the first data to be embedded; the processing module 32 embeds the first data to be embedded into the high-privacy domain to obtain the data to be encrypted.
[0074] In a possible implementation, if the processing module 32 determines that the target binary data segment belongs to the redundant shard of the sensitive data, it encodes the target binary data segment into a decimal form to obtain the encoded data; the processing module 32 uses the reference transparency value as the default value and embeds the encoded data into a small offset of the transparency to obtain the second data to be embedded; the processing module 32 embeds the second data to be embedded into the low-privacy domain to obtain the data to be encrypted.
[0075] In a possible implementation, the processing module 32 assigns a dynamic key to the data to be encrypted and encrypts the data to be encrypted in combination with a preset encryption algorithm, specifically including: the processing module 32 monitors the risk factors for the data to be encrypted through the edge computing device, and the risk factors include data interception and network fluctuations; if the processing module 32 determines that the risk factors indicate that there is no data interception and network fluctuations, it obtains the user's eye movement pattern; the processing module 32 generates a random number by using the pseudo-random number generation algorithm according to the eye movement pattern; the processing module 32 randomly generates a dynamic key by using the random number.
[0076] In a possible implementation, if the processing module 32 determines that the privacy domain is the high-privacy domain, it assigns a dynamic key to the high-privacy domain by using the lattice-based encryption algorithm; if the processing module 32 determines that the privacy domain is the medium-privacy domain, it assigns a dynamic key to the medium-privacy domain by using the medium-strength AES encryption algorithm; if the processing module 32 determines that the privacy domain is the low-privacy domain, it assigns a dynamic key to the low-privacy domain by using the lightweight symmetric encryption algorithm.
[0077] It should be noted that when the device provided in the above embodiments realizes its functions, only the division of the above functional modules is used for illustration. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the device and method embodiments provided in the above embodiments belong to the same concept. For the specific implementation process, please refer to the method embodiments and will not be elaborated here.
[0078] This application also provides an electronic device. Refer to Figure 4 , Figure 4 which is a schematic structural diagram of an electronic device provided by an embodiment of this application. The electronic device may include: at least one processor 41, at least one network interface 44, a user interface 43, a memory 45, and at least one communication bus 42.
[0079] Among them, the communication bus 42 is used to realize the connection and communication between these components.
[0080] Among them, the user interface 43 may include a display screen (Display) and a camera (Camera). Optionally, the user interface 43 may further include a standard wired interface and a wireless interface.
[0081] Among them, the network interface 44 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface).
[0082] Among them, the processor 41 may include one or more processing cores. The processor 41 connects various parts within the entire server using various interfaces and lines, and executes various functions of the server and processes data by running or executing instructions, programs, code sets, or instruction sets stored in the memory 45, and by calling the data stored in the memory 45. Optionally, the processor 41 may be implemented in at least one hardware form of digital signal processing (DSP), field-programmable gate array (FPGA), or programmable logic array (PLA). The processor 41 may integrate a combination of one or more of a central processing unit (CPU), a graphics processing unit (GPU), and a modem, etc. Among them, the CPU mainly processes the operating system, user interface, application programs, etc.; the GPU is responsible for rendering and drawing the content to be displayed on the display screen; the modem is used to process wireless communications. It can be understood that the above-mentioned modem may not be integrated into the processor 41 and may be implemented separately by a single chip.
[0083] Among them, the memory 45 may include random access memory (RAM) and may also include read-only memory. Optionally, the memory 45 includes a non-transitory computer-readable storage medium. The memory 45 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 45 may include a program storage area and a data storage area. Among them, the program storage area may store instructions for implementing the operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the above-mentioned method embodiments, etc.; the data storage area may store the data involved in the above-mentioned method embodiments. Optionally, the memory 45 may also be at least one storage device located far from the aforementioned processor 41. As Figure 4 shown, the memory 45, as a computer storage medium, may include an operating system, a network communication module, a user interface module, and an application program for a data encryption processing method applied to an AR scenario.
[0084] In Figure 4In the electronic device shown, the user interface 43 is mainly used to provide an interface for the user to input and obtain the data input by the user; while the processor 41 can be used to call an application program stored in the memory 45 that implements a data encryption processing method for an AR scenario. When executed by one or more processors, the electronic device is caused to execute the method as described in one or more of the above embodiments.
[0085] It should be noted that, for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence, because according to this application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to this application.
[0086] This application also provides a computer-readable storage medium storing instructions. When executed by one or more processors, the electronic device is caused to execute the method as described in one or more of the above embodiments.
[0087] In the above embodiments, the descriptions of the various embodiments each have their own emphases. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0088] In several embodiments provided by this application, it should be understood that the disclosed device can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some service interfaces. The indirect couplings or communication connections of the devices or units can be in electrical or other forms.
[0089] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0090] In addition, in each embodiment of this application, the functional units can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.
[0091] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of various embodiments of this application. The aforementioned memory includes: various media such as USB flash drives, mobile hard disks, magnetic disks, or optical discs that can store program codes.
[0092] The foregoing are only exemplary embodiments of the present disclosure and should not be used to limit the scope of the present disclosure. That is, any equivalent changes and modifications made in accordance with the teachings of the present disclosure still fall within the scope covered by the present disclosure. After considering the specification and the disclosure of the practical truth, those skilled in the art will readily think of other implementation manners of the present disclosure. This application aims to cover any variations, uses, or adaptive changes of the present disclosure, and these variations, uses, or adaptive changes follow the general principles of the present disclosure and include the common general knowledge or conventional technical means in the technical field not recorded in the present disclosure. The specification and the embodiments are only regarded as exemplary, and the scope and spirit of the present disclosure are defined by the claims.
Claims
1. A data encryption processing method applied to AR scenarios, characterized in that: The method comprises: Acquire three-dimensional point cloud data of a target AR scene and gaze point data of a user in the target AR scene, wherein the user wears AR glasses for displaying the target AR scene; Determining a privacy domain of the target AR scene according to the three-dimensional point cloud data and the gaze point data; Acquire sensitive data of the target AR scene; Storing the sensitive data in the privacy domain to obtain data to be encrypted; Allocating a dynamic key to the data to be encrypted, and encrypting the data to be encrypted in combination with a preset encryption algorithm; The determining, according to the three-dimensional point cloud data and the gaze point data, a privacy domain of the target AR scene specifically includes: Determining a virtual element where the user's line of sight is focused from the three-dimensional point cloud data and the gaze point data; determining the virtual element as a high privacy domain; Determining an environmental object of the target AR scene from the three-dimensional point cloud data and the gaze point data; Determining the environmental object as a medium privacy domain; Determining a scene background of the target AR scene from the three-dimensional point cloud data and the gaze point data; Determining the scene background as a low privacy domain; The storing the sensitive data in the privacy domain to obtain the data to be encrypted specifically includes: Splitting the sensitive data into multiple binary data segments using a secret sharing algorithm; If it is determined that the target binary data segment belongs to the core slice of the sensitive data, a texture mapping technique is used to determine the target texture of the virtual element; According to the value of the target binary data segment, adjusting the value corresponding to the target texture to obtain first data to be embedded; The first data to be embedded is embedded into the high privacy domain to obtain the data to be encrypted.
2. The data encryption processing method applied to AR scenarios according to claim 1 is characterized in that: The acquiring of the three-dimensional point cloud data of the target AR scene and the gaze point data of the user in the target AR scene specifically includes: Receiving original scene image data of the target AR scene sent by the depth camera; Analyzing the original scene image data using an environmental perception model to generate the three-dimensional point cloud data; receiving eye movement data of the user sent by an eye tracking sensor; The gaze point data is determined by using a gaze point analysis algorithm according to the eye movement data.
3. The data encryption processing method applied to AR scenarios according to claim 1 is characterized in that: The method further comprises: If it is determined that the target binary data segment belongs to a redundant fragment of the sensitive data, encoding the target binary data segment into a decimal form to obtain encoded data; Using a reference transparency value as a default value, and embedding the encoded data into a small offset of the transparency to obtain second data to be embedded; The second data to be embedded is embedded into the low privacy domain to obtain the data to be encrypted.
4. The data encryption processing method applied to AR scenarios according to claim 1 is characterized in that: The step of allocating a dynamic key to the data to be encrypted and encrypting the data to be encrypted in combination with a preset encryption algorithm specifically includes: Monitoring risk factors for the data to be encrypted by an edge computing device, wherein the risk factors include data interception and network fluctuations; If it is determined that the risk factor indicates that there is no data interception and network fluctuation, obtaining the eye movement pattern of the user; Generate a random number using a pseudo-random number generation algorithm according to the eye movement pattern; The dynamic key is randomly generated using the random number.
5. The data encryption processing method applied to AR scenarios according to claim 4 is characterized in that: The method further comprises: If it is determined that the privacy domain is the high privacy domain, using an encryption algorithm based on a lattice cipher to allocate the dynamic key to the high privacy domain; If it is determined that the privacy domain is the medium privacy domain, using a medium strength AES encryption algorithm to allocate the dynamic key to the medium privacy domain; If it is determined that the privacy domain is the low privacy domain, a lightweight symmetric encryption algorithm is used to allocate the dynamic key to the low privacy domain.
6. A data encryption processing device applied to AR scenarios, characterized in that: The data encryption processing device executes the method according to any one of claims 1 to 5, and the data encryption processing device comprises an acquisition module (31) and a processing module (32), wherein: The acquisition module (31) is used to acquire three-dimensional point cloud data of a target AR scene and gaze point data of a user in the target AR scene, wherein the user wears AR glasses for displaying the target AR scene; The processing module (32) is used to determine the privacy domain of the target AR scene according to the three-dimensional point cloud data and the gaze point data; The acquisition module (31) is further used to acquire sensitive data of the target AR scene; The processing module (32) is further used to store the sensitive data in the privacy domain to obtain data to be encrypted; The processing module (32) is also used to allocate a dynamic key to the data to be encrypted, and encrypt the data to be encrypted in combination with a preset encryption algorithm.
7. An electronic device, characterized in that: The electronic device comprises a processor (41), a memory (45), a user interface (43) and a network interface (44), wherein the memory (45) is used to store instructions, the user interface (43) and the network interface (44) are both used to communicate with other devices, and the processor (41) is used to execute the instructions stored in the memory (45) so that the electronic device executes the method according to any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores instructions, and when the instructions are executed, the method according to any one of claims 1 to 5 is performed.
Citation Information
Patent Citations
AR data processing method and device based on block chain technology, and electronic equipment
CN117892323A
Intelligent glasses control method and system based on multi-mode privacy protection
CN119577814A