Electronic data security remote evidence obtaining method and system

By extracting video keyframes in remote forensics and building a comprehensive feature vector in combination with hashing algorithms and face-changing detection model, the problem of real-time modification of audio and video data in remote forensics is solved, and multi-dimensional authenticity verification and data security guarantee of forensics video content is realized.

CN119992670AActive Publication Date: 2025-05-13SICHUAN ZHONGHE YUESHENG TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510465953.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-05-13
Estimated Expiration
2045-04-15

AI Technical Summary

Technical Problem

During the remote evidence collection process, intelligent AI technology makes real-time modification of audio and video data possible, seriously affecting the authenticity of the evidence and making it difficult to ensure data security.

Method used

By obtaining the forensic video generated in real time by participating forensics who log in to the remote forensics platform, keyframe extraction and feature extraction are performed, combining the first hash algorithm and face-changing detection model, a comprehensive feature vector is constructed and the second hash value is calculated, and it is bound to the forensics video and stored.

Benefits of technology

The multi-dimensional authenticity verification of remote evidence for video content is realized. It not only checks the tampering of the content itself, but also identifies forgery behavior, protects the evidence for the forensic content and its authenticity evaluation results, making the entire evidence for evidence process more comprehensive and credible.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119992670A_ABST
    Figure CN119992670A_ABST
Patent Text Reader

Abstract

The invention provides an electronic data security remote evidence obtaining method and system, and relates to the technical field of data security, and the method comprises the steps: obtaining an evidence obtaining video of a person participating in evidence obtaining; key frames and key frame features are extracted from the evidence obtaining video; calculating a first Hash value of the key frame feature by adopting a first Hash algorithm; performing face change detection on a face part in the evidence obtaining video by using a face change detection model to obtain face change detection result information of the key frame; constructing a comprehensive feature vector corresponding to the key frame according to the first hash value of the key frame, the face change detection result information and the timestamp; calculating a second hash value of the comprehensive feature vector by adopting a second hash algorithm; and binding the second hash value with the evidence obtaining video according to the extraction time of the key frame, and storing the bound evidence obtaining video and the second hash value. According to the method, the evidence obtaining content is protected, the authenticity evaluation result of the evidence obtaining content is also protected, and the whole evidence obtaining process is more comprehensive and credible.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security technology, and in particular to a method and system for secure remote evidence collection of electronic data. Background Art

[0002] Remote evidence collection refers to a digital evidence collection technology based on electronic information technology, which can support a series of legally recognized evidence collection processes such as interview evidence collection, audio and video fixation, and material confirmation and signature in a remote and online manner. By integrating secure storage, high-speed network transmission, secure encryption technology and advanced data analysis capabilities, the remote evidence collection system can greatly improve the efficiency of evidence acquisition and processing, and can achieve resource sharing and collaborative work among multiple judicial organs, law enforcement agencies and related units in different geographical locations.

[0003] However, with the continuous development of intelligent AI technology, it has become possible to modify the audio and video data generated during remote evidence collection in real time, which has a huge impact on the authenticity of the evidence involved in remote evidence collection.

[0004] Therefore, how to provide a method to ensure data security during remote forensics is an urgent problem to be solved. Summary of the invention

[0005] In order to improve the above problems, the present invention provides a method and system for secure remote evidence collection of electronic data.

[0006] A first aspect of an embodiment of the present invention provides a method for secure remote evidence collection of electronic data, the method comprising: Obtain the evidence collection video generated in real time after the evidence collection personnel log in to the remote evidence collection platform; Extracting key frames and extracting features of the key frames from the forensic video at a preset extraction frequency to obtain key frames and key frame features; Calculate a first hash value of the key frame feature using a first hash algorithm; Use the face-changing detection model to perform face-changing detection on the face part of the forensic video and obtain face-changing detection result information of the key frame; Constructing a comprehensive feature vector of the corresponding key frame according to the first hash value of the key frame, the face-changing detection result information and the timestamp; Calculating a second hash value of the comprehensive feature vector using a second hash algorithm; The second Hash value is bound to the forensic video according to the extraction time of the key frame, and the bound forensic video and the second Hash value are stored.

[0007] Optionally, the method further comprises: Obtain biometric characteristics of persons involved in evidence collection; Perform identity detection based on the biometric features and key frame features to obtain identity detection result information; The identity detection result information is added to the elements used to construct the comprehensive feature vector.

[0008] Optionally, the method further comprises: Use the background detection model to perform background detection on the background part of the forensic video to obtain background detection result information of the key frame; The background detection result information is added to the elements used to construct the comprehensive feature vector.

[0009] Optionally, the method further comprises: The test result information is a test score; When the detection score is lower than a preset score threshold, the acquisition of the forensic video is stopped.

[0010] Optionally, the method for constructing the comprehensive feature vector specifically includes: The comprehensive feature vector is constructed using the numerical value of the detection score as the element of the comprehensive feature vector.

[0011] Optionally, the method further comprises: A time stamp of a key frame is generated based on the extraction frequency.

[0012] Optionally, the method further comprises: When the acquisition of evidence video begins, the video timing starts synchronously; When the timestamp of each key frame is generated, the sampling time point of the video timing is synchronously recorded; Calculate a first time interval between a currently generated timestamp and a previously generated timestamp, and calculate a second time interval between a current sampling time point and a previously generated sampling time point; Determine whether the first time interval is consistent with the second time interval, and if not, stop acquiring the forensic video.

[0013] Optionally, the method further comprises: Obtain the device ID information used by the forensic personnel to log in to the remote forensic platform; The device ID information is added to the elements used to construct the comprehensive feature vector.

[0014] Optionally, the method further comprises: When the bound forensic video and the second Hash value are stored, other elements in the comprehensive feature vector except the first Hash value are stored as meta-information.

[0015] A second aspect of an embodiment of the present invention provides an electronic data security remote evidence collection system, including: A video acquisition unit, used to acquire the evidence collection video generated in real time after the evidence collection personnel log in to the remote evidence collection platform; A feature extraction unit, used to extract key frames and feature extraction of the key frames from the forensic video at a preset extraction frequency to obtain key frames and key frame features; A hash calculation unit, configured to calculate a first hash value of a key frame feature by using a first hash algorithm; A face-changing detection unit, used to perform face-changing detection on the face part of the forensic video using a face-changing detection model, and obtain face-changing detection result information of a key frame; A vector construction unit, used to construct a comprehensive feature vector corresponding to the key frame according to the first hash value of the key frame, the face-changing detection result information and the timestamp; The hash calculation unit is further used to calculate a second hash value of the comprehensive feature vector using a second hash algorithm; The data storage unit is used to bind the second Hash value to the forensic video according to the extraction time of the key frame, and store the bound forensic video and the second Hash value.

[0016] In summary, the present invention provides a method and system for remote electronic data security evidence collection, which combines information from multiple different dimensions to verify the authenticity of video content from different angles, not only checking the tampering of the content itself, but also identifying forgery. Therefore, not only the evidence content is protected, but also the evaluation results of its authenticity are protected, making the entire evidence collection process more comprehensive and credible. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for use in the embodiments are briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present invention and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without creative work.

[0018] Figure 1 A method flow chart of a method for secure remote evidence collection of electronic data according to an embodiment of the present invention; Figure 2 The figure is a functional module block diagram of the electronic data security remote evidence collection system according to an embodiment of the present invention.

[0019] Reference numerals: Video acquisition unit 110; feature extraction unit 120; hash calculation unit 130; face-changing detection unit 140; vector construction unit 150; data storage unit 160. DETAILED DESCRIPTION

[0020] With the continuous development of intelligent AI technology, it has become possible to modify the audio and video data generated during remote evidence collection in real time, which has a huge impact on the authenticity of the evidence involved in remote evidence collection.

[0021] Therefore, how to provide a method to ensure data security during remote forensics is an urgent problem to be solved.

[0022] In view of this, the designers of the present invention have designed a method and system for secure remote evidence collection of electronic data.

[0023] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Generally, the components of the embodiments of the present invention described and shown in the drawings here can be arranged and designed in various different configurations.

[0024] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the invention claimed for protection, but merely represents selected embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0025] It should be noted that similar reference numerals and letters denote similar items in the following drawings, and therefore, once an item is defined in one drawing, further definition and explanation thereof is not required in subsequent drawings.

[0026] In the description of the present invention, it should be noted that the terms "top", "bottom", "inside", "outside", etc. indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, or the orientation or positional relationship in which the invented product is usually placed when in use, which is only for the convenience of describing the present invention and simplifying the description, and does not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as limiting the present invention. In addition, the terms "first", "second", etc. are only used to distinguish the description, and cannot be understood as indicating or implying relative importance.

[0027] It should be noted that, in the absence of conflict, the embodiments of the present invention and the features in the embodiments may be combined with each other.

[0028] The following is a detailed description of a method for secure remote evidence collection of electronic data provided by this embodiment.

[0029] See also Figure 1 This embodiment provides a method for secure remote evidence collection of electronic data, the method comprising: Step S101, obtaining the evidence collection video generated in real time after the evidence collection personnel log in to the remote evidence collection platform.

[0030] Personnel involved in evidence collection refer to those who provide evidence materials, but they may also be informants, witnesses, etc. during the case handling process, or they may be local case handlers who assist informants and witnesses.

[0031] In order to ensure the security of electronic data transmission during remote evidence collection, the personnel involved in evidence collection usually operate through a designated remote evidence collection platform. The personnel involved in evidence collection log in to the remote evidence collection platform through real-name authentication to generate and upload evidence collection videos online.

[0032] The remote evidence collection platform can support a series of legally recognized evidence collection processes such as remote and online interview collection, audio and video fixation, and material confirmation and signature.

[0033] It should be noted that the generation of evidence videos is carried out in real time, that is, the personnel involved in evidence collection use the recording function of the equipment used to record and upload the evidence videos in real time.

[0034] Step S102, extracting key frames from the forensic video and extracting features of the key frames according to a preset extraction frequency to obtain key frames and key frame features.

[0035] When the generation of the forensic video begins, key frames are extracted from the forensic video at a preset extraction frequency (for example, one frame is extracted every N frames). At the same time, feature extraction is performed on the specific content of the extracted key frames to obtain key frame features, which facilitates the subsequent calculation of the first hash value.

[0036] It should be noted that the extraction frequency of key frames can also be dynamically adjusted according to the changes in the scene in the forensic video.

[0037] Step S103: Calculate a first hash value of the key frame feature using a first hash algorithm.

[0038] The hash algorithm can map data of any length to a string of fixed length (i.e., a hash value). There are many common hash algorithms at present, such as MD5 and SHA series. As a preferred implementation, in the embodiment provided by the present invention, a perceptual hash algorithm can be selected. Unlike the traditional hash algorithm, perceptual hash is designed to produce similar hash values ​​even when the content changes slightly, and is more suitable for image content comparison. Perceptual hash algorithms include aHash (AverageHash), pHash (Perceptual Hash), and dHash (Difference Hash).

[0039] Taking the pHash algorithm as an example, the calculation process of the first hash value is: Reduce the image size (e.g. 32x32 or 64x64); Convert to grayscale; Perform discrete cosine transform (DCT) to retain the low-frequency part; Generate a fixed-length binary hash value (eg, 64 bits) based on the distribution of pixel values.

[0040] Step S104, using the face-changing detection model to perform face-changing detection on the face part in the forensic video, and obtaining face-changing detection result information of the key frame.

[0041] Based on the first hash value, in order to enhance anti-counterfeiting capabilities and effectively identify possible face-swapping operations, a face-swapping detection model is used to detect face-swapping operations on the face part of the forensic video. Specifically, for the face-swapping detection model, a deep learning model (such as FaceForensics++, DeepFake Detection, etc.) can be selected to perform face-swapping detection on key frames.

[0042] The face-swapping detection result information may be expressed in different ways, for example, only a "yes" or "no" detection result may be output, or a face-swapping confidence score may be output (for example, a floating point number between 0 and 1, the closer to 1, the more likely it is a fake face).

[0043] Step S105, constructing a comprehensive feature vector corresponding to the key frame according to the first hash value of the key frame, the face-changing detection result information and the timestamp.

[0044] The construction of the comprehensive feature vector not only takes into account the first hash value reflecting the key frame characteristics, but also includes the detection results of potential forgery behaviors and the timestamp when the operation is performed. By integrating multiple verification information into the hash value generation process, the authenticity verification capability of the video content can be significantly improved.

[0045] A single pHash or traditional hash value may be easily bypassed, but when combined with AI face-changing detection, attackers need to forge information in multiple dimensions at the same time, which greatly increases the difficulty.

[0046] Based on the above ideas, when constructing a comprehensive feature vector, in addition to introducing the face-changing detection result information and the timestamp, other information may also be introduced based on the first hash value. The specific information introduced is as follows.

[0047] As a preferred embodiment, the method further comprises: Obtain biometric characteristics of persons involved in evidence collection; Perform identity detection based on the biometric features and key frame features to obtain identity detection result information; The identity detection result information is added to the elements used to construct the comprehensive feature vector.

[0048] In this embodiment, the biometric feature mainly refers to facial information. In the process of generating forensic video, in addition to detecting whether AI face-changing is performed, the identity recognition of the characters in the video also needs to be continuously detected. Therefore, the identity detection result is also added to the elements of constructing the comprehensive feature vector.

[0049] As a preferred embodiment, the method further comprises: Use the background detection model to perform background detection on the background part of the forensic video to obtain background detection result information of the key frame; The background detection result information is added to the elements used to construct the comprehensive feature vector.

[0050] Background detection is also a commonly used dimension for judging the authenticity of a video. Computer vision techniques (such as edge detection, light and shadow consistency analysis, depth estimation, etc.) can be used to analyze the background in the background detection model. Therefore, background detection is also added to the elements for constructing the comprehensive feature vector.

[0051] It should be noted that the output results of the above-mentioned identity detection and background detection are expressed in a similar way to face detection. They can either output only a "yes" or "no" detection result, or output a detection confidence score.

[0052] During construction, if the output result is a test score (i.e., confidence score), the value of the test score is used as an element of the comprehensive feature vector to construct the comprehensive feature vector. If the output is a "yes" or "no" test result, a specific value can be used to correspond to "yes" or "no", such as 1 for yes and 0 for no.

[0053] Considering the impact of the detection results, when any of the above detection results is negative, or the detection result information is a detection score (i.e., confidence score) and the detection score is lower than the preset score threshold, it is determined that the video is fake, and the acquisition of the evidence video is stopped at this time. The personnel involved in the evidence collection can be informed to regenerate the evidence video.

[0054] As a preferred embodiment, the method further comprises: Obtain the device ID information used by the forensic personnel to log in to the remote forensic platform; The device ID information is added to the elements used to construct the comprehensive feature vector.

[0055] When constructing a comprehensive feature vector, including the device ID can provide an additional dimension for verifying the authenticity of video or audio content. The device ID can help confirm the legitimacy of the data source and ensure that the content is generated by a specific device and not forged. Therefore, the device ID information is also added to the elements of constructing the comprehensive feature vector.

[0056] In this embodiment, when constructing a comprehensive feature vector, the elements that may be included are the first hash value of the key frame, face change detection result information, timestamp, identity detection result information, background detection result information, and device ID information. Among them, one or more of the identity detection result information, background detection result information, and device ID information are selected to be added to the construction based on actual on-site conditions and needs.

[0057] It should be noted that each element involved in constructing the comprehensive feature vector includes verification information on the authenticity of the video content, and the same is true for the timestamp. Specifically, the timestamp of the key frame is generated based on the extraction frequency. The timestamp corresponds to the time point when the key frame is extracted. When the extraction frequency is determined, the timestamp of each time can be determined by calculating from the time point when the video generation starts. However, if tampering is performed during the process of generating the video, such as inserting or deleting some clips, the timestamp will be inconsistent with the extraction frequency. This can be judged in the following way.

[0058] The method further comprises: When the acquisition of evidence video begins, the video timing starts synchronously; When the timestamp of each key frame is generated, the sampling time point of the video timing is synchronously recorded; Calculate a first time interval between a currently generated timestamp and a previously generated timestamp, and calculate a second time interval between a current sampling time point and a previously generated sampling time point; Determine whether the first time interval is consistent with the second time interval, and if not, stop acquiring the forensic video.

[0059] By comparing the first time interval between the timestamps with the second time interval for actual key frame sampling, it is determined whether insertion or deletion has occurred. If this occurs, it is determined that there is a problem with the authenticity of the entire forensic video, and therefore the acquisition of the forensic video is stopped.

[0060] Step S106: Calculate a second hash value of the comprehensive feature vector using a second hash algorithm.

[0061] After the comprehensive feature vector is completed, a unique hash value, namely, a second hash value, is generated for the comprehensive feature vector through a second hash algorithm. It should be noted that the second hash algorithm can be the same as the first hash algorithm, or a different algorithm can be used.

[0062] As a preferred method, the second hash algorithm uses an algorithm different from the first hash algorithm, such as SHA-256. In specific calculation, the comprehensive feature vector is first serialized into a string or binary format, and then a hash function is applied to the serialized data to generate a second hash value of a fixed length.

[0063] The second hash value not only reflects the content characteristics of the video frame, but also includes the detection results of potential forgery behaviors (such as AI face-changing, background tampering, etc.). A single pHash or traditional hash value may be easily bypassed, but after combining the detection result information such as AI face-changing detection and background detection, the attacker needs to forge information in multiple dimensions at the same time, which greatly increases the difficulty.

[0064] Through the above process, the respective verification dimension of each element in the comprehensive feature vector is achieved. This approach allows verification at different levels; Even in some cases where the content-specific hash does not fully reflect all tampering attempts (for example, if counterfeiting techniques are very advanced), the composite hash value can still provide an additional layer of protection because any modification of the meta-information will affect the final hash value.

[0065] By incorporating the detection results into the generation process of the second hash value, a multi-dimensional and multi-level anti-counterfeiting mechanism can be constructed. This method not only improves the ability to verify the authenticity of the video, but also effectively responds to complex counterfeiting behaviors.

[0066] Step S107, binding the second Hash value to the forensic video according to the extraction time of the key frame, and storing the bound forensic video and the second Hash value.

[0067] Considering that the extraction time of the key frame may change dynamically, binding the second hash value and the forensic video based on the extraction time of the key frame is convenient for subsequent verification. When verifying the forensic video, the calculation basis of the second hash value can be effectively determined by the extraction time, which is convenient for recalculation and verification.

[0068] As a preferred implementation, when the bound forensic video and the second hash value are stored, the other elements in the comprehensive feature vector except the first hash value are stored as meta-information. Considering that during verification, the calculation process of the verification end may be biased, resulting in inaccurate verification results, or in order to facilitate the verification end to perform rapid verification without recalculating the first hash value, but directly verifying through meta-information, the other elements in the comprehensive feature vector except the first hash value can be stored as meta-information to facilitate extraction during verification.

[0069] It should be noted that when using this method, the second hash value and metadata need to be packaged into blocks and uploaded to the blockchain for storage. Due to the characteristics of the blockchain, these records cannot be tampered with and can be used as a benchmark for subsequent verification.

[0070] Through the above process, the remote acquisition and storage of forensic videos are completed, and the security and flexibility of the system are enhanced through two different hash calculations. The first hash calculation ensures the uniqueness and integrity of the forensic content itself, and the second hash calculation ensures the consistency and non-tamperability of all meta-information including AI face-changing detection, background detection results and other detections. This design not only protects the content itself, but also protects the evaluation results of its authenticity, making the entire verification process more comprehensive and credible.

[0071] The entire verification process is described below: Get the saved forensic video, second hash value and other meta information; Repeat the above steps S102 and S103 according to the binding time of the second Hash value to recalculate a new first Hash value; According to the data type corresponding to the meta-information, the forensic video is tested accordingly to obtain the test result information; Obtain a new comprehensive feature vector according to the detection result information and the new first hash value; Use the same hash algorithm for the second hash calculation to obtain a new second hash value; The original second hash value and its meta information corresponding to the forensic video are queried from the blockchain. If they match, it means that the file has not been tampered with.

[0072] The forensic video acquisition method and verification method described above include the following advantages: 1. Enhanced authenticity verification Multi-dimensional anti-counterfeiting: By combining multiple technologies, the authenticity of video or audio content can be verified from different angles, not only checking the tampering of the content itself, but also identifying counterfeiting behavior.

[0073] High accuracy: Using deep learning models for AI face-changing detection and background detection can provide highly accurate results and reduce false positives and false negatives.

[0074] 2. Immutability Blockchain technology guarantee: All verification results are uploaded to the blockchain to ensure the immutability and transparency of the data. Any attempt to modify the original data will be recorded for easy tracking.

[0075] Timestamp record: The timestamp of each operation is accurately recorded, ensuring the traceability of the entire process and enhancing the integrity of the chain of evidence.

[0076] 3. Enhance legal effectiveness High judicial recognition: This comprehensive verification method can provide strong evidentiary support and is more easily recognized in legal proceedings. For example, it can effectively prevent the use of forged evidence when handling complex criminal cases.

[0077] Comply with regulatory requirements: Many countries and regions have strict requirements for the authenticity and integrity of electronic evidence. This multi-level verification approach helps meet these regulatory standards.

[0078] 4. Real-time monitoring and feedback Instant alarm function: During video acquisition or playback, if an abnormality is detected (such as traces of AI face-changing or inconsistent background), the system can immediately issue an alarm to remind relevant personnel to take measures.

[0079] Continuous Updates: As new technologies develop, the system can continuously optimize detection algorithms through software updates to maintain its ability to combat new counterfeiting techniques.

[0080] 5. Flexibility and scalability Modular design: Each component (such as AI face-changing detection, background detection, pHash calculation, and blockchain storage) can be independently developed and maintained, making it easy to adjust or upgrade according to specific needs.

[0081] Cross-field application: In addition to judicial evidence collection, this method can also be applied to financial transactions, intellectual property protection, news media and other fields, and has broad application prospects.

[0082] 6. User-Friendliness Simplified process: For users, they only need to upload video or audio files, and the system will automatically complete all subsequent verification steps and generate detailed reports, greatly simplifying the operation process.

[0083] Visualization of results: The system can provide an intuitive result display interface to help users quickly understand the analysis conclusions without having to deeply understand the technical details behind them.

[0084] In summary, the electronic data security remote evidence collection method provided by the present invention combines information of multiple different dimensions to verify the authenticity of video content from different angles, not only checking the tampering of the content itself, but also identifying forgery. Therefore, not only the evidence collection content is protected, but also the evaluation results of its authenticity are protected, making the entire evidence collection process more comprehensive and credible.

[0085] like Figure 2 As shown, the electronic data security remote evidence collection system provided by the present invention comprises: The video acquisition unit 110 is used to acquire the evidence collection video generated in real time after the evidence collection personnel log in to the remote evidence collection platform; The feature extraction unit 120 is used to extract key frames and extract features of the key frames from the forensic video at a preset extraction frequency to obtain key frames and key frame features; A hash calculation unit 130, configured to calculate a first hash value of a key frame feature by using a first hash algorithm; The face-changing detection unit 140 is used to perform face-changing detection on the face part in the forensic video using the face-changing detection model to obtain face-changing detection result information of the key frame; A vector construction unit 150, configured to construct a comprehensive feature vector of a corresponding key frame according to the first hash value of the key frame, the face-changing detection result information, and the timestamp; The hash calculation unit 130 is further used to calculate a second hash value of the comprehensive feature vector using a second hash algorithm; The data storage unit 160 is used to bind the second Hash value to the forensic video according to the extraction time of the key frame, and store the bound forensic video and the second Hash value.

[0086] The electronic data secure remote evidence collection system provided in the embodiment of the present invention is used to implement the above-mentioned electronic data secure remote evidence collection method, so the specific implementation method is the same as the above-mentioned method and will not be repeated here.

[0087] In summary, the present invention provides a method and system for remote electronic data security evidence collection, which combines information from multiple different dimensions to verify the authenticity of video content from different angles, not only checking the tampering of the content itself, but also identifying forgery. Therefore, not only the evidence content is protected, but also the evaluation results of its authenticity are protected, making the entire evidence collection process more comprehensive and credible.

[0088] In several embodiments disclosed in the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely schematic. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architecture, functions and operations of the devices, methods and computer program products according to multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of the code, and a module, a program segment or a part of the code contains one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart can be implemented with a dedicated hardware-based system that performs a specified function or action, or can be implemented with a combination of dedicated hardware and computer instructions.

[0089] In addition, the functional modules in the various embodiments of the present application may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.

[0090] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium, including several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

Claims

1. A method for secure remote evidence collection of electronic data, characterized in that: The method comprises: Obtain the evidence collection video generated in real time after the evidence collection personnel log in to the remote evidence collection platform; Extracting key frames and extracting features of the key frames from the forensic video at a preset extraction frequency to obtain key frames and key frame features; Calculate a first hash value of the key frame feature using a first hash algorithm; Use the face-changing detection model to perform face-changing detection on the face part of the forensic video, and obtain face-changing detection result information of the key frame; Constructing a comprehensive feature vector of the corresponding key frame according to the first hash value of the key frame, the face-changing detection result information and the timestamp; Calculating a second hash value of the comprehensive feature vector using a second hash algorithm; The second Hash value is bound to the forensic video according to the extraction time of the key frame, and the bound forensic video and the second Hash value are stored.

2. The electronic data security remote evidence collection method according to claim 1, characterized in that: The method further comprises: Obtain biometric characteristics of persons involved in evidence collection; Perform identity detection based on the biometric features and key frame features to obtain identity detection result information; The identity detection result information is added to the elements used to construct the comprehensive feature vector.

3. The electronic data security remote evidence collection method according to claim 1, characterized in that: The method further comprises: Use the background detection model to perform background detection on the background part of the forensic video to obtain background detection result information of the key frame; The background detection result information is added to the elements used to construct the comprehensive feature vector.

4. The electronic data secure remote evidence collection method according to any one of claims 1 to 3, characterized in that: The method further comprises: The test result information is a test score; When the detection score is lower than a preset score threshold, the acquisition of the forensic video is stopped.

5. The electronic data secure remote evidence collection method according to claim 4, characterized in that: The method for constructing the comprehensive feature vector specifically includes: The comprehensive feature vector is constructed using the numerical value of the detection score as the element of the comprehensive feature vector.

6. The electronic data secure remote evidence collection method according to claim 1, characterized in that: The method further comprises: A time stamp of a key frame is generated based on the extraction frequency.

7. The electronic data secure remote evidence collection method according to claim 6, characterized in that: The method further comprises: When the acquisition of evidence video begins, the video timing starts synchronously; When the timestamp of each key frame is generated, the sampling time point of the video timing is synchronously recorded; Calculate a first time interval between a currently generated timestamp and a previously generated timestamp, and calculate a second time interval between a current sampling time point and a previously generated sampling time point; Determine whether the first time interval is consistent with the second time interval, and if not, stop acquiring the forensic video.

8. The electronic data secure remote evidence collection method according to claim 4, characterized in that: The method further comprises: Obtain the device ID information used by the forensic personnel to log in to the remote forensic platform; The device ID information is added to the elements used to construct the comprehensive feature vector.

9. The electronic data secure remote evidence collection method according to claim 8, characterized in that: The method further comprises: When the bound forensic video and the second Hash value are stored, other elements in the comprehensive feature vector except the first Hash value are stored as meta-information.

10. An electronic data security remote evidence collection system, characterized in that: include: A video acquisition unit, used to acquire the evidence collection video generated in real time after the evidence collection personnel log in to the remote evidence collection platform; A feature extraction unit, used to extract key frames and feature extraction of the key frames from the forensic video at a preset extraction frequency to obtain key frames and key frame features; A hash calculation unit, configured to calculate a first hash value of a key frame feature by using a first hash algorithm; A face-changing detection unit, used to perform face-changing detection on the face part of the forensic video using a face-changing detection model, and obtain face-changing detection result information of a key frame; A vector construction unit, used to construct a comprehensive feature vector corresponding to the key frame according to the first hash value of the key frame, the face-changing detection result information and the timestamp; The hash calculation unit is further used to calculate a second hash value of the comprehensive feature vector using a second hash algorithm; The data storage unit is used to bind the second Hash value to the forensic video according to the extraction time of the key frame, and store the bound forensic video and the second Hash value.

Citation Information

Patent Citations

  • A video fingerprint extraction method and device

    CN109657098A

  • Real-time face change detection method, system and equipment based on deep learning and medium

    CN119625801A

  • Short video copyright storage method based on blockchain and expression identification

    US20220167066A1