An Electronic Data Security Remote Forensics Method and System
By extracting video keyframes in remote forensics and using hash algorithms and face-changing detection models to build a comprehensive feature vector, the problem of real-time modification of audio and video data in remote forensics is solved, and multi-dimensional authenticity verification and data security guarantee of forensics video content is realized.
Patent Information
- Application Number
- CN202510465953.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-15
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2045-04-15
AI Technical Summary
During the remote evidence collection process, audio and video data may be modified in real time, affecting the authenticity of the evidence and making it difficult to guarantee data security.
By obtaining the forensic video generated by the forensics involved in the remote forensics platform, keyframe extraction and feature extraction are performed, combining the first hash algorithm and face-changing detection model, a comprehensive feature vector is constructed and the second hash value is calculated, and it is bound to the forensics video and stored.
The multi-dimensional authenticity verification of remote evidence for video content is realized. It not only checks the tampering of the content itself, but also identifies forgery behavior, protects the evidence for the forensic content and its authenticity evaluation results, making the entire evidence for evidence process more comprehensive and credible.
Smart Images

Figure CN119992670B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security, and in particular, to a method and system for remotely obtaining evidence of electronic data security. Background Art
[0002] Remote evidence collection refers to a digital evidence collection technology based on electronic information technology, which can support a series of legally recognized evidence collection processes such as remote and online conversation evidence collection, audio and video fixation, and material confirmation signature. By integrating secure storage, high-speed network transmission, security encryption technology, and advanced data analysis capabilities, the remote evidence collection system can greatly improve the efficiency of evidence acquisition and processing, and can achieve resource sharing and collaborative work among multiple judicial organs, law enforcement agencies, and related units in different geographical locations.
[0003] However, with the continuous development of intelligent AI technology, it has become possible to modify the audio and video data generated during the remote evidence collection process in real time, which has a huge impact on the authenticity of the evidence involved in remote evidence collection.
[0004] Therefore, in the process of remote evidence collection, how to provide a method that can ensure data security is an urgent problem to be solved at present. Summary of the Invention
[0005] In order to improve the above problems, the present invention provides a method and system for remotely obtaining evidence of electronic data security.
[0006] In the first aspect of the embodiment of the present invention, a method for remotely obtaining evidence of electronic data security is provided, and the method includes:
[0007] Obtain the evidence collection video generated in real time after the personnel participating in the evidence collection log in to the remote evidence collection platform;
[0008] Extract key frames and features of the key frames from the evidence collection video at a preset extraction frequency to obtain key frames and key frame features;
[0009] Calculate the first hash value of the key frame features using the first hash algorithm;
[0010] Use a face swapping detection model to detect face swapping in the face part of the evidence collection video to obtain face swapping detection result information of the key frames;
[0011] Construct a comprehensive feature vector corresponding to the key frame according to the first hash value, face swapping detection result information, and time stamp of the key frame;
[0012] Calculate the second hash value of the comprehensive feature vector using the second hash algorithm;
[0013] Bind the second hash value to the forensic video according to the extraction time of the key frame, and store the bound forensic video and the second hash value.
[0014] Optionally, the method further includes:
[0015] Obtain the biometric characteristics of the personnel participating in the forensics;
[0016] Perform identity detection based on the biometric characteristics and key frame characteristics to obtain identity detection result information;
[0017] Add the identity detection result information to the elements for constructing the comprehensive feature vector.
[0018] Optionally, the method further includes:
[0019] Use the background detection model to perform background detection on the background part of the forensic video to obtain the background detection result information of the key frame;
[0020] Add the background detection result information to the elements for constructing the comprehensive feature vector.
[0021] Optionally, the method further includes:
[0022] The detection result information is a detection score;
[0023] When the detection score is lower than the preset score threshold, stop obtaining the forensic video.
[0024] Optionally, the method for constructing the comprehensive feature vector specifically includes:
[0025] Construct the comprehensive feature vector with the value of the detection score as an element of the comprehensive feature vector.
[0026] Optionally, the method further includes:
[0027] Generate a time stamp for the key frame based on the extraction frequency.
[0028] Optionally, the method further includes:
[0029] When starting to obtain the forensic video, start video timing synchronously;
[0030] When generating a time stamp for each key frame, synchronously record the sampling time point of the video timing;
[0031] Calculate the first time interval between the currently generated time stamp and the previously generated time stamp, and calculate the second time interval between the current sampling time point and the previous sampling time point;
[0032] Determine whether the first time interval is consistent with the second time interval. If they are inconsistent, stop obtaining the forensic video.
[0033] Optionally, the method further includes:
[0034] Obtain the device ID information used by the forensic personnel to log in to the remote forensic platform;
[0035] Add the device ID information to the elements for constructing the comprehensive feature vector.
[0036] Optionally, the method further includes:
[0037] When storing the bound forensic video and the second hash value, store other elements in the comprehensive feature vector except the first hash value as meta-information.
[0038] In the second aspect of the embodiments of the present invention, an electronic data security remote forensic system is provided, including:
[0039] A video acquisition unit, configured to acquire a forensic video generated in real time after the forensic personnel log in to the remote forensic platform;
[0040] A feature extraction unit, configured to perform key frame extraction and feature extraction of the key frames on the forensic video at a preset extraction frequency to obtain key frames and key frame features;
[0041] A hash calculation unit, configured to calculate a first hash value of the key frame features using a first hash algorithm;
[0042] A face swapping detection unit, configured to use a face swapping detection model to perform face swapping detection on the face part in the forensic video to obtain face swapping detection result information of the key frames;
[0043] A vector construction unit, configured to construct a comprehensive feature vector corresponding to the key frame according to the first hash value, face swapping detection result information, and time stamp of the key frame;
[0044] The hash calculation unit is further configured to calculate a second hash value of the comprehensive feature vector using a second hash algorithm;
[0045] A data storage unit, configured to bind the second hash value with the forensic video according to the extraction time of the key frame, and store the bound forensic video and the second hash value.
[0046] In summary, the present invention provides an electronic data security remote forensics method and system. By combining various information from different dimensions, the authenticity of video content is verified from different perspectives, not only checking for tampering of the content itself, but also identifying forgery behaviors. Therefore, not only the forensics content is protected, but also the evaluation result of its authenticity is protected, making the entire forensics process more comprehensive and credible. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for use in the embodiments. It should be understood that the following drawings only show certain embodiments of the present invention and should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.
[0048] Figure 1 It is a flowchart of the method for the electronic data security remote forensics method according to the embodiment of the present invention;
[0049] Figure 2 It is a functional module block diagram of the electronic data security remote forensics system according to the embodiment of the present invention.
[0050] Reference Numerals:
[0051] Video acquisition unit 110; Feature extraction unit 120; Hash calculation unit 130; Face swap detection unit 140; Vector construction unit 150; Data storage unit 160. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0052] With the continuous development of intelligent AI technology, it has become possible to modify audio and video data generated during the remote forensics process in real time, which has a huge impact on the authenticity of evidence involved in remote forensics.
[0053] Therefore, in the process of remote forensics, how to provide a method that can ensure data security is an urgent problem to be solved at present.
[0054] In view of this, the designer of the present invention designed an electronic data security remote forensics method and system.
[0055] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Usually, the components of the embodiments of the present invention described and illustrated in the drawings here can be arranged and designed in various different configurations.
[0056] Accordingly, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.
[0057] It should be noted that like reference numerals and letters denote like items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0058] In the description of the present invention, it should be noted that the orientation or positional relationship indicated by the terms "top", "bottom", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings, or the orientation or positional relationship in which the inventive product is customarily placed during use. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the present invention. In addition, the terms "first", "second", etc. are only used for distinguishing descriptions and should not be construed as indicating or implying relative importance.
[0059] It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments may be combined with each other.
[0060] A method for remotely obtaining electronic data security evidence will be specifically described below with reference to the present embodiment.
[0061] Please refer to Figure 1 , a method for remotely obtaining electronic data security evidence provided by the present embodiment, the method includes:
[0062] Step S101, obtaining the evidence-taking video generated in real time after the evidence-taking personnel log in to the remote evidence-taking platform.
[0063] The evidence-taking personnel refer to those who provide evidence-taking materials, which may be informants, witnesses, etc. during the case handling process, or case handling personnel who assist informants and witnesses locally.
[0064] To ensure the transmission security of electronic data during remote evidence-taking, the evidence-taking personnel usually operate through a designated remote evidence-taking platform. The evidence-taking personnel log in to the remote evidence-taking platform through real-name authentication to generate and upload the evidence-taking video online.
[0065] The remote evidence-taking platform can support a series of legally recognized evidence-taking processes such as remote and online conversation evidence-taking, audio and video fixation, and material confirmation signature.
[0066] It should be noted that the generation of the evidence-taking video is carried out in real time, that is, the personnel participating in the evidence-taking use the video recording function of the device they use to record the evidence-taking video in real time and upload it.
[0067] Step S102, extract key frames from the evidence-taking video at a preset extraction frequency and extract features of the key frames to obtain key frames and key frame features.
[0068] After the generation of the evidence-taking video starts, key frames are extracted from the evidence-taking video at a preset extraction frequency (for example, one frame is extracted every N frames), and at the same time, features of the extracted key frames are extracted to obtain key frame features, which is convenient for calculating the first hash value in the subsequent process.
[0069] It should be noted that the extraction frequency of key frames can also be dynamically adjusted according to the changes in the scenes in the evidence-taking video.
[0070] Step S103, calculate the first hash value of the key frame features using the first hash algorithm.
[0071] The hash algorithm can map data of any length to a fixed-length string (i.e., the hash value). There are many common hash algorithms currently, such as MD5 and SHA series. As a preferred implementation, in the embodiments provided by the present invention, the perceptual hash algorithm can be selected. Different from traditional hash algorithms, the perceptual hash aims to generate similar hash values even when the content changes slightly, and is more suitable for comparing image content. The perceptual hash algorithm includes aHash (AverageHash), pHash (Perceptual Hash), and dHash (Difference Hash).
[0072] Taking the pHash algorithm as an example, the calculation process of the first hash value is as follows:
[0073] Reduce the image size (for example, 32x32 or 64x64);
[0074] Convert to grayscale;
[0075] Perform discrete cosine transform (DCT) and retain the low-frequency part;
[0076] Generate a fixed-length binary hash value (for example, 64 bits) according to the distribution of pixel values.
[0077] Step S104, use the face-swapping detection model to perform face-swapping detection on the face part in the evidence-taking video to obtain the face-swapping detection result information of the key frames.
[0078] Based on the first hash value, in order to enhance the anti-counterfeiting ability and effectively identify possible face-swapping operations, a face-swapping detection model is used to detect face-swapping in the face part of the forensic video. Specifically, for the face-swapping detection model, a deep learning model (such as FaceForensics++, DeepFake Detection, etc.) can be selected to detect face-swapping in key frames.
[0079] The face-swapping detection result information can be expressed in different ways. For example, only the detection results of "yes" or "no" can be output, or a face-swapping confidence score (such as a floating-point number from 0 to 1, the closer to 1, the more likely it is a fake face) can be output.
[0080] Step S105: Construct a comprehensive feature vector corresponding to the key frame according to the first hash value, face-swapping detection result information, and time stamp of the key frame.
[0081] The construction of the comprehensive feature vector not only takes into account the first hash value reflecting the key frame features, but also includes the detection results of potential forgery behaviors and the time stamp when the operation is performed. By integrating multiple verification information into the hash value generation process, the authenticity verification ability of the video content can be significantly improved.
[0082] A single pHash or traditional hash value may be easily bypassed, but after combining AI face-swapping detection, attackers need to forge information in multiple dimensions simultaneously, and the difficulty increases significantly.
[0083] Based on the above ideas, when constructing the comprehensive feature vector, in addition to introducing face-swapping detection result information and time stamp on the basis of the first hash value, other information can also be introduced. Specifically, the introduced information is as follows.
[0084] As a preferred embodiment, the method further includes:
[0085] Obtain the biometric features of the personnel participating in the forensics;
[0086] Perform identity detection according to the biometric features and key frame features to obtain identity detection result information;
[0087] Add the identity detection result information to the elements for constructing the comprehensive feature vector.
[0088] In this embodiment, the biometric features mainly refer to face information. During the generation process of the forensic video, in addition to detecting whether AI face-swapping is performed, the identity recognition of the people in the video also needs to be continuously detected. Therefore, the identity detection results are also added to the elements for constructing the comprehensive feature vector.
[0089] As a preferred embodiment, the method further includes:
[0090] Use the background detection model to perform background detection on the background part of the forensics video, and obtain the background detection result information of the key frames;
[0091] Add the background detection result information to the elements for constructing the comprehensive feature vector.
[0092] Background detection is also a commonly used dimension for judging the authenticity of videos. Computer vision techniques (such as edge detection, light and shadow consistency analysis, depth estimation, etc.) can be used in the background detection model to analyze the background. Therefore, background detection is also added to the elements for constructing the comprehensive feature vector.
[0093] It should be noted that for the above-mentioned identity detection and background detection, the expression methods of their output results are similar to those of face detection. It can either only output the detection results of "yes" or "no", or output a detection confidence score.
[0094] When constructing, if the output result is a detection score (i.e., the confidence score), then use the value of the detection score as an element of the comprehensive feature vector to construct the comprehensive feature vector. If the output is the detection result of "yes" or "no", specific values can be used to correspond to "yes" or "no" respectively, such as 1 representing yes and 0 representing no.
[0095] Considering the influence of the detection results, when any of the above detection results is no, or the detection result information is a detection score (i.e., the confidence score) and the detection score is lower than the preset score threshold, it is determined that video forgery has occurred. At this time, the acquisition of the forensics video is stopped. The forensics personnel can be informed to generate the forensics video again.
[0096] As a preferred implementation manner, the method further includes:
[0097] Obtain the device ID information used by the forensics personnel to log in to the remote forensics platform;
[0098] Add the device ID information to the elements for constructing the comprehensive feature vector.
[0099] When constructing the comprehensive feature vector, including the device ID can provide an additional dimension for verifying the authenticity of video or audio content. The device ID can help confirm the legality of the data source and ensure that the content is generated by a specific device rather than forged. Therefore, the device ID information is also added to the elements for constructing the comprehensive feature vector.
[0100] In this embodiment, when constructing the comprehensive feature vector, the elements that can be included are the first hash value of the key frame, face swap detection result information, time stamp, identity detection result information, background detection result information, and device ID information. Among them, the identity detection result information, background detection result information, and device ID information are selected according to the actual on-site situation and requirements, and one or more of them are added to the construction.
[0101] It should be noted that each element participating in the construction of the comprehensive feature vector includes verification information on the authenticity of the video content, and the same is true for the time stamp. Specifically, the time stamp of the key frame is generated based on the extraction frequency. The time stamp corresponds to the time point when the key frame is extracted. When the extraction frequency is determined, starting from the time point when the video is generated, each time stamp can be determined. However, if the video is tampered with during the generation process, such as inserting or deleting some segments, it will cause the time stamp to be inconsistent with the extraction frequency. The following method can be used for judgment.
[0102] The method further includes:
[0103] When starting to obtain the forensics video, start video timing synchronously;
[0104] When generating the time stamp of each key frame, synchronously record the sampling time point of the video timing;
[0105] Calculate the first time interval between the currently generated time stamp and the previously generated time stamp, and calculate the second time interval between the current sampling time point and the previous sampling time point;
[0106] Judge whether the first time interval and the second time interval are consistent. If they are inconsistent, stop obtaining the forensics video.
[0107] By comparing the first time interval between the time stamps with the second time interval for actual key frame sampling, it is judged whether there is an insertion or deletion situation. When this situation occurs, it is judged that the authenticity of the entire forensics video is problematic, so the acquisition of the forensics video is stopped.
[0108] Step S106, calculate the second hash value of the comprehensive feature vector using the second hash algorithm.
[0109] After completing the comprehensive feature vector, generate a unique hash value for the comprehensive feature vector through the second hash algorithm, that is, the second hash value. It should be noted that the second hash algorithm can be the same as the first hash algorithm or can adopt different algorithms.
[0110] As a preferred method, the second hashing algorithm uses an algorithm different from the first hashing algorithm, such as SHA-256. During specific calculations, first serialize the comprehensive feature vector into a string or binary format, and then apply a hashing function to the serialized data to generate a second hash value of a fixed length.
[0111] The second hash value not only reflects the content features of the video frames but also contains the detection results of potential forgery behaviors (such as AI face swapping, background tampering, etc.). A single pHash or traditional hash value may be easily bypassed, but after combining the detection result information such as AI face swapping detection and background detection, the attacker needs to forge information in multiple dimensions simultaneously, making the difficulty increase significantly.
[0112] Through the above process, the respective verification dimensions of each element in the comprehensive feature vector are achieved. This method allows verification at different levels;
[0113] Even in some cases where the content feature hash fails to fully reflect all tampering behaviors (for example, the forgery technology is very advanced), the comprehensive hash value can still provide an additional layer of protection because any modification to the meta-information will affect the final hash value.
[0114] By incorporating the detection results into the generation process of the second hash value, a multi-dimensional and multi-level anti-counterfeiting mechanism can be constructed. This method not only improves the ability to verify the authenticity of videos but also effectively deals with complex forgery behaviors.
[0115] Step S107: Bind the second hash value to the forensic video according to the extraction time of the key frame, and store the bound forensic video and the second hash value.
[0116] Considering that the extraction time of the key frame may change dynamically, binding the second hash value and the forensic video based on the extraction time of the key frame is convenient for subsequent verification. When verifying the forensic video, the calculation basis of the second hash value can be effectively determined through the extraction time, which is convenient for recalculation and verification.
[0117] As a preferred implementation, when storing the bound forensic video and the second hash value, store the other elements in the comprehensive feature vector except the first hash value as meta-information. Considering that during verification, there may be deviations in the calculation process at the verification end, resulting in inaccurate verification results, or for the convenience of the verification end to perform quick verification without recalculating the first hash value but directly verifying through the meta-information, the other elements in the comprehensive feature vector except the first hash value can be stored as meta-information for convenient extraction during verification.
[0118] It should be noted that when adopting this method, the second hash value and the meta-information need to be packaged into a block and uploaded to the blockchain for storage. Due to the characteristics of the blockchain, these records are immutable and can be used as a benchmark for subsequent verification.
[0119] Through the above process, the remote acquisition and preservation of the forensics video are completed, and the security and flexibility of the system are enhanced through two different hash calculations. The first hash calculation ensures the uniqueness and integrity of the forensics content itself, and the second hash calculation ensures the consistency and immutability of all meta-information including AI face swap detection, background detection results, etc. This design not only protects the content itself but also protects the evaluation results of its authenticity, making the entire verification process more comprehensive and credible.
[0120] The following will explain the entire verification process:
[0121] Obtain the saved forensics video, the second hash value, and other meta-information;
[0122] According to the binding time of the second hash value, repeat the above steps S102 and S103 to recalculate the new first hash value;
[0123] According to the data type corresponding to the meta-information, perform corresponding detections on the forensics video to obtain detection result information;
[0124] Obtain a new comprehensive feature vector based on the detection result information and the new first hash value;
[0125] Use the same hash algorithm for the second hash calculation to obtain a new second hash value;
[0126] Query the original second hash value and its meta-information corresponding to the forensics video from the blockchain. If they match, it indicates that the file has not been tampered with.
[0127] The above forensics video acquisition method and verification method have the following advantages:
[0128] 1. Enhanced authenticity verification
[0129] Multi-dimensional anti-counterfeiting: By combining multiple technologies, the authenticity of video or audio content can be verified from different angles, not only checking for tampering of the content itself but also identifying forgery behaviors.
[0130] High accuracy: Using deep learning models for AI face swap detection and background detection can provide highly accurate results, reducing the false positive rate and false negative rate.
[0131] 2. Immutability
[0132] Blockchain technology guarantee: Upload all verification results to the blockchain to ensure the immutability and transparency of data. Any attempt to modify the original data will be recorded for easy tracking.
[0133] Timestamp recording: The timestamp of each operation is accurately recorded, ensuring the traceability of the entire process and enhancing the integrity of the evidence chain.
[0134] 3. Enhancement of legal effect
[0135] High judicial recognition: This comprehensive verification method can provide strong evidence support and is more likely to be recognized in legal procedures. For example, in dealing with complex criminal cases, it can effectively prevent the use of forged evidence.
[0136] Compliance with regulatory requirements: Many countries and regions have strict requirements for the authenticity and integrity of electronic evidence. Adopting this multi-level verification method helps to meet these regulatory standards.
[0137] 4. Real-time monitoring and feedback
[0138] Instant alarm function: During video acquisition or playback, if abnormalities are detected (such as traces of AI face swapping or inconsistent backgrounds), the system can immediately issue an alarm to remind relevant personnel to take measures.
[0139] Continuous update: With the development of new technologies, the system can continuously optimize the detection algorithm through software updates to maintain the ability to combat new forgery techniques.
[0140] 5. Flexibility and scalability
[0141] Modular design: Each component (such as AI face swapping detection, background detection, pHash calculation, blockchain storage) can be developed and maintained independently, facilitating adjustment or upgrade according to specific requirements.
[0142] Cross-domain application: In addition to judicial forensics, this method can also be applied to multiple fields such as financial transactions, intellectual property protection, and news media, with broad application prospects.
[0143] 6. User-friendliness
[0144] Simplified process: For users, they only need to upload video or audio files, and the system automatically completes all subsequent verification steps and generates a detailed report, greatly simplifying the operation process.
[0145] Visualized results: The system can provide an intuitive result display interface to help users quickly understand the analysis conclusions without having to deeply understand the underlying technical details.
[0146] In summary, the electronic data security remote forensics method provided by the present invention combines various information from different dimensions to verify the authenticity of video content from different perspectives. It not only checks for tampering of the content itself but also can identify forgery behaviors. Therefore, it not only protects the forensics content but also protects the evaluation results of its authenticity, making the entire forensics process more comprehensive and credible.
[0147] As Figure 2 shown, the electronic data security remote forensics system provided by the embodiments of the present invention includes:
[0148] A video acquisition unit 110 for acquiring a forensics video generated in real time after a forensics participant logs in to the remote forensics platform;
[0149] A feature extraction unit 120 for extracting key frames and features of the key frames from the forensics video at a preset extraction frequency to obtain key frames and key frame features;
[0150] A hash calculation unit 130 for calculating a first hash value of the key frame features using a first hash algorithm;
[0151] A face swapping detection unit 140 for using a face swapping detection model to perform face swapping detection on the face part in the forensics video to obtain face swapping detection result information of the key frames;
[0152] A vector construction unit 150 for constructing a comprehensive feature vector corresponding to the key frames according to the first hash value, face swapping detection result information, and time stamps of the key frames;
[0153] The hash calculation unit 130 is further configured to calculate a second hash value of the comprehensive feature vector using a second hash algorithm;
[0154] A data storage unit 160 for binding the second hash value to the forensics video according to the extraction time of the key frames and storing the bound forensics video and the second hash value.
[0155] The electronic data security remote forensics system provided by the embodiments of the present invention is used to implement the above-mentioned electronic data security remote forensics method. Therefore, the specific implementation manners are the same as those of the above method and will not be elaborated here.
[0156] In summary, the present invention provides an electronic data security remote forensics method and system. By combining various information from different dimensions, it verifies the authenticity of video content from different perspectives. It not only checks for tampering of the content itself but also can identify forgery behaviors. Therefore, it not only protects the forensics content but also protects the evaluation results of its authenticity, making the entire forensics process more comprehensive and credible.
[0157] In several embodiments disclosed in the present application, it should be understood that the disclosed apparatus and method can also be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of the apparatus, method, and computer program product according to multiple embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and a module, a program segment, or a part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.
[0158] In addition, in each embodiment of the present application, the various functional modules may be integrated together to form an independent part, or each module may exist alone, or two or more modules may be integrated to form an independent part.
[0159] If the above functions are implemented in the form of software functional modules and sold or used as an independent product, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
Claims
1. A method for secure remote evidence collection of electronic data, characterized in that: The method comprises: Obtain the evidence collection video generated in real time after the evidence collection personnel log in to the remote evidence collection platform; Extracting key frames and extracting features of the key frames from the forensic video at a preset extraction frequency to obtain key frames and key frame features; Calculate a first hash value of the key frame feature using a first hash algorithm; Use the face-changing detection model to perform face-changing detection on the face part of the forensic video, and obtain face-changing detection result information of the key frame; Constructing a comprehensive feature vector of the corresponding key frame according to the first hash value of the key frame, the face-changing detection result information and the timestamp; Calculating a second hash value of the comprehensive feature vector using a second hash algorithm; The second Hash value is bound to the forensic video according to the extraction time of the key frame, and the bound forensic video and the second Hash value are stored.
2. The electronic data security remote evidence collection method according to claim 1, characterized in that: The method further comprises: Obtain biometric characteristics of persons involved in evidence collection; Perform identity detection based on the biometric features and key frame features to obtain identity detection result information; The identity detection result information is added to the elements used to construct the comprehensive feature vector.
3. The electronic data security remote evidence collection method according to claim 1, characterized in that: The method further comprises: Use the background detection model to perform background detection on the background part of the forensic video to obtain background detection result information of the key frame; The background detection result information is added to the elements used to construct the comprehensive feature vector.
4. The electronic data secure remote evidence collection method according to any one of claims 1 to 3, characterized in that: The method further comprises: The test result information is a test score; When the detection score is lower than a preset score threshold, the acquisition of the forensic video is stopped.
5. The electronic data secure remote evidence collection method according to claim 4, characterized in that: The method for constructing the comprehensive feature vector specifically includes: The comprehensive feature vector is constructed using the numerical value of the detection score as the element of the comprehensive feature vector.
6. The electronic data secure remote evidence collection method according to claim 1, characterized in that: The method further comprises: A time stamp of a key frame is generated based on the extraction frequency.
7. The electronic data secure remote evidence collection method according to claim 6, characterized in that: The method further comprises: When the acquisition of evidence video begins, the video timing starts synchronously; When the timestamp of each key frame is generated, the sampling time point of the video timing is synchronously recorded; Calculate a first time interval between a currently generated timestamp and a previously generated timestamp, and calculate a second time interval between a current sampling time point and a previously generated sampling time point; Determine whether the first time interval is consistent with the second time interval, and if not, stop acquiring the forensic video.
8. The electronic data secure remote evidence collection method according to claim 4, characterized in that: The method further comprises: Obtain the device ID information used by the forensic personnel to log in to the remote forensic platform; The device ID information is added to the elements used to construct the comprehensive feature vector.
9. The electronic data secure remote evidence collection method according to claim 8, characterized in that: The method further comprises: When the bound forensic video and the second Hash value are stored, other elements in the comprehensive feature vector except the first Hash value are stored as meta-information.
10. An electronic data security remote evidence collection system, characterized in that: include: A video acquisition unit, used to acquire the evidence collection video generated in real time after the evidence collection personnel log in to the remote evidence collection platform; A feature extraction unit, used to extract key frames and feature extraction of the key frames from the forensic video at a preset extraction frequency to obtain key frames and key frame features; A hash calculation unit, configured to calculate a first hash value of a key frame feature by using a first hash algorithm; A face-changing detection unit, used to perform face-changing detection on the face part of the forensic video using a face-changing detection model, and obtain face-changing detection result information of a key frame; A vector construction unit, used to construct a comprehensive feature vector corresponding to the key frame according to the first hash value of the key frame, the face-changing detection result information and the timestamp; The hash calculation unit is further used to calculate a second hash value of the comprehensive feature vector using a second hash algorithm; The data storage unit is used to bind the second Hash value to the forensic video according to the extraction time of the key frame, and store the bound forensic video and the second Hash value.
Citation Information
Patent Citations
A video fingerprint extraction method and device
CN109657098A
Real-time face change detection method, system and equipment based on deep learning and medium
CN119625801A