Data processing method, device and equipment and computer readable storage medium
By encrypting or signing the multimedia data based on identity information in the data acquisition device, the problem of difficulty in protecting sensitive data in the prior art is solved, and high security and effective protection of data are achieved.
Patent Information
- Application Number
- CN202311532319.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-15
- Publication Date
- 2025-05-16
AI Technical Summary
The prior art is difficult to effectively protect sensitive data, such as video data collected through cameras, to prevent data leakage.
By acquiring the multimedia data collected by the data acquisition device and encrypting or signing the data based on the identity information, it is ensured that only authorized devices can access the processed data.
Improves data security, ensuring that even if multimedia data is sensitive, it can be effectively protected and prevents unauthorized access.
Smart Images

Figure CN120017292A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a data processing method, apparatus, device and computer-readable storage medium. Background Art
[0002] With the development of computer technology, more and more types of data appear in the network, including some sensitive data that needs to be protected. For example, based on the video data collected by the camera, the video data involves a lot of information about the collected object, including but not limited to the portrait, behavior habits, and environmental information of the private space of the collected object. Therefore, it is necessary to process these data to improve the security of the data. Summary of the invention
[0003] The present application provides a data processing method, apparatus, device and computer-readable storage medium for processing data to improve data security. The technical solution is as follows:
[0004] In a first aspect, a data processing method is provided, which is applied to a data acquisition device, and the method includes: acquiring multimedia data collected by the data acquisition device; encrypting or signing the multimedia data based on identity information to obtain a data processing result corresponding to the multimedia data, wherein the identity information is determined based on information used for authentication between a second device corresponding to a target object and the data acquisition device, the target object is an object using the data acquisition device, and the data processing result is used for an authorized device to access the multimedia data.
[0005] After acquiring multimedia data, the multimedia data will be processed based on the identity information. Since the identity information is the information used for authentication between the second device and the data acquisition device, the security is bidirectionally authenticated by the data acquisition device and the second device, and the reliability is high. The data processing results obtained based on the highly reliable identity information are highly secure. Even if the multimedia data is sensitive data, it can be well protected.
[0006] In a possible implementation, the identity information includes first identity information for identifying the data acquisition device and second identity information for identifying the second device. Before encrypting or signing the multimedia data based on the identity information and obtaining the data processing result corresponding to the multimedia data, it also includes: encrypting the first identity information to obtain a first security ciphertext, and sending the first security ciphertext to the second device; receiving the second security ciphertext returned by the second device, the second security ciphertext being encrypted based on the second identity information, while verifying the transmission security based on the first security ciphertext; decrypting the second security ciphertext, and verifying whether the transmission channel between the data acquisition device and the second device is secure based on the decryption result. The transmission channel between the data acquisition device and the second device is authenticated by the identity information, so that the highly secure transmission channel is used to interact with the second device, and the process of transmitting the data processing result is highly secure.
[0007] In a possible implementation, multimedia data is encrypted or signed based on identity information to obtain a data processing result corresponding to the multimedia data, including: obtaining a first key, the first key is negotiated with the second device based on the identity information; encrypting the multimedia data according to the first key to obtain ciphertext data, and using the ciphertext data as the data processing result. Since the identity information is the information used for authentication between the second device and the data acquisition device, the security is bidirectionally authenticated by the data acquisition device and the second device, and the reliability is high. The security is high when the first key obtained according to the identity information is used for encryption.
[0008] In a possible implementation, obtaining the first key includes: calculating a second public key and a second private key of the data acquisition device based on the identity information; and obtaining the first key through negotiation based on the second public key, the second private key, and the identity information. First, an asymmetric public-private key pair, i.e., the second public key and the second private key, is obtained through negotiation, and then the first key is obtained through negotiation based on the second public key and the second private key, so that more efficient symmetric encryption is performed through the first key, and the performance of encrypting multimedia data is good.
[0009] In a possible implementation, multimedia data is encrypted or signed based on identity information to obtain a data processing result corresponding to the multimedia data, including: obtaining a second key of a data acquisition device, the second key has not been authenticated by a second device corresponding to a target object; encrypting the multimedia data according to the second key to obtain ciphertext data corresponding to the multimedia data; signing the ciphertext data according to the identity information to obtain signature data corresponding to the ciphertext data, and obtaining a data processing result according to the signature data and the ciphertext data, wherein the signature data is used to verify whether the ciphertext data is abnormal. Even if identity information is not used in the process of encrypting multimedia data, the ciphertext data can be signed by the identity information to implement security verification of the ciphertext data according to the signature data, and the versatility is high. The process of processing multimedia data according to identity information is not limited, and the first key can be generated according to the identity information, and the signature can also be performed according to the identity information, and the flexibility is high.
[0010] In a possible implementation, the ciphertext data is signed according to the identity information to obtain the signature data corresponding to the ciphertext data, and the data processing result is obtained according to the signature data and the ciphertext data, including: obtaining the third public key of the second device, encrypting the second key according to the third public key, obtaining the ciphertext parameter corresponding to the second key, and the ciphertext parameter is used to obtain the second key required for decrypting the ciphertext data; signing the ciphertext data and the ciphertext parameter according to the identity information to obtain the signature data corresponding to the ciphertext data and the ciphertext parameter, and obtaining the data processing result according to the ciphertext data, the ciphertext parameter and the signature data. The data processing result obtained by the signature includes both the ciphertext data corresponding to the multimedia data and the ciphertext parameter corresponding to the second key. When there is a device requesting to obtain multimedia data later, there is no need to send the ciphertext data and the ciphertext parameter separately for multiple times. Data provision can be achieved by transmitting a data processing result, and the data processing efficiency is high.
[0011] In a possible implementation, after obtaining the data processing result corresponding to the multimedia data, the method further includes: sending the data processing result to the second device corresponding to the target object, and the data processing result is used by the second device to obtain the multimedia data. The data processing result can be sent to the second device so that the target object can access the multimedia data at any time through the second device, which facilitates the data access of the target object and improves the interactive experience.
[0012] In a possible implementation, the data acquisition device is connected to the second device corresponding to the target object through a third device; the data acquisition device authenticates the second device through the third device. The interaction between the data acquisition device and the second device can be direct interaction or indirect interaction through the third device, which is highly flexible.
[0013] In a second aspect, another data processing method is provided, which is applied to a first device, and the method includes: sending an access request for multimedia data; when access rights to the multimedia data are obtained based on the access request, obtaining ciphertext data corresponding to the multimedia data, the ciphertext data is obtained by encrypting or signing the multimedia data based on identity information, the identity information is determined based on information used for authentication between a second device corresponding to a target object and a data acquisition device for the multimedia data, the target object being an object using the data acquisition device; decrypting the ciphertext data to obtain the multimedia data.
[0014] When a third-party device independent of the data acquisition device and the second device needs to obtain multimedia data, the device needs to be verified and authorized. Only after the verification is passed can the device obtain the multimedia data. This allows data sharing to be achieved while protecting the personal information of the target object, further exploring the data value of the multimedia data and achieving efficient use of the data.
[0015] In a possible implementation, obtaining ciphertext data corresponding to multimedia data includes: receiving ciphertext data returned based on an access request. If the access request is verified, the ciphertext data can be directly obtained, and the operation of obtaining the ciphertext data is low in complexity and high in efficiency.
[0016] In a possible implementation, obtaining ciphertext data corresponding to multimedia data includes: receiving a first authorization mark returned based on an access request, the first authorization mark indicating permission to obtain multimedia data; and requesting to obtain ciphertext data according to the first authorization mark. Since the first authorization mark indicates that the second device allows the first device to obtain multimedia data, the ciphertext data can be obtained by requesting the first authorization mark. During the process of obtaining the ciphertext data, the device is verified by the first authorization mark, which has high security. Even if the ciphertext data is provided by a device different from the second device, it can be obtained by the first authorization mark. In addition, the method of interactively obtaining ciphertext data is not limited. The ciphertext data can be directly received or requested by the first authorization mark, which has high flexibility.
[0017] In a possible implementation, before decrypting the ciphertext data, it also includes: receiving re-encrypted data returned based on the access request, the re-encrypted data is obtained by encrypting the reference ciphertext according to the second authorization mark, the second authorization mark is generated according to the first public key, the first public key is the public key of the first device requesting the multimedia data, and the reference ciphertext is the ciphertext obtained by encrypting the key of the ciphertext data; decrypting the ciphertext data to obtain the multimedia data, including: obtaining the key of the ciphertext data according to the decryption result of the re-encrypted data, decrypting the ciphertext data according to the key, and obtaining the multimedia data. Since the second authorization mark is generated according to the first public key, the re-encrypted data can be decrypted by the first private key of the first device, without the need to re-acquire the key used to decrypt the re-encrypted data, the decryption efficiency is high, the key acquisition method is simple, and the decryption process operation complexity is low.
[0018] In a possible implementation, before decrypting the ciphertext data, it also includes: sending a first public key; receiving a first ciphertext obtained by encrypting a key according to the first public key, where the key is a key used to encrypt multimedia data; decrypting the ciphertext data to obtain multimedia data, including: decrypting the first ciphertext according to a first private key corresponding to the first public key to obtain the key; decrypting the ciphertext data according to the key to obtain multimedia data. Even if the ciphertext data and the key are not transmitted synchronously, the key can be requested again and encrypted by the first public key to prevent the key from being intercepted and tampered with during transmission, and the key transmission has a high degree of security.
[0019] In a possible implementation, the access request is used to obtain device information of the first device requesting multimedia data, the device information of the first device is used to determine whether to grant the first device permission to obtain multimedia data based on at least one device information, the at least one device information is information of at least one device that signed a data protocol, and the data protocol is used to obtain access rights to multimedia data. By searching in at least one device information, security verification of the first device can be achieved, and the verification process is simple and efficient.
[0020] In a possible implementation, sending an access request for multimedia data includes: sending the access request to a third device, the third device being connected to a second device corresponding to the target object, and the third device being used to send the access request to the second device. The interaction between the second device and the first device may be direct interaction or indirect interaction through the third device, and the interaction process is flexible and versatile, and has wide versatility.
[0021] In a possible implementation, the identity information is used by the data acquisition device and the second device to negotiate to obtain a first key, and the ciphertext data is obtained by encrypting the multimedia data according to the first key.
[0022] In one possible implementation, the identity information is used to sign the ciphertext data corresponding to the multimedia data. The signed signature data is used by the second device to verify whether the ciphertext data sent by the received data acquisition device is abnormal. The second device is used to provide the ciphertext data to the first device.
[0023] In a possible implementation, the identity information includes first identity information for identifying the data acquisition device and second identity information for identifying the second device.
[0024] In a third aspect, a data processing device is provided, which is applied to a data acquisition device, and the device includes: an acquisition module, used to acquire multimedia data collected by the data acquisition device; a processing module, used to encrypt or sign the multimedia data based on identity information to obtain a data processing result corresponding to the multimedia data, wherein the identity information is determined based on information used for authentication between a second device corresponding to a target object and the data acquisition device, the target object is an object using the data acquisition device, and the data processing result is used for an authorized device to access the multimedia data.
[0025] In one possible implementation, the identity information includes first identity information for identifying the data acquisition device and second identity information for identifying the second device. The processing module is further used to encrypt the first identity information to obtain a first security ciphertext, and send the first security ciphertext to the second device; when verifying the transmission security based on the first security ciphertext, receive the second security ciphertext returned by the second device, the second security ciphertext being encrypted based on the second identity information; decrypt the second security ciphertext, and verify whether the transmission channel between the data acquisition device and the second device is secure based on the decryption result.
[0026] In a possible implementation, the processing module is used to obtain a first key, where the first key is obtained through negotiation with the second device based on identity information; encrypt the multimedia data according to the first key to obtain ciphertext data, and use the ciphertext data as a data processing result.
[0027] In a possible implementation, the processing module is used to calculate the second public key and the second private key of the data acquisition device based on the identity information; and to negotiate the first key according to the second public key, the second private key and the identity information.
[0028] In one possible implementation, the processing module is used to obtain a second key of the data acquisition device, where the second key has not been authenticated by a second device corresponding to the target object; encrypt the multimedia data according to the second key to obtain ciphertext data corresponding to the multimedia data; sign the ciphertext data according to the identity information to obtain signature data corresponding to the ciphertext data, and obtain a data processing result based on the signature data and the ciphertext data, where the signature data is used to verify whether the ciphertext data is abnormal.
[0029] In one possible implementation, the processing module is used to obtain a third public key of the second device, encrypt the second key according to the third public key, and obtain a ciphertext parameter corresponding to the second key, the ciphertext parameter is used to obtain the second key required to decrypt the ciphertext data; sign the ciphertext data and the ciphertext parameter according to the identity information to obtain signature data corresponding to the ciphertext data and the ciphertext parameter, and obtain a data processing result based on the ciphertext data, the ciphertext parameter and the signature data.
[0030] In a possible implementation, the apparatus further includes: a sending module, configured to send a data processing result to a second device corresponding to the target object, wherein the data processing result is used by the second device to obtain multimedia data.
[0031] In a possible implementation, the data acquisition device is connected to a second device corresponding to the target object via a third device; and the data acquisition device performs authentication with the second device via the third device.
[0032] In a fourth aspect, another data processing device is provided, which is applied to a first device, and includes: a sending module, used to send an access request for multimedia data; an acquisition module, used to obtain ciphertext data corresponding to the multimedia data when the access right to the multimedia data is obtained based on the access request, the ciphertext data is obtained by encrypting or signing the multimedia data according to identity information, the identity information is determined based on the information used for authentication between a second device corresponding to the target object and a data acquisition device for the multimedia data, and the target object is an object using the data acquisition device; a decryption module, used to decrypt the ciphertext data to obtain the multimedia data.
[0033] In a possible implementation, the acquisition module is used to receive the ciphertext data returned based on the access request.
[0034] In a possible implementation, the acquisition module is configured to receive a first authorization flag returned based on an access request, the first authorization flag indicating permission to acquire multimedia data; and request to acquire ciphertext data according to the first authorization flag.
[0035] In one possible implementation, the acquisition module is also used to receive re-encrypted data returned based on the access request, the re-encrypted data is obtained by encrypting the reference ciphertext according to the second authorization flag, the second authorization flag is generated according to the first public key, the first public key is the public key of the first device requesting the multimedia data, and the reference ciphertext is the ciphertext encrypted by the key of the ciphertext data; the decryption module is used to obtain the key of the ciphertext data according to the decryption result of the re-encrypted data, and decrypt the ciphertext data according to the key to obtain the multimedia data.
[0036] In a possible implementation, the sending module is also used to send the first public key; the acquisition module is also used to receive the first ciphertext obtained by encrypting the key according to the first public key, and the key is the key used to encrypt multimedia data; the decryption module is used to decrypt the first ciphertext according to the first private key corresponding to the first public key to obtain the key; and the ciphertext data is decrypted according to the key to obtain the multimedia data.
[0037] In one possible implementation, an access request is used to obtain device information of a first device requesting multimedia data, and the device information of the first device is used to determine whether to grant the first device permission to obtain multimedia data based on at least one device information, and the at least one device information is information of at least one device that has signed a data protocol, and the data protocol is used to obtain access rights to multimedia data.
[0038] In a possible implementation, the sending module is used to send an access request to a third device, the third device is connected to a second device corresponding to the target object, and the third device is used to send the access request to the second device.
[0039] In a possible implementation, the identity information is used by the data acquisition device and the second device to negotiate to obtain a first key, and the ciphertext data is obtained by encrypting the multimedia data according to the first key.
[0040] In one possible implementation, the identity information is used to sign the ciphertext data corresponding to the multimedia data. The signed signature data is used by the second device to verify whether the ciphertext data sent by the received data acquisition device is abnormal. The second device is used to provide the ciphertext data to the first device.
[0041] In a possible implementation, the identity information includes first identity information for identifying the data acquisition device and second identity information for identifying the second device.
[0042] In a fifth aspect, a data processing device is provided, which includes a processor, and the processor is used to load and execute at least one instruction so that the data processing device executes the method in the first aspect or any possible implementation of the first aspect, or executes the method in the second aspect or any possible implementation of the second aspect.
[0043] In a possible implementation, the device includes a memory, which is coupled to a processor, and the memory stores at least one instruction.
[0044] In a sixth aspect, a computer-readable storage medium is provided, in which at least one instruction is stored, and the instruction is loaded and executed by a processor to implement the data processing method in the first aspect or any possible implementation of the first aspect, or to implement the data processing method in the second aspect or any possible implementation of the second aspect.
[0045] In the seventh aspect, a computer program (product) is provided, which includes a computer program / instructions, and the computer program / instructions are executed by a processor to enable a computer to implement the data processing method in the first aspect or any possible implementation of the first aspect, or to implement the data processing method in the second aspect or any possible implementation of the second aspect.
[0046] In an eighth aspect, a communication device is provided, the device comprising: a transceiver, a memory, and a processor. The transceiver, the memory, and the processor communicate with each other through an internal connection path, the memory is used to store instructions, and the processor is used to execute the instructions stored in the memory to control the transceiver to receive signals and control the transceiver to send signals, and when the processor executes the instructions stored in the memory, the processor executes the method in the first aspect or any possible implementation of the first aspect, or executes the method in the second aspect or any possible implementation of the second aspect.
[0047] Optionally, there are one or more processors and one or more memories.
[0048] Optionally, the memory may be integrated with the processor, or the memory may be provided separately from the processor.
[0049] In the specific implementation process, the memory can be a non-transitory memory, such as a read-only memory (ROM), which can be integrated with the processor on the same chip or can be set on different chips. This application does not limit the type of memory and the setting method of the memory and the processor.
[0050] In a ninth aspect, a chip is provided, comprising a processor for calling and executing program instructions or codes stored in a memory, so that a communication device equipped with the chip executes the methods in the above aspects.
[0051] In the tenth aspect, another chip is provided, including: an input interface, an output interface, a processor and a memory, wherein the input interface, the output interface, the processor and the memory are connected via an internal connection path, and the processor is used to execute the code in the memory. When the code is executed, the processor is used to execute the methods in the above aspects.
[0052] It should be understood that the beneficial effects achieved by the technical solutions of the third to tenth aspects of the present application and the corresponding possible implementation methods can be referred to the above-mentioned technical effects of the first aspect and its corresponding possible implementation methods or the second aspect and its corresponding possible implementation methods, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] Figure 1 A schematic diagram of an implementation environment provided for an embodiment of the present application;
[0054] Figure 2 A schematic diagram of another implementation environment provided for an embodiment of the present application;
[0055] Figure 3 A flowchart of a data processing method provided in an embodiment of the present application;
[0056] Figure 4 A schematic diagram of interaction between a first device and a data acquisition device provided in an embodiment of the present application;
[0057] Figure 5 A flowchart of another data processing method provided in an embodiment of the present application;
[0058] Figure 6 A schematic diagram of device interaction provided in an embodiment of the present application;
[0059] Figure 7 Another device interaction diagram provided in an embodiment of the present application;
[0060] Figure 8 A schematic diagram of the structure of a data processing device provided in an embodiment of the present application;
[0061] Fig. 9 A schematic diagram of the structure of another data processing device provided in an embodiment of the present application;
[0062] Fig.10 A schematic diagram of the structure of a network device provided in an embodiment of the present application;
[0063] Fig.11 A schematic diagram of the structure of another network device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0064] The terms used in the implementation method of this application are only used to explain the specific embodiments of this application, and are not intended to limit this application. In order to make the purpose, technical solution and advantages of this application clearer, the implementation method of this application will be further described in detail below with reference to the accompanying drawings.
[0065] With the development of computer technology, the data in the network has shown an explosive growth. As the data increases, it also brings challenges to data processing. For example, there is a kind of sensitive data in the network, which includes sensitive information that needs to be avoided from being leaked. The above-mentioned sensitive data is, for example, video data collected by a camera. The video data collected by the camera includes a large amount of personal information, which is also sensitive information. Taking the data acquisition device as a camera located in the private environment of the target object as an example, the video data recorded by the camera includes a large amount of personal information such as the target object’s portrait, behavioral habits, and environmental information of the private space. The ownership of personal information belongs to the target object, not the platform or the operator. It is necessary to protect personal information to avoid leakage and improve data security.
[0066] This application embodiment provides a data processing method for sensitive data. Please refer to Figure 1 , which shows a schematic diagram of the implementation environment of the data processing method provided in an embodiment of the present application, and the implementation environment includes a first device 01, a data acquisition device 02, and a second device 03. Among them, the first device 01, the data acquisition device 02, and the second device 03 establish a communication connection respectively through a wired or wireless network. Exemplarily, the target object that needs to use the data acquisition device authenticates the security of the data acquisition device 02 based on the second device 03. The authenticated data acquisition device 02 can collect multimedia data, and process the multimedia data based on the identity information used in the authentication process to obtain a data processing result corresponding to the multimedia data.
[0067] After processing the multimedia data, if there are other devices, for example, the first device 01 requests to obtain the multimedia data, the first device 01 sends an access request to the second device 03, and the second device 03 performs device security verification on the first device 01 according to the access request. If the verification is passed, that is, the first device 01 obtains the access right to the multimedia data, the first device 01 can obtain the ciphertext data based on the authorization of the second device 03, and decrypt the ciphertext data to obtain the multimedia data. The ciphertext data is obtained by the second device 03 according to the data processing result processed by the data acquisition device 02.
[0068] The interaction between the data acquisition device 02, the second device 03 and the first device 01 may be performed directly or indirectly through other devices. Figure 2 Schematic diagram of another implementation environment of the data processing method provided in the embodiment of the present application, the implementation environment also includes a third device 04. The third device 04 establishes communication connections with the first device 01, the data acquisition device 02 and the second device 03 respectively through a wired or wireless network. Figure 2For example, in the case where the second device 03 and the data acquisition device 02 need to interact to implement end-to-end encryption with two-way authentication, the second device 03 and the data acquisition device 02 can interact directly or indirectly through the third device 04. In the case where the first device 01 needs to request multimedia data collected by the data acquisition device 02, the first device 01 can implement the data request through the third device 04, for example, obtain ciphertext data through the third device 04, and decrypt the obtained ciphertext data to obtain the multimedia data. In addition, even if the third device 04 participates in the interaction between the first device 01, the data acquisition device 02 and the second device 03, the data obtained by the third device 04 is also processed ciphertext data, and the third device 04 cannot decrypt the ciphertext data, thereby avoiding data leakage of multimedia data in the third device 04.
[0069] In a possible implementation, the first device 01 and the second device 03 may be any device with an object interaction function, and the first device 01 and the second device 03 may be terminal devices such as desktop computers, laptop computers or smart phones, or servers that process data in the interaction process, such as central servers, edge servers, or local servers in local data centers. The server may be a physical server or a cloud server that provides cloud computing services. The multimedia data collected by the data acquisition device 02 may include video data, image data, and audio data, etc., and the data acquisition device 02 may be any device with a data acquisition function, and the data acquisition device 02 may be a video acquisition device, such as a camera, or an image acquisition device, such as a camera, or an audio acquisition device, such as a recorder, etc. In addition, the data acquisition device 02 may be a complete device that provides a data acquisition function, or a network card configured on the data acquisition device for data processing, or the data acquisition device 02 is a terminal that provides a data acquisition function. Exemplarily, the third device 04 may be any platform that provides a data processing function, including but not limited to a visual networking platform.
[0070] The data processing method provided in the embodiment of the present application can be applied to the above Figure 1 or Figure 2 The implementation scenario shown in FIG. 1 is a flowchart of the method. Figure 3 As shown, it includes S301-S302.
[0071] S301, acquiring multimedia data collected by a data collection device.
[0072] In a possible implementation, before acquiring the multimedia data collected by the data acquisition device, it is also necessary to authenticate the data acquisition device to determine whether the multimedia data can be collected by the data acquisition device. The authentication process includes but is not limited to: acquiring first identity information for identifying the data acquisition device; and executing the operation of acquiring the multimedia data collected by the data acquisition device when the first identity information is authenticated by the target object.
[0073] Exemplarily, the data acquisition device may provide an information input control to obtain the first identity information input through the information input control, or the first identity information may be pre-stored, for example, the manufacturer sets and stores the first identity information of each data acquisition device before shipment. In this case, the data acquisition device may access the storage space to obtain the first identity information stored in the storage space. The embodiment of the present application does not limit the first identity information of the data acquisition device, and may be any information used to identify the data acquisition device, including but not limited to the device identity identification number (identity document, ID) or product serial number of the data acquisition device. In the case where the data acquisition device includes multiple products, the product serial numbers included in the first identity information may be all product serial numbers of the multiple products. For example, the data acquisition device is a SLR camera, and the SLR camera includes two products, namely the body and the lens. The product serial numbers included in the first identity information may be the product serial number of the body and the product serial number of the lens. Optionally, the product serial numbers included in the first identity information may also be some of the product serial numbers of the multiple products. Continuing with the example of a SLR camera being the data acquisition device, the data collected by the SLR camera is determined based on the viewfinder configured on the camera body, and the lens configured on the SLR camera will be replaced based on the acquisition requirements, for example, lenses of different focal lengths may be replaced based on the distance of data acquisition, that is, the fixed product of the SLR camera is the camera body. Therefore, the product serial number included in the first identity information may also be only the product serial number of the camera body.
[0074] Regardless of the method and type of the first identity information obtained, the data acquisition device can send the first identity information to the second device corresponding to the target object for security authentication after obtaining the first identity information. The second device corresponding to the target object can be a device used by the target object, or a device authorized by the target object to manage data. For example, the target object has limited free time and authorizes a guardian to manage data, so the second device can also be a device used by the guardian of the target object. After receiving the first identity information, the second device can display the received first identity information, and the target object determines whether the data acquisition device is safe based on the displayed first identity information. Taking the first identity information as an identity identification number as an example, the second device registers the data acquisition device based on the first identity information, displays the identity identification number of the registered data acquisition device, and the target object explicitly requests the data acquisition device to be authenticated based on the identity identification number of the displayed data acquisition device, and further determines whether the data acquisition device is safe based on experience.
[0075] In addition, the data acquisition device may also send the first identity information to a certification authority (CA) or other authoritative and impartial third-party trust organization to apply for a digital certificate from the CA. The CA verifies the device security of the data acquisition device based on the received first identity information, and issues a digital certificate to the data acquisition device if the verification is passed. The issued digital certificate includes the issuing authority, validity period, and device identification of the data acquisition device. After obtaining the digital certificate, the data acquisition device may send the digital certificate to the second device. The target object reads the digital certificate based on the second device. Since the digital certificate is issued by the CA and the digital certificate is within the validity period, the target object determines that the data acquisition device is a safe and trustworthy device.
[0076] In one case, the data acquisition device may also apply for a digital certificate based on the second device. That is, the data acquisition device sends the first identity information to the second device, and the second device sends the received first identity information to the CA to apply to the CA for a digital certificate for the data acquisition device, and when the digital certificate is successfully issued, the data acquisition device is determined to be a security device that can be used for data acquisition. In addition, the process of applying for a digital certificate from the CA may also be performed by other objects, such as the manufacturer of the data acquisition device. Before the data acquisition device leaves the factory, the manufacturer applies to the CA for authentication of the data acquisition device to obtain the product serial number of each data acquisition device.
[0077] In the above device authentication process, the data acquisition device and the second device may interact directly or indirectly. For example, the data acquisition device and the second device are connected via a third device. In this case, the data acquisition device authenticates the target object via the third device, for example, the first identity information is sent to the third device, and the third device sends it to the second device, so that the target object authenticates according to the first identity information displayed by the second device.
[0078] Regardless of the method used to determine the device security of the data acquisition device, the target object can, when the device security is determined, authorize the data acquisition device to perform data acquisition by interacting with the second device, so that the second device can determine the device security of the data acquisition device and realize the authentication of the data acquisition device. Among them, the interaction can be achieved through face recognition or agreement signing and the like. For example, based on face recognition technology, the target object performs the specified action provided by the second device to determine whether it is authorized by the person himself, and the specified action includes but is not limited to blinking, turning the head left and right, and nodding. Alternatively, the second device provides an agreement signing control, and the agreement signing control is, for example, "I have read and agreed to the privacy policy", and the target object triggers the agreement signing control to authorize the data acquisition device to perform data collection. The above-mentioned trigger control can be triggered by click, voice or other triggering methods.
[0079] After the second device interacts with the target object to determine that the data collection device is safe, it can send a certificate indicating that the device is safe to the data collection device, such as Figure 4 As shown, the data collection device further determines, based on the received certificate, that the security authentication of the target object has been passed, and can start data collection.
[0080] Regardless of the method by which the data acquisition device is authenticated by the target object, data acquisition can be performed based on the authentication of the target object to obtain multimedia data. Among them, data acquisition can be performed by following the target object for data acquisition, that is, the target object is the object to be collected. Taking the data acquisition device as a camera as an example, the lens of the camera follows the target object to achieve video recording of the target object. Data acquisition can also be performed according to the acquisition target set by the target object, that is, the target object is the object that needs to be collected. For example, the data acquisition device is a home camera placed by the target object. The target object sets the acquisition target of the home camera to the living room by placing the home camera, and the home camera starts recording the video of the living room. In addition, the embodiment of the present application does not limit the data type of the multimedia data collected by the data acquisition device, which can be video data, image data, audio data, etc.
[0081] S302, encrypt or sign the multimedia data based on the identity information to obtain the data processing result corresponding to the multimedia data, the identity information is determined based on the information used for authentication between the second device corresponding to the target object and the data acquisition device, the target object is the object using the data acquisition device, and the data processing result is used for the authorized device to access the multimedia data.
[0082] In one possible case, the multimedia data collected by the data acquisition device includes the personal information of the target object. In the case where the data acquisition device follows the target object to collect data, the collected multimedia data includes but is not limited to the portrait and behavioral habits of the target object. In the case where the collection target of the data acquisition device is set to the target object, the collected multimedia data includes but is not limited to the environmental information of the target object's private space, such as the living room environmental information exemplified in the above embodiment. In addition, since the target object may pass through the living room, the collected multimedia data will also include the portrait and personal habits of the target object. Since the multimedia data collected by the data acquisition device includes the personal information of the target object, the ownership of the multimedia data belongs to the target object. Therefore, the data acquisition device needs to process the multimedia data to prevent other devices from arbitrarily accessing the multimedia data and causing the leakage of personal information.
[0083] In one possible implementation, before processing multimedia data, the data acquisition device will also perform security authentication with the second device to authenticate the transmission security of the transmission channel between the data acquisition device and the second device. The identity information used in the security authentication process includes first identity information for identifying the data acquisition device and second identity information for identifying the second device. Similar to the description of the first identity information, the second identity information can also be any information that can identify the second device, including but not limited to the ID of the second device. For a detailed description, please refer to the relevant content of the first identity information in S301, which will not be repeated here.
[0084] Exemplarily, the process of authentication based on identity information includes: the data acquisition device encrypts the first identity information to obtain a first security ciphertext, and sends the first security ciphertext to the second device; while verifying the transmission security based on the first security ciphertext, receiving the second security ciphertext returned by the second device, the second security ciphertext being encrypted based on the second identity information; decrypting the second security ciphertext, and verifying whether the transmission with the second device is secure based on the decryption result.
[0085] Next, taking the first identity information as ID_i and the second identity information as ID_M as an example, the verification process based on the first identity information and the second identity information is illustrated. The data acquisition device randomly generates an authentication key K, and uses ID_i and K to generate authentication information, the authentication information includes R and n, where R = PRF (K, ID_i||Nonce), n = PRF (K, R), PRF () is a calculation function, || indicates a splicing operation, and Nonce refers to an arbitrary or non-repeated random value used once.
[0086] Afterwards, the data acquisition device generates a first secure ciphertext based on the authentication information. For example, an authorization value (Auth_value_i) is first generated based on R and n, and a first secure ciphertext is generated based on the authorization value. The calculation process of the authorization value is Auth_value_i=AES-CMAC(n, ID_i||R||"MAC"), AES-CMAC is a calculation function, and MAC indicates the type of generated parameters. The process of generating the first secure ciphertext based on the authorization value is, for example, C1=Enc(PK1, ID_i||Auth_value_i ID_i||R||n||Ai). Among them, C1 is the first secure ciphertext, Enc refers to encryption, PK1 is the public key 1 in the public-private key pair 1 randomly generated by the second device, Ai is the parameter generated based on the randomly generated ai, Ai=ai×g, and g indicates the cryptographic parameter.
[0087] After obtaining the first security ciphertext, the data acquisition device can send the first security ciphertext to the second device. The second device uses the private key 1 corresponding to the public key 1 to decrypt the first security ciphertext and obtain the first identity information ID_i, the authorization value Auth_value_i, the authentication information R and n, and Ai. The reference value Auth_value_i'=AES-CMAC(n, ID_i||R||"MAC") is recalculated based on the obtained information, and the calculated reference value and authorization value are compared. If the reference value and the authorization value are different, it is determined that the first security ciphertext has been tampered with during the transmission process, and the transmission between the data acquisition device and the second device is not safe. If the reference value and the authorization value are the same, it is determined that the first security ciphertext has not been tampered with during the transmission process, and the transmission between the data acquisition device and the second device is safe. In this case, the second device starts to generate the second security ciphertext based on the second identity information.
[0088] Similar to the process of generating Ai, the second device will also generate the parameter Bi used in the encryption process, Bi = bi × g + Ai, where bi is a randomly generated parameter. Afterwards, the second device generates a second secure ciphertext based on Bi and the second identity information ID_M. The generation process includes first generating an intermediate value Si = F2 (SK2, bi, Bi, ID_i, ID_M), where F2 is a calculation function, F2 (SK2, bi, Bi, ID_i, ID_M) = bi + Hash (ID_i||ID_M||Bi) × SK2, SK2 is the private key 2 in the public-private key pair in the signature certificate of the second device. The second device uses Si to calculate the second secure ciphertext C2 = AES-GCM (n, ID_i||ID_M||Ai||Bi||Si), where AES-GCM refers to the calculation function.
[0089] The second device sends the calculated second security ciphertext to the data acquisition device, and the data acquisition device performs transmission verification based on the received second security ciphertext. For example, the second security ciphertext is decrypted using n to obtain ID_i||ID_M||Ai||Bi||Si, and Ti=Hash(ID_i||ID_M||Bi)×PK2 is calculated based on the decryption result. Among them, PK2 is the public key 2 corresponding to the private key 2 used in the process of encrypting the second security ciphertext. Compare whether Si×g and Ti+Bi-Ai are equal. If they are equal, it means that the second security ciphertext has not been tampered with during the transmission process, that is, the transmission between the data acquisition device and the second device is secure. If they are not equal, it means that the second security ciphertext has been tampered with during the transmission process, that is, the transmission between the data acquisition device and the second device is not secure. Similar to the device authentication process in S301, the data acquisition device and the second device can also authenticate the second device through a third device during the process of authenticating transmission security.
[0090] Exemplarily, the data acquisition device can process multimedia data through the identity information used in the above authentication process, such as the first identity information ID_i and the second identity information ID_M in the above embodiment. The present application embodiment does not limit the process of the data acquisition device processing multimedia data based on identity information, which can be achieved in the following two ways including but not limited to.
[0091] Processing process 1: Obtain a first key, which is obtained by negotiation with a second device based on identity information; encrypt multimedia data according to the first key to obtain ciphertext data, and use the ciphertext data as a data processing result.
[0092] In one possible case, the data collection device can calculate the second public key and the second private key of the data collection device based on the identity information; and negotiate the first key based on the second public key, the second private key and the identity information. Since the second device is the device corresponding to the target object, and the ownership of the multimedia data belongs to the target object, the data collection device can interact and negotiate with the second device.
[0093] Optionally, the data acquisition device calculates a second public key pk=Bi+Ti and a second private key sk=ai+Si, wherein Bi, Ti, ai and Si are parameters generated during the authentication process, Ti is calculated based on the first identity information and the second identity information, and Si is also calculated based on the first identity information and the second identity information. For a detailed description of Bi, Ti, ai and Si, please refer to the authentication process of the data acquisition device and the second device in the above embodiment, which will not be repeated here.
[0094] Exemplarily, the data acquisition device sends identity information to the second device, the second device generates a first identifier based on the received identity information, negotiates based on the first identifier, and obtains a second public key and a second private key. Optionally, the second device can splice the product serial number of the body and lens or other hardware information included in the identity information, and use the splicing result as the first identifier.
[0095] The embodiment of the present application does not limit the process of the second device negotiating the second public key and the second private key based on the first identifier. In one possible case, the second device pre-deploys multiple shared public-private key pairs, and defines a second identifier for identifying different public-private key pairs for each public-private key pair. The second device searches for the second identifier based on the first identifier, and when a matching second identifier is found, the public-private key pair corresponding to the second identifier is used as the second public key and the second private key. Alternatively, the second device can calculate the second public key and the second private key based on the first identifier, for example, using an asymmetric encryption algorithm (RSA) to calculate the second public key and the second private key based on the first identifier.
[0096] After the second public key and the second private key are obtained through negotiation with the second device, the data acquisition device can further negotiate with the second device based on the identity information to obtain the first key. Negotiation generation means that the data acquisition device and the second device first respectively generate the parameters required to obtain the first key, and then the data acquisition device and the second device exchange the generated parameters, and perform similar steps according to the exchanged parameters to respectively calculate the first key.
[0097] Next, taking the example of the data acquisition device calculating the first parameter X and the second device calculating the second parameter Y and the third parameter B_M, the process of negotiating the first key is explained. Exemplarily, the data acquisition device randomly generates data x, generates the first parameter X according to the data x, and the calculation process is, for example, X=x×g. The second device randomly generates data y, generates the second parameter Y according to the data y, and the calculation process is, for example, Y=y×g, and then randomly generates the third parameter B_M. The data acquisition device sends the first parameter X and Bi generated in the process of verifying the transmission security to the second device, and the second device sends the second parameter Y and the third parameter B_M to the data acquisition device. Afterwards, the data acquisition device calculates pk_M=B_M+Hash(ID_M, B_M)×PK2, and verifies the validity of pk_M and ID_M, such as whether the data format is correct. When the verification indication is valid, W=Bi||B_M||ID_i||ID_M||X||Y is calculated, and MK=(x+Hash(W)×ski)×(Y+Hash(W)×pk_M) is calculated based on W to obtain the first key K_auth||K_enc=KDF(MK, W||"workkey"), where KDF is a function and workkey indicates that the calculated result is the key.
[0098] Similar to the operation of the data acquisition device, the second device also generates pk_i according to the first parameters X and Bi. The calculation process is, for example, pk_i=Bi+Hash(ID_i||ID_M, Bi)×PK2, and the validity of pk_i and ID_i is verified. After the verification is passed, W, MK and the first key are calculated. For example, W=Bi||B_M||ID_i||ID_M||X||Y, MK=(y+Hash(W)×sk_M)×(X+Hash(W)×pk_i), and the first key K_auth||K_enc=KDF(MK, W||"workkey").
[0099] Figure 4 An interactive schematic diagram provided for an embodiment of the present application, Figure 4 In the method, the second device and the data acquisition device are connected through a third device. Both the data acquisition device and the second device include a secure channel establishment module. The secure channel establishment module is responsible for establishing a two-way authenticated end-to-end encrypted channel between the second device and the data acquisition device. Establishing an encrypted channel means generating a first key based on identity information, thereby encrypting the transmitted multimedia data based on the first key.
[0100] After calculating and obtaining the first key, the data acquisition device can encrypt the multimedia data according to the first key to obtain ciphertext data. Figure 4As shown, the data acquisition device also includes an encryption and decryption module for encrypting multimedia data. The embodiment of the present application does not limit the process of the data acquisition device using the first key to encrypt multimedia data, and any encryption algorithm can be used to implement it, including but not limited to the advanced encryption standard (AES), triple data encryption algorithm (TDEA), a stream encryption algorithm (Salsa20), data encryption standard (DES) and a block cipher algorithm (RC5). By using the first key for symmetric encryption, the symmetrically encrypted ciphertext data can be decrypted by the first key. Since the encryption key and the decryption key are both the first key, the above encryption process involves fewer keys, the encryption and decryption efficiency is high, and the performance is good.
[0101] Processing method two: obtain a second key of the data acquisition device, where the second key has not been authenticated by a second device corresponding to the target object; encrypt the multimedia data according to the second key to obtain ciphertext data corresponding to the multimedia data; sign the ciphertext data according to the identity information to obtain signature data corresponding to the ciphertext data, and obtain a data processing result based on the signature data and the ciphertext data, where the signature data is used to verify whether the ciphertext data is abnormal.
[0102] Exemplarily, the data acquisition device can randomly generate a second key, which can be a symmetric encryption key or an asymmetric encryption key. When the second key is an asymmetric encryption key, the second key is a public-private key pair (pk, sk), where pk indicates a public key and sk indicates a private key.
[0103] Regardless of the method and type of the second key generated by the data acquisition device, the second key can be used to encrypt the multimedia data. In the case where the second key is a symmetric encryption key, the data acquisition device can use a symmetric encryption algorithm to encrypt the multimedia data according to the second key. In the case where the second key is an asymmetric encryption key, the data acquisition device can use an asymmetric encryption algorithm to encrypt the multimedia data according to the public key included in the second key. The asymmetric encryption algorithm is, for example, RSA or other encryption algorithms.
[0104] Since the ciphertext data is encrypted based on the directly generated second key, the security of the second key has not been authenticated by the second device, and the security of the ciphertext data encrypted based on the second key is also unknown. Therefore, it is necessary to sign the ciphertext data using the identity information authenticated by the second device, so as to indicate the security of the ciphertext data through the signature data corresponding to the ciphertext data.
[0105] In one possible case, the process of the data acquisition device signing the ciphertext data includes: obtaining the third public key of the second device, encrypting the second key according to the third public key, obtaining the ciphertext parameter corresponding to the second key, and the ciphertext parameter is used to obtain the second key required for decrypting the ciphertext data; signing the ciphertext data and the ciphertext parameter according to the identity information, obtaining the signature data corresponding to the ciphertext data and the ciphertext parameter, and obtaining the data processing result according to the ciphertext data, the ciphertext parameter and the signature data. Among them, the third public key is the public key owned by the second device, and the third public key is, for example, the public key 1 in the public-private key pair 1 or the public key 2 in the public-private key pair 2 used in the above-mentioned authentication process. The data acquisition device can receive the third public key sent by the second device, or, when the third public key is publicly available, access the public location of the third public key to obtain the third public key.
[0106] Regardless of the method by which the data acquisition device obtains the third public key, the second key required for decrypting the ciphertext data can be encrypted according to the third public key. In the case where the ciphertext data is encrypted using a symmetric encryption algorithm, the key required for decrypting the ciphertext data is the second key. Therefore, the data acquisition device can use the third public key of the second device to encrypt the second key to obtain the ciphertext parameters. In the case where the ciphertext data is encrypted using an asymmetric algorithm, the key required for decrypting the ciphertext data is the private key sk included in the second key. Therefore, the data acquisition device can use the third public key to encrypt the private key sk included in the second key to obtain the ciphertext parameters. By encrypting the second key required for decryption, the second device can obtain the second key to decrypt the ciphertext data when it needs to obtain multimedia data to obtain multimedia data.
[0107] Since the ciphertext data and ciphertext parameters may be intercepted and tampered with during the transmission process, the data acquisition device needs to sign the ciphertext data and ciphertext parameters to verify whether the ciphertext data and ciphertext parameters are intercepted and tampered with by other devices based on the signature data, thereby determining the security of the ciphertext data and ciphertext parameters. Among them, the data acquisition device can splice the ciphertext data and ciphertext parameters, sign the splicing result according to the identity information, and obtain a signature data corresponding to the ciphertext data and ciphertext parameters. It is also possible to sign the ciphertext data and ciphertext parameters respectively according to the identity information to obtain multiple signature data corresponding to the ciphertext data and ciphertext parameters. The signature can be a hash calculation based on the identity information, ciphertext data and ciphertext parameters using a hash algorithm, or it can be performed in other ways.
[0108] In a possible implementation, after the data acquisition device obtains the data processing result, it will also send the data processing result to the second device corresponding to the target object, so that the second device can obtain multimedia data according to the data processing result, and then provide the multimedia data to the target object. For the ciphertext data obtained in the first processing process, since the first key is obtained by negotiation between the data acquisition device and the second device, the first key is known data on the second device side, and the second device can decrypt the ciphertext data according to the first key to obtain the multimedia data.
[0109] For the ciphertext data obtained in the second processing step, since the second key is a key directly generated by the data acquisition device, the second key is unknown data on the second device side. The second device first performs verification based on the signature data, performs signature calculation based on the ciphertext data, ciphertext parameters and identity information to obtain signature data, and compares the calculated signature data with the signature data sent by the data acquisition device. If the calculated signature data is different from the signature data sent by the data acquisition device, it is determined that the verification has not passed, the ciphertext data and ciphertext parameters have been intercepted and tampered with during transmission, the security is unknown, and the decryption is canceled. If the calculated signature data is the same as the signature data sent by the data acquisition device, it is determined that the verification has passed, there is no abnormality in the ciphertext data and ciphertext parameters, and the ciphertext data and ciphertext parameters can be decrypted. The second device uses all the third private keys to decrypt the ciphertext parameters to obtain the second key, and then decrypts the ciphertext data according to the second key to obtain multimedia data. Exemplarily, the above process of decrypting ciphertext data to obtain multimedia data can be performed by Figure 4 The encryption and decryption module included in the first device is implemented.
[0110] In one possible implementation, see Figure 4 After processing the ciphertext data, the data acquisition device will also send the ciphertext data to the third device for ciphertext data storage, so that when an authorized device requests data later, the third device can provide data to the authorized device. Since the data sent by the data acquisition device to the third device is encrypted ciphertext data, even the third device used for data communication between the data acquisition device and the second device cannot access and obtain multimedia data without authorization, which effectively protects the multimedia data.
[0111] In summary, in the data processing method provided by the embodiment of the present application, after the data acquisition device acquires the multimedia data, it will process the multimedia data to obtain the data processing result, so as to prevent other devices from accessing the multimedia data without authorization, thereby realizing the privacy protection of the data and the target object. In addition, the processing of the multimedia data is based on the identity information. Since the identity information is the information used for authentication between the second device and the data acquisition device, the security is bidirectionally authenticated by the data acquisition device and the second device, and the reliability is high. The multimedia data obtained based on the identity information with high reliability has high security.
[0112] This application also provides a data processing method that can be applied to Figure 1 or Figure 2 In the implementation scenario shown in FIG. 1 , the method can be executed by a first device, and the flowchart of the data processing method is as follows: Figure 5 As shown, including S501-S503.
[0113] S501: Send an access request for multimedia data.
[0114] Exemplarily, the first device is another device independent of the data acquisition device and the second device. In one possible case, the first device is a device used by a user, and the user refers to an object that needs to use multimedia data. Figure 3 In the embodiment shown, the data acquisition device is a camera placed in the living room of the target object, and the user can be the guardian of the target object who applies to view the camera, so as to timely confirm the safety of the target object according to the multimedia data collected by the camera. Regardless of the situation of the first device, a request for access to multimedia data will be sent based on the demand for data acquisition.
[0115] In a possible implementation, the first device may send an access request to the second device corresponding to the target object to request authorization from the target object, the owner of the multimedia data. The embodiment of the present application does not limit the way in which the first device sends the access request to the second device, which may be sent directly, for example Figure 6 As shown, Figure 6 In the example, a communication connection is established between the second device and the first device, and the first device sends an access request to the second device based on the communication connection. The first device may also send an access request to the second device indirectly, for example Figure 7 As shown, the second device and the first device cannot communicate directly due to the limitation of the communication link. The second device and the first device are connected through a third device. Based on this, the first device can send an access request to the third device, and the third device forwards the access request to the second device. The third device can be a visual networking platform or other real-time network.
[0116] In addition, the first device can also send an access request to the third device. For example, the third device stores ciphertext data corresponding to multimedia data and can provide data to authorized devices. Therefore, the first device can request ciphertext data from the third device, and the third device shares the data provision task of the second device, thereby improving data processing efficiency. In the case where the first device requests multimedia data from a third device different from the second device, since the ownership of the multimedia data is the target object corresponding to the second device, the third device will send the access request to the second device for authorization verification.
[0117] Regardless of the method by which the second device receives the access request from the first device, the first device can be authenticated according to the access request. Figure 6 and Figure 7 In the example, the second device includes an authorization module for verifying the first device. Exemplarily, the second device can obtain device information of the first device according to the access request, and determine whether to grant the first device permission to obtain multimedia data according to the device information of the first device and at least one device information, wherein the at least one device information is information of at least one device that has signed a data protocol, and the data protocol is used to obtain access rights to multimedia data.
[0118] The embodiment of the present application does not limit the process of obtaining the device information of the first device according to the access request. The device information of the first device can be sent to the second device synchronously with the access request, that is, the device information is carried in the access request of the first device, and the second device can parse the received access request and read the device information carried in the access request. Alternatively, the device information of the first device can also be sent to the second device asynchronously with the access request. For example, after obtaining the access request, the second device triggers the device verification of the first device based on the access request and sends the identity verification instruction to the first device. Based on the received device verification instruction, the first device sends the device information to the second device for identity verification. The device information of the first device can be the device identification of the first device. In the case where the first device is a device used by the user, the device information of the first device can also include the object information of the user, such as the object identification of the user, the organization or enterprise institution to which the user belongs, etc. The object identification is, for example, the name, certificate number, telephone number, and biometric information of the user, such as a face photo, fingerprint, etc.
[0119] After obtaining the device information of the first device, the second device can verify the first device according to the obtained device information. Exemplarily, the second device searches at least one device information according to the device information of the first device, and determines to grant the first device permission to obtain multimedia data when the at least one device information includes the device information of the first device. The embodiment of the present application does not limit the way in which the second device obtains at least one device information, and the data agreement signed by the second device and the device can be signed online. In this case, the second device counts the device information used by the device that signed the data agreement to obtain at least one device information. Alternatively, the data agreement signed by the second device and the device is signed offline. For example, the target object and the object corresponding to the device sign the data agreement offline, and after signing, the object information of the object corresponding to the device is input into the control according to the information provided by the second device as the device information of the device. In some cases, at least one device information may also be referred to as a whitelist.
[0120] In the case where at least one device information does not include the device information of the first device, the second device can directly determine that the first device is not granted the permission to obtain multimedia data, and send a refusal instruction to the first device. The second device can also verify the device security of the first device based on the device information of the first device, and determine to grant the first device the permission to obtain multimedia data when the verification result indicates that the device is safe, wherein verifying the device security can be to find the network domain name in the device information of the first device, determine whether the network location of the first device belongs to a trusted network, or, according to the organization in the device information of the first device, verify the organizational security of the organization, and determine the accuracy of the device information according to the member list of the organization. Optionally, the second device can directly interact with the first device to perform the operations of S502-S503 when the verification is passed, so that the first device can obtain multimedia data, and can also interact with the first device to sign a data agreement when the verification is passed to determine the operations performed by the first device on the multimedia data, so as to avoid the first device from arbitrarily forwarding multimedia data, resulting in data leakage.
[0121] S502, when access rights to multimedia data are obtained based on an access request, ciphertext data corresponding to the multimedia data is obtained, the ciphertext data is obtained by encrypting or signing the multimedia data according to identity information, the identity information is determined based on information used for authentication between a second device corresponding to the target object and a data acquisition device for the multimedia data, and the target object is an object using the data acquisition device.
[0122] Exemplarily, since the ciphertext data is obtained by encrypting the multimedia data, the first device that needs to obtain the multimedia data can obtain the ciphertext data and decrypt the ciphertext data to obtain the requested multimedia data. The ciphertext data is obtained by processing according to the identity information. Optionally, the identity information is used by the data acquisition device and the second device to negotiate to obtain a first key, and then the ciphertext data is obtained by encrypting the multimedia data according to the first key. For the process of encrypting the multimedia data to obtain the ciphertext data, please refer to Figure 3 The description of the processing method 1 in the embodiment S302 shown is not repeated here. Optionally, the identity information can also be used to sign the ciphertext data corresponding to the multimedia data, and the signature data obtained by the signature is used by the second device to verify whether the ciphertext data sent by the received data acquisition device is abnormal, and the second device is used to provide the ciphertext data to the first device. For the signature and the second device verification process, please refer to Figure 3 The relevant description in the embodiment S302 shown is not repeated here. In addition, the embodiment of the present application does not limit the process of the first device obtaining the ciphertext data, and the ciphertext data can be obtained in the following two ways including but not limited to.
[0123] Acquisition method 1: Receive the ciphertext data returned based on the access request.
[0124] Exemplarily, after the second device determines that the first device is allowed to obtain the multimedia data based on the access request, it can provide the ciphertext data to the first device so that the first device decrypts the ciphertext data to obtain the multimedia data. The second device can choose to send the ciphertext data to the first device, or send a permission to send instruction to other devices that can provide ciphertext data. The other device sends the ciphertext data to the first device based on the received permission to send instruction, and the first device thereby receives the returned ciphertext data.
[0125] Among them, other devices can be Figure 7 The third device shown, Figure 7 In the embodiment, after the data acquisition device and the second device complete the processing of the multimedia data through interaction, the encrypted ciphertext data is sent to the third device, and the third device manages the data provision. In this case, the second device can send a permission to send instruction to the third device indicating that the ciphertext data can be sent, so as to notify the third device to provide the ciphertext data to the first device. Optionally, the permission to send instruction can be an instruction specifically used to indicate that the verification is passed, or it can be a second authorization mark that needs to be provided to the first device, and the second authorization mark is the data that the first device needs to use in the process of obtaining multimedia data according to the ciphertext data.
[0126] In the case where the instruction to send is allowed to be the second authorization mark, the first device also needs to generate a second authorization mark based on the first public key. Exemplarily, the second device generates a second authorization mark based on the first public key of the first device, and the third public key and the third private key owned by the second device. The generation process is, for example, that the second device calculates the second authorization mark based on the first public key, the third public key and the third private key. In some cases, the second authorization mark may be referred to as a token. Regarding the role of the second authorization mark, please refer to the relevant description of decrypting the ciphertext data in S503, which will not be repeated here. By sending the second authorization mark that needs to be sent later to the third device, the notification of sending data can be realized, avoiding repeated sending of multiple data, and effectively reducing the interaction cost between the second device and the third device.
[0127] Acquisition method 2: receiving a first authorization mark returned based on the access request, the first authorization mark indicating permission to obtain the multimedia data; and requesting to obtain the ciphertext data according to the first authorization mark.
[0128] In one possible scenario, after determining that the first device can obtain multimedia data, the second device generates a first authorization mark, where the first authorization mark indicates that the first device is allowed to obtain multimedia data. The first authorization mark may include device information of the first device, etc. In some cases, the first authorization mark may be called a token. After obtaining the first authorization mark, the first device may request multimedia data based on the first authorization mark, wherein the first device may request multimedia data from any device that can provide data, including but not limited to the second device and the third device. In one possible scenario, when the device requesting multimedia data from the first device is a different device from the second device, the second device also needs to send the first authorization mark to the device providing the data so that the device performs mark verification based on the received first authorization mark. For example Figure 6 As shown, the second device sends the first authorization mark to the third device so that the third device performs mark verification.
[0129] Next, we will take the example of the first device requesting multimedia data from the third device for explanation. In one possible case, the first device sends the first authorization mark to the third device, and the third device compares the received first authorization mark with the first authorization mark sent by the second device. When the first authorization mark sent by the first device and the first authorization mark sent by the second device are the same, it is determined that the first device has been verified. When the first authorization mark sent by the first device and the first authorization mark sent by the second device are different, it is determined that the first device has failed to be verified. The third device can cancel sending the ciphertext data to the first device, or send a request failure instruction to the first device to notify the first device that the request for multimedia data has failed. In addition, in the case where the first authorization mark also includes the authorization time, the third device can further compare the current time with the authorization time when the first authorization mark sent by the first device and the first authorization mark sent by the second device are the same. When the current time is within the authorization time, it is determined that the first device has been verified. When the current time is not within the authorization time, it is determined that the first device has failed to be verified. The above verification process can be performed through Figure 6 or Figure 7 The authorization verification module included in the third device is shown to execute. Regardless of the method used to determine whether the first device has passed the verification, the third device can send ciphertext data to the first device when the verification is passed, so that the first device can obtain the ciphertext data.
[0130] S503, decrypt the ciphertext data to obtain multimedia data.
[0131] Since the first device needs to use the key of the ciphertext data during the process of decrypting the ciphertext data, the first device needs to request the key of the ciphertext data. For example, the first device can request the key from the device that indirectly manages the key. The device that indirectly manages the key refers to the device that manages the reference ciphertext. Figure 7 For example, Figure 7 In the example, the third device can receive the reference ciphertext sent by the second device or the data acquisition device, store and manage the received reference ciphertext. In this case, the third device is a device for indirectly managing the key. The reference ciphertext refers to the ciphertext encrypted by the key. In a possible implementation, the reference ciphertext can be obtained by encrypting the key of the ciphertext data using the third key of the second device. The key refers to the key required to encrypt multimedia data and decrypt the ciphertext data. The key can be Figure 3 The first key or the second key in the embodiment shown.
[0132] Optionally, the first device receives the re-encrypted data returned by the device for indirectly managing the key based on the access request, and decrypts the re-encrypted data to obtain the key. The re-encrypted data is obtained by encrypting the reference ciphertext according to the second authorization mark, and the second authorization mark is generated according to the first public key of the first device. For a specific description, please refer to the relevant description of the first acquisition method in S502, which will not be repeated here.
[0133] In one possible case, encrypting the reference ciphertext according to the second authorization flag to obtain the re-encrypted data may be performed by the second device, or may be performed as follows: Figure 7 The process is shown to be executed by a third device, or by another device including a reference ciphertext. Since the process of obtaining re-encrypted data by different devices is similar, the process of obtaining re-encrypted data is described below using the third device as an example.
[0134] The second device sends the second authorization mark to the third device, and the third device re-encrypts the reference ciphertext according to the received second authorization mark. The embodiment of the present application does not limit the process of encrypting the reference ciphertext by the third device, and any encryption algorithm can be used to re-encrypt the reference ciphertext based on the second authorization mark to obtain re-encrypted data. After obtaining the re-encrypted data, the third device can send the re-encrypted data to the first device if the access request of the first device is verified by the second device, so that the first device obtains the re-encrypted data. Based on the situation that the third device is also used to send ciphertext data to the first device, the third device can synchronously send the ciphertext data and the re-encrypted data to the first device, for example Figure 7 As shown, Figure 7 C0 indicates ciphertext data. Alternatively, the third device may also asynchronously send the ciphertext data and the re-encrypted data to the first device.
[0135] Regardless of the method of receiving the re-encrypted data, the first device can obtain the key of the ciphertext data according to the decryption result of the re-encrypted data. Since the second authorization mark for encrypting the re-encrypted data is generated according to the first public key, the re-encrypted data can be decrypted by the first private key corresponding to the first public key, and the decryption result obtained includes the reference ciphertext. In addition, since the second authorization identifier is generated according to the third public key and the third private key, the first device can determine the second authorization identifier according to the decryption result, and parse the second authorization identifier to obtain the third private key. Then, the reference ciphertext is decrypted by the third private key to obtain the key. After obtaining the key, the first device can decrypt the ciphertext data by the key to obtain the multimedia data.
[0136] Optionally, the first device may also request a key from a device that directly manages the key, where the device that directly manages the key refers to a device that manages an unencrypted key, such as Figure 6The second device shown may also be a data collection device. The process of the first device requesting a key from the device that directly manages the key includes but is not limited to: sending a first public key; receiving a first ciphertext obtained by encrypting the key according to the first public key, where the key is the key used to encrypt multimedia data.
[0137] Next, the process of obtaining the key is explained by taking the device that directly manages the key as the second device as an example. The first device sends the first public key to the second device. Since the second device has authenticated the device security of the first device, it determines that it is allowed to provide the key to the first device. The second device encrypts the key with the first public key to obtain the first ciphertext, and then sends the first ciphertext to the first device. Since the first ciphertext is encrypted by the first public key, and the first private key is the private key corresponding to the first public key, after receiving the first ciphertext, the first device can use the first private key to decrypt the first ciphertext and obtain the key, thereby decrypting the ciphertext data according to the key to obtain multimedia data.
[0138] In summary, the data processing method provided by the embodiment of the present application requires verification and authorization of the first device when there is a third-party device independent of the data acquisition device and the second device, that is, when the first device needs to obtain multimedia data. After the verification is passed, the first device can obtain the multimedia data, so as to realize data sharing under the premise of protecting the personal information of the target object, further explore the data value of the multimedia data, and realize efficient use of the data. Moreover, even if the verification process is executed through other platforms such as a third device, the third device cannot obtain the multimedia data, but can only obtain the ciphertext data, which effectively reduces the possibility of data leakage of the multimedia data on the third device and further improves the security of data processing.
[0139] The data processing method of the embodiment of the present application is introduced above. Corresponding to the above method, the embodiment of the present application also provides a data processing device. Figure 8 Schematic diagram of a data processing device provided in an embodiment of the present application. Figure 8 As shown in the following multiple modules, the Figure 8 The data processing device shown is capable of executing the above Figure 3 It should be understood that the device may include more additional modules than the modules shown or omit some of the modules shown, and the embodiments of the present application are not limited to this. Figure 8 As shown, the device is applied to a data acquisition device, and the device comprises:
[0140] An acquisition module 801 is used to acquire multimedia data collected by a data acquisition device;
[0141] Processing module 802 is used to encrypt or sign multimedia data based on identity information to obtain data processing results corresponding to the multimedia data. The identity information is determined based on the information used for authentication between the second device corresponding to the target object and the data acquisition device. The target object is the object using the data acquisition device. The data processing results are used for authorized devices to access multimedia data.
[0142] In one possible implementation, the identity information includes first identity information for identifying the data acquisition device and second identity information for identifying the second device. The processing module 802 is further used to encrypt the first identity information to obtain a first security ciphertext, and send the first security ciphertext to the second device; when verifying the transmission security based on the first security ciphertext, receive the second security ciphertext returned by the second device, the second security ciphertext being encrypted based on the second identity information; decrypt the second security ciphertext, and verify whether the transmission channel between the data acquisition device and the second device is secure based on the decryption result.
[0143] In a possible implementation, the processing module 802 is used to obtain a first key, where the first key is obtained through negotiation with the second device based on the identity information; encrypt the multimedia data according to the first key to obtain ciphertext data, and use the ciphertext data as a data processing result.
[0144] In a possible implementation, the processing module 802 is used to calculate the second public key and the second private key of the data acquisition device based on the identity information; and to negotiate the first key according to the second public key, the second private key and the identity information.
[0145] In one possible implementation, the processing module 802 is used to obtain a second key of the data acquisition device, where the second key has not been authenticated by a second device corresponding to the target object; encrypt the multimedia data according to the second key to obtain ciphertext data corresponding to the multimedia data; sign the ciphertext data according to the identity information to obtain signature data corresponding to the ciphertext data, and obtain a data processing result based on the signature data and the ciphertext data, where the signature data is used to verify whether the ciphertext data is abnormal.
[0146] In one possible implementation, the processing module 802 is used to obtain a third public key of the second device, encrypt the second key according to the third public key, and obtain a ciphertext parameter corresponding to the second key, the ciphertext parameter is used to obtain the second key required to decrypt the ciphertext data; sign the ciphertext data and the ciphertext parameter according to the identity information to obtain signature data corresponding to the ciphertext data and the ciphertext parameter, and obtain a data processing result based on the ciphertext data, the ciphertext parameter and the signature data.
[0147] In a possible implementation, the apparatus further includes: a sending module, configured to send a data processing result to a second device corresponding to the target object, wherein the data processing result is used by the second device to obtain multimedia data.
[0148] In a possible implementation, the data acquisition device is connected to a second device corresponding to the target object via a third device; and the data acquisition device performs authentication with the second device via the third device.
[0149] After acquiring multimedia data, the above-mentioned device will process the multimedia data based on the identity information. Since the identity information is the information used for authentication between the second device and the data acquisition device, the security is bidirectionally authenticated by the data acquisition device and the second device, and the reliability is high. The data processing results obtained based on the identity information with a high degree of reliability have high security.
[0150] The embodiment of the present application also provides another data processing device. Fig. 9 Schematic diagram of a data processing device provided in an embodiment of the present application. Fig. 9 As shown in the following multiple modules, the Fig. 9 The data processing device shown is capable of executing the above Figure 5 It should be understood that the device may include more additional modules than the modules shown or omit some of the modules shown, and the embodiments of the present application are not limited to this. Fig. 9 As shown, the device is applied to a first device, and the device includes:
[0151] A sending module 901, used for sending an access request to multimedia data;
[0152] An acquisition module 902 is used to acquire ciphertext data corresponding to the multimedia data when the access right to the multimedia data is acquired based on the access request, the ciphertext data being obtained by encrypting or signing the multimedia data according to the identity information, the identity information being determined based on information used for authentication between the second device corresponding to the target object and the data acquisition device for the multimedia data, the target object being the object using the data acquisition device;
[0153] The decryption module 903 is used to decrypt the ciphertext data to obtain multimedia data.
[0154] In a possible implementation, the acquisition module 902 is configured to receive ciphertext data returned based on the access request.
[0155] In a possible implementation, the acquisition module 902 is configured to receive a first authorization flag returned based on an access request, where the first authorization flag indicates that the multimedia data is allowed to be acquired; and request to acquire the ciphertext data according to the first authorization flag.
[0156] In one possible implementation, the acquisition module 902 is also used to receive re-encrypted data returned based on an access request, the re-encrypted data is obtained by encrypting a reference ciphertext according to a second authorization flag, the second authorization flag is generated according to a first public key, the first public key is a public key owned by a first device requesting multimedia data, and the reference ciphertext is a ciphertext encrypted with a key of the ciphertext data; the decryption module 903 is used to obtain the key of the ciphertext data according to the decryption result of the re-encrypted data, and decrypt the ciphertext data according to the key to obtain the multimedia data.
[0157] In a possible implementation, the sending module 901 is also used to send a first public key; the obtaining module 902 is also used to receive a first ciphertext obtained by encrypting a key according to the first public key, where the key is a key used to encrypt multimedia data; the decryption module 903 is used to decrypt the first ciphertext according to a first private key corresponding to the first public key to obtain the key; and decrypt the ciphertext data according to the key to obtain multimedia data.
[0158] In one possible implementation, an access request is used to obtain device information of a first device requesting multimedia data, and the device information of the first device is used to determine whether to grant the first device permission to obtain multimedia data based on at least one device information, and the at least one device information is information of at least one device that has signed a data protocol, and the data protocol is used to obtain access rights to multimedia data.
[0159] In a possible implementation, the sending module 901 is used to send an access request to a third device, the third device is connected to a second device corresponding to the target object, and the third device is used to send the access request to the second device.
[0160] In a possible implementation, the identity information is used by the data acquisition device and the second device to negotiate to obtain a first key, and the ciphertext data is obtained by encrypting the multimedia data according to the first key.
[0161] In one possible implementation, the identity information is used to sign the ciphertext data corresponding to the multimedia data. The signed signature data is used by the second device to verify whether the ciphertext data sent by the received data acquisition device is abnormal. The second device is used to provide the ciphertext data to the first device.
[0162] In a possible implementation, the identity information includes first identity information for identifying the data acquisition device and second identity information for identifying the second device.
[0163] When the above-mentioned device needs to obtain multimedia data, it will first perform security verification and authorization. Only after the verification is passed, the device can obtain the multimedia data, so as to realize data sharing while protecting the personal information of the target object, further explore the data value of multimedia data, and realize efficient use of data.
[0164] It should be understood that the above Figure 8 or Fig. 9 When the device provided realizes its functions, only the division of the above-mentioned functional modules is used as an example for illustration. In practical applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the device and method embodiments provided in the above embodiments belong to the same concept, and their specific implementation process is detailed in the method embodiment, which will not be repeated here.
[0165] See also Fig.10 , Fig.10 A schematic diagram of the structure of a network device 1000 provided by an exemplary embodiment of the present application is shown. Fig.10 The network device 1000 shown is used to perform the above Figure 3 or Figure 5 The operations involved in the data processing method shown. The network device 1000 is, for example, a switch, a router, etc. The network device 1000 can be implemented by a general bus architecture.
[0166] like Fig.10 As shown, the network device 1000 includes at least one processor 1001 , a memory 1003 , and at least one communication interface 1004 .
[0167] Processor 1001 is, for example, a general-purpose central processing unit (CPU), a digital signal processor (DSP), a network processor (NP), a graphics processing unit (GPU), a neural-network processing units (NPU), a data processing unit (DPU), a microprocessor, or one or more integrated circuits for implementing the solution of the present application. For example, processor 1001 includes an application-specific integrated circuit (ASIC), a programmable logic device (PLD) or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. PLD is, for example, a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. It can implement or execute various logic blocks, modules, and circuits described in conjunction with the disclosure of the embodiments of the present application. The processor can also be a combination that implements a computing function, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and the like.
[0168] Optionally, the network device 1000 further includes a bus. The bus is used to transmit information between the components of the network device 1000. The bus may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Fig.10 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.
[0169] The memory 1003 is, for example, a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, or a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 1003 is, for example, independent and connected to the processor 1001 via a bus. The memory 1003 can also be integrated with the processor 1001.
[0170] The communication interface 1004 uses any transceiver-like device for communicating with other devices or communication networks, and the communication network can be Ethernet, a radio access network (RAN) or a wireless local area network (WLAN), etc. The communication interface 1004 may include a wired communication interface and may also include a wireless communication interface. Specifically, the communication interface 1004 may be an Ethernet interface, a fast Ethernet (FE) interface, a gigabit Ethernet (GE) interface, an asynchronous transfer mode (ATM) interface, a wireless local area network (WLAN) interface, a cellular network communication interface or a combination thereof. The Ethernet interface may be an optical interface, an electrical interface or a combination thereof. In an embodiment of the present application, the communication interface 1004 may be used for the network device 1000 to communicate with other devices.
[0171] In a specific implementation, as an embodiment, the processor 1001 may include one or more CPUs, such as Fig.10 0 and CPU1 shown in FIG. Each of these processors may be a single-CPU processor or a multi-CPU processor. A processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0172] In a specific implementation, as an embodiment, the network device 1000 may include multiple processors, such as Fig.10 1 and 1005. Each of these processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). The processor here may refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).
[0173] In a specific implementation, as an embodiment, the network device 1000 may also include an output device and an input device. The output device communicates with the processor 1001 and can display information in a variety of ways. For example, the output device may be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector. The input device communicates with the processor 1001 and can receive user input in a variety of ways. For example, the input device may be a mouse, a keyboard, a touch screen device, or a sensor device.
[0174] In some embodiments, the memory 1003 is used to store the program code 1010 for executing the solution of the present application, and the processor 1001 can execute the program code 1010 stored in the memory 1003. That is, the network device 1000 can implement the data processing method provided by the method embodiment through the processor 1001 and the program code 1010 in the memory 1003. The program code 1010 may include one or more software modules. Optionally, the processor 1001 itself can also store the program code or instruction for executing the solution of the present application.
[0175] In a specific embodiment, the network device 1000 of the embodiment of the present application may correspond to the computing device in the above-mentioned various method embodiments.
[0176] in, Figure 3 or Figure 5Each step of the data processing method shown is completed by an integrated logic circuit of hardware or software instructions in the processor of the network device 1000. The steps of the method disclosed in conjunction with the embodiment of the present application can be directly embodied as a hardware processor, or a combination of hardware and software modules in the processor. The software module can be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory, and the processor reads the information in the memory, and completes the steps of the above method in conjunction with its hardware. To avoid repetition, it is not described in detail here.
[0177] See also Fig.11 , Fig.11 FIG. 1 shows a schematic diagram of the structure of a network device 1100 provided by another exemplary embodiment of the present application. Fig.11 The network device 1100 shown is used to perform the above Figure 3 or Figure 5 All or part of the operations involved in the data processing method shown. The network device 1100 is, for example, a switch, a router, etc. The network device 1100 can be implemented by a general bus architecture.
[0178] like Fig.11 As shown, the network device 1100 includes: a main control board 1110 and an interface board 1130 .
[0179] The main control board is also called a main processing unit (MPU) or a route processor card. The main control board 1110 is used to control and manage various components in the network device 1100, including routing calculation, device management, device maintenance, and protocol processing functions. The main control board 1110 includes: a central processing unit 1111 and a memory 1112.
[0180] The interface board 1130 is also called a line processing unit (LPU), a line card (linecard) or a service board. The interface board 1130 is used to provide various service interfaces and realize the forwarding of data packets. The service interface includes but is not limited to an Ethernet interface, a POS (Packet over SONET / SDH) interface, etc., and the Ethernet interface is, for example, a Flexible Ethernet Service Interface (Flexible Ethernet Clients, FlexE Clients). The interface board 1130 includes: a central processing unit 1131, a network processor 1132, a forwarding table entry memory 1134 and a physical interface card (physical interface card, PIC) 1133.
[0181] The central processing unit 1131 on the interface board 1130 is used to control and manage the interface board 1130 and communicate with the central processing unit 1111 on the main control board 1110 .
[0182] The network processor 1132 is used to implement the forwarding processing of the message. The network processor 1132 can be in the form of a forwarding chip. The forwarding chip can be a network processor (NP). In some embodiments, the forwarding chip can be implemented by an application-specific integrated circuit (ASIC) or a field programmable gate array (FPGA). Specifically, the network processor 1132 is used to forward the received message based on the forwarding table stored in the forwarding table entry memory 1134. If the destination address of the message is the address of the network device 1100, the message is sent to the CPU (such as the central processor 1131) for processing; if the destination address of the message is not the address of the network device 1100, the next hop and the output interface corresponding to the destination address are found from the forwarding table according to the destination address, and the message is forwarded to the output interface corresponding to the destination address. Among them, the processing of the uplink message may include: processing of the message input interface, forwarding table search; the processing of the downlink message may include: forwarding table search, etc. In some embodiments, the central processor can also perform the function of the forwarding chip, such as implementing software forwarding based on a general-purpose CPU, so that the forwarding chip is not required in the interface board.
[0183] The physical interface card 1133 is used to implement the physical layer docking function, whereby the original traffic enters the interface board 1130, and the processed message is sent from the physical interface card 1133. The physical interface card 1133, also called a daughter card, can be installed on the interface board 1130, and is responsible for converting the photoelectric signal into a message and forwarding the message to the network processor 1132 for processing after performing a validity check. In some embodiments, the central processor 1131 can also perform the functions of the network processor 1132, such as implementing software forwarding based on a general-purpose CPU, so that the network processor 1132 is not required in the physical interface card 1133.
[0184] Optionally, the network device 1100 includes a plurality of interface boards, for example, the network device 1100 further includes an interface board 1140, and the interface board 1140 includes: a central processor 1141, a network processor 1142, a forwarding table entry memory 1144, and a physical interface card 1143. The functions and implementation methods of the components in the interface board 1140 are the same or similar to those of the interface board 1130, and are not described in detail herein.
[0185] Optionally, the network device 1100 further includes a switching fabric board 1120. The switching fabric board 1120 may also be referred to as a switch fabric unit (SFU). When the network device 1100 has multiple interface boards, the switching fabric board 1120 is used to complete data exchange between the interface boards. For example, the interface board 1130 and the interface board 1140 may communicate through the switching fabric board 1120.
[0186] The main control board 1110 is coupled to the interface board. For example, the main control board 1110, the interface board 1130, the interface board 1140, and the switching network board 1120 are connected to the system backplane through the system bus to achieve intercommunication. In a possible implementation, an inter-process communication (IPC) channel is established between the main control board 1110 and the interface board 1130 and the interface board 1140, and the main control board 1110 and the interface board 1130 and the interface board 1140 communicate through the IPC channel.
[0187] Logically, the network device 1100 includes a control plane and a forwarding plane. The control plane includes a main control board 1110 and a central processing unit 1111. The forwarding plane includes various components for performing forwarding, such as a forwarding table entry memory 1134, a physical interface card 1133, and a network processor 1132. The control plane performs functions such as a router, generating a forwarding table, processing signaling and protocol messages, and configuring and maintaining the status of the network device. The control plane sends the generated forwarding table to the forwarding plane. On the forwarding plane, the network processor 1132 forwards the message received by the physical interface card 1133 based on the forwarding table sent by the control plane. The forwarding table sent by the control plane can be stored in the forwarding table entry memory 1134. In some embodiments, the control plane and the forwarding plane can be completely separated and not on the same network device.
[0188] It is worth noting that there may be one or more main control boards, and when there are multiple boards, they may include a primary main control board and a backup main control board. There may be one or more interface boards. The stronger the data processing capability of the network device, the more interface boards are provided. There may also be one or more physical interface cards on the interface board. There may be no switching network board, or there may be one or more switching network boards. When there are multiple switching network boards, they can jointly realize load sharing and redundant backup. In a centralized forwarding architecture, network devices may not need switching network boards, and the interface board is responsible for processing the service data of the entire system. In a distributed forwarding architecture, network devices may have at least one switching network board, and data exchange between multiple interface boards is realized through the switching network board, providing large-capacity data exchange and processing capabilities. Therefore, the data access and processing capabilities of network devices with distributed architectures are greater than those of network devices with centralized architectures. Optionally, the network device may have only one board, that is, no switching board, and the functions of the interface board and the main control board are integrated on the board. In this case, the central processor on the interface board and the central processor on the main control board can be combined into one central processor on the board to perform the functions of the two. This type of network device has low data exchange and processing capabilities (for example, low-end switches or routers and other network devices). The specific architecture to be adopted depends on the specific networking deployment scenario, and no limitation is made here.
[0189] In a specific embodiment, the network device 1100 corresponds to the above Figure 8 or Fig. 9 In some embodiments, Figure 8 The processing module 802 in the processing and forwarding device shown is equivalent to the central processor 1111 or the network processor 1132 in the network device 1100.
[0190] The embodiment of the present application also provides a communication device, which includes: a transceiver, a memory, and a processor. The transceiver, the memory, and the processor communicate with each other through an internal connection path, the memory is used to store instructions, and the processor is used to execute the instructions stored in the memory to control the transceiver to receive signals and control the transceiver to send signals, and when the processor executes the instructions stored in the memory, the processor executes the data processing method.
[0191] It should be understood that the processor may be a CPU, or other general-purpose processors, DSPs, ASICs, FPGAs or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc. It is worth noting that the processor may be a processor supporting an advanced RISC machines (ARM) architecture.
[0192] Further, in an optional embodiment, the memory may include a read-only memory and a random access memory, and provide instructions and data to the processor. The memory may also include a non-volatile random access memory. For example, the memory may also store information about the device type.
[0193] The memory may be a volatile memory or a nonvolatile memory, or may include both volatile and nonvolatile memory. Among them, the nonvolatile memory may be a ROM, a programmable read-only memory (programmable ROM, PROM), an erasable programmable read-only memory (erasable PROM, EPROM), an EEPROM or a flash memory. The volatile memory may be a RAM, which is used as an external cache. By way of example but not limitation, many forms of RAM are available. For example, static random access memory (static RAM, SRAM), dynamic random access memory (dynamic random access memory, DRAM), synchronous dynamic random access memory (synchronous DRAM, SDRAM), double data rate synchronous dynamic random access memory (doubledata rate SDRAM, DDR SDRAM), enhanced synchronous dynamic random access memory (enhanced SDRAM, ESDRAM), synchronous connection dynamic random access memory (synchlink DRAM, SLDRAM) and direct memory bus random access memory (direct rambus RAM, DR RAM).
[0194] The embodiment of the present application also provides a data processing device, the device includes a processor, the processor is used to load and run at least one instruction, so that the data processing device implements the data processing method provided by the embodiment of the present application. Optionally, the device also includes a memory, the memory is coupled to the processor, and the memory is used to store at least one instruction.
[0195] An embodiment of the present application also provides a data processing system, which includes a data acquisition device and a third device, and the data acquisition device and the third device are used to execute the data processing method provided in the embodiment of the present application.
[0196] An embodiment of the present application also provides a computer-readable storage medium, in which at least one instruction is stored. The instruction is loaded and executed by a processor so that a computer implements any of the data processing methods described above.
[0197] The embodiments of the present application also provide a computer program (product), which, when executed by a computer, can enable a processor or a computer to execute the corresponding steps and / or processes in the above method embodiments.
[0198] An embodiment of the present application also provides a chip, which includes a processor for calling and executing instructions stored in a memory from the memory, so that a communication device equipped with the chip executes any of the data processing methods described above.
[0199] An embodiment of the present application also provides another chip, including: an input interface, an output interface, a processor and a memory, wherein the input interface, the output interface, the processor and the memory are connected via an internal connection path, and the processor is used to execute the code in the memory. When the code is executed, the processor is used to execute any of the data processing methods described above.
[0200] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in this application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website site, computer, server or data center to another website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) mode. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integration. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state hard disk Solid State Disk), etc.
[0201] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.) and signals involved in this application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions. For example, the multimedia data involved in this application are all obtained with full authorization.
[0202] Those of ordinary skill in the art will appreciate that, in conjunction with the various method steps and modules described in the embodiments disclosed herein, they can be implemented in software, hardware, firmware, or any combination thereof. In order to clearly illustrate the interchangeability of hardware and software, the steps and components of each embodiment have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those of ordinary skill in the art may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0203] A person skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware or by instructing related hardware through a program, and the program may be stored in a computer-readable storage medium, and the above-mentioned storage medium may be a read-only memory, a disk or an optical disk, etc.
[0204] When software is used for implementation, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer program instructions. As an example, the method of the embodiment of the present application can be described in the context of a machine executable instruction, and the machine executable instruction is such as included in the program module executed in the device on the real or virtual processor of the target. Generally speaking, a program module includes a routine, a program, a library, an object, a class, a component, a data structure, etc., which performs a specific task or realizes a specific abstract data structure. In various embodiments, the function of the program module can be merged or divided between the described program modules. The machine executable instruction for the program module can be executed in a local or distributed device. In a distributed device, the program module can be located in both a local and a remote storage medium.
[0205] The computer program code for realizing the method for the embodiment of the present application can be written in one or more programming languages. These computer program codes can be provided to the processor of a general-purpose computer, a special-purpose computer or other programmable data processing device, so that the program code, when executed by a computer or other programmable data processing device, causes the function / operation specified in the flow chart and / or block diagram to be implemented. The program code can be executed completely on a computer, partially on a computer, as an independent software package, partially on a computer and partially on a remote computer or completely on a remote computer or server.
[0206] In the context of the embodiments of the present application, computer program codes or related data may be carried by any appropriate carrier to enable a device, apparatus or processor to perform the various processes and operations described above. Examples of carriers include signals, computer readable media, and the like.
[0207] Examples of signals may include electrical, optical, radio, acoustic or other forms of propagated signals, such as carrier waves, infrared signals, etc.
[0208] A machine-readable medium may be any tangible medium that contains or stores a program for or related to an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination thereof. More detailed examples of machine-readable storage media include an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical storage device, a magnetic storage device, or any suitable combination thereof.
[0209] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and modules described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0210] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the module is only a logical function division. There may be other division methods in actual implementation, such as multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or modules, or it can be an electrical, mechanical or other form of connection.
[0211] The modules described as separate components may or may not be physically separated, and the components displayed as modules may or may not be physical modules, that is, they may be located in one place or distributed on multiple network modules. Some or all of the modules may be selected according to actual needs to achieve the purpose of the embodiments of the present application.
[0212] In addition, each functional module in each embodiment of the present application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The above integrated modules can be implemented in the form of hardware or software functional modules.
[0213] If the integrated module is implemented in the form of a software function module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk and other media that can store program code.
[0214] In the present application, the terms "first", "second", etc. are used to distinguish between identical or similar items having substantially the same effects and functions. It should be understood that there is no logical or temporal dependency between "first", "second", and "nth", nor is there a limitation on quantity and execution order. It should also be understood that although the following description uses the terms first, second, etc. to describe various elements, these elements should not be limited by the terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of the various described examples, a first image may be referred to as a second image, and similarly, a second image may be referred to as a first image. Both the first image and the second image may be images, and in some cases, may be separate and different images.
[0215] It should also be understood that in the various embodiments of the present application, the size of the serial number of each process does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0216] The term "at least one" in this application means one or more, and the term "multiple" in this application means two or more, for example, multiple second messages means two or more second messages. The terms "system" and "network" are often used interchangeably herein.
[0217] It should be understood that the terms used in the description of the various examples herein are only for describing specific examples and are not intended to be limiting. As used in the description of the various examples and the appended claims, the singular forms "a", "an", and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise.
[0218] It should also be understood that the term "and / or" used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items. The term "and / or" is a description of the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this application generally indicates that the associated objects before and after are in an "or" relationship.
[0219] It should also be understood that the term “comprise” (also known as “includes,” “including,” “comprises” and / or “comprising”) when used in this specification specifies the presence of stated features, integers, steps, operations, elements, and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0220] It should also be understood that the terms "if" and "if" may be interpreted to mean "when" or "upon" or "in response to determining" or "in response to detecting." Similarly, the phrases "if it is determined that ..." or "if [a stated condition or event] is detected" may be interpreted to mean "upon determining that ..." or "in response to determining that ..." or "upon detecting [a stated condition or event]" or "in response to detecting [a stated condition or event]," depending on the context.
[0221] It should be understood that determining B based on A does not mean determining B only based on A. B can also be determined based on A and / or other information.
[0222] It should also be understood that the references to "one embodiment", "an embodiment", or "a possible implementation" throughout the specification mean that specific features, structures, or characteristics related to the embodiment or implementation are included in at least one embodiment of the present application. Therefore, the references to "in one embodiment" or "in an embodiment", or "a possible implementation" throughout the specification do not necessarily refer to the same embodiment. In addition, these specific features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
Claims
1. A data processing method, characterized in that: The method is applied to a first device, and the method includes: Sending a request for access to multimedia data; In the case where the access right to the multimedia data is obtained based on the access request, obtaining ciphertext data corresponding to the multimedia data, the ciphertext data being obtained by encrypting or signing the multimedia data according to identity information, the identity information being determined based on information used for authentication between a second device corresponding to a target object and a data acquisition device for the multimedia data, the target object being an object using the data acquisition device; The ciphertext data is decrypted to obtain the multimedia data.
2. The method according to claim 1, characterized in that The obtaining of ciphertext data corresponding to the multimedia data includes: The encrypted data returned based on the access request is received.
3. The method according to claim 1, characterized in that The obtaining of ciphertext data corresponding to the multimedia data includes: receiving a first authorization flag returned based on the access request, wherein the first authorization flag indicates that access to the multimedia data is allowed; The ciphertext data is obtained according to the first authorization flag.
4. The method according to any one of claims 1 to 3, characterized in that: Before decrypting the ciphertext data, the method further comprises: receiving re-encrypted data returned based on the access request, the re-encrypted data being obtained by encrypting a reference ciphertext according to a second authorization flag, the second authorization flag being generated according to a first public key, the first public key being a public key owned by a first device requesting the multimedia data, and the reference ciphertext being a ciphertext obtained by encrypting the key of the ciphertext data; The decrypting the ciphertext data to obtain the multimedia data includes: The key of the ciphertext data is obtained according to the decryption result of the re-encrypted data, and the ciphertext data is decrypted according to the key to obtain the multimedia data.
5. The method according to any one of claims 1 to 3, characterized in that: Before decrypting the ciphertext data, the method further comprises: Send the first public key; receiving a first ciphertext obtained by encrypting a key according to the first public key, where the key is a key used to encrypt the multimedia data; The decrypting the ciphertext data to obtain the multimedia data includes: Decrypting the first ciphertext according to a first private key corresponding to the first public key to obtain the key; The ciphertext data is decrypted according to the key to obtain the multimedia data.
6. The method according to any one of claims 1 to 5, characterized in that: The access request is used to obtain device information of the first device requesting the multimedia data, and the device information of the first device is used to determine whether to grant the first device permission to obtain the multimedia data based on at least one device information, and the at least one device information is information of at least one device that has signed a data protocol, and the data protocol is used to obtain access rights to the multimedia data.
7. The method according to any one of claims 1 to 6, characterized in that: The sending of the access request to the multimedia data comprises: The access request is sent to a third device, the third device is connected to a second device corresponding to the target object, and the third device is used to send the access request to the second device.
8. The method according to any one of claims 1 to 7, characterized in that: The identity information is used by the data acquisition device and the second device to negotiate to obtain a first key, and the ciphertext data is obtained by encrypting the multimedia data according to the first key.
9. The method according to any one of claims 1 to 7, characterized in that: The identity information is used to sign the ciphertext data corresponding to the multimedia data. The signature data obtained by the signature is used by the second device to verify whether the ciphertext data sent by the data acquisition device is abnormal. The second device is used to provide the ciphertext data to the first device.
10. The method according to any one of claims 1 to 9, characterized in that: The identity information includes first identity information for identifying the data acquisition device and second identity information for identifying the second device.
11. A data processing method, characterized in that: The method is applied to a data acquisition device, and the method comprises: Acquiring multimedia data collected by a data collection device; The multimedia data is encrypted or signed based on the identity information to obtain a data processing result corresponding to the multimedia data, the identity information is determined based on the information used for authentication between the second device corresponding to the target object and the data acquisition device, the target object is the object using the data acquisition device, and the data processing result is used for authorized devices to access the multimedia data.
12. The method according to claim 11, characterized in that The identity information includes first identity information for identifying the data acquisition device and second identity information for identifying the second device. Before encrypting or signing the multimedia data based on the identity information and obtaining the data processing result corresponding to the multimedia data, the method further includes: Encrypting the first identity information to obtain a first security ciphertext, and sending the first security ciphertext to the second device; In a case where transmission security is verified based on the first security ciphertext, receiving a second security ciphertext returned by the second device, where the second security ciphertext is encrypted based on the second identity information; Decrypt the second security ciphertext, and verify whether the transmission channel between the data acquisition device and the second device is secure based on the decryption result.
13. The method according to claim 11 or 12, characterized in that: The encrypting or signing the multimedia data based on the identity information to obtain a data processing result corresponding to the multimedia data includes: Acquire a first key, where the first key is obtained through negotiation with the second device based on the identity information; The multimedia data is encrypted according to the first key to obtain ciphertext data, and the ciphertext data is used as the data processing result.
14. The method according to claim 13, characterized in that The obtaining of the first key comprises: Calculate and obtain a second public key and a second private key of the data acquisition device based on the identity information; The first key is obtained through negotiation according to the second public key, the second private key and the identity information.
15. The method according to claim 11 or 12, characterized in that: The encrypting or signing the multimedia data based on the identity information to obtain a data processing result corresponding to the multimedia data includes: Acquire a second key of the data acquisition device, where the second key has not been authenticated by a second device corresponding to the target object; Encrypting the multimedia data according to the second key to obtain ciphertext data corresponding to the multimedia data; The ciphertext data is signed according to the identity information to obtain signature data corresponding to the ciphertext data, and the data processing result is obtained according to the signature data and the ciphertext data. The signature data is used to verify whether the ciphertext data is abnormal.
16. The method according to claim 15, characterized in that The step of signing the ciphertext data according to the identity information to obtain signature data corresponding to the ciphertext data, and obtaining the data processing result according to the signature data and the ciphertext data includes: Obtaining a third public key of the second device, encrypting the second key according to the third public key, and obtaining a ciphertext parameter corresponding to the second key, wherein the ciphertext parameter is used to obtain a second key required for decrypting the ciphertext data; The ciphertext data and the ciphertext parameters are signed according to the identity information to obtain signature data corresponding to the ciphertext data and the ciphertext parameters, and the data processing result is obtained according to the ciphertext data, the ciphertext parameters and the signature data.
17. The method according to any one of claims 11 to 16, characterized in that: After obtaining the data processing result corresponding to the multimedia data, the method further includes: The data processing result is sent to a second device corresponding to the target object, and the data processing result is used by the second device to obtain multimedia data.
18. The method according to any one of claims 11 to 17, characterized in that: The data acquisition device is connected to a second device corresponding to the target object via a third device; the data acquisition device is authenticated with the second device via the third device.
19. A data processing device, characterized in that: The device comprises: A transceiver module, used to perform operations related to receiving and / or sending in any of the methods described in claims 1-10; A processing module, used to perform other operations other than the operations related to receiving and / or sending in any one of the methods described in claims 1-10.
20. A data processing device, characterized in that: The device comprises: A transceiver module, used to perform operations related to receiving and / or sending in any of the methods described in claims 11-18; A processing module, used to perform other operations other than the operations related to receiving and / or sending in any one of the methods described in claims 11-18.
21. A data processing device, characterized in that: The device includes a processor, which is used to load and execute at least one instruction so that the data processing device implements the data processing method as described in any one of claims 1-10, or implements the data processing method as described in any one of claims 11-18.
22. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores at least one instruction, and the instruction is loaded and executed by the processor to implement the data processing method as described in any one of claims 1-10, or to implement the data processing method as described in any one of claims 11-18.
23. A chip, characterized in that: The chip includes a processor, which is used to run program instructions or codes, so that a device containing the chip executes the data processing method as described in any one of claims 1-10, or executes the data processing method as described in any one of claims 11-18.