Code stream signature and authentication method
By independently calculating the summary data for each data unit and transmitting it to the authentication end, the problems of authentication complexity and unit independent authentication in the tree-type signature of audio and video content in the prior art are solved, and efficient code stream signature and authentication methods are realized.
Patent Information
- Application Number
- CN202311614706.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-28
- Publication Date
- 2025-05-30
AI Technical Summary
In the prior art, in the process of tree signature of audio and video content, if a single network abstraction layer (NAL) unit errors or changes in transmission sequence, it leads to authentication failure and cannot be individually authenticated, resulting in high authentication complexity.
Using a code stream signature and authentication method, the independent authentication of each data unit is realized by independently calculating the summary data for each data unit and transmitting these summary data to the authentication end.
In the case of some data units being lost, other data units can still be authenticated, which simplifies the authentication process, reduces the code rate overhead, and supports independent authentication of SVAC encodings at different levels.
Smart Images

Figure CN120074825A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of media, and in particular to a method for signing and authenticating a bitstream. Background Art
[0002] In many audio and video encoding and decoding scenarios (such as monitoring, live broadcast, video-on-demand, etc.), there are certain requirements for the authenticity and integrity of audio and video content; therefore, in order to ensure the security of audio and video content during transmission and prevent the audio and video content from being tampered with during transmission, it is necessary to sign the audio and video content.
[0003] However, the current technology for tree-shaped signature of audio and video content has some defects: for example, if a single Network Abstract Layer (NAL) unit is incorrect, or the order of NAL units changes during transmission, it will cause the authentication of multiple NAL units participating in the authentication to fail. Another example is that each NAL unit or NAL unit sequence cannot be authenticated independently. Another example is that if there are multiple NAL unit sequences that need to be decoded independently, or support frame extraction scenarios, or the base layer and enhancement layer NAL unit sequences in GB / T 25724-2017, multiple independent authentication sequences are required, which will make the authentication very complex and difficult to implement using the existing technology. Summary of the Invention
[0004] In view of this, the present application provides a method for signing and authenticating a bitstream.
[0005] In a first aspect, an embodiment of the present application provides a method for signing a bitstream. The method includes: first, obtaining authentication data; where the authentication data includes: signature data and digest data of each data unit in a group of data units of the bitstream, and the signature data is obtained by signing the digest data of each data unit in the group of data units; then, adding the authentication data to the bitstream.
[0006] That is to say, in the present application, a digest is independently calculated for each data unit, and the digest data of each data unit is transmitted to the authentication end; in this way, the authentication end can authenticate each data unit independently; therefore, even in the case of partial loss (frame loss) of some data units, other data units can still be authenticated.
[0007] For the temporal scalable video coding (SVC) of the Surveillance Video and Audio Coding (SVAC) standard, each data unit uses the temporal_id to identify its temporal layer. During decoding, some temporal layers or data units may not participate in decoding. In this application, since each data unit independently generates the digest data, during authentication, for the data units participating in authentication, the corresponding digest data can be searched in the authentication data, and the data units not participating in authentication do not affect the authentication of other data units.
[0008] For the spatial SVC of the SVAC standard, each data unit uses the layer_id to identify its spatial layer. During decoding, some spatial layers or data units may not participate in decoding. In this application, since each data unit independently generates the digest data, during authentication, for the data units participating in authentication, the corresponding digest data can be searched in the authentication data, and the data units not participating in authentication do not affect the authentication of other data units.
[0009] For the video quality SVC of the SVAC standard, during decoding, some quality layers or data units may not participate in decoding. In this application, since each data unit independently generates the digest data, during authentication, for the data units participating in authentication, the corresponding digest data can be searched in the authentication data, and the data units not participating in authentication do not affect the authentication of other data units.
[0010] In addition, for SVC coding, only the authentication data of a group of data units needs to be transmitted to support the authentication of the sub-bitstream extracted from the bitstream.
[0011] That is to say, this application can also effectively solve the problem that the current SVAC coding, including temporal SVC coding, spatial SVC coding, and video quality SVC coding, requires independent authentication.
[0012] Data unit
[0013] The basic syntax structure of the coded bitstream can be a NAL unit or an access unit.
[0014] NAL unit
[0015] A syntax structure that includes a type indication of subsequent data and the number of bytes contained (located in the NAL header), and the data appears in the form of a Raw Byte Sequence Payload (RBSP), which may also include scattered anti-counterfeiting bytes when necessary.
[0016] access unit
[0017] A group of NAL units that are correlated with each other according to specified rules and are consecutive in decoding order.
[0018] It should be noted that, from another dimension, the data unit can also include a coded image.
[0019] coded picture
[0020] The coded representation of a frame of an image.
[0021] It should be noted that the present application does not group the data units. Instead, for the convenience of description, the term "a group of data units" is used to describe them.
[0022] Exemplarily, a group of data units can include n data units, and these n data units are all data units that need to be authenticated, where n is a positive integer. Correspondingly, the authentication data can include n digest data, and the n digest data correspond to the n data units one by one. Exemplarily, "a group of data units" can also be described as "n data units".
[0023] Exemplarily, multiple digest data of a group of data units can form a digest data list; that is to say, the authentication data can include a digest data list.
[0024] Exemplarily, the authentication data can be Auth.
[0025] Exemplarily, the signature data can be signature.
[0026] Exemplarily, the digest data can also be referred to as authentication digest data.
[0027] Exemplarily, the bitstream can be an audio compression bitstream (or referred to as an audio compression bit stream) or a video compression bitstream (or referred to as a video compression bit stream), and the present application does not limit this. The present application takes the signature and authentication of a video compression bitstream as an example for illustration.
[0028] bitstream
[0029] The binary data stream formed by coded images / audio frames.
[0030] According to the first aspect, the method further includes: calculating each data unit in a set of data units according to a digest algorithm to obtain the digest data of each data unit in the set of data units. In this way, the digest data of each data unit can be quickly determined.
[0031] For example, calculate data unit 1 in a set of data units according to the digest algorithm to obtain the digest data of data unit 1; calculate data unit 2 in a set of data units according to the digest algorithm to obtain the digest data of data unit 2;... and so on.
[0032] Exemplarily, each data unit in a set of data units can be calculated by a hash algorithm (Hash) according to the digest algorithm to obtain the digest data of each data unit in the set of data units.
[0033] It should be understood that the type of the digest algorithm in this application is not limited.
[0034] Exemplarily, the digest data can also be referred to as authentication digest data (such as authentication_hash).
[0035] According to the first aspect, or any implementation manner of the above first aspect, the method further includes: concatenating the digest data of each data unit in a set of data units to determine the digest data of the concatenated digest data; signing the digest data of the concatenated digest data with a private key to obtain signature data. In this way, the signature data can be quickly determined.
[0036] Exemplarily, the concatenation can be splicing. For example, the digest data of n data units are respectively: H1, H2, H3, H4, H5,..., Hn; then the concatenated digest data is H1 + H2 + H3 + H4 + H5 +... + Hn. Calculate the hash of the concatenated digest data H1 + H2 + H3 + H4 + H5 +... + Hn to obtain the digest data Hg of the concatenated digest data.
[0037] It should be understood that the top-level digest data can also be generated, and the top-level digest data is signed with a private key to obtain signature data. This application does not limit the way of signing according to the digest data of the data units.
[0038] Exemplarily, the private key can be PrivateKey.
[0039] According to the first aspect, or any implementation manner of the above first aspect, the method further includes: generating authentication data according to the signature data and the digest data of each data unit in a set of data units.
[0040] According to the first aspect, or any implementation manner of the above first aspect, adding authentication data to the bitstream includes: encoding the authentication data and adding the encoded authentication data to the bitstream. In this way, the bitrate overhead can be reduced.
[0041] Exemplarily, the authentication data can be encoded using Base64; then, the encoded authentication data is packed into the NAL unit of the authentication data in the bitstream.
[0042] According to the first aspect, or any implementation manner of the above first aspect, each data unit in a set of data units includes one or more Network Abstraction Layer (NAL) units.
[0043] According to the first aspect, or any implementation manner of the above first aspect, multiple NAL units in a set of data units are associated with each other according to a specified rule, and the decoding order of multiple NAL units in a set of data units is consecutive. That is to say, one data unit is one access unit.
[0044] According to the first aspect, or any implementation manner of the above first aspect, each data unit in a set of data units includes an encoded image.
[0045] According to the first aspect, or any implementation manner of the above first aspect, the bitstream further includes a first identifier, and the first identifier indicates the authentication mode adopted by a set of data units.
[0046] For example, the first identifier can be authenticate_mode.
[0047] If authenticate_mode is 0, it indicates that each data unit independently performs digest data authentication;
[0048] If authenticate_mode is 1, it indicates the tree-shaped digest data authentication.
[0049] According to the first aspect, or any implementation manner of the above first aspect, the bitstream further includes a security parameter set, and the security parameter set includes the first identifier.
[0050] Exemplarily, compared with the prior art, the security parameter set of the present application further adds: authenticate_mode (which can be called the first identifier).
[0051] In a possible way, the security parameter set in the bitstream is represented in the form of RBSP. Therefore, the bitstream further includes a security parameter set, and the security parameter set includes the first identifier, which can be written as the bitstream further includes a security parameter set RBSP, and the security parameter set RBSP includes the first identifier.
[0052] According to the first aspect, or any implementation manner of the above first aspect, the bitstream further includes a NAL unit of authentication data, and the NAL unit of authentication data includes a second identifier; wherein, the second identifier indicates the temporal level, and the value of the second identifier is 0.
[0053] Since in the temporal SVC coding scenario of the SVAC standard, the temporal base layer (i.e., the data unit with the second identifier being 0) needs to be parsed, in order to ensure that during the authentication process, whether or not the temporal enhancement layer is parsed, the authentication data can be obtained; the value of the second identifier in the NAL unit of the authentication data can be set to 0.
[0054] In a possible manner, the authentication data in the bitstream is represented in the form of RBSP. Therefore, the bitstream further includes a NAL unit of authentication data, and the NAL unit of authentication data includes a second identifier, which can be written as the bitstream further includes an authentication unit of authentication data RBSP, and the NAL unit of authentication data RBSP includes a second identifier.
[0055] Exemplarily, the second identifier can be temporal_id.
[0056] Exemplarily, compared with the prior art, the authentication data newly adds authentication_hash (digest data).
[0057] According to the first aspect, or any implementation manner of the above first aspect, the bitstream further includes a NAL unit of authentication data, and the NAL unit of authentication data includes a third identifier; wherein, the third identifier indicates the spatial level or the quality coding level, and the value of the third identifier is 0.
[0058] Since in the spatial SVC coding or quality SVC coding scenario of the SVAC standard, the spatial base layer / quality coding base layer (i.e., the data unit with the third identifier being 0) needs to be parsed, in order to ensure that during the authentication process, whether or not the spatial enhancement layer / quality coding enhancement layer is parsed, the authentication data can be obtained; the value of the third identifier in the NAL unit of the authentication data can be set to 0.
[0059] Exemplarily, the third identifier can be layer_id.
[0060] It should be noted that the authentication data in the first aspect and any implementation manner of the first aspect may further include the public key corresponding to the private key. Exemplarily, the public key is Public Key. The public key can be used to verify the signature data. It should be understood that the public key corresponding to the above private key can also be transmitted in other ways, such as being built into the authentication end, being transmitted to the authentication end in the authentication certificate, etc., and the present application does not limit this.
[0061] It should be noted that the first aspect and any implementation manner of the first aspect can be executed by the encoder in the signature end, or by the signature module in the signature end, or by the encoder and the authentication module in the signature end in cooperation. This application does not limit this.
[0062] According to the first aspect, or any implementation manner of the above first aspect, the authentication data further includes: a fourth identifier, and the fourth identifier is used to identify a data unit.
[0063] Exemplarily, the fourth identifier may be decode_order_index.
[0064] Exemplarily, the authentication data may include multiple fourth identifiers, and the multiple fourth identifiers correspond to multiple data units one by one.
[0065] Exemplarily, compared with the prior art, the authentication data newly adds decode_order_index.
[0066] According to the first aspect, or any implementation manner of the above first aspect, the bitstream further includes: a fifth identifier; the method further includes:
[0067] Determine the value n according to the fifth identifier; where a group of data units includes n data units, and n is a positive integer;
[0068] Calculate each data unit in the n data units according to the digest algorithm to obtain the digest data of each data unit in the n data units.
[0069] Exemplarily, the fifth identifier may be successive_hash_pictures_minus1.
[0070] In a second aspect, an embodiment of the present application provides a bitstream, and the bitstream includes: a group of data units and authentication data; where the authentication data includes: signature data and the digest data of each data unit in a group of data units, and the signature data is obtained by signing the digest data of each data unit in a group of data units.
[0071] According to the second aspect, each data unit in a group of data units includes one or more network abstraction layer NAL units.
[0072] According to the second aspect, or any implementation manner of the above second aspect, multiple NAL units in a group of data units are associated with each other according to a specified rule, and the decoding order of multiple NAL units in a group of data units is continuous. That is to say, one data unit is one access unit
[0073] According to a second aspect, or any implementation manner of the above second aspect, each data unit in a set of data units includes an encoded image.
[0074] According to a second aspect, or any implementation manner of the above second aspect, the bitstream further includes a first identifier, and the first identifier indicates an authentication mode adopted by a set of data units.
[0075] According to a second aspect, or any implementation manner of the above second aspect, the bitstream further includes a security parameter set, and the security parameter set includes the first identifier.
[0076] According to a second aspect, or any implementation manner of the above second aspect, the bitstream further includes a NAL unit of authentication data, and the NAL unit of authentication data includes a second identifier; wherein, the second identifier indicates a temporal level, and the value of the second identifier is 0.
[0077] According to a second aspect, or any implementation manner of the above second aspect, the bitstream further includes a NAL unit of authentication data, and the NAL unit of authentication data includes a third identifier; wherein, the third identifier indicates a spatial level or a quality coding level, and the value of the third identifier is 0.
[0078] According to a second aspect, or any implementation manner of the above second aspect, the authentication data further includes: a fourth identifier, and the fourth identifier is used to identify a data unit.
[0079] According to a second aspect, or any implementation manner of the above second aspect, the bitstream further includes: a fifth identifier, and the fifth identifier is used to determine the number n of data units included in a set of data units.
[0080] According to a second aspect, or any implementation manner of the above second aspect, the bitstream further includes a NAL unit of authentication data, and the NAL unit of authentication data further includes a sixth identifier, and the sixth identifier is used to determine the number of digest data included in the authentication data.
[0081] The second aspect and any implementation manner of the second aspect respectively correspond to the first aspect and any implementation manner of the first aspect. For the technical effects corresponding to the second aspect and any implementation manner of the second aspect, reference may be made to the technical effects corresponding to the first aspect and any implementation manner of the first aspect above, which will not be elaborated herein.
[0082] In a third aspect, an embodiment of the present application provides a method for authenticating a bitstream. The method includes: First, determining first digest data for each data unit in a set of data units of the bitstream; Next, obtaining authentication data from the bitstream, where the authentication data includes: signature data and second digest data for each data unit in the set of data units, and the signature data is obtained by signing the second digest data for each data unit in the set of data units; After that, when the signature data is successfully verified, verifying the first digest data of the multiple data units in the set of data units according to the multiple second digest data in the authentication data.
[0083] It should be noted that the first digest data and the second digest data are used to distinguish the digest data calculated by the authentication end and the digest data in the authentication data.
[0084] According to the third aspect, determining first digest data for each data unit in a set of data units includes: calculating, according to a digest algorithm, each data unit in the set of data units to obtain first digest data for each data unit in the set of data units.
[0085] According to the third aspect, or any one of the above implementation manners of the third aspect, the method further includes: obtaining a public key; concatenating the second digest data for each data unit in the set of data units, and determining digest data of the concatenated second digest data; verifying the signature data according to the public key, the digest data of the concatenated second digest data, and a signature algorithm.
[0086] According to the third aspect, or any one of the above implementation manners of the third aspect, the method further includes: obtaining a first identifier from the bitstream, where the first identifier indicates an authentication mode adopted by a set of data units; when the value of the first identifier is a first preset value, performing the step of determining first digest data for each data unit in the set of data units of the bitstream.
[0087] According to the third aspect, or any one of the above implementation manners of the third aspect, the method further includes: obtaining a sixth identifier from the bitstream, and determining a value n according to the sixth identifier; where a set of data units includes n data units, and n is a positive integer; obtaining second digest data for each of the n data units from the bitstream.
[0088] According to the third aspect, or any one of the above implementation manners of the third aspect, the method further includes: obtaining a fifth identifier from the bitstream, and determining a value n according to the fifth identifier; where a set of data units includes n data units, and n is a positive integer; determining first digest data for each data unit in a set of data units of the bitstream includes: calculating, according to a digest algorithm, each of the n data units to obtain digest data for each of the n data units.
[0089] According to a third aspect, or any implementation manner of the above third aspect, the authentication data further includes a plurality of fourth identifiers, and the plurality of fourth identifiers correspond to the plurality of second digest data one by one. The method further includes: obtaining a seventh identifier corresponding to each data unit in a group of data units from the bitstream; verifying a plurality of first digest data of the group of data units according to the plurality of second digest data in the authentication data, including: for a first data unit in the group of data units: searching for a fourth identifier identical to the seventh identifier of the first data unit from the plurality of fourth identifiers included in the authentication data; if there is a fourth identifier identical to the seventh identifier of the first data unit, comparing the first digest of the first data unit with the second digest corresponding to the fourth identifier identical to the seventh identifier of the first data unit; if the two are the same, determining that the authentication of the first data unit is successful; otherwise, determining that the authentication of the first data unit fails.
[0090] Exemplarily, the seventh identifier may be obtained from an image header RBSP, and the seventh identifier may be decode_order_index.
[0091] According to a third aspect, or any implementation manner of the above third aspect, verifying a plurality of first digest data of a group of data units according to the plurality of second digest data in the authentication data includes: for a second data unit in the group of data units: searching for a second digest identical to the first digest of the second data unit from the plurality of second digests included in the authentication data; if there is a second digest identical to the first digest of the second data unit, determining that the authentication of the second data unit is successful; otherwise, determining that the authentication of the second data unit fails.
[0092] According to a third aspect, or any implementation manner of the above third aspect, each data unit in a group of data units includes one or more network abstraction layer (NAL) units.
[0093] According to a third aspect, or any implementation manner of the above third aspect, the plurality of NAL units in a group of data units are associated with each other according to a specified rule, and the decoding order of the plurality of NAL units in a group of data units is continuous.
[0094] According to a third aspect, or any implementation manner of the above third aspect, each data unit in a group of data units includes an encoded image.
[0095] It should be noted that the third aspect and any implementation manner of the third aspect may be executed by a decoder in the authentication end, or by an authentication module in the authentication end, or by the decoder and the authentication module in the authentication end in cooperation. This application does not make any restrictions on this.
[0096] The third aspect and any implementation manner of the third aspect respectively correspond to the first aspect and any implementation manner of the first aspect. For the technical effects corresponding to the third aspect and any implementation manner of the third aspect, reference may be made to the technical effects corresponding to the first aspect and any implementation manner of the first aspect above, which will not be elaborated herein.
[0097] Fourth aspect, an embodiment of the present application provides a signature device for a bitstream, the device includes:
[0098] A first authentication data acquisition module, configured to acquire authentication data; wherein, the authentication data includes: signature data and digest data of each data unit in a group of data units of the bitstream, and the signature data is obtained by signing the digest data of each data unit in the group of data units;
[0099] An addition module, configured to add the authentication data to the bitstream.
[0100] Exemplarily, the above signature device for a bitstream can be used to execute the signature method in the first aspect or any possible implementation manner of the first aspect.
[0101] The fourth aspect and any implementation manner of the fourth aspect respectively correspond to the first aspect and any implementation manner of the first aspect. For the technical effects corresponding to the fourth aspect and any implementation manner of the fourth aspect, reference may be made to the technical effects corresponding to the first aspect and any implementation manner of the first aspect above, which will not be elaborated herein.
[0102] Fifth aspect, an embodiment of the present application provides an authentication device for a bitstream, the device includes:
[0103] A digest data determination module, configured to determine first digest data of each data unit in a group of data units of the bitstream;
[0104] A second authentication data acquisition module, configured to acquire authentication data from the bitstream, the authentication data includes: signature data and second digest data of each data unit in a group of data units, and the signature data is obtained by signing the second digest data of each data unit in the group of data units;
[0105] A verification module, configured to, when the verification of the signature data is successful, verify the multiple first digest data of a group of data units according to the multiple second digest data in the authentication data.
[0106] Exemplarily, the above authentication device for a bitstream can be used to execute the authentication method in the third aspect or any possible implementation manner of the third aspect.
[0107] The fifth aspect and any implementation of the fifth aspect respectively correspond to the third aspect and any implementation of the third aspect. For the technical effects corresponding to the fifth aspect and any implementation of the fifth aspect, reference may be made to the technical effects corresponding to the third aspect and any implementation of the third aspect as described above, which will not be elaborated herein.
[0108] In a sixth aspect, an embodiment of the present application provides an electronic device, including: a memory and a processor, the memory being coupled to the processor; the memory stores program instructions, and when the program instructions are executed by the processor, the electronic device is caused to execute the signature method of the bitstream in the first aspect or any possible implementation of the first aspect.
[0109] The sixth aspect and any implementation of the sixth aspect respectively correspond to the first aspect and any implementation of the first aspect. For the technical effects corresponding to the sixth aspect and any implementation of the sixth aspect, reference may be made to the technical effects corresponding to the first aspect and any implementation of the first aspect as described above, which will not be elaborated herein.
[0110] In a seventh aspect, an embodiment of the present application provides an electronic device, including: a memory and a processor, the memory being coupled to the processor; the memory stores program instructions, and when the program instructions are executed by the processor, the electronic device is caused to execute the authentication method of the bitstream in the third aspect or any possible implementation of the third aspect.
[0111] The seventh aspect and any implementation of the seventh aspect respectively correspond to the third aspect and any implementation of the third aspect. For the technical effects corresponding to the seventh aspect and any implementation of the seventh aspect, reference may be made to the technical effects corresponding to the third aspect and any implementation of the third aspect as described above, which will not be elaborated herein.
[0112] In an eighth aspect, an embodiment of the present application provides a chip, including one or more interface circuits and one or more processors; the one or more processors receive or send data through the one or more interface circuits, and when the one or more processors execute computer instructions, the steps of the signature method of the bitstream in the first aspect or any possible implementation of the first aspect are caused to be executed.
[0113] The eighth aspect and any implementation of the eighth aspect respectively correspond to the first aspect and any implementation of the first aspect. For the technical effects corresponding to the eighth aspect and any implementation of the eighth aspect, reference may be made to the technical effects corresponding to the first aspect and any implementation of the first aspect as described above, which will not be elaborated herein.
[0114] In a ninth aspect, an embodiment of the present application provides a chip, including one or more interface circuits and one or more processors; the one or more processors receive or send data through the one or more interface circuits, and when the one or more processors execute computer instructions, the steps of the code stream authentication method in the third aspect or any possible implementation manner of the third aspect are executed.
[0115] The ninth aspect and any implementation manner of the ninth aspect respectively correspond to the third aspect and any implementation manner of the third aspect. For the technical effects corresponding to the ninth aspect and any implementation manner of the ninth aspect, reference may be made to the technical effects corresponding to the third aspect and any implementation manner of the third aspect above, which will not be elaborated here.
[0116] In a tenth aspect, an embodiment of the present application provides a computer-readable storage medium storing a computer program, and when the computer program runs on a computer or a processor, the computer or the processor is caused to execute the code stream signature method in the first aspect or any possible implementation manner of the first aspect.
[0117] The tenth aspect and any implementation manner of the tenth aspect respectively correspond to the first aspect and any implementation manner of the first aspect. For the technical effects corresponding to the tenth aspect and any implementation manner of the tenth aspect, reference may be made to the technical effects corresponding to the first aspect and any implementation manner of the first aspect above, which will not be elaborated here.
[0118] In an eleventh aspect, an embodiment of the present application provides a computer-readable storage medium storing a computer program, and when the computer program runs on a computer or a processor, the computer or the processor is caused to execute the code stream authentication method in the third aspect or any possible implementation manner of the third aspect.
[0119] The eleventh aspect and any implementation manner of the eleventh aspect respectively correspond to the third aspect and any implementation manner of the third aspect. For the technical effects corresponding to the eleventh aspect and any implementation manner of the eleventh aspect, reference may be made to the technical effects corresponding to the third aspect and any implementation manner of the third aspect above, which will not be elaborated here.
[0120] In a twelfth aspect, an embodiment of the present application provides a computer program product including computer instructions, and when the computer instructions are executed by a computer or a processor, the computer or the processor is caused to execute the code stream signature method in the first aspect or any possible implementation manner of the first aspect.
[0121] The twelfth aspect and any implementation manner of the twelfth aspect respectively correspond to the first aspect and any implementation manner of the first aspect. For the technical effects corresponding to the twelfth aspect and any implementation manner of the twelfth aspect, reference may be made to the technical effects corresponding to the first aspect and any implementation manner of the first aspect as described above, which will not be elaborated herein.
[0122] In a thirteenth aspect, an embodiment of the present application provides a computer program product, which includes computer instructions. When the computer instructions are executed by a computer or a processor, the computer or the processor is caused to execute the method for authenticating a bitstream in the third aspect or any possible implementation manner of the third aspect.
[0123] The thirteenth aspect and any implementation manner of the thirteenth aspect respectively correspond to the third aspect and any implementation manner of the third aspect. For the technical effects corresponding to the thirteenth aspect and any implementation manner of the thirteenth aspect, reference may be made to the technical effects corresponding to the third aspect and any implementation manner of the third aspect as described above, which will not be elaborated herein.
[0124] In a fourteenth aspect, an embodiment of the present application provides a computer-readable storage medium, which stores a bitstream in the second aspect or any possible implementation manner of the second aspect.
[0125] The fourteenth aspect and any implementation manner of the fourteenth aspect respectively correspond to the second aspect and any implementation manner of the second aspect. For the technical effects corresponding to the fourteenth aspect and any implementation manner of the fourteenth aspect, reference may be made to the technical effects corresponding to the second aspect and any implementation manner of the second aspect as described above, which will not be elaborated herein.
[0126] In a fifteenth aspect, an embodiment of the present application provides a device for storing a bitstream, which includes: a receiver and at least one storage medium. The receiver is configured to receive a bitstream in the second aspect or any possible implementation manner of the second aspect; and the at least one storage medium is configured to store the bitstream.
[0127] The fifteenth aspect and any implementation manner of the fifteenth aspect respectively correspond to the second aspect and any implementation manner of the second aspect. For the technical effects corresponding to the fifteenth aspect and any implementation manner of the fifteenth aspect, reference may be made to the technical effects corresponding to the second aspect and any implementation manner of the second aspect as described above, which will not be elaborated herein.
[0128] In a sixteenth aspect, an embodiment of the present application provides an apparatus for transmitting a bitstream. The apparatus includes: a transmitter and at least one storage medium. The at least one storage medium is configured to store the bitstream in the second aspect or any possible implementation manner of the second aspect. The transmitter is configured to obtain the bitstream from the storage medium and send the bitstream to a terminal device through a transmission medium.
[0129] The sixteenth aspect and any implementation manner of the sixteenth aspect respectively correspond to the second aspect and any implementation manner of the second aspect. For the technical effects corresponding to the sixteenth aspect and any implementation manner of the sixteenth aspect, reference may be made to the technical effects corresponding to the second aspect and any implementation manner of the second aspect above, which will not be elaborated here.
[0130] In a seventeenth aspect, an embodiment of the present application provides a system for distributing a bitstream. The system includes: at least one storage medium configured to store the bitstream in at least one of the second aspect or any possible implementation manner of the second aspect, and a streaming media device configured to obtain a target bitstream from the at least one storage medium and send the target bitstream to a terminal device, where the streaming media device includes a content server or a content distribution server.
[0131] The seventeenth aspect and any implementation manner of the seventeenth aspect respectively correspond to the second aspect and any implementation manner of the second aspect. For the technical effects corresponding to the seventeenth aspect and any implementation manner of the seventeenth aspect, reference may be made to the technical effects corresponding to the second aspect and any implementation manner of the second aspect above, which will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0132] Figure 1 A schematic diagram of an exemplary application scenario;
[0133] Figure 2 A schematic diagram of an exemplary authentication and signature system 200;
[0134] Figure 3 A schematic diagram of an exemplary signature process 300;
[0135] Figure 4 A schematic diagram of an exemplary authentication process 400;
[0136] Figure 5A A schematic diagram of an exemplary signature process 500;
[0137] Figure 5B A schematic diagram of an exemplary signature process;
[0138] Figure 6 A schematic diagram of an exemplary authentication process 600;
[0139] Figure 7 Schematic diagram of the signature device for the exemplary code stream;
[0140] Figure 8 Schematic diagram of the authentication device for the exemplary code stream;
[0141] Figure 9 Schematic diagram of the structure of the exemplary device. Detailed implementation manners
[0142] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without making creative efforts belong to the scope of protection of the present application.
[0143] The term "and / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone.
[0144] The terms "first" and "second" in the description and claims of the embodiments of the present application are used to distinguish different objects, rather than to describe the specific order of the objects. For example, the first target object and the second target object are used to distinguish different target objects, rather than to describe the specific order of the target objects.
[0145] In the embodiments of the present application, words such as "exemplary" or "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, using words such as "exemplary" or "for example" aims to present relevant concepts in a specific way.
[0146] In the description of the embodiments of the present application, unless otherwise specified, the meaning of "a plurality of" refers to two or more. For example, a plurality of processing units refers to two or more processing units; a plurality of systems refers to two or more systems.
[0147] Figure 1 The schematic diagram of the structure of the electronic device 100 is shown. It should be understood that Figure 1 The illustrated electronic device 100 is only an example of an electronic device, and the electronic device 100 may have more or fewer components than those shown in the figure, may combine two or more components, or may have different component configurations. Figure 1The various components shown in can be implemented in hardware, software, or a combination of hardware and software, including one or more signal processing and / or application specific integrated circuits.
[0148] Exemplarily, the signature and authentication method for the bitstream involved in this application can be applied to sign and authenticate any one of an audio compression bitstream (or referred to as an audio compression bitstream) or a video compression bitstream (or referred to as a video compression bitstream), and this application does not limit this. This application takes signing and authenticating a video compression bitstream as an example for illustration.
[0149] bitstream
[0150] The binary data stream formed by encoding image / audio frames.
[0151] Figure 1 It is a schematic diagram of an exemplary application scenario shown. Figure 1 It shows a monitoring scenario, a live broadcast scenario, and an on-demand scenario.
[0152] Refer to Figure 1 , exemplarily, in the monitoring scenario, the camera 11 can sign the monitoring video bitstream to obtain the signed monitoring video bitstream 101. Then, the signed monitoring video bitstream 101 is sent to the laptop 13 through the network 12. After that, the laptop 13 can authenticate the signed monitoring video bitstream 101 to obtain the authentication result 105 and display it, and play the monitoring video 104.
[0153] Refer to Figure 1 , exemplarily, in the live broadcast scenario, the mobile phone 14 can sign the live broadcast video bitstream to obtain the signed live broadcast video bitstream 102. Then, the signed live broadcast video bitstream 102 is sent to the mobile phone 15 through the network 12. After that, the mobile phone 15 can authenticate the signed live broadcast video bitstream 102 to obtain the authentication result 107 and display it, and play the live broadcast video 106.
[0154] Refer to Figure 1 , exemplarily, in the on-demand scenario, the personal computer 16 can sign the on-demand video bitstream to obtain the signed on-demand video bitstream 103. Then, the signed on-demand video bitstream 103 is sent to the mobile phone 17 through the network 12. After that, the mobile phone 17 can authenticate the signed on-demand video bitstream 103 to obtain the authentication result 109 and display it, and play the on-demand video 108.
[0155] It should be understood that this application can also be used in other audio and video encoding and decoding scenarios, such as digital content trust scenarios, etc., and this application does not limit this.
[0156] Figure 2 Schematic diagram of the exemplary authentication and signature system 200. In Figure 2 the above Figure 1 the authentication and signature processes are described.
[0157] Referring to Figure 2 , exemplarily, the authentication and signature system 200 may include a signature end 210 and an authentication end 220.
[0158] For example, the signature end 210 may be the camera 11, the mobile phone 14, and the personal computer 16 in the above Figure 1 , and the authentication end 220 may be the laptop 13, the mobile phone 15, and the mobile phone 17 in the above Figure 1 .
[0159] It should be understood that the same terminal device may serve as both the signature end 210 and the authentication end 220, and this application does not limit this.
[0160] Continuing to refer to Figure 2 , exemplarily, after the signature end 210 obtains the video data 201, it may perform video encoding 21 on the video data 201 to obtain a bitstream 202; and perform video signature 22 on the bitstream 202 to obtain a signed bitstream 203.
[0161] For example, the video data 201 may be the surveillance video collected by the camera 11, the live video recorded by the mobile phone 14, or the on-demand video produced by the personal computer 16 in the above Figure 1 .
[0162] For example, the signed bitstream 203 may be the signed surveillance video bitstream 101, the signed live video bitstream 102, or the signed on-demand video bitstream 103 in the above Figure 1 .
[0163] It should be noted that the two operations of video encoding 21 and video signature 22 may be performed in parallel.
[0164] It should be noted that in one possible way, the signature end 210 may include an encoder, and the encoder performs video encoding 21 and video signature 22. In one possible way, the signature end 210 may include an encoder and a signature module, and the encoder performs video encoding 21 and the signature module performs video signature 22. In one possible way, the signature end 210 may include a signature module, and the signature module performs video encoding 21 and video signature 22.
[0165] After that, the signature end 210 may send the signed bitstream 203 to the authentication end 220.
[0166] Continuing to refer to Figure 2, Exemplarily, after the authentication end 220 receives the signed bitstream 203, it can perform video authentication 23 on the signed bitstream 203 to obtain an authentication result 205; and can perform video decoding 24 on the bitstream 202 in the signed bitstream 203 to obtain the decoded video data 204.
[0167] For example, the decoded video data 204 can be the surveillance video 104, the live video 106, or the on-demand video 108 in the above Figure 1 .
[0168] For example, the authentication result 205 can be the authentication result 105, the authentication result 107, or the authentication result 109 in the above image 1.
[0169] It should be noted that the two operations of video authentication 23 and video decoding 24 can be executed in parallel.
[0170] It should be noted that in one possible way, the authentication end 220 can include a decoder, and the decoder performs video decoding 24 and video authentication 23. In one possible way, the authentication end 220 can include a decoder and an authentication module, the decoder performs video decoding 24, and the authentication module performs video authentication 23. In one possible way, the authentication end 220 can include an authentication module, and the authentication module performs video decoding 24 and video authentication 23.
[0171] It should be noted that when the signing end 210 performs lossless encoding, the video data is the same as the decoded video data; when the signing end 210 performs lossy encoding, there are differences between the video data and the decoded video data.
[0172] It should be noted that the encoder, decoder, and authentication module can be implemented by software or by hardware, and this application does not make any restrictions in this regard.
[0173] Figure 3 FIG. 300 is a schematic diagram of the exemplary signing process 300. Among them, the process 300 can be implemented by the signing end 210.
[0174] S301, obtain authentication data; among them, the authentication data includes: signature data and the digest data of each data unit in a group of data units, and the signature data is obtained by signing the digest data of each data unit in a group of data units.
[0175] Exemplarily, when authentication needs to be supported, the number n of data units to be authenticated can be determined. Wherein, n is a positive integer.
[0176] data unit
[0177] The basic syntax structure of the coded bitstream can be either a NAL unit or an access unit.
[0178] NAL unit
[0179] A syntax structure that contains a type indication of the subsequent data and the number of bytes included (located in the NAL header), and the data appears in the form of a Raw Byte Sequence Payload (RBSP), which may also include scattered anti-counterfeiting bytes when necessary.
[0180] Access unit
[0181] A group of NAL units that are correlated with each other according to specified rules and are consecutive in decoding order.
[0182] It should be noted that, from another dimension, the data unit can also include the coded picture.
[0183] Coded picture
[0184] The coded representation of a frame of image.
[0185] Refer to Figure 3 , exemplarily, the n data units that need to be authenticated in the bitstream are respectively: data unit 1, data unit 2,..., data unit n. These n data units that need to be authenticated can be called a group of data units. A group of data units involved subsequently all refer to the data units that need to be authenticated.
[0186] It should be noted that this application does not group the data units, but for the convenience of description, the term "a group of data units" is used.
[0187] Refer to Figure 3 , exemplarily, a digest data can be independently calculated for each data unit in a group of data units, and the digest data (which can also be called the authentication digest data) of each data unit in this group of data units can be obtained. The n digest data can include: digest data 1, digest data 2,..., digest data n; among them, the n digest data correspond to the n data units one by one; for example, digest data 1 corresponds to data unit 1, digest data 2 corresponds to data unit 2,..., digest data n corresponds to data unit n.
[0188] Exemplarily, a signature data (signature) can be obtained by signing according to the digest data of each data unit in a group of data units.
[0189] Exemplarily, authentication data (Auth) can be generated based on the signature data and the digest data of each data unit in a set of data units. In this way, the authentication data can be {digest data 1, digest data 2,..., digest data n, signature}.
[0190] Optionally, the digest data of each data unit in a set of data units in the authentication data can form a digest data list {digest data 1, digest data 2,..., digest data n}.
[0191] S302. Add the authentication data to the bitstream.
[0192] Exemplarily, after obtaining the authentication data, the authentication data can be added to the bitstream to obtain a signed bitstream, that is, the signed bitstream 203 in the above. Figure 2 The signed bitstream 203.
[0193] It should be noted that S301 to S302 can be executed by the encoder in the signing end 210, or by the signature module in the signing end 210, or by the encoder and the authentication module in the signing end 210 in cooperation (the encoder executes S302 and the authentication module executes S301), and the present application does not limit this.
[0194] Figure 4 It is a schematic diagram of the authentication process 400 shown exemplarily. Among them, the process 400 can be implemented by the authentication end 220, and the process 400 corresponds to the process 300.
[0195] S401. Determine the first digest data of each data unit in a set of data units.
[0196] Exemplarily, n data units to be authenticated (i.e., a set of data units to be authenticated) can be read from the bitstream. Then, a digest data is independently calculated for each data unit in this set of data units, and the digest data of each data unit in this set of data units can be obtained. To distinguish the digest data calculated in S401 from the digest data included in the authentication data, the digest data calculated in S401 can be called the first digest data, and the digest data included in the authentication data can be called the second digest data.
[0197] Refer to Figure 4 , exemplarily, the n first digest data are respectively: digest data 11, digest data 12,..., digest data 1n.
[0198] Exemplarily, the n first digest data correspond one-to-one with the n data units. For example, digest data 11 corresponds to data unit 1, digest data 12 corresponds to data unit 2,..., and digest data 1n corresponds to data unit n.
[0199] S402. Obtain authentication data from the bitstream. The authentication data includes: signature data and second digest data of each data unit in a set of data units. The signature data is obtained by signing the second digest data of each data unit in the set of data units.
[0200] Exemplarily, the bitstream can be parsed to read the authentication data from the bitstream. Among them, the authentication data includes: signature data and n pieces of second digest data (including digest data 21, digest data 22,..., digest data 2n).
[0201] Exemplarily, the n pieces of second digest data can form a digest data list {digest data 21, digest data 22,..., digest data 2n}.
[0202] Exemplarily, the n pieces of second digest data correspond one-to-one with the n data units. For example, digest data 21 corresponds to data unit 1, digest data 22 corresponds to data unit 2,..., and digest data 2n corresponds to data unit n.
[0203] S403. When the signature data is successfully verified, verify the multiple first digest data of a set of data units according to the multiple second digest data in the authentication data.
[0204] Exemplarily, the signature data can be verified. When the signature data is successfully verified, verify the multiple first digest data of a set of data units according to the multiple second digest data in the authentication data.
[0205] Specifically, for the first data unit in a set of data units obtained from the bitstream (the first data unit can be any data unit in the set of data units obtained from the bitstream), it is possible to check whether there is a second digest data in the multiple second digest data in the authentication data that is the same as the first digest data of the first data unit; when a second digest data that is the same as the first digest data of the first data unit is found in the multiple second digest data in the authentication data, it is determined that the authentication of the first data unit is successful, that is, the authentication result can be authentication success. Otherwise, it is determined that the authentication of the first data unit fails, that is, the authentication result can be authentication failure.
[0206] For example, in the implementation process, the digest data list {digest data 21, digest data 22,..., digest data 2n} can be made into a Map data structure, such as Map[digest data 21]=1, Map[digest data 22]=1,..., Map[digest data 2n]=1, to achieve fast lookup.
[0207] It should be noted that S401 to S403 can be executed by the decoder in the authentication end 220, or by the authentication module in the authentication end 220, or by the decoder and the authentication module in the authentication end 220 in cooperation (the authentication module executes S401 and S403, and the decoder block executes S402). This application does not limit this.
[0208] For the temporal SVC coding of the public security video surveillance digital video and audio coding (Surveillance Video and Audio Coding, SVAC) standard, each data unit uses temporal_id to identify its temporal level. During decoding, there may be some temporal levels or data units that do not participate in decoding; in this application, since each data unit independently generates digest data, therefore, during authentication, for the data units participating in authentication, the corresponding digest data can be searched in the authentication data, and the data units that do not participate in authentication do not affect the authentication of other data units.
[0209] For the spatial SVC coding of the SVAC standard, each data unit uses layer_id to identify its spatial level. During decoding, there may be some spatial levels or data units that do not participate in decoding; in this application, since each data unit independently generates digest data, therefore, during authentication, for the data units participating in authentication, the corresponding digest data can be searched in the authentication data, and the data units that do not participate in authentication do not affect the authentication of other data units.
[0210] For the video quality SVC coding of the SVAC standard, during decoding, there may be some quality levels or data units that do not participate in decoding. In this application, since each data unit independently generates digest data, therefore, during authentication, for the data units participating in authentication, the corresponding digest data can be searched in the authentication data, and the data units that do not participate in authentication do not affect the authentication of other data units.
[0211] In addition, for SVC coding, only a set of authentication data of data units needs to be transmitted to support the authentication of sub-bitstreams extracted from the bitstream.
[0212] In summary, this application can effectively solve the problem that the current SVAC coding temporal SVC coding, spatial SVC coding, and video quality SVC coding require independent authentication.
[0213] Secondly, since each data unit is independently authenticated, it is also possible to authenticate other data units in the case of loss (dropped frames) of some data units.
[0214] Figure 5ASchematic diagram of the exemplary signature process 500. Among them, the process 500 can be implemented by the signature end 210. The process 500 is a process in which the SVAC signature end realizes the signature of the data unit by indicating the end of the data unit authentication sequence through SuccessiveHashPictures.
[0215] S501, generate a security parameter set RBSP.
[0216] Exemplarily, when video image authentication needs to be supported, a security parameter set RBSP is generated; among them, the definition of the security parameter set RBSP can be as shown in Table 1 below:
[0217] Table 1 Definition of the security parameter set RBSP
[0218]
[0219]
[0220] Authentication mode authentication_mode
[0221] A 2-bit unsigned integer. Indicates the authentication mode used for authentication, which can be as shown in Table 2:
[0222] Table 2 Explanation of the authentication mode
[0223] Value of authentication_mode Description 0 Each data unit independently performs digest data authentication method 1 Tree-shaped digest data authentication method 2~3 Reserved
[0224] If authenticate_mode is 0, first concatenate the digest data of the image data (which can also be a data unit), calculate the digest data of the concatenated digest data, and then perform a digital signature on the calculated digest data.
[0225] Number of successive authenticated image frames successive_hash_pictures_minus1
[0226] An 8-bit unsigned integer. Represents the number of consecutive displayed images (or the number of data units) for digital signature in decoding order, and these consecutive displayed images (or the number of data units) are limited to within one random access image or RLI frame image interval. The value of successive_hash_pictures_minus1 should be 0 to 255.
[0227] SuccessiveHashPictures = successive_hash_pictures_minus1 + 1
[0228] If successive_hash_pictures_minus1 equals 0, digitally sign the digest data of each display image (or data unit) to be authenticated.
[0229] If successive_hash_pictures_minus1 is greater than 0 and authenticate_mode is 0, first concatenate the digest data of SuccessiveHashPictures image data (or data units), generate digest data for the concatenated digest data, and then digitally sign the generated digest data.
[0230] If successive_hash_pictures_minus1 is greater than 0 and authenticate_mode is 1, first generate tree digest data for the digest data of SuccessiveHashPictures consecutive display images (or data units) in decoding order, and then digitally sign the top digest data of the tree (i.e., the prior art signature method). Among them, the top digest data of n data units is the digest data generated according to the digest algorithm (such as the authentication method indicated by hash_type) after arranging the top digest data of the first n - 1 data units and the digest data of the nth data.
[0231] Hash type hash_type
[0232] A 2-bit unsigned integer. It indicates the algorithm used for authentication (i.e., the algorithm for determining the digest data of a data unit), and the specific correspondence is shown in Table 3:
[0233] Table 3 Correspondence between hash type and specific algorithm
[0234] Value of hash_type Authentication algorithm Digest data length (bytes) 0 SM3 32 1~3 Reserved Reserved
[0235] Digital signature type signature_type
[0236] A 2-bit unsigned integer. It indicates the algorithm for digitally signing the digest data of a data unit, as shown in Table 4.
[0237] Table 4 Correspondence between digital signature type and specific encryption algorithm
[0238]
[0239]
[0240] Authentication enable flag authentication_flag
[0241] 1-bit unsigned integer. It indicates whether a set of data units supports authentication, as shown in Table 5:
[0242] Table 5 Description of Authentication Enable Flag
[0243] Value of authentication_flag Description 0 Does not support authentication 1 Supports authentication
[0244] camera_idc is a 19-byte string used to represent the certificate identifier of the camera from which the video stream's corresponding image is sourced.
[0245] It should be noted that, compared with the prior art, the present application newly adds in the safety parameter set: authenticate_mode (which can be referred to as the first identifier).
[0246] Exemplarily, when authenticate_mode is 0, it can be determined that the signature method involved in the present application is used for signature, and reference can be made to S502 - S504 below; when authenticate_mode is 1, it can be determined that the signature method in the prior art is used for signature, that is, calculating the tree-shaped digest data and signing the top-level digest data. Furthermore, when using the signature method of the present application, during the process of generating the safety parameter set RBSP, the authenticate_mode in the safety parameter set RBSP can be set to 0.
[0247] Exemplarily, during the process of generating the safety parameter set RBSP, the authentication_flag in the safety parameter set RBSP can be set to 1, so that it can indicate that a set of data units located after the safety parameter set RBSP supports authentication.
[0248] It should be noted that hash_type, signature_type, and camera_idc in the safety parameter set RBSP are optional.
[0249] S502: Calculate, according to the digest algorithm, each data unit in a set of data units of the video stream to obtain the digest data of each data unit in the set of data units.
[0250] Exemplarily, according to successive_hash_pictures_minus1 (which can also be referred to as the fifth identifier) in the safety parameter set RBSP, the number of data units that need to be authenticated, SuccessiveHashPictures, can be calculated; that is, the number of data units included in a set of data units is SuccessiveHashPictures.
[0251] Among them, SuccessiveHashPictures = successive_hash_pictures_minus1 + 1. Then, for each of the SuccessiveHashPictures data units with authentication_idc being 1, the digest data of each data unit can be calculated according to the digest algorithm.
[0252] In a possible way, authentication_idc is located in the NAL header of the NAL unit.
[0253] Authentication enable flag authentication_idc
[0254] A binary variable. It indicates whether the NAL unit is authenticated. A value of '0' indicates that the NAL unit is not authenticated, and a value of '1' indicates that the NAL unit is authenticated by the authentication method specified in the security parameter set.
[0255] In a possible way, when the security parameter set RBSP includes hash_type, the digest algorithm can be the authentication algorithm indicated by hash_type in the security parameter set RBSP. In this case, for each of the SuccessiveHashPictures data units with authentication_idc being 1, the digest data of each data unit can be calculated according to the authentication algorithm indicated by hash_type in the security parameter set RBSP. For example, for each of the SuccessiveHashPictures data units with authentication_idc being 1, a hash calculation can be performed according to the digest algorithm indicated by hash_type in the security parameter set RBSP to obtain the digest data of each of the SuccessiveHashPictures data units.
[0256] In a possible way, the signature end 210 and the authentication end 220 can pre - agree on the digest algorithm; in this way, for each of the SuccessiveHashPictures data units with authentication_idc being 1, the digest data of each data unit can be calculated according to the pre - agreed digest algorithm. In this case, the security parameter set RBSP may not include hash_type.
[0257] It should be understood that the present application does not limit the manner in which the signature end 210 and the authentication end 220 synchronize the digest algorithm.
[0258] Referring again to Figure 5A , by way of example, a hash calculation is performed on data unit 1 to obtain digest data H1; a hash calculation is performed on data unit 2 to obtain digest data H2; a hash calculation is performed on data unit 3 to obtain digest data H3; a hash calculation is performed on data unit 4 to obtain digest data H4; a hash calculation is performed on data unit 5 to obtain digest data H5;...; a hash calculation is performed on data unit n to obtain digest data Hn.
[0259] S503, concatenate the digest data of each data unit in a set of data units, and determine the digest data of the concatenated digest data.
[0260] By way of example, the digest data of each of the SuccessiveHashPictures data units with authentication_idc of 1 can be concatenated to obtain the concatenated digest data as H1 + H2 + H3 + H4 + H5 +... + Hn.
[0261] Next, the concatenated digest data can be calculated to obtain the digest data of the concatenated digest data. For example, a hash calculation is performed on H1 + H2 + H3 + H4 + H5 +... + Hn to obtain the digest data Hg of the concatenated digest data (as Figure 5A shown).
[0262] S504, use the private key to sign the digest data of the digest data of each data unit in the concatenated set of data units to obtain signature data.
[0263] In one possible way, when the security parameter set RBSP includes signature_type, the signature algorithm and the private key indicated by signature_type in the security parameter set RBSP can be used to sign the digest data of the concatenated digest data to obtain signature data.
[0264] In one possible way, the signature end 210 and the authentication end 220 can pre-agree on the signature algorithm; in this way, the signature data can be obtained by signing the digest data of the concatenated digest data according to the pre-agreed signature algorithm and private key. In this case, the security parameter set RBSP may not include signature_type.
[0265] It should be understood that the present application does not limit the manner in which the signature end 210 and the authentication end 220 synchronize the signature algorithm.
[0266] It should be understood that the top-level summary data can also be generated, and the top-level summary data is signed using the private key to obtain the signature data. This application does not limit the manner of signing according to the summary data of the data unit.
[0267] Exemplarily, authentication data is generated according to the summary data and signature data of each data unit in a set of data units.
[0268] For example, the authentication data can include {H1, H2, H3, H4, H5,..., Hn, signature}.
[0269] S505, encode the authentication data and add the encoded authentication data to the bitstream.
[0270] Exemplarily, the authentication data can be encoded using Base64; then, the encoded authentication data is packed into the NAL unit of the authentication data.
[0271] In a possible manner, when the data unit includes one or more access units, or the data unit is an encoded image; the definition of the authentication data RBSP in the NAL unit of the authentication data can be as shown in Table 6 below:
[0272] Table 6 Definition of Authentication Data RBSP
[0273]
[0274] Authentication sequence number authentication_id
[0275] Binary variable. The authentication sequence number of the authentication data set.
[0276] Number of authentication summary data authentication_hash_number_minus1
[0277] 8-bit unsigned integer. Adding 1 represents the length of the signature data in bytes, and the value should be 0 to 255.
[0278] Authentication summary data authentication_hash
[0279] Binary data, with a length equal to the length of the summary data corresponding to the hash type in the correspondence table between the hash type and the specific algorithm in the security parameter set, in bytes.
[0280] Length of signature data authentication_data_length_minus1
[0281] 8-bit unsigned integer. Adding 1 represents the length of the signature data in bytes, and the value should be 0 to 255.
[0282] The number of bytes of the signature data, authentication_data[i]
[0283] An 8-bit unsigned integer. The i-th byte of a signature data. The signature data shall be Base64-encoded. See rfc3548 for the Base64 encoding method.
[0284] Exemplarily, the authentication data includes the digest data, i.e., authentication_hash (authentication digest data) in Table 6.
[0285] Exemplarily, authentication_hash_number_minus1 in the authentication data RBSP can be referred to as the sixth identifier.
[0286] It should be noted that, compared with the authentication data RBSP in the prior art, the NAL unit of the authentication data in Table 6 of the present application newly adds authentication_id, authentication_hash, and authentication_hash_number_minus1.
[0287] In a possible way, when the data unit includes multiple access units, or the data unit is an encoded image; the definition of the authentication data RBSP in the NAL unit of the authentication data can be as shown in Table 7 below:
[0288] Table 7 Definition of the authentication data RBSP
[0289]
[0290] The decoding order index, decode_order_index
[0291] An 8-bit unsigned integer. It indicates the value of the decoding order index of the current image. The same as the definition of decode_order_index in the picture header RBSP.
[0292] Exemplarily, the definitions of other syntax elements in Table 7 can refer to the description in Table 6 and will not be elaborated here.
[0293] It should be noted that, compared with the authentication data RBSP in the prior art, the NAL unit of the authentication data in Table 7 of the present application newly adds authentication_id, authentication_hash, authentication_hash_number_minus1, and decode_order_index (which can also be referred to as the fourth identifier).
[0294] In addition, in the scenario of temporal SVC coding of the SVAC standard, each data unit includes a second identifier (temporal_id) for identifying the temporal layer to which the data unit belongs; correspondingly, the authentication data RBSP may also include the second identifier (temporal_id). Since in the scenario of temporal SVC coding of the SVAC standard, the temporal base layer (i.e., the data unit with the second identifier being 0) needs to be parsed, in order to ensure that the authentication data can be obtained regardless of whether the temporal enhancement layer is parsed during the authentication process; the value of the second identifier in the NAL unit of the authentication data can be set to 0.
[0295] In the scenario of spatial SVC coding or quality SVC coding of the SVAC standard, each data unit includes a third identifier (layer_id) for identifying the spatial layer or quality coding layer to which the data unit belongs; correspondingly, the authentication data RBSP may also include the third identifier (layer_id). Since in the scenario of spatial SVC coding or quality SVC coding of the SVAC standard, the spatial base layer / quality coding base layer (i.e., the data unit with the third identifier being 0) needs to be parsed, in order to ensure that the authentication data can be obtained regardless of whether the spatial enhancement layer / quality coding enhancement layer is parsed during the authentication process; the value of the third identifier in the NAL unit of the authentication data can be set to 0.
[0296] Figure 5B It is a schematic diagram of the signature process shown for illustration. Figure 5B Two groups of data units in the bitstream and the authentication data corresponding to the two groups of data units are shown.
[0297] Refer to Figure 5B , for example, Sec represents the NAL unit of the security parameter set RESP, P1 to Pn respectively correspond to a data unit, and Auth represents the authentication data. Private Key is the private key, sign is the signature, and Public Key is the public key.
[0298] Refer to Figure 5B , in one possible way, the public key can be added to the authentication data.
[0299] It should be understood that the public key corresponding to the above private key can also be transmitted in other ways, such as being built into the authentication end, transmitted to the authentication end in the authentication certificate, etc., and this application does not limit this.
[0300] It should be noted that the authentication data corresponding to the current group of data units may be connected after the current group of data units, such as Figure 5BAs shown by the first set of data units and the authentication data of the first set of data units. The authentication data corresponding to the current set of data units is not necessarily connected after the current set of data units, and may also be connected after the first few data units of the next set of data units (as shown by the second set of data units and the authentication data of the second set of data units in Figure 5B ). This is due to the difference between the rate of the encoded data units and the rate of generating the authentication data. However, since each data unit in this application is independently authenticated, it will not affect the authentication of the current set of data units. Figure 5B As shown by the second set of data units and the authentication data of the second set of data units in Figure 5B .
[0301] Figure 6 It is a schematic diagram of the exemplary authentication process 600. Process 600 is a process in which the SVAC authentication end realizes data unit authentication when SuccessiveHashPictures indicates the end of the data unit authentication sequence. Process 600 corresponds to Process 500.
[0302] S601, calculate each data unit in a set of data units of the bitstream according to the digest algorithm to obtain the first digest data of each data unit in the set of data units.
[0303] Exemplarily, after the authentication end 220 receives the security parameter set RBSP of the bitstream, when it parses that the authentication_flag is 1 from the security parameter set RBSP of the bitstream, it determines that the subsequent set of data units supports authentication. At this time, it can continue to parse the syntax elements in the security parameter set RBSP according to the order of each syntax element in Table 1.
[0304] Exemplarily, parse the hash_mode in the security parameter set RBSP; when it is parsed that the hash_mode is 0, S602 can be executed.
[0305] Exemplarily, parse the hash_type in the security parameter set RBSP; determine the digest algorithm according to the value of the parsed hash_type.
[0306] Exemplarily, parse the signature_type in the security parameter set RBSP; determine the signature algorithm according to the value of the parsed signature_type.
[0307] Exemplarily, parse successive_hash_pictures_minus1 in the safety parameter set RBSP; calculate SuccessiveHashPictures according to the value of the parsed successive_hash_pictures_minus1 (which can also be referred to as the fifth identifier). Further, it can be determined that SuccessiveHashPictures data units need to be authenticated; that is, the number of data units included in a group of data units is SuccessiveHashPictures. Among them, SuccessiveHashPictures = successive_hash_pictures_minus1 + 1.
[0308] Exemplarily, parse camera_idc in the safety parameter set RBSP; determine the authentication certificate identifier of the camera from which the bitstream corresponds to the image source according to the value of the parsed camera_idc.
[0309] Exemplarily, after receiving the safety parameter set RBSP of the bitstream, the authentication end 220 can receive the NAL unit; at this time, the NAL unit can be parsed, and authentication_idc can be parsed from the NAL unit header. When each of the SuccessiveHashPictures data units with authentication_idc being 1 is received, each data unit can be calculated to obtain the digest data of each of the SuccessiveHashPictures data units.
[0310] In a possible way, when hash_type is parsed from the safety parameter set RBSP of the bitstream, each of the SuccessiveHashPictures data units with authentication_idc being 1 can be calculated according to the authentication algorithm (i.e., the digest algorithm) indicated by hash_type to obtain the first digest data of each of the SuccessiveHashPictures data units with authentication_idc being 1.
[0311] For example, according to the digest algorithm indicated by hash_type in the safety parameter set RBSP, hash calculation can be performed on each of the SuccessiveHashPictures data units with authentication_idc being 1, to obtain the digest data of each of the SuccessiveHashPictures data units with authentication_idc being 1.
[0312] In a possible way, when hash_type cannot be parsed from the safety parameter set RBSP of the bitstream, calculation can be performed on each of the SuccessiveHashPictures data units with authentication_idc being 1 according to a pre-agreed digest algorithm, to obtain the digest data of each of the SuccessiveHashPictures data units with authentication_idc being 1.
[0313] Refer to Figure 6 , the n first digest data are {H1’, H2’, H3’, H4’, H5’,..., Hn’}
[0314] S602, obtain authentication data from the bitstream, where the authentication data includes: signature data and the second digest data of each of the data units in a set of data units, and the signature data is obtained by signing the second digest data of each of the data units in a set of data units.
[0315] Exemplarily, the authentication data RBSP in the bitstream can be parsed to obtain the authentication data.
[0316] Exemplarily, parse authentication_hash_number_minus1 (which can also be referred to as the sixth identifier) in the authentication data RBSP, to obtain the quantity of the second digest data included in the authentication data.
[0317] Exemplarily, according to authentication_hash_number_minus1, parse authentication_hash in the authentication data RBSP, to obtain the second digest data of each of the SuccessiveHashPictures data units with authentication_idc being 1; where the quantity of the second digest data is the same as the value calculated according to authentication_hash_number_minus1.
[0318] Exemplarily, when the authentication data generated in the signature end 210 further includes the public key corresponding to the private key used for signature, the public key can also be parsed from the authentication data RBSP.
[0319] Exemplarily, when the authentication data RBSP is defined as shown in Table 6, the authentication data can include {H1, H2, H3, H4, H5,..., Hn, signature}.
[0320] Exemplarily, when the authentication data RBSP is defined as shown in Table 7, the authentication data can include {decode_order_index_1, decode_order_index_2, decode_order_index_3, decode_order_index_4, decode_order_index_5,..., decode_order_index_n, H1, H2, H3, H4, H5,..., Hn, signature}. Among them, decode_order_index_1 corresponds to H1, decode_order_index_2 corresponds to H2, and so on.
[0321] S603, verify the signature data according to the public key, the first digest data of each data unit in a group of data units, and the signature algorithm.
[0322] Exemplarily, the first digest data of each of the SuccessiveHashPictures data units with authentication_idc being 1 can be concatenated to obtain the concatenated first digest data; then, the digest data Hg' of the concatenated first digest data is determined. After that, the verification algorithm corresponding to the signature algorithm can be used to process the public key, Hg', and the signature data to obtain the verification result of the signature data.
[0323] In a possible way, when signature_type is parsed from the code stream security parameter set RBSP, the signature algorithm can be determined according to the signature algorithm indicated by signature_type.
[0324] In a possible way, the signature algorithm can be determined according to a pre-agreed signature algorithm.
[0325] In a possible way, when camera_idc is obtained from the security parameter set RBSP of the code stream, the public key can be found from the authentication certificate indicated by camera_idc.
[0326] In a possible way, the public key can be parsed and obtained from the authentication data RBSP of the code stream.
[0327] In a possible way, a public key pre-built in the authentication end 220 can be obtained.
[0328] S604, when the signature data is successfully verified, based on multiple second digest data in a set of data units, verify multiple first digest data of the set of data units.
[0329] Exemplarily, when the authentication data RBSP is defined as shown in Table 6, for the second data unit in a set of data units, the digest data {H1, H2, H3, H4, H5,..., Hn} of the authentication data can be searched to find the digest data that is the same as the digest data Hk' of the second data unit; if there is digest data in the digest data list {H1, H2, H3, H4, H5,..., Hn} of the authentication data that is the same as the digest data Hk' of the second data unit, the authentication of the first data unit is successful; if there is no digest data in the digest data list {H1, H2, H3, H4, H5,..., Hn} of the authentication data that is the same as the digest data Hk' of the second data unit, the authentication of the first data unit fails. Wherein, k is a positive integer less than or equal to n.
[0330] Exemplarily, when the authentication data RBSP is defined as shown in Table 7, for the first data unit in a set of data units, the decoding order index {decode_order_index_1, decode_order_index_2, decode_order_index_3, decode_order_index_4, decode_order_index_5,..., decode_order_index_n} of the authentication data can be searched to find the decoding order index that is the same as the decoding order index decode_order_index_k of the first data unit; if there is a decode_order_index_j that is the same as decode_order_index_k, then compare the digest data Hk' of the first data unit with the digest data Hj corresponding to decode_order_index_j, where j is less than or equal to n. If Hk' and Hj are the same, the authentication of the first data unit is successful. If there is no decoding order index that is the same as decode_order_index_k, or Hk' and Hj are not the same, the authentication of the first data unit fails.
[0331] In one possible way, the SVAC signature side can identify the end or start of a group of data units through the security parameter set RBSP to implement data unit signature. Correspondingly, the SVAC authentication side can implement data unit signature when the security parameter set RBSP identifies the end or start of a group of data units. In this case, the definition of the security parameter set RBSP can be as shown in Table 8:
[0332] Table 8 Definition of Security Parameter Set RBSP
[0333]
[0334]
[0335] Among them, the descriptions of the syntax elements in Table 8 can refer to the descriptions of the syntax elements in Table 1 above, and will not be elaborated here.
[0336] Exemplarily, when video image authentication needs to be supported, a security parameter set RBSP is generated. It should be noted that the signature side 210 can indicate the end of the previous authentication sequence (i.e., the previous group of data units) by inserting a new security parameter set RBSP, and stop authentication or start a new authentication (authentication of the next group of data units).
[0337] It should be noted that compared with the prior art, the security parameter set of this application newly adds: authenticate_mode (which can be called the first identifier).
[0338] Exemplarily, when adopting the signature method of this application, the authenticate_mode in the security parameter set RBSP can be set to 0 during the process of generating the security parameter set RBSP.
[0339] Exemplarily, during the process of generating the security parameter set RBSP, the authentication_flag in the security parameter set RBSP can be set to 1, so that it can indicate that a group of data units located after the security parameter set RBSP supports authentication.
[0340] It should be noted that hash_type, signature_type, and camera_idc in the security parameter set RBSP are optional.
[0341] In this way, the signature process of the signature end 210 for the bitstream can refer to the above S501 - S505. Among them, in the case where the security parameter set RBSP is as shown in Table 8, the method for determining the data units to be authenticated in S502 is slightly different from the method described above. In the case where the security parameter set RBSP is as shown in Table 8, after generating a security parameter set RBSP, the signature end 210 independently calculates the digest data for each data unit with authentication_idc = 1 in the NAL header until the next security parameter set RBSP is generated. That is to say, the data units located between two security parameter set RBSPs are the data units to be authenticated.
[0342] Exemplarily, the authentication process of the authentication end 220 for the bitstream can refer to the above S601 - S604. In the case where the security parameter set RBSP is as shown in Table 8, the method for determining the data units to be authenticated in S601 is slightly different from the method described above. In the case where the security parameter set RBSP is as shown in Table 8, after receiving a security parameter set RBSP, the authentication end 220 can independently calculate the digest data for each subsequent received data unit with authentication_idc = 1 until the next security parameter set RBSP is received.
[0343] Exemplarily, when the security parameter set RBSP is defined as shown in Table 8, the authentication data RBSP definition can be as shown in Table 6 or Table 7, which will not be elaborated here.
[0344] Figure 7 It is a schematic diagram of a bitstream signature device shown exemplarily. The schematic diagram of the bitstream signature device can be used to execute the method of the foregoing embodiments. Therefore, the beneficial effects it can achieve can refer to the beneficial effects in the corresponding method provided above, which will not be elaborated here.
[0345] Refer to Figure 7 , exemplarily, the bitstream signature device 700 includes:
[0346] A first authentication data acquisition module 701, configured to acquire authentication data; wherein, the authentication data includes: signature data and the digest data of each data unit in a group of data units of the bitstream, and the signature data is obtained by signing the digest data of each data unit in the group of data units.
[0347] An addition module 702, configured to add the authentication data to the bitstream.
[0348] Exemplarily, the bitstream signature device 700 further includes:
[0349] A digest data calculation module, configured to calculate the digest data of each data unit in a group of data units according to a digest algorithm.
[0350] Exemplarily, the signature device 700 of the bitstream further includes:
[0351] A signature module, configured to connect the digest data of each data unit in a set of data units, determine the digest data of the connected digest data; and sign the digest data of the connected digest data using a private key to obtain signature data.
[0352] Exemplarily, the signature device 700 of the bitstream further includes:
[0353] An authentication data generation module, configured to generate authentication data according to the signature data and the digest data of each data unit in a set of data units.
[0354] Exemplarily, the adding module 702 is specifically configured to encode the authentication data and add the encoded authentication data to the bitstream.
[0355] Exemplarily, each data unit in a set of data units includes one or more Network Abstraction Layer (NAL) units.
[0356] Exemplarily, multiple NAL units in a set of data units are correlated with each other according to a specified rule, and the decoding order of multiple NAL units in a set of data units is consecutive. That is to say, one data unit is one access unit.
[0357] Exemplarily, each data unit in a set of data units includes an encoded image.
[0358] Exemplarily, the bitstream further includes a first identifier, and the first identifier indicates the authentication mode adopted by a set of data units.
[0359] Exemplarily, the bitstream further includes a security parameter set, and the security parameter set includes the first identifier.
[0360] Exemplarily, the bitstream further includes a NAL unit of authentication data, and the NAL unit of authentication data includes a second identifier; wherein, the second identifier indicates the temporal level, and the value of the second identifier is 0.
[0361] Exemplarily, the bitstream further includes a NAL unit of authentication data, and the NAL unit of authentication data includes a third identifier; wherein, the third identifier indicates the spatial level or the quality coding level, and the value of the third identifier is 0.
[0362] Exemplarily, the authentication data further includes: a fourth identifier, and the fourth identifier is used to identify a data unit.
[0363] Exemplarily, the bitstream further includes: a fifth identifier; and the signature device 700 of the bitstream further includes
[0364] A numerical value determination module, configured to determine a numerical value n according to a fifth identifier; wherein a set of data units includes n data units, and n is a positive integer;
[0365] An abstract data calculation module is further configured to calculate each data unit in the n data units according to an abstract algorithm to obtain the abstract data of each data unit in the n data units.
[0366] Figure 8 It is a schematic diagram of a code stream authentication device shown exemplarily. The schematic diagram of the code stream authentication device can be used to execute the method of the foregoing embodiment. Therefore, the beneficial effects it can achieve can refer to the beneficial effects in the corresponding method provided above, and will not be elaborated here.
[0367] Refer to Figure 8 , exemplarily, the code stream authentication device 800 includes:
[0368] An abstract data determination module 801, configured to determine the first abstract data of each data unit in a set of data units of the code stream;
[0369] A second authentication data acquisition module 802, configured to acquire authentication data from the code stream, where the authentication data includes: signature data and the second abstract data of each data unit in a set of data units, and the signature data is obtained by signing according to the second abstract data of each data unit in a set of data units;
[0370] A verification module 803, configured to, when the verification of the signature data is successful, verify the multiple first abstract data of a set of data units according to the multiple second abstract data in the authentication data.
[0371] Exemplarily, the abstract data determination module 801 is specifically configured to calculate each data unit in a set of data units according to an abstract algorithm to obtain the first abstract data of each data unit in a set of data units.
[0372] Exemplarily, the code stream authentication device 800 further includes:
[0373] A public key acquisition module, configured to acquire a public key;
[0374] The verification module 803 is configured to concatenate the second abstract data of each data unit in a set of data units to determine the abstract data of the concatenated second abstract data; and is further configured to verify the signature data according to the public key, the abstract data of the concatenated second abstract data, and a signature algorithm.
[0375] Exemplarily, the code stream authentication device 800 further includes:
[0376] An identifier acquisition module, configured to acquire a first identifier from the code stream, where the first identifier indicates an authentication mode adopted by a set of data units;
[0377] When the value of the first identifier is the first preset value, the summary data determination module determines the first summary data of each data unit in a set of data units of the bitstream.
[0378] Exemplarily, the identifier acquisition module is further configured to acquire a sixth identifier from the bitstream and determine a value n according to the sixth identifier; wherein, a set of data units includes n data units, and n is a positive integer.
[0379] The authentication device 800 of the bitstream further includes:
[0380] The summary data acquisition module is configured to acquire the second summary data of each data unit in the n data units from the bitstream.
[0381] Exemplarily, the identifier acquisition module is further configured to acquire a fifth identifier from the bitstream and determine a value n according to the fifth identifier; wherein, a set of data units includes n data units, and n is a positive integer.
[0382] The summary data determination module is specifically configured to calculate each data unit in the n data units according to a summary algorithm to obtain the summary data of each data unit in the n data units.
[0383] Exemplarily, the authentication data further includes a plurality of fourth identifiers, and the plurality of fourth identifiers correspond to the plurality of second summary data one by one.
[0384] The identifier acquisition module is further configured to acquire a seventh identifier corresponding to each data unit in a set of data units from the bitstream.
[0385] The verification module is specifically configured to, for the first data unit in a set of data units: search for a fourth identifier that is the same as the seventh identifier of the first data unit from the plurality of fourth identifiers included in the authentication data; if there is a fourth identifier that is the same as the seventh identifier of the first data unit, then compare the first summary of the first data unit with the second summary corresponding to the fourth identifier that is the same as the seventh identifier of the first data unit.
[0386] If the two are the same, it is determined that the authentication of the first data unit is successful.
[0387] Otherwise, it is determined that the authentication of the first data unit fails.
[0388] Exemplarily, each data unit in a set of data units includes one or more network abstraction layer NAL units.
[0389] Exemplarily, the verification module is specifically configured to, for a second data unit in a set of data units: find, from multiple second digests included in the authentication data, a second digest that is the same as the first digest of the second data unit; if there is a second digest that is the same as the first digest of the second data unit, determine that the authentication of the second data unit is successful; otherwise, determine that the authentication of the second data unit fails.
[0390] Exemplarily, multiple NAL units in a set of data units are correlated with each other according to a specified rule, and the decoding order of multiple NAL units in a set of data units is consecutive. That is to say, one data unit is one access unit.
[0391] Exemplarily, each data unit in a set of data units includes an encoded image.
[0392] In one example, Figure 9 FIG. shows a schematic block diagram of a device 900 according to an embodiment of the present application. The device 900 may include: a processor 901 and a transceiver / transceiver pin 902. Optionally, it further includes a memory 903.
[0393] Each component of the device 900 is coupled together through a bus 904. Among them, the bus 904 includes, in addition to a data bus, a power bus, a control bus, and a status signal bus. However, for the sake of clear illustration, all various buses are referred to as bus 904 in the figure.
[0394] Optionally, the memory 903 may be used to store instructions in the foregoing method embodiments. The processor 901 may be used to execute the instructions in the memory 903, control the receiving pin to receive signals, and control the sending pin to send signals.
[0395] The device 900 may be an electronic device or a chip of an electronic device in the foregoing method embodiments.
[0396] Among them, all relevant contents of each step involved in the foregoing method embodiments may be cited in the function descriptions of the corresponding functional modules, and will not be elaborated herein.
[0397] An embodiment of the present application further provides a chip, including one or more interface circuits and one or more processors; the one or more processors receive or send data through the one or more interface circuits. When the one or more processors execute computer instructions, the steps of the relevant method described above are executed to implement the method in the foregoing embodiments. Among them, the interface circuit is a transceiver / transceiver pin 902.
[0398] This embodiment further provides a computer-readable storage medium. Computer instructions are stored in the computer-readable storage medium. When the computer instructions run on an electronic device, the electronic device is caused to execute the relevant method steps to implement the method in the foregoing embodiments.
[0399] This embodiment also provides a computer program product, which includes computer instructions. When the computer instructions are executed by a computer or a processor, the computer is enabled to execute the above related steps to implement the method in the above embodiment.
[0400] In addition, an embodiment of the present application also provides a device, which may specifically be a chip, a component or a module. The device may include a processor and a memory connected to each other. Wherein, the memory is used to store computer execution instructions. When the device runs, the processor may execute the computer execution instructions stored in the memory so that the chip executes the methods in the above method embodiments.
[0401] Among them, the electronic device, computer-readable storage medium, computer program product or chip provided in this embodiment are all used to execute the corresponding method provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method provided above, which will not be elaborated here.
[0402] Through the description of the above embodiments, those skilled in the art can understand that for the convenience and simplicity of description, only the above division of each functional module is used as an example. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.
[0403] In several embodiments provided by the present application, it should be understood that the disclosed device and method can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of the device or unit can be in an electrical, mechanical or other form.
[0404] The units described as separate components may or may not be physically separated. The components displayed as units may be a physical unit or multiple physical units, that is, they may be located in one place, or they may be distributed to multiple different places. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0405] In addition, in each embodiment of the present application, each functional unit can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0406] Any content of each embodiment of the present application, as well as any content of the same embodiment, can be freely combined. Any combination of the above content is within the scope of the present application.
[0407] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiments of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. The software product is stored in a storage medium and includes several instructions to enable a device (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the methods of each embodiment of the present application. The aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical discs and other various media that can store program codes.
[0408] The steps of the method or algorithm described in combination with the disclosed content of the embodiments of the present application can be implemented in a hardware manner or by a processor executing software instructions. The software instructions can be composed of corresponding software modules. The software modules can be stored in a random access memory (RAM), flash memory, read-only memory (ROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, hard disks, mobile hard disks, compact disc read-only memories (CD-ROMs), or any other form of storage medium well-known in the art. An exemplary storage medium is coupled to the processor, enabling the processor to read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an ASIC.
[0409] Those skilled in the art should be able to realize that in one or more of the above examples, the functions described in the embodiments of the present application can be implemented by hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. The computer-readable medium includes computer-readable storage media and communication media, where the communication media includes any medium that facilitates the transmission of a computer program from one place to another. The storage media can be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0410] The embodiments of the present application have been described above in conjunction with the accompanying drawings. However, the present application is not limited to the above specific implementation manners. The above specific implementation manners are merely illustrative rather than restrictive. Under the inspiration of the present application, those of ordinary skill in the art can also make many forms without departing from the purpose of the present application and the scope protected by the claims, and all of them fall within the protection scope of the present application.
Claims
1. A method for signing a bitstream, characterized in that, the method comprises: obtaining authentication data; wherein, the authentication data includes: signature data and digest data of each data unit in a set of data units of the bitstream, and the signature data is obtained by signing the digest data of each data unit in the set of data units. Adding the authentication data to the bitstream.
2. The method according to claim 1, characterized in that, the method further comprises: Calculating each data unit in the set of data units according to a digest algorithm to obtain the digest data of each data unit in the set of data units.
3. The method according to claim 1 or 2, characterized in that, the method further comprises: Connecting the digest data of each data unit in the set of data units to determine the digest data of the connected digest data; Signing the digest data of the connected digest data with a private key to obtain the signature data.
4. The method according to any one of claims 1 to 3, characterized in that, the method further comprises: Generating the authentication data according to the signature data and the digest data of each data unit in the set of data units.
5. The method according to any one of claims 1 to 4, characterized in that, the adding the authentication data to the bitstream includes: Encoding the authentication data and adding the encoded authentication data to the bitstream.
6. The method according to any one of claims 1 to 5, characterized in that, each data unit in the set of data units includes one or more network abstraction layer (NAL) units.
7. The method according to claim 6, characterized in that, multiple NAL units in the set of data units are correlated with each other according to a specified rule, and the decoding order of multiple NAL units in the set of data units is consecutive.
8. The method according to any one of claims 1 to 5, characterized in that, each data unit in the set of data units includes an encoded image.
9. The method according to any one of claims 1 to 8, characterized in that, the bitstream further includes a first identifier, and the first identifier indicates the authentication mode adopted by the set of data units.
10. The method according to claim 9, characterized in that, the bitstream further includes a security parameter set, and the security parameter set includes the first identifier.
11. The method according to any one of claims 1 to 10, characterized in that, the bitstream further includes a NAL unit of authentication data, and the NAL unit of authentication data includes a second identifier; wherein, the second identifier indicates the time domain level, and the value of the second identifier is 0.
12. The method according to any one of claims 1 to 10, characterized in that, the bitstream further includes a NAL unit of authentication data, and the NAL unit of authentication data includes a third identifier; wherein, the third identifier indicates the spatial domain level or the quality coding level, and the value of the third identifier is 0.
13. The method according to any one of claims 1 to 12, characterized in that, The authentication data further includes: a fourth identifier for identifying a data unit.
14. The method according to any one of claims 1 to 13, wherein, the bitstream further includes: a fifth identifier; and the method further includes: determining a value n according to the fifth identifier; wherein the set of data units includes n data units, and n is a positive integer; calculating each data unit in the n data units according to a digest algorithm to obtain the digest data of each data unit in the n data units.
15. A bitstream, wherein, the bitstream includes: a set of data units and authentication data; wherein the authentication data includes: signature data and the digest data of each data unit in the set of data units, and the signature data is obtained by signing the digest data of each data unit in the set of data units.
16. The bitstream according to claim 15, wherein, each data unit in the set of data units includes one or more Network Abstraction Layer (NAL) units.
17. The bitstream according to claim 16, wherein, the multiple NAL units in the set of data units are correlated with each other according to a specified rule, and the decoding order of the multiple NAL units in the set of data units is consecutive.
18. The bitstream according to claim 15, wherein, each data unit in the set of data units includes an encoded image.
19. The bitstream according to any one of claims 15 to 18, wherein, the bitstream further includes a first identifier for indicating the authentication mode adopted by the set of data units.
20. The bitstream according to claim 19, wherein, the bitstream further includes a security parameter set, and the security parameter set includes the first identifier.
21. The bitstream according to any one of claims 15 to 20, wherein, the bitstream further includes a NAL unit of authentication data, and the NAL unit of authentication data includes a second identifier; wherein the second identifier indicates a time domain level, and the value of the second identifier is 0.
22. The bitstream according to any one of claims 15 to 20, wherein, the bitstream further includes a NAL unit of authentication data, and the NAL unit of authentication data includes a third identifier; wherein the third identifier indicates a spatial domain level or a quality coding level, and the value of the third identifier is 0.
23. The bitstream according to any one of claims 15 to 22, wherein, the authentication data further includes: a fourth identifier for identifying a data unit.
24. The bitstream according to any one of claims 15 to 23, wherein, the bitstream further includes: a fifth identifier for determining the number n of data units included in the set of data units.
25. The bitstream according to any one of claims 15 to 24, wherein, the bitstream further includes a NAL unit of authentication data, and the NAL unit of authentication data includes a sixth identifier for determining the number of digest data included in the authentication data.
26. A method for authenticating a bitstream, characterized in that, the method includes: determining first digest data of each data unit in a set of data units of the bitstream; obtaining authentication data from the bitstream, where the authentication data includes: signature data and second digest data of each data unit in the set of data units, and the signature data is obtained by signing the second digest data of each data unit in the set of data units; when the verification of the signature data is successful, verifying the first digest data of the set of data units according to the multiple second digest data in the authentication data.
27. The method according to claim 26, characterized in that, the determining first digest data of each data unit in the set of data units includes: calculating each data unit in the set of data units according to a digest algorithm to obtain the first digest data of each data unit in the set of data units.
28. The method according to claim 26 or 27, characterized in that, the method further includes: obtaining a public key; connecting the second digest data of each data unit in the set of data units, and determining the digest data of the connected second digest data; verifying the signature data according to the public key, the digest data of the connected second digest data, and a signature algorithm.
29. The method according to any one of claims 26 to 28, characterized in that, the method further includes: obtaining a first identifier from the bitstream, where the first identifier indicates an authentication mode adopted by the set of data units; when the value of the first identifier is a first preset value, performing the step of determining first digest data of each data unit in a set of data units of the bitstream.
30. The method according to any one of claims 26 to 29, characterized in that, the method further includes: obtaining a sixth identifier from the bitstream, and determining a value n according to the sixth identifier; where the set of data units includes n data units, and n is a positive integer; obtaining second digest data of each data unit in the n data units from the bitstream.
31. The method according to any one of claims 26 to 30, characterized in that, the method further includes: obtaining a fifth identifier from the bitstream, and determining a value n according to the fifth identifier; where the set of data units includes n data units, and n is a positive integer; the determining first digest data of each data unit in a set of data units of the bitstream includes: calculating each of the n data units according to a digest algorithm to obtain the digest data of each of the n data units.
32. The method according to any one of claims 26 to 31, characterized in that, the authentication data further includes multiple fourth identifiers, and the multiple fourth identifiers correspond to the multiple second digest data one by one. The method further includes: obtaining a seventh identifier corresponding to each data unit in the set of data units from the bitstream; the verifying the first digest data of the set of data units according to the multiple second digest data in the authentication data includes: For the first data unit in the set of data units: Among the multiple fourth identifiers included in the authentication data, find the fourth identifier that is the same as the seventh identifier of the first data unit; If there is a fourth identifier that is the same as the seventh identifier of the first data unit, compare the first digest of the first data unit and the second digest corresponding to the fourth identifier that is the same as the seventh identifier of the first data unit; If the two are the same, determine that the authentication of the first data unit is successful; Otherwise, determine that the authentication of the first data unit fails.
33. The method according to any one of claims 26 to 31, wherein, the verifying the multiple first digest data of the set of data units according to the multiple second digest data in the authentication data includes: For the second data unit in the set of data units: Among the multiple second digests included in the authentication data, find the second digest that is the same as the first digest of the second data unit; If there is a second digest that is the same as the first digest of the second data unit, determine that the authentication of the second data unit is successful; Otherwise, determine that the authentication of the second data unit fails.
34. The method according to any one of claims 26 to 33, wherein, each data unit in the set of data units includes one or more network abstraction layer (NAL) units.
35. The method according to claim 34, wherein, the multiple NAL units in the set of data units are associated with each other according to a specified rule, and the decoding order of the multiple NAL units in the set of data units is consecutive.
36. The method according to any one of claims 26 to 33, wherein, each data unit in the set of data units includes an encoded image.
37. An electronic device, wherein, comprising: a memory and a processor, the memory being coupled to the processor; the memory stores program instructions, and when the program instructions are executed by the processor, the electronic device executes the signature method of the bitstream according to any one of claims 1 to 14, or executes the authentication method of the bitstream according to any one of claims 26 to 36.
38. A computer-readable storage medium, wherein, the computer-readable storage medium stores a computer program, and when the computer program runs on a computer or a processor, the computer or the processor executes the method according to any one of claims 1 to 14, or executes the method according to any one of claims 26 to 36.
39. A computer program product, wherein, the computer program product contains computer instructions, and when the computer instructions are executed by a computer or a processor, the steps of the method according to any one of claims 1 to 14 are executed, or the steps of the method according to any one of claims 26 to 36 are executed.
40. A computer-readable storage medium, wherein, The computer-readable storage medium stores a bitstream as described in any one of claims 15 to 25.