Monitoring video stream hybrid encryption and decryption method and system based on multi-level authentication
By using a multi-level authentication mechanism in the video surveillance system to mix and encrypt and decrypt video data, the problems of video data transmission security and resource consumption in traditional systems are solved, and the effect of high security and efficient data processing is achieved.
Patent Information
- Application Number
- CN202510050805.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-13
- Publication Date
- 2025-05-30
AI Technical Summary
Traditional video surveillance systems are easily intercepted and tampered during video data transmission, and existing video encryption technology consumes a large amount of processor resources, making it difficult to meet the needs of high real-time and low resource consumption.
The monitoring video stream hybrid encryption and decryption method based on multi-level authentication is adopted, and the data key and video data are mixed and encrypted through encryption algorithms to generate encrypted data, and the hardware acceleration and multi-level authentication mechanism are used to ensure the security and integrity of the data.
It realizes high security and efficient data processing of video data during storage and transmission, and is suitable for monitoring occasions where high-level security protection is required, significantly improving the protection capabilities of the system.
Smart Images

Figure CN120075368A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of monitoring video encryption and decryption, and in particular, to a method and system for hybrid encryption and decryption of monitoring video streams based on multi-level authentication. Background Art
[0002] With the increasingly complex global security situation, video surveillance systems play an increasingly important role in ensuring public safety and enterprise asset security. Especially in key infrastructure such as banks, government agencies, and military facilities, the security requirements for video surveillance data are extremely high. These scenarios not only require the video surveillance system to capture images in real time, but also require that these data can be effectively protected during storage and transmission to prevent data leakage or malicious tampering. However, traditional video surveillance systems mostly use open networks or dedicated networks to transmit video data, which makes the video data extremely vulnerable to interception and tampering during transmission.
[0003] In addition, although current video encryption technologies can provide a certain degree of security guarantee, they often rely on software encryption technologies, which not only consume a large amount of processor resources but also are difficult to meet the requirements of high real-time performance. Therefore, how to ensure high security of video data while meeting the requirements of real-time processing and low resource consumption has become an important challenge for technological development. Summary of the Invention
[0004] The purpose of the present invention is to provide a method and system for hybrid encryption and decryption of monitoring video streams based on multi-level authentication to improve the above problems. To achieve the above purpose, the technical solutions adopted by the present invention are as follows:
[0005] In the first aspect, the present application provides a method for hybrid encryption and decryption of monitoring video streams based on multi-level authentication, including:
[0006] Obtain a data key and video data sent by a data sender, where the data key is generated by a random number generator or obtained from an external memory, and the video data is local monitoring video data or real-time monitoring video stream data;
[0007] Perform hybrid encryption on the data key and the video data through an encryption algorithm to obtain encrypted data, where the encrypted data includes an encryption key, encrypted video, and video signature;
[0008] Send the encrypted data to a data receiver, where the encrypted data is used to trigger the data receiver to perform decryption calculations and restore the video data through multi-level authentication.
[0009] In the second aspect, the present application further provides a system for hybrid encryption and decryption of monitoring video streams based on multi-level authentication, including:
[0010] A data communication terminal for data acquisition, data transmission, and task scheduling;
[0011] A programmable logic terminal for encrypting and decrypting video data.
[0012] The beneficial effects of the present invention are as follows: In the present invention, video data is encrypted at the programmable logic terminal through multiple encryption algorithms to ensure the security of video data during storage or transmission. At the same time, hardware acceleration is utilized to achieve high-speed data processing. Multiple groups of digest values are generated for the encrypted video and the digest values are signed to verify the integrity and authenticity of the data, preventing the data from being tampered with during transmission. When the verification fails, it is not necessary to discard the entire video, providing a comprehensive security solution for surveillance videos and being applicable to surveillance scenarios that require high-level security protection. And through hardware acceleration and specially designed multi-level authentication, the protection ability of the system is significantly improved while maintaining high-efficient data processing performance.
[0013] Other features and advantages of the present invention will be described in the subsequent specification, and, in part, will become apparent from the specification or can be understood by implementing the embodiments of the present invention. The objectives and other advantages of the present invention can be achieved and obtained through the structures specifically pointed out in the written specification, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the embodiments. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0015] Figure 1 It is a schematic flow diagram of a hybrid encryption and decryption method for surveillance video streams based on multi-level authentication described in the embodiments of the present invention;
[0016] Figure 2 It is a schematic data flow diagram of a hybrid encryption and decryption system for surveillance video streams based on multi-level authentication described in the embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0017] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. Components of the embodiments of the present invention generally described and illustrated in the drawings herein may be arranged and designed in a variety of different configurations. Therefore, the detailed description of the embodiments of the present invention provided herein is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0018] It should be noted that: Similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present invention, the terms "first", "second", etc. are only used for descriptive distinction and cannot be construed as indicating or implying relative importance.
[0019] Embodiment 1:
[0020] This embodiment provides a method for hybrid encryption and decryption of monitored video streams based on multi-level authentication.
[0021] See Figure 1 , which shows that this method includes step S100, step S200, and step S300.
[0022] Step S100: Obtain the data key and video data sent by the data sender. The data key is generated by a random number generator or obtained from an external memory, and the video data is local monitored video data or real-time monitored video stream data;
[0023] Step S200: Perform hybrid encryption on the data key and the video data through an encryption algorithm to obtain encrypted data, where the encrypted data includes an encryption key, encrypted video, and video signature;
[0024] The step S200 includes:
[0025] Step S201: Obtain the SM2 public key, perform encryption calculation on the data key through the SM2 public key to obtain the encryption key, and the SM2 public key is obtained through the SM2 algorithm;
[0026] Step S202: Perform encryption calculation on the video data through the SM4 algorithm to obtain the encrypted video;
[0027] Step S203: Perform signature calculation on the encrypted video to obtain the video signature.
[0028] In this embodiment, first, the data key is encrypted through a serial process, and then the video data is encrypted. The encryption of the data key ensures the security of the key itself used to encrypt the video. Among them, the SM2 algorithm is an asymmetric encryption and decryption algorithm, and the SM4 algorithm is a symmetric encryption and decryption algorithm.
[0029] Step S203 includes:
[0030] Step A100: Group the encrypted video according to the GOP boundary based on the video structure to obtain a plurality of groups, where each group includes a plurality of image frames;
[0031] In this embodiment, a group contains one I-frame and its associated several P-frames and B-frames, and the boundary of the group is determined by the structure information of the video encoder. The number of groups is dynamically determined according to the video coding parameters, including but not limited to: GOP size, video frame rate, video coding standard.
[0032] Step A100 includes:
[0033] Obtain the boundary information of the encrypted video through the video structure of the encrypted video, divide the encrypted video through the boundary information to obtain a plurality of groups, and determine the number of groups of the encrypted video according to the coding parameters of the encrypted video.
[0034] In this embodiment, the size of each group is determined by the video structure. When the size of the group corresponding to an encrypted video for one digest is smaller, the number of groups is more. Then, for the total encrypted video, more digests need to be generated. During authentication, the position of the incorrect data can be known more precisely, and the corresponding calculation amount will increase; conversely, when the size of the group corresponding to an encrypted video for one digest is larger, the number of groups is less. Then, for all encryption results, fewer digests need to be generated. During authentication, the position of the incorrect data is known more broadly, and the corresponding calculation amount is less.
[0035] Step A200: Generate a digest for each group through the SM3 algorithm to obtain a plurality of first digest values;
[0036] Step A300: Encrypt and calculate all the first digest values through the SM2 public key to obtain a video signature.
[0037] In this embodiment, while encrypting the video data, multiple groups of encryption results are calculated in parallel to obtain the digest value corresponding to each group. At the same time, each digest value is signed until the last digest value is input, and the digest signature is completed to obtain a video signature. This parallel processing improves the efficiency of data processing and provides the ability to verify data integrity.
[0038] After calculating the video signature, it is not necessary to transmit all the digest values during transmission. Only the video signature needs to be transmitted, which can ensure the security of the digest at the same time. If only the digest value is transmitted and an error occurs during the transmission of the digest value, the data recipient will not be able to verify it.
[0039] Step S300: Send the encrypted data to the data recipient, where the encrypted data is used to trigger the data recipient to perform decryption calculations and restore the video data through multi-level authentication.
[0040] In the step S300, performing decryption calculations and restoring the video data through multi-level authentication includes:
[0041] Step B100: Calculate the digest of the corresponding group in the encrypted video through the SM3 algorithm to obtain multiple second digest values;
[0042] Step B200: Decrypt and calculate the video signature through the SM2 private key to obtain multiple first digest values, where the SM2 private key is obtained by the data recipient;
[0043] Step B300: Decrypt and calculate the encrypted key through the SM2 private key to obtain the data key;
[0044] Step B400: Perform video authentication verification through the first digest value and the second digest value to obtain a verification result, and decrypt the encrypted video through the verification result and the data key to restore the video data.
[0045] The B400 includes:
[0046] Step B401: Compare and verify the first digest value and the second digest value of each group;
[0047] Step B402: If the first digest value and the second digest value of any group are different, the group is invalid and no decryption calculation is performed on this group;
[0048] Step B403: If the first digest value and the second digest value of any group are the same, the group is valid, and decrypt the group through the data key to restore the video data corresponding to this group.
[0049] In this embodiment, the first digest value and the second digest value are used for the integrity verification of the video data. The abnormality of each group of data can be located through the corresponding digest value, and there is no need to verify the entire video stream, which improves the speed of data processing.
[0050] Specifically, decrypt the groups that pass the comparison verification and do not decrypt the groups that do not pass. Calculating multiple groups of digest values is actually to subdivide the verification interval. When the verification fails, there is no need to discard the entire video data.
[0051] In summary, the encryption and decryption method with multi-level authentication designed by the present invention uses the Chinese commercial cryptography algorithms SM2, SM4, and SM3 for highly secure video data encryption and verification, ensuring the high security of surveillance video data during storage and transmission, while maintaining high-efficient data processing performance, and is very suitable for surveillance scenarios that require high-level security protection.
[0052] Embodiment 2:
[0053] This embodiment provides a hybrid encryption and decryption system for surveillance video streams based on multi-level authentication. The system includes:
[0054] A data communication end for data acquisition, data transmission, and task scheduling;
[0055] A programmable logic end for encryption and decryption processing of video data.
[0056] In this embodiment, the system adopts a heterogeneous computing architecture, that is, communication control and task scheduling are implemented at the data communication end, and data processing is implemented at the programmable logic end. At the same time, the system can be implemented on multiple FPGA platforms. At the same time, in this embodiment, the data communication end is abbreviated as the PS end, and the programmable logic end is abbreviated as the PL end.
[0057] The data communication end includes:
[0058] A data acquisition module for acquiring the data key and video data sent by the data sender. The data key is generated by a random number generator or obtained from an external memory, and the video data is local surveillance video data or real-time surveillance video stream data;
[0059] In this embodiment, both internal key generation and external key input are supported. The built-in random number generator of the system is used to generate the data key. The generated data key will be securely stored in the internal storage unit of the FPGA to avoid the risk of data key leakage. And the system designs an interface to allow users or the PS end to perform key transmission.
[0060] A data sending module for sending the encrypted data to the data receiver. The encrypted data is used to trigger the data receiver to perform decryption calculation and restore the video data through multi-level authentication.
[0061] The PS end acts as a central control unit to coordinate the work of different components in the system, manage data flow and task allocation. For example, reading data from an external storage device, managing and coordinating encryption and decryption tasks, outputting transmission and storage control, etc.
[0062] In terms of communication control, the PS side transfers data with the PL side through the AXI bus, is responsible for managing peripheral interfaces (such as SD cards, network interfaces, etc.), and obtains raw data and keys from external devices. And a custom data header containing data category information is added before the data to be actually transmitted, obtaining a custom data frame to facilitate the PL side to correctly parse and process the incoming data.
[0063] In terms of task scheduling, the PS side runs an embedded operating system or a real-time operating system, and is responsible for dynamically scheduling tasks according to data processing requirements. First, it obtains the data key, writes it into the DDR through the AXI bus, controls the PL side module to start, and waits for it to complete the processing of the data key. When the PL side finishes processing the data key and writes it back to the DDR, the PS side reads and stores it. Then it obtains the plaintext data, also writes it into the DDR, then controls the PL side module to start, and waits for it to complete the processing of the current plaintext data. When the PL side finishes processing the current plaintext data and writes it back to the DDR, the PS reads and stores it, and then repeats the above plaintext encryption operation until the encryption is completed, where the plaintext data represents video data.
[0064] The data acquisition module on the PS side can not only acquire the data key and video data sent by the data sender, but also acquire the data processed by the PL side, and can also send the acquired data to the PL side and external devices through the data sending module.
[0065] The programmable logic side includes:
[0066] A data encryption module for performing hybrid encryption on the data key and the video data through an encryption algorithm to obtain encrypted data, where the encrypted data includes an encryption key, an encrypted video, and a video signature;
[0067] A data decryption module for performing decryption calculations and restoring video data through multi-level authentication.
[0068] In this embodiment, the PL side is responsible for accelerating compute-intensive tasks, deploying functions such as video encryption, decryption, and data verification in this part, and can realize generating an encryption key, encrypting or decrypting data, and calculating the digest and signature. And the processed data is also transmitted back to the PS side through the AXI bus.
[0069] As Figure 2 shown, through the PS side and the PL side, finally, the video data enters the PS side from the external input device, and the PS side transmits the data to the PL side through the AXI high-speed interface. In the PL side, the data undergoes encryption, signature, and authentication processing, and then is transmitted back to the PS side. The PS side sends the processed data to the storage device or transmits it through the network interface.
[0070] The data encryption module includes:
[0071] A first encryption unit, configured to obtain an SM2 public key, perform an encryption calculation on the data key through the SM2 public key to obtain an encrypted key, and the SM2 public key is obtained through the SM2 algorithm;
[0072] A second encryption unit, configured to perform an encryption calculation on the video data through the SM4 algorithm to obtain an encrypted video;
[0073] A signature calculation unit, configured to perform a signature calculation on the encrypted video to obtain a video signature;
[0074] The data decryption module includes:
[0075] A digest calculation unit, configured to calculate the digest of the corresponding group in the encrypted video through the SM3 algorithm to obtain a plurality of second digest values;
[0076] A first decryption unit, configured to perform a decryption calculation on the video signature through the SM2 private key to obtain a plurality of first digest values, and the SM2 private key is obtained by the data receiver;
[0077] A second decryption unit, configured to perform a decryption calculation on the encrypted key through the SM2 private key to obtain a data key;
[0078] A third decryption unit, configured to perform video authentication verification through the first digest value and the second digest value to obtain a verification result, and decrypt the encrypted video through the verification result and the data key to restore the video data.
[0079] In this embodiment, during the encryption and decryption process of video data, the system realizes parallel processing of read and write operations. Specifically, it can encrypt or decrypt while reading video data, and immediately write the encrypted or decrypted output to a specified output path through the PS side, such as local storage, a display device, or a network transmission buffer. This process meets the requirements of real-time processing, enabling the system to continuously process new input data while encrypting or decrypting.
[0080] Through the optimized design of the overall architecture and in combination with the national cryptography algorithm solution, the encryption transmission and authentication process of the video are fully integrated into the programmable logic end and data communication end parts of the FPGA, providing an efficient and secure video encryption, decryption, and verification solution. By adopting a multi-level authentication mechanism and combining the SM2 algorithm, SM4 algorithm, and SM3 algorithm, the identities of users and devices are strictly verified. The PL side is responsible for the hybrid encryption and preliminary processing of data, while the PS side is responsible for the storage of encrypted data and further security management, effectively utilizing the advantages of the dual-core processor architecture to improve the overall performance and security of the system.
[0081] It should be noted that regarding the system in the above embodiments, the specific manners in which each module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated herein.
[0082] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
[0083] The above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or replacements, which should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.
Claims
1. A hybrid encryption and decryption method for surveillance video stream based on multi-level authentication, characterized in that: include: Obtaining a data key and video data sent by a data sender, wherein the data key is generated by a random number generator or obtained from an external memory, and the video data is local monitoring video data or real-time monitoring video stream data; The data key and the video data are mixed and encrypted by an encryption algorithm to obtain encrypted data, wherein the encrypted data includes an encryption key, an encrypted video and a video signature; The encrypted data is sent to a data receiver, and the encrypted data is used to trigger the data receiver to perform decryption calculations and restore video data through multi-level authentication.
2. The method for hybrid encryption and decryption of surveillance video streams based on multi-level authentication according to claim 1 is characterized in that , the data key and the video data are mixed and encrypted by an encryption algorithm to obtain encrypted data, including: Obtaining an SM2 public key, performing encryption calculation on the data key using the SM2 public key to obtain an encryption key, wherein the SM2 public key is obtained using an SM2 algorithm; Perform encryption calculation on the video data by using the SM4 algorithm to obtain an encrypted video; Perform signature calculation on the encrypted video to obtain a video signature.
3. The monitoring video stream hybrid encryption and decryption method based on multi-level authentication according to claim 2 is characterized in that , the step of performing signature calculation on the encrypted video to obtain a video signature includes: Performing GOP boundary grouping on the encrypted video according to the video structure to obtain a plurality of groups, wherein each of the groups includes a plurality of image frames; Generate a digest of each of the groups using the SM3 algorithm to obtain a plurality of first digest values; All first summary values are encrypted and calculated using the SM2 public key to obtain a video signature.
4. The method for hybrid encryption and decryption of surveillance video streams based on multi-level authentication according to claim 3 is characterized in that , performing GOP boundary grouping on the encrypted video according to the video structure to obtain multiple groups, including: The boundary information of the encrypted video is obtained through the video structure of the encrypted video, the encrypted video is divided according to the boundary information to obtain a plurality of groups, and the number of the groups of the encrypted video is determined according to the encoding parameters of the encrypted video.
5. The method for hybrid encryption and decryption of surveillance video streams based on multi-level authentication according to claim 3 is characterized in that , the decryption calculation is performed, and the video data is restored through multi-level authentication, including: Calculate the digest of the corresponding group in the encrypted video by using the SM3 algorithm to obtain multiple second digest values; Decrypting and calculating the video signature by using an SM2 private key to obtain a plurality of first summary values, wherein the SM2 private key is obtained by a data receiving party; Decrypt the encryption key using the SM2 private key to obtain a data key; The video authentication is performed using the first digest value and the second digest value to obtain a verification result, and the encrypted video is decrypted using the verification result and the data key to restore the video data.
6. The method for hybrid encryption and decryption of surveillance video streams based on multi-level authentication according to claim 5 is characterized in that , the video authentication is performed by using the first digest value and the second digest value to obtain a verification result, and the encrypted video is decrypted by using the verification result and the data key to restore the video data, including: Compare and verify the first digest value and the second digest value of each group; If the first digest value and the second digest value of any group are different, the group is invalid and no decryption calculation is performed on the group; If the first digest value and the second digest value of any group are the same, the group is valid, and the group is decrypted and calculated using the data key to restore the video data corresponding to the group.
7. A surveillance video stream hybrid encryption and decryption system based on multi-level authentication, characterized in that: include: Data communication terminal, used for data acquisition, data transmission and task scheduling; Programmable logic side, used for encryption and decryption processing of video data.
8. The surveillance video stream hybrid encryption and decryption system based on multi-level authentication according to claim 7 is characterized in that: The data communication terminal comprises: A data acquisition module is used to acquire a data key and video data sent by a data sender, wherein the data key is generated by a random number generator or acquired from an external memory, and the video data is local monitoring video data or real-time monitoring video stream data; The data sending module is used to send encrypted data to a data receiver, wherein the encrypted data is used to trigger the data receiver to perform decryption calculations and restore video data through multi-level authentication.
9. The surveillance video stream hybrid encryption and decryption system based on multi-level authentication according to claim 8 is characterized in that: The programmable logic terminal comprises: A data encryption module, used to perform mixed encryption on the data key and the video data through an encryption algorithm to obtain encrypted data, wherein the encrypted data includes an encryption key, an encrypted video and a video signature; The data decryption module is used to perform decryption calculations and restore video data through multi-level authentication.
10. The surveillance video stream hybrid encryption and decryption system based on multi-level authentication according to claim 9 is characterized in that: The data encryption module comprises: A first encryption unit is used to obtain an SM2 public key, and perform encryption calculation on the data key by using the SM2 public key to obtain an encryption key, wherein the SM2 public key is obtained by using an SM2 algorithm; A second encryption unit is used to perform encryption calculation on the video data through an SM4 algorithm to obtain an encrypted video; A signature calculation unit, used to perform signature calculation on the encrypted video to obtain a video signature; The data decryption module comprises: A digest calculation unit, used to calculate the digest of the corresponding group in the encrypted video by using the SM3 algorithm to obtain a plurality of second digest values; A first decryption unit, configured to perform decryption calculation on the video signature by using an SM2 private key to obtain a plurality of first digest values, wherein the SM2 private key is obtained by a data receiving party; A second decryption unit, used to perform decryption calculation on the encryption key by using the SM2 private key to obtain a data key; The third decryption unit is used to perform video authentication verification using the first digest value and the second digest value to obtain a verification result, and decrypt the encrypted video using the verification result and the data key to restore the video data.