Bit stream, bit stream signature and detection method
By independently calculating the summary data of the access unit in the bitstream of audio and video content and limiting the hash period, the problem of unknown cache space size during the signature or authentication process is solved, and the signature or authentication efficiency and security are improved.
Patent Information
- Application Number
- CN202410104632.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-12
- Filing Date
- 2024-01-24
- Publication Date
- 2025-06-13
AI Technical Summary
During the signature or authentication process of audio and video content, the reserved cache space cannot be determined, resulting in low signature or authentication efficiency.
By independently calculating and adding the digest data of each access unit in the bitstream, and positioning the maximum number of access units in the stream segment through hash periods, the maximum footprint of the data is clearly confirmed, thereby accurately reserving cache space.
It improves the signature or authentication efficiency of bitstreams, ensures accurate reservation and effective detection of authentication data, and enhances the security and integrity of audio and video content.
Smart Images

Figure CN120151569A_ABST
Abstract
Description
[0001] This application claims the priority of a Chinese patent application with the application number 202311725386.8 and the application title "A Bitstream, Signature and Detection Method of Bitstream" filed with the National Intellectual Property Administration on December 12, 2023, the entire content of which is incorporated herein by reference. Technical Field
[0002] Embodiments of this application relate to the field of media technology, and in particular, to a bitstream, bitstream signature and detection method. Background Art
[0003] In many audio and video coding and decoding scenarios (such as monitoring, live broadcast, on-demand, etc.), there are certain requirements for the authenticity and integrity of audio and video content; therefore, in order to ensure the security of audio and video content during transmission and prevent the audio and video content from being tampered with during transmission, it is necessary to sign the audio and video content.
[0004] Currently, the process of signing a bitstream is as follows: generate the digest corresponding to each access unit in the bitstream, and then use a digital signature algorithm to sign the digest, and then write the signature into the bitstream. However, during the signature or authentication process, the signatures and digests corresponding to multiple access units are stored in one area, and the size of this area is unknown, resulting in an inability to determine the size of the reserved cache space for caching the signatures and digests when signing or authenticating the bitstream, and thus the efficiency of bitstream signature or authentication is relatively low. Summary of the Invention
[0005] This application provides a bitstream, bitstream signature and detection method to solve the problem that during the signature or authentication process, the signatures and digests corresponding to multiple access units are stored in one area, and the size of this area is unknown, resulting in an inability to determine the size of the reserved cache space for caching the signatures and digests when authenticating the audio and video content, leading to a relatively low authentication efficiency of the audio and video content.
[0006] This application adopts the following technical solutions.
[0007] In a first aspect, embodiments of this application provide a bitstream signature method. This bitstream signature method is executed by a computing device or a chip in a computing device. For example, the computing device may refer to a mobile phone or a computer, etc. Exemplarily, the method includes: the computing device obtains a set of security parameters and authentication data, and then outputs a bitstream, which includes the set of security parameters and authentication data. Among them, the set of security parameters includes a hash period, which is used to indicate the maximum number of access units included in a bitstream segment, and the authentication data includes signature data and the digest of each access unit in a group of access units. The signature data is obtained by signing the digest of each access unit in a group of access units, and a group of access units includes at least one access unit in a bitstream segment.
[0008] In this application, the computing device independently generates digest data for each access unit and adds the digest data of each access unit to the bitstream. In this way, the authentication side can independently authenticate each access unit. Therefore, even if some access units are lost (frames are dropped), other access units can still be authenticated. Moreover, by limiting the maximum number of access units in a bitstream segment, the computing device can limit the number of digest data of access units included in an authentication data, and further limit the maximum occupied space of an authentication data, which is beneficial to clearly defining the maximum occupied space of the authentication data, realizing more accurate reservation of buffer space for the authentication data, and improving the signature or authentication efficiency of the bitstream.
[0009] In a possible implementation, the authentication data is located after the access unit arranged in the decoding order in a group of access units associated with the authentication data, and before the authentication data corresponding to the access units in the next hash period.
[0010] In this application, by limiting the position of the authentication data in the bitstream, the scope of action of the authentication data can be better determined. This can avoid the problem that the authentication data corresponding to a group of access units exceeds the above range, resulting in the inability to find the corresponding authentication data when authenticating the aforementioned group of access units, and further leading to the untrustworthiness and subsequent discarding of the group of access units, which is beneficial to improving the availability of the access units.
[0011] In a possible implementation, the security parameter set further includes: indication information, which is used to indicate the number of authentication data included within the scope of action of the security parameter set. The scope of action of this security parameter set is the random access segment where the security parameter set is located in the bitstream.
[0012] In this application, by defining indication information in the security parameter set to clarify the number of authentication data that should be included within the scope of action of the security parameter set, during authentication, the number of authentication data that should be present can be compared with the actually received number, so as to efficiently detect the loss of authentication data and improve the efficiency of detecting the loss of authentication data.
[0013] In a possible implementation, the authentication data carries an identifier, which occupies M bits, where M is an integer greater than or equal to 2. This identifier is used to distinguish 2 to the power of M consecutive authentication data in the bitstream.
[0014] In this application, since the identifier of the authentication data occupies M bits, it is possible to distinguish 2 to the power of M consecutive authentication data in the bitstream, which is beneficial to improving the fault tolerance of the position of the authentication data in the bitstream. That is, there can be more other authentication units between the authentication data and the group of access units corresponding to this authentication data, without affecting the authentication of the aforementioned group of access units by this authentication data.
[0015] In a possible implementation, there are P access units between the authentication data and the access unit that is the last in the decoding order among a group of access units associated with the authentication data; where 0 ≤ P ≤ (2 M -1)*Q, and Q is the maximum number indicated by the hash period.
[0016] In a second aspect, an embodiment of the present application further provides a bitstream signature method. This bitstream signature method is executed by a computing device or a chip in the computing device. For example, the computing device may refer to a mobile phone or a computer, etc. Exemplarily, the method includes: The computing device obtains a set of security parameters and authentication data, and then outputs the set of security parameters. Among them, the bitstream includes the set of security parameters and the authentication data. The set of security parameters includes indication information, and the indication information is used to indicate the number of authentication data included within the scope of the set of security parameters. The scope of the set of security parameters is the random access segment where the set of security parameters is located in the bitstream, and the authentication data includes signature data and the digest of each access unit in a group of access units, and the signature data is obtained by signing the digest of each access unit in a group of access units.
[0017] In a possible implementation, the set of security parameters further includes a hash period, and the hash period is used to indicate the maximum number of access units included in a bitstream segment.
[0018] In a possible implementation, the authentication data is located after the access unit that is the last in the decoding order among a group of access units associated with the authentication data, and is located before the authentication data corresponding to the access units within the next hash period.
[0019] In a possible implementation, the authentication data carries an identifier, and the identifier occupies M bit positions, where M is an integer greater than or equal to 2, and the identifier is used to distinguish 2 to the power of M consecutive authentication data in the bitstream.
[0020] In a possible implementation, there are P access units between the authentication data and the access unit that is the last in the decoding order among a group of access units associated with the authentication data; where 0 ≤ P ≤ (2 M -1)*Q, and Q is the maximum number indicated by the hash period.
[0021] For more possible implementations of the second aspect, reference may be made to the description of the first aspect or any possible implementation in the first aspect above, and details are not described herein.
[0022] In a third aspect, an embodiment of the present application provides a bitstream. The bitstream includes a plurality of bitstream segments, authentication data, and a security data set. The security parameter set includes a hash period, and the hash period is used to indicate the maximum number of access units included in a bitstream segment. The authentication data includes signature data and a digest of each access unit in a set of access units. The signature data is obtained by signing the digest of each access unit in a set of access units. The set of access units includes at least one access unit in a bitstream segment.
[0023] In a possible implementation, the authentication data is located after the access unit arranged last in decoding order in a set of access units associated with the authentication data, and before the authentication data corresponding to the access units in the next hash period.
[0024] In a possible implementation, the security parameter set further includes: indication information, and the indication information is used to indicate the number of authentication data included within the scope of the security parameter set. The scope of the security parameter set is the random access segment in the bitstream where the security parameter set is located.
[0025] In a possible implementation, the authentication data carries an identifier, the identifier occupies M bits, M is an integer greater than or equal to 2, and the identifier is used to distinguish 2 to the power of M consecutive authentication data in the bitstream.
[0026] In a possible implementation, there are P access units between the authentication data and the access unit arranged last in decoding order in a set of access units associated with the authentication data; where 0 ≤ P ≤ (2 M - 1)*Q, and Q is the maximum number indicated by the hash period.
[0027] In a fourth aspect, an embodiment of the present application further provides a bitstream. The bitstream includes: a plurality of bitstream segments, authentication data, and a security data set. The security parameter set includes indication information, and the indication information is used to indicate the number of authentication data included within the scope of the security parameter set. The scope of the security parameter set is the random access segment in the bitstream where the security parameter set is located. The authentication data includes signature data and a digest of each access unit in a set of access units. The signature data is obtained by signing the digest of each access unit in a set of access units. The set of access units includes at least one access unit in a bitstream segment.
[0028] In a possible implementation, the security parameter set includes a hash period, and the hash period is used to indicate the maximum number of access units included in a bitstream segment.
[0029] In a possible implementation, the authentication data is located after the access unit arranged last in decoding order in a set of access units associated with the authentication data, and before the authentication data corresponding to the access units in the next hash period.
[0030] In a possible implementation, the authentication data carries an identifier that occupies M bits, where M is an integer greater than or equal to 2. The identifier is used to distinguish 2 to the power of M consecutive authentication data in the bitstream.
[0031] In a possible implementation, there are P access units between the authentication data and the last access unit in the decoding order among a group of access units associated with the authentication data; where 0 ≤ P ≤ (2 M - 1)*Q, and Q is the maximum number indicated by the hash period.
[0032] For more possible implementations of the fourth aspect, reference may be made to the description of the third aspect or any possible implementation in the third aspect above, which will not be elaborated here.
[0033] Fifth aspect, the present application provides a bitstream detection method. The bitstream detection method is executed by a computing device or a chip in the computing device. For example, the computing device may refer to a mobile phone or a computer, etc. Exemplarily, the method includes: the computing device obtains a set of security parameters and authentication data in the bitstream. If there are access units participating in the signature in a hash period, then in the next hash period in the direction of the decoding order of the bitstream in the current hash period, the authentication data is detected. Furthermore, if the authentication data cannot be detected, it is determined that the authentication data is lost; if the authentication data is detected, it is determined that the authentication data is not lost. Among them, the set of security parameters includes a hash period, and the hash period is used to indicate the maximum number of access units included in a bitstream segment. The authentication data includes signature data and the digest of each access unit in a group of access units. The signature data is obtained by signing the digest of each access unit in a group of access units. A group of access units includes at least one access unit in a bitstream segment.
[0034] In a possible implementation, if there are access units participating in the signature in a group of access units, then after the first access unit that is the last in the decoding order in the group of access units, and in the bitstream between the second access unit that is arranged after the first access unit in the decoding order of the bitstream, the authentication data is detected; there are X access units between the second access unit and the first access unit, and X is the maximum number indicated by the hash period.
[0035] For more content about the authentication data or the set of security parameters, reference may be made to the description of the authentication data or the set of security parameters in the first aspect above, which will not be elaborated here.
[0036] Sixth aspect, the present application provides a bitstream detection method. The bitstream detection method is executed by a computing device or a chip in the computing device. For example, the computing device may be a mobile phone or a computer, etc. Exemplarily, the method includes: the computing device obtains a security parameter set and authentication data in the bitstream. If there are access units participating in signature in a hash period, the authentication data is detected in the (2^M - 1)-th hash period after the current hash period along the bitstream decoding order direction. Then, if the authentication data cannot be detected, it is determined that the authentication data is lost; if the authentication data is detected, it is determined that the authentication data is not lost. Among them, the security parameter set includes a hash period, and the hash period is used to indicate the maximum number of access units included in a bitstream segment. The authentication data includes signature data and the digest of each access unit in a group of access units, and the signature data is obtained by signing the digest of each access unit in a group of access units. The authentication data carries an identifier, the identifier occupies M bit positions, M is an integer greater than or equal to 2, and the identifier is used to distinguish 2^M consecutive authentication data in the bitstream. A group of access units includes at least one access unit in a bitstream segment.
[0037] In a possible implementation manner, if there are access units participating in signature in a group of access units, the authentication data is detected in the bitstream after the first access unit arranged in the last order of decoding in this group of access units and before the second access unit arranged after the first access unit along the decoding order of the bitstream; there are N access units between the second access unit and the first access unit, and N = (2 M - 1)*Q, and Q is the maximum number indicated by the hash period.
[0038] For more content about the authentication data or the security parameter set, reference may be made to the description of the authentication data or the security parameter set in the first aspect above, which will not be elaborated here.
[0039] Seventh aspect, the present application provides a bitstream detection method. The bitstream detection method is executed by a computing device or a chip in the computing device. For example, the computing device may be a mobile phone or a computer, etc. Exemplarily, the method includes: the computing device obtains the security parameter set in the bitstream and the number of authentication data within the scope of the security parameter set, and then determines the loss situation of the authentication data according to the indication information and the number of authentication data within the scope of the security parameter set. Among them, the scope of the security parameter set is the random access segment where the security parameter set is located in the bitstream, and the security data set includes indication information, and the indication information is used to indicate the number of authentication data that should be included within the scope of the security parameter set.
[0040] In a possible implementation, the computing device determines the loss situation of the authentication data according to the indication information and the number of authentication data within the scope of the security parameter set, including: if the number of authentication data indicated by the indication information is consistent with the number of authentication data in the security parameter set, the authentication data is not lost; if the number of authentication data indicated by the indication information is inconsistent with the number of authentication data in the security parameter set, the authentication data is lost.
[0041] For more content of the authentication data or the security parameter set, reference may be made to the description of the authentication data or the security parameter set in the first aspect above, which will not be elaborated here.
[0042] In an eighth aspect, the present application provides a bitstream signature device. The bitstream signature device includes a module for executing the method of the first aspect or any possible implementation manner in the first aspect, or the bitstream signature device includes a module for executing the method of the second aspect or any possible implementation manner in the second aspect.
[0043] In a ninth aspect, the present application provides a bitstream detection device. The bitstream detection device includes a module for executing the method of the fifth aspect or any possible implementation manner in the fifth aspect, or the bitstream detection device includes a module for executing the method of the sixth aspect or any possible implementation manner in the sixth aspect, or the bitstream detection device includes a module for executing the method of the seventh aspect or any possible implementation manner in the seventh aspect.
[0044] In a tenth aspect, the present application provides a signature and authentication system, which includes a signature end and an authentication end. The signature end is used to execute the bitstream signature method in the first aspect or any possible implementation manner in the first aspect, or execute the bitstream signature method in the second aspect or any possible implementation manner in the second aspect. The authentication end is used to execute the bitstream detection method in the fifth aspect or any possible implementation manner in the fifth aspect, or execute the bitstream detection method in the sixth aspect or any possible implementation manner in the sixth aspect, or execute the bitstream detection method in the seventh aspect or any possible implementation manner in the seventh aspect.
[0045] In an eleventh aspect, an embodiment of the present application provides a computing device. It includes: a memory and a processor; the memory stores program instructions, and when the program instructions are executed by the processor, the computing device executes the bitstream signature method in the first aspect or any possible implementation manner in the first aspect, or executes the bitstream signature method in the second aspect or any possible implementation manner in the second aspect, or executes the bitstream detection method in the fifth aspect or any possible implementation manner in the fifth aspect, or executes the bitstream detection method in the sixth aspect or any possible implementation manner in the sixth aspect, or executes the bitstream detection method in the seventh aspect or any possible implementation manner in the seventh aspect.
[0046] In a twelfth aspect, an embodiment of the present application provides a chip, including one or more interface circuits and one or more processors; the one or more processors receive or send data through the one or more interface circuits, and when the one or more processors execute computer instructions, the steps of the bitstream signature method in the first aspect or any possible implementation manner of the first aspect are executed, or the steps of the bitstream signature method in the second aspect or any possible implementation manner of the second aspect are executed, the steps of the bitstream detection method in the fifth aspect or any possible implementation manner of the fifth aspect are executed, or the steps of the bitstream detection method in the sixth aspect or any possible implementation manner of the sixth aspect are executed, or the steps of the bitstream detection method in the seventh aspect or any possible implementation manner of the seventh aspect are executed.
[0047] In a thirteenth aspect, an embodiment of the present application provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program runs on a computer or a processor, the computer or the processor executes the bitstream signature method in the first aspect or any possible implementation manner of the first aspect, or executes the bitstream signature method in the second aspect or any possible implementation manner of the second aspect, or executes the bitstream detection method in the fifth aspect or any possible implementation manner of the fifth aspect, or executes the bitstream detection method in the sixth aspect or any possible implementation manner of the sixth aspect, or executes the bitstream detection method in the seventh aspect or any possible implementation manner of the seventh aspect.
[0048] In a fourteenth aspect, an embodiment of the present application provides a computer program product. The computer program product includes computer instructions, and when the computer instructions are executed by a computer or a processor, the computer or the processor executes the bitstream signature method in the first aspect or any possible implementation manner of the first aspect, or executes the bitstream signature method in the second aspect or any possible implementation manner of the second aspect, or executes the bitstream detection method in the fifth aspect or any possible implementation manner of the fifth aspect, or executes the bitstream detection method in the sixth aspect or any possible implementation manner of the sixth aspect, or executes the bitstream detection method in the seventh aspect or any possible implementation manner of the seventh aspect.
[0049] In a fifteenth aspect, an embodiment of the present application provides a computer-readable storage medium. The computer-readable storage medium stores the bitstream in the third aspect or any possible implementation manner of the third aspect, or stores the bitstream in the fourth aspect or any possible implementation manner of the fourth aspect.
[0050] Sixteenth aspect, an embodiment of the present application provides a device for storing a bitstream. The device includes: a receiver and at least one storage medium. The receiver is configured to receive the bitstream in the third aspect or any possible implementation manner of the third aspect, or to receive the bitstream in the fourth aspect or any possible implementation manner of the fourth aspect; the at least one storage medium is configured to store the bitstream.
[0051] Seventeenth aspect, an embodiment of the present application provides a device for transmitting a bitstream. The device includes: a transmitter and at least one storage medium. The at least one storage medium is configured to store the bitstream in the third aspect or any possible implementation manner of the third aspect, or to store the bitstream in the fourth aspect or any possible implementation manner of the fourth aspect; the transmitter is configured to obtain the bitstream from the storage medium and send the bitstream to the terminal device through a transmission medium.
[0052] Eighteenth aspect, an embodiment of the present application provides a system for distributing a bitstream. The system includes: at least one storage medium, configured to store at least one bitstream in the third aspect or any possible implementation manner of the third aspect, or to store at least one bitstream in the fourth aspect or any possible implementation manner of the fourth aspect; a streaming media device, configured to obtain a target bitstream from the at least one storage medium and send the target bitstream to the terminal device, where the streaming media device includes a content server or a content distribution server.
[0053] Regarding the beneficial effects of the second aspect to the eighteenth aspect, reference may be made to the description of any implementation manner in the first aspect or the second aspect, which will not be elaborated here. Based on the implementation manners provided in the above aspects of the present application, further combinations can be made to provide more implementation manners. Description of the Drawings
[0054] Figure 1 It is a schematic diagram of an application scenario provided by the present application;
[0055] Figure 2 It is a schematic diagram of the structure of a signature and authentication system provided by the present application;
[0056] Figure 3 It is a flowchart of a method for signing a bitstream provided by the present application Figure 1 ;
[0057] Figure 4 It is a bitstream illustration provided by the present application Figure 1 ;
[0058] Figure 5 It is a flowchart of a method for signing a bitstream provided by the present application Figure 2 ;
[0059] Figure 6 It is a bitstream illustration provided by the present applicationFigure 2 ;
[0060] Figure 7 Schematic flowchart of a bitstream detection method provided for this application;
[0061] Figure 8 Schematic diagram of a bitstream signature device provided for this application;
[0062] Figure 9 Schematic diagram of a bitstream detection device provided for this application;
[0063] Figure 10 Schematic diagram of the structure of a computing device provided for this application. Detailed implementation manners
[0064] This application provides a bitstream signature method, which includes: obtaining a security parameter set and authentication data, and outputting a bitstream. The bitstream includes the security parameter set and the authentication data, and the security parameter set includes a hash period. The hash period is used to indicate the maximum number of access units included in a bitstream segment, and the authentication data includes signature data and a digest of each access unit in a group of access units. The signature data is obtained by signing the digest of each access unit in a group of access units, and a group of access units includes at least one access unit in a bitstream segment.
[0065] In this application, the computing device independently generates digest data for each access unit and adds the digest data of each access unit to the bitstream. In this way, the authentication end can independently authenticate each access unit; therefore, even if some access units are lost (frames are dropped), other access units can still be authenticated. In addition, by limiting the maximum number of access units in a bitstream segment, the computing device can limit the number of digest data of access units included in an authentication data, and further limit the maximum occupied space of an authentication data, which is beneficial to clarify the maximum occupied space of the authentication data, realize accurate reservation of cache space for the authentication data, and improve the efficiency of signing or authenticating the bitstream.
[0066] Next, the technical solutions in the embodiments of this application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the following described embodiments are some, but not all, of the embodiments of this application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the protection scope of this application.
[0067] The term "and / or" in this article is merely a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone.
[0068] In the description of the embodiments of the present application, the terms "first", "second", etc. in the specification and claims are used to distinguish different objects, rather than to describe a specific order of the objects. For example, the first target object, the second target object, etc. are used to distinguish different target objects, rather than to describe a specific order of the target objects.
[0069] In the embodiments of the present application, words such as "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design solution described as "exemplarily" or "for example" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplarily" or "for example" is intended to present the relevant concepts in a specific manner.
[0070] In the description of the embodiments of the present application, unless otherwise specified, the meaning of "a plurality of" refers to two or more. For example, a plurality of processing units refers to two or more processing units; a plurality of systems refers to two or more systems.
[0071] The following provides an introduction to the related art.
[0072] A data unit is the basic syntax structure of an encoded bitstream. It can be a Network Abstract Layer unit (NAL unit) or an access unit.
[0073] A NAL unit is a syntax structure that contains a type indication of the subsequent data and the number of bytes included (located in the NAL header). The data appears in the form of a raw byte sequence payload (RBSP), and when necessary, it also includes scattered anti-counterfeiting bytes. For example, a NAL unit includes a security parameter set NAL unit (which can also be referred to as a security data set) or an authentication data NAL unit (which can also be referred to as authentication data).
[0074] An access unit (AU) is a set of NAL units that are interrelated according to specified rules and are consecutive in decoding order, forming a compressed video bitstream (which can also be referred to as a bitstream). A bitstream represents the binary data stream formed by encoded image / audio frames.
[0075] It should be noted that from another dimension, a data unit can also include an encoded image.
[0076] A coded picture is the encoded representation of a frame of an image.
[0077] Security Parameter Set (SEC), which contains configuration parameters required for encrypting and authenticating a bitstream.
[0078] It should be noted that the present application does not group data units, but for the convenience of description, the term "a group of data units" is used.
[0079] Exemplarily, a group of data units may include n data units, all of which are data units to be authenticated, where n is a positive integer. Correspondingly, the authentication data may include n digest data, and the n digest data correspond one-to-one with the n data units. Exemplarily, "a group of data units" may also be described as "n data units".
[0080] Exemplarily, multiple digest data of a group of data units can form a digest data list; that is to say, the authentication data may include a digest data list.
[0081] Exemplarily, the authentication data may be Auth.
[0082] Exemplarily, the signature data may be signature.
[0083] Exemplarily, the digest data may also be referred to as authentication digest data or digest.
[0084] Exemplarily, the bitstream may be an audio compression bitstream (or referred to as an audio compression code stream) or a video compression bitstream (or referred to as a video compression code stream), and the present application does not limit this. The present application takes the signature and detection of a video compression bitstream as an example for illustration.
[0085] As Figure 1 shown, Figure 1 is a schematic diagram of the application scenario provided by the present application. Figure 1 Shows a monitoring scenario, a live broadcast scenario, and an on-demand scenario.
[0086] Referring to Figure 1 , exemplarily, in the monitoring scenario, the camera 11 can sign the monitoring video bitstream to obtain the signed monitoring video bitstream 101. Then, the signed monitoring video bitstream 101 is sent to the laptop 13 through the network 12. After that, the laptop 13 can authenticate the signed monitoring video bitstream 101 to obtain the authentication result 105 and display it, as well as play the monitoring video 104.
[0087] Referring to Figure 1, Exemplarily, in a live streaming scenario, the mobile phone 14 can sign the live video bitstream to obtain the signed live video bitstream 102. Then, the signed live video bitstream 102 is sent to the mobile phone 15 via the network 12. After that, the mobile phone 15 can authenticate the signed live video bitstream 102 to obtain the authentication result 107 and display it, and play the live video 106.
[0088] Referring to Figure 1 , Exemplarily, in an on-demand scenario, the personal computer 16 can sign the on-demand video bitstream to obtain the signed on-demand video bitstream 103. Then, the signed on-demand video bitstream 103 is sent to the mobile phone 17 via the network 12. After that, the mobile phone 17 can authenticate the signed on-demand video bitstream 103 to obtain the authentication result 109 and display it, and play the on-demand video 108.
[0089] It should be understood that the present application can also be used in other scenarios of audio and video encoding and decoding, such as digital content trust scenarios, etc., and the present application does not limit this.
[0090] As Figure 2 shown, Figure 2 is a schematic structural diagram of the signature and authentication system provided by the present application. The authentication and signature processes in the above Figure 2 are described in Figure 1 .
[0091] Referring to Figure 2 , Exemplarily, the signature and authentication system 200 can include a signature end 210 and an authentication end 220. The signature end 210 can also be referred to as a front-end device, and the authentication end 220 can also be referred to as a back-end device.
[0092] For example, the signature end 210 can be the camera 11, the mobile phone 14, and the personal computer 16 in the above Figure 1 , and the authentication end 220 can be the laptop computer 13, the mobile phone 15, and the mobile phone 17 in the above Figure 1 .
[0093] It should be understood that the same terminal device can be used as both the signature end 210 and the authentication end 220, and the present application does not limit this.
[0094] Continuing to refer to Figure 2 , Exemplarily, after the signature end 210 obtains the video data 201, it can perform video encoding 21 on the video data 201 to obtain a bitstream 202; and perform video signature 22 on the bitstream 202 to obtain a signed bitstream 203.
[0095] For example, the video data 201 can be the above Figure 1The surveillance video captured by the camera 11, the live video recorded by the mobile phone 14, or the on-demand video produced by the personal computer 16.
[0096] For example, the signed bitstream 203 can be the above-mentioned Figure 1 Signed surveillance video bitstream 101, signed live video bitstream 102, or signed on-demand video bitstream 103 in the above.
[0097] It should be noted that the two operations of video encoding 21 and video signing 22 can be executed in parallel.
[0098] In a possible implementation manner, the signing end 210 may include an encoder, and the encoder executes video encoding 21 and video signing 22. In a possible way, the signing end 210 may include an encoder and a signing module, the encoder executes video encoding 21, and the signing module executes video signing 22. In a possible way, the signing end 210 may include a signing module, and the signing module executes video encoding 21 and video signing 22.
[0099] After that, the signing end 210 can send the signed bitstream 203 to the authentication end 220.
[0100] Continuing to refer to Figure 2 , exemplarily, after the authentication end 220 receives the signed bitstream 203, it can perform video authentication 23 on the signed bitstream 203 to obtain an authentication result 205; and it can perform video decoding 24 on the bitstream 202 in the signed bitstream 203 to obtain decoded video data 204.
[0101] For example, the decoded video data 204 can be the above-mentioned Figure 1 Surveillance video 104, live video 106, or on-demand video 108 in the above.
[0102] For example, the authentication result 205 can be the above-mentioned Figure 1 Authentication result 105, authentication result 107, or authentication result 109 in the above.
[0103] It should be noted that the two operations of video authentication 23 and video decoding 24 can be executed in parallel.
[0104] In a possible implementation manner, the authentication end 220 may include a decoder, and the decoder executes video decoding 24 and video authentication 23.
[0105] In a possible implementation manner, the authentication end 220 may include a decoder and an authentication module, the decoder executes video decoding 24, and the authentication module executes video authentication 23.
[0106] In a possible implementation, the authentication end 220 may include an authentication module, and the video decoding 24 and video authentication 23 are performed by the authentication module.
[0107] It should be noted that when the signing end 210 performs lossless encoding, the video data is the same as the decoded video data; when the signing end 210 performs lossy encoding, there are differences between the video data and the decoded video data.
[0108] It should be noted that the encoder, decoder, and authentication module may be implemented by software or hardware, and the present application does not limit this.
[0109] The following describes the implementation manners of the embodiments of the present application in detail with reference to the accompanying drawings.
[0110] Figure 3 is a flowchart of a bitstream signature method provided by the present application Figure 1 , and this bitstream signature method can be applied to Figure 2 the shown signature and authentication system. For example, this bitstream signature method can be implemented by the processing device 300. In this embodiment, the data unit is an access unit, and the following will all take the access unit as an example for description. In a possible example, the processing device 300 may be Figure 2 the shown signing end 210, and this bitstream signature method may include the following steps S310 and S320.
[0111] S310, the processing device 300 obtains authentication data and a security parameter set.
[0112] Among them, the authentication data includes: signature data and digest data of each access unit in a group of access units. The signature data is obtained by signing the digest data of each access unit in a group of access units. The security parameter set includes a hash period, and this hash period is used to indicate the maximum number of access units in a bitstream segment. A group of access units includes at least one access unit in a bitstream segment.
[0113] Exemplarily, when authentication needs to be supported, the number n of access units to be authenticated can be determined. Wherein, n is a positive integer.
[0114] Referring to Figure 3 , exemplarily, the n access units to be authenticated in the bitstream a are respectively: access unit 1, access unit 2,..., access unit n. These n access units to be authenticated can be called a group of access units. A group of access units involved subsequently all refer to the access units to be authenticated.
[0115] It should be noted that the present application does not group the access units, but for the convenience of description, "a group of access units" is used for description.
[0116] Exemplarily, referring to Figure 3 , the processing device 300 can independently calculate a digest data for each access unit in a group of access units, and the digest of each access unit in the group of access units can be obtained. The n digests can include: Digest 1, Digest 2,..., Digest n; where the n digests correspond one-to-one to the n access units; for example, Digest 1 corresponds to access unit 1, Digest 2 corresponds to access unit 2,..., Digest n corresponds to access unit n.
[0117] Exemplarily, a signature can be performed according to the digest of each access unit in a group of access units to obtain signature data (signature).
[0118] Exemplarily, authentication data (Auth) can be generated according to the signature data and the digest of each access unit in a group of access units. In this way, the authentication data can be {Digest 1, Digest 2,..., Digest n, signature}.
[0119] Optionally, the digests of each access unit in a group of access units in the authentication data can form a digest list (authentication_hash) {Digest 1, Digest 2,..., Digest n}.
[0120] In a possible implementation, the processing device 300 receives the parameters in the security parameter set. Such as Parameter 1, Parameter 2, etc.
[0121] In a possible example, Parameter 1 is the hash period. The processing device 300 determines hash_period_in_doi_minus1 according to the hash period configured by the user, and then writes the value of hash_period_in_doi_minus1 into the security parameter set. Among them, the maximum number of access units within one hash period can be hash_period_in_doi_minus1 + 1.
[0122] For example, if the hash period is 2, then hash_period_in_doi_minus1 is determined to be 2, and hash_period_in_doi_minus1 with a value of 2 is written into the security parameter set. Furthermore, the maximum number of access units included in a bitstream segment is 3, that is, the maximum number of access units within one hash period is 3. In the following descriptions, one hash period always refers to the number of access units within that hash period, that is, hash_period_in_doi_minus1 + 1.
[0123] The maximum value of hash_period_in_doi is set to the doi period, which can ensure that the number of access units participating in authentication is less than or equal to the maximum length of the digest list. hash_period_in_doi can be hash_period_in_doi_minus1 + 1.
[0124] In this application, hash_period_in_doi is used to indicate the time domain range of access units covered by an authentication data NAL unit (i.e., deltaDoi), and all access units that need to participate in authentication within this time domain range are co-signed. Using hash_period_in_doi can solve the problem of the change of SuccessiveHashPictures in the sub-stream. Therefore, there is no need to transmit the respective SuccessiveHashPictures for each sub-stream, which can save transmission bandwidth and standardize the scope of the authentication data NAL unit, improving the efficiency of signing or authenticating the bitstream.
[0125] In another possible example, parameter 2 is indication information. This indication information is used to indicate the number of authentication data included within the scope of the security parameter set. The scope of the security parameter set is the random access segment where the security parameter set is located in the bitstream. The processing device 300 determines the indication information based on the hash period and the number of access units included within the scope of the security parameter set. This indication information can be authentication_data_num_minus1, and then the value of authentication_data_num_minus1 is written into the security parameter set. The number of authentication data included within the scope of the security parameter set is authentication_data_num_minus1 + 1.
[0126] For example, if the hash period is 2, that is, the number of access units within this hash period is 3, and the number of access units within the scope of the security parameter set is 9, then it is determined that the number of authentication data included within the scope of the security parameter set is the number of access units within the scope of the security parameter set (9) divided by the number of access units within the hash period (3) which equals 3. Then it is determined that authentication_data_num_minus1 is 2, and the value of authentication_data_num_minus1 being 2 is written into the security parameter set.
[0127] It should be noted that the values of the above authentication_data_num_minus1 and hash_period_in_doi_minus1 can both be written into the security parameter set in binary form.
[0128] In the present application, by defining indication information in the security parameter set to clarify the quantity of authentication data that should be in the scope of the security parameter set, and then during authentication, the quantity of the authentication data that should be and the quantity of the actually received authentication data can be compared to efficiently detect the loss of authentication data, improving the efficiency of authentication data loss detection.
[0129] For the detailed content of the security parameter set, reference can be made to the content shown below Figure 5 and will not be elaborated here.
[0130] S320, the processing device 300 outputs the bitstream b.
[0131] This bitstream b includes a security parameter set and authentication data.
[0132] Exemplarily, after obtaining the authentication data and the security parameter set, the processing device 300 adds the authentication data and the security parameter set to the bitstream a to obtain the signed bitstream b, which is the signed bitstream 203 in the above Figure 2 above.
[0133] It should be noted that the above S310 - S320 can be executed by the encoder in the signing end 210, or by the signing module in the signing end 210, or can also be executed collaboratively by the encoder and the authentication module in the signing end 210 (the encoder executes S320 and the authentication module executes S310), and the present application does not limit this.
[0134] In a possible implementation manner, the following describes the positions of the security parameter set and the authentication data in the bitstream b.
[0135] Exemplarily, during the decoding process of the bitstream b obtained through the content shown in Figure 3 each security parameter set becomes effective when received by the decoder and causes the previously effective security parameter set (if any) to become ineffective. A security parameter set should exist before all access units of the random access point (RAP) pictures in the bitstream b. The security parameter set should be in the same access unit as the sequence parameter set (which can also be referred to as the sequence parameter set NAL unit), and the security parameter set should be before the sequence parameter set. Therefore, the scope of the security parameter set is the random access segment (RAS) in the bitstream b where the security parameter set is located, and this RAS represents all access units in the bitstream b starting from the access unit where the security parameter set is located to before the next RAP picture.
[0136] As shown in Figure 4 shown, Figure 4 is a bitstream schematic provided by the present application Figure 1。In the bitstream, the safety parameter set is located before the random access unit (the access unit corresponding to the RAP picture), and the scope of the safety parameter set includes two bitstream segments, that is, two sets of access units. In this example, the positional relationships indicated by "before" and "after" are "before" and "after" along the bitstream decoding order. For example, a is before b, which means that the position of a in the bitstream is before the position of b in the bitstream along the bitstream decoding order. That is, during decoding, a is decoded first, and then b is decoded.
[0137] Exemplarily, the authentication data is located after the access unit that is the last in the decoding order in a set of access units associated with the authentication data, and before the authentication data corresponding to the access units within the next hash period.
[0138] A set of access units associated with the authentication data represents multiple access units corresponding to the signature data in the authentication data. Since the processing device 300 signs the digests of the multiple access units to obtain the signature data, the signature data corresponds to multiple units.
[0139] As Figure 4 shown, the maximum number of access units indicated by the hash period is determined starting from the random access unit in the bitstream as a set of access units, and this set of access units corresponds to one hash period. For example, random access unit 0, access unit 1, and access unit 2 are a set of access units, and access unit 3, access unit 4, and access unit 5 are a set of access units. The processing device 300 calculates the digests of random access unit 0, access unit 1, and access unit 2 respectively, and signs the digests of random access unit 0, access unit 1, and access unit 2 to obtain the signature data. The processing device 300 writes the foregoing signature data and digest into authentication data 0. Therefore, a set of access units associated with authentication data 0 is access unit 0, access unit 1, and access unit 2. A set of access units associated with authentication data 1 is access unit 3, access unit 4, and access unit 5.
[0140] For example, authentication data 0 is located after access unit 2, which is the last in the decoding order in the associated access units 0, access unit 1, and access unit 2, and before authentication data 1 corresponding to the access units within the next hash period.
[0141] In this application, the processing device realizes better determination of the scope of the authentication data by defining the position of the authentication data in the bitstream. This avoids the problem that the authentication data corresponding to a set of access units exceeds the above range, resulting in the inability to accurately determine the authentication data corresponding to the set of access units during authentication of the foregoing set of access units, and then leading to the untrustworthiness of the set of access units and then being discarded, which is beneficial to improving the availability of the access units.
[0142] It should be noted that Figure 4 the bitstream shown may beFigure 3 The bitstream b shown in
[0143] As Figure 5 shown, Figure 5 is a schematic flow diagram of a bitstream signature method provided by this application Figure 2 . Among them, Figure 5 The method shown can be implemented by the processing device 300, and the processing device 300 can be Figure 2 implemented by the signature end 210 in . The bitstream signature method may include the following steps S510 - S550.
[0144] S510, the processing device generates a set of security parameters.
[0145] Exemplarily, when video image authentication needs to be supported, a set of security parameters is generated. In one possible implementation, the RBSP in the NAL unit for generating the set of security parameters (also known as the security parameter set RBSP) is generated.
[0146] The security parameter set RBSP includes some parameters, and these parameters can be used by one or more other types of NAL units. At the beginning of the decoding process, each security parameter set RBSP becomes effective when received by the decoder and causes the previously effective security parameter set RBSP (if any) to become invalid. A security parameter set NAL unit should exist before the access unit of all random access point images. When there are non - display knowledge images in the encoded video sequence, for non - RL pre - knowledge images, a security parameter set should be located before the access unit whose patch_index value is 0, and for RL pre - knowledge images, a security parameter set should be located before its access unit. The display images within the adjacent random access image intervals use the same security parameter set, and the knowledge images and the display images within the random access image interval where they generate the bitstream use the same security parameter set. The security parameter set NAL unit should be in the same access unit as the sequence parameter set NAL unit, and the security parameter set NAL unit should be located before the sequence parameter set NAL unit. If the access unit includes an encoded picture delimiter NAL unit, the security parameter set NAL unit should be located after the encoded picture delimiter NAL unit. At most one security parameter set RBSP is effective at a specified moment during the decoding process.
[0147] Among them, the definition of the security parameter set RBSP can be as shown in Table 1 below:
[0148] Table 1 Definition of the security parameter set RBSP
[0149]
[0150]
[0151] The encryption flag indicates whether there is a NAL unit with an encryption flag of 1 within the scope of the current set of security parameters, or in other words, whether there is a NAL unit that undergoes encryption operations. This encryption_flag is a binary variable. A value of '1' indicates support for encrypting the coded slice of the display picture, or the sequence parameter set of the display picture, or the picture parameter set of the display picture, or the coded slice of the non-display knowledge picture, or the coded slice of the display knowledge picture, or the sequence parameter set of the knowledge picture, or the picture parameter set of the knowledge picture, or the extended data unit. That is, the RBSP in the NAL unit may be encrypted. A value of '0' indicates that encryption of the RBSP in the NAL unit is not supported.
[0152] The authentication flag is a binary variable that indicates whether there is a NAL unit with an authentication flag of 1 within the scope of the current set of security parameters, or in other words, whether there is a NAL unit that undergoes authentication operations. If an access unit includes at least one NAL unit with authentication_idc equal to 1, then a hash calculation is required for all NAL units with authentication_idc equal to 1 in this access unit arranged in decoding order, to generate the digest data of this access unit. The digest data of the access unit will be used for authentication operations.
[0153] For example, a value of '1' indicates support for authenticating the coded video sequence. The NAL units that can participate in authentication include the coded slices of the display picture or the knowledge picture, as well as the sequence parameter set, picture parameter set, security parameter set, and extended data unit transmitted in this frame. When support for authenticating the above data content is available, the absolute time extension information must be carried in the coded video sequence, and the authentication data carried in the coded bitstream should be Base64-encoded. The authentication data is transmitted through a NAL unit with nal_unit_type equal to 10. If there are NAL units with authentication_idc equal to 1 and nal_unit_type equal to 0 - 9, 12, 14, 17, and 18 in an access unit, a hash calculation is performed on the NAL units with authentication_idc equal to 1 in this access unit arranged in decoding order, to generate the digest data of this access unit. An authentication_flag equal to 0 indicates that authentication of the coded video sequence is not supported, and the coded video sequence should not contain a NAL unit with nal_unit_type equal to 10.
[0154] It should be noted that if the authentication_flag is 1 while the encryption_flag is 1, that is, the current encoded video sequence supports both encryption and authentication, then it should be encrypted first and then authenticated, that is, the data used for authentication should be the encrypted NAL unit.
[0155] The encryption type (encryption_type), which is a 4-bit unsigned integer, is used to indicate the algorithm adopted for encryption. The specific corresponding relationship is shown in Table 2 below.
[0156] Table 2 Corresponding Relationship between Encryption Types and Specific Encryption Algorithms
[0157] Value of encryption_type Encryption algorithm 0 SM1 1 SM4 2~15 Reserved
[0158] The video encryption key flag vek_flag, which is a binary variable. A value of '1' indicates carrying vek, and a value of '0' indicates not carrying vkek.
[0159] The initialization vector flag iv_flag, which is a binary variable. A value of '1' indicates carrying iv, and a value of '0' indicates not carrying iv.
[0160] The video encryption key encryption type vek_encryption_type, which is a 4-bit unsigned integer, indicates the encryption type of the video encryption key.
[0161] The length of the encrypted video encryption key evek_length_minus1, which is an 8-bit unsigned integer. It indicates the length of the encrypted video encryption key in bytes.
[0162] The encrypted video encryption key evek, which is an n-bit unsigned integer. It represents the encrypted video encryption key used for encryption calculation, and its length is evek_length_minus1 plus 1 byte.
[0163] The length of the video encryption key version number vkek_version length_minus1, which is an 8-bit unsigned integer. It indicates the length of the video encryption key version number in bytes.
[0164] The video encryption key version number vkek_version, which is an n-bit unsigned integer. It indicates the video encryption key version number, and its length is vkek_version_length_minus1 plus 1 byte.
[0165] The initialization vector length iv_length_minus1, which is an 8-bit unsigned integer. It indicates the length of the initialization vector in bytes.
[0166] The initial vector iv is an n-bit unsigned integer. It indicates the initial vector for block encryption and has a length of iv_length_minus1 plus 1 byte.
[0167] The non-display knowledge image hash authentication flag hash_discard_non_output_library_pictures_flag is a binary variable. A value of '1' means that non-display knowledge images are not authenticated; a value of 0 means that non-display knowledge images are authenticated. The authentication method for non-display knowledge images is to obtain the authentication data by digitally signing only the digest data of the image. If hash_discard_library_pictures is not in the bitstream, its default value is equal to 1. The authentication_idc of each NAL unit in the unauthenticated images should be equal to 0.
[0168] The P / B frame hash authentication flag hash_discard_pb_pictures_flag is a binary variable. A value of '1' means that images other than random access point images and knowledge images are not authenticated; a value of 0 means that images other than random access point images and knowledge images are authenticated. If hash_discard_pb_pictures is not in the bitstream, its default value is equal to 1. The authentication_idc of each NAL unit in the unauthenticated images should be equal to 0.
[0169] The signature data format signature_fmt is a 2-bit unsigned integer. It indicates the signature data format. The specific correspondence between the values of signature_fmt and the syntax of signature_type is shown in Table 3 below.
[0170] Table 3 Signature Data Format
[0171]
[0172] The camera certificate identifier camera_idc is a 152-bit string. It indicates the certificate identifier of the camera from which the image originated.
[0173] The camera identifier camera_id is a 160-bit string. It indicates the camera ID from which the image originated.
[0174] The authentication enable flag (authentication_idc) is a binary variable. It indicates whether the NAL unit is authenticated. A value of '0' means that the NAL unit is not authenticated, and a value of '1' means that the NAL unit is authenticated using the authentication method specified in the security parameter set.
[0175] The hash period indicates a bitstream segment associated with one piece of authentication data. The maximum number of access units contained in this bitstream segment is hash_period_in_doi_minus1 + 1, which is exactly one hash period. The time-domain distance between any two access units in this bitstream segment indicated by the DOI should be less than or equal to hash_period_in_doi_minus1. Since the random access point image within a random access segment is the first image to participate in the signature, a set of access units can be determined based on the DOI of the random access point image and hash_period_in_doi_minus1, and this set of access units is co-signed. hash_period_in_doi_minus1 being 0 means that each access unit is signed separately and transmits its respective authentication data. The value range of hash_period_in_doi_minus1 is 0 to 255.
[0176] hash_period_in_doi_minus1 being 0 means that each access unit is independently signed, and the authentication data carrying this signature should be located after the access unit associated with this signature and before the authentication data of the next access unit. hash_period_in_doi_minus1 being greater than 0 means that multiple access units are co-signed, and the authentication data carrying this signature should be located after the last access unit in the decoding order among the multiple access units associated with this signature and before the authentication data of the access units in the next hash period.
[0177] authentication_data_num_minus1 + 1 indicates the number of authentication data contained within the scope of this security parameter set. The receiving end can quickly detect and determine whether all the authentication data has been received completely, that is, whether any authentication data is missing.
[0178] The hash type (hash_type), is a 2-bit unsigned integer. It indicates the algorithm used for authentication (i.e., the algorithm for determining the digest data of the access unit), and the specific correspondence is shown in Table 4:
[0179] Table 4 Correspondence between Hash Type and Specific Algorithm
[0180] Value of hash_type Authentication algorithm Digest data length (bytes) 0 SM3 32 1~3 Reserved Reserved
[0181] The digital signature type (signature_type), is a 2-bit unsigned integer. It indicates the algorithm for digitally signing the digest data of the access unit, as shown in Table 5.
[0182] Table 5 Correspondence between Digital Signature Type and Specific Encryption Algorithm
[0183] Value of signature_type Signature algorithm 0 SM2 1~3 Reserved
[0184] The camera_idc is a 19-byte string used to represent the certificate identification of the camera from which the bitstream-corresponding image is sourced.
[0185] It should be noted that hash_type, signature_type, and camera_idc in the safety parameter set RBSP are optional.
[0186] S520, the processing device 300 calculates each access unit in a set of access units of the bitstream according to the digest algorithm to obtain the digest of each access unit in the set of access units.
[0187] Exemplarily, the number of access units that need to be authenticated can be calculated according to hash_period_in_doi_minus1 in the safety parameter set RBSP, that is, hash_period_in_doi_minus1 + 1; that is, the number of access units included in a set of access units is hash_period_in_doi_minus1 + 1.
[0188] Next, each of the hash_period_in_doi_minus1 + 1 access units with authentication_idc being 1 can be calculated according to the digest algorithm to obtain the digest data of each of the hash_period_in_doi_minus1 + 1 access units.
[0189] In a possible implementation, the authentication_idc is located in the NAL header of the NAL unit.
[0190] In a possible implementation, when the security parameter set RBSP includes hash_type, the digest algorithm may be the authentication algorithm indicated by hash_type in the security parameter set RBSP. In this case, the digest data of each of the hash_period_in_doi_minus1 + 1 access units with authentication_idc being 1 can be calculated according to the authentication algorithm indicated by hash_type in the security parameter set RBSP. For example, the digest data of each of the hash_period_in_doi_minus1 + 1 access units with authentication_idc being 1 can be obtained by performing a hashing calculation on each of the hash_period_in_doi_minus1 + 1 access units according to the digest algorithm indicated by hash_type in the security parameter set RBSP.
[0191] In a possible implementation, the signature end 210 and the authentication end 220 can pre - agree on a digest algorithm; in this way, the digest data of each of the hash_period_in_doi_minus1 + 1 access units with authentication_idc being 1 can be calculated according to the pre - agreed digest algorithm. In this case, the security parameter set RBSP may not include hash_type.
[0192] It should be noted that this application does not limit the way for the signature end 210 and the authentication end 220 to synchronize the digest algorithm.
[0193] Refer again to Figure 5 , exemplarily, perform a hashing calculation on access unit 1 to obtain digest H1; perform a hashing calculation on access unit 2 to obtain digest H2; perform a hashing calculation on access unit 3 to obtain digest H3; perform a hashing calculation on access unit 4 to obtain digest H4; perform a hashing calculation on access unit 5 to obtain digest H5;...; perform a hashing calculation on access unit n to obtain digest Hn.
[0194] S530, the processing device 300 connects the digests of each access unit in a group of access units and determines the digest of the connected digest.
[0195] Exemplarily, the digests of each access unit in hash_period_in_doi_minus1 + 1 access units with authentication_idc being 1 can be concatenated to obtain the concatenated digest as H1 + H2 + H3 + H4 + H5 +... + Hn.
[0196] Next, the concatenated digest can be calculated to obtain the digest of the concatenated digest. For example, performing a hash calculation on H1 + H2 + H3 + H4 + H5 +... + Hn to obtain the digest of the concatenated digest Hg (as Figure 4 shown).
[0197] S540, the processing device 300 signs the digest of the digest of each access unit in the concatenated set of access units using the private key to obtain signature data.
[0198] In a possible implementation, when the security parameter set RBSP includes signature_type, the digest of the concatenated digest can be signed according to the signature algorithm and the private key indicated by signature_type in the security parameter set RBSP to obtain signature data.
[0199] In a possible implementation, the signature end 210 and the authentication end 220 can pre - agree on a signature algorithm; in this way, the digest of the concatenated digest can be signed according to the pre - agreed signature algorithm and the private key to obtain signature data. In this case, the security parameter set RBSP may not include signature_type.
[0200] It should be noted that the present application does not limit the way for the signature end 210 and the authentication end 220 to synchronize the signature algorithm.
[0201] It should be noted that tree - top digest data can also be generated, and the tree - top digest data is signed using the private key to obtain signature data. The present application does not limit the way of signing according to the digest data of the access units.
[0202] Exemplarily, the processing device 300 generates authentication data according to the digest of each access unit in a set of access units and the signature data.
[0203] For example, the authentication data can include {H1, H2, H3, H4, H5,..., Hn, signature}.
[0204] S550, the processing device 300 adds the authentication data and the security parameter set to the bitstream.
[0205] Exemplarily, the processing device 300 can encode the authentication data and the security parameter set and add the encoded authentication data and security parameter set to the bitstream.
[0206] For example, the processing device 300 may encode the authentication data or the security parameter set using Base64; then, the encoded authentication data is packed into the NAL unit of the authentication data.
[0207] In this application, the signing end 210 defines the scope of the authentication data through hash_period_in_doi_minus1, realizing the constraint of the authentication data, so that the authentication data only corresponds to the access units within the scope.
[0208] In a possible implementation, the definition of the authentication data RBSP in the NAL unit of the authentication data can be as shown in Table 6 below:
[0209] Table 6 Definition of authentication data RBSP
[0210]
[0211]
[0212] The value range of for_current_ras_idc is 0 to 1. If it is 1, it indicates that all the access units corresponding to the digests in the digest list of the authentication data are within the current random access segment. If it is 0, it indicates that all the access units corresponding to the digests in the digest list of the authentication data are not within the current random access segment. All the access units of the common signature should be within the same reachable access segment. If for_current_ras_idc is 0, then the NAL unit of the authentication data must be one of the consecutive (hash_period_in_doi_minus1 + 1) access units starting from the RAP picture access unit within the current RAS.
[0213] The authentication data identifier, also known as the identification information (authentication_data_id), has a value range of 0 to 1 and is used to identify the authentication data.
[0214] The authentication digest quantity (authentication_hash_number_minus1) is an 8-bit unsigned integer, and the value range is 0 to 255. authentication_hash_number_minus1 plus 1 represents the number of digests participating in the common signature.
[0215] The authentication digest data (authentication_hash) is binary data, and the length is the digest data length hash_size corresponding to the digest algorithm hash_type listed in the correspondence table of the hash type and the specific algorithm in the security parameter set.
[0216] The signature data authentication_data[i] is an 8-bit unsigned integer representing the i-th byte of a signature data.
[0217] The order of the digests of each access unit in the digest list carried in the authentication data NAL unit shall be the same as the order of these access units in the video compression bitstream (i.e., the decoding order).
[0218] It should be noted that the security parameter set can also be transmitted to the authentication side through other reliable mechanisms.
[0219] The content of Table 6 above is only an example and should not be construed as a limitation of this application. In other embodiments of this application, the value of authentication_data_id can be M, that is, it occupies M bits. This authentication_data_id is used to distinguish at least 2 M consecutive authentication data. There are P access units between the authentication data and the position of the last access unit in the decoding order among the multiple access units associated with the authentication data; where 0 ≤ P ≤ (2 M -1)*Q, Q is the maximum number indicated by the hash period, that is, hash_period_in_doi_minus1 + 1.
[0220] As Figure 6 shown, Figure 6 is a bitstream schematic provided by this application Figure 2 . In this example, hash_period_in_doi_minus1 defined in the security parameter set is 2, that is, a bitstream segment (a group of access units) has 3 access units. authentication_data_id is 2.
[0221] Referring to Figure 6 , the bitstream includes the first group of access units, the second group of access units, the third group of access units, and the fourth group of access units. The corresponding authentication data identifiers can be 00, 01, 10, and 11 respectively. Therefore, considering reasons such as signal fluctuations or delays, the authentication data corresponding to the first group of access units may not be received immediately after access unit 13. For example, it may be received after access unit 22, or after access unit 32. Figure 6 The bitstream shown can be Figure 3 bitstream b in
[0222] In the present application, since the identifier of the authentication data occupies M bits, it is possible to distinguish 2 to the power of M consecutive authentication data in the bitstream, which is beneficial to improving the fault tolerance of the position of the authentication data in the bitstream. That is, there can be more other authentication units between the authentication data and a group of access units corresponding to the authentication data, without affecting the authentication of the aforementioned group of access units by the authentication data.
[0223] In a possible scenario, the authentication data of the first group of access units is received at the latest before the authentication data of the fourth group of access units. In other words, the authentication data is located after the access unit with the last decoding order in a group of access units associated with the authentication data, and before the authentication data corresponding to the access units within the next 2 M −1 hash periods.
[0224] In a possible embodiment, a possible embodiment of the signature side is shown below. This embodiment includes the following steps ① - ⑥.
[0225] Step ①: The processing device 300 determines hash_period_in_doi_minus1 according to the configured hash period and writes it into the security parameter set.
[0226] Step ②: The processing device 300 sets the authentication_data_id of the current authentication data. In a RAS bitstream or a CVS (constrained variable-length coding with sub-blocks), the value of authentication_data_id should not be the same as the value of authentication_data_id of the previous authentication data NAL unit in the bitstream in terms of decoding order.
[0227] Step ③: The processing device 300 extracts hash_period_in_doi_minus1 + 1 AUs from the compressed video bitstream output by the encoder according to the device configuration, and calculates the digest H1, H2, …, Hn of each AU in the decoding order, where n is hash_period_in_doi_minus1 + 1. These digests are written into the digest list authentication_hash[i] in the authentication data in sequence.
[0228] When calculating the digest of an AU, determine the NAL units to be authenticated in the AU according to the configuration, and concatenate all the NAL units participating in the authentication in the AU to calculate the digest of the AU. Set the authentication_idc in the header information of these NAL units to 1, and set the authentication_data_id in the headers of these NAL units to the authentication_data_id of the current authentication data, such as 0 or 1.
[0229] In the case of hierarchical coding enabled, the basic unit for calculating the digest is a set of NAL units in an AU that are marked as participating in the signature and have the same layer_id. Therefore, the number of digests of an AU is equal to the number of layers in the hierarchical configuration.
[0230] Step ④: The processing device 300 calculates the digest Hg of this set of AUs according to the digests of each AU in this set of AUs, that is, H1, H2, …, Hn.
[0231] Step ⑤: The processing device 300 calculates the signature of the digest Hg and writes the signature into the signature data authentication_data[i] of the authentication data.
[0232] Step ⑥: The processing device 300 outputs the compressed video bitstream. The bitstream includes the security parameters (security parameter set NAL unit) and authentication data (authentication data NAL unit) determined by the above operations. The parameters authentication_data_id and authentication_idc in the unit header of the NAL units in the bitstream have been set in the above manner. This bitstream can be Figure 3 the bitstream b in.
[0233] In a possible embodiment, through the above Figures 3 - 6 the content shown can obtain the following bitstream.
[0234] This bitstream includes: multiple bitstream segments, authentication data, and a security data set;
[0235] Among them, the security parameter set includes a hash period, which is used to indicate the maximum number of access units included in a bitstream segment. The authentication data includes signature data and the digest of each access unit in a set of access units. The signature data is obtained by signing according to the digest of each access unit in a set of access units. A set of access units includes at least one access unit in a bitstream segment.
[0236] The bitstream of this embodiment can be Figure 3 the bitstream b shown in, and for more detailed content of multiple bitstream segments, authentication data, or security data sets, reference can be made to the above Figures 3 - 6The expressions shown are not elaborated here.
[0237] In a possible scenario, the security parameter set in the bitstream of this embodiment only includes the hash period.
[0238] In another possible scenario, the security parameter set in the bitstream of this embodiment includes the hash period and indication information.
[0239] In a possible embodiment, the present application also provides a bitstream signature method. This bitstream signature method can be applied to Figure 2 the signature and authentication system shown, for example, this bitstream signature method can be implemented by the processing device 300. In this embodiment, the data unit is the access unit, and the access unit will be used as an example for illustration below. In a possible example, the processing device 300 can be Figure 2 the signature end 210 shown, and this bitstream signature method can include the following steps ① and ②.
[0240] Step ①: The processing device 300 obtains the security parameter set and the authentication data.
[0241] Among them, the security parameter set includes indication information, and the indication information is used to indicate the number of authentication data included within the scope of the security parameter set. The scope of the security parameter set is the random access segment where the security parameter set is located in the bitstream. The authentication data includes signature data and the digest of each access unit in a group of access units. The signature data is obtained by signing the digest of each access unit in a group of access units;
[0242] Step ②: The processing device 300 outputs a bitstream. This bitstream includes the security parameter set and the authentication data.
[0243] For the detailed content of the above steps ① and ②, reference can be made to the Figures 3 - 6 expressions shown, which are not elaborated here.
[0244] Correspondingly, the embodiment of the present application also provides a bitstream, which includes: multiple bitstream segments, authentication data, and a security data set;
[0245] Among them, the security parameter set includes indication information, and the indication information is used to indicate the number of authentication data included within the scope of the security parameter set. The scope of the security parameter set is the random access segment where the security parameter set is located in the bitstream. The authentication data includes signature data and the digest of each access unit in a group of access units. The signature data is obtained by signing the digest of each access unit in a group of access units. A group of access units includes at least one access unit in a bitstream segment.
[0246] The bitstream in this embodiment can be Figure 3The bitstream b shown therein. For more details about multiple bitstream segments, authentication data, or security data sets, reference may be made to the above Figures 3 - 6 stated expressions, which will not be elaborated here.
[0247] In a possible scenario, the security parameter set in the bitstream of this embodiment only includes indication information.
[0248] In another possible scenario, the security parameter set in the bitstream of this embodiment includes a hash period and indication information.
[0249] After introducing the above bitstream signature method, the processing device 300 can send the bitstream obtained by the above bitstream signature method to Figure 2 the authentication end shown therein for processing. Based on this, an embodiment of this application also provides a bitstream detection method.
[0250] Figure 7 It is a flowchart of a bitstream detection method provided by this application. This bitstream detection method can be applied to Figure 2 the signature and authentication system shown therein. For example, this bitstream detection method can be implemented by the processing device 600. In this embodiment, the data unit is an access unit, and the following will be described by taking the access unit as an example. In a possible example, the processing device 600 can be Figure 2 the authentication end 220 shown therein, and this bitstream detection method can include the following steps S710 - S740.
[0251] S710. The processing device 600 obtains the security parameter set and authentication data in the bitstream.
[0252] Among them, the security parameter set includes a hash period, which is used to indicate the maximum number of access units included in a bitstream segment; the authentication data includes: signature data and the digest of each access unit in a group of access units. The signature data is obtained by signing the digest of each access unit in a group of access units. A group of access units includes at least one access unit in a bitstream segment;
[0253] For the content of the security parameter set and authentication data, reference may be made to the above Figures 3 - 6 stated expressions, which will not be elaborated here.
[0254] Exemplarily, the processing device 600 can obtain the security parameter set and authentication data by decoding the bitstream.
[0255] For example, the processing device 300 used base64 encoding before adding the security parameter set and authentication data to the bitstream. Therefore, the processing device 600 decodes the bitstream after obtaining it to obtain the security parameter set and authentication data.
[0256] S720. If the processing device 600 determines that there is an access unit participating in signature in a hash period, it detects the authentication data in the next hash period in the bitstream decoding order direction of the current hash period.
[0257] Exemplarily, the processing device 600 can determine whether there is an access unit participating in signature in a hash period according to each NAL unit in the access units included in a hash period.
[0258] For example, in the NAL units included in the access unit, authentication_idc is defined. If authentication_idc is 1, it indicates that the NAL unit will participate in signature, that is, the access unit including the NAL unit will participate in signature.
[0259] As Figure 4 shown, if it is determined that there is an access unit participating in signature in a hash period including a random access unit, the authentication data is detected in the next hash period in the bitstream decoding order direction of the current hash period.
[0260] Exemplarily, in a live broadcast scenario, if the processing device 600 sequentially receives each NAL unit in the bitstream decoding order. Figure 4 Taking it as an example, the processing device 600 will sequentially receive a set of access units (random access unit 0, access unit 1, access unit 2) corresponding to authentication data 0 in a hash period. Due to signal fluctuations or low signature efficiency of the processing device 300, the authentication data 0 cannot follow immediately after access unit 2. Since the identification information authentication_data_id of the authentication data only occupies one bit, the processing device 600 can only distinguish two consecutive authentication data (such as authentication data 0 and authentication data 1). Therefore, it is detected whether there is authentication data 0 in the next hash period (the hash period corresponding to authentication data 1) in the bitstream decoding order direction of the hash period corresponding to authentication data 0. If there is authentication data 0, the authentication data 0 can also authenticate the random access unit 0, access unit 1, and access unit 2. If not, the random access unit 0, access unit 1, and access unit 2 cannot be authenticated.
[0261] In a possible situation, in the hash period corresponding to authentication data 1, the authentication data 0 is located before the authentication data 1.
[0262] It should be noted that the above processing device 600 can only distinguish two consecutive representations of authentication data. The processing device 600 knows that the authentication data corresponding to the random access unit 0, access unit 1, and access unit 2 is authentication data 0, and the authentication data corresponding to the access unit 3, access unit 4, and access unit 5 is authentication data 1. If the position where the authentication data 0 appears is in the next hash period of the hash period corresponding to the authentication data 1, there may be two authentication data 0s in one hash period. At this time, the processing device 600 is not clear about the hash periods corresponding to these two authentication data 0s, and thus cannot accurately determine which authentication data 0 is used to authenticate the random access unit 0, access unit 1, and access unit 2. At this time, the situation of authentication failure or error of the random access unit 0, access unit 1, and access unit 2 will occur. Therefore, by limiting the position of the authentication data, the foregoing situation of authentication failure or error can be avoided.
[0263] It should be noted that the processing device 600 can also detect whether there is authentication data 0 in the hash period corresponding to the authentication data 0. Since the processing device 600 stores all the received NAL units, it is possible to directly detect whether there is authentication data 0 in the hash period corresponding to the authentication data 1.
[0264] S730. If the processing device 600 fails to detect the authentication data, it is determined that the authentication data is lost.
[0265] Such as Figure 4 As shown, if the processing device 600 fails to detect the authentication data 0 in the hash period corresponding to the authentication data 1, it is determined that the authentication data 0 is lost, and thus the random access unit 0, access unit 1, and access unit 2 cannot be authenticated.
[0266] S740. If the processing device 600 detects the authentication data, it is determined that the authentication data is not lost.
[0267] Regarding the above bitstream detection method, the following shows an embodiment in which the processing device 600 executes the bitstream authentication method. When the processing device 600 executes the bitstream authentication method, it can detect the bitstream. This embodiment includes the following steps ① - step ⑥.
[0268] Step ①: The processing device 600 obtains a bitstream. The bitstream includes a security parameter set and authentication data. The security parameter set includes the parameters required for the authentication operation, and the authentication data includes the parameters and data required for the authentication operation.
[0269] Step ②: The processing device 600 parses a digest list {H1, H2,..., Hn} from the authentication data and calculates the set digest Hg' of this group of digest sets. The method by which the processing device 600 calculates the set digest must be the same as the method by which the processing device 300 calculates the set digest.
[0270] Step ③: The processing device 600 uses Hg’ to verify the signature data parsed from the authentication data, and determines whether the digest list {H1, H2, …, Hn} transmitted in the authentication data passes the verification. If the verification fails, all access units corresponding to the authentication data are untrusted.
[0271] Step ④: The processing device 600 determines the access units participating in the signature according to the parameters in the authentication data.
[0272] If the signature object is a knowledge image, or in other words, the current authentication data corresponds to a knowledge image, that is, the case where is_non_output_library_flag is equal to 1, the processing device 600 determines the knowledge image corresponding to the authentication data according to the authentication_library_picture
[0273] _index. Specifically, the processing device 600 can search forward from the starting position of the authentication data in the bitstream to find the access unit of the coded image whose library_picture_index is equal to authentication_library_picture_index for the first time. If the coded data of the knowledge image is included in multiple access units, all these access units need to be searched and obtained. In another implementation, if the processing device 600 caches the access units of the knowledge image in advance, there is no need to perform a search operation in the bitstream.
[0274] If the signature object is not a knowledge image and hash_period_in_doi_minus1 is equal to 0. This means that one access unit participates in the signature. Search forward 2*(hash_period_in_doi_minus1 + 1) access units from the starting position of the authentication data in the bitstream, and find the NAL unit whose authentication_data_id in the NAL unit header information is the same as the value of the parameter authentication_data_id in the authentication data. The access unit where the NAL unit is located is the access unit participating in the signature.
[0275] If the signature object is not a knowledge image and hash_period_in_doi_minus1 is greater than 0. This indicates that multiple access units are involved in the signature. Starting from the position of the authentication data NAL unit in the bitstream, search forward for 2*(hash_period_in_doi_minus1 + 1) access units. Find the set of NAL units whose authentication_data_id in the NAL unit header information is the same as the value of the parameter authentication_data_id in this authentication data, and denote it as the set of NAL units within the scope of the authentication data. Search for the set of NAL units with authentication_idc equal to 1 in the header information within the set of NAL units within the scope of the authentication data, and denote it as the set of NAL units participating in the signature within the scope of the authentication data. The set of access units where these NAL units are located is the set of access units participating in the signature.
[0276] If the for_current_ras_idc of this authentication data is 0, it means that the AU associated with the current authentication data is within the previous RAS. At this time, starting from the position of the authentication data NAL unit in the bitstream, search forward for the first RAP. Starting from this RAP (excluding this RAP), search forward for (hash_period_in_doi_minus1 + 1) access units to determine the set of NAL units within the scope of the authentication data, and further determine the set of NAL units participating in the signature within the scope of the authentication data and the access units participating in the signature.
[0277] Step ⑤: The processing device 600 authenticates the access units participating in the signature.
[0278] Before authenticating the access units participating in the signature, the processing device 600 initializes the matching start position to the first digest position {H1, H2,..., Hn} in the digest list, that is, position 1.
[0279] Authenticate each access unit in the decoding order of a group of access units participating in the signature, including: The processing device 600 calculates a digest Hx of an access unit. Starting from the matching start position of the digest list, the processing device 600 searches for the matching digest in the order from front to back. If a matching digest is found, the access unit passes the authentication, and at the same time, the matching start position is updated to the next position of the matching digest. Among them, the method for the processing device 600 to calculate the access unit digest is the same as the method for the processing device 300 to calculate the access unit digest;
[0280] The digest list described in this step has been verified and are all trusted digests.
[0281] Step ⑥: Optionally, the processing device 600 detects whether the authentication data is lost.
[0282] In a possible implementation, the processing device 600 may determine whether there is any missing authentication data based on the security parameter set parameter authentication_data_num and the reception of the authentication data of the access units within the scope of the security parameter set. Specifically, after receiving the security parameter set, the receiving end counts the received authentication data. If the authentication data in the RAS where the security parameter set is located is less than authentication_data_num_minus1, it is determined that there is a loss. If the authentication data in the RAS where the security parameter set is located is equal to authentication_data_num_minus1, then search for the first authentication data with for_current_ras_idc being 0 in the next RAS. If not found, it is determined that there is a loss.
[0283] In another possible implementation, the processing device 600 may also detect whether there is any missing authentication data based on hash_period_in_doi_minus1. Specifically, if there are access units participating in the signature within a hash period of the RAS, then detect the authentication data NAL unit in the next hash period. If not detected, it is determined that there is a loss. If this hash period is the last one of the current RAS, then detect the authentication data NAL unit in the first hash period of the next RAS. If not detected, it is determined that there is a loss.
[0284] In another possible embodiment of the present application, the present application further provides a bitstream detection method. This bitstream detection method can be applied to Figure 2 the signature and authentication system shown, such as this bitstream detection method can be implemented by the processing device 600. In this embodiment, the data unit is the access unit, and the access unit will be used as an example for description hereinafter. In a possible example, the processing device 600 may be Figure 2 the authentication end 220 shown, and this bitstream detection method may include the following steps ①-④.
[0285] Step ①: The processing device 600 obtains the security parameter set and the authentication data in the bitstream.
[0286] Among them, the security parameter set includes a hash period, which is used to indicate the maximum number of access units included in a bitstream segment; the authentication data includes: signature data and the digest of each access unit in a set of access units, and the signature data is obtained by signing the digest of each access unit in a set of access units. A set of access units includes at least one access unit in a bitstream segment. The identification information (identification) authentication_data_id carried by the authentication data occupies M bits, where M is an integer greater than or equal to 2, and the identification is used to distinguish 2 to the power of M consecutive authentication data in the bitstream.
[0287] For the detailed content of the security parameter set and the authentication data, reference can be made to the above Figures 3 - 6 stated expressions, which will not be elaborated here.
[0288] Step ②: If the processing device 600 determines that there are access units participating in the signature in a hash period, then detect the authentication data in the 2 M -1 hash periods after the current hash period in the bitstream decoding order direction.
[0289] Since the identification of the authentication data occupies M bits, if M is 2, the processing device 600 can determine the hash periods corresponding to the authentication data 0, authentication data 1, authentication data 2, and authentication data 3, that is, the corresponding multiple sets of access units. For the authentication data 0, the processing device 600 can detect whether it exists at the latest in the hash period corresponding to the authentication data 3.
[0290] In a possible scenario, within the hash period corresponding to the authentication data 1, the authentication data 0 is before the authentication data 3.
[0291] It should be noted that the above authentication data 0, authentication data 1, authentication data 2, and authentication data 3 are arranged in the bitstream decoding order. Correspondingly, the multiple sets of data corresponding to the authentication data 0, authentication data 1, authentication data 2, and authentication data 3 are also arranged in the bitstream decoding order.
[0292] It should be noted that the processing device 600 can also detect whether the authentication data 0 exists within the hash period corresponding to the authentication data 0, whether the authentication data 0 exists within the hash period corresponding to the authentication data 1, and whether the authentication data 0 exists within the hash period corresponding to the authentication data 2. Since the processing device 600 stores all the received NAL units, for the sake of saving computing resources, it can directly detect whether the authentication data 0 exists within the hash period corresponding to the authentication data 3. In other words, the processing device 600 detects whether the previously received data includes the authentication data 0 within the hash period corresponding to the authentication data 3.
[0293] Step ③: If the authentication data cannot be detected, it is determined that the authentication data is lost.
[0294] Step ④: If the authentication data is detected, it is determined that the authentication data is not lost.
[0295] In another possible embodiment of the present application, the present application further provides a bitstream detection method. The bitstream detection method can be applied to Figure 2 the signature and authentication system shown in, for example, the bitstream detection method can be implemented by the processing device 600. In this embodiment, the data unit is an access unit, and the following will be described by taking the access unit as an example. In a possible example, the processing device 600 may be Figure 2 the authentication end 220 shown in, and the bitstream detection method may include the following steps ① and ②.
[0296] Step ①: The processing device 600 obtains the set of security parameters in the bitstream and the number of authentication data within the scope of the set of security parameters.
[0297] Among them, the scope of the set of security parameters is the random access segment where the set of security parameters is located in the bitstream, and the security data set includes indication information, and the indication information is used to indicate the number of authentication data that should be included within the scope of the set of security parameters.
[0298] For the detailed content of the set of security parameters and the authentication data, reference can be made to the content shown above Figures 3 - 6 and will not be elaborated here.
[0299] Step ②: The processing device 600 determines the loss situation of the authentication data according to the indication information and the number of authentication data within the scope of the set of security parameters.
[0300] Exemplarily, the processing device 600 compares the number a of authentication data that should be included within the scope of the set of security parameters indicated by the indication information with the number b of authentication data actually obtained by the processing device 600 from within the scope of the set of security parameters to determine whether the authentication data is lost. If the number a is the same as the number b, the authentication data is not lost. If the number a is different from the number b, the authentication data is lost.
[0301] In the present application, by defining the indication information in the set of security parameters to clarify the number of authentication data that should be in the scope of the set of security parameters, and then during authentication, the number of authentication data that should be and the actually received number can be compared to efficiently detect the loss situation of the authentication data and improve the efficiency of detecting the loss of authentication data.
[0302] It can be understood that, in order to implement the functions in the above embodiments, the processing devices 300 and 600 include corresponding hardware structures and / or software modules for executing various functions. Those skilled in the art should easily realize that, for the units and method steps of each example described in combination with the embodiments disclosed in this application, this application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the form of hardware or computer software driving hardware depends on the specific application scenarios and design constraints of the technical solution.
[0303] In the foregoing, in combination with Figures 1 - 6 , the bitstream signature method provided according to this embodiment has been described in detail. Next, in combination with Figure 8 , the bitstream signature device provided according to this embodiment will be described.
[0304] Figure 8 FIG. is a schematic diagram of the bitstream signature device provided in this application. The schematic diagram of the bitstream signature device can be used to execute the method of the foregoing embodiment. Therefore, the beneficial effects it can achieve can refer to the beneficial effects in the corresponding method provided above, which will not be elaborated here. Exemplarily, the bitstream signature device 800 includes:
[0305] A first acquisition module 810, configured to acquire a set of security parameters and authentication data. The set of security parameters includes a hash period, and the hash period is used to indicate the maximum number of access units included in a bitstream segment. The authentication data includes signature data and a digest of each access unit in a group of access units. The signature data is obtained by signing the digest of each access unit in a group of access units. A group of access units includes at least one access unit in a bitstream segment.
[0306] A first output module 820, configured to output a bitstream, where the bitstream includes a set of security parameters and authentication data.
[0307] For more content that can be implemented by the bitstream signature device 800, reference can be made to the steps executed by the processing device 300 in the foregoing method embodiment. The bitstream signature device 800 can be used to implement the functions of the processing device 300 in the foregoing method embodiment, and thus can also achieve the beneficial effects of the foregoing method embodiment.
[0308] In a possible embodiment, the bitstream signature device may include a third acquisition module and an output module.
[0309] A second acquisition module, configured to acquire a security parameter set and authentication data. The security parameter set includes indication information for indicating the number of authentication data included within the scope of the security parameter set. The scope of the security parameter set is the random access segment where the security parameter set is located in the bitstream. The authentication data includes signature data and the digest of each access unit in a group of access units, and the signature data is obtained by signing the digest of each access unit in the group of access units.
[0310] A second output module, configured to output a bitstream, where the bitstream includes the security parameter set and the authentication data.
[0311] For more implementable content of the bitstream signature device, reference may be made to the steps performed by the processing device 300 in the foregoing method embodiments. The bitstream signature device can be used to implement the functions of the processing device 300 in the foregoing method embodiments, and thus can also achieve the beneficial effects of the foregoing method embodiments.
[0312] In the foregoing, in combination with Figure 7 , a bitstream detection method provided according to this embodiment is described in detail. Next, in combination with Figure 9 , a bitstream detection device provided according to this embodiment will be described. Figure 9 FIG. is a schematic diagram of a bitstream detection device provided in this application. The schematic diagram of the bitstream detection device can be used to execute the method of the foregoing embodiment. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method provided above, and will not be elaborated here. Exemplarily, the bitstream detection device 900 includes:
[0313] A third acquisition module 910, configured to acquire the security parameter set and the authentication data in the bitstream.
[0314] The security parameter set includes a hash period for indicating the maximum number of access units included in a bitstream segment. The authentication data includes signature data and the digest of each access unit in a group of access units, and the signature data is obtained by signing the digest of each access unit in the group of access units. A group of access units includes at least one access unit in a bitstream segment.
[0315] A first detection module 920, if there are access units participating in the signature in a hash period, detects the authentication data in the next hash period in the direction of the bitstream decoding order in the current hash period; if the authentication data cannot be detected, it is determined that the authentication data is lost, and if the authentication data is detected, it is determined that the authentication data is not lost.
[0316] For more implementable content of the bitstream detection device 900, reference may be made to the steps performed by the processing device 600 in the foregoing method embodiments. The bitstream detection device 900 can be used to implement the functions of the processing device 600 in the foregoing method embodiments, and thus can also achieve the beneficial effects of the foregoing method embodiments.
[0317] In the foregoing, in combination with Figure 7 , the bitstream detection method provided according to this embodiment has been described in detail. Next, the bitstream detection device provided according to this embodiment will be described. The schematic diagram of the bitstream detection device can be used to execute the method of the foregoing embodiment. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method provided above, and will not be elaborated here. Exemplarily, the bitstream detection device includes:
[0318] A fourth acquisition module, configured to acquire a set of security parameters and authentication data in the bitstream.
[0319] Wherein, the set of security parameters includes a hash period, and the hash period is used to indicate the maximum number of access units included in a bitstream segment; the authentication data includes signature data and a digest of each access unit in a group of access units, and the signature data is obtained by signing the digest of each access unit in the group of access units. The authentication data carries an identifier, the identifier occupies M bits, M is an integer greater than or equal to 2, and the identifier is used to distinguish 2 to the power of M consecutive authentication data in the bitstream. The group of access units includes at least one access unit in the one bitstream segment;
[0320] A second detection module, configured to, if there are access units participating in the signature in a hash period, detect the authentication data in the (2 to the power of M minus 1)th hash period after the current hash period in the bitstream decoding order direction; if the authentication data cannot be detected, it is determined that the authentication data is lost, and if the authentication data is detected, it is determined that the authentication data is not lost.
[0321] For more implementable content of the bitstream detection device, reference may be made to the steps performed by the processing device 600 in the foregoing method embodiments. The bitstream detection device can be used to implement the functions of the processing device 600 in the foregoing method embodiments, and thus can also achieve the beneficial effects of the foregoing method embodiments.
[0322] In the foregoing, in combination with Figure 7 , the bitstream detection method provided according to this embodiment has been described in detail. Next, the bitstream detection device provided according to this embodiment will be described. The schematic diagram of the bitstream detection device can be used to execute the method of the foregoing embodiment. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method provided above, and will not be elaborated here. Exemplarily, the bitstream detection device includes:
[0323] A fifth acquisition module, configured to acquire a security parameter set in a bitstream and the number of authentication data within the scope of the security parameter set.
[0324] Wherein, the scope of the security parameter set is a random access segment where the security parameter set is located in the bitstream, and the security data set includes indication information for indicating the number of authentication data that should be included within the scope of the security parameter set;
[0325] A determination module, configured to determine the loss situation of the authentication data according to the indication information and the number of authentication data within the scope of the security parameter set.
[0326] For more content that can be implemented by the bitstream detection device, reference may be made to the steps executed by the processing device 600 in the above method embodiments. The bitstream detection device can be used to implement the functions of the processing device 600 in the above method embodiments, and thus can also achieve the beneficial effects possessed by the above method embodiments.
[0327] It can be understood that Figure 8 or Figure 9 The device shown is only an example provided in this embodiment. Depending on the bitstream signature or detection process, the device may include more or fewer units, which are not limited in this application.
[0328] When Figure 8 or Figure 9 When the device shown is implemented by hardware, the hardware can be implemented by a processor or a chip system. The chip system includes one or more chips, and each chip includes a processor and a power supply circuit. The power supply circuit is used to supply power to the processor, and the processor is used to implement the method in any possible implementation manner in the above embodiments through logic circuits or by executing code instructions. The beneficial effects can be referred to the description in any aspect of the above embodiments, which will not be elaborated here.
[0329] It can be understood that the processor in the embodiments of the present application can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor can be a microprocessor or any conventional processor.
[0330] An embodiment of the present application also provides a computing device. Figure 8The bitstream signature device 800 shown or Figure 9 The bitstream detection device 900 shown can be implemented by a computing device, such as Figure 10 shown, Figure 10 is a schematic structural diagram of the computing device provided in this application. The computing device 1000 includes: a memory 1010 and at least one processor 1020. The processor 1020 can implement the bitstream signature method or the bitstream detection method provided in the foregoing embodiments. The memory 1010 is used to store software instructions corresponding to the foregoing bitstream signature method or bitstream detection method. For example, the computing device can be Figure 1 the camera 11 or the mobile phone 15 in etc. The computing device 1000 can be the foregoing processing device 300 or processing device 600.
[0331] As an alternative implementation, in terms of hardware implementation, the computing device 1000 can refer to a chip or a chip system encapsulated with one or more processors 1020. For example, when the computing device 1000 is used to implement the method steps in the foregoing embodiments, the processor 1020 included in the computing device 1000 executes the steps and possible sub-steps of the processing device 300 or the processing device 600 in the foregoing method. In an alternative scenario, the computing device 1000 may further include a communication interface 1030, and the communication interface 1030 can be used to send and receive data. For example, the communication interface 1030 is used to receive bitstreams, etc.; the communication interface 1030 can be implemented through the interface circuit included in the computing device 1000. Therefore, in some examples, the communication interface 1030 can also be referred to as a transceiver of the computing device. In this embodiment, the communication interface 1030 supports wired connection using the unified multimedia interconnection interface.
[0332] In the embodiments of this application, the communication interface 1030, the processor 1020, and the memory 1010 can be connected through a bus 1040. The bus 1040 can be divided into an address bus, a data bus, a control bus, etc. The bus 1040 can be a peripheral component interconnect express (PCIe) bus, or an extended industry standard architecture (EISA) bus, a unified bus (Ubus or UB), a compute express link (CXL), a cache coherent interconnect for accelerators (CCIX), or other types of buses, etc.
[0333] The processor 1020 may include a CPU, a graphics processing unit (GPU), an embedded neural-network processing unit (NPU), a microprocessor (MP), a digital signal processor (DSP), an ASIC, an FPGA, or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof.
[0334] The memory 1010 may include volatile memory, such as random access memory (RAM). The memory 1010 may also include non-volatile memory, such as read only memory (ROM), flash memory, a hard disk drive (HDD), or a solid state drive (SSD).
[0335] It should be noted that the computing device 1000 may also execute Figure 8 the functions of the bitstream signature device 800 shown or execute Figure 9 the functions of the bitstream detection device 900 shown, which will not be elaborated here. Among them, all relevant contents of each step involved in the above method embodiments can be cited in the function descriptions of the corresponding functional modules, and will not be elaborated here.
[0336] The embodiments of the present application also provide a computer-readable storage medium. The computer-readable storage medium may be any available medium that can be stored by the computing device or a data storage device such as a data center that includes one or more available media. The available medium may be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a digital video disc (DVD)), or a semiconductor medium (for example, a solid state drive), etc. The computer-readable storage medium stores instructions that instruct the computing device to execute the bitstream signature method or the bitstream detection method. The computer-readable storage medium may also store the above-mentioned bitstream, such as the bitstream obtained by the Figure 3 method shown.
[0337] Embodiments of the present application also provide a computer program product containing instructions. The computer program product can be software or a program product containing instructions that can run on a computing device or be stored in any available medium. When the computer program product runs on at least one computing device, at least one computing device is caused to execute the bitstream signature method or the bitstream detection method.
[0338] In addition, embodiments of the present application also provide a device, which may specifically be a chip, a component or a module. The device may include a processor and a memory connected to each other. The memory is used to store computer-executable instructions. When the device runs, the processor may execute the computer-executable instructions stored in the memory, so that the chip executes the methods in the above method embodiments.
[0339] Among them, the computing device, computer-readable storage medium, computer program product or chip provided in this embodiment are all used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding methods provided above, and will not be elaborated here.
[0340] Through the description of the above embodiments, those skilled in the art can understand that for the convenience and brevity of description, only the above division of each functional module is used as an example. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.
[0341] In several embodiments provided by the present application, it should be understood that the disclosed device and method can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of the device or unit can be in an electrical, mechanical or other form.
[0342] The units described as separate components may or may not be physically separated. The components displayed as units may be one physical unit or multiple physical units, that is, they may be located in one place, or they may be distributed to multiple different places. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0343] In addition, in each embodiment of the present application, each functional unit may be integrated into one processing unit, or each unit may exist physically alone, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of a software functional unit.
[0344] Any content of each embodiment of the present application, as well as any content of the same embodiment, can be freely combined. Any combination of the above content is within the scope of the present application.
[0345] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiments of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The software product is stored in a storage medium and includes several instructions for causing a device (which may be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the methods of the various embodiments of the present application. The aforementioned storage medium includes: USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs and other various media that can store program codes.
[0346] The steps of the methods or algorithms described in connection with the disclosed content of the embodiments of the present application may be implemented in a hardware manner or by a processor executing software instructions. The software instructions may be composed of corresponding software modules. The software modules may be stored in RAM, flash memory, ROM, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, hard disks, mobile hard disks, compact disc read-only memory (CD-ROM), or any other form of storage medium well-known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium may also be a component of the processor. The processor and the storage medium may be located in an ASIC.
[0347] Those skilled in the art should be able to realize that in one or more of the above examples, the functions described in the embodiments of the present application can be implemented by hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. The computer-readable medium includes computer-readable storage media and communication media, where the communication media includes any medium that facilitates the transmission of a computer program from one place to another. The storage media can be any available medium accessible by a general-purpose or special-purpose computer.
[0348] The embodiments of the present application have been described above in conjunction with the accompanying drawings. However, the present application is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not restrictive. Under the inspiration of the present application, those of ordinary skill in the art can also make many forms without departing from the purpose of the present application and the scope protected by the claims, and all of them fall within the protection scope of the present application.
Claims
1. A bit stream signature method, characterized in that: The method comprises: Obtain security parameter sets and authentication data; The security parameter set includes a hash period, the hash period is used to indicate the maximum number of access units included in a bitstream segment, the authentication data includes signature data and a digest of each access unit in a group of access units, the signature data is obtained by signing according to the digest of each access unit in the group of access units, and the group of access units includes at least one access unit in the bitstream segment; A bit stream is output, the bit stream including the security parameter set and the authentication data.
2. The method according to claim 1, characterized in that The authentication data is located after the last access unit in the decoding order of a group of access units associated with the authentication data, and is located before the authentication data corresponding to the access unit in the next hash cycle.
3. The method according to claim 1 or 2, characterized in that: The security parameter set also includes: indication information, where the indication information is used to indicate the number of authentication data contained in the scope of the security parameter set, and the scope of the security parameter set is the random access segment in the bitstream where the security parameter set is located.
4. The method according to claim 1 or 3, characterized in that: The authentication data carries an identifier, which occupies M bits, where M is an integer greater than or equal to 2, and the identifier is used to distinguish consecutive 2 to the power of M authentication data in the bit stream.
5. The method according to claim 4, characterized in that There are P access units between the authentication data and the last access unit in the decoding order of a group of access units associated with the authentication data; wherein 0≤P≤(2 M -1)*Q, where Q is the maximum number of hash cycle indications.
6. A bit stream signature method, characterized in that: The method comprises: Obtain security parameter sets and authentication data; The security parameter set includes indication information, where the indication information is used to indicate the number of authentication data contained in the scope of the security parameter set, where the scope of the security parameter set is a random access segment in a bitstream where the security parameter set is located, and the authentication data includes signature data and a digest of each access unit in a group of access units, where the signature data is obtained by signing according to the digest of each access unit in the group of access units; A bit stream is output, the bit stream including the security parameter set and the authentication data.
7. The method according to claim 6, characterized in that The security parameter set also includes a hash period, which is used to indicate the maximum number of access units included in a bit stream segment.
8. The method according to claim 6 or 7, characterized in that: The authentication data is located after the last access unit in the decoding order of a group of access units associated with the authentication data, and is located before the authentication data corresponding to the access unit in the next hash cycle.
9. The method according to claim 6 or 7, characterized in that: The authentication data carries an identifier, which occupies M bits, where M is an integer greater than or equal to 2, and the identifier is used to distinguish consecutive 2 to the power of M authentication data in the bit stream.
10. The method according to claim 9, characterized in that There are P access units between the authentication data and the last access unit in the decoding order of a group of access units associated with the authentication data; wherein 0≤P≤(2 M -1)*Q, where Q is the maximum number of hash cycle indications.
11. A bit stream, characterized in that The bit stream comprises: multiple bitstream segments, authentication data, and security data sets; The security parameter set includes a hash period, which is used to indicate the maximum number of access units included in a bitstream segment, and the authentication data includes signature data and a summary of each access unit in a group of access units, and the signature data is obtained by signing according to the summary of each access unit in a group of access units, and the group of access units includes at least one access unit in the bitstream segment.
12. The bit stream according to claim 11, characterized in that The authentication data is located after the last access unit in the decoding order of a group of access units associated with the authentication data, and is located before the authentication data corresponding to the access unit in the next hash cycle.
13. The bit stream according to claim 11 or 12, characterized in that The security parameter set also includes: indication information, where the indication information is used to indicate the number of authentication data contained in the scope of the security parameter set, and the scope of the security parameter set is the random access segment in the bitstream where the security parameter set is located.
14. The bit stream according to claim 11 or 13, characterized in that The authentication data carries an identifier, which occupies M bits, where M is an integer greater than or equal to 2, and the identifier is used to distinguish consecutive 2 to the power of M authentication data in the bit stream.
15. The bit stream according to claim 14, characterized in that There are P access units between the authentication data and the last access unit in the decoding order of a group of access units associated with the authentication data; wherein 0≤P≤(2 M -1)*Q, where Q is the maximum number of hash cycle indications.
16. A bit stream, characterized in that The bit stream comprises: multiple bitstream segments, authentication data, and security data sets; The security parameter set includes indication information, and the indication information is used to indicate the number of authentication data contained in the scope of the security parameter set. The scope of the security parameter set is the random access segment where the security parameter set is located in the bitstream. The authentication data includes signature data and a summary of each access unit in a group of access units. The signature data is obtained by signing according to the summary of each access unit in a group of access units.
17. The bit stream according to claim 16, characterized in that The security parameter set includes a hash period, and the hash period is used to indicate the maximum number of access units included in a bit stream segment.
18. The bit stream according to claim 16 or 17, characterized in that The authentication data is located after the last access unit in the decoding order of a group of access units associated with the authentication data, and is located before the authentication data corresponding to the access unit in the next hash cycle.
19. The bit stream according to claim 16 or 17, characterized in that The authentication data carries an identifier, which occupies M bits, where M is an integer greater than or equal to 2, and the identifier is used to distinguish consecutive 2 to the power of M authentication data in the bit stream.
20. The bit stream according to claim 19, characterized in that There are P access units between the authentication data and the last access unit in the decoding order of a group of access units associated with the authentication data; wherein 0≤P≤(2 M -1)*Q, where Q is the maximum number of hash cycle indications.
21. A bit stream detection method, characterized in that: The method comprises: Get the security parameter set and authentication data in the bit stream; The security parameter set includes a hash period, and the hash period is used to indicate the maximum number of access units included in a bitstream segment; the authentication data includes signature data and a digest of each access unit in a group of access units, and the signature data is obtained by signing according to the digest of each access unit in the group of access units, and the group of access units includes at least one access unit in the bitstream segment; If there is an access unit participating in the signature in a hash cycle, the authentication data is detected in the next hash cycle in the direction of the bitstream decoding order of the current hash cycle; If the authentication data cannot be detected, it is determined that the authentication data is lost.
22. A bit stream detection method, characterized in that: The method comprises: Get the security parameter set and authentication data in the bit stream; The security parameter set includes a hash period, and the hash period is used to indicate the maximum number of access units included in a bitstream segment; the authentication data includes signature data and a summary of each access unit in a group of access units, and the signature data is obtained by signing according to the summary of each access unit in the group of access units, and the authentication data carries an identifier, and the identifier occupies M bits, where M is an integer greater than or equal to 2, and the identifier is used to distinguish between consecutive 2 to the power of M authentication data in the bitstream, and the group of access units includes at least one access unit in the one bitstream segment; If there is an access unit participating in the signature in a hash cycle, the authentication data is detected in the 2M-th power minus 1 hash cycle after the current hash cycle in the direction of the bitstream decoding order; If the authentication data cannot be detected, it is determined that the authentication data is lost.
23. A bit stream detection method, characterized in that: The method comprises: Obtain the security parameter set in the bit stream and the number of authentication data within the scope of the security parameter set; The scope of the security parameter set is a random access segment in the bitstream where the security parameter set is located, and the security data set includes indication information, where the indication information is used to indicate the number of authentication data that should be included in the scope of the security parameter set; The loss of authentication data is determined based on the indication information and the number of authentication data within the scope of the security parameter set.
24. The method according to claim 23, characterized in that The determining, according to the indication information and the number of authentication data within the scope of the security parameter set, of the loss of authentication data includes: If the number of authentication data indicated by the indication information is consistent with the number of authentication data in the security parameter set, then the authentication data is not lost; If the number of authentication data indicated by the indication information is inconsistent with the number of authentication data in the security parameter set, the authentication data is lost.
25. A bit stream signature device, characterized in that: The device comprises: A first acquisition module, used to acquire a security parameter set and authentication data; The security parameter set includes a hash period, the hash period is used to indicate the maximum number of access units included in a bitstream segment, the authentication data includes signature data and a summary of each access unit in a group of access units, the signature data is obtained by signing the summary of each access unit in the group of access units, and the group of access units includes at least one access unit in the bitstream segment. An output module is used to output a bit stream, wherein the bit stream includes the security parameter set and the authentication data.
26. A bitstream signature device, characterized in that: The device comprises: A second acquisition module, used to acquire a security parameter set and authentication data; The security parameter set includes indication information, where the indication information is used to indicate the number of authentication data contained in the scope of the security parameter set, where the scope of the security parameter set is a random access segment in a bitstream where the security parameter set is located, and the authentication data includes signature data and a digest of each access unit in a group of access units, where the signature data is obtained by signing according to the digest of each access unit in the group of access units; The second output module is used to output a bit stream, where the bit stream includes the security parameter set and the authentication data.
27. A bit stream detection device, characterized in that: The device comprises: A third acquisition module, used to obtain a security parameter set and authentication data in a bit stream; The security parameter set includes a hash period, and the hash period is used to indicate the maximum number of access units included in a bitstream segment; the authentication data includes signature data and a digest of each access unit in a group of access units, and the signature data is obtained by signing according to the digest of each access unit in the group of access units, and the group of access units includes at least one access unit in the bitstream segment; The first detection module is used to detect authentication data in the next hash cycle along the bit stream decoding order direction of the current hash cycle if there is an access unit participating in the signature in a hash cycle; if the authentication data cannot be detected, it is determined that the authentication data is lost.
28. A bit stream detection device, characterized in that: The device comprises: A fourth acquisition module, used to obtain a security parameter set and authentication data in a bit stream; The security parameter set includes a hash period, and the hash period is used to indicate the maximum number of access units included in a bitstream segment; the authentication data includes signature data and a summary of each access unit in a group of access units, and the signature data is obtained by signing according to the summary of each access unit in the group of access units, and the authentication data carries an identifier, and the identifier occupies M bits, where M is an integer greater than or equal to 2, and the identifier is used to distinguish between consecutive 2 to the power of M authentication data in the bitstream, and the group of access units includes at least one access unit in the one bitstream segment; The second detection module is used to detect authentication data in the 2M-th power minus 1 hash cycle after the current hash cycle along the bit stream decoding order direction if there is an access unit participating in the signature in a hash cycle; if no authentication data is detected, it is determined that the authentication data is lost.
29. A bit stream detection device, characterized in that: The device comprises: A fifth acquisition module, used to acquire a security parameter set in a bit stream and the number of authentication data within the scope of the security parameter set; The scope of the security parameter set is a random access segment in the bitstream where the security parameter set is located, and the security data set includes indication information, where the indication information is used to indicate the number of authentication data that should be included in the scope of the security parameter set; The determination module is used to determine the loss of authentication data according to the indication information and the number of authentication data within the scope of the security parameter set.
30. A signature and authentication system, characterized in that: The system includes a signing end and an authentication end; The signing end is used to execute the method according to any one of claims 1 to 10; The authentication end is used to execute the method of any one of claims 21 to 24.
31. A chip, characterized in that: The chip comprises at least one processor and a memory, wherein the at least one processor executes a program or instruction stored in the memory so that the chip implements the method described in any one of claims 1 to 10 above, or implements the method described in any one of claims 21 to 24.
32. A computing device, characterized in that include: A memory and a processor, wherein the memory is used to store computer instructions; when the processor executes the computer instructions, the method described in any one of claims 1 to 10 is implemented, or the method described in any one of claims 21 to 24 is implemented.
33. A non-transitory computer-readable storage medium, characterized in that: The storage medium stores a computer program or instruction, which, when executed by a processing device, implements the method described in any one of claims 1 to 10; and / or, when executed by a processing device, implements the method described in any one of claims 21 to 24.
34. A computer program product, characterized in that The computer program product comprises computer instructions, which, when executed by a computer or a processor, cause the steps of the method according to any one of claims 1 to 10 to be performed, or the steps of the method according to any one of claims 21 to 24 to be performed.
35. A non-transitory computer-readable storage medium, characterized in that: The computer-readable storage medium stores a bit stream according to any one of claims 11 to 20.