Video encryption method, video encryption device and computer storage medium
By designing and storing encrypted frames in video cloud storage technology, and encrypting the video encryption key is used to encrypt the video encryption key, the security issues of video data transmission and storage are solved, efficient encrypted transmission and storage are achieved, and performance and security are improved.
Patent Information
- Application Number
- CN202510708083.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-29
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2045-05-29
AI Technical Summary
In the existing video cloud storage technology, the security issues of video data during transmission and storage are low in efficiency and have a great impact on cloud storage performance.
A video encryption method is proposed. By designing transmission encrypted frames and storing encrypted auxiliary frames in a video encryption system, encrypting the transmission auxiliary frames and video encryption keys in the storage auxiliary frames using the video key encryption key in the storage key, and inserting these auxiliary frames into the data stream to achieve efficient encrypted transmission and storage.
It realizes efficient encrypted transmission and storage of video cloud storage data streams, improves encryption efficiency and cloud storage performance, and ensures the security of video data.
Smart Images

Figure CN120238676A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of video cloud storage, and particularly to a video encryption method, a video encryption device, and a computer storage medium. Background Art
[0002] With the development of cloud computing technology, video cloud storage services have been widely used. However, the security issues of video data during transmission and storage have become increasingly prominent. Traditional encryption methods often have disadvantages such as low encryption efficiency for massive video data and great impact on cloud storage performance. Summary of the Invention
[0003] To solve the above technical problems, this application proposes a video encryption method, a video encryption device, and a computer storage medium.
[0004] To solve the above technical problems, this application proposes a video encryption method, which is applied to a video encryption platform in a video encryption system; the video encryption method includes: Obtain a first encrypted code stream from a video capture device, where an identification number of a video encryption key is stored in a transmission auxiliary frame in the first encrypted code stream; Obtain a storage key, and encrypt the video encryption key of the transmission auxiliary frame with the video key encryption key in the storage key; Generate a storage auxiliary frame according to the video key encryption key identification number of the storage key and the encrypted video encryption key; Insert the storage auxiliary frame into the first encrypted code stream, generate a second encrypted code stream and store it in a storage medium.
[0005] Wherein, the transmission auxiliary frame is generated by the video capture device writing the identification number of the video encryption key into a key frame extension header of a video code stream.
[0006] Wherein, the storage auxiliary frame includes an additional data field and an overall data field; The generating the storage auxiliary frame according to the video key encryption key identification number of the storage key and the encrypted video encryption key includes: Write the video key encryption key identification number of the storage key into the overall data field of the storage auxiliary frame; Write the encrypted video encryption key into the additional data field of the storage auxiliary frame.
[0007] Wherein, the inserting the storage auxiliary frame into the first encrypted code stream includes: Insert the storage auxiliary frame into the head position and / or the tail position of the first encrypted code stream.
[0008] Among them, the video encryption method further includes: Generate a random symmetric key and send the encrypted random symmetric key to the video acquisition device, so that the video acquisition device generates a video encryption key by using the encrypted random symmetric key.
[0009] To solve the above technical problems, the present application also proposes another video encryption method, which is characterized in that the video encryption method is applied to a video encryption system, where the video encryption system includes a video acquisition device, a video encryption platform, and a storage medium; the video encryption method includes: The video acquisition device encrypts the video stream by using the video encryption key to obtain an encrypted stream. The video acquisition device generates a transmission auxiliary frame according to the identification number of the video encryption key. The video encryption platform obtains the transmission auxiliary frame and the encrypted stream from the video acquisition device. The video encryption platform obtains a storage key and encrypts the video encryption key of the transmission auxiliary frame by using the video key encryption key in the storage key. The video encryption platform generates a storage auxiliary frame according to the video key encryption key identification number of the storage key and the encrypted video encryption key. The video encryption platform stores the storage auxiliary frame and the encrypted stream into the storage medium.
[0010] Among them, the video encryption system further includes a client. The video encryption method further includes: In response to the real-time video recording query instruction of the client, the video encryption platform sends the storage auxiliary frame and the encrypted stream to the client. The client obtains the storage key and the encrypted video encryption key based on the storage auxiliary frame. The client decrypts the encrypted video encryption key by using the video key encryption key in the storage key to obtain the video encryption key. The client decodes the encrypted stream by using the video encryption key to obtain and play the decoded stream.
[0011] Among them, the video encryption system further includes a client. The video encryption method further includes: In response to the historical video playback instruction of the client, the video encryption platform reads the storage auxiliary frame and the encrypted stream from the storage medium. The video encryption platform analyzes the video key encryption key identification number in the storage auxiliary frame, and queries the corresponding video key encryption key by using the video key encryption key identification number; The video encryption platform decrypts the encrypted video key encryption key by using the video key encryption key, and obtains the video key; The video encryption platform sends the video key and the encrypted cipher stream to the client; The client decodes the encrypted cipher stream by using the video key, and obtains and plays the decoded stream.
[0012] To solve the above technical problem, the present application also proposes a video encryption device, which includes a memory and a processor coupled to the memory; wherein, the memory is used to store program data, and the processor is used to execute the program data to implement the video encryption method as described above.
[0013] To solve the above technical problem, the present application also proposes a computer storage medium, which is used to store program data, and when the program data is executed by a computer, it is used to implement the above video encryption method.
[0014] Compared with the prior art, the beneficial effect of the present application is that: the video encryption platform obtains a first encrypted cipher stream from a video acquisition device, wherein, the transmission auxiliary frame in the first encrypted cipher stream stores the identification number of the video key; obtains a storage key, and encrypts the video key of the transmission auxiliary frame by using the video key encryption key in the storage key; generates a storage auxiliary frame according to the video key encryption key identification number of the storage key and the encrypted video key; inserts the storage auxiliary frame into the first encrypted cipher stream, generates a second encrypted cipher stream and stores it in a storage medium. Through the above video encryption method, a transmission encryption frame and a storage encryption auxiliary frame are designed, realizing efficient encrypted transmission and storage of video cloud storage data streams. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings. Among them: Figure 1 is a schematic flowchart of the first embodiment of the video encryption method provided by the present application; Figure 2 is a schematic overall flowchart of the video encryption method provided by the present application; Figure 3It is a schematic structural diagram of the key frame level description provided by this application; Figure 4 It is a schematic structural diagram of the detailed definition of the key frame header provided by this application; Figure 5 It is a schematic structural diagram of the detailed definition of the extended frame header provided by this application; Figure 6 It is a schematic structural diagram of the overall frame format definition provided by this application; Figure 7 It is a schematic structural diagram of the definition of the format of a single additional data provided by this application; Figure 8 It is a schematic structural diagram of the data content definition of the VK information provided by this application; Figure 9 It is a schematic flow diagram of the second embodiment of the video encryption method provided by this application; Figure 10 It is a schematic flow diagram of the third embodiment of the video encryption method provided by this application; Figure 11 It is a schematic flow diagram of the fourth embodiment of the video encryption method provided by this application; Figure 12 It is a schematic framework diagram of an embodiment of the video encryption system provided by this application; Figure 13 It is a schematic structural diagram of an embodiment of the video encryption device provided by this application; Figure 14 It is a schematic structural diagram of an embodiment of the computer storage medium provided by this application. Detailed implementation manners
[0016] Next, the technical solutions in the embodiments of this application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.
[0017] In the description, claims and the above-mentioned drawings of this application, terms such as "first", "second", "third", "fourth", etc. (if any) are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of this application described here, for example, can be implemented in an order other than those illustrated or described here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0018] In order to implement a new encryption method that can not only ensure the security of video data but also balance encryption efficiency and ensure high-performance scenarios in cloud storage, this application provides a transmission encryption and storage encryption method for video cloud storage data streams based on the national cryptography standard 39786-2021.
[0019] Among them, the cloud storage system involved in this application is a distributed data storage system composed of 1 to multiple metadata servers and data node servers; the metadata and real data of the stored files are separated, and the real data is stored in slices, and erasure code is used to achieve redundancy and fault tolerance. The specific technical terms and their meanings involved include but are not limited to the following: ICC: Intelligent Connection Center (Inteligent connection center).
[0020] VEK: Video Encryption Key, same as VK.
[0021] VK: Video Key (the name used for transmission encryption in GDPR, same as VEK).
[0022] VKEK: Video Key Encryption Key.
[0023] eVEK: Encrypted Video Encryption Key encrypted with VKEK.
[0024] sVK: Encrypted Video Key encrypted with VKEK.
[0025] VETK: Video Export Key (the VEK for encrypting the exported video).
[0026] IV: Initialization Vector.
[0027] KMS: Key Manager system.
[0028] Based on the above technical principles, please continue to refer to Figure 1 and Figure 2 , Figure 1 is a schematic flowchart of the first embodiment of the video encryption method provided by this application, Figure 2 is a schematic overall flowchart of the video encryption method provided by this application.
[0029] As Figure 2 shown, the video encryption system of this application includes but is not limited to: IPC (IP CAMERA) network cameras represent front-end video recording and acquisition devices (i.e., video acquisition devices), Server represents the platform and streaming media (i.e., video encryption platform), Disk represents the physical disk in cloud storage (i.e., storage medium), KMSAgent represents the KMS (Key Management Service) proxy service, and Client represents the video viewing client.
[0030] The video encryption system of this application generally follows the principle that whoever generates the audio and video code stream encrypts it, and whoever uses the audio and video code stream decrypts it. The front-end device encrypts the acquired audio and video and transmits it, i.e., source-side encryption; the storage device or platform stores the encrypted audio and video, and the storage device and platform support users to play the real-time encrypted audio and video, play back the encrypted video recording, download the encrypted video recording, and export within the scope of their permissions.
[0031] The above video encryption platform supports user identity authentication based on the digital certificate stored in the USBKey (identity authentication). For users who pass the authentication, they can play the real-time encrypted audio and video, play back the encrypted video recording, download the encrypted video recording, and export according to their permissions. The encrypted audio and video file after export can only be decrypted and played in a dedicated player with the user's USBKey.
[0032] The main innovation point of the video encryption method of this application is the encryption operation of video data, and the encryption operation is divided into two stages: transmission encryption and storage encryption. When the audio and video are transmitted, the transmission encryption frame format is used for transmission, and the VK of the corresponding encrypted video is pushed through a digital envelope before transmission. When the audio and video are encrypted and stored, the backend storage stores them by inserting a storage encryption auxiliary frame in front of the transmission encryption frame. On the software platform side, it stores them by saving the equivalent storage encryption auxiliary frame in the database and saving the transmission encryption frame as it is to the cloud storage.
[0033] Among them, Figure 2 the Key Management System (KMS) in Figure 2 is used for the lifecycle management of the VKEK and is responsible for the distribution of the VKEK in the system.
[0034] To solve the problems of network isolation between subsystems in the video surveillance system and the differences in the docking methods with KMSs of different manufacturers, the present application introduces a KMS proxy service in the storage device and the software platform. The KMS proxy service can directly dock with the KMS or can be cascaded with the upper-level KMS proxy. When each subsystem needs to obtain the VKEK, it docks with the directly network-reachable KMS proxy service.
[0035] As Figure 1 shown, the specific steps are as follows: Step S11: Obtain the first encrypted cipher stream from the video capture device, where the transmission auxiliary frame in the first encrypted cipher stream stores the identification number of the video encryption key.
[0036] In the embodiment of the present application, as Figure 2 shown, the video capture device generates a device signature certificate, a device signature private key, a device encryption certificate, a device encryption private key, a CA (Certificate Authority) certificate, etc.
[0037] The video encryption platform generates a platform signature certificate, a platform signature private key ID (Identity document), a platform encryption certificate, a platform encryption private key, a CA certificate; a platform certificate, a platform private key ID, a user certificate, etc.
[0038] Before video data transmission and encryption, the video capture device and the video encryption platform need to complete two-way authentication based on digital certificates and complete certificate exchange through the TLCP (Information security technology—Transport layer cryp, Transport Layer Cryptography Protocol) protocol.
[0039] Then, during the digital envelope negotiation process, the video encryption platform generates a random symmetric key for subsequent video stream encryption, and the video capture device can obtain the encrypted symmetric key through the digital envelope technology and the RTSP (Real Time Streaming Protocol) protocol. The video capture device generates the video encryption key VK using the encrypted random symmetric key.
[0040] In an embodiment of the present application, on the one hand, the video capture device transmits the video encryption key VK encrypted with a symmetric key to the video encryption platform. On the other hand, it encrypts the 2KB data of the video stream key frame header with the video encryption key VK encrypted with the symmetric key to obtain the encrypted bitstream. At the same time, the VKID (identification number of the video encryption key) is encapsulated into the extended frame header of the key frame for transmission to the video encryption platform.
[0041] Specifically, in order to achieve transmission encryption between the video capture device and the video encryption platform, the present application provides a design for the transmission encryption frame structure.
[0042] Among them, the present application designs a frame structure for transmission encryption, which is used to encrypt the audio and video transmission process. The audio and video encrypted transmission adopts the key frame encryption method, and by default, only the 2KB data header of the key frame is encrypted. Compared with encrypting the entire complete frame or encrypting a large amount of video streams, key frame encryption can significantly reduce the computing resources required for encryption and decryption because the number of key frames is much less than that of P frames and B frames, and the small amount of 2KB data is also much less than the general key frame size. It is more suitable for scenarios that balance security and performance, improving the transmission and playback efficiency of the video stream, which is particularly important for real-time video streams and large-scale video distribution scenarios.
[0043] The specific process of transmission encryption is as follows: The user (the video capture device in the present application) transmits the encrypted key (SM4) based on the RTSP protocol, and this key is used for subsequent bitstream encryption.
[0044] The video capture device and the video encryption platform negotiate the symmetric key (SM4) based on the simplified digital envelope (SM2) interaction process. Through this step, the two parties can securely exchange the encryption key, laying the foundation for subsequent encryption operations.
[0045] The bitstream encryption defaults to the OFB (Output Feedback Mode) mode, which is suitable for encrypting streaming media data and can provide a high encryption speed and low latency.
[0046] Define the bitstream encryption offset and the bitstream encryption length (by default, the key frame header is 2KB). The bitstream encryption offset refers to the number of bytes to offset from the starting position of the original raw bitstream data before starting encryption; the bitstream encryption length refers to the length of the data encrypted starting from the offset position, in bytes. The setting of these two parameters can flexibly control the encryption granularity and range to meet different security requirements.
[0047] Furthermore, for the design of the transmission encryption extended frame structure of the present application, please continue to refer to Figures 3 to 5 , Figure 3 which is the schematic structural diagram of the key frame level description provided by the present application.Figure 4 It is a schematic diagram of the detailed definition of the key frame header provided by this application. Figure 5 It is a schematic diagram of the detailed definition of the extended frame header provided by this application.
[0048] As Figure 3 shown, the composition of the key frame is successively a frame header with a length of 24 bytes, variable-length frame data, and a frame tail with a length of 8 bytes. Taking Figure 5 as an example, the transmission encryption extended frame is extended backward from the standard frame header, and its length is variable, used to store key information such as VKID. And Figure 4 the detailed definition of the key frame header represents the 24-byte content of the frame header and the position of the extended field. The extended field starts from the 24th byte and has a variable length.
[0049] For details, please continue to refer to Figure 5 , and the extended frame is defined as follows: (1) Extended frame header type: 0xB5, used to mark and distinguish the extended frame.
[0050] (2) Extended frame length: variable length, the length of the extended frame in time.
[0051] (3) Bitstream encryption type: The bitstream encryption uses the encryption type of the OFB mode. The following several configurations are supported: 0: Reserved, no type.
[0052] 1: AES256-OFB-NOPADDING, an AES encryption algorithm using a 256-bit key, encrypted using the output feedback mode, and no data padding is performed. This type of encryption is usually used in scenarios that require high security and continuous encryption capabilities.
[0053] 2: SM4-OFB-NOPADDING, an encryption method that uses the SM4 algorithm, the output feedback mode, and no data padding. It is suitable for scenarios that require continuous encryption of a large amount of data or real-time data streams.
[0054] 3: SM4-ECB-NOPADDING, an encryption method that uses the SM4 algorithm, the electronic codebook mode, and no data padding. It is suitable for encrypting fixed-length data blocks.
[0055] 4: SM1-OFB-NOPADDING, an encryption method that uses the SM1 algorithm, the output feedback mode, and no data padding. It is suitable for scenarios that require continuous encryption of a large amount of data or real-time data streams.
[0056] 5: SM1-ECB-NOPADDING, an encryption method that uses the SM1 algorithm, the electronic codebook mode, and no data padding. It is suitable for encrypting fixed-length data blocks.
[0057] (4) Bitstream encryption offset: Starting from the start position of the original raw bitstream data, how many bytes to offset for encryption.
[0058] (5) Bitstream encryption length: The length of the data encrypted starting from the offset position, in bytes, that is, how much data needs to be decrypted to be played normally.
[0059] (6) VKID: The ID of the video encryption key VK (i.e., VEK). The client can obtain VK from the local cache through this ID number. This VK is provided by the device and is negotiated and transmitted for the first time by the RTSP protocol and digital envelope technology.
[0060] (7) CRC16: Perform a CRC16 checksum on the data before encryption for verification during decoding.
[0061] (8) Bitstream encryption IV: The initial vector for symmetric encryption when encrypting the bitstream.
[0062] Step S12: Obtain the storage key and encrypt the video encryption key of the transmission auxiliary frame using the video key encryption key in the storage key.
[0063] In the embodiment of the present application, the video encryption platform obtains the storage keys: VKEK and VKEKID through the KMS proxy, and encrypts VK using VKEK to obtain eVK.
[0064] Step S13: Generate a storage auxiliary frame according to the video key encryption key identification number of the storage key and the encrypted video encryption key.
[0065] In the embodiment of the present application, the video encryption platform generates a storage auxiliary frame using the VKEKID, VKID, and eVK generated in step S14.
[0066] Specifically, in order to implement storage encryption between the storage medium and the video encryption platform, the present application provides a design for the structure of the storage encryption auxiliary frame.
[0067] Among them, audio and video encryption storage adds a storage encryption auxiliary frame by encrypting the storage encryption key, and the encryption key is managed by KMS.
[0068] The present application supports the encrypted bitstream through the design of the storage encryption auxiliary frame structure, and inserts a storage encryption auxiliary frame at the head and tail of the video recording file. These two auxiliary frames are used to save the video encryption key VK (i.e., VEK) encrypted by VKEK and VKEKID. Ensure that the VKEK used for the storage encryption auxiliary frames at the head and tail of each video recording file is the same, and only the same VK and VKEK are used in each video recording file. This design can simplify key management, improve encryption efficiency, and ensure data consistency and security at the same time.
[0069] Specifically, for the storage encryption auxiliary frame design of this application, please refer to Figures 6 to 8 , Figure 6 which is a schematic structural diagram of the overall frame format definition provided by this application, Figure 7 which is a schematic structural diagram of the single additional data format definition provided by this application, Figure 8 which is a schematic structural diagram of the data content definition of the VK information provided by this application.
[0070] As Figure 6 shown, the overall frame format is defined as follows: VKEK type: 0x00 – KMS allocation; 0x01 – user allocation; 0x02 – USBKey allocation.
[0071] VKEKID: The VKEK identifier allocated by KMS or the key identifier in the USBKey.
[0072] As Figure 7 shown, the single additional data format is defined as follows: Data type: 0x01 – VK information.
[0073] As Figure 8 shown, the data content definition of the VK information is as follows: VKID: The VK (i.e., VEK) identifier.
[0074] IV: The initial vector for symmetric encryption, not required in the ECB (Electronic Codebook Mode) mode.
[0075] VK encrypted value: The VK (i.e., eVK) encrypted by the VKEK.
[0076] Encryption type: The algorithm for encrypting the VK by the VKEK, the synchronous code stream encryption algorithm.
[0077] Step S14: Insert the storage auxiliary frame into the first encrypted code stream, generate the second encrypted code stream, and store it in the storage medium.
[0078] In the embodiment of this application, the video encryption platform stores the storage encryption auxiliary frame and the encrypted code stream together on the cloud storage disk.
[0079] Specifically, the video encryption platform inserts a storage encryption auxiliary frame at the head and tail of the video file of the encrypted code stream to generate a new encrypted code stream.
[0080] In this application, the video encryption platform obtains a first encrypted code stream from a video capture device. Among them, the identification number of the video encryption key is stored in the transmission auxiliary frame in the first encrypted code stream; obtains the storage key, and encrypts the video encryption key of the transmission auxiliary frame by using the video key encryption key in the storage key; generates a storage auxiliary frame according to the video key encryption key identification number of the storage key and the encrypted video encryption key; inserts the storage auxiliary frame into the first encrypted code stream, generates a second encrypted code stream and stores it in a storage medium. Through the above video encryption method, transmission encrypted frames and storage encrypted auxiliary frames are designed, realizing efficient encrypted transmission and storage of video cloud storage data streams.
[0081] Please refer to Figure 2 Continue to refer to Figure 9 , Figure 9 which is a schematic flowchart of the second embodiment of the video encryption method provided by this application.
[0082] As Figure 9 shown, the specific steps are as follows: Step S21: The video capture device encrypts the video code stream by using the video encryption key to obtain an encrypted code stream.
[0083] Step S22: The video capture device generates a transmission auxiliary frame according to the identification number of the video encryption key.
[0084] Step S23: The video encryption platform obtains the transmission auxiliary frame and the encrypted code stream from the video capture device.
[0085] Step S24: The video encryption platform obtains the storage key, and encrypts the video encryption key of the transmission auxiliary frame by using the video key encryption key in the storage key.
[0086] Step S25: The video encryption platform generates a storage auxiliary frame according to the video key encryption key identification number of the storage key and the encrypted video encryption key.
[0087] Step S26: The video encryption platform stores the storage auxiliary frame and the encrypted code stream in a storage medium.
[0088] In the embodiment of this application, the content of the above steps S21 to S26 has been elaborated in detail in steps S11 to S14 of the video encryption method shown above, and will not be repeated here. Figure 1 shown, and will not be elaborated here.
[0089] Furthermore, as Figure 2 shown, the video encryption system of this application further includes a client Client to provide a function for users to call and view video data.
[0090] For details, please refer to Figure 10 , Figure 10It is a schematic flowchart of the third embodiment of the video encryption method provided by this application.
[0091] As Figure 10 shown, the specific steps are as follows: Step S31: In response to the real-time video recording query instruction of the client, the video encryption platform sends the stored auxiliary frame and the encrypted cipher stream to the client.
[0092] Step S32: The client obtains the storage key and the encrypted video encryption key based on the stored auxiliary frame.
[0093] Step S33: The client decrypts the encrypted video encryption key using the video key encryption key in the storage key to obtain the video encryption key.
[0094] Step S34: The client decodes the encrypted cipher stream using the video encryption key to obtain and play the decoded stream.
[0095] In the embodiment of this application, when the user inputs a real-time video recording query instruction through the client, the client can directly obtain the VKID and the encrypted cipher stream in the transmission encrypted frame from the video encryption platform. Therefore, the client can directly decrypt to obtain VK, and use VK to decrypt the 2KB data of the key frame header to play.
[0096] Specifically, when the client performs real-time preview, the video stream data obtained by the client through the streaming media service needs to decrypt the encrypted frames in the video stream to play normally. At this time, only need to obtain the VKID according to the extended frame data in the key frame, first obtain the video encryption key VK (i.e., VEK) from the front end through the VKID, and then use VK to decrypt the cipher stream, reducing the complex key synchronization process. Subsequently, the client can quickly complete the decryption action according to the code stream data itself and the client cache data.
[0097] Specifically, please refer to Figure 11 , Figure 11 It is a schematic flowchart of the fourth embodiment of the video encryption method provided by this application.
[0098] Step S41: In response to the historical video recording playback instruction of the client, the video encryption platform reads the stored auxiliary frame and the encrypted cipher stream from the storage medium.
[0099] Step S42: The video encryption platform parses the video key encryption key identification number in the stored auxiliary frame, and queries the corresponding video key encryption key using the video key encryption key identification number.
[0100] Step S43: The video encryption platform decrypts the encrypted video encryption key using the video key encryption key to obtain the video encryption key.
[0101] Step S44: The video encryption platform sends the video encryption key and the encrypted cipher stream to the client.
[0102] Step S45: The client uses the video encryption key to decode the encrypted cipher stream, obtains and plays the decoded stream.
[0103] In the embodiment of the present application, when the user inputs a historical video playback instruction through the client, the client needs to first exchange certificates with the video encryption platform to complete mutual authentication, and then initiate an RTSP request. The video encryption platform generates a random symmetric key for this interaction, encrypts the SM4 symmetric key with the SM2 private key and transmits it to the client to establish a secure connection.
[0104] The video encryption platform reads the video file from the cloud storage, obtains the stored encrypted auxiliary frame and the encrypted cipher stream. The video encryption platform parses the VKEKID in the encrypted auxiliary frame, queries the VKEK through the KMS proxy, and decrypts the eVk with the VKEK to obtain the video encryption key VK.
[0105] The video encryption platform securely transmits the VK encrypted by RTSP and the symmetric key to the client, and the client can query and obtain it subsequently.
[0106] Specifically, when the client performs video playback, the video encryption platform reads the encrypted video file data from the cloud storage, first obtains the VKEKID by reading the encrypted auxiliary frame at the head, and queries the VKEK through the VKEKID from the KMS. The video encryption platform uses the VKEK to decrypt the eVk, obtains the VK, uses the VK to decrypt the video file data, and the client completes the playback.
[0107] This application directly stores the encrypted VK in the video file, reducing the conventional complex key synchronization process, which not only ensures security but also facilitates fast decryption for video playback.
[0108] The video encryption method of this application realizes the end-to-end transmission encryption and storage encryption functions of the data stream by designing the transmission encryption extension frame and the storage encryption auxiliary frame.
[0109] The video encryption method of this application designs a transmission encryption extension frame. By defining the cipher stream encryption offset and the cipher stream encryption length, it improves the encryption transmission efficiency and security. At the same time, the video encryption key ID (VKID) is extended and recorded in the key frame header. When the client previews, the encryption key can be queried through the VKID in the real-time cipher stream, realizing the fast decryption preview of the real-time cipher stream, and improving the encryption and decryption efficiency on the basis of secure transmission.
[0110] The video encryption method of this application designs a storage encryption auxiliary frame to store the video encryption key VEK encrypted by the VKEK and the VKEKID. Record the VKEKID in the auxiliary frame, and insert a storage encryption auxiliary frame at the head and tail of the video file respectively to achieve the effect of fast decryption during the playback process.
[0111] In the storage encryption auxiliary frame of the video encryption method of this application, it is necessary to ensure that the VKEKs used in the storage encryption auxiliary frames at the head and tail of each video file are the same, and only the same VK and VKEK are used in each video file.
[0112] Those skilled in the art can understand that in the above method of the specific implementation manner, the writing order of each step does not mean a strict execution order and does not constitute any limitation to the implementation process. The specific execution order of each step should be determined according to its function and possible internal logic.
[0113] To implement the above video encryption method, this application also proposes a video encryption system. For details, please refer to Figure 12 , Figure 12 which is a schematic framework diagram of an embodiment of the video encryption system provided by this application.
[0114] The video encryption system 500 of this embodiment includes: a video acquisition device 51, a video encryption platform 52, and a storage medium 53.
[0115] Among them, the video acquisition device 51 is used to encrypt the video stream using the video encryption key to obtain the encrypted stream.
[0116] The video acquisition device 51 is used to generate a transmission auxiliary frame according to the identification number of the video encryption key.
[0117] The video encryption platform 52 is used to obtain the transmission auxiliary frame and the encrypted stream from the video acquisition device.
[0118] The video encryption platform 52 is used to obtain the storage key, and use the video key encryption key in the storage key to encrypt the video encryption key of the transmission auxiliary frame.
[0119] The video encryption platform 52 is used to generate a storage auxiliary frame according to the video key encryption key identification number of the storage key and the encrypted video encryption key.
[0120] The video encryption platform 52 is used to store the storage auxiliary frame and the encrypted stream into the storage medium 53.
[0121] To implement the above video encryption method, this application also proposes a video encryption device. For details, please refer to Figure 13 , Figure 13It is a schematic structural diagram of an embodiment of the video encryption device provided by this application.
[0122] The video encryption device 700 in this embodiment includes a processor 71, a memory 72, an input / output device 73, and a bus 74.
[0123] The processor 71, the memory 72, and the input / output device 73 are respectively connected to the bus 74. Program data is stored in the memory 72, and the processor 71 is configured to execute the program data to implement the video encryption method described in the above embodiment.
[0124] In the embodiment of this application, the processor 71 may also be referred to as a CPU (Central Processing Unit). The processor 71 may be an integrated circuit chip with signal processing capabilities. The processor 71 may also be a general-purpose processor, a digital signal processor (DSP, Digital Signal Process), an application specific integrated circuit (ASIC, Application Specific Integrated Circuit), a field programmable gate array (FPGA, FieldProgrammable Gate Array), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. The general-purpose processor may be a microprocessor or the processor 71 may also be any conventional processor, etc.
[0125] This application also provides a computer storage medium. Please continue to refer to Figure 14 , Figure 14 It is a schematic structural diagram of an embodiment of the computer storage medium provided by this application. A computer program 61 is stored in the computer storage medium 600. When the computer program 61 is executed by a processor, it is used to implement the video encryption method described in the above embodiment.
[0126] When the embodiments of the present application are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the methods described in various embodiments of the present application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs.
[0127] The above are only the embodiments of the present application, and do not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present application, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present application.
Claims
1. A video encryption method, characterized in that, The video encryption method is applied to a video encryption platform in a video encryption system; The video encryption method includes: Obtaining a first encrypted cipher stream from a video capture device, where an identification number of a video encryption key is stored in a transmission auxiliary frame in the first encrypted cipher stream; Obtaining a storage key, and encrypting the video encryption key of the transmission auxiliary frame with the video key encryption key in the storage key; Generating a storage auxiliary frame according to the video key encryption key identification number of the storage key and the encrypted video encryption key; Inserting the storage auxiliary frame into the first encrypted cipher stream, generating a second encrypted cipher stream and storing it in a storage medium.
2. The video encryption method according to claim 1, wherein The transmission auxiliary frame is generated by the video capture device writing the identification number of the video encryption key into a key frame extension header of a video code stream.
3. The video encryption method according to claim 1, wherein The storage auxiliary frame includes an additional data field and an overall data field; The generating a storage auxiliary frame according to the video key encryption key identification number of the storage key and the encrypted video encryption key includes: Writing the video key encryption key identification number of the storage key into the overall data field of the storage auxiliary frame; Writing the encrypted video encryption key into the additional data field of the storage auxiliary frame.
4. The video encryption method according to claim 3, wherein The inserting the storage auxiliary frame into the first encrypted cipher stream includes: Inserting the storage auxiliary frame into a head position and / or a tail position of the first encrypted cipher stream.
5. The video encryption method according to claim 1, wherein The video encryption method further includes: Generating a random symmetric key, and sending the encrypted random symmetric key to the video capture device, so that the video capture device generates a video encryption key by using the encrypted random symmetric key.
6. A video encryption method, characterized in that, The video encryption method is applied to a video encryption system, wherein the video encryption system includes a video capture device, a video encryption platform and a storage medium; the video encryption method includes: The video capture device encrypts a video code stream with a video encryption key to obtain an encrypted cipher stream; The video capture device generates a transmission auxiliary frame according to the identification number of the video encryption key; The video encryption platform obtains the transmission auxiliary frame and the encrypted cipher stream from the video capture device; The video encryption platform obtains a storage key, and encrypts the video encryption key of the transmission auxiliary frame with the video key encryption key in the storage key; The video encryption platform generates a storage auxiliary frame according to the video key encryption key identification number of the storage key and the encrypted video encryption key; The video encryption platform stores the storage auxiliary frame and the encrypted cipher stream in the storage medium.
7. The video encryption method according to claim 6, wherein The video encryption system further includes a client; The video encryption method further includes: In response to the real-time video recording query instruction of the client, the video encryption platform sends the storage auxiliary frame and the encrypted cipher stream to the client; The client obtains the storage key and the encrypted video encryption key based on the storage auxiliary frame; The client decrypts the encrypted video encryption key by using the video key encryption key in the storage key to obtain the video encryption key; The client decodes the encrypted cipher stream by using the video encryption key to obtain and play the decoded stream.
8. The video encryption method according to claim 6, wherein The video encryption system further includes a client; The video encryption method further includes: In response to the historical video playback instruction of the client, the video encryption platform reads the storage auxiliary frame and the encrypted cipher stream from the storage medium; The video encryption platform analyzes the video key encryption key identification number in the storage auxiliary frame and queries the corresponding video key encryption key by using the video key encryption key identification number; The video encryption platform decrypts the encrypted video encryption key by using the video key encryption key to obtain the video encryption key; The video encryption platform sends the video encryption key and the encrypted cipher stream to the client; The client decrypts the encrypted cipher stream by using the video encryption key to obtain and play the decoded stream.
9. A video encryption device, characterized in that, The video encryption device includes a memory and a processor coupled to the memory; Wherein, the memory is used for storing program data, and the processor is used for executing the program data to implement the video encryption method according to any one of claims 1 to 8.
10. A computer storage medium, characterized in that, The computer storage medium is used for storing program data, and when the program data is executed by a computer, it is used to implement the video encryption method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Audio and video data playing method and device, equipment, storage medium and program product
CN118828064A
Video security downloading and playing method based on GB35114 protocol
CN119172569A
Encrypted video playing method and device, storage medium and computer equipment
CN119484898A
Data protection method and device and storage medium
CN119788436A
Encryption recorder, encryption recording method, program to allow computer to execute the method, and computer-readable recording medium with the program recorded
JP2002304807A