Video encryption method, video encryption device and computer storage medium

By designing the transmission of encrypted frames and the storage of encrypted auxiliary frames, the problem of low encryption efficiency in video cloud storage is solved, efficient video data encryption and secure storage are achieved, and encryption efficiency and security are improved.

CN120238676BActive Publication Date: 2025-09-05ZHEJIANG DAHUA TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510708083.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-29
Publication Date
2025-09-05
Estimated Expiration
2045-05-29

AI Technical Summary

Technical Problem

Existing video cloud storage encryption methods are inefficient, have a significant impact on cloud storage performance, and are difficult to achieve efficient video data encryption and secure storage.

Method used

Design the transmission encrypted frame and storage encrypted auxiliary frame, obtain the video encryption key identification number in the encrypted code stream through the video acquisition device, use the storage key to encrypt the transmission auxiliary frame, and generate the storage auxiliary frame in the video encryption platform, and insert it into the encrypted code stream for storage.

Benefits of technology

It achieves efficient encrypted transmission and storage of video cloud storage data streams, improves encryption efficiency and security, and reduces the impact on cloud storage performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238676B_ABST
    Figure CN120238676B_ABST
Patent Text Reader

Abstract

The present application proposes a video encryption method, a video encryption device, and a computer storage medium. The video encryption method includes: obtaining a first encryption code stream from a video capture device, wherein the transmission auxiliary frame in the first encryption code stream stores the identification number of the video encryption key; obtaining a storage key, and using the video key encryption key in the storage key to encrypt the video encryption key of the transmission auxiliary frame; generating a storage auxiliary frame based on the video key encryption key identification number of the storage key and the encrypted video encryption key; inserting the storage auxiliary frame into the first encryption code stream to generate a second encryption code stream and store it in a storage medium. Through the above-mentioned video encryption method, the transmission encryption frame and the storage encryption auxiliary frame are designed to achieve efficient encrypted transmission and storage of video cloud storage data streams.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of video cloud storage technology, and in particular to a video encryption method, a video encryption device, and a computer storage medium. Background Art

[0002] With the development of cloud computing technology, video cloud storage services have become widely used. However, the security issues of video data during transmission and storage are becoming increasingly prominent. Traditional encryption methods often have shortcomings such as low encryption efficiency for massive video data and significant impact on cloud storage performance. Summary of the Invention

[0003] To solve the above technical problems, the present application proposes a video encryption method, a video encryption device and a computer storage medium.

[0004] To solve the above technical problems, the present application proposes a video encryption method, which is applied to a video encryption platform in a video encryption system; the video encryption method comprises:

[0005] Acquire a first encrypted code stream from a video capture device, wherein a transmission auxiliary frame in the first encrypted code stream stores an identification number of a video encryption key;

[0006] Obtaining a storage key, and encrypting the video encryption key of the transmission auxiliary frame using a video key encryption key in the storage key;

[0007] Generate a storage auxiliary frame according to the video key encryption key identification number of the storage key and the encrypted video encryption key;

[0008] The storage auxiliary frame is inserted into the first encrypted code stream to generate a second encrypted code stream and store it in a storage medium.

[0009] The transmission auxiliary frame is generated by the video acquisition device writing the identification number of the video encryption key into the key frame extended frame header of the video code stream.

[0010] Wherein, the storage auxiliary frame includes an additional data field and an overall data field;

[0011] The step of generating a storage auxiliary frame according to the video key encryption key identification number of the storage key and the encrypted video encryption key includes:

[0012] Writing the video key encryption key identification number of the storage key into the overall data field of the storage auxiliary frame;

[0013] The encrypted video encryption key is written into the additional data field of the storage auxiliary frame.

[0014] The step of inserting the storage auxiliary frame into the first encrypted code stream includes:

[0015] The storage auxiliary frame is inserted into the head position and / or the tail position of the first encrypted code stream.

[0016] The video encryption method further includes:

[0017] A random symmetric key is generated, and the encrypted random symmetric key is sent to the video acquisition device, so that the video acquisition device generates a video encryption key using the encrypted random symmetric key.

[0018] To solve the above technical problems, the present application also proposes another video encryption method, characterized in that the video encryption method is applied to a video encryption system, wherein the video encryption system includes a video acquisition device, a video encryption platform and a storage medium; the video encryption method includes:

[0019] The video capture device encrypts the video code stream using the video encryption key to obtain an encrypted code stream;

[0020] The video acquisition device generates a transmission auxiliary frame according to the identification number of the video encryption key;

[0021] The video encryption platform obtains the transmission auxiliary frame and the encryption code stream from the video acquisition device;

[0022] The video encryption platform obtains a storage key and encrypts the video encryption key of the transmission auxiliary frame using a video key encryption key in the storage key;

[0023] The video encryption platform generates a storage auxiliary frame according to the video key encryption key identification number of the storage key and the encrypted video encryption key;

[0024] The video encryption platform stores the storage auxiliary frame and the encrypted code stream in the storage medium.

[0025] Wherein, the video encryption system further includes a client;

[0026] The video encryption method further includes:

[0027] In response to a real-time video query instruction from the client, the video encryption platform sends the stored auxiliary frame and the encrypted code stream to the client;

[0028] The client obtains the storage key and the encrypted video encryption key based on the storage auxiliary frame;

[0029] The client uses the video key encryption key in the storage key to decrypt the encrypted video encryption key to obtain the video encryption key;

[0030] The client decodes the encrypted code stream using the video encryption key, and obtains and plays the decoded code stream.

[0031] Wherein, the video encryption system further includes a client;

[0032] The video encryption method further includes:

[0033] In response to a historical video playback instruction from the client, the video encryption platform reads the stored auxiliary frame and the encrypted code stream from the storage medium;

[0034] The video encryption platform parses the video key encryption key identification number in the storage auxiliary frame, and uses the video key encryption key identification number to query the corresponding video key encryption key;

[0035] The video encryption platform decrypts the encrypted video encryption key using the video key encryption key to obtain the video encryption key;

[0036] The video encryption platform sends the video encryption key and the encrypted code stream to the client;

[0037] The client decodes the encrypted code stream using the video encryption key, and obtains and plays the decoded code stream.

[0038] In order to solve the above technical problems, the present application also proposes a video encryption device, which includes a memory and a processor coupled to the memory; wherein the memory is used to store program data, and the processor is used to execute the program data to implement the video encryption method as described above.

[0039] In order to solve the above technical problems, the present application also proposes a computer storage medium, which is used to store program data. When the program data is executed by a computer, it is used to implement the above video encryption method.

[0040] Compared with the existing technology, the beneficial effects of this application are as follows: the video encryption platform obtains a first encrypted code stream from a video capture device, wherein the transmission auxiliary frame in the first encrypted code stream stores the identification number of the video encryption key; obtains the storage key, and uses the video key encryption key in the storage key to encrypt the video encryption key of the transmission auxiliary frame; generates a storage auxiliary frame based on the video key encryption key identification number of the storage key and the encrypted video encryption key; inserts the storage auxiliary frame into the first encrypted code stream, generates a second encrypted code stream, and stores it in a storage medium. Through the above-mentioned video encryption method, the transmission encrypted frame and the storage encrypted auxiliary frame are designed to achieve efficient encrypted transmission and storage of video cloud storage data streams. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without inventive efforts. Among them:

[0042] Figure 1 This is a flowchart of the first embodiment of the video encryption method provided by this application;

[0043] Figure 2 This is a schematic diagram of the overall process of the video encryption method provided by this application;

[0044] Figure 3 This is a schematic diagram of the structure of the key frame hierarchy description provided by this application;

[0045] Figure 4 This is a schematic diagram of the structure of the detailed definition of the key frame header provided by this application;

[0046] Figure 5 This is a schematic diagram of the structure of the detailed definition of the extended frame header provided by this application;

[0047] Figure 6 This is a schematic diagram of the overall frame format definition provided by this application;

[0048] Figure 7 This is a schematic diagram of the structure of a single additional data format definition provided by this application;

[0049] Figure 8 This is a schematic diagram of the structure of the data content definition of the VK information provided by this application;

[0050] Figure 9 This is a flow chart of the second embodiment of the video encryption method provided by this application;

[0051] Figure 10This is a flowchart of the third embodiment of the video encryption method provided by this application;

[0052] Figure 11 This is a flowchart of a fourth embodiment of the video encryption method provided by this application;

[0053] Figure 12 This is a schematic diagram of the framework of an embodiment of a video encryption system provided by the present application;

[0054] Figure 13 This is a structural diagram of an embodiment of a video encryption device provided by the present application;

[0055] Figure 14 It is a structural diagram of an embodiment of a computer storage medium provided by this application. DETAILED DESCRIPTION

[0056] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0057] The terms "first," "second," "third," "fourth," and the like (if any) in the specification and claims of this application and in the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of the application described herein can, for example, be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or elements is not necessarily limited to those steps or elements explicitly listed, but may include other steps or elements not explicitly listed or inherent to such process, method, product, or apparatus.

[0058] In order to realize a new encryption method that can ensure the security of video data while taking into account encryption efficiency and ensuring high-performance cloud storage scenarios, this application provides a transmission encryption and storage encryption method for video cloud storage data streams based on the National Secret 39786-2021 standard.

[0059] The cloud storage system involved in this application is a distributed data storage system consisting of one or more metadata servers and data node servers. The metadata and actual data of stored files are separated, and the actual data is stored in shards. Erasure codes are used for redundancy and fault tolerance. Specific technical terms and their meanings include, but are not limited to, the following:

[0060] ICC: Intelligent connection center.

[0061] VEK: Video Encryption Key (Video EncryptionKey), same as VK.

[0062] VK: Video Encryption Key (GDPR’s name for transmission encryption, same as VEK).

[0063] VKEK: Video Key Encryption Key.

[0064] eVEK: VEK (Encrypted Video Encryption Key) encrypted using VKEK.

[0065] sVK: VK / VEK (Encrypted Video Key) encrypted using VKEK.

[0066] VETK: Video Export Encryption Key (VEK for encrypting exported video).

[0067] IV: Initialization Vector.

[0068] KMS: Key Management System.

[0069] Based on the above technical principles, please continue to refer to Figure 1 and Figure 2 , Figure 1 This is a flow chart of the first embodiment of the video encryption method provided by this application. Figure 2 This is a schematic diagram of the overall process of the video encryption method provided by this application.

[0070] like Figure 2As shown, the video encryption system of the present application includes but is not limited to: IPC (IP CAMERA) network camera represents the front-end video acquisition device (i.e., video acquisition device), Server represents the platform and streaming media (i.e., video encryption platform), Disk represents the physical disk in the cloud storage (i.e., storage medium), KMSAgent represents KMS (Key Management Service, key management service) agent service, and Client represents the video viewing client.

[0071] The video encryption system of this application generally follows the principle that whoever generates the video and audio stream encrypts it, and whoever uses the video and audio stream decrypts it. The front-end device encrypts and transmits the captured video and audio, i.e., source-side encryption. The storage device or platform stores the encrypted video and audio. The storage device and platform support real-time encrypted video and audio playback, encrypted video playback, encrypted video downloading, and exporting within the user's permission range.

[0072] The aforementioned video encryption platform supports user authentication based on digital certificates stored in a USBKey (identity authentication). Authenticated users can, based on their permissions, perform real-time encrypted audio and video playback, encrypted video playback, encrypted video download, and export. Exported encrypted audio and video files can only be decrypted and played in a dedicated player with the user's USBKey.

[0073] The main innovation of the video encryption method of this application lies in the encryption operation of video data, which is divided into two stages: transmission encryption and storage encryption. During the transmission process, audio and video are transmitted in the transmission encryption frame format, and the corresponding encrypted video VK is pushed through a digital envelope before transmission. When the audio and video are encrypted and stored, the back-end storage stores them by inserting a storage encryption auxiliary frame before the transmission encryption frame. On the software platform side, the equivalent storage encryption auxiliary frame is saved in the database and the transmission encryption frame is saved as is to the cloud storage for storage.

[0074] in, Figure 2 The key management system KMS in the system is used for the life cycle management of VKEK and is responsible for the issuance of VKEK in the system.

[0075] To address the network isolation between subsystems in video surveillance systems and the differences in KMS connection methods between different vendors, this application introduces a KMS proxy service within the storage device and software platform. The KMS proxy service can connect directly to the KMS or cascade with a higher-level KMS proxy. When each subsystem needs to obtain a VKEK, it connects to a KMS proxy service that is directly reachable over the network.

[0076] like Figure 1 As shown, the specific steps are as follows:

[0077] Step S11: Acquire a first encrypted code stream from a video capture device, wherein the identification number of the video encryption key is stored in a transmission auxiliary frame in the first encrypted code stream.

[0078] In the embodiments of this application, Figure 2 As shown, the video capture device generates a device signature certificate, a device signature private key, a device encryption certificate, a device encryption private key, a CA (Certificate Authority) certificate, etc.

[0079] The video encryption platform generates a platform signature certificate, a platform signature private key ID (Identity document, identification number), a platform encryption certificate, a platform encryption private key, a CA certificate; a platform certificate, a platform private key ID, a user certificate, etc.

[0080] Before video data is transmitted and encrypted, the video capture device and the video encryption platform need to complete two-way authentication based on digital certificates and exchange certificates through the TLCP (Information security technology—Transport layer cryptography protocol).

[0081] During the digital envelope negotiation process, the video encryption platform generates a random symmetric key for subsequent video stream encryption. The video capture device then obtains the encrypted symmetric key through digital envelope technology and the RTSP (Real Time Streaming Protocol). The video capture device then uses the encrypted random symmetric key to generate the video encryption key VK.

[0082] In an embodiment of the present application, the video capture device, on the one hand, transmits the video encryption key VK encrypted with a symmetric key to the video encryption platform, and on the other hand, uses the video encryption key VK encrypted with a symmetric key to encrypt 2KB data of the key frame header of the video stream to obtain an encrypted code stream, and at the same time encapsulates the VKID (identification number of the video encryption key) into the extended frame header of the key frame for transmission to the video encryption platform.

[0083] Specifically, in order to achieve transmission encryption between the video capture device and the video encryption platform, the present application provides a transmission encryption frame structure design.

[0084] Among them, this application designs a frame structure for transmission encryption, which is used to encrypt the audio and video transmission process. Audio and video encrypted transmission adopts key frame encryption. By default, only the 2KB header of the key frame data is encrypted. Compared with encrypting the entire complete frame or encrypting massive video streams, key frame encryption can significantly reduce the computing resources required for encryption and decryption. Because the number of key frames is far less than P frames and B frames, and the small amount of 2KB data is also far less than the size of a general key frame, it is more suitable for scenarios where security and performance are balanced, and the transmission and playback efficiency of video streams is improved, which is especially important for real-time video streaming and large-scale video distribution scenarios.

[0085] The specific process of transmission encryption is as follows:

[0086] The user (the video capture device in this application) transmits the encrypted key (SM4) based on the RTSP protocol, which is used for subsequent code stream encryption.

[0087] The video capture device and the video encryption platform negotiate a symmetric key (SM4) based on a simplified digital envelope (SM2) interaction process. This allows both parties to securely exchange encryption keys, laying the foundation for subsequent encryption operations.

[0088] The default mode for stream encryption is OFB (Output Feedback Mode), which is suitable for encrypting streaming media data and can provide higher encryption speed and lower latency.

[0089] Defines the encryption offset and encryption length (default keyframe header is 2KB). The encryption offset is the number of bytes from the start of the raw stream data at which encryption begins; the encryption length is the length of the encrypted data after the offset, in bytes. These two parameters provide flexible control over the encryption granularity and scope to meet different security requirements.

[0090] Further, please refer to the transmission encryption extension frame structure design of this application Figures 3 to 5 , Figure 3 This is a schematic diagram of the structure of the key frame hierarchy description provided by this application. Figure 4 This is a schematic diagram of the detailed definition of the key frame header provided by this application. Figure 5 This is a structural diagram of the detailed definition of the extended frame header provided by this application.

[0091] like Figure 3 As shown in the figure, the key frame consists of a 24-byte frame header, variable-length frame data, and an 8-byte frame trailer. Figure 5 For example, the transmission encryption extension frame is an extension of the standard frame header. Its length is not fixed and it is used to store key information such as VKID. Figure 4The detailed definition of the key frame header is expressed as the 24-byte content of the frame header and the position of the extension field. The extension field starts from 24 bytes and has an indefinite length.

[0092] Please continue to read for details Figure 5 , the extended frame is defined as follows:

[0093] (1) Extended frame header type: 0xB5, used to mark and distinguish extended frames.

[0094] (2) Extended frame length: variable length, extended frame length of time.

[0095] (3) Code stream encryption type: Code stream encryption uses the OFB mode encryption type. The following configurations are supported:

[0096] 0: Reserved, no type.

[0097] 1: AES256-OFB-NOPADDING: This uses the AES encryption algorithm with a 256-bit key, output feedback mode, and no padding. This type of encryption is typically used in scenarios that require high security and continuous encryption capabilities.

[0098] 2: SM4-OFB-NOPADDING: This encryption method uses the SM4 algorithm, employs output feedback mode, and does not perform data padding. It is suitable for scenarios that require continuous encryption of large amounts of data or real-time data streams.

[0099] 3: SM4-ECB-NOPADDING: Uses the SM4 algorithm in electronic codebook mode without padding. Suitable for encrypting fixed-length data blocks.

[0100] 4: SM1-OFB-NOPADDING: This encryption method uses the SM1 algorithm, employs output feedback mode, and does not perform data padding. It is suitable for scenarios that require continuous encryption of large amounts of data or real-time data streams.

[0101] 5: SM1-ECB-NOPADDING: Uses the SM1 algorithm in electronic codebook mode without padding. Suitable for encrypting fixed-length data blocks.

[0102] (4) Code stream encryption offset: The offset of bytes from the starting position of the original raw code stream data to be encrypted.

[0103] (5) Code stream encryption length: The length of the encrypted data starting from the offset position, in bytes, that is, how much data needs to be decrypted before it can be played normally.

[0104] (6) VKID: The ID of the video encryption key VK (VEK). The client can obtain the VK in the local cache through this ID number. The VK is provided by the device and the first negotiation and transmission is completed by the RTSP protocol and digital envelope technology.

[0105] (7) CRC16: Perform CRC16 checksum on the data before encryption, which is used for verification during decoding.

[0106] (8) Code stream encryption IV: The initial vector of symmetric encryption when encrypting the code stream.

[0107] Step S12: Obtain the storage key, and use the video key encryption key in the storage key to encrypt the video encryption key of the transmission auxiliary frame.

[0108] In an embodiment of the present application, the video encryption platform obtains the storage keys: VKEK and VKEKID through the KMS agent, and uses VKEK to encrypt VK to obtain eVK.

[0109] Step S13: Generate a storage auxiliary frame according to the video key encryption key identification number of the storage key and the encrypted video encryption key.

[0110] In an embodiment of the present application, the video encryption platform uses the VKEKID, VKID, and eVK generated in step S14 to generate a storage auxiliary frame.

[0111] Specifically, in order to implement storage encryption between a storage medium and a video encryption platform, the present application provides a storage encryption auxiliary frame structure design.

[0112] Among them, audio and video encrypted storage uses encrypted storage encryption keys to add storage encryption auxiliary frames, and the encryption keys are managed by KMS.

[0113] This application supports the storage of encrypted bitstreams through a storage encryption auxiliary frame structure design. Two storage encryption auxiliary frames are inserted at the beginning and end of a video file. These two auxiliary frames store the video encryption key (VK) (VEK) encrypted by VKEK, as well as the VKEKID. This ensures that the same VKEK is used in the beginning and end of each video file, and that only the same VK and VKEK are used in each video file. This design simplifies key management, improves encryption efficiency, and ensures data consistency and security.

[0114] Specifically, the storage encryption auxiliary frame design of this application can be found in Figures 6 to 8 , Figure 6 This is a schematic diagram of the overall frame format definition provided by this application. Figure 7 This is a schematic diagram of the structure of a single additional data format definition provided by this application. Figure 8This is a structural diagram of the data content definition of the VK information provided by this application.

[0115] like Figure 6 As shown, the overall frame format is defined as follows:

[0116] VKEK type: 0x00 – KMS allocated; 0x01 – User allocated; 0x02 – USBKey allocated.

[0117] VKEKID: VKEK ID assigned by KMS or key ID in USBKey.

[0118] like Figure 7 As shown, the single additional data format is defined as follows:

[0119] Data Type: 0x01 – VK Information.

[0120] like Figure 8 As shown, the data content of VK information is defined as follows:

[0121] VKID: VK (VEK) identification.

[0122] IV: Initial vector for symmetric encryption. Not required in ECB (Electronic Codebook Mode).

[0123] VK encrypted value: VK encrypted by VKEK (i.e. eVK).

[0124] Encryption type: VKEK encryption algorithm, synchronous code stream encryption algorithm.

[0125] Step S14: inserting the storage auxiliary frame into the first encrypted code stream to generate a second encrypted code stream and storing it in a storage medium.

[0126] In an embodiment of the present application, the video encryption platform stores the encrypted auxiliary frames and the encrypted code stream together on a cloud storage disk.

[0127] Specifically, the video encryption platform inserts a storage encryption auxiliary frame at the head and the tail of the video file of the encrypted code stream to generate a new encrypted code stream.

[0128] In this application, the video encryption platform obtains a first encrypted code stream from a video capture device, wherein the transmission auxiliary frame in the first encrypted code stream stores the identification number of the video encryption key; obtains the storage key, and uses the video key encryption key in the storage key to encrypt the video encryption key of the transmission auxiliary frame; generates a storage auxiliary frame based on the video key encryption key identification number of the storage key and the encrypted video encryption key; inserts the storage auxiliary frame into the first encrypted code stream, generates a second encrypted code stream, and stores it in a storage medium. Through the above-mentioned video encryption method, the transmission encrypted frame and the storage encrypted auxiliary frame are designed to achieve efficient encrypted transmission and storage of video cloud storage data streams.

[0129] Please combine Figure 2 Continue reading Figure 9 , Figure 9 This is a flow chart of the second embodiment of the video encryption method provided by this application.

[0130] like Figure 9 As shown, the specific steps are as follows:

[0131] Step S21: The video capture device encrypts the video code stream using the video encryption key to obtain an encrypted code stream.

[0132] Step S22: The video capture device generates a transmission auxiliary frame according to the identification number of the video encryption key.

[0133] Step S23: The video encryption platform obtains the transmission auxiliary frame and the encryption code stream from the video acquisition device.

[0134] Step S24: the video encryption platform obtains the storage key, and uses the video key encryption key in the storage key to encrypt the video encryption key of the transmission auxiliary frame.

[0135] Step S25: The video encryption platform generates a storage auxiliary frame according to the video key encryption key identification number of the storage key and the encrypted video encryption key.

[0136] Step S26: The video encryption platform stores the auxiliary frame and the encrypted code stream in a storage medium.

[0137] In the embodiment of the present application, the contents of steps S21 to S26 are as follows: Figure 1 Steps S11 to S14 of the video encryption method have been described in detail and will not be repeated here.

[0138] Furthermore, if Figure 2 As shown, the video encryption system of the present application also includes a client to provide users with a video data call and review function.

[0139] Please refer to the following for details: Figure 10 , Figure 10 This is a flowchart of the third embodiment of the video encryption method provided by this application.

[0140] like Figure 10 As shown, the specific steps are as follows:

[0141] Step S31: In response to the real-time video query instruction from the client, the video encryption platform sends the stored auxiliary frames and the encrypted code stream to the client.

[0142] Step S32: The client obtains the storage key and the encrypted video encryption key based on the storage auxiliary frame.

[0143] Step S33: The client uses the video key encryption key in the storage key to decrypt the encrypted video encryption key to obtain the video encryption key.

[0144] Step S34: The client decodes the encrypted code stream using the video encryption key, obtains and plays the decoded code stream.

[0145] In this embodiment of the present application, when a user enters a real-time video query command through the client, the client can directly obtain the VKID and encryption code stream in the transmitted encrypted frame from the video encryption platform. Therefore, the client can directly decrypt the VK and use the VK to decrypt the 2KB key frame header data for playback.

[0146] Specifically, during real-time preview on the client side, the video stream data obtained from the streaming service requires decryption of the encrypted frames in the video stream for proper playback. This requires only obtaining the VKID based on the extended frame data in the keyframe. Using the VKID, the client obtains the video encryption key (VK) (VEK) from the frontend, and then uses the VK to decrypt the cipher stream. This reduces the complexity of key synchronization. The client then quickly completes decryption based on the stream data itself and the client's cached data.

[0147] Please refer to the following for details: Figure 11 , Figure 11 This is a flowchart of the fourth embodiment of the video encryption method provided by this application.

[0148] Step S41: In response to the historical video playback instruction from the client, the video encryption platform reads the stored auxiliary frames and the encrypted code stream from the storage medium.

[0149] Step S42: The video encryption platform parses the video key encryption key identification number stored in the auxiliary frame, and uses the video key encryption key identification number to query the corresponding video key encryption key.

[0150] Step S43: The video encryption platform uses the video key encryption key to decrypt the encrypted video encryption key to obtain the video encryption key.

[0151] Step S44: The video encryption platform sends the video encryption key and the encrypted code stream to the client.

[0152] Step S45: The client decodes the encrypted code stream using the video encryption key, obtains and plays the decoded code stream.

[0153] In this embodiment of the present application, when a user enters a historical video playback command through the client, the client must first exchange certificates with the video encryption platform to complete two-way authentication, and then initiate an RTSP request. The video encryption platform generates a random symmetric key for this interaction, encrypts the SM4 symmetric key with the SM2 private key, and transmits it to the client to establish a secure connection.

[0154] The video encryption platform reads the video file from the cloud storage, obtains the encrypted auxiliary frame and the encrypted code stream. The video encryption platform parses the VKEKID in the encrypted auxiliary frame, queries the VKEK through the KMS agent, and decrypts eVk using the VKEK to obtain the video encryption key VK.

[0155] The video encryption platform securely transmits VK to the client via RTSP and symmetric key encryption, which can then be queried and obtained by the client.

[0156] Specifically, when a client plays back a video, the video encryption platform reads the encrypted video file data from cloud storage, obtains the VKEKID by reading the encrypted auxiliary frame in the header, and then queries the KMS for the VKEK using the VKEKID. The video encryption platform uses the VKEK to decrypt the eVK, obtains the VK, and then decrypts the video file data using the VK to obtain the original video data, allowing the client to complete playback.

[0157] This application stores VK encryption directly in the video file, reducing the conventional and complex key synchronization process, ensuring security while facilitating quick decryption for video playback.

[0158] The video encryption method of the present application realizes end-to-end transmission encryption and storage encryption functions of data streams by designing transmission encryption extension frames and storage encryption auxiliary frames.

[0159] The video encryption method of this application designs a transmission encryption extension frame, which improves the encryption transmission efficiency and security by defining the code stream encryption offset and code stream encryption length. At the same time, the video encryption key ID (VKID) is recorded in the key frame header. When the client previews, the encryption key can be queried through the VKID in the real-time code stream, realizing fast decryption preview of the real-time code stream, thereby improving the efficiency of encryption and decryption on the basis of secure transmission.

[0160] The video encryption method of the present application designs a storage encryption auxiliary frame to store the video encryption key VEK encrypted by VKEK and the VKEKID. The VKEKID is recorded in the auxiliary frame. By inserting a storage encryption auxiliary frame at the head and end of the video file, the effect of fast decryption during the playback process is achieved.

[0161] The video encryption method of the present application needs to ensure that the VKEK used in the first and last storage encryption auxiliary frames in each video file is the same in the storage encryption auxiliary frames, and only the same VK and VKEK are used in each video file.

[0162] Those skilled in the art will understand that in the above-mentioned method of the specific implementation method, the writing order of each step does not mean a strict execution order and does not constitute any limitation on the implementation process. The specific execution order of each step should be determined by its function and possible internal logic.

[0163] To implement the above video encryption method, this application also proposes a video encryption system, please refer to Figure 12 , Figure 12 This is a schematic diagram of the framework of an embodiment of the video encryption system provided by this application.

[0164] The video encryption system 500 of this embodiment includes: a video acquisition device 51 , a video encryption platform 52 and a storage medium 53 .

[0165] The video capture device 51 is used to encrypt the video code stream using the video encryption key to obtain the encrypted code stream.

[0166] The video capture device 51 is configured to generate a transmission auxiliary frame according to the identification number of the video encryption key.

[0167] The video encryption platform 52 is used to obtain the transmission auxiliary frame and the encryption code stream from the video acquisition device.

[0168] The video encryption platform 52 is used to obtain a storage key and encrypt the video encryption key of the transmission auxiliary frame using a video key encryption key in the storage key.

[0169] The video encryption platform 52 is configured to generate a storage auxiliary frame according to the video key encryption key identification number of the storage key and the encrypted video encryption key.

[0170] The video encryption platform 52 is used to store the storage auxiliary frame and the encrypted code stream in the storage medium 53.

[0171] In order to implement the above video encryption method, this application also proposes a video encryption device, please refer to Figure 13 , Figure 13It is a structural diagram of an embodiment of a video encryption device provided by this application.

[0172] The video encryption device 700 of this embodiment includes a processor 71 , a memory 72 , an input / output device 73 , and a bus 74 .

[0173] The processor 71 , the memory 72 , and the input / output device 73 are respectively connected to a bus 74 . The memory 72 stores program data, and the processor 71 is used to execute the program data to implement the video encryption method described in the above embodiment.

[0174] In the embodiments of the present application, the processor 71 may also be referred to as a CPU (Central Processing Unit). The processor 71 may be an integrated circuit chip with signal processing capabilities. The processor 71 may also be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component. A general-purpose processor may be a microprocessor, or the processor 71 may be any conventional processor.

[0175] This application also provides a computer storage medium, please continue to refer to Figure 14 , Figure 14 1 is a schematic structural diagram of an embodiment of a computer storage medium provided in the present application. The computer storage medium 600 stores a computer program 61. When the computer program 61 is executed by a processor, it is used to implement the video encryption method of the above embodiment.

[0176] When the embodiments of the present application are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) or a processor to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program code, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0177] The above description is only an implementation method of the present application and does not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made using the contents of the description and drawings of this application, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present application.

Claims

1. A video encryption method, characterized in that: The video encryption method is applied to a video encryption platform in a video encryption system; The video encryption method comprises: Acquire a first encrypted code stream from a video capture device, wherein a transmission auxiliary frame in the first encrypted code stream stores an identification number of a video encryption key; Obtaining a storage key, and encrypting the video encryption key of the transmission auxiliary frame using a video key encryption key in the storage key; Generate a storage auxiliary frame according to the video key encryption key identification number of the storage key and the encrypted video encryption key; Inserting the storage auxiliary frame into the first encrypted code stream to generate a second encrypted code stream and storing the second encrypted code stream in a storage medium; The transmission auxiliary frame is generated by the video acquisition device writing the identification number of the video encryption key into the key frame extended frame header of the video code stream; The storage auxiliary frame includes an additional data field and an overall data field; The step of generating a storage auxiliary frame according to the video key encryption key identification number of the storage key and the encrypted video encryption key includes: Writing the video key encryption key identification number of the storage key into the overall data field of the storage auxiliary frame; Writing the encrypted video encryption key into the additional data field of the storage auxiliary frame; The video capture device encrypts the key frame header data of the video stream using the video encryption key to obtain the first encrypted code stream; the identification number of the video encryption key is encapsulated into the extended frame header of the key frame; The step of generating a storage auxiliary frame according to the video key encryption key identification number of the storage key and the encrypted video encryption key includes: The storage auxiliary frame is generated according to the video key encryption key identification number of the storage key, the encrypted video encryption key and the identification number of the video encryption key.

2. The video encryption method according to claim 1, wherein: The inserting the storage auxiliary frame into the first encrypted code stream comprises: The storage auxiliary frame is inserted into the head position and / or the tail position of the first encrypted code stream.

3. The video encryption method according to claim 1, wherein: The video encryption method further includes: A random symmetric key is generated, and the encrypted random symmetric key is sent to the video acquisition device, so that the video acquisition device generates a video encryption key using the encrypted random symmetric key.

4. A video encryption method, characterized in that: The video encryption method is applied to a video encryption system, wherein the video encryption system includes a video acquisition device, a video encryption platform and a storage medium; the video encryption method includes: The video capture device encrypts the video code stream using the video encryption key to obtain an encrypted code stream; The video capture device generates a transmission auxiliary frame according to the identification number of the video encryption key; the transmission auxiliary frame is generated by the video capture device writing the identification number of the video encryption key into the key frame extended frame header of the video code stream; The video encryption platform obtains the transmission auxiliary frame and the encryption code stream from the video acquisition device; The video encryption platform obtains a storage key and encrypts the video encryption key of the transmission auxiliary frame using a video key encryption key in the storage key; The video encryption platform generates a storage auxiliary frame according to the video key encryption key identification number of the storage key and the encrypted video encryption key; The video encryption platform stores the storage auxiliary frame and the encrypted code stream in the storage medium; The video encryption platform generates a storage auxiliary frame according to the video key encryption key identification number of the storage key and the encrypted video encryption key, including: The video encryption platform writes the video key encryption key identification number of the storage key into the overall data field of the storage auxiliary frame; The video encryption platform writes the encrypted video encryption key into the additional data field of the storage auxiliary frame; The video capture device encrypts the key frame header data of the video stream using a video encryption key to obtain the encrypted code stream; the identification number of the video encryption key is encapsulated into the extended frame header of the key frame; The video encryption platform generates a storage auxiliary frame according to the video key encryption key identification number of the storage key and the encrypted video encryption key, including: The video encryption platform generates the storage auxiliary frame according to the video key encryption key identification number of the storage key, the encrypted video encryption key and the identification number of the video encryption key.

5. The video encryption method according to claim 4, wherein: The video encryption system also includes a client; The video encryption method further includes: In response to a real-time video query instruction from the client, the video encryption platform sends the stored auxiliary frame and the encrypted code stream to the client; The client obtains the storage key and the encrypted video encryption key based on the storage auxiliary frame; The client uses the video key encryption key in the storage key to decrypt the encrypted video encryption key to obtain the video encryption key; The client decodes the encrypted code stream using the video encryption key, and obtains and plays the decoded code stream.

6. The video encryption method according to claim 4, wherein: The video encryption system also includes a client; The video encryption method further includes: In response to a historical video playback instruction from the client, the video encryption platform reads the stored auxiliary frame and the encrypted code stream from the storage medium; The video encryption platform parses the video key encryption key identification number in the storage auxiliary frame, and uses the video key encryption key identification number to query the corresponding video key encryption key; The video encryption platform decrypts the encrypted video encryption key using the video key encryption key to obtain the video encryption key; The video encryption platform sends the video encryption key and the encrypted code stream to the client; The client decodes the encrypted code stream using the video encryption key, and obtains and plays the decoded code stream.

7. A video encryption device, characterized in that: The video encryption device includes a memory and a processor coupled to the memory; The memory is used to store program data, and the processor is used to execute the program data to implement the video encryption method according to any one of claims 1 to 6.

8. A computer storage medium, characterized in that The computer storage medium is used to store program data, and when the program data is executed by a computer, it is used to implement the video encryption method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Data protection method and device and storage medium

    CN119788436A