Encryption method and device, decryption method and device, electronic equipment and storage medium

By decoding the video stream and chaotic encryption of the matrix, a two-dimensional secret text matrix is generated to cover the YUV image matrix, which solves the problems of video stream expansion and resource consumption, and achieves efficient and secure video stream encryption.

CN120281855AActive Publication Date: 2025-07-08BEIJING ZHONGYU WANTONG TECH CO LTD
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202510780772.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-12
Publication Date
2025-07-08
Estimated Expiration
2045-06-12

AI Technical Summary

Technical Problem

The existing video stream encryption method causes the video stream size to expand, increase bandwidth consumption and require multiple encoding and decoding, which consumes a lot of resources.

Method used

The video stream is decoded and generated a YUV image matrix, the features to be encrypted are identified and the rectangular encryption area is generated, and the matrix is scrambled and SM4 encryption is performed through random numbers and video encryption keys, a two-dimensional secret text matrix is generated to cover the original image matrix, and the occluded video stream is encoded and the encryption key information is attached.

Benefits of technology

Provides high randomness and security encryption methods, reduces data redundancy, improves privacy data security, enhances encryption effect, and adapts to the privacy data encryption needs of different scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281855A_ABST
    Figure CN120281855A_ABST
Patent Text Reader

Abstract

The invention provides an encryption method and device, a decryption method and device, electronic equipment and a storage medium. Comprising the following steps: decoding a video stream to obtain a YUV image, and generating an original image matrix; obtaining a rectangular encryption area according to the to-be-encrypted features in the YUV image; scrambling a matrix corresponding to the rectangular encryption area to obtain a scrambled matrix; processing the scrambling matrix by using a random number and a video encryption key to generate a two-dimensional ciphertext matrix, and encrypting the random number to obtain an encrypted random number; covering the rectangular encryption area with the two-dimensional ciphertext matrix to obtain an occluded image matrix, and encoding the occluded video stream to obtain an encoded video stream; encrypting the video encryption key based on the video key encryption key to obtain an encrypted video encryption key; and writing the version number of the video key encryption key, the encrypted video encryption key, the encrypted random number and the rectangular encryption area into the additional attribute of the coded video stream to obtain an encrypted video stream.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of image encryption technology, and in particular to an encryption method, a decryption method, a device, an electronic device and a storage medium. Background Art

[0002] With the rapid development of video surveillance technology, the need to protect privacy information (such as faces, license plates, sensitive data, etc.) in video data has become increasingly urgent. Currently, the methods for protecting privacy vision in video streams lack practical applications. The protection of privacy data mainly relies on encryption methods such as mosaics and frame insertion for privacy data, which has the following risks: 1. Data resource inflation: When performing privacy vision protection through methods such as mosaics and frame insertion, it will cause the video stream size to expand, resulting in data redundancy and increasing bandwidth consumption.

[0003] 2. Low processing efficiency: When using traditional mosaics and other methods for privacy vision protection, multiple encoding and decoding operations are required, consuming a large amount of resources. Summary of the Invention

[0004] The technical problem to be solved by the embodiments of this application is to provide an encryption method, a decryption method, a device, an electronic device and a storage medium to solve the problems that the existing encryption methods will cause the video stream size to expand, resulting in data redundancy, increasing bandwidth consumption, and requiring multiple encoding and decoding operations, consuming a large amount of resources.

[0005] In a first aspect, the embodiments of this application provide an encryption method, and the method includes: Perform decoding processing on the video stream to obtain a YUV image, and generate an original image matrix associated with the YUV image; According to the to-be-encrypted features identified in the YUV image, obtain a rectangular encryption area corresponding to the YUV image; Perform position scrambling processing on the matrix corresponding to the rectangular encryption area to obtain a scrambled matrix; Use a random number and a video encryption key to process the scrambled matrix to generate a two-dimensional ciphertext matrix, and perform SM4 encryption on the random number based on the video encryption key to obtain an encrypted random number; Cover the two-dimensional ciphertext matrix to the rectangular encryption area of the original image matrix to obtain an occluded image matrix, and encode the occluded video stream obtained by splicing the occluded YUV images in chronological order to obtain an encoded video stream; Perform symmetric encryption processing on the video encryption key based on the video key encryption key obtained by decryption to obtain an encrypted video encryption key; Write the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number, and the rectangular encrypted area into the additional attributes of the encoded video stream to obtain an encrypted video stream.

[0006] In a second aspect, an embodiment of the present application provides a decryption method, and the method includes: Obtain an encrypted video stream and additional attributes, and perform decoding processing on the encrypted video stream to obtain a YUV image; Extract the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number, and the rectangular encrypted area from the additional attributes; Determine a video encryption key according to the version number and the encrypted video encryption key; Decrypt the encrypted random number based on the video encryption key to obtain a decrypted random number; Generate a two-dimensional random matrix according to the size of the rectangular encrypted area, and convert the two-dimensional random matrix into a one-dimensional random matrix; Determine a two-dimensional reduction matrix based on the random number, the video encryption key, and the one-dimensional random matrix; Cover the two-dimensional reduction matrix to the position corresponding to the rectangular encrypted area of the YUV image to obtain a decrypted YUV image; Perform encoding processing on the decrypted YUV image to obtain a restored video stream.

[0007] In a third aspect, an embodiment of the present application provides an encryption device, and the device includes: An original matrix generation module, configured to perform decoding processing on a video stream to obtain a YUV image, and generate an original image matrix associated with the YUV image; An encrypted area acquisition module, configured to obtain a rectangular encrypted area corresponding to the YUV image according to the to-be-encrypted feature identified in the YUV image; A scrambling matrix acquisition module, configured to perform position scrambling processing on the matrix corresponding to the rectangular encrypted area to obtain a scrambled matrix; A random number encryption module, configured to process the scrambled matrix with a random number and a video encryption key to generate a two-dimensional ciphertext matrix, and perform SM4 encryption on the random number based on the video encryption key to obtain an encrypted random number; A video stream encoding module, configured to cover the two-dimensional ciphertext matrix to the rectangular encrypted area of the original image matrix to obtain an occluded image matrix, and encode the occluded video stream obtained by splicing the occluded YUV images in time sequence to obtain an encoded video stream; An encryption key acquisition module, configured to perform symmetric encryption processing on the video encryption key based on the video key encryption key obtained by decryption, so as to obtain an encrypted video encryption key; An encrypted video stream acquisition module, configured to write the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number, and the rectangular encrypted area into the additional attributes of the encoded video stream, so as to obtain an encrypted video stream.

[0008] In a fourth aspect, an embodiment of the present application provides a decryption device, where the device includes: A video stream decoding module, configured to obtain an encrypted video stream and additional attributes, and perform decoding processing on the encrypted video stream to obtain a YUV image; An additional information extraction module, configured to extract the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number, and the rectangular encrypted area from the additional attributes; An encryption key determination module, configured to determine a video encryption key according to the version number and the encrypted video encryption key; A random number decryption module, configured to decrypt the encrypted random number based on the video encryption key to obtain a decrypted random number; A random matrix generation module, configured to generate a two-dimensional random matrix according to the size of the rectangular encrypted area, and convert the two-dimensional random matrix into a one-dimensional random matrix; A reduction matrix determination module, configured to determine a two-dimensional reduction matrix based on the random number, the video encryption key, and the one-dimensional random matrix; A YUV image acquisition module, configured to cover the two-dimensional reduction matrix to a position corresponding to the rectangular encrypted area of the YUV image to obtain a decrypted YUV image; A video stream acquisition module, configured to perform encoding processing on the decrypted YUV image to obtain a restored video stream.

[0009] In a fifth aspect, an embodiment of the present application provides an electronic device, including: A processor, a memory, and a computer program stored on the memory and executable on the processor, where when the processor executes the program, it implements the encryption method described in any one of the above, or the decryption method described in any one of the above.

[0010] In a sixth aspect, an embodiment of the present application provides a computer-readable storage medium, where when the instructions in the storage medium are executed by a processor of an electronic device, the electronic device can execute the encryption method described in any one of the above, or the decryption method described in any one of the above.

[0011] Compared with the prior art, the embodiments of the present application include the following advantages: In the embodiments of the present application, by decoding a video stream, a YUV image is obtained, and an original image matrix associated with the YUV image is generated. According to the features to be encrypted in the identified YUV image, a rectangular encryption area corresponding to the YUV image is obtained. The matrix corresponding to the rectangular encryption area is subjected to position scrambling processing to obtain a scrambled matrix. The scrambled matrix is processed using a random number and a video encryption key to generate a two-dimensional ciphertext matrix, and the random number is encrypted using SM4 based on the video encryption key to obtain an encrypted random number. The two-dimensional ciphertext matrix is overlaid on the rectangular encryption area of the original image matrix to obtain an occluded image matrix, and the occluded video stream obtained by splicing the occluded image matrix in chronological order is encoded to obtain an encoded video stream. The video encryption key is symmetrically encrypted based on the decrypted video key encryption key to obtain an encrypted video encryption key. The version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number, and the rectangular encryption area are written into the additional attributes of the encoded video stream to obtain an encrypted video stream. In the embodiments of the present application, the scrambled matrix is processed using the video encryption key and the random number, which can provide a key with high randomness and high security for the encryption operation, enhance the expandability of the key, and improve the security of privacy data. At the same time, the random matrix generation and confusion technology is introduced to generate a random matrix matching the size of the privacy image block, and the relevant matrix is scrambled in position, which has high randomness and irregularity, making the encrypted image difficult to be cracked and enhancing the encryption effect. And the corresponding size of the random matrix can be flexibly generated according to the size of the privacy image block to meet the requirements of privacy data encryption in different scenarios.

[0012] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. Description of the Drawings

[0013] Figure 1 It is a flowchart of the steps of an encryption method provided by an embodiment of the present application; Figure 2 It is a flowchart of the steps of a decryption method provided by an embodiment of the present application; Figure 3 It is a schematic structural diagram of an encryption device provided by an embodiment of the present application; Figure 4 It is a schematic structural diagram of a decryption device provided by an embodiment of the present application; Figure 5 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed Embodiments

[0014] To make the above objects, features, and advantages of the present application more obvious and understandable, the present application will be further described in detail below with reference to the drawings and specific embodiments.

[0015] The terms used in the embodiments of the present application are for the purpose of describing specific embodiments only and are not intended to limit the present application. The singular forms "a", "the", and "said" used in the embodiments of the present application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise.

[0016] Referring to Figure 1 , a flowchart showing the steps of an encryption method provided by an embodiment of the present application is shown. As Figure 1 shown, the encryption method may include: Step 101 to Step 107.

[0017] Step 101: Decode the video stream to obtain a YUV image and generate an original image matrix associated with the YUV image.

[0018] In this embodiment, the YUV image is an image form represented in the YUV color space. Its essence is to store the luminance information (Y) and chrominance information (U, V) of the image separately. This unique structure gives it significant advantages in video processing and image transmission. In the YUV image, "Y" represents luminance, corresponding to the grayscale information of the image, which determines the brightness of the image. "U" and "V" represent chrominance, respectively representing the difference between the blue component and luminance and the difference between the red component and luminance, and are used to describe the color and saturation of the image.

[0019] When encrypting the video stream, the video stream to be encrypted can be decoded to obtain a YUV image. In a specific implementation, a hardware decoder can be used to decode the video stream to obtain a YUV image. Of course, other decoding methods (such as pure software decoding methods (such as FFmpeg software decoding, etc.)) can also be used to decode the video stream to obtain a YUV image.

[0020] When decoding the video stream, if the original video frames of the video stream are all in the YUV format, a YUV image can be directly obtained through decoding. If the original video frames of the video stream are not in the YUV format and the decoded video frame format is not in the YUV format, format conversion is required, such as converting the decoded RGB format or other format frames to the YUV format to obtain a YUV image.

[0021] After obtaining the YUV image, an original image matrix associated with the YUV image can be generated.

[0022] In a specific implementation of the present application, the chaos coefficient method can be used to process the YUV image to obtain the original image matrix.

[0023] The chaos coefficient method is an image processing technology based on chaos theory, and the generation process can be as follows: 1. Selection of chaotic system and parameter setting.

[0024] First, a suitable chaotic system needs to be selected, such as the Logistic map, etc. Then, parameter setting is carried out. Taking the Logistic map as an example, two key parameters need to be set, the initial value (which can be a decimal number in the interval (0, 1)) and the control parameter (set between 3.57 and 4 to ensure that the system is in a chaotic state).

[0025] 2. Random matrix generation process.

[0026] (1) Determine the matrix size: According to the width and height of the YUV image (i.e., the size of the YUV image), determine that the size of the random matrix needs to match the image pixel matrix.

[0027] (2) Generate a chaotic sequence: Use the selected chaotic system to perform iterative calculations starting from the initial value to generate a new value in each iteration, forming a chaotic sequence.

[0028] (3) Sequence conversion: Map the values in the chaotic sequence (usually between 0 and 1) to the required range (for image encryption, it needs to be mapped to the integer range of 0 - 255, corresponding to the image pixel values).

[0029] (4) Matrix reshaping: Rearrange the one-dimensional chaotic sequence into a two-dimensional matrix to ensure that the number of rows and columns of the matrix is consistent with the height and width of the YUV image, and thus obtain the original image matrix.

[0030] In another specific implementation of this application, the YUV image can be processed using the random number method to obtain the original image matrix, and the generation process can be as follows: 1. Select a random number generator: a. Use the SM3 algorithm to construct a pseudo-random number generator (PRNG). b. Generate a seed: a) Seed source: The original YUV image can be regarded as a specific data set in the digital domain. Calculate the hash value of the original YUV image through the SM3 algorithm. This hash value represents the unique digital fingerprint of the image. Then, combined with the timestamp (reflecting the time information when generating random numbers, with dynamic variability), the two are combined to obtain the seed. The advantage of doing this is that different YUV images will have different hash values, plus the constantly changing timestamp, which can ensure the uniqueness of the seed generated each time. b) Seed length: Since the output of the SM3 algorithm is fixed at 256 bits, the seed length is 256 bits. These 256 bits of the seed contain enough information to lay a foundation for generating high-quality random numbers in the future.

[0031] 2. Generate a random number sequence: a) Initialize the PRNG: Use the SM3-CTR (Counter Mode) mode generator. The CTR mode is a working mode that converts a block cipher into a stream cipher. Here, the previously generated 256-bit seed is used as the input to initialize the generator. In this way, the internal state of the generator is determined, and based on the image and time-related information contained in the seed, it is prepared for generating the subsequent random number sequence. b) Output random bytes: For a YUV image, assume that the luminance component Y (assuming the size is n×n, where n is the number of pixels in the width or height of the image) is to be processed. At this time, n×n bytes are generated, each byte corresponding to an integer from 0 to 255, forming a random number sequence . These random bytes will be used to construct a random matrix that matches the size of the Y component and will subsequently participate in the processing operations of the YUV image.

[0032] 3. Construct a random matrix (i.e., the original image matrix): Fill it row by row into an n×n matrix: , , and respectively represent the row elements and column elements of matrix A.

[0033] It can be understood that the above scheme is only a matrix generation method listed for better understanding the technical solution of the embodiments of the present application and does not serve as the only limitation of this embodiment.

[0034] Step 102: Obtain the rectangular encryption area corresponding to the YUV image according to the to-be-encrypted feature identified in the YUV image.

[0035] After obtaining the YUV image of the video stream, the to-be-encrypted features in the YUV image can be identified first. The implementation process can be described in detail in combination with the following specific implementation manners.

[0036] In a specific implementation of the present application, the above step 102 may include: Sub-step A1: Detect the to-be-encrypted data in the YUV image.

[0037] In this embodiment, an AI (Artificial Intelligence) model can be used to detect the to-be-encrypted data in the YUV image, such as using an AI model to detect privacy data in the YUV image, such as personal identity information, license plates, etc.

[0038] By using an AI model to detect the to-be-encrypted data in the YUV image in real time in the embodiments of the present application, accurate positioning of privacy data can be achieved, processing of invalid data can be reduced, and the encryption and decryption efficiency can be improved.

[0039] Of course, in specific implementations, other methods can also be used to detect the data to be encrypted in the YUV image, such as detection methods based on rules and template matching (i.e., by presetting the visual feature rules or templates of the privacy data and matching them with the image content), etc. The detection method for the data to be encrypted can be determined according to the service requirements, and this embodiment does not limit this.

[0040] After detecting the data to be encrypted in the YUV image, sub-step A2 is executed.

[0041] Sub-step A2: Extract the encryption features corresponding to the data to be encrypted in the YUV image.

[0042] After detecting the data to be encrypted in the YUV image, the encryption features corresponding to the data to be encrypted in the YUV image can be extracted. In this example, the extracted encryption features are obtained from the privacy data included in the YUV image. For example, if the privacy data is a face in the image, then the extracted features include the color features of the face contour shape in the YUV color space, the facial skin texture features, etc.

[0043] After extracting the encryption features corresponding to the data to be encrypted in the YUV image, sub-step A3 is executed.

[0044] Sub-step A3: Determine the rectangular encryption area corresponding to the YUV image according to the encryption features.

[0045] The rectangular encryption area is the Rectangle rectangular area, which is used to refer to a specific rectangular range in the video frame and is used to locate, crop, encode, or analyze the image content.

[0046] After extracting the encryption features corresponding to the data to be encrypted in the YUV image, the rectangular encryption area corresponding to the YUV image can be determined according to the encryption features. Specifically, the encryption features in the YUV image can be exactly enclosed into a rectangular area to obtain the rectangular encryption area.

[0047] It can be understood that there can be multiple rectangular encryption areas for the same YUV image. For example, if it is necessary to encrypt the face and license plate in a YUV image, and the features corresponding to the face and license plate are in different positions in the image, then the face and license plate can form two rectangular encryption areas, etc. Specifically, the number of rectangular encryption areas for the YUV image can be determined according to the specific situation, and this embodiment does not limit this.

[0048] In the embodiment of the present application, from feature detection to feature extraction and then to area determination, no manual intervention is required, which is suitable for large-scale image privacy protection scenarios.

[0049] After obtaining the rectangular encryption region corresponding to the YUV image based on the features to be encrypted in the recognized YUV image, step 103 is executed.

[0050] Step 103: Perform position scrambling processing on the matrix corresponding to the rectangular encryption region to obtain a scrambled matrix.

[0051] After obtaining the rectangular encryption region, a matrix can be generated according to the rectangular encryption region, and position scrambling processing is performed on this matrix to obtain a scrambled matrix. The implementation process can be described in detail in combination with the following specific implementation manners.

[0052] In a specific implementation of the present application, the above step 103 may include: Sub-step B1: Generate a two-dimensional random matrix associated with the rectangular encryption region according to the size of the rectangular encryption region.

[0053] In this embodiment, after obtaining the rectangular encryption region, a two-dimensional random matrix associated with the rectangular encryption region can be generated according to the size of the rectangular encryption region. Specifically, the width (W) and height (H) of the rectangular encryption region (i.e., the size of the rectangular encryption region) can be obtained, and the dimension of the two-dimensional matrix is determined to be W×H. Then, a cryptographically secure pseudo-random number generator is used, and image metadata (such as the shooting timestamp, YUV component hash value) is used as the seed to ensure randomness and reproducibility. Finally, random integers in the range of 0-255 can be generated and filled into the matrix (i.e., the two-dimensional random matrix) according to the row-major principle, and each element corresponds to an 8-bit binary value (suitable for 8-bit image pixel encryption).

[0054] In the embodiment of the present application, by making the matrix size exactly the same as the encryption region, it can be ensured that subsequent encryption operations correspond pixel by pixel, avoiding data misalignment.

[0055] After generating the two-dimensional random matrix associated with the rectangular encryption region according to the size of the rectangular encryption region, sub-step B2 is executed.

[0056] Sub-step B2: Convert the two-dimensional random matrix into a one-dimensional random matrix.

[0057] After generating the two-dimensional random matrix associated with the rectangular encryption region according to the size of the rectangular encryption region, the two-dimensional random matrix can be converted into a one-dimensional random matrix. Specifically, all elements of the two-dimensional matrix can be expanded into a one-dimensional array in row-major order, that is, a one-dimensional random matrix is obtained.

[0058] Sub-step B3: Generate a one-dimensional matrix of the same length as the one-dimensional random matrix.

[0059] After converting a two-dimensional random matrix into a one-dimensional random matrix, a one-dimensional matrix of the same length as the one-dimensional random matrix can be generated. Specifically, a one-dimensional matrix of the same length as the one-dimensional random matrix can be generated using the chaotic coefficient method or the random number method.

[0060] After generating a one-dimensional matrix of the same length as the one-dimensional random matrix, sub-step B4 is executed.

[0061] Sub-step B4: Perform position scrambling on the matrix elements in the one-dimensional random matrix and the one-dimensional matrix to obtain the scrambled matrix.

[0062] After generating a one-dimensional matrix of the same length as the one-dimensional random matrix, position scrambling can be performed on the matrix elements in the one-dimensional random matrix and the one-dimensional matrix to obtain the scrambled matrix. Specifically, a confusion operation can be performed on the one-dimensional random matrix and the one-dimensional matrix, and the coordinate values in the two matrices can be scrambled to exchange the coordinate positions in the two matrices, thereby obtaining the scrambled matrix.

[0063] In the embodiments of the present application, by introducing a random matrix generation and confusion technology, a random matrix matching the size of the privacy image block is generated using chaotic coefficients and random numbers, and the relevant matrices are position-scrambled, which has high randomness and irregularity, making it difficult to crack the encrypted image and enhancing the encryption effect. And a random matrix of the corresponding size can be flexibly generated according to the size of the privacy image block to meet the requirements of privacy data encryption in different scenarios.

[0064] After obtaining the scrambled matrix, step 104 is executed.

[0065] Step 104: Process the scrambled matrix using a random number and a video encryption key to generate a two-dimensional ciphertext matrix, and perform SM4 encryption on the random number based on the video encryption key to obtain an encrypted random number.

[0066] The video encryption key (VEK) is the key used to directly encrypt and decrypt video data and is the actual key for encrypting video content.

[0067] After obtaining the scrambled matrix, a random number S can be generated first using a random number generator, and the scrambled matrix can be processed using the random number and the video encryption key to generate a two-dimensional ciphertext matrix. The implementation process can be described in detail in combination with the following specific implementation manner.

[0068] In a specific implementation of the present application, the above step 104 may include: Sub-step C1: Generate the random number and the video encryption key.

[0069] In this embodiment, a random number generator can be used to generate a random number S.

[0070] The generation process of the video encryption key can be as follows: Obtain key materials (such as user-initiated input, video content hash, current system timestamp, etc.), and then use a key derivation function to derive the key materials into an encryption key of a fixed length, that is, the video encryption key, to ensure the randomness and unpredictability of the key.

[0071] After generating the random number and the video encryption key, sub-step C2 is executed.

[0072] Sub-step C2: Based on the random number and the video encryption key, generate a one-dimensional target matrix of the same length as the scrambling matrix through a key splitting function.

[0073] A key derivation function (Key Derivation Function, KDF) is a function used to derive one or more keys from initial key materials (such as passwords, keys, or shared keys, etc.). Its purpose is to convert the input key materials into keys suitable for specific encryption applications while providing key expansion and enhanced security.

[0074] After generating the random number and the video encryption key, a one-dimensional target matrix of the same length as the scrambling matrix can be generated based on the random number and the video encryption key through a key splitting function. Specifically, the key derivation process can be as follows: 1. Parameter configuration: salt value (represented by the random number S), key materials (i.e., the video encryption key VEK), output length (set to the number of elements N of the scrambling matrix), information parameter (optional fixed string, used to distinguish different derivation scenarios, such as the image encryption scenario in this embodiment, etc.). 2. Execute the KDF calculation: derived key = KDF (salt value = S, input key materials = VEK, output length = N, information = fixed string). 3. Generate a one-dimensional target matrix E, convert the output byte sequence of length N into a numerical array in sequence, and determine the data type of the array as needed (such as uint8, etc.) to ensure that the array length is exactly the same as the number of elements of the scrambling matrix to generate a one-dimensional target matrix E.

[0075] At the same time, the random number can be encrypted using the video encryption key with SM4 (SM4 is a block cipher algorithm released by the China National Cryptography Administration and belongs to the symmetric encryption algorithm) to obtain an encrypted random number, and this encrypted random number can be attached to the additional attributes of the video stream and transmitted to the receiver for subsequent decryption processes.

[0076] After generating the one-dimensional target matrix, sub-step C3 is executed.

[0077] Sub-step C3: Perform a bitwise AND operation on the scrambling matrix and the one-dimensional target matrix to generate a one-dimensional ciphertext matrix.

[0078] The AND operation, also known as logical multiplication, is a binary logical operation. Its definition is: the result of the AND operation is true if and only if all the logical variables involved in the operation have a true (True) value. As long as one logical variable has a false (False) value, the result is false.

[0079] After generating the one-dimensional target matrix, the scrambling matrix and the one-dimensional target matrix can be subjected to a bitwise AND operation to generate a one-dimensional ciphertext matrix.

[0080] Sub-step C4: Convert the one-dimensional ciphertext matrix into the two-dimensional ciphertext matrix.

[0081] After obtaining the one-dimensional ciphertext matrix, the one-dimensional ciphertext matrix can be converted into a two-dimensional ciphertext matrix. The specific process can be as follows: 1. Determine the shape of the two-dimensional ciphertext matrix: Assume the length of the one-dimensional ciphertext matrix is n. To convert the one-dimensional ciphertext matrix into a two-dimensional ciphertext matrix M with the shape (row, column), it is necessary to satisfy row × column = n. For example, for the one-dimensional ciphertext matrix = [4, 2, 3, 0, 5, 7] (length n = 6), the following can be selected: (1) row = 2, column = 3, and the shape of the two-dimensional matrix is 2 × 3. (2) row = 3, column = 2, and the shape of the two-dimensional matrix is 3 × 2, etc. (which can be selected according to business requirements). 2. Select the element filling order: (1) Row-first, that is, fill the elements row by row, that is, fill the first row first, and then fill the second row, and so on. (2) Column-first, that is, fill the elements column by column, that is, fill the first column first, and then fill the second column, and so on. After filling is completed, the two-dimensional ciphertext matrix can be obtained.

[0082] In the embodiment of the present application, by adopting the key splitting technology KDF, a key matrix of the same length as the scrambling matrix is derived from the VEK and the random number S, which can provide a key with high randomness and high security for the encryption operation, enhance the expandability of the key, and improve the security of privacy data.

[0083] Step 105: Cover the two-dimensional ciphertext matrix to the rectangular encryption area of the original image matrix to obtain an occluded image matrix, and encode the occluded video stream obtained by splicing the occluded YUV images in chronological order to obtain an encoded video stream.

[0084] After obtaining the two-dimensional ciphertext matrix, the two-dimensional ciphertext matrix can be overlaid on the rectangular encryption area of the original image matrix to obtain an occluded image matrix, thus completing the visual occlusion of the privacy data. Then, the occluded YUV images can be stitched together in chronological order to obtain an occluded video stream, and the occluded video stream can be encoded to obtain an encoded video stream. The specific process can be as follows: 1. Ciphertext superposition: Cover the two-dimensional ciphertext matrix F2 on the Rect area (i.e., the rectangular encryption area) of the original image matrix A, replace the original pixel values, and achieve visual occlusion (the size of the Rect area is m×m). 2. Video stream encoding: Use a preset encoding method (such as H.264, H.265, etc.) to encode the superimposed video stream to obtain an encoded video stream.

[0085] Step 106: Symmetrically encrypt the video encryption key based on the video key encryption key pair obtained by decryption to obtain an encrypted video encryption key.

[0086] The Video Key Encryption Key (VKEK) is the key used to encrypt the VEK, and its main function is to protect the security of the VEK itself.

[0087] Before encapsulating the encoded video stream, the video encryption key can be encrypted first. Specifically, the video key encryption key can be decrypted first. Then, use the video key encryption key to symmetrically encrypt the video encryption key to obtain an encrypted video encryption key. This encryption process can be described in detail in combination with the following specific implementation methods.

[0088] In a specific implementation of the present application, the above step 105 may include: Sub-step D1: Obtain the video key encryption ciphertext from the key management center, and the video key encryption ciphertext is the ciphertext encrypted based on the SM2 public key.

[0089] In this embodiment, the key management center is a security system responsible for generating, distributing, storing, and managing encryption keys.

[0090] The video key encryption ciphertext is the result of encrypting the "video key encryption key" using the SM2 public key.

[0091] SM2 is an elliptic curve public key cryptography algorithm released by the China National Cryptography Administration, which is used for digital signature, key exchange, and encryption.

[0092] When encrypting the video encryption key, the video key encryption ciphertext encrypted based on the SM2 public key can be obtained from the key management center.

[0093] Sub-step D2: Decrypt the ciphertext of the video key encryption using the SM2 private key corresponding to the SM2 public key to obtain the video key encryption key.

[0094] After obtaining the ciphertext of the video key encryption, the SM2 private key corresponding to the SM2 public key can be used to decrypt the ciphertext of the video key encryption to obtain the video key encryption key.

[0095] In the above process, the ciphertext management center can use the hardware security module to generate the SM2 key pair, transmit the SM2 private key to the local device through a secure channel (such as a key negotiation protocol, etc.), and the SM2 public key is publicly stored in the key directory in the ciphertext management and is used to encrypt the ciphertext of the video key encryption.

[0096] Sub-step D3: Perform symmetric encryption processing on the video encryption key based on the video key encryption key to obtain the encrypted video encryption key.

[0097] The encrypted video encryption key (Encrypted VEK, EVEK) is the ciphertext form after the VEK is encrypted by the VKEK.

[0098] After obtaining the video key encryption key, the video key encryption key can be used to perform symmetric encryption processing on the video encryption key to obtain the encrypted video encryption key.

[0099] In the embodiments of the present application, the national cryptography SM2 and SM4 algorithms are adopted to construct a privacy visual encryption solution that complies with national cryptography throughout the entire link, solving the problem of conflicts between traditional encryption and video coding.

[0100] Step 107: Write the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number, and the rectangular encryption area into the additional attributes of the encoded video stream to obtain the encrypted video stream.

[0101] The VKEK Version (i.e., the version number of the video key encryption key) is a unique number or label used to identify and manage different versions of the VKEK, aiming to support the key lifecycle management, rotation strategy, and coexistence of multiple versions, ensuring that the encrypted data can still be correctly decrypted after the key is updated.

[0102] In this example, the VKEK Version can be obtained from the ciphertext management center when obtaining the ciphertext of the video key encryption.

[0103] Through the above steps, an encrypted video encryption key, an encrypted random number, and a rectangular encrypted area can be obtained. Then, the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number, and the rectangular encrypted area can be written into the additional attributes of the encoded video stream to obtain an encrypted video stream. The data in the additional attributes can be used to assist the video stream receiver to complete the video frame decryption process.

[0104] The encryption method provided by the embodiments of the present application decodes the video stream to obtain a YUV image and generates an original image matrix associated with the YUV image. According to the encrypted features to be recognized in the YUV image, a rectangular encrypted area corresponding to the YUV image is obtained. The matrix corresponding to the rectangular encrypted area is subjected to position scrambling to obtain a scrambled matrix. The scrambled matrix is processed using a random number and a video encryption key to generate a two-dimensional ciphertext matrix, and the random number is encrypted using SM4 based on the video encryption key to obtain an encrypted random number. The two-dimensional ciphertext matrix is overlaid on the rectangular encrypted area of the original image matrix to obtain an occluded image matrix, and the occluded video stream obtained by splicing the occluded image matrices in chronological order is encoded to obtain an encoded video stream. The video encryption key is symmetrically encrypted based on the decrypted video key encryption key to obtain an encrypted video encryption key. The version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number, and the rectangular encrypted area are written into the additional attributes of the encoded video stream to obtain an encrypted video stream. In the embodiments of the present application, the scrambled matrix is processed using a video encryption key and a random number, which can provide a key with high randomness and high security for the encryption operation, enhance the expandability of the key, and improve the security of privacy data. At the same time, the random matrix generation and confusion technology are introduced to generate a random matrix matching the size of the privacy image block, and the relevant matrices are scrambled in position, which has high randomness and irregularity, making the encrypted image difficult to be cracked and enhancing the encryption effect. And the corresponding size of the random matrix can be flexibly generated according to the size of the privacy image block to meet the requirements of privacy data encryption in different scenarios.

[0105] Refer to Figure 2 , which shows the step flowchart of a decryption method provided by the embodiments of the present application. As Figure 2 shown, the decryption method may include: Step 201 to Step 208.

[0106] Step 201: Obtain the encrypted video stream and additional attributes, and decode the encrypted video stream to obtain a YUV image.

[0107] In this embodiment, an encrypted video stream and its additional attributes can be obtained, and the encrypted video stream can be decoded to obtain a YUV image. Specifically, an encrypted video stream encoded by an encoding method such as H.264 / H.255 can be obtained, and the video stream can be decoded into a frame image in YUV format, that is, a YUV image, using a hardware decoder.

[0108] Step 202: Extract the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number, and the rectangular encrypted area from the additional attributes.

[0109] Meanwhile, the version number (VKEK version) corresponding to the video key encryption key, the encrypted video encryption key (EVEK), the encrypted random number (S1), and the rectangular encrypted area (Rect) in the additional attributes can be extracted.

[0110] Step 203: Determine the video encryption key according to the version number and the encrypted video encryption key.

[0111] After obtaining the version number corresponding to the video key encryption key and the encrypted video encryption key, the video encryption key can be determined according to the version number and the encrypted video encryption key. The specific process can be as follows: Obtain the ciphertext encrypted based on the SM2 public key from the key management center according to the version number, and decrypt the video key encryption ciphertext using the SM2 private key corresponding to the SM2 public key to obtain the video key encryption key. Finally, use the video key encryption key to perform symmetric decryption on the encrypted video encryption key to obtain the video encryption key.

[0112] After obtaining the video encryption key, step 204 is executed.

[0113] Step 204: Decrypt the encrypted random number based on the video encryption key to obtain the decrypted random number.

[0114] After obtaining the video encryption key, the encrypted random number S1 can be decrypted using SM4 based on the video encryption key to obtain the decrypted random number S.

[0115] Step 205: Generate a two-dimensional random matrix according to the size of the rectangular encrypted area, and convert the two-dimensional random matrix into a one-dimensional random matrix.

[0116] After extracting the rectangular encrypted area, a two-dimensional random matrix can be generated according to the size of the rectangular encrypted area, and then, the two-dimensional random matrix can be converted into a one-dimensional random matrix.

[0117] It can be understood that the generation and conversion process of the two-dimensional random matrix are similar to those in the above embodiment, and will not be elaborated herein.

[0118] Step 206: Determine a two-dimensional restoration matrix based on the random number, the video encryption key, and the one-dimensional random matrix.

[0119] The two-dimensional restoration matrix refers to a matrix used to restore the encrypted area within a video image.

[0120] After obtaining the one-dimensional random matrix, a two-dimensional restoration matrix can be determined based on the random number, the video encryption key, and the one-dimensional random matrix. The specific implementation process can be as follows: Generate a one-dimensional target matrix of the same length as the one-dimensional random matrix through a key splitting function based on the random number and the video encryption key. Then, perform a bitwise OR operation (the OR operation is also known as logical addition and is a binary logical operation. Its definition is: as long as at least one of the participating logical variables has a value of true, the result of the OR operation is true; only when all logical variable values are false, the result is false) on the one-dimensional random matrix and the one-dimensional target matrix to obtain a one-dimensional ciphertext matrix, and convert the one-dimensional ciphertext matrix into a two-dimensional ciphertext matrix. Finally, the matrix element positions of the two-dimensional ciphertext matrix can be sorted according to the rectangular encryption area to obtain the two-dimensional restoration matrix.

[0121] In the above implementation process, sorting the matrix element positions of the two-dimensional ciphertext matrix is to restore the original index according to the permutation rule during encryption for reordering the element positions. During this process, the permutation rule is implicitly synchronized through the random number S, VEK generated during encryption, and the shared algorithm logic. After the video stream receiver obtains S and VEK through decryption, the same chaotic coefficient method or random number method is used to regenerate the random sequence to ensure that the random sequences generated based on S and VEK are exactly the same, and the permutation rule during encryption can be reproduced based on the same algorithm logic without additional transmission of the rule itself.

[0122] Step 207: Overlay the two-dimensional restoration matrix at the position corresponding to the rectangular encrypted area of the YUV image to obtain the decrypted YUV image.

[0123] After obtaining the two-dimensional restoration matrix, the two-dimensional restoration matrix can be overlaid at the position corresponding to the rectangular encrypted area of the YUV image to replace the rectangular encrypted area and obtain the decrypted YUV image.

[0124] Step 208: Perform encoding processing on the decrypted YUV image to obtain the restored video stream.

[0125] After obtaining the decrypted YUV image, the decrypted YUV images can be arranged in chronological order and encoded (such as re-encoded into the original RGB format, etc.) to obtain the restored video stream.

[0126] The decryption method provided by the embodiments of this application obtains an encrypted video stream and additional attributes, decodes the encrypted video stream to obtain a YUV image. Extracts the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number, and the rectangular encryption area from the additional attributes. Determines the video encryption key based on the version number and the encrypted video encryption key. Decrypts the encrypted random number based on the video encryption key to obtain the decrypted random number. Generates a two-dimensional random matrix according to the size of the rectangular encryption area, and converts the two-dimensional random matrix into a one-dimensional random matrix. Determines the two-dimensional reduction matrix based on the random number, the video encryption key, and the one-dimensional random matrix. Covers the position corresponding to the rectangular encryption area of the YUV image with the two-dimensional reduction matrix to obtain the decrypted YUV image. Encodes the decrypted YUV image to obtain the restored video stream. The embodiments of this application achieve a good balance among security, performance, and flexibility through innovative key management, region-selective encryption, and random matrix confusion. It is especially suitable for application scenarios with strict requirements for protecting sensitive information and ensuring video processing efficiency. Compared with traditional solutions, there are significant improvements in computational overhead, storage efficiency, and privacy protection capabilities.

[0127] In an intelligent monitoring system, the video stream may contain sensitive face information. To protect privacy, it is necessary to encrypt the face areas in the video frames to ensure that only authorized users can decrypt and restore the original images. The technical solution of this embodiment can achieve efficient and accurate privacy protection through the following steps: I. Encryption process: 1. Convert the video stream into a YUV image, and generate an n×n random matrix A according to the image using chaotic coefficients.

[0128] 2. Use a pre-trained AI model to detect all faces in the image and perform feature extraction, and the set is the feature block Rect (i.e., the rectangular encryption area).

[0129] 3. Generate a two-dimensional random matrix B1 according to Rect, and convert the two-dimensional random matrix B1 into a one-dimensional matrix B2.

[0130] 4. Generate a matrix C of the same length as matrix B2, and perform a position scrambling operation on matrix B2 and matrix C to generate matrix D.

[0131] 5. Generate a random number S and a VEK, use the key derivation function KDF to generate a matrix E of the same length as matrix D for the random number S and the VEK, perform an AND operation on matrix D and matrix E to generate matrix F1, and convert the one-dimensional matrix F1 into a two-dimensional matrix F2.

[0132] 6. Superimpose the two-dimensional matrix F2 on the original matrix A to complete the visual occlusion of the private data. Use VEK to perform SM4 encryption on the random number S to obtain S1. Obtain VKEK, use VKEK to perform symmetric encryption on VEK to obtain EVEK. Write the version (version number) of VKEK, EVEK, random number S1, and the feature block Rect into the additional attributes of the video stream encoding, and output the encrypted video stream.

[0133] II. Decryption process: 1. When the authorized user decodes, extract the relevant information in the additional attributes. Apply to the key management center for the corresponding encrypted VKEK according to the VKEK version. Use the private key to decrypt the encrypted VKEK to obtain VKEK. Use VKEK to decrypt EVEK to obtain VEK. Use VEK to decrypt the random number S1 to obtain the random number S.

[0134] 2. Generate a two-dimensional random matrix G1 according to the feature block Rect, and convert the two-dimensional random matrix G1 into a one-dimensional matrix G2.

[0135] 3. Use the key derivation function KDF on the random number S and VEK to generate a matrix H that is the same length as the matrix G2.

[0136] 4. Perform an OR operation on the matrix G2 and the matrix H to generate a one-dimensional matrix I1, and convert the one-dimensional matrix I1 into a two-dimensional matrix I2.

[0137] 5. According to the original feature block Rect, restore the original pixel arrangement of the matrix I2, and then superimpose it on the YUV image to restore the face area.

[0138] It can be understood that the encryption and decryption methods of the embodiments of the present application can be applied not only to the scenario of intelligent monitoring systems, but also to other scenarios (such as enterprise information transmission, etc.). The embodiments are not limited thereto.

[0139] Referring to Figure 3 , a schematic structural diagram of an encryption device provided by an embodiment of the present application is shown. As Figure 3 shown, the encryption device 300 may include the following modules: Original matrix generation module 310, configured to decode the video stream to obtain a YUV image, and generate an original image matrix associated with the YUV image; Encryption area acquisition module 320, configured to obtain a rectangular encryption area corresponding to the YUV image according to the to-be-encrypted features identified in the YUV image; Scrambling matrix acquisition module 330, configured to perform position scrambling processing on the matrix corresponding to the rectangular encryption area to obtain a scrambled matrix; The random number encryption module 340 is used to process the scrambling matrix with a random number and a video encryption key to generate a two-dimensional ciphertext matrix, and perform SM4 encryption on the random number based on the video encryption key to obtain an encrypted random number; The video stream encoding module 350 is used to cover the two-dimensional ciphertext matrix to the rectangular encryption area of the original image matrix to obtain an occluded image matrix, and encode the occluded video stream obtained by splicing the occluded YUV images in chronological order to obtain an encoded video stream; The encryption key acquisition module 360 is used to perform symmetric encryption processing on the video encryption key based on the video key encryption key obtained by decryption to obtain an encrypted video encryption key; The encrypted video stream acquisition module 370 is used to write the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number, and the rectangular encryption area into the additional attributes of the encoded video stream to obtain an encrypted video stream.

[0140] Optionally, the encryption area acquisition module includes: The encrypted data detection unit is used to detect the data to be encrypted in the YUV image; The to-be-encrypted feature extraction unit is used to extract the to-be-encrypted feature corresponding to the data to be encrypted in the YUV image; The encryption area determination unit is used to determine the rectangular encryption area corresponding to the YUV image according to the to-be-encrypted feature.

[0141] Optionally, the scrambling matrix acquisition module includes: The two-dimensional matrix generation unit is used to generate a two-dimensional random matrix associated with the rectangular encryption area according to the size of the rectangular encryption area; The random matrix conversion unit is used to convert the two-dimensional random matrix into a one-dimensional random matrix; The one-dimensional matrix generation unit is used to generate a one-dimensional matrix having the same length as the one-dimensional random matrix; The scrambling matrix acquisition unit is used to perform position scrambling processing on the matrix elements in the one-dimensional random matrix and the one-dimensional matrix to obtain the scrambling matrix.

[0142] Optionally, the random number encryption module includes: The random number generation unit is used to generate the random number and the video encryption key; The target matrix generation unit is used to generate a one-dimensional target matrix having the same length as the scrambling matrix through a key splitting function based on the random number and the video encryption key; A ciphertext matrix generation unit for performing a bitwise AND operation on the scrambling matrix and the one-dimensional target matrix to generate a one-dimensional ciphertext matrix; A ciphertext matrix conversion unit for converting the one-dimensional ciphertext matrix into the two-dimensional ciphertext matrix.

[0143] Optionally, the encryption key acquisition module includes: An encrypted ciphertext acquisition unit for acquiring a video key encrypted ciphertext from a key management center, where the video key encrypted ciphertext is a ciphertext encrypted based on an SM2 public key; A video key acquisition unit for decrypting the video key encrypted ciphertext based on the SM2 private key corresponding to the SM2 public key to obtain the video key encryption key; An encryption key acquisition unit for performing symmetric encryption processing on the video encryption key based on the video key encryption key to obtain an encrypted video encryption key.

[0144] The encryption device provided by the embodiment of the present application decodes a video stream to obtain a YUV image and generates an original image matrix associated with the YUV image. According to the features to be encrypted in the recognized YUV image, a rectangular encryption area corresponding to the YUV image is obtained. The matrix corresponding to the rectangular encryption area is subjected to position scrambling processing to obtain a scrambling matrix. The scrambling matrix is processed using a random number and a video encryption key to generate a two-dimensional ciphertext matrix, and the random number is encrypted using SM4 based on the video encryption key to obtain an encrypted random number. The two-dimensional ciphertext matrix is overlaid on the rectangular encryption area of the original image matrix to obtain an occluded image matrix, and the occluded video stream obtained by splicing the occluded image matrices in chronological order is encoded to obtain an encoded video stream. The video encryption key is symmetrically encrypted based on the decrypted video key encryption key to obtain an encrypted video encryption key. The version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number, and the rectangular encryption area are written into the additional attributes of the encoded video stream to obtain an encrypted video stream. The embodiment of the present application processes the scrambling matrix using a video encryption key and a random number, which can provide a key with high randomness and high security for the encryption operation, enhance the scalability of the key, and improve the security of privacy data. At the same time, the random matrix generation and confusion technology is introduced to generate a random matrix matching the size of the privacy image block, and the relevant matrices are scrambled in position, which has high randomness and irregularity, making the encrypted image difficult to crack and enhancing the encryption effect. And a random matrix of a corresponding size can be flexibly generated according to the size of the privacy image block to meet the encryption requirements of privacy data in different scenarios.

[0145] Refer to Figure 4 , which shows a structural schematic diagram of a decryption device provided by the embodiment of the present application. As Figure 4As shown, the decryption device 400 may include the following modules: A video stream decoding module 410, configured to obtain an encrypted video stream and additional attributes, and perform decoding processing on the encrypted video stream to obtain a YUV image; An additional information extraction module 420, configured to extract the version number, encrypted video encryption key, encrypted random number, and rectangular encrypted area corresponding to the video key encryption key from the additional attributes; An encryption key determination module 430, configured to determine a video encryption key according to the version number and the encrypted video encryption key; A random number decryption module 440, configured to decrypt the encrypted random number based on the video encryption key to obtain a decrypted random number; A random matrix generation module 450, configured to generate a two-dimensional random matrix according to the size of the rectangular encrypted area, and convert the two-dimensional random matrix into a one-dimensional random matrix; A reduction matrix determination module 460, configured to determine a two-dimensional reduction matrix based on the random number, the video encryption key, and the one-dimensional random matrix; A YUV image acquisition module 470, configured to cover the two-dimensional reduction matrix to a position corresponding to the rectangular encrypted area of the YUV image to obtain a decrypted YUV image; A video stream acquisition module 480, configured to perform encoding processing on the decrypted YUV image to obtain a restored video stream.

[0146] Optionally, the encryption key determination module includes: A ciphertext acquisition unit, configured to obtain a video key encryption ciphertext from a key management center according to the version number, where the video key encryption ciphertext is a ciphertext encrypted based on an SM2 public key; A first key acquisition unit, configured to decrypt the video key encryption ciphertext based on the SM2 private key corresponding to the SM2 public key to obtain a video key encryption key; A second key acquisition unit, configured to perform symmetric decryption processing on the encrypted video encryption key based on the video key encryption key to obtain the video encryption key.

[0147] Optionally, the reduction matrix determination module includes: A one-dimensional target matrix generation unit, configured to generate a one-dimensional target matrix of the same length as the one-dimensional random matrix based on the random number and the video encryption key through a key splitting function; A one-dimensional ciphertext matrix acquisition unit, configured to perform a bitwise OR operation on the one-dimensional random matrix and the one-dimensional target matrix to obtain a one-dimensional ciphertext matrix; A one-dimensional ciphertext matrix conversion unit for converting the one-dimensional ciphertext matrix into a two-dimensional ciphertext matrix; A reduction matrix acquisition unit for sorting the matrix element positions of the two-dimensional ciphertext matrix according to the rectangular encryption region to obtain the two-dimensional reduction matrix.

[0148] The decryption device provided by the embodiment of the present application obtains an encrypted video stream and additional attributes, decodes the encrypted video stream to obtain a YUV image. Extract the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number, and the rectangular encryption region in the additional attributes. Determine the video encryption key according to the version number and the encrypted video encryption key. Decrypt the encrypted random number based on the video encryption key to obtain the decrypted random number. Generate a two-dimensional random matrix according to the size of the rectangular encryption region, and convert the two-dimensional random matrix into a one-dimensional random matrix. Determine the two-dimensional reduction matrix based on the random number, the video encryption key, and the one-dimensional random matrix. Overlay the two-dimensional reduction matrix on the position corresponding to the rectangular encryption region of the YUV image to obtain the decrypted YUV image. Perform encoding processing on the decrypted YUV image to obtain the restored video stream. The embodiment of the present application achieves a good balance among security, performance, and flexibility through innovative key management, region-selective encryption, and random matrix confusion. It is particularly suitable for application scenarios with strict requirements for sensitive information protection while ensuring video processing efficiency. Compared with traditional solutions, there are significant improvements in computational overhead, storage efficiency, and privacy protection capabilities.

[0149] The embodiment of the present application also provides an electronic device, including: a memory, a processor, and a computer program stored on the memory and executable on the processor. When the computer program is executed by the processor, the above encryption method or the above decryption method is implemented.

[0150] Figure 5 FIG. shows a schematic structural diagram of an electronic device 500 according to an embodiment of the present invention. As Figure 5 shown, the electronic device 500 includes a central processing unit (CPU) 501, which can execute various appropriate actions and processes according to computer program instructions stored in a read-only memory (ROM) 502 or computer program instructions loaded from a storage unit 508 into a random access memory (RAM) 503. In the RAM 503, various programs and data required for the operation of the electronic device 500 can also be stored. The CPU 501, the ROM 502, and the RAM 503 are connected to each other through a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.

[0151] Multiple components in the electronic device 500 are connected to the I / O interface 505, including: an input unit 506, such as a keyboard, a mouse, a microphone, etc.; an output unit 507, such as various types of displays, speakers, etc.; a storage unit 508, such as a magnetic disk, an optical disc, etc.; and a communication unit 509, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 509 allows the electronic device 500 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0152] Each of the processes and treatments described above may be executed by the processing unit 501. For example, the method of any of the above embodiments may be implemented as a computer software program, which is tangibly included in a computer-readable medium, such as the storage unit 508. In some embodiments, part or all of the computer program may be loaded and / or installed onto the electronic device 500 via the ROM 502 and / or the communication unit 509. When the computer program is loaded into the RAM 503 and executed by the CPU 501, one or more actions in the method described above may be executed.

[0153] Additionally, an embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the above encryption method or the above decryption method is implemented.

[0154] Each embodiment in this specification is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. The same or similar parts among the embodiments may be referred to each other.

[0155] Those skilled in the art should understand that the embodiments of the present application may be provided as a method, a device, or a computer program product. Therefore, the embodiments of the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0156] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of the methods, terminals (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowcharts and / or block diagrams, and the combination of processes and / or blocks in the flowcharts and / or block diagrams, may be implemented by computer program instructions. These computer program instructions may be provided to the processors of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminals to generate a machine, such that the instructions executed by the processors of the computer or other programmable data processing terminals generate for implementing the processesFigure 1 one or more processes and / or blocks Figure 1 means for the functions specified in one or more blocks

[0157] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including an instruction means that implements the functions in the process Figure 1 one or more processes and / or blocks Figure 1 specified in one or more blocks

[0158] These computer program instructions may also be loaded onto a computer or other programmable data processing terminal, such that a series of operational steps are executed on the computer or other programmable terminal to produce a computer-implemented process, so that the instructions executed on the computer or other programmable terminal provide steps for implementing the functions specified in the process Figure 1 one or more processes and / or blocks Figure 1 specified in one or more blocks

[0159] Although the preferred embodiments of the embodiments of the present application have been described, those skilled in the art can make additional changes and modifications once they learn the basic creative concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments and all changes and modifications falling within the scope of the embodiments of the present application

[0160] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or terminal including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or terminal. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or terminal including the said element

[0161] The above has introduced in detail an encryption method, a decryption method, a device, an electronic device, and a computer-readable storage medium provided by this application. Specific examples are used in this article to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to this application.

Claims

1. An encryption method, characterized in that, The method includes: Performing decoding processing on the video stream to obtain a YUV image, and generating an original image matrix associated with the YUV image; Obtaining a rectangular encryption region corresponding to the YUV image according to the to-be-encrypted feature identified in the YUV image; Performing position scrambling processing on the matrix corresponding to the rectangular encryption region to obtain a scrambled matrix; Processing the scrambled matrix using a random number and a video encryption key to generate a two-dimensional ciphertext matrix, and performing SM4 encryption on the random number based on the video encryption key to obtain an encrypted random number; Covering the two-dimensional ciphertext matrix to the rectangular encryption region of the original image matrix to obtain an occluded image matrix, and encoding the occluded video stream obtained by splicing the occluded YUV images in chronological order to obtain an encoded video stream; Performing symmetric encryption processing on the video encryption key based on the decrypted video key encryption key to obtain an encrypted video encryption key; Writing the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number, and the rectangular encryption region into the additional attributes of the encoded video stream to obtain an encrypted video stream.

2. The method according to claim 1, wherein The obtaining a rectangular encryption region corresponding to the YUV image according to the to-be-encrypted feature identified in the YUV image includes: Detecting the to-be-encrypted data in the YUV image; Extracting the to-be-encrypted feature corresponding to the to-be-encrypted data in the YUV image; Determining the rectangular encryption region corresponding to the YUV image according to the to-be-encrypted feature.

3. The method according to claim 1, wherein The performing position scrambling processing on the matrix corresponding to the rectangular encryption region to obtain a scrambled matrix includes: Generating a two-dimensional random matrix associated with the rectangular encryption region according to the size of the rectangular encryption region; Converting the two-dimensional random matrix into a one-dimensional random matrix; Generating a one-dimensional matrix of the same length as the one-dimensional random matrix; Performing position scrambling processing on the matrix elements in the one-dimensional random matrix and the one-dimensional matrix to obtain the scrambled matrix.

4. The method according to claim 1, characterized in that, The processing the scrambled matrix using a random number and a video encryption key to generate a two-dimensional ciphertext matrix includes: Generating the random number and the video encryption key; Generating a one-dimensional target matrix of the same length as the scrambled matrix through a key splitting function based on the random number and the video encryption key; Performing a bitwise AND operation on the scrambled matrix and the one-dimensional target matrix to generate a one-dimensional ciphertext matrix; Converting the one-dimensional ciphertext matrix into the two-dimensional ciphertext matrix.

5. The method according to claim 1, wherein The performing symmetric encryption processing on the video encryption key based on the decrypted video key encryption key to obtain an encrypted video encryption key includes: Obtaining a video key encryption ciphertext from the key management center, where the video key encryption ciphertext is a ciphertext encrypted based on the SM2 public key; Decrypting the video key encryption ciphertext based on the SM2 private key corresponding to the SM2 public key to obtain the video key encryption key; Performing symmetric encryption processing on the video encryption key based on the video key encryption key to obtain an encrypted video encryption key.

6. A decryption method, characterized in that, The method includes: Obtain an encrypted video stream and additional attributes, and perform decoding processing on the encrypted video stream to obtain a YUV image; Extract the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number, and the rectangular encryption area from the additional attributes; Determine the video encryption key according to the version number and the encrypted video encryption key; Decrypt the encrypted random number based on the video encryption key to obtain the decrypted random number; Generate a two-dimensional random matrix according to the size of the rectangular encryption area, and convert the two-dimensional random matrix into a one-dimensional random matrix; Determine a two-dimensional reduction matrix based on the random number, the video encryption key, and the one-dimensional random matrix; Cover the two-dimensional reduction matrix to the position corresponding to the rectangular encryption area of the YUV image to obtain the decrypted YUV image; Perform encoding processing on the decrypted YUV image to obtain the restored video stream.

7. The method according to claim 6, wherein The determining the video encryption key according to the version number and the encrypted video encryption key includes: According to the version number, obtain the video key encryption ciphertext from the key management center, and the video key encryption ciphertext is a ciphertext encrypted based on the SM2 public key; Decrypt the video key encryption ciphertext based on the SM2 private key corresponding to the SM2 public key to obtain the video key encryption key; Perform symmetric decryption processing on the encrypted video encryption key based on the video key encryption key to obtain the video encryption key.

8. The method according to claim 6, characterized in that The determining the two-dimensional reduction matrix based on the random number, the video encryption key, and the one-dimensional random matrix includes: Generate a one-dimensional target matrix of the same length as the one-dimensional random matrix through a key splitting function based on the random number and the video encryption key; Perform a bitwise OR operation on the one-dimensional random matrix and the one-dimensional target matrix to obtain a one-dimensional ciphertext matrix; Convert the one-dimensional ciphertext matrix into a two-dimensional ciphertext matrix; Sort the matrix element positions of the two-dimensional ciphertext matrix according to the rectangular encryption area to obtain the two-dimensional reduction matrix.

9. An encryption device, characterized in that, The device includes: An original matrix generation module, configured to perform decoding processing on a video stream to obtain a YUV image, and generate an original image matrix associated with the YUV image; An encryption area acquisition module, configured to obtain a rectangular encryption area corresponding to the YUV image according to the encryption feature to be encrypted identified in the YUV image; A scrambling matrix acquisition module, configured to perform position scrambling processing on the matrix corresponding to the rectangular encryption area to obtain a scrambled matrix; A random number encryption module, configured to process the scrambled matrix using a random number and a video encryption key to generate a two-dimensional ciphertext matrix, and perform SM4 encryption on the random number based on the video encryption key to obtain an encrypted random number; A video stream encoding module, configured to cover the two-dimensional ciphertext matrix to the rectangular encryption area of the original image matrix to obtain an occluded image matrix, and encode the occluded video stream obtained by splicing the occluded YUV images in chronological order to obtain an encoded video stream; An encryption key acquisition module, configured to perform symmetric encryption processing on the video encryption key based on the video key encryption key obtained by decryption, to obtain an encrypted video encryption key; An encrypted video stream acquisition module, configured to write the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number, and the rectangular encrypted area into additional attributes of the encoded video stream, to obtain an encrypted video stream.

10. A decryption device, characterized in that, The apparatus includes: A video stream decoding module, configured to acquire an encrypted video stream and additional attributes, and perform decoding processing on the encrypted video stream to obtain a YUV image; An additional information extraction module, configured to extract the version number corresponding to the video key encryption key, the encrypted video encryption key, the encrypted random number, and the rectangular encrypted area from the additional attributes; An encryption key determination module, configured to determine a video encryption key according to the version number and the encrypted video encryption key; A random number decryption module, configured to decrypt the encrypted random number based on the video encryption key to obtain a decrypted random number; A random matrix generation module, configured to generate a two-dimensional random matrix according to the size of the rectangular encrypted area, and convert the two-dimensional random matrix into a one-dimensional random matrix; A reduction matrix determination module, configured to determine a two-dimensional reduction matrix based on the random number, the video encryption key, and the one-dimensional random matrix; A YUV image acquisition module, configured to cover the two-dimensional reduction matrix to a position corresponding to the rectangular encrypted area of the YUV image, to obtain a decrypted YUV image; A video stream acquisition module, configured to perform encoding processing on the decrypted YUV image to obtain a restored video stream.

11. An electronic device, characterized in that, It includes: A processor, a memory, and a computer program stored on the memory and executable on the processor, where when the processor executes the program, it implements the encryption method according to any one of claims 1 to 5, or the decryption method according to any one of claims 6 to 8.

12. A computer-readable storage medium, characterized in that, When the instructions in the storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the encryption method according to any one of claims 1 to 5, or the decryption method according to any one of claims 6 to 8.

Citation Information

Patent Citations

  • Adaptive image encryption domain reversible hiding method based on hybrid encryption mechanism

    CN108566500A

  • Image encryption storage method and device

    CN111832035A

  • Image processing method, device and equipment

    CN112788195A

  • Method and system for improving data transmission security

    CN115988220A

  • Video stream parallel chaotic encryption method based on key frame and image compression

    CN116488792A