Secure transmission method, device and equipment of multimedia data, medium and product
By encrypting the multimedia streaming data based on the vendor ID and encapsulating it into an improved vendor-specific format, the problem that the H.264 compressed AVTP format does not support encryption is solved, and the secure transmission of multimedia data is realized, which enhances the security and efficiency of video streams.
Patent Information
- Application Number
- CN202510697006.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-28
- Publication Date
- 2025-07-11
AI Technical Summary
The existing H.264 compressed AVTP format does not support encryption, resulting in susceptible interception and unauthorized access within sensitive videos during transmission, lack of built-in encryption mechanisms, and relying on external encryption protocols may introduce additional latency and complexity.
By obtaining the multimedia stream data to be transmitted and the vendor ID, encrypting the data based on the vendor ID, and encapsulating it in an improved vendor-specific format, including an encrypted payload structure, forming an encrypted data packet to be transmitted.
It realizes encryption of multimedia data without the need for additional security layers, enhances the security of data streams, meets the application needs of different suppliers, and promotes market innovation and competitive advantages.
Smart Images

Figure CN120301698A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technologies, and in particular, to a method, apparatus, device, medium, and product for secure transmission of multimedia data. Background Art
[0002] The Audio / Video Transport Protocol (AVTP) specifies a protocol for transmitting audio and video data through Time-Sensitive Networking (TSN) capabilities. It aims to utilize TSN capabilities, including the General Precision Time Protocol (gPTP), the Stream Reservation Protocol (SRP), and the Forwarding and Queuing Enhancements for Time-Sensitive Streams (FQTSS). It aims to facilitate the efficient transmission of audio and video data and is particularly suitable for the widely adopted compression standard H.264 video streams. One of its main features is low latency, which is crucial for real-time automotive video stream applications. Additionally, security is an important consideration when using AVTP and H.264 to stream sensitive content.
[0003] The existing H.264-compressed AVTP format itself does not support encryption, which poses a challenge to protecting sensitive video content during transmission. Although AVTP aims to efficiently transmit low-latency and high-quality audio and video data, its current specification lacks a built-in mechanism for encrypting H.264 streams. This means that without an additional security layer, video data transmitted via AVTP may be vulnerable to interception and unauthorized access. Therefore, external encryption protocols (such as AES, etc.) must be relied upon to protect its H.264 streams, which may complicate implementation and potentially introduce additional latency. Summary of the Invention
[0004] The present invention provides a method, apparatus, device, medium, and product for secure transmission of multimedia data to achieve processing of video stream data based on the use of an improved vendor-specific format, improving the efficiency and effectiveness of video stream applications.
[0005] According to a first aspect of the present invention, there is provided a method for secure transmission of multimedia data, including:
[0006] Obtaining multimedia stream data to be transmitted and a vendor ID;
[0007] Performing encryption processing on the multimedia stream data to be transmitted based on the vendor ID to obtain encrypted information;
[0008] Encapsulating the vendor ID and the encrypted information according to the improved vendor-specific format to form a data packet to be transmitted and transmitting it, where the improved vendor-specific format includes an encrypted payload structure.
[0009] According to a second aspect of the present invention, there is provided a secure transmission device for multimedia data, comprising:
[0010] An information acquisition module, configured to acquire multimedia stream data to be transmitted and a supplier ID;
[0011] A data encryption module, configured to perform encryption processing on the multimedia stream data to be transmitted based on the supplier ID to obtain encrypted information;
[0012] A data packet transmission module, configured to encapsulate the supplier ID and the encrypted information according to the improved supplier-specific format to form a data packet to be transmitted and perform transmission, where the improved supplier-specific format includes an encrypted payload structure.
[0013] According to a third aspect of the present invention, there is provided an electronic device, the electronic device comprising:
[0014] At least one processor; and
[0015] A memory communicatively connected to the at least one processor; wherein,
[0016] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the secure transmission method of multimedia data according to any embodiment of the present invention.
[0017] According to a fourth aspect of the present invention, there is provided a computer-readable storage medium, the computer-readable storage medium storing computer instructions, and the computer instructions are used to implement the secure transmission method of multimedia data according to any embodiment of the present invention when executed by a processor.
[0018] According to a fifth aspect of the present invention, an embodiment of the present invention further provides a computer program product, the computer program product comprising a computer program, and the computer program implements the secure transmission method of multimedia data according to any embodiment of the present invention when executed by a processor.
[0019] The technical solution of the embodiment of the present invention is as follows: obtain the multimedia stream data to be transmitted and the supplier ID; encrypt the multimedia stream data to be transmitted based on the supplier ID to obtain encrypted information; encapsulate the supplier ID and the encrypted information according to the improved supplier-specific format to form a data packet to be transmitted and transmit it. The improved supplier-specific format includes an encrypted payload structure. By adding the encrypted payload structure to the improved supplier-specific format, an encryption key is dynamically generated using the supplier ID to encrypt the data stream to be transmitted and encapsulate it into an encrypted data packet to be transmitted. This enhances the security of the data stream, enables the encryption of the stream data without an additional security layer, can configure different improved supplier-specific formats for different suppliers to meet the requirements of various applications, and at the same time promotes market innovation and competitive advantages.
[0020] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0022] Figure 1 is a flowchart of a method for secure transmission of multimedia data provided in Embodiment 1 of the present invention;
[0023] Figure 2 is an example diagram of a traditional compressed video format in a method for secure transmission of multimedia data provided in Embodiment 1 of the present invention;
[0024] Figure 3 is an example diagram of an improved supplier-specific format in a method for secure transmission of multimedia data provided in Embodiment 1 of the present invention;
[0025] Figure 4 is a flowchart of a decryption example of a method for secure transmission of multimedia data provided in Embodiment 1 of the present invention;
[0026] Figure 5 is a flowchart of a method for secure transmission of multimedia data provided in Embodiment 2 of the present invention;
[0027] Figure 6 is a flowchart of an encryption example of a method for secure transmission of multimedia data provided in Embodiment 2 of the present invention;
[0028] Figure 7 It is a schematic structural diagram of a secure transmission device for multimedia data provided in Embodiment 3 of the present invention;
[0029] Figure 8 It is a schematic structural diagram of an electronic device implementing the embodiment of the present invention. Detailed implementation manners
[0030] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0031] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0032] Embodiment 1
[0033] Figure 1 The present invention provides a flowchart of a secure transmission method for multimedia data in Embodiment 1. This embodiment is applicable to the transmission of multimedia data streams through the AVTP transmission protocol. This method can be executed by a secure transmission device for multimedia data, and the secure transmission device for multimedia data can be implemented in the form of hardware and / or software. The secure transmission device for multimedia data can be configured in an electronic device. As Figure 1 shown, the method includes:
[0034] S110. Obtain the multimedia stream data to be transmitted and the supplier ID.
[0035] In this embodiment, the multimedia stream data to be transmitted can be understood as multimedia stream data that needs to be encrypted before transmission. For example, it can be H.264 video stream data. The supplier ID can be understood as a code or number used to uniquely identify a supplier, which can quickly identify, track, and manage supplier information. For example, the media access control address can be used as the supplier ID.
[0036] Specifically, the processor can receive the multimedia stream data to be transmitted, as well as the supplier ID related to the transmission of the multimedia stream data to be transmitted.
[0037] S120. Encrypt the multimedia stream data to be transmitted based on the supplier ID to obtain encrypted information.
[0038] In this embodiment, the encrypted information can be understood as information related to encryption, such as including ciphertext and keys, etc.
[0039] Specifically, the processor can use the supplier ID as the key and encrypt the multimedia stream data to be transmitted in a specified encryption manner to obtain the encrypted ciphertext and combine it with the key, etc. as the encrypted information.
[0040] S130. Package the supplier ID and the encrypted information according to an improved supplier-specific format to form a data packet to be transmitted and transmit it. The improved supplier-specific format includes an encrypted payload structure.
[0041] It can be understood that traditional AVTP aims to promote the efficient transmission of audio and video data, making it particularly suitable for the widely adopted compression standard H.264 video stream. One of its main features is low latency, which is crucial for real-time automotive video stream applications. AVTP also supports the precise synchronization of video streams, ensuring that H.264 videos remain synchronized, thus achieving a seamless viewing experience. In addition, it includes a mechanism for prioritizing media traffic, which can maintain high video quality even in a congested network environment, which is crucial for high-resolution content. The protocol promotes interoperability by complying with standards such as IEEE 1722, enabling devices from different manufacturers to work effectively together. In addition, AVTP can handle multiple H.264 streams simultaneously, making it suitable for complex settings such as multi-camera events. Its efficient transmission ability combined with the compression of H.264 can optimize the bandwidth usage without sacrificing quality.
[0042] Exemplarily, Figure 2 FIG. is an example diagram of a traditional compressed video format in a secure transmission method for multimedia data provided in the first embodiment of the present invention, as Figure 2As shown, the traditional format is the AVTP H264 compressed video format, which includes: subtype data, StreamID, AVTP Time, FormatInfo, Packet Info, and H.264Header: occupying 8 bytes, containing the header information of H.264 video encoding and H.264Data. It can be seen from the figure that the existing H.264 compressed AVTP format itself does not support encryption, which poses a challenge to protecting sensitive video content during transmission. Although AVTP aims to efficiently transmit low-latency and high-quality audio and video data, its current specification lacks a built-in mechanism for encrypting H.264 streams, highlighting the need for potential enhancements or the adoption of vendor-specific solutions.
[0043] In this embodiment, to address the above needs, an improved vendor-specific format is preset for different vendors. An encrypted payload structure for adding encrypted data is set in the improved vendor-specific format. By means of the improved vendor-specific format, vendors can customize the protocol according to their specific application requirements and optimize performance in various environments. Among them, the encrypted payload structure can be understood as a data structure for writing information related to encryption. The packet to be transmitted can be understood as the packed data formed according to the improved vendor-specific format and is used for transmission according to the corresponding transmission format.
[0044] Among them, the improved vendor-specific format includes: subtype data bit, StreamID bit, protocol timestamp bit, format specification bit, packet information bit, and encrypted payload structure. The subtype data bit can be understood as a field for indicating the type of data. The StreamID bit can be understood as a field for identifying different data streams. The protocol timestamp bit can be understood as a field for recording the timestamp information of data, so as to synchronize the data of different devices. The format specification bit can be understood as a field for storing the vendor ID used by the vendor for encryption. The packet information bit can be understood as containing information about the packet, such as including the size of the stream data, the vendor ID for decryption, the decoding format of the data (such as H.264), etc.
[0045] Specifically, the processor can write the vendor ID and the attribute information related to the multimedia stream data to be transmitted to the specified position of the packet to be transmitted according to the improved vendor-specific format, write the encryption information to form the packet to be transmitted according to the structural format of the encrypted payload structure and perform transmission. The improved vendor-specific format includes the encrypted payload structure.
[0046] Exemplarily, a specific example is used to demonstrate the improved vendor-specific format. Figure 3This is an example diagram for improving the vendor - specific format in a secure transmission method for multimedia data provided in Embodiment 1 of the present invention. As Figure 3 shown, the first line is the subtype data bit, the second line is the stream ID bit, the third line is the protocol timestamp bit (the transmission protocol in the present invention uses AVTP), the fourth line is the Format Specific bit, the fifth and sixth lines are the PacketInfo bits, and the subsequent lines are all encrypted payload structures. According to the set encryption method, the encryption information can be determined. For example, if the encryption information includes an initialization vector, encrypted ciphertext data, and an authentication tag, then the encrypted payload structure includes the positions for writing the initialization vector, encrypted ciphertext data, and authentication tag, as well as the data length of the encrypted data. It can be seen that compared with Figure 2 the traditional compressed video format in [reference], the improved vendor - specific format provided in the present invention includes: an encrypted payload structure (Vendor Payload) for writing encrypted stream data, and a position for writing the vendor ID, i.e., vendor_id_1 in the figure. The vendor ID1 can write the MAC address of the encryption key. And the traditional packet information is modified, including the length of the unencrypted stream data and vendor ID2 (vendor_id_2). The vendor ID2 is used for the MAC address of the decryption key. The structure included in the encrypted payload structure can be customized according to the encryption algorithm set by the vendor. For example, when the encryption method uses the AES - 128 - GCM (Advanced Encryption Standard in Galois / Counter mode) method, the encrypted payload structure includes: encrypted data length, unique initialization vector, encrypted data, and authentication tag. The encrypted secure H.264 stream data payload can be integrated into the vendor - specific AVTP format, which can enhance the security of the video stream while maintaining high performance. AES - 128 - GCM is a powerful encryption technology that provides confidentiality and integrity, ensuring the H.264 stream data is protected from unauthorized access and tampering.
[0047] Vendor-specific formats can utilize the Media Access Control (MAC) address as a unique vendor ID, which helps dynamically generate encryption keys, enhancing security by ensuring that the keys are unique for each session. During transmission, H.264 data is encrypted in blocks using AES-128-GCM, which not only protects the video content but also uses an authentication tag to verify the integrity of the data. Care must be taken with the packetization process to ensure that the encrypted payload complies with the AVTP specification while addressing issues such as the Maximum Transmission Unit (MTU) size and potential fragmentation. By effectively integrating the AES-128-GCM-secured H.264 payload into the vendor-specific AVTP format, vendors can provide secure, high-quality video streaming solutions that meet the needs of various applications while promoting market innovation and competitive advantage.
[0048] The technical solution of the embodiment of the present invention includes: obtaining the multimedia stream data to be transmitted and the vendor ID; encrypting the multimedia stream data to be transmitted based on the vendor ID to obtain encrypted information; encapsulating the vendor ID and the encrypted information according to the improved vendor-specific format to form a data packet to be transmitted and transmitting it. The improved vendor-specific format includes an encrypted payload structure. By adding the encrypted payload structure to the improved vendor-specific format, an encryption key is dynamically generated using the vendor ID to encrypt the data stream to be transmitted and encapsulate it into an encrypted data packet to be transmitted. This enhances the security of the data stream, enabling the encryption of stream data without an additional security layer. Different improved vendor-specific formats can be configured for different vendors to meet the needs of various applications while promoting market innovation and competitive advantage.
[0049] As a first alternative embodiment of the first embodiment, on the basis of the above embodiment, it further includes:
[0050] Obtaining the multimedia stream data to be decrypted and decrypting the multimedia stream data to be decrypted according to the improved vendor-specific format to obtain decrypted data.
[0051] In this embodiment, the multimedia stream data to be decrypted can be understood as encrypted multimedia stream data. The decrypted data can be understood as the data result after decryption.
[0052] Specifically, the processor can obtain the multimedia stream data to be decrypted and decrypt the multimedia stream data to be decrypted according to the improved vendor-specific format to obtain decrypted data.
[0053] Exemplarily, an Audio Video Bridging (AVB) talker node typically transmits H264 video stream data, and an AVB listener can receive the multimedia stream data to be decrypted transmitted. Whether subsequent decryption processing can be performed can be determined by checking parameters related to the stream ID and timestamp.
[0054] Further, decrypt the multimedia stream data to be decrypted according to the improved vendor-specific format to obtain decrypted data, including:
[0055] Read the stream data length of the multimedia stream data to be decrypted; derive the media access control address of the vendor from the multimedia stream data to be decrypted according to the improved vendor-specific format; derive the decryption key of the set number of bytes from the media access control address through an encryption hash function; read the decryption unique initialization vector from the head position of the encrypted payload structure of the multimedia stream data to be decrypted according to the improved vendor-specific format; read the ciphertext data from the encrypted payload structure according to the stream data length, and decrypt the ciphertext data through the decryption unique initialization vector and the decryption key to obtain intermediate decrypted data; verify the integrity of the intermediate decrypted data through the authentication tag at the tail position of the encrypted payload structure, and use the complete intermediate decrypted data as the final decrypted data.
[0056] In this embodiment, the stream data length is used to characterize the length of the data that needs to be decrypted in the multimedia stream data to be decrypted. The media access control address of the vendor can be understood as the MAC address used for decryption. The encryption hash function can be understood as the function used during encryption. The decryption key can be understood as the key used to decrypt the encrypted data. The ciphertext data can be understood as the encrypted data content. The intermediate decrypted data can be understood as the data content obtained by decryption.
[0057] Specifically, the processor can first read the subtype data, stream ID, and timestamp of the multimedia stream data to be decrypted to determine whether the multimedia stream data to be decrypted can be processed currently (for example, different subtypes of data have different priorities, sorted by the stream ID or the timestamp, etc.). When decryption is possible, read the stream data length of the multimedia stream data to be decrypted, and derive the media access control address of the vendor from the multimedia stream data to be decrypted according to the improved vendor-specific format (for example Figure 3 where vendor_id_1 and vendor_id_2 in record the MAC address). Derive the decryption key of the set number of bytes from the media access control address through an encryption hash function (such as the SHA-256 function). Read the decryption unique initialization vector from the head position of the encrypted payload structure of the multimedia stream data to be decrypted according to the improved vendor-specific format (that is Figure 3in IV). The processor can read the ciphertext data from the encrypted payload structure according to the stream data length, set the decryption context according to the decryption method corresponding to the encryption algorithm by decrypting the unique initialization vector and the decryption key, decrypt the ciphertext data, and append the result to the dynamically allocated buffer to obtain the intermediate decrypted data after decryption. The processor can verify the integrity of the intermediate decrypted data through the authentication tag at the tail position of the encrypted payload structure, and use the complete intermediate decrypted data as the final decrypted data.
[0058] Further, after decrypting the multimedia stream data to be decrypted according to the improved vendor-specific format to obtain the decrypted data, it further includes:
[0059] Read the data format and protocol format subtype from the multimedia stream data to be decrypted according to the improved vendor-specific format, and transmit the data format, format subtype, and decrypted data to the media framework for display.
[0060] In this embodiment, the media framework can be understood as being used to build a streaming media application to play data streams such as audio and video. For example, it can be GStreamer that supports scenarios from simple playback to complex codec, filtering, and transmission.
[0061] Specifically, the processor can read the data format and protocol format subtype from the multimedia stream data to be decrypted according to the improved vendor-specific format, and transmit the data format, format subtype, and decrypted data to the media framework. After the media framework performs operations such as decoding on the decrypted data based on the data format and format subtype, it is displayed on the display.
[0062] Exemplarily, a specific example is used to demonstrate the decryption process. Figure 4 It is a flowchart of the decryption example of a secure transmission method for multimedia data provided in Embodiment 1 of the present invention. As Figure 4 shown, the steps can be:
[0063] S401. Read the subtype, stream ID, and timestamp of the multimedia stream data to be decrypted, and verify whether the multimedia stream data to be decrypted needs to be decoded currently;
[0064] S402. Derive the media access control address of the vendor from the multimedia stream data to be decrypted according to the improved vendor-specific format;
[0065] S403. Derive the decryption key of the set number of bytes from the media access control address through the SHA-256 function;
[0066] S404. Read the decryption unique initialization vector from the encrypted payload structure of the multimedia stream data to be decrypted;
[0067] S405. Read the ciphertext data from the encrypted payload structure according to the stream data length, and decrypt the ciphertext data by using the decryption unique initialization vector and the decryption key to obtain intermediate decrypted data;
[0068] S406. Verify the integrity of the intermediate decrypted data through the authentication tag at the tail position of the encrypted payload structure, and use the complete intermediate decrypted data as the final decrypted data;
[0069] S407. Transmit the data format, format subtype, and decrypted data to the media framework for display.
[0070] Embodiment 2
[0071] Figure 5 The flowchart of a secure transmission method for multimedia data provided by Embodiment 2 of the present invention. This embodiment is a further refinement of the above embodiment. As Figure 5 shown, the method includes:
[0072] S501. Obtain the multimedia stream data to be transmitted and the supplier ID.
[0073] S502. Read the multimedia stream data to be transmitted in units of data blocks to obtain data blocks to be encrypted.
[0074] In this embodiment, the data blocks to be encrypted can be understood as parts obtained by dividing the overall stream data into blocks.
[0075] Specifically, the processor can read the multimedia stream data to be transmitted in units of data blocks to form multiple data blocks to be encrypted.
[0076] S503. Derive a derived key of a set number of bytes from the supplier ID through an encryption hash function, and randomly generate a unique initialization vector.
[0077] In this embodiment, the encryption hash function can be understood as a function for generating a key, such as the SHA-256 function. The set number of bytes is used to indicate the length of the derived key, such as 16 bytes. The derived key can be understood as the key for encryption. The unique initialization vector can be understood as a randomly generated value, which is combined with the key during the encryption process to ensure that the same plaintext generates different ciphertexts at different times or in different scenarios.
[0078] Specifically, the processor can derive a derived key of a set number of bytes from the vendor ID (which can be the MAC address) through an encryption hash function (such as through SHA-256), using the MAC address as the unique vendor ID, which helps to dynamically generate encryption keys and enhance security by ensuring that the key is unique for each session. The processor can randomly generate a unique Initialization Vector (IV).
[0079] S504. Encrypt each data block to be encrypted through an encryption algorithm, the derived key, and the unique initialization vector to obtain encrypted data.
[0080] In this embodiment, the encryption algorithm can use algorithms such as AES-128-GCM for data encryption.
[0081] Specifically, the processor can use the AES-128-GCM algorithm to create and initialize an encryption context based on the derived key and the unique initialization vector IV, and then encrypt each data block to be encrypted to obtain encrypted data.
[0082] S505. Authenticate the encrypted data to generate an authentication tag, and use the unique initialization vector, the authentication tag, and the encrypted data as encrypted information.
[0083] In this embodiment, the authentication tag can be understood as a tag used to authenticate data to verify data integrity and authenticity.
[0084] Specifically, the processor can authenticate the encrypted data to generate an authentication tag, and then use the unique initialization vector, the authentication tag, and the encrypted data obtained after the encryption process as encrypted information.
[0085] S506. Obtain the transmission configuration information of the multimedia stream data to be transmitted.
[0086] In this embodiment, the transmission configuration information can be understood as the configuration information when transmitting the multimedia stream data to be transmitted, such as metadata, etc., and can include, for example, the current stream ID, the protocol format type of the transmission, and the timestamp, etc.
[0087] S507. Write the vendor ID, the protocol format subtype, the stream ID, and the timestamp in the transmission configuration information to the specified position of the data packet to be transmitted according to the improved vendor-specific format.
[0088] In this embodiment, the protocol format subtype can be understood as characterizing the type of data. The stream ID can be understood as the ID used to identify different data streams. The timestamp can be understood as the field used to record the timestamp information of the data, so as to synchronize the data of different devices. The specified position can be understood as the position specified for different items in the improved vendor-specific format, that is Figure 3 the corresponding position in
[0089] S508. Determine the payload length of the encrypted data in the encryption information and write it to the length position in the encrypted payload structure.
[0090] In this embodiment, the payload length is used to characterize the length of the encrypted data. The length position can be understood as the position used to store the payload length.
[0091] Specifically, the processor can determine the length of the encrypted data in the encryption information and fill it into the length position of the payload structure according to the protocol format subtype.
[0092] S509. Write the unique initialization vector in the encryption information to the head position in the encrypted payload structure.
[0093] In this embodiment, the head position is the position before the encrypted data and is used to store the unique initialization vector.
[0094] Specifically, the processor can write the unique initialization vector in the encryption information to the corresponding head position in the encrypted payload structure.
[0095] S510. Write the encrypted data in the encryption information to the encrypted payload position in the encrypted payload structure.
[0096] In this embodiment, the encrypted payload position can be understood as the position used to store the encrypted data.
[0097] Specifically, the processor can write the encrypted data in the encryption information to the encrypted payload position in the encrypted payload structure one by one according to the encrypted data blocks.
[0098] S511. Write the authentication tag in the encryption information to the end position in the encrypted payload structure to obtain the encapsulated data packet to be transmitted.
[0099] In this embodiment, the end position can be understood as the end of the encrypted payload structure.
[0100] Specifically, the processor can write the authentication tag in the encryption information to the end position in the encrypted payload structure to fill in all the content and obtain the encapsulated data packet to be transmitted.
[0101] The technical solution of the embodiment of the present invention adds an encrypted payload structure to the improved vendor-specific format and uses the media access control (MAC) address in the improved vendor-specific format as the unique vendor ID, which helps to dynamically generate an encryption key and enhances the security of the data stream by ensuring that the key is unique for each session. During transmission, the H.264 data is encrypted block by block using an encryption algorithm, which not only protects the video content but also uses the generated authentication tag to verify the integrity of the data, ensuring that the encrypted payload complies with the AVTP specification while solving problems such as the maximum transmission unit (MTU) size and potential fragmentation. By adding the encrypted encrypted information to the encrypted payload structure, that is, to the improved AVTP format specific to the vendor, the vendor can provide a secure and high-quality video stream solution to meet the needs of various applications while promoting market innovation and competitive advantages.
[0102] Exemplarily, a specific example is used to demonstrate the encryption process. Figure 6 It is a flowchart of the encryption example of a secure transmission method for multimedia data provided by the second embodiment of the present invention. As Figure 6 shown, the steps can be as follows:
[0103] S601. Fill in the AVTP data subtype, Stream ID, and AVTP Timestamp.
[0104] S602. Fill in the MAC address into vendor_id_1 and vendor_id_2.
[0105] S603. Derive a derived key of a set number of bytes from the vendor ID through an encryption hash function (SHA-256) and randomly generate a unique initialization vector.
[0106] S604. Read the multimedia stream data to be transmitted and encrypt each data block to be encrypted through an encryption algorithm (AES-128-GCM), the derived key, and the unique initialization vector (IV) to obtain encrypted data.
[0107] S605. Determine the payload length of the encrypted data in the encrypted information and write it to the length position in the encrypted payload structure.
[0108] S606. Write the unique initialization vector in the encrypted information to the header position in the encrypted payload structure.
[0109] S607. Write the encrypted data in the encrypted information to the encrypted payload position in the encrypted payload structure.
[0110] S608. Write the authentication tag in the encrypted information to the end position in the encrypted payload structure, obtain the encapsulated data packet to be transmitted, and transmit it.
[0111] Embodiment III
[0112] Figure 7 The structural schematic diagram of a secure transmission device for multimedia data provided by Embodiment III of the present invention. As Figure 7 shown, the device includes:
[0113] An information acquisition module 71, configured to acquire the multimedia stream data to be transmitted and the supplier ID;
[0114] A data encryption module 72, configured to encrypt the multimedia stream data to be transmitted based on the supplier ID to obtain encrypted information;
[0115] A data packet transmission module 73, configured to encapsulate the supplier ID and the encrypted information according to the improved supplier-specific format to form a data packet to be transmitted and transmit it, where the improved supplier-specific format includes an encrypted payload structure.
[0116] The technical solution of the embodiment of the present invention is as follows: acquire the multimedia stream data to be transmitted and the supplier ID; encrypt the multimedia stream data to be transmitted based on the supplier ID to obtain encrypted information; encapsulate the supplier ID and the encrypted information according to the improved supplier-specific format to form a data packet to be transmitted and transmit it, and the improved supplier-specific format includes an encrypted payload structure. By adding the encrypted payload structure to the improved supplier-specific format, a dynamic encryption key is generated using the supplier ID to encrypt the data stream to be transmitted and encapsulate it into an encrypted data packet to be transmitted. The security of the data stream is enhanced, and the encryption of the stream data can be achieved without an additional security layer. Different improved supplier-specific formats can be configured for different suppliers to meet the requirements of various applications, while promoting market innovation and competitive advantages.
[0117] Further, the data encryption module 72 is specifically configured to:
[0118] Read the multimedia stream data to be transmitted in units of data blocks to obtain data blocks to be encrypted;
[0119] Derive a derived key of a set number of bytes from the supplier ID through an encryption hash function, and randomly generate a unique initialization vector;
[0120] Encrypt each data block to be encrypted through an encryption algorithm, the derived key, and the unique initialization vector to obtain encrypted data;
[0121] Authenticate the encrypted data to generate an authentication tag, and use the unique initialization vector, the authentication tag, and the encrypted data as encrypted information.
[0122] Further, the improved vendor-specific format includes: subtype data bits, stream ID bits, protocol timestamp bits, format specification bits, encapsulation information bits, and an encrypted payload structure.
[0123] Further, the data packet transmission module 73 is specifically configured to:
[0124] Obtain the transmission configuration information of the multimedia stream data to be transmitted;
[0125] According to the improved vendor-specific format, write the vendor ID, the protocol format subtype, the stream ID, and the timestamp in the transmission configuration information to the specified positions of the data packet to be transmitted;
[0126] Determine the payload length of the encrypted data in the encrypted information and write it to the length position in the encrypted payload structure;
[0127] Write the unique initialization vector in the encrypted information to the header position in the encrypted payload structure;
[0128] Write the encrypted data in the encrypted information to the encrypted payload position in the encrypted payload structure;
[0129] Write the authentication tag in the encrypted information to the end position in the encrypted payload structure to obtain the encapsulated data packet to be transmitted.
[0130] Optionally, the device further includes:
[0131] A data decryption module, configured to obtain the multimedia stream data to be decrypted and decrypt the multimedia stream data to be decrypted according to the improved vendor-specific format to obtain decrypted data.
[0132] Further, the data decryption module is specifically configured to:
[0133] Read the stream data length of the multimedia stream data to be decrypted;
[0134] Derive the media access control address of the vendor from the multimedia stream data to be decrypted according to the improved vendor-specific format;
[0135] Derive a decryption key of a set number of bytes from the media access control address through an encryption hash function;
[0136] Read the decryption unique initialization vector from the head position of the encrypted payload structure of the multimedia stream data to be decrypted according to the improved vendor-specific format;
[0137] Read the ciphertext data from the encrypted payload structure according to the stream data length, and decrypt the ciphertext data by using the decryption unique initialization vector and the decryption key to obtain intermediate decrypted data;
[0138] Verify the integrity of the intermediate decrypted data through the authentication tag at the tail position of the encrypted payload structure, and use the complete intermediate decrypted data as the final decrypted data.
[0139] Optionally, the device further includes:
[0140] A data display module, configured to read the data format and protocol format subtype from the multimedia stream data to be decrypted according to the improved vendor-specific format after decrypting the multimedia stream data to be decrypted according to the improved vendor-specific format, and transmit the data format, the format subtype, and the decrypted data to a media framework for display.
[0141] The secure transmission device for multimedia data provided by an embodiment of the present invention can execute the secure transmission method for multimedia data provided by any embodiment of the present invention, and has function modules and beneficial effects corresponding to the execution of the method.
[0142] Embodiment 4
[0143] Figure 8 FIG. shows a schematic structural diagram of an electronic device 80 that can be used to implement an embodiment of the present invention. The electronic device is intended to represent various forms of digital computers, such as, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, a personal digital processor, a cellular phone, a smart phone, a wearable device (such as a helmet, glasses, a watch, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are only examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0144] Such as Figure 8As shown, the electronic device 80 includes at least one processor 81 and a memory communicatively connected to the at least one processor 81, such as a read-only memory (ROM) 82, a random access memory (RAM) 83, etc. The memory stores a computer program executable by the at least one processor. The processor 81 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 82 or the computer program loaded from the storage unit 88 into the random access memory (RAM) 83. In the RAM 83, various programs and data required for the operation of the electronic device 80 can also be stored. The processor 81, the ROM 82, and the RAM 83 are connected to each other via a bus 84. The input / output (I / O) interface 85 is also connected to the bus 84.
[0145] Multiple components in the electronic device 80 are connected to the I / O interface 85, including: an input unit 86, such as a keyboard, a mouse, etc.; an output unit 87, such as various types of displays, speakers, etc.; a storage unit 88, such as a disk, an optical disc, etc.; and a communication unit 89, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 89 allows the electronic device 80 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0146] The processor 81 can be various general-purpose and / or dedicated processing components with processing and computing capabilities. Some examples of the processor 81 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 81 executes the various methods and processes described above, such as the secure transmission method of multimedia data.
[0147] In some embodiments, the secure transmission method of multimedia data can be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as the storage unit 88. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 80 via the ROM 82 and / or the communication unit 89. When the computer program is loaded into the RAM 83 and executed by the processor 81, one or more steps of the secure transmission method of multimedia data described above can be executed. Alternatively, in other embodiments, the processor 81 can be configured to execute the secure transmission method of multimedia data in any other appropriate way (e.g., by means of firmware).
[0148] The various embodiments of the systems and techniques described above in this specification can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which may be a special-purpose or general-purpose programmable processor that receives data and instructions from, and transmits data and instructions to, a storage system, at least one input device, and at least one output device.
[0149] The computer programs for implementing the methods of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the computer programs, when executed by the processor, cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The computer programs can be executed entirely on the machine, partly on the machine, as a stand-alone software package partly on the machine and partly on a remote machine or entirely on the remote machine or server.
[0150] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0151] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) through which the user can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).
[0152] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.
[0153] The computing system can include a client and a server. The client and the server are generally remote from each other and typically interact through a communication network. The relationship between the client and the server is created by computer programs that run on the respective computers and have a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, solving the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0154] In one embodiment, the embodiment of the present invention further includes a computer program product, which includes a computer program that, when executed by a processor, implements the secure transmission method of multimedia data in any embodiment of the present invention.
[0155] In the process of implementing the computer program product, computer program code for performing the operations of the present invention can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network - including a local area network (LAN) or a wide area network (WAN) - or, alternatively, can be connected to an external computer (e.g., by connecting through the Internet using an Internet service provider).
[0156] It should be understood that various forms of the processes shown above can be used, steps can be reordered, added, or deleted. For example, the steps described in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitations are imposed herein.
[0157] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.
Claims
1. A secure transmission method for multimedia data, characterized in that Includes: Obtain the multimedia stream data to be transmitted and the supplier ID; Perform encryption processing on the multimedia stream data to be transmitted based on the supplier ID to obtain encrypted information; Encapsulate the supplier ID and the encrypted information according to the improved supplier-specific format to form a data packet to be transmitted and transmit it, where the improved supplier-specific format includes an encrypted payload structure.
2. The method according to claim 1, wherein The performing encryption processing on the multimedia stream data to be transmitted based on the supplier ID to obtain encrypted information includes: Read the multimedia stream data to be transmitted in units of data blocks to obtain data blocks to be encrypted; Derive a derived key of a set number of bytes from the supplier ID through an encryption hash function, and randomly generate a unique initialization vector; Encrypt each data block to be encrypted through an encryption algorithm, the derived key, and the unique initialization vector to obtain encrypted data; Authenticate the encrypted data to generate an authentication tag, and use the unique initialization vector, the authentication tag, and the encrypted data as encrypted information.
3. The method according to claim 1, characterized in that The improved supplier-specific format includes: subtype data bits, stream ID bits, protocol timestamp bits, format specification bits, encapsulation information bits, and an encrypted payload structure.
4. The method according to claim 1, wherein The encapsulating the supplier ID and the encrypted information according to the improved supplier-specific format to form a data packet to be transmitted and transmit it includes: Obtain the transmission configuration information of the multimedia stream data to be transmitted; Write the supplier ID, the protocol format subtype, the stream ID, and the timestamp in the transmission configuration information to the specified positions of the data packet to be transmitted according to the improved supplier-specific format; Determine the payload length of the encrypted data in the encrypted information and write it to the length position in the encrypted payload structure; Write the unique initialization vector in the encrypted information to the header position in the encrypted payload structure; Write the encrypted data in the encrypted information to the encrypted payload position in the encrypted payload structure; Write the authentication tag in the encrypted information to the end position in the encrypted payload structure to obtain the encapsulated data packet to be transmitted.
5. The method according to claim 1, characterized in that, Also includes: Obtain the multimedia stream data to be decrypted, and decrypt the multimedia stream data to be decrypted according to the improved supplier-specific format to obtain decrypted data.
6. The method according to claim 5, wherein The decrypting the multimedia stream data to be decrypted according to the improved supplier-specific format to obtain decrypted data includes: Read the stream data length of the multimedia stream data to be decrypted; Derive the media access control address of the supplier from the multimedia stream data to be decrypted according to the improved supplier-specific format; Derive a decryption key of a set number of bytes from the media access control address through an encryption hash function; Read the decryption unique initialization vector from the header position of the encrypted payload structure of the multimedia stream data to be decrypted according to the improved supplier-specific format; Read the ciphertext data from the encrypted payload structure according to the stream data length, and decrypt the ciphertext data through the decryption unique initialization vector and the decryption key to obtain intermediate decrypted data; Verify the integrity of the intermediate decrypted data through the authentication tag at the tail position of the encrypted payload structure, and use the complete intermediate decrypted data as the final decrypted data.
7. The method according to claim 5, characterized in that, After decrypting the multimedia stream data to be decrypted according to the improved vendor-specific format to obtain the decrypted data, it further includes: Read the data format and protocol format subtype from the multimedia stream data to be decrypted according to the improved vendor-specific format, and transmit the data format, the format subtype, and the decrypted data to the media framework for display.
8. A secure transmission device for multimedia data, characterized in that, It includes: An information acquisition module for acquiring multimedia stream data to be transmitted and a vendor ID; A data encryption module for encrypting the multimedia stream data to be transmitted based on the vendor ID to obtain encrypted information; A data packet transmission module for encapsulating the vendor ID and the encrypted information according to the improved vendor-specific format to form a data packet to be transmitted and transmitting it, where the improved vendor-specific format includes an encrypted payload structure.
9. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the secure transmission method of multimedia data according to any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing a processor to implement the secure transmission method of multimedia data according to any one of claims 1-7 when executed.
11. A computer program product, characterized in that, The computer program product includes a computer program that implements the secure transmission method of multimedia data according to any one of claims 1-7 when executed by a processor.
Citation Information
Cited By
Video data encryption storage method and device, encrypted video playback method and device, and camera device
CN120856932A