Method and system for coupling data sequences, and method and apparatus for verifying coupling thereof
By combining secret numbers and abstracts in the monitoring system, the verification problem of time correlation of data sequences in the video surveillance system is solved, ensuring that data sequences are captured at the same time, preventing tampering, and allowing the use of data sequences alone as evidence.
Patent Information
- Application Number
- CN202510041368.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-01-17
- Filing Date
- 2025-01-10
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-01-10
AI Technical Summary
In a video surveillance system, it is not possible to ensure that the data sequences generated by different devices are timely related, especially when an event occurs, the audio data sequence may be tampered with, resulting in the inability to verify whether the video data sequence and the audio data sequence are captured at the same time.
Coupling and verification of the data sequence is achieved by merging the first secret number and the digital signature in the first data sequence and merging the digest generated based on the secret number in the second data sequence.
Ensure that data sequences are temporally correlated, prevent tampering, and allow individual data sequences to be used as evidence even if another data sequence is lost.
Smart Images

Figure CN120342622A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to methods and systems for coupling a first data sequence and a second data sequence to each other, and to methods and apparatuses for verifying that the first data sequence and the second data sequence are coupled to each other. In particular, the present invention relates to coupling data sequences that are temporally related to each other and verifying the coupling of these data sequences. Background Art
[0002] During the monitoring of a scene using a video surveillance system, multiple data sequences including data related to the monitored scene are generated. The data sequences may be generated by one or more cameras and / or one or more microphone devices included in the video surveillance system and configured to capture video and / or sound from the scene. Thus, the data sequences may be video sequences including video data having images of the scene, audio sequences including audio data having sounds emitted from the scene or its surroundings, or metadata sequences including metadata having information related to the scene. Each of the data sequences is captured within a corresponding time period, and the time periods of two or more data sequences may at least partially overlap, resulting in at least two data sequences being temporally related to each other.
[0003] In the case of an event such as a crime or an accident such as a car crash occurring in a monitored scene, it may be useful to investigate the recorded data sequences generated at the time of the event / accident to summarize what happened in the scene before, during, and after the event / accident. However, when the data sequences are generated by different parts of the surveillance system, there is no guarantee that the data sequences claimed to be captured at the time of the event / accident were captured at that time. Thus, the audio data of an audio data sequence claimed to be captured simultaneously with the video data of a video data sequence may not at all reflect the sounds of the scene when the video data was captured. For example, the audio data sequence may have been tampered with to change its recording time from the actual real time to another false time. Thus, there is no guarantee that two data sequences generated by two different parts of the surveillance system and claimed to be captured simultaneously were captured simultaneously. Thus, it cannot be guaranteed that these two data sequences are temporally related. Furthermore, if only another data sequence is provided as circumstantial evidence in an event / accident investigation, there is no guarantee that a data sequence generated by one part of the surveillance system and temporally related to another data sequence generated by another part will be considered lost. Thus, if a data sequence including only video data (without sound) is provided as evidence instead of a temporally related data sequence including audio data, it is undetectable, and thus the loss of the sound (contained in the temporally related data sequence including audio data) captured from the event / accident cannot be detected.
[0004] Digital signature schemes for digitally signing data sequences are known. By digitally signing a data sequence, the authenticity of the data sequence can be verified. Nevertheless, when data sequences from the same monitored or captured scene are used as evidence, it may not be sufficient to merely prove that each data sequence is individually authentic. It may also be necessary to prove that the data sequences were captured at the same time and in the same location. Accordingly, a convenient and secure method is needed to couple data sequences that are related in time to each other, such that it can be proven that the data sequences are authentic and originate from the same captured scene, and were captured during at least partially overlapping time periods. Summary of the Invention
[0005] In view of the above, it is therefore an object of the present invention to mitigate the disadvantages of the prior art and to provide techniques for coupling a first data sequence and a second data sequence that are related to each other in time, such that it is possible to verify the coupling of the first data sequence and the second data sequence. Another object is to provide techniques for verifying the coupling of the first data sequence and the second data sequence with each other.
[0006] According to a first aspect of the present invention, the above object is achieved by a method for coupling a first data sequence and a second data sequence that are related to each other in time, such that it is possible to verify the coupling of the first data sequence and the second data sequence. The method includes: processing, by a first processing device, a first data sequence captured during a first time period:
[0007] generating a first digital signature of the first data sequence based on first data of the first data sequence and based on a first secret number;
[0008] combining the first secret number and the first digital signature into the first data sequence; and
[0009] transmitting the first data sequence. The method further includes: processing, by a second processing device, a second data sequence captured during a second time period that at least partially overlaps with the first time period:
[0010] generating a second digital signature of the second data sequence based on second data of the second data sequence and based on a first digest, wherein the first digest is generated based on the first secret number;
[0011] combining the generated second digital signature and the first digest into the second data sequence, whereby the first data sequence and the second data sequence are coupled by the first secret number and the first digest; and
[0012] transmitting the second data sequence.
[0013] The first data sequence and the second data sequence are coupled to each other by incorporating a first secret number into the first data sequence and by incorporating a first digest into the second data sequence. If the receiver receives only one of the data sequences, the receiver can infer from the first secret number or the first digest included in the received data sequence that the received data sequence may be coupled to the other data sequence, i.e., it may be temporally related to the other data sequence and that other data sequence is lost or at least not yet received by the receiver, e.g., inadvertently due to a delay or interruption caused by network congestion, or deliberately due to a transmission pause. Further, if both the first data sequence and the second data sequence are received, the receiver can use the received first secret number and the received first digest (generated based on the first secret number) to verify that the first data sequence and the second data sequence are coupled to each other and thus temporally related to each other. If the receiver is to receive the first data sequence and another data sequence claimed to be coupled to the first data sequence but including another digest that is not generated based on the first secret number or is not generated using the correct cryptographic one-way function, the receiver will not be able to verify the coupling of the data sequences and thus the receiver will understand that the claim is incorrect.
[0014] The first data sequence and the second data sequence can be authenticated independently of each other by incorporating a first digital signature into the first data sequence and by incorporating a second digital signature into the second data sequence. Thus, if only the first data sequence is available, it can be authenticated without the need for the presence of the second data sequence. Thus, even if the second data sequence that is temporally related is not available, the first data sequence can be used as evidence after verifying its authenticity. If the first data sequence is lost, the same is true for the second data sequence.
[0015] As used herein, the term "coupled" shall be understood to provide a corresponding link for a data sequence, which link can be used as an indication of the possible existence of temporally related data sequences and for verifying that two data sequences are temporally related. The first secret number provided to the first data sequence is an example of a first link indicating the possible existence of temporally related data sequences, and the second digest provided to the second data sequence is an example of a second link indicating the possible existence of temporally related data sequences. The reason for this is that the first processing device and the second processing device are set to generate their respective identical first secret numbers synchronously in time. Then, the first processing device includes its first secret number in the first data sequence, and the second processing device generates a first digest based on its first secret number and includes the first digest in the second data sequence. If only one data sequence pair provided with a link (i.e., secret number / digest) is available to the receiver, the presence of the link in the data sequence will indicate to the receiver the possible existence of a temporally related data sequence. This means that, for example, if a video data sequence provided with a link is received, the receiver can infer that there may be a temporally related data sequence that has been lost for some reason. The temporally related data sequence can be a metadata sequence, an audio data sequence, or another video data sequence captured by another part of the monitoring system during a time period that at least partially overlaps with the capture time period of the received video data sequence. Additionally, the first link and the second link can be used to verify whether the first data sequence and the second data sequence are temporally related. Thus, when their respective links verify that they are coupled, the two data sequences are coupled to each other and are thus temporally related to each other. The two data sequences can also be said to be interconnected or interlinked.
[0016] As used herein, the expression "data sequence" shall be understood as a sequence or data stream of data, where the data can be image data, video data, audio data, or metadata, to name just a few examples. Other examples include radar data, lidar data, and sonar data. Sometimes a data sequence includes one type of data, but it can also include a combination of several types of data. For example, a data sequence can include only video data or only metadata, but a data sequence can also include both video data and metadata. The expressions "first data" and "second data" refer to the data contained in the first data sequence and the second data sequence, respectively.
[0017] As used herein, the expression "temporally related" or a similar expression shall be understood to mean that two or more data sequences are temporally related and are thus recorded, collected, or created during at least partially overlapping time periods. In other words, if the first data sequence is captured during a first time period that at least partially overlaps with a second time period during which the second data sequence is captured, the first data sequence and the second data sequence can be said to be temporally related.
[0018] The term "digest" as used in this disclosure shall be understood as the output resulting from applying a one-way cryptographic function to the input. A one-way cryptographic function may also be referred to as a cryptographic digest algorithm. For example, a first digest may be obtained by applying a one-way cryptographic function to a first secret number. In other words, the first digest can be said to be generated based on the first secret number. The cryptographic digest algorithm may be a cryptographic hash algorithm. Using a cryptographic hash algorithm on hashed data is a well-known method for creating a digest. A digest may also be referred to as a hash digest, hash, (digital) fingerprint, message digest, checksum, to name just a few examples. Thus, the terms digest, hash digest, hash, (digital) fingerprint, message digest, and checksum may be used interchangeably.
[0019] According to a second aspect of the present invention, the above object is achieved by a method for verifying that a first data sequence and a second data sequence are coupled to each other. The method includes:
[0020] obtaining a first data sequence including first data, a first secret number, and a first digital signature;
[0021] obtaining a second data sequence including second data, a first digest of the first secret number, and a second digital signature;
[0022] verifying the first digital signature;
[0023] verifying the second digital signature;
[0024] generating a second first digest based on the first secret number; and
[0025] verifying that the first data sequence and the second data sequence are coupled to each other when the first digital signature and the second digital signature have been verified and when the generated second first digest matches the first digest.
[0026] According to a third aspect of the present invention, the above object is achieved by a coupling system for coupling a first data sequence and a second data sequence that are related to each other in time to enable verification that the first data sequence is coupled to the second data sequence. The system includes:
[0027] a first processing device configured to process a first data sequence captured during a first time period and further configured to:
[0028] generate a first digital signature of the first data sequence based on the first data of the first data sequence and based on the first secret number;
[0029] merge the first secret number and the first digital signature into the first data sequence; and
[0030] send the first data sequence; and
[0031] A second processing device, configured to process a second data sequence captured within a second time period that at least partially overlaps with the first time period, and further configured to:
[0032] Generate a second digital signature of the second data sequence based on the second data of the second data sequence and based on the first digest, wherein the first digest is generated based on a first secret digit;
[0033] Merge the second digital signature and the first digest into the second data sequence, whereby the first data sequence and the second data sequence are coupled by the first secret digit and the first digest; and
[0034] Transmit the second data sequence.
[0035] According to a fourth aspect of the present invention, the above object is achieved by a verification device configured to verify that a first data sequence and a second data sequence are coupled to each other. The verification device is configured to:
[0036] Obtain a first data sequence including first data, a first secret digit, and a first digital signature;
[0037] Obtain a second data sequence including second data, a first digest of the first secret digit, and a second digital signature;
[0038] Verify the first digital signature;
[0039] Verify the second digital signature;
[0040] Generate a second first digest based on the first secret digit; and
[0041] Verify that the first data sequence and the second data sequence are coupled to each other when the first digital signature and the second digital signature have been verified and when the generated second first digest matches the first digest.
[0042] According to a fifth aspect of the present invention, the above object is achieved by a non-transitory computer-readable medium storing computer code instructions adapted to perform the method of the first aspect when executed by a device having processing capabilities.
[0043] According to a sixth aspect of the present invention, the above object is achieved by a non-transitory computer-readable medium storing computer code instructions adapted to perform the method of the second aspect when executed by a device having processing capabilities.
[0044] The second, third, fourth, fifth, and sixth aspects generally may have the same features and advantages as the first aspect.
[0045] Embodiments of the present invention are defined in the dependent claims. It should also be noted that, unless otherwise explicitly stated, the present invention relates to all possible combinations of the features disclosed herein. Therefore, it should be understood that the present invention is not limited to the specific components of the described systems and devices or the steps of the described methods, as such systems, devices, and methods may vary. It should also be understood that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting. It must be noted that the articles "a", "an", "the", and "said" used in the specification and the appended claims are intended to mean that there is one or more elements, unless the context clearly dictates otherwise. Thus, for example, a reference to "an object" or "the object" may include a plurality of objects, and so on. In addition, the term "comprising" does not exclude other elements or steps. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] The present invention will be described in more detail by way of example and with reference to the accompanying drawings, in which:
[0047] Figure 1 An exemplary environment in which embodiments are implemented is schematically illustrated.
[0048] Figure 2 A monitoring system according to an embodiment is schematically illustrated.
[0049] Figure 3A is a flowchart of a method for coupling a first data sequence and a second data sequence that are related to each other in time according to an embodiment.
[0050] Figure 3B The generation of an exemplary first data sequence and a first digital signature is schematically illustrated.
[0051] Figure 4 is a flowchart of a method for verifying that a first data sequence and a second data sequence are coupled to each other according to an embodiment.
[0052] Figure 5 A coupling system for coupling a first data sequence and a second data sequence that are related to each other in time according to an embodiment is schematically illustrated.
[0053] Figure 6 A verification device for verifying that a first data sequence and a second data sequence are coupled to each other according to an embodiment is schematically illustrated. DETAILED DESCRIPTION
[0054] The present invention will be described more fully hereinafter with reference to the accompanying drawings, in which embodiments of the invention are shown and like reference numerals are used for like elements.
[0055] Figure 1An exemplary environment in which various embodiments of the present invention can be implemented is shown. As illustrated, the exemplary environment is a portion of a city, including a river, a road spanning the river, a parking lot, buildings, sidewalks, stairs, and a grass lawn with trees. Additionally, a car accident, misparked cars, a crowd, and a liquid flowing into the river are illustrated. Figure 1 A monitoring system 100 including a plurality of devices is also shown. For example, by way of illustration only, the monitoring system 100 may include a monitoring camera 102, a microphone device 104, a fire sensor 106, a door station 108, and / or a fluid sensor 110. Other examples of devices that may be included in the monitoring system are radar, lidar, sonar, and / or GPS devices, which are configured to provide radar data (e.g., radar point cloud), lidar data (such as, lidar point cloud), sonar data, and / or analysis metadata. It should be understood that several of the devices included in the monitoring system 100 may be integrated into a single unit. For example, the microphone device may be integrated into the monitoring camera 102, and the door station 108 may include a camera, a microphone device, and a speaker. The monitoring system 100 may also include or be connected to a client 120, such as a video management system. In Figure 1 which, the client 120 is illustrated as including a monitoring station 122 having a plurality of display devices 124 for presenting corresponding data sequences, such as corresponding video data sequences of the monitored scene. An operator 126 of the monitoring station 122 is also illustrated.
[0056] Each of one or more devices included in the monitoring system 100 is configured to perform monitoring in the environment so as to monitor the objects present in the environment and the events occurring. For example, the monitoring camera 102 is configured to capture images and / or videos of a portion of the environment covered by the camera's field of view. In the illustrated example, the monitoring camera 102 may, for example, have a field of view suitable for capturing images / videos of the road, the riverbank, and / or the sidewalk, and thus may also capture images / videos of car accidents, fluid leaks, and / or crowds. The microphone device 104 may be positioned to capture sounds from the monitored environment. Thus, the microphone device 104 may record sounds from car accidents and people in the crowd.
[0057] The monitoring camera 102 may also be referred to as a surveillance camera. The camera may be a fixed camera, such as a stationary camera, or a movable camera, such as a pan-tilt-zoom (PTZ) camera. Additionally, the camera 102 may be a visible light camera, a thermal imager, or a camera including both a visible light camera and a thermal imager.
[0058] As Figure 2Schematically illustrated, the various parts of the monitoring system 100 can be communicatively connected via a communication network 130. Accordingly, the monitoring camera 102, the microphone device 104, the fire sensor 106, the door station 108, and the fluid sensor 110 can be connected to each other and to one or more other devices connected to the communication network 130, such as the client 120, the server 140, and / or a cloud service 150 such as cloud computing (e.g., cloud storage and / or cloud computing capabilities / resources). Communication between the devices via the communication network 130 can be performed via wired and / or wireless connections. A data sequence captured by one or more of the monitoring camera 102, the microphone device 104, the fire sensor 106, the door station 108, and / or the fluid sensor 110 can be stored and / or processed in the server 140. Generally, the client 120 is also connected to the server 140, and the client 120 and / or the server 140 can be connected to the cloud service 150. The client 120 can be used to control one or more of the monitoring camera 102, the microphone device 104, the fire sensor 106, the door station 108, and / or the fluid sensor 110, for example, by an operator issuing a control command at the monitoring station 122.
[0059] Reference will now be made to Figure 3A the flowchart and the schematic diagram of Figure 5 a coupling system 500 for coupling a first data sequence and a second data sequence that are temporally related to each other, and a block diagram of
[0060] a method for coupling a first data sequence and a second data sequence that are temporally related to each other to enable verification of the coupling of the first data sequence and the second data sequence. It should also be understood that some actions may be optional and that the actions may be performed in another suitable order.
[0061] As described above, the method can be performed by different parts of the monitoring system 100, such as by different monitoring cameras 102, by one monitoring camera 102 and one microphone device 104, or by different parts of a single device, such as by different parts of a single monitoring camera 102 (including, for example, the microphone device 104). It should be understood that the different parts of a single monitoring camera 102 can be different parts that process the same type of data sequence, such as different parts that process different video sequences. Thus, the parts of the coupling system 500 can be implemented in different parts of the monitoring system 100. The first processing device 510 is implemented in a first part of the monitoring system 100 that captures the first data sequence DS1, and the second processing device 520 is implemented in a second part different from the first part of the monitoring system 100 that captures the second data sequence DS2. For example, the first processing device 510 can be implemented in the monitoring camera 102, and the second processing device 520 can be implemented in the microphone device 104. As another example, in the case where the monitoring camera 102 is capable of generating two types of data sequences (e.g., a video data sequence and an audio data sequence), the first processing device 510 can be implemented in the part of the monitoring camera 102 that is capable of generating the video data sequence, and the second processing device 520 can be implemented in the part of the monitoring camera 102 that is capable of generating the audio data sequence.
[0062] It should be noted that capturing an audio sequence of the monitored or captured scene that is the same as the video sequence can well capture sounds from outside the field of view of the camera that captures the video sequence. For example, a microphone device arranged inside or near the camera can capture the voices of people inside and outside the camera's field of view, or the sound of breaking a window in front of, above, or behind the camera. These sounds will all be regarded as belonging to the same monitored or captured scene as the sounds within the camera's field of view.
[0063] In order to be able to authenticate the data sequences generated by different parts of the monitoring system 100, a digital signature is generated for each data sequence and incorporated into its (own) data sequence. In addition, in order to couple (link) data sequences that are temporally related, i.e., sequences captured within at least partially overlapping time periods, the digital signature of each data sequence is generated based on the corresponding link, as described below.
[0064] In action 302, based on the first data data1 of the first data sequence DS1 and based on the first secret digit SN1, the first digital signature DSIGN1 of the first data sequence DS1 is generated. Action 302 is performed by the first processing device 510, which processes the first data sequence DS1 captured within the first time period.
[0065] The first data, data1, can be video data including one or more image frames, audio data including one or more audio frames, and / or metadata including information related to a data sequence or a scene. An audio frame includes multiple audio samples of multiple audio channels captured within a period of time.
[0066] Use a cryptographically secure number (CSN) generator 515 to generate a first secret number SN1 based on a seed value. The cryptographically secure number generator 515 is included in the first processing device 510. The seed value used by the first processing device 510 can be referred to as the first seed value, and the cryptographically secure number generator 515 included in the first processing device 510 can be referred to as the first cryptographically secure number generator. The seed value can be a pseudo-random number generated by sampling an entropy source. In addition, the cryptographically secure number generator can be a true random number generator (TRNG), a full-entropy seeded pseudo-random number generator (PRNG), a cryptographically secure pseudo-random number generator (CSPRNG), or a cryptographic pseudo-random number generator (CPRNG). The full-entropy seeded pseudo-random number generator (PRNG) can be seeded with sufficient entropy from an entropy source such as a TRNG output, energy entropy harvesting, network entropy harvesting, lava lamp entropy harvesting, etc., just to name a few examples.
[0067] The generated first secret number SN1 can be a one-time password (OTP), such as a time-based OTP (TOTP). The first secret number SN1 can be obtained by applying a hash function to the seed value and the time (e.g., the current system time) or a counter. Therefore, the generated first secret number SN1 can only be used within a limited time period, thus preventing it from being misused by another part of the monitoring system if it is leaked or retrieved for some reason. The limited time period can be in the range of one-tenth of a second, a second, or dozens of seconds. Once the limited time period expires, a new first secret number SN1 is generated, and this new first secret number SN1 can be used within the limited time period (a new instance). Therefore, it can be said that each instance of the first secret number SN1 is valid during the corresponding instance of the limited time period.
[0068] In some embodiments, a first digital signature DSIGN1 is generated by applying a first cryptographic digital signature algorithm to first data data1 and a first secret number SN1. The first cryptographic digital signature algorithm may be based on public-key cryptography, sometimes referred to as asymmetric cryptography, whereby a first processing device 510 uses the private key of its encryption key pair and the message, i.e., the first data data1 and the first secret number SN1, to create the first digital signature DSIGN1. A receiver having the corresponding public key of the key pair and receiving the message and the first digital signature DSIGN1 may verify whether the first digital signature DSIGN1 matches the message, i.e., whether the first data data1 and the first secret number SN1 match, thereby verifying the authenticity of the message.
[0069] In some embodiments, the first device 510 and the second device 520 may exchange their respective unique identifiers or corresponding digests of their respective unique identifiers. This may occur when the first processing device 510 and the second processing device 520 are manufactured by different manufacturers, as well as when they are manufactured by the same manufacturer to provide additional anti-fraud security. The unique identifier may be a digital certificate for encryption or the public key of the encryption key pair of the corresponding processing device. The digest of the unique identifier may be obtained by the first processing device 510 and the second processing device 520 applying a (first / second) cryptographic digest algorithm to their unique identifiers. By exchanging the unique identifier or its digest, the first processing device 510 may include the unique identifier or its digest of the second processing device in the first data sequence DS1, and the second processing device 520 may include the unique identifier or its digest of the first processing device in the second data sequence DS2. Thus, the receiver of the first data sequence DS1 will obtain the unique identifier or its digest of the second processing device, and the receiver of the second data sequence DS2 will also obtain the unique identifier or its digest of the first processing device. By the received unique identifier or its digest, the receiver can verify whether the two processing devices claiming to send data sequences purported to be coupled to each other are the actual sending processing devices. Thus, if a fraudulent processing device can copy the content of the first data sequence DS1 sent by the first processing device, i.e., the unique identifier (or its digest) of the second processing device 520, the first digital signature DSIGN1, the first secret number SN1, and the first data data1, and create a fraudulent data sequence including the copied content, the receiver of the fraudulent data sequence (purported to be the first data sequence DS1) and the second data sequence DS2 can infer that the fraudulent processing device is not the actual sender, because the unique identifier (or its digest) of the first processing device included in the second data sequence DS2 does not match the unique identifier of the fraudulent processing device. It should be understood that such an exchange of unique identifiers or their digests may occur between any number of processing devices operating in the monitoring system 100.
[0070] To ensure that each instance of the first secret number SN1 is used at least once within its valid time period to generate at least one first digital signature DSIGN1 of the first data sequence DS1, instances of the first digital signature DSIGN1 are generated more frequently than instances of the first secret number SN1, and each instance of the first digital signature DSIGN1 is generated based on a valid instance of the first secret number SN1. Thus, there will always be at least one first data sequence DS1 including the first digital signature DSIGN1 based on the generated first secret number SN1, and this first secret number SN1 can be used to verify a second data sequence DS2 including a first digest digest1 (generated by another device based on the first secret number SN1) coupled to the first data sequence DS1. Therefore, the first digital signature DSIGN1 is generated more frequently than the first secret number SN1. For example, assuming that the limited time period for the validity of the above first secret number SN1 is 10 seconds and the first digital signature DSIGN1 is generated once per second, an instance of the first digital signature DSIGN1 can be generated per second, and thus ten instances of the first digital signature DSIGN1 can be generated for the first data sequence DS1 using the same first secret number SN1. However, it should be understood that the instances of the first digital signature DSIGN1 may be different because they are generated based on possibly different instances of the first data data1. Figure 3B Schematically shows an exemplary first data sequence DS1 including a plurality of first data data1, data1-1, data1-2, …, data1-20. At time point t = 0s, the first secret numbers SN1, SN1-1 have been generated. The first secret numbers SN1, SN1-1 are used to generate the first digital signatures DSIGN1, DSIGN1-1, …, DSIGN1-10 of the first data data1, data1-1, …, data1-10 within a limited time period of 10 seconds. When this time period expires, new first secret numbers SN1, SN1-2 are generated. The new first secret numbers SN1, SN1-2 are used to generate the first digital signatures DSIGN1, DSIGN1-11, …, DSIGN1-20 of the first data data1, data1-11, …, data1-20 within a limited time period of 10 seconds. Then, at the time point t = 20s, new first secret numbers SN1, SN1-3 are generated again, and they are used to generate subsequent digital signatures within the limited time period.
[0071] To be able to verify that the second data sequence DS2 is related to the first data sequence DS1 in time and digitally sign the first data sequence DS1, in operation 304, the first secret number SN1 and the first digital signature DSIGN1 are incorporated into the first data sequence DS1.
[0072] The action of generating the first digital signature DSIGN1 and incorporating the generated first digital signature DSIGN1 into the first data sequence DS1 can be referred to as digitally signing the first data sequence DS1. The digital signature of the data sequence by the transmitter enables the receiver to authenticate the data sequence as coming from the transmitter. Further, by also generating the digital signature based on the secret digit as a link and by incorporating the secret digit into the data sequence, the receiver can authenticate the data sequence and indicate that there may be another temporally related data sequence.
[0073] In action 306, the first data sequence DS1 is transmitted. The first data sequence DS1 is transmitted to a receiver, such as to client 120, or to a storage device, such as server 140 or cloud service 150, where the first data sequence DS1 is stored before being provided to the verification device 600. The verification device 600 will be described in more detail below.
[0074] The second processing device 520 is processing a second data sequence DS2 captured during a second time period that at least partially overlaps with the first time period. To digitally sign the second data sequence DS2 and enable verification that the second data sequence DS2 is temporally related to another data sequence, the second processing device 520 generates a second digital signature DSIGN2 of the second data sequence DS2 based on the second data data2 of the second data sequence DS2 and based on the first digest digest1. The first digest digest1 is generated based on the first secret digit SN1. The first digest digest1 generated based on the first secret digit SN1 can be obtained by the second processing device 520 applying a first cryptographic digest algorithm to the first secret digit SN1.
[0075] The second processing device 520 may have received the first secret number SN1 and information about in which time period (e.g., a second time period that at least partially overlaps with the first time period) the first secret number SN1 should be used to generate the first digest digest1. Alternatively, the second processing device 520 may have the same seed value as the cryptographic secure number generator 515 of the first processing device 510 and the same type of cryptographic secure number generator 525, and may also know when (e.g., start time and time interval) to use the cryptographic secure number generator 525 to generate the first secret number SN1 based on the seed value. Once the first secret number SN1 is generated, it can be used to generate the first digest digest1. As described above, the generated first secret number SN1 may only be used within a limited time period, thus preventing it from being misused by another part of, for example, a monitoring system if it is leaked or retrieved from the second processing device 520 for some reason. When the limited time period expires, a new instance of the first secret number SN1 is generated and used for a new instance of the limited time period.
[0076] In some embodiments, the first processing device 510 and the second processing device 520 may have exchanged the seed value and characteristics of the cryptographic secure number generator required to generate the first secret number SN1. As another example, the first processing device 510 and the second processing device 520 may have exchanged / received from the client 120 the seed value and characteristics of the cryptographic secure number generator required to generate the first secret number SN1. Assuming that the clocks of the two processing devices are synchronized, they will be able to generate the same first secret number SN1 within the same time period. Once the second processing device 520 has generated the first secret number SN1, it can use the generated first secret number SN1 within a limited time period to generate the first digest digest1.
[0077] In some embodiments, the second digital signature DSIGN2 is generated by applying a second cryptographic signature algorithm to the second data data2, the first digest digest1, and the second secret number SN2. The first digest digest1 generated based on the first secret number SN1 can be obtained by applying a first cryptographic digest algorithm to the first secret number SN1. As the first cryptographic signature algorithm, the second cryptographic signature algorithm may be based on public-key cryptography, sometimes also referred to as asymmetric cryptography. Thus, the second processing device 520 can use the private key of its encryption key pair and the message, i.e., the second data data2 and the second secret number SN2, to create the second digital signature DSIGN2. A receiver having the corresponding public key of the key pair and receiving the message and the second digital signature DSIGN2 can verify whether the second digital signature DSIGN2 matches the message, i.e., whether the second data data2 and the second secret number SN2 match, thereby verifying the authenticity of the message.
[0078] Due to reasons similar to those described above regarding the frequency at which the first processing device 510 generates the first digital signature DSIGN1 relative to the frequency at which it generates the first secret number SN1, the second processing device 520 generates the second digital signature DSIGN2 more frequently than it generates the first secret number SN1. Additionally, the second digital signature DSIGN2 (and the first digest digest1) may be generated at the same frequency as the first digital signature DSIGN1, or the second digital signature DSIGN2 (and the first digest digest1) may be generated at a frequency different (higher / lower) from the frequency at which the first digital signature DSIGN1 is generated. For example, assuming that the effective finite time period for the above-mentioned first secret number SN1 is 10 seconds and the second digital signature DSIGN2 is generated every three seconds, then instances of the second digital signature DSIGN2 (and the first digest digest1) may be generated every three seconds. Thus, when compared to ten instances of the first digital signature DSIGN1 when the first digital signature DSIGN1 is generated once per second in the above example, three instances of the second digital signature DSIGN2 for generating the second data sequence DS2 are generated using the same first secret number SN1. However, as described above regarding the first digital signature DSIGN1, it should be understood that instances of the second digital signature DSIGN2 may be different because they are generated based on possibly different instances of the second data data2.
[0079] In action 310, the second processing device 520 merges the generated second digital signature DSIGN2 and the first digest digest1 into the second data sequence DS2. Thereby, the first data sequence DS1 and the second data sequence DS2 are coupled by the first secret number SN1 and the first digest digest1. In action 312, the second processing device 520 transmits the second data sequence DS2. Similar to the first data sequence DS1, the second data sequence DS2 is transmitted to a receiver such as the verification device 600 or a storage device such as the server 140 and stored before being provided to the verification device 600.
[0080] Sometimes, in addition to the first digest digest1 included in the generation of the second digital signature DSIGN2 as described above, a digest may also be required to be included when generating the first digital signature DSIGN1. For example, this may occur when two or more data sequences that are related to each other in time should be more closely linked to each other by cross-coupling them. The cross-coupling of the first data sequence and the second data sequence is achieved by providing a link to the data sequences that not only connects the second sequence to the first sequence but also connects the first sequence to the second sequence.
[0081] In these embodiments, the first digital signature DSIGN1 is also generated based on a second digest digest2, which is based on a second secret number SN2. The second secret number SN2 can be generated using a cryptographically secure number generator 515 of the first processing device 510 based on a seed value. The seed value can be the same seed value as the above-mentioned first seed value, or can be a second seed value different from the first seed value. In addition, the cryptographically secure number generator 515 should know when to generate the second secret number SN2. Therefore, the cryptographically secure number generator 515 knows the start time and time interval for generating the second secret number SN2. The seed value can be a pseudo-random number generated by sampling an entropy source. For example, the cryptographically secure number generator 515 can be a true random number generator (TRNG), a full-entropy seeded pseudo-random number generator (PRNG), a cryptographically secure pseudo-random number generator (CSPRNG), or a cryptographic pseudo-random number generator (CPRNG). The full-entropy seeded pseudo-random number generator (PRNG) can be seeded with sufficient entropy from an entropy source such as a TRNG output, energy entropy harvesting, network entropy harvesting, lava lamp entropy harvesting, etc., to name just a few examples.
[0082] In some embodiments, the first processing device 510 and the second processing device 520 may have exchanged the second seed value, start time, time interval, and characteristics of the cryptographically secure number generator required to generate the second secret number SN2. Assuming that the clocks of the two processing devices 510, 520 are synchronized, they will be able to generate the same second secret number SN2 within the same time period. Once the first processing device 510 has generated the second secret number SN2, it can use the second secret number SN2 to generate the second digest digest2.
[0083] In some embodiments, the second secret number SN2 can be a one-time password (OTP), such as a time-based OTP (TOTP). Therefore, the second secret number SN2 may only be usable within a limited time period to prevent its misuse. The limited time period can be the same limited time period as the first secret number SN1, or can be another second limited time period, as long as the limited time period is shorter than the time period for generating the digital signature.
[0084] In addition, the second digest digest2 generated based on the second secret number SN2 can be obtained by the first processing device 510 applying a second cryptographic digest algorithm to the second secret number SN2. The second cryptographic digest algorithm can be the same as the first cryptographic digest algorithm.
[0085] Thus, in some embodiments that include cross - coupling of a first data sequence and a second data sequence, the first processing device 510 can generate a first digital signature DSIGN1 by applying a first cryptographic digital signature algorithm to the first data data1, the first secret number SN1, and the second digest digest2. In such an embodiment, the second processing device 520 also generates a second digital signature DSIGN2 based on the second secret number SN2. Thus, the second digital signature DSIGN2 is generated by applying a second cryptographic digital signature algorithm to the second data data2, the first digest digest1, and the second secret number SN2. Further, in these embodiments, action 304 also includes incorporating the second digest digest2 into the first data sequence DS1, and action 310 also includes incorporating the second secret number SN2 into the second data sequence DS2.
[0086] In cases where more than two data sequences are temporally related, it may be advantageous to cross - couple one or more pairs among two or more temporally related data sequences so that a receiver can verify that at least some pairs of the received data sequences are temporally related, even if the receiver does not receive one or more of the other cross - coupled data sequences.
[0087] Assume that there are three temporally related data sequences, and they are processed by corresponding processing devices. Thus, assume that one of the data sequences is a first data sequence DS1 processed by the first processing device 510, one is a second data sequence DS2 processed by the second processing device 520, and the other is a third data sequence DS3 processed by a third processing device (not shown). Even Figure 5 although only two processing devices are shown, it should be understood that the coupling system 500 can include any number of processing devices as long as the number of processing devices is equal to the number of temporally related data sequences.
[0088] The cross - coupling of the first data sequence DS1 and the second data sequence DS2 is performed as described above.
[0089] In order to also cross-couple the third data sequence DS3 with the first data sequence DS1, the third digest digest3 should be included when generating the first digital signature DSIGN1, and the third digest should also be incorporated into the first data sequence DS1. In the same way as generating the first digest digest1 and the second digest digest2, the third digest digest3 is generated based on the third secret number SN3. Then, the third processing device should generate the third digital signature DSIGN3 of the third data sequence DS3 based on the third data data3 of the third data sequence DS3 and based on the first digest digest1. The first digest digest1 is generated by the third processing device in the same way as the second processing device 520 generates the first digest digest1 based on the first secret number SN1. The third processing device knows the first secret number SN1 or the first seed value in a similar way to the above-mentioned second processing device 520. After that, the third processing device incorporates the generated third digital signature DSIGN3 and the first digest digest1 into the third data sequence DS3. If the second data sequence DS2 is to be coupled to the third data sequence DS3, the second digest digest2 should also be included when generating the third digital signature DSIGN3. The second digest digest2 is generated by the third processing device in the same way as the first processing device 510 generates the second digest digest2 based on the second secret number SN2. The third processing device knows the second secret number SN2 or the second seed value in a similar way to the above-mentioned second processing device 520. If the second data sequence DS2 is to be coupled to the third data sequence DS3, the second digest digest2 is also included in the third data sequence DS3.
[0090] Once the cross-coupling of the three data sequences is executed, the data sequences DS1, DS2, DS3 will have the contents shown in the following table.
[0091]
[0092] It can be inferred from the above table and the cross-coupling of the two data sequences described previously that each of the cross-coupled data sequences will include its own data, its own secret number, its own digital signature, and the corresponding digest based on the corresponding secret number of each of the one or more data sequences included in the cross-coupling. In addition, the digital signature of each of the cross-coupled data sequences will be generated based on its own data, its own secret number, and the corresponding digest of each of the one or more data sequences included in the cross-coupling.
[0093] Now reference will be made to Figure 4 the flowchart and schematic diagram of which illustrate the verification device 600 for verifying the coupling of the first data sequence and the second data sequence Figure 6The block diagram describes a method for verifying that a first data sequence and a second data sequence are coupled to each other. The verification device 600 is included in or connected to the monitoring system 100. For example, the verification device 600 can be included in the client 120, or it can be connected to the client 120, the server 140, or the cloud service 150. It should be understood that some actions can be optional and the actions can be performed in another suitable order.
[0094] In operation 402, the first data sequence DS1 includes the first data data1, the first secret number SN1, and the obtained first digital signature DSIGN1, and in operation 404, the second data sequence DS2 includes the second data data2, the first digest digest1 of the first secret number SN1, and the obtained second digital signature DSIGN2.
[0095] For example, the first data sequence DS1 and the second data sequence DS2 can be obtained by receiving them from the first processing device 510 and the second processing device 520 respectively, or by retrieving them from a storage device (such as from the server 140 or the cloud service 150). The operations of obtaining the first data sequence DS1 and the second data sequence DS2 can be performed by the obtaining module 602 included in the verification device 600.
[0096] To authenticate that the obtained first data sequence DS1 and second data sequence DS2 originate from the respective so-called transmitters, such as from the first processing device 510 and the second processing device 520 or from a device including the first processing device 510 and the second processing device 520, the first digital signature DSIGN1 and the second digital signature DSIGN2 included in the obtained respective first data sequence DS1 and second data sequence DS2 are verified in operations 406 and 408. This can be performed by the verification module 604 of the verification device 600.
[0097] In some embodiments, the verification of the first digital signature DSIGN1 (operation 406) includes verifying that the first digital signature DSIGN1 is the result of applying a first cryptographic digital signature algorithm to the first data data1 and the first secret number SN1. In addition, the verification of the second digital signature DSIGN2 (operation 408) includes verifying that the second digital signature DSIGN2 is the result of applying a second cryptographic digital signature algorithm to the second data data2 and the first digest digest1.
[0098] In order to be able to verify the digital signatures, the verification module 604 knows how the first digital signature DSIGN1 and the second digital signature DSIGN2 are generated by a so-called transmitter, for example by the first processing device 510 and the second processing device 520 or by a device comprising the first processing device 510 and the second processing device 520. Thus, the verification module 604 is configured to verify the received digital signatures DSIGN1, DSIGN2 using (against / with) the received data (such as the first data data1, the first secret number SN1, the second data data2, and the first digest digest1). For example, the verification module 604 may be configured to decrypt the received first digital signature DSIGN1 and second digital signature DSIGN2 and generate a first signature digest signdigest1 based on the received first data data1 and the received first secret number SN1, and generate a second signature digest signdigest2 based on the received second data data2 and the received first digest digest1. Then, the verification module 604 compares the decrypted version of the first digital signature DSIGN1 with the generated first signature digest signdigest1, and if they match, the first digital signature DSIGN1 is verified. The verification module 604 also compares the decrypted version of the second digital signature DSIGN2 with the generated second signature digest signdigest2, and if they match, the second digital signature DSIGN2 is verified.
[0099] In some embodiments, the first digital signature DSIGN1 is verified when the decrypted version of the first digital signature DSIGN1 is a hash that matches the hash of the first data data1 and the first secret number SN1.
[0100] In a similar manner, and in some embodiments, the second digital signature DSIGN2 may be verified when the decrypted version of the obtained second digital signature DSIGN2 is a hash that matches the hash of the second data data2 and the first digest digest1.
[0101] The term "match" as used in this disclosure should be understood to mean that two values match each other if they are the same.
[0102] In order to be able to verify that the obtained first data sequence DS1 and second data sequence DS2 are coupled, i.e., related to each other in time, which means that they are captured during at least partially overlapping time periods, in action 410, a second first digest digest1' is generated based on the first secret number SN1 from the first data sequence DS1.
[0103] In some embodiments, a second first digest digest1' generated based on a first secret number SN1 can be obtained by applying a first cryptographic digest algorithm to the first secret number SN1.
[0104] In some embodiments including cross-coupled data sequences, a second second digest digest2' is generated based on a second secret number SN2. The second second digest digest2' generated based on the second secret number SN2 can be obtained by applying a second cryptographic digest algorithm to the second secret number SN2. The first cryptographic digest algorithm and the second cryptographic digest algorithm can be the same cryptographic digest algorithm. Action 410 can be performed by the generation module 606 included in the verification device 600.
[0105] In action 414, when the first digital signature DSIGN1 and the second digital signature DSIGN2 have been verified and when the generated second first digest digest1' matches the first digest digest1, the first data sequence DS1 and the second data sequence DS2 are verified to be coupled to each other. This can be performed by the verification module 608 included in the verification device 600.
[0106] As previously described, there are times when it is desirable to more firmly link two or more data sequences (such as the first data sequence DS1 and the second data sequence DS2) to each other by cross-coupling them. Thus, such cross-coupled data sequences can be obtained by the verification device 600.
[0107] In these embodiments, the first data sequence DS1 further includes the second digest digest2 and the second data sequence DS2 further includes the second secret number SN2. Additionally, the verification of the first digital signature DSIGN1 (action 406) includes verifying that the first digital signature DSIGN1 is the result of applying a first cryptographic digital signature algorithm to the first data data1, the first secret number SN1, and the second digest digest2. Additionally, the verification of the second digital signature DSIGN2 (action 408) includes verifying that the second digital signature DSIGN2 is the result of applying a second cryptographic digital signature algorithm to the second data data2, the first digest digest1, and the second secret number SN2. Also in such embodiments, the method includes action 412, in which a second second digest digest2' is generated based on the second secret number SN2. This can be performed by the generation module 606. In such embodiments, action 414 of verifying that the first data sequence DS1 and the second data sequence DS2 are coupled to each other further requires that the generated second second digest digest2' match the second digest digest2.
[0108] Now referring to Figure 5Describe a coupling system 500 for coupling a first data sequence and a second data sequence that are related to each other in time, enabling verification of the coupling of the first data sequence and the second data sequence.
[0109] As described above, the coupling system 500 includes a first processing device 510, which is configured to process a first data sequence DS1 captured within a first time period. The first processing device 510 may include a receiving module 512, which is configured to receive the first data sequence DS1. The first processing device 510 is configured to generate a first digital signature DSIGN1 of the first data sequence DS1 based on the first data data1 of the first data sequence DS1 and based on a first secret number SN1. This may be performed by the generating module 514 of the first processing device 510. In addition, the first processing device 510 is configured to merge the first secret number SN1 and the first digital signature DSIGN1 into the first data sequence DS1 and send the first data sequence DS1. This may be performed by the merging module 516 and the sending module 518 of the first processing device 510, respectively.
[0110] The coupling system 500 further includes a second processing device 520, which is configured to process a second data sequence DS2 captured within a second time period that at least partially overlaps with the first time period. The second processing device 520 may include a receiving module 522, which is configured to receive the second data sequence DS2. The second processing device 520 is further configured to generate a second digital signature DSIGN2 of the second data sequence DS2 based on the second data data2 of the second data sequence DS2 and based on a first digest digest1, where the first digest digest1 is generated based on the first secret number SN1. This may be performed by the generating module 524 of the second processing device 520. In addition, the second processing device 520 is configured to merge the second digital signature DSIGN2 and the first digest digest1 into the second data sequence DS2, whereby the first data sequence DS1 and the second data sequence DS2 are coupled by the first secret number SN1 and the first digest digest1. This may be performed by the merging module 526 of the second processing device 520. The second processing device 520 is further configured to send the second data sequence DS2. This may be performed by the sending module 528 of the second processing device 520.
[0111] The first processing device 510 and the second processing device 520 may be respective encoders included in corresponding parts of the monitoring system 100, such as a video encoder and an audio encoder. For example, the first processing device 510 may be a video encoder included in the monitoring camera 102 and configured to process the first data sequence when the first data sequence is a video data sequence. The second processing device 520 may be an audio encoder included in the monitoring camera 102 or the microphone device 104 and configured to process the second data sequence when the second data sequence is an audio data sequence.
[0112] In an embodiment, where data sequences that are related to each other in time should be cross-coupled, the first processing device 510 is further configured to generate a first digital signature DSIGN1 additionally based on a second digest digest2 that is generated on a second secret number SN2. In addition, the first processing device 510 is configured to incorporate the second digest digest2 into the first data sequence DS1. In such an embodiment, the second processing device 520 is further configured to generate a second digital signature DSIGN2 additionally based on the second secret number SN2 and incorporate the second secret number SN2 into the second data sequence DS2.
[0113] To be able to couple data sequences that are related in time, the first processing device 510 and the second processing device 520 should be synchronized in time. This can be achieved by providing a synchronization clock for the first processing device 510 and the second processing device 520. In particular, when the first processing device 510 and the second processing device 520 are different processing devices, it is advantageous to provide them with a synchronization clock. In this case, synchronization should be understood as the difference between the clocks being less than a threshold. By having synchronized clocks, it is ensured that the processing devices 510, 520 can generate the expected secret numbers SN1 and SN2 when the algorithms used to create these numbers are time-based. In some cases, the clock difference threshold results in a small range of secret numbers SN1 and SN2 being acceptable. Any secret number generated within the threshold clock difference is acceptable. In these cases, any acceptable secret number is an expected number, thus constituting a match when verifying the coupling of the data sequences.
[0114] The first processing device 510 and the second processing device 520 may be included in a single device, such as in a single monitoring camera 102, or included in two different devices, such as in respective monitoring cameras 102, or in the monitoring camera 102 and the microphone device 104 respectively.
[0115] Now reference will be made to Figure 6 describe a verification device 600 for verifying that the first data sequence and the second data sequence are coupled to each other.
[0116] The verification device 600 is configured to obtain a first data sequence DS1 including first data data1, a first secret number SN1, and a first digital signature DSIGN1. The verification device 600 is further configured to obtain a second data sequence DS2 including second data data2, a first digest digest1 of the first secret number SN1, and a second digital signature DSIGN2. This can be performed by the obtaining module 602 of the verification device 600.
[0117] In addition, the verification device 600, for example, through the verification module 604, is configured to verify the first digital signature DSIGN1 and verify the second digital signature DSIGN2.
[0118] The verification device 600, for example, through the generating module 606, is further configured to generate a second first digest digest1' based on the first secret number SN1. Sometimes, the first processing device 510 and the second processing device 520 are not fully synchronized in time, and thus the first secret numbers generated by them are not exactly the same, resulting in a digest generated based on the first secret number SN1 received from the first processing device 510 being different from the first digest digest1 generated by the processing device 520 on the first secret number SN1 it generated. Therefore, the verification device 600 sometimes generates several instances of the second first digest digest1' based on instances of the first secret number SN1 within a threshold clock difference of the received first secret number SN1. The threshold clock difference can be a predetermined value pre-known to the verification device 600. Alternatively, the threshold clock difference can be included in one or more streams, or sent to the verification device 600 in some other way. The threshold clock difference is typically a low multiple (e.g., two to five times) of the time each secret number is valid. In this way, a fixed number of secret numbers can be verified. Another way to achieve this is to make the threshold a number instead of a clock difference. The verification device 600 can know the threshold number in the same way as the threshold clock difference. The threshold number will indicate how many adjacent secret numbers the verification should accept. In one example, only the closest secret numbers in each direction (e.g., the closest lower secret number and the closest higher secret number) are considered valid.
[0119] In addition, the verification device 600, e.g., via the verification module 608, is configured to verify that the first data sequence DS1 and the second data sequence DS2 are coupled to each other when the first digital signature DSIGN1 and the second digital signature DSIGN2 have been verified and the generated second first digest digest1' matches the first digest digest1. When the verification device 600 generates several instances of the second first digest digest1' based on instances of the first secret number SN1 within a threshold clock difference of the received first secret number SN1, the verification device 600 may have to compare each of them with the received first digest digest1 to find a match.
[0120] As previously described, in some embodiments, the temporally related data sequences are cross-coupled. In these embodiments, the first data sequence DS1 further includes a second digest digest2, and the second data sequence DS2 further includes a second secret number SN2. Thus, in addition to the first data data1, the first secret number SN1, and the first digital signature DSIGN1, the first data sequence DS1 further includes the second digest digest2. Similarly, in addition to the second data data2, the first digest digest1, and the second digital signature DSIGN2, the second data sequence DS2 further includes the second secret number SN2. To verify such cross-coupled data sequences, the verification device 600 is further configured to generate a second second digest digest2' based on the second secret number SN2 from the second data sequence DS2; and to verify that the first data sequence DS1 and the second data sequence DS2 are coupled to each other in time when the generated second second digest digest2' also matches the second digest digest2 from the first data sequence DS1. As described above, sometimes the first processing device 510 and the second processing device 520 are not completely synchronized in time, and thus the second secret numbers generated by them respectively are not exactly the same, resulting in a digest generated based on the second secret number SN2 received from the second processing device 520 being different from the second second digest digest2 generated by the processing device 510 on its generated second secret number. Thus, the verification device 600 sometimes generates several instances of the second second digest digest2' based on instances of the second secret number SN2 within a threshold clock difference of the received second secret number SN2. When the verification device 600 generates several instances of the second second digest digest2' based on instances of the second secret number SN2 within a threshold clock difference of the received second secret number SN2, the verification device 600 may have to compare each of them with the received second digest digest2 to find a match.
[0121] As described above, in some embodiments, the first device 510 and the second device 520 may exchange their respective unique identifiers or corresponding digests of their respective unique identifiers to provide additional anti-fraud security. The verification device 600 may obtain the unique identifier of the second processing device or its digest from the first data sequence DS1, where it has been included by the first processing device 510. The verification device 600 may also obtain the unique identifier of the first processing device or its digest from the second data sequence DS2, where it has been included by the second processing device 520. By the received unique identifier or its digest, the verification device 600 is able to verify that the two processing devices claiming to send data sequences claimed to be coupled to each other are the actual sending processing devices. Thus, if a fraudulent processing device is able to copy the content of the first data sequence DS1 sent by the first processing device, i.e., the unique identifier of the second processing device (or its digest), the first digital signature DSIGN1, the first secret digit SN1, and the first data data1, and create a fraudulent data sequence including the copied content, the verification device 600 receiving the fraudulent data sequence (claimed to be the first data sequence DS1) and the second data sequence DS2 may infer that the fraudulent processing device is not the actual sender because the unique identifier of the first processing device (or its digest) included in the second data sequence DS2 does not match the unique identifier of the fraudulent processing device.
[0122] The embodiment also relates to a non-transitory computer-readable medium having computer code instructions stored thereon, the computer code instructions being adapted to perform embodiments of the methods described herein when executed by a device having processing capabilities.
[0123] As described above, the coupling system 500 may be configured to implement a method for coupling temporally related data sequences, and the verification device 600 may be configured to implement a method for verifying data sequence coupling and thus being temporally related. To this end, the coupling system 500 and the verification device 600 may include circuitry configured to implement the various method steps described herein.
[0124] In a hardware implementation, the circuitry may be dedicated and specifically designed to implement one or more method steps. The circuitry may be in the form of one or more integrated circuits, such as one or more application-specific integrated circuits or one or more field-programmable gate arrays.
[0125] In a software implementation, the circuitry may be replaced by a processor, such as a microprocessor, that is associated with computer code instructions stored on a (non-transitory) computer-readable medium, such as non-volatile memory, to cause the coupled system 500 and the verification device 600 to perform the method steps disclosed herein. Examples of non-volatile memory include read-only memory, flash memory, ferroelectric RAM, magnetic computer storage devices, optical discs, and the like. In the case of software, each of the above method steps may thus correspond to a portion of computer code instructions stored on a computer-readable medium that, when executed by the processor, cause the coupled system 500 and the verification device 600 to perform any of the methods disclosed herein.
[0126] It should be understood that a combination of hardware and software implementations may also be had, meaning that some method steps are implemented in hardware and others in software.
[0127] It should be understood that those skilled in the art may modify the above embodiments in various ways and still utilize the advantages of the invention shown in the above embodiments. Accordingly, the invention should not be limited to the embodiments shown, but should be defined only by the appended claims. Additionally, as will be understood by those skilled in the art, the embodiments shown may be combined.
Claims
1. A method for coupling a first data sequence and a second data sequence that are related to each other in time to enable verification that the first data sequence and the second data sequence are related to each other in time, the method comprising: Processing, by a first processing device (510), a first data sequence (DS1) captured from a monitored environment during a first time period: Generating (302) a first digital signature (DSIGN1) of the first data sequence (DS1) by applying a first cryptographic digital signature algorithm to first data (data1) of the first data sequence (DS1) and a first secret number (SN1); Merging (304) the first secret number (SN1) and the first digital signature (DSIGN1) into the first data sequence (DS1); And Transmitting (306) the first data sequence (DS1); Processing, by a second processing device (520), a second data sequence (DS2) that is different from the first data sequence (DS1) and is captured from the monitored environment during a second time period that at least partially overlaps the first time period, wherein the first processing device and the second processing device (510, 520) are different parts of a monitoring system (100) and are configured to synchronously generate a corresponding identical first secret number (SN1) in time, and wherein the second data sequence (DS2) is different from the first data sequence (DS1): Generating (308) a second digital signature (DSIGN2) of the second data sequence (DS2) by applying a second cryptographic digital signature algorithm to second data (data2) of the second data sequence (DS2) and a first digest (digest1), wherein the first digest (digest1) is generated by the second processing device (520) applying a first cryptographic digest algorithm to the first secret number (SN1); Merging (310) the generated second digital signature (DSIGN2) and the first digest (digest1) into the second data sequence (DS2), whereby the first data sequence (DS1) and the second data sequence (DS2) are coupled by the first secret number (SN1) and the first digest (digest1); and Transmitting (312) the second data sequence (DS2).
2. The method according to claim 1, wherein The first processing device and the second processing device (510, 520) generate corresponding identical second secret numbers (SN2) in time synchronization, wherein the first digital signature (DSIGN1) is further generated based on a second digest (digest2), and the second digest (digest2) is generated by the first processing device (510) applying a second cryptographic digest algorithm to the second secret number (SN2), wherein the second digital signature (DSIGN2) is further generated based on the second secret number (SN2), and wherein merging (304) the first secret number (SN1) and the first digital signature (DSIGN1) into the first data sequence (DS1) further includes: merging the second digest (digest2) into the first data sequence (DS1); and wherein merging (310) the generated second digital signature (DSIGN2) and the first digest (digest1) into the second data sequence (DS2) further includes: merging the second secret number (SN2) into the second data sequence (DS2).
3. The method according to claim 2, wherein The first digital signature (DSIGN1) is generated by the first processing device (510) applying the first cryptographic digital signature algorithm to the first data (data1), the first secret number (SN1), and the second digest (digest2); and wherein the second digital signature (DSIGN2) is generated by the second processing device (520) applying the second cryptographic digital signature algorithm to the second data (data2), the first digest (digest1), and the second secret number (SN2).
4. The method according to claim 1, wherein, The first secret number and the second secret number (SN1, SN2) are generated based on corresponding seed values and using corresponding cryptographically secure number generators (515, 525).
5. The method according to claim 4, wherein Each of the first secret number and the second secret number (SN1, SN2) is a one-time password OTP, for example a time-based OTP, TOTP.
6. A method for verifying that a first data sequence and a second data sequence are related to each other in time, the method comprising: obtaining (402) a first data sequence (DS1) including first data (data1), a first secret number (SN1), and a first digital signature (DSIGN1); obtaining (404) a second data sequence (DS2) including second data (data2), a first digest (digest1) of the first secret number (SN1), and a second digital signature (DSIGN2); verifying (406) the first digital signature (DSIGN1); verifying (408) the second digital signature (DSIGN2); generating (410) a second first digest (digest1’) by applying a first cryptographic digest algorithm to the first secret number (SN1); and Verify (414) that the first data sequence (DS1) and the second data sequence (DS2) are temporally related to each other when the first digital signature and the second digital signature (DSIGN1, DSIGN2) have been verified and when the generated second first digest (digest1') matches the first digest (digest1).
7. The method according to claim 6, wherein The first data sequence (DS1) further includes a second digest (digest2), wherein the second data sequence (DS2) further includes a second secret number (SN2), and wherein the method further includes: Generating (412) a second second digest (digest2') by applying a second cryptographic digest algorithm to the second secret number (SN2); and wherein verifying (414) that the first data sequence (DS1) and the second data sequence (DS2) are temporally related to each other further requires that the generated second second digest (digest2') match the second digest (digest2).
8. The method according to claim 6, wherein Verifying (406) the first digital signature (DSIGN1) includes: Verifying that the first digital signature (DSIGN1) is the result of applying a first cryptographic digital signature algorithm to the first data (data1), the first secret number (SN1), and, when according to claim 8, also to the second digest (digest2); and wherein verifying (408) the second digital signature (DSIGN2) includes: Verifying that the second digital signature (DSIGN2) is the result of applying a second cryptographic digital signature algorithm to the second data (data2), the first digest (digest1), and, when according to claim 8, also to the second secret number (SN2).
9. A coupling system (500) for coupling a first data sequence and a second data sequence that are temporally related to each other to enable verification that the first data sequence and the second data sequence are temporally related to each other, the system comprising: A first processing device (510) configured to process a first data sequence (DS1) captured from a monitored environment during a first time period and further configured to: Generate a first digital signature (DSIGN1) of the first data sequence (DS1) by applying a first cryptographic digital signature algorithm to the first data (data1) of the first data sequence (DS1) and a first secret number (SN1); Merge the first secret number (SN1) and the first digital signature (DSIGN1) into the first data sequence (DS1); And Transmit the first data sequence (DS1); And A second processing device (520), configured to process a second data sequence (DS2) that is different from the first data sequence (DS1) and is captured from the monitored environment during a second time period that at least partially overlaps with the first time period, wherein the first processing device and the second processing device (510, 520) are different parts of a monitoring system (100) and are set to synchronously generate corresponding identical first secret digits (SN1) in time, and wherein the second data sequence (DS2) is different from the first data sequence (DS1), and wherein the second processing device (520) is further configured to: Generate a second digital signature (DSIGN2) of the second data sequence (DS2) by applying a second cryptographic digital signature algorithm to second data (data2) of the second data sequence (DS2) and a first digest (digest1), wherein the first digest (digest1) is generated by the second processing device (520) applying a first cryptographic digest algorithm to the first secret digit (SN1); Combine the second digital signature (DSIGN2) and the first digest (digest1) into the second data sequence (DS2), whereby the first data sequence (DS1) and the second data sequence (DS2) are coupled by the first secret digit (SN1) and the first digest (digest1); and Transmit the second data sequence (DS2).
10. The coupling system (500) according to claim 9, wherein The first processing device and the second processing device (510, 520) are set to synchronously generate corresponding identical second secret digits (SN2) in time, wherein the first processing device (520) is further configured to: Generate the first digital signature (DSIGN1) additionally based on a second digest (digest2), the second digest (digest2) being generated by applying a second cryptographic digest algorithm to the second secret digit (SN2), and Combine the second digest (digest2) into the first data sequence (DS1); and wherein the second processing device (520) is further configured to: Generate the second digital signature (DSIGN2) additionally based on the second secret digit (SN2), and Combine the second secret digit (SN2) into the second data sequence (DS2).
11. The coupling system (500) according to claim 9, wherein, The first processing device and the second processing device (510, 520) are different processing devices with synchronized clocks.
12. The coupling system (500) according to claim 9, wherein, The first processing device and the second processing device (510, 520) are included in a single device, such as in a single monitoring camera, or are included in two different devices, such as in two different monitoring cameras.
13. A verification device (600) for verifying that a first data sequence and a second data sequence are temporally related to each other, the verification device being configured to: Obtain a first data sequence (DS1) including first data (data1), a first secret digit (SN1), and a first digital signature (DSIGN1); Obtain a second data sequence (DS2) including second data (data2), a first digest (digest1) of the first secret number (SN1), and a second digital signature (DSIGN2); Verify the first digital signature (DSIGN1); Verify the second digital signature (DSIGN2); Generate a second first digest (digest1’) by applying a first cryptographic digest algorithm to the first secret number (SN1); and Verify that the first data sequence (DS1) and the second data sequence (DS2) are temporally related to each other when the first digital signature and the second digital signature (DSIGN1, DSIGN2) have been verified and when the generated second first digest (digest1') matches the first digest (digest1).
14. The verification device (600) according to claim 13, wherein, The first data sequence (DS1) further includes a second digest (digest2), wherein the second data sequence (DS2) further includes a second secret number (SN2), and wherein the verification device is further configured to: Generate a second second digest (diges2’) by applying a second cryptographic digest algorithm to the second secret number (SN2); and Verify that the first data sequence (DS1) and the second data sequence (DS2) are temporally related to each other when the generated second second digest (digest2’) also matches the second digest (digest2).
Citation Information
Patent Citations
Multimedia electronic data forensic report and generating and displaying method and system thereof
CN103617402A
Method, computing unit and system for monitoring interior of passenger compartment
CN115123110A
Artificial intelligence generated content processing method, system and device and storage medium
CN116910792A
Signature device
JP2010251877A
Secure digital media capture and analysis
US20200014816A1