Data processing method and system for security and protection monitoring, storage medium and program product
Through homomorphic encryption and distributed storage methods, the complexity of data life cycle management in the security monitoring system is solved, and the compliant call and complete deletion of data is realized, ensuring data privacy and security.
Patent Information
- Application Number
- CN202510485687.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-17
- Publication Date
- 2025-07-25
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the data life cycle management of existing security monitoring systems, cross-system deletion operations are complex, resulting in inconsistent data status and problems with orphan data residues and compliance.
The homomorphic encryption scheme is used to encrypt the face and monitoring data, generate homomorphic computing logical contracts, and divide the data into fragments and store them in the cloud storage center and IPFS. The relationship is established through hash groups, and combined with life cycle strategies, the distributed storage and effective index of data are realized.
Ensure that data is called and processed in compliance during the life cycle, avoid data retention, ensure privacy and inaccessibility, achieve the effect of complete deletion, and meet the compliance requirements of security monitoring.
Smart Images

Figure CN120372656A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of storage encryption technology, and particularly to a data processing method, system, storage medium, and program product for security monitoring. Background Art
[0002] In the field of security monitoring, with the increase in the deployment density of cameras and the popularization of high-definition video technology, the amount of monitoring data generated by the system grows exponentially every day. This data not only includes the original video stream but also key information extracted from it (such as face data, behavior characteristics, etc.), which is the core basis for security event tracing, personnel management, and abnormal behavior analysis.
[0003] The related technology provides an invention named Data Processing Method, Device, Video Monitoring System, Storage Medium, with a publication number of CN114398449B, which solves the problem that: with the advent of the big data era, the explosive growth of camera devices will inevitably generate a large amount of data. Since the current data storage is centralized storage, mainly uploading the data collected by camera devices to the cloud center or storing it locally without relevant processing, it leads to greater difficulty in later processing / searching.
[0004] However, in actual use, security monitoring usually needs to follow the life cycle management strategy. This mainly includes: when the data reaches the preset storage period, it is processed to release storage resources and meet compliance requirements such as privacy protection. However, in the related technology, a logically complete security record is split and stored in three different technical systems: Original video (encrypted): stored in the cloud storage center. Face data (encrypted, extracted from the video): stored in IPFS (InterPlanetary File System). Data pointer (video hash + face data hash): stored on the blockchain. This architecture of physical separation + pointer indexing introduces complexity in performing data life cycle management, especially in the expiration deletion operation; for example: it is extremely difficult to implement an atomic deletion operation across these three systems. If the deletion operation is successful in one system but fails in another system (for example, the cloud video is deleted, but the face data cannot be deleted due to the temporary inaccessibility of the IPFS node, or the blockchain transaction fails resulting in the pointer not being processed), it will cause inconsistent data states: when it is necessary to delete the monitoring data for a certain period, it may occur that the video file in the cloud storage has been deleted, but the face data in the IPFS has not been removed due to node communication delay, or the index pointer on the blockchain has not been synchronized and updated. This cross-system data state inconsistency will lead to the residual of orphan data or the existence of invalid pointers, which not only violates data compliance requirements but also accumulates invalid data, increasing the system maintenance cost.
[0005] In summary, it is difficult to completely delete data from different channels in the related technology. Summary of the Invention
[0006] The present application provides a data processing method, system, storage medium and program product for security monitoring. On the one hand, due to following the life cycle strategy, users cannot obtain encrypted data through conventional means after the deadline. On the other hand, although the platform retains fragmented data segments, since there is no opportunity to obtain the key throughout the process, these segments cannot be recombined and restored into meaningful data at all. In terms of actual effect, it is equivalent to completely deleting the expired data.
[0007] In a first aspect, the present application provides a data processing method for security monitoring, including: obtaining face data and monitoring data, where the face data is obtained by recognizing the monitoring data; encrypting the face data and the monitoring data to generate face encrypted data and monitoring encrypted data, and generating a homomorphic calculation logic contract for the face encrypted data and the monitoring encrypted data by using a preset homomorphic encryption scheme; respectively dividing the face encrypted data and the monitoring encrypted data into multiple face data segments and monitoring data segments; sending the monitoring data segments to a cloud storage center, sending the face data segments to IPFS, receiving a face hash value group returned by the cloud storage center based on the monitoring data segments, and receiving a monitoring hash value group returned by IPFS based on the face data segments, where the face hash value group is the storage address of the monitoring data segments in the cloud storage center, and the face hash value group is the storage address of the face data segments in IPFS; storing the monitoring hash value group, the face hash value group, and the homomorphic calculation logic contract in a blockchain, and the homomorphic calculation logic contract is associated with a predefined life cycle strategy; sending a request for the face data or / and the monitoring data to the cloud storage center or / and IPFS; enabling the cloud storage center or / and IPFS to call the homomorphic calculation logic contract to give a calculation result; decrypting the encryption result by using the key corresponding to the face encrypted data or / and the key corresponding to the monitoring encrypted data.
[0008] By adopting the above technical solution, a homomorphic computing logic contract is generated for the face encrypted data and the monitoring encrypted data by using a preset homomorphic encryption scheme. While ensuring data privacy, homomorphic encryption enables specific operations to be performed in the ciphertext state with the help of the homomorphic computing logic contract. The monitoring data segments are sent to the cloud storage center, and the face data segments are sent to IPFS. The face hash value group returned by the cloud storage center based on the monitoring data segments is received, and the monitoring hash value group returned by IPFS based on the face data segments is received. The advantages of different storage systems are utilized to store different types of data respectively, and associations are established through the hash value groups to achieve distributed storage and effective indexing of data. The cloud storage center or / and IPFS call the homomorphic computing logic contract to give the calculation result; with the help of the lifecycle policy, the effective usage time range of the data is clarified. During the data lifecycle, the cloud storage center or / and IPFS can call key information such as relevant hash value groups and homomorphic computing logic contracts from the blockchain according to the rules, and then through homomorphic encryption operations, without decrypting each data segment, the ability to temporarily reconstruct the access data according to specific logic is realized, so as to achieve compliant invocation and processing of data and meet various requirements in the security monitoring process. Once the data reaches the expiration date specified by the lifecycle, since the entire process encrypts and fragments the data, even if the data segments still exist, the logic for reconstructing the access data, which is bound to the lifecycle policy, will become invalid. At the same time, the face data and the monitoring data are encrypted and exist in ciphertext form. Then, in the subsequent platform processing process, even if the platform receives these encrypted ciphertext data, it can perform corresponding ciphertext operations according to the operation rules supported by homomorphic encryption without knowing the plaintext content of the data, and finally obtain the result that meets the user's needs. This benefits from the characteristics of homomorphic encryption, which not only ensures that the privacy of the data is not known to the platform during the transmission and processing links, but also allows users to rest assured to hand over the data to the platform. To sum up, the design of the entire system makes the confidentiality and inaccessibility of the data achieve an effect similar to complete deletion. On the one hand, due to following the lifecycle policy, users cannot obtain the encrypted data through conventional means after the expiration date; on the other hand, although the platform retains fragmented data segments, since there is no chance to obtain the key throughout the process, these segments cannot be reconstructed and restored into meaningful data at all. From the actual effect, it is equivalent to completely deleting the expired data, which not only complies with the compliance requirements of data management, but also avoids risks such as privacy leakage that may be caused by data residue.
[0009] In some embodiments in combination with some embodiments of the first aspect, the steps of enabling the cloud storage center and / or IPFS to call the homomorphic computing logic contract to give a calculation result specifically include: the cloud storage center and / or IPFS call the monitoring hash value group, the face hash value group, and the homomorphic computing logic contract from the blockchain; the cloud storage center and / or IPFS obtain the current time and perform a time check based on the current time and a predefined lifecycle policy; if the time check result passes, the cloud storage center and / or IPFS obtain the monitoring data segment and / or the face data segment from the corresponding storage location based on the monitoring hash value group and / or the face hash value group; the cloud storage center and / or IPFS combine the temporary decryption key with the monitoring data segment and / or the face data segment to obtain the face data and / or the monitoring data; the cloud storage center and / or IPFS run the homomorphic computing logic contract to obtain the calculation result; if the time check result fails, the request is rejected.
[0010] By adopting the above technical solution, when the cloud storage center and / or IPFS call the monitoring hash value group, the face hash value group, and the homomorphic computing logic contract from the blockchain, this operation relies on the immutable and traceable characteristics of the blockchain to ensure the accuracy and reliability of the obtained key information. Then the cloud storage center and / or IPFS obtain the current time and perform a time check based on the current time and a predefined lifecycle policy. Through the verification in the time dimension, it avoids non-compliant or expired data from being mixed into the subsequent process. If the time check passes, using the indexing function of the hash value group, the corresponding data segments can be accurately extracted, providing accurate materials for subsequent integration and operation. The cloud storage center and / or IPFS run the homomorphic computing logic contract to obtain the calculation result. The operation is performed on the ciphertext according to the homomorphic computing logic contract, making the calculation result meet the expectations and ensuring data privacy, and ensuring that the security monitoring data can be called and processed as needed and in compliance.
[0011] In some embodiments in combination with some embodiments of the first aspect, the steps of the cloud storage center and / or IPFS running the homomorphic computing logic contract to obtain the calculation result specifically include: the cloud storage center and / or IPFS find the face data segment and / or the monitoring data segment corresponding to the face data and / or the monitoring data involved in the request; if the cloud storage center and / or IPFS find all the face data segments and / or the monitoring data segments corresponding to the face data and / or the monitoring data involved, the cloud storage center and / or IPFS integrate all the face data segments and / or the monitoring data segments corresponding to the face data and / or the monitoring data involved into a data batch; the cloud storage center and / or IPFS generate an aggregation commitment for the data batch, and the aggregation commitment indicates that all the segments in the data batch exist and are not publicly disclosed; the cloud storage center and / or IPFS supervise the operation of the homomorphic computing logic contract according to the aggregation commitment; wherein it is verified that all the segments in the data batch are used and have a successful receipt.
[0012] By adopting the above technical solutions, the cloud storage center or / and IPFS search for the corresponding face data segments or / and monitoring data segments of the face data or / and monitoring data involved in the request to ensure that subsequent operations focus on the correct data objects and avoid interference from invalid data. When all relevant data segments are successfully found, the cloud storage center or / and IPFS integrate all the involved face data or / and the corresponding face data segments or / and monitoring data segments of the monitoring data into a data batch. By integrating to form a data batch, it is convenient for unified management and batch processing. The cloud storage center or / and IPFS generate an aggregation commitment for the data batch. The aggregation commitment indicates that all segments within the data batch exist and are not publicly disclosed. The generation of this aggregation commitment is crucial. Without revealing the specific content of the segments, it provides a covert and effective way to verify data integrity, which can not only protect data privacy but also confirm the validity of the data batch. Then the cloud storage center or / and IPFS supervise the operation of the homomorphic computing logic contract according to the aggregation commitment; among them, it verifies that all segments within the data batch are used and have a successful receipt. By using the aggregation commitment to supervise the operation of the homomorphic computing logic contract, it can ensure that each data segment participates as required and the operation is successful during the calculation process, preventing data loss or incorrect use, and ensuring the accuracy and credibility of the homomorphic computing result in a confidential scenario.
[0013] Combined with some embodiments of the first aspect, in some embodiments, after the step of rejecting the request if the time check result fails; the cloud storage center or / and IPFS mark the corresponding monitoring data segments or / and face data segments as in a state where they can be overwritten.
[0014] By adopting the above technical solutions, when the cloud storage center or / and IPFS mark the corresponding monitoring data segments or / and face data segments as in a state where they can be overwritten, it creates good conditions for the reasonable utilization of storage resources. As time goes by and new data is generated, these marked data segments can be naturally overwritten by the new data, avoiding the long-term occupation of invalid data and enabling gradual deletion.
[0015] Combined with some embodiments of the first aspect, in some embodiments, the step of encrypting the face data and the monitoring data to generate face encrypted data and monitoring encrypted data specifically includes: dynamically encrypting the face data and the monitoring data to generate face encrypted data and monitoring encrypted data; where the face data or the monitoring data corresponds to a separate secret key.
[0016] By adopting the above technical solutions, the face data or the monitoring data corresponds to a separate secret key, making the encryption of each data independent of each other. Even if the secret key of a certain data encounters security threats such as accidental leakage, the confidentiality of other data can still be reliably guaranteed, fundamentally enhancing the overall security of the data.
[0017] In some embodiments in combination with some embodiments of the first aspect, the steps of respectively splitting the face encrypted data and the monitoring encrypted data into multiple face data segments and monitoring data segments specifically include: The sizes of the face encrypted data and the monitoring encrypted data are positively correlated with the numbers of the face data segments and the monitoring data segments.
[0018] By adopting the above technical solution, the sizes of the face encrypted data and the monitoring encrypted data are positively correlated with the numbers of the face data segments and the monitoring data segments. Through this positive correlation setting, when facing data of different scales, the number of data segments can be reasonably adjusted according to the data volume. When the data volume is large, the number of data segments can be increased accordingly, so that the size of each segment is within a more convenient range for processing.
[0019] Moreover, when performing subsequent data processing operations such as homomorphic calculation and decryption, working in units of segments can more flexibly schedule resources, avoid performance bottlenecks caused by processing large-scale data, improve the efficiency and accuracy of the entire data processing process, optimize the ability to handle data of different scales in each link from data storage to processing, and ensure that the security monitoring data processing can be carried out efficiently and smoothly.
[0020] In some embodiments in combination with some embodiments of the first aspect, after the step of sending the face data segments to IPFS, it further includes: IPFS selects at least two target storage nodes for each face data segment; and stores the face data segments into their corresponding target storage nodes respectively.
[0021] By adopting the above technical solution, after the step of sending the face data segments to IPFS, IPFS selects at least two target storage nodes for each face data segment; and stores the face data segments into their corresponding target storage nodes respectively, realizing redundant storage of data. This redundant storage method utilizes the characteristics of distributed storage. When an unexpected situation such as a network failure or a hardware failure occurs in a certain storage node, other normal storage nodes still store the complete face data segments, ensuring that the data will not be lost due to a single-point failure, and improving the reliability and availability of face data storage.
[0022] In a second aspect, the present application provides a security monitoring data processing system, which includes: one or more processors and a memory; the memory is coupled to the one or more processors, and the memory is used to store computer program code, the computer program code includes computer instructions, and the one or more processors call the computer instructions to enable the security monitoring data processing system to execute the method described in the first aspect and any possible implementation manner in the first aspect.
[0023] In a third aspect, the present application provides a computer program product containing instructions, which, when the computer program product runs on a data processing system for anti-surveillance, causes the data processing system for anti-surveillance to execute the method described in the first aspect and any possible implementation manner in the first aspect.
[0024] In a fourth aspect, the present application provides a computer-readable storage medium including instructions, which, when the instructions run on a data processing system for anti-surveillance, causes the data processing system for anti-surveillance to execute the method described in the first aspect and any possible implementation manner in the first aspect.
[0025] One or more technical solutions provided in the embodiments of the present application have at least the following technical effects or advantages: 1. Use a preset homomorphic encryption scheme to generate a homomorphic computing logic contract for face encrypted data and monitoring encrypted data. While ensuring data privacy, homomorphic encryption enables specific operations to be performed in the ciphertext state with the help of the homomorphic computing logic contract. Send the monitoring data fragments to the cloud storage center and the face data fragments to IPFS. Receive the face hash value group returned by the cloud storage center based on the monitoring data fragments, and receive the monitoring hash value group returned by IPFS based on the face data fragments. Utilize the advantages of different storage systems to store different types of data separately and establish associations through the hash value groups to achieve distributed storage and effective indexing of data. The cloud storage center or / and IPFS call the homomorphic computing logic contract to give the calculation result; with the help of the lifecycle policy, the effective usage time range of the data is clarified. During the data lifecycle, the cloud storage center or / and IPFS can call relevant key information such as hash value groups and homomorphic computing logic contracts from the blockchain according to the rules, and then through homomorphic encryption operations, without decrypting each data fragment, temporarily reorganize the ability to access data according to specific logic to achieve compliant invocation and processing of data, meeting various requirements in the security monitoring process. Once the data reaches the expiration date specified by the lifecycle, due to the encryption and fragmentation processing of the data throughout the process, even if the data fragments still exist, the logic for reorganizing access to the data, which is bound to the lifecycle policy, will become invalid. At the same time, the face data and monitoring data are encrypted and exist in ciphertext form. Then, in the subsequent platform processing, even if the platform receives these encrypted ciphertext data, it can perform corresponding ciphertext operations according to the operation rules supported by homomorphic encryption without knowing the cleartext content of the data, and finally obtain the result that meets the user's needs. This benefits from the characteristics of homomorphic encryption, which not only ensures that the privacy of data is not known to the platform during transmission and processing, but also allows users to rest assured to hand over the data to the platform. In summary, the design of the entire system makes the confidentiality and inaccessibility of data achieve an effect similar to complete deletion. On the one hand, users cannot obtain encrypted data through conventional means outside the deadline due to following the lifecycle policy; on the other hand, although the platform retains fragmented data fragments, since there is no chance to obtain the key throughout the process, these fragments cannot be reorganized and restored into meaningful data. From the actual effect, it is equivalent to completely deleting the expired data, which not only complies with the compliance requirements of data management but also avoids risks such as privacy leakage that may be caused by data residue.
[0026] 2. The cloud storage center or / and IPFS call the monitoring hash value group, face hash value group, and homomorphic computing logic contract from the blockchain. This operation leverages the immutable and traceable characteristics of the blockchain to ensure the accuracy and reliability of the obtained key information. Subsequently, the cloud storage center or / and IPFS obtain the current time and perform a time check based on the current time and the predefined lifecycle policy. Through the verification in the time dimension, it avoids non-compliant or expired data from being mixed into the subsequent processes. If the time check passes, using the indexing function of the hash value group, the corresponding data segments can be accurately extracted, providing accurate materials for subsequent integration and operation. The cloud storage center or / and IPFS run the homomorphic computing logic contract to obtain the calculation result, and perform operations on the ciphertext according to the homomorphic computing logic contract, making the calculation result meet the expectations and ensuring data privacy, ensuring that the security monitoring data can be called and processed as needed and in compliance.
[0027] 3. The cloud storage center or / and IPFS search for the face data segments or / and monitoring data segments corresponding to the face data or / and monitoring data involved in the request to ensure that subsequent operations focus on the correct data objects and avoid interference from invalid data. When all relevant data segments are successfully found, the cloud storage center or / and IPFS integrate all the face data or / and face data segments or / and monitoring data segments corresponding to the monitoring data involved into a data batch. By integrating to form a data batch, it is convenient for unified management and batch processing. The cloud storage center or / and IPFS generate an aggregation commitment for the data batch. The aggregation commitment indicates that all segments within the data batch exist and are not publicly disclosed. The generation of this aggregation commitment is crucial. Without revealing the specific content of the segments, it provides a covert and effective way to verify data integrity, ensuring both data privacy and the validity of the data batch. Then the cloud storage center or / and IPFS supervise the operation of the homomorphic computing logic contract according to the aggregation commitment; among them, verify that all segments within the data batch are used and have a successful receipt. Supervising the operation of the homomorphic computing logic contract with the help of the aggregation commitment can ensure that each data segment participates as required and the operation is successful during the calculation process, preventing data loss or incorrect use, and ensuring the accuracy and credibility of the homomorphic calculation result in a confidential scenario. Description of the Drawings
[0028] Figure 1 is a flowchart of a data processing method for security monitoring in an embodiment of the present application; Figure 2 is Figure 1 a specific flowchart of step S106 in Figure 3 is another flowchart of a data processing method for security monitoring in an embodiment of the present application; Figure 4It is a schematic diagram of an exemplary hardware structure of the data processing system for security monitoring in the embodiments of the present application. Detailed implementation manners
[0029] The terms used in the following embodiments of the present application are only for the purpose of describing specific embodiments and are not intended to limit the present application. As used in the specification and appended claims of the present application, the singular forms "a", "an", "the", "above-mentioned", "said", and "this" are also intended to include the plural forms, unless the context clearly indicates otherwise. It should also be understood that the terms and / or used in the present application refer to and include any or all possible combinations of one or more of the listed items.
[0030] Hereinafter, the terms "first" and "second" are only used for descriptive purposes and cannot be understood as implying or suggesting relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined as "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the embodiments of the present application, unless otherwise specified, the meaning of "a plurality" is two or more.
[0031] Please refer to Figure 1 , Figure 1 which is a flowchart of the data processing method for security monitoring in the embodiments of the present application; S101. Obtain face data and monitoring data, where the face data is obtained by recognizing the monitoring data; Among them, the face data refers to the information related to the facial features of a person extracted from the monitoring data through specific recognition technologies.
[0032] S102. Encrypt the face data and the monitoring data to generate face encrypted data and monitoring encrypted data, and generate a homomorphic computing logic contract for the face encrypted data and the monitoring encrypted data by using a preset homomorphic encryption scheme; Among them, the homomorphic encryption scheme refers to a special encryption technology that allows specific mathematical operations to be performed on the encrypted data (ciphertext), and the result after the operation is the same as the result of performing the same operation on the plaintext after decryption. It is used to ensure that certain calculation operations can still be performed on the encrypted data while ensuring data privacy. The homomorphic computing logic contract is a form of smart contract constructed based on the homomorphic encryption algorithm. It defines the operation rules, data processing processes, and related permission controls that can be performed in the ciphertext state, and is used to regulate the subsequent operation behaviors on the encrypted data.
[0033] It should be noted that the keys used for encrypting and subsequently decrypting the face data and surveillance data are all stored locally. After the data is encrypted, whether it is the encrypted face data, encrypted surveillance data, or the encrypted result obtained through the homomorphic computing logic contract operation, it is stored in the relevant external storage systems, such as cloud storage centers, IPFS, etc.
[0034] In some embodiments, based on the programming interface of the selected homomorphic encryption algorithm, the homomorphic computing logic contract code is written, the allowed operation logic, input and output formats, etc. in the contract are defined, and then it is deployed to the corresponding blockchain or the platform that supports the contract operation, and associated with the encrypted face data and encrypted surveillance data to make it effective.
[0035] It should be noted that homomorphic encryption has been detailedly disclosed in the related technologies and will not be elaborated here.
[0036] In some embodiments, the face data and surveillance data are dynamically encrypted to generate encrypted face data and encrypted surveillance data; where the face data or surveillance data corresponds to a separate key.
[0037] Among them, dynamic encryption is an encryption method that dynamically generates keys according to a specific encryption algorithm. Specifically, for each piece of face data or each piece of surveillance data, a unique encryption and decryption key will be assigned to it, and each key is independent of each other and has no correlation.
[0038] Moreover, the key generation algorithms used for the face data and surveillance data are different. However, for the same type of data, for example, all face data follows the same key generation algorithm, and all surveillance data also follows its corresponding same key generation algorithm, but only the specific generated key content is different, so as to ensure the consistency and uniqueness of the encryption method for the same type of data.
[0039] It is worth noting that in terms of the complexity of the key generation algorithm, the complexity of the key generation algorithm corresponding to the face data is higher than that of the surveillance data. This is because the face data often involves more personal privacy information and requires a higher level of encryption protection, so its key generation algorithm is more complex and can generate keys with higher security and greater cracking difficulty.
[0040] It can be seen that the face data or surveillance data corresponds to a separate key, making the encryption of each data independent of each other. Even if the key of a certain data encounters security threats such as accidental leakage, the confidentiality of other data can still be reliably guaranteed, fundamentally improving the overall security of the data.
[0041] S103. Split the encrypted face data and encrypted surveillance data into multiple face data segments and surveillance data segments respectively; Among them, the face data segment and the monitoring data segment refer to the smaller data units formed by splitting the face encrypted data and the monitoring encrypted data according to certain rules, and each of them carries part of the information of the original encrypted data.
[0042] The purpose is to fragment the data. By splitting the face data and the monitoring data into multiple data segments and storing these segments in different locations such as local, cloud storage center, and IPFS respectively, neither the local system, nor the cloud storage center or IPFS can obtain the complete data by itself. In this way, when the data reaches the expiration date of its life cycle, due to the lack of complete data information, each storage end cannot effectively restore it, thus facilitating the realization of an effect similar to complete deletion.
[0043] In some embodiments, the sizes of the face encrypted data and the monitoring encrypted data are positively correlated with the numbers of the face data segments and the monitoring data segments.
[0044] Among them, "positively correlated" means that there is a co-varying relationship between the sizes of the face encrypted data and the monitoring encrypted data and the numbers of the face data segments and the monitoring data segments into which they are respectively split, that is, the larger the overall volume of the data, the more the number of data segments split out, and vice versa. For example, if the volume of the monitoring encrypted data increases, then the number of monitoring data segments split out will also increase accordingly.
[0045] It can be seen that the sizes of the face encrypted data and the monitoring encrypted data are positively correlated with the numbers of the face data segments and the monitoring data segments. Through this positive correlation setting, when facing data of different scales, the number of data segments can be reasonably adjusted according to the data volume. When the data volume is large, the number of data segments can be increased accordingly, so that the size of each segment is within a more convenient range for processing.
[0046] S104: Send the monitoring data segment to the cloud storage center, send the face data segment to IPFS, receive the face hash value group returned by the cloud storage center based on the monitoring data segment, and receive the monitoring hash value group returned by IPFS based on the face data segment, where the face hash value group is the storage address of the monitoring data segment in the cloud storage center, and the face hash value group is the storage address of the face data segment in IPFS; Among them, the cloud storage center refers to a centralized storage platform provided by a cloud service provider with large-scale storage capabilities and reliable data storage services, which is used to store massive amounts of information such as surveillance data segments. It usually has functions such as high availability, scalability, and data backup and recovery. IPFS (InterPlanetary File System) is a decentralized file storage system based on distributed hash tables and blockchain technology. It stores and shares files through multiple nodes, and has characteristics such as distributed storage, content addressing, and censorship resistance. It is used to store data such as face data segments, which can better protect the privacy and storage reliability of data. The face hash value group is a set of hash values obtained by calculating face data segments through a specific hash algorithm. These hash values represent the storage addresses and unique identifiers of face data segments in the corresponding storage system (such as IPFS), and are used to quickly locate and retrieve the corresponding face data segments later. Similarly, the surveillance hash value group is the storage address and unique identifier of surveillance data segments in the cloud storage center, and realizes efficient indexing and management of data through hash values.
[0047] Specifically, the segmented surveillance data segments are sent to the cloud storage center through network transmission. After receiving these data segments, the cloud storage center will store them according to its own storage management mechanism, and calculate the corresponding surveillance hash values for each surveillance data segment using a hash algorithm, and return these surveillance hash value groups to the sender. At the same time, the face data segments are sent to IPFS, and each node in IPFS will cooperate to store these data segments and also calculate the corresponding face hash value groups and feedback them to the sender. For example, in the security surveillance network of a city, the data generated by surveillance devices in each area are stored in the cloud storage center and IPFS respectively after the above processing. Through the corresponding hash value groups, it will be convenient to search and call the required data segments in different storage systems later.
[0048] In some embodiments, after step S104, it further includes: IPFS selects at least two target storage nodes for each face data segment; The face data segments are respectively stored in their corresponding target storage nodes.
[0049] Specifically, IPFS selects at least two suitable target storage nodes for each face data segment. During the selection process, it will try to ensure that these nodes are distributed in different geographical locations or network regions to reduce the risk of multiple nodes failing simultaneously due to factors such as local network failures or natural disasters. Then, IPFS will transmit each face data segment to its corresponding target storage node respectively.
[0050] It can be seen that after the step of sending the face data segments to IPFS, IPFS selects at least two target storage nodes for each face data segment; and stores the face data segments in their corresponding target storage nodes respectively, realizing redundant storage of data. This redundant storage method utilizes the characteristics of distributed storage. When an unexpected situation such as a network failure or a hardware failure occurs in a certain storage node, other normal storage nodes still store the complete face data segments, ensuring that the data will not be lost due to a single point of failure, and improving the reliability and availability of face data storage.
[0051] S105. Store the monitoring hash value group, the face hash value group, and the homomorphic computing logic contract in the blockchain. The homomorphic computing logic contract is associated with a predefined lifecycle policy; Among them, the lifecycle policy refers to the pre-set processing rules for each stage from the generation to the final destruction of data, and is used to regulate the management behavior of data throughout its lifecycle.
[0052] S106. Send a request for face data or / and monitoring data to the cloud storage center or / and IPFS; and enable the cloud storage center or / and IPFS to call the homomorphic computing logic contract to give a calculation result; Specifically, the user or the relevant application system sends a request with clear requirements to the cloud storage center or / and IPFS. The cloud storage center or / and IPFS will first call key information such as the monitoring hash value group, the face hash value group, and the homomorphic computing logic contract from the blockchain, and then perform a time check according to the lifecycle policy associated with the homomorphic computing logic contract at the current time to determine whether the data is in an operable stage. If the time check passes, the corresponding monitoring data segment or / and face data segment will be obtained from the corresponding storage location based on the hash value group, and the homomorphic computing logic contract will be used to perform ciphertext operations on these data segments to obtain the encrypted calculation result.
[0053] It should be noted that the face data and monitoring data involved in steps S101 to S105 are a general concept, which represents various face-related information and basic data such as monitoring videos and images collected and processed by the security monitoring system during the entire operation process. However, the face data and monitoring data mentioned in step S106 are specific, and are corresponding data screened out based on specific needs and specific conditions. For example, when a user initiates a request to obtain face data within a specific time range, IPFS will first find and locate the face data fragments corresponding to all face data within the time range based on this clear requirement, and then perform cumulative operations on these face data fragments according to the established rules and logic, so that they are recombined and restored to face encrypted data, and then further perform cumulative combination and other processing on these face encrypted data (homomorphic computing logic contract), so as to meet the needs of corresponding operations and calculations on specific face data, and ensure that the user can be provided with the data results that they expect to obtain and meet specific conditions.
[0054] See also Figure 2 , Figure 2 yes Figure 1 A specific flow chart of step S106; In some embodiments, step 106 specifically includes: S1061, the cloud storage center or / and IPFS calls the monitoring hash value group, the face hash value group, and the homomorphic computing logic contract from the blockchain; It should be noted that the cloud storage center or / and IPFS mentioned here are the operation objects corresponding to the different data retrieval needs of users. Specifically, the user may only retrieve facial data, in which case IPFS is mainly involved for the corresponding operation, because facial data fragments are usually stored in IPFS; it is also possible to only retrieve monitoring data, in which case the cloud storage center is mainly responsible for the relevant operations, after all, most monitoring data fragments are stored in the cloud storage center; of course, it is also possible that the user needs both facial data and monitoring data at the same time, then the cloud storage center and IPFS must participate to complete the operations related to the data fragments stored by each. The expressions involving or / and in the subsequent content are similar, and they all correspond to different data retrieval scenarios according to this logic, and will not be repeated later.
[0055] Specifically, the cloud storage center and / or IPFS will send a request to the blockchain network, and through the communication mechanism between blockchain nodes and the corresponding interface, search and obtain the monitoring hash value group, face hash value group and homomorphic computing logic contract from the blockchain.
[0056] S1062, the cloud storage center or / and IPFS obtains the current time, and performs a time check based on the current time and a predefined life cycle policy; Specifically, the cloud storage center or / and IPFS will first obtain the current time of its own system, and this time information is precisely synchronized to ensure compliance with the actual situation. Then, this current time is compared with the time conditions in the predefined lifecycle policy associated with the homomorphic computing logic contract, such as checking whether the data has exceeded the specified storage period or whether it has not yet reached the time node allowing access, etc.
[0057] S1063: If the time check result is passed, the cloud storage center or / and IPFS obtains the monitoring data segment or / and face data segment from the corresponding storage location based on the monitoring hash value group or / and face hash value group; Specifically, the cloud storage center or / and IPFS will, according to the obtained monitoring hash value group or / and face hash value group, locate the corresponding storage locations through its internal data indexing and searching mechanism, and then extract the monitoring data segment or / and face data segment from these locations.
[0058] S1064: The cloud storage center or / and IPFS combines the monitoring data segment or / and face data segment to obtain face data or / and monitoring data; Specifically, the cloud storage center or / and IPFS will splice and summarize the obtained monitoring data segment or / and face data segment according to the original logical relationship of the data (such as time sequence, spatial association, etc.) and the pre-set combination rules.
[0059] S1065: The cloud storage center or / and IPFS runs the homomorphic computing logic contract to obtain the calculation result; It should be noted that the principle and process of this step are similar to those of step S106. The relevant principles and processes can be referred to in step S106 and will not be elaborated here.
[0060] S1066: If the time check result is not passed, the request is rejected.
[0061] Specifically, the cloud storage center or / and IPFS will generate a rejection response message, which contains the reason for rejection (such as the data has expired, not yet reached the access time, etc.) and the relevant time information (such as the specified valid time range, current time, etc.), and then send this message to the requester through the network communication protocol (such as HTTP, TCP, etc.).
[0062] It can be seen that the cloud storage center and / or IPFS call the monitoring hash value group, face hash value group, and homomorphic computing logic contract from the blockchain. This operation relies on the immutable and traceable characteristics of the blockchain to ensure the accuracy and reliability of the obtained key information. Subsequently, the cloud storage center and / or IPFS obtain the current time and perform a time check based on the current time and the predefined lifecycle policy. Through the verification in the time dimension, it is possible to prevent non-compliant or expired data from being mixed into the subsequent processes. If the time check passes, by using the indexing function of the hash value group, the corresponding data fragments can be accurately extracted, providing accurate materials for subsequent integration and calculation. The cloud storage center and / or IPFS run the homomorphic computing logic contract to obtain the calculation result, and perform the operation on the ciphertext according to the homomorphic computing logic contract, making the calculation result meet the expectations and ensuring data privacy, and ensuring that the security monitoring data can be called and processed as needed and in compliance.
[0063] S1067. The cloud storage center and / or IPFS mark the corresponding monitoring data fragments and / or face data fragments as overwritable.
[0064] Specifically, the cloud storage center and / or IPFS will scan and identify the corresponding previously used monitoring data fragments and / or face data fragments according to the internal management mechanism. Then, by modifying the metadata information of the data fragments, such as adding an "overwritable" identifier in the attribute field of the data, or updating the status flag of the data to be overwritable. In this way, when new data needs to be stored, the storage system will preferentially consider using the storage space where these marked data fragments are located to store the new data.
[0065] It can be seen that when the cloud storage center and / or IPFS mark the corresponding monitoring data fragments and / or face data fragments as overwritable, it creates good conditions for the reasonable utilization of storage resources. As time goes by and new data is generated, these marked data fragments can be naturally overwritten by the new data, avoiding the long-term occupation of invalid data and enabling gradual deletion.
[0066] S107. Decrypt the encryption result using the secret key corresponding to the face encrypted data and / or the secret key corresponding to the monitoring encrypted data.
[0067] Specifically, when the encrypted calculation result is received, the private key corresponding to the encrypted face data and monitoring data previously (if asymmetric encryption is used) is used to decrypt the encryption result according to the decryption rules of the corresponding homomorphic encryption algorithm.
[0068] It can be seen that by using the preset homomorphic encryption scheme to generate a homomorphic computing logic contract for face encrypted data and monitoring encrypted data, while ensuring data privacy, homomorphic encryption can perform specific operations in the ciphertext state with the help of the homomorphic computing logic contract. The monitoring data fragments are sent to the cloud storage center, and the face data fragments are sent to IPFS. The face hash value group returned by the cloud storage center based on the monitoring data fragments is received, and the monitoring hash value group returned by IPFS based on the face data fragments is received. The advantages of different storage systems are used to store different types of data respectively, and associations are established through the hash value group to achieve distributed storage and effective indexing of data. The cloud storage center or / and IPFS call the homomorphic computing logic contract to give the calculation result; with the help of the lifecycle policy, the effective usage time range of the data is clarified. During the data lifecycle, the cloud storage center or / and IPFS can call key information such as relevant hash value groups and homomorphic computing logic contracts from the blockchain according to the rules, and then through homomorphic encryption operations, without decrypting each data fragment, temporarily reorganize the ability to access data according to specific logic, realizing compliant invocation and processing of data, and meeting various requirements in the security monitoring process. Once the data reaches the expiration date specified by the lifecycle, because the entire process encrypts and fragments the data, even if the data fragments still exist, the logic for reorganizing and accessing data, which is bound to the lifecycle policy, will become invalid. At the same time, the face data and monitoring data are encrypted and exist in ciphertext form. Then, in the subsequent platform processing process, even if the platform receives these encrypted ciphertext data, it can perform corresponding ciphertext operations without knowing the plaintext content of the data according to the operation rules supported by homomorphic encryption, and finally obtain the result that meets the user's needs. This benefits from the characteristics of homomorphic encryption, which not only ensures that the privacy of data is not known to the platform party during the transmission and processing links, but also allows users to rest assured to hand over the data to the platform. To sum up, the design of the entire system makes the confidentiality and inaccessibility of data achieve an effect similar to complete deletion. On the one hand, due to following the lifecycle policy, users cannot obtain the encrypted data through conventional channels after the expiration date; on the other hand, although the platform retains fragmented data fragments, because there is no chance to obtain the key throughout the process, these fragments cannot be reorganized and restored into meaningful data at all. From the actual effect, it is equivalent to completely deleting the expired data, which not only complies with the compliance requirements of data management, but also avoids risks such as privacy leakage that may be caused by data residue.
[0069] The above embodiments effectively solve the thorny problem of difficultly deleting data from different channels to a certain extent. However, during the actual application process, a new situation has emerged that needs attention. That is, the final result obtained is not calculated within the local system, but is given after the corresponding operations are completed by an external storage system (such as a cloud storage center, IPFS, etc.) with the help of a homomorphic computing logic contract. Since the calculation is performed by an external storage system, many potential risks are likely to occur, resulting in errors in the result. After all, for these external storage systems, as mentioned above, they only execute operation operations according to the established homomorphic computing logic contract. In fact, they do not know what the specific meaning of the data being processed is, nor can they accurately know whether such a calculation meets the actual requirements and is completely correct. They just mechanically process the encrypted data in ciphertext according to the operation rules specified in the contract, and cannot judge the rationality and accuracy of the calculation from the perspective of the meaning of the data itself and the business logic. Therefore, it is very easy to have a situation where the calculation result does not match the expectation, which in turn affects the effectiveness and reliability of the entire security monitoring data processing process.
[0070] Please refer to Figure 3 , Figure 3 which is another process schematic diagram of the data processing method for security monitoring in the embodiments of the present application; Therefore, in some embodiments, step S106 specifically includes: S201. The cloud storage center or / and IPFS searches for the corresponding face data segment or / and monitoring data segment of the face data or / and monitoring data involved in the request; As mentioned above, the face data and monitoring data mentioned in step S106 are specific, and are the corresponding data selected based on specific requirements and specific conditions. The face data or / and monitoring data involved in the request here are the corresponding data selected based on specific requirements and specific conditions.
[0071] Specifically, the cloud storage center or / and IPFS will first analyze the received request content, extract the key information involved, such as elements such as the time range, specific area, and data type (whether it is face data or monitoring data, etc.) targeted by the request. Then, relying on these key information, combined with the index mechanism established when storing data segments before (such as using a hash value group as an index and finding through the corresponding relationship between the hash value and the data segment), filter and compare in the large number of data segments stored respectively, so as to locate the corresponding face data segment or / and monitoring data segment of the face data or / and monitoring data involved in the request.
[0072] S202. If the cloud storage center and / or IPFS find all the face data fragments and / or surveillance data fragments corresponding to the involved face data and / or surveillance data, the cloud storage center and / or IPFS will integrate all the face data fragments and / or surveillance data fragments corresponding to the involved face data and / or surveillance data into a data batch; Specifically, the cloud storage center and / or IPFS will sort and summarize all the found relevant data fragments according to the original logical relationships of the data (such as chronological order, spatial association, data source, etc.) and the preset integration rules. For example, if they are surveillance data fragments and these fragments are collected by the same camera at different time periods, they can be arranged and integrated in chronological order; for face data fragments, if they are face information captured from different angles of the same area, they can be combined according to certain angle sequences or person identifiers and other rules. In this way, all relevant data fragments are integrated into a data batch, enabling subsequent operations such as data transmission, storage backup, or homomorphic computing to be processed in batches with this data batch as the unit, reducing the cumbersome process of operating on each data fragment one by one and improving the integrity and efficiency of the operations.
[0073] S203. The cloud storage center and / or IPFS generate an aggregation commitment for the data batch, and the aggregation commitment indicates that all the fragments in the data batch exist and are not publicly disclosed; Specifically, the cloud storage center and / or IPFS will use specific cryptographic algorithms (such as a combined algorithm based on hash functions, digital signatures, and other related technologies) to process all the data fragments in the integrated data batch, perform comprehensive operations and encoding on the key feature information of these data fragments (such as the hash value and length of the data fragments), and generate a unique aggregation commitment identifier. This identifier is tightly bound to this data batch and represents the specific status and integrity of this batch of data.
[0074] S204. The cloud storage center and / or IPFS supervise the operation of the homomorphic computing logic contract according to the aggregation commitment; among them, it is verified that all the fragments in the data batch are used and have a successful receipt.
[0075] Specifically, after the homomorphic computing logic contract starts running, the cloud storage center and / or IPFS will monitor the operation of the contract on data batches in real time. On the one hand, by aggregating the information contained in the commitment (such as the characteristic information of data fragments, etc.), it is compared whether the data used by the contract is indeed all the fragments within the data batch, preventing the situation of omission or incorrect use of other data. On the other hand, it will track the process of each data fragment participating in the operation. After a data fragment is used, it waits to receive the corresponding successful receipt. If no receipt is received within the specified time or a receipt indicating operation failure is received, corresponding measures will be taken in a timely manner (such as pausing the contract operation, reinitiating the operation, etc.) to ensure the smooth and accurate progress of the entire computing process.
[0076] It can be seen that the cloud storage center and / or IPFS search for the face data fragments or / and monitoring data fragments corresponding to the face data or / and monitoring data involved in the request to ensure that subsequent operations focus on the correct data objects and avoid interference from invalid data. When all relevant data fragments are successfully found, the cloud storage center and / or IPFS integrate all the face data fragments or / and monitoring data fragments corresponding to the face data or / and monitoring data involved into a data batch. By integrating to form a data batch, it is convenient for unified management and batch processing. The cloud storage center and / or IPFS generate an aggregation commitment for the data batch. The aggregation commitment indicates that all the fragments within the data batch exist and are not publicly disclosed. The generation of this aggregation commitment is crucial. Without revealing the specific content of the fragments, it provides a hidden and effective way to verify data integrity, which can not only protect data privacy but also confirm the validity of the data batch. Then the cloud storage center and / or IPFS supervise the operation of the homomorphic computing logic contract according to the aggregation commitment; among them, it verifies that all the fragments within the data batch are used and have successful receipts. By using the aggregation commitment to supervise the operation of the homomorphic computing logic contract, it can ensure that each data fragment participates as required and the operation is successful during the computing process, preventing data loss or incorrect use, and ensuring the accuracy and credibility of the homomorphic computing results in a confidential scenario.
[0077] The following introduces the exemplary security monitoring data processing system 400 provided by the embodiments of the present application. Figure 4 It is an exemplary hardware structure diagram of the security monitoring data processing system 400 provided by the embodiments of the present application.
[0078] In some embodiments, the data processing system 400 of the security monitoring is a computer device or the data processing system 400 of the security monitoring includes a computer device. The computer device includes a processor, a memory, and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data. The network interface of the computer device is used to communicate with other external terminals or servers through a network connection. In some embodiments, the network interface can be a wired network interface, and in some embodiments, the network interface can also be a wireless network interface. The computer program, when executed by the processor, implements the method in the embodiments of the present application.
[0079] Those skilled in the art can understand that Figure 4 the structure shown in is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have a different component layout.
[0080] As mentioned above, the above embodiments are only used to illustrate the technical solutions of the present application, and are not intended to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.
[0081] As used in the above embodiments, depending on the context, the term when... can be interpreted to mean if... or after... or in response to determining... or in response to detecting.... Similarly, depending on the context, the phrase upon determining... or if detecting (the stated condition or event) can be interpreted to mean if determining... or in response to determining... or when detecting (the stated condition or event) or in response to detecting (the stated condition or event).
[0082] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from a website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, digital subscriber line) or a wireless manner (such as infrared, wireless, microwave, etc.). The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more integrated available media. The available medium may be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid-state drive), etc.
[0083] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by a computer program instructing relevant hardware. The program can be stored in a computer-readable storage medium. When the program is executed, it may include the processes of the above method embodiments. The foregoing storage medium includes: various media that can store program codes such as ROM or random access memory RAM, magnetic disks, or optical discs.
Claims
1. A data processing method for security monitoring, characterized in that, Including: Obtaining face data and monitoring data, where the face data is obtained by recognizing the monitoring data; Encrypting the face data and the monitoring data to generate encrypted face data and encrypted monitoring data, and generating a homomorphic computing logic contract for the encrypted face data and the encrypted monitoring data using a preset homomorphic encryption scheme; Respectively splitting the encrypted face data and the encrypted monitoring data into multiple face data segments and monitoring data segments; Sending the monitoring data segments to a cloud storage center, sending the face data segments to IPFS, receiving a face hash value group returned by the cloud storage center based on the monitoring data segments, and receiving a monitoring hash value group returned by IPFS based on the face data segments, where the face hash value group is the storage address of the monitoring data segments in the cloud storage center, and the face hash value group is the storage address of the face data segments in IPFS; Storing the monitoring hash value group, the face hash value group, and the homomorphic computing logic contract in a blockchain, and the homomorphic computing logic contract is associated with a predefined lifecycle policy; Sending a request for the face data or / and the monitoring data to the cloud storage center or / and IPFS; causing the cloud storage center or / and IPFS to call the homomorphic computing logic contract to give a calculation result; Decrypting the encryption result using the secret key corresponding to the encrypted face data or / and the secret key corresponding to the encrypted monitoring data.
2. The method according to claim 1, characterized in that, The step of causing the cloud storage center or / and IPFS to call the homomorphic computing logic contract to give a calculation result specifically includes: The cloud storage center or / and IPFS calling the monitoring hash value group, the face hash value group, and the homomorphic computing logic contract from the blockchain; The cloud storage center or / and IPFS obtaining the current time and performing a time check based on the current time and the predefined lifecycle policy; If the time check result passes, the cloud storage center or / and IPFS obtaining the monitoring data segments or / and the face data segments from the corresponding storage locations based on the monitoring hash value group or / and the face hash value group; The cloud storage center or / and IPFS combining the monitoring data segments or / and the face data segments to obtain the face data or / and the monitoring data; The cloud storage center or / and IPFS running the homomorphic computing logic contract to obtain a calculation result; If the time check result fails, rejecting the request.
3. The method according to claim 2, wherein The step of the cloud storage center or / and IPFS running the homomorphic computing logic contract to obtain a calculation result specifically includes: The cloud storage center or / and IPFS searching for the face data segments or / and the monitoring data segments corresponding to the face data or / and the monitoring data involved in the request; If the cloud storage center and / or the IPFS find all the face data segments and / or surveillance data segments corresponding to the involved face data and / or surveillance data, the cloud storage center and / or the IPFS integrate all the face data segments and / or surveillance data segments corresponding to the involved face data and / or surveillance data into a data batch; The cloud storage center and / or the IPFS generate an aggregation commitment for the data batch, and the aggregation commitment indicates that all the segments in the data batch exist and are not disclosed; The cloud storage center and / or the IPFS supervise the operation of the homomorphic computing logic contract according to the aggregation commitment; wherein it is verified that all the segments in the data batch are used and have successful receipts.
4. The method according to claim 2, characterized in that, After the step of rejecting the request if the time check result fails; The cloud storage center and / or the IPFS mark the corresponding surveillance data segments and / or face data segments as being in a state where they can be overwritten.
5. The method according to claim 1, characterized in that, The step of encrypting the face data and the surveillance data to generate face encrypted data and surveillance encrypted data specifically includes: Dynamically encrypting the face data and the surveillance data to generate the face encrypted data and the surveillance encrypted data; wherein the face data or the surveillance data corresponds to a separate secret key.
6. The method according to claim 1, wherein The step of separately splitting the face encrypted data and the surveillance encrypted data into multiple face data segments and surveillance data segments specifically includes: Wherein the sizes of the face encrypted data and the surveillance encrypted data are positively correlated with the numbers of the face data segments and the surveillance data segments.
7. The method according to claim 1, characterized in that After the step of sending the face data segments to the IPFS, it further includes: The IPFS selects at least two target storage nodes for each of the face data segments; Storing the face data segments into their corresponding target storage nodes respectively.
8. A data processing system for preventing monitoring, characterized in that, The anti-surveillance data processing system includes: one or more processors and a memory; the memory is coupled to the one or more processors, the memory is used to store computer program code, the computer program code includes computer instructions, and the one or more processors call the computer instructions to enable the anti-surveillance data processing system to execute the method according to any one of claims 1-7.
9. A computer program product comprising instructions, characterized in that, When the computer program product runs on the anti-surveillance data processing system, it enables the anti-surveillance data processing system to execute the method according to any one of claims 1-7.
10. A computer-readable storage medium, comprising instructions, characterized in that, When the instruction runs on the anti-surveillance data processing system, it enables the anti-surveillance data processing system to execute the method according to any one of claims 1-7.
Citation Information
Patent Citations
Data processing methods, devices, video surveillance systems, and storage media
CN114398449B