Bit stream, bit stream signature and authentication method

By calculating summary data with layer units as granularity and generating authentication data, the problem of access unit failure during bitstream signature or authentication is solved, and more efficient data utilization and transmission efficiency is achieved, ensuring the security and integrity of audio and video content.

CN120372694APending Publication Date: 2025-07-25HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410176090.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-01-24
Filing Date
2024-02-07
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

In the prior art, the bitstream signature or authentication process calculates summary data with the access unit as a granularity, resulting in the entire access unit being invalid when frames, packets are lost or authentication fails during transmission, and the integrity and security of audio and video content cannot be effectively guaranteed.

Method used

The layer unit is used to calculate the summary data as a granularity, and by signing the summary data of each layer unit in a set of layer units of the bitstream, authenticating data is generated, and only the corresponding layer unit is invalid during the transmission process, reducing data loss, and improving data utilization and transmission efficiency.

Benefits of technology

During the transmission process, only the layer units that fail authentication are invalid, reduce data loss, improve the utilization rate and transmission efficiency of bitstream data, and enhance the security and integrity of audio and video content.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120372694A_ABST
    Figure CN120372694A_ABST
Patent Text Reader

Abstract

The invention discloses a bit stream, a bit stream signature and an authentication method, and relates to the technical field of multimedia. The bit stream signature method comprises the steps that the computing device obtains authentication data and then outputs a bit stream, and the bit stream comprises the authentication data. Wherein the authentication data comprises signature data, the signature data is obtained by performing signature according to abstract data of each layer unit in a group of layer units of the bit stream, and one layer unit in the group of layer units comprises a network abstraction layer (NAL) unit with the same layer identifier in the bit stream. The abstract data is calculated by taking the layer unit as granularity, so that only the corresponding layer unit fails under the conditions of frame loss, packet loss or layer unit authentication failure and the like in the transmission process. If only the layer unit which fails to be authenticated loses efficacy, that is, the lost data is less, the utilization rate of the data in the bit stream can be improved, and the transmission efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims the priority of a Chinese patent application with the application number 202410104600.6 and the application title "A Bitstream, Bitstream Signature and Authentication Method" filed on January 24, 2024, the entire content of which is incorporated herein by reference. Technical Field

[0002] This application relates to the field of multimedia technologies, and in particular, to a bitstream, bitstream signature and authentication method. Background Art

[0003] In many audio and video encoding and decoding scenarios (such as surveillance, live broadcast, video-on-demand, etc.), there are certain requirements for the authenticity and integrity of audio and video content; therefore, in order to ensure the security of audio and video content during transmission and prevent the audio and video content from being tampered with during transmission, it is necessary to sign the audio and video content.

[0004] Currently, the process of signing a bitstream is as follows: generate the digest corresponding to each access unit in the bitstream, and then use a digital signature algorithm to sign the digest, and thus write the signature into the bitstream. However, during the signature or authentication process, the digest data is calculated at the granularity of access units. If frames or packets are lost during transmission or the authentication fails, etc., the entire access unit will become invalid (unusable). Summary of the Invention

[0005] This application provides a bitstream, bitstream signature and authentication method to solve the problem that during the signature or authentication process, the digest data is calculated at the granularity of access units, and if frames or packets are lost during transmission or the authentication fails, etc., the entire access unit will become invalid.

[0006] This application adopts the following technical solutions.

[0007] In a first aspect, an embodiment of this application provides a bitstream signature method. This bitstream signature method is executed by a computing device or a chip in the computing device. For example, the computing device may refer to a mobile phone, a computer, etc. Exemplarily, the method includes: the computing device obtains authentication data, and then outputs a bitstream, and the bitstream includes the authentication data. The authentication data includes signature data, and the signature data is obtained by signing the digest data of each layer unit in a group of layer units of the bitstream. A layer unit in the group of layer units includes network abstraction layer (NAL) units with the same layering identifier.

[0008] In this application, the summary data is calculated at the granularity of layer units, which can achieve that only the corresponding layer unit fails in case of frame loss, packet loss or layer unit authentication failure during the transmission process. For example, if only the layer unit with authentication failure fails, that is, less data is lost, the utilization rate of data in the bitstream can be improved and the transmission efficiency can be enhanced.

[0009] In a possible scenario, one layer unit in a group of layer units includes network abstraction layer units with the same layering identifier in one access unit in the bitstream.

[0010] In a possible scenario, the authentication data of a group of layer units corresponds to the security parameter set.

[0011] In a possible implementation manner, the authentication data further includes the summary data of each layer unit in a group of layer units.

[0012] In a possible implementation manner, the summary data respectively corresponding to multiple layer units in a group of layer units are arranged in sequence according to the bitstream order of the multiple layer units in the authentication data.

[0013] In a possible implementation manner, a group of layer units includes a first layer unit, and the above bitstream signature method further includes: the computing device arranges the network abstraction layer units included in the first layer unit in the bitstream order and then performs summary calculation to obtain the summary data of the first layer unit.

[0014] In a possible implementation manner, the above bitstream signature method further includes: the computing device determines the secondary summary data of a group of layer units according to the summary data of each layer unit in the group of layer units, and then signs the secondary summary data with a private key to obtain the signature data.

[0015] In a possible scenario, the secondary summary data is obtained by concatenating the (n + 1)-th combined summary data and the summary data of the (n + 2)-th layer unit in the bitstream order, calculating the summary of the concatenated data to obtain the (n + 2)-th combined summary data, until the summary data of each layer unit in the group of layer units participates in the concatenation; the (n + 1)-th combined summary data is obtained by calculating the summary after concatenating the n-th combined summary data and the summary data of the (n + 1)-th layer unit, where n is a positive integer.

[0016] In a possible scenario, the secondary summary data is obtained by concatenating the second summary data of each layer unit in a group of layer units and calculating the secondary summary of the concatenated second summary data.

[0017] In a possible implementation manner, the maximum number of layer units included in a group of layer units is determined according to the hash period and the number of spatial layer divisions.

[0018] In a possible implementation, the decoding order of multiple network abstraction layer units included in a layer unit and having the same layering identifier is consecutive.

[0019] In a possible implementation, the network abstraction layer units included in a layer unit have the same authentication identifier value and the authentication identifier is greater than 0.

[0020] In a possible implementation, the computing device obtains authentication data, including: the computing device generates the authentication data.

[0021] In a possible implementation, before the computing device outputs the bitstream, the above bitstream signature method further includes: the computing device adds the authentication data to the bitstream.

[0022] In a second aspect, an embodiment of the present application provides a bitstream. The bitstream includes a set of layer units and authentication data. Among them, the authentication data includes signature data, and the signature data is obtained by signing the digest data of each layer unit in a set of layer units of the bitstream. A layer unit in the set of layer units includes network abstraction layer units having the same layering identifier.

[0023] In a possible implementation, the authentication data further includes the digest data of each layer unit in the set of layer units.

[0024] In a possible implementation, the digest data respectively corresponding to multiple layer units in the set of layer units are arranged in sequence in the authentication data according to the bitstream order of the multiple layer units.

[0025] In a possible implementation, the decoding order of multiple network abstraction layer units included in a layer unit and having the same layering identifier is consecutive.

[0026] In a possible implementation, the network abstraction layer units included in a layer unit have the same authentication identifier value and the authentication identifier is greater than 0.

[0027] In a possible implementation, the maximum number of layer units included in a set of layer units is determined according to the hash period and the number of spatial domain layers.

[0028] In a third aspect, an embodiment of the present application provides a bitstream authentication method. The bitstream authentication method is executed by a computing device or a chip in the computing device. For example, the computing device may be a mobile phone or a computer, etc. Exemplarily, the method includes: the computing device determines first digest data of each layer unit in a group of layer units in the bitstream, and then obtains authentication data from the bitstream. If the signature data is successfully verified, then according to the first digest data of each layer unit in a group of layer units in the bitstream, multiple second digest data in the authentication data are verified. Wherein, one layer unit in a group of layer units includes network abstraction layer units with the same layering identifier. The authentication data includes: signature data and second digest data of each layer unit in a group of layer units, and the signature data is obtained by signing the second digest data of each layer unit in a group of layer units.

[0029] In a possible scenario, one layer unit in a group of layer units includes network abstraction layer units with the same layering identifier in one access unit in the bitstream.

[0030] In a possible implementation, the first digest list includes the first digest data of each layer unit in a group of layer units, and the second digest list includes the second digest data of each layer unit in a group of layer units. The method further includes: matching the identifier of the first digest list with the identifier of the second digest list; the identifier includes an authentication data identifier and / or a security parameter set identifier ID; if the identifier of the first digest list is consistent with the identifier of the second digest list, then execute verifying multiple second digest data in the authentication data according to the first digest data of each layer unit in a group of layer units in the bitstream.

[0031] In a possible implementation, the maximum number of layer units included in a group of layer units is determined according to the hash period and the number of spatial layering levels.

[0032] In a possible implementation, the second digest data respectively corresponding to multiple layer units in a group of layer units are arranged in sequence in the authentication data according to the bitstream order of the multiple layer units.

[0033] In a possible implementation, the computing device verifies multiple second digest data in the authentication data according to the first digest data of each layer unit in a group of layer units in the bitstream, including: the computing device sequentially matches the first digest data with the second digest data according to the arrangement order of the multiple second digest data in the authentication data and the multiple first digest data of a group of layer units. If the match is successful, the layer unit of the successfully matched first digest data is successfully authenticated; if the match fails, the layer unit of the failed-matched first digest data is failed to be authenticated.

[0034] In a possible implementation, the above bitstream authentication method further includes: the computing device obtains a public key, and then determines second-level digest data corresponding to a set of layer units according to the second digest data of each layer unit included in the authentication data, and then verifies the signature data according to the public key, the second-level digest data, and the signature algorithm.

[0035] In a possible implementation, the second-level digest data is obtained by concatenating the (n + 1)-th combined digest data and the second digest data of the (n + 2)-th layer unit in the bitstream order, calculating the digest of the concatenated data to obtain the (n + 2)-th combined digest data, until the second digest data of each layer unit in a set of layer units participates in the concatenation; the (n + 1)-th combined digest data is obtained by calculating the digest after concatenating the n-th combined digest data and the second digest data of the (n + 1)-th layer unit, where n is a positive integer.

[0036] In a possible implementation, the second-level digest data is obtained by concatenating the second digest data of each layer unit in a set of layer units and calculating the digest of the concatenated second digest data.

[0037] Fourthly, an embodiment of the present application provides a bitstream authentication method. This bitstream authentication method is executed by a computing device or a chip in the computing device. For example, the computing device may refer to a mobile phone, a computer, etc. Exemplarily, the method includes: the computing device determines first digest data of a set of layer units of a bitstream, and then obtains authentication data from the bitstream, so as to verify the signature data by using the first digest data. Among them, the authentication data includes signature data, and the signature data is obtained by signing according to the second digest data of each layer unit in a set of layer units, and one layer unit in the set of layer units includes network abstraction layer units with the same layering identifier.

[0038] In a possible case, the set of layer units corresponding to the third digest list is sorted before the set of layer units corresponding to the first digest list in the bitstream.

[0039] In a possible implementation, the computing device determines first digest data of a set of layer units of a bitstream, including: the computing device determines third digest data of each layer unit in a set of layer units of the bitstream, and then determines first digest data corresponding to the set of layer units according to the third digest data of each layer unit in the set of layer units.

[0040] In a possible implementation, the computing device determines first digest data corresponding to a set of layer units according to the third digest data of each layer unit in the set of layer units, including: the computing device concatenates the (n + 1)-th combined digest data and the third digest data of the (n + 2)-th layer unit in the bitstream order, calculates the digest of the concatenated data to obtain the (n + 2)-th combined digest data, until the third digest data of each layer unit in the set of layer units participates in the concatenation to obtain the first digest data; the (n + 1)-th combined digest data is obtained by calculating the digest after concatenating the n-th combined digest data and the third digest data of the (n + 1)-th layer unit, where n is a positive integer.

[0041] In a possible implementation, the computing device determines first digest data corresponding to a set of layer units according to the third digest data of each layer unit in the set of layer units, including: the computing device concatenates the third digest data of each layer unit in the set of layer units to obtain the concatenated third digest data, and then calculates the digest of the concatenated third digest data to obtain the first digest data.

[0042] In a possible implementation, the computing device verifies signature data by using the first digest data, including: the computing device obtains a public key, and then verifies the signature data according to the public key, the first digest data, and a signature algorithm.

[0043] In a possible implementation, the above bitstream authentication method includes: the computing device matches the identifier of the first digest data with the identifier of the authentication data; the identifier includes an authentication data identifier and / or a security parameter set identifier ID, and if the identifier of the first digest data matches the identifier of the authentication data, then the computing device executes verifying the signature data by using the first digest data.

[0044] In a possible implementation, the maximum number of layer units included in a set of layer units is determined according to a hash period and the number of spatial domain layers.

[0045] In a fifth aspect, the present application provides a bitstream signature device. The bitstream signature device includes a module for executing the method of the first aspect or any possible implementation manner in the first aspect.

[0046] In a sixth aspect, the present application provides a bitstream authentication device. The bitstream authentication device includes a module for executing the method of the third aspect or any possible implementation manner in the third aspect, or the bitstream authentication device includes a module for executing the method of the fourth aspect or any possible implementation manner in the fourth aspect.

[0047] In a seventh aspect, an embodiment of the present application provides a computing device, including: a memory and a processor; the memory stores program instructions, and when the program instructions are executed by the processor, the computing device is caused to execute the bitstream signature method in the first aspect or any possible implementation manner of the first aspect, or execute the bitstream authentication method in the third aspect or any possible implementation manner of the third aspect, or execute the bitstream authentication method in the fourth aspect or any possible implementation manner of the fourth aspect.

[0048] In an eighth aspect, an embodiment of the present application provides a chip, including one or more interface circuits and one or more processors; the one or more processors receive or send data through the one or more interface circuits, and when the one or more processors execute computer instructions, the steps of the bitstream signature method in the first aspect or any possible implementation manner of the first aspect are caused to be executed, or the steps of the bitstream authentication method in the third aspect or any possible implementation manner of the third aspect are caused to be executed, or the steps of the bitstream authentication method in the fourth aspect or any possible implementation manner of the fourth aspect are caused to be executed.

[0049] In a ninth aspect, an embodiment of the present application provides a non-transitory computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program runs on a computer or a processor, the computer or the processor is caused to execute the bitstream signature method in the first aspect or any possible implementation manner of the first aspect, or execute the bitstream authentication method in the third aspect or any possible implementation manner of the third aspect, or execute the bitstream authentication method in the fourth aspect or any possible implementation manner of the fourth aspect.

[0050] In a tenth aspect, an embodiment of the present application provides a computer program product. The computer program product includes computer instructions, and when the computer instructions are executed by a computer or a processor, the computer or the processor is caused to execute the bitstream signature method in the first aspect or any possible implementation manner of the first aspect, or execute the bitstream authentication method in the third aspect or any possible implementation manner of the third aspect, or execute the bitstream authentication method in the fourth aspect or any possible implementation manner of the fourth aspect.

[0051] In an eleventh aspect, an embodiment of the present application provides a non-transitory computer-readable storage medium. The computer-readable storage medium stores the bitstream in the second aspect or any possible implementation manner of the second aspect.

[0052] In a twelfth aspect, an embodiment of the present application provides a device for storing a bitstream. The device includes: a receiver and at least one storage medium, and the receiver is configured to receive the bitstream in the second aspect or any possible implementation manner of the second aspect.

[0053] In a thirteenth aspect, an embodiment of the present application provides a device for transmitting a bitstream. The device includes: a transmitter and at least one storage medium. The at least one storage medium is used to store the bitstream in the second aspect or any possible implementation manner of the second aspect; the transmitter is used to obtain the bitstream from the storage medium and send the bitstream to an end-side device through a transmission medium.

[0054] In a fourteenth aspect, an embodiment of the present application provides a system for distributing a bitstream. The system includes: at least one storage medium for storing at least one bitstream in the second aspect or any possible implementation manner of the second aspect; a streaming media device for obtaining a target bitstream from the at least one storage medium and sending the target bitstream to an end-side device, where the streaming media device includes a content server or a content distribution server.

[0055] Regarding the beneficial effects of the second aspect to the fourteenth aspect, reference may be made to the description of any implementation manner in the first aspect or the second aspect, which will not be elaborated here. Based on the implementation manners provided in the above aspects of the present application, further combinations can be made to provide more implementation manners. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] Figure 1 It is a schematic diagram of an application scenario provided by the present application;

[0057] Figure 2 It is a schematic diagram of the structure of a signature and authentication system provided by the present application;

[0058] Figure 3 It is a schematic flowchart of a bitstream signature method provided by the present application Figure 1 ;

[0059] Figure 4a It is a schematic flowchart of a bitstream signature method provided by the present application Figure 2 ;

[0060] Figure 4b It is a schematic diagram of a connection summary provided by the present application;

[0061] Figure 4c It is a schematic diagram of a tree top summary provided by the present application;

[0062] Figure 5 It is a schematic flowchart of a bitstream authentication method provided by the present application Figure 1 ;

[0063] Figure 6 It is a schematic flowchart of a bitstream authentication method provided by the present application Figure 2 ;

[0064] Figure 7 It is a schematic diagram of a bitstream signature device provided by the present application;

[0065] Figure 8a Schematic diagram of the bitstream authentication device provided by this application Figure 1 ;

[0066] Figure 8b Schematic diagram of the bitstream authentication device provided by this application Figure 2 ;

[0067] Figure 9 Schematic structural diagram of the computing device provided by this application. Detailed implementation manners

[0068] This application provides a bitstream signature method, which includes: a computing device obtains authentication data, and then outputs a bitstream, where the bitstream includes the authentication data. Among them, the authentication data includes signature data, and the signature data is obtained by signing the digest data of each layer unit in a group of layer units of the bitstream. One layer unit in the group of layer units includes network abstraction layer units with the same layering identifier.

[0069] In this application, calculating the digest data with layer units as the granularity can achieve that only the corresponding layer unit fails in the case of frame loss, packet loss or layer unit authentication failure during transmission. For example, if only the layer unit with authentication failure fails, that is, less data is lost, the utilization rate of the data in the bitstream can be improved, and the transmission efficiency can be enhanced.

[0070] Next, the technical solutions in the embodiments of this application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the following described embodiments are some, but not all, of the embodiments of this application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the protection scope of this application.

[0071] The term "and / or" in this article is merely a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. These three situations.

[0072] The terms "first" and "second" etc. in the description and claims of the embodiments of this application are used to distinguish different objects, rather than to describe a specific order of the objects. For example, the first target object and the second target object etc. are used to distinguish different target objects, rather than to describe a specific order of the target objects.

[0073] In the embodiments of the present application, words such as "exemplarily" or "for example" are used to represent examples, illustrations, or explanations. Any embodiment or design solution described as "exemplarily" or "for example" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplarily" or "for example" is intended to present relevant concepts in a specific manner.

[0074] In the description of the embodiments of the present application, unless otherwise specified, "a plurality of" means two or more. For example, a plurality of processing units means two or more processing units; a plurality of systems means two or more systems.

[0075] The following provides an introduction to related technologies.

[0076] A bitstream is a binary data stream formed by encoding image / audio frames. Both the NAL unit stream and the byte stream can be referred to as bitstreams.

[0077] A NAL unit (NAL unit) is a syntax structure that contains a type indication of the subsequent data and the number of bytes contained (located in the NAL header), and the data appears in the form of a raw byte sequence payload (RBSP), and may also include scattered anti-counterfeiting bytes when necessary. For example, a NAL unit includes a security parameter set NAL unit (which can also be referred to as a security data set) or an authentication data NAL unit (which can also be referred to as authentication data).

[0078] A layer unit (LU) is a set of NAL units with the same layer identifier (layer_id) value that are associated with each other according to specified rules and are consecutive in decoding order.

[0079] An access unit (AU) is a group of NAL units that are associated with each other according to specified rules and are consecutive in decoding order, constituting a compressed video bitstream (which can also be referred to as a bitstream). A bitstream represents a binary data stream formed by encoding image / audio frames.

[0080] A data unit is a basic syntax structure of an encoded bitstream, which can be a NAL unit, a layer unit, or an access unit. This data unit can also be referred to as a basic unit or a basic data unit.

[0081] It should be noted that from another dimension, a layer unit can also include an encoded image.

[0082] A coded picture is an encoded representation of a frame of an image.

[0083] An encoded video sequence, which is the highest-level syntax structure of a bitstream, contains one or more consecutive access units. An encoded video sequence starts with an access unit of an IDR picture (instantaneous decoding refresh picture), an access unit of a RAPI picture (random access point I picture), an access unit of a leading library picture of an RL picture, or an access unit of a display library picture. The stream-ending NAL unit or the sequence-ending NAL unit of an encoded video sequence indicates the end of an encoded video sequence. Each encoded video sequence contains at most one IDR picture, RAPI picture, leading library picture of an RL picture, or display library picture. The access units are arranged in bitstream order in the bitstream, and the bitstream order should be the same as the decoding order. The decoding order may not be the same as the display order.

[0084] The RBSP of a security parameter set (SEC) includes parameters that can be used by one or more other types of NAL units. The aforementioned parameters are configuration parameters required for signing and authenticating operations on the compressed video bitstream. Library pictures are encrypted or authenticated independently of display pictures, and the security parameter set for library pictures in the security parameter set RBSP is distinguished by the library picture flag (sec_is_library_flag). The bitstream may contain multiple security parameter sets, which are distinguished by the security parameter set ID (sec_para_set_id), and at most 3 security parameter sets are supported simultaneously. A security parameter set NAL unit should exist before the random access point access unit of a random access segment (RAS) or the first library picture access unit, and it acts on the current RAS or library picture, providing parameters for the encryption and authentication of the current RAS or library picture access unit. In the case of multiple security parameter sets, the sec_para_set_id is used for distinction; if a security parameter set NAL unit does not exist in the random access point access unit of a RAS, it is considered that the current RAS (excluding non-display library picture access units) is not encrypted and not involved in authentication; if a security parameter set NAL unit does not exist in the first library picture access unit, it is considered that the current library picture is not encrypted and not involved in authentication. The security parameter set NAL unit should be in the same access unit as the sequence parameter set NAL unit, and the security parameter set NAL unit should be before the sequence parameter set NAL unit. If the access unit includes an access unit delimiter NAL unit, the security parameter set NAL unit should be after the access unit delimiter NAL unit.

[0085] Library picture, a reference picture other than the current bitstream used when decoding the current bitstream. Each picture corresponds to a sequence parameter set, and the coded picture with the knowledge bitstream flag being 1 in the corresponding sequence set parameters. The NAL unit type of the coded slice of the library picture is 12, 17, or 18, and the library picture is associated with the privacy coded slice.

[0086] Output library picture, each picture corresponds to a sequence parameter set, and the coded picture with the knowledge bitstream flag being 1 and the knowledge picture mode index being 1 in the corresponding sequence set parameters. The NAL unit type of the coded slice of the output library picture is 17. The output library picture is a random access point picture, and the output library picture as the leading library picture of an RL picture is not a random access point picture.

[0087] Non-output library picture, each picture corresponds to a sequence parameter set, and the coded picture with the knowledge bitstream flag being 1 and the knowledge picture mode index being 0 or 2 in the corresponding sequence set parameters. The NAL unit type of the coded slice of the non-output library picture is 12 or 18.

[0088] Leading library picture of an RL picture, a non-output library picture in the bitstream order before an associated RL picture or a newly appeared output library picture before an RL picture after bitstream editing, and there is no access unit of other pictures between the access unit where the first coded slice of the library picture is located and the access unit of the associated RL picture. The leading library picture of an RL picture is not a random access point picture.

[0089] It should be noted that if the leading library picture of an RL picture is an output library picture, the output library picture does not need to be output at this time, and it can be identified through the display information SEI payload of the output library picture (the library_display_flag should be '0').

[0090] Non-leading library picture of an RL picture, a non-output library picture in the bitstream order before an associated RL picture, and there is at least one access unit of other pictures between the access unit where the first coded slice of the non-output library picture is located and the access unit of the associated RL picture. The non-leading library picture of an RL picture is not a random access point picture.

[0091] Display image (output picture), which refers to the RL image, IDR image, P image, B image, or RAPI image reconstructed and output by the decoder after decoding. It should be noted that neither the display knowledge image nor the non-display knowledge image belongs to the display image defined in this case.

[0092] An image is a frame of a coded video sequence, and its coded data is contained in one or more access units. Its coded image consists of an image header NAL unit, supplementary enhancement information (if any), and all coded slice NAL units of this image. Specifically, the coded image of an IDR image includes an image header NAL unit, zero or more supplementary extension description NAL units of this IDR image, and all IDR image coded slice NAL units of this IDR image. The coded image of a RAPI image includes an image header NAL unit, zero or more supplementary extension description NAL units of this RAPI image, and all RAPI image coded slice NAL units of this RAPI image. The coded images of P images and B images include an image header NAL unit, zero or more supplementary extension description NAL units of this P image or B image, and all non-random access point picture (NRAP image) coded slice NAL units of this P image or B image. The coded image of an RL image includes an image header NAL unit, zero or more supplementary extension description NAL units of this RL image, and all RL image coded slice NAL units of this RL image. The coded image of a knowledge image consists of an image header NAL unit, one or more knowledge image coded slice NAL units, and one or more privacy image coded slice NAL units. The RL preamble knowledge image is continuous with the privacy image coded slice NAL units and all coded slice NAL units in the coded image of the display knowledge image. Its access unit contains all NAL units of the coded image. The coded slices of non-RL preamble knowledge images can be interleaved with the access units of display images as access units.

[0093] The first coded slice NAL unit of an image should immediately follow the image header NAL unit of this image. For the coded images of IDR images, RAPI images, RL images, or knowledge images, the image header NAL should immediately follow an image parameter set NAL unit, and this image parameter set NAL should immediately follow a sequence parameter set NAL unit.

[0094] In particular, one or more bitstreams of display images can be interleaved between multiple knowledge image bitstream slices of non-RL preamble knowledge images, but the interleaved display image bitstreams should not be access units of RL images, IDR images, or RAPI images. All knowledge image bitstream slices of an RL preamble knowledge image or a display knowledge image should be continuous. Each knowledge image bitstream slice can be interleaved with a privacy image coded slice NAL unit (if any) after it, but not with the bitstream of the display image.

[0095] The bitstreams of all slices of a knowledge image shall be located before the bitstream of the first RL image referring to the knowledge image. The knowledge image bitstream slices of different knowledge images shall not be interleaved. The knowledge image referred to by an RL image is the knowledge image represented by the access unit of the first knowledge image found in reverse order in the decoding order starting from the RL access unit in the bitstream.

[0096] It should be noted that this application does not group layer units or access units. Instead, for the convenience of description, the terms "a group of access units" and "a group of layer units" are used to describe.

[0097] Exemplarily, a group of layer units may include n layer units, and all these n layer units are layer units that need to be authenticated, where n is a positive integer. Correspondingly, the authentication data may include n digest data, and the n digest data correspond to the n layer units one by one. Exemplarily, "a group of layer units" may also be described as "n layer units".

[0098] Exemplarily, the multiple digest data of a group of layer units can form a digest data list; that is to say, the authentication data may include a digest data list.

[0099] Exemplarily, the authentication data may be Auth.

[0100] Exemplarily, the signature data may be signature.

[0101] Exemplarily, the digest data may also be referred to as authentication digest data or digest.

[0102] Exemplarily, the bitstream may be an audio compression bitstream (or referred to as an audio compression code stream) or a video compression bitstream (or referred to as a video compression code stream), and this application does not limit this. This application takes signing and authenticating a video compression bitstream as an example for illustration.

[0103] As Figure 1 shown, Figure 1 is a schematic diagram of the application scenario provided by this application. Figure 1 It shows a monitoring scenario, a live broadcast scenario, and an on-demand scenario.

[0104] Referring to Figure 1 , exemplarily, in the monitoring scenario, the camera 11 can sign the monitoring video bitstream to obtain the signed bitstream 101 of the monitoring video. Then, the signed bitstream 101 of the monitoring video is sent to the laptop 13 through the network 12. After that, the laptop 13 can authenticate the signed bitstream 101 of the monitoring video to obtain the authentication result 105 and display it, and play the monitoring video 104.

[0105] Referring to Figure 1, Exemplarily, in a live broadcast scenario, the mobile phone 14 can sign the live video bitstream to obtain the signed live video bitstream 102. Then, the signed live video bitstream 102 is sent to the mobile phone 15 through the network 12. After that, the mobile phone 15 can authenticate the signed live video bitstream 102 to obtain the authentication result 107 and display it, and play the live video 106.

[0106] Referring to Figure 1 , Exemplarily, in an on-demand scenario, the personal computer 16 can sign the on-demand video bitstream to obtain the signed on-demand video bitstream 103. Then, the signed on-demand video bitstream 103 is sent to the mobile phone 17 through the network 12. After that, the mobile phone 17 can authenticate the signed on-demand video bitstream 103 to obtain the authentication result 109 and display it, and play the on-demand video 108.

[0107] It should be understood that the present application can also be used in other scenarios of audio and video coding and decoding, such as digital content trust scenarios, etc., and the present application does not limit this.

[0108] As Figure 2 shown, Figure 2 is a schematic structural diagram of the signature and authentication system provided by the present application. The authentication and signature processes in the above Figure 2 are described below. Figure 1 in the authentication and signature processes in the above

[0109] Referring to Figure 2 , Exemplarily, the authentication and signature system 200 can include a signature end 210 and an authentication end 220.

[0110] For example, the signature end 210 can be the camera 11, the mobile phone 14, and the personal computer 16 in the above Figure 1 , and the authentication end 220 can be the laptop computer 13, the mobile phone 15, and the mobile phone 17 in the above Figure 1 .

[0111] It should be understood that the same terminal device can be used as both the signature end 210 and the authentication end 220, and the present application does not limit this.

[0112] Continuing to refer to Figure 2 , Exemplarily, after the signature end 210 obtains the video data 201, it can perform video encoding 21 on the video data 201 to obtain the bitstream 202; and perform video signature 22 on the bitstream 202 to obtain the signed bitstream 203.

[0113] For example, the video data 201 can be the surveillance video collected by the camera 11, the live video recorded by the mobile phone 14, or the on-demand video produced by the personal computer 16 in the above Figure 1 .

[0114] For example, the signed bit stream 203 may be Figure 1 The signed surveillance video bit stream 101, the signed live video bit stream 102 or the signed on-demand video bit stream 103.

[0115] It should be noted that the two operations of video encoding 21 and video signing 22 can be performed in parallel.

[0116] In a possible implementation, the signing end 210 may include an encoder, and the encoder performs video encoding 21 and video signing 22. In a possible implementation, the signing end 210 may include an encoder and a signature module, and the encoder performs video encoding 21 and the signature module performs video signing 22. In a possible implementation, the signing end 210 may include a signature module, and the signature module performs video encoding 21 and video signing 22.

[0117] Afterwards, the signing end 210 may send the signed bit stream 203 to the authenticating end 220 .

[0118] Continue to refer to Figure 2 For example, after receiving the signed bitstream 203, the authentication end 220 can perform video authentication 23 on the signed bitstream 203 to obtain an authentication result 205; and can perform video decoding 24 on the bitstream 202 in the signed bitstream 203 to obtain decoded video data 204.

[0119] For example, the decoded video data 204 may be the above Figure 1 The monitoring video 104, the live video 106 or the on-demand video 108.

[0120] For example, the authentication result 205 may be as described above. Figure 1 Authentication result 105, authentication result 107 or authentication result 109.

[0121] It should be noted that the two operations of video authentication 23 and video decoding 24 can be performed in parallel.

[0122] In a possible implementation, the authentication end 220 may include a decoder, and the decoder performs video decoding 24 and video authentication 23 .

[0123] In a possible implementation, the authentication end 220 may include a decoder and an authentication module, the decoder performs video decoding 24 and the authentication module performs video authentication 23.

[0124] In a possible implementation, the authentication end 220 may include an authentication module, and the authentication module performs video decoding 24 and video authentication 23 .

[0125] It should be noted that when the signing end 210 performs lossless encoding, the video data is the same as the decoded video data; when the signing end 210 performs lossy encoding, there are differences between the video data and the decoded video data.

[0126] It should be noted that the encoder, decoder, and authentication module can be implemented in software or in hardware, and the present application does not limit this.

[0127] The following describes in detail the implementation manner of the embodiments of the present application with reference to the accompanying drawings.

[0128] Figure 3 It is a flowchart of a bitstream signature method provided by the present application Figure 1 , and this bitstream signature method can be applied to Figure 2 the signature and authentication system shown in Figure 2 , for example, this bitstream signature method can be implemented by the processing device 300. In a possible example, the processing device 300 can be

[0129] S310. The processing device 300 obtains authentication data.

[0130] Among them, the authentication data includes signature data, and this signature data is obtained by signing the digest data of each LU in a group of LUs of the bitstream. One LU in a group of LUs includes NAL units with the same hierarchical identifier.

[0131] In a possible situation, the processing device 300 generates authentication data.

[0132] Hierarchical identifier (layer_id), a 2-bit unsigned integer, to indicate the hierarchical identifier of the current image. The value range of the hierarchical identifier is 0 to MAX_LAYER - 1. The layer_id of the picture header NAL unit and all coded slice NAL units of a coded picture should be the same. The value of LayerId is equal to the value of layer_id. The LayerId of a coded picture or layer unit is the LayerId of the coded slice NAL units within this coded picture or layer unit.

[0133] When the nal_unit_type of a NAL unit is 5, 7, 8, 9, 10, or 15, the LayerId should be 0.

[0134] When the nal_unit_type of a NAL unit is 6, and this NAL unit includes supplementary enhancement payloads with PayloadType of 19, 25, 26, or 127, the LayerId should be 0.

[0135] It should be noted that MAX_LAYER is specified by the grade.

[0136] The NAL unit type flag nal_unit_type, which is a 5-bit unsigned integer, represents the type of the RBSP data structure in the NAL unit. For the detailed content of nal_unit_type, reference can be made to the nal_unit_type description shown below Figure 4a and will not be elaborated here.

[0137] In a possible scenario, one LU in a group of LUs includes the NAL units with the same hierarchical identifier in an AU of the bitstream.

[0138] Exemplarily, when authentication needs to be supported, the number n of layer units to be authenticated can be determined. Here, n is a positive integer.

[0139] Refer to Figure 3 , exemplarily, the n layer units to be authenticated in bitstream a are respectively: layer unit 1, layer unit 2,..., layer unit n. These n layer units to be authenticated can be called a group of layer units. The group of layer units involved subsequently all refer to the layer units to be authenticated.

[0140] Exemplarily, refer to Figure 3 , the processing device 300 can independently calculate a digest data for each layer unit in a group of layer units by using a digest algorithm, and the digest data of each layer unit in the group of layer units can be obtained. The n digest data can include: digest data 1, digest data 2,..., digest data n; among them, the n digest data correspond to the n layer units one by one; for example, digest data 1 corresponds to layer unit 1, digest data 2 corresponds to layer unit 2,..., digest data n corresponds to layer unit n.

[0141] Exemplarily, the processing device 300 can perform digest calculation on the NAL units included in a layer unit arranged in the bitstream order to obtain the digest data of the layer unit.

[0142] For example, the processing device 300 splices the NAL units included in a group of layer units together and calculates the digest of the spliced NAL units to obtain the digest data of the layer unit.

[0143] Exemplarily, the processing device 300 can sign according to the digest of each layer unit in a group of layer units to obtain signature data (signature).

[0144] Exemplarily, the processing device 300 may generate authentication data (Auth) based on the signature data and the digest data of each layer unit in a set of layer units. In this way, the authentication data may be {digest data 1, digest data 2,..., digest data n, signature}.

[0145] Optionally, the digest data of each layer unit in a set of layer units in the authentication data may form a digest list (authentication_hash) {digest data 1, digest data 2,..., digest data n}.

[0146] In a possible example, the processing device 300 arranges the network abstraction layer units included in the first layer unit in the order of bit stream a and then calculates the digest using a digest algorithm to obtain the digest data of the first layer unit.

[0147] In a possible implementation manner, the processing device 300 determines the secondary digest data corresponding to a set of layer units according to the digest data of each layer unit in the set of layer units, and then signs the secondary digest data using a private key to obtain the signature data.

[0148] In a possible example, the secondary digest data may also be referred to as the second digest data or the second digest value.

[0149] Regarding the above signature data, the following shows two possible examples of obtaining the signature data.

[0150] Example 1, the processing device 300 concatenates the digest data of each layer unit in a set of layer units, determines the digest data of the concatenated digest data, and then signs the digest data of the concatenated digest data using a private key to obtain the signature data. The digest data of the concatenated digest data is the secondary digest data.

[0151] Exemplarily, the processing device 300 concatenates the digest values Hpic1, Hpic2,..., Hpicn of each layer unit in a set of layer units in the bit stream order, calculates the digest of the concatenated digest (digest data) to obtain the secondary digest data, that is, uses the concatenation method to perform a second digest. For example, for the digest values Hpic1, Hpic2,..., Hpicn of each layer unit in the bit stream order, refer to the following Figure 4b Use the concatenation method to perform a second digest. Then, sign the secondary digest data of the set of layer units to obtain the signature data.

[0152] For example, if the above set of layer units includes 50 layer units and the data volume of the summary data of one layer unit is 32 bits (bytes), the processing device 300 needs to calculate the summary 50 times first to obtain the summary data of each layer unit in the set of layer units. Further, the summary data of the 50 layer units are concatenated to obtain the concatenated summary data (data volume: 32 * 50 bytes), and then a summary is calculated for the concatenated summary data to obtain the secondary summary data of the set of layer units. The entire process may take time T1, and the measured value of T1 is 90.7901 ms.

[0153] In this application, the summary calculation process needs to be implemented using a key module. Since each call to the key module needs to be configured first and this operation takes a long time, the above-mentioned summary Hg can be obtained by calculating the summary only n + 1 times, reducing the number of summary calculations, thereby reducing the time and computing performance required for summary calculation and improving the efficiency of summary calculation.

[0154] Example 2: The processing device 300 connects the (n + 1)-th combined summary data and the summary data of the (n + 2)-th layer unit in the bit stream order, calculates the summary of the connected data to obtain the (n + 2)-th combined summary data, and so on until the summary data of each layer unit in the set of layer units participates in the connection to obtain the secondary summary data; the (n + 1)-th combined summary data is obtained by calculating the summary after connecting the n-th combined summary data and the summary data of the (n + 1)-th layer unit, or the (n + 1)-th combined summary data is obtained by calculating the summary after connecting the summary data of the n-th data unit and the summary data of the (n + 1)-th data unit, where n is a positive integer. Further, the processing device 300 signs the secondary summary data to obtain the signature data.

[0155] The processing device 300 connects the summary values Hpic1, Hpic2,..., Hpicn of each layer unit in a set of layer units in the bit stream order, connects Hpic1 and Hpic2 together, calculates the summary of the connected Hpic1 and Hpic2 to obtain the combined summary data Hpic1,2, then connects Hpic1,2 and Hpic3 together, calculates the summary of the connected Hpic1,2 and Hpic3 to obtain the combined summary data Hpic1,3, and so on, until Hpic1,n - 1 and Hpicn are connected together, calculates the summary of the connected Hpic1,n - 1 and Hpicn to obtain Hpic1,n, that is, until the summary values of each layer unit in the set of layer units participate in the connection, thereby obtaining the tree-top summary, that is, using the tree-top method to perform the secondary summary. For example, for the layer unit summary values Hpic1, Hpic2,..., Hpicn in the bit stream order, refer to the following Figure 4c Use the tree-top method to perform the secondary summary to obtain the tree-top summary. This tree-top summary is the secondary summary data.

[0156] For example, if a set of layer units includes 3 layer units, and the summary data of these 3 layer units are H1, H2, and H3 in sequence along the bitstream order, the tree-top summary of this set of layer units is calculated using the tree-top method. That is, the processing device 300 concatenates H1 and H2, calculates the summary of the concatenated H1 and H2 to obtain the combined summary data H1,2, then concatenates the combined summary data H1,2 with H3, and calculates the summary of the concatenated H1,2 and H3 to obtain the combined summary data H1,3. This combined summary data H1,3 is also the secondary summary data of this set of layer units.

[0157] For example, if the above-mentioned set of layer units includes 50 layer units, and the data volume of the summary data of one layer unit is 32 bytes. Therefore, the processing device 300 needs to calculate the summary 50 times first to obtain the summary data of each layer unit in the set of layer units. Then, using the tree-top calculation method, the summary is calculated n - 1 (i.e., 49) times (the data volume is 32 * 2 bytes each time the calculation is performed) to obtain the tree-top summary, which is also the secondary summary data of the set of layer units. The entire process may take time T2, and the measured value of T2 is 120.8181 ms.

[0158] In this application, the processing device 300 needs to calculate the summary H1 / n 2n - 1 times. The number of summary calculations is relatively small, that is, the number of summary calculations is reduced, thereby reducing the time required for calculating the summary and improving the efficiency of calculating the summary.

[0159] For example, the processing device 300 uses the private key to sign the secondary summary data to obtain the signature data.

[0160] It should be noted that the maximum number of data units included in a set of data units can be determined according to hash_period_in_doi_minus1 in the security parameter set and / or the number of airspace division layers (NumOfLayers) in the sequence parameter set, such as n + 2 in the above example and Figure 4cThe maximum value of n shown is determined according to hash_period_in_doi_minus1 and / or NumOfLayers. For example, the maximum number of access units included in a set of access units is equal to hash_period_in_doi_minus1 + 1. The maximum number of layer units included in a set of layer units is equal to the sum of the number of layer units in hash_period_in_doi_minus1 + 1 access units, such as (hash_period_in_doi_minus1 + 1) multiplied by (the number of layer units in one access unit indicated by NumOfLayers). The maximum number of NAL units included in a set of NAL units is equal to the sum of the number of NAL units in hash_period_in_doi_minus1 + 1 access units.

[0161] The above bitstream includes a sequence parameter set.

[0162] In a possible scenario, the summary data respectively corresponding to multiple layer units in a set of layer units are arranged in sequence in the authentication data according to the bitstream order of the multiple layer units.

[0163] Exemplarily, the coded slices of multiple frames of images in a video correspond to a set of layer units, and the multiple frames of images include non-RL preknowledge images. In the bitstream, the non-RL preknowledge images may be divided into two patches, that is, two access units. In the bitstream, the multiple layer units included in each of the two access units are arranged in sequence according to the bitstream order, and the two access units are also arranged in sequence in the bitstream according to the bitstream order.

[0164] For example, patch0 includes LU00, LU10, LU20, and patch1 includes LU01, LU11, LU21. In the bitstream, the foregoing layer units are arranged in sequence according to the bitstream order, that is, in the order of LU00, LU10, LU20, LU01, LU11, LU21 in sequence.

[0165] Correspondingly, the arrangement order of the summary data corresponding to the above layer units in the authentication data is consistent with the arrangement order of the layer units in the bitstream.

[0166] If a non-RL pre-indication image is divided into two patches, that is, two access units. Each of the two access units includes multiple layer units.

[0167] S320. The processing device 300 outputs a bitstream.

[0168] The bitstream includes the above authentication data.

[0169] Exemplarily, after obtaining the authentication data, the processing device 300 adds the authentication data to the bitstream a to obtain the signed bitstream b, and then outputs the bitstream b, which is the signed bitstream 203 in the above Figure 2 signed bitstream.

[0170] It should be noted that the above S310 - S320 can be executed by the encoder in the signing end 210, or by the signature module in the signing end 210, or by the encoder and the authentication module in the signing end 210 in cooperation (the encoder executes S320 and the authentication module executes S310). This application does not limit this.

[0171] As Figure 4a shown, Figure 4a is a flowchart of a bitstream signature method provided by this application Figure 2 . Among them, Figure 4a the method shown can be implemented by the processing device 300, and the processing device 300 can be implemented by the signing end 210 in Figure 2 . The bitstream signature method may include the following steps S410 - S440.

[0172] S410. The processing device 300 generates a security parameter set NAL unit and inserts it into the bitstream (compressed video bitstream).

[0173] Exemplarily, when video image authentication needs to be supported, a security parameter set is generated.

[0174] In a possible implementation manner, to generate the RBSP (also referred to as the security parameter set RBSP) in the security parameter set NAL unit, the scope of action of the security parameter set is a single RAS in the bitstream, also referred to as a random access segment, and all layer units (access units) participating in the authentication cannot cross the RAS.

[0175] Exemplarily, configure the security parameter set ID (sec_para_set_id), knowledge image identifier (sec_is_library_flag), authentication enable flag (authentication_enable_flag), authentication digest calculation mode (authentication_hash_mode), hash type (hash_type), non - random access point image hash authentication flag (hash_discard_nrap_pictures_flag), hash period (hash_period_in_doi_minus1), authentication flag (authentication_idc), authentication data identifier (authentication_data_id) in the security parameter set.

[0176] Among them, sec_para_set_id is the security parameter set ID, a 2-bit unsigned integer. It is used to distinguish different security parameter sets acting on the same RAS or knowledge image access unit, and the value range is 1 to 3.

[0177] sec_is_library_flag is a binary variable. A value of '1' indicates that this security parameter set acts on the knowledge image, and a value of '0' indicates that this security parameter set acts on the display image.

[0178] authentication_enable_flag is a binary variable. A value of '1' indicates that authentication of the current RAS or knowledge image is supported. The NAL units that can participate in authentication include the coded slices of the display image or knowledge image in the current RAS, as well as the sequence parameter set, picture parameter set, security parameter set, extended data unit, and supplementary enhancement information transmitted in this access unit. The authentication data is transmitted through the NAL unit with nal_unit_type equal to 10. A value of '0' indicates that the current security parameter set does not support authentication of the RAS or knowledge image, and there should be no NAL unit with nal_unit_type equal to 10 generated using this security parameter set for this RAS or knowledge image.

[0179] The knowledge image only supports independent signature authentication, and the display image supports joint signature authentication. Multiple display image access units participating in joint signature authentication should be located in the same RAS. The image types in multiple access units participating in joint signature can be display images. For the independent signature authentication of the knowledge image, an independent security parameter set independent of the display image is used for independent signature authentication, and sec_is_library_flag is used to distinguish in the security parameter set.

[0180] If there are NAL units with authentication_idc greater than 0 and nal_unit_type equal to 1 to 3, 5 to 9, 12, 14, 17, 18, and 19 in an access unit, for the NAL units with the same authentication_idc value greater than 0 and the same layer_id value in each layer unit of this access unit, after arranging them in bitstream order, a digest calculation is performed to generate the digest data of the NumOfLayers layer units corresponding to the authentication_idc of this access unit. The digest calculation method is specified by hash_type.

[0181] For hash_period_in_doi_minus1 + 1 access units, calculate the digest of each layer unit in each access unit in bitstream order. The scope of action of the authentication data should not cross the RAS; then calculate the secondary digest in the method indicated by authentication_hash_mode in sequence.

[0182] Perform digital signature on the secondary digest value to generate the authentication data RBSP and package it into the authentication data RBSP NAL unit.

[0183] Note: If the values of authentication_enable_flag and encryption_enable_flag in multiple security parameter sets in the bitstream are equal to 1, that is, the current RAS or knowledge image supports both encryption and authentication, then it should be encrypted first and then authenticated, that is, the data used for authentication should be the encrypted NAL unit.

[0184] authentication_hash_mode is a binary variable. It identifies the method of calculating the secondary digest. The value of '0' indicates that the secondary digest is calculated using the concatenation method, that is, the layer unit digest values Hpic1, Hpic2,..., Hpicn are concatenated in bitstream order, and the secondary digest of the concatenated digest (digest data) is calculated to obtain the secondary digest data, that is, the concatenation method is used to do the secondary digest. For example, for the layer unit digest values Hpic1, Hpic2,..., Hpicn in bitstream order, refer to Figure 4b Using the concatenation method to do the secondary digest, Figure 4b is the concatenated digest schematic diagram provided by this application. The above calculation of the secondary digest can also be called the calculation of the second-level digest.

[0185] The value of '1' indicates that the secondary digest is calculated using the tree-top method, that is, for the layer unit digest values Hpic1, Hpic2,..., Hpicn in bitstream order, Hpic1 and Hpic2 are concatenated together, and the digest of the concatenated Hpic1 and Hpic2 is calculated to obtain Hpic1,2. Then Hpic1,2 and Hpic3 are concatenated together, and the digest of the concatenated Hpic1,2 and Hpic3 is calculated to obtain Hpic1,3, and so on, until Hpic1,n - 1 and Hpicn are concatenated together, and the digest of the concatenated Hpic1,n - 1 and Hpicn is calculated to obtain Hpic1,n, thereby obtaining the tree-top digest, that is, the tree-top method is used to do the secondary digest. For example, for the layer unit digest values Hpic1, Hpic2,..., Hpicn in bitstream order, refer to Figure 4c Using the tree-top method to do the secondary digest, Figure 4c is the tree-top digest schematic diagram provided by this application.

[0186] For example, the processing device 300 concatenates the combined digest data with the digest data of the (n + 2)-th layer unit in the bitstream order, and calculates the secondary digest of the concatenated digest data until the digest data of each layer unit in a group of layer units participates in the concatenation, obtaining the secondary digest data. The combined digest data is obtained by calculating the digest after concatenating the digest data of the n-th layer unit and the digest data of the (n + 1)-th layer unit, where n is a positive integer.

[0187] The hash_discard_nrap_pictures_flag is a binary variable. A value of '1' indicates that non-random access point images are not authenticated; a value of 0 indicates that non-random access point images can be authenticated. If hash_discard_nrap_pictures is not in the bitstream, its default value is equal to 1.

[0188] hash_period_in_doi_minus, an 8-bit unsigned integer, with a value range of 0 to (MAX_HASH_PERIOD / NumOfLayers - 1), where MAX_HASH_PERIOD is set to 256. HashPeriodInDoi is equal to hash_period_in_doi_minus + 1. It indicates the number of access units participating in signature authentication related to an authentication data. This number is less than or equal to HashPeriodInDoi.

[0189] The processing device 300 sets hash_period_in_doi_minus to HashPeriodInDoi minus 1 according to the user-configured HashPeriodInDoi. A HashPeriodInDoi of 1 indicates independent signature for a single access unit, and the authentication data NAL unit carrying this signature should be located in the access unit associated with this signature or the first access unit after it. A HashPeriodInDoi greater than 1 indicates joint signature for multiple access units.

[0190] NumOfLayers is the number of spatial layers.

[0191] authentication_idc, an unsigned integer of 2 bits, with the value range from 0 to 3. When the nal_unit_type of this NAL unit is 10, the value of authentication_idc should be equal to the security parameter set ID sec_para_set_id corresponding to the authentication data contained in this NAL unit, indicating that the authentication data carried in this authentication data NAL unit is generated based on the security parameter set corresponding to the security parameter set ID sec_para_set_id; otherwise (the nal_unit_type of this NAL unit is not 10), it indicates whether the NAL unit is authenticated. At this time, the value '0' indicates that this NAL unit is not authenticated, and a value other than '0' indicates that this NAL unit is authenticated by the authentication method specified by the security parameter set with sec_para_set_id equal to authentication_idc.

[0192] When the nal_unit_type of a NAL unit is 10, this NAL unit does not participate in signature authentication.

[0193] When the nal_unit_type of a NAL unit is 11, 15 or 16, authentication_idc should be 0.

[0194] When the nal_unit_type of a NAL unit is 6 and it contains a payload with PayloadType equal to 25 or 26, authentication_idc should be 0.

[0195] authentication_data_id, an unsigned integer of 2 bits. The value range is 0 to 1, which is the identifier of the authentication data for the signature authentication participated by this NAL unit, and should be consistent with the authentication_data_id in the authentication data RBSP in which this NAL unit participates in signature authentication. The authentication_data_id of the NAL units participating in authentication corresponding to the same authentication data should be the same and consistent with the authentication_data_id in the authentication data. The authentication_data_id of a set of display picture coding slice NAL units participating in joint signature authentication should be different from the authentication_data_id of the previous set of display picture coding slice NAL units with the same authentication_idc participating in joint signature authentication.

[0196] When the nal_unit_type of a NAL unit is 10, this authentication_data_id shall be consistent with the authentication_data_id in the authentication data RBSP of this NAL unit.

[0197] In a possible example, on the premise of not affecting the decoding process of NAL units with nal_unit_type not equal to 11 and not affecting the consistency of this case (standard), NAL units with nal_unit_type equal to 11 can be discarded by the decoder. When the nal_unit_type value of a coded slice NAL unit is equal to 1, 2, 4, 12 or 17, the nal_unit_type values of all other coded slice NAL units encoding the same picture shall be the same. If UserPermission is equal to 0, NAL units with nal_unit_type value equal to 19 can be discarded by the decoder. When the nal_unit_type value of a coded slice NAL unit is equal to 19, the RBSP data contains the coded unit data of several coded slices in the coded slice of the picture.

[0198] When the number of coded slices of a knowledge picture is equal to 1, the nal_unit_type of this knowledge picture coded slice NAL unit shall be 12 or 17. When the number of coded slices of a non-display knowledge picture is greater than 1, the nal_unit_type of the first and the last knowledge picture coded slice NAL units in decoding order shall be 18, and the nal_unit_type of the remaining knowledge picture coded slice NAL units shall be 12.

[0199] The above nal_unit_type of 0 is used to indicate the coded slice of an IDR picture, and the IDR picture is a random access point picture. The nal_unit_type of 1 is used to indicate the coded slice of a NRAP picture, and the NRAP picture is a P picture or a B picture. The nal_unit_type of 2 is used to indicate the coded slice of a RAPI picture, and the RAPI picture is a random access point picture. The nal_unit_type of 3 is used to indicate the picture header, and the picture header is a syntax structure that contains syntax elements acting on a picture. Each coded picture contains and only contains one picture header NAL unit. The nal_unit_type of 5 is used to indicate the extended data unit, the nal_unit_type of 6 is used to indicate the supplementary enhancement information, the nal_unit_type of 7 is used to indicate the sequence parameter set, the nal_unit_type of 8 is used to indicate only the picture parameter set, the nal_unit_type of 9 is used to indicate the security parameter set, the nal_unit_type of 10 is used to indicate the authentication data. The nal_unit_type of 10 is used to indicate the end of the stream, the nal_unit_type of 12 is used to indicate the coded slice of a non-display knowledge picture, the nal_unit_type of 14 is used to indicate the coded slice of a RL picture. The RL picture is a P picture or a B picture that only uses knowledge pictures as reference pictures for inter-frame predictive decoding, and the RL picture is a random access point picture. The nal_unit_type of 17 is used to indicate the coded slice of a display knowledge picture, the nal_unit_type of 18 is used to indicate the coded slice at the boundary of a non-display knowledge picture, and the nal_unit_type of 19 is used to indicate the coded slice of a privacy picture.

[0200] In a possible example, the processing device 300 sets sec_para_set_id according to the configuration settings, sets the above sec_is_library_flag to 0, authentication_enable_flag to 1 (indicating that authentication is enabled), hash_type to 0 (using the SM3 algorithm), sets the value of authentication_hash_mode to 0 or 1 (calculating the second digest using the concatenation method or the tree top method) according to the configuration, and sets hash_discard_nrap_pictures_flag according to the configuration. If it is necessary to authenticate non-random access point pictures, it is set to 0, otherwise it is set to 1. According to the configured hash period HashPeriodInDoi, it sets hash_period_in_doi_minus1 to HashPeriodInDoi minus 1; HashPeriodInDoi being 1 means independently signing a single access unit, and HashPeriodInDoi being greater than 1 means jointly signing multiple access units.

[0201] Furthermore, the processing device 300 packs the set of security parameters into a security parameter set NAL unit. For example, the processing device 300 sets the authentication_idc of the security parameter set NAL unit. Since the layer_id of the security parameter set NAL unit is 0, when the authentication_idc is non-zero, the authentication_idc is set to the authentication_idc of the layer unit with layer_id being 0, that is, the sec_para_set_id of the security parameter set selected for authenticating the layer unit where it is located.

[0202] The processing device 300 sets the authentication_data_id of the security parameter set NAL unit to 0 or 1, and it is recommended that the authentication_data_id be different from that of the NAL unit participating in the authentication with the same sec_para_set_id and authentication_idc in the previous group.

[0203] The processing device 300 adds the security parameter set NAL unit in front of the picture sequence parameter set NAL unit and inserts it into the bitstream.

[0204] In a possible example, the processing device 300 can code the above fields into the security parameter set according to the syntax table shown in Table 1 according to the preset syntax.

[0205] Table 1

[0206]

[0207]

[0208] Among them, the encryption_enable_flag is an encryption enable flag, a binary variable. A value of '1' indicates that encryption is supported for the coded slice of the display picture, or the picture sequence parameter set of the display picture, or the picture parameter set of the display picture, or the non-display knowledge picture coded slice, or the display knowledge picture coded slice, or the knowledge picture sequence parameter set, or the knowledge picture parameter set, or the extended data unit, that is, the RBSP in the NAL unit may be encrypted. A value of '0' indicates that encryption of the RBSP in the NAL unit is not supported.

[0209] The encryption_unit_mode is the encryption basic unit, a 2-bit unsigned integer. It indicates the encryption basic unit. A value of '0' means encryption is performed on a NAL unit basis; a value of '1' means encryption is performed on an access unit basis, where all the parts of the RBSPs of NAL units in the access unit are concatenated in bitstream order and then encrypted, and after encryption, it is restored to the encrypted NAL unit; a value of '2' means encryption is performed on a layer unit basis, where all the parts of the RBSPs of NAL units in the layer unit are concatenated in bitstream order and then encrypted, and after encryption, it is restored to the encrypted NAL unit; a value of '3' is reserved. The IV needs to be re-initialized for each encryption.

[0210] The encryption_level_mode is the encryption level mode, a 2-bit unsigned integer. It indicates the encryption level mode. A value of '0' means that when encrypting all types of NAL units, the encryption object is all RBSP data (except the last byte of the RBSP); a value of '1' means that when encrypting NAL units with nal_unit_type equal to 1, 2, 4, 12, 14, 17, 18, and 19, the encryption object is the first encryptionByte bytes of the RBSP, and when encrypting other types of NAL units, the encryption object is all RBSP data (except the last byte of the RBSP); a value of '2' means that when encrypting NAL units with nal_unit_type equal to 1, 2, 4, 5, 12, 14, 17, 18, and 19, the encryption object is the first encryptionByte bytes of the RBSP, and when encrypting other types of NAL units, the encryption object is all RBSP data (except the last byte of the RBSP); a value of '3' is reserved. Among them, encryptionByte = Min(EncryptionNum * EncryptionBaseByte, NumBytesInPayload - 1).

[0211] The encryption_num_minus1 is the number of encryption basic byte lengths, an 8-bit unsigned integer. It indicates the number of encryption basic byte lengths, and the value of the number of encryption basic byte lengths EncryptionNum is equal to the value of encryption_num_minus1 plus 1.

[0212] The encryption_base_byte is the length of the encryption basic byte, an unsigned 2-bit integer. It indicates the length of the encryption basic byte. A value of '0' means the value of the encryption basic byte EncryptionBaseByte is 16, a value of '1' means the value of the encryption basic byte EncryptionBaseByte is 64, a value of '2' means the value of the encryption basic byte EncryptionBaseByte is 256, and a value of '3' means the value of the encryption basic byte EncryptionBaseByte is 1024.

[0213] The encryption_type is the encryption type, an unsigned 4-bit integer. It indicates the algorithm used for encryption. The specific correspondence is shown in Table 2.

[0214] Table 2

[0215] Value of encryption_type Encryption algorithm 0 SM1 1 SM4 2~15 Reserved

[0216] The vek_flag is the video encryption key flag, a binary variable. A value of '1' means carrying vek, and a value of '0' means not carrying vkek.

[0217] The iv_flag is the initialization vector flag, a binary variable. A value of '1' means carrying iv, and a value of '0' means not carrying iv.

[0218] The vek_encryption_type is the encryption type of the video encryption key, an unsigned 4-bit integer. It indicates the encryption type of the video encryption key.

[0219] The eve k_length_minus1 is the length of the encrypted video encryption key, an unsigned 8-bit integer. It indicates the length of the encrypted video encryption key in bytes.

[0220] The eve k is the encrypted video encryption key, an unsigned n-bit integer. It represents the encrypted video encryption key used for encryption calculation, with a length of eve k_length_minus1 plus 1 byte.

[0221] The vkek_version length_minus1 is the length of the video encryption key version number, an unsigned 8-bit integer. It indicates the length of the video encryption key version number in bytes.

[0222] The vkek_version is the video encryption key version number, an unsigned n-bit integer. It indicates the video encryption key version number, with a length of vkek_version_length_minus1 plus 1 byte.

[0223] iv_length_minus1 is an 8-bit unsigned integer representing the length of the initial vector. It indicates the length of the initial vector in bytes.

[0224] iv is the initial vector, an n-bit unsigned integer. It indicates the initial vector used for block encryption, with a length of iv_length_minus1 + 1 bytes. hash_type is the hash type, a 2-bit unsigned integer. It indicates the algorithm used for authentication, and the specific correspondence is shown in Table 3.

[0225] Table 3

[0226] Value of hash_type Authentication algorithm Digest data length (bytes) 0 SM3 32 1~3 Reserved Reserved

[0227] signature_type is the digital signature type, a 2-bit unsigned integer. It indicates the algorithm for digitally signing the digest data of the image, as shown in Table 4.

[0228] Table 4

[0229] Value of signature_type Signature algorithm 0 SM2 1~3 Reserved

[0230] signature_fmt is the signature data format, a 2-bit unsigned integer. It indicates the signature data format, and the specific regulations on the corresponding relationship between the value meaning of signature_fmt and the syntax of signature_type are shown in Table 5.

[0231] Table 5

[0232]

[0233] In this step, for the knowledge image, sec_is_library_flag of the security parameter set 2 is 1, indicating independent signature authentication for the knowledge image, and the scope of the security parameter set is a single knowledge image. The knowledge images participating in the authentication cannot cross RAS and cannot be in two RASs. Each knowledge image, including the displayed knowledge image and the non-displayed knowledge image, should be independently signed and authenticated.

[0234] S420. The processing device 300 calculates the digest data of the security parameter set corresponding to the displayed images participating in the signature in RAS.

[0235] When calculating the digest of an access unit, for the NAL units of the layer units to be authenticated in the access unit (including the security parameter set NAL unit (if any), the picture sequence parameter set NAL unit (if any), the picture parameter set NAL unit (if any), the picture header NAL unit, the displayed picture hierarchical coded slice NAL unit, the extended data NAL unit (if any), the supplementary enhancement information NAL unit (if any), etc.).

[0236] The calculation method of the summary data for the displayed image can be as follows:

[0237] Step 1: The processing device 300 sets the authentication_idc in the header information of these NAL units to the sec_para_set_id in the security parameter set; (Note: When generating the bitstream, if the authentication_idc of the NAL units with the same layer_id is non-zero, it is recommended to use the security parameter set with the same sec_para_set_id.).

[0238] Step 2: The processing device 300 sets the authentication_data_id of the current NAL unit. If there is a previous participating NAL unit with the same authentication_data_id for authentication, the authentication_data_id should be different from that of the previous group; otherwise, if this NAL unit participates in authentication together with the security parameter set NAL unit, the authentication_data_id also needs to be the same as the authentication_data_id of the security parameter set NAL unit; otherwise, it is set to 0 or 1.

[0239] Step 3: The processing device 300 then concatenates all the participating NAL units in this layer unit to calculate the summary of this layer unit.

[0240] The processing device 300 extracts the HashPeriodInDoi access units participating in authentication from the compressed video bitstream output by the encoder according to the configuration, and calculates the summaries H1, H2,..., Hn of each layer unit in each access unit in the order of the bitstream, where n is equal to the total number of layer units participating in authentication in all access units. The scope of action of the authentication data should not cross RAS, so the number of access units authenticated together in the last group in each RAS may be less than HashPeriodInDoi.

[0241] Calculate the secondary summary based on each summary value in the manner specified by authentication_hash_mode.

[0242] The above group of layer units is the layer units included in the HashPeriodInDoi access units participating in authentication extracted from the bitstream.

[0243] S430: The processing device 300 signs the summary data of a group of layer units to obtain the signature data.

[0244] The summary data of this group of layer units is the secondary summary value of the above group of layer units.

[0245] For the details of S430, refer to the two possible examples shown under S310 above, which will not be elaborated here.

[0246] S440. The processing device 300 generates an authentication data NAL unit for the security parameter set corresponding to the display image and adds it to the bitstream.

[0247] Among them, multiple digest data corresponding to multiple layer units in a group of layer units are arranged in sequence in the authentication data according to the bitstream order of the multiple layer units.

[0248] In a possible case, the above authentication data NAL includes signature data.

[0249] In another possible case, the above authentication data NAL unit includes signature data and digest data of each layer unit in a group of layer units corresponding to the display image.

[0250] Regarding the content of generating the authentication data NAL unit, a possible example is provided below.

[0251] Step 1. The processing device 300 sets for_current_ras_idc to 0 and auth_is_library_flag to 0.

[0252] Step 2. The processing device 300 sets the authentication_data_id of the current authentication data, and this authentication_data_id is consistent with the authentication_data_id of the NAL unit participating in the authentication this time.

[0253] Step 3. The processing device 300 sets the authentication_hash_list_flag according to the configuration. 0 indicates that the authentication data does not contain a digest list, and 1 indicates that the authentication data contains a digest list. When authentication_hash_list_flag is 1, set authentication_hash_number_minus1 to the number of digests minus 1, and authentication_hash is the digest values {H1, H2,..., Hn} of the display image.

[0254] Step 4. The processing device 300 writes the signature data into authentication_data and sets authentication_data_length_minus1 to the actual length of authentication_data minus 1.

[0255] The processing device 300 packs the authentication data into an authentication data NAL unit, and then inserts the authentication data NAL unit into the last access unit of this authentication or after it, before the next authentication data NAL unit, and before the next-next access unit that is not a random access point access unit of a display knowledge image. Set the temporal_id and layer_id of the authentication data NAL unit header to 0. In particular, the last authentication data in each RAS is allowed to be placed in the next RAS. In this case, set the for_current_ras_idc in the authentication data to 0. The interval between the authentication data and the layer unit in the last access unit participating in the authentication shall not exceed HashPeriodInDoi (equal to hash_period_in_doi_minus1 + 1 in the security parameter set corresponding to this authentication) access units (excluding non-display knowledge image access units). Set the authentication_idc of the authentication data NAL unit to the sec_para_set_id in the corresponding security parameter set, and set the authentication_data_id to the authentication_data_id in the NAL unit header of the layer unit participating in the authentication.

[0256] The authentication data of the displayed image can be located in the access unit where the last displayed image coded slice is located; it can also be located in the access unit of the displayed image coded slice of the next RAS. The authentication data NAL unit shall be located after all other types of NAL units in the access unit except the NAL unit at the end of the stream and the NAL unit at the end of the coded video sequence.

[0257] As a possible implementation, the definition of the authentication data RBSP can be as shown in Table 6.

[0258] Table 6

[0259]

[0260] Among them, for_current_ras_idc is an authentication data position identifier, a binary variable. Its value of '1' indicates that all access units corresponding to the digests in the digest list in this authentication data are within the current random access segment. If it is '0', it indicates that all access units corresponding to the digests in the digest list in this authentication data are not within the current random access segment. All access units with a common signature shall be within the same random access segment.

[0261] auth_is_library_flag is the flag bit for knowledge image authentication data, a binary variable. A value of '1' indicates that the authentication data is the signature data of the knowledge image; a value of '0' indicates that the authentication data is the signature data of the display image or the displayed knowledge image. The value of AuthIsLibraryFlag is equal to the value of auth_is_library_flag. If auth_is_library_flag does not exist in the bitstream, the value of AuthIsLibraryFlag is 0.

[0262] authenticaion_library_picture_index is the index of the authenticated knowledge image.

[0263] authentication_hash_list_flag is the authentication digest list identifier, a binary variable. A value of '1' indicates that the authentication data carries the digest list of the access unit that generates the signature in the authentication data. A value of '0' indicates that the authentication data does not carry the digest list of the access unit that generates the signature in the authentication data.

[0264] authentication_hash_number_minus1 is the number of authentication digests, an 8-bit unsigned integer with a value range of 0 to 255. authentication_hash_number_minus1 plus 1 represents the number of authentication digest data.

[0265] authentication_data_length_minus1 is the length of the signature data, an 8-bit unsigned integer. Plus 1 represents the length of the signature data in bytes, and the value should be in the range of 0 to 255.

[0266] authentication_data[i] is the number of bytes of the signature data, an 8-bit unsigned integer. The i-th byte of a signature data. The authentication data NAL unit should be located after all other types of NAL units in the access unit except for the NAL unit at the end of the stream and the NAL unit at the end of the coded video sequence. The order of the authentication data NAL units corresponding to the same set of security parameters in the bitstream should be the same as the bitstream order of their corresponding access units, that is, if the first authentication data NAL unit is before the second authentication data NAL unit, then any access unit associated with the first authentication data NAL unit is before any access unit associated with the second authentication data NAL unit.

[0267] The authentication data NAL unit for the display picture shall be located in or after the last access unit of this authentication, before the next authentication data NAL unit, and before the next-next access unit which is not a random access point access unit of a display knowledge picture. Specifically, the last authentication data in each RAS is allowed to be placed in the next RAS. In this case, set for_current_ras_idc in the authentication data to 0. The interval between the authentication data and the layer units in the last access unit participating in the authentication shall not exceed HashPeriodInDoi (equal to hash_period_in_doi_minus1 + 1 in the security parameter set corresponding to this authentication) access units (excluding non-display knowledge picture access units). The authentication data for the display picture can be located in the access unit where the last display picture coded slice is located; it can also be located in the access unit of the display picture coded slice in the next RAS.

[0268] The authentication data NAL unit for the knowledge picture shall be located in or after the last access unit of this authentication, before the next authentication data NAL unit, and before the next-next random access point access unit.

[0269] The interval between the authentication data for the display knowledge picture and the display knowledge picture access unit shall not exceed HashPeriodInDoi (equal to hash_period_in_doi_minus1 + 1 in the security parameter set corresponding to this authentication) access units. The authentication data for the display knowledge picture can be located in the access unit where the last display knowledge picture coded slice is located; it can also be located in the access unit of the display picture coded slice in the next RAS.

[0270] The authentication data for the non-display knowledge picture is located in the access unit where the last non-display knowledge picture coded slice is located.

[0271] Write the above authentication data RBSP into the authentication data NAL unit.

[0272] In a possible embodiment, only the above Figure 3 and Figure 4a shown content can obtain the following bitstream.

[0273] The bitstream includes: a set of layer units and authentication data. Among them, the authentication data includes signature data, and the signature data is obtained by signing the digest data of each layer unit in a set of layer units of the bitstream. A layer unit in a set of layer units includes network abstraction layer units with the same layering identifier in the bitstream.

[0274] In a possible implementation manner, the above authentication data further includes the digest data of each layer unit in a set of layer units.

[0275] In a possible implementation, the above bitstream further includes a security data set.

[0276] For more details about a set of layer units, authentication data, or the security data set, reference may be made to the descriptions shown above Figure 3 and Figure 4a which are not elaborated herein.

[0277] The bitstream in this embodiment may be Figure 3 the bitstream b shown in

[0278] After introducing the above bitstream signature method, the processing device 300 may send the bitstream obtained by the above bitstream signature method to Figure 2 the authentication end 220 shown in for processing. Based on this, the embodiments of the present application further provide two bitstream authentication methods.

[0279] Figure 5 is a flowchart illustration of a bitstream authentication method provided by the present application Figure 1 and this bitstream authentication method can be applied to Figure 2 the signature and authentication system shown in. For example, this bitstream authentication method can be implemented by the processing device 500. In a possible example, the processing device 500 may be Figure 2 the authentication end 220 shown in. The bitstream in this embodiment may be Figure 3 the bitstream b in, and this bitstream authentication method may include the following steps S510 - S530.

[0280] S510. The processing device 500 determines the first digest data of each layer unit in a set of layer units in the bitstream.

[0281] Among them, a layer unit in a set of layer units includes network abstraction layer units in the bitstream having the same layering identifier.

[0282] Exemplarily, the processing device 500 determines each layer unit in a set of layer units in the bitstream. Taking one layer unit as an example, it confirms the NAL units participating in authentication in this layer unit, splices the NAL units participating in authentication together, calculates the digest of the spliced NAL units, and obtains the first digest data of this layer unit.

[0283] It should be noted that during the process of the processing device 500 continuously receiving the bitstream, the first digest data of the layer units will be continuously calculated and cached. Moreover, the processing device 500 can calculate the first digest data in the order of receiving the layer units (i.e., the bitstream order) and cache them in sequence.

[0284] In a possible scenario, all access units of a set of layer units are stored in a digest list.

[0285] For example, the processing device 500 caches the first digest data in the memory of the processing device 500.

[0286] S520. The processing device 500 obtains the authentication data from the bitstream.

[0287] Among them, the authentication data includes: signature data and second digest data of each layer unit in a group of layer units. The signature data is obtained by signing the second digest data of each layer unit in a group of layer units.

[0288] For more details of the authentication data, reference can be made to the above Figure 3 or Figure 4a the content shown, which will not be elaborated here.

[0289] S530. If the processing device 500 successfully verifies the signature data, it verifies multiple second digest data in the authentication data according to the first digest data of each layer unit in a group of layer units in the bitstream.

[0290] In a possible implementation, the signature data can be verified in the following way.

[0291] The processing device 500 obtains the public key, and then determines the secondary digest data corresponding to a group of layer units according to the second digest data of each layer unit in the group of layer units included in the authentication data, so as to verify the signature data according to the public key, the secondary digest data and the signature algorithm.

[0292] In a possible implementation, the processing device 500 calculates the second digest data of each layer unit in a group of layer units in a tree-top manner or a concatenation manner according to the value indicated by authentication_hash_mode (such as 0 or 1) to obtain the secondary digest data.

[0293] For the description of the secondary digest data, reference can be made to the content of the secondary digest data shown under S310 above, which will not be elaborated here. Figure 3

[0294] Exemplarily, when the digital signature type signature_type is parsed from the code stream security parameter set RBSP, the processing device 300 can determine the signature algorithm according to the signature algorithm indicated by signature_type. signature_type is a 2-bit unsigned integer used to indicate the algorithm for digitally signing the digest data of the image.

[0295] Exemplarily, the processing device 500 can determine the signature algorithm according to a pre-agreed signature algorithm.

[0296] ​Exemplarily, when the camera certificate identifier camera_idc is obtained from the secure parameter set RBSP of the bitstream, the processing device 300 may look up the public key in the authentication certificate indicated by camera_idc.

[0297] Exemplarily, the processing device 500 may parse and obtain the public key from the authentication data RBSP of the bitstream.

[0298] Exemplarily, the processing device 500 may obtain the public key pre-built in the authentication end 220.

[0299] In a possible scenario, the second digest data respectively corresponding to multiple layer units in a group of layer units are arranged in sequence in the authentication data according to the bitstream order of the multiple layer units.

[0300] For the content in this scenario, reference may be made to the arrangement of the second digest data in the authentication data under S320 above, which will not be elaborated here.

[0301] In a possible implementation manner, the processing device 500 verifies multiple second digest data in the authentication data according to the first digest data of each layer unit in a group of layer units in the bitstream, including:

[0302] The processing device 500 sequentially matches the first digest data with the second digest according to the arrangement order of the multiple second digest data in the authentication data and the multiple first digest data of a group of layer units.

[0303] In a possible example, the processing device 500 matches the first digest data of multiple layer units included in a group of layer units with the multiple second digest data in the authentication data in sequence. If the match is successful, the layer unit of the successfully matched first digest data is authenticated successfully and the layer unit is valid (usable); if the match fails, the layer unit of the first digest data with the failed match is authenticated as failed (unusable).

[0304] It should be noted that the above match also includes position matching. For example, when it is determined that the digest data a in the multiple second digest data matches the digest data b in the multiple first digest data, it is determined whether the next digest data of the digest data a in the multiple second digest data matches the next digest data of the digest data a in the multiple first digest data. If the match is successful, the layer unit corresponding to the next digest data of the digest data a is valid.

[0305] In a possible implementation, the processing device 500 calculates first digest data based on layer units in the bitstream, stores the first digest data in a first digest list, and stores second digest data obtained from the authentication data in a second digest list. The processing device 500 can match the identifier of the second digest list with the digest list cached locally by the processing device 500. If it is determined that the identifier of the second digest list matches the identifier of the first digest list, the step of "verifying multiple second digest data in the authentication data according to the first digest data of each layer unit in a group of layer units in the bitstream" in S530 above is executed.

[0306] In a possible example, the above identifiers can be sec_para_set_id and authentication_data_id.

[0307] In a possible scenario, the processing device 500 stores the first digest data and third digest data calculated based on layer units in the bitstream into a first digest list and a third digest list respectively. The first digest list includes the first digest data of each layer unit in a group of layer units, and the third digest list includes the third digest data of each layer unit in a group of layer units. It should be noted that the processing device 500 stores the obtained first digest list and third digest list into the memory of the processing device 500, such as memory, hard disk, cache, etc. The authentication data also includes a second digest list, which includes the second digest data of each layer unit in a group of layer units.

[0308] Furthermore, if the identifier of the first digest list is consistent with the identifier of the second digest list, and the identifier of the third digest list is inconsistent with the identifier of the second digest list, then the authentication of a group of layer units corresponding to the third digest list fails.

[0309] It should be noted that the sorting of a group of layer units corresponding to the third digest list in the bitstream is before the group of layer units corresponding to the first digest list.

[0310] Figure 6 Flow schematic of a bitstream authentication method provided by this application Figure 2 , and this bitstream authentication method can be applied to Figure 2 the signature and authentication system shown in, for example, this bitstream authentication method can be implemented by the processing device 500. In a possible example, the processing device 500 can be Figure 2 the authentication end 220 shown in, and the bitstream in this embodiment can be Figure 3 the bitstream b in, and this bitstream authentication method can include the following steps S610 - S630.

[0311] S610. The processing device 500 determines the first digest data of a group of layer units in the bitstream.

[0312] Among them, the first summary data is the above-mentioned secondary summary data.

[0313] In a possible implementation, the processing device 500 determines the third summary data of each layer unit in a group of layer units, and then determines the first summary data corresponding to the group of layer units according to the third summary data of each layer unit in the group of layer units.

[0314] Exemplarily, the processing device 500 concatenates the third summary data of all layer units in a group of layer units to obtain the concatenated third summary data, and calculates the summary of the concatenated third summary data to obtain the first summary data. This first summary data is the secondary summary data of the above-mentioned group of layer units.

[0315] For example, the processing device 500 directly concatenates the strings corresponding to the third summary data of all layer units to obtain the concatenated third summary data.

[0316] Exemplarily, the processing device 300 determines the third summary data of each layer unit in a group of layer units of the bitstream, and then calculates the tree-top summary of the multiple third summary data in the group of layer units as the first summary data.

[0317] For the content of S610 and the content of the above possible implementation, reference can be made to the content of calculating the summary data of a group of layer units in the above S310, which will not be elaborated here.

[0318] It should be noted that during the process of the processing device 500 continuously receiving the bitstream, the summary data of the layer units will be continuously calculated and cached. Also, the processing device 500 can calculate the summary data in the order of receiving the layer units (i.e., the bitstream order) and cache them in sequence, and then calculate the first summary data of a group of layer units according to the summary data of each layer unit in the group of layer units.

[0319] This first summary data can be stored in the memory of the processing device 500.

[0320] S620. The processing device 500 obtains authentication data from the bitstream.

[0321] Among them, the authentication data includes signature data, and the signature data is obtained by signing according to the second summary data of each layer unit in a group of layer units. A layer unit in the group of layer units includes network abstraction layer units with the same layering identifier in an access unit of the bitstream.

[0322] For more detailed content of the authentication data, reference can be made to the above Figures 3 - 5 shown content, which will not be elaborated here.

[0323] S630. The processing device 500 verifies the signature data using the first digest data.

[0324] In a possible implementation, the processing device 300 verifies the signature data using the first digest data, including: the processing device obtains the public key, and then verifies the signature data according to the public key, the first digest data, and the signature algorithm.

[0325] For the details of S830, reference can be made to the description of verifying the signature data in the above S730, which will not be elaborated here.

[0326] In a possible implementation, the processing device 500 determines the identifier of the first digest data that matches the identifier of the authentication data from the memory. If the identifier of the first digest data matches the identifier of the authentication data, the steps of verifying the signature data using the first digest data as described above are executed.

[0327] In a possible scenario, the processing device 500 calculates the first digest data based on the first set of layer units in the bitstream and the fourth digest data based on the second set of layer units. It should be noted that the processing device 500 stores the obtained first digest data and fourth digest data in the memory of the processing device 500, such as the memory, hard disk, or cache, etc. Both the first digest data and the fourth digest data are secondary digest data.

[0328] Furthermore, if the identifier of the first digest data is consistent with the identifier of the authentication data, and the identifier of the fourth digest data is inconsistent with the identifier of the authentication data, the authentication of the second set of layer units corresponding to the fourth digest data fails.

[0329] It should be noted that the second set of layer units is sorted before the first set of layer units in the bitstream.

[0330] In a possible example, the above identifier can be sec_para_set_id, authentication_data_id.

[0331] For the details of S630, reference can be made to the description of S530 above, which will not be elaborated here.

[0332] Regarding the bitstream authentication method, a complete embodiment is provided below. This embodiment includes the following steps ① - ④.

[0333] Step ①: The processing device 500 inputs a bitstream (compressed video bitstream), and then obtains the secure parameter set NAL unit in the bitstream.

[0334] The processing device 500 obtains one or more security parameter sets of NAL units of the RAS, and obtains sec_para_set_id, authentication_enable_flag, authentication_data_id, hash_type, authentication_hash_mode, hash_discard_nrap_pictures_flag, and hash_period_in_doi_minus1 from the security parameter set. If the authentication_enable_flag in the security parameter set is 0, the security parameter set does not support authenticating the displayed image. If the hash_discard_nrap_pictures_flag in the security parameter set is 1, the security parameter set does not support authenticating non-random access point images.

[0335] For each security parameter set, authenticate the layer units participating in the authentication according to steps 2 and 3.

[0336] Step ②: The processing device 500 obtains the display image access unit in the RAS for a security parameter set and calculates the digest data of the display image.

[0337] Calculate the digest:

[0338] The processing device 500 receives the NAL data of hash_period_in_doi_minus1 + 1 display image access units in the RAS, splices together the NAL units of the layer units participating in the authentication in the access unit, and calculates the digest of the layer unit. The last set of data participating in the authentication in the RAS may be less than hash_period_in_doi_minus1 + 1.

[0339] The processing device 500 calculates the secondary digest based on each digest value in the bitstream order, and stores the secondary digest value in the local cache with sec_para_set_id and authentication_data_id as identifiers.

[0340] For example, the processing device 500 stores the digest of multiple layer units with consecutive and identical authentication_data_id into the local cache in the form of a digest list {H1’, H2’, …, Hm’} identified by sec_para_set_id and authentication_data_id in the bitstream order, where m is equal to the total number of layer units participating in the authentication in the access unit. If there is an unauthenticated digest list identified by authentication_data_id previously, the layer units generating this digest list fail the authentication, and the new digest list is used to overwrite the old one.

[0341] Step ③: Obtain the display image authentication data to complete the authentication of the display image.

[0342] The processing device 500 calculates from the access unit where the last display image coding slice participating in the authentication is located to the maximum hash_period_in_doi_minus1 + 1 access units to obtain the authentication data.

[0343] When for_current_ras_idc in the authentication data is 1, it indicates that the authentication data is the authentication data of the current RAS; when for_current_ras_idc is 0, it indicates that the authentication data is the last authentication data of the previous RAS.

[0344] In a possible scenario, when authentication_hash_list_flag in the authentication data is 0, the secondary digest value is used for authentication.

[0345] The processing device 500 looks up the secondary digest value in the local cache according to the sec_para_set_id and authentication_data_id in the authentication data. If the secondary digest value is found, the digital signature in the authentication data is verified with the secondary digest value; if the signature verification is successful, the layer units participating in generating the secondary digest value are successfully authenticated, and if the verification fails, the layer units participating in generating the secondary digest value fail the authentication.

[0346] If the processing device 500 finds that the sec_para_set_id and authentication_data_id are consistent with those of the sec_para_set_id and authentication_data_id of the latest received layer unit sequence, and at this time there are other secondary digest values whose identifiers are not equal to sec_para_set_id and authentication_data_id and have not been authenticated, then the authentication data corresponding to the unauthenticated secondary digest values is lost, and the layer unit authentication corresponding to these unauthenticated secondary digest values fails. If the secondary digest value of the layer unit corresponding to the authentication_data_id cannot be found, the authentication data is invalid and the authentication fails.

[0347] In another possible scenario, when the authentication_hash_list_flag is 1, digest list authentication is used.

[0348] 1. Parse the authentication_data_id and the corresponding digest list {H1, H2,..., Hn} from the authentication data NAL unit, and calculate the secondary digest; if the authentication_hash_mode is 0, use the concatenation method to calculate the secondary digest; if the authentication_hash_mode is 1, use the tree-top method to calculate the secondary digest.

[0349] 2. Use the secondary digest value to verify the signature data parsed from the authentication data NAL unit, and determine whether the digest list {H1, H2,..., Hn} transmitted in the authentication data NAL unit passes the verification. If the verification fails, the digest list data in the authentication data is untrustworthy and the digest list authentication fails.

[0350] 3. Determine the layer units participating in the signature according to the parameters in the certified data NAL unit. Search for the digest list of the layer units cached locally according to sec_para_set_id and authentication_data_id. If found, the layer units to be certified can be confirmed through the digest list. If found and the sec_para_set_id, authentication_data_id are the same as those of the sec_para_set_id and authentication_data_id of the latest received layer unit sequence, and at this time there are still uncertified digest lists with other identifiers not equal to sec_para_set_id and authentication_data_id, then the certified data corresponding to the uncertified digest lists is lost, and the layer unit authentication corresponding to these uncertified digest lists fails. If the digest list of the layer unit corresponding to sec_para_set_id and authentication_data_id is not found, the certified data is invalid and the authentication fails.

[0351] 4. Sequentially match the digest list {H1’, H2’, …, Hm’} of the layer units and the digest list {H1, H2, …, Hn} in the certified data to implement the authentication of the layer units. First, search for H1’ in the digest list in the certified data. After successful search, record the position of the digest list in the certified data, and the layer unit corresponding to H1’ is successfully authenticated; then start searching for H2’ from the next position of this position in the digest list in the certified data. If the search is successful, update the position of the digest list in the certified data, and the layer unit corresponding to H2’ is successfully authenticated; continue to search for subsequent H3’, …, Hm’. If the search is successful, the corresponding layer unit is successfully authenticated. If the search fails, the corresponding layer unit authentication fails.

[0352] It can be understood that in order to implement the functions in the above embodiments, the processing device 300 and the processing device 500 include the corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should easily realize that, combined with the units and method steps of each example described in the embodiments disclosed in this application, this application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the way of hardware or computer software driving hardware depends on the specific application scenario and design constraint conditions of the technical solution.

[0353] In the above text, in combination with Figures 1 to 4c , the bitstream signature method provided according to this embodiment is described in detail. Next, in combination with Figure 7 , the bitstream signature device provided according to this embodiment will be described.

[0354] Figure 7Schematic diagram of the bitstream signature device provided by this application. The schematic diagram of the bitstream signature device can be used to execute the method of the foregoing embodiment. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method provided above, and will not be elaborated here. Exemplarily, the bitstream signature device 700 includes:

[0355] An acquisition module 710, configured to acquire authentication data. Among them, the authentication data includes signature data, and the signature data is obtained by signing the digest data of each layer unit in a group of layer units of the bitstream. One layer unit in the group of layer units includes network abstraction layer units with the same layering identifier.

[0356] An output module 720, configured to output a bitstream, and the bitstream includes authentication data.

[0357] For more implementable content of the bitstream signature device 700, reference may be made to the steps executed by the processing device 300 in the foregoing method embodiment. The bitstream signature device 700 can be used to implement the functions of the processing device 300 in the foregoing method embodiment, and thus can also achieve the beneficial effects of the foregoing method embodiment.

[0358] In the foregoing, in combination with Figure 5 , the bitstream authentication method provided according to this embodiment is described in detail. Next, in combination with Figure 8a , the bitstream authentication device provided according to this embodiment will be described. Figure 8a Schematic diagram of the bitstream authentication device provided by this application Figure 1 , the schematic diagram of the bitstream authentication device can be used to execute the method of the foregoing embodiment. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method provided above, and will not be elaborated here. Exemplarily, the bitstream authentication device 800a includes:

[0359] A first determination module 811, configured to determine the first digest data of each layer unit in a group of layer units in the bitstream. One layer unit in the group of layer units includes network abstraction layer units with the same layering identifier.

[0360] A first acquisition module 821, configured to acquire authentication data from the bitstream. The authentication data includes: signature data and the second digest data of each layer unit in a group of layer units, and the signature data is obtained by signing the second digest data of each layer unit in the group of layer units.

[0361] A first verification module 831, configured to, if the verification of the signature data is successful, verify the multiple second digest data in the authentication data according to the first digest data of each layer unit in a group of layer units in the bitstream.

[0362] For more realizable content of the bitstream authentication device 800a, reference may be made to the steps performed by the processing device 500 in the foregoing method embodiments. The bitstream authentication device 800a can be used to implement the functions of the processing device 500 in the foregoing method embodiments, and thus can also achieve the beneficial effects of the foregoing method embodiments.

[0363] In the foregoing, in combination with Figure 6 , the bitstream authentication method provided according to this embodiment has been described in detail. Next, in combination with Figure 8b , the bitstream authentication device provided according to this embodiment will be described below. Figure 8b Schematic diagram of the bitstream authentication device provided by this application Figure 2 , the schematic diagram of the bitstream authentication device can be used to execute the method of the foregoing embodiment. Therefore, the beneficial effects it can achieve can refer to the beneficial effects in the corresponding method provided above, and will not be elaborated here. Exemplarily, the bitstream authentication device 800b includes:

[0364] A second determination module 812, configured to determine first digest data of a group of layer units in the bitstream.

[0365] A second acquisition module 822, configured to acquire authentication data from the bitstream, where the authentication data includes signature data, and the signature data is obtained by signing the second digest data of each layer unit in a group of layer units, and one layer unit in the group of layer units includes network abstraction layer units with the same layering identifier.

[0366] A second verification module 832, configured to verify the signature data by using the first digest data.

[0367] For more realizable content of the bitstream authentication device 800b, reference may be made to the steps performed by the processing device 500 in the foregoing method embodiments. The bitstream authentication device 800b can be used to implement the functions of the processing device 500 in the foregoing method embodiments, and thus can also achieve the beneficial effects of the foregoing method embodiments.

[0368] It can be understood that Figure 8a or Figure 8b The devices shown are only examples provided in this embodiment. According to different bitstream signature or authentication processes, the device may include more or fewer units, and this application does not limit this.

[0369] When Figure 7 , 8a or Figure 8bWhen the device shown is implemented by hardware, the hardware can be implemented by a processor or a chip system. The chip system includes one or more chips, and each chip includes a processor and a power supply circuit. The power supply circuit is used to supply power to the processor, and the processor is used to implement the method of any possible implementation manner in the above embodiments through logic circuits or by executing code instructions. The beneficial effects can be referred to the description of any aspect in the above embodiments, and will not be elaborated here.

[0370] It can be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.

[0371] An embodiment of the present application also provides a computing device. Figure 7 The bitstream signature device 700 shown, Figure 8a the bitstream authentication device 800a shown, or Figure 8b the bitstream authentication device 800b shown can be implemented by a computing device, such as Figure 9 shown, Figure 9 is a schematic structural diagram of the computing device provided by the present application. The computing device 900 includes: a memory 910 and at least one processor 920. The processor 920 can implement the bitstream signature method or the bitstream authentication method provided in the above embodiments, and the memory 910 is used to store software instructions corresponding to the above bitstream signature method or bitstream authentication method. For example, the computing device may be Figure 1 the camera 11 or the mobile phone 15 in etc. The computing device 900 may be the above processing device 300 or processing device 500.

[0372] As an alternative implementation, in terms of hardware implementation, the computing device 900 may refer to a chip or a chip system encapsulating one or more processors 920. By way of example, when the computing device 900 is used to implement the method steps in the above embodiments, the processor 920 included in the computing device 900 executes the steps and their possible sub-steps of the processing device 300 or the processing device 500 in the above method. In an alternative scenario, the computing device 900 may further include a communication interface 930, which can be used to send and receive data. For example, the communication interface 930 is used to receive a bit stream, etc.; the communication interface 930 can be implemented through the interface circuit included in the computing device 900. Therefore, in some examples, the communication interface 930 may also be referred to as the transceiver of the computing device. In this embodiment, the communication interface 930 supports wired connection using the unified multimedia interconnect interface.

[0373] In the embodiments of the present application, the communication interface 930, the processor 920, and the memory 910 may be connected through a bus 940. The bus 940 may be divided into an address bus, a data bus, a control bus, etc. The bus 940 may be a peripheral component interconnect express (PCIe) bus, or an extended industry standard architecture (EISA) bus, a unified bus (Ubus or UB), a compute express link (CXL), a cache coherent interconnect for accelerators (CCIX), or other types of buses, etc.

[0374] The processor 920 may include a CPU, a graphics processing unit (GPU), an embedded neural-network processing unit (NPU), a microprocessor (MP), a digital signal processor (DSP), an ASIC, an FPGA, or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof.

[0375] The memory 910 may include volatile memory, such as random access memory (RAM). The memory 910 may also include non-volatile memory, such as read only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).

[0376] It is worth noting that the computing device 900 may also execute Figure 7 the functions of the bitstream signature device 700 shown, Figure 8a the bitstream authentication device 800a shown, or Figure 8b the bitstream authentication device 800b shown, which will not be elaborated here. Among them, all relevant contents of each step involved in the above method embodiments can be cited in the function descriptions of the corresponding functional modules, and will not be elaborated here.

[0377] The embodiment of the present application also provides a computer-readable storage medium. The computer-readable storage medium may be any available medium that can be stored by a computing device or a data storage device such as a data center containing one or more available media. The available medium may be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., digital video disc (DVD)), or a semiconductor medium (e.g., solid state drive), etc. The computer-readable storage medium stores instructions that instruct the computing device to execute the bitstream signature method or the bitstream authentication method. The computer-readable storage medium may also store the above-mentioned bitstreams, such as those obtained by Figure 3 or Figure 4a the method shown.

[0378] The embodiment of the present application also provides a computer program product containing instructions. The computer program product may be software or a program product containing instructions that can run on a computing device or be stored in any available medium. When the computer program product runs on at least one computing device, it causes at least one computing device to execute the bitstream signature method or the bitstream authentication method.

[0379] In addition, the embodiment of the present application also provides a device, which may specifically be a chip, a component, or a module. The device may include a processor and a memory connected to each other; wherein, the memory is used to store computer execution instructions, and when the device runs, the processor may execute the computer execution instructions stored in the memory to enable the chip to execute the methods in the above method embodiments.

[0380] Among them, the computing device, computer-readable storage medium, computer program product, or chip provided in this embodiment are all used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding methods provided above, and will not be elaborated here.

[0381] Through the description of the above embodiments, those skilled in the art can understand that for the convenience and simplicity of description, only the division of the above functional modules is used as an example. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.

[0382] In several embodiments provided in this application, it should be understood that the disclosed device and method can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of modules or units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling, direct coupling, or communication connection can be through some interfaces. The indirect coupling or communication connection of the device or unit can be in an electrical, mechanical, or other form.

[0383] The unit described as a separated component may or may not be physically separated. The component displayed as a unit may be a physical unit or multiple physical units, that is, it can be located in one place, or it can be distributed to multiple different places. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0384] In addition, each functional unit in each embodiment of this application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.

[0385] Any content in each embodiment of this application, as well as any content in the same embodiment, can be freely combined. Any combination of the above content is within the scope of this application.

[0386] When an integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on such understanding, the technical solution of the embodiments of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions for causing a device (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs that can store program codes.

[0387] The steps of the methods or algorithms described in combination with the disclosed content of the embodiments of this application can be implemented in a hardware manner or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, and the software modules can be stored in RAM, flash memory, ROM, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, hard disks, mobile hard disks, compact disc read-only memory (CD-ROM), or any other form of storage medium well-known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an ASIC.

[0388] Those skilled in the art should be able to realize that in the above one or more examples, the functions described in the embodiments of this application can be implemented by hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. The computer-readable medium includes a computer-readable storage medium and a communication medium, where the communication medium includes any medium facilitating the transmission of a computer program from one place to another. The storage medium can be any available medium accessible by a general-purpose or special-purpose computer.

[0389] The embodiments of this application have been described above in conjunction with the accompanying drawings. However, this application is not limited to the above specific implementation manners. The above specific implementation manners are merely illustrative and not restrictive. Under the inspiration of this application, those of ordinary skill in the art can also make many forms without departing from the purpose of this application and the scope protected by the claims, and all of them belong to the protection scope of this application.

Claims

1. A bitstream signature method, characterized in that, The method includes: Obtaining authentication data; Wherein, the authentication data includes signature data, and the signature data is obtained by signing the digest data of each layer unit in a group of layer units of the bitstream, and one layer unit in the group of layer units includes network abstraction layer (NAL) units with the same layering identifier; Outputting a bitstream, where the bitstream includes authentication data.

2. The method according to claim 1, characterized in that, The authentication data further includes the digest data of each layer unit in the group of layer units.

3. The method according to claim 2, characterized in that The digest data corresponding to multiple layer units in the group of layer units are arranged in sequence in the authentication data according to the bitstream order of the multiple layer units.

4. The method according to claim 3, characterized in that, The group of layer units includes a first layer unit, and the method further includes: Performing digest calculation after arranging the NAL units included in the first layer unit in bitstream order to obtain the digest data of the first layer unit.

5. The method according to any one of claims 1 to 4, characterized in that, The method further includes: Determining secondary digest data of the group of layer units according to the digest data of each layer unit in the group of layer units; Signing the secondary digest data with a private key to obtain the signature data.

6. The method according to claim 5, wherein The secondary digest data is obtained by concatenating the (n + 1)-th combined digest data and the digest data of the (n + 2)-th layer unit in bitstream order, calculating the digest of the concatenated data to obtain the (n + 2)-th combined digest data, until the digest data of each layer unit in the group of layer units participates in the concatenation; the (n + 1)-th combined digest data is obtained by calculating the digest after concatenating the n-th combined digest data and the digest data of the (n + 1)-th layer unit, and n is a positive integer.

7. The method according to claim 5, characterized in that, The secondary digest data is obtained by concatenating the second digest data of each layer unit in the group of layer units and calculating the secondary digest of the concatenated second digest data.

8. The method according to any one of claims 1 to 7, characterized in that, The maximum number of layer units included in the group of layer units is determined according to the hash period and the number of spatial layers.

9. The method according to any one of claims 1 to 8, characterized in that, The decoding order of multiple NAL units with the same layering identifier included in one layer unit is consecutive.

10. The method according to any one of claims 1 to 9, characterized in that, The NAL units included in one layer unit have the same authentication identifier with a value greater than 0.

11. The method according to any one of claims 1 to 10, characterized in that, The obtaining of the authentication data includes: Generating the authentication data.

12. The method according to any one of claims 1 to 11, characterized in that, Before outputting the bitstream, the method further includes: Adding the authentication data to the bitstream.

13. A bitstream, characterized in that, The bitstream includes: A group of layer units and authentication data; Wherein, the authentication data includes signature data, and the signature data is obtained by signing the digest data of each layer unit in a group of layer units of the bitstream, and one layer unit in the group of layer units includes network abstraction layer (NAL) units with the same layering identifier.

14. The bitstream according to claim 13, characterized in that, The authentication data further includes the digest data of each layer unit in the group of layer units.

15. The bitstream according to claim 14, wherein The digest data corresponding to multiple layer units in the group of layer units are arranged in sequence in the authentication data according to the bitstream order of the multiple layer units.

16. The bitstream according to any one of claims 13 to 15, characterized in that, The decoding order of multiple NAL units with the same layering identifier included in one layer unit is consecutive.

17. The bitstream according to any one of claims 13 to 16, characterized in that, The NAL units included in one layer unit have the same authentication identifier with a value greater than 0.

18. The bitstream according to any one of claims 13 to 17, characterized in that, The maximum number of layer units included in the set of layer units is determined according to the hash period and the number of spatial layer divisions.

19. A bitstream authentication method, characterized in that, The method includes: Determining first digest data of each layer unit in a set of layer units in a bitstream; one layer unit in the set of layer units includes network abstraction layer (NAL) units having the same layering identifier; Obtaining authentication data from the bitstream; the authentication data includes: signature data and second digest data of each layer unit in the set of layer units, and the signature data is signed according to the second digest data of each layer unit in the set of layer units; If the verification of the signature data is successful, then verify multiple second digest data in the authentication data according to the first digest data of each layer unit in the set of layer units in the bitstream.

20. The method according to claim 19, wherein The first digest list includes the first digest data of each layer unit in the set of layer units, and the second digest list includes the second digest data of each layer unit in the set of layer units. The method further includes: Matching the identifier of the first digest list with the identifier of the second digest list; the identifier includes an authentication data identifier and / or a security parameter set identifier ID; If the identifier of the first digest list is consistent with the identifier of the second digest list, then execute verifying multiple second digest data in the authentication data according to the first digest data of each layer unit in the set of layer units in the bitstream.

21. The method according to claim 19 or 20, characterized in that, The maximum number of layer units included in the set of layer units is determined according to the hash period and the number of spatial layer divisions.

22. The method according to any one of claims 19 to 21, characterized in that, The second digest data respectively corresponding to multiple layer units in the set of layer units are arranged in sequence in the authentication data according to the bitstream order of the multiple layer units.

23. The method according to claim 22, wherein The verifying multiple second digest data in the authentication data according to the first digest data of each layer unit in the set of layer units in the bitstream includes: Sequentially matching the first digest data with the second digest data according to the arrangement order of multiple second digest data in the authentication data and multiple first digest data of a set of layer units; If the match is successful, then the layer unit of the first digest data with a successful match is authenticated successfully; If the match fails, then the layer unit of the first digest data with a failed match is authenticated failed.

24. The method according to any one of claims 19 to 23, characterized in that, The method further includes: Obtaining a public key; Determining second-level digest data corresponding to the set of layer units according to the second digest data of each layer unit in the set of layer units included in the authentication data; Verifying the signature data according to the public key, the second-level digest data, and a signature algorithm.

25. The method according to claim 24, wherein, The second-level digest data is obtained by connecting the (n + 1)-th combined digest data with the second digest data of the (n + 2)-th layer unit in sequence along the bitstream order, calculating the digest of the connected data to obtain the (n + 2)-th combined digest data, until the second digest data of each layer unit in the set of layer units all participate in the connection; the (n + 1)-th combined digest data is obtained by calculating the digest after connecting the n-th combined digest data with the second digest data of the (n + 1)-th layer unit, and n is a positive integer.

26. The method according to claim 24, wherein The second-level digest data is obtained by connecting the second digest data of each layer unit in the set of layer units and calculating the digest of the connected second digest data.

27. A bitstream authentication method, characterized in that The method includes: Determining first digest data of a set of layer units in a bitstream; Obtaining authentication data from the bitstream, where the authentication data includes signature data, and the signature data is signed according to second digest data of each layer unit in the set of layer units, and a layer unit in the set of layer units includes a network abstraction layer (NAL) unit having the same layering identifier; Verifying the signature data by using the first digest data.

28. The method according to claim 27, characterized in that, The determining first digest data of a set of layer units of the bitstream includes: Determining third digest data of each layer unit in the set of layer units of the bitstream; Determining the first digest data corresponding to the set of layer units according to the third digest data of each layer unit in the set of layer units.

29. The method according to claim 28, wherein Determining the first digest data corresponding to the set of layer units according to the third digest data of each layer unit in the set of layer units includes: Connecting the (n + 1)-th combined digest data with the third digest data of the (n + 2)-th layer unit in the order of the bitstream, calculating a digest of the connected data to obtain the (n + 2)-th combined digest data, until the third digest data of each layer unit in the set of layer units participates in the connection, to obtain the first digest data; the (n + 1)-th combined digest data is obtained by calculating a digest after connecting the n-th combined digest data with the third digest data of the (n + 1)-th layer unit, and n is a positive integer.

30. The method according to claim 28, characterized in that, Determining the first digest data corresponding to the set of layer units according to the third digest data of each layer unit in the set of layer units includes: Connecting the third digest data of each layer unit in the set of layer units to obtain concatenated third digest data; Calculating a digest of the connected third digest data to obtain the first digest data.

31. The method according to any one of claims 27 to 28, characterized in that, The verifying the signature data by using the first digest data includes: Obtaining a public key; Verifying the signature data according to the public key, the first digest data, and a signature algorithm.

32. The method according to any one of claims 27 to 31, characterized in that, The method further includes: Matching an identifier of the first digest data with an identifier of the authentication data; the identifier includes an authentication data identifier and / or a security parameter set identifier ID; If the identifier of the first digest data matches the identifier of the authentication data, then performing verifying the signature data by using the first digest data.

33. The method according to any one of claims 27 to 32, characterized in that The maximum number of layer units included in the set of layer units is determined according to a hash period and the number of spatial layers.

34. A bitstream signature device, characterized in that, The apparatus includes: An obtaining module, configured to obtain authentication data; where the authentication data includes signature data, and the signature data is signed according to digest data of each layer unit in a set of layer units of the bitstream, and a layer unit in the set of layer units includes a network abstraction layer (NAL) unit having the same layering identifier; An output module, configured to output a bitstream, where the bitstream includes authentication data.

35. The device according to claim 34, characterized in that, The authentication data further includes digest data of each layer unit in the set of layer units.

36. The device according to claim 35, characterized in that, Digest data respectively corresponding to multiple layer units in the set of layer units are arranged in sequence in the authentication data according to the bitstream order of the multiple layer units.

37. The device according to claim 36, characterized in that, The set of layer units includes a first layer unit, and the apparatus further includes: The abstract calculation module is used to perform abstract calculation on the network abstraction layer (NAL) units included in the first layer units after arranging them in bitstream order, so as to obtain the abstract data of the first layer units.

38. The device according to any one of claims 34 to 37, characterized in that, The apparatus further includes: The signature module is used to determine the secondary abstract data of the set of layer units according to the abstract data of each layer unit in the set of layer units, and sign the secondary abstract data with a private key to obtain the signature data.

39. The device according to claim 38, wherein, The secondary abstract data is obtained by concatenating the (n + 1)-th combined abstract data and the abstract data of the (n + 2)-th layer unit in bitstream order, calculating the abstract of the concatenated data to obtain the (n + 2)-th combined abstract data, until the abstract data of each layer unit in the set of layer units participates in the concatenation; the (n + 1)-th combined abstract data is obtained by calculating the abstract after concatenating the n-th combined abstract data and the abstract data of the (n + 1)-th layer unit, where n is a positive integer.

40. The device according to claim 38, characterized in that, The secondary abstract data is obtained by concatenating the second abstract data of each layer unit in the set of layer units and then calculating the secondary abstract of the concatenated second abstract data.

41. The device according to any one of claims 34 to 40, characterized in that, The maximum number of layer units included in the set of layer units is determined according to the hash period and the number of spatial domain layers.

42. The device according to any one of claims 34 to 41, characterized in that The decoding order of multiple network abstraction layer (NAL) units with the same layering identifier included in one layer unit is consecutive.

43. The device according to any one of claims 34 to 42, characterized in that, The network abstraction layer (NAL) units included in one layer unit have the same authentication identifier and the authentication identifier is greater than 0.

44. The device according to any one of claims 34 to 43, characterized in that, The obtaining module is used to generate the authentication data.

45. The device according to any one of claims 34 to 44, characterized in that, The apparatus further includes an adding module; The adding module is used to add the authentication data to the bitstream.

46. A bitstream authentication device, characterized in that, The apparatus includes: The first determination module is used to determine the first abstract data of each layer unit in a set of layer units in the bitstream; one layer unit in the set of layer units includes network abstraction layer (NAL) units with the same layering identifier. The first obtaining module is used to obtain authentication data from the bitstream; the authentication data includes: signature data and the second abstract data of each layer unit in the set of layer units, and the signature data is obtained by signing the second abstract data of each layer unit in the set of layer units. The first verification module is used to, if the verification of the signature data is successful, verify the multiple second abstract data in the authentication data according to the first abstract data of each layer unit in a set of layer units in the bitstream.

47. The device according to claim 46, characterized in that, The first abstract list includes the first abstract data of each layer unit in the set of layer units, the second abstract list includes the second abstract data of each layer unit in the set of layer units, and the first verification module is further used to match the identifier of the first abstract list with the identifier of the second abstract list; the identifier includes the authentication data identifier and / or the security parameter set identifier ID; if the identifier of the first abstract list is consistent with the identifier of the second abstract list, then perform the verification of the multiple second abstract data in the authentication data according to the first abstract data of each layer unit in a set of layer units in the bitstream.

48. The device according to claim 46 or 47, characterized in that, The maximum number of layer units included in the set of layer units is determined according to the hash period and the number of spatial domain layers.

49. The device according to any one of claims 46 to 48, characterized in that, The second digest data respectively corresponding to multiple layer units in the group of layer units are arranged in sequence in the authentication data according to the bitstream order of the multiple layer units.

50. The device according to claim 49, characterized in that, The verification module is specifically configured to sequentially match the first digest data with the second digest data according to the arrangement order of the multiple second digest data in the authentication data and the multiple first digest data of the group of layer units; if the match is successful, the layer unit corresponding to the successfully matched first digest data is successfully authenticated; if the match fails, the layer unit corresponding to the failed-matched first digest data is failed to be authenticated.

51. The device according to any one of claims 46 to 50, characterized in that, The verification module is further configured to obtain a public key, determine the secondary digest data corresponding to the group of layer units according to the second digest data of each layer unit included in the authentication data, and verify the signature data according to the public key, the secondary digest data, and the signature algorithm.

52. The device according to claim 51, characterized in that, The secondary digest data is obtained by concatenating the (n + 1)-th combined digest data and the second digest data of the (n + 2)-th layer unit in bitstream order, calculating the digest of the concatenated data to obtain the (n + 2)-th combined digest data, until the second digest data of each layer unit in the group of layer units all participate in the concatenation; the (n + 1)-th combined digest data is obtained by calculating the digest after concatenating the n-th combined digest data and the second digest data of the (n + 1)-th layer unit, where n is a positive integer.

53. The device according to claim 51, wherein The secondary digest data is obtained by concatenating the second digest data of each layer unit in the group of layer units together and calculating the secondary digest of the concatenated second digest data.

54. A bitstream authentication device, characterized in that, The apparatus includes: A second determination module, configured to determine the first digest data of a group of layer units of a bitstream; A second acquisition module, configured to acquire authentication data from the bitstream, where the authentication data includes signature data, and the signature data is obtained by signing the second digest data of each layer unit in the group of layer units, and one layer unit in the group of layer units includes network abstraction layer (NAL) units with the same layering identifier in one access unit of the bitstream; A second verification module, configured to verify the signature data by using the first digest data.

55. The device according to claim 54, characterized in that, The second determination module is specifically configured to determine the third digest data of each layer unit in the group of layer units of the bitstream, and determine the first digest data corresponding to the group of layer units according to the third digest data of each layer unit in the group of layer units.

56. The device according to claim 55, characterized in that, The second determination module is further specifically configured to concatenate the (n + 1)-th combined digest data and the third digest data of the (n + 2)-th layer unit in bitstream order, calculate the digest of the concatenated data to obtain the (n + 2)-th combined digest data, until the third digest data of each layer unit in the group of layer units all participate in the concatenation to obtain the first digest data; the (n + 1)-th combined digest data is obtained by calculating the digest after concatenating the n-th combined digest data and the third digest data of the (n + 1)-th layer unit, where n is a positive integer.

57. The device according to claim 55, characterized in that, The second determination module is further specifically configured to connect the third digest data of each layer unit in the group of layer units together to obtain the connected third digest data, and calculate a secondary digest for the connected third digest data to obtain the first digest data.

58. The device according to any one of claims 54 to 57, characterized in that, The second verification module is specifically configured to obtain a public key, and verify the signature data according to the public key, the first digest data, and a signature algorithm.

59. The device according to any one of claims 54 to 58, characterized in that, The second verification module is further configured to match the identifier of the first digest data with the identifier of the authentication data; the identifier includes an authentication data identifier and / or a security parameter set identifier ID; if the identifier of the first digest data matches the identifier of the authentication data, then execute verifying the signature data by using the first digest data.

60. The device according to any one of claims 54 to 59, characterized in that, The maximum number of layer units included in the group of layer units is determined according to a hash period and the number of spatial domain layers.

61. A computing device, characterized in that, Comprising: A memory and a processor, the memory is used for storing computer instructions; when the processor executes the computer instructions, the method according to any one of claims 1 to 12 is implemented, or, the method according to any one of claims 19 to 33 is implemented.

62. A non-transitory computer-readable storage medium, characterized in that, A computer program or instruction is stored in the storage medium, and when the computer program or instruction is executed by a processing device, the method according to any one of claims 1 to 12 is implemented; and / or, when the computer program or instruction is executed by a processing device, the method according to any one of claims 19 to 33 is implemented.

63. A computer program product, characterized in that, A computer program product includes computer instructions, and when the computer instructions are executed by a computer or a processor, the steps of the method according to any one of claims 1 to 12 are executed, or, the steps of the method according to any one of claims 19 to 33 are executed.

64. A non-transitory computer-readable storage medium, characterized in that, A computer-readable storage medium stores the bitstream according to any one of claims 13 to 18.