Signature method, authentication method and device
By independently generating the security parameter sets of knowledge images and display images in the compressed video bitstream, the problem of complexity of security parameter sets in the prior art is solved, and the effect of reducing complexity and independent signature authentication is achieved.
Patent Information
- Application Number
- CN202410176180.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-01-24
- Filing Date
- 2024-02-07
- Publication Date
- 2025-07-25
AI Technical Summary
In the prior art, in the process of signing audio and video content, it is necessary to ensure that the knowledge image and the random access clips where it is located adopt the same security parameter set, resulting in an increase in the complexity of the security parameter set.
In the process of compressing video bit stream signature, the knowledge image and the data units of the display image are respectively signed, and the security parameter set acting on the knowledge image and the display image are independently generated to ensure that the authentication end can independently authenticate the data units of the knowledge image.
It reduces the complexity of the security parameter set, solves the constraints of the failure to meet the same security parameter set of random access fragments after knowledge image editing, and realizes independent signature authentication.
Smart Images

Figure CN120378108A_ABST
Abstract
Description
[0001] This application claims the priority of a Chinese patent application with the application number 202410103225.3 and the application title "A Signature Method, Authentication Method and Device", which was filed with the National Intellectual Property Administration on January 24, 2024, and the entire content of which is incorporated herein by reference. Technical Field
[0002] Embodiments of this application relate to the field of media, and in particular, to a signature method, an authentication method and a device. Background Art
[0003] In many audio and video encoding and decoding scenarios (such as monitoring, live broadcast, on-demand, etc.), there are certain requirements for the authenticity and integrity of audio and video content; therefore, in order to ensure the security of audio and video content during transmission and prevent the audio and video content from being tampered with during transmission, it is necessary to sign the audio and video content.
[0004] Currently, the process of signing audio and video content is as follows: generate a digest corresponding to each access unit in the audio and video content, and then use a digital signature algorithm to sign the digest, so as to write the signature into the audio and video content. In the current standard, for unified signature and authentication of display pictures and library pictures, it is necessary to ensure that the library picture and the random access segment (RAS) where the library picture is located adopt the same security parameter set, which increases the complexity of the security parameter set. Summary of the Invention
[0005] This application provides a signature method, an authentication method and a device to solve the problem that in the signature process, it is necessary to ensure that the library picture and the random access segment where the library picture is located adopt the same security parameter set, which increases the complexity of the security parameter set.
[0006] This application adopts the following technical solutions.
[0007] In a first aspect, an embodiment of this application provides a signature method. This signature method is executed by a signature device or a chip in the signature device. For example, the signature device may refer to a mobile phone, a computer, etc. Exemplarily, the method includes: generating a security parameter set; the security parameter set includes a library picture identifier, and the library picture identifier is used to indicate that the security parameter set acts on the library picture or the display picture; calculating the digest data corresponding to the display picture or the library picture for the security parameter set; signing the digest data to obtain signature data; generating authentication data corresponding to the display picture or the library picture for the security parameter set; the authentication data includes the signature data; and adding the authentication data and the security parameter set to the compressed video bitstream.
[0008] In this application, during the signature process of the compressed video bitstream, the data units of the knowledge image and the display image are respectively signed, and a security parameter set for the knowledge image is separately generated. The security parameter set for the knowledge image is independent of the security parameter set for the display image. In this way, the compressed video bitstream carries the security parameter set for the knowledge image, enabling the authentication end to separately authenticate the data units of the knowledge image according to the security parameter set of the knowledge image. Compared with unified signature authentication for the display image and the knowledge image, the data units of the display image and the data units of the knowledge image use different independent security parameter sets, without the need to ensure the constraint that the knowledge image and the random access segment where the knowledge image is located adopt the same security parameter set, reducing the complexity of the security parameter set. At the same time, during the knowledge image editing process, if it is required that the knowledge image and the random access segment where it is located use the same security parameter set, and the random access segment where the edited knowledge image is located may use a different security parameter set, the above encryption method provided in this application solves the contradiction that the security parameter set of the edited knowledge image cannot meet the constraint that the knowledge image and the random access segment where it is located adopt the same security parameter set by separately signing and authenticating the data units of the knowledge image.
[0009] In a possible implementation manner, when the knowledge image identifier takes a first value, it indicates that the security parameter set acts on the knowledge image, and when the knowledge image identifier takes a second value, it indicates that the security parameter set acts on the display image. In this way, for the data units of the knowledge image and the display image, the authentication end can identify whether one or more security parameter sets in the compressed video bitstream act on the data units of the knowledge image or the data units of the display image through the knowledge image identifier, so as to implement independent signature authentication of the data units of the knowledge image using an independent security parameter set.
[0010] In a possible implementation manner, the authentication data is located in or after the last access unit of the current authentication, before the next authentication data NAL unit, and before the next random access point access unit. In this way, when the authentication end authenticates the access unit of the current authentication, it can extract the security parameter set corresponding to the knowledge image from the random access segment to which the access unit of the current authentication belongs, authenticate the knowledge image, and thus use the knowledge image as a reference image in inter-frame prediction.
[0011] In a possible implementation manner, the knowledge image is a display knowledge image, and the interval between the authentication data and the access unit of the display knowledge image does not exceed the number of access units equal to the hash period value. In this way, it is ensured that the access unit of the display knowledge image is within the access unit participating in signature authentication of the authentication data of the display knowledge image, ensuring that the display knowledge image can be independently signed and authenticated by the security parameter set.
[0012] In a possible implementation, the knowledge image is a non-display knowledge image, and the authentication data is located in the access unit where the last non-display knowledge image coding slice is located.
[0013] In a possible implementation, the security parameter set further includes a security parameter set identifier, which is used to distinguish different security parameter sets acting on the same random access segment or knowledge image access unit. In this way, multiple security parameter sets are included in the same random access segment, and the authentication side can identify the security parameter set corresponding to the knowledge image access unit according to the security parameter set identifier, so as to independently authenticate the knowledge image access unit using this security parameter set.
[0014] In a possible implementation, the security parameter set further includes a hash period, which is used to indicate the maximum number of access units in the bitstream segment.
[0015] In a possible implementation, the authentication data includes digest data. The digest data is used to authenticate the display image or the knowledge image.
[0016] In a possible implementation, the knowledge image is an encoded image with a sequence parameter set corresponding to each frame of image, and the knowledge bitstream flag in the corresponding sequence set parameter is 1. The display image is a reference knowledge image (refrence library picture), an instant decoding refresh (refrence library picture, IDR) image, a P image, a B image, or a random access point I frame (random access point I picture, RAPI) image output by the decoder after decoding the reconstructed image.
[0017] In a second aspect, an embodiment of the present application provides a compressed video bitstream, which includes authentication data and a security parameter set; wherein, the security parameter set includes a knowledge image identifier, and the knowledge image identifier is used to indicate whether the security parameter set acts on a knowledge image or a display image. The authentication data includes signature data corresponding to the digest data, and the digest data is the digest data of the display image or the knowledge image corresponding to the security parameter set.
[0018] In a possible implementation, when the knowledge image identifier takes a first value, it indicates that the security parameter set acts on the knowledge image, and when the knowledge image identifier takes a second value, it indicates that the security parameter set acts on the display image.
[0019] In a possible implementation, the authentication data is located in the last access unit of the current authentication or after it, before the next authentication data NAL unit, and before the next next random access point access unit.
[0020] In a possible implementation, the knowledge image is a display knowledge image, and the interval between the authentication data and the access unit displaying the knowledge image does not exceed the number of access units equal to the hash period value.
[0021] In a possible implementation, the knowledge image is a non-display knowledge image, and the authentication data is located in the access unit where the last non-display knowledge image coding slice is located.
[0022] In a possible implementation, the security parameter set further includes a security parameter set identifier, which is used to distinguish different security parameter sets acting on the same random access segment or knowledge image access unit.
[0023] In a possible implementation, the security parameter set further includes a hash period, which is used to indicate the maximum number of access units in the bitstream segment.
[0024] In a possible implementation, the authentication data includes digest data. The digest data is used to authenticate the display image or the knowledge image.
[0025] In a possible implementation, for the knowledge image, each frame of image corresponds to a sequence parameter set, and the coded image with the knowledge bitstream flag being 1 in the corresponding sequence set parameters; the display image is a reference knowledge image, an instant decoding refresh image, a P image, a B image, or a random access point I-frame image output by the decoder after decoding the reconstructed image.
[0026] In a third aspect, an embodiment of the present application provides an authentication method, which is executed by an authentication device or a chip in the authentication device. For example, the authentication device may refer to a mobile phone, a computer, etc. Exemplarily, the method includes: inputting a compressed video bitstream; the compressed video bitstream includes authentication data and a security parameter set, the authentication data includes signature data, the signature data is obtained by signing the digest data, the digest data is the digest of the display image or the knowledge image corresponding to the security parameter set, and the security parameter set includes a knowledge image identifier, and the knowledge image identifier is used to indicate whether the security parameter set acts on the knowledge image or the display image; calculating the digest data of the image corresponding to the security parameter set; and authenticating the display image or the knowledge image according to the calculated digest data and the authentication data.
[0027] In a possible implementation, when the knowledge image identifier takes a first value, it indicates that the security parameter set acts on the knowledge image, and when the knowledge image identifier takes a second value, it indicates that the security parameter set acts on the display image.
[0028] In a possible implementation, the authentication data is located in the last access unit of the current authentication or after it, before the next authentication data NAL unit, and before the next next random access point access unit.
[0029] In a possible implementation, the knowledge image is a display knowledge image, and the interval between the authentication data and the access unit displaying the knowledge image does not exceed the number of access units equal to the hash period value.
[0030] In a possible implementation, the knowledge image is a non-display knowledge image, and the authentication data is located in the access unit where the last non-display knowledge image coding slice is located.
[0031] In a possible implementation, the security parameter set further includes a security parameter set identifier, which is used to distinguish different security parameter sets acting on the same random access segment or knowledge image access unit.
[0032] In a possible implementation, the security parameter set further includes a hash period, which is used to indicate the maximum number of access units in the bitstream segment.
[0033] In a possible implementation, the authentication data includes digest data. The digest data is used to authenticate the display image or the knowledge image.
[0034] In a possible implementation, the knowledge image is an encoded image with a sequence parameter set corresponding to each frame of image, and the knowledge bitstream flag in the corresponding sequence set parameter is 1. The display image is a reference knowledge image, an instant decoding refresh image, a P image, a B image, or a random access point I-frame image output by the decoder after decoding the reconstructed image.
[0035] In a fourth aspect, the present application provides a signature device. The signature device includes a module for executing the method of the first aspect or any possible implementation of the first aspect.
[0036] In a fifth aspect, the present application provides an authentication device. The authentication device includes a module for executing the method of the third aspect or any possible implementation of the third aspect.
[0037] In a sixth aspect, an embodiment of the present application provides an electronic device. The electronic device includes: a memory and a processor, the memory is coupled to the processor; the memory stores program instructions, and when the program instructions are executed by the processor, the electronic device executes the signature method in the first aspect or any possible implementation of the first aspect, or executes the authentication method in the third aspect or any possible implementation of the third aspect.
[0038] In a seventh aspect, an embodiment of the present application provides a chip, which includes one or more interface circuits and one or more processors; the one or more processors receive or send data through the one or more interface circuits, and when the one or more processors execute computer instructions, the steps of the signature method in the first aspect or any possible implementation manner of the first aspect are executed, or the steps of the authentication method in the third aspect or any possible implementation manner of the third aspect are executed.
[0039] In an eighth aspect, an embodiment of the present application provides a non-transitory computer-readable storage medium. The non-transitory computer-readable storage medium stores a computer program, and when the computer program runs on a computer or a processor, the computer or the processor is caused to execute the signature method in the first aspect or any possible implementation manner of the first aspect, or execute the authentication method in the third aspect or any possible implementation manner of the third aspect.
[0040] In a ninth aspect, an embodiment of the present application provides a computer program product. The computer program product includes computer instructions, and when the computer instructions are executed by a computer or a processor, the computer or the processor is caused to execute the signature method in the first aspect or any possible implementation manner of the first aspect, or execute the authentication method in the third aspect or any possible implementation manner of the third aspect.
[0041] In a tenth aspect, an embodiment of the present application provides a non-transitory computer-readable storage medium. The non-transitory computer-readable storage medium stores a compressed video bitstream in the second aspect or any possible implementation manner of the second aspect.
[0042] In an eleventh aspect, an embodiment of the present application provides a device for storing a bitstream. The device includes: a receiver and at least one storage medium, the receiver is configured to receive a compressed video bitstream in the second aspect or any possible implementation manner of the second aspect; the at least one storage medium is configured to store the compressed video bitstream.
[0043] In a twelfth aspect, an embodiment of the present application provides a device for transmitting a bitstream. The device includes: a transmitter and at least one storage medium, the at least one storage medium is configured to store a compressed video bitstream in the second aspect or any possible implementation manner of the second aspect; the transmitter is configured to obtain the compressed video bitstream from the storage medium and send the compressed video bitstream to an end-side device through a transmission medium.
[0044] In a thirteenth aspect, an embodiment of the present application provides a system for distributing a bitstream. The system includes: at least one storage medium for storing at least one compressed video bitstream in the second aspect or any possible implementation manner of the second aspect; a streaming media device for obtaining a target compressed video bitstream from at least one storage medium and sending the target compressed video bitstream to an end-side device, where the streaming media device includes a content server or a content distribution server.
[0045] For the beneficial effects of the second aspect to the thirteenth aspect, reference may be made to the description of any implementation manner in the first aspect, which will not be elaborated here. Based on the implementation manners provided in the above aspects of the present application, further combinations can be made to provide more implementation manners. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] Figure 1 A schematic diagram of an application scenario provided by the present application;
[0047] Figure 2 A schematic diagram of the structure of a signature and authentication system provided by the present application;
[0048] Figure 3a A schematic diagram of the flowchart of a signature method provided by the present application;
[0049] Figure 3b A schematic diagram of a connection summary provided by the present application;
[0050] Figure 3c A schematic diagram of a tree top summary provided by the present application;
[0051] Figure 4 A schematic diagram of the flowchart of an authentication method provided by the present application;
[0052] Figure 5 A schematic diagram of a signature device provided by the present application;
[0053] Figure 6 A schematic diagram of an authentication device provided by the present application;
[0054] Figure 7 A schematic diagram of the structure of an electronic device provided by the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0055] The present application provides a signature method, which includes: generating a security parameter set; the security parameter set includes a knowledge image identifier for indicating that the security parameter set acts on a knowledge image or a display image; calculating summary data of the display image or the knowledge image corresponding to the security parameter set; signing the summary data to obtain signature data; generating authentication data of the display image or the knowledge image corresponding to the security parameter set; the authentication data includes the signature data; and adding the authentication data and the security parameter set to the compressed video bitstream.
[0056] In the present application, during the signature process of the compressed video bitstream, data units of the knowledge image and the display image are respectively signed, and a security parameter set for the knowledge image is separately generated. The security parameter set for the knowledge image is independent of the security parameter set for the display image. In this way, the compressed video bitstream carries the security parameter set for the knowledge image, enabling the authentication end to separately authenticate the data units of the knowledge image according to the security parameter set of the knowledge image. Compared with unified signature authentication for the display image and the knowledge image, the data units of the display image and the data units of the knowledge image respectively use different independent security parameter sets, without the need to ensure the constraint that the knowledge image and the random access segment where the knowledge image is located adopt the same security parameter set, reducing the complexity of the security parameter set. At the same time, during the editing process of the knowledge image, if it is required that the knowledge image and the random access segment where it is located use the same security parameter set, and the random access segment where the edited knowledge image is located may use a different security parameter set, the above encryption method provided by the present application solves the contradiction that the security parameter set of the edited knowledge image cannot meet the constraint that the knowledge image and the random access segment where it is located adopt the same security parameter set by separately signing and authenticating the data units of the knowledge image.
[0057] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0058] The term "and / or" in this article is merely a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone.
[0059] The terms "first", "second", etc. in the specification and claims of the embodiments of the present application are used to distinguish different objects, rather than to describe a specific order of the objects. For example, the first target object and the second target object are used to distinguish different target objects, rather than to describe a specific order of the target objects.
[0060] In the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, using words such as "exemplary" or "for example" aims to present relevant concepts in a specific manner.
[0061] In the description of the embodiments of the present application, unless otherwise specified, "a plurality of" means two or more. For example, a plurality of processing units means two or more processing units; a plurality of systems means two or more systems.
[0062] The following gives an introduction to related technologies.
[0063] bitstream
[0064] The binary data stream formed by encoding image / audio frames. Both NAL unit stream and byte stream can be referred to as bitstream. For example, the bitstream can be a compressed video bitstream.
[0065] The NAL unit stream format consists of a series of syntax structures called NAL units, sorted in decoding order. The decoding order and content of NAL units in the NAL unit stream are constrained.
[0066] The byte stream can be constructed from the NAL unit stream by arranging the NAL units in decoding order and adding a start code prefix and several zero-valued bytes to each NAL unit to form a bitstream. The NAL unit stream format can be extracted from the bitstream format by searching for the unique start code prefix in the bitstream.
[0067] data unit
[0068] The basic syntax structure of the encoded bitstream, which can be an NAL unit, an access unit, or a layer unit.
[0069] layer unit
[0070] A set of NAL units with the same layer_id value, associated with each other according to specified rules and consecutive in decoding order.
[0071] NAL unit
[0072] A syntax structure that contains a type indication of the subsequent data and the number of bytes contained (located in the NAL header), and the data appears in the form of a Raw Byte Sequence Payload (RBSP), which may also include scattered anti-counterfeiting bytes when necessary.
[0073] access unit
[0074] A group of NAL units associated with each other according to specified rules and consecutive in decoding order.
[0075] It should be noted that from another dimension, the data unit can also include an encoded image.
[0076] Coded picture
[0077] Coded representation of a picture.
[0078] Coded video sequence
[0079] A coded video sequence is the highest-level syntax structure of a bitstream and contains one or more consecutive access units. A coded video sequence starts with an access unit of an IDR (instantaneous decoding refresh picture) picture, an access unit of a RAPI (random access point I picture), an access unit of an RL (reference library picture) reference picture, or an access unit of an output library picture. The end of the stream NAL unit or the end of the coded video sequence NAL unit indicates the end of a coded video sequence. Each coded video sequence contains at most one IDR picture, RAPI picture, RL reference picture, or output library picture. Access units are arranged in bitstream order in the bitstream, and the bitstream order should be the same as the decoding order.
[0080] Security parameter set, SEC
[0081] A security parameter set contains the configuration parameters required for encryption and authentication operations on a compressed video bitstream. At the start of the decoding process, each security parameter set becomes effective as soon as it is received by the decoder and causes any previously effective security parameter set (if any) to become ineffective. A security parameter set NAL unit should be present before the access unit of all random access point (RAP) pictures. The security parameter set NAL unit should be in the same access unit as the sequence parameter set NAL unit, and the security parameter set NAL unit should be before the sequence parameter set NAL unit. Therefore, the scope of a security parameter set is the random access segment in the compressed video bitstream in which it is located, i.e., all AUs in the bitstream from the start of the AU in which the security parameter set is located to the next RAP picture.
[0082] Library picture
[0083] A reference picture of a non-current bitstream used when decoding the current bitstream. Each picture corresponds to a sequence parameter set, and the coded picture for which the library bitstream flag in the corresponding sequence set parameter is 1. The NAL unit type of the coded slice of a library picture is 12, 17, or 18, and the library picture is associated with a privacy coded slice.
[0084] Output library picture
[0085] Each frame of image corresponds to a sequence parameter set, and is an encoded image with the knowledge bitstream flag being 1 and the knowledge image mode index being 1 in the corresponding sequence set parameters. The NAL unit type of the coded slice for displaying the knowledge image is 17. The displayed knowledge image is a random access point image, and the displayed knowledge image as the leading library picture of an RL picture is not a random access point image.
[0086] Non-output library picture
[0087] Each frame of image corresponds to a sequence parameter set, and is an encoded image with the knowledge bitstream flag being 1 and the knowledge image mode index being 0 or 2 in the corresponding sequence set parameters. The NAL unit type of the coded slice for the non-output library picture is 12 or 18.
[0088] Leading library picture of an RL picture
[0089] A non-output library picture whose bitstream order is before an associated RL picture or a displayed knowledge picture newly appeared before an RL picture after bitstream editing, and there is no access unit of other images between the access unit where the first knowledge image coded slice of this knowledge picture is located and the access unit of the associated RL picture. The leading library picture of an RL picture is not a random access point image.
[0090] Non-leading library picture of an RL picture
[0091] A non-output library picture whose bitstream order is before an associated RL picture, and there is at least one access unit of other images between the access unit where the first knowledge image coded slice of this non-output library picture is located and the access unit of the associated RL picture. The non-leading library picture of an RL picture is not a random access point image.
[0092] Output picture
[0093] An RL picture, IDR picture, P picture, B picture or RAPI picture whose reconstructed image is output after being decoded by the decoder. It should be noted that both the displayed knowledge picture and the non-output library picture do not belong to the output picture.
[0094] Reference picture
[0095] An image used for inter-frame prediction of subsequent image frames during the decoding process.
[0096] Coded patch
[0097] The coded representation of a slice. NAL units within the same coded slice unit shall be adjacent.
[0098] An image is a frame of a coded video sequence, and its coded data is contained in one or more access units. Its coded image consists of an image header NAL unit, supplementary enhancement information (if any), and all the coded slice NAL units of that image. Specifically, the coded image of an IDR image includes an image header NAL unit, zero or more supplementary extension description NAL units of that IDR image, and all the IDR image coded slice NAL units of that IDR image. The coded image of a RAPI image includes an image header NAL unit, zero or more supplementary extension description NAL units of that RAPI image, and all the RAPI image coded slice NAL units of that RAPI image. The coded image of a P image and a B image includes an image header NAL unit, zero or more supplementary extension description NAL units of that P image or B image, and all the NRAP image coded slice NAL units of that P image or B image. The coded image of a RL image includes an image header NAL unit, zero or more supplementary extension description NAL units of that RL image, and all the RL image coded slice NAL units of that RL image. The coded image of a knowledge image consists of an image header NAL unit, one or more knowledge image coded slice NAL units, and one or more privacy image coded slice NAL units. The RL pre-knowledge image, the privacy image coded slice NAL units, and all the coded slice NAL units in the coded image of the displayed knowledge image are consecutive. Its access unit contains all the NAL units of the coded image. The coded slices of a non-RL pre-knowledge image can be interleaved with the access units of the displayed image as an access unit.
[0099] The first coded slice NAL unit of an image shall immediately follow the image header NAL unit of that image. For the coded image of an IDR image, a RAPI image, a RL image, or a knowledge image, the image header NAL shall immediately follow an image parameter set NAL unit, and that image parameter set NAL shall immediately follow a sequence parameter set NAL unit.
[0100] In particular, between multiple knowledge image bitstream slices of a non-RL pre-knowledge image, one or more bitstreams of displayed images can be interleaved, but the interleaved bitstreams of the displayed images shall not be access units of RL images, IDR images, or RAPI images. All the knowledge image bitstream slices of a RL pre-knowledge image or a displayed knowledge image shall be consecutive. After each knowledge image bitstream slice, it can be interleaved with privacy image coded slice NAL units (if any), but not with the bitstream of the displayed image.
[0101] The bitstreams of all slices of a knowledge image shall be located before the bitstream of the first RL image referring to the knowledge image. The knowledge image bitstream slices of different knowledge images shall not be interleaved. The knowledge image referred to by an RL image is the knowledge image represented by the access unit of the first knowledge image found in reverse order in the decoding order starting from the RL access unit in the bitstream.
[0102] It should be noted that the present application does not group data units, but for the convenience of description, the term "data unit" is used for description.
[0103] Exemplarily, a data unit may include n data units, all of which are data units to be authenticated, and n is a positive integer. Correspondingly, the authentication data may include n digest data, and the n digest data correspond to the n data units one by one. Exemplarily, "a group of data units" may also be described as "n data units".
[0104] Exemplarily, multiple digest data of a group of data units may form a digest data list; that is to say, the authentication data may include a digest data list.
[0105] Exemplarily, the authentication data may be Auth.
[0106] Exemplarily, the signature data may be signature.
[0107] Exemplarily, the digest data may also be referred to as authentication digest data.
[0108] Exemplarily, the bitstream may be an audio compression bitstream (or referred to as an audio compression bitstream) or a video compression bitstream (or referred to as a compressed video bitstream), and the present application does not limit this. The present application takes signing and authenticating a video compression bitstream as an example for illustration.
[0109] Exemplarily, the signing and authentication method involved in the present application may be applied to sign and authenticate any one of an audio compression bitstream (or referred to as an audio compression bitstream) or a video compression bitstream (or referred to as a compressed video bitstream), and the present application does not limit this. The present application takes signing and authenticating a video compression bitstream as an example for illustration.
[0110] As Figure 1 shown, Figure 1 is a schematic diagram of the application scenario provided by the present application. Figure 1 It shows a monitoring scenario, a live broadcast scenario, and an on-demand scenario.
[0111] Referring to Figure 1, Exemplarily, in a monitoring scenario, the camera 11 can sign the monitoring video stream to obtain the signed monitoring video stream 101. Then, the signed monitoring video stream 101 is sent to the laptop 13 through the network 12. After that, the laptop 13 can authenticate the signed monitoring video stream 101 to obtain the authentication result 105 and display it, and play the monitoring video 104.
[0112] Referring to Figure 1 , Exemplarily, in a live broadcast scenario, the mobile phone 14 can sign the live broadcast video stream to obtain the signed live broadcast video stream 102. Then, the signed live broadcast video stream 102 is sent to the mobile phone 15 through the network 12. After that, the mobile phone 15 can authenticate the signed live broadcast video stream 102 to obtain the authentication result 107 and display it, and play the live broadcast video 106.
[0113] Referring to Figure 1 , Exemplarily, in an on-demand scenario, the personal computer 16 can sign the on-demand video stream to obtain the signed on-demand video stream 103. Then, the signed on-demand video stream 103 is sent to the mobile phone 17 through the network 12. After that, the mobile phone 17 can authenticate the signed on-demand video stream 103 to obtain the authentication result 109 and display it, and play the on-demand video 108.
[0114] It should be understood that the present application can also be used in other scenarios of audio and video encoding and decoding, such as digital content trust scenarios, etc., and the present application does not limit this.
[0115] As Figure 2 shown, Figure 2 is a schematic structural diagram of the signature and authentication system provided by the present application. The authentication and signature processes in Figure 2 are described above. Figure 1 in
[0116] Referring to Figure 2 , Exemplarily, the signature and authentication system 200 can include a signature end 210 and an authentication end 220.
[0117] For example, the signature end 210 can be the camera 11, the mobile phone 14, and the personal computer 16 above, and the authentication end 220 can be the laptop 13, the mobile phone 15, and the mobile phone 17 above. Figure 1 in Figure 1 in
[0118] It should be understood that the same terminal device can serve as both the signature end 210 and the authentication end 220, and the present application does not limit this.
[0119] Continuing to refer to Figure 2, Exemplarily, after the signature end 210 obtains the video data 201, it can perform video encoding 21 on the video data 201 to obtain a bitstream 202; and perform video signature 22 on the bitstream 202 to obtain a signed bitstream 203.
[0120] For example, the video data 201 can be the surveillance video captured by the camera 11, the live video recorded by the mobile phone 14, or the on-demand video produced by the personal computer 16 as described above. Figure 1
[0121] For example, the signed bitstream 203 can be the signed surveillance video bitstream 101, the signed live video bitstream 102, or the signed on-demand video bitstream 103 as described above. Figure 1
[0122] It should be noted that the two operations of video encoding 21 and video signature 22 can be executed in parallel.
[0123] It should be noted that in one possible way, the signature end 210 can include an encoder, and the encoder performs video encoding 21 and video signature 22. In one possible way, the signature end 210 can include an encoder and a signature module, the encoder performs video encoding 21 and the signature module performs video signature 22. In one possible way, the signature end 210 can include a signature module, and the signature module performs video encoding 21 and video signature 22.
[0124] After that, the signature end 210 can send the signed bitstream 203 to the authentication end 220.
[0125] Continuing to refer to Figure 2 , Exemplarily, after the authentication end 220 receives the signed bitstream 203, it can perform video authentication 23 on the signed bitstream 203 to obtain an authentication result 205; and can perform video decoding 24 on the bitstream 202 in the signed bitstream 203 to obtain decoded video data 204.
[0126] For example, the decoded video data 204 can be the surveillance video 104, the live video 106, or the on-demand video 108 as described above. Figure 1
[0127] For example, the authentication result 205 can be the authentication result 105, the authentication result 107, or the authentication result 109 as described above. Figure 1
[0128] It should be noted that the two operations of video authentication 23 and video decoding 24 can be executed in parallel.
[0129] It should be noted that, in one possible way, the authentication end 220 may include a decoder, and the decoder performs video decoding 24 and video authentication 23. In one possible way, the authentication end 220 may include a decoder and an authentication module, where the decoder performs video decoding 24 and the authentication module performs video authentication 23. In one possible way, the authentication end 220 may include an authentication module, and the authentication module performs video decoding 24 and video authentication 23.
[0130] It should be noted that when the signing end 210 performs lossless encoding, the video data is the same as the decoded video data; when the signing end 210 performs lossy encoding, there are differences between the video data and the decoded video data.
[0131] It should be noted that the encoder, decoder, and authentication module can be implemented by software or by hardware, and this application does not limit this.
[0132] As Figure 3a shown, Figure 3a is a schematic flowchart of the signing method provided by this application. Among them, process 300 can be implemented by the signing end 210.
[0133] S301, generate a security parameter set.
[0134] The security parameter set includes a knowledge image identifier, and the knowledge image identifier is used to indicate that the security parameter set acts on the knowledge image or the display image.
[0135] As a possible implementation, the signing end 210 generates a security parameter set for the data unit of the knowledge image or the display image. The knowledge image identifier of the security parameter set for the knowledge image indicates that the security parameter set acts on the knowledge image, that is, the scope of action of the security parameter set is the knowledge image (or the data unit of the knowledge image, the knowledge image data unit). The knowledge image identifier of the security parameter set for the display image indicates that the security parameter set acts on the display image, that is, the scope of action of the security parameter set is the display image (or the data unit of the display image, the display image data unit)
[0136] Optionally, the value of the knowledge image identifier can be a binary variable. For example, when the knowledge image identifier is the first value, it indicates that the security parameter set acts on the knowledge image, and when the knowledge image identifier is the second value, it indicates that the security parameter set acts on the display image. Among them, the first value can be 1, the second value can be 0, or the first value can be 0, and the second value can be 1. Taking the first value of the knowledge image identifier being 1 to indicate that the security parameter set acts on the knowledge image and the second value being 0 to indicate that the security parameter set acts on the display image as an example, the knowledge image identifier of the security parameter set corresponding to the knowledge image is 1, and the knowledge image identifier of the security parameter set corresponding to the display image is 0.
[0137] A data unit is a basic syntax structure for an encoded bitstream (such as a compressed video bitstream), which can be a NAL unit, an access unit, or a layer unit. A group of data units can also be referred to as a bitstream segment in the bitstream.
[0138] Reference Figure 3a , exemplarily, the n data units that need to be authenticated in the compressed video bitstream are respectively: data unit 1, data unit 2,..., data unit n. These n data units that need to be authenticated can be referred to as a group of data units. A group of data units involved hereinafter all refer to the data units that need to be authenticated.
[0139] It should be noted that the present application does not group the data units, but for the convenience of description, the term "a group of data units" is used to describe.
[0140] , exemplarily, data unit 1 is a data unit of a knowledge image, and data units 2,..., data unit n are data units of a display image.
[0141] The signature end 210 generates a security parameter set 1 for data units 2,..., data unit n, and at the same time generates an independent security parameter set 2 for data unit 1. Thus, the security parameter set 1 acts on the data units of the display image, and its scope of action is also referred to as the display image; the security parameter set 2 acts on the data units of the knowledge image, and its scope of action is also referred to as the knowledge image.
[0142] The security parameter set will be introduced in detail below.
[0143] The security parameter set contains the configuration parameters required for encrypting and authenticating the compressed video bitstream. At the beginning of the decoding process, each security parameter set becomes effective when received by the decoder, and will cause the previously effective security parameter set (if any) to become invalid. A security parameter set should exist before the access unit of all random access point images. The security parameter set should be in the same access unit as the sequence parameter set NAL unit, and the security parameter set should be located before the sequence parameter set. Therefore, the scope of action of the security parameter set is the random access segment in the compressed video bitstream, that is, all access units in the bitstream starting from the access unit where the security parameter set is located to before the next RAP image.
[0144] The safety parameter set may be a safety parameter set NAL unit. The safety parameter set NAL unit includes a safety verification set RBSP. The safety parameter set RBSP includes some parameters, and these parameters can be used by one or more other types of NAL units. The knowledge image is encrypted or authenticated independently of the display image, and whether it is a safety parameter set of the knowledge image is distinguished by the is_library_flag in the safety parameter data RBSP. The bitstream may contain multiple safety parameter sets, which are distinguished by the safety parameter set ID sec_para_set_id, and at most 3 safety parameter sets are supported simultaneously. There should be a safety parameter set NAL unit before the random access point access unit of the RAS or the first knowledge image access unit, which acts on the current RAS or knowledge image. The safety parameter set provides parameters for the encryption and authentication of the current RAS or knowledge image access unit. In the case of multiple safety parameter sets, sec_para_set_id is used for distinction; if there is no safety parameter set NAL unit in the random access point access unit of the RAS, it is considered that the current RAS (excluding non-display knowledge image access units) is not encrypted and does not participate in authentication; if there is no safety parameter set NAL unit in the first knowledge image access unit, it is considered that the current knowledge image is not encrypted and does not participate in authentication.
[0145] As a possible implementation, the knowledge image identifier can be incorporated into the safety parameter set according to the syntax table shown in Table 1 according to the preset syntax.
[0146] Table 1
[0147]
[0148]
[0149] Among them, sec_is_library_flag is the knowledge image identifier, a binary variable. The value of '1' indicates that this safety parameter set acts on the knowledge image, and the value of '0' indicates that this safety parameter set acts on the display image.
[0150] sec_para_set_id is the safety parameter set ID, a 2-bit unsigned integer. It is used to distinguish different safety parameter sets acting on the same RAS or knowledge image access unit, and the value range is 1 to 3.
[0151] The encryption_enable_flag is an encryption enable flag, a binary variable. A value of '1' indicates support for encrypting the coded slice of the display image, or the sequence parameter set of the display image sequence, or the picture parameter set of the display image, or the coded slice of the non-display knowledge image, or the coded slice of the display knowledge image, or the sequence parameter set of the knowledge image, or the picture parameter set of the knowledge image, or the extended data unit, that is, the RBSP in the NAL unit may be encrypted. A value of '0' indicates that encryption of the RBSP in the NAL unit is not supported.
[0152] The authentication_enable_flag is an authentication enable flag, a binary variable. A value of '1' indicates support for authenticating the current RAS or knowledge image. The NAL units that can participate in authentication include the coded slices of the display image or knowledge image in the current RAS, as well as the sequence parameter set, picture parameter set, security parameter set, extended data unit, and supplementary enhancement information transmitted in this access unit. When support for authenticating the above data content exists, the authentication data carried in the coded bitstream should be Base64 encoded. The authentication data is transmitted through the NAL unit with nal_unit_type equal to 10. A value of '0' indicates that the current security parameter set does not support authenticating the RAS or knowledge image, and there should be no NAL unit with nal_unit_type equal to 10 for the RAS or knowledge image generated using this security parameter set.
[0153] The knowledge image only supports independent signature authentication, and the display image supports joint signature authentication. Multiple display image access units participating in joint signature authentication should be in the same RAS. The image types in multiple access units participating in joint signature can be display images. For the independent signature authentication of the knowledge image, an independent security parameter set independent of the display image is used for independent signature authentication, and it is distinguished by sec_is_library_flag in the security parameter set.
[0154] If there are NAL units with authentication_idc greater than 0 and nal_unit_type equal to 1 to 3, 5 to 9, 12, 14, 17, 18, and 19 in an access unit, for the NAL units with the same authentication_idc value greater than 0 and the same layer_id value in each layer unit of this access unit, after arranging them in bitstream order, a digest calculation is performed to generate the digest data of the NumOfLayers layer units corresponding to the authentication_idc of this access unit. The digest calculation method is specified by hash_type.
[0155] For hash_period_in_doi_minus1 + 1 access units, calculate the digest of each layer unit in each access unit in the bitstream order. The scope of the authentication data should not cross the RAS; then calculate the secondary digest in the method indicated by authentication_hash_mode in sequence.
[0156] Perform a digital signature on the secondary digest value to generate the authentication data RBSP and package it into the authentication data RBSP NAL unit.
[0157] If the values of authentication_enable_flag and encryption_enable_flag in multiple sets of security parameters in the bitstream are equal to 1, that is, the current RAS or knowledge image supports both encryption and authentication, then it should be encrypted first and then authenticated, that is, the data used for authentication should be the encrypted NAL unit.
[0158] encryption_unit_mode is the basic encryption unit, an unsigned integer of 2 bits. It indicates the basic encryption unit. The value of '0' means encryption is performed in units of NAL; the value of '1' means encryption is performed in units of access units. The parts of all NAL unit RBSPs in the access unit that need to be encrypted are concatenated in the bitstream order and then encrypted, and after encryption, it is restored to the encrypted NAL unit; the value of '2' means encryption is performed in units of layer units. The parts of all NAL unit RBSPs in the layer unit that need to be encrypted are concatenated in the bitstream order and then encrypted, and after encryption, it is restored to the encrypted NAL unit; the value of '3' is reserved. The IV needs to be re-initialized for each encryption.
[0159] The encryption_level_mode is the encryption level mode, which is a 2-bit unsigned integer. It indicates the encryption level mode. When the value is '0', it means that when encrypting all types of NAL units, the encryption object is all RBSP data (except the last byte of the RBSP); when the value is '1', it means that when encrypting NAL units with nal_unit_type equal to 1, 2, 4, 12, 14, 17, 18, and 19, the encryption object is the first encryptionByte bytes of the RBSP, and when encrypting other types of NAL units, the encryption object is all RBSP data (except the last byte of the RBSP); when the value is '2', it means that when encrypting NAL units with nal_unit_type equal to 1, 2, 4, 5, 12, 14, 17, 18, and 19, the encryption object is the first encryptionByte bytes of the RBSP, and when encrypting other types of NAL units, the encryption object is all RBSP data (except the last byte of the RBSP); the value '3' is reserved. Among them, encryptionByte = Min(EncryptionNum * EncryptionBaseByte, NumBytesInPayload - 1).
[0160] The encryption_num_minus1 is the number of encryption basic byte lengths, which is an 8-bit unsigned integer. It indicates the number of encryption basic byte lengths. The value of the encryption basic byte length EncryptionNum is equal to the value of encryption_num_minus1 plus 1.
[0161] The encryption_base_byte is the encryption basic byte length, which is a 2-bit unsigned integer. It indicates the encryption basic byte length. When the value is '0', it means that the value of the encryption basic byte length EncryptionBaseByte is 16; when the value is '1', it means that the value of the encryption basic byte length EncryptionBaseByte is 64; when the value is '2', it means that the value of the encryption basic byte length EncryptionBaseByte is 256; when the value is '3', it means that the value of the encryption basic byte length EncryptionBaseByte is 1024.
[0162] The encryption_type is the encryption type, which is a 4-bit unsigned integer. It indicates the algorithm used for encryption. The specific corresponding relationship is shown in Table 2.
[0163] Table 2
[0164] Value of encryption_type Encryption algorithm 0 SM1 1 SM4 2~15 Reserved
[0165] The vek_flag is the video encryption key flag, a binary variable. A value of '1' indicates that the vek is carried, and a value of '0' indicates that the vkek is not carried.
[0166] The iv_flag is the initialization vector flag, a binary variable. A value of '1' indicates that the iv is carried, and a value of '0' indicates that the iv is not carried.
[0167] The vek_encryption_type is the video encryption key encryption type, a 4-bit unsigned integer. It indicates the encryption type of the video encryption key.
[0168] The evek_length_minus1 is the encrypted video encryption key length, an 8-bit unsigned integer. It indicates the length of the encrypted video encryption key in bytes.
[0169] The evek is the encrypted video encryption key, an n-bit unsigned integer. It represents the encrypted video encryption key for encryption calculation, with a length of evek_length_minus1 + 1 bytes.
[0170] The vkek_version_length_minus1 is the video encryption key version number length, an 8-bit unsigned integer. It indicates the length of the video encryption key version number in bytes.
[0171] The vkek_version is the video encryption key version number, an n-bit unsigned integer. It indicates the video encryption key version number, with a length of vkek_version_length_minus1 + 1 bytes.
[0172] The iv_length_minus1 is the initialization vector length, an 8-bit unsigned integer. It indicates the length of the initialization vector in bytes.
[0173] The iv is the initialization vector, an n-bit unsigned integer. It indicates the initialization vector for block encryption, with a length of iv_length_minus1 + 1 bytes.
[0174] The hash_type is the hash type, a 2-bit unsigned integer. It indicates the algorithm used for authentication, and the specific correspondence is shown in Table 3.
[0175] Table 3
[0176] Value of hash_type Authentication algorithm Digest data length (bytes) 0 SM3 32 1~3 Reserved Reserved
[0177] The authentication_hash_mode is the authentication digest calculation mode, a binary variable. It identifies the method of calculating the secondary digest. A value of '0' indicates that the connection method is used to calculate the secondary digest, that is, for each layer unit digest values Hpic1, Hpic2,..., Hpicn, in bitstream order, refer to Figure 3b the connection method to perform the secondary digest; a value of '1' indicates that the tree-top method is used to calculate the secondary digest, that is, for the layer unit digest values Hpic1, Hpic2,..., Hpicn, in bitstream order, use Figure 3c the tree-top method shown to perform the secondary digest.
[0178] The hash_discard_nrap_pictures_flag is the non-random access point picture hash authentication flag, a binary variable. A value of '1' indicates that the non-random access point pictures are not authenticated; equal to 0 indicates that the non-random access point pictures can be authenticated. If hash_discard_nrap_pictures is not in the bitstream, its default value is equal to 1.
[0179] The hash_period_in_doi_minus1 is the hash period, an 8-bit unsigned integer, with a value range of 0 to (MAX_HASH_PERIOD / NumOfLayers - 1), where MAX_HASH_PERIOD is set to 256. HashPeriodInDoi is equal to hash_period_in_doi_minus1 + 1. It indicates the number of access units participating in the signature authentication related to an authentication data. This number is less than or equal to HashPeriodInDoi. A HashPeriodInDoi of 1 indicates independent signature for a single access unit, and the authentication data NAL unit carrying this signature should be located at or after the first access unit associated with this signature. A HashPeriodInDoi greater than 1 indicates joint signature for multiple access units.
[0180] The signature_type is the digital signature type, a 2-bit unsigned integer. It indicates the algorithm for digitally signing the digest data of the image, as shown in Table 4.
[0181] Table 4
[0182]
[0183]
[0184] The signature_fmt is the signature data format, a 2-bit unsigned integer. It indicates the signature data format. The specific regulations on the corresponding relationship between the value meanings of signature_fmt and the syntax of signature_type are shown in Table 5.
[0185] Table 5
[0186]
[0187] Exemplarily, for the display image, the security parameter set 1sec_is_library_flag is set to 0, indicating that signature authentication is performed on the display image, and the scope of the security parameter set is a single RAS. All access units participating in the authentication cannot cross RAS and cannot be in two RASs.
[0188] The generation method of the security parameter set 1 can be as follows:
[0189] Step 1: Set sec_para_set_id according to the configuration;
[0190] Step 2: Set sec_is_library_flag to 0, authentication_enable_flag to 1 (indicating enabling authentication), hash_type to 0 (using the SM3 algorithm), and set the authentication_hash_mode value to 0 or 1 (calculating the secondary digest using the connection method or the tree-top method) according to the configuration;
[0191] Step 3: Set hash_discard_nrap_pictures_flag according to the configuration. If it is necessary to authenticate non-random access point images, set it to 0, otherwise set it to 1;
[0192] Step 4: Set hash_period_in_doi_minus1 to HashPeriodInDoi minus 1 according to the configured hash period HashPeriodInDoi; HashPeriodInDoi being 1 indicates independent signature for a single access unit, and HashPeriodInDoi being greater than 1 indicates joint signature for multiple access units.
[0193] Exemplarily, for the knowledge image, the sec_is_library_flag of the security parameter set 2 is 1, indicating independent signature authentication for the knowledge image, and the scope of the security parameter set is a single knowledge image. The knowledge images participating in the authentication cannot cross RAS and cannot be in two RASs. Each knowledge image, including the display knowledge image and the non-display knowledge image, should be independently signed and authenticated.
[0194] The generation method of the security parameter set 2 can be as follows:
[0195] Step 1: Set sec_para_set_id according to the configuration;
[0196] Step 2: Set sec_is_library_flag to 1, authentication_enable_flag to 1 (indicating that authentication is enabled), hash_type to 0 (using the SM3 algorithm), and set the value of authentication_hash_mode to 0 or 1 according to the configuration (using the connection method or the tree-top method to calculate the secondary digest);
[0197] Step 3: Set hash_discard_nrap_pictures_flag to 0 or 1 according to the configuration, which has no effect;
[0198] Step 4: Set hash_period_in_doi_minus1 to HashPeriodInDoi minus 1 according to the configured hash period HashPeriodInDoi; since the knowledge graph has no DOI, a knowledge graph generates only one authentication data for one set of security parameters.
[0199] S302, calculate the digest data of the display image or the knowledge graph corresponding to the set of security parameters.
[0200] When calculating the digest of an access unit, calculate the digest data for the NAL units of the layer units to be authenticated in the access unit (including the security parameter set NAL unit (if any), the picture sequence parameter set NAL unit (if any), the picture parameter set NAL unit (if any), the picture header NAL unit, the display image hierarchical coded slice NAL unit, the extended data NAL unit (if any), the supplementary enhancement information NAL unit (if any), etc.).
[0201] As a possible implementation, the calculation method of the digest data of the display image can be as follows:
[0202] Step 1: Set authentication_idc in the header information of these NAL units to sec_para_set_id in this set of security parameters; (Note: When generating the bitstream, if the authentication_idc of the NAL units with the same layer_id is non-zero, it is recommended to use the set of security parameters with the same sec_para_set_id.)
[0203] Step 2: Set the authentication_data_id of the current NAL unit. If there is a NAL unit participating in authentication with the same authentication_data_id in the previous group, the authentication_data_id should be different from that of the previous group; otherwise, if this NAL unit participates in authentication together with the security parameter set NAL unit, the authentication_data_id also needs to be consistent with the authentication_data_id of the security parameter set NAL unit; otherwise, set it to 0 or 1.
[0204] Step 3: Then splice all the NAL units participating in authentication in this layer unit together to calculate the digest of this layer unit.
[0205] Take out the HashPeriodInDoi access units participating in authentication from the compressed video bitstream output by the encoder according to the configuration, and calculate the digests H1, H2, …, Hn of each layer unit in each access unit in the order of the bitstream, where n is equal to the total number of layer units participating in authentication in all access units. The scope of action of the authentication data should not cross RAS, so the number of access units authenticated together in the last group in each RAS may be less than HashPeriodInDoi.
[0206] Calculate the secondary digest based on each digest value in the manner specified by authentication_hash_mode.
[0207] As a possible implementation method, the calculation method of the digest data of the knowledge image can be as follows:
[0208] Step 1: Set the authentication_idc in the header information of these NAL units to the sec_para_set_id in the corresponding security parameter set.
[0209] Step 2: Set the authentication_data_id of the current NAL unit. If there is a NAL unit participating in authentication with the same authentication_data_id in the previous group, the authentication_data_id should be different from that of the previous group; otherwise, if this NAL unit participates in authentication together with the security parameter set NAL unit, the authentication_data_id also needs to be consistent with the authentication_data_id of the security parameter set NAL unit; otherwise, set it to 0 or 1.
[0210] Step 3: Then splice all the NAL units participating in the authentication in this layer unit together to calculate the digest of this layer unit.
[0211] When the knowledge image is a display knowledge image, the coded slice NAL units of this knowledge image are included in a single access unit, and calculate the digest data H1, H2, …, Hn of the layer units participating in the authentication of this access unit in bitstream order, where n is the total number of layer units in the knowledge image access unit;
[0212] When the knowledge image is a non-display knowledge image, the coded slice NAL units of this knowledge image may be included in multiple access units, and calculate the digests H1, H2, …, Hn of the layer units participating in the authentication of these multiple access units in bitstream order, where n is the total number of layer units in the knowledge image access unit.
[0213] Calculate the secondary digest based on each digest value H1, H2, …, Hn in the manner specified by authentication_hash_mode.
[0214] S303: Sign the digest data to obtain the signature data.
[0215] As a possible implementation, perform a digital signature on the secondary digest to obtain the signature data.
[0216] S304: Generate the authentication data for the security parameter set corresponding to the display image or the knowledge image; the authentication data includes the signature data.
[0217] As a possible implementation, generate the authentication data according to one or more security parameter sets respectively. For example, generate the authentication data for the display image according to security parameter set 1, and generate the authentication data for the knowledge image according to security parameter set 2.
[0218] Optionally, the generation method of the authentication data for the knowledge image can be as follows:
[0219] Step 1: Set for_current_ras_idc to 0 and auth_is_library_flag to 0;
[0220] Step 2: Set the authentication_data_id of the current authentication data, and this authentication_data_id is the same as the authentication_data_id of the NAL units participating in this authentication.
[0221] Step 3: Set authentication_hash_list_flag according to the configuration. 0 indicates that the authentication data does not contain a digest list, and 1 indicates that the authentication data contains a digest list. When authentication_hash_list_flag is 1, set authentication_hash_number_minus1 to the number of digests minus 1, and authentication_hash to the digest values {H1, H2, …, Hn} of the display image.
[0222] Step 4: Write the signature data into authentication_data, and set authentication_data_length_minus1 to the actual length of authentication_data minus 1.
[0223] Optionally, the authentication data may also include digest data. For example, the authentication data of data unit 1 includes the digest data of data unit 1.
[0224] Optionally, the generation method of the authentication data of the knowledge image may be as follows:
[0225] Step 1: Set auth_is_library_flag to 1 and authenticaion_library_picture_index to the library_picture_index of the knowledge image;
[0226] Step 2: Set the authentication_data_id of the current authentication data, which is the same as the authentication_data_id of the NAL unit participating in this authentication;
[0227] Step 3: Set authentication_hash_list_flag according to the configuration. 0 indicates that the authentication data does not contain a digest list, and 1 indicates that the authentication data contains a digest list. When authentication_hash_list_flag is 1, set authentication_hash_number_minus1 to the number of layer unit digests minus 1, and authentication_hash to the data values of the layer unit digests.
[0228] Write the signature data into authentication_data, and set authentication_data_length_minus1 according to the actual length of authentication_data minus 1.
[0229] Optionally, the authentication data may further include digest data. For example, the authentication data of data unit 1 includes the digest data of data unit 1.
[0230] As a possible implementation, the definition of the authentication data RBSP can be as shown in Table 6.
[0231] Table 6
[0232]
[0233]
[0234] Among them, for_current_ras_idc is the authentication data position identifier, a binary variable. Its value of '1' indicates that all access units corresponding to the digests in the digest list of this authentication data are within the current random access segment. If it is '0', it indicates that all access units corresponding to the digests in the digest list of this authentication data are not within the current random access segment. All access units with a common signature should be within the same random access segment.
[0235] auth_is_library_flag is the knowledge image authentication data flag bit, a binary variable. Its value of '1' indicates that this authentication data is the signature data of the knowledge image; its value of '0' indicates that this authentication data is the signature data of the display image or the display knowledge image. The value of AuthIsLibraryFlag is equal to the value of auth_is_library_flag. If auth_is_library_flag does not exist in the bitstream, the value of AuthIsLibraryFlag is 0.
[0236] authenticaion_library_picture_index is the authentication knowledge image index, an n-bit unsigned integer. It indicates the index of the knowledge image corresponding to the knowledge bitstream to which the current authentication data applies. The value range is 0 to 511. If authenticaion_library_picture_index does not exist in the bitstream, its default value is equal to 0.
[0237] The authentication_data_id is the authentication data identifier, a 1-bit unsigned integer. The value range is 0 to 1, which is the identifier of the authentication data. For the authentication data NAL units with the same authentication_idc value, the authentication data NAL units with the authentication_data_id value of 0 or 1 should appear alternately in the coded video sequence, that is, the authentication_data_id values of two adjacent authentication data NAL units in a coded video sequence in decoding order should not be the same.
[0238] The authentication_hash_list_flag is the authentication digest list identifier, a binary variable. A value of '1' indicates that the authentication data carries the digest list of the access unit that generates the signature in the authentication data. A value of '0' indicates that the authentication data does not carry the digest list of the access unit that generates the signature in the authentication data.
[0239] The authentication_hash_number_minus1 is the number of authentication digests, an 8-bit unsigned integer, and the value range is 0 to 255. Adding 1 to authentication_hash_number_minus1 represents the number of authentication digest data.
[0240] The authentication_hash is the authentication digest data, binary data. It is the digest data obtained by calculating the digest of the access unit according to the digest algorithm corresponding to hash_type in the corresponding security parameter set, and the length is the digest data length hash_size corresponding to the digest algorithm hash_type. The arrangement order of the digests in the digest list carried in the authentication data NAL unit should be the same as the bitstream order of each layer unit therein.
[0241] The authentication_data_length_minus1 is the length of the signature data, an 8-bit unsigned integer. Adding 1 represents the length of the signature data, in bytes, and the value should be 0 to 255.
[0242] authentication_data[i] is the number of bytes of the signature data, an 8-bit unsigned integer. The i-th byte of a signature data. The authentication data NAL unit shall be located after all other types of NAL units in the access unit except the stream end NAL unit and the coded video sequence end NAL unit. The order of the authentication data NAL units corresponding to the same set of security parameters in the bitstream shall be the same as the bitstream order of their corresponding access units, that is, if the first authentication data NAL unit is before the second authentication data NAL unit, then any access unit associated with the first authentication data NAL unit is before any access unit associated with the second authentication data NAL unit.
[0243] S305. Add the authentication data and the set of security parameters to the compressed video bitstream.
[0244] As a possible implementation, add the authentication data and the set of security parameters of the displayed image to the compressed video bitstream.
[0245] Optionally, pack the authentication data of the displayed image into the authentication data NAL unit and then insert the authentication data NAL unit into the last access unit of this authentication or after it, before the next authentication data NAL unit, and before the next-next access unit that is not a random access point access unit of the displayed knowledge image. Set the temporal_id and layer_id of the authentication data NAL unit header to 0. In particular, the last authentication data in each RAS is allowed to be placed in the next RAS. In this case, set the for_current_ras_idc in the authentication data to 0. The interval between the authentication data and the layer unit in the last access unit participating in the authentication shall not exceed HashPeriodInDoi (equal to hash_period_in_doi_minus1 + 1 in the set of security parameters corresponding to this authentication) access units (excluding non-displayed knowledge image access units). Set the authentication_idc of the authentication data NAL unit to the sec_para_set_id in the corresponding set of security parameters, and set the authentication_data_id to the authentication_data_id in the NAL unit header of the layer unit participating in the authentication.
[0246] The authentication data of the displayed image can be located in the access unit where the last coded slice of the displayed image is located; it can also be located in the access unit of the coded slice of the displayed image in the next RAS. The authentication data NAL unit shall be located after all other types of NAL units in the access unit except the stream end NAL unit and the coded video sequence end NAL unit.
[0247] Optionally, the display image security parameter set may be packed into a security parameter set NAL unit and the security parameter set NAL unit may be added to the compressed video bitstream in the following manner:
[0248] Step 1: Set the authentication_idc of the security parameter set NAL unit. Since the layer_id of the security parameter set NAL unit is 0, when authentication_idc is non-zero, authentication_idc is set to the authentication_idc of the layer unit with layer_id of 0, i.e., the sec_para_set_id of the security parameter set selected for authenticating the layer unit where it is located;
[0249] Step 2: Set the authentication_data_id of the security parameter set NAL unit to 0 or 1. It is recommended that it be different from the authentication_data_id of the NAL unit participating in authentication with the same sec_para_set_id and authentication_idc as the previous group;
[0250] Step 3: Add the security parameter set NAL unit before the picture sequence parameter set NAL unit and insert it into the compressed video bitstream.
[0251] As a possible implementation, the authentication data of the knowledge picture may be packed into an authentication data NAL unit, and then the authentication data NAL unit may be inserted into the last access unit of this authentication or after it, before the next authentication data NAL unit, and before the access unit of the next random access point. Set the temporal_id and layer_id of the authentication data NAL unit header to 0. The authentication_idc of the authentication data NAL unit is set to the sec_para_set_id in the corresponding security parameter set, and the authentication_data_id is set to the authentication_data_id in the NAL unit header of the layer unit participating in authentication.
[0252] The interval between the authentication data for displaying the knowledge picture and the access unit for displaying the knowledge picture should not exceed HashPeriodInDoi (equal to hash_period_in_doi_minus1 + 1 in the security parameter set corresponding to this authentication). The authentication data for displaying the knowledge picture may be located in the access unit where the last coded slice of the knowledge picture for display is located; it may also be located in the access unit of the coded picture for display of the next RAS.
[0253] The authentication data of the non-display knowledge image is located in the access unit where the last non-display knowledge image coding slice is located.
[0254] The authentication data NAL unit shall be located after all other types of NAL units in the access unit except for the stream end NAL unit and the coded video sequence end NAL unit.
[0255] Optionally, the security parameter set of the knowledge image is packed into the security parameter set NAL unit, and the security parameter set NAL unit is added to the compressed video bitstream in the following ways:
[0256] Step 1: Set the authentication_idc of the security parameter set NAL unit. Since the layer_id of the security parameter set NAL unit is 0, when the authentication_idc is non-zero, the authentication_idc needs to be the same as the authentication_idc of the layer unit with layer_id of 0, that is, the sec_para_set_id of the security parameter set selected for the authentication of the layer unit where it is located;
[0257] Step 2: Set the authentication_data_id of the security parameter set NAL unit to 0 or 1. It is recommended to be different from the authentication_data_id of the NAL unit participating in the authentication with the same sec_para_set_id and authentication_idc as the previous group;
[0258] Step 3: Add the security parameter set NAL unit before the picture sequence parameter set NAL unit and insert it into the compressed video bitstream.
[0259] It should be noted that S301 to S305 can be executed by the encoder in the signing end 210, or by the signing module in the signing end 210, or by the encoder and the authentication module in the signing end 210 in cooperation. This application does not limit this.
[0260] As Figure 4 shown, Figure 4 is a schematic flowchart of the authentication method provided by this application. Among them, process 400 can be implemented by the authentication end 220.
[0261] S401: Input the compressed video bitstream.
[0262] The compressed video bitstream includes authentication data and a safety parameter set. The authentication data includes signature data. The above authentication data and safety parameter set can be multiple groups. For example, data units 2, …, data unit n are the authentication data of the display image, corresponding to safety parameter set 1; data unit 1 is the authentication data of the knowledge image, corresponding to safety parameter set 2.
[0263] For the safety parameter set corresponding to the display image, such as the safety parameter set NAL unit corresponding to safety parameter set 1, obtain one or more safety parameter set NAL units of the RAS, and obtain sec_para_set_id, authentication_enable_flag, authentication_data_id, hash_type, authentication_hash_mode, hash_discard_nrap_pictures_flag, hash_period_in_doi_minus1 from the safety parameter set. If authentication_enable_flag in the safety parameter set is 0, this safety parameter set does not support authenticating the display image. If hash_discard_nrap_pictures_flag in the safety parameter set is 1, this safety parameter set does not support authenticating non-random access point images.
[0264] For the safety parameter set corresponding to the knowledge image, such as the safety parameter set NAL unit corresponding to safety parameter set 2, obtain sec_para_set_id, sec_is_library_flag, authentication_enable_flag, authentication_data_id, hash_type, hash_period_in_doi_minus1. If authentication_enable_flag in the safety parameter set is 0 or hash_discard_library_pictures_flag is 1, this safety parameter set does not support independent signature authentication of the knowledge image.
[0265] Optionally, when digest data is required for secondary digest authentication, the authentication data further includes digest data.
[0266] S402, calculate the digest data of the display image or knowledge image corresponding to the safety parameter set.
[0267] As a possible implementation, for the display image corresponding to the safety parameter set, the steps of calculating the digest data can be as follows:
[0268] Receive the NAL data of hash_period_in_doi_minus1 + 1 display image access units in the RAS, and splice together the NAL units of the layer units participating in authentication in the access unit to calculate the digest of the layer units. The last set of data participating in authentication together in the RAS may be less than hash_period_in_doi_minus1 + 1.
[0269] Calculate the secondary digest based on each digest value in the bitstream order, and store the secondary digest value in the local cache with sec_para_set_id and authentication_data_id as identifiers;
[0270] Store the digests of multiple layer units with consecutive and identical authentication_data_id, with sec_para_set_id and authentication_data_id as identifiers, and generate a digest list {H1’, H2’, …, Hm’} in the bitstream order in the local cache, where m is equal to the total number of layer units participating in authentication in the access unit. If there is a previous digest list identified by authentication_data_id that has not been authenticated, the layer units generating this digest list fail authentication, and the new digest list overwrites the old one.
[0271] As a possible implementation, for the knowledge image corresponding to the security parameter set, the steps to calculate the digest data can be as follows:
[0272] When the knowledge image is a display knowledge image, the coded slice NAL units of this knowledge image are included in a single access unit, and calculate the digest data H1’, H2’, …, Hm’ of the layer units participating in authentication in this access unit in the bitstream order, where m is the total number of layer units in the knowledge image access unit;
[0273] When the knowledge image is a non-display knowledge image, the coded slice NAL units of this knowledge image may be included in multiple access units, and calculate the digests H1’, H2’, …, Hm’ of the layer units participating in authentication in these multiple access units in the bitstream order, where m is the total number of layer units in the knowledge image access unit.
[0274] Calculate the secondary digest based on each digest value H1’, H2’, …, Hm’, and store the secondary digest value in the local cache with sec_para_set_id and authentication_data_id as identifiers. If authentication_hash_mode is 0, calculate the secondary digest using the concatenation method; if authentication_hash_mode is 1, calculate the secondary digest using the tree-top method.
[0275] Generate a list of digests {H1’, H2’, …, Hm’} identified by sec_para_set_id and authentication_data_id and store them in the local cache.
[0276] S403: Authenticate the display image or knowledge image based on the calculated digest data and authentication data.
[0277] As a possible implementation, for the digest data and authentication data of the display image, the authentication steps for the image can be as follows:
[0278] Start calculating from the access unit where the last display image coding slice participating in the authentication is located up to a maximum of hash_period_in_doi_minus1 + 1 access units to obtain the authentication data.
[0279] When for_current_ras_idc in the authentication data is 1, it means the authentication data is the authentication data of the current RAS; when for_current_ras_idc is 0, it means the authentication data is the last authentication data of the previous RAS.
[0280] When authentication_hash_list_flag in the authentication data is 0, use the secondary digest value for authentication:
[0281] Look up the secondary digest value in the local cache according to sec_para_set_id and authentication_data_id in the authentication data. If the secondary digest value is found, use the secondary digest value to verify the digital signature in the authentication data; if the signature verification is successful, the layer unit participating in generating the secondary digest value is successfully authenticated; if the verification fails, the layer unit participating in generating the secondary digest value fails the authentication. If found and the sec_para_set_id, authentication_data_id are the same as those of the sec_para_set_id and authentication_data_id of the latest received layer unit sequence, and at this time if there are other secondary digest values with identifiers not equal to sec_para_set_id and authentication_data_id that have not been authenticated, then the authentication data corresponding to the unauthenticated secondary digest values is lost, and the layer units corresponding to these unauthenticated secondary digest values fail the authentication. If the secondary digest value of the layer unit corresponding to authentication_data_id is not found, then the authentication data is invalid and the authentication fails.
[0282] When authentication_hash_list_flag is 1, use the digest list for authentication:
[0283] Step 1: Parse the authentication_data_id and the corresponding digest list {H1, H2, …, Hn} from the authentication data NAL unit, and calculate the secondary digest; if authentication_hash_mode is 0, use the concatenation method to calculate the secondary digest; if authentication_hash_mode is 1, use the tree-top method to calculate the secondary digest.
[0284] Step 2: Use the secondary digest value to verify the signature data parsed from the authentication data NAL unit, and determine whether the digest list {H1, H2, …, Hn} transmitted in the authentication data NAL unit passes the verification. If the verification fails, the digest list data in the authentication data is untrustworthy, and the digest list authentication fails.
[0285] Step 3: Determine the layer units participating in the signature according to the parameters in the authentication data NAL unit. Search for the digest list of the layer unit cached locally according to sec_para_set_id and authentication_data_id. If found, the layer unit to be authenticated can be confirmed through the digest list. If found and the sec_para_set_id, authentication_data_id are the same as those of the sec_para_set_id and authentication_data_id of the latest received layer unit sequence, at this time, if there are other unauthenticated digest lists with identifiers not equal to sec_para_set_id and authentication_data_id, the authentication data corresponding to the unauthenticated digest list is lost, and the layer unit authentication corresponding to these unauthenticated digest lists fails. If the digest list of the layer unit corresponding to sec_para_set_id and authentication_data_id is not found, the authentication data is invalid and the authentication fails.
[0286] Step 4: Sequentially match the digest list {H1’, H2’, …, Hm’} of the layer unit with the digest list {H1, H2, …, Hn} in the authentication data to implement the authentication of the layer unit. First, search for H1’ in the digest list in the authentication data. After successful search, record the position of the digest list in the authentication data, and the layer unit corresponding to H1’ is successfully authenticated; then start searching for H2’ from the next position of this position in the digest list in the authentication data. If the search is successful, update the position of the digest list in the authentication data, and the layer unit corresponding to H2’ is successfully authenticated; continue to search for the subsequent H3’, …, Hm’. If the search is successful, the corresponding layer unit is successfully authenticated. If the search fails, the corresponding layer unit is authenticated as failed.
[0287] As a possible implementation, for the summary data and authentication data of the knowledge image, the authentication steps for the image can be as follows:
[0288] If the authenticated image is a displayed knowledge image, calculate up to the maximum hash_period_in_doi_minus1 + 1 access units starting from the layer unit where the last encoded slice of the displayed knowledge image participating in the authentication is located, and receive the authentication data; if the authenticated image is a non-displayed knowledge image, obtain the authentication data after the non-displayed knowledge image encoded slice in the layer unit with layer_id = 0 in the access unit where the last non-displayed knowledge image encoded slice is located.
[0289] When auth_is_library_flag is 1, it is the authentication data of the knowledge image.
[0290] When for_current_ras_idc in the authentication data is 1, it indicates that the authentication data is the authentication data of the current RAS; when for_current_ras_idc is 0, it indicates that the authentication data is the last authentication data of the previous RAS.
[0291] Judge whether the authenticaion_library_picture_index in the authentication data is consistent with the library_picture_index of the current knowledge image. If they are inconsistent, the authentication fails and the authentication ends.
[0292] When authentication_hash_list_flag in the authentication data is 0, use the secondary digest value for authentication:
[0293] Look up the secondary digest value in the local cache according to the sec_para_set_id and authentication_data_id in the authentication data. If the secondary digest value is found, use it to verify the digital signature in the authentication data. If the signature verification is successful, the layer unit that participated in generating the secondary digest value is authenticated successfully; if the verification fails, the layer unit that participated in generating the secondary digest value is authenticated failed. If found and the sec_para_set_id, authentication_data_id are the same as those of the sec_para_set_id and authentication_data_id of the latest received layer unit sequence, and at this time there are other secondary digest values whose identifiers are not equal to sec_para_set_id and authentication_data_id and have not been authenticated, then the authentication data corresponding to the unauthenticated secondary digest value is lost, and the layer units corresponding to these unauthenticated secondary digest values are authenticated failed. If the secondary digest value of the layer unit corresponding to the authentication_data_id is not found, then the authentication data is invalid and the authentication fails.
[0294] When the authentication_hash_list_flag is 1, use the digest list authentication:
[0295] Step 1: Parse the authentication_data_id and the corresponding digest list {H1, H2, …, Hn} from the authentication data NAL unit, and calculate the secondary digest of each digest value. If the authentication_hash_mode is 0, use the concatenation method to calculate the secondary digest; if the authentication_hash_mode is 1, use the tree-top method to calculate the secondary digest.
[0296] Step 2: Use the secondary digest value to verify the signature data parsed from the authentication data NAL unit, and determine whether the digest list {H1, H2, …, Hn} transmitted in the authentication data NAL unit passes the verification. If it does not pass the verification, the digest list data in the authentication data is not trustworthy and the digest list authentication fails.
[0297] Step 3. Determine the layer units participating in the signature according to the parameters in the authentication data NAL unit. Search for the digest list of the layer units cached locally according to sec_para_set_id and authentication_data_id. If found, the layer units to be authenticated can be confirmed through the digest list. If found and the sec_para_set_id, authentication_data_id are the same as those of the sec_para_set_id and authentication_data_id of the latest received layer unit sequence, and at this time there are still unauthenticated digest lists with other identifiers not equal to sec_para_set_id and authentication_data_id, then the authentication data corresponding to the unauthenticated digest lists is lost, and the layer units corresponding to these unauthenticated digest lists fail the authentication. If the digest list of the layer units corresponding to sec_para_set_id and authentication_data_id is not found, the authentication data is invalid and the authentication fails.
[0298] Step 4. Sequentially match the digest list {H1’, H2’, …, Hm’} of the layer units with the digest list {H1, H2, …, Hn} in the authentication data to implement the authentication of the layer units. First, search for H1’ in the digest list in the authentication data. After successful search, record the position of the digest list in the authentication data, and the layer unit corresponding to H1’ is successfully authenticated. Then, start searching for H2’ from the next position of this position in the digest list in the authentication data. If the search is successful, update the position of the digest list in the authentication data, and the layer unit corresponding to H2’ is successfully authenticated. Continue to search for subsequent H3’, …, Hm’. If the search is successful, the corresponding layer unit is successfully authenticated. If the search fails, the corresponding layer unit fails the authentication.
[0299] It can be understood that, in order to implement the functions in the above embodiments, the signature end 210 and the authentication end 220 include the corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should easily realize that, combining the units and method steps of each example described in the embodiments disclosed in the present application, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the way of hardware or computer software driving hardware depends on the specific application scenario and design constraint conditions of the technical solution.
[0300] In the above text, in combination with Figures 1 to 4 , the signature and authentication methods provided according to this embodiment are described in detail. Next, in combination with Figure 5 and Figure 6 , the signature device and the authentication device provided according to this embodiment will be described.
[0301] Figure 5 Schematic diagram of the signature device provided for this application. The signature device can be used to execute the method of the foregoing embodiment. Therefore, the beneficial effects it can achieve can refer to the beneficial effects in the corresponding method provided above, which will not be elaborated here.
[0302] Referring to Figure 5 , Figure 5 A signature device provided for this application. Exemplarily, the signature device 500 includes:
[0303] A parameter set generation module 501 for generating a security parameter set; the security parameter set includes a knowledge image identifier, and the knowledge image identifier is used to indicate that the security parameter set acts on the knowledge image or the display image.
[0304] An abstract calculation module 502 for calculating the abstract data of the display image or the knowledge image corresponding to the security parameter set.
[0305] A signature module 503 for signing the abstract data to obtain signature data.
[0306] An authentication generation module 504 for generating authentication data of the display image or the knowledge image corresponding to the security parameter set; the authentication data includes signature data.
[0307] An output module 505 for adding the authentication data and the security parameter set to the compressed video bitstream.
[0308] Exemplarily, when the knowledge image identifier takes the first value, it indicates that the security parameter set acts on the knowledge image, and when the knowledge image identifier takes the second value, it indicates that the security parameter set acts on the display image.
[0309] Exemplarily, the authentication data is located in or after the last access unit of the current authentication, before the next authentication data NAL unit, and before the next next random access point access unit.
[0310] Exemplarily, the knowledge image is a display knowledge image, and the interval between the access unit of the authentication data and the display knowledge image does not exceed the number of access units equal to the hash period value.
[0311] Exemplarily, the knowledge image is a non-display knowledge image, and the authentication data is located in the access unit where the last non-display knowledge image coding slice is located.
[0312] Exemplarily, the security parameter set further includes a security parameter set identifier, and the security parameter set identifier is used to distinguish different security parameter sets acting on the same random access segment or knowledge image access unit.
[0313] Exemplarily, the security parameter set further includes a hash period, and the hash period is used to indicate the maximum number of access units in the bitstream segment.
[0314] Exemplarily, the authentication data includes digest data. The digest data is used to authenticate the display image or the knowledge image.
[0315] Exemplarily, for the knowledge image, a sequence parameter set corresponds to each frame of image, and the coded image with the knowledge bitstream flag being 1 in the corresponding sequence set parameters; the display image is the reference knowledge image, the instantaneously decoded refresh image, the P image, the B image, or the random access point I-frame image output by the decoder after decoding the reconstructed image.
[0316] For more implementable content of the signature device 500, reference may be made to the steps executed by the signature end 210 in the above method embodiment. The signature device 500 can be used to implement the functions of the signature end 210 in the above method embodiment, and thus can also achieve the beneficial effects of the above method embodiment.
[0317] Figure 6 This is a schematic diagram of the authentication device provided by the present application. The schematic diagram of the authentication device can be used to execute the method of the foregoing embodiment. Therefore, the beneficial effects it can achieve can refer to the beneficial effects in the corresponding method provided above, which will not be elaborated here.
[0318] Refer to Figure 6 , Figure 6 This is an authentication device provided by the present application. Exemplarily, the authentication device 600 includes:
[0319] An input module 601, configured to input a compressed video bitstream; the compressed video bitstream includes authentication data and a safety parameter set, the authentication data includes signature data, the signature data is obtained by signing the digest data, the digest data is the digest of the display image or the knowledge image corresponding to the safety parameter set, and the safety parameter set includes a knowledge image identifier, and the knowledge image identifier is used to indicate whether the safety parameter set acts on the knowledge image or the display image.
[0320] A digest calculation module 602, configured to calculate the digest data of the display image or the knowledge image corresponding to the safety parameter set.
[0321] An authentication module 603, configured to authenticate the display image or the knowledge image according to the calculated digest data and the authentication data.
[0322] Exemplarily, when the knowledge image identifier takes a first value, it indicates that the safety parameter set acts on the knowledge image; when the knowledge image identifier takes a second value, it indicates that the safety parameter set acts on the display image.
[0323] Exemplarily, the authentication data is located in or after the last access unit of the current authentication, before the next authentication data NAL unit, and before the next next random access point access unit.
[0324] Exemplarily, the knowledge image is a display knowledge image, and the interval between the authentication data and the access unit for displaying the knowledge image does not exceed the number of access units equal to the hash period value.
[0325] Exemplarily, the knowledge image is a non-display knowledge image, and the authentication data is located in the access unit where the last non-display knowledge image coding slice is located.
[0326] Exemplarily, the security parameter set further includes a security parameter set identifier, which is used to distinguish different security parameter sets acting on the same random access segment or knowledge image access unit.
[0327] Exemplarily, the security parameter set further includes a hash period, which is used to indicate the maximum number of access units in the bitstream segment.
[0328] Exemplarily, the authentication data includes digest data. The digest data is used to authenticate the display image or the knowledge image.
[0329] Exemplarily, for each frame of image, there is a corresponding sequence parameter set, and the coded image with the knowledge bitstream flag being 1 in the corresponding sequence set parameters, and the display image is the reference knowledge image, the instant decoding refresh image, the P image, the B image or the random access point I-frame image output by the decoder after decoding the reconstructed image.
[0330] It can be understood that Figure 5 or Figure 6 The device shown is only an example provided in this embodiment. According to different signature or authentication processes, the device may include more or fewer units, which are not limited in this application.
[0331] When the signature device or the authentication device is implemented by hardware, the hardware can be implemented by a processor or a chip system. The chip system includes one or more chips, and each chip includes a processor and a power supply circuit. The power supply circuit is used to supply power to the processor, and the processor is used to implement the method of any possible implementation manner in the above embodiment through logic circuits or by executing code instructions. The beneficial effects can be seen in the description of any aspect in the above embodiment, which will not be elaborated here.
[0332] It can be understood that the processor in the embodiments of this application can be a CPU, or other general-purpose processors, digital signal processors (DSPs), ASICs, FPGAs or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor can be a microprocessor or any conventional processor.
[0333] In addition, Figure 5 the signature device 500 shown or Figure 6The authentication device 600 shown can also be implemented by an electronic device, such as Figure 7 shown Figure 7 is a schematic structural diagram of the electronic device provided by this application. The electronic device 700 includes: a memory 710 and at least one processor 720. The processor 720 can implement the signature method or authentication method provided in the above embodiments. The memory 710 is used to store software instructions corresponding to the above signature method or authentication method. For example, the electronic device can be Figure 1 the camera 11 or the mobile phone 15 in
[0334] As an alternative implementation, in terms of hardware implementation, the electronic device 700 can refer to a chip or chip system encapsulating one or more processors 720. By way of example, when the electronic device 700 is used to implement the method steps in the above embodiments, the processor 720 included in the electronic device 700 executes the steps of the signature end 210 or the authentication end 220 in the above method and their possible sub-steps. In an alternative scenario, the electronic device 700 may further include a communication interface 730, and the communication interface 730 can be used to send and receive data. For example, the communication interface 730 is used to receive a bitstream, etc.; the communication interface 730 can be implemented through the interface circuit included in the electronic device 700. Therefore, in some examples, the communication interface 730 can also be referred to as the transceiver of the electronic device. In this embodiment, the communication interface 730 supports wired connection using the unified multimedia interconnect interface.
[0335] In the embodiments of this application, the communication interface 730, the processor 720, and the memory 710 can be connected through a bus 740. The bus 740 can be divided into an address bus, a data bus, a control bus, etc. The bus 740 can be a PCIe bus, or an extended industry standard architecture (EISA) bus, a unified bus (Ubus or UB), a compute express link (CXL), a cache coherent interconnect for accelerators (CCIX), or other types of buses, etc.
[0336] It should be noted that the electronic device 700 can also execute Figure 5 the functions of the signature device 500 shown or Figure 6 the functions of the authentication device 600 shown, which will not be elaborated here. Among them, all relevant contents of each step involved in the above method embodiments can be cited in the function descriptions of the corresponding functional modules, and will not be elaborated here.
[0337] An embodiment of the present application further provides a chip, including one or more interface circuits and one or more processors; the one or more processors receive or send data through the one or more interface circuits. When the one or more processors execute computer instructions, the above-related method steps are executed to implement the steps of the method in the above embodiment. Among them, the interface circuit is a transceiver / transceiver pin.
[0338] This embodiment further provides a non-transitory computer-readable storage medium, in which computer instructions are stored. When the computer instructions run on an electronic device, the electronic device is caused to execute the above-related method steps to implement the method in the above embodiment.
[0339] This embodiment further provides a computer program product, which includes computer instructions. When the computer instructions are executed by a computer or a processor, the computer is caused to execute the above-related steps to implement the method in the above embodiment.
[0340] In addition, an embodiment of the present application further provides a device, which may specifically be a chip, a component or a module. The device may include a processor and a memory connected thereto; among them, the memory is used to store computer execution instructions. When the device runs, the processor may execute the computer execution instructions stored in the memory, so that the chip executes the methods in the above method embodiments.
[0341] Among them, the electronic device, the non-transitory computer-readable storage medium, the computer program product or the chip provided in this embodiment are all used to execute the corresponding method provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method provided above, and will not be elaborated here.
[0342] Through the description of the above embodiments, those skilled in the art can understand that for the convenience and conciseness of description, only the above division of each functional module is used as an example. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.
[0343] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections between each other can be through some interfaces. The indirect couplings or communication connections of devices or units can be in electrical, mechanical or other forms.
[0344] The units described as separate components may or may not be physically separated. The components displayed as units may be one physical unit or multiple physical units, that is, they can be located in one place, or they can be distributed to multiple different places. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0345] In addition, in each embodiment of the present application, each functional unit can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0346] Any content in each embodiment of the present application, as well as any content in the same embodiment, can be freely combined. Any combination of the above content is within the scope of the present application.
[0347] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiments of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions for causing a device (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the methods in each embodiment of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read only memory (ROM), random access memory (RAM), magnetic disks or optical discs that can store program codes.
[0348] The steps of the method or algorithm described in connection with the disclosure of the embodiments of the present application may be implemented in hardware or by a processor executing software instructions. The software instructions may be composed of corresponding software modules, and the software modules may be stored in a random access memory (RAM), flash memory, read only memory (ROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), registers, hard disk, removable hard disk, compact disc read only memory (CD-ROM), or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium may also be a component of the processor. The processor and the storage medium may be located in an ASIC.
[0349] Those skilled in the art should be able to realize that in one or more of the above examples, the functions described in the embodiments of the present application can be implemented by hardware, software, firmware, or any combination thereof. When implemented in software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. The computer-readable medium includes non-transitory computer-readable storage media and communication media, where the communication media includes any medium that facilitates the transmission of a computer program from one place to another. The storage medium may be any available medium accessible by a general-purpose or special-purpose computer.
[0350] The embodiments of the present application have been described above in conjunction with the accompanying drawings. However, the present application is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not restrictive. Under the inspiration of the present application, those of ordinary skill in the art can also make many forms without departing from the purpose of the present application and the scope protected by the claims, and all of them fall within the protection scope of the present application.
Claims
1. A signature method, characterized in that, The method includes: Generating a set of security parameters; the set of security parameters includes a knowledge image identifier, and the knowledge image identifier is used to indicate that the set of security parameters acts on a knowledge image or a display image; Calculating digest data of the display image or the knowledge image corresponding to the set of security parameters; Signing the digest data to obtain signature data; Generating authentication data of the display image or the knowledge image corresponding to the set of security parameters; the authentication data includes the signature data; Adding the authentication data and the set of security parameters to a compressed video bitstream.
2. The method according to claim 1, characterized in that, When the knowledge image identifier takes a first value, it indicates that the set of security parameters acts on a knowledge image, and when the knowledge image identifier takes a second value, it indicates that the set of security parameters acts on a display image.
3. The method according to claim 1 or 2, characterized in that, The authentication data is located in or after the last access unit of the current authentication, before the next authentication data NAL unit, and before the next next random access point access unit.
4. The method according to any one of claims 1 to 3, characterized in that The knowledge image is a display knowledge image, and the interval between the access unit of the authentication data and the access unit of the display knowledge image does not exceed the number of access units equal to the value of the hash period.
5. The method according to any one of claims 1 to 3, characterized in that, The knowledge image is a non-display knowledge image, and the authentication data is located in the access unit where the last non-display knowledge image coded slice is located.
6. The method according to any one of claims 1-4, characterized in that, The set of security parameters further includes a hash period, and the hash period is used to indicate the maximum number of access units in a bitstream segment.
7. The method according to any one of claims 1-6, characterized in that, The set of security parameters further includes a security parameter set identifier, and the security parameter set identifier is used to distinguish different sets of security parameters acting on the same random access segment or knowledge image access unit.
8. The method according to any one of claims 1-7, characterized in that, The authentication data further includes the digest data, and the digest data is used to authenticate the display image or the knowledge image.
9. The method according to any one of claims 1-8, characterized in that, The knowledge image is an encoded image with one sequence parameter set corresponding to each frame image and the knowledge bitstream flag being 1 in the corresponding sequence set parameters, and the display image is a reference knowledge RL image, an instantly decoded refresh IDR image, a P image, a B image, or a random access point I-frame RAPI image output by the decoder after decoding the reconstructed image.
10. A compressed video bitstream, characterized in that, Including: Authentication data and a set of security parameters; Wherein, the set of security parameters includes a knowledge image identifier, the knowledge image identifier is used to indicate that the set of security parameters acts on a knowledge image or a display image, the authentication data includes the signature data corresponding to the digest data, and the digest data is obtained by performing a digest calculation on the display image or the knowledge image corresponding to the set of security parameters.
11. The compressed video bitstream according to claim 10, characterized in that, When the knowledge image identifier takes a first value, it indicates that the set of security parameters acts on a knowledge image, and when the knowledge image identifier takes a second value, it indicates that the set of security parameters acts on a display image.
12. The compressed video bitstream according to claim 10 or 11, characterized in that, The authentication data is located in or after the last access unit of the current authentication, before the next authentication data NAL unit, and before the next next random access point access unit.
13. The compressed video bitstream according to any one of claims 10 - 12, characterized in that, The knowledge image is a display knowledge image, and the interval between the access unit of the authentication data and the access unit of the display knowledge image does not exceed the number of access units equal to the value of the hash period.
14. The compressed video bitstream according to any one of claims 10-12, characterized in that, The knowledge image is a non-display knowledge image, and the authentication data is located in the access unit where the last non-display knowledge image coded slice is located.
15. The compressed video bitstream according to any one of claims 10-14, characterized in that, The security parameter set further includes a hash period, which is used to indicate the maximum number of access units in a bitstream segment.
16. The compressed video bitstream according to any one of claims 10-15, characterized in that, The security parameter set further includes a security parameter set identifier, which is used to distinguish different security parameter sets acting on the same random access segment or knowledge picture access unit.
17. The compressed video bitstream according to any one of claims 10-16, characterized in that, The authentication data further includes the digest data, which is used to authenticate the display picture or the knowledge picture.
18. The compressed video bitstream according to any one of claims 10-17, characterized in that, For the knowledge picture, each frame of picture corresponds to a sequence parameter set, and the coded picture with the knowledge bitstream flag being 1 in the corresponding sequence set parameters; for the display picture, it is an RL picture, an IDR picture, a P picture, a B picture or a RAPI picture output by the decoder after decoding the reconstructed picture.
19. A certification method, characterized in that, The method includes: Inputting a compressed video bitstream; the compressed video bitstream includes authentication data and a security parameter set, the authentication data includes signature data, the signature data is obtained by signing the digest data, the digest data is the digest of the display picture or the knowledge picture corresponding to the security parameter set, and the security parameter set includes a knowledge picture identifier, which is used to indicate whether the security parameter set acts on a knowledge picture or a display picture; Calculating the digest data of the display picture or the knowledge picture corresponding to the security parameter set; Authenticating the display picture or the knowledge picture according to the calculated digest data and the authentication data.
20. The method according to claim 19, characterized in that, When the knowledge picture identifier takes a first value, it indicates that the security parameter set acts on a knowledge picture; when the knowledge picture identifier takes a second value, it indicates that the security parameter set acts on a display picture.
21. The method according to claim 19 or 20, characterized in that, The authentication data is located in or after the last access unit of the current authentication, before the next authentication data NAL unit, and before the next access unit of the next random access point.
22. The method according to any one of claims 19 - 21, characterized in that For the knowledge picture being a display knowledge picture, the interval between the access unit of the authentication data and the display knowledge picture does not exceed the number of access units equal to the value of the hash period.
23. The method according to any one of claims 19-22, characterized in that, For the knowledge picture being a non-display knowledge picture, the authentication data is located in the access unit where the last non-display knowledge picture coded slice is located.
24. The method according to any one of claims 19 - 23, characterized in that, The security parameter set further includes a hash period, which is used to indicate the maximum number of access units in a bitstream segment.
25. The method according to any one of claims 19-24, characterized in that, The authentication data further includes the digest data, which is used to authenticate the display picture or the knowledge picture.
26. The method according to any one of claims 19-25, characterized in that, For the knowledge picture, each frame of picture corresponds to a sequence parameter set, and the coded picture with the knowledge bitstream flag being 1 in the corresponding sequence set parameters; for the display picture, it is an RL picture, an IDR picture, a P picture, a B picture or a RAPI picture output by the decoder after decoding the reconstructed picture.
27. An electronic device, characterized in that, Including: A memory and a processor, the memory is coupled to the processor; The memory stores program instructions, and when the program instructions are executed by the processor, the electronic device is enabled to execute the signature method according to any one of claims 1-9, or execute the authentication method according to any one of claims 19-26.
28. A non-transitory computer-readable storage medium, characterized in that, The non-transitory computer-readable storage medium stores a computer program, which, when running on a computer or a processor, causes the computer or the processor to execute the signature method according to any one of claims 1-9, or to execute the authentication method according to any one of claims 19-26.
29. A computer program product, characterized in that, The computer program product includes computer instructions, which, when executed by a computer or a processor, cause the steps of the method according to any one of claims 1-9 to be executed, or cause the steps of the method according to any one of claims 19-26 to be executed.
30. A non-transitory computer-readable storage medium, characterized in that, The non-transitory computer-readable storage medium stores a compressed video bitstream according to any one of claims 10-18.