Encryption method, decryption method and device
By independently generating the security parameter sets of knowledge images and displayed images, the problem of the complexity of the encryption and decryption of audio and video content in the prior art is solved, and independent encryption and decryption of knowledge images and displayed images is realized, the complexity of the security parameter set is reduced, and the encryption and decryption efficiency is improved.
Patent Information
- Application Number
- CN202410166342.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-01-24
- Filing Date
- 2024-02-05
- Publication Date
- 2025-07-25
AI Technical Summary
In the prior art, the encryption and decryption method of audio and video content has the problem of security parameter set complexity, especially under the constraint that knowledge images and display images need to use the same security parameter set, resulting in an increase in the encryption and decryption complexity.
The knowledge image and display image are encrypted and decrypted separately by using independent security parameter sets. By generating knowledge image identification and security parameter set identification, it is ensured that the knowledge image and the data units of the displayed image use different security parameter sets, reducing the complexity of the security parameter set.
The independent encryption and decryption of knowledge images and display images is realized, which reduces the complexity of the security parameter set, solves the contradiction between the use of the same security parameter set after the knowledge image is edited and the random access fragment is randomly accessed, and improves the efficiency and flexibility of encryption and decryption.
Smart Images

Figure CN120378652A_ABST
Abstract
Description
[0001] This application claims the priority of a Chinese patent application with the application number 202410107250.9 and the application title "Encryption Method, Decryption Method and Device", which was filed with the National Intellectual Property Administration on January 24, 2024. The entire content of this Chinese patent application is incorporated herein by reference in its entirety. Technical Field
[0002] Embodiments of this application relate to the field of media, and in particular, to an encryption method, a decryption method, and a device. Background Art
[0003] In many audio and video encoding and decoding scenarios (such as monitoring, live streaming, video-on-demand, etc.), there are certain requirements for the authenticity and integrity of audio and video content. Therefore, in order to ensure the security of audio and video content during transmission and prevent the audio and video content from being tampered with during transmission, it is necessary to encrypt the audio and video content.
[0004] However, the current technologies for encrypting and decrypting audio and video content have some defects. For example, in the current standard, when uniformly encrypting the output picture and the library picture, it is necessary to ensure that the library picture and the random access segment (RAS) where the library picture is located adopt the same security parameter set constraint, which increases the complexity of the security parameter set. Summary of the Invention
[0005] In view of this, this application provides an encryption method, a decryption method, and a device, which can independently encrypt and decrypt the library picture and the output picture respectively, reducing the complexity of the security parameter set.
[0006] In a first aspect, embodiments of this application provide an encryption method, which includes: First, generate a security parameter set. The security parameter set includes a library picture identifier and a security parameter set identifier. The library picture identifier is used to indicate whether the security parameter set acts on the output picture or the library picture, and the security parameter set identifier is used to distinguish different security parameter sets acting on the same random access segment or library picture access unit. Next, use the encryption method specified by the security parameter set to encrypt the network abstraction layer (NAL) unit to be encrypted corresponding to the security parameter set. Then, obtain the encrypted NAL unit. The encrypted NAL unit includes a NAL unit header, and the NAL unit header includes an encryption flag. The encryption flag is the security parameter set identifier, which is used to indicate that the encrypted NAL unit is encrypted by the encryption method specified in the security parameter set corresponding to the security parameter set identifier. Finally, output the compressed video bitstream. The compressed video bitstream includes the encrypted NAL unit and the security parameter set.
[0007] In the above encryption method provided by the present application, during the encryption of the compressed video bitstream, the data units of the knowledge image and the display image are encrypted separately, and the security parameter sets for the knowledge image and the display image are generated independently. The security parameter set for the knowledge image and the security parameter set for the display image are independent of each other. In this way, the compressed video bitstream carries the security parameter set for the knowledge image, enabling the decryption end to decrypt the encrypted data units of the knowledge image separately according to the security parameter set of the knowledge image. Compared with unified encryption and decryption for the display image and the knowledge image, the data units of the display image and the data units of the knowledge image use different independent security parameter sets respectively, without the need to ensure the constraint that the knowledge image and the random access segment where the knowledge image is located adopt the same security parameter set, reducing the complexity of the security parameter set. At the same time, during the editing process of the knowledge image, if it is required that the knowledge image and the random access segment where it is located adopt the same security parameter set, and the random access segment where the edited knowledge image is located may use different security parameter sets, the above encryption method provided by the present application solves the contradiction that the security parameter set of the edited knowledge image cannot meet the constraint that the knowledge image and the random access segment where it is located adopt the same security parameter set by encrypting and decrypting the data units of the knowledge image separately, reducing the complexity of the security parameter set.
[0008] In a possible implementation manner, when the knowledge image identifier takes a first value, it indicates that the security parameter set acts on the knowledge image, and when the knowledge image identifier takes a second value, it indicates that the security parameter set acts on the display image. In this way, for the data units of the knowledge image and the data units of the display image, the encryption end can identify whether one or more security parameter sets in the compressed video bitstream act on the data units of the knowledge image or the data units of the display image through the knowledge image identifier, so as to realize independent encryption and decryption of the data units of the knowledge image using independent security parameter sets.
[0009] In a possible implementation manner, the security parameter set includes an encryption basic unit, and the encryption basic unit is used to indicate that encryption is performed in units of data units including Network Abstract Layer (NAL) units, Access Units (AU), or Layer Units (LU).
[0010] In a possible implementation manner, after the security parameter set is generated, the security parameter set is packed into a security parameter set NAL unit; the security parameter set NAL unit is added before the picture sequence parameter set NAL unit.
[0011] In a possible implementation, the steps of obtaining the encrypted NAL unit may include: restoring the encrypted data to the encrypted raw byte sequence payload (RBSP) data; concatenating the NAL unit header and the encrypted RBSP data; setting the encryption flag of the NAL unit header to the value of the security parameter set identifier in the security parameter set corresponding to the encrypted NAL unit to obtain the encrypted NAL unit.
[0012] In a possible implementation, after restoring the encrypted data to the encrypted raw byte sequence payload RBSP data, an anti-counterfeiting start code is added to the encrypted RBSP data.
[0013] In a possible implementation, the knowledge image is an encoded image in which each frame image corresponds to a sequence parameter set and the knowledge bitstream flag in the corresponding sequence set parameter is 1, and the display image is a reference library (RL) image, an instantaneous decoding refresh (IDR) image, a P image, a B image, or a random access point I frame (RAPI) image output by the decoder after decoding the reconstructed image.
[0014] In a second aspect, an embodiment of the present application provides a decryption method, which includes: first, inputting a compressed video bitstream; then, obtaining a security parameter set in the compressed video bitstream; the security parameter set includes a knowledge image identifier and a security parameter set identifier, the knowledge image identifier is used to indicate whether the security parameter set acts on a display image or a knowledge image, and the security parameter set identifier is used to distinguish different security parameter sets acting on the same random access segment or knowledge image access unit; then, using the encryption method specified by the security parameter set, decrypting the encrypted NAL unit corresponding to the security parameter set; the encryption flag of the encrypted NAL unit is the security parameter set identifier; finally, obtaining the decrypted RBSP data.
[0015] In a possible implementation, when the knowledge image identifier takes a first value, it indicates that the security parameter set acts on the knowledge image, and when the knowledge image identifier takes a second value, it indicates that the security parameter set acts on the display image.
[0016] In a possible implementation, the security parameter set includes an encryption basic unit, and the encryption basic unit is used to indicate that encryption is performed in units of data units including NAL units, AUs, or layer units LUs.
[0017] In a possible implementation, after obtaining the decrypted RBSP data, an anti-counterfeiting start code is added to the decrypted RBSP data.
[0018] In a possible implementation, after obtaining the decrypted RBSP data, the NAL unit header and the decrypted RBSP data are spliced to obtain the decrypted NAL unit.
[0019] In a possible implementation, the knowledge image is an encoded image in which each frame of image corresponds to a sequence parameter set and the knowledge bitstream flag in the corresponding sequence set parameter is 1. The display image is a reference knowledge image, an instantly decoded refresh image, a P image, a B image, or a random access point I-frame image that the decoder outputs the reconstructed image after decoding.
[0020] In a third aspect, the present application provides a compressed video bitstream, which includes an encrypted data unit and a security parameter set; wherein, the security parameter set includes a knowledge image identifier and a security parameter set identifier. The knowledge image identifier is used to indicate whether the security parameter set acts on the display image or the knowledge image, and the security parameter set identifier is used to distinguish different security parameter sets acting on the same random access segment or knowledge image access unit. The encrypted NAL unit includes a NAL unit header, and the NAL unit header includes an encryption flag, and the encryption flag is the security parameter set identifier.
[0021] In a possible implementation, when the knowledge image identifier takes a first value, it indicates that the security parameter set acts on the knowledge image, and when the knowledge image identifier takes a second value, it indicates that the security parameter set acts on the display image.
[0022] In a possible implementation, the security parameter set includes an encryption basic unit, and the encryption basic unit is used to indicate that encryption is performed in units of data units including NAL units, AUs, or layer units LUs.
[0023] In a possible implementation, the knowledge image is an encoded image in which each frame of image corresponds to a sequence parameter set and the knowledge bitstream flag in the corresponding sequence set parameter is 1. The display image is a reference knowledge image, an instantly decoded refresh image, a P image, a B image, or a random access point I-frame image that the decoder outputs the reconstructed image after decoding.
[0024] Fourth aspect, there is provided an encryption device. The encryption device includes modules for performing the method according to any one of the implementations in the first aspect. For example, the encryption device includes a generation module, an encryption module, an acquisition module, and an output module. The generation module is configured to generate a set of security parameters; the set of security parameters includes a knowledge image identifier and a security parameter set identifier, the knowledge image identifier is used to indicate that the set of security parameters acts on a display image or a knowledge image, and the security parameter set identifier is used to distinguish different sets of security parameters acting on the same random access segment or knowledge image access unit; the encryption module is configured to encrypt the network abstraction layer (NAL) unit to be encrypted corresponding to the set of security parameters by using the encryption method specified by the set of security parameters; the acquisition module is configured to acquire the encrypted NAL unit; the encrypted NAL unit includes a NAL unit header, and the NAL unit header includes an encryption flag, and the encryption flag is the security parameter set identifier; the output module is configured to output a compressed video bitstream; the compressed video bitstream includes the encrypted NAL unit and the set of security parameters.
[0025] Fifth aspect, there is provided a decryption device. The decryption device includes modules for performing the method according to any one of the implementations in the second aspect. For example, the decryption device includes an input module, an acquisition module, and a decryption module. The input module is configured to input a compressed video bitstream; the acquisition module is configured to acquire the set of security parameters in the compressed video bitstream; the set of security parameters includes a knowledge image identifier and a security parameter set identifier, the knowledge image identifier is used to indicate that the set of security parameters acts on a display image or a knowledge image, and the security parameter set identifier is used to distinguish different sets of security parameters acting on the same random access segment or knowledge image access unit; the decryption module is configured to decrypt the encrypted NAL unit corresponding to the set of security parameters by using the encryption method specified by the set of security parameters; the encryption flag of the encrypted NAL unit is the security parameter set identifier; the decryption module is further configured to acquire the decrypted RBSP data.
[0026] Sixth aspect, there is provided an encoding device. The encoding device includes: at least one processor, which when executing program code or instructions, implements the method described in the first aspect or any of its possible implementations.
[0027] Optionally, the encoding device may further include at least one memory, and the at least one memory is used to store the program code or instructions.
[0028] Seventh aspect, there is provided a decoding device. The decoding device includes: at least one processor, which when executing program code or instructions, implements the method described in the second aspect or any of its possible implementations.
[0029] Optionally, the decoding device may further include at least one memory, and the at least one memory is used to store the program code or instructions.
[0030] In an eighth aspect, an embodiment of the present application further provides a chip, including: an input interface, an output interface, and at least one processor. Optionally, the chip further includes a memory. The at least one processor is configured to execute the code in the memory, and when the at least one processor executes the code, the chip implements the method described in any possible implementation manner of the above first aspect or second aspect.
[0031] Optionally, the above chip may also be an integrated circuit.
[0032] In a ninth aspect, an embodiment of the present application further provides a non-transitory computer-readable storage medium for storing a computer program, where the computer program includes a method for implementing the method described in any possible implementation manner of the above first aspect or second aspect.
[0033] In a tenth aspect, an embodiment of the present application further provides a computer program product including instructions, which when run on a computer, causes the computer to implement the method described in any possible implementation manner of the above first aspect or second aspect.
[0034] The encoding and decoding device, non-transitory computer-readable storage medium, computer program product, and chip provided in this embodiment are all used to execute the encryption and decryption method provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the encryption and decryption method provided above, and will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] Figure 1 It is a schematic diagram of an exemplary application scenario;
[0036] Figure 2 It is a schematic diagram of an exemplary encryption and decryption system 200;
[0037] Figure 3 It is a schematic diagram of an exemplary encryption process 300;
[0038] Figure 4 It is a schematic diagram of an exemplary decryption process 400;
[0039] Figure 5 It is a schematic diagram of an exemplary encryption device;
[0040] Figure 6 It is a schematic diagram of an exemplary decryption device;
[0041] Figure 7 It is a schematic diagram of the structure of an exemplary device. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0042] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts belong to the scope of protection of the present application.
[0043] The term "and / or" in this article is merely a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone.
[0044] The terms "first", "second", etc. in the description and claims of the embodiments of the present application are used to distinguish different objects, rather than to describe a specific order of the objects. For example, the first target object and the second target object are used to distinguish different target objects, rather than to describe the specific order of the target objects.
[0045] In the embodiments of the present application, words such as "exemplary" or "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, the use of words such as "exemplary" or "for example" is intended to present relevant concepts in a specific manner.
[0046] In the description of the embodiments of the present application, unless otherwise specified, the meaning of "a plurality of" refers to two or more. For example, a plurality of processing units refers to two or more processing units; a plurality of systems refers to two or more systems.
[0047] Exemplarily, the method for encrypting and decrypting the bitstream involved in the present application can be applied to encrypting and decrypting any one of the audio compression bitstream (or referred to as the audio compression bitstream) or the video compression bitstream (or referred to as the video compression bitstream). The present application does not limit this. The present application takes encrypting and decrypting the video compression bitstream as an example for description. Next, for the sake of simplicity of subsequent description, the technical terms that the present application may involve will be described first.
[0048] Bitstream
[0049] The binary data stream formed by encoding image / audio frames. Both the NAL unit stream and the byte stream can be referred to as bitstreams.
[0050] The NAL unit stream format consists of a series of syntax structures called NAL units, sorted in decoding order. The decoding order and content of the NAL units in the NAL unit stream are constrained.
[0051] A byte stream can be constructed from an NAL unit stream by arranging the NAL units in decoding order and adding a start code prefix and a number of zero-valued bytes to each NAL unit to form a bitstream. The NAL unit stream format can be extracted from the bitstream format by searching for the unique start code prefix in the bitstream.
[0052] data unit
[0053] The basic syntax structure of an encoded bitstream can be an NAL unit, an access unit, or a layer unit.
[0054] layer unit
[0055] A set of NAL units with the same layer_id value that are related to each other according to specified rules and are consecutive in decoding order.
[0056] NAL unit
[0057] A syntax structure that contains a type indication of the subsequent data and the number of bytes contained (located in the NAL header), and the data appears in the form of a Raw Byte Sequence Payload (RBSP), which may also include scattered anti-counterfeiting bytes when necessary.
[0058] access unit
[0059] A group of NAL units that are related to each other according to specified rules and are consecutive in decoding order.
[0060] It should be noted that, from another dimension, the data unit can also include a coded picture.
[0061] coded picture
[0062] The encoded representation of a frame of an image.
[0063] encoded video sequence
[0064] An encoded video sequence, which is the highest-level syntax structure of a bitstream, contains one or more consecutive access units. An encoded video sequence starts with an access unit of an IDR image (instantaneous decoding refresh picture), an access unit of a RAPI image (random access point I picture), an access unit of a leading library picture of an RL picture, or an access unit of an output library picture. The stream-ending NAL unit or the sequence-ending NAL unit of an encoded video sequence indicates the end of an encoded video sequence. Each encoded video sequence contains at most one IDR image, RAPI image, leading library picture of an RL picture, or output library picture. Access units are arranged in bitstream order in the bitstream, and the bitstream order should be the same as the decoding order. The decoding order may not be the same as the display order.
[0065] Sequence Parameter Set
[0066] A sequence parameter set contains configuration parameters required for encryption and authentication operations on the compressed video bitstream. At the start of the decoding process, each sequence parameter set takes effect as soon as it is received by the decoder and causes any previously effective sequence parameter set (if any) to become ineffective. A sequence parameter set NAL unit should be present before the access unit of all random access point (RAP) images. The sequence parameter set NAL unit should be within the same access unit as the slice parameter set NAL unit, and the sequence parameter set NAL unit should be before the slice parameter set NAL unit. Therefore, the scope of a sequence parameter set is the random access segment in the compressed video bitstream in which it is located, i.e., all AUs in the bitstream from the AU in which the sequence parameter set is located up to but not including the next RAP image.
[0067] Library picture
[0068] A reference image of a non-current bitstream used when decoding the current bitstream. Each picture corresponds to a sequence parameter set, and is an encoded picture for which the library bitstream flag in the corresponding sequence set parameter is 1. The NAL unit type of the coded slice of a library picture is 12, 17, or 18, and the library picture is associated with a coded slice of privacy.
[0069] Output library picture
[0070] Each frame of image corresponds to a sequence parameter set, and is an encoded image with the knowledge bitstream flag being 1 and the knowledge image mode index being 1 in the corresponding sequence set parameters. The NAL unit type of the coded slice for displaying the knowledge image is 17. The displayed knowledge image is a random access point image, and the displayed knowledge image serving as the leading library picture of an RL picture is not a random access point image.
[0071] Non-output library picture
[0072] Each frame of image corresponds to a sequence parameter set, and is an encoded image with the knowledge bitstream flag being 1 and the knowledge image mode index being 0 or 2 in the corresponding sequence set parameters. The NAL unit type of the coded slice for the non-output library picture is 12 or 18.
[0073] Leading library picture of an RL picture
[0074] A non-output library picture whose bitstream order is before an associated RL picture or a displayed knowledge picture newly appearing before an RL picture through bitstream editing, and there is no access unit of other images between the access unit where the first knowledge image coded slice of this knowledge picture is located and the access unit of the associated RL picture. The leading library picture of an RL picture is not a random access point image.
[0075] Non-leading library picture of an RL picture
[0076] A non-output library picture whose bitstream order is before an associated RL picture, and there is at least one access unit of other images between the access unit where the first knowledge image coded slice of this non-output library picture is located and the access unit of the associated RL picture. The non-leading library picture of an RL picture is not a random access point image.
[0077] Output picture
[0078] An RL picture, IDR picture, P picture, B picture or RAPI picture whose reconstructed image is output after being decoded by the decoder. It should be noted that both the displayed knowledge picture and the non-output library picture do not belong to the output picture.
[0079] An image is a frame of an encoded video sequence, and its encoded data is contained in one or more access units. Its encoded image consists of an image header NAL unit, supplementary enhancement information (if any), and all the encoded slice NAL units of the image. Specifically, the encoded image of an IDR image includes an image header NAL unit, zero or more supplementary extension description NAL units of the IDR image, and all the IDR image encoded slice NALU units of the IDR image. The encoded image of a RAPI image includes an image header NAL unit, zero or more supplementary extension description NAL units of the RAPI image, and all the RAPI image encoded slice NAL units of the RAPI image. The encoded images of P images and B images include an image header NAL unit, zero or more supplementary extension description NAL units of the P image or B image, and all the NRAP image encoded slice NAL units of the P image or B image. The encoded image of an RL image includes an image header NAL unit, zero or more supplementary extension description NAL units of the RL image, and all the RL image encoded slice NAL units of the RL image. The encoded image of a knowledge image consists of an image header NAL unit, one or more knowledge image encoded slice NAL units, and one or more privacy image encoded slice NAL units. The RL pre-knowledge image, the privacy image encoded slice NAL units, and all the encoded slice NAL units in the encoded image of the displayed knowledge image are consecutive. Its access unit contains all the NAL units of the encoded image. The encoded slices of non-RL pre-knowledge images can be interleaved with the access units of the displayed images as access units.
[0080] The first encoded slice NAL unit of an image shall immediately follow the image header NAL unit of the image. For the encoded image of an IDR image, a RAPI image, an RL image, or a knowledge image, the image header NAL shall immediately follow an image parameter set NAL unit, and the image parameter set NAL shall immediately follow a sequence parameter set NAL unit.
[0081] In particular, one or more bitstreams of displayed images can be interleaved between multiple knowledge image bitstream slices of non-RL pre-knowledge images, but the interleaved bitstreams of displayed images shall not be access units of RL images, IDR images, or RAPI images. All the knowledge image bitstream slices of an RL pre-knowledge image or a displayed knowledge image shall be consecutive. After each knowledge image bitstream slice, it can be interleaved with privacy image encoded slice NAL units (if any), but not with the bitstreams of displayed images.
[0082] The bitstreams of all the slices of a knowledge image shall be located before the bitstream of the first RL image that references the knowledge image. The knowledge image bitstream slices of different knowledge images cannot be interleaved. The knowledge image referenced by an RL image is the knowledge image represented by the access unit of the first knowledge image found in reverse order in the decoding order starting from the RL access unit in the bitstream.
[0083] Figure 1 Schematic diagram of exemplary application scenarios Figure 1 Monitoring scenarios, live broadcast scenarios, and on-demand scenarios are shown
[0084] Referring to Figure 1 , exemplarily, in a monitoring scenario, camera 11 can encrypt the monitoring video stream to obtain the encrypted monitoring video stream 101. Then, the encrypted monitoring video stream 101 is sent to laptop 13 via network 12. After that, laptop 13 can decrypt the encrypted monitoring video stream 101 to obtain the decryption result 105 and display it, as well as play the monitoring video 104
[0085] Referring to Figure 1 , exemplarily, in a live broadcast scenario, mobile phone 14 can encrypt the live broadcast video stream to obtain the encrypted live broadcast video stream 102. Then, the encrypted live broadcast video stream 102 is sent to mobile phone 15 via network 12. After that, mobile phone 15 can decrypt the encrypted live broadcast video stream 102 to obtain the decryption result 107 and display it, as well as play the live broadcast video 106
[0086] Referring to Figure 1 , exemplarily, in an on-demand scenario, personal computer 16 can encrypt the on-demand video stream to obtain the encrypted on-demand video stream 103. Then, the encrypted on-demand video stream 103 is sent to mobile phone 17 via network 12. After that, mobile phone 17 can decrypt the encrypted on-demand video stream 103 to obtain the decryption result 109 and display it, as well as play the on-demand video 108
[0087] It should be understood that the present application can also be used in other scenarios of audio and video encoding and decoding, such as digital content trust scenarios, etc., and the present application does not limit this
[0088] Figure 2 Schematic diagram of the decryption and encryption system 200 shown exemplarily. In Figure 2 the above Figure 1 the decryption and encryption processes in are described
[0089] Referring to Figure 2 , exemplarily, the decryption and encryption system 200 can include an encryption end 210 and a decryption end 220
[0090] For example, the encryption end 210 can be front-end devices such as camera 11, mobile phone 14, and personal computer 16 in the above Figure 1 , and the decryption end 220 can be back-end devices such as laptop 13, mobile phone 15, and mobile phone 17 in the above Figure 1
[0091] It should be understood that the same terminal device can serve as either the encryption end 210 or the decryption end 220, and this application places no restrictions on this.
[0092] Continuing to refer to Figure 2 , exemplarily, after the encryption end 210 obtains the video data 201, it can perform video encoding 21 on the video data 201 to obtain a bitstream 202; and perform video encryption 22 on the bitstream 202 to obtain an encrypted bitstream 203.
[0093] For example, the video data 201 can be the surveillance video captured by the camera 11 in the above Figure 1 , the live video recorded by the mobile phone 14, or the on-demand video produced by the personal computer 16.
[0094] For example, the encrypted bitstream 203 can be the encrypted surveillance video bitstream 101, the encrypted live video bitstream 102, or the encrypted on-demand video bitstream 103 in the above Figure 1 .
[0095] It should be noted that the two operations of video encoding 21 and video encryption 22 can be executed in parallel.
[0096] It should be noted that in one possible way, the encryption end 210 can include an encoder, and the encoder performs video encoding 21 and video encryption 22. In one possible way, the encryption end 210 can include an encoder and an encryption module, where the encoder performs video encoding 21 and the encryption module performs video encryption 22. In one possible way, the encryption end 210 can include an encryption module, and the encryption module performs video encoding 21 and video encryption 22.
[0097] After that, the encryption end 210 can send the encrypted bitstream 203 to the decryption end 220.
[0098] Continuing to refer to Figure 2 , exemplarily, after the decryption end 220 receives the encrypted bitstream 203, it can perform video decryption 23 on the encrypted bitstream 203 to obtain a decryption result 205; and can perform video decoding 24 on the bitstream 202 in the encrypted bitstream 203 to obtain the decoded video data 204.
[0099] For example, the decoded video data 204 can be the surveillance video 104, the live video 106, or the on-demand video 108 in the above Figure 1 .
[0100] For example, the decryption result 205 can be the decryption result 105, the decryption result 107, or the decryption result 109 in the above image 1.
[0101] It should be noted that the two operations of video decryption 23 and video decoding 24 can be executed in parallel.
[0102] It should be noted that in one possible way, the decryption end 220 may include a decoder, and the decoder executes video decoding 24 and video decryption 23. In one possible way, the decryption end 220 may include a decoder and a decryption module, the decoder executes video decoding 24 and the decryption module executes video decryption 23. In one possible way, the decryption end 220 may include a decryption module, and the decryption module executes video decoding 24 and video decryption 23.
[0103] It should be noted that when the encryption end 210 performs lossless encoding, the video data is the same as the decoded video data; when the encryption end 210 performs lossy encoding, there are differences between the video data and the decoded video data.
[0104] It should be noted that the encoder, decoder, encryption module, and decryption module can be implemented by software or by hardware, and this application does not limit this.
[0105] Figure 3 It is a schematic diagram of the exemplary encryption process 300. Among them, the process 300 can be implemented by the encryption end 210.
[0106] S301, generate a security parameter set;
[0107] Generate a security parameter set for the data unit of the image. The security parameter set includes a knowledge image identifier and a security parameter set identifier. The knowledge image identifier is used to indicate whether the security parameter set acts on the display image or the knowledge image, and all NAL units encrypted with the same security parameter set should belong to the scope of action of this security parameter set. The security parameter set identifier is used to distinguish different security parameter sets acting on the same random access segment or knowledge image access unit.
[0108] Among them, the value of the knowledge image identifier can be a binary variable. For example, when the knowledge image identifier is the first value, it indicates that the security parameter set acts on the knowledge image, and when the knowledge image identifier is the second value, it indicates that the security parameter set acts on the display image. Among them, the first value can be 1, the second value can be 0, or the first value can be 0, and the second value can be 1. Taking the first value of the knowledge image identifier being 1 to indicate that the security parameter set acts on the knowledge image and the second value being 0 to indicate that the security parameter set acts on the display image as an example, the knowledge image identifier of the security parameter set corresponding to the knowledge image is 1, and the knowledge image identifier of the security parameter set corresponding to the display image is 0.
[0109] As a possible implementation, a data unit of an image is a data unit taken from a compressed video bitstream output by an encoder. It is determined whether the data unit needs to be encrypted according to the configuration. If so, an encryption identifier is added to the data unit.
[0110] A data unit is a basic syntax structure of an encoded bitstream (such as a compressed video bitstream), which can be a NAL unit, an access unit, or a layer unit. A group of data units can also be referred to as a bitstream segment in the bitstream.
[0111] Refer to Figure 3 , for example, the n data units that need to be encrypted in the compressed video bitstream are respectively: data unit 1, data unit 2,..., data unit n. These n data units that need to be encrypted can be referred to as a group of data units. A group of data units involved subsequently all refer to the data units that need to be encrypted.
[0112] It should be noted that the present application does not group the data units. Instead, for the convenience of description, the term "a group of data units" is used.
[0113] For example, data unit 1 is a data unit of a knowledge image, and data units 2,..., data unit n are data units of a display image.
[0114] The encryption end 210 generates a security parameter set 1 for data units 2,..., data unit n, and simultaneously generates an independent security parameter set 2 for data unit 1. In this way, the security parameter set 1 acts on the data units of the display image, and its scope of action is also the display image; the security parameter set 2 acts on the data units of the knowledge image, and its scope of action is also the knowledge image.
[0115] As a possible implementation, a NAL unit is taken from the compressed video bitstream output by the encoder. The NAL unit includes a NAL unit header and RBSP data. It is determined whether the NAL unit needs to be encrypted according to the configuration. If so, the NAL unit encryption flag (such as encryption_idc) in the NAL unit header is set to 1, and the subsequent operation of generating the security parameter set is performed.
[0116] As a possible implementation, the syntax definition of the NAL unit is shown in Table 1.
[0117] Table 1
[0118]
[0119] Among them, NumBytesInNALunit indicates the length of the NAL unit, with the unit being bytes. A NAL unit consists of a unit header part and a unit payload part. The unit payload part contains an RBSP syntax structure and possibly an authentication data payload, and may also contain some emulation_prevention_three_byte. To derive NumBytesInNALunit, it is necessary to demarcate the boundaries of the NAL unit.
[0120] The forbidden_zero_bit is a zero prohibition code, a binary variable. It should be equal to '0'.
[0121] The nal_unit_type is a NAL unit type flag, a 5-bit unsigned integer. It represents the type of the RBSP data structure in the NAL unit. On the premise of not affecting the decoding process of NAL units where nal_unit_type is not equal to 11 and not affecting the consistency of this standard, NAL units where nal_unit_type is equal to 11 can be discarded by the decoder. When the nal_unit_type value of a coded slice NAL unit is equal to 1, 2, 4, 12, or 17, the nal_unit_type values of all other coded slice NAL units encoding the same image should be the same. If UserPermission is equal to 0, NAL units where nal_unit_type is equal to 19 can be discarded by the decoder. When the nal_unit_type value of a coded slice NAL unit is equal to 19, the RBSP data contains the data of several coding units in the coded slice of the image.
[0122] When the number of coded slices of a knowledge image is equal to 1, the nal_unit_type of the NAL unit of this knowledge image coded slice should be 12 or 17. When the number of coded slices of a non-display knowledge image is greater than 1, the nal_unit_type of the first and the last NAL units of the knowledge image coded slices in decoding order should be 18, and the nal_unit_type of the remaining NAL units of the knowledge image coded slices should be 12.
[0123] For the specific demarcation of the NAL unit type, see Table 2.
[0124] Table 2
[0125]
[0126]
[0127] The encryption_idc is an encryption flag, a 2-bit unsigned integer with a value range of 0 to 3. It indicates whether the NAL unit is encrypted. A value of '0' means the RBSP in this NAL unit is not encrypted, and a value other than '0' means the RBSP in this NAL unit is encrypted using the encryption method specified in the security parameter set with sec_para_set_id equal to encryption_idc. The last byte of the RBSP is not encrypted.
[0128] When the nal_unit_type of a NAL unit is 9, 10, 11, 15, or 16, the encryption_idc should be 0.
[0129] When the nal_unit_type of a NAL unit is 6 and it contains a payload with PayloadType equal to 25 or 26, the encryption_idc should be 0.
[0130] The authentication_idc is an authentication flag, a 2-bit unsigned integer with a value range of 0 to 3. If the nal_unit_type of this NAL unit is 10, the value of authentication_idc should be equal to the security parameter set ID sec_para_set_id corresponding to the authentication data contained in this NAL unit, indicating that the authentication data carried in this authentication data NAL unit is generated based on the security parameter set corresponding to the security parameter set ID sec_para_set_id; otherwise (the nal_unit_type of this NAL unit is not 10), it indicates whether the NAL unit is authenticated. At this time, a value of '0' means this NAL unit is not authenticated, and a value other than '0' means this NAL unit is authenticated using the authentication method specified in the security parameter set with sec_para_set_id equal to authentication_idc.
[0131] When the nal_unit_type of a NAL unit is 10, this NAL unit does not participate in signature authentication.
[0132] When the nal_unit_type of a NAL unit is 11, 15, or 16, the authentication_idc should be 0.
[0133] When the nal_unit_type of a NAL unit is 6 and it contains a payload with PayloadType equal to 25 or 26, the authentication_idc should be 0.
[0134] The authentication_data_id is the identifier of the authentication data, which is a 2-bit unsigned integer. The value range is 0 to 1, and it is the identifier of the authentication data for the signature authentication participated by this NAL unit, and should be consistent with the authentication_data_id in the authentication data RBSP for which it participates in the signature authentication. The authentication_data_id of the NAL units participating in the authentication corresponding to the same authentication data should be the same and consistent with the authentication_data_id in the authentication data. The authentication_data_id of a set of display picture coding slice NAL units participating in the common signature authentication should be different from that of the previous set of display picture coding slice NAL units with the same authentication_idc participating in the common signature authentication.
[0135] When the nal_unit_type of a NAL unit is 10, this authentication_data_id should be consistent with the authentication_data_id in the authentication data RBSP of this NAL unit.
[0136] The temporal_id is the temporal layer identifier, which is a 3-bit unsigned integer. It indicates the temporal layer identifier of the current picture. The value range of the temporal layer identifier is 0 to MAX_TEMPORAL_ID. A temporal layer identifier of 0 indicates the lowest layer. When the nal_unit_type of a NAL unit is 7, 8, 9, 10, 11, or 16, the temporal_id should be 0. The temporal_id of all picture header NAL units and all coding slice NAL units within an access unit should be the same. The temporal_id of an access unit is the temporal_id of the coding slice NAL units within this access unit. If an access unit contains NAL units with nal_unit_type of 7, 8, or 9, the temporal_id of this access unit should be 0.
[0137] When the nal_unit_type of a NAL unit is 3, 5, 6, or 15, the temporal_id of this NAL unit should be equal to the temporal_id of the access unit in which it is located.
[0138] The layer_id is a layer identification, a 2-bit unsigned integer, which indicates the layer identification of the current image. The value range of the layer identification is 0 to MAX_LAYER - 1. The layer_id of the picture header NAL unit and all coded slice NAL units of a coded picture should be the same. The value of LayerId is equal to the value of layer_id. The LayerId of a coded picture or layer unit is the LayerId of the coded slice NAL units within that coded picture or layer unit.
[0139] When the nal_unit_type of a NAL unit is 5, 7, 8, 9, 10 or 15, the LayerId shall be 0.
[0140] When the nal_unit_type of a NAL unit is 6 and the NAL unit includes supplementary enhancement payload with PayloadType being 19, 25, 26 or 127, the LayerId shall be 0.
[0141] The payload_byte[i] is the i-th byte of the payload, an 8-bit arbitrary variable, which represents the i-th byte of the payload of a NAL unit and is equal to rbsp_byte[i]. The payload of a NAL unit is defined as an ordered sequence of bytes, including an RBSP (or a byte sequence generated after encrypting the RBSP if encryption_idc equals 1).
[0142] The rbsp_byte[j] is the j-th byte of an RBSP. If encryption_idc equals 1, rbsp_byte[j] is the j-th byte of the byte sequence after encrypting the RBSP. The RBSP needs to go through a decryption process, which is not specified in this standard.
[0143] An RBSP is defined as an ordered sequence of bytes, containing a SODB, as described below:
[0144] a) If the SODB is empty (with a length of 0 bits), the RBSP is also empty;
[0145] b) Otherwise, the RBSP includes the following SODB:
[0146] 1) The first byte of the RBSP includes (with the most significant bit first) 8 bits of the SODB; the next byte of the RBSP shall include the next 8 bits of the SODB, and so on, until the remaining SODB is less than 8 bits;
[0147] 2) rbsp_trailing_bits() is used after the SODB: The leading (counting from the most significant bit) bits in the last RBSP byte include the remaining bits of the SODB (if any); the next bit is a single rbsp_stop_one_bit with a value of 1, and when rbsp_stop_one_bit is not the last bit of a byte-aligned byte, one or more rbsp_alignment_zero_bit should follow to form a byte alignment.
[0148] Syntax structures with these RBSP attributes are indicated in the syntax table with an "_rbsp" suffix. These structures are carried as the content of the rbsp_byte[j] data bytes in the NAL unit.
[0149] When the boundary of the RBSP is known, the decoder can parse the SODB from the RBSP by concatenating the RBSP bytes into a bit string and discarding the last (rightmost) bit equal to 1, rbsp_stop_one_bit, and any subsequent bits equal to 0. The data necessary for the decoding process is contained in the SODB part of the RBSP.
[0150] emulation_prevention_three_byte is an anti-counterfeiting code.
[0151] As a possible implementation, the knowledge image identifier can be encoded into the security parameter set according to the preset syntax in the syntax table shown in Table 3.
[0152] Table 3
[0153]
[0154]
[0155]
[0156] Among them, sec_is_library_flag is the knowledge image identifier, a binary variable. A value of '1' (the first value) indicates that this security parameter set applies to the knowledge image, and a value of '0' (the second value) indicates that this security parameter set applies to the display image.
[0157] sec_para_set_id is the security parameter set ID, a 2-bit unsigned integer. It is used to distinguish different security parameter sets acting on the same RAS or knowledge image access unit, and the value range is 1 to 3.
[0158] The encryption_enable_flag is an encryption enable flag, a binary variable. A value of '1' indicates support for encrypting the coded slice of the display image, or the sequence parameter set of the display image, or the picture parameter set of the display image, or the non-display knowledge image coded slice, or the display knowledge image coded slice, or the knowledge image sequence parameter set, or the knowledge image picture parameter set, or the extended data unit, that is, the RBSP in the NAL unit may be encrypted. A value of '0' indicates that encryption of the RBSP in the NAL unit is not supported.
[0159] The authentication_enable_flag is an authentication enable flag, a binary variable. A value of '1' indicates support for authenticating the current RAS or knowledge image. The NAL units that can participate in authentication include the coded slices of the display image or knowledge image in the current RAS, as well as the sequence parameter set, picture parameter set, security parameter set, extended data unit, and supplementary enhancement information transmitted in the access unit. When support for authenticating the above data content exists, the authentication data carried in the coded bitstream should be Base64 encoded. The authentication data is transmitted through the NAL unit with nal_unit_type equal to 10. A value of '0' indicates that the current security parameter set does not support authenticating the RAS or knowledge image, and there should be no NAL unit with nal_unit_type equal to 10 for the RAS or knowledge image generated using this security parameter set.
[0160] Knowledge images only support independent signature authentication, and display images support co-signature authentication. Multiple display image access units participating in co-signature authentication should be in the same RAS. The image types in multiple access units participating in co-signature can be display images. For the independent signature authentication of knowledge images, an independent security parameter set independent of the display image is used for independent signature authentication, and sec_is_library_flag is used to distinguish in the security parameter set.
[0161] If there are NAL units with authentication_idc greater than 0 and nal_unit_type equal to 1 - 3, 5 - 9, 12, 14, 17, 18, and 19 in an access unit, for the NAL units with the same authentication_idc value greater than 0 and the same layer_id value in each layer unit of the access unit, after arranging them in bitstream order, a digest calculation is performed to generate the digest data of the NumOfLayers layer units corresponding to the authentication_idc of the access unit. The digest calculation method is specified by hash_type.
[0162] For hash_period_in_doi_minus1 + 1 access units, calculate the digest of each layer unit in each access unit in bitstream order. The scope of the authentication data should not cross RAS; then calculate the secondary digest in the method indicated by authentication_hash_mode in sequence.
[0163] Perform a digital signature on the secondary digest value to generate the authentication data RBSP and pack it into the authentication data RBSP NAL unit.
[0164] If the values of authentication_enable_flag and encryption_enable_flag in multiple sets of security parameters in the bitstream are equal to 1, that is, the current RAS or knowledge image supports both encryption and authentication, then it should be encrypted first and then authenticated, that is, the data used for authentication should be the encrypted NAL unit.
[0165] encryption_unit_mode is the encryption basic unit, a 2-bit unsigned integer. It indicates the encryption basic unit. The value of '0' means encrypting in units of NAL; the value of '1' means encrypting in units of access units, concatenating the parts of all NAL unit RBSPs in the access unit that need to be encrypted in bitstream order and then encrypting, and restoring them to the encrypted NAL unit after encryption; the value of '2' means encrypting in units of layer units, concatenating the parts of all NAL unit RBSPs in the layer unit that need to be encrypted in bitstream order and then encrypting, and restoring them to the encrypted NAL unit after encryption; the value of '3' is reserved. The initial vector (IV) needs to be re-initialized for each encryption.
[0166] The encryption_level_mode is the encryption level mode, an unsigned 2-bit integer. It indicates the encryption level mode. When the value is '0', when encrypting all types of NAL units, the encryption object is all RBSP data (except the last byte of the RBSP); when the value is '1', when encrypting NAL units with nal_unit_type equal to 1, 2, 4, 12, 14, 17, 18, and 19, the encryption object is the first encryptionByte bytes of the RBSP, and when encrypting other types of NAL units, the encryption object is all RBSP data (except the last byte of the RBSP); when the value is '2', when encrypting NAL units with nal_unit_type equal to 1, 2, 4, 5, 12, 14, 17, 18, and 19, the encryption object is the first encryptionByte bytes of the RBSP, and when encrypting other types of NAL units, the encryption object is all RBSP data (except the last byte of the RBSP); the value '3' is reserved. Among them, encryptionByte = Min(EncryptionNum * EncryptionBaseByte, NumBytesInPayload - 1).
[0167] The encryption_num_minus1 is the number of encryption base byte lengths, an unsigned 8-bit integer. It indicates the number of encryption base byte lengths. The value of the number of encryption base byte lengths EncryptionNum is equal to the value of encryption_num_minus1 plus 1.
[0168] The encryption_base_byte is the encryption base byte length, an unsigned 2-bit integer. It indicates the encryption base byte length. When the value is '0', it means the value of the encryption base byte length EncryptionBaseByte is 16; when the value is '1', it means the value of the encryption base byte length EncryptionBaseByte is 64; when the value is '2', it means the value of the encryption base byte length EncryptionBaseByte is 256; when the value is '3', it means the value of the encryption base byte length EncryptionBaseByte is 1024.
[0169] The encryption_type is the encryption type, an unsigned 4-bit integer. It indicates the algorithm used for encryption. The specific corresponding relationship is shown in Table 4.
[0170] Table 4
[0171] Value of encryption_type Encryption algorithm 0 SM1 1 SM4 2~15 Reserved
[0172] vek_flag is the video encryption key flag, a binary variable. A value of '1' indicates that the video encryption key (VEK) is carried, and a value of '0' indicates that the vek is not carried.
[0173] iv_flag is the initialization vector flag, a binary variable. A value of '1' indicates that the iv is carried, and a value of '0' indicates that the iv is not carried.
[0174] vek_encryption_type is the video encryption key encryption type, a 4-bit unsigned integer. It indicates the encryption type of the video encryption key.
[0175] evek_length_minus1 is the length of the encrypted video encryption key, an 8-bit unsigned integer. It indicates the length of the encrypted video encryption key in bytes.
[0176] evek is the encrypted video encryption key, an n-bit unsigned integer. It represents the encrypted video encryption key for encryption calculation, with a length of evek_length_minus1 + 1 bytes.
[0177] vkek_version length_minus1 is the length of the video encryption key version number, an 8-bit unsigned integer. It indicates the length of the video encryption key version number in bytes.
[0178] vkek_version is the video encryption key version number, an n-bit unsigned integer. It indicates the video encryption key version number, with a length of vkek_version_length_minus1 + 1 bytes.
[0179] iv_length_minus1 is the length of the initialization vector, an 8-bit unsigned integer. It indicates the length of the initialization vector in bytes.
[0180] iv is the initialization vector, an n-bit unsigned integer. It indicates the initialization vector for block encryption, with a length of iv_length_minus1 + 1 bytes. hash_type is the hash type, a 2-bit unsigned integer. It indicates the algorithm used for authentication, and the specific correspondence is shown in Table 5.
[0181] Table 5
[0182] Value of hash_type Authentication algorithm Digest data length (bytes) 0 SM3 32 1~3 Reserved Reserved
[0183] The authentication_hash_mode is the authentication digest calculation mode, a binary variable. It identifies the method of calculating the secondary digest. A value of '0' indicates that the secondary digest is calculated using the concatenation method, i.e., the secondary digest is calculated for the layer unit digest values Hpic1, Hpic2, …, Hpicn in bitstream order; a value of '1' indicates that the secondary digest is calculated using the tree-top method, i.e., the layer unit digest values Hpic1, Hpic2, …, Hpicn are used as a reference in bitstream order to calculate the secondary digest using the tree-top method.
[0184] The hash_discard_nrap_pictures_flag is the non-random access point image hash authentication flag, a binary variable. A value of '1' indicates that non-random access point images are not authenticated; a value of 0 indicates that non-random access point images can be authenticated. If hash_discard_nrap_pictures is not in the bitstream, its default value is equal to 1.
[0185] The hash_period_in_doi_minus1 is the hash period, an 8-bit unsigned integer with a value range of 0 to (MAX_HASH_PERIOD / NumOfLayers - 1), where MAX_HASH_PERIOD is set to 256. HashPeriodInDoi is equal to hash_period_in_doi_minus1 + 1. It indicates the number of access units participating in signature authentication related to an authentication data. This number is less than or equal to HashPeriodInDoi. A HashPeriodInDoi of 1 indicates independent signature for a single access unit, and the authentication data NAL unit carrying this signature should be located at or after the first access unit following the access unit associated with this signature. A HashPeriodInDoi greater than 1 indicates joint signature for multiple access units.
[0186] The signature_type is the digital signature type, a 2-bit unsigned integer. It indicates the algorithm for digitally signing the digest data of the image, as shown in Table 6.
[0187] Table 6
[0188] Value of signature_type Signature algorithm 0 SM2 1~3 Reserved
[0189] The signature_fmt is the signature data format, a 2-bit unsigned integer. It indicates the signature data format. The specific regulations on the corresponding relationship between the value meanings of signature_fmt and the syntax of signature_type are shown in Table 7.
[0190] Table 7
[0191]
[0192] Exemplarily, in combination with the specific content of the above security parameter set, the steps for the encryption end 210 to generate the security parameter set can be as follows:
[0193] Step 1: Set sec_para_set_id according to the configuration, and set sec_is_library_flag according to the scope of the current security parameter set;
[0194] Step 2: Set encryption_enable_flag to 1 (indicating encryption is enabled); set encryption_type according to the encryption type in the configuration;
[0195] Step 3: Set encryption_unit_mode according to the configuration. Determine the basic encryption unit according to encryption_unit_mode. If the value of encryption_unit_mode is '0', it means encrypting in units of NAL; if the value is '1', it means encrypting in units of access units, and concatenating in bitstream order and encrypting the parts of all NAL unit RBSPs in the access unit that need to be encrypted; if the value is '2', it means encrypting in units of layer units, and concatenating in bitstream order and encrypting the parts of all NAL unit RBSPs in the layer unit that need to be encrypted;
[0196] Step 4: Set encryption_level_mode according to the configuration. If only part of the RBSP data of the coded slice NAL unit needs to be encrypted, set it to 1; if only part of the RBSP data of the coded slice NAL unit and the extended data NAL unit needs to be encrypted, set it to 2; otherwise, set it to 0; if encryption_level_mode is set to 1 or 2, set encryption_num_minus1 and encryption_base_byte according to the configured encryption byte length;
[0197] Step 5: Set vek_flag to 1, and set vek_encryption_type according to the key encryption type in the configuration. Generate VEK based on a secure random number, use the algorithm specified by vek_encryption_type to encrypt VEK using VKEK in ECB mode to obtain EVEK, write the data length minus one and the data of EVEK into evek_length_minus1 and evek respectively, and write the data length minus one and the data of the VKEK version used in the VEK encryption process into vkek_version_length_minus1 and vkek_version respectively; VEK and VKEK need to be updated according to business security requirements;
[0198] Step 6: Set iv_flag to 1, subtract one from the data length of the currently configured IV, and write the data length and data into iv_length_minus1 and iv respectively.
[0199] S302: Use the encryption method specified by the security parameter set to encrypt the NAL unit to be encrypted corresponding to the security parameter set.
[0200] As a possible implementation, encrypt the data unit according to the encryption algorithm used in the encryption method specified in the security parameter set to obtain the encrypted data unit. Among them, the encryption algorithm can be a symmetric encryption algorithm, such as encryption algorithms like SM1 and SM4.
[0201] Continuing to take the NAL unit as an example of the data unit, in some possible embodiments, the encryption end 210 extracts the RBSP data, then encrypts the RBSP data according to the encryption method specified in the security parameter set to obtain the encrypted RBSP data, and finally splices the NAL unit header and the encrypted RBSP data to obtain the encrypted NAL unit. If the RBSP data has been processed with the anti-counterfeiting start code, the encryption end 210 needs to remove the anti-counterfeiting start code after extracting the RBSP data. After the encryption end 210 obtains the encrypted RBSP data, it can add the anti-counterfeiting start code to the encrypted RBSP.
[0202] Exemplarily, in combination with the above definitions of the NAL unit and the security parameter set RBSP, the steps for encrypting the NAL unit that needs to be encrypted within the scope of the security parameter set are described.
[0203] Step 1: Determine the encryption level of each NAL unit to be encrypted: If encryption_level_mode is 0, encrypt the entire RBSP of the NAL unit; if encryption_level_mode is 1 and the NAL type of the NAL unit is a coded slice, encrypt its RBSP partially; if encryption_level_mode is 1 and the NAL type of the NAL unit is not a coded slice, encrypt its entire RBSP; if encryption_level_mode is 2 and the NAL type of the NAL unit is a coded slice or extended data, encrypt its RBSP partially; if encryption_level_mode is 2 and the NAL type of the NAL unit is not a coded slice or extended data, encrypt its entire RBSP.
[0204] Step 2: Determine the encryption data length of each NAL unit to be encrypted: For each NAL unit to be encrypted, calculate the encrypted byte length of the NAL unit according to the value of encryption_level_mode, its NAL type, and the RBSP length of the NAL unit. This length does not exceed the RBSP data length minus one. If the RBSP of the NAL unit is fully encrypted, the encryption data length is the RBSP data length minus one. If the RBSP of the NAL unit is partially encrypted, the corresponding encryption data length is determined by encryption_num_minus1 and encryption_base_byte. If this data length is greater than the RBSP data length minus one, the encryption data length is the RBSP data length minus one.
[0205] Step 3: Determine the data to be encrypted according to the encryption data length: If there is only one NAL unit in the encryption basic unit, obtain the first encryption data length bytes of the RBSP of the NAL unit for encryption according to its encrypted byte length, and retain the remaining unencrypted part of the RBSP data; if there are multiple NAL units in the encryption basic unit, obtain the first encryption data length bytes of the RBSP of each NAL unit according to the encrypted byte length of each NAL unit, and retain the remaining unencrypted part of each RBSP data. Concatenate the encrypted part data of these NAL units in bitstream order for encryption, and record the length of the encrypted part data of each RBSP.
[0206] Step 4: For the encrypted data to be encrypted, use the encryption algorithm marked by encryption_type in the security parameter set to encrypt with the VEK; initialize the IV to iv in the security parameter set during encryption.
[0207] S303, obtain the encrypted NAL unit;
[0208] The NAL unit includes a NAL unit header, and the NAL unit header includes an encryption flag. The encryption flag is the security parameter set identifier of the above-generated security parameter set, that is, the value of the encryption flag is equal to the value of the security parameter set. The encryption flag is used to indicate that the encrypted NAL unit is encrypted by the encryption method specified in the security parameter set corresponding to the security parameter set identifier.
[0209] As a possible implementation, restore the encrypted data to the original byte sequence load RBSP data after encryption; concatenate the NAL unit header and the encrypted RBSP data; set the encryption flag of the NAL unit header to the value of the security parameter set identifier in the security parameter set corresponding to the encrypted NAL unit to obtain the encrypted NAL unit.
[0210] Optionally, if there is only one NAL unit in the encryption basic unit, directly splice the encrypted data with the remaining unencrypted data of the reserved RBSP to obtain the encrypted RBSP data; if there are multiple NAL units in the encryption basic unit, split the encrypted data according to the length of each encrypted part of the RBSP recorded to obtain each encrypted part of the RBSP after encryption, and splice it with the remaining unencrypted data of the RBSP corresponding to the same NAL unit in turn to obtain each encrypted RBSP.
[0211] Optionally, perform anti-counterfeiting start code addition processing on the encrypted RBSP, combine it with the corresponding NAL unit header, and set the encryption_idc of the NAL unit header to the sec_para_set_id in its corresponding security parameter set to obtain the completely encrypted NAL unit.
[0212] S304, output the compressed video bitstream.
[0213] The compressed video bitstream includes encrypted data units and security parameter sets. The security parameter set includes encryption parameters and knowledge image identifiers, and the knowledge image identifier is used to indicate whether the security parameter set acts on the knowledge image or the display image.
[0214] The security parameter set can be in the form of RBSP. The security parameter set RBSP includes some parameters (such as encryption parameters), and these parameters can be used by one or more other types of NAL units. The knowledge image is encrypted or authenticated independently of the display image, and the sec_is_library_flag in the security parameter set RBSP is used to distinguish whether it is the security parameter set of the knowledge image. Multiple security parameter sets can be included in the bitstream, and they are distinguished by the security parameter set ID (sec_para_set_id). Up to 3 security parameter sets are supported simultaneously. There should be a security parameter set NAL unit before the random access point access unit of the RAS or the first knowledge image access unit, which acts on the current RAS or knowledge image. The security parameter set provides parameters for the encryption and authentication of the current RAS or knowledge image access unit. In the case of multiple security parameter sets, the sec_para_set_id is used to distinguish; if there is no security parameter set NAL unit in the random access point access unit of the RAS, it is considered that the current RAS (excluding non-display knowledge image access units) is not encrypted and does not participate in authentication; if there is no security parameter set NAL unit in the first knowledge image access unit, it is considered that the current knowledge image is not encrypted and does not participate in authentication.
[0215] When there is a non-display knowledge image in the encoded video sequence, for a non-RL preknowledge image, there should be a safety parameter set within the access unit whose patch_index value is 0. For an RL preknowledge image, there should be a safety parameter set within the access unit whose patch_index value is 0 and before the picture sequence parameter set. In some applications, the safety parameter set can also be transmitted to the decoder through other reliable mechanisms.
[0216] Figure 4 Schematic diagram of the exemplary decryption process 400. Among them, the process 400 can be implemented by the decryption end 220, and the process 400 corresponds to the process 300.
[0217] S401, input the compressed video bitstream;
[0218] The compressed video bitstream is input to the decryption end 220. The compressed video bitstream includes encrypted data units and a safety parameter set. The safety parameter set includes encryption parameters and a knowledge image identifier, and the knowledge image identifier is used to indicate whether the safety parameter set acts on a knowledge image or a display image. Among them, the safety parameter set can be one or more safety parameter set NAL units, which may include safety parameter set NAL units, but the safety parameter set NAL units are not encrypted and are not the same unit as the encrypted NAL units in this application.
[0219] Refer to Figure 4 , exemplarily, the n data units to be decrypted in the compressed video bitstream are respectively: data unit 1, data unit 2,..., data unit n. These n data units to be decrypted can be called a group of data units, that is, a group of decryption basic units to be decrypted.
[0220] Exemplarily, data unit 1 is the data unit of the encrypted knowledge image, and data units 2,..., data unit n are the data units of the encrypted display images.
[0221] Combined with the above NAL unit syntax definition, the steps to obtain the safety parameter set NAL unit in the compressed video bitstream can be as follows:
[0222] Step 1, if the encryption_type is 0, decrypt the encrypted bitstream using the SM1 algorithm; if the encryption_type is 1, decrypt the encrypted bitstream using the SM4 algorithm;
[0223] Step 2. Determine the decryption basic unit according to encryption_unit_mode. If the value of encryption_unit_mode is '0', it means decrypting in units of NAL; if the value is '1', it means decrypting in units of access units, and concatenating the parts of all NAL unit RBSPs in the access unit that need to be decrypted in bitstream order for decryption; if the value is '2', it means decrypting in units of layer units, and concatenating the parts of all NAL unit RBSPs in the layer unit that need to be decrypted in bitstream order for decryption.
[0224] Step 3. If encryption_level_mode is 1 or 2, obtain encryption_num_minus1 and encryption_base_byte in the security parameter set, and calculate the encrypted byte length in the case of partial encryption.
[0225] Step 4. If vek_flag is 1, obtain eve_length_minus1 and eve in the current security parameter set to get EVEK, obtain vkek_version_length_minus1 and vkek_version in the current security parameter set, obtain VKEK based on vkek_version, obtain the decryption algorithm marked by vek_encryption_type in the security parameter set, and use this algorithm to decrypt EVEK with VKEK to get VEK.
[0226] Step 5. If iv_flag is 1, obtain iv_length_minus1 and iv in the security parameter set to get IV.
[0227] S402. Decrypt the encrypted NAL unit corresponding to the security parameter set using the encryption method specified by the security parameter set.
[0228] Decrypt the encrypted data unit according to the algorithm used in the encryption method specified in the security parameter set to obtain the decrypted data unit.
[0229] Taking the encrypted data unit as an NAL unit as an example, the decrypting end 220 extracts the encrypted RBSP data from the encrypted NAL unit, then decrypts the encrypted RBSP data according to the video encryption key specified by the security parameter set to obtain the decrypted RBSP data, and finally concatenates the NAL unit header and the decrypted RBSP data to obtain the decrypted NAL unit. After extracting the encrypted RBSP data, if the encrypted RBSP data has added an anti-counterfeiting start code, remove the anti-counterfeiting start code of the encrypted RBSP data.
[0230] Decrypt the encrypted NAL unit corresponding to a security parameter set.
[0231] As a possible implementation, decrypt the NAL unit(s) with one or more encryption_idc set to sec_para_set_id in the current security parameter set in units of decryption basic units.
[0232] Combined with the semantic definitions of the above NAL unit and the security parameter set RBSP, the decryption steps of the encrypted NAL unit can be as follows:
[0233] Step 1: Determine the encryption level of each NAL unit to be decrypted: If encryption_level_mode is 0, decrypt all of the NAL unit RBSP; if encryption_level_mode is 1 and the NAL type of the NAL unit is a coded slice, decrypt its RBSP part; if encryption_level_mode is 1 and the NAL type of the NAL unit is not a coded slice, decrypt all of its RBSP; if encryption_level_mode is 2 and the NAL type of the NAL unit is a coded slice or extended data, decrypt its RBSP part; if encryption_level_mode is 2 and the NAL type of the NAL unit is not a coded slice or extended data, decrypt all of its RBSP;
[0234] Step 2: Determine the encrypted data length of each NAL unit to be decrypted: For each NAL unit to be decrypted, calculate the encrypted byte length of the NAL unit according to the value of encryption_level_mode, its NAL type, and the RBSP length of the NAL unit, and this length does not exceed one less than the RBSP data length. If the RBSP of the NAL unit is to be fully decrypted, the encrypted data length is one less than the RBSP data length; if the RBSP of the NAL unit is to be partially decrypted, the corresponding encrypted data length is determined by encryption_num_minus1 and encryption_base_byte, and if this data length is greater than one less than the RBSP data length, the encrypted data length is one less than the RBSP data length;
[0235] Step 3. Determine the data to be decrypted according to the encrypted data length: If there is only one NAL unit in the decryption basic unit, obtain the data of the first encrypted data length bytes before the RBSP of this NAL unit according to its encrypted byte length for decryption, and retain the remaining unencrypted data of the RBSP; If there are multiple NAL units in the decryption basic unit, obtain the data of the first encrypted data length bytes before the RBSP of each NAL unit according to the encrypted byte length of each NAL unit, and retain the remaining unencrypted data of each RBSP. Concatenate the encrypted data parts of these NAL units in bitstream order for decryption, and record the encrypted data length of each RBSP part.
[0236] Step 4. Decrypt the encrypted data: Decrypt the data to be decrypted with the algorithm and VEK marked by the encryption_type in the security parameter set to obtain the decrypted data. The initialization IV used during decryption is the IV obtained from the security parameter set.
[0237] S403. Obtain the decrypted RBSP data.
[0238] If there is only one NAL unit in the decryption basic unit, directly concatenate the decrypted data with the remaining unencrypted data of the RBSP retained to obtain the decrypted RBSP data; If there are multiple NAL units in the decryption basic unit, split the decrypted data according to the encrypted data length of each RBSP part recorded to obtain the decrypted part RBSP of each encrypted part RBSP, and concatenate them with the remaining unencrypted data of the RBSP corresponding to the same NAL unit in sequence to obtain each decrypted RBSP.
[0239] As a possible implementation, after obtaining the encrypted RBSP data, perform an anti-counterfeiting start code addition process on the decrypted RBSP, and combine it with the corresponding NAL unit header to obtain the complete decrypted NAL unit.
[0240] In a possible embodiment of the present application, the video encryption key, video key encryption key, etc. are symmetric encryption keys. The encryption end 210 and the decryption end 220 can use the same key to encrypt and decrypt data. The specific encryption and decryption methods can be any symmetric encryption method, which will not be elaborated here.
[0241] In some possible embodiments, if there is a decoder directly processing the decrypted RBSP data later and it is not necessary to restore the decrypted RBSP data to the decrypted NAL unit, then it is not necessary to obtain the complete decrypted NAL unit.
[0242] In some possible embodiments, when it is not necessary to restore the decrypted RBSP data to a decrypted NAL unit, there is no need to add an anti-counterfeiting start code to the decrypted RBSP data of the decrypted NAL unit.
[0243] In some possible embodiments, the decryption end 220 uses the decrypted RBSP data, i.e., the decrypted image, as a reference image for subsequent image decoding. The process will not be elaborated here.
[0244] Combined with the above Figure 3 shown encryption method and Figure 4 the decryption method shown, in the encryption process of the compressed video bitstream, the above encryption method provided by the present application separately encrypts the data units of the knowledge image and the display image, and independently generates a security parameter set for the knowledge image and a security parameter set for the display image. The security parameter set for the knowledge image is independent of the security parameter set for the display image. In this way, the compressed video bitstream carries the security parameter set for the knowledge image, enabling the decryption end to separately decrypt the encrypted data units of the knowledge image according to the security parameter set of the knowledge image. Compared with unified encryption and decryption for the display image and the knowledge image, the data units of the display image and the data units of the knowledge image use different independent security parameter sets respectively, without the need to ensure the constraint that the knowledge image and the random access segment where the knowledge image is located adopt the same security parameter set, reducing the complexity of the security parameter set. At the same time, during the knowledge image editing process, if it is required that the knowledge image and the random access segment where it is located use the same security parameter set, and the random access segment where the edited knowledge image is located may use a different security parameter set, the above encryption method provided by the present application separately encrypts and decrypts the data units of the knowledge image, solving the contradiction that the security parameter set of the edited knowledge image cannot meet the constraint that the knowledge image and the random access segment where it is located adopt the same security parameter set.
[0245] Please refer to Figure 5 , for example, the encryption device 500 includes:
[0246] A generation module 501, configured to generate a security parameter set; the security parameter set includes a knowledge image identifier and a security parameter set identifier. The knowledge image identifier is used to indicate whether the security parameter set acts on the display image or the knowledge image, and the security parameter set identifier is used to distinguish different security parameter sets acting on the same random access segment or knowledge image access unit;
[0247] An encryption module 502, configured to encrypt the network abstraction layer (NAL) unit to be encrypted corresponding to the security parameter set by using the encryption method specified by the security parameter set;
[0248] An acquisition module 503, configured to acquire an encrypted NAL unit; the NAL unit includes a NAL unit header, and the NAL unit header includes an encryption flag, and the encryption flag is a security parameter set identifier;
[0249] An output module 504, configured to output a compressed video bitstream; the compressed video bitstream includes the encrypted NAL unit and the security parameter set.
[0250] Exemplarily, when the knowledge image identifier takes a first value, it indicates that the security parameter set acts on the knowledge image, and when the knowledge image identifier takes a second value, it indicates that the security parameter set acts on the display image.
[0251] Exemplarily, the security parameter set further includes an encryption basic unit, and the encryption basic unit is used to indicate encryption in units of a NAL unit, an access unit AU, or a layer unit LU.
[0252] Exemplarily, the output module 504 is further configured to: pack the security parameter set into a security parameter set NAL unit; and add the security parameter set NAL unit before the picture sequence parameter set NAL unit.
[0253] Exemplarily, the encryption module 502 is further configured to: restore the encrypted data to the encrypted original byte sequence payload RBSP data; splice the NAL unit header and the encrypted RBSP data; and set the encryption flag of the NAL unit header to the value of the security parameter set identifier in the security parameter set corresponding to the encrypted NAL unit, so as to obtain the encrypted NAL unit.
[0254] Exemplarily, the encryption module 502 is further configured to: add an anti-counterfeiting start code to the encrypted RBSP data.
[0255] Exemplarily, for the knowledge image, each frame of image corresponds to a sequence parameter set, and the coded image with the knowledge bitstream flag being 1 in the corresponding sequence set parameters, and the display image is a reference knowledge image, an instant decoding refresh image, a P image, a B image, or a random access point I-frame image output by the decoder after decoding the reconstructed image.
[0256] When the encryption device 500 implements the encryption method shown in any of the foregoing figures through software, the encryption device 500 and its respective units may also be software modules. The above encryption method is implemented by calling the software module through a processor. The processor may be a central processing unit (CPU), implemented by an application-specific integrated circuit (ASIC), or a programmable logic device (PLD). The above PLD may be a complex programmable logic device (CPLD), a field programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0257] It can be understood that Figure 5 The encryption device 500 shown is only an example provided in this embodiment. Depending on the different encryption and decryption processes, the encryption device 500 may include more or fewer units, which are not limited in this application.
[0258] When the encryption device 500 is implemented by hardware, the hardware may be implemented by a processor or a chip system. The chip system includes one or more chips, and each chip includes an interface circuit and a control circuit. The interface circuit is used to receive data from other devices outside the chip and transmit it to the control circuit, or send the data from the control circuit to other devices outside the chip. The control circuit and the interface circuit use logic circuits or execute code instructions to implement the method of any possible implementation manner in the above embodiment. The beneficial effects can be referred to the description of any aspect in the above embodiment, which will not be elaborated here.
[0259] It can be understood that the processor in the embodiments of this application may be a CPU, or other general-purpose processors, digital signal processors (DSPs), ASICs, FPGAs, or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0260] Figure 6 It is a schematic diagram of a decryption device shown for illustration. The schematic diagram of the decryption device can be used to execute the method of the foregoing embodiment. Therefore, the beneficial effects it can achieve can refer to the beneficial effects in the corresponding method provided above, which will not be elaborated here.
[0261] Please refer toFigure 6 , exemplarily, the decryption device 600 includes:
[0262] An input module 601, configured to input a compressed video bitstream;
[0263] An acquisition module 602, configured to acquire a set of security parameters in the compressed video bitstream; the set of security parameters includes a knowledge image identifier and a security parameter set identifier, the knowledge image identifier is used to indicate whether the set of security parameters acts on a display image or a knowledge image, and the security parameter set identifier is used to distinguish different sets of security parameters acting on the same random access segment or knowledge image access unit;
[0264] A decryption module 603, configured to decrypt the encrypted NAL unit corresponding to the set of security parameters by using the encryption method specified by the set of security parameters; the encryption flag of the encrypted NAL unit is the security parameter set identifier;
[0265] The decryption module 603 is further configured to acquire the decrypted RBSP data.
[0266] Exemplarily, when the knowledge image identifier takes a first value, it indicates that the set of security parameters acts on a knowledge image, and when the knowledge image identifier takes a second value, it indicates that the set of security parameters acts on a display image.
[0267] Exemplarily, the set of security parameters further includes an encryption basic unit, and the encryption basic unit is used to indicate encryption in units of NAL units, access units AU, or layer units LU.
[0268] Exemplarily, the decryption module 603 is further configured to: add an anti-counterfeiting start code to the decrypted RBSP data.
[0269] Exemplarily, the decryption module 603 is further configured to: splice the NAL unit header and the decrypted RBSP data to obtain the decrypted NAL unit.
[0270] Exemplarily, for a knowledge image, each frame of image corresponds to a sequence parameter set, and the coded image with the knowledge bitstream flag being 1 in the corresponding sequence set parameters, and a display image is a reference knowledge image, an instant decoding refresh image, a P image, a B image, or a random access point I-frame image output by the decoder after decoding the reconstructed image.
[0271] When the decryption device 600 implements the decryption method shown in any of the foregoing figures through software, the decryption device 600 and its respective units may also be software modules. The above decryption method is implemented by the processor calling the software module. The processor may be a CPU, implemented by an ASIC, or a PLD, and the above PLD may be a CPLD, an FPGA, a GAL, or any combination thereof.
[0272] It can be understood that Figure 6The decryption device 600 shown is only an example provided in this embodiment. Depending on the different encryption and decryption processes, the decryption device 600 may include more or fewer units, which is not limited in this application.
[0273] When the decryption device 600 is implemented by hardware, the hardware can be implemented by a processor or a chip system. The chip system includes one or more chips, and each chip includes an interface circuit and a control circuit. The interface circuit is used to receive data from other devices outside the chip and transmit it to the control circuit, or send the data from the control circuit to other devices outside the chip. The control circuit and the interface circuit use logic circuits or execute code instructions to implement the method of any possible implementation manner in the above embodiments. The beneficial effects can be referred to the description of any aspect in the above embodiments, and will not be elaborated here.
[0274] It can be understood that the processor in the embodiments of this application can be a CPU, or other general-purpose processors, DSPs, ASICs, FPGAs or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor can be a microprocessor or any conventional processor.
[0275] In one example, Figure 7 A schematic block diagram of a device 700 according to an embodiment of this application is shown. The device 700 may include: a processor 701 and a transceiver / transceiver pin 702. Optionally, it further includes a memory 703.
[0276] Each component of the device 700 is coupled together through a bus 704. The bus 704 includes, in addition to the data bus, a power bus, a control bus, and a status signal bus. However, for the sake of clarity, all kinds of buses are referred to as the bus 704 in the figure.
[0277] Optionally, the memory 703 can be used to store the instructions in the foregoing method embodiments. The processor 701 can be used to execute the instructions in the memory 703, control the receiving pin to receive signals, and control the sending pin to send signals.
[0278] The device 700 can be the electronic device or the chip of the electronic device in the above method embodiments.
[0279] Among them, all relevant contents of each step involved in the above method embodiments can be cited in the function descriptions of the corresponding functional modules, and will not be elaborated here.
[0280] An embodiment of the present application further provides a chip, including one or more interface circuits and one or more processors; the one or more processors receive or send data through the one or more interface circuits. When the one or more processors execute computer instructions, the above-mentioned relevant method steps are executed to implement the method steps in the above-mentioned embodiment. Among them, the interface circuit is a transceiver / transceiver pin 902.
[0281] This embodiment further provides a non-transitory computer-readable storage medium, in which computer instructions are stored. When the computer instructions run on an electronic device, the electronic device is enabled to execute the above-mentioned relevant method steps to implement the method in the above-mentioned embodiment.
[0282] This embodiment further provides a computer program product, which includes computer instructions. When the computer instructions are executed by a computer or a processor, the computer is enabled to execute the above-mentioned relevant steps to implement the method in the above-mentioned embodiment.
[0283] In addition, an embodiment of the present application further provides a device, which may specifically be a chip, a component or a module. The device may include a connected processor and a memory; among them, the memory is used to store computer execution instructions. When the device runs, the processor may execute the computer execution instructions stored in the memory, so that the chip executes the methods in the above-mentioned method embodiments.
[0284] Among them, the electronic device, the non-transitory computer-readable storage medium, the computer program product or the chip provided in this embodiment are all used to execute the corresponding method provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method provided above, and will not be elaborated here.
[0285] Through the description of the above embodiments, those skilled in the art can understand that for the convenience and simplicity of description, only the above-mentioned division of each functional module is used for illustration. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.
[0286] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections between each other can be through some interfaces. The indirect couplings or communication connections of devices or units can be in electrical, mechanical or other forms.
[0287] The units described as separate components may or may not be physically separated. The components displayed as units may be one physical unit or multiple physical units, that is, they can be located in one place, or they can be distributed to multiple different places. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0288] In addition, in each embodiment of the present application, each functional unit can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.
[0289] Any content of each embodiment of the present application, as well as any content of the same embodiment, can be freely combined. Any combination of the above content is within the scope of the present application.
[0290] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a non-transitory computer-readable storage medium. Based on such an understanding, the technical solution of the embodiments of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The software product is stored in a storage medium and includes several instructions for causing a device (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the methods of each embodiment of the present application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read only memory (ROM), random access memory (RAM), magnetic disks or optical discs that can store program codes.
[0291] The steps of the method or algorithm described in connection with the disclosed content of the embodiments of the present application can be implemented in a hardware manner or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, and the software modules can be stored in a random access memory (RAM), flash memory, read only memory (ROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), registers, hard disk, removable hard disk, compact disc read only memory (CD-ROM), or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an ASIC.
[0292] Those skilled in the art should be able to realize that in one or more of the above examples, the functions described in the embodiments of the present application can be implemented by hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. The computer-readable medium includes a non-transitory computer-readable storage medium and a communication medium, where the communication medium includes any medium that facilitates the transmission of a computer program from one place to another. The storage medium can be any available medium accessible by a general-purpose or special-purpose computer.
[0293] The embodiments of the present application have been described above in conjunction with the accompanying drawings. However, the present application is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not restrictive. Under the inspiration of the present application, those of ordinary skill in the art can also make many forms without departing from the purpose of the present application and the scope protected by the claims, and all of them belong to the protection scope of the present application.
Claims
1. A cryptographic method, characterized in that, The method includes: Generating a security parameter set; the security parameter set includes a knowledge image identifier and a security parameter set identifier, the knowledge image identifier is used to indicate that the security parameter set acts on a display image or a knowledge image, and the security parameter set identifier is used to distinguish different security parameter sets acting on the same random access segment (RAS) or knowledge image access unit; Using the encryption method specified by the security parameter set to encrypt the network abstraction layer (NAL) unit to be encrypted corresponding to the security parameter set; Obtaining the encrypted NAL unit; the encrypted NAL unit includes a NAL unit header, and the NAL unit header includes an encryption flag, and the encryption flag is the security parameter set identifier; Outputting a compressed video bitstream; the compressed video bitstream includes the encrypted NAL unit and the security parameter set.
2. The method according to claim 1, wherein When the knowledge image identifier takes a first value, it indicates that the security parameter set acts on a knowledge image, and when the knowledge image identifier takes a second value, it indicates that the security parameter set acts on a display image.
3. The method according to claim 1 or 2, characterized in that, The security parameter set further includes an encryption basic unit, and the encryption basic unit is used to indicate encryption in units of NAL units, access units (AU) or layer units (LU).
4. The method according to any one of claims 1-3, characterized in that After generating the security parameter set, the method further includes: Packing the security parameter set into a security parameter set NAL unit; Adding the security parameter set NAL unit before the picture sequence parameter set NAL unit.
5. The method according to any one of claims 1-4, characterized in that, The obtaining of the encrypted NAL unit includes: Restoring the encrypted data to the encrypted raw byte sequence payload (RBSP) data; Concatenating the NAL unit header and the encrypted RBSP data; Setting the encryption flag of the NAL unit header to the value of the security parameter set identifier in the security parameter set corresponding to the encrypted NAL unit, to obtain the encrypted NAL unit.
6. The method according to claim 5, characterized in that, After restoring the encrypted data to the encrypted raw byte sequence payload RBSP data, the method further includes: Adding an anti-counterfeiting start code to the encrypted RBSP data.
7. The method according to any one of claims 1-6, characterized in that, The knowledge image is an encoded image with a knowledge bitstream flag of 1 in the corresponding sequence set parameter where each frame image corresponds to a sequence parameter set, and the display image is a reference knowledge (RL) image, an instant decoding refresh (IDR) image, a P image, a B image or a random access point I-frame (RAPI) image output by the decoder after decoding the reconstructed image.
8. A decryption method, characterized in that, including: Inputting a compressed video bitstream; Obtaining the security parameter set in the compressed video bitstream; The security parameter set includes a knowledge image identifier and a security parameter set identifier, the knowledge image identifier is used to indicate that the security parameter set acts on a display image or a knowledge image, and the security parameter set identifier is used to distinguish different security parameter sets acting on the same random access segment or knowledge image access unit; Using the encryption method specified by the security parameter set to decrypt the encrypted NAL unit corresponding to the security parameter set; the encryption flag of the encrypted NAL unit is the security parameter set identifier; Obtaining the decrypted RBSP data.
9. The method according to claim 8, wherein When the knowledge image identifier takes a first value, it indicates that the security parameter set acts on the knowledge image. When the knowledge image identifier takes a second value, it indicates that the security parameter set acts on the display image.
10. The method according to claim 8 or 9, characterized in that The security parameter set further includes an encryption basic unit, and the encryption basic unit is used to indicate encryption in units of NAL units, access units AU, or layer units LU.
11. The method according to any one of claims 8-10, characterized in that, After obtaining the decrypted RBSP data, the method further includes: Adding an anti-counterfeiting start code to the decrypted RBSP data.
12. The method according to any one of claims 8-11, characterized in that, After obtaining the decrypted RBSP data, the method further includes: Concatenating the NAL unit header and the decrypted RBSP data to obtain a decrypted NAL unit.
13. A compressed video bitstream, characterized in that, The compressed video bitstream includes: Encrypted NAL units and a security parameter set; Wherein, the security parameter set includes a knowledge image identifier and a security parameter set identifier. The knowledge image identifier is used to indicate that the security parameter set acts on the display image or the knowledge image. The security parameter set identifier is used to distinguish different security parameter sets acting on the same random access segment or knowledge image access unit. The encrypted NAL unit includes a NAL unit header, and the encrypted NAL unit header includes an encryption flag, and the encryption flag is the security parameter set identifier.
14. The compressed video bitstream according to claim 13, characterized in that, When the knowledge image identifier takes a first value, it indicates that the security parameter set acts on the knowledge image. When the knowledge image identifier takes a second value, it indicates that the security parameter set acts on the display image.
15. The compressed video bitstream according to claim 13 or 14, characterized in that, The security parameter set further includes an encryption basic unit, and the encryption basic unit is used to indicate encryption in units of NAL units, access units AU, or layer units LU.
16. The compressed video bitstream according to any one of claims 13-15, characterized in that, The knowledge image is an encoded image corresponding to each frame of image with a sequence parameter set, and the knowledge bitstream flag in the corresponding sequence set parameter is 1. The display image is a reference knowledge RL image, an instantly decoded refresh IDR image, a P image, a B image, or a random access point I-frame RAPI image output by the decoder after decoding the reconstructed image.
17. An encryption device, characterized in that, Including: A generation module, configured to generate a security parameter set; The security parameter set includes a knowledge image identifier and a security parameter set identifier. The knowledge image identifier is used to indicate that the security parameter set acts on the display image or the knowledge image. The security parameter set identifier is used to distinguish different security parameter sets acting on the same random access segment or knowledge image access unit; An encryption module, configured to encrypt the network abstraction layer NAL unit to be encrypted corresponding to the security parameter set by using the encryption method specified by the security parameter set; An acquisition module, configured to acquire the encrypted NAL unit; the encrypted NAL unit includes a NAL unit header, and the NAL unit header includes an encryption flag, and the encryption flag is the security parameter set identifier; An output module, configured to output a compressed video bitstream; the compressed video bitstream includes the encrypted NAL unit and the security parameter set.
18. The device according to claim 17, characterized in that, When the knowledge image identifier takes a first value, it indicates that the security parameter set acts on the knowledge image. When the knowledge image identifier takes a second value, it indicates that the security parameter set acts on the display image.
19. The device according to claim 17 or 18, characterized in that, The security parameter set further includes an encryption basic unit, which is used to indicate encryption in units of NAL units, access units AU, or layer units LU.
20. The device according to any one of claims 17 - 19, characterized in that The output module is further configured to: package the security parameter set into a security parameter set NAL unit; add the security parameter set NAL unit before the picture sequence parameter set NAL unit.
21. The device according to any one of claims 17 - 20, characterized in that, The encryption module is further configured to: restore the encrypted data to the encrypted original byte sequence payload RBSP data; concatenate the NAL unit header and the encrypted RBSP data; set the encryption flag of the NAL unit header to the value of the security parameter set identifier in the security parameter set corresponding to the encrypted NAL unit, to obtain the encrypted NAL unit.
22. The device according to claim 21, characterized in that, The encryption module is further configured to: add an anti-counterfeiting start code to the encrypted RBSP data.
23. The device according to any one of claims 17-22, characterized in that The knowledge picture is an encoded picture in which each picture corresponds to a sequence parameter set and the knowledge bitstream flag in the corresponding sequence set parameter is 1, and the display picture is a reference knowledge RL picture, an instantly decoded refresh IDR picture, a P picture, a B picture, or a random access point I-frame RAPI picture output by the decoder after decoding the reconstructed picture.
24. A decryption device, characterized in that, including: an input module, configured to input a compressed video bitstream; an acquisition module, configured to acquire the security parameter set in the compressed video bitstream; The security parameter set includes a knowledge picture identifier and a security parameter set identifier. The knowledge picture identifier is used to indicate whether the security parameter set acts on a display picture or a knowledge picture, and the security parameter set identifier is used to distinguish different security parameter sets acting on the same random access segment or knowledge picture access unit; a decryption module, configured to decrypt the encrypted NAL unit corresponding to the security parameter set by using the encryption method specified by the security parameter set; the encryption flag of the encrypted NAL unit is the security parameter set identifier; The decryption module is further configured to obtain the decrypted RBSP data.
25. The device according to claim 24, characterized in that, When the knowledge picture identifier takes a first value, it indicates that the security parameter set acts on a knowledge picture, and when the knowledge picture identifier takes a second value, it indicates that the security parameter set acts on a display picture.
26. The device according to claim 24 or 25, characterized in that, The security parameter set further includes an encryption basic unit, which is used to indicate encryption in units of NAL units, access units AU, or layer units LU.
27. The device according to any one of claims 24-26, characterized in that, The decryption module is further configured to: add an anti-counterfeiting start code to the decrypted RBSP data.
28. The device according to any one of claims 24-27, characterized in that, The decryption module is further configured to: concatenate the NAL unit header and the decrypted RBSP data to obtain a decrypted NAL unit.
29. The device according to any one of claims 24-28, characterized in that, The knowledge picture is an encoded picture in which each picture corresponds to a sequence parameter set and the knowledge bitstream flag in the corresponding sequence set parameter is 1, and the display picture is a reference knowledge RL picture, an instantly decoded refresh IDR picture, a P picture, a B picture, or a random access point I-frame RAPI picture output by the decoder after decoding the reconstructed picture.
30. A coding device, comprising at least one processor and a memory, characterized in that, The at least one processor executes the program or instruction stored in the memory, so that the encoding device implements the method described in any one of claims 1-7 above.
31. A decoding device, comprising at least one processor and a memory, characterized in that, The at least one processor executes a program or instructions stored in the memory, so that the encoding device implements the method according to any one of claims 8-12 above.
32. A non-transitory computer-readable storage medium for storing a computer program, characterized in that, When the computer program runs on a computer or a processor, the computer or the processor implements the method according to any one of claims 1-7 above.
33. A computer program product comprising instructions, characterized in that, When the instructions run on a computer or a processor, the computer or the processor implements the method according to any one of claims 8-12 above.