A method and apparatus for dynamic controllable video coding

By introducing a controllable encoding module and encrypted control signals at the video acquisition end, real-time switching and layered encoding of video streams are achieved, solving the problems of slow response to dynamic security needs and resource waste in existing technologies, and improving the security and resource utilization efficiency of video surveillance systems.

CN121462770BActive Publication Date: 2026-05-01BEIJING YANXUN COMMUNICATION TECHNOLOGY DEVELOPMENT CO
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING YANXUN COMMUNICATION TECHNOLOGY DEVELOPMENT CO
Filing Date
2025-11-21
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

When faced with dynamic changes in security requirements, existing video surveillance systems require manual intervention to switch encoding methods, resulting in slow response and security risks. Furthermore, dual encoding methods increase the consumption of equipment resources and waste network bandwidth, making it impossible to achieve on-demand encryption.

Method used

A controllable encoding module is introduced at the video acquisition end, combined with encrypted control signals, to realize real-time switching control of the video stream. A layered encoding strategy is adopted, using H.264/H.265 encoding in ordinary scenarios and SVAC encryption encoding in confidential scenarios. A cache synchronization mechanism is used to ensure the continuity and integrity of the recorded data.

Benefits of technology

It enables real-time, automatic switching of video streams, meets the requirements of different security levels, saves equipment resources and network bandwidth, improves system security and reliability, and reduces equipment investment costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121462770B_ABST
    Figure CN121462770B_ABST
Patent Text Reader

Abstract

The application discloses a kind of dynamic controllable video encoding method and device, method includes introducing controllable coding module in video acquisition end, control is carried out to the real-time switching of video stream in combination with encryption control signal;Using encrypted video platform, the coding control instruction including non-encryption encoding instruction and encryption encoding instruction is issued through network control interface;Video encoding is carried out using layered coding strategy;When video does not need to be encrypted, non-encryption encoding mode instruction is issued by platform;When video needs to be encrypted, encryption encoding mode instruction is issued by platform, and video acquisition terminal switches to encryption mode;In encrypted video platform client, corresponding session key is obtained from key management module according to session identification in video frame header, received encrypted video stream is decrypted and played, and decryption end adopts frame-level decryption strategy, only complete decryption is carried out to key frame, and prediction frame is reconstructed by referring to decrypted frame, effectively solve the problem of video security and video sharing.
Need to check novelty before this filing date? Find Prior Art

Description

A method and apparatus for dynamically controllable video coding Technical Field

[0001] This invention relates to the field of video encoding processing technology, and specifically to a method and apparatus for dynamically controllable video encoding. Background Technology

[0002] Regarding the intelligent application of video surveillance, a contradiction exists in the application field: some key locations are not absolute geographical attributes, but are affected by activities or events taking place at those locations. For example, when there are no important events, a certain place is just an ordinary street or square, and the video needs to meet the requirements of interconnection. However, during major events, it becomes a key and vulnerable area, and the security and controllability of the video must be guaranteed. Currently, most users adopt a dual-stream dual-encoding method, where the front-end camera or encoding device needs to run two independent encoding algorithms (such as H.264 and SVAC) simultaneously.

[0003] However, encoding is a computationally intensive task. Dual encoding consumes a large amount of DSP / CPU resources, leading to a significant increase in device power consumption and heat generation, shortening device lifespan, and limiting the device's ability to run other intelligent analysis tasks simultaneously. Simultaneous uploading of two high-definition video streams consumes twice the network bandwidth. During off-peak periods, the transmission of encrypted streams is itself a waste of bandwidth, and during periods of network resource scarcity, this will crowd out the transmission of other critical data. This results in a loss of both front-end device computing power and transmission bandwidth. Crucially, because unencrypted video streams are continuously outputting, the system needs to manage two streams with different security levels simultaneously, increasing the configuration complexity of the streaming media server, storage server, and client. Negligence in the management of any stream can lead to security incidents, thus failing to guarantee security. Furthermore, the existing encoding methods are fundamentally "static" and cannot respond to "dynamic" changes in security requirements. Switching from a normal state to a critical state often requires manual intervention to enable / disable a stream, resulting in slow response and a high risk of errors. In normal operation, the system cannot provide "on-demand encryption" services. For example, even during normal hours, if the surveillance footage suddenly captures a sensitive event (such as a sudden security incident), the system cannot automatically and in real time convert the video to encrypted transmission. Summary of the Invention

[0004] The purpose of this invention is to provide a method and apparatus for dynamically controllable video encoding to solve the problems mentioned in the background art.

[0005] The specific technical solution provided by this invention is as follows: A device for dynamic and controllable video encoding, comprising a video acquisition terminal, an encrypted video platform, an unencrypted video platform, a control channel, a user permission verification module, and a recording module;

[0006] Preferably, the video acquisition terminal includes a camera or encoder with dual encoding capabilities for switching encoding modes of the video stream; the camera or encoder includes a main encoding module and a secondary encoding module; the main encoding module is used to perform encrypted video encoding tasks; the secondary encoding module is used to perform unencrypted video encoding tasks; the encrypted video platform is used to issue encoding control commands through a network control interface; the unencrypted video platform is used to execute unencrypted encoding commands on the video stream; the control channel is used to manage the encrypted and unencrypted modes of the video stream, including protocol channel 1 and protocol channel 2; protocol channel 1 is used to send the video stream and encryption parameters to the encrypted video platform; protocol channel 2 is used to send the video stream to the unencrypted video platform; the user permission verification module is used to verify the user permissions of the user issuing the control commands; the recording module is used to trigger an automatic reconnection process through a callback interface and call the decryption parameters.

[0007] A method for dynamically controllable video encoding includes the following steps:

[0008] Step S1: Introduce a controllable encoding module at the video acquisition end, and combine it with an encryption control signal to control the real-time switching of the video stream.

[0009] Preferably, before controlling the real-time switching of the video stream, the video data is first written to a buffer. A dual-buffer synchronization mechanism, including a main buffer and a secondary buffer, is set up. When an encryption mode switching command is detected, the remaining frame data in the main buffer is automatically transferred to the secondary buffer for temporary storage, and the new video stream data is written to the main buffer. After the encryption or decryption switch is completed, the buffer scheduling module submits the data in the secondary buffer to the target storage terminal to ensure the continuity and integrity of the recorded data and avoid the loss of video segments due to switching delays.

[0010] Step S2: Using the encrypted video platform, issue encoding control commands, including unencrypted and encrypted encoding commands, through the network control interface.

[0011] Step S3: Adopt a layered coding strategy. Use H.264 / H.265 video coding in ordinary scenarios and SVAC encrypted video coding in classified scenarios.

[0012] Preferably, the use of H.264 / H.265 video encoding in ordinary scenarios includes: automatically loading H.264 / H.265 encoding parameters after receiving unencrypted encoding instructions at the video acquisition end, and performing scene-adaptive preprocessing including noise reduction and brightness equalization; adopting an IPB frame hybrid encoding strategy to dynamically adjust the I / P / B frame ratio; performing DCT / ICT transformation and adaptive quantization; in the entropy encoding stage, H.264 uses CABAC, and H.265 introduces SAO offset compensation; the bitstream is encapsulated in the standard RTP / RTSP format and marked with an "unencrypted identifier"; and ensuring transmission requirements in multiple scenarios through hardware acceleration and priority scheduling mechanisms.

[0013] Preferably, in classified scenarios, SVAC encrypted video encoding includes: after receiving the encryption encoding instruction, the front end switches to the SVAC encoding process to perform encoding and encryption fusion; the device identity is authenticated through SM2 two-way authentication, and a temporary session key is distributed using ZUC; SVAC2.0 encoding parameters are initialized, and three-level encryption is enabled; during the acquisition phase, sensitive area positioning and anti-tampering preprocessing are added, and metadata such as timestamps and device identifiers are embedded; three-layer encryption is implemented during the encoding process: the first layer uses the ZUC encryption algorithm to add control information to the cryptographic stream header; the second layer selectively encrypts the high-frequency coefficients of I-frames and the high bits of motion vectors in P / B frames, and updates the subkey every 10 frames; the third layer generates an SM3 digest of the metadata and encrypts it with the SM2 public key to form a digital watermark; it is encapsulated into an SVAC dedicated bitstream, with the encryption identifier and algorithm type marked in the header, transmitted end-to-end through IPSec VPN, and the SM3 hash value is verified every 100 frames; after identity authentication and bitstream integrity verification, the decoding end decrypts and restores the video layer by layer.

[0014] Step S4: When the video does not need to be encrypted, the platform issues an instruction for unencrypted encoding.

[0015] Preferably, the image acquisition module outputs raw frame data; the unencrypted encoding module performs conventional intra / inter-frame prediction, transformation, quantization, and entropy encoding operations on the input frame; the generated video stream is encapsulated according to the RTP / RTSP protocol and output to either an encrypted or unencrypted video platform; in unencrypted mode, the encrypted encoding channel is simultaneously activated: the main encoding module performs SVAC encryption encoding, and the secondary encoding module performs H.264 / H.265 encoding; after encoding, the streams are pushed to both the encrypted and unencrypted video platforms to achieve synchronous dual-stream output.

[0016] Step S5: When the video needs to be encrypted, the platform issues an encryption encoding method instruction, and the video acquisition terminal switches to encryption mode.

[0017] Preferably, the platform issues encryption encoding instructions including: the encoder generates a session key according to the instructions and inserts an encryption identifier header into the first frame of each GOP; performs a symmetric encryption algorithm on the keyframe data; encrypts only the motion vector and part of the macroblock header information for the predicted frame; the encrypted video frame is repackaged into an SVAC stream and output to the encrypted video platform; when the encryption mode is activated, the last frame image in the cache is called and the text message "video has been encrypted" is superimposed; at the same time, a status flag field, including the session identifier and encryption status flag, is written into the metadata of the frame; the encoder encodes the still frame in JPEG or I-frame format and pushes it to the unencrypted video platform through the unencrypted output channel.

[0018] Preferably, an automatic keyframe generation and insertion mechanism is also introduced, and the implementation process is as follows:

[0019] a. Define and detect the handover moment, and monitor the conditions used for redundancy confirmation handover moment;

[0020] b. Trigger the automatic keyframe generation process based on monitoring conditions;

[0021] c. Ensure the continuity of video recordings.

[0022] Step S6: On the encrypted video platform client, the corresponding session key is obtained from the key management module based on the session identifier in the video frame header. The received encrypted video stream is then decrypted and played. The decryption end adopts a frame-level decryption strategy, performing full decryption only on key frames. Predicted frames are reconstructed by referring to the decrypted frames.

[0023] Compared with existing technologies, the beneficial effects achieved by this invention are as follows: This invention introduces a controllable encoding module at the video acquisition end, combined with an encryption control signal, to achieve real-time switching control of the video stream. When encryption is enabled, video data, after being processed by the encryption algorithm, is only output to the encrypted platform, while transmission to the unencrypted platform is automatically stopped, ensuring the security of video data in confidential scenarios. When encryption is disabled, video data is output to both the encrypted and unencrypted platforms simultaneously, meeting the sharing needs in public scenarios. This invention's method can meet the video application needs of different application scenarios in the same location. This method and device effectively resolve the contradiction between video security and video sharing, while also saving construction costs and reducing investment in redundant equipment deployment. Attached Figure Description

[0024] Figure 1 is a flowchart of the steps of a dynamic controllable video encoding method provided by an embodiment of the present invention.

[0025] Figure 2 is a schematic diagram of the logical architecture of the dynamic controllable video encoding provided in an embodiment of the present invention. Detailed Implementation

[0026] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention are within the scope of protection of the present invention.

[0027] Example 1:

[0028] The device for dynamically controllable video encoding described in this embodiment includes: a camera, an encrypted video platform, and an unencrypted platform.

[0029] In this embodiment, the camera is used to register with both encrypted and unencrypted video platforms, and is controlled via the camera's web interface. Registration with the encrypted video platform uses the GB35114 protocol, establishing a control channel "Protocol Channel 1". This channel has video encryption mode management capabilities, allowing remote issuance of encryption control commands carrying encryption parameters. In the GB35114 protocol's stream levels, level A represents unencrypted video streams, and level C represents encrypted video streams. Registration with the unencrypted video platform uses the GB28181 protocol, establishing a control channel "Protocol Channel 2". This device defaults to unencrypted mode; only connections registered with the encrypted platform can control whether the video stream is encrypted.

[0030] For example, when protocol channel 1 controls the camera to operate in Class A streaming mode, the system enters unencrypted mode. At this time, the camera outputs a video stream using H.264 or H.265 encoding (configurable via the camera interface). The video stream is sent to the encrypted video platform and the unencrypted video platform via protocol channel 1 and protocol channel 2 respectively. In unencrypted mode, the camera's internal encryption module is in standby mode and does not perform encryption key negotiation or key stream generation. When protocol channel 1 controls the camera to switch to Class C streaming mode, the system enters encrypted mode and performs the following steps:

[0031] Step a1: When protocol channel 1 controls the camera to switch to C-level stream, perform stream interruption protection, immediately stop the video transmission of protocol channel 1, and close the unencrypted stream buffer to prevent data residue during the switching process;

[0032] Step a2: Generate an encrypted session key. The security module inside the camera generates a temporary encryption key Kzuc, using the timestamp, device ID, and channel number as the random source.

[0033] Step a3: Perform key encryption and transmission, using the platform's public key Ppub to perform SM2 encryption operations to generate... And transmit it to the encrypted video platform via the GB 35114 signaling channel;

[0034] Step a4: Encrypt the video stream. The camera calls the ZUC encryption algorithm on the encoded frame data, generates a key stream with the session key Kzuc and the initialization vector IV, and re-encapsulates each frame data after performing an XOR operation.

[0035] Step a5: After the platform confirms receipt of the key, re-establish the encrypted video connection for channel 1 and restore the video stream;

[0036] Step a6: Protocol channel 2 generates a static prompt frame that displays "Video has been encrypted". The metadata carries EncryptFlag=1 and SessionID for unencrypted platform prompts and recording continuity assurance, thus completing the push of the unencrypted prompt frame.

[0037] For example, when protocol channel 1 switches from a Class C stream back to a Class A stream, the system exits encryption mode and performs the following steps:

[0038] Step b1: The camera clears the current session key Kzuc and resets the encryption status flag EncryptFlag to 0;

[0039] Step b2: Re-establish the unencrypted video channel and restore H.264 / H.265 video output;

[0040] Step b3: Protocol channel 2 automatically stops sending static notification frames and resumes real-time video transmission to ensure continuous video service.

[0041] In this embodiment, based on the encrypted video platform, user permissions can be added in the platform configuration interface, including whether the user can control the encryption and unencryption of the camera. The platform's backend service has a user permission verification module. The platform only allows the issuance of control commands when the user has the encryption switching permission. In addition to the mode identifier, the control command also carries a public key identifier (KeyID) generated by the platform and an authentication signature. The camera performs signature verification upon receiving the command to prevent unauthorized commands from triggering encryption switching. Whether a user needs camera video encryption is determined by the user, including but not limited to situations where there is sensitive information at the camera's location. When a user switches whether the video stream is encrypted, all existing video requests stop. To view the video again, a new request can be made. If the platform has a recording service enabled, when it detects a video stream switch (…), it will automatically record the video stream. When an event occurs, the recording module triggers an automatic reconnection process via a callback interface and calls the decryption parameters corresponding to the most recent SessionID. This mechanism ensures continuous storage of video segments, preventing frame loss or segmentation due to encryption switching. There are no special requirements on unencrypted platforms.

[0042] As shown in Figures 1 and 2, the method for dynamically controllable video encoding described in this embodiment includes the following steps:

[0043] Step S1: Introduce a controllable encoding module at the video acquisition end, and combine it with an encryption control signal to control the real-time switching of the video stream.

[0044] In this embodiment, a camera or encoder with dual encoding capabilities is installed at the video acquisition end. The camera or encoder internally includes a main encoding module and a sub-encoding module. The main encoding module is used to perform encrypted video encoding tasks, and the sub-encoding module is used to perform unencrypted video encoding tasks. Both share an image acquisition unit, and the dynamic switching or parallel output of the encoding channels is realized through a control logic module.

[0045] For example, before implementing dynamic switching, video data is first written to a buffer. A dual-buffer synchronization mechanism, including a main buffer and a secondary buffer, is set up. When an encryption mode switching command is detected, the remaining frame data in the main buffer is automatically transferred to the secondary buffer for temporary storage, and the new video stream data is written to the main buffer. After the encryption or decryption switch is completed, the buffer scheduling module submits the data in the secondary buffer to the target storage terminal to ensure the continuity and integrity of the recorded data and avoid the loss of video segments due to switching delays.

[0046] Step S2: Using the encrypted video platform, issue encoding control commands, including unencrypted and encrypted encoding commands, through the network control interface.

[0047] In this embodiment, the encoding control command includes an encoding mode identifier field (unencrypted / encrypted), key negotiation parameters, and a switching timestamp identifier. After receiving the command, the camera or encoder determines the current encoding channel and strategy based on the identifier field and records the switching status in its internal register to ensure the timing consistency of the command execution. A centralized control plane and a distributed execution plane are constructed. The control plane is responsible for generating and issuing global encoding strategy control signaling, while the execution plane has signaling parsing and execution processing capabilities. Through a scheduled switching mechanism based on high-precision timestamps, it ensures that the encoding mode switching occurs at the GOP (Group of Pictures) boundary, avoiding video stream interruption and screen tearing, and achieving seamless dynamic switching of the encoding method.

[0048] For example, to improve storage compatibility across different encoding modes, this invention adopts a unified encapsulation format (e.g., MP4 or PS encapsulation) and appends a status field to the file header, including:

[0049] EncryptFlag: Indicates whether the current stream is encrypted;

[0050] SwitchFlag: Indicates whether it is a switching frame;

[0051] SessionID: Used for stream-level association and video stitching.

[0052] The backend storage system can automatically parse different stream types based on these fields, enabling unified management and seamless identification of encrypted and unencrypted streams.

[0053] Step S3: Adopt a layered coding strategy. After receiving an unencrypted coding instruction, adopt an IPB frame hybrid coding strategy. After receiving an encrypted coding instruction, adopt a more secure SVAC encrypted video coding strategy.

[0054] In this embodiment, the present invention adopts a layered coding strategy. In ordinary scenarios, it uses highly compatible H.264 / H.265 video encoding. After receiving unencrypted encoding instructions at the video acquisition end, it automatically loads H.264 / H.265 encoding parameters. First, scene-adaptive preprocessing is performed, including noise reduction and brightness equalization. Then, an IP / B frame hybrid coding strategy is adopted to dynamically adjust the I / P / B frame ratio and improve compression efficiency. Next, DCT / ICT transformation and adaptive quantization (QP 20-40) are performed to balance image quality and bitrate. In the entropy coding stage, H.264 uses CABAC, and H.265 introduces SAO offset compensation to improve compression performance. The bitstream is encapsulated in standard RTP / RTSP format and marked with an "unencrypted identifier (0x00)". Finally, through hardware acceleration and priority scheduling mechanisms, it ensures that single-frame encoding is ≤15ms and end-to-end latency is <200ms, meeting the requirements for smooth 1080P@30fps transmission in multiple scenarios, thereby achieving high compatibility and real-time performance.

[0055] In this embodiment, SVAC encrypted video encoding, which offers higher security, is used in confidential scenarios. Upon receiving the encryption encoding command, the front-end switches to the SVAC encoding process, achieving deep integration of encoding and encryption. Device identity is verified through SM2 bidirectional authentication, and a temporary session key is distributed using ZUC to ensure secure access. The device initializes SVAC2.0 encoding parameters and enables three-level encryption. During the acquisition phase, sensitive area (ROI) location and anti-tampering preprocessing are added, embedding metadata such as timestamps and device identifiers. Three layers of encryption are implemented during encoding: the first layer uses ZUC to encrypt the cryptographic stream header control information; the second layer selectively encrypts the high-frequency coefficients of I-frames and the high bits of motion vectors in P / B frames, updating the subkey every 10 frames; the third layer generates an SM3 digest of the metadata and encrypts it with an SM2 public key, forming a digital watermark. This is encapsulated as a dedicated SVAC stream, with the encryption identifier and algorithm type marked in the header. It is transmitted end-to-end via IPSec VPN, and the SM3 hash value is verified every 100 frames to ensure integrity. The decoding end, after identity authentication and stream integrity verification, decrypts and restores the video layer by layer, ensuring that only authorized terminals can access it, achieving end-to-end security protection.

[0056] Step S4: When the video does not need to be encrypted, the platform issues an instruction for unencrypted encoding.

[0057] In this embodiment, the unencrypted encoding process includes: the image acquisition module outputting raw frame data YUV; the unencrypted encoding module performing conventional intra / inter-frame prediction, transform, quantization, and entropy encoding operations on the input frame; and encapsulating the generated video stream according to the RTP / RTSP protocol and outputting it to either an encrypted or unencrypted video platform. Furthermore, to enhance flexibility, an encrypted encoding channel can optionally be activated simultaneously in unencrypted mode: the main encoding module performs SVAC encryption encoding, and the secondary encoding module performs H.264 / H.265 encoding; after encoding, the streams are pushed to both the encrypted and unencrypted video platforms respectively, achieving simultaneous dual-stream output and avoiding delays from secondary acquisition and transcoding.

[0058] Step S5: When the video needs to be encrypted, the platform issues an encryption encoding method instruction, and the camera or encoder switches to encryption mode.

[0059] In this embodiment, the encryption encoding process includes: the encoder generating a session key according to instructions. The system inserts an encrypted header into the first frame of each Group of Pictures (GOP); performs symmetric encryption algorithms (such as ZUC or SM4-CBC mode) on keyframe (I-frame) data; and encrypts only motion vectors and part of the macroblock header information for predicted frames (P / B frames) to reduce processing latency. The encrypted video frames are then repackaged into an SVAC stream and output to the encrypted video platform. Still frame generation and push process: When encryption mode is activated, the system retrieves the last frame image from the cache and overlays the text message "Video has been encrypted." Simultaneously, a status flag field, including the session ID and encryption status flag (EncryptFlag=1), is written into the frame's metadata. The encoder encodes the still frame as a JPEG or I-frame and pushes it to the unencrypted video platform through the unencrypted output channel. This ensures the unencrypted platform can continuously receive parseable frames, avoiding stream interruptions or recording loss due to encryption switching.

[0060] In this embodiment, when encryption is enabled, video data is processed by the encryption algorithm and output only to the encrypted platform, while transmission to unencrypted platforms is automatically stopped, ensuring the security of video data in confidential scenarios. To prevent playback issues caused by GOP (Group of Pictures) interruption or missing non-keyframes during encryption mode switching, this invention designs an automatic keyframe generation and insertion mechanism, the implementation process of which is as follows:

[0061] a. Define and detect the handover moment, and monitor the conditions used for redundancy confirmation handover moment.

[0062] In this embodiment, the system identifies the moment of encryption mode switching by detecting changes in the EncryptFlag flag. When the camera or encoder detects a change in the EncryptFlag flag... (Enter encrypted mode) or When exiting encrypted mode, the system defines this moment as the switching trigger point. In addition, the following conditions are monitored to confirm the moment of redundancy switching: the mode field (StreamMode) in the control signaling changes; the frame sequence number in the buffer queue is discontinuous or the timestamp is reset; the encoding parameters (such as the stream identifier and encryption flag) are updated.

[0063] b. Trigger the automatic keyframe generation process based on monitoring conditions.

[0064] In this embodiment, when any two monitored conditions are met simultaneously, the "keyframe generation process" is triggered, and the keyframe generation module... Perform the following steps at all times:

[0065] Terminate the current GOP queue: Stop encoding the current P-frame and B-frame, and clear any unsubmitted prediction data;

[0066] Acquire the latest image frame: Extract the most recent complete raw frame data from the camera buffer;

[0067] Force encoding as an I-frame: Re-encode the frame as an I-frame (keyframe) with the current encoding parameters, and insert the switch flag field SwitchFlag=1 into the frame header;

[0068] Synchronize timestamps and session information: Assign a new timestamp (Timestamp_) to newly generated I-frames. Include the SessionID so the backend can identify the switching point; push to the new stream channel: encapsulate and send this keyframe as the first frame of the new video stream, and start a new GOP structure.

[0069] c. Ensure the continuity of video recordings.

[0070] In this embodiment, the video recording storage module determines whether the SwitchFlag=1 flag exists based on the video frame header information: if the keyframe switching flag is detected, the current recording file is automatically closed and a new file index is generated; the start time of the new recording file is determined by Timestamp_ This definition ensures a continuous timeline for the video files; the playback device can stitch together two recording segments based on the SessionID order, achieving seamless video transitions and complete playback. This mechanism guarantees that even with frequent switching between encrypted and unencrypted modes, the recorded files maintain logical continuity and can be played smoothly.

[0071] For example, when the video no longer needs encryption, the platform issues a switching command, the camera or encoder disables the encryption logic of the main encoding module, re-enables the unencrypted encoding channel of the secondary encoding module, and repeats step S3. The system automatically inserts keyframes during the switching to maintain the continuity of the video stream sequence.

[0072] For example, when a switching failure, cache conflict, or keyframe generation anomaly is detected, the system automatically records the current error state and timestamp, rolls back to the last successfully submitted keyframe position, regenerates and inserts a new I-frame, rebuilds the GOP structure, re-establishes the transmission channel, and restores video stream synchronization. This mechanism enables automatic repair and data backtracking of recorded segments in abnormal situations, ensuring the integrity and reliability of video files.

[0073] Step S6: On the encrypted video platform client, the corresponding session key is obtained from the key management module based on the session identifier (SessionID) in the video frame header. The received encrypted video stream is then decrypted and played. The decryption end adopts a frame-level decryption strategy, performing full decryption only on key frames. Predicted frames are reconstructed by referencing decrypted frames to improve playback real-time performance and reduce CPU load.

[0074] This invention effectively solves the problem of encrypted and shared video applications. This method can meet the video application needs of different application scenarios in the same area. By introducing a controllable encoding module at the video acquisition end, combined with encryption control signals, real-time switching control of the video stream is achieved. When encryption is enabled, video data, after being processed by the encryption algorithm, is only output to the encrypted platform, while transmission to the unencrypted platform is automatically stopped, ensuring the security of video data in confidential scenarios. When encryption is disabled, video data is output to both the encrypted and unencrypted platforms simultaneously, meeting the sharing needs in public scenarios. Furthermore, through a robust cache protection and storage compatibility mechanism, the defects of video data loss and insufficient device compatibility present in traditional solutions are effectively avoided, thereby further improving the security, reliability, and application scope of the video surveillance system. This method and equipment can effectively resolve the contradiction between video confidentiality and video sharing, while saving construction costs and reducing investment in redundant equipment deployment.

[0075] It should be noted that, in this invention, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus.

[0076] Finally, it should be noted that the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A device for dynamically controllable video encoding, characterized in that: It includes a video acquisition terminal, an encrypted video platform, an unencrypted video platform, a control channel, a user permission verification module, and a recording module; the video acquisition terminal includes a camera or encoder with dual encoding capabilities, used to control the switching of encoding methods for the video stream; the camera or encoder includes a main encoding module and a sub-encoding module; The main encoding module is used to perform encrypted video encoding tasks; the secondary encoding module is used to perform unencrypted video encoding tasks; the encrypted video platform is used to issue encoding control commands through the network control interface; the unencrypted video platform is used to execute commands for unencrypted encoding of the video stream; the control channel is used to manage the encryption and unencrypted modes of the video stream, including protocol channel 1 and protocol channel 2; protocol channel 1 is used to send the video stream and encryption parameters to the encrypted video platform. Protocol channel 2 is used to send video streams to an unencrypted video platform; The user permission verification module is used to verify the user permissions of the user issuing control commands; the recording module is used to trigger an automatic reconnection process through a callback interface and call decryption parameters; the control channel is also used to: define level A as unencrypted video stream and level C as encrypted video stream; when protocol channel 1 controls the video acquisition terminal to work in level A stream, it enters unencrypted mode; in unencrypted mode, the encryption module inside the video acquisition terminal is in standby mode and does not perform encryption key negotiation or key stream generation; the video stream can be... The event switching between protocols includes: Protocol Channel 1 controlling the video capture terminal to switch to a Class C stream, and Protocol Channel 1 switching back from a Class C stream to a Class A stream. When Protocol Channel 1 controls the video capture terminal to switch to a Class C stream, the following steps are executed: Step a1: When Protocol Channel 1 controls the video capture terminal to switch to a Class C stream, stream interruption protection is implemented, immediately stopping the video stream transmission of Protocol Channel 1 and closing the unencrypted stream buffer; Step a2: An encrypted session key is generated. The security module inside the video capture terminal generates a temporary encryption key, using a timestamp, device ID, and channel number as the random source; Step a3: Key encryption and transmission are performed. Step a4: The encrypted video platform encrypts the video stream. The video acquisition terminal calls the ZUC encryption algorithm on the encoded output frame data, generates a key stream with the session key and initialization vector, performs an XOR operation on each frame data and re-encapsulates it. Step a5: After the encrypted video platform confirms receipt of the key, it re-establishes the encrypted video connection of protocol channel 1 and restores the video stream. Step a6: Protocol channel 2 generates a static prompt frame, which displays "The video has been encrypted", and pushes an unencrypted prompt frame.

2. The apparatus for dynamically controllable video encoding according to claim 1, characterized in that: When protocol channel 1 switches from C-level stream back to A-level stream, it exits the encryption mode and performs the following steps: Step b1: The camera clears the current session key and resets the encryption status flag to 0; Step b2: The unencrypted video channel is re-established, and the video stream output of different encoding methods is restored. Step b3: Protocol channel 2 automatically stops sending static notification frames and resumes real-time video transmission.

3. A method for dynamically controllable video coding, applied to the apparatus for dynamically controllable video coding as described in claims 1-2, characterized in that: The operation includes the following steps: Step S1: Introduce a controllable encoding module at the video acquisition end, and control the real-time switching of the video stream in conjunction with the encryption control signal; Step S2: Utilize the encrypted video platform to issue encoding control commands, including unencrypted encoding commands and encrypted encoding commands, through the network control interface; Step S3: Adopt a layered encoding strategy, using H.264 / H.265 video encoding in ordinary scenarios and SVAC encrypted video encoding in confidential scenarios; Step S4: When the video does not need encryption, the platform issues an unencrypted encoding command; Step S5: When the video needs encryption, the platform issues an encrypted encoding command, and the video acquisition terminal switches to encrypted mode; Step S6: On the encrypted video platform client, obtain the corresponding session key from the key management module based on the session identifier in the video frame header, decrypt and play the received encrypted video stream. The decryption end adopts a frame-level decryption strategy, performing complete decryption only on key frames, and reconstructing predicted frames by referencing decrypted frames.

4. The method for dynamically controllable video coding according to claim 3, characterized in that: In common scenarios, H.264 / H.265 video encoding includes: automatically loading H.264 / H.265 encoding parameters after receiving unencrypted encoding instructions at the video acquisition end, and performing scene-adaptive preprocessing including noise reduction and brightness equalization; adopting an IPB frame hybrid encoding strategy to dynamically adjust the I / P / B frame ratio; performing DCT / ICT transformation and adaptive quantization; in the entropy encoding stage, H.264 uses CABAC, and H.265 introduces SAO offset compensation; the bitstream is encapsulated in standard RTP / RTSP format and marked with an "unencrypted identifier"; and ensuring transmission requirements in multiple scenarios through hardware acceleration and priority scheduling mechanisms.

5. The method for dynamically controllable video coding according to claim 4, characterized in that: In classified scenarios, SVAC encrypted video encoding includes: upon receiving the encryption encoding instruction, the front end switches to the SVAC encoding process to integrate encoding and encryption; SM2 two-way authentication of device identity is performed, and a temporary session key is distributed using ZUC; SVAC2.0 encoding parameters are initialized, and three-level encryption is enabled; during the acquisition phase, sensitive area positioning and anti-tampering preprocessing are added, and metadata such as timestamps and device identifiers are embedded; during the encoding process, three layers of encryption are implemented: the first layer uses the ZUC encryption algorithm to add control information to the cryptographic stream header; the second layer selectively encrypts the high-frequency coefficients of I-frames and the high bits of motion vectors in P / B frames, updating the subkey every 10 frames; the third layer generates an SM3 digest of the metadata and encrypts it with the SM2 public key to form a digital watermark; it is encapsulated into an SVAC dedicated bitstream, with the encryption identifier and algorithm type marked in the header, transmitted end-to-end via IPSec VPN, and the SM3 hash value is verified every 100 frames; after identity authentication and bitstream integrity verification, the decoding end decrypts and restores the video layer by layer.

6. The method for dynamically controllable video coding according to claim 5, characterized in that: In step S4, the platform issues an instruction for unencrypted encoding, including: the image acquisition module outputs raw frame data; the unencrypted encoding module performs conventional intra / inter-frame prediction, transformation, quantization, and entropy encoding operations on the input frame; the generated video stream is encapsulated according to the RTP / RTSP protocol and output to either the encrypted or unencrypted video platform; in unencrypted mode, the encrypted encoding channel is simultaneously activated: the main encoding module performs SVAC encryption encoding, and the secondary encoding module performs H.264 / H.265 encoding; after encoding is completed, the streams are pushed to both the encrypted and unencrypted video platforms to achieve synchronous dual-stream output.

7. The method for dynamically controllable video coding according to claim 6, characterized in that: In step S5, the platform issues an encryption encoding method instruction, which includes: the encoder generating a session key according to the instruction and inserting an encryption identifier header into the first frame of each GOP; performing a symmetric encryption algorithm on the keyframe data; encrypting only the motion vector and part of the macroblock header information for the prediction frame; re-encapsulating the encrypted video frame into an SVAC stream and outputting it to the encrypted video platform; when the encryption mode is activated, calling the last frame image in the cache and overlaying the text message "The video has been encrypted"; at the same time, writing a status flag field, including the session identifier and encryption status flag, into the metadata of the frame; the encoder encoding the frame in JPEG or I-frame format and pushing it to the unencrypted video platform through the unencrypted output channel.

8. The method for dynamically controllable video coding according to claim 7, characterized in that: In step S5, an automatic keyframe generation and insertion mechanism is also introduced, and the process is as follows: a. Define and detect the switching moment, and monitor the conditions used to confirm the switching moment for redundancy; b. Trigger the automatic keyframe generation process according to the monitored conditions; c. Ensure the continuity of the video file.

Citation Information

Patent Citations

  • Camera advanced security method and system based on security chip

    CN116318880A

  • Video transmission method and device for grain depot local area network, and medium

    CN120711242A