Method for transmitting and receiving an image representing at least one object, electronic transmitting and receiving devices and associated computer program products

The described system securely transmits images by obfuscating and encrypting specific areas, allowing only authorized users to decipher and reconstruct the content, thus addressing the challenges of complex and costly secure communication methods while ensuring optimal confidentiality.

FR3144470B1Active Publication Date: 2025-05-09THALES SA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2022014422
Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-12-23
Publication Date
2025-05-09
Estimated Expiration
2042-12-23

AI Technical Summary

Technical Problem

Current secure communication methods for video surveillance are complex and costly, and existing techniques for ensuring confidentiality of personal data in images, such as total blurring followed by decryption, do not optimally protect data when only authorized users should access specific content.

Method used

A process and system for securely transmitting images by applying obfuscation to specific areas of the image and encrypting pixel values, allowing only authorized users to decipher and reconstruct specific parts of the image using individual secret keys calculated from a correspondence table.

Benefits of technology

This approach effectively protects personal data in images during transmission by ensuring that only authorized users can access specific content, while maintaining simplicity and reducing costs compared to traditional secure communication methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000030_0000
    Figure 00000030_0000
  • Figure 00000031_0000
    Figure 00000031_0000
  • Figure 00000032_0000
    Figure 00000032_0000
Patent Text Reader

Abstract

Methods for transmitting and receiving an image representing at least one object, electronic transmitting and receiving devices, and associated computer program products. The present invention relates to a method for transmitting, from a transmitting device (20), and a method for receiving, by a receiving device (25), an image with obfuscated area(s). The transmitting method comprises applying obfuscation to identified areas of an acquired image and generating an encrypted message comprising the encrypted pixel values ​​of the identified areas in the resulting image. The transmitting method also comprises sending an individual secret key and transmitting the image with obfuscated area(s) to the receiving device.The reception process includes receiving the image with obfuscated area(s), the encrypted message, and the individual secret key. The reception process also includes partially decrypting the encrypted message and reconstructing a partially reconstructed image from the decrypted message and the received image. See Figure 1 for an abbreviation.
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Methods for transmitting and receiving an image representing at least one object, electronic transmitting and receiving devices and associated computer program products

[0001] The present invention relates to a method for transmitting an image representing at least one object. The present invention also relates to a computer program product suitable for implementing such a transmission method and an electronic device for transmitting an image representing at least one object.

[0002] The present invention also relates to a method for receiving an image. The present invention also relates to a computer program product capable of implementing such a reception method and an electronic device for receiving an image representing at least one object.

[0003] The present invention relates more specifically to the field of encryption and decryption of information contained in an image.

[0004] Public interest in the confidentiality of transmitted information has recently grown significantly, particularly with regard to the protection of personal data relating to individuals.

[0005] For example, within the European Union, the General Data Protection Regulation (GDPR) illustrates this growing interest.

[0006] This regulation imposes in particular confidentiality as a design standard for personal data communication devices.

[0007] Thus, when transmitting information, it is now recommended that only users authorized to consult the information transmitted are able to access said information.

[0008] In the context of video surveillance, it is known to transfer images through secure communication channels. However, such communication is complex to implement. In addition, such communication involves high costs because communication means over secure channels require specific infrastructures.

[0009] Alternatively, it is known to apply total blurring to the images, to transmit them in this state, and to communicate only to a chosen recipient, a key allowing the image to be completely unblurred.

[0010] However, this all-or-nothing technique only ensures the confidentiality of personal data when the recipient is authorized to consult the entire content of the images. Thus, the confidentiality of personal data is not optimal.

[0011] The present invention aims to ensure, in a simple manner, the confidentiality of personal data present in an image during their communication.

[0012] To this end, the present invention relates to a method of transmitting, from an electronic transmitting device and to at least one electronic receiving device, an image representing at least one object,

[0013] the transmission method being implemented by the electronic transmission device and comprising a configuration phase comprising the following step: - sending to the or each receiving electronic device a respective individual secret key,

[0014] the method further comprising an encryption phase comprising the following steps: - obtaining the image representing the at least one object, in which one or more zones comprising certain pixels of the image are identified, each identified zone representing the or one of the objects, - applying an obfuscation to the or each area of ​​the image, to form an image with obfuscated area(s), - generation of an encrypted message comprising values ​​of the pixels of the areas in the obtained image, in which said values ​​are encrypted, - transmission, to the or each electronic receiving device, of the image with obfuscated zone(s) and of the encrypted message with a view to its at least partial decryption, by each electronic receiving device to reconstitute a partially reconstituted image associated with the electronic receiving device,

[0015] in which each individual secret key is calculated from a correspondence table, the correspondence table associating with each electronic receiving device, a respective list of object(s) that said electronic receiving device is authorized to consult by decrypting the encrypted message, from said individual secret key.

[0016] With the transmission method according to the invention, it is possible to transmit an image which protects personal data, while being partially decipherable for a user authorized to consult part of its content.

[0017] This effect is obtained in particular by obfuscating the identified zone(s), as well as by the individual secret key capable of only allowing decryption of certain pixel values, i.e. of certain zone(s).

[0018] According to particular embodiments of the invention, the transmission method comprises one or more of the following characteristics, taken in isolation or in all technically possible combinations: - the obtaining step includes the following sub-steps: • image acquisition, and • identification in the acquired image of the zone(s) representing the or each object from an identification model,

[0019] the identification step being preferentially implemented by an identification model more preferentially comprising a neural network; - the configuration phase also includes the following steps prior to the sending step: • acquisition of the correspondence table, • determination of a master public key and a master secret key, • calculation, for each electronic receiving device, of the respective individual secret key from the master secret key and the list of object(s) associated with said electronic receiving device in the correspondence table,

[0020] during the generation step, the values ​​of the pixels being encrypted from the master public key,

[0021] the master public key and the individual secret keys preferably being distinct, the individual secret keys preferably still being distinct from each other; - the generation step includes the following sub-steps: • storage, in a message, of the values ​​of the pixels corresponding to the zone(s) identified in the image, • application of an encryption algorithm to the values ​​of the pixels of the message from the master public key, to form the encrypted message,

[0022] the encryption algorithm preferably being chosen from the group consisting of: • algorithm B SW07, • the CPW08 algorithm, and • the AC 17 algorithm; and • the image obtained comes from a camera chosen from a predefined list of cameras, the correspondence table associating, with each electronic reception device, for each object, one or more cameras capable of capturing images for which said electronic reception device is authorized to consult said object,

[0023] the or each individual secret key further being a function of the camera(s) associated with the corresponding electronic receiving device in the correspondence table.

[0024] The present invention also relates to a computer program product comprising software instructions, which when executed, implement a reception method as described above.

[0025] The present invention also relates to an electronic device for transmitting, to at least one electronic receiving device, an image representing at least one object from a predefined list of object(s), the electronic transmitting device comprising a configuration unit comprising: - a sending module configured to send to the or each receiving electronic device a respective individual secret key,

[0026] the sending electronic device further comprising an encryption unit comprising: - an obtaining module configured to obtain the image representing the at least one object, in which one or more zones comprising certain pixels of the image are identified, each identified zone representing the or one of the objects, - an application module configured to apply masking to the or each area of ​​the image, to form an image with obfuscated area(s), - a generation module configured to generate an encrypted message comprising values ​​of the pixels of the areas in the obtained image, in which said values ​​are encrypted, - a transmission module configured to transmit, to each electronic reception device, the image with obfuscated zone(s) and the encrypted message with a view to its at least partial decryption, by each electronic reception device to reconstitute a partially reconstituted image associated with the respective electronic reception device,

[0027] in which each individual secret key is calculated from a correspondence table, the correspondence table associating with each electronic reception device, a respective list of object(s) that said electronic reception device is authorized to consult by decrypting the encrypted message, from said individual secret key.

[0028] The present invention also relates to a method of receiving, by an electronic receiving device and from an electronic transmitting device, an image with at least one obfuscated zone capable of representing an object from a predefined list of object(s),

[0029]

[0030]

[0031]

[0032]

[0033]

[0034]

[0035]

[0036]

[0037] the method being implemented by the electronic receiving device and comprising the following steps: - reception of the image with obfuscated zone(s), of an encrypted message comprising encrypted pixel values, and of an individual secret key associated with the electronic receiving device, the individual secret key being capable of decrypting only the encrypted pixel values ​​corresponding to one or more areas of the image with obfuscated area(s) representing objects that the receiving electronic device is authorized to consult, - decryption, using a decryption algorithm and the received individual secret key, of the encrypted pixel values ​​of the encrypted message to obtain a partially decrypted message, and - reconstruction of a partially reconstructed image, by replacing the obfuscated area(s) of the image with obfuscated area(s) with pixels whose values ​​are included in the partially deciphered message, at least one area of ​​the partially reconstructed image representing an object that the receiving electronic device is authorized to consult. With the reception method according to the invention, it is possible to decrypt only a part of an image for which only certain objects are authorized to be consulted. This effect is achieved in particular by the individual secret key which allows only part of the encrypted message to be decrypted. Thus, the partially reconstructed image preserves the confidentiality of objects that the receiving device is not authorized to consult. The present invention also relates to a computer program product comprising software instructions, which when executed by a computer, implement a reception method as described above. The present invention also relates to an electronic device for receiving, from an electronic transmission device, an image with at least one obfuscated zone capable of representing an object, the electronic receiving device comprising: - a reception module configured to receive the image with obfuscated zone(s), an encrypted message comprising encrypted pixel values, and an individual secret key (Is) associated with said electronic reception device, the individual secret key being suitable for decrypting only the encrypted pixel values ​​corresponding to one or more areas of the image with obfuscated area(s) representing objects that the receiving electronic device is authorized to consult, - a decryption module configured to decrypt, from a decryption algorithm and the received individual secret key (Is), the encrypted pixel values ​​of the encrypted message to obtain a partially decrypted message, and - a reconstruction module configured to reconstruct a partially reconstructed image, by replacing the obfuscated area(s) of the image with obfuscated area(s) with pixels whose values ​​are included in the partially decrypted message,

[0038] at least one area of ​​the partially reconstructed image representing an object that the electronic receiving device is authorized to consult.

[0039] The present invention also relates to an electronic communication system comprising an electronic transmission device and at least one electronic reception device,

[0040] wherein the transmitting electronic device is defined above and each receiving electronic device is also defined above.

[0041] The communication system makes it possible to improve, in a simple manner, the confidentiality of personal data.

[0042] These characteristics and advantages of the invention will appear on reading the description which follows, given solely by way of non-limiting example, and made with reference to the appended drawings, in which: - [Fig.l] [Fig.l] is a schematic representation of a communication system according to the invention comprising an electronic transmission device and at least one electronic reception device according to the invention; - [Fig.2] [Fig.2] is an example of an image acquired by the electronic transmission device of [Fig.l]; - [Fig.3] [Fig.3] is an example of an image with obfuscated area(s) emitted by the electronic transmitting device of [Fig.l], intended for the electronic receiving device(s) of [Fig.l]; - [Fig.4] [Fig.4] is an example of a partially reconstructed image obtained by the or one of the electronic receiving devices of [Fig.l]; - [Fig.5] [Fig.5] is a flowchart of a transmission method according to the invention, implemented by the electronic transmission device of [Fig.l]; and - [Fig.6] [Fig.6] is a flowchart of a reception method according to the invention, implemented by each electronic reception device of [Fig.1].

[0043] With reference to [Fig.l], an electronic communication system 10 is described. The electronic communication system 10 is suitable for being connected to a camera 15.

[0044] The communication system 10 comprises an electronic transmission device 20 and at least one electronic reception device 25. In the example of [Fig.l], the communication system 10 comprises several reception devices 25.

[0045] The camera 15 is for example a video surveillance camera in a city street. The camera 15 is capable of capturing images 37 of an environment. On the images captured 37 by the camera 15, several objects of interest, also called objects, are for example visible. The objects of interest include for example silhouettes of passers-by in the street, faces of said passers-by, and vehicles.

[0046] Thus, each image captured 37 by the camera 15 represents at least one of said objects.

[0047] The camera 15 is for example connected to the transmission device 20 and capable of sending it the captured images 37.

[0048] The transmission device 20 comprises a configuration unit 30 and an encryption unit 35.

[0049] The configuration unit 30 comprises a module 40 for sending individual secret key(s) Is to each receiving device 25. Preferably, the configuration unit 30 further comprises a module 42 for acquiring a correspondence table, a module 44 for determining a master public key Mp and a master secret key Ms, and a module 46 for calculating the individual secret key(s) Is.

[0050] The encryption unit 35 comprises a module 50 for obtaining at least one respective image 37 from the camera 15, a module 52 for applying an obfuscation to parts of the image which will be detailed below, a module 54 for generating an encrypted message and a module 56 for transmitting, to each reception device 25, elements from the application 52 and generation 54 modules.

[0051] Each reception device 25 comprises a reception module 60, a module 62 for decrypting the encrypted message and a module 64 for reconstructing an image.

[0052] Each receiving device 25 is associated with a user. In the example shown in [Fig. 1], the communication system 10 comprises a first 25A, a second 25B and a third 25C receiving device. The first receiving device 25A is for example associated with a security guard monitoring an entrance to a parking lot. The second receiving device 25B is for example associated with a service police. The third reception device 25 is for example associated with an investigating judge. In this example, the security guard is only authorized to consult the “vehicle” objects in the images 37. The police service is only authorized to consult the “silhouette” objects in the images 37. Finally, the investigating judge is authorized to consult all the objects, i.e. the vehicles, the silhouettes and the faces, in the image 37.

[0053] Preferably, each reception device 25 further comprises a respective display screen 67.

[0054] The sending module 40 is configured to send, to each receiving device 25, the individual secret key Is which is specific to it. For this purpose, the sending module 40 is configured to send this key Is through a secure channel, for example of the TLS type, such as an HTTPS channel which is encrypted and authenticated.

[0055] Each individual secret key Is is for example stored in the configuration unit 30. Each individual secret key Is is respective of a reception device 25. In the case where the communication system 10 comprises several reception devices 25, the individual secret keys Is are distinct from each other.

[0056] Each individual secret key Is is capable of allowing decryption of the encrypted message to reveal the objects that the user of the receiving device 25 to which said key Is is sent is authorized to consult.

[0057] In the example previously described, the sending module 40 is configured to send a first Isb, a second Is2, and a third Is3 individual secret keys.

[0058] In particular, the sending module 40 is configured to send: - to the first receiving device 25A, the first individual secret key L i, which is suitable for decrypting objects representing vehicles, - to the second receiving device 25B, the second individual secret key Is 2, which is suitable for deciphering objects representing silhouettes, and - to the third receiving device 25C, a third individual secret key Is 3, which is suitable for deciphering all objects, i.e. vehicles, silhouettes and faces.

[0059] Optionally, the acquisition module 42 is configured to acquire the correspondence table. The correspondence table associates, with each receiving device 25, a respective list of object(s) that said receiving device 25 is authorized to consult by decrypting the encrypted message using the respective individual secret key Is. In the above-mentioned example, the correspondence table associates: - to the first receiving device 25A, the “vehicle” object; - to the second receiving device 25B, the “silhouette” object; and - at the third receiving device 25C, the objects “vehicle”, “silhouette”, and “face”.

[0060] The determination module 44 is configured to determine the master public key Mp and the master secret key Ms. In a manner known per se, the master public key Mp is configured to encrypt data which can be deciphered using the master secret key Ms.

[0061] The master public key Mp and the master secret key Ms are preferably distinct from each other. Thus, the master public key Mp is intended to be consultable by anyone wishing to encrypt data. The master secret key Ms is, for its part, kept secret, i.e. confidential, by the configuration unit 30. The master secret key Ms is preferably not communicated to any other electronic device.

[0062] The master public key Mp and master secret key Ms are for example determined randomly.

[0063] The calculation module 46 is configured to calculate, for each electronic reception device 25, the respective individual secret key Is, for example from the master secret key Mset of the list of object(s) associated with the electronic reception device 25 in the correspondence table.

[0064] The calculation module 46 is for example configured to apply a key generation function of an attribute-based encryption algorithm, also called an ABE algorithm (from the English Attribute-Based Encryption) known per se, in which each attribute is an object. Thus, the calculation module 46 is configured to calculate an individual secret key Is for each receiving device 25 from the objects that said receiving device 25 is authorized to consult in the correspondence table.

[0065] The calculation of each individual secret key Is depends on the type of ABE algorithm used. Preferably, the ABE algorithm is chosen from the following algorithms: - BSW07 described in the article Ciphertext-Policy Attribute-Based Encryption by Bethencourt et al, - CPW08 described in the article Ciphertext-Policy Attribute-Based Encryption: An Expressive, Efficient, and Provably Secure Realization by Waters et al, and - AC17 described in the article FAME: Fast Attribute-based Message Encryption by Agrawal et al.

[0066] Thus, the calculation module 46 is configured to calculate the individual secret key(s) Is, such that each individual secret key Is only allows the decryption of the object(s) associated with the corresponding reception device 25 in the correspondence table.

[0067] "Decrypting an object" means decrypting encrypted pixel values ​​associated with the object, as will be described below.

[0068] The obtaining module 50 is configured to obtain the image 37 representing at least one object, in which one or more zones 70 are identified as representing the object or one of the objects. Each zone 70 comprises certain pixels of the image 37.

[0069] The expression “certain pixels of the image” is understood to mean that only a portion of the pixels of the image are included in each zone 70.

[0070] In a manner known per se, each image is composed of a plurality of elements, for example pixels. Each pixel is defined by its spatial position in the image and by a tuple of values. Each value is called a spectral channel or band.

[0071] For example, the image is a so-called RGB image, in which the n-tuple of values ​​is a triplet of values ​​corresponding to the colors red, green and blue. Each value of the triplet of values ​​is for example between 0 and 255. The higher the value associated with a color, the darker the pixel has a shade of said color. Alternatively, when the image 37 is in grayscale, each pixel is then associated with a single value corresponding to a grayscale. In this case, a maximum value (for example 255) corresponds to a white pixel, while a minimum value (for example equal to 0) corresponds to a black pixel, or vice versa.

[0072] According to one embodiment, the obtaining module 50 is configured to acquire, from the camera 15, the image 37 captured by said camera 15.

[0073] [Fig.2] represents such an image 37. It is notably visible in [Fig.2] that five vehicles, five silhouettes and two faces are identified.

[0074] The obtaining module 50 is further configured to identify, in the acquired image 37, the zone(s) 70 representing the or each object, from an identification model. The identification model comprises for example a neural network, preferably a neural network trained to detect the zone(s) 70 corresponding to each type of object in the image 37 and to classify each detected zone among a plurality of classes each corresponding to an object. Each of these zones being subsequently called identified zone 70. In a manner known per se, the neural network comprises a plurality of artificial neurons organized into layers. The neural network then comprises an input layer, one or more hidden or intermediate layers, and an output layer. The neurons of two successive layers are connected to each other by a link comprising an adjustable weight, also called synaptic weight.

[0075] Preferably, the obtaining module 50 is configured to detect a portion of the acquired image 37, occupied by each object and to assign it membership in a specific class among the objects of the correspondence table.

[0076] Preferably, this detection comprises the definition, by the trained neural network, of a rectangular bounding box around the object. Each bounding box then forms a respective identified zone 70.

[0077] According to a variant not shown, the obtaining module 50 is configured to segment the object more finely in the acquired image 37 by producing masks on these objects, i.e. to assign a designation to each pixel of the image. Thus, each identified zone 70 is formed by all the pixels of the image comprising the same designation. It is then understood that the shape of the identified zones 70 according to this variant is not necessarily rectangular.

[0078] The application module 52 is configured to apply an obfuscation to the or each identified zone 70, to form an image with obfuscated zone(s) 75.

[0079] “Obfuscation” means a modification of the value(s) of a set of pixels to camouflage an object represented in the pixels.

[0080] According to an example shown in [Fig. 3], the obfuscation is a blurring. The application module 52 is for example configured to divide each identified zone 70 into group(s) of several pixels and to calculate, for each group, an average value of the values ​​of the pixels in the group. The application module 52 is then configured to replace each pixel in each group with a pixel having the calculated average value. If each pixel comprises a triplet of values, said average value is the average of each value in the triplet. Alternatively, the blurring comprises applying a blurring filter to the identified zones 70, such as a Gaussian filter.

[0081] Alternatively, the obfuscation is a masking comprising the replacement of each identified zone 70 by a shape whose pixels have a predefined color, preferably a monochrome shape, consisting for example of black pixels.

[0082] The application module 52 is configured to obtain an image with obfuscated zone(s) 75 in which the or each identified zone 70 is modified by the application of the obfuscation and in which the parts of the image not corresponding to an identified zone 70 are not impacted by the obfuscation.

[0083] The generation module 54 is configured to generate an encrypted message, also called a secure message, comprising the values ​​of the pixels of each identified zone 70 in the image obtained 37 by the obtaining module 50. The values ​​of the pixels present in the encrypted message are encrypted. For this, the generation module 54 is for example configured to store, in a message, the values ​​of the pixels corresponding to the identified zone(s) 70 in the obtained image 37. The message is for example a database.

[0084] In particular, the generation module 54 is configured so that the message comprises, for each identified zone 70, several data fields. For each identified area 70, a first data field comprises the position of said area 70 in the image 37. For each identified area 70, a second data field comprises the values ​​of the pixels of said area 70. The first and second data fields are for example ordered so that the message comprises, for each identified area 70, the first data field relating to the identified area 70, then the second data field relating to said identified area 70.

[0085] Preferably, the message further comprises, for each identified zone 70, a third data field comprising a first character string indicating the object represented in said zone 70. For example, for each identified zone 70, the third data field is located, in the message, between the first and second data fields.

[0086] In the example previously described, the message comprises the first data field comprising the position of a zone 70 in the image 37, then the third data field comprising a first respective character string “face”, then the second data field comprising the values ​​of the pixels ordered in a predefined manner, corresponding to the zone 70 representing a face in the image 37.

[0087] The generation module 54 is further configured to apply an encryption algorithm to the values ​​of the pixels of the message, from the master public key Mp, to form the encrypted message. The encrypted pixel values ​​in the encrypted message, associated with each identified zone 70 form “a ciphertext”. Thus, it is understood that the encrypted, or secure, message comprises a ciphertext for each identified zone 70.

[0088] In particular, the generation module 54 is for example configured to apply the encryption algorithm only to the content of the second data field in the message. In other words, the content of the first data field, and optionally the content of the third data field, are not encrypted by the encryption algorithm. More specifically, the generation module 54 is for example configured to encrypt the values ​​of the pixels in the following manner.

[0089] The determination module 54 is configured to apply an encryption algorithm to each set of pixel values ​​based on the master public key Mp and possibly an encryption policy. The encryption algorithm depends on the ABE algorithm applied such as the BSW07, the CPW08, or the AC 17 described previously.

[0090] The encryption policy associates with each identified zone 70 a logical relationship depending on the object(s) represented in the identified zone 70, and for example context element(s), from the correspondence table.

[0091] Each logical relation is typically formulable, according to Boolean algebra, by a logical equation comprising at least one operand and possibly one or more operators. Each operand is an object of the correspondence table and / or a context element. Each operator is preferably chosen from the following operators: “AND” and “OR”.

[0092] Thus, for example, in the case of superposition of two objects in the image 37, an identified zone 70 partially encompasses another identified zone, the policy includes a logical relationship associated with the partially encompassed zone of the type “first object AND second object” or of the type “first object OR second object”;

[0093] When the logical relationship is of the type “first object AND second object”, the pixels of said partially enclosed area 70 are encrypted so that only a receiving device 25 having an individual secret key corresponding to the first object and the second object can decrypt these pixels.

[0094] When the logical relationship is of the type “first object OR second object”, the pixels of said partially enclosed area are encrypted so that only a receiving device 25 having an individual secret key corresponding to the first object or the second object can decrypt these pixels.

[0095] It is understood that the third data field comprises the logical relationship associated with the corresponding identified zone 70, in the encryption policy.

[0096] The transmission module 56 is configured to transmit, to each reception device 25, the image with obfuscated zone(s) 75 and the encrypted message. Preferably, the encrypted message is included in metadata of the image with obfuscated zone(s) 75 transmitted.

[0097] It is then understood that a third party intercepting the image with obfuscated zone(s) 75 and the encrypted message transmitted by the transmission module 56, is not able to consult the objects of the identified zones 70 in the acquired image 37, i.e. the objects whose pixel values ​​have been encrypted in the encrypted message.

[0098] Furthermore, the image with obfuscated zone(s) 75 and the encrypted message are for example transmitted over an unsecured channel, without any risk to the confidentiality of personal data being incurred.

[0099] Concerning each reception device 25, its reception module 60 is configured to receive, from the transmission device 20, and in particular from the transmission module 56 of the encryption unit 35, the image with obfuscated zone(s) 75 and the encrypted message. The reception module 60 is further configured to receive, from the transmission device 25, and more particularly from the configuration unit 30, the individual secret key Is which is specific to it.

[0100] The decryption module 62 is configured to apply a decryption algorithm to the encrypted pixel values ​​of the encrypted message from the received individual secret key Is, to obtain a partially decrypted message.

[0101] In particular, the decryption module 62 is configured to use a decryption algorithm using the individual secret key Is. For example, decryption module 62 is configured to further use the public master key Mp. The decryption algorithm used depends on the ABE algorithm that was used to generate the individual secret key Is. This algorithm is for example known to each reception module 25, by the reception of the individual secret key Is.

[0102] According to one example, the decryption module 62 is configured to apply the decryption algorithm to all the values ​​of the pixels of the encrypted message, i.e. to the content of the second data field(s) in the message. In this case, the decryption module 62 is configured to obtain, for the zone(s) 70 representing one or more objects that the associated receiving device 25 is authorized to consult, the values ​​of the pixels of the identified zone 70 corresponding to those of the image acquired 37 by the transmitting device 20.

[0103] For areas 70 corresponding to objects that the receiving module 25 is not authorized to consult, the decryption algorithm fails to decrypt the pixel values ​​and returns an error message.

[0104] As a variant, for these zones 70, the values ​​of the pixels obtained following the application of the decryption algorithm are distinct from those of these zones 70 in the acquired image 37. In other words, the values ​​of the pixels corresponding to zones 70 for which the reception device 37 is not authorized to consult the object represented, form a noisy signal, for example an unintelligible content in the partially decrypted message.

[0105] It is then understood that the expression “partially decrypted message” refers to the fact that the application of the decryption algorithm does not necessarily make it possible to decrypt the entire encrypted message but only the parts corresponding to the zone(s) representing the object(s) that the receiving device 25 is authorized to consult.

[0106] The reconstruction module 64 is configured to reconstruct a partially reconstructed image 77 by replacing in the image with obfuscated zone(s) 75, the values ​​of the pixels of the zones by the values ​​of the pixels of the corresponding zones in the partially decrypted message.

[0107] The partially reconstructed image 77 is such that the zones corresponding to objects that the reception device 25 is authorized to consult are the same as those 70 of the image 37 acquired by the transmission device 20 from the camera 15. The other zones 70 are not deciphered and therefore comprise pixels of value(s) distinct from those in the acquired image 37 by the transmission device 20. For example, these values ​​form an unintelligible noisy signal.

[0108] An example of a partially reconstructed image 77 obtained by the first receiving device 25A is illustrated in [Fig. 3]. As shown in [Fig. 3], among the objects “vehicle”, “silhouette” and “face” only the “vehicle” objects are visible.

[0109] Preferably, the reconstitution module 64 is further configured to transmit the partially reconstituted image 77 to the display screen 67 of said reception device 25, for its display to the user of said reception device 25.

[0110] According to a variant, the decryption module 62 is configured to, if the encrypted message received by the reception module 60 comprises for each zone 70, the third data field, apply the decryption algorithm only to the values ​​of the pixels associated with the third data field comprising a respective first character string indicating an object that said reception device 25 is authorized to consult, in the encrypted message. According to this variant, the reconstruction module 64 is configured to replace, in the image with obfuscated zone(s) 75, only the values ​​of the pixels of the zone(s) 70 comprising values ​​of the pixels to which the decryption algorithm has been applied.

[0111] In the example of [Fig. 1], the configuration unit 30 comprises a first information processing unit formed for example by a first memory 80 and a first processor 82 associated with the first memory 80. The sending module 40; and optionally the acquisition module 42, the determination module 44, and the calculation module 46 are each produced in the form of software, or a software brick, executable by the first processor 82. The first memory 80 is then capable of storing sending software and optionally acquisition software, determination software and calculation software. The first processor 82 is then capable of executing each of these software programs.

[0112] Still in the example of [Fig. 1], the encryption unit 35 comprises a second information processing unit formed for example by a second memory 85 and a second processor 87 associated with the second memory 85. The obtaining module 50, the application module 52, the generation module 54, and the transmission module 56 are each produced in the form of software, or a software brick, executable by the second processor 87. The second memory 85 is then able to store obtaining software, application software, generation software and transmission software. The second processor 87 is then able to execute each of these software programs.

[0113] Still in the example of [Fig. 1], each reception device 25 comprises a third information processing unit formed for example of a third memory 90 and a third processor 92 associated with the third memory 90. The reception module 60, the decryption module 62, and the reconstitution module 64 are each produced in the form of software, or a software brick, executable by the third processor 92. The third memory 90 is then capable of storing reception software, decryption software, and reconstruction software. The third processor 92 is then capable of executing each of these software programs.

[0114] In a variant not shown, at least one of the sending module 40, the obtaining module 50, the application module 52, the generation module 54, the transmission module 56, the reception module 60, the decryption module 62, the reconstitution module 64, and optionally the acquisition module 42, the determination module 44, the calculation module 46, is produced in the form of a programmable logic component, such as an FPGA (Field Programmable Gate Array) or in the form of a dedicated integrated circuit, such as an ASIC (Application Specific Integrated Circuit).

[0115] When the configuration unit 30, the encryption unit 35 and each reception device 25 are produced in the form of one or more software programs, that is to say in the form of a computer program, they are furthermore capable of being recorded on a medium, not shown, readable by a computer. The computer-readable medium is, for example, a medium capable of storing electronic instructions and of being coupled to a bus of a computer system. By way of example, the readable medium is an optical disk, a magneto-optical disk, a ROM memory, a RAM memory, any type of non-volatile memory (for example EPROM, EEPROM, FLASH, NVRAM), a magnetic card or an optical card. A computer program comprising software instructions is then stored on the readable medium.

[0116] The operation of the communication system 10 will now be described.

[0117] Firstly, the operation of the transmission device 20 will be described with reference to [Fig.5] representing a flowchart of a transmission method 100 according to the invention.

[0118] The transmission method 100 comprises a configuration phase 110 and an encryption phase 120.

[0119] Preferably, the configuration phase 110 is implemented prior to the encryption phase 120.

[0120] Initially, an operator of the transmission device 20 creates the correspondence table and sends it to the configuration unit 30.

[0121] Optionally, the configuration phase 110 comprises an acquisition step 112 during which the acquisition module 42 acquires the correspondence table from the operator.

[0122] Optionally, the configuration phase 110 comprises a determination step 114 during which the determination module 44 determines the master public key Mp and the master secret key Ms, for example randomly.

[0123] Optionally again, the configuration phase 110 then comprises a step 116 of calculating the individual secret keys Is specific to each reception device 25, from the correspondence table indicating, for each reception device 25, the object(s) that it is authorized to consult. Preferably, each individual secret key is calculated from the master secret key Ms, the objects of the correspondence table, and an ABE algorithm as described previously.

[0124] The configuration phase 110 further comprises a step 118 of sending, to each reception device 25, the individual secret key Is which is specific to it. For this, the sending module 70 preferentially uses a secure channel of the TLS type, such as an HTTPS channel which is encrypted and authenticated.

[0125] Alternatively, each individual secret key Is is already stored in the configuration unit 30. According to this variant, the configuration phase 110 only comprises the sending step 118.

[0126] The encryption phase 120 comprises a step 121 of obtaining the image 37 comprising at least one zone 70 identified as respectively representing an object.

[0127] The obtaining step 121 preferably comprises a sub-step 122 of acquiring, from the camera 15, the image 37.

[0128] Then, the obtaining step 121 preferably comprises a sub-step 123 of identifying, in the acquired image 37, the zones 70 representing each object.

[0129] For example, during the identification sub-step 123, the obtaining module 50 applies, to the acquired image 37, the identification model including the neural network described previously, to identify each zone 70.

[0130] The encryption phase 120 further comprises an application step 124, during which the application module 52 applies, to each identified zone 70, the obfuscation to form the image with obfuscated zone(s) 75. The image with obfuscated zone(s) 75 comprises, in each identified zone 70, pixels whose value is distinct from the value of the same pixels in the acquired image 37.

[0131] The encryption phase 120 further comprises a step 125 of generating the encrypted message.

[0132] The generation step 125 preferably comprises a storage sub-step 126 and a sub-step of applying an encryption 127.

[0133] During the storage sub-step 126, the generation module 54 stores, for each identified zone 70, the values ​​of the pixels of the acquired image 37, in the message. The message is preferably a database.

[0134] Advantageously, the message then comprises, for each identified zone 70 in the acquired image 37: the first data field comprising the position of said area 70 in the acquired image 37 and the second data field comprising the values ​​of the pixels in the acquired image 37. For each identified area 70, the first data field is preferentially arranged, in the message, before the second data field.

[0135] During the encryption application sub-step 127, the generation module 54 applies to the values ​​of the pixels of the message, the encryption from the master public key Mp and the encryption policy as indicated previously.

[0136] At the end of the encryption application sub-step 127, all the values ​​of the pixels of the message are encrypted, thus forming the encrypted message.

[0137] The encryption phase 120 further comprises a transmission step 128 during which the transmission module 56 transmits, to each reception device 25, the image with obfuscated zone(s) 75 and the encrypted message.

[0138] For example, the encrypted message is included in the metadata of the image with obfuscated zone(s) 75.

[0139] The transmission step 128 is for example carried out via a standard and non-secure communication channel.

[0140] For example, all steps 121, 124, 125, 128 of the encryption phase 120 are repeated for a plurality of images 37 forming a video stream. Thus, for each image 37 of the video stream, the encryption unit 35 successively implements each of the steps of obtaining 121, applying 124, generating 125 and transmitting 128.

[0141] According to another example, for each image 37 forming the video stream, the encryption unit successively implements only the steps of obtaining 121, application 124 and generation 125. The encryption phase 120 then comprises a single transmission step 128 for the entirety, i.e. all, of the images with obfuscated zone(s) 75 and the associated encrypted messages.

[0142] The configuration 110 and encryption 120 phases are for example implemented successively as described previously.

[0143] According to an alternative, the configuration 110 and encryption 120 phases are implemented in parallel. In this case, it is still preferable for the determination step 114 to be implemented prior to the generation step 125 so that during the application sub-step 127, the master public key Mp has already been determined.

[0144] Secondly, the operation of each reception device 25 will be described with reference to [Fig.6] describing a reception method 200, according to the invention, implemented by each reception device 25.

[0145] The reception method 200 comprises a reception step 210. During the reception step 210, the reception module 60 receives, from the transmission device 20, the individual secret key Is which is specific to him, the image with obfuscated zone(s) 75 and the encrypted message.

[0146] The reception 210 of the individual secret key Is and the reception of the image with obfuscated zone(s) 75 are preferably not carried out at the same times.

[0147] Advantageously, the reception module 60 receives the individual secret key Is which is specific to it from the sending module 40, via the secure channel.

[0148] For example, the receiving module 60 receives the image with obfuscated zone(s) 75 and the encrypted message from the transmitting module 56, via the unsecured channel.

[0149] The individual secret key Is is received before or after the image with obfuscated zone(s) 75 and the encrypted message.

[0150] Preferably, the encrypted message is a database.

[0151] Then, the reception method 200 comprises a decryption step 220 during which the decryption module 62 applies the decryption algorithm to the encrypted message, from the individual secret key Is, received to obtain the partially decrypted message.

[0152] For example, the decryption module 62 applies the decryption algorithm to all encrypted pixel values ​​of the encrypted message.

[0153] During the decryption step 220, the application of the decryption algorithm makes it possible to obtain, for the identified zone(s) 70 representing an object that the reception device 25 is authorized to consult, the values ​​of the pixels of said zones 70 in the acquired image 37. For the other zone(s) where appropriate, the application of the decryption algorithm provides pixel values ​​distinct from those in the acquired image 37.

[0154] In other words, the application of the decryption algorithm makes it possible to decrypt only the values ​​of the pixels of the zone(s) 70 representing the object(s) that the receiving device 25 is authorized to consult. For the values ​​of the pixels of the other zone(s) 70, the application of the decryption algorithm provides pixel values ​​that do not represent any intelligible content.

[0155] The decryption method 200 then comprises a reconstruction step 230 during which the reconstruction module 64 reconstructs the partially reconstructed image 77. For this, the reconstruction module 64 replaces, in the image with obfuscated zone(s) 75, the values ​​of the pixels of the obfuscated zone(s) with the values ​​of the corresponding pixels of the partially decrypted message, to form the partially reconstructed image 77.

[0156] Preferably, during the replacement step 230, the reconstitution module 64 sends the partially reconstituted image 77 to the display screen 67 of the reception device 25.

[0157] Thus, the user of the receiving device 25 consulting the partially reconstituted image 77 has access only to the objects of the acquired image 37 that he is authorized to consult, the other object(s) not being represented in the partially reconstituted image 77.

[0158] The reception method 200 is for example iterated for a plurality of images with obfuscated zone(s) 77 and associated encrypted messages. The individual secret key Is is preferably received only once.

[0159] According to a first variant, the encrypted message further comprises, for each identified zone 70, the third data field comprising the first character string indicating the object represented in said zone 70. For example, if a zone 70 represents a face, the encrypted message comprises the first data field indicating the position of said zone in the acquired image, the third data field comprising the first character string “face” and the second data field comprising the values ​​of the pixels of said zone 70 which have been encrypted.

[0160] According to this first variant, during the decryption step 220, the decryption module 62 applies the decryption algorithm only to the values ​​of the pixels associated with the third data field comprising a character string corresponding to an object that the reception device 25 is authorized to consult.

[0161] Still according to this first variant, during the replacement step 230, the reconstitution module 64 replaces, in the image with obfuscated zone(s) 75, only the pixels of zone(s) 70 for which the decryption algorithm has been applied by the decryption module 62. According to this variant, the zone(s) of the partially reconstituted image 77 distinct from the zone(s) representing an object that the reception device 25 is authorized to consult, are identical to those of the image with obfuscated zone(s) 75.

[0162] According to a second variant, the reception module 60 receives several images with obfuscated zone(s) 75 and the corresponding encrypted messages before implementing the decryption 220 and reconstruction 230 steps. According to this second variant, the individual secret key Is is for example received before and / or after the reception of all the images with obfuscated zone(s) 77 and corresponding encrypted messages.

[0163] According to a third variant not shown, the communication system 10 comprises several cameras 15. According to this third variant, each secret individual key Is is capable of deciphering only values ​​of the pixels corresponding to a zone 70 representing one or more objects and coming from one or more chosen cameras 15.

[0164] For example, the communication system 10 comprises a first camera 15 capturing images in front of a first parking entrance, and a second camera 15' capturing images in front of a second parking entrance. The communication system 10 comprises a first receiving device 25A associated with a first security guard monitoring the first entrance and a first receiving device 25A' associated with a second security guard monitoring the second entrance.

[0165] In this example, the first reception device 25A associated with the first security guard is authorized to consult only the “vehicle” objects captured by the first camera 15, while the first reception device 25A' associated with the second security guard is authorized to consult only the “vehicle” objects captured by the second camera 15'.

[0166] According to the optional addition in which the configuration unit 30 comprises the acquisition module 42, the determination module 44 and the calculation module 46, the correspondence table then associates, with each reception device 25, the list of respective object(s) and for each object, the camera(s) 15 from which the images 37 representing this object originate. Thus, in this example, the correspondence table associates: - to the first receiving device 25A associated with the first guard, the “vehicle” object coming from the first camera 15, 15', - to the first receiving device 25A' associated with the second security guard, the “vehicle” object coming from the second camera 15, 15', - to the second receiving device 25B associated with the police service, the “silhouette” object coming from each camera 15, 15', and - to the third reception device 25C associated with the investigating judge, the objects “vehicle”, “silhouette” and “face” coming from each camera 15, 15'.

[0167] The calculation module 46 is then configured to calculate each individual secret key Is as a function of the list of object(s) and in addition of the camera 15, 15' from which the image 37 comes.

[0168] The obtaining module 50 is configured to obtain at least one respective image 37 from each camera 15, 15', each image 37 having one or more identified zones 70.

[0169] The application module 52 is then configured to apply the masking to each identified area 70 of each image 37.

[0170] The generation module 54 is configured to generate a respective encrypted message for each image 37.

[0171] Alternatively, the generation module 54 is configured to generate a single encrypted message for a set comprising an image 37 from each camera 15, 15'. Each logical relationship of the encryption policy then combines the object(s) represented in the identified area 70 and a context element which is the camera 15, 15' from which the image 37 associated with the identified area 70 comes.

[0172] The transmission module 56 is configured to transmit, to each reception device 25, each image with obfuscated zone(s) 75 and the or each encrypted message.

[0173] According to this third variant, the decryption module 62 is configured to, if the reception module 60 has received an encrypted message for each image with obfuscated zone(s) 75, then apply the decryption algorithm to each encrypted message corresponding to a camera 15, 15' for which the reception device 25 is authorized to consult at least one object. The decryption module 62 is configured to, if the reception module 60 has received only one encrypted message for all the images with obfuscated zone(s) received 75, then apply the decryption algorithm only to the values ​​of the pixels for which the individual secret key Is is associated with at least one object and / or context element(s) verifying the logical relationship of the third data field.

[0174] According to this variant, the reconstruction module 64 is configured to, if an image-encrypted message with obfuscated zone(s) 75 is received, then replace the pixel values ​​of each obfuscated zone of each received image 75 with the pixel values ​​of the associated partially decrypted message.

[0175] The reconstruction module 64 is configured to, if an encrypted message is received for all the images with obfuscated zone(s) 75, then replace in each image with obfuscated zone(s) 75, the pixel values ​​of each obfuscated zone with the decrypted pixel values ​​of the partially decrypted message.

[0176] According to this third variant, the transmission method is identical to the transmission method 100 described previously, with the following differences.

[0177] During the optional calculation step 116, the calculation module 46 calculates the individual secret key Is associated with each reception device 25, also taking into account the camera(s) 15 for which the reception device 25 is authorized to consult the objects.

[0178] During the obtaining step 121, the obtaining module 50 obtains a respective image 37 with one or more identified zones 70, for each camera 15, 15'. Preferably, the obtaining step 121 comprises the acquisition 122 and identification 123 sub-steps which are implemented for each image 37.

[0179] The application step 124 is applied to each image 37 to form, for said image 37, an image with respective obfuscated zone(s) 75.

[0180] During the generation step 125, the generation module 54 generates a respective encrypted message per image 37 as described previously, or an encrypted message for all of the images 37. In the latter case, the third data field of the encrypted message then includes the logical relationship associated with the object(s) represented in the identified zone 70 and the context element(s) of the encryption policy.

[0181] During the transmission step 128, the transmission module 56 transmits, to each reception device 25, the images with obfuscated zone(s) 75 and the encrypted message(s).

[0182] The reception method 200 according to this variant embodiment is identical to the reception method 200 described previously with the following differences.

[0183] During the reception step 210, the reception module 60 receives each image with obfuscated zone(s) 75 and the encrypted message(s).

[0184] The decryption step 220 is implemented for the or each encrypted message to obtain one or more partially decrypted messages.

[0185] If an encrypted message for each image with obfuscated zone(s) 75 has been received, the reconstruction step 230 is iterated for each partially decrypted message, i.e. for each image with obfuscated zone(s) 75.

[0186] If an encrypted message has been received for all the images with obfuscated zone(s) 75, during the reconstruction step 230, the reconstruction module 64 replaces, for each image with obfuscated zone(s) 75, the pixel values ​​of each obfuscated zone with the decrypted pixel values ​​of the partially decrypted message.

[0187] The first and second variants previously described can be combined with the third variant described above.

[0188] With the transmission method 100 according to the invention, it is possible to transmit an image which protects personal data, while being partially decipherable for a user authorized to consult part of its content.

[0189] With the reception method 200 according to the invention, it is possible to decrypt only a part of an image for which only certain objects are authorized to be consulted.

[0190] Thus, the transmission 100 and reception 200 methods according to the invention make it possible to improve the confidentiality of personal data.

Claims

1. Claims Method for transmitting (100), from an electronic transmitting device (20) and to at least one electronic receiving device (25), an image (37) representing at least one object, the transmission method (100) being implemented by the electronic transmitting device (20) and comprising a configuration phase (110) comprising the following step: - acquisition (112) of a correspondence table, the correspondence table associating with each electronic reception device (25), a respective list of object(s) that said electronic reception device (25) is authorized to consult by decryption of an encrypted message, from an individual secret key (Is), - determination (114) of a master public key (Mp) and a master secret key (Ms), - calculation (116), for each electronic reception device (25), of the respective individual secret key (Is) from the master secret key (Ms) and the list of object(s) associated with said electronic reception device (25) in the correspondence table, - sending (118) to the or each electronic receiving device (25) of the respective individual secret key (Is), the method (100) further comprising an encryption phase (120) comprising the following steps: - obtaining (121) the image (37) representing the at least one object, in which one or more zones (70) comprising certain pixels of the image are identified, each identified zone (70) representing the or one of the objects, - application (124) of an obfuscation to the or each zone (70) of the image (37), to form an image with obfuscated zone(s) (75), - generation (125) of the encrypted message comprising values of the pixels of the areas in the obtained image, in which said values are encrypted, the values of the pixels being encrypted from the master public key (Mp), - transmission (128), to the or each electronic reception device (25), of the image with obfuscated zone(s) (75) and of the encrypted message with a view to its at least partial decryption, by each electronic reception device (25) to reconstitute a partially reconstituted image (77) associated with the electronic reception device (25), in which each individual secret key (Is) is calculated from the correspondence table by application of a key generation function of an attribute encryption algorithm.

2. Method (100) according to claim 1, in which the obtaining step (121) comprises the following sub-steps: - acquisition (122) of the image (37), and - identification (123) in the acquired image of the zone(s) (70) representing the or each object from an identification model, the identification step (123) being preferentially implemented by an identification model more preferentially comprising a neural network.

3. Method (100) according to claim 1 or 2, in which the generation step (125) comprises the following sub-steps: - storing (126), in a message, the values of the pixels corresponding to the zone(s) identified in the image, - applying (127) an encryption algorithm to the values of the pixels of the message from the master public key (Mp), to form the encrypted message, the encryption algorithm preferably being chosen from the group consisting of: - the BS W07 algorithm, - the CPW08 algorithm, and - the AC 17 algorithm

4. Method (100) according to any one of the preceding claims, in which the obtained image (37) comes from a camera (15, 15') chosen from a predefined list of cameras (15, 15'), the correspondence table associating, with each electronic device

5.

6. reception (25), for each object, one or more cameras (15, 15') capable of capturing images for which said electronic reception device (25) is authorized to consult said object, the or each individual secret key (Is) further being a function of the camera(s) (15, 15') associated with the corresponding electronic reception device (25) in the correspondence table. Reception computer program product comprising software instructions, which when executed, implement a reception method (100) according to any one of the preceding claims. Electronic transmission device (20), intended for at least one electronic reception device (25), of an image (37) representing at least one object from a predefined list of object(s), the electronic transmission device (25) comprising a configuration unit (30) comprising: - an acquisition module (42) configured to acquire a correspondence table, the correspondence table associating with each electronic reception device (25), a respective list of object(s) that said electronic reception device (25) is authorized to consult by decrypting an encrypted message, from an individual secret key (Is), - a determination module (44) configured to determine a master public key (Mp) and a master secret key (Ms), and - a calculation module (46) configured to calculate the respective individual secret key (Is) from the master secret key (Ms) and the list of object(s) associated with said electronic receiving device (25) in the correspondence table, - a sending module (40) configured to send to the or each receiving electronic device (25) the respective individual secret key (Is), the electronic transmission device (20) further comprising an encryption unit (35) comprising:

7. - an obtaining module (50) configured to obtain the image (37) representing the at least one object, in which one or more zones (70) comprising certain pixels of the image are identified, each identified zone (70) representing the or one of the objects, - an application module (52) configured to apply masking to the or each zone (70) of the image (37), to form an image with obfuscated zone(s), - a generation module (54) configured to generate the encrypted message comprising values of the pixels of the areas (70) in the obtained image (37), in which said values are encrypted, the values of the pixels being encrypted from a master public key (Mp), - a transmission module (56) configured to transmit, to each electronic reception device (25), the image with obfuscated zone(s) (75) and the encrypted message with a view to its at least partial decryption, by each electronic reception device (25) to reconstitute a partially reconstituted image (77) associated with the respective electronic reception device (25), wherein each individual secret key (Is) is calculated from the correspondence table by applying a key generation function of an attribute encryption algorithm. Method for receiving (200), by an electronic receiving device (25) and from an electronic transmitting device (20), an image (75) with at least one obfuscated zone suitable for representing an object from a predefined list of object(s), the method (200) being implemented by the electronic receiving device (25) and comprising the following steps: - reception (210) of the image with obfuscated zone(s) (75), of an encrypted message comprising encrypted pixel values, and of an individual secret key (Is) associated with the electronic reception device (25), the individual secret key (Is) being suitable for decrypting only the encrypted values of pixels corresponding to one or more zones of the image with obfuscated area(s) (75) representing objects that the electronic receiving device (25) is authorized to consult, - decryption (220), from a decryption algorithm and the received individual secret key (Is), of the encrypted pixel values of the encrypted message to obtain a partially decrypted message, and - reconstruction (230) of a partially reconstructed image (77), by replacing the obfuscated zone(s) of the image with obfuscated zone(s) (75) by pixels whose values are included in the partially deciphered message, at least one area of the partially reconstructed image (77) representing an object that the electronic receiving device (25) is authorized to consult.

8. A receiving computer program product comprising software instructions, which when executed by a computer, implement a receiving method (200) according to the preceding claim.

9. Electronic receiving device (25), from an electronic transmitting device (20), of an image (75) with at least one obfuscated zone capable of representing an object, the electronic receiving device (25) comprising: - a reception module (60) configured to receive the image with obfuscated zone(s) (75), an encrypted message comprising encrypted pixel values, and an individual secret key (Is) associated with said electronic reception device (25), the individual secret key (Is) being capable of decrypting only the encrypted values of pixels corresponding to one or more zones of the image with obfuscated zone(s) (75) representing objects that the electronic receiving device (25) is authorized to consult, - a decryption module (62) configured to decrypt, from a decryption algorithm and the received individual secret key (Is), the encrypted pixel values of the encrypted message to obtain a partially decrypted message, and

10. - a reconstruction module (64) configured to reconstruct a partially reconstructed image (77), by replacing the obfuscated zone(s) of the image with obfuscated zone(s) (75) with pixels whose values are included in the partially decrypted message, at least one area of the partially reconstructed image (77) representing an object that the electronic receiving device (25) is authorized to consult. Electronic communication system (10) comprising an electronic transmission device (20) and at least one electronic reception device (25), wherein the electronic transmission device (20) is according to claim 6 and each electronic reception device (25) is according to claim 9.