Signed video data using salted hash
Patent Information
- Application Number
- JP2022157229
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2021-10-07
- Filing Date
- 2022-09-30
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2042-09-30
AI Technical Summary
Existing methods for digitally signing video data, particularly live video streams, are not well suited to protect against unauthorized parties identifying the secret hash function used in the signing process, and there is a need for a computationally efficient signature technique that can be verified in parallel with video decoding.
A method involving generating a salt from a bitstring not extracted from the video data, using a hash function to create a fingerprint, and providing a signature that includes this fingerprint, which is computationally complex and difficult to guess, allowing verification without receiving the entire video data.
The method effectively protects the hash function from being guessed and enables parallel verification of video data integrity and authenticity, even when only a portion of the data is available, ensuring high security and efficiency in video streaming applications.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical Field]
[0001] This disclosure relates to the field of security measures for protecting programs or data from unauthorized activity. More specifically, this disclosure proposes a method and apparatus for signing video data. [Background technology]
[0002] In the field of secure digital communications, it is known that so-called salts are used to prevent unauthorized parties from guessing passwords based on their hash, even if those passwords are used repeatedly. Salts, sometimes called cryptographic salts, have also been used to prevent hash collisions, an abnormal condition where hashing separate data items produces the same result. Hash collisions can not only disrupt internal system processing procedures but also expose the system to attacks.
[0003] For example, U.S. Patent No. 10728023(B2) discloses a method for implementing a hash function with a content-based salt. This method involves identifying a data block B of a given size, dividing this data block into x segments, selecting y bytes from each of these segments, and summing them up to y. total Making it a part-time job, and this y total This involves performing bitwise AND / OR operations on z bytes of a byte to obtain a salt for data block S(B), calculating the hash value h(B) of the data block, and calculating the hash value h(h(B)*S(B)) of the concatenation of the hash value and the salt, which generates a unique fingerprint that can identify data block B. Here, the number of selected bytes y is a function of a number of calculations determined to avoid generating the same hash for two different data blocks.
[0004] CN113158248A discloses a method for securely storing video data, in which a data hash value is calculated for a combination of a data record, a timestamp, and an operation sequence number. A signature is generated from the hash value using a private key belonging to a key pair that further includes a public key. These elements are sent to a server, which stores the data record, timestamp, operation serial number, public key, and signature after successful verification.
[0005] U.S. Patent Application Publication 20140010366(A1) discloses a method for cryptographic video verification in which the data of each video frame is augmented with a timestamp before being hashed. The hash of the augmented video frame is included in a document that is cryptographically signed.
[0006] WO0064094A1 discloses a method for inserting a digital signature into digital data, particularly video data. According to one embodiment disclosed, the digital signature is salted with a timestamp assigned by a trusted third party. This timestamp is related to the time at which it is timestamped, and not to the time at which the digital data is acquired. In this embodiment, the digital data is hashed and signed, then combined with the timestamp, and the resulting combination is hashed and encrypted.
[0007] U.S. Patent Application Publication No. 2011200224(A1) discloses a method for providing an identifier for a content item, comprising: generating a first identifier for the content item based on at least a portion of a baseband-level representation of the content item; generating a second identifier for the content item based on at least a portion of an encoded representation of the content item; and generating a message containing the first identifier and the second identifier. The content item may be a video item, and the baseband-level representation may include raw video.
[0008] WO2017202451A1 discloses a method for providing a secure digital signature by first sampling a biometric signature including a time and coordinates, and then constructing a set of polynomials based on this sampling. A hash calculation is then performed on the data to be signed, which is salted with data based on the polynomials from the sampling. Finally, the salted hash is encrypted with a private key from a qualified proof and stored along with the signed data, hash, and public key to enable signature validation.
[0009] Techniques available for modifying hashes using content-based salts are not sufficiently suitable for digitally signing video data, especially data encoding live video streams. [Prior art documents] [Patent Documents]
[0010] [Patent Document 1] US Patent No. 10728023(B2) [Patent Document 2] CN113158248A [Patent Document 3] U.S. Patent Application Publication No. 20140010366(A1) [Patent Document 4] WO0064094A1 [Patent Document 5] U.S. Patent Application Publication No. 2011200224(A1) [Patent Document 6] WO2017202451A1 [Non-patent literature]
[0011] [Non-Patent Document 1] Recommendation ITU-T H.264(06 / 2019) "Advanced video coding for generic audiovisual services" [Non-Patent Document 2] ITU-T H.265(08 / 2021) “High efficiency video coding” [Overview of the project]
[0012] One objective of this disclosure is to create a usable method and apparatus for signing (digitally signing) video data using a mechanism that protects against situations where an unauthorized party could identify the secret function used in the signing process based on past signatures. This is particularly desirable when the secret function includes a hash function, given the limited number of available hash functions with proven ability to resist attacks. A further objective is to propose such a method and apparatus that generates digital signatures that can be verified in parallel with execution processes that sequentially decrypt streams of video data, such as live video streams. A specific objective is to propose a computationally efficient signing technique having these characteristics.
[0013] At least some of these objectives are achieved by the present invention as defined in the independent claims. The dependent claims relate to advantageous embodiments of the present invention.
[0014] A first aspect of the present invention provides a method for signing video data, comprising: obtaining video data representing a video sequence; obtaining bit strings that were not extracted from the video data; generating a salt by hashing the bit strings; generating a first fingerprint; and providing a signature of the video data including the first fingerprint. The first fingerprint is generated by hashing a combination of the salt and a first portion of the video data, or by hashing a combination of the salt and a hash of the first portion of the video data.
[0015] The recipient of the signed video data can use this signature to verify the authenticity or integrity of the video data and, similarly, ensure non-repudiation. An unauthorized party, even if it knows the first part of the video data and the first fingerprint generated therefrom, or rather, since the first part of the video data (or its hash) is modified by sorting each time, it becomes very difficult to guess which hash function was used. This also prevents anyone without the bit string from generating a new fingerprint, for example, a fingerprint that references non-authentic video data. Thirdly, since the bit string is not extracted from the video data, the probability that the same bit string appears in the video data is very small, and thus, for all practical purposes, the bit string can be considered independent of the video data. Using a content-independent sort allows the recipient to complete the verification process without receiving the entire video data, as in the case of a video streaming application.
[0016] In the present disclosure, the "hash" of data item B1 includes both the primary hash h(B1) and the higher-order hash obtained by recursive hashing. This term applies to at least the following examples. h(h(B1))=(h○h)(B1) (h○...○h)(B1) h({h(B1),h(B2)}) Here, B2 is a further data item, and {·} represents a data concatenation operation such as concatenation. Thus, the "hash of the first part of the video data" includes the primary hash of the said part, as well as the hash of this hash, or the hash of each combination of hashes.
[0017] In some embodiments, the first part of the video data is the entire video data. In other embodiments, the first part of the video data, together with the second, third, and further parts from which the fingerprint is taken, makes up the entire video data. Again, in other embodiments, fingerprinting is applied only to a subset of the video data. Here, for example, the video data may be divided into segments, and each fingerprint may be generated from a subset of segments. In such embodiments, this subset is extracted in a pre-agreed manner that allows for repeated extraction by a recipient who wishes to verify the signature. In such embodiments, for example, the first part may be a subset of data structures encoding a first video frame, and the second part may be a subset of data structures encoding a second video frame, and both subsets are extracted by the same pre-agreed extraction algorithm. In relation to the aforementioned objective of protecting the secret function from being guessed, it can be understood that this secret function includes both a hash function and a subset extraction algorithm. Even if subset extraction is repeated in the same manner across the first, second, and subsequent portions of the video data, each resulting fingerprint will be modified by salting in such a way that the attacker faces a computationally very complex inversion problem. To ensure with high confidence that the received video data has not been manipulated by an unauthorized party, it is preferable that the subset constitutes a significant proportion of the video data or is well distributed throughout the entire video data.
[0018] As described above, this method may further include generating a second fingerprint based on a second portion of the video data and a salt previously generated from a bit string. Similar to the first fingerprint, the second fingerprint can be generated by hashing a combination of the salt and the second portion of the video data, or by hashing a combination of the salt and the hash of the second portion of the video data. Advantageously, even if the same salt is used for both fingerprints, the hash function used to generate the fingerprints remains protected from easy guessing. The salt may be conveniently cached in memory during the time elapsed between the generation of the first fingerprint and the generation of the second fingerprint. In this embodiment, the first and second portions of the video data may represent (for example, encoded) respective time segments of a video sequence. These time segments may constitute frames of the video sequence. Alternatively, the time segments may constitute groups of pictures (GOPs) of the video sequence, where GOPs are defined as independently decodeable segments. Insofar as the GOP contains frames that are predicted in one direction (forward) or frames that are predicted in both directions, these can be decoded without depending on the frames outside the GOP. The time segments may be disparate, overlapping, or partially overlapping. To avoid misunderstanding, a preferred option is to use data that encodes each video frame or each GOP, rather than plaintext video frames or plaintext GOPs, as the aforementioned first part, second part, etc. of the video data.
[0019] In one embodiment, a salt is generated using a first hash function, and a first (second, third, etc.) fingerprint is generated using a second different hash function. The first hash function is kept secret. To achieve this, this method involves sharing the definition of the first hash function with the recipient of the signed video data via a dedicated communication channel. This allows the recipient to verify the signature of the video data by repeating this operation. Even when the hash function definition is shared via a dedicated communication channel, according to this embodiment, the signed and / or video data can be transmitted over any communication channel without significantly compromising the security of the signing device. The dedicated communication channel may refer to a digital transmission channel in which unauthorized eavesdropping is extremely difficult, easily detectable, or both. Encrypted communications and communications requiring two-channel permission are examples of this type of dedicated communication channel. Furthermore, the hash function definition may be shared embedded by granting the recipient access to software configured in light of the hash function used, which may be, for example, a video decryption application or a signature verification application. Thus, the hash function definition is provided to the recipient's service without being verifiable in plaintext. Another option is to place this hash function definition in a secure memory space of some device whose access is exclusively controlled by the device owner. This device could be, for example, a digital video camera used to record video data. The secure memory space may be physically located on a removable medium such as a chip or chipset (e.g., a trusted platform module (TPM) or secure element (SE)) with the sender and receiver each holding one copy. The level of trust can be increased if the hash function definition is divided into two parts, each held by different users on the receiver side, and these users are then required to collaborate in verifying the signature.
[0020] In one embodiment, the original bitstring from which the salt is generated includes reproducible information related to the acquisition of the video sequence. This information is reproducible in the sense that the intended recipient can obtain the bitstring without assistance from the signer who provided the signature for the video data. Alternatively, according to a further embodiment, at least a portion of the bitstring is extracted from metadata associated with the video data. In yet another embodiment, the video signature includes a bitstring in plaintext. In particular, this does not necessarily represent a vulnerability if the hash function from which the salt was generated (the first hash function) is kept secret between the signer and the recipient.
[0021] In another embodiment, the original bitstring from which the salt is generated is selected by the sender, who then inserts the original information from which this bitstring can be derived into metadata associated with the video data. For example, the bitstring may be a prime factorization. In TIFF2023056492000002.tif8170, the integer M is also acceptable, and the salt is the prime factors p1, p2, ..., p t This is a hash of combinations of [the specified elements].
[0022] In some embodiments, the signature of video data consists of multiple sub-signatures associated with each (e.g., consecutive) segment of the video data. This is particularly useful when the video data has a time-series structure. The step of providing the signature may then include inserting the sub-signatures into each segment of the video data. More specifically, the sub-signatures may be inserted into the video bitstream in the vicinity of each time segment (i.e., in or near each time segment), or the sub-signatures may be included in metadata associated with such time segments. The insertion of the sub-signatures may be considered accomplished "in or near" a time segment if the verification of the sub-signatures does not noticeably delay or interfere with a decryption operation performed in parallel with this verification operation in, for example, a video playback application on the recipient side.
[0023] A second aspect of the present invention provides an apparatus configured to perform the above method. Broadly speaking, the second aspect of the present invention shares the effects and advantages of the first aspect and can be implemented with corresponding degree of technical modification.
[0024] The present invention further relates to a computer program that includes instructions for enabling a computer to perform the above-described method. This computer program may be stored in or distributed on a data carrier. In this specification, “data carrier” may be a transient data carrier, such as a modulated electromagnetic wave or light wave, or a non-transient data carrier. Non-transient data carriers include volatile and non-volatile memories, such as magnetic, optical, or solid-state persistent and non-persistent storage media. Again within the scope of “data carrier,” such memories may be fixedly mounted or portable.
[0025] In general, all terms used in the claims should be interpreted according to their ordinary meaning in the art unless expressly provided herein. Any reference to “a / an / the (element, apparatus, component, means, step, etc.)” should be interpreted frankly as referring to at least one of such elements, apparatus, components, means, steps, etc., unless expressly provided otherwise. Each step of any method disclosed herein does not have to be performed in the order described herein unless expressly indicated.
[0026] Next, as an example, each aspect and each embodiment will be described with reference to the attached drawings. [Brief explanation of the drawing]
[0027] [Figure 1] This is a flowchart illustrating a method for signing video data according to one embodiment of the present invention. [Figure 2] This figure shows a device configured to perform video data signing according to one embodiment of the present invention. [Modes for carrying out the invention]
[0028] Next, the embodiments of this disclosure will be described more fully below with reference to the accompanying drawings in which certain embodiments of the present invention are shown. However, these embodiments may be carried out in a number of different forms and should not be construed as limiting; rather, these embodiments are provided as examples so as to make this disclosure complete and comprehensive and to fully convey to those skilled in the art the scope of all embodiments of the present invention. Similar numbers refer to similar elements throughout this description.
[0029] Referring to Figure 1, a method 100 for signing video data representing a video sequence (for example, to be encoded) is described. This method 100 is performed by or on behalf of the signer and provides a signature that can be verified by the recipient. Method 100 may be implemented by a general-purpose programmable computer, i.e., a computer with associated input and output interfaces, if appropriately configured. Specifically, method 100 can be performed by a device 200, shown in block diagram form in Figure 2. The device 200 comprises a processing circuit 210, a memory 220, and an input / output interface 230 suitable for bidirectional communication with an external memory 290 for storing the video data to be signed during some operational stage. The device 200 and the external memory 290 may be owned and operated by various entities, such as when the signature is provided as an external service, or by a common entity. The (internal) memory 220 of the device 200 may be suitable for storing a program 221 having software instructions for executing method 100, cryptographic information (e.g., a private key) for generating signatures, variables, and cached data used in fingerprinting, as well as logs, configuration files, and data supporting various internal housekeeping procedures. The device 200 may be provided as a local computer or local server, or it may be implemented in a distributed manner based on networked (cloud) processing resources. Specifically, the device 200 may be integrated into a digital video camera, such as a video camera suitable for surveillance applications, and thus method 100 can be performed on video data generated by this video data before the video data is supplied to an external recipient.
[0030] In the first step 110 of Method 100, video data representing a video sequence is acquired. This video data may or may not have a defined range (duration). Rather, the recording of the video sequence may still be in progress, which is often the case in streaming applications, including live streaming and video surveillance applications. There are known decryption processes adapted to handle incomplete video data, in the sense that it can be supplemented with relatively recent data, and one notable example is the technique described in Recommendation ITU-T H.264 (06 / 2019) "Advanced video coding for generic audiovisual services" (International Telecommunication Union). Similarly, Method 100 has been devised from the desire to carry out signature verification in parallel with this type of decryption process without delay or interference. The act of acquiring the video data may include gaining access to the memory in which the video data is stored (e.g., external memory 290 in Figure 2), downloading the video data, and / or receiving a transmission with the video data.
[0031] In the second step 112, a bitstring b that has not been extracted from the video data is obtained. This bitstring b is a series of binary values. This method 100 does not presuppose that the bitstring indicates, represents, or encodes any information. However, to facilitate the receiver's playback of the bitstring, it may include the time, date, or position of the acquisition (recording) of the video sequence. This acquisition time may point to the start or end. In live or streaming video sequences, it is conceivable to repeatedly generate new salts based on new bitstrings. For example, if the bitstring points to the beginning of a consecutive segment of the recording, the signature would be ready for verification as soon as the acquisition begins, and a high level of security can be maintained by ensuring that the new salt replaces the previous salt. Another option is to extract the bitstring from metadata associated with the video data, such as file system parameters or file format metadata. Yet another option is to insert into such metadata the original information from which the bitstring can be derived by a pre-agreed operation.
[0032] In the third step 114, a salt is generated by hashing the bit string b, i.e., σ = h1(b). This hashing is performed by a hash function (or one-way function) h1, which may be a cryptographic hash function that achieves a level of security deemed appropriate in light of the sensitivity of the video data being signed. Three examples are SHA-256, SHA3-512, and RSA-1024. The hash function h1 is predefined so that the salt and thereby the fingerprint can be regenerated when the fingerprint is verified (for example, it is reproducible). In some embodiments, this hash function h1 is kept secret between the signer and the receiver, which may require securely sharing the definition of the hash function with the receiver (120). Such a step 120, which will be described below, can be performed at any appropriate point before, between, or after such steps, independently of any further steps of Method 100.
[0033] The following describes one implementation of the aforementioned options, in which the original information from which the bit string can be derived by a pre-agreed operation is inserted into the metadata. In this implementation, the information is an integer M selected by the sender. This selection may be random. This integer is Prime factors p1, p2, ..., as in TIFF2023056492000003.tif9170. t It is factorizable into the following, where q1, ..., q t The value is ≥ 1. The salt is calculated as a hash of prime factors combined in ascending, descending, or another pre-agreed order, for example, σ = h1({p1,p2,...,p t}) or σ=h1({p t ,p t-1,..., p1}). As a result, the recipient can retrieve the integer M from the metadata, perform prime factorization, and recalculate the sort to verify the signature of the video data. It is recalled that prime factorization produces a unique result. Therefore, this may also be a pre-agreed operation in this sense when used with an ordering such as ascending or descending order of the resulting factors.
[0034] In the fourth step 116 of method 100, fingerprints F1, F2,... are generated by hashing the video content. For purposes of illustration, it will initially be assumed that fingerprinting is performed at the granularity of one video frame. Both relatively fine granularity and relatively coarse granularity are valid alternatives to this, including fingerprinting a given image band (macroblock) of consecutive frames or fingerprinting consecutive groups of pictures (GOPs).
[0035] On the other hand, the fourth step 116 may include hashing the combination of the sort σ of the video data and the first part π1. F1 = h2({σ, π1}) Here, h2 is the second hash function. The first and second hash functions may be the same, i.e., h1 = h2, or they may be different. The curly brace notation {·} refers to a general data concatenation operation, which may include concatenating the data linearly (juxtaposition) or concatenating it in various staggered arrays. This concatenation operation may further include arithmetic operations on the data, such as bitwise OR, XOR, multiplication, division, or modulo operations. Further fingerprints F2, F3,... can be calculated similarly. That is, F n = h2({σ, π n ) and n ≥ 2. In particular, a preferred option is not to substitute the salt σ. Rather, the salt can be cached after the first fingerprint F1 has been computed (114.1) and retrieved for later use when the second fingerprint and subsequent fingerprints are generated.
[0036] On the other hand, the fourth step 116 may include hashing a combination of the salt σ of the video data and the hash of the first part π1. A simple implementation is as follows: F1=({σ,h2(π1)}) Furthermore, in feasible implementations, higher-order hashes are used. F1=h2({σ,h2(h2(π1))})
[0037] In use cases where the available bitrate is limited, two further implementations generate one fingerprint per GOP. The first implementation generates one fingerprint for every frame π1, π2, ..., π within the GOP. N The goal is to generate a GOP fingerprint based on the hash of the combination of hashes. F GOP1 =h2({σ,h2({h2(π1),h2(π2),...,h2(π N )})}) The second implementation involves repeatedly generating fingerprints of the GOP. TIFF2023056492000004.tif45170 Here, TIFF2023056492000005.tif8170 is a temporary variable that can be discarded once the next element in the sequence has been successfully calculated. In the second implementation, as in the first implementation, h2(π1), h2(π2), ..., h2(π N This eliminates the need to remember the hash. Hash linking also protects frames within the GOP from unauthorized removal, insertion, and reordering.
[0038] In the variations of the above options, the hash function used to perform (one or more) internal hashing operations can be replaced with a third hash function h3 that is different from the second hash function h2 used for external operations.
[0039] A common advantage of this second group of implementation forms of step 116 in the fourth step is that the hash length is fixed and, moreover, generally much shorter than the data required to encode a single video frame or a single GOP. Thus, the combination of salt and hash of video data can be achieved by lightweight memory operations with limited computational cost.
[0040] In the fifth step 118, a signature of the video data is provided, which includes at least one of the generated fingerprints F1, F2... This signature may be formed by collecting the generated fingerprints into a so-called document (a text file or another data structure) and signing this document. For example, the signature of the document may be generated by asymmetric cryptography, i.e., using a private key from a key pair whose public key has been previously shared with the recipient so that the recipient can verify the signature. Thus, the signature of the video sequence may consist of a document and a document signature. Optionally, if the secrecy of the first hash function h1 is preserved, a bit string b may be included in the signature.
[0041] Another option is to provide a signature consisting of multiple sub-signatures S1, S2, S3, ... (118). The sub-signatures may relate to consecutive segments of video data, particularly time segments. If GOP-level signing is applied, the fifth step 118 may also include, for each GOP, providing a document that holds the signature of each frame within that GOP, and generating a signature for the document. Alternatively, according to the low-bitrate option described above, the document is F GOP1This consists of the following. In any case, step 118, which provides the signature, may also include inserting the sub-signatures S1, S2, S3, ... into each segment of the video data. More specifically, the sub-signatures may be inserted into the video bitstream in the vicinity of each time segment, or they may be included in the metadata associated with such time segments. Specifically, GOP-level sub-signatures may be included in the metadata of the first or last frame of the GOP, or they may be included by inserting the sub-signatures into the video bitstream in the vicinity of such frames. This may support the so-called intra-update option in the ITU-T H.264 format.
[0042] Optionally, method 100 may include an additional step 120 in which the definition of a first hash function h1 for generating a salt σ is shared with the recipient of the signed video data via a dedicated communication channel. As already described, the dedicated communication channel may refer to a digital transmission channel protected from unauthorized eavesdropping, including encrypted communications and communications requiring two-channel permission. The definition of the hash function may also be shared in various embedded forms via decryption software or hardware. The definition of the first hash function h1 may be incomplete or limited to specific configuration parameters, and it is understood that this first hash function h1 shall have a standardized or otherwise pre-agreed form. Step 120 may be performed before, after, or in parallel with the other steps of method 100.
[0043] The embodiments of this disclosure have been described primarily with reference to several embodiments. However, as will be readily apparent to those skilled in the art, other embodiments not disclosed herein are equally feasible within the scope of the invention as defined by the appended claims. In practice, Method 100 is not limited to encoded video data, but may be performed on unencoded (i.e., plaintext) video data. Method 100 is also applicable to further encoded video formats, such as AOMedia Video 1 (AV1) and the formats specified in Recommendation ITU-T H.265 (08 / 2021) "High efficiency video coding". [Explanation of Symbols]
[0044] 100 ways 110 First Step 112 Second Step 114 The Third Step 116. The Fourth Step 118. Step 5 120 additional steps 200 equipment 210 Processing Circuit 220 memory 221 Programs 230 Input / Output Interfaces 290 External memory
Claims
Claim 1 A method (100) for signing video data, comprising: obtaining (110) video data representing a video sequence; obtaining (112) a bit string not extracted from the video data; providing a salt based on the bit string; a) combining the salt with a first portion of the video data, or b) combining the salt with a hash of the first portion of the video data to generate (116.1) a first fingerprint by hashing; providing (118) a signature of the video data including the first fingerprint; wherein the salt is provided by hashing (114) the bit string, the salt and the first fingerprint are generated using different hash functions from each other, and the method further comprises sharing (220) a definition of the hash function for generating the salt with a recipient of the signed video data via a dedicated communication path A method comprising the above. Claim 2 a) combining the salt with a second portion of the video data, or b) combining the salt with a hash of the second portion of the video data to further generate (116.2) a second fingerprint by hashing, wherein the signature of the video data further includes the second fingerprint, the method according to claim 1. Claim 3 The method according to claim 2, wherein the first portion and the second portion represent respective time segments of the video sequence. Claim 4 The method according to claim 3, wherein the first portion and the second portion represent respective frames of the video sequence. Claim 5 The method according to claim 3, wherein the first portion and the second portion represent respective independently decodable groups of pictures (GOPs) of the video sequence. Claim 6 further comprising caching (114.1) the salt, wherein generating (116.2) the second fingerprint includes using the cached salt, the method according to claim 2. Claim 7 The method according to claim 1, wherein the first portion of the video data is all the obtained video data. Claim 8 the bit string includes reproducible information related to the acquisition of the video sequence; at least a part of the bit string is extracted from metadata associated with the video data; the original information from which the bit string can be uniquely derived is inserted into metadata associated with the video data; the signature of the video data further includes the bit string The method according to claim 1, wherein at least one of the above is satisfied. **Claim 9** The method according to claim 1, wherein the video sequence is a streaming video sequence. **Claim 10** the video data has a time-series structure, and the signature is composed of a plurality of sub-signatures related to respective segments of the video data, the signature is provided by inserting the sub-signature in or near each of the respective segments of the video data (118). The method according to claim 9. **Claim 11** The method according to claim 1, wherein the signature of the video data is included in metadata associated with the video data. **Claim 12** The method according to claim 1, wherein the signature of the video data is signed using a cipher. **Claim 13** An apparatus (200) comprising a processing circuit (210) configured to execute the method according to any one of claims 1 to 12. **Claim 14** A computer program (221) comprising instructions for causing a computer to execute the method according to any one of claims 1 to 12 when executed on the computer.