Video transmitting apparatus, video receiving apparatus, video system, video transmitting method, video receiving method, and program
By switching communication methods and recording video data securely, the video receiving and transmitting devices ensure the continued reception of untampered data after tampering detection.
Patent Information
- Application Number
- JP2024088419
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-05-30
- Publication Date
- 2025-12-11
AI Technical Summary
Existing video tampering detection technologies fail to ensure the continued reception of untampered video data after detection of tampering.
A video receiving device and transmitting device configured to switch communication methods upon detecting tampering, enabling the recording and transmission of video data using alternative protocols to prevent further tampering.
Enhances the likelihood of receiving untampered video data by changing communication methods and recording video data securely upon detection of tampering.
Smart Images

Figure 2025180816000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to video technology. [Background technology]
[0002] There is technology to detect tampering with video data. Regarding tampering detection, ONVIF, a standard for connecting imaging devices and client devices, is currently standardizing methods for adding tamper detection data to video data. ONVIF stands for Open Network Video Interface Forum.
[0003] In ONVIF, a system is being considered in which the imaging device attaches a digital signature based on the hash value of the video data to the SEI included in the NAL unit of an encoding format such as H.264 or H.265 and transmits the SEI. The client device is also considering determining whether the video data has been tampered with by comparing the received digital signature with the hash value of the video data. Here, NAL unit is a Network Abstraction Layer unit, and SEI is Supplemental Enhancement Information.
[0004] Regarding technology for detecting such video tampering, Patent Document 1 describes a technique for displaying the verification result of whether or not video data has been tampered with. Patent Document 1 also discloses that if the video data has not been tampered with, the video data is output, and if the video data has been tampered with, the video data is not output. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] Patent Publication No. 2017-41841 Summary of the Invention [Problem to be solved by the invention]
[0006] The technology described in Patent Document 1 can display the verification result regarding whether or not video data has been tampered with. However, if video data is tampered with, there is a problem in that untampered video data cannot be received thereafter.
[0007] Therefore, an object of the present invention is to provide a technique that can increase the possibility of receiving untampered video data when tampering of video data is detected. [Means for solving the problem]
[0008] In order to solve the above problems, a video transmitting device of the present invention has the following configuration: A video receiving device that communicates with a video transmitting device using at least a first method, the video receiving device having a receiving means for receiving video data in communication using the first method, a determining means for determining whether the received video data has been tampered with, and a transmitting means for transmitting a command to the video transmitting device to start communication using a second method different from the first method when it is determined that the received video data has been tampered with.
[0009] In order to solve the above problems, the video receiving device of the present invention has the following configuration: a video transmitting device that communicates with a video receiving device using at least a first method, the video transmitting device having receiving means for receiving information indicating that video data received by the video receiving device in communication using the first method has been tampered with, and control means for starting communication with the video receiving device using a second method different from the first method when the information is received. [Effects of the Invention]
[0010] According to the present invention, when tampering with video data is detected, it is possible to increase the possibility of receiving untampered video data. [Brief explanation of the drawings]
[0011] [Figure 1] FIG. 1 is a diagram illustrating a network configuration according to each embodiment. [Figure 2] FIG. 1 is a block diagram showing a configuration of an imaging device according to each embodiment. [Figure 3] FIG. 2 is a block diagram showing the configuration of a controller according to each embodiment. [Figure 4] FIG. 4 is a sequence diagram showing a processing method when video tampering is detected according to the first embodiment. [Figure 5] 3 is a flowchart showing a video tampering detection method according to the first embodiment. [Figure 6] FIG. 11 is a sequence diagram showing a processing method when video tampering is detected according to the second embodiment. [Figure 7] FIG. 2 is a diagram illustrating an example of a hardware configuration according to each embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0012] Embodiments of the present invention will be described in detail below with reference to the accompanying drawings. The embodiments described below are merely examples of implementations of the present invention. The present invention may be modified or altered as appropriate depending on the configuration and various conditions of the device to which the present invention is applied, and is not necessarily limited to the following embodiments. Furthermore, not all of the combinations of configurations described in the embodiments are necessarily essential to the solution of the present invention. The term "video" below does not necessarily refer to video, but may also refer to still images. Tampering with video data can involve changing the content of a video by deleting, adding, or replacing specific frames from the video. It can also involve replacing specific items or people in the video with other items. Other examples include so-called deep fakes, which use AI technology to alter a video. The type of tampering that is effective depends on the tampering detection technology employed. While tampering detection technologies will be discussed later, the present invention is applicable to various tampering detection methods, not just the methods described below. It is sufficient that the present invention is effective against at least tampering that can be detected by the tampering detection technology. The present invention can be used in a variety of video-related applications. In each embodiment, the transmission of the "response" may be omitted as appropriate.
[0013] First Embodiment A first embodiment of the present invention will be described below with reference to FIGS.
[0014] FIG. 1 is a network configuration diagram including an imaging device (video transmission device) 1000. 2000 is a client device (video reception device) in this embodiment. A video system is constructed by the imaging device 1000 and the client device 2000. Note that the imaging device 1000 will be described as an example of a video transmission device. Also, the client device 2000 will be described as an example of a video reception device. These are merely examples, and the present invention can be applied to other devices. For example, a distribution server may be provided outside the imaging device 1000, and the distribution server may have the function of a video transmission device.
[0015] The imaging device 1000 is connected to the client device 2000 via a network 3000 so that they can communicate with each other. The client device 2000 transmits various commands (information) for controlling the video format, angle of view, image quality, etc. to the imaging device 1000. The imaging device 1000 executes processing according to the commands and transmits responses to the commands to the client device 2000.
[0016] Fig. 2 is a block diagram showing the configuration of the imaging device 1000. In Fig. 2, a control unit 1001 performs overall control of the imaging device 1000. The control unit 1001 can be realized by, for example, a CPU.
[0017] The memory unit 1002 is mainly used as a storage area for programs executed by the control unit 1001, a work area during program execution, a temporary storage area for video data generated by the imaging unit 1003 (described later), and various other data.
[0018] The imaging unit 1003 has an imaging element, etc. The imaging unit 1003 captures an image of a subject formed by an imaging mechanism 1004 (described later), converts the acquired video signal into digital data (video data), and outputs the digital data to the storage unit 1002 as a captured image.
[0019] The imaging mechanism 1004 has an imaging optical system including lenses and other optical components, etc. The imaging mechanism 1004 may also have a pan mechanism, tilt mechanism, and zoom mechanism for controlling the imaging direction and angle of view.
[0020] The encoding unit 1005 compresses and encodes the video data captured by the imaging unit 1003 in a format that complies with standards such as H.264 and H.265. The compression and encoding method can also be a method that complies with any other standard, such as AV1 or H.266.
[0021] When performing compression encoding, the encoding unit 1005 calculates a hash value of the video data, encrypts it, and then adds the resulting digital signature to the video data as data for tamper detection, for example by describing the digital signature in the SEI included in the NAL unit.
[0022] The encoding unit 1005 also generates a pair of a public key and a private key. This public key and private key pair is used to create a digital signature and is generated independently by the imaging device 1000.
[0023] Next, the control unit 1001 transmits the generated public key data to the client device 2000 via the communication unit 1008. The communication unit 1008 functions as a transmitting unit and a receiving unit.
[0024] Furthermore, the encoding unit 1005 generates a hash value based on the features extracted from the video data as described above.
[0025] First, the encoding unit 1005 extracts features from each frame of video. These features can be image brightness, contrast, edge information, color distribution, or other visual features. Any features can be used. The video features used here are selected based on the content of the video.
[0026] The encoding unit 1005 then optionally combines the extracted features to generate a unique hash value.
[0027] Next, the encoding unit 1005 encrypts the generated hash value using a private key. This encrypted hash value functions as a digital signature and is transmitted to the video data and the client device. As an example, such a digital signature is generated for each frame and attached to the video data. As another example, a digital signature may be attached for each GOP (Group Of Pictures).
[0028] In this way, as an example, the encoding unit 1005 also functions as a generating unit that generates data for detecting tampering (a digital signature based on a hash value). It also functions as an assigning unit that assigns data for detecting tampering to video data. However, components other than the encoding unit 1005 may have such a function. For example, the control unit 1001 may have such a function.
[0029] Furthermore, as will be described later, when a tampering detection method is used that does not require the video transmission side to add data for detecting tampering to the video data, the imaging device 1000 does not necessarily need to have such a generating means or adding means.
[0030] The video data generated as described above is output to the storage unit 1002 and temporarily stored therein.
[0031] The recording control unit 1006 controls the recording of video data captured by the imaging unit 1003. When recording video data, the video data stored in the storage unit 1002 is recorded (accumulated) in the recording unit 1007, which will be described later. The recording control unit 1006 may also record the video data directly from the imaging unit 1003 to the recording unit 1007.
[0032] The recording unit 1007 is used as a storage area for saving captured video data. The recording unit 1007 can be realized using a recording device such as an HDD or SSD. Alternatively, the recording unit 1007 may be realized using an SD card slot or the like so that external recording media can be used. Alternatively, the data may be recorded in the recording unit 1007 external to the imaging device 1000 via a USB terminal, a network, or the like.
[0033] The communication unit 1008 receives change commands and control commands for changing various setting values from the client device 2000 via the network 3000. The communication unit 1008 also transmits various data such as responses to each command and video data to the client device 2000. The commands are, for example, commands that comply with the ONVIF standard, but commands that comply with various other standards can also be used.
[0034] The basic configuration of the imaging device 1000 has been described above using Fig. 2, but the processing blocks shown in Fig. 2 are merely an example of an embodiment of the information processing device in this embodiment, and are not limited to this. Various modifications and changes are possible within the scope of the gist of the present invention, such as including an audio input unit and an audio output unit.
[0035] FIG. 3 is a block diagram showing the configuration of the client device 2000.
[0036] The control unit 2001 is realized by, for example, a CPU, and controls the entire client device 2000 .
[0037] The memory unit 2002 is mainly used as a storage area for programs executed by the control unit 2001, a work area during program execution, and a storage area for various data such as information indicating connectable imaging devices currently present on the network 3000.
[0038] The display control unit 2003 displays various setting screens, a display screen for acquiring data, a viewer for images received from the imaging device 1000, various messages, etc. on a display unit (not shown). The display unit is realized by, for example, an LCD display or an organic EL display.
[0039] The tampering detection unit (tampering determination unit) 2004 determines whether the video data received from the image capture device 1000 has been tampered with. The tampering detection unit 2004 determines whether the video data has been tampered with by, for example, comparing data included in the NAL unit of the video data received from the image capture device 1000 with a hash value calculated from the video data.
[0040] The tampering detection unit 2004 acquires a digital signature based on the hash value added to the received video data. The tampering detection unit 2004 also acquires public key data in advance via the communication unit 2006. A tampering detection method using a digital signature will be described later.
[0041] Note that data for detecting tampering (digital signature based on hash values) does not necessarily have to be added to the video data. In this case, the tampering detection unit 2004 uses a tampering detection method that does not use data such as hash values. Some examples of such methods are given below.
[0042] For example, the tamper detection unit 2004 may detect tampering using a technique based on compression artifacts. This technique determines whether tampering has occurred by analyzing artifacts related to the compression history of video data. This technique uses an algorithm that detects specific patterns and noise discontinuities that occur during compression. In particular, non-uniformity in quantization matrices and the presence of unnatural edges at block boundaries are indicators of tampering.
[0043] The tampering detection unit 2004 may also detect tampering using a technique that analyzes image noise patterns. This technique uses sensor noise and patterns in image processing to detect whether the video has been tampered with. It analyzes the noise characteristics (Photo Response Non-Uniformity: PRNU) specific to the camera sensor, and if these are inconsistent across each frame of the video, it determines that tampering is highly likely.
[0044] The tampering detection unit 2004 may also detect tampering using a detection technique that uses machine learning. This technique uses a machine learning model to learn and identify characteristic artifacts caused by various tampering techniques. In particular, it trains a convolutional neural network (CNN) or a generative adversarial network (GAN) to detect tampered video with high accuracy. This method trains the model using a large amount of normal video data and tampered video data, achieving robust detection performance even for new data.
[0045] The tampering detection unit 2004 may also detect tampering using a detection technique based on multimodal analysis. This technique improves the accuracy of tamper detection by simultaneously analyzing multiple features of video data. By combining and analyzing information such as video image quality indicators, audio frequency spectrum, and metadata, multiple clues necessary to identify tampering are provided.
[0046] As described above, the tampering detection unit 2004 can detect tampering by analyzing the received video data. The tampering detection unit 2004 can also use various other tampering detection techniques.
[0047] 3, the input unit 2005 is realized by, for example, a keyboard, buttons, a cross key, a touch panel, a mouse, etc., and their input interfaces, and notifies the control unit 2001 of the contents of operations performed by the user. The user may perform operations while viewing the user interface displayed on the display unit.
[0048] The communication unit 2006 transmits various commands, including a command for starting video recording, to the image capture device 1000 via the network 3000. The communication unit 2006 also receives responses to the transmitted commands and video data from the image capture device 1000. In this way, the communication unit 2006 functions as a transmitting unit and a receiving unit.
[0049] The basic configuration of client device 2000 has been described above using Fig. 3, but the processing blocks shown in Fig. 3 are merely an example of an embodiment of a video receiving device according to the present invention, and are not limited to this. Various modifications and changes are possible within the scope of the gist of the present invention, such as a configuration including an image analysis unit and a recording unit.
[0050] Next, with reference to the sequence diagram of FIG. 4, a process according to this embodiment when video tampering is detected will be described.
[0051] In S1001, the control unit 2001 of the client device 2000 transmits a command (distribution start request) to the imaging device 1000 via the communication unit 2006 to cause the imaging device 1000 to start transmitting video data. This command may be, for example, a command conforming to the ONVIF standard. Alternatively, a method of requesting distribution via RTP using an RTSP command may be used, or another method may be used. RTSP is Real Time Streaming Protocol. RTP is Real-time Transport Protocol.
[0052] When the imaging device 1000 receives the distribution start request command, the imaging device 1000 determines whether video distribution is possible with the settings included in the distribution start request and responds with the determination result. In other words, the imaging device 1000 transmits a response indicating the determination result to the client device 2000.
[0053] If distribution is possible, in S1002, the control unit 1001 of the imaging device 1000 starts distribution (transmission) of the video data via the communication unit 1008 with the settings included in the distribution start request. This video data is provided with data for tamper detection as needed. As an example, the video data is distributed in a stream format, but this is not limiting. For example, the video data may be transmitted in a file format or as a still image.
[0054] In S1003, the tampering detection unit 2004 of the client device 2000 detects whether the received video data has been tampered with. The tampering detection method can be any of the methods described in each embodiment. Multiple tampering detection methods can also be combined.
[0055] An example of a method for detecting tampering in the client device 2000 in step S1003 will now be described with reference to Fig. 5. This method uses a digital signature.
[0056] In S1011, the tampering detection unit 2004 decrypts the encrypted digital signature attached to the received video data using the public key separately received from the image capture device 1000. This decryption results in a hash value based on the video data generated by the image capture device 1000. Note that, as an example, the encrypted digital signature is obtained from the SEI of the video data.
[0057] In S1012, the tampering detection unit 2004 applies the same hash function as that used by the image capturing device 1000 to the received video data to calculate a hash value.
[0058] In S1013, the tampering detection unit 2004 compares the hash value assigned to the received video data with the hash value calculated by the tampering detection unit 2004 from the received video data. If the hash values match in S1013, it is determined that no tampering has occurred. On the other hand, if the hash value assigned to the video data does not match the hash value calculated from the received video data in S1013, the tampering detection unit 2004 determines that the video has been tampered with. Then, in S1004, the control unit 2001 transmits a request command to the imaging device 1000 via the communication unit 2006 to stop video distribution.
[0059] It is not necessary to send a request command to stop the video distribution. In other words, the video distribution may be continued. In this case, the display control unit 2003 may display information on the display unit to notify the user that the video has been tampered with, but this is not necessarily required.
[0060] 4, when a request command to stop video distribution is transmitted from the client device 2000 to the imaging device 1000 in S1004, the imaging device 1000 stops the distribution of video data and then transmits a response to the client device 2000 indicating that the distribution of video data has been stopped.
[0061] If it is determined in S1003 that the video data has been tampered with, the processes of S1005 to S1008 are performed. On the other hand, if it is determined in S1003 that the video data has not been tampered with, the processes of S1005 to S1008 are not performed. Furthermore, the processes of S1005 to S1008 are, as an example, performed automatically without any new instructions from the user, but may also be performed after a UI such as a message for confirming whether or not to perform these processes is displayed on the display unit and the user's confirmation is obtained.
[0062] If the tampering detection unit 2004 determines that the received video data has been tampered with, the following process is performed. That is, in S1005, the control unit 2001 of the client device 2000 transmits a request command (video recording start request command) to the image capture device 1000 via the communication unit 2006 to cause the image capture device 1000 to start recording video data. For example, the recording of video data can be started by a SetRecordingJobMode command or a SetRecordingJobConfiguration command in the ONVIF standard. Alternatively, a unique command for starting the recording of video data can be set in advance via a network using an HTTP request or the like, and transmitted to the image capture device 1000. Any command for causing the image capture device (video transmission device) 1000 to start recording video data can be used.
[0063] In S1006, upon receiving this request command, the imaging device 1000 starts recording video data. Specifically, upon receiving the video recording start request command, the recording control unit 1006 of the imaging device 1000 starts recording video data to the recording unit 1007. As described above, the recording unit 1007 itself may be provided outside the imaging device 1000.
[0064] The recording control unit 1006 can also control the recording unit 1007 to record video from the time when the video recording start request command is received. If video at the time when it is determined that the video data has been tampered with is stored in the storage unit 1002, the recording unit 1007 may record video data from that time onward. If video before the time when it is determined that the video data has been tampered with is stored in the storage unit 1002, the recording unit 1007 may also record that video data. That is, the start time of the target video data may be the timing when the video recording start request is received, or the imaging device 1000 may hold video data for a certain period of time in advance and record video from the certain period of time before that. In any case, recording of the video data and related video data may be started in response to receiving information (notification) indicating that the video data has been tampered with. A predetermined command, a flag, or various other types of information may be used as the information indicating that the video data has been tampered with.
[0065] The control unit 1001 of the imaging device 1000 transmits a response indicating that video recording has started to the client device 2000 via the communication unit 1008.
[0066] The above-described processes in S1005 and S1006 are aimed at protecting untampered video data, particularly in the event that video data has been tampered with.
[0067] The order of the processes in S1004 and S1005 may be reversed, i.e., S1005 may be executed first.
[0068] Next, the processes of S1007 and S1008 will be described. These processes are intended to increase the possibility that the client device (video receiving device) 2000 can receive untampered video data, especially after tampering of the video data is detected.
[0069] If the tampering detection unit 2004 determines that the video data received in the first format has been tampered with, the following process is performed in S1007. That is, the control unit 2001 of the client device 2000 issues a new video distribution start request to the imaging device 1000 via the communication unit 2006, using a second format different from the previous format. That is, a video distribution start request is issued using a format different from the distribution start request of S1001. For example, if a distribution request using RTP has been issued in S1001, a command may be sent to start transmitting video data using a confidential (encrypted) protocol (communication format) such as SRTP (Secure RTP). Alternatively, if a distribution request using a standardized protocol such as RTP has been issued in S1001, a video distribution request may be issued using a unique distribution format that is different from the standard and that can be used by both the imaging device 1000 and the client device 2000. Alternatively, a file transfer function using FTP or HTTP may be further provided, and video transmission may be requested using the file transfer protocol. In this case, the file may be transferred to a server different from the client device 2000.
[0070] In any case, if the tampering detection unit 2004 determines that the video data has been tampered with, video distribution should be started using a distribution method different from the method that was used up until then. Video tampering is often carried out by illegally extracting video streams during distribution, so changing the video distribution method makes it more difficult to extract video, further reducing the possibility of video tampering.
[0071] Upon receiving a request to start video distribution using a method different from that used before video tampering was detected, the image capturing device 1000 transmits a response to the image capturing device 100 notifying that the video distribution will start. Then, in S1008, the control unit 2001 of the client device 2000 starts distributing the video data in the newly specified distribution method via the communication unit 2006. The video data may be provided with the aforementioned data for detecting tampering.
[0072] As described above, the processes of S1007 and S1008 are intended to increase the possibility that the client device (video receiving device) 2000 can receive untampered video data, particularly after tampering with the video data is detected. Therefore, to achieve this purpose, the processes of S1005 and S1006 for protecting untampered video data can be omitted. Specifically, the processes of starting recording of video data or changing recording settings when tampering with video data is detected may be omitted.
[0073] On the other hand, in order to achieve the purpose of protecting untampered video data, the processes of S1007 and S1008 do not necessarily have to be performed.
[0074] As described above, the processes shown in FIGS. 4 and 5 can be selected as appropriate depending on the purpose and the problem to be solved.
[0075] Although the present embodiment has been described above, the processing described above is merely an example of an embodiment of the processing of the present invention, and is not limited to this.
[0076] For example, the video distribution described in S1007 and S1008 may be additionally performed without making a request to stop video distribution in S1004. Also, after confirming in S1008 that the additionally distributed video has not been tampered with, the original video distribution (stream) may be stopped.
[0077] In addition, an example has been described in which, when it is determined that the video data has been tampered with, in S1005, the control unit 2001 of the client device 2000 sends a request command to the imaging device 1000 via the communication unit 2006 to instruct the imaging device 1000 to start recording the video data.
[0078] However, instead of transmitting this request command, the control unit 2001 of the client device 2000 may transmit information (notification) indicating that the video data has been tampered with to the imaging device 1000. The information indicating that the video data has been tampered with may be any information as long as it can be determined in advance between the imaging device 1000 and the client device 2000. The information indicating that the video data has been tampered with may be a predetermined command, a flag, or any other type of information. In any case, the information may be such that, upon receiving the information, the imaging device 1000 can start recording the video data without receiving a command directly instructing the imaging device 1000 to start recording. If the imaging device 1000 and the client device 2000 are manufactured by the same manufacturer, it may be possible to determine in advance how to notify the client device 1000 of video tampering with any information. If the imaging device 1000 and the client device 2000 are not manufactured by the same manufacturer, it is preferable to use a predetermined standard command.
[0079] In S1006, upon receiving this information, the imaging device 1000 starts recording the video data. Specifically, upon receiving information indicating that the video data has been tampered with, the recording control unit 1006 of the imaging device 1000 starts recording the video data to the recording unit 1007. As described above, the recording unit 1007 itself may be provided outside the imaging device 1000.
[0080] As in the example using a request command (video recording start request command), the recording control unit 1006 can control the recording of video from the time the video recording start request command is received. If video at the time when it is determined that the video data has been tampered with is stored in the storage unit 1002, the video data may also be recorded in the recording unit 1007. If video before the time when it is determined that the video data has been tampered with is stored in the storage unit 1002, the video data may also be recorded in the recording unit 1007. That is, the start time of video recording may be the timing when the video recording start request is received, or the imaging device 1000 may hold video data for a certain period of time in advance and record video from the certain period of time before. In any case, recording of the video data and related video data may be started in response to receiving information indicating that the video data has been tampered with.
[0081] Then, the control unit 1001 of the imaging device 1000 transmits a response indicating that video recording has started to the client device 2000 via the communication unit 1008.
[0082] While the tampering continues, the control unit 2001 of the client device 2000 may transmit information (notification) indicating that the video data has been tampered with to the imaging device 1000 at regular intervals (e.g., 5 seconds). In this case, after S1006, if the information indicating that the video data has been tampered with is not received for a predetermined time (e.g., 5 minutes) or more, the recording of the video may be stopped.
[0083] Furthermore, the new video distribution start request sent in S1007 may be a request to start playing the video that began recording in S1006. Furthermore, instead of performing video distribution in S1008, the imaging device 1000 may further include an email forwarding function, and may forward the recorded video data and information related to the video recording by email to a pre-set address using an email communication protocol.
[0084] As described above, simply starting video recording in response to tampering detection in S1003 has the effect of protecting video that has not been transmitted over the network at the time of tampering on the imaging device 1000 side. Therefore, to achieve this effect, it is not necessary to request video distribution start using a different distribution method in S1007 or to distribute video in S1008. However, by requesting video distribution start and distributing video using different distribution requests, it is possible to reduce the possibility of tampering on the network path. Therefore, conversely, to achieve this effect, it is not necessary to start video recording in response to tampering detection in S1003.
[0085] Second Embodiment The second embodiment will be described below with reference to FIGS. 1 to 3 and 6. FIG.
[0086] Note that the basic configuration of the network in Fig. 1, the basic configuration of the imaging device 1000 in Fig. 2, and the basic configuration of the controller 2000 in Fig. 3 are the same as those in the first embodiment, and therefore descriptions thereof will be omitted. Furthermore, descriptions of other parts that are the same as those in the first embodiment will be omitted as appropriate.
[0087] The process performed when video tampering is detected according to this embodiment will be described with reference to the sequence diagram of FIG.
[0088] In S1101, the control unit 2001 of the client device 2000 transmits, via the communication unit 2006, a request command (video recording start request command) to the imaging device 1000 to instruct the imaging device 1000 to start recording video data.
[0089] In S1102, the imaging device 1000 receives this request command via the communication unit 1008 and starts recording video data. Specifically, upon receiving the video recording start request command, the recording control unit 1006 of the imaging device 1000 starts recording video data to the recording unit 1007. As described above, the recording unit 1007 itself may be provided outside the imaging device 1000.
[0090] The recording control unit 1006 can also control the recording unit 1007 to record video starting from the time when the video recording start request command is received. If video data prior to the time when the video recording start request command is received is stored in the storage unit 1002, the recording unit 1007 may also record that video data. That is, the start time of video recording may be the timing when the video recording start request is received, or the imaging device 1000 may retain video data for a certain period of time in advance and record video from the certain period of time prior. Furthermore, video recording may be performed based on pre-set settings, even without receiving a video recording start request command. For example, if the imaging device 1000 is set to always record video data, the imaging device 1000 will always record video. Alternatively, the imaging device 1000 may start recording video data when an event, such as human detection, occurs. In any case, this embodiment assumes that video data recording has been performed before tampering is detected.
[0091] In S1102, when video recording is started in response to the video recording start request command, the control unit 1001 of the imaging device 1000 transmits a response indicating that video recording has started to the client device 2000 via the communication unit 1008.
[0092] In S1103, the control unit 2001 of the client device 2000 transmits a command (distribution start request) to the imaging device 1000 via the communication unit 2006 to start transmitting video data. This command may be, for example, a command conforming to the ONVIF standard or an RTSP command. Alternatively, a method of requesting RTP distribution using an RTSP command or another method may be used.
[0093] When the imaging device 1000 receives the distribution start request command via the communication unit 1008, the imaging device 1000 determines whether video distribution is possible with the settings included in the distribution start request and responds with the determination result. In other words, the imaging device 1000 transmits a response indicating the determination result to the client device 2000.
[0094] In S1104, the control unit 1001 of the imaging device 1000 starts transmitting the video data with the settings included in the distribution start request via the communication unit 1008. This video data is provided with data for tamper detection as necessary.
[0095] In S1105, the tampering detection unit 2004 of the client device 2000 detects whether the received video data has been tampered with. The tampering detection method can be any of the methods described in the first embodiment. A combination of multiple tampering detection methods may also be used. The method for determining whether tampering has occurred is the same as that described in S1003, so a description thereof will be omitted.
[0096] If it is determined in S1105 that the video data has been tampered with, in S1106, the control unit 2001 of the client device 2000 sends a request command to the imaging device 1000 via the communication unit 2006 to stop the video distribution.
[0097] If a request command to stop video distribution is transmitted to the imaging device 1000, the imaging device 1000 stops the distribution of video data in S1106 and then transmits a response to the client device 2000 indicating that the distribution of video data has been stopped.
[0098] As in the first embodiment, it is not necessary to send a request command to stop the video distribution. In other words, the video distribution may be continued. In this case, the display control unit 2003 may display information on the display unit to notify the user that the video has been tampered with, but this is not necessarily required.
[0099] If it is determined in S1105 that the video data has been tampered with, the processes of S1107 to S1110 are performed. On the other hand, if it is determined in S1105 that the video data has not been tampered with, the processes of S1107 to S1110 are not performed. Furthermore, as an example, the processes of S1107 to S1110 are performed automatically without any new instructions from the user. However, if it is determined that the video data has been tampered with, a message or the like may be displayed to confirm whether or not to perform the processes of S1107 to S1110, and the processes may be performed after obtaining the user's confirmation.
[0100] If it is determined that the video data has been tampered with, in S1107, the control unit 2001 of the client device 2000 sends a request command (a request command to change the recording settings) to the imaging device 1000 via the communication unit 2006 to instruct the imaging device 1000 to change the recording settings of the video data.
[0101] Here, we will explain how this change request command changes the video recording being performed by the image capture device 1000. If at least one of the following changes is instructed, protection of untampered video data can be further strengthened in the event that video data is tampered with.
[0102] An example of changing the video recording settings is to lengthen the retention period of recorded video. Because the capacity of the recording unit that records video captured by the image capture device 1000 is limited, the setting may be such that the video is overwritten after a certain period of time has passed. For example, if the setting is to overwrite after 24 hours, a command to change this to 48 hours is sent from the client device 2000 to the image capture device 1000. The time presented here is an example.
[0103] As an example, the following commands can be used to change the settings related to video data recording. For example, the change can be instructed using the Max Retention Time of the Recording Control command in the ONVIF standard. Another method is to set a unique command in advance to change the settings related to video data recording via a network using an HTTP request or the like, and send this command to the image capture device 1000. Any command will do as long as it causes the image capture device (video transmission device) 1000 to change the video data recording settings.
[0104] If the image capture device 1000 and the client device 2000 are manufactured by the same manufacturer, it is possible to decide in advance to notify the client device of any information that has been used to tamper with the video. If the image capture device 1000 and the client device 2000 are not manufactured by the same manufacturer, it is advisable to use a predetermined standard command.
[0105] Other examples of the change request command include the following: For example, if the setting is such that data is overwritten after a certain period of time has elapsed, the command may be to stop (prohibit) such overwriting for newly recorded video data. Alternatively, the command may be to make changes to protect recorded video data. Furthermore, a command may be sent to improve the image quality of the video to be recorded in order to improve the visibility of the protected video data.
[0106] The above is just one example, and any change that can be triggered by the occurrence of video data tampering and further strengthens the protection of the video data at the distribution source is acceptable. Note that the order of the processing of S1106 and the processing of S1107 and S1108 may be reversed. In other words, the processing of S1107 and S1108 may be executed before S1106.
[0107] Upon receiving the command requesting a change in recording settings, the imaging device 1000 changes the settings in response to the request in step S1108, and then continues recording video data with the changed settings.
[0108] For example, when a command is issued to extend the storage time of the video, the recording control unit 1006 of the image capturing device 1000 changes the time until the video is overwritten.
[0109] Furthermore, when a command to stop (prohibit) overwriting is received, the recording control unit 1006 of the imaging device 1000 continues recording without overwriting the video thereafter.
[0110] Furthermore, in the case of a command to improve the image quality of the video to be recorded, the recording control unit 1006 of the imaging device 1000 continues recording with the changed image quality. The image quality here refers to resolution, bit depth, and the like.
[0111] The control unit 1001 of the imaging device 1000 transmits a response indicating that the video recording settings have been changed to the client device 2000 via the communication unit 1008.
[0112] The above-described processes in S1005 and S1006 are aimed at protecting untampered video data, particularly in the event that video data has been tampered with.
[0113] Next, the processes of S1109 and S1110 will be described. These processes are intended to increase the possibility that the client device (video receiving device) 2000 can receive untampered video data, especially after tampering of video data is detected.
[0114] If the tampering detection unit 2004 determines that the video data has been tampered with, in S1109, the control unit 2001 of the client device 2000 sends a new video distribution start request to the imaging device 1000 via the communication unit 2006. At this time, the request to start video distribution is made using a distribution method different from the distribution started in S1102 or the previous distribution method. For example, if a distribution request using RTP was made in S1001, a command may be sent to start transmitting video data using a confidential (encrypted) protocol (communication method) such as SRTP (Secure RTP). Alternatively, if a distribution request using a standardized protocol such as RTP was made in S1001, a method may be used in which a video distribution request is made using a unique distribution method that is different from the standard and can be used by both the imaging device 1000 and the client device 2000. Alternatively, a method may be used in which a file transfer function using FTP or HTTP is further provided and video transmission is requested using the file transfer protocol. In this case, a method may be used in which the file is transferred to a server different from the client device 2000.
[0115] In any case, if the tampering detection unit 2004 determines that the video data has been tampered with, the video distribution should be started using a distribution method different from the method that was used up until then. Video tampering is often carried out by illegally extracting video streams that are being distributed, so changing the video distribution method can prevent further video tampering.
[0116] Upon receiving a request to start video distribution using a method different from that used before video tampering was detected, the imaging device 1000 transmits a response to the imaging device 1000 notifying that the video distribution will begin. Then, in S1110, the control unit 1001 of the imaging device 1000 starts distributing video data in the newly specified distribution method via the communication unit 1008. This distributed video data may be provided with the aforementioned data for detecting tampering.
[0117] As described above, the processes of S1109 and S1110 are intended to increase the possibility that the client device (video receiving device) 2000 can receive untampered video data, particularly after tampering with video data is detected. Therefore, to achieve this purpose, the processes of S1107 and S1108 for protecting untampered video data can be omitted. Specifically, the configuration itself for starting recording of video data or changing recording settings when tampering with video data is detected may be omitted.
[0118] On the other hand, in order to achieve the purpose of protecting untampered video data, the processes of S1109 and S1110 do not necessarily have to be performed.
[0119] As described above, the processes shown in FIG. 6 can be selected as appropriate depending on the purpose and the problem to be solved.
[0120] The processing performed when video tampering is detected according to this embodiment has been described above with reference to FIG. 6. However, the processing shown in FIG. 6 is merely an example of an embodiment of internal processing according to the present invention, and is not limited to this.
[0121] For example, the video distribution described in S1110 may be additionally performed without making a request to stop the video distribution in S1106. Also, after confirming that the additionally distributed video in S1110 has not been tampered with, the original video distribution (stream) may be stopped.
[0122] Also, in the above example, when it is determined that the video data has been tampered with, the control unit 2001 of the client device 2000 transmits, in step S1107, a change request command to the imaging device 1000 via the communication unit 2006, instructing the imaging device 1000 to change the recording settings of the video data. However, instead of transmitting this command, the control unit 2001 of the client device 2000 may transmit, to the imaging device 1000, information (notification) indicating that the video data has been tampered with. The information indicating that the video data has been tampered with may be a predetermined command, a flag, or any other type of information. The information indicating that the video data has been tampered with may be any information as long as it can be determined in advance between the imaging device 1000 and the client device 2000. In any case, the information may be such that, when the imaging device 1000 receives the information, the imaging device 1000 can change the recording settings of the video data without receiving a command directly instructing the imaging device 1000 to change the recording settings.
[0123] In S1108, the imaging device 1000 receives this information via the communication unit 1008 and changes the recording settings for the video data. Specifically, upon receiving information indicating that the video data has been tampered with, the recording control unit 1006 of the imaging device 1000 changes the recording settings for the video data in the recording unit 1007 and starts recording the video with the new settings. As described above, the recording unit 1007 itself may be provided outside the imaging device 1000.
[0124] Then, the control unit 1001 of the imaging device 1000 transmits a response indicating that the video recording settings have been changed to the client device 2000 via the communication unit 1008.
[0125] While the tampering continues, the control unit 2001 of the client device 2000 may transmit information (notification) indicating that the video data has been tampered with to the imaging device 1000 at regular intervals (e.g., 5 seconds).
[0126] In this case, after S1108, if information indicating that the video data has been tampered with is not received for a certain period of time (for example, 5 minutes or more), the video recording settings may be restored.
[0127] The request to start video distribution in S1109 may be a request to start playing the video that began recording in S1102. In this case, the client device 2000 may request the recorded video from the time tampering was detected in S1109, or may request all the video from the start of recording.
[0128] Also, instead of distributing the video in S1109, an email forwarding function may be provided and the recorded video and information about the video recording may be forwarded by email using an email communication protocol. The change in recording settings in S1108 may be a change in settings to encrypt the recording disc, and the encrypted information may be forwarded using the email forwarding function described above.
[0129] Note that simply changing the video recording settings in response to tampering detection in S1105 has the effect of protecting recorded video that has not been transmitted over the network at the time of tampering on the imaging device 1000 side. Therefore, to achieve this effect, it is not necessary to issue a video distribution start request using a different distribution method in S1109 or to distribute video in S1110. However, by requesting to start video distribution and distributing video using different distribution requests, it is possible to reduce the possibility of tampering on the network path. Therefore, to achieve this effect, it is not necessary to change the video recording settings in response to tampering detection in S1105.
[0130] Although the embodiments of the present invention have been described above, the present invention is not limited to these embodiments, and various modifications and changes are possible within the scope of the gist of the present invention.
[0131] (Other Examples) The hardware configuration for realizing each function of the image capture device 1000 and the client device 2000 according to the embodiment of the present invention will be described with reference to FIG.
[0132] The RAM (Random Access Memory) 702 temporarily stores computer programs executed by the CPU (Central Processing Unit) 701. The RAM 702 also temporarily stores data (commands and video data) acquired from the outside via the communication interface 704. The RAM 702 also provides a work area used by the CPU 701 when executing various processes. The RAM 702 also functions as, for example, a frame memory or a buffer memory.
[0133] The CPU 701 executes computer programs stored in the RAM 702. In addition to the CPU, a processor such as a DSP (Digital Signal Processor) or an ASIC (Application Specific Integrated Circuit) may also be used.
[0134] An HDD (Hard Disk Drive) 703 stores operating system programs and video data, as well as computer programs.
[0135] Computer programs and data stored in the HDD 703 are loaded into the RAM 702 as needed under the control of the CPU 701, and executed by the CPU 701. Other storage media than the HDD, such as flash memory, may also be used. A bus 705 connects the various pieces of hardware. The various pieces of hardware exchange data via the bus 705. The above is the hardware configuration in each embodiment.
[0136] The present invention can also be realized by a process in which one or more processors read and execute a program that realizes one or more functions of the above-described embodiments. The program may be supplied to a system or device having a processor via a network or a storage medium. The present invention can also be realized by a circuit (e.g., an ASIC) that realizes one or more functions of the above-described embodiments.
[0137] The control device in each embodiment may be realized by the hardware shown in Fig. 7 or by other hardware, or may be realized by software.
[0138] Furthermore, the present invention is not limited to the above-described embodiments, and various modifications are possible without departing from the spirit of the present invention. For example, combinations of the embodiments and modifications are also included in the disclosure of this specification.
[0139] For example, in S1005, the control unit 2001 of the client device 2000 transmits a request command to the image capturing device 1000 to start recording video data. This command may include the recording settings instructed by the command in S1107 of the second embodiment. In this case, in S1006, the image capturing device 1000 starts recording video using the instructed recording settings. This further strengthens the protection of the video data from the distribution source. [Explanation of symbols]
[0140] 1000 Imaging device (video transmission device) 1001 control section 1003 Imaging unit 1005 Encoding section 1006 Recording control unit 1007 Recording Department 1008 Communications Department 2000 Client device (video receiving device) 2001 Control Unit 2003 Display control unit 2004 Tampering detection unit 2006 Communications Department
Claims
1. A video receiving device that communicates with a video transmitting device using at least a first method, a receiving means for receiving video data in communication using the first method; a determination means for determining whether the received video data has been tampered with; a transmitting means for transmitting a command to the video transmitting device to start communication using a second method different from the first method when it is determined that the received video data has been tampered with; A video receiving device comprising:
2. When it is determined that the received video data has been tampered with, the transmitting means transmits to the video transmitting device a command to stop transmission of video using the first method from the video transmitting device to the video receiving device.
2. The video receiving device according to claim 1.
3. The video data received in the communication is given a digital signature generated based on the video data, and the determination means determines whether the received video data has been tampered with based on the digital signature.
2. The video receiving device according to claim 1.
4. The command is a command that complies with the ONVIF standard.
2. The video receiving device according to claim 1.
5. The determination means determines whether the received video data has been tampered with by analyzing the received video data.
2. The video receiving device according to claim 1.
6. The video transmission device has an imaging means, The transmitting means transmits the command to the video transmitting device to start transmitting the video data captured by the imaging means.
2. The video receiving device according to claim 1.
7. The second method is an encrypted communication method.
2. The video receiving device according to claim 1.
8. The second method is a file transfer protocol.
2. The video receiving device according to claim 1.
9. The second method is an email communication protocol.
2. The video receiving device according to claim 1.
10. The receiving means receives video data from the video transmitting device in communication using the second method after the command is transmitted.
2. The video receiving device according to claim 1.
11. A video transmitting device that communicates with a video receiving device using at least a first method, a receiving means for receiving information indicating that the video data received by the video receiving device in communication using the first method has been tampered with; a control means for starting communication with the video receiving device using a second method different from the first method when the information is received; A video transmission device comprising:
12. The second method is an encrypted communication method.
12. The video transmission device according to claim 11.
13. The second method is a file transfer protocol.
12. The video transmission device according to claim 11.
14. The second method is an email communication protocol.
12. The video transmission device according to claim 11.
15. An imaging means; a transmitting means for transmitting the video data captured by the imaging means to the video receiving device; and When the information is received, the control means starts transmission of the video data captured by the imaging means using the second method.
12. The video transmission device according to claim 11.
16. A means for adding a digital signature generated based on the video data transmitted to the video receiving device to the video data.
12. The video transmission device according to claim 11, further comprising:
17. The receiving means receives the information from the video receiving device.
12. The video transmission device according to claim 11.
18. A video transmitting device; a video receiving device that communicates with the video transmitting device using at least a first method; A video system comprising: The video receiving device a receiving means for receiving video data in communication using the first method; a determination means for determining whether the received video data has been tampered with; and The video transmission device a control means for starting communication with the video receiving device using a second method different from the first method when the determination means of the video receiving device determines that the received video data has been tampered with. A video system comprising:
19. The video data received by the video receiving device is provided with a digital signature generated based on the video data, and the determination means of the video receiving device determines whether the received video data has been tampered with based on the digital signature.
20. The video system according to claim 18.
20. The determination means determines whether the received video data has been tampered with by analyzing the received video data.
20. The video system according to claim 18.
21. The second method is an encrypted communication method.
20. The video system according to claim 18.
22. The second method is a file transfer protocol.
20. The video system according to claim 18.
23. The second method is an email communication protocol.
20. The video system according to claim 18.
24. The video transmission device An imaging means; a transmitting means for transmitting the video data captured by the imaging means to the video receiving device; and When the determination means of the video receiving device determines that the received video data has been tampered with, the control means starts transmission of the video data captured by the imaging means using the second method.
20. The video system according to claim 18.
25. A video receiving method for performing communication using at least a first method with a video transmitting device, comprising: a receiving step of receiving video data in communication using the first method; a determining step of determining whether the received video data has been tampered with; a transmitting step of transmitting a command to the video transmitting device to start communication using a second method different from the first method when it is determined that the received video data has been tampered with; A video receiving method comprising:
26. A video transmission method for performing communication using at least a first method with a video receiving device, comprising: a receiving step of receiving information indicating that the video data received by the video receiving device in the communication using the first method has been tampered with; a control step of starting communication with the video receiving device using a second method different from the first method when the information is received; A video transmission method comprising:
27. A video transmitting device; a video receiving device that communicates with the video transmitting device using at least a first method; 1. A method for a video system comprising: a receiving step in which the video receiving device receives video data in communication using the first method; a determination step in which the video receiving device determines whether the received video data has been tampered with; a control step of causing the video transmitting device to start communication with the video receiving device using a second method different from the first method when the received video data is determined to have been tampered with in the determination step of the video receiving device; A method comprising:
28. A program that causes a computer to function as each of the means of the video receiving device according to claim 1.
29. A program that causes a computer to function as each of the means of the video transmission device according to claim 11.
30. A program that causes a computer to function as each of the means of the video system according to claim 18.
Citation Information
Patent Citations
Signature generation system, signature generation device and signature generation method
JP2017041841A