Coherent Image Encryption

The method encrypts coherent image data to maintain intra-image coherence and prevent inter-image analysis, ensuring secure single-image access while allowing multi-image techniques only for authorized users.

JP7720999B2Active Publication Date: 2025-08-08アイサイ オサケユキチュア
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024523728
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-10-19
Filing Date
2022-10-10
Publication Date
2025-08-08
Estimated Expiration
2042-10-10

AI Technical Summary

Technical Problem

Existing encryption methods for coherent image data fail to provide selective security, allowing unauthorized access to coherent image analysis techniques, which compromises the integrity of sensitive information.

Method used

A method that encrypts phase values of coherent images using a first encryption key to maintain intra-image coherence while preventing inter-image analysis, combined with classical encryption for additional security, ensuring only authorized users can perform multi-image coherent techniques.

Benefits of technology

Enables selective control over encryption levels, allowing single-image analysis while preventing multi-image coherent techniques, thus enhancing data security and privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007720999000001
    Figure 0007720999000001
  • Figure 0007720999000002
    Figure 0007720999000002
  • Figure 0007720999000003
    Figure 0007720999000003
Patent Text Reader

Abstract

A computer-implemented method for encrypting an image, wherein image data is generated by collecting a signal having a bandwidth, the image data including data corresponding to a plurality of pixels of the image, each pixel having an associated phase value, the method including modifying each phase value associated with each of the plurality of pixels based on a first encryption key, wherein after modifying each phase value, a rate of phase change between adjacent pixels does not exceed the bandwidth.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] METHOD FOR ENCRYPTING COHERENT IMAGE DATA In particular, the present invention relates to a method for encrypting image data such that coherence within the image is not lost. [Background technology]

[0002] Information and data security has become an increasingly important and ubiquitous part of modern society. Currently, the need to maintain data and information security is of paramount importance. Such data may include personal information, corporate information, government-owned data, etc. One way to ensure data security is to encrypt the data with an encryption key, preventing it from being accessed, read, and / or edited by entities that do not have a copy of the encryption key.

[0003] There are many forms of data that data owners want to keep secure, including image data. Image data can refer to any form of data collected by an imaging device and stored in a multidimensional array. Typically, image data is stored in a two-dimensional array, with each element of the array defining the attributes of an image pixel. Image data can be encrypted by applying an encryption key to each pixel of the image, randomizing one or more attributes of each pixel in the image.

[0004] Modern systems recognize that a set of coherent images contains information beyond that present in each image in the set individually. In other words, in a set of coherent images, coherence between the images can provide additional information. Typically, this information is estimated using coherence analysis techniques. A set of coherent images can be obtained by periodically imaging the same target from the same distance and direction. For example, in satellite image processing, a series of coherent images can be generated by a satellite generating an image of a particular target each time it orbits the Earth (if the satellite images the same location on the Earth's surface each time it passes the same point above the Earth, a series of images acquired by the satellite will be coherent with each other).

[0005] One such coherent technology is coherent change detection (CCD). CCDs detect changes between coherent images that are difficult for the human eye to see. This is because the sensitivity of a CCD is a small fraction of the wavelength of the light used to collect the image. For example, in the context of radar imaging, CCDs can resolve centimeter-scale changes from satellite-collected images. In the context of synthetic aperture radar (SAR) imaging, CCDs provide users with the ability to see slight differences between two SAR images with a resolution that exceeds "naked eye" analysis.

[0006] Another coherent technique used in SAR imaging is digital elevation model (DEM) generation. DEM takes advantage of the slight positional differences between two coherent images. The phase information associated with each pixel in the coherent images is then compared, highlighting variations relative to a reference plane. In other words, in SAR imaging, the phase information can be used to infer the height of features in the image relative to a reference "zero" height. DEM generation allows this height data to be obtained from the phase variation information via phase unwrapping to form a three-dimensional digital elevation model of the area.

[0007] The third coherent technique used in SAR imaging is Differential Interferometric Synthetic Aperture Radar Imaging (InSAR). InSAR can be thought of as a combination of the CCD and DEM techniques mentioned above. In particular, InSAR facilitates the detection of very subtle changes in elevation over time. Analysis of satellite-generated imagery with InSAR can detect changes in the environment on the order of one millimeter over a period of one month. This can be used to identify a variety of hazardous or emerging conditions, from land slides to infrastructure collapses, such as dam or bridge collapses.

[0008] As the information gained from a set of coherent images via the coherent analysis techniques described above increases, it becomes clear that new forms of data exist that require encryption to ensure security. In some scenarios, a data owner may wish to have a different level or form of security for the data associated with a single image analysis than for the data associated with coherent image analysis. In other words, a data owner may wish to provide data users with access to each image in a set of coherent images, while also wishing to limit access to the information gained via such coherent analysis techniques.

[0009] Based on the above considerations, the inventors have devised the claimed invention.

[0010] The embodiments described below are not limited to implementations that address any or all of the drawbacks of known methods discussed above. Summary of the Invention

[0011] This Summary is provided to introduce a selection of concepts in a simplified form. These concepts are further described below in the Detailed Description. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended for use in determining the scope of the claimed subject matter. Modifications and alternative features used to facilitate the practice of the invention and / or to achieve a substantially similar technical effect are deemed to be within the scope of the invention(s) disclosed herein.

[0012] The invention is defined as set forth in the following claims.

[0013] In a general sense, the present invention provides a method for encrypting image data so that a data consumer can analyze a single image without requiring decryption, but cannot use the image for coherent image analysis that takes into account other images in an image set without first decrypting the image data. In other words, the present invention provides data owners the flexibility to cryptographically protect information associated with coherent image analysis without encrypting information associated with individual image analysis.

[0014] In a first aspect of the present invention, there is provided a computer-implemented method for encrypting image data, the image data being generated by collecting a signal having a bandwidth, the image data including data corresponding to a plurality of pixels of the image, each pixel having an associated phase value, the method including the step of modifying each phase value respectively associated with each of the plurality of pixels based on a first encryption key, wherein after the step of modifying each phase value, a rate of phase change between adjacent pixels does not exceed the bandwidth.

[0015] In some examples, for added security, the images may be further encrypted using "classical" encryption techniques. Those skilled in the art will understand, based on the disclosure herein, that any such classical encryption must encrypt the phase information in each image in a reversible manner, i.e., in such a way that the phase information can be retrieved when the classically encrypted image is decrypted. In other words, the coherent encryption methods described herein can be combined with additional classical encryption techniques performed after the coherent encryption methods described herein, provided that the classical encryption techniques do not irretrievably destroy the phase information encoded in each image.

[0016] In another aspect of the invention, there is provided an apparatus including a processor configured to perform any of the methods disclosed herein.

[0017] In another aspect of the present invention, there is provided a computer program product comprising instructions that, when executed by a computer, cause the computer to perform any of the methods disclosed herein.

[0018] In another aspect of the present invention, a computer-readable storage medium is provided that includes instructions that, when executed by a computer, cause the computer to perform any of the methods disclosed herein.

[0019] The methods described herein can be implemented by software in machine-readable form, e.g., in the form of a computer program comprising computer program code means adapted to perform all the steps of any of the methods described herein when the program is run on a computer, on a tangible storage medium, and the computer program can be embodied on a computer-readable medium. Examples of tangible (or non-transitory) storage media include magnetic disks, thumb drives, memory cards, etc. The software may be suitable for execution on a parallel or serial processor, and the method steps can be performed in any suitable order or simultaneously.

[0020] This application recognizes that firmware and software are individually tradable commodities with value. It is designed to include software that operates or controls on "dumb" or standard hardware to perform a desired function. It is also intended to include software that "describes" or defines hardware configurations, such as HDL (Hardware Description Language) software that designs silicon chips or configures general-purpose programmable chips to perform desired functions.

[0021] The features and embodiments described herein may be combined as appropriate as would be apparent to one skilled in the art, and may be combined with any aspect of the invention unless expressly specified that such a combination is not possible, or unless one skilled in the art would understand that such a combination is not possible.

[0022] Hereinafter, an embodiment of the present invention will be described by way of example with reference to the drawings. [Brief explanation of the drawings]

[0023] [Figure 1] 1 shows a simplified schematic diagram of an example image that can be encrypted using the method of the claimed invention. [Figure 2] 1 shows a schematic diagram of a satellite in Earth orbit collecting SAR image data. [Figure 3a] 1 illustrates the method steps of the claimed invention. [Figure 3b] 1 illustrates a method for modifying the phase value of each pixel in an image by distorting a mask according to some embodiments of the present invention. [Figure 4a] 10 shows the mask that is overlaid on the image to be encrypted. [Figure 4b] 1 shows a mask that defines a polygonal network that includes a plurality of nodes, each node defining a vertex of the polygonal network. [Figure 4c] 1 shows the deformed mask by adjusting the height of each node of the mask relative to the plane defined by the mask before the mask is deformed. [Figure 5] We present a method for encrypting multiple coherent images to remove the coherence between them. [Figure 6a] An example of the results of coherent change detection (CCD) between two coherent images is shown. [Figure 6b] 1 shows an example of the results of a CCD between two images where image data associated with at least one of the images has been encrypted according to the methods described herein. [Figure 7] 1 illustrates a computer configured to perform the method of the claimed invention. Common reference numerals are used in the figures to represent the same or similar features. DETAILED DESCRIPTION OF THE INVENTION

[0024] Embodiments of the present invention are described below by way of example only. These examples represent the best mode of carrying out the invention currently known to the applicant, but are not the only way this can be achieved. The description describes sample functions and a sequence of steps for constructing and operating the examples. However, the same or equivalent functions and sequences may be achieved by different examples.

[0025] FIG. 1 shows a simplified diagram of an example image 10 that can be encrypted using the method of the present invention. Image 10 includes a plurality of pixels, with data associated with each pixel of the image. Image 10 is generated by detecting an imaging signal that has interacted with an imaging target. This can be based on a variety of imaging techniques, including both reflection-based techniques, where the imaging signal is reflected from the imaging target, and transmission-based techniques, where the imaging signal propagates through the imaging target to a detector. A particular example of interest, discussed below in connection with FIG. 3, is SAR imaging by a satellite in Earth orbit, which is an example of an imaging technique based on the reflection of a radar signal.

[0026] The imaging detector captures the imaging signal and associated image data in the form of an image 10 divided into a plurality of pixels. Each pixel is associated with one or more data values that capture information contained in the imaging signal. For example, a first pixel 12 has a first correlation phase value and a second correlation amplitude value at another value. Similarly, a second pixel 14 has a second correlation phase value and a second correlation amplitude at another value.

[0027] The first and second correlated amplitude values may indicate the amplitude of the resulting signal received at the first and second pixels 12, 14, respectively. The first and second correlated amplitude values may be recorded as luminance values of the first and second pixels 12, 14, respectively. Alternatively, the first and second correlated amplitude values may be recorded in another format, such as RGB values, CMYK values, etc. Additionally or alternatively, luminance values, RGB values and / or CMYK values or the like may be recorded as data associated with each of the pixels 12, 14 in addition to the associated amplitude values.

[0028] The correlation amplitude value can be used in imaging analysis to infer various properties of the imaging target. For example, in reflectance-based imaging techniques, the correlation amplitude value can indicate the reflectivity of the imaging target, e.g., a relatively high correlation amplitude value can indicate a higher reflectivity than a relatively low correlation amplitude value. This can be used, for example, in qualitative analysis to determine the type of material comprising the imaging target. For example, a high reflectivity may indicate that the imaging target is made of a reflective material such as metal. Conversely, a low reflectivity may represent a non-reflective material such as wood, concrete, or leaves. Note that for a given material, the reflectivity may be a function of the wavelength of the imaging signal, such that a material may have high reflectivity at some wavelengths and low reflectivity at other wavelengths.

[0029] On the other hand, in transmission-based imaging techniques, the associated amplitude value may indicate the attenuation coefficient of the imaged object; for example, a relatively high associated amplitude value may indicate a lower attenuation coefficient than a relatively low associated amplitude value. This can be used, for example, in qualitative analysis to determine the type of material from which the imaging target is formed. For example, a low attenuation coefficient may indicate that the imaging target is formed of an optically transparent material such as glass, a transparent liquid such as water or oil, or a transparent gas such as air, carbon dioxide, methane, or other greenhouse gases, oxygen, an inert gas, or any other optically transparent material. Conversely, a low reflectance may indicate an optically dense (or opaque) material such as lead, aluminum, or any other optically dense material. Note that for a particular material, the attenuation coefficient is a function of the wavelength of the imaging signal, so that a material may have a low attenuation coefficient at certain (usually short) wavelengths and a high attenuation coefficient at other (usually long) wavelengths. Typical examples are greenhouse gases, and indeed many gases that are optically transparent to visible light, ultraviolet light, and X-rays, but may be optically dense to longer wavelength infrared light due to their high absorption coefficients in the infrared portion of the electromagnetic spectrum.

[0030] The first and second associated phase values may indicate the relative phases of the generated signals received at the first and second pixels 12, 14, respectively. The associated phase values may have values ranging from 0 to 2π, 0 to 360, −π to π, −180 to 180, or any other suitable range. Additionally, a data value indicative of an “unwrapped” phase may be associated with each pixel of the image 10. In other words, while phase information is typically cyclically encoded (recognizing that phase is a cyclically repeating property), unwrapping the phase information to eliminate the cyclic repeat may instead provide information that is more directly indicative of the optical path length between the imaging target and the detector.

[0031] In some examples, data associated with each pixel 12, 14 of the image 10 can be encoded with a complex number z = x + iy. In this manner, the amplitude and phase values of each pixel 12, 14 of the image 10 can be encoded with a single complex number z. For example, the amplitude value can be determined by determining the magnitude of the complex number z. That is, the amplitude value can be |z| = (x² + y²)½. Also, the phase value can be determined by taking the argument of the complex number z. That is, the phase value can be arg(z) = tan−1(y / x).

[0032] Correlated phase value information can be used in imaging analysis to infer various characteristics of the imaging target. For example, those skilled in the art will recognize that in some cases of images generated by reflecting a signal from a target, the phase information indicates, for example, the total length of the signal path. The phase information can be unwrapped by the data user to determine the distance between the signal source and / or receiver and the surface from which the signal is reflected. In most practical settings, the phase information is used to determine the distance of one reflective surface relative to another. For example, in the case of overhead imagery, the phase difference between different pixels can indicate the relative height of the reflective surface captured in each pixel. In another example, those skilled in the art will recognize that in some cases of images generated by transmitting a signal through a target, the phase information can indicate the density of the target, as changes in density result in changes in the target's refractive index, thereby changing the effective optical or signal path length.

[0033] In other words, in reflectance-based imaging techniques, the correlation phase value can indicate the distance between the imaging target and the detector, and in the context of overhead imaging, for example, the correlation phase value can indicate the relative height of the imaging target or components of the imaging target, which can be used to determine the distance and / or height distribution of the imaged targets.

[0034] On the other hand, in transmission-based imaging techniques, the correlation phase value can indicate the concentration distribution of the imaging target. For example, concentration changes in the imaging target change the effective optical path length that the imaging signal travels through the imaging target. In particular, increasing the density of the target increases the effective optical path length. This can be used to determine the concentration distribution of the imaging target.

[0035] In some embodiments, the or each image is generated by synthetic aperture radar (SAR) imaging.

[0036] The method of the claimed invention is applicable to a wide range of images, but finds particularly beneficial application in the context of SAR imaging. As noted above, the claimed invention enables data users to implement single-image coherent techniques, such as autofocus processes, multi-view processing, and / or other frequency-domain based techniques, while simultaneously preventing the same data user from implementing multi-image coherent techniques, such as CCD, DEM, or InSAR.

[0037] In some embodiments, the or each image is a satellite-generated image.

[0038] Data security for satellite-generated imagery is particularly important due to the wide range of data that overhead satellites can collect. For example, image-to-image coherent imagery may be able to determine whether land is occupied by determining whether a human has passed over the land or by proving human presence based on coherent imagery. To protect individuals' privacy from satellite imagery of land, data may need to be encrypted. In other applications, all government data may need to be encrypted for security and / or defense purposes. For example, data associated with military installations must be kept secure for the safety of military and other personnel. Additionally, encrypted image data may be necessary to prevent customers or clients of the data owner from accessing information they are not authorized to access (e.g., they may not have the right to purchase or use the information).

[0039] FIG. 2 shows a schematic diagram of a satellite 20 collecting SAR image data in orbit around Earth 22. Satellite 20 is in a repeating orbit around Earth 22, e.g., a daily repeating orbit. To collect SAR image data, satellite 20 reflects a radar signal 24 from the surface of one or more imaging targets on the surface of Earth 22. As satellite 20 repeats its orbit, it periodically revisits the same location relative to Earth 22. Each time satellite 20 images the same imaging target from the same location relative to Earth with its radar signal, it images another SAR image of the same imaging target. Each of these SAR images is coherent with respect to each other, meaning that the individual or entity in possession of the set of coherent images implements a multi-image coherent imaging technique, such as CCD, DEM, or InSAR.

[0040] In such examples, the wavelength of the imaging signal may be a wavelength suitable for radar imaging. For example, the wavelength of the imaging signal 24 may be 0.5 cm or greater, 1 cm or greater, 3 cm or greater, 5 cm or greater, or 8 cm or greater. In other examples, the wavelength of the imaging signal may be between 0.5 cm and 10 cm. In one particular embodiment, the wavelength of the imaging signal 24 is approximately 3 cm.

[0041] Additionally, the imaging signal may have a characteristic bandwidth similar to that found in radar imaging signals. For example, the characteristic bandwidth may be 0.5 kHz or greater, 1 kHz or greater, 5 kHz or greater, or 10 kHz or greater. In one particular embodiment, the characteristic bandwidth of the imaging signal 24 is approximately 4 kHz.

[0042] Additionally, the imaging signal can gain additional bandwidth due to the Doppler effect caused by the movement of the satellite 20 relative to the Earth 22. This so-called Doppler bandwidth can be 1 MHz or greater, 10 MHz or greater, 100 MHz or greater, 500 MHz or greater, 1000 MHz or greater, or 5000 MHz or greater. In one particular embodiment, the Doppler bandwidth of the imaging signal 24 due to the orbit of the satellite 20 around the Earth 22 is approximately 300 megahertz.

[0043] In some examples, the imaging target of satellite 20 may be a geographic area on the surface of Earth 22. The area may be 10 square kilometers or more, 50 square kilometers or more, 100 square kilometers or more, 1,000 square kilometers or more, 5,000 square kilometers or more, or 10,000 square kilometers or more.

[0044] For example, each image may be 5 km x 5 km or larger in area, 10 km x 10 km or larger in area, 50 km x 50 km or larger in area, or 100 km x 100 km or larger in area.

[0045] In these examples, for example, a single pixel of image 10 may image an area of 0.1 square meter or more, 0.5 square meter or more, 1 square meter or more, 2 square kilometers or more, or 5 square kilometers or more. For example, each pixel of image 10 can correspond to an area of 0.25 m x 0.25 m or more, an area of 0.5 m x 0.5 m or more, an area of 1 m x 1 m or more, an area of 1.5 m x 1.5 m or more, or an area of 2 m x 2 m or more. In one particular embodiment, each pixel of image 10 corresponds to an area of 1 m x 1 m of the imaging target.

[0046] FIG. 3a illustrates the steps of the method. In step S300, unencrypted image data is provided to a data owner in the form of an image 10. The image 10 is imaged using an imaging signal. The imaging signal includes a wavenumber range (the inverse of the wavelength) that defines the bandwidth of the imaging signal. The bandwidth can be determined by downconverting the frequency of the imaging signal to effectively remove the carrier frequency associated with the signal. Before downconversion, the bandwidth of the imaging signal can range from a lower non-zero frequency / wavenumber to a higher non-zero frequency / wavenumber. The bandwidth can be defined as the difference between the high and low non-zero frequencies / wavenumbers. After downconversion, the bandwidth can be downconverted from a zero frequency / wavenumber to a higher non-zero frequency / wavenumber. The higher downconverted non-zero frequency / wavenumber can be equal to the bandwidth value. In step S310, a first encryption key is provided to the data owner. The first encryption key can be generated by random seed generation. In step S320, the phase values for each pixel 12, 14 in the image 10 are modified based on the first encryption key so that the rate of phase change between adjacent pixels after encryption does not exceed the bandwidth of the imaging signal. Such encryption does not prevent data users from performing amplitude-based or single-image coherent image analysis, such as autofocus processes, multi-view processing, and other frequency-domain-based techniques. However, it does prevent those who do not possess the first encryption key from implementing multi-image coherent image analysis, such as CCD, DEM, or InSAR. Finally, in step S330, an encrypted image is generated as the output of the encryption process.

[0047] By encrypting the phase information associated with image data, data owners can set different security levels for the image data. For example, the encrypted phase information can have no effect on other information, such as amplitude information, associated with the image data. This selective encryption of the phase information allows data users to access and view only a subset of the information associated with the image data. For example, a data user can be permitted to view information indicating the spatial intensity of the imaging signal, which may be encoded by the amplitude values associated with each pixel of the image.

[0048] When the correlation phase value of each pixel 12, 14 of the image 10 is changed, the rate of phase change between adjacent pixels of the encrypted image must not exceed the bandwidth of the imaging signal. Meeting this criterion means that the sampling wavenumber range is wider than the bandwidth of the imaging signal (including the encrypted phase signal), making it possible to realize the single-image coherent imaging technique described above. In other words, changing the phase value of each pixel in this way does not destroy the coherence of the image itself. On the other hand, changing the phase information does not affect the image in such a way that the phase difference between the encrypted image and other (unencrypted) images cannot be meaningfully calculated or determined. picture Image data encryption That is, while conventional methods of encrypting phase information destroy phase information by preventing the calculation or determination of either intra-image or inter-image phase differences, the claimed invention provides an encryption method that allows the continuous calculation or determination of intra-image phase differences while preventing the calculation or determination of inter-image phase differences. Failure to comply with this standard effectively destroys phase information, making single-image coherent imaging techniques impossible.

[0049] This further facilitates data owners' selective control over increasing encryption levels for specific images. For example, by encrypting image data according to the methods described herein, a data user may implement several analysis techniques that rely on calculating or determining phase differences within an image. These analysis techniques may include, for example, autofocus procedures, multi-look processing, and / or other frequency-domain-based techniques. Such analysis techniques may be more generally described as single-image coherent techniques. At the same time, a data user may not implement multi-image coherent techniques, such as CCD, DEM, or InSAR, that rely on calculating or determining phase differences between images.

[0050] In cases where the signal includes multiple bandwidths, such as satellite-based SAR imaging where the imaging signal has a native bandwidth and a Doppler bandwidth, the rate of phase change described above must not exceed the maximum of the bandwidths in order for the methods described herein to work. In some examples, the rate of phase change may not exceed the minimum bandwidth associated with the signal so that information encoded in frequencies associated with lower bandwidths is not lost in the encryption process described herein.

[0051] In some embodiments, the step of encrypting image data associated with each image of the OR includes the steps of selecting a portion of each image of the OR to be encrypted, encrypting the image data associated with each image of the OR, and encrypting the selected portion by modifying each phase value associated with each of the plurality of pixels within the selected portion based on a first encryption key.

[0052] In this way, the data owner is provided with a greater level of selective control over the encryption of image data. For example, the data owner may choose to encrypt one or more regions of a given image but not other regions in order to blur a given region (or regions) of interest. In some examples, the data owner may encrypt data associated with a central region of an image without encrypting one or more border regions. In other examples, the data owner may encrypt data associated with a region of an image imaging a particular subject of interest, but not the remainder of the image.

[0053] FIG. 3b illustrates a method for modifying the phase values of each pixel in an image by deforming a mask 40 (described below with reference to FIGS. 4a-4c) according to some embodiments of the present invention. The steps described in FIG. 3b may replace step S320 in FIG. 3a. In step S322 in FIG. 3b, the mask 40 is overlaid on the unencrypted image 10. In step S324, the mask 40 is deformed based on a first encryption key. For example, before deformation, the mask 40 may be a plane overlaid on the image 10. Deforming the mask may include adjusting the height of certain sections of the mask relative to the plane defined by the image 10. Thus, the deformed mask 46 may appear to have actual "wrinkles" or "creases" relative to the undeformed mask 40. In step S326, the phase values of each pixel in the image 10 are modified based on the deformed mask 46. In other words, the phase values of each pixel in the image 10 may be modified by assuming that the relative positions of the pixels have changed as the mask is deformed.

[0054] In some examples, the pre-deformation mask may have a zero phase value associated with each point in the mask. The deformation mask may include associating a new phase value with each dot in the deformation mask based on the adjusted height of the dot in the mask. Changing the phase of each pixel may then include adding (or subtracting) the new phase value associated with the dot in the deformation mask that corresponds to the corresponding pixel in image 10 to the phase value associated with that pixel.

[0055] In other words, in some embodiments, the method further includes overlaying a corresponding mask on the or each image to be encrypted, and modifying each phase value associated with each of the plurality of pixels of the or each image to be encrypted includes deforming the mask based on the first encryption key and modifying each phase value associated with each of the plurality of pixels of the or each image to be encrypted based on the deformation of the mask. In practice, the mask can be a tool that can implement the first encryption key to coherently encrypt one or more images to be encrypted.

[0056] The provision of a mask and subsequent deformation provides a mechanism for gradually varying the phase value change from pixel to pixel so that the rate of phase change across the image does not exceed the wavenumber bandwidth of the imaging signal. Modifying the phase of each pixel of the image based on deformation of the mask provides the data owner with a means of ensuring that the degree of modification does not suffer from abrupt discontinuities or high rates of change, since the mask can be continuously modified to ensure a bandwidth limit that matches the rate of phase change from pixel to pixel.

[0057] In some embodiments, the deformation masks associated with each of the one or more images to be encrypted may each undergo a different deformation.

[0058] By differently transforming the mask associated with each image, the phase information of each image is altered accordingly, thus removing any coherence between any pair of images in the multiple images, thereby encrypting the information encoded within the images and making them resistant to inter-image coherence analysis such as CCD, DEM-generated, or InSAR.

[0059] In some embodiments, modifying the or each mask may further be based on a non-linear function.

[0060] In some embodiments, the deformation mask or the corresponding function defining the gradient of each deformation mask may be discontinuous.

[0061] By nonlinearly transforming and / or distorting the mask so that there is a discontinuity in the gradient of the mask (also known as a "low derivative discontinuity"), the phase change between adjacent pixels (after each pixel's phase has been changed based on the mask deformation) can be made apparently unpredictable, thus making the encryption more secure.

[0062] FIG. 4a shows a mask 40 that can be overlaid on the image 10 to be encrypted.

[0063] FIG. 4 b shows a mask 40 that includes a plurality of interconnected nodes 42 that define a polygonal network 44 .

[0064] FIG. 4c shows a deformation mask 46 that is deformed before deformation by adjusting the height of each of the plurality of nodes 42 relative to the plane defined by the mask 40. FIG.

[0065] In some embodiments, the or each mask comprises a plurality of nodes, and transforming the mask comprises adjusting the height of each node relative to the respective image based on the first cryptographic key.

[0066] In some examples, the mask may be deformed so that it is defined by a continuous gradient between the nodes of the mask. This ensures that there are no discontinuities in the rate of phase change between pixels, allowing intra-image phase differences to be calculated or determined, facilitating single-image coherence analysis techniques. Furthermore, by deforming the mask based on adjusting the corresponding height of each node relative to a plane defined by the mask before the mask deformation, the degree of deformation of each mask portion can be interpolated based on the adjusted node height, as opposed to having to input a new adjusted height for each mask portion corresponding to an image pixel, thereby reducing the degree of computation. In this way, by adjusting the height of each node relative to a plane defined by the mask before the deformation, the computational cost of the deformation can be reduced, making the overall approach more efficient.

[0067] Other methods of deforming the mask to keep the rate of change of phase information between adjacent pixels lower than the bandwidth of the image signal are possible. For example, the mask may be a continuously deforming plane based on a mathematical function. The mask deformation may include "dimples" or other perturbations. The perturbations may be defined by one or more curves and / or one or more sharp edges. In practice, any parametric deformation can be used as long as it meets the phase change rate requirements. The parameters of the parametric surface can then be encrypted to provide security similar to encrypting the nodes of the surface.

[0068] Assuming that the mask transformation is based on the first encryption key, transforming the mask based on the node height adjustment allows for a simpler encryption key. In other words, since each pixel of the image needs to be individually encrypted based on the first encryption key, the encryption key can be shortened to a reasonable and manageable length without requiring an unreasonably long encryption key. By facilitating mask interpolation between adjusted nodes, the total computational cost of encryption is reduced.

[0069] In some embodiments, the position of each of the plurality of nodes within each mask is determined based on a second cryptographic key.

[0070] This further improves the security of the encrypted data. In particular, because the position of each of the multiple nodes in the mask is determined based on the second encryption key, no two masks will be identical if they are encrypted with different encryption keys. This means that not only is the phase information of the original image data encrypted and kept secret, but also that an "eavesdropper," other person, or entity attempting to illegally obtain phase information data will not even be able to determine the qualitative nature of the changes in each phase value. In particular, without the second encryption key, once the mask is deformed, an individual or entity will not be able to know what the structure of the mask is, preventing them from reversing the encryption.

[0071] In some embodiments, the first and second cryptographic keys are the same.

[0072] In this way, only one encryption key needs to be stored and used as the basis for mask transformation, thereby reducing the computational cost and burden of encrypted image data.

[0073] In some embodiments, the first encryption key and the second encryption key are different.

[0074] This improves the security of the image data, as any individual or entity attempting to fraudulently obtain the phase information data would need to decrypt two independent encryption keys.

[0075] The owner of the encrypted image data or another party can select whether the first and second encryption keys are the same or different, depending on their needs. For example, if the data owner has stringent requirements for processing speed or data storage, the first and second encryption keys may be the same. In another example, if the data owner has very stringent data security requirements, the data owner can select different first and second encryption keys.

[0076] In some embodiments, each of the one or more nodes defines a corresponding vertex of a polygonal network defined by the mask.

[0077] In some embodiments, each of the one or more nodes defines a corresponding center of a polygon in the polygon network defined by the mask.

[0078] In this way, the slope of the deformation mask can be controlled so that when the phase values are changed based on the mask deformation, the rate of phase change between adjacent pixels does not exceed the waveband width of the imaging signal. In some examples, the deformation of each edge of each polygon is based on linear interpolation between nodes that define the mutually distal endpoints of the edge. Furthermore, the edges of each polygon can define discontinuities in the gradient of the deformation mask. This, as described above, makes the phase change between adjacent pixels (after the phase of each pixel is changed based on the mask deformation) clearly unpredictable, thereby making encryption more secure.

[0079] In some embodiments, the edges connecting the vertices of the polygonal network are defined to maximize the area of each polygon of the polygonal network.

[0080] This can further avoid discontinuities in phase change. In other words, by maximizing the area of each polygon in the polygonal network, the rate of phase change between adjacent pixels can be prevented from exceeding the wavenumber bandwidth of the imaging signal. The process of maximizing the area of each polygon in the polygonal network can be achieved by an appropriate optimization algorithm. For example, the polygonal network can be defined through Delaunay triangulation or another similar algorithm or method.

[0081] Each polygon of polygon network 44 can span multiple pixels of image 10. For example, the area of each polygon of polygon network 44 (e.g., each triangle of the network determined by a Delaunay triangulation) may exceed an area equivalent to 10 pixels by 10 pixels or more, 50 pixels by 50 pixels or more, 100 pixels by 100 pixels or more, 150 pixels by 150 pixels or more, or 200 pixels by 200 pixels or more. In one particular example, polygon network 44 is defined by a Delaunay triangulation, and each triangle traverses an area equivalent to 100 pixels by 100 pixels or more.

[0082] In some examples, each polygon of the polygon network may be defined by an alternative to Delaunay triangulation. For example, the polygon network may be defined by Voronoi tessellation or another similar process, where each polygon is defined by referencing one of the nodes of the polygon network. In the case of Voronoi tessellation, each node defines the center of a corresponding polygon of the polygon network, and the corresponding polygon defines a locus of points, the node among the multiple nodes being closest to the locus.

[0083] In some embodiments, each of the one or more images to be encrypted is encrypted with a different second encryption key.

[0084] As shown in Figure 1, each of the multiple coherent images is further encrypted independently, improving the security of the encrypted data. This ensures that even if an individual or entity illicitly decrypts one image, they cannot decrypt the other encrypted images and thus recover the coherence.

[0085] In some embodiments, the first and / or second cryptographic keys are generated based on a random seed generation.

[0086] In this way, the outcome of the random seed generation process cannot be reliably predicted, thereby maintaining the secrecy of the first and / or second cryptographic keys.

[0087] The mask 40 may be used to define a polygonal network 44 by adding a plurality of nodes 42 to the mask. The locations of the nodes 42 may be determined using a second encryption key. The second encryption key may be generated by random seed generation. In some cases, the second encryption key may be the same as the first encryption key, or the first and second encryption keys may be different.

[0088] The plurality of interconnected nodes 42 are connected via a series of edges to define a polygonal network 44. The polygonal network 44 may include a repeating tessellation of similar polygons. For example, in the example shown in FIG. 4b, the polygonal network 44 includes a series of triangles, possibly equilateral triangles. The polygonal network 44 may be configured to maximize the area of each polygon in the polygonal network. In the example of FIG. 4b, this is achieved by performing a Delaunay triangulation procedure. Those skilled in the art will recognize that other suitable optimization algorithms may be appropriate.

[0089] Deforming mask 40 to generate deformation mask 6 includes adjusting the relative heights of each of the plurality of nodes 42 based on the first encryption key, thereby generating a wrinkled deformation mask 46 that, when overlaid on image 10, provides a basis for adjusting the phase values associated with each pixel 12, 14 of image 10 to encrypt the image data, as shown in Figure 4c.

[0090] FIG. 5 illustrates a method for encrypting multiple coherent images to remove coherence between them. In step S500, multiple coherent images are provided to a data owner / encryption device. As shown in FIG. 2, multiple coherent images can be collected from a satellite 20 in a daily repeating orbit around Earth 22 using SAR imaging. In step S520, image data for one or more of the multiple coherent images is encrypted according to the method shown in FIGS. 3a-b, thereby removing coherence between each encrypted image and each other image in the multiple coherent images. In step S530, a coherently encrypted image stack is output.

[0091] In other words, in some embodiments, the method further includes providing a plurality of coherent images, each of the plurality of coherent images being associated with respective image data, and encrypting the image data associated with one or more images of the plurality of coherent images by a method implementing the first aspect on the image data associated with each of the one or more images, wherein encrypting the one or more images removes coherence between each of the one or more encrypted images and each of the other images of the plurality of coherent images.

[0092] By removing the coherence between each encrypted image and each other image in the plurality of coherent images, the methods described herein can ensure that data users do not implement multi-image coherence techniques that rely on calculating or determining phase differences between images, such as CCD, DEM, or InSAR.

[0093] As noted above, the method described in Figure 5 allows a data user to implement single-image coherence techniques, such as autofocus processes, multi-view processing, and / or other frequency-domain based techniques, on each image, while the same data user can implement multi-image coherence techniques, such as CCD, DEM, or InSAR, on the entire stack of coherently encrypted images, unless the initial encryption key is provided.

[0094] In some embodiments, the image data associated with each of the one or more images is encrypted with a different first encryption key.

[0095] In this way, the data security of the encryption is enhanced because each image of multiple coherent images is independently encrypted, so even if an individual or entity fraudulently decrypts one of the images, they will not be able to decrypt the other encrypted images and therefore will be able to recover their coherence.

[0096] Figure 6a shows an example of a CCD result between two coherent images. CCD image 62 can show the results of successful coherent change detection, including details of several geographic features.

[0097] FIG. 6b shows an example of the results of CCD between two images in which image data associated with at least one of the images has been encrypted according to the methods described herein. It is easy to see that features identifiable in CCD image 62 are indistinguishable in “encrypted” CCD image 64. In the example shown in FIG. 6b, the encrypted image data has been encrypted using a mask generated by Delaunay triangulation, as described above. Triangular artifacts are visible in “encrypted” CCD image 64, which are the result of said Delaunay triangulation. However, it can also be seen that the triangular artifacts do not yield information about the underlying image data that would be accessible if the image had not been encrypted.

[0098] 7 illustrates an example of a computer 70 configured to perform the methods of the present invention. The computer 70 includes a communications interface 71, a signal generator module 72, a detector module 73, a storage unit 74, a processor 75, and one or more additional modules 76. The computer 70 may be a computer onboard a satellite 20 that orbits Earth 22 and collects SAR image data. The computer 70 may also be a ground-based computer configured to communicate with the satellite 20 via the communications interface 71. The communications interface may also be configured to facilitate communication between the computer 70 and a server or between the computer 70 and a user.

[0099] The signal generator module 72 may include instructions or logic that, when executed by the computer 70 or by the satellite 20 received via the communications interface 71, causes the imaging signal 24 to be generated. The detector module 73 may include instructions or logic that, when executed by the computer 70 or by the satellite 20 received via the communications interface 71, causes the computer 70 or the satellite 20 (as the case may be) to detect / receive the imaging signal 24 containing the image data to be encrypted and store the image data in the storage unit 74.

[0100] Processor 75 is configured to perform the methods of the claimed invention. This may include processor 75 configured to perform any of the methods shown in Figures 3a, 3b, or 5 to encrypt image data associated with image 10. Processor 75 may perform the method by executing instructions or logic contained in a computer-readable medium or computer program product. The encrypted image or images may be stored in memory 74 or transmitted to a data user or data owner via communication interface 71.

[0101] The computer 70 may include one or more additional modules 76. These modules may include, but are not limited to, one or more other processors configured to analyze image data collected by the detector module 73. The one or more additional modules 76 may further include one or more processors configured to calibrate the received / detected image data, for example, by calibrating the image data collected by the detector module 73 based on the angle of incidence of the imaging signal 24, or may be configured to perform operations for image analysis, such as InSAR, CCD, or DEM image analysis techniques.

[0102] In some embodiments, the image data encryption methods described herein are reversible.

[0103] This allows data owners more flexibility in determining the security level of their data. For example, a data owner may determine that a data user who previously did not have the right to obtain phase information associated with inter-image coherent imaging technology has now acquired the right. In this case, rather than recollecting the data to send to the newly authorized user, the data owner can simply provide the data user with the encryption key required for decryption, i.e., to decrypt the data.

[0104] In the above-described embodiments, the method may be performed on a server. The server may include a single server or a network of servers. In some examples, the functionality of the server may be provided by a network of servers distributed across geographic regions, such as a globally distributed network of servers, and a user may connect to an appropriate one of the server networks based on the user's location.

[0105] For clarity, the above description describes embodiments of the present invention with reference to a single data user or data owner. It should be understood that in practice the system may be shared by multiple users and / or owners, and may be shared by a large number of users and / or owners simultaneously.

[0106] The above embodiments are fully automatic. In some instances, a user or operator of the system may manually instruct some steps of the method to be performed.

[0107] In embodiments described herein, the method may be performed by a system. The system may be implemented as any type of computing and / or electronic device. Such a device may include one or more processors, which may be microprocessors, controllers, or any other suitable type of processor, for processing computer-executable instructions for controlling the operation of the device to collect and record routing information. In some examples, for example, when using a system-on-chip architecture, the processor may include one or more fixed function blocks (also called accelerators) that implement portions of the method in hardware (rather than software or firmware). Platform software, including an operating system or any other suitable platform software, may be provided with the computing-based device to enable application software to run on the device.

[0108] The various functions described herein may be implemented in hardware, software, or any combination thereof. If implemented in software, the functions may be stored on or transmitted over as one or more instructions or code on a computer-readable medium. A computer-readable medium may include, for example, a computer-readable storage medium. A computer-readable storage medium may include volatile or nonvolatile, removable or non-removable media implemented in any method or technology for storing information such as computer-readable instructions, data structures, program modules, or other data. A computer-readable storage medium may be any available storage medium accessible by a computer. By way of example and not limitation, such computer-readable storage media may include RAM, ROM, EEPROM, flash memory or other storage devices, CD-ROM or other optical storage disks, magnetic disk storage devices or other magnetic storage devices, or any other medium accessible by a computer that can be used to carry or store desired program code in the form of instructions or data structures. As used herein, optical disk and disk include optical discs (CDs), laser discs, optical disks, digital versatile discs (DVDs), floppy disks, and Blu-ray discs (BDs). Also, propagated signals are not included within the scope of computer-readable storage media. Computer-readable media also includes communication media, including any medium that facilitates transfer of a computer program from one place to another. A connection may, for example, be a communications medium. For example, when software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave, it is included within the definition of communications media. Combinations of the above should also be included within the scope of computer-readable media.

[0109] Alternatively or additionally, the functions described herein may be performed, at least in part, by one or more hardware logic components. For example, but not limited to, hardware logic components that may be used include field programmable gate arrays (FPGAs), programmable application specific integrated circuits (ASICs), programmable application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), etc.

[0110] It should be understood that the computing devices used to implement the methods of the claimed invention may be distributed systems, whereby, for example, several devices may communicate via network connections and jointly perform tasks described as being performed by the computing devices.

[0111] It should be understood that a computing device performing the methods of the claimed invention may be located remotely and accessed via a network or other communications link (e.g., using a communications interface).

[0112] As used herein, the term "computer" refers to any device having processing capability that enables the execution of instructions. Those skilled in the art will recognize that such processing capability may be incorporated into many different devices, and thus the term "computer" includes PCs, servers, mobile phones, personal digital assistants, and many other devices.

[0113] Those skilled in the art will recognize that storage devices storing program instructions may be distributed across a network. For example, a remote computer may store an example process written as software. A local or terminal computer may access the remote computer and download some or all of the software to execute the program. Alternatively, a local computer may download pieces of software as needed, or may execute some software instructions at a local terminal and some at a remote computer (or computer network). Those skilled in the art will also recognize that, utilizing conventional techniques known to those skilled in the art, all or some of the software instructions may be executed by dedicated circuitry, such as a DSP, a programmable logic array, or the like.

[0114] It should be understood that the above benefits and advantages may relate to one embodiment or several embodiments. The embodiments are not limited to those that solve any or all of the described problems or that have any or all of the described benefits and advantages. Variations are to be considered within the scope of the present invention.

[0115] A reference to "an" or "an" item means one or more of those items. The term "comprising" is used herein to indicate the inclusion of identified method steps or elements, but these steps or elements are not inclusive and the method or apparatus may include additional steps or elements.

[0116] As used herein, the terms "component" and "system" are intended to include a computer-readable data store comprised of computer-implementable instructions that, when executed by a processor, cause the computer to perform a particular function. The computer-executable instructions may include routines, functions, etc. It should also be understood that a component or system may be located on a single device or distributed across multiple devices.

[0117] Moreover, as used herein, the word "exemplary" is intended to mean "serving as an example or instance of something."

[0118] Furthermore, to the extent the term "comprises" is used in the detailed description or claims, it is intended that the term have the same inclusiveness as the term "comprises," as the term "comprises" is interpreted as a transitional term within the claims.

[0119] Additionally, the operations described herein may include computer-implementable instructions, which may be implemented by one or more processors and / or stored on one or more computer-readable media. Computer-executable instructions may include routines, subroutines, programs, threads of execution, etc. Additionally, the results of the operations of these methods may be stored on a computer-readable medium, displayed on a display device, and / or the like.

[0120] Although the ordering of steps in the methods described herein is exemplary, these steps may be performed in any suitable order, or simultaneously where appropriate. Furthermore, steps may be added to or substituted into any method, or single steps may be deleted from any method, without departing from the scope of the subject matter described herein. Aspects of any of the above examples may be combined with aspects of any other example described to form further examples without losing the desired effect.

[0121] What has been described above includes examples of one or more embodiments. Of course, in order to describe the above aspects, it is not possible to describe every possible variation and modification of the above-described devices or methods, but those skilled in the art will recognize that many further modifications and arrangements of the various aspects are possible. Accordingly, the described aspects are intended to include all such variations, modifications, and modifications that fall within the scope of the appended claims.

Claims

1. 1. A computer-implemented method for encrypting image data, comprising: the image data is generated by acquiring a signal having a bandwidth; the image data includes data corresponding to a plurality of pixels of an image, each pixel having an associated phase value; The method comprises:

1. A method comprising: modifying each phase value associated with each of the plurality of pixels based on a first cryptographic key; and wherein after modifying each phase value, a rate of phase change between adjacent pixels does not exceed a bandwidth.

2. The method comprises: providing one or more additional images to form a plurality of coherent images, each image of the plurality of coherent images being associated with respective image data; and encrypting the image data associated with one or more of the plurality of coherent images by performing the method of claim 1 on the image data associated with each of the one or more images of the plurality of coherent images; 10. The method of claim 1, wherein encrypting the one or more images of the plurality of coherent images removes coherence between each of the one or more encrypted images of the plurality of coherent images and each other image of the plurality of coherent images.

3. The method of claim 2 , wherein image data associated with each of the one or more images is encrypted with a different first encryption key.

4. selecting an image or a portion of each image to encrypt; 4. The method of claim 1, further comprising the step of encrypting the selected portion by modifying each phase value associated with each of a plurality of pixels within the selected portion based on the first encryption key.

5. The method further comprises the step of overlaying a respective mask on the or each image to be encrypted, wherein modifying each phase value respectively associated with each of a plurality of pixels of the or each image to be encrypted comprises: modifying the mask based on the first encryption key; and modifying each phase value associated with each of a plurality of pixels of the or each image to be encrypted based on the deformation of the mask.

6. 6. The method of claim 5, dependent on claim 2, wherein the deformation masks associated with each of the one or more images to be encrypted are each subjected to a different deformation.

7. 6. The method of claim 5, wherein the or each mask comprises a plurality of nodes, and wherein said step of transforming a mask comprises adjusting the height of each of the nodes for the respective image based on the first cryptographic key.

8. The method of claim 7 , wherein the position of each of a plurality of said nodes within a respective said mask is determined based on a second cryptographic key.

9. 9. The method of claim 2, wherein each of the one or more images is encrypted with a different second encryption key.

10. The method of claim 7 , wherein each of a plurality of said nodes defines a respective vertex of a polygonal network defined by said mask or a respective center of a polygon of said polygonal network defined by said mask.

11. 4. A method according to any one of claims 1 to 3, wherein the or each image is generated by synthetic aperture radar imaging and / or the or each image is a satellite generated image.

12. The method of claim 1 , wherein the first cryptographic key is generated based on a random seed generation.

13. The method of claim 8 , wherein the second cryptographic key is generated based on a random seed generation.

14. An apparatus comprising a processor configured to perform the method of any one of claims 1 to 3.

15. A computer readable medium comprising instructions which, when executed by a computer, cause the computer to carry out the method of any one of claims 1 to 3.

Citation Information

Patent Citations

  • Method and apparatus for multiple image encryption and decryption

    KR1020190139483A

  • Holographic encryption of multi-dimensional images

    US20160110564A1

  • Magnetic resonance imaging device and processing method thereof

    WO2014125876A1