Image delivery using synthetic re-encrypted images
The method of encrypted region image segmentation and re-encryption in surveillance systems addresses privacy concerns by allowing only authorized users to reconstruct images, ensuring confidentiality of sensitive information.
Patent Information
- Application Number
- JP2023501040
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-07-05
- Filing Date
- 2021-07-06
- Publication Date
- 2025-11-12
- Estimated Expiration
- 2041-07-06
AI Technical Summary
The widespread use of digital surveillance systems raises concerns about privacy invasion and targeted surveillance of individuals, prompting the need for privacy-preserving methods to distribute images to multiple users while maintaining confidentiality.
A method involving encrypted region image segmentation, re-encryption, and composite image generation is employed to create user-specific plaintext versions of source images, using a privacy management server to generate encrypted private masks, re-encrypted images, and combine them into a composite private image for distribution to client devices.
This approach ensures that only authorized users can reconstruct the complete image, maintaining privacy by preventing unauthorized access to sensitive information within the distributed images.
Smart Images

Figure 0007768967000017 
Figure 0007768967000018 
Figure 0007768967000019
Abstract
Description
[Technical Field]
[0001]
[0001] Related Applications This application claims the benefit of the filing date of U.S. Provisional Patent Application No. 62 / 705,604, filed July 7, 2020, entitled "Privacy-Preserving Surveillance Systems and Methods," the entire contents of which are incorporated herein by reference.
[0002] This invention relates to image processing, and in particular to using cryptographic operations to distribute images to multiple users in a manner that preserves the privacy of selected users. [Background technology]
[0003]
[0003] Recent advances in imaging technology and artificial intelligence have led to an explosion in the popularity of digital surveillance. Video surveillance of public places has traditionally been used by police to prevent crime. Surveillance cameras are also increasingly being used on private premises, in stores, offices, and schools. Data collected by the cameras is often further processed to extract various features, such as the license plate of a vehicle or the identity of a person appearing in a particular image.
[0004]
[0004] The widespread use of such technology has raised several problems. Pro-democracy activists have criticized some governments for using surveillance to target political opponents, dissidents, and particular social and ethnic groups. More recently, society at large has also become less accepting of mass surveillance, increasingly viewing it as an invasion of privacy. Summary of the Invention [Problem to be solved by the invention]
[0005]
[0005] Therefore, there is a great deal of interest in developing privacy-preserving video surveillance systems and methods. [Means for solving the problem]
[0006] According to one aspect, a method for distributing privacy-preserving images to a plurality of users includes, using at least one hardware processor of a privacy management server, performing encrypted region image segmentation of the source image to determine a plurality of encrypted private masks in response to receiving an encrypted source image decodable with a management key. Each of the plurality of encrypted private masks indicates a region of the source image selected to depict a private item of a respective one of the plurality of users. The method further includes, using at least one hardware processor of the privacy management server, transmitting the plurality of encrypted private masks to an image distribution server for decryption, and, in response thereto, determining a plurality of encrypted private images. Each private image of the plurality of encrypted private images is determined according to the source image and a respective decryption mask including decrypting each of the plurality of encrypted private masks, the respective decryption masks being received from the image distribution server. The method further includes, using at least one hardware processor of the privacy management server, performing an encrypted region rekey procedure to generate a plurality of re-encrypted images. Each re-encrypted image of the plurality of re-encrypted images includes a result of converting a respective private image of the plurality of encrypted private images from a state decodable with the management key to a state decodable with a respective user's private key. The method further includes combining, using at least one hardware processor of the privacy management server, the plurality of re-encrypted images into a composite private image and transmitting the composite private image to an image distribution server for further distribution to a plurality of client devices, each configured to reconstruct a user-specific plaintext version of the source image according to the composite private image.
[0007] According to another aspect, a computer system includes a privacy management server configured to perform encrypted region image segmentation of the source image to determine a plurality of encrypted private masks in response to receiving an encrypted source image decodable by a management key. Each mask of the plurality of encrypted private masks indicates a region of the source image selected to show a private item of a respective user of a plurality of users. The privacy management server is further configured to transmit the plurality of encrypted private masks to an image distribution server for decryption and, in response thereto, determine a plurality of encrypted private images. Each private image of the plurality of encrypted private images is determined according to the source image and further according to a respective decryption mask including a decryption of each mask of the plurality of encrypted private masks, the respective decryption masks being received from the image distribution server. The privacy management server is further configured to perform an encrypted region rekey procedure to generate a plurality of re-encrypted images. Each re-encrypted image of the plurality of re-encrypted images includes a result of converting a respective private image of the plurality of encrypted private images from a state decodable by the management key to a state decodable by a respective user's private key. The privacy management server is further configured to combine the plurality of re-encrypted images into a composite private image and transmit the composite private image to the image distribution server for further distribution to a plurality of client devices. Each client device is configured to reconstruct a user-specific plaintext version of the source image according to the composite private image.
[0008] According to another aspect, a non-transitory computer-readable medium stores instructions that, when executed by at least one hardware processor of a privacy management server, cause the privacy management server to perform encrypted region image segmentation of the source image to determine a plurality of encrypted private masks in response to receiving an encrypted source image decodable with a management key. Each mask of the plurality of encrypted private masks indicates a region of the source image selected to show a private item of a respective one of a plurality of users. The instructions further cause the privacy management server to transmit the plurality of encrypted private masks to an image distribution server for decryption and, in response, determine a plurality of encrypted private images. Each private image of the plurality of encrypted private images is determined according to the source image and a respective decryption mask including a decryption of each mask of the plurality of encrypted private masks, the respective decryption masks being received from the image distribution server. The instructions further cause the privacy management server to perform an encrypted region key rekey procedure to generate a plurality of re-encrypted images. Each re-encrypted image of the plurality of re-encrypted images includes a result of converting a respective private image of the plurality of encrypted private images from a state decodable with the management key to a state decodable with a respective user's private key. The instructions further cause the privacy management server to combine the multiple re-encrypted images into a composite private image and send the composite private image to an image distribution server for further distribution to multiple client devices, each client device configured to reconstruct a user-specific plaintext version of the source image according to the composite private image.
[0009] The above aspects and advantages of the present invention will be better understood upon reading the following detailed description and upon reference to the drawings in which: [Brief explanation of the drawings]
[0010] [Figure 1] FIG. 1 illustrates an exemplary privacy-preserving surveillance system according to some embodiments of the present invention. [Figure 2]
[0011] FIG. 2 illustrates exemplary components of an input sensor according to some embodiments of the present invention. [Figure 3]
[0012] FIG. 2 illustrates exemplary components of a client device in accordance with some embodiments of the present invention. [Figure 4]
[0013] FIG. 2 illustrates exemplary components of an image distribution server according to some embodiments of the present invention. [Figure 5]
[0014] FIG. 2 illustrates exemplary components of a privacy management server according to some embodiments of the present invention. [Figure 6]
[0015] 1A and 1B illustrate exemplary source images according to some embodiments of the present invention; [Figure 7]
[0016] FIG. 7 illustrates an exemplary public image contained within the source image of FIG. 6 according to some embodiments of the present invention. [Figure 8]
[0017] FIG. 7 illustrates an exemplary private image included within the source image of FIG. 6 according to some embodiments of the present invention. [Figure 9]
[0018] 10A-10C illustrate exemplary user masks according to some embodiments of the present invention; [Figure 10]
[0019] FIG. 2 illustrates exemplary data exchanges that take place to set up a privacy-preserving monitoring system, according to some embodiments of the present invention. [Figure 11]
[0020] FIG. 2 illustrates exemplary data exchanges that occur during operation of a privacy-preserving monitoring system, according to some embodiments of the present invention. [Figure 12]
[0021] FIG. 12 illustrates an exemplary series of steps performed by a privacy management server in an embodiment such as that shown in FIG. 11. [Figure 13]
[0022] FIG. 4 illustrates an exemplary data exchange that occurs in another embodiment of the present invention. [Figure 14]
[0023] FIG. 14 illustrates another exemplary sequence of steps performed by a privacy management server in an embodiment such as that shown in FIG. 13. [Figure 15]
[0024] FIG. 10 illustrates an exemplary sequence of steps performed by an image distribution server according to some embodiments of the present invention. [Figure 16]
[0025] 5 illustrates an exemplary series of steps that outline an exchange between a client device and a delivery server according to some embodiments of the present invention; [Figure 17A]
[0026] FIG. 10 illustrates exemplary reconstructed images available to selected client devices in accordance with some embodiments of the present invention. [Figure 17B]
[0027] FIG. 10 illustrates another exemplary reconstructed image available to another client device according to some embodiments of the present invention. [Figure 18]
[0028] FIG. 2 illustrates an exemplary data exchange in an embodiment of the present invention configured to perform a selected task in a privacy-preserving manner. [Figure 19]
[0029] FIG. 2 illustrates an exemplary hardware configuration of a computing device configured to perform operations according to some embodiments of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0011]
[0030] In the following description, it is understood that all described connections between structures can be direct operational connections or indirect operational connections through intervening structures. A set of elements includes one or more elements. Reference to an element is understood to refer to at least one element. A plurality of elements includes at least two elements. Unless otherwise specified, the use of "or" refers to a non-exclusive "or." Unless specifically required, described method steps do not necessarily have to be performed in the particular illustrated order. A first element (e.g., data) derived from a second element encompasses a first element equal to the second element and a first element generated by processing the second element and, optionally, other data. Making a determination or decision according to a parameter encompasses making a determination or decision according to the parameter and, optionally, other data. Unless otherwise specified, a label for any quantity / data may be the quantity / data itself or may be a label different from the quantity / data itself. A computer program is a sequence of processor instructions that perform a task. In some embodiments of the present invention, computer programs described may be standalone software entities or subentities (e.g., subroutines, libraries) of other computer programs. The term "database" is used herein to denote any structured collection of data. As used herein, performing encryption-domain procedures / operations refers to performing the respective procedures / operations in the encryption domain, i.e., directly on encrypted inputs to generate encrypted outputs in a manner that does not involve decrypting the inputs. An encryption-domain procedure differs from a procedure that decrypts an input and then encrypts the output of the respective procedure. In other words, an entity that performs an encryption-domain procedure / operation on an encrypted item does not need to know the plaintext version of the respective item. Computer-readable media encompasses non-transitory media, such as magnetic, optical, and semiconductor storage media (e.g., hard drives, optical disks, flash memory, DRAM), as well as communication links, such as conductive cables and fiber optic links.In some embodiments, the present invention provides, inter alia, computer systems including hardware (e.g., one or more processors) programmed to perform the methods described herein, and computer-readable media encoded with instructions for performing the methods described herein.
[0012]
[0031] The following description illustrates embodiments of the present invention by way of example, and not necessarily by way of limitation.
[0032] 1 illustrates an exemplary privacy-preserving surveillance system 10 according to some embodiments of the present invention. The term "surveillance" is used herein solely to clarify the disclosure by focusing on a particular example use case, and is not intended to limit it to typical surveillance activities such as crime prevention. While the following description focuses on a video surveillance example, the systems and methods of the present disclosure may be adapted for other applications, such as ensuring privacy and / or confidentiality during collaboration between multiple parties working on the same document, preventing cyberbullying via online messaging, etc.
[0013]
[0033] System 10 includes, among other things, an input sensor 14, a distribution server 30, a privacy management server 40, and a plurality of client devices 12a-12c, all communicatively coupled by a network 15, which may include the Internet.
[0014]
[0034] The sensors 14 (e.g., cameras, microphones, etc.) are configured to acquire signals (e.g., encoded images and / or audio) that are further manipulated and converted as described below. In a video surveillance example, the sensors 14 may include video cameras positioned to acquire images of a public place, such as a schoolyard, market square, etc. Accordingly, the sensors 14 may include hardware and / or software means for acquiring signals (e.g., charge-coupled device CCD photosensors), computer-readable media for storing the acquired signals, and means for transmitting the respective signals (e.g., physical layer communication hardware, encoders, antennas, etc.). FIG. 2 illustrates other exemplary components of the input sensors 14, which may include dedicated software modules according to some embodiments of the present invention. The encryption engine 16 encrypts the acquired images / audio recordings. The communication module 18 further transmits the resulting encrypted signals to the privacy management server 40 and / or the image distribution server 30, as described below.
[0015]
[0035] In some embodiments, encryption engine 16 encrypts data according to a homomorphic encryption scheme. Homomorphic encryption is a particular type of encryption that allows for the performance of certain computations, such as addition and / or multiplication, of encrypted data such that decrypting the result of the computation produces the same output as applying the respective computation to a plaintext version of the same data. In other words, let Enc(p)=c denote a homomorphic encryption operation, where p represents a plaintext message and c represents the corresponding ciphertext, Dec(c)=p represents a homomorphic decryption operation that recovers each plaintext message from the ciphertext, and Eval(F,{c,...,c k})=C is a set of ciphertexts c i represents a homomorphic evaluation procedure that generates ciphertext C by applying a function F to Dec(C)=F(p1,...,p k ) [1] where p i =Dec(c i), i=1,...k. In formal mathematical terms, the encryption and decryption procedures of a homomorphic encryption scheme are said to be homomorphic between the plaintext space and the ciphertext space.
[0016]
[0036] Several homomorphic encryption schemes / cryptosystems are known in the art. Schemes that preserve the homomorphic property for any combination of addition and multiplication are generally referred to as fully homomorphic. An example is the Gentry-Sahai-Waters (GSW) scheme. Other schemes / algorithms are homomorphic only for certain types of operations, e.g., only addition in the case of the Paillier scheme and only multiplication in the case of the Rivest-Shamir-Adelman (RSA) scheme. Such schemes are referred to in the art as partially homomorphic. In contrast, ciphers that do not have the above-mentioned homomorphic property are considered non-homomorphic in this specification. An example of a non-homomorphic encryption scheme is the Advanced Encryption Standard (AES), which is used in some Transport Layer Security (TLS) communication protocols.
[0017]
[0037] Client devices 12a-12c collectively represent any end-user electronic device, such as a personal computer, smartphone, television, etc., used to access and / or process (e.g., visualize, play, etc.) data provided by input sensors 14. In some embodiments, such as shown in FIG. 3, client device 12 may execute a monitoring software application 22 configured to conduct a user authentication exchange (e.g., a login procedure) with distribution server 30 and to subsequently display reconstructed images to the user. A data reconstruction engine 24 is configured to reconstruct images from a set of plaintext public images and a set of encrypted private images, as described below. A client encryption engine 26 is configured to decrypt the received encrypted private images. In some embodiments, engine 26 implements a homomorphic decryption algorithm.
[0018]
[0038] Each of the distribution server 30 and the privacy management server 40 collectively represents a set of interconnected computer systems that may or may not be physically proximate to one another. Exemplary components of the servers 30 and 40 are shown in Figures 4 and 5, respectively. In some embodiments, such components represent computer programs (software) executing on at least a hardware processor. Not all of the components shown need execute on the same hardware processor or physical machine. Those skilled in the art will recognize that in alternative embodiments, some of the components shown may be implemented in dedicated hardware, such as an application-specific integrated circuit (ASIC) and / or a field-programmable gate array (FPGA), in firmware, or a combination of the above.
[0019]
[0039] In some embodiments, distribution server 30 manages the monitoring service, including, for example, communicating with client devices 12a-12c for user registration and / or authentication and delivering selectively encrypted data to each client device. Without loss of generality, server 30 may be referred to herein as an image distribution server, i.e., a server configured to deliver images (e.g., video) to clients. Those skilled in the art will appreciate that, depending on the actual embodiment and use case, server 30 may deliver other types of data, such as audio, electronic documents, etc. A user manager component 32 may manage a set of user and / or account data (e.g., usernames, passwords, various service contract parameters, etc.) and provide a user interface for user registration and account management.
[0020]
[0040] An access manager component 38 may selectively store and / or retrieve data from data repository 20 and may selectively transfer such data to each client device 12a-12c depending on the identity of the user currently authenticated at the respective client device. Access manager 38 may include a web server or the like.
[0021]
[0041] Encryption key manager 34 may initiate and / or perform key generation and exchange procedures with client devices 12a-12c and privacy management server 40. Key manager 34 may also generate a set of proxy re-encryption tokens and selectively associate each such token with a registered user of the monitoring service and / or client device 12a-12c. Further details of such processes are provided below.
[0022]
[0042] The managed encryption engine 36 may be configured to perform data encryption and / or decryption operations, as described in further detail below. The engine 36 may implement a version of a homomorphic encryption / decryption algorithm.
[0023]
[0043] In some embodiments, data repository 20 may include a computer-readable storage medium configured to store a database of private and public data. Public data may include any data accessible to all users, such as cleartext (i.e., unencrypted) images. Private data may be accessible and / or decryptable only by selected users. Examples of private data include user-specific and synthetic proxy re-encrypted images, as shown below. Such data may be indexed according to user to allow selective insertion and retrieval. Indexing may take any form known in the art.
[0024]
[0044] In some embodiments, privacy management server 40 (FIG. 5) provides services such as encryption and automatic detection of private / sensitive items in data provided by input sensors 14. A re-encryption engine 46 of server 40 is configured to perform a key swap procedure on the encrypted data, as described in more detail below. As used herein, a key swap procedure refers to a procedure that converts ciphertext from a state decipherable using one key to a state decipherable using another key. One example of a key swap procedure is referred to in the art as proxy re-encryption, which allows entity Z, given some information about another entity Y, to modify a ciphertext encrypted under entity X's public key, thereby making the ciphertext decipherable by entity Y. In other words, entity Y can decrypt a ciphertext encrypted under X's public key using its secret key, but can only decrypt it after the respective ciphertext has been proxy-re-encrypted by entity Z using a re-encryption key (also referred to in the art as a re-encryption token) unique to entity Y. 1, some embodiments of privacy management server 40 proxy re-encrypt data that was previously encrypted with the public key of distribution server 30 to make the respective data decodable by selected users of client devices 12a-12c. The proxy re-encryption procedure uses a re-encryption token that is unique to each user and / or device, e.g., a token generated according to the respective user / device's public encryption key.
[0025]
[0045] In some embodiments, re-encryption engine 46 operates in the encryption domain, i.e., each key swap procedure occurs without decrypting the input. To accomplish encryption domain key swapping, some embodiments of engine 46 implement a proxy re-encryption algorithm that is compatible with homomorphic encryption / decryption algorithms implemented by client devices 12 a-12 c, distribution server 30, and / or input sensors 14. Such algorithms are beyond the scope of this specification; several such examples are known in the art of encryption, such as the PALISADE code library available at https: / / gitlab.com / palisade / palisade-development.
[0026]
[0046] The set of item detectors 42 may be configured to determine whether input data received from the sensors 14 (e.g., frames captured by a surveillance camera) includes representations of private / confidential items associated with a selected user. Examples of private items include a person, a face or some other body part, a logo / trademark, a license plate, a bank card, a personal ID (e.g., a driver's license, a passport), handwritten characters, and a person's signature. In embodiments configured to operate with voice, examples of private items may include any item that allows a person to be identified, such as any voice quality, such as tone quality, vocal fry, pitch, tempo, and intonation. Other examples of private audio items include the speech of names and selected words (e.g., curse words, racial slurs, etc.), gunshots, the sound of an argument, etc. In embodiments configured to process text documents and / or electronic messages, examples of private items include written names, addresses, financial information such as credit card numbers, etc. Other examples include text written by a selected author, text written about a selected subject, and text written in a selected style or conveying a selected emotion, etc.
[0027]
[0047] Private items may be user-specific. For example, in a schoolyard surveillance use case, each parent may define their child as a private item, and thus each child may be visible only to their respective parent. In some embodiments, multiple users may share private items, and / or one user may have multiple private items. In one such example, all members of a particular user group (e.g., parents of third-grade children) may be able to see the faces of their child's classmates, but other users may not.
[0028]
[0048] FIG. 6 illustrates an example source image 70 received from a surveillance camera (input sensor 14), where image 70 shows example private / confidential items, including people (e.g., children 72a-72b), a face 72c, and a particular object 72d. FIGS. 7-8 illustrate example public and private images included in example source image 70. In some embodiments, the private image includes a representation (e.g., a number array) that represents the private / confidential item. In the example of FIG. 8, private image 76a includes a region of the source image that shows private item 72a of FIG. 6. Additionally, public image 74 (FIG. 7) may include other regions of source image 70 that do not show any private items. For example, public image 74 may show all of the content of source image 70 that is not private. An example of a public image includes the background of a scene (landscape, buildings, trees, courtyard, sky, etc.). In some embodiments, public image 74 and / or private image 76a are represented as a number array having the same size as source image 70.
[0029]
[0049] The item detector 42 may be configured using any method known in the art. For example, an exemplary item detector 42 may include an artificial intelligence (AI) system 43a, such as a set of artificial neural networks, pre-trained to identify instances of respective private items in source images. An exemplary AI system 43a includes a facial recognition module and an image segmentation module, etc. The construction and training of such item detectors is beyond the scope of this specification; several architectures and training strategies are known in the art.
[0030]
[0050] In an image processing embodiment, an example item detector 42 may receive a source image 70 and output a user mask indicating regions of the source image that exhibit representations of private items (e.g., regions of the source image that show a particular person's face). FIG. 9 shows an example user mask 80a associated with the private item 72a of FIG. 6. One example user mask is characterized by a subset of pixels belonging to the image of the respective private item. Another example user mask includes all pixels located within a contiguous region of the source image 70, this region representing the private item. For example, in the embodiment shown in FIG. 9, such a region may be defined as the interior of a polygon (e.g., a convex hull, a bounding box, etc.) that encloses the image of the private item. A convenient computer-readable code for a user mask includes a sparse array of numbers, the array having the same size as the source image 70, with all elements zero except for elements corresponding to pixels of the mask. Multiple user masks may be associated with a single user (i.e., with a single re-encryption token; see below). Some user masks may overlap.
[0031]
[0051] In some embodiments, detector 42 operates in the encrypted domain, i.e., without decrypting the source image. To achieve such encrypted domain operation, AI system 43a (e.g., a neural network implementing face recognition) may be purposely structured to be compatible with homomorphic encryption schemes. For example, detector 42 may receive a homomorphically encrypted source image and, in response, output a homomorphically encrypted user mask, where the user mask is encrypted using the same encryption key used to encrypt the source image. Several such AI systems have been described in the art. See, for example, N. Dowlin et al., "CryptoNets: Applying Neural Networks to Encrypted Data with High Throughput and Accuracy," Proceedings of the 33rd International Conference on Computer Vision and Systems Engineering (CVSS) , Vol. 1, No. 10, pp. 1111-1115, 2013. rd CryptoNets are described in International Conference on Machine Learning, New York, NY, 2016, JMLR:W&CP, vol. 48. In one such example, an AI system 43a includes a neural network in which selected layers correspond to polynomials of a predetermined degree, and typical nonlinear activation functions such as rectified linear units (ReLUs) are replaced with polynomial approximations.
[0032]
[0052] In some embodiments, the AI system 43a is pre-trained by the AI training system 11 (e.g., a machine learning algorithm running on a processor) using training data provided or otherwise indicated by each user. In one such example, when registering for the service, each user may provide a sample representation of their respective sensitive items, such as an image of a face or a sample of a person's vocalizations. Some embodiments may then train the AI system 43a to identify representations representative of each private item in the data stream received from the input sensor 14. One such example is training facial recognition software with target faces provided by each user. The training generates a set of optimized detector parameter values 45a, which are sent to the item detector 42. In a neural network embodiment, example parameters 45a include a set of synaptic weights and neuron biases, etc.
[0033]
[0053] FIG. 10 illustrates an exemplary exchange for initializing / configuring a privacy-preserving monitoring service in accordance with some embodiments of the present invention. In the illustrated example, the distribution server 30 performs a key generation procedure to generate a pair of homomorphic encryption keys (herein considered administrative keys) specific to the distribution server 30 and transmits a public key 52 of the pair of homomorphic encryption keys to the input sensor 14 for use in encrypting acquired signals / images. The server 30 also performs a key generation and / or exchange protocol with the client device 12 (which collectively represents any of the client devices 12a-12c of FIG. 1), which generates a different pair of encryption keys (herein considered user keys) specific to each user accessing the privacy-preserving monitoring service via the client device 12. Alternate embodiments may generate device-specific encryption keys. User and / or device key generation may occur at sign-up as part of each user's initial service setup procedure and may proceed according to a homomorphic encryption key generation algorithm. The client device 12 then transmits a public user key 54 to the distribution server 30. In response to receiving the keys 54, the key manager 34 may generate a set of proxy re-encryption tokens 50 uniquely associated with each user and / or client device. Some embodiments generate each set of user-specific tokens 50 according to a public key associated with each user / device and according to an administrative key via a token generation algorithm compatible with the homomorphic encryption algorithm used by the client device 12 to generate the user / device keys. Such key generation protocols / procedures are beyond the scope of this specification, and some examples are known in the art of encryption. The re-encryption tokens 50 are then transmitted to the privacy management server 40 for use in proxy re-encryption of the user-specific private images, as described in more detail below.
[0034]
[0054] 11 and 13 illustrate the exchange of data that occurs in two exemplary embodiments of a privacy-preserving surveillance system. For clarity, the following description will focus on video surveillance, i.e., the relevant source data includes image data. Those skilled in the art will recognize that the methods described herein are applicable to other applications where the relevant data includes encoding of audio (e.g., recorded audio), text, etc.
[0035]
[0055] Figures 12 and 14 illustrate alternative sequences of steps performed by the privacy management server 40 in the embodiments described by Figures 11 and 13, respectively. Additionally, Figure 15 illustrates exemplary steps performed by the image distribution server 30.
[0036]
[0056] In some embodiments, data acquired by input sensor 14 is encoded as a plaintext image I, for example comprising an array of numbers, each number representing the intensity of a respective image at a different location / pixel. Some images may have multiple channels (e.g., red, green, and blue), and in such embodiments, each channel may be represented by a separate array. Image I is then encrypted by sensor encryption engine 16 according to public management key 52 to generate an encrypted data stream 60 that is sent to privacy management server 40. Stream 60 may include, for example, a set of encrypted source images as follows:
[0037]
number
[0038] where Enc(x,k) generically denotes the encryption of quantity x using key k, and k p admin denotes the public management key 52. An asterisk (*) is used throughout to denote an encrypted quantity. In a video surveillance embodiment, each encrypted source image I * may correspond to different frames and may be tagged with an associated timestamp indicating the moment that each frame was taken.
[0039]
[0057] In response to receiving the data stream 60, each encrypted source image I * For each image, in step 204 (FIG. 12), the server 40 may apply an item detector 42 to determine whether the respective image contains private data (i.e., images of items considered private by some users). If yes, some embodiments of the detector 42 return a set of user masks (see example mask 80a in FIG. 9) that identify regions of the source image that show various private items. Such masks are also indexed according to the users who declared the respective items private. Some embodiments may further determine a set of public masks that include regions of the current frame that contain only public data. In one example embodiment, the public masks are determined by inverting all user masks and overlaying the results. In another embodiment, the item detector 42 may be trained to return the set of public masks along with the user masks.
[0040]
[0058] However, the privacy management server 40 does not have the private management key, and therefore does not have the source image I * , some embodiments of item detector 42 operate in the encrypted domain, i.e., directly on the encrypted data, and generate an encrypted output (i.e., the user mask is also encrypted). Thus, in some embodiments, item detector 42 runs on server 40, but server 40 is unaware of the content of the source image, nor which regions of the source image contain private items, if any.
[0041]
[0059] In some embodiments, a set of steps 206-208 (FIG. 12) generates a current source image I according to the output of the item detector 42. *, and perform an encrypted region image segmentation procedure to extract a set of encrypted public and private images from i. Each private image may contain the (encrypted) content of the current source image located within a different user mask. In some embodiments, the encrypted private image associated with user mask i may be determined by pixel-wise multiplication of the encrypted source image and the encrypted mask i, as follows:
[0042]
number
[0043] In the above equation, M * i is the encrypted user mask i returned by the item detector 42
[0044]
number
[0045] In the above formula, M i denotes the unencrypted / plaintext user mask i.
[0060] where the circled dot operator is pixel-wise multiplication
[0046]
number
[0047] where the pair {x,y} indexes the location / pixel in the source image and user mask, respectively. Pixel-wise multiplication is applied to images / arrays of the same size.
[0061] Meanwhile, the encrypted public image of the current frame (item 62 in FIG. 11 ) may be calculated by element-wise multiplication of the encrypted source image and the encrypted public mask as follows:
[0048]
number
[0049] In the above formula, M*PUBLIC denotes the encrypted public mask generated by the item detector 42,
[0050]
number
[0051] In the above formula, M PUBLIC indicates the respective unencrypted / plaintext public mask.
[0062] In some embodiments, in step 210, the privacy management server 40 may use the re-encryption engine 46 to proxy-re-encrypt the determined private image as shown above (e.g., equation [2]) according to a re-encryption token associated with each user / mask i to generate an individual user-specific re-encrypted private image 66 ( FIG. 11 ), which is then transmitted to the image distribution server 30. Such proxy re-encryption ensures that each private image is decipherable only by the holder of the decryption key associated with the user / mask i. In some embodiments, the re-encrypted private image 66 is tagged with an indicia of the respective user so that the server 30 can selectively insert and / or retrieve the image 66 from the data repository 20. A further sequence of steps 212-214 transmits the encrypted public image 62 and the re-encrypted private image 66 to the server 60 for further distribution to the client devices 12 a-12 c.
[0052]
[0063] 13-14, in step 230, server 40 may transmit encrypted user mask 64 to image distribution server 30 for decryption and, in response, receive a decrypted user mask 65 from server 30. In some embodiments, decrypted mask 65 includes a plaintext version of the encrypted user mask determined by item detector 42, as follows:
[0053]
number
[0054] where Dec(x,k) generically denotes the decryption of quantity x using key k, and k s admin denotes a private encryption key held by the image distribution server 30. In such an embodiment, the privacy management server 40 knows explicitly whether a source image shows a private item and which areas of the source image show private items, but the server 40 does not know the exact location of each source image I * Privacy is still maintained because no region of the image can be decoded.
[0055]
[0064] Next, in step 234, the private image may be extracted by copying the pixels of the encrypted frame that lie within each decrypted user mask 65. In some embodiments, this may be to find the encrypted private image associated with mask i as follows:
[0056]
number
[0057]
[0065] A further step 236 may use the re-encryption engine 46 to proxy-re-encrypt each such private image with the user's re-encryption token associated with each mask i to generate an individual re-encrypted private image. Then, in step 238, some embodiments may calculate a composite re-encrypted private image 67 according to the multiple individual re-encrypted private images determined in step 236. In some embodiments, the composite image 67 is calculated by dividing each individual re-encrypted private image by its respective user mask M i The composite private image may then be calculated according to the following formula:
[0058]
number
[0059] where ReEnc(x,t) generically denotes the proxy re-encryption of ciphertext x using token t, and t i denotes the re-encrypted token associated with user / mask i, where the circled plus operator denotes pixel-wise addition.
[0060]
number
[0061] where the pairs {x,y} index positions / pixels in example images I1 and I2, respectively. Pixel-wise addition can be applied to images of the same size.
[0066] The calculated composite re-encrypted private image 67 may then be sent to the image distribution server in step 240. In another embodiment, the privacy management server 40 may calculate individual proxy re-encrypted private images and send each image to the distribution server 30. Additionally, the server 30 may determine the composite image 67 from the received individual re-encrypted images, for example, using equation
[10] .
[0062]
[0067] Alternatively (step 226 of FIG. 14), the privacy management server 40 may compute the encrypted public image 62 as described above (e.g., equation [6]). Alternatively, the image 62 may be determined by the plaintext public mask as follows:
[0063]
number
[0064] In the above formula, M PUBLIC is received from the distribution server 30. In yet another embodiment, M PUBLIC is the sum of all plaintext user masks M received from the server 30 iand overlapping the results. In either of these situations, image 62 is encrypted with a control key because server 40 performs image segmentation in the encrypted domain, i.e., without decrypting the source image. In other words, server 40 does not know the plaintext content of public image 62. In step 228, encrypted public image 62 is sent to server 30 for decryption and further delivery to clients.
[0065]
[0068] 15 illustrates an exemplary operation of image delivery server 30, according to some embodiments of the present invention. In the sequence of steps 252-254, server 30 may wait for a communication from privacy management server 40. If such a communication includes an encrypted user mask (step 256 returns yes), image delivery server 30 may use encryption engine 36 to decrypt each mask with its private management key (e.g., equation [6] above) and send the decrypted mask to privacy management server 40.
[0066]
[0069] If the communication contains an encrypted public image 62, the server 40 decrypts it to produce a decrypted public image 63.
[0067]
number
[0068] may be obtained and the image 63 may be stored in the data repository 20. The decoded public image 63 may be tagged with a timestamp, frame number, or other indicia that associates the image 63 with the source image from which it was derived.
[0069]
[0070] If the communication received from server 40 includes re-encrypted private images (either specific to user / mask i or synthetic, depending on whether server 40 follows flowchart 12 or 14, respectively), image distribution server 30 may insert each private image into data repository 20. The re-encrypted private images may be tagged with a timestamp and / or label that associates each image with its respective source image. The private images may be tagged to indicate their association with a particular user and / or mask.
[0070]
[0071] FIG. 16 illustrates further exemplary steps performed by the image delivery server 30 in connection with a client device 12, which may collectively represent any of the client devices 12a-12c of FIG. 1. At step 280, the client device 12 may perform a user authentication procedure to identify the current user of the device 12 to the delivery server 30. Step 280 may implement any user authentication protocol known in the art (e.g., password, two-factor, biometric authentication, etc.). At step 282, the device 12 may then send a query to the server 30 to indicate a request to view images captured within a particular time frame, e.g., from a particular surveillance camera. In response, in a sequence of steps 284-290, the image delivery server 30 may selectively retrieve a set of public and private images from the data repository 20 in accordance with the query and transmit the respective images to the client device 12. Depending on whether the privacy management server 40 operates according to the flowchart illustrated in FIG. 12 or FIG. 14, the private images may each include an individual re-encrypted private image 66 or a composite re-encrypted private image 67. Such transactions may occur, for example, via a web interface. In another embodiment, the image delivery server 30 may open a dedicated connection (e.g., a VPN tunnel) with the client device 20 and transmit public and private images over the respective connections.
[0071]
[0072] Those skilled in the art will appreciate that, although the public images are decrypted to plaintext prior to delivery, step 288 does not necessarily involve transmitting each public image in plaintext. Instead, step 288 may involve re-encrypting the transmitted public image as part of transmission, e.g., over TLS / HTTPS. However, such encryption does not affect image reconstruction at the client device; in a TLS / HTTPS transaction, the receiving client device is always able to decrypt the payload.
[0072]
[0073] In response to receiving the public and private images, at step 292, client device 12 may use client encryption engine 26 (FIG. 3) to decrypt each private image using a private encryption key associated with the respective user of client device 12. Then, at step 294, data reconstruction engine 24 may calculate a reconstructed image according to the decrypted private image and also according to the decrypted public image 63 received from image distribution server 30. For example, the reconstructed image may be the pixel-wise addition of decrypted public image 63 and the decrypted private image, as follows:
[0073]
number
[0074] or
[0075]
number
[0076] where R i denotes the reconstructed image seen by user i, and k s i denotes the private key of user i. If the source image contains private data of multiple users, a user mask M belonging to a user different from the current user i of client device 12 is jEquation
[14] does not have to compute the entire reconstructed image, in the sense that the region of the reconstructed image corresponding to may be empty. To obtain a complete reconstructed image, some embodiments may fill the missing regions with dummy data, such as zeros, random noise, random colors, etc.
[0077]
[0074] Reconstructing frames according to equation
[14] may be preferable in situations where masks associated with different users may overlap, for example, when some information is relevant to multiple users (e.g., members of a selected group) and other information may be private to each user. Another example of such a situation may arise in an automated image segmentation system configured to generate multi-label classifications.
[0078] In one embodiment where the reconstructed image is calculated from the composite private image, the reconstructed image R i is calculated, but the private key k held by user i is s i can decrypt only the private data of each user. Therefore, the user mask M j The area of the reconstructed image corresponding to the scrambled image will show a scrambled image. This effect is illustrated in Figures 17A-17B, which show how reconstructions of the same source image appear to two different users. Figure 17A shows the reconstructed image as seen by user A, who has declared item 72a (Figure 6) as private. User A can see the image of private item 72a, but cannot see images of other users' private items, such as images of items 72b, 72c, and 72d (see Figure 6). Figure 17B shows the reconstructed image as seen by another user B, for whom item 72b is private. User B can see the image of item 72b, but cannot see images of private items 72a, 72c, and 72d.
[0079] According to equation
[15] , i.e., from the composite encrypted private image to the frame R iReconstructing a composite private image may be preferable in embodiments in which the item detector 42 generates only non-overlapping user masks and / or in embodiments in which different users do not share private information. Otherwise, areas of the reconstructed image covered by overlapping masks may not be decipherable by any individual user and may therefore appear scrambled. Operating on a composite private image can further conserve computational resources by allowing the same encrypted private data (i.e., one composite private image) to be sent to all users rather than storing, indexing, and selectively distributing individual private images to each user. In such embodiments, the server 40 may directly insert private and public images into the data repository 20 without further involvement of the distribution server 30. A disadvantage of embodiments using a composite re-encrypted private image is that the level of privacy guaranteed is relatively lower compared to embodiments using individual private images, since the server 40 operates using decrypted / plaintext masks when computing the private image. In other words, the server 40 does not know the content of the private image, but it does know, for example, whether the source image contains private items and the approximate location of each private item via its respective plaintext mask.
[0080] FIG. 18 illustrates an enhanced form of a privacy-preserving monitoring system according to some embodiments of the present invention. In some embodiments, the privacy management server 40 (FIG. 5) further comprises an image task module 44 configured to perform specific tasks according to the encrypted data stream 60 received from the input sensor 14. An example of an image processing task includes event detection (determining whether an image or a series of images indicates the occurrence of a specific event). For example, in a school monitoring embodiment, the task module 44 may be configured to analyze images captured by a surveillance camera to determine whether the images indicate a fight or bullying event. In a traffic monitoring embodiment, the task module may automatically determine whether a source image indicates an accident, a traffic jam, or the like. Another example task includes counting the number of people in an image and determining whether the count exceeds a predetermined threshold. Yet another example task generally includes any image classification / labeling task, such as determining whether an image indicates a specific type of object (e.g., a weapon, a personal ID, a bank card, a vehicle license plate, etc.). Those skilled in the art will appreciate that while the above examples involve image processing, this aspect is not intended to be limiting and some embodiments may be adapted to process other types of data, such as audio files, text documents, etc. For example, in an audio processing embodiment, task module 44 may determine whether audio captured by input sensor 14 indicates a gunshot, a person shouting, an insult or racist remark, etc.
[0081] In some embodiments, task modules 44 (FIG. 5) include AI systems 43b pre-trained to perform the respective tasks. Some such examples are known in the art of computer vision, and their architecture and training are beyond the scope of this disclosure. AI systems 43b may be pre-trained by system 11 in the sense that AI training system 11 may determine, for example, by a machine learning process, a set of optimized task module parameter values 45b (e.g., synaptic weights, etc.) and may use the values 45b to instantiate a runtime instance of image task module 44.
[0082] Task modules 44 may operate in the encrypted domain, i.e., without decrypting the source data. In such an embodiment, modules 44 may input encrypted images and generate encrypted outputs containing the results of the execution of their respective tasks, each output being encrypted using a public control key k associated with distribution server 30. p admin For example, the output of task module 44 may include an encrypted version of a decision or label (e.g., YES / NO depending on whether data stream 60 indicates the occurrence of a particular event). Because module 44 runs in an encrypted domain, privacy management server 40 does not know the outcome of the task.
[0083] In some embodiments, the output of task module 44 is proxy-re-encrypted by engine 46 (FIG. 5) using the selected user's re-encryption token to generate re-encryption task result 86, which is then sent to distribution server 30 for distribution to predetermined notification devices 13 (e.g., the selected user's smartphone). In some embodiments, notification device 13 may receive decrypted public image 63 so that each user can view the publicly available image data in addition to being notified of the occurrence of their respective event or situation. For example, a school principal (or security personnel) may receive a notification that a fight is occurring on school campus, but the principal (or security personnel) may not know who is actually involved in the fight if such information is considered private. Meanwhile, because task result 86 is only decryptable by the selected notification device, all users except the principal may be unaware that the fight occurred. Furthermore, the owner / operator of server 40 may also be unaware of the event.
[0084] Some embodiments are further enhanced by the addition of a superuser, who may be able to view all private information contained in the source images. Such a superuser may correspond to an authority such as a school principal, a company human resources representative, etc. During the configuration of the monitoring service, the image distribution server 30 may generate a pair of encryption keys and a set of re-encryption tokens associated with the superuser. In one such exemplary embodiment, in response to determining the user mask and extracting the private images, the privacy management server 40 may proxy-re-encrypt the extracted private images associated with all users with the superuser's re-encryption tokens, thereby creating a composite private image accessible only to the superuser. Each re-encrypted private data is then transmitted to the image distribution server 30 and made accessible to the superuser along with the decrypted public image 63. The superuser may decrypt each re-encrypted private image, thereby completely reconstructing the source image according to the public image 63 and the decrypted composite private image. Meanwhile, users who do not possess the superuser's private encryption key cannot view private data belonging to another user.
[0085]
[0082] Figure 19 illustrates an exemplary computer system 90 configured to perform some of the methods described herein. The computer system 90 may correspond to any of the client devices 12a-12c, the image distribution server 30, and the privacy management server 40. The illustrated hardware configuration is that of a personal computer; configurations of other computing devices, such as mobile phones and servers, may differ slightly from that illustrated in Figure 19. A processor 92 includes a physical device (e.g., a microprocessor, a multi-core integrated circuit formed on a semiconductor substrate) configured to perform calculations and / or logical operations on a set of signals and / or data. Such signals or data may be encoded in the form of processor instructions, e.g., machine code, and sent to the processor 92. The processor 92 may include an array of central processing units (CPUs) and / or graphics processing units (GPUs).
[0086]
[0083] The memory unit 93 may include a volatile computer-readable medium (e.g., dynamic random access memory (DRAM)) that stores data and / or instruction codes accessed or generated by the processor 92 in the course of performing operations. The input devices 94 may include a computer keyboard, mouse, trackpad, microphone, etc., including respective hardware interfaces and / or adapters that enable a user to introduce data and / or instructions into the computer system 90. The output devices 95 may include display devices such as monitors and speakers, etc., and hardware interfaces / adapters such as graphics cards, that enable the respective computing devices to communicate data to a user. In some embodiments, the input / output devices 94, 95 share common hardware (e.g., a touchscreen). The storage device 96 includes a computer-readable medium that enables non-volatile storage, reading, and writing of software instructions and / or data. Examples of storage devices include magnetic and optical disks, as well as flash memory devices and removable media such as CD and / or DVD disks and drives. Network adapter 97 includes mechanical, electrical, and signaling circuitry for transmitting data over a physical link coupled to an electronic communications network (e.g., network 15 of FIG. 1) and / or other devices / computer systems. Adapter 97 may be further configured to transmit and / or receive data using a variety of communication protocols.
[0087] Controller hub 98 collectively represents multiple system buses, peripheral buses, and / or chipset buses, and / or any other circuitry that enables communication between processor 92 and other hardware components of computer system 90. For example, controller hub 98 may include a memory controller, an input / output (I / O) controller, and an interrupt controller. Depending on the hardware manufacturer, some such controllers may be incorporated into a single integrated circuit and / or may be integrated with processor 92. In another embodiment, controller hub 98 may include a northbridge that connects processor 92 to memory 93 and / or a southbridge that connects processor 92 to devices 94, 95, 96, and 97.
[0088]
[0085] The example systems and methods described herein enable distribution of data (e.g., video recordings, photographs, audio recordings, digital documents, etc.) to multiple users in a manner that preserves the privacy of each user. Some embodiments use homomorphic encryption and proxy re-encryption techniques to manipulate each data such that selected portions of the data are revealed depending on the identity of the user currently accessing the data.
[0089]
[0086] One illustrative application of some embodiments involves video surveillance, where broadcast data includes a stream of images received from a surveillance camera. Some embodiments use image recognition techniques to determine whether an image contains items deemed sensitive by selected users (e.g., a particular person or face, a particular license plate, etc.), and then manipulate and selectively encrypt each image so that only the respective user can see the sensitive items. Meanwhile, other users can be given access to a different version of the same image, in which the sensitive items are obscured (e.g., hidden, cropped, scrambled, etc.).
[0090] One exemplary use case involves monitoring a school yard for signs of bullying, fighting, and verbal aggression. In some embodiments, selected users (e.g., parents) may designate some of the children as private items. Images of the school yard captured by a video camera may be distributed to multiple users. However, images distributed to the principal and the children's parents, who are considered private, may show each child's face, while images distributed to all other users may have the face obscured or scrambled. Such operations may, for example, protect the privacy of a child being bullied and / or delay disclosure of the aggressor's identity until an investigation of the incident has been conducted.
[0091]
[0088] Applications of some embodiments are not limited to surveillance. In another example, a camera records a presentation of a product or prototype. The images are then transmitted to multiple remote users, for example, in the form of a video conference. However, different users may receive different versions of the same image. For example, users who have signed a non-disclosure agreement may be shown their respective product or prototype, while images distributed to other users may have their respective items obscured / scrambled.
[0092] The nature of the items considered private / sensitive may vary widely from embodiment to embodiment. Some examples include offensive hand gestures, clothing (headscarves, swimwear, etc.), jewelry, certain body parts (bare legs, chest, etc.), weapons, company logos, bodies lying on the ground (which may be homeless or people needing medical assistance), and people in uniform (e.g., police officers, medical personnel). An artificial intelligence system 43 (FIG. 5) may be trained to recognize any such types of private items in the source images. Some users will then be able to see the image of each item, while others will not.
[0093] Many conventional video surveillance systems use encryption to prevent unauthorized access to captured images. Some such systems are also augmented by automatic image recognition and / or image segmentation capabilities. However, conventional surveillance systems first decrypt source images in preparation for image recognition. For example, conventional computer systems performing image analysis typically also possess encryption keys to decrypt source images. In contrast, by utilizing homomorphic encryption, some embodiments of the present invention perform automatic item detection / mask creation directly in the encrypted domain, i.e., without first decrypting the source images. Specifically, a privacy management server as described herein does not even have the keys to decrypt the source data. Thus, in embodiments of the present invention, the computer system performing image recognition and / or segmentation is unaware of the content of the analyzed images, which substantially enhances the privacy of users of the system.
[0094] The use of homomorphic encryption according to some embodiments of the present invention also enables the separation of user management / image distribution activities from image analysis activities. In an exemplary privacy-preserving video surveillance system such as that shown in FIG. 1, server 30 and server 40 may be owned and operated by separate entities. In one exemplary use-case scenario illustrating the benefits of some embodiments of the present invention, company A owns and operates input sensors 14 and distribution server 30, and outsources image processing services, i.e., services provided by server 40, to another company B. Sensors 14 may collect images from an office building, and company A may be interested in automatically detecting events such as unusual office dynamics, the presence of unknown persons, determining attendance at specific office events, determining the times when specific employees arrive or leave work, etc. Company B may provide such services in a privacy-preserving manner, because server 40 does not have access to unencrypted data and, further, does not have the information to decrypt the incoming source data. Instead, image segmentation and / or performance of other tasks occurs in an encrypted domain, with the results of such operations only decryptable by computer systems (e.g., server 30, selected client devices 12a-12c) operated by representatives of Company A. Privacy is further enhanced in embodiments such as those shown in Figures 11 and 13 by the fact that distribution server 30 does not have access to the source data itself, but only to its "public portions," i.e., portions of the source image that do not show private / sensitive items.
[0095] Applications of some embodiments are not limited to image processing / video surveillance, but can also be adapted for processing audio files, documents, electronic messages, and the like. In one such exemplary embodiment, a target person's voice may be selected as a private item. Source data, such as an audio recording, may be processed as shown herein, i.e., divided into a private portion and a public portion, where the private portion may consist of a segment of the source recording containing the target person's speech. The private portion may then be proxy re-encrypted with a token corresponding to a selected subset of users. When each audio recording is reconstructed, those selected users can hear the target person speaking, while other users cannot. Another exemplary embodiment may distort / scramble the speech of specific words (e.g., curse words, selected names, etc.).
[0096] In one exemplary document or message processing embodiment, private items may include specific names, addresses, phone numbers, credit card or bank account numbers, etc. In some embodiments, private items may include entire portions of a document, such as specific sections / chapters, portions with specific authors, or portions dealing with specific subjects. In yet another exemplary embodiment, private items may include portions of conversation (e.g., electronic message exchanges) that exhibit specific emotions, such as anger, threats, suicidal thoughts, or sexually explicit intent. The item detector 42 may use a set of rules or a pre-trained artificial intelligence system to automatically identify such private items in the encrypted source document. Using selective proxy re-encryption techniques as presented herein, the same document may then be distributed to multiple users, with selected users able to view each private item in clear text while other users cannot.
[0097]
[0094] It will be apparent to those skilled in the art that the above-described embodiments can be modified in many ways without departing from the scope of the present invention, and therefore the scope of the present invention is to be determined by the appended claims and their legal equivalents.
Claims
1. 1. A method for distributing privacy-preserved images to a plurality of users, comprising: using at least one hardware processor of a privacy management server, responsive to receiving an encrypted source image decodable with a management key, performing encrypted region image segmentation of the encrypted source image to determine a plurality of encrypted private masks, each mask representing a region of the encrypted source image selected to represent a private item of a respective one of the plurality of users; sending the plurality of encrypted private masks to an image distribution server for decryption; determining a plurality of encrypted private images, each private image of the plurality of encrypted private images being determined according to the encrypted source image and further according to a respective decryption mask including a decryption of a respective mask of the plurality of encrypted private masks, the respective decryption masks being received from the image distribution server; performing an encryption region key change procedure to generate a plurality of re-encrypted images, each of the plurality of re-encrypted images including a result of converting a private image of the plurality of encrypted private images from a state decodable by the management key to a state decodable by the private key of the respective user; combining the re-encrypted images into a composite private image; transmitting the composite private image to the image distribution server for further distribution to a plurality of client devices, each client device configured to reconstruct a user-specific plaintext version of the encrypted source image according to the composite private image; The method includes:
2. 10. The method of claim 1, [Equation 1] where the circled dot symbol indicates pixel-wise multiplication and I * denotes the encrypted source image and M denotes the respective decryption mask.
3. 2. The method of claim 1, wherein combining the multiple re-encrypted images comprises copying each of the re-encrypted images to a location indicated by the respective decryption mask of the composite private image.
4. The method of claim 1 , comprising determining the composite private image according to a pixel-by-pixel addition of the plurality of re-encrypted images.
5. 10. The method of claim 1, performing the encrypted region image segmentation of the encrypted source image further comprises determining an encrypted public image including a region of the encrypted source image selected so as not to show private items of any of the plurality of users; The method further includes transmitting, using at least one hardware processor of the privacy management server, the encrypted public image to the image distribution server for decryption and further transmission to the plurality of client devices; each said client device is configured to reconstruct the user-specific plaintext version of the encrypted source image further according to a decrypted public image received from the image distribution server; method.
6. 6. The method of claim 5, comprising determining the encrypted public image according to the respective decryption masks.
7. The method of claim 1 , wherein the encrypted source image is encrypted according to a homomorphic encryption scheme.
8. 10. The method of claim 1, wherein the user-specific plaintext version of the encrypted source image shows private items of selected users of the plurality of users and obscures private items of other users of the plurality of users.
9. The method of claim 1 , wherein the private items include items selected from the group consisting of people and human faces.
10. The method of claim 1 , wherein the private item includes a bank card.
11. 1. A computer system including a privacy management server, the privacy management server comprising: responsive to receiving an encrypted source image decodable with a management key, performing encrypted region image segmentation of the encrypted source image to determine a plurality of encrypted private masks, each mask representing a region of the encrypted source image selected to represent a private item of a respective one of a plurality of users; sending the plurality of encrypted private masks to an image distribution server for decryption; determining a plurality of encrypted private images, each private image of the plurality of encrypted private images being determined according to the encrypted source image and further according to a respective decryption mask including a decryption of a respective mask of the plurality of encrypted private masks, the respective decryption masks being received from the image distribution server; performing an encryption region key change procedure to generate a plurality of re-encrypted images, each of the plurality of re-encrypted images including a result of converting a private image of the plurality of encrypted private images from a state decodable by the management key to a state decodable by the private key of the respective user; combining the re-encrypted images into a composite private image; transmitting the composite private image to the image distribution server for further distribution to a plurality of client devices, each client device configured to reconstruct a user-specific plaintext version of the encrypted source image according to the composite private image; A computer system configured to:
12. 12. The computer system of claim 11, wherein the privacy management server: [Equation 2] where the circled dot symbol indicates pixel-wise multiplication, and I * denote the encrypted source image, and M denotes the respective decryption mask.
13. 12. The computer system of claim 11, wherein combining the plurality of re-encrypted images comprises copying each of the re-encrypted images to a location indicated by the respective decryption mask of the composite private image.
14. 12. The computer system of claim 11, wherein the privacy management server is configured to determine the composite private image according to a pixel-by-pixel addition of the plurality of re-encrypted images.
15. 12. The computer system of claim 11, performing the encrypted region image segmentation of the encrypted source image further comprises determining an encrypted public image including a region of the encrypted source image selected so as not to show private items of any of the plurality of users; the privacy management server is further configured to transmit the encrypted public image to the image distribution server for decryption and further transmission to the plurality of client devices; each said client device is configured to reconstruct the user-specific plaintext version of the encrypted source image further according to a decrypted public image received from the image distribution server; Computer system.
16. 16. The computer system of claim 15, wherein the privacy management server is configured to determine the encrypted public image according to the respective decryption mask.
17. 12. The computer system of claim 11, wherein the encrypted source image is encrypted according to a homomorphic encryption scheme.
18. 12. The computer system of claim 11, wherein the user-specific plaintext version of the encrypted source image shows private items of selected users of the plurality of users and obscures private items of other users of the plurality of users.
19. 12. The computer system of claim 11, wherein the private items include items selected from a group including people and human faces.
20. 12. The computer system of claim 11, wherein the private item comprises a bank card.
21. A non-transitory computer-readable medium storing instructions that, when executed by at least one hardware processor of a privacy management server, cause the privacy management server to: responsive to receiving an encrypted source image decodable with a management key, performing encrypted region image segmentation of the encrypted source image to determine a plurality of encrypted private masks, each mask representing a region of the encrypted source image selected to represent a private item of a respective one of a plurality of users; sending the plurality of encrypted private masks to an image distribution server for decryption; determining a plurality of encrypted private images, each private image of the plurality of encrypted private images being determined according to the encrypted source image and further according to a respective decryption mask including a decryption of a respective mask of the plurality of encrypted private masks, the respective decryption masks being received from the image distribution server; performing an encryption region key change procedure to generate a plurality of re-encrypted images, each of the plurality of re-encrypted images including a result of converting a private image of the plurality of encrypted private images from a state decodable by the management key to a state decodable by the private key of the respective user; combining the re-encrypted images into a composite private image; transmitting the composite private image to the image distribution server for further distribution to a plurality of client devices, each client device configured to reconstruct a user-specific plaintext version of the encrypted source image according to the composite private image; A non-transitory computer-readable medium for causing
Citation Information
Patent Citations
Apparatus and method for image processing
JP2003046745A
Data identification device, system, program, and method capable of access control of identification request source
JP2020010217A
Image distribution apparatus
US20120151601A1
Systems and methods for processing and handling privacy-sensitive image data
US20190050592A1
Image masking device and image masking method
WO2018225775A1