A system and method for protecting a base bitstream incorporating independently encoded tiles.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- DIVX LLC
- Filing Date
- 2025-06-23
- Publication Date
- 2026-08-05
AI Technical Summary
【0032】 本発明のさらになおも別の実施形態では、複数の圧縮単位のうちのそれぞれの圧縮単位の一部を解読するステップは、複数部分を復号するために、共通暗号化形式(CENC)を使用するステップを含む。 本明細書は、例えば、以下の項目も提供する。 (項目1) プロセッサ命令を含有する、非一過性の機械可読媒体であって、プロセッサによる前記命令の実行は、前記プロセッサに、 複数のフレームを備えるビデオビットストリームを受信するステップであって、各フレームは、前記フレーム内の複数の独立して符号化された圧縮単位を備える、ステップと、 複数のフレームの中の複数の圧縮単位のうちのそれぞれの圧縮単位の一部を暗号化するステップと、 前記圧縮単位の前記暗号化された部分を含む、前記複数の独立して符号化された圧縮単位を備える出力ビットストリームを生成するステップと を含む、プロセスを行わせる、非一過性の機械可読媒体。 (項目2) 圧縮単位は、復号されるために特定のフレーム内の別の圧縮単位に依存しないように、ビデオの前記特定のフレームの独立して復号可能な部分である、項目1に記載の非一過性の機械可読媒体。 (項目3) ビデオのフレーム内の圧縮単位の場所を識別するように、メタデータヘッダを解析するステップと、 前記圧縮単位の前記場所に基づいて、前記ビデオビットストリームの一部を暗号化するステップと をさらに含む、項目1に記載の非一過性の機械可読媒体。 (項目4) 前記複数の圧縮単位のうちのそれぞれの圧縮単位の前記一部を暗号化するステップは、前記ビデオビットストリームと関連付けられるヘッダ内の情報に基づいて、圧縮単位が有効にされることを判定するステップを含む、項目1に記載の非一過性の機械可読媒体。 (項目5) ビデオのフレームの中の各圧縮単位の一部を暗号化するステップをさらに含む、項目1に記載の非一過性の機械可読媒体。 (項目6) 前記一部は、i)前記圧縮単位の最初のNバイト、ii)前記圧縮単位の最後のNバイト、iii)前記圧縮単位内のNバイトの中央部分、およびiv)前記圧縮単位内のNバイトのパターンから成る群から選択される、項目5に記載の非一過性の機械可読媒体。 (項目7) 前記圧縮単位は、高効率ビデオ符号化(HEVC)規格内のタイルであり、前記ビデオビットストリームは、前記HEVC規格に基づいて符号化される、項目1に記載の非一過性の機械可読媒体。 (項目8) 前記ビデオビットストリーム内の前記タイルの構造を識別するように、前記HEVCビデオビットストリームのピクチャパラメータセット(PPS)を解析するステップと、 前記構造に基づいて、前記タイルの複数部分を暗号化するステップと をさらに含む、項目7に記載の非一過性の機械可読媒体。 (項目9) 前記複数の圧縮単位のうちのそれぞれの圧縮単位の前記一部を暗号化するステップは、複数部分を暗号化するために、共通暗号化形式(CENC)を使用するステップを含む、項目1に記載の非一過性の機械可読媒体。 (項目10) コンテンツエンコーダであって、 メモリと通信するように構成されるプロセッサであって、前記メモリは、エンコーダアプリケーションを含有する、プロセッサ を備え、 前記エンコーダアプリケーションは、前記プロセッサに、 複数のフレームを備えるビデオビットストリームを受信することであって、各フレームは、前記フレーム内の複数の独立して符号化された圧縮単位を備える、ことと、 複数のフレームの中の複数の圧縮単位のうちのそれぞれの圧縮単位の一部を暗号化することと、 前記圧縮単位の前記暗号化された部分を含む、前記複数の独立して符号化された圧縮単位を備える出力ビットストリームを生成することと を行うように指図する、コンテンツエンコーダ。 (項目11) 圧縮単位は、復号されるために特定のフレーム内の別の圧縮単位に依存しないように、ビデオの前記特定のフレームの独立して復号可能な部分である、項目10に記載のコンテンツエンコーダ。 (項目12) 前記エンコーダアプリケーションはさらに、前記プロセッサに、 ビデオのフレーム内の圧縮単位の場所を識別するように、メタデータヘッダを解析することと、 前記圧縮単位の前記場所に基づいて、前記ビデオビットストリームの一部を暗号化することと を行うように指図する、項目10に記載のコンテンツエンコーダ。 (項目13) 前記複数の圧縮単位のうちのそれぞれの圧縮単位の前記一部を暗号化するステップは、前記ビデオビットストリームと関連付けられるヘッダ内の情報に基づいて、圧縮単位が有効にされることを判定するステップを含む、項目10に記載のコンテンツエンコーダ。 (項目14) 前記エンコーダアプリケーションはさらに、前記プロセッサに、ビデオのフレームの中の各圧縮単位の一部を暗号化するように指図する、項目10に記載のコンテンツエンコーダ。 (項目15) 前記一部は、i)前記圧縮単位の最初のNバイト、ii)前記圧縮単位の最後のNバイト、iii)前記圧縮単位内のNバイトの中央部分、およびiv)前記圧縮単位内のNバイトのパターンから成る群から選択される、項目14に記載のコンテンツエンコーダ。 (項目16) 前記圧縮単位は、高効率ビデオ符号化(HEVC)規格内のタイルであり、前記ビデオビットストリームは、前記HEVC規格に基づいて符号化される、項目10に記載のコンテンツエンコーダ。 (項目17) 前記エンコーダアプリケーションはさらに、前記プロセッサに、 前記ビデオビットストリーム内の前記タイルの構造を識別するように、前記HEVCビデオビットストリームのピクチャパラメータセット(PPS)を解析することと、 前記構造に基づいて、前記タイルの複数部分を暗号化することと を行うように指図する、項目16に記載のコンテンツエンコーダ。 (項目18) 前記複数の圧縮単位のうちのそれぞれの圧縮単位の前記一部を暗号化するステップは、複数部分を暗号化するために、共通暗号化形式(CENC)を使用するステップを含む、項目10に記載のコンテンツエンコーダ。 (項目19) コンテンツデコーダであって、 メモリと通信するように構成されるプロセッサであって、前記メモリは、デコーダアプリケーションを含有する、プロセッサ を備え、 前記デコーダアプリケーションは、前記プロセッサに、 複数のフレームを備えるビデオビットストリームを受信することであって、各フレームは、前記フレーム内の複数の独立して符号化された圧縮単位を備える、ことと、 複数のフレームの中の複数の圧縮単位のうちのそれぞれの圧縮単位の一部を解読することと、 再生のために出力された復号ビデオを生成することと を行うように指図する、コンテンツデコーダ。 (項目20) 圧縮単位は、復号されるために特定のフレーム内の別の圧縮単位に依存しないように、ビデオの前記特定のフレームの独立して復号可能な部分である、項目19に記載のコンテンツデコーダ。 (項目21) 前記デコーダアプリケーションはさらに、前記プロセッサに、 ビデオのフレーム内の圧縮単位の場所を識別するようにメタデータヘッダを解析することと、 前記圧縮単位の前記場所に基づいて、前記ビデオビットストリームの一部を解読することと を行うように指図する、項目19に記載のコンテンツデコーダ。 (項目22) それぞれの前記複数の圧縮単位の前記一部を解読するステップは、前記ビデオビットストリームと関連付けられるヘッダ内の情報に基づいて、圧縮単位が有効にされることを判定するステップを含む、項目19に記載のコンテンツデコーダ。 (項目23) 前記デコーダアプリケーションはさらに、前記プロセッサに、ビデオのフレームの中の各圧縮単位の一部を解読するように指図する、項目19に記載のコンテンツデコーダ。 (項目24) 前記一部は、i)前記圧縮単位の最初のNバイト、ii)前記圧縮単位の最後のNバイト、iii)前記圧縮単位内のNバイトの中央部分、およびiv)前記圧縮単位内のNバイトのパターンから成る群から選択される、項目23に記載のコンテンツデコーダ。 (項目25) 前記圧縮単位は、高効率ビデオ符号化(HEVC)規格内のタイルであり、前記ビデオビットストリームは、前記HEVC規格に基づいて復号される、項目19に記載のコンテンツデコーダ。 (項目26) 前記デコーダアプリケーションはさらに、前記プロセッサに、 前記ビデオビットストリーム内の前記タイルの構造を識別するように、前記HEVCビデオビットストリームのピクチャパラメータセット(PPS)を解析し、 前記構造に基づいて、前記タイルの複数部分を解読するように指図する、項目25に記載のコンテンツデコーダ。 (項目27) 前記複数の圧縮単位のうちのそれぞれの圧縮単位の前記一部を解読するステップは、複数部分を復号するために、共通暗号化形式(CENC)を使用するステップを含む、項目19に記載のコンテンツデコーダ。
Smart Images

Figure 0007901215000001 
Figure 0007901215000002 
Figure 0007901215000003
Abstract
Description
Technical Field
[0001] The present invention relates to the field of encryption and decryption of video information. More specifically, the present invention is directed to a method and system for generating a protected stream of compressed digital video using partial frame encryption.
Background Art
[0002] Existing digital video compression techniques are complex processes that rely on various techniques when converting units of uncompressed video data into an encoded form (i.e., “encoding”). Such encoding allows fewer bits to be used when representing the content of the original uncompressed video data. The resulting encoded data can be converted using the reverse process (i.e., “decoding”) that produces digital video units of data that are either visually similar or identical to the original data. Modern techniques of digital video compression can achieve a very high level of compression.
[0003] The Motion Pictures Experts Group (MPEG) and the International Standards Organization (ISO) have produced various international standards that define video compression and decompression algorithms for video coding. These standards include MPEG-1, MPEG-2, MPEG-4, H.261, H.264, and the newer High Efficiency Video Coding (HEVC) standard, which offers significantly improved compression efficiency compared to its predecessors. Specifically, HEVC can achieve twice the compression ratio at the same subjective quality compared to the previous H.264 standard. To achieve these compression optimizations, the HEVC standard has introduced several new tools, particularly designed for the parallel processing of video content on multi-core processor architectures. Specifically, many smartphone and tablet architectures currently available on the market utilize multi-core processors and are therefore capable of playing HEVC content using their multi-core architectures. Furthermore, with the increasing video traffic across networks, the HEVC standard provides a tool that alleviates some of the bandwidth requirements for distributing high-quality content.
[0004] Protecting the distribution of digital content from copyright infringement and other types of illegal distribution is yet another concern for content providers. The term Digital Rights Management (DRM) is used to describe access control technologies used to control access to and / or copying of digital content. DRM systems typically involve the use of cryptographic information to control or protect access to portions of the content. Content protection is typically achieved by using cryptographic information, such as one or more encryption keys (but not limited to) to encrypt the content.
[0005] Currently, various types of encryption methods exist that can be used to protect data. In the digital world, encryption is often implemented by using a set of bits of a known length as a "key" to perform a predictable transformation into a unit of data. This creates another unit of data that cannot be "read" without knowledge of the key used to perform the transformation. The encryption process is not easily reversible except to the extent that the encryption key or its counterpart (e.g., the "public" key) is available to be used when transforming or "decrypting" the encrypted data back into its original form. Video data is often encrypted using symmetric block ciphers, such as those conforming to the Data Encryption Standard (DES) or the Advanced Encryption Standard (AES). The specific techniques used to encrypt digital content may nevertheless consume additional processing resources that need to be considered in relation to the encoding and distribution of content over a network. [Overview of the Initiative] [Means for solving the problem]
[0006] A system and method for partial frame encryption according to embodiments of the present invention are disclosed. In one embodiment, the method receives a video bitstream comprising several frames, each frame comprising several independently encoded compression units within the frame; encrypts a portion of each of the compression units within the frames; and generates an output bitstream comprising several independently encoded compression units, each comprising the encrypted portion of the compression unit.
[0007] In a further embodiment of the present invention, the compression unit is an independently decodeable portion of a particular frame of video, such that it does not depend on another compression unit within a particular frame for decoding.
[0008] In a further embodiment of the present invention, the method further parses the metadata header to identify the location of a compression unit within a video frame, and encrypts a portion of the video bitstream based on the location of the compression unit.
[0009] In a further embodiment of the present invention, the method encrypts a portion of each of several compression units by determining whether a compression unit is enabled based on information in a header associated with a video bitstream.
[0010] Still, in further embodiments of the present invention, the method further includes the step of encrypting a portion of each compression unit within a video frame.
[0011] In yet another embodiment of the present invention, a portion is selected from the group consisting of i) the first N bytes of the compressed unit, ii) the last N bytes of the compressed unit, iii) the central portion of the N bytes within the compressed unit, and v) the pattern of the N bytes within the compressed unit.
[0012] In yet another embodiment of the present invention, the compression unit is a tile within the High Efficiency Video Coding (HEVC) standard, and the video bitstream is encoded according to the HEVC standard.
[0013] Furthermore, in yet another embodiment of the present invention, the method further includes the steps of: parsing the picture parameter set (PPS) of an HEVC video bitstream to identify the structure of tiles in the video bitstream; and encrypting multiple portions of the tiles based on the structure.
[0014] Again, in another embodiment of the present invention, the method further encrypts a portion of each of several compression units by using a Common Encryption Format (CENC) to encrypt multiple portions.
[0015] Another embodiment of the present invention includes a content encoder, which includes a processor configured to communicate with a memory, the memory containing an encoder application, the encoder application instructing the processor to receive a video bitstream, which includes several frames, each containing several independently encoded compressed units within the frame, to encrypt a portion of each of the compressed units within the frames, and to generate an output bitstream, which includes several independently encoded compressed units, each containing the encrypted portion of the compressed units.
[0016] In another embodiment of the present invention, the compression unit is an independently decodeable portion of a particular frame of video, such that it does not depend on another compression unit within a particular frame for decoding.
[0017] In yet another embodiment of the present invention, the encoder application further instructs the processor to parse the metadata header to identify the location of a compression unit within a video frame, and to encrypt a portion of the video bitstream based on the location of the compression unit.
[0018] In yet another embodiment of the present invention, the step of encrypting a portion of each of several compression units includes the step of determining whether the compression unit is enabled based on information in a header associated with the video bitstream.
[0019] In yet another embodiment, the encoder application further instructs the processor to encrypt a portion of each compression unit within the video frame.
[0020] Again, in another embodiment of the present invention, a portion is selected from the group consisting of i) the first N bytes of the compressed unit, ii) the last N bytes of the compressed unit, iii) the central portion of the N bytes within the compressed unit, and v) the pattern of the N bytes within the compressed unit.
[0021] In another further embodiment of the present invention, the compression unit is a tile within the High Efficiency Video Coding (HEVC) standard, and the video bitstream is encoded according to the HEVC standard.
[0022] Again, in yet another embodiment of the present invention, the encoder application further instructs the processor to analyze the picture parameter set (PPS) of the HEVC video bitstream to identify the structure of the tiles in the video bitstream, and to encrypt multiple portions of the tiles based on the structure.
[0023] Again, in further embodiments of the present invention, the step of encrypting a portion of each of the multiple compression units includes the step of using a Common Encryption Format (CENC) to encrypt the multiple portions.
[0024] In another embodiment of the present invention, the content decoder includes a processor configured to communicate with a memory, the memory containing a decoder application, the decoder application instructing the processor to receive a video bitstream comprising several frames, each frame comprising several independently encoded compression units within the frame, to decode a portion of each compression unit among several compression units within the several frames, and to produce a decoded video output for playback.
[0025] In yet another embodiment of the present invention, the compression unit is an independently decodeable portion of a particular frame of video, such that it does not depend on another compression unit within a particular frame for decoding.
[0026] Again, in yet another embodiment of the present invention, the decoder application further instructs the processor to parse the metadata header to identify the location of a compression unit within a video frame, and to decode a portion of the video bitstream based on the location of the compression unit.
[0027] Again, in yet another embodiment of the present invention, the step of decoding a part of each of several compression units includes the step of determining, based on information in a header associated with the video bitstream, that the compression unit is enabled.
[0028] In yet another further embodiment of the present invention, the decoder application further instructs the processor to decode a part of each compression unit in a video frame.
[0029] Again, in yet another embodiment of the present invention, the part is selected from the group consisting of: i) the first N bytes of the compression unit, ii) the last N bytes of the compression unit, iii) the central part of N bytes within the compression unit, and v) a pattern of N bytes within the compression unit.
[0030] Still, in a further embodiment of the present invention, the compression unit is a tile within the High Efficiency Video Coding (HEVC) standard, and the video bitstream is decoded based on the HEVC standard.
[0031] Still, in another embodiment of the present invention, the decoder application further analyzes the Picture Parameter Set (PPS) of the HEVC video bitstream to identify the structure of the tiles in the video bitstream, and based on the structure, instructs the processor to decode multiple parts of the tiles.
[0032] In yet another still further embodiment of the present invention, the step of decoding a part of each of the plurality of compression units includes the step of using a Common Encryption Format (CENC) to decode the plurality of parts. This specification also provides, for example, the following items. (Item 1) A non-transitory machine-readable medium containing processor instructions, execution of the instructions by a processor causes the processor to A step of receiving a video bitstream comprising multiple frames, wherein each frame comprises multiple independently encoded compression units within the frame, A step of encrypting a portion of each of the multiple compression units within multiple frames, A step of generating an output bitstream comprising the plurality of independently encoded compression units, including the encrypted portion of the compression unit; A non-transient, machine-readable medium that enables a process to be carried out, including the following. (Item 2) A non-transient, machine-readable medium as described in Item 1, wherein the compression unit is an independently decodeable portion of a particular frame of video, such that it does not depend on another compression unit within that particular frame for decoding. (Item 3) The steps include: parsing the metadata header to identify the location of compression units within video frames; A step of encrypting a portion of the video bitstream based on the location of the compression unit. Non-transient, machine-readable media as described in item 1, further including the above. (Item 4) The non-transient machine-readable medium according to item 1, wherein the step of encrypting the portion of each of the plurality of compression units includes the step of determining whether the compression unit is enabled based on information in a header associated with the video bitstream. (Item 5) A non-transient, machine-readable medium as described in Item 1, further comprising the step of encrypting a portion of each compression unit within a video frame. (Item 6) The non-transient machine-readable medium described in item 5, wherein the part is selected from the group consisting of i) the first N bytes of the compressed unit, ii) the last N bytes of the compressed unit, iii) the central portion of the N bytes within the compressed unit, and iv) the pattern of the N bytes within the compressed unit. (Item 7) The compression unit is a tile within the High Efficiency Video Coding (HEVC) standard, and the video bitstream is encoded in accordance with the HEVC standard, in a non-transient, machine-readable medium as described in item 1. (Item 8) The steps include: analyzing the picture parameter set (PPS) of the HEVC video bitstream to identify the structure of the tiles within the video bitstream; Based on the above structure, the steps include: Non-transient machine-readable media as described in item 7, further including the above. (Item 9) The non-transient, machine-readable medium described in item 1, wherein the step of encrypting a portion of each of the plurality of compression units includes the step of using a common encryption format (CENC) to encrypt the plurality of portions. (Item 10) It is a content encoder, A processor configured to communicate with memory, wherein the memory contains an encoder application. Equipped with, The encoder application provides the processor with Receiving a video bitstream comprising multiple frames, wherein each frame comprises multiple independently encoded compression units within the frame, Encrypting a portion of each compression unit among multiple compression units within multiple frames, To generate an output bitstream comprising the plurality of independently encoded compression units, including the encrypted portion of the compression unit; A content encoder that instructs the system to perform certain actions. (Item 11) The content encoder described in item 10, wherein the compression unit is an independently decodeable portion of a particular frame of video, such that it does not depend on another compression unit within that particular frame for decoding. (Item 12) The encoder application further provides the processor with: Parsing the metadata header to identify the location of compression units within video frames, Encrypting a portion of the video bitstream based on the location of the compression unit The content encoder described in item 10 instructs the system to perform the following actions. (Item 13) The content encoder according to item 10, wherein the step of encrypting a portion of each of the plurality of compression units includes determining whether the compression unit is enabled based on information in a header associated with the video bitstream. (Item 14) The encoder application further instructs the processor to encrypt a portion of each compression unit within a video frame, as described in item 10. (Item 15) The content encoder according to item 14, wherein the part is selected from the group consisting of i) the first N bytes of the compression unit, ii) the last N bytes of the compression unit, iii) the central portion of the N bytes within the compression unit, and iv) a pattern of the N bytes within the compression unit. (Item 16) The content encoder described in item 10, wherein the compression unit is a tile within the High Efficiency Video Coding (HEVC) standard, and the video bitstream is encoded according to the HEVC standard. (Item 17) The encoder application further provides the processor with: The picture parameter set (PPS) of the HEVC video bitstream is analyzed to identify the structure of the tiles within the video bitstream, Based on the above structure, multiple parts of the tile are encrypted. The content encoder described in item 16 instructs the system to perform the following actions. (Item 18) The content encoder according to item 10, wherein the step of encrypting a portion of each of the plurality of compression units includes the step of using a Common Encryption Format (CENC) to encrypt the plurality of units. (Item 19) It is a content decoder, A processor configured to communicate with memory, wherein the memory contains a decoder application. Equipped with, The decoder application provides the processor with Receiving a video bitstream comprising multiple frames, wherein each frame comprises multiple independently encoded compression units within the frame, Decoding a portion of each compression unit among multiple compression units within multiple frames, To generate a decoded video output for playback and A content decoder that instructs the system to perform certain actions. (Item 20) The content decoder described in item 19, wherein the compression unit is an independently decodeable portion of a particular frame of video, such that it does not depend on another compression unit within that particular frame for decoding. (Item 21) The decoder application further provides the processor with: Parsing the metadata header to identify the location of compression units within video frames, Decoding a portion of the video bitstream based on the location of the compression unit The content decoder described in item 19 instructs the system to perform the following actions. (Item 22) The content decoder according to item 19, wherein the step of decoding the portion of each of the plurality of compression units includes the step of determining whether the compression unit is enabled based on information in a header associated with the video bitstream. (Item 23) The decoder application further instructs the processor to decode a portion of each compression unit within a video frame, as described in item 19. (Item 24) The content decoder according to item 23, wherein the part is selected from the group consisting of i) the first N bytes of the compression unit, ii) the last N bytes of the compression unit, iii) the central portion of the N bytes within the compression unit, and iv) a pattern of the N bytes within the compression unit. (Item 25) The content decoder described in item 19, wherein the compression unit is a tile within the High Efficiency Video Coding (HEVC) standard, and the video bitstream is decoded according to the HEVC standard. (Item 26) The decoder application further provides the processor with: The picture parameter set (PPS) of the HEVC video bitstream is analyzed to identify the structure of the tiles within the video bitstream. A content decoder as described in item 25, which instructs to decode multiple portions of the tile based on the aforementioned structure. (Item 27) The content decoder according to item 19, wherein the step of decrypting a portion of each of the multiple compression units includes the step of using a Common Encryption Format (CENC) to decrypt the multiple portions. [Brief explanation of the drawing]
[0033] [Figure 1] Figure 1 is a diagram of a video encoding and distribution system according to an embodiment of the present invention. [Figure 2A] Figure 2A conceptually illustrates a content encoder configured to generate partially encrypted content according to an embodiment of the present invention. [Figure 2B] Figure 2B conceptually illustrates a content server configured to manage and distribute partially encrypted content according to an embodiment of the present invention. [Figure 2C] Figure 2C conceptually illustrates a playback device configured to receive and play partially encrypted content according to an embodiment of the present invention. [Figure 3] Figure 3 illustrates a process for partially encrypting content according to an embodiment of the present invention. [Figure 4] Figure 4 illustrates a process for partially encrypting content according to an embodiment of the present invention. [Figure 5] Figure 5 illustrates a process for decrypting and playing back partially encrypted content according to an embodiment of the present invention. [Figure 6] Figure 6 illustrates an example of a tile within a video frame according to an embodiment of the present invention. [Figure 7] Figure 7 illustrates an example of the syntactic structure of tiles in HEVC video according to an embodiment of the present invention. [Modes for carrying out the invention]
[0034] As described above, different techniques may be used to encrypt content, each consuming a different amount of processing resources in addition to the processing costs associated with the compression technique (e.g., H.264 or HEVC) used to compress or encode the video content. Therefore, many embodiments of the present invention can achieve efficiency in generating a protected, compressed video sequence with encrypted frames by encrypting only a portion of a frame, rather than the entire frame. These techniques, generally, can be referred to as “partial frame encryption” because they encrypt only a portion of a frame. One or more portions within a video frame to be encrypted can be defined within the frame by their starting location and length. Often, this information is provided within a header associated with the frame and may be used by a decoder to locate the encrypted portion of the frame for decryption.
[0035] Many video compression formats, such as H.264 / MPEG-4 AVC (Advanced Video Coding), have dependencies (depending on the compression algorithm) within a frame and across multiple frames. These dependencies mean that when an encrypted portion cannot be decrypted and therefore cannot be properly played back, other portions within that frame or in other frames that depend on the encrypted portion also cannot be played back. Therefore, in AVC-coded bitstreams, encrypting the first x bytes of a unit frame or sequence is often sufficient to prevent the decryption of many other portions of the frame or other units.
[0036] Many embodiments may utilize the ISO / IEC 23001-7:2012 Common Encryption Scheme (CENC) standard for encryption, which is an industry encryption standard that specifies standard encryption and key mapping methods that can be used by one or more digital rights and key management systems (DRM systems) to enable decryption of the same file using different DRM systems. This scheme enables encryption of multiple discontinuous portions of a frame.
[0037] Some video compression formats, such as High Efficiency Video Coding (HEVC), enable simultaneous parallel processing of different parts of a frame video, allowing multiple parts of a frame to be encoded and decoded independently without referencing or relying on information in other parts. One such feature designed to enable parallel processing is "tiling" in HEVC. Specifically, tiles can be used to allow multiple parts of a frame to be encoded and decoded simultaneously by different processors by dividing the image into square regions (tiles), each tile consisting of several coding tree units (CTUs).
[0038] A tile can be contained within a single NAL (Network Abstraction Layer) unit or slice. Similar, independently decryptable portions of a frame can be referred to as a compressed unit (i.e., a tile in HEVC) across different encoding formats. Compressed units can be processed independently of each other, thus enabling parallelism when decrypting a bitstream. In an HEVC encoded stream with tiling enabled, if only the first x bytes of a video NAL unit or frame are encrypted, the other portions (tiles) can be fully decryptable without needing to decrypt the encrypted portion, due to their independence from the encrypted portion.
[0039] Therefore, in many embodiments, the security of an encoded bitstream having tiles (or other compressed units) can be enhanced by encrypting at least a portion of the tiles within a frame to make more of the frame irrecoverable without decrypting the encrypted portion. In some embodiments, the encoder and / or encoding process may be designed to decrypt at least a portion of the bitstream to determine the location of the tiles and encrypt a portion of the tiles. The encoder may obtain information about the structure and / or location of the tiles to encrypt the information within the multiple tiles and protect more of the bitstream from being decrypted without being decrypted. A method for obtaining this information about the tiles (or other independently decryptable units) may include the step of parsing the NAL unit header to determine the starting location of one or more tiles. Systems and methods for partial frame encryption of compressed units according to embodiments of the present invention are discussed further below.
[0040] (A system architecture for partially encoding and playing back video using partial frame encryption) As discussed above, many new compression standards provide new tools that enable parallel processing (i.e., encoding and decoding) of video content on multicore architectures. These tools include the use of “tiles” in the HEVC standard, among several types of similar independently decodeable compression units that can be used, for example, to divide frames of video content into separate decodeable units. As described throughout this application, a compression unit (e.g., a tile in HEVC) can generally refer to a divided and / or independently decodeable portion of a single frame of video for a given encoding standard. Furthermore, “tile” is a type of compression unit introduced within the HEVC standard. While many of the following embodiments describe partial-frame encryption of tiles based on video compressed according to the HEVC standard, according to embodiments of the present invention, partial-frame encryption may be used to encrypt video compressed according to any other standard that uses similar types of compression units to divide video frames, as appropriate for the requirements of the specific application.
[0041] Furthermore, to protect digital content compressed using independently decryptable compression units, certain encryption techniques may be used that apply partial-frame encryption to one or more portions of compression units (i.e., tiles) within a video frame. Specifically, in newer standards (e.g., HEVC) designed to allow independent decryption of compression units within a video frame, it may no longer be sufficient to encrypt only a portion of the entire video frame (i.e., video image) based on the compression standard design, where other portions will have inter-frame dependency states that would require proper decryption of the encrypted frame. As discussed above, in these older compression standards, the dependency states between different parts of a single video frame mean that when an encrypted portion cannot be decrypted and therefore cannot be properly played back, other portions in other frames that depend on the encrypted portion also cannot be played back. Therefore, in many embodiments, partial-frame encryption may be applied to multiple portions of one or more compression units within a video frame. A system for encoding video content using partial-frame encryption according to an embodiment of the present invention is illustrated in Figure 1.
[0042] System 100 includes a content encoder 102 configured to encode source media into encoded video. In some embodiments, the content encoder may encode the content using a compression standard (e.g., the HEVC standard) that enables parallel processing of content by generating compression units (e.g., tiles) within each frame of video, which enable independent encoding / decoding of multiple parts of a frame without referring to other parts of the video frame. Specifically, in some embodiments, the content encoder may encode the content using the HEVC standard to encode frames of video content. The HEVC standard may also generate one or more independently decodeable tiles within each frame of video.
[0043] In addition to encoding video frames based on a compression standard (e.g., HEVC), in many embodiments, the content encoder 106 may further encrypt multiple portions of the video content to protect the content from illegal distribution. To reduce the overhead associated with encrypting video content, in many embodiments, the content encoder 106 encodes the video content using partial frame encryption, thereby encrypting only a portion of one or more compression units (i.e., tiles) within a video frame (rather than encrypting the entire frame of video content). In some embodiments, the content encoder encrypts the first x bytes of each tile within a video frame. Other embodiments may, as appropriate for the requirements of the specific application, encrypt different portions of a tile, including x bytes located somewhere in the bitstream, the trailing x bytes, and any other combination of bytes within the tile. In some embodiments, the content encoder may encrypt identical portions of all tiles within a frame. In other embodiments, the content encoder may encrypt different portions of different tiles. In some embodiments, the content encoder may encrypt multiple portions of only certain tiles (e.g., less than all tiles) within a video frame. To make it easily understandable, a container file containing encrypted video may include a separate DRM track containing information about the location of encrypted portions of tiles within a frame and / or cryptographic information used to encrypt all or each of those encrypted portions.
[0044] In some embodiments, the content encoder 106 stores content in a Matroska (MKV) container file. The Matroska container is a media container developed as an open standards project by the Matroska nonprofit organization (Aussonne, France). The Matroska container is based on Extensible Binary Meta-Language (EBML), which is a binary derivative of Extensible Markup Language (XML). Decryption of Matroska containers is supported by many consumer electronic (CE) devices. In other embodiments, depending on the requirements of the specific application, any of the various container file formats may be used, including (but not limited to) the MP4 container file format defined by the Motion Picture Experts Group as MPEG-4 Part 14.
[0045] In some embodiments, after the content encoder 106 compresses and / or encrypts the video sequence, the content encoder 106 uploads the encoded video to the content server 102.
[0046] In many embodiments, the content server 102 facilitates the distribution of source media to one or more playback devices 108-114. In some embodiments of the present invention, the content server 102 may be responsible for storing protected content for distribution to playback devices. In many embodiments, the content server receives and processes download requests from various playback devices 108-114 attempting to download encoded video. In some embodiments, a device may request either (i) to download the entire file, or (ii) to receive the streamed video for playback in either progressive or adaptive streaming mode. When the distribution server receives a download request from a playback device, it can provide the playback device with the encoded video for storage and / or playback.
[0047] The downloaded video file may include one or more headers containing data representing the structure of compression units (e.g., tiles in HEVC encoded video) within the video frames. The headers may include pointers to the starting locations of one or more tiles. In some embodiments, the locations of tiles in an encoded HEVC video sequence may be defined in a picture parameter structure (PPS) that provides information about the tile structure within one or more frames of the video. In some embodiments, tiles may be fixed to a certain location within a frame, while in other embodiments, tiles may be at different locations across different frames of the video. A decoder on a playback device may use this information to determine multiple portions of frames that need to be decoded to play the video file.
[0048] In some embodiments, the content server 102 receives stream requests from various playback devices and subsequently streams the encoded video to the playback devices for incremental playback and / or as part of an adaptive bitrate streaming system. In some embodiments, the various playback devices can use HTTP or another suitable stateless protocol to request the stream over a network 104 such as the Internet. In some embodiments, the various playback devices can use RTSP, thereby allowing the distribution server to record the state of each playback device and determine the video to stream based on the commands received from the playback devices and the stored data representing the state of the playback devices.
[0049] In some embodiments, the DRM server 116 (Digital Rights Management) facilitates authorization and access to the source media, including managing the keys required to encrypt / decrypt the source media.
[0050] A DRM server 116 according to one embodiment of the present invention may be responsible for storing protected streams and / or files of content for distribution to playback devices (e.g., streaming and / or download). The DRM server may also store common cryptographic information used to protect the content. In some embodiments, the common cryptographic information is identified using an identifier and a portion of the content associated with the common cryptographic information.
[0051] In the illustrated embodiment, the playback device includes a personal computer 108-110 and a mobile phone 112-114. In other embodiments, the playback device may include consumer electronic devices such as a DVD player, a Blu-ray® player, a television, a set-top box, a video game console, a tablet, and other devices capable of connecting to a server via HTTP and playing encoded video.
[0052] In the illustrated embodiments, the content encoder, content server, and DRM server are server applications configured to run on server computer hardware. In other embodiments, the content encoder, content server, and DRM server may be any processing device including a processor and having sufficient resources to perform encryption, distribution, and digital rights management of source media including (but not limited to) video, audio, and / or subtitles. A specific architecture is shown in Figure 1, but any of the various architectures may be used, as appropriate, to meet the requirements of the specific use of embodiments of the present invention, enabling the playback device to request encoded video using partial frame encryption.
[0053] A basic architecture of a content encoder 202 according to an embodiment of the present invention is illustrated in Figure 2A. The content encoder 202 includes a processor 204 that communicates with a non-volatile memory 208, a volatile memory 206, and a network interface 214. In the illustrated embodiment, the non-volatile memory includes a content encoder application 210 that configures the processor to encode content 212. In some embodiments, the content encoder application 210 encrypts the content using partial-frame encryption so that only multiple portions of one or more compression units (e.g., tiles), rather than the entire frame, are encrypted within the frame of the video, in order to reduce the overhead associated with encrypting compressed video.
[0054] In some embodiments, the network interface 214 may communicate with the processor 204, volatile memory 206, and / or non-volatile memory 208. A specific content encoder architecture is illustrated in Figure 2A, but any of a variety of architectures, including one in which the content encoder application resides on disk or some other form of storage and is loaded into volatile memory at runtime, can be used to implement the content encoder according to embodiments of the present invention.
[0055] A basic architecture of a content server 222 according to an embodiment of the present invention is illustrated in Figure 2B. The content server 222 includes a processor 224 that communicates with non-volatile memory 228, volatile memory 226, and a network interface 234. In the illustrated embodiment, the non-volatile memory includes a content distribution application 230 that configures the processor to distribute content 232. In some embodiments, the network interface 234 may communicate with the processor 224, volatile memory 226, and / or non-volatile memory 228. Although a specific content server architecture is illustrated in Figure 2B, any of the various architectures, including an architecture in which the content distribution application resides on disk or some other form of storage device and is loaded into volatile memory at runtime, can be used to implement the content server according to an embodiment of the present invention.
[0056] A basic architecture of a playback device according to an embodiment of the present invention is illustrated in Figure 2C. The playback device 252 includes a processor 254 that communicates with a non-volatile memory 258, a volatile memory 256, and a network interface 240. In the illustrated embodiment, the non-volatile memory includes a decoder application 260 that configures the processor to decode content 262. In some embodiments, the decoder application 260 uses information provided in the video container file and / or video stream to identify the location of compressed units within the video frames and decodes only certain portions of the compressed units to decode the video.
[0057] In some embodiments, the network interface 264 may communicate with the processor 254, volatile memory 256, and / or non-volatile memory 258. Although specific regeneration device architectures are illustrated in Figure 2C, any of a variety of architectures, including one in which the decoder application resides on disk or some other form of storage and is loaded into volatile memory at runtime, can be used to implement the regeneration device according to embodiments of the present invention.
[0058] (Systems and methods for partial-frame encryption) As discussed above, some video compression formats (e.g., HEVC) allow multiple parts of a frame (e.g., compression units or tiles) to be encoded and decoded independently without referencing or relying on information in other parts of the frame (or other frames). These independently decodeable parts of a frame can be referred to as compression units across different encoding formats. Therefore, during encryption of a stream with independent compression units, if only the first x bytes of a frame are encrypted, the other parts (compression units or tiles) may be fully decodeable due to their independence from the encrypted compression unit, without the need to decrypt the encrypted portion of the compression unit. Thus, the security of an encoded bitstream having tiles (or other compression units) can be improved by encrypting at least some of the multiple tiles in the frame so that more of the frame becomes unrecoverable without decrypting the encrypted portion. A process for partial frame encryption of compression units in a video bitstream according to an embodiment of the present invention is illustrated in Figure 3.
[0059] The process receives video data (in 302). In some embodiments, the process may download video data from one or more content sources. In other embodiments, the process may stream video data during video playback.
[0060] This process (in 304) determines the locations of multiple compression units within the video data. The locations may be determined based on information provided by one or more headers associated with the video frames. In some embodiments, the headers may provide information about the starting location of each compression unit within a frame. In some embodiments, the location of each compression unit may be fixed within each frame of the video and therefore do not need to be identified by a header. For example, the encoder may be pre-programmed with information about the structure of the video sequence.
[0061] This process determines (in 306) a portion of each compression unit within the video frame to be encrypted. In some embodiments, this process determines that a fixed x bytes of each compression unit should be encrypted. In some embodiments, this process determines different portions of different compression units based on the characteristics of the compression units. In other embodiments, this process may encode the middle or last x bytes in one or more compression units for a video frame. In some embodiments, this process may encrypt only multiple portions of other frames of the video while leaving certain frames of the video unencrypted. As can be easily understood, the specific portion of a particular frame to be encrypted and the mode of encryption typically depend on the requirements of the application.
[0062] This process encrypts multiple parts of the compression unit (in 308). In some embodiments, this process encrypts multiple parts using standard DES and / or AES encryption. Other embodiments may use other encryption mechanisms as appropriate for the requirements of the specific application.
[0063] This process generates an output bitstream containing a compressed unit with an encrypted portion (at 310). The process then terminates.
[0064] A specific process for encrypting multiple parts of a compression unit is illustrated in Figure 3. However, depending on the requirements of the specific application according to the embodiments of the present invention, any of the various processes can be used to encrypt multiple parts of a compression unit as appropriate.
[0065] (Overview of the HEVC standard) As discussed above, the HEVC video compression standard includes several new tools designed for the playback of video content, using a multi-core architecture that supports parallel processing. These tools include wavefront parallel processing (WPP) and tiling, in addition to slicing structures. When WPP and / or tiling are used, a video bitstream corresponding to a single image may be packetized into independently decodeable subsets of the bitstream. Specifically, HEVC includes independently decodeable tiles that divide a video frame into rectangular regions of a certain size. An embodiment of tiling within a video frame according to an embodiment of the present invention is illustrated in Figure 6. Specifically, Figure 6 is a schematic diagram illustrating an embodiment in which a frame in the horizontal and vertical dimensions is evenly divided into nine tiles, from tile 1 in the upper left corner to tile 9 in the lower right corner. Each tile contains an encoded tree unit.
[0066] Tile-related parameters may be transmitted in HEVC within the Picture Parameter Set (PPS). Different images within a video sequence may be permitted to use different PPSs. Tile parameters may vary by image within the same video sequence. While the number and location of tiles are likely to remain constant in most video applications, situations may arise where not only may the tile configuration vary by image within the same video sequence, but the groups of tiles may also vary by image.
[0067] Figure 7 illustrates an example of the syntactic structure of tiles in the Picture Parameter Set (PPS) in HEVC video. When tiles_enabled_flag is turned on, the number of tiles in each dimension may be signaled. If the tiles are uniformly sized (for example, uniform_spacing_flag is 1), no additional information may be signaled. The width and height of the tiles may be signaled. For example, as shown in Figure 7, num_tile_columns_minus1 and num_tile_rows_minus1 may be set to 2, and uniform_spacing_flag may be set to 1.
[0068] The encoder may change how tiles are divided frame by frame by an encoder that signals a new PPS with new tile division parameters. In many embodiments, tiles do not need to be uniformly sized relative to one another, or remain the same size relative to an identical tile in a previous example. Specifically, the encoder may signal a new PPS with new tile division parameters that will be applied to a new set of one or more frames.
[0069] (Partial frame encryption in HEVC) As discussed above, the HEVC standard introduces a tool that supports high-level parallel processing. Specifically, HEVC includes tiles that allow frames to be divided into rectangular regions, which can then be encoded and decoded independently. Frames may be divided uniformly or non-uniformly as tiles. The entry point of each tile may be defined in the slice header. To enable partial encryption of video files using the HEVC standard, many embodiments of the present invention may partially encrypt multiple tiles to encrypt the video content. A process for partial encryption of HEVC tiles according to an embodiment of the present invention is illustrated in Figure 4.
[0070] This process determines whether the tile is enabled (in 402). In many embodiments, when the tile is enabled, the bitstream may include an entry point offset indicating the starting position of each image partition, which is necessary for each core to immediately access the partition.
[0071] This process determines the structure of NAL units within the frame and / or bitstream (in case of 404).
[0072] This process determines the tile structure within a NAL unit (in 406). In some embodiments, this process parses the NAL header to determine the starting location of each tile within a video frame. In some embodiments, HEVC tiles may divide the image into rectangular regions of a certain size. The tile parameter structure may be defined in HEVC in Picture Parameter Set (PPS), Video Usefulness Information (VUI), and / or Supplemental Enhancement Information (SEI) messages. An embodiment of PPS in HEVC is illustrated in Figure 7. If tiles_enabled_flag is turned on, the number of tiles in each dimension may be signaled. In some embodiments, if the tiles are uniformly sized (e.g., uniform_spacing_flag is 1), no additional information may be signaled. The PPS may also signal the width and height of the tiles.
[0073] This process selects several NAL units (in 408). In some embodiments, this process may select all NAL units. In some embodiments, this process may select one or more NAL units.
[0074] This process selects several tiles within each selected NAL unit (in 410). In some embodiments, the encoder may change how the tiles are divided per image by an encoder that signals a new PPS with new tile division parameters. Figure 7 illustrates an embodiment of signaling tiles in a PPS. In some embodiments, the tiles may be different sizes compared to one another, or different sizes compared to identical tiles in previous examples. In some embodiments, the encoder may signal a new PPS with new tile division parameters for each new image, or when the tile partition changes from the previous image.
[0075] This process encrypts at least a portion of the selected tile. In some embodiments, this process may encrypt the first x bytes, the last x bytes, or a certain number of x bytes located within a portion of the tile's bitstream. In some embodiments, this process may encrypt several blocks within the tile. Other embodiments may encrypt other portions of the tile as appropriate to the requirements of the specific application. In many embodiments, this process encrypts multiple portions of the tile using a Common Encryption Format (CENC) that uses a common specification for how to encrypt a bitstream. CENC specifies industry-standard encryption and key mapping methods that can be used by DRM systems to enable file decryption. This scheme works by defining a common format of encryption-related metadata necessary to decrypt a protected stream. This scheme leaves the details of copyright mapping, key acquisition and storage, and DRM compliance rules, among several other considerations, to the DRM system supporting the CENC scheme. Furthermore, in many embodiments, the encrypted information may be stored within an MKV container.
[0076] Next, this process terminates. A specific process for encrypting a portion of the tiles in HEVC video content is illustrated in Figure 4, but depending on the requirements of the specific application according to the embodiments of the present invention, any of the various processes may be used to encrypt multiple portions of the tiles.
[0077] (Decrypting partially encrypted video) A process for decrypting a partially encrypted video according to an embodiment of the present invention is illustrated in Figure 5.
[0078] The process receives encrypted video data (in 502). In some embodiments, the process may download video content from a content provider, stream it, and / or stream it for download. In other embodiments, the video data may be stored on disk or retrieved by any other mechanism, as appropriate for the requirements of the specific use.
[0079] This process (in 504) determines the location of multiple compression units (e.g., tiles in HEVC) within the video data. In some embodiments, the location of a tile may be fixed within one or more frames of the video. In other embodiments, the location of a tile may change between frames or sets of frames. The location of a tile may be determined based on information contained within the PPS corresponding to the frame. Specifically, this process may parse the PPS to identify a particular byte within an encrypted tile.
[0080] This process determines (in 506) whether the compression unit is encrypted and decrypts the encrypted compression unit. In some embodiments, this process may obtain a decryption key for decrypting the encrypted content. The decryption key may be obtained based on authorization received from the DRM service associated with the content.
[0081] This process decodes the compression unit (in 508). In many embodiments, this process decodes the content based on a specific compression standard used to encode the video (e.g., HEVC video).
[0082] This process generates the decoded video output for playback (at 510). Then, this process terminates.
[0083] Figure 5 illustrates a specific process for decrypting multiple parts of a compressed unit within video content. However, depending on the requirements of the specific application according to the embodiments of the present invention, any of the various processes may be used to decrypt multiple parts of a compressed unit within video content.
[0084] Although the present invention is described in certain specific aspects, many additional modifications and variations will be obvious to those skilled in the art. Therefore, it should be understood that the present invention can be practiced in ways other than those specifically described. Accordingly, embodiments of the present invention should be considered illustrative rather than restrictive in all respects.
[0085] Furthermore, the foregoing discussion merely discloses and illustrates exemplary embodiments of the present invention. Those skilled in the art will readily recognize from such discussion and the accompanying drawings that various changes, modifications, and variations can be made without departing from the spirit and scope of the invention. Thus, the present invention is not limited to the specific embodiments disclosed, but it is intended to include all embodiments that fall within the scope of the accompanying claims.
Claims
1. A content decoder, The aforementioned content decoder is Memory containing the decoder application, A processor configured to communicate with the aforementioned memory Equipped with, The decoder application provides the processor with Receiving an encoded video bitstream comprising multiple frames, each frame comprising multiple independently encoded compression units within the frame, each independently encoded compression unit being a tile, For each of the aforementioned multiple frames, Receiving a metadata header that identifies the location of the plurality of independently encoded compression units within the frame, Receiving encrypted information that identifies the location of the encrypted portion of the plurality of independently encoded compression units within the frame, and Decrypting the encrypted portion of each of the multiple compression units in the frame based on the received metadata header and the received encryption information, wherein decrypting the encrypted portion of the multiple compression units means decrypting the multiple compression units. To execute and A content decoder that instructs the system to perform certain actions.
2. The content decoder according to claim 1, wherein the compression unit is an independently decodeable portion of a particular frame of video and does not depend on another compression unit within the particular frame for decoding.
3. The content decoder according to claim 1, wherein each of the plurality of compression units includes at least one portion protected using encryption and at least one portion that is not encrypted.
4. The content decoder according to claim 1, wherein each of the encrypted portions is selected from the group consisting of i) the first N bytes of the compression unit, ii) the last N bytes of the compression unit, iii) the central portion of the N bytes in the compression unit, and iv) a pattern of the N bytes in the compression unit.
5. The content decoder according to claim 1, wherein the encrypted information is contained in a separate DRM track, at least a portion of which is located in a container file containing the encoded video bitstream, and the encrypted information identifies a portion of the frame for decryption before the plurality of compression units are decrypted.
6. The content decoder according to claim 1, wherein the encoded video bitstream further comprises at least one unit containing a set of parameters that identify the location of the plurality of compression units within the frame.
7. The content decoder according to claim 6, wherein the parameters associated with each compression unit within the plurality of compression units are transmitted in the parameter set.
8. The content decoder according to claim 1, wherein the encrypted information identifies the number of bytes of data in the frame for decryption before decrypting the plurality of compression units.
9. The content decoder according to claim 1, wherein the metadata header comprises a pointer, each pointer being a pointer to the starting location of one of the plurality of compression units.
10. The content decoder according to claim 1, wherein the plurality of compression units are decoded in parallel with each other.
11. The content decoder according to claim 10, wherein the plurality of compression units are decoded by a plurality of processors.
12. A method for decoding a video, wherein the method is: In a content decoder, the function is to receive an encoded video bitstream comprising multiple frames, wherein each frame comprises multiple independently encoded compression units, and each independently encoded compression unit is a tile. For each of the aforementioned multiple frames, Receiving a metadata header that identifies the location of the plurality of independently encoded compression units within the frame, Receiving encrypted information that identifies the location of the encrypted portion of the plurality of independently encoded compression units within the frame, and Decrypting the encrypted portion of each of the multiple compression units in the frame based on the received metadata header and the received encryption information, wherein decrypting the encrypted portion of the multiple compression units means decrypting the multiple compression units. To execute and Methods that include...
13. The method according to claim 12, wherein the compression unit is an independently decodeable portion of a particular frame of video and does not depend on another compression unit within the particular frame for decoding.
14. The method according to claim 12, wherein each of the plurality of compression units includes at least one portion protected using encryption and at least one portion that is not encrypted.
15. The method according to claim 12, wherein each of the encrypted portions is selected from the group consisting of i) the first N bytes of the compressed unit, ii) the last N bytes of the compressed unit, iii) the central portion of the N bytes in the compressed unit, and iv) a pattern of the N bytes in the compressed unit.
16. The method according to claim 12, wherein the encrypted information is contained in a separate DRM track, at least a portion of which is located in a container file containing the encoded video bitstream, and the encrypted information identifies a portion of the frame for decryption before the plurality of compression units are decrypted.
17. The method according to claim 12, wherein the encrypted information identifies the number of bytes of data in the frame for decryption before decrypting the plurality of compression units.
18. The method according to claim 12, wherein the plurality of compression units are decoded in parallel with each other.
19. The method according to claim 18, wherein the plurality of compression units are decoded by a plurality of processors.
20. A content decoder, The aforementioned content decoder is Memory containing the decoder application, A processor configured to communicate with the aforementioned memory Equipped with, The decoder application provides the processor with Receiving an encoded video bitstream comprising multiple frames, each frame comprising multiple independently encoded compression units within the frame, each independently encoded compression unit being a tile, For each of the aforementioned multiple frames, Receiving a metadata header that identifies the location of the plurality of independently encoded compression units within the frame, Receiving encrypted information that identifies the location of the encrypted portion of the plurality of independently encoded compression units within the frame, and Decrypting the encrypted portion of each of the multiple compression units in the frame based on the received metadata header and the received encryption information, wherein decrypting the encrypted portion of the multiple compression units involves decrypting the multiple compression units in parallel with each other. To execute and A content decoder that instructs the system to perform certain actions.