Encryption of sample auxiliary information

WO2025078937A3PCT designated stage expired Publication Date: 2025-05-22NOKIA TECHNOLOGIES OY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2024/059806
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-10-09
Filing Date
2024-10-07
Publication Date
2025-05-22

AI Technical Summary

Technical Problem

Existing digital rights and key management systems face challenges in efficiently encrypting and decrypting bitstreams and sample auxiliary information within files, particularly in ensuring secure and compatible encryption methods across different media types.

Method used

The proposed solution involves an apparatus and method that encrypts bitstreams using different encryption methods and encapsulates them within an encapsulated file. This file includes tracks with samples containing the first encrypted bitstream and sample auxiliary information containing the second encrypted bitstream. Additionally, it includes specific information for decryption, such as encryption-related data, which is stored in separate sample auxiliary information entries.

Benefits of technology

This approach enables secure encryption and decryption of bitstreams and sample auxiliary information, ensuring compatibility across various media types by using distinct encryption methods and encapsulation techniques, thereby enhancing the security and interoperability of digital rights and key management systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2024059806_22052025_PF_FP_ABST
    Figure IB2024059806_22052025_PF_FP_ABST
Patent Text Reader

Abstract

Various embodiments provide methods, apparatuses, and computer program products. An example method includes receiving a first bitstream and a second bitstream; producing or generating the following: an encapsulated file comprising at least one track comprising one or more samples, wherein the first bitstream is encapsulated in the one or more samples, and wherein the second bitstream is encapsulated in a first sample auxiliary information; receiving or determining one or more sample group description entries and a mapping of the one or more sample group description entries to the first sample auxiliary information; and writing at least one sample to group box for indicating that the at least one sample to group box relates to the first sample auxiliary information and for indicating the mapping of the one or more sample group description entries to the first sample auxiliary information.
Need to check novelty before this filing date? Find Prior Art

Description

ENCRYPTION OF SAMPLE AUXILIARY INFORMATIONTECHNICAL FIELD

[0001] The examples and non-limiting embodiments relate generally to digital rights and key management systems, and more particularly, to method, apparatus, and computer program product for providing encryption and decryption of a file or bitstream.BACKGROUND

[0002] It is known to provide encryption and decryption.SUMMARY

[0003] Example 1. An apparatus comprising at least one processor; and at least one non-transitory memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: receiving a first bitstream and a second bitstream; encrypting the first bitstream with a first encryption method to generate a first encrypted bitstream; encrypting the second bitstream with a second encryption method to generate a second encrypted bitstream; taking following as an input: the first encrypted bitstream; the second encrypted bitstream; encryption related data for the first encrypted bitstream; and encryption related data for the second encrypted bitstream; producing or generating the following: an encapsulated file comprising at least one track comprising one or more samples, wherein the first encrypted bitstream is encapsulated in the one or more samples, and wherein the second encrypted bitstream is encapsulated in a first sample auxiliary information; including following information in the encapsulated file: a second sample auxiliary information; and a third sample auxiliary information; wherein the second auxiliary information comprises encryption related data for the first encrypted bitstream, and wherein the third sample auxiliary information comprises encryption related data for the second encrypted bitstream.

[0004] Example 2. An apparatus comprising at least one processor; and at least one non-transitory memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: receiving an encapsulated file comprising at least one track comprising one or more samples, wherein a first encrypted bitstream is encapsulated in the one or more samples, and wherein the first encrypted bitstream is encrypted with a first encryption method, and wherein a second encrypted bitstream is encapsulated in one or more first sample auxiliary information, and wherein the second encrypted bitstream is encrypted with a second encryption method; including followinginformation in the encapsulated file: a second sample auxiliary information; and a third sample auxiliary information; wherein the second auxiliary information comprises encryption related data for the first encrypted bitstream, and wherein the third sample auxiliary information comprises encryption related data for the second encrypted bitstream; parsing the encapsulated file to generate or produce following: the first encrypted bitstream; the second encrypted bitstream; encryption related data for the first encrypted bitstream; and encryption related data for the second encrypted bitstream; decrypting the first encrypted bitstream by using the encryption related data for the first encrypted bitstream to produce a first unencrypted bitstream; and decrypting the second encrypted bitstream by using the encryption related data for the second encrypted bitstream to produce a second unencrypted bitstream.

[0005] Example 3. The apparatus of example 1 or 2, wherein the apparatus is further caused to perform: applying one or more of following conditions: the first and the second bitstream are encrypted, and the first, second, and third sample auxiliary information streams are unencrypted; or the first and the second bitstream and first, second, and third sample auxiliary information streams are encrypted; wherein when the first and the second bitstreams in the at least one track is encrypted, a four-character- code (4CC) of a sample entry of the at least one track is transformed based on a media-type encapsulated in the at least one track.

[0006] Example 4. The apparatus of example 3, wherein when one or more of the first, second, or third sample auxiliary information streams in the at least one track are encrypted, file-format transformation is used for protected sample auxiliary information (SAI) streams.

[0007] Example 5. The apparatus of any of the examples 3 or 4, wherein the transformation functions by encapsulating original media declarations of the one or more of the first, second, or third sample auxiliary information, or by changing a four character code (4CC) of a box indicating presence of an SAI in the at least one track, such that protection-unaware readers reads or analyzes data in the SAI as a new data format.

[0008] Example 6. The apparatus of any of the examples 3 to 5, wherein the apparatus is further caused to perform: defining a transformed sample auxiliary information entry box or a protected sample auxiliary information entry box to indicate that the one or more of the of the first, second, or third sample auxiliary information streams in the at least one track is encrypted.

[0009] Example 7. The apparatus of any of the examples 3 to 6, wherein one or more protected sample auxiliary information entries are comprised in the one or more samples of the at least one track comprised in a sample description, or wherein the one or more protected sample auxiliary informationentries are present in one of: a movie box, a movie fragment box, a track box, or a track fragment box.

[0010] Example 8. The apparatus of example 7, wherein when more than one protected sample auxiliary information entries are present then each protected sample auxiliary information entry corresponds to a specific sample auxiliary information in the at least one track and are not alternatives of each other for selection.

[0011] Example 9. The apparatus of any of the examples 3 to 8, wherein when a format of the first, second, or third sample auxiliary information varies with a media-type, the apparatus is further caused to use a different encapsulating four character-code for each media type.

[0012] Example 10. The apparatus of any of the examples 8 or 9, wherein the protected sample auxiliary information entries are defined by using protected sample auxiliary information entry codes.

[0013] Example 11. The apparatus of any of the examples 7 to 10, wherein the apparatus is further caused to perform: adding a protection scheme information box or a SAI protection scheme information box to each of the one or more protected sample auxiliary information entries.

[0014] Example 12. The apparatus of any of the examples 1 to 11, wherein an original format of the first, second, and the third sample auxiliary information is stored within a protection scheme information box or a SAI protection scheme information box comprised in an original format box.

[0015] Example 13. The apparatus of any of the examples 1 to 11, wherein an original format of the first, second, and the third sample auxiliary information is stored within a protection scheme information box or a SAI protection scheme information box comprised in an SAI original format box.

[0016] Example 14. The apparatus of any of the examples 1 to 11, wherein the apparatus is further caused to perform: allowing the protection scheme information box and / or the SAI protection scheme information box to be present in the protected sample auxiliary information entry.

[0017] Example 15. The apparatus of example 14, wherein when the protection scheme information box and / or the SAI protection scheme information box is present in the protected sample auxiliary information entry, and wherein the protected sample auxiliary information entry comprises information required both to understand the encryption transform applied and parameters of the transformation.

[0018] Example 16. The apparatus of any of examples 14 or 15, wherein the protection scheme information box and / or the SAI protection scheme information box documents original format of the sample auxiliary information.

[0019] Example 17. The apparatus of any of the examples 7 to 16, wherein the apparatus is caused to use at least one of the following signaling to identify the protection applied on the first, second, and third sample auxiliary information: MPEG-4 systems with IPMP, when IPMP descriptors in MPEG-4 systems streams are used; scheme signaling using a scheme type box and a scheme information box, when the scheme type box and the scheme information box are used; or scheme signaling using SAI scheme type box and a SAI scheme information box when the signaling using SAI scheme type box and the SAI scheme information box.

[0020] Example 18. The apparatus of example 17, wherein at least one protection scheme information box and / or SAI protection scheme information box is comprised in the protected sample auxiliary information entry.

[0021] Example 19. The apparatus of example 18, wherein when more than one protection scheme information box and / or SAI protection scheme information box occur in a protected sample auxiliary information entry, the more than one protection scheme information box and / or SAI protection scheme information box are equivalent, alternative, descriptions of the same protection.

[0022] Example 20. The apparatus of example 12, wherein when an original format box is used for storing an original format of the first, second, or third sample auxiliary information, a data format parameter present in the original format box is extended to indicate a four-character-code of an original un-transformed format of the first, second, or third sample auxiliary information.

[0023] Example 21. The apparatus of example 13, wherein when the SAI original format box is used for storing an original format of the first, second, or third sample auxiliary information, the SAI original format box comprises a data format parameter to indicate a four-character-code of an original un-transformed format of the first, second, or third sample auxiliary information.

[0024] Example 22. The apparatus of example 21, wherein the SAI original format box comprises one or more of following parameters: an original scheme type for indicating a corresponding scheme type of the original un-transformed format of the first, second, or third sample auxiliary information and an original scheme version for indicating a corresponding scheme version of the original un- transformed format of the first, second, or third sample auxiliary information.

[0025] Example 23. The apparatus of any of examples 14 to 16, wherein a scheme type box is comprised in a SAI protection scheme information box and / or a protection scheme information box for identifying a protection or a restriction scheme used for encrypting the first, second, or third sample auxiliary information.

[0026] Example 24. The apparatus of example 23, wherein the apparatus is further caused to perform: defining a SAI scheme type box, wherein the SAI scheme type box is comprised a SAI protection scheme information box and / or a protection scheme information box for identifying a protection or a restriction scheme used for encrypting the first, second, or third sample auxiliary information.

[0027] Example 25. The apparatus of example 23, wherein a scheme information box is comprised in the SAI protection scheme information box and / or a protection scheme information box is a container box that is interpreted by the scheme being used, and wherein information an encryption or restriction system needs for protecting the first, second, or third sample auxiliary information is stored in the scheme information box.

[0028] Example 26. The apparatus of example 23, wherein the apparatus is caused to perform: defining a SAI scheme information box, wherein the SAI scheme information box is comprised in the SAI protection scheme information box and / or a protection scheme information box is a container box that is interpreted by a scheme being used, and wherein information an encryption or restriction system needs for protecting the first, second, or third sample auxiliary information is stored in the scheme information box.

[0029] Example 27. The apparatus of any of examples 23 to 24, wherein the scheme type box and / or the SAI scheme type box conform to following: a scheme type parameter in the scheme type box and / or the SAI scheme type box is set to a value equal to a four-character code defined in ISO / IEC 23001-7 for different protection schemes; a scheme version parameter in the scheme type box and / or the SAI scheme type box is set to a predefined value; the protection scheme information box and / or the SAI protection scheme information box used for signaling the protection related information for the first, second, or third sample auxiliary information also comprises a scheme information box and / or SAI scheme information box; the scheme information box and / or SAI scheme information box used for signaling the protection related information for the first, second, or third sample auxiliary information comprises a tack information box extended to support signaling of the first, second, or third sample auxiliary information and describing the default encryption parameters for the first, second, or third sample auxiliary information; the scheme information box and / or SAI scheme information box used forsignaling the protection related information for the sample auxiliary information comprises a SAI encryption box or a track SAI encryption box describing default encryption parameters for the first, second, or third sample auxiliary information; a track encryption box which defines a default value for each sample in the at least one track is modified or extended to indicate the default values associated with a specific SAI that is protected; or the track encryption box comprises default values for a protected flag, a vector size for samples in a sample group for the at least one track , and an identifier used for samples in the sample group.

[0030] Example 28. The apparatus of example 1, wherein the apparatus is further caused to perform: receiving or determining one or more sample group description entries and a mapping of the one or more sample group description entries to the first, second, and third sample auxiliary information; and writing at least one sample to group box for indicating that the at least one sample to group box relates to the first, second or third sample auxiliary information and for indicating the mapping of the one or more sample group description entries to the first, second, or third sample auxiliary information.

[0031] Example 29. The apparatus of example 28, wherein the apparatus is further caused to perform: determining that there is one type of sample auxiliary information in the at least one track and, as a consequence, excludes identification of the first, second or third sample auxiliary information from the at least one sample to group box.

[0032] Example 30. The apparatus of example 28, wherein the apparatus is further caused to perform: determining that there is more than one type of sample auxiliary information in the at least one track and, as a consequence, includes identification of at least two of the first, second, or third sample auxiliary information in the at least one sample to group box.

[0033] Example 31. The apparatus of example 2, wherein the apparatus is further caused to perform: parsing at least one sample to group box from a file; parsing that the at least one sample to group box relates to first, second or third sample auxiliary information; and parsing, from the at least one sample to group box, a mapping of one or more sample group description entries to the first, second or third sample auxiliary information.

[0034] Example 32. An apparatus comprising at least one processor; and at least one non- transitory memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: receiving a first bitstream and a second bitstream; producing or generating the following: an encapsulated file comprising at least one track comprising one or more samples, wherein the first bitstream is encapsulated in the one or more samples, and wherein the second bitstream is encapsulated in a first sample auxiliary information; receiving or determining one or more samplegroup description entries and a mapping of the one or more sample group description entries to the first sample auxiliary information; and writing at least one sample to group box for indicating that the at least one sample to group box relates to the first sample auxiliary information and for indicating the mapping of the one or more sample group description entries to the first sample auxiliary information.

[0035] Example 33. The apparatus of example 32, wherein the apparatus is further caused to perform: determining that there is one type of sample auxiliary information in the at least one track and, as a consequence, excludes identification of the first sample auxiliary information from the at least one sample to group box.

[0036] Example 34. The apparatus of example 32, wherein the apparatus is further caused to perform: determining that there is more than one type of sample auxiliary information in the at least one track and, as a consequence, includes identification of the first sample auxiliary information in the at least one sample to group box.

[0037] Example 35. An apparatus comprising at least one processor; and at least one non- transitory memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: parsing at least one sample to group box from a file; parsing that the at least one sample to group box relates to first sample auxiliary information; and parsing, from the at least one sample to group box, a mapping of one or more sample group description entries to the first sample auxiliary information.

[0038] Example 36. A method comprising: receiving a first bitstream and a second bitstream; encrypting the first bitstream with a first encryption method to generate a first encrypted bitstream; encrypting the second bitstream with a second encryption method to generate a second encrypted bitstream; taking following as an input: the first encrypted bitstream; the second encrypted bitstream; encryption related data for the first encrypted bitstream; and encryption related data for the second encrypted bitstream; producing or generating the following: an encapsulated file comprising at least one track comprising one or more samples, wherein the first encrypted bitstream is encapsulated in the one or more samples, and wherein the second encrypted bitstream is encapsulated in a first sample auxiliary information; including following information in the encapsulated file: a second sample auxiliary information; and a third sample auxiliary information; wherein the second auxiliary information comprises encryption related data for the first encrypted bitstream, and wherein the third sample auxiliary information comprises encryption related data for the second encrypted bitstream.

[0039] Example 37. A method comprising: receiving an encapsulated file comprising at least one track comprising one or more samples, wherein a first encrypted bitstream is encapsulated in the one ormore samples, and wherein the first encrypted bitstream is encrypted with a first encryption method, and wherein a second encrypted bitstream is encapsulated in one or more first sample auxiliary information, and wherein the second encrypted bitstream is encrypted with a second encryption method; including following information in the encapsulated file: a second sample auxiliary information; and a third sample auxiliary information; wherein the second auxiliary information comprises encryption related data for the first encrypte bitstream, and wherein the third sample auxiliary information comprises encryption related data for the second encrypted bitstream; parsing the encapsulated file to generate or produce following: the first encrypted bitstream; the second encrypted bitstream; encryption related data for the first encrypted bitstream; and encryption related data for the second encrypted bitstream; decrypting the first encrypted bitstream by using the encryption related data for the first encrypted bitstream to produce a first unencrypted bitstream; and decrypting the second encrypted bitstream by using the encryption related data for the second encrypted bitstream to produce a second unencrypted bitstream.

[0040] Example 38. The method of example 36 or 37, wherein the method is further caused to perform: applying one or more of following conditions: the first and the second bitstream are encrypted, and the first, second, and third sample auxiliary information streams are unencrypted; or the first and the second bitstream and first, second, and third sample auxiliary information streams are encrypted; wherein when the first and the second bitstreams in the at least one track is encrypted, a four-character- code (4CC) of a sample entry of the at least one track is transformed based on a media-type encapsulated in the at least one track.

[0041] Example 39. The method of example 38, wherein when one or more of the first, second, or third sample auxiliary information streams in the at least one track are encrypted, file-format transformation is used for protected sample auxiliary information (SAI) streams.

[0042] Example 40. The method of any of the examples 38 or 39, wherein the transformation functions by encapsulating original media declarations of the one or more of the first, second, or third sample auxiliary information, or by changing a four character code (4CC) of a box indicating presence of an SAI in the at least one track, such that protection-unaware readers reads or analyzes data in the SAI as a new data format.

[0043] Example 41. The method of any of the examples 38 to 40 further comprising defining a transformed sample auxiliary information entry box or a protected sample auxiliary information entry box to indicate that the one or more of the of the first, second, or third sample auxiliary information streams in the at least one track is encrypted.

[0044] Example 42. The method of any of the examples 38 to 41, wherein one or more protected sample auxiliary information entries are comprised in the one or more samples of the at least one track comprised in a sample description, or wherein the one or more protected sample auxiliary information entries are present in one of: a movie box, a movie fragment box, a track box, or a track fragment box.

[0045] Example 43. The method of example 42, wherein when more than one protected sample auxiliary information entries are present then each protected sample auxiliary information entry corresponds to a specific sample auxiliary information in the at least one track and are not alternatives of each other for selection.

[0046] Example 44. The method of any of the examples 38 to 43, wherein when a format of the first, second, or third sample auxiliary information varies with a media-type, the method is further comprises using a different encapsulating four character-code for each media type.

[0047] Example 45. The method of any of the examples 43 or 44, wherein the protected sample auxiliary information entries are defined by using protected sample auxiliary information entry codes.

[0048] Example 46. The method of any of the examples 42 to 45 further comprising adding a protection scheme information box or a SAI protection scheme information box to each of the one or more protected sample auxiliary information entries.

[0049] Example 47. The method of any of the examples 36 to 46, wherein an original format of the first, second, and the third sample auxiliary information is stored within a protection scheme information box or a SAI protection scheme information box comprised in an original format box.

[0050] Example 48. The method of any of the examples 36 to 46, wherein an original format of the first, second, and the third sample auxiliary information is stored within a protection scheme information box or a SAI protection scheme information box comprised in an SAI original format box.

[0051] Example 49. The method of any of the examples 36 to 46 further comprising allowing the protection scheme information box and / or the SAI protection scheme information box to be present in the protected sample auxiliary information entry.

[0052] Example 50. The method of example 49, wherein when the protection scheme information box and / or the SAI protection scheme information box is present in the protected sample auxiliary information entry, and wherein the protected sample auxiliary information entry comprises information required both to understand the encryption transform applied and parameters of the transformation.

[0053] Example 51. The method of any of examples 49 or 50, wherein the protection scheme information box and / or the SAI protection scheme information box documents original format of the sample auxiliary information.

[0054] Example 52. The method of any of the examples 42 to 51 further comprising using at least one of the following signaling to identify the protection applied on the first, second, and third sample auxiliary information:MPEG-4 systems with IPMP, when IPMP descriptors in MPEG-4 systems streams are used; scheme signaling using a scheme type box and a scheme information box, when the scheme type box and the scheme information box are used; or scheme signaling using SAI scheme type box and a SAI scheme information box when the signaling using SAI scheme type box and the SAI scheme information box.

[0055] Example 53. The method of example 52, wherein at least one protection scheme information box and / or SAI protection scheme information box is comprised in the protected sample auxiliary information entry.

[0056] Example 54. The method of example 53, wherein when more than one protection scheme information box and / or SAI protection scheme information box occur in a protected sample auxiliary information entry, the more than one protection scheme information box and / or SAI protection scheme information box are equivalent, alternative, descriptions of the same protection.

[0057] Example 55. The method of example 47, wherein when an original format box is used for storing an original format of the first, second, or third sample auxiliary information, a data format parameter present in the original format box is extended to indicate a four-character-code of an original un-transformed format of the first, second, or third sample auxiliary information.

[0058] Example 56. The method of example 48, wherein when the SAI original format box is used for storing an original format of the first, second, or third sample auxiliary information, the SAI original format box comprises a data format parameter to indicate a four-character-code of an original untransformed format of the first, second, or third sample auxiliary information.

[0059] Example 57. The method of example 56, wherein the SAI original format box comprises one or more of following parameters: an original scheme type for indicating a corresponding scheme type of the original un-transformed format of the first, second, or third sample auxiliary information and an original scheme version for indicating a corresponding scheme version of the original untransformed format of the first, second, or third sample auxiliary information.

[0060] Example 58. The method of any of examples 49 to 51, wherein a scheme type box is comprised in a SAI protection scheme information box and / or a protection scheme information box for identifying a protection or a restriction scheme used for encrypting the first, second, or third sample auxiliary information.

[0061] Example 59. The method of example 58 further comprising: defining a SAI scheme type box, wherein the SAI scheme type box is comprised a SAI protection scheme information box and / or a protection scheme information box for identifying a protection or a restriction scheme used for encrypting the first, second, or third sample auxiliary information.

[0062] Example 60. The method of example 58, wherein a scheme information box is comprised in the SAI protection scheme information box and / or a protection scheme information box is a container box that is interpreted by the scheme being used, and wherein information an encryption or restriction system needs for protecting the first, second, or third sample auxiliary information is stored in the scheme information box.

[0063] Example 61. The method of example 58 further comprising defining a SAI scheme information box, wherein the SAI scheme information box is comprised in the SAI protection scheme information box and / or a protection scheme information box is a container box that is interpreted by a scheme being used, and wherein information an encryption or restriction system needs for protecting the first, second, or third sample auxiliary information is stored in the scheme information box.

[0064] Example 62. The method of any of examples 58 to 59, wherein the scheme type box and / or the SAI scheme type box conform to following: a scheme type parameter in the scheme type box and / or the SAI scheme type box is set to a value equal to a four-character code defined in ISO / IEC 23001-7 for different protection schemes; a scheme version parameter in the scheme type box and / or the SAI scheme type box is set to a predefined value; the protection scheme information box and / or the SAI protection scheme information box used for signaling the protection related information for the first, second, or third sample auxiliary information also comprises a scheme information box and / or SAI scheme information box; the scheme information box and / or SAI scheme information box used for signaling the protection related information for the first, second, or third sample auxiliary informationcomprises a tack information box extended to support signaling of the first, second, or third sample auxiliary information and describing the default encryption parameters for the first, second, or third sample auxiliary information; the scheme information box and / or SAI scheme information box used for signaling the protection related information for the sample auxiliary information comprises a SAI encryption box or a track SAI encryption box describing default encryption parameters for the first, second, or third sample auxiliary information; a track encryption box which defines a default value for each sample in the at least one track is modified or extended to indicate the default values associated with a specific SAI that is protected; or the track encryption box comprises default values for a protected flag, a vector size for samples in a sample group for the at least one track, and an identifier used for samples in the sample group.

[0065] Example 63. The method of example 36 further comprising: receiving or determining one or more sample group description entries and a mapping of the one or more sample group description entries to the first, second, and third sample auxiliary information; and writing at least one sample to group box for indicating that the at least one sample to group box relates to the first, second or third sample auxiliary information and for indicating the mapping of the one or more sample group description entries to the first, second, or third sample auxiliary information.

[0066] Example 64. The method of example 63 further comprising determining that there is one type of sample auxiliary information in the at least one track and, as a consequence, excludes identification of the first, second or third sample auxiliary information from the at least one sample to group box.

[0067] Example 65. The method of example 63 further comprising determining that there is more than one type of sample auxiliary information in the at least one track and, as a consequence, includes identification of at least two of the first, second, or third sample auxiliary information in the at least one sample to group box.

[0068] Example 66. The method of example 37 further comprising: parsing at least one sample to group box from a file; parsing that the at least one sample to group box relates to first, second or third sample auxiliary information; and parsing, from the at least one sample to group box, a mapping of one or more sample group description entries to the first, second or third sample auxiliary information.

[0069] Example 67. A method comprising: receiving a first bitstream and a second bitstream; producing or generating the following: an encapsulated file comprising at least one track comprising one or more samples, wherein the first bitstream is encapsulated in the one or more samples, and wherein the second bitstream is encapsulated in a first sample auxiliary information; receiving ordetermining one or more sample group description entries and a mapping of the one or more sample group description entries to the first sample auxiliary information; and writing at least one sample to group box for indicating that the at least one sample to group box relates to the first sample auxiliary information and for indicating the mapping of the one or more sample group description entries to the first sample auxiliary information.

[0070] Example 68. The method of example 67 further comprising determining that there is one type of sample auxiliary information in the at least one track and, as a consequence, excludes identification of the first sample auxiliary information from the at least one sample to group box.

[0071] Example 69. The method of example 67 further comprising determining that there is more than one type of sample auxiliary information in the at least one track and, as a consequence, includes identification of the first sample auxiliary information in the at least one sample to group box.

[0072] Example 70. A method comprising: parsing at least one sample to group box from a file; parsing that the at least one sample to group box relates to first sample auxiliary information; and parsing, from the at least one sample to group box, a mapping of one or more sample group description entries to the first sample auxiliary information.

[0073] Example 71. An apparatus comprising: means for receiving a first bitstream and a second bitstream; means for encrypting the first bitstream with a first encryption method to generate a first encrypted bitstream; means for encrypting the second bitstream with a second encryption method to generate a second encrypted bitstream; means for taking following as an input: the first encrypted bitstream; the second encrypted bitstream; encryption related data for the first encrypted bitstream; and encryption related data for the second encrypted bitstream; means for producing or generating the following: an encapsulated file comprising at least one track comprising one or more samples, wherein the first encrypted bitstream is encapsulated in the one or more samples, and wherein the second encrypted bitstream is encapsulated in a first sample auxiliary information; including following information in the encapsulated file: a second sample auxiliary information; and a third sample auxiliary information; wherein the second auxiliary information comprises encryption related data for the first encrypted bitstream, and wherein the third sample auxiliary information comprises encryption related data for the second encrypted bitstream.

[0074] Example 72. An apparatus comprising: means for receiving an encapsulated file comprising at least one track comprising one or more samples, wherein a first encrypted bitstream is encapsulated in the one or more samples, and wherein the first encrypted bitstream is encrypted with a first encryption method, and wherein a second encrypted bitstream is encapsulated in one or more firstsample auxiliary information, and wherein the second encrypted bitstream is encrypted with a second encryption method; means for including following information in the encapsulated file: a second sample auxiliary information; and a third sample auxiliary information; wherein the second auxiliary information comprises encryption related data for the first encrypted bitstream, and wherein the third sample auxiliary information comprises encryption related data for the second encrypted bitstream; means for parsing the encapsulated file to generate or produce following: the first encrypted bitstream; the second encrypted bitstream; encryption related data for the first encrypted bitstream; and encryption related data for the second encrypted bitstream; means for decrypting the first encrypted bitstream by using the encryption related data for the first encrypted bitstream to produce a first unencrypted bitstream; and means for decrypting the second encrypted bitstream by using the encryption related data for the second encrypted bitstream to produce a second unencrypted bitstream.

[0075] Example 73. The apparatus of any of examples 71 or 72, wherein the apparatus comprises means for performing methods as described in one or more of the examples 38 to 66.

[0076] Example 74. An apparatus comprising: means for receiving a first bitstream and a second bitstream; means for producing or generating the following: an encapsulated file comprising at least one track comprising one or more samples, wherein the first bitstream is encapsulated in the one or more samples, and wherein the second bitstream is encapsulated in a first sample auxiliary information; means for receiving or determining one or more sample group description entries and a mapping of the one or more sample group description entries to the first sample auxiliary information; and means for writing at least one sample to group box for indicating that the at least one sample to group box relates to the first sample auxiliary information and for indicating the mapping of the one or more sample group description entries to the first sample auxiliary information.

[0077] Example 75. The apparatus of example 74, wherein the apparatus further comprises means for performing method as described in any of the examples 68 or 69.

[0078] Example 76. An apparatus comprising: means for parsing at least one sample to group box from a file; means for parsing that the at least one sample to group box relates to first sample auxiliary information; and means for parsing, from the at least one sample to group box, a mapping of one or more sample group description entries to the first sample auxiliary information.

[0079] Example 77. A computer readable medium comprising program instructions which, when executed by an apparatus, cause the apparatus to perform at least the following: receiving a first bitstream and a second bitstream; encrypting the first bitstream with a first encryption method togenerate a first encrypted bitstream; encrypting the second bitstream with a second encryption method to generate a second encrypted bitstream; taking following as an input: the first encrypted bitstream; the second encrypted bitstream; encryption related data for the first encrypted bitstream; and encryption related data for the second encrypted bitstream; producing or generating the following: an encapsulated file comprising at least one track comprising one or more samples, wherein the first encrypted bitstream is encapsulated in the one or more samples, and wherein the second encrypted bitstream is encapsulated in a first sample auxiliary information; including following information in the encapsulated file: a second sample auxiliary information; and a third sample auxiliary information; wherein the second auxiliary information comprises encryption related data for the first encrypted bitstream, and wherein the third sample auxiliary information comprises encryption related data for the second encrypted bitstream.

[0080] Example 78. A computer readable medium comprising program instructions which, when executed by an apparatus, cause the apparatus to perform at least the following: receiving an encapsulated file comprising at least one track comprising one or more samples, wherein a first encrypted bitstream is encapsulated in the one or more samples, and wherein the first encrypted bitstream is encrypted with a first encryption method, and wherein a second encrypted bitstream is encapsulated in one or more first sample auxiliary information, and wherein the second encrypted bitstream is encrypted with a second encryption method; including following information in the encapsulated file: a second sample auxiliary information; and a third sample auxiliary information; wherein the second auxiliary information comprises encryption related data for the first encrypted bitstream, and wherein the third sample auxiliary information comprises encryption related data for the second encrypted bitstream; parsing the encapsulated file to generate or produce following: the first encrypted bitstream; the second encrypted bitstream; encryption related data for the first encrypted bitstream; and encryption related data for the second encrypted bitstream; decrypting the first encrypted bitstream by using the encryption related data for the first encrypted bitstream to produce a first unencrypted bitstream; and decrypting the second encrypted bitstream by using the encryption related data for the second encrypted bitstream to produce a second unencrypted bitstream.

[0081] Example 79. The computer readable medium of any of examples 77 or 78, wherein the computer readable medium comprises a non-transitory computer readable medium.

[0082] Example 80. The computer readable medium of any of examples 77 to 79, wherein the computer readable medium causes the apparatus to further perform the methods as described in one or more of the examples 38 to 66.

[0083] Example 81. A computer readable medium comprising program instructions which, when executed by an apparatus, cause the apparatus to perform at least the following: receiving a first bitstream and a second bitstream; producing or generating the following: an encapsulated file comprising at least one track comprising one or more samples, wherein the first bitstream is encapsulated in the one or more samples, and wherein the second bitstream is encapsulated in a first sample auxiliary information; receiving or determining one or more sample group description entries and a mapping of the one or more sample group description entries to the first sample auxiliary information; and writing at least one sample to group box for indicating that the at least one sample to group box relates to the first sample auxiliary information and for indicating the mapping of the one or more sample group description entries to the first sample auxiliary information.

[0084] Example 82. The computer readable medium of example 81, wherein the computer readable medium comprises a non-transitory computer readable medium.

[0085] Example 83. The computer readable medium of any of examples 81 or 82, wherein the computer readable medium causes the apparatus to further perform the methods as described in any of the examples 68 to 69.

[0086] Example 84. A computer readable medium comprising program instructions which, when executed by an apparatus, cause the apparatus to perform at least the following: parsing at least one sample to group box from a file; parsing that the at least one sample to group box relates to first sample auxiliary information; and parsing, from the at least one sample to group box, a mapping of one or more sample group description entries to the first sample auxiliary information.BRIEF DESCRIPTION OF THE DRAWINGS

[0087] The foregoing embodiments and other features are explained in the following description, taken in connection with the accompanying drawings, wherein:

[0088] FIG. 1 shows schematically an electronic device employing embodiments of the examples described herein.

[0089] FIG. 2 shows schematically a user equipment suitable for employing embodiments of the examples described herein.

[0090] FIG. 3 shows a block diagram of a general structure of a video encoder.

[0091] FIG. 4 is an example apparatus, which may be implemented in hardware, and is caused to, implement examples described herein.

[0092] FIG. 5 is an example method to implement the embodiments described herein, in accordance with an embodiment.

[0093] FIG. 6 is another example method to implement the embodiments described herein, in accordance with another embodiment.

[0094] FIG. 7 is yet another example method to implement the embodiments described herein, in accordance with another embodiment.

[0095] FIG. 8 is still another example method to implement the embodiments described herein, in accordance with another embodiment.

[0096] FIG. 9 is a block diagram of one possible and non-limiting system in which the example embodiments may be practiced.DETAILED DESCRIPTION OF EXAMPLE EMBODIMENTS

[0097] The following acronyms and abbreviations that may be found in the specification and / or the drawing figures are defined as follows:4CC four character code5G fifth generation cellular network technology5GC 5G core network a.k.a. also known asAVC advanced video codingCU central unitDSP digital signal processorDU distributed unit eNB (or eNodeB) evolved Node B (for example, an LTE base station)EN-DC E-UTRA-NR dual connectivity en-gNB or En-gNB node providing NR user plane and control plane protocol terminations towards the UE, and acting as secondary node in EN-DCE-UTRA evolved universal terrestrial radio access, for example, the LTE radio access technologyFl or Fl-C interface between CU and DU control interface gNB (or gNodeB) base station for 5G / NR, for example, a node providing NR user plane and control plane protocol terminations towards the UE, and connected via the NG interface to the 5GCIEC International Electrotechnical Commission loT internet of thingsISO International Organization for StandardizationISOBMFF ISO base media file formatJPEG joint photographic experts groupLTE long-term evolution mdat MediaDataBoxMME mobility management entity moov MovieBoxMP4 file format for MPEG-4 Part 14 filesMPEG moving picture experts groupMPEG-2 H.222 / H.262 as defined by the ITUMPEG-4 audio and video coding standard for ISO / IEC 14496 ng or NG new generation ng-eNB or NG-eNB new generation eNBNR new radio (5G radio)N / W or NW networkPDCP packet data convergence protocolPHY physical layerPNG portable network graphicsRAN radio access networkRFC request for commentsREC radio link controlRRC radio resource controlRRH remote radio headRU radio unitRx receiverSDAP service data adaptation protocolSGW serving gatewaySMF session management functionSPS sequence parameter setSVC scalable video codingSI interface between eNodeBs and the EPC trak TrackBoxTx transmitterUE user equipmentUICC Universal Integrated Circuit CardUPF user plane functionURL uniform resource locatorX2 interconnecting interface between two eNodeBs in LTE networkXn interface between two NG-RAN nodes

[0098] Some embodiments will now be described more fully hereinafter with reference to the accompanying drawings, in which some, but not all, embodiments are shown. Indeed, various embodiments of the invention may be embodied in many different forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided so that this disclosure will satisfy applicable legal requirements. Like reference numerals refer to like elements throughout. As used herein, the terms ‘data,’ ‘content,’ ‘information,’ and similar terms may be used interchangeably to refer to data capable of being transmitted, received and / or stored in accordance with embodiments of the present invention. Thus, use of any such terms should not be taken to limit the spirit and scope of embodiments.

[0099] Additionally, as used herein, the term ‘circuitry’ refers to (a) hardware-only circuit implementations (e.g., implementations in analog circuitry and / or digital circuitry); (b) combinations of circuits and computer program product(s) comprising software and / or firmware instructions stored on one or more computer readable memories that work together to cause an apparatus to perform one or more functions described herein; and (c) circuits, such as, for example, a microprocessor(s) or a portion of a microprocessor(s), that require software or firmware for operation even if the software or firmware is not physically present. This definition of ‘circuitry’ applies to all uses of this term herein, including in any claims. As a further example, as used herein, the term ‘circuitry’ also includes an implementation comprising one or more processors and / or portion(s) thereof and accompanying software and / or firmware. As another example, the term ‘circuitry’ as used herein also includes, for example, a baseband integrated circuit or applications processor integrated circuit for a mobile phone or a similar integrated circuit in a server, a cellular network device, other network device, and / or other computing device.

[0100] As defined herein, a ‘computer-readable storage medium,’ which refers to a non-transitory physical storage medium (e.g., volatile or non-volatile memory device), can be differentiated from a ‘computer-readable transmission medium,’ which refers to an electromagnetic signal.

[0101] A method, apparatus and computer program product are provided in accordance with example embodiments for encrypting and / or decrypting a bitstream or a file.

[0102] In an example, the following describes in detail suitable apparatus and possible mechanisms for encrypting and / or decrypting a bitstream or a file. In this regard reference is first made to FIG. 1 and FIG. 2, where FIG. 1 shows an example block diagram of an apparatus 50. The apparatus may be an internet of things (loT) apparatus configured to perform various functions, for example, gathering information by one or more sensors, receiving or transmitting information, analyzing information gathered or received by the apparatus, or the like. The apparatus may comprise a video coding system, which may incorporate a codec. FIG. 2 shows a layout of an apparatus according to an example embodiment. The elements of FIG. 1 and FIG. 2 will be explained next.

[0103] The apparatus 50, may for example be, a mobile terminal or user equipment of a wireless communication system, a sensor device, a tag, or a lower power device. However, it would be appreciated that embodiments of the examples described herein may be implemented within any electronic device or apparatus which may process data by neural networks.

[0104] The apparatus 50 may comprise a housing 30 for incorporating and protecting the device. The apparatus 50 may further comprise a display 32, for example, in the form of a liquid crystal display, light emitting diode display, organic light emitting diode display, and the like. In other embodiments of the examples described herein the display may be any suitable display technology suitable to display media or multimedia content, for example, an image or a video. The apparatus 50 may further comprise a keypad 34. In other embodiments of the examples described herein any suitable data or user interface mechanism may be employed. For example, the user interface may be implemented as a virtual keyboard or data entry system as part of a touch-sensitive display.

[0105] The apparatus may comprise a microphone 36 or any suitable audio input which may be a digital or analogue signal input. The apparatus 50 may further comprise an audio output device which in embodiments of the examples described herein may be any one of: an earpiece 38, speaker, or an analogue audio or digital audio output connection. The apparatus 50 may also comprise a battery (or in other embodiments of the examples described herein the device may be powered by any suitable mobileenergy device such as solar cell, fuel cell or clockwork generator). The apparatus may further comprise a camera 42 capable of recording or capturing images and / or video. The apparatus 50 may further comprise an infrared port for short range line of sight communication to other devices. In other embodiments the apparatus 50 may further comprise any suitable short range communication solution such as for example a Bluetooth wireless connection or a USB / firewire wired connection.

[0106] The apparatus 50 may comprise a controller 56, a processor or a processor circuitry for controlling the apparatus 50. The controller 56 may be connected to a memory 58 which in embodiments of the examples described herein may store both data in the form of an image, audio data and video data, and / or may also store instructions for implementation on the controller 56. The controller 56 may further be connected to codec circuitry 54 suitable for carrying out coding and / or decoding of audio, image and / or video data or assisting in coding and / or decoding carried out by the controller.

[0107] The apparatus 50 may further comprise a card reader 48 and a smart card 46, for example, a universal integrated circuit card (UICC) and UICC reader for providing user information and being suitable for providing authentication information for authentication and authorization of the user at a network.

[0108] The apparatus 50 may comprise radio interface circuitry 52 connected to the controller and suitable for generating wireless communication signals, for example, for communication with a cellular communications network, a wireless communications system or a wireless local area network. The apparatus 50 may further comprise an antenna 44 connected to the radio interface circuitry 52 for transmitting radio frequency signals generated at the radio interface circuitry 52 to other apparatus(es) and / or for receiving radio frequency signals from other apparatus(es).

[0109] The apparatus 50 may comprise a camera 42 capable of recording or detecting individual frames which are then passed to the codec circuitry 54 or the controller for processing. The apparatus may receive the video image data for processing from another device prior to transmission and / or storage. The apparatus 50 may also receive either wirelessly or by a wired connection the image for coding / decoding. The structural elements of apparatus 50 described above represent examples of means for performing a corresponding function.

[0110] FIG. 3 shows a block diagram of a general structure of a video encoder. FIG. 3 presents an encoder for two layers, but it would be appreciated that presented encoder could be similarly extended to encode more than two layers. FIG. 3 illustrates a video encoder comprising a first encoder section 501 for a base layer and a second encoder section 502 for an enhancement layer. Each of the firstencoder section 501 and the second encoder section 502 may comprise similar elements for encoding incoming pictures. The encoder sections 501, 502 may comprise a pixel predictor 302, 402, prediction error encoder 303, 403 and prediction error decoder 304, 404. FIG. 3 also shows an embodiment of the pixel predictor 302, 402 as comprising an inter-predictor 306, 406, an intra-predictor 308, 408, a mode selector 310, 410, a filter 316, 416, and a reference frame memory 318, 418. The pixel predictor 302 of the first encoder section 501 receives base layer picture(s) / image(s) 300 of a video stream to be encoded at both the inter-predictor 306 (which determines the difference between the image and a motion compensated reference frame) and the intra-predictor 308 (which determines a prediction for an image block based only on the already processed parts of current frame or picture). The output of both the inter-predictor and the intra-predictor are passed to the mode selector 310. The intra-predictor 308 may have more than one intra-prediction modes. Hence, each mode may perform the intra-prediction and provide the predicted signal to the mode selector 310. The mode selector 310 also receives a copy of the base layer image(s) 300. Correspondingly, the pixel predictor 402 of the second encoder section 502 receives enhancement layer picture(s) / images(s) 400 of a video stream to be encoded at both the interpredictor 406 (which determines the difference between the image and a motion compensated reference frame) and the intra-predictor 408 (which determines a prediction for an image block based only on the already processed parts of current frame or picture). The output of both the inter-predictor and the intra- predictor are passed to the mode selector 410. The intra-predictor 408 may have more than one intraprediction modes. Hence, each mode may perform the intra-prediction and provide the predicted signal to the mode selector 410. The mode selector 410 also receives a copy of the enhancement layer pictures 400.

[0111] Depending on which encoding mode is selected to encode the current block, the output of the inter-predictor 306, 406 or the output of one of the optional intra-predictor modes or the output of a surface encoder within the mode selector is passed to the output of the mode selector 310, 410. The output of the mode selector 310, 410 is passed to a first summing device 321, 421. The first summing device may subtract the output of the pixel predictor 302, 402 from the base layer image(s) 300 / enhancement layer image(s) 400 to produce a first prediction error signal 320, 420 which is input to the prediction error encoder 303, 403.

[0112] The pixel predictor 302, 402 further receives from a preliminary reconstructor 339, 439 the combination of the prediction representation of the image block 312, 412 and the output 338, 438 of the prediction error decoder 304, 404. The preliminary reconstructed image 314, 414 may be passed to the intra-predictor 308, 408 and to the filter 316, 416. The filter 316, 416 receiving the preliminary representation may filter the preliminary representation and output a final reconstructed image 340, 440 which may be saved in the reference frame memory 318, 418. The reference frame memory 318 maybe connected to the inter-predictor 306 to be used as the reference image against which a future base layer image 300 is compared in inter-prediction operations. Subject to the base layer being selected and indicated to be source for inter-layer sample prediction and / or inter-layer motion information prediction of the enhancement layer according to some embodiments, the reference frame memory 318 may also be connected to the inter-predictor 406 to be used as the reference image against which a future enhancement layer image(s) 400 is compared in inter-prediction operations. Moreover, the reference frame memory 418 may be connected to the inter-predictor 406 to be used as the reference image against which the future enhancement layer image(s) 400 is compared in inter -prediction operations.

[0113] Filtering parameters from the filter 316 of the first encoder section 501 may be provided to the second encoder section 502 subject to the base layer being selected and indicated to be source for predicting the filtering parameters of the enhancement layer according to some embodiments.

[0114] The prediction error encoder 303, 403 comprises a transform unit 342, 442 and a quantizer 344, 444. The transform unit 342, 442 transforms the first prediction error signal 320, 420 to a transform domain. The transform is, for example, the DCT transform. The quantizer 344, 444 quantizes the transform domain signal, for example, the DCT coefficients, to form quantized coefficients.

[0115] The prediction error decoder 304, 404 receives the output from the prediction error encoder 303, 403 and performs the opposite processes of the prediction error encoder 303, 403 to produce a decoded prediction error signal 338, 438 which, when combined with the prediction representation of the image block 312, 412 at the second summing device 339, 439, produces the preliminary reconstructed image 314, 414. The prediction error decoder may be considered to comprise a dequantizer 346, 446, which dequantizes the quantized coefficient values, for example, DCT coefficients, to reconstruct the transform signal and an inverse transformation unit 348, 448, which performs the inverse transformation to the reconstructed transform signal wherein the output of the inverse transformation unit 348, 448 includes reconstructed block(s). The prediction error decoder may also comprise a block filter which may filter the reconstructed block(s) according to further decoded information and filter parameters.

[0116] The entropy encoder 330, 430 receives the output of the prediction error encoder 303, 403 and may perform a suitable entropy encoding / variable length encoding on the signal to provide a compressed signal. The outputs of the entropy encoders 330, 430 may be inserted into a bitstream, for example, by a multiplexer 508.

[0117] The one or more apparatuses described in FIGs 1 to 3 may be caused to implement mechanisms for encrypting or decrypting a bitstream or media file, for example, a bitstream or a file based on ISO Base Media File Format.

[0118] Part 7 of ISO / IEC 23001 specifies common encryption formats for use in any file format based on ISO / IEC 14496-12, ISO Base Media File Format. File, track, and track fragment metadata is specified to enable multiple digital rights and key management systems (DRMs) to access the same common encrypted file or stream.

[0119] ISO base media file format

[0120] Available media file format standards include International Standards Organization (ISO) base media file format (ISO / IEC 14496-12, which may be abbreviated ISOBMFF), Moving Picture Experts Group (MPEG)-4 file format (ISO / IEC 14496-14, also known as the MP4 format), and the file format for NAL (Network Abstraction Layer) unit structured video (ISO / IEC 14496-15).

[0121] Some concepts, structures, and specifications of ISOBMFF are described below as an example of a container file format, based on which some embodiments may be implemented. The features of the disclosure are not limited to ISOBMFF, but rather the description is given for one possible basis on top of which at least some embodiments may be partly or fully realized.

[0122] A basic building block in the ISO base media file format is called a box. Each box has a header and a payload. The box header indicates the type of the box and the size of the box in terms of bytes. Box type is typically identified by an unsigned 32-bit integer, interpreted as a four character code (4CC). A box may enclose other boxes, and the ISO file format specifies which box types are allowed within a box of a certain type. Furthermore, the presence of some boxes may be mandatory in each file, while the presence of other boxes may be optional. Additionally, for some box types, it may be allowable to have more than one box present in a file. Thus, the ISO base media file format may be considered to specify a hierarchical structure of boxes.

[0123] In files conforming to the ISO base media file format, the media data may be provided in one or more instances of MediaDataBox (‘mdat‘) and the MovieBox (‘moov’) may be used to enclose the metadata for timed media. In some cases, for a file to be operable, both of the ‘mdat’ and ‘moov’ boxes may be required to be present. The ‘moov’ box may include one or more tracks, and each track may reside in one corresponding TrackBox (‘trak’). Each track is associated with a handler, identified by a four-character code, specifying the track type. Video, audio, and image sequence tracks can becollectively called media tracks, and they include an elementary media stream. Other track types comprise hint tracks and timed metadata tracks.

[0124] Tracks comprise samples, such as audio or video frames. For video tracks, a media sample may correspond to a coded picture or an access unit.

[0125] A media track refers to samples (which may also be referred to as media samples) formatted according to a media compression format (and its encapsulation to the ISO base media file format). A hint track refers to hint samples, including cookbook instructions for constructing packets for transmission over an indicated communication protocol. A timed metadata track may refer to samples describing referred media and / or hint samples.

[0126] The 'trak' box includes in its hierarchy of boxes the SampleDescriptionBox, which gives detailed information about the coding type used, and any initialization information needed for that coding. The SampleDescriptionBox includes an entry-count and as many sample entries as the entrycount indicates. The format of sample entries is track-type specific but derived from generic classes (e.g., VisualSampleEntry, AudioS ampleEntry). Which type of sample entry form is used for derivation of the track-type specific sample entry format is determined by the media handler of the track.

[0127] A sample entry may comprise a configuration box, which itself may comprise a configuration record. The configuration record may comprise information that may be used to configure a decoder instance for decoding the samples mapped to the sample entry.

[0128] A sample table includes all the time and data indexing of the media samples in a track. Using the tables here, it is possible to locate samples in time, determine their type (e.g., I-frame or not), and determine their size, container, and offset into that container.

[0129] When the track that includes the SampleTableBox, refers to no data, then the SampleTableBox does not need to include any sub-boxes (this is not a very useful media track).

[0130] When the track that the SampleTableBox is included in, refers to data, then the following sub-boxes are required: SampleDescriptionBox, SampleSizeBox (or CompactSampleSizeBox), SampleToChunkBox, and ChunkOffsetBox (or ChunkLargeOffsetBox). Further, the SampleDescriptionBox shall include at least one entry. A SampleDescriptionBox is required because it includes the data reference index field, which indicates which DataEntry to use to retrieve the mediasamples. Without the SampleDescriptionBox, it is not possible to determine where the media samples are stored.

[0131] The syntax of SampleTableBox in ISOBMFF is as follows: aligned(8) class SampleTableBox extends Box('stbl') { }

[0132] A SampleSizeBox includes the sample count and a table giving the size in bytes of each sample. This allows the media data itself to be unframed. The total number of samples in the media is always indicated in the sample count.

[0133] There are two variants of the sample size box. The first variant has a fixed size 32-bit field for representing the sample sizes; it permits defining a constant size for all samples in a track. The second variant permits smaller size fields, to save space when the sizes are varying but small. One of these boxes shall be present; the first version is preferred for maximum compatibility.

[0134] A sample size of zero is not prohibited in general, but it should be valid and defined for the coding system, as defined by the sample entry, that the sample belongs to.

[0135] The syntax of SampleSizeBox in ISOBMFF is as follows: aligned(8) class SampleSizeBox extends FullBoxfstsz', version = 0, 0) { unsigned int(32) sample_size; unsigned int(32) sample_count; if (sample_size==0) { for (i= 1; i <= sample_count; i++) { unsigned int(32) entry _size;}}}

[0136] The semantics of SampleSizeBox structure in ISOBMFF is as follows:- version is an integer that specifies the version of this box;- sample_size is integer specifying the default sample size. If all the samples are the same size, this field includes that size value. When this field is set to 0, then the samples have different sizes,and those sizes are stored in the sample size table. If this field is not 0, it specifies the constant sample size, and no array follows.- sample_count is an integer that gives the number of samples in the track; when samplesize is 0, then it is also the number of entries in the following table.- entry_size is an integer specifying the size of a sample, indexed by its number.

[0137] The syntax of CompactSampleSizeBox in ISOBMFF is as follows: aligned(8) class CompactSampleSizeBox extends FullBox('stz2', version = 0, 0) { unsigned int(24) reserved = 0; unsigned int(8) field_size; unsigned int(32) sample_count; for (i=l; i <= sample_count; i++) { unsigned int(field_size) entry _size;

[0138] The semantics of CompactSampleSizeBox structure in ISOBMFF is as follows:-version is an integer that specifies the version of this box;-field_size is an integer specifying the size in bits of the entries in the following table; it shall take the value 4, 8 or 16. If the value 4 is used, then each byte includes two values:- entry[i]«4 + entry[i+l]; if the sizes do not fill an integral number of bytes, the last byte is padded with zeros.- sample_count is an integer that gives the number of entries in the following table -entry_size is an integer specifying the size of a sample, indexed by its number.

[0139] The track reference mechanism can be used to associate tracks with each other. The TrackReferenceBox ('tref ) includes box(es), each of which provides a reference from the including track to a set of other tracks. These references are labeled through the box type (e.g., the four-character code of the box) of the included box(es).

[0140] The ISO Base Media File Format includes three mechanisms for timed metadata that may be associated with particular samples: sample groups, timed metadata tracks, and sample auxiliaryinformation. A derived specification may provide similar functionality with one or more of these three mechanisms.

[0141] A sample grouping in the ISO base media file format and its derivatives, such as ISO / IEC 14496-15, may be defined as an assignment of each sample in a track to be a member of one sample group, based on a grouping criterion. A sample group in a sample grouping is not limited to being contiguous samples and may include non-adjacent samples. As there may be more than one sample grouping for the samples in a track, each sample grouping may have a type field to indicate the type of grouping. Sample groupings may be represented by two linked data structures: (1) a SampleToGroupBox (sbgp box) represents the assignment of samples to sample groups; and (2) a SampleGroupDescriptionBox (sgpd box) includes a sample group entry for each sample group describing the properties of the group. There may be multiple instances of the SampleToGroupBox and SampleGroupDescriptionBox based on different grouping criteria. These may be distinguished by a type field used to indicate the type of grouping. SampleToGroupBox may comprise a grouping_type_parameter field that can be used, e.g., to indicate a sub-type of the grouping.

[0142] In ISOMBFF, an edit list provides a mapping between the presentation timeline and the media timeline. Among other things, an edit list provides for the linear offset of the presentation of samples in a track, provides for the indication of empty times and provides for a particular sample to be dwelled on for a certain period of time. The presentation timeline may be accordingly modified to provide for looping, such as for the looping videos of the various regions of the scene. One example of the box that includes the edit list, the EditListBox, is provided below: aligned(8) class EditListBox extends FullBox(‘elst’, version, flags) { unsigned int(32) entry _count; for (i=l; i <= entry _count; i++) { if (version==l) { unsigned int(64) segment_duration; int(64) media lime;} else { / / version==0 unsigned int(32) segment_duration; int(32) media lime;} int(16) media_rate_integer; int(16) media_rate_fraction = 0;}}

[0143] In ISOBMFF, an EditListBox may be included in EditBox, which is included in a TrackBox ('trak').

[0144] In this example of the edit list box, flags specifies the repetition of the edit list. By way of example, setting a specific bit within the box flags (the least significant bit, e.g., flags & 1 in ANSI-C notation, where & indicates a bit-wise AND operation) equal to 0 specifies that the edit list is not repeated, while setting the specific bit (e.g., flags & 1 in ANSI-C notation) equal to 1 specifies that the edit list is repeated. The values of box flags greater than 1 may be defined to be reserved for future extensions. As such, when the edit list box indicates the playback of zero or one samples, (flags & 1) shall be equal to zero. When the edit list is repeated, the media at time 0 resulting from the edit list follows immediately the media having the largest time resulting from the edit list such that the edit list is repeated seamlessly.

[0145] In ISOBMFF, a Track group enables grouping of tracks based on certain characteristics or the tracks within a group have a particular relationship. Track grouping, however, does not allow any image items in the group.

[0146] The syntax of TrackGroupBox in ISOBMFF is as follows: aligned(8) class TrackGroupBox extends Box('trgr') {} aligned(8) class TrackGroupTypeBox(unsigned int(32) track_group_type) extends FullBox(track_group_type, version = 0, flags = 0) { unsigned int(32) track_group_id; / / the remaining data may be specified for a particular track_group_type}

[0147] track_group_type indicates the grouping type and may be set to one of the following values, or a value registered, or a value from a derived specification or registration:- 'msrc' indicates that this track belongs to a multi-source presentation. The tracks that have the same value of track_group_id within a TrackGroupTypeBox of track_group_type 'msrc' are mapped as being originated from the same source. For example, a recording of a video telephony call may have both audio and video for both participants, and the value oftrack_group_id associated with the audio track and the video track of one participant differs from value of track_group_id associated with the tracks of the other participant.

[0148] The pair of track_group_id and track_group_type identifies a track group within the file. The tracks that include a particular TrackGroupTypeBox having the same value of track_group_id and track_group_type belong to the same track group.

[0149] The Entity grouping is similar to track grouping but enables grouping of both tracks and image items in the same group.

[0150] The syntax of EntityToGroupBox in ISOBMFF is as follows: aligned(8) class EntityToGroupBox(grouping_type, version, flags) extends FullBox(grouping_type, version, flags) { unsigned int(32) group_id; unsigned int(32) num_entities_in_group; for(i=0; i<num_entities_in_group; i++) unsigned int(32) entity _id;}

[0151] group_id is a non-negative integer assigned to the particular grouping that shall not be equal to any group_id value of any other EntityToGroupBox, any item_ID value of the hierarchy level (file, movie, or track) that includes the GroupsListBox, or any track_ID value (when the GroupsListBox is included in the file level).

[0152] num_entities_in_group specifies the number of entity _id values mapped to this entity group.

[0153] entity _id is resolved to an item, when an item with item_ID equal to entity _id is present in the hierarchy level (file, movie or track) that includes the GroupsListBox, or to a track, when a track with track_ID equal to entity _id is present and the GroupsListBox is included in the file level.

[0154] The ProtectionSchemelnfoBox includes the information required both to understand the encryption transform applied and its parameters, and also to find other information such as the kind and location of the key management system. It also documents the original (unencrypted) format of themedia. The ProtectionSchemelnfoBox is a container Box. It is mandatory in a sample entry that uses a code indicating a protected stream.

[0155] When used in a protected sample entry, this box may include the OriginalFormatBox to document the original format. At least one of the following signalling methods may be used to identify the protection applied:- MPEG-4 systems with IPMP: no other boxes, when IPMP descriptors in MPEG-4 systems streams are used; orScheme signalling: a SchemeTypeBox and SchemelnformationBox, when these are used (either both shall occur, or neither).

[0156] At least one ProtectionSchemelnfoBox shall occur in a protected sample entry. When more than one occurs, they are equivalent, alternative, descriptions of the same protection. Readers should choose one to process.

[0157] The syntax of ProtectionSchemelnfoBox in ISOBMFF is as follows: aligned(8) class ProtectionSchemelnfoBox(fmt) extends Box('sinf) { OriginalFormatBox(fmt) original_format;SchemeTypeBox scheme_type_box; / / optionalSchemelnformationBox info; / / optional}

[0158] The OriginalFormatBox includes the four character code of the original un-transformed sample description.

[0159] The syntax of OriginalFormatBox in ISOBMFF is as follows: aligned(8) class OriginalFormatBox(codingname) extends Box ('frma') { unsigned int(32) data_format = codingname; / / format of decrypted, encoded data (in case of protection) / / or un-transformed sample entry (in case of restriction / / and complete track information)}

[0160] data_format is the four character code of the original un-transformed sample entry (e.g. 'mp4v' if the stream includes protected or restricted MPEG-4 visual material).

[0161] The SchemeTypeBox identifies the protection or restriction scheme.

[0162] The syntax of SchemeTypeBox in ISOBMFF is as follows: aligned(8) class SchemeTypeBox extends FullBoxfschm', 0, flags) { unsigned int(32) scheme_type; / / 4CC identifying the scheme unsigned int(32) scheme_version; / / scheme version if (flags & 0x000001) { utf8string scheme_uri; / / browser uri}}

[0163] scheme_type is the code defining the protection or restriction scheme, normally expressed as a four character code.

[0164] scheme_version is the version of the scheme (used to create the content).

[0165] scheme_URI is an absolute URI allowing for the option of directing the user to a web-page if they do not have the scheme installed on their system.

[0166] The SchemelnformationBox is a container Box that is only interpreted by the scheme being used. Any information the encryption or restriction system needs is stored here. The content of this box is a series of boxes whose type and format are defined by the scheme declared in the SchemeTypeBox.

[0167] The syntax of SchemelnformationBox in ISOBMFF is as follows: aligned(8) class SchemelnformationBox extends Box('schi') {Box scheme_specific_d ata [] ;}

[0168] A restricted sample entry is defined as a sample entry on which the following transformation procedure has been applied:- The four character code of the sample entry is replaced by a new sample entry code 'resv' meaning restricted video.- A RestrictedSchemelnfoBox is added to the sample description, leaving all other boxes unmodified.- The original sample entry type is stored within an OriginalFormatBox included in the Restricted SchemelnfoB ox .

[0169] A RestrictedSchemelnfoBox is formatted exactly the same as a ProtectionSchemelnfoBox, except that is uses the identifier 'rinf instead of 'sinf .

[0170] The original sample entry type is included in the OriginalFormatBox located in the RestrictedSchemelnfoBox (e.g., in an identical way to the ProtectionSchemelnfoBox for encrypted media).

[0171] The exact nature of the restriction is defined in the SchemeTypeBox, and the data needed for that scheme is stored in the SchemelnformationBox, again, analogously to protection information.

[0172] Restriction and protection can be applied at the same time. The order of the transformations follows from the four-character code of the sample entry. For instance, when the sample entry type is 'resv', undoing the above transformation may result in a sample entry type 'encv', indicating that the media is protected.

[0173] When the file author only wants to provide advisory information without stopping legacy players from playing the file, the RestrictedSchemelnfoBox may be placed inside the sample entry without transforming the four character code. In this case it is not necessary to include an OriginalFormatBox .

[0174] The RestrictedSchemelnfoBox includes the information required both to understand the restriction scheme applied and its parameters. It also documents the original (un-transformed) sample entry type of the media. The RestrictedSchemelnfoBox is a container Box. It is mandatory in a sample entry that uses a code indicating a restricted stream, e.g., 'resv'.

[0175] When used in a restricted sample entry, this box may include the OriginalFormatBox to document the original sample entry type and a SchemeTypeBox. A SchemelnformationBox may be required depending on the restriction scheme.

[0176] The syntax of RestrictedSchemelnfoBox in ISOBMFF is as follows:aligned(8) class RestrictedSchemelnfoBox(fmt) extends Boxfrinf ) { OriginalFomiatBox(fmt) original_format;SchemeTypeBox scheme_type_box;SchemelnformationBox info; / / optional}

[0177] Per-sample sample auxiliary information may be stored anywhere in the same file as the sample data itself; for self-contained media files, this is typically in a MediaDataBox or a box from a derived specification. It is stored either (a) in multiple chunks, with the number of samples per chunk, as well as the number of chunks, matching the chunking of the primary sample data or (b) in a single chunk for all the samples in a movie sample table (or a movie fragment). The Sample Auxiliary Information for all samples included within a single chunk (or track run) is stored contiguously (similarly to sample data).

[0178] Sample Auxiliary Information, when present, is always stored in the same file as the samples to which it relates as they share the same data reference ('dref ) structure. However, this data may be located anywhere within this file, using auxiliary information offsets ('saio') to indicate the location of the data.

[0179] Whether sample auxiliary information is permitted or required may be specified by the brands or the coding format in use. The format of the sample auxiliary information is determined by aux_info_type. If aux_info_type and aux_info_type_parameter are omitted then the implied value of aux_info_type is either (a) in the case of transformed content, such as protected content, the scheme_type included in the ProtectionSchemelnfoBox or ScrambleSchemelnfoBox, or otherwise (b) the sample entry type. In the case of tracks including multiple transformations, aux_info_type and aux_info_type_parameter shall not be omitted. The default value of the aux_info_type_parameter is 0. Some values of aux_info_type may be restricted to be used only with particular track types. A track may have multiple streams of sample auxiliary information of different types.

[0180] While aux_info_type determines the format of the auxiliary information, several streams of auxiliary information having the same format may be used when their value of aux_info_type_parameter differs. The semantics of aux_info_type_parameter for a particular aux_info_type value shall be specified along with specifying the semantics of the particular aux_info_type value and the implied auxiliary information format.

[0181] This box provides the size of the auxiliary information for each sample. For each instance of this box, there shall be a matching SampleAuxiliarylnformationOffsetsBox with the same values of aux_info_type and aux_info_type_parameter, providing the offset information for this auxiliary information.

[0182] The syntax of Sample Auxiliary InformationSizesBox in ISOBMFF is given below: aligned(8) class SampleAuxiliarylnformationSizesBox extends FullBoxfsaiz', version = 0, flags){ if (flags & 1) { unsigned int(32) aux_info_type; unsigned int(32) aux_info_type_parameter;} unsigned int(8) default_sample_info_size; unsigned int(32) sample_count; if (default_sample_info_size == 0) { unsigned int(8) sample_info_size[ sample_count ];}}

[0183] Where the different fields are defined as follows:

[0184] aux_info_type is an integer that identifies the type of the sample auxiliary information. At most one occurrence of this box with the same values for aux_info_type and aux_info_type_parameter shall exist in the containing box.

[0185] aux_info_type_parameter identifies the “stream” of auxiliary information having the same value of aux_info_type and associated to the same track. The semantics of aux_info_type_parameter are determined by the value of aux_info_type.

[0186] default_sample_info_size is an integer specifying the sample auxiliary information size for the case where all the indicated samples have the same sample auxiliary information size. When the size varies then this field shall be zero.

[0187] sample_count is an integer that gives the number of samples for which a size is defined. For a SampleAuxiliarylnformationSizesBox appearing in the SampleTableBox this shall be the same as, or less than, the sample_count within the SampleSizeBox or CompactSampleSizeBox. For a SampleAuxiliarylnformationSizesBox appearing in a TrackFragmentBox this shall be the same as, or less than, the sum of the sample_count entries within the TrackRunBoxes of the track fragment. If this is less than the number of samples, then auxiliary information is supplied for the initial samples, and the remaining samples have no associated auxiliary information.

[0188] sample_info_size gives the size of the sample auxiliary information in bytes. This may be zero to indicate samples with no associated auxiliary information.

[0189] The Sample Auxiliary InformationOffsetsBox provides the position information for the sample auxiliary information, in a way similar to the chunk offsets for sample data.

[0190] The syntax of SampleAuxiliarylnformationOffsetsBox in ISOBMFF is as follows: aligned(8) class SampleAuxiliarylnformationOffsetsBox extends FullBoxfsaio', version, flags){ if (flags & 1) { unsigned int(32) aux_info_type; unsigned int(32) aux_info_type_parameter;} unsigned int(32) entry_count; if ( version == 0 ) { unsigned int(32) offset[ entry _count ];} else { unsigned int(64) offset[ entry _count ] ;}}

[0191] aux_info_type and aux_info_type_parameter are defined as in theSampleAuxiliarylnformationSizesBox

[0192] entry _count gives the number of entries in the following table. For a S ample Auxiliary InformationOffsetsB ox appearing in a Sample Table Box this shall be equal to one or to the value of the entry_count field in the ChunkOffsetBox or ChunkLargeOffsetBox. For a Sample Auxiliary InformationOffsetsB ox appearing in a TrackFragmentBox, this shall be equal to one or to the number of TrackRunBoxes in the TrackFragmentBox.

[0193] offset gives the position in the file of the Sample Auxiliary Information for each Chunk or Track Fragment Run. If entry _count is one, then the Sample Auxiliary Information for all Chunks or Runs is contiguous in the file in chunk or run order. When in the SampleTableBox, the offsets are relative to the same base offset as derived for the respective samples through the data_reference_index of the sample entry referenced by the samples. In a TrackFragmentBox, this value is relative to the base offset established by the TrackFragmentHeaderBox in the same track fragment.

[0194] When sample auxiliary information is present in the MovieFragmentBox, the offsets in the Sample Auxiliary InformationOffsetsB ox are treated the same as the data_offset in the TrackRunBox, that is, they are relative to any base data offset established for that track fragment.

[0195] When only one offset is provided, then the Sample Auxiliary Information for all the track runs in the fragment is stored contiguously, otherwise exactly one offset shall be provided for each track run.

[0196] When the field default_sample_info_size is non-zero in one of these boxes, then the size of the auxiliary information is constant for the identified samples.

[0197] In addition, when:- this box is present in the MovieBox,- and default_sample_info_size is non-zero in the box in the MovieBox,- and the SampleAuxiliarylnformationSizesBox is absent in a movie fragment, then the auxiliary information has this same constant size for every sample in the movie fragment also; it is then not necessary to repeat the box in the movie fragment.

[0198] The file-format transformations may be used under several circumstances, for example:- They shall be used when the content has been transformed (e.g., by encryption) in such a way that it may no longer be decoded by the normal decoder; or- They may be used when the content should only be decoded when the protection system is understood and implemented.

[0199] The transformation functions by encapsulating the original media declarations. The encapsulation changes the four character-code of the sample entries, so that protection-unaware readers see the media stream as a new stream format.

[0200] Because the format of a sample entry varies with media-type, a different encapsulating four character-code is used for each media type (audio, video, text, and the like). Example four character-code are shown in Table 1 below:Table 1

[0201] The transformed sample entry type shall only be used with the indicated sample entry classes, or classes derived from them that add only boxes (but not fields).

[0202] A protected sample entry is defined as using one of the preceding sample entry codes, and the following transformation procedure:- The four character code of the sample description is replaced with a four character code indicating protection encapsulation: these codes vary only by media-type. For example, 'mp4v' is replaced with 'encv' and 'mp4a' is replaced with 'enca'.- A ProtectionSchemelnfoBox (defined below) is added to the sample description, leaving all other boxes unmodified.- The original sample entry type (four character code) is stored within the ProtectionSchemelnfoBox, in a new box called the OriginalFormatBox (defined below);

[0203] There are then three methods for signalling the nature of the protection, which may be used individually or in combination.- When MPEG-4 systems is used, then IPMP shall be used to signal that the streams are protected.- IPMP descriptors may also be used outside the MPEG-4 systems context using boxes including IPMP descriptors.- The protection applied may also be described using the scheme type and information boxes.

[0204] When IPMP is used outside of MPEG-4 systems, then a ‘global’ IPMPControlBox may also occur within the MovieBox.

[0205] When MPEG-4 systems is used, an MPEG-4 systems terminal can effectively treat, for example, 'encv' with an original format of 'mp4v' exactly the same as 'mp4v', by using the IPMP descriptors.

[0206] Files conforming to the ISOBMFF may include any non-timed objects, referred to as items, meta items, or metadata items, in a meta box (four-character code: ‘meta’ ). While the name of the meta box refers to metadata, items can generally include metadata or media data. The meta box may reside at the top level of the file, within a movie box (four-character code: ‘moov’), and within a track box (four-character code: ‘trak’), but at most one meta box may occur at each of the file level, movie level, or track level. The meta box may be required to include a ‘hdlr’ box indicating the structure or format of the ‘meta’ box contents. The meta box may list and characterize any number of items that can be referred and each one of them can be associated with a file name and are uniquely identified with the file by item identifier (item_id) which is an integer value. The metadata items may be for example stored in the 'idaf box of the meta box or in an 'mdat' box or reside in a separate file. If the metadata is located external to the file then its location may be declared by the DatalnformationBox (four-character code: ‘dinf’). In the specific case that the metadata is formatted using extensible Markup Language (XML) syntax and is required to be stored directly in the MetaBox, the metadata may be encapsulated into either the XMLBox (four-character code: ‘xml ‘) or the BinaryXMLBox (four-character code: ‘bxml’). An item may be stored as a contiguous byte range, or it may be stored in several extents, eachbeing a contiguous byte range. In other words, items may be stored fragmented into extents, e.g. to enable interleaving. An extent is a contiguous subset of the bytes of the resource. The resource can be formed by concatenating the extents.

[0207] MPEG-5 Part 2 Low Complexity Enhancement Video Coding (LCEVC) is published as ISO / IEC 23094-2. LCEVC works by encoding a lower resolution (and potentially also lower bit depth) version of a source video using any existing codec (the “base codec”) and then coding the differences between the lower resolution video and the full resolution source, up to mathematically lossless coding if needed, using a different compression method (the “enhancement”). This enhancement is achieved by a combination of processing an input video at a lower resolution with an existing single-layer codec, and using a simple and small set of highly specialized tools to correct impairments, upscale, and add details to the processed video.

[0208] In an example, a first encoded bitstream encoded with a first coding standard / method, and a second encoded bitstream(s) encoded with a second coding standard / method may be used as input to produce an encapsulated file with one track. The one track may comprise the first encoded bitstream and the second encoded bitstream(s). The file may also include an indication that the first encoded bitstream is encapsulated in the samples of the track, and the second encoded bitstream is encapsulated in the sample auxiliary information of the track.

[0209] In an example, an encapsulated file with at least one track may be used as input to produce a first encoded bitstream encoded with a first coding standard / method, and a second encoded bitstreams encoded with second coding standard / method. The at least one track may comprise a first encoded bitstream and a second encoded bitstream(s). The file may also include an indication that the first encoded bitstream is encapsulated in the samples of the track and the second encoded bitstream is encapsulated in the sample auxiliary information of the track.

[0210] In an example, the samples of the base track may contain the data related to the base codec, and the data related to second codec (for example, LCEVC). The data related to the second codec may be carried as part of the sample auxiliary information related to the samples of the base track.

[0211] In an example, the SampleAuxiliarylnformationSizesBox may be extended. The extension may comprise a SampleDescriptionBox, which may be referred to as the sample_entry_container in the syntax. The sample_entry_container may include a sample entry that specifies the format of the sample auxiliary information. The extension may comprise information of a sample entry, which may, for example, include one or more ConfigurationBoxes. Examples may be similarly realized with other syntax, such as extending the SampleAuxiliarylnformationSizesBox directly with an instance of anSampleEntry, containing a single SampleEntry in a newly defined box that is used to extend SampleAuxiliarylnformationSizesBox, or extending SampleAuxiliarylnformationSizesBox with a decoding configuration record structure.

[0212] In an example, aux_info_type may be set equal to the sample entry 4CC. In an example, a file reader may interpret aux_info_type to indicate a sample entry 4CC, when sample_entry_container is present in SampleAuxiliarylnformationSizesBox.

[0213] In an example, aux_info_type may be set equal to the media handler 4CC, and aux_info_type_parameter may be set equal to the sample entry 4CC. In an example, a file reader may interpret aux_info_type to indicate a media handler 4CC and aux_info_type_parameter to indicate a sample entry 4CC, when sample_entry_container is present in SampleAuxiliarylnformationSizesBox.

[0214] In an example, a sample entry 4CC in the examples above may be allowed to indicate a transformed media track, such as an encrypted media track or a restricted media track. In this case, the one or more sample entries carried in the SampleAuxiliarylnformationSizesBox may include the boxes implied by the transformation. In an example, a file writer may write boxes for transformed media track processing in one or more sample entries carried in the SampleAuxiliarylnformationSizesBox. In an example, a file reader may parse boxes for transformed media track processing from one or more sample entries carried in the SampleAuxiliarylnformationSizesBox. The file reader or a player may subsequently process the sample auxiliary information according to the boxes for transformed media track processing. For example, the file reader or the player may decrypt the sample auxiliary information.

[0215] Examples are described by using LCEVC as an example codec whose coded streams are present together with the coded stream of a base codec. However, the examples are not limited to LCEVC coded streams, but generally apply to any coded stream.

[0216] Common encryption as specified in ISO / IEC 23001-7

[0217] Scheme signalling shall conform to ISO / IEC 14496-12. As defined in ISO / IEC 14496-12, the sample entry is transformed and a ProtectionSchemelnfoBox is added to the standard sample entry in the SampleDescriptionBox to denote that a stream is protected. The ProtectionSchemelnfoBox may include a SchemeTypeBox so that the scheme is identifiable. The SchemeTypeBox may obey the following additional constraints:- The scheme_type field shall be set to a value equal to a four-character code as defined by the protection scheme for example ‘cenc’ .- The scheme_version field shall be set to 0x00010000 (Major version 1, Minor version 0).

[0218] The ProtectionSchemelnfoBox may also include a SchemelnformationBox. The SchemelnformationBox shall include a TrackEncryptionBox, describing the default encryption parameters for the track.

[0219] The schemes identify general classes of algorithms used to encrypt data. Implementations should not rely solely on scheme_type and scheme_version to determine if they can process a file and should also take into account:- parameters associated with the scheme (e.g., the pattern in case of pattern encryption, or the size of initialization vectors),- use of CencSampleEncryptionlnformationGroupEntry and the associated parameters (e.g. change in isProtected, change in number and / or values of keys, change in size of initialization vectors),- value of the field aux_info_type_parameter associated with CENC SAI,- versions and flags of the SampleEncryptionBox box if present,- versions of the ProtectionSystemSpecificHeaderBox and TrackEncryptionBox, and / or- support for, and values of versions and flags, of ItemEncryptionBox and ItemAuxiliarylnformationBox.

[0220] The encryption metadata defined by Common Encryption may be categorized as follows: Protection system specific data;Common encryption information for a media track;Common encryption information for groups of media samples; orCENC SAI, including cryptographic information for individual media samples.

[0221] The ProtectionSystemSpecificHeaderBox box includes information needed by a content protection system to play back the content. The data format is specified by the system identified by the ProtectionSystemSpecificHeaderBox parameter SystemID, and is considered opaque for the purposes of this part of ISO / IEC 23001. The collection of ProtectionSystemSpecific HeaderBoxes from the initial MovieBox, together with those in a movie fragment, may provide all the required content protection system information to decode that fragment.

[0222] The data encapsulated in the Data field may be read by the identified content protection system client to enable decryption key acquisition and decryption of media data. For license / rights-based systems, the header information may include data such as the URL of license server(s) or rights issuer(s) used, embedded licenses / rights, embedded keys(s), and / or other protection system specific metadata.

[0223] A single file may be constructed to be playable by multiple key and digital rights management (DRM) systems, by including ProtectionSystemSpecificHeaderBoxes for each system supported. In order to find all of the protection system specific data that is relevant to a sample in the presentation readers shall:- examine all ProtectionSystemSpecificHeaderBoxes in the MovieBox and in the MovieFragmentBox associated with the sample (but not those in other MovieFragmentBoxes);- match the SystemID field in this box to the SystemlD(s) of the DRM System(s) they support; and- match the KID associated with the sample (either from the default_KID field of the Track Encryption Box or the KID field of the appropriate sample group description entry) with one of the KID values in the ProtectionSystemSpecificHeaderBox. Boxes without a list of applicable KID values, or with an empty list, shall be considered to apply to all KIDs in the file or movie fragment.

[0224] The data in a ProtectionSystemSpecificHeaderBox is associated with samples based on a matching KID value in the ProtectionSystemSpecificHeaderBox and sample group description or default TrackEncryptionBox describing the sample. When a sample or set of samples is moved due to file defragmentation or refragmentation or removed by editing, then the associated ProtectionSystemSpecificHeaderBoxes for the remaining samples shall be stored following the above requirements.

[0225] The syntax of ProtectionSystemSpecificHeaderBox is as follows: aligned(8) class ProtectionSystemSpecificHeaderBox extends FullBox('pssh', version, flags=0) { unsigned int(8)

[0016] SystemID; if (version > 0){ unsigned int(32) KID_count;{ unsigned int(8)

[0016] KID;} [KID_count];}unsigned int(32) DataSize; unsigned int(8) [DataSize] Data;}

[0226] SystemID specifies a UUID that uniquely identifies the content protection system that this header belongs to.

[0227] KID_count specifies the number of KID entries in the following table. The value may be zero.

[0228] KID identifies a key identifier that the Data field applies to. If not set, then the Data array shall apply to all KIDs in the movie or movie fragment including this box.

[0229] DataSize specifies the size in bytes of the Data member.

[0230] Data holds the content protection system specific data.

[0231] The TrackEncryptionBox includes default values for the isProtected flag, Per_Sample_IV_Size, and KID for the entire track. In the case where pattern-based encryption is in effect, it supplies the pattern; and when constant IVs are in use, it supplies the constant IV. These values are used as the encryption parameters for the samples in this track unless over-ridden by the sample group description associated with a group of samples. For files with only one key per track, this box allows the basic encryption parameters to be specified once per track instead of being repeated per sample.

[0232] When both the value of default_isProtected is 1 and default_Per_Sample_IV_Size is 0, then the default_constant_IV_size for all samples that use these settings shall be present. A constant IV shall not be used with counter-mode encryption. A sample group description may supply keys or keys and constant IVs for sample groups that override these default values for those samples mapped to the group.

[0233] For sample entries protected using multiple keys per sample, per-sample protection values shall be indicated for all samples using CencSampleEncryptionlnformationGroupEntry sample grouping. As a consequence, the values in the TrackEncryptionBox are ignored.

[0234] The syntax of TrackEncryptionBox in ISOBMFF is as follows:aligned(8) class TrackEncryptionBox extends FullBoxftenc', version, flags=0){ unsigned int(8) reserved = 0; if (version==0) { unsigned int(8) reserved = 0;} else { / / version is 1 or greater unsigned int(4) default_crypt_byte_block; unsigned int(4) default_skip_byte_block;} unsigned int(8) default_isProtected; unsigned int(8) default_Per_Sample_IV_Size; unsigned int(8)

[0016] default_KID; if (default_isProtected ==1 && default_Per_Sample_IV_Size == 0) { unsigned int(8) default_constant_IV_size; unsigned int(8)[default_constant_IV_size] default_constant_IV;} }

[0235] version should be zero unless pattern-based encryption is in use, whereupon it shall be 1.

[0236] default_isProtected is the protection flag which indicates the default protection state of the samples in the track.

[0237] default_Per_Sample_IV_Size is the default initialization vector size in bytes

[0238] default_KID is the default key identifier used for samples in this track.

[0239] default_constant_IV_size is the size of a possible default initialization vector for all samples.

[0240] default_constant_IV, if present, is the default initialization vector for all samples.

[0241] default_crypt_byte_block specifies the count of the encrypted blocks in the protection pattern, where each block is of size 16-bytes.

[0242] default_skip_byte_block specifies the count of the unencrypted blocks in the protection pattern.

[0243] Each sample in a protected track shall be associated with an isProtected flag, optional subsample information and, for each key involved in the sample protection, a Per_Sample_IV_Size, KID, and an optional constant_IV. This can be accomplished by relying on the default values in the TrackEncryptionBox, and optionally specifying parameters by sample group. Encryption parameters specified in a sample group override the corresponding default parameter values for the samples in that group defined in the TrackEncryptionBox. Samples not mapped to any sample group use the default parameters established in the TrackEncryptionBox.

[0244] When specifying the parameters by sample group, samples are mapped using the SampleToGroupBox to sample group descriptions in the SampleGroupDescriptionBox of type CencSampleEncryptionlnformationGroupEntry as defined below.

[0245] The syntax of CencSampleEncryptionlnformationGroupEntry is the same for all track types (e.g., is independent from the handler type of the track).

[0246] For fragmented files, it may be necessary to store both the mappings and descriptions in each track fragment to make them accessible for decryption of the samples they describe, e.g., when movie fragments are separately stored and delivered by streaming. aligned(8) class CencSampleEncryptionlnformationGroupEntry extends SampleGroupEntry( 'seig' ) unsigned int(l) multi_key_flag ; unsigned int(7) reserved = 0; unsigned int(4) crypt_byte_block; unsigned int(4) skip_byte_block; unsigned int(8) isProtected; if (multi_key_flag == 1) { unsigned int(16) key_count;} else { key_count = 1;for (i=l; i <= key_count; i++) { unsigned int(8) Per_Sample_IV_Size; unsigned int(8)

[0016] KID; if (Per_Sample_IV_Size == 0) { unsigned int(8) constant_IV_size; unsigned int(8)[constant_IV_size] constant_IV;}}}

[0247] These structures use a common semantic for their fields as follows:- multi_key_flag indicates that the multiple key version of the sample group description is used. If this flag is set, multiple keys will be described for this sample group description entry; otherwise, a single key is described for this sample group description entry.- isProtected is the flag which indicates the encryption state of the samples in the sample group.- key_count indicates the number of keys that may apply to a sample associated to this sample group description entry. It is not required that a sample associated with this sample group description entry uses all the keys described.- Per_Sample_IV_Size is the initialization vector size in bytes for samples in the sample group.- KID is the key identifier used for samples in the sample group.- constant_IV_size is the size of a possible initialization vector used for all samples associated with this group (when per-sample initialization vectors are not used).- constant_IV, if present, is the initialization vector used for all samples associated with this group.- crypt_byte_block specifies the count of the encrypted blocks in the protection pattern, where each block is of size 16-bytes.- skip_byte_block specifies the count of the unencrypted blocks in the protection pattern.

[0248] Each protected sample in a protected track shall have initialization vector information associated with it. Both initialization vector and subsample encryption information may be given in a CENC SAI referenced by SampleAuxiliarylnformationSizesBox and SampleAuxiliarylnformationOffsetBox, as defined in ISO / IEC 14496-12, with aux_info_type equal to the scheme and aux_info_type_parameter equal to 0 or 1.

[0249] For example, for tracks protected using the 'cenc' scheme, the default value for aux_info_type is 'cenc' and the default value for the aux_info_type_parameter is 0, so content should be created omitting these optional fields.

[0250] The format of the CENC SAI for aux_info_type_parameter equal to 0 or 1 may be: aligned(8) class CencSampleAuxiliaryDataFormat{ if (aux_info_type_parameter==0) { unsigned int(Per_Sample_IV_Size*8) Initialization Vector; if (sample_info_size > Per_Sample_IV_Size ) { unsigned int(16) subsample_count;{ unsigned int(16) BytesOfClearData; unsigned int(32) BytesOfProtectedData;} [subsample_count ]}} else if (aux_info_type_parameter == 1) { unsigned int(16) multi_IV_count; for (i= 1; i <= multi _IV_count; i++) { unsigned int(16) multi_subindex_IV; unsigned int(Per_Sample_IV_Size*8) IV;} unsigned int(32) subsample_count;{ unsigned int(16) multi_subindex; unsigned int(16) BytesOfClearData; unsigned int(32) BytesOfProtectedData;} [subsample_count]}}

[0251] Where: sample_info_size is the size of the CENC SAI for this sample.Initialization Vector is the initialization vector for the sample, unless a constan t_IV is present in the TrackEncryptionBox.subsample_count is the count of subsamples for this sample.BytesOfClearData is the number of bytes of clear data in this subsample. BytesOfProtectedData is the number of bytes of protected data in this subsample. multi_IV_count indicates the number of entries in the initialization vector loop; this value may be zero when constant initialization vectors are used. multi_subindex_IV indicates the index of the associated key entry, where value one is the first entry, in the associated list; if this data is read for the processing of a media sample, the associated list is the 'seig' sample group description entry associated with this sample; otherwise (this data is read for the processing of an item), the associated list is the list of key definitions in the 'ienc' item property of this item. The associated key entry shall have a Per_Sample_IV_Size different from 0, e.g., key entries using constant IV shall not be present in this loop, if this data is read for the processing of a media sample (e.g. not an item) and aux_info_type_parameter is set to 1, the associated 'seig' sample group description entry shall have the multi_key_flag set to 1; Within a CENC SAI, there shall not be two multi_subindex_IV with the same value.IV indicates the initialization vector to be used for the first block of protected data for the associated key entry. multi_subindex indicates the index of the associated key entry, where value one is the first entry, in the associated list (see multi_subindex_IV) for the following run of encrypted data. If subsample encryption is not used (the size of the CENC SAI equals Per_Sample_IV_Size), then the entire sample is protected. In this case, for a media track, all CENC SAI will have the same size and hence the default_sample_info_size of the SampleAuxiliarylnformationSizesBox will be equal to the Per_Sample_IV_Size of the initialization vector. If Per_Sample_IV_Size is also zero (because constant IVs are in use) then the CENC SAI would then be empty and should be omitted.

[0252] The SampleEncryptionBox provides an optional storage location for CENC SAI of samples in a track or track fragment.

[0253] The SampleEncryptionBox may be used when samples in a track or track fragment are protected. Storage of SampleEncryptionBox in a TrackFragmentBox makes the necessary CENC SAI accessible within the movie fragment for all included samples in order to make each track fragment independently decryptable; for instance, when movie fragments are delivered as DASH media segments.

[0254] When version 0 of SampleEncryptionBox is used, sample_count shall be equal to the number of samples in the track or track fragment. Consequently, version 0 shall not be used when selective encryption is in use.

[0255] When version other than 0 of SampleEncryptionBox is used, the SampleEncryptionBox only includes CENC SAI for samples having their isProtected flag different from 0x00, either through default or through an explicit CencSampleEncryptionlnformationGroupEntry sample to group mapping. The CENC SAI entries are listed in the same order as samples in the track or track fragment. For example, the first entry will describe the CENC SAI of the first protected sample in the track or track fragment, regardless of the number of unprotected samples before this protected sample. Consequently, for version other than 0 of SampleEncryptionBox, there is no CENC SAI for a sample with isProtected different from 0x00, and the corresponding SampleAuxiliarylnformationSizesBox entry shall be 0.

[0256] Derived specifications may further restrict the content of the SampleEncryptionBox, for example by enforcing that all samples in a track fragment are either protected or unprotected.

[0257] The following flags are defined for SampleEncryptionBox: senc_use_subsamples: flag mask is 0x000002. This flag shall not be set if the version is other than 0.

[0258] The variable UseSubSampleEncryption is set as follows: if the version of the SampleEncryptionBox is 0 and the flag senc_use_subsamples is set, UseSubSampleEncryption is set to 1, otherwise, if the version of the SampleEncryptionBox is not 0 and the sample description entry associated with the sample uses a protection scheme mandating usage of subsamples for the described media type, UseSubSampleEncryption is set to 1, otherwise, UseSubSampleEncryption is set to 0. aligned(8) class SampleEncryptionBox extends FullBoxfsenc', version, flags){ unsigned int(32) sample_count;{ if (version==0) { unsigned int(Per_Sample_IV_Size*8) Initialization Vector; if (UseSubSampleEncryption) {unsigned int(16) subsample_count;{ unsigned int(16) BytesOfClearData; unsigned int(32) BytesOfProtectedData;} [subsample_count ]}} else if ((version==l) && isProtected){ unsigned int(16) multi_IV_count; for (i=l; i <= multi _IV_count; i++) { unsigned int(16) multi_subindex_I V; unsigned int(Per_Sample_IV_Size*8) IV;} unsigned int(32) subsample_count;{ unsigned int(16) multi_subindex; unsigned int(16) BytesOfClearData; unsigned int(32) BytesOfProtectedData;} [subsample_count]} else if ((version==2) && isProtected) { unsigned int(Per_Sample_IV_Size*8) Initialization Vector; if (UseSubS ampl eEncryption) { unsigned int(16) subsample_count;{ unsigned int(16) BytesOfClearData; unsigned int(32) BytesOfProtectedData;} [subsample_count ]}}} [ sample_count ]}

[0259] sample_count is the number of CENC SAI coded in the SampleEncryptionBox. For version 0, it shall be either 0 or the number of samples in the track or track fragment where the SampleEncryptionBox is included. For versions other than 0, it shall be the number of protected samples in the track or track fragment where the SampleEncryptionBox is included.

[0260] Initialization Vector values for each sample shall be either a constant IV, and located in the sample entry or a sample group description; or shall be signalled per sample, and be located in the CENC SAI of each protected sample.

[0261] subsample_count specifies the number of subsample encryption entries present for this sample. If present this field shall be greater than 0.

[0262] BytesOfClearData specifies the number of bytes of clear data at the beginning of this subsample encryption entry.

[0263] BytesOfProtectedData specifies the number of bytes of protected data following the clear data (this value may be zero if no protected bytes exist for this subsample). The subsample encryption entries shall not include an entry with a zero value in both the BytesOfClearData field and in the BytesOfProtectedData field unless a 'tref box is found for this track with one or more track references of type 'seal' pointing to one or more tracks with sample entry code 'enev'. The total length of all BytesOfClearData and BytesOfProtectedData in a sample shall equal the length of the sample. Subsample encryption entries should be as compactly represented as possible. For example, instead of two entries with { 15 clear, 0 protected], { 17 clear, 500 protected] use one entry of {32 clear, 500 protected}. If pattern-based encryption is used, then the pattern applies to the protected byte range, BytesOfProtectedData; otherwise all protected bytes are encrypted.multi_IV_count, multi_subindex_IV, IV and multi_subindex shall conform to the definition specified in ISO / IEC 23001- 7.

[0264] In certain applications and use case scenarios the media tracks carry sample auxiliary information (SAI) along with the samples of the track. The SAI’ s are treated as an extension of media samples. One such example is the carriage of base bitstreams in the samples of the media track and LC- EVC bitstream in the SAI of the media track.

[0265] The SAI’s may carry sensitive information or copyright-protected media data which may need to be encrypted. However, the common encryption as specified in ISO / IEC 23001-7 does not support encryption of SAI’s. Since in use cases such as LC-EVC, SAIs may include decodable media data which could be visually observed, there is a need to provide solutions which support encryption of data present in SAI’s.

[0266] An example embodiment defines a method / entity which (writer): takes the following as inputo a first bitstream; and o a second bitstream o encrypts■ the first bitstream with a first encryption method; and■ the second bitstream with a second encryption method wherein the method is further comprises taking the following as input: o a first bitstream encrypted with a first method; o a second bitstream encrypted with a second method; o encryption related data for the first bitstream encrypted with a first method; o encryption related data for the second bitstream encrypted with a second method produces or generates the following: o an encapsulated file with at least one track having one or more samples, wherein the first bitstream is encapsulated in one or more samples of the track wherein the second bitstream is encapsulated in one or more associated first sample auxiliary information wherein the method is further comprises including the following information in the file: o a second sample auxiliary information; and o a third auxiliary information; wherein the second auxiliary information comprises encryption related data for the first bitstream encrypted with a first method o wherein the third auxiliary information includes encryption related data for the second bitstream encrypted with a second method encapsulated in the first sample auxiliary information of the track.

[0267] For example, the first bitstream may include a high efficiency video coding (HE VC) coded video, and the second bitstream may include a low complexity enhancement video coding (LCEVC) coded video. The HEVC coded video and the LCEVC coded video are encrypted. The HEVC coded video is stored in a track (e.g., trackID=l), information used for encrypting HEVC coded video is also stored in trackID=l as sample auxiliary information (e.g., as the first sample auxiliary information (SAI) SAI=1). The LCEVC coded video is also stored in trackID=l as LCEVC sample auxiliary information (e.g., as the second sample auxiliary information (SAI=2)). The information used for encrypting LCEVC coded video is also stored in trackID=l as sample auxiliary information (e.g., the third sample auxiliary information (SAI=3)).

[0268] Another example embodiment defines a method / entity is which (reader): takes the following as inputs: o an encapsulated file with at least one track having one or more samples,wherein the first bitstream is encapsulated in one or more samples of the track wherein the second bitstream is encapsulated in one or more associated first sample auxiliary information wherein the method is further characterized in that it includes the following information in the file: o a second sample auxiliary information; and o a third auxiliary information; wherein the second sample auxiliary information comprises encryption related data for the first bitstream encrypted with a first method; wherein the third sample auxiliary information comprises encryption related data for the second bitstream encrypted with a second method encapsulated in the first sample auxiliary information of the track; wherein the method further comprises parsing the above said encapsulated file and produce or generate the following: a first bitstream encrypted with a first method; a second bitstream encrypted with a second method; encryption related data for the first bitstream encrypted with a first method; and encryption related data for the second bitstream encrypted with a second method wherein the method further comprises following: the first bitstream encrypted with a first method is decrypted using the encryption related data for the first bitstream to produce an unencrypted first bitstream; and the second bitstream encrypted with a second method is decrypted using the encryption related data for the second bitstream to produce an unencrypted second bitstream.

[0269] Support for protected streams and protected sample auxiliary information streams in tracks

[0270] In an embodiment, when a track includes a media stream (for, e.g., AVC bitstream conforming with avcl sample entry) and one or more sample auxiliary information streams the following conditions may apply:- the media stream is encrypted, and the one or more sample auxiliary information streams is unencrypted;- both the media stream and the one or more sample auxiliary information streams are encrypted; or- the media stream is unencrypted, and the one or more sample auxiliary information streams are encrypted.

[0271] When the media stream in the track is encrypted the four-character-code of the sample entry of the track is transformed based on the media-type encapsulated in the track and 4CC of the transformed track takes on one of the values mentioned above in Table 1.

[0272] In an embodiment, when one or more sample auxiliary information streams in the track is encrypted, the following file-format transformation may be used for protected SAI streams, e.g., encrypted the one or more sample auxiliary information.

[0273] In an embodiment, the transformation functions by encapsulating the original media declarations of the sample auxiliary information. In an embodiment, the encapsulation changes the four character-code of any of the box indicating the presence of SAI’ s in the track, so that protection-unaware readers see the data in the SAI as a new data format.

[0274] In an embodiment, a new box may be defined called the TransformedSAIEntry (transformed sample auxiliary information entry) or ProtectedSAIEntry (protected sample auxiliary information entry) or any other suitable alternative name may be used to indicate when a sample auxiliary information stream in the track is encrypted.

[0275] In the following paragraphs the term transformed sample auxiliary information entry or protected sample auxiliary information entry may be used alternatively.

[0276] In an embodiment, one or more protected sample auxiliary information entries may be present in the sample entry of the track inside the sample description or alternatively it may be present in the MovieBox or in the MovieFragmentBox or in the TrackBox or the TrackFragmentBox.

[0277] In an embodiment, when more than one protected sample auxiliary information entries are present then each protected sample auxiliary information entry corresponds to a specific sample auxiliary information in the track and are not alternatives of each other for selection.

[0278] In an embodiment, the format of a sample auxiliary information varies with media-type, a different encapsulating four character-code is used for each media type (audio, video, text, etc.). They are shown in Table 2 below. Alternatively, any other 4CC codes may be used.

[0279] Table 2 Protected sample auxiliary information -entry codesTable 2

[0280] In an embodiment, a protected sample auxiliary information entry is defined as using one of the preceding protected sample auxiliary information entry codes, and the following transformation procedure.

[0281] In an embodiment, the ProtectionSchemelnfoBox is added to the protected sample auxiliary information entry.

[0282] In an alternate embodiment, a new box is defined called SAIProtectionSchemelnfoBox (defined below) is added to the protected sample auxiliary information entry.

[0283] In an embodiment, the original format of the sample auxiliary information is stored within the ProtectionSchemelnfoBox or the SAIProtectionSchemelnfoBox, in the OriginalFormatBox.

[0284] In an alternate embodiment, the original format of the sample auxiliary information is stored within the ProtectionSchemelnfoBox or the SAIProtectionSchemelnfoBox, in a new box called S AIOriginalF ormatB ox .

[0285] In an embodiment, allow ProtectionSchemelnfoBox and / or SAIProtectionSchemelnfoBox to be present in the protected sample auxiliary information entry.

[0286] In an embodiment, when ProtectionSchemelnfoBox and / or SAIProtectionSchemelnfoBox is present in the protected sample auxiliary information entry it inlcudes the information required both to understand the encryption transform applied and its parameters, and also to find other information such as the kind and location of the key management system used for encrypting the sample auxiliary information.

[0287] In an embodiment, ProtectionSchemelnfoBox and / or SAIProtectionSchemelnfoBox documents the original (unencrypted) format of the sample auxiliary information.

[0288] In an embodiment, at least one of the following signalling methods is used to identify the protection applied on the sample auxiliary information:- MPEG-4 systems with IPMP: no other boxes, when IPMP descriptors in MPEG-4 systems streams are used; and- Scheme signalling: a SchemeTypeBox and SchemelnformationBox, when these are used (either both occurs, or neither).

[0289] In an alternate embodiment, the scheme signalling may use new boxes called the SAISchemeTypeBox and SAISchemelnformationBox, when these are used (either both occurs, or neither).

[0290] In an embodiment, at least one ProtectionSchemelnfoBox and / or SAIProtectionSchemelnfoBox shall occur in a protected sample auxiliary information entry.

[0291] In an embodiment, when more than one ProtectionSchemelnfoBox and / or SAIProtectionSchemelnfoBox occur in a protected sample auxiliary information entry, they are equivalent, alternative, descriptions of the same protection. Readers should choose one to process the corresponding (encrypted) sample auxiliary information.

[0292] In an example implementation embodiment, the ISOBMFF implementation of SAIProtectionSchemelnfoBox is shown below.aligned(8) class SAIProtectionSchemelnfoBox(fmt) extends Box('ssin') { SAIOriginalFormatBox(fmt) sai_original_format;SAISchemeTypeBox sai_scheme_type_box; / / optionalSAISchemelnformationBox sai_scheme_info; / / optional}

[0293] In an embodiment, when the OriginalFormatBox is used for storing the original format of the sample auxiliary information, the data_format parameter present in the OriginalFormatBox is extended to indicate the four-character-code of the original un-transformed format of the sample auxiliary information.

[0294] In an embodiment, when the SAIOriginalFormatBox is used for storing the original format of the sample auxiliary information, the SAIOriginalFormatBox includes the data_format parameter to indicate the four-character-code of the original un-transformed format of the sample auxiliary information.

[0295] In an embodiment, in addition to data_format parameter or alternatively the SAIOriginalFormatBox may include other parameters for example original_scheme_type and original_scheme_version indicating the corresponding scheme type and scheme_version of the (identifying) original un-transformed format of the sample auxiliary information.

[0296] In an example implementation embodiment, the ISOBMFF implementation of SAIOriginalFormatBox is shown below aligned(8) class SAIOriginalFormatBox(codingname) extends Box ('sofb') { unsigned int(32) data_format = codingname; / / format of decrypted, encoded data (in case of protection) / / or un-transformed format of the sample auxiliary information}

[0297] data_format is the four-character-code of the original un-transformed format of the sample auxiliary information.

[0298] In an embodiment, the SchemeTypeBox is allowed to be present in the SAIProtectionSchemelnfoBox and / or ProtectionSchemelnfoBox which identifies the protection or restriction scheme used for encrypting the sample auxiliary information.

[0299] In an alternate embodiment, a new box is defined called the SAISchemeTypeBox, which is allowed to be present in the SAIProtectionSchemelnfoBox and / or ProtectionSchemelnfoBox which identifies the protection or restriction scheme used for encrypting the sample auxiliary information.

[0300] In an example implementation embodiment, the ISOBMFF implementation of SAISchemeTypeBox is shown below: aligned(8) class SAISchemeTypeBox extends FullBox('ssch', 0, flags) { unsigned int(32) scheme_type; / / 4CC identifying the scheme unsigned int(32) scheme_ version; / / scheme version if (flags & 0x000001) { utf8string scheme_uri; / / browser uri}}

[0301] scheme_type is the code defining the protection or restriction scheme, normally expressed as a four character code;

[0302] scheme_version is the version of the scheme (used to create the sample auxiliary information)

[0303] scheme_URI is an absolute URI allowing for the option of directing the user to a web-page if they do not have the scheme installed on their system.

[0304] In an embodiment, the SchemelnformationBox is allowed to be present in the SAIProtectionSchemelnfoBox and / or ProtectionSchemelnfoBox is a container box that is only interpreted by the scheme being used. Any information the encryption or restriction system needs for protecting the sample auxiliary information is stored here. The content of this box is a series of boxes whose type and format are defined by the scheme declared in the SchemeTypeBox and / or S AIS chemeT ypeB ox .

[0305] In an alternate embodiment, a new box is defined called the SAISchemelnformationBox, which is allowed to be present in the SAIProtectionSchemelnfoBox and / or ProtectionSchemelnfoBox is a container box that is interpreted by the scheme being used. Any information the encryption or restriction system needs for protecting the sample auxiliary information is stored here. The content of this box is a series of boxes whose type and format are defined by the scheme declared in the SchemeTypeBox and / or SAISchemeTypeBox.

[0306] In an example implementation embodiment, the ISOBMFF implementation of SAISchemelnformationBox is shown below. aligned(8) class SAISchemelnformationBox extends Box('ssci') {Box SAI_scheme_specific_data[];}

[0307] Protection Schemes - scheme type signaling

[0308] In an embodiment, the scheme signalling for sample auxiliary information conforms to transformation steps discussed above.

[0309] In an embodiment, the SchemeTypeBox and / or SAISchemeTypeBox obeys the following constraints.

[0310] In an embodiment, the scheme_type parameter in SchemeTypeBox and / or SAISchemeTypeBox is set to a value equal to a four-character code defined in ISO / IEC 23001-7 for different protection schemes.

[0311] In an embodiment, the scheme_version parameter in SchemeTypeBox and / or SAISchemeTypeBox shall be set to 0x00010000 (Major version 1, Minor version 0).

[0312] In an embodiment, the ProtectionSchemelnfoBox and / or SAIProtectionSchemelnfoBox used for signalling the protection related information for sample auxiliary information also include a SchemelnformationBox and / or SAISchemelnformationBox.

[0313] In an embodiment, the SchemelnformationBox and / or SAISchemelnformationBox used for signalling the protection related information for sample auxiliary information include a TrackEncryptionBox (extended to support signalling of sample auxiliary information as defined below), describing the default encryption parameters for the sample auxiliary information.

[0314] In an alternate embodiment, the SchemelnformationBox and / or SAISchemelnformationBox used for signalling the protection related information for sample auxiliary information include a new box called SAIEncryptionBox or TrackSAIEncryptionBox, describing the default encryption parameters for the sample auxiliary information.

[0315] In an embodiment, the TrackEncryptionBox which defines the default value for each sample in a track is modified / extended to indicate the default values associated with specific SAI which is protected.

[0316] In an embodiment, the TrackEncryptionBox includes default values for the isProtected flag, Per_Sample_IV_Size, and KID for the entire track. The extension / modification can be achieved either by introducing a new version of the box or by setting certain bits within the flag parameter of the box. Alternatively, a new SAIEncryptionBox box may be defined which provides default values for a SAI.

[0317] In an example embodiment, the modified TrackEncryptionBox is shown below: aligned(8) class TrackEncryptionBox extends FullBoxftenc', version=2, flags=0) unsigned int(8) reserved = 0; if (version==0) { unsigned int(8) reserved = 0;} else { / / version is 1 or greater unsigned int(4) default_crypt_byte_block; unsigned int(4) default_skip_byte_block;} if(version==2){ unsigned int(32) sample_aux_info_identifier; unsigned int(32) s ample_aux_info_type ; unsigned int(32) sample_aux_info_parameter:} unsigned int(8) def ault_isProtec ted ; unsigned int(8) def ault_Per_S ample_I V_S ize ;unsigned int(8)

[0016] default_KID; if (default_isProtected ==1 && default_Per_Sample_IV_Size == 0) { unsigned int(8) default_constant_IV_size; unsigned int(8)[default_constant_IV_size] default_constant_IV; }} aligned(8) class SAIEncryptionBox extends FullBoxfsaen', version, flags=0) unsigned int(32) sample_aux_info_identifier; unsigned int(32) sample_aux_info_type; unsigned int(32) sample_aux_info_parameter; if (version==0) { unsigned int(8) reserved = 0;else { / / version is 1 or greater unsigned int(4) default_crypt_byte_block; unsigned int(4) default_skip_byte_block;} unsigned int(8) def ault_isProtec ted ; unsigned int(8) def ault_Per_S ample_I V_S ize ; unsigned int(8)

[0016] default_KID; if (default_isProtected ==1 && default_Per_Sample_IV_Size == 0) { unsigned int(8) default_constant_IV_size; unsigned int(8)[default_constant_IV_size] default_constant_IV; }

[0318] sample_aux_info_identifier indicates the identity of the SAI to which the default values belong to. In an embodiment, this value may be a four character code (4CC).

[0319] In an embodiment, the schemes identify general classes of algorithms used to encrypt sample auxiliary information. Implementations should not rely solely on scheme_type and scheme_version to determine if they can process a file with protected sample auxiliary information and should also take into account:parameters associated with the scheme (e.g. the pattern in case of pattern encryption, or the size of initialization vectors), use of CencSampleEncryptionlnformationGroupEntry and the associated parameters (e.g. change in isProtected, change in number and / or values of keys, change in size of initialization vectors), value of the field aux_info_type_parameter associated with CENC SAI, versions and flags of the SampleEncryptionBox box if present or alternatively, the versions and flags of the SampleSAIEncryptionBox box if present, and versions of the ProtectionSystemSpecificHeaderBox and TrackEncryptionBox or alternatively, versions of the ProtectionSystemSpecificSAIHeaderBox and SAIEncryptionBox (TrackSAIEncryptionBox),

[0320] In an embodiment which may be applied independently of or together with other embodiments, the SampleToGroupBox is amended to indicate that the sample grouping provided in the SampleToGroupBox relates to sample auxiliary information. For example, a new version of the SampleToGroupBox may be defined to indicate that the sample grouping provided in the SampleToGroupBox relates to sample auxiliary information.

[0321] In an embodiment, when the SampleToGroupBox indicates that the sample grouping provided in the SampleToGroupBox relates to sample auxiliary information, the SampleToGroupBox is amended to include identification which sample auxiliary information it relates to. In an example, the following syntax may be used:aligned(8) class SampleToGroupBox extends FullBoxfsbgp', version, flags){ unsigned int(32) grouping_type; if ((version == 2 II version == 3) && (flags & 1)) { unsigned int(32) gr_aux_info_type; unsigned int(32) gr_aux_info_type_parameter;} if (version == 1 11 version == 3) { unsigned int(32) grouping_type_parameter;} unsigned int(32) entry _count; for (i=l; i <= entry _count; i++){ unsigned int(32) sample_count; unsigned int(32) group_description_index;}}

[0322] In an example, the additional semantics for SampleToGroupBox may be specified as follows: versions 2 and 3 of the SampleToGroupBox indicate that sample auxiliary information of the mapped sample is associated with the sample group description provided for the mapped sample in this SampleToGroupBox. When version is equal to 2 or 3 and the least significant bit of the flags field is set (e.g., flags & 1 is non-zero), this SampleToGroupBox is associated with sample auxiliary information for which aux_info_type is equal to gr_aux_info_type and aux_info_type_parameter is equal to gr_aux_info_type_parameter. When version is equal to 2 or 3 and the least significant bit of the flags field is not set, this SampleToGroupBox is associated with sample auxiliary information for which aux_info_type and aux_info_type_parameter are not present.

[0323] In an embodiment which may be applied independently of or together with other embodiments, a file writer receives or determines one or more sample group description entries and a mapping of the one or more sample group description entries to sample auxiliary information. The file writer writes at least one SampleToGroupBox in a file in a manner that the at least one SampleToGroupBox indicates that it relates to sample auxiliary information and indicates the mapping of the one or more sample group description entries to sample auxiliary information.

[0324] In an additional embodiment, the file writer determines that there is only one type of sample auxiliary information in a track and, as a consequence, excludes identification of the sample auxiliary information from the at least one SampleToGroupBox.

[0325] In an additional embodiment, the file writer determines that there is more than one type of sample auxiliary information in a track and, as a consequence, includes identification of the sample auxiliary information from the at least one SampleToGroupBox.

[0326] In an embodiment which may be applied independently of or together with other embodiments, a file reader parses at least one SampleToGroupBox from a file, wherein as part of the parsing of the at least one SampleToGroupBox, the file reader parses that the at least one SampleToGroupBox relates to sample auxiliary information and parses, from the at least one SampleToGroupBox, a mapping of one or more sample group description entries to sample auxiliary information.

[0327] In an embodiment, a SampleToGroupBox that has grouping_type equal to the four- character code of any of the presently specified sample groups, e.g., in ISOBMFF, ISO / IEC 14496-15, or CENC, is indicated by a file writer or parsed by a file reader to concern sample auxiliary information. For example, grouping lype may indicate random access recovery points, rate share groups, alternative startup sequences, random access points (RAP), temporal level, stream access point (SAP), sample-to- item, dependent random access point (DRAP), pixel aspect ratio, clean aperture, extended dependent random access point (EDRAP), or essential descriptions hierarchy sample group as specified in ISOBMFF. The file writer may indicate or the file reader may parse an indication that the sample auxiliary information includes a bitstream of a media codec, such as an LCEVC bitstream, or a transformed bitstream, such as an encrypted bitstream. The indication may be, for example, comprise aux_info_type equal to the sample entry 4CC that identifies the format of the bitstream or the transformed bitstream. This embodiment may be used, for example, to indicate or parse stream access points of a media bitstream that is stored as sample auxiliary information by including (in a file) or parsing (from a file) a SAP sample group that is indicated to concern the sample auxiliary information.

[0328] In an embodiment, a SampleToGroup box that has grouping lype equal to 'seig' (CencSampleEncryptionlnformationGroupEntry) and indicates that the sample grouping provided in the SampleToGroupBox relates to sample auxiliary information is written in a file and / or parsed from a file. In this case, the information provided in mapped entries of CencSampleEncryptionlnformationGroupEntry describes sample auxiliary information and may therefore be used in relation to encryption of sample auxiliary information, such as encryption of LCEVC coded data carried as sample auxiliary information.

[0329] In an embodiment, encryption parameters specified in a SAI sample group override the corresponding default parameter values for the samples SAIs in that group defined in the TrackEncryptionBox for SAI or SAIEncryptionBox. SAIs not mapped to any sample group use the default parameters established in the TrackEncryptionBox for SAI or SAIEncryptionBox.

[0330] When specifying the parameters by sample group, SAI of samples are mapped using the SampleToGroupBox to sample group descriptions in the SampleGroupDescriptionBox of type CencSampleEncryptionlnformationGroupEntry or CencSampleSAIEncryptionlnformationGroupEntry as defined below: aligned(8) class CencSampleSAIEncryptionlnformationGroupEntry extends SampleGroupEntry( 'seig' ) unsigned int(32) sample_aux_info_identifier; unsigned int(32) sample_aux_info_type; unsigned int(32) sample_aux_info_parameter; unsigned int(l) multi_key_flag ; unsigned int(7) reserved = 0; unsigned int(4) crypt_byte_block; unsigned int(4) skip_byte_block; unsigned int(8) isProtected; if (multi_key_flag == 1) { unsigned int(16) key_count;} else { key_count = 1 ;} for (i= 1; i <= key_count; i++) { unsigned int(8) Per_Sample_IV_Size; unsigned int(8)

[0016] KID; if (Per_Sample_IV_Size == 0) { unsigned int(8) constant_IV_size; unsigned int(8)[constant_IV_size] constant_IV;}}

[0331] In an embodiment, SampleAuxiliarylnformationSizesBox is amended to indicate that the associated sample auxiliary information is relative to identified other sample auxiliary information for the same sample and may be interpreted as if that other identified sample auxiliary information were a sample. For example, that other identified sample auxiliary information may carry LCEVC coded data, and the associated sample auxiliary information may carry the CENC information for the LCEVC coded data. In an embodiment, a new version of the SampleAuxiliarylnformationSizesBox is defined to indicate that the associated sample auxiliary information is relative to identified other sample auxiliary information for the same sample. In an embodiment, a new flags bit of SampleAuxiliarylnformationSizesBox, when set, is used to indicate that the presence of the fields identifying the other sample auxiliary information to which this sample auxiliary information is relative. In an example, the following syntax may be used: aligned(8) class SampleAuxiliarylnformationSizesBox extends FullBox('saiz', version, flags){ if (flags & 1) { unsigned int(32) aux_info_type; unsigned int(32) aux_info_type_parameter;} if (version == 1 && (flags & 2)) { unsigned int(32) ref_aux_info_type; unsigend int(32) ref_aux_info_type_parameter;} unsigned int(8) default_sample_info_size; unsigned int(32) sample_count; if (default_sample_info_size == 0) { unsigned int(8) sample_info_size[ sample_count ];}}

[0332] In an example, the additional semantics for SampleAuxiliarylnformationSizesBox may be specified as follows: version 1 of the SampleAuxiliarylnformationSizesBox indicates that sample auxiliary information is relative to identified other sample auxiliary information for the same sample. When version is equal to 1 and the second least significant bit of the flags field is set (e.g., flags & 2 is non-zero), the identified other sample auxiliary information has aux_info_type equal to ref_aux_info_type and aux_info_type_parameter equal to gr_aux_info_type_parameter. When versionis equal to 1 and the second least significant bit of the flags field is not set, the identified other sample auxiliary information does not have aux_info_type and aux_info_type_parameter fields present.

[0333] In an embodiment, each protected sample SAI in a protected track shall have initialization vector information associated with it. Both initialization vector and subsample encryption information may be given in an extended or modified or a new CENC SAI referenced by SampleAuxiliarylnformationSizesBox and SampleAuxiliarylnformationOffsetBox, as defined in ISO / IEC 14496-12, with aux_info_type equal to the scheme and aux_info_type_parameter equal to 0 or 1.

[0334] For example, Sample SAI’s of tracks protected using the 'cenc' scheme, the default value for aux_info_type is 'cenc' and the default value for the aux_info_type_parameter is 0, so content should be created omitting these optional fields. aligned(8) class CencSampleSAIAuxiliaryDataFormat{ if (aux_info_type_parameter==0) { unsigned int(Per_Sample_IV_Size*8) Initialization Vector; if (sample_info_size > Per_Sample_IV_Size ) { unsigned int(16) subsample_count;{ unsigned int(16) BytesOfClearData; unsigned int(32) BytesOfProtectedData;} [subsample_count ]}} else if (aux_info_type_parameter == 1) { unsigned int(16) multi_IV_count; for (i=l; i <= multi _IV_count; i++) { unsigned int(16) multi_subindex_I V; unsigned int(Per_Sample_IV_Size*8) IV;} unsigned int(32) subsample_count;{ unsigned int(16) multi_subindex; unsigned int(16) BytesOfClearData; unsigned int(32) BytesOfProtectedData;} [subsample_count]}}

[0335] FIG. 4 is an example apparatus 450, which may be implemented in hardware, caused to perform encrypting and / or decrypting a bitstream or a file. The apparatus 450 comprises at least one processor 452, at least one non-transitory memory 454 including computer program code 455, wherein the at least one memory 454 and the computer program code 455 are configured to, with the at least one processor 452, cause the apparatus 450 to perform example described herein, including encrypting and / or decrypting a bitstream or a file.

[0336] The apparatus 450 optionally includes a display 458 that may be used to display content during rendering. The apparatus 450 optionally includes one or more network (NW) interfaces (I / F(s)) 460. The NW I / F(s) 460 may be wired and / or wireless and communicate over the Internet / other network(s) via any communication technique. The NW I / F(s) 460 may comprise one or more transmitters and one or more receivers. The N / W I / F(s) 460 may comprise standard well-known components such as an amplifier, filter, frequency-converter, (de)modulator, and encoder / decoder circuitry(ies) and one or more antennas.

[0337] The apparatus 450 may be a remote, virtual or cloud apparatus. The apparatus 450 may be either a coder or a decoder, or both a coder and a decoder. The at least one memory 454 may be implemented using any suitable data storage technology, such as semiconductor based memory devices, flash memory, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory. The at least one memory 454 may comprise a database for storing data. The apparatus 450 need not comprise each of the features mentioned, or may comprise other features as well. The apparatus 450 may correspond to or be another embodiment of the apparatus 50 shown in FIG. 1 to FIG. 3. The apparatus 450 may correspond to or be another embodiment of the apparatuses shown in FIG. 7, including UE 110, RAN node 170, or network element(s) 190.

[0338] FIG. 5 is an example method 500 to implement the embodiments described herein, in accordance with an embodiment. At 512, the method 500 includes receiving a first bitstream and a second bitstream. At 514, the method 500 includes encrypting the first bitstream with a first encryption method to generate a first encrypted bitstream. At 516, the method 500 includes encrypting the second bitstream with a second encryption method to generate a second encrypted bitstream. At 518 , the method 500 includes taking following as an input: the first encrypted bitstream;the second encrypted bitstream; encryption related data for the first encrypted bitstream; and encryption related data for the second encrypted bitstream. At 520, the method 500 includes producing or generating the following: an encapsulated file comprising at least one track comprising one or more samples, wherein the first encrypted bitstream is encapsulated in the one or more samples, and wherein the second encrypted bitstream is encapsulated in a first sample auxiliary information. At 522, the method 500 includes including following information in the encapsulated file: a second sample auxiliary information; and a third sample auxiliary information. At 524, the method 500 includes, wherein the second auxiliary information comprises encryption related data for the first encrypted bitstream, and wherein the third sample auxiliary information comprises encryption related data for the second encrypted bitstream.

[0339] The method 500 may be performed with an apparatus described herein, for example, the any apparatus of FIG. 1 to FIG. 4, any apparatus of FIG. 9, or any other apparatus described herein.

[0340] FIG. 6 is another example method 600 to implement the embodiments described herein, in accordance with an embodiment. At 602, the method 600 includes receiving an encapsulated file comprising at least one track comprising one or more samples, wherein a first encrypted bitstream is encapsulated in the one or more samples, and wherein the first encrypted bitstream is encrypted with a first encryption method, and wherein a second encrypted bitstream is encapsulated in one or more first sample auxiliary information, and wherein the second encrypted bitstream is encrypted with a second encryption method. At 604, the method 600 includes including following information in the encapsulated file: a second sample auxiliary information; and a third sample auxiliary information; wherein the second auxiliary information comprises encryption related data for the first encrypte bitstream, and wherein the third sample auxiliary information comprises encryption related data for the second encrypted bitstream. At 606, the method 600 includes parsing the encapsulated file to generate or produce following: the first encrypted bitstream; the second encrypted bitstream; encryption related data for the first encrypted bitstream; and encryption related data for the second encrypted bitstream. At 608, the method 600 includes decrypting the first encrypted bitstream by using the encryption related data for the first encrypted bitstream to produce a first unencrypted bitstream. At 610, the method 600 includes decrypting the second encrypted bitstream by using the encryption related data for the second encrypted bitstream to produce a second unencrypted bitstream.

[0341] The method 600 may be performed with an apparatus described herein, for example, the any apparatus of FIG. 1 to FIG. 4, any apparatus of FIG. 9, or any other apparatus described herein.

[0342] FIG. 7 is yet another example method 700 to implement the embodiments described herein, in accordance with an embodiment. At 702, the method 700 includes receiving a first bitstream and a second bitstream. At 704, the method 700 producing or generating the following: an encapsulated file comprising at least one track comprising one or more samples, wherein the first bitstream is encapsulated in the one or more samples, and wherein the second bitstream is encapsulated in a first sample auxiliary information. At 706, the method 700 receiving or determining one or more sample group description entries and a mapping of the one or more sample group description entries to the first sample auxiliary information. At 708, the method 700 writing at least one sample to group box for indicating that the at least one sample to group box relates to the first sample auxiliary information and for indicating the mapping of the one or more sample group description entries to the first sample auxiliary information.

[0343] The method 700 may be performed with an apparatus described herein, for example, the any apparatus of FIG. 1 to FIG. 4, any apparatus of FIG. 9, or any other apparatus described herein.

[0344] FIG. 8 is still another example method 800 to implement the embodiments described herein, in accordance with an embodiment. At 802, the method 800 includes parsing at least one sample to group box from a file. At 804, the method 800 parsing that the at least one sample to group box relates to first sample auxiliary information. At 806, the method 800 parsing, from the at least one sample to group box, a mapping of one or more sample group description entries to the first sample auxiliary information.

[0345] The method 800 may be performed with an apparatus described herein, for example, the any apparatus of FIG. 1 to FIG. 4, any apparatus of FIG. 9, or any other apparatus described herein.

[0346] Referring to FIG. 9, this figure shows a block diagram of one possible and non-limiting example in which the examples may be practiced. A user equipment (UE) 110, radio access network (RAN) node 170, and network element(s) 190 are illustrated. In the example of FIG. 1, the user equipment (UE) 110 is in wireless communication with a wireless network 100. A UE is a wireless device that can access the wireless network 100. The UE 110 includes one or more processors 120, one or more memories 125, and one or more transceivers 130 interconnected through one or more buses 127. Each of the one or more transceivers 130 includes a receiver, Rx, 132 and a transmitter, Tx, 133. The one or more buses 127 may be address, data, or control buses, and may include any interconnection mechanism, such as a series of lines on a motherboard or integrated circuit, fiber optics or other optical communication equipment, and the like. The one or more transceivers 130 are connected to one or more antennas 128. The one or more memories 125 include computer program code 123. The UE 110 includes a module 140, comprising one of or both parts 140-1 and / or 140-2, which may be implementedin a number of ways. The module 140 may be implemented in hardware as module 140-1, such as being implemented as part of the one or more processors 120. The module 140-1 may be implemented also as an integrated circuit or through other hardware such as a programmable gate array. In another example, the module 140 may be implemented as module 140-2, which is implemented as computer program code 123 and is executed by the one or more processors 120. For instance, the one or more memories 125 and the computer program code 123 may be configured to, with the one or more processors 120, cause the user equipment 110 to perform one or more of the operations as described herein. The UE 110 communicates with a radio access network (RAN) node 170 via a wireless link 111.

[0347] The RAN node 170 in this example is a base station that provides access by wireless devices such as the UE 110 to the wireless network 100. The RAN node 170 may be, for example, a base station for fifth generation cellular network technology (5G), also called New Radio (NR). In 5G, the RAN node 170 may be a NG-RAN node, which is defined as either a gNB (e.g., base station for 5G / NR, for example, a node providing NR user plane and control plane protocol terminations towards the UE, and connected via the NG interface to the 5GC) or an ng (new generation)-eNB. A gNB is a node providing NR user plane and control plane protocol terminations towards the UE, and connected via the NG interface to a 5G core network (5GC) (such as, for example, the network element(s) 190). The ng-eNB, is a node providing evolved universal terrestrial radio access (E-UTRA), for example, the LTE radio access technology, user plane and control plane protocol terminations towards the UE, and connected via the NG interface to the 5GC. The NG-RAN node may include multiple gNBs, which may also include a central unit (CU) (gNB-CU) 196 and distributed unit(s) (DUs) (gNB-DUs), of which DU 195 is shown. Note that the DU may include or be coupled to and control a radio unit (RU). The gNB- CU is a logical node hosting radio resource control (RRC), service data adaptation protocol (SDAP) and PDCP protocols of the gNB or RRC and packet data convergence protocol (PDCP) protocols of the en-gNB (e.g., node providing NR user plane and control plane protocol terminations towards the UE, and acting as secondary node in E-UTRA-NR dual connectivity (EN-DC)) that controls the operation of one or more gNB-DUs. The gNB-CU terminates the interface between CU and DU control interface (Fl or Fl-C) interface connected with the gNB-DU. The Fl interface is illustrated as reference 198, although reference 198 also illustrates a link between remote elements of the RAN node 170 and centralized elements of the RAN node 170, such as between the gNB-CU 196 and the gNB-DU 195. The gNB-DU is a logical node hosting radio link control (RLC), MAC and physical layer (PHY) layers of the gNB or en-gNB, and its operation is partly controlled by gNB-CU. One gNB-CU supports one or multiple cells. One cell is supported by only one gNB-DU. The gNB-DU terminates the Fl interface 198 connected with the gNB-CU. Note that the DU 195 is considered to include the transceiver 160, for example, as part of a RU, but some examples of this may have the transceiver 160 as part of a separateRU, for example, under control of and connected to the DU 195. The RAN node 170 may also be an eNB (evolved NodeB) base station, for example, long term evolution (LTE), or any other suitable base station or node.

[0348] The RAN node 170 includes one or more processors 152, one or more memories 155, one or more network interfaces (N / W I / F(s)) 161, and one or more transceivers 160 interconnected through one or more buses 157. Each of the one or more transceivers 160 includes a receiver, Rx, 162 and a transmitter, Tx, 163. The one or more transceivers 160 are connected to one or more antennas 158. The one or more memories 155 include computer program code 153. The CU 196 may include the processor(s) 152, memories 155, and network interfaces 161. Note that the DU 195 may also include its own memory / memories and processor(s), and / or other hardware, but these are not shown.

[0349] The RAN node 170 includes a module 150, comprising one of or both parts 150-1 and / or 150-2, which may be implemented in a number of ways. The module 150 may be implemented in hardware as module 150-1, such as being implemented as part of the one or more processors 152. The module 150-1 may be implemented also as an integrated circuit or through other hardware such as a programmable gate array. In another example, the module 150 may be implemented as module 150-2, which is implemented as computer program code 153 and is executed by the one or more processors 152. For instance, the one or more memories 155 and the computer program code 153 are configured to, with the one or more processors 152, cause the RAN node 170 to perform one or more of the operations as described herein. Note that the functionality of the module 150 may be distributed, such as being distributed between the DU 195 and the CU 196, or be implemented solely in the DU 195.

[0350] The one or more network interfaces 161 communicate over a network such as via the links 176 and 131. Two or more gNBs 170 may communicate using, for example, link 176. The link 176 may be wired or wireless or both and may implement, for example, an Xn interface for 5G, an X2 interface for LTE, or other suitable interface for other standards.

[0351] The one or more buses 157 may be address, data, or control buses, and may include any interconnection mechanism, such as a series of lines on a motherboard or integrated circuit, fiber optics or other optical communication equipment, wireless channels, and the like. For example, the one or more transceivers 160 may be implemented as a remote radio head (RRH) 195 for LTE or a distributed unit (DU) 195 for gNB implementation for 5G, with the other elements of the RAN node 170 possibly being physically in a different location from the RRH / DU, and the one or more buses 157 could be implemented in part as, for example, fiber optic cable or other suitable network connection to connectthe other elements (for example, a central unit (CU), gNB-CU) of the RAN node 170 to the RRH / DU 195. Reference 198 also indicates those suitable network link(s).

[0352] It is noted that description herein indicates that ‘cells’ perform functions, but it should be clear that equipment which forms the cell may perform the functions. The cell makes up part of a base station. That is, there can be multiple cells per base station. For example, there could be three cells for a single carrier frequency and associated bandwidth, each cell covering one-third of a 360 degree area so that the single base station’s coverage area covers an approximate oval or circle. Furthermore, each cell can correspond to a single carrier and a base station may use multiple carriers. So when there are three 120 degree cells per carrier and two carriers, then the base station has a total of 6 cells.

[0353] The wireless network 100 may include a network element or elements 190 that may include core network functionality, and which provides connectivity via a link or links 181 with a further network, such as a telephone network and / or a data communications network (for example, the Internet). Such core network functionality for 5G may include access and mobility management function(s) (AMF(S)) and / or user plane functions (UPF(s)) and / or session management function(s) (SMF(s)). Such core network functionality for LTE may include MME (Mobility Management Entity ) / SGW (Serving Gateway) functionality. These are merely example functions that may be supported by the network element(s) 190, and note that both 5G and LTE functions might be supported. The RAN node 170 is coupled via a link 131 to the network element 190. The link 131 may be implemented as, for example, an NG interface for 5G, or an SI interface for LTE, or other suitable interface for other standards. The network element 190 includes one or more processors 175, one or more memories 171, and one or more network interfaces (N / W I / F(s)) 180, interconnected through one or more buses 185. The one or more memories 171 include computer program code 173. The one or more memories 171 and the computer program code 173 are configured to, with the one or more processors 175, cause the network element 190 to perform one or more operations.

[0354] The wireless network 100 may implement network virtualization, which is the process of combining hardware and software network resources and network functionality into a single, softwarebased administrative entity, a virtual network. Network virtualization involves platform virtualization, often combined with resource virtualization. Network virtualization is categorized as either external, combining many networks, or parts of networks, into a virtual unit, or internal, providing network-like functionality to software containers on a single system. Note that the virtualized entities that result from the network virtualization are still implemented, at some level, using hardware such as processors 152 or 175 and memories 155 and 171, and also such virtualized entities create technical effects.

[0355] The computer readable memories 125, 155, and 171 may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor based memory devices, flash memory, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory. The computer readable memories 125, 155, and 171 may be means for performing storage functions. The processors 120, 152, and 175 may be of any type suitable to the local technical environment, and may include one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs) and processors based on a multi-core processor architecture, as non-limiting examples. The processors 120, 152, and 175 may be means for performing functions, such as controlling the UE 110, RAN node 170, network element(s) 190, and other functions as described herein.

[0356] In general, the various embodiments of the user equipment 110 can include, but are not limited to, cellular telephones such as smart phones, tablets, personal digital assistants (PDAs) having wireless communication capabilities, portable computers having wireless communication capabilities, image capture devices such as digital cameras having wireless communication capabilities, gaming devices having wireless communication capabilities, music storage and playback appliances having wireless communication capabilities, Internet appliances permitting wireless Internet access and browsing, tablets with wireless communication capabilities, as well as portable units or terminals that incorporate combinations of such functions.

[0357] One or more of modules 140-1, 140-2, 150-1, and 150-2 may be caused to implement mechanisms for encrypting and / or decrypting a bitstream or a file. Computer program code 173 may also be caused to implement mechanisms for encrypting and / or decrypting a bitstream or a file.

[0358] As described above, FIGs. 5 to 8 include flowcharts of an apparatus (e.g. 50, 450, or any other apparatuses described herein), method, and computer program product according to certain example embodiments. It will be understood that each block of the flowcharts, and combinations of blocks in the flowcharts, may be implemented by various means, such as hardware, firmware, processor, circuitry, and / or other devices associated with execution of software including one or more computer program instructions. For example, one or more of the procedures described above may be embodied by computer program instructions. In this regard, the computer program instructions which embody the procedures described above may be stored by a memory (e.g. 58, 125, or 554) of an apparatus employing an embodiment of the present invention and executed by processing circuitry (e.g. 56, 120, or 552) of the apparatus. As will be appreciated, any such computer program instructions may be loaded onto a computer or other programmable apparatus (e.g., hardware) to produce a machine, such that the resulting computer or other programmable apparatus implements the functions specified in theflowchart blocks. These computer program instructions may also be stored in a computer-readable memory that may direct a computer or other programmable apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture, the execution of which implements the function specified in the flowchart blocks. The computer program instructions may also be loaded onto a computer or other programmable apparatus to cause a series of operations to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide operations for implementing the functions specified in the flowchart blocks.

[0359] A computer program product is therefore defined in those instances in which the computer program instructions, such as computer-readable program code portions, are stored by at least one non- transitory computer-readable storage medium with the computer program instructions, such as the computer-readable program code portions, being configured, upon execution, to perform the functions described above, such as in conjunction with the flowchart(s) of FIGs. 5 to 8. In other embodiments, the computer program instructions, such as the computer-readable program code portions, need not be stored or otherwise embodied by a non-transitory computer-readable storage medium, but may, instead, be embodied by a transitory medium with the computer program instructions, such as the computer- readable program code portions, still being configured, upon execution, to perform the functions described above.

[0360] Accordingly, blocks of the flowcharts support combinations of means for performing the specified functions and combinations of operations for performing the specified functions for performing the specified functions. It will also be understood that one or more blocks of the flowcharts, and combinations of blocks in the flowcharts, may be implemented by special purpose hardware-based computer systems which perform the specified functions, or combinations of special purpose hardware and computer instructions.

[0361] In some embodiments, certain ones of the operations above may be modified or further amplified. Furthermore, in some embodiments, additional optional operations may be included. Modifications, additions, or amplifications to the operations above may be performed in any order and in any combination.

[0362] In the above, some example embodiments have been described with the help of syntax of the bitstream. It needs to be understood, however, that the corresponding structure and / or computerprogram may reside at the encoder for generating the bitstream and / or at the decoder for decoding the bitstream.

[0363] In the above, where example embodiments have been described with reference to an encoder, it needs to be understood that the resulting bitstream and the decoder have corresponding elements in them. Likewise, where example embodiments have been described with reference to a decoder, it needs to be understood that the encoder has structure and / or computer program for generating the bitstream to be decoded by the decoder.

[0364] Many modifications and other embodiments of the inventions set forth herein will come to mind to one skilled in the art to which these inventions pertain having the benefit of the teachings presented in the foregoing descriptions and the associated drawings. Therefore, it is to be understood that the inventions are not to be limited to the specific embodiments disclosed and that modifications and other embodiments are intended to be included within the scope of the appended claims. Moreover, although the foregoing descriptions and the associated drawings describe example embodiments in the context of certain example combinations of elements and / or functions, it should be appreciated that different combinations of elements and / or functions may be provided by alternative embodiments without departing from the scope of the appended claims. In this regard, for example, different combinations of elements and / or functions than those explicitly described above are also contemplated as may be set forth in some of the appended claims. Accordingly, the description is intended to embrace all such alternatives, modifications and variances which fall within the scope of the appended claims. Although specific terms are employed herein, they are used in a generic and descriptive sense only and not for purposes of limitation.

[0365] It should be understood that the foregoing description is only illustrative. Various alternatives and modifications may be devised by those skilled in the art. For example, features recited in the various dependent claims could be combined with each other in any suitable combination(s). In addition, features from different embodiments described above could be selectively combined into a new embodiment. Accordingly, the description is intended to embrace all such alternatives, modifications and variances which fall within the scope of the appended claims.

[0366] References to a ‘computer’, ‘processor’, etc. should be understood to encompass not only computers having different architectures such as single / multi-processor architectures and sequential (Von Neumann) / parallel architectures but also specialized circuits such as field-programmable gate arrays (FPGA), application specific circuits (ASIC), signal processing devices and other processing circuitry. References to computer program, instructions, code etc. should be understood to encompasssoftware for a programmable processor or firmware such as, for example, the programmable content of a hardware device such as instructions for a processor, or configuration settings for a fixed-function device, gate array or programmable logic device, and the like.

[0367] As used herein, the term ‘circuitry’ may refer to any of the following: (a) hardware circuit implementations, such as implementations in analog and / or digital circuitry, and (b) combinations of circuits and software (and / or firmware), such as (as applicable): (i) a combination of processor(s) or (ii) portions of processor(s) / software including digital signal processor(s), software, and memory(ies) that work together to cause an apparatus to perform various functions, and (c) circuits, such as a microprocessor(s) or a portion of a microprocessor(s), that require software or firmware for operation, even if the software or firmware is not physically present. This description of ‘circuitry’ applies to uses of this term in this application. As a further example, as used herein, the term ‘circuitry’ would also cover an implementation of merely a processor (or multiple processors) or a portion of a processor and its (or their) accompanying software and / or firmware. The term ‘circuitry’ would also cover, for example and if applicable to the particular element, a baseband integrated circuit or applications processor integrated circuit for a mobile phone or a similar integrated circuit in a server, a cellular network device, or another network device.

[0368] Circuitry or Circuit: As used in this application, the term ‘circuitry’ or ‘circuit’ may refer to one or more or all of the following:(a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry); and(b) combinations of hardware circuits and software, such as (as applicable):(i) a combination of analog and / or digital hardware circuit(s) with software / firmware; and(ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions); and(c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.

[0369] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The termcircuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.

Claims

CLAIMSWhat is claimed is:

1. An apparatus comprising at least one processor; and at least one non -transitory memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: receiving a first bitstream and a second bitstream; encrypting the first bitstream with a first encryption method to generate a first encrypted bitstream; encrypting the second bitstream with a second encryption method to generate a second encrypted bitstream; taking following as an input: the first encrypted bitstream; the second encrypted bitstream; encryption related data for the first encrypted bitstream; and encryption related data for the second encrypted bitstream; producing or generating the following: an encapsulated file comprising at least one track comprising one or more samples, wherein the first encrypted bitstream is encapsulated in the one or more samples, and wherein the second encrypted bitstream is encapsulated in a first sample auxiliary information; including following information in the encapsulated file: a second sample auxiliary information; and a third sample auxiliary information; wherein the second auxiliary information comprises the encryption related data for the first encrypted bitstream, and wherein the third sample auxiliary information comprises the encryption related data for the second encrypted bitstream.

2. An apparatus comprising at least one processor; and at least one non-transitory memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: receiving an encapsulated file comprising at least one track comprising one or more samples, wherein a first encrypted bitstream is encapsulated in the one or more samples, and wherein the first encrypted bitstream is encrypted with a first encryption method, and whereina second encrypted bitstream is encapsulated in one or more first sample auxiliary information, and wherein the second encrypted bitstream is encrypted with a second encryption method; including following information in the encapsulated file: a second sample auxiliary information; and a third sample auxiliary information; wherein the second auxiliary information comprises encryption related data for the first encrypted bitstream, and wherein the third sample auxiliary information comprises encryption related data for the second encrypted bitstream; parsing the encapsulated file to generate or produce following: the first encrypted bitstream; the second encrypted bitstream; the encryption related data for the first encrypted bitstream; and the encryption related data for the second encrypted bitstream; decrypting the first encrypted bitstream by using the encryption related data for the first encrypted bitstream to produce a first unencrypted bitstream; and decrypting the second encrypted bitstream by using the encryption related data for the second encrypted bitstream to produce a second unencrypted bitstream.

3. The apparatus of claim 1 or 2, wherein the apparatus is further caused to perform: applying one or more of following conditions: the first and the second bitstream are encrypted, and the first, second, and third sample auxiliary information streams are unencrypted; or the first and the second bitstream and first, second, and third sample auxiliary information streams are encrypted; wherein when the first and the second bitstreams in the at least one track is encrypted, a four-character-code (4CC) of a sample entry of the at least one track is transformed based on a media-type encapsulated in the at least one track.

4. The apparatus of claim 3, wherein when one or more of the first, second, or third sample auxiliary information streams in the at least one track are encrypted, file-format transformation is used for protected sample auxiliary information (SAI) streams.

5. The apparatus of any of the claims 3 or 4, wherein the transformation functions by encapsulating original media declarations of the one or more of the first, second, or third sample auxiliary information, or by changing a four character code (4CC) of a box indicating presenceof an SAI in the at least one track, such that protection-unaware readers reads or analyzes data in the SAI as a new data format.

6. The apparatus of any of the claims 3 to 5, wherein the apparatus is further caused to perform: defining a transformed sample auxiliary information entry box or a protected sample auxiliary information entry box to indicate that the one or more of the of the first, second, or third sample auxiliary information streams in the at least one track is encrypted.

7. The apparatus of any of the claims 3 to 6, wherein one or more protected sample auxiliary information entries are comprised in the one or more samples of the at least one track comprised in a sample description, or wherein the one or more protected sample auxiliary information entries are present in one of: a movie box, a movie fragment box, a track box, or a track fragment box.

8. The apparatus of claim 7, wherein when more than one protected sample auxiliary information entries are present then each protected sample auxiliary information entry corresponds to a specific sample auxiliary information in the at least one track and are not alternatives of each other for selection.

9. The apparatus of any of the claims 3 to 8, wherein when a format of the first, second, or third sample auxiliary information varies with a media-type, the apparatus is further caused to use a different encapsulating four character-code for each media type.

10. The apparatus of any of the claims 8 or 9, wherein the protected sample auxiliary information entries are defined by using protected sample auxiliary information entry codes.

11. The apparatus of any of the claims 7 to 10, wherein the apparatus is further caused to perform: adding a protection scheme information box or a SAI protection scheme information box to each of the one or more protected sample auxiliary information entries.

12. The apparatus of any of the claims 1 to 11, wherein an original format of the first, second, and the third sample auxiliary information is stored within a protection scheme information box or a SAI protection scheme information box comprised in an original format box.

13. The apparatus of any of the claims 1 to 11, wherein an original format of the first, second, and the third sample auxiliary information is stored within a protection scheme iinformation box or a SAI protection scheme information box comprised in an SAI original format box.

14. The apparatus of any of the claims 1 to 11, wherein the apparatus is further caused to perform: allowing the protection scheme information box and / or the SAI protection scheme information box to be present in the protected sample auxiliary information entry.

15. The apparatus of claim 14, wherein when the protection scheme information box and / or the SAI protection scheme information box is present in the protected sample auxiliary information entry, and wherein the protected sample auxiliary information entry comprises information required both to understand the encryption transform applied and parameters of the transformation.

16. The apparatus of any of claims 14 or 15, wherein the protection scheme information box and / or the SAI protection scheme information box documents original format of the sample auxiliary information.

17. The apparatus of any of the claims 7 to 16, wherein the apparatus is caused to use at least one of the following signaling to identify the protection applied on the first, second, and third sample auxiliary information:MPEG-4 systems with IPMP, when IPMP descriptors in MPEG-4 systems streams are used; scheme signaling using a scheme type box and a scheme information box, when the scheme type box and the scheme information box are used; or scheme signaling using SAI scheme type box and a SAI scheme information box when the signaling using SAI scheme type box and the SAI scheme information box.

18. The apparatus of claim 17, wherein at least one protection scheme information box and / or SAI protection scheme information box is comprised in the protected sample auxiliary information entry.

19. The apparatus of claim 18, wherein when more than one protection scheme information box and / or SAI protection scheme information box occur in a protected sample auxiliaryinformation entry, the more than one protection scheme information box and / or SAI protection scheme information box are equivalent, alternative, descriptions of the same protection.

20. The apparatus of claim 12, wherein when an original format box is used for storing an original format of the first, second, or third sample auxiliary information, a data format parameter present in the original format box is extended to indicate a four-character-code of an original un-transformed format of the first, second, or third sample auxiliary information.

21. The apparatus of claim 13 , wherein when the SAI original format box is used for storing an original format of the first, second, or third sample auxiliary information, the SAI original format box comprises a data format parameter to indicate a four-character-code of an original un-transformed format of the first, second, or third sample auxiliary information.

22. The apparatus of claim 21, wherein the SAI original format box comprises one or more of following parameters: an original scheme type for indicating a corresponding scheme type of the original un-transformed format of the first, second, or third sample auxiliary information and an original scheme version for indicating a corresponding scheme version of the original un-transformed format of the first, second, or third sample auxiliary information.

23. The apparatus of any of claims 14 to 16, wherein a scheme type box is comprised in a SAI protection scheme information box and / or a protection scheme information box for identifying a protection or a restriction scheme used for encrypting the first, second, or third sample auxiliary information.

24. The apparatus of claim 23, wherein the apparatus is further caused to perform: defining a SAI scheme type box, wherein the SAI scheme type box is comprised a SAI protection scheme information box and / or a protection scheme information box for identifying a protection or a restriction scheme used for encrypting the first, second, or third sample auxiliary information.

25. The apparatus of claim 23, wherein a scheme information box is comprised in the SAI protection scheme information box and / or a protection scheme information box is a container box that is interpreted by the scheme being used, and wherein information an encryption or restriction system needs for protecting the first, second, or third sample auxiliary information is stored in the scheme information box.

26. The apparatus of claim 23, wherein the apparatus is caused to perform: defining a SAI scheme information box, wherein the SAI scheme information box is comprised in the SAIprotection scheme information box and / or a protection scheme information box is a container box that is interpreted by a scheme being used, and wherein information an encryption or restriction system needs for protecting the first, second, or third sample auxiliary information is stored in the scheme information box.

27. The apparatus of any of claims 23 to 24, wherein the scheme type box and / or the SAI scheme type box conform to following: a scheme type parameter in the scheme type box and / or the SAI scheme type box is set to a value equal to a four-character code defined in ISO / IEC 23001-7 for different protection schemes; a scheme version parameter in the scheme type box and / or the SAI scheme type box is set to a predefined value; the protection scheme information box and / or the SAI protection scheme information box used for signaling the protection related information for the first, second, or third sample auxiliary information also comprises a scheme information box and / or SAI scheme information box; the scheme information box and / or SAI scheme information box used for signaling the protection related information for the first, second, or third sample auxiliary information comprises a track information box extended to support signaling of the first, second, or third sample auxiliary information and describing the default encryption parameters for the first, second, or third sample auxiliary information; the scheme information box and / or SAI scheme information box used for signaling the protection related information for the sample auxiliary information comprises a SAI encryption box or a track SAI encryption box describing default encryption parameters for the first, second, or third sample auxiliary information; a track encryption box which defines a default value for each sample in the at least one track is modified or extended to indicate the default values associated with a specific SAI that is protected; or the track encryption box comprises default values for a protected flag, a vector size for samples in a sample group for the at least one track , and an identifier used for samples in the sample group.

28. The apparatus of claim 1, wherein the apparatus is further caused to perform: receiving or determining one or more sample group description entries and a mapping of the one or more sample group description entries to the first, second, and third sample auxiliary information; andwriting at least one sample to group box for indicating that the at least one sample to group box relates to the first, second or third sample auxiliary information and for indicating the mapping of the one or more sample group description entries to the first, second, or third sample auxiliary information.

29. The apparatus of claim 28, wherein the apparatus is further caused to perform: determining that there is one type of sample auxiliary information in the at least one track and, as a consequence, excludes identification of the first, second or third sample auxiliary information from the at least one sample to group box.

30. The apparatus of claim 28, wherein the apparatus is further caused to perform: determining that there is more than one type of sample auxiliary information in the at least one track and, as a consequence, includes identification of at least two of the first, second, or third sample auxiliary information in the at least one sample to group box.

31. The apparatus of claim 2, wherein the apparatus is further caused to perform: parsing at least one sample to group box from a file; parsing that the at least one sample to group box relates to first, second or third sample auxiliary information; and parsing, from the at least one sample to group box, a mapping of one or more sample group description entries to the first, second or third sample auxiliary information.

32. An apparatus comprising at least one processor; and at least one non-transitory memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: receiving a first bitstream and a second bitstream; producing or generating the following: an encapsulated file comprising at least one track comprising one or more samples, wherein the first bitstream is encapsulated in the one or more samples, and wherein the second bitstream is encapsulated in a first sample auxiliary information; receiving or determining one or more sample group description entries and a mapping of the one or more sample group description entries to the first sample auxiliary information; and writing at least one sample to group box for indicating that the at least one sample to group box relates to the first sample auxiliary information and for indicating the mapping of the one or more sample group description entries to the first sample auxiliary information.

33. The apparatus of claim 32, wherein the apparatus is further caused to perform: determining that there is one type of sample auxiliary information in the at least one track and, as a consequence, excludes identification of the first sample auxiliary information from the at least one sample to group box.

34. The apparatus of claim 32, wherein the apparatus is further caused to perform: determining that there is more than one type of sample auxiliary information in the at least one track and, as a consequence, includes identification of the first sample auxiliary information in the at least one sample to group box.

35. An apparatus comprising at least one processor; and at least one non -transitory memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: parsing at least one sample to group box from a file; parsing that the at least one sample to group box relates to first sample auxiliary information; and parsing, from the at least one sample to group box, a mapping of one or more sample group description entries to the first sample auxiliary information.

36. A method comprising: receiving a first bitstream and a second bitstream; encrypting the first bitstream with a first encryption method to generate a first encrypted bitstream; encrypting the second bitstream with a second encryption method to generate a second encrypted bitstream; taking following as an input: the first encrypted bitstream; the second encrypted bitstream; encryption related data for the first encrypted bitstream; and encryption related data for the second encrypted bitstream; producing or generating the following: an encapsulated file comprising at least one track comprising one or more samples, wherein the first encrypted bitstream is encapsulated in the one or more samples, and wherein the second encrypted bitstream is encapsulated in a first sample auxiliary information; including following information in the encapsulated file: a second sample auxiliary information; anda third sample auxiliary information; wherein the second auxiliary information comprises encryption related data for the first encrypted bitstream, and wherein the third sample auxiliary information comprises encryption related data for the second encrypted bitstream.

37. A method comprising: receiving an encapsulated file comprising at least one track comprising one or more samples, wherein a first encrypted bitstream is encapsulated in the one or more samples, and wherein the first encrypted bitstream is encrypted with a first encryption method, and wherein a second encrypted bitstream is encapsulated in one or more first sample auxiliary information, and wherein the second encrypted bitstream is encrypted with a second encryption method; including following information in the encapsulated file: a second sample auxiliary information; and a third sample auxiliary information; wherein the second auxiliary information comprises encryption related data for the first encrypted bitstream, and wherein the third sample auxiliary information comprises encryption related data for the second encrypted bitstream; parsing the encapsulated file to generate or produce following: the first encrypted bitstream; the second encrypted bitstream; encryption related data for the first encrypted bitstream; and encryption related data for the second encrypted bitstream; decrypting the first encrypted bitstream by using the encryption related data for the first encrypted bitstream to produce a first unencrypted bitstream; and decrypting the second encrypted bitstream by using the encryption related data for the second encrypted bitstream to produce a second unencrypted bitstream.

38. The method of claim 36 or 37, wherein the method is further caused to perform: applying one or more of following conditions: the first and the second bitstream are encrypted, and the first, second, and third sample auxiliary information streams are unencrypted; or the first and the second bitstream and first, second, and third sample auxiliary information streams are encrypted; wherein when the first and the second bitstreams in the at least one track is encrypted, a four-character-code (4CC) of a sample entry of the at least one track is transformed based on a media-type encapsulated in the at least one track.

39. The method of claim 38, wherein when one or more of the first, second, or third sample auxiliary information streams in the at least one track are encrypted, file-format transformation is used for protected sample auxiliary information (SAI) streams.

40. The method of any of the claims 38 or 39, wherein the transformation functions by encapsulating original media declarations of the one or more of the first, second, or third sample auxiliary information, or by changing a four character code (4CC) of a box indicating presence of an SAI in the at least one track, such that protection-unaware readers reads or analyzes data in the SAI as a new data format.

41. The method of any of the claims 38 to 40 further comprising defining a transformed sample auxiliary information entry box or a protected sample auxiliary information entry box to indicate that the one or more of the of the first, second, or third sample auxiliary information streams in the at least one track is encrypted.

42. The method of any of the claims 38 to 41, wherein one or more protected sample auxiliary information entries are comprised in the one or more samples of the at least one track comprised in a sample description, or wherein the one or more protected sample auxiliary information entries are present in one of: a movie box, a movie fragment box, a track box, or a track fragment box.

43. The method of claim 42, wherein when more than one protected sample auxiliary information entries are present then each protected sample auxiliary information entry corresponds to a specific sample auxiliary information in the at least one track and are not alternatives of each other for selection.

44. The method of any of the claims 38 to 43, wherein when a format of the first, second, or third sample auxiliary information varies with a media-type, the method is further comprises using a different encapsulating four character-code for each media type.

45. The method of any of the claims 43 or 44, wherein the protected sample auxiliary information entries are defined by using protected sample auxiliary information entry codes.

46. The method of any of the claims 42 to 45 further comprising adding a protection scheme information box or a SAI protection scheme information box to each of the one or more protected sample auxiliary information entries.

47. The method of any of the claims 36 to 46, wherein an original format of the first, second, and the third sample auxiliary information is stored within a protection scheme information box or a SAI protection scheme information box comprised in an original format box.

48. The method of any of the claims 36 to 46, wherein an original format of the first, second, and the third sample auxiliary information is stored within a protection scheme information box or a SAI protection scheme information box comprised in an SAI original format box.

49. The method of any of the claims 36 to 46 further comprising allowing the protection scheme information box and / or the SAI protection scheme information boxto be present in the protected sample auxiliary information entry.

50. The method of claim 49, wherein when the protection scheme information box and / or the SAI protection scheme information boxis present in the protected sample auxiliary information entry, and wherein the protected sample auxiliary information entry comprises information required both to understand the encryption transform applied and parameters of the transformation.

51. The method of any of claims 49 or 50, wherein the protection scheme information box and / or the SAI protection scheme information box documents original format of the sample auxiliary information.

52. The method of any of the claims 42 to 51 further comprising using at least one of the following signaling to identify the protection applied on the first, second, and third sample auxiliary information:MPEG-4 systems with IPMP, when IPMP descriptors in MPEG-4 systems streams are used; scheme signaling using a scheme type box and a scheme information box, when the scheme type box and the scheme information box are used; orscheme signaling using SAI scheme type box and a SAI scheme information box when the signaling using SAI scheme type box and the SAI scheme information box.

53. The method of claim 52, wherein at least one protection scheme information box and / or SAI protection scheme information box is comprised in the protected sample auxiliary information entry.

54. The method of claim 53, wherein when more than one protection scheme information box and / or SAI protection scheme information box occur in a protected sample auxiliary information entry, the more than one protection scheme information box and / or SAI protection scheme information box are equivalent, alternative, descriptions of the same protection.

55. The method of claim 47, wherein when an original format box is used for storing an original format of the first, second, or third sample auxiliary information, a data format parameter present in the original format box is extended to indicate a four-character-code of an original un-transformed format of the first, second, or third sample auxiliary information.

56. The method of claim 48, wherein when the SAI original format box is used for storing an original format of the first, second, or third sample auxiliary information, the SAI original format box comprises a data format parameter to indicate a four-character-code of an original un-transformed format of the first, second, or third sample auxiliary information.

57. The method of claim 56, wherein the SAI original format box comprises one or more of following parameters: an original scheme type for indicating a corresponding scheme type of the original un-transformed format of the first, second, or third sample auxiliary information and an original scheme version for indicating a corresponding scheme version of the original un-transformed format of the first, second, or third sample auxiliary information.

58. The method of any of claims 49 to 51, wherein a scheme type box is comprised in a SAI protection scheme information box and / or a protection scheme information box for identifying a protection or a restriction scheme used for encrypting the first, second, or third sample auxiliary information.

59. The method of claim 58 further comprising: defining a SAI scheme type box, wherein the SAI scheme type box is comprised a SAI protection scheme information box and / or a protection scheme information box for identifying a protection or a restriction scheme used for encrypting the first, second, or third sample auxiliary information.

60. The method of claim 58, wherein a scheme information box is comprised in the SAI protection scheme information box and / or a protection scheme information box is a container box that is interpreted by the scheme being used, and wherein information an encryption or restriction system needs for protecting the first, second, or third sample auxiliary information is stored in the scheme information box.

61. The method of claim 58 further comprising defining a SAI scheme information box, wherein the SAI scheme information box is comprised in the SAI protection scheme information box and / or a protection scheme information box is a container box that is interpreted by a scheme being used, and wherein information an encryption or restriction system needs for protecting the first, second, or third sample auxiliary information is stored in the scheme information box.

62. The method of any of claims 58 to 59, wherein the scheme type box and / or the SAI scheme type box conform to following: a scheme type parameter in the scheme type box and / or the SAI scheme type box is set to a value equal to a four-character code defined in ISO / IEC 23001-7 for different protection schemes; a scheme version parameter in the scheme type box and / or the SAI scheme type box is set to a predefined value; the protection scheme information box and / or the SAI protection scheme information box used for signaling the protection related information for the first, second, or third sample auxiliary information also comprises a scheme information box and / or SAI scheme information box; the scheme information box and / or SAI scheme information box used for signaling the protection related information for the first, second, or third sample auxiliary information comprises a track information box extended to support signaling of the first, second, or third sample auxiliary information and describing the default encryption parameters for the first, second, or third sample auxiliary information; the scheme information box and / or SAI scheme information box used for signaling the protection related information for the sample auxiliary information comprises a SAI encryption box or a track SAI encryption box describing default encryption parameters for the first, second, or third sample auxiliary information;a track encryption box which defines a default value for each sample in the at least one track is modified or extended to indicate the default values associated with a specific SAI that is protected; or the track encryption box comprises default values for a protected flag, a vector size for samples in a sample group for the at least one track, and an identifier used for samples in the sample group.

63. The method of claim 36 further comprising: receiving or determining one or more sample group description entries and a mapping of the one or more sample group description entries to the first, second, and third sample auxiliary information; and writing at least one sample to group box for indicating that the at least one sample to group box relates to the first, second or third sample auxiliary information and for indicating the mapping of the one or more sample group description entries to the first, second, or third sample auxiliary information.

64. The method of claim 63 further comprising determining that there is one type of sample auxiliary information in the at least one track and, as a consequence, excludes identification of the first, second or third sample auxiliary information from the at least one sample to group box.

65. The method of claim 63 further comprising determining that there is more than one type of sample auxiliary information in the at least one track and, as a consequence, includes identification of at least two of the first, second, or third sample auxiliary information in the at least one sample to group box.

66. The method of claim 37 further comprising: parsing at least one sample to group box from a file; parsing that the at least one sample to group box relates to first, second or third sample auxiliary information; and parsing, from the at least one sample to group box, a mapping of one or more sample group description entries to the first, second or third sample auxiliary information.

67. A method comprising: receiving a first bitstream and a second bitstream; producing or generating the following:an encapsulated file comprising at least one track comprising one or more samples, wherein the first bitstream is encapsulated in the one or more samples, and wherein the second bitstream is encapsulated in a first sample auxiliary information; receiving or determining one or more sample group description entries and a mapping of the one or more sample group description entries to the first sample auxiliary information; and writing at least one sample to group box for indicating that the at least one sample to group box relates to the first sample auxiliary information and for indicating the mapping of the one or more sample group description entries to the first sample auxiliary information.

68. The method of claim 67 further comprising determining that there is one type of sample auxiliary information in the at least one track and, as a consequence, excludes identification of the first sample auxiliary information from the at least one sample to group box.

69. The method of claim 67 further comprising determining that there is more than one type of sample auxiliary information in the at least one track and, as a consequence, includes identification of the first sample auxiliary information in the at least one sample to group box.

70. A method comprising when: parsing at least one sample to group box from a file; parsing that the at least one sample to group box relates to first sample auxiliary information; and parsing, from the at least one sample to group box, a mapping of one or more sample group description entries to the first sample auxiliary information.

71. An apparatus comprising: means for receiving a first bitstream and a second bitstream; means for encrypting the first bitstream with a first encryption method to generate a first encrypted bitstream; means for encrypting the second bitstream with a second encryption method to generate a second encrypted bitstream; means for taking following as an input: the first encrypted bitstream; the second encrypted bitstream; encryption related data for the first encrypted bitstream; and encryption related data for the second encrypted bitstream; means for producing or generating the following:an encapsulated file comprising at least one track comprising one or more samples, wherein the first encrypted bitstream is encapsulated in the one or more samples, and wherein the second encrypted bitstream is encapsulated in a first sample auxiliary information; including following information in the encapsulated file: a second sample auxiliary information; and a third sample auxiliary information; wherein the second auxiliary information comprises encryption related data for the first encrypted bitstream, and wherein the third sample auxiliary information comprises encryption related data for the second encrypted bitstream.

72. An apparatus comprising: means for receiving an encapsulated file comprising at least one track comprising one or more samples, wherein a first encrypted bitstream is encapsulated in the one or more samples, and wherein the first encrypted bitstream is encrypted with a first encryption method, and wherein a second encrypted bitstream is encapsulated in one or more first sample auxiliary information, and wherein the second encrypted bitstream is encrypted with a second encryption method; means for including following information in the encapsulated file: a second sample auxiliary information; and a third sample auxiliary information; wherein the second auxiliary information comprises encryption related data for the first encrypted bitstream, and wherein the third sample auxiliary information comprises encryption related data for the second encrypted bitstream; means for parsing the encapsulated file to generate or produce following: the first encrypted bitstream; the second encrypted bitstream; encryption related data for the first encrypted bitstream; and encryption related data for the second encrypted bitstream; means for decrypting the first encrypted bitstream by using the encryption related data for the first encrypted bitstream to produce a first unencrypted bitstream; and means for decrypting the second encrypted bitstream by using the encryption related data for the second encrypted bitstream to produce a second unencrypted bitstream.

73. The apparatus of any of claims 71 or 72, wherein the apparatus comprises means for performing methods as claimed in one or more of the claims 38 to 66.

74. An apparatus comprising: means for receiving a first bitstream and a second bitstream; means for producing or generating the following: an encapsulated file comprising at least one track comprising one or more samples, wherein the first bitstream is encapsulated in the one or more samples, and wherein the second bitstream is encapsulated in a first sample auxiliary information; means for receiving or determining one or more sample group description entries and a mapping of the one or more sample group description entries to the first sample auxiliary information; and means for writing at least one sample to group box for indicating that the at least one sample to group box relates to the first sample auxiliary information and for indicating the mapping of the one or more sample group description entries to the first sample auxiliary information.

75. The apparatus of claim 74, wherein the apparatus further comprises means for performing method as claimed in any of the claims 68 or 69.

76. An apparatus comprising: means for parsing at least one sample to group box from a file; means for parsing that the at least one sample to group box relates to first sample auxiliary information; and means for parsing, from the at least one sample to group box, a mapping of one or more sample group description entries to the first sample auxiliary information.

77. A computer readable medium comprising program instructions which, when executed by an apparatus, cause the apparatus to perform at least the following: receiving a first bitstream and a second bitstream; encrypting the first bitstream with a first encryption method to generate a first encrypted bitstream; encrypting the second bitstream with a second encryption method to generate a second encrypted bitstream; taking following as an input: the first encrypted bitstream; the second encrypted bitstream; encryption related data for the first encrypted bitstream; andencryption related data for the second encrypted bitstream; producing or generating the following: an encapsulated file comprising at least one track comprising one or more samples, wherein the first encrypted bitstream is encapsulated in the one or more samples, and wherein the second encrypted bitstream is encapsulated in a first sample auxiliary information; including following information in the encapsulated file: a second sample auxiliary information; and a third sample auxiliary information; wherein the second auxiliary information comprises encryption related data for the first encrypted bitstream, and wherein the third sample auxiliary information comprises encryption related data for the second encrypted bitstream.

78. A computer readable medium comprising program instructions which, when executed by an apparatus, cause the apparatus to perform at least the following: receiving an encapsulated file comprising at least one track comprising one or more samples, wherein a first encrypted bitstream is encapsulated in the one or more samples, and wherein the first encrypted bitstream is encrypted with a first encryption method, and wherein a second encrypted bitstream is encapsulated in one or more first sample auxiliary information, and wherein the second encrypted bitstream is encrypted with a second encryption method; including following information in the encapsulated file: a second sample auxiliary information; and a third sample auxiliary information; wherein the second auxiliary information comprises encryption related data for the first encrypted bitstream, and wherein the third sample auxiliary information comprises encryption related data for the second encrypted bitstream; parsing the encapsulated file to generate or produce following: the first encrypted bitstream; the second encrypted bitstream; encryption related data for the first encrypted bitstream; and encryption related data for the second encrypted bitstream; decrypting the first encrypted bitstream by using the encryption related data for the first encrypted bitstream to produce a first unencrypted bitstream; and decrypting the second encrypted bitstream by using the encryption related data for the second encrypted bitstream to produce a second unencrypted bitstream.

79. The computer readable medium of any of claims 77 or 78, wherein the computer readable medium comprises a non-transitory computer readable medium.

80. The computer readable medium of any of claims 77 to 79, wherein the computer readable medium causes the apparatus to further perform the methods as claimed in one or more of the claims 38 to 66.

81. A computer readable medium comprising program instructions which, when executed by an apparatus, cause the apparatus to perform at least the following: receiving a first bitstream and a second bitstream; producing or generating the following: an encapsulated file comprising at least one track comprising one or more samples, wherein the first bitstream is encapsulated in the one or more samples, and wherein the second bitstream is encapsulated in a first sample auxiliary information; receiving or determining one or more sample group description entries and a mapping of the one or more sample group description entries to the first sample auxiliary information; and writing at least one sample to group box for indicating that the at least one sample to group box relates to the first sample auxiliary information and for indicating the mapping of the one or more sample group description entries to the first sample auxiliary information.

82. The computer readable medium of claim 81, wherein the computer readable medium comprises a non-transitory computer readable medium.

83. The computer readable medium of any of claims 81 or 82, wherein the computer readable medium causes the apparatus to further perform the methods as claimed in any of the claims 68 to 69.

84. A computer readable medium comprising program instructions which, when executed by an apparatus, cause the apparatus to perform at least the following: parsing at least one sample to group box from a file; parsing that the at least one sample to group box relates to first sample auxiliary information; and parsing, from the at least one sample to group box, a mapping of one or more sample group description entries to the first sample auxiliary information.

Citation Information

Patent Citations

  • Technique for Handling Media Content to be Accessible via Multiple Media Tracks

    US20110261957A1

  • Apparatus, a method and a computer program for omnidirectional video

    US20230059516A1