Data processing method and apparatus, device, and computer-readable storage medium
By performing two-way authentication between the data acquisition device and the second device, and encrypting or signing the multimedia data based on identity information, the problem of insufficient multimedia data protection in the prior art is solved, and high-security data access and protection are achieved.
Patent Information
- Application Number
- PCT/CN2024/107184
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-15
- Filing Date
- 2024-07-24
- Publication Date
- 2025-05-22
AI Technical Summary
The prior art is difficult to effectively protect collected multimedia data, especially sensitive data, to prevent unauthorized access and leakage.
By performing two-way authentication between the data acquisition device and the second device, encrypting or signing the multimedia data based on the identity information, data processing results are generated to ensure that only authorized devices can access the encrypted multimedia data.
Improves the security of multimedia data, ensuring that even if the data is sensitive, it can be effectively protected and prevents unauthorized access and leakage.
Smart Images

Figure CN2024107184_22052025_PF_FP_ABST
Abstract
Description
Data processing method, device, equipment and computer-readable storage medium
[0001] This application claims priority to Chinese patent application No. 202311532319.4 filed on November 15, 2023, entitled “Data processing method, apparatus, device and computer-readable storage medium”, the entire contents of which are incorporated herein by reference. Technical Field
[0002] The present application relates to the field of computer technology, and in particular to data processing methods, devices, equipment, and computer-readable storage media. Background Art
[0003] With the advancement of computer technology, more and more types of data are appearing on networks, including some sensitive data that requires protection. For example, video data captured by cameras contains a large amount of information about the captured subjects, including but not limited to their portraits, behavioral habits, and private environment information. Therefore, this data needs to be processed to improve its security.
[0004] Summary of the Invention
[0005] This application provides a data processing method, apparatus, device, and computer-readable storage medium for processing data to improve data security. The technical solution is as follows:
[0006] In a first aspect, a data processing method is provided, which is applied to a data acquisition device, and the method includes: obtaining multimedia data collected by the data acquisition device; encrypting or signing the multimedia data based on identity information to obtain a data processing result corresponding to the multimedia data, wherein the identity information is determined based on information used for authentication between a second device corresponding to a target object and the data acquisition device, the target object is an object using the data acquisition device, and the data processing result is used for authorized devices to access multimedia data.
[0007] After acquiring multimedia data, it is processed based on the identity information. Since the identity information is used for authentication between the second device and the data acquisition device, security is highly reliable through bidirectional authentication between the data acquisition device and the second device. The data processing results obtained based on this highly reliable identity information are highly secure. Even sensitive multimedia data can be well protected.
[0008] In one possible implementation, the identity information includes first identity information for identifying the data acquisition device and second identity information for identifying the second device. Before encrypting or signing multimedia data based on the identity information and obtaining the data processing result corresponding to the multimedia data, the method further includes: encrypting the first identity information to obtain a first secure ciphertext, and sending the first secure ciphertext to the second device; receiving a second secure ciphertext returned by the second device after verifying transmission security based on the first secure ciphertext, the second secure ciphertext being encrypted based on the second identity information; decrypting the second secure ciphertext, and verifying the security of the transmission channel between the data acquisition device and the second device based on the decryption result. The transmission channel between the data acquisition device and the second device is authenticated by the identity information, so that the highly secure transmission channel is utilized to interact with the second device, and the process of transmitting the data processing result is highly secure.
[0009] In one possible implementation, multimedia data is encrypted or signed based on identity information to obtain a data processing result corresponding to the multimedia data, including: obtaining a first key, the first key being negotiated with a second device based on the identity information; encrypting the multimedia data using the first key to obtain ciphertext data, and using the ciphertext data as the data processing result. Because the identity information is used for authentication between the second device and the data acquisition device, security is highly reliable due to bidirectional authentication between the data acquisition device and the second device, and encryption using the first key obtained based on the identity information provides high security.
[0010] In one possible implementation, obtaining the first key includes: calculating a second public key and a second private key of the data acquisition device based on the identity information; and obtaining the first key through negotiation based on the second public key, the second private key, and the identity information. An asymmetric public-private key pair, namely, the second public key and the second private key, is first obtained through negotiation, and the first key is then obtained through negotiation based on the second public key and the second private key. This allows for more efficient symmetric encryption using the first key, resulting in improved performance in encrypting multimedia data.
[0011] In one possible implementation, multimedia data is encrypted or signed based on identity information to obtain a data processing result corresponding to the multimedia data, including: obtaining a second key of a data acquisition device, the second key not being authenticated by a second device corresponding to the target object; encrypting the multimedia data according to the second key to obtain ciphertext data corresponding to the multimedia data; signing the ciphertext data according to the identity information to obtain signature data corresponding to the ciphertext data, obtaining a data processing result based on the signature data and the ciphertext data, and the signature data is used to verify whether the ciphertext data is abnormal. Even if identity information is not used in the process of encrypting multimedia data, the ciphertext data can be signed by the identity information to achieve security verification of the ciphertext data based on the signature data, with high versatility. The process of processing multimedia data based on identity information is not limited, and the first key can be generated based on the identity information, and the signature can also be performed based on the identity information, with high flexibility.
[0012] In one possible implementation, ciphertext data is signed based on identity information to obtain signature data corresponding to the ciphertext data, and a data processing result is obtained based on the signature data and the ciphertext data. This includes: obtaining a third public key of the second device, encrypting the second key based on the third public key to obtain a ciphertext parameter corresponding to the second key, the ciphertext parameter being used to obtain the second key required for decrypting the ciphertext data; signing the ciphertext data and the ciphertext parameter based on the identity information to obtain signature data corresponding to the ciphertext data and the ciphertext parameter, and obtaining a data processing result based on the ciphertext data, the ciphertext parameter, and the signature data. The data processing result obtained by the signature includes both the ciphertext data corresponding to the multimedia data and the ciphertext parameter corresponding to the second key. Subsequently, when a device requests to obtain multimedia data, there is no need to send the ciphertext data and ciphertext parameter multiple times separately. Data provision can be achieved by transmitting a single data processing result, resulting in high data processing efficiency.
[0013] In one possible implementation, after obtaining the data processing result corresponding to the multimedia data, the method further includes: sending the data processing result to a second device corresponding to the target object, where the data processing result is used by the second device to obtain the multimedia data. By sending the data processing result to the second device, the target object can access the multimedia data at any time through the second device, thereby facilitating data access for the target object and improving the interactive experience.
[0014] In one possible implementation, a data acquisition device is connected to a second device corresponding to a target object via a third device; the data acquisition device authenticates the second device via the third device. The interaction between the data acquisition device and the second device can be direct or indirect via the third device, providing high flexibility.
[0015] In a second aspect, another data processing method is provided, which is applied to a first device, and the method includes: sending an access request for multimedia data; when access rights to the multimedia data are obtained based on the access request, obtaining ciphertext data corresponding to the multimedia data, the ciphertext data is obtained by encrypting or signing the multimedia data based on identity information, the identity information is determined based on information used for authentication between a second device corresponding to a target object and a data acquisition device for the multimedia data, the target object being an object using the data acquisition device; decrypting the ciphertext data to obtain the multimedia data.
[0016] When a third-party device independent of the data acquisition device and the second device needs to obtain multimedia data, the device needs to be verified and authorized. Only after the verification is passed can the device obtain the multimedia data, so as to realize data sharing while protecting the personal information of the target object, further explore the data value of the multimedia data, and realize efficient use of the data.
[0017] In one possible implementation, obtaining ciphertext data corresponding to multimedia data includes: receiving ciphertext data returned based on an access request. If verification based on the access request is successful, the ciphertext data can be directly obtained, which has low complexity and high efficiency.
[0018] In one possible implementation, obtaining ciphertext data corresponding to multimedia data includes: receiving a first authorization flag returned based on an access request, the first authorization flag indicating permission to obtain the multimedia data; and requesting to obtain the ciphertext data based on the first authorization flag. Because the first authorization flag indicates that the second device has permitted the first device to obtain the multimedia data, the ciphertext data can be obtained by requesting to obtain the ciphertext data using the first authorization flag. During the process of obtaining the ciphertext data, device verification is performed using the first authorization flag, providing high security. Even if the ciphertext data is provided by a device different from the second device, the ciphertext data can still be obtained using the first authorization flag.
[0019] Furthermore, the present application does not limit the interactive method of obtaining ciphertext data. Ciphertext data can be directly received or requested through the first authorization mark, which is highly flexible.
[0020] In one possible implementation, before decrypting the ciphertext data, the method further includes: receiving re-encrypted data returned based on the access request, the re-encrypted data being obtained by encrypting a reference ciphertext based on a second authorization flag, the second authorization flag being generated based on a first public key, the first public key being a public key owned by the first device requesting the multimedia data, and the reference ciphertext being a ciphertext obtained by encrypting the ciphertext data using the key; and decrypting the ciphertext data to obtain the multimedia data, including: obtaining the key for the ciphertext data based on a decryption result of the re-encrypted data, and decrypting the ciphertext data based on the key to obtain the multimedia data. Because the second authorization flag is generated based on the first public key, the re-encrypted data can be decrypted using the first private key owned by the first device, eliminating the need to re-acquire the key used to decrypt the re-encrypted data. This results in high decryption efficiency, a simple key acquisition method, and low operational complexity in the decryption process.
[0021] In one possible implementation, before decrypting the ciphertext data, the process further includes: sending a first public key; receiving a first ciphertext obtained by encrypting a key using the first public key, where the key is the key used to encrypt the multimedia data; and decrypting the ciphertext data to obtain the multimedia data, including: decrypting the first ciphertext using a first private key corresponding to the first public key to obtain the key; and decrypting the ciphertext data using the key to obtain the multimedia data. Even if the ciphertext data and the key are not transmitted synchronously, a request can be made to obtain the key again, and the key can be encrypted using the first public key to prevent the key from being intercepted and tampered with during transmission, thereby enhancing the security of key transmission.
[0022] In one possible implementation, an access request is used to obtain device information of a first device requesting multimedia data. The device information of the first device is used to determine whether to grant the first device access to the multimedia data based on at least one piece of device information. The at least one piece of device information is information about at least one device that has signed a data agreement, and the data agreement is used to obtain access rights to the multimedia data. By searching within the at least one piece of device information, secure verification of the first device can be achieved, resulting in a simple and efficient verification process.
[0023] In one possible implementation, sending a request to access multimedia data includes sending the access request to a third device, the third device being connected to a second device corresponding to a target object, and the third device being configured to send the access request to the second device. The interaction between the second device and the first device can be direct or indirect via the third device, and the interaction process is flexible and versatile, with wide applicability.
[0024] In a possible implementation, the identity information is used by the data acquisition device and the second device to negotiate to obtain a first key, and the ciphertext data is obtained by encrypting the multimedia data according to the first key.
[0025] In one possible implementation, identity information is used to sign the ciphertext data corresponding to the multimedia data, and the signature data obtained is used by the second device to verify whether the ciphertext data sent by the received data acquisition device is abnormal, and the second device is used to provide the ciphertext data to the first device.
[0026] In a possible implementation, the identity information includes first identity information for identifying the data acquisition device and second identity information for identifying the second device.
[0027] In a third aspect, a data processing device is provided, which is applied to a data acquisition device, and the device includes: an acquisition module, used to acquire multimedia data collected by the data acquisition device; a processing module, used to encrypt or sign the multimedia data based on identity information to obtain a data processing result corresponding to the multimedia data, the identity information is determined based on the information used for authentication between a second device corresponding to the target object and the data acquisition device, the target object is an object using the data acquisition device, and the data processing result is used for authorized devices to access multimedia data.
[0028] In one possible implementation, the identity information includes first identity information for identifying the data acquisition device and second identity information for identifying the second device. The processing module is further used to encrypt the first identity information to obtain a first security ciphertext and send the first security ciphertext to the second device; when verifying the transmission security based on the first security ciphertext, receive the second security ciphertext returned by the second device, the second security ciphertext being encrypted based on the second identity information; decrypt the second security ciphertext, and verify whether the transmission channel between the data acquisition device and the second device is secure based on the decryption result.
[0029] In one possible implementation, the processing module is configured to obtain a first key, where the first key is obtained through negotiation with the second device based on identity information; encrypt multimedia data according to the first key to obtain ciphertext data, and use the ciphertext data as a data processing result.
[0030] In a possible implementation, the processing module is configured to calculate a second public key and a second private key of the data acquisition device based on the identity information; and obtain the first key through negotiation according to the second public key, the second private key and the identity information.
[0031] In one possible implementation, the processing module is used to obtain a second key of the data acquisition device, where the second key has not been authenticated by a second device corresponding to the target object; encrypt the multimedia data according to the second key to obtain ciphertext data corresponding to the multimedia data; sign the ciphertext data according to the identity information to obtain signature data corresponding to the ciphertext data; obtain a data processing result based on the signature data and the ciphertext data, and the signature data is used to verify whether the ciphertext data is abnormal.
[0032] In one possible implementation, the processing module is used to obtain a third public key of the second device, encrypt the second key based on the third public key, and obtain a ciphertext parameter corresponding to the second key, where the ciphertext parameter is used to obtain the second key required to decrypt the ciphertext data; sign the ciphertext data and the ciphertext parameter based on the identity information to obtain signature data corresponding to the ciphertext data and the ciphertext parameter, and obtain a data processing result based on the ciphertext data, the ciphertext parameter, and the signature data.
[0033] In a possible implementation, the apparatus further includes: a sending module, configured to send a data processing result to a second device corresponding to the target object, where the data processing result is used by the second device to obtain multimedia data.
[0034] In a possible implementation, the data acquisition device is connected to a second device corresponding to the target object via a third device; and the data acquisition device performs authentication with the second device via the third device.
[0035] In a fourth aspect, another data processing device is provided, which is applied to a first device and includes: a sending module for sending an access request for multimedia data; an acquisition module for obtaining ciphertext data corresponding to the multimedia data when access rights to the multimedia data are obtained based on the access request, the ciphertext data being obtained by encrypting or signing the multimedia data based on identity information, the identity information being determined based on information used for authentication between a second device corresponding to a target object and a data acquisition device for the multimedia data, the target object being an object using the data acquisition device; a decryption module for decrypting the ciphertext data to obtain the multimedia data.
[0036] In a possible implementation, the acquisition module is configured to receive ciphertext data returned based on the access request.
[0037] In a possible implementation, the acquisition module is configured to receive a first authorization flag returned based on an access request, where the first authorization flag indicates permission to acquire multimedia data; and request to acquire ciphertext data according to the first authorization flag.
[0038] In one possible implementation, the acquisition module is also used to receive re-encrypted data returned based on the access request, the re-encrypted data is obtained by encrypting the reference ciphertext according to the second authorization flag, the second authorization flag is generated according to the first public key, the first public key is the public key owned by the first device requesting multimedia data, and the reference ciphertext is the ciphertext obtained by encrypting the key of the ciphertext data; the decryption module is used to obtain the key of the ciphertext data according to the decryption result of the re-encrypted data, and decrypt the ciphertext data according to the key to obtain the multimedia data.
[0039] In one possible implementation, the sending module is also used to send the first public key; the acquisition module is also used to receive a first ciphertext obtained by encrypting a key according to the first public key, where the key is the key used to encrypt multimedia data; the decryption module is used to decrypt the first ciphertext according to the first private key corresponding to the first public key to obtain the key; and the ciphertext data is decrypted according to the key to obtain multimedia data.
[0040] In one possible implementation, the access request is used to obtain device information of the first device requesting multimedia data, and the device information of the first device is used to determine whether to grant the first device permission to obtain multimedia data based on at least one device information, and the at least one device information is information of at least one device that has signed a data agreement, and the data agreement is used to obtain access rights to multimedia data.
[0041] In a possible implementation, the sending module is configured to send an access request to a third device, the third device is connected to a second device corresponding to the target object, and the third device is configured to send the access request to the second device.
[0042] In a possible implementation, the identity information is used by the data acquisition device and the second device to negotiate to obtain a first key, and the ciphertext data is obtained by encrypting the multimedia data according to the first key.
[0043] In one possible implementation, identity information is used to sign the ciphertext data corresponding to the multimedia data, and the signature data obtained is used by the second device to verify whether the ciphertext data sent by the received data acquisition device is abnormal, and the second device is used to provide the ciphertext data to the first device.
[0044] In a possible implementation, the identity information includes first identity information for identifying the data acquisition device and second identity information for identifying the second device.
[0045] In a fifth aspect, a data processing device is provided, which includes: a transceiver module for performing operations related to reception and / or transmission in the method of the first aspect or any possible implementation method of the first aspect, and a processing module for performing operations other than the operations related to reception and / or transmission in the method of the first aspect or any possible implementation method of the first aspect; or, a transceiver module for performing operations related to reception and / or transmission in the method of the second aspect or any possible implementation method of the second aspect, and a processing module for performing operations other than the operations related to reception and / or transmission in the method of the second aspect or any possible implementation method of the second aspect.
[0046] In a sixth aspect, a data processing device is provided, which includes a processor, and the processor is used to load and execute at least one instruction so that the data processing device executes the method in the first aspect or any possible implementation of the first aspect, or executes the method in the second aspect or any possible implementation of the second aspect.
[0047] In a possible implementation, the device includes a memory coupled to a processor, and the memory stores at least one instruction.
[0048] In the seventh aspect, a computer-readable storage medium is provided, in which at least one instruction is stored. The instruction is loaded and executed by a processor to implement the data processing method in the first aspect or any possible implementation of the first aspect, or to implement the data processing method in the second aspect or any possible implementation of the second aspect.
[0049] In the eighth aspect, a computer program (product) is provided, which includes a computer program / instructions, and the computer program / instructions are executed by a processor to enable a computer to implement the data processing method in the first aspect or any possible implementation of the first aspect, or to implement the data processing method in the second aspect or any possible implementation of the second aspect.
[0050] In a ninth aspect, a communication device is provided, comprising: a transceiver, a memory, and a processor. The transceiver, the memory, and the processor communicate with each other via an internal connection path; the memory is configured to store instructions; and the processor is configured to execute the instructions stored in the memory to control the transceiver to receive signals and to control the transceiver to transmit signals. When the processor executes the instructions stored in the memory, the processor executes the method according to the first aspect or any possible implementation of the first aspect, or executes the method according to the second aspect or any possible implementation of the second aspect.
[0051] Optionally, there are one or more processors and one or more memories.
[0052] Optionally, the memory may be integrated with the processor, or the memory may be provided separately from the processor.
[0053] In the specific implementation process, the memory can be a non-transitory memory, such as a read-only memory (ROM), which can be integrated on the same chip as the processor or be set on different chips. This application does not limit the type of memory and the setting method of the memory and the processor.
[0054] In a tenth aspect, a chip is provided, comprising a processor for calling and executing program instructions or codes stored in a memory, so that a communication device equipped with the chip executes the methods in the above aspects.
[0055] In the eleventh aspect, another chip is provided, comprising: an input interface, an output interface, a processor and a memory, wherein the input interface, the output interface, the processor and the memory are connected through an internal connection path, and the processor is used to execute the code in the memory. When the code is executed, the processor is used to execute the methods in the above aspects.
[0056] It should be understood that the beneficial effects achieved by the technical solutions of the third to eleventh aspects of this application and the corresponding possible implementation methods can be referred to the above-mentioned technical effects of the first aspect and its corresponding possible implementation methods or the second aspect and its corresponding possible implementation methods, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] FIG1 is a schematic diagram of an implementation environment provided by an embodiment of the present application;
[0058] FIG2 is a schematic diagram of another implementation environment provided by an embodiment of the present application;
[0059] FIG3 is a flow chart of a data processing method provided in an embodiment of the present application;
[0060] FIG4 is a schematic diagram of interaction between a second device and a data acquisition device provided in an embodiment of the present application;
[0061] FIG5 is a flow chart of another data processing method provided in an embodiment of the present application;
[0062] FIG6 is a schematic diagram of a device interaction provided in an embodiment of the present application;
[0063] FIG7 is another schematic diagram of device interaction provided in an embodiment of the present application;
[0064] FIG8 is a schematic structural diagram of a data processing device provided in an embodiment of the present application;
[0065] FIG9 is a schematic structural diagram of another data processing device provided in an embodiment of the present application;
[0066] FIG10 is a schematic diagram of the structure of a network device provided in an embodiment of the present application;
[0067] FIG11 is a schematic diagram of the structure of another network device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0068] The terms used in the embodiments of this application are only used to explain the specific embodiments of this application and are not intended to limit this application. To make the purpose, technical solutions and advantages of this application clearer, the embodiments of this application will be further described in detail below with reference to the accompanying drawings.
[0069] With the development of computer technology, the data in the network has shown explosive growth. As the data increases, it also brings challenges to data processing. For example, there is sensitive data in the network, which includes sensitive information that needs to be avoided from being leaked. The above-mentioned sensitive data is, for example, video data collected by a camera. The video data collected by the camera includes a large amount of personal information, which is also sensitive information. Taking the data acquisition device as an example, a camera located in the private environment of the target object, the video data recorded by the camera includes a large amount of personal information such as the target object's portrait, behavioral habits, and environmental information of the private space. The ownership of personal information belongs to the target object, not the platform or the operator. Personal information needs to be protected to avoid leakage and improve data security.
[0070] The embodiment of the present application provides a data processing method for sensitive data. Please refer to Figure 1, which shows a schematic diagram of the implementation environment of the data processing method provided by the embodiment of the present application, and the implementation environment includes a first device 01, a data acquisition device 02 and a second device 03. Among them, the first device 01, the data acquisition device 02 and the second device 03 are respectively connected by a wired or wireless network. For example, the target object that needs to use the data acquisition device authenticates the security of the data acquisition device 02 based on the second device 03. The authenticated data acquisition device 02 can collect multimedia data and process the multimedia data based on the identity information used in the authentication process to obtain the data processing results corresponding to the multimedia data.
[0071] After processing the multimedia data, if another device, such as the first device 01, requests to obtain the multimedia data, the first device 01 sends an access request to the second device 03. The second device 03 performs device security verification on the first device 01 based on the access request. If the verification is successful, that is, the first device 01 obtains access rights to the multimedia data, the first device 01 can obtain the ciphertext data based on the authorization of the second device 03 and decrypt the ciphertext data to obtain the multimedia data. The ciphertext data is obtained by the second device 03 based on the data processing results of the data acquisition device 02.
[0072] The interaction between the above-mentioned data acquisition device 02, the second device 03 and the first device 01 can be executed directly or indirectly through other devices. Figure 2 is a schematic diagram of the implementation environment of another data processing method provided in an embodiment of the present application, and the implementation environment also includes a third device 04. The third device 04 establishes a communication connection with the first device 01, the data acquisition device 02 and the second device 03 respectively through a wired or wireless network. Taking Figure 2 as an example, in the case where the second device 03 and the data acquisition device 02 need to interact to implement end-to-end encryption with two-way authentication, the second device 03 and the data acquisition device 02 can interact directly or indirectly through the third device 04. In the case where the first device 01 needs to request multimedia data collected by the data acquisition device 02, the first device 01 can realize the data request through the third device 04, for example, obtain ciphertext data through the third device 04, and decrypt the obtained ciphertext data to obtain multimedia data. In addition, even if the third device 04 participates in the interaction between the first device 01, the data acquisition device 02 and the second device 03, the data obtained by the third device 04 is also processed ciphertext data, and the third device 04 cannot decrypt the ciphertext data, thereby avoiding data leakage of multimedia data in the third device 04.
[0073] In one possible implementation, the first device 01 and the second device 03 can be any device with object interaction capabilities. The first device 01 and the second device 03 can be terminal devices such as desktop computers, laptop computers, or smartphones, or servers that process data during the interaction process, such as central servers, edge servers, or local servers in local data centers. The server can be a physical server or a cloud server that provides cloud computing services. The multimedia data collected by the data acquisition device 02 may include video data, image data, and audio data, etc., and the data acquisition device 02 can be any device with data acquisition capabilities. The data acquisition device 02 can be a video acquisition device such as a video camera, an image acquisition device such as a camera, or an audio acquisition device such as a recorder. In addition, the data acquisition device 02 can be a complete device that provides data acquisition capabilities, or a network card configured on the data acquisition device for data processing, or the data acquisition device 02 can be a terminal that provides data acquisition capabilities. For example, the third device 04 can be any platform that provides data processing capabilities, including but not limited to a visual network platform.
[0074] The data processing method provided in the embodiment of the present application can be applied to the implementation scenario shown in Figure 1 or Figure 2 above. The flowchart of the method is shown in Figure 3, including S301-S302.
[0075] S301, acquiring multimedia data collected by a data collection device.
[0076] In one possible implementation, before acquiring multimedia data collected by a data acquisition device, the data acquisition device needs to be authenticated to determine whether the multimedia data can be acquired by the data acquisition device. The authentication process includes, but is not limited to, acquiring first identity information used to identify the data acquisition device; and acquiring the multimedia data acquired by the data acquisition device if the first identity information is authenticated by the target object.
[0077] Exemplarily, the data acquisition device may provide an information input control to obtain the first identity information input through the information input control, or the first identity information may be pre-stored, for example, the manufacturer sets and stores the first identity information of each data acquisition device before leaving the factory. In this case, the data acquisition device may access the storage space to obtain the first identity information stored in the storage space. The embodiment of the present application does not limit the first identity information of the data acquisition device, and may be any information used to identify the data acquisition device, including but not limited to the device identity identification number (identity document, ID) or product serial number of the data acquisition device. In the case where the data acquisition device includes multiple products, the product serial numbers included in the first identity information may be all product serial numbers of the multiple products. For example, if the data acquisition device is a SLR camera, the SLR camera includes two products, namely the body and the lens. The product serial numbers included in the first identity information may be the product serial number of the body and the product serial number of the lens. Optionally, the product serial numbers included in the first identity information may also be some of the product serial numbers of the multiple products. Continuing with the example of a SLR camera being the data acquisition device, the data collected by the SLR camera is determined based on the viewfinder configured on the camera body, and the lens configured on the SLR camera will be replaced according to the acquisition requirements, for example, lenses of different focal lengths may be replaced based on the distance of data acquisition. In other words, the fixed product of the SLR camera is the camera body. Therefore, the product serial number included in the first identity information may also be only the product serial number of the camera body.
[0078] Regardless of the method and type of the first identity information obtained, the data acquisition device can send the first identity information to the second device corresponding to the target object for security authentication after obtaining the first identity information. The second device corresponding to the target object can be a device used by the target object, or a device authorized by the target object to manage data. For example, the target object has limited free time and authorizes a guardian to manage data, so the second device can also be a device used by the guardian of the target object. After receiving the first identity information, the second device can display the received first identity information, and the target object determines whether the data acquisition device is safe based on the displayed first identity information. Taking the first identity information as an identity identification number as an example, the second device registers the data acquisition device based on the first identity information and displays the identity identification number of the registered data acquisition device. The target object explicitly requests the data acquisition device to be authenticated based on the identity identification number of the displayed data acquisition device, and further determines whether the data acquisition device is safe based on experience.
[0079] In addition, the data acquisition device may also send the first identity information to a certification authority (CA) or other authoritative and impartial third-party trust organization to apply for a digital certificate from the CA. The CA verifies the device security of the data acquisition device based on the received first identity information, and issues a digital certificate to the data acquisition device if the verification is passed. The issued digital certificate includes the issuing authority, validity period, and device identification of the data acquisition device. After obtaining the digital certificate, the data acquisition device may send the digital certificate to a second device. The target object reads the digital certificate based on the second device. Since the digital certificate is issued by the CA and is within the validity period, the target object can determine that the data acquisition device is a safe and trustworthy device.
[0080] In one scenario, the data acquisition device may also apply for a digital certificate based on the second device. Specifically, the data acquisition device sends the first identity information to the second device, and the second device sends the received first identity information to the CA to apply for a digital certificate for the data acquisition device from the CA. If the digital certificate is successfully issued, the data acquisition device is determined to be a secure device that can be used for data acquisition. Furthermore, the process of applying for a digital certificate from the CA may also be performed by other entities, such as the manufacturer of the data acquisition device. Before shipping the data acquisition device, the manufacturer may apply to the CA for authentication of the data acquisition device to obtain the product serial number of each data acquisition device.
[0081] During the device authentication process described above, the data acquisition device and the second device may interact directly or indirectly. For example, the data acquisition device and the second device may be connected via a third device. In this case, the data acquisition device authenticates the target object via the third device. For example, the first identity information may be sent to the third device, which then sends it to the second device, allowing the target object to authenticate based on the first identity information displayed by the second device.
[0082] Regardless of the method used to determine the device security of the data acquisition device, the target object can authorize the data acquisition device to collect data by interacting with the second device when the device security is determined, so that the second device can determine the device security of the data acquisition device and authenticate the data acquisition device. The interaction can be achieved through face recognition or agreement signing. For example, based on face recognition technology, the target object performs the specified action provided by the second device to determine whether it is authorized by the person himself. The specified action includes but is not limited to blinking, turning the head left and right, and nodding. Alternatively, the second device provides an agreement signing control, and the agreement signing control is, for example, "I have read and agreed to the privacy policy". The target object triggers the agreement signing control to authorize the data acquisition device to collect data. The above-mentioned trigger control can be triggered by click, voice or other triggering methods.
[0083] After interacting with the target object to determine the device security of the data acquisition device, the second device can send a certificate indicating the device security to the data acquisition device, as shown in Figure 4. The data acquisition device then determines that it has passed the security authentication of the target object based on the received certificate and can start data acquisition.
[0084] Regardless of the method by which the data acquisition device is authenticated by the target object, data acquisition can be performed based on the authentication of the target object to obtain multimedia data. Among them, data acquisition can be performed by following the target object, that is, the target object is the object being collected. Taking the data acquisition device as a camera as an example, the lens of the camera follows the target object to achieve video recording of the target object. Data acquisition can also be performed according to the acquisition target set by the target object, that is, the target object is the object for which data acquisition is required. For example, the data acquisition device is a home camera placed on the target object, and the target object sets the acquisition target of the home camera to the living room by placing the home camera, and the home camera starts recording the video of the living room. In addition, the embodiment of the present application does not limit the data type of the multimedia data acquired by the data acquisition device, which can be video data, image data, audio data, etc.
[0085] S302, encrypt or sign the multimedia data based on the identity information to obtain the data processing result corresponding to the multimedia data, the identity information is determined based on the information used for authentication between the second device corresponding to the target object and the data acquisition device, the target object is the object using the data acquisition device, and the data processing result is used for the authorized device to access the multimedia data.
[0086] In one possible case, the multimedia data collected by the data acquisition device includes the personal information of the target object. In the case where the data acquisition device follows the target object to collect data, the collected multimedia data includes but is not limited to the portrait and behavioral habits of the target object. In the case where the collection target of the data acquisition device is set to the target object, the collected multimedia data includes but is not limited to the environmental information of the target object's private space, such as the living room environmental information exemplified in the above embodiment. Moreover, since the target object may pass through the living room, the collected multimedia data will also include the portrait and personal habits of the target object. Since the multimedia data collected by the data acquisition device includes the personal information of the target object, the ownership of the multimedia data belongs to the target object. Therefore, the data acquisition device needs to process the multimedia data to prevent other devices from arbitrarily accessing the multimedia data and causing leakage of personal information.
[0087] In one possible implementation, before processing multimedia data, the data acquisition device will also perform security authentication with the second device to authenticate the transmission security of the transmission channel between the data acquisition device and the second device. The identity information used in the security authentication process includes first identity information for identifying the data acquisition device and second identity information for identifying the second device. Similar to the description of the first identity information, the second identity information can also be any information that can identify the second device, including but not limited to the ID of the second device. For a detailed description, please refer to the relevant content of the first identity information in S301, which will not be repeated here.
[0088] Exemplarily, the process of authentication based on identity information includes: the data acquisition device encrypts the first identity information to obtain a first secure ciphertext, and sends the first secure ciphertext to the second device; when verifying the transmission security based on the first secure ciphertext, receives the second secure ciphertext returned by the second device, and the second secure ciphertext is encrypted based on the second identity information; decrypts the second secure ciphertext, and verifies whether the transmission with the second device is secure based on the decryption result.
[0089] Next, we'll use the example of ID_i as the first identity and ID_M as the second identity to illustrate the verification process based on the first and second identity information. The data acquisition device randomly generates an authentication key, K, and uses ID_i and K to generate authentication information. The authentication information includes R and n, where R = PRF(K, ID_i||Nonce), n = PRF(K, R), where PRF() is a calculation function, || indicates a concatenation operation, and Nonce is an arbitrary or non-repeating random value used once.
[0090] Afterwards, the data acquisition device generates a first secure ciphertext based on the authentication information. For example, an authorization value (Auth_value_i) is first generated based on R and n, and a first secure ciphertext is generated based on the authorization value. The calculation process of the authorization value is Auth_value_i = AES-CMAC (n, ID_i||R||"MAC"), where AES-CMAC is a calculation function and MAC indicates the type of generated parameters. The process of generating the first secure ciphertext based on the authorization value is, for example, C1 = Enc (PK1, ID_i||Auth_value_iID_i||R||n||Ai). Among them, C1 is the first secure ciphertext, Enc refers to encryption, PK1 is the public key 1 in the public-private key pair 1 randomly generated by the second device, Ai is the parameter generated based on the randomly generated ai, Ai = ai×g, and g indicates the cryptographic parameter.
[0091] After obtaining the first security ciphertext, the data acquisition device can send the first security ciphertext to the second device. The second device uses the private key 1 corresponding to the public key 1 to decrypt the first security ciphertext and obtain the first identity information ID_i, the authorization value Auth_value_i, the authentication information R and n, and Ai. Based on the obtained information, the reference value Auth_value_i'=AES-CMAC(n, ID_i||R||"MAC") is recalculated, and the calculated reference value and the authorization value are compared. If the reference value and the authorization value are different, it is determined that the first security ciphertext has been tampered with during the transmission process, and the transmission between the data acquisition device and the second device is not secure. If the reference value and the authorization value are the same, it is determined that the first security ciphertext has not been tampered with during the transmission process, and the transmission between the data acquisition device and the second device is secure. In this case, the second device begins to generate a second security ciphertext based on the second identity information.
[0092] Similar to the process of generating Ai, the second device also generates the parameter Bi used in the encryption process, Bi = bi × g + Ai, where bi is a randomly generated parameter. The second device then generates a second secure ciphertext based on Bi and the second identity information ID_M. The generation process includes first generating an intermediate value Si = F2(SK2, bi, Bi, ID_i, ID_M), where F2 is a calculation function, F2(SK2, bi, Bi, ID_i, ID_M) = bi + Hash(ID_i||ID_M||Bi) × SK2, and SK2 is private key 2 from the public-private key pair in the second device's signature certificate. The second device uses Si to calculate the second secure ciphertext C2 = AES-GCM(n, ID_i||ID_M||Ai||Bi||Si), where AES-GCM refers to the calculation function.
[0093] The second device sends the calculated second security ciphertext to the data acquisition device, and the data acquisition device performs transmission verification based on the received second security ciphertext. For example, it uses n to decrypt the second security ciphertext to obtain ID_i||ID_M||Ai||Bi||Si, and calculates Ti=Hash(ID_i||ID_M||Bi)×PK2 based on the decryption result. Among them, PK2 is the public key 2 corresponding to the private key 2 used in the process of encrypting the second security ciphertext. Compare Si×g and Ti+Bi-Ai to see if they are equal. If they are equal, it means that the second security ciphertext has not been tampered with during the transmission process, that is, the transmission between the data acquisition device and the second device is secure. If they are not equal, it means that the second security ciphertext has been tampered with during the transmission process, that is, the transmission between the data acquisition device and the second device is not secure. Similar to the device authentication process in S301, the data acquisition device and the second device can also authenticate the second device through a third device during the process of authenticating transmission security.
[0094] For example, the data acquisition device may process multimedia data using the identity information used in the above-mentioned authentication process, such as the first identity information ID_i and the second identity information ID_M in the above-mentioned embodiment. The embodiment of the present application does not limit the process by which the data acquisition device processes multimedia data based on identity information, and may be implemented in the following two ways, including but not limited to.
[0095] Processing process 1: Obtain a first key, which is obtained through negotiation with the second device based on the identity information; encrypt the multimedia data according to the first key to obtain ciphertext data, and use the ciphertext data as the data processing result.
[0096] In one possible scenario, the data acquisition device can calculate a second public key and a second private key of the data acquisition device based on the identity information; and then negotiate the first key using the second public key, the second private key, and the identity information. Because the second device corresponds to the target object, and ownership of the multimedia data belongs to the target object, the data acquisition device can interact and negotiate with the second device.
[0097] Optionally, the data acquisition device calculates a second public key pk = Bi + Ti and a second private key sk = ai + Si, where Bi, Ti, ai, and Si are parameters generated during the authentication process, Ti is calculated based on the first identity information and the second identity information, and Si is also calculated based on the first identity information and the second identity information. A detailed description of Bi, Ti, ai, and Si can be found in the authentication process of the data acquisition device and the second device in the above embodiment, and will not be repeated here.
[0098] For example, the data acquisition device sends identity information to the second device. The second device generates a first identifier based on the received identity information and negotiates based on the first identifier to obtain a second public key and a second private key. Optionally, the second device may concatenate the camera body and lens product serial numbers or other hardware information included in the identity information and use the concatenated result as the first identifier.
[0099] The embodiments of the present application do not limit the process by which the second device obtains the second public key and the second private key through negotiation based on the first identifier. In one possible scenario, the second device pre-deploys multiple shared public-private key pairs, and defines a second identifier for each public-private key pair to identify a different public-private key pair. The second device searches for the second identifier based on the first identifier, and when a matching second identifier is found, the public-private key pair corresponding to the second identifier is used as the second public key and the second private key. Alternatively, the second device may calculate the second public key and the second private key based on the first identifier, for example, using an asymmetric encryption algorithm (RSA) to calculate the second public key and the second private key based on the first identifier.
[0100] After obtaining the second public key and the second private key through negotiation with the second device, the data acquisition device can further negotiate with the second device to obtain the first key based on the identity information. Negotiated generation involves the data acquisition device and the second device first separately generating the parameters required to obtain the first key. The data acquisition device and the second device then exchange the generated parameters and, based on the exchanged parameters, perform similar steps to calculate the first key.
[0101] Next, taking the example of the data acquisition device calculating the first parameter X and the second device calculating the second parameter Y and the third parameter B_M, the process of negotiating the first key is explained. For example, the data acquisition device randomly generates data x, generates the first parameter X based on the data x, and the calculation process is, for example, X=x×g. The second device randomly generates data y, generates the second parameter Y based on the data y, and the calculation process is, for example, Y=y×g, and then randomly generates the third parameter B_M. The data acquisition device sends the first parameter X and Bi generated during the transmission security verification process to the second device, and the second device sends the second parameter Y and the third parameter B_M to the data acquisition device. Afterwards, the data acquisition device calculates pk_M=B_M+Hash(ID_M, B_M)×PK2, and verifies the validity of pk_M and ID_M, for example, whether the data format is correct. When the verification indication is valid, W=Bi||B_M||ID_i||ID_M||X||Y is calculated, and MK=(x+Hash(W)×ski)×(Y+Hash(W)×pk_M) is calculated based on W, and the first key K_auth||K_enc=KDF(MK, W||"workkey") is obtained, where KDF is a function and workkey indicates that the calculated result is the key.
[0102] Similar to the operation of the data acquisition device, the second device also first generates pk_i based on the first parameters X and Bi. The calculation process is, for example, pk_i = Bi + Hash(ID_i||ID_M, Bi) × PK2. The validity of pk_i and ID_i is verified. After passing the verification, W, MK, and the first key are calculated. For example, W = Bi || B_M || ID_i || ID_M || X || Y, MK = (y + Hash(W) × sk_M) × (X + Hash(W) × pk_i), and the first key K_auth || K_enc = KDF(MK, W || "workkey").
[0103] Figure 4 is an interaction diagram provided by an embodiment of the present application. In Figure 4, the second device and the data acquisition device are connected through a third device. The data acquisition device and the second device both include a secure channel establishment module. The secure channel establishment module is responsible for establishing a bidirectionally authenticated end-to-end encrypted channel between the second device and the data acquisition device. Establishing an encrypted channel means generating a first key based on identity information, thereby encrypting the transmitted multimedia data based on the first key.
[0104] After calculating and obtaining the first key, the data acquisition device can encrypt the multimedia data according to the first key to obtain ciphertext data. For example, as shown in Figure 4, the data acquisition device also includes an encryption and decryption module for encrypting the multimedia data. The embodiment of the present application does not limit the process of the data acquisition device using the first key to encrypt the multimedia data, and can be implemented using any encryption algorithm, including but not limited to the Advanced Encryption Standard (AES), the Triple Data Encryption Algorithm (TDEA), a stream encryption algorithm (Salsa20), the Data Encryption Standard (DES), and a block cipher algorithm (RC5). By using the first key for symmetric encryption, the symmetrically encrypted ciphertext data can be decrypted by the first key. Since the encryption key and the decryption key are both the first key, the above encryption process involves fewer keys, the encryption and decryption efficiency is high, and the performance is good.
[0105] Processing process two: obtaining a second key of the data acquisition device, where the second key has not been authenticated by a second device corresponding to the target object; encrypting the multimedia data according to the second key to obtain ciphertext data corresponding to the multimedia data; signing the ciphertext data according to the identity information to obtain signature data corresponding to the ciphertext data; obtaining a data processing result based on the signature data and the ciphertext data, where the signature data is used to verify whether the ciphertext data is abnormal.
[0106] Exemplarily, the data acquisition device can randomly generate a second key, which can be a symmetric encryption key or an asymmetric encryption key. When the second key is an asymmetric encryption key, the second key is a public-private key pair (pk, sk), where pk indicates the public key and sk indicates the private key.
[0107] Regardless of the method and type of the second key generated by the data acquisition device, the second key can be used to encrypt the multimedia data. If the second key is a symmetric encryption key, the data acquisition device can use a symmetric encryption algorithm to encrypt the multimedia data based on the second key. If the second key is an asymmetric encryption key, the data acquisition device can use an asymmetric encryption algorithm to encrypt the multimedia data based on the public key included in the second key, such as RSA or other encryption algorithms.
[0108] Since the ciphertext data is encrypted using the directly generated second key, the security of the second key has not been authenticated by the second device, and the security of the ciphertext data encrypted using the second key is also unknown. Therefore, it is necessary to sign the ciphertext data using identity information authenticated by the second device, so that the security of the ciphertext data is indicated by the signature data corresponding to the ciphertext data.
[0109] In one possible scenario, the process of the data acquisition device signing the ciphertext data includes: obtaining the third public key of the second device, encrypting the second key based on the third public key to obtain the ciphertext parameter corresponding to the second key, the ciphertext parameter being used to obtain the second key required for decrypting the ciphertext data; signing the ciphertext data and the ciphertext parameter based on the identity information to obtain signature data corresponding to the ciphertext data and the ciphertext parameter, and obtaining a data processing result based on the ciphertext data, the ciphertext parameter, and the signature data. The third public key is a public key owned by the second device, and the third public key is, for example, public key 1 in public-private key pair 1 or public key 2 in public-private key pair 2 used in the above-mentioned authentication process. The data acquisition device can receive the third public key sent by the second device, or, if the third public key is publicly available, access the public location of the third public key to obtain the third public key.
[0110] Regardless of the method by which the data acquisition device obtains the third public key, the second key required for decrypting the ciphertext data can be encrypted according to the third public key. In the case where the ciphertext data is encrypted using a symmetric encryption algorithm, the key required for decrypting the ciphertext data is the second key. Therefore, the data acquisition device can use the third public key of the second device to encrypt the second key to obtain the ciphertext parameters. In the case where the ciphertext data is encrypted using an asymmetric algorithm, the key required for decrypting the ciphertext data is the private key sk included in the second key. Therefore, the data acquisition device can use the third public key to encrypt the private key sk included in the second key to obtain the ciphertext parameters. By encrypting the second key required for decryption, the second device can obtain the second key to decrypt the ciphertext data when it needs to obtain multimedia data, thereby obtaining the multimedia data.
[0111] Since the ciphertext data and ciphertext parameters may be intercepted and tampered with during transmission, the data acquisition device needs to sign the ciphertext data and ciphertext parameters to verify whether the ciphertext data and ciphertext parameters have been intercepted and tampered with by other devices based on the signature data, thereby determining the security of the ciphertext data and ciphertext parameters. The data acquisition device can splice the ciphertext data and ciphertext parameters, sign the splicing result based on the identity information, and obtain a signature data corresponding to the ciphertext data and ciphertext parameters. It can also sign the ciphertext data and ciphertext parameters separately based on the identity information to obtain multiple signature data corresponding to the ciphertext data and ciphertext parameters. The signature can be performed by using a hash algorithm to perform a hash calculation based on the identity information, ciphertext data, and ciphertext parameters, or it can be performed by other methods.
[0112] In one possible implementation, after obtaining the data processing results, the data acquisition device also sends the data processing results to a second device corresponding to the target object, so that the second device can obtain multimedia data based on the data processing results and, in turn, provide the multimedia data to the target object. Regarding the ciphertext data obtained in process one, since the first key is negotiated between the data acquisition device and the second device, the first key is known to the second device. The second device can then decrypt the ciphertext data using the first key to obtain the multimedia data.
[0113] For the ciphertext data obtained in the second processing step, since the second key is a key directly generated by the data acquisition device, the second key is unknown data on the second device side. The second device first verifies based on the signature data, calculates the signature based on the ciphertext data, ciphertext parameters and identity information to obtain the signature data, and compares the calculated signature data with the signature data sent by the data acquisition device. If the calculated signature data is different from the signature data sent by the data acquisition device, it is determined that the verification has failed, the ciphertext data and ciphertext parameters have been intercepted and tampered with during transmission, and the security is unknown, and the decryption is canceled. If the calculated signature data is the same as the signature data sent by the data acquisition device, it is determined that the verification has passed, there is no abnormality in the ciphertext data and ciphertext parameters, and the ciphertext data and ciphertext parameters can be decrypted. The second device uses all the third private keys to decrypt the ciphertext parameters to obtain the second key, and then decrypts the ciphertext data based on the second key to obtain multimedia data. Exemplarily, the above-mentioned process of decrypting ciphertext data to obtain multimedia data can be implemented by the encryption and decryption module included in the first device in Figure 4.
[0114] In one possible implementation, as shown in Figure 4 , after processing the encrypted data, the data acquisition device also sends the encrypted data to a third device for storage. This allows the third device to provide the data to the authorized device if an authorized device subsequently requests the data. Because the data sent by the data acquisition device to the third device is encrypted ciphertext data, even the third device used for data communication between the data acquisition device and the second device cannot access the multimedia data without authorization, effectively protecting the multimedia data.
[0115] In summary, in the data processing method provided by the embodiment of the present application, after the data acquisition device acquires multimedia data, it processes the multimedia data to obtain a data processing result, thereby preventing other devices from accessing the multimedia data without authorization, thereby achieving privacy protection for the data and the target object. In addition, the processing of multimedia data is based on identity information. Since the identity information is the information used for authentication between the second device and the data acquisition device, the security is highly reliable through bidirectional authentication between the data acquisition device and the second device. The multimedia data obtained based on the highly reliable identity information processing is highly secure.
[0116] The present application also provides a data processing method, which can be applied to the implementation scenario shown in Figure 1 or Figure 2. The method can be executed by the first device. The flowchart of the data processing method is shown in Figure 5, including S501-S503.
[0117] S501: Sending an access request for multimedia data.
[0118] Exemplarily, the first device is another device independent of the data acquisition device and the second device. In one possible case, the first device is a device used by a user, and the user refers to an object that needs to use multimedia data. Continuing with the embodiment shown in FIG3 , the data acquisition device is a camera placed in the living room by the target object as an example. The user can be the guardian of the target object who applies to view the camera, so as to promptly confirm the safety of the target object based on the multimedia data collected by the camera. Regardless of the situation of the first device, a request for access to multimedia data will be sent based on the need for data acquisition.
[0119] In one possible implementation, the first device may send an access request to the second device corresponding to the target object to request authorization from the target object, the owner of the multimedia data. The embodiment of the present application does not limit the manner in which the first device sends the access request to the second device. It may be sent directly, for example, as shown in FIG6 , in which a communication connection is established between the second device and the first device, and the first device sends an access request to the second device based on the communication connection. The first device may also send an access request indirectly to the second device, for example, as shown in FIG7 , the second device and the first device cannot communicate directly due to limitations of the communication link, and the second device and the first device are connected through a third device. Based on this, the first device may send an access request to the third device, and the third device forwards the access request to the second device. Among them, the third device may be a visual Internet platform, or other real-time network.
[0120] In addition, the first device can also send an access request to a third device. For example, if the third device stores the ciphertext data corresponding to multimedia data and can provide data to authorized devices, the first device can request the ciphertext data from the third device, thereby sharing the data provision task of the second device with the third device, thereby improving data processing efficiency. If the first device requests multimedia data from a third device that is different from the second device, since the ownership of the multimedia data belongs to the target object corresponding to the second device, the third device will send the access request to the second device for authorization verification.
[0121] Regardless of how the second device receives the access request from the first device, it can verify the first device based on the access request. For example, in Figures 6 and 7, the second device includes an authorization module for verifying the first device. Exemplarily, the second device can obtain device information of the first device based on the access request, and determine whether to grant the first device permission to access multimedia data based on the device information of the first device and at least one device information, where the at least one device information is information about at least one device that has signed a data agreement, and the data agreement is used to obtain access rights to multimedia data.
[0122] The embodiments of the present application do not limit the process of obtaining the device information of the first device based on the access request. The device information of the first device can be sent to the second device synchronously with the access request, that is, the access request of the first device carries the device information, and the second device can parse the received access request and read the device information carried in the access request. Alternatively, the device information of the first device can also be sent to the second device asynchronously with the access request. For example, after obtaining the access request, the second device triggers the device verification of the first device based on the access request and sends an identity authentication instruction to the first device. The first device sends the device information to the second device for identity authentication based on the received device verification instruction. The device information of the first device can be the device identification of the first device. In the case where the first device is a device used by the user, the device information of the first device can also include the object information of the user, such as the object identification of the user, the organization to which it belongs or the corporate institution, etc. The object identification is, for example, the name, ID number, telephone number, and biometric information of the user, such as a face photo, fingerprint, etc.
[0123] After obtaining the device information of the first device, the second device can verify the first device based on the obtained device information. Exemplarily, the second device searches at least one device information based on the device information of the first device, and when the at least one device information includes the device information of the first device, determines to grant the first device the permission to obtain multimedia data. The embodiment of the present application does not limit the way in which the second device obtains at least one device information. The data agreement signed by the second device and the device can be signed online. In this case, the second device counts the device information used by the device that signed the data agreement to obtain at least one device information. Alternatively, the data agreement signed by the second device and the device is signed offline. For example, the target object and the object corresponding to the device sign the data agreement offline, and after signing, the object information of the object corresponding to the device is input into the information input control provided by the second device as the device information of the device. In some cases, the at least one device information may also be referred to as a whitelist.
[0124] In the event that at least one device information does not include the device information of the first device, the second device may directly determine that the first device is not granted permission to obtain multimedia data and send a refusal instruction to the first device. The second device may also verify the device security of the first device based on the device information of the first device. If the verification result indicates that the device is secure, the second device may determine to grant the first device permission to obtain multimedia data. Verifying device security may include searching the network domain name in the device information of the first device to determine whether the network location of the first device belongs to a trusted network, or verifying the organizational security of the organization in the device information of the first device and determining the accuracy of the device information based on the member list of the organization. Optionally, if the verification is successful, the second device may directly interact with the first device to perform operations S502-S503 to enable the first device to obtain multimedia data. If the verification is successful, the second device may also interact with the first device to sign a data agreement to determine the operations performed by the first device on the multimedia data, thereby preventing the first device from arbitrarily forwarding multimedia data and causing data leakage.
[0125] S502, when access rights to multimedia data are obtained based on an access request, ciphertext data corresponding to the multimedia data is obtained, the ciphertext data is obtained by encrypting or signing the multimedia data according to the identity information, the identity information is determined based on the information used for authentication between the second device corresponding to the target object and the data acquisition device of the multimedia data, and the target object is the object using the data acquisition device.
[0126] Exemplarily, since the ciphertext data is obtained by encrypting the multimedia data, the first device that needs to obtain the multimedia data can obtain the ciphertext data and decrypt the ciphertext data to obtain the requested multimedia data. The ciphertext data is obtained by processing the identity information. Optionally, the identity information is used by the data acquisition device and the second device to negotiate to obtain a first key, and the ciphertext data is obtained by encrypting the multimedia data according to the first key. For the process of encrypting the multimedia data to obtain the ciphertext data, please refer to the relevant description of the processing process one in the embodiment S302 shown in Figure 3, which will not be repeated here. Optionally, the identity information can also be used to sign the ciphertext data corresponding to the multimedia data, and the signature data obtained by the signature is used by the second device to verify whether the ciphertext data sent by the received data acquisition device is abnormal, and the second device is used to provide the ciphertext data to the first device. For the process of signing and verifying the second device, please refer to the relevant description in the embodiment S302 shown in Figure 3, which will not be repeated here. In addition, the embodiment of the present application does not limit the process of the first device obtaining the ciphertext data, and it can be obtained by including but not limited to the following two methods.
[0127] Acquisition method 1: Receive the encrypted data returned based on the access request.
[0128] For example, after the second device determines, based on the access request, that the first device is permitted to obtain multimedia data, it may provide the ciphertext data to the first device, so that the first device can decrypt the ciphertext data to obtain the multimedia data. The second device may choose to send the ciphertext data to the first device, or send a permission to send instruction to another device that can provide ciphertext data. Based on the received permission to send instruction, the other device sends the ciphertext data to the first device, and the first device thereby receives the returned ciphertext data.
[0129] Among them, the other device can be the third device shown in Figure 7. In Figure 7, after the data acquisition device and the second device interactively complete the processing of the multimedia data, the encrypted ciphertext data is sent to the third device, and the third device manages the data provision. In this case, the second device can send a permission to send instruction to the third device indicating that the ciphertext data can be sent, so as to notify the third device to provide the ciphertext data to the first device. Optionally, the permission to send instruction can be an instruction specifically used to indicate that the verification is passed, or it can be a second authorization flag that needs to be provided to the first device. The second authorization flag is the data required by the first device to obtain the multimedia data based on the ciphertext data.
[0130] In the case where the instruction to send is allowed to be the second authorization mark, the first device also needs to generate a second authorization mark based on the first public key. Exemplarily, the second device generates the second authorization mark based on the first public key of the first device and the third public key and the third private key owned by the second device. The generation process is, for example, that the second device calculates the second authorization mark based on the first public key, the third public key and the third private key. In some cases, the second authorization mark may be referred to as a token. Regarding the role of the second authorization mark, please refer to the relevant description of decrypting the ciphertext data in S503, which will not be repeated here. By sending the second authorization mark that needs to be sent subsequently to the third device, the notification of sending data can be realized, thereby avoiding the repeated sending of multiple data and effectively reducing the interaction cost between the second device and the third device.
[0131] Acquisition method 2: receiving a first authorization flag returned based on the access request, the first authorization flag indicating permission to obtain multimedia data; and requesting to obtain ciphertext data according to the first authorization flag.
[0132] In one possible scenario, after determining that the first device can obtain multimedia data, the second device generates a first authorization mark, which indicates that the first device is allowed to obtain multimedia data. The first authorization mark may include device information of the first device, etc. In some cases, the first authorization mark may be called a token. After obtaining the first authorization mark, the first device may request multimedia data based on the first authorization mark, wherein the first device can request multimedia data from any device that can provide data, including but not limited to the second device and the third device. In one possible scenario, when the device requesting multimedia data for the first device is a different device from the second device, the second device also needs to send the first authorization mark to the device providing the data so that the device performs mark verification based on the received first authorization mark. For example, as shown in Figure 6, the second device sends the first authorization mark to the third device so that the third device performs mark verification.
[0133] Next, we'll use the example of a first device requesting multimedia data from a third device. In one possible scenario, the first device sends a first authorization flag to the third device. The third device compares the received first authorization flag with the first authorization flag sent by the second device. If the first authorization flag sent by the first device is identical, the third device determines that the first device has passed authentication. If the first authorization flag sent by the first device is different from the first authorization flag sent by the second device, the third device determines that the first device has failed authentication. The third device can cancel sending the ciphertext data to the first device or send a request failure instruction to the first device to notify the first device that the multimedia data request has failed. Furthermore, if the first authorization flag also includes an authorization time, the third device can further compare the current time with the authorization time if the first authorization flag sent by the first device is identical. If the current time falls within the authorization time, the third device determines that the first device has passed authentication; if the current time does not fall within the authorization time, the third device determines that the first device has failed authentication. This authentication process can be performed by the authorization verification module included in the third device shown in Figures 6 or 7. Regardless of the method used to determine that the first device has passed authentication, the third device can send ciphertext data to the first device if authentication has passed, allowing the first device to obtain the ciphertext data.
[0134] S503: Decrypt the ciphertext data to obtain multimedia data.
[0135] Since the first device needs to use the key of the ciphertext data in the process of decrypting the ciphertext data, the first device needs to request the key of the ciphertext data. Exemplarily, the first device can request the key from the device that indirectly manages the key. The device that indirectly manages the key refers to the device that manages the reference ciphertext. Taking Figure 7 as an example, in Figure 7, the third device can receive the reference ciphertext sent by the second device or the data acquisition device, store and manage the received reference ciphertext. In this case, the third device is a device that indirectly manages the key. Among them, the reference ciphertext refers to the ciphertext encrypted by the key. In one possible implementation, the reference ciphertext can be obtained by encrypting the key of the ciphertext data using the third key of the second device. The key refers to the key required to encrypt multimedia data and decrypt the ciphertext data. The key can be the first key or the second key in the embodiment shown in Figure 3.
[0136] Optionally, the first device receives re-encrypted data returned by the device for indirect key management based on the access request, and decrypts the re-encrypted data to obtain the key. The re-encrypted data is obtained by encrypting the reference ciphertext based on the second authorization flag, which is generated based on the first public key of the first device. For a detailed description, see the description of the first acquisition method in S502, and will not be repeated here.
[0137] In one possible scenario, encrypting the reference ciphertext based on the second authorization flag to obtain re-encrypted data can be performed by the second device, or can be performed by a third device as shown in FIG7 , or by another device that includes the reference ciphertext. Because the process of obtaining re-encrypted data is similar for different devices, the process of obtaining re-encrypted data is described below using the third device as an example.
[0138] The second device sends the second authorization mark to the third device, and the third device re-encrypts the reference ciphertext based on the received second authorization mark. The embodiment of the present application does not limit the process of encrypting the reference ciphertext by the third device, and any encryption algorithm can be used to re-encrypt the reference ciphertext based on the second authorization mark to obtain re-encrypted data. After obtaining the re-encrypted data, the third device can send the re-encrypted data to the first device if the access request of the first device is verified by the second device, so that the first device obtains the re-encrypted data. Based on the situation that the third device is also used to send ciphertext data to the first device, the third device can synchronously send the ciphertext data and the re-encrypted data to the first device, for example, as shown in Figure 7, where C0 indicates the ciphertext data. Alternatively, the third device can also asynchronously send the ciphertext data and the re-encrypted data to the first device.
[0139] Regardless of how the re-encrypted data is received, the first device can obtain the key for the ciphertext data based on the decryption result of the re-encrypted data. Since the second authorization flag used to encrypt the re-encrypted data is generated based on the first public key, the re-encrypted data can be decrypted using the first private key corresponding to the first public key. The decryption result includes the reference ciphertext. Furthermore, since the second authorization flag is generated based on the third public key and the third private key, the first device can determine the second authorization flag based on the decryption result and parse the second authorization flag to obtain the third private key. The reference ciphertext is then decrypted using the third private key to obtain the key. After obtaining the key, the first device can use the key to decrypt the ciphertext data to obtain the multimedia data.
[0140] Optionally, the first device may also request a key from a device that directly manages keys. The device that directly manages keys refers to a device that manages unencrypted keys, such as the second device shown in FIG6 , or may be a data acquisition device. The process of the first device requesting a key from the device that directly manages keys includes but is not limited to: sending a first public key; and receiving a first ciphertext obtained by encrypting the key using the first public key, where the key is the key used to encrypt multimedia data.
[0141] Next, we'll use the second device as an example to illustrate the key acquisition process. The first device sends the first public key to the second device. Since the second device has authenticated the first device's device security, it determines that it is permitted to provide the key to the first device. The second device then encrypts the key using the first public key to produce a first ciphertext, which it then sends to the first device. Since the first ciphertext is encrypted using the first public key, and the first private key is the private key corresponding to the first public key, upon receiving the first ciphertext, the first device can decrypt it using the first private key to obtain the key. This decryption of the ciphertext data using the key yields the multimedia data.
[0142] In summary, the data processing method provided by the embodiment of the present application requires verification and authorization of the first device when there is a third-party device independent of the data acquisition device and the second device, that is, when the first device needs to obtain multimedia data. Only after the verification is passed can the first device obtain the multimedia data, so as to achieve data sharing while protecting the personal information of the target object, further explore the data value of the multimedia data, and realize efficient use of the data. Moreover, even if the verification process is executed through other platforms such as a third device, the third device cannot obtain the multimedia data and can only obtain the ciphertext data, which effectively reduces the possibility of data leakage of the multimedia data on the third device and further improves the security of data processing.
[0143] The above describes the data processing method of the embodiment of the present application. Corresponding to the above method, the embodiment of the present application also provides a data processing device. Figure 8 is a structural diagram of a data processing device provided by the embodiment of the present application. Based on the following multiple modules shown in Figure 8, the data processing device shown in Figure 8 can perform all or part of the operations shown in Figure 3 above. It should be understood that the device may include more additional modules than the modules shown or omit some of the modules shown therein, and the embodiment of the present application does not limit this. As shown in Figure 8, the device is applied to a data acquisition device, and the device includes:
[0144] An acquisition module 801 is used to acquire multimedia data collected by a data acquisition device;
[0145] Processing module 802 is used to encrypt or sign multimedia data based on identity information to obtain data processing results corresponding to the multimedia data. The identity information is determined based on the information used for authentication between the second device corresponding to the target object and the data acquisition device. The target object is the object using the data acquisition device. The data processing results are used for authorized devices to access multimedia data.
[0146] In one possible implementation, the identity information includes first identity information for identifying the data acquisition device and second identity information for identifying the second device. The processing module 802 is further used to encrypt the first identity information to obtain a first security ciphertext and send the first security ciphertext to the second device; when verifying the transmission security based on the first security ciphertext, receive the second security ciphertext returned by the second device, the second security ciphertext being encrypted based on the second identity information; decrypt the second security ciphertext, and verify whether the transmission channel between the data acquisition device and the second device is secure based on the decryption result.
[0147] In one possible implementation, the processing module 802 is configured to obtain a first key, which is obtained by negotiation with the second device based on identity information; encrypt multimedia data according to the first key to obtain ciphertext data, and use the ciphertext data as a data processing result.
[0148] In a possible implementation, the processing module 802 is configured to calculate a second public key and a second private key of the data acquisition device based on the identity information; and obtain the first key through negotiation based on the second public key, the second private key and the identity information.
[0149] In one possible implementation, the processing module 802 is used to obtain a second key of the data acquisition device, where the second key has not been authenticated by the second device corresponding to the target object; encrypt the multimedia data according to the second key to obtain ciphertext data corresponding to the multimedia data; sign the ciphertext data according to the identity information to obtain signature data corresponding to the ciphertext data; obtain a data processing result based on the signature data and the ciphertext data, and the signature data is used to verify whether the ciphertext data is abnormal.
[0150] In one possible implementation, the processing module 802 is used to obtain the third public key of the second device, encrypt the second key according to the third public key, and obtain the ciphertext parameter corresponding to the second key, and the ciphertext parameter is used to obtain the second key required to decrypt the ciphertext data; sign the ciphertext data and the ciphertext parameter according to the identity information to obtain the signature data corresponding to the ciphertext data and the ciphertext parameter, and obtain the data processing result based on the ciphertext data, the ciphertext parameter and the signature data.
[0151] In a possible implementation, the apparatus further includes: a sending module, configured to send a data processing result to a second device corresponding to the target object, where the data processing result is used by the second device to obtain multimedia data.
[0152] In a possible implementation, the data acquisition device is connected to a second device corresponding to the target object via a third device; and the data acquisition device performs authentication with the second device via the third device.
[0153] After obtaining multimedia data, the above-mentioned device will process the multimedia data based on the identity information. Since the identity information is the information used for authentication between the second device and the data acquisition device, the security is bidirectionally authenticated by the data acquisition device and the second device, and the reliability is high. The data processing results obtained based on the highly reliable identity information are highly secure.
[0154] The present application also provides another data processing device. FIG9 is a schematic diagram of the structure of a data processing device provided by an embodiment of the present application. Based on the following multiple modules shown in FIG9, the data processing device shown in FIG9 can perform all or part of the operations shown in FIG5 above. It should be understood that the device may include more additional modules than the modules shown or omit some of the modules shown therein, and the present application does not limit this. As shown in FIG9, the device is applied to a first device, and the device includes:
[0155] A sending module 901 is used to send an access request for multimedia data;
[0156] An acquisition module 902 is configured to, upon obtaining access rights to the multimedia data based on the access request, obtain ciphertext data corresponding to the multimedia data, the ciphertext data being obtained by encrypting or signing the multimedia data based on identity information, the identity information being determined based on information used for authentication between a second device corresponding to a target object and a data acquisition device for the multimedia data, where the target object is an object using the data acquisition device;
[0157] The decryption module 903 is used to decrypt the ciphertext data to obtain multimedia data.
[0158] In a possible implementation, the acquisition module 902 is configured to receive ciphertext data returned based on the access request.
[0159] In a possible implementation, the acquisition module 902 is configured to receive a first authorization flag returned based on an access request, where the first authorization flag indicates that acquisition of multimedia data is allowed; and request acquisition of ciphertext data according to the first authorization flag.
[0160] In one possible implementation, the acquisition module 902 is also used to receive re-encrypted data returned based on the access request, the re-encrypted data is obtained by encrypting the reference ciphertext according to the second authorization flag, the second authorization flag is generated according to the first public key, the first public key is the public key owned by the first device requesting multimedia data, and the reference ciphertext is the ciphertext obtained by encrypting the key of the ciphertext data; the decryption module 903 is used to obtain the key of the ciphertext data according to the decryption result of the re-encrypted data, and decrypt the ciphertext data according to the key to obtain the multimedia data.
[0161] In one possible implementation, the sending module 901 is also used to send the first public key; the acquisition module 902 is also used to receive a first ciphertext obtained by encrypting a key according to the first public key, where the key is the key used to encrypt multimedia data; the decryption module 903 is used to decrypt the first ciphertext according to the first private key corresponding to the first public key to obtain the key; and decrypt the ciphertext data according to the key to obtain multimedia data.
[0162] In one possible implementation, the access request is used to obtain device information of the first device requesting multimedia data, and the device information of the first device is used to determine whether to grant the first device permission to obtain multimedia data based on at least one device information, and the at least one device information is information of at least one device that has signed a data agreement, and the data agreement is used to obtain access rights to multimedia data.
[0163] In a possible implementation, the sending module 901 is configured to send an access request to a third device, the third device is connected to a second device corresponding to the target object, and the third device is configured to send the access request to the second device.
[0164] In a possible implementation, the identity information is used by the data acquisition device and the second device to negotiate to obtain a first key, and the ciphertext data is obtained by encrypting the multimedia data according to the first key.
[0165] In one possible implementation, identity information is used to sign the ciphertext data corresponding to the multimedia data, and the signature data obtained is used by the second device to verify whether the ciphertext data sent by the received data acquisition device is abnormal, and the second device is used to provide the ciphertext data to the first device.
[0166] In a possible implementation, the identity information includes first identity information for identifying the data acquisition device and second identity information for identifying the second device.
[0167] When the above-mentioned device needs to obtain multimedia data, it will first perform security verification and authorization. Only after the verification is passed can the device obtain the multimedia data, so as to realize data sharing while protecting the personal information of the target object, further explore the data value of multimedia data, and realize efficient use of data.
[0168] It should be understood that the devices provided in FIG. 8 or FIG. 9 above are merely examples of the division of the functional modules described above when implementing their functions. In actual applications, the functions described above can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the devices and method embodiments provided in the above embodiments are based on the same concept. The specific implementation process is detailed in the method embodiment and will not be repeated here.
[0169] Referring to FIG. 10 , FIG. 10 illustrates a schematic diagram of the structure of a network device 1000 provided in accordance with an exemplary embodiment of the present application. The network device 1000 illustrated in FIG. 10 is configured to execute the operations involved in the data processing method illustrated in FIG. 3 or FIG. 5 . The network device 1000 is, for example, a switch or router, and may be implemented using a general bus architecture.
[0170] As shown in FIG. 10 , a network device 1000 includes at least one processor 1001 , a memory 1003 , and at least one communication interface 1004 .
[0171] The processor 1001 is, for example, a general-purpose central processing unit (CPU), a digital signal processor (DSP), a network processor (NP), a graphics processing unit (GPU), a neural-network processing unit (NPU), a data processing unit (DPU), a microprocessor, or one or more integrated circuits for implementing the solution of the present application. For example, the processor 1001 includes an application-specific integrated circuit (ASIC), a programmable logic device (PLD) or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The PLD is, for example, a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. It can implement or execute the various logic blocks, modules, and circuits described in conjunction with the disclosure of the embodiments of the present application. The processor can also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and the like.
[0172] Optionally, network device 1000 also includes a bus. The bus is used to transmit information between the various components of network device 1000. The bus may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, for example. Buses can be categorized as address buses, data buses, control buses, and the like. For ease of illustration, FIG10 shows only one thick line, but this does not imply that there is only one bus or only one type of bus.
[0173] The memory 1003 is, for example, a read-only memory (ROM) or other type of static storage device that can store static information and instructions, or a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 1003 is, for example, independent and connected to the processor 1001 via a bus. The memory 1003 can also be integrated with the processor 1001.
[0174] The communication interface 1004 uses any transceiver-like device for communicating with other devices or communication networks. The communication network can be Ethernet, a radio access network (RAN), or a wireless local area network (WLAN). The communication interface 1004 can include a wired communication interface or a wireless communication interface. Specifically, the communication interface 1004 can be an Ethernet interface, a fast Ethernet (FE) interface, a gigabit Ethernet (GE) interface, an asynchronous transfer mode (ATM) interface, a wireless local area network (WLAN) interface, a cellular network communication interface, or a combination thereof. The Ethernet interface can be an optical interface, an electrical interface, or a combination thereof. In the embodiment of the present application, the communication interface 1004 can be used for the network device 1000 to communicate with other devices.
[0175] In a specific implementation, as an embodiment, the processor 1001 may include one or more CPUs, such as CPU0 and CPU1 shown in FIG10 . Each of these processors may be a single-core (single-CPU) processor or a multi-core (multi-CPU) processor. The processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0176] In a specific implementation, as an embodiment, the network device 1000 may include multiple processors, such as processor 1001 and processor 1005 shown in FIG10 . Each of these processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). The processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).
[0177] In a specific implementation, as an embodiment, network device 1000 may further include an output device and an input device. The output device communicates with processor 1001 and can display information in various ways. For example, the output device may be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector. The input device communicates with processor 1001 and can receive user input in various ways. For example, the input device may be a mouse, keyboard, touch screen device, or sensor device.
[0178] In some embodiments, the memory 1003 is used to store program code 1010 for executing the solution of the present application, and the processor 1001 can execute the program code 1010 stored in the memory 1003. That is, the network device 1000 can implement the data processing method provided by the method embodiment through the processor 1001 and the program code 1010 in the memory 1003. The program code 1010 may include one or more software modules. Optionally, the processor 1001 itself may also store program code or instructions for executing the solution of the present application.
[0179] In a specific embodiment, the network device 1000 of the embodiment of the present application may correspond to the computing device in the above-mentioned various method embodiments.
[0180] Among them, each step of the data processing method shown in Figure 3 or Figure 5 is completed by the hardware integrated logic circuit or software instructions in the processor of the network device 1000. The steps of the method disclosed in conjunction with the embodiments of the present application can be directly embodied as being executed by the hardware processor, or can be executed by a combination of hardware and software modules in the processor. The software module can be located in a storage medium mature in the art such as random access memory, flash memory, read-only memory, programmable read-only memory or electrically erasable programmable memory, registers, etc. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware. To avoid repetition, it will not be described in detail here.
[0181] Referring to FIG11 , FIG11 shows a schematic diagram of the structure of a network device 1100 provided in another exemplary embodiment of the present application. The network device 1100 shown in FIG11 is configured to perform all or part of the operations involved in the data processing method shown in FIG3 or FIG5 . The network device 1100 is, for example, a switch, a router, etc., and can be implemented using a general bus architecture.
[0182] As shown in FIG. 11 , the network device 1100 includes a main control board 1110 and an interface board 1130 .
[0183] The main control board (MCB), also known as the main processing unit (MPU) or route processor card, is used to control and manage various components in network device 1100, including routing calculations, device management, device maintenance, and protocol processing. MCB 1110 includes a central processing unit (CPU) 1111 and memory 1112.
[0184] Interface board 1130 is also known as a line processing unit (LPU), line card, or service board. It provides various service interfaces and implements data packet forwarding. Service interfaces include, but are not limited to, Ethernet interfaces and POS (Packet over SONET / SDH) interfaces. Ethernet interfaces, for example, are Flexible Ethernet Clients (FlexE Clients). Interface board 1130 includes a central processing unit (CPU) 1131, a network processor (NPU) 1132, a forwarding table memory 1134, and a physical interface card (PIC) 1133.
[0185] The central processing unit 1131 on the interface board 1130 is used to control and manage the interface board 1130 and communicate with the central processing unit 1111 on the main control board 1110 .
[0186] The network processor 1132 is used to implement message forwarding processing. The network processor 1132 can be in the form of a forwarding chip. The forwarding chip can be a network processor (NP). In some embodiments, the forwarding chip can be implemented using an application-specific integrated circuit (ASIC) or a field programmable gate array (FPGA). Specifically, the network processor 1132 is used to forward received messages based on the forwarding table stored in the forwarding entry memory 1134. If the destination address of the message is the address of the network device 1100, the message is sent to the CPU (such as the central processing unit 1131) for processing. If the destination address of the message is not the address of the network device 1100, the next hop and outgoing interface corresponding to the destination address are searched in the forwarding table based on the destination address, and the message is forwarded to the outgoing interface corresponding to the destination address. Processing of uplink messages can include processing the message inbound interface and forwarding table lookup; processing of downlink messages can include forwarding table lookup, etc. In some embodiments, the central processing unit can also perform the functions of the forwarding chip, such as implementing software forwarding based on a general-purpose CPU, thereby eliminating the need for a forwarding chip in the interface board.
[0187] Physical interface card 1133 implements physical layer interconnection. Raw traffic enters interface board 1130 through this card, and processed packets are sent from this physical interface card 1133. Physical interface card 1133, also known as a daughter card, can be installed on interface board 1130. It converts optical and electrical signals into packets, performs a validity check on these packets, and then forwards them to network processor 1132 for processing. In some embodiments, central processing unit 1131 can also perform the functions of network processor 1132, such as implementing software forwarding based on a general-purpose CPU, eliminating the need for network processor 1132 in physical interface card 1133.
[0188] Optionally, network device 1100 includes multiple interface boards. For example, network device 1100 further includes interface board 1140. Interface board 1140 includes a central processing unit 1141, a network processor 1142, a forwarding table entry memory 1144, and a physical interface card 1143. The functions and implementation of each component in interface board 1140 are the same as or similar to those of interface board 1130 and are not described in detail here.
[0189] Optionally, network device 1100 further includes a switching fabric board 1120. Switching fabric board 1120 may also be referred to as a switch fabric unit (SFU). If network device 1100 includes multiple interface boards, switching fabric board 1120 is used to exchange data between the interface boards. For example, interface board 1130 and interface board 1140 can communicate via switching fabric board 1120.
[0190] The main control board 1110 is coupled to the interface board. For example, the main control board 1110, the interface board 1130, the interface board 1140, and the switching network board 1120 are connected to the system backplane via a system bus to achieve intercommunication. In one possible implementation, an inter-process communication (IPC) channel is established between the main control board 1110 and the interface boards 1130 and 1140, and communication is performed between the main control board 1110 and the interface boards 1130 and 1140 via the IPC channel.
[0191] Logically, network device 1100 includes a control plane and a forwarding plane. The control plane includes a main control board 1110 and a central processing unit 1111. The forwarding plane includes various components that perform forwarding, such as a forwarding table entry memory 1134, physical interface cards 1133, and a network processor 1132. The control plane performs functions such as routing, generating forwarding tables, processing signaling and protocol messages, and configuring and maintaining the network device's status. The control plane sends the generated forwarding tables to the forwarding plane. On the forwarding plane, the network processor 1132 forwards messages received by the physical interface card 1133 based on the forwarding tables sent by the control plane. The forwarding tables sent by the control plane can be stored in the forwarding table entry memory 1134. In some embodiments, the control plane and forwarding plane can be completely separate and not located on the same network device.
[0192] It's worth noting that there may be one or more main control boards (SPUs), which can include both active and standby SPUs. There may also be one or more interface boards. The higher the network device's data processing capabilities, the more interface boards it provides. Interface boards can also have one or more physical interface cards. There may be no SPUs, one or more SPUs, and multiple SPUs can provide load balancing and redundancy. In a centralized forwarding architecture, network devices may not require SPUs; the interface boards handle service data processing for the entire system. In a distributed forwarding architecture, network devices may have at least one SPU, which enables data exchange between multiple interface boards, providing high-capacity data exchange and processing capabilities. Therefore, network devices with distributed architectures have greater data access and processing capabilities than those with centralized architectures. Alternatively, a network device can consist of a single card, without a switching fabric board (SFB), integrating the functions of the interface board and the main control board. In this case, the central processing unit (CPU) on the interface board and the CPU on the main control board can be combined into a single CPU on this card, performing the combined functions of the two. This type of network device has lower data exchange and processing capabilities (for example, low-end network devices such as switches or routers). The specific architecture used depends on the specific network deployment scenario and is not specified here.
[0193] In a specific embodiment, the network device 1100 corresponds to the data processing apparatus shown in Figure 8 or Figure 9. In some embodiments, the processing module 802 in the processing and forwarding apparatus shown in Figure 8 corresponds to the central processing unit 1111 or the network processor 1132 in the network device 1100.
[0194] An embodiment of the present application further provides a communication device, comprising: a transceiver, a memory, and a processor. The transceiver, the memory, and the processor communicate with each other via an internal connection path. The memory is used to store instructions, and the processor is used to execute the instructions stored in the memory to control the transceiver to receive signals and control the transceiver to send signals. When the processor executes the instructions stored in the memory, the processor executes a data processing method.
[0195] It should be understood that the processor may be a CPU, or other general-purpose processor, DSP, ASIC, FPGA or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. It is worth noting that the processor may be a processor supporting the Advanced Reduced Instruction Set Machine (ARM) architecture.
[0196] Furthermore, in an optional embodiment, the memory may include a read-only memory and a random access memory, and provide instructions and data to the processor. The memory may also include a non-volatile random access memory. For example, the memory may also store device type information.
[0197] The memory may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a ROM, a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an EEPROM, or a flash memory. The volatile memory may be a RAM, which is used as an external cache. By way of example but not limitation, many forms of RAM are available. For example, static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).
[0198] The present application also provides a data processing device, including a processor configured to load and execute at least one instruction to enable the data processing device to implement the data processing method provided in the present application. Optionally, the device also includes a memory coupled to the processor and configured to store the at least one instruction.
[0199] An embodiment of the present application also provides a data processing system, which includes a data acquisition device and a first device, and the data acquisition device and the first device are used to execute the data processing method provided in the embodiment of the present application.
[0200] An embodiment of the present application further provides a computer-readable storage medium, in which at least one instruction is stored. The instruction is loaded and executed by a processor to enable a computer to implement any of the data processing methods described above.
[0201] The embodiments of the present application further provide a computer program (product), which, when executed by a computer, can enable a processor or computer to execute the corresponding steps and / or processes in the above method embodiments.
[0202] An embodiment of the present application also provides a chip, which includes a processor for calling and executing instructions stored in a memory from the memory, so that a communication device equipped with the chip executes any of the data processing methods described above.
[0203] An embodiment of the present application also provides another chip, including: an input interface, an output interface, a processor and a memory, wherein the input interface, the output interface, the processor and the memory are connected via an internal connection path, and the processor is used to execute the code in the memory. When the code is executed, the processor is used to execute any of the data processing methods described above.
[0204] In the above embodiments, all or part of the embodiments may be implemented by software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described herein are generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated therein. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive).
[0205] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, storage, display, etc.), and signals involved in this application are all authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data must comply with the relevant laws, regulations, and standards of the relevant countries and regions. For example, the multimedia data involved in this application was obtained with full authorization.
[0206] Those skilled in the art will appreciate that the various method steps and modules described in conjunction with the embodiments disclosed herein can be implemented in software, hardware, firmware, or any combination thereof. In order to clearly illustrate the interchangeability of hardware and software, the steps and components of each embodiment have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0207] Those skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware, or may be accomplished by a program to instruct the relevant hardware, and the program may be stored in a computer-readable storage medium, and the above-mentioned storage medium may be a read-only memory, a disk or an optical disk, etc.
[0208] When software is used for implementation, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer program instructions. As an example, the method of the embodiment of the present application can be described in the context of a machine executable instruction, and the machine executable instruction is such as included in the program module executed in the device on the real or virtual processor of the target. Generally speaking, a program module includes a routine, a program, a library, an object, a class, a component, a data structure, etc., which performs a specific task or realizes a specific abstract data structure. In various embodiments, the function of the program module can be merged or split between the described program modules. The machine executable instruction for the program module can be executed in a local or distributed device. In a distributed device, the program module can be located in both a local and a remote storage medium.
[0209] The computer program code for realizing the method for the embodiment of the application can be written in one or more programming languages.These computer program codes can be provided to the processor of general-purpose computer, special-purpose computer or other programmable data processing device, so that program code, when being executed by computer or other programmable data processing device, causes the function / operation specified in flow chart and / or block diagram to be implemented.Program code can be executed completely on computer, partly on computer, as independent software package, partly on computer and partly on remote computer or completely on remote computer or server.
[0210] In the context of the embodiments of the present application, computer program code or related data may be carried by any suitable carrier to enable a device, apparatus, or processor to perform the various processes and operations described above. Examples of carriers include signals, computer-readable media, and the like.
[0211] Examples of signals may include electrical, optical, radio, acoustic or other forms of propagated signals, such as carrier waves, infrared signals, etc.
[0212] A machine-readable medium may be any tangible medium that contains or stores a program for or in connection with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination thereof. More detailed examples of machine-readable storage media include an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical storage device, a magnetic storage device, or any suitable combination thereof.
[0213] Those skilled in the art will clearly understand that, for the sake of convenience and brevity of description, the specific working processes of the above-described systems, devices, and modules can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0214] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the modules is merely a logical function division. In actual implementation, there may be other division methods, such as multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or modules, or can be electrical, mechanical or other forms of connection.
[0215] Modules described as separate components may or may not be physically separate, and components displayed as modules may or may not be physical modules, that is, they may be located in one place or distributed across multiple network modules. Some or all of the modules may be selected according to actual needs to achieve the purpose of the embodiments of the present application.
[0216] In addition, the functional modules in the various embodiments of the present application may be integrated into a processing module, or each module may exist physically separately, or two or more modules may be integrated into a single module. The above-mentioned integrated modules may be implemented in the form of hardware or software functional modules.
[0217] If the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0218] In this application, the terms "first", "second", etc. are used to distinguish between identical or similar items that have substantially the same effects and functions. It should be understood that there is no logical or temporal dependency between "first", "second", and "nth", nor is there any limitation on quantity or order of execution. It should also be understood that although the following description uses the terms first, second, etc. to describe various elements, these elements should not be limited by the terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of the various described examples, a first image may be referred to as a second image, and similarly, a second image may be referred to as a first image. Both the first image and the second image may be images, and in some cases, may be separate and different images.
[0219] It should also be understood that in the various embodiments of the present application, the size of the serial number of each process does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0220] In this application, the term "at least one" means one or more, and the term "plurality" means two or more. For example, "plurality of second messages" means two or more second messages. The terms "system" and "network" are often used interchangeably herein.
[0221] It should be understood that the terminology used in the description of the various examples herein is for the purpose of describing particular examples only and is not intended to be limiting. As used in the description of the various examples and the appended claims, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise.
[0222] It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the listed items. The term "and / or" describes an association between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A exists alone, A and B exist simultaneously, or B exists alone. Furthermore, the character " / " in this application generally indicates that the associated objects are in an "or" relationship.
[0223] It will also be understood that the term “comprise” (also known as “includes,” “including,” “comprises,” and / or “comprising”) when used in this specification specifies the presence of stated features, integers, steps, operations, elements, and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0224] It should also be understood that the terms “if” and “if” may be interpreted to mean “when” or “upon” or “in response to determining” or “in response to detecting.” Similarly, the phrases “if it is determined that ” or “if [stated condition or event] is detected” may be interpreted to mean “upon determining ” or “in response to determining ” or “upon detecting [stated condition or event]” or “in response to detecting [stated condition or event],” depending on the context.
[0225] It should be understood that determining B based on A does not mean determining B solely based on A; B can also be determined based on A and / or other information. It should also be understood that references throughout this specification to "one embodiment," "an embodiment," or "a possible implementation" mean that specific features, structures, or characteristics associated with an embodiment or implementation are included in at least one embodiment of this application. Therefore, the appearance of "in one embodiment," "in an embodiment," or "a possible implementation" throughout this specification does not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
Claims
1. A data processing method, characterized in that: The method is applied to a first device, and the method includes: Sending a request for access to multimedia data; In the case where the access right to the multimedia data is obtained based on the access request, obtaining ciphertext data corresponding to the multimedia data, the ciphertext data being obtained by encrypting or signing the multimedia data according to identity information, the identity information being determined based on information used for authentication between a second device corresponding to a target object and a data acquisition device for the multimedia data, the target object being an object using the data acquisition device; The ciphertext data is decrypted to obtain the multimedia data.
2. The method according to claim 1, characterized in that: The obtaining of ciphertext data corresponding to the multimedia data includes: The encrypted data returned based on the access request is received.
3. The method according to claim 1, characterized in that The obtaining of ciphertext data corresponding to the multimedia data includes: receiving a first authorization flag returned based on the access request, wherein the first authorization flag indicates that access to the multimedia data is allowed; The ciphertext data is obtained according to the first authorization flag.
4. The method according to any one of claims 1 to 3, characterized in that: Before decrypting the ciphertext data, the method further comprises: receiving re-encrypted data returned based on the access request, the re-encrypted data being obtained by encrypting a reference ciphertext according to a second authorization flag, the second authorization flag being generated according to a first public key, the first public key being a public key owned by a first device requesting the multimedia data, and the reference ciphertext being a ciphertext obtained by encrypting the key of the ciphertext data; The decrypting the ciphertext data to obtain the multimedia data includes: The key of the ciphertext data is obtained according to the decryption result of the re-encrypted data, and the ciphertext data is decrypted according to the key to obtain the multimedia data.
5. The method according to any one of claims 1 to 3, characterized in that: Before decrypting the ciphertext data, the method further comprises: Send the first public key; receiving a first ciphertext obtained by encrypting a key according to the first public key, where the key is a key used to encrypt the multimedia data; The decrypting the ciphertext data to obtain the multimedia data includes: Decrypting the first ciphertext according to a first private key corresponding to the first public key to obtain the key; The ciphertext data is decrypted according to the key to obtain the multimedia data.
6. The method according to any one of claims 1 to 5, characterized in that: The access request is used to obtain device information of the first device requesting the multimedia data, and the device information of the first device is used to determine whether to grant the first device permission to obtain the multimedia data based on at least one device information, and the at least one device information is information of at least one device that has signed a data protocol, and the data protocol is used to obtain access rights to the multimedia data.
7. The method according to any one of claims 1 to 6, characterized in that: The sending of the access request to the multimedia data comprises: The access request is sent to a third device, the third device is connected to a second device corresponding to the target object, and the third device is used to send the access request to the second device.
8. The method according to any one of claims 1 to 7, characterized in that: The identity information is used by the data acquisition device and the second device to negotiate to obtain a first key, and the ciphertext data is obtained by encrypting the multimedia data according to the first key.
9. The method according to any one of claims 1 to 7, characterized in that: The identity information is used to sign the ciphertext data corresponding to the multimedia data. The signature data obtained by the signature is used by the second device to verify whether the ciphertext data sent by the data acquisition device is abnormal. The second device is used to provide the ciphertext data to the first device.
10. The method according to any one of claims 1 to 9, characterized in that: The identity information includes first identity information for identifying the data acquisition device and second identity information for identifying the second device.
11. A data processing method, characterized in that: The method is applied to a data acquisition device, and the method comprises: Acquiring multimedia data collected by a data collection device; The multimedia data is encrypted or signed based on the identity information to obtain a data processing result corresponding to the multimedia data, the identity information is determined based on the information used for authentication between the second device corresponding to the target object and the data acquisition device, the target object is the object using the data acquisition device, and the data processing result is used for authorized devices to access the multimedia data.
12. The method according to claim 11, characterized in that The identity information includes first identity information for identifying the data acquisition device and second identity information for identifying the second device. Before encrypting or signing the multimedia data based on the identity information and obtaining the data processing result corresponding to the multimedia data, the method further includes: Encrypting the first identity information to obtain a first security ciphertext, and sending the first security ciphertext to the second device; In a case where transmission security is verified based on the first security ciphertext, receiving a second security ciphertext returned by the second device, where the second security ciphertext is encrypted based on the second identity information; Decrypt the second security ciphertext, and verify whether the transmission channel between the data acquisition device and the second device is secure based on the decryption result.
13. The method according to claim 11 or 12, characterized in that: The encrypting or signing the multimedia data based on the identity information to obtain a data processing result corresponding to the multimedia data includes: Acquire a first key, where the first key is obtained through negotiation with the second device based on the identity information; The multimedia data is encrypted according to the first key to obtain ciphertext data, and the ciphertext data is used as the data processing result.
14. The method according to claim 13, characterized in that The obtaining of the first key comprises: Calculate and obtain a second public key and a second private key of the data acquisition device based on the identity information; The first key is obtained through negotiation according to the second public key, the second private key and the identity information.
15. The method according to claim 11 or 12, characterized in that: The encrypting or signing the multimedia data based on the identity information to obtain a data processing result corresponding to the multimedia data includes: Acquire a second key of the data acquisition device, where the second key has not been authenticated by a second device corresponding to the target object; Encrypting the multimedia data according to the second key to obtain ciphertext data corresponding to the multimedia data; The ciphertext data is signed according to the identity information to obtain signature data corresponding to the ciphertext data, and the data processing result is obtained according to the signature data and the ciphertext data. The signature data is used to verify whether the ciphertext data is abnormal.
16. The method according to claim 15, characterized in that The step of signing the ciphertext data according to the identity information to obtain signature data corresponding to the ciphertext data, and obtaining the data processing result according to the signature data and the ciphertext data includes: Obtaining a third public key of the second device, encrypting the second key according to the third public key, and obtaining a ciphertext parameter corresponding to the second key, wherein the ciphertext parameter is used to obtain a second key required for decrypting the ciphertext data; The ciphertext data and the ciphertext parameters are signed according to the identity information to obtain signature data corresponding to the ciphertext data and the ciphertext parameters, and the data processing result is obtained according to the ciphertext data, the ciphertext parameters and the signature data.
17. The method according to any one of claims 11 to 16, characterized in that: After obtaining the data processing result corresponding to the multimedia data, the method further includes: Send the data processing result to the second device corresponding to the target object, and the data processing result is used by the second device Get multimedia data.
18. The method according to any one of claims 11 to 17, characterized in that: The data acquisition device is connected to a second device corresponding to the target object via a third device; the data acquisition device is authenticated with the second device via the third device.
19. A data processing device, characterized in that: The device comprises: A transceiver module, used to perform operations related to receiving and / or sending in any of the methods described in claims 1-10; A processing module, used to perform other operations other than the operations related to receiving and / or sending in any one of the methods described in claims 1-10.
20. A data processing device, characterized in that: The device comprises: A transceiver module, used to perform operations related to receiving and / or sending in any of the methods described in claims 11-18; A processing module, used to perform other operations other than the operations related to receiving and / or sending in any one of the methods described in claims 11-18.
21. A data processing device, characterized in that: The device includes a processor, which is used to load and execute at least one instruction so that the data processing device implements the data processing method as described in any one of claims 1-10, or implements the data processing method as described in any one of claims 11-18.
22. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores at least one instruction, and the instruction is loaded and executed by the processor to implement the data processing method as described in any one of claims 1-10, or to implement the data processing method as described in any one of claims 11-18.
23. A chip, characterized in that: The chip includes a processor, which is used to run program instructions or codes, so that a device containing the chip executes the data processing method as described in any one of claims 1-10, or executes the data processing method as described in any one of claims 11-18.
Citation Information
Patent Citations
Audio and video monitor method, system, monitoring server and computer medium
CN108989034A
Multimedia data encryption processing method and device
CN111586066A
Data sharing method and related equipment
CN112311746A
Multimedia data storage method, computer equipment and storage device
CN115834035A
Video surveillance system
EP3282695A1
Cited By
Universe cross-system interface authorization authentication method, device, equipment and medium
CN121744391A