Bitstream, bitstream signing method and detection method
By limiting the maximum number of access units in the positioning stream segment and independently storing the summary data of each access unit, the problem of low signature or authentication efficiency caused by unknown cache space is solved, and more efficient audio and video content authentication is achieved.
Patent Information
- Application Number
- PCT/CN2024/113698
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-24
- Filing Date
- 2024-08-21
- Publication Date
- 2025-08-07
AI Technical Summary
During the transmission of audio and video content, the prior art cannot determine the cache space size, resulting in low bitstream signature or authentication efficiency.
The computing device obtains the security parameter set and authentication data, limits the maximum number of access units in the positioning stream segment, clearly confirms the maximum space of the authentication data, and independently stores the summary data of each access unit in the bitstream, ensuring that the authentication end can independently authenticate each access unit.
It improves the efficiency of bitstream signature or authentication, and can effectively authenticate other access units when some access units are lost, enhancing the fault tolerance of authentication data and the accuracy of cache space.
Smart Images

Figure CN2024113698_07082025_PF_FP_ABST
Abstract
Description
A bit stream, bit stream signature and detection method
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on December 12, 2023, with application number 202311725386.8 and application name “A code stream, a signature of a code stream and a detection method”, and claims priority to the Chinese patent application filed with the State Intellectual Property Office on January 24, 2024, with application number 202410104632.6 and application name “A bit stream, a bit stream signature and a detection method”, all contents of which are incorporated by reference into this application. Technical Field
[0002] The embodiments of the present application relate to the field of media technology, and in particular to a bitstream, a bitstream signature, and a detection method. Background Art
[0003] Many audio and video encoding and decoding scenarios (for example, surveillance, live broadcast, on-demand, etc.) have certain requirements for the authenticity and integrity of audio and video content. Therefore, in order to ensure the security of audio and video content during transmission and prevent the audio and video content from being tampered with during transmission, the audio and video content needs to be signed.
[0004] Currently, the process for signing a bitstream involves generating digests corresponding to each access unit in the bitstream, then signing the digests using a digital signature algorithm, and writing the signatures into the bitstream. However, during the signing or authentication process, the signatures and digests corresponding to multiple access units are stored in a single area, the size of which is unknown. This makes it impossible to determine the size of the cache space reserved for caching signatures and digests when signing or authenticating the bitstream, resulting in low efficiency for bitstream signing or authentication.
[0005] Summary of the Invention
[0006] The present application provides a bitstream, a bitstream signature, and a detection method to solve the problem that, during the signing or authentication process, signatures and digests corresponding to multiple access units are stored in an area whose size is unknown. As a result, when authenticating audio and video content, the size of the reserved cache space cannot be determined to cache the signatures and digests, resulting in low efficiency in audio and video content authentication.
[0007] This application adopts the following technical solution.
[0008] In the first aspect, an embodiment of the present application provides a bitstream signature method. The bitstream signature method is executed by a computing device or a chip in a computing device, such as a mobile phone or a computer. Exemplarily, the method includes: the computing device obtains a security parameter set and authentication data, and then outputs a bitstream, which includes a security parameter set and authentication data. The security parameter set includes a hash period, which is used to indicate the maximum number of access units included in a bitstream segment, and the authentication data includes signature data and a summary of each access unit in a group of access units. The signature data is obtained by signing according to the summary of each access unit in a group of access units, and a group of access units includes at least one access unit in a bitstream segment.
[0009] In this application, the computing device independently generates summary data for each access unit and adds the summary data of each access unit to the bitstream. In this way, the authentication end can independently authenticate each access unit; therefore, in the event that some access units are lost (frame loss), other access units can also be authenticated. In addition, by limiting the maximum number of access units in the bitstream segment, the computing device can limit the amount of summary data of access units included in an authentication data, and further limit the maximum space occupied by an authentication data. This is conducive to clarifying the maximum space occupied by the authentication data, reserving cache space for the authentication data more accurately, and improving the efficiency of signing or authenticating the bitstream.
[0010] In one possible implementation, the authentication data is located after the last access unit in decoding order in a group of access units associated with the authentication data, and is located before the authentication data corresponding to the access unit in the next hash cycle.
[0011] In this application, by limiting the position of authentication data in the bitstream, the scope of authentication data is better determined. This avoids the problem that the authentication data corresponding to a group of access units exceeds the above range, resulting in the inability to find the corresponding authentication data when authenticating the aforementioned group of access units, and thus rendering the group of access units untrustworthy and subsequently discarded, which is conducive to improving the availability of access units.
[0012] In a possible implementation, the security parameter set further includes: indication information, where the indication information is used to indicate the number of authentication data contained within the scope of the security parameter set, where the scope of the security parameter set is the random access segment in the bitstream where the security parameter set is located.
[0013] In this application, by defining indication information in the security parameter set, the amount of authentication data that should be within the scope of the security parameter set is clarified. Then, during authentication, the amount of authentication data that should be received can be compared with the actual amount received to efficiently detect the loss of authentication data, thereby improving the efficiency of authentication data loss detection.
[0014] In a possible implementation, the authentication data carries an identifier, which occupies M bits, where M is an integer greater than or equal to 2, and the identifier is used to distinguish consecutive 2M-power authentication data in the bit stream.
[0015] In the present application, since the identifier of the authentication data occupies M bits, it is possible to distinguish consecutive 2M authentication data in the bit stream, which is beneficial to improving the fault tolerance of the position of the authentication data in the bit stream, that is, there can be more other authentication units between the authentication data and a group of access units corresponding to the authentication data without affecting the authentication data for authenticating the aforementioned group of access units.
[0016] In one possible implementation, there are P access units between the authentication data and the last access unit in the decoding order of the set of access units associated with the authentication data; where 0≤P≤(2 M -1)*Q, where Q is the maximum number of hash cycle indications.
[0017] In the second aspect, an embodiment of the present application also provides a bitstream signature method. The bitstream signature method is executed by a computing device or a chip in a computing device, such as a mobile phone or a computer. Exemplarily, the method includes: the computing device obtains a security parameter set and authentication data, and then outputs a security parameter set. The bitstream includes a security parameter set and authentication data. The security parameter set includes indication information, which is used to indicate the number of authentication data contained within the scope of the security parameter set. The scope of the security parameter set is the random access segment in the bitstream where the security parameter set is located. The authentication data includes signature data and a summary of each access unit in a group of access units. The signature data is obtained by signing according to the summary of each access unit in a group of access units.
[0018] In a possible implementation, the security parameter set further includes a hash period, where the hash period is used to indicate the maximum number of access units included in a bitstream segment.
[0019] In one possible implementation, the authentication data is located after the last access unit in decoding order in a group of access units associated with the authentication data, and is located before the authentication data corresponding to the access unit in the next hash cycle.
[0020] In a possible implementation, the authentication data carries an identifier, the identifier occupies M bits, where M is an integer greater than or equal to 2, and the identifier is used to distinguish consecutive 2M-power authentication data in the bit stream.
[0021] In one possible implementation, there are P access units between the authentication data and the last access unit in the decoding order of the set of access units associated with the authentication data; where 0≤P≤(2M -1)*Q, where Q is the maximum number of hash cycle indications.
[0022] For more possible implementations of the second aspect, reference may be made to the description of the first aspect or any possible implementation in the first aspect, which will not be elaborated here.
[0023] In a third aspect, embodiments of the present application provide a bitstream. The bitstream includes multiple bitstream segments, authentication data, and a security parameter set. The security parameter set includes a hash period, which indicates the maximum number of access units included in a bitstream segment. The authentication data includes signature data and a digest of each access unit in a set of access units. The signature data is obtained by signing the digest of each access unit in the set of access units, where the set of access units includes at least one access unit in a bitstream segment.
[0024] In one possible implementation, the authentication data is located after the last access unit in decoding order in a group of access units associated with the authentication data, and is located before the authentication data corresponding to the access unit in the next hash cycle.
[0025] In a possible implementation, the security parameter set further includes: indication information, where the indication information is used to indicate the number of authentication data contained within the scope of the security parameter set, where the scope of the security parameter set is the random access segment in the bitstream where the security parameter set is located.
[0026] In a possible implementation, the authentication data carries an identifier, the identifier occupies M bits, where M is an integer greater than or equal to 2, and the identifier is used to distinguish consecutive 2M-power authentication data in the bit stream.
[0027] In one possible implementation, there are P access units between the authentication data and the last access unit in the decoding order of the set of access units associated with the authentication data; where 0≤P≤(2 M -1)*Q, where Q is the maximum number of hash cycle indications.
[0028] Fourthly, embodiments of the present application further provide a bitstream. The bitstream includes: multiple bitstream segments, authentication data, and a security data set. The security parameter set includes indication information, which is used to indicate the number of authentication data items contained within the scope of the security parameter set. The scope of the security parameter set is the random access segment in the bitstream where the security parameter set is located. The authentication data includes signature data and a digest of each access unit in a set of access units. The signature data is obtained by signing the digest of each access unit in the set of access units. The set of access units includes at least one access unit in a bitstream segment.
[0029] In a possible implementation, the security parameter set includes a hash period, and the hash period is used to indicate the maximum number of access units included in a bitstream segment.
[0030] In one possible implementation, the authentication data is located after the last access unit in decoding order in a group of access units associated with the authentication data, and is located before the authentication data corresponding to the access unit in the next hash cycle.
[0031] In a possible implementation, the authentication data carries an identifier, the identifier occupies M bits, where M is an integer greater than or equal to 2, and the identifier is used to distinguish consecutive 2M-power authentication data in the bit stream.
[0032] In one possible implementation, there are P access units between the authentication data and the last access unit in the decoding order of the set of access units associated with the authentication data; where 0≤P≤(2 M -1)*Q, where Q is the maximum number of hash cycle indications.
[0033] For more possible implementations of the fourth aspect, reference may be made to the description of the third aspect or any possible implementation in the third aspect, which will not be elaborated here.
[0034] In a fifth aspect, the present application provides a bitstream detection method. The bitstream detection method is executed by a computing device or a chip in the computing device, such as a mobile phone or a computer. Exemplarily, the method includes: the computing device obtains a security parameter set and authentication data in the bitstream, and if there is an access unit participating in the signature in a hash cycle, the authentication data is detected in the next hash cycle along the bitstream decoding order direction of the current hash cycle, and then if the authentication data is not detected, it is determined that the authentication data is lost, and if the authentication data is detected, it is determined that the authentication data is not lost. The security parameter set includes a hash cycle, and the hash cycle is used to indicate the maximum number of access units included in a bitstream segment. The authentication data includes signature data and a summary of each access unit in a group of access units, and the signature data is obtained by signing according to the summary of each access unit in a group of access units, and a group of access units includes at least one access unit in a bitstream segment.
[0035] In one possible implementation, if an access unit participating in the signature exists in a group of access units, the authentication data is detected in a bit stream that is arranged after the last first access unit in the decoding order in the group of access units, and before a second access unit that is arranged after the first access unit in the decoding order along the bit stream; X access units are included between the second access unit and the first access unit, where X is the maximum number of hash cycle indications.
[0036] For more information about the authentication data or security parameter set, please refer to the description of the authentication data or security parameter set in the first aspect above, which will not be repeated here.
[0037] In a sixth aspect, the present application provides a bitstream detection method. The bitstream detection method is executed by a computing device or a chip within the computing device, such as a mobile phone or computer. Exemplarily, the method includes: the computing device obtains a security parameter set and authentication data from the bitstream. If an access unit participating in the signature exists in a hash cycle, the authentication data is detected in the 2M-th power minus 1 hash cycle following the current hash cycle in the bitstream decoding order. If no authentication data is detected, the authentication data is determined to be lost; if authentication data is detected, the authentication data is determined to be not lost. The security parameter set includes a hash cycle, which indicates the maximum number of access units included in a bitstream segment. The authentication data includes signature data and a digest of each access unit in a group of access units. The signature data is signed based on the digest of each access unit in the group of access units. The authentication data carries an identifier, which occupies M bits, where M is an integer greater than or equal to 2. The identifier is used to distinguish consecutive 2M-th power authentication data in the bitstream. A group of access units includes at least one access unit in a bitstream segment.
[0038] In a possible implementation, if a group of access units includes an access unit that participates in the signature, the authentication data is detected in a bitstream that is arranged after the last first access unit in the decoding order of the group of access units, and before the second access unit that is arranged after the first access unit in the decoding order of the bitstream; there are N access units between the second access unit and the first access unit, where N is N=(2 M -1)*Q, where Q is the maximum number of hash cycle indications.
[0039] For more information about the authentication data or security parameter set, please refer to the description of the authentication data or security parameter set in the first aspect above, which will not be repeated here.
[0040] In a seventh aspect, the present application provides a bitstream detection method. The bitstream detection method is executed by a computing device or a chip in the computing device, such as a mobile phone or a computer. Exemplarily, the method includes: the computing device obtains the security parameter set in the bitstream and the number of authentication data within the scope of the security parameter set, and then determines the loss of authentication data based on the indication information and the number of authentication data within the scope of the security parameter set. The scope of the security parameter set is the random access segment in the bitstream where the security parameter set is located, and the security data set includes indication information, which is used to indicate the number of authentication data that should be included in the scope of the security parameter set.
[0041] In one possible implementation, the computing device determines the loss of authentication data based on the indication information and the number of authentication data within the scope of the security parameter set, including: if the number of authentication data indicated by the indication information is consistent with the number of authentication data in the security parameter set, then the authentication data is not lost; if the number of authentication data indicated by the indication information is inconsistent with the number of authentication data in the security parameter set, then the authentication data is lost.
[0042] For more information about the authentication data or security parameter set, please refer to the description of the authentication data or security parameter set in the first aspect above, which will not be repeated here.
[0043] In an eighth aspect, the present application provides a bitstream signature device. The bitstream signature device includes a module for executing the method of the first aspect or any possible implementation of the first aspect, or the bitstream signature device includes a module for executing the method of the second aspect or any possible implementation of the second aspect.
[0044] In a ninth aspect, the present application provides a bitstream detection device. The bitstream detection device includes a module for executing the method of the fifth aspect or any possible implementation of the fifth aspect, or the bitstream detection device includes a module for executing the method of the sixth aspect or any possible implementation of the sixth aspect, or the bitstream detection device includes a module for executing the method of the seventh aspect or any possible implementation of the seventh aspect.
[0045] In a tenth aspect, the present application provides a signature and authentication system, which includes a signature end and an authentication end. The signature end is used to execute the bitstream signature method in the first aspect or any possible implementation of the first aspect, or to execute the bitstream signature method in the second aspect or any possible implementation of the second aspect. The authentication end is used to execute the bitstream detection method in the fifth aspect or any possible implementation of the fifth aspect, or to execute the bitstream detection method in the sixth aspect or any possible implementation of the sixth aspect, or to execute the bitstream detection method in the seventh aspect or any possible implementation of the seventh aspect.
[0046] In an eleventh aspect, an embodiment of the present application provides a computing device, comprising: a memory and a processor; the memory storing program instructions, which, when executed by the processor, causes the computing device to execute the bitstream signature method of the first aspect or any possible implementation of the first aspect, or the bitstream signature method of the second aspect or any possible implementation of the second aspect, or the bitstream detection method of the fifth aspect or any possible implementation of the fifth aspect, or the bitstream detection method of the sixth aspect or any possible implementation of the sixth aspect, or the bitstream detection method of the seventh aspect or any possible implementation of the seventh aspect.
[0047] In a twelfth aspect, an embodiment of the present application provides a chip, comprising one or more interface circuits and one or more processors; the one or more processors receive or send data through the one or more interface circuits, and when the one or more processors execute computer instructions, the steps of the bitstream signature method in the first aspect or any possible implementation of the first aspect are executed, or the steps of the bitstream signature method in the second aspect or any possible implementation of the second aspect are executed, or the steps of the bitstream detection method in the fifth aspect or any possible implementation of the fifth aspect are executed, or the steps of the bitstream detection method in the sixth aspect or any possible implementation of the sixth aspect are executed, or the steps of the bitstream detection method in the seventh aspect or any possible implementation of the seventh aspect are executed.
[0048] In a thirteenth aspect, an embodiment of the present application provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, which, when running on a computer or a processor, causes the computer or processor to execute the bitstream signature method in the first aspect or any possible implementation of the first aspect, or the bitstream signature method in the second aspect or any possible implementation of the second aspect, or the bitstream detection method in the fifth aspect or any possible implementation of the fifth aspect, or the bitstream detection method in the sixth aspect or any possible implementation of the sixth aspect, or the bitstream detection method in the seventh aspect or any possible implementation of the seventh aspect.
[0049] In a fourteenth aspect, an embodiment of the present application provides a computer program product. The computer program product includes computer instructions, which, when executed by a computer or a processor, cause the computer or processor to perform the bitstream signature method of the first aspect or any possible implementation of the first aspect, or the bitstream signature method of the second aspect or any possible implementation of the second aspect, or the bitstream detection method of the fifth aspect or any possible implementation of the fifth aspect, or the bitstream detection method of the sixth aspect or any possible implementation of the sixth aspect, or the bitstream detection method of the seventh aspect or any possible implementation of the seventh aspect.
[0050] In a fifteenth aspect, an embodiment of the present application provides a computer-readable storage medium. The computer-readable storage medium stores a bitstream in the third aspect or any possible implementation of the third aspect, or stores a bitstream in the fourth aspect or any possible implementation of the fourth aspect.
[0051] In a sixteenth aspect, embodiments of the present application provide a device for storing a bitstream. The device includes: a receiver configured to receive the bitstream according to the third aspect or any possible implementation of the third aspect, or the bitstream according to the fourth aspect or any possible implementation of the fourth aspect; and at least one storage medium configured to store the bitstream.
[0052] In the seventeenth aspect, an embodiment of the present application provides a device for transmitting a bit stream, the device comprising: a transmitter and at least one storage medium, the at least one storage medium being used to store the bit stream in the third aspect or any possible implementation of the third aspect, or being used to store the bit stream in the fourth aspect or any possible implementation of the fourth aspect; the transmitter being used to obtain the bit stream from the storage medium and send the bit stream to the end-side device through the transmission medium.
[0053] In aspect 18, an embodiment of the present application provides a system for distributing bitstreams. The system includes: at least one storage medium for storing at least one bitstream according to the third aspect or any possible implementation of the third aspect, or for storing at least one bitstream according to the fourth aspect or any possible implementation of the fourth aspect; and a streaming media device for acquiring a target bitstream from the at least one storage medium and sending the target bitstream to an end-side device, wherein the streaming media device includes a content server or a content distribution server.
[0054] Regarding the beneficial effects of the third aspect to the eighteenth aspect, reference may be made to the description of any implementation in the first aspect or the second aspect, and no further details will be given here. Based on the implementation provided in the above aspects, this application can also be further combined to provide more implementations. BRIEF DESCRIPTION OF THE DRAWINGS
[0055] FIG1 is a schematic diagram of an application scenario provided by this application;
[0056] FIG2 is a schematic diagram of the structure of the signature and authentication system provided by this application;
[0057] FIG3 is a flowchart of a bitstream signature method provided by the present application;
[0058] FIG4 is a first schematic diagram of a bit stream provided by the present application;
[0059] FIG5 is a second flow chart of a bitstream signature method provided by the present application;
[0060] FIG6 is a second schematic diagram of a bit stream provided by this application;
[0061] FIG7 is a flow chart of a bit stream detection method provided by the present application;
[0062] FIG8 is a schematic diagram of a bitstream signature device provided by the present application;
[0063] FIG9 is a schematic diagram of a bit stream detection device provided by the present application;
[0064] FIG10 is a schematic diagram of the structure of the computing device provided in this application. DETAILED DESCRIPTION
[0065] The present application provides a bitstream signing method, comprising: obtaining a security parameter set and authentication data, and outputting a bitstream. The bitstream includes the security parameter set and the authentication data, wherein the security parameter set includes a hash period. The hash period indicates the maximum number of access units included in a bitstream segment, and the authentication data includes signature data and a digest of each access unit in a set of access units. The signature data is obtained by signing the digest of each access unit in a set of access units, wherein the set of access units includes at least one access unit in a bitstream segment.
[0066] In this application, the computing device independently generates summary data for each access unit and adds the summary data of each access unit to the bitstream. In this way, the authentication end can independently authenticate each access unit; therefore, in the event that some access units are lost (frame loss), other access units can also be authenticated. In addition, by limiting the maximum number of access units in the bitstream segment, the computing device can limit the amount of summary data of access units included in an authentication data, and further limit the maximum space occupied by an authentication data. This is conducive to clarifying the maximum space occupied by the authentication data, reserving cache space for the authentication data more accurately, and improving the efficiency of signing or authenticating the bitstream.
[0067] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described below are part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0068] The term "and / or" in this article is merely a description of the association relationship between associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone.
[0069] In the description and claims of the embodiments of this application, the terms "first" and "second" are used to distinguish different objects, rather than to describe a specific order of objects. For example, the terms "first target object" and "second target object" are used to distinguish different objects, rather than to describe a specific order of objects.
[0070] In the embodiments of this application, words such as "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as "exemplarily" or "for example" in the embodiments of this application should not be interpreted as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplarily" or "for example" is intended to present the relevant concepts in a concrete manner.
[0071] In the description of the embodiments of this application, unless otherwise specified, "multiple" means two or more. For example, "multiple processing units" means two or more processing units; "multiple systems" means two or more systems.
[0072] The following is an introduction to related technologies.
[0073] A data unit is the basic syntax structure of a coded bit stream and can be either a Network Abstract Layer unit (NAL unit) or an access unit.
[0074] A NAL unit is a syntactic structure that includes an indication of the type of subsequent data and the number of bytes contained (located in the NAL header). The data appears in the form of a raw byte sequence payload (RBSP), and may include interspersed security bytes if necessary. For example, a NAL unit may include a security parameter set NAL unit (also called a security data set) or an authentication data NAL unit (also called authentication data).
[0075] An access unit (AU) is a group of NAL units that are linked to each other according to a specified rule and are sequentially transmitted in decoding order to form a compressed video bitstream (also called a bitstream). A bitstream represents the binary data stream formed by coded image / audio frames.
[0076] It should be noted that, from another perspective, a data unit may also include a coded image.
[0077] Coded picture: a coded representation of a frame of image.
[0078] Security parameter set (SEC): The security parameter set contains the configuration parameters required for encryption and authentication operations on the bit stream.
[0079] It should be noted that this application does not group the data units, but uses "a group of data units" to describe them for the convenience of description.
[0080] For example, a group of data units may include n data units, each of which requires authentication, where n is a positive integer. Accordingly, the authentication data may include n digest data, each of which corresponds one-to-one to the n data units. For example, "a group of data units" may also be described as "n data units."
[0081] Exemplarily, a plurality of summary data of a group of data units may constitute a summary data list; that is, the authentication data may include the summary data list.
[0082] Exemplarily, the authentication data may be Auth.
[0083] Exemplarily, the signature data may be signature.
[0084] Exemplarily, the summary data may also be referred to as authentication summary data or summary.
[0085] For example, the bitstream may be an audio compression bitstream (or audio compression codestream) or a video compression bitstream (or video compression codestream), and this application does not limit this. This application uses the example of signing and detecting a video compression bitstream for illustration.
[0086] As shown in Figure 1, Figure 1 is a schematic diagram of the application scenarios provided by this application. Figure 1 shows a monitoring scenario, a live broadcast scenario, and a video-on-demand scenario.
[0087] Referring to Figure 1 , in an exemplary surveillance scenario, camera 11 can sign a surveillance video bitstream, obtaining a signed surveillance video bitstream 101. Signed surveillance video bitstream 101 is then sent to laptop computer 13 via network 12. Laptop computer 13 can then authenticate signed surveillance video bitstream 101, obtain and display an authentication result 105, and play surveillance video 104.
[0088] 1 , illustratively, in a live broadcast scenario, mobile phone 14 can sign a live video bitstream to obtain a signed live video bitstream 102. Then, the signed live video bitstream 102 is sent to mobile phone 15 via network 12. Mobile phone 15 can then authenticate the signed live video bitstream 102, obtain and display an authentication result 107, and play the live video 106.
[0089] 1 , illustratively, in a video-on-demand scenario, a personal computer 16 can sign a video-on-demand bitstream to obtain a signed video-on-demand bitstream 103. The signed video-on-demand bitstream 103 is then sent to a mobile phone 17 via a network 12. The mobile phone 17 can then authenticate the signed video-on-demand bitstream 103, obtain and display an authentication result 109, and play the video-on-demand 108.
[0090] It should be understood that the present application can also be used in other audio and video encoding and decoding scenarios, such as digital content trusted scenarios, etc., and the present application does not limit this.
[0091] As shown in Figure 2, Figure 2 is a schematic diagram of the structure of the signature and authentication system provided by this application. Figure 2 illustrates the authentication and signature process in Figure 1 above.
[0092] 2 , illustratively, an authentication and signature system 200 may include a signature terminal 210 and an authentication terminal 220. The signature terminal 210 may also be referred to as a front-end device, and the authentication terminal 220 may also be referred to as a back-end device.
[0093] For example, the signing end 210 may be the camera 11, mobile phone 14 and personal computer 16 in FIG1 , and the authentication end 220 may be the laptop computer 13, mobile phone 15 and mobile phone 17 in FIG1 .
[0094] It should be understood that the same terminal device can serve as both the signing end 210 and the authentication end 220, and this application does not impose any restrictions on this.
[0095] 2 , illustratively, after acquiring the video data 201 , the signing end 210 may perform video encoding 21 on the video data 201 to obtain a bitstream 202 ; and perform video signing 22 on the bitstream 202 to obtain a signed bitstream 203 .
[0096] For example, the video data 201 may be a surveillance video captured by the camera 11 in FIG. 1 , a live video recorded by the mobile phone 14 , or a video on demand produced by the personal computer 16 .
[0097] For example, the signed bitstream 203 may be the signed surveillance video bitstream 101 , the signed live video bitstream 102 , or the signed on-demand video bitstream 103 in FIG. 1 .
[0098] It should be noted that the video encoding 21 and video signing 22 operations can be performed in parallel.
[0099] In one possible implementation, the signing end 210 may include an encoder, which performs video encoding 21 and video signing 22. In another possible implementation, the signing end 210 may include an encoder and a signature module, which performs video encoding 21 and video signing 22. In another possible implementation, the signing end 210 may include a signature module, which performs video encoding 21 and video signing 22.
[0100] Afterwards, the signing end 210 may send the signed bit stream 203 to the authenticating end 220 .
[0101] Continuing to refer to Figure 2, illustratively, after the authentication end 220 receives the signed bitstream 203, it can perform video authentication 23 on the signed bitstream 203 to obtain an authentication result 205; and it can perform video decoding 24 on the bitstream 202 in the signed bitstream 203 to obtain decoded video data 204.
[0102] For example, the decoded video data 204 may be the surveillance video 104, the live video 106, or the on-demand video 108 in FIG. 1 .
[0103] For example, the authentication result 205 may be the authentication result 105, the authentication result 107, or the authentication result 109 in FIG. 1 .
[0104] It should be noted that the video authentication 23 and the video decoding 24 can be performed in parallel.
[0105] In a possible implementation, the authentication end 220 may include a decoder, and the decoder performs video decoding 24 and video authentication 23 .
[0106] In a possible implementation, the authentication end 220 may include a decoder and an authentication module, wherein the decoder performs video decoding 24 and the authentication module performs video authentication 23 .
[0107] In a possible implementation, the authentication end 220 may include an authentication module, which performs video decoding 24 and video authentication 23 .
[0108] It should be noted that when the signing end 210 performs lossless encoding, the video data and the decoded video data are the same; when the signing end 210 performs lossy encoding, there are differences between the video data and the decoded video data.
[0109] It should be noted that the encoder, decoder and authentication module can be implemented by software or hardware, and this application does not impose any restrictions on this.
[0110] The implementation of the embodiments of the present application will be described in detail below with reference to the accompanying drawings.
[0111] FIG3 is a flow chart illustrating a bitstream signature method provided by this application. This bitstream signature method can be applied to the signature and authentication system shown in FIG2 . For example, this bitstream signature method can be implemented by a processing device 300. In this embodiment, the data unit is an access unit, and the following description uses the access unit as an example. In one possible example, the processing device 300 can be the signing terminal 210 shown in FIG2 . This bitstream signature method can include the following steps S310 and S320.
[0112] S310: The processing device 300 obtains authentication data and a security parameter set.
[0113] The authentication data includes signature data and summary data for each access unit in a set of access units, where the signature data is signed based on the summary data for each access unit in the set of access units. The security parameter set includes a hash period, which indicates the maximum number of access units in a bitstream segment, where a set of access units includes at least one access unit in a bitstream segment.
[0114] For example, when authentication needs to be supported, the number n of access units that need to be authenticated may be determined, where n is a positive integer.
[0115] 3 , illustratively, the n access units in bitstream a that require authentication are: access unit 1, access unit 2, ..., access unit n. These n access units that require authentication can be referred to as a group of access units. All subsequent references to a group of access units refer to access units that require authentication.
[0116] It should be noted that this application does not group the access units, but uses "a group of access units" to describe them for the sake of convenience.
[0117] For example, referring to FIG3 , the processing device 300 can independently calculate a digest for each access unit in a group of access units, thereby obtaining a digest for each access unit in the group. The n digests can include: digest 1, digest 2, ..., digest n; wherein the n digests correspond one-to-one to the n access units; for example, digest 1 corresponds to access unit 1, digest 2 corresponds to access unit 2, ..., digest n corresponds to access unit n.
[0118] Exemplarily, a signature may be performed based on the digest of each access unit in a group of access units to obtain signature data (signature).
[0119] For example, authentication data (Auth) may be generated based on the signature data and the digest of each access unit in a set of access units. Thus, the authentication data may be {digest 1, digest 2, ..., digest n, signature}.
[0120] Optionally, the digest of each access unit in a set of access units in the authentication data may form a digest list (authentication_hash) {digest 1, digest 2, ..., digest n}.
[0121] In a possible implementation, the processing device 300 receives parameters in a security parameter set, such as parameter 1, parameter 2, and so on.
[0122] In one possible example, parameter 1 is the hash period. The processing device 300 determines hash_period_in_doi_minus1 based on the hash period configured by the user, and then writes the value of hash_period_in_doi_minus1 into the security parameter set. The maximum number of access units in one hash period may be hash_period_in_doi_minus1+1.
[0123] For example, if the hash period is 2, hash_period_in_doi_minus1 is determined to be 2, and hash_period_in_doi_minus1 is written as 2 into the security parameter set. Therefore, the maximum number of access units included in a bitstream segment is 3, that is, the maximum number of access units in one hash period is 3. In the following expressions, one hash period refers to the number of access units in the hash period, that is, hash_period_in_doi_minus1+1.
[0124] The maximum value of hash_period_in_doi is set to the doi period, which ensures that the number of access units participating in authentication is less than or equal to the maximum length of the digest list. hash_period_in_doi can be hash_period_in_doi_minus1+1.
[0125] In this application, hash_period_in_doi is used to indicate the time domain range (i.e., deltaDoi) of the access unit covered by an authentication data NAL unit. All access units within this time domain that need to participate in authentication are jointly signed. Using hash_period_in_doi can solve the problem of changes in SuccessiveHashPictures in substreams. Therefore, there is no need to transmit separate SuccessiveHashPictures for each substream, thereby saving transmission bandwidth and standardizing the scope of authentication data NAL units, improving the efficiency of signing or authenticating bitstreams.
[0126] In another possible example, parameter 2 is indication information. This indication information is used to indicate the number of authentication data included within the scope of the security parameter set. The scope of the security parameter set is the random access segment in the bitstream where the security parameter set is located. The processing device 300 determines the indication information based on the hash period and the number of access units included within the scope of the security parameter set. The indication information may be authentication_data_num_minus1, and the value of authentication_data_num_minus1 is then written to the security parameter set. The number of authentication data included within the scope of the security parameter set is authentication_data_num_minus1+1.
[0127] For example, if the hash period is 2, that is, the number of access units in the hash period is 3, and the number of access units in the scope of the security parameter set is 9, then the number of authentication data contained in the scope of the security parameter set is determined to be the number of access units in the scope of the security parameter set (9) divided by the number of access units in the hash period (3), which is equal to 3. Then, authentication_data_num_minus1 is determined to be 2, and authentication_data_num_minus1 is written as 2 into the security parameter set.
[0128] It is worth noting that the values of authentication_data_num_minus1 and hash_period_in_doi_minus1 can be written into the security parameter set in binary form.
[0129] In this application, by defining indication information in the security parameter set, the number of authentication data that should be within the scope of the security parameter set is clarified. Then, during authentication, the number of authentication data that should be there can be compared with the number of authentication data actually received to efficiently detect the loss of authentication data, thereby improving the efficiency of authentication data loss detection.
[0130] For the detailed contents of the security parameter set, please refer to the contents shown in Figure 5 below, which will not be described here in detail.
[0131] S320 , the processing device 300 outputs a bit stream b.
[0132] The bit stream b includes a security parameter set and authentication data.
[0133] Exemplarily, after obtaining the authentication data and the security parameter set, the processing device 300 adds the authentication data and the security parameter set to the bit stream a to obtain a signed bit stream b, that is, the signed bit stream 203 in FIG. 2 .
[0134] It should be noted that the above S310~S320 can be executed by the encoder in the signature end 210, or by the signature module in the signature end 210, or by the encoder and authentication module in the signature end 210 in collaboration (the encoder executes S320, and the authentication module executes S310). This application does not impose any restrictions on this.
[0135] In a possible implementation, the positions of the security parameter set and the authentication data in the bit stream b are described below.
[0136] Exemplarily, in the process of decoding the bitstream b obtained by the content shown in Figure 3, each security parameter set takes effect at the same time as it is received by the decoder, and will cause the previously valid security parameter set (if any) to become invalid. A security parameter set should exist before the access unit of all random access point (RAP) images in bitstream b. The security parameter set should be located in the same access unit as the sequence parameter set (also referred to as the sequence parameter set NAL unit), and the security parameter set should be located before the sequence parameter set. Therefore, the scope of the security parameter set is the random access point segment (RAS) in the bitstream b where the security parameter set is located. The RAS represents all access units in the bitstream b from the access unit where the security parameter set is located to the next RAP image.
[0137] As shown in Figure 4, Figure 4 is a bitstream schematic diagram provided by the present application. In the bitstream, the security parameter set is located before the random access unit (the access unit corresponding to the RAP image), and the scope of the security parameter set includes two bitstream segments, that is, two groups of access units. In this example, the position relationship shown as "before" and "after" is "before" and "after" along the bitstream decoding order. For example, a is located before b, which means that the position of a in the bitstream is located before the position of b in the bitstream along the bitstream decoding order, that is, when decoding, a is decoded first, and then b is decoded.
[0138] Exemplarily, the authentication data is located after the last access unit in the decoding order in a group of access units associated with the authentication data, and is located before the authentication data corresponding to the access unit in the next hash cycle.
[0139] The group of access units associated with the authentication data represents multiple access units corresponding to the signature data in the authentication data. Since the processing device 300 signs the digests of the multiple access units to obtain the signature data, the signature data corresponds to multiple units.
[0140] As shown in Figure 4, the maximum number of access units indicated by the hash cycle is determined starting from the random access unit in the bitstream as a group of access units, and the group of access units corresponds to one hash cycle. For example, random access unit 0, access unit 1, and access unit 2 are a group of access units, and access unit 3, access unit 4, and access unit 5 are a group of access units. The processing device 300 calculates the digests of random access unit 0, access unit 1, and access unit 2 respectively, and signs the digests of random access unit 0, access unit 1, and access unit 2 to obtain signature data. The processing device 300 writes the aforementioned signature data and digest into authentication data 0. Therefore, the group of access units associated with authentication data 0 is access unit 0, access unit 1, and access unit 2. The group of access units associated with authentication data 1 is access unit 3, access unit 4, and access unit 5.
[0141] For example, authentication data 0 is located after access unit 2 which is the last in the decoding order among the associated access units 0, 1, and 2, and is located before authentication data 1 corresponding to the access unit in the next hash cycle.
[0142] In this application, the processing device better determines the scope of the authentication data by limiting the position of the authentication data in the bitstream. This avoids the problem that the authentication data corresponding to a group of access units exceeds the above range, resulting in the inability to accurately determine the authentication data corresponding to the group of access units when authenticating the aforementioned group of access units, and thus rendering the group of access units untrustworthy and subsequently discarded, which is conducive to improving the availability of access units.
[0143] It should be noted that the bit stream shown in FIG. 4 may be the bit stream b shown in FIG. 3 .
[0144] As shown in Figure 5, Figure 5 is a second flow chart of a bitstream signature method provided by this application. The method shown in Figure 5 can be implemented by a processing device 300, which can be implemented by the signature terminal 210 in Figure 2. The bitstream signature method can include the following steps S510-S550.
[0145] S510: The processing device generates a security parameter set.
[0146] For example, when video image authentication needs to be supported, a security parameter set is generated. In one possible implementation, an RBSP (also referred to as a security parameter set RBSP) is generated in a security parameter set NAL unit.
[0147] The security parameter set RBSP includes parameters that can be used by one or more other types of NAL units. At the start of the decoding process, each security parameter set RBSP takes effect upon receipt by the decoder and invalidates the previously valid security parameter set RBSP (if any). A security parameter set NAL unit should precede the access unit of all random access point pictures. When non-display knowledge pictures are present in the coded video sequence, a security parameter set should precede the access unit containing a patch_index value of 0 for non-RL pre-knowledge pictures, and a security parameter set should precede the access unit containing RL pre-knowledge pictures. Display pictures in adjacent random access picture intervals use the same security parameter set, and knowledge pictures use the same security parameter set as display pictures in the random access picture interval in which their bitstreams are generated. The security parameter set NAL unit should be located in the same access unit as the sequence parameter set NAL unit, and the security parameter set NAL unit should precede the sequence parameter set NAL unit. If the access unit contains a coded picture boundary NAL unit, the security parameter set NAL unit should follow the coded picture boundary NAL unit. At most one security parameter set RBSP is valid at a given moment in the decoding process.
[0148] The definition of the security parameter set RBSP may be as shown in Table 1 below:
[0149] Table 1 Security Parameter Set RBSP Definition
[0150] The encryption flag (encryption_flag) indicates whether there are NAL units with the NAL unit encryption flag set to 1 within the scope of the current security parameter set, or whether there are NAL units that are encrypted. The encryption_flag is a binary variable. A value of '1' indicates that encryption of display picture coding slices, display picture sequence parameter sets, display picture image parameter sets, non-display knowledge picture coding slices, display knowledge picture coding slices, knowledge picture sequence parameter sets, knowledge picture image parameter sets, or extended data units is supported, that is, the RBSP in the NAL unit may be encrypted. A value of '0' indicates that encryption of the RBSP in the NAL unit is not supported.
[0151] The authentication flag (authentication_flag) is a binary variable that indicates whether there are any NAL units with the authentication flag set to 1 within the scope of the current security parameter set, or whether any NAL units are subject to authentication. If an AU contains at least one NAL unit with authentication_idc equal to 1, all NAL units with authentication_idc set to 1 in the access unit are sorted in decoding order and hashed to generate the summary data for the access unit. The summary data of the access unit will be used for authentication.
[0152] For example, a value of '1' indicates support for authentication of the coded video sequence. The NAL units that can participate in authentication include the coded slices of the display image or knowledge image, as well as the sequence parameter set, picture parameter set, security parameter set, and extension data unit transmitted in the frame. When authentication of the above data content is supported, the coded video sequence must carry absolute time extension information, and the authentication data carried in the coded bitstream must be Base64 encoded. Authentication data is transmitted via NAL units with nal_unit_type equal to 10. If an access unit contains NAL units with authentication_idc equal to 1 and nal_unit_type equal to 0 to 9, 12, 14, 17, or 18, the NAL units with authentication_idc equal to 1 in the access unit are sorted in decoding order and hashed to generate the digest data for the access unit. An authentication_flag equal to 0 indicates that authentication of the coded video sequence is not supported, and the coded video sequence should not contain NAL units with nal_unit_type equal to 10.
[0153] It is worth noting that if authentication_flag is 1 and encryption_flag is 1 at the same time, that is, the current coded video sequence supports both encryption and authentication, it should be encrypted first and then authenticated, that is, the data used for authentication should be the encrypted NAL unit.
[0154] The encryption type (encryption_type) is a 4-bit unsigned integer used to indicate the encryption algorithm used. The specific correspondence is shown in Table 2 below.
[0155] Table 2 Correspondence between encryption types and specific encryption algorithms
[0156] The video encryption key flag vek_flag is a binary variable. A value of '1' indicates that vek is carried, and a value of '0' indicates that vkek is not carried.
[0157] The initial vector flag iv_flag is a binary variable. A value of '1' indicates that the iv is carried, and a value of '0' indicates that the iv is not carried.
[0158] The video encryption key encryption type vek_encryption_type is a 4-bit unsigned integer indicating the encryption type of the video encryption key.
[0159] The encrypted video encryption key length evek_length_minus1 is an 8-bit unsigned integer. It indicates the encrypted video encryption key length in bytes.
[0160] The encrypted video encryption key evek is an n-bit unsigned integer. It represents the encrypted video encryption key and is used for encryption calculations. Its length is evek_length_minus1 plus 1 byte.
[0161] The length of the video encryption key version number vkek_version length_minus1 is an 8-bit unsigned integer. It indicates the length of the video encryption key version number in bytes.
[0162] The video encryption key version number vkek_version is an n-bit unsigned integer. It indicates the video encryption key version number and its length is vkek_version_length_minus1 plus 1 byte.
[0163] Initial vector length iv_length_minus1 is an 8-bit unsigned integer. It indicates the length of the initial vector in bytes.
[0164] The initial vector iv is an n-bit unsigned integer. It indicates the initial vector used for block encryption and has a length of iv_length_minus1 plus 1 byte.
[0165] The hash authentication flag for non-output library pictures, hash_discard_non_output_library_pictures_flag, is a binary variable. A value of '1' indicates that non-output library pictures are not authenticated; a value of 0 indicates that non-output library pictures are authenticated. Non-output library pictures are authenticated by digitally signing only the image digest data. If hash_discard_library_pictures is not included in the bitstream, its default value is 1. The authentication_idc flag for each NAL unit in pictures not to be authenticated shall be 0.
[0166] The hash authentication flag for P / B frames, hash_discard_pb_pictures_flag, is a binary variable. A value of '1' indicates that authentication is not performed for pictures other than random access point pictures and knowledge pictures; a value of 0 indicates that authentication is performed for pictures other than random access point pictures and knowledge pictures. If hash_discard_pb_pictures is not present in the codestream, its default value is 1. The authentication_idc flag for each NAL unit in pictures not to be authenticated shall be 0.
[0167] The signature data format, signature_fmt, is a 2-bit unsigned integer. It indicates the signature data format. The specific meaning of the signature_fmt value and the corresponding syntax of signature_type are shown in Table 3 below.
[0168] Table 3 Signature data format
[0169] The camera certificate identifier, camera_idc, is a 152-bit string that indicates the certificate identifier of the camera that the image originated from.
[0170] Camera ID camera_id, a 160-bit string, indicates the camera ID of the image source.
[0171] The authentication enable flag (authentication_idc) is a binary variable that indicates whether the NAL unit is authenticated. A value of '0' indicates that the NAL unit is not authenticated, and a value of '1' indicates that the NAL unit is authenticated using the authentication method specified in the security parameter set.
[0172] The hash period indicates a bitstream segment associated with one authentication data. The number of access units contained in the bitstream segment is at most hash_period_in_doi_minus1+1, which is one hash period. The temporal distance between any two access units in the bitstream segment, indicated by the DOI, should be less than or equal to hash_period_in_doi_minus1. Because the random access point image within a random access segment is the first image to participate in the signature, a group of access units can be determined based on the DOI of the random access point image and hash_period_in_doi_minus1, and this group of access units is signed together. When hash_period_in_doi_minus1 is 0, it means that each access unit is signed separately and transmits its own authentication data. The value range of hash_period_in_doi_minus1 is 0 to 255.
[0173] If hash_period_in_doi_minus1 is 0, each access unit is signed independently. The authentication data carrying the signature should be located after the access unit associated with the signature and before the authentication data of the next access unit. If hash_period_in_doi_minus1 is greater than 0, multiple access units are signed together. The authentication data carrying the signature should be located after the last access unit in decoding order among the multiple access units associated with the signature and before the authentication data of the access unit in the next hash period.
[0174] authentication_data_num_minus1+1 represents the number of authentication data items within the scope of the security parameter set. The receiving end can use this to quickly detect whether all authentication data has been received completely, that is, whether any authentication data has been lost.
[0175] Hash type (hash_type), a 2-bit unsigned integer, indicates the algorithm used for authentication (i.e., the algorithm for determining the summary data of the access unit). The specific correspondence is shown in Table 4:
[0176] Table 4 Correspondence between hash types and specific algorithms
[0177] The digital signature type (signature_type) is a 2-bit unsigned integer that indicates the algorithm used to digitally sign the summary data of the access unit, as shown in Table 5.
[0178] Table 5 Correspondence between digital signature types and specific encryption algorithms
[0179] camera_idc is a 19-byte string that indicates the certificate identifier of the camera that the bitstream corresponds to.
[0180] It should be noted that hash_type, signature_type and camera_idc in the security parameter set RBSP are optional.
[0181] S520: The processing device 300 calculates each access unit in a group of access units of the bit stream according to a digest algorithm to obtain a digest of each access unit in the group of access units.
[0182] Exemplarily, the number of access units that need to be authenticated, ie, hash_period_in_doi_minus1+1, can be calculated based on hash_period_in_doi_minus1 in the security parameter set RBSP; that is, the number of access units included in a group of access units is hash_period_in_doi_minus1+1.
[0183] Next, each of the hash_period_in_doi_minus1+1 access units whose authentication_idc is 1 may be calculated according to a digest algorithm to obtain digest data of each of the hash_period_in_doi_minus1+1 access units.
[0184] In one possible implementation, authentication_idc is located in the NAL header of the NAL unit.
[0185] In one possible implementation, when the security parameter set RBSP includes hash_type, the digest algorithm may be the authentication algorithm indicated by hash_type in the security parameter set RBSP. In this case, a hash algorithm may be calculated for each of the hash_period_in_doi_minus1+1 access units where authentication_idc is 1, based on the authentication algorithm indicated by hash_type in the security parameter set RBSP, to obtain digest data for each of the hash_period_in_doi_minus1+1 access units. For example, a hash algorithm may be performed for each of the hash_period_in_doi_minus1+1 access units where authentication_idc is 1, based on the digest algorithm indicated by hash_type in the security parameter set RBSP, to obtain digest data for each of the hash_period_in_doi_minus1+1 access units.
[0186] In one possible implementation, the signing end 210 and the authenticating end 220 may pre-agreed on a digest algorithm. Thus, the pre-agreed digest algorithm may be used to calculate the hash_period_in_doi_minus1+1 digest data for each of the access units whose authentication_idc is 1, thereby obtaining digest data for each of the access units. In this case, the security parameter set RBSP may not include hash_type.
[0187] It is worth noting that the present application does not limit the way in which the signing end 210 and the authenticating end 220 synchronize the digest algorithm.
[0188] Referring to Figure 5 again, for example, a hash calculation is performed on access unit 1 to obtain digest H1; a hash calculation is performed on access unit 2 to obtain digest H2; a hash calculation is performed on access unit 3 to obtain digest H3; a hash calculation is performed on access unit 4 to obtain digest H4; a hash calculation is performed on access unit 5 to obtain digest H5; ...; a hash calculation is performed on access unit n to obtain digest Hn.
[0189] S530: The processing device 300 concatenates the digest of each access unit in a group of access units, and determines a digest of the concatenated digests.
[0190] Illustratively, the digest of each access unit in hash_period_in_doi_minus1+1 access units with authentication_idc being 1 may be concatenated to obtain the concatenated digest H1+H2+H3+H4+H5+...+Hn.
[0191] Next, the concatenated digests can be calculated to obtain a digest of the concatenated digests. For example, H1+H2+H3+H4+H5+...+Hn can be hashed to obtain a digest of the concatenated digests Hg (as shown in FIG4 ).
[0192] S540: The processing device 300 uses the private key to sign the digest of the digest of each access unit in the connected set of access units to obtain signature data.
[0193] In a possible implementation, when the security parameter set RBSP includes signature_type, the concatenated digest may be signed according to the signature algorithm and private key indicated by signature_type in the security parameter set RBSP to obtain signature data.
[0194] In one possible implementation, the signing end 210 and the authenticating end 220 may pre-agreed on a signature algorithm. Thus, the concatenated digest of the digests may be signed using the pre-agreed signature algorithm and private key to obtain signature data. In this case, the security parameter set RBSP may not include signature_type.
[0195] It is worth noting that the present application does not limit the manner in which the signing end 210 and the authentication end 220 synchronize the signature algorithms.
[0196] It is worth noting that the tree top summary data can also be generated and signed with a private key to obtain signature data. This application does not limit the way of signing the summary data of the access unit.
[0197] Exemplarily, the processing device 300 generates authentication data based on the digest and signature data of each access unit in a group of access units.
[0198] For example, the authentication data may include {H1, H2, H3, H4, H5, ..., Hn, signature}.
[0199] S550 , the processing device 300 adds the authentication data and the security parameter set to the bit stream.
[0200] For example, the processing device 300 may encode the authentication data and the security parameter set, and add the encoded authentication data and security parameter set to the bitstream.
[0201] For example, the processing device 300 may encode the authentication data or the security parameter set using Base64; and then, pack the encoded authentication data into a NAL unit of authentication data.
[0202] In this application, the signing end 210 limits the scope of the authentication data through hash_period_in_doi_minus1 to constrain the authentication data so that the authentication data only corresponds to the access unit within the scope.
[0203] In one possible implementation, the authentication data RBSP definition in the NAL unit of the authentication data may be as shown in Table 6 below:
[0204] Table 6 Authentication data RBSP definition
[0205] for_current_ras_idc takes a value ranging from 0 to 1. If it is 1, it indicates that all access units corresponding to the digests in the digest list in the authentication data are in the current random access segment. If it is 0, it indicates that none of the access units corresponding to the digests in the digest list in the authentication data are in the current random access segment. All access units signed together should be in the same access segment. If for_current_ras_idc is 0, the authentication data NAL unit must be in one of the consecutive (hash_period_in_doi_minus1+1) access units starting from the RAP picture access unit in the current RAS.
[0206] The authentication data identifier, also known as identification information (authentication_data_id), has a value range of 0 to 1 and is used to identify authentication data.
[0207] The number of authentication digests (authentication_hash_number_minus1) is an 8-bit unsigned integer ranging from 0 to 255. Authentication_hash_number_minus1 plus 1 represents the number of digests involved in the co-signature.
[0208] The authentication summary data (authentication_hash) is binary data, and its length is the summary data length hash_size corresponding to the digest algorithm hash_type listed in the table of correspondence between hash types and specific algorithms in the security parameter set.
[0209] The signature data authentication_data[i] is an 8-bit unsigned integer, representing the i-th byte of a signature data.
[0210] The order of arrangement of the summaries of the access units in the summary list carried in the authentication data NAL unit should be the same as the order of arrangement (ie, decoding order) of these access units in the video compression bit stream.
[0211] It is worth noting that the security parameter set can also be transmitted to the authentication end through other reliable mechanisms.
[0212] The contents of Table 6 above are only examples and should not be construed as limiting the present application. In other embodiments of the present application, the value of authentication_data_id may be M, i.e., it occupies M bits. The authentication_data_id is used to distinguish at least 2 consecutive M authentication data, there are P access units between the authentication data and the last access unit in the decoding order among the multiple access units associated with the authentication data; where 0≤P≤(2 M -1)*Q, where Q is the maximum number of hash period indications, i.e. hash_period_in_doi_minus1+1.
[0213] As shown in FIG6 , FIG6 is a second schematic diagram of a bitstream provided by this application. In this example, hash_period_in_doi_minus1 defined in the security parameter set is 2, that is, a bitstream segment (a group of access units) has 3 access units. Authentication_data_id is 2.
[0214] 6 , the bitstream includes a first group of access units, a second group of access units, a third group of access units, and a fourth group of access units, whose corresponding authentication data identifiers may be 00, 01, 10, and 11, respectively. Therefore, due to factors such as signal fluctuations or delays, the authentication data corresponding to the first group of access units may not be received immediately after access unit 13, and may be received, for example, after access unit 22 or after access unit 32. The bitstream shown in FIG6 may be bitstream b in FIG3 .
[0215] In the present application, since the identifier of the authentication data occupies M bits, it is possible to distinguish consecutive 2M authentication data in the bit stream, which is beneficial to improving the fault tolerance of the position of the authentication data in the bit stream, that is, there can be more other authentication units between the authentication data and a group of access units corresponding to the authentication data without affecting the authentication data for authenticating the aforementioned group of access units.
[0216] In one possible scenario, the authentication data of the first group of access units is received at the latest before the authentication data of the fourth group of access units is received. In other words, the authentication data is located after the last access unit in the decoding order of the group of access units associated with the authentication data, and is located 2 M - Before accessing the authentication data corresponding to the unit within 1 hash cycle.
[0217] In a possible embodiment, a possible embodiment of the signature end is shown below. This embodiment includes the following steps ① to ⑥.
[0218] Step ①: The processing device 300 determines hash_period_in_doi_minus1 according to the configured hash period, and writes it into the security parameter set.
[0219] Step 2: The processing device 300 sets the authentication_data_id of the current authentication data. In a RAS bitstream or a CVS (constrained variable-length coding with sub-blocks), the authentication_data_id value should not be the same as the authentication_data_id value of the previous authentication data NAL unit in the decoding order in the bitstream.
[0220] Step 3: Based on the device configuration, the processing device 300 extracts hash_period_in_doi_minus1+1 AUs from the compressed video bitstream output by the encoder and calculates the digests H1, H2, …, Hn for each AU in decoding order, where n is hash_period_in_doi_minus1+1. These digests are then written sequentially into the digest list authentication_hash[i] in the authentication data.
[0221] When calculating the digest of an AU, the NAL units that need to be authenticated in the AU are determined based on the configuration, and all the NAL units participating in the authentication in the AU are concatenated together to calculate the digest of the AU. The authentication_idc in the header information of these NAL units is set to 1, and the authentication_data_id in the header of these NAL units is set to the authentication_data_id of the current authentication data, such as 0 or 1.
[0222] When layered coding is enabled, the basic unit for computing the digest is the set of NAL units in an AU that are marked as participating in the signature and have the same layer_id. Therefore, the number of digests for an AU is equal to the number of layers in the layered configuration.
[0223] Step ④: The processing device 300 calculates the summary Hg of the group of AUs according to the summary of each AU in the group of AUs, ie, H1, H2, ..., Hn.
[0224] Step 5: The processing device 300 calculates the signature of the digest Hg and writes the signature into the signature data authentication_data[i] of the authentication data.
[0225] Step 6: Processing device 300 outputs a compressed video bitstream. This bitstream includes the security parameters (security parameter set NAL units) determined in the above operations and authentication data (authentication data NAL units). The parameters authentication_data_id and authentication_idc in the unit header of the NAL units in the bitstream are set as described above. This bitstream can be bitstream b in Figure 3.
[0226] In a possible embodiment, the following bit stream can be obtained through the contents shown in FIG. 3 to FIG. 6 .
[0227] The bitstream includes: a plurality of bitstream segments, authentication data, and a security data set;
[0228] Among them, the security parameter set includes a hash period, which is used to indicate the maximum number of access units included in a bitstream segment, and the authentication data includes signature data and a summary of each access unit in a group of access units, and the signature data is obtained by signing based on the summary of each access unit in a group of access units, and a group of access units includes at least one access unit in a bitstream segment.
[0229] The bitstream of this embodiment may be the bitstream b shown in FIG3 . For more details about the multiple bitstream segments, authentication data or security data sets, please refer to the descriptions shown in FIG3 to FIG6 above, which will not be repeated here.
[0230] In one possible scenario, the security parameter set in the bitstream of this embodiment only includes the hash period.
[0231] In another possible scenario, the security parameter set in the bitstream of this embodiment includes a hash period and indication information.
[0232] In one possible embodiment, the present application also provides a bitstream signature method. The bitstream signature method can be applied to the signature and authentication system shown in Figure 2. For example, the bitstream signature method can be implemented by a processing device 300. In this embodiment, the data unit is an access unit, and the following description is based on the access unit as an example. In one possible example, the processing device 300 can be the signature terminal 210 shown in Figure 2, and the bitstream signature method can include the following steps ① and ②.
[0233] Step ①: The processing device 300 obtains a security parameter set and authentication data.
[0234] The security parameter set includes indication information indicating the number of authentication data included within the scope of the security parameter set, where the scope of the security parameter set is the random access segment in the bitstream in which the security parameter set is located, and the authentication data includes signature data and a digest of each access unit in the set of access units, where the signature data is signed based on the digest of each access unit in the set of access units;
[0235] Step ②: The processing device 300 outputs a bit stream, which includes a security parameter set and authentication data.
[0236] For the details of the above steps ① and ②, please refer to the descriptions shown in Figures 3 to 6 above, and will not be repeated here.
[0237] Correspondingly, an embodiment of the present application further provides a bitstream, the bitstream comprising: a plurality of bitstream segments, authentication data, and a security data set;
[0238] The security parameter set includes indication information, which is used to indicate the number of authentication data contained within the scope of the security parameter set. The scope of the security parameter set is the random access segment in the bitstream where the security parameter set is located. The authentication data includes signature data and a summary of each access unit in a group of access units. The signature data is obtained by signing according to the summary of each access unit in a group of access units. A group of access units includes at least one access unit in a bitstream segment.
[0239] The bitstream in this embodiment may be the bitstream b shown in FIG3 . For more details of the multiple bitstream segments, authentication data or security data sets, please refer to the descriptions shown in FIG3 to FIG6 above, which will not be repeated here.
[0240] In a possible scenario, the security parameter set in the bitstream of this embodiment only includes indication information.
[0241] In another possible scenario, the security parameter set in the bitstream of this embodiment includes a hash period and indication information.
[0242] After the above introduction of the bitstream signature method, the processing device 300 can send the bitstream obtained by the above bitstream signature method to the authentication end shown in Figure 2 for processing. Based on this, an embodiment of the present application also provides a bitstream detection method.
[0243] FIG7 is a flow chart illustrating a bitstream detection method provided by the present application. This bitstream detection method can be applied to the signature and authentication system shown in FIG2 . For example, this bitstream detection method can be implemented by processing device 600. In this embodiment, the data unit is an access unit, and the following description uses the access unit as an example. In one possible example, processing device 600 can be authenticating terminal 220 shown in FIG2 . This bitstream detection method can include the following steps S710-S740.
[0244] S710: The processing device 600 obtains a security parameter set and authentication data in a bit stream.
[0245] The security parameter set includes a hash period, where the hash period is used to indicate the maximum number of access units included in a bitstream segment; the authentication data includes: signature data and a digest of each access unit in a set of access units, where the signature data is signed based on the digest of each access unit in the set of access units, where the set of access units includes at least one access unit in a bitstream segment;
[0246] For the contents of the security parameter set and authentication data, please refer to the descriptions of Figures 3 to 6 above and will not be repeated here.
[0247] For example, the processing device 600 may obtain the security parameter set and the authentication data by decoding the bit stream.
[0248] For example, the processing device 300 uses base64 to encode the security parameter set and the authentication data before adding them to the bitstream. Therefore, after obtaining the bitstream, the processing device 600 decodes the bitstream to obtain the security parameter set and the authentication data.
[0249] S720: If the processing device 600 determines that an access unit participating in the signature exists in a hash cycle, the authentication data is detected in the next hash cycle along the bitstream decoding order direction of the current hash cycle.
[0250] Exemplarily, the processing device 600 may determine whether there is an access unit participating in the signature within a hash period based on each NAL unit in the access unit included in the hash period.
[0251] For example, authentication_idc is defined in the NAL unit included in the access unit. If authentication_idc is 1, it indicates that the NAL unit will participate in the signature, that is, the access unit including the NAL unit will participate in the signature.
[0252] As shown in FIG4 , if it is determined that an access unit participating in the signature exists within a hash cycle including a random access unit, the authentication data is detected in the next hash cycle along the bitstream decoding order direction within the current hash cycle.
[0253] For example, in a live broadcast scenario, the processing device 600 receives each NAL unit sequentially in the order of bitstream decoding. Taking FIG4 as an example, the processing device 600 will sequentially receive the security parameter set, random access unit 0, access unit 1, access unit 2, and so on. Due to signal fluctuations or low signature efficiency of the processing device 300, the authentication data 0 corresponding to a group of access units (random access unit 0, access unit 1, access unit 2) within a hash cycle cannot follow access unit 2 in a timely manner. Since the authentication data identification information authentication_data_id only occupies one bit, the processing device 600 can only distinguish between two consecutive authentication data (such as authentication data 0 and authentication data 1). Therefore, in the hash cycle corresponding to authentication data 0, the next hash cycle (the hash cycle corresponding to authentication data 1) along the direction of bitstream decoding order is detected to determine whether authentication data 0 exists. If authentication data 0 exists, then this authentication data 0 can also authenticate random access unit 0, access unit 1, and access unit 2. If it does not exist, then random access unit 0, access unit 1, and access unit 2 cannot be authenticated.
[0254] In one possible scenario, in the hash cycle corresponding to the authentication data 1, the authentication data 0 is located before the authentication data 1.
[0255] It is worth noting that the processing device 600 can only distinguish between two consecutive authentication data representations. The processing device 600 may know that the authentication data corresponding to random access unit 0, access unit 1, and access unit 2 is authentication data 0, and that access unit 3, access unit 4, and access unit 5 correspond to authentication data 1. If the location of authentication data 0 is in the hash cycle after the hash cycle corresponding to authentication data 1, two authentication data 0s may appear in one hash cycle. In this case, the processing device 600 is unclear about the hash cycles corresponding to these two authentication data 0s and cannot accurately determine which authentication data 0 is used to authenticate random access unit 0, access unit 1, and access unit 2. In this case, the authentication of random access unit 0, access unit 1, and access unit 2 will fail or fail. By limiting the location of the authentication data, the aforementioned authentication failure or error can be avoided.
[0256] It is worth noting that the processing device 600 can also detect whether authentication data 0 exists in the hash period corresponding to authentication data 0. Since the processing device 600 stores all received NAL units, it can directly detect whether authentication data 0 exists in the hash period corresponding to authentication data 1.
[0257] S730: If the processing device 600 cannot detect the authentication data, it is determined that the authentication data is lost.
[0258] As shown in FIG4 , if the processing device 600 cannot detect authentication data 0 within the hash period corresponding to authentication data 1, it is determined that authentication data 0 is lost, and thus random access unit 0, access unit 1, and access unit 2 cannot be authenticated.
[0259] S740: If the processing device 600 detects the authentication data, it determines that the authentication data is not lost.
[0260] With respect to the above-mentioned bitstream detection method, the following illustrates an embodiment of a bitstream authentication method executed by the processing device 600 , wherein the bitstream can be detected when the processing device 600 executes the bitstream authentication method. This embodiment includes the following steps ① to ⑥.
[0261] Step ①: The processing device 600 obtains a bitstream. The bitstream includes a security parameter set and authentication data. The security parameter set includes parameters required for the authentication operation, and the authentication data includes parameters and data required for the authentication operation.
[0262] Step 2: The processing device 600 parses the authentication data to obtain the digest list {H1, H2, ..., Hn} and calculates the set digest Hg' of this set of digests. The method used by the processing device 600 to calculate the set digest must be the same as the method used by the processing device 300 to calculate the set digest.
[0263] Step 3: The processing device 600 uses Hg' to verify the signature data parsed from the authentication data and determines whether the digest list {H1, H2, ..., Hn} transmitted in the authentication data passes the verification. If not, all access units corresponding to the authentication data are untrustworthy.
[0264] Step ④: The processing device 600 determines the access units participating in the signature based on the parameters in the authentication data.
[0265] If the signature object is a knowledge image, or the current authentication data corresponds to a knowledge image, that is, is_non_output_library_flag is equal to 1, the processing device 600 determines the knowledge image corresponding to the authentication data based on the authentication_library_picture_index in the authentication data. Specifically, the processing device 600 can search for the first access unit of the encoded image whose library_picture_index is equal to the authentication_library_picture_index starting from the position of the authentication data in the bit stream. If the encoded data of the knowledge image is contained in multiple access units, it is necessary to search and obtain all of these access units. In another implementation, if the processing device 600 caches the access units of the knowledge image in advance, there is no need to perform a search operation in the bit stream.
[0266] If the signature object is not a knowledge image and hash_period_in_doi_minus1 is equal to 0, this indicates that an access unit is involved in the signature. From the position of the authentication data in the bitstream, search forward 2*(hash_period_in_doi_minus1+1) access units and find the NAL unit whose authentication_data_id in the NAL unit header information is the same as the authentication_data_id parameter in the authentication data. The access unit where this NAL unit is located is the access unit involved in the signature.
[0267] If the signature object is not a knowledge image, and hash_period_in_doi_minus1 is greater than 0. This means that multiple access units participate in the signature. Starting from the position of the authentication data NAL unit in the bit stream, search forward 2*(hash_period_in_doi_minus1+1) access units, find the NAL unit set whose authentication_data_id in the NAL unit header information is the same as the parameter authentication_data_id in the authentication data, and record it as the NAL unit set within the authentication data scope. In the NAL unit set within the authentication data scope, search for the NAL unit set whose authentication_idc in the header information is 1, and record it as the NAL unit set participating in the signature within the authentication data scope. The set of access units where these NAL units are located is the access unit participating in the signature.
[0268] If the for_current_ras_idc of the authentication data is 0, it means that the AU associated with the current authentication data is in the previous RAS. In this case, the first RAP can be searched forward from the position of the authentication data NAL unit in the bitstream, and (hash_period_in_doi_minus1+1) access units can be searched forward from the RAP (excluding the RAP) to determine the set of NAL units within the scope of the authentication data, and further determine the set of NAL units and access units participating in the signature within the scope of the authentication data.
[0269] Step ⑤: The processing device 600 authenticates the access units participating in the signature.
[0270] Before authenticating the access unit participating in the signature, the processing device 600 initializes the matching start position to the first digest position in the digest list {H1, H2, . . . , Hn}, that is, position 1.
[0271] Authenticating each access unit in sequence according to the decoding order of the access units participating in the signature includes: Processing device 600 calculates the digest Hx of an access unit. Processing device 600 starts from the matching start position in the digest list and searches for a matching digest in order from front to back. If a matching digest is found, the access unit is authenticated, and the matching start position is updated to the next position of the matching digest. The method for calculating the access unit digest by processing device 600 is the same as the method for calculating the access unit digest by processing device 300;
[0272] The list of digests described in this step has been verified and is trustworthy.
[0273] Step ⑥: Optionally, the processing device 600 detects whether the authentication data is lost.
[0274] In one possible implementation, the processing device 600 may determine whether authentication data is lost based on the security parameter set parameter authentication_data_num and the reception of authentication data from access units within the scope of the security parameter set. Specifically, after receiving the security parameter set, the receiving end counts the received authentication data. If the authentication data in the RAS where the security parameter set is located is less than authentication_data_num_minus1, it is determined to be lost. If the authentication data in the RAS where the security parameter set is located is equal to authentication_data_num_minus1, the first authentication data with for_current_ras_idc set to 0 is searched in the next RAS. If no authentication data is found, it is determined to be lost.
[0275] In another possible implementation, the processing device 600 may also detect whether the authentication data is lost based on hash_period_in_doi_minus1. Specifically, if there is an access unit participating in the signature within a hash period of the RAS, the authentication data NAL unit is detected in the next hash period. If no authentication data is detected, the authentication data NAL unit is determined to be lost. If the hash period is the last one of the current RAS, the authentication data NAL unit is detected in the first hash period of the next RAS. If no authentication data is detected, the authentication data NAL unit is determined to be lost.
[0276] In another possible embodiment of the present application, the present application further provides a bitstream detection method. This bitstream detection method can be applied to the signature and authentication system shown in Figure 2. For example, the bitstream detection method can be implemented by processing device 600. In this embodiment, the data unit is an access unit, and the following description uses the access unit as an example. In one possible example, the processing device 600 can be the authentication terminal 220 shown in Figure 2. The bitstream detection method can include the following steps ①-④.
[0277] Step ①: The processing device 600 obtains the security parameter set and authentication data in the bit stream.
[0278] The security parameter set includes a hash period, which is used to indicate the maximum number of access units included in a bitstream segment. The authentication data includes signature data and a digest of each access unit in a group of access units, where the signature data is signed based on the digest of each access unit in the group of access units. A group of access units includes at least one access unit in a bitstream segment. The authentication data carries identification information (identifier) authentication_data_id, which occupies M bits, where M is an integer greater than or equal to 2. The identifier is used to distinguish consecutive 2M-power authentication data in the bitstream.
[0279] For the detailed contents of the security parameter set and authentication data, please refer to the descriptions shown in Figures 3 to 6 above, which will not be repeated here.
[0280] Step ②: If the processing device 600 determines that there is an access unit participating in the signature in a hash cycle, then the second access unit after the current hash cycle along the bit stream decoding order direction M - Authentication data is checked in 1 hash cycle.
[0281] Since the authentication data identifier occupies M bits, for example, M is 2, processing device 600 can determine the hash cycles, and therefore the corresponding access units, for authentication data 0, 1, 2, and 3. For authentication data 0, processing device 600 can detect its presence at the latest during the hash cycle corresponding to authentication data 3.
[0282] In one possible scenario, in the hash cycle corresponding to the authentication data 1, the authentication data 0 is located before the authentication data 3.
[0283] It is worth noting that the above-mentioned authentication data 0, authentication data 1, authentication data 2, and authentication data 3 are arranged in the order of bit stream decoding. Correspondingly, the multiple groups of data corresponding to authentication data 0, authentication data 1, authentication data 2, and authentication data 3 are also arranged in the order of bit stream decoding.
[0284] It is worth noting that the processing device 600 can also detect whether authentication data 0 exists within the hash period corresponding to authentication data 0, detect whether authentication data 0 exists within the hash period corresponding to authentication data 1, and detect whether authentication data 0 exists within the hash period corresponding to authentication data 2. Since the processing device 600 stores all received NAL units, to save computing resources, the processing device 600 can directly detect whether authentication data 0 exists within the hash period corresponding to authentication data 3. In other words, the processing device 600 detects whether authentication data 0 is included in the previously received data within the hash period corresponding to authentication data 3.
[0285] Step 3: If the authentication data cannot be detected, it is determined that the authentication data is lost.
[0286] Step ④: If the authentication data is detected, it is determined that the authentication data is not lost.
[0287] In another possible embodiment of the present application, the present application further provides a bitstream detection method. This bitstream detection method can be applied to the signature and authentication system shown in Figure 2. For example, the bitstream detection method can be implemented by processing device 600. In this embodiment, the data unit is an access unit, and the following description uses the access unit as an example. In one possible example, the processing device 600 can be the authentication terminal 220 shown in Figure 2. The bitstream detection method can include the following steps ① and ②.
[0288] Step ①: The processing device 600 obtains the security parameter set in the bit stream and the number of authentication data within the scope of the security parameter set.
[0289] The scope of the security parameter set is the random access segment in the bitstream where the security parameter set is located, and the security data set includes indication information, which is used to indicate the number of authentication data that should be included in the scope of the security parameter set.
[0290] For the detailed contents of the security parameter set and authentication data, please refer to the contents shown in Figures 3 to 6 above, which will not be repeated here.
[0291] Step ②: The processing device 600 determines the loss of the authentication data based on the indication information and the number of authentication data within the scope of the security parameter set.
[0292] Exemplarily, the processing device 600 compares the number a of authentication data that should be included within the scope of the security parameter set indicated by the instruction information with the number b of authentication data actually obtained by the processing device 600 from within the scope of the security parameter set to determine whether the authentication data is lost. If the number a is the same as the number b, the authentication data is not lost. If the number a is different from the number b, the authentication data is lost.
[0293] In this application, the indication information is defined in the security parameter set to clarify the amount of authentication data that should be within the scope of the security parameter set. During authentication, the expected amount of authentication data can be compared with the actual amount received to efficiently detect the loss of authentication data, thereby improving the efficiency of authentication data loss detection.
[0294] It is understood that, in order to implement the functions in the above embodiments, the processing device 300 and the processing device 600 include hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should readily appreciate that, in conjunction with the units and method steps of the various examples described in the embodiments disclosed in this application, this application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in hardware or in a manner driven by computer software depends on the specific application scenario and design constraints of the technical solution.
[0295] The bitstream signature method provided in accordance with the present embodiment is described in detail above with reference to FIG. 1 to FIG. 6 . The bitstream signature apparatus provided in accordance with the present embodiment will be described below with reference to FIG. 8 .
[0296] FIG8 is a schematic diagram of a bitstream signature device provided by the present application. The schematic diagram of the bitstream signature device can be used to implement the methods of the aforementioned embodiments. Therefore, the beneficial effects achieved by the bitstream signature device can be referenced to the beneficial effects of the corresponding methods provided above and will not be further described here. Exemplarily, the bitstream signature device 800 includes:
[0297] The first acquisition module 810 is configured to acquire a security parameter set and authentication data. The security parameter set includes a hash period, which indicates the maximum number of access units in a bitstream segment. The authentication data includes signature data and a digest of each access unit in a set of access units. The signature data is obtained by signing the digest of each access unit in the set of access units, where the set of access units includes at least one access unit in a bitstream segment.
[0298] The first output module 820 is configured to output a bit stream, where the bit stream includes a security parameter set and authentication data.
[0299] For more achievable aspects of the bitstream signature device 800, reference may be made to the steps performed by the processing device 300 in the aforementioned method embodiment. The bitstream signature device 800 may be used to implement the functions of the processing device 300 in the aforementioned method embodiment, thereby also achieving the beneficial effects of the aforementioned method embodiment.
[0300] In a possible embodiment, the bitstream signature device may include a third acquisition module and an output module.
[0301] The second acquisition module is configured to acquire a security parameter set and authentication data. The security parameter set includes indication information indicating the number of authentication data items within the scope of the security parameter set, where the scope of the security parameter set is the random access segment in the bitstream where the security parameter set is located. The authentication data includes signature data and a digest of each access unit in a set of access units, where the signature data is signed based on the digest of each access unit in the set of access units.
[0302] The second output module is used to output a bit stream, where the bit stream includes a security parameter set and authentication data.
[0303] For more achievable content of the bitstream signature device, reference may be made to the steps performed by the processing device 300 in the above method embodiment. The bitstream signature device can be used to implement the functions of the processing device 300 in the above method embodiment, thereby also achieving the beneficial effects of the above method embodiment.
[0304] The above description, in conjunction with FIG7 , details the bitstream detection method provided according to this embodiment. The following description, in conjunction with FIG9 , details the bitstream detection device provided according to this embodiment. FIG9 is a schematic diagram of the bitstream detection device provided by this application. The schematic diagram of the bitstream detection device can be used to perform the method of the aforementioned embodiment. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects of the corresponding method provided above, and will not be repeated here. Exemplarily, the bitstream detection device 900 includes:
[0305] The third acquisition module 910 is configured to acquire the security parameter set and authentication data in the bit stream.
[0306] The security parameter set includes a hash period, which indicates the maximum number of access units in a bitstream segment. The authentication data includes signature data and a digest of each access unit in a set of access units. The signature data is signed based on the digest of each access unit in the set of access units. A set of access units includes at least one access unit in a bitstream segment.
[0307] The first detection module 920 detects authentication data in the next hash cycle along the bit stream decoding order direction of the current hash cycle if there is an access unit participating in the signature in a hash cycle; if no authentication data is detected, it is determined that the authentication data is lost; if the authentication data is detected, it is determined that the authentication data is not lost.
[0308] For more achievable aspects of the bitstream detection device 900, reference may be made to the steps performed by the processing device 600 in the above method embodiment. The bitstream detection device 900 may be used to implement the functions of the processing device 600 in the above method embodiment, thereby also achieving the beneficial effects of the above method embodiment.
[0309] The above description, in conjunction with FIG7 , details the bitstream detection method provided in accordance with this embodiment. The following description will describe the bitstream detection device provided in accordance with this embodiment. The schematic diagram of the bitstream detection device can be used to implement the method of the aforementioned embodiment. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding method provided above, and will not be repeated here. Exemplarily, the bitstream detection device includes:
[0310] The fourth acquisition module is used to obtain the security parameter set and authentication data in the bit stream.
[0311] The security parameter set includes a hash period, where the hash period is used to indicate the maximum number of access units included in a bitstream segment; the authentication data includes signature data and a digest of each access unit in a group of access units, where the signature data is signed according to the digest of each access unit in the group of access units; the authentication data carries an identifier, where the identifier occupies M bits, where M is an integer greater than or equal to 2, and the identifier is used to distinguish consecutive 2(M) authentication data in the bitstream; and the group of access units includes at least one access unit in the bitstream segment.
[0312] The second detection module is used to detect authentication data in the 2M-th power minus 1 hash cycle after the current hash cycle along the bit stream decoding order direction if there is an access unit participating in the signature in a hash cycle; if no authentication data is detected, it is determined that the authentication data is lost; if the authentication data is detected, it is determined that the authentication data is not lost.
[0313] For more achievable contents of the bitstream detection device, reference may be made to the steps performed by the processing device 600 in the above method embodiment. The bitstream detection device can be used to implement the functions of the processing device 600 in the above method embodiment, thereby also achieving the beneficial effects of the above method embodiment.
[0314] The above description, in conjunction with FIG7 , details the bitstream detection method provided in accordance with this embodiment. The following description will describe the bitstream detection device provided in accordance with this embodiment. The schematic diagram of the bitstream detection device can be used to implement the method of the aforementioned embodiment. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding method provided above, and will not be repeated here. Exemplarily, the bitstream detection device includes:
[0315] The fifth acquisition module is used to obtain the security parameter set in the bit stream and the number of authentication data within the scope of the security parameter set.
[0316] The scope of the security parameter set is a random access segment in the bitstream where the security parameter set is located, and the security data set includes indication information, where the indication information is used to indicate the number of authentication data that should be included in the scope of the security parameter set;
[0317] The determination module is used to determine the loss of authentication data according to the indication information and the number of authentication data within the scope of the security parameter set.
[0318] For more achievable contents of the bitstream detection device, reference may be made to the steps performed by the processing device 600 in the above method embodiment. The bitstream detection device can be used to implement the functions of the processing device 600 in the above method embodiment, thereby also achieving the beneficial effects of the above method embodiment.
[0319] It can be understood that the device shown in Figure 8 or Figure 9 is only an example provided in this embodiment. Depending on the different bitstream signatures or detection processes, the device may include more or fewer units, and this application is not limited to this.
[0320] When the apparatus shown in FIG8 or FIG9 is implemented by hardware, the hardware may be implemented by a processor or a chip system. The chip system includes one or more chips, each chip including a processor and a power supply circuit. The power supply circuit is used to power the processor, and the processor is used to implement the method of any possible implementation method of the above embodiments through a logic circuit or executing code instructions. The beneficial effects can be found in the description of any aspect of the above embodiments and will not be repeated here.
[0321] It is understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0322] A computing device is also provided in an embodiment of the present application. The bitstream signature device 800 shown in FIG8 or the bitstream detection device 900 shown in FIG9 can be implemented by a computing device, as shown in FIG10 , which is a schematic diagram of the structure of the computing device provided in the present application. The computing device 1000 includes: a memory 1010 and at least one processor 1020. The processor 1020 can implement the bitstream signature method or bitstream detection method provided in the above embodiment. The memory 1010 is used to store software instructions corresponding to the above bitstream signature method or bitstream detection method. For example, the computing device can be the camera 11 or the mobile phone 15 in FIG1 . The computing device 1000 can be the above-mentioned processing device 300 or the processing device 600.
[0323] As an optional implementation, in hardware implementation, the computing device 1000 may refer to a chip or chip system encapsulated with one or more processors 1020. For example, when the computing device 1000 is used to implement the method steps in the above embodiment, the processor 1020 included in the computing device 1000 executes the steps of the processing device 300 or the processing device 600 in the above method and its possible sub-steps. In an optional scenario, the computing device 1000 may also include a communication interface 1030, which can be used to send and receive data. For example, the communication interface 1030 is used to receive a bit stream, etc.; the communication interface 1030 can be implemented by an interface circuit included in the computing device 1000. Therefore, in some examples, the communication interface 1030 may also be referred to as a transceiver of the computing device. In this embodiment, the communication interface 1030 supports wired connection using a unified multimedia interconnect interface.
[0324] In an embodiment of the present application, the communication interface 1030, the processor 1020, and the memory 1010 may be connected via a bus 1040, which may be divided into an address bus, a data bus, a control bus, etc. The bus 1040 may be a peripheral component interconnect express (PCIe) bus, an extended industry standard architecture (EISA) bus, a unified bus (Ubus or UB), a compute express link (CXL), a cache coherent interconnect for accelerators (CCIX), or other types of buses.
[0325] Processor 1020 may include a CPU, a graphics processing unit (GPU), an embedded neural-network processing unit (NPU), a microprocessor (MP), a digital signal processor (DSP), an ASIC, an FPGA or other programmable logic device, a transistor logic device, a hardware component or any combination thereof.
[0326] The memory 1010 may include a volatile memory, such as a random access memory (RAM). The memory 1010 may also include a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD), or a solid state drive (SSD).
[0327] It is worth noting that the computing device 1000 can also perform the functions of the bitstream signature device 800 shown in Figure 8 or the bitstream detection device 900 shown in Figure 9, which are not described in detail here. In particular, all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module and are not repeated here.
[0328] The present application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that can be stored by a computing device or a data storage device such as a data center that contains one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a digital video disc (DVD)), or a semiconductor medium (e.g., a solid-state drive). The computer-readable storage medium stores instructions that instruct the computing device to execute a bitstream signature method or a bitstream detection method. The computer-readable storage medium can also store the bitstream mentioned above, such as the bitstream obtained by the method shown in FIG3.
[0329] Embodiments of the present application also provide a computer program product comprising instructions. This computer program product may be software or a program product comprising instructions that can be run on a computing device or stored in any available medium. When the computer program product is run on at least one computing device, it causes the at least one computing device to perform a bitstream signature method or a bitstream detection method.
[0330] In addition, an embodiment of the present application also provides a device, which can specifically be a chip, component or module, and the device may include a connected processor and memory; wherein the memory is used to store computer-executable instructions, and when the device is running, the processor can execute the computer-executable instructions stored in the memory to enable the chip to execute the methods in the above-mentioned method embodiments.
[0331] Among them, the computing device, computer-readable storage medium, computer program product or chip provided in this embodiment are all used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding methods provided above, and will not be repeated here.
[0332] Through the description of the above implementation methods, technical personnel in the relevant field can understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0333] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0334] Units described as separate components may or may not be physically separate, and components shown as units may be one physical unit or multiple physical units, that is, they may be located in one place or distributed in multiple places. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0335] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0336] Any content of each embodiment of this application, as well as any content of the same embodiment, can be freely combined. Any combination of the above content is within the scope of this application.
[0337] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a device (which can be a single-chip microcomputer, chip, etc.) or a processor to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a ROM, a RAM, a magnetic disk, or an optical disk.
[0338] The steps of the method or algorithm described in conjunction with the disclosure of the embodiments of the present application can be implemented in a hardware manner, or can be implemented by a processor executing software instructions. The software instructions can be composed of corresponding software modules, and the software modules can be stored in RAM, flash memory, ROM, erasable programmable read-only memory (Erasable Programmable ROM, EPROM), electrically erasable programmable read-only memory (Electrically EPROM, EEPROM), registers, hard disks, mobile hard disks, read-only compact discs (CD-ROMs) or any other form of storage medium well known in the art. An exemplary storage medium is coupled to a processor so that the processor can read information from the storage medium and can write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an ASIC.
[0339] Those skilled in the art will appreciate that in one or more of the above examples, the functions described in the embodiments of the present application can be implemented using hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. Computer-readable media include computer-readable storage media and communication media, wherein communication media include any media that facilitates the transmission of computer programs from one place to another. The storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0340] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms without departing from the purpose of this application and the scope of protection of the claims, all of which are within the protection of this application.
Claims
1. A bitstream signature method, characterized in that: The method comprises: Obtain security parameter sets and authentication data; The security parameter set includes a hash period, where the hash period is used to indicate a maximum number of access units included in a bitstream segment; the authentication data includes signature data and a digest of each access unit in a set of access units, where the signature data is signed based on the digest of each access unit in the set of access units, where the set of access units includes at least one access unit in the bitstream segment; A bit stream is output, the bit stream including the security parameter set and the authentication data.
2. The method according to claim 1, characterized in that The authentication data is located after the last access unit in the decoding order in a group of access units associated with the authentication data, and is located before the authentication data corresponding to the access unit in the next hash cycle.
3. The method according to claim 1 or 2, characterized in that The security parameter set further includes indication information, where the indication information is used to indicate the number of authentication data contained within the scope of the security parameter set, where the scope of the security parameter set is the random access segment in the bitstream where the security parameter set is located.
4. The method according to claim 1 or 3, characterized in that The authentication data carries an identifier, which occupies M bits, where M is an integer greater than or equal to 2, and the identifier is used to distinguish consecutive 2M-power authentication data in the bit stream.
5. The method according to claim 4, characterized in that There are P access units between the authentication data and the last access unit in the decoding order of the access units associated with the authentication data; where 0≤P≤(2 M -1)*Q, where Q is the maximum number of hash cycle indications.
6. A bitstream signature method, characterized in that: The method comprises: Obtain security parameter sets and authentication data; The security parameter set includes indication information, where the indication information is used to indicate the number of authentication data included within the scope of the security parameter set, where the scope of the security parameter set is the random access segment in the bitstream where the security parameter set is located, and the authentication data includes signature data and a digest of each access unit in a set of access units, where the signature data is signed based on the digest of each access unit in the set of access units; A bit stream is output, the bit stream including the security parameter set and the authentication data.
7. The method according to claim 6, characterized in that The security parameter set further includes a hash period, where the hash period is used to indicate the maximum number of access units included in a bitstream segment.
8. The method according to claim 6 or 7, characterized in that The authentication data is located after the last access unit in the decoding order in a group of access units associated with the authentication data, and is located before the authentication data corresponding to the access unit in the next hash cycle.
9. The method according to claim 6 or 7, characterized in that The authentication data carries an identifier, which occupies M bits, where M is an integer greater than or equal to 2, and the identifier is used to distinguish consecutive 2M-power authentication data in the bit stream.
10. The method according to claim 9, characterized in that There are P access units between the authentication data and the last access unit in the decoding order of the access units associated with the authentication data; where 0≤P≤(2 M -1)*Q, where Q is the maximum number of hash cycle indications.
11. A bit stream, characterized in that The bitstream includes: multiple bitstream segments, authentication data, and security data sets; The security parameter set includes a hash period, which is used to indicate the maximum number of access units included in a bitstream segment. The authentication data includes signature data and a summary of each access unit in a group of access units. The signature data is obtained by signing based on the summary of each access unit in a group of access units, and the group of access units includes at least one access unit in the bitstream segment.
12. The bit stream according to claim 11, wherein The authentication data is located after the last access unit in the decoding order in a group of access units associated with the authentication data, and is located before the authentication data corresponding to the access unit in the next hash cycle.
13. The bit stream according to claim 11 or 12, characterized in that The security parameter set further includes indication information, where the indication information is used to indicate the number of authentication data contained within the scope of the security parameter set, where the scope of the security parameter set is the random access segment in the bitstream where the security parameter set is located.
14. The bit stream according to claim 11 or 13, characterized in that The authentication data carries an identifier, which occupies M bits, where M is an integer greater than or equal to 2, and the identifier is used to distinguish consecutive 2M-power authentication data in the bit stream.
15. The bit stream according to claim 14, wherein There are P access units between the authentication data and the last access unit in the decoding order of the access units associated with the authentication data; where 0≤P≤(2 M -1)*Q, where Q is the maximum number of hash cycle indications.
16. A bit stream, characterized in that The bitstream includes: multiple bitstream segments, authentication data, and security data sets; The security parameter set includes indication information, which is used to indicate the number of authentication data contained within the scope of the security parameter set. The scope of the security parameter set is the random access segment in the bitstream where the security parameter set is located. The authentication data includes signature data and a summary of each access unit in a group of access units. The signature data is obtained by signing according to the summary of each access unit in a group of access units.
17. The bit stream according to claim 16, wherein The security parameter set includes a hash period, and the hash period is used to indicate the maximum number of access units included in a bitstream segment.
18. The bit stream according to claim 16 or 17, characterized in that The authentication data is located after the last access unit in the decoding order in a group of access units associated with the authentication data, and is located before the authentication data corresponding to the access unit in the next hash cycle.
19. The bit stream according to claim 16 or 17, characterized in that The authentication data carries an identifier, which occupies M bits, where M is an integer greater than or equal to 2, and the identifier is used to distinguish consecutive 2M-power authentication data in the bit stream.
20. The bit stream according to claim 19, wherein There are P access units between the authentication data and the last access unit in the decoding order of the access units associated with the authentication data; where 0≤P≤(2 M -1)*Q, where Q is the maximum number of hash cycle indications.
21. A bit stream detection method, characterized in that: The method comprises: Get the security parameter set and authentication data in the bit stream; The security parameter set includes a hash period, where the hash period is used to indicate a maximum number of access units included in a bitstream segment; the authentication data includes signature data and a digest of each access unit in a set of access units, where the signature data is signed based on the digest of each access unit in the set of access units, where the set of access units includes at least one access unit in the bitstream segment; If an access unit participating in the signature exists in a hash cycle, the authentication data is detected in the next hash cycle in the direction of the bitstream decoding order of the current hash cycle; If the authentication data cannot be detected, it is determined that the authentication data is lost.
22. A bit stream detection method, characterized in that: The method comprises: Get the security parameter set and authentication data in the bit stream; The security parameter set includes a hash period, where the hash period is used to indicate the maximum number of access units included in a bitstream segment; the authentication data includes signature data and a digest of each access unit in a group of access units, where the signature data is signed according to the digest of each access unit in the group of access units; the authentication data carries an identifier, where the identifier occupies M bits, where M is an integer greater than or equal to 2, and the identifier is used to distinguish consecutive 2(M) authentication data in the bitstream; and the group of access units includes at least one access unit in the bitstream segment. If an access unit participating in the signature exists in a hash cycle, the authentication data is detected in the 2M-th power minus 1 hash cycle following the current hash cycle in the direction of bitstream decoding order; If the authentication data cannot be detected, it is determined that the authentication data is lost.
23. A bit stream detection method, characterized in that: The method comprises: Get the security parameter set in the bitstream and the number of authentication data within the scope of the security parameter set; The scope of the security parameter set is a random access segment in the bitstream where the security parameter set is located, and the security data set includes indication information, where the indication information is used to indicate the number of authentication data that should be included in the scope of the security parameter set; Determine the loss of authentication data based on the indication information and the number of authentication data within the scope of the security parameter set.
24. The method according to claim 23, wherein The determining, based on the indication information and the number of authentication data within the scope of the security parameter set, of the loss of authentication data includes: If the number of authentication data indicated by the indication information is consistent with the number of authentication data in the security parameter set, the authentication data is not lost; If the number of authentication data indicated by the instruction information is inconsistent with the number of authentication data in the security parameter set, the authentication data Lost.
25. A bitstream signature device, characterized in that: The device comprises: A first acquisition module, configured to acquire a security parameter set and authentication data; The security parameter set includes a hash period, which is used to indicate the maximum number of access units included in a bitstream segment. The authentication data includes signature data and a digest of each access unit in a set of access units. The signature data is obtained by signing the digest of each access unit in the set of access units. The set of access units includes at least one access unit in the bitstream segment. An output module is configured to output a bit stream, where the bit stream includes the security parameter set and the authentication data.
26. A bitstream signature device, characterized in that: The device comprises: A second acquisition module is used to obtain a security parameter set and authentication data; The security parameter set includes indication information, where the indication information is used to indicate the number of authentication data included within the scope of the security parameter set, where the scope of the security parameter set is the random access segment in the bitstream where the security parameter set is located, and the authentication data includes signature data and a digest of each access unit in a set of access units, where the signature data is signed based on the digest of each access unit in the set of access units; The second output module is configured to output a bit stream, where the bit stream includes the security parameter set and the authentication data.
27. A bit stream detection device, characterized in that: The device comprises: A third acquisition module is used to obtain the security parameter set and authentication data in the bit stream; The security parameter set includes a hash period, where the hash period is used to indicate a maximum number of access units included in a bitstream segment; the authentication data includes signature data and a digest of each access unit in a set of access units, where the signature data is signed based on the digest of each access unit in the set of access units, where the set of access units includes at least one access unit in the bitstream segment; The first detection module is used to detect authentication data in the next hash cycle along the bit stream decoding order direction of the current hash cycle if there is an access unit participating in the signature in a hash cycle; if the authentication data cannot be detected, it is determined that the authentication data is lost.
28. A bit stream detection device, characterized in that: The device comprises: a fourth acquisition module, configured to acquire a security parameter set and authentication data in the bit stream; The security parameter set includes a hash period, where the hash period is used to indicate the maximum number of access units included in a bitstream segment; the authentication data includes signature data and a digest of each access unit in a group of access units, where the signature data is signed according to the digest of each access unit in the group of access units; the authentication data carries an identifier, where the identifier occupies M bits, where M is an integer greater than or equal to 2, and the identifier is used to distinguish consecutive 2(M) authentication data in the bitstream; and the group of access units includes at least one access unit in the bitstream segment. The second detection module is used to detect authentication data in the 2M-th power minus 1 hash cycle after the current hash cycle along the bit stream decoding order direction if there is an access unit participating in the signature in a hash cycle; if no authentication data is detected, it is determined that the authentication data is lost.
29. A bit stream detection device, characterized in that: The device comprises: a fifth obtaining module, configured to obtain a security parameter set in the bit stream and the number of authentication data within the scope of the security parameter set; The scope of the security parameter set is a random access segment in the bitstream where the security parameter set is located, and the security data set includes indication information, where the indication information is used to indicate the number of authentication data that should be included in the scope of the security parameter set; The determination module is used to determine the loss of authentication data according to the indication information and the number of authentication data within the scope of the security parameter set.
30. A signature and authentication system, characterized in that: The system includes a signing end and an authentication end; The signing end is used to perform the method according to any one of claims 1 to 10; The authentication end is used to execute the method according to any one of claims 21 to 24.
31. A chip, characterized in that: The chip comprises at least one processor and a memory, wherein the at least one processor executes a program or instruction stored in the memory so that the chip implements the method described in any one of claims 1 to 10, or implements the method described in any one of claims 21 to 24.
32. A computing device, characterized in that include: A memory and a processor, wherein the memory is used to store computer instructions; when the processor executes the computer instructions, it implements the method according to any one of claims 1 to 10, or implements the method according to any one of claims 21 to 24.
33. A non-transitory computer-readable storage medium, characterized in that The storage medium stores a computer program or instruction, which, when executed by a processing device, implements the method described in any one of claims 1 to 10; and / or, when executed by a processing device, implements the method described in any one of claims 21 to 24.
34. A computer program product, characterized in that The computer program product contains computer instructions, which, when executed by a computer or a processor, cause the steps of the method according to any one of claims 1 to 10 to be performed, or the steps of the method according to any one of claims 21 to 24 to be performed.
35. A non-transitory computer-readable storage medium, characterized in that The computer-readable storage medium stores the bit stream according to any one of claims 11 to 20.