Encryption method and apparatus, and decryption method and apparatus
By carrying the key selection identifier in the NAL unit of the audio and video content, and carrying multiple encrypted video encryption keys and initialization vectors in the security parameter set of compressed video bitstream, the problem that the prior art cannot authorize part of the audio and video content separately according to the user level, and the encryption and decryption according to the user level is realized.
Patent Information
- Application Number
- PCT/CN2024/118891
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-24
- Filing Date
- 2024-09-13
- Publication Date
- 2025-06-19
AI Technical Summary
The prior art cannot authorize part of the audio and video content separately according to the user level, resulting in the inability to effectively protect the security of the audio and video content.
By carrying the key selection identifier in the NAL unit and carrying multiple encrypted video encryption keys and multiple initialization vectors in the security parameter set of compressed video bitstream, the decryption end can decrypt according to the key selection identifier and security parameter set.
It realizes the encryption and decryption of different NAL units of compressed video bit streams according to user level, meeting the needs of encrypting and authorizing video content of different types and confidentiality levels.
Smart Images

Figure CN2024118891_19062025_PF_FP_ABST
Abstract
Description
Encryption method, decryption method and device
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on December 12, 2023, with application number 202311706701.2 and application name “Encryption and decryption method of code stream”, and the Chinese patent application filed with the State Intellectual Property Office on January 24, 2024, with application number 202410104708.5 and application name “Encryption method, decryption method and device”, all contents of which are incorporated by reference into this application. Technical Field
[0002] The embodiments of the present application relate to the field of media, and in particular to an encryption method, a decryption method, and a device. Background Art
[0003] Many audio and video encoding and decoding scenarios (for example, surveillance, live broadcast, on-demand, etc.) have certain requirements for the authenticity and integrity of audio and video content. Therefore, in order to ensure the security of audio and video content during transmission and prevent the audio and video content from being tampered with during transmission, the audio and video content needs to be encrypted.
[0004] However, the current technology for encrypting and decrypting audio and video content has some defects: for example, in the current standard, a unified key is used to encrypt data for the same stream, and all users with the key can view the entire content of the stream. It cannot support the separate authorization of part of the stream content according to different user levels.
[0005] Summary of the Invention
[0006] In view of this, the present application provides an encryption method, a decryption method and an apparatus, which can support separate authorization of partial content of a code stream according to different levels of users.
[0007] In a first aspect, an embodiment of the present application provides an encryption method, which includes: first, obtaining a network abstraction layer (NAL) unit; then, extracting raw byte sequence payload (RBSP) data from the NAL unit, and encrypting the RBSP data according to the encryption method specified in the security parameter set to obtain encrypted RBSP data; then, splicing the NAL unit header and the encrypted RBSP data to obtain an encrypted NAL unit; wherein the encrypted NAL unit includes a key selection identifier, which is used to indicate an encrypted video encryption key (EVEK) and an initialization vector (IV) used to calculate a stream key; finally, outputting a compressed video bit stream; the compressed video bit stream includes the encrypted NAL unit and the security parameter set, and the security parameter set includes multiple encrypted video encryption keys and multiple initialization vectors.
[0008] The above-mentioned encryption method provided by the present application carries a key selection identifier in the NAL unit, and carries multiple encrypted video encryption keys and multiple initialization vectors in the security parameter set of the compressed video bitstream. It can indicate the encrypted video encryption key for calculating the stream key based on the key selection identifier, and carry multiple encrypted video encryption keys and multiple initialization vectors based on the security parameter set, so that the decryption end can decrypt the encrypted video encryption key and initialization vector corresponding to the key selection identifier to obtain the video encryption key, and then decrypt the encrypted NAL unit according to the video encryption key. In this way, the encrypted video encryption keys corresponding to different NAL units in the same compressed video bitstream can be different, so that different keys can be used to encrypt different NAL units of the compressed video bitstream according to the level (such as the confidentiality level). The decryption end can only realize the decryption of the encrypted NAL unit when it has the video key encryption key (Video Key Encryption Key, VKEK) corresponding to the key selection identifier, thereby meeting the needs of separately encrypting and authorizing video content of different types and different confidentiality levels.
[0009] In one possible implementation, the security parameter set also includes a key quantity and a key encryption key index. The key quantity indicates the number of encrypted video encryption keys or initialization vectors in the security parameter set. The key encryption key index indicates the video key encryption key index used to encrypt the video encryption key. Thus, during decoding, the decryption end can select the corresponding encrypted video encryption key based on the key selection identifier and the video key encryption key index. Only when the corresponding video key encryption key is available can the encrypted NAL unit be decrypted, thereby enabling the use of different keys according to the level to encrypt and decrypt different NAL units in the compressed video bitstream.
[0010] Optionally, the encryption method specified in the security parameter set is to encrypt the RBSP data using a video encryption key corresponding to the level of the RBSP data. The encrypted video encryption key obtained by encrypting the video encryption key with the video key encryption key is included in a plurality of encrypted video encryption keys in the security parameter set, and the encrypted video encryption key and the corresponding initialization vector are indicated by the key selection identifier.
[0011] In a possible implementation, the security parameter set is a security parameter set NAL unit.
[0012] In a possible implementation manner, the NAL unit header of the encrypted NAL unit includes a key selection identifier.
[0013] Optionally, the key selection identifier is a variable, and the variable is used to indicate that the stream key is calculated using the encrypted video encryption key indicated by the corresponding video key encryption key index and the initialization vector.
[0014] In a possible implementation, before encrypting the RBSP data, it is necessary to determine that the NAL unit needs to be encrypted, and set the NAL unit encryption flag in the NAL unit header to a first value, where the first value indicates that the NAL unit is encrypted.
[0015] In a second aspect, an embodiment of the present application provides a decryption method, which includes: first, obtaining a security parameter set and an encrypted NAL unit from a compressed video bitstream; wherein the encrypted NAL unit includes encrypted RBSP data and a key selection identifier, and the key selection identifier is used to indicate an encrypted video encryption key and an initialization vector used to calculate a stream key; then, decrypting the encrypted video encryption key indicated by the key selection identifier in the multiple encrypted video encryption keys and multiple initialization vectors contained in the security parameter set to obtain a video encryption key; wherein the security parameter set includes multiple groups of encrypted video encryption keys; then, taking out the encrypted RBSP data from the encrypted NAL unit, and using the video encryption key to decrypt the encrypted RBSP data of the encrypted NAL unit to obtain decrypted RBSP data; finally, splicing the NAL unit header and the decrypted RBSP data to obtain a decrypted NAL unit.
[0016] In one possible implementation, the security parameter set also includes a key quantity and a key encryption key index. The key quantity indicates the number of encrypted video encryption keys or initialization vectors in the security parameter set. The key encryption key index indicates the video key encryption key index used to encrypt the video encryption key. Thus, during decoding, the decryption end can select the corresponding encrypted video encryption key based on the key selection identifier and the video key encryption key index. Only when the corresponding video key encryption key is available can the encrypted NAL unit be decrypted, thereby enabling the use of different keys according to the level to encrypt and decrypt different NAL units in the compressed video bitstream.
[0017] In a possible implementation, the security parameter set is a security parameter set NAL unit.
[0018] In a possible implementation manner, the NAL unit header of the encrypted NAL unit includes a key selection identifier.
[0019] Optionally, the key selection identifier is a variable, and the variable is used to indicate that the stream key is calculated using the encrypted video encryption key indicated by the corresponding video key encryption key index and the initialization vector.
[0020] In a possible implementation, before decrypting the encrypted video encryption key to obtain the video encryption key, it is necessary to determine that the NAL unit is an encrypted NAL unit according to the NAL unit encryption flag in the NAL unit header.
[0021] In a third aspect, the present application provides a bitstream comprising a NAL unit and a security parameter set; wherein the NAL unit comprises encrypted RBSP data and a key selection identifier; the encrypted RBSP data is obtained by encrypting the RBSP data using a video encryption key, and the key selection identifier is used to indicate an encrypted video encryption key used to calculate a stream key; the security parameter set comprises multiple encrypted video encryption keys and multiple initialization vectors.
[0022] In one possible implementation, the code stream includes a compressed video bit stream.
[0023] In one possible implementation, the security parameter set also includes a key quantity and a key encryption key index, where the key quantity is used to indicate the number of encrypted video encryption keys or initialization vectors in the security parameter set, and the key encryption key index is used to indicate the video key encryption key index used to encrypt the video encryption key.
[0024] In a possible implementation, the security parameter set is a security parameter set NAL unit.
[0025] In a possible implementation manner, the NAL unit header of the encrypted NAL unit includes a key selection identifier.
[0026] In a possible implementation, the key selection identifier is a variable, and the variable is used to indicate the calculation of the stream key using the encrypted video encryption key indicated by the corresponding video key encryption key index and the initialization vector.
[0027] In a fourth aspect, an encryption device is provided. The encryption device includes a module for executing the method of any implementation method of the first aspect. For example, the encryption device includes a first acquisition module, a first extraction module, an encryption module, a first splicing module, and an output module. The first acquisition module is used to obtain a network abstraction layer (NAL) unit; the NAL unit includes a NAL unit header and raw byte sequence payload (RBSP) data. The first extraction module is used to extract the RBSP data. The encryption module is used to encrypt the RBSP data according to the encryption method specified in the security parameter set to obtain encrypted RBSP data. The first splicing module is used to splice the NAL unit header and the encrypted RBSP data to obtain an encrypted NAL unit; the encrypted NAL unit includes a key selection identifier, which is used to indicate an encrypted video encryption key and initialization vector used to calculate a stream key. The output module outputs a compressed video bitstream; the compressed video bitstream includes the encrypted NAL unit and the security parameter set, and the security parameter set includes multiple encrypted video encryption keys and multiple initialization vectors.
[0028] In a fifth aspect, a decryption device is provided. The decryption device includes a module for executing the method of any implementation of the second aspect. For example, the decryption device includes a second acquisition module, a decryption module, a second extraction module, and a second splicing module. The second acquisition module is configured to acquire a compressed video bitstream; the compressed video bitstream includes an encrypted NAL unit and a security parameter set. The encrypted NAL unit includes encrypted RBSP data and a key selection identifier, the key selection identifier indicating an encrypted video encryption key used to calculate a stream key. The security parameter set includes multiple encrypted video encryption keys and multiple initialization vectors. The decryption module is configured to decrypt the encrypted video encryption key indicated by the key selection identifier in the multiple encrypted video encryption keys and multiple initialization vectors contained in the security parameter set to obtain a video encryption key. The second extraction module is configured to extract the encrypted RBSP data from the encrypted NAL unit. The decryption module is further configured to decrypt the encrypted RBSP data based on the video encryption key to obtain decrypted RBSP data. The second splicing module is configured to splice the NAL unit header and the decrypted RBSP data to obtain a decrypted NAL unit.
[0029] In a sixth aspect, a coding device is provided, comprising: at least one processor, which, when executing program code or instructions, implements the method described in the first aspect or any possible implementation thereof.
[0030] Optionally, the encoding device may further include at least one memory, and the at least one memory is used to store the program code or instruction.
[0031] In a seventh aspect, a decoding device is provided, comprising: at least one processor, which, when executing program code or instructions, implements the method described in the second aspect or any possible implementation thereof.
[0032] Optionally, the decoding device may further include at least one memory, and the at least one memory is used to store the program code or instruction.
[0033] In an eighth aspect, an encryption and decryption system is provided. The encryption and decryption system includes an encryption end and a decryption end, wherein the encryption end is configured to implement the method described in any possible implementation of the first aspect, and the decryption end is configured to implement the method described in any possible implementation of the second aspect.
[0034] In a ninth aspect, an embodiment of the present application further provides a chip comprising: an input interface, an output interface, and at least one processor. Optionally, the chip further comprises a memory. The at least one processor is configured to execute code in the memory. When the at least one processor executes the code, the chip implements the method described in any possible implementation of the first or second aspect above.
[0035] Optionally, the chip may also be an integrated circuit.
[0036] In the tenth aspect, an embodiment of the present application further provides a non-transitory computer-readable storage medium for storing a computer program, which includes a method for implementing any possible implementation method in the first or second aspect above.
[0037] In the eleventh aspect, an embodiment of the present application further provides a computer program product comprising instructions, which, when executed on a computer, enables the computer to implement the method described in any possible implementation of the first or second aspect above.
[0038] The encoding and decoding device, computer storage medium, computer program product and chip provided in this embodiment are all used to execute the encryption and decryption method provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the encryption and decryption method provided above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] FIG1 is a schematic diagram of an exemplary application scenario;
[0040] FIG2 is a schematic diagram illustrating an exemplary encryption and decryption system 200;
[0041] FIG3 a is a schematic diagram illustrating an exemplary encryption process 300;
[0042] FIG3 b is a schematic diagram showing an exemplary compressed video bit stream;
[0043] FIG4 is a schematic diagram illustrating an exemplary decryption process 400;
[0044] FIG5 is a schematic diagram illustrating an encryption and decryption process 500 in a hierarchical encryption and decryption scenario;
[0045] FIG6 is a schematic diagram illustrating an exemplary encryption and decryption process 600 in a parity key mechanism scenario;
[0046] FIG7 is a schematic diagram of an exemplary encryption device;
[0047] FIG8 is a schematic diagram illustrating an exemplary decryption device;
[0048] FIG9 is a schematic structural diagram of an exemplary device. DETAILED DESCRIPTION
[0049] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0050] The term "and / or" in this article is merely a description of the association relationship between associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone.
[0051] In the description and claims of the embodiments of this application, the terms "first" and "second" are used to distinguish different objects, rather than to describe a specific order of objects. For example, the terms "first target object" and "second target object" are used to distinguish different objects, rather than to describe a specific order of objects.
[0052] In the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of this application should not be interpreted as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.
[0053] In the description of the embodiments of this application, unless otherwise specified, "multiple" means two or more. For example, "multiple processing units" means two or more processing units; "multiple systems" means two or more systems.
[0054] For example, the code stream encryption and decryption methods involved in this application can be applied to encrypting and decrypting any one of an audio compression code stream (or audio compression bit stream) or a video compression code stream (or video compression bit stream), and this application does not limit this. This application uses the encryption and decryption of a video compression code stream as an example. To keep the subsequent description concise, the technical terms that may be involved in this application are first explained.
[0055] bitstream
[0056] A binary data stream formed by coded image / audio frames. Both NAL unit streams and byte streams can be called bit streams.
[0057] The NAL unit stream format consists of a series of syntax structures called NAL units, which are sorted in decoding order. The decoding order and content of NAL units in a NAL unit stream are constrained.
[0058] A byte stream can be constructed from a NAL unit stream by placing the NAL units in decoding order and appending a start code prefix and a number of zero-valued bytes to each NAL unit to form a bit stream. The NAL unit stream format can be extracted from the bit stream format by searching for a unique start code prefix in the bit stream.
[0059] data unit
[0060] The basic syntax structure of the coded bit stream can be either a NAL unit or an access unit.
[0061] NAL unit
[0062] A syntax structure that contains an indication of the type of data that follows and the number of bytes it contains (located in the NAL header). The data appears in the form of a Raw Byte Sequence Payload (RBSP), which may also include interspersed security bytes.
[0063] access unit access unit
[0064] A set of NAL units that are related to each other according to specified rules and are consecutive in decoding order.
[0065] It should be noted that, from another perspective, a data unit may also include a coded image.
[0066] coded picture
[0067] The encoded representation of a frame of image.
[0068] Security Parameter Set
[0069] The security parameter set contains the configuration parameters required for encryption and authentication operations on the compressed video bitstream. At the beginning of the decoding process, each security parameter set takes effect when it is received by the decoder and will cause the previously valid security parameter set (if any) to become invalid. The security parameter set NAL unit should be present before the access unit (AU) of all random access point (RAP) pictures. The security parameter set NAL unit should be located in the same access unit as the sequence parameter set NAL unit, and the security parameter set NAL unit should be located before the sequence parameter set NAL unit. Therefore, the scope of the security parameter set is the random access segment in the compressed video bitstream where it is located, that is, all AUs in the bitstream from the AU where the security parameter set is located to the next RAP picture.
[0070] The security parameter set RBSP includes parameters that can be used by one or more other types of NAL units. At the start of the decoding process, each security parameter set RBSP takes effect upon receipt by the decoder and invalidates the previously valid security parameter set RBSP (if any). A security parameter set NAL unit should precede the access unit of all random access point pictures. When non-display knowledge pictures are present in the coded video sequence, a security parameter set should precede the access unit containing a patch_index value of 0 for non-RL pre-knowledge pictures, and a security parameter set should precede the access unit containing RL pre-knowledge pictures. Display pictures in adjacent random access picture intervals use the same security parameter set, and knowledge pictures use the same security parameter set as display pictures in the random access picture interval in which their bitstreams are generated. The security parameter set NAL unit should be located in the same access unit as the sequence parameter set NAL unit, and the security parameter set NAL unit should precede the sequence parameter set NAL unit. If the access unit contains a coded picture boundary NAL unit, the security parameter set NAL unit should follow the coded picture boundary NAL unit. At most one security parameter set RBSP is valid at a given moment in the decoding process.
[0071] An access unit (AU) refers to a group of NAL units that are associated with each other according to specified rules and are arranged continuously in decoding order to form a compressed video bit stream.
[0072] Figure 1 is a schematic diagram of exemplary application scenarios, showing a monitoring scenario, a live broadcast scenario, and a video-on-demand scenario.
[0073] Referring to Figure 1 , in an exemplary surveillance scenario, camera 11 can encrypt a surveillance video stream to obtain an encrypted surveillance video stream 101. This encrypted surveillance video stream 101 is then sent to laptop computer 13 via network 12. Laptop computer 13 can then decrypt this encrypted surveillance video stream 101, obtain and display the decryption result 105, and play surveillance video 104.
[0074] 1 , for example, in a live broadcast scenario, mobile phone 14 can encrypt a live video stream to obtain an encrypted live video stream 102. Then, encrypted live video stream 102 is sent to mobile phone 15 via network 12. Mobile phone 15 can then decrypt encrypted live video stream 102, obtain and display a decryption result 107, and play live video 106.
[0075] 1 , in an exemplary on-demand scenario, a personal computer 16 can encrypt an on-demand video stream to obtain an encrypted on-demand video stream 103. The encrypted on-demand video stream 103 is then sent to a mobile phone 17 via a network 12. The mobile phone 17 can then decrypt the encrypted on-demand video stream 103, obtain and display a decryption result 109, and play the on-demand video 108.
[0076] It should be understood that the present application can also be used in other audio and video encoding and decoding scenarios, such as digital content trusted scenarios, etc., and the present application does not limit this.
[0077] Fig. 2 is a schematic diagram of an exemplary encryption and decryption system 200. Fig. 2 illustrates the decryption and encryption process in Fig. 1 .
[0078] 2 , illustratively, the encryption and decryption system 200 may include an encryption end 210 and a decryption end 220 .
[0079] For example, the encryption end 210 can be a front-end device such as the camera 11, mobile phone 14 and personal computer 16 in Figure 1 above, and the decryption end 220 can be a back-end device such as the laptop computer 13, mobile phone 15 and mobile phone 17 in Figure 1 above.
[0080] It should be understood that the same terminal device can serve as both the encryption end 210 and the decryption end 220, and this application does not impose any limitation on this.
[0081] 2 , illustratively, after the encryption end 210 obtains the video data 201 , it may perform video encoding 21 on the video data 201 to obtain a code stream 202 ; and perform video encryption 22 on the code stream 202 to obtain an encrypted code stream 203 .
[0082] For example, the video data 201 may be a surveillance video captured by the camera 11 in FIG. 1 , a live video recorded by the mobile phone 14 , or a video on demand produced by the personal computer 16 .
[0083] For example, the encrypted code stream 203 may be the encrypted surveillance video code stream 101, the encrypted live video code stream 102, or the encrypted on-demand video code stream 103 in FIG. 1 .
[0084] It should be noted that the video encoding 21 and the video encryption 22 operations can be performed in parallel.
[0085] It should be noted that, in one possible embodiment, the encryption end 210 may include an encoder, and the encoder performs video encoding 21 and video encryption 22. In another possible embodiment, the encryption end 210 may include an encoder and an encryption module, and the encoder performs video encoding 21, and the encryption module performs video encryption 22. In another possible embodiment, the encryption end 210 may include an encryption module, and the encryption module performs video encoding 21 and video encryption 22.
[0086] Afterwards, the encryption end 210 may send the encrypted code stream 203 to the decryption end 220 .
[0087] 2 , illustratively, after the decryption end 220 receives the encrypted code stream 203 , it can perform video decryption 23 on the encrypted code stream 203 to obtain a decryption result 205 ; and it can perform video decoding 24 on the code stream 202 in the encrypted code stream 203 to obtain decoded video data 204 .
[0088] For example, the decoded video data 204 may be the surveillance video 104, the live video 106, or the on-demand video 108 in FIG. 1 .
[0089] For example, the decryption result 205 may be the decryption result 105 , the decryption result 107 , or the decryption result 109 in the above-mentioned image 1 .
[0090] It should be noted that the video decryption 23 and the video decoding 24 can be performed in parallel.
[0091] It should be noted that, in one possible embodiment, the decryption end 220 may include a decoder, which performs video decoding 24 and video decryption 23. In another possible embodiment, the decryption end 220 may include a decoder and a decryption module, which performs video decoding 24 and video decryption 23. In another possible embodiment, the decryption end 220 may include a decryption module, which performs video decoding 24 and video decryption 23.
[0092] It should be noted that when the encryption end 210 performs lossless encoding, the video data and the decoded video data are the same; when the encryption end 210 performs lossy encoding, there are differences between the video data and the decoded video data.
[0093] It should be noted that the encoder, decoder and decryption module can be implemented by software or hardware, and this application does not impose any restrictions on this.
[0094] FIG3 a is a schematic diagram illustrating an exemplary encryption process 300 , wherein the process 300 may be implemented by the encryption terminal 210 .
[0095] S301, obtain NAL unit;
[0096] As a possible implementation, extract a NAL unit from the compressed video bitstream output by the encoder and determine whether the NAL unit needs to be encrypted based on the configuration. If necessary, set the NAL unit encryption flag (e.g., encryption_idc) in the NAL unit header to 1 and continue with the following operations.
[0097] The NAL unit includes a NAL unit header and RBSP data.
[0098] S302, extract RBSP data;
[0099] If the RBSP data has been processed with an anti-counterfeiting start code, the anti-counterfeiting start code needs to be removed.
[0100] S303, encrypting the RBSP data according to the encryption method specified in the security parameter set to obtain encrypted RBSP data;
[0101] After obtaining the encrypted RBSP data, an anti-counterfeiting start code may be added to the encrypted RBSP.
[0102] S304, concatenating the NAL unit header and the encrypted RBSP data to obtain an encrypted NAL unit;
[0103] The encrypted NAL unit includes a key selection identifier, which indicates the encrypted video encryption key and initialization vector used to calculate the stream key. The encrypted video encryption key indicated by the key selection identifier is obtained by encrypting the video encryption key using the video key encryption key. The encrypted video encryption key may also be referred to as the encrypted video encryption key. The video key encryption key is selected using the encryption method specified in the security parameter set. The video encryption key can be a randomly generated key based on the security parameter set or a randomly selected key from the key library based on the security parameter set.
[0104] In a possible implementation, the key selection identifier may be encoded into the NAL unit header of the encrypted NAL unit.
[0105] In a possible implementation, the key selection identifier may be encoded into the NAL unit header of the encrypted NAL unit according to a preset syntax table.
[0106] Exemplarily, the key selection identifier may be encoded into the NAL unit header of the encrypted NAL unit according to the syntax table shown in Table 1.
[0107] Table 1
[0108] Among them, forbidden_zero_bit is the zero prohibition code, a binary variable, and should be equal to 0.
[0109] nal_ref_idc is a binary variable that is a NAL unit reference flag. When it is not equal to 0, it indicates that the content of the NAL unit contains a sequence parameter set, a picture parameter set, a security parameter set, an authentication data set, a picture header, or a coded slice of a reference picture. When the nal_ref_idc of a coded slice NAL unit of a coded picture is equal to 0, the nal_ref_idc of all coded slice NAL units of the coded picture should be equal to 0.
[0110] nal_unit_type is the NAL unit type identifier, a 5-bit unsigned integer. It indicates the type of RBSP data structure in the NAL unit. VCL NAL units are NAL units with a nal_unit_type value of 0, 1, 2, 12, 14, 17, 18, or 19. All other NAL units are called non-VCL NAL units. NAL units with a nal_unit_type value of 11 may be discarded by the decoder without affecting the decoding process of NAL units with a nal_unit_type value other than 11 and without affecting conformance to this standard. When the nal_unit_type value of a coded slice NAL unit is 0, 1, 2, 12, or 17, the nal_unit_type value of all other coded slice NAL units encoding the same picture shall be the same. If UserPermission is 0, NAL units with a nal_unit_type value of 19 may be discarded by the decoder. When the nal_unit_type value of a coded slice NAL unit is 19, the RBSP data contains data for several coding units in the coded slice of the picture.
[0111] encryption_idc is an encryption flag, a binary variable. It indicates whether the NAL unit is encrypted. A value of '0' indicates that the RBSP in the NAL unit is not encrypted. A value of '1' indicates that the RBSP in the NAL unit is encrypted as the basic data unit using the encryption method specified in the security parameter set. The last byte of the RBSP is not encrypted. When the nal_unit_type of a NAL unit is 11, 15, or 16, encryption_idc should be 0.
[0112] authentication_idc is an authentication flag, a binary variable. It indicates whether the NAL unit is authenticated. A value of '0' indicates that the NAL unit is unauthenticated, while a value of '1' indicates that the NAL unit is authenticated using the authentication method specified in the security parameter set, and the coded bitstream must carry absolute time extension information to identify the authentication time. When the nal_unit_type of a NAL unit is 11, 15, or 16, authentication_idc should be 0.
[0113] temporal_id is a 3-bit unsigned integer that identifies the temporal layer of the current picture. The temporal layer identifier ranges from 0 to MAX_TEMPORAL_ID. A temporal layer identifier of 0 indicates the lowest layer. When the nal_unit_type of a NAL unit is 7, 8, 9, 11, or 16, temporal_id should be 0. The temporal_id of the picture header NAL unit and all coded slice NAL units of a coded picture should be the same. The temporal_id of all NAL units in an access unit should be the same as the temporal_id of the coded slice NAL units in the access unit.
[0114] layer_id is a 3-bit unsigned integer that specifies the layer identifier of the current image. The layer identifier value ranges from 0 to MAX_LAYERS. The layer_id of the sequence parameter set and picture parameter set NALUs is 0. The layer_id of the picture header NAL unit and all coded slice NAL units of a coded picture should be the same. The value of layerId is equal to the value of layer_id.
[0115] The key selection identification part newly added in this application includes encryption_key_sel. For example, encryption_key_sel is the encryption key selection, a 2-bit variable, and a value range of 0 to 3 (in other possible embodiments, it can also be any value range). The constraint value range of the current level (the level is determined by the currently used codec protocol) is 0 to 1. A value of '0' indicates that evek[0] and iv[0] are used to calculate the stream key, and a value of '1' indicates that evek[1] and iv[1] are used to calculate the stream key.
[0116] A profile is a subset of specified syntax, semantics, and algorithms, indicating the profile to which a bitstream conforms. A level is a defined set of syntax elements and syntax element parameter values within a particular profile.
[0117] Profiles and levels provide a means of defining subsets of the syntax and semantics of this document. Profiles and levels impose various constraints on the bitstream, thereby specifying the decoder capabilities required to decode a particular bitstream. A profile is a subset of the syntax, semantics, and algorithms specified in this document. A decoder conforming to a profile must fully support the subset defined by that profile. A level is a restricted set of syntax elements and syntax element parameter values within a profile. Within a given profile, different levels often imply different decoder capabilities and memory requirements.
[0118] This application describes the various restrictions corresponding to different profiles and levels. All unrestricted syntax elements and parameters can take any value allowed by this document. If a decoder can correctly decode all allowed values of syntax elements specified by a profile and level, then the decoder is said to comply with this document at this profile and level. If a bitstream does not contain syntax elements that are not allowed by a profile and level, and the values of the syntax elements it contains do not exceed the range allowed by this profile and level, then the bitstream is considered to comply with this document at this profile and level.
[0119] profile_id and level_id define the profile and level of the bitstream.
[0120] S305: Output the compressed video bit stream.
[0121] The compressed video bitstream includes an encrypted NAL unit and a security parameter set. The security parameter set includes a plurality of encrypted video encryption keys and a plurality of initialization vectors.
[0122] Exemplarily, the output compressed video bit stream may be as shown in FIG3b, including a security parameter set, one or more data units, and authentication data, such as data unit 1, data unit 2, data unit 3, ... data unit n. In this embodiment, the data unit may be a NAL unit. In another possible embodiment, the data unit may also be a layer unit, an access unit, etc.
[0123] In one possible implementation, the security parameter set further includes a key quantity and a key encryption key index. The key quantity indicates the number of encrypted video encryption keys and initialization vectors in the security parameter set, and the key encryption key index indicates the video key encryption key used to encrypt the video encryption key.
[0124] In a possible implementation, multiple encrypted video encryption keys, multiple initialization vectors, key quantities, and key encryption key indexes may be compiled into a security parameter set according to a preset syntax.
[0125] In one possible implementation, multiple encrypted video encryption keys, multiple initialization vectors, key quantities, and key encryption key indexes can be compiled into a security parameter set according to the syntax table shown in Table 2. Table 2 only shows the multiple encrypted video encryption keys, multiple initialization vectors, key quantities, and key encryption key indexes newly added to this application. The existing parts of the security parameter set can be referred to Table 3, but will not be repeated here.
[0126] Table 2
[0127] evek_iv_num_minus1 is the number of keys, a 2-bit variable with a value range of 0 to 3 (or any value range in other possible embodiments). The current profile (the profile is determined by the currently used codec protocol) constrains the value range of 0 to 1. The number of keys indicates the number of video encryption keys and initialization vectors after encryption in the security parameter set.
[0128] vkek_id_for_evek[i] is the key encryption key index, a 2-bit variable with a value range of 0 to 3. The current profile constraint value range is 0 to 1. The key encryption key index is used to indicate the video key encryption key index used to encrypt the video encryption key.
[0129] evek[i] is the i-th encrypted video encryption key, and iv[i] is the i-th initialization vector, which can be collectively referred to as the i-th key group.
[0130] Table 3
[0131] Among them, the encryption flag encryption_flag indicates whether there is a NAL unit with a NAL unit encryption flag of 1 within the scope of the current security parameter set, or whether there is a NAL unit for encryption operation.
[0132] The authentication flag, authentication_flag, indicates whether there are any NAL units with the authentication flag set to 1 within the scope of the current security parameter set, or whether any NAL units are subject to authentication. If an AU contains at least one NAL unit with authentication_idc equal to 1, all NAL units with authentication_idc set to 1 in the access unit are sorted in decoding order and hashed to generate the digest data for the access unit. The digest data of the access unit will be used for authentication.
[0133] The number of consecutive authentication image frames successive_hash_pictures_minus1 plus 1 represents the number of consecutive access units signed in the decoding order.
[0134] encryption_type is the encryption type, a 4-bit unsigned integer that indicates the encryption algorithm used. For example, a value of 0 for encryption_type corresponds to SM1, a value of 1 corresponds to SM4, and values of 2 to 15 correspond to reserved encryption algorithms.
[0135] vek_flag is the video encryption key flag, a binary variable. A value of '1' indicates that vek is carried, and a value of '0' indicates that vkek is not carried.
[0136] iv_flag is the initialization vector flag, a binary variable. A value of '1' indicates that the iv is carried, and a value of '0' indicates that the iv is not carried.
[0137] vek_encryption_type is the video encryption key encryption type, a 4-bit unsigned integer, indicating the encryption type of the video encryption key.
[0138] evek_length_minus1 is the length of the encrypted video encryption key, an 8-bit unsigned integer. It indicates the length of the encrypted video encryption key in bytes.
[0139] evek is the encrypted video encryption key, an n-bit unsigned integer. It represents the encrypted video encryption key and is used for encryption calculations. Its length is evek_length_minus1 plus 1 byte.
[0140] vkek_version length_minus1 is the length of the video encryption key version number, an 8-bit unsigned integer. Indicates the length of the video encryption key version number in bytes.
[0141] vkek_version is the video encryption key version number, an n-bit unsigned integer. Indicates the video encryption key version number, and its length is vkek_version_length_minus1 plus 1 byte.
[0142] iv_length_minus1 is an 8-bit unsigned integer representing the length of the initial vector, in bytes.
[0143] iv is the initialization vector, an n-bit unsigned integer. It indicates the initialization vector used for block encryption and has a length of iv_length_minus1 plus 1 byte.
[0144] hash_type is a 2-bit unsigned integer representing the hash type. It indicates the authentication algorithm used. For example, a hash_type value of 0 corresponds to the SM3 authentication algorithm with a digest length of 32 bytes. A hash_type value of 1 to 3 corresponds to the reserved authentication algorithm.
[0145] hash_discard_non_output_library_pictures_flag is a binary variable that indicates the hash authentication flag for non-display knowledge images. A value of '1' indicates that non-display knowledge images are not authenticated; a value of 0 indicates that non-display knowledge images are authenticated by digitally signing only the image digest data. If hash_discard_library_pictures is not included in the bitstream, its default value is 1. The authentication_idc field of each NAL unit in non-authenticated images should be 0.
[0146] hash_discard_pb_pictures_flag is a binary variable that specifies the hash authentication flag for P / B frames. A value of '1' indicates that authentication is not performed for all pictures except random access point pictures and knowledge pictures; a value of 0 indicates that authentication is performed for all pictures except random access point pictures and knowledge pictures. If hash_discard_pb_pictures is not present in the bitstream, its default value is 1. The authentication_idc flag for each NAL unit in pictures not to be authenticated shall be 0.
[0147] successive_hash_pictures_minus1 is the number of consecutive authenticated image frames, an 8-bit unsigned integer. This represents the number of consecutive images in the coded video sequence that are digitally signed in decoding order. These consecutive images can include display images and display knowledge images, and these consecutive images are limited to a single random access image or RLI frame interval. The value of successive_hash_pictures_minus1 should be between 0 and 255.
[0148] signature_type is the digital signature type, a 2-bit unsigned integer. It indicates the algorithm used to digitally sign the image's summary data. For example, a signature_type value of 0 corresponds to the SM2 signature algorithm, while signature_type values of 1 to 3 correspond to reserved signature algorithms.
[0149] signature_fmt is a 2-bit unsigned integer indicating the signature data format. The corresponding relationship between the value of signature_fmt and the syntax of signature_type can be shown in Table 4 below.
[0150] Table 4
[0151] FIG4 is a schematic diagram illustrating an exemplary decryption process 400 , wherein the process 400 may be implemented by the decryption terminal 220 , and the process 400 corresponds to the process 300 .
[0152] S401, obtaining a compressed video bit stream;
[0153] A compressed video bitstream is input to the decryption terminal 220. The compressed video bitstream includes an encrypted NAL unit and a security parameter set. The security parameter set contains multiple encrypted video encryption keys and multiple initialization vectors. The encrypted RBSP data of the encrypted NAL unit is encrypted as configured. The security parameter set can be a security parameter set NAL unit, but the security parameter set NAL unit is unencrypted and is different from the encrypted NAL unit in this application.
[0154] S402, decrypting the encrypted video encryption key indicated by the key selection identifier in the multiple encrypted video encryption keys and the multiple initialization vectors to obtain a video encryption key;
[0155] As one possible implementation, a key selection identifier is retrieved from the encrypted NAL unit. The key selection identifier indicates the encrypted video encryption key and initialization vector used to calculate the stream key. The encrypted video encryption key indicated by the key selection identifier is then decrypted to obtain the video encryption key. For example, the encrypted video encryption key and initialization vector are used to calculate the stream key, i.e., the video encryption key.
[0156] Optionally, the encrypted video encryption key and initialization vector are decrypted using a video key encryption key to obtain the video encryption key and initialization vector, wherein the video key encryption key is determined according to the key encryption key index in the security parameter set.
[0157] For the method of carrying the above-mentioned multiple sets of encrypted video encryption keys in the security parameter set, please refer to Table 3 and related descriptions above. For the method of carrying the key selection identifier in the NAL unit header, please refer to Table 2 and related descriptions above, which will not be repeated here.
[0158] S403, extract the encrypted RBSP data from the encrypted NAL unit;
[0159] If an anti-counterfeiting start code has been added to the encrypted RBSP data, remove the anti-counterfeiting start code from the encrypted RBSP data.
[0160] S404, decrypting the encrypted RBSP data according to the video encryption key to obtain decrypted RBSP data;
[0161] In a possible embodiment of the present application, the video encryption key, the video key encryption key, etc. are symmetric encryption keys. The encryption end 210 and the decryption end 220 can use the same key to encrypt and decrypt data. The specific encryption and decryption methods can be any symmetric encryption method, which will not be repeated here.
[0162] S405: Concatenate the NAL unit header and the decrypted RBSP data to obtain a decrypted NAL unit.
[0163] Optionally, an anti-counterfeiting start code is added to the decrypted RBSP data of the decrypted NAL unit.
[0164] In some possible embodiments, a subsequent decoder directly processes the decrypted RBSP data and does not need to restore the decrypted RBSP data to a decrypted NAL unit, and therefore S405 does not need to be performed.
[0165] In some possible embodiments, when the decrypted RBSP data does not need to be restored to the decrypted NAL unit, there is no need to add an anti-counterfeiting start code to the decrypted RBSP data of the decrypted NAL unit.
[0166] In combination with the encryption method shown in FIG3a and the decryption method shown in FIG4, a key selection identifier is carried in the NAL unit, and multiple encrypted video encryption keys and multiple initialization vectors are carried in the security parameter set of the compressed video bitstream. The encrypted video encryption key used to calculate the stream key can be indicated based on the key selection identifier, and multiple encrypted video encryption keys and multiple initialization vectors are carried based on the security parameter set, so that the decryption end can decrypt the encrypted video encryption key and initialization vector corresponding to the key selection identifier to obtain the video encryption key, and then decrypt the encrypted NAL unit based on the video encryption key. In this way, the encrypted video encryption keys corresponding to different NAL units in the same compressed video bitstream can be different, so that different keys can be used to encrypt different NAL units of the compressed video bitstream according to the level (such as the confidentiality level). The decryption end can only decrypt the encrypted NAL unit when it has the video key encryption key corresponding to the key selection identifier, thereby meeting the requirements of separately encrypting and authorizing video content of different types and different confidentiality levels.
[0167] The above-mentioned encryption method and decryption method provided in this application can be applied to any encoding and decoding scenario that requires multiple sets of keys. The application scenarios of the above-mentioned encryption method and decryption method are exemplified below using the hierarchical encryption and decryption scenario and the parity key mechanism scenario.
[0168] FIG5 is a schematic diagram illustrating an encryption and decryption process 500 in a hierarchical encryption and decryption scenario, wherein the process 500 can be implemented by the encryption end 210 and the decryption end 220 in cooperation with each other.
[0169] S501, the encryption end 210 obtains a NAL unit;
[0170] Please refer to S301 in FIG. 3 a for the above S501 , which will not be described in detail here.
[0171] S502: The encryption end 210 determines the level of the NAL unit.
[0172] The above-mentioned levels may refer to confidentiality levels, etc., or they may refer to grades and levels.
[0173] S503, the encryption end 210 encrypts the RBSP data according to the level of the NAL unit to obtain an encrypted NAL unit;
[0174] In this embodiment, S502 executes the process of S302-S304 shown in Figure 3a. The difference is that different RBSP data may have different levels (for example, confidentiality levels). After the encryption end 210 determines the level of the RBSP data, it selects the video key encryption key and initialization vector corresponding to the level of the RBSP data according to the encryption method specified in the security parameter set to encrypt the video encryption key, obtain the encrypted video encryption key, and set the encryption_key_sel in the key selection identifier to the variables corresponding to the encrypted video encryption key and initialization vector.
[0175] S504, the encryption end 210 outputs a compressed video bit stream;
[0176] The specific processing method of the above S504 is the same as that of S305 shown in FIG3 a , and will not be repeated here.
[0177] S505, the decryption terminal 220 obtains the compressed video bit stream;
[0178] For a specific method of obtaining the compressed video bit stream, please refer to S401 in FIG. 4 , which will not be described in detail here.
[0179] S506, the decryption terminal 220 determines the video key encryption key according to the key encryption key index;
[0180] The decryption terminal 220 obtains a video key encryption key based on the key encryption key index. The video key encryption key is used to encrypt the video encryption key to obtain the encrypted video encryption key indicated by the key selection identifier. The video key encryption key may be stored locally on the decryption terminal 220. If the decryption terminal 220 locally stores the video key encryption key corresponding to the key encryption key index, or if the level of the decryption terminal 220 meets the level constraint value range of the key encryption key index, the level of the decryption terminal 220 is sufficient to decrypt the encrypted NAL unit.
[0181] S507, the decryption terminal 220 uses the video key encryption key to decrypt the encrypted video encryption key indicated by the key selection identifier to obtain the video encryption key;
[0182] For the specific processing method of the above S507, please refer to S402 shown in FIG4 , which will not be described in detail here.
[0183] S508: The decryption terminal 220 decrypts the encrypted RBSP data using the video encryption key to obtain a decrypted NAL unit.
[0184] For the specific processing method of decrypting the encrypted RBSP data, please refer to S403-S405 in Figure 4, which will not be repeated here.
[0185] Based on the above S501-S508, the encryption end 210 adds a key selection identifier in the NAL unit, and the key selection identifier corresponds to the level of the encrypted NAL unit. At the same time, multiple encrypted video encryption keys and multiple initialization vectors are added to the security parameter set, so that the decryption end 220 can decrypt the encrypted video encryption key corresponding to the key selection identifier when the level can decrypt the encrypted NAL unit, obtain the video encryption key and the corresponding initialization vector, and then decrypt the encrypted NAL unit according to the video encryption key and the initialization vector. In this way, the keys corresponding to different NAL units in the same compressed video bit stream can be different, so that different NAL units of the compressed video bit stream can be encrypted using different keys according to the level. The decryption end can only decrypt the encrypted NAL unit when it has the video key encryption key corresponding to the key selection identifier, thereby meeting the requirements of separately encrypting and authorizing video content of different types and different confidentiality levels.
[0186] 6 is a schematic diagram illustrating an encryption and decryption process 600 in a parity key mechanism scenario. The process 600 may be implemented by the encryption end 210 and the decryption end 220 in cooperation with each other.
[0187] S601, the encryption end 210 obtains a NAL unit;
[0188] S602, the encryption end 210 encrypts the RBSP data to obtain an encrypted NAL unit;
[0189] S603, the encryption end 210 outputs a compressed video bit stream;
[0190] For the specific processing method of the above S601-S603, please refer to S301-S305 shown in Figure 3a, which will not be repeated here.
[0191] S604, the decryption terminal 220 obtains the compressed video bit stream;
[0192] S605, the decryption terminal 220 determines the video key encryption key according to the key encryption key index;
[0193] For the specific processing method of the above S604-S605, please refer to S505-S506 shown in Figure 5, which will not be repeated here.
[0194] S606, the decryption terminal 220 obtains multiple encrypted video encryption keys according to the key selection identifier;
[0195] The decryption terminal 220 obtains all or part of the encrypted video encryption key from the multiple sets of encrypted video encryption keys carried by the security parameter set according to the key selection identifier. Taking the compressed video bitstream including multiple encrypted NAL units as an example, all or part of the encrypted video encryption key includes the encrypted video encryption key corresponding to the current NAL unit and the encrypted video encryption keys corresponding to the next n encrypted NAL units. In this way, when the decryption terminal 220 needs to perform a key change to decrypt subsequent encrypted NAL units, it prepares the key stream in advance to ensure seamless connection of the decryption operation during the key switch, thereby reducing the delay introduced by the process of generating the stream key, reducing the jitter of the subsequent decoding process, and improving the decoding performance.
[0196] S607, the decryption terminal 220 uses the video key encryption key to decrypt the encrypted video encryption key indicated by the key selection identifier to obtain the video encryption key;
[0197] S608: The decryption terminal 220 decrypts the encrypted RBSP data using the video encryption key to obtain a decrypted NAL unit.
[0198] For the specific processing method of the above S607-S608, please refer to S507-S508 shown in Figure 5, which will not be repeated here.
[0199] Figure 7 is a schematic diagram of an exemplary encryption device. The schematic diagram of the encryption device can be used to execute the method of the aforementioned embodiment. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding method provided above, and will not be repeated here.
[0200] Referring to FIG. 7 , illustratively, the encryption device 700 includes:
[0201] The first acquisition module 701 is used to obtain a network abstraction layer NAL unit; the NAL unit includes a NAL unit header and raw byte sequence payload RBSP data;
[0202] A first extraction module 702 is used to extract RBSP data;
[0203] An encryption module 703 is configured to encrypt the RBSP data according to an encryption method specified in the security parameter set to obtain encrypted RBSP data;
[0204] A first splicing module 704 is configured to splice the NAL unit header and the encrypted RBSP data to obtain an encrypted NAL unit; the encrypted NAL unit includes a key selection identifier, the key selection identifier being used to indicate an encrypted video encryption key and an initialization vector for calculating a stream key;
[0205] The output module 705 outputs a compressed video bit stream; the compressed video bit stream includes an encrypted NAL unit and a security parameter set, and the security parameter set includes multiple encrypted video encryption keys and multiple initialization vectors.
[0206] Exemplarily, the security parameter set further includes a key quantity and a key encryption key index, where the key quantity is used to indicate the number of encrypted video encryption keys or initialization vectors in the security parameter set, and the key encryption key index is used to indicate a video key encryption key index for encrypting the video encryption key.
[0207] Exemplarily, the security parameter set is a security parameter set NAL unit.
[0208] Exemplarily, the NAL unit header of the encrypted NAL unit includes a key selection identifier.
[0209] Exemplarily, the key selection identifier is a variable, and the variable is used to indicate that the stream key is calculated using the encrypted video encryption key indicated by the corresponding video key encryption key index and the initialization vector.
[0210] Exemplarily, the first acquisition module 701 is further used to: determine that the NAL unit needs to be encrypted; and set the NAL unit encryption flag in the NAL unit header of the NAL unit to a first value, where the first value indicates that the NAL unit is encrypted.
[0211] Exemplarily, the first extraction module 702 is further configured to: remove the anti-counterfeiting start code when the RBSP data has been processed with the anti-counterfeiting start code. The output module 705 is further configured to: add the anti-counterfeiting start code to the encrypted RBSP data.
[0212] When encryption device 700 implements any of the encryption methods shown in the aforementioned figures through software, encryption device 700 and its various units may also be software modules. The aforementioned encryption method is implemented by invoking the software module via a processor. The processor may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or a programmable logic device (PLD). The PLD may be a complex programmable logical device (CPLD), a field programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0213] It can be understood that the encryption device 700 shown in FIG7 is only an example provided in this embodiment. The encryption device 700 may include more or fewer units according to different encryption and decryption processes, and this application does not limit this.
[0214] When the encryption device 700 is implemented via hardware, the hardware may be implemented via a processor or a chip system. The chip system includes one or more chips, each of which includes an interface circuit and a control circuit. The interface circuit is used to receive data from other devices outside the chip and transmit it to the control circuit, or to send data from the control circuit to other devices outside the chip. The control circuit and interface circuit implement the method of any possible implementation method in the above embodiments through logic circuits or executing code instructions. The beneficial effects can be found in the description of any aspect of the above embodiments and will not be repeated here.
[0215] It is understood that the processor in the embodiments of the present application may be a CPU, or other general-purpose processor, digital signal processor (DSP), ASIC, FPGA or other programmable logic device, transistor logic device, hardware component or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0216] Figure 8 is a schematic diagram of an exemplary decryption device. The schematic diagram of the decryption device can be used to execute the method of the aforementioned embodiment. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding method provided above, and will not be repeated here.
[0217] Referring to FIG8 , illustratively, the decryption device 800 includes:
[0218] A second acquisition module 801 is configured to acquire a compressed video bitstream, wherein the compressed video bitstream includes an encrypted NAL unit and a security parameter set, the encrypted NAL unit includes encrypted RBSP data and a key selection identifier, the key selection identifier is used to indicate an encrypted video encryption key used to calculate a stream key, and the security parameter set includes multiple encrypted video encryption keys and multiple initialization vectors;
[0219] a decryption module 802 configured to decrypt the encrypted video encryption key indicated by the key selection identifier among the multiple encrypted video encryption keys included in the security parameter set to obtain a video encryption key;
[0220] The second extraction module 803 is used to extract the encrypted RBSP data from the encrypted NAL unit;
[0221] The decryption module 802 is further configured to decrypt the encrypted RBSP data according to the video encryption key to obtain decrypted RBSP data;
[0222] The second splicing module 804 is further configured to splice the NAL unit header and the decrypted RBSP data to obtain a decrypted NAL unit.
[0223] Exemplarily, the security parameter set further includes a key quantity and a key encryption key index, where the key quantity is used to indicate the number of encrypted video encryption keys and initialization vectors in the security parameter set, and the key encryption key index is used to indicate a video key encryption key index for encrypting the video encryption key.
[0224] Exemplarily, the security parameter set is a security parameter set NAL unit.
[0225] Exemplarily, the NAL unit header of the encrypted NAL unit includes a key selection identifier.
[0226] Exemplarily, the key selection identifier is a variable, and the variable is used to indicate that the stream key is calculated using the encrypted video encryption key indicated by the corresponding video key encryption key index and the initialization vector.
[0227] Exemplarily, the second acquisition module 801 is further configured to: determine the encrypted NAL unit according to the NAL unit encryption flag of the encrypted NAL unit header.
[0228] Exemplarily, the second extraction module 803 is further configured to: when the encrypted RBSP data has been processed with an anti-counterfeiting start code, remove the anti-counterfeiting start code.
[0229] Exemplarily, the second splicing module 804 is further configured to add an anti-counterfeiting start code to the decrypted RBSP data of the decrypted NAL unit.
[0230] When decryption device 800 implements any of the decryption methods shown in the aforementioned figures via software, decryption device 800 and its various units may also be software modules. A processor invokes these software modules to implement the aforementioned decryption methods. The processor may be a CPU, an ASIC, or a PLD. The PLD may be a CPLD, an FPGA, a GAL, or any combination thereof.
[0231] It can be understood that the decryption device 800 shown in FIG8 is only an example provided in this embodiment. The decryption device 800 may include more or fewer units according to different encryption and decryption processes, and this application does not limit this.
[0232] When decryption device 800 is implemented via hardware, the hardware can be implemented via a processor or a chip system. The chip system includes one or more chips, each of which includes an interface circuit and a control circuit. The interface circuit is used to receive data from devices outside the chip and transmit it to the control circuit, or to send data from the control circuit to devices outside the chip. The control circuit and interface circuit implement the method of any possible implementation method in the above embodiments through logic circuits or executing code instructions. The beneficial effects can be found in the description of any aspect of the above embodiments and will not be repeated here.
[0233] It is understood that the processor in the embodiments of the present application may be a CPU, or other general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, transistor logic device, hardware component, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0234] In one example, FIG9 shows a schematic block diagram of a device 900 according to an embodiment of the present application. The device 900 may include: a processor 901 and a transceiver / transceiver pin 902 , and optionally, a memory 903 .
[0235] The various components of the device 900 are coupled together via a bus 904, wherein the bus 904 includes, in addition to a data bus, a power bus, a control bus, and a status signal bus. However, for the sake of clarity, all buses are referred to as bus 904 in the figure.
[0236] Optionally, the memory 903 may be used to store instructions in the aforementioned method embodiment. The processor 901 may be used to execute the instructions in the memory 903 and control the receiving pin to receive a signal and control the transmitting pin to send a signal.
[0237] The apparatus 900 may be the electronic device or a chip of the electronic device in the above method embodiment.
[0238] Among them, all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module and will not be repeated here.
[0239] The present application also provides a chip including one or more interface circuits and one or more processors. The one or more processors receive or send data via the one or more interface circuits. When the one or more processors execute computer instructions, the steps of the above-mentioned related methods are implemented. The interface circuit is a transceiver / transceiver pin 902.
[0240] This embodiment also provides a non-transitory computer-readable storage medium, which stores computer instructions. When the computer instructions are executed on an electronic device, the electronic device executes the above-mentioned related method steps to implement the method in the above-mentioned embodiment.
[0241] This embodiment further provides a computer program product, which includes computer instructions. When the computer instructions are executed by a computer or a processor, the computer executes the above-mentioned related steps to implement the method in the above-mentioned embodiment.
[0242] In addition, an embodiment of the present application also provides a device, which can specifically be a chip, component or module, and the device may include a connected processor and memory; wherein the memory is used to store computer-executable instructions, and when the device is running, the processor can execute the computer-executable instructions stored in the memory to enable the chip to execute the methods in the above-mentioned method embodiments.
[0243] Among them, the electronic device, non-transitory computer-readable storage medium, computer program product or chip provided in this embodiment are all used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding methods provided above, and will not be repeated here.
[0244] Through the description of the above implementation methods, technical personnel in the relevant field can understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0245] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0246] Units described as separate components may or may not be physically separate, and components shown as units may be one physical unit or multiple physical units, that is, they may be located in one place or distributed in multiple places. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0247] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0248] Any content of each embodiment of this application, as well as any content of the same embodiment, can be freely combined. Any combination of the above content is within the scope of this application.
[0249] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a device (which can be a single-chip microcomputer, chip, etc.) or a processor (processor) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0250] The steps of the method or algorithm described in conjunction with the disclosure of the embodiments of the present application can be implemented in a hardware manner, or can be implemented by a processor executing a software instruction. The software instruction can be composed of corresponding software modules, and the software module can be stored in a random access memory (Random Access Memory, RAM), a flash memory, a read-only memory (Read Only Memory, ROM), an erasable programmable read-only memory (Erasable Programmable ROM, EPROM), an electrically erasable programmable read-only memory (Electrically EPROM, EEPROM), a register, a hard disk, a mobile hard disk, a read-only compact disc (CD-ROM) or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and can write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an ASIC.
[0251] Those skilled in the art will appreciate that, in one or more of the above examples, the functions described in the embodiments of the present application can be implemented using hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. Computer-readable media include non-transitory computer-readable storage media and communication media, wherein the communication media includes any medium that facilitates the transmission of a computer program from one place to another. The storage medium can be any available medium that a general-purpose or special-purpose computer can access.
[0252] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms without departing from the purpose of this application and the scope of protection of the claims, all of which are within the protection of this application.
Claims
1. An encryption method, characterized in that: The method comprises: Obtain a network abstraction layer NAL unit; the NAL unit includes a NAL unit header and raw byte sequence payload RBSP data; Retrieving the RBSP data; Encrypt the RBSP data according to the encryption method specified in the security parameter set to obtain encrypted RBSP data; splicing the NAL unit header and the encrypted RBSP data to obtain an encrypted NAL unit; the encrypted NAL unit includes a key selection identifier, and the key selection identifier is used to indicate an encrypted video encryption key (Encrypted Video Encryption Key) and an initialization vector used to calculate a stream key; Output a compressed video bit stream; the compressed video bit stream includes the encrypted NAL unit and a security parameter set, and the security parameter set includes multiple encrypted video encryption keys and multiple initialization vectors.
2. The method according to claim 1, characterized in that The security parameter set also includes a key quantity and a key encryption key index, wherein the key quantity is used to indicate the number of encrypted video encryption keys or initialization vectors in the security parameter set, and the key encryption key index is used to indicate a video key encryption key index for encrypting the video encryption key.
3. The method according to claim 1 or 2, characterized in that: The security parameter set is a security parameter set NAL unit.
4. The method according to any one of claims 1 to 3, characterized in that The NAL unit header of the encrypted NAL unit includes the key selection identifier.
5. The method according to claim 4, characterized in that The key selection identifier is a variable, and the variable is used to indicate that the stream key is calculated using the encrypted video encryption key indicated by the corresponding video key encryption key index and the initialization vector.
6. The method according to any one of claims 1 to 5, characterized in that Before encrypting the RBSP data according to the encryption method specified in the security parameter set to obtain the encrypted RBSP data, the method further includes: Determining that the NAL unit needs to be encrypted; A NAL unit encryption flag in a NAL unit header of the NAL unit is set to a first value, wherein the first value indicates that the NAL unit is encrypted.
7. The method according to any one of claims 1 to 6, characterized in that After extracting the RBSP data, the method further includes: When the RBSP data has been processed with an anti-counterfeiting start code, removing the anti-counterfeiting start code; After encrypting the RBSP data according to the encryption method specified in the security parameter set to obtain the encrypted RBSP data, the method further includes: An anti-counterfeiting start code is added to the encrypted RBSP data.
8. A decryption method, characterized in that: The method comprises: Obtain a compressed video bitstream; the compressed video bitstream includes an encrypted network abstraction layer NAL unit and a security parameter set, the encrypted NAL unit includes encrypted raw byte sequence payload RBSP data and a key selection identifier, the key selection identifier is used to indicate an encrypted video encryption key used to calculate a stream key, and the security parameter set includes multiple encrypted video encryption keys and multiple initialization vectors; decrypting the encrypted video encryption key indicated by the key selection identifier among the multiple encrypted video encryption keys included in the security parameter set to obtain a video encryption key; Retrieving the encrypted RBSP data from the encrypted NAL unit; The encrypted RBSP data is decrypted according to the video encryption key to obtain decrypted RBSP data.
9. The method according to claim 8, characterized in that The security parameter set also includes a key quantity and a key encryption key index, wherein the key quantity is used to indicate the number of encrypted video encryption keys or initialization vectors in the security parameter set, and the key encryption key index is used to indicate a video key encryption key index for encrypting the video encryption key.
10. The method according to claim 8 or 9, characterized in that: The security parameter set is a security parameter set NAL unit.
11. The method according to any one of claims 8 to 10, characterized in that: The NAL unit header of the encrypted NAL unit includes the key selection identifier.
12. The method according to claim 11, characterized in that The key selection identifier is a variable, and the variable is used to indicate that the stream key is calculated using the encrypted video encryption key indicated by the corresponding video key encryption key index and the initialization vector.
13. The method according to any one of claims 8 to 12, characterized in that: After decrypting the encrypted RBSP data according to the video encryption key to obtain the decrypted RBSP data, the method further includes: The NAL unit header and the decrypted RBSP data are concatenated to obtain a decrypted NAL unit.
14. The method according to any one of claims 8 to 13, characterized in that: Before decrypting the encrypted video encryption key indicated by the key selection identifier in the multiple encrypted video encryption keys and multiple initialization vectors contained in the security parameter set to obtain the video encryption key, the method further includes: The encrypted NAL unit is determined according to the NAL unit encryption flag of the encrypted NAL unit header.
15. The method according to any one of claims 8 to 14, characterized in that After extracting the encrypted RBSP data from the encrypted NAL unit, the method further includes: When the encrypted RBSP data has been processed with an anti-counterfeiting start code, the anti-counterfeiting start code is removed.
16. The method according to claim 13, characterized in that After the NAL unit header and the decrypted RBSP data are concatenated to obtain the decrypted NAL unit, the method further includes: An anti-counterfeiting start code is added to the decrypted RBSP data of the decrypted NAL unit.
17. A compressed video bit stream, characterized in that The compressed video bitstream comprises: Network Abstraction Layer NAL units and security parameter sets; The NAL unit includes encrypted raw byte sequence payload RBSP data and a key selection identifier; the encrypted RBSP data is obtained by encrypting the RBSP data according to a video encryption key, and the key selection identifier is used to indicate an encrypted video encryption key and an initialization vector used to calculate a stream key; the security parameter set includes multiple encrypted video encryption keys and multiple initialization vectors.
18. The compressed video bit stream according to claim 17, characterized in that The security parameter set also includes a key quantity and a key encryption key index, wherein the key quantity is used to indicate the number of encrypted video encryption keys or initialization vectors in the security parameter set, and the key encryption key index is used to indicate a video key encryption key index for encrypting the video encryption key.
19. The compressed video bit stream according to claim 17 or 18, characterized in that The security parameter set is a security parameter set NAL unit.
20. The compressed video bit stream according to any one of claims 17 to 19, characterized in that The NAL unit header of the encrypted NAL unit includes the key selection identifier.
21. The compressed video bitstream of claim 20, wherein: The key selection identifier is a variable, and the variable is used to indicate that the stream key is calculated using the encrypted video encryption key indicated by the corresponding video key encryption key index and the initialization vector.
22. An encryption device, characterized in that: include: The first acquisition module is used to acquire a network abstraction layer NAL unit; The NAL unit includes a NAL unit header and raw byte sequence payload RBSP data; A first extraction module, used for extracting the RBSP data; An encryption module, used for encrypting the RBSP data according to an encryption method specified in a security parameter set to obtain encrypted RBSP data; A first splicing module, used for splicing the NAL unit header and the encrypted RBSP data to obtain an encrypted NAL unit; The encrypted NAL unit includes a key selection identifier, and the key selection identifier is used to indicate an encrypted video encryption key and an initialization vector used to calculate a stream key; The output module outputs a compressed video bit stream; the compressed video bit stream includes the encrypted NAL unit and a security parameter set, and the security parameter set includes multiple encrypted video encryption keys and multiple initialization vectors.
23. A decryption device, characterized in that: include: A second acquisition module is used to acquire a compressed video bit stream; the compressed video bit stream includes an encrypted network abstraction layer NAL unit and a security parameter set, the encrypted NAL unit includes encrypted raw byte sequence payload RBSP data and a key selection identifier, the key selection identifier is used to indicate an encrypted video encryption key used to calculate a stream key, and the security parameter set includes multiple encrypted video encryption keys and multiple initialization vectors; A decryption module, used for decrypting the encrypted video encryption key indicated by the key selection identifier in the multiple encrypted video encryption keys and multiple initialization vectors contained in the security parameter set to obtain a video encryption key; A second extraction module, used for extracting the encrypted RBSP data from the encrypted NAL unit; The decryption module is further used to decrypt the encrypted RBSP data according to the video encryption key to obtain decrypted RBSP data.
24. An encryption and decryption system, characterized in that: The system includes an encryption end and a decryption end; The encryption end is used to execute the method described in any one of claims 1 to 7; The decryption end is used to execute the method described in any one of claims 8-16.
25. A coding device, comprising at least one processor and a memory, characterized in that: The at least one processor executes a program or instruction stored in the memory so that the encoding device implements the method according to any one of claims 1 to 7.
26. A decoding device, comprising at least one processor and a memory, characterized in that: The at least one processor executes a program or instruction stored in the memory so that the encoding device implements the method according to any one of claims 8 to 16.
27. A non-transitory computer-readable storage medium for storing a computer program, characterized in that: When the computer program is executed on a computer or a processor, the computer or the processor is enabled to implement the method according to any one of claims 1 to 16.
28. A computer program product, comprising instructions, characterized in that: When the instructions are executed on a computer or a processor, the computer or the processor is enabled to implement the method according to any one of claims 1 to 16.
29. A chip comprising at least one processor and a memory, characterized in that: The at least one processor executes a program or instruction stored in the memory so that the chip implements the method of any one of claims 1 to 16.
Citation Information
Patent Citations
Video signal source encryption and decryption system and method based on AVS2 entropy coding of block encryption
CN112533001A
Video encryption method and device, video decryption method and device
CN114938464A
Video encryption and decryption method and device
CN116800446A
Method for lightweight video contents encryption and decryption to provide mobile contents service
KR1020120037213A
Method of encoding and decoding bytestream with NAL structure
KR1020140133690A
Cited By
Video encryption transmission method, video decryption output method and device
CN121865010A