Bitstream, bitstream signing method, and bitstream verification method

By signing and authenticating the bitstream with the layer unit as granularity calculation of summary data, the problem of access unit failure in the prior art is solved, and higher data utilization and transmission efficiency are achieved.

WO2025156618A1PCT designated stage Publication Date: 2025-07-31HUAWEI TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/113453
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-07
Filing Date
2024-08-20
Publication Date
2025-07-31

AI Technical Summary

Technical Problem

In the prior art, the signature or authentication process of the bitstream calculates summary data with the access unit as a granularity, resulting in the entire access unit being invalid when frames, packets or authentication fails during transmission, and the integrity and security of audio and video content cannot be effectively guaranteed.

Method used

The layer unit is used to calculate the summary data as a granularity, and by signing the summary data of each layer unit in a set of layer units of the bitstream, authenticating data is generated, and only the corresponding layer unit is invalid during the transmission process, reducing lost data, and improving data utilization and transmission efficiency.

Benefits of technology

When frame drop, packet drop or layer unit authentication fails during transmission, only the corresponding layer unit fails, reducing data loss, improving data utilization in bitstream, and improving transmission efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024113453_31072025_PF_FP_ABST
    Figure CN2024113453_31072025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed are a bitstream, a bitstream signing method, and a bitstream verification method, relating to the technical field of multimedia. The bitstream signing method comprises: a computing device acquires verification data, and then outputs a bitstream, the bitstream comprising the verification data. The verification data comprises signature data, which is obtained by signing on the basis of digest data of each layer unit in a group of layer units of the bitstream, and one layer unit in the group of layer units comprises network abstraction layer (NAL) units having a same hierarchical identifier in the bitstream. By means of computing the digest data by using layer units as the granularity, only a corresponding layer unit is invalidated when frame loss, packet loss, or layer unit verification failure occurs during transmission. When only the layer unit for which verification failure occurs is invalidated, that is, less data is lost, the utilization rate of data in the bitstream can be increased, and the transmission efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

A bit stream, bit stream signature and authentication method

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on January 24, 2024, with application number 202410104600.6 and application name “A bitstream, bitstream signature and authentication method”, and claims priority to the Chinese patent application filed with the State Intellectual Property Office on February 7, 2024, with application number 202410176090.3 and application name “A bitstream, bitstream signature and authentication method”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of multimedia technology, and in particular to a bit stream, a bit stream signature, and an authentication method. Background Art

[0003] Many audio and video encoding and decoding scenarios (for example, surveillance, live broadcast, on-demand, etc.) have certain requirements for the authenticity and integrity of audio and video content. Therefore, in order to ensure the security of audio and video content during transmission and prevent the audio and video content from being tampered with during transmission, the audio and video content needs to be signed.

[0004] Currently, the process for signing a bitstream involves generating a digest corresponding to each access unit in the bitstream, then signing the digest using a digital signature algorithm, and then writing the signature into the bitstream. However, during the signing or authentication process, the digest data is calculated at the access unit granularity. If frames or packets are lost during transmission, or authentication fails, the entire access unit will be invalidated (unusable).

[0005] Summary of the Invention

[0006] The present application provides a bitstream, bitstream signature and authentication method to solve the problem that during the signing or authentication process, summary data is calculated based on the granularity of the access unit. If frames or packets are lost or authentication fails during transmission, the entire access unit will become invalid.

[0007] This application adopts the following technical solution.

[0008] In a first aspect, an embodiment of the present application provides a bitstream signature method. The bitstream signature method is executed by a computing device or a chip in the computing device, such as a mobile phone or a computer. Exemplarily, the method includes: the computing device obtains authentication data and then outputs a bitstream, wherein the bitstream includes the authentication data. The authentication data includes signature data, which is obtained by signing the summary data of each layer unit in a set of layer units of the bitstream, wherein one layer unit in the set of layer units includes a network abstraction layer (NAL) unit with the same layer identifier.

[0009] In this application, summary data is calculated at the layer unit granularity. This ensures that in the event of frame or packet loss or layer unit authentication failure during transmission, only the corresponding layer unit is invalidated. If only the layer unit that failed authentication is invalidated, less data is lost, which can improve the utilization of data in the bitstream and enhance transmission efficiency.

[0010] In one possible scenario, a layer unit in a set of layer units includes a network abstraction layer unit having the same layer identifier in an access unit in the bitstream.

[0011] In one possible scenario, the authentication data of a group of layer units corresponds to a security parameter set.

[0012] In one possible implementation, the authentication data further includes summary data of each layer unit in a set of layer units.

[0013] In a possible implementation, the digest data corresponding to the multiple layer units in a group of layer units are arranged in sequence in the authentication data according to the bit stream order of the multiple layer units.

[0014] In one possible implementation, a group of layer units includes a first layer unit, and the above-mentioned bitstream signature method further includes: the computing device arranges the network abstraction layer units included in the first layer unit in bitstream order and performs summary calculation to obtain summary data of the first layer unit.

[0015] In one possible implementation, the above-mentioned bitstream signature method also includes: the computing device determines the secondary summary data of a group of layer units based on the summary data of each layer unit in a group of layer units, and then uses the private key to sign the secondary summary data to obtain signature data.

[0016] In one possible scenario, the secondary summary data is obtained by concatenating the n+1th combined summary data with the summary data of the n+2th layer unit along the bit stream order, calculating the summary of the concatenated data, and obtaining the n+2th combined summary data, until the summary data of each layer unit in a group of layer units are concatenated; the n+1th combined summary data is obtained by calculating the summary after concatenating the nth combined summary data with the summary data of the n+1th layer unit, where n is a positive integer.

[0017] In a possible scenario, the secondary summary data is obtained by connecting the second summary data of each layer unit in a group of layer units and calculating the secondary summary of the connected second summary data.

[0018] In a possible implementation, the maximum number of layer units included in a group of layer units is determined according to the hash period and the number of spatial hierarchical layers.

[0019] In a possible implementation, the decoding order of multiple network abstraction layer units with the same layer identifier included in a layer unit is continuous.

[0020] In a possible implementation, the network abstraction layer units included in a layer unit have authentication identifiers with the same value, and the authentication identifiers are greater than 0.

[0021] In a possible implementation, the computing device obtains authentication data, including: the computing device generates authentication data.

[0022] In a possible implementation, before the computing device outputs the bitstream, the bitstream signature method further includes: the computing device adding authentication data to the bitstream.

[0023] In a second aspect, embodiments of the present application provide a bitstream. The bitstream includes a set of layer units and authentication data. The authentication data includes signature data, where the signature data is obtained by signing the digest data of each layer unit in the set of layer units of the bitstream, wherein one layer unit in the set of layer units includes a network abstraction layer unit having the same layer identifier.

[0024] In one possible implementation, the authentication data further includes summary data of each layer unit in a set of layer units.

[0025] In a possible implementation, the digest data corresponding to the multiple layer units in a group of layer units are arranged in sequence in the authentication data according to the bit stream order of the multiple layer units.

[0026] In a possible implementation, the decoding order of multiple network abstraction layer units with the same layer identifier included in a layer unit is continuous.

[0027] In a possible implementation, the network abstraction layer units included in a layer unit have authentication identifiers with the same value, and the authentication identifiers are greater than 0.

[0028] In a possible implementation, the maximum number of layer units included in a group of layer units is determined according to the hash period and the number of spatial hierarchical layers.

[0029] In the third aspect, an embodiment of the present application provides a bitstream authentication method. The bitstream authentication method is executed by a computing device or a chip in a computing device, such as a mobile phone or a computer. Exemplarily, the method includes: the computing device determines the first summary data of each layer unit of a group of layer units in the bitstream, and then obtains the authentication data from the bitstream. If the signature data is successfully verified, the multiple second summary data in the authentication data are verified based on the first summary data of each layer unit of a group of layer units in the bitstream. Among them, a layer unit in a group of layer units includes a network abstraction layer unit with the same hierarchical identifier. The authentication data includes: signature data and the second summary data of each layer unit in a group of layer units, and the signature data is obtained by signing according to the second summary data of each layer unit in a group of layer units.

[0030] In one possible scenario, a layer unit in a set of layer units includes a network abstraction layer unit having the same layer identifier in an access unit in the bitstream.

[0031] In one possible implementation, the first summary list includes first summary data of each layer unit in a group of layer units, and the second summary list includes second summary data of each layer unit in a group of layer units. The method also includes: matching the identifier of the first summary list with the identifier of the second summary list; the identifier includes the authentication data identifier and / or the security parameter set identifier ID; if the identifier of the first summary list is consistent with the identifier of the second summary list, then performing verification of multiple second summary data in the authentication data based on the first summary data of each layer unit in a group of layer units in the bitstream.

[0032] In a possible implementation, the maximum number of layer units included in a group of layer units is determined according to the hash period and the number of spatial hierarchical layers.

[0033] In a possible implementation, the second digest data corresponding to the multiple layer units in a group of layer units are arranged in sequence in the authentication data according to the bit stream order of the multiple layer units.

[0034] In one possible implementation, a computing device verifies the plurality of second digest data in the authentication data based on the first digest data of each layer unit of a group of layer units in the bitstream, including: the computing device sequentially matches the first digest data with the second digest data based on an arrangement order of the plurality of second digest data in the authentication data and the plurality of first digest data of the group of layer units. If a match is successful, the layer unit of the successfully matched first digest data is authenticated successfully; if a match is unsuccessful, the layer unit of the unmatched first digest data is authenticated unsuccessfully.

[0035] In one possible implementation, the above-mentioned bitstream authentication method also includes: the computing device obtains a public key, and then determines the secondary summary data corresponding to a set of layer units based on the second summary data of each layer unit in a set of layer units included in the authentication data, and then verifies the signature data based on the public key, the secondary summary data and the signature algorithm.

[0036] In a possible implementation, the secondary summary data is obtained by concatenating the n+1th combined summary data with the second summary data of the n+2th layer unit in bit stream order, calculating the summary of the concatenated data, and obtaining the n+2th combined summary data, until the second summary data of each layer unit in a group of layer units is concatenated; the n+1th combined summary data is obtained by calculating the summary after concatenating the nth combined summary data with the second summary data of the n+1th layer unit, where n is a positive integer.

[0037] In a possible implementation, the secondary summary data is obtained by connecting the second summary data of each layer unit in a group of layer units and calculating a summary of the connected second summary data.

[0038] In a fourth aspect, an embodiment of the present application provides a bitstream authentication method. The bitstream authentication method is executed by a computing device or a chip in the computing device, such as a mobile phone or a computer. Exemplarily, the method includes: the computing device determines the first summary data of a set of layer units of the bitstream, and then obtains authentication data from the bitstream, thereby verifying the signature data using the first summary data. The authentication data includes signature data, and the signature data is obtained by signing based on the second summary data of each layer unit in a set of layer units, and one layer unit in the set of layer units includes a network abstraction layer unit with the same layer identifier.

[0039] In one possible scenario, a group of layer units corresponding to the third summary list is ordered before a group of layer units corresponding to the first summary list in the bitstream.

[0040] In one possible implementation, the computing device determines the first summary data of a group of layer units of the bitstream, including: the computing device determines the third summary data of each layer unit in the group of layer units of the bitstream, and then determines the first summary data corresponding to the group of layer units based on the third summary data of each layer unit in the group of layer units.

[0041] In one possible implementation, a computing device determines first summary data corresponding to a group of layer units based on the third summary data of each layer unit in the group of layer units, including: the computing device concatenates the n+1th combined summary data with the third summary data of the n+2th layer unit along the bit stream order, calculates the summary of the concatenated data, and obtains the n+2th combined summary data, until the third summary data of each layer unit in the group of layer units is concatenated to obtain the first summary data; the n+1th combined summary data is obtained by calculating the summary after concatenating the nth combined summary data with the third summary data of the n+1th layer unit, where n is a positive integer.

[0042] In one possible implementation, a computing device determines first summary data corresponding to a group of layer units based on the third summary data of each layer unit in the group of layer units, including: the computing device connects the third summary data of each layer unit in the group of layer units to obtain the connected third summary data, and then calculates a summary of the connected third summary data to obtain the first summary data.

[0043] In a possible implementation, the computing device verifies the signature data using the first summary data, including: the computing device obtains a public key, and then verifies the signature data according to the public key, the first summary data, and a signature algorithm.

[0044] In one possible implementation, the above-mentioned bitstream authentication method includes: the computing device matches the identifier of the first summary data with the identifier of the authentication data; the identifier includes the authentication data identifier and / or the security parameter set identifier ID, and if the identifier of the first summary data matches the identifier of the authentication data, then executing the verification of the signature data using the first summary data.

[0045] In a possible implementation, the maximum number of layer units included in a group of layer units is determined according to the hash period and the number of spatial hierarchical layers.

[0046] In a fifth aspect, the present application provides a bitstream signature device, which includes a module for executing the method of the first aspect or any possible implementation of the first aspect.

[0047] In a sixth aspect, the present application provides a bitstream authentication device. The bitstream authentication device includes a module for executing the method of the third aspect or any possible implementation of the third aspect, or the bitstream authentication device includes a module for executing the method of the fourth aspect or any possible implementation of the fourth aspect.

[0048] In a seventh aspect, an embodiment of the present application provides a computing device, comprising: a memory and a processor; the memory storing program instructions, which, when executed by the processor, causes the computing device to execute the bitstream signature method of the first aspect or any possible implementation of the first aspect, or to execute the bitstream authentication method of the third aspect or any possible implementation of the third aspect, or to execute the bitstream authentication method of the fourth aspect or any possible implementation of the fourth aspect.

[0049] In an eighth aspect, embodiments of the present application provide a chip comprising one or more interface circuits and one or more processors; the one or more processors receive or send data via the one or more interface circuits, and when the one or more processors execute computer instructions, the steps of the bitstream signature method in the first aspect or any possible implementation of the first aspect are executed, or the steps of the bitstream authentication method in the third aspect or any possible implementation of the third aspect are executed, or the steps of the bitstream authentication method in the fourth aspect or any possible implementation of the fourth aspect are executed.

[0050] In a ninth aspect, embodiments of the present application provide a non-transitory computer-readable storage medium. The computer-readable storage medium stores a computer program that, when executed on a computer or processor, causes the computer or processor to execute the bitstream signature method of the first aspect or any possible implementation of the first aspect, or the bitstream authentication method of the third aspect or any possible implementation of the third aspect, or the bitstream authentication method of the fourth aspect or any possible implementation of the fourth aspect.

[0051] In a tenth aspect, embodiments of the present application provide a computer program product. The computer program product includes computer instructions that, when executed by a computer or processor, cause the computer or processor to perform the bitstream signature method of the first aspect or any possible implementation of the first aspect, or to perform the bitstream authentication method of the third aspect or any possible implementation of the third aspect, or to perform the bitstream authentication method of the fourth aspect or any possible implementation of the fourth aspect.

[0052] In an eleventh aspect, an embodiment of the present application provides a non-transitory computer-readable storage medium storing a bit stream according to the second aspect or any possible implementation of the second aspect.

[0053] In a twelfth aspect, an embodiment of the present application provides a device for storing a bitstream, comprising: a receiver and at least one storage medium, wherein the receiver is configured to receive the bitstream in the second aspect or any possible implementation of the second aspect.

[0054] In the thirteenth aspect, an embodiment of the present application provides a device for transmitting a bit stream, the device comprising: a transmitter and at least one storage medium, the at least one storage medium being used to store the bit stream in the second aspect or any possible implementation of the second aspect; the transmitter being used to obtain the bit stream from the storage medium and send the bit stream to an end-side device through a transmission medium.

[0055] In a fourteenth aspect, an embodiment of the present application provides a system for distributing bitstreams. The system includes: at least one storage medium for storing at least one bitstream according to the second aspect or any possible implementation of the second aspect; and a streaming media device for acquiring a target bitstream from the at least one storage medium and transmitting the target bitstream to an end-side device, wherein the streaming media device includes a content server or a content distribution server.

[0056] Regarding the beneficial effects of the third to fourteenth aspects, reference may be made to the description of any implementation in the first or second aspects, and no further details will be given here. Based on the implementations provided in the above aspects, this application can also be further combined to provide more implementations. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] FIG1 is a schematic diagram of an application scenario provided by this application;

[0058] FIG2 is a schematic diagram of the structure of the signature and authentication system provided by this application;

[0059] FIG3 is a flowchart of a bitstream signature method provided by the present application;

[0060] FIG4a is a second flow chart of a bitstream signature method provided by the present application;

[0061] Figure 4b is a connection summary diagram provided by this application;

[0062] Figure 4c is a schematic diagram of a treetop summary provided by this application;

[0063] FIG5 is a flowchart of a bit stream authentication method provided by the present application;

[0064] FIG6 is a second flow chart of a bit stream authentication method provided by the present application;

[0065] FIG7 is a schematic diagram of a bitstream signature device provided by the present application;

[0066] FIG8a is a schematic diagram of a bit stream authentication device provided by the present application;

[0067] FIG8b is a second schematic diagram of a bit stream authentication device provided by this application;

[0068] FIG9 is a schematic diagram of the structure of the computing device provided in this application. DETAILED DESCRIPTION

[0069] The present application provides a bitstream signing method, comprising: a computing device obtaining authentication data and then outputting a bitstream, the bitstream including the authentication data. The authentication data includes signature data, the signature data being signed based on summary data of each layer unit in a set of layer units of the bitstream, wherein one layer unit in the set of layer units includes a network abstraction layer unit having the same layer identifier.

[0070] In this application, summary data is calculated at the layer unit granularity. This ensures that in the event of frame or packet loss or layer unit authentication failure during transmission, only the corresponding layer unit is invalidated. If only the layer unit that failed authentication is invalidated, less data is lost, which can improve the utilization of data in the bitstream and enhance transmission efficiency.

[0071] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described below are part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0072] The term "and / or" in this article is merely a description of the association relationship between associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone.

[0073] In the description and claims of the embodiments of this application, the terms "first" and "second" are used to distinguish different objects, rather than to describe a specific order of objects. For example, the terms "first target object" and "second target object" are used to distinguish different objects, rather than to describe a specific order of objects.

[0074] In the embodiments of this application, words such as "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as "exemplarily" or "for example" in the embodiments of this application should not be interpreted as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplarily" or "for example" is intended to present the relevant concepts in a concrete manner.

[0075] In the description of the embodiments of this application, unless otherwise specified, "multiple" means two or more. For example, "multiple processing units" means two or more processing units; "multiple systems" means two or more systems.

[0076] The following is an introduction to related technologies.

[0077] A bitstream is a binary data stream formed by coded image / audio frames. Both NAL unit streams and byte streams can be called bitstreams.

[0078] A NAL unit is a syntactic structure that includes an indication of the type of subsequent data and the number of bytes contained (located in the NAL header). The data appears in the form of a raw byte sequence payload (RBSP), and may include interspersed security bytes if necessary. For example, a NAL unit may include a security parameter set NAL unit (also called a security data set) or an authentication data NAL unit (also called authentication data).

[0079] A layer unit (LU) is a set of NAL units with the same layer identifier (layer_id) value that are associated with each other according to a specified rule and are continuous in decoding order.

[0080] An access unit (AU) is a group of NAL units that are linked to each other according to a specified rule and are sequentially transmitted in decoding order to form a compressed video bitstream (also called a bitstream). A bitstream represents the binary data stream formed by coded image / audio frames.

[0081] A data unit is the basic syntax structure of a coded bitstream. It can be a NAL unit, a layer unit, or an access unit. This data unit is also called a basic unit or a basic data unit.

[0082] It should be noted that, from another dimension, the layer unit may also include a coded image.

[0083] Coded picture: a coded representation of a frame of image.

[0084] A coded video sequence is the highest-level syntax structure of a bitstream and contains one or more consecutive access units. A coded video sequence starts with an access unit of an IDR picture (instantaneous decoding refresh picture), an access unit of a RAPI picture (random access point I picture), an access unit of an RL leading library picture (leading library picture of an RL picture), or an access unit of a display knowledge picture. The end-of-stream NAL unit or the end-of-coded video sequence NAL unit indicates the end of a coded video sequence. Each coded video sequence contains at most one IDR picture, RAPI picture, RL leading library picture, or display knowledge picture. Access units are arranged in the bitstream in bitstream order, and the bitstream order should be the same as the decoding order. The decoding order may be different from the display order.

[0085] The RBSP of the security parameter set (SEC) includes some parameters that can be used by one or more other types of NAL units. The aforementioned parameters are the configuration parameters required for signing and authenticating the compressed video bitstream. The knowledge image is encrypted or authenticated independently of the display image. The knowledge image identifier (sec_is_library_flag) in the security parameter data RBSP is used to distinguish whether it is a security parameter set for the knowledge image. The codestream (bitstream) can contain multiple security parameter sets, which are distinguished by the security parameter set ID (sec_para_set_id). Up to three security parameter sets are supported simultaneously. A security parameter set NAL unit should be present before the random access point access unit or the first knowledge image access unit of a random access segment (RAS). This unit is applied to the current RAS or knowledge image. The security parameter set provides parameters for encryption and authentication of the current RAS or knowledge image access unit. In the case of multiple security parameter sets, sec_para_set_id is used to distinguish them. If there is no security parameter set NAL unit in the random access point access unit of the RAS, the current RAS (excluding non-display knowledge image access units) is considered to be unencrypted and does not participate in authentication. If there is no security parameter set NAL unit in the first knowledge image access unit, the current knowledge image is considered to be unencrypted and does not participate in authentication. The security parameter set NAL unit should be located in the same access unit as the sequence parameter set NAL unit, and the security parameter set NAL unit should be located before the sequence parameter set NAL unit. If the access unit includes an access unit boundary NAL unit, the security parameter set NAL unit should be located after the access unit boundary NAL unit.

[0086] A library picture is a reference picture of a non-current bitstream used when decoding the current bitstream. Each frame corresponds to a sequence parameter set, and the knowledge bitstream flag in the corresponding sequence set parameter is 1. The NAL unit type of the coding slice of the knowledge picture is 12, 17, or 18, and the knowledge picture is associated with a privacy coding slice.

[0087] Output library picture: Each frame corresponds to a sequence parameter set, and the corresponding sequence set parameter has a knowledge bitstream flag of 1 and a knowledge picture mode index of 1. The coded slice NAL unit type of the display knowledge picture is 17. The display knowledge picture is a random access point picture. The display knowledge picture that serves as the RL pre-knowledge picture is not a random access point picture.

[0088] Non-output library picture: Each frame corresponds to a sequence parameter set, and the knowledge bitstream flag in the corresponding sequence set parameter is 1 and the knowledge picture mode index is 0 or 2. The coded slice NAL unit type of non-output library picture is 12 or 18.

[0089] Leading library picture of an RL picture, a non-displayed library picture that precedes an associated RL picture in the codestream order, or a displayed library picture that appears before an RL picture after bitstream editing, with no access units of other pictures between the access unit containing the first library picture coding slice of the knowledge picture and the access unit of the associated RL picture. The leading RL knowledge picture is not a random access point picture.

[0090] It is worth noting that if the RL pre-knowledge image is a display knowledge image, the display knowledge image does not need to be output and can be identified by the display knowledge image display information SEI payload (library_display_flag should be '0').

[0091] A non-leading library picture of an RL picture is a non-display library picture that precedes an associated RL picture in the codestream order. There is at least one access unit of another picture between the access unit containing the first library picture coding slice of the non-display library picture and the access unit of the associated RL picture. A non-leading library picture of an RL picture is not a random access point picture.

[0092] Output picture: The decoder reconstructs the output image (RL picture, IDR picture, P picture, B picture or RAPI picture) after decoding. It is worth noting that neither display knowledge pictures nor non-display knowledge pictures fall under the definition of display pictures in this case.

[0093] A picture is a frame of a coded video sequence, whose coded data is contained in one or more access units. Its coded picture consists of a picture header NAL unit, supplemental enhancement information (if present), and all coded slice NAL units of the picture. Specifically, the coded picture of an IDR picture includes a picture header NAL unit, zero or more supplemental extended description NAL units of the IDR picture, and all coded slice NAL units of the IDR picture. The coded picture of a RAPI picture includes a picture header NAL unit, zero or more supplemental extended description NAL units of the RAPI picture, and all coded slice NAL units of the RAPI picture. The coded picture of a P picture and a B picture includes a picture header NAL unit, zero or more supplemental extended description NAL units of the P picture or B picture, and all coded slice NAL units of the NRAP picture (non random access point picture) of the P picture or B picture. The coded picture of an RL picture includes a picture header NAL unit, zero or more supplemental extended description NAL units of the RL picture, and all coded slice NAL units of the RL picture. The coded image of the knowledge image consists of an image header NAL unit and one or more knowledge image coding slice NAL units and one or more privacy image coding slice NAL units. The RL pre-knowledge image and privacy image coding slice NAL units and all coding slice NAL units in the coded image of the display knowledge image are continuous, and its access unit contains all NAL units of the coded image. The coding slices of non-RL pre-knowledge images can be interleaved with the access units of the display image as access units.

[0094] The first coded slice NAL unit of a picture shall be followed by the picture header NAL unit of the picture. For coded pictures that are IDR pictures, RAPI pictures, RL pictures or knowledge pictures, the picture header NAL shall be followed by a picture parameter set NAL unit, and the picture parameter set NAL shall be followed by a sequence parameter set NAL unit.

[0095] In particular, the bitstreams of one or more display images may be interleaved between multiple knowledge image bitstream slices of non-RL pre-knowledge images, but the interleaved display image bitstreams shall not be access units of RL images, IDR images, or RAPI images. All knowledge image bitstream slices of an RL pre-knowledge image or display knowledge image shall be continuous. Each knowledge image bitstream slice may be interleaved with the NAL unit of the privacy image coding slice (if present), but shall not be interleaved with the bitstream of the display image.

[0096] The bitstreams of all slices of a knowledge image should precede the bitstream of the first RL image that references that knowledge image. Knowledge image bitstream slices from different knowledge images cannot be interleaved. The knowledge image referenced by an RL image is the knowledge image represented by the first access unit of the knowledge image found in reverse order from the RL access unit in the bitstream.

[0097] It should be noted that this application does not group layer units or access units, but for the convenience of description, uses "a group of access units" and "a group of layer units" to describe them.

[0098] Illustratively, a group of layer units may include n layer units, each of which is a layer unit requiring authentication, where n is a positive integer. Accordingly, the authentication data may include n digest data, each of which corresponds one-to-one to each of the n layer units. Illustratively, "a group of layer units" may also be described as "n layer units."

[0099] Exemplarily, a plurality of summary data of a group of layer units may constitute a summary data list; that is, the authentication data may include the summary data list.

[0100] Exemplarily, the authentication data may be Auth.

[0101] Exemplarily, the signature data may be signature.

[0102] Exemplarily, the summary data may also be referred to as authentication summary data or summary.

[0103] For example, the bitstream may be an audio compression bitstream (or audio compression codestream) or a video compression bitstream (or video compression codestream), and this application does not limit this. This application uses the signing and authentication of a video compression bitstream as an example for explanation.

[0104] As shown in Figure 1, Figure 1 is a schematic diagram of the application scenarios provided by this application. Figure 1 shows a monitoring scenario, a live broadcast scenario, and a video-on-demand scenario.

[0105] Referring to Figure 1 , in an exemplary surveillance scenario, camera 11 can sign a surveillance video bitstream, obtaining a signed surveillance video bitstream 101. Signed surveillance video bitstream 101 is then sent to laptop computer 13 via network 12. Laptop computer 13 can then authenticate signed surveillance video bitstream 101, obtain and display an authentication result 105, and play surveillance video 104.

[0106] 1 , illustratively, in a live broadcast scenario, mobile phone 14 can sign a live video bitstream to obtain a signed live video bitstream 102. Then, the signed live video bitstream 102 is sent to mobile phone 15 via network 12. Mobile phone 15 can then authenticate the signed live video bitstream 102, obtain and display an authentication result 107, and play the live video 106.

[0107] 1 , illustratively, in a video-on-demand scenario, a personal computer 16 can sign a video-on-demand bitstream to obtain a signed video-on-demand bitstream 103. The signed video-on-demand bitstream 103 is then sent to a mobile phone 17 via a network 12. The mobile phone 17 can then authenticate the signed video-on-demand bitstream 103, obtain and display an authentication result 109, and play the video-on-demand 108.

[0108] It should be understood that the present application can also be used in other audio and video encoding and decoding scenarios, such as digital content trusted scenarios, etc., and the present application does not limit this.

[0109] As shown in Figure 2, Figure 2 is a schematic diagram of the structure of the signature and authentication system provided by this application. Figure 2 illustrates the authentication and signature process in Figure 1 above.

[0110] 2 , illustratively, the authentication and signature system 200 may include a signing end 210 and an authentication end 220 .

[0111] For example, the signing end 210 may be the camera 11, mobile phone 14 and personal computer 16 in FIG1 , and the authentication end 220 may be the laptop computer 13, mobile phone 15 and mobile phone 17 in FIG1 .

[0112] It should be understood that the same terminal device can serve as both the signing end 210 and the authentication end 220, and this application does not impose any restrictions on this.

[0113] 2 , illustratively, after acquiring the video data 201 , the signing end 210 may perform video encoding 21 on the video data 201 to obtain a bitstream 202 ; and perform video signing 22 on the bitstream 202 to obtain a signed bitstream 203 .

[0114] For example, the video data 201 may be a surveillance video captured by the camera 11 in FIG. 1 , a live video recorded by the mobile phone 14 , or an on-demand video produced by the personal computer 16 .

[0115] For example, the signed bitstream 203 may be the signed surveillance video bitstream 101 , the signed live video bitstream 102 , or the signed on-demand video bitstream 103 in FIG. 1 .

[0116] It should be noted that the video encoding 21 and video signing 22 operations can be performed in parallel.

[0117] In one possible implementation, the signing end 210 may include an encoder, which performs video encoding 21 and video signing 22. In another possible implementation, the signing end 210 may include an encoder and a signature module, which performs video encoding 21 and video signing 22. In another possible implementation, the signing end 210 may include a signature module, which performs video encoding 21 and video signing 22.

[0118] Afterwards, the signing end 210 may send the signed bit stream 203 to the authenticating end 220 .

[0119] Continuing to refer to Figure 2, illustratively, after the authentication end 220 receives the signed bitstream 203, it can perform video authentication 23 on the signed bitstream 203 to obtain an authentication result 205; and it can perform video decoding 24 on the bitstream 202 in the signed bitstream 203 to obtain decoded video data 204.

[0120] For example, the decoded video data 204 may be the surveillance video 104, the live video 106, or the on-demand video 108 in FIG. 1 .

[0121] For example, the authentication result 205 may be the authentication result 105, the authentication result 107, or the authentication result 109 in FIG. 1 .

[0122] It should be noted that the video authentication 23 and the video decoding 24 can be performed in parallel.

[0123] In a possible implementation, the authentication end 220 may include a decoder, and the decoder performs video decoding 24 and video authentication 23 .

[0124] In a possible implementation, the authentication end 220 may include a decoder and an authentication module, wherein the decoder performs video decoding 24 and the authentication module performs video authentication 23 .

[0125] In a possible implementation, the authentication end 220 may include an authentication module, which performs video decoding 24 and video authentication 23 .

[0126] It should be noted that when the signing end 210 performs lossless encoding, the video data and the decoded video data are the same; when the signing end 210 performs lossy encoding, there are differences between the video data and the decoded video data.

[0127] It should be noted that the encoder, decoder and authentication module can be implemented by software or hardware, and this application does not impose any restrictions on this.

[0128] The following describes in detail the implementation of the embodiments of the present application with reference to the accompanying drawings.

[0129] FIG3 is a flowchart of a bitstream signature method provided by the present application. The bitstream signature method can be applied to the signature and authentication system shown in FIG2 . For example, the bitstream signature method can be implemented by a processing device 300. In one possible example, the processing device 300 can be the signing terminal 210 shown in FIG2 . The bitstream signature method can include the following steps S310-S320.

[0130] S310: The processing device 300 obtains authentication data.

[0131] The authentication data includes signature data, which is obtained by signing according to summary data of each LU in a group of LUs of the bit stream, and one LU in the group of LUs includes a NAL unit with the same layer identifier.

[0132] In one possible scenario, the processing device 300 generates authentication data.

[0133] Layer identifier (layer_id), a 2-bit unsigned integer, specifies the layer identifier of the current picture. The layer identifier value ranges from 0 to MAX_LAYER-1. The layer_id of the picture header NAL unit and all coded slice NAL units of a coded picture should be the same. The value of layerId is equal to the value of layer_id. The LayerId of a coded picture or layer unit is the LayerId of the coded slice NAL unit within that coded picture or layer unit.

[0134] When the nal_unit_type of a NAL unit is 5, 7, 8, 9, 10, or 15, LayerId shall be 0.

[0135] When the nal_unit_type of a NAL unit is 6 and the NAL unit includes a supplementary enhancement payload with a PayloadType of 19, 25, 26, or 127, LayerId shall be 0.

[0136] It is worth noting that MAX_LAYER is specified by the profile.

[0137] The NAL unit type flag nal_unit_type is a 5-bit unsigned integer that indicates the type of the RBSP data structure in the NAL unit. For details of nal_unit_type, please refer to the nal_unit_type representation shown in Figure 4a below and will not be repeated here.

[0138] In one possible scenario, one LU in a group of LUs includes a NAL unit with the same layer identifier in one AU of the bitstream.

[0139] For example, when authentication needs to be supported, the number n of layer units that need to be authenticated may be determined, where n is a positive integer.

[0140] 3 , illustratively, the n layer units in bitstream a that require authentication are layer unit 1, layer unit 2, ..., layer unit n. These n layer units that require authentication can be referred to as a group of layer units. All subsequent references to a group of layer units refer to layer units that require authentication.

[0141] For example, referring to FIG3 , processing device 300 may use a digest algorithm to independently calculate a digest for each layer unit in a group of layer units, thereby obtaining the digest data for each layer unit in the group. The n digest data may include: digest data 1, digest data 2, ..., digest data n; wherein the n digest data correspond one-to-one to the n layer units; for example, digest data 1 corresponds to layer unit 1, digest data 2 corresponds to layer unit 2, ..., and digest data n corresponds to layer unit n.

[0142] Exemplarily, the processing device 300 may perform digest calculation on the NAL units included in a layer unit after arranging them in a bitstream order to obtain the summary data of the layer unit.

[0143] For example, the processing device 300 splices together the NAL units included in a group of layer units, calculates the summary of the spliced ​​NAL units, and obtains summary data of the layer unit.

[0144] Exemplarily, the processing device 300 may sign according to the digest of each layer unit in a group of layer units to obtain signature data (signature).

[0145] For example, the processing device 300 may generate authentication data (Auth) based on the signature data and the summary data of each layer unit in a set of layer units. In this way, the authentication data may be {summary data 1, summary data 2, ..., summary data n, signature}.

[0146] Optionally, the summary data of each layer unit in a group of layer units in the authentication data may constitute a summary list (authentication_hash) {summary data 1, summary data 2, ..., summary data n}.

[0147] In a possible example, the processing device 300 arranges the network abstraction layer units included in the first layer unit in the order of the bit stream a, and calculates a digest using a digest algorithm to obtain summary data of the first layer unit.

[0148] In a possible implementation, the processing device 300 determines secondary summary data corresponding to a group of layer units based on the summary data of each layer unit in the group of layer units, and then signs the secondary summary data using a private key to obtain signature data.

[0149] In a possible example, the secondary summary data may also be referred to as secondary summary data or a secondary summary value.

[0150] Regarding the signature data described above, two possible examples of obtaining the signature data are shown below.

[0151] In Example 1, the processing device 300 concatenates the summary data of each layer unit in a group of layer units, determines the summary data of the concatenated summary data, and then signs the summary data of the concatenated summary data using a private key to obtain signature data. The summary data of the concatenated summary data is the secondary summary data.

[0152] Exemplarily, processing device 300 concatenates the digest values ​​Hpic1, Hpic2, ..., Hpicn of each layer unit in a group of layer units in bitstream order, calculates a digest of the concatenated digests (digest data), and obtains secondary digest data, i.e., performs a secondary digest using a concatenation method. For example, a secondary digest is performed using a concatenation method on the digest values ​​Hpic1, Hpic2, ..., Hpicn of each layer unit in bitstream order, with reference to FIG. 4b below. The secondary digest data of the group of layer units is then signed to obtain signature data.

[0153] For example, if the aforementioned set of layer units includes 50 layer units, and the summary data for each layer unit is 32 bytes, the processing device 300 must first calculate the summary 50 times to obtain the summary data for each layer unit in the set. The summary data for the 50 layer units is then concatenated to obtain concatenated summary data (32*50 bytes). A further digest is then calculated for the concatenated summary data to obtain the secondary summary data for the set of layer units. The entire process takes T1, which was measured to be 90.7901 ms.

[0154] In this application, the digest calculation process needs to be implemented using a key module. Since each call to the key module requires configuration, this operation takes a long time. Therefore, the above-mentioned digest Hg only needs to be calculated n+1 times, which reduces the number of digest calculations, thereby reducing the time and computing performance required for digest calculation, and improving the efficiency of digest calculation.

[0155] In Example 2, the processing device 300 concatenates the n+1th combined digest data with the digest data of the n+2th layer unit along the bitstream sequence, calculates a digest of the concatenated data, and obtains the n+2th combined digest data. This continues until the digest data of each layer unit in a group of layer units is concatenated to obtain secondary digest data. The n+1th combined digest data is calculated by concatenating the nth combined digest data with the digest data of the n+1th layer unit, or the n+1th combined digest data is calculated by concatenating the digest data of the nth data unit with the digest data of the n+1th data unit, where n is a positive integer. The processing device 300 then signs the secondary digest data to obtain signature data.

[0156] The processing device 300 concatenates the digest values ​​Hpic1, Hpic2, ..., Hpicn of each layer unit in a group of layer units in bitstream order, calculates the digest of the concatenation of Hpic1 and Hpic2, and obtains combined digest data Hpic1,2. The processing device 300 then concatenates Hpic1,2 and Hpic3, calculates the digest of the concatenation of Hpic1,2 and Hpic3, and obtains combined digest data Hpic1,3. This process repeats until Hpic1,n-1 is concatenated with Hpicn, and the digest of the concatenation of Hpic1,n-1 and Hpicn is calculated to obtain Hpic1,n. This is done until the digest values ​​of each layer unit in the group of layer units are concatenated, thereby obtaining a treetop digest. For example, the layer unit digest values ​​Hpic1, Hpic2, ..., Hpicn are subjected to a treetop digest in bitstream order, referring to FIG. 4c below, to obtain a treetop digest. This treetop digest is the secondary summary data.

[0157] For example, if a group of layer units includes 3 layer units, and the summary data of the 3 layer units are H1, H2, and H3 in sequence along the bit stream, the tree-top summary of the group of layer units is calculated using a tree-top method, that is, the processing device 300 connects H1 and H2, calculates the summary of the connected H1 and H2, and obtains the combined summary data H1,2, and then connects the combined summary data H1,2 with H3, calculates the summary of the connected H1,2 and H3, and obtains the combined summary data H1,3. The combined summary data H1,3 is also the secondary summary data of the group of layer units.

[0158] For example, if the group of layer units described above includes 50 layer units, and the data size of the summary data for each layer unit is 32 bytes, the processing device 300 must first calculate the summary 50 times to obtain the summary data for each layer unit in the group. Then, using the top-of-tree calculation method, it calculates the summary n-1 (i.e., 49) times (each calculation uses 32*2 bytes of data) to obtain the top-of-tree summary, which is the secondary summary data for the group of layer units. The entire process takes T2, which was measured to be 120.8181 ms.

[0159] In the present application, the processing device 300 needs to calculate the digest 2n-1 times to obtain the digest H1 / n. The number of digest calculations is relatively small, which reduces the number of digest calculations, thereby reducing the time required for digest calculation and improving the efficiency of digest calculation.

[0160] For example, the processing device 300 signs the secondary summary data using the private key to obtain signature data.

[0161] It is worth noting that the maximum number of data units included in a group of data units can be determined based on hash_period_in_doi_minus1 in the security parameter set and / or the number of spatial layers (NumOfLayers) in the sequence parameter set. For example, n+2 in the above example and the maximum value of n shown in Figure 4c are determined based on hash_period_in_doi_minus1 and / or NumOfLayers. For example, the maximum number of access units included in a group of access units is equal to hash_period_in_doi_minus1+1. The maximum number of layer units included in a group of layer units is equal to the sum of the number of layer units in hash_period_in_doi_minus1+1 access units, such as (hash_period_in_doi_minus1+1) multiplied by (the number of layer units in one access unit indicated by NumOfLayers). The maximum number of NAL units included in a group of NAL units is equal to the sum of the number of NAL units in hash_period_in_doi_minus1+1 access units.

[0162] The above-mentioned bitstream includes a sequence parameter set.

[0163] In a possible scenario, the digest data corresponding to the multiple layer units in a group of layer units are arranged in sequence in the authentication data according to the bit stream order of the multiple layer units.

[0164] For example, a coded slice of multiple frames in a video corresponds to a set of layer units, where the multiple frames include a non-RL pre-knowledge image. In the bitstream, the non-RL pre-knowledge image may be divided into two patches, i.e., two access units. In the bitstream, the multiple layer units included in each of the two access units are arranged sequentially in bitstream order, and the two access units are also arranged sequentially in bitstream order in the bitstream.

[0165] For example, patch 0 includes LU00, LU10, and LU20, and patch 1 includes LU01, LU11, and LU21. In the bitstream, the aforementioned layer units are arranged in the order of the bitstream, that is, in the order of LU00, LU10, LU20, LU01, LU11, and LU21.

[0166] Correspondingly, the arrangement order of the summary data corresponding to the above-mentioned layer units in the authentication data is consistent with the arrangement order of the layer units in the bit stream.

[0167] If a non-RL preamble indicates that the picture is divided into two patches, that is, two access units, each of the two access units includes multiple layer units.

[0168] S320: The processing device 300 outputs a bit stream.

[0169] This bit stream includes the authentication data described above.

[0170] Illustratively, after obtaining the authentication data, the processing device 300 adds the authentication data to the bit stream a to obtain the signed bit stream b, and then outputs the bit stream b, which is the signed bit stream 203 in FIG. 2 .

[0171] It should be noted that the above S310~S320 can be executed by the encoder in the signature end 210, or by the signature module in the signature end 210, or by the encoder and authentication module in the signature end 210 in collaboration (the encoder executes S320, and the authentication module executes S310). This application does not impose any restrictions on this.

[0172] As shown in Figure 4a, Figure 4a is a second flow chart of a bitstream signature method provided by this application. The method shown in Figure 4a can be implemented by a processing device 300, which can be implemented by the signature terminal 210 in Figure 2. The bitstream signature method can include the following steps S410-S440.

[0173] S410: The processing device 300 generates a security parameter set NAL unit and inserts it into a bit stream (compressed video bit stream).

[0174] Exemplarily, when it is necessary to support video image authentication, a security parameter set is generated.

[0175] In one possible implementation, to generate an RBSP in a security parameter set NAL unit (also referred to as a security parameter set RBSP), the scope of the security parameter set is a single RAS in the bitstream, also referred to as a random access segment, and all layer units (access units) involved in authentication cannot cross RAS.

[0176] Exemplarily, the security parameter set ID (sec_para_set_id), knowledge image identifier (sec_is_library_flag), authentication enable flag (authentication_enable_flag), authentication summary calculation mode (authentication_hash_mode), hash type (hash_type), non-random access point image hash authentication flag (hash_discard_nrap_pictures_flag), hash period (hash_period_in_doi_minus1), authentication flag (authentication_idc), and authentication data identifier (authentication_data_id) in the configuration security parameter set.

[0177] sec_para_set_id is the security parameter set ID, a 2-bit unsigned integer used to distinguish different security parameter sets acting on the same RAS or knowledge image access unit, and its value range is 1 to 3.

[0178] sec_is_library_flag is a binary variable. A value of '1' indicates that this security parameter set applies to knowledge images, and a value of '0' indicates that this security parameter set applies to display images.

[0179] authentication_enable_flag is a binary variable. A binary variable. A value of '1' indicates that authentication of the current RAS or knowledge image is supported. The NAL units that can participate in the authentication include the coded slices of the display image or knowledge image in the current RAS, as well as the sequence parameter set, picture parameter set, security parameter set, extended data unit, and supplementary enhancement information transmitted in the access unit. Authentication data is transmitted through a NAL unit with nal_unit_type equal to 10. A value of '0' indicates that the current security parameter set does not support authentication of the RAS or knowledge image, and there should be no NAL unit with nal_unit_type equal to 10 for the RAS or knowledge image generated using the security parameter set.

[0180] Knowledge images only support independent signature authentication, while display images support co-signature authentication. Multiple display image access units participating in co-signature authentication must reside in the same RAS. The image type in multiple access units participating in co-signature authentication can be display images. Independent signature authentication for knowledge images uses a security parameter set independent of the display image, distinguished by the sec_is_library_flag in the security parameter set.

[0181] If an access unit contains NAL units with authentication_idc greater than 0 and nal_unit_type equal to 1-3, 5-9, 12, 14, 17, 18, or 19, the digest of the NAL units with the same authentication_idc value greater than 0 and the same layer_id value for each layer unit in the access unit is calculated in bitstream order. The digest data for NumOfLayers layer units corresponding to the authentication_idc value of the access unit is generated. The digest calculation method is specified by hash_type.

[0182] For hash_period_in_doi_minus1+1 access units, calculate the digest of each layer unit in each access unit in the order of the bit stream. The authentication data scope should not cross RAS. Then calculate the secondary digest in sequence according to the method indicated by authentication_hash_mode.

[0183] The secondary digest value is digitally signed to generate the authentication data RBSP, which is packaged into the authentication data RBSP NAL unit.

[0184] Note: If the authentication_enable_flag and encryption_enable_flag values ​​of multiple security parameter sets in the codestream are equal to 1, that is, the current RAS or knowledge image supports both encryption and authentication, it should be encrypted first and then authenticated, that is, the data used for authentication should be the encrypted NAL unit.

[0185] authentication_hash_mode is a binary variable. It identifies the method for calculating the secondary digest. A value of '0' indicates that the secondary digest is calculated using a connection method, that is, the unit summary values ​​Hpic1, Hpic2, ..., Hpicn of each layer are connected together in the order of the bit stream, and the secondary digest of the connected digest (digest data) is calculated to obtain the secondary summary data, that is, the secondary digest is made using a connection method. For example, the unit summary values ​​Hpic1, Hpic2, ..., Hpicn of each layer are used to make a secondary digest using a connection method according to the bit stream order, with reference to FIG4b. FIG4b is a schematic diagram of the connection digest provided by this application. The above-mentioned calculation of the secondary digest can also be referred to as the calculation of the secondary digest.

[0186] A value of '1' indicates that a secondary digest is calculated using a tree-top approach. For the layer unit digest values ​​Hpic1, Hpic2, ..., Hpicn, Hpic1 and Hpic2 are concatenated in bitstream order, and the digest of the concatenated Hpic1 and Hpic2 is calculated to obtain Hpic1,2. Hpic1,2 and Hpic3 are then concatenated, and the digest of the concatenated Hpic1,2 and Hpic3 is calculated to obtain Hpic1,3. This process is repeated until Hpic1,n-1 and Hpicn are concatenated, and the digest of the concatenated Hpic1,n-1 and Hpicn is calculated to obtain Hpic1,n. This results in a tree-top approach for secondary digest calculation. For example, for the layer unit digest values ​​Hpic1, Hpic2, ..., Hpicn, a tree-top approach is used to calculate secondary digest calculations in bitstream order, as shown in FIG4c . FIG4c is a schematic diagram of a tree-top digest provided by this application.

[0187] For example, the processing device 300 connects the combined summary data with the summary data of the (n+2)th layer unit in the bit stream sequence, calculates the secondary summary of the connected summary data, and continues until the summary data of each layer unit in a group of layer units participates in the connection to obtain secondary summary data. The combined summary data is obtained by calculating the summary after connecting the summary data of the nth layer unit with the summary data of the (n+1)th layer unit, where n is a positive integer.

[0188] hash_discard_nrap_pictures_flag is a binary variable. A value of '1' indicates that non-RANDOM ACCESS POINT pictures are not authenticated; a value of 0 indicates that non-RANDOM ACCESS POINT pictures are authenticated. If hash_discard_nrap_pictures is not in the codestream, its default value is 1.

[0189] hash_period_in_doi_minus, an 8-bit unsigned integer with a value range of 0 to (MAX_HASH_PERIOD / NumOfLayers-1). MAX_HASH_PERIOD is set to 256. HashPeriodInDoi is equal to hash_period_in_doi_minus1+1. Indicates the number of access units involved in signature authentication associated with one authentication data. This number is less than or equal to HashPeriodInDoi.

[0190] The processing device 300 sets hash_period_in_doi_minus1 to HashPeriodInDoi minus 1 based on the user-configured HashPeriodInDoi. A HashPeriodInDoi of 1 indicates that a single access unit is independently signed, and the authentication data NAL unit carrying the signature should be located in the access unit associated with the signature or the first access unit after it. A HashPeriodInDoi greater than 1 indicates that multiple access units are jointly signed.

[0191] NumOfLayers is the number of spatial domain layers.

[0192] authentication_idc, a 2-bit unsigned integer with a value range of 0 to 3. If the nal_unit_type of the NAL unit is 10, the authentication_idc value shall be equal to the security parameter set ID sec_para_set_id corresponding to the authentication data contained in the NAL unit, indicating that the authentication data NAL unit carries authentication data generated based on the security parameter set corresponding to the security parameter set ID sec_para_set_id; otherwise (the nal_unit_type of the NAL unit is not 10), it indicates whether the NAL unit is authenticated. In this case, a value of '0' indicates that the NAL unit is not authenticated, and a value other than '0' indicates that the NAL unit is authenticated using the authentication method specified by the security parameter set with sec_para_set_id equal to authentication_idc.

[0193] When the nal_unit_type of a NAL unit is 10, the NAL unit does not participate in signature authentication.

[0194] When the nal_unit_type of a NAL unit is 11, 15, or 16, authentication_idc shall be 0.

[0195] When a NAL unit has nal_unit_type 6 and contains a payload with PayloadType equal to 25 or 26, authentication_idc shall be 0.

[0196] authentication_data_id, a 2-bit unsigned integer. The value range is 0 to 1. It is the identifier of the authentication data of the signature authentication that this NAL unit participates in. It should be consistent with the authentication_data_id in the authentication data RBSP that it participates in the signature authentication. The authentication_data_id of the NAL units participating in the authentication corresponding to the same authentication data should be the same and consistent with the authentication_data_id in the authentication data. The authentication_data_id of a group of display image coding slice NAL units participating in the joint signature authentication should be different from the authentication_data_id of the previous group of display image coding slice NAL units participating in the joint signature authentication with the same authentication_idc.

[0197] When the nal_unit_type of a NAL unit is 10, this authentication_data_id should be consistent with the authentication_data_id in the authentication data RBSP of the NAL unit.

[0198] In one possible example, NAL units with nal_unit_type equal to 11 can be discarded by the decoder without affecting the decoding process of NAL units with nal_unit_type not equal to 11 and without affecting the consistency of this case (standard). When the nal_unit_type value of a coded slice NAL unit is equal to 1, 2, 4, 12 or 17, the nal_unit_type value of all other coded slice NAL units encoding the same image should be the same. If UserPermission is equal to 0, NAL units with nal_unit_type value equal to 19 can be discarded by the decoder. When the nal_unit_type value of a coded slice NAL unit is equal to 19, the RBSP data contains data of several coding units in the coded slice of the image.

[0199] When the number of coded slices of a knowledge picture is equal to 1, the nal_unit_type of the knowledge picture coded slice NAL unit should be 12 or 17. When the number of coded slices of a non-display knowledge picture is greater than 1, the nal_unit_type of the first and last knowledge picture coded slice NAL units in decoding order should be 18, and the nal_unit_type of the remaining knowledge picture coded slice NAL units should be 12.

[0200] The above nal_unit_type is 0 and is used to indicate the coded slice of an IDR picture, which is a random access point picture. The nal_unit_type is 1 and is used to indicate the coded slice of an NRAP picture, which is a P picture or a B picture. The nal_unit_type is 2 and is used to indicate the coded slice of a RAPI picture, which is a random access point picture. The nal_unit_type is 3 and is used to indicate the picture header. The picture header is a syntax structure that contains syntax elements that act on a picture. Each coded picture contains and only contains one picture header NAL unit. The nal_unit_type is 5 and is used to indicate an extended data unit. The nal_unit_type is 6 and is used to indicate supplemental enhancement information. The nal_unit_type is 7 and is used to indicate a sequence parameter set. The nal_unit_type is 8 and is used for just a picture parameter set. The nal_unit_type is 9 and is used to indicate a security parameter set. The nal_unit_type is 10 and is used to indicate authentication data. nal_unit_type is 10 to indicate the end of the stream, nal_unit_type is 12 to indicate a coded slice of a non-displayed knowledge picture, and nal_unit_type is 14 to indicate a coded slice of an RL picture. An RL picture is a P-picture or B-picture that uses only the knowledge picture as a reference picture for inter-frame prediction decoding. An RL picture is a random access point picture. nal_unit_type is 17 to indicate a coded slice of a displayed knowledge picture, nal_unit_type is 18 to indicate a coded slice that demarcates a non-displayed knowledge picture, and nal_unit_type is 19 to indicate a coded slice of a privacy picture.

[0201] In one possible example, the processing device 300 sets sec_para_set_id according to the configuration, sets the above-mentioned sec_is_library_flag to 0, authentication_enable_flag to 1 (indicating that authentication is enabled), hash_type to 0 (using the SM3 algorithm), sets the authentication_hash_mode value to 0 or 1 according to the configuration (using the connection method or the tree top method to calculate the secondary digest), and sets hash_discard_nrap_pictures_flag according to the configuration. If authentication of non-random access point images is required, it is set to 0, otherwise it is set to 1. According to the configured hash period HashPeriodInDoi, hash_period_in_doi_minus1 is set to HashPeriodInDoi minus 1; HashPeriodInDoi being 1 indicates that a single access unit is independently signed, and HashPeriodInDoi greater than 1 indicates that multiple access units are jointly signed.

[0202] Furthermore, the processing device 300 packages the security parameter set into a security parameter set NAL unit. For example, the processing device 300 sets the authentication_idc of the security parameter set NAL unit. Since the layer_id of the security parameter set NAL unit is 0, if the authentication_idc is non-zero, the authentication_idc is set to the authentication_idc of the layer unit with layer_id 0, that is, the sec_para_set_id of the security parameter set selected for authentication of the layer unit.

[0203] The processing device 300 sets the authentication_data_id of the security parameter set NAL unit to 0 or 1. It is recommended that the authentication_data_id of the NAL units participating in authentication with the same sec_para_set_id and authentication_idc as the previous group be different.

[0204] The processing device 300 adds a security parameter set NAL unit before the picture sequence parameter set NAL unit and inserts it into the bitstream.

[0205] In a possible example, the processing device 300 may compile the above fields into the security parameter set according to a preset syntax according to the syntax table shown in Table 1.

[0206] Table 1

[0207] Among them, encryption_enable_flag is the encryption enable flag, a binary variable. A value of '1' indicates that encryption of display picture coding slices, display picture sequence parameter sets, display picture parameter sets, non-display knowledge picture coding slices, display knowledge picture coding slices, knowledge picture sequence parameter sets, knowledge picture parameter sets, or extension data units is supported, that is, the RBSP in the NAL unit may be encrypted. A value of '0' indicates that encryption of RBSP in the NAL unit is not supported.

[0208] encryption_unit_mode is a 2-bit unsigned integer indicating the encryption basic unit. A value of '0' indicates encryption per NAL; a value of '1' indicates encryption per access unit, concatenating the encrypted portions of all NAL unit RBSPs in the access unit in bitstream order and restoring them to the encrypted NAL unit; a value of '2' indicates encryption per layer unit, concatenating the encrypted portions of all NAL unit RBSPs in the layer unit in bitstream order and restoring them to the encrypted NAL unit; a value of '3' indicates reserved. The IV must be reinitialized for each encryption.

[0209] encryption_level_mode is the encryption level mode, a 2-bit unsigned integer. It indicates the encryption level mode. A value of '0' indicates that when encrypting all NAL unit types, the entire RBSP data (except the last byte of the RBSP) is encrypted. A value of '1' indicates that when encrypting NAL units with nal_unit_type equal to 1, 2, 4, 12, 14, 17, 18, and 19, the first encryptionByte bytes of the RBSP are encrypted, and when encrypting other NAL unit types, the entire RBSP data (except the last byte of the RBSP) is encrypted. A value of '2' indicates that when encrypting NAL units with nal_unit_type equal to 1, 2, 4, 5, 12, 14, 17, 18, and 19, the first encryptionByte bytes of the RBSP are encrypted, and when encrypting other NAL unit types, the entire RBSP data (except the last byte of the RBSP) is encrypted. A value of '3' is reserved. Where encryptionByte = Min(EncryptionNum * EncryptionBaseByte, NumBytesInPayload - 1).

[0210] encryption_num_minus1 is the number of encryption basic byte lengths, an 8-bit unsigned integer. It indicates the number of encryption basic byte lengths. The value of EncryptionNum is equal to the value of encryption_num_minus1 plus 1.

[0211] encryption_base_byte is the encryption base byte length, a 2-bit unsigned integer. It indicates the encryption base byte length. A value of '0' indicates that the encryption base byte length is 16, a value of '1' indicates that the encryption base byte length is 64, a value of '2' indicates that the encryption base byte length is 256, and a value of '3' indicates that the encryption base byte length is 1024.

[0212] encryption_type is the encryption type, a 4-bit unsigned integer. It indicates the encryption algorithm used. For specific correspondence, see Table 2.

[0213] Table 2

[0214] vek_flag is the video encryption key flag, a binary variable. A value of '1' indicates that vek is carried, and a value of '0' indicates that vkek is not carried.

[0215] iv_flag is the initialization vector flag, a binary variable. A value of '1' indicates that the iv is carried, and a value of '0' indicates that the iv is not carried.

[0216] vek_encryption_type is the video encryption key encryption type, a 4-bit unsigned integer, indicating the encryption type of the video encryption key.

[0217] evek_length_minus1 is the length of the encrypted video encryption key, an 8-bit unsigned integer. It indicates the length of the encrypted video encryption key in bytes.

[0218] evek is the encrypted video encryption key, an n-bit unsigned integer. It represents the encrypted video encryption key and is used for encryption calculations. Its length is evek_length_minus1 plus 1 byte.

[0219] vkek_version length_minus1 is the length of the video encryption key version number, an 8-bit unsigned integer. Indicates the length of the video encryption key version number in bytes.

[0220] vkek_version is the video encryption key version number, an n-bit unsigned integer. Indicates the video encryption key version number, and its length is vkek_version_length_minus1 plus 1 byte.

[0221] iv_length_minus1 is an 8-bit unsigned integer representing the length of the initial vector, in bytes.

[0222] iv is the initialization vector, an n-bit unsigned integer. It indicates the initialization vector used for block encryption and has a length of iv_length_minus1 plus 1 byte.

[0223] hash_type is the hash type, a 2-bit unsigned integer. It indicates the algorithm used for authentication. The specific correspondence is shown in Table 3.

[0224] Table 3

[0225] signature_type is the digital signature type, a 2-bit unsigned integer, indicating the algorithm used to digitally sign the image summary data, as shown in Table 4.

[0226] Table 4

[0227] signature_fmt is the signature data format, a 2-bit unsigned integer. It indicates the signature data format. The specific meaning of the signature_fmt value and the corresponding relationship between the signature_type syntax are shown in Table 5.

[0228] Table 5

[0229] This step generates security parameter set 2 for the knowledge image, with the sec_is_library_flag set to 1, indicating independent signature authentication for the knowledge image. The security parameter set is scoped to a single knowledge image. The knowledge image participating in the authentication cannot span multiple RASs or reside in two RASs. Each knowledge image, including both displayed and non-displayed knowledge images, must be independently signed and authenticated.

[0230] S420: The processing device 300 calculates summary data of the security parameter set corresponding to the display image participating in the signature in the RAS.

[0231] When calculating the summary of an access unit, the NAL units of the layer units that need to be authenticated in the access unit are used (including security parameter set NAL unit (if present), picture sequence parameter set NAL unit (if present), picture parameter set NAL unit (if present), picture header NAL unit, display picture layered coding slice NAL unit, extended data NAL unit (if present), supplementary enhancement information NAL unit (if present), etc.).

[0232] The summary data for the displayed image can be calculated as follows:

[0233] Step 1. The processing device 300 sets the authentication_idc in the header information of these NAL units to the sec_para_set_id in the security parameter set; (Note: when generating the bit stream, if the authentication_idc of the NAL unit with the same layer_id is not 0, it is recommended to use the same security parameter set with sec_para_set_id.).

[0234] Step 2. The processing device 300 sets the authentication_data_id of the current NAL unit. If there is a NAL unit participating in authentication with the same authentication_data_id as the previous group, the authentication_data_id should be different from the authentication_data_id of the previous group; otherwise, if the NAL unit participates in authentication together with the security parameter set NAL unit, the authentication_data_id also needs to be consistent with the authentication_data_id of the security parameter set NAL unit; otherwise, it is set to 0 or 1.

[0235] Step 3: The processing device 300 then concatenates all NAL units involved in authentication in the layer unit and calculates the digest of the layer unit.

[0236] Based on the configuration, the processing device 300 extracts HashPeriodInDoi access units participating in authentication from the compressed video bitstream output by the encoder and calculates the digests H1, H2, ..., Hn for each layer unit within each access unit in bitstream order, where n is equal to the total number of layer units participating in authentication across all access units. The authentication data should not span RASs, so the number of access units authenticated together in the last group within each RAS may be less than HashPeriodInDoi.

[0237] Calculates a secondary digest based on each digest value in the manner specified by authentication_hash_mode.

[0238] The above-mentioned group of layer units is the layer units included in the HashPeriodInDoi access units participating in the authentication taken out from the bit stream.

[0239] S430: The processing device 300 signs the summary data of a group of layer units to obtain signature data.

[0240] The summary data of the group of layer units is the secondary summary value of the group of layer units.

[0241] For the details of S430 , reference may be made to the two possible examples of obtaining signature data shown in S310 above, which will not be described in detail here.

[0242] S440: The processing device 300 generates an authentication data NAL unit corresponding to the security parameter set of the display image, and adds the NAL unit to the bitstream.

[0243] The plurality of digest data corresponding to the plurality of layer units in a group of layer units are arranged in sequence in the authentication data according to the bit stream order of the plurality of layer units.

[0244] In one possible scenario, the authentication data NAL includes signature data.

[0245] In another possible scenario, the authentication data NAL unit includes signature data and summary data of each layer unit in a group of layer units corresponding to the display image.

[0246] The following provides a possible example for generating the content of the authentication data NAL unit.

[0247] Step 1: The processing device 300 sets for_current_ras_idc to 0 and auth_is_library_flag to 0.

[0248] Step 2: The processing device 300 sets the authentication_data_id of the current authentication data. The authentication_data_id is consistent with the authentication_data_id of the NAL unit participating in the authentication.

[0249] Step 3: The processing device 300 sets authentication_hash_list_flag according to the configuration. 0 indicates that the authentication data does not contain a digest list, and 1 indicates that the authentication data does contain a digest list. When authentication_hash_list_flag is 1, authentication_hash_number_minus1 is set to the number of digests minus 1, and authentication_hash is the digest value {H1, H2, ..., Hn} of the displayed image.

[0250] Step 4: The processing device 300 writes the signature data into authentication_data and sets authentication_data_length_minus1 to the actual length of authentication_data minus 1.

[0251] The processing device 300 packages the authentication data into an authentication data NAL unit, and then inserts the authentication data NAL unit into or after the last access unit of this authentication, before the next authentication data NAL unit, and before the next random access point access unit that is not a display knowledge image. The temporal_id and layer_id of the authentication data NAL unit header are set to 0. In particular, the last authentication data in each RAS is allowed to be placed in the next RAS. In this case, the for_current_ras_idc in the authentication data is set to 0. The interval between the authentication data and the layer unit in the last access unit participating in the authentication cannot exceed HashPeriodInDoi (equal to hash_period_in_doi_minus1+1 in the security parameter set corresponding to this authentication) access units (excluding non-display knowledge image access units). The authentication_idc of the authentication data NAL unit is set to sec_para_set_id in the corresponding security parameter set, and the authentication_data_id is set to the authentication_data_id in the NAL unit header of the layer unit participating in the authentication.

[0252] The authentication data for a display picture may be located in the access unit containing the last display picture coded slice, or in the access unit containing the display picture coded slice of the next RAS. The authentication data NAL unit shall be located after all other NAL units in the access unit except the end-of-stream NAL unit and the end-of-coded video sequence NAL unit.

[0253] As a possible implementation, the authentication data RBSP definition may be as shown in Table 6.

[0254] Table 6

[0255] for_current_ras_idc is a binary variable that identifies the location of the authentication data. A value of '1' indicates that all access units corresponding to the digests in the digest list in the authentication data are within the current random access segment. A value of '0' indicates that none of the access units corresponding to the digests in the digest list in the authentication data are within the current random access segment. All access units signed together should be within the same random access segment.

[0256] auth_is_library_flag is the knowledge image authentication data flag, a binary variable. A value of '1' indicates that the authentication data is the signature data of a knowledge image; a value of '0' indicates that the authentication data is the signature data of a display image or a display knowledge image. The value of AuthIsLibraryFlag is equal to the value of auth_is_library_flag. If auth_is_library_flag is not present in the bitstream, the value of AuthIsLibraryFlag is 0.

[0257] authenticaion_library_picture_index is the authentication knowledge image index.

[0258] authentication_hash_list_flag is a binary variable that identifies the authentication digest list. A value of '1' indicates that the authentication data carries a digest list of access units used to generate the signature in the authentication data. A value of '0' indicates that the authentication data does not carry a digest list of access units used to generate the signature in the authentication data.

[0259] authentication_hash_number_minus1 is the number of authentication digests, an 8-bit unsigned integer ranging from 0 to 255. Authentication_hash_number_minus1 plus 1 indicates the number of authentication digests.

[0260] authentication_data_length_minus1 is the length of the signature data, an 8-bit unsigned integer. 1 plus 1 indicates the length of the signature data in bytes, and the value should be between 0 and 255.

[0261] authentication_data[i] is the number of signature data bytes, an 8-bit unsigned integer. The i-th byte of a signature data. The authentication data NAL unit should be located after all other types of NAL units in the access unit except the end-of-stream NAL unit and the end-of-coded video sequence NAL unit. The order of authentication data NAL units corresponding to the same security parameter set in the bitstream should be the same as the bitstream order of the access unit to which they correspond, that is, if the first authentication data NAL unit is located before the second authentication data NAL unit, then any access unit associated with the first authentication data NAL unit is located before any access unit associated with the second authentication data NAL unit.

[0262] The authentication data NAL unit of the display image should be located in or after the last access unit of this authentication, before the next authentication data NAL unit, and before the next random access point access unit that is not a display knowledge image. In particular, the last authentication data in each RAS is allowed to be placed in the next RAS. In this case, set for_current_ras_idc in the authentication data to 0. The interval between the authentication data and the layer unit in the last access unit participating in the authentication cannot exceed HashPeriodInDoi (equal to hash_period_in_doi_minus1+1 in the security parameter set corresponding to this authentication) access units (excluding non-display knowledge image access units). The authentication data of the display image can be located in the access unit where the last display image coding slice is located; it can also be located in the access unit of the display image coding slice of the next RAS.

[0263] The authentication data NAL unit of the knowledge image should be located in or after the last access unit of this authentication, before the next authentication data NAL unit, and before the next random access point access unit.

[0264] The interval between the authentication data of the display knowledge image and the display knowledge image access unit shall not exceed HashPeriodInDoi (equal to hash_period_in_doi_minus1+1 in the security parameter set corresponding to this authentication) access units. The authentication data of the display knowledge image may be located in the access unit of the last display knowledge image coding slice; it may also be located in the access unit of the display image coding slice of the next RAS.

[0265] The authentication data of the non-display knowledge image is located in the access unit where the last non-display knowledge image coding slice is located.

[0266] The authentication data RBSP is written into the authentication data NAL unit.

[0267] In a possible embodiment, only the contents shown in FIG. 3 and FIG. 4 a can obtain the following bit stream.

[0268] The bitstream includes: a set of layer units and authentication data. The authentication data includes signature data, the signature data being signed based on digest data of each layer unit in the set of layer units of the bitstream, wherein a layer unit in the set of layer units includes a network abstraction layer unit having the same layer identifier in the bitstream.

[0269] In a possible implementation, the authentication data further includes summary data of each layer unit in a group of layer units.

[0270] In a possible implementation, the bit stream further includes a security data set.

[0271] For more details about a set of layer units, authentication data or security data sets, please refer to the descriptions shown in Figures 3 and 4a above, and will not be repeated here.

[0272] The bit stream in this embodiment may be the bit stream b shown in FIG. 3 .

[0273] After the above introduction of the bitstream signature method, the processing device 300 can send the bitstream obtained by the above bitstream signature method to the authentication end 220 shown in Figure 2 for processing. Based on this, the embodiment of the present application also provides two bitstream authentication methods.

[0274] FIG5 is a flowchart illustrating a bitstream authentication method provided by the present application. The bitstream authentication method can be applied to the signature and authentication system shown in FIG2 . For example, the bitstream authentication method can be implemented by a processing device 500. In one possible example, the processing device 500 can be the authentication terminal 220 shown in FIG2 . The bitstream in this embodiment can be the bitstream b in FIG3 . The bitstream authentication method can include the following steps S510-S530.

[0275] S510 , the processing device 500 determines first summary data for each layer unit of a group of layer units in a bitstream.

[0276] A layer unit in a group of layer units includes a network abstraction layer unit having the same layer identifier in the bit stream.

[0277] Exemplarily, the processing device 500 determines each layer unit in a group of layer units in the bitstream, takes a layer unit as an example, confirms the NAL units participating in the authentication in the layer unit, splices the NAL units participating in the authentication together, calculates the summary of the spliced ​​NAL units, and obtains the first summary data of the layer unit.

[0278] It is worth noting that as the processing device 500 continuously receives the bitstream, it continuously calculates and caches the first digest data for each layer unit. Furthermore, the processing device 500 may calculate and cache the first digest data in the order in which the layer units are received (i.e., the order of the bitstream).

[0279] In one possible scenario, all access units of a group of layer units are stored in a summary list.

[0280] For example, the processing device 500 caches the first summary data in a memory of the processing device 500 .

[0281] S520: The processing device 500 obtains authentication data from the bit stream.

[0282] The authentication data includes signature data and second summary data of each layer unit in a group of layer units, and the signature data is obtained by signing according to the second summary data of each layer unit in the group of layer units.

[0283] For more detailed content of the authentication data, please refer to the content shown in Figure 3 or Figure 4a above, which will not be repeated here.

[0284] S530: If the processing device 500 successfully verifies the signature data, the processing device 500 verifies the plurality of second digest data in the authentication data according to the first digest data of each layer unit of a group of layer units in the bitstream.

[0285] In one possible implementation, the signature data may be verified in the following manner.

[0286] The processing device 500 obtains the public key, and then determines the secondary summary data corresponding to a set of layer units based on the second summary data of each layer unit in the set of layer units included in the authentication data, thereby verifying the signature data based on the public key, the secondary summary data and the signature algorithm.

[0287] In a possible implementation, the processing device 500 calculates the second summary data of each layer unit of a group of layer units in a tree top manner or a connection manner according to the value indicated by authentication_hash_mode (such as 0 or 1) to obtain secondary summary data.

[0288] For the description of the secondary summary data, reference may be made to the content of the secondary summary data shown in S310 in FIG. 3 , which will not be described in detail here.

[0289] For example, when the digital signature type signature_type is parsed from the codestream security parameter set RBSP, the processing device 300 can determine the signature algorithm according to the signature algorithm indicated by signature_type. signature_type is a 2-bit unsigned integer used to indicate the algorithm for digitally signing the summary data of the image.

[0290] Illustratively, the processing device 500 may determine the signature algorithm according to a pre-agreed signature algorithm.

[0291] For example, when the camera certificate identifier camera_idc is obtained from the security parameter set RBSP of the code stream, the processing device 300 may search for the public key in the authentication certificate indicated by camera_idc.

[0292] Exemplarily, the processing device 500 may parse the authentication data RBSP of the code stream to obtain the public key.

[0293] Exemplarily, the processing device 500 may obtain a public key pre-installed in the authentication terminal 220 .

[0294] In a possible scenario, the second digest data corresponding to the multiple layer units in a group of layer units are arranged in sequence in the authentication data according to the bit stream order of the multiple layer units.

[0295] For the content in this case, reference may be made to the arrangement of the second summary data in the authentication data in S320 above, which will not be described in detail here.

[0296] In one possible implementation, the processing device 500 verifies the plurality of second digest data in the authentication data based on the first digest data of each layer unit of a group of layer units in the bitstream, including:

[0297] The processing device 500 sequentially matches the first digest data with the second digests according to the arrangement order of the plurality of second digest data in the authentication data and the plurality of first digest data of a group of layer units.

[0298] In one possible example, the processing device 500 matches the first summary data of multiple layer units included in a group of layer units with the multiple second summary data in the authentication data in sequence. If the match is successful, the layer unit of the successfully matched first summary data is successfully authenticated, and the layer unit is valid (available); if the match fails, the layer unit of the unmatched first summary data fails to be authenticated (unavailable).

[0299] It's worth noting that the aforementioned matching also includes position matching. For example, if summary data a among the plurality of second summary data matches summary data b among the plurality of first summary data, the next summary data after summary data a among the plurality of second summary data matches the next summary data after summary data a among the plurality of first summary data. If so, the layer unit corresponding to the next summary data after summary data a is valid.

[0300] In one possible implementation, the processing device 500 calculates first digest data based on the layer units in the bitstream and stores the first digest data in a first digest list. Furthermore, the processing device 500 stores the second digest data obtained from the authentication data in a second digest list. The processing device 500 may match the identifier of the second digest list with a digest list locally cached by the processing device 500. If it is determined that the identifier of the second digest list matches the identifier of the first digest list, the step of "verifying the plurality of second digest data in the authentication data based on the first digest data of each layer unit in the set of layer units in the bitstream" in S530 above is executed.

[0301] In a possible example, the above identifier may be sec_para_set_id and authentication_data_id.

[0302] In one possible scenario, processing device 500 stores the first digest data and third digest data calculated based on the layer units in the bitstream in a first digest list and a third digest list, respectively. The first digest list includes the first digest data for each layer unit in the set of layer units, and the third digest list includes the third digest data for each layer unit in the set of layer units. Notably, processing device 500 stores the obtained first and third digest lists in a memory of processing device 500, such as a memory, a hard disk, or a cache. The authentication data also includes a second digest list, which includes the second digest data for each layer unit in the set of layer units.

[0303] Furthermore, if the identifier of the first digest list is consistent with the identifier of the second digest list, and the identifier of the third digest list is inconsistent with the identifier of the second digest list, then the authentication of a group of layer units corresponding to the third digest list fails.

[0304] It is worth noting that the group of layer units corresponding to the third summary list is ordered before the group of layer units corresponding to the first summary list in the bitstream.

[0305] FIG6 is a second flow chart of a bitstream authentication method provided by the present application. The bitstream authentication method can be applied to the signature and authentication system shown in FIG2 . For example, the bitstream authentication method can be implemented by a processing device 500. In one possible example, the processing device 500 can be the authentication terminal 220 shown in FIG2 , and the bitstream in this embodiment can be the bitstream b in FIG3 . The bitstream authentication method can include the following steps S610-S630.

[0306] S610: The processing device 500 determines first summary data of a group of layer units in a bitstream.

[0307] The first summary data is the above-mentioned second-level summary data.

[0308] In a possible implementation, the processing device 500 determines third summary data of each layer unit in a group of layer units, and then determines first summary data corresponding to the group of layer units based on the third summary data of each layer unit in the group of layer units.

[0309] Exemplarily, the processing device 500 concatenates the third summary data of all layer units in a group of layer units to obtain concatenated third summary data, and calculates a digest of the concatenated third summary data to obtain first summary data. The first summary data is the secondary summary data of the group of layer units.

[0310] For example, the processing device 500 directly concatenates the character strings corresponding to the third digest data of all layer units to obtain concatenated third digest data.

[0311] Exemplarily, the processing device 300 determines third summary data of each layer unit in a group of layer units of the bitstream, and further calculates a tree-top summary of a plurality of third summary data in the group of layer units as the first summary data.

[0312] For the content of S610 and the content of the above possible implementation methods, reference may be made to the content of calculating summary data of a group of layer units in the above S310, which will not be described in detail here.

[0313] It is worth noting that as the processing device 500 continuously receives the bitstream, it continuously calculates and caches the summary data for each layer unit. Furthermore, the processing device 500 may calculate and cache the summary data in the order in which the layer units were received (i.e., the order in which the bitstream was received), thereby calculating the first summary data for a group of layer units based on the summary data for each layer unit in the group.

[0314] The first summary data may be stored in a memory of the processing device 500 .

[0315] S620: The processing device 500 obtains authentication data from the bit stream.

[0316] The authentication data includes signature data, which is obtained by signing based on the second summary data of each layer unit in a group of layer units, and a layer unit in the group of layer units includes a network abstraction layer unit with the same hierarchical identifier in an access unit of the bit stream.

[0317] For more details about the authentication data, please refer to the contents shown in Figures 3 to 5 above, which will not be repeated here.

[0318] S630: The processing device 500 verifies the signature data using the first digest data.

[0319] In a possible implementation, the processing device 300 verifies the signature data using the first digest data, including: the processing device obtains a public key, and then verifies the signature data according to the public key, the first digest data, and the signature algorithm.

[0320] For the details of S830 , please refer to the description of verifying the signature data in the above S730 , which will not be described in detail here.

[0321] In one possible implementation, the processing device 500 determines from the memory an identifier of the first summary data that matches the identifier of the authentication data, and if the identifier of the first summary data matches the identifier of the authentication data, performs the above-mentioned step of verifying the signature data using the first summary data.

[0322] In one possible scenario, the processing device 500 calculates first summary data based on the first set of layer units in the bitstream and fourth summary data based on the second set of layer units. It is worth noting that the processing device 500 stores the obtained first summary data and fourth summary data in a memory of the processing device 500, such as a memory, a hard disk, or a cache. Both the first summary data and the fourth summary data are secondary summary data.

[0323] Furthermore, if the identifier of the first digest data is consistent with the identifier obtained by the authentication data, and the identifier of the fourth digest data is inconsistent with the identifier of the authentication data, then the authentication of the second group layer unit corresponding to the fourth digest data fails.

[0324] It is worth noting that the second set of layer units is ordered before the first set of layer units in the bitstream.

[0325] In a possible example, the above identifier may be sec_para_set_id and authentication_data_id.

[0326] For the detailed content of S630, please refer to the description of S530 above, which will not be repeated here.

[0327] A complete embodiment of the bitstream authentication method is provided below, which includes the following steps ①-④.

[0328] Step ①: The processing device 500 inputs a bit stream (compressed video bit stream), and then obtains a security parameter set NAL unit in the bit stream.

[0329] The processing device 500 obtains one or more security parameter set NAL units of the RAS and obtains sec_para_set_id, authentication_enable_flag, authentication_data_id, hash_type, authentication_hash_mode, hash_discard_nrap_pictures_flag, and hash_period_in_doi_minus1 from the security parameter set. If the authentication_enable_flag in the security parameter set is 0, the security parameter set does not support authentication of displayed images. If the hash_discard_nrap_pictures_flag in the security parameter set is 1, the security parameter set does not support authentication of non-random access point images.

[0330] For each security parameter set, authenticate the layer units involved in authentication according to steps 2 and 3.

[0331] Step ②: The processing device 500 obtains a display image access unit in the RAS for a security parameter set and calculates summary data of the display image.

[0332] Calculation Summary:

[0333] The processing device 500 receives NAL data of hash_period_in_doi_minus1+1 display image access units in the RAS, concatenates the NAL units of the layer units involved in authentication in the access unit, and calculates the digest of the layer unit. The last group of data involved in authentication in the RAS may be less than hash_period_in_doi_minus1+1.

[0334] The processing device 500 calculates secondary digests based on the digest values ​​in the order of the bit stream, and stores the secondary digest values ​​into a local cache using sec_para_set_id and authentication_data_id as identifiers.

[0335] For example, the processing device 500 generates a digest list {H1', H2', ..., Hm'} for consecutive layer units with the same authentication_data_id, identified by sec_para_set_id and authentication_data_id, in bitstream order, and stores it in the local cache, where m is equal to the total number of layer units participating in authentication in the access unit. If an unauthenticated digest list identified by authentication_data_id exists, the layer unit that generated this digest list fails authentication, and the new digest list overwrites the old digest list.

[0336] Step 3: Obtain display image authentication data and complete display image authentication.

[0337] The processing device 500 calculates from the access unit where the last display image coding slice participating in the authentication is located to a maximum of hash_period_in_doi_minus1+1 access units to obtain the authentication data.

[0338] When for_current_ras_idc in the authentication data is 1, it indicates that the authentication data is the authentication data of the current RAS; when for_current_ras_idc is 0, it indicates that the authentication data is the last authentication data of the previous RAS.

[0339] In one possible scenario, when authentication_hash_list_flag in the authentication data is 0, secondary digest value authentication is used.

[0340] The processing device 500 searches for the secondary digest value in the local cache according to the sec_para_set_id and authentication_data_id in the authentication data. If the secondary digest value is found, the digital signature in the authentication data is verified using the secondary digest value. If the signature verification succeeds, the layer unit authentication participating in generating the secondary digest value succeeds. If the verification fails, the layer unit authentication participating in generating the secondary digest value fails.

[0341] If the processing device 500 finds and the sec_para_set_id and authentication_data_id match the sec_para_set_id and authentication_data_id of the most recently received layer unit sequence, and if there are other unauthenticated secondary digest values ​​whose identifiers are not equal to the sec_para_set_id and authentication_data_id, the authentication data corresponding to the unauthenticated secondary digest values ​​are lost, and authentication of the layer units corresponding to these unauthenticated secondary digest values ​​fails. If the secondary digest value for the layer unit corresponding to the authentication_data_id is not found, the authentication data is invalid, and authentication fails.

[0342] In another possible scenario, when authentication_hash_list_flag is 1, digest list authentication is used.

[0343] 1. Parse the authentication data NAL unit to obtain the authentication_data_id and the corresponding digest list {H1, H2, ..., Hn}, and calculate the secondary digest; if authentication_hash_mode is 0, use the concatenation method to do the secondary digest calculation; if authentication_hash_mode is 1, use the tree top method to do the secondary digest calculation.

[0344] 2. Use the secondary digest value to verify the signature data parsed from the authentication data NAL unit and determine whether the digest list {H1, H2, ..., Hn} transmitted in the authentication data NAL unit passes verification. If not, the digest list data in the authentication data is untrustworthy and digest list authentication fails.

[0345] 3. Determine the layer units involved in the signature based on the parameters in the authentication data NAL unit. Search the locally cached digest list for the layer unit based on the sec_para_set_id and authentication_data_id. If found, the layer unit to be authenticated can be confirmed through the digest list. If found and the sec_para_set_id and authentication_data_id are consistent with the sec_para_set_id and authentication_data_id of the most recently received layer unit sequence, if there are other unauthenticated digest lists whose identifiers are not equal to sec_para_set_id and authentication_data_id, the authentication data corresponding to the unauthenticated digest lists are lost, and the layer units corresponding to these unauthenticated digest lists fail authentication. If the digest list for the layer unit corresponding to the sec_para_set_id and authentication_data_id is not found, the authentication data is invalid and authentication fails.

[0346] 4. Sequentially match the summary list of the layer unit {H1', H2', ..., Hm'} with the summary list in the authentication data {H1, H2, ..., Hn} to authenticate the layer unit. First, search for H1' in the summary list in the authentication data. If the search is successful, record the position of the summary list in the authentication data. The layer unit corresponding to H1' is successfully authenticated. Then, search for H2' in the summary list in the authentication data, starting from the position immediately after that position. If the search is successful, update the position of the summary list in the authentication data. The layer unit corresponding to H2' is successfully authenticated. Continue searching for H3', ..., Hm'. If the search is successful, the corresponding layer unit is successfully authenticated. If the search fails, the corresponding layer unit fails.

[0347] It is understood that, in order to implement the functions in the above embodiments, the processing device 300 and the processing device 500 include hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should readily appreciate that, in conjunction with the various exemplary units and method steps described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in hardware or in a manner driven by computer software depends on the specific application scenario and design constraints of the technical solution.

[0348] The bitstream signature method provided in accordance with this embodiment is described in detail above in conjunction with FIG. 1 to FIG. 4 c . The bitstream signature apparatus provided in accordance with this embodiment will be described below in conjunction with FIG. 7 .

[0349] FIG7 is a schematic diagram of a bitstream signature device provided by the present application. The schematic diagram of the bitstream signature device can be used to execute the method of the aforementioned embodiment. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding method provided above, and will not be repeated here. Exemplarily, the bitstream signature device 700 includes:

[0350] Acquisition module 710 is configured to acquire authentication data, wherein the authentication data includes signature data, the signature data being signed based on summary data of each layer unit in a set of layer units of the bitstream, wherein one layer unit in the set of layer units includes a network abstraction layer unit having the same layer identifier.

[0351] The output module 720 is configured to output a bit stream, where the bit stream includes authentication data.

[0352] For more achievable aspects of the bitstream signature apparatus 700, reference may be made to the steps performed by the processing device 300 in the aforementioned method embodiment. The bitstream signature apparatus 700 may be used to implement the functions of the processing device 300 in the aforementioned method embodiment, thereby also achieving the beneficial effects of the aforementioned method embodiment.

[0353] The above description, in conjunction with Figure 5, details the bitstream authentication method provided according to this embodiment. The following description, in conjunction with Figure 8a, details the bitstream authentication device provided according to this embodiment. Figure 8a is a first schematic diagram of a bitstream authentication device provided by this application. The schematic diagram of the bitstream authentication device can be used to perform the method of the aforementioned embodiment. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects of the corresponding method provided above, and will not be repeated here. Exemplarily, the bitstream authentication device 800a includes:

[0354] The first determining module 811 is configured to determine first summary data of each layer unit in a group of layer units in a bitstream, wherein a layer unit in the group of layer units includes a network abstraction layer unit having the same layer identifier.

[0355] The first acquisition module 821 is configured to acquire authentication data from the bitstream. The authentication data includes signature data and second summary data of each layer unit in a group of layer units. The signature data is obtained by signing the second summary data of each layer unit in the group of layer units.

[0356] The first verification module 831 is configured to verify the plurality of second summary data in the authentication data according to the first summary data of each layer unit of a group of layer units in the bitstream if the signature data is successfully verified.

[0357] For more achievable aspects of the bitstream authentication device 800a, reference may be made to the steps performed by the processing device 500 in the aforementioned method embodiment. The bitstream authentication device 800a may be used to implement the functions of the processing device 500 in the aforementioned method embodiment, thereby also achieving the beneficial effects of the aforementioned method embodiment.

[0358] The above description, in conjunction with Figure 6, details the bitstream authentication method provided by this embodiment. The following description, in conjunction with Figure 8b, details the bitstream authentication device provided by this embodiment. Figure 8b is a second schematic diagram of the bitstream authentication device provided by this application. The schematic diagram of the bitstream authentication device can be used to perform the method of the aforementioned embodiment. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding method provided above, and will not be repeated here. Exemplarily, the bitstream authentication device 800b includes:

[0359] The second determining module 812 is configured to determine first summary data of a group of layer units in the bitstream.

[0360] The second acquisition module 822 is used to obtain authentication data from the bit stream, where the authentication data includes signature data, where the signature data is signed based on the second summary data of each layer unit in a group of layer units, where one layer unit in the group of layer units includes a network abstraction layer unit with the same layer identifier.

[0361] The second verification module 832 is configured to verify the signature data using the first digest data.

[0362] For more achievable aspects of the bitstream authentication device 800b, reference may be made to the steps performed by the processing device 500 in the aforementioned method embodiment. The bitstream authentication device 800b may be used to implement the functions of the processing device 500 in the aforementioned method embodiment, thereby also achieving the beneficial effects of the aforementioned method embodiment.

[0363] It can be understood that the device shown in Figure 8a or Figure 8b is only an example provided in this embodiment. Depending on the different bitstream signature or authentication processes, the device may include more or fewer units, and this application is not limited to this.

[0364] When the apparatus shown in FIG. 7 , 8 a , or FIG. 8 b is implemented by hardware, the hardware may be implemented by a processor or a chip system. The chip system includes one or more chips, each of which includes a processor and a power supply circuit. The power supply circuit is used to power the processor, and the processor is used to implement the method of any possible implementation method in the above embodiments through a logic circuit or executing code instructions. The beneficial effects can be found in the description of any aspect of the above embodiments and will not be repeated here.

[0365] It is understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.

[0366] A computing device is also provided in an embodiment of the present application. The bitstream signature device 700 shown in Figure 7, the bitstream authentication device 800a shown in Figure 8a, or the bitstream authentication device 800b shown in Figure 8b can be implemented by a computing device, as shown in Figure 9, which is a structural diagram of the computing device provided in this application. The computing device 900 includes: a memory 910 and at least one processor 920. The processor 920 can implement the bitstream signature method or bitstream authentication method provided in the above embodiment, and the memory 910 is used to store software instructions corresponding to the above bitstream signature method or bitstream authentication method. For example, the computing device can be the camera 11 or the mobile phone 15 in Figure 1. The computing device 900 can be the above-mentioned processing device 300 or the processing device 500.

[0367] As an optional implementation, in hardware implementation, the computing device 900 may refer to a chip or chip system encapsulated with one or more processors 920. For example, when the computing device 900 is used to implement the method steps in the above embodiment, the processor 920 included in the computing device 900 executes the steps of the processing device 300 or the processing device 500 in the above method and its possible sub-steps. In an optional scenario, the computing device 900 may also include a communication interface 930, which can be used to send and receive data. For example, the communication interface 930 is used to receive a bit stream, etc.; the communication interface 930 can be implemented by an interface circuit included in the computing device 900. Therefore, in some examples, the communication interface 930 may also be referred to as a transceiver of the computing device. In this embodiment, the communication interface 930 supports wired connection using a unified multimedia interconnect interface.

[0368] In an embodiment of the present application, the communication interface 930, the processor 920, and the memory 910 may be connected via a bus 940, which may be divided into an address bus, a data bus, a control bus, etc. The bus 940 may be a peripheral component interconnect express (PCIe) bus, an extended industry standard architecture (EISA) bus, a unified bus (Ubus or UB), a compute express link (CXL), a cache coherent interconnect for accelerators (CCIX), or other types of buses.

[0369] The processor 920 may include a CPU, a graphics processing unit (GPU), an embedded neural-network processing unit (NPU), a microprocessor (MP), a digital signal processor (DSP), an ASIC, an FPGA or other programmable logic device, a transistor logic device, a hardware component or any combination thereof.

[0370] The memory 910 may include a volatile memory, such as a random access memory (RAM). The memory 910 may also include a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD), or a solid state drive (SSD).

[0371] It is worth noting that the computing device 900 can also perform the functions of the bitstream signature device 700 shown in FIG7 , the bitstream authentication device 800a shown in FIG8 a , or the bitstream authentication device 800b shown in FIG8 b , which are not described in detail here. All relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module and are not described in detail here.

[0372] An embodiment of the present application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that can be stored by a computing device or a data storage device such as a data center that contains one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a digital video disc (DVD)), or a semiconductor medium (e.g., a solid-state drive). The computer-readable storage medium stores instructions that instruct the computing device to execute a bitstream signature method or a bitstream authentication method. The computer-readable storage medium can also store the bitstream mentioned above, such as the bitstream obtained by the method shown in Figure 3 or Figure 4a.

[0373] Embodiments of the present application also provide a computer program product comprising instructions. The computer program product may be software or a program product comprising instructions that can be run on a computing device or stored in any available medium. When the computer program product is run on at least one computing device, the at least one computing device is caused to perform a bitstream signature method or a bitstream authentication method.

[0374] In addition, an embodiment of the present application also provides a device, which can specifically be a chip, component or module, and the device may include a connected processor and memory; wherein the memory is used to store computer-executable instructions, and when the device is running, the processor can execute the computer-executable instructions stored in the memory to enable the chip to execute the methods in the above-mentioned method embodiments.

[0375] Among them, the computing device, computer-readable storage medium, computer program product or chip provided in this embodiment are all used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding methods provided above, and will not be repeated here.

[0376] Through the description of the above implementation methods, technical personnel in the relevant field can understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.

[0377] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0378] Units described as separate components may or may not be physically separate, and components shown as units may be one physical unit or multiple physical units, that is, they may be located in one place or distributed in multiple places. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.

[0379] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0380] Any content of each embodiment of this application, as well as any content of the same embodiment, can be freely combined. Any combination of the above content is within the scope of this application.

[0381] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a device (which can be a single-chip microcomputer, chip, etc.) or a processor to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a ROM, a RAM, a magnetic disk, or an optical disk.

[0382] The steps of the method or algorithm described in conjunction with the disclosure of the embodiments of the present application can be implemented in a hardware manner, or can be implemented by a processor executing software instructions. The software instructions can be composed of corresponding software modules, and the software modules can be stored in RAM, flash memory, ROM, erasable programmable read-only memory (Erasable Programmable ROM, EPROM), electrically erasable programmable read-only memory (Electrically EPROM, EEPROM), registers, hard disks, mobile hard disks, read-only compact discs (CD-ROMs) or any other form of storage medium well known in the art. An exemplary storage medium is coupled to a processor so that the processor can read information from the storage medium and can write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an ASIC.

[0383] Those skilled in the art will appreciate that in one or more of the above examples, the functions described in the embodiments of the present application can be implemented using hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. Computer-readable media include computer-readable storage media and communication media, wherein communication media include any media that facilitates the transmission of computer programs from one place to another. The storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.

[0384] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms without departing from the purpose of this application and the scope of protection of the claims, all of which are within the protection of this application.

Claims

1. A bitstream signature method, characterized in that, The method includes: Obtaining authentication data; Wherein, the authentication data includes signature data, and the signature data is obtained by signing the digest data of each layer unit in a group of layer units of the bitstream, and one layer unit in the group of layer units includes network abstraction layer (NAL) units with the same layering identifier; Outputting a bitstream, the bitstream including the authentication data.

2. The method according to claim 1, wherein The authentication data further includes the digest data of each layer unit in the group of layer units.

3. The method according to claim 2, characterized in that, The digest data respectively corresponding to multiple layer units in the group of layer units are arranged in sequence in the authentication data according to the bitstream order of the multiple layer units.

4. The method according to claim 3, characterized in that, The group of layer units includes a first layer unit, and the method further includes: Arranging the network abstraction layer (NAL) units included in the first layer unit in bitstream order and then performing digest calculation to obtain the digest data of the first layer unit.

5. The method according to any one of claims 1 to 4, characterized in that The method further includes: Determining secondary digest data of the group of layer units according to the digest data of each layer unit in the group of layer units; Signing the secondary digest data with a private key to obtain the signature data.

6. The method according to claim 5, wherein The secondary digest data is obtained by concatenating the (n + 1)-th combined digest data and the digest data of the (n + 2)-th layer unit in bitstream order, calculating the digest of the concatenated data to obtain the (n + 2)-th combined digest data, until the digest data of each layer unit in the group of layer units participates in the concatenation; the (n + 1)-th combined digest data is obtained by calculating the digest after concatenating the n-th combined digest data and the digest data of the (n + 1)-th layer unit, where n is a positive integer.

7. The method according to claim 5, characterized in that, The secondary digest data is obtained by concatenating the second digest data of each layer unit in the group of layer units and calculating the secondary digest of the concatenated second digest data.

8. The method according to any one of claims 1 to 7, characterized in that, The maximum number of layer units included in the group of layer units is determined according to the hash period and the number of spatial layers.

9. The method according to any one of claims 1 to 8, characterized in that The decoding order of multiple network abstraction layer (NAL) units with the same layering identifier included in one layer unit is consecutive.

10. The method according to any one of claims 1 to 9, characterized in that, The network abstraction layer (NAL) units included in one layer unit have the same authentication identifier and the authentication identifier is greater than 0.

11. The method according to any one of claims 1 to 10, characterized in that, The obtaining of the authentication data includes: Generating the authentication data.

12. The method according to any one of claims 1 to 11, characterized in that, Before outputting the bitstream, the method further includes: Adding the authentication data to the bitstream.

13. A bitstream, characterized in that, The bitstream includes: A group of layer units and authentication data; Wherein, the authentication data includes signature data, and the signature data is obtained by signing the digest data of each layer unit in a group of layer units of the bitstream, and one layer unit in the group of layer units includes network abstraction layer (NAL) units with the same layering identifier.

14. The bitstream according to claim 13, wherein The authentication data further includes the digest data of each layer unit in the group of layer units.

15. The bitstream according to claim 14, wherein, The digest data respectively corresponding to multiple layer units in the group of layer units are arranged in sequence in the authentication data according to the bitstream order of the multiple layer units.

16. The bitstream according to any one of claims 13 to 15, characterized in that, The decoding order of multiple network abstraction layer (NAL) units with the same layering identifier included in one layer unit is consecutive.

17. The bitstream according to any one of claims 13 to 16, characterized in that, The network abstraction layer (NAL) units included in one layer unit have the same authentication identifier and the authentication identifier is greater than 0.

18. The bitstream according to any one of claims 13 to 17, characterized in that, The maximum number of layer units included in the set of layer units is determined according to the hash period and the number of spatial layers.

19. A bitstream authentication method, characterized in that, The method includes: Determining first digest data of each layer unit in a set of layer units in a bitstream; one layer unit in the set of layer units includes network abstraction layer (NAL) units having the same layering identifier; Obtaining authentication data from the bitstream; the authentication data includes: signature data and second digest data of each layer unit in the set of layer units, and the signature data is obtained by signing according to the second digest data of each layer unit in the set of layer units; If the verification of the signature data is successful, then verify multiple second digest data in the authentication data according to the first digest data of each layer unit in the set of layer units in the bitstream.

20. The method according to claim 19, wherein The first digest list includes the first digest data of each layer unit in the set of layer units, and the second digest list includes the second digest data of each layer unit in the set of layer units. The method further includes: Matching the identifier of the first digest list with the identifier of the second digest list; the identifier includes an authentication data identifier and / or a security parameter set identifier ID; If the identifier of the first digest list is consistent with the identifier of the second digest list, then execute verifying multiple second digest data in the authentication data according to the first digest data of each layer unit in the set of layer units in the bitstream.

21. The method according to claim 19 or 20, characterized in that, The maximum number of layer units included in the set of layer units is determined according to the hash period and the number of spatial layers.

22. The method according to any one of claims 19 to 21, characterized in that, The second digest data respectively corresponding to multiple layer units in the set of layer units are arranged in sequence in the authentication data according to the bitstream order of the multiple layer units.

23. The method according to claim 22, wherein The verifying multiple second digest data in the authentication data according to the first digest data of each layer unit in the set of layer units in the bitstream includes: Sequentially matching the first digest data with the second digest data according to the arrangement order of the multiple second digest data in the authentication data and the multiple first digest data of the set of layer units; If the matching is successful, then the layer unit of the successfully matched first digest data is authenticated successfully; If the matching fails, then the layer unit of the first digest data with the failed matching is authenticated failed.

24. The method according to any one of claims 19 to 23, characterized in that The method further includes: Obtaining a public key; Determining second-level digest data corresponding to the set of layer units according to the second digest data of each layer unit in the set of layer units included in the authentication data; Verifying the signature data according to the public key, the second-level digest data and a signature algorithm.

25. The method according to claim 24, wherein The second-level digest data is obtained by concatenating the (n + 1)-th combined digest data with the second digest data of the (n + 2)-th layer unit in the bitstream order, calculating the digest of the concatenated data to obtain the (n + 2)-th combined digest data, until the second digest data of each layer unit in the set of layer units all participate in the concatenation; the (n + 1)-th combined digest data is obtained by calculating the digest after concatenating the n-th combined digest data with the second digest data of the (n + 1)-th layer unit, where n is a positive integer.

26. The method according to claim 24, characterized in that, The second-level digest data is obtained by concatenating the second digest data of each layer unit in the set of layer units and calculating the digest of the concatenated second digest data.

27. A bitstream authentication method, characterized in that The method includes: Determining first digest data of a set of layer units in a bitstream; Obtaining authentication data from the bitstream, where the authentication data includes signature data, and the signature data is signed according to second digest data of each layer unit in the set of layer units, and one layer unit in the set of layer units includes network abstraction layer (NAL) units with the same layering identifier; Verifying the signature data by using the first digest data.

28. The method according to claim 27, wherein The determining first digest data of a set of layer units in the bitstream includes: Determining third digest data of each layer unit in the set of layer units in the bitstream; Determining the first digest data corresponding to the set of layer units according to the third digest data of each layer unit in the set of layer units.

29. The method according to claim 28, wherein Determining the first digest data corresponding to the set of layer units according to the third digest data of each layer unit in the set of layer units includes: Connecting the (n + 1)-th combined digest data with the third digest data of the (n + 2)-th layer unit in the order of the bitstream, calculating the digest of the connected data to obtain the (n + 2)-th combined digest data, until the third digest data of each layer unit in the set of layer units participates in the connection, to obtain the first digest data; the (n + 1)-th combined digest data is obtained by calculating the digest after connecting the n-th combined digest data with the third digest data of the (n + 1)-th layer unit, and n is a positive integer.

30. The method according to claim 28, wherein Determining the first digest data corresponding to the set of layer units according to the third digest data of each layer unit in the set of layer units includes: Connecting the third digest data of each layer unit in the set of layer units to obtain the concatenated third digest data; Calculating the digest of the connected third digest data to obtain the first digest data.

31. The method according to any one of claims 27 to 28, characterized in that, The verifying the signature data by using the first digest data includes: Obtaining a public key; Verifying the signature data according to the public key, the first digest data, and a signature algorithm.

32. The method according to any one of claims 27 to 31, characterized in that, The method further includes: Matching the identifier of the first digest data with the identifier of the authentication data; the identifier includes an authentication data identifier and / or a security parameter set identifier ID; If the identifier of the first digest data matches the identifier of the authentication data, then perform verifying the signature data by using the first digest data.

33. The method according to any one of claims 27 to 32, characterized in that, The maximum number of layer units included in the set of layer units is determined according to a hash period and the number of spatial layers.

34. A bitstream signature device, characterized in that, The apparatus includes: An obtaining module, configured to obtain authentication data; where the authentication data includes signature data, and the signature data is signed according to the digest data of each layer unit in a set of layer units of the bitstream, and one layer unit in the set of layer units includes network abstraction layer (NAL) units with the same layering identifier; An output module, configured to output a bitstream, where the bitstream includes authentication data.

35. The device according to claim 34, characterized in that, The authentication data further includes the digest data of each layer unit in the set of layer units.

36. The device according to claim 35, characterized in that, The digest data respectively corresponding to multiple layer units in the set of layer units are arranged in sequence in the authentication data according to the bitstream order of the multiple layer units.

37. The device according to claim 36, characterized in that, The set of layer units includes a first layer unit, and the apparatus further includes: The abstract calculation module is used to perform abstract calculation on the network abstraction layer (NAL) units included in the first-layer unit after arranging them in bitstream order, so as to obtain the abstract data of the first-layer unit.

38. The device according to any one of claims 34 to 37, characterized in that, The device further includes: The signature module is used to determine the secondary abstract data of the set of layer units according to the abstract data of each layer unit in the set of layer units, and sign the secondary abstract data with a private key to obtain the signature data.

39. The device according to claim 38, characterized in that, The secondary abstract data is obtained by concatenating the (n + 1)-th combined abstract data and the abstract data of the (n + 2)-th layer unit in bitstream order, calculating the abstract of the concatenated data to obtain the (n + 2)-th combined abstract data, until the abstract data of each layer unit in the set of layer units participates in the concatenation; the (n + 1)-th combined abstract data is obtained by calculating the abstract after concatenating the n-th combined abstract data and the abstract data of the (n + 1)-th layer unit, where n is a positive integer.

40. The device according to claim 38, characterized in that, The secondary abstract data is obtained by concatenating the second abstract data of each layer unit in the set of layer units and then calculating the secondary abstract of the concatenated second abstract data.

41. The device according to any one of claims 34 to 40, characterized in that, The maximum number of layer units included in the set of layer units is determined according to the hash period and the number of spatial domain layers.

42. The device according to any one of claims 34 to 41, characterized in that, The decoding order of multiple network abstraction layer (NAL) units with the same layer identification included in one layer unit is continuous.

43. The device according to any one of claims 34 to 42, characterized in that, The network abstraction layer (NAL) units included in one layer unit have the same authentication identification value and the authentication identification is greater than 0.

44. The device according to any one of claims 34 to 43, characterized in that, The acquisition module is used to generate the authentication data.

45. The device according to any one of claims 34 to 44, characterized in that, The device further includes an addition module; The addition module is used to add the authentication data to the bitstream.

46. A bitstream authentication device, characterized in that, The device includes: The first determination module is used to determine the first abstract data of each layer unit of a set of layer units in the bitstream; one of the layer units in the set of layer units includes network abstraction layer (NAL) units with the same layer identification; The first acquisition module is used to acquire authentication data from the bitstream; the authentication data includes: signature data and the second abstract data of each layer unit in the set of layer units, and the signature data is obtained by signing the second abstract data of each layer unit in the set of layer units; The first verification module is used to, if the verification of the signature data is successful, verify the multiple second abstract data in the authentication data according to the first abstract data of each layer unit of a set of layer units in the bitstream.

47. The device according to claim 46, characterized in that, The first abstract list includes the first abstract data of each layer unit in the set of layer units, and the second abstract list includes the second abstract data of each layer unit in the set of layer units. The first verification module is further used to match the identification of the first abstract list with the identification of the second abstract list; the identification includes the authentication data identification and / or the security parameter set identification ID; if the identification of the first abstract list is consistent with the identification of the second abstract list, then perform the verification of the multiple second abstract data in the authentication data according to the first abstract data of each layer unit of a set of layer units in the bitstream.

48. The device according to claim 46 or 47, characterized in that, The maximum number of layer units included in the set of layer units is determined according to the hash period and the number of spatial domain layers.

49. The device according to any one of claims 46 to 48, characterized in that, The second summary data respectively corresponding to multiple layer units in the group of layer units are arranged in sequence in the authentication data according to the bitstream order of the multiple layer units.

50. The device according to claim 49, characterized in that, The verification module is specifically configured to sequentially match the first summary data with the second summary data according to the arrangement order of the multiple second summary data in the authentication data and the multiple first summary data of a group of layer units; if the match is successful, the layer unit corresponding to the successfully matched first summary data is successfully authenticated; if the match fails, the layer unit corresponding to the failed-matched first summary data is failed to be authenticated.

51. The device according to any one of claims 46 to 50, characterized in that, The verification module is further configured to obtain a public key, determine the secondary summary data corresponding to the group of layer units according to the second summary data of each layer unit included in the authentication data, and verify the signature data according to the public key, the secondary summary data, and a signature algorithm.

52. The device according to claim 51, wherein, The secondary summary data is obtained by connecting the (n + 1)-th combined summary data and the second summary data of the (n + 2)-th layer unit in bitstream order, calculating the summary of the connected data to obtain the (n + 2)-th combined summary data, until the second summary data of each layer unit in a group of layer units all participates in the connection; the (n + 1)-th combined summary data is obtained by calculating the summary after connecting the n-th combined summary data and the second summary data of the (n + 1)-th layer unit, where n is a positive integer.

53. The device according to claim 51, characterized in that, The secondary summary data is obtained by connecting the second summary data of each layer unit in a group of layer units together and calculating the secondary summary of the connected second summary data.

54. A bitstream authentication device, characterized in that, The device includes: A second determination module, configured to determine the first summary data of a group of layer units of a bitstream; A second acquisition module, configured to acquire authentication data from the bitstream, where the authentication data includes signature data, and the signature data is obtained by signing according to the second summary data of each layer unit in the group of layer units, and one layer unit in the group of layer units includes NAL units of a network abstraction layer with the same layering identifier in one access unit of the bitstream; A second verification module, configured to verify the signature data by using the first summary data.

55. The device according to claim 54, characterized in that, The second determination module is specifically configured to determine the third summary data of each layer unit in a group of layer units of the bitstream, and determine the first summary data corresponding to the group of layer units according to the third summary data of each layer unit in the group of layer units.

56. The device according to claim 55, characterized in that, The second determination module is further specifically configured to connect the (n + 1)-th combined summary data and the third summary data of the (n + 2)-th layer unit in bitstream order, calculate the summary of the connected data to obtain the (n + 2)-th combined summary data, until the third summary data of each layer unit in a group of layer units all participates in the connection to obtain the first summary data; the (n + 1)-th combined summary data is obtained by calculating the summary after connecting the n-th combined summary data and the third summary data of the (n + 1)-th layer unit, where n is a positive integer.

57. The device according to claim 55, characterized in that, The second determination module is further specifically configured to concatenate the third digest data of each layer unit in the group of layer units to obtain the concatenated third digest data, and calculate a secondary digest for the concatenated third digest data to obtain the first digest data.

58. The device according to any one of claims 54 to 57, characterized in that, The second verification module is specifically configured to obtain a public key, and verify the signature data according to the public key, the first digest data, and a signature algorithm.

59. The device according to any one of claims 54 to 58, characterized in that, The second verification module is further configured to match the identifier of the first digest data with the identifier of the authentication data; the identifier includes an authentication data identifier and / or a security parameter set identifier ID; if the identifier of the first digest data matches the identifier of the authentication data, then execute verifying the signature data by using the first digest data.

60. The device according to any one of claims 54 to 59, characterized in that, The maximum number of layer units included in the group of layer units is determined according to a hash period and the number of spatial domain hierarchical layers.

61. A computing device, characterized in that, Comprising: A memory and a processor, the memory is used for storing computer instructions; when the processor executes the computer instructions, the method described in any one of claims 1 to 12 is implemented, or, the method described in any one of claims 19 to 33 is implemented.

62. A non-transitory computer-readable storage medium, characterized in that, A computer program or instruction is stored in the storage medium, when the computer program or instruction is executed by a processing device, the method described in any one of claims 1 to 12 is implemented; and / or, when the computer program or instruction is executed by a processing device, the method described in any one of claims 19 to 33 is implemented.

63. A computer program product, characterized in that, A computer program product includes computer instructions, when the computer instructions are executed by a computer or a processor, the steps of the method described in any one of claims 1 to 12 are executed, or, the steps of the method described in any one of claims 19 to 33 are executed.

64. A non-transitory computer-readable storage medium, characterized in that, A computer-readable storage medium stores the bitstream described in any one of claims 13 to 18.

Citation Information

Patent Citations

  • Data encoding method, data decoding method, related terminal and device

    CN111064717A

  • Video signal source encryption and decryption system and method based on AVS2 entropy coding of block encryption

    CN112533001A

  • Determination method and device of protection strategy, processor and electronic equipment

    CN117349820A

  • Code stream signature and authentication method

    CN118449703A

  • Code stream signature and authentication method

    CN118487771A