Bitstream, and bitstream signature and authentication method
By introducing security parameter sets and identifications into the bitstream signature method, the digest calculation method is flexibly selected, which solves the problem of poor applicability of fixed digest calculation method in the prior art, and improves the applicability and efficiency of bitstream signature.
Patent Information
- Application Number
- PCT/CN2024/113475
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-07
- Filing Date
- 2024-08-20
- Publication Date
- 2025-07-31
AI Technical Summary
In the bitstream signature process in the prior art, the fixed digest calculation method cannot be flexibly adjusted based on the end-side calculation performance factors, resulting in poor applicability.
By introducing a security parameter set in the bitstream signature method, including identification to indicate the summary calculation method, allowing flexibly selecting the summary calculation method based on the calculation performance of the end-side device, including the connection method and the treetop method, to improve the applicability of the summary calculation.
The summary calculation method is dynamically adjusted according to the performance of the end-side device, and the applicability and efficiency of the bitstream signature process are improved.
Smart Images

Figure CN2024113475_31072025_PF_FP_ABST
Abstract
Description
A bit stream, bit stream signature and authentication method
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on January 24, 2024, with application number 202410104552.0 and application name “A bitstream, bitstream signature and digest calculation method”, and claims priority to the Chinese patent application filed with the State Intellectual Property Office on February 7, 2024, with application number 202410176997.X and application name “A bitstream, bitstream signature and authentication method”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of multimedia technology, and in particular to a bit stream, a bit stream signature, and an authentication method. Background Art
[0003] Many audio and video encoding and decoding scenarios (for example, surveillance, live broadcast, on-demand, etc.) have certain requirements for the authenticity and integrity of audio and video content. Therefore, in order to ensure the security of audio and video content during transmission and prevent the audio and video content from being tampered with during transmission, the audio and video content needs to be signed.
[0004] Currently, the process for signing a bitstream involves generating digests corresponding to each access unit in the bitstream, signing the digests using a digital signature algorithm, and then writing the signatures into the bitstream. However, this signing process relies on a fixed digest calculation method that cannot be flexibly adjusted based on client-side computing performance factors, resulting in poor applicability.
[0005] Summary of the Invention
[0006] The present application provides a bitstream, bitstream signature and authentication method to solve the problem that only a fixed digest calculation method is used during the signing process, which cannot be flexibly adjusted according to the terminal computing performance factors and has poor applicability.
[0007] This application adopts the following technical solution.
[0008] In a first aspect, an embodiment of the present application provides a bitstream signature method. The bitstream signature method is executed by a computing device or a chip in a computing device, such as a mobile phone or a computer. Exemplarily, the method includes: the computing device obtains authentication data, and then outputs a bitstream, the bitstream including a security parameter set and authentication data. The security parameter set includes an identifier, which is used to indicate a calculation method for the digest; the authentication data includes signature data, which is obtained by signing secondary summary data, and the secondary summary data is obtained by processing the summary data of each data unit of a group of data units in the bitstream according to the calculation method of the digest indicated by the identifier.
[0009] In this application, the computing device determines the calculation method of the summary of a group of data units based on the identifier in the security parameter set, and then can flexibly select the calculation method of the summary of the data unit based on factors such as the computing performance of the end-side device, thereby improving the applicability of the summary.
[0010] In one possible scenario, the authentication data of a group of data units corresponds to a security parameter set.
[0011] In a possible implementation, the identifier is a first value, which is used to indicate that the summary is calculated by connecting the summary data of each data unit in a group of data units, calculating the secondary summary of the connected summary data, and obtaining the secondary summary data.
[0012] In one possible implementation, the identifier is a second value, which is used to indicate that the digest is calculated by concatenating the n+1th combined digest data with the digest data of the n+2th data unit in bit stream order, calculating the digest of the concatenated data, and obtaining the n+2th combined digest data, until the digest data of each data unit in a group of data units is concatenated to obtain secondary summary data; the n+1th combined digest data is obtained by calculating the digest after concatenating the nth combined digest data with the digest data of the n+1th data unit, where n is a positive integer.
[0013] In a possible implementation, the data unit is a Network Abstraction Layer (NAL) unit.
[0014] In a possible implementation, the data unit is a layer unit, and the layer unit includes network abstraction layer NAL units with the same layer identifier.
[0015] In a possible implementation, the data unit is an access unit.
[0016] In a possible implementation, the authentication data further includes summary data of each data unit in a group of data units.
[0017] In one possible implementation, the computing device obtains the security parameter set and the authentication data, including: generating the security parameter set and the authentication data.
[0018] In a possible implementation, before the computing device outputs the bitstream, the bitstream signature method further includes: the computing device adding authentication data to the bitstream.
[0019] In one possible implementation, the security parameter set corresponds to the authentication data. For example, the authentication data is authentication data that displays the image corresponding to the security parameter set.
[0020] In a second aspect, embodiments of the present application provide a bitstream. The bitstream includes a set of data units, a security parameter set, and authentication data. The security parameter set includes an identifier that indicates a digest calculation method; the authentication data includes signature data, which is obtained by signing secondary digest data. The secondary digest data is obtained by processing the digest data of each data unit in a set of data units in the bitstream according to the digest calculation method indicated by the identifier.
[0021] In a possible implementation, the identifier is a first value, which is used to indicate that the summary is calculated by connecting the summary data of each data unit in a group of data units, calculating the secondary summary of the connected summary data, and obtaining the secondary summary data.
[0022] In one possible implementation, the identifier is a second value, which is used to indicate that the digest is calculated by concatenating the n+1th combined digest data with the digest data of the n+2th data unit in bit stream order, calculating the digest of the concatenated data, and obtaining the n+2th combined digest data, until the digest data of each data unit in a group of data units is concatenated to obtain secondary summary data; the n+1th combined digest data is obtained by calculating the digest after concatenating the nth combined digest data with the digest data of the n+1th data unit, where n is a positive integer.
[0023] In a possible implementation, the data unit is a Network Abstraction Layer (NAL) unit.
[0024] In a possible implementation, the data unit is a layer unit, and the layer unit includes network abstraction layer NAL units with the same layer identifier.
[0025] In a possible implementation, the data unit is an access unit.
[0026] In a possible implementation, the authentication data further includes summary data of each data unit in a group of data units.
[0027] On the third aspect, an embodiment of the present application provides a bitstream authentication method. The bitstream authentication method is executed by a computing device or a chip in the computing device, such as a mobile phone or a computer. Exemplarily, the method includes: the computing device determines the first summary data of each data unit of a group of data units in the bitstream, and obtains the authentication data from the bitstream, and then if the signature data is successfully verified, the multiple second summary data in the authentication data are verified based on the first summary data of each data unit of the group of data units in the bitstream. Wherein, the authentication data includes: signature data and the second summary data of each data unit in the group of data units, the signature data is obtained by signing the secondary summary data, the secondary summary data is obtained by processing the second summary data of each data unit in the group of data units in the bitstream according to the calculation method of the summary indicated by the identifier, and the security parameter set in the bitstream includes the identifier.
[0028] In a possible implementation, the identifier is a first value, which is used to indicate that the digest is calculated by concatenating the second digest data of each data unit in a group of data units, calculating a secondary digest of the concatenated second digest data, and obtaining secondary digest data.
[0029] In one possible implementation, the identifier is a second value, and the second value is used to indicate that the digest is calculated by concatenating the n+1th combined digest data with the second digest data of the n+2th data unit in bit stream order, calculating the digest of the concatenated data, and obtaining the n+2th combined digest data, until the digest data of each data unit in a group of data units is concatenated to obtain secondary summary data; the n+1th combined digest data is obtained by calculating the digest after concatenating the nth combined digest data with the second digest data of the n+1th data unit, where n is a positive integer.
[0030] In a possible implementation, the data unit is a Network Abstraction Layer (NAL) unit.
[0031] In a possible implementation, the data unit is a layer unit, and the layer unit includes network abstraction layer NAL units with the same layer identifier.
[0032] In a possible implementation, the data unit is an access unit.
[0033] In a fourth aspect, an embodiment of the present application provides a bitstream authentication method. The bitstream authentication method is executed by a computing device or a chip in a computing device, such as a mobile phone or a computer. Exemplarily, the method includes: the computing device determines the first summary data of a group of data units in the bitstream, obtains authentication data from the bitstream, and then verifies the signature data using the first summary data. The authentication data includes signature data, the signature data is obtained by signing the secondary summary data, the secondary summary data is obtained by processing the second summary data of each data unit of a group of data units in the bitstream according to the calculation method of the summary indicated by the identifier, and the security parameter set in the bitstream includes the identifier.
[0034] In one possible implementation, the computing device determines first summary data of a group of data units of a bitstream, including: the computing device determines third summary data of each data unit in the group of data units of the bitstream, and then processes the third summary data of each data unit in the group of data units according to a calculation method of the summary indicated by the identifier to obtain first summary data of the group of data units.
[0035] In a possible implementation, the identifier is a first value, which is used to indicate that the summary is calculated by connecting the summary data of each data unit in a group of data units, calculating the secondary summary of the connected summary data, and obtaining the secondary summary data.
[0036] In one possible implementation, the identifier is a second value, which is used to indicate that the digest is calculated by concatenating the n+1th combined digest data with the digest data of the n+2th data unit in bit stream order, calculating the digest of the concatenated data, and obtaining the n+2th combined digest data, until the digest data of each data unit in a group of data units is concatenated to obtain secondary summary data; the n+1th combined digest data is obtained by calculating the digest after concatenating the nth combined digest data with the digest data of the n+1th data unit, where n is a positive integer.
[0037] In a possible implementation, the data unit is a Network Abstraction Layer (NAL) unit.
[0038] In a possible implementation, the data unit is a layer unit, and the layer unit includes network abstraction layer NAL units with the same layer identifier.
[0039] In a possible implementation, the data unit is an access unit.
[0040] In a fifth aspect, the present application provides a bitstream signature device, which includes a module for executing the method of the first aspect or any possible implementation of the first aspect.
[0041] In a sixth aspect, the present application provides a bitstream authentication device. The bitstream authentication device includes a module for executing the method of the third aspect or any possible implementation of the third aspect, or the bitstream authentication device includes a module for executing the method of the fourth aspect or any possible implementation of the fourth aspect.
[0042] In a seventh aspect, an embodiment of the present application provides a computing device, comprising: a memory and a processor; the memory storing program instructions, which, when executed by the processor, causes the computing device to execute the bitstream signature method of the first aspect or any possible implementation of the first aspect, or to execute the bitstream authentication method of the third aspect or any possible implementation of the third aspect, or to execute the bitstream authentication method of the fourth aspect or any possible implementation of the fourth aspect.
[0043] In an eighth aspect, embodiments of the present application provide a chip comprising one or more interface circuits and one or more processors; the one or more processors receive or send data via the one or more interface circuits, and when the one or more processors execute computer instructions, the steps of the bitstream signature method in the first aspect or any possible implementation of the first aspect are executed, or the steps of the bitstream authentication method in the third aspect or any possible implementation of the third aspect are executed, or the steps of the bitstream authentication method in the fourth aspect or any possible implementation of the fourth aspect are executed.
[0044] In a ninth aspect, embodiments of the present application provide a non-transitory computer-readable storage medium. The computer-readable storage medium stores a computer program that, when executed on a computer or processor, causes the computer or processor to execute the bitstream signature method of the first aspect or any possible implementation of the first aspect, or the bitstream authentication method of the third aspect or any possible implementation of the third aspect, or the bitstream authentication method of the fourth aspect or any possible implementation of the fourth aspect.
[0045] In a tenth aspect, embodiments of the present application provide a computer program product. The computer program product includes computer instructions that, when executed by a computer or processor, cause the computer or processor to perform the bitstream signature method of the first aspect or any possible implementation of the first aspect, or to perform the bitstream authentication method of the third aspect or any possible implementation of the third aspect, or to perform the bitstream authentication method of the fourth aspect or any possible implementation of the fourth aspect.
[0046] In an eleventh aspect, an embodiment of the present application provides a non-transitory computer-readable storage medium storing a bit stream according to the second aspect or any possible implementation of the second aspect.
[0047] In a twelfth aspect, an embodiment of the present application provides a device for storing a bitstream, comprising: a receiver and at least one storage medium, wherein the receiver is configured to receive the bitstream in the second aspect or any possible implementation of the second aspect.
[0048] In the thirteenth aspect, an embodiment of the present application provides a device for transmitting a bit stream, the device comprising: a transmitter and at least one storage medium, the at least one storage medium being used to store the bit stream in the second aspect or any possible implementation of the second aspect; the transmitter being used to obtain the bit stream from the storage medium and send the bit stream to an end-side device through a transmission medium.
[0049] In a fourteenth aspect, an embodiment of the present application provides a system for distributing bitstreams. The system includes: at least one storage medium for storing at least one bitstream according to the second aspect or any possible implementation of the second aspect; and a streaming media device for acquiring a target bitstream from the at least one storage medium and transmitting the target bitstream to an end-side device, wherein the streaming media device includes a content server or a content distribution server.
[0050] Regarding the beneficial effects of the second to fourteenth aspects, reference may be made to the description of any implementation in the first or second aspects, and no further details will be given here. Based on the implementations provided in the above aspects, this application can also be further combined to provide more implementations. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] FIG1 is a schematic diagram of an application scenario provided by this application;
[0052] FIG2 is a schematic diagram of the structure of the signature and authentication system provided by this application;
[0053] FIG3 is a flowchart of a bitstream signature method provided by the present application;
[0054] FIG4 is a first schematic diagram of summary calculation of a group of data units provided by this application;
[0055] FIG5 is a second schematic diagram of summary calculation of a group of data units provided by this application;
[0056] FIG6 is a second flow chart of a bitstream signature method provided by the present application;
[0057] FIG7 is a flowchart of a bit stream authentication method provided by the present application;
[0058] FIG8 is a second flow chart of a bit stream authentication method provided by the present application;
[0059] FIG9 is a schematic diagram of a bitstream signature device provided by the present application;
[0060] FIG10a is a schematic diagram of a bit stream authentication device provided by the present application;
[0061] FIG10 b is a second schematic diagram of a bit stream authentication device provided by the present application;
[0062] FIG11 is a schematic diagram of the structure of the computing device provided in this application. DETAILED DESCRIPTION
[0063] The present application provides a bitstream signing method, comprising: a computing device obtaining a security parameter set and authentication data, and then outputting a bitstream, the bitstream including the security parameter set and the authentication data. The security parameter set includes an identifier that indicates a digest calculation method; the authentication data includes signature data, the signature data being obtained by signing secondary digest data, the secondary digest data being obtained by processing the digest data of each data unit in a group of data units in the bitstream according to the digest calculation method indicated by the identifier.
[0064] In this application, the computing device determines the calculation method of the summary of a group of data units based on the identifier in the security parameter set, and then can flexibly select the calculation method of the summary data of the data unit based on factors such as the computing performance of the end-side device, thereby improving the applicability of the secondary summary data calculation.
[0065] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described below are part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0066] The term "and / or" in this article is merely a description of the association relationship between associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone.
[0067] In the description and claims of the embodiments of this application, the terms "first" and "second" are used to distinguish different objects, rather than to describe a specific order of objects. For example, the terms "first target object" and "second target object" are used to distinguish different objects, rather than to describe a specific order of objects.
[0068] In the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of this application should not be interpreted as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.
[0069] In the description of the embodiments of this application, unless otherwise specified, "multiple" means two or more. For example, "multiple processing units" means two or more processing units; "multiple systems" means two or more systems.
[0070] The following is an introduction to related technologies.
[0071] A bitstream is a binary data stream formed by coded image / audio frames. Both NAL unit streams and byte streams can be called bitstreams.
[0072] A network abstract layer unit (NAL unit) is a syntactic structure that includes an indication of the type of subsequent data and the number of bytes contained (located in the NAL header). The data appears in the form of a raw byte sequence payload (RBSP), and may include interspersed security bytes if necessary. For example, a NAL unit may include a security parameter set NAL unit (also called a security data set) or an authentication data NAL unit (also called authentication data).
[0073] A layer unit (LU) is a set of NAL units with the same layer identifier (layer_id) value that are associated with each other according to a specified rule and are continuous in decoding order.
[0074] An access unit (AU) is a group of NAL units that are linked to each other according to a specified rule and are sequentially transmitted in decoding order to form a compressed video bitstream (also called a bitstream). A bitstream represents the binary data stream formed by coded image / audio frames.
[0075] A data unit is the basic syntax structure of a coded bitstream. It can be a NAL unit, a layer unit, or an access unit. This data unit is also called a basic unit or a basic data unit.
[0076] layer_id is a 2-bit unsigned integer that specifies the layer identifier of the current image. The layer identifier value ranges from 0 to MAX_LAYER-1. The layer_id of the picture header NAL unit and all coded slice NAL units of a coded picture should be the same. The value of layerId is equal to the value of layer_id. The LayerId of a coded picture or layer unit is the LayerId of the coded slice NAL unit within that coded picture or layer unit.
[0077] When the nal_unit_type of a NAL unit is 5, 7, 8, 9, 10, or 15, LayerId shall be 0.
[0078] When the nal_unit_type of a NAL unit is 6 and the NAL unit includes a supplementary enhancement payload with a PayloadType of 19, 25, 26, or 127, LayerId shall be 0.
[0079] It is worth noting that MAX_LAYER is specified by the profile.
[0080] It should be noted that, from another perspective, a data unit may also include a coded image.
[0081] Coded picture: a coded representation of a frame of image.
[0082] A coded video sequence is the highest-level syntax structure of a bitstream and contains one or more consecutive access units. A coded video sequence starts with an access unit of an IDR picture (instantaneous decoding refresh picture), an access unit of a RAPI picture (random access point I picture), an access unit of an RL leading library picture (leading library picture of an RL picture), or an access unit of a display knowledge picture. The end-of-stream NAL unit or the end-of-coded video sequence NAL unit indicates the end of a coded video sequence. Each coded video sequence contains at most one IDR picture, RAPI picture, RL leading library picture, or display knowledge picture. Access units are arranged in the bitstream in bitstream order, and the bitstream order should be the same as the decoding order. The decoding order may be different from the display order.
[0083] The RBSP of the security parameter set (SEC) includes some parameters that can be used by one or more other types of NAL units. The aforementioned parameters are the configuration parameters required for signing and authenticating the compressed video bitstream. The knowledge image is encrypted or authenticated independently of the display image. The knowledge image identifier (sec_is_library_flag) in the security parameter data RBSP is used to distinguish whether it is a security parameter set for the knowledge image. The codestream (bitstream) can contain multiple security parameter sets, which are distinguished by the security parameter set ID (sec_para_set_id). Up to three security parameter sets are supported simultaneously. A security parameter set NAL unit should be present before the random access point access unit or the first knowledge image access unit of a random access segment (RAS). This unit is applied to the current RAS or knowledge image. The security parameter set provides parameters for encryption and authentication of the current RAS or knowledge image access unit. In the case of multiple security parameter sets, sec_para_set_id is used to distinguish them. If there is no security parameter set NAL unit in the random access point access unit of the RAS, the current RAS (excluding non-display knowledge image access units) is considered to be unencrypted and does not participate in authentication. If there is no security parameter set NAL unit in the first knowledge image access unit, the current knowledge image is considered to be unencrypted and does not participate in authentication. The security parameter set NAL unit should be located in the same access unit as the sequence parameter set NAL unit, and the security parameter set NAL unit should be located before the sequence parameter set NAL unit. If the access unit includes an access unit boundary NAL unit, the security parameter set NAL unit should be located after the access unit boundary NAL unit.
[0084] A library picture is a reference picture of a non-current bitstream used when decoding the current bitstream. Each frame corresponds to a sequence parameter set, and the knowledge bitstream flag in the corresponding sequence set parameter is 1. The NAL unit type of the coding slice of the knowledge picture is 12, 17, or 18, and the knowledge picture is associated with a privacy coding slice.
[0085] Output library picture: Each frame corresponds to a sequence parameter set, and the corresponding sequence set parameter has a knowledge bitstream flag of 1 and a knowledge picture mode index of 1. The coded slice NAL unit type of the display knowledge picture is 17. The display knowledge picture is a random access point picture. The display knowledge picture that serves as the RL pre-knowledge picture is not a random access point picture.
[0086] Non-output library picture: Each frame corresponds to a sequence parameter set, and the knowledge bitstream flag in the corresponding sequence set parameter is 1 and the knowledge picture mode index is 0 or 2. The coded slice NAL unit type of non-output library picture is 12 or 18.
[0087] A leading library picture of an RL picture is a non-displayed knowledge picture that precedes an associated RL picture in the codestream order, or a displayed knowledge picture that appears before an RL picture after bitstream editing. There are no access units of other pictures between the access unit containing the first knowledge picture coding slice of this knowledge picture and the access unit of the associated RL picture. The preceding RL knowledge picture is not a random access point picture.
[0088] It is worth noting that if the RL pre-knowledge image is a display knowledge image, the display knowledge image does not need to be output and can be identified by the display knowledge image display information SEI payload (library_display_flag should be '0').
[0089] A non-leading library picture of an RL picture is a non-display library picture that precedes an associated RL picture in the codestream order. There is at least one access unit of another picture between the access unit containing the first library picture coding slice of the non-display library picture and the access unit of the associated RL picture. A non-leading library picture of an RL picture is not a random access point picture.
[0090] Output picture: The decoder reconstructs the output image (RL picture, IDR picture, P picture, B picture or RAPI picture) after decoding. It is worth noting that neither display knowledge pictures nor non-display knowledge pictures fall under the definition of display pictures in this case.
[0091] A picture is a frame of a coded video sequence, whose coded data is contained in one or more access units. Its coded picture consists of a picture header NAL unit, supplemental enhancement information (if present), and all coded slice NAL units of the picture. Specifically, the coded picture of an IDR picture includes a picture header NAL unit, zero or more supplemental extended description NAL units of the IDR picture, and all coded slice NAL units of the IDR picture. The coded picture of a RAPI picture includes a picture header NAL unit, zero or more supplemental extended description NAL units of the RAPI picture, and all coded slice NAL units of the RAPI picture. The coded picture of a P picture and a B picture includes a picture header NAL unit, zero or more supplemental extended description NAL units of the P picture or B picture, and all coded slice NAL units of the NRAP picture (non random access point picture) of the P picture or B picture. The coded picture of an RL picture includes a picture header NAL unit, zero or more supplemental extended description NAL units of the RL picture, and all coded slice NAL units of the RL picture. The coded image of the knowledge image consists of an image header NAL unit and one or more knowledge image coding slice NAL units and one or more privacy image coding slice NAL units. The RL pre-knowledge image and privacy image coding slice NAL units and all coding slice NAL units in the coded image of the display knowledge image are continuous, and its access unit contains all NAL units of the coded image. The coding slices of non-RL pre-knowledge images can be interleaved with the access units of the display image as access units.
[0092] The first coded slice NAL unit of a picture shall be followed by the picture header NAL unit of the picture. For coded pictures that are IDR pictures, RAPI pictures, RL pictures or knowledge pictures, the picture header NAL shall be followed by a picture parameter set NAL unit, and the picture parameter set NAL shall be followed by a sequence parameter set NAL unit.
[0093] In particular, the bitstreams of one or more display images may be interleaved between multiple knowledge image bitstream slices of non-RL pre-knowledge images, but the interleaved display image bitstreams shall not be access units of RL images, IDR images, or RAPI images. All knowledge image bitstream slices of an RL pre-knowledge image or display knowledge image shall be continuous. Each knowledge image bitstream slice may be interleaved with the NAL unit of the privacy image coding slice (if present), but shall not be interleaved with the bitstream of the display image.
[0094] The bitstreams of all slices of a knowledge image should precede the bitstream of the first RL image that references that knowledge image. Knowledge image bitstream slices from different knowledge images cannot be interleaved. The knowledge image referenced by an RL image is the knowledge image represented by the first access unit of the knowledge image found in reverse order from the RL access unit in the bitstream.
[0095] Hash period (hash_period_in_doi_minus), an 8-bit unsigned integer, ranges from 0 to (MAX_HASH_PERIOD / NumOfLayers-1), where MAX_HASH_PERIOD is set to 256. HashPeriodInDoi is equal to hash_period_in_doi_minus1+1. Indicates the number of access units involved in signature authentication associated with a piece of authentication data. This number is less than or equal to HashPeriodInDoi.
[0096] According to the user-configured HashPeriodInDoi, set hash_period_in_doi_minus1 to HashPeriodInDoi minus 1. A HashPeriodInDoi of 1 indicates that a single access unit is independently signed, and the authentication data NAL unit carrying the signature should be located in the access unit associated with the signature or the first access unit after it. A HashPeriodInDoi greater than 1 indicates that multiple access units are jointly signed.
[0097] NumOfLayers is the number of spatial domain layers.
[0098] It should be noted that this application does not group the data units, but uses "a group of data units" to describe them for the convenience of description.
[0099] For example, a group of data units may include n data units, each of which requires authentication, where n is a positive integer. Accordingly, the authentication data may include n digest data, each of which corresponds one-to-one to the n data units. For example, "a group of data units" may also be described as "n data units."
[0100] Exemplarily, a plurality of summary data of a group of data units may constitute a summary data list; that is, the authentication data may include the summary data list.
[0101] Exemplarily, the authentication data may be Auth.
[0102] Exemplarily, the signature data may be signature.
[0103] Exemplarily, the summary data may also be referred to as authentication summary data or summary.
[0104] For example, the bitstream may be an audio compression bitstream (or audio compression codestream) or a video compression bitstream (or video compression codestream), and this application does not limit this. This application uses the signing and authentication of a video compression bitstream as an example for explanation.
[0105] As shown in Figure 1, Figure 1 is a schematic diagram of the application scenarios provided by this application. Figure 1 shows a monitoring scenario, a live broadcast scenario, and a video-on-demand scenario.
[0106] Referring to Figure 1 , in an exemplary surveillance scenario, camera 11 can sign a surveillance video bitstream, obtaining a signed surveillance video bitstream 101. Signed surveillance video bitstream 101 is then sent to laptop computer 13 via network 12. Laptop computer 13 can then authenticate signed surveillance video bitstream 101, obtain and display an authentication result 105, and play surveillance video 104.
[0107] 1 , illustratively, in a live broadcast scenario, mobile phone 14 can sign a live video bitstream to obtain a signed live video bitstream 102. Then, the signed live video bitstream 102 is sent to mobile phone 15 via network 12. Mobile phone 15 can then authenticate the signed live video bitstream 102, obtain and display an authentication result 107, and play the live video 106.
[0108] 1 , illustratively, in a video-on-demand scenario, a personal computer 16 can sign a video-on-demand bitstream to obtain a signed video-on-demand bitstream 103. The signed video-on-demand bitstream 103 is then sent to a mobile phone 17 via a network 12. The mobile phone 17 can then authenticate the signed video-on-demand bitstream 103, obtain and display an authentication result 109, and play the video-on-demand 108.
[0109] It should be understood that the present application can also be used in other audio and video encoding and decoding scenarios, such as digital content trusted scenarios, etc., and the present application does not limit this.
[0110] As shown in Figure 2, Figure 2 is a schematic diagram of the structure of the signature and authentication system provided by this application. Figure 2 illustrates the authentication and signature process in Figure 1 above.
[0111] 2 , illustratively, the authentication and signature system 200 may include a signing end 210 and an authentication end 220 .
[0112] For example, the signing end 210 may be the camera 11, mobile phone 14 and personal computer 16 in FIG1 , and the authentication end 220 may be the laptop computer 13, mobile phone 15 and mobile phone 17 in FIG1 .
[0113] It should be understood that the same terminal device can serve as both the signing end 210 and the authentication end 220, and this application does not impose any restrictions on this.
[0114] 2 , illustratively, after acquiring the video data 201 , the signing end 210 may perform video encoding 21 on the video data 201 to obtain a bitstream 202 ; and perform video signing 22 on the bitstream 202 to obtain a signed bitstream 203 .
[0115] For example, the video data 201 may be a surveillance video captured by the camera 11 in FIG. 1 , a live video recorded by the mobile phone 14 , or a video on demand produced by the personal computer 16 .
[0116] For example, the signed bitstream 203 may be the signed surveillance video bitstream 101 , the signed live video bitstream 102 , or the signed on-demand video bitstream 103 in FIG. 1 .
[0117] It should be noted that the video encoding 21 and video signing 22 operations can be performed in parallel.
[0118] In one possible implementation, the signing end 210 may include an encoder, which performs video encoding 21 and video signing 22. In another possible implementation, the signing end 210 may include an encoder and a signature module, which performs video encoding 21 and video signing 22. In another possible implementation, the signing end 210 may include a signature module, which performs video encoding 21 and video signing 22.
[0119] Afterwards, the signing end 210 may send the signed bit stream 203 to the authenticating end 220 .
[0120] Continuing to refer to Figure 2, illustratively, after the authentication end 220 receives the signed bitstream 203, it can perform video authentication 23 on the signed bitstream 203 to obtain an authentication result 205; and it can perform video decoding 24 on the bitstream 202 in the signed bitstream 203 to obtain decoded video data 204.
[0121] For example, the decoded video data 204 may be the surveillance video 104, the live video 106, or the on-demand video 108 in FIG. 1 .
[0122] For example, the authentication result 205 may be the authentication result 105, the authentication result 107, or the authentication result 109 in FIG. 1 .
[0123] It should be noted that the video authentication 23 and the video decoding 24 can be performed in parallel.
[0124] In a possible implementation, the authentication end 220 may include a decoder, and the decoder performs video decoding 24 and video authentication 23 .
[0125] In a possible implementation, the authentication end 220 may include a decoder and an authentication module, wherein the decoder performs video decoding 24 and the authentication module performs video authentication 23 .
[0126] In a possible implementation, the authentication end 220 may include an authentication module, which performs video decoding 24 and video authentication 23 .
[0127] It should be noted that when the signing end 210 performs lossless encoding, the video data and the decoded video data are the same; when the signing end 210 performs lossy encoding, there are differences between the video data and the decoded video data.
[0128] It should be noted that the encoder, decoder and authentication module can be implemented by software or hardware, and this application does not impose any restrictions on this.
[0129] The implementation of the embodiments of the present application will be described in detail below with reference to the accompanying drawings.
[0130] FIG3 is a flowchart of a bitstream signature method provided by the present application. The bitstream signature method can be applied to the signature and authentication system shown in FIG2 . For example, the bitstream signature method can be implemented by a processing device 300. In one possible example, the processing device 300 can be the signing terminal 210 shown in FIG2 . The bitstream signature method can include the following steps S310 and S320.
[0131] S310: The processing device 300 obtains a security parameter set and authentication data.
[0132] Among them, the security parameter set includes an identifier, which is used to indicate the calculation method of the summary; the authentication data includes signature data, which is obtained by signing the secondary summary data, and the secondary summary data is obtained by processing the summary data of each data unit of a group of data units in the bit stream according to the calculation method of the summary indicated by the identifier.
[0133] Exemplarily, the secondary summary data may also be referred to as a secondary summary value.
[0134] For example, when authentication needs to be supported, the number n of data units that need to be authenticated may be determined, where n is a positive integer.
[0135] 3 , illustratively, the n data units in bitstream a that require authentication are: data unit 1, data unit 2, ..., data unit n. These n data units that require authentication can be referred to as a group of data units. All subsequent references to a group of data units refer to data units that require authentication.
[0136] For example, referring to FIG3 , processing device 300 may independently calculate a digest for each data unit in a group of data units, thereby obtaining a digest for each data unit in the group of data units. The n digests may include: digest data 1, digest data 2, ..., digest data n; wherein the n digest data correspond one-to-one to the n data units; for example, digest data 1 corresponds to data unit 1, digest data 2 corresponds to data unit 2, ..., digest data n corresponds to data unit n.
[0137] It should be noted that this application does not group the data units, but uses "a group of data units" to describe them for the convenience of description.
[0138] For example, the identifier may be an authentication hash calculation mode (authentication_hash_mode), which indicates the digest calculation method. The authentication_hash_mode is configured by the user in the security parameter set as needed. The digest calculation method may also be referred to as the secondary digest calculation method.
[0139] For the above identification, two possible implementations are provided below.
[0140] In a first possible implementation, the identifier is a first value (e.g., 0), which indicates that a concatenation method is used to calculate the secondary digest. That is, the digest is calculated by concatenating the digest data of each data unit in a group of data units and calculating a secondary digest of the concatenated digest data to obtain the secondary digest data. Calculating the secondary digest may also be referred to as calculating the secondary digest.
[0141] With respect to the first possible implementation method described above, a possible embodiment is provided below. As shown in FIG4 , FIG4 is a first schematic diagram of a summary calculation of a group of data units provided by this application.
[0142] After confirming that the identifier is the first value from the security parameter set, the processing device 300 concatenates the digests of each data unit in a group of data units and then calculates a secondary digest of the group of data units to obtain secondary digest data.
[0143] In the following description, using layer units as data units as an example, processing device 300 concatenates the digest values Hpic1, Hpic2, ..., Hpicn of each layer unit in a group of layer units in bitstream order, calculates a digest of the concatenated digests (digest data), and obtains secondary digest data, i.e., performing secondary digest using the concatenation method. For example, referring to FIG4 , the digest values Hpic1, Hpic2, ..., Hpicn of each layer unit are concatenated in bitstream order.
[0144] For example, if the aforementioned set of layer units includes 50 layer units, and the summary data for each layer unit is 32 bytes, the processing device 300 must first calculate the summary 50 times to obtain the summary data for each layer unit in the set. The summary data for the 50 layer units is then concatenated to obtain concatenated summary data (32*50 bytes). A further digest is then calculated for the concatenated summary data to obtain the secondary summary data for the set of layer units. The entire process takes T1, which was measured to be 90.7901 ms.
[0145] In this application, the digest calculation process needs to be implemented using a key module. Since each call to the key module requires configuration, this operation takes a long time. Therefore, the above-mentioned digest Hg only needs to be calculated n+1 times, which reduces the number of digest calculations, thereby reducing the time and computing performance required for digest calculation, and improving the efficiency of digest calculation.
[0146] In a second possible implementation, the above-mentioned identifier is a second value (such as 1), which is used to indicate that the secondary summary is calculated using a tree-top method, that is, the summary is calculated by using the summary data of each data unit in a group of data units, and the obtained tree-top summary is used as the secondary summary data.
[0147] For example, the processing device 300 concatenates the n+1th combined summary data with the summary data of the n+2th data unit along the bit stream sequence, calculates the summary of the concatenated data, and obtains the n+2th combined summary data, until the summary data of each data unit in a group of data units is concatenated to obtain secondary summary data; the n+1th combined summary data is obtained by calculating the summary after concatenating the nth combined summary data with the summary data of the n+1th data unit, or the n+1th combined summary data is obtained by calculating the summary after concatenating the summary data of the nth data unit with the summary data of the n+1th data unit, where n is a positive integer.
[0148] The n+1th data unit and the n+2th data unit are arranged in sequence along the bit stream.
[0149] Regarding the second possible implementation method described above, a possible embodiment is provided below. As shown in FIG5 , FIG5 is a second schematic diagram of a summary calculation for a set of data units provided in this application. This summary value may also be referred to as summary data. The following description uses the data unit as a layer unit as an example.
[0150] A value of '1' indicates that a secondary digest is calculated using the tree-top approach. For the digest values Hpic1, Hpic2, ..., Hpicn of each layer unit in a group of layer units, Hpic1 and Hpic2 are concatenated in bitstream order, and the digest of the concatenated Hpic1 and Hpic2 is calculated to obtain combined digest data Hpic1,2. Hpic1,2 and Hpic3 are then concatenated, and the digest of the concatenated Hpic1,2 and Hpic3 is calculated to obtain combined digest data Hpic1,3. This process repeats until Hpic1,n-1 is concatenated with Hpicn, and the digest of the concatenated Hpic1,n-1 and Hpicn is calculated to obtain Hpic1,n. This is done until the digest values of each layer unit in the group of layer units are concatenated, resulting in a tree-top digest. For example, the layer unit digest values Hpic1, Hpic2, ..., Hpicn are secondary digested using the tree-top approach in bitstream order, as shown in Figure 5. This tree-top digest is the secondary digest data.
[0151] It is worth noting that the above n is the number of layer units included in a group of layer units, and the maximum value of n is (hash_period_in_doi_minus1+1) multiplied by the number of layer units in an access unit indicated by layer_id.
[0152] For example, if a group of layer units includes 3 layer units, and the summary data of the 3 layer units are H1, H2, and H3 in sequence along the bit stream, the tree-top summary of the group of layer units is calculated using a tree-top method, that is, the processing device 300 connects H1 and H2, calculates the summary of the connected H1 and H2, and obtains the combined summary data H1,2, and then connects the combined summary data H1,2 with H3, calculates the summary of the connected H1,2 and H3, and obtains the combined summary data H1,3. The combined summary data H1,3 is also the secondary summary data of the group of layer units.
[0153] For example, if the group of layer units described above includes 50 layer units, and the data size of the summary data for each layer unit is 32 bytes, the processing device 300 must first calculate the summary 50 times to obtain the summary data for each layer unit in the group. Then, using the top-of-tree calculation method, it calculates the summary n-1 (i.e., 49) times (each calculation uses 32*2 bytes of data) to obtain the top-of-tree summary, which is the secondary summary data for the group of layer units. The entire process takes T2, which was measured to be 120.8181 ms.
[0154] In the present application, the processing device 300 needs to calculate the digest 2n-1 times to obtain the digest H1 / n. The number of digest calculations is relatively small, which reduces the number of digest calculations, thereby reducing the time required for digest calculation and improving the efficiency of digest calculation.
[0155] For example, the above-mentioned method of splicing the abstracts may be to directly splice together the character strings corresponding to the abstracts.
[0156] It is worth noting that the above-mentioned first value of 0 and second value of 1 are merely examples and should not be construed as limiting the present application. In the present application, the first value may be 1 and the second value may be 0; or the first value may be 1 and the second value may be 2, etc. Alternatively, a third value may be included, corresponding to other digest calculation methods.
[0157] It is worth noting that the maximum number of data units included in a group of data units can be determined based on hash_period_in_doi_minus1 in the security parameter set and / or NumOfLayers in the sequence parameter set. That is, the maximum value of n in the first possible implementation and n+2 in the second possible implementation is determined based on hash_period_in_doi_minus1 and / or NumOfLayers. For example, the maximum number of access units included in a group of access units is equal to hash_period_in_doi_minus1+1. The maximum number of layer units included in a group of layer units is equal to the sum of the number of layer units in hash_period_in_doi_minus1+1 access units, such as (hash_period_in_doi_minus1+1) multiplied by the number of layer units in one access unit indicated by NumOfLayers. The maximum number of NAL units included in a group of NAL units is equal to the sum of the number of NAL units in hash_period_in_doi_minus1+1 access units.
[0158] It is worth noting that the above values of hash_period_in_doi_minus1 can all be written into the security parameter set in binary form.
[0159] In a possible implementation, the processing device 300 may perform a signature based on the secondary summary data to obtain signature data (signature).
[0160] In a possible example, the processing device 300 signs the secondary summary data using a signature algorithm and a private key to obtain signature data.
[0161] Optionally, the summary data of each data unit in a group of data units in the authentication data may form a summary list (authentication_hash) {summary data 1, summary data 2, . . . , summary data n}.
[0162] Optionally, the processing device 300 may generate authentication data (Auth) based on the signature data and the digest data of each data unit in a group of data units. In this way, the authentication data may be {digest data 1, digest data 2, ..., digest data n, signature}.
[0163] In one possible scenario, the security parameter set corresponds to authentication data.
[0164] S320: The processing device 300 outputs a bit stream.
[0165] The bit stream includes a security parameter set and authentication data.
[0166] Illustratively, after obtaining the authentication data and the security parameter set, the processing device 300 adds the authentication data and the security parameter set to the bitstream a to obtain a signed bitstream b, thereby outputting the bitstream b, which is the signed bitstream 203 in FIG. 2 .
[0167] It should be noted that the above S310 and S320 can be executed by the encoder in the signature end 210, or by the signature module in the signature end 210, or by the encoder and authentication module in the signature end 210 in collaboration (the encoder executes S320, and the authentication module executes S310). This application does not impose any restrictions on this.
[0168] This embodiment uses the data unit as a layer unit as an example to explain the bitstream signature method in detail. Figure 6 shows a second flow chart of a bitstream signature method provided by this application. The method shown in Figure 6 can be implemented by a processing device 300, which can be the signature terminal 210 in Figure 2. This bitstream signature method may include the following steps: S610-S640.
[0169] S610: The processing device 300 generates a security parameter set NAL unit and inserts it into a bit stream (compressed video bit stream).
[0170] Exemplarily, when it is necessary to support video image authentication, a security parameter set is generated.
[0171] In one possible implementation, to generate the RBSP in the security parameter set NAL unit (also referred to as the security parameter set RBSP), the scope of the security parameter set is a single random access sequence (RAS) in the bitstream, also referred to as a random access fragment, and all layer units (access units) involved in the authentication cannot cross the RAS.
[0172] Exemplarily, the security parameter set ID (sec_para_set_id), knowledge image identifier (sec_is_library_flag), authentication enable flag (authentication_enable_flag), authentication_hash_mode, hash type (hash_type), non-random access point image hash authentication flag (hash_discard_nrap_pictures_flag), hash period (hash_period_in_doi_minus1), authentication flag (authentication_idc), and authentication data identifier (authentication_data_id) in the configuration security parameter set.
[0173] sec_para_set_id is the security parameter set ID, a 2-bit unsigned integer used to distinguish different security parameter sets acting on the same RAS or knowledge image access unit, and its value range is 1 to 3.
[0174] sec_is_library_flag is a binary variable. A value of '1' indicates that this security parameter set applies to knowledge images, and a value of '0' indicates that this security parameter set applies to display images.
[0175] authentication_enable_flag is a binary variable. A binary variable. A value of '1' indicates that authentication of the current RAS or knowledge image is supported. The NAL units that can participate in the authentication include the coded slices of the display image or knowledge image in the current RAS, as well as the sequence parameter set, picture parameter set, security parameter set, extended data unit, and supplementary enhancement information transmitted in the access unit. Authentication data is transmitted through a NAL unit with nal_unit_type equal to 10. A value of '0' indicates that the current security parameter set does not support authentication of the RAS or knowledge image, and there should be no NAL unit with nal_unit_type equal to 10 for the RAS or knowledge image generated using the security parameter set.
[0176] Knowledge images only support independent signature authentication, while display images support co-signature authentication. Multiple display image access units participating in co-signature authentication must reside in the same RAS. The image type in multiple access units participating in co-signature authentication can be display images. Independent signature authentication for knowledge images uses a security parameter set independent of the display image, distinguished by the sec_is_library_flag in the security parameter set.
[0177] If an access unit contains NAL units with authentication_idc greater than 0 and nal_unit_type equal to 1-3, 5-9, 12, 14, 17, 18, or 19, the digest of the NAL units with the same authentication_idc value greater than 0 and the same layer_id value for each layer unit in the access unit is calculated in bitstream order. The digest data for NumOfLayers layer units corresponding to the authentication_idc value of the access unit is generated. The digest calculation method is specified by hash_type.
[0178] For hash_period_in_doi_minus1+1 access units, calculate the digest of each layer unit in each access unit in the order of the bit stream. The authentication data scope should not cross RAS. Then calculate the secondary digest according to the method indicated by authentication_hash_mode.
[0179] The secondary digest value is digitally signed to generate the authentication data RBSP, which is packaged into the authentication data RBSP NAL unit.
[0180] Note: If the authentication_enable_flag and encryption_enable_flag values of multiple security parameter sets in the codestream are equal to 1, that is, the current RAS or knowledge image supports both encryption and authentication, it should be encrypted first and then authenticated, that is, the data used for authentication should be the encrypted NAL unit.
[0181] hash_discard_nrap_pictures_flag is a binary variable. A value of '1' indicates that non-RANDOM ACCESS POINT pictures are not authenticated; a value of 0 indicates that non-RANDOM ACCESS POINT pictures are authenticated. If hash_discard_nrap_pictures is not in the codestream, its default value is 1.
[0182] authentication_idc, a 2-bit unsigned integer with a value range of 0 to 3. If the nal_unit_type of the NAL unit is 10, the authentication_idc value shall be equal to the security parameter set ID sec_para_set_id corresponding to the authentication data contained in the NAL unit, indicating that the authentication data NAL unit carries authentication data generated based on the security parameter set corresponding to the security parameter set ID sec_para_set_id; otherwise (the nal_unit_type of the NAL unit is not 10), it indicates whether the NAL unit is authenticated. In this case, a value of '0' indicates that the NAL unit is not authenticated, and a value other than '0' indicates that the NAL unit is authenticated using the authentication method specified by the security parameter set with sec_para_set_id equal to authentication_idc.
[0183] When the nal_unit_type of a NAL unit is 10, the NAL unit does not participate in signature authentication.
[0184] When the nal_unit_type of a NAL unit is 11, 15, or 16, authentication_idc shall be 0.
[0185] When a NAL unit has nal_unit_type 6 and contains a payload with PayloadType equal to 25 or 26, authentication_idc shall be 0.
[0186] authentication_data_id, a 2-bit unsigned integer. The value range is 0 to 1. It is the identifier of the authentication data of the signature authentication that this NAL unit participates in. It should be consistent with the authentication_data_id in the authentication data RBSP that it participates in the signature authentication. The authentication_data_id of the NAL units participating in the authentication corresponding to the same authentication data should be the same and consistent with the authentication_data_id in the authentication data. The authentication_data_id of a group of display image coding slice NAL units participating in the joint signature authentication should be different from the authentication_data_id of the previous group of display image coding slice NAL units participating in the joint signature authentication with the same authentication_idc.
[0187] When the nal_unit_type of a NAL unit is 10, this authentication_data_id should be consistent with the authentication_data_id in the authentication data RBSP of the NAL unit.
[0188] In one possible example, NAL units with nal_unit_type equal to 11 can be discarded by the decoder without affecting the decoding process of NAL units with nal_unit_type not equal to 11 and without affecting the consistency of this case (standard). When the nal_unit_type value of a coded slice NAL unit is equal to 1, 2, 4, 12 or 17, the nal_unit_type value of all other coded slice NAL units encoding the same image should be the same. If UserPermission is equal to 0, NAL units with nal_unit_type value equal to 19 can be discarded by the decoder. When the nal_unit_type value of a coded slice NAL unit is equal to 19, the RBSP data contains data of several coding units in the coded slice of the image.
[0189] When the number of coded slices of a knowledge picture is equal to 1, the nal_unit_type of the knowledge picture coded slice NAL unit should be 12 or 17. When the number of coded slices of a non-display knowledge picture is greater than 1, the nal_unit_type of the first and last knowledge picture coded slice NAL units in decoding order should be 18, and the nal_unit_type of the remaining knowledge picture coded slice NAL units should be 12.
[0190] The above nal_unit_type is 0 and is used to indicate the coded slice of an IDR picture, which is a random access point picture. The nal_unit_type is 1 and is used to indicate the coded slice of an NRAP picture, which is a P picture or a B picture. The nal_unit_type is 2 and is used to indicate the coded slice of a RAPI picture, which is a random access point picture. The nal_unit_type is 3 and is used to indicate the picture header. The picture header is a syntax structure that contains syntax elements that act on a picture. Each coded picture contains and only contains one picture header NAL unit. The nal_unit_type is 5 and is used to indicate an extended data unit. The nal_unit_type is 6 and is used to indicate supplemental enhancement information. The nal_unit_type is 7 and is used to indicate a sequence parameter set. The nal_unit_type is 8 and is used for just a picture parameter set. The nal_unit_type is 9 and is used to indicate a security parameter set. The nal_unit_type is 10 and is used to indicate authentication data. nal_unit_type is 10 to indicate the end of the stream, nal_unit_type is 12 to indicate a coded slice of a non-displayed knowledge picture, and nal_unit_type is 14 to indicate a coded slice of an RL picture. An RL picture is a P-picture or B-picture that uses only the knowledge picture as a reference picture for inter-frame prediction decoding. An RL picture is a random access point picture. nal_unit_type is 17 to indicate a coded slice of a displayed knowledge picture, nal_unit_type is 18 to indicate a coded slice that demarcates a non-displayed knowledge picture, and nal_unit_type is 19 to indicate a coded slice of a privacy picture.
[0191] In one possible example, the processing device 300 sets sec_para_set_id according to the configuration, sets the above-mentioned sec_is_library_flag to 0, authentication_enable_flag to 1 (indicating that authentication is enabled), hash_type to 0 (using the SM3 algorithm), sets the authentication_hash_mode value to 0 or 1 according to the configuration (using the connection method or the tree top method to calculate the secondary digest), and sets hash_discard_nrap_pictures_flag according to the configuration. If authentication of non-random access point images is required, it is set to 0, otherwise it is set to 1. According to the configured hash period HashPeriodInDoi, hash_period_in_doi_minus1 is set to HashPeriodInDoi minus 1; HashPeriodInDoi being 1 indicates that a single access unit is independently signed, and HashPeriodInDoi greater than 1 indicates that multiple access units are jointly signed.
[0192] Furthermore, the processing device 300 packages the security parameter set into a security parameter set NAL unit. For example, the processing device 300 sets the authentication_idc of the security parameter set NAL unit. Since the layer_id of the security parameter set NAL unit is 0, if the authentication_idc is non-zero, the authentication_idc is set to the authentication_idc of the layer unit with layer_id 0, that is, the sec_para_set_id of the security parameter set selected for authentication of the layer unit.
[0193] The processing device 300 sets the authentication_data_id of the security parameter set NAL unit to 0 or 1. It is recommended that the authentication_data_id of the NAL units participating in authentication with the same sec_para_set_id and authentication_idc as the previous group be different.
[0194] The processing device 300 adds a security parameter set NAL unit before the picture sequence parameter set NAL unit and inserts it into the bitstream.
[0195] In a possible example, the processing device 300 may compile the above fields into the security parameter set according to a preset syntax according to the syntax table shown in Table 1.
[0196] Table 1
[0197] Among them, encryption_enable_flag is the encryption enable flag, a binary variable. A value of '1' indicates that encryption of display picture coding slices, display picture sequence parameter sets, display picture parameter sets, non-display knowledge picture coding slices, display knowledge picture coding slices, knowledge picture sequence parameter sets, knowledge picture parameter sets, or extension data units is supported, that is, the RBSP in the NAL unit may be encrypted. A value of '0' indicates that encryption of RBSP in the NAL unit is not supported.
[0198] encryption_unit_mode is a 2-bit unsigned integer indicating the encryption basic unit. A value of '0' indicates encryption per NAL; a value of '1' indicates encryption per access unit, concatenating the encrypted portions of all NAL unit RBSPs in the access unit in bitstream order and restoring them to the encrypted NAL unit; a value of '2' indicates encryption per layer unit, concatenating the encrypted portions of all NAL unit RBSPs in the layer unit in bitstream order and restoring them to the encrypted NAL unit; a value of '3' indicates reserved. The IV must be reinitialized for each encryption.
[0199] encryption_level_mode is the encryption level mode, a 2-bit unsigned integer. It indicates the encryption level mode. A value of '0' indicates that when encrypting all NAL unit types, the entire RBSP data (except the last byte of the RBSP) is encrypted. A value of '1' indicates that when encrypting NAL units with nal_unit_type equal to 1, 2, 4, 12, 14, 17, 18, and 19, the first encryptionByte bytes of the RBSP are encrypted, and when encrypting other NAL unit types, the entire RBSP data (except the last byte of the RBSP) is encrypted. A value of '2' indicates that when encrypting NAL units with nal_unit_type equal to 1, 2, 4, 5, 12, 14, 17, 18, and 19, the first encryptionByte bytes of the RBSP are encrypted, and when encrypting other NAL unit types, the entire RBSP data (except the last byte of the RBSP) is encrypted. A value of '3' is reserved. Where encryptionByte = Min(EncryptionNum * EncryptionBaseByte, NumBytesInPayload - 1).
[0200] encryption_num_minus1 is the number of encryption basic byte lengths, an 8-bit unsigned integer. It indicates the number of encryption basic byte lengths. The value of EncryptionNum is equal to the value of encryption_num_minus1 plus 1.
[0201] encryption_base_byte is the encryption base byte length, a 2-bit unsigned integer. It indicates the encryption base byte length. A value of '0' indicates that the encryption base byte length is 16, a value of '1' indicates that the encryption base byte length is 64, a value of '2' indicates that the encryption base byte length is 256, and a value of '3' indicates that the encryption base byte length is 1024.
[0202] encryption_type is the encryption type, a 4-bit unsigned integer. It indicates the encryption algorithm used. For specific correspondence, see Table 2.
[0203] Table 2
[0204] vek_flag is the video encryption key flag, a binary variable. A value of '1' indicates that vek is carried, and a value of '0' indicates that vkek is not carried.
[0205] iv_flag is the initialization vector flag, a binary variable. A value of '1' indicates that the iv is carried, and a value of '0' indicates that the iv is not carried.
[0206] vek_encryption_type is the video encryption key encryption type, a 4-bit unsigned integer, indicating the encryption type of the video encryption key.
[0207] evek_length_minus1 is the length of the encrypted video encryption key, an 8-bit unsigned integer. It indicates the length of the encrypted video encryption key in bytes.
[0208] evek is the encrypted video encryption key, an n-bit unsigned integer. It represents the encrypted video encryption key and is used for encryption calculations. Its length is evek_length_minus1 plus 1 byte.
[0209] vkek_version length_minus1 is the length of the video encryption key version number, an 8-bit unsigned integer. Indicates the length of the video encryption key version number in bytes.
[0210] vkek_version is the video encryption key version number, an n-bit unsigned integer. Indicates the video encryption key version number, and its length is vkek_version_length_minus1 plus 1 byte.
[0211] iv_length_minus1 is an 8-bit unsigned integer representing the length of the initial vector, in bytes.
[0212] iv is the initialization vector, an n-bit unsigned integer. It indicates the initial vector used for block encryption and has a length of iv_length_minus1 plus 1 byte. hash_type is the hash type, a 2-bit unsigned integer. It indicates the authentication algorithm used. The specific correspondence is shown in Table 3.
[0213] Table 3
[0214] signature_type is the digital signature type, a 2-bit unsigned integer, indicating the algorithm used to digitally sign the image summary data, as shown in Table 4.
[0215] Table 4
[0216] signature_fmt is the signature data format, a 2-bit unsigned integer. It indicates the signature data format. The specific meaning of the signature_fmt value and the corresponding relationship between the signature_type syntax are shown in Table 5.
[0217] Table 5
[0218] This step generates security parameter set 2 for the knowledge image, with the sec_is_library_flag set to 1, indicating independent signature authentication for the knowledge image. The security parameter set is scoped to a single knowledge image. The knowledge image participating in the authentication cannot span multiple RASs or reside in two RASs. Each knowledge image, including both displayed and non-displayed knowledge images, must be independently signed and authenticated.
[0219] S620: The processing device 300 calculates summary data of the security parameter set corresponding to the display image participating in the signature in the RAS.
[0220] When calculating the summary of an access unit, the NAL units of the layer units that need to be authenticated in the access unit are used (including security parameter set NAL unit (if present), picture sequence parameter set NAL unit (if present), picture parameter set NAL unit (if present), picture header NAL unit, display picture layered coding slice NAL unit, extended data NAL unit (if present), supplementary enhancement information NAL unit (if present), etc.).
[0221] The summary data for the displayed image can be calculated as follows:
[0222] Step 1. The processing device 300 sets the authentication_idc in the header information of these NAL units to the sec_para_set_id in the security parameter set; (Note: when generating the bit stream, if the authentication_idc of the NAL unit with the same layer_id is not 0, it is recommended to use the same security parameter set with sec_para_set_id.).
[0223] Step 2. The processing device 300 sets the authentication_data_id of the current NAL unit. If there is a NAL unit participating in authentication with the same authentication_data_id as the previous group, the authentication_data_id should be different from the authentication_data_id of the previous group; otherwise, if the NAL unit participates in authentication together with the security parameter set NAL unit, the authentication_data_id also needs to be consistent with the authentication_data_id of the security parameter set NAL unit; otherwise, it is set to 0 or 1.
[0224] Step 3: The processing device 300 then concatenates all NAL units involved in authentication in the layer unit and calculates the digest of the layer unit.
[0225] Based on the configuration, the processing device 300 extracts HashPeriodInDoi access units participating in authentication from the compressed video bitstream output by the encoder and calculates the digests H1, H2, ..., Hn for each layer unit within each access unit in bitstream order, where n is equal to the total number of layer units participating in authentication across all access units. The authentication data should not span RASs, so the number of access units authenticated together in the last group within each RAS may be less than HashPeriodInDoi.
[0226] Calculates a secondary digest based on each digest value in the manner specified by authentication_hash_mode.
[0227] The above-mentioned group of layer units is the layer units included in the HashPeriodInDoi access units participating in the authentication taken out from the bit stream.
[0228] S630: The processing device 300 signs the summary data of a group of layer units to obtain signature data.
[0229] The summary data of the group of layer units is the secondary summary value of the group of layer units.
[0230] For details of S630 , reference may be made to the two possible examples of obtaining signature data shown in S310 above, which will not be described in detail here.
[0231] S640: The processing device 300 generates an authentication data NAL unit displaying the security parameter set corresponding to the image, and adds the NAL unit to the bitstream.
[0232] The plurality of digest data corresponding to the plurality of layer units in a group of layer units are arranged in sequence in the authentication data according to the bit stream order of the plurality of layer units.
[0233] In one possible scenario, the authentication data NAL includes signature data.
[0234] In another possible scenario, the authentication data NAL unit includes signature data and summary data of each layer unit in a group of layer units corresponding to the display image.
[0235] The following provides a possible example for generating the content of the authentication data NAL unit.
[0236] Step 1: The processing device 300 sets for_current_ras_idc to 0 and auth_is_library_flag to 0;
[0237] Step 2: The processing device 300 sets the authentication_data_id of the current authentication data. The authentication_data_id is consistent with the authentication_data_id of the NAL unit participating in the authentication.
[0238] Step 3: The processing device 300 sets authentication_hash_list_flag according to the configuration. 0 indicates that the authentication data does not contain a digest list, and 1 indicates that the authentication data does contain a digest list. When authentication_hash_list_flag is 1, authentication_hash_number_minus1 is set to the number of digests minus 1, and authentication_hash is the digest value {H1, H2, ..., Hn} of the displayed image.
[0239] Step 4: The processing device 300 writes the signature data into authentication_data and sets authentication_data_length_minus1 to the actual length of authentication_data minus 1.
[0240] The processing device 300 packages the authentication data into an authentication data NAL unit, and then inserts the authentication data NAL unit into or after the last access unit of this authentication, before the next authentication data NAL unit, and before the next random access point access unit that is not a display knowledge image. The temporal_id and layer_id of the authentication data NAL unit header are set to 0. In particular, the last authentication data in each RAS is allowed to be placed in the next RAS. In this case, the for_current_ras_idc in the authentication data is set to 0. The interval between the authentication data and the layer unit in the last access unit participating in the authentication cannot exceed HashPeriodInDoi (equal to hash_period_in_doi_minus1+1 in the security parameter set corresponding to this authentication) access units (excluding non-display knowledge image access units). The authentication_idc of the authentication data NAL unit is set to sec_para_set_id in the corresponding security parameter set, and the authentication_data_id is set to the authentication_data_id in the NAL unit header of the layer unit participating in the authentication.
[0241] The authentication data for a display picture may be located in the access unit containing the last display picture coded slice, or in the access unit containing the display picture coded slice of the next RAS. The authentication data NAL unit shall be located after all other NAL units in the access unit except the end-of-stream NAL unit and the end-of-coded video sequence NAL unit.
[0242] As a possible implementation, the authentication data RBSP definition may be as shown in Table 6.
[0243] Table 6
[0244] for_current_ras_idc is a binary variable that identifies the location of the authentication data. A value of '1' indicates that all access units corresponding to the digests in the digest list in the authentication data are within the current random access segment. A value of '0' indicates that none of the access units corresponding to the digests in the digest list in the authentication data are within the current random access segment. All access units signed together should be within the same random access segment.
[0245] auth_is_library_flag is the knowledge image authentication data flag, a binary variable. A value of '1' indicates that the authentication data is the signature data of a knowledge image; a value of '0' indicates that the authentication data is the signature data of a display image or a display knowledge image. The value of AuthIsLibraryFlag is equal to the value of auth_is_library_flag. If auth_is_library_flag is not present in the bitstream, the value of AuthIsLibraryFlag is 0.
[0246] authenticaion_library_picture_index is the authentication knowledge image index.
[0247] authentication_hash_list_flag is a binary variable that identifies the authentication digest list. A value of '1' indicates that the authentication data carries a digest list of access units used to generate the signature in the authentication data. A value of '0' indicates that the authentication data does not carry a digest list of access units used to generate the signature in the authentication data.
[0248] authentication_hash_number_minus1 is the number of authentication digests, an 8-bit unsigned integer ranging from 0 to 255. Authentication_hash_number_minus1 plus 1 indicates the number of authentication digests.
[0249] authentication_data_length_minus1 is the length of the signature data, an 8-bit unsigned integer. 1 plus 1 indicates the length of the signature data in bytes, and the value should be between 0 and 255.
[0250] authentication_data[i] is the number of signature data bytes, an 8-bit unsigned integer. The i-th byte of a signature data. The authentication data NAL unit should be located after all other types of NAL units in the access unit except the end-of-stream NAL unit and the end-of-coded video sequence NAL unit. The order of authentication data NAL units corresponding to the same security parameter set in the bitstream should be the same as the bitstream order of the access unit to which they correspond, that is, if the first authentication data NAL unit is located before the second authentication data NAL unit, then any access unit associated with the first authentication data NAL unit is located before any access unit associated with the second authentication data NAL unit.
[0251] The authentication data NAL unit of the display image should be located in or after the last access unit of this authentication, before the next authentication data NAL unit, and before the next random access point access unit that is not a display knowledge image. In particular, the last authentication data in each RAS is allowed to be placed in the next RAS. In this case, set for_current_ras_idc in the authentication data to 0. The interval between the authentication data and the layer unit in the last access unit participating in the authentication cannot exceed HashPeriodInDoi (equal to hash_period_in_doi_minus1+1 in the security parameter set corresponding to this authentication) access units (excluding non-display knowledge image access units). The authentication data of the display image can be located in the access unit where the last display image coding slice is located; it can also be located in the access unit of the display image coding slice of the next RAS.
[0252] The authentication data NAL unit of the knowledge image should be located in or after the last access unit of this authentication, before the next authentication data NAL unit, and before the next random access point access unit.
[0253] The interval between the authentication data of the display knowledge image and the display knowledge image access unit shall not exceed HashPeriodInDoi (equal to hash_period_in_doi_minus1+1 in the security parameter set corresponding to this authentication) access units. The authentication data of the display knowledge image may be located in the access unit of the last display knowledge image coding slice; it may also be located in the access unit of the display image coding slice of the next RAS.
[0254] The authentication data of the non-display knowledge image is located in the access unit where the last non-display knowledge image coding slice is located.
[0255] The authentication data RBSP is written into the authentication data NAL unit.
[0256] In a possible implementation, the above embodiment further includes that the processing device 300 outputs a bit stream including the security parameter set and the authentication data.
[0257] For example, the processing device 300 outputs a bit stream including the security parameter set and the authentication data to the authentication end 220 in FIG. 2 .
[0258] In other embodiments of the present application, the data unit may also be a NAL unit or an access unit. For the content of the bitstream signature method when the data unit is a NAL unit or an access unit, reference may be made to the description of the bitstream signature method when the data unit is a layer unit in Figure 6 above, which will not be repeated here.
[0259] In a possible embodiment, only the contents shown in FIG. 3 and FIG. 4 can obtain the following bit stream.
[0260] The bit stream includes: a set of data units, a security parameter set, and authentication data;
[0261] Among them, the security parameter set includes an identifier, which is used to indicate the calculation method of the summary; the authentication data includes signature data, which is obtained by signing the secondary summary data, and the secondary summary data is obtained by processing the summary data of each data unit of a group of data units in the bit stream according to the calculation method of the summary indicated by the identifier.
[0262] For more detailed information about a set of data units, authentication data, or security data sets, please refer to the descriptions shown in Figures 3 to 6 above, which will not be repeated here.
[0263] The bit stream in this embodiment may be the bit stream b shown in FIG. 3 .
[0264] After the above introduction of the bitstream signature method, the processing device 300 can send the bitstream obtained by the above bitstream signature method to the authentication end 220 shown in Figure 2 for processing. Based on this, the embodiment of the present application also provides two bitstream authentication methods.
[0265] FIG7 is a flowchart illustrating a bitstream authentication method provided by the present application. The bitstream authentication method can be applied to the signature and authentication system shown in FIG2 . For example, the bitstream authentication method can be implemented by a processing device 700. In one possible example, the processing device 700 can be the authentication terminal 220 shown in FIG2 . The bitstream in this embodiment can be the bitstream b in FIG3 . The bitstream authentication method can include the following steps S710-S730.
[0266] S710: The processing device 700 determines first summary data of each data unit of a group of data units in a bit stream.
[0267] Exemplarily, the processing device 700 determines each layer unit in a group of layer units in the bitstream, takes a layer unit as an example, confirms the NAL units participating in the authentication in the layer unit, splices the NAL units participating in the authentication together, calculates the summary of the spliced NAL units, and obtains the first summary data of the layer unit.
[0268] It is worth noting that, while the processing device 700 continuously receives the bitstream, it continuously calculates and caches the first summary data of the layer units. Furthermore, the processing device 700 may calculate and cache the first summary data in the order in which the layer units are received.
[0269] In one possible scenario, all access units of a group of layer units are stored in a summary list.
[0270] For example, the processing device 700 caches the first summary data in a memory of the processing device 700 .
[0271] It is worth noting that the above description uses the data unit as a layer unit as an example. In other embodiments of the present application, the data unit may also be a NAL unit or an access unit.
[0272] S720: The processing device 700 obtains authentication data from the bit stream.
[0273] The authentication data includes: signature data and second summary data of each data unit in a group of data units, the signature data is obtained by signing the secondary summary data, the secondary summary data is obtained by processing the second summary data of each data unit in a group of data units in the bit stream according to the calculation method of the summary indicated by the identifier, and the security parameter set in the bit stream includes the identifier.
[0274] For more details about the authentication data or security parameter set, please refer to the contents shown in Figures 3 to 6 above, which will not be repeated here.
[0275] S730: If the processing device 700 successfully verifies the signature data, the processing device 700 verifies the plurality of second digest data in the authentication data according to the first digest data of each data unit of a group of data units in the bit stream.
[0276] In one possible implementation, the signature data may be verified in the following manner.
[0277] The processing device 700 obtains the public key, and then determines the secondary summary data corresponding to a group of data units based on the second summary data of each data unit in the group of data units included in the authentication data, thereby verifying the signature data based on the public key, the secondary summary data and the signature algorithm.
[0278] For the description of the secondary summary data, reference may be made to the content of the secondary summary data shown in S310 in FIG. 3 , which will not be described in detail here.
[0279] For example, when the digital signature type signature_type is parsed from the codestream security parameter set RBSP, the processing device 300 can determine the signature algorithm according to the signature algorithm indicated by signature_type. signature_type is a 2-bit unsigned integer used to indicate the algorithm for digitally signing the summary data of the image.
[0280] Illustratively, the processing device 700 may determine the signature algorithm according to a pre-agreed signature algorithm.
[0281] Exemplarily, when the camera certificate identifier camera_idc is obtained from the security parameter set RBSP of the code stream, the processing device 300 may search for the public key in the authentication certificate indicated by camera_idc.
[0282] Exemplarily, the processing device 700 may parse the authentication data RBSP of the code stream to obtain the public key.
[0283] Exemplarily, the processing device 700 may obtain a public key pre-installed in the authentication terminal 220 .
[0284] In a possible scenario, the second digest data corresponding to the multiple data units in a group of data units are arranged in sequence in the authentication data according to the bit stream order of the multiple data units.
[0285] In one possible implementation, the processing device 700 verifies the plurality of second digest data in the authentication data based on the first digest data of each data unit of a group of data units in the bitstream, including:
[0286] The processing device 700 sequentially matches the first digest data with the second digests according to the arrangement order of the plurality of second digest data in the authentication data and the plurality of first digest data of a group of data units.
[0287] In one possible example, the processing device 700 matches the first summary data of multiple data units included in a group of data units with the multiple second summary data in the authentication data in sequence. If the match is successful, the data unit of the successfully matched first summary data is successfully authenticated, and the data unit is valid (usable); if the match fails, the data unit of the unmatched first summary data fails to be authenticated (unusable).
[0288] It's worth noting that the aforementioned matching also includes position matching. For example, if summary data a among the plurality of second summary data matches summary data b among the plurality of first summary data, the next summary data after summary data a among the plurality of second summary data matches the next summary data after summary data a among the plurality of first summary data. If so, the data unit corresponding to the next summary data after summary data a is valid.
[0289] In one possible implementation, processing device 700 calculates first digest data based on data units in the bitstream and stores the first digest data in a first digest list. Furthermore, processing device 700 stores second digest data obtained from the authentication data in a second digest list. Processing device 700 may match the identifier of the second digest list with a digest list locally cached by processing device 700. If it is determined that the identifier of the second digest list matches the identifier of the first digest list, the step of "verifying the plurality of second digest data in the authentication data based on the first digest data of each data unit in the group of data units in the bitstream" in S730 above is executed.
[0290] In a possible example, the above identifier may be sec_para_set_id and authentication_data_id.
[0291] In one possible scenario, processing device 700 stores the first digest data and third digest data calculated based on the data units in the bitstream in a first digest list and a third digest list, respectively. The first digest list includes the first digest data of each data unit in a group of data units, and the third digest list includes the third digest data of each data unit in the group of data units. It is worth noting that processing device 700 stores the obtained first digest list and third digest list in a memory of processing device 700, such as a memory, a hard disk, or a cache. The authentication data also includes a second digest list, which includes the second digest data of each data unit in the group of data units.
[0292] Furthermore, if the identifier of the first digest list is consistent with the identifier of the second digest list, and the identifier of the third digest list is inconsistent with the identifier of the second digest list, then the authentication of a group of data units corresponding to the third digest list fails.
[0293] It should be noted that the group of data units corresponding to the third summary list is arranged before the group of data units corresponding to the first summary list in the bit stream.
[0294] In a possible example, the above identifier may be sec_para_set_id and authentication_data_id.
[0295] FIG8 is a second flow chart of a bitstream authentication method provided by the present application. The bitstream authentication method can be applied to the signature and authentication system shown in FIG2 . For example, the bitstream authentication method can be implemented by a processing device 700. In one possible example, the processing device 700 can be the authentication terminal 220 shown in FIG2 , and the bitstream in this embodiment can be the bitstream b in FIG3 . The bitstream authentication method can include the following steps S810-S830.
[0296] S810: The processing device 700 determines first summary data of a group of data units in a bit stream.
[0297] The first summary data is the above-mentioned second-level summary data.
[0298] In one possible implementation, the processing device 700 determines third summary data for each data unit in a group of data units, and then determines first summary data corresponding to the group of data units based on the third summary data for each data unit in the group of data units. The first summary data is the second-level summary data corresponding to the group of data units.
[0299] Exemplarily, the processing device 700 concatenates the third summary data of all data units in a group of data units to obtain concatenated third summary data, and calculates a digest of the concatenated third summary data to obtain the first summary data.
[0300] For example, the processing device 700 directly concatenates the character strings corresponding to the third digest data of all data units to obtain concatenated third digest data.
[0301] Exemplarily, processing device 300 concatenates the (n+1)th combined digest data with the second digest data of the (n+2)th data unit along the bit stream sequence, calculates a digest of the concatenated data, and obtains the (n+2)th combined digest data. This continues until the digest data of each data unit in a group of data units is concatenated to obtain the secondary digest data. The (n+1)th combined digest data is calculated by concatenating the (n)th combined digest data with the second digest data of the (n+1)th data unit, where n is a positive integer.
[0302] For the content of S810 and the content of the above possible implementation methods, reference may be made to the content of calculating the secondary summary data of a group of data units in the above S310, which will not be described in detail here.
[0303] It is worth noting that as the processing device 700 continuously receives the bitstream, it continuously calculates and caches the summary data of the data units. Furthermore, the processing device 700 may calculate the summary data in the order in which the layer units were received (i.e., the bitstream order), cache the summary data sequentially, and then calculate the first summary data of the group of data units based on the summary data of each data unit in the group of data units.
[0304] The first summary data may be stored in a memory of the processing device 700 .
[0305] S820: The processing device 700 obtains authentication data from the bit stream.
[0306] The authentication data includes signature data, which is obtained by signing the secondary summary data. The secondary summary data is obtained by processing the summary data of each data unit of a group of data units in the bit stream according to the calculation method of the summary indicated by the identifier, and the security parameter set in the bit stream includes the identifier.
[0307] For more detailed information about the authentication data, security parameter set, or secondary summary data, please refer to the contents shown in FIG. 3 to FIG. 6 above, which will not be described in detail here.
[0308] S830: The processing device 700 verifies the signature data using the first digest data.
[0309] In a possible implementation, the processing device 300 verifies the signature data using the first digest data, including: the processing device obtains a public key, and then verifies the signature data according to the public key, the first digest data, and the signature algorithm.
[0310] For the details of S830, please refer to the description of verifying the signature data in the above S730, which will not be repeated here.
[0311] In one possible implementation, the processing device 700 determines from the memory an identifier of the first summary data that matches the identifier of the authentication data, and if the identifier of the first summary data matches the identifier of the authentication data, performs the above-mentioned step of verifying the signature data using the first summary data.
[0312] In one possible scenario, the processing device 700 calculates first digest data based on the first group of data units in the bitstream and fourth digest data based on the second group of data units. It is worth noting that the processing device 700 stores the obtained first digest data and fourth digest data in a memory of the processing device 700, such as a memory, a hard disk, or a cache. Both the first digest data and the fourth digest data are secondary digest data.
[0313] Furthermore, if the identifier of the first digest data is consistent with the identifier obtained by the authentication data, and the identifier of the fourth digest data is inconsistent with the identifier of the authentication data, then the authentication of the second group of data units corresponding to the fourth digest data fails.
[0314] It is worth noting that the second group of data units is arranged before the first group of data units in the bit stream.
[0315] In a possible example, the above identifier may be sec_para_set_id and authentication_data_id.
[0316] This embodiment uses the data unit as the layer unit and the identifier as the second value as an example to explain the bitstream authentication method in detail. A complete embodiment of the bitstream authentication method is provided below. The embodiment includes the following steps ①-③.
[0317] Step ①: The processing device 700 inputs a bit stream (compressed video bit stream), and then obtains a security parameter set NAL unit in the bit stream.
[0318] The processing device 700 obtains one or more security parameter set NAL units of the RAS and obtains sec_para_set_id, authentication_enable_flag, authentication_data_id, hash_type, authentication_hash_mode, hash_discard_nrap_pictures_flag, and hash_period_in_doi_minus1 from the security parameter set. If the authentication_enable_flag in the security parameter set is 0, the security parameter set does not support authentication of displayed images. If the hash_discard_nrap_pictures_flag in the security parameter set is 1, the security parameter set does not support authentication of non-random access point images.
[0319] For each security parameter set, authenticate the layer units involved in authentication according to steps 2 and 3.
[0320] Step ②: The processing device 700 obtains a display image access unit in the RAS for a security parameter set and calculates summary data of the display image.
[0321] Calculation Summary:
[0322] The processing device 700 receives NAL data of hash_period_in_doi_minus1+1 display image access units in the RAS, concatenates the NAL units of the layer units involved in authentication in the access unit, and calculates the digest of the layer unit. The last group of data involved in authentication in the RAS may be less than hash_period_in_doi_minus1+1.
[0323] The processing device 700 calculates secondary digests based on the digest values in the order of the bit stream, and stores the secondary digest values into a local cache using sec_para_set_id and authentication_data_id as identifiers.
[0324] For example, the processing device 700 generates a digest list {H1', H2', ..., Hm'} for consecutive layer units with the same authentication_data_id, identified by sec_para_set_id and authentication_data_id, in bitstream order, and stores it in the local cache, where m is equal to the total number of layer units participating in authentication in the access unit. If an unauthenticated digest list identified by authentication_data_id exists, the layer unit generating this digest list fails authentication, and the new digest list overwrites the old digest list.
[0325] Step 3: Obtain display image authentication data and complete display image authentication.
[0326] The processing device 700 calculates from the access unit where the last display image coding slice participating in the authentication is located to a maximum of hash_period_in_doi_minus1+1 access units to obtain the authentication data.
[0327] When for_current_ras_idc in the authentication data is 1, it indicates that the authentication data is the authentication data of the current RAS; when for_current_ras_idc is 0, it indicates that the authentication data is the last authentication data of the previous RAS.
[0328] In one possible scenario, when authentication_hash_list_flag in the authentication data is 0, secondary digest value authentication is used.
[0329] The processing device 700 searches for the secondary digest value in the local cache according to the sec_para_set_id and authentication_data_id in the authentication data. If the secondary digest value is found, the digital signature in the authentication data is verified using the secondary digest value. If the signature verification succeeds, the layer unit authentication that participated in generating the secondary digest value succeeds. If the verification fails, the layer unit authentication that participated in generating the secondary digest value fails.
[0330] If the processing device 700 finds and the sec_para_set_id and authentication_data_id match the sec_para_set_id and authentication_data_id of the most recently received layer unit sequence, and if there are other unauthenticated secondary digest values whose identifiers are not equal to the sec_para_set_id and authentication_data_id, the authentication data corresponding to the unauthenticated secondary digest values are lost, and authentication of the layer units corresponding to these unauthenticated secondary digest values fails. If the secondary digest value for the layer unit corresponding to the authentication_data_id is not found, the authentication data is invalid, and authentication fails.
[0331] In another possible scenario, when authentication_hash_list_flag is 1, digest list authentication is used.
[0332] 1. Parse the authentication data NAL unit to obtain the authentication_data_id and the corresponding digest list {H1, H2, ..., Hn}, and calculate the secondary digest; if authentication_hash_mode is 0, use the concatenation method to do the secondary digest calculation; if authentication_hash_mode is 1, use the tree top method to do the secondary digest calculation.
[0333] 2. Use the secondary digest value to verify the signature data parsed from the authentication data NAL unit and determine whether the digest list {H1, H2, ..., Hn} transmitted in the authentication data NAL unit passes verification. If not, the digest list data in the authentication data is untrustworthy and digest list authentication fails.
[0334] 3. Determine the layer units involved in the signature based on the parameters in the authentication data NAL unit. Search the locally cached digest list for the layer unit based on the sec_para_set_id and authentication_data_id. If found, the layer unit to be authenticated can be confirmed through the digest list. If found and the sec_para_set_id and authentication_data_id are consistent with the sec_para_set_id and authentication_data_id of the most recently received layer unit sequence, if there are other unauthenticated digest lists whose identifiers are not equal to sec_para_set_id and authentication_data_id, the authentication data corresponding to the unauthenticated digest lists are lost, and the layer units corresponding to these unauthenticated digest lists fail authentication. If the digest list for the layer unit corresponding to the sec_para_set_id and authentication_data_id is not found, the authentication data is invalid and authentication fails.
[0335] 4. Sequentially match the summary list of the layer unit {H1', H2', ..., Hm'} with the summary list in the authentication data {H1, H2, ..., Hn} to authenticate the layer unit. First, search for H1' in the summary list in the authentication data. If the search is successful, record the position of the summary list in the authentication data. The layer unit corresponding to H1' is successfully authenticated. Then, search for H2' in the summary list in the authentication data, starting from the position immediately after that position. If the search is successful, update the position of the summary list in the authentication data. The layer unit corresponding to H2' is successfully authenticated. Continue searching for H3', ..., Hm'. If the search is successful, the corresponding layer unit is successfully authenticated. If the search fails, the corresponding layer unit fails.
[0336] In other embodiments of the present application, the data unit may also be a NAL unit or an access unit. For the content of the bitstream authentication method when the data unit is a NAL unit or an access unit, reference may be made to the description of the bitstream authentication method when the data unit is a layer unit in steps ①-③ above, which will not be repeated here.
[0337] It is understood that, in order to implement the functions in the above embodiments, the processing device 300 and the processing device 700 include hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should readily appreciate that, in conjunction with the various exemplary units and method steps described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in hardware or in a manner driven by computer software depends on the specific application scenario and design constraints of the technical solution.
[0338] The bitstream signature method provided in accordance with this embodiment is described in detail above with reference to FIG. 3 to FIG. 6 . The bitstream signature apparatus provided in accordance with this embodiment will be described below with reference to FIG. 9 .
[0339] FIG9 is a schematic diagram of a bitstream signature device provided by the present application. The schematic diagram of the bitstream signature device can be used to execute the method of the aforementioned embodiment. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding method provided above, and will not be repeated here. Exemplarily, the bitstream signature device 900 includes:
[0340] Acquisition module 910 is configured to acquire a security parameter set and authentication data. The security parameter set includes an identifier that indicates a digest calculation method; the authentication data includes signature data obtained by signing secondary digest data. The secondary digest data is obtained by processing the digest data of each data unit in a group of data units in the bitstream according to the digest calculation method indicated by the identifier.
[0341] The output module 920 is configured to output a bit stream, where the bit stream includes a security parameter set and authentication data.
[0342] For more achievable aspects of the bitstream signature device 900, reference may be made to the steps performed by the processing device 300 in the aforementioned method embodiment. The bitstream signature device 900 may be used to implement the functions of the processing device 300 in the aforementioned method embodiment, thereby also achieving the beneficial effects of the aforementioned method embodiment.
[0343] The above description, in conjunction with Figure 7, details the bitstream authentication method provided by this embodiment. The following description, in conjunction with Figure 10a, details the bitstream authentication device provided by this embodiment. Figure 10a is a schematic diagram of a bitstream authentication device provided by this application. The schematic diagram of the bitstream authentication device can be used to perform the method of the aforementioned embodiment. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects of the corresponding method provided above, and will not be repeated here. Exemplarily, the bitstream authentication device 1000a includes:
[0344] The first determining module 1011 is configured to determine first summary data of each data unit in a group of data units in a bit stream.
[0345] The first acquisition module 1021 is configured to acquire authentication data from the bitstream. The authentication data includes signature data and second digest data for each data unit in a set of data units. The signature data is obtained by signing the secondary digest data. The secondary digest data is obtained by processing the second digest data for each data unit in the set of data units in the bitstream according to the digest calculation method indicated by the identifier. The security parameter set in the bitstream includes the identifier.
[0346] The first verification module 1031 is configured to verify the plurality of second summary data in the authentication data according to the first summary data of each data unit of a group of data units in the bit stream if the signature data is successfully verified.
[0347] For more achievable aspects of the bitstream authentication apparatus 1000a, reference may be made to the steps performed by the processing device 700 in the aforementioned method embodiment. The bitstream authentication apparatus 1000a may be used to implement the functions of the processing device 700 in the aforementioned method embodiment, thereby also achieving the beneficial effects of the aforementioned method embodiment.
[0348] The above description, in conjunction with Figure 8, details the bitstream authentication method provided according to this embodiment. The following description, in conjunction with Figure 10b, details the bitstream authentication device provided according to this embodiment. Figure 10b is a second schematic diagram of the bitstream authentication device provided by this application. The schematic diagram of the bitstream authentication device can be used to perform the method of the aforementioned embodiment. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding method provided above, and will not be repeated here. Exemplarily, the bitstream authentication device 1000b includes:
[0349] The second determining module 1012 is configured to determine first summary data of a group of data units in the bit stream.
[0350] The second acquisition module 1022 is configured to acquire authentication data from the bitstream. The authentication data includes signature data, which is obtained by signing secondary summary data. The secondary summary data is obtained by processing the second summary data of each data unit in a group of data units in the bitstream according to the digest calculation method indicated by the identifier. The security parameter set in the bitstream includes the identifier.
[0351] The second verification module 1032 is configured to verify the signature data using the first digest data.
[0352] For more achievable aspects of the bitstream authentication apparatus 1000b, reference may be made to the steps performed by the processing device 700 in the aforementioned method embodiment. The bitstream authentication apparatus 1000b may be used to implement the functions of the processing device 700 in the aforementioned method embodiment, thereby also achieving the beneficial effects of the aforementioned method embodiment.
[0353] It can be understood that the device shown in Figure 10a or Figure 10b is only an example provided in this embodiment. Depending on the different bitstream signature or authentication processes, the device may include more or fewer units, and this application is not limited to this.
[0354] When the device shown in FIG. 10a or FIG. 10b is implemented by hardware, the hardware may be implemented by a processor or a chip system. The chip system includes one or more chips, each of which includes a processor and a power supply circuit. The power supply circuit is used to power the processor, and the processor is used to implement the method of any possible implementation method in the above embodiments through a logic circuit or executing code instructions. The beneficial effects can be found in the description of any aspect of the above embodiments and will not be repeated here.
[0355] It is understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0356] A computing device is also provided in an embodiment of the present application. The bitstream signature device 900 shown in Figure 9, the bitstream authentication device 1000a shown in Figure 10a, or the bitstream authentication device 1000b shown in Figure 10b can be implemented by a computing device, as shown in Figure 11, which is a structural diagram of the computing device provided in this application. The computing device 1100 includes: a memory 1110 and at least one processor 1120. The processor 1120 can implement the bitstream signature method or bitstream authentication method provided in the above embodiment, and the memory 1110 is used to store software instructions corresponding to the above bitstream signature method or bitstream authentication method. For example, the computing device can be the camera 11 or the mobile phone 15 in Figure 1. The computing device 1100 can be the above-mentioned processing device 300 or the processing device 700.
[0357] As an optional implementation, in hardware implementation, the computing device 1100 may refer to a chip or chip system encapsulated with one or more processors 1120. For example, when the computing device 1100 is used to implement the method steps in the above embodiment, the processor 1120 included in the computing device 1100 executes the steps of the processing device 300 or the processing device 700 in the above method and its possible sub-steps. In an optional scenario, the computing device 1100 may also include a communication interface 1130, which can be used to send and receive data. For example, the communication interface 1130 is used to receive a bit stream, etc.; the communication interface 1130 can be implemented by an interface circuit included in the computing device 1100. Therefore, in some examples, the communication interface 1130 may also be referred to as a transceiver of the computing device. In this embodiment, the communication interface 1130 supports wired connection using a unified multimedia interconnect interface.
[0358] In an embodiment of the present application, the communication interface 1130, the processor 1120, and the memory 1110 may be connected via a bus 1140, which may be divided into an address bus, a data bus, a control bus, etc. The bus 1140 may be a peripheral component interconnect express (PCIe) bus, an extended industry standard architecture (EISA) bus, a unified bus (Ubus or UB), a compute express link (CXL), a cache coherent interconnect for accelerators (CCIX), or other types of buses.
[0359] Processor 1120 may include a CPU, a graphics processing unit (GPU), an embedded neural-network processing unit (NPU), a microprocessor (MP), a digital signal processor (DSP), an ASIC, an FPGA or other programmable logic device, a transistor logic device, a hardware component or any combination thereof.
[0360] The memory 1110 may include a volatile memory, such as a random access memory (RAM). The memory 1110 may also include a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD), or a solid state drive (SSD).
[0361] It is worth noting that the computing device 1100 can also perform the functions of the bitstream signature device 900 shown in FIG9 , the bitstream authentication device 1000a shown in FIG10a , or the bitstream authentication device 1000b shown in FIG10b , which are not described in detail here. All relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module and are not described in detail here.
[0362] An embodiment of the present application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that can be stored by a computing device or a data storage device such as a data center that contains one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a digital video disc (DVD)), or a semiconductor medium (e.g., a solid-state drive). The computer-readable storage medium stores instructions that instruct the computing device to execute a bitstream signature method or a bitstream authentication method. The computer-readable storage medium can also store the bitstreams mentioned above, such as the bitstreams obtained by the methods shown in Figures 3 to 6.
[0363] Embodiments of the present application also provide a computer program product comprising instructions. The computer program product may be software or a program product comprising instructions that can be run on a computing device or stored in any available medium. When the computer program product is run on at least one computing device, the at least one computing device is caused to perform a bitstream signature method or a bitstream authentication method.
[0364] In addition, an embodiment of the present application also provides a device, which can specifically be a chip, component or module, and the device may include a connected processor and memory; wherein the memory is used to store computer-executable instructions, and when the device is running, the processor can execute the computer-executable instructions stored in the memory to enable the chip to execute the methods in the above-mentioned method embodiments.
[0365] Among them, the computing device, computer-readable storage medium, computer program product or chip provided in this embodiment are all used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding methods provided above, and will not be repeated here.
[0366] Through the description of the above implementation methods, technical personnel in the relevant field can understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0367] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0368] Units described as separate components may or may not be physically separate, and components shown as units may be one physical unit or multiple physical units, that is, they may be located in one place or distributed in multiple places. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0369] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0370] Any content of each embodiment of this application, as well as any content of the same embodiment, can be freely combined. Any combination of the above content is within the scope of this application.
[0371] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a device (which can be a single-chip microcomputer, chip, etc.) or a processor to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a ROM, a RAM, a magnetic disk, or an optical disk.
[0372] The steps of the method or algorithm described in conjunction with the disclosure of the embodiments of the present application can be implemented in a hardware manner, or can be implemented by a processor executing software instructions. The software instructions can be composed of corresponding software modules, and the software modules can be stored in RAM, flash memory, ROM, erasable programmable read-only memory (Erasable Programmable ROM, EPROM), electrically erasable programmable read-only memory (Electrically EPROM, EEPROM), registers, hard disks, mobile hard disks, read-only compact discs (CD-ROMs) or any other form of storage medium well known in the art. An exemplary storage medium is coupled to a processor so that the processor can read information from the storage medium and can write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an ASIC.
[0373] Those skilled in the art will appreciate that in one or more of the above examples, the functions described in the embodiments of the present application can be implemented using hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. Computer-readable media include computer-readable storage media and communication media, wherein communication media include any media that facilitates the transmission of computer programs from one place to another. The storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0374] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms without departing from the purpose of this application and the scope of protection of the claims, all of which are within the protection of this application.
Claims
1. A bitstream signature method, characterized in that, The method includes: Obtaining a security parameter set and authentication data; Wherein, the security parameter set includes an identifier, and the identifier is used to indicate the calculation method of the digest; the authentication data includes the signature data, and the signature data is obtained by signing the secondary digest data, and the secondary digest data is obtained by processing the digest data of each data unit in a set of data units in the bitstream according to the calculation method of the digest indicated by the identifier; Outputting a bitstream, where the bitstream includes the security parameter set and the authentication data.
2. The method according to claim 1, characterized in that, The identifier is a first value, and the first value is used to indicate that the calculation method of the digest is to concatenate the digest data of each data unit in the set of data units, and calculate the secondary digest of the concatenated digest data to obtain the secondary digest data.
3. The method according to claim 1, wherein The identifier is a second value, and the second value is used to indicate that the calculation method of the digest is to concatenate the (n + 1)-th combined digest data with the digest data of the (n + 2)-th data unit in sequence along the bitstream, and calculate the digest of the concatenated data to obtain the (n + 2)-th combined digest data, until the digest data of each data unit in a set of data units participates in the concatenation to obtain the secondary digest data; the (n + 1)-th combined digest data is obtained by calculating the digest after concatenating the n-th combined digest data with the digest data of the (n + 1)-th data unit, and n is a positive integer.
4. The method according to any one of claims 1 to 3, characterized in that, The data unit is a Network Abstraction Layer (NAL) unit.
5. The method according to any one of claims 1 to 3, characterized in that The data unit is a layer unit, and the layer unit includes Network Abstraction Layer (NAL) units with the same layering identifier.
6. The method according to any one of claims 1 to 3, characterized in that, The data unit is an access unit.
7. The method according to any one of claims 1 to 6, characterized in that, The authentication data further includes the digest data of each data unit in a set of data units.
8. The method according to any one of claims 1 to 7, characterized in that The obtaining of the security parameter set and the authentication data includes: Generating the security parameter set and the authentication data.
9. The method according to any one of claims 1 to 8, characterized in that Before outputting the bitstream, the method further includes: Adding the authentication data to the bitstream.
10. The method according to any one of claims 1 to 9, characterized in that, The security parameter set corresponds to the authentication data.
11. A bitstream, characterized in that, The bitstream includes: A set of data units, a security parameter set, and authentication data; Wherein, the security parameter set includes an identifier, and the identifier is used to indicate the calculation method of the digest; the authentication data includes signature data, and the signature data is obtained by signing the secondary digest data, and the secondary digest data is obtained by processing the digest data of each data unit in a set of data units in the bitstream according to the calculation method of the digest indicated by the identifier.
12. The bitstream according to claim 11, wherein, The identifier is a first value, and the first value is used to indicate that the calculation method of the digest is to concatenate the digest data of each data unit in the set of data units, and calculate the secondary digest of the concatenated digest data to obtain the secondary digest data.
13. The bitstream according to claim 11, wherein, The identifier is a second value, and the second value is used to indicate that the calculation method of the digest is to concatenate the (n + 1)-th combined digest data and the digest data of the (n + 2)-th data unit in the bitstream order, calculate the digest of the concatenated data to obtain the (n + 2)-th combined digest data, until the digest data of each data unit in a group of data units participates in the concatenation to obtain the secondary digest data; the (n + 1)-th combined digest data is obtained by calculating the digest after concatenating the n-th combined digest data and the digest data of the (n + 1)-th data unit, where n is a positive integer.
14. The bitstream according to any one of claims 11 to 13, characterized in that, The data unit is a network abstraction layer (NAL) unit.
15. The bitstream according to any one of claims 11 to 13, characterized in that, The data unit is a layer unit, and the layer unit includes network abstraction layer (NAL) units with the same layering identifier.
16. The bitstream according to any one of claims 11 to 13, characterized in that The data unit is an access unit.
17. The bitstream according to any one of claims 11 to 16, characterized in that, The authentication data further includes the digest data of each data unit in a group of data units.
18. A bitstream authentication method, characterized in that, The method includes: Determining the first digest data of each data unit in a group of data units in the bitstream; Obtaining authentication data from the bitstream; the authentication data includes: signature data and the second digest data of each data unit in the group of data units, the signature data is obtained by signing the secondary digest data, the secondary digest data is obtained by processing the second digest data of each data unit in a group of data units in the bitstream according to the digest calculation method indicated by the identifier, and the security parameter set in the bitstream includes the identifier; If the verification of the signature data is successful, then verify the multiple second digest data in the authentication data according to the first digest data of each data unit in the group of data units in the bitstream.
19. The method according to claim 18, wherein The identifier is a first value, and the first value is used to indicate that the calculation method of the digest is to concatenate the second digest data of each data unit in the group of data units and calculate the secondary digest of the concatenated second digest data to obtain the secondary digest data.
20. The method according to claim 18, wherein The identifier is a second value, and the second value is used to indicate that the calculation method of the digest is to concatenate the (n + 1)-th combined digest data and the second digest data of the (n + 2)-th data unit in the bitstream order, calculate the digest of the concatenated data to obtain the (n + 2)-th combined digest data, until the second digest data of each data unit in a group of data units participates in the concatenation to obtain the secondary digest data; the (n + 1)-th combined digest data is obtained by calculating the digest after concatenating the n-th combined digest data and the second digest data of the (n + 1)-th data unit, where n is a positive integer.
21. The method according to any one of claims 18 to 20, characterized in that, The data unit is a network abstraction layer (NAL) unit.
22. The method according to any one of claims 18 to 20, characterized in that, The data unit is a layer unit, and the layer unit includes network abstraction layer (NAL) units with the same layering identifier.
23. The method according to any one of claims 18 to 20, characterized in that The data unit is an access unit.
24. A bitstream authentication method, characterized in that, The method includes: Determining the first digest data of each data unit in a group of data units in the bitstream; Obtaining authentication data from the bitstream, the authentication data includes signature data, the signature data is obtained by signing the secondary digest data, the secondary digest data is obtained by processing the second digest data of each data unit in a group of data units in the bitstream according to the digest calculation method indicated by the identifier, and the security parameter set in the bitstream includes the identifier; Verify the signature data by using the first digest data of the bitstream.
25. The method according to claim 24, wherein The determination of the first digest data of a set of data units of the bitstream includes: Determine the third digest data of each data unit in the set of data units of the bitstream; Process the third digest data of each data unit in the set of data units according to the digest calculation method indicated by the identifier to obtain the first digest data of the set of data units.
26. The method according to claim 24 or 25, characterized in that, The identifier is a first value, and the first value is used to indicate that the digest calculation method is to concatenate the digest data of each data unit in the set of data units, and calculate the second-level digest of the concatenated digest data to obtain the second-level digest data.
27. The method according to claim 24 or 25, characterized in that, The identifier is a second value, and the second value is used to indicate that the digest calculation method is to concatenate the (n + 1)-th combined digest data with the second digest data of the (n + 2)-th data unit in the bitstream order, calculate the digest of the concatenated data to obtain the (n + 2)-th combined digest data, until the digest data of each data unit in the set of data units participates in the concatenation to obtain the second-level digest data; the (n + 1)-th combined digest data is obtained by calculating the digest after concatenating the n-th combined digest data with the second digest data of the (n + 1)-th data unit, where n is a positive integer.
28. The method according to any one of claims 24 to 27, characterized in that, The data unit is a network abstraction layer (NAL) unit.
29. The method according to any one of claims 24 to 27, characterized in that The data unit is a layer unit, and the layer unit includes network abstraction layer (NAL) units with the same layering identifier.
30. The method according to any one of claims 24 to 27, characterized in that, The data unit is an access unit.
31. A bitstream signature device, characterized in that, The apparatus includes: An acquisition device, configured to acquire a security parameter set and authentication data; wherein, the security parameter set includes an identifier, and the identifier is used to indicate the digest calculation method; the authentication data includes the signature data, and the signature data is obtained by signing the second-level digest data, and the second-level digest data is obtained by processing the digest data of each data unit in a set of data units in the bitstream according to the digest calculation method indicated by the identifier; An output device, configured to output a bitstream, and the bitstream includes the security parameter set and the authentication data.
32. The device according to claim 31, characterized in that, The identifier is a first value, and the first value is used to indicate that the digest calculation method is to concatenate the digest data of each data unit in the set of data units, and calculate the second-level digest of the concatenated digest data to obtain the second-level digest data.
33. The device according to claim 31, characterized in that The identifier is a second value, and the second value is used to indicate that the digest calculation method is to concatenate the (n + 1)-th combined digest data with the digest data of the (n + 2)-th data unit in the bitstream order, calculate the digest of the concatenated data to obtain the (n + 2)-th combined digest data, until the digest data of each data unit in the set of data units participates in the concatenation to obtain the second-level digest data; the (n + 1)-th combined digest data is obtained by calculating the digest after concatenating the n-th combined digest data with the digest data of the (n + 1)-th data unit, where n is a positive integer.
34. The device according to any one of claims 31 to 33, characterized in that The data unit is a network abstraction layer (NAL) unit.
35. The device according to any one of claims 31 to 33, characterized in that, The data unit is a layer unit, and the layer unit includes network abstraction layer (NAL) units with the same layering identifier.
36. The device according to any one of claims 31 to 33, characterized in that, The data unit is an access unit.
37. The device according to any one of claims 31 to 36, characterized in that, The authentication data further includes the digest data of each data unit in a set of data units.
38. The device according to any one of claims 31 to 37, characterized in that, The obtaining module is specifically configured to generate the set of security parameters and the authentication data.
39. The device according to any one of claims 31 to 38, characterized in that, The device further includes an adding module, and the adding module is configured to add the authentication data to the bitstream.
40. The device according to any one of claims 31 to 39, characterized in that, The set of security parameters corresponds to the authentication data.
41. A bitstream authentication device, characterized in that, The device includes: A first determination module, configured to determine the first digest data of each data unit in a set of data units in the bitstream; A first obtaining module, configured to obtain authentication data from the bitstream; the authentication data includes: signature data and the second digest data of each data unit in the set of data units, the signature data is obtained by signing the secondary digest data, the secondary digest data is obtained by processing the second digest data of each data unit in the set of data units in the bitstream according to the digest calculation method indicated by the identifier, and the set of security parameters in the bitstream includes the identifier; A first verification module, configured to, if the verification of the signature data is successful, verify the multiple second digest data in the authentication data according to the first digest data of each data unit in a set of data units in the bitstream.
42. The apparatus according to claim 41, wherein The identifier is a first value, and the first value is used to indicate that the digest calculation method is to concatenate the second digest data of each data unit in the set of data units, and calculate the secondary digest of the concatenated second digest data to obtain the secondary digest data.
43. The device according to claim 41, characterized in that, The identifier is a second value, and the second value is used to indicate that the digest calculation method is to concatenate the (n + 1)-th combined digest data with the digest data of the (n + 2)-th data unit in sequence along the bitstream, calculate the digest of the concatenated data to obtain the (n + 2)-th combined digest data, until the digest data of each data unit in the set of data units participates in the concatenation to obtain the secondary digest data; the (n + 1)-th combined digest data is obtained by calculating the digest after concatenating the n-th combined digest data with the digest data of the (n + 1)-th data unit, and n is a positive integer.
44. The device according to any one of claims 41 to 43, characterized in that, The data unit is a network abstraction layer (NAL) unit.
45. The device according to any one of claims 41 to 43, characterized in that, The data unit is a layer unit, and the layer unit includes network abstraction layer (NAL) units with the same layering identifier.
46. The device according to any one of claims 41 to 43, characterized in that, The data unit is an access unit.
47. A bitstream authentication device, characterized in that, The device includes: A second determination module, configured to determine the first digest data of a set of data units in the bitstream; A second obtaining module, configured to obtain authentication data from the bitstream, the authentication data includes signature data, the signature data is obtained by signing the secondary digest data, the secondary digest data is obtained by processing the second digest data of each data unit in the set of data units in the bitstream according to the digest calculation method indicated by the identifier, and the set of security parameters in the bitstream includes the identifier; A second verification module, configured to verify the signature data by using the first digest data.
48. The device according to claim 47, characterized in that, The determination module is specifically configured to determine the third digest data of each data unit in a set of data units of the bitstream, and then process the third digest data of each data unit in the set of data units according to the digest calculation method indicated by the identifier to obtain the first digest data of the set of data units.
49. The device according to claim 47 or 48, characterized in that, The identifier is a first value, and the second value is used to indicate that the calculation method of the digest is to concatenate the (n + 1)-th combined digest data and the second digest data of the (n + 2)-th data unit in the bitstream order, calculate the digest of the concatenated data to obtain the (n + 2)-th combined digest data, until the digest data of each data unit in a group of data units participates in the concatenation to obtain the secondary digest data; the (n + 1)-th combined digest data is obtained by calculating the digest after concatenating the n-th combined digest data and the second digest data of the (n + 1)-th data unit, where n is a positive integer.
50. The device according to claim 47 or 48, characterized in that, The identifier is a second value, and the second value is used to indicate that the calculation method of the digest is to use the top-level digest calculated based on the digest data of each data unit in the group of data units as the secondary digest data.
51. The device according to any one of claims 47 to 50, characterized in that, The data unit is a network abstraction layer (NAL) unit.
52. The device according to any one of claims 47 to 50, characterized in that, The data unit is a layer unit, and the layer unit includes network abstraction layer (NAL) units with the same layering identifier.
53. The device according to any one of claims 47 to 50, characterized in that, The data unit is an access unit.
54. A computing device, characterized in that, Comprising: A memory and a processor, the memory is used to store computer instructions; when the processor executes the computer instructions, it implements the method described in any one of claims 1 to 10, or implements the method described in any one of claims 18 to 30.
55. A non-transitory computer-readable storage medium, characterized in that, The computer program or instructions are stored in the storage medium, and when the computer program or instructions are executed by a processing device, it implements the method described in any one of claims 1 to 10; and / or when the computer program or instructions are executed by a processing device, it implements the method described in any one of claims 18 to 30.
56. A computer program product, characterized in that, The computer program product includes computer instructions, and when the computer instructions are executed by a computer or a processor, it causes the steps of the method described in any one of claims 1 to 10 to be executed, or the steps of the method described in any one of claims 18 to 30 to be executed.
57. A non-transitory computer-readable storage medium, characterized in that, The computer-readable storage medium stores the bitstream described in any one of claims 11 to 17.
Citation Information
Patent Citations
Video distribution method and device, electronic equipment and storage medium
CN115695942A
Stationary data processing
CN116249977A
Distributed Validation of Digitally Signed Electronic Documents
US20140040611A1