Encryption method, decryption method and apparatus

By independently generating security parameter sets from the knowledge image and the displayed image, the complexity of security parameter sets in the prior art is solved, and an independent encryption and decryption process is realized, reducing the complexity of security parameter sets.

WO2025156660A1PCT designated stage Publication Date: 2025-07-31HUAWEI TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/118910
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-05
Filing Date
2024-09-13
Publication Date
2025-07-31

AI Technical Summary

Technical Problem

The existing audio and video content encryption and decryption technology increases the complexity of the security parameter set when encrypting the displayed image and the knowledge image in a unified manner, and cannot meet the constraints of the knowledge image and random access fragments using the same security parameter set.

Method used

The knowledge image and display image are encrypted and decrypted using an independent security parameter set, and the knowledge image identification and security parameter set identification are generated, and the network abstraction layer NAL units are encrypted, and the encrypted NAL units are generated and the compressed video bit stream is output.

Benefits of technology

It reduces the complexity of the security parameter set, solves the contradiction that the security parameter set cannot meet the same constraints after knowledge image editing, and realizes an independent encryption and decryption process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024118910_31072025_PF_FP_ABST
    Figure CN2024118910_31072025_PF_FP_ABST
Patent Text Reader

Abstract

Provided are an encryption method, a decryption method, and an apparatus. The encryption method comprises: generating a security parameter set comprising a library picture identifier and a security parameter set identifier, the library picture identifier being used to indicate that the security parameter set is to act on an output picture or a library picture, and the security parameter set identifier being used to distinguish different security parameter sets acting on a same RAS or library picture AU; encrypting an NAL unit to be encrypted corresponding to the security parameter set, an NAL unit header of the NAL unit once it has been encrypted comprising an encryption flag used to indicate that the NAL unit has been encrypted with a specified encryption method in the security parameter set corresponding to the security parameter set identifier; and outputting a compressed video bitstream comprising the encrypted NAL unit and the security parameter set. Thus, a security parameter set is independently generated for each of a library picture and a output picture for encryption and decryption, which solves the contradiction that a security parameter set for the library picture cannot meet the constraint of using a same security parameter set for the library picture and a random access segment where the library picture is located.
Need to check novelty before this filing date? Find Prior Art

Description

Encryption method, decryption method and device

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on January 24, 2024, with application number 202410107250.9 and application name “Encryption method, decryption method and device”, and the Chinese patent application filed with the State Intellectual Property Office on February 5, 2024, with application number 202410166342.4 and application name “Encryption method, decryption method and device”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The embodiments of the present application relate to the field of media, and in particular to an encryption method, a decryption method, and a device. Background Art

[0003] Many audio and video encoding and decoding scenarios (for example, surveillance, live broadcast, on-demand, etc.) have certain requirements for the authenticity and integrity of audio and video content. Therefore, in order to ensure the security of audio and video content during transmission and prevent the audio and video content from being tampered with during transmission, the audio and video content needs to be encrypted.

[0004] However, the current technology for encrypting and decrypting audio and video content has some defects: for example, in the current standard, unified encryption of display images (output pictures) and knowledge images (library pictures) requires ensuring that the knowledge image and the random access segment (RAS) where the knowledge image is located use the same security parameter set constraints, which increases the complexity of the security parameter set.

[0005] Summary of the Invention

[0006] In view of this, the present application provides an encryption method, a decryption method and an apparatus, which can independently encrypt and decrypt knowledge images and display images, thereby reducing the complexity of the security parameter set.

[0007] In a first aspect, an embodiment of the present application provides an encryption method, which includes: first, generating a security parameter set, the security parameter set including a knowledge image identifier and a security parameter set identifier, the knowledge image identifier being used to indicate that the security parameter set acts on a display image or a knowledge image, and the security parameter set identifier being used to distinguish different security parameter sets acting on the same random access segment or knowledge image access unit; next, encrypting the network abstraction layer NAL unit to be encrypted corresponding to the security parameter set using the encryption method specified by the security parameter set; then, obtaining the encrypted NAL unit; the encrypted NAL unit including a NAL unit header, the NAL unit header including an encryption flag, the encryption flag being a security parameter set identifier, used to indicate that the encrypted NAL unit is encrypted using the encryption method specified in the security parameter set corresponding to the security parameter set identifier; finally, outputting a compressed video bit stream; the compressed video bit stream including the encrypted NAL unit and the security parameter set.

[0008] The encryption method provided by the present application encrypts the data units of the knowledge image and the display image separately during the encryption process of the compressed video bitstream, and independently generates a security parameter set acting on the knowledge image and a security parameter set acting on the display image, and the security parameter set acting on the knowledge image and the security parameter set acting on the display image are independent of each other. In this way, the compressed video bitstream carries a security parameter set acting on the knowledge image, so that the decryption end can separately decrypt the encrypted data unit of the knowledge image according to the security parameter set of the knowledge image. Compared with the unified encryption and decryption for the display image and the knowledge image, the data unit of the display image and the data unit of the knowledge image use different independent security parameter sets respectively, and there is no need to ensure that the knowledge image and the random access segment where the knowledge image is located adopt the same security parameter set constraint, thereby reducing the complexity of the security parameter set. At the same time, during the knowledge image editing process, if the knowledge image and the random access segment in which it is located are constrained to use the same security parameter set, the random access segment in which the edited knowledge image is located may use a different security parameter set. The above-mentioned encryption method provided in this application solves the contradiction that the security parameter set of the edited knowledge image cannot meet the constraint that the knowledge image and the random access segment in which it is located use the same security parameter set by encrypting and decrypting the data units of the knowledge image separately, thereby reducing the complexity of the security parameter set.

[0009] In one possible implementation, a first value for the knowledge image identifier indicates that the security parameter set applies to the knowledge image, while a second value for the knowledge image identifier indicates that the security parameter set applies to the display image. In this way, for data units of the knowledge image and data units of the display image, the encryption end can use the knowledge image identifier to identify whether one or more security parameter sets in the compressed video bitstream apply to the knowledge image data unit or the display image data unit, respectively. This allows independent encryption and decryption of the knowledge image data unit using independent security parameter sets.

[0010] In one possible implementation, the security parameter set includes an encryption basic unit, which is used to indicate that encryption is performed in units of data units including network abstraction layer (NAL) units, access units (AU) or layer units (LU).

[0011] In a possible implementation, after the security parameter set is generated, the security parameter set is packaged into a security parameter set NAL unit; and the security parameter set NAL unit is added before the picture sequence parameter set NAL unit.

[0012] In one possible implementation, the step of obtaining the encrypted NAL unit may include: restoring the encrypted data to encrypted raw byte sequence payload (RBSP) data; splicing the NAL unit header and the encrypted RBSP data; setting the encryption flag of the NAL unit header to the value of the security parameter set identifier in the security parameter set corresponding to the encrypted NAL unit to obtain the encrypted NAL unit.

[0013] In a possible implementation, after the encrypted data is restored to the encrypted original byte sequence payload RBSP data, an anti-counterfeiting start code is added to the encrypted RBSP data.

[0014] In one possible implementation, the knowledge image is a coded image in which each frame corresponds to a sequence parameter set and the knowledge bit stream flag in the corresponding sequence set parameter is 1. The display image is a reference knowledge library (RL) image, an instantaneous decoding refresh (IDR) image, a P image, a B image, or a random access point I frame (RAPI) image that is output by the decoder after decoding to reconstruct the image.

[0015] In the second aspect, an embodiment of the present application provides a decryption method, which includes: first, inputting a compressed video bit stream; then, obtaining a security parameter set in the compressed video bit stream; the security parameter set includes a knowledge image identifier and a security parameter set identifier, the knowledge image identifier is used to indicate that the security parameter set acts on a display image or a knowledge image, and the security parameter set identifier is used to distinguish different security parameter sets acting on the same random access segment or knowledge image access unit; then, using the encryption method specified by the security parameter set, decrypting the encrypted NAL unit corresponding to the security parameter set; the encryption flag of the encrypted NAL unit is the security parameter set identifier; finally, obtaining the decrypted RBSP data.

[0016] In a possible implementation, when the knowledge image identifier is a first value, it indicates that the security parameter set acts on the knowledge image; and when the knowledge image identifier is a second value, it indicates that the security parameter set acts on the display image.

[0017] In a possible implementation, the security parameter set includes an encryption basic unit, where the encryption basic unit is used to indicate that encryption is performed in units of data units including NAL units, AUs, or layer units LUs.

[0018] In a possible implementation, after the decrypted RBSP data is obtained, an anti-counterfeiting start code is added to the decrypted RBSP data.

[0019] In a possible implementation, after obtaining the decrypted RBSP data, the NAL unit header and the decrypted RBSP data are concatenated to obtain a decrypted NAL unit.

[0020] In one possible implementation, the knowledge image is a coded image in which each frame corresponds to a sequence parameter set and the knowledge bit stream flag in the corresponding sequence set parameter is 1. The display image is a reference knowledge image, an instant decoding refresh image, a P image, a B image, or a random access point I frame image output by the decoder after decoding.

[0021] In a third aspect, the present application provides a compressed video bit stream, which includes an encrypted data unit and a security parameter set; wherein the security parameter set includes a knowledge image identifier and a security parameter set identifier, the knowledge image identifier is used to indicate that the security parameter set acts on a display image or a knowledge image, and the security parameter set identifier is used to distinguish different security parameter sets acting on the same random access segment or knowledge image access unit, the encrypted NAL unit includes a NAL unit header, the NAL unit header includes an encryption flag, and the encryption flag is a security parameter set identifier.

[0022] In a possible implementation, when the knowledge image identifier is a first value, it indicates that the security parameter set acts on the knowledge image; and when the knowledge image identifier is a second value, it indicates that the security parameter set acts on the display image.

[0023] In a possible implementation, the security parameter set includes an encryption basic unit, where the encryption basic unit is used to indicate that encryption is performed in units of data units including NAL units, AUs, or layer units LUs.

[0024] In one possible implementation, the knowledge image is a coded image in which each frame corresponds to a sequence parameter set and the knowledge bit stream flag in the corresponding sequence set parameter is 1. The display image is a reference knowledge image, an instant decoding refresh image, a P image, a B image, or a random access point I frame image output by the decoder after decoding.

[0025] In a fourth aspect, an encryption device is provided. The encryption device includes a module for executing the method of any one of the implementation methods in the first aspect. For example, the encryption device includes a generation module, an encryption module, an acquisition module, and an output module. The generation module is used to generate a security parameter set; the security parameter set includes a knowledge image identifier and a security parameter set identifier, the knowledge image identifier is used to indicate that the security parameter set acts on a display image or a knowledge image, and the security parameter set identifier is used to distinguish different security parameter sets acting on the same random access segment or knowledge image access unit; the encryption module is used to encrypt the network abstraction layer NAL unit to be encrypted corresponding to the security parameter set using the encryption method specified by the security parameter set; the acquisition module is used to obtain the encrypted NAL unit; the encrypted NAL unit includes a NAL unit header, the NAL unit header includes an encryption flag, and the encryption flag is a security parameter set identifier; the output module is used to output a compressed video bit stream; the compressed video bit stream includes the encrypted NAL unit and the security parameter set.

[0026] In a fifth aspect, a decryption device is provided. The decryption device includes a module for executing the method of any one of the implementation methods in the second aspect. For example, the decryption device includes an input module, an acquisition module, and a decryption module. The input module is used to input a compressed video bit stream; the acquisition module is used to obtain a security parameter set in the compressed video bit stream; the security parameter set includes a knowledge image identifier and a security parameter set identifier, the knowledge image identifier is used to indicate that the security parameter set acts on a display image or a knowledge image, and the security parameter set identifier is used to distinguish different security parameter sets acting on the same random access segment or knowledge image access unit; the decryption module is used to decrypt the encrypted NAL unit corresponding to the security parameter set using the encryption method specified by the security parameter set; the encryption flag of the encrypted NAL unit is the security parameter set identifier; the decryption module is also used to obtain decrypted RBSP data.

[0027] In a sixth aspect, a coding device is provided, comprising: at least one processor, which, when executing program code or instructions, implements the method described in the first aspect or any possible implementation thereof.

[0028] Optionally, the encoding device may further include at least one memory, and the at least one memory is used to store the program code or instruction.

[0029] In a seventh aspect, a decoding device is provided, comprising: at least one processor, which, when executing program code or instructions, implements the method described in the second aspect or any possible implementation thereof.

[0030] Optionally, the decoding device may further include at least one memory, and the at least one memory is used to store the program code or instruction.

[0031] In an eighth aspect, embodiments of the present application further provide a chip comprising: an input interface, an output interface, and at least one processor. Optionally, the chip further comprises a memory. The at least one processor is configured to execute code in the memory. When the at least one processor executes the code, the chip implements the method described in any possible implementation of the first or second aspect above.

[0032] Optionally, the chip may also be an integrated circuit.

[0033] In a ninth aspect, an embodiment of the present application further provides a non-transitory computer-readable storage medium for storing a computer program, which includes a method for implementing any possible implementation method in the first or second aspect above.

[0034] In the tenth aspect, an embodiment of the present application further provides a computer program product comprising instructions, which, when executed on a computer, enables the computer to implement the method described in any possible implementation of the first or second aspect above.

[0035] The encoding and decoding device, non-transitory computer-readable storage medium, computer program product and chip provided in this embodiment are all used to execute the encryption and decryption method provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the encryption and decryption method provided above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] FIG1 is a schematic diagram of an exemplary application scenario;

[0037] FIG2 is a schematic diagram illustrating an exemplary encryption and decryption system 200;

[0038] FIG3 is a schematic diagram illustrating an exemplary encryption process 300;

[0039] FIG4 is a schematic diagram illustrating an exemplary decryption process 400;

[0040] FIG5 is a schematic diagram of an exemplary encryption device;

[0041] FIG6 is a schematic diagram illustrating an exemplary decryption device;

[0042] FIG7 is a schematic structural diagram of an exemplary device. DETAILED DESCRIPTION

[0043] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0044] The term "and / or" in this article is merely a description of the association relationship between associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone.

[0045] In the description and claims of the embodiments of this application, the terms "first" and "second" are used to distinguish different objects, rather than to describe a specific order of objects. For example, the terms "first target object" and "second target object" are used to distinguish different objects, rather than to describe a specific order of objects.

[0046] In the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of this application should not be interpreted as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.

[0047] In the description of the embodiments of this application, unless otherwise specified, "multiple" means two or more. For example, "multiple processing units" means two or more processing units; "multiple systems" means two or more systems.

[0048] For example, the code stream encryption and decryption methods involved in this application can be applied to encrypting and decrypting any one of an audio compression code stream (or audio compression bit stream) or a video compression code stream (or video compression bit stream), and this application does not limit this. This application uses the encryption and decryption of a video compression code stream as an example. To keep the subsequent description concise, the technical terms that may be involved in this application are first explained.

[0049] bitstream

[0050] A binary data stream formed by coded image / audio frames. Both NAL unit streams and byte streams can be called bit streams.

[0051] The NAL unit stream format consists of a series of syntax structures called NAL units, which are sorted in decoding order. The decoding order and content of NAL units in a NAL unit stream are constrained.

[0052] A byte stream can be constructed from a NAL unit stream by placing the NAL units in decoding order and appending a start code prefix and a number of zero-valued bytes to each NAL unit to form a bit stream. The NAL unit stream format can be extracted from the bit stream format by searching for a unique start code prefix in the bit stream.

[0053] data unit

[0054] The basic syntax structure of the coded bit stream can be a NAL unit, an access unit, or a layer unit.

[0055] layer unit

[0056] A set of NAL units with the same layer_id value that are related to each other according to specified rules and are continuous in decoding order.

[0057] NAL unit

[0058] A syntax structure that contains an indication of the type of data that follows and the number of bytes it contains (located in the NAL header). The data appears in the form of a Raw Byte Sequence Payload (RBSP), which may also include interspersed security bytes.

[0059] access unit access unit

[0060] A set of NAL units that are related to each other according to specified rules and are consecutive in decoding order.

[0061] It should be noted that, from another perspective, a data unit may also include a coded image.

[0062] coded picture

[0063] The encoded representation of a frame of image.

[0064] Encoded video sequence

[0065] A coded video sequence is the highest-level syntax structure of a bitstream and contains one or more consecutive access units. A coded video sequence starts with an access unit of an IDR picture (instantaneous decoding refresh picture), an access unit of a RAPI picture (random access point I picture), an access unit of an RL leading library picture (leading library picture of an RL picture), or an access unit of a display knowledge picture. The end-of-stream NAL unit or the end-of-coded video sequence NAL unit indicates the end of a coded video sequence. Each coded video sequence contains at most one IDR picture, RAPI picture, RL leading library picture, or display knowledge picture. Access units are arranged in the bitstream in bitstream order, and the bitstream order should be the same as the decoding order. The decoding order may be different from the display order.

[0066] Security Parameter Set

[0067] The security parameter set contains the configuration parameters required for encryption and authentication operations on the compressed video bitstream. At the beginning of the decoding process, each security parameter set takes effect when it is received by the decoder and will cause the previously valid security parameter set (if any) to become invalid. The security parameter set NAL unit should be present before the access unit of all random access point (RAP) pictures. The security parameter set NAL unit should be located in the same access unit as the sequence parameter set NAL unit, and the security parameter set NAL unit should be located before the sequence parameter set NAL unit. Therefore, the scope of the security parameter set is the random access segment in the compressed video bitstream where it is located, that is, all AUs in the bitstream from the AU where the security parameter set is located to the next RAP picture.

[0068] library picture

[0069] A reference picture in a non-current bitstream used when decoding the current bitstream. Each frame corresponds to a sequence parameter set, and the corresponding sequence set parameter has the knowledge bitstream flag set to 1. The coded slice NAL unit type of the knowledge picture is 12, 17, or 18, and the knowledge picture is associated with a privacy coded slice.

[0070] Display knowledge image output library picture

[0071] Each frame corresponds to a sequence parameter set, and the corresponding sequence set parameter has a coded image with the knowledge bitstream flag set to 1 and the knowledge image mode index set to 1. The coded slice NAL unit type of the display knowledge image is 17. The display knowledge image is a random access point image, and the display knowledge image that serves as the RL pre-knowledge image is not a random access point image.

[0072] Non-display knowledge image non output library picture

[0073] Each frame corresponds to a sequence parameter set, and the corresponding sequence set parameter has a knowledge bit stream flag of 1 and a knowledge image mode index of 0 or 2. The NAL unit type of the coded slice of the non-display knowledge image is 12 or 18.

[0074] Leading library picture of an RL picture

[0075] A non-displayed knowledge picture that precedes an associated RL picture in the codestream order, or a displayed knowledge picture that appears before an RL picture after bitstream editing, has no access units between the access unit containing the first knowledge picture coding slice of the knowledge picture and the access unit of the associated RL picture. The preceding RL knowledge picture is not a random access point picture.

[0076] Non-leading library picture of an RL picture

[0077] A non-display knowledge picture precedes an associated RL picture in the codestream order. There is at least one access unit of another picture between the access unit containing the first knowledge picture coding slice of the non-display knowledge picture and the access unit of the associated RL picture. The non-RL preceding knowledge picture is not a random access point picture.

[0078] Display image output picture

[0079] After decoding, the decoder reconstructs the image output as RL picture, IDR picture, P picture, B picture or RAPI picture. It should be noted that display knowledge picture and non-display knowledge picture are not display pictures.

[0080] A picture is a frame of a coded video sequence, whose coded data is contained in one or more access units. Its coded picture consists of a picture header NAL unit, supplementary enhancement information (if present), and all coded slice NAL units of the picture. Specifically, the coded picture of an IDR picture includes a picture header NAL unit, zero or more supplementary extended description NAL units of the IDR picture, and all IDR picture coded slice NALU units of the IDR picture. The coded picture of a RAPI picture includes a picture header NAL unit, zero or more supplementary extended description NAL units of the RAPI picture, and all RAPI picture coded slice NAL units of the RAPI picture. The coded picture of a P picture and a B picture includes a picture header NAL unit, zero or more supplementary extended description NAL units of the P picture or B picture, and all NRAP picture coded slice NAL units of the P picture or B picture. The coded picture of an RL picture includes a picture header NAL unit, zero or more supplementary extended description NAL units of the RL picture, and all RL picture coded slice NAL units of the RL picture. The coded image of the knowledge image consists of an image header NAL unit and one or more knowledge image coding slice NAL units and one or more privacy image coding slice NAL units. The RL pre-knowledge image and privacy image coding slice NAL units and all coding slice NAL units in the coded image of the display knowledge image are continuous, and its access unit contains all NAL units of the coded image. The coding slices of non-RL pre-knowledge images can be interleaved with the access units of the display image as access units.

[0081] The first coded slice NAL unit of a picture shall be followed by the picture header NAL unit of the picture. For coded pictures that are IDR pictures, RAPI pictures, RL pictures or knowledge pictures, the picture header NAL shall be followed by a picture parameter set NAL unit, and the picture parameter set NAL shall be followed by a sequence parameter set NAL unit.

[0082] In particular, the bitstreams of one or more display images may be interleaved between multiple knowledge image bitstream slices of non-RL pre-knowledge images, but the interleaved display image bitstreams shall not be access units of RL images, IDR images, or RAPI images. All knowledge image bitstream slices of an RL pre-knowledge image or display knowledge image shall be continuous. Each knowledge image bitstream slice may be interleaved with the NAL unit of the privacy image coding slice (if present), but shall not be interleaved with the bitstream of the display image.

[0083] The bitstreams of all slices of a knowledge image should precede the bitstream of the first RL image that references that knowledge image. Knowledge image bitstream slices from different knowledge images cannot be interleaved. The knowledge image referenced by an RL image is the knowledge image represented by the first access unit of the knowledge image found in reverse order from the RL access unit in the bitstream.

[0084] Figure 1 is a schematic diagram of exemplary application scenarios, showing a monitoring scenario, a live broadcast scenario, and a video-on-demand scenario.

[0085] Referring to Figure 1 , in an exemplary surveillance scenario, camera 11 can encrypt a surveillance video stream to obtain an encrypted surveillance video stream 101. This encrypted surveillance video stream 101 is then sent to laptop computer 13 via network 12. Laptop computer 13 can then decrypt this encrypted surveillance video stream 101, obtain and display the decryption result 105, and play surveillance video 104.

[0086] 1 , for example, in a live broadcast scenario, mobile phone 14 can encrypt a live video stream to obtain an encrypted live video stream 102. Then, encrypted live video stream 102 is sent to mobile phone 15 via network 12. Mobile phone 15 can then decrypt encrypted live video stream 102, obtain and display a decryption result 107, and play live video 106.

[0087] 1 , in an exemplary on-demand scenario, a personal computer 16 can encrypt an on-demand video stream to obtain an encrypted on-demand video stream 103. The encrypted on-demand video stream 103 is then sent to a mobile phone 17 via a network 12. The mobile phone 17 can then decrypt the encrypted on-demand video stream 103, obtain and display a decryption result 109, and play the on-demand video 108.

[0088] It should be understood that the present application can also be used in other audio and video encoding and decoding scenarios, such as digital content trusted scenarios, etc., and the present application does not limit this.

[0089] Fig. 2 is a schematic diagram of an exemplary decryption and encryption system 200. In Fig. 2, the decryption and encryption process in Fig. 1 is described.

[0090] 2 , illustratively, the decryption and encryption system 200 may include an encryption end 210 and a decryption end 220 .

[0091] For example, the encryption end 210 can be a front-end device such as the camera 11, mobile phone 14 and personal computer 16 in Figure 1 above, and the decryption end 220 can be a back-end device such as the laptop computer 13, mobile phone 15 and mobile phone 17 in Figure 1 above.

[0092] It should be understood that the same terminal device can serve as both the encryption end 210 and the decryption end 220, and this application does not impose any limitation on this.

[0093] 2 , illustratively, after the encryption end 210 obtains the video data 201 , it may perform video encoding 21 on the video data 201 to obtain a code stream 202 ; and perform video encryption 22 on the code stream 202 to obtain an encrypted code stream 203 .

[0094] For example, the video data 201 may be a surveillance video captured by the camera 11 in FIG. 1 , a live video recorded by the mobile phone 14 , or a video on demand produced by the personal computer 16 .

[0095] For example, the encrypted code stream 203 may be the encrypted surveillance video code stream 101, the encrypted live video code stream 102, or the encrypted on-demand video code stream 103 in FIG. 1 .

[0096] It should be noted that the video encoding 21 and the video encryption 22 operations can be performed in parallel.

[0097] It should be noted that, in one possible embodiment, the encryption end 210 may include an encoder, and the encoder performs video encoding 21 and video encryption 22. In another possible embodiment, the encryption end 210 may include an encoder and an encryption module, and the encoder performs video encoding 21, and the encryption module performs video encryption 22. In another possible embodiment, the encryption end 210 may include an encryption module, and the encryption module performs video encoding 21 and video encryption 22.

[0098] Afterwards, the encryption end 210 may send the encrypted code stream 203 to the decryption end 220 .

[0099] 2 , illustratively, after the decryption end 220 receives the encrypted code stream 203 , it can perform video decryption 23 on the encrypted code stream 203 to obtain a decryption result 205 ; and it can perform video decoding 24 on the code stream 202 in the encrypted code stream 203 to obtain decoded video data 204 .

[0100] For example, the decoded video data 204 may be the surveillance video 104, the live video 106, or the on-demand video 108 in FIG. 1 .

[0101] For example, the decryption result 205 may be the decryption result 105 , the decryption result 107 , or the decryption result 109 in the above-mentioned image 1 .

[0102] It should be noted that the video decryption 23 and the video decoding 24 can be performed in parallel.

[0103] It should be noted that, in one possible embodiment, the decryption end 220 may include a decoder, which performs video decoding 24 and video decryption 23. In another possible embodiment, the decryption end 220 may include a decoder and a decryption module, which performs video decoding 24 and video decryption 23. In another possible embodiment, the decryption end 220 may include a decryption module, which performs video decoding 24 and video decryption 23.

[0104] It should be noted that when the encryption end 210 performs lossless encoding, the video data and the decoded video data are the same; when the encryption end 210 performs lossy encoding, there are differences between the video data and the decoded video data.

[0105] It should be noted that the encoder, decoder, encryption module and decryption module can be implemented by software or hardware, and this application does not impose any restrictions on this.

[0106] FIG3 is a schematic diagram illustrating an exemplary encryption process 300 , wherein the process 300 may be implemented by the encryption terminal 210 .

[0107] S301, generating a security parameter set;

[0108] A security parameter set is generated for each image data unit. The security parameter set includes a knowledge image identifier and a security parameter set identifier. The knowledge image identifier indicates that the security parameter set applies to a display image or knowledge image. All NAL units encrypted using the same security parameter set should fall within the scope of this security parameter set. The security parameter set identifier is used to distinguish different security parameter sets that apply to the same random access segment or knowledge image access unit.

[0109] The value of the knowledge image identifier can be a binary variable. For example, when the knowledge image identifier is the first value, it indicates that the security parameter set acts on the knowledge image, and when the knowledge image identifier is the second value, it indicates that the security parameter set acts on the display image. The first value can be 1, the second value can be 0, or the first value can be 0, and the second value can be 1. Taking the first value of the knowledge image identifier as 1, indicating that the security parameter set acts on the knowledge image, and the second value as 0, indicating that the security parameter set acts on the display image, as an example, the knowledge image identifier of the security parameter set corresponding to the knowledge image is 1, and the knowledge image identifier of the security parameter set corresponding to the display image is 0.

[0110] As a possible implementation, the image data unit is a data unit extracted from the compressed video bitstream output by the encoder, and whether the data unit needs to be encrypted is determined according to the configuration. If necessary, an encryption flag is added to the data unit.

[0111] A data unit is the basic syntax structure of a coded bitstream (such as a compressed video bitstream). It can be a NAL unit, an access unit, or a layer unit. A group of data units is also called a bitstream segment in the codestream.

[0112] Referring to Figure 3 , for example, the n data units in the compressed video bitstream that require encryption are: data unit 1, data unit 2, ..., data unit n. These n data units that require encryption can be referred to as a group of data units. All subsequent references to a group of data units refer to data units that require encryption.

[0113] It should be noted that this application does not group the data units, but uses "a group of data units" to describe them for the convenience of description.

[0114] Exemplarily, data unit 1 is a data unit of a knowledge image, and data unit 2, ..., data unit n are data units of a display image.

[0115] Encryption terminal 210 generates security parameter set 1 for data units 2, ..., and n, and also generates a separate security parameter set 2 for data unit 1. Thus, security parameter set 1 applies to the data units of the display image, also known as the display image; security parameter set 2 applies to the data units of the knowledge image, also known as the knowledge image.

[0116] As a possible implementation, a NAL unit is extracted from the compressed video bitstream output by the encoder. The NAL unit includes a NAL unit header and RBSP data. The NAL unit is then determined to be encrypted based on the configuration. If encryption is required, the NAL unit encryption flag (e.g., encryption_idc) in the NAL unit header is set to 1, and the subsequent security parameter set generation operation is performed.

[0117] As a possible implementation, the syntax definition of the NAL unit is shown in Table 1.

[0118] Table 1

[0119] NumBytesInNALunit indicates the length of the NAL unit in bytes. A NAL unit consists of a unit header and a unit payload. The unit payload contains an RBSP syntax structure and possible authentication data payload, and may also contain some emulation_prevention_three_bytes. To derive NumBytesInNALunit, it is necessary to demarcate NAL unit boundaries.

[0120] forbidden_zero_bit is a binary variable that specifies the forbidden zero bit. It should be equal to '0'.

[0121] nal_unit_type is a 5-bit unsigned integer that identifies the NAL unit type. It indicates the type of the RBSP data structure in the NAL unit. NAL units with nal_unit_type equal to 11 can be discarded by the decoder without affecting the decoding process of NAL units with nal_unit_type not equal to 11 and without affecting the consistency of this standard. When the nal_unit_type value of a coded slice NAL unit is equal to 1, 2, 4, 12 or 17, the nal_unit_type value of all other coded slice NAL units encoding the same image should be the same. If UserPermission is equal to 0, NAL units with nal_unit_type value equal to 19 can be discarded by the decoder. When the nal_unit_type value of a coded slice NAL unit is equal to 19, the RBSP data contains data of several coding units in the coded slice of the image.

[0122] When the number of coded slices of a knowledge picture is equal to 1, the nal_unit_type of the knowledge picture coded slice NAL unit should be 12 or 17. When the number of coded slices of a non-display knowledge picture is greater than 1, the nal_unit_type of the first and last knowledge picture coded slice NAL units in decoding order should be 18, and the nal_unit_type of the remaining knowledge picture coded slice NAL units should be 12.

[0123] The specific classification of NAL unit types can be seen in Table 2.

[0124] Table 2

[0125] encryption_idc is the encryption flag, a 2-bit unsigned integer ranging from 0 to 3. It indicates whether the NAL unit is encrypted. A value of '0' indicates that the RBSP in the NAL unit is not encrypted. A value other than '0' indicates that the RBSP in the NAL unit is encrypted using the encryption method specified in the security parameter set whose sec_para_set_id is equal to encryption_idc. The last byte of the RBSP is not encrypted.

[0126] When the nal_unit_type of a NAL unit is 9, 10, 11, 15, or 16, encryption_idc shall be 0.

[0127] When a NAL unit has nal_unit_type 6 and contains a payload with PayloadType equal to 25 or 26, encryption_idc shall be 0.

[0128] authentication_idc is an authentication flag, a 2-bit unsigned integer with a value range of 0 to 3. If the nal_unit_type of the NAL unit is 10, the authentication_idc value should be equal to the security parameter set ID sec_para_set_id corresponding to the authentication data contained in the NAL unit, indicating that the authentication data NAL unit carries authentication data generated based on the security parameter set corresponding to the security parameter set ID sec_para_set_id; otherwise (the nal_unit_type of the NAL unit is not 10), it indicates whether the NAL unit is authenticated. In this case, a value of '0' indicates that the NAL unit is not authenticated, and a value other than '0' indicates that the NAL unit is authenticated using the authentication method specified by the security parameter set with sec_para_set_id equal to authentication_idc.

[0129] When the nal_unit_type of a NAL unit is 10, the NAL unit does not participate in signature authentication.

[0130] When the nal_unit_type of a NAL unit is 11, 15, or 16, authentication_idc shall be 0.

[0131] When a NAL unit has nal_unit_type 6 and contains a payload with PayloadType equal to 25 or 26, authentication_idc shall be 0.

[0132] authentication_data_id is the authentication data identifier, a 2-bit unsigned integer. The value range is 0 to 1, and it is the identifier of the authentication data of the signature authentication in which this NAL unit participates. It should be consistent with the authentication_data_id in the authentication data RBSP in which it participates in the signature authentication. The authentication_data_id of the NAL units participating in the authentication corresponding to the same authentication data should be the same and consistent with the authentication_data_id in the authentication data. The authentication_data_id of a group of display image coding slice NAL units participating in the joint signature authentication should be different from the authentication_data_id of the previous group of display image coding slice NAL units participating in the joint signature authentication with the same authentication_idc.

[0133] When the nal_unit_type of a NAL unit is 10, this authentication_data_id should be consistent with the authentication_data_id in the authentication data RBSP of the NAL unit.

[0134] temporal_id is the temporal layer identifier, a 3-bit unsigned integer. It indicates the temporal layer identifier of the current image. The value range of the temporal layer identifier is 0 to MAX_TEMPORAL_ID. A temporal layer identifier of 0 indicates the lowest layer. When the nal_unit_type of a NAL unit is 7, 8, 9, 10, 11 or 16, temporal_id should be 0. The temporal_id of all picture header NAL units and all coded slice NAL units in an access unit should be the same. The temporal_id of an access unit is the temporal_id of the coded slice NAL unit in the access unit. If an access unit contains a NAL unit with a nal_unit_type of 7, 8 or 9, the temporal_id of the access unit should be 0.

[0135] When the nal_unit_type of a NAL unit is 3, 5, 6, or 15, the temporal_id of the NAL unit shall be equal to the temporal_id of the access unit in which it resides.

[0136] layer_id is a 2-bit unsigned integer that represents the layer identifier of the current image. The layer identifier value ranges from 0 to MAX_LAYER-1. The layer_id of the picture header NAL unit and all coded slice NAL units of a coded picture should be the same. The value of layerId is equal to the value of layer_id. The LayerId of a coded picture or layer unit is the LayerId of the coded slice NAL unit within that coded picture or layer unit.

[0137] When the nal_unit_type of a NAL unit is 5, 7, 8, 9, 10, or 15, LayerId shall be 0.

[0138] When the nal_unit_type of a NAL unit is 6 and the NAL unit includes a supplementary enhancement payload with a PayloadType of 19, 25, 26, or 127, LayerId shall be 0.

[0139] payload_byte[i] is the i-th byte of the payload, an 8-bit arbitrary variable. It represents the i-th byte of a NAL unit payload and is equal to rbsp_byte[i]. A NAL unit payload is defined as an ordered sequence of bytes, including an RBSP (if encryption_idc is 1, it is the byte sequence generated by RBSP encryption).

[0140] rbsp_byte[j] is the jth byte of an RBSP. If encryption_idc is 1, rbsp_byte[j] is the jth byte of the RBSP encrypted byte sequence. The RBSP needs to be decrypted, which is not specified in this standard.

[0141] An RBSP is defined as an ordered sequence of bytes, containing an SODB, as follows:

[0142] a) If SODB is empty (length is 0 bits), RBSP is also empty;

[0143] b) Otherwise the RBSP includes the following SODB:

[0144] 1) The first byte of the RBSP includes (most significant bit first) 8 bits of SODB; the next byte of the RBSP shall include the next 8 bits of SODB, and so on, until the remaining SODB is less than 8 bits;

[0145] 2)rbsp_trailing_bits() is used after SODB: the leading (starting from the most significant) bits in the last RBSP byte include the remaining bits of SODB (if any); the next bit is a single rbsp_stop_one_bit whose value is 1, and when rbsp_stop_one_bit is not the last bit of a byte that is not byte-aligned, one or more rbsp_alignment_zero_bits should follow to form a byte alignment.

[0146] Syntax structures with these RBSP attributes are indicated in the syntax tables with a "_rbsp" suffix. These structures are carried in NAL units as the contents of the rbsp_byte[j] data byte.

[0147] When the boundaries of the RBSP are known, the decoder can parse the SODB from the RBSP by concatenating the RBSP bytes into a bit string and discarding the last (rightmost) bit rbsp_stop_one_bit equal to 1 and any subsequent bits equal to 0. The data necessary for the decoding process is contained in the SODB part of the RBSP.

[0148] emulation_prevention_three_byte is the anti-counterfeiting code.

[0149] As a possible implementation method, the knowledge image identifier can be compiled into the security parameter set according to the preset syntax according to the syntax table shown in Table 3.

[0150] Table 3

[0151] sec_is_library_flag is a binary variable that identifies the knowledge image. A value of '1' (the first value) indicates that this security parameter set applies to the knowledge image, and a value of '0' (the second value) indicates that this security parameter set applies to the display image.

[0152] sec_para_set_id is the security parameter set ID, a 2-bit unsigned integer used to distinguish different security parameter sets acting on the same RAS or knowledge image access unit, and its value range is 1 to 3.

[0153] encryption_enable_flag is the encryption enable flag, a binary variable. A value of '1' indicates that encryption of display picture coded slices, display picture sequence parameter sets, display picture parameter sets, non-display knowledge picture coded slices, display knowledge picture coded slices, knowledge picture sequence parameter sets, knowledge picture parameter sets, or extension data units is supported, that is, the RBSP in the NAL unit may be encrypted. A value of '0' indicates that encryption of the RBSP in the NAL unit is not supported.

[0154] authentication_enable_flag is the authentication enable flag, a binary variable. A value of '1' indicates that authentication of the current RAS or knowledge image is supported. The NAL units that can participate in the authentication include the coded slices of the display image or knowledge image in the current RAS, as well as the sequence parameter set, image parameter set, security parameter set, extended data unit, and supplementary enhancement information transmitted in the access unit. When authentication of the above data content is supported, the authentication data carried in the coded bitstream should be Base64 encoded. The authentication data is transmitted through the NAL unit with nal_unit_type equal to 10. A value of '0' indicates that the current security parameter set does not support authentication of the RAS or knowledge image, and there should be no NAL unit with nal_unit_type equal to 10 for the RAS or knowledge image generated using the security parameter set.

[0155] Knowledge images only support independent signature authentication, while display images support co-signature authentication. Multiple display image access units participating in co-signature authentication must reside in the same RAS. The image type in multiple access units participating in co-signature authentication can be display images. Independent signature authentication for knowledge images uses a security parameter set independent of the display image, distinguished by the sec_is_library_flag in the security parameter set.

[0156] If an access unit contains NAL units with authentication_idc greater than 0 and nal_unit_type equal to 1-3, 5-9, 12, 14, 17, 18, or 19, the digest of the NAL units with the same authentication_idc value greater than 0 and the same layer_id value for each layer unit in the access unit is calculated in bitstream order. The digest data for NumOfLayers layer units corresponding to the authentication_idc value of the access unit is generated. The digest calculation method is specified by hash_type.

[0157] For hash_period_in_doi_minus1+1 access units, calculate the digest of each layer unit in each access unit in the order of the bit stream. The authentication data scope should not cross RAS. Then calculate the secondary digest according to the method indicated by authentication_hash_mode.

[0158] The secondary digest value is digitally signed to generate the authentication data RBSP, which is packaged into the authentication data RBSP NAL unit.

[0159] If the authentication_enable_flag and encryption_enable_flag values ​​of multiple security parameter sets in the codestream are equal to 1, that is, the current RAS or knowledge image supports both encryption and authentication, it should be encrypted first and then authenticated, that is, the data used for authentication should be the encrypted NAL unit.

[0160] encryption_unit_mode is a 2-bit unsigned integer indicating the encryption basic unit. A value of '0' indicates encryption per NAL; a value of '1' indicates encryption per access unit, concatenating the encrypted portions of all NAL unit RBSPs in the access unit in bitstream order and restoring them to the encrypted NAL unit; a value of '2' indicates encryption per layer unit, concatenating the encrypted portions of all NAL unit RBSPs in the layer unit in bitstream order and restoring them to the encrypted NAL unit; a value of '3' indicates reserved. The Initial Vector (IV) must be reinitialized for each encryption.

[0161] encryption_level_mode is the encryption level mode, a 2-bit unsigned integer. It indicates the encryption level mode. A value of '0' indicates that when encrypting all NAL unit types, the entire RBSP data (except the last byte of the RBSP) is encrypted. A value of '1' indicates that when encrypting NAL units with nal_unit_type equal to 1, 2, 4, 12, 14, 17, 18, and 19, the first encryptionByte bytes of the RBSP are encrypted, and when encrypting other NAL unit types, the entire RBSP data (except the last byte of the RBSP) is encrypted. A value of '2' indicates that when encrypting NAL units with nal_unit_type equal to 1, 2, 4, 5, 12, 14, 17, 18, and 19, the first encryptionByte bytes of the RBSP are encrypted, and when encrypting other NAL unit types, the entire RBSP data (except the last byte of the RBSP) is encrypted. A value of '3' is reserved. Where encryptionByte = Min(EncryptionNum * EncryptionBaseByte, NumBytesInPayload - 1).

[0162] encryption_num_minus1 is the number of encryption basic byte lengths, an 8-bit unsigned integer. It indicates the number of encryption basic byte lengths. The value of EncryptionNum is equal to the value of encryption_num_minus1 plus 1.

[0163] encryption_base_byte is the encryption base byte length, a 2-bit unsigned integer. It indicates the encryption base byte length. A value of '0' indicates that the encryption base byte length is 16, a value of '1' indicates that the encryption base byte length is 64, a value of '2' indicates that the encryption base byte length is 256, and a value of '3' indicates that the encryption base byte length is 1024.

[0164] encryption_type is the encryption type, a 4-bit unsigned integer. It indicates the encryption algorithm used. For specific correspondence, see Table 4.

[0165] Table 4

[0166] vek_flag is the video encryption key flag, a binary variable. A value of '1' indicates that the video encryption key (VEK) is carried, and a value of '0' indicates that the VEK is not carried.

[0167] iv_flag is the initialization vector flag, a binary variable. A value of '1' indicates that the iv is carried, and a value of '0' indicates that the iv is not carried.

[0168] vek_encryption_type is the video encryption key encryption type, a 4-bit unsigned integer, indicating the encryption type of the video encryption key.

[0169] evek_length_minus1 is the length of the encrypted video encryption key, an 8-bit unsigned integer. It indicates the length of the encrypted video encryption key in bytes.

[0170] evek is the encrypted video encryption key, an n-bit unsigned integer. It represents the encrypted video encryption key and is used for encryption calculations. Its length is evek_length_minus1 plus 1 byte.

[0171] vkek_version length_minus1 is the length of the video encryption key version number, an 8-bit unsigned integer. Indicates the length of the video encryption key version number in bytes.

[0172] vkek_version is the video encryption key version number, an n-bit unsigned integer. Indicates the video encryption key version number, and its length is vkek_version_length_minus1 plus 1 byte.

[0173] iv_length_minus1 is an 8-bit unsigned integer representing the length of the initial vector, in bytes.

[0174] iv is the initial vector, an n-bit unsigned integer. It indicates the initial vector used for block encryption and its length is iv_length_minus1 plus 1 byte.

[0175] hash_type is the hash type, a 2-bit unsigned integer. It indicates the algorithm used for authentication. The specific correspondence is shown in Table 5.

[0176] Table 5

[0177] authentication_hash_mode is the authentication digest calculation mode, a binary variable that identifies the secondary digest calculation method. A value of '0' indicates that the secondary digest is calculated using the concatenated method, that is, the secondary digests of the layer unit digest values ​​Hpic1, Hpic2, ..., Hpicn are calculated in bitstream order. A value of '1' indicates that the secondary digest is calculated using the tree-top method, that is, the secondary digests of the layer unit digest values ​​Hpic1, Hpic2, ..., Hpicn are calculated using the tree-top method in bitstream order.

[0178] hash_discard_nrap_pictures_flag is a binary variable that specifies the hash authentication flag for non-random access point images. A value of '1' indicates that non-random access point images are not authenticated; a value of 0 indicates that non-random access point images can be authenticated. If hash_discard_nrap_pictures is not in the codestream, its default value is 1.

[0179] hash_period_in_doi_minus1 is the hash period, an 8-bit unsigned integer with a value range of 0 to (MAX_HASH_PERIOD / NumOfLayers-1), and MAX_HASH_PERIOD is set to 256. HashPeriodInDoi is equal to hash_period_in_doi_minus1+1. It indicates the number of access units involved in signature authentication related to one authentication data. This number is less than or equal to HashPeriodInDoi. If HashPeriodInDoi is 1, it means that a single access unit is signed independently, and the authentication data NAL unit carrying the signature should be located in the access unit associated with the signature or the first access unit thereafter. If HashPeriodInDoi is greater than 1, it means that multiple access units are signed together.

[0180] signature_type is the digital signature type, a 2-bit unsigned integer, indicating the algorithm used to digitally sign the image summary data, as shown in Table 6.

[0181] Table 6

[0182] signature_fmt is the signature data format, a 2-bit unsigned integer. It indicates the signature data format. The specific meaning of the signature_fmt value and the corresponding relationship between the signature_type syntax are shown in Table 7.

[0183] Table 7

[0184] For example, in combination with the specific content of the security parameter set, the encryption end 210 may generate the security parameter set as follows:

[0185] Step 1. Set sec_para_set_id according to the configuration and set sec_is_library_flag according to the scope of the current security parameter set.

[0186] Step 2. Set encryption_enable_flag to 1 (indicates that encryption is enabled); set encryption_type according to the encryption type in the configuration;

[0187] Step 3. Set encryption_unit_mode according to the configuration. Determine the encryption basic unit according to encryption_unit_mode. If the encryption_unit_mode value is '0', it means encryption is performed in NAL units; if the value is '1', it means encryption is performed in access units, and the encrypted parts of all NAL unit RBSPs in the access unit are spliced ​​together in bitstream order for encryption; if the value is '2', it means encryption is performed in layer units, and the encrypted parts of all NAL unit RBSPs in the layer unit are spliced ​​together in bitstream order for encryption;

[0188] Step 4. Set encryption_level_mode according to the configuration. If only part of the RBSP data of the coded slice NAL unit needs to be encrypted, set it to 1; if only part of the RBSP data of the coded slice NAL unit and the extended data NAL unit needs to be encrypted, set it to 2; otherwise, set it to 0; if encryption_level_mode is set to 1 or 2, encryption_num_minus1 and encryption_base_byte need to be set according to the configured encryption byte length;

[0189] Step 5. Set vek_flag to 1 and set vek_encryption_type according to the key encryption type in the configuration. Generate a VEK based on a secure random number. Use the algorithm specified by vek_encryption_type to encrypt the VEK using the VKEK in ECB mode to obtain the EVEK. Write the EVEK data length minus one and the data into evek_length_minus1 and evek, respectively. Write the VKEK version used in the VEK encryption process minus one and the data into vkek_version_length_minus1 and vkek_version, respectively. VEK and VKEK need to be updated according to business security requirements.

[0190] Step 6: Set iv_flag to 1, and write the data length of the currently configured IV minus one and the data into iv_length_minus1 and iv respectively.

[0191] S302, using the encryption method specified by the security parameter set, encrypting the NAL unit to be encrypted corresponding to the security parameter set;

[0192] As a possible implementation, the data unit is encrypted using an encryption algorithm adopted by the encryption method specified in the security parameter set to obtain an encrypted data unit. The encryption algorithm may be a symmetric encryption algorithm, such as SM1, SM4, or other encryption algorithms.

[0193] Continuing with the example of a NAL unit as the data unit, in some possible embodiments, the encryption end 210 extracts the RBSP data, then encrypts the RBSP data according to the encryption method specified in the security parameter set to obtain encrypted RBSP data. Finally, the NAL unit header and the encrypted RBSP data are concatenated to obtain an encrypted NAL unit. If the RBSP data has been processed with an anti-counterfeiting start code, the encryption end 210 needs to remove the anti-counterfeiting start code after extracting the RBSP data. After obtaining the encrypted RBSP data, the encryption end 210 can add the anti-counterfeiting start code to the encrypted RBSP.

[0194] Exemplarily, in combination with the above-mentioned definitions of the NAL unit and the security parameter set RBSP, the steps of encrypting the NAL unit that needs to be encrypted within the scope of the security parameter set are described.

[0195] Step 1. Determine the encryption level of each NAL unit that needs to be encrypted: if encryption_level_mode is 0, the NAL unit RBSP is fully encrypted; if encryption_level_mode is 1, the NAL type of the NAL unit is a coded slice, and its RBSP is partially encrypted; if encryption_level_mode is 1, the NAL type of the NAL unit is not a coded slice, and its RBSP is fully encrypted; if encryption_level_mode is 2, the NAL type of the NAL unit is a coded slice or extended data, and its RBSP is partially encrypted; if encryption_level_mode is 2, the NAL type of the NAL unit is not a coded slice or extended data, and its RBSP is fully encrypted.

[0196] Step 2. Determine the encrypted data length of each NAL unit that needs to be encrypted: For each NAL unit that needs to be encrypted, calculate the encrypted byte length of the NAL unit based on the encryption_level_mode value, its NAL type, and the RBSP length of the NAL unit. This length does not exceed the RBSP data length minus one. If the RBSP of the NAL unit is fully encrypted, the encrypted data length is the RBSP data length minus one. If the RBSP of the NAL unit is partially encrypted, the corresponding encrypted data length is determined by encryption_num_minus1 and encryption_base_byte. If the data length is greater than the RBSP data length minus one, the encrypted data length is the RBSP data length minus one.

[0197] Step 3. Determine the data to be encrypted based on the encrypted data length: If there is only one NAL unit in the encryption basic unit, obtain the data length of the NAL unit's pre-RBSP encrypted data according to its encrypted byte length for encryption, and retain the remaining unencrypted data of the RBSP; If there are multiple NAL units in the encryption basic unit, obtain the data length of the pre-RBSP encrypted data of each NAL unit according to the encrypted byte length of each NAL unit, and retain the remaining unencrypted data of each RBSP, splice the RBSP encrypted part data of these NAL units together in bit stream order for encryption, and record the length of each RBSP encrypted part data.

[0198] Step 4: For the encrypted data to be encrypted, use the encryption algorithm marked with encryption_type in the security parameter set and encrypt it using VEK; when encrypting, initialize IV to iv in the security parameter set.

[0199] S303, obtaining the encrypted NAL unit;

[0200] The NAL unit includes a NAL unit header, which includes an encryption flag. The encryption flag is the security parameter set identifier of the security parameter set generated above, that is, the value of the encryption flag is equal to the value of the security parameter set, and the encryption flag is used to indicate that the encrypted NAL unit is encrypted using the encryption method specified in the security parameter set corresponding to the security parameter set identifier.

[0201] As a possible implementation method, the encrypted data is restored to the encrypted original byte sequence payload RBSP data; the NAL unit header and the encrypted RBSP data are spliced; the encryption flag of the NAL unit header is set to the value of the security parameter set identifier in the security parameter set corresponding to the encrypted NAL unit to obtain the encrypted NAL unit.

[0202] Optionally, if there is only one NAL unit in the encryption basic unit, the encrypted data is directly spliced ​​with the remaining unencrypted data of the retained RBSP to obtain the encrypted RBSP data; if there are multiple NAL units in the encryption basic unit, the encrypted data is divided according to the length of each recorded RBSP encryption part data to obtain the encrypted partial RBSP of each encrypted partial RBSP, and then spliced ​​with the remaining unencrypted data of the RBSP corresponding to the same NAL unit in turn to obtain each encrypted RBSP.

[0203] Optionally, the encrypted RBSP is added with an anti-counterfeiting start code, combined with the corresponding NAL unit header, and the encryption_idc of the NAL unit header is set to the sec_para_set_id in the corresponding security parameter set to obtain a completely encrypted NAL unit.

[0204] S304: Output the compressed video bit stream.

[0205] The compressed video bitstream includes an encrypted data unit and a security parameter set. The security parameter set includes encryption parameters and a knowledge image identifier, and the knowledge image identifier is used to indicate that the security parameter set acts on a knowledge image or a display image.

[0206] A security parameter set (SPS) can be in the form of an RBSP. The SPS RBSP includes parameters (such as encryption parameters) that can be used by one or more other types of NAL units. Knowledge images are encrypted or authenticated independently of display images. The sec_is_library_flag in the SPS RBSP distinguishes whether it is a SPS for a knowledge image. A codestream can contain multiple SPSs, distinguished by their SPS IDs (sec_para_set_id). Up to three SPSs are supported simultaneously. A SPS NAL unit must precede the random access point access unit of a RAS or the first knowledge image access unit. This SPS applies to the current RAS or knowledge image. The SPS provides parameters for encryption and authentication of the current RAS or knowledge image access unit. In the case of multiple SPSs, the sec_para_set_id is used to distinguish them. If no SPS NAL unit is present in the random access point access unit of a RAS, the current RAS (excluding non-display knowledge image access units) is considered unencrypted and does not participate in authentication. If no SPS NAL unit is present in the first knowledge image access unit, the current knowledge image is considered unencrypted and does not participate in authentication.

[0207] When non-display knowledge pictures are present in the coded video sequence, for non-RL pre-knowledge pictures, the security parameter set should be located within the access unit containing the patch_index value of 0. For RL pre-knowledge pictures, the security parameter set should be located within the access unit containing the patch_index value of 0, preceding the picture sequence parameter set. In some applications, the security parameter set can also be delivered to the decoder through other reliable mechanisms.

[0208] FIG4 is a schematic diagram illustrating an exemplary decryption process 400 , wherein the process 400 may be implemented by the decryption terminal 220 , and the process 400 corresponds to the process 300 .

[0209] S401, input compressed video bit stream;

[0210] A compressed video bitstream is input to the decryption terminal 220. The compressed video bitstream includes encrypted data units and a security parameter set. The security parameter set includes encryption parameters and a knowledge image identifier, which indicates whether the security parameter set applies to a knowledge image or a display image. The security parameter set can be one or more security parameter set NAL units, which may include a security parameter set NAL unit. However, the security parameter set NAL unit is not encrypted and is different from the encrypted NAL unit in this application.

[0211] 4 , illustratively, the n data units that need to be decrypted in the compressed video bitstream are: data unit 1, data unit 2, ..., data unit n. These n data units that need to be decrypted can be called a group of data units, that is, a group of decryption basic units that need to be decrypted.

[0212] Exemplarily, data unit 1 is a data unit of an encrypted knowledge image, and data unit 2, ..., data unit n are data units of an encrypted display image.

[0213] Combined with the above NAL unit syntax definition, the steps for obtaining the security parameter set NAL unit in the compressed video bitstream can be as follows:

[0214] Step 1: If encryption_type is 0, use algorithm SM1 to decrypt the encrypted bit stream; if encryption_type is 1, use algorithm SM4 to decrypt the encrypted bit stream;

[0215] Step 2: Determine the decryption basic unit based on encryption_unit_mode. If the encryption_unit_mode value is '0', it indicates decryption in NAL units; if the value is '1', it indicates decryption in access unit units, and all NAL unit RBSP parts in the access unit that need to be decrypted are spliced ​​together in bitstream order for decryption; if the value is '2', it indicates decryption in layer units, and all NAL unit RBSP parts in the layer unit that need to be decrypted are spliced ​​together in bitstream order for decryption;

[0216] Step 3. If encryption_level_mode is 1 or 2, obtain encryption_num_minus1 and encryption_base_byte in the security parameter set and calculate the encrypted byte length in the partial encryption case.

[0217] Step 4. If vek_flag is 1, obtain evek_length_minus1 and evek from the current security parameter set to obtain EVEK, obtain vkek_version_length_minus1 and vkek_version from the current security parameter set, obtain VKEK based on vkek_version, obtain the decryption algorithm marked with vek_encryption_type from the security parameter set, and use the algorithm to decrypt EVEK with VKEK to obtain VEK;

[0218] Step 5: If iv_flag is 1, obtain iv_length_minus1 and iv in the security parameter set to obtain IV.

[0219] S402: Decrypt the encrypted NAL unit corresponding to the security parameter set using the encryption method specified by the security parameter set.

[0220] The encrypted data unit is decrypted according to the algorithm adopted by the encryption method specified in the security parameter set to obtain a decrypted data unit.

[0221] Taking the encrypted data unit as a NAL unit as an example, the decryption terminal 220 extracts the encrypted RBSP data from the encrypted NAL unit, decrypts the encrypted RBSP data using the video encryption key specified in the security parameter set to obtain the decrypted RBSP data, and finally concatenates the NAL unit header and the decrypted RBSP data to obtain the decrypted NAL unit. After extracting the encrypted RBSP data, if the encrypted RBSP data has an anti-counterfeiting start code, the anti-counterfeiting start code of the encrypted RBSP data is removed.

[0222] For a security parameter set, decrypt the corresponding encrypted NAL unit.

[0223] As a possible implementation manner, one or more NAL units whose encryption_idc is set to sec_para_set_id in the current security parameter set are decrypted in a decryption basic unit.

[0224] Combined with the semantic definitions of the NAL unit and security parameter set RBSP, the decryption steps of the encrypted NAL unit can be as follows:

[0225] Step 1, determine the encryption level of each NAL unit that needs to be decrypted: if encryption_level_mode is 0, then all NAL unit RBSPs are decrypted; if encryption_level_mode is 1, and the NAL type of the NAL unit is a coded slice, then its RBSP is partially decrypted; if encryption_level_mode is 1, and the NAL type of the NAL unit is not a coded slice, then all its RBSPs are decrypted; if encryption_level_mode is 2, and the NAL type of the NAL unit is a coded slice or extended data, then its RBSP is partially decrypted; if encryption_level_mode is 2, and the NAL type of the NAL unit is not a coded slice or extended data, then all its RBSPs are decrypted;

[0226] Step 2. Determine the encrypted data length of each NAL unit that needs to be decrypted: For each NAL unit that needs to be decrypted, calculate the encrypted byte length of the NAL unit based on the encryption_level_mode value, its NAL type, and the RBSP length of the NAL unit. This length does not exceed the RBSP data length minus one. If the RBSP of the NAL unit is fully decrypted, the encrypted data length is the RBSP data length minus one. If the RBSP of the NAL unit is partially decrypted, the corresponding encrypted data length is determined by encryption_num_minus1 and encryption_base_byte. If the data length is greater than the RBSP data length minus one, the encrypted data length is the RBSP data length minus one.

[0227] Step 3, determining the data to be decrypted according to the encrypted data length: if there is only one NAL unit in the decryption basic unit, obtain the data of the pre-RBSP encrypted data length bytes of the NAL unit according to its encrypted byte length for decryption, and retain the remaining unencrypted data of the RBSP; if there are multiple NAL units in the decryption basic unit, obtain the data of the pre-RBSP encrypted data length bytes of each NAL unit according to the encrypted byte length of each NAL unit, retain the remaining unencrypted data of each RBSP, splice the RBSP encrypted part data of these NAL units together in bit stream order for decryption, and record the length of each RBSP encrypted part data;

[0228] Step 4: Decrypt the encrypted data: Use the algorithm marked with encryption_type in the security parameter set and VEK to decrypt the data to obtain the decrypted data. The initialization IV used for decryption is the IV obtained from the security parameter set.

[0229] S403: Obtain decrypted RBSP data.

[0230] If there is only one NAL unit in the decryption basic unit, directly concatenate the decrypted data with the remaining unencrypted data of the retained RBSP to obtain the decrypted RBSP data; if there are multiple NAL units in the decryption basic unit, split the decrypted data according to the length of each recorded RBSP encrypted part data to obtain the partial RBSP after decryption of each encrypted part RBSP, and concatenate them with the remaining unencrypted data of the RBSP corresponding to the same NAL unit in turn to obtain the decrypted RBSPs.

[0231] As a possible implementation method, after obtaining the encrypted RBSP data, the decrypted RBSP is processed by adding an anti-counterfeiting start code and combined with the corresponding NAL unit header to obtain a complete decrypted NAL unit.

[0232] In a possible embodiment of the present application, the video encryption key, the video key encryption key, etc. are symmetric encryption keys. The encryption end 210 and the decryption end 220 can use the same key to encrypt and decrypt data. The specific encryption and decryption methods can be any symmetric encryption method, which will not be repeated here.

[0233] In some possible embodiments, a subsequent decoder directly processes the decrypted RBSP data and does not need to restore the decrypted RBSP data to a decrypted NAL unit, so it is not necessary to obtain a complete decrypted NAL unit.

[0234] In some possible embodiments, when the decrypted RBSP data does not need to be restored to the decrypted NAL unit, there is no need to add an anti-counterfeiting start code to the decrypted RBSP data of the decrypted NAL unit.

[0235] In some possible embodiments, the decryption end 220 uses the decrypted RBSP data, that is, the decrypted image, as a reference image for subsequent image decoding, and this process will not be described in detail here.

[0236] In combination with the encryption method shown in FIG3 and the decryption method shown in FIG4 , the encryption method provided by the present application separately encrypts the data units of the knowledge image and the display image during the encryption process of the compressed video bitstream, and independently generates a security parameter set acting on the knowledge image and a security parameter set acting on the display image, and the security parameter set acting on the knowledge image and the security parameter set acting on the display image are independent of each other. In this way, the compressed video bitstream carries a security parameter set acting on the knowledge image, so that the decryption end can separately decrypt the encrypted data unit of the knowledge image according to the security parameter set of the knowledge image. Compared with the unified encryption and decryption for the display image and the knowledge image, the data unit of the display image and the data unit of the knowledge image use different independent security parameter sets respectively, and there is no need to ensure that the knowledge image and the random access segment where the knowledge image is located adopt the same security parameter set constraint, thereby reducing the complexity of the security parameter set. At the same time, during the knowledge image editing process, if the knowledge image and the random access segment in which it is located are constrained to use the same security parameter set, while the random access segment in which the edited knowledge image is located may use a different security parameter set, the above-mentioned encryption method provided in this application solves the contradiction that the security parameter set of the edited knowledge image cannot meet the constraint that the knowledge image and the random access segment in which it is located use the same security parameter set by encrypting and decrypting the data units of the knowledge image separately.

[0237] Referring to FIG. 5 , illustratively, the encryption device 500 includes:

[0238] Generation module 501, for generating a security parameter set; the security parameter set includes a knowledge image identifier and a security parameter set identifier, the knowledge image identifier is used to indicate that the security parameter set acts on a display image or a knowledge image, and the security parameter set identifier is used to distinguish different security parameter sets acting on the same random access segment or knowledge image access unit;

[0239] An encryption module 502 is configured to encrypt the network abstraction layer NAL unit to be encrypted corresponding to the security parameter set using an encryption method specified by the security parameter set;

[0240] The acquisition module 503 is used to obtain the encrypted NAL unit; the NAL unit includes a NAL unit header, the NAL unit header includes an encryption flag, and the encryption flag is a security parameter set identifier;

[0241] The output module 504 is configured to output a compressed video bit stream; the compressed video bit stream includes the encrypted NAL unit and the security parameter set.

[0242] Exemplarily, when the knowledge image identifier is a first value, it indicates that the security parameter set acts on the knowledge image; and when the knowledge image identifier is a second value, it indicates that the security parameter set acts on the display image.

[0243] Exemplarily, the security parameter set further includes an encryption basic unit, which is used to indicate that encryption is performed in units of NAL units, access units AUs, or layer units LUs.

[0244] Exemplarily, the output module 504 is further configured to: pack the security parameter set into a security parameter set NAL unit; and add the security parameter set NAL unit before the picture sequence parameter set NAL unit.

[0245] Exemplarily, the encryption module 502 is also used to: restore the encrypted data to the encrypted original byte sequence payload RBSP data; splice the NAL unit header and the encrypted RBSP data; set the encryption flag of the NAL unit header to the value of the security parameter set identifier in the security parameter set corresponding to the encrypted NAL unit to obtain the encrypted NAL unit.

[0246] Exemplarily, the encryption module 502 is further configured to add an anti-counterfeiting start code to the encrypted RBSP data.

[0247] Exemplarily, the knowledge image is a coded image in which each frame corresponds to a sequence parameter set and the knowledge bit stream flag in the corresponding sequence set parameter is 1; the display image is a reference knowledge image, an instant decoding refresh image, a P image, a B image or a random access point I frame image output by the decoder after decoding.

[0248] When the encryption device 500 implements any of the encryption methods shown in the aforementioned figures through software, the encryption device 500 and its various units may also be software modules. The encryption method is implemented by invoking the software module via a processor. The processor may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or a programmable logic device (PLD). The PLD may be a complex programmable logical device (CPLD), a field programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.

[0249] It can be understood that the encryption device 500 shown in FIG5 is only an example provided in this embodiment. The encryption device 500 may include more or fewer units according to different encryption and decryption processes, and this application does not limit this.

[0250] When the encryption device 500 is implemented via hardware, the hardware can be implemented via a processor or a chip system. The chip system includes one or more chips, each of which includes an interface circuit and a control circuit. The interface circuit is used to receive data from other devices outside the chip and transmit it to the control circuit, or to send data from the control circuit to other devices outside the chip. The control circuit and interface circuit are used to implement the method of any possible implementation method in the above embodiments through logic circuits or executing code instructions. The beneficial effects can be found in the description of any aspect of the above embodiments and will not be repeated here.

[0251] It is understood that the processor in the embodiments of the present application may be a CPU, or other general-purpose processor, digital signal processor (DSP), ASIC, FPGA or other programmable logic device, transistor logic device, hardware component or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.

[0252] Figure 6 is a schematic diagram of an exemplary decryption device. The schematic diagram of the decryption device can be used to execute the method of the aforementioned embodiment. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding method provided above, and will not be repeated here.

[0253] Referring to FIG. 6 , illustratively, the decryption device 600 includes:

[0254] Input module 601, used for inputting compressed video bit stream;

[0255] An acquisition module 602 is configured to acquire a security parameter set from a compressed video bitstream; the security parameter set includes a knowledge image identifier and a security parameter set identifier, wherein the knowledge image identifier indicates whether the security parameter set applies to a display image or a knowledge image, and the security parameter set identifier is used to distinguish different security parameter sets that apply to the same random access segment or knowledge image access unit.

[0256] The decryption module 603 is configured to decrypt the encrypted NAL unit corresponding to the security parameter set using the encryption method specified by the security parameter set; the encryption flag of the encrypted NAL unit is the security parameter set identifier;

[0257] The decryption module 603 is further configured to obtain the decrypted RBSP data.

[0258] Exemplarily, when the knowledge image identifier is a first value, it indicates that the security parameter set acts on the knowledge image; and when the knowledge image identifier is a second value, it indicates that the security parameter set acts on the display image.

[0259] Exemplarily, the security parameter set further includes an encryption basic unit, which is used to indicate that encryption is performed in units of NAL units, access units AUs, or layer units LUs.

[0260] Exemplarily, the decryption module 603 is further configured to add an anti-counterfeiting start code to the decrypted RBSP data.

[0261] Exemplarily, the decryption module 603 is further configured to: concatenate the NAL unit header and the decrypted RBSP data to obtain a decrypted NAL unit.

[0262] Exemplarily, the knowledge image is a coded image in which each frame corresponds to a sequence parameter set and the knowledge bit stream flag in the corresponding sequence set parameter is 1; the display image is a reference knowledge image, an instant decoding refresh image, a P image, a B image or a random access point I frame image output by the decoder after decoding.

[0263] When decryption device 600 implements any of the decryption methods shown in the aforementioned figures via software, decryption device 600 and its various units may also be software modules. A processor invokes the software modules to implement the aforementioned decryption methods. The processor may be a CPU, an ASIC, or a PLD. The PLD may be a CPLD, an FPGA, a GAL, or any combination thereof.

[0264] It can be understood that the decryption device 600 shown in FIG6 is only an example provided in this embodiment. The decryption device 600 may include more or fewer units according to different encryption and decryption processes, and this application does not limit this.

[0265] When decryption device 600 is implemented via hardware, the hardware can be implemented via a processor or a chip system. The chip system includes one or more chips, each of which includes an interface circuit and a control circuit. The interface circuit is used to receive data from devices outside the chip and transmit it to the control circuit, or to send data from the control circuit to devices outside the chip. The control circuit and interface circuit implement the method of any possible implementation method in the above embodiments through logic circuits or executing code instructions. The beneficial effects can be found in the description of any aspect of the above embodiments and will not be repeated here.

[0266] It is understood that the processor in the embodiments of the present application may be a CPU, or other general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, transistor logic device, hardware component, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.

[0267] In one example, FIG7 shows a schematic block diagram of a device 700 according to an embodiment of the present application. The device 700 may include: a processor 701 and a transceiver / transceiver pin 702 , and optionally, a memory 703 .

[0268] The various components of the device 700 are coupled together via a bus 704, wherein the bus 704 includes, in addition to a data bus, a power bus, a control bus, and a status signal bus. However, for the sake of clarity, the various buses are collectively referred to as bus 704 in the figure.

[0269] Optionally, the memory 703 may be used to store instructions in the aforementioned method embodiment. The processor 701 may be used to execute the instructions in the memory 703 and control the receiving pin to receive a signal and control the transmitting pin to send a signal.

[0270] The apparatus 700 may be the electronic device or a chip of the electronic device in the above method embodiment.

[0271] Among them, all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module and will not be repeated here.

[0272] The present application also provides a chip including one or more interface circuits and one or more processors. The one or more processors receive or send data via the one or more interface circuits. When the one or more processors execute computer instructions, the steps of the above-mentioned related methods are implemented. The interface circuit is a transceiver / transceiver pin 902.

[0273] This embodiment also provides a non-transitory computer-readable storage medium, which stores computer instructions. When the computer instructions are executed on an electronic device, the electronic device executes the above-mentioned related method steps to implement the method in the above-mentioned embodiment.

[0274] This embodiment further provides a computer program product, which includes computer instructions. When the computer instructions are executed by a computer or a processor, the computer executes the above-mentioned related steps to implement the method in the above-mentioned embodiment.

[0275] In addition, an embodiment of the present application also provides a device, which can specifically be a chip, component or module, and the device may include a connected processor and memory; wherein the memory is used to store computer-executable instructions, and when the device is running, the processor can execute the computer-executable instructions stored in the memory to enable the chip to execute the methods in the above-mentioned method embodiments.

[0276] Among them, the electronic device, non-transitory computer-readable storage medium, computer program product or chip provided in this embodiment are all used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding methods provided above, and will not be repeated here.

[0277] Through the description of the above implementation methods, technical personnel in the relevant field can understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.

[0278] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0279] Units described as separate components may or may not be physically separate, and components shown as units may be one physical unit or multiple physical units, that is, they may be located in one place or distributed in multiple places. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.

[0280] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0281] Any content of each embodiment of this application, as well as any content of the same embodiment, can be freely combined. Any combination of the above content is within the scope of this application.

[0282] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a non-transitory computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a device (which can be a single-chip microcomputer, chip, etc.) or a processor to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0283] The steps of the method or algorithm described in conjunction with the disclosure of the embodiments of the present application can be implemented in a hardware manner, or can be implemented by a processor executing a software instruction. The software instruction can be composed of corresponding software modules, and the software module can be stored in a random access memory (Random Access Memory, RAM), a flash memory, a read-only memory (Read Only Memory, ROM), an erasable programmable read-only memory (Erasable Programmable ROM, EPROM), an electrically erasable programmable read-only memory (Electrically EPROM, EEPROM), a register, a hard disk, a mobile hard disk, a read-only compact disc (CD-ROM) or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and can write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an ASIC.

[0284] Those skilled in the art will appreciate that, in one or more of the above examples, the functions described in the embodiments of the present application can be implemented using hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. Computer-readable media include non-transitory computer-readable storage media and communication media, wherein the communication media includes any medium that facilitates the transmission of a computer program from one place to another. The storage medium can be any available medium that a general-purpose or special-purpose computer can access.

[0285] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms without departing from the purpose of this application and the scope of protection of the claims, all of which are within the protection of this application.

Claims

1. A cryptographic method, characterized in that, The method includes: Generating a security parameter set; the security parameter set includes a knowledge image identifier and a security parameter set identifier, the knowledge image identifier is used to indicate that the security parameter set acts on a display image or a knowledge image, and the security parameter set identifier is used to distinguish different security parameter sets acting on the same random access segment (RAS) or knowledge image access unit; Using the encryption method specified by the security parameter set to encrypt the network abstraction layer (NAL) unit to be encrypted corresponding to the security parameter set; Obtaining the encrypted NAL unit; the encrypted NAL unit includes a NAL unit header, and the NAL unit header includes an encryption flag, and the encryption flag is the security parameter set identifier; Outputting a compressed video bitstream; the compressed video bitstream includes the encrypted NAL unit and the security parameter set.

2. The method according to claim 1, wherein When the knowledge image identifier takes a first value, it indicates that the security parameter set acts on a knowledge image, and when the knowledge image identifier takes a second value, it indicates that the security parameter set acts on a display image.

3. The method according to claim 1 or 2, characterized in that, The security parameter set further includes an encryption basic unit, and the encryption basic unit is used to indicate encryption in units of a NAL unit, an access unit (AU), or a layer unit (LU).

4. The method according to any one of claims 1-3, characterized in that After generating the security parameter set, the method further includes: Packing the security parameter set into a security parameter set NAL unit; Adding the security parameter set NAL unit before the picture sequence parameter set NAL unit.

5. The method according to any one of claims 1 to 4, characterized in that The obtaining of the encrypted NAL unit includes: Restoring the encrypted data to encrypted raw byte sequence payload (RBSP) data; Concatenating the NAL unit header and the encrypted RBSP data; Setting the encryption flag of the NAL unit header to the value of the security parameter set identifier in the security parameter set corresponding to the encrypted NAL unit to obtain the encrypted NAL unit.

6. The method according to claim 5, wherein After restoring the encrypted data to encrypted RBSP data, the method further includes: Adding an anti-counterfeiting start code to the encrypted RBSP data.

7. The method according to any one of claims 1-6, characterized in that, The knowledge image is an encoded image with a knowledge bitstream flag of 1 in the sequence parameter set corresponding to each frame of image, and the display image is a reference knowledge (RL) image, an instant decoding refresh (IDR) image, a P image, a B image, or a random access point I-frame (RAPI) image output by the decoder after decoding the reconstructed image.

8. A decryption method, characterized in that, It includes: Inputting a compressed video bitstream; Obtaining the security parameter set in the compressed video bitstream; The security parameter set includes a knowledge image identifier and a security parameter set identifier, the knowledge image identifier is used to indicate that the security parameter set acts on a display image or a knowledge image, and the security parameter set identifier is used to distinguish different security parameter sets acting on the same random access segment or knowledge image access unit; Using the encryption method specified by the security parameter set to decrypt the encrypted NAL unit corresponding to the security parameter set; the encryption flag of the encrypted NAL unit is the security parameter set identifier; Obtaining the decrypted RBSP data.

9. The method according to claim 8, wherein When the knowledge image identifier takes a first value, it indicates that the security parameter set acts on the knowledge image; when the knowledge image identifier takes a second value, it indicates that the security parameter set acts on the display image.

10. The method according to claim 8 or 9, characterized in that, The security parameter set further includes an encryption basic unit, and the encryption basic unit is used to indicate encryption in units of NAL units, access units AU, or layer units LU.

11. The method according to any one of claims 8 to 10, characterized in that After obtaining the decrypted RBSP data, the method further includes: Adding an anti-counterfeiting start code to the decrypted RBSP data.

12. The method according to any one of claims 8-11, characterized in that, After obtaining the decrypted RBSP data, the method further includes: Concatenating the NAL unit header and the decrypted RBSP data to obtain a decrypted NAL unit.

13. A compressed video bitstream, characterized in that, The compressed video bitstream includes: Encrypted NAL units and a security parameter set; Wherein, the security parameter set includes a knowledge image identifier and a security parameter set identifier. The knowledge image identifier is used to indicate that the security parameter set acts on the display image or the knowledge image, and the security parameter set identifier is used to distinguish different security parameter sets acting on the same random access segment or knowledge image access unit. The encrypted NAL unit includes a NAL unit header, and the encrypted NAL unit header includes an encryption flag, and the encryption flag is the security parameter set identifier.

14. The compressed video bitstream according to claim 13, wherein, When the knowledge image identifier takes a first value, it indicates that the security parameter set acts on the knowledge image; when the knowledge image identifier takes a second value, it indicates that the security parameter set acts on the display image.

15. The compressed video bitstream according to claim 13 or 14, characterized in that, The security parameter set further includes an encryption basic unit, and the encryption basic unit is used to indicate encryption in units of NAL units, access units AU, or layer units LU.

16. The compressed video bitstream according to any one of claims 13-15, characterized in that, The knowledge image is an encoded image with a sequence parameter set corresponding to each frame image and a knowledge bitstream flag of 1 in the corresponding sequence set parameters. The display image is a reference knowledge RL image, an instantly decoded refresh IDR image, a P image, a B image, or a random access point I-frame RAPI image output by the decoder after decoding the reconstructed image.

17. An encryption device, characterized in that, It includes: A generation module for generating a security parameter set; The security parameter set includes a knowledge image identifier and a security parameter set identifier. The knowledge image identifier is used to indicate that the security parameter set acts on the display image or the knowledge image, and the security parameter set identifier is used to distinguish different security parameter sets acting on the same random access segment or knowledge image access unit; An encryption module for encrypting the network abstraction layer NAL unit to be encrypted corresponding to the security parameter set by using the encryption method specified by the security parameter set; An acquisition module for acquiring the encrypted NAL unit; the encrypted NAL unit includes a NAL unit header, and the NAL unit header includes an encryption flag, and the encryption flag is the security parameter set identifier; An output module for outputting a compressed video bitstream; the compressed video bitstream includes the encrypted NAL unit and the security parameter set.

18. The device according to claim 17, characterized in that, When the knowledge image identifier takes a first value, it indicates that the security parameter set acts on the knowledge image; when the knowledge image identifier takes a second value, it indicates that the security parameter set acts on the display image.

19. The device according to claim 17 or 18, characterized in that, The security parameter set further includes an encryption basic unit, which is used to indicate encryption in units of NAL units, access units AU, or layer units LU.

20. The device according to any one of claims 17 - 19, characterized in that, The output module is further used for: packing the security parameter set into a security parameter set NAL unit; adding the security parameter set NAL unit before the picture sequence parameter set NAL unit.

21. The device according to any one of claims 17-20, characterized in that, The encryption module is further used for: restoring the encrypted data to the encrypted original byte sequence payload RBSP data; concatenating the NAL unit header and the encrypted RBSP data; setting the encryption flag of the NAL unit header to the value of the security parameter set identifier in the security parameter set corresponding to the encrypted NAL unit, to obtain the encrypted NAL unit.

22. The device according to claim 21, wherein, The encryption module is further used for: adding an anti-counterfeiting start code to the encrypted RBSP data.

23. The device according to any one of claims 17-22, characterized in that, The knowledge picture is an encoded picture in which each frame of picture corresponds to a sequence parameter set, and the knowledge bitstream flag in the corresponding sequence set parameter is 1. The display picture is a reference knowledge RL picture, an instant decoding refresh IDR picture, a P picture, a B picture, or a random access point I-frame RAPI picture output by the decoder after decoding the reconstructed picture.

24. A decryption device, characterized in that, including: an input module, which is used to input a compressed video bitstream; an acquisition module, which is used to acquire the security parameter set in the compressed video bitstream; The security parameter set includes a knowledge picture identifier and a security parameter set identifier. The knowledge picture identifier is used to indicate whether the security parameter set acts on a display picture or a knowledge picture. The security parameter set identifier is used to distinguish different security parameter sets acting on the same random access segment or knowledge picture access unit; a decryption module, which is used to decrypt the encrypted NAL unit corresponding to the security parameter set by using the encryption method specified by the security parameter set; the encryption flag of the encrypted NAL unit is the security parameter set identifier; The decryption module is further used to obtain the decrypted RBSP data.

25. The device according to claim 24, characterized in that, When the knowledge picture identifier takes a first value, it indicates that the security parameter set acts on a knowledge picture. When the knowledge picture identifier takes a second value, it indicates that the security parameter set acts on a display picture.

26. The device according to claim 24 or 25, characterized in that The security parameter set further includes an encryption basic unit, which is used to indicate encryption in units of NAL units, access units AU, or layer units LU.

27. The device according to any one of claims 24-26, characterized in that, The decryption module is further used for: adding an anti-counterfeiting start code to the decrypted RBSP data.

28. The device according to any one of claims 24-27, characterized in that, The decryption module is further used for: concatenating the NAL unit header and the decrypted RBSP data to obtain the decrypted NAL unit.

29. The device according to any one of claims 24-28, characterized in that, The knowledge picture is an encoded picture in which each frame of picture corresponds to a sequence parameter set, and the knowledge bitstream flag in the corresponding sequence set parameter is 1. The display picture is a reference knowledge RL picture, an instant decoding refresh IDR picture, a P picture, a B picture, or a random access point I-frame RAPI picture output by the decoder after decoding the reconstructed picture.

30. A coding device, comprising at least one processor and a memory, characterized in that, The at least one processor executes the program or instruction stored in the memory, so that the encoding device implements the method described in any one of claims 1-7 above.

31. A decoding device, comprising at least one processor and a memory, characterized in that, The at least one processor executes a program or instructions stored in the memory, so that the encoding device implements the method according to any one of claims 8-12 above.

32. A non-transitory computer-readable storage medium for storing a computer program, characterized in that, When the computer program runs on a computer or a processor, the computer or the processor implements the method according to any one of claims 1-7 above.

33. A computer program product, the computer program product comprising instructions, characterized in that, When the instructions run on a computer or a processor, the computer or the processor implements the method according to any one of claims 8-12 above.

Citation Information

Patent Citations

  • Video signal source encryption and decryption system and method based on AVS2 entropy coding of block encryption

    CN112533001A

  • Method and System of NAL Unit Header Structure for Signaling New Elements

    US20200177923A1

  • A method, an apparatus and a computer program product for video encoding and video decoding

    WO2023073283A1