Signature method, authentication method, and apparatus
By independently generating the security parameter sets of knowledge images and display images, the problem of consistency complexity of security parameter sets in audio and video content signatures is solved, and independent signature authentication is realized, reducing complexity.
Patent Information
- Application Number
- PCT/CN2024/118918
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-07
- Filing Date
- 2024-09-13
- Publication Date
- 2025-07-31
AI Technical Summary
In the prior art, it is necessary to ensure that the security parameter sets of knowledge images and random access fragments are consistent during the signature process of audio and video content, which increases the complexity of the security parameter set.
The security parameter sets that are independently generated for the knowledge image and the display image are signed separately to ensure that the knowledge image can also meet the independent authentication requirements of the security parameter set after editing.
It reduces the complexity of the security parameter set, solves the constraints of the inability to meet the consistent security parameter set after knowledge image editing, and realizes independent signature authentication.
Smart Images

Figure CN2024118918_31072025_PF_FP_ABST
Abstract
Description
Signature method, authentication method and device
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on January 24, 2024, with application number 202410103225.3 and application name “A signature method, authentication method and device”, and the Chinese patent application filed with the State Intellectual Property Office on February 7, 2024, with application number 202410176180.2 and application name “A signature method, authentication method and device”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The embodiments of the present application relate to the media field, and in particular to a signature method, an authentication method and a device. Background Art
[0003] Many audio and video encoding and decoding scenarios (for example, surveillance, live broadcast, on-demand, etc.) have certain requirements for the authenticity and integrity of audio and video content. Therefore, in order to ensure the security of audio and video content during transmission and prevent the audio and video content from being tampered with during transmission, the audio and video content needs to be signed.
[0004] Currently, the process for signing audio and video content involves generating digests corresponding to the access units within the audio and video content. These digests are then signed using a digital signature algorithm, and the signatures are then incorporated into the content. The current standard uniformly signs and authenticates both the output image and the library image. This requires ensuring that the library image and the random access segment (RAS) containing the library image adhere to the same security parameter set, increasing the complexity of the security parameter set.
[0005] Summary of the Invention
[0006] The present application provides a signature method, an authentication method and an apparatus to solve the problem that during the signing process, it is necessary to ensure that the knowledge image and the random access fragment in which the knowledge image is located use the same security parameter set constraint, which increases the complexity of the security parameter set.
[0007] This application adopts the following technical solution.
[0008] In a first aspect, embodiments of the present application provide a signing method. The signing method is executed by a signing device or a chip in the signing device, such as a mobile phone or a computer. Exemplarily, the method includes: generating a security parameter set; the security parameter set includes a knowledge image identifier, which is used to indicate that the security parameter set acts on a knowledge image or a display image; calculating summary data of the security parameter set corresponding to the display image or the knowledge image; signing the summary data to obtain signature data; generating authentication data of the security parameter set corresponding to the display image or the knowledge image; the authentication data includes signature data; and adding the authentication data and the security parameter set to a compressed video bitstream.
[0009] In this application, during the signing process of the compressed video bitstream, the data units of the knowledge image and the display image are signed separately, and a security parameter set is generated for the knowledge image. The security parameter set for the knowledge image and the security parameter set for the display image are independent of each other. In this way, the compressed video bitstream carries the security parameter set for the knowledge image, enabling the authentication end to independently authenticate the data units of the knowledge image based on the security parameter set of the knowledge image. Compared to performing unified signature authentication for the display image and the knowledge image, the data units of the display image and the data units of the knowledge image use different independent security parameter sets, eliminating the need to ensure that the knowledge image and the random access segment in which the knowledge image resides use the same security parameter set, thereby reducing the complexity of the security parameter set. Furthermore, during the knowledge image editing process, if the knowledge image and the random access segment in which it resides are constrained to use the same security parameter set, the random access segment in which the edited knowledge image resides may use a different security parameter set. The encryption method provided in this application resolves the contradiction that the security parameter set of the edited knowledge image cannot meet the constraint that the knowledge image and the random access segment in which it resides use the same security parameter set by independently signing and authenticating the data units of the knowledge image.
[0010] In one possible implementation, a first value for the knowledge image identifier indicates that the security parameter set applies to the knowledge image, while a second value for the knowledge image identifier indicates that the security parameter set applies to the display image. Thus, for data units of the knowledge image and data units of the display image, the authenticator can use the knowledge image identifier to identify whether one or more security parameter sets in the compressed video bitstream apply to the knowledge image data unit or the display image data unit, respectively. This allows for independent signature authentication using independent security parameter sets to indicate the knowledge image data unit.
[0011] In one possible implementation, the authentication data is located within or after the last access unit currently being authenticated, before the next authentication data NAL unit, and before the next random access point access unit. This allows the authenticator to extract the security parameter set corresponding to the knowledge image from the random access segment to which the currently authenticated access unit belongs when authenticating the currently authenticated access unit, authenticate the knowledge image, and use the knowledge image as a reference image in inter-frame prediction.
[0012] In one possible implementation, the knowledge image is a display knowledge image, and the interval between the access units of the authentication data and the display knowledge image does not exceed a number of access units equal to the hash period. This ensures that the access units of the display knowledge image are within the access units of the authentication data of the display knowledge image that participate in signature authentication, ensuring that the display knowledge image can be independently signed and authenticated as indicated by the security parameter set.
[0013] In a possible implementation, the knowledge image is a non-display knowledge image, and the authentication data is located in the access unit where the last non-display knowledge image coding slice is located.
[0014] In one possible implementation, the security parameter set also includes a security parameter set identifier, which is used to distinguish different security parameter sets applicable to the same random access segment or knowledge image access unit. In this way, if the same random access segment contains multiple security parameter sets, the authenticator can identify the security parameter set corresponding to the knowledge image access unit based on the security parameter set identifier and use that security parameter set to independently authenticate the knowledge image access unit.
[0015] In a possible implementation, the security parameter set further includes a hash period, where the hash period is used to indicate the maximum number of access units in the bitstream segment.
[0016] In a possible implementation, the authentication data includes summary data, which is used to authenticate the display image or the knowledge image.
[0017] In one possible implementation, the knowledge image is a coded image in which each frame corresponds to a sequence parameter set and the knowledge bit stream flag in the corresponding sequence set parameter is 1. The display image is a reference knowledge image (refrence library picture), an immediate decoding refresh (refrence library picture, IDR) picture, a P picture, a B picture, or a random access point I frame (RAPI) picture output by the decoder after decoding.
[0018] In a second aspect, an embodiment of the present application provides a compressed video bit stream, which includes authentication data and a security parameter set; wherein the security parameter set includes a knowledge image identifier, which is used to indicate that the security parameter set acts on the knowledge image or the display image, and the authentication data includes signature data corresponding to the summary data, and the summary data is the summary data of the security parameter set corresponding to the display image or the knowledge image.
[0019] In a possible implementation, when the knowledge image identifier is a first value, it indicates that the security parameter set acts on the knowledge image; and when the knowledge image identifier is a second value, it indicates that the security parameter set acts on the display image.
[0020] In a possible implementation, the authentication data is located in or after the last access unit of the current authentication, before the next authentication data NAL unit, and before the next random access point access unit.
[0021] In a possible implementation, the knowledge image is a display knowledge image, and the interval between the authentication data and the access unit of the display knowledge image does not exceed a number of access units equal to the hash period value.
[0022] In a possible implementation, the knowledge image is a non-display knowledge image, and the authentication data is located in the access unit where the last non-display knowledge image coding slice is located.
[0023] In a possible implementation, the security parameter set further includes a security parameter set identifier, which is used to distinguish different security parameter sets acting on the same random access segment or knowledge image access unit.
[0024] In a possible implementation, the security parameter set further includes a hash period, where the hash period is used to indicate the maximum number of access units in the bitstream segment.
[0025] In a possible implementation, the authentication data includes summary data, which is used to authenticate the display image or the knowledge image.
[0026] In one possible implementation, the knowledge image is a coded image in which each frame corresponds to a sequence parameter set and the knowledge bit stream flag in the corresponding sequence set parameter is 1. The display image is a reference knowledge image, an instant decoding refresh image, a P image, a B image, or a random access point I frame image output by the decoder after decoding.
[0027] In a third aspect, an embodiment of the present application provides an authentication method, which is executed by an authentication device or a chip in the authentication device, such as a mobile phone or a computer. Exemplarily, the method includes: inputting a compressed video bitstream; the compressed video bitstream includes authentication data and a security parameter set, the authentication data includes signature data, the signature data is obtained by signing the summary data, the summary data is a summary of the security parameter set corresponding to the display image or knowledge image, the security parameter set includes a knowledge image identifier, and the knowledge image identifier is used to indicate that the security parameter set acts on the knowledge image or the display image; calculating the summary data of the image corresponding to the security parameter set; and authenticating the display image or the knowledge image based on the calculated summary data and the authentication data.
[0028] In a possible implementation, when the knowledge image identifier is a first value, it indicates that the security parameter set acts on the knowledge image; and when the knowledge image identifier is a second value, it indicates that the security parameter set acts on the display image.
[0029] In a possible implementation, the authentication data is located in or after the last access unit of the current authentication, before the next authentication data NAL unit, and before the next random access point access unit.
[0030] In a possible implementation, the knowledge image is a display knowledge image, and the interval between the authentication data and the access unit of the display knowledge image does not exceed a number of access units equal to the hash period value.
[0031] In a possible implementation, the knowledge image is a non-display knowledge image, and the authentication data is located in the access unit where the last non-display knowledge image coding slice is located.
[0032] In a possible implementation, the security parameter set further includes a security parameter set identifier, which is used to distinguish different security parameter sets acting on the same random access segment or knowledge image access unit.
[0033] In a possible implementation, the security parameter set further includes a hash period, where the hash period is used to indicate the maximum number of access units in the bitstream segment.
[0034] In a possible implementation, the authentication data includes summary data, which is used to authenticate the display image or the knowledge image.
[0035] In one possible implementation, the knowledge image is a coded image in which each frame corresponds to a sequence parameter set and the knowledge bit stream flag in the corresponding sequence set parameter is 1. The display image is a reference knowledge image, an instant decoding refresh image, a P image, a B image, or a random access point I frame image output by the decoder after decoding.
[0036] In a fourth aspect, the present application provides a signature device, which includes a module for executing the method of the first aspect or any possible implementation of the first aspect.
[0037] In a fifth aspect, the present application provides an authentication device, which includes a module for executing the method of the third aspect or any possible implementation of the third aspect.
[0038] In a sixth aspect, embodiments of the present application provide an electronic device comprising: a memory and a processor, the memory being coupled to the processor; the memory storing program instructions, which, when executed by the processor, cause the electronic device to execute the signing method of the first aspect or any possible implementation of the first aspect, or to execute the authentication method of the third aspect or any possible implementation of the third aspect.
[0039] In a seventh aspect, embodiments of the present application provide a chip comprising one or more interface circuits and one or more processors; the one or more processors receive or send data via the one or more interface circuits, and when the one or more processors execute computer instructions, the steps of the signature method in the first aspect or any possible implementation of the first aspect are executed, or the steps of the authentication method in the third aspect or any possible implementation of the third aspect are executed.
[0040] In an eighth aspect, embodiments of the present application provide a non-transitory computer-readable storage medium. The non-transitory computer-readable storage medium stores a computer program that, when executed on a computer or processor, causes the computer or processor to execute the signing method of the first aspect or any possible implementation of the first aspect, or to execute the authentication method of the third aspect or any possible implementation of the third aspect.
[0041] In a ninth aspect, embodiments of the present application provide a computer program product. The computer program product includes computer instructions that, when executed by a computer or a processor, cause the computer or processor to perform the signing method of the first aspect or any possible implementation of the first aspect, or to perform the authentication method of the third aspect or any possible implementation of the third aspect.
[0042] In a tenth aspect, embodiments of the present application provide a non-transitory computer-readable storage medium storing a compressed video bit stream according to the second aspect or any possible implementation of the second aspect.
[0043] In an eleventh aspect, embodiments of the present application provide a device for storing a bitstream. The device includes: a receiver configured to receive the compressed video bitstream according to the second aspect or any possible implementation of the second aspect; and at least one storage medium configured to store the compressed video bitstream.
[0044] In the twelfth aspect, an embodiment of the present application provides a device for transmitting a code stream, the device comprising: a transmitter and at least one storage medium, the at least one storage medium being used to store the compressed video bit stream in the second aspect or any possible implementation of the second aspect; the transmitter being used to obtain the compressed video bit stream from the storage medium and send the compressed video bit stream to the end-side device through the transmission medium.
[0045] In a thirteenth aspect, an embodiment of the present application provides a system for distributing code streams. The system includes: at least one storage medium for storing at least one compressed video bitstream according to the second aspect or any possible implementation of the second aspect; and a streaming media device for obtaining a target compressed video bitstream from the at least one storage medium and transmitting the target compressed video bitstream to an end-side device, wherein the streaming media device includes a content server or a content distribution server.
[0046] Regarding the beneficial effects of the second to thirteenth aspects, reference may be made to the description of any implementation in the first aspect, which will not be repeated here. Based on the implementations provided in the above aspects, this application can also be further combined to provide more implementations. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] FIG1 is a schematic diagram of an application scenario provided by this application;
[0048] FIG2 is a schematic diagram of the structure of the signature and authentication system provided by this application;
[0049] FIG3a is a schematic diagram of the process of the signature method provided by this application;
[0050] Figure 3b is a schematic diagram of the connection summary provided by this application;
[0051] Figure 3c is a schematic diagram of a treetop summary provided by this application;
[0052] FIG4 is a flow chart of the authentication method provided by this application;
[0053] FIG5 is a schematic diagram of a signature device provided in this application;
[0054] FIG6 is a schematic diagram of an authentication device provided in this application;
[0055] FIG7 is a schematic structural diagram of the electronic device provided in this application. DETAILED DESCRIPTION
[0056] The present application provides a signing method, which includes: generating a security parameter set; the security parameter set includes a knowledge image identifier, which is used to indicate that the security parameter set acts on a knowledge image or a display image; calculating summary data of the security parameter set corresponding to the display image or the knowledge image; signing the summary data to obtain signature data; generating authentication data of the security parameter set corresponding to the display image or the knowledge image; the authentication data includes signature data; and adding the authentication data and the security parameter set to a compressed video bit stream.
[0057] In this application, during the signing process of the compressed video bitstream, the data units of the knowledge image and the display image are signed separately, and a security parameter set is generated for the knowledge image. The security parameter set for the knowledge image and the security parameter set for the display image are independent of each other. In this way, the compressed video bitstream carries the security parameter set for the knowledge image, enabling the authentication end to independently authenticate the data units of the knowledge image based on the security parameter set of the knowledge image. Compared to performing unified signature authentication for the display image and the knowledge image, the data units of the display image and the data units of the knowledge image use different independent security parameter sets, eliminating the need to ensure that the knowledge image and the random access segment in which the knowledge image resides use the same security parameter set, thereby reducing the complexity of the security parameter set. Furthermore, during the knowledge image editing process, if the knowledge image and the random access segment in which it resides are constrained to use the same security parameter set, the random access segment in which the edited knowledge image resides may use a different security parameter set. The encryption method provided in this application resolves the contradiction that the security parameter set of the edited knowledge image cannot meet the constraint that the knowledge image and the random access segment in which it resides use the same security parameter set by independently signing and authenticating the data units of the knowledge image.
[0058] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0059] The term "and / or" in this article is merely a description of the association relationship between associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone.
[0060] In the description and claims of the embodiments of this application, the terms "first" and "second" are used to distinguish different objects, rather than to describe a specific order of objects. For example, the terms "first target object" and "second target object" are used to distinguish different objects, rather than to describe a specific order of objects.
[0061] In the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of this application should not be interpreted as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.
[0062] In the description of the embodiments of this application, unless otherwise specified, "multiple" means two or more. For example, "multiple processing units" means two or more processing units; "multiple systems" means two or more systems.
[0063] The following is an introduction to related technologies.
[0064] bitstream
[0065] A binary data stream formed by encoding image / audio frames. Both NAL unit streams and byte streams can be called bitstreams. For example, the bitstream can be a compressed video bitstream.
[0066] The NAL unit stream format consists of a series of syntax structures called NAL units, which are sorted in decoding order. The decoding order and content of NAL units in a NAL unit stream are constrained.
[0067] A byte stream can be constructed from a NAL unit stream by placing the NAL units in decoding order and appending a start code prefix and a number of zero-valued bytes to each NAL unit to form a bit stream. The NAL unit stream format can be extracted from the bit stream format by searching for a unique start code prefix in the bit stream.
[0068] data unit
[0069] The basic syntax structure of the coded bit stream can be a NAL unit, an access unit, or a layer unit.
[0070] layer unit
[0071] A set of NAL units with the same layer_id value that are related to each other according to specified rules and are continuous in decoding order.
[0072] NAL unit
[0073] A syntax structure that contains an indication of the type of data that follows and the number of bytes it contains (located in the NAL header). The data appears in the form of a Raw Byte Sequence Payload (RBSP), which may also include interspersed security bytes.
[0074] access unit access unit
[0075] A set of NAL units that are related to each other according to specified rules and are consecutive in decoding order.
[0076] It should be noted that, from another perspective, a data unit may also include a coded image.
[0077] coded picture
[0078] The encoded representation of a frame of image.
[0079] Encoded video sequence
[0080] A coded video sequence is the highest-level syntactic structure of a bitstream and contains one or more consecutive access units. A coded video sequence starts with an access unit of an IDR (instantaneous decoding refresh picture) image, an access unit of a RAPI (random access point I picture) image, an access unit of an RL (refrence library picture) pre-knowledge image, or an access unit of a display knowledge image. The end-of-stream NAL unit or the end-of-coded video sequence NAL unit indicates the end of a coded video sequence. Each coded video sequence contains at most one IDR picture, RAPI picture, RL pre-knowledge image, or display knowledge image. The access units are arranged in the bitstream order, and the bitstream order should be the same as the decoding order.
[0081] Security parameter set security parameter set, SEC
[0082] The security parameter set contains the configuration parameters required for encryption and authentication operations on the compressed video bitstream. At the beginning of the decoding process, each security parameter set takes effect when it is received by the decoder and will cause the previously valid security parameter set (if any) to become invalid. The security parameter set NAL unit should be present before the access unit of all random access point (RAP) pictures. The security parameter set NAL unit should be located in the same access unit as the sequence parameter set NAL unit, and the security parameter set NAL unit should be located before the sequence parameter set NAL unit. Therefore, the scope of the security parameter set is the random access segment in the compressed video bitstream where it is located, that is, all AUs in the bitstream from the AU where the security parameter set is located to the next RAP picture.
[0083] library picture
[0084] A reference picture in a non-current bitstream used when decoding the current bitstream. Each frame corresponds to a sequence parameter set, and the corresponding sequence set parameter has the knowledge bitstream flag set to 1. The coded slice NAL unit type of the knowledge picture is 12, 17, or 18, and the knowledge picture is associated with a privacy coded slice.
[0085] Display knowledge image output library picture
[0086] Each frame corresponds to a sequence parameter set, and the corresponding sequence set parameter has a coded image with the knowledge bitstream flag set to 1 and the knowledge image mode index set to 1. The coded slice NAL unit type of the display knowledge image is 17. The display knowledge image is a random access point image, and the display knowledge image that serves as the RL pre-knowledge image is not a random access point image.
[0087] Non-display knowledge image non output library picture
[0088] Each frame corresponds to a sequence parameter set, and the corresponding sequence set parameter has a knowledge bit stream flag of 1 and a knowledge image mode index of 0 or 2. The NAL unit type of the coded slice of the non-display knowledge image is 12 or 18.
[0089] Leading library picture of an RL picture
[0090] A non-displayed knowledge picture that precedes an associated RL picture in the codestream order, or a displayed knowledge picture that appears before an RL picture after bitstream editing, has no access units between the access unit containing the first knowledge picture coding slice of the knowledge picture and the access unit of the associated RL picture. The preceding RL knowledge picture is not a random access point picture.
[0091] Non-leading library picture of an RL picture
[0092] A non-display knowledge picture precedes an associated RL picture in the codestream order. There is at least one access unit of another picture between the access unit containing the first knowledge picture coding slice of the non-display knowledge picture and the access unit of the associated RL picture. The non-RL preceding knowledge picture is not a random access point picture.
[0093] Display image output picture
[0094] After decoding, the decoder reconstructs the image output as RL picture, IDR picture, P picture, B picture or RAPI picture. It should be noted that display knowledge picture and non-display knowledge picture are not display pictures.
[0095] reference picture
[0096] An image used for inter-frame prediction of subsequent images during the decoding process.
[0097] coded patch
[0098] The coded representation of a slice. NAL units in the same coded slice unit should be adjacent.
[0099] A picture is a frame of a coded video sequence, whose coded data is contained in one or more access units. Its coded picture consists of a picture header NAL unit, supplementary enhancement information (if present), and all coded slice NAL units of the picture. Specifically, the coded picture of an IDR picture includes a picture header NAL unit, zero or more supplementary extended description NAL units of the IDR picture, and all IDR picture coded slice NAL units of the IDR picture. The coded picture of a RAPI picture includes a picture header NAL unit, zero or more supplementary extended description NAL units of the RAPI picture, and all RAPI picture coded slice NAL units of the RAPI picture. The coded picture of a P picture and a B picture includes a picture header NAL unit, zero or more supplementary extended description NAL units of the P picture or B picture, and all NRAP picture coded slice NAL units of the P picture or B picture. The coded picture of an RL picture includes a picture header NAL unit, zero or more supplementary extended description NAL units of the RL picture, and all RL picture coded slice NAL units of the RL picture. The coded image of the knowledge image consists of an image header NAL unit and one or more knowledge image coding slice NAL units and one or more privacy image coding slice NAL units. The RL pre-knowledge image and privacy image coding slice NAL units and all coding slice NAL units in the coded image of the display knowledge image are continuous, and its access unit contains all NAL units of the coded image. The coding slices of non-RL pre-knowledge images can be interleaved with the access units of the display image as access units.
[0100] The first coded slice NAL unit of a picture shall be followed by the picture header NAL unit of the picture. For coded pictures that are IDR pictures, RAPI pictures, RL pictures or knowledge pictures, the picture header NAL shall be followed by a picture parameter set NAL unit, and the picture parameter set NAL shall be followed by a sequence parameter set NAL unit.
[0101] In particular, the bitstreams of one or more display images may be interleaved between multiple knowledge image bitstream slices of non-RL pre-knowledge images, but the interleaved display image bitstreams shall not be access units of RL images, IDR images, or RAPI images. All knowledge image bitstream slices of an RL pre-knowledge image or display knowledge image shall be continuous. Each knowledge image bitstream slice may be interleaved with the NAL unit of the privacy image coding slice (if present), but shall not be interleaved with the bitstream of the display image.
[0102] The bitstreams of all slices of a knowledge image should precede the bitstream of the first RL image that references that knowledge image. Knowledge image bitstream slices from different knowledge images cannot be interleaved. The knowledge image referenced by an RL image is the knowledge image represented by the first access unit of the knowledge image found in reverse order from the RL access unit in the bitstream.
[0103] It should be noted that this application does not group data units, but uses "data units" to describe them for the convenience of description.
[0104] Exemplarily, a data unit may include n data units, each of which requires authentication, where n is a positive integer. Correspondingly, the authentication data may include n digest data, each corresponding one-to-one to each of the n data units. Exemplarily, "a group of data units" may also be described as "n data units."
[0105] Exemplarily, a plurality of summary data of a group of data units may constitute a summary data list; that is, the authentication data may include the summary data list.
[0106] Exemplarily, the authentication data may be Auth.
[0107] Exemplarily, the signature data may be signature.
[0108] Exemplarily, the summary data may also be referred to as authentication summary data.
[0109] For example, the code stream may be an audio compression code stream (or audio compression bit stream) or a video compression code stream (or compressed video bit stream), and this application does not limit this. This application uses the example of signing and authenticating a video compression code stream for illustration.
[0110] For example, the signature and authentication methods involved in this application can be applied to signing and authenticating any one of an audio compression stream (or audio compression bit stream) or a video compression stream (or compressed video bit stream), and this application does not limit this. This application uses the signing and authentication of a video compression stream as an example for explanation.
[0111] As shown in Figure 1, Figure 1 is a schematic diagram of the application scenarios provided by this application. Figure 1 shows a monitoring scenario, a live broadcast scenario, and a video-on-demand scenario.
[0112] Referring to Figure 1 , in an exemplary surveillance scenario, camera 11 can sign a surveillance video stream, obtaining a signed surveillance video stream 101. Signed surveillance video stream 101 is then sent to laptop computer 13 via network 12. Laptop computer 13 can then authenticate signed surveillance video stream 101, obtain and display an authentication result 105, and play surveillance video 104.
[0113] 1 , illustratively, in a live broadcast scenario, mobile phone 14 can sign a live video stream to obtain a signed live video stream 102. Then, signed live video stream 102 is sent to mobile phone 15 via network 12. Mobile phone 15 can then authenticate signed live video stream 102, obtain and display an authentication result 107, and play live video 106.
[0114] 1 , in an exemplary on-demand scenario, a personal computer 16 can sign an on-demand video stream to obtain a signed on-demand video stream 103. The signed on-demand video stream 103 is then sent to a mobile phone 17 via a network 12. The mobile phone 17 can then authenticate the signed on-demand video stream 103, obtain and display an authentication result 109, and play the on-demand video 108.
[0115] It should be understood that the present application can also be used in other audio and video encoding and decoding scenarios, such as digital content trusted scenarios, etc., and the present application does not limit this.
[0116] As shown in Figure 2, Figure 2 is a schematic diagram of the structure of the signature and authentication system provided by this application. Figure 2 illustrates the authentication and signature process in Figure 1 above.
[0117] 2 , illustratively, a signature and authentication system 200 may include a signature end 210 and an authentication end 220 .
[0118] For example, the signing end 210 may be the camera 11, mobile phone 14 and personal computer 16 in FIG1 , and the authentication end 220 may be the laptop computer 13, mobile phone 15 and mobile phone 17 in FIG1 .
[0119] It should be understood that the same terminal device can serve as both the signing end 210 and the authentication end 220, and this application does not impose any restrictions on this.
[0120] 2 , illustratively, after acquiring the video data 201 , the signing end 210 may perform video encoding 21 on the video data 201 to obtain a code stream 202 ; and perform video signature 22 on the code stream 202 to obtain a signed code stream 203 .
[0121] For example, the video data 201 may be a surveillance video captured by the camera 11 in FIG. 1 , a live video recorded by the mobile phone 14 , or a video on demand produced by the personal computer 16 .
[0122] For example, the signed code stream 203 may be the signed surveillance video code stream 101, the signed live video code stream 102, or the signed on-demand video code stream 103 in FIG. 1 .
[0123] It should be noted that the video encoding 21 and video signing 22 operations can be performed in parallel.
[0124] It should be noted that, in one possible embodiment, the signing end 210 may include an encoder, which performs video encoding 21 and video signing 22. In another possible embodiment, the signing end 210 may include an encoder and a signature module, which performs video encoding 21 and video signing 22. In another possible embodiment, the signing end 210 may include a signature module, which performs video encoding 21 and video signing 22.
[0125] Afterwards, the signing end 210 may send the signed code stream 203 to the authenticating end 220 .
[0126] 2 , illustratively, after receiving the signed code stream 203 , the authentication end 220 may perform video authentication 23 on the signed code stream 203 to obtain an authentication result 205 ; and may perform video decoding 24 on the code stream 202 in the signed code stream 203 to obtain decoded video data 204 .
[0127] For example, the decoded video data 204 may be the surveillance video 104, the live video 106, or the on-demand video 108 in FIG. 1 .
[0128] For example, the authentication result 205 may be the authentication result 105, the authentication result 107, or the authentication result 109 in FIG. 1 .
[0129] It should be noted that the video authentication 23 and the video decoding 24 can be performed in parallel.
[0130] It should be noted that, in one possible embodiment, the authentication end 220 may include a decoder, and the decoder performs video decoding 24 and video authentication 23. In another possible embodiment, the authentication end 220 may include a decoder and an authentication module, and the decoder performs video decoding 24 and the authentication module performs video authentication 23. In another possible embodiment, the authentication end 220 may include an authentication module, and the authentication module performs video decoding 24 and video authentication 23.
[0131] It should be noted that when the signing end 210 performs lossless encoding, the video data and the decoded video data are the same; when the signing end 210 performs lossy encoding, there are differences between the video data and the decoded video data.
[0132] It should be noted that the encoder, decoder and authentication module can be implemented by software or hardware, and this application does not impose any restrictions on this.
[0133] As shown in FIG3 a , FIG3 a is a flow chart of the signature method provided by the present application, wherein process 300 can be implemented by the signature terminal 210 .
[0134] S301: Generate a security parameter set.
[0135] The security parameter set includes a knowledge image identifier, which is used to indicate that the security parameter set acts on a knowledge image or a display image.
[0136] As a possible implementation, the signing end 210 generates a security parameter set for a knowledge image or a data unit of a display image. The knowledge image identifier of the security parameter set for a knowledge image indicates that the security parameter set applies to the knowledge image, i.e., the scope of the security parameter set is the knowledge image (or the data unit of the knowledge image, or the knowledge image data unit). The knowledge image identifier of the security parameter set for a display image indicates that the security parameter set applies to the display image, i.e., the scope of the security parameter set is the display image (or the data unit of the display image, or the display image data unit).
[0137] Optionally, the value of the knowledge image identifier can be a binary variable. For example, when the knowledge image identifier is the first value, it indicates that the security parameter set acts on the knowledge image, and when the knowledge image identifier is the second value, it indicates that the security parameter set acts on the display image. The first value can be 1, the second value can be 0, or the first value can be 0, and the second value can be 1. Taking the case where the first value of the knowledge image identifier is 1, indicating that the security parameter set acts on the knowledge image, and the second value is 0, indicating that the security parameter set acts on the display image, as an example, the knowledge image identifier of the security parameter set corresponding to the knowledge image is 1, and the knowledge image identifier of the security parameter set corresponding to the display image is 0.
[0138] A data unit is the basic syntax structure of a coded bitstream (such as a compressed video bitstream). It can be a NAL unit, an access unit, or a layer unit. A group of data units is also called a bitstream segment in the codestream.
[0139] Referring to Figure 3a, illustratively, the n data units in the compressed video bitstream that require authentication are: data unit 1, data unit 2, ..., data unit n. These n data units that require authentication can be referred to as a group of data units. All subsequent references to a group of data units refer to data units that require authentication.
[0140] It should be noted that this application does not group the data units, but uses "a group of data units" to describe them for the convenience of description.
[0141] Exemplarily, data unit 1 is a data unit of a knowledge image, and data unit 2, ..., data unit n are data units of a display image.
[0142] Signing end 210 generates security parameter set 1 for data units 2, ..., and n, and also generates an independent security parameter set 2 for data unit 1. Thus, security parameter set 1 applies to the data units of the display image, also known as the display image scope; security parameter set 2 applies to the data units of the knowledge image, also known as the knowledge image scope.
[0143] The following is a detailed introduction to the security parameter set.
[0144] The security parameter set contains the configuration parameters required for encryption and authentication operations on the compressed video bitstream. At the beginning of the decoding process, each security parameter set takes effect when it is received by the decoder and will cause the previously valid security parameter set (if any) to become invalid. The security parameter set should be present before the access unit of all random access point pictures. The security parameter set should be located in the same access unit as the sequence parameter set NAL unit, and the security parameter set should be located before the sequence parameter set. Therefore, the scope of the security parameter set is the random access segment in the compressed video bitstream where it is located, that is, all access units in the bitstream from the access unit where the security parameter set is located to the next RAP picture.
[0145] The security parameter set can be a security parameter set NAL unit, which includes a security verification set RBSP. The security parameter set RBSP includes some parameters that can be used by one or more other types of NAL units. Knowledge images are encrypted or authenticated independently of display images. The is_library_flag in the security parameter data RBSP is used to distinguish whether it is a security parameter set for knowledge images. The codestream can contain multiple security parameter sets, which are distinguished by the security parameter set ID sec_para_set_id. Up to three security parameter sets are supported simultaneously. There should be a security parameter set NAL unit before the random access point access unit of the RAS or the first knowledge image access unit, which acts on the current RAS or knowledge image. The security parameter set provides parameters for the encryption and authentication of the current RAS or knowledge image access unit. In the case of multiple security parameter sets, sec_para_set_id is used to distinguish them; if there is no security parameter set NAL unit in the random access point access unit of the RAS, the current RAS (excluding non-display knowledge image access units) is considered not encrypted and does not participate in authentication; if there is no security parameter set NAL unit in the first knowledge image access unit, the current knowledge image is considered not encrypted and does not participate in authentication.
[0146] As a possible implementation method, the knowledge image identifier can be compiled into the security parameter set according to the preset syntax according to the syntax table shown in Table 1.
[0147] Table 1
[0148] sec_is_library_flag is a binary variable that identifies the knowledge image. A value of '1' indicates that this security parameter set applies to the knowledge image, and a value of '0' indicates that this security parameter set applies to the display image.
[0149] sec_para_set_id is the security parameter set ID, a 2-bit unsigned integer used to distinguish different security parameter sets acting on the same RAS or knowledge image access unit, and its value range is 1 to 3.
[0150] encryption_enable_flag is the encryption enable flag, a binary variable. A value of '1' indicates that encryption of display picture coded slices, display picture sequence parameter sets, display picture parameter sets, non-display knowledge picture coded slices, display knowledge picture coded slices, knowledge picture sequence parameter sets, knowledge picture parameter sets, or extension data units is supported, that is, the RBSP in the NAL unit may be encrypted. A value of '0' indicates that encryption of the RBSP in the NAL unit is not supported.
[0151] authentication_enable_flag is the authentication enable flag, a binary variable. A value of '1' indicates that authentication of the current RAS or knowledge image is supported. The NAL units that can participate in the authentication include the coded slices of the display image or knowledge image in the current RAS, as well as the sequence parameter set, image parameter set, security parameter set, extended data unit, and supplementary enhancement information transmitted in the access unit. When authentication of the above data content is supported, the authentication data carried in the coded bitstream should be Base64 encoded. The authentication data is transmitted through the NAL unit with nal_unit_type equal to 10. A value of '0' indicates that the current security parameter set does not support authentication of the RAS or knowledge image, and there should be no NAL unit with nal_unit_type equal to 10 for the RAS or knowledge image generated using the security parameter set.
[0152] Knowledge images only support independent signature authentication, while display images support co-signature authentication. Multiple display image access units participating in co-signature authentication must reside in the same RAS. The image type in multiple access units participating in co-signature authentication can be display images. Independent signature authentication for knowledge images uses a security parameter set independent of the display image, distinguished by the sec_is_library_flag in the security parameter set.
[0153] If an access unit contains NAL units with authentication_idc greater than 0 and nal_unit_type equal to 1-3, 5-9, 12, 14, 17, 18, or 19, the digest of the NAL units with the same authentication_idc value greater than 0 and the same layer_id value for each layer unit in the access unit is calculated in bitstream order. The digest data for NumOfLayers layer units corresponding to the authentication_idc value of the access unit is generated. The digest calculation method is specified by hash_type.
[0154] For hash_period_in_doi_minus1+1 access units, calculate the digest of each layer unit in each access unit in the order of the bit stream. The authentication data scope should not cross RAS. Then calculate the secondary digest according to the method indicated by authentication_hash_mode.
[0155] The secondary digest value is digitally signed to generate the authentication data RBSP, which is packaged into the authentication data RBSP NAL unit.
[0156] If the authentication_enable_flag and encryption_enable_flag values of multiple security parameter sets in the codestream are equal to 1, that is, the current RAS or knowledge image supports both encryption and authentication, it should be encrypted first and then authenticated, that is, the data used for authentication should be the encrypted NAL unit.
[0157] encryption_unit_mode is a 2-bit unsigned integer indicating the encryption basic unit. A value of '0' indicates encryption per NAL; a value of '1' indicates encryption per access unit, concatenating the encrypted portions of all NAL unit RBSPs in the access unit in bitstream order and restoring them to the encrypted NAL unit; a value of '2' indicates encryption per layer unit, concatenating the encrypted portions of all NAL unit RBSPs in the layer unit in bitstream order and restoring them to the encrypted NAL unit; a value of '3' indicates reserved. The IV must be reinitialized for each encryption.
[0158] encryption_level_mode is the encryption level mode, a 2-bit unsigned integer. It indicates the encryption level mode. A value of '0' indicates that when encrypting all NAL unit types, the entire RBSP data (except the last byte of the RBSP) is encrypted. A value of '1' indicates that when encrypting NAL units with nal_unit_type equal to 1, 2, 4, 12, 14, 17, 18, and 19, the first encryptionByte bytes of the RBSP are encrypted, and when encrypting other NAL unit types, the entire RBSP data (except the last byte of the RBSP) is encrypted. A value of '2' indicates that when encrypting NAL units with nal_unit_type equal to 1, 2, 4, 5, 12, 14, 17, 18, and 19, the first encryptionByte bytes of the RBSP are encrypted, and when encrypting other NAL unit types, the entire RBSP data (except the last byte of the RBSP) is encrypted. A value of '3' is reserved. Where encryptionByte = Min(EncryptionNum * EncryptionBaseByte, NumBytesInPayload - 1).
[0159] encryption_num_minus1 is the number of encryption basic byte lengths, an 8-bit unsigned integer. It indicates the number of encryption basic byte lengths. The value of EncryptionNum is equal to the value of encryption_num_minus1 plus 1.
[0160] encryption_base_byte is the encryption base byte length, a 2-bit unsigned integer. It indicates the encryption base byte length. A value of '0' indicates that the encryption base byte length is 16, a value of '1' indicates that the encryption base byte length is 64, a value of '2' indicates that the encryption base byte length is 256, and a value of '3' indicates that the encryption base byte length is 1024.
[0161] encryption_type is the encryption type, a 4-bit unsigned integer. It indicates the encryption algorithm used. For specific correspondence, see Table 2.
[0162] Table 2
[0163] vek_flag is the video encryption key flag, a binary variable. A value of '1' indicates that vek is carried, and a value of '0' indicates that vkek is not carried.
[0164] iv_flag is the initialization vector flag, a binary variable. A value of '1' indicates that the iv is carried, and a value of '0' indicates that the iv is not carried.
[0165] vek_encryption_type is the video encryption key encryption type, a 4-bit unsigned integer, indicating the encryption type of the video encryption key.
[0166] evek_length_minus1 is the length of the encrypted video encryption key, an 8-bit unsigned integer. It indicates the length of the encrypted video encryption key in bytes.
[0167] evek is the encrypted video encryption key, an n-bit unsigned integer. It represents the encrypted video encryption key and is used for encryption calculations. Its length is evek_length_minus1 plus 1 byte.
[0168] vkek_version length_minus1 is the length of the video encryption key version number, an 8-bit unsigned integer. Indicates the length of the video encryption key version number in bytes.
[0169] vkek_version is the video encryption key version number, an n-bit unsigned integer. Indicates the video encryption key version number, and its length is vkek_version_length_minus1 plus 1 byte.
[0170] iv_length_minus1 is an 8-bit unsigned integer representing the length of the initial vector, in bytes.
[0171] iv is the initialization vector, an n-bit unsigned integer. It indicates the initialization vector used for block encryption and has a length of iv_length_minus1 plus 1 byte.
[0172] hash_type is the hash type, a 2-bit unsigned integer. It indicates the algorithm used for authentication. The specific correspondence is shown in Table 3.
[0173] Table 3
[0174] authentication_hash_mode is the authentication digest calculation mode, a binary variable. It identifies the secondary digest calculation method. A value of '0' indicates the secondary digest is calculated using a concatenated method, i.e., the secondary digests are calculated for each layer's digest values Hpic1, Hpic2, ..., Hpicn in bitstream order, using the concatenated method as shown in Figure 3b. A value of '1' indicates the secondary digest is calculated using a tree-top method, i.e., the secondary digests are calculated for each layer's digest values Hpic1, Hpic2, ..., Hpicn in bitstream order, using the tree-top method shown in Figure 3c.
[0175] hash_discard_nrap_pictures_flag is a binary variable that specifies the hash authentication flag for non-random access point images. A value of '1' indicates that non-random access point images are not authenticated; a value of 0 indicates that non-random access point images can be authenticated. If hash_discard_nrap_pictures is not in the codestream, its default value is 1.
[0176] hash_period_in_doi_minus1 is the hash period, an 8-bit unsigned integer with a value range of 0 to (MAX_HASH_PERIOD / NumOfLayers-1), and MAX_HASH_PERIOD is set to 256. HashPeriodInDoi is equal to hash_period_in_doi_minus1+1. It indicates the number of access units involved in signature authentication related to one authentication data. This number is less than or equal to HashPeriodInDoi. If HashPeriodInDoi is 1, it means that a single access unit is signed independently, and the authentication data NAL unit carrying the signature should be located in the access unit associated with the signature or the first access unit thereafter. If HashPeriodInDoi is greater than 1, it means that multiple access units are signed together.
[0177] signature_type is the digital signature type, a 2-bit unsigned integer, indicating the algorithm used to digitally sign the image summary data, as shown in Table 4.
[0178] Table 4
[0179] signature_fmt is the signature data format, a 2-bit unsigned integer. It indicates the signature data format. The specific meaning of the signature_fmt value and the corresponding relationship between the signature_type syntax are shown in Table 5.
[0180] Table 5
[0181] Exemplarily, for generating a security parameter set 1 for a display image, sec_is_library_flag is 0, indicating that signature authentication is performed on the display image, and the scope of the security parameter set is a single RAS. All access units involved in the authentication cannot cross RASs and cannot be in two RASs.
[0182] The security parameter set 1 may be generated as follows:
[0183] Step 1. Set sec_para_set_id according to the configuration;
[0184] Step 2. Set sec_is_library_flag to 0, authentication_enable_flag to 1 (to enable authentication), hash_type to 0 (to use the SM3 algorithm), and authentication_hash_mode to 0 or 1 (to calculate the secondary digest using the concatenated or top-of-tree method) depending on the configuration.
[0185] Step 3. Set hash_discard_nrap_pictures_flag according to the configuration. If authentication of non-random access point images is required, set it to 0; otherwise, set it to 1.
[0186] Step 4. According to the configured hash period HashPeriodInDoi, set hash_period_in_doi_minus1 to HashPeriodInDoi minus 1; HashPeriodInDoi being 1 indicates that a single access unit is independently signed, and HashPeriodInDoi greater than 1 indicates that multiple access units are jointly signed.
[0187] For example, the sec_is_library_flag for security parameter set 2 generated for a knowledge image is set to 1, indicating that the knowledge image is independently signed and authenticated. The security parameter set is scoped to a single knowledge image, and the knowledge image participating in the authentication cannot span multiple RASs or reside in two RASs. Each knowledge image, including both displayed and non-displayed knowledge images, must be independently signed and authenticated.
[0188] The generation of security parameter set 2 can be as follows:
[0189] Step 1. Set sec_para_set_id according to the configuration;
[0190] Step 2. Set sec_is_library_flag to 1, authentication_enable_flag to 1 (to enable authentication), hash_type to 0 (to use the SM3 algorithm), and authentication_hash_mode to 0 or 1 (to calculate the secondary digest using the concatenated or tree-top method) depending on the configuration.
[0191] Step 3. Set hash_discard_nrap_pictures_flag to 0 or 1 according to the configuration. No effect.
[0192] Step 4: According to the configured hash period HashPeriodInDoi, set hash_period_in_doi_minus1 to HashPeriodInDoi minus 1; because the knowledge image has no DOI, a knowledge image only generates one authentication data for one security parameter set.
[0193] S302: Calculate summary data of the security parameter set corresponding to the display image or knowledge image.
[0194] When calculating the summary of an access unit, the summary data is calculated for the NAL units of the layer units that need to be authenticated in the access unit (including the security parameter set NAL unit (if present), the picture sequence parameter set NAL unit (if present), the picture parameter set NAL unit (if present), the picture header NAL unit, the display picture layered coded slice NAL unit, the extended data NAL unit (if present), the supplemental enhancement information NAL unit (if present), etc.).
[0195] As a possible implementation, the summary data of the displayed image can be calculated as follows:
[0196] Step 1. Set the authentication_idc in the header information of these NAL units to the sec_para_set_id in the security parameter set; (Note: When generating the bitstream, if the authentication_idc of the NAL unit with the same layer_id is non-zero, it is recommended to use the same security parameter set with the same sec_para_set_id.)
[0197] Step 2. Set the authentication_data_id of the current NAL unit. If there is a NAL unit participating in authentication with the same authentication_data_id as the previous group, the authentication_data_id should be different from the authentication_data_id of the previous group; otherwise, if the NAL unit participates in authentication together with the security parameter set NAL unit, the authentication_data_id also needs to be consistent with the authentication_data_id of the security parameter set NAL unit; otherwise, set it to 0 or 1;
[0198] Step 3: Then concatenate all NAL units involved in authentication in the layer unit and calculate the digest of the layer unit.
[0199] Based on the configuration, extract the HashPeriodInDoi access units participating in authentication from the compressed video bitstream output by the encoder. Compute the digests H1, H2, …, Hn for each layer unit within each access unit in bitstream order, where n equals the total number of layer units participating in authentication across all access units. Authentication data should not span RASs, so the number of access units authenticated together in the last group within each RAS may be less than HashPeriodInDoi.
[0200] Calculates a secondary digest based on each digest value in the manner specified by authentication_hash_mode.
[0201] As a possible implementation method, the summary data of the knowledge image can be calculated as follows:
[0202] Step 1: Set the authentication_idc in the header information of these NAL units to the sec_para_set_id in the corresponding security parameter set;
[0203] Step 2. Set the authentication_data_id of the current NAL unit. If there is a NAL unit participating in authentication with the same authentication_data_id as the previous group, the authentication_data_id should be different from the authentication_data_id of the previous group; otherwise, if the NAL unit participates in authentication together with the security parameter set NAL unit, the authentication_data_id also needs to be consistent with the authentication_data_id of the security parameter set NAL unit; otherwise, set it to 0 or 1;
[0204] Step 3: Then concatenate all NAL units involved in authentication in the layer unit and calculate the digest of the layer unit.
[0205] If the knowledge image is a display knowledge image, the coded slice NAL unit of the knowledge image is contained in a single access unit, and the digest data H1, H2, ..., Hn of the layer units participating in authentication of the access unit are calculated in bitstream order, where n is the total number of layer units in the knowledge image access unit;
[0206] If the knowledge image is a non-display knowledge image, the coding slice NAL unit of the knowledge image may be included in multiple access units, and the layer units participating in the authentication of these multiple access units are summarized H1, H2,…, Hn in the order of the bit stream, where n is the total number of layer units in the knowledge image access unit.
[0207] Based on the digest values H1, H2, ..., Hn, a secondary digest is calculated in the manner specified by authentication_hash_mode.
[0208] S303: Sign the summary data to obtain signature data.
[0209] As a possible implementation method, a digital signature is performed on the secondary digest to obtain signature data.
[0210] S304, generating authentication data of the security parameter set corresponding to the display image or the knowledge image; the authentication data includes signature data.
[0211] As a possible implementation, authentication data is generated according to one or more security parameter sets. For example, authentication data for display images is generated according to security parameter set 1, and authentication data for knowledge images is generated according to security parameter set 2.
[0212] Optionally, the authentication data of the knowledge image may be generated as follows:
[0213] Step 1. Set for_current_ras_idc to 0 and auth_is_library_flag to 0.
[0214] Step 2: Set the authentication_data_id of the current authentication data. The authentication_data_id should be consistent with the authentication_data_id of the NAL unit participating in the authentication.
[0215] Step 3. Set authentication_hash_list_flag according to the configuration. 0 indicates that the authentication data does not include a digest list, and 1 indicates that the authentication data includes a digest list. If authentication_hash_list_flag is 1, set authentication_hash_number_minus1 to the number of digests minus 1. Authentication_hash is the digest value {H1, H2, ..., Hn} of the displayed image.
[0216] Step 4. Write the signature data into authentication_data and set authentication_data_length_minus1 to the actual length of authentication_data minus 1.
[0217] Optionally, the authentication data may further include summary data, for example, the authentication data of data unit 1 includes the summary data of data unit 1 .
[0218] Optionally, the authentication data of the knowledge image may be generated as follows:
[0219] Step 1. Set auth_is_library_flag to 1 and authentication_library_picture_index to the library_picture_index of the knowledge image.
[0220] Step 2: Set the authentication_data_id of the current authentication data. The authentication_data_id should be consistent with the authentication_data_id of the NAL unit participating in the authentication.
[0221] Step 3. Set authentication_hash_list_flag according to the configuration. 0 indicates that the authentication data does not contain a digest list, and 1 indicates that the authentication data does contain a digest list. When authentication_hash_list_flag is 1, set authentication_hash_number_minus1 to the number of layer unit digests minus 1, and authentication_hash to the data value of the layer unit digest.
[0222] Write the signature data to authentication_data and set authentication_data_length_minus1 based on the actual length of authentication_data minus 1.
[0223] Optionally, the authentication data may further include summary data, for example, the authentication data of data unit 1 includes the summary data of data unit 1 .
[0224] As a possible implementation, the authentication data RBSP definition may be as shown in Table 6.
[0225] Table 6
[0226] for_current_ras_idc is a binary variable that identifies the location of the authentication data. A value of '1' indicates that all access units corresponding to the digests in the digest list in the authentication data are within the current random access segment. A value of '0' indicates that none of the access units corresponding to the digests in the digest list in the authentication data are within the current random access segment. All access units signed together should be within the same random access segment.
[0227] auth_is_library_flag is the knowledge image authentication data flag, a binary variable. A value of '1' indicates that the authentication data is the signature data of a knowledge image; a value of '0' indicates that the authentication data is the signature data of a display image or a display knowledge image. The value of AuthIsLibraryFlag is equal to the value of auth_is_library_flag. If auth_is_library_flag is not present in the bitstream, the value of AuthIsLibraryFlag is 0.
[0228] authenticaion_library_picture_index is the authentication knowledge image index, an n-bit unsigned integer. It specifies the index of the knowledge image in the knowledge bitstream that the current authentication data is acting on. The value range is 0 to 511. If authenticaion_library_picture_index does not exist in the codestream, its default value is 0.
[0229] authentication_data_id is the authentication data identifier, a 1-bit unsigned integer. The value range is 0 to 1, and it identifies the authentication data. For authentication data NAL units with the same authentication_idc value, authentication data NAL units with authentication_data_id values of 0 or 1 should appear alternately in the coded video sequence. That is, the authentication_data_id values of two adjacent authentication data NAL units in decoding order in a coded video sequence should not be the same.
[0230] authentication_hash_list_flag is a binary variable that identifies the authentication digest list. A value of '1' indicates that the authentication data carries a digest list of access units used to generate the signature in the authentication data. A value of '0' indicates that the authentication data does not carry a digest list of access units used to generate the signature in the authentication data.
[0231] authentication_hash_number_minus1 is the number of authentication digests, an 8-bit unsigned integer ranging from 0 to 255. Authentication_hash_number_minus1 plus 1 indicates the number of authentication digests.
[0232] authentication_hash is the authentication digest data, binary data. The digest is obtained by digesting the access unit using the digest algorithm corresponding to hash_type in the corresponding security parameter set. The length is hash_size, the digest data length corresponding to the digest algorithm hash_type. The digests in the digest list carried in the authentication data NAL unit should be arranged in the same order as the bitstream order of the layer units.
[0233] authentication_data_length_minus1 is the length of the signature data, an 8-bit unsigned integer. 1 plus 1 indicates the length of the signature data in bytes, and the value should be between 0 and 255.
[0234] authentication_data[i] is the number of bytes of signature data, an 8-bit unsigned integer. The i-th byte of a signature data. The authentication data NAL unit should be located after all other types of NAL units in the access unit except the end-of-stream NAL unit and the end-of-coded video sequence NAL unit. The order of authentication data NAL units corresponding to the same security parameter set in the bitstream should be the same as the bitstream order of the access unit to which they correspond, that is, if the first authentication data NAL unit is located before the second authentication data NAL unit, then any access unit associated with the first authentication data NAL unit is located before any access unit associated with the second authentication data NAL unit.
[0235] S305: Add the authentication data and security parameter set to the compressed video bit stream.
[0236] As a possible implementation, authentication data of the display image and a set of security parameters are added to the compressed video bitstream.
[0237] Optionally, the authentication data for the display image is packaged into an authentication data NAL unit and then inserted into or after the last access unit of the authentication, before the next authentication data NAL unit, and before the next random access point access unit that is not a display image. The temporal_id and layer_id of the authentication data NAL unit header are set to 0. In particular, the last authentication data in each RAS is allowed to be placed in the next RAS. In this case, the for_current_ras_idc in the authentication data is set to 0. The interval between the authentication data and the layer unit in the last access unit participating in the authentication cannot exceed HashPeriodInDoi (equal to hash_period_in_doi_minus1+1 in the security parameter set corresponding to this authentication) access units (excluding non-display image access units). The authentication_idc of the authentication data NAL unit is set to sec_para_set_id in the corresponding security parameter set, and the authentication_data_id is set to the authentication_data_id in the NAL unit header of the layer unit participating in the authentication.
[0238] The authentication data for a display picture may be located in the access unit containing the last display picture coded slice, or in the access unit containing the display picture coded slice of the next RAS. The authentication data NAL unit shall be located after all other NAL units in the access unit except the end-of-stream NAL unit and the end-of-coded video sequence NAL unit.
[0239] Optionally, the display image security parameter set is packaged into a security parameter set NAL unit and the security parameter set NAL unit is added to the compressed video bitstream in the following manner:
[0240] Step 1: Set the authentication_idc of the security parameter set NAL unit. Since the layer_id of the security parameter set NAL unit is 0, when authentication_idc is non-zero, it is set to the authentication_idc of the layer unit with layer_id 0, that is, the sec_para_set_id of the security parameter set selected for authentication of the layer unit.
[0241] Step 2: Set the authentication_data_id of the security parameter set NAL unit to 0 or 1. It is recommended that the authentication_data_id of the NAL units participating in the authentication with the same sec_para_set_id and authentication_idc as the previous group be different.
[0242] Step 3: Add the security parameter set NAL unit before the image sequence parameter set NAL unit and insert it into the compressed video bit stream.
[0243] As a possible implementation, the authentication data of the knowledge image is packaged into an authentication data NAL unit, which is then inserted into or after the last access unit of the authentication, before the next authentication data NAL unit, and before the next random access point access unit. The temporal_id and layer_id of the authentication data NAL unit header are set to 0. The authentication_idc of the authentication data NAL unit is set to the sec_para_set_id in the corresponding security parameter set, and the authentication_data_id is set to the authentication_data_id in the NAL unit header of the layer unit participating in the authentication.
[0244] The interval between the authentication data of the display knowledge image and the display knowledge image access unit shall not exceed HashPeriodInDoi (equal to hash_period_in_doi_minus1+1 in the security parameter set corresponding to this authentication) access units. The authentication data of the display knowledge image may be located in the access unit of the last display knowledge image coding slice; it may also be located in the access unit of the display image coding slice of the next RAS.
[0245] The authentication data of the non-display knowledge image is located in the access unit where the last non-display knowledge image coding slice is located.
[0246] The authentication data NAL unit should be located after all other types of NAL units in the access unit except the end-of-stream NAL unit and the end-of-coded video sequence NAL unit.
[0247] Optionally, the security parameter set of the knowledge image is packaged into a security parameter set NAL unit and the security parameter set NAL unit is added to the compressed video bitstream in the following manner:
[0248] Step 1. Set the authentication_idc of the security parameter set NAL unit. Since the layer_id of the security parameter set NAL unit is 0, when authentication_idc is non-zero, it needs to be consistent with the authentication_idc of the layer unit with layer_id 0, that is, the sec_para_set_id of the security parameter set selected for authentication of the layer unit.
[0249] Step 2: Set the authentication_data_id of the security parameter set NAL unit to 0 or 1. It is recommended that the authentication_data_id of the NAL units participating in the authentication with the same sec_para_set_id and authentication_idc as the previous group be different.
[0250] Step 3: Add the security parameter set NAL unit before the image sequence parameter set NAL unit and insert it into the compressed video bit stream.
[0251] It should be noted that S301 to S305 can be executed by the encoder in the signature end 210, or by the signature module in the signature end 210, or by the encoder and authentication module in the signature end 210 in collaboration. This application does not impose any restrictions on this.
[0252] As shown in FIG4 , FIG4 is a flowchart of the authentication method provided by the present application, wherein process 400 can be implemented by the authentication terminal 220 .
[0253] S401: Input compressed video bit stream.
[0254] The compressed video bitstream includes authentication data and a security parameter set, where the authentication data includes signature data. Multiple sets of authentication data and security parameter sets are possible. For example, data units 2, ..., and n represent authentication data for the display image, corresponding to security parameter set 1; data unit 1 represents authentication data for the knowledge image, corresponding to security parameter set 2.
[0255] For the security parameter set for the displayed image, for example, the security parameter set NAL unit corresponding to security parameter set 1, obtain one or more security parameter set NAL units of the RAS and obtain the sec_para_set_id, authentication_enable_flag, authentication_data_id, hash_type, authentication_hash_mode, hash_discard_nrap_pictures_flag, and hash_period_in_doi_minus1 from the security parameter set. If the authentication_enable_flag in the security parameter set is 0, the security parameter set does not support authentication of the displayed image. If the hash_discard_nrap_pictures_flag in the security parameter set is 1, the security parameter set does not support authentication of non-random access point pictures.
[0256] For the security parameter set of the knowledge image, such as the security parameter set NAL unit corresponding to security parameter set 2, obtain sec_para_set_id, sec_is_library_flag, authentication_enable_flag, authentication_data_id, hash_type, and hash_period_in_doi_minus1. If authentication_enable_flag in the security parameter set is 0 or hash_discard_library_pictures_flag is 1, the security parameter set does not support independent signature authentication for the knowledge image.
[0257] Optionally, when summary data is required for secondary summary authentication, the authentication data further includes the summary data.
[0258] S402: Calculate summary data of the display image or knowledge image corresponding to the security parameter set.
[0259] As a possible implementation, for the display image corresponding to the security parameter set, the steps for calculating summary data may be as follows:
[0260] Receive the NAL data of hash_period_in_doi_minus1+1 display image access units in the RAS, concatenate the NAL units of the layer units participating in the authentication in the access unit together to calculate the digest of the layer unit. The last group of data participating in the authentication in the RAS may be less than hash_period_in_doi_minus1+1.
[0261] Calculate the secondary digest based on each digest value in the order of the bit stream, and store the secondary digest value in the local cache with sec_para_set_id and authentication_data_id as identifiers;
[0262] The digests of multiple consecutive layer units with the same authentication_data_id are stored in the local cache using the sec_para_set_id and authentication_data_id as identifiers, in bitstream order, to generate a digest list {H1', H2', ..., Hm'}, where m is equal to the total number of layer units participating in authentication in the access unit. If an unauthenticated digest list with the authentication_data_id exists, authentication of the layer unit generated by this digest list fails, and the new digest list overwrites the old one.
[0263] As a possible implementation method, for the knowledge image corresponding to the security parameter set, the steps for calculating the summary data can be as follows:
[0264] If the knowledge image is a display knowledge image, the coded slice NAL unit of the knowledge image is contained in a single access unit, and the digest data H1', H2', ..., Hm' of the layer units participating in authentication of the access unit are calculated according to the bitstream order, where m is the total number of layer units in the knowledge image access unit;
[0265] If the knowledge image is a non-display knowledge image, the coding slice NAL unit of the knowledge image may be included in multiple access units, and the layer units participating in the authentication of these multiple access units are summarized H1', H2', ..., Hm' in the order of the bit stream, where m is the total number of layer units in the knowledge image access unit.
[0266] Calculates a secondary digest based on each digest value H1', H2', ..., Hm' and stores it in the local cache using sec_para_set_id and authentication_data_id as identifiers. If authentication_hash_mode is 0, the secondary digest is calculated using the concatenated method; if authentication_hash_mode is 1, the secondary digest is calculated using the top-of-tree method.
[0267] Using sec_para_set_id and authentication_data_id as identifiers, generate a summary list {H1', H2', ..., Hm'} and store it in the local cache.
[0268] S403: Authenticate the display image or knowledge image based on the calculated summary data and authentication data.
[0269] As a possible implementation, for the summary data and authentication data of the displayed image, the authentication steps for the image may be as follows:
[0270] The authentication data is obtained by counting from the access unit where the last display image coding slice participating in the authentication is located to the maximum hash_period_in_doi_minus1+1 access units.
[0271] When for_current_ras_idc in the authentication data is 1, it indicates that the authentication data is the authentication data of the current RAS; when for_current_ras_idc is 0, it indicates that the authentication data is the last authentication data of the previous RAS.
[0272] When authentication_hash_list_flag is 0 in the authentication data, secondary digest value authentication is used:
[0273] The secondary digest value is searched for in the local cache based on the sec_para_set_id and authentication_data_id in the authentication data. If the secondary digest value is found, it is used to verify the digital signature in the authentication data. If the signature verification succeeds, authentication of the layer unit involved in generating the secondary digest value succeeds. If the verification fails, authentication of the layer unit involved in generating the secondary digest value fails. If the secondary digest value is found and the sec_para_set_id and authentication_data_id match those of the most recently received layer unit sequence, if there are other unauthenticated secondary digest values whose identifiers are not equal to the sec_para_set_id and authentication_data_id, the authentication data corresponding to the unauthenticated secondary digest values are lost, and authentication of the layer units corresponding to these unauthenticated secondary digest values fails. If the secondary digest value for the layer unit corresponding to the authentication_data_id is not found, the authentication data is invalid and authentication fails.
[0274] When authentication_hash_list_flag is 1, digest list authentication is used:
[0275] Step 1: Parse the authentication data NAL unit to obtain the authentication_data_id and the corresponding digest list {H1, H2, ..., Hn}, and calculate the secondary digest; if authentication_hash_mode is 0, use the concatenation method to calculate the secondary digest; if authentication_hash_mode is 1, use the tree top method to calculate the secondary digest.
[0276] Step 2: Use the secondary digest value to verify the signature data parsed from the authentication data NAL unit and determine whether the digest list {H1, H2, …, Hn} transmitted in the authentication data NAL unit passes verification. If not, the digest list data in the authentication data is untrustworthy and digest list authentication fails.
[0277] Step 3. Determine the layer units involved in the signature based on the parameters in the authentication data NAL unit. Search the locally cached digest list for the layer unit based on the sec_para_set_id and authentication_data_id. If found, the layer unit to be authenticated can be confirmed through the digest list. If found and the sec_para_set_id and authentication_data_id are consistent with the sec_para_set_id and authentication_data_id of the most recently received layer unit sequence, if there are other unauthenticated digest lists whose identifiers are not equal to sec_para_set_id and authentication_data_id, the authentication data corresponding to the unauthenticated digest lists are lost, and the authentication of the layer units corresponding to these unauthenticated digest lists fails. If the digest list for the layer unit corresponding to the sec_para_set_id and authentication_data_id is not found, the authentication data is invalid and authentication fails.
[0278] Step 4: Sequentially match the summary list of the layer unit {H1', H2', ..., Hm'} with the summary list in the authentication data {H1, H2, ..., Hn} to authenticate the layer unit. First, search for H1' in the summary list in the authentication data. If the search is successful, record the position of the summary list in the authentication data. The layer unit corresponding to H1' is successfully authenticated. Then, search for H2' in the summary list in the authentication data, starting from the position immediately after that position. If the search is successful, update the position of the summary list in the authentication data. The layer unit corresponding to H2' is successfully authenticated. Continue searching for H3', ..., Hm'. If the search is successful, the corresponding layer unit is successfully authenticated. If the search fails, the corresponding layer unit fails.
[0279] As a possible implementation method, for the summary data and authentication data of the knowledge image, the authentication steps for the image can be as follows:
[0280] If the image being authenticated is a display knowledge image, the authentication data is received starting from the layer unit where the last display knowledge image coding slice participating in the authentication is located to the maximum hash_period_in_doi_minus1+1 access units; if the image being authenticated is a non-display knowledge image, the authentication data is obtained after the non-display knowledge image coding slice in the access unit where the last non-display knowledge image coding slice is located and in the layer unit whose layer_id is 0.
[0281] If auth_is_library_flag is 1, it is the authentication data of the knowledge image.
[0282] When for_current_ras_idc in the authentication data is 1, it indicates that the authentication data is the authentication data of the current RAS; when for_current_ras_idc is 0, it indicates that the authentication data is the last authentication data of the previous RAS.
[0283] Determine whether the authentication_library_picture_index in the authentication data is consistent with the library_picture_index of the current knowledge image. If not, the authentication fails and ends.
[0284] When authentication_hash_list_flag is 0 in the authentication data, secondary digest value authentication is used:
[0285] The secondary digest value is searched for in the local cache based on the sec_para_set_id and authentication_data_id in the authentication data. If the secondary digest value is found, it is used to verify the digital signature in the authentication data. If the signature verification succeeds, authentication of the layer unit involved in generating the secondary digest value succeeds. If the verification fails, authentication of the layer unit involved in generating the secondary digest value fails. If the secondary digest value is found and the sec_para_set_id and authentication_data_id match those of the most recently received layer unit sequence, if there are other unauthenticated secondary digest values whose identifiers are not equal to the sec_para_set_id and authentication_data_id, the authentication data corresponding to the unauthenticated secondary digest values are lost, and authentication of the layer units corresponding to these unauthenticated secondary digest values fails. If the secondary digest value for the layer unit corresponding to the authentication_data_id is not found, the authentication data is invalid and authentication fails.
[0286] When authentication_hash_list_flag is 1, digest list authentication is used:
[0287] Step 1: Parse the authentication data NAL unit to obtain the authentication_data_id and the corresponding digest list {H1, H2, ..., Hn}, and calculate the secondary digest of each digest value; if authentication_hash_mode is 0, use the concatenation method to perform the secondary digest calculation; if authentication_hash_mode is 1, use the tree top method to perform the secondary digest calculation.
[0288] Step 2: Use the secondary digest value to verify the signature data parsed from the authentication data NAL unit and determine whether the digest list {H1, H2, …, Hn} transmitted in the authentication data NAL unit passes verification. If not, the digest list data in the authentication data is untrustworthy and digest list authentication fails.
[0289] Step 3. Determine the layer units involved in the signature based on the parameters in the authentication data NAL unit. Search the locally cached digest list for the layer unit based on the sec_para_set_id and authentication_data_id. If found, the layer unit to be authenticated can be confirmed through the digest list. If found and the sec_para_set_id and authentication_data_id are consistent with the sec_para_set_id and authentication_data_id of the most recently received layer unit sequence, if there are other unauthenticated digest lists whose identifiers are not equal to sec_para_set_id and authentication_data_id, the authentication data corresponding to the unauthenticated digest lists are lost, and the authentication of the layer units corresponding to these unauthenticated digest lists fails. If the digest list for the layer unit corresponding to the sec_para_set_id and authentication_data_id is not found, the authentication data is invalid and authentication fails.
[0290] Step 4: Sequentially match the summary list of the layer unit {H1', H2', ..., Hm'} with the summary list in the authentication data {H1, H2, ..., Hn} to authenticate the layer unit. First, search for H1' in the summary list in the authentication data. If the search is successful, record the position of the summary list in the authentication data. The layer unit corresponding to H1' is successfully authenticated. Then, search for H2' in the summary list in the authentication data, starting from the position immediately after that position. If the search is successful, update the position of the summary list in the authentication data. The layer unit corresponding to H2' is successfully authenticated. Continue searching for H3', ..., Hm'. If the search is successful, the corresponding layer unit is successfully authenticated. If the search fails, the corresponding layer unit fails.
[0291] It will be appreciated that, to implement the functions in the aforementioned embodiments, the signing end 210 and the authenticating end 220 include hardware structures and / or software modules corresponding to the respective functions. Those skilled in the art will readily appreciate that, in conjunction with the various exemplary units and method steps described in the embodiments disclosed herein, the present application can be implemented in hardware or a combination of hardware and computer software. Whether a function is implemented in hardware or in a hardware-driven manner by computer software depends on the specific application scenario and design constraints of the technical solution.
[0292] The above text describes in detail the signature and authentication method provided according to this embodiment in conjunction with Figures 1 to 4. The following text describes the signature device and authentication device provided according to this embodiment in conjunction with Figures 5 and 6.
[0293] Figure 5 is a schematic diagram of the signature device provided in this application. The signature device can be used to execute the method of the aforementioned embodiment. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding method provided above, and will not be repeated here.
[0294] Referring to FIG5 , FIG5 is a signature device provided by the present application. Exemplarily, the signature device 500 includes:
[0295] The parameter set generation module 501 is used to generate a security parameter set; the security parameter set includes a knowledge image identifier, and the knowledge image identifier is used to indicate that the security parameter set acts on a knowledge image or a display image.
[0296] The summary calculation module 502 is used to calculate summary data of the security parameter set corresponding to the display image or the knowledge image.
[0297] The signature module 503 is used to sign the summary data to obtain signature data.
[0298] The authentication generation module 504 is used to generate authentication data corresponding to the security parameter set of the display image or the knowledge image; the authentication data includes signature data.
[0299] The output module 505 is configured to add the authentication data and the security parameter set to the compressed video bit stream.
[0300] Exemplarily, when the knowledge image identifier is a first value, it indicates that the security parameter set acts on the knowledge image; and when the knowledge image identifier is a second value, it indicates that the security parameter set acts on the display image.
[0301] Exemplarily, the authentication data is located in or after the last access unit of the current authentication, before the next authentication data NAL unit, and before the next random access point access unit.
[0302] Exemplarily, the knowledge image is a display knowledge image, and the interval between the access units of the authentication data and the display knowledge image does not exceed a number of access units equal to the hash period value.
[0303] Exemplarily, the knowledge image is a non-display knowledge image, and the authentication data is located in the access unit where the last non-display knowledge image coding slice is located.
[0304] Exemplarily, the security parameter set further includes a security parameter set identifier, which is used to distinguish different security parameter sets acting on the same random access segment or knowledge image access unit.
[0305] Exemplarily, the security parameter set further includes a hash period, where the hash period is used to indicate the maximum number of access units in the bitstream segment.
[0306] Exemplarily, the authentication data includes summary data, which is used to authenticate the display image or the knowledge image.
[0307] Exemplarily, the knowledge image is a coded image in which each frame corresponds to a sequence parameter set and the knowledge bit stream flag in the corresponding sequence set parameter is 1; the display image is a reference knowledge image, an instant decoding refresh image, a P image, a B image or a random access point I frame image output by the decoder after decoding.
[0308] For more achievable features of the signature device 500, reference can be made to the steps performed by the signature terminal 210 in the aforementioned method embodiment. The signature device 500 can be used to implement the functions of the signature terminal 210 in the aforementioned method embodiment, thereby also achieving the beneficial effects of the aforementioned method embodiment.
[0309] Figure 6 is a schematic diagram of the authentication device provided in this application. The schematic diagram of the authentication device can be used to execute the method of the aforementioned embodiment. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding method provided above, and will not be repeated here.
[0310] Referring to FIG6 , FIG6 is an authentication device provided by the present application. Exemplarily, the authentication device 600 includes:
[0311] Input module 601 is used to input a compressed video bit stream; the compressed video bit stream includes authentication data and a security parameter set, the authentication data includes signature data, the signature data is obtained by signing the summary data, the summary data is a summary of the security parameter set corresponding to the display image or knowledge image, the security parameter set includes a knowledge image identifier, and the knowledge image identifier is used to indicate that the security parameter set acts on the knowledge image or display image.
[0312] The summary calculation module 602 calculates summary data of the display image or knowledge image corresponding to the security parameter set.
[0313] The authentication module 603 is used to authenticate the display image or knowledge image based on the calculated summary data and authentication data.
[0314] Exemplarily, when the knowledge image identifier is a first value, it indicates that the security parameter set acts on the knowledge image; and when the knowledge image identifier is a second value, it indicates that the security parameter set acts on the display image.
[0315] Exemplarily, the authentication data is located in or after the last access unit of the current authentication, before the next authentication data NAL unit, and before the next random access point access unit.
[0316] Exemplarily, the knowledge image is a display knowledge image, and the interval between the access units of the authentication data and the display knowledge image does not exceed a number of access units equal to the hash period value.
[0317] Exemplarily, the knowledge image is a non-display knowledge image, and the authentication data is located in the access unit where the last non-display knowledge image coding slice is located.
[0318] Exemplarily, the security parameter set further includes a security parameter set identifier, which is used to distinguish different security parameter sets acting on the same random access segment or knowledge image access unit.
[0319] Exemplarily, the security parameter set further includes a hash period, where the hash period is used to indicate the maximum number of access units in the bitstream segment.
[0320] Exemplarily, the authentication data includes summary data, which is used to authenticate the display image or the knowledge image.
[0321] Exemplarily, the knowledge image is a coded image in which each frame corresponds to a sequence parameter set and the knowledge bit stream flag in the corresponding sequence set parameter is 1; the display image is a reference knowledge image, an instant decoding refresh image, a P image, a B image or a random access point I frame image output by the decoder after decoding.
[0322] It can be understood that the device shown in Figure 5 or Figure 6 is only an example provided in this embodiment. Depending on the different signing or authentication processes, the device may include more or fewer units, and this application is not limited to this.
[0323] When the signature device or authentication device is implemented via hardware, the hardware may be implemented via a processor or a chip system. The chip system includes one or more chips, each of which includes a processor and a power supply circuit. The power supply circuit is used to power the processor, which is used to implement any of the possible implementation methods in the above embodiments through logic circuits or by executing code instructions. The beneficial effects can be found in the description of any aspect of the above embodiments and will not be elaborated here.
[0324] It is understood that the processor in the embodiments of the present application may be a CPU, or other general-purpose processor, digital signal processor (DSP), ASIC, FPGA or other programmable logic device, transistor logic device, hardware component or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0325] In addition, the signature device 500 shown in FIG5 or the authentication device 600 shown in FIG6 can also be implemented by an electronic device, as shown in FIG7 . FIG7 is a schematic diagram of the structure of an electronic device provided by this application. The electronic device 700 includes: a memory 710 and at least one processor 720. The processor 720 can implement the signature method or authentication method provided in the above embodiments. The memory 710 is used to store software instructions corresponding to the above signature method or authentication method. For example, the electronic device can be the camera 11 or the mobile phone 15 in FIG1 .
[0326] As an optional implementation, in terms of hardware implementation, the electronic device 700 may refer to a chip or chip system encapsulated with one or more processors 720. For example, when the electronic device 700 is used to implement the method steps in the above embodiment, the processor 720 included in the electronic device 700 executes the steps of the signature end 210 or the authentication end 220 in the above method and its possible sub-steps. In an optional scenario, the electronic device 700 may also include a communication interface 730, which can be used to send and receive data. For example, the communication interface 730 is used to receive a code stream, etc.; the communication interface 730 can be implemented by an interface circuit included in the electronic device 700. Therefore, in some examples, the communication interface 730 can also be called a transceiver of the electronic device. In this embodiment, the communication interface 730 supports wired connection using a unified multimedia interconnection interface.
[0327] In an embodiment of the present application, the communication interface 730, the processor 720, and the memory 710 may be connected via a bus 740, which may be divided into an address bus, a data bus, a control bus, etc. The bus 740 may be a PCIe bus, an extended industry standard architecture (EISA) bus, a unified bus (Ubus or UB), a compute express link (CXL), a cache coherent interconnect for accelerators (CCIX), or other types of buses.
[0328] It is worth noting that the electronic device 700 can also perform the functions of the signature device 500 shown in Figure 5 or the authentication device 600 shown in Figure 6, which will not be described in detail here. Among them, all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module and will not be repeated here.
[0329] The present application also provides a chip comprising one or more interface circuits and one or more processors; the one or more processors receive or send data via the one or more interface circuits, and when the one or more processors execute computer instructions, the steps of the above-mentioned related methods are implemented. The interface circuits are transceivers / transceiver pins.
[0330] This embodiment also provides a non-transitory computer-readable storage medium, which stores computer instructions. When the computer instructions are executed on an electronic device, the electronic device executes the above-mentioned related method steps to implement the method in the above-mentioned embodiment.
[0331] This embodiment further provides a computer program product, which includes computer instructions. When the computer instructions are executed by a computer or a processor, the computer executes the above-mentioned related steps to implement the method in the above-mentioned embodiment.
[0332] In addition, an embodiment of the present application also provides a device, which can specifically be a chip, component or module, and the device may include a connected processor and memory; wherein the memory is used to store computer-executable instructions, and when the device is running, the processor can execute the computer-executable instructions stored in the memory to enable the chip to execute the methods in the above-mentioned method embodiments.
[0333] Among them, the electronic device, non-transitory computer-readable storage medium, computer program product or chip provided in this embodiment are all used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding methods provided above, and will not be repeated here.
[0334] Through the description of the above implementation methods, technical personnel in the relevant field can understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0335] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0336] Units described as separate components may or may not be physically separate, and components shown as units may be one physical unit or multiple physical units, that is, they may be located in one place or distributed in multiple places. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0337] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0338] Any content of each embodiment of this application, as well as any content of the same embodiment, can be freely combined. Any combination of the above content is within the scope of this application.
[0339] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a device (which can be a single-chip microcomputer, chip, etc.) or a processor (processor) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0340] The steps of the method or algorithm described in conjunction with the disclosure of the embodiments of the present application can be implemented in a hardware manner, or can be implemented by a processor executing a software instruction. The software instruction can be composed of corresponding software modules, and the software module can be stored in a random access memory (Random Access Memory, RAM), a flash memory, a read-only memory (Read Only Memory, ROM), an erasable programmable read-only memory (Erasable Programmable ROM, EPROM), an electrically erasable programmable read-only memory (Electrically EPROM, EEPROM), a register, a hard disk, a mobile hard disk, a read-only compact disc (CD-ROM) or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and can write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an ASIC.
[0341] Those skilled in the art will appreciate that, in one or more of the above examples, the functions described in the embodiments of the present application can be implemented using hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. Computer-readable media include non-transitory computer-readable storage media and communication media, wherein the communication media includes any medium that facilitates the transmission of a computer program from one place to another. The storage medium can be any available medium that a general-purpose or special-purpose computer can access.
[0342] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms without departing from the purpose of this application and the scope of protection of the claims, all of which are within the protection of this application.
Claims
1. A signature method, characterized in that, The method includes: Generating a set of security parameters; the set of security parameters includes a knowledge image identifier, and the knowledge image identifier is used to indicate that the set of security parameters acts on a knowledge image or a display image; Calculating the digest data of the display image or the knowledge image corresponding to the set of security parameters; Signing the digest data to obtain signature data; Generating authentication data for the display image or the knowledge image corresponding to the set of security parameters; the authentication data includes the signature data; Adding the authentication data and the set of security parameters to a compressed video bitstream.
2. The method according to claim 1, characterized in that, When the knowledge image identifier takes a first value, it indicates that the set of security parameters acts on a knowledge image, and when the knowledge image identifier takes a second value, it indicates that the set of security parameters acts on a display image.
3. The method according to claim 1 or 2, characterized in that The authentication data is located in or after the last access unit of the current authentication, before the next authentication data NAL unit, and before the next next random access point access unit.
4. The method according to any one of claims 1-3, characterized in that When the knowledge image is a display knowledge image, the interval between the access unit of the authentication data and the access unit of the display knowledge image does not exceed the number of access units equal to the value of the hash period.
5. The method according to any one of claims 1-3, characterized in that When the knowledge image is a non-display knowledge image, the authentication data is located in the access unit where the last non-display knowledge image coding slice is located.
6. The method according to any one of claims 1-4, characterized in that, The set of security parameters further includes a hash period, and the hash period is used to indicate the maximum number of access units in a bitstream segment.
7. The method according to any one of claims 1-6, characterized in that, The set of security parameters further includes a security parameter set identifier, and the security parameter set identifier is used to distinguish different sets of security parameters acting on the same random access segment or knowledge image access unit.
8. The method according to any one of claims 1-7, characterized in that The authentication data further includes the digest data, and the digest data is used to authenticate the display image or the knowledge image.
9. The method according to any one of claims 1 to 8, characterized in that, For the knowledge image, each frame of image corresponds to a sequence parameter set, and the coding image with the knowledge bitstream flag being 1 in the corresponding sequence set parameter; for the display image, it is a reference knowledge RL image, an instant decoding refresh IDR image, a P image, a B image, or a random access point I-frame RAPI image output by the decoder after decoding the reconstructed image.
10. A compressed video bitstream, characterized in that, It includes: Authentication data and a set of security parameters; Wherein, the set of security parameters includes a knowledge image identifier, the knowledge image identifier is used to indicate that the set of security parameters acts on a knowledge image or a display image, the authentication data includes the signature data corresponding to the digest data, and the digest data is obtained by performing a digest calculation on the display image or the knowledge image corresponding to the set of security parameters.
11. The compressed video bitstream according to claim 10, wherein When the knowledge image identifier takes a first value, it indicates that the set of security parameters acts on a knowledge image, and when the knowledge image identifier takes a second value, it indicates that the set of security parameters acts on a display image.
12. The compressed video bitstream according to claim 10 or 11, characterized in that, The authentication data is located in or after the last access unit of the current authentication, before the next authentication data NAL unit, and before the next next random access point access unit.
13. The compressed video bitstream according to any one of claims 10 - 12, characterized in that, When the knowledge image is a display knowledge image, the interval between the access unit of the authentication data and the access unit of the display knowledge image does not exceed the number of access units equal to the value of the hash period.
14. The compressed video bitstream according to any one of claims 10-12, characterized in that, When the knowledge image is a non-display knowledge image, the authentication data is located in the access unit where the last non-display knowledge image coding slice is located.
15. The compressed video bitstream according to any one of claims 10 - 14, characterized in that, The security parameter set further includes a hash period, which is used to indicate the maximum number of access units in a bitstream segment.
16. The compressed video bitstream according to any one of claims 10-15, characterized in that, The security parameter set further includes a security parameter set identifier, which is used to distinguish different security parameter sets acting on the same random access segment or knowledge picture access unit.
17. The compressed video bitstream according to any one of claims 10-16, characterized in that, The authentication data further includes the digest data, which is used to authenticate the display picture or the knowledge picture.
18. The compressed video bitstream according to any one of claims 10-17, characterized in that, The knowledge picture is an encoded picture corresponding to each frame of picture with a sequence parameter set, and the knowledge bitstream flag in the corresponding sequence set parameter is 1. The display picture is an RL picture, an IDR picture, a P picture, a B picture or a RAPI picture output by the decoder after decoding the reconstructed picture.
19. A certification method, characterized in that, The method includes: Inputting a compressed video bitstream; the compressed video bitstream includes authentication data and a security parameter set. The authentication data includes signature data, which is obtained by signing digest data. The digest data is the digest of the display picture or the knowledge picture corresponding to the security parameter set. The security parameter set includes a knowledge picture identifier, which is used to indicate whether the security parameter set acts on a knowledge picture or a display picture. Calculating the digest data of the display picture or the knowledge picture corresponding to the security parameter set. Authenticating the display picture or the knowledge picture according to the calculated digest data and the authentication data.
20. The method according to claim 19, wherein When the knowledge picture identifier takes a first value, it indicates that the security parameter set acts on a knowledge picture. When the knowledge picture identifier takes a second value, it indicates that the security parameter set acts on a display picture.
21. The method according to claim 19 or 20, characterized in that, The authentication data is located in or after the last access unit of the current authentication, before the next authentication data NAL unit, and before the next access unit of the next random access point.
22. The method according to any one of claims 19-21, characterized in that, The knowledge picture is a display knowledge picture, and the interval between the access unit of the authentication data and the access unit of the display knowledge picture does not exceed the number of access units equal to the value of the hash period.
23. The method according to any one of claims 19-22, characterized in that, The knowledge picture is a non-display knowledge picture, and the authentication data is located in the access unit where the last non-display knowledge picture coded slice is located.
24. The method according to any one of claims 19-23, characterized in that The security parameter set further includes a hash period, which is used to indicate the maximum number of access units in a bitstream segment.
25. The method according to any one of claims 19 - 24, characterized in that, The authentication data further includes the digest data, which is used to authenticate the display picture or the knowledge picture.
26. The method according to any one of claims 19-25, characterized in that, The knowledge picture is an encoded picture corresponding to each frame of picture with a sequence parameter set, and the knowledge bitstream flag in the corresponding sequence set parameter is 1. The display picture is an RL picture, an IDR picture, a P picture, a B picture or a RAPI picture output by the decoder after decoding the reconstructed picture.
27. An electronic device, characterized in that, Including: A memory and a processor, the memory is coupled to the processor; The memory stores program instructions, which when executed by the processor cause the electronic device to execute the signature method according to any one of claims 1-9, or execute the authentication method according to any one of claims 19-26.
28. A non-transitory computer-readable storage medium, characterized in that, The non-transitory computer-readable storage medium stores a computer program, which, when running on a computer or a processor, causes the computer or the processor to execute the signature method according to any one of claims 1-9, or to execute the authentication method according to any one of claims 19-26.
29. A computer program product, characterized in that, The computer program product includes computer instructions, which, when executed by a computer or a processor, cause the steps of the method according to any one of claims 1-9 to be executed, or cause the steps of the method according to any one of claims 19-26 to be executed.
30. A non-transitory computer-readable storage medium, characterized in that, The non-transitory computer-readable storage medium stores a compressed video bitstream according to any one of claims 10-18.
Citation Information
Patent Citations
Method, system and device for improving safety of monitoring data
CN101783793A
Digital signature authentication
CN107077622A
Video signal source encryption and decryption system and method based on AVS2 entropy coding of block encryption
CN112533001A
Video encoding method, video decoding method, encoder, decoder, and medium
CN117082249A