Method, apparatus and system for encrypting and decrypting data stream
Abstract
A method for encrypting a data stream that is transmitted from a sender to a receiver through a channel (800), said method comprising adjusting (110-120) the encryption attributes during transmission based on the characteristics of one or several of (i) the current resource consumption of the issuer, the receiver or both; and (ii) the quality of the channel; encrypt the data stream according to the encryption attributes set ;, and transmit the encrypted data stream and information of said encryption attributes set to said receiver.

Term
Term ended
Projected expiry passed 28 April 2024, 2.4 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
15 claims: 2 independent, 13 dependent
- 1ES 2 276 222 T3 REIVINDICACIONES 1. Un método para encriptar un tren de datos que se transmite de un emisor a un receptor a través de un canal (800), comprendiendo dicho método ajustar (110-120) los atributos de encriptación durante la transmisión en base a las características de uno o varios de (i) el consumo de recursos actual del emisor, el receptor o ambos;y (ii) la calidad del canal;encriptar el tren de datos según los atributos de encriptación ajustados;, y transmitir el tren de datos encriptados e información de dichos atributos de encriptación ajustados a dicho receptor.
- 2El método de la reivindicación 1, en el que dicha etapa de ajustar los atributos de encriptación comprende:determinar si la complejidad actual es más alta que un primer umbral predeterminado, siendo dicha complejidad actual una medida del consumo de recursos del emisor, el receptor o ambos;y si dicha complejidad actual es más alta que dicho primer umbral predeterminado, ajustar los atributos de encriptación para reducir el consumo de recursos del emisor o del receptor.
- 3El método de la reivindicación 2, en el que dicha etapa de ajustar los atributos de encriptación comprende:determinar si la complejidad actual es más baja que un segundo umbral predeterminado, siendo el segundo umbral más bajo que dicho primer umbral predeterminado, y si dicha complejidad actual es más baja que dicho segundo umbral predeterminado, ajustar los atributos de encriptación para reducir el consumo de recursos del emisor o del receptor.
- 4El método de la reivindicación 1, en el que dicha etapa de ajustar los atributos de encriptación comprende:determinar si la BER actual del canal ha aumentado en una primera cantidad predeterminada;si dicha BER actual del canal ha aumentado en la primera cantidad predeterminada, ajustar los atributos de encriptación para reducir una longitud de propagación de error de la encriptación;determinar si la BER actual del canal ha disminuido en una segunda cantidad predeterminada;y si dicha BER actual del canal ha disminuido en la segunda cantidad predeterminada, ajustar los atributos de encriptación para aumentar la longitud de propagación de error de la encriptación.
- 5El método de la reivindicación 1, en el que dicha etapa de ajustar los atributos de encriptación comprende:determinar si la BER actual del canal es más alta que un primer umbral predeterminado, si dicha BER actual del canal es más alta que un primer umbral predeterminado, ajustar los atributos de encriptación para reducir la longitud de propagación de error de la encriptación;determinar si la BER actual del canal es más baja que el segundo umbral predeterminado;si dicha BER actual del canal es más baja que el segundo umbral predeterminado, ajustar los atributos de encriptación para aumentar la longitud de propagación de error de la encriptación.
- 6El método de la reivindicación 1, en el que dicho tren de datos es un tren de vídeo comprimido que contiene datos de trama-I, datos de trama-P y datos de trama-B, donde dicha etapa de ajustar los atributos de encriptación ajusta los atributos de encriptación para los datos de trama-I, datos de trama-P y datos de trama-B, respectivamente.
- 7El método de la reivindicación 2, en el que dicho tren de datos es un tren de vídeo comprimido que contiene datos de trama-I, datos de trama-P y datos de trama-B, y donde dicha etapa de ajustar los atributos de encriptación para reducir el consumo de recursos de dicho emisor o de dicho receptor incluye respectivamente ajustar los atributos de encriptación para los datos de trama-I, datos de trama-P y datos de trama-B, en el orden de trama-B, trama-P y trama-I.
- 8El método de la reivindicación 3, en el que dicho tren de datos es un tren de vídeo comprimido que contiene datos de trama-I, datos de trama-P y datos de trama-B, y donde dicha etapa de ajustar los atributos de encriptación para aumentar el consumo de recursos de dicho emisor o de dicho receptor incluye respectivamente ajustar los atributos de encriptación para los datos de trama-I, datos de trama-P y datos de trama-B, en el orden de trama-I, trama-P y trama-B.
- 9El método de la reivindicación 1, en el que dicho tren de datos contiene una capa de base y al menos una capa de mejora, donde dicha etapa de ajustar los atributos de encriptación ajusta los atributos de encriptación para dicha capa de base y dicha al menos una capa de mejora, respectivamente.
- 10El método de la reivindicación 2, en el que dicho tren de datos contiene una capa de base y al menos una capa de mejora, donde dicha etapa de ajustar los atributos de encriptación ajusta los atributos de encriptación para reducir el consumo de recursos de dicho emisor o de dicho receptor incluye sucesivamente ajustar los atributos de encriptación en el orden desde dicha capa de mejora a dicha capa de base.
- 11El método de la reivindicación 3, en el que dicho tren de datos contiene una capa de base y al menos una capa de mejora, donde dicha etapa de ajustar los atributos de encriptación para aumentar el consumo de recursos de dicho emisor o de dicho receptor incluye respectivamente ajustar los atributos de encriptación para dicha capa de base y para dicha al menos una capa de mejora en el orden desde dicha capa de base a dicha capa de mejora.
- 12Un aparato para encriptar un tren de datos que se transmite desde un emisor a un receptor a través de un canal (800), comprendiendo dicho aparato de encriptación:unos medios (612) para ajustar los atributos de encriptación durante la transmisión de dicho tren de datos para generar información de atributos de encriptación, ajustando dichos ES 2 276 222 T3 medios de ajuste los atributos de encriptación en base a las características de uno o varios de (i) el consumo de recursos actual del emisor, el receptor o ambos;y (ii) la calidad del canal;y un aleatorizador (614) para realizar la encriptación de al menos una parte de dicho tren de datos según los atributos de encriptación ajustados por dichos medios de ajuste de atributos de encriptación.
- 13El aparato de la reivindicación 12, en el que dichos medios para ajustar los atributos de encriptación incluyen una unidad de detección de calidad de canal, y enviar información sobre la calidad del canal a dicha unidad de determinación y ajuste;y dicha unidad de determinación y ajuste ajusta adicionalmente los atributos de encriptación en base a la información sobre la calidad de canal procedente de dicha unidad de detección de calidad de canal.
- 14El aparato de la reivindicación 12, en el que dicho tren de datos es un tren de vídeo comprimido que contiene datos de trama-I, datos de trama-P y datos de trama-B, donde dichos medios de ajuste de los atributos de encriptación ajustan los atributos de encriptación para los datos de trama-I, datos de trama-P y datos de trama-B, respectivamente;donde dicho aleatorizador encripta los datos de trama-I, datos de trama-P y datos de trama-B, respectivamente;según la información de atributos de encriptación.
- 15El aparato de la reivindicación 12, en el que dicho tren de datos contiene una capa de base y al menos una capa de mejora;donde dichos medios de ajuste de los atributos de encriptación ajustan los atributos de encriptación para dicha capa de base y dicha al menos una capa de mejora respectivamente según la información de atributos de encriptación.
Independent claims15
135 paragraphs in 12 sections, as filed
ES 2 276 222 T3
DESCRIPTION
Method, apparatus and system for encrypting and decrypting a data stream.
Technical field
The present invention relates to data encryption and in particular to a method and apparatus for encrypting and decrypting a data stream and to a system for making the transmission of the data stream secure.
Previous technique
With the trend towards the digitization of audio and video information and the development of computer and network technology, digitized audio and video works are distributed to users through networks in the form of data streams (such as trains in MPEG or MP3 format), which have been widely used. A security problem arises with data streams that are transmitted in a network environment.
The protection of a data stream in a network is usually carried out by means of encryption. Currently many approaches have been proposed for the encryption of MPEG streams, for example the Naive Algorithm, the Selective Algorithm, the Zigzag Permutation Algorithm, etc. These algorithms provide a number of encryption approaches, from simple to complex, for data streams.
However, in these traditional approaches to data stream encryption, a data stream is typically encrypted with a single policy regardless of the location of the receiver, the sender, and the channel between them. As a result, either resources are wasted or the quality of information reproduction is degraded.
US patent application 2001/053221 described an encryption technique in which ordinary text is divided into blocks and the encryption attribute is set for each block. Therefore, the encryption attribute can vary between blocks.
In the first place, the encryption and decryption operations consume strongly the resources of the system, including computing capacity of the processor, storage spaces and bandwidths of the sender and receiver. Therefore, if the strength of encryption and decryption cannot be adjusted at the appropriate time to match the consumption of system resources, neither the data stream can obtain better protection when the resources are not fully used or not fully utilized. it can encrypt and decrypt the data stream in real time, and playback quality degrades when resources are overused.
Also, the network environment can vary over time, leading to frequent channel quality changes. For example, the Bit Error Rate (BER), Packet Loss Rate (PLR), time delay, etc., of a channel can vary greatly, especially in area network wireless communication environments. wide, like the Internet. Thus, if the same encryption policy is adopted for the entire volume of a data stream, the reproduction quality can be degraded, because the receiver cannot receive enough data to decrypt in time.
Description of the invention
In order to solve the aforementioned problems in existing techniques, according to one aspect of the present invention there is provided a method for encrypting a data stream that is transmitted from a sender to a receiver through a channel, after at least a part of it has been encrypted, said method comprising adjusting the encryption attributes during transmission, and transmitting said encrypted data stream and information about said encryption attributes to said receiver.
According to another aspect of the present invention, a method is provided for encrypting a data stream that is transmitted from a sender to a receiver through a channel, after at least a part of it has been encrypted, said method comprising receiving the encryption attributes set during reception of the encrypted data stream, and decrypt the data stream according to said encryption attributes.
According to yet another aspect, an apparatus is provided for encrypting a data stream that is transmitted from a sender to a receiver through a channel, after at least a part of it has been encrypted, said apparatus for encrypting: means for adjusting the encryption attributes during transmission, and transmitting said data stream to generate information about the encryption attributes; and a scrambler for performing the encryption of said at least part of the data stream according to the encryption attributes set by said means for adjusting the encryption attributes.
According to yet another aspect of the present invention, there is provided an apparatus for decrypting a data stream that is transmitted from a sender to a receiver through a channel, after at least a part of it has been encrypted, said apparatus comprising to decrypt: an encryption setting information receiving unit to receive the encryption attribute information from the sender, and a descrambler to perform
ES 2 276 222 T3 decrypting said data stream according to the information about the encryption attributes received by said encryption setting information unit.
According to yet another aspect of the present invention, there is provided an apparatus for sending a data stream securely, comprising the aforementioned apparatus for encryption.
According to yet another aspect of the present invention, there is provided an apparatus for receiving a data stream securely, comprising the aforementioned apparatus for decryption.
According to yet another aspect of the present invention, there is provided a system for the secure transmission of a data stream comprising the aforementioned apparatus for sending a data stream, the aforementioned apparatus for receiving a data stream, and a channel connecting said apparatus for sending a data stream, and said apparatus for receiving a data stream.
Brief description of the drawings
The above features, advantages, and objectives of the present invention will become apparent from the description of the preferred embodiments of the present invention with reference to the accompanying drawings:
Figure 1 is a flow chart showing a method for encrypting a data stream according to an embodiment of the present invention;
Figure 2 is a flow chart showing the steps of setting encryption attributes in a method for encrypting a data stream according to another embodiment of the present invention;
Figure 3 is a flow chart showing the steps of setting encryption attributes in a method for encrypting a data stream according to another embodiment of the present invention;
Figure 4 is a flow chart showing the steps of setting encryption attributes in a method for encrypting a data stream according to yet another embodiment of the present invention;
Figure 5 is a flow chart showing the steps of setting encryption attributes in a method for encrypting a data stream according to yet another embodiment of the present invention;
Figure 6 shows schematically the structure of the system for providing data stream transmission security in the prior art; and Figure 7 schematically shows a structure of a system for providing data stream transmission security according to an embodiment of the present invention.
Mode (s) of carrying out the invention
A detailed description of the preferred embodiments of the present invention will now be given with reference to the drawings.
Figure 1 is a flow chart showing a method for encrypting a data stream according to an embodiment of the present invention.
The process for encrypting and decrypting a data stream in the prior art typically includes: first, an encryption policy is predetermined; then, the sender encrypts the entire data stream (Naive Algorithm) or a part of it (Selective Algorithm) according to the policy and transmits the encrypted data stream to the receiver through a channel that connects the sender and the receiver; finally, the receiver decrypts the received data according to the defined decryption policy and reproduces the information carried by the data stream.
As shown in Figure 1, according to the embodiment of the present invention, during the data stream encryption and decryption process, a determination is made as to whether the current complexity is greater than an upper limit threshold in Step 105. In the present embodiment, the current complexity is a measure of the resource consumption of the sender, receiver, or both. The actual complexity may be the processor load or storage usage by the sender, or an overall measure that takes into account the processor load and the usage by both the sender and the receiver, according to the present embodiment.
If the current complexity measure includes resource consumption by the receiver, information on the resource consumption by the receiver, such as the aforementioned processor load and storage usage needs to be fed back to the sender. Those skilled in the art can anticipate various ways to feed back this information, for example by means of acknowledgment packets, a separate link or return channel, etc., the present invention is not particularly limited as long as the sender can obtain the information about the resource consumption of the receiver.
ES 2 276 222 T3
In cases where the receiver is a terminal device with a relatively weak processor and relatively small storage, such as a top-drop decoder box, a mobile telecommunications terminal, or the like, the current complexity preferably takes into account mainly the resource consumption by the receiver, such as the receiver's processor load. Accordingly, the predetermined upper threshold can be, for example, 80% of the maximum processor load.
If the resulting determination in Step 105 is "Yes" (eg, the receiver's processor load has exceeded 80%), then the process proceeds to Step 110, adjusting the encryption attributes to reduce resource consumption. Encryption attributes in the present invention refer to those adjustable attributes related to encryption processing, such as encryption algorithm, encryption mode, encryption parameters, etc. There are many algorithms for data encryption known in the art, for example DES, 3DES, AES, RC4, etc., each of these algorithms has different encryption modes, such as ECB, CBC, OFB, etc., and some of them also include encryption parameters, for example, in the RC4 encryption algorithm, different lengths of encryption keys can be chosen by adjusting the encryption parameters. Different encryption algorithms have different encryption strengths in different encryption modes or with encryption parameters. Consequently, algorithms with different intensities have different consumptions of system resources (such as processor load, storage usage, etc.).
The present embodiment uses the encryption attributes to adjust the encryption strengths, thus making the encryption of the data stream adapted to the condition of resource consumption at the receiver or at the sender, and to the condition of the channel (described later ), so that a balance can be reached between system resources, data security (encryption intensity) and the quality of the reproduction of the transmitted information. For example, in Step 110, the computing resources used for encryption and decryption may be reduced by changing the encryption algorithm from "3DES" to "DES" or by shortening the length of the encryption key, as a result of this. which can reduce resource consumption.
Next, if the result of the determination in Step 105 is "No", the process proceeds to Step 115, determining whether the current complexity is less than a predetermined lower threshold. In this embodiment, the lower threshold is 50% of the maximum processor load.
Next, if the result of the determination in Step 115 is "Yes", the process proceeds to Step 120, in which the encryption attributes are adjusted to increase the encryption strength.
Through Steps 115 and 120, the method of the present invention fully utilizes system resources to ensure data security. If the consumption of system resources improves, for example when the processor load on the receiver has been reduced below 50%, the encryption attributes will be adjusted to increase the encryption strength.
Next, if the result of the determination in Step 115 is "No", or after Step 110 or Step 120, the process proceeds to Step 125, determining whether the channel BER has increased by a predetermined value. . If the result of the determination of Step 125 is "Yes", Step 130 can be performed, in which the encryption attributes are adjusted to reduce the error propagation length of the encryption.
If the result of the determination in Step 125 is "No", Step 135 will be performed, determining whether the channel BER has decreased by a predetermined value. If the result of the determination in Step 135 is "Yes", Step 140 will be performed, in which the encryption attributes are adjusted to increase the error propagation length of the encryption.
In the present application, the error propagation length refers to the affected range of the decrypted data. Usually, the error propagation length can be adjusted by changing the encryption mode, for example, in the Electronic Code Block (ECB) mode the data to be encoded is divided into blocks, the size of each block is the same as the length of the encryption key, and each block is encrypted with the same encryption key, therefore the error propagation length of the ECB is equal to the length of the encryption key, that is, one block. In Cipher Block Chaining (CBC) mode, first the clear text is also divided into blocks of fixed length (such as 64 bits), then an XOR operation is performed between the encrypted code output of the previous encrypted block. and the block of clear code to be encrypted, the result of the XOR operation is encrypted with the encryption key to obtain the encrypted code, therefore the error propagation length is equal to the length of the two blocks, Encrypted Feedback Mode (CFB), Output Feedback Mode (OFB), etc., have different error propagation characteristics. In addition to the encryption modes, the different encryption algorithms can also cause different error propagation lengths, for example, if an encryption algorithm like RC4 is used, the error propagation length would be very small, which is only equal to the error itself.
Generally, the longer the error propagation length, that is, the more strongly the encrypted data is associated with each other, the more difficult it is to split the data, so the security is better, at the same time, however, the higher the required channel quality. During transmission, the method of the present embodiment adjusts the error propagation length based on the current channel quality, to balance between the channel quality, data security, and the reproduction quality of the transmitted information.
ES 2 276 222 T3
Alternatively, in Step 135 and in Steps 130, 140, the determination can be made to adjust the encryption mode by comparing the channel's BER with a set of predetermined thresholds, for example, when the current BER is 10E-4, it is Choose CBC mode, and when channel quality worsens and current BER increases to be 10E-3, ECB mode can be used to reduce error propagation in encryption layer.
As shown in Figure 1, if the result of the determination in Step 135 is "No", or after Steps 130 or 140, Step 145 will be performed, in which the set encryption attributes and the set encryption attributes are transmitted to the receiver. corresponding encrypted data stream. If the encryption attributes have been adjusted, it is necessary to inform the receiver of the adjusted information, in order for the receiver to successfully perform decryption. In the present embodiment, the information about the encryption attributes is recorded in the header of the data packet for the data stream in the form of metadata; preferably the information of the encryption attributes is also encrypted. The following Table 1 shows by way of example the content of the information about the encryption attributes according to the present embodiment.
TABLE 1
Encryption attribute information content
<td>Field</td><td>Value</td>
<td>Encryption algorithm</td><td>3DES</td>
<td>Encryption Mode</td><td>CBC</td>
<td>Encryption Parameter</td><td>Neither</td>
Of course, many other approaches can be used to transmit the attribute information from the sender to the receiver, the present invention is not limited to the above embodiment, for example, it is also possible to transmit the encryption attribute information to the receiver with a packet. data separately or even through another channel.
With the above method of the present invention, during encryption, transmission and reception, the encryption policy is adjusted according to the resource consumption and the quality of the channel, and the data stream is properly encrypted under the condition of ensuring the routine operation of the emitter and receiver systems, thus being able to achieve the optimum state of balance between the system performance, data security and data reproduction quality.
Additionally, according to another embodiment of the present invention, there is provided a suitable method for encrypting a compressed video stream. Currently used video compression methods commonly record video data as three kinds of frame data, ie, I-frame data, P-frame data, and B-frame data. Between them, an I-frame (Intraframe) records an independent complete image; a P-frame (Prediction Frame) only contains the difference between the frame of the present frame and the previously decompressed image. A B-frame (Bidirectional Prediction Frame) has the same principle as the P-frame, but in addition to referring to the previously decompressed image, it can also refer to the subsequent uncompressed image. Since it is not necessary to store the entire image, storage space is greatly saved. Generally, the frame order in an MPEG data stream is IBBPBBPBBPBBPbbIBBIPBBP .....
From the point of view of data security, the relative importance of these three kinds of frame data is successively I-frame> P-frame> B-frame>. This is because if only P-frame data or B-frame data is obtained without correctly decrypted I-frame data, the entire data stream cannot be reproduced correctly. In the present embodiment, taking advantage of the characteristics of a compressed video stream, the encryption attributes are adjusted with respect to the three classes of frame data respectively, so that the data stream can be encrypted more efficiently.
Figure 2 is a flow chart showing the steps of setting encryption attributes in a method for encrypting a data stream according to another embodiment of the present invention. The differences between this embodiment and the previous embodiment are the step of adjusting the encryption attributes to reduce resource consumption (i.e., Step 110 of Figure 1) and the step of adjusting the encryption attributes to increase the strength of encryption (ie, Step 120 of Figure 1). Figure 2 shows the detailed flow of the step for adjusting the encryption attributes in order to reduce the resource consumption (Step 110) in the method for encrypting a data stream according to the present embodiment.
As shown in Figure 2, if the result of the determination in Step 105 (Figure 1) is "Yes", a determination is first made as to whether the encryption strength of the B-frame has reached the strength of lower encryption in Step 205. If the result of the determination of Step 205 is "No", the Step
ES 2 276 222 T3
210 to reduce the encryption intensity of the B-frame data, then the next step of the method will be performed (Step 125 of Figure 1); if "Yes", Step 215 will be performed, determining whether the encryption strength of the P-frame data has reached the lowest encryption strength.
Next, if the result of the determination of Step 215 is "No", the process goes to Step 220, reducing the encryption intensity of the data of the P-frame, then the next step of the method will be performed (Step 125 of Figure 1); if "Yes", Step 225 will be performed, determining whether the encryption strength of the I-frame data has reached the lowest encryption strength.
Next, if the result of the determination of Step 225 is "No", Step 230 will be performed, reducing the encryption intensity of the I-frame data, then the next method step will be performed (Step 125 of Figure 1); if it is “Yes”, this means that the encryption strengths for the data of the three types of frames have reached the lowest value. In that case, encryption and transmission can wait until system resources have been recovered or the process has been carried out with the lowest encryption strengths.
Here, the encryption strength refers to the degree of difficulty in splitting the encrypted data according to specific encryption attributes, which is usually associated with the complexity of the encryption algorithm, the complexity of the encryption mode, the complexity of the encryption key. and the like, and increasing the encryption strength would usually lead to increased consumption of system resources. The following Table 2 shows by way of example a list of combinations of encryption methods and encryption modes commonly used in the prior art, and their comparison.
TABLE 2
A comparison of encryption strengths
<td>Rank of intensity</td><td> 1</td><td> 2</td><td> 3</td><td> 4</td><td> 5</td><td> 6</td>
<td>Attributes of</td><td>AES</td><td>3DES</td><td>AES</td><td>3DES</td><td>DES</td><td>DES</td>
<td>encryption</td><td>(CBC)</td><td>(CBC)</td><td>(ECB)</td><td>(ECB)</td><td>(CBC)</td><td>(ECB)</td>
In the present embodiment, the lowest encryption strengths can be set for various kinds of framed data, respectively. Preferably, the lower encryption strengths are made successively lower for I-frame data, P-frame data, and B-frame data. And the lowest encryption strength can be zero, that is, no encryption. For example, according to the establishment of a preferred embodiment, the lowest encryption strength for I-frames is DES (CBC), the lowest encryption strength for P-frames is DES (ECB), and the encryption strength lowest for B-frames is "no encryption." Thus, in the cases of relatively large resource consumption, when all the encryption strengths are adjusted to the minimum according to the method of the present embodiment, it is also possible to ensure sufficient protection for the I-frames having a high importance, thereby which guarantees the security of the entire video data stream, in which case the consumption of system resources for encryption is significantly reduced and the reproduction quality is ensured due to the reduction of the encryption strengths of the P-frames and B-frames.
Figure 3 is a flow chart showing the steps of adjusting the encryption attributes in a method for encrypting a data stream according to another embodiment of the present invention, showing in particular the detailed flow of the step for adjusting the encryption attributes. in order to raise the encryption strength (Step 120) in a method for encrypting a data stream according to the present embodiment.
As shown in Figure 3, if the result of the determination in Step 115 (Figure 1) is "Yes", a determination is made first as to whether the encryption strength of the I-frame data has reached the highest encryption strength in Step 305. If the result of the determination of Step 305 is "No", Step 310 will be performed by increasing the encryption strength of the I-frame data, then the next step of the method will be performed (Step 125 in Figure 1); if "Yes", Step 315 will be performed, determining whether the encryption strength of the P-frame data has reached the highest encryption strength.
Next, if the result of the determination of Step 315 is "No", Step 320 will be performed, increasing the encryption intensity of the P-frame data, then the next method step will be performed (Step 125 of Figure 1); if "Yes", Step 325 will be performed, determining whether the encryption strength of the B-frame data has reached the highest encryption strength.
Next, if the result of the determination of Step 325 is "No", Step 330 will be performed, increasing the encryption strength of the B-frame data, then the next step of the method will be performed (Step 125
ES 2 276 222 T3 of Figure 1); if it is “Yes”, this means that the encryption strengths for the data of the three types of frames have reached the highest values. In that case, just continue the process.
Similarly, the highest encryption strengths can also be set for the data of different frames, respectively, but in this embodiment the same highest encryption strength, such as AES (CBC), is set for all frames.
Correspondingly, the following Table 3 shows by way of example the content of the encryption attribute information according to the present embodiment.
TABLE 3
Encryption attribute information content
<td>Field</td><td>Value</td>
<td>Encryption algorithm for l-frames</td><td>3DES</td>
<td>Encryption mode for l-frames</td><td>CBC</td>
<td>Encryption parameter for l-frames</td><td>Neither</td>
<td>Encryption algorithm for P-frames</td><td>DES</td>
<td>Encryption mode for P-frames</td><td>CBC</td>
<td>Encryption parameter for P-frames</td><td>Neither</td>
<td>Encryption algorithm for B-frames</td><td>Neither</td>
<td>Encryption mode for B-frames</td><td>Neither</td>
<td>Encryption parameter for B-frames</td><td>Neither</td>
According to this embodiment, when the consumption of system resources is alleviated, the encryption intensities in the order of I-frame, P-frame and B-frame can be increased, thereby maximizing the security of the streams. encrypted data within the system resource limit.
Although different encryption algorithms are used for different types of video frames in the present embodiment, different algorithms can also be used for the same type of video frames based on their importance in practice. For example, for P-frames, a P-frame located in a preceding position within a GOP (Group of Pictures) is more important than another P-frame located in a subsequent position within the GOP, so that the highest encryption strength for the preceding P-frame within a GOP.
Furthermore, although in the present invention the encryption attributes are adjusted according to the relative importance of the I-frame, the P-frame and the B-frame, the adjustment is not limited to this mode only. For example, the lowest encryption strength for I-frames is set to "no encryption", the lowest encryption strength for P-frames is set to DES (ECB); the lowest encryption strength for B-frames is set to DES (CBC); and the highest encryption strength for I-frames is set to "no encryption", the highest encryption strength for P-frames is set to 3DES (CCB); the highest encryption strength for B-frames is set to AES (CBC); at the same time, in the steps shown in Figure 2, the encryption intensities increase in the order of B-frame> P-frame> I-frame. In this way, those receivers who have not obtained permission can see intermittent images, that is, I-frame, but cannot see the full video, this is an advantage for those service providers that want to attract more users and also obtain protection reliable.
With the method of this embodiment, encryption strengths can be more precisely adjusted for different portions of the data stream, so that resource consumption and security can be optimally balanced. Due to the use of the dependent relationship between the frame types in the compressed video system, it is possible to reduce the compression intensity for a part of the data significantly, thereby saving the system resources of both the receiver and the sender. . Furthermore, by selecting the highest and lowest encryption strengths for the data of different types of frames, various results can be obtained which are advantageous to data stream providers.
According to yet another embodiment of the present invention, a method is provided for encrypting a layered data stream. The technique to divide the compressed data stream into layers is widely used in this field. For example, according to MPEG-2 and later standards, a data stream is divided into a base layer and one or more enhancement layers. Among them, the base layer provides a relatively low video resolution and can be decoded and
ES 2 276 222 T3 reproduced independently, and the enhancement layer provides higher resolution and needs to be decoded based on the base layer. In the case of having a plurality of enhancement layers (such as a first enhancement layer, a second enhancement layer, etc.), the decoding of the highest resolution enhancement layer depends on the decoding of the (s) lower resolution enhancement layer (s). That is, the base layer can be decoded independently to reproduce the low-quality video; the first enhancement layer based on the decoded base layer can be decoded to obtain the highest resolution; additionally, the second enhancement layer based on the first decoded enhancement layer can be decoded to obtain an even higher video playback quality and so on. Thus, from a safety point of view, the base layer has the highest importance, then the first enhancement layer, the second enhancement layer, etc. The method of this embodiment takes advantage of the characteristics of the layered data stream of this type, adjusting the encryption strengths for the different layers respectively.
The differences between this embodiment and the preceding embodiment of Figure 1 are the step of adjusting the encryption attributes to reduce resource consumption (i.e., Step 110 of Figure 1) and the step of adjusting the encryption attributes to increasing the encryption strength (ie, Step 120 of Figure 1).
Figure 4 is a flowchart showing the steps of adjusting encryption attributes in a method for encrypting a data stream according to still another embodiment of the present invention, showing in particular the detailed flow of the step of adjusting encryption attributes. encryption in order to reduce encryption strength (Step 110). The data stream is assumed to have three layers, basic layer, first enhancement layer, and second enhancement layer.
As shown in Figure 4, if the result of the determination in Step 105 (Figure 1) is "Yes", a determination is made first as to whether the encryption strength of the second enhancement layer has reached the strength lowest encryption at Step 405. If the result of the determination of Step 405 is "No", Step 410 will be performed by reducing the encryption intensity of the second enhancement layer, then the next step of the method will be performed (Step 125 in Figure 1); if "Yes", Step 415 will be performed, determining whether the encryption strength of the first enhancement layer has reached the lowest encryption strength.
If the result of the determination of Step 415 is "No", Step 420 will be performed, reducing the encryption intensity of the first enhancement layer, then the next step of the method will be performed (Step 125 of Figure 1); if "Yes", Step 425 will be performed, determining whether the base layer encryption strength has reached the lowest encryption strength.
Next, if the result of the determination of Step 425 is "No", Step 430 will be performed, reducing the encryption intensity of the base layer, then the next step of the method will be performed (Step 125 of Figure 1 ); if it is “Yes”, this means that the encryption strengths of all layers have reached the lowest value. In that case, the encryption and transmission process can be stopped until system resources are freed by other applications, or the lower encryption strengths can be continued.
In this embodiment, the lowest encryption strengths can be set for the different layers, respectively, preferably the lowest encryption strength for the base layer is set as the highest, the lowest encryption strength for the first layer of enhancement is set as the second highest, and the lowest encryption strength for the second enhancement layer is set as the lowest. Also, the lowest encryption strength can be zero, this is no encryption. For example, the lowest encryption strength for the base layer is DES (CBC), the lowest encryption strength for the first enhancement layer is DES (ECB), and the lowest encryption strength for the second layer of improvement is "no encryption." Thus, in cases of relatively large resource consumption, when all encryption strengths are set to be the lowest according to the method of the present invention, sufficient protection is still guaranteed for the very important base layer, thereby which guarantees the security of the entire video train, Although the consumption of system resources can be significantly reduced and the quality of reproduction can be ensured due to the reduction of the encryption strengths of the first and second enhancement layers.
Figure 5 is a flowchart showing the steps of adjusting the encryption attributes in a method for encrypting a data stream according to still another embodiment of the present invention, showing in particular the detailed flow of the step of adjusting the attributes of encryption in order to increase the encryption strength (Step 120) in the method for encrypting a data stream.
As shown in Figure 5, if the result of the determination in Step 115 (Figure 1) is "Yes", a determination is first made as to whether the encryption strength of the base layer has reached the strength of Highest encryption at Step 505. If the result of the determination of Step 505 is "No", Step 510 will be performed, increasing the encryption strength of the base layer, then the next step of the method will be performed (Step 125 in Figure 1); if "Yes", Step 515 will be performed, determining whether the encryption strength of the first enhancement layer has reached the highest encryption strength.
Next, if the result of the determination of Step 515 is "No", Step 520 will be performed, increasing the encryption intensity of the first enhancement layer, then the next step of the method will be performed (Step 125 of Figure 1); if "Yes", Step 525 will be performed, determining whether the encryption strength of the second enhancement layer has reached the highest encryption strength.
ES 2 276 222 T3
Next, if the result of the determination of Step 525 is "No", Step 530 will be performed, increasing the encryption intensity of the second enhancement layer, then the next step of the method will be performed (Step 125 of Figure 1); if it is “Yes”, this means that the encryption strengths of all layers have reached the highest values. In that case, you can simply continue the process.
Similarly, the highest encryption strengths can be set for the different layers respectively, but in the present embodiment the same highest encryption strength is set, such as AES (CBC) for all layers.
Correspondingly, the following Table 4 shows by way of example the content of the encryption attribute information in this embodiment.
TABLE 4
Encryption attribute information content
<td>Field</td><td>Value</td>
<td>Encryption algorithm for the base layer</td><td>3DES</td>
<td>Encryption mode for the base layer</td><td>CBC</td>
<td>Encryption Parameter for Base Layer</td><td>Neither</td>
<td>Encryption algorithm for the first layer of enhancement</td><td>DES</td>
<td>Encryption mode for the first layer of enhancement</td><td>CBC</td>
<td>Encryption Parameter for First Layer of Enhancement</td><td>Neither</td>
<td>Encryption algorithm for the second layer of enhancement</td><td>Neither</td>
<td>Encryption mode for the second layer of enhancement</td><td>Neither</td>
<td>Encryption parameter for the second enhancement layer</td><td>Neither</td>
According to the present embodiment, when the consumption of system resources is alleviated, the encryption strengths in the order of the base layer, the first enhancement layer, and the second enhancement layer can be increased, thereby making it maximized. the security of the data streams within the system resource limit.
Furthermore, according to an alternative embodiment, in the steps shown in Figure 4, the encryption intensities are reduced in the order of the base layer, the first enhancement layer, and the second enhancement layer; In the stages shown in Figure 5, the encryption strengths are raised in the order of the second enhancement layer, the first enhancement layer, and the base layer; the lowest encryption strengths of the base layer, the first enhancement layer and the second enhancement layer are set to "no encryption", DES (CBC) and 3DES (CBC) respectively; and the highest encryption strength for the base layer, the first enhancement layer and the second enhancement layer are set to "no encryption", AES (CBC) and AES (CBC) respectively. Thus, those receivers who do not have permission can see low resolution reproduced video, meanwhile, the enhancement layers that provide high quality reproduced video are adequately protected, this is an advantage for those service providers that want to attract more users and obtain also reliable protection.
Furthermore, according to yet another embodiment of the present invention, there is provided a suitable method for encrypting a layered compressed video stream. For example, an MPEG-2 video data stream includes a base layer and one or more enhancement layers, while each layer contains I-frame, P-frame, and B-frame data. Therefore, the present embodiment combines the embodiments described with reference to Figures 2 and 3 and Figures 4 and 5, providing an encryption method that can adjust encryption strengths for different frames of the same layer.
Particularly, in Steps 410, 420 and 430 as shown in Figure 4, the process shown in Figure 2 is performed with respect to the base layer, the first enhancement layer and the second enhancement layer, respectively; In Stages 510, 520 and 530, as shown in Figure 5, the process is performed as shown in Figure 3 with respect to each type of weft within the base layer, the first enhancement layer and the second enhancement layer, respectively; additionally, when the encryption strengths for all types of frames within a layer have reached their lowest value, the encryption strength of this layer is determined as the lowest (Stages 405, 415 and 425), on the other hand, When the encryption strengths for all types of frames within a layer have reached their highest value, the encryption strength of this layer is determined as the highest (Steps 505, 515 and 525).
ES 2 276 222 T3
For the layered compressed video stream, the encryption method of the present embodiment can not only adjust the encryption strengths with respect to the different layers, but can also adjust the encryption strengths with respect to the different frame types within of the same layer, so that the encryption attributes can be adjusted more flexibly and more precisely, balancing system resources, the security of the data and the quality of reproduction of the information transmitted. As a result, the method of this embodiment can improve the efficiency of the system operation and maximize the reproduction quality.
Furthermore, according to other aspects of the present invention, there is provided an apparatus for encrypting and decrypting a data stream, an apparatus for securely sending a data stream, and an apparatus for securely receiving a data stream, as well as a system for provide security in the transmission of a data stream. A detailed description is given below with reference to Figures 6 and 7.
Figure 6 schematically shows the structure of the system for a secure transmission of a data stream in the prior art. As shown in Figure 6, the system includes: a transmitter (emitter) 600, a receiver (receiver) 700 and a channel 800 that connects the receiver and the emitter. The emitter 600 comprises an encoder 601, encryption means 602 and a channel encoder 603; receiver 700 comprises a source decoder 701, decryption means 702, and a channel decoder 703.
The secure transmission of a data stream in the prior art is as follows: at the sender, first the original data (such as audio, video or other data) is encoded at the source by the source encoder 601, by For example, the original video data is compressed and encoded into a data stream in MPEG2 format, and so on. Here, the original data stream can come from a video jack card or other acquisition devices, it can also come from a data recording medium, such as a CD drive, a DVD drive, a disk drive and analogous elements. And when the data has been saved in a suitable format on the recording medium, the source encoder 601 can be omitted. Then, according to a certain encryption policy, the encryption means 602 encrypts the data stream, here the encryption policy can be predetermined, or it can be determined through a "handshake" before encryption and transmission. . Finally, the encrypted data stream is channel coded by channel encoder 603 and transmitted by receiving means 700 through channel 800.
At the receiver, the data received by the channel decoder 703 is first decoded per channel, forming the received data stream. Then, according to the above encryption policy, the decryption means decrypts the received data stream. Finally, the source decoder 701 source-decrypts the received data stream to form the reproduced data.
Figure 7 schematically shows a structure of a system for the secure transmission of a data stream according to an embodiment of the present invention. As shown in Figure 7, the system for the secure transmission of a data stream comprises: a transmitting apparatus (emitter) 600, a receiving apparatus (receiver) 700 and a channel 800 that connects the receiver and the emitter. Among them, the emitter 600 comprises a source encoder 601, encryption apparatus 610 and a channel encoder 603; receiver 700 comprises a source decoder 701, a decryption apparatus 710, and a channel decoder 703.
According to this embodiment, in transmitter 600, during encryption the encryption apparatus 601 encrypts the data stream coming from the source encoder 601 or from a reading device for data recording medium (not shown), and transmits the stream of data encrypted to the channel encoder 602, that is, during the process of encryption and transmission of the data stream, the encryption policy is adjusted based on the condition of resource consumption and channel quality.
Encryption apparatus 610 includes scrambler 614 for encrypting a data stream according to specific encryption attributes; a complexity calculating unit 611 to calculate the complexity according to the resource consumption of the sender and receiver (the term "complexity" has been explained in the above description); a channel quality detection unit 613 for detecting the current quality of the channel 800 used to transmit the data stream, such as the Bit Error Rate (BER), the Packet Loss Rate (PLR), the width of band and the like, and for sending the detected channel quality data to a setting and determining unit 612; the adjusting and determining unit 612 to determine whether it is necessary to adjust the encryption attributes based on the information from the complexity calculation unit 611 and the channel quality detection unit 613, and if necessary, to adjust the encryption attributes for the data stream and transferring the encryption attributes to scrambler 614, thereby controlling scrambler 614 to perform encryption. Specifically, the determining and adjusting unit 612 as shown above performs the determining and adjusting steps as shown above in the flow chart of Figure 1. The determining and adjusting unit 612 may be realized in the form of hardware or of software corresponding to the stages of the flow, as is known to those of skill in the art.
The unit 612 for determining and adjusting, the unit 611 for calculating the complexity and the unit 613 for detecting the channel quality from the means for adjusting the encryption attributes perform the encryption policy based on the consumption of resources. and in channel quality during encryption and transmission of the data stream, in this embodiment of the present invention.
ES 2 276 222 T3
According to this embodiment, the adjusted attribute information is recorded in the header of the data packet in the form of metadata and transmitted to the receiver (receiving means 700) together with the data stream; preferably, the attribute information is also encrypted. The content of the encryption attribute information according to this embodiment is shown by way of example in Table 1.
At receiver 700, channel decoder 703 performs channel decoding of received data to form a received data stream. The encryption attribute information in the header of the data stream packets is transferred to and extracted from the encryption setting information receiving unit 711, and then the extracted information is transferred to the descrambler 712, controlling the descrambler to decrypt the corresponding data from the data stream appropriately.
It should be noted that the method for transmitting the encryption attributes is not limited to the metadata of the above embodiment, and it is also possible that the encryption attributes are transmitted through a separate secure channel, accordingly, the receiving unit 711 of the encryption attribute information needs to receive the encryption attribute information from the secure channel, which is also within the scope of the present invention.
Additionally, according to another embodiment of the present invention, when the data stream to be encrypted and transmitted is a compressed video stream containing I-frame data, P-frame data, and B-frame data, the determination unit 612 and tuning adjusts the encryption attributes of the I-frame data, P-frame data and B-frame data; scrambler 614 encrypts I-frame data, P-frame data, and B-frame data, respectively, according to the encryption attribute information. Specifically, the determining and adjusting unit 612 performs the checking and adjusting steps as shown in Figures 2 and 3. The content of the encryption attribute information according to the present invention is shown by way of example in Table 3.
Accordingly, the encryption attribute information receiving unit 711 of the present invention receives the encryption attribute information for the I-frame data, P-frame data, and B-frame data, respectively, the descrambler 712 decrypts I-frame data, P-frame data, and B-frame data, respectively, according to the encryption attribute information.
Furthermore, according to yet another embodiment of the present invention, when the data stream to be encrypted and transmitted is a compressed video stream containing a base layer, a first enhancement layer, and a second enhancement layer, the determination unit 612 and setting adjusts the encryption attributes for the base layer, the first enhancement layer and the second enhancement layer, respectively, the scrambler 614 encrypts the base layer, the first enhancement layer and the second enhancement layer, respectively, according to the encryption attribute information. Specifically, the determining and adjusting unit 612 performs the steps of determining and adjusting as indicated in Figures 4 and 5. The content of the encryption attribute information according to the present embodiment is shown by way of example in Table 4.
Accordingly, the encryption setting information receiving unit 711 of the present invention receives the encryption attribute information for the basic layer, the first enhancement layer, and the second enhancement layer, respectively; descrambler 712 decrypts the base layer, the first enhancement layer, and the second enhancement layer, respectively, based on the encryption attribute information.
Those skilled in the art should appreciate that, in the above embodiments, the components of the encryption and decryption apparatus, and of the sender and receiver, such as source encoder 601, apparatus 610, and channel encoder 603, decoder The source 701, the decryption apparatus 710, and the channel decoder 703 can be implemented in the form of hardware or software.
Furthermore, although an emitter 600 and a receiver 700 are shown in the system depicted in Figure 7, those skilled in the art can easily anticipate a system with a transmitting means and a plurality of receiving means, for example, in a system VOD, wherein a VOD server serves a plurality of VOD terminals.
Although a detailed description of the encryption and decryption method has been given, the apparatus for securely sending a data stream, the apparatus for securely receiving a data stream, and a system for securely transmitting a data stream of the present invention Through some exemplary embodiments, the above-mentioned embodiments have not been exhausted, being able to those skilled in the art make various changes and modifications within the object of the present invention. Therefore, the present invention is not limited to these embodiments, but the object of the present invention is only defined by the appended claims.
Contents12
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
14 members in 6 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 03123416 | China | A | |
| 03123416 | China | A | |
| 20031023416 | China | – | |
| 0312341604101698 | – | – | – |
| CN2003123416 | – | – | – |
Members14
| Document | Office | Kind | |
|---|---|---|---|
| US2004223611A1 | United States of America | A1 | |
| CN1549491A | China | A | |
| EP1487147A2 | European Patent Office (EPO) | A2 | |
| EP1487147A3 | European Patent Office (EPO) | A3 | |
| EP1487147B1 | European Patent Office (EPO) | B1 | |
| AT347762T | Austria | T | |
| ATE347762T1 | Austria | T1 | |
| DE602004003520D1 | Germany | D1 | |
| ES2276222T3This record | Spain | T3 | |
| DE602004003520T2 | Germany | T2 | |
| US7436955B2 | United States of America | B2 | |
| US2009034721A1 | United States of America | A1 | |
| CN100483992C | China | C | |
| US8121288B2 | United States of America | B2 |
Numbers
- Publication
- 2276222
- Publication, DOCDB
- 2276222
- Publication, EPODOC
- ES2276222T
- Application
- 4101698
- Application, DOCDB
- 04101698
- Application, EPODOC
- ES20040101698T
Titles2
- Spanish
- METODO, APARATO Y SISTEMA PARA ENCRIPTAR Y DESENCRIPTAR UN TREN DE DATOS.
- English
- METHOD, APPARATUS AND SYSTEM FOR ENCRYPTING AND DESCRIBING A DATA TRAIN.
Classification
- CPC, 7
- H04N21/44055
- H04N7/1675
- H04N21/23476
- H04L9/0637
- H04L9/088
- H04L65/70
- H04L65/1101
- IPC, 4
- H04L9 00
- H04H20 00
- H04L29 06
- H04N7 167