WO2022204817A1 - Method and system for media redaction at an edge device - Google Patents
Method and system for media redaction at an edge device Download PDFInfo
- Publication number
- WO2022204817A1 WO2022204817A1 PCT/CA2022/050490 CA2022050490W WO2022204817A1 WO 2022204817 A1 WO2022204817 A1 WO 2022204817A1 CA 2022050490 W CA2022050490 W CA 2022050490W WO 2022204817 A1 WO2022204817 A1 WO 2022204817A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- redaction
- redacted
- media
- media element
- processor
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
- G06F21/6218—Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
- G06F21/6245—Protecting personal data, e.g. for financial or medical purposes
- G06F21/6254—Protecting personal data, e.g. for financial or medical purposes by anonymising data, e.g. decorrelating personal data from the owner's identification
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06N—COMPUTING ARRANGEMENTS BASED ON SPECIFIC COMPUTATIONAL MODELS
- G06N20/00—Machine learning
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06N—COMPUTING ARRANGEMENTS BASED ON SPECIFIC COMPUTATIONAL MODELS
- G06N3/00—Computing arrangements based on biological models
- G06N3/02—Neural networks
- G06N3/04—Architecture, e.g. interconnection topology
- G06N3/045—Combinations of networks
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06N—COMPUTING ARRANGEMENTS BASED ON SPECIFIC COMPUTATIONAL MODELS
- G06N3/00—Computing arrangements based on biological models
- G06N3/02—Neural networks
- G06N3/08—Learning methods
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06T—IMAGE DATA PROCESSING OR GENERATION, IN GENERAL
- G06T5/00—Image enhancement or restoration
- G06T5/70—Denoising; Smoothing
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06V—IMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
- G06V10/00—Arrangements for image or video recognition or understanding
- G06V10/20—Image preprocessing
- G06V10/25—Determination of region of interest [ROI] or a volume of interest [VOI]
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06V—IMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
- G06V10/00—Arrangements for image or video recognition or understanding
- G06V10/70—Arrangements for image or video recognition or understanding using pattern recognition or machine learning
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06V—IMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
- G06V20/00—Scenes; Scene-specific elements
- G06V20/40—Scenes; Scene-specific elements in video content
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04N—PICTORIAL COMMUNICATION, e.g. TELEVISION
- H04N21/00—Selective content distribution, e.g. interactive television or video on demand [VOD]
- H04N21/40—Client devices specifically adapted for the reception of or interaction with content, e.g. set-top-box [STB]; Operations thereof
- H04N21/45—Management operations performed by the client for facilitating the reception of or the interaction with the content or administrating data related to the end-user or to the client device itself, e.g. learning user preferences for recommending movies, resolving scheduling conflicts
- H04N21/454—Content or additional data filtering, e.g. blocking advertisements
- H04N21/4542—Blocking scenes or portions of the received content, e.g. censoring scenes
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06V—IMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
- G06V2201/00—Indexing scheme relating to image or video recognition or understanding
- G06V2201/10—Recognition assisted with metadata
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04N—PICTORIAL COMMUNICATION, e.g. TELEVISION
- H04N21/00—Selective content distribution, e.g. interactive television or video on demand [VOD]
- H04N21/20—Servers specifically adapted for the distribution of content, e.g. VOD servers; Operations thereof
- H04N21/23—Processing of content or additional data; Elementary server operations; Server middleware
- H04N21/234—Processing of video elementary streams, e.g. splicing of video streams or manipulating encoded video stream scene graphs
- H04N21/23418—Processing of video elementary streams, e.g. splicing of video streams or manipulating encoded video stream scene graphs involving operations for analysing video streams, e.g. detecting features or characteristics
Definitions
- TITLE METHOD AND SYSTEM FOR MEDIA REDACTION AT AN EDGE DEVICE
- the described embodiments relate generally to a system and method for media redaction, and specifically to a method and system for media redaction, transporting metadata, and various use cases for identification, tracking and/or counting of objects at an edge device.
- a redaction system comprising an edge device comprising at least one media recording unit and a processor, the at least one media recording unit being configured to record media elements.
- the processor is configured to receive a media element from the at least one media recording unit, analyze, in real-time, the media element to identify one or more image areas requiring redaction, wherein the image areas requiring redaction are identified based on one or more predetermined classification factors, and redact, in real-time, the identified image areas from the media element to create a redacted media element with redacted image areas.
- the processor is further configured to, prior to redaction, extract metadata from the determined image areas, the metadata comprising informational data based on the predetermined classification factors.
- the processor is further configured to, after redaction, embed the derived metadata into the corresponding media element.
- the processor is further configured to transmit the redacted media element to an external device.
- the processor is further configured to transmit the redacted media element and the derived metadata through separate transport streams.
- the processor is further configured to transmit the redacted media element and the derived metadata through a single transport stream.
- the processor uses an artificial intelligence algorithm to identify the image areas requiring redaction.
- the predetermined classification factors are comprised of inputs from an operator.
- the processor is coupled to a memory unit.
- the memory unit is configured to store the redacted media element.
- the memory unit is configured to store the redacted media element and the metadata.
- each predetermined classification factor is selected from the group consisting of human faces, license plate numbers, and home addresses.
- each predetermined classification can consist of any of a recognizable set of objects, for example vehicles, license plate numbers, human faces, home addresses, identification badges, etc.
- a computer-implemented method of redacting metadata comprising receiving, at a processor of an edge device, a media element from at least one media recording unit, the edge device comprising the at least one media recording unit configured to record media elements.
- the method further comprises analyzing, in real time at the processor of the edge device, the media element to identify if one or more image areas require redaction, wherein the image areas requiring redaction are identified based on one or more predetermined classification factors, and redacting, in real-time at the processor of the edge device, the identified image areas from the media element to create a redacted media element with redacted image areas.
- the method further comprises extracting, at the processor prior to redacting, metadata from the determined image areas, the metadata comprising informational data based on the predetermined classification factors.
- the method further comprises embedding, at the processor after redacting, the derived metadata into the corresponding media element.
- the method further comprises transmitting, at the processor, the redacted media element to an external device.
- the method further comprises transmitting, at the processor, the redacted media element and the derived metadata through separate transport streams.
- the method further comprises an artificial intelligence algorithm in use by the processor to identify the image areas requiring redaction.
- the processor is coupled to a memory unit.
- the method further comprises storing the redacted media element within the memory unit.
- the method further comprises storing the redacted media element and the metadata within the memory unit.
- each predetermined classification factor is selected from the group consisting of human faces, license plate numbers, and home addresses.
- a redaction system comprising at least one media recording unit for recording one or more media elements and at least one redaction device, the at least one redaction device being connected to the at least one media recording unit, the at least one redaction device comprising a processing unit and a memory unit.
- the processing unit is configured to receive a media element from the at least one media recording unit, analyze, in real-time, the media element to identify one or more image areas requiring redaction wherein the image areas requiring redaction are identified based on one or more predetermined classification factors, and redact, in real-time, the identified image areas from the media element to create a redacted media element with redacted image areas.
- the processing unit is further configured to extract metadata from the identified image areas prior to redaction to generate derived metadata, the metadata comprising informational data based on the predetermined classification factors.
- the processing unit is further configured to, after redaction, embed at least a part of the derived metadata into the corresponding redacted media element to generate a derived media element.
- the processing unit is further configured to transmit the redacted media element.
- the processing unit is further configured to transmit the redacted media element, the metadata, and the derived media element through separate transport streams.
- the processing unit is further configured to transmit the redacted media element, the metadata, and the derived media element through a single transport stream.
- the processing unit uses an artificial intelligence algorithm to identify the image areas requiring redaction.
- the predetermined classification factors are comprised of inputs from an operator.
- the processing unit is coupled to a memory unit.
- the memory unit is configured to store the redacted media element.
- the memory unit is configured to store the redacted media element and the metadata.
- the memory unit is configured to store the redacted media element, the metadata, and the derived media element.
- each predetermined classification factor is selected from the group consisting of human faces, license plate numbers, and home addresses.
- a computer-implemented method of redacting media comprising receiving, at a processing unit of at least one redaction device, a media element from at least one media recording unit, the at least one redaction device being connected to the at least one media recording unit, analyzing, in real-time at the processing unit of the at least one redaction device, the media element to identify if one or more image areas require redaction, wherein the image areas requiring redaction are identified based on one or more predetermined classification factors, and redacting, in real-time at the processing unit of the at least one redaction device, the identified image areas from the media element to create a redacted media element with redacted image areas.
- the method further comprises, at the processing unit, extracting metadata from the identified image areas prior to redaction to generate derived metadata, the metadata comprising informational data based on the predetermined classification factors.
- the method further comprises, at the processing unit, embedding at least part of the derived metadata into the corresponding redacted media element after redaction to generate a derived media element.
- the method further comprises transmitting, at the processing unit, the redacted media element.
- the method further comprises transmitting, at the processing unit, the redacted media element, the metadata, and the derived media element through separate transport streams.
- the method further comprises transmitting, at the processing unit, the redacted media element, the metadata and the derived media element through a single transport stream.
- the method further comprises an artificial intelligence algorithm in use by the processor to determine the image areas requiring redaction.
- the processing unit is coupled to a memory unit.
- the method further comprises storing the redacted media element within the memory unit.
- the method further comprises storing the redacted media element and the metadata within the memory unit.
- the method further comprises storing the redacted media element, the metadata, and the derived media element within the memory unit.
- each predetermined classification factor is selected from the group consisting of human faces, license plate numbers, and home addresses.
- FIG. 1 A is a simplified block diagram of an example embodiment of a system for media redaction at an edge device, in accordance with some embodiments
- FIG. 1 B is a simplified block diagram of an example embodiment of a system for media redaction at an edge device, in accordance with other embodiments;
- FIG. 2A is a simplified block diagram of an example embodiment of an edge device, in accordance with some embodiments.
- FIG. 2B is a simplified block diagram of an example embodiment of an edge device, in accordance with other embodiments.
- FIG. 2C is a simplified block diagram of an example embodiment for a computing device
- FIG. 3A is a simplified block diagram of an example embodiment of a redaction process, in accordance with some embodiments.
- FIG. 3B is a simplified block diagram of an example embodiment of a redaction process, in accordance with some other embodiments.
- FIG. 3C is a simplified block diagram of an example embodiment of a redaction process, in accordance with still some other embodiments.
- FIG. 4A is an example embodiment of a method for redaction at an edge device in accordance with some embodiments
- FIG. 4B is an example embodiment of a method for redaction at an edge device in accordance with some other embodiments
- FIG. 4C is an example embodiment for a method for redaction at an edge device in accordance with still some other embodiments.
- FIG. 4D is an example embodiment for a method for redaction at an edge device in accordance with still some other embodiments.
- FIG. 4E is an example embodiment for a method for redaction at an edge device in accordance with still some other embodiments.
- FIG. 4F is an example embodiment for a method for redaction at an edge device in accordance with still some other embodiments.
- FIG. 5A is an exemplary image before redaction in accordance with some embodiments.
- FIG. 5B is an exemplary image after redaction in accordance with some embodiments.
- FIG. 6A is an exemplary image before redaction in accordance with some embodiments.
- FIG. 6B is an exemplary image after redaction in accordance with some embodiments.
- FIG. 7 is an exemplary image after derived metadata is embedded within the media element in accordance with some embodiments.
- FIG. 8 is another exemplary image after derived metadata is embedded within the media element in accordance with some embodiments.
- FIG. 9 is an exemplary image after derived metadata is embedded within the media element in accordance with some other embodiments.
- FIG. 10A is an exemplary image after derived metadata is embedded within the media element in accordance with some other embodiments.
- FIG. 10B is an exemplary image after derived metadata is embedded within the media element in accordance with some other embodiments. DESCRIPTION OF EXEMPLARY EMBODIMENTS
- Coupled can have several different meanings depending in the context in which these terms are used.
- the terms coupled or coupling can have a mechanical, chemical or electrical connotation.
- the terms coupled or coupling can indicate that two elements or devices can be directly connected to one another or connected to one another through one or more intermediate elements or devices via an electrical or magnetic signal, electrical connection, an electrical element or a mechanical element depending on the particular context.
- coupled electrical elements may send and/or receive data.
- the wording “and/or” is intended to represent an inclusive-or. That is, “X and/or Y” is intended to mean X or Y or both, for example. As a further example, “X, Y, and/or Z” is intended to mean X or Y or Z or any combination thereof.
- the embodiments of the systems and methods described herein may be implemented in hardware or software, or a combination of both. These embodiments may be implemented in computer programs executing on programmable computers, each computer including at least one processor, a data storage system (including volatile memory or non-volatile memory or other data storage elements or a combination thereof), and at least one communication interface.
- the programmable computers (referred to below as edge devices and redaction devices) may be a server, network appliance, embedded device, computer expansion module, a personal computer, laptop, personal data assistant, cellular telephone, smart-phone device, tablet computer, a wireless device or any other computing device capable of being configured to carry out the methods described herein.
- At least some of the software programs used to implement at least one of the embodiments described herein may be stored on a storage media (e.g., a computer readable medium such as, but not limited to, ROM, flash memory, magnetic disk, optical disc) or a device that is readable by a programmable device.
- the software program code when read by the programmable device, configures the programmable device to operate in a new, specific and predefined manner in order to perform at least one of the methods described herein.
- the programs associated with the systems and methods of the embodiments described herein may be capable of being distributed in a computer program product comprising a computer readable medium that bears computer usable instructions, such as program code, for one or more processors.
- the program code may be preinstalled and embedded during manufacture and/or may be later installed as an update for an already deployed computing system.
- the medium may be provided in various forms, including non-transitory forms such as, but not limited to, one or more diskettes, compact disks, DVD, tapes, chips, and magnetic, optical and electronic storage.
- the medium may be transitory in nature such as, but not limited to, wire-line transmissions, satellite transmissions, internet transmissions (e.g. downloads), media, digital and analog signals, and the like.
- the computer useable instructions may also be in various formats, including compiled and non-compiled code.
- the communication interface may be a network communication interface.
- the communication interface may be a software communication interface, such as those for inter-process communication (IPC).
- IPC inter-process communication
- FIG. 1A illustrates a simplified block diagram of an example embodiment of a system 100a for redaction at an edge device.
- the redaction system 100a generally includes a media recording unit 102a, a redaction device 112, a server 106 and one or more computer terminals 108a, 108b.
- the media recording unit 102a may be configured to capture various types of media elements including, for example, video, images, image bursts, and/or audio media. Captured video can comprise a plurality of captured image frames that are captured at any pre-determ ined and/or variable frame rate. In various cases, the media recording unit 102a can be a camera (i.e. , a digital camera, a closed-circuit television camera, etc.).
- a camera i.e. , a digital camera, a closed-circuit television camera, etc.
- media recording unit 102a can include traffic cameras, body cams, smart building security cameras and other security cameras etc.
- the media recording units 102a consist of Internet of Things or loT sensors or devices.
- the media recording unit 102a is coupled to the redaction device 112.
- the redaction device 112 may be connected to the media recording unit 102a through a direct secure connection (e.g., a wired USB or HDMII connection).
- the redaction device 112 can be conveniently and directly coupled to “off the shelf” camera systems using standardized connections (i.e. , a “plug-and-play” device).
- the redaction device 112 is directly or indirectly coupled to the media recording unit 102a using a secure network, including for example, network 105.
- the redaction device 112 is a physical component (e.g. a physical server or processor etc.). In some other cases, the redaction device 112 is a virtualized component (e.g. a cloud device).
- the redaction device 112 includes a media redaction module 104.
- the media redaction module 104 is configured to receive media elements captured by the media recording unit 102a, and may be configured to redact certain target areas of these media elements to generate redacted media elements (i.e., modifying the media element to generate a redacted media elements). As explained, the redacted media elements may be transmitted, over the network 105, to one or more of the server 106 and/or the computer terminals 108.
- redaction by the redaction module 104 can occur in real-time or near real-time.
- the redaction module 104 may receive real-time or near real time media elements from the media recording unit 102a.
- the media elements can then be processed, in real-time or near real-time, to generate one or more of redacted media elements.
- the redacted media elements may then be transmitted to other components connected to the network 105.
- the combination of the media recording unit 102a and the redaction device 112 may be referred to as an “edge device” 110a - in other words, a device located on the edge of the network 105.
- the edge device 110a therefore allows redaction such that only redacted media elements can exit the edge device 110a through the network 105. This can accordingly prevent non-redacted, and privacy sensitive media elements from being transmitted over the network 105 to other computing devices 108 and/or server 106, which can risk the unredacted media being intercepted during transmission by, for example, unscrupulous third parties.
- embodiments provided herein allow for secure redaction “on the spot” (i.e., at the edge device). This is contrasted to many prior systems where the redaction occurs on a remote, unsecure, third party computing device and therefore presents the risk that the unredacted media elements can be intercepted, and the privacy sensitive information contained therein being possibly used for nefarious purposes.
- the edge device 110a may be a secure element which prevents unauthorized access, but otherwise allows authorized access. Accordingly, unauthorized personnel may not breach the edge device 110a to acquire the unredacted media elements. In other embodiments, the edge device 110 may be secured to prevent any type of access.
- one or more of the edge devices 110a, 110b are located at a local 5G node.
- the redaction device 112 may be located at a local 5G node.
- the media recording units 102a may be coupled (e.g. connected, tethered or wireless connected, or otherwise directly or indirectly coupled etc.) to the 5G network.
- the redaction device 112 may transmit some or all of the redacted media elements, derived metadata and derived redacted media elements, as discussed in detail below, using the 5G network.
- the media redaction module 104 generates the redacted media elements by identifying target redaction areas in the media elements that are required to be redacted. For example, this can include identifying target areas of captured images, or target areas of captured image frames of a digital video. An area can include, for example, one or more contiguous or non-contiguous image pixels.
- the target redaction areas can be identified by the media redaction module 104 based on one or more predetermined redaction rules.
- the redaction rules generally include conditions for determining when an area of a media element (for example, an area of an image or a video frame) requires redaction.
- the redaction rules can include determining whether an area of a media element includes privacy sensitive subject matter. For instance, and by way of non limiting examples, redaction rules can include determining whether an area includes human faces, entire human subjects, license plates, any type of sensitive text (e.g., an address), and/or objects on private property. In other cases, the redaction rules can also include determining, more generally, whether an area of a media element includes non- desirable subject matter, irrespective of whether that subject matter is privacy sensitive. For instance, the redaction rule can include determining that an area of a media element includes target moving objects, target airborne objects, shadow artifacts or other undesirable lighting effects.
- the module 104 may extract metadata from target redaction areas to generate derived metadata.
- the derived metadata may include informational data on the subject matter contained in the redaction areas.
- the derived metadata may include, by way of non-limiting examples, identifying information on the height, sex, skin color, hair color, approximate weight, and/or facial features of the subject located within the media element.
- the derived metadata may include information corresponding to the location of the image area within the media element where the redacted subject is located.
- a party receiving the redacted media elements can also receive information about the redacted elements. This information can then be advantageously used by the third parties to generate insights or monitor statistics (e.g., number of subjects, or number of males versus females that have accessed a space such as a washroom or swimming pool, etc.), without comprising the privacy of the objects or people being redacted. Accordingly, a wide range of third parties may be able to access redacted media captured of an environment, as well metadata about that media (i.e., for analysis) without compromising privacy concerns.
- insights or monitor statistics e.g., number of subjects, or number of males versus females that have accessed a space such as a washroom or swimming pool, etc.
- the derived metadata which is extracted from the media elements, can be transmitted as a separate data stream from the redacted media element.
- the derived metadata can be transmitted as an encrypted stream to prevent exposure of the information contained in the derived metadata during transmission.
- some or all of the derived metadata can be transmitted as an unencrypted stream.
- the derived metadata can be directly embedded into the corresponding redacted media elements to generate derived redacted media elements.
- a derived redacted media element includes the redacted media element, as well as embedded derived metadata extracted from the redacted areas. This, in turn, allows for transmitting a single data stream from the edge device 110a which includes both the redacted media elements and any corresponding derived metadata. In various cases, this can ensure that the derived metadata is not lost during transmission, and is integrated within the redacted media elements. This can also avoid any synchronization problems in respect of correlating derived metadata with its corresponding redacted media element as may be the case when transmitting the derived metadata and the redacted media element in two separate streams.
- one or more of the various data streams are encrypted using an encryption protocol, such as, for example, a Transport Layer Security (TLS) 1 .2 protocol or above, etc.
- TLS Transport Layer Security
- one or more of the various data streams may be encrypted using a Secure Sockets Layer (SSL) encryption protocol, such as SSL 2.0 or 3.0.
- SSL Secure Sockets Layer
- one or more of the various data streams may be encrypted using TLS 1 .0 or 1 .1 protocols.
- the various data streams may be encrypted using one or more of the SSL or TLS or other cryptographic protocols upon generation of such streams, and prior to transmission.
- the various data streams may be encrypted using one or more of the SSL or TLS or other cryptographic protocols at the time of transmission of such streams over the network.
- different encryption protocols may be used upon generation and during transmission over the network. For example, a first encryption protocol may be used upon generation of one or more of redacted media element, derived metadata and/or derived redacted media elements, and a second encryption protocol (i.e. such streams may be further encrypted, or decrypted and re-encrypted) may be applied during transmission of such streams over the network.
- the derived metadata can be broken down into time steps to avoid issues arising from compression.
- the derived metadata is not updated on every frame when embedded into redacted media elements to generate derived redacted media elements. This may provide the advantage of successfully transmitting useful metadata without losing some or all of it to compression losses.
- the derived redacted media elements are compressed before transmission.
- the derived metadata is also compressed along with the redacted media elements, which can cause the metadata to be unusable.
- the compressed derived redacted media elements can have enough frames to capture the derived metadata containing portions of the media element.
- the frequency of updates required to the embedded derived metadata can be determined based on the frequency of change in the original media elements being redacted. For example, in cases, where the frequency of change (in human subjects or other objects etc.) in a frame or a media element to be redacted is low, the embedded derived metadata may not be updated as frequently as compared to when the frequency of change is high. In such cases, interpolation and other similar techniques can be used to determine the change in redacted metadata in the intervening frames.
- the derived redacted media element can show a subject walking across the screen.
- the derived metadata for the subject can stay the same in the derived redacted media element for any predetermined period of time or number of frames (e.g., 0.5 second, 1 second, 1.5 seconds, etc., or over 2 frames, 4 frames, 8 frames etc.).
- interpolation techniques can be used to determine the subject’s movement and position in the intervening media frames.
- the derived metadata can be embedded in an encrypted manner.
- a receiving computing device e.g., devices 108a,b etc.
- it may then be decoded to extract the information contained in the derived metadata.
- network 105 may be connected to the internet.
- the connection between network 105 and the Internet may be made via a firewall server (not shown).
- a firewall server not shown.
- multiple networks 105 or virtual networks may be connected to the internet.
- Network 105 may be operated, which can be internetworked or isolated. These have been omitted for ease of illustration, however it will be understood that the teachings herein can be applied to such systems.
- Network 105 may be constructed from one or more computer network technologies, such as IEEE 802.3 (Ethernet), IEEE 802.11 and similar technologies, and can be wired or wireless.
- network 105 may be a WiFi® or cellular network.
- network 105 may be any network or network components capable of carrying data including the Internet, Ethernet, plain old telephone service (POTS) line, public switch telephone network (PSTN), integrated services digital network (ISDN), digital subscriber line (DSL), coaxial cable, fiber optics, satellite, mobile, wireless (e.g.
- POTS plain old telephone service
- PSTN public switch telephone network
- ISDN integrated services digital network
- DSL digital subscriber line
- coaxial cable fiber optics, satellite, mobile, wireless (e.g.
- Wi-Fi Wi-Fi
- WiMAX SS7 signaling network
- fixed line local area network
- LAN local area network
- WAN wide area network
- UMTS Universal Mobile Telecommunications System
- LTE Advanced 3GPP Long-Term Evolution Advanced
- 4G/5G networks Worldwide Interoperability for Microwave Access (WiMAX), etc.
- UMTS Universal Mobile Telecommunications System
- LTE Advanced 3GPP Long-Term Evolution Advanced
- WiMAX Worldwide Interoperability for Microwave Access
- WiMAX Worldwide Interoperability for Microwave Access
- Server 106 is a computer server that is connected to network 105.
- Server 106 has a processor, volatile and non-volatile memory, at least one network interface, and may have various other input/output devices. As with all devices shown in the system 100a, there may be multiple servers 106, although not all are shown. It will also be understood that the server 106 need not be a dedicated physical computer. For example, in various embodiments, the various logical components that are shown as being provided on server
- 106 may be hosted by a third party “cloud” hosting service such as AmazonTM Web ServicesTM Elastic Compute Cloud (Amazon EC2).
- cloud AmazonTM Web ServicesTM Elastic Compute Cloud (Amazon EC2).
- the server 106 may communicate with the edge device 110a to receive one or more of redacted media elements, derived metadata and/or derived redacted media elements. In some cases, the server 106 may receive this data and store this data for subsequent access by one or more computing devices 108. In other cases, the server 106 may transmit the redacted media elements, derived metadata and/or derived redacted media elements (i.e. , in real-time, or near real-time), to one or more computing devices 108. In some other embodiments, the server 106 may store one or more software programs that are operable to process the received data (i.e., redacted media elements, derived metadata and/or derived media elements), to generate further processed data.
- the server 106 is a “cloud server”
- communication between the edge device 110a and the cloud server 106 may allow the edge device 110a to act as part of the Internet of Thing (“loT”) (i.e., an loT edge device).
- LoT Internet of Thing
- Computing device 108 may be any suitable computing devices associated with third parties, such as a desktop computer, and may also include mobile devices such as smartphones, tablets or laptops.
- the computing devices 108 can receive the redacted media elements and derived metadata, and analyze the redacted media elements and derived metadata for further processing (i.e., monitoring the number of individuals, or types of individuals, to access a particular space over time based on the derived metadata).
- the computing devices 108 may be used analyze derived redacted metadata for the same.
- FIG. 1 B illustrates a simplified block diagram of an example embodiment of a system 100b for privacy at an edge device.
- the system 100b is generally analogous to the system 100a, with the exception that the edge device 110b comprises a single physical (e.g. a hardware unit) or virtualized unit 114, which includes both a media capturing unit 102b and the privacy redaction module 104. Accordingly, the unit 114 may be a specially adapted unit that is configured to carry out both functions of capturing media elements, and preforming redaction on the captured media elements.
- the edge device 110b comprises a single physical (e.g. a hardware unit) or virtualized unit 114, which includes both a media capturing unit 102b and the privacy redaction module 104.
- the unit 114 may be a specially adapted unit that is configured to carry out both functions of capturing media elements, and preforming redaction on the captured media elements.
- the edge devices 110a, 110b are physical components (e.g. a physical server, hardware or processor etc.). In some other cases, the edge devices 110a, 110b are virtualized components (e.g. a cloud device).
- the edge device receives one or more audio/video streams on one or more wired or wireless connections.
- the edge device 110b processes the received audio/video streams, redacting and transmitting the redacted streams to a server 106 or a computing device 108 or another third party for further processing and insight generation.
- the redaction is done in real-time or near real-time.
- the redaction and transmission are both done in real-time or near real-time.
- the edge device such as the edge device 110a, is an loT device and configured to receive one or more audio/video streams on one or more wired or wireless connections.
- the incoming streams are processed on the cloud or a virtualized server, generating redacted streams, derived metadata streams and/or derived redacted streams in real-time or near real-time.
- edge devices 110 may be located in the systems 100 and may be operating at any given time (i.e., concurrently or at separate times), and/or may be collecting media elements of the same or different locations at the same or different times.
- the edge devices can be any combination of the edge devices 100a or 100b.
- FIG. 2A shows a simplified block diagram of an example embodiment of an edge device, such as, for example, edge device 110a of FIG. 1A.
- the edge device 110a may generally include the media recording unit 102 which is connected (i.e., via wired secure connection) to the redaction device 112.
- the redaction device 112 includes a processor 208 and the redaction module 104.
- the processor 202 may also couple to one or more of a communication interface 204, an I/O unit 206, a memory 210, a power unit 212, or any combination of the aforementioned units.
- Processor 202 can be any suitable processor, controller or digital signal processor that can provide sufficient processing power depending on the configuration, purposes and requirements of the edge device 110a as is known by those skilled in the art.
- the processor 202 may be a high-performance general processor.
- the processor 202 can include more than one processor with each processor being configured to perform different dedicated tasks.
- the processor 202 may include a standard processor, such as an Intel® processor, an ARM® processor or a microcontroller.
- Communication interface 204 can include wired or wireless connection capabilities.
- the communication interface 204 can include a radio that communicates utilizing 4G, LTE, 5G, CDMA, GSM, GPRS or Bluetooth protocol according to standards such as IEEE 802.11a, 802.11 b, 802.11 g, or 802.11 n, etc.
- the communication interface 204 can be used by the redaction device 112 to communicate with other devices or computers via the network 105 of FIG. 1A.
- I/O unit 206 can include at least one of a mouse, a keyboard, a touch screen, a thumbwheel, a track-pad, a track-ball, a card-reader, voice recognition software and the like depending on the particular implementation of the redaction device 112. In some cases, some of these components can be integrated with one another. In various cases, the media recording unit 102a may couple to the redaction device 112, via the I/O unit 206.
- Power unit 212 can be any suitable power source that provides power to the redaction device 112 (and in some cases, the media recording unit 102a) such as a power adaptor or a rechargeable battery pack depending on the implementation of the redaction device 112 as is known by those skilled in the art.
- Privacy redaction module 104 may be used to identify target areas (i.e. , one or more contiguous or non-contiguous pixel areas) of a media element to redact, and to further redact these target areas.
- the redaction can occur by using any suitable redaction technique, including using a blur, mask, remove, ghost, or cover for any sensitive content present within a received media element, or otherwise content that is not desired to be viewable.
- the privacy redaction module 104 may be configured to redact faces, people entirely, license plates, addresses, text, moving objects, shadows, passports, objects with personal identifiers, objects on public property, objects on private property, airborne objects, or other lighting effects.
- the privacy redaction module 104 can also extract derived metadata from media elements, as well as embed the derived metadata into the media elements to generate derived redacted media elements.
- Privacy redaction module 104 may further comprise an artificial intelligence (Al) algorithm.
- the Al algorithm may be implemented by dedicated hardware, GPU hardware, as an FPGA, as part of a special function on a System on a Chip (“SoC”), or any combination of the aforementioned implementations.
- SoC System on a Chip
- the Al algorithm may be used to identify image areas requiring redaction, as further described in FIG. 3.
- Memory 210 may include both a volatile and non-volatile memory.
- Non-volatile memory stores computer programs consisting of computer-executable instructions, which may be loaded into volatile memory for execution by processor 202 as needed. It will be understood by those skilled in the art that reference herein to the edge device 110a as carrying out a function, or acting in a particular way, imply that processor 202 is executing instructions (e.g., a software program) stored in memory 210 and possibly transmitting or receiving input data and output data via one or more interfaces. Memory 210 may also store input data to, or output data from, processor 202 in the course of executing the computer-executable instructions.
- the memory 210 may store the privacy redaction module 104. That is, while the memory 210 and the privacy redaction module 104 have been illustrated separately for ease of exposition, the privacy redaction module 104 may comprise one or more executable instructions (i.e. , software program) stored in the memory 210.
- Memory 210 may also store software code for implementing a metadata database 216, a redacted media database 218, a transmit module 220, a receive module 222, and an operating system 224.
- the memory unit 210 can include RAM, ROM, one or more hard drives, one or more flash drives or some other suitable data storage elements such as disk drives, etc.
- the memory 210 is configured to store one or more of the incoming media elements from one or more of the media recording unit, as well as the generated redacted media elements, derived metadata and/or the derived redacted media elements (discussed in detail below).
- the one or more of the incoming media elements, redacted media elements, derived metadata and/or the derived redacted media elements are cached in the memory 210.
- the cache may be cleared upon a predetermined duration of time in some cases. In some other cases, the cache may be cleared once the redacted media elements, derived metadata and/or the derived redacted media elements are transmitted from the edge device 110 over the network.
- Metadata database 216 may be configured to store information, such as information taken from the redacted image areas within media elements (i.e. , derived metadata), or otherwise information related to the media elements in the redaction system.
- Redacted media database 218 may be configured to store previously redacted media elements.
- Transmit module 220 is configured to, in collaboration with other components of the edge device 110a, configure and transmit (i.e., via the communication interface 204) data signals (or data streams) for transmittal.
- the transmit module 220 encodes the device’s data into a data signal and transmits the data signal.
- the data signals can include one or more of redacted media elements, derived metadata and/or derived media elements.
- the data signals may be transmitted over network 105.
- Receive module 222 is configured to receive one or more information signals from one or more other devices (i.e., via the communication interface 204).
- the receive module 222 in collaboration with other components of the edge device 200, may be configured to receive media elements from at least one media recording unit.
- Operating system 224 provides various basic operational processes for the operation of the edge device 110a.
- the operating system 224 may be a Microsoft® Windows Server® operating system, or a Linux®-based operating system, Unix® or macOS®, or another operating system.
- FIG. 2B shows a simplified block diagrams of an example embodiment of the edge device 110b of FIG. 1 B.
- the edge device 110b is generally analogous to the edge device 110a, with the exception that the media recording unit 102 is located within the same hardware block as the remaining components (i.e., 104, 202 - 224). In these cases, the media recording unit 102 may be directly coupled to the processor 202 (or may be indirectly coupled as well).
- FIG. 2C shows a simplified block diagrams of an example embodiment of a computing device 108.
- the computing device 108 may also include a processor 226 coupled to a memory 228 and one or more of a decoding unit 230, I/O unit 222 and a communication interface 234.
- the decoding unit 230 can be used to decode (i.e. , de-encrypt) received derived metadata that is received from an edge device 110 and/or server 106.
- the decoding unit 230 can also be used to extract and decode (i.e., de-encrypt) derived metadata that is embedded in a derived redacted media element.
- the decoding module 230 may be a software module that is stored on the memory 228 and executed by the processor 226.
- the server 106 may have a similar hardware and software architecture as the computing device 108.
- FIG. 3A there is shown a simplified block diagram of an example embodiment of a privacy redaction process 300a in accordance with some embodiments.
- a media recording unit 102 may transmit an incoming stream to the privacy redaction module 104.
- the privacy redaction module 104 may include a redaction area identification unit 304 and a redaction unit 306.
- Redaction area identification unit 304 may be configured to receive one or more media elements from the media recording unit 102, and identify target redaction areas based on one or more redaction rules.
- the redaction rules can classify areas of the media elements that require redaction, and can comprise, for example, groups of contiguous or non-contiguous pixels in a media elements.
- the redaction rules may include, for example, determining the presence in media elements of faces, people entirely, license plates, addresses, text, moving objects, shadows, passports, objects with personal identifiers, objects on public property, objects on private property, airborne objects, or other lighting effects.
- the redaction rules used by a given privacy redaction module 104 may vary based on various redaction configuration settings.
- an example redaction setting can be the environment in which the media recording unit 102 is located. That is, the redaction rules may vary based on the surrounding environment.
- the redaction rules may involve marking areas for redaction in media elements that correspond to human subjects. That is, in washroom or bathroom settings the redaction rules can specifically target human subjects to preserve their privacy in the washroom or bathroom setting.
- a similar idea may be followed in the case of deploying the edge device 110 in a swimming pool area.
- the redaction rules may involve not only identifying the presence of subjects, but also identifying for redaction areas where license plates are identified in the media elements, or objects located on private property.
- the redaction rules may also vary based on other redaction settings that include the time of day. For example, certain objects can be redacted at different times of the day (e.g., cars versus people, etc.), as for example if an area is repurposed during the course of a day.
- the time of day can be monitored, for example, based on an internal clock in the edge device 110 (not shown), or one or more ambient light sensors (i.e. , detect dark versus light conditions), or an external source of ‘time of day’ information (not shown).
- the redaction rules may vary based on the area of the media element being analyzed. That is, within a given media element, some portions of the media element may have different redaction rules than other portions of the media element. For example, if the media element corresponds to an image of a room, different parts of the rooms may have different redaction rules. For example, if a camera is monitoring a room that includes one or more cloth changing stalls that are viewable by the camera, it may be desirable to implement unique redaction rules for the known areas of the media element which correspond to the imaged locations of the changing stalls. Accordingly, if a customer enters a changing stall, the redaction rules may be automatically applied to preserve the privacy of that individual while they are changing.
- redaction rules may no longer apply.
- another redaction setting is the area (or portion) of the media element being analyzed.
- the area of a media element that is subject to the redaction rules may vary based on factors including, the time of day or the location of the edge device 110.
- the redaction rules and/or redaction configuration settings may be pre-set (or pre-defined). For example, during an initialization stage, an operator may interact with the edge device 110 to configure the redaction settings, as well as the redaction rules associated with that setting. For example, the operator may stipulate a redaction rule that any detected human subjects should be redacted, but may qualify this rule with a setting that the redaction rule only applies between 8 AM to 5 PM, or only to particular regions of a media element. The operator may also initialize these rules and settings for an edge device 110 having regard, for example, to the environment in which the edge device 110 is located. In some cases, the modification of the redaction rules and/or settings may occur directly by interacting with the I/O unit 206 of each edge device 110. In other cases, the redaction rules and/or settings can be modified remotely (i.e. , via a computing terminal 108 communicating via the network 105).
- a privacy redaction hardware unit 114 may also be coupled to multiple media recording units 102.
- the privacy redaction module 104 can store different redaction profiles (i.e., redaction rules and/or redaction settings) for different media recording units 102.
- the identification unit 304 may generate an indication of the target areas for redaction.
- the identification unit 304 may generate pixel coordinate data defining the area of the media element requiring redaction.
- these can include coordinate data for one or more corners of an imaginary bounding box around the target area (i.e., or any other shape of bounding box).
- the output of the identification unit 304 is a media element comprising one or more marked visual indications of the target redaction areas (i.e., a lined bounding box around the area).
- the identification unit 304 may be operable to perform image analysis on the received media elements.
- the identification unit 304 may include a trained image analysis machine learning model.
- the trained machine learning model may be configured to analyze the media to locate specific areas (e.g., pixel groups) that satisfy certain redaction rules and/or settings.
- the trained machine learning model may be trained to identify human faces, license plates, specific classes of objects, etc. as the case may be.
- the trained machine learning model is a trained convolution neural network (CNN) configured to perform classification of image areas.
- CNN convolution neural network
- the redaction unit 306 may then receive the media elements from the identification unit 304, as well as the indications of the target redactions areas, and may apply redaction to those designated areas to generate the redacted media element. For example, this may include applying a blur, mask, remove, ghost, or cover to the target redaction areas.
- FIG. 5A shows an exemplary image 500a before redaction in accordance with an example embodiment.
- the image 500a contains unredacted data, for example, of people and potential identifying information.
- FIG. 5B shows an exemplary image 500b after redaction, and includes the redacted data 502.
- the redaction rule used to identify the target redaction image areas is the presence of “people”, or human subjects.
- FIG. 6A shows another exemplary image 600a before redaction.
- the image 600a contains unredacted data, for example, of people and potential identifying information (e.g., license plate numbers and address information).
- FIG. 6B shows an exemplary image 600b after redaction.
- the image 600b contains redacted data 602.
- the redaction rules used to identify image areas that require redaction may include “license plates”, “home addresses”, “people” and “text”.
- FIG. 3B there is shown a simplified block diagram for an example embodiment of a privacy redaction process 300b in accordance with some other embodiments.
- the process 300b is generally analogous to the process 300a of FIG. 3A, with the exception that the privacy redaction module 104 has an added metadata extraction functionality using a metadata extraction unit 312.
- the metadata extraction unit 312 is operable to extract derived metadata corresponding to one or more identified target redaction area, prior to the area being redacted. That is, once the target redaction area is indicated by the identification unit 304, the metadata extraction unit 312 may extract specific pre-defined features from that area which define the derived metadata. In some cases, the metadata extraction unit 312 can operate on the media element prior to the redaction unit 306. In other cases, the metadata extraction unit 312 can operate on the media element (or a copy thereof) concurrently or partially concurrently with the redaction unit 306.
- the derived metadata generated by the metadata extraction unit 312, can include various identifying information about the target redaction area.
- the derived metadata can include information about the subject’s sex, height, body type, hair color, skin color, eye color, color of clothing, color composition related to the subject, etc.
- the derived metadata can include information, for example, about the geographic area tied to the license plate (such as the state or province), the license plate number itself etc. Accordingly, the derived metadata can correspond to any desirable extractable information based on one or more features, properties or characteristics of the target redaction area.
- the derived metadata can provide important information for third parties observing and analyzing the redacted images.
- the derived metadata, extracted from a given target redaction area may vary based on the subject matter being redacted. For example, if the redacted area corresponds to a human face, the corresponding derived metadata may include analyzing the subject’s sex, skin color, eye color or hair color etc.
- the derived metadata for a license plate can be, as previously discussed, the license plate number and the geographic area of the license plate (such as the state or province). Accordingly, there may be pre-defined metadata extraction rules for extracting derived metadata based on the subject matter being identified for redaction. In some cases, the pre-defined metadata extraction rules may correspond to the redaction rule applied.
- the extraction unit 312 may automatically extract certain metadata associated with human faces.
- the extraction rules may be the same as the redaction rules.
- the extraction rules may not be the same as the redaction rules.
- the metadata extraction rules may specify that if the human face is determined to be a male then a first set of metadata is extracted, otherwise if the human face is determined to correspond to a female, then a second set of metadata is extracted. Accordingly, in some cases, the metadata extraction rules may depend on previously extracted metadata (e.g., the extracted human subject’s perceived sex).
- the metadata extraction rules may also vary based on various external parameters, such as the environment, time of day, location of the edge device, etc.
- the metadata extraction unit 312 may also operate a trained machine learning module (i.e. , a CNN) that is operable to analyze media elements and extract relevant metadata.
- a trained machine learning module i.e. , a CNN
- the metadata extraction rules can be varied, directly or indirectly, by an operator interacting with the edge device 110.
- different media recording units 102 may be associated with different derived metadata profiles, or otherwise different profiles for the type of derived metadata generated.
- the privacy redaction module 104 may generate two streams of data corresponding to the redacted media element 308 and the derived metadata 310.
- the two streams may be transmitted through a single transport stream (i.e., a single multiplexed data stream). In other embodiments, the two streams may be transmitted through separate transport streams.
- the two streams can be identified as corresponding to one another by pixel location, pixel count, pixel coordinates, location of redacted object, or any other method of identifying corresponding redacted media element 308 with derived metadata 310.
- FIG. 3C shows a simplified block diagram for an example embodiment of a privacy redaction process 300c in accordance with one or more embodiments.
- the process 300c is generally analogous to the process 300b with the exception that the privacy redaction module 104 does not generate a separate redacted media element and derived metadata streams, but rather embeds at least a portion of the derived metadata into the redacted media element.
- the derived metadata is embedded in a free space around the redacted media element frame to generate a derived redacted media element 316.
- the derived metadata is overlaid (completely or partially) on the redacted media element frame to generate a derived redacted media element 316.
- the derived metadata is embedded directly in-line with the redacted media element frame to generate a derived redacted media element 316.
- transmitted the redacted media elements and the derived metadata as two separate streams may be more resource intensive. For example, additional information may need to be stored in the derived metadata to enable correlation with the redacted media elements at a future time.
- a media embedding unit 314 may be provided in the privacy redaction module 104 to embed and/or encode the derived metadata (e.g., from the metadata extraction unit 312) into the redacted media element (e.g., generated by the redaction unit 306).
- FIG. 7 shows an exemplary derived redacted media element 700 in accordance with one or more embodiments.
- the derived metadata may be embedded into the redacted media element to create the derived redacted media element 700.
- the redaction areas of the image correspond to human subjects
- the derived metadata corresponds, for example, to the height and width of each subject, as well as to the subject’s sex and the subject’s center position in the image.
- the derived metadata is embedded into each redacted image area 702a - 702f by a visual indicia that is located (e.g., overlaid) on the redacted area position.
- the derived metadata is encoded into various variable or adjustable properties of the visual indicia.
- an “X” mark is used as the visual indicia to encode and embed the derived metadata directly into the media element.
- the location of the “X” can indicate the location of the pixel coordinates of the redacted subject in the image.
- the point where the “X” crosses can indicate a center point location for the subject.
- the height of the “X” mark i.e. , extending from the top to the bottom of the redacted area
- the width of the “X” mark can express the width of the subject.
- different colors of markings can also be used to express different information (i.e., a blue “X” can indicate a male, while a pink “X” can indicate a female).
- the derived metadata can also be expressed by adjusting other properties of the visual indicia including, for example, the type of line used (e.g., a choice of a stippled, solid or dotted lines for the “X” mark can indicate one or more of the sex, age, race etc. of the redacted subject) and the width of the line used (e.g., graded degrees of line thickness can indicate the size etc. of the human subject).
- each new adjustable variable in the visual indicia adds a new degree or dimension for information encoding.
- different portions of the same visual indicia may also have adjustable properties, which further increases the constellation of data that can be encoded.
- the top half of the “X” may have a thicker or thinner line width than the bottom half of the “X”, or the top half of the “X” may have a different line type (e.g., stippled, solid or dotted).
- the actual shape of the visual indicia may be another adjustable property. For instance, varying the shape properties of the visual indicia can, itself, encode different types of metadata (e.g., a circle may denote a child, while a triangle can denote an adult, etc.)
- FIG. 8 shows another example embodiment where a visual indicia is used to embed the derived metadata into the redacted media element to generate the derived media element 800.
- each redacted object 802a - 802e is marked with an “X” to indicate a position and/or size of the redacted image area.
- the visual indicia’s may not be shapes, but can be any other suitable indicia such as a barcode, a QR code, various shape patterns, color grid encoding, text (i.e., plain text expressing the metadata or coded/crypted text (e.g., hashes, alphanumeric codes, etc.)).
- the derived metadata can also be encoded by varying the type of redaction method used (e.g., the type of blur, cover or mask can be selected to encode certain data).
- the size of the redaction area may, itself, encode metadata.
- the height and/or width of the redacted area can indicate the height and width of the subject.
- non-visual indicia i.e. , watermarks
- non-visual indicia i.e. , watermarks
- the computer device 108 may include the decoding module 230 that stores the pre-configured decoding rules in order to extract and decode metadata from each received derived redacted media element.
- FIG. 9 there is shown an exemplary derived redacted media element 900 in accordance with some other embodiments.
- the derived media element 900 is generally analogous to the derived redacted media element 700, with the exception that the indicia 902 used to encode the metadata may not be directly overlaid (completely or partially) over the redacted areas.
- an augmented redacted media element 900 can be generated, whereby additional area is inserted around one or more edges (or portions of edges) of the redacted media element, and the indicia can be inserted in the surplus area.
- the redacted media element can be cropped and the indicia can be inserted in the additional area resulting from the cropping.
- the indicia 902 can be directly overlaid (completely or partially) over the media element, but not directly overlaid over the redacted areas.
- the indica 902 can be embedded anywhere in the media element where there is free space.
- each discrete indicia included in the derived redacted media element 900 can correspond to a specific redacted area (i.e., a one-to-one mapping).
- each indicia may also encode information about which redaction target area it corresponds to.
- each indicia can include one or more pixel coordinate information about the location of the target area that is associated with that marking (e.g., coordinates of the center point of the redacted area, or coordinates of one or more corners of the redacted area).
- a decoding module 230 can associate different indicia 902 with different associated redacted areas.
- a single indicia can also correspond to more than one redaction area, and may include encoded information about which redaction areas it corresponds to.
- multiple redaction areas may have similar derived metadata, which can be encoded using a single indicia.
- the indicia can include the common derived metadata between each target area, as well as identifying information about which target areas are associated with this common derived metadata.
- multiple indicia can correspond to the same redaction area, and may include encoded information about which redaction areas it corresponds to.
- the same redaction area may have multiple metadata points, such as data corresponding to height and color composition, which can be encoded using multiple indicia.
- the indicia can include the derived metadata as well as identifying information about which target areas are associated with this derived metadata.
- FIGS. 10A and 10B show other example embodiments where the indicia 1002 used to encode the metadata is not directly overlaid over the redacted areas in the generation of derived media elements 1000a and 1000b, respectively.
- the derived media elements 1000a and 1000b are generally analogous to the derived media element 900.
- FIG. 10A is a frame recorded prior to the frame recorded in FIG. 10B.
- tagged indicia 1002a and 1002b can correspond to a particular subject 1004 for tracking purposes.
- a particular subject 1004 can be tagged by the edge device 110 and can be monitored as the subject 1004 moves from frame to frame.
- the indicia 1002a and 1002b can encode information such as skin color, hair color, eye color, clothing color, or color composition of the subject 1004 as well as target information about which redaction target area it corresponds to.
- each indicia can include one or more pixel coordinate information about the location of the subject 1004 and the color composition of the subject 1004.
- Color composition can be a gradient taken from hair color, skin color, clothing color and shoe color to identify the subject as they move across multiple frames.
- pixel location of the subject 1004 can be identified and compared between frames to determine location of the subject 1004.
- depth tracking can be used for assistance in location determination.
- subject 1004 is located on the left side of the frame and corresponding to indicia 1002a in FIG. 10A.
- FIG. 10B shows the subject 1004 within the center of the frame corresponding to indicia 1002b.
- Subject 1004 can be identified across multiple fames by the edge device processor 202 based on the color composition.
- the subject 1004 can be tracked over multiple frames taken by the media recording unit 102 at the edge device 110.
- the subject s clothing or a particular piece of clothing, the number of visible suitcases associated with them, the height and width of the subject etc. can be used to identify and track subjects.
- Tracking features can be used to determine traffic flow patterns at traffic lights, pedestrian crossing usage, data collection at airports (e.g.. determining how many people are catching connecting flights vs. have reached their final destination), time spent by students at their lockers in schools, etc.
- multiple objects and/or subject can be tagged and tracked at the same time in the same frames.
- Tracking can be done in real-time or near real-time as well as by post processing not in real-time.
- multiple objects and/or subjects identified in frames of the derived media elements may be tracked using previously recorded frames.
- previously derived metadata from the media elements can be used to determine movements of objects and/or subjects detected.
- previously recorded frames of media elements having derived metadata can be processed to determine if multiple recorded indicia correspond to the same object (e.g., identical metadata on color composition, etc.) across multiple frames. The object can then be tracked using metadata embedded within the free space around the redacted media element.
- indicia 1002 can be used for counting purposes.
- color composition of objects can be used to determine the number of objects within a frame.
- the color composition of object 1004 may be different than the color composition of object 1006.
- Object 1004 and object 1006 can be counted as separate objects based on the color composition.
- Color composition can be used to prevent counting an object twice in the same frame or media segment.
- facial detection can be used to count individual people within a frame.
- the ability to integrate the counting of objects with object tracking can be beneficial. For example, in an airport, data can be collected based on how many people are leaving a first airport gate and moving to a second airport gate for a connecting flight.
- the number of individuals leaving the first airport gate can be noted, and each individual can be tracked to determine if they have moved from the first airport gate to the second airport gate. This can show how many individuals have actually entered the second airport gate from the first airport gate, as opposed to taking a general number of individuals entering the second airport gate, which would not provide a data point on how many individuals have taken a connecting flight.
- Use cases for the edge device 100 may include using the device in washrooms, schools, airports, restaurants, sports venues, shops, recreational facilities, or any other establishment. Further use cases may include monitoring roadways, traffic stops, crosswalks, parking lots, etc. In such use cases, privacy is of importance to individuals.
- the edge device 100 provides a way to protect the privacy of individuals as the raw media does not leave the edge device 100.
- the media can be examined, metadata can be derived, certain elements in the media can be redacted and metadata can be embedded within the redacted media prior to the media leaving the edge device 100.
- work locations e.g., mines, yards, etc.
- loads taken from or brought to the work location by the trucks can be monitored, the number of trucks can be counted, etc., while protecting the privacy of the individuals driving.
- the license plates of the trucks as well as individual faces of the drivers can be redacted to protect individual privacy.
- the present application can allow monitoring and extraction of data based on individuals without compromising on induvial privacy.
- the ability to track and count subjects, objects or vehicles for statistical purposes while maintaining individual privacy is important on institutional and personal levels.
- FIG. 4A shows an example embodiment of a method 400a for redacting media elements at an edge device.
- Method 400a can be performed, for example, by the processor 202 of the edge device 110.
- a media element is received from a media recording unit 102 by the edge device processor 202.
- the media element may be, for example, a video comprising multiple video frames, where each frame requires redaction of identified areas.
- the media element may be an image.
- the media element is analyzed in real-time or near real-time by the edge device processor 202 (i.e. , executing the privacy redaction module 104) to identify any areas of the media element require redaction (i.e., target redaction areas).
- the media element is not necessarily analyzed in real-time or near real-time, but rather is stored on the memory 210 and may be retrieved for subsequent analysis.
- the target redaction areas may be identified based on one or more redaction rules and/or redaction settings.
- the target redaction areas can be identified, as also discussed, by using one or more indicators (i.e., pixel coordinates) of the areas requiring redaction.
- the identified target redaction area or areas are redacted from the media element to generate a redacted media element.
- the redaction occurs in real-time or near real-time. In other cases, the redaction can occur on a previously stored media element (i.e., stored on the edge device memory 210).
- the redacted media element may be transmitted, for example, to one or more computer devices 108 via network 105.
- FIG. 4B shows an example embodiment of a method 400b for redacting media elements at an edge device 110.
- Method 400b can be performed, for example, by the processor 202 of the edge device 110.
- Method 400b is generally analogous to method 400a, with the exception that after identifying the target image redaction areas at act 404b, at 406b, the privacy redaction module 104 can extract derived metadata from one or more of the areas identified as target redaction areas. At 408b, the target image redaction areas can then be redacted. At 410b, the redacted media element and the derived metadata may be separately transmitted.
- Method 400c can be performed, for example, by the processor 202 of the edge device 110.
- Method 400c is generally analogous to method 400b, with the exception that at act 410c, one or more derived metadata can be embedded and/or encoded into the redacted media element to generate a derived redacted media element. At act 412c, the derived redacted media element may be transmitted.
- Method 400d can be performed, for example, by the processor 202 of the edge device 110.
- Method 400d is generally analogous to method 400c, with the exception that at act 41 Od, the processor 202 can make a decision on the location where the metadata can be embedded to generate a derived redacted media element.
- the decision at act 41 Od can be made based on pre-programmed conditions.
- the pre-programmed conditions can be selected by a user, based on location, for particular projects, based on the number of redacted items, etc.
- the edge device 110 is located at a traffic light
- the pre-programmed condition can be directed to act 412d.
- one or more derived metadata can be embedded and/or encoded into the redacted media element to generate a derived redacted media element, as shown in FIG. 7, for example.
- the pre-programmed condition at a traffic light may embed the derived metadata within the redacted media element as the number of subjects at a traffic light can be lower than the number of subjects at, for example, an airport. The reduced number of subjects results in a derived redacted media element that contains the derived metadata in the media element without being overcrowded.
- the derived redacted media element may be transmitted.
- the pre programmed condition can be direction to act 416d.
- one or more derived metadata can be embedded and/or encoded into area around the redacted media element to generate derived redacted media element, as shown in FIG. 9, for example.
- the pre-programmed condition at an airport may embed the derived metadata into the area surrounding the redacted media element as the number of subjects can be a lot higher. In such instances, having the metadata embedded within the media element can result in a crowded frame and as such, embedding the metadata around the media element results in increased readability.
- the derived redacted media element may be transmitted.
- the decision at act 41 Od can be made based on dynamic pre programmed conditions.
- the dynamic pre-programed conditions can change based on the metadata derived from the at least one or more target image redaction areas.
- the edge device 110 may be initially pre-programmed to embed the derived metadata into the redacted media image at act 412d when being used to count individuals. Once a certain number of individuals have been counted, the edge device 110 may change pre-programmed conditions to embed the derived metadata into the area around the redacted media image at act 416d.
- Method 400e can be performed, for example, by the processor 202 of the edge device 110.
- Method 400e is generally analogous to method 400c, with the exception that at act 41 Oe, external input can be received at the communication interface 204 of the edge device 110 to embed derived metadata into the redacted media element.
- one or more derived metadata can be embedded and/or encoded into the redacted media element to generate a derived redacted media element.
- the metadata can be embedded by way of an overlaid layer, where the overlay may be partial or complete.
- the metadata can be embedded in the same layer as the redacted image.
- the derived redacted media element may be transmitted.
- Method 400f can be performed, for example, by the processor 202 of the edge device 110.
- Method 400f is generally analogous to method 400e, with the exception that at act 41 Of, external input can be received at the communication interface 204 of the edge device 110 to embed derived metadata into the area around the redacted media element. At act 412f, one or more derived metadata can be embedded and/or encoded into the area around the redacted media element to generate a derived redacted media element. At act 414f, the derived redacted media element may be transmitted.
- the external input may be from a user or an operator of the edge device.
- a prompt may be provided to the user to select where the derived metadata may be input in relation to the redacted media element.
- the prompt may be triggered by a pre-determ ined time.
- the prompt may be triggered based on metadata collected from the redacted media element. For example, if the metadata collected includes the count of the number of people within the frame, once the count reaches 50, the prompt may be triggered. In some cases, the prompt may be triggered by a user configuration instruction.
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Software Systems (AREA)
- General Engineering & Computer Science (AREA)
- Bioethics (AREA)
- Medical Informatics (AREA)
- Multimedia (AREA)
- Databases & Information Systems (AREA)
- Artificial Intelligence (AREA)
- Evolutionary Computation (AREA)
- Computing Systems (AREA)
- Data Mining & Analysis (AREA)
- Mathematical Physics (AREA)
- Computer Hardware Design (AREA)
- Computer Security & Cryptography (AREA)
- Molecular Biology (AREA)
- Computational Linguistics (AREA)
- Computer Vision & Pattern Recognition (AREA)
- Biophysics (AREA)
- Biomedical Technology (AREA)
- Life Sciences & Earth Sciences (AREA)
- Signal Processing (AREA)
- Two-Way Televisions, Distribution Of Moving Picture Or The Like (AREA)
- Image Analysis (AREA)
Abstract
Description
Claims
Priority Applications (4)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP22778264.6A EP4315113A4 (en) | 2021-03-31 | 2022-03-31 | METHOD AND SYSTEM FOR WRITING MEDIA AT A PERIPHERAL DEVICE |
| CA3213061A CA3213061A1 (en) | 2021-03-31 | 2022-03-31 | Method and system for media redaction at an edge device |
| PH1/2023/552621A PH12023552621A1 (en) | 2021-03-31 | 2022-03-31 | Method and system for media redaction at an edge device |
| US18/371,018 US20240012939A1 (en) | 2021-03-31 | 2023-09-21 | Method and system for media redaction at an edge device |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US202163168777P | 2021-03-31 | 2021-03-31 | |
| US63/168,777 | 2021-03-31 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US18/371,018 Continuation US20240012939A1 (en) | 2021-03-31 | 2023-09-21 | Method and system for media redaction at an edge device |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2022204817A1 true WO2022204817A1 (en) | 2022-10-06 |
Family
ID=83455304
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CA2022/050490 Ceased WO2022204817A1 (en) | 2021-03-31 | 2022-03-31 | Method and system for media redaction at an edge device |
Country Status (5)
| Country | Link |
|---|---|
| US (1) | US20240012939A1 (en) |
| EP (1) | EP4315113A4 (en) |
| CA (1) | CA3213061A1 (en) |
| PH (1) | PH12023552621A1 (en) |
| WO (1) | WO2022204817A1 (en) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2025120760A1 (en) * | 2023-12-06 | 2025-06-12 | 株式会社日立ハイテク | Data management system control method |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20250111086A1 (en) * | 2023-09-28 | 2025-04-03 | Motorola Mobility Llc | Electronic device that selectively presents an anonymized image version of an image sourced from the device on a secondary display connected to the device |
Citations (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20160378999A1 (en) * | 2015-06-24 | 2016-12-29 | Airwatch Llc | Dynamic content redaction |
| US20190068895A1 (en) * | 2017-08-22 | 2019-02-28 | Alarm.Com Incorporated | Preserving privacy in surveillance |
| US20190138748A1 (en) * | 2017-11-06 | 2019-05-09 | Microsoft Technology Licensing, Llc | Removing personally identifiable data before transmission from a device |
| US20190373210A1 (en) * | 2018-06-05 | 2019-12-05 | Axon Enterprise, Inc. | Systems and methods for redaction of screens |
| US20200074156A1 (en) * | 2017-09-06 | 2020-03-05 | Hitachi Vantara Corporation | Emotion detection enabled video redaction |
| US10789385B1 (en) * | 2016-05-04 | 2020-09-29 | United Services Automobile Association (Usaa) | Dynamic tagging of media for service sessions |
| US20200402280A1 (en) * | 2019-06-24 | 2020-12-24 | Realwear, Inc. | Photo redaction security system and related methods |
Family Cites Families (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP7036493B2 (en) * | 2016-02-26 | 2022-03-15 | アイオムニセント ピーティーワイ リミテッド | Monitoring method and equipment |
| US11386229B2 (en) * | 2019-07-04 | 2022-07-12 | Blackberry Limited | Filtering personally identifiable information from vehicle data |
-
2022
- 2022-03-31 PH PH1/2023/552621A patent/PH12023552621A1/en unknown
- 2022-03-31 WO PCT/CA2022/050490 patent/WO2022204817A1/en not_active Ceased
- 2022-03-31 CA CA3213061A patent/CA3213061A1/en active Pending
- 2022-03-31 EP EP22778264.6A patent/EP4315113A4/en not_active Withdrawn
-
2023
- 2023-09-21 US US18/371,018 patent/US20240012939A1/en not_active Abandoned
Patent Citations (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20160378999A1 (en) * | 2015-06-24 | 2016-12-29 | Airwatch Llc | Dynamic content redaction |
| US10789385B1 (en) * | 2016-05-04 | 2020-09-29 | United Services Automobile Association (Usaa) | Dynamic tagging of media for service sessions |
| US20190068895A1 (en) * | 2017-08-22 | 2019-02-28 | Alarm.Com Incorporated | Preserving privacy in surveillance |
| US20200074156A1 (en) * | 2017-09-06 | 2020-03-05 | Hitachi Vantara Corporation | Emotion detection enabled video redaction |
| US20190138748A1 (en) * | 2017-11-06 | 2019-05-09 | Microsoft Technology Licensing, Llc | Removing personally identifiable data before transmission from a device |
| US20190373210A1 (en) * | 2018-06-05 | 2019-12-05 | Axon Enterprise, Inc. | Systems and methods for redaction of screens |
| US20200402280A1 (en) * | 2019-06-24 | 2020-12-24 | Realwear, Inc. | Photo redaction security system and related methods |
Non-Patent Citations (1)
| Title |
|---|
| See also references of EP4315113A4 * |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2025120760A1 (en) * | 2023-12-06 | 2025-06-12 | 株式会社日立ハイテク | Data management system control method |
Also Published As
| Publication number | Publication date |
|---|---|
| PH12023552621A1 (en) | 2024-02-19 |
| EP4315113A4 (en) | 2025-01-22 |
| CA3213061A1 (en) | 2022-10-06 |
| US20240012939A1 (en) | 2024-01-11 |
| EP4315113A1 (en) | 2024-02-07 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US10812761B2 (en) | Complex hardware-based system for video surveillance tracking | |
| CN107358146B (en) | Method for processing video frequency, device and storage medium | |
| US9754630B2 (en) | System to distinguish between visually identical objects | |
| EP3692461B1 (en) | Removing personally identifiable data before transmission from a device | |
| US20240012939A1 (en) | Method and system for media redaction at an edge device | |
| Shu et al. | Cardea: Context-aware visual privacy protection for photo taking and sharing | |
| US20210407266A1 (en) | Remote security system and method | |
| CN109766779A (en) | Hovering Person Identification Method and Related Products | |
| Korshunov et al. | Framework for objective evaluation of privacy filters | |
| US20130216107A1 (en) | Method of surveillance by face recognition | |
| US10248870B2 (en) | Traffic-counting system and method thereof | |
| US8929596B2 (en) | Surveillance including a modified video data stream | |
| WO2019245680A1 (en) | Automatic video privacy | |
| CN106454253A (en) | Method and system for detecting area wandering | |
| KR102297575B1 (en) | Intelligent video surveillance system and method | |
| US20170300751A1 (en) | Smart history for computer-vision based security system | |
| CN106303469A (en) | Video analysis detection method and system to indoor and outdoor surroundings Flame | |
| CN109815839B (en) | Loitering person identification method under micro-service architecture and related product | |
| CN105791747A (en) | Video monitoring method and apparatus | |
| US20210364356A1 (en) | System and method for using artificial intelligence to enable elevated temperature detection of persons using commodity-based thermal cameras | |
| CN105072478A (en) | Life recording system and method based on wearable equipment | |
| Kumar et al. | Border surveillance system using computer vision | |
| CN111385530B (en) | Intelligent camera combined encryption method and system | |
| CN110111436A (en) | A kind of face is registered method, apparatus and system | |
| CN115802107A (en) | Method and device for pushing information by intelligent equipment and intelligent equipment |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 22778264 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 3213061 Country of ref document: CA |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 12023552621 Country of ref document: PH |
|
| WWE | Wipo information: entry into national phase |
Ref document number: P6002495/2023 Country of ref document: AE |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2022778264 Country of ref document: EP |
|
| ENP | Entry into the national phase |
Ref document number: 2022778264 Country of ref document: EP Effective date: 20231031 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| WWW | Wipo information: withdrawn in national office |
Ref document number: 2022778264 Country of ref document: EP |