Overview
ISO/IEC 23000-21:2019 - part of the MPEG‑A family - defines a standard representation for the signalling and data used to preserve privacy when storing and sharing images and video. Commonly called the Visual Identity Management Application Format, this standard enables selective protection of image/video regions (for example faces or text) and describes how privacy description information (PDI) is represented, signalled and applied across the media lifecycle.
Keywords: ISO/IEC 23000-21, MPEG‑A, visual identity management, privacy, selective encryption, content sensitive encryption.
Key topics and technical requirements
- Standard representation of privacy signalling: Defines how to express access control, region descriptions, user/context/service descriptions and other privacy metadata so they can be processed and enforced interoperably.
- Privacy Description Management (PDI): A framework for encoding user descriptions, context and service descriptions (MPEG‑21 user description integration is referenced) to drive authorization decisions.
- Content Sensitive Encryption (CSE) / Selective encryption: Mechanisms to encrypt subsets of compressed bitstreams (regions of interest, ROI) while retaining format compliance so parts of a stream remain decodable under limited access.
- CSE coverage includes application to Rec. ITU‑T H.264 / ISO/IEC 14496‑10 (AVC) and HEVC (H.265) coding, and region encryption for AVC/HEVC.
- The standard specifies signalling for CSE and examples of schemes (e.g., an AES‑CTR based 'sve1' sensitive encryption scheme is referenced).
- System-level support and signalling: Requirements for signalling protected streams, multiple-access scenarios, content-sensitive encryption markers applied to video NAL units, and metadata to support per-region keys and access control.
- Scope boundaries: Key management (distribution/PKI/DRM) is explicitly out of scope - the document focuses on representation and signalling rather than key provisioning.
Practical applications and who uses it
ISO/IEC 23000-21 is applicable to:
- Multimedia service and streaming providers who need to protect user privacy in shared or hosted media.
- Social networks and video‑sharing platforms implementing per-region privacy controls (faces, license plates, sensitive text).
- Camera and device manufacturers building privacy-aware capture apps that embed PDI and selective encryption at capture time.
- Content protection engineers, security architects and standards implementers integrating selective encryption and interoperable privacy metadata into workflows and players.
- Developers of privacy-compliant sharing/storage systems who require a standardized way to express who can view which regions and under what conditions (time, purpose, group, etc.).
Keywords: privacy protection, selective encryption, region of interest, PDI, MPEG‑A implementation.
Related standards
This standard helps restore user control and enable interoperable privacy management for modern image/video sharing and storage ecosystems.