Dynamic key threshold fragmentation privacy tracing method based on block chain collaborative verification
Through blockchain dynamic key threshold sharding and zero-knowledge proof verification, combined with the encoding and decoding watermark of the Unet architecture, the contradiction between privacy protection and regulatory traceability in video conferencing is resolved, and end-to-end encryption and verifiable traceability of data are achieved, protecting user privacy and accountability.
Patent Information
- Application Number
- CN202511256795.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-04
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2045-09-04
AI Technical Summary
Existing blockchain technology makes it difficult to achieve both privacy protection and regulatory traceability in video conferencing. Traditional solutions have the risk of single point failure and the problem of ineffective responsibility traceability.
A dynamic key threshold sharding method based on blockchain is adopted to generate a master key pair and DID identifier, use zero-knowledge proof to verify information, and combine the encoding and decoding fusion watermark of the Unet architecture to achieve end-to-end encryption and verifiable traceability of data.
It achieves full-process encryption protection and verifiable traceability of video conferencing data, protects user privacy, prevents failure of responsibility tracing, and provides a dynamic balance between security and compliance.
Smart Images

Figure CN120768546A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security, and in particular to a dynamic key threshold sharding privacy tracing method based on blockchain collaborative verification. Background Art
[0002] As video conferencing becomes a core use case for digital collaboration, the conflict between data privacy and trusted evidence storage is becoming increasingly prominent. Traditional centralized identity management systems rely on a single trusted entity to centrally control user identity information. This model not only presents a single point of failure risk but also struggles to support cross-domain interoperability. While the decentralized identity (DID) system, enabled by blockchain technology, empowers users with identity autonomy through public-private key pairs, existing solutions still face a dilemma between privacy protection and compliance auditing. Completely anonymous DID identification struggles to meet regulatory traceability requirements, while directly uploading identity mappings to the blockchain in plain text exposes sensitive information. This conflict is particularly acute in video conferencing scenarios: traditional solutions rely on centralized servers to encrypt audio and video streams and audit logs, but service providers can tamper with meeting records, and password-based authentication mechanisms are susceptible to man-in-the-middle attacks, rendering accountability ineffective in the event of content leaks.
[0003] Existing blockchain and decentralized identity solutions face a profound technical conflict between privacy protection and regulatory traceability. Current mainstream implementations face a common dilemma: Ensuring traceability by storing all identity-related information on-chain exposes public key-identity mappings to the public network, severely violating the principles of data minimization and privacy protection. While fully anonymized DID systems can protect user identity privacy, they completely eliminate accountability in the event of leaks, such as unauthorized screen capture and dissemination of video conference content. Further complicating matters, the end-to-end encryption requirements unique to video conferencing scenarios create a dilemma for traditional audit mechanisms: Without access to session keys, the service provider struggles to track the path of a leak, while centralized key escrow introduces single-point trust risks. These profound technical contradictions make it difficult for existing solutions to simultaneously meet the basic requirements of forensic evidence collection and the compliance standards of data protection regulations. A new technical architecture is urgently needed that can achieve effective traceability while preserving privacy.
[0004] Liu et al. (Liu Z, Yu X, Liu N, et al. Integrating AI with detection methods, IoT, and blockchain to achieve food authenticity and traceability from farm to table [J]. Trends in Food Science & Technology, 2025: 104925.) proposed an innovative approach combining artificial intelligence (AI), the Internet of Things (IoT), and blockchain technology to optimize the entire data collection and management process. In this approach, AI is used for intelligent analysis and decision support, IoT enables widespread physical device connectivity and data collection, and blockchain provides tamper-proof and traceable data storage and transmission. This integrated architecture not only improves the efficiency and accuracy of data collection but also significantly enhances the security and credibility of traceability information.
[0005] Brandín et al. (Brandín R, Abrishami S. IoT-BIM and blockchain integration for enhanced data traceability in offsite manufacturing[J].Automation in Construction, 2024, 159: 105266.) proposed a traceability management model based on information modeling (Supply Chain Management Model - Product Data Object (SCMM-PDO), establishing a highly secure and transparent traceability management framework. This model uses information modeling technology to standardize and centralize data management across different supply chain nodes. Leveraging the immutability and transparency of blockchain, it enables trusted data sharing and traceability across multiple parties. Furthermore, SCMM-PDO incorporates comprehensive data access and authorization mechanisms to ensure data transparency and public access, protecting the privacy and commercial confidentiality of all parties.
[0006] While the aforementioned research has made significant progress in improving data transparency and traceability, most solutions focus primarily on the authenticity and integrity of on-chain data, with insufficient attention paid to protecting data privacy. Due to the public nature of blockchain, the public storage and transmission of sensitive data on-chain can lead to privacy risks. Therefore, how to ensure traceability while protecting user privacy has become a pressing issue in current blockchain traceability and forensics technology. Summary of the Invention
[0007] Purpose of the invention: In response to the above problems, the purpose of the present invention is to provide a dynamic key threshold sharding privacy tracing method based on blockchain collaborative verification.
[0008] Technical solution: The dynamic key threshold sharding privacy tracing method based on blockchain collaborative verification of the present invention includes the following steps: Participating users register their identities and generate master key pairs and DID identifiers; The trusted unit issues verifiable credentials to participating users based on the DID identifier; When attending a meeting, the user generates zero-knowledge proof verification information, and the system authenticates the user based on the generated zero-knowledge proof verification information; The conferencing system uses Unet for encoding and a symmetric decoder that shares the encoder downsampling parameters for decoding. Storing key information on the blockchain; When information leakage occurs, the traceability and identity tracking mechanism is triggered, and retrieval and comparison are performed on the blockchain to decrypt and track the identity.
[0009] Furthermore, the steps for the participating users to register their identities and generate a master key pair and DID identifier include: Before joining the conference for the first time, the participating user generates a master key pair locally ( ),in is the master private key, is the master public key; Generate master virtual identity information based on master public key = ,in, represents a hash function, Indicates the timestamp, represents a random number, Indicates a link operation; Generate keys through threshold distributed key generation , and adopt Threshold encryption algorithm uses the key disassembled shards , requires at least The key can be recovered by the collaboration of shards, Indicates the shards; Constructing encrypted tuples for secure storage and stored on the authentication chain, where the encrypted tuple is represented as , is the AES threshold encryption function, Indicates the real identity of the participating user; When a non-first-time user joins a meeting, based on the current meeting information or time, a sub-public key pair is generated in a secure environment or offline environment using the master key pair. ,in is the child private key, are the sub-public keys, respectively expressed as: , , where represents the time parameter, Represents the modulo operation, n represents the order of the elliptic curve, represents the sub-public key generation function, Represents an elliptic curve generator; Participants randomly generate salt values through the conference system , encrypt the salt value, and the encrypted salt value is ; Calculating intermediate binding parameters , the formula is: ; Combine the child public key, session context, and intermediate hash value to generate the virtual identity information of this meeting ,in Represents the context.
[0010] Furthermore, the expression for verifiable credentials is: , Where, Is the attribute strategy, input context environment , using the function Determine whether dynamic generation is allowed , Represents a binary value domain; Indicates the start time and end time; is the BLS signature generated by the trusted unit, is the private key of the trusted unit, is a multiplicative cyclic group.
[0011] Furthermore, when participating in a meeting, the participating user generates zero-knowledge proof verification information, and the system authenticates the participating user based on the generated zero-knowledge proof verification information. The steps include: Build a zero-knowledge proof circuit locally on the user The inputs, including public inputs and private inputs, are expressed as: , in, express The hash value of Design constraints include: , , , in, represents the public key of the trusted unit, express The generator of Represents a bilinear map , is a multiplicative cyclic group, is the target multiplicative group; Finally, the zero-knowledge proof verification information is constructed, which is expressed as: , Where, represents a function that generates a cryptographic proof π; The system verifies the triple legitimacy of the participant's identity, including: Identity ownership: users actually own the generated dynamic Master private key ; dynamic Legitimacy: Dynamic identity is based on 、 、 、 Correctly generated; Identity authentication validity: The authentication signature held by the user is legal; the verification equation is ,in Represents a validation function.
[0012] Furthermore, the steps of encoding using Unet on the conference system and decoding using a symmetric decoder that shares encoder downsampling parameters include: Step 41: In the message processor, enter the secret message , the secret message Transformed into a three-dimensional tensor , expressed as: ,in, represents a dimension reshaping operation, Indicates that the tensor elements are in the real number field, Indicates the length of the secret message, Indicates the number of message channels, feature map height and width; Reuse The convolution kernel improves the feature expression ability and obtains the feature F1, which is expressed as: ,in, Represents atomic operations of convolution, batch normalization, and activation functions; Then, a deconvolution layer with a stride of 2 is used to gradually expand the resolution to the target size. and through SE modules Optimize features and get features , the formula is: , Where, Respectively represent the number of channels, height and width of the carrier image; Finally, the convolutional layer is used to align the number of channels with the carrier image to obtain the processed secret message. , expressed as: ,in, represents the convolutional layer; Step 42, in the improved encoder operation, input carrier image ,Will and the secret message after message processing Perform channel splicing to obtain the fused information, which is expressed as: ,in, represents the channel dimension; The integrated information Input into the Unet architecture, and then gradually downsample to obtain information , expressed as: , in, Indicates the Convolutional downsampling module with a layer stride of 2, Indicates that the encoder ends at layer; Then, the image size is gradually restored through the upsampling module, and the encoded features are incorporated into the current feature map using the jump connection to obtain the feature map , the formula is: , in, represents a deconvolution layer with a stride of 2, Indicates the strided convolution function; The final output is the image with embedded watermark for: ; Step 43, noise layer: adopt the mini-batch training strategy Mini-Batch, and randomly select from the real non-differentiable noise attack layer, the noiseless attack layer, and the non-differentiable simulated noise layer during each training, expressed as: , in, represents the noise floor; Step 44, decoder: adopt symmetric coding structure, use symmetric decoder with shared encoder downsampling parameters, extract watermark information, shared parameter layer, where represents the first The input feature map of the layer is expressed as: , in, Indicates the The input feature map of the layer; Spatial aggregation and output: , , in, represents a 1×1 convolutional layer, Represents a single-channel feature map after convolution, represents the extracted secret message, Represents the Sigmoid function.
[0013] Furthermore, when information leakage occurs, the traceability and identity tracking mechanism is triggered, and a search and comparison is performed on the blockchain. The steps for decrypting and tracking the identity include: Step 61: Extract the watermark information from the leaked content and compare it with the watermark information stored on the chain to lock the specific meeting and the virtual identity information generated by the participants in this meeting. ; Step 62, through the preset zero-knowledge verification and Merkle tree verification, prove the locked is effective and participates in current meetings; Step 63: Aggregate decryption keys through multi-party collaboration , decrypted 、 get After searching and comparing the value on the chain, Decrypted tracking ID: ,in Indicates the decryption salt value operation, Indicates decryption intermediate binding parameters.
[0014] Furthermore, key information includes meeting ID, screenshot watermark hash value, encrypted salt value, intermediate binding parameters, hash value of verifiable credentials, zero-knowledge proof, participant temporary virtual identity information and constructed Merkle tree root value, off-chain information storage address and timestamp information.
[0015] Beneficial effects: Compared with the prior art, the present invention has the following significant advantages: 1. This invention uses a collaborative architecture of blockchain evidence storage and dynamic key threshold sharding to achieve end-to-end encryption protection and verifiable traceability for the entire video conferencing process, thus safeguarding user privacy sovereignty. 2. To prevent the problem of being unable to track the responsible party after the conference content is leaked, the present invention innovatively designs a dynamic identity binding strategy, a verifiable credential system based on zero-knowledge proof, and a codec fusion watermark based on the Unet architecture: Participants use dynamically generated anonymous identities to To access a meeting, the user's true identity is encrypted and anchored off-chain by a verifiable credential (VC) issued by a trusted entity. Only the hash fingerprint of the session key shard and zero-knowledge proof evidence remain on-chain, ensuring that attackers cannot infer sensitive information from on-chain data. 3. When a data leak occurs, the tracing unit determines the identity information of the participants through a preset zero-knowledge verification circuit, and triggers multi-party collaborative threshold decryption to recover the key by comparing on-chain and off-chain information, and accurately locates the responsible person based on the encrypted identity mapping table; 4. Through deep coupling of cryptographic primitives, the present invention achieves multiple protections in anonymous access, data minimization on the chain, key sharding and disaster recovery, etc., which not only eliminates the risks of single-point tampering and single-key leakage in centralized systems, but also avoids the traceability failure caused by complete anonymity. Ultimately, it constructs a governance paradigm in which privacy is available but invisible, and traceability is controllable and not beyond one's authority, providing a dynamic balance foundation of security and compliance for highly sensitive digital collaboration scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 Flowchart for user registration on-chain; Figure 2 Generate schematics for temporary identities; Figure 3 It is a codec fusion watermark based on Unet architecture; Figure 4 A time consumption graph for each step is provided for tracing back the source. DETAILED DESCRIPTION
[0017] In order to make the purpose, technical solutions and advantages of this application more clear, this application is further described in detail below with reference to the accompanying drawings and embodiments.
[0018] The present invention aims to build a video conferencing security architecture that balances privacy protection and compliance traceability, and realizes a "data available but invisible" trust mechanism through cryptographic technology. Its core innovation lies in the deep coupling of decentralized identity, zero-knowledge verification, deep watermarking and threshold collaborative decryption with dynamic keys as the hub: the temporary key generated for each meeting is split into multiple shards, which are distributed and kept by blockchain nodes and traceability units. Only the hash fingerprint of the shard combination is stored on the chain, forming a lightweight evidence chain that cannot be tampered with but has no privacy exposure. Participants access anonymously through verifiable credentials, for example, proving themselves as "legal meeting members" without disclosing specific information, and the trusted unit signature ensures the authenticity of the anonymous identity. When a data leak occurs, the traceability unit extracts the watermark, compares the zero-knowledge proof, verifies the correlation between the leaked ciphertext and the fingerprint on the chain, triggers multi-party threshold decryption to recover the key, and finally combines the encrypted and stored DID mapping table to accurately locate the person responsible, without exposing irrelevant information throughout the process. This architecture ensures that the audio and video streams and metadata in daily meetings are always end-to-end encrypted, and the traceability process replaces traditional manual audits with mathematical verifiability. This not only meets the "right to be forgotten" requirements of the GDPR (General Data Protection Regulation), but also enables rapid extraction of evidence when disputes occur, providing a dynamic balance between privacy and compliance for multi-party collaboration.
[0019] Through the aforementioned technological innovations, this invention creatively integrates decentralized identity, zero-knowledge proofs, deep watermarking, and threshold cryptography to construct a privacy-first, exception-controlled, three-tier governance architecture (identity management layer, data storage layer, and security traceability layer). This resolves the inherent contradiction between privacy protection and regulatory traceability in traditional solutions. It reconstructs the trust paradigm for digital collaboration, transforming the fragile trust chain of the centralized era, which relied on institutional endorsements, into a decentralized, verifiable trust network secured by mathematical algorithms. All data exchanged during daily meetings is encrypted, preventing service providers and even internal personnel from breaching the cryptographic barrier to access sensitive information. However, in the event of a security incident, pre-set cryptographic rules automatically activate the traceability process, enabling targeted extraction of legal evidence while protecting the privacy of unrelated parties. This "privacy-first, exception-controlled" governance model not only resolves the long-standing security-efficiency paradox in video conferencing but also provides a reusable privacy and security framework for emerging scenarios such as the Industrial Internet of Things, driving the evolution of digital collaboration towards a higher level of trust.
[0020] The dynamic key threshold sharding privacy tracing method based on blockchain collaborative verification described in this embodiment includes the following steps: Step 1: Participating users register their identities and generate a master key pair and DID identifier.
[0021] Combine Figure 1Initially, meeting creation and identity registration are required. Furthermore, the steps for participants to register their identities and generate a master key pair and DID identifier include: Before joining the meeting for the first time, the participant generates a master key pair locally using the Trusted Execution Environment (TEE). ),in is the master private key, is the master public key; Generate master virtual identity information based on master public key = ,in, represents a hash function, Indicates the timestamp, represents a random number, Indicates a link operation; Generate keys through threshold distributed key generation , and adopt Threshold encryption algorithm uses the key disassembled shards , requires at least The key can be recovered by the collaboration of shards, Indicates the The number of shards m depends on the number of traceability units and related personnel; Constructing encrypted tuples for secure storage and stored on the authentication chain, where the encrypted tuple is represented as , It is the AES (Advanced Encryption Standard) threshold encryption function, Indicates the real identity of the participating user and will use the encryption key Distribute the fragments to each traceability unit and relevant persons in charge; When a non-first-time user joins a meeting, based on the current meeting information or time, the user can use the master key pair to generate a sub-public key pair in a secure environment or an offline environment. ,in is the child private key, are the sub-public keys, respectively expressed as: , , represents the time parameter, Represents the modulo operation, n represents the order of the elliptic curve, represents the sub-public key generation function, Represents an elliptic curve generator; Participants randomly generate salt values through the conference system , encrypt the salt value, and the encrypted salt value is ; In order to bind and salt value to calculate the intermediate binding parameters To prevent malicious linking behavior, the formula is: ; Combine the child public key, session context, and intermediate hash value to generate the virtual identity information of this meeting ,in Represents the context.
[0022] Step 2: The trusted unit issues a verifiable credential to the participating user based on the DID identifier.
[0023] The above-mentioned trusted units refer to trusted entities, such as systems used to provide verification and authentication services.
[0024] During the credential distribution phase, the trusted unit will issue verifiable credentials to participating users. .
[0025] Furthermore, the expression for verifiable credentials is: , Where, Is the attribute strategy, input context environment , using the strategy definition function Determine whether dynamic generation is allowed ,in , P, S, and T represent user identity authority, target scenario, and time window respectively. Represents a binary value domain; Indicates the start time and end time; is the BLS signature generated by the trusted unit, is the private key of the trusted unit, is a multiplicative cyclic group.
[0026] like Figure 2 As shown, during the conference participation key sharding phase, the system will generate a key for this conference through threshold distributed key generation. , and adopt The threshold encryption algorithm splits it into n fragments , requires at least The key can be recovered by the collaboration of shards, Indicates the nth shard, where n depends on the number of traceability units and related personnel. The user will create a random salt value , and use threshold encryption: In order to bind And salt value, you need to calculate the intermediate binding parameters: . Finally, the meeting .
[0027] Step 3: When attending a meeting, the user generates zero-knowledge proof verification information, and the system authenticates the user based on the generated zero-knowledge proof verification information.
[0028] Furthermore, when participating in a meeting, the participating user generates zero-knowledge proof verification information, and the system authenticates the participating user based on the generated zero-knowledge proof verification information. The steps include: Build a zero-knowledge proof circuit locally on the user The inputs, including public inputs and private inputs, are expressed as: , in, express The hash value of The design constraints are: , , , in, represents the public key of the trusted unit, express The generator of Represents a bilinear map , is a multiplicative cyclic group, is the target multiplicative group; Finally, the zero-knowledge proof verification information is constructed, which is expressed as: , Where, represents a function that generates a cryptographic proof π; The system verifies the triple legitimacy of the participant's identity, including: Identity ownership: users actually own the generated dynamic Master private key ; dynamic Legitimacy: Dynamic identity is based on 、 、 、 Correctly generated; Identity authentication validity: The authentication signature held by the user is legal; the verification equation is ,in Represents a validation function.
[0029] This method can verify that the DID dynamically generated by the user is legitimate without exposing specific information, and that the identity attributes behind it are authenticated by a trusted unit.
[0030] Step 4: Use Unet for encoding on the conference system and use a symmetric decoder that shares the encoder downsampling parameters for decoding.
[0031] In the Unet-based codec fusion watermarking stage, the existing watermarking architecture mainly includes an encoder, information processor, noise layer, decoder, and discriminator. To make the screen watermark more robust and invisible, enable more efficient and stable information extraction, and enhance the stability of subsequent tracking, this example redesigns the original codec separation architecture, using Unet for encoding and then decoding using a symmetric decoder that shares the encoder downsampling parameters. Sharing parameters enhances the coupling capability of the codec.
[0032] like Figure 3 As shown, further, the steps of encoding using Unet on the conference system and decoding using a symmetric decoder with shared encoder downsampling parameters include: Step 41: In the message processor, enter the secret message The secret message includes the meeting information and the user's virtual identity information for this meeting. Transformed into a three-dimensional tensor , expressed as: ,in, represents a dimension reshaping operation, Indicates that the tensor elements are in the real number field, Indicates the length of the secret message, Indicates the number of message channels, feature map height and width; Reuse The convolution kernel improves the feature expression ability and obtains the feature F1, which is expressed as: ,in, Represents atomic operations of convolution, batch normalization, and activation functions; Then, a deconvolution layer with a stride of 2 is used to gradually expand the resolution to the target size. ,like and through SE modules Optimize features and get features , the formula is: , Where, Respectively represent the number of channels, height and width of the carrier image; Finally, the convolutional layer is used to align the number of channels with the carrier image to obtain the processed secret message. , expressed as: ,in, Represents a convolutional layer.
[0033] Step 42, in the improved encoder operation, input carrier image ,Will and the secret message after message processing Perform channel splicing to obtain the fused information, which is expressed as: ,in, represents the channel dimension; The integrated information Input into the Unet architecture, and then gradually downsample to obtain information , expressed as: , in, Indicates the Convolutional downsampling module with a layer stride of 2, Indicates that the encoder ends at layer; Then, the image size is gradually restored through the upsampling module, and the encoded features are incorporated into the current feature map using the jump connection to obtain the feature map , the formula is: , in, represents a deconvolution layer with a stride of 2, Indicates the strided convolution function; The final output is the image embedded with the watermark for: .
[0034] Step 43: The noise layer solves the training-testing inconsistency problem in the deep watermark model and improves robustness to JPEG compression. Traditional methods use a fixed noise layer, which causes the model to overfit to specific attack patterns. By dynamically mixing noise sources, the model is forced to learn generalized anti-attack capabilities. This example uses the mini-batch training strategy. During each training, a random selection is made between the real non-differentiable noise attack layer, the noiseless attack layer, and the non-differentiable simulated noise layer, expressed as: , in, represents the noise floor.
[0035] Step 44, decoder: responsible for converting the noisy image Reconstruct the secret message, adopt a symmetric coding structure, use the downsampling process in the encoder, extract the watermark information, reuse the downsampling part of the encoder, and share the parameter layer, where represents the first The input feature map of the layer is expressed as: , in, Indicates the The input feature map of the layer; Spatial aggregation and output: , , in, Represents a single-channel feature map after convolution, represents the extracted secret message, Represents the Sigmoid function.
[0036] Step 5: Store key information in the blockchain.
[0037] Finally, the key information is stored on the chain, including the meeting ID, screen capture watermark hash value, and encrypted salt value. , intermediate binding parameters , VC hash value, zero-knowledge proof, participant temporary And the constructed Merkle tree root value, off-chain information storage address and timestamp information.
[0038] Off-chain, IPFS (InterPlanetary File System) will be used to store detailed information.
[0039] During the conference data encryption and evidence storage stage, the relevant information of the conference, such as video, audio, text and embedded watermark information, will be encrypted by the threshold encryption algorithm to generate ciphertext ,in The dynamic key for this meeting, message represents the relevant meeting information. Finally, the content stored on the chain adopts a lightweight structure: , in, The unique identifier of the conference. Indicates the hash value of the screen capture watermark. Indicates all participating users The root node of the generated Merkle tree, Represents the IPFS address stored off-chain, and T represents the timestamp.
[0040] Step 6: When information leakage occurs, the traceability and identity tracking mechanism is triggered, and a search and comparison is performed on the authentication chain to decrypt and track the identity.
[0041] Furthermore, when information leakage occurs, the traceability and identity tracking mechanism is triggered, and a search and comparison is performed on the authentication chain. The steps of decrypting and tracking the identity include: Step 61: First, extract the watermark information from the leaked content and compare it with the watermark information stored in the authentication chain to lock the specific meeting and the virtual identity information generated by the participants in this meeting. ; Step 62, through the preset zero-knowledge verification and Merkle tree verification, prove the locked is available and participating in current meetings; Step 63: Aggregate decryption keys through multi-party collaboration , decrypted 、 get After searching and comparing the value on the chain, Decrypted tracking ID: ,in Indicates the decryption salt value operation, Represents the decryption of an intermediate bound value operation.
[0042] In one example, during the leakage time tracing phase, when a meeting content leak is detected, the tracing unit will perform the following process to trace the identity: (a) Extracting the screenshot watermark hash from the leaked data , and on-chain Perform matching to determine the associated meeting records and corresponding suspicious users; (b) Call the prefabricated zero-knowledge verification circuit to verify the leaked ciphertext watermark extracted and the Merkle tree on the chain The spatiotemporal consistency of The user actually exists and complies with regulations, and the user actually participates in the meeting; (c) Aggregate at least The key shards perform threshold decryption by decrypting the intermediate binding value , trace back to the real identity mapping table on the user chain, and thus track the specific person.
[0043] To further illustrate the effectiveness and superiority of the dynamic key threshold sharding privacy tracing method based on blockchain collaborative verification described in the present invention, an experiment was conducted on the time consumption of each of the above steps. The experimental environment uses the hardware configuration of i5-13490F processor and NVIDIA GeForce RTX 4060ti GPU, runs the Ethereum blockchain network under Ubuntu 20.04 LTS system, and completes the cryptographic operation verification based on the ZKP circuit of OpenSSL 3.0.8 and Groth16 protocol. All experiments were carried out under the conditions of controlling network delay (0.1-0.5ms) and enabling GPU acceleration. The experimental results are shown in the figure below. Figure 4 As shown, in the screen capture watermark hash matching, image watermark extraction and on-chain hash matching consume 57ms and 15ms respectively; in the threshold decryption identity tracing, shard aggregation request, threshold decryption calculation and on-chain identity mapping consume 73ms, 102ms and 17ms respectively; in the spatiotemporal consistency zero-knowledge verification, virtual identity retrieval and ZK circuit verification consume 52ms and 154ms respectively.
[0044] In this example, the gas consumption of a smart contract for traceability and forensics was calculated, as shown in Table 1. This demonstrates the low on-chain consumption of the present invention. Furthermore, a security comparison with existing blockchain traceability methods, as shown in Table 2, demonstrates that the present invention has significant security advantages over existing solutions.
[0045] Table 1
[0046] Table 2
[0047] In the present invention, the codec fusion watermarking method based on the Unet architecture demonstrates significant advantages in both robustness and concealment. To simulate the partial loss of watermark information due to changes in shooting angle or framing in screen capture (i.e., cropping attack), the performance at three cropping ratios of 30%, 50%, and 70% was experimentally tested. The test results are shown in Table 3. Although cropping severely damages the integrity of the image, the present invention maintains a low bit error rate (BER) at all ratios and maintains high levels of peak signal-to-noise ratio (PSNR) and structural similarity (SSIM), proving that the watermark content can be effectively restored even when partial information is missing, demonstrating excellent screen capture resistance. In comparison with methods such as HiDDeN, MBRS, and Adaptor, the present invention demonstrated significant superiority in this test.
[0048] Table 3 .
Claims
1. A dynamic key threshold sharding privacy tracing method based on blockchain collaborative verification, characterized by: The following steps are involved: Participating users register their identities and generate master key pairs and DID identifiers; The trusted unit issues verifiable credentials to participating users based on the DID identifier; When attending a meeting, the user generates zero-knowledge proof verification information, and the system authenticates the user based on the generated zero-knowledge proof verification information; The conferencing system uses Unet for encoding and a symmetric decoder that shares the encoder downsampling parameters for decoding. Storing key information on the blockchain; When information leakage occurs, the traceability and identity tracking mechanism is triggered, and retrieval and comparison are performed on the blockchain to decrypt and track the identity.
2. The dynamic key threshold sharding privacy tracing method based on blockchain collaborative verification according to claim 1 is characterized in that: The steps for participants to register their identities and generate a master key pair and DID identifier include: Before joining the conference for the first time, the participating user generates a master key pair locally ( ),in is the master private key, is the master public key; Generate master virtual identity information based on master public key = ,in, represents a hash function, Indicates the timestamp, represents a random number, Indicates a link operation; Generate keys through threshold distributed key generation , and adopt Threshold encryption algorithm uses the key disassembled shards , requires at least The key can be recovered by the collaboration of shards, Indicates the shards; Constructing encrypted tuples for secure storage and stored on the authentication chain, where the encrypted tuple is represented as , is the AES threshold encryption function, Indicates the real identity of the participating user; When a non-first-time user joins a meeting, based on the current meeting information or time, a sub-public key pair is generated in a secure environment or offline environment using the master key pair. ,in is the child private key, are the sub-public keys, respectively expressed as: , , where represents the time parameter, Represents the modulo operation, n represents the order of the elliptic curve, represents the sub-public key generation function, Represents an elliptic curve generator; Participants randomly generate salt values through the conference system , encrypt the salt value, and the encrypted salt value is ; Calculating intermediate binding parameters , the formula is: ; Combine the child public key, session context, and intermediate hash value to generate the virtual identity information of this meeting ,in Represents the context.
3. The dynamic key threshold sharding privacy tracing method based on blockchain collaborative verification according to claim 2 is characterized in that: The expression for verifiable credentials is: , Where, Is the attribute strategy, input context environment , using the function Determine whether dynamic generation is allowed , Represents a binary value domain; Indicates the start time and end time; is the BLS signature generated by the trusted unit, is the private key of the trusted unit, is a multiplicative cyclic group.
4. The dynamic key threshold sharding privacy tracing method based on blockchain collaborative verification according to claim 3 is characterized in that: When joining a meeting, the user generates zero-knowledge proof verification information. The system authenticates the user based on the generated zero-knowledge proof verification information in the following steps: Build a zero-knowledge proof circuit locally on the user The input, including public input and private input, are expressed as: , in, express The hash value of Design constraints include: , , , in, represents the public key of the trusted unit, express The generator of Represents a bilinear map , is a multiplicative cyclic group, is the target multiplicative group; Finally, the zero-knowledge proof verification information is constructed, which is expressed as: , Where, represents a function that generates a cryptographic proof π; The system verifies the triple legitimacy of the participant's identity, including: Identity ownership: users actually own the generated dynamic Master private key ; dynamic Legitimacy: Dynamic identity is based on 、 、 、 Correctly generated; Identity authentication validity: The authentication signature held by the user is legal; the verification equation is ,in Represents a validation function.
5. The dynamic key threshold sharding privacy tracing method based on blockchain collaborative verification according to claim 4 is characterized in that: The steps for encoding using Unet on the conference system and decoding using a symmetric decoder that shares the encoder downsampling parameters include: Step 41: In the message processor, enter the secret message , the secret message Transformed into a three-dimensional tensor , expressed as: ,in, Represents a dimension reshaping operation, Indicates that the tensor elements are in the real number field, Indicates the length of the secret message, Indicates the number of message channels, feature map height and width; Reuse The convolution kernel improves the feature expression ability and obtains the feature F1, which is expressed as: ,in, Represents atomic operations of convolution, batch normalization, and activation functions; Then, a deconvolution layer with a stride of 2 is used to gradually expand the resolution to the target size. and through SE modules Optimize features and get features , the formula is: , Where, Respectively represent the number of channels, height and width of the carrier image; Finally, the convolutional layer is used to align the number of channels with the carrier image to obtain the processed secret message. , expressed as: ,in, represents the convolutional layer; Step 42, in the improved encoder operation, input carrier image ,Will and the secret message after message processing Perform channel splicing to obtain the fused information, which is expressed as: ,in, represents the channel dimension; The integrated information Input into the Unet architecture, and then gradually downsample to obtain information , expressed as: , in, Indicates the Convolutional downsampling module with a layer stride of 2, Indicates that the encoder ends at layer; Then, the image size is gradually restored through the upsampling module, and the encoded features are incorporated into the current feature map using the jump connection to obtain the feature map , the formula is: , in, represents a deconvolution layer with a stride of 2, Indicates the strided convolution function; The final output is the image with embedded watermark for: ; Step 43, noise layer: adopt the mini-batch training strategy Mini-Batch, and randomly select from the real non-differentiable noise attack layer, the noiseless attack layer, and the non-differentiable simulated noise layer during each training, expressed as: , in, represents the noise floor; Step 44, decoder: adopt symmetric coding structure, use symmetric decoder with shared encoder downsampling parameters, extract watermark information, shared parameter layer, where represents the first The input feature map of the layer is expressed as: , in, Indicates the The input feature map of the layer; Spatial aggregation and output: , , in, represents a 1×1 convolutional layer, Represents a single-channel feature map after convolution, represents the extracted secret message, Represents the Sigmoid function.
6. The dynamic key threshold sharding privacy tracing method based on blockchain collaborative verification according to claim 5 is characterized in that: When information leakage occurs, the traceability and identity tracking mechanism is triggered, and a search and comparison is performed on the blockchain. The steps for decrypting and tracking the identity include: Step 61: Extract the watermark information from the leaked content and compare it with the watermark information stored on the chain to lock the specific meeting and the virtual identity information generated by the participants in this meeting. ; Step 62, through the preset zero-knowledge verification and Merkle tree verification, prove the locked is effective and participates in current meetings; Step 63: Aggregate decryption keys through multi-party collaboration , decrypted 、 get After searching and comparing the value on the chain, Decrypted tracking ID: ,in Indicates the decryption salt value operation, Indicates decryption intermediate binding parameters.
7. The dynamic key threshold sharding privacy tracing method based on blockchain collaborative verification according to any one of claims 1 to 6 is characterized in that: Key information includes meeting ID, screenshot watermark hash value, encrypted salt value, intermediate binding parameters, hash value of verifiable credentials, zero-knowledge proof, participant temporary virtual identity information and constructed Merkle tree root value, off-chain information storage address and timestamp information.
Citation Information
Patent Citations
Management system and method based on block chain
CN113822778A
Urban rail vehicle electronic resume data-oriented block chain management and storage method
CN116402491A
Tracing ring signature data sharing method based on block chain hierarchical nodes
CN116488804A
Identity privacy protection and traceable distributed supervision method and system on block chain and readable storage medium
CN117792607A
Block chain-based double-stream video conference privacy tracing method
CN120378119A
Cited By
Watermark-based universal multimedia interface protocol ownership detection method and device
CN120930114A
A watermark-based universal multimedia interface protocol ownership detection method and device
CN120930114B
Weighted threshold signature method and apparatus supporting silence settings and conditional privacy
CN122496184A
Weighted threshold signature method and apparatus supporting silence settings and conditional privacy
CN122496184B