Data sharing method, data display method and device, and data sharing system
By embedding digital watermarks containing security identifiers and group keys into video conferencing data, and combining this with digital fingerprint technology for verification, the problem of information leakage when data flows to low-security meetings in video conferencing systems is solved, thus improving the security of video conferencing.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2024-12-30
- Publication Date
- 2026-06-30
AI Technical Summary
In existing video conferencing systems, information from high-security meetings can easily be leaked by malicious insiders to low-security meetings, leading to information leakage. Existing access control technologies cannot effectively prevent high-security data from flowing to low-security meetings.
By embedding digital watermarks into the data, which contain security level identifiers and group keys, the data is only allowed to be displayed by devices with matching security levels, and the authenticity and integrity of the data are verified by digital fingerprints, ensuring the secure sharing of data within the group.
This effectively prevents data from high-security meetings from flowing to low-security meetings, enhances the security of video conferencing, ensures the authenticity and integrity of data sources, and prevents information leakage.
Smart Images

Figure CN122317360A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security, and in particular to a data sharing method, a data display method and apparatus, and a data sharing system. Background Technology
[0002] Currently, video conferencing is categorized into different security levels. The higher the security level, the more confidential the content of the meeting. Typically, the content of high-security meetings is prohibited from being shared with low-security meetings. However, in reality, many information leaks occur, leading to the leakage of information from high-security meetings. For example, malicious participants in a high-security meeting might forward the meeting content to others without authorization, causing a leak of the high-security meeting's information. Preventing information leaks from video conferencing is crucial to improving video conferencing security. Summary of the Invention
[0003] This application provides a data sharing method, a data display method and apparatus, and a data sharing system.
[0004] Firstly, a data sharing method is provided. This method includes: a data provider acquiring target data. The target data is obtained by embedding a digital watermark into the original data held by the data provider. The target data is used for sharing within a target group. The digital watermark is generated based on the security level identifier corresponding to the target group, the group key of the target group, and the fingerprint information of the original data. The data provider sends the target data to group devices within the target group.
[0005] In this application, by binding a security classification identifier to a digital watermark, it is possible to restrict the display of target data to only devices whose security classification matches the group security classification indicated by the identifier. By binding data fingerprint information to the digital watermark, the authenticity and integrity of the data source can be guaranteed, ensuring that the data has not been tampered with during transit, thereby enhancing the security of group data sharing. By binding a group key to the digital watermark, since the group key is used internally within the group, external adversaries typically cannot obtain it, thus preventing the forgery of the digital watermark to embed in false data for device display, further ensuring the authenticity and security of the data source. The device matching the group security classification indicated by the security classification identifier includes: the group security classification of the device's group being the same as the group security classification indicated by the security classification identifier. In this case, the device can only display data from groups whose group security classification is the same as the group security classification of the device's group, thus preventing data sharing between groups with different security classifications. Alternatively, the device matches the group security level indicated by the security level identifier, including cases where the group security level of the device's group is higher than or equal to the group security level indicated by the security level identifier. In this case, the device can display data from groups with a security level no higher than the group security level corresponding to the device's group. This prevents data from high-security groups from flowing to low-security groups, thereby achieving data security protection for high-security groups. By applying this solution to video conferencing scenarios, where the target group is a conference group, the problem of data flowing from high-security conferences to low-security conferences, leading to the illegal leakage of information from high-security conferences, can be solved, thereby improving the security of video conferencing.
[0006] One implementation method is that the digital watermark includes a security level identifier and a first signature value, the first signature value is obtained by signing the first authentication information with a group key, and the first authentication information includes fingerprint information.
[0007] Optionally, the first authentication information may also include one or more of the following: a security classification identifier, group information of the target group, user identifiers of group users accessing the target group through group devices, or user identifiers of data providers.
[0008] This application identifies the data-sharing object as the target group by binding the group information of the target group to the digital watermark. This allows for tracing the source of the leak within the target group after a data breach, thus narrowing the scope of data tracing. By binding the user identifiers of group users accessing the target group through group devices to the digital watermark, different digital watermarks can be generated for different group users within the target group. This enables precise identification of the leak source after a data breach, facilitating leak tracing. Furthermore, binding the user identifier of the data provider to the digital watermark identifies the data source, providing assurance of the data's authenticity and security.
[0009] Another implementation method is that the digital watermark includes a second signature value, which is obtained by signing the second authentication information with a group key. The second authentication information includes a security level identifier and fingerprint information.
[0010] In this implementation, the security classification identifier is used as part of the second authentication information for signature encryption, instead of being carried in plaintext in the digital watermark. This prevents the leakage of security classification identifier information and thus improves information security.
[0011] Optionally, the second authentication information may also include one or more of the following: group information of the target group, user identifiers of group users accessing the target group through group devices, or user identifiers of data providers.
[0012] Optionally, the target group is a conference group, the group device is a conference terminal, and the group information includes the conference identifier corresponding to the conference group and / or the conference timestamp corresponding to the conference group.
[0013] This proposed solution can be applied to video conferencing scenarios, and can solve the problem of data flow from high-security meetings to low-security meetings, leading to the illegal leakage of information from high-security meetings, thereby improving the security of video conferencing.
[0014] Optionally, one implementation method for a data provider to obtain target data includes: the data provider sending raw data to the group administrator of the target group; the group administrator holding a security level identifier and a group key; the group device including a security module; and the security level identifier and group key being determined by end-to-end communication between the group administrator and the security module in the group device. The data provider then receives the target data sent by the group administrator.
[0015] In this application, the group administrator pre-approves and embeds digital watermarks on data that the data provider needs to share in the target group. This ensures that only approved data can be embedded with digital watermarks and displayed in the target group, thus improving the security of group data sharing. Furthermore, the security module in the device communicates end-to-end with the group administrator to obtain the group's security classification identifier and group key, ensuring that these identifiers are not leaked.
[0016] Optionally, the security module includes, but is not limited to, a trusted execution environment (TEE) or a hardware security module (HSM).
[0017] Optionally, the raw data may be audio data, video data, document data, or file data.
[0018] This application's solution can embed digital watermarks into structured or unstructured data, thereby preventing the illegal leakage of various types of data.
[0019] Secondly, a data display method is provided. The method includes: a first device receiving target data, the first device being a group device in a first group, the first device holding a first security level identifier corresponding to the first group and a first group key for the first group; the first device extracting a digital watermark from the target data and obtaining fingerprint information corresponding to the target data; the first device verifying the digital watermark based on the first security level identifier, the first group key, and the fingerprint information; and if the digital watermark verification passes, the first device displaying the target data.
[0020] One implementation method for a digital watermark, comprising a security classification identifier and a first signature value, wherein a first device verifies the digital watermark based on the first security classification identifier, a first group key, and fingerprint information, includes: if the first security classification identifier matches the security classification identifier in the digital watermark, the first device signs first authentication information using the first group key to obtain a second signature value, wherein the first authentication information includes fingerprint information; if the second signature value matches the first signature value, the first device determines that the digital watermark verification is successful.
[0021] In this application, when the digital watermark includes a security classification identifier, the device first determines whether its own security classification identifier matches the security classification identifier in the digital watermark. If the security classification identifier held by the device does not match the security classification identifier in the digital watermark, the device can directly determine that the verification of the digital watermark fails and will not execute subsequent processes. That is, it is not necessary to use the group key held by the device to calculate the signature value of the authentication information, which can improve the verification efficiency of the digital watermark.
[0022] Optionally, the first security classification identifier matches the security classification identifier in the digital watermark, including cases where the group security classification indicated by the first security classification identifier is higher than or equal to the group security classification indicated by the security classification identifier in the digital watermark. In this case, the first device can display data in groups whose group security classification is no higher than the group security classification corresponding to the first group, preventing data from flowing from high-security groups to low-security groups, thereby achieving data security protection for high-security groups. Alternatively, the first security classification identifier matches the security classification identifier in the digital watermark, including cases where the group security classification indicated by the first security classification identifier is equal to the group security classification indicated by the security classification identifier in the digital watermark. In this case, the first device can only display data in groups whose group security classification is the same as the group security classification corresponding to the first group, preventing data sharing between groups with different security classifications.
[0023] Optionally, if the first security classification identifier does not match the security classification identifier in the digital watermark, or if the second signature value does not match the first signature value, the first device determines that the digital watermark verification fails.
[0024] Another implementation method, in which the digital watermark includes a third signature value, involves the first device verifying the digital watermark based on a first security level identifier, a first group key, and fingerprint information. This verification method includes: the first device signing second authentication information using the first group key to obtain a fourth signature value, where the second authentication information includes the first security level identifier and fingerprint information. If the fourth signature value matches the third signature value, the first device determines that the digital watermark verification is successful.
[0025] Optionally, if the digital watermark verification fails, the first device does not display the target data.
[0026] Optionally, the first device includes a security module that stores a first security level identifier and a first group key.
[0027] This application separates users and devices, sets up a security module in the device to store the security level identifier and group key corresponding to the group, and performs digital watermark matching in the security module to ensure that the security level identifier and group key are not leaked, so that users cannot obtain the security level identifier and group key, and cannot maliciously forge digital watermarks to cause data leakage.
[0028] Optionally, the security module in the first device obtains the first security level identifier and the first group key by communicating end-to-end with the group manager of the first group.
[0029] In this application, the security module in the device communicates end-to-end with the group administrator to obtain the security level identifier and group key corresponding to the group, ensuring that the security level identifier and group key are not leaked.
[0030] Optionally, after the first device verifies the digital watermark, it transmits the target data to the projection device.
[0031] Optionally, one implementation of the first device receiving target data includes: the first device receiving target data sent by a second device, where the second device is a group device in a second group; and the digital watermark being generated based on a second security level identifier corresponding to the second group, a second group key of the second group, fingerprint information corresponding to the target data, and a user identifier of a group user accessing the second group through the second device. The user identifier of the group user accessing the second group through the second device, used to generate the digital watermark, is used to determine that the leaker of the target data is a group user accessing the second group through the second device, should the first device fail to verify the digital watermark.
[0032] In this implementation, since the first device is a group device within the first group, it cannot possess the second security level identifier corresponding to the second group and the second group key of the second group. Therefore, it cannot verify the digital watermark in the target data and thus cannot display the target data, thereby preventing data leakage of the second group. Alternatively, it can iterate through the group users in the second group, generating corresponding digital watermarks based on the second security level identifier, the second group key, the fingerprint information corresponding to the target data, and the user identifiers of different group users in the second group. These multiple generated digital watermarks are then matched with the digital watermark in the target data. Finally, the group user corresponding to the digital watermark matching the digital watermark in the target data is identified as the source of the leakage, thus achieving leakage tracing.
[0033] Alternatively, another implementation of the first device receiving target data includes: the first device receiving target data sent by a data provider.
[0034] Thirdly, a data sharing device is provided, comprising multiple functional modules that interact to implement the methods described in the first aspect and its various embodiments. The multiple functional modules can be implemented using software, hardware, or a combination of both, and can be arbitrarily combined or divided based on specific implementations.
[0035] For example, this data sharing device can be applied to data providers. This data sharing device includes, but is not limited to, an acquisition module and a transceiver module.
[0036] The acquisition module is used to acquire target data, which is obtained by embedding a digital watermark into the original data held by the data provider. The target data is used for sharing within a target group, and the digital watermark is generated based on the security level identifier corresponding to the target group, the group key of the target group, and the fingerprint information of the original data. The transceiver module is used to send the target data to group devices within the target group.
[0037] Optionally, the digital watermark includes the security level identifier and a first signature value, wherein the first signature value is obtained by signing the first authentication information using the group key, and the first authentication information includes the fingerprint information.
[0038] Optionally, the first authentication information may further include one or more of the following: the security classification identifier, the group information of the target group, the user identifier of the group user accessing the target group through the group device, or the user identifier of the data provider.
[0039] Optionally, the digital watermark includes a second signature value, which is obtained by signing the second authentication information using the group key. The second authentication information includes the security level identifier and the fingerprint information.
[0040] Optionally, the second authentication information may also include one or more of the following: group information of the target group, user identifiers of group users who access the target group through the group device, or user identifiers of the data provider.
[0041] Optionally, the target group is a conference group, the group device is a conference terminal, and the group information includes the conference identifier corresponding to the conference group and / or the conference timestamp corresponding to the conference group.
[0042] Optionally, the transceiver module is configured to send the original data to the group manager of the target group, the group manager holding the security identifier and the group key, the group device including a security module, and the security identifier and the group key being determined by the group manager through end-to-end communication with the security module in the group device; and to receive the target data sent by the group manager.
[0043] Optionally, the raw data may be audio data, video data, document data, or file data.
[0044] Fourthly, a data display device is provided, the device comprising multiple functional modules that interact to implement the methods described in the second aspect and its various embodiments. The multiple functional modules can be implemented based on software, hardware, or a combination of both, and can be arbitrarily combined or divided based on specific implementations.
[0045] For example, this data display device can be applied to the first device. This data display device includes, but is not limited to, a transceiver module, an information extraction module, a watermark verification module, and a display module.
[0046] The system includes a transceiver module for receiving target data, wherein the first device is a group device within a first group, and the first device holds a first security level identifier and a first group key corresponding to the first group. An information extraction module is used by the first device to extract a digital watermark from the target data and to obtain fingerprint information corresponding to the target data. A watermark verification module is used to verify the digital watermark based on the first security level identifier, the first group key, and the fingerprint information. A display module is used to display the target data if the digital watermark verification is successful.
[0047] Optionally, the digital watermark includes a security classification identifier and a first signature value. The watermark verification module is configured to: if the first security classification identifier matches the security classification identifier in the digital watermark, sign the first authentication information using the first group key to obtain a second signature value, wherein the first authentication information includes the fingerprint information; and if the second signature value matches the first signature value, determine that the digital watermark verification is successful.
[0048] Optionally, matching the first security classification identifier with the security classification identifier in the digital watermark includes: the group security classification indicated by the first security classification identifier is higher than or equal to the group security classification indicated by the security classification identifier in the digital watermark. Alternatively, matching the first security classification identifier with the security classification identifier in the digital watermark includes: the group security classification indicated by the first security classification identifier is equal to the group security classification indicated by the security classification identifier in the digital watermark.
[0049] Optionally, the watermark verification module is further configured to determine that the verification of the digital watermark fails if the first security level identifier does not match the security level identifier in the digital watermark, or if the second signature value does not match the first signature value.
[0050] Optionally, the digital watermark includes a third signature value, and the watermark verification module is configured to: sign the second authentication information using the first group key to obtain a fourth signature value, wherein the second authentication information includes the first security level identifier and the fingerprint information; and if the fourth signature value matches the third signature value, determine that the digital watermark verification is successful.
[0051] Optionally, the display module is further configured to not display the target data if the digital watermark verification fails.
[0052] Optionally, the first device includes a security module that stores the first security level identifier and the first group key.
[0053] Optionally, the security module is used to obtain the first security level identifier and the first group key by communicating end-to-end with the group manager of the first group.
[0054] Optionally, the transceiver module is further configured to transmit the target data to the projection device after the digital watermark has been verified.
[0055] Optionally, the transceiver module is used to receive the target data sent by a second device, where the second device is a group device in a second group. The digital watermark is generated based on a second security level identifier corresponding to the second group, a second group key of the second group, fingerprint information corresponding to the target data, and a user identifier of a group user who accesses the second group through the second device. The user identifier of the group user who accesses the second group through the second device, used to generate the digital watermark, is used to determine that the leaker of the target data is a group user who accesses the second group through the second device, should the digital watermark verification fail on the first device.
[0056] Optionally, the transceiver module is used to receive the target data sent by the data provider.
[0057] Fifthly, a data sharing system is provided, comprising: a data provider, a group manager of a target group, and one or more group devices within the target group. The data provider is used to implement the methods described in the first aspect and its embodiments. The group devices are used to implement the methods described in the second aspect and its embodiments.
[0058] For example, the data provider sends the raw data it holds to the group administrator. The group administrator embeds a digital watermark in the raw data to obtain the target data and sends the target data to the data provider. The digital watermark is generated based on the security level identifier corresponding to the target group, the group key of the target group, and the fingerprint information of the raw data. The data provider then sends the target data to the group device. The group device extracts the digital watermark from the target data and obtains the fingerprint information corresponding to the target data. It then verifies the digital watermark based on the security level identifier corresponding to the target group, the group key of the target group, and the fingerprint information held by the group device. After successful verification of the digital watermark, the target data is displayed.
[0059] In this application, the group administrator pre-approves and embeds a digital watermark on the data that the data provider needs to share in the target group. This ensures that only approved data can be embedded with the digital watermark and displayed in the target group, guaranteeing the authenticity of the data shared and preventing unapproved data from being displayed, thus improving the security of group data sharing. Furthermore, the data provider sends data embedded with the digital watermark to the group devices in the target group. Only devices holding the security identifier and group key corresponding to the target group, and whose fingerprint information has been verified, can match the digital watermark. This restricts access to the data to only devices that can match the digital watermark. Since only the group devices in the target group hold the security identifier and group key, even if the data is leaked—for example, if maliciously forwarded by internal group members to devices in other groups—the devices in other groups cannot match the digital watermark and therefore cannot display the data, thus preventing data leakage. Furthermore, since fingerprint verification of data can only be successful if the data has not been tampered with, once the data is tampered with, the device cannot match the digital watermark in the data and therefore cannot display the data. This ensures the authenticity and integrity of the data source, prevents the data from being illegally leaked and displayed, and improves the security of group data sharing.
[0060] Optionally, the group device includes a security module. The security module in the group device is used to communicate end-to-end with the group administrator to obtain a security level identifier and a group key, and stores the security level identifier and the group key in the security module.
[0061] In this application, the security module in the group device obtains and stores the security level identifier and group key corresponding to the group through end-to-end communication with the group administrator, thereby ensuring that the security level identifier and group key are not leaked.
[0062] Optionally, the target group includes multiple group devices. The data provider sends the target data to each of the multiple group devices. Each of the multiple group devices, after verifying the digital watermark, sends a verification result to the group administrator, indicating whether the digital watermark has been successfully verified. The group administrator is also used to send a prohibition display command to each of the multiple group devices if the verification results from the multiple group devices differ. The prohibition display command instructs the group devices to prohibit the display of the target data.
[0063] If multiple devices in the same group show different verification results for the digital watermark in the same data, it indicates that some of these devices may have been compromised by an adversary. In this case, this application can prevent serious consequences caused by mis-displaying data by prohibiting all devices in the group from displaying the data.
[0064] Optionally, the data sharing system is a conference system, the group manager is the conference administrator, the group devices are conference terminals, and the conference system also includes a conference server, through which the data provider and the group devices communicate.
[0065] Optionally, the conference server stores a security classification identifier and a group key corresponding to the target group. The data provider sends the target data to the conference server. The conference server extracts a digital watermark from the target data and obtains the fingerprint information corresponding to the target data. Based on the security classification identifier, group key, and fingerprint information held by the conference server, the digital watermark is verified. If the digital watermark verification is successful, the target data is sent to the group devices.
[0066] In this application, the meeting administrator can synchronize the security level identifier and meeting key corresponding to the meeting to the meeting server. The meeting server then performs the first security verification on the digital watermark in the data from the data provider. After the verification is successful, the data is forwarded to the meeting terminal, thereby further improving the security of the meeting.
[0067] Optionally, in the conference system, if the verification results of the digital watermark in the same data differ among multiple conference terminals, the conference administrator can send a transmission ban instruction to the conference server. This transmission ban instruction is used to instruct the conference server to prohibit further data transmission to the conference terminals in order to prevent further leakage of conference data.
[0068] In a sixth aspect, a computer device is provided, comprising: a processor and a memory; the memory for storing a computer program, the computer program including program instructions; the processor for invoking the computer program to implement the methods of the first aspect and its embodiments, and to implement the methods of the second aspect and its embodiments.
[0069] In a seventh aspect, a computer-readable storage medium is provided, wherein instructions are stored thereon, which, when executed by a processor, implement the methods of the first aspect and its embodiments described above, or implement the methods of the second aspect and its embodiments described above.
[0070] Eighthly, a computer program product is provided, comprising a computer program that, when executed by a processor, implements the methods described in the first aspect and its embodiments, or implements the methods described in the second aspect and its embodiments.
[0071] In a ninth aspect, a chip is provided, the chip including programmable logic circuitry and / or program instructions, which, when the chip is running, implement the methods of the first aspect and its embodiments described above, or implement the methods of the second aspect and its embodiments described above. Attached Figure Description
[0072] Figure 1 This is a schematic diagram illustrating a scenario of meeting information leakage provided in an embodiment of this application;
[0073] Figure 2 This is a schematic diagram of an application scenario provided by an embodiment of this application;
[0074] Figure 3 This is a schematic diagram of a group key distribution provided in an embodiment of this application;
[0075] Figure 4 This is a schematic diagram of a group key negotiation provided in an embodiment of this application;
[0076] Figure 5 This is a schematic diagram of a video conferencing scenario provided in an embodiment of this application;
[0077] Figure 6 This is a flowchart illustrating a data sharing method provided in an embodiment of this application;
[0078] Figure 7 This is a schematic diagram illustrating the division of the fingerprint extraction area and the watermark embedding area according to an embodiment of this application;
[0079] Figure 8 This is a schematic diagram of a watermark embedding and verification process provided in an embodiment of this application;
[0080] Figure 9 This is a flowchart illustrating a data display method provided in an embodiment of this application;
[0081] Figure 10 This is a schematic diagram illustrating a meeting data leakage provided in an embodiment of this application;
[0082] Figure 11 This is a schematic diagram illustrating meeting data leakage in a screen-sharing scenario provided in an embodiment of this application;
[0083] Figure 12 This is a schematic diagram of the structure of a data sharing device provided in an embodiment of this application;
[0084] Figure 13 This is a schematic diagram of the structure of a data display device provided in an embodiment of this application;
[0085] Figure 14 This is a schematic diagram of the hardware structure of a computer device provided in an embodiment of this application. Detailed Implementation
[0086] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.
[0087] Currently, video conferencing is categorized into different security levels. The higher the security level, the greater the confidentiality of the meeting content. Typically, the content of high-security meetings, especially shared materials, is prohibited from being shared with low-security meetings. However, in reality, many information leaks occur, leading to the disclosure of information from high-security meetings. For example, malicious internal participants in a high-security meeting might forward the meeting content to others without authorization, resulting in the leakage of information from the high-security meeting. Figure 1 This is a schematic diagram illustrating a meeting information leakage scenario provided in an embodiment of this application. For example... Figure 1 As shown, participants 1, 2, and 3 access conference 1 via terminals T1, T2, and T3 respectively, while participants 4, 5, and 6 access conference 2 via terminals T4, T5, and T6 respectively. Participant 1 operates terminal T1 to share conference data with terminals T2 and T3 participating in conference 1 via a multipoint control unit (MCU). Participant 3 operates terminal T3 to forward this conference data to terminal T4 participating in conference 2. Since participant 4 does not have permission to participate in conference 1, if terminal T4 displays this conference data, it will result in the unauthorized disclosure of the conference data. Therefore, ensuring that terminals in a conference can only display conference data matching their own security level to prevent unauthorized disclosure of conference data is crucial to improving the security of video conferencing, especially for conferences with special security levels.
[0088] Related technologies offer a Rights Management Services (RMS) document management solution. RMS is a document access control technology used to enhance document content security and access management, ensuring that only authorized users can access specific information content, and that no one else can read the document. RMS implementation includes two stages: generating protected documents and user access to the documents.
[0089] During the protected document generation phase, the client randomly generates a content key and uses this content key to encrypt the document content using Advanced Encryption Standard (AES) to obtain an encrypted document. The client then creates a certificate containing a policy (user or group access permissions and other restrictions) and encrypts both the policy and the content key using the organization's public key to obtain encrypted content containing the encryption policy and the encrypted content key. The client embeds this encrypted content into the encrypted document to form the protected document.
[0090] During the user document access phase, when a user wants to use a protected document, they need to send encrypted content containing the encryption policy and the encrypted content key (key) along with their user certificate to the RMS. The RMS first decrypts the encrypted content using the organization's private key to obtain the policy and content key. Then, the RMS evaluates the policy to generate a list of permissions for the user to the document and encrypts the content key using the user's public key from their certificate. Afterward, the RMS embeds the encrypted content key (using the user's public key) along with the user's permission list for the document into a license and returns the license to the user. The user decrypts the content key using their private key, allowing their document application to decrypt the encrypted document according to the user's needs and enforce document access control based on the policy.
[0091] However, the aforementioned RMS document management solution is only applicable to permission management of structured data such as static documents, and relies on document program execution strategies. It cannot manage permissions for unstructured data such as dynamic audio and video involved in video conferencing, and its application is highly limited.
[0092] Based on this, this application provides a technical solution that combines digital watermarking and digital fingerprinting technologies to uniformly manage display permissions for both structured and unstructured data. Digital watermarking technology is a technique that embeds specific information (such as copyright information or the provider's user information) into digital media to protect its copyright, prove product authenticity, track piracy, or provide additional product information. Digital watermarks can be embedded in various digital media, such as images, audio, video, and text. The watermark information is embedded in the carrier file without affecting the readability and integrity of the original file. Based on the perceptibility of the digital watermark, it can be divided into visible and invisible watermarks. Visible watermarks refer to directly embedding visible information, such as text or images, into digital media. Visible watermarks can be used to identify the owner or copyright information of digital media. Invisible watermarks refer to embedding invisible information, such as digital codes or noise, into digital media. Invisible watermarks can be used to verify the integrity and authenticity of digital media and to trace its source. Digital watermarking technology has a wide range of applications, including copyright protection, anti-counterfeiting, digital forensics, and information hiding. It tightly binds media information to its source, providing a degree of information protection and becoming a crucial means of digital media security. Digital fingerprinting is a technology used to identify digital content, similar to the concept of human fingerprints. It generates a unique identifier (essentially giving the digital content an identity) through calculation and analysis. For example, the hash value or semantic meaning of the perceived object can be used as a digital fingerprint to identify and verify the authenticity and integrity of the digital content. Digital fingerprinting technology is widely used in copyright protection, content recognition, and cybersecurity. Implementation methods for digital fingerprinting include hash algorithms, feature extraction, and comparison techniques.
[0093] In the technical solution provided in this application, a digital watermark is embedded in the data shared in a group by the data provider. This digital watermark is generated based on the group's security classification identifier, the group's group key, and the data's fingerprint information. The data provider then sends the data embedded with the digital watermark to the group's devices. This ensures that only devices holding the group's security classification identifier, group key, and whose fingerprint information has been verified can match the digital watermark, and only devices that can match the watermark have permission to display the data. Since only the group's devices hold the group's security classification identifier and group key, even if the data is leaked—for example, if malicious internal group members forward it to devices in other groups—the other group's devices cannot match the digital watermark and therefore cannot display the data, thus preventing data leakage. Furthermore, since fingerprint verification of the data is only possible if the data has not been tampered with, once the data is tampered with, the device cannot match the digital watermark and therefore cannot display the data, thus ensuring the authenticity and integrity of the data source and improving the security of shared data. The technical solution provided in this application can embed digital watermarks into structured or unstructured data, including but not limited to audio data, video data, document data, file data, and other digitized streaming media data, such as remote desktop sharing and remote sharing applications. Groups in this application include, for example, meeting groups, discussion groups, and departmental groups.
[0094] The technical solution provided in this application is implemented as follows: In the data sharing phase, the data provider acquires the target data, which is obtained by embedding a digital watermark into the original data held by the data provider. The target data is used for sharing within a target group. The digital watermark is generated based on the security level identifier corresponding to the target group, the group key of the target group, and the fingerprint information of the original data. The data provider sends the target data to the group devices in the target group. In the data display phase, the device receiving the target data extracts the digital watermark from the target data and obtains the fingerprint information corresponding to the target data. Then, the device verifies the digital watermark based on its own security level identifier, group key, and fingerprint information. If the digital watermark verification is successful, the target data is displayed. The security classification identifier corresponding to the target group indicates the group's security classification. By binding the security classification identifier to the digital watermark, it is possible to restrict the display of target data to only devices whose security classification matches the group's security classification indicated by the identifier. Furthermore, by embedding the security classification identifier as part of the digital watermark into the data, and because it is impossible to modify any part of the original digital watermark information, it is ensured that the security classification identifier in the digital watermark cannot be reversibly recovered or illegally tampered with. The device matching the group security classification indicated by the security classification identifier includes situations where the group's security classification is the same as the group's security classification indicated by the identifier. In this case, the device can only display data from groups whose group security classification is the same as the group's security classification, thus preventing data sharing between groups with different security classifications. Alternatively, the device matches the group security level indicated by the security level identifier, including cases where the group security level of the device is located is higher than or equal to the group security level indicated by the security level identifier. In this case, the device can display data from groups with a security level no higher than the group security level corresponding to the device's group. This prevents data from high-security groups from flowing to low-security groups, thereby achieving data security protection for high-security groups. By binding data fingerprint information to the digital watermark, the authenticity and integrity of the data source can be guaranteed, ensuring that the data has not been tampered with during transit, thus improving the security of group data sharing. By binding the group key to the digital watermark, since the group key is a key used internally by the group, external adversaries usually cannot obtain the group key, and therefore cannot forge the digital watermark to embed in false data for device display, further ensuring the authenticity and security of the data source. By applying the solution of this application to video conferencing scenarios, i.e., the target group is a conference group, the problem of data flowing from high-security conferences to low-security conferences, leading to the illegal leakage of information from high-security conferences, can be solved, thereby improving the security of video conferencing.
[0095] In one embodiment, the digital watermark includes a security classification identifier corresponding to the target group and a first signature value. The first signature value is obtained by signing the first authentication information using the group key of the target group. The first authentication information includes the fingerprint information of the original data. The first signature value can be a symmetric signature value obtained by symmetric signing the first authentication information using the group key of the target group, or it can be a truncated result of the symmetric signature value. The symmetric signature algorithm used to calculate the symmetric signature value can be, for example, the AES-based message authentication code (CMAC) algorithm. This application does not limit the symmetric signature algorithm used. Let the group key be key, and the fingerprint information of the original data be fi. Taking the first signature value as a 64-bit truncated result of signing the fingerprint information fi using the AES-CMAC algorithm as an example, the first signature value can be represented as AES_CMAC_64(key,fi). Correspondingly, the digital watermark can be represented as: security classification identifier ||AES_CMAC_64(key,fi). Here, the symbol "||" represents string concatenation.
[0096] This application allows for the truncation of symmetric signature values, embedding the truncated value as watermark information into the data. This reduces the watermark embedding capacity, thereby ensuring the fidelity and robustness of the data (especially audio data) after watermark embedding. Since some data is limited by watermark payload capacity and cannot support the full signature length—for example, for audio data—too much embedded watermark information can affect the fidelity and robustness of the audio data. For instance, currently, audio watermark payloads are generally within 8 bytes. Therefore, the symmetric signature value can be truncated before embedding the truncated result (because symmetric signatures are reversible, they can be truncated without affecting signature verification. However, asymmetric signatures must rely on the complete signature value for verification). Specifically, refer to Section 2.4 of the Request for Comments (RFC) document (IETF RFC 4493) issued by the Internet Engineering Task Force (IETF), which describes the message authentication code (MAC) generation algorithm: "MACs can be truncated. According to [NIST-CMAC], at least a 64-bit MAC should be used as a protection against guessing attacks. In most cases, the most important bits of the result should be truncated first." This implementation method reduces the watermark embedding capacity by truncating the symmetric signature value and embedding the truncated result as watermark information into the audio data, thus ensuring the fidelity and robustness of the audio data after embedding the watermark information. For video data, document data, or file data, either the symmetric signature value or the truncated result of the symmetric signature value can be embedded as watermark information into the data.
[0097] Optionally, the aforementioned first authentication information may also include one or more of the following: a security classification identifier corresponding to the target group, group information of the target group, user identifier of the group user accessing the target group through the group device, or user identifier of the data provider. Taking the first signature value as a 64-bit truncated result of a symmetric signature value obtained by signing the fingerprint information fi, group information, and one or more of the aforementioned user identifiers using the AES-CMAC algorithm, the first signature value can be represented as AES_CMAC_64(key,fi||security classification identifier||group information||user identifier). Correspondingly, the digital watermark can be represented as: security classification identifier||AES_CMAC_64(key,fi||security classification identifier||group information||user identifier).
[0098] This application identifies the data-sharing object as the target group by binding the group information of the target group to the digital watermark. This allows for tracing the source of the leak within the target group after a data breach, thus narrowing the scope of data tracing. By binding the user identifiers of group users accessing the target group through group devices to the digital watermark, different digital watermarks can be generated for different group users within the target group. This enables precise identification of the leak source after a data breach, facilitating leak tracing. Furthermore, binding the user identifier of the data provider to the digital watermark identifies the data source, providing assurance of the data's authenticity and security.
[0099] In another implementation, the digital watermark includes a second signature value. The second signature value is obtained by signing the second authentication information using the group key of the target group. The second authentication information includes a security classification identifier corresponding to the target group and fingerprint information of the original data. The second signature value can be a symmetric signature value obtained by symmetrically signing the second authentication information using the group key of the target group, or it can be a truncated result of the symmetric signature value. The symmetric signature algorithm used to calculate the symmetric signature value can be, for example, the AES-CMAC algorithm; this application does not limit the symmetric signature algorithm used. Let the group key be key, and the fingerprint information of the original data be fi. Taking the second signature value as a 64-bit truncated result of the symmetric signature value obtained by signing the fingerprint information fi and the security classification identifier corresponding to the target group using the AES-CMAC algorithm as an example, the second signature value can be represented as AES_CMAC_64(key, fi||security classification identifier), and correspondingly, the digital watermark can be represented as: AES_CMAC_64(key, fi||security classification identifier).
[0100] In this implementation, the security classification identifier is used as part of the second authentication information for signature encryption, instead of carrying the security classification identifier in plaintext in the digital watermark. This can prevent the leakage of security classification identifier information and thus improve information security.
[0101] Optionally, the second authentication information may also include one or more of the following: group information of the target group, user identifiers of group users accessing the target group through group devices, or user identifiers of data providers. Taking the second signature value as a 64-bit truncated result of a symmetric signature value obtained by signing the fingerprint information fi, the security level identifier corresponding to the target group, the group information, and one or more of the aforementioned user identifiers using the AES-CMAC algorithm, the second signature value can be represented as AES_CMAC_64(key,fi||security level identifier||group information||user identifier). Correspondingly, the digital watermark can be represented as: AES_CMAC_64(key,fi||security level identifier||group information||user identifier).
[0102] Optionally, the target group mentioned above can be a meeting group, discussion group, or departmental group, etc., and this application does not limit the type of group. Taking a meeting group as an example, the group device is a meeting terminal. Accordingly, the group information includes, but is not limited to, the meeting identifier corresponding to the meeting group and / or the meeting timestamp corresponding to the meeting group. The meeting identifier can be, for example, a meeting number, and the meeting timestamp can include the start time and / or end time of the meeting.
[0103] The technical solution of this application will be described in detail below from multiple perspectives, including application scenarios, methods and processes, software devices, hardware devices, and systems.
[0104] The following are examples illustrating the application scenarios of embodiments of this application.
[0105] This application's embodiments can be applied to group communication scenarios, such as various scenarios involving data sharing and display within a group, preventing the illegal leakage of group data. Two common group communication scenarios are non-real-time asynchronous interaction scenarios and real-time synchronous interaction scenarios. Non-real-time asynchronous interaction scenarios primarily involve multi-party information exchange, such as group messaging in instant messaging applications. Real-time synchronous interaction scenarios primarily involve multi-party video conferencing (i.e., multipoint video conferencing), such as ad-hoc small group meetings or scheduled large organizational meetings. Taking this application's embodiments as an example in a video conferencing scenario, it can solve the problem of data flow from high-security meetings to low-security meetings, leading to the illegal leakage of information from high-security meetings, thereby improving the security of video conferencing. Optionally, the data shared and displayed in the group includes, but is not limited to, audio data, video data, document data, file data, and other digitized streaming media data, such as remote desktop sharing and remote application sharing.
[0106] For example, Figure 2 This is a schematic diagram illustrating an application scenario provided in an embodiment of this application. For example... Figure 2 As shown, this application scenario includes a data provider, a group manager, and one or more group members. Figure 2 Taking an application scenario with three group members (group member A, group member B, and group member C) as an example, the number of group members is not a limitation on the application scenario of this application embodiment.
[0107] The group administrator is honest and trustworthy, at least to the data provider and group members. The group administrator can be a user terminal, server, or cloud computing platform, etc. The group administrator is used to pre-approve the content that needs to be displayed in the group. See, for example... Figure 2The data provider needs to send the data N, which is to be shared in the group, to the group administrator for review. After the group administrator approves the data N, a digital watermark is embedded in the data N to obtain the data M, and the data M is returned to the data provider.
[0108] It is worth noting that the data provider can be a group member in the group or an external device; this application embodiment does not limit this. Figure 2 The application scenario shown is illustrated using an external device as an example of a data provider.
[0109] Each member of the group consists of a group user and a group device. The group user accesses the group through the group device. For example, group member A includes group user A and group device A. Group member B includes group user B and group device B. Group member C includes group user C and group device C. Optionally, the group device can be a user terminal such as a mobile phone, tablet, or computer. The group device can receive data from the data provider and display the data locally. See, for example... Figure 2 The data provider sends data M to group device A, group device B, and group device C respectively. After group device A, group device B, and group device C verify the digital watermark in data M locally, they display data M.
[0110] Optionally, the group administrator generates the same digital watermark for all group members. For example, the group administrator generates the same digital watermark for all group members based on the group's security level identifier, the group's group key, the fingerprint information of data N, the group's group information, and the data provider's user identifier. This digital watermark is then embedded in data N to obtain data M, which is sent by the data provider to group devices A, B, and C. Alternatively, the group administrator generates a separate digital watermark for each group member, meaning different digital watermarks are generated for different group members. For example, the group administrator generates different digital watermarks for different group members based on the group's security level identifier, group key, fingerprint information of data N, group information, user identifier of the data provider, and user identifiers of different group users. For instance, digital watermark A (bound to the user identifier of group user A) is generated for group member A and embedded in data N to obtain data M1, which is sent by the data provider to group member A; digital watermark B (bound to the user identifier of group user B) is generated for group member B and embedded in data N to obtain data M2, which is sent by the data provider to group member B; and digital watermark C (bound to the user identifier of group user C) is generated for group member C and embedded in data N to obtain data M3, which is sent by the data provider to group member C.
[0111] In this embodiment, both the group manager and each group device within the group hold a security level identifier and a group key corresponding to that group. The security level identifier indicates the group's security level. Groups with different security levels have different security level identifiers. Different groups have different group keys; each group has its own unique group key.
[0112] Optionally, the group device includes a security module. The security level identifier and group key are determined by end-to-end communication between the group administrator and the security module in the group device. The group device stores the security level identifier and group key corresponding to the group in the security module. In this embodiment, by separating the group users and the group device, and by setting up a security module in the group device to store the security level identifier and group key corresponding to the group, and performing digital watermark matching in the security module, the security level identifier and group key are protected from leakage. This prevents group users from obtaining the security level identifier and group key and from maliciously forging digital watermarks to cause data leakage.
[0113] In group devices, security modules are used to protect data and operational security. Security modules can be implemented in hardware (such as HSMs) or software (such as TEEs), and are a collective term for a class of security hardware and software. A TEE generally refers to a secure area within the main processor of any mobile device such as a smartphone or tablet. TEEs are used to meet the need for various sensitive data to be stored, processed, and protected in a trusted environment. TEEs are authorized security software, also known as "trusted applications," used to provide a secure execution environment, ensuring end-to-end security by implementing protection, confidentiality, integrity, and data access permissions. HSMs are primarily used to protect and manage sensitive data and keys, and provide related cryptographic operations. The core functions of an HSM include encryption / decryption, key management, and sensitive data protection, ensuring that only authorized users or applications can access this data.
[0114] Optionally, the security level identifier corresponding to the group can be determined by the group administrator and then sent to each group device. After receiving the security level identifier sent by the group administrator, the group device stores the security level identifier in the security module.
[0115] Optionally, the group key can be uniformly designated by the group administrator and then distributed to each group device. After receiving the group key from the group administrator, the group device stores the group key in its security module. For example, combined with... Figure 2 The application scenarios shown Figure 3 This is a schematic diagram of a group key distribution provided in an embodiment of this application. For example... Figure 3As shown, the group manager generates a group key and communicates end-to-end with the security modules in each group device to directly distribute the group key to the security modules of each group device, thereby achieving group key synchronization. Optionally, the group manager generates the group key through a key distribution center (KDC).
[0116] Alternatively, the group key can be negotiated between the group administrator and the security module in the group device. For example, combining... Figure 2 The application scenarios shown Figure 4 This is a schematic diagram of a group key negotiation provided in an embodiment of this application. Figure 4 As shown, the group administrator generates a public-private key pair, including private key r0 and public key z0, where z0 = r0 * G. The security module in group device A generates a public-private key pair, including private key r1 and public key z1, where z1 = r1 * G. The security module in group device B generates a public-private key pair, including private key r2 and public key z2, where z2 = r2 * G. The security module in group device C generates a public-private key pair, including private key r3 and public key z3, where z3 = r3 * G. Here, G represents the base point of the elliptic curve. Group devices A, B, and C each send their respective public keys to the group administrator. The group administrator generates a random number SID, negotiates a key with the public key z1 of group device A using its own private key r0 to obtain x1, x1 = r0 * z1, and calculates y1 = H(x1||SID)⊕γ; it negotiates a key with the public key z2 of group device B using its own private key r0 to obtain x2, x2 = r0 * z2, and calculates y2 = H(x2||SID)⊕γ; it negotiates a key with the public key z3 of group device C using its own private key r0 to obtain x3, x3 = r0 * z3, and calculates y3 = H(x3||SID)⊕γ. The group administrator sends the public key z0, random number SID, y1, y2, and y3 to the security modules of each group device. Group device A negotiates a key with the group administrator's public key z0 using its own private key r1 to obtain x1, x1 = r1 * z0, and further calculates γ = H(x1||SID)⊕y1. Group device B uses its private key r2 and the group administrator's public key z0 to negotiate a key to obtain x2, where x2 = r2 * z0. It then calculates γ = H(x2||SID)⊕y2. Group device C uses its private key r3 and the group administrator's public key z0 to negotiate a key to obtain x3, where x3 = r3 * z0. It then calculates γ = H(x3||SID)⊕y3. Finally, the group administrator and each group device calculate the same group key, key = H(γ||y1||y2||y3||SID). Here, H() represents the hash value calculated within the parentheses.
[0117] Optionally, Figure 2 The application scenario shown is a video conferencing scenario. In a video conferencing scenario, the group manager is the conference manager, which may be, for example, a super multipoint control unit (SMC). Each group member is a participant, for example, group member A is participant A, group member B is participant B, and group member C is participant C. The group device is the conference terminal, and the group users are the participants. Typically, a video conference can include multiple participants, with each participant joining the video conference through a conference terminal. The conference terminal can be a dedicated physical device or a software program with conferencing capabilities. This software program can run on various computing devices, such as mobile phones, tablets, and computers. In this case, the computing device running the software program can also be considered a conference terminal. In some cases, a participant may only include one participant, for example, the participant joining the video conference through a conferencing software program running on their personal mobile phone. In some cases, a single participant can include multiple participants. For example, in a conference room scenario, multiple participants located in the conference room can join the video conference through a single conference terminal in that conference room.
[0118] Optionally, the video conferencing scenario also includes a conference server, such as an MCU (Microcontroller Unit). The conference server communicates with the conference administrator, who can manage multiple conference servers in a distributed manner. Conference terminals join the video conference through the conference server. Specifically, conference terminals can obtain video conference data from the conference server and send locally collected data back to the conference server, which then forwards it to other participating terminals. Conference terminals can connect wirelessly, allowing participants to join the video conference smoothly regardless of their geographical location. For example, Figure 5 This is a schematic diagram of a video conferencing scenario provided in an embodiment of this application. Figure 5 As shown, in Figure 2 Based on the application scenario shown, the video conferencing scenario also includes a conference server, through which conference terminals communicate. The data provider sends the data M that needs to be shared in the video conference to the conference server, which then sends data M to the conference terminals of participant A, participant B, and participant C respectively.
[0119] Optionally, the conference server can directly forward data M from the data provider to the conference terminals. Alternatively, the conference administrator can synchronize the security identifier and conference key corresponding to the conference to the conference server. After the conference server verifies the digital watermark in data M from the data provider, it then forwards data M to the conference terminals. In other words, the conference server performs the first security verification on the data, thereby further enhancing the security of the conference.
[0120] The method flow of the embodiments of this application is illustrated below.
[0121] The solution provided in this application mainly includes two stages: data sharing and data display. The implementation process of the data sharing stage is as follows. Figure 6 The illustrated embodiment; the implementation process of the data display phase can be referred to below. Figure 9 The illustrated embodiment.
[0122] For example, Figure 6 This is a flowchart illustrating a data sharing method 600 provided in an embodiment of this application. Figure 6 As shown, method 600 includes, but is not limited to, steps 601 to 602. Method 600 can be applied to... Figure 2 The data provider shown in the application scenario can also be applied to... Figure 5 The data provider in the video conferencing scenario shown.
[0123] Step 601: The data provider obtains the target data by embedding a digital watermark in the original data held by the data provider. The target data is used to share in the target group. The digital watermark is generated based on the security level identifier corresponding to the target group, the group key of the target group, and the fingerprint information of the original data.
[0124] Optionally, the raw data includes, but is not limited to, audio data, video data, document data, file data, and other digitized streaming media data, such as remote desktop sharing and remote sharing applications. For document or file data, the document or file data can be transcoded to an image layer, and then a digital watermark can be embedded in the image.
[0125] Optionally, the process by which the data provider obtains the target data includes: the data provider sending raw data to the group administrator of the target group and receiving the target data sent by the group administrator. The group administrator holds the security level identifier and the group key corresponding to the target group. The group device in the target group includes a security module. The security level identifier and the group key corresponding to the target group are determined by end-to-end communication between the group administrator and the security module in the group device. For details on how the group administrator and the security module in the group device determine the security level identifier and the group key corresponding to the target group through end-to-end communication, please refer to the relevant content in the above embodiments. Figure 3 and Figure 4 The embodiments of this application will not be described in detail here.
[0126] For the group administrator, after receiving the raw data sent by the data provider, the group administrator first reviews the raw data. After the raw data is approved, the fingerprint information of the raw data is extracted, and a digital watermark is generated based on the security level identifier of the target group, the group key of the target group, and the fingerprint information of the raw data. The digital watermark is then embedded in the raw data to obtain the target data, and the target data is then sent to the data provider.
[0127] In this embodiment, the group administrator pre-approves and embeds digital watermarks on data that the data provider needs to share in the target group. This ensures that only approved data can be embedded with the digital watermark and displayed in the target group. By binding a security classification identifier to the digital watermark, only devices matching the group security classification indicated by the identifier can display the target data. By binding data fingerprint information to the digital watermark, the authenticity and integrity of the data source can be guaranteed, ensuring that the data has not been tampered with during transit. The data provider cannot share data that does not match the approved content (data not approved by the group administrator) with the target group, thereby improving the security of group data sharing. By binding a group key to the digital watermark, since the group key is used internally within the group, external adversaries typically cannot obtain it and therefore cannot forge digital watermarks to embed in fake data for device display, further ensuring the authenticity and security of the data source.
[0128] In the first embodiment, the digital watermark includes a security classification identifier corresponding to the target group and a first signature value. The first signature value is obtained by signing the first authentication information using the group key of the target group. The first authentication information includes the fingerprint information of the original data. Let the group key be denoted as key, and the fingerprint information of the original data be denoted as fi. The digital watermark can be represented, for example, as: security classification identifier || AES_CMAC_64(key, fi).
[0129] Optionally, the first authentication information may also include one or more of the following: a security classification identifier corresponding to the target group, group information of the target group, user identifiers of group users accessing the target group through group devices, or user identifiers of data providers. Let the group key be denoted as `key`, the fingerprint information of the original data as `fi`, and the digital watermark, for example, be represented as: security classification identifier || AES_CMAC_64(key, fi || security classification identifier || group information || user identifier).
[0130] In this embodiment, by binding the group information of the target group to the digital watermark, the data sharing object can be identified as the target group. This allows for tracing the source of the leak within the target group after a data breach, thus narrowing the scope of data tracing. By binding the user identifiers of group users accessing the target group through group devices to the digital watermark, different digital watermarks can be generated for different group users within the target group. This enables precise identification of the leak source after a data breach, facilitating leak tracing. Furthermore, by binding the user identifier of the data provider to the digital watermark, the data source can be identified, providing assurance of the data source's authenticity and security.
[0131] In the second implementation, the digital watermark includes a second signature value. The second signature value is obtained by signing the second authentication information using the group key of the target group. The second authentication information includes a security classification identifier corresponding to the target group and fingerprint information of the original data. Let the group key be denoted as `key`, and the fingerprint information of the original data as `fi`. The digital watermark can be represented, for example, as: AES_CMAC_64(key,fi||security classification identifier).
[0132] Optionally, the second authentication information may also include one or more of the following: group information of the target group, user identifiers of group users accessing the target group through the group device, or user identifiers of the data provider. Let the group key be denoted as `key`, the fingerprint information of the original data as `fi`, and the digital watermark, for example, be represented as: AES_CMAC_64(key,fi||security level identifier||group information||user identifier).
[0133] Since digital watermarks are bound to the fingerprint information of the original data, the fingerprint information extracted by the watermark extraction end from the data embedded with the digital watermark must be consistent with the fingerprint information extracted by the watermark embedding end from the original data. In other words, the same fingerprint information must be extracted from the data before and after embedding the digital watermark to avoid situations where changes to the data content after embedding the digital watermark lead to incorrect extracted fingerprint information, thereby achieving correct verification of the digital watermark. This application does not limit the implementation method of embedding digital watermarks in data; the following three possible implementation methods are illustrated as examples.
[0134] The first possible implementation can be applied to image data, which can be video data or image data obtained by transcoding document or file data to an image layer. In this first possible implementation, the image is divided into regions: a fingerprint extraction region and a watermark embedding region. The fingerprint extraction region is used to extract fingerprint information, and the watermark embedding region is used to embed a digital watermark. For example, Figure 7 This is a schematic diagram illustrating the division of a fingerprint extraction area and a watermark embedding area according to an embodiment of this application. The watermark embedding end extracts fingerprint information from the fingerprint extraction area and embeds a digital watermark in the watermark embedding area. Correspondingly, the watermark extraction end extracts fingerprint information from the fingerprint extraction area and verifies the digital watermark embedded in the watermark embedding area. Since the area for extracting fingerprint information before and after watermark embedding is the same, the watermark extraction end and the watermark embedding end can extract the same fingerprint information if the image data has not been tampered with, thereby enabling the watermark extraction end to effectively match the digital watermark.
[0135] The second possible implementation can be applied to image data or audio data (collectively referred to as media data). In this second possible implementation, taking into account the characteristics of media data transmission in frames and playback per frame, the watermark embedding end embeds a digital watermark generated based on the previous media frame into the subsequent media frame. The watermark extraction end uses a backward verification algorithm to verify the previous frame using information from the subsequent frame. Since the digital watermark is embedded in the subsequently transmitted media data, the embedded digital watermark will not affect the fingerprint calculation of the previously transmitted media data. For example, Figure 8 This is a schematic diagram of a watermark embedding and verification process provided in an embodiment of this application. First, Di is defined as the i-th media frame obtained by segmenting the media data, where i is a positive integer. f(D) i (f) is a fingerprint algorithm used to calculate the fingerprint information f of the i-th media frame. i W(f) i ) represents the watermark generation algorithm, indicating the fingerprint information f based on the i-th media frame. i Generate digital watermark W i .
[0136] See Figure 8 The watermark embedding end adds a digital watermark to the media frame. The specific implementation steps are as follows: 1) Calculate the media frame D transmitted in real time. i fingerprint information f i ;2) Based on fingerprint information f i The security classification identifier corresponding to the target group and the group key of the target group generate a digital watermark W. i 3) Use a watermark embedding algorithm to embed the digital watermark W i Embedded into the next media frame D i+1 The watermark embedding is completed in the middle. This is for watermarks with embedded digital watermarks W. iThe next media frame D i+1 Repeat steps 1 to 3 above to complete the cyclic embedding process.
[0137] See Figure 8 The watermark extraction end verifies the digital watermark in the media frame. The specific implementation steps are as follows: 1) Extract the media frame D using the watermark extraction algorithm. i+1 Digital watermark W i ;2) Calculate the previous frame D i fingerprint information f i ';3) Based on fingerprint information f i The digital watermark W(f) is generated from the security classification identifier corresponding to the target group and the group key of the target group. i '); 4) Compare W(f) i ') and W i If the values are the same, the check passes; otherwise, the check fails. Continue using media frame D following steps 1-4 above. i+2 Digital watermark W i+1 Continue verifying media frame D i+1 This continues until the verification process is complete.
[0138] The third possible implementation can be applied to image or audio data (collectively referred to as media data). Deep learning models can be used to ensure that the digital watermark has a negligible impact on the media data, thus maintaining the consistency of the fingerprint information before and after the watermark embedding. Taking image data as an example, during the watermark embedding process, a fixed peak signal-to-noise ratio (PSNR) algorithm is used to control the magnitude of the modification, ensuring that the embedded digital watermark does not significantly alter the appearance of the image. During training, a convolutional neural network is used to minimize the reconstruction loss between the original watermark vector and the extracted watermark vector, ensuring that the impact of the embedded digital watermark on the image is sufficiently small, so that the extracted fingerprint information does not change significantly. The embedded digital watermark is a high-dimensional vector, and this vector property makes its perturbation in the high-dimensional space have a very small impact on the low-dimensional image features (fingerprint).
[0139] Step 602: Send target data to the group devices in the target group.
[0140] After receiving the target data, the group device in the target group extracts the digital watermark from the target data and obtains the fingerprint information corresponding to the target data. Based on the security level identifier of the target group, the group key of the target group, and the fingerprint information corresponding to the target data held by the group device, the digital watermark is verified. After the digital watermark is verified, the target data is displayed.
[0141] In this embodiment, a digital watermark is embedded in the data shared within a target group by the data provider. This watermark is generated based on the security identifier corresponding to the target group, the group key of the target group, and the fingerprint information of the data. The data provider then sends the data embedded with the digital watermark to the group devices within the target group. This ensures that only devices holding the security identifier and group key of the target group, and whose fingerprint information has been verified, can match the digital watermark. Furthermore, only devices that can match the digital watermark are authorized to display the data. Since only the group devices within the target group hold the security identifier and group key, even if the data is leaked—for example, if maliciously forwarded by internal group members to devices in other groups—the devices in other groups cannot match the digital watermark and therefore cannot display the data, thus preventing data leakage. Furthermore, since the fingerprint information of the data can only be verified if the data has not been tampered with, once the data is tampered with, the device cannot match the digital watermark and therefore cannot display the data. This ensures the authenticity and integrity of the data source, prevents illegal data leakage and display, and improves the security of group data sharing. In addition, the group administrator can pre-approve and embed digital watermarks on the data that the data provider needs to share in the target group. This ensures that only approved data can be embedded with digital watermarks and displayed in the target group, thus guaranteeing the authenticity of the data shared in the target group and preventing unapproved data from being displayed, thereby further improving the security of group data sharing.
[0142] For example, Figure 9 This is a flowchart illustrating a data display method 900 provided in an embodiment of this application. Figure 9 As shown, method 900 includes, but is not limited to, steps 901 to 904. Method 900 can be applied to... Figure 2 The group devices (group members) shown in the application scenario can also be applied to... Figure 5 The conference terminal (participant) in the video conferencing scenario shown.
[0143] Step 901: The first device receives the target data. The first device is a group device in the first group. The first device holds the first security level identifier and the first group key corresponding to the first group.
[0144] Optionally, in conjunction with method 600 above, if the first group is the target group in method 600, the first device is the group device in the target group, the first security level identifier held by the first device is the security level identifier corresponding to the target group, and the first group key held by the first device is the group key of the target group. In this case, the target data received by the first device can be sent by the data provider, that is, the first device receives the target data sent by the data provider.
[0145] Optionally, the first device includes a security module that stores a first security level identifier and a first group key.
[0146] In this embodiment of the application, by separating the user and the device, a security module is set in the device to store the security level identifier and group key corresponding to the group, and digital watermark matching is performed in the security module to ensure that the security level identifier and group key are not leaked, so that the user cannot obtain the security level identifier and group key, and cannot maliciously forge digital watermarks to cause data leakage.
[0147] Optionally, the security module in the first device obtains the first security level identifier and the first group key through end-to-end communication with the group manager of the first group. The implementation method of the security module in the group device communicating end-to-end with the group manager to obtain the security level identifier and group key corresponding to the group can be found in the relevant content of the above embodiments. Figure 3 and Figure 4 The embodiments of this application will not be described in detail here.
[0148] In this embodiment, the security module in the device obtains the security level identifier and group key corresponding to the group through end-to-end communication with the group administrator, ensuring that the security level identifier and group key are not leaked.
[0149] Step 902: The first device extracts the digital watermark from the target data and obtains the fingerprint information corresponding to the target data.
[0150] Optionally, the first device extracts the digital watermark from the target data and obtains the fingerprint information corresponding to the target data based on the embedding method of the digital watermark in the target data and the fingerprint information extraction method used when embedding the digital watermark.
[0151] For example, in conjunction with the first possible implementation of step 602 above, the first device extracts fingerprint information from the fingerprint extraction area and extracts a digital watermark from the watermark embedding area. In conjunction with the second possible implementation of step 602 above, the first device extracts the digital watermark from the subsequent media frame and calculates the fingerprint information of the preceding media frame accordingly. In conjunction with the third possible implementation of step 602 above, the first device directly extracts the digital watermark from the target data and calculates the fingerprint information of the target data.
[0152] Step 903: The first device verifies the digital watermark based on the first security level identifier, the first group key, and the fingerprint information corresponding to the target data.
[0153] In a first implementation, the digital watermark includes a security classification identifier and a signature value 1. One implementation of step 903 includes: if the first security classification identifier matches the security classification identifier in the digital watermark, the first device uses a first group key to sign the authentication information 1 to obtain a signature value 2. The authentication information 1 includes fingerprint information corresponding to the target data. If signature value 2 matches signature value 1, the first device determines that the digital watermark verification is successful. Conversely, if the first security classification identifier does not match the security classification identifier in the digital watermark, or if signature value 2 does not match signature value 1, the first device determines that the digital watermark verification is unsuccessful.
[0154] In this embodiment, when the digital watermark includes a security classification identifier, the device first determines whether its own security classification identifier matches the security classification identifier in the digital watermark. If the security classification identifier held by the device does not match the security classification identifier in the digital watermark, the device can directly determine that the verification of the digital watermark fails and will not execute subsequent processes. That is, it is not necessary to use the group key held by the device to calculate the signature value of the authentication information, which can improve the verification efficiency of the digital watermark.
[0155] Optionally, the implementation method of the first device signing the authentication information 1 using the first group key can refer to the above-described implementation method of signing the first authentication information using the group key of the target group, which will not be repeated here. It is worth noting that the first device can determine whether the first security level identifier matches the security level identifier in the digital watermark in the security module, and sign the authentication information 1 using the first group key to obtain the signature value 2, thereby preventing the first security level identifier and the first group key from leaving the security module, so as to ensure information security and data processing security.
[0156] For example, referring to the first embodiment in step 601 above, the security level identifier in the digital watermark is the security level identifier corresponding to the target group, and the signature value 1 in the digital watermark is the first signature value. When the first device is a group device in the target group, the first security level identifier held by the first device is the security level identifier corresponding to the target group, that is, the first security level identifier is the same as the security level identifier in the digital watermark, and the first group key held by the first device is the group key of the target group. If the target data is not tampered with during transit, the fingerprint information obtained by the first device based on the target data is also the same as the fingerprint information used to calculate the first signature value. Accordingly, the signature value 2 calculated by the first device is the same as the signature value 1 in the digital watermark. In this case, the first device can verify the digital watermark.
[0157] Optionally, the first security classification identifier matches the security classification identifier in the digital watermark, including: the group security classification indicated by the first security classification identifier is higher than or equal to the group security classification indicated by the security classification identifier in the digital watermark. In this case, the first device can display data in groups whose group security classification is not higher than the group security classification corresponding to the first group, which can prevent data from high-security groups from flowing to low-security groups, thereby achieving data security protection for high-security groups.
[0158] Alternatively, the first security classification identifier matches the security classification identifier in the digital watermark, including cases where the group security classification indicated by the first security classification identifier is equal to the group security classification indicated by the security classification identifier in the digital watermark. In this case, the first device can only display data from groups whose group security classification is the same as the group security classification corresponding to the first group, thus preventing data sharing between groups with different security classifications.
[0159] It is worth noting that the matching criteria between the security classification identifier held by the device and the security classification identifier in the digital watermark can be set according to actual application requirements, and this application embodiment does not limit this.
[0160] In a second implementation, the digital watermark includes a signature value 3. One implementation of step 903 includes: a first device signing the authentication information 2 using a first group key to obtain a signature value 4. The authentication information 2 includes a first security level identifier and fingerprint information corresponding to the target data. If the signature value 4 matches the signature value 3, the first device determines that the digital watermark verification is successful. Conversely, if the signature value 4 does not match the signature value 3, the first device determines that the digital watermark verification fails.
[0161] Optionally, the implementation method of the first device signing the authentication information 2 using the first group key can refer to the above-described implementation method of signing the second authentication information using the group key of the target group, which will not be repeated here. It is worth noting that the first device can sign the authentication information 2 using the first group key in the security module to obtain the signature value 4, thereby preventing the first security level identifier and the first group key from leaving the security module, thus ensuring information security and data processing security.
[0162] For example, referring to the second implementation method in step 601 above, the security level identifier in the digital watermark is the security level identifier corresponding to the target group, and the signature value 3 in the digital watermark is the second signature value. When the first device is a group device in the target group, the first security level identifier held by the first device is the security level identifier corresponding to the target group, that is, the first security level identifier is the same as the security level identifier in the digital watermark, and the first group key held by the first device is the group key of the target group. If the target data has not been tampered with during transit, the fingerprint information obtained by the first device based on the target data is also the same as the fingerprint information used to calculate the second signature value. Accordingly, the signature value 4 calculated by the first device is the same as the signature value 3 in the digital watermark. In this case, the first device can verify the digital watermark.
[0163] Step 904: If the digital watermark verification is successful, the first device displays the target data.
[0164] Conversely, if the digital watermark verification fails, the first device will not display the target data. For example, in step 901 above, the target data received by the first device is sent by the second device; that is, the first device receives the target data sent by the second device, and the second device is a group device in the second group. The digital watermark in the target data is generated based on the second security level identifier corresponding to the second group, the second group key of the second group, and the fingerprint information corresponding to the target data. In this case, since the first device is a group device in the first group, it cannot possess the second security level identifier corresponding to the second group and the second group key of the second group. Therefore, it cannot verify the digital watermark in the target data and cannot display the target data, thus preventing data leakage of the second group.
[0165] Optionally, when the digital watermark in the target data is generated based on the second security level identifier corresponding to the second group, the second group key of the second group, the fingerprint information corresponding to the target data, and the user identifier of the group user who accessed the second group through the second device, the user identifier of the group user who accessed the second group through the second device used to generate the digital watermark can be used to determine that the leaker of the target data is a group user who accessed the second group through the second device when the first device fails to verify the digital watermark. In specific implementation, the group users in the second group can be traversed, and corresponding digital watermarks can be generated based on the second security level identifier, the second group key, the fingerprint information corresponding to the target data, and the user identifiers of different group users in the second group. The generated multiple digital watermarks are then matched with the digital watermark in the target data. Finally, the group user corresponding to the digital watermark that matches the digital watermark in the target data is identified as the source of the leak, thereby achieving leak tracing.
[0166] Optionally, after the first device verifies the digital watermark, it can transmit the target data to the projection device. It's worth noting that if the projection device is an external device not belonging to the first group, the first device must complete watermark detection before projection. Additionally, the projection device also needs to complete watermark detection before displaying the data to prevent data leakage in the projection scenario.
[0167] The order of steps in the methods provided in this application can be adjusted appropriately, and steps can be added or removed as needed. Any variations that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the protection scope of this application. For example, the embodiments of this application can be applied to, but are not limited to, audio and video conferencing systems, cloud service conferencing systems, and document access control systems, enabling secure protection against leakage of various types of data such as audio data, video data, document data, and file data. They are also compatible with existing RMS document access control systems; for example, shared protected documents can be transcoded to an image layer and then further embedded with digital watermarks for protection.
[0168] The following example, using a video conferencing scenario, illustrates the application of this solution.
[0169] In a first application example, this embodiment of the application can prevent data sharing between meetings of different security levels, thereby protecting the data security of security-level meetings. In the case of security-level video conferences, data sharing between different security-level meetings is generally prohibited. However, malicious internal participants in a security-level meeting may forward data from the current meeting to other personnel who do not have permission to participate in that security-level meeting. For example, referring to the reference... Figure 5 The video conferencing scenario shown is as follows: Figure 10This is a schematic diagram illustrating a meeting data leakage scenario provided in an embodiment of this application. For example... Figure 10 As shown, assume participants A, B, and C are participants in meeting 1, and participants D, E, and F are participants in meeting 2. Participant C forwards data M containing a digital watermark to participant D. This forwarding behavior includes direct forwarding or unauthorized recording. Regarding... Figure 10 The illustrated video conferencing data leakage scenario demonstrates how implementing the solution in this application can prevent participant D from displaying data M, thus avoiding data leakage in meeting 1. The specific implementation is as follows:
[0170] First, the meeting administrator assigns a security level identifier SL to meeting 1 based on the meeting security level of meeting 1, and assigns a meeting key key to meeting 1; the meeting terminals of each participant in meeting 1 obtain and store the security level identifier SL and the meeting key key.
[0171] Secondly, the data provider sends data N, which needs to be shared in Meeting 1, to the meeting administrator. The meeting administrator reviews the content of data N and, after approval, embeds a digital watermark into data N to obtain data M, which is then returned to the data provider. The digital watermark is generated based on the security level identifier SL, the meeting key key, and the fingerprint information fi of data N, for example, represented as: AES_CMAC_64(key,fi||SL). Optionally, the digital watermark can also be bound to meeting information and / or the user identifiers of participants. For example, the user identifiers of participants C can be bound to the digital watermark embedded in the data provided to participant C.
[0172] Then, the data provider sends data M to the conference server, which forwards it to the conference terminals of each participant in Conference 1. Upon receiving data M, each conference terminal in Conference 1 extracts the digital watermark from it and verifies it using its stored security classification identifier SL, conference key, and the extracted fingerprint information of data M. Since the conference terminals in Conference 1 possess the security classification identifier SL and conference key corresponding to Conference 1, and assuming data M has not been tampered with during transit, if the digital watermark in data M is successfully verified, data M can be displayed correctly.
[0173] When a malicious user (participant C) in Meeting 1 forwards data M to participant D in Meeting 2, participant D's meeting terminal will extract the digital watermark from data M for verification. However, since participant D is not in Meeting 1, it cannot obtain the security level identifier SL and the meeting key for Meeting 1, and therefore cannot verify the digital watermark in data M. Consequently, participant D's meeting terminal determines it lacks display permissions and prevents the display of data M, thus preventing meeting data leakage. Furthermore, if the meeting administrator binds the user identifier of the participant to the digital watermark embedded in the data provided to different participants, then by iterating through the digital watermarks generated for each participant in Meeting 1 and matching them with the digital watermark in the leaked data, the source of the leak can be identified, enabling leak tracing.
[0174] The second application example demonstrates how this embodiment can prevent data leakage in screen sharing scenarios. After a legitimately participating meeting terminal joins the meeting and acquires the meeting data, it can project the data onto a large screen via wired or wireless means. However, if the large screen attempts to project the meeting data onto other large screens through screen sharing, it will cause a data leakage problem. For example, Figure 11 This is a schematic diagram illustrating meeting data leakage in a screen-sharing scenario provided in an embodiment of this application. For example... Figure 11 As shown, after receiving conference data from the conference server, conference terminal T1 projects the data onto local terminal T2 (a compliant device allowed by the conference). Local terminal T2 then projects the data onto external terminal T3 (a device not authorized by the conference) via conference screen sharing. This is for... Figure 11The proposed solution addresses the issue of meeting data leakage in the screen-sharing scenario. By implementing this solution, the leakage of meeting data can be prevented from being displayed on the external terminal T3. Specifically, a digital watermark is embedded in the meeting data (this watermark is bound to the security level identifier of the meeting accessed by the meeting terminal T1 and the meeting key; the implementation method for embedding the digital watermark in the meeting data can be found in the above embodiment). Furthermore, it is stipulated that both the sending and receiving ends must verify the digital watermark in the meeting data before it can be screen-sharing externally. For terminal T2, before screen-sharing the meeting data, it must first verify the digital watermark in the meeting data, and only if the digital watermark verification is successful will it have permission to screen-sharing externally. Similarly, after receiving the conference data, terminal T3 also needs to verify the digital watermark in the conference data. Since terminal T3 is not a legitimate device in the conference that conference terminal T1 has accessed, it does not have the security level identifier and conference key corresponding to the conference. Therefore, it cannot verify the digital watermark in the conference data. As a result, terminal T3 determines that it does not have display permission and prohibits the display of the conference data, thereby preventing data leakage in the screen projection scenario.
[0175] The third application example demonstrates how this embodiment ensures that unapproved data cannot flow into the meeting. While the data provider may send the data to be shared in the meeting to the meeting administrator for content review in advance, and the review is completed, there is a possibility that other unapproved and illegal content might be sent to the participants during the actual transmission process. Furthermore, before the meeting terminal receives the meeting data, it may be tampered with by malicious adversaries or false meeting data may be sent, causing the data displayed on the meeting terminal to contradict the meeting content or resulting in a major meeting incident. To address this, in this embodiment, the data provider sends the meeting data to the meeting administrator for review before the meeting, receives the meeting data embedded with a digital watermark, and then sends the watermarked meeting data to the meeting server, which forwards it to the meeting terminal. If the data provider maliciously tampers with the meeting data before sending it to the meeting, since the data provider does not possess the meeting key, it cannot forge the watermark information. The meeting terminal will fail to verify the digital watermark and can directly refuse to display it. Furthermore, if other adversaries maliciously send non-compliant meeting data to the meeting terminal, they will be unable to forge correct watermark information because they lack the corresponding security identifier and meeting key. The meeting terminal will also fail to verify the digital watermark and can directly refuse to display it. By implementing this solution, all unverified external meeting data can be prevented from being displayed on the meeting terminal, ensuring the legality and authenticity of the data source and further enhancing the security of classified meetings.
[0176] In a fourth application example, this embodiment of the application can detect when a conference terminal has been compromised by an adversary. When the conference terminal is secure, after receiving conference data, it extracts and verifies the digital watermark in the data, and only displays the conference data if the watermark verification is successful. However, the conference terminal may be compromised by an adversary. Once compromised, the conference terminal may skip the watermark verification process and directly display the conference data, leading to incorrect data display. Because meetings are real-time, multiple meeting terminals accessing the same meeting will perform watermark verification on the same meeting data at roughly the same time. If some meeting terminals are compromised, these terminals may pass verification for some non-compliant meeting data. However, as long as not all meeting terminals are compromised, legitimate meeting terminals will fail verification for these non-compliant data. This can lead to different verification results for the same meeting data from different terminals within the same meeting. If this occurs, it can be determined that some meeting terminals are insecure, meaning the meeting has been attacked. In this case, all meeting terminals can be prevented from displaying the relevant meeting data to avoid serious consequences from misreplay. Furthermore, once insecurity is detected in a meeting terminal, the meeting can be stopped immediately, thereby improving the security of real-time meetings.
[0177] The following is an example of a system described in an embodiment of this application.
[0178] This application provides a data sharing system, including: a data provider, a group manager for a target group, and one or more group devices within the target group. This data sharing system is illustrated in, for example, [see...]. Figure 2 In this context, the data provider can be used to execute method 600, the group device can be used to execute method 900, and the group manager can be used to execute the actions performed by the group manager in the above method embodiments.
[0179] For example, a data provider sends raw data it holds to a group administrator. The group administrator embeds a digital watermark in the raw data to obtain target data and sends the target data back to the data provider. The digital watermark is generated based on the security level identifier corresponding to the target group, the group key of the target group, and the fingerprint information of the raw data. The data provider then sends the target data to a group device. The group device extracts the digital watermark from the target data and obtains the fingerprint information corresponding to the target data. It then verifies the digital watermark based on the security level identifier corresponding to the target group, the group key of the target group, and the fingerprint information held by the group device. After successful verification of the digital watermark, the target data is displayed.
[0180] In this embodiment, the group administrator pre-approves and embeds a digital watermark into the data that the data provider needs to share in the target group. This ensures that only approved data can be embedded with the digital watermark and displayed in the target group, guaranteeing the authenticity of the data shared and preventing unapproved data from being displayed, thus improving the security of group data sharing. Furthermore, the data provider sends data embedded with the digital watermark to the group devices in the target group. Only devices holding the security identifier and group key corresponding to the target group, and whose fingerprint information has been verified, can match the digital watermark. This restricts the data display to only devices that can match the digital watermark. Since only the group devices in the target group hold the security identifier and group key, even if the data is leaked—for example, if malicious internal group members forward it to devices in other groups—the devices in other groups cannot match the digital watermark and therefore cannot display the data, thus preventing data leakage. Furthermore, since fingerprint verification of data can only be successful if the data has not been tampered with, once the data is tampered with, the device cannot match the digital watermark in the data and therefore cannot display the data. This ensures the authenticity and integrity of the data source, prevents the data from being illegally leaked and displayed, and improves the security of group data sharing.
[0181] Optionally, the group device includes a security module. The security module in the group device is used to communicate end-to-end with the group administrator to obtain a security level identifier and a group key, and stores the security level identifier and the group key in the security module.
[0182] In this embodiment, the security module in the group device obtains and stores the security level identifier and group key corresponding to the group through end-to-end communication with the group administrator, thereby ensuring that the security level identifier and group key are not leaked.
[0183] Optionally, the target group includes multiple group devices. The data provider sends the target data to each of the multiple group devices. Each of the multiple group devices, after verifying the digital watermark, sends a verification result to the group administrator, indicating whether the digital watermark verification passed. The group administrator is also used to send a prohibition display command to each of the multiple group devices if the verification results from the multiple group devices differ. This prohibition display command instructs the group devices to prohibit the display of the target data.
[0184] If multiple devices in the same group show different verification results for the digital watermark in the same data, it indicates that some of these devices may have been compromised by an adversary. In this case, this application embodiment can prevent serious consequences caused by mis-displaying data by prohibiting all devices in the group from displaying the data.
[0185] Optionally, the aforementioned data sharing system is a conference system, the group manager is the conference administrator, the group devices are conference terminals, and the conference system also includes a conference server, through which the data provider and the group devices communicate. For example, see [link to example conference system]. Figure 5 .
[0186] Optionally, the conference server stores a security classification identifier and a group key corresponding to the target group. The data provider sends the target data to the conference server. The conference server extracts a digital watermark from the target data and obtains the fingerprint information corresponding to the target data. Based on the security classification identifier, group key, and fingerprint information held by the conference server, the digital watermark is verified. If the digital watermark verification is successful, the target data is sent to the group devices.
[0187] In this embodiment, the meeting manager can synchronize the security identifier and meeting key corresponding to the meeting to the meeting server. The meeting server then performs the first security verification on the digital watermark in the data from the data provider. After the verification is successful, the data is forwarded to the meeting terminal, thereby further improving the meeting security.
[0188] Optionally, in the conference system, if the verification results of the digital watermark in the same data differ among multiple conference terminals, the conference administrator can send a transmission ban instruction to the conference server. This transmission ban instruction is used to instruct the conference server to prohibit further data transmission to the conference terminals in order to prevent further leakage of conference data.
[0189] The following describes an example of a virtual device in an embodiment of this application.
[0190] For example, Figure 12 This is a schematic diagram of a data sharing device provided in an embodiment of this application. This data sharing device can be applied to a data provider. Figure 12 As shown, the data sharing device 1200 includes, but is not limited to, an acquisition module 1201 and a transceiver module 1202.
[0191] The acquisition module 1201 is used to acquire target data, which is obtained by embedding a digital watermark into the original data held by the data provider. The target data is used for sharing within the target group, and the digital watermark is generated based on the security level identifier corresponding to the target group, the group key of the target group, and the fingerprint information of the original data. The transceiver module 1202 is used to send the target data to the group devices in the target group.
[0192] Optionally, the digital watermark includes a security classification identifier and a first signature value, the first signature value being obtained by signing the first authentication information using a group key, the first authentication information including fingerprint information.
[0193] Optionally, the first authentication information may also include one or more of the following: a security classification identifier, group information of the target group, user identifiers of group users accessing the target group through group devices, or user identifiers of data providers.
[0194] Optionally, the digital watermark includes a second signature value, which is obtained by signing the second authentication information with a group key. The second authentication information includes a security level identifier and fingerprint information.
[0195] Optionally, the second authentication information may also include one or more of the following: group information of the target group, user identifiers of group users accessing the target group through group devices, or user identifiers of data providers.
[0196] Optionally, the target group is a conference group, the group device is a conference terminal, and the group information includes the conference identifier corresponding to the conference group and / or the conference timestamp corresponding to the conference group.
[0197] Optionally, the transceiver module 1202 is used to send raw data to the group manager of the target group, the group manager holding a security level identifier and a group key, the group device including a security module, and the security level identifier and group key being determined by end-to-end communication between the group manager and the security module in the group device; and to receive the target data sent by the group manager.
[0198] Optionally, the raw data may be audio data, video data, document data, or file data.
[0199] For example, Figure 13 This is a schematic diagram of a data display device provided in an embodiment of this application. This data display device can be applied to a first device. For example... Figure 13 As shown, the data display device 1300 includes, but is not limited to, a transceiver module 1301, an information extraction module 1302, a watermark verification module 1303, and a display module 1304. Optionally, please refer to... Figure 13 The data display device 1300 also includes a security module 1305.
[0200] The transceiver module 1301 is used to receive target data. The first device is a group device in a first group, and the first device holds a first security level identifier and a first group key corresponding to the first group. The information extraction module 1302 is used by the first device to extract a digital watermark from the target data and obtain fingerprint information corresponding to the target data. The watermark verification module 1303 is used to verify the digital watermark based on the first security level identifier, the first group key, and the fingerprint information. The display module 1304 is used to display the target data if the digital watermark verification is successful.
[0201] Optionally, the digital watermark includes a security classification identifier and a first signature value. The watermark verification module 1303 is used to: if the first security classification identifier matches the security classification identifier in the digital watermark, sign the first authentication information using a first group key to obtain a second signature value, wherein the first authentication information includes fingerprint information; and if the second signature value matches the first signature value, determine that the digital watermark verification is successful.
[0202] Optionally, matching the first security classification identifier with the security classification identifier in the digital watermark includes: the group security classification indicated by the first security classification identifier is higher than or equal to the group security classification indicated by the security classification identifier in the digital watermark. Alternatively, matching the first security classification identifier with the security classification identifier in the digital watermark includes: the group security classification indicated by the first security classification identifier is equal to the group security classification indicated by the security classification identifier in the digital watermark.
[0203] Optionally, the watermark verification module 1303 is further configured to determine that the digital watermark verification fails if the first security level identifier does not match the security level identifier in the digital watermark, or if the second signature value does not match the first signature value.
[0204] Optionally, the digital watermark includes a third signature value. The watermark verification module 1303 is used to: sign the second authentication information using a first group key to obtain a fourth signature value. The second authentication information includes a first security level identifier and fingerprint information. If the fourth signature value matches the third signature value, it is determined that the digital watermark verification is successful.
[0205] Optionally, the display module 1304 is also configured to not display the target data if the digital watermark verification fails.
[0206] Optionally, the security module 1305 stores a first security level identifier and a first group key.
[0207] Optionally, the security module 1305 is used to obtain a first security level identifier and a first group key by communicating end-to-end with the group manager of the first group.
[0208] Optionally, the transceiver module 1301 is also used to transmit the target data to the projection device after the digital watermark has been verified.
[0209] Optionally, the transceiver module 1301 is used to receive target data sent by a second device, where the second device is a group device in a second group. The digital watermark is generated based on the second security level identifier corresponding to the second group, the second group key of the second group, the fingerprint information corresponding to the target data, and the user identifier of the group user who accesses the second group through the second device. The user identifier of the group user who accesses the second group through the second device, used to generate the digital watermark, is used to determine that the leaker of the target data is a group user who accesses the second group through the second device, should the digital watermark verification fail on the first device.
[0210] Optionally, the transceiver module 1301 is used to receive target data sent by the data provider.
[0211] The hardware device of the present application embodiment is illustrated below.
[0212] For example, Figure 14 This is a schematic diagram of the hardware structure of a computer device provided in an embodiment of this application. This computer device can be a data provider, a group device (such as a conference terminal), or a group manager as described in the above embodiments. Figure 14 As shown, the computer device 1400 includes a processor 1401 and a memory 1402, which are connected via a bus 1403. Figure 14 The processor 1401 and memory 1402 are described independently. Alternatively, the processor 1401 and memory 1402 are integrated together.
[0213] The memory 1402 is used to store computer programs, including the operating system and program code. The memory 1402 can be various types of storage media, such as read-only memory (ROM), random access memory (RAM), electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM), flash memory, optical storage, registers, optical disc storage, disk storage, or other magnetic storage devices.
[0214] The processor 1401 is a general-purpose processor or a special-purpose processor. The processor 1401 may be a single-core processor or a multi-core processor. The processor 1401 includes at least one circuit to perform the actions described in the embodiments of this application, such as method 600 or method 900, or the actions performed by the group manager described above.
[0215] Optionally, the computer device 1400 also includes a network interface 1404, which is connected to the processor 1401 and the memory 1402 via a bus 1403. The network interface 1404 enables the computer device 1400 to communicate with other devices. For example, the processor 1401 can interact with other devices through the network interface 1404.
[0216] Optionally, the computer device 1400 also includes an input / output (I / O) interface 1405, which is connected to the processor 1401 and the memory 1402 via a bus 1403. The processor 1401 can receive input commands or data through the I / O interface 1405. The I / O interface 1405 is used to connect input devices to the computer device 1400, such as a keyboard and mouse. Optionally, in some possible scenarios, the network interface 1404 and the I / O interface 1405 described above are collectively referred to as a communication interface.
[0217] Optionally, the computer device 1400 also includes a display 1406, which is connected to the processor 1401 and the memory 1402 via a bus 1403. The display 1406 can be used to display intermediate and / or final results generated by the processor 1401 executing the methods described above. In one possible implementation, the display 1406 is a touch screen to provide a human-computer interaction interface.
[0218] Bus 1403 can be any type of communication bus used to interconnect internal devices of computer device 1400, such as a system bus. This embodiment illustrates the interconnection of internal devices of computer device 1400 via bus 1403. Optionally, the internal devices of computer device 1400 may communicate with each other using connection methods other than bus 1403, such as interconnecting through internal logical interfaces of computer device 1400.
[0219] The aforementioned devices can be disposed on separate chips, or at least partially or entirely on the same chip. Whether to dispose of the devices independently on different chips or integrate them on one or more chips often depends on the needs of the product design. This application does not limit the specific implementation of the aforementioned devices.
[0220] Figure 14 The computer device 1400 shown is merely exemplary. In its implementation, the computer device 1400 may include other components, which will not be listed hereafter. Figure 14 The computer device 1400 shown can achieve data sharing by performing all or part of the steps of the method 600 provided in the above embodiments, or... Figure 14 The computer device 1400 shown can display data by performing all or part of the steps of the method 900 provided in the above embodiments.
[0221] This application also provides a computer-readable storage medium storing instructions that, when executed by a processor, implement the above-described method 600 or method 900.
[0222] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method 600 or method 900.
[0223] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware or by a program instructing related hardware. The program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk.
[0224] In the embodiments of this application, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.
[0225] In this application, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this document generally indicates that the preceding and following related objects have an "or" relationship.
[0226] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, data stored, data displayed, etc.) and signals involved in this application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.
[0227] The above description is merely an optional embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the concept and principles of this application should be included within the protection scope of this application.
Claims
1. A data sharing method, characterized in that, The method includes: The data provider obtains target data, which is obtained by embedding a digital watermark in the original data held by the data provider. The target data is used for sharing in a target group. The digital watermark is generated based on the security level identifier corresponding to the target group, the group key of the target group, and the fingerprint information of the original data. The data provider directs the transmission of the target data to group devices within the target group.
2. The method according to claim 1, characterized in that, The digital watermark includes the security level identifier and a first signature value. The first signature value is obtained by signing the first authentication information using the group key. The first authentication information includes the fingerprint information.
3. The method according to claim 2, characterized in that, The first authentication information also includes one or more of the following: the security level identifier, the group information of the target group, the user identifier of the group user who accesses the target group through the group device, or the user identifier of the data provider.
4. The method according to claim 1, characterized in that, The digital watermark includes a second signature value, which is obtained by signing the second authentication information using the group key. The second authentication information includes the security level identifier and the fingerprint information.
5. The method according to claim 4, characterized in that, The second authentication information also includes one or more of the following: group information of the target group, user identifiers of group users accessing the target group through the group device, or user identifiers of the data provider.
6. The method according to claim 3 or 5, characterized in that, The target group is a conference group, the group device is a conference terminal, and the group information includes the conference identifier corresponding to the conference group and / or the conference timestamp corresponding to the conference group.
7. The method according to any one of claims 1 to 6, characterized in that, The data provider acquires the target data, including: The data provider sends the original data to the group manager of the target group. The group manager holds the security identifier and the group key. The group device includes a security module. The security identifier and the group key are determined by the group manager through end-to-end communication with the security module in the group device. The data provider receives the target data sent by the group administrator.
8. The method according to any one of claims 1 to 7, characterized in that, The raw data may be audio data, video data, document data, or file data.
9. A data display method, characterized in that, The method includes: The first device receives target data. The first device is a group device in the first group. The first device holds a first security level identifier corresponding to the first group and a first group key of the first group. The first device extracts a digital watermark from the target data and obtains fingerprint information corresponding to the target data; The first device verifies the digital watermark based on the first security level identifier, the first group key, and the fingerprint information; If the digital watermark is verified, the first device displays the target data.
10. The method according to claim 9, characterized in that, The digital watermark includes a security classification identifier and a first signature value. The first device verifies the digital watermark based on the first security classification identifier, the first group key, and the fingerprint information, including: If the first security level identifier matches the security level identifier in the digital watermark, the first device uses the first group key to sign the first authentication information to obtain a second signature value, wherein the first authentication information includes the fingerprint information; If the second signature value matches the first signature value, the first device determines that the digital watermark has been verified.
11. The method according to claim 10, characterized in that, The first security classification identifier matches the security classification identifier in the digital watermark, including: the group security classification indicated by the first security classification identifier is higher than or equal to the group security classification indicated by the security classification identifier in the digital watermark; Alternatively, the first security classification identifier may match the security classification identifier in the digital watermark, including: the group security classification indicated by the first security classification identifier is equal to the group security classification indicated by the security classification identifier in the digital watermark.
12. The method according to claim 10 or 11, characterized in that, The method further includes: If the first security classification identifier does not match the security classification identifier in the digital watermark, or if the second signature value does not match the first signature value, the first device determines that the verification of the digital watermark fails.
13. The method according to claim 9, characterized in that, The digital watermark includes a third signature value. The first device verifies the digital watermark based on the first security level identifier, the first group key, and the fingerprint information, including: The first device uses the first group key to sign the second authentication information to obtain a fourth signature value. The second authentication information includes the first security level identifier and the fingerprint information. If the fourth signature value matches the third signature value, the first device determines that the digital watermark has been verified.
14. The method according to any one of claims 9 to 13, characterized in that, The method further includes: If the digital watermark verification fails, the first device will not display the target data.
15. The method according to any one of claims 9 to 14, characterized in that, The first device includes a security module, which stores the first security level identifier and the first group key.
16. The method according to claim 15, characterized in that, The method further includes: The security module in the first device obtains the first security level identifier and the first group key by communicating end-to-end with the group administrator of the first group.
17. The method according to any one of claims 9 to 16, characterized in that, The method further includes: After the first device verifies the digital watermark, it transmits the target data to the projection device.
18. The method according to any one of claims 9 to 17, characterized in that, The first device receives target data, including: The first device receives the target data sent by the second device, the second device being a group device in the second group, and the digital watermark is generated based on the second security level identifier corresponding to the second group, the second group key of the second group, the fingerprint information corresponding to the target data, and the user identifier of the group user who accesses the second group through the second device; The user identifier of the group user who accessed the second group through the second device, used to generate the digital watermark, is used to determine that the leaker of the target data is a group user who accessed the second group through the second device if the first device fails to verify the digital watermark.
19. The method according to any one of claims 9 to 17, characterized in that, The first device receives target data, including: The first device receives the target data sent by the data provider.
20. A data sharing device, characterized in that, The device includes multiple functional modules that interact with each other to implement the method as described in any one of claims 1 to 8.
21. A data display device, characterized in that, The device includes multiple functional modules that interact with each other to implement the method as described in any one of claims 9 to 19.
22. A data sharing system, characterized in that, include: The data provider, the group administrator of the target group, and one or more group devices in the target group; The data provider is used to send the original data held by the data provider to the group administrator; The group manager is used to embed a digital watermark in the original data to obtain target data and send the target data to the data provider. The digital watermark is generated based on the security level identifier corresponding to the target group, the group key of the target group, and the fingerprint information of the original data. The data provider is used to send the target data to the group of devices; The group device is used to extract the digital watermark from the target data and obtain the fingerprint information corresponding to the target data. It verifies the digital watermark based on the security level identifier corresponding to the target group, the group key of the target group, and the fingerprint information corresponding to the target data held by the group device. After the digital watermark is verified, the target data is displayed.
23. The data sharing system according to claim 22, characterized in that, The group of devices includes a security module; The security module in the group device is used to communicate end-to-end with the group administrator to obtain the security level identifier and the group key, and to store the security level identifier and the group key in the security module.
24. The data sharing system according to claim 22 or 23, characterized in that, The target group includes multiple group devices; The data provider is used to send the target data to the multiple group devices respectively; The plurality of group devices are respectively used to send the verification result of the digital watermark to the group manager after verifying the digital watermark, and the verification result is used to indicate whether the digital watermark has been verified successfully; The group manager is also used to send a prohibition display instruction to each of the multiple group devices when the verification results from the multiple group devices are different. The prohibition display instruction is used to instruct the group devices to prohibit the display of the target data.
25. The data sharing system according to any one of claims 22 to 24, characterized in that, The data sharing system is a conference system, the group manager is a conference manager, the group device is a conference terminal, and the conference system also includes a conference server. The data provider and the group device communicate through the conference server.
26. The data sharing system according to claim 25, characterized in that, The conference server stores the security level identifier corresponding to the target group and the group key of the target group; The data provider is used to send the target data to the conference server; The conference server is used to extract the digital watermark from the target data and obtain the fingerprint information corresponding to the target data. It verifies the digital watermark based on the security level identifier corresponding to the target group, the group key of the target group, and the fingerprint information corresponding to the target data held by the conference server. If the digital watermark is verified, the target data is sent to the group device.
27. A computer device, characterized in that, include: Processor and memory; The memory is used to store computer programs, the computer programs including program instructions; The processor is configured to invoke the computer program to implement the method as described in any one of claims 1 to 8, or to implement the method as described in any one of claims 9 to 19.
28. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed by a processor, implement the method as described in any one of claims 1 to 19.
29. A computer program product, characterized in that, Includes a computer program, which, when executed by a processor, implements the method as described in any one of claims 1 to 19.