A watermark embedding method, device, equipment, storage medium and product
By adding watermark embedding code in the load balancer, the problem of needing to modify the application server and client codes in the existing technology is solved, and fast page dark watermark embedding is achieved, reducing development costs.
Patent Information
- Application Number
- CN202411490125.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-23
- Publication Date
- 2025-10-14
- Estimated Expiration
- 2044-10-23
AI Technical Summary
The existing technology requires modifying the business codes of the application server and the application client to implement page dark watermark embedding, which leads to high development costs and difficulty in implementing fast page dark watermark embedding.
The watermark embedding code is added to the page data file through the load balancer, and the watermark embedding logic is written into the network traffic between the application server and the application client using the load balancer, without modifying the original business code of the application server and the application client.
This enables the application client to quickly embed watermarks without changing the original business code, simplifies the embedding process of page dark watermarks, and reduces development costs.
Smart Images

Figure CN119417685B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a watermark embedding method, a watermark embedding device, an electronic device, a computer-readable storage medium, and a computer program product. Background Art
[0002] Digital watermarking is a data protection technology that uses data redundancy to embed specific identification information. Digital watermarks are divided into visible watermarks and invisible watermarks (also called dark watermarks). The invisible watermark embedded in the application page is also called the page dark watermark. The dark watermark is used to protect the page copyright and prevent illegal copying.
[0003] Typically, a page dark watermark is generated by a dark watermark server. Specifically, the dark watermark server sends the generated dark watermark address to the application server, which then sends the dark watermark address to the application client. The application client then renders the dark watermark based on the dark watermark address, thus embedding the page dark watermark.
[0004] However, the above method requires modifying the business codes of the application server and the application client, adding codes related to obtaining the address of the dark watermark and sending the dark watermark to the business code of the application server, and adding codes related to rendering the dark watermark to the business code of the application client. The development cost is high, and it is difficult to achieve quick page dark watermark embedding. Summary of the Invention
[0005] This application provides a watermark embedding method. This method enables fast webpage dark watermark embedding without modifying the existing service code of the application server and application client. This application also provides a watermark embedding device, electronic device, computer-readable storage medium, and computer program product corresponding to the above method.
[0006] In a first aspect, the present application provides a watermark embedding method, applied to a load balancer, the method comprising:
[0007] Obtaining a page data file of a first application page sent by the application server;
[0008] Adding a watermark embedding code to the page data file; wherein the watermark embedding code is used to embed a watermark in the first application page;
[0009] The modified page data file is sent to the application client.
[0010] In a second aspect, the present application provides a watermark embedding method, applied to an application client, the method comprising:
[0011] Receiving a page data file of a first application page sent by a load balancer, wherein the page data file includes a watermark embedding code;
[0012] Load the page data file and perform the following steps:
[0013] Determining a target account requesting access to the first application page;
[0014] Taking the target account as an input parameter, executing the watermark embedding code to generate a watermark including the account information of the target account;
[0015] Rendering the first application page, and rendering the watermark including the account information of the target account on the first application page.
[0016] In a third aspect, the present application provides a watermark embedding device, which includes:
[0017] An acquisition module, configured to acquire a page data file of a first application page sent by an application server;
[0018] An adding module, configured to add a watermark embedding code to the page data file; wherein the watermark embedding code is used to embed a watermark in the first application page;
[0019] The communication module is used to send the modified page data file to the application client.
[0020] In a fourth aspect, the present application provides a watermark embedding device, comprising:
[0021] a communication module, configured to receive a page data file of a first application page sent by a load balancer, wherein the page data file includes a watermark embedding code;
[0022] An execution module is used to load the page data file and perform the following steps: determining a target account requesting access to the first application page; using the target account as an input parameter, executing the watermark embedding code to generate a watermark including the account information of the target account; rendering the first application page, and rendering the watermark including the account information of the target account on the first application page.
[0023] In a fifth aspect, the present application provides an electronic device, comprising a processor and a memory. The processor and the memory communicate with each other. The processor is configured to execute instructions stored in the memory to cause the electronic device to perform the watermark embedding method according to the first aspect or any implementation of the first aspect, or to perform the watermark embedding method according to the second aspect or any implementation of the second aspect.
[0024] In a sixth aspect, the present application provides a computer-readable storage medium, in which instructions are stored, and the instructions instruct the electronic device to execute the watermark embedding method described in the first aspect or any one of the implementations of the first aspect, or to execute the watermark embedding method as described in the second aspect or any one of the implementations of the second aspect.
[0025] In the seventh aspect, the present application provides a computer program product comprising instructions, which, when run on an electronic device, enables the electronic device to execute the watermark embedding method described in the first aspect or any one of the implementations of the first aspect, or to execute the watermark embedding method as described in the second aspect or any one of the implementations of the second aspect.
[0026] Based on the implementation methods provided in the above aspects, this application can also be further combined to provide more implementation methods.
[0027] It can be seen from the above technical solutions that this application has the following advantages:
[0028] The present application provides a watermark embedding method, which is applied to a load balancer. The load balancer obtains a page data file of a first application page sent by an application server and adds a watermark embedding code to the page data file, wherein the watermark embedding code is used to embed a watermark in the first application page. Then, the load balancer sends the modified page data file to the application client.
[0029] In this method, considering that the network traffic between the application server and the application client needs to pass through the load balancer, the load balancer is used to write the watermark embedding code in the page data file of the application page. Without modifying the original business code of the application server and the application client, the watermark embedding logic is added to the page data file.
[0030] Correspondingly, the present application also provides a watermark embedding method, which is applied to an application client. The application client receives a page data file of a first application page sent by a load balancer, and the page data file includes a watermark embedding code. Then, the application client loads the page data file and performs the following steps: determining the target account requesting access to the first application page, taking the target account as an input parameter, executing the watermark embedding code, generating a watermark including the account information of the target account, rendering the first application page, and rendering the watermark including the account information of the target account on the first application page.
[0031] In this method, the page data file received by the application client includes watermark embedding logic. In this way, when the application client loads the page data file, it can execute the watermark embedding logic at the same time and embed the watermark in the application page, thereby realizing fast page dark watermark embedding. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] In order to more clearly illustrate the technical methods of the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments.
[0033] Figure 1 A schematic diagram of a process for embedding a dark watermark on a page provided in an embodiment of the present application;
[0034] Figure 2 A schematic diagram of the architecture of an application system provided in an embodiment of the present application;
[0035] Figure 3 A schematic diagram of a watermark embedding method according to an embodiment of the present invention;
[0036] Figure 4 An interactive schematic diagram of a watermark embedding method provided in an embodiment of the present application;
[0037] Figure 5 A schematic diagram of a watermark embedding method according to an embodiment of the present invention;
[0038] Figure 6 A schematic diagram of an information storage process provided in an embodiment of the present application;
[0039] Figure 7 A schematic structural diagram of a watermark embedding device provided in an embodiment of the present application;
[0040] Figure 8 A schematic structural diagram of a watermark embedding device provided in an embodiment of the present application;
[0041] Figure 9 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0042] The terms "first" and "second" in the embodiments of this application are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of technical features indicated. Therefore, features specified as "first" or "second" may explicitly or implicitly include one or more of the features.
[0043] First, some technical terms and application scenarios involved in the embodiments of this application are introduced.
[0044] Information hiding technology refers to the process of encoding, modulating, and encrypting secret information and then embedding it into digital media signals. Digital watermarking technology is a type of information hiding technology, which refers to the process of embedding specific watermark information into the information carrier.
[0045] According to different application scenarios and use purposes, the digital watermark can be classified from different aspects. For example, according to different multimedia contents as information carriers, the digital watermark can be classified into image watermark, video watermark, page watermark and the like. For another example, according to whether the digital watermark is visually visible, the digital watermark can also be classified into visible watermark and invisible watermark.
[0046] In the present application, the embedded digital watermark in the application page and visually invisible is also called page dark watermark.
[0047] In the related art, the embedding of the page dark watermark usually needs the cooperation of the dark watermark server, the application server and the application client. The dark watermark server refers to a server for generating a dark watermark, the application server refers to a server for processing the page access request of the application client and providing a page data file, and the application client refers to a client for accessing the resources of the application server and rendering the application page according to the page data file.
[0048] Specifically, referring to a flowchart of a page dark watermark embedding shown in Figure 1 The dark watermark server generates dark watermarks containing specific identifiers (for example, account identifiers) for different accounts, and sends the dark watermarks to the content delivery network (CDN) storage. The content delivery network usually refers to a distributed network composed of edge node server groups distributed in different regions.
[0049] The user sends an application page request to the application server through the application client, the application server carries an account identifier, calls the dark watermark server, the dark watermark server returns the address of the dark watermark to the application server, for example, the uniform resource location (URL) of the dark watermark. The application server sends the address of the dark watermark to the application client, and the application client finds the corresponding dark watermark in the content delivery network according to the address of the dark watermark, and renders the dark watermark when rendering the application page.
[0050] The above method can realize the embedding of the page dark watermark. When the user uses the application client to browse the application page, if the application page screenshot operation is performed, the hidden dark watermark is contained in the screenshot, and the purpose of screenshot tracing is achieved.
[0051] However, the above method needs to modify the business code of the application server and the application client, increase the code related to obtaining the address of the watermark and sending the address of the watermark in the business code of the application server, and increase the code related to rendering the watermark in the business code of the application client, which has a large development cost and is difficult to achieve quick page watermark embedding.
[0052] Therefore, the present application provides a watermark embedding method, which is applied to a load balancer. The load balancer obtains a page data file of a first application page sent by an application server, and adds watermark embedding code in the page data file, where the watermark embedding code is used to embed a watermark in the first application page. Then, the load balancer sends the modified page data file to an application client.
[0053] In the method, considering that the network traffic between the application server and the application client needs to pass through the load balancer, the watermark embedding code is written in the page data file of the application page by using the load balancer, and the watermark embedding logic is added in the page data file without modifying the original business code of the application server and the application client.
[0054] Correspondingly, the present application also provides a watermark embedding method, which is applied to an application client. The application client receives a page data file of a first application page sent by a load balancer, and the page data file includes watermark embedding code. Then, the application client loads the page data file and executes the following steps: determining a target account requesting to access the first application page, taking the target account as an input parameter, executing the watermark embedding code, generating a watermark including account information of the target account, rendering the first application page, and rendering the watermark including the account information of the target account on the first application page.
[0055] In the method, the page data file received by the application client includes watermark embedding logic. Thus, when the application client loads the page data file, the watermark embedding logic can be executed together to embed the watermark in the application page, thereby achieving quick page watermark embedding.
[0056] In order to facilitate understanding of the technical solutions provided by the embodiments of the present application, the following will be described with reference to the accompanying drawings.
[0057] Referring to Figure 2 An application system architecture diagram provided by the embodiments of the present application is shown in FIG. 1. The application system 20 includes an application client 21, a load balancer 22, and an application server 23, which will be described in detail below.
[0058] Application system 20 provides applications and employs an architecture consisting of an application client 21 and an application server 23. Application client 21 is used to access resources on the application server. Application client 21 receives page data files from application server 23 and, based on these files, renders application pages with which users can interact. Application server 23 processes application page access requests from application clients. Application server 23 can receive application page access requests from application client 21 and return page data files to application client 21.
[0059] The load balancer 22 is located between the application client 21 and the application server 23. It is used to receive network traffic (such as application page access requests) sent by the application client 21, distribute the network traffic to one of the multiple servers in the application server 23, collect responses returned by the application server 23, and send the responses to the application client 21. By distributing network traffic among multiple servers in the application server 23 through the load balancer 22, overload of multiple servers in the application server 23 due to excessive network traffic is avoided, thereby improving the reliability and availability of the application system 20.
[0060] The load balancer 22 may have different manifestations. For example, the load balancer 22 may be a hardware device, or, in a cloud environment, the load balancer 22 may also provide load balancing services in the form of cloud services.
[0061] In some embodiments, application system 20 can provide a website (Web) application, which is provided by using Web technology. Web applications provide services over the Internet, allowing users to access them through a website client without having to install specific software on their local computing devices. These applications have excellent applicability and are widely used in various applications, such as e-commerce services and email services. In this case, application client 21 can be a Web browser, and application server 23 can be a Web server.
[0062] In other embodiments, the application system 20 may also provide mobile applications or desktop applications. Mobile applications generally refer to applications designed for mobile devices such as smartphones and tablets, while desktop applications generally refer to applications designed for personal computers (PCs). In this case, the application client 21 may be an application (APP) running on a mobile device or a personal computer, i.e., the application client 21 may be a client of a mobile application or a desktop application, and the application server 23 may be a server that provides the APP, i.e., the application server 23 is a server of a mobile application or a desktop application.
[0063] See also Figure 3The flowchart of a watermark embedding method provided by an embodiment of the present application is shown. The method can be applied to the load balancer 22. The method specifically includes:
[0064] S301 : The load balancer 22 obtains the page data file of the first application page sent by the application server 23 .
[0065] The first application page can be understood as any application page that requires watermark embedding. When the application system 20 provides a web application, the first application page can be any web page that requires watermark embedding. When the application system 20 provides a mobile application or desktop application, the first application page can be any app page that requires watermark embedding.
[0066] The first application page may be different in different application scenarios. For example, when the application system 20 provides e-commerce services, the first application page may be a product search page, an order page, etc. For another example, when the application system 20 provides email services, the first application page may be an inbox page, an email sending page, etc.
[0067] The page data file can be understood as a data file used to create and design application pages. When the application system 20 provides a Web application, the page data file can be a hypertext markup language (HTML) file. The HTML file defines the structure and content of the web page. The Web client can learn how to display multimedia data on the web page, such as text, pictures, links, videos, etc. by loading the HTML file. Typically, an HTML file consists of a series of elements (also called tags), and the elements can be wrapped in "<>". For example, denotes a paragraph, indicates a link, indicates a picture.
[0068] In the embodiments of the present application, the page data file of the first application page can define the structure and content of the first application page, and is used to create the first application page. That is, the application client 21 can load the page data file of the first application page to render the first application page.
[0069] In a specific implementation, the user can trigger a viewing operation of the first application page in the application client 21. In response to the viewing operation of the first application page, the application client 21 generates an application page access request of the first application page, and sends the application page access request of the first application page to the load balancer 22. The load balancer 22 sends the application page access request of the first application page to the application server 23 (for example, one of the plurality of servers in the application server 23). The application server 23 (for example, one of the plurality of servers in the application server 23) processes the application page access request of the first application page, returns network traffic of the first application (which can also be referred to as an application page access response) to the load balancer 22, and the network traffic of the first application includes the page data file of the first application page.
[0070] Considering that the network traffic usually involves multiple types and formats, the load balancer 22 can determine the page data file by analyzing the network traffic. Specifically, when the application server 23 is a Web server and the application client 21 is a Web client, the page data file is an HTML file. The load balancer 22 receives the network traffic of the first application page sent by the Web server, and then analyzes the network traffic to determine the file with a file suffix markup language and / or the file in a text format in the network traffic as an HTML file.
[0071] That is, when the application system 20 provides a Web application, the load balancer 22 can detect the format of the network traffic related to the first application page, and extract the HTML file of the first application page from the network traffic of the first application page by identifying the.html suffix or identifying the text format.
[0072] S302: The load balancer 22 adds a watermark embedding code in the page data file.
[0073] In the embodiments of the present application, after the load balancer 22 extracts the page data file of the first application page, the watermark embedding code can be added in the page data file. The watermark embedding code can be used to embed a watermark in the first application page, in other words, the watermark embedding code provides the execution logic of embedding a steganographic watermark in the first application page.
[0074] In a specific implementation, considering that the embedded watermark in the first application page should be related to the target account requesting to access the first application page, i.e., the embedded watermark in the first application page should represent the identity of the target account requesting to access the first application page, therefore, the input parameter of the watermark embedding code can include the target account requesting to access the first application page, and the watermark embedding code can include code indicating to generate a watermark including account information of the target account. In this way, the embedded watermark representing the target account in the first application page is implemented.
[0075] In some possible implementations, the application server 23 is a Web server, the application client 21 is a Web client, and the page data file is an HTML file. In this case, the load balancer 22 can add the watermark embedding code in a head element of the HTML file.
[0076] In this case, the HTML file can specifically include a head element (denoted as element) and a body element (denoted as element), the head element can include metadata of the first application page, for example, a <title> Tags, linking to external cascading style sheets (CSS)< / title> <link> tag, a <script>标签等,主体元素中可以包括第一应用页面的页面数据。
[0077] 在本申请实施例中,当应用系统20提供Web应用时,在第一应用页面的HTML文件的头元素中添加水印嵌入代码,如此,将水印嵌入代码作为第一应用页面的元数据提供给应用客户端21。
[0078] 在一些实施例中,水印嵌入代码可以以如下形式提供:
[0079]
[0080] 其中,"src=https: / / [Hidden Watermark script].js”用于引入一段JS脚本,JS脚本中包括用于在第一应用页面中嵌入水印的水印嵌入代码,"HiddenWatermarkFunc("[User Info Path]","UserID"”用于执行JS脚本。也就是说,JS脚本中包括HiddenWatermarkFunc函数,通过在HTML文件中添加"HiddenWatermarkFunc("[User InfoPath]","UserID"”,能够调用JS脚本中的HiddenWatermarkFunc函数,实现水印嵌入逻辑。
[0081] S303:负载均衡器22将修改后的页面数据文件发送至应用客户端21。
[0082] 在负载均衡器22完成水印嵌入代码的添加后,可以将修改后、包括水印嵌入代码的页面数据文件发送至应用客户端21。如此,应用客户端21在加载页面数据文件时,能够一并执行水印嵌入逻辑。
[0083] 参见图4所示的一种水印嵌入方法的交互示意图,当应用系统20提供Web应用时,应用客户端21向负载均衡器22发送第一应用页面的应用页面访问请求,负载均衡器22基于负载均衡算法,将第一应用页面的应用页面访问请求发送至应用客户端23,应用客户端23处理第一应用页面的应用页面访问请求,生成第一应用页面的网络流量,并将第一应用页面的网络流量返回至负载均衡器22。
[0084] 负载均衡器22解析第一应用页面的网络流量,识别出HTML文件。针对除HTML文件以外的其他网络流量,负载均衡器22直接发送至应用客户端21,针对HTML文件,负载均衡器22对HTML文件进行修改,在第一应用页面的HTML文件中添加水印嵌入代码,并将修改后的第一应用页面的HTML文件发送至应用客户端21。
[0085] 如此,在不改变原有的应用客户端、负载均衡器和应用服务端之间通信流程的基础上,利用负载均衡器,在应用页面的页面数据文件中写入水印嵌入代码,无需修改应用服务端和应用客户端的原有业务代码,在页面数据文件中增加水印嵌入逻辑。
[0086] 前文针对负载均衡器22实现水印嵌入的过程进行了介绍,下面将针对应用客户端进行水印嵌入的过程进行说明。参见图5所示的本申请实施例提供的一种水印嵌入方法的流程示意图,该方法可以应用于应用客户端21,该方法具体包括:
[0087] S501:应用客户端21接收负载均衡器22发送的第一应用页面的页面数据文件。
[0088] 在应用客户端21发送第一应用页面的应用页面访问请求后,通过应用服务端23处理第一应用页面的应用页面访问请求,可以生成第一应用页面的页面数据文件。在本申请实施例中,第一应用页面的页面数据文件中包括水印嵌入代码,换言之,第一应用页面的页面数据文件中具有负载均衡器22添加的水印嵌入逻辑。
[0089] S502:应用客户端21加载页面数据文件,执行以下步骤:确定请求访问第一应用页面的目标账户,将目标账户作为输入参数,执行水印嵌入代码,生成包括目标账户的账户信息的水印,渲染第一应用页面,在第一应用页面上,渲染包括目标账户的账户信息的水印。
[0090] 由于第一应用页面的页面数据文件中定义有第一应用页面的结构和内容,因此,应用客户端21加载页面数据文件,能够渲染第一应用页面。
[0091] 在本申请实施例中,第一应用页面的页面数据文件中包括水印嵌入代码,当应用客户端21加载页面数据文件时,执行水印嵌入代码,一并渲染水印,实现在第一应用页面中嵌入水印的目的。
[0092] 其中,水印可以以暗水印图片的形式呈现,换言之,应用客户端21可以在第一应用页面上叠加渲染暗水印图片,以在第一应用页面上嵌入暗水印图片。
[0093] 第一应用页面嵌入的水印中应当表征用户身份,因此,应用客户端21需要确定请求访问第一应用页面的目标账户,进而生成包括目标账户的账户信息的水印。如此,当用户针对第一应用页面执行截图操作时,第一应用页面的截图中包括目标账户的账户信息,通过第一应用页面的截图,能够获取截图者的身份信息,实现截图溯源的目的。
[0094] 在一些可能的实现方式中,应用客户端21中存储有标识目标账户的信息。具体地,应用客户端21可以获取标识目标账户的信息,并根据标识目标账户的信息,确定请求访问第一应用页面的目标账户。
[0095] 当应用系统20提供Web应用时,应用客户端21可以在cookie中存储标识目标账户的信息,换言之,应用客户端21可以从cookie中获取标识目标账户的信息。其中,cookie可理解为应用服务端23发送至应用客户端21,并存储在应用客户端21中的数据片段,用于存储与应用客户端21相关的数据。
[0096] 每个cookie可以由一个或多个名称-值的键值对形式组成,也就是说,标识目标账户的信息可以以标识目标账户的字段与标识目标账户的字段值组成的键值对的形式存储。在此情况下,应用客户端21可以获取标识目标账户的字段,接着,根据标识目标账户的字段,确定标识目标账户的字段值。
[0097] 如此,应用客户端21在cookie中查找标识目标账户的字段(例如是UID字段),并提取标识目标账户的字段的字段值,进而确定标识目标账户的信息。
[0098] 在另一些可能的实现方式中,应用客户端21中未存储标识目标账户的信息,应用客户端21无法直接获取标识目标账户的信息。具体地,响应于标识目标账户的信息为空,应用客户端21可以获取账户路径信息,并根据账户路径信息,确定请求访问第一应用页面的目标账户。
[0099] 其中,账户路径信息可理解为用于存储账户信息的路径,通常情况下,账户路径信息可以由应用系统20提供的应用维护。也就是说,当应用客户端21中未直接存储标识目标账户的信息时,应用客户端21可以通过查找账户路径信息,从账户路径信息中提取标识目标账户的信息,进而确定请求访问第一应用页面的目标账户。
[0100] 本申请实施例对于账户路径信息的形式不作限制。在一些实施例中,账户路径信息可以为文件系统路径,即,账户路径信息可以指示一个文件路径。在另一些实施例中,账户路径信息也可以为数据库记录路径,即,账户路径信息可以指示数据库中的一个表路径。在又一些实施例中,账户路径信息也可以指示应用程序编程接口(applicationprogramming interface,API)端点,通过API端点,能够获取标识目标账户的信息。
[0101] 在该方法中,应用客户端接收到的页面数据文件中包括水印嵌入逻辑,如此,应用客户端在加载页面数据文件时,能够一并执行水印嵌入逻辑,将水印嵌入在应用页面中,实现快捷的页面暗水印嵌入。
[0102] 基于前述内容可知,标识目标账户的信息可以存储在应用客户端21中。在一些实施例中,应用客户端21中标识目标账户的信息可以由应用系统20提供的应用维护,换言之,在应用系统20提供的应用的实际业务处理过程中,将标识目标账户的信息写入应用客户端21中。
[0103] 在另一些实施例中,应用系统20提供的应用也可以集成身份认证服务,身份认证服务可以由身份认证服务端提供,例如,身份认证服务可以为单点登录(singlesignon,SSO)服务,借助身份认证服务的身份认证过程,将标识目标账户的信息写入应用客户端21中。
[0104] 具体实现时,参见图6所示的一种信息存储流程的示意图,应用客户端21发送第一应用页面的应用页面访问请求,负载均衡器22将第一应用页面的应用页面访问请求转发至应用服务端23。应用服务端23判断请求访问第一应用页面的目标账户是否通过身份认证,响应于目标账户未通过身份认证,应用服务端23返回表征身份认证未通过的响应,负载均衡器22将表征身份认证未通过的响应转发至应用客户端21。
[0105] 接着,应用客户端21可以请求进行身份认证。具体地,负载均衡器22获取应用客户端21发送的身份认证跳转请求,并将身份认证跳转请求发送至身份认证服务端24,负载均衡器22接收身份认证服务端24返回的身份认证跳转响应,并将身份认证跳转响应发送至应用客户端21。
[0106] 其中,身份认证跳转请求可以为页面重定向跳转的形式,换言之,当负载均衡器22接收到身份认证跳转请求时,可以跳转至身份认证服务端24,进行身份认证流程。
[0107] 身份认证跳转响应可理解为由身份认证服务端24生成的、用于请求获取与身份认证相关信息的响应,例如,身份认证跳转响应中可以包括应用系统20提供的应用的业务参数。在本申请实施例中,身份认证跳转响应中可以包括账户获取信息,该账户获取信息用于获取标识目标账户的信息。也就是说,在本申请实施例中,在原有的身份认证跳转响应中,新增账户获取信息,以便在身份认证流程中,一并请求获取标识目标账户的信息。例如,账户获取信息可以为标识目标账户的字段。
[0108] 应用客户端21在接收到身份认证跳转响应后,用户可以通过应用客户端21填写身份认证跳转响应中与身份认证相关的信息,生成身份认证请求。负载均衡器22获取应用客户端21发送的身份认证请求,并将身份认证请求发送至身份认证服务端24,负载均衡器22接收身份认证服务端发送的身份认证响应,并将身份认证响应发送至应用客户端21。
[0109] 其中,负载均衡器22可以通过应用服务端23将身份认证请求发送至身份认证服务端24,类似地,负载均衡器22也可以通过应用服务端23将身份认证响应发送至应用客户端21。
[0110] 进一步地,由于本申请实施例中,身份认证跳转请求中包括账户获取信息,因此,应用客户端21生成的身份认证请求中包括标识目标账户的信息。身份认证服务端24校验身份认证请求,生成的身份认证响应中也携带有标识目标账户的信息,该标识目标账户的信息用于在身份认证响应表征身份认证通过的情况下,存储在应用客户端21中。
[0111] 应用客户端21获取负载均衡器22发送的身份认证跳转响应,响应于身份认证跳转响应表征身份认证通过,应用客户端21从身份认证跳转响应中提取标识目标账户的信息,并存储标识目标账户的信息。
[0112] 在一些可能的实现方式中,身份认证跳转响应中可以包括"set-cookie”函数,在身份认证通过时,应用客户端21提取标识目标账户的信息(例如是提取标识目标账户的字段值),执行"set-cookie”函数,将标识目标账户的字段与标识目标账户的字段值组成的键值对存储在cookie中。
[0113] 也就是说,通过在身份认证跳转响应中新增账户获取信息,在身份认证流程中,携带有标识目标账户的信息。如此,在加载页面数据文件,获取目标账户作为输入参数时,应用客户端能够直接获取到标识目标账户的信息,快速部署页面暗水印。
[0114] 上文结合图1至图6对本申请实施例提供的水印嵌入方法进行了详细介绍,下面将结合附图对本申请实施例提供的装置、设备进行介绍。
[0115] 参见图7所示的水印嵌入装置的结构示意图,该装置70包括:
[0116] 获取模块701,用于获取应用服务端发送的第一应用页面的页面数据文件;
[0117] 添加模块702,用于在所述页面数据文件中,添加水印嵌入代码;其中,所述水印嵌入代码用于在所述第一应用页面中嵌入水印;
[0118] 通信模块703,用于将修改后的所述页面数据文件发送至应用客户端。
[0119] 在一些可能的实现方式中,所述应用服务端为网站服务端,所述应用客户端为网站客户端;或者,所述应用服务端为移动应用或桌面应用的服务端,所述应用客户端为移动应用或桌面应用的客户端。
[0120] 在一些可能的实现方式中,所述水印嵌入代码的输入参数包括请求访问所述第一应用页面的目标账户,所述水印嵌入代码包括:指示生成包括所述目标账户的账户信息的水印的代码。
[0121] 在一些可能的实现方式中,所述应用服务端为网站服务端,所述应用客户端为网站客户端,所述页面数据文件为超文本标记语言HTML文件;所述获取模块701具体用于:
[0122] 接收所述网站服务端发送的第一应用页面的网络流量;
[0123] 解析所述网络流量,将所述网络流量中文件后缀表征标记语言的文件和 / 或所述网络流量中文本格式的文件,确定为所述HTML文件。
[0124] 在一些可能的实现方式中,所述应用服务端为网站服务端,所述应用客户端为网站客户端,所述页面数据文件为超文本标记语言HTML文件;所述添加模块702具体用于:
[0125] 在所述HTML文件的头元素中,添加水印嵌入代码。
[0126] 在一些可能的实现方式中,所述装置70还包括身份认证模块,所述身份认证模块用于:
[0127] 获取所述应用客户端发送的身份认证请求,将所述身份认证请求发送至身份认证服务端;
[0128] 接收所述身份认证服务端发送的身份认证响应,将所述身份认证响应发送至所述应用客户端;
[0129] 其中,所述身份认证响应中携带有标识所述目标账户的信息,所述标识目标账户的信息用于在所述身份认证响应表征身份认证通过的情况下,存储在所述应用客户端中。
[0130] 在一些可能的实现方式中,所述身份认证模块还用于:
[0131] 获取所述应用客户端发送的身份认证跳转请求;
[0132] 将所述身份认证跳转请求发送至身份认证服务端,接收所述身份认证服务端返回的身份认证跳转响应;其中,所述身份认证跳转响应中包括账户获取信息,所述账户获取信息用于获取标识目标账户的信息;
[0133] 将所述身份认证跳转响应发送至所述应用客户端。
[0134] 根据本申请实施例的水印嵌入装置70可对应于执行本申请实施例中描述的方法,并且水印嵌入装置70的各个模块 / 单元的上述和其它操作和 / 或功能分别为了实现图3所示实施例中的各个方法的相应流程,为了简洁,在此不再赘述。
[0135] 参见图8所示的水印嵌入装置的结构示意图,该装置80包括:
[0136] 通信模块801,用于接收负载均衡器发送的第一应用页面的页面数据文件,所述页面数据文件中包括水印嵌入代码;
[0137] 执行模块802,用于加载所述页面数据文件,执行以下步骤:确定请求访问所述第一应用页面的目标账户;将所述目标账户作为输入参数,执行所述水印嵌入代码,生成包括所述目标账户的账户信息的水印;渲染所述第一应用页面,并在所述第一应用页面上,渲染所述包括所述目标账户的账户信息的水印。
[0138] 在一些可能的实现方式中,所述执行模块802具体用于:
[0139] 获取标识目标账户的信息;
[0140] 根据所述标识目标账户的信息,确定请求访问所述第一应用页面的目标账户。
[0141] 在一些可能的实现方式中,所述标识目标账户的信息以标识目标账户的字段与标识目标账户的字段值组成的键值对的形式存储,所述执行模块802具体用于:
[0142] 获取所述标识目标账户的字段;
[0143] 根据所述标识目标账户的字段,确定所述标识目标账户的字段值。
[0144] 在一些可能的实现方式中,所述执行模块802具体用于:
[0145] 响应于所述标识目标账户的信息为空,获取账户路径信息;
[0146] 根据所述账户路径信息,确定请求访问所述第一应用页面的目标账户。
[0147] 在一些可能的实现方式中,所述执行模块802具体用于:
[0148] 获取所述负载均衡器发送的身份认证跳转响应,所述身份认证跳转响应由身份认证服务端生成;
[0149] 响应于所述身份认证跳转响应表征身份认证通过,从所述身份认证跳转响应中提取标识目标账户的信息,并存储所述标识目标账户的信息。
[0150] 根据本申请实施例的水印嵌入装置80可对应于执行本申请实施例中描述的方法,并且水印嵌入装置80的各个模块 / 单元的上述和其它操作和 / 或功能分别为了实现图5所示实施例中的各个方法的相应流程,为了简洁,在此不再赘述。
[0151] 本申请实施例还提供了一种电子设备。该电子设备具体用于实现如图7所示实施例中水印嵌入装置70的功能,或者用于实现如图8所示实施例中水印嵌入装置80的功能。
[0152] 图9提供了一种电子设备900的结构示意图,如图9所示,电子设备900包括总线901、处理器902、通信接口903和存储器904。处理器902、存储器904和通信接口903之间通过总线901通信。
[0153] 总线901可以是外设部件互连标准(peripheral component interconnect,PCI)总线或扩展工业标准结构(extended industry standard architecture,EISA)总线等。总线可以分为地址总线、数据总线、控制总线等。为便于表示,图9中仅用一条粗线表示,但并不表示仅有一根总线或一种类型的总线。
[0154] 处理器902可以为中央处理器(central processing unit,CPU)、图形处理器(graphics processing unit,GPU)、微处理器(micro processor,MP)或者数字信号处理器(digital signal processor,DSP)等处理器中的任意一种或多种。
[0155] 通信接口903用于和外部通信。例如,通信接口903可以用于和终端通信。
[0156] 存储器904可以包括易失性存储器(volatile memory),例如随机存取存储器(random access memory,RAM)。存储器904还可以包括非易失性存储器(non-volatilememory),例如只读存储器(read-only memory,ROM),快闪存储器,硬盘驱动器(hard diskdrive,HDD)或固态驱动器(solid state drive,SSD)。
[0157] 存储器904中存储有可执行代码,处理器902执行该可执行代码以执行前述水印嵌入方法。
[0158] 具体地,在实现图7所示实施例的情况下,且图7实施例中所描述的水印嵌入装置70的各模块或单元为通过软件实现的情况下,执行图7中的各模块 / 单元功能所需的软件或程序代码可以部分或全部存储在存储器904中。处理器902执行存储器904中存储的各单元对应的程序代码,执行前述水印嵌入方法。
[0159] 类似地,在实现图8所示实施例的情况下,且图8实施例中所描述的水印嵌入装置80的各模块或单元为通过软件实现的情况下,执行图8中的各模块 / 单元功能所需的软件或程序代码可以部分或全部存储在存储器904中。处理器902执行存储器904中存储的各单元对应的程序代码,执行前述水印嵌入方法。
[0160] 本申请实施例还提供了一种计算机可读存储介质。所述计算机可读存储介质可以是计算设备能够存储的任何可用介质或者是包含一个或多个可用介质的数据中心等数据存储设备。所述可用介质可以是磁性介质(例如软盘、硬盘、磁带)、光介质(例如DVD)、或者半导体介质(例如固态硬盘)等。该计算机可读存储介质包括指令,所述指令指示计算设备执行上述应用于水印嵌入装置70或水印嵌入装置80的水印嵌入方法。
[0161] 本申请实施例还提供了一种计算机程序产品,所述计算机程序产品包括一个或多个计算机指令。在计算设备上加载和执行所述计算机指令时,全部或部分地产生按照本申请实施例所述的流程或功能。
[0162] 所述计算机指令可以存储在计算机可读存储介质中,或者从一个计算机可读存储介质向另一计算机可读存储介质传输,例如,所述计算机指令可以从一个网站站点、计算机或数据中心通过有线(例如同轴电缆、光纤、数字用户线(DSL))或无线(例如红外、无线、微波等)方式向另一个网站站点、计算机或数据中心进行传输。
[0163] 所述计算机程序产品被计算机执行时,所述计算机执行前述水印嵌入方法的任一方法。该计算机程序产品可以为一个软件安装包,在需要使用前述水印嵌入方法的任一方法的情况下,可以下载该计算机程序产品并在计算机上执行该计算机程序产品。
[0164] 附图中的流程图和框图,图示了按照本申请各个实施例的系统、方法和计算机程序产品的可能实现的体系架构、功能和操作。在这点上,流程图或框图中的每个方框可以代表一个模块、程序段、或代码的一部分,该模块、程序段、或代码的一部分包含一个或多个用于实现规定的逻辑功能的可执行指令。也应当注意,在有些作为替换的实现中,方框中所标注的功能也可以以不同于附图中所标注的顺序发生。例如,两个接连地表示的方框实际上可以基本并行地执行,它们有时也可以按相反的顺序执行,这依所涉及的功能而定。也要注意的是,框图和 / 或流程图中的每个方框、以及框图和 / 或流程图中的方框的组合,可以用执行规定的功能或操作的专用的基于硬件的系统来实现,或者可以用专用硬件与计算机指令的组合来实现。
[0165] 描述于本申请实施例中所涉及到的单元可以通过软件的方式实现,也可以通过硬件的方式来实现。其中,单元 / 模块的名称在某种情况下并不构成对该单元本身的限定。
[0166] 本文中以上描述的功能可以至少部分地由一个或多个硬件逻辑部件来执行。例如,非限制性地,可以使用的示范类型的硬件逻辑部件包括:现场可编程门阵列(FPGA)、专用集成电路(ASIC)、专用标准产品(ASSP)、片上系统(SOC)、复杂可编程逻辑设备(CPLD)等等。
[0167] 在本申请实施例的上下文中,机器可读介质可以是有形的介质,其可以包含或存储以供指令执行系统、装置或设备使用或与指令执行系统、装置或设备结合地使用的程序。机器可读介质可以是机器可读信号介质或机器可读储存介质。机器可读介质可以包括但不限于电子的、磁性的、光学的、电磁的、红外的、或半导体系统、装置或设备,或者上述内容的任何合适组合。机器可读存储介质的更具体示例会包括基于一个或多个线的电气连接、便携式计算机盘、硬盘、随机存取存储器(RAM)、只读存储器(ROM)、可擦除可编程只读存储器(EPROM或快闪存储器)、光纤、便捷式紧凑盘只读存储器(CD-ROM)、光学储存设备、磁储存设备、或上述内容的任何合适组合。
[0168] 需要说明的是,本说明书中各个实施例采用递进的方式描述,每个实施例重点说明的都是与其他实施例的不同之处,各个实施例之间相同相似部分互相参见即可。对于实施例公开的系统或装置而言,由于其与实施例公开的方法相对应,所以描述的比较简单,相关之处参见方法部分说明即可。
[0169] 应当理解,在本申请中,"至少一个(项)”是指一个或者多个,"多个”是指两个或两个以上。"和 / 或”,用于描述关联对象的关联关系,表示可以存在三种关系,例如,"A和 / 或B”可以表示:只存在A,只存在B以及同时存在A和B三种情况,其中A,B可以是单数或者复数。字符" / ”一般表示前后关联对象是一种"或”的关系。"以下至少一项(个)”或其类似表达,是指这些项中的任意组合,包括单项(个)或复数项(个)的任意组合。例如,a,b或c中的至少一项(个),可以表示:a,b,c,"a和b”,"a和c”,"b和c”,或"a和b和c”,其中a,b,c可以是单个,也可以是多个。
[0170] 还需要说明的是,在本文中,诸如第一和第二等之类的关系术语仅仅用来将一个实体或者操作与另一个实体或操作区分开来,而不一定要求或者暗示这些实体或操作之间存在任何这种实际的关系或者顺序。而且,术语"包括”、"包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者设备不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者设备所固有的要素。在没有更多限制的情况下,由语句"包括一个……”限定的要素,并不排除在包括所述要素的过程、方法、物品或者设备中还存在另外的相同要素。
[0171] 结合本文中所公开的实施例描述的方法或算法的步骤可以直接用硬件、处理器执行的软件模块,或者二者的结合来实施。软件模块可以置于随机存储器(RAM)、内存、只读存储器(ROM)、电可编程ROM、电可擦除可编程ROM、寄存器、硬盘、可移动磁盘、CD-ROM、或技术领域内所公知的任意其它形式的存储介质中。
[0172] 对所公开的实施例的上述说明,使本领域专业技术人员能够实现或使用本申请。对这些实施例的多种修改对本领域的专业技术人员来说将是显而易见的,本文中所定义的一般原理可以在不脱离本申请的精神或范围的情况下,在其它实施例中实现。因此,本申请将不会被限制于本文所示的这些实施例,而是要符合与本文所公开的原理和新颖特点相一致的最宽的范围。< / script>
Claims
1. A watermark embedding method, characterized in that: Applied to a load balancer, the method includes: Obtaining a page data file of a first application page sent by the application server; Adding a watermark embedding code to the page data file; wherein the watermark embedding code is used to embed a watermark in the first application page; Sending the modified page data file to the application client; When the application server is a website server, the application client is a website client, and the page data file is a Hypertext Markup Language (HTML) file, obtaining the page data file of the first application page sent by the application server includes: Receiving network traffic of a first application page sent by the website server; parsing the network traffic, and determining files in the network traffic that have file suffixes representing markup languages and / or files in text format in the network traffic as the HTML files; Adding a watermark embedding code to the page data file includes: A watermark embedding code is added to the head element of the HTML file; the input parameters of the watermark embedding code include the target account requesting access to the first application page, and the watermark embedding code includes: code instructing the application client to generate a watermark including the account information of the target account.
2. The method according to claim 1, characterized in that When the application server is a server of a mobile application or a desktop application, and the application client is a client of a mobile application or a desktop application, the method further includes: Obtaining an identity authentication request sent by the application client, and sending the identity authentication request to an identity authentication server; receiving an identity authentication response from the identity authentication server, and sending the identity authentication response to the application client; The identity authentication response carries information identifying the target account, and the information identifying the target account is used to be stored in the application client when the identity authentication response indicates that the identity authentication is successful.
3. The method according to claim 2, characterized in that Before obtaining the identity authentication request sent by the application client, the method further includes: Obtaining an identity authentication jump request sent by the application client; Sending the identity authentication jump request to the identity authentication server, and receiving an identity authentication jump response returned by the identity authentication server; wherein the identity authentication jump response includes account acquisition information, and the account acquisition information is used to obtain information identifying the target account; The identity authentication jump response is sent to the application client.
4. A watermark embedding method, characterized in that: Applied to an application client, the method includes: Receive a page data file of a first application page sent by a load balancer, the page data file including a watermark embedding code; the input parameter of the watermark embedding code includes a target account requesting access to the first application page, and the watermark embedding code includes: code instructing the application client to generate a watermark including account information of the target account; the load balancer is configured to, when the application server is a website server and the page data file is a Hypertext Markup Language (HTML) file, receive network traffic for the first application page sent by the website server, parse the network traffic, and determine that files with a file suffix representing a markup language and / or files in a text format in the network traffic are the HTML files; the load balancer is further configured to add the watermark embedding code to a header element of the HTML file; Load the page data file and perform the following steps: Determining a target account requesting access to the first application page; Taking the target account as an input parameter, executing the watermark embedding code to generate a watermark including the account information of the target account; The first application page is rendered, and the watermark including the account information of the target account is rendered on the first application page.
5. The method according to claim 4, characterized in that Determining the target account requesting access to the first application page includes: Obtain information identifying the target account; The target account requesting access to the first application page is determined based on the information identifying the target account.
6. The method according to claim 5, characterized in that The information identifying the target account is stored in the form of a key-value pair consisting of a field identifying the target account and a field value identifying the target account. Acquiring the information identifying the target account includes: Obtain the field identifying the target account; According to the field identifying the target account, a value of the field identifying the target account is determined.
7. The method according to claim 5, characterized in that The method further comprises: In response to the information identifying the target account being empty, acquiring account path information; Determine a target account requesting access to the first application page based on the account path information.
8. The method according to claim 5, characterized in that The obtaining of information identifying the target account includes: Obtaining an identity authentication jump response sent by the load balancer, where the identity authentication jump response is generated by the identity authentication server; In response to the identity authentication jump response indicating that the identity authentication is successful, information identifying the target account is extracted from the identity authentication jump response, and the information identifying the target account is stored.
9. A watermark embedding device, characterized in that: The device comprises: An acquisition module, configured to acquire a page data file of a first application page sent by an application server; An adding module, configured to add a watermark embedding code to the page data file; wherein the watermark embedding code is used to embed a watermark in the first application page; A communication module, configured to send the modified page data file to an application client; The acquisition module is specifically used for: When the application server is a website server, the application client is a website client, and the page data file is a Hypertext Markup Language HTML file, receiving network traffic of a first application page sent by the website server; Parsing the network traffic, and determining files in the network traffic whose file suffixes represent markup languages and / or files in text format in the network traffic as the HTML files; The adding module is specifically used for: A watermark embedding code is added to the head element of the HTML file; the input parameters of the watermark embedding code include the target account requesting access to the first application page, and the watermark embedding code includes: code instructing the application client to generate a watermark including the account information of the target account.
10. A watermark embedding device, characterized in that: The device comprises: The communication module is configured to receive a page data file of a first application page sent by a load balancer, the page data file including a watermark embedding code; the input parameter of the watermark embedding code including a target account requesting access to the first application page, the watermark embedding code including code instructing the application client to generate a watermark including account information of the target account; the load balancer is configured to, when the application server is a website server and the page data file is a Hypertext Markup Language (HTML) file, receive network traffic for the first application page sent by the website server, parse the network traffic, and determine that files with a file suffix representing a markup language and / or files in a text format in the network traffic are the HTML files; the load balancer is further configured to add the watermark embedding code to a header element of the HTML file; An execution module is used to load the page data file and perform the following steps: determining a target account requesting access to the first application page; using the target account as an input parameter, executing the watermark embedding code to generate a watermark including the account information of the target account; rendering the first application page, and rendering the watermark including the account information of the target account on the first application page.
11. An electronic device, characterized in that: The electronic device includes a processor and a memory; The processor is configured to execute instructions stored in the memory, so that the electronic device executes the method according to any one of claims 1 to 3, or executes the method according to any one of claims 4 to 8.
12. A computer-readable storage medium, characterized in that The method comprises instructions, wherein the instructions instruct an electronic device to execute the method according to any one of claims 1 to 3, or execute the method according to any one of claims 4 to 8.
13. A computer program product, characterized in that The computer program product comprises computer-readable instructions, and the computer-readable instructions are used to implement the method according to any one of claims 1 to 3, or to execute the method according to any one of claims 4 to 8.
Citation Information
Patent Citations
Method and device for generating watermark in webpage, client and server
CN110276175A
Watermark information adding method, server and system
CN111177664A