Media data transmission method, device and system
By embedding digital watermarks in the media data, and verifying the authenticity and integrity of the media data using signature values, the problem of difficulty in preventing man-in-the-middle attacks in the prior art is solved, and the secure transmission and real-time nature of the media data are achieved.
Patent Information
- Application Number
- CN202311626620.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-29
- Publication Date
- 2025-05-30
AI Technical Summary
When the prior art realizes the security of data transmission, it is difficult to effectively prevent man-in-the-middle attacks, especially under the end-to-end encryption mechanism, data transmission still has security risks.
By embedding digital watermarks in the media data, the digital watermark includes the signature value obtained by the sending end using the target key to sign the authentication message. The signature value is used to verify the authenticity and integrity of the media data, and realize end-to-end identity authentication of the media data.
This solution can effectively prevent man-in-the-middle attacks, ensure the secure transmission of media data between the two parties in the communication, and maintain the smoothness and real-timeness of media data transmission in real-time communication scenarios.
Smart Images

Figure CN120074828A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and particularly to a method, apparatus, and system for media data transmission. Background Art
[0002] To achieve secure data transmission, end-to-end encryption (E2EE) is usually adopted for communication. End-to-end encryption allows data to always exist in ciphertext form during the transmission from the sender to the receiver.
[0003] However, even with the end-to-end encryption mechanism, there may still be some security risks in data transmission. For example, there is the problem of "man-in-the-middle attack". A man-in-the-middle attack (MitM) is an active wiretapping attack type. The attacker places himself between the two communication parties, disguises himself as one or several entities involved in the data transmission process, and intercepts and tampers with the data transmitted between the two communication parties. How to prevent man-in-the-middle attacks is particularly important for communication security and is an important research topic at present. Summary of the Invention
[0004] This application provides a method, apparatus, and system for media data transmission.
[0005] In a first aspect, a method for media data transmission is provided. A first communication party obtains first fingerprint information of first media data. The first communication party generates a first digital watermark according to the first fingerprint information. The first digital watermark includes a first signature value obtained by the first communication party signing a first authentication message with a target key. The first authentication message includes the first fingerprint information. The first communication party sends the first media data and second media data to a second communication party. The second media data has the first digital watermark embedded therein. Among them, the second media data is sent after the first media data.
[0006] In this application, since the signature value in the digital watermark is calculated by the sending end using the target key for the authentication message including the fingerprint information of the media data, where the fingerprint information can provide data identity proof for the media data, enabling the generated digital watermark to be coupled with the media data and preventing malicious forgery, and the signature value can be used to judge the authenticity of the media data, realizing end-to-end identity authentication of the first media data. Usually, it is difficult for an attacker to steal both the target key for generating the digital watermark and the algorithm for generating the digital watermark at the same time. Therefore, it is difficult for the attacker to counterfeit the digital watermark, making it difficult to carry out undetected attack behaviors. Therefore, the solution of this application can achieve the secure transmission of media data between the two communication parties. Additionally, this application embeds the digital watermark generated based on the previously transmitted media data into the subsequently transmitted media data. In a real-time communication scenario, the fingerprint calculation time, signature time during the digital watermark generation process by the sending end, and the time for embedding the digital watermark in the media data will not affect the previously transmitted media data, enabling the smoothness and real-time nature of media data transmission. Moreover, since the digital watermark is embedded in the subsequently transmitted media data, the embedded digital watermark will not affect the fingerprint calculation of the previously transmitted media data, thus solving the problem of irreversible rewriting of the current media data caused by embedding the digital watermark in the current media data.
[0007] Optionally, the target key is the private key held by the first communication party. When the target key is the private key held by the first communication party, the second communication party can verify whether the first media data comes from the first communication party and the integrity of the first media data based on the first signature value. Since the private key usually does not leave the device and any third party without the private key cannot forge the signature, it is difficult for an attacker to counterfeit the first digital watermark generated by the first communication party and carry out undetected attack behaviors when it is difficult for the attacker to obtain the private key held by the first communication party.
[0008] Alternatively, the target key is a session key negotiated between the first communication party and the second communication party. When the target key is the session key negotiated between the first communication party and the second communication party, the second communication party can verify whether the first media data comes from the first communication party and the integrity of the first media data based on the first signature value. Since it is difficult for any third party other than the first communication party and the second communication party to obtain the session private key negotiated between the first communication party and the second communication party, it is difficult for an attacker to counterfeit the first digital watermark generated by the first communication party and carry out undetected attack behaviors.
[0009] Alternatively, the target key is a shared key of the group where the first communication party and the second communication party are located, and the shared key is negotiated by multiple communication parties in the group. When the target key is the shared key of the group, the second communication party can verify whether the first media data comes from other communication parties in the group and the integrity of the first media data based on the signature value. Since it is difficult for any third party outside the group to obtain the shared key of the group, it is difficult for an attacker to forge the digital watermark generated by the communication parties in the group and thus carry out undetected attack behaviors.
[0010] Optionally, the first media data is in the first media frame, and the second media data is in the second media frame, and the second media frame is a media frame adjacent to the first media frame.
[0011] In this application, the sending end can embed the digital watermark generated based on the previous media frame into the subsequent media frame, and the receiving end uses the information of the subsequent frame to verify the previous frame, so as to realize the continuity verification of the media data.
[0012] Optionally, the first authentication message further includes authentication attribute information, and the first digital watermark includes authentication attribute information and a first signature value.
[0013] Optionally, the first communication party uses a key derivation function to generate a derived key based on the shared key of the group where the first communication party and the second communication party are located, the identity identifier of the first communication party, and the identity identifier of the second communication party. The shared key is negotiated by multiple communication parties in the group. The first communication party uses the derived key as the authentication attribute information for the hash value calculated for multiple identity public keys, and the multiple identity public keys include the identity public key of the first communication party and the identity public key of the second communication party.
[0014] In this application, by participating the authentication attribute information associated with the identities of the two communication parties in the generation of the digital watermark, the authentication attribute information used by different communication parties can be made different, ensuring the uniqueness of the authentication attribute information and facilitating subsequent traceability and evidence collection based on the digital watermark.
[0015] Optionally, the first communication party obtains the second fingerprint information of the second media data. The first communication party generates a second digital watermark according to the second fingerprint information. The second digital watermark includes a second signature value obtained by the first communication party signing the second authentication message with the target key. The second authentication message includes the second fingerprint information. After the first communication party sends the second media data to the second communication party, the first communication party sends the third media data to the second communication party, and the second digital watermark is embedded in the third media data.
[0016] Optionally, the first media data and the second media data are audio data, video data, or file data.
[0017] In a second aspect, a media data transmission method is provided. The method includes: a second communication party receiving first media data and second media data sent by a first communication party. Among them, the second media data is received after the first media data. A first digital watermark is embedded in the second media data, and the first digital watermark includes a first signature value. The second communication party obtains a first authentication message, and the first authentication message includes first fingerprint information of the first media data. The second communication party uses a target key and the first authentication message to verify the first signature value to determine the authenticity of the first media data.
[0018] Optionally, the target key is a public key held by the first communication party. Alternatively, the target key is a session key negotiated between the first communication party and the second communication party. Alternatively, the target key is a shared key of the group where the first communication party and the second communication party are located, and the shared key is negotiated by multiple communication parties in the group.
[0019] Optionally, the first digital watermark further includes authentication attribute information, and the first authentication message further includes authentication attribute information.
[0020] Optionally, the second communication party receives third media data sent by the first communication party. Among them, the third media data is received after the second media data, and a second digital watermark is embedded in the third media data. The second digital watermark includes a second signature value. The second communication party obtains a second authentication message, and the second authentication message includes second fingerprint information of the second media data. The second communication party uses the target key and the second authentication message to verify the second signature value to determine the authenticity of the second media data.
[0021] Optionally, the first media data and the second media data are audio data, video data or file data.
[0022] In a third aspect, a media data transmission device is provided. The device can be applied to the first communication party, and the device can be, for example, the communication device of the first communication party. The device includes a plurality of functional modules, and the plurality of functional modules interact to implement the methods in the first aspect and its various embodiments above. The plurality of functional modules can be implemented based on software, hardware, or a combination of software and hardware, and the plurality of functional modules can be arbitrarily combined or divided based on specific implementations.
[0023] In a fourth aspect, a media data transmission device is provided. The device can be applied to the second communication party, and the device can be, for example, the communication device of the second communication party. The device includes a plurality of functional modules, and the plurality of functional modules interact to implement the methods in the second aspect and its various embodiments above. The plurality of functional modules can be implemented based on software, hardware, or a combination of software and hardware, and the plurality of functional modules can be arbitrarily combined or divided based on specific implementations.
[0024] In a fifth aspect, a media data transmission system is provided, including: a first communication party and a second communication party. Among them, the first communication party is used to execute the methods in the first aspect and its various embodiments above, and the second communication party is used to execute the methods in the second aspect and its various embodiments above.
[0025] Optionally, both the first communication party and the second communication party are participants in a meeting.
[0026] In a sixth aspect, a communication device is provided, including: a processor and a memory; the memory is used to store a computer program, and the computer program includes program instructions; the processor is used to call the computer program to implement the methods in the first aspect and its various embodiments above, or to implement the methods in the second aspect and its various embodiments above.
[0027] In a seventh aspect, a computer-readable storage medium is provided, on which instructions are stored. When the instructions are executed by a processor, the methods in the first aspect and its various embodiments above are implemented, or the methods in the second aspect and its various embodiments above are implemented.
[0028] In an eighth aspect, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the methods in the first aspect and its various embodiments above are implemented, or the methods in the second aspect and its various embodiments above are implemented.
[0029] In a ninth aspect, a chip is provided. The chip includes a programmable logic circuit and / or program instructions. When the chip runs, the methods in the first aspect and its various embodiments above are implemented, or the methods in the second aspect and its various embodiments above are implemented. Description of the Drawings
[0030] Figure 1 is a schematic diagram of a man-in-the-middle attack provided by an embodiment of the present application;
[0031] Figure 2 is a schematic diagram of audio watermark frame embedding provided by the related art;
[0032] Figure 3 is a flowchart of the implementation of an audio watermark algorithm provided by the related art;
[0033] Figure 4 is a flowchart of the implementation of an audio fingerprint algorithm provided by the related art;
[0034] Figure 5 is a flowchart of the implementation of embedding a signature watermark in a media stream provided by the related art;
[0035] Figure 6It is a schematic diagram of an application scenario provided by an embodiment of the present application;
[0036] Figure 7 It is a schematic diagram of a channel key negotiation process provided by an embodiment of the present application;
[0037] Figure 8 It is another schematic diagram of a channel key negotiation process provided by an embodiment of the present application;
[0038] Figure 9 It is a flowchart of a media data transmission method provided by an embodiment of the present application;
[0039] Figure 10 It is a schematic diagram of a signature authentication process provided by an embodiment of the present application;
[0040] Figure 11 It is a schematic diagram of the structure of a media data transmission device provided by an embodiment of the present application;
[0041] Figure 12 It is another schematic diagram of the structure of a media data transmission device provided by an embodiment of the present application;
[0042] Figure 13 It is a schematic diagram of the hardware structure of a communication device provided by an embodiment of the present application. Detailed implementation manners
[0043] To make the objectives, technical solutions and advantages of the present application clearer, the following will further describe the embodiments of the present application in detail with reference to the accompanying drawings.
[0044] Man-in-the-middle attack is a common type of active attack in current data transmission. The attack behaviors that an attacker can implement include operations such as reading, tampering, inserting, deleting, and reordering the transmitted data. For example, Figure 1 It is a schematic diagram of a man-in-the-middle attack provided by an embodiment of the present application. As Figure 1 shown, the attacker can launch an active attack on the real-time data stream transmitted between different terminal users through a digital channel.
[0045] Therefore, it is particularly important to adopt data protection technologies to protect the transmitted data to prevent man-in-the-middle attacks for communication security. Currently, commonly used data protection technologies include digital watermark technology, data fingerprint technology, and digital signature technology.
[0046] Among them, digital watermarking technology is a technology that embeds specific information such as copyright information or user information of the provider into digital media to protect the copyright of digital media, prove the authenticity and reliability of products, track piracy or provide additional information about products. Digital watermarks can be embedded in various digital media, such as images, audio, video, and text. The watermark information is embedded in the carrier file without affecting the visibility and integrity of the original file. According to the perceptibility of digital watermarks, digital watermarks can be divided into visible watermarks and invisible watermarks. Visible watermarks refer to directly embedding visible information, such as text or images, in digital media. Visible watermarks can be used to identify the owner or copyright information of digital media. Invisible watermarks refer to embedding invisible information, such as digital codes or noises, in digital media. Invisible watermarks can be used to verify the integrity and authenticity of digital media and trace the source of digital media. The application of digital watermarking technology is very extensive, including fields such as copyright protection, anti-counterfeiting, digital forensics, and information hiding. Digital watermarking technology has become one of the important means of digital media security protection.
[0047] Digital fingerprint technology is a technology used to identify digital content, similar to the concept of human fingerprints. Digital fingerprints can generate a unique identifier (equivalent to providing an identity for digital content) by calculating and analyzing digital content, which is used to identify and verify the authenticity and integrity of digital content. Digital fingerprint technology is widely used in fields such as copyright protection, content identification, and network security. The implementation methods of digital fingerprint technology include technologies such as hash algorithms, feature extraction, and comparison.
[0048] Digital signature technology is a technology used to verify the authenticity and integrity of data. Digital signatures are divided into asymmetric signatures and symmetric signatures. In the case of asymmetric signatures, the sender uses the private key held by himself to sign the message. After the receiver receives the data from the sender and the signature value of the sender for this data, the receiver uses the public key held by the sender to verify the signature value. In the case of symmetric signatures, the sender uses a symmetric key to sign the message. After the receiver receives the data from the sender and the signature value of the sender for this data, the receiver uses this symmetric key to verify the signature value. If the verification of the signature value passes, it means that the data has not been tampered with. If the verification of the signature value fails, it means that the data has been tampered with. Signature verification can be used to verify the integrity (untampered) and authenticity (not false data or forged data) of data. Digital signature technology can be used to protect various electronic documents and electronic data such as digital media data, electronic contracts, and emails.
[0049] In the related art, digital watermarks are proposed to be embedded in media data to achieve the identification and tracking of media data. Media data includes but is not limited to audio data, video data, file data, and other digital streaming media data, such as remote shared desktops, remote shared documents, and remote shared applications. Taking audio data as an example, watermark information can be embedded into audio data in real time through audio watermarking technology, and this process can occur at any stage of transmission. Audio watermarking technology is a digital copyright protection technology that protects the copyright of audio content by embedding some specific information in the audio signal. These information can be in the form of digital codes, digital signatures, digital watermarks, etc., and they are embedded into different time domain, frequency domain, phase, amplitude and other parameters of the audio signal to ensure that the quality and audibility of the audio signal are not affected.
[0050] Audio data is divided into file information and real-time information. Regardless of whether it is file information or real-time information, its internal structure adopts a framed form, and the entire audio data is divided into several audio data frames Fi. The audio data frame is the smallest unit of the audio segment, and both sending and encoding / decoding are carried out based on the data length of the audio data frame. Therefore, the current audio watermark embedding scheme can take the audio data frame as a unit and embed the watermark information into the frequency signal components of each audio data frame respectively through the frequency masking method by the watermark embedding algorithm W(Fi) to obtain the audio data frame Di containing the watermark information. Where i is an integer greater than 1. For example, Figure 2 is a schematic diagram of audio watermark framed embedding provided by the related art. To exclude interference and meet the real-time transmission scenario, it is necessary to determine the position of the audio watermark segment in the audio data frame through the synchronization frame so that it can be accurately restored at the extraction end. In addition, due to the covert communication characteristics of the watermark information, the watermark information can be used as an out-of-band communication channel for carrying authentication information. Compared with traditional cryptographic authentication measures, the data transmitted in real-time communication is more covert and more difficult to be discovered and cracked.
[0051] For example, Figure 3 is a flowchart of the implementation of an audio watermark algorithm provided by the related art. As Figure 3 shown, the implementation process of embedding watermark information in the audio data frame includes the following steps A1 to A5.
[0052] In step A1, the original watermark information is modulated, error-corrected encoded, and spread-spectrum transformed into the original watermark sequence m, m = {m(i); i = 0, …, L-1; m(i) ∈ {0,1}}. Where L is the length of the original watermark sequence, usually the number of bits.
[0053] In step A2, a synchronization sequence n is added to the original watermark sequence m to obtain the watermark unit sequence m + n, n = {n(i); i = 0, …, L-1; n(i) ∈ {0,1}}.
[0054] In step A3, a fast Fourier transform (FFT) is performed on the original audio data frame in units of the data length of the audio data frame to convert the original audio data frame into frequency-domain data.
[0055] In step A4, the amplitude data in the fixed frequency-domain information segment of the frequency-domain data is dynamically modified. Among them, a magnitude reduction operation is used for the amplitude data with a value of 0 in the watermark unit sequence, and a magnitude increase operation is used for the amplitude data with a value of 1 in the watermark unit sequence to complete watermark embedding and obtain amplitude data containing watermark information.
[0056] In step A5, the inverse fast Fourier transform (IFFT) is performed on the frequency-domain data containing watermark information to restore the audio data frame containing watermark information.
[0057] Thus, the embedding of the audio watermark into the audio data is completed. Each piece of audio is coupled with the watermark information and is widely used in scenarios such as traceability and copyright declaration with the spread of the audio.
[0058] However, limited by the low security of the digital watermark algorithm itself, anyone who illegally obtains the digital watermark algorithm can easily forge the watermark information. In addition, due to the decoupling of the watermark information from the media data content and the fact that the watermark information is not securely bound to the identity authentication, after the attacker intercepts the media data content embedded with the watermark information, the original watermark information can be easily removed or tampered with. Therefore, it is difficult to rely on the watermark information to verify the authenticity and integrity of the media data content, and problems such as counterfeiting, denial, and framing are likely to occur.
[0059] Regarding the problem of the decoupling of the watermark information from the media data content, since digital fingerprints can provide identities for data, embedding digital fingerprints as watermark information in the media data can well solve this problem. Taking the audio fingerprint technology as an example, the implementation of the audio fingerprint technology usually includes two stages: feature extraction and fingerprint matching. In the feature extraction stage, the audio signal is converted into a set of digital features, which can reflect the time-domain, frequency-domain, phase, amplitude, and other information of the audio signal. In the fingerprint matching stage, the converted digital features are compared with the fingerprints in the database to determine the identity of the audio signal.
[0060] For example, Figure 4 is a flowchart of the implementation of an audio fingerprint algorithm provided by the related technology. As Figure 4As shown in the figure, the calculation and verification process of the audio fingerprint includes the following steps B1 to B5. Among them, steps B1 to B4 are the calculation process of the audio fingerprint (corresponding to the above feature extraction stage), and step B5 is the verification process of the audio fingerprint (corresponding to the above fingerprint matching stage).
[0061] In step B1, the original audio data is preprocessed to obtain multiple audio segments.
[0062] The preprocessing process usually includes adding a Hamming window and framing.
[0063] In step B2, the FFT function is used to perform frequency domain conversion on multiple audio segments respectively to obtain multiple frequency domain segments.
[0064] In step B3, methods such as singular value decomposition (SVD) and feature matrix selection are used to extract the features of multiple frequency domain segments to obtain the overall audio features.
[0065] In step B4, a hash operation is performed on the audio features to obtain a hash feature value, and this hash feature value is used as the audio fingerprint.
[0066] In step B5, after the original audio data and the audio fingerprint are obtained at the extraction end, the audio fingerprint of the obtained original audio data is calculated, and the bit error ratio (BER) (i.e., hash matching) between the obtained audio fingerprint and the calculated audio fingerprint is calculated using a matching function, so as to determine whether they come from the same data source.
[0067] Based on the implementation process of the above audio fingerprint algorithm, it can be seen that multiple steps such as spectrum analysis, feature extraction, and hash operation need to be performed on the audio signal to calculate the audio fingerprint, and the calculation amount is relatively large. Therefore, calculating the audio fingerprint usually takes a long time. Although the audio fingerprint provides the identity information of the audio data, using the audio fingerprint as a watermark can solve the problem of decoupling the existing watermark information from the data content, but for the audio stream that needs to be transmitted in real time, the calculation time of the audio fingerprint is difficult to meet the requirement of embedding the audio fingerprint of the current audio data frame as watermark information in real time in the current audio data frame for transmission. In addition, after embedding the audio fingerprint as watermark information into the current audio data frame, it will change the data content of the current audio data frame, which in turn will also affect the calculation result of the audio fingerprint of the current audio data frame. Therefore, embedding the audio fingerprint in the current audio data frame will easily lead to misjudgment in the fingerprint matching stage.
[0068] Regarding the problem that the watermark information is not securely bound to identity authentication, related technologies have proposed embedding digital signatures as watermark information in media data. However, since the watermark embedding algorithm is time-consuming to a certain extent, and in addition, the signature algorithm is also time-consuming, especially the asymmetric signature algorithm, which brings higher latency than the symmetric signature algorithm under the premise of equal security. When the watermark embedding algorithm and the signature algorithm exist simultaneously, the sum of their latencies makes it difficult to ensure the real-time transmission of the media stream. Constrained by the low-latency performance requirements of real-time communication, the current solution can only sign some data frames (such as key frames) to minimize the impact of the latency caused by watermark embedding and signing on the real-time transmission of the media stream.
[0069] For example, Figure 5 is a flowchart of an implementation of embedding a signature watermark in a media stream provided by related technologies. As Figure 5 shown, during the process of terminal user 1 transmitting a media stream to terminal user 2 in real time, signature authentication is used to prevent unauthorized modification of the data content by third-party illegal users. Specifically, a signature value is generated using a signature algorithm (symmetric signature or asymmetric signature), and then the generated signature value is added to the real-time media stream in the form of a watermark. For example, the media stream transmitted from terminal user 1 to terminal user 2 successively includes media frame 1, media frame 2, media frame 3, media frame 4, and media frame 5, where media frame 2 and media frame 4 are key frames. Terminal user 1 embeds the signature watermark H2 for media frame 2 in media frame 2 and embeds the signature watermark H4 for media frame 4 in media frame 4. In this way, after terminal user 2 receives the media stream from terminal user 1, it can verify the signature carried by the media frame to verify the authenticity and integrity of the media stream. Among them, embedding a signature watermark in a media frame means embedding the signature in the media frame using a digital watermark algorithm.
[0070] However, the disadvantages of the scheme of embedding a signature watermark in a media frame are also obvious, that is, only key frames can be verified, and the correctness of all media frames cannot be guaranteed. Too many key frames will affect the real-time transmission of the media stream. For example, for an audio stream, too many key frames are likely to cause audio-video out-of-sync or audio quality stuttering; while too few key frames will result in low verification reliability of the media stream.
[0071] Based on the defects existing in the related technologies, the present application provides a technical solution, which combines and applies digital watermark technology, digital fingerprint technology and digital signature technology. The communicating party as the sender signs the fingerprint information of the previously sent media data, and carries the signature value in the digital watermark and embeds it into the subsequently sent media data. The communicating party as the receiver can verify the signature value in the subsequently received media data based on the fingerprint information of the previously received media data, so as to judge the integrity and authenticity of the previously transmitted media data, thereby realizing end-to-end identity authentication. By embedding the digital watermark associated with the previously transmitted media data into the subsequently transmitted media data, it not only solves the problems in the related technologies that the calculation of audio fingerprints is time-consuming and affects the transmission real-time performance of media data, and embedding the audio fingerprint into the current media data will change the data content and cause misjudgment in the fingerprint matching stage, but also solves the problem in the related technologies that the signature is time-consuming and affects the transmission real-time performance of media data.
[0072] The technical solution provided by this application is as follows. The first communication party obtains the first fingerprint information of the first media data. The first communication party generates a first digital watermark according to the first fingerprint information. The first digital watermark includes a first signature value obtained by the first communication party signing a first authentication message with a target key. The first authentication message includes the first fingerprint information. The first communication party sends the first media data and the second media data to the second communication party. The first digital watermark is embedded in the second media data. Wherein, the second media data is sent after the first media data. Correspondingly, after receiving the first media data and the second media data successively sent by the first communication party, the second communication party can determine the authenticity of the first media data by verifying the first signature value in the first digital watermark embedded in the second media data. Since the signature value in the digital watermark is calculated by the sending end using the target key for the authentication message including the fingerprint information of the media data, and the fingerprint information can provide data identity proof for the media data, the generated digital watermark can be coupled with the media data to prevent malicious forgery. The signature value can be used to judge the authenticity of the media data, realizing end-to-end identity authentication of the first media data. It is usually difficult for an attacker to steal both the target key for generating the digital watermark and the algorithm for generating the digital watermark at the same time. Therefore, it is difficult for the attacker to forge the digital watermark, and it is difficult to carry out undetected attack behaviors. Therefore, the solution of this application can realize the secure transmission of media data between the two communication parties. In addition, this application embeds the digital watermark generated according to the previously transmitted media data into the subsequently transmitted media data. In a real-time communication scenario, the fingerprint calculation time, signature time, and the time for embedding the digital watermark in the media data during the process of generating the digital watermark by the sending end will not affect the previously transmitted media data, and the smoothness and real-time nature of the media data transmission can be realized. In addition, since the digital watermark is embedded in the subsequently transmitted media data, the embedded digital watermark will not affect the fingerprint calculation of the previously transmitted media data, thus solving the problem of irreversible rewriting of the current media data caused by embedding the digital watermark in the current media data.
[0073] The technical solution of this application will be introduced in detail from multiple perspectives such as application scenarios, method processes, software devices, hardware devices, and systems.
[0074] The application scenario of the embodiment of this application will be illustrated by examples below.
[0075] The embodiments of the present application can be applied to various communication scenarios for transmitting media data, such as point-to-point communication and group communication. Point-to-point communication refers to the instant communication between two communication parties, such as the voice communication service or video communication service in an instant communication application. Group communication refers to the instant communication among two or more communication parties. Two common scenarios of group communication are non-real-time asynchronous interaction scenarios and real-time synchronous interaction scenarios. Among them, the non-real-time asynchronous interaction scenario is mainly for multi-party information interaction, such as the group message communication service in an instant communication application. The real-time synchronous interaction scenario is mainly for multi-party real-time audio and video conferences, such as ad hoc small group meetings, scheduled large-scale organizational meetings, etc.
[0076] Optionally, the media data includes but is not limited to audio data, video data, file data, and other digital streaming media data, such as remote shared desktops, remote shared documents, and remote shared applications, etc.
[0077] In the group communication scenario, to ensure the security of message transmission among multiple communication parties, encrypting the communication data is a relatively common processing method at present. For example, all communication nodes in a group use a pre-agreed key to encrypt the sent messages or decrypt the received messages, so as to achieve encrypted communication. Generally speaking, the key used to encrypt communication messages in a group can be called a shared key. The multiple communication nodes in the group can be divided into management nodes and member nodes according to their roles. The management node is responsible for generating the shared key and distributing the shared key to all member nodes. To ensure the secure distribution of the shared key, the management node can negotiate a channel key with each member node respectively, encrypt the shared key with the negotiated channel key, and then send the encrypted shared key to the corresponding member node. After receiving the encrypted shared key, the member node decrypts it with the channel key negotiated with the management node to obtain the shared key, so as to achieve the secure distribution of the shared key in the group. After that, multiple communication nodes in the group use the shared key to encrypt communication messages to achieve E2EE secure communication.
[0078] Taking the video conferencing scenario as an example, usually, a video conference can involve multiple participants, and each participant joins the video conference through a conference terminal. The conference terminal can be a dedicated physical device or a software program with conferencing capabilities. This software program can run on various computing devices, such as mobile phones, tablets, computers, and other user terminals. In this case, the computing device running this software program can also be considered a conference terminal. The conference terminal joins the video conference through a conference service platform. Specifically, the conference terminal can obtain the media data of the video conference from the conference service platform and send the locally captured media data to the conference service platform so that the conference service platform can forward it to other participating conference terminals. The conference terminals can be connected through a wireless network, enabling participants to join the video conference smoothly regardless of geographical location. In some cases, a participant may only include one attendee. For example, the attendee joins the video conference through a conferencing software program running on a personal mobile phone. In some cases, a participant can also include multiple attendees. For example, in a meeting room scenario, multiple attendees in the meeting room join the video conference through a conference terminal in the meeting room.
[0079] In the video conferencing scenario, during the process of multiple participants joining the conference, they respectively establish digital channels with the conference service platform through conference terminals for communication. The digital channels include a signaling channel and a media channel. Among them, the signaling channel is usually used to carry call signaling and conference control signaling. The media channel is usually used to carry real-time audio and video coding streams, and this media channel is usually also referred to as the in-band communication channel of the video conference. Correspondingly, digital watermarking can serve as a logical out-of-band communication channel for carrying media authentication information. In the video conferencing scenario, the key materials required for E2EE usually include the public keys of all participants, and these public keys can be transmitted through the digital channels established with the conference service platform.
[0080] A public key and a private key are a pair of keys (public-private key pair) obtained through an algorithm. If one key in the key pair is used to encrypt a piece of data, the other key is required to decrypt it. For example, if the public key is used to encrypt the data, the private key is used for decryption; if the private key is used to encrypt the data, the public key is used for decryption, otherwise the decryption will not succeed. The public key is the part of the key pair that is publicly available to the communication peer, while the private key is the non-public part of the key pair. Under normal circumstances, the private key held by a participant cannot be known to any third party, including other participants and the conference service platform.
[0081] In the embodiments of the present application, the public key and private key held by the participating party (communication party) may refer to the device public key and device private key possessed by the conference terminal (for example, a dedicated conference terminal equipped in a conference room can be used by one or more users, and the device public key and device private key possessed by the dedicated conference terminal itself); or it may also refer to the user public key and user private key of the participating user who logs in to the conference terminal (for example, the conference terminal is a computer device running a conference application program, and the user public key and user private key of the currently logged-in user of the conference application program are the public key and private key held by the participating party. If the logged-in user is changed, then the public key and private key held by the participating party also change accordingly).
[0082] If the public key and private key held by the participating party are the device public key and device private key possessed by the conference terminal, then when the conference terminal needs to use the public key and private key held by the participating party, it can directly read the device public key and device private key from the local memory. If the public key and private key held by the participating party are the user public key and user private key of the participating user who logs in to the conference terminal, then the conference terminal can obtain and store the user public key and the signature of the user public key using the user private key according to the information of the logged-in user when the user logs in. This signature is used to prove that the logged-in user holds the private key corresponding to the user public key. In some cases, there may be no logged-in user on the conference terminal (for example, the conference terminal in a conference room is public and does not require user login), but during the conference, it may be bound to a certain participating user or user terminal (temporarily bound). Then, the user public key and user private key of the participating user bound to the conference terminal or the device public key and device private key of the user terminal can also be used as the public key and private key held by the participating party. If the public key and private key held by the participating party are the user public key and user private key of the user, or the device public key and device private key of the user terminal (such as the user's mobile phone, tablet computer, etc.), and the conference terminal and the user terminal are two different physical devices, then the conference terminal can obtain the user public key or the device public key of the user terminal through means such as Bluetooth, near field communication (NFC), and user input.
[0083] Optionally, the public-private key pair held by the participating party may include a long-term public-private key pair and / or a temporary public-private key pair. Among them, the long-term public-private key pair may be the public key generated when the logged-in user of the conference terminal registers and remains unchanged, or the public key generated when the conference terminal itself registers in the conference system; the temporary public-private key pair represents a public-private key pair that is valid for a period of time and will be updated, such as updating the temporary public-private key pair every once in a while or generating a temporary public-private key pair each time joining a conference. Multiple participating parties participating in the conference can send the public keys they hold to the conference service platform for storage in advance.
[0084] For example, Figure 6This is a schematic diagram of an application scenario provided by an embodiment of the present application. This application scenario is a video conferencing scenario, for example, it can be a video conferencing system. As Figure 6 shown, this application scenario includes a conference service platform and four conference terminals (Conference Terminal A, Conference Terminal B, Conference Terminal C, and Conference Terminal D). Four participating users (User A, User B, User C, and User D) access the conference through Conference Terminal A, Conference Terminal B, Conference Terminal C, and Conference Terminal D respectively. Among them, User A and Conference Terminal A are collectively referred to as Participating Party A, User B and Conference Terminal B are collectively referred to as Participating Party B, User C and Conference Terminal C are collectively referred to as Participating Party C, and User D and Conference Terminal D are collectively referred to as Participating Party D.
[0085] Optionally, the conference service platform is a multipoint control unit (MCU). The MCU can provide authentication services to the participating parties (through the conference terminals used by the participating users) and forward the conference data. For example, Conference Terminal A sends the video data on the side of User A to the MCU, and the MCU forwards the video data to Conference Terminal B, Conference Terminal C, and Conference Terminal D so that User B, User C, and User D can respectively watch the video image of User A through Conference Terminal B, Conference Terminal C, and Conference Terminal D.
[0086] In the video conferencing scenario, multiple participating parties in the conference can negotiate a master key as the shared key in the conference. The master key is usually used to encrypt and decrypt the media data and control signaling transmitted in the conference to achieve end-to-end encryption.
[0087] The master key of the conference can be obtained through the joint negotiation of multiple participating parties (usually all participating parties) participating in the conference. The negotiation process can be carried out based on the E2EE key negotiation protocol or the group key negotiation protocol. Two common key negotiation processes based on the E2EE key negotiation protocol can be respectively as Figure 7 、 Figure 8 shown.
[0088] In Figure 7 the channel key negotiation protocol process shown, the conference terminals form a communication pair in pairs. In the case where the conference includes 4 conference terminals, there are a total of 6 communication pairs in the conference, and each communication pair has a communication key, as Figure 7As shown in (a) therein, the communication key between conference terminal A and conference terminal B is Kab, the communication key between conference terminal A and conference terminal C is Kac, the communication key between conference terminal A and conference terminal D is Kad, the communication key between conference terminal B and conference terminal C is Kbc, the communication key between conference terminal B and conference terminal D is Kbd, and the communication key between conference terminal C and conference terminal D is Kcd. When conference terminal A, as the conference manager, generates the master key M, as Figure 7 shown in (b) therein, conference terminal A encrypts the master key M using Kab and sends it to user B; encrypts the master key M using Kac and sends it to conference terminal C; encrypts the master key M using Kad and sends it to conference terminal D.
[0089] Figure 8 This is a process of key negotiation based on the Signal protocol in the E2EE key negotiation protocol. In Figure 8 the example of channel key negotiation shown in (a) therein, each conference terminal has a sender key different from other conference terminals. When sending a message, it encrypts the message to be sent using its own sender key and sends it to other users. Taking conference terminal A as an example, conference terminal A can randomly generate its own sender key Ka, and then encrypt the sender key Ka using the pairing key EKab with conference terminal B and send the encrypted sender key EKab(Ka) to conference terminal B; encrypt the sender key Ka using the pairing key EKac with conference terminal C and send the encrypted sender key EKac(Ka) to conference terminal C; encrypt the sender key Ka using the pairing key with conference terminal D and send the encrypted sender key EKad(Ka) to conference terminal D. When conference terminal A, as the conference manager, generates the master key M, as Figure 8 shown in (b) therein, conference terminal A encrypts the master key M using Ka and sends it to conference terminal B, conference terminal C, and conference terminal D.
[0090] The above Figure 7 and Figure 8 are only examples of channel key negotiation. The embodiments of the present application do not limit the process of negotiating the master key, and other methods can also be used to negotiate the master key. For example, the master key can be negotiated based on the Message Laver Security (MLS) protocol defined in the request for comments (RFC) document numbered 9420 formulated by the Internet Engineering Task Force (IETF) (abbreviation: IETF RFC9420).
[0091] The method flow of the embodiments of the present application will be illustrated by way of example below.
[0092] For example, Figure 9 is a schematic flow diagram of a media data transmission method provided by the embodiments of the present application. As Figure 9 shown, method 900 includes but is not limited to the following steps 901 to step 905. This method 900 can be applied to group communication, for example, it can be applied to a video conferencing scenario as Figure 6 shown. Then, in method 900, communication party 1 (sender) and communication party 2 (receiver) can be Figure 6 any two participants in the
[0093] Step 901, communication party 1 obtains fingerprint information 1 of media data 1.
[0094] Optionally, communication party 1 generates a unique hash value by applying a hash algorithm to media data 1 as fingerprint information 1. The media stream between the two communication parties is usually transmitted in the form of media frames. The media frame can be, for example, an audio frame, a video frame, etc. Media data 1 can contain the data content of one media frame, or media data 1 can also contain the data content of multiple adjacent media frames.
[0095] Step 902, communication party 1 generates digital watermark 1 according to fingerprint information 1. Digital watermark 1 includes signature value 1 obtained by communication party 1 signing authentication message 1 with key 1. Authentication message 1 includes fingerprint information 1.
[0096] Optionally, authentication message 1 further includes authentication attribute information. Correspondingly, digital watermark 1 includes this authentication attribute information and signature value 1. Denote media data 1 as D1, fingerprint information 1 of media data 1 as f(D1), key 1 as k1, and authentication attribute information as m. Then, authentication message 1 can be expressed as f(D1)||m, signature value 1 can be expressed as H(k1, f(D1)||m), and digital watermark 1 can be expressed as W1: m||H(k1, f(D1)||m). Here, the symbol || represents string concatenation.
[0097] The authentication attribute information can be any information involved in generating the digital watermark. For example, the authentication attribute information can be associated with the identities of both communication parties, so that the authentication attribute information used by different communication parties is different, ensuring the uniqueness of the authentication attribute information and facilitating subsequent traceability and evidence collection. Another example is in the video conferencing scenario, the authentication attribute information can include conference information, such as conference identifiers or conference timestamp information, etc. Optionally, communication party 1 and communication party 2 are any two communication parties in the group. One implementation of communication party 1 obtaining the authentication attribute information is as follows. Communication party 1 uses a key derivation function (KDF) to generate a derived key based on the shared key of the group where communication party 1 and communication party 2 are located, the identity identifier of communication party 1, and the identity identifier of communication party 2. The shared key is negotiated by multiple communication parties in the group. Communication party 1 takes the hash value calculated for multiple identity public keys using the derived key as the authentication attribute information. The multiple identity public keys include the identity public key of communication party 1 and the identity public key of communication party 2. The multiple identity public keys can also include the identity public keys of other communication parties in the group.
[0098] For example, refer to Figure 6In the application scenario shown, communication party 1 is participant A, and communication party 2 is participant B. Participant A can make the derived key OTP_OOB = KDF(mk, IDA||IDB||"OOB"), where mk represents the master key, IDA represents the identifier of participant A (the identifier of user A or the identifier of conference terminal A), IDB represents the identifier of participant B (the identifier of user B or the identifier of conference terminal B), and OOB represents out-of-band parameters. The out-of-band parameters can be pre-generated by a conference service platform (such as an MCU). The out-of-band parameters for different conferences can be the same or different. Further, the derived key can also be generated based on the identifiers of other participants in the conference, or can be generated based on the identifiers of all participants in the conference. Additionally, participant A can also generate a public key string based on the public key of participant A and the public key of participant B. For example, the public key string allGroupPK = pkA||pkB can be made, where pkA represents the public key of participant A and pkB represents the public key of participant B. Another example is that when the public key information includes a long-term public key and a temporary public key, the public key string allGroupPK = epkA||epkB||LongPKA||LongPKB can be made, where epkA represents the temporary public key of participant A, epkB represents the temporary public key of participant B, LongPKA represents the long-term public key of participant A, and LongPKB represents the long-term public key of participant B. Further, the public key string can also be generated based on the public keys of other participants in the conference, or can be generated based on the public keys of all participants in the conference. Then, participant A uses the derived key OTP_OOB to perform a hash operation on the public key string allGroupPK to obtain the authentication attribute information m: Hash(OTP_OOB, allGroupPK). The hash operation here can use a keyed hash function. A keyed hash function is a hash function that takes a key as an additional input. It can accept two inputs, a message and a key, and outputs a hash value of a fixed length.
[0099] Optionally, signature value 1 can be an asymmetric signature value calculated by communication party 1 using an asymmetric signature algorithm. The asymmetric signature algorithm can be, for example, the elliptic curve digital signature algorithm (ECDSA). Or, signature value 1 can also be a symmetric signature value calculated by communication party 1 using a symmetric signature algorithm. The symmetric signature algorithm can be, for example, the advanced encryption standard (AES) cypher-based message authentication code (CMAC) (abbreviation: AES-CMAC) algorithm.
[0100] Optionally, Communicator 1 may use the private key held by Communicator 1, or the session key negotiated between Communicator 1 and Communicator 2, or the shared key of the group where Communicator 1 and Communicator 2 are located to sign Authentication Message 1. Among them, signing Authentication Message 1 using the private key by Communicator 1 belongs to asymmetric signature, and signing Authentication Message 1 using the session key or the shared key of the group belongs to symmetric signature. The following separately describes three possible implementation methods of Key 1.
[0101] In the first possible implementation method, Key 1 is the private key held by Communicator 1. Then Communicator 1 uses Key 1 to sign Authentication Message 1 to obtain Signature Value 1. It may be that Communicator 1 first runs a hashing algorithm on Authentication Message 1 to obtain a data hash value of a fixed length, and then uses the private key to encrypt this fixed-length hash value to obtain Signature Value 1. This Signature Value 1 is, for example, an ECDSA signature.
[0102] In the first possible implementation method, Communicator 2 can verify whether Media Data 1 comes from Communicator 1 and the integrity of Media Data 1 based on Signature Value 1. Since the private key usually does not leave the device, any third party without the private key cannot forge the signature. Therefore, when it is difficult for an attacker to obtain the private key held by Communicator 1, it is difficult to forge the digital watermark 1 generated by Communicator 1 and thus carry out an undetected attack behavior.
[0103] In the second possible implementation method, Key 1 is the session key negotiated between Communicator 1 and Communicator 2. Then the Signature Value 1 obtained by Communicator 1 using Key 1 to sign Authentication Message 1 can be a message authentication code. For example, Communicator 1 can generate Signature Value 1 according to Authentication Message 1 and the session key based on the hash-based message authentication code (HMAC) algorithm.
[0104] Optionally, one implementation method for Communicator 1 and Communicator 2 to negotiate the session key is that the communicator receives the key negotiation message sent by the other party. This key negotiation message includes multiple negotiation public keys held by the other party, including the long-term identity public key of the other party. The communicator verifies the authenticity of the multiple negotiation public keys. If the communicator determines that all the multiple negotiation public keys are real public keys from the other party, the communicator uses the multiple negotiation public keys and the multiple negotiation private keys held by itself, including its own long-term identity private key, to generate the session key. Among them, the key negotiated based on the long-term identity public key of the other party and its own long-term identity private key participates in the generation of the session key. As long as the long-term identity private keys of both communicating parties are not leaked, then the attacker cannot crack the session key generated by the communicator. Therefore, the generated session key has high security and confidentiality.
[0105] Optionally, another implementation for Communicator 1 and Communicator 2 to negotiate a session key is that the communicator receives a key negotiation message sent by the other party. The key negotiation message includes multiple negotiation public keys held by the other party, and the authentication sources of the multiple negotiation public keys include at least two trusted institutions. The communicator verifies the authenticity of the multiple negotiation public keys. If the communicator determines that all of the multiple negotiation public keys are real public keys from the other party, the communicator generates a session key using the multiple negotiation public keys and multiple negotiation private keys held by itself. The authentication sources of the negotiation public keys corresponding to the multiple negotiation private keys include at least two trusted institutions. Since different trusted institutions provide different identity factors for the communicator, the communicator performs multi-factor authentication based on multiple identity factors, and the finally generated session key also incorporates multiple identity factors of both communicating parties. Therefore, the security and confidentiality of the generated session key are relatively high.
[0106] In the second possible implementation, Communicator 2 can verify whether Media Data 1 comes from Communicator 1 and the integrity of Media Data 1 based on Signature Value 1. Since it is difficult for any third party other than Communicator 1 and Communicator 2 to obtain the session private key negotiated between Communicator 1 and Communicator 2, it is difficult for an attacker to forge the digital watermark 1 generated by Communicator 1 and thus carry out undetected attack behaviors.
[0107] In the third possible implementation, Key 1 is a shared key of the group where Communicator 1 and Communicator 2 are located, and the shared key is negotiated by multiple communicators in the group. Then, the signature value 1 obtained by Communicator 1 signing the authentication message 1 using Key 1 can be a message authentication code. For example, Communicator 1 can generate the signature value 1 based on the authentication message 1 and the shared key using the HMAC algorithm. The shared key is, for example, the main key of the meeting.
[0108] In the third possible implementation, Communicator 2 can verify whether Media Data 1 comes from other communicators in the group and the integrity of Media Data 1 based on Signature Value 1. Since it is difficult for any third party outside the group to obtain the shared key of the group, it is difficult for an attacker to forge the digital watermark generated by a communicator in the group and thus carry out undetected attack behaviors.
[0109] Step 903: Communicator 1 sends Media Data 1 and Media Data 2 to Communicator 2. Digital watermark 1 is embedded in Media Data 2, where Media Data 2 is sent after Media Data 1.
[0110] In the embodiments of the present application, the sending end embeds a digital watermark generated based on the previously transmitted media data into the subsequently transmitted media data. In a real-time communication scenario, the fingerprint calculation time, signature time during the generation of the digital watermark by the sending end, and the time for embedding the digital watermark into the media data will not affect the previously transmitted media data, and the smoothness and real-time performance of the media data transmission can be achieved. In addition, since the digital watermark is embedded into the subsequently transmitted media data, the embedded digital watermark will not affect the fingerprint calculation of the previously transmitted media data, thus solving the problem of irreversible rewriting of the current media data caused by embedding the digital watermark into the current media data.
[0111] Optionally, Media Data 1 may include the data content of one media frame, or Media Data 1 may also include the data content of multiple adjacent media frames. Similarly, Media Data 2 may include the data content of one media frame, or Media Data 2 may also include the data content of multiple adjacent media frames. In a possible implementation, Media Data 1 is in Media Frame 1, and Media Data 2 is in Media Frame 2, and Media Frame 2 is the media frame adjacent to Media Frame 1. That is to say, the digital watermark generated based on the previous frame of media data can be embedded into the subsequent frame of media data. Of course, the embodiments of the present application do not exclude the scheme of embedding the digital watermark generated based on the previous frames into the media frame after several frames.
[0112] Further, after Communication Party 2 receives Media Data 1 and Media Data 2 sent by Communication Party 1, the following steps 904 to 905 may be executed.
[0113] Step 904: Communication Party 2 obtains Authentication Message 2, and Authentication Message 2 includes Fingerprint Information 2 of Media Data 1.
[0114] After Communication Party 2 receives Media Data 1 sent by Communication Party 1, it generates Fingerprint Information 2 of Media Data 1 by applying the same hashing algorithm to Media Data 1 as that applied by Communication Party 1 to Media Data 1 in Step 901 above. If Media Data 1 is not tampered with during transmission, then Fingerprint Information 2 is the same as Fingerprint Information 1.
[0115] After receiving the media data 2 sent by the communicating party 2, the communicating party 2 extracts the digital watermark 1 from the media data 2 using a watermark extraction algorithm. When the digital watermark 1 only includes the signature value 1, the communicating party 2 may use the calculated fingerprint information 2 as the authentication message 2. Then, the above step 904 may be that the communicating party 2 obtains the authentication message 2 based on the media data 1. When the digital watermark 1 includes the authentication attribute information and the signature value 1, the communicating party 2 may use the calculated fingerprint information 2 and the authentication attribute information extracted from the digital watermark 1 as the authentication message 2 together. Then, the above step 904 may be that the communicating party 2 obtains the authentication message 2 based on the media data 1 and the media data 2.
[0116] Step 905: The communicating party 2 uses the key 2 and the authentication message 2 to verify the signature value 1 to determine the authenticity of the media data 1.
[0117] Combined with the first possible implementation manner of the above step 902, the key 1 is the private key held by the communicating party 1, so the key 2 is the public key held by the communicating party 1, that is, the key 2 and the key 1 are a public-private key pair held by the communicating party 1. When the communicating party 2 uses the key 2 and the authentication message 2 to verify the signature value 1, it may be that the communicating party 2 first runs the same hash algorithm on the authentication message 2 as the communicating party 1 runs on the authentication message 1 to obtain the data hash value 1, and then uses the key 2 to decrypt the signature value 1 to obtain the data hash value 2. If the data hash value 1 is the same as the data hash value 2, it is determined that the media data 1 is authentic data. If the data hash value 1 is different from the data hash value 2, it is determined that the media data 1 is not authentic data.
[0118] Combined with the second possible implementation manner of the above step 902, the key 1 is the session key negotiated between the communicating party 1 and the communicating party 2, so the key 2 and the key 1 are the same key. In this implementation manner, the signature value 1 may be a message authentication code. When the communicating party 2 uses the key 2 and the authentication message 2 to verify the signature value 1, it may be that the communicating party 2 calculates the message authentication code based on the authentication message 2 and the session key and using the HMAC algorithm. If the message authentication code calculated by the communicating party 2 is the same as the message authentication code (signature value 1) carried in the digital watermark 1, it is determined that the media data 1 is authentic data. If the message authentication code calculated by the communicating party 2 is different from the message authentication code (signature value 1) carried in the digital watermark 1, it is determined that the media data 1 is not authentic data.
[0119] Combined with the third possible implementation manner of step 902 above, if the secret key 1 is the shared secret key of the group where communication party 1 and communication party 2 are located, then the secret key 2 and the secret key 1 are the same secret key. In this implementation manner, the signature value 1 can be a message authentication code. Then, communication party 2 uses the secret key 2 and the authentication message 2 to verify the signature value 1. It can be that communication party 2 calculates the message authentication code based on the authentication message 2 and the shared secret key and based on the HMAC algorithm. If the message authentication code calculated by communication party 2 is the same as the message authentication code (signature value 1) carried in the digital watermark 1, it is determined that the media data 1 is authentic data. If the message authentication code calculated by communication party 2 is different from the message authentication code (signature value 1) carried in the digital watermark 1, it is determined that the media data 1 is not authentic data.
[0120] In the embodiments of the present application, since the signature value in the digital watermark is calculated by the sending end using the secret key for the authentication message including the fingerprint information of the media data, where the fingerprint information can provide data identity proof for the media data, it can couple the generated digital watermark with the media data to prevent malicious forgery, and the signature value can be used to judge the authenticity of the media data, realizing end-to-end identity authentication of the first media data. And it is usually difficult for an attacker to steal both the target secret key for generating the digital watermark and the algorithm for generating the digital watermark at the same time. Therefore, it is difficult for the attacker to forge the digital watermark, and thus it is difficult to perform undetected attack behaviors. Therefore, the embodiments of the present application can realize the secure transmission of media data between the two communication parties.
[0121] In addition, based on the concept of embedding the digital watermark generated according to the previously transmitted media data into the subsequently transmitted media data provided by the embodiments of the present application, further, communication party 1 can also obtain the fingerprint information 3 of the media data 2, and generate the digital watermark 2 according to the fingerprint information 3. The digital watermark 2 includes the signature value 2 obtained by communication party 1 signing the authentication message 3 using the secret key 1, and the authentication message 3 includes the fingerprint information 2. After communication party 1 sends the media data 2 to communication party 2, it sends the media data 3 to communication party 2, and the digital watermark 2 is embedded in the media data 3. Correspondingly, after communication party 2 receives the media data 3 sent by communication party 1, it obtains the authentication message 4, and the authentication message 4 includes the fingerprint information 4 of the media data 2. Communication party 2 uses the secret key 2 and the authentication message 4 to verify the signature value 2 to determine the authenticity of the media data 2. The implementation of this process can refer to the above steps 901 to 905, and so on in a loop until the entire media stream transmission ends.
[0122] The present application uses the following embodiments to illustrate the implementation process of the above method 900 by way of example.
[0123] For example, the sending end embeds the digital watermark generated based on the previous media frame into the subsequent media frame, and the receiving end uses the backward verification algorithm to perform the verification of the previous frame using the information of the subsequent frame.Figure 10 This is a schematic diagram of a signature authentication process provided by an embodiment of the present application. First, define D i is the i-th media frame obtained by framing the media stream, where i is a positive integer. i ) is a fingerprint algorithm used to calculate the fingerprint information f of the i-th media frame i . m is the authentication attribute information. W(f i ) is a watermark generation algorithm, which is used to generate fingerprint information f based on the i-th media frame. i Generate digital watermark W i , W i =m||H(k,f i ||m), where H is the hash function and k is the key for the hash calculation.
[0124] See also Figure 10 The sender adds a digital watermark with authentication attribute information to the media frame. The specific implementation steps are as follows: 1) Calculate the real-time transmission media frame D i Fingerprint information f i , and then the fingerprint information f i Calculate the signature information H using the key k and the authentication attribute information m i =H(k,f i ||m); 2) the frame signature information H i The digital watermark W is obtained by concatenating the authentication attribute information m with the characters i ; 3) Use the watermark embedding algorithm to embed the digital watermark W i Embedded into the next media frame D i+1 The watermark embedding is completed in i The next media frame D i+1 Repeat steps 1 to 3 above to complete the loop embedding process.
[0125] See also Figure 10 The receiving end verifies the digital watermark with authentication attribute information in the media frame. The specific implementation steps are as follows: 1) Use the watermark extraction algorithm to extract the media frame D i+1 The digital watermark W in i ; 2) Calculate the previous frame D i Fingerprint information f i ', and from the digital watermark W i Extract authentication attribute information m; 3) fingerprint information f i 'Calculate W(f i ')=m||H(k,f i '||m); 4) Compare W(f i ') and W iWhether the values are the same. If they are the same, the verification passes; if they are different, the verification fails. Continue to use the media frame D according to the above steps 1 to 4 i+2 and the digital watermark W i+1 in it to continue verifying the media frame D i+1 until the verification process is completed.
[0126] The embodiments of the present application combine and apply digital watermark technology, digital fingerprint technology, and digital signature technology. As the communicating party at the sending end, it signs the fingerprint information of the previously sent media data and embeds the signature value in the digital watermark into the subsequently sent media data. As the communicating party at the receiving end, it can verify the signature value in the subsequently received media data based on the fingerprint information of the previously received media data, thereby judging the integrity and authenticity of the previously transmitted media data, so as to achieve end-to-end identity authentication. By embedding the digital watermark associated with the previously transmitted media data into the subsequently transmitted media data, it not only solves the problem that the time-consuming calculation of fingerprints affects the transmission real-time of media data, and embedding fingerprints into the current media data will change the data content and cause misjudgment in the fingerprint matching stage, but also solves the problem that the signature time-consuming affects the transmission real-time of media data, and at the same time realizes automatic continuous out-of-band authentication (OOBA) of media data.
[0127] Next, taking Figure 6 the video conferencing scenario shown as an example, the specific implementation manners of the embodiments of the present application will be illustrated. Assume that the above-mentioned communicating party 1 is participant A, and communicating party 2 is participant B.
[0128] In step S1, participant A registers in the MCU of the video conferencing system and sends the public key bundle of participant A to the MCU; participant B registers in the MCU of the video conferencing system and sends the public key bundle of participant B to the MCU; participant C registers in the MCU of the video conferencing system and sends the public key bundle of participant C to the MCU; participant D registers in the MCU of the video conferencing system and sends the public key bundle of participant D to the MCU.
[0129] Optionally, the public key bundle of participant A may include the long-term public key LongPKA and the ephemeral public key epkA. The public key bundle of participant B may include the long-term public key LongPKB and the ephemeral public key epkB. The public key bundle of participant C may include the long-term public key LongPKC and the ephemeral public key epkC. The public key bundle of participant D may include the long-term public key LongPKD and the ephemeral public key epkD.
[0130] In step S2, Party A, as the meeting initiator, obtains the public key materials of Party B, Party C, and Party D from the MCU; Party B joins the meeting and obtains the public key materials of Party A, Party C, and Party D from the MCU; Party C joins the meeting and obtains the public key materials of Party A, Party B, and Party D from the MCU; Party D joins the meeting and obtains the public key materials of Party A, Party B, and Party C from the MCU.
[0131] In step S3, Party A, Party B, Party C, and Party D negotiate the master key mk.
[0132] In step S4, Party A generates the authentication attribute information m.
[0133] For example, Party A generates the public key string allGroupPK = epkA||epkB||epkC||epkD||LongPKA||LongPKB||LongPKC||LongPKD; then generates the derived key OTP_OOB = KDF(mk, IDA||IDB||IDC||IDD||"OOB"), where mk represents the master key, IDA represents the identifier of Party A, IDB represents the identifier of Party B, IDC represents the identifier of Party C, IDD represents the identifier of Party D, and OOB represents the out-of-band parameter. After that, Party A performs a hash operation on the public key string allGroupPK using the derived key OTP_OOB to obtain the authentication attribute information m.
[0134] In step S5, Party A generates digital watermark 1 based on the authentication attribute information m and the fingerprint information of media data 1. Digital watermark 1 includes the authentication attribute information m and the signature value obtained by Party A signing the authentication attribute information m and the fingerprint information of media data 1 using the master key mk.
[0135] In step S6, Party A sequentially sends media data 1 and media data 2 to Party B, Party C, and Party D. Digital watermark 1 is embedded in media data 2.
[0136] In step S7, Party B, Party C, and Party D respectively verify the signature value in digital watermark 1 based on the master key mk, the authentication attribute information m in digital watermark 1, and the fingerprint information of media data 1 calculated by themselves to determine whether media data 1 is authentic data.
[0137] The order of the steps of the media data transmission method provided by the embodiments of the present application can be appropriately adjusted, and the steps can also be increased or decreased accordingly according to the situation. Any person skilled in the art in the technical field disclosed in the present application can easily think of a changed method, which should be covered by the protection scope of the present application. For example, by adding authentication attribute information related to personal identity to the digital watermark, so as to trace the media data and conduct security forensics, etc. Another example is that a communication party can act as both the sender and the receiver of media data, that is, a communication party can simultaneously have the ability to execute the above steps 901 to 903 (steps executed by the sender) and steps 904 to 905 (steps executed by the receiver).
[0138] Embodiments of the present application also provide a media data transmission method, which can be applied to various application scenarios involving media data transmission. For example, it can be applied to a video conferencing scenario as shown in Figure 6 The implementation process of this method includes but is not limited to the following steps M1 to M3.
[0139] In step M1, the first communication party obtains the first fingerprint information of the first media data.
[0140] In step M2, the first communication party generates a first digital watermark according to the first fingerprint information. The first digital watermark includes a first signature value obtained by the first communication party signing a first authentication message with a target key. The first authentication message includes the first fingerprint information.
[0141] In step M3, the first communication party sends the first media data and the second media data to the second communication party. The second media data is embedded with the first digital watermark, where the second media data is sent after the first media data.
[0142] When this method is specifically used to implement the embodiment shown in the above method 900, the first communication party can be, for example, communication party 1, the second communication party can be, for example, communication party 2, the first media data can be, for example, media data 1, the second media data can be, for example, media data 2, the first fingerprint information can be, for example, fingerprint information 1, the first digital watermark can be, for example, digital watermark 1, the first authentication message can be, for example, authentication message 1, and the first signature value can be, for example, signature value 1.
[0143] Optionally, the target key is the private key held by the first communication party; or, the target key is a session key negotiated between the first communication party and the second communication party; or, the target key is a shared key of the group where the first communication party and the second communication party are located, and the shared key is negotiated by multiple communication parties in the group.
[0144] Optionally, the first media data is in a first media frame, and the second media data is in a second media frame, where the second media frame is a media frame adjacent to the first media frame.
[0145] Optionally, the first authentication message further includes authentication attribute information, and the first digital watermark includes authentication attribute information and a first signature value.
[0146] Optionally, the first communicating party uses a key derivation function to generate a derived key based on the shared key of the group where the first communicating party and the second communicating party are located, the identity identifier of the first communicating party, and the identity identifier of the second communicating party. The shared key is negotiated by multiple communicating parties in the group. The first communicating party uses the derived key as the authentication attribute information for the hash value calculated for multiple identity public keys, where the multiple identity public keys include the identity public key of the first communicating party and the identity public key of the second communicating party.
[0147] Optionally, the method further includes: The first communicating party obtains second fingerprint information of the second media data. The first communicating party generates a second digital watermark according to the second fingerprint information. The second digital watermark includes a second signature value obtained by the first communicating party signing a second authentication message with a target key. The second authentication message includes the second fingerprint information. After the first communicating party sends the second media data to the second communicating party, the first communicating party sends third media data to the second communicating party, and the second digital watermark is embedded in the third media data. When the method is specifically used to implement the embodiment shown in the above method 900, the second fingerprint information may be, for example, fingerprint information 3, the second digital watermark may be, for example, digital watermark 2, the second authentication message may be, for example, authentication message 3, the second signature value may be, for example, signature value 2, and the third media data may be, for example, media data 3.
[0148] Optionally, the first media data and the second media data are audio data, video data, or file data.
[0149] The embodiment of the present application further provides another media data transmission method, which can be applied to various application scenarios involving media data transmission, such as Figure 6 the video conferencing scenario shown. The implementation process of the method includes but is not limited to the following steps N1 to step N3.
[0150] In step N1, the second communicating party receives the first media data and the second media data sent by the first communicating party, where the second media data is received after the first media data, and the second media data is embedded with a first digital watermark, and the first digital watermark includes a first signature value.
[0151] In step N2, the second communicating party obtains a first authentication message, and the first authentication message includes first fingerprint information of the first media data.
[0152] In step N3, the second communication party verifies the first signature value using the target key and the first authentication message to determine the authenticity of the first media data.
[0153] When this method is specifically used to implement the embodiment shown in the above method 900, the first communication party may be, for example, communication party 1, the second communication party may be, for example, communication party 2, the first media data may be, for example, media data 1, the second media data may be, for example, media data 2, the first fingerprint information may be, for example, fingerprint information 2, the first digital watermark may be, for example, digital watermark 1, the first authentication message may be, for example, authentication message 2, and the first signature value may be, for example, signature value 1.
[0154] Optionally, the target key is the public key held by the first communication party; or, the target key is the session key negotiated between the first communication party and the second communication party; or, the target key is the shared key of the group where the first communication party and the second communication party are located, and the shared key is negotiated by multiple communication parties in the group.
[0155] Optionally, the first digital watermark further includes authentication attribute information, and the first authentication message further includes authentication attribute information.
[0156] Optionally, this method further includes: the second communication party receives the third media data sent by the first communication party, where the third media data is received after the second media data, and the second digital watermark including the second signature value is embedded in the third media data. The second communication party obtains the second authentication message, and the second authentication message includes the second fingerprint information of the second media data. The second communication party verifies the second signature value using the target key and the second authentication message to determine the authenticity of the second media data. When this method is specifically used to implement the embodiment shown in the above method 900, the second fingerprint information may be, for example, fingerprint information 4, the second digital watermark may be, for example, digital watermark 2, the second authentication message may be, for example, authentication message 4, the second signature value may be, for example, signature value 2, and the third media data may be, for example, media data 3.
[0157] Optionally, the first media data and the second media data are audio data, video data, or file data.
[0158] The following gives an example of the software device in the embodiments of the present application.
[0159] For example, Figure 11 is a schematic structural diagram of a media data transmission device provided by an embodiment of the present application. This media data transmission device is applied to the first communication party. As Figure 11 shown, the media data transmission device 1100 includes but is not limited to: an acquisition module 1101, a processing module 1102, and a sending module 1103.
[0160] An acquisition module 1101 is configured to acquire first fingerprint information of first media data. A processing module 1102 is configured to generate a first digital watermark according to the first fingerprint information, where the first digital watermark includes a first signature value obtained by a first communication party signing a first authentication message using a target key, and the first authentication message includes the first fingerprint information. A sending module 1103 is configured to send the first media data and second media data to a second communication party, where the second media data is embedded with the first digital watermark, and the second media data is sent after the first media data.
[0161] Optionally, the target key is a private key held by the first communication party; alternatively, the target key is a session key negotiated between the first communication party and the second communication party; or, the target key is a shared key of a group where the first communication party and the second communication party are located, and the shared key is negotiated by multiple communication parties in the group.
[0162] Optionally, the first media data is in a first media frame, and the second media data is in a second media frame, and the second media frame is a media frame adjacent to the first media frame.
[0163] Optionally, the first authentication message further includes authentication attribute information, and the first digital watermark includes the authentication attribute information and the first signature value.
[0164] Optionally, the processing module 1102 is further configured to: generate a derived key by using a key derivation function based on a shared key of a group where the first communication party and the second communication party are located, an identity identifier of the first communication party, and an identity identifier of the second communication party, where the shared key is negotiated by multiple communication parties in the group; use the derived key to calculate a hash value of multiple identity public keys as the authentication attribute information, and the multiple identity public keys include an identity public key of the first communication party and an identity public key of the second communication party.
[0165] Optionally, the acquisition module 1101 is further configured to acquire second fingerprint information of the second media data. The processing module 1102 is further configured to generate a second digital watermark according to the second fingerprint information, where the second digital watermark includes a second signature value obtained by the first communication party signing a second authentication message using the target key, and the second authentication message includes the second fingerprint information. The sending module 1103 is further configured to send a third media data to the second communication party after sending the second media data to the second communication party, where the third media data is embedded with the second digital watermark.
[0166] Optionally, the first media data and the second media data are audio data, video data, or file data.
[0167] For another example, Figure 12 is a schematic structural diagram of another media data transmission device provided by an embodiment of the present application. The media data transmission device is applied to the second communication party. As Figure 12As shown, the media data transmission device 1200 includes, but is not limited to: a receiving module 1201, an obtaining module 1202, and a verification module 1203.
[0168] The receiving module 1201 is configured to receive first media data and second media data sent by a first communication party, where the second media data is received after the first media data, and a first digital watermark is embedded in the second media data, and the first digital watermark includes a first signature value. The obtaining module 1202 is configured to obtain a first authentication message, and the first authentication message includes first fingerprint information of the first media data. The verification module 1203 is configured to verify the first signature value by using a target key and the first authentication message to determine the authenticity of the first media data.
[0169] Optionally, the target key is a public key held by the first communication party; or, the target key is a session key negotiated between the first communication party and a second communication party; or, the target key is a shared key of a group where the first communication party and the second communication party are located, and the shared key is negotiated by multiple communication parties in the group.
[0170] Optionally, the first digital watermark further includes authentication attribute information, and the first authentication message further includes authentication attribute information.
[0171] Optionally, the receiving module 1201 is further configured to receive third media data sent by the first communication party, where the third media data is received after the second media data, and a second digital watermark is embedded in the third media data, and the second digital watermark includes a second signature value. The obtaining module 1202 is further configured to obtain a second authentication message, and the second authentication message includes second fingerprint information of the second media data. The verification module 1203 is further configured to verify the second signature value by using the target key and the second authentication message to determine the authenticity of the second media data.
[0172] Optionally, the first media data and the second media data are audio data, video data, or file data.
[0173] The following gives an example of the hardware device of the embodiment of the present application.
[0174] For example, Figure 13 is a schematic diagram of the hardware structure of a communication device provided by an embodiment of the present application. The communication device may be the device of any communication party in the above embodiment, for example, it may be a conference terminal. As Figure 13 shown, the communication device 1300 includes a processor 1301 and a memory 1302, and the memory 1301 is connected to the memory 1302 through a bus 1303. Figure 13 It is described with the processor 1301 and the memory 1302 being independent of each other. Optionally, the processor 1301 and the memory 1302 are integrated together. Optionally, in combination with Figure 6Look, Figure 13 the communication device 1300 in Figure 6 can be any of the conference terminals shown.
[0175] Among them, the memory 1302 is used to store computer programs, and the computer programs include an operating system and program codes. The memory 1302 is various types of storage media, such as read-only memory (ROM), random access memory (RAM), electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM), flash memory, optical memory, register, optical disc storage, optical disc storage, magnetic disk or other magnetic storage devices.
[0176] Among them, the processor 1301 is a general-purpose processor or a special-purpose processor. The processor 1301 may be a single-core processor or a multi-core processor. The processor 1301 includes at least one circuit to execute the actions performed by the communication party 1 or the communication party 2 in the above method 900 provided by the embodiments of the present application.
[0177] Optionally, the communication device 1300 further includes a network interface 1304, and the network interface 1304 is connected to the processor 1301 and the memory 1302 through a bus 1303. The network interface 1304 can enable the communication device 1300 to communicate with other devices. For example, the processor 1301 can interact with other devices through the network interface 1304, such as communicating with an MCU through the network interface 1304, and so on.
[0178] Optionally, the communication device 1300 further includes an input / output (I / O) interface 1305, and the I / O interface 1305 is connected to the processor 1301 and the memory 1302 through a bus 1303. The processor 1301 can receive input commands or data, etc. through the I / O interface 1305. The I / O interface 1305 is used for the communication device 1300 to connect to input devices, and these input devices are, for example, a keyboard, a mouse, etc. Optionally, in some possible scenarios, the above network interface 1304 and the I / O interface 1305 are collectively referred to as a communication interface.
[0179] Optionally, the communication device 1300 further includes a display 1306, which is connected to the processor 1301 and the memory 1302 via a bus 1303. The display 1306 can be used to display intermediate results and / or final results generated by the processor 1301 when executing the above method. In a possible implementation, the display 1306 is a touch display screen to provide a human-computer interaction interface.
[0180] Among them, the bus 1303 is of any type and is a communication bus used to interconnect internal components of the communication device 1300. For example, a system bus. In the embodiments of the present application, the above components inside the communication device 1300 are interconnected via the bus 1303 as an example. Optionally, the above components inside the communication device 1300 communicate with each other using other connection methods in addition to the bus 1303. For example, the above components inside the communication device 1300 are interconnected via a logical interface inside the communication device 1300.
[0181] The above components can be respectively arranged on independent chips, or at least partially or entirely arranged on the same chip. Whether to arrange each component on a different chip independently or integrate and arrange them on one or more chips often depends on the needs of product design. The embodiments of the present application do not limit the specific implementation forms of the above components.
[0182] Figure 13 The shown communication device 1300 is merely exemplary. During implementation, the communication device 1300 includes other components, which will not be listed one by one herein. Figure 13 The shown communication device 1300 can realize the transmission of media data by executing all or part of the steps of the method provided in the above embodiments.
[0183] The system of the embodiments of the present application will be illustrated by examples below.
[0184] The embodiments of the present application further provide a media data transmission system, including: a first communication party and a second communication party. Among them, the first communication party is used to execute the steps executed by the communication party 1 in the above method 900, such as executing steps 901 to 903. The second communication party is used to execute the steps executed by the communication party 2 in the above method 900, such as executing steps 904 to 905.
[0185] Optionally, the media data transmission system can be a conference system, such as an audio-video conference system or a cloud service conference system. Both the first communication party and the second communication party are participants in the conference.
[0186] The embodiments of the present application also provide a computer-readable storage medium, on which instructions are stored. When the instructions are executed by a processor, the steps executed by Communication Party 1 or Communication Party 2 in the above method 900 are implemented.
[0187] The embodiments of the present application also provide a computer program product, including a computer program. When the computer program is executed by a processor, the steps executed by Communication Party 1 or Communication Party 2 in the above method 900 are implemented.
[0188] Those of ordinary skill in the art can understand that all or part of the steps of the above embodiments can be completed by hardware, or can be completed by a program instructing relevant hardware. The program can be stored in a computer-readable storage medium. The storage medium mentioned above can be a read-only memory, a magnetic disk, an optical disc, or the like.
[0189] In the embodiments of the present application, the terms "first", "second", and "third" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance.
[0190] The term "and / or" in the present application is only a description of the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally represents an "or" relationship between the front and rear associated objects.
[0191] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data for analysis, stored data, displayed data, etc.), and signals involved in the present application are all authorized by the user or fully authorized by all parties. The collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions.
[0192] The above are only optional embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the concept and principles of the present application shall be included in the protection scope of the present application.
Claims
1. A method for transmitting media data, characterized in that, the method comprises: A first communication party obtains first fingerprint information of first media data; The first communication party generates a first digital watermark according to the first fingerprint information, where the first digital watermark includes a first signature value obtained by the first communication party signing a first authentication message with a target key, and the first authentication message includes the first fingerprint information; The first communication party sends the first media data and second media data to a second communication party, where the first digital watermark is embedded in the second media data, and the second media data is sent after the first media data.
2. The method according to claim 1, characterized in that, the target key is a private key held by the first communication party; alternatively, the target key is a session key negotiated between the first communication party and the second communication party; alternatively, the target key is a shared key of a group where the first communication party and the second communication party are located, and the shared key is negotiated by multiple communication parties in the group.
3. The method according to claim 1 or 2, characterized in that, the first media data is in a first media frame, the second media data is in a second media frame, and the second media frame is a media frame adjacent to the first media frame.
4. The method according to any one of claims 1 to 3, characterized in that, the first authentication message further includes authentication attribute information, and the first digital watermark includes the authentication attribute information and the first signature value.
5. The method according to claim 4, characterized in that, the method further comprises: The first communication party uses a key derivation function to generate a derived key based on the shared key of the group where the first communication party and the second communication party are located, the identity identifier of the first communication party, and the identity identifier of the second communication party, and the shared key is negotiated by multiple communication parties in the group; The first communication party uses the derived key to calculate a hash value of multiple identity public keys as the authentication attribute information, and the multiple identity public keys include the identity public key of the first communication party and the identity public key of the second communication party.
6. The method according to any one of claims 1 to 5, characterized in that, the method further comprises: The first communication party obtains second fingerprint information of the second media data; The first communication party generates a second digital watermark according to the second fingerprint information, where the second digital watermark includes a second signature value obtained by the first communication party signing a second authentication message with the target key, and the second authentication message includes the second fingerprint information; After the first communication party sends the second media data to the second communication party, the first communication party sends third media data to the second communication party, and the second digital watermark is embedded in the third media data.
7. The method according to any one of claims 1 to 6, characterized in that, the first media data and the second media data are audio data, video data or file data.
8. A method for transmitting media data, characterized in that, The method includes: The second communication party receives first media data and second media data sent by the first communication party, where the second media data is received after the first media data, and a first digital watermark is embedded in the second media data, and the first digital watermark includes a first signature value; The second communication party obtains a first authentication message, and the first authentication message includes first fingerprint information of the first media data; The second communication party uses a target key and the first authentication message to verify the first signature value to determine the authenticity of the first media data.
9. The method according to claim 8, wherein, the target key is the public key held by the first communication party; or, the target key is a session key negotiated between the first communication party and the second communication party; or, the target key is a shared key of the group where the first communication party and the second communication party are located, and the shared key is negotiated by multiple communication parties in the group.
10. The method according to claim 8 or 9, wherein, the first digital watermark further includes authentication attribute information, and the first authentication message further includes the authentication attribute information.
11. The method according to any one of claims 8 to 10, wherein, the method further includes: The second communication party receives third media data sent by the first communication party, where the third media data is received after the second media data, and a second digital watermark is embedded in the third media data, and the second digital watermark includes a second signature value; The second communication party obtains a second authentication message, and the second authentication message includes second fingerprint information of the second media data; The second communication party uses the target key and the second authentication message to verify the second signature value to determine the authenticity of the second media data.
12. The method according to any one of claims 8 to 11, wherein, the first media data and the second media data are audio data, video data or file data.
13. A media data transmission device, wherein, applied to the first communication party, the device includes: an acquisition module, configured to acquire first fingerprint information of first media data; a processing module, configured to generate a first digital watermark according to the first fingerprint information, and the first digital watermark includes a first signature value obtained by the first communication party signing a first authentication message with a target key, and the first authentication message includes the first fingerprint information; a sending module, configured to send the first media data and second media data to a second communication party, and the first digital watermark is embedded in the second media data, where the second media data is sent after the first media data.
14. The device according to claim 13, wherein, the target key is the private key held by the first communication party; or, the target key is a session key negotiated between the first communication party and the second communication party; Alternatively, the target key is a shared key of the group where the first communication party and the second communication party are located, and the shared key is negotiated by multiple communication parties in the group.
15. The device according to claim 13 or 14, wherein, the first media data is in a first media frame, the second media data is in a second media frame, and the second media frame is a media frame adjacent to the first media frame.
16. The device according to any one of claims 13 to 15, wherein, the first authentication message further includes authentication attribute information, and the first digital watermark includes the authentication attribute information and the first signature value.
17. The device according to claim 16, wherein, the processing module is further configured to: generate a derived key by using a key derivation function based on the shared key of the group where the first communication party and the second communication party are located, the identity identifier of the first communication party, and the identity identifier of the second communication party, and the shared key is negotiated by multiple communication parties in the group; use the hash value calculated for multiple identity public keys by using the derived key as the authentication attribute information, and the multiple identity public keys include the identity public key of the first communication party and the identity public key of the second communication party.
18. The device according to any one of claims 13 to 17, wherein, the obtaining module is further configured to obtain second fingerprint information of the second media data; the processing module is further configured to generate a second digital watermark according to the second fingerprint information, and the second digital watermark includes a second signature value obtained by the first communication party signing a second authentication message by using the target key, and the second authentication message includes the second fingerprint information; the sending module is further configured to send third media data to the second communication party after sending the second media data to the second communication party, and the third media data is embedded with the second digital watermark.
19. The device according to any one of claims 13 to 18, wherein, the first media data and the second media data are audio data, video data or file data.
20. A media data transmission device, wherein, applied to a second communication party, the device includes: a receiving module, configured to receive first media data and second media data sent by a first communication party, wherein the second media data is received after the first media data, and the second media data is embedded with a first digital watermark, and the first digital watermark includes a first signature value; an obtaining module, configured to obtain a first authentication message, and the first authentication message includes first fingerprint information of the first media data; a verification module, configured to verify the first signature value by using a target key and the first authentication message to determine the authenticity of the first media data.
21. The device according to claim 20, wherein, the target key is a public key held by the first communication party; alternatively, the target key is a session key negotiated between the first communication party and the second communication party; Alternatively, the target key is a shared key of the group where the first communication party and the second communication party are located, and the shared key is negotiated by multiple communication parties in the group.
22. The apparatus according to claim 20 or 21, wherein, the first digital watermark further includes authentication attribute information, and the first authentication message further includes the authentication attribute information.
23. The apparatus according to any one of claims 20 to 22, wherein, the receiving module is further configured to receive third media data sent by the first communication party, where the third media data is received after the second media data, and a second digital watermark is embedded in the third media data, and the second digital watermark includes a second signature value; the obtaining module is further configured to obtain a second authentication message, and the second authentication message includes second fingerprint information of the second media data; the verification module is further configured to verify the second signature value by using the target key and the second authentication message to determine the authenticity of the second media data.
24. The apparatus according to any one of claims 20 to 23, wherein, the first media data and the second media data are audio data, video data or file data.
25. A media data transmission system, wherein, comprising: a first communication party and a second communication party, the first communication party is configured to execute the method according to any one of claims 1 to 7, and the second communication party is configured to execute the method according to any one of claims 8 to 12.
26. The system according to claim 25, wherein, both the first communication party and the second communication party are participants in the meeting.
27. A communication device, wherein, comprising: a processor and a memory; the memory is configured to store a computer program, and the computer program includes program instructions; the processor is configured to call the computer program to implement the method according to any one of claims 1 to 12.
28. A computer-readable storage medium, wherein, instructions are stored on the computer-readable storage medium, and when the instructions are executed by a processor, the method according to any one of claims 1 to 12 is implemented.
29. A computer program product, wherein, comprising a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 12 is implemented.
Citation Information
Cited By
Media data transmission method, apparatus and system
EP4804458A1
Media data transmission method, apparatus and system
WO2025112578A1