Watermark embedding method, detection method and device for Tor network flow

By performing time slot block division and dynamic watermark bit generation of data streams in the Tor network, the problem of time-time and space-time overhead of identifying the homologous relationship of the Tor network data stream in the prior art is solved, and high accuracy and low visibility watermark embedding and detection in complex network environments are achieved.

CN120165843AActive Publication Date: 2025-06-17BEIJING UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510651158.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-20
Publication Date
2025-06-17
Estimated Expiration
2045-05-20

AI Technical Summary

Technical Problem

In the prior art, when identifying the homologous relationship of Tor network data flow, the time and space overhead is too large and it is difficult to adapt to interference from complex network environments.

Method used

By dividing the data stream in time slot blocks at the watermark embed end of the Tor network, dynamic watermark bits are generated using the basic time slots, and real embedded watermark signals are constructed through redundant encoding and exclusive OR operations. The embedding position is randomly selected and the subscript vector is recorded to ensure the deep coupling of the watermark signal and the original flow.

Benefits of technology

It significantly reduces interference to network flow statistical features, improves the accuracy of watermark extraction in complex network environments, and enhances the security and low visibility of the watermark system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165843A_ABST
    Figure CN120165843A_ABST
Patent Text Reader

Abstract

The invention provides a watermark embedding method, a detection method and a device for a Tor network flow, a watermark embedding end divides a data flow into time slot blocks according to the product of the redundancy and the bit number of a watermark to be embedded, the first two time slot blocks serve as basic time slots to generate dynamic basic watermark bits, and the rest time slot blocks serve as embedded time slots to add watermarks. A watermark signal is constructed based on redundant coding and a basic watermark bit, and a binary numerical value is distinguished by adding time delay to an even time slot group or an odd time slot group to adjust an expected value of a centroid difference of the odd and even time slot groups in an embedded time slot part of each time slot block so as to embed a watermark bit; after time slot blocks are divided at a watermark detection end, a basic time slot and an embedded time slot are distinguished, an embedded real watermark bit is detected by calculating an expected value of a centroid difference of odd and even time slot groups in the embedded time slot, a watermark error correction code bit is recovered, a complete watermark error correction code is obtained, an original watermark signal is extracted based on a shared subscript vector, and a watermark error correction code is obtained. And the interference of a complex network environment on network flow statistical characteristics is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network data processing, and in particular, to a method, a detection method and a device for embedding watermarks in Tor network flows. Background Art

[0002] The wide application of the Tor network (Onion Network) provides a hidden environment for cybercrimes. Determining the relationship between the two communicating parties has become the key to network security. Early passive traffic analysis technologies analyzed traffic characteristics by deploying sniffing nodes to match data streams, but they needed to process a large amount of traffic, with high overhead and being vulnerable to interference. The network watermarking technology in active traffic analysis technologies emerged as the times require. It draws on the concept of digital watermarks, embeds watermarks by modulating traffic characteristics upstream, and detects and judges the communication relationship downstream.

[0003] Early passive traffic analysis technologies deployed sniffing and observing nodes at key positions in the network, analyzed and compared the timing characteristics, packet lengths, data packets, etc. of a large number of network flows intercepted on both sides to match the data streams, and then further determined the homologous relationship of the traffic through specific similarity calculation algorithms. This passive traffic homology recognition technology needs to capture and process all network traffic, bringing about the problems of spatio-temporal overhead of network devices. At the same time, long-term and large-scale network flow analysis not only requires a large number of samples for pre-training, but is also easily affected by various flow adjustments in complex network environments, affecting the accuracy of the results. Summary of the Invention

[0004] In view of this, embodiments of the present invention provide a method, a detection method and a device for embedding watermarks in Tor network flows to eliminate or improve one or more defects existing in the prior art, and solve the problem that the spatio-temporal overhead is too large to cope with the interference of complex network environments in the process of identifying the homologous relationship of Tor network data streams in the prior art.

[0005] A method for embedding watermarks in Tor network flows according to the present invention is executed at the watermark embedding end of the Tor network. The method includes the following steps: After a first set time offset amount, the data stream to be processed is divided into a first number of time slot blocks, where the first number is the product of the redundancy of the watermark to be embedded and the number of bits; each time slot block is divided into multiple time slots according to a first duration, the first two time slots in each time slot block are used as basic time slots, and the remaining time slots are used as embedding time slots; the basic watermark bits are determined according to the transmission rate of the flow in the basic time slots; For each bit in the watermark signal, a second number of embedding positions are randomly selected from the first number of time slot blocks and recorded as a subscript vector to be shared with the watermark detection end, where the second number is equal to the redundancy of the watermark to be embedded; Generate a pseudo-random seed according to the current timestamp and a random salt value through a hash function, and input it into a pseudo-random generator to generate an element value of a pseudo-random number sequence with a length equal to the number of bits, and then map it to a watermark signal in the form of a binary array; perform redundant encoding on the watermark signal according to the watermark redundancy to be embedded and the subscript vector to obtain a watermark error correction code; perform an exclusive OR operation on the watermark error correction code and the basic watermark bit to obtain a real embedded watermark signal; Divide the time slots in each time slot block into even time slot groups and odd time slot groups, and distinguish binary values by adding a time delay to adjust the expected value of the centroid difference between the even time slot group and the odd time slot group, so as to embed the real embedded watermark signal into the embedded time slot part of each time slot block of the data stream according to the subscript vector for inspection at the watermark detection end.

[0006] In some embodiments, only 2 basic time slots are set, and the number of embedded time slots is an even number; The method determines the basic watermark bit according to the transmission rate of the flow in the basic time slot, and the calculation formula is: ; Wherein, represents the first basic time slot, represents the second basic time slot, represents the flow transmission rate in the first basic time slot, represents the flow transmission rate in the second basic time slot, represents the basic watermark bit; The calculation formula for the flow transmission rate is: ; Wherein, I i represents the i-th time slot, L ij represents the length of the j-th data packet in the i-th time slot, k i represents the number of data packets in the i-th time slot.

[0007] In some embodiments, generate a pseudo-random seed according to the current timestamp and a random salt value through a hash function, and the calculation formula is: ; Wherein, SHA-1 represents using the SHA-1 hash function, || represents the concatenation operation, represents the current timestamp, and s represents the random salt value; Input into a pseudo-random generator to generate an element value of a pseudo-random number sequence with a length equal to the number of bits, and the calculation formula is: ; Wherein, R represents the element value of the pseudo-random number sequence, with a value range of (0, 1), PRNG represents the random number generation algorithm, and length represents the length of the generated random number; Is mapped to a watermark signal in the form of a binary array, and the expression is: ; Wherein, Represents the i-th bit of the watermark signal, Represents the i-th element value of the pseudo-random number sequence; The true embedded watermark signal is obtained by performing an exclusive OR operation on the watermark error correction code and the basic watermark bit, and the expression is: ; Wherein, Represents the i-th bit of the true embedded watermark signal, Represents the i-th bit of the watermark error correction code, Represents the i-th bit of the basic watermark bit.

[0008] In some embodiments, the time slots in each time slot block are divided into even time slot groups and odd time slot groups, and the expected value of the centroid difference between the odd and even time slot groups is adjusted by adding a time delay to the even time slot group or the odd time slot group to distinguish binary values, so as to embed the true embedded watermark signal into the embedded time slot part of each time slot block of the data stream according to the subscript vector, including: Define the aggregated centroid of the even time slot group in a single time slot block as , and the aggregated centroid of the odd time slot group as , and the calculation formula is: ; ; Wherein, Represents the number of packets of the j-th time slot in the even time slot group, Represents the time slot centroid of the j-th time slot in the even time slot group, Represents the number of packets of the j-th time slot in the odd time slot group, Represents the time slot centroid of the j-th time slot in the odd time slot group, Represents the number of time slots in the even time slot group or the odd time slot group; The calculation formula for the centroid difference between the odd and even time slot groups is: ; Then the expected value of the centroid difference between the odd and even time slot groups is: ; For the time slot block , if the embedded true embedded watermark signal is 1, increase the centroid of the even time slot group aggregation value so that is a positive value; on the contrary, if the embedded true embedded watermark signal is 0, by increasing value so that is a negative value; where, let be the jth data packet in the time slot interval, and the offset relative to the start time stamp of this time slot is uniformly distributed in the interval, add a delay to this data packet, and the calculation formula is: ; The value range of the a parameter is .

[0009] On the other hand, the present invention provides a watermark detection method for Tor network traffic. The method is executed at the watermark detection end and is used to detect the watermark embedded by the above-mentioned watermark embedding method for Tor network traffic. The method includes the following steps: After receiving the data stream, wait for the second set time offset to perform the next operation; After performing time synchronization, divide the data stream into the first number of time slot blocks. The first number is the product of the redundancy of the watermark to be embedded and the number of bits; each time slot block is divided into multiple time slots according to the first duration. The first two time slots in each time slot block are used as basic time slots, and the remaining time slots are used as embedded time slots; For each time slot block, calculate the transmission flow rate of the basic time slot and determine the corresponding basic watermark bit; divide the embedded time slots into even time slot groups and odd time slot groups, and calculate the expected value of the centroid difference between the even and odd time slot groups. If it is greater than 0, restore the corresponding true watermark bit to 1. If it is less than 0, restore the corresponding true watermark bit to 0; solve the corresponding watermark error correction code bit according to the basic watermark bit and the true watermark, and repeat the operation for each time slot block to obtain the complete watermark error correction code; Extract the original watermark signal from the watermark error correction code based on the shared subscript vector.

[0010] In some embodiments, the method further includes comparing the original watermark signal extracted at the current time step with that extracted at the previous time step to calculate the Hamming distance. If the Hamming distance is lower than the set value, it is determined to be homologous, otherwise it is non-homologous.

[0011] In some embodiments, the original watermark signal is extracted from the watermark error correction code based on the shared subscript vector, and the calculation formula is as follows: ; Among them, denotes the extracted original watermark signal, r denotes the watermark redundancy, denotes the subscript vector of the i-th bit of the original watermark signal, denotes the watermark error correction code of the k-th bit.

[0012] On the other hand, the present invention also provides a watermark embedding and detection device for Tor network traffic, including a processor, a memory, and computer programs / instructions stored on the memory. The processor is used to execute the computer programs / instructions. When the computer programs / instructions are executed, the device implements the steps of the above method.

[0013] On the other hand, the present invention also provides a computer-readable storage medium, on which computer programs / instructions are stored. When the computer programs / instructions are executed by a processor, the steps of the above method are implemented.

[0014] On the other hand, the present invention also provides a computer program product, including computer programs / instructions. When the computer programs / instructions are executed by a processor, the steps of the above method are implemented.

[0015] The beneficial effects of the present invention are at least: For the watermark embedding method, detection method and device for Tor network traffic of the present invention, the watermark embedding end divides the data stream into time slot blocks according to the product of the watermark redundancy to be embedded and the number of bits. The first two of each time slot block are used as basic time slots to generate dynamic basic watermark bits, and the rest are used as embedding time slots to add watermarks. A watermark signal is constructed based on redundant coding and basic watermark bits. In the embedding time slot part of each time slot block, a watermark bit is embedded by adding a time delay to adjust the expected value of the centroid difference between the even and odd time slot groups through the even time slot group or the odd time slot group to distinguish binary values; after dividing the time slot block at the watermark detection end, the basic time slot and the embedding time slot are distinguished, and the embedded true watermark bit is detected by calculating the expected value of the centroid difference within the embedding time slot, the watermark error correction code bit is restored to obtain the complete watermark error correction code, and the original watermark signal is extracted based on the shared subscript vector. The present invention uses the basic time slot rate to generate a dynamic watermark benchmark, and realizes the deep coupling of the watermark signal and the original traffic through the exclusive OR operation with the error correction code, greatly reducing the interference to the statistical characteristics of the network traffic and adapting to complex network environments.

[0016] Furthermore, the watermark detection end significantly improves the accuracy of watermark extraction in complex network environments by statistically analyzing the sign of the expected value of the centroid difference instead of the absolute time delay value.

[0017] Furthermore, the distributed embedding strategy based on shared subscript vectors enhances the security of the watermark system. By randomly dispersing the watermark bits in multiple time slot blocks and using a dynamically generated pseudo-random sequence to determine the embedding position, it is difficult for attackers to locate the watermark features through local traffic analysis. The dynamic seed is generated by combining the timestamp and random salt value to ensure that each embedded watermark pattern is unique and non-replicable, effectively preventing replay attacks.

[0018] Furthermore, it is suitable for high-anonymity scenarios such as the Tor network, and achieves low visibility and high reliability of watermark embedding without destroying the traffic statistics characteristics. Through the synergy of the multi-level error correction mechanism and the dynamic synchronization strategy, the detection end can accurately restore the original watermark signal by only sharing a small amount of information such as the subscript vector, providing an effective technical means for tracing the anonymous network flow.

[0019] Additional advantages, purposes, and features of the present invention will be described in part in the following description, and will become apparent to those skilled in the art after studying the following, or may be learned from the practice of the present invention. The purposes and other advantages of the present invention may be achieved and obtained by the structures specifically indicated in the specification and the accompanying drawings.

[0020] Those skilled in the art will appreciate that the objectives and advantages that can be achieved with the present invention are not limited to the above specific description, and the above and other objectives that can be achieved by the present invention will be more clearly understood from the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] The drawings described herein are used to provide a further understanding of the present invention, constitute a part of the present application, and do not constitute a limitation of the present invention. In the drawings: Figure 1 The figure is a flow chart of embedding a detection watermark in a Tor network data stream according to an embodiment of the present invention.

[0022] Figure 2 The figure is a schematic diagram of a time slot division method for Tor network data flow according to an embodiment of the present invention.

[0023] Figure 3 The figure is a schematic diagram of the structure of time slot blocks divided for Tor network data flow according to an embodiment of the present invention.

[0024] Figure 4 The figure is a schematic diagram of a structure for embedding a watermark in a Tor network data stream according to an embodiment of the present invention. DETAILED DESCRIPTION

[0025] To make the objectives, technical solutions and advantages of the present invention more clear and understandable, the present invention will be further described in detail below in conjunction with the embodiments and the drawings. Herein, the illustrative embodiments of the present invention and their descriptions are used to explain the present invention, but not to limit the present invention.

[0026] Herein, it should also be noted that in order to avoid obscuring the present invention due to unnecessary details, only the structures and / or processing steps closely related to the solution according to the present invention are shown in the drawings, while other details less related to the present invention are omitted.

[0027] It should be emphasized that the term "comprising / including" when used herein refers to the presence of features, elements, steps or components, but does not exclude the presence or addition of one or more other features, elements, steps or components.

[0028] Aiming at the limitations of the same-source judgment of network traffic in the Tor anonymous communication network, drawing on the concept of "digital watermark", by actively modulating certain characteristics of the communication traffic upstream of the network, special watermark information is secretly embedded into the network traffic. After network transmission, by analyzing the captured communication traffic downstream of the network, it is judged whether there is a communication relationship between the suspicious sender and the suspicious receiver. Due to the existence of a large number of mechanisms such as packet fragmentation, recombination and dummy packets in the Tor network, these factors pose challenges to the robustness of the network watermarking technology. At the same time, the introduction of delay by the watermarking technology cannot affect the normal user experience, and the algorithm should have a certain complexity, which also poses challenges to the concealment of the network watermarking technology.

[0029] A watermark embedding method for Tor network flows according to the present invention, the method is used to be executed at the watermark embedding end of the Tor network, referring to Figure 1 , the method includes the following steps S101 to S104: Step S101: Referring to Figure 2 and Figure 3 , the data stream to be processed is divided into a first number of time slot blocks after a first set time offset, the first number is the product of the watermark embedding redundancy and the number of bits; each time slot block is divided into multiple time slots according to a first duration, the first two time slots in each time slot block are used as basic time slots, and the remaining time slots are used as embedding time slots; the basic watermark bit is determined according to the transmission rate of the flow in the basic time slot.

[0030] Step S102: For each bit in the watermark signal, randomly select a second number of determined embedding positions in the first number of time slot blocks and record them as a subscript vector to be shared with the watermark detection end, and the second number is equal to the watermark embedding redundancy.

[0031] Step S103: Generate a pseudo-random seed according to the current timestamp and random salt value through a hash function, and input it into a pseudo-random generator to generate an element value of a pseudo-random number sequence equal to the number of bits, and then map it into a watermark signal in the form of a binary array; perform redundancy encoding on the watermark signal according to the watermark embedding redundancy and the subscript vector to obtain a watermark error correction code; perform an exclusive OR operation on the watermark error correction code and the basic watermark bit to obtain a real embedded watermark signal.

[0032] Step S104: Refer to Figure 4 , divide the time slots in each time slot block into even time slot groups and odd time slot groups, and distinguish binary values by adding a time delay to adjust the expected value of the centroid difference between the even time slot group and the odd time slot group, so as to embed the real embedded watermark signal into the embedded time slot part of each time slot block of the data stream according to the subscript vector for detection and verification at the watermark detection end.

[0033] In step S101, the data stream in the Tor network is divided into time slot blocks for watermark embedding. An offset is selected in the data stream, and the data stream with a set duration after this offset is divided into 10n time slots with a length of T, where n = r × l, r is the watermark embedding redundancy, and l is the number of bits. Every 10 time slots form a time slot block. The first two time slots are used as basic time slots, and the last eight are used as embedded time slots. In the subsequent process, each time slot block is used to embed one bit of the real embedded watermark information. To improve security, basic time slots are introduced to construct dynamic basic watermark bits.

[0034] In some embodiments, only 2 basic time slots are set, and the number of embedded time slots is an even number.

[0035] The method determines the basic watermark bit according to the transmission rate of the flow in the basic time slot, and the calculation formula is: ; Where represents the first basic time slot, represents the second basic time slot, represents the flow transmission rate in the first basic time slot, represents the flow transmission rate in the second basic time slot, represents the basic watermark bit.

[0036] The calculation formula for the flow transmission rate is: ; Where I i represents the i-th time slot, L ij represents the length of the j-th data packet in the i-th time slot, and k i represents the number of data packets in the i-th time slot.

[0037] For the divided data stream, the 8 embedded time slots within each time slot block are divided into even time slot groups and odd time slot groups. Among the 10n time slots of each time slot block, there are data packets . Using to represent the absolute timestamp of the data packet , and to represent the absolute timestamp of the starting point of the first time slot block, then there is being the relative offset of the data packet relative to the starting point of the first time slot block, and being the relative offset of the data packet within its respective time slot interval.

[0038] Given a stream containing sufficient data packets, any offset and any interval size , the relative offset of the data packet within its respective time slot interval follows a uniform distribution. Therefore, the expected value of is shown in the following formula: ; Let there be a total of data packets within the time slot . The focus is on the "centroid" of the time slot . Denote the offset of the jth data packet within the time slot relative to the starting timestamp of its interval as . Then the centroid of this time slot can be obtained as shown in the following formula: If there are no data packets within the time slot , then this time slot is an empty time slot. Define the centroid of the empty time slot as .

[0039] In step S102, after the redundancy encoding operation, the final true embedded watermark signal contains r×l bits. That is, each of the l bits of the watermark signal appears r times. For the n time slot blocks divided in step S101, one bit is embedded in each. Therefore, for each bit in the watermark signal, r positions corresponding to the n time slot blocks are respectively selected, obtaining the subscript vector as .

[0040] In step S103, a pseudo-random seed is generated through a hash function based on the current timestamp and a random salt value. The calculation formula is: ; Among them, SHA-1 indicates the use of the SHA-1 hash function, || represents the concatenation operation, represents the current timestamp, and s represents the random salt value.

[0041] Input the pseudo-random seed into the pseudo-random generator to generate the element values of the pseudo-random number sequence with a length equal to the number of bits. The calculation formula is: ; Among them, R represents the element value of the pseudo-random number sequence, with a value range of (0,1), PRNG represents the random number generation algorithm, and length represents the length of the generated random number.

[0042] Map the element values of the pseudo-random number sequence to the watermark signal in the form of a binary array. The expression is: ; Among them, represents the i-th bit of the watermark signal, represents the i-th element value of the pseudo-random number sequence.

[0043] The watermark signal generates a watermark error correction code based on the redundancy of the watermark to be embedded and the subscript vector.

[0044] Perform an exclusive OR operation on the watermark error correction code and the basic watermark bit to obtain the real embedded watermark signal. The expression is: ; Among them, represents the i-th bit of the real embedded watermark signal, represents the i-th bit of the watermark error correction code, represents the i-th bit of the basic watermark bit.

[0045] In step S104, the embedded time slots in the time slot block can be marked as , distinguishing the even time slot group and the odd time slot group , and the expression is as follows: ; ; Define the aggregate centroid of the even time slot group in a single time slot block as , and the aggregate centroid of the odd time slot group as , and the calculation formula is: ; ; Among them, represents the number of packets of the j-th time slot in the even time slot group, Denote the slot centroid of the j-th slot within the even slot group, Denote the number of data packets in the j-th slot within the odd slot group, Denote the slot centroid of the j-th slot within the odd slot group, Denote the number of slots within the even slot group or the odd slot group.

[0046] The expected values of the aggregated centroids of the even slot group and the odd slot group are as follows: ; The calculation formula for the difference between the centroids of the odd and even slot groups is: ; Then the expected value of the difference between the centroids of the odd and even slot groups is: ; For the slot block , if the true embedded watermark signal is 1, increase the value of the aggregated centroid of the even slot group such that is a positive value; on the contrary, if the true embedded watermark signal is 0, by increasing the value of such that is a negative value; where, let be the j-th data packet within the time slot interval, and the offset relative to the start time stamp of this time slot is uniformly distributed within the interval, add a delay to this data packet, and the calculation formula is: ; The value range of the a parameter is .

[0047] On the other hand, the present invention provides a watermark detection method for Tor network flows. The method is executed at the watermark detection end and is used to detect the watermark embedded by the watermark embedding method for Tor network flows through the above steps S101~S104. Referring to Figure 1 , the method includes the following steps S201~S204: Step S201: Wait for a second set time offset after receiving the data stream and then perform the next operation.

[0048] Step S202: After performing time synchronization, divide the data stream into a first number of slot blocks. The first number is the product of the redundancy of the watermark to be embedded and the number of bits; each slot block is divided into multiple slots according to a first duration, and the first two slots in each slot block are used as basic slots, and the remaining slots are used as embedded slots.

[0049] Step S203: For each time slot block, calculate the transmission stream rate of the basic time slot and determine the corresponding basic watermark bit; divide the embedded time slots into even time slot groups and odd time slot groups, and calculate the expected value of the centroid difference between the even and odd time slot groups. If it is greater than 0, restore the corresponding true watermark bit to 1; if it is less than 0, restore the corresponding true watermark bit to 0; solve the corresponding watermark error correction code bit according to the basic watermark bit and the true watermark, and repeat the operation for each time slot block to obtain the complete watermark error correction code.

[0050] Step S204: Extract the original watermark signal from the watermark error correction code based on the shared subscript vector.

[0051] In step S201, after receiving the data stream, the watermark detection end first performs synchronization and waits for the second set time offset, which is the sum of the first set time offset and the transmission delay.

[0052] In step S202, use the same rules, time slot length, watermark error correction code bit data n, etc. as the watermark embedding section to divide the time slot block and time slots, and at the same time divide the basic time slot and the embedded time slot.

[0053] In step S203, extract the watermark error correction code from the stream. For each time slot block , first calculate the stream transmission rate of the basic time slot in this time slot block and , calculate the aggregated centroids of the even time slot group and the odd time slot group within this time slot block and subtract to get . Then, from and restore the basic watermark bit within the time slot block . If , then restore the true watermark bit to '1', otherwise restore it to '0'. Then, according to the basic watermark bit calculated from the time slot block and the true watermark bit , calculate the watermark error correction code bit . Repeat the above steps to finally obtain the detected watermark error correction code .

[0054] In some embodiments, the original watermark signal is extracted from the watermark error correction code based on the shared subscript vector, and the calculation formula is as follows: ; where represents the extracted original watermark signal, r represents the watermark redundancy, represents the subscript vector of the i-th bit of the original watermark signal, Denote the watermark error correction code of the k-th bit.

[0055] In some embodiments, the method further includes comparing the original watermark signal extracted at the current time step with that extracted at the previous time step to calculate the Hamming distance. If the Hamming distance is lower than a set value, it is determined to be of the same origin; otherwise, it is of different origins.

[0056] On the other hand, the present invention also provides a watermark embedding and detection device for Tor network flows, including a processor, a memory, and computer programs / instructions stored on the memory. The processor is used to execute the computer programs / instructions, and when the computer programs / instructions are executed, the device implements the steps of the above method.

[0057] On the other hand, the present invention also provides a computer-readable storage medium, on which computer programs / instructions are stored. When the computer programs / instructions are executed by a processor, the steps of the above method are implemented.

[0058] On the other hand, the present invention also provides a computer program product, including computer programs / instructions. When the computer programs / instructions are executed by a processor, the steps of the above method are implemented.

[0059] The present invention will be described below in conjunction with a specific embodiment: This embodiment proposes a method, device, and storage medium for generating Tor network flow watermarks, aiming to overcome the challenges faced by the existing background technology. Through steps such as time slot block division, original watermark signal generation and redundant coding, watermark embedding, watermark detection, and homology determination, the communication relationship between the suspicious sender and the receiver is accurately determined. This method is particularly applicable to scenarios such as network active tracking and covert channels. The technical method is as follows: Step S1: Time slot block division. For the data packet flow sent by the sender, which passes through a complex network and has a certain duration, it is regarded as the target traffic. Starting from an offset, the time slot interval is divided, and the division is carried out in units of time slot intervals. On this basis, a fixed number of time slot intervals are combined and regarded as a time slot block.

[0060] Step S2: Watermark signal generation and redundant coding. Using the timestamp information and random salt value to generate a pseudo-random seed, according to the pseudo-random seed, a random number sequence is generated using a pseudo-random number generator and mapped into a watermark original signal in the form of 0-1. After obtaining the watermark original signal, it is subjected to redundant coding to generate a watermark error correction code.

[0061] Step S3: Watermark embedding. For each bit of the watermark error correction code, there is a corresponding time slot block for watermark embedding. Based on the basic time slot flow rate relationship within the time slot block and the watermark error correction code, the actual embedded watermark bit is obtained. By adjusting the difference in the aggregated centroids between the even time slot group and the odd time slot group in the embedded time slots within the time slot block, the watermark bit in the form of 0-1 is dynamically embedded into the corresponding time slot block in combination with the flow rate characteristics, ensuring the complexity and concealment of the watermark algorithm.

[0062] Step S4: Watermark detection. After the watermark detection end receives the data stream, it is necessary to first complete the time synchronization between the watermark detection ends. After completing the time synchronization, the watermark error correction code is restored according to the time slot blocks divided in Step S1, and the original watermark signal is extracted according to the redundancy rule in Step S2.

[0063] Step S5: Homology determination. The original watermark signal generated in Step S2 and the original watermark signal extracted in Step S4 are used to determine the traffic homology. Calculate the difference between the two, set a threshold, and determine whether the traffic is homologous based on whether the difference value is less than the threshold, that is, the communication relationship between the suspected sender and the receiver.

[0064] Meanwhile, this embodiment provides a device for the Tor network watermark embedding and detection method to implement the above method, which includes the following modules: Time block division module: configured to divide the network data packet stream sent by the sender into time slot blocks, and generate a time slot block sequence including basic time slots and embedded time slots according to the preset offset duration and redundancy.

[0065] Watermark signal generation and redundancy coding module: includes a pseudo-random seed generation unit that generates a pseudo-random seed based on the time stamp and random salt value through a hash function; a built-in pseudo-random number generator that maps the pseudo-random number to the original watermark signal and generates a watermark error correction code using the redundancy coding rule.

[0066] Watermark embedding module: dynamically calculates the flow rate of the basic time slots within the time slot block, generates basic watermark bits, and combines them with the watermark error correction code to generate the actual embedded watermark bits; according to the actual watermark bits, adjusts the difference in the aggregated centroids between the even time slot group and the odd time slot group within the time slot block through a delay strategy to achieve dynamic watermark embedding.

[0067] Watermark detection module: includes a time synchronization unit for calibrating the time offset between the watermark detection end and the embedding end to offset the influence of the Tor network transmission delay; a configured time slot block division unit that divides the received traffic into time slot blocks based on the same parameters; a built-in centroid calculation unit and a basic time slot flow rate calculation unit that restore the original watermark signal through the difference in aggregated centroids and the flow rate.

[0068] Homology determination module: Calculate the Hamming distance between the original watermark signal and the detected watermark signal, and compare it with a preset threshold to determine whether the traffic is from the same source; support dynamic adjustment of the threshold to adapt to the false alarm rate and missed alarm rate requirements in different network environments.

[0069] The specific implementation is as follows: As Figure 1 shown, it is a framework schematic diagram of a dynamic adaptive flow watermarking method based on flow rate and time slot centroid characteristics. The specific steps are as follows: Step S11: Time slot block division. For the data packet flow f sent by the sender and passing through the Tor network with a duration of and the watermark redundancy to be embedded of and the number of bits of . First, select an offset in the data flow and select a duration . Divide into (where ) time slot intervals with a length of : . On this basis, take 10 time slots as a time slot block unit , can be regarded as consisting of n time slot blocks with a length of 10T: , as Figure 2 shown.

[0070] A time slot block contains 10 time slots with a length of T, as shown in the following formula: ; For the time sequence block , divide the 10 time slots into basic time slots and embedded time slots . The basic time slots consist of the first 2 time slots, and the embedded time slots consist of the last 8 time slots, as shown in the following formula.

[0071] ; Assume that in a continuous data flow with a length of , there are data packets in the 10n time slots of each time slot block. Use to represent the absolute timestamp of the data packet , and to represent the absolute timestamp of the starting point of the first time slot block. Then there is is the relative offset of the data packet relative to the starting point of the first time slot block, and is the data packet The relative offset of its corresponding time slot interval.

[0072] Given a flow containing sufficient data packets, any offset and any interval size , the relative offsets of the data packets within their respective time slot intervals follow a uniform distribution, so the expected value of ; Let there be a total of data packets within the time slot , and the focus is on the "centroid" of the time slot . Denote the offset of the j-th data packet within the time slot relative to the start timestamp of its interval as , then the centroid of this time slot can be obtained as follows: If there are no data packets within the time slot , then this time slot is an empty time slot, and the centroid of the empty time slot is defined as .

[0073] For the watermarking scheme of this method, the structural schematic diagram of the timing block is as shown in Figure 3 . Each time slot block contains a basic time slot and a marked time slot, and is responsible for embedding 1 bit of watermark information. The basic time slot contains two sub-time slots, whose function is to determine the true watermark bit to be embedded by comparing the flow rate magnitude relationship between the two time slots and combining the original watermark bit. The marked time slot contains four time slots, which are mainly used to obtain the true watermark based on the basic time slot and modulate the network traffic of the marked time slot. NTNW completes the embedding of the watermark information through the mutual cooperation of the basic time slot and the marked time slot in the time slot block.

[0074] Step S12, watermark signal generation and redundancy coding. For the data packet flow f sent by the sender and passing through the Tor network with a duration of , the redundancy of the watermark signal W to be embedded is r, and the number of watermark bits is l. The generation of the watermark error correction code consists of three steps: pseudo-random seed generation, original watermark signal generation, and redundancy coding, with the number of bits being n.

[0075] First, use the current timestamp and the random salt value s to generate the pseudo-random seed , as shown in the following formula: ; Among them, SHA-1 indicates the use of the SHA-1 hash function, and || represents the concatenation operation, which concatenates the current timestamp and the random salt value in string form. Then, according to the pseudo-random seed , a pseudo-random number sequence R of length l is generated using a pseudo-random number generator. Among them, the random numbers in R take values in the range (0, 1), as shown in the following formula: ; According to the pseudo-random number sequence R, a watermark signal W is generated by mapping the element values of the pseudo-random number sequence, as shown in the following formula: ; Among them, represents the i-th bit of the watermark signal, represents the i-th element value of the pseudo-random number sequence. The watermark signal W is composed of multiple bit positions represented by '0' and '1', and can be expressed as a binary array of length l as shown in the following formula.

[0076] ; After obtaining the watermark signal W, the next step is to generate a watermark error correction code through redundant coding . To enhance the robustness of the watermark signal and resist the damage of network jitter and other interferences to part of the watermark signal, redundant coding is introduced. When the redundancy is r, each bit of the watermark signal W will be transmitted r times repeatedly to improve the reliability of the watermark signal. The length of the watermark error correction code is , for each bit of the watermark signal randomly select r from n positions to obtain the subscript vector as , fill in these subscript positions with , and finally generate the watermark error correction code , and the subscript vector corresponding to each bit of the watermark signal is used as the shared parameter between the watermark embedding end and the watermark detection end.

[0077] Step S13: Watermark embedding. Let there be a total of data packets in the time slot , and the corresponding data packet length is . Denote the flow transmission rate of this time slot as ; If there is no data packet transmission in the time slot , the flow transmission rate of this time slot is denoted as 0.

[0078] For each bit of the watermark error correction code, there is a corresponding time slot block For embedding the bit watermark, where . First, use the basic time slot of the time slot block to calculate its two sub-time slots , of the streaming transmission rate and . Obtain the basic watermark bit of the time slot block according to their size relationship , which is used in combination with the watermark error correction code , as shown in the following formula: ; To enhance the concealment of watermark embedding, according to the watermark error correction code corresponding to the time slot block and the basic watermark bit , obtain the actual embedded watermark signal through an exclusive OR operation, as shown in the following formula: ; The last 8 time slots of each time slot block are marked time slots , which distinguish the even time slot group and the odd time slot group , and the expression is as follows: ; ; Define the aggregate centroid of the even time slot group in a single time slot block as , and the aggregate centroid of the odd time slot group as , which is calculated from the time slot centroid and the number of packets in the time slot, as shown in the following formula: ; ; Among them, represents the number of packets of the data packet in the j-th time slot in the even time slot group, represents the time slot centroid of the j-th time slot in the even time slot group, represents the number of packets of the data packet in the j-th time slot in the odd time slot group, represents the time slot centroid of the j-th time slot in the odd time slot group, represents the number of time slots in the even time slot group or the odd time slot group.

[0079] The expected values of the aggregate centroids of the even time slot group and the odd time slot group are calculated as follows: ; The calculation formula for the difference between the centroids of the odd and even time slot groups is: ; Then the expected value of the difference between the centroids of the odd and even time slot groups is: ; For a time slot block , if the embedded true embedded watermark signal is 1, increase the value of the centroid of the even time slot group aggregation such that is a positive value; on the contrary, if the embedded true embedded watermark signal is 0, then by increasing the value of such that is a negative value; where, let be the jth data packet within the time slot interval, and the offset relative to the start time stamp of this time slot is uniformly distributed within the interval. Add a delay to this data packet, and the calculation formula is: ; where the value range of the a parameter is , and the new offset of this data packet after adding the delay will be uniformly distributed within the interval. This delay strategy compresses the relative offset that was originally within the interval to the interval. The expected values of the centroid of the even time slot group aggregation and the centroid of the odd time slot group aggregation obtained after using the aforementioned delay strategy are shown in the following formula: ; Let be the result after embedding the watermark bit "1" in the centroid of the even time slot group aggregation, be the result after embedding the watermark bit "0" in the centroid of the odd time slot group aggregation, and its expected value is shown in the following formula: ; In summary, the embedding of "1" or "0" in the true watermark bit will cause the of the time slot block to shift to the right or to the right by , and the implementation method is as follows Figure 4 shown.

[0080] Step S14: Watermark detection. After the watermark information is embedded, the target network flow f is forwarded through the Tor network and reaches the egress relay node where the watermark detection module is deployed. The watermark detection party is responsible for listening to the target network flow sent to the suspected receiver . The following introduces the specific process of watermark information detection: Synchronization of watermark embedding and detection: After receiving the data stream, the watermark detection end needs to wait for the time offset , which is the time offset required for the watermark detection module and the watermark embedding module to synchronize. , where , represents the sum of the transmission delay and time perturbation required from the watermark embedding end to reach the watermark detection end through the Tor network transmission, and is an empirical coefficient. After the watermark detection end passes the time offset , it starts the next operation.

[0081] Watermark error correction code restoration: After the watermark detection end completes time synchronization, it performs time slot block start splitting on the data stream . Using the same time slot interval length T, the number of bits n of the watermark error correction code, and other parameters as the watermark embedding end, it performs time slot block splitting on the captured data stream . It extracts the watermark error correction code from the stream. For each time slot block , first calculate the stream transmission rate of the basic time slot in this time slot block and , calculate the aggregated centroids of the even time slot group and the odd time slot group within this time slot block and , and subtract them to get . Then, from and , restore the basic watermark bit within the time slot block. If , then restore the true watermark bit to '1', otherwise restore it to '0'. Next, according to the basic watermark bit calculated from the time slot block and the true watermark bit , calculate the watermark error correction code bit . Repeat the above steps to finally obtain the detected watermark error correction code .

[0082] Original watermark signal extraction: After detecting the watermark error correction code , according to the redundancy rule during watermark embedding, that is, the mapping subscript vector of the original watermark signal bits at the subscripts of the watermark error correction code, extract the original watermark signal. Let the jth subscript vector , analyze the watermark error correction codes restored at the positions of the r subscripts of this subscript vector, and restore the ith original watermark signal , and the calculation formula is as shown in the following formula. Finally, extract the original detected watermark signal from the watermark detection error correction code.

[0083] Step S5, homology determination. After the above steps, finally, according to the original watermark information and the original detected watermark signal extracted in the previous step Determine the traffic homology. Calculate and the difference between them, and use the Hamming distance to measure it, denoted as . Set a threshold . According to whether it is lower than , determine whether the traffic is homologous, and confirm the communication relationship between the receiving end and the sending end.

[0084] ; Correspondingly to the above method, the present invention also provides a device / system. The device / system includes a computer device, the computer device includes a processor and a memory, the memory stores computer instructions, and the processor is used to execute the computer instructions stored in the memory. When the computer instructions are executed by the processor, the device / system implements the steps of the method described above.

[0085] The embodiment of the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the steps of the foregoing edge computing server deployment method. The computer-readable storage medium can be a tangible storage medium, such as a random access memory (RAM), memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, register, floppy disk, hard disk, removable storage disk, CD-ROM, or any other form of storage medium known in the technical field.

[0086] In summary, for the watermark embedding method, detection method and device for Tor network traffic of the present invention, the watermark embedding end divides the data stream into time slot blocks according to the product of the redundancy of the watermark to be embedded and the number of bits. The first two of each time slot block are used as basic time slots to generate dynamic basic watermark bits, and the rest are used as embedding time slots to add watermarks. A watermark signal is constructed based on redundant coding and basic watermark bits. In the embedding time slot part of each time slot block, a watermark bit is embedded by adding a time delay to adjust the expected value of the centroid difference between the even and odd time slot groups through the even time slot group or the odd time slot group to distinguish binary values; after dividing the time slot block at the watermark detection end, distinguish the basic time slot and the embedding time slot, and detect the embedded true watermark bit by calculating the expected value of the centroid difference between the even and odd time slot groups in the embedding time slot, recover the watermark error correction code bit and obtain the complete watermark error correction code, and extract the original watermark signal based on the shared subscript vector. The present invention uses the basic time slot rate to generate a dynamic watermark benchmark, and realizes the deep coupling of the watermark signal and the original traffic through the exclusive OR operation with the error correction code, greatly reducing the interference to the statistical characteristics of the network traffic and adapting to complex network environments.

[0087] Furthermore, the watermark detection end significantly improves the accuracy of watermark extraction in complex network environments by statistically analyzing the sign of the expected value of the centroid difference rather than the absolute time delay value.

[0088] Furthermore, the distributed embedding strategy based on shared subscript vectors enhances the security of the watermark system. By randomly dispersing the watermark bits in multiple time slot blocks and using a dynamically generated pseudo-random sequence to determine the embedding position, it is difficult for attackers to locate the watermark features through local traffic analysis. The dynamic seed is generated by combining the timestamp and random salt value to ensure that each embedded watermark pattern is unique and non-replicable, effectively preventing replay attacks.

[0089] Furthermore, it is suitable for high-anonymity scenarios such as the Tor network, and achieves low visibility and high reliability of watermark embedding without destroying the traffic statistics characteristics. Through the synergy of the multi-level error correction mechanism and the dynamic synchronization strategy, the detection end can accurately restore the original watermark signal by only sharing a small amount of information such as the subscript vector, providing an effective technical means for tracing the anonymous network flow.

[0090] It should be understood by those skilled in the art that the exemplary components, systems and methods described in conjunction with the embodiments disclosed herein can be implemented in hardware, software or a combination of the two. Whether it is performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention. When implemented in hardware, it can be, for example, an electronic circuit, an application-specific integrated circuit (ASIC), appropriate firmware, a plug-in, a function card, etc. When implemented in software, the elements of the present invention are programs or code segments used to perform the required tasks. The program or code segment can be stored in a machine-readable medium, or transmitted on a transmission medium or a communication link via a data signal carried in a carrier.

[0091] It should be clear that the present invention is not limited to the specific configuration and processing described above and shown in the figures. For the sake of simplicity, a detailed description of the known method is omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present invention is not limited to the specific steps described and shown, and those skilled in the art can make various changes, modifications and additions, or change the order between the steps after understanding the spirit of the present invention.

[0092] In the present invention, features described and / or illustrated for one embodiment may be used in the same or similar manner in one or more other embodiments, and / or combined with features of other embodiments or replace features of other embodiments.

[0093] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, various modifications and variations can be made to the embodiments of the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A watermark embedding method for Tor network flow, characterized in that: The method is used to be executed at a watermark embedding end of a Tor network, and the method comprises the following steps: Divide the data stream to be processed into a first number of time slot blocks after a first set time offset, wherein the first number is the product of the redundancy of the watermark to be embedded and the number of bits; divide each time slot block into a plurality of time slots according to a first time length, wherein the first two time slots in each time slot block are used as basic time slots, and the remaining time slots are used as embedded time slots; determine the basic watermark bit according to the transmission rate of the stream in the basic time slot; For each bit in the watermark signal, randomly select a second number of time slot blocks in the first number of time slot blocks to determine the embedding position and record it as a subscript vector to be shared with the watermark detection end, wherein the second number is equal to the redundancy of the watermark to be embedded; Generate a pseudo-random seed according to the current timestamp and the random salt value through a hash function, input the pseudo-random seed into a pseudo-random generator to generate a pseudo-random number sequence element value with a length equal to the number of bits, and then map it into the watermark signal in the form of a binary array; perform redundant encoding on the watermark signal according to the redundancy of the watermark to be embedded and the subscript vector to obtain a watermark error correction code; perform an XOR operation on the watermark error correction code and the basic watermark bit to obtain a real embedded watermark signal; The time slots in each time slot block are distinguished into an even time slot group and an odd time slot group, and the expected value of the centroid difference of the odd and even time slot groups is adjusted by adding a delay to the even time slot group or the odd time slot group to distinguish the binary value, so as to embed the real embedded watermark signal into the embedded time slot part of each time slot block of the data stream according to the subscript vector, so as to be detected and checked at the watermark detection end.

2. The watermark embedding method for Tor network flow according to claim 1 is characterized in that: The number of the basic time slots is only 2, and the number of the embedded time slots is an even number; The method determines the basic watermark bit according to the transmission rate of the flow in the basic time slot, and the calculation formula is: ; in, Indicates the first basic time slot, Indicates the second basic time slot, represents the stream transmission rate in the first basic time slot, represents the streaming rate in the second basic time slot, represents the basic watermark bit; The calculation formula for the flow transmission rate is: ; Among them, I i represents the i-th time slot, L ij represents the length of the jth data packet in the i-th time slot, k i represents the number of packets in the i-th time slot.

3. The watermark embedding method for Tor network flow according to claim 2 is characterized in that: A pseudo-random seed is generated through a hash function based on the current timestamp and a random salt value. The calculation formula is: ; Among them, SHA-1 means using the SHA-1 hash function, || means the concatenation operation, Represents the current timestamp, s represents the random salt value; The input pseudo-random generator generates a pseudo-random number sequence element value with a length equal to the number of bits, and the calculation formula is: ; Wherein, R represents the element value of the pseudo-random number sequence, and its value range is (0,1); PRNG represents the random number generation algorithm; and length represents the length of the generated random number; The watermark signal mapped to a binary array is expressed as: ; in, represents the i-th bit of the watermark signal, represents the i-th element value of the pseudo-random number sequence; The watermark error correction code and the basic watermark bit are subjected to an XOR operation to obtain the real embedded watermark signal, which is expressed as: ; in, represents the i-th bit of the real embedded watermark signal, represents the i-th bit of the watermark error correction code, Represents the i-th bit of the basic watermark bit.

4. The watermark embedding method for Tor network flow according to claim 3 is characterized in that: The method includes distinguishing an even time slot group and an odd time slot group for the time slots in each time slot block, and distinguishing a binary value by adding a time delay to the even time slot group or the odd time slot group to adjust the expected value of the centroid difference of the odd and even time slot groups, so as to embed the real embedded watermark signal into the embedded time slot part of each time slot block of the data stream according to the subscript vector, including: Define the aggregate centroid of the even time slot groups in a single time slot block as , the aggregate centroid of the odd time slot group is , the calculation formula is: ; ; in, represents the number of packets of the jth time slot in the even time slot group, represents the time slot centroid of the jth time slot in the even time slot group, represents the number of data packets in the jth time slot in the odd time slot group, represents the time slot centroid of the jth time slot in the odd time slot group, Indicates the number of time slots in the even time slot group or the odd time slot group; The calculation formula of the centroid difference of the odd and even time slot groups is: ; Then the expected value of the centroid difference of the odd and even time slot groups is: ; For time slot blocks , if the embedded real watermark signal If it is 1, the even time slot group aggregation centroid is increased The value of is a positive value; on the contrary, if the embedded real watermark signal is 0, by increasing The value of is a negative value; For time slot The jth data packet in the interval has an offset relative to the start timestamp of the time slot. exist The interval is evenly distributed, adding delay to the data packet , the calculation formula is: ; The value range of parameter a is .

5. A watermark detection method for Tor network flow, characterized in that: The method is executed at a watermark detection end and is used to detect a watermark embedded by the watermark embedding method for a Tor network stream according to any one of claims 1 to 4. The method comprises the following steps: After receiving the data stream, wait for a second set time offset to perform the next operation; After time synchronization is performed, the data stream is divided into a first number of time slot blocks, where the first number is the product of the redundancy of the watermark to be embedded and the number of bits; each time slot block is divided into a plurality of time slots according to the first time length, the first two time slots in each time slot block are used as basic time slots, and the remaining time slots are used as embedded time slots; For each time slot block, the transmission flow rate of the basic time slot is calculated, and the corresponding basic watermark bit is determined; the embedded time slot is divided into an even time slot group and an odd time slot group, and the expected value of the centroid difference of the odd and even time slot groups is calculated. If it is greater than 0, the corresponding real watermark bit is restored to 1, and if it is less than 0, the corresponding real watermark bit is restored to 0; according to the basic watermark bit and the real watermark, the corresponding watermark error correction code bit is solved, and the operation is repeated for each time slot block to obtain a complete watermark error correction code; An original watermark signal is extracted from the watermark error correction code based on the shared index vector.

6. The watermark detection method for Tor network flow according to claim 5 is characterized in that: The method further comprises comparing the original watermark signal extracted at the current time step with the original watermark signal extracted at the previous time step to calculate the Hamming distance, and if the Hamming distance is lower than a set value, it is determined that the two watermark signals are of the same source, otherwise, they are of different sources.

7. The watermark detection method for Tor network flow according to claim 6 is characterized in that: The original watermark signal is extracted from the watermark error correction code based on the shared subscript vector, and the calculation formula is as follows: ; in, represents the extracted original watermark signal, r represents the watermark redundancy, represents the subscript vector of the i-th bit of the original watermark signal, Represents the watermark error correction code of the kth bit.

8. A watermark embedding and detection device for Tor network flow, comprising a processor, a memory and a computer program / instruction stored in the memory, characterized in that: The processor is used to execute the computer program / instructions. When the computer program / instructions are executed, the device implements the steps of the method according to any one of claims 1 to 7.

9. A computer-readable storage medium having a computer program / instruction stored thereon, characterized in that: When the computer program / instructions are executed by a processor, the steps of the method as claimed in any one of claims 1 to 7 are implemented.

10. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Tor dark network user tracing method and system based on time slot watermark

    CN111711597A

  • Interval Centroid Based Watermark

    US20080232363A1