Media data playing method, tracing method, device and protection system
By embedding digital watermarks based on the target key signature generated by the identity private key and the authentication public key in the video conference, the problem of watermarks being easily erased and malicious forgery in the video conference is solved, and the authenticity verification of media data and user privacy protection are achieved.
Patent Information
- Application Number
- CN202311873583.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-29
- Publication Date
- 2025-07-01
AI Technical Summary
In existing video conferencing, digital watermarking technology has the problem of being easily erased and maliciously forged and framed, and cannot effectively protect user privacy and the authenticity of media data.
By embedding the digital watermark in the media data based on the identity private key held by the terminal and the target key signature generated by the authentication public key provided by the authentication party, only the authenticator has traceability rights and the privacy of the terminal user is protected.
It realizes the authenticity verification and traceability of media data, prevents others from maliciously counterfeiting watermarks from leaking media data, protects user privacy, and reduces the risk of malicious counterfeiting and disclosure.
Smart Images

Figure CN120238710A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular to a method for playing media data, a method for tracing the source, a device, and a protection system. Background Art
[0002] With the development of information technology, information security issues have become prominent. To address issues such as multimedia copyright infringement and illegal recording and leakage of information, extensive exploration has been carried out in the fields of encryption and digital watermarking. Encryption technology can achieve the secure transmission of media data between the provider and the recipient. However, after the recipient obtains the encrypted information and decrypts it to obtain the plaintext media data, the encryption technology no longer provides protection. Subsequently, if the recipient re-transmits the media data or it is illegally recorded during playback, it will result in the illegal leakage of the media data. Digital watermarking technology can embed copyright information or the recipient's user information into the media data to protect the copyright of the media data, prove the authenticity and reliability of the product, track piracy, or provide additional information about the product. The key to implementing digital watermarking technology lies in how to generate and embed a secure and reliable digital watermark in the media data. Summary of the Invention
[0003] This application provides a method for playing media data, a method for tracing the source, a device, and a protection system.
[0004] In a first aspect, a method for playing media data is provided. The method is applied to a terminal. The method includes: the terminal obtains the authentication attribute information of the media data to be played, and the authentication attribute information is used to identify the playback source range of the media data. The terminal generates a digital watermark according to the authentication attribute information, and the digital watermark includes the authentication attribute information and the signature information obtained by signing the authentication attribute information with a target key. The target key is obtained based on the identity private key held by the terminal and the authentication public key provided by the authenticator. Only the authenticator has the right to trace the media data. The terminal embeds the digital watermark in the media data and plays the media data embedded with the digital watermark.
[0005] In this application, by carrying the authentication attribute information of media data in the digital watermark and the signature information obtained by signing the authentication attribute information with a target key, the authentication attribute information in the digital watermark can declare the playback source range of the media data, acting as the identity information of the media data, thereby narrowing the traceability range of the media data. The signature information in the digital watermark is used to ensure the authenticity of the authentication attribute information of the media data, that is, to ensure the authenticity of the media data. Since the target key is obtained based on the identity private key held by the terminal and the authentication public key provided by the authenticator, as long as the identity private key held by the terminal is not leaked, other user terminals cannot calculate the target key, and thus cannot calculate the signature information using the target key to forge the watermark. Therefore, it can prevent others from maliciously forging the watermark to leak media data for framing. In addition, in this application, the playback source of the media data is proved by the signature information, rather than directly carrying the user or device identity information in the digital watermark. Therefore, it can also avoid the leakage of user or device identity information.
[0006] In the first possible implementation manner, the terminal uses a key negotiation algorithm to generate a target key for the identity private key and the authentication public key. Correspondingly, the implementation manner for the terminal to sign the authentication attribute information with the target key includes: the terminal uses the target key to sign the authentication attribute information based on a symmetric signature algorithm to obtain a symmetric signature value, and the signature information is the symmetric signature value, or the signature information is a truncated result value of the symmetric signature value.
[0007] In this implementation manner, only the authenticator and the terminal can calculate the same symmetric key. As long as the identity private key held by the terminal and the authentication private key held by the authenticator are not leaked, any third party other than the terminal and the authenticator cannot calculate the target key, and thus cannot calculate the signature information using the target key to forge the watermark. Therefore, it can prevent others from maliciously forging the watermark to leak media data for framing. In addition, this application can perform truncation processing on the symmetric signature value to use the truncated result value as the watermark information to be embedded in the media data, which can reduce the watermark embedding capacity, thereby ensuring the fidelity and robustness of the media data (especially audio data) after embedding the watermark information.
[0008] Optionally, in the above first possible implementation manner, the authentication public key is jointly provided by multiple approvers, and the authentication public key is a distributed key generation (DKG) public key. The multiple approvers jointly hold n private key shards and the number of private key shards held by each approver is less than t. The DKG public key is calculated based on the n private key shards, and the private key corresponding to the DKG public key is obtained based on at least t private key shards among the n private key shards. Among them, n is an integer greater than 1, and 2 ≤ t ≤ n.
[0009] In this implementation method, the authenticator needs to rely on multiple approvers to recover the private key corresponding to the authentication public key, and further combine the identity public key held by the terminal to calculate the same key as the target key used by the terminal to generate the digital watermark. Compared with the solution where the authenticator directly holds the authentication private key, in this solution, since the authenticator is supervised by multiple approvers, the risk that the authenticator maliciously imitates the watermark to frame the end user can be reduced, the reliability of the authenticator and the watermark security are improved, and the reliability of watermark tracing is further improved.
[0010] In the second possible implementation method, the terminal uses an asymmetric key generation algorithm to generate a target key for the identity private key and the authentication public key. Correspondingly, the implementation method for the terminal to sign the authentication attribute information with the target key includes: the terminal uses the target key to sign the authentication attribute information based on the asymmetric signature algorithm to obtain an asymmetric signature value, and the signature information is this asymmetric signature value.
[0011] In this implementation method, only the terminal can calculate the target key used to generate the digital watermark, which can prevent any third party, including the authenticator, from maliciously imitating the watermark and leaking media data for framing. In addition, only the authenticator can calculate the key that can verify the digital watermark generated by the terminal, that is, only the authenticator has the right to trace the media data played by the terminal, which can well protect the privacy of the end user.
[0012] Optionally, an implementation method for the terminal to use an asymmetric key generation algorithm to generate a target key for the identity private key and the authentication public key includes: the terminal uses a key derivation function to generate a derived key based on the identity private key and the authentication public key. The terminal generates the target key according to the derived key and the identity private key.
[0013] Optionally, the target key is SK, SK = (K + SKu) mod q. Where SKu is the identity private key, K is the derived key, q is a prime number, mod q means taking the modulus of q, and the value range of SK is [1, q).
[0014] Optionally, the terminal sends a key acquisition request to the authenticator, and the key acquisition request includes the device identifier of the terminal. The terminal receives a key acquisition response sent by the authenticator, and the key acquisition response includes the authentication public key.
[0015] Optionally, the terminal is a conference terminal participating in a conference, and the media data comes from this conference. The authentication attribute information may include the conference identifier of this conference and / or the conference timestamp information of the conference.
[0016] Optionally, the terminal receives media data sent by other conference terminals participating in this conference.
[0017] Second aspect, a method for tracing media data is provided. This method is applied to the authenticator. The method includes: The authenticator obtains the digital watermark in the media data to be traced. The digital watermark includes the authentication attribute information of the media data and the signature information obtained based on the authentication attribute information. The authentication attribute information is used to identify the playback source range of the media data. The authenticator determines the playback source range according to the authentication attribute information. The authenticator generates a first key based on the authentication private key held by the authenticator and the first identity public key held by the first terminal, where the first terminal is any terminal within the playback source range. The authenticator verifies the signature information based on the first key and the authentication attribute information to determine whether the media data comes from the first terminal.
[0018] In this application, since only the authenticator that provides the authentication public key to the terminal can calculate the key for verifying the digital watermark generated by the terminal, only the authenticator has the authority to trace the media data. Even if other terminal users extract the digital watermark in the media data, they cannot trace the playback source of the media data, which can protect the user privacy of the playback source and reduce the risk of leakage of the playback source information at the same time.
[0019] The first possible implementation manner, the implementation manner in which the authenticator generates the first key based on the authentication private key held by the authenticator and the first identity public key held by the first terminal, includes: The authenticator uses a key agreement algorithm to generate the first key for the authentication private key and the first identity public key. Correspondingly, the implementation manner in which the authenticator verifies the signature information based on the first key and the authentication attribute information includes: The authenticator signs the authentication attribute information based on the first key using a symmetric signature algorithm to obtain a symmetric signature value; if the signature information matches the symmetric signature value, the authenticator determines that the media data comes from the first terminal.
[0020] In this implementation manner, only the authenticator and the terminal can calculate the same symmetric key. As long as the identity private key held by the terminal and the authentication private key held by the authenticator are not leaked, any third party other than the terminal and the authenticator cannot calculate the target key, and thus cannot calculate the signature information using the target key to forge the watermark. Therefore, it can prevent others from maliciously forging the watermark to leak the media data for framing.
[0021] Optionally, in the above first possible implementation manner, the authentication public key corresponding to the authentication private key is jointly provided by multiple approvers. The authentication public key is a DKG public key. The multiple approvers jointly hold n private key shards and the number of private key shards held by each approver is less than t. The DKG public key is calculated based on the n private key shards, and the authentication private key is obtained based on at least t private key shards among the n private key shards, where n is an integer greater than 1 and 2 ≤ t ≤ n.
[0022] In this implementation method, the authenticator needs to rely on multiple approvers to recover the private key corresponding to the authentication public key, and further combine it with the identity public key held by the terminal to calculate the same key as the target key used by the terminal to generate the digital watermark. Compared with the scheme where the authenticator directly holds the authentication private key, in this scheme, since the authenticator is supervised by multiple approvers, the risk of the authenticator maliciously forging watermarks to frame the terminal user can be reduced, the reliability of the authenticator and the watermark security are improved, and the reliability of watermark traceability is further enhanced.
[0023] Optionally, the length of the signature information is less than the length of the symmetric signature value. If the signature information matches the symmetric signature value, the implementation method for the authenticator to determine that the media data comes from the first terminal includes: if the signature information is the same as the truncated result value of the symmetric signature value, the authenticator determines that the media data comes from the first terminal.
[0024] The second possible implementation method, the implementation method for the authenticator to generate the first key according to the authentication private key held by the authenticator and the first identity public key held by the first terminal includes: the authenticator uses an asymmetric key generation algorithm to generate the first key for the authentication private key and the first identity public key. Correspondingly, the implementation method for the authenticator to verify the signature information based on the first key and the authentication attribute information includes: the authenticator uses the first key to perform signature verification on the authentication attribute information and the signature information; if the signature verification passes, the authenticator determines that the media data comes from the first terminal.
[0025] In this implementation method, only the terminal can calculate the target key used to generate the digital watermark, which can prevent any third party, including the authenticator, from maliciously forging watermarks and leaking media data for framing. In addition, only the authenticator can calculate the key that can verify the digital watermark generated by the terminal, that is, only the authenticator has the authority to trace the media data played by the terminal, which can well protect the privacy of the terminal user.
[0026] Optionally, the implementation method for the authenticator to use an asymmetric key generation algorithm to generate the first key for the authentication private key and the first identity public key includes: the authenticator uses a key derivation function to generate a derived key based on the authentication private key and the first identity public key. The authenticator generates the first key according to the derived key and the authentication private key.
[0027] Optionally, the first key is PK, PK = gK·PKu, where PKu is the first identity public key, K is the derived key, and g is the primitive root of the prime number q.
[0028] Optionally, the authenticator receives a key acquisition request sent by a terminal within the playback source range, and the key acquisition request includes the device identifier of the terminal. The authenticator sends a key acquisition response to the terminal, and the key acquisition response includes the authentication public key corresponding to the authentication private key.
[0029] Optionally, there are multiple terminals within the playback source range. If it is determined that the media data does not come from the first terminal, the authenticator generates a second key based on the authentication private key and the second identity public key held by the second terminal, where the second terminal is any terminal other than the first terminal within the playback source range. The authenticator verifies the signature information based on the second key and the authentication attribute information to determine whether the media data comes from the second terminal.
[0030] In this application, the authenticator can traverse and verify all terminals within the playback source range of the media data until the terminal from which the media data comes is determined.
[0031] Optionally, the authentication attribute information includes a meeting identifier and / or meeting timestamp information. The authenticator determines the implementation method of the playback source range according to the authentication attribute information, including: the authenticator determines the meeting to which the media data belongs according to the authentication attribute information, and determines that the playback source range includes the meeting terminals participating in the meeting.
[0032] In a third aspect, a playback device for media data is provided. The device includes a plurality of functional modules that interact with each other to implement the methods in the first aspect and its various embodiments above. The plurality of functional modules can be implemented based on software, hardware, or a combination of software and hardware, and the plurality of functional modules can be arbitrarily combined or divided based on specific implementations.
[0033] In a fourth aspect, a tracing device for media data is provided. The device includes a plurality of functional modules that interact with each other to implement the methods in the second aspect and its various embodiments above. The plurality of functional modules can be implemented based on software, hardware, or a combination of software and hardware, and the plurality of functional modules can be arbitrarily combined or divided based on specific implementations.
[0034] In a fifth aspect, a protection system for media data is provided, including: a terminal and an authenticator. The terminal is used to execute the methods in the first aspect and its various embodiments above, and the authenticator is used to execute the methods in the second aspect and its various embodiments above.
[0035] Optionally, the system is a video conferencing system, the terminal is a meeting terminal, and the authenticator is a meeting management party.
[0036] In a sixth aspect, a terminal is provided, including: a processor and a memory; the memory is used to store a computer program, and the computer program includes program instructions; the processor is used to call the computer program to implement the methods in the first aspect and its various embodiments above.
[0037] In a seventh aspect, a computer device is provided, including: a processor and a memory; the memory is used to store a computer program, and the computer program includes program instructions; the processor is used to call the computer program to implement the methods in the second aspect and its various embodiments described above.
[0038] In an eighth aspect, a computer-readable storage medium is provided. Instructions are stored on the computer-readable storage medium, and when the instructions are executed by a processor, the methods in the first aspect and its various embodiments described above are implemented, or the methods in the second aspect and its various embodiments described above are implemented.
[0039] In a ninth aspect, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the methods in the first aspect and its various embodiments described above are implemented, or the methods in the second aspect and its various embodiments described above are implemented.
[0040] In a tenth aspect, a chip is provided. The chip includes a programmable logic circuit and / or program instructions. When the chip runs, the methods in the first aspect and its various embodiments described above are implemented, or the methods in the second aspect and its various embodiments described above are implemented. Description of the Drawings
[0041] Figure 1 It is a schematic diagram of the implementation of a digital watermarking technology provided by an embodiment of the present application;
[0042] Figure 2 It is a schematic diagram of a video conferencing scenario provided by an embodiment of the present application;
[0043] Figure 3 It is a schematic diagram of the implementation process of a visible watermark algorithm provided by the related art;
[0044] Figure 4 It is a schematic diagram of the implementation process of a watermark algorithm combined with symmetric encryption provided by the related art;
[0045] Figure 5 It is a schematic diagram of an application scenario provided by an embodiment of the present application;
[0046] Figure 6 It is a schematic diagram of the process of a method for playing media data provided by an embodiment of the present application;
[0047] Figure 7 It is a schematic diagram of the process of a method for tracing media data provided by an embodiment of the present application;
[0048] Figure 8 It is a schematic diagram of a copyright authentication scenario of media data provided by an embodiment of the present application;
[0049] Figure 9It is a schematic diagram of a leakage location scenario for media data provided by an embodiment of the present application;
[0050] Figure 10 It is a schematic structural diagram of a media data playback device provided by an embodiment of the present application;
[0051] Figure 11 It is a schematic structural diagram of a media data traceability device provided by an embodiment of the present application;
[0052] Figure 12 It is a schematic hardware structure diagram of a computer device provided by an embodiment of the present application. Detailed implementation manners
[0053] To make the objectives, technical solutions, and advantages of the present application clearer, the following will further describe the embodiments of the present application in detail with reference to the accompanying drawings.
[0054] Digital watermarking technology is a kind of information hiding technology. The watermark information is embedded in the carrier file without affecting the observability and integrity of the original file. The application of digital watermarking technology is very extensive, including fields such as copyright protection, anti-counterfeiting, digital forensics, and information hiding. Currently, digital watermarking technology has become one of the important means for digital media security protection. For example, Figure 1 It is a schematic diagram of the implementation of a digital watermarking technology provided by an embodiment of the present application. As Figure 1 shown, it generates a watermark from specific identification information (which can be the creator of the digital media, the user serial number, or the copyright information, etc.) and embeds it into the digital media information carrier. By performing watermark detection on the digital media containing the watermark, the embedded watermark information can be extracted, thereby indicating some information of the digital media itself. Digital watermarks can be embedded in various digital media, such as images, audio, video, and text, etc. According to the perceptibility of the digital watermark, digital watermarks can be divided into visible watermarks and invisible watermarks.
[0055] Visible watermarks refer to watermarks that are perceptually visible, such as logos inserted or overlaid on images. Visible watermarks usually refer to directly embedding visible information in digital media, such as text or images, etc. Visible watermarks are generally used to visually identify images or videos obtained in a video database or on the Internet to prevent these images from being used for illegal commercial purposes. Similarly, audible watermarks are watermarks that are auditorily perceptible in audio. Invisible watermarks refer to embedding invisible information in digital media, such as digital codes or noises, etc. After embedding an invisible watermark in digital media, the digital media itself is not damaged too much and can retain the original playback quality. When needed, the owner can extract the watermark from the digital media through a watermark detection algorithm to prove the ownership or integrity, etc. of the digital media.
[0056] The basic characteristics of digital watermarking mainly include fidelity, robustness, and capacity. Fidelity is used to measure the similarity of a signal before and after being processed. After embedding watermark information into digital media information, it should meet certain perceptual requirements, which may or may not be visible watermarks, depending on the application scenario. Robustness refers to the extractability and detectability of the watermark in digital media information with watermarking after undergoing various signal processing or various attacks. The measurement indicators of robustness include vulnerability, effectiveness, and security. Capacity, also known as embedding rate, loading rate, or payload, refers to the maximum number of watermark bits that can be embedded per unit time or in a media digital work. The larger the capacity of the digital watermark, the more watermark information can be embedded. However, if the capacity of the digital watermark is too large, it will affect fidelity or robustness.
[0057] With the development of information technology, the problem of illegal leakage of media data has become increasingly serious. In related technologies, digital watermarking is proposed to be embedded in media data to achieve the identification and tracking of media data. Media data includes, but is not limited to, audio data, video data, file data, and other digitalized streaming media data, such as remote shared desktops, remote shared documents, and remote shared applications.
[0058] Taking the video conferencing scenario as an example, Figure 2 is a schematic diagram of a video conferencing scenario provided by an embodiment of the present application. As Figure 2 shown, the conference administrator convenes a security conference, the sending-side conference terminal sends audio and video streams, and data transmission is carried out through the conference service platform. The receiving-side conference terminal receives and plays the audio and video streams to complete the end-to-end interaction process. However, during the audio and video playback process, there may be internal leakers who record secretly or forward the played audio and video streams to unauthorized personnel, resulting in data leakage.
[0059] Among them, the act of secret recording includes transcribing with screen recording software or shooting with a camera. It is almost impossible to prevent others from secretly taking pictures and recording by technical means. Therefore, the main idea of anti-secret recording is to trace the secret recorder to deter the act of secret recording. Therefore, digital watermarking technology is particularly important here. As Figure 2As shown in the figure, after the receiving-side conference terminal receives the audio-visual stream, real-time watermark generation and embedding can be performed when playing the audio-visual stream, and the embedded watermark information is bound to the user identity or device identity accessing the conference. Among them, the user identity accessing the conference can be the identity of the user currently logged in to the conference terminal, and the device identity accessing the conference can be the identity of the conference terminal playing the audio-visual stream. In this way, once a piracy behavior (such as surreptitious recording from a distance) occurs, the conference administrator only needs to obtain a small part of the leaked segment in the audio-visual stream, and can extract the watermark information through the watermark extraction algorithm, and identify the device identity and / or user identity in the watermark information, so as to locate the device or user that leaked the data, and realize the traceability of internal leakers. Among them, the security during the transmission process before watermark embedding is guaranteed by end-to-end encryption.
[0060] Currently, most video conferences use visible watermark algorithms for traceability and copyright protection. Specifically, watermark embedding is performed during audio-visual playback, and the watermark information includes device information or user information on the playback side, etc., so that the watermark information is directly displayed on the played video and presented in a visible form to the naked eye. For example, Figure 3 is a schematic diagram of the implementation process of a visible watermark algorithm provided by the related technology. As Figure 3 shown, when the receiving-side conference terminal plays the conference content in real time, the original digital media information is input into the embedder to embed watermark information (including user identifiers or device identifiers) in real time, and finally the watermarked digital media information is obtained. The capacity of the watermark can be set when embedding the watermark. The single-row watermark can be centered, and the multi-row watermark can cover the entire screen. Since the watermark will also be recorded when using screen recording software to record the conference content, and the watermark in the video will also be recorded when surreptitiously recording from a distance. Therefore, by applying this visible watermark algorithm, the presence of the watermark can be detected through the watermark detection algorithm, or the watermark content can be directly observed, omitting the watermark detection step, more intuitively determining the exact source of the video, thus realizing the function of post-event watermark tracing, and also achieving the effect of deterring piracy behavior.
[0061] However, the existing visible watermark algorithms embed the plaintext information of users or devices as watermarks without any encryption and hiding processing. Therefore, everyone can directly observe the presence of the watermark on the digital media, and thus everyone can know the owner of the digital media information, which leaks user privacy information to a certain extent. In addition, visible watermarks are easily maliciously damaged by illegal persons and are difficult to resist various attack forms of watermark algorithms. For example, the visible watermark on the video can be erased, and then it cannot be observed again when it is spread again, and thus cannot be traced. In addition, other users can guess the watermark information of specific users according to the characteristics of visible watermarks, and thus can embed the watermark information of specific users into the video for malicious framing operations.
[0062] Considering the protection of user privacy information, related technologies provide a watermark algorithm combined with cryptography. For example, Figure 4 is a schematic diagram of the implementation process of a watermark algorithm combined with symmetric encryption provided by related technologies. As Figure 4 shown, when the receiving-side conference terminal plays the conference content in real time, the watermark information (user information and / or device information) is encrypted using the symmetric key K to generate a specific watermark, which is embedded in the digital media, and finally the watermarked digital media information is obtained. Then, the watermark information can be extracted using the watermark detection algorithm, and the symmetric key K is used to decrypt the watermark to obtain the specific information contained in the watermark, thereby realizing information traceability. It can be seen that after encrypting the watermark information with the key, the watermark information containing user information and / or device information becomes ciphertext and is no longer presented in plaintext, protecting the privacy of users and preventing malicious forgery and framing by unauthorized users (users without the symmetric key).
[0063] However, due to the use of the symmetric encryption algorithm, the same symmetric key needs to be stored on each legitimate user terminal, which is prone to key leakage. For example, in a video conferencing scenario, multiple conference terminals store the same key to encrypt their own watermark information and embed it in the audio-video stream, so that the conference administrator can use this key to trace the leaked content of the conference to identify the internal leaker later. In addition, since multiple user terminals use the same key to encrypt the watermark information, anyone who holds the symmetric key can encrypt and decrypt, and there will be a problem of malicious forgery of watermarks by internal personnel for framing.
[0064] Based on the above analysis of related technologies, although the visible watermark technology for video conferencing is simple and intuitive, it has the risks of being easily erased and maliciously forged and framed; although the watermark algorithm combined with symmetric encryption improves the security of the watermark, there is still a problem of malicious forgery and framing by internal personnel. Based on this, the present application provides a technical solution, where the key generated based on the identity private key held by the terminal and the authentication public key provided by the authentication party is used to generate the watermark. On the one hand, by binding the identity private key held by the terminal to the watermark information, only the terminal holding this identity private key can generate its own watermark and embed it in the media data. Since the private key usually does not leave the device and the leakage risk is low, other terminal users can be basically prevented from forging watermarks. On the other hand, it is restricted that only the authentication party can recover the key for verifying the watermark information, and by restricting the traceability authority of the media data, the privacy protection of terminal users is realized. Among them, the authentication party is a management party or a trusted institution trusted by the terminal.
[0065] The playback solution for media data provided by this application is as follows. The terminal generates a digital watermark based on the authentication attribute information of the media data to be played. The digital watermark includes the authentication attribute information and the signature information obtained by signing the authentication attribute information with a target key. After embedding the digital watermark in the media data, the terminal plays the media data embedded with the digital watermark. Among them, the authentication attribute information of the media data is used to identify the playback source range of the media data. The target key is obtained based on the identity private key held by the terminal and the authentication public key provided by the authenticator. Since the generation of the target key combines the authentication public key provided by the authenticator, it is equivalent to restricting that only the authenticator holding the authentication private key corresponding to the authentication public key has the right to trace the origin of the media data. By carrying the authentication attribute information of the media data and the signature information obtained by signing the authentication attribute information with the target key in the digital watermark, the authentication attribute information in the digital watermark can declare the playback source range of the media data, acting as the identity information of the media data, thereby narrowing the scope of tracing the origin of the media data. The signature information in the digital watermark is used to ensure the authenticity of the authentication attribute information of the media data, that is, to ensure the authenticity of the media data. Since the target key is obtained based on the identity private key held by the terminal and the authentication public key provided by the authenticator, as long as the identity private key held by the terminal is not leaked, other user terminals cannot calculate the target key, and thus cannot calculate the signature information using the target key to forge the watermark. Therefore, it can prevent others from maliciously forging the watermark and leaking the media data for framing. In addition, in this application, the playback source of the media data is proved by the signature information, rather than directly carrying the user or device identity information in the digital watermark. Therefore, it can also avoid the leakage of user or device identity information.
[0066] Since the key used by the terminal to generate the digital watermark is calculated based on the identity private key held by the terminal and the authentication public key provided by the authenticator, correspondingly, the authenticator can calculate the key for verifying the digital watermark generated by the terminal based on the authentication private key held by the authenticator and the identity public key held by the terminal. Therefore, the authenticator has the ability to trace the media data with embedded digital watermark played by the terminal. In this way, when the copyright information of the media data is questioned, or when the media data is leaked and the leakage source needs to be located, the authenticator can trace and collect evidence for the media data. The media data tracing solution provided in this application is as follows: The authenticator obtains the digital watermark in the media data to be traced. The digital watermark includes the authentication attribute information of the media data and the signature information obtained based on the authentication attribute information. The authentication attribute information is used to identify the playback source range of the media data. The authenticator determines the playback source range of the media data according to the authentication attribute information, then generates a key based on the authentication private key held by the authenticator and the identity public key held by the terminal within the playback source range, and further verifies the signature information in the digital watermark based on the key and the authentication attribute information to determine whether the media data comes from the terminal. In this application, since only the authenticator that provides the authentication public key to the terminal can calculate the key for verifying the digital watermark generated by the terminal, only the authenticator has the tracing authority for the media data. Even if other terminal users extract the digital watermark in the media data, they cannot trace the playback source of the media data, which can protect the user privacy of the playback source and reduce the risk of leakage of the playback source information.
[0067] In the first possible implementation manner, the solution of this application is implemented based on a watermark algorithm combined with symmetric encryption. In this implementation manner, the above-mentioned target key generated by the terminal based on the identity private key held by the terminal and the authentication public key provided by the authenticator is a symmetric key. The terminal uses the target key to sign the authentication attribute information of the media data based on the symmetric signature algorithm to obtain a symmetric signature value. The signature information in the digital watermark includes part or all of the content of the symmetric signature value. Correspondingly, the authenticator uses the authentication private key held by the authenticator and the identity public key held by the terminal to generate the same key as the target key, and uses the key to sign the authentication attribute information in the digital watermark based on the symmetric signature algorithm to obtain a symmetric signature value. If the signature information in the embedded digital watermark in the media data matches the symmetric signature value calculated by the authenticator, the authenticator determines that the media data comes from the terminal holding the identity public key used to generate the key.
[0068] In this implementation method, only the authenticator and the terminal can calculate the same symmetric key. As long as the identity private key held by the terminal and the authentication private key held by the authenticator are not leaked, any third party other than the terminal and the authenticator cannot calculate the target key, and thus cannot use the target key to calculate the signature information to forge the watermark. Therefore, it can prevent others from maliciously forging the watermark to leak media data for framing.
[0069] Optionally, in the above first possible implementation method, the authentication public key held by the authenticator is jointly provided by multiple approvers, and the authentication public key is a DKG public key. The multiple approvers jointly hold n private key shards and the number of private key shards held by each approver is less than t. The DKG public key is calculated based on the n private key shards, and the private key corresponding to the DKG public key is obtained based on at least t private key shards among the n private key shards. Wherein, n is an integer greater than 1, and 2≤t≤n.
[0070] Among them, the DKG public key is a common public key calculated by multiple parties according to n private key shards. The private key corresponding to the DKG public key (abbreviated as DKG private key) is the secure aggregation of the n private key shards. The generation process of the DKG public key essentially belongs to secret sharing. In this application, the recovery threshold of the DKG private key is set to t, that is, any greater than or equal to t private key shards among the n private key shards can recover the DKG private key. The recovery threshold t of the DKG private key can be adjusted according to actual needs to improve the reliable and available resilience. If the authenticator wants to obtain the authentication private key, it needs at least t private key shards. Since the number of private key shards held by each approver is less than t, only when two or more approvers agree can the authenticator recover the authentication private key. That is to say, the authenticator needs to rely on multiple approvers to recover the private key corresponding to the authentication public key, and further combine with the identity public key held by the terminal to calculate the same key as the target key used by the terminal to generate the digital watermark. Compared with the scheme where the authenticator directly holds the authentication private key, in this scheme, since the authenticator is supervised by multiple approvers, the risk of the authenticator maliciously forging the watermark to frame the terminal user can be reduced, the reliability of the authenticator and the watermark security are improved, and the reliability of watermark traceability is further improved.
[0071] Or, in the above first possible implementation method, the authenticator can also generate a public-private key pair including the authentication public key and the authentication private key.
[0072] The second possible implementation mode is that the solution of the present application is implemented based on a watermarking algorithm combined with asymmetric encryption. In this implementation mode, the target key generated by the terminal based on the identity private key held by the terminal and the authentication public key provided by the authentication party is an asymmetric key. The target key is, for example, the private key in a public-private key pair. The terminal uses the target key to sign the authentication attribute information of the media data based on the asymmetric signature algorithm to obtain an asymmetric signature value, and the signature information in the digital watermark is the asymmetric signature value. Correspondingly, the authentication party uses the authentication private key held by the authentication party and the identity public key held by the terminal to generate an asymmetric key corresponding to the target key. The asymmetric key is, for example, the public key corresponding to the target key. Then, the authentication party uses the generated key to perform signature verification on the authentication attribute information and signature information in the digital watermark. If the signature verification passes, the authentication party determines that the media data embedded with the digital watermark comes from the terminal holding the identity public key used to generate the key.
[0073] In this implementation mode, only the terminal can calculate the target key used to generate the digital watermark, which can prevent any third party, including the authentication party, from maliciously forging the watermark to leak media data for framing. In addition, only the authentication party can calculate the key that can verify the digital watermark generated by the terminal, that is, only the authentication party has the right to trace the media data played by the terminal, which can well protect the privacy of terminal users.
[0074] Next, the technical solution of the present application will be introduced in detail from multiple perspectives such as application scenarios, method processes, software devices, hardware devices, and systems.
[0075] Next, the application scenarios of the embodiments of the present application will be illustrated by examples.
[0076] The embodiments of the present application can be applied to various scenarios involving the playback and traceability of media data, and can achieve copyright protection of media data. Optionally, the media data includes but is not limited to audio data, video data, file data, and other digital streaming media data, such as remote shared desktops, remote shared documents, and remote shared applications.
[0077] For example, Figure 5 is a schematic diagram of an application scenario provided by the embodiments of the present application. As Figure 5 shown, this application scenario includes an authentication party and one or more terminals. The terminals and the authentication party are connected through a wired network or a wireless network. Figure 5 Taking the application scenario including three terminals (Terminal A, Terminal B, and Terminal C) as an example, the number of terminals is not a limitation on the application scenario of the present application.
[0078] Optionally, the terminal can be a user terminal such as a mobile phone, a tablet, or a computer. The terminals can transmit media data to each other and play the received media data from other terminals locally. For example, seeFigure 5 , the terminal A sends the media data M to the terminal B and the terminal C respectively, and then the terminal A, the terminal B, and the terminal C play the media data M respectively. If the media data M is leaked, it may be leaked when the terminal A plays it, or it may be leaked when the terminal B plays it, or it may be leaked when the terminal C plays it.
[0079] The authenticator is a management party or a trusted institution trusted by the terminal. The authenticator can be a user terminal, a server, a cloud computing platform, etc. The authenticator is used to provide an authentication public key to the terminal so that the terminal can generate a corresponding key by combining its own identity private key, and further use the generated key to generate a unique digital watermark of the terminal to be embedded in the media data for playback. For example, see Figure 5 , the media data M played by the terminal A is embedded with a digital watermark A, and the digital watermark A binds the identity private key SKa held by the terminal A and the authentication public key PKm provided by the authenticator. The media data M played by the terminal B is embedded with a digital watermark B, and the digital watermark B binds the identity private key SKb held by the terminal B and the authentication public key PKm provided by the authenticator. The media data M played by the terminal C is embedded with a digital watermark C, and the digital watermark C binds the identity private key SKc held by the terminal C and the authentication public key PKm provided by the authenticator. Then, the authenticator can trace the leaked media data M to determine whether the leakage source is the terminal A, the terminal B, or the terminal C. For example, the authenticator uses the authentication private key SKm and the identity public key PKa held by the terminal A to generate a key KEYa, uses the authentication private key SKm and the identity public key PKb held by the terminal B to generate a key KEYb, uses the authentication private key SKm and the identity public key PKc held by the terminal C to generate a key KEYc, and then uses the key KEYa, the key KEYb, and the key KEYc to verify the digital watermark in the leaked media data M respectively to determine whether the digital watermark is the digital watermark A generated by the terminal A, the digital watermark B generated by the terminal B, or the digital watermark C generated by the terminal C, so as to determine the leakage source of the media data M.
[0080] Optionally, Figure 5The application scenario shown is a video conferencing scenario, and the above-mentioned terminal is a conference terminal. The above-mentioned authenticator is the conference management party, such as the conference terminal used by the conference administrator. Usually, a video conference can include multiple participants, and one participant joins the video conference through one conference terminal. The form of the conference terminal can be a dedicated physical device or a software program with conference functions. This software program can run on various computing devices, such as various user terminals like mobile phones, tablets, and computers. In this case, the computing device running this software program can also be considered a conference terminal. The conference terminal joins the video conference through the conference service platform. Specifically, the conference terminal can obtain the media data of the video conference from the conference service platform and send the locally collected media data to the conference service platform so that the conference service platform can forward it to other participating conference terminals. The conference terminals can be connected through a wireless network, enabling participants to join the video conference smoothly without being restricted by geographical locations. In some cases, one participant may only include one participating user. For example, the participating user joins the video conference through the conference software program running on the personal mobile phone. In some cases, one participant can also include multiple participating users. For example, in a conference room scenario, multiple participating users in the conference room join the video conference through one conference terminal in the conference room. Among them, the conference service platform can be a multipoint control unit (MCU).
[0081] In the embodiments of the present application, each terminal holds a public-private key pair representing its own identity, which is called the identity public key and the identity private key. The public key and the private key are a key pair obtained through an algorithm. If the data is encrypted with the public key, it can be decrypted with the private key. If the data is signed with the private key, it can be verified with the public key. The public key is the part of the key pair that is publicly available to the communication peer, and the private key is the non-public part of the key pair. Under normal circumstances, the identity private key held by a terminal cannot be known to any third party, including other terminals and the authenticator.
[0082] In the embodiments of the present application, the identity public key and the identity private key held by the terminal can refer to the device public key and the device private key possessed by the terminal. For example, the dedicated conference terminal equipped in the conference room can be used by one or more users, and the identity public key and the identity private key held by the terminal can refer to the device public key and the device private key possessed by the dedicated conference terminal itself. Or, the identity public key and the identity private key held by the terminal can also refer to the user public key and the user private key of the user logging in to the terminal. For example, if the terminal is a computer device running a conference application program, the identity public key and the identity private key held by the terminal can refer to the user public key and the user private key of the current logged-in user of the conference application program. If the logged-in user is changed, then the identity public key and the identity private key held by the terminal will also change accordingly.
[0083] If the identity public key and identity private key held by the terminal are the device public key and device private key possessed by the terminal, then when the terminal needs to use the identity public key and identity private key, it can directly read the device public key and device private key from the local memory. If the identity public key and identity private key held by the terminal are the user public key and user private key of the user logged in to the terminal, then the terminal can obtain and store the user public key according to the information of the logged-in user when the user logs in, and use the user private key to sign the user public key. This signature is used to prove that the logged-in user holds the private key corresponding to the user public key. In some cases, there may be no logged-in user on the terminal. For example, the conference terminal in the meeting room is public and does not require user login, but during the meeting, it may be bound to a certain participating user or user terminal (temporarily bound). Then, the user public key and user private key of the user bound to the terminal or the device public key and device private key of the user terminal can also be used as the identity public key and identity private key held by the terminal. If the identity public key and identity private key held by the terminal are the user public key and user private key of the user, or the device public key and device private key of the user terminal (such as the user's mobile phone, tablet, etc.), and the terminal and the user terminal are two different physical devices, then the terminal can obtain the user public key or the device public key of the user terminal through means such as Bluetooth, near field communication (NFC), and user input.
[0084] In a video conferencing scenario, multiple conference terminals participating in the conference can pre-send the identity public keys they hold to the conference service platform for storage. The conference service platform can store the identity public keys held by each of the multiple conference terminals in each conference in terms of conferences. The conference can be identified by a conference identifier and / or conference timestamp information. The conference identifier can be, for example, a conference number, and the conference timestamp information can include the start time and end time of the conference. In this way, the conference management party can obtain the identity public keys held by the multiple conference terminals participating in the specified conference from the conference service platform.
[0085] The following gives an example of the method flow of the embodiments of the present application.
[0086] For example, Figure 6 is a schematic diagram of the method flow for playing media data provided by an embodiment of the present application. As Figure 6 shown, method 600 includes but is not limited to the following steps 601 to 604. This method 600 can be applied to Figure 5 any terminal in the application scenario shown.
[0087] Step 601: The terminal obtains the authentication attribute information of the media data to be played, and this authentication attribute information is used to identify the playback source range of the media data.
[0088] Optionally, the authentication attribute information of the media data can indirectly identify the playback source range of the media data. For example, the authentication attribute information of the media data includes the context information of the media data, and the context information can reflect the possible source of the media data, such as from a certain meeting or from a certain website, etc. Further, the terminals that may play the media data can be determined according to the context information. Or, the authentication attribute information of the media data can also directly identify the playback source range of the media data. For example, the authentication attribute information of the media data includes the device identifier of the terminal that may play the media data, etc. For example, in Figure 5 the application scenario shown, the authentication attribute information of the media data M can include the device identifier of terminal A, the device identifier of terminal B, and the device identifier of terminal C, which is used to indicate that the playback source range of the media data M includes terminal A, terminal B, and terminal C. In the embodiments of the present application, the authentication attribute information of the media data is used as an auxiliary index to narrow the traceability range of the media data, and the specific content of the authentication attribute information is not limited.
[0089] Optionally, the embodiments of the present application can be applied to a video conference scenario. The terminal is a conference terminal participating in the conference, and the media data to be played on the terminal comes from the conference. The authentication attribute information of the media data can include the conference identifier of the conference and / or the conference timestamp information of the conference, which is used to indicate that the playback source range of the media data includes all conference terminals participating in the conference.
[0090] Optionally, when the terminal obtains the media data to be played, it can be that the terminal receives the media data sent by other conference terminals participating in the conference, or it can also be that the terminal generates the media data to be played.
[0091] Step 602: The terminal generates a digital watermark according to the authentication attribute information. The digital watermark includes the authentication attribute information and the signature information obtained by signing the authentication attribute information with a target key. The target key is obtained based on the identity private key held by the terminal and the authentication public key provided by the authenticator.
[0092] Among them, only the authenticator has the right to trace the media data. Optionally, the implementation method for the terminal to obtain the authentication public key provided by the authenticator can be that the terminal sends a key acquisition request to the authenticator, and the key acquisition request includes the device identifier of the terminal. The terminal receives the key acquisition response sent by the authenticator, and the key acquisition response includes the authentication public key provided by the authenticator. Optionally, the key acquisition request can also include the identity public key held by the terminal.
[0093] Optionally, let the authentication attribute information of the media data be m, and the target key obtained based on the identity private key held by the terminal and the authentication public key provided by the authenticator be k. Then, the digital watermark W generated by the terminal can be expressed as: W = m || sign(k, m). Here, the symbol || represents string concatenation. sign(k, m) represents the signature information obtained by signing m with k.
[0094] Step 603: The terminal embeds the digital watermark into the media data to be played.
[0095] Optionally, if the media data is audio data, the watermark information can be embedded into the audio data through audio watermarking technology. For example, the watermark information can be embedded into different parameters such as time domain, frequency domain, phase, and amplitude of the audio signal to ensure that the quality and audibility of the audio signal are not affected. Or, if the media data is video data, the digital watermark can be embedded into the video data in the form of an invisible watermark. The invisible watermark is more difficult to be removed by attackers through technical means compared to the visible watermark. Therefore, embedding the digital watermark in the form of an invisible watermark into the video data can reduce the risk of the digital watermark being removed, thereby improving the reliability of the traceability of the media data.
[0096] Step 604: The terminal plays the media data embedded with the digital watermark.
[0097] In the embodiments of the present application, by carrying the authentication attribute information of the media data in the digital watermark and the signature information obtained by signing the authentication attribute information with the target key, the authentication attribute information in the digital watermark can declare the playback source range of the media data and serve as the identity information of the media data, thereby narrowing the traceability range of the media data. The signature information in the digital watermark is used to ensure the authenticity of the authentication attribute information of the media data, that is, to ensure the authenticity of the media data. Since the target key is obtained based on the identity private key held by the terminal and the authentication public key provided by the authenticator, as long as the identity private key held by the terminal is not leaked, other user terminals cannot calculate the target key, and thus cannot calculate the signature information using the target key to forge the watermark. Therefore, it can prevent others from maliciously forging the watermark to leak the media data for framing. In addition, in the embodiments of the present application, the signature information is used to prove the playback source of the media data, rather than directly carrying the user or device identity information in the digital watermark. Therefore, it can also avoid the leakage of user or device identity information.
[0098] Furthermore, when the copyright information of the media data is questioned, or when the media data is leaked and the leakage source needs to be located, the authenticator can conduct traceability evidence collection on the media data. For example, Figure 7 is a schematic flowchart of a media data traceability method provided by an embodiment of the present application. As Figure 7As shown, method 700 includes, but is not limited to, steps 701 to 704 below. Method 600 can be applied to the authenticator in the Figure 5 application scenario shown.
[0099] Step 701: The authenticator obtains the digital watermark in the media data to be traced. The digital watermark includes the authentication attribute information of the media data and the signature information obtained based on the authentication attribute information. The authentication attribute information is used to identify the playback source range of the media data.
[0100] Among them, the explanation of the authentication attribute information of the media data can refer to step 601 above, and the embodiments of the present application will not elaborate here.
[0101] Step 702: The authenticator determines the playback source range of the media data according to the authentication attribute information.
[0102] Optionally, the authentication attribute information includes a conference identifier and / or conference timestamp information. Accordingly, the authenticator determines the conference from which the media data comes according to the authentication attribute information, and then determines that the playback source range of the media data includes the conference terminals participating in the conference.
[0103] Step 703: The authenticator generates a first key according to the authentication private key held by the authenticator and the first identity public key held by the first terminal, where the first terminal is any terminal within the playback source range.
[0104] Optionally, after receiving the key acquisition request sent by the terminal, the authenticator may also send a key acquisition response to the terminal, and the key acquisition response includes an authentication public key. The authentication private key held by the authenticator and the authentication public key provided by the authenticator to the terminal are a public-private key pair.
[0105] Step 704: The authenticator verifies the signature information in the digital watermark based on the first key and the authentication attribute information in the digital watermark to determine whether the media data comes from the first terminal.
[0106] Optionally, in the case where multiple terminals are included within the playback source range of media data, if the authenticator determines that the media data does not come from the first terminal, the authenticator can also generate a second key based on the authentication private key held by the authenticator and the second identity public key held by the second terminal, where the second terminal is any terminal other than the first terminal within the playback source range. Then, the authenticator verifies the signature information in the digital watermark based on the second key and the authentication attribute information in the digital watermark to determine whether the media data comes from the second terminal. That is to say, the authenticator can traverse and verify all terminals within the playback source range of the media data until the terminal from which the media data comes is determined. Among them, for each terminal within the playback source range of the media data, the implementation manner for the authenticator to verify whether the media data comes from this terminal can uniformly refer to the implementation manner for verifying whether the media data comes from the first terminal described in the embodiments of this application.
[0107] In the embodiments of this application, since only the authenticator that provides the authentication public key to the terminal can calculate the key for verifying the digital watermark generated by this terminal, only the authenticator has the right to trace the media data. Even if other terminal users extract the digital watermark in the media data, they cannot trace the playback source of the media data, which can protect the user privacy of the playback source and at the same time reduce the risk of leakage of playback source information.
[0108] Optionally, the solution of this application can be implemented based on a watermark algorithm combined with symmetric encryption, or can also be implemented based on a watermark algorithm combined with asymmetric encryption, and the following two possible implementation manners are described respectively.
[0109] In the first possible implementation manner, the solution of this application is implemented based on a watermark algorithm combined with symmetric encryption. In step 602 above, the terminal uses a key negotiation algorithm to generate a target key for the identity private key held by this terminal and the authentication public key provided by the authenticator. Correspondingly, the terminal uses the target key to sign the authentication attribute information of the media data based on a symmetric signature algorithm to obtain a symmetric signature value. The signature information in the digital watermark can be this symmetric signature value, or can also be a truncated result value of this symmetric signature value.
[0110] Correspondingly, in step 703 above, the authenticator uses a key negotiation algorithm to generate a first key for the authentication private key held by the authenticator and the first identity public key held by the first terminal. In step 704 above, the authenticator uses the first key to sign the authentication attribute information in the digital watermark based on a symmetric signature algorithm to obtain a symmetric signature value. If the signature information in the digital watermark matches this symmetric signature value, the authenticator determines that the media data embedded with this digital watermark comes from the first terminal.
[0111] Here, the authenticator and the terminal respectively use the same key agreement algorithm to generate the same key for the private key they hold and the public key provided by the other party. This key - agreement (KA) algorithm can be the Diffie - Hellman (DH) algorithm. For example, the identity public key held by the terminal is PKu, the identity private key held by the terminal is SKu, the authentication public key held by the authenticator is PKW, and the authentication private key held by the authenticator is SKW. Then the key generated by the terminal using the DH algorithm for SKu and PKW can be expressed as DH(SKu, PKW), and the key generated by the authenticator using the DH algorithm for SKW and PKu can be expressed as DH(SKW, PKu), and DH(SKu, PKW) is the same as DH(SKW, PKu).
[0112] Optionally, the terminal uses the target key to sign the authentication attribute information of the media data based on the symmetric signature algorithm to obtain a symmetric signature value. It can be that the terminal first calculates the hash value of the authentication attribute information, and then uses the target key to sign the hash value based on the symmetric signature algorithm to obtain the symmetric signature value. The symmetric signature algorithm used by the terminal can be, for example, the advanced encryption standard (AES) based cypher - based message authentication code (CMAC) (abbreviation: AES - CMAC) algorithm, and the symmetric signature value can be an AES - CMAC value with a length of at least 128 bits. Correspondingly, the authenticator uses the first key to sign the authentication attribute information in the digital watermark based on the symmetric signature algorithm to obtain a symmetric signature value. It can be that the authenticator first calculates the hash value of the authentication attribute information, and then uses the first key to sign the hash value based on the symmetric signature algorithm to obtain the symmetric signature value. The symmetric signature algorithm used by the authenticator is the same as the symmetric signature algorithm used by the terminal.
[0113] Optionally, the signature information in the digital watermark generated by the terminal is the symmetric signature value obtained by the terminal using the target key to sign the authentication attribute information of the media data based on the symmetric signature algorithm. Correspondingly, in step 704 above, if the signature information in the digital watermark embedded in the media data is the same as the symmetric signature value obtained by the authenticator using the first key to sign the authentication attribute information in the digital watermark based on the symmetric signature algorithm, then the authenticator determines that the media data comes from the first terminal.
[0114] Alternatively, the signature information in the digital watermark generated by the terminal is a truncated result value of a symmetric signature value obtained by the terminal using a target key to sign the authentication attribute information of the media data based on a symmetric signature algorithm. Accordingly, in step 704 above, if the signature information in the digital watermark embedded in the media data is the same as the truncated result value of the symmetric signature value obtained by the authenticator using a first key to sign the authentication attribute information in the digital watermark based on a symmetric signature algorithm, the authenticator determines that the media data comes from the first terminal.
[0115] Since some media data is limited by the watermark payload capacity and is not sufficient to carry the full signature length. For example, for audio data, if too much watermark information is embedded, it will affect the fidelity and robustness of the audio data. And the symmetric signature value is usually smaller than the asymmetric signature value. Therefore, this type of media data is suitable for using a symmetric signature scheme to shorten the signature length. However, even the length of the symmetric signature value may exceed the watermark payload capacity limit. For example, the audio watermark payload on the market is generally within 8 bytes. Therefore, in order to carry the authentication attribute information and the signature, the symmetric signature value also needs to be truncated (truncate) and then the truncated result value is embedded (because symmetric signature is reversible, so it can be truncated without affecting signature verification. However, asymmetric signature must rely on the full signature value for signature verification). Specifically, refer to the introduction of the message authentication code (MAC) generation algorithm in section 2.4 of the request for comments (RFC) document numbered 4493 formulated by the Internet Engineering Task Force (IETF) (abbreviation: IETF RFC4493): "The MAC can be truncated. According to [NIST-CMAC], at least 64-bit MAC should be used as protection against guessing attacks. In most cases, the result should be truncated with the most significant bits first". This implementation method truncates the symmetric signature value and embeds the truncated result value into the audio data as watermark information, which can reduce the watermark embedding capacity and thus ensure the fidelity and robustness of the audio data after embedding the watermark information. For video data, either the symmetric signature value or the truncated result value of the symmetric signature value can be embedded into the video data as watermark information.
[0116] In the first possible implementation method above, only the authenticator and the terminal can calculate the same symmetric key. As long as the identity private key held by the terminal and the authentication private key held by the authenticator are not leaked, any third party other than the terminal and the authenticator cannot calculate the target key, and thus cannot calculate the signature information using the target key to forge the watermark. Therefore, it can prevent others from maliciously forging the watermark to leak media data for framing.
[0117] Optionally, in the first possible implementation described above, the authentication public key held by the authenticator is provided jointly by multiple approvers, and this authentication public key is a DKG public key. The multiple approvers jointly hold n private key shards, and the number of private key shards held by each approver is less than t. The DKG public key is calculated based on the n private key shards, and the private key corresponding to the DKG public key is obtained based on at least t private key shards among the n private key shards. Here, n is an integer greater than 1, and 2 ≤ t ≤ n. In this implementation, the authenticator needs to rely on multiple approvers to recover the authentication private key, and further combines it with the identity public key held by the terminal to calculate the same key as the target key used by the terminal to generate the digital watermark. Compared with the scheme where the authenticator directly holds the authentication private key, in this scheme, since the authenticator is supervised by multiple approvers, the risk that the authenticator maliciously forges the watermark to frame the end user can be reduced, the reliability of the authenticator and the watermark security are improved, and the reliability of watermark traceability is further improved.
[0118] In the second possible implementation, the solution of this application is implemented based on a watermark algorithm that combines asymmetric encryption. In step 602 above, the terminal uses an asymmetric key generation algorithm to generate a target key for the identity private key held by the terminal and the authentication public key provided by the authenticator. The target key is an asymmetric key, for example, the private key in a public-private key pair. Correspondingly, the terminal uses the target key to sign the authentication attribute information of the media data based on the asymmetric signature algorithm to obtain an asymmetric signature value, and the signature information in the digital watermark is this asymmetric signature value.
[0119] Correspondingly, in step 703 above, the authenticator uses an asymmetric key generation algorithm to generate a first key for the authentication private key held by the authenticator and the first identity public key held by the first terminal. In step 704 above, the authenticator uses the first key to verify the signature of the authentication attribute information and the signature information in the digital watermark. If the signature verification passes, the authenticator determines that the media data embedded with this digital watermark comes from the first terminal.
[0120] Optionally, the implementation method for the terminal to generate a target key using an asymmetric key generation algorithm for the identity private key held by the terminal and the authentication public key provided by the authentication party is that the terminal uses a key derivation function (KDF) to generate a derived key based on the identity private key held by the terminal and the authentication public key provided by the authentication party, and generates the target key according to the derived key and the identity private key held by the terminal. Correspondingly, the implementation method for the authentication party to generate a first key using an asymmetric key generation algorithm for the authentication private key held by the authentication party and the first identity public key held by the first terminal is that the authentication party uses a key derivation function to generate a derived key based on the authentication private key held by the authentication party and the first identity public key held by the first terminal, and generates the first key according to the derived key and the authentication private key held by the authentication party. The asymmetric key generation algorithm used by the terminal and the asymmetric key generation algorithm used by the authentication party here are matching algorithms for generating public-private key pairs. For example, the terminal uses an asymmetric key generation algorithm to generate the private key in the public-private key pair, and the authentication party uses a matching asymmetric key generation algorithm to generate the public key in the public-private key pair.
[0121] In this implementation method, the authentication party and the terminal can respectively generate a pair of public-private keys according to the private key held by themselves and the public key provided by the other party. For example, the identity public key held by the terminal is PKu, the identity private key held by the terminal is SKu, the authentication public key held by the authentication party is Pkw, and the authentication private key held by the authentication party is SKw. Then the key generated by the terminal according to SKu and Pkw can be the private key SK, SK = (KDF(SKu, Pkw) + SKu) mod q, where KDF(SKu, Pkw) is the derived key generated by the terminal using the key derivation function for SKu and Pkw, q is a prime number, mod q means taking the modulus of q, and the value range of SK is [1, q). The key generated by the authentication party according to SKw and SKu can be the public key PK, PK = g KDF(SKw,PKu) ·PKu, where KDF(SKw, PKu) is the derived key generated by the authentication party using the key derivation function for SKw and PKu, and g is the primitive root of the prime number q. KDF(SKu, Pkw) is the same as KDF(SKw, PKu). For example, it can be set that K = KDF(SKu, Pkw) = KDF(SKw, PKu).
[0122] The following gives an example to illustrate the implementation algorithm process of the terminal generating a signature private key according to the identity private key held by the terminal and the authentication public key provided by the authentication party, and the authentication party generating a signature public key corresponding to the signature private key according to the authentication private key held by the authentication party and the identity public key held by the terminal.
[0123] The first step is that the public parameters g, q, and KDF are preset in the terminal and the authentication party, where q is a prime number and g is the primitive root of q.
[0124] Step 2: The terminal generates an identity public-private key pair, including an identity private key SKu and an identity public key PKu, PKu = g SKu 。The authenticator generates an authentication public-private key pair, including an authentication private key SKw and an authentication public key Pkw, Pkw = g SKw 。
[0125] Step 3: The terminal generates a signature private key SK based on SKu and Pkw: SK = (ck + SKu) mod q, ck = KDF(Pkw SKu ); The authenticator generates a signature public key PK based on SKw and PKu: PK = g ck’ ·PKu, ck’ = KDF(PKu SKw )。
[0126] Since PKu = g SKu , Pkw = g SKw , so Pkw SKu = g SKwSKu = g SKuSKw = PKu SKw ; Correspondingly, ck and ck’ derived using the same key derivation function KDF are also the same. Thus, it can be verified that: g SK = g (ck+SKu) = g ck ·g SKu = g ck’ ·PKu = PK, that is, the signature private key SK generated by the terminal and the signature public key PK generated by the authenticator are a public-private key pair.
[0127] Optionally, the asymmetric signature algorithm can be, for example, the elliptic curve digital signature algorithm (ECDSA). The terminal uses the target key to sign the authentication attribute information of the media data based on the asymmetric signature algorithm to obtain an asymmetric signature value. It can be that the terminal first runs a hash algorithm on the authentication attribute information to obtain a data hash value, and then uses the target key to sign the hash value of the fixed length to obtain an asymmetric signature value. This asymmetric signature value is, for example, an ECDSA signature. Correspondingly, the authenticator first runs a hash algorithm on the authentication attribute information in the digital watermark to obtain a data hash value, and then uses the first key to sign and verify the calculated data hash value and the signature information in the digital watermark. If the signature verification passes, the authenticator determines that the media data embedded with the digital watermark comes from the first terminal. The hash algorithm used by the authenticator for the authentication attribute information is the same as the hash algorithm used by the terminal for the authentication attribute information.
[0128] Under the above second possible implementation manner, only the terminal can calculate the target key for generating the digital watermark, which can prevent any third party, including the authenticator, from maliciously forging the leaked media data by imitating the watermark for framing. In addition, only the authenticator can calculate the key for verifying the digital watermark generated by the terminal, that is, only the authenticator has the right to trace the media data played by the terminal, which can well protect the privacy of the terminal user.
[0129] The embodiments of the present application can be applied to the copyright authentication scenario or leakage location scenario of media data.
[0130] In the copyright authentication scenario of media data, the authenticator determines whether the media data comes from a terminal, that is, determines whether the ownership of the media data belongs to the terminal or the user of the terminal. For example, Figure 8 is a schematic diagram of a copyright authentication scenario of media data provided by the embodiments of the present application. As Figure 8 shown, user A is the owner of media data A. User A can generate key A according to the identity private key of user A and the authentication public key provided by the authenticator, and embed the signature information generated by using key A into media data A in the form of a digital watermark. If the ownership of media data A is questioned, for example, when user B questions the ownership of media data A while watching the playback content of media data A, user B can provide a partial segment of media data A to the authenticator. The authenticator extracts the watermark information in media data A by using the watermark detection algorithm, and verifies the signature information in the watermark information by using the key generated based on the authentication private key held by the authenticator and the identity public key of user A, so as to determine that media data A belongs to user A.
[0131] In the leakage location scenario of media data, the authenticator determines whether the media data comes from a terminal, that is, determines whether the media data is leaked by the terminal or the user of the terminal. For example, Figure 9 is a schematic diagram of a leakage location scenario of media data provided by the embodiments of the present application. As Figure 9 shown, user A generates key A according to the identity private key of user A and the authentication public key provided by the authenticator, and embeds the signature information generated by using key A into media data A in the form of a digital watermark and then plays it. If media data A is leaked during the playback process, the leaked segment of media data A can be provided to the authenticator. The authenticator extracts the watermark information in the leaked segment by using the watermark detection algorithm, and verifies the signature information in the watermark information by traversing with multiple keys respectively, where each key is generated based on the authentication private key held by the authenticator and the identity public key of a possible leaking user, so as to determine that the leakage source of media data A is user A.
[0132] The sequence of steps of the above-mentioned media data playback method or traceability method provided by the embodiments of the present application can be appropriately adjusted, and the steps can also be increased or decreased accordingly according to the situation. For example, the solution provided by the embodiments of the present application is mainly used to solve the problem of leakage or suspected ownership of media data during transmission in the air channel. In practical applications, if the media data is leaked through other channels (such as being copied) or only to prove the user's copyright ownership of the media data, the solution provided by the embodiments of the present application can also be used to embed digital watermarks in the media data and use the above method 700 for traceability. In this case, the above step 604 may not be executed, that is, after the terminal embeds the digital watermark in the media data, it may not play the media data embedded with the digital watermark. Any person skilled in the art within the technical scope disclosed in the present application can easily think of the changed methods, which should be covered by the protection scope of the present application.
[0133] The following is an example of the software device of the embodiments of the present application.
[0134] For example, Figure 10 is a schematic structural diagram of a media data playback device provided by the embodiments of the present application. The device is applied to a terminal. As Figure 10 shown, the device 1000 includes but is not limited to an acquisition module 1001, a generation module 1002, and a watermark embedding module 1003. Optionally, the device 1000 further includes a sending module 1004 and a receiving module 1005.
[0135] The acquisition module 1001 is used to acquire the authentication attribute information of the media data to be played, and the authentication attribute information is used to identify the playback source range of the media data. The generation module 1002 is used to generate a digital watermark according to the authentication attribute information. The digital watermark includes the authentication attribute information and the signature information obtained by signing the authentication attribute information with a target key. The target key is obtained based on the identity private key held by the terminal and the authentication public key provided by the authenticator. Only the authenticator has the traceability authority for the media data. The watermark embedding module 1003 is used to embed the digital watermark in the media data and play the media data embedded with the digital watermark.
[0136] Optionally, the generation module 1002 is used to: generate a target key for the identity private key and the authentication public key by using a key negotiation algorithm; sign the authentication attribute information with the target key based on a symmetric signature algorithm to obtain a symmetric signature value, and the signature information is the symmetric signature value, or the signature information is a truncated result value of the symmetric signature value.
[0137] Optionally, the authentication public key is jointly provided by multiple approvers. The authentication public key is a DKG public key. The multiple approvers jointly hold n private key shards, and the number of private key shards held by each approver is less than t. The DKG public key is calculated based on the n private key shards, and the private key corresponding to the DKG public key is obtained based on at least t private key shards among the n private key shards, where n is an integer greater than 1, and 2 ≤ t ≤ n.
[0138] Optionally, the generation module 1002 is configured to: generate a target key for the identity private key and the authentication public key by using an asymmetric key generation algorithm; sign the authentication attribute information based on the target key by using an asymmetric signature algorithm to obtain an asymmetric signature value, and the signature information is the asymmetric signature value.
[0139] Optionally, the generation module 1002 is specifically configured to: generate a derived key based on the identity private key and the authentication public key by using a key derivation function; generate a target key according to the derived key and the identity private key.
[0140] Optionally, the target key is SK, SK = (K + SKu) mod q, where SKu is the identity private key, K is the derived key, q is a prime number, mod q represents taking the modulus of q, and the value range of SK is [1, q).
[0141] Optionally, the sending module 1004 is configured to send a key acquisition request to the approver, and the key acquisition request includes the device identifier of the terminal. The receiving module 1005 is configured to receive a key acquisition response sent by the approver, and the key acquisition response includes the authentication public key.
[0142] Optionally, the terminal is a conference terminal participating in a conference, the media data comes from the conference, and the authentication attribute information includes the conference identifier of the conference and / or the conference timestamp information of the conference.
[0143] Optionally, the receiving module 1005 is configured to receive media data sent by other conference terminals participating in the conference.
[0144] For another example, Figure 11 is a schematic structural diagram of a media data traceability device provided by an embodiment of the present application. The device is applied to an approver. As Figure 11 shown, the device 1100 includes but is not limited to an acquisition module 1101, a determination module 1102, a generation module 1103, and a verification module 1104. Optionally, the device 1100 further includes a receiving module 1105 and a sending module 1106.
[0145] An acquisition module 1101 is configured to acquire a digital watermark in media data to be traced. The digital watermark includes authentication attribute information of the media data and signature information obtained based on the authentication attribute information. The authentication attribute information is used to identify the playback source range of the media data. A determination module 1102 is configured to determine the playback source range according to the authentication attribute information. A generation module 1103 is configured to generate a first key according to an authentication private key held by an authenticator and a first identity public key held by a first terminal, where the first terminal is any terminal within the playback source range. A verification module 1104 is configured to verify the signature information based on the first key and the authentication attribute information to determine whether the media data comes from the first terminal.
[0146] Optionally, the generation module 1103 is configured to generate a first key for the authentication private key and the first identity public key by using a key agreement algorithm. The verification module 1104 is configured to sign the authentication attribute information based on the first key by using a symmetric signature algorithm to obtain a symmetric signature value. If the signature information matches the symmetric signature value, it is determined that the media data comes from the first terminal.
[0147] Optionally, the authentication public key corresponding to the authentication private key is jointly provided by multiple approvers. The authentication public key is a DKG public key. The multiple approvers jointly hold n private key shards and the number of private key shards held by each approver is less than t. The DKG public key is calculated based on the n private key shards, and the authentication private key is obtained based on at least t private key shards among the n private key shards, where n is an integer greater than 1 and 2 ≤ t ≤ n.
[0148] Optionally, the length of the signature information is less than the length of the symmetric signature value. The verification module 1104 is configured to: if the signature information is the same as the truncated result value of the symmetric signature value, determine that the media data comes from the first terminal.
[0149] Optionally, the generation module 1103 is configured to generate a first key for the authentication private key and the first identity public key by using an asymmetric key generation algorithm. The verification module 1104 is configured to perform signature verification on the authentication attribute information and the signature information by using the first key. If the signature verification passes, it is determined that the media data comes from the first terminal.
[0150] Optionally, the generation module 1103 is specifically configured to: generate a derived key based on the authentication private key and the first identity public key by using a key derivation function; generate a first key according to the derived key and the authentication private key.
[0151] Optionally, the first key is PK, and PK = gK·PKu, where PKu is the first identity public key, K is the derived key, and g is a primitive root of prime number q.
[0152] Optionally, a receiving module 1105 is configured to receive a key acquisition request sent by a terminal within the playback source range, where the key acquisition request includes the device identifier of the terminal. A sending module 1106 is configured to send a key acquisition response to the terminal, where the key acquisition response includes the authentication public key corresponding to the authentication private key.
[0153] Optionally, the playback source range includes multiple terminals. The generating module 1103 is further configured to, if it is determined that the media data does not come from the first terminal, generate a second key according to the authentication private key and the second identity public key held by the second terminal, where the second terminal is any terminal other than the first terminal within the playback source range. The verifying module 1104 is further configured to verify the signature information based on the second key and the authentication attribute information to determine whether the media data comes from the second terminal.
[0154] Optionally, the authentication attribute information includes a conference identifier and / or conference timestamp information. The determining module 1102 is specifically configured to: determine the conference to which the media data belongs according to the authentication attribute information; determine that the playback source range includes the conference terminals participating in the conference.
[0155] The hardware device of the embodiment of the present application will be exemplified below.
[0156] For example, Figure 12 is a schematic diagram of the hardware structure of a computer device provided by an embodiment of the present application. The computer device may be the terminal or the authenticating party in the above embodiment. As Figure 12 shown, the computer device 1200 includes a processor 1201 and a memory 1202, and the memory 1201 is connected to the memory 1202 through a bus 1203. Figure 12 It is described with the processor 1201 and the memory 1202 being independent of each other. Optionally, the processor 1201 and the memory 1202 are integrated together. Optionally, in combination Figure 5 viewed, Figure 12 the computer device 1200 in Figure 5 may be the authenticating party or any terminal shown.
[0157] Among them, the memory 1202 is used to store computer programs, which include an operating system and program code. The memory 1202 is various types of storage media, such as read-only memory (ROM), random access memory (RAM), electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM), flash memory, optical memory, registers, optical disc storage, optical disc storage, magnetic disk, or other magnetic storage devices.
[0158] Among them, the processor 1201 is a general-purpose processor or a special-purpose processor. The processor 1201 may be a single-core processor or a multi-core processor. The processor 1201 includes at least one circuit to execute the above-mentioned method 600 or method 700 provided by the embodiments of the present application.
[0159] Optionally, the computer device 1200 further includes a network interface 1204, and the network interface 1204 is connected to the processor 1201 and the memory 1202 through the bus 1203. The network interface 1204 can enable the computer device 1200 to communicate with other devices. For example, the processor 1201 can interact with other devices through the network interface 1204, such as communicating with an MCU through the network interface 1204, and so on.
[0160] Optionally, the computer device 1200 further includes an input / output (I / O) interface 1205, and the I / O interface 1205 is connected to the processor 1201 and the memory 1202 through the bus 1203. The processor 1201 can receive input commands or data through the I / O interface 1205. The I / O interface 1205 is used for the computer device 1200 to connect to input devices, such as a keyboard, a mouse, etc. Optionally, in some possible scenarios, the above-mentioned network interface 1204 and I / O interface 1205 are collectively referred to as a communication interface.
[0161] Optionally, the computer device 1200 further includes a display 1206, and the display 1206 is connected to the processor 1201 and the memory 1202 through the bus 1203. The display 1206 can be used to display intermediate results and / or final results generated by the processor 1201 executing the above method. In one possible implementation, the display 1206 is a touch display screen to provide a human-computer interaction interface.
[0162] Among them, the bus 1203 is of any type and is a communication bus used to implement the interconnection of internal components of the computer device 1200. For example, a system bus. In the embodiments of the present application, the above-mentioned components inside the computer device 1200 are interconnected through the bus 1203 as an example. Optionally, the above-mentioned components inside the computer device 1200 communicate with each other using other connection methods except the bus 1203. For example, the above-mentioned components inside the computer device 1200 are interconnected through the logical interfaces inside the computer device 1200.
[0163] The above-mentioned components can be respectively arranged on independent chips, or at least partially or entirely arranged on the same chip. Whether to independently arrange each component on different chips or to integrate and arrange them on one or more chips often depends on the needs of product design. The embodiments of the present application do not limit the specific implementation forms of the above-mentioned components.
[0164] Figure 12 The shown computer device 1200 is only exemplary. During the implementation process, the computer device 1200 includes other components, which will not be listed one by one herein. Figure 12 The shown computer device 1200 can play media data by executing all or part of the steps of the method 600 provided in the above-mentioned embodiments, or, Figure 12 The shown computer device 1200 can trace the origin of media data by executing all or part of the steps of the method 700 provided in the above-mentioned embodiments.
[0165] The following gives an example of the system in the embodiments of the present application.
[0166] The embodiments of the present application also provide a protection system for media data, including: a terminal and an authenticator. The terminal is used to execute the above-mentioned method 600, and the authenticator is used to execute the above-mentioned method 700.
[0167] Optionally, the system is a video conferencing system, the terminal is a conference terminal, and the authenticator is a conference management party.
[0168] The embodiments of the present application also provide a computer-readable storage medium, on which instructions are stored. When the instructions are executed by a processor, the above-mentioned method 600 or method 700 is implemented.
[0169] The embodiments of the present application also provide a computer program product, including a computer program. When the computer program is executed by a processor, the above-mentioned method 600 or method 700 is implemented.
[0170] Those of ordinary skill in the art can understand that all or part of the steps to implement the above embodiments can be completed by hardware or by a program instructing relevant hardware. The program can be stored in a computer-readable storage medium, and the storage medium mentioned above can be a read-only memory, a magnetic disk, an optical disk, or the like.
[0171] In the embodiments of the present application, the terms "first", "second", and "third" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance.
[0172] The term "and / or" in the present application is merely a description of the association relationship between associated objects, indicating that three relationships may exist. For example, A and / or B may represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally represents an "or" relationship between the preceding and following associated objects.
[0173] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data for analysis, stored data, displayed data, etc.), and signals involved in the present application are all authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant laws, regulations, and standards of relevant countries and regions.
[0174] The above are only optional embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the concept and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A method for playing media data, characterized in that Applied to a terminal, the method includes: Obtaining authentication attribute information of media data to be played, where the authentication attribute information is used to identify the playback source range of the media data; Generating a digital watermark according to the authentication attribute information, where the digital watermark includes the authentication attribute information and signature information obtained by signing the authentication attribute information with a target key, and the target key is obtained based on an identity private key held by the terminal and an authentication public key provided by an authenticator, and only the authenticator has the right to trace the media data; Embedding the digital watermark in the media data and playing the media data embedded with the digital watermark.
2. The method according to claim 1, characterized in that The method further includes: Generating the target key for the identity private key and the authentication public key by using a key agreement algorithm; The signing the authentication attribute information with the target key includes: Signing the authentication attribute information with the target key based on a symmetric signature algorithm to obtain a symmetric signature value, where the signature information is the symmetric signature value, or the signature information is a truncated result value of the symmetric signature value.
3. The method according to claim 2, wherein The authentication public key is jointly provided by multiple approvers, the authentication public key is a distributed key generation (DKG) public key, the multiple approvers jointly hold n private key shards and the number of private key shards held by each approver is less than t, the DKG public key is calculated based on the n private key shards, and the private key corresponding to the DKG public key is obtained based on at least t private key shards among the n private key shards, where n is an integer greater than 1 and 2 ≤ t ≤ n.
4. The method according to claim 1, characterized in that The method further includes: Generating the target key for the identity private key and the authentication public key by using an asymmetric key generation algorithm; The signing the authentication attribute information with the target key includes: Signing the authentication attribute information with the target key based on an asymmetric signature algorithm to obtain an asymmetric signature value, where the signature information is the asymmetric signature value.
5. The method according to claim 4, characterized in that, The generating the target key for the identity private key and the authentication public key by using the asymmetric key generation algorithm includes: Generating a derived key based on the identity private key and the authentication public key by using a key derivation function; Generating the target key according to the derived key and the identity private key.
6. The method according to claim 5, wherein The target key is SK, SK = (K + SKu) mod q, where SKu is the identity private key, K is the derived key, q is a prime number, mod q represents taking the modulus with respect to q, and the value range of SK is [1, q).
7. According to the method described in any one of claims 1 to 6, characterized in that, The method further includes: Sending a key acquisition request to the authenticator, where the key acquisition request includes the device identifier of the terminal; Receiving a key acquisition response sent by the authenticator, where the key acquisition response includes the authentication public key.
8. The method according to any one of claims 1 to 7, characterized in that The terminal is a conference terminal participating in a conference, the media data comes from the conference, and the authentication attribute information includes the conference identifier of the conference and / or the conference timestamp information of the conference.
9. The method according to claim 8, characterized in that, The method further includes: Receiving the media data sent by other conference terminals participating in the conference.
10. A method for tracing media data, characterized in that, Applied to an authenticator, the method includes: Obtain the digital watermark in the media data to be traced. The digital watermark includes the authentication attribute information of the media data and the signature information obtained based on the authentication attribute information. The authentication attribute information is used to identify the playback source range of the media data; Determine the playback source range according to the authentication attribute information; Generate a first key according to the authentication private key held by the authentication party and the first identity public key held by the first terminal, where the first terminal is any terminal within the playback source range; Verify the signature information based on the first key and the authentication attribute information to determine whether the media data comes from the first terminal.
11. The method according to claim 10, characterized in that, The generating a first key according to the authentication private key held by the authentication party and the first identity public key held by the first terminal includes: Using a key agreement algorithm to generate the first key for the authentication private key and the first identity public key; The verifying the signature information based on the first key and the authentication attribute information includes: Signing the authentication attribute information based on the symmetric signature algorithm using the first key to obtain a symmetric signature value; If the signature information matches the symmetric signature value, determine that the media data comes from the first terminal.
12. The method according to claim 11, wherein The authentication public key corresponding to the authentication private key is provided jointly by multiple approvers. The authentication public key is a distributed key generation (DKG) public key. The multiple approvers jointly hold n private key shards and the number of private key shards held by each approver is less than t. The DKG public key is calculated based on the n private key shards, and the authentication private key is obtained based on at least t private key shards among the n private key shards, where n is an integer greater than 1 and 2 ≤ t ≤ n.
13. The method according to claim 11 or 12, characterized in that, The length of the signature information is less than the length of the symmetric signature value. The if the signature information matches the symmetric signature value, determine that the media data comes from the first terminal includes: If the signature information is the same as the truncated result value of the symmetric signature value, determine that the media data comes from the first terminal.
14. The method according to claim 10, wherein The generating a first key according to the authentication private key held by the authentication party and the first identity public key held by the first terminal includes: Using an asymmetric key generation algorithm to generate the first key for the authentication private key and the first identity public key; The verifying the signature information based on the first key and the authentication attribute information includes: Performing signature verification on the authentication attribute information and the signature information using the first key; If the signature verification passes, determine that the media data comes from the first terminal.
15. The method according to claim 14, wherein The using an asymmetric key generation algorithm to generate the first key for the authentication private key and the first identity public key includes: Using a key derivation function to generate a derived key based on the authentication private key and the first identity public key; Generating the first key according to the derived key and the authentication private key.
16. The method according to claim 15, characterized in that, The first key is PK, and PK = g K ·PKu, where PKu is the first identity public key, K is the derived key, and g is a primitive root of prime number q.
17. The method according to any one of claims 10 to 16, characterized in that The method further includes: Receiving a key acquisition request sent by a terminal within the playback source range, where the key acquisition request includes the device identifier of the terminal; Send a key acquisition response to the terminal, where the key acquisition response includes the authentication public key corresponding to the authentication private key.
18. The method according to any one of claims 10 to 17, characterized in that, The playback source range includes multiple terminals, and the method further includes: If it is determined that the media data does not come from the first terminal, generate a second key according to the authentication private key and the second identity public key held by the second terminal, where the second terminal is any terminal other than the first terminal within the playback source range; Verify the signature information based on the second key and the authentication attribute information to determine whether the media data comes from the second terminal.
19. The method according to any one of claims 10 to 18, characterized in that The authentication attribute information includes a meeting identifier and / or meeting timestamp information. Determining the playback source range according to the authentication attribute information includes: Determine the meeting to which the media data belongs according to the authentication attribute information; Determine that the playback source range includes the meeting terminals participating in the meeting.
20. A playback device for media data, characterized in that, Applied to a terminal, the device includes: An acquisition module, configured to acquire authentication attribute information of media data to be played, where the authentication attribute information is used to identify the playback source range of the media data; A generation module, configured to generate a digital watermark according to the authentication attribute information, where the digital watermark includes the authentication attribute information and signature information obtained by signing the authentication attribute information with a target key, and the target key is obtained based on the identity private key held by the terminal and the authentication public key provided by the authenticator, and only the authenticator has the right to trace the media data; A watermark embedding module, configured to embed the digital watermark in the media data and play the media data embedded with the digital watermark.
21. The device according to claim 20, characterized in that, The generation module is configured to: Generate the target key for the identity private key and the authentication public key by using a key negotiation algorithm; Sign the authentication attribute information based on the symmetric signature algorithm by using the target key to obtain a symmetric signature value, where the signature information is the symmetric signature value, or the signature information is a truncated result value of the symmetric signature value.
22. The device according to claim 21, characterized in that, The authentication public key is jointly provided by multiple approvers. The authentication public key is a distributed key generation (DKG) public key. The multiple approvers jointly hold n private key shards, and the number of private key shards held by each approver is less than t. The DKG public key is calculated based on the n private key shards, and the private key corresponding to the DKG public key is obtained based on at least t private key shards among the n private key shards, where n is an integer greater than 1, and 2 ≤ t ≤ n.
23. The device according to claim 20, characterized in that, The generation module is configured to: Generate the target key for the identity private key and the authentication public key by using an asymmetric key generation algorithm; Sign the authentication attribute information based on the asymmetric signature algorithm by using the target key to obtain an asymmetric signature value, where the signature information is the asymmetric signature value.
24. The device according to claim 23, characterized in that, The generation module is configured to: Generate a derived key based on the identity private key and the authentication public key by using a key derivation function; Generate the target key according to the derived key and the identity private key.
25. The device according to claim 24, characterized in that, The target key is SK, SK = (K + SKu) mod q, where SKu is the identity private key, K is the derived key, q is a prime number, mod q represents taking the modulus of q, and the value range of SK is [1, q).
26. The device according to any one of claims 20 to 25, characterized in that, The device further includes: A sending module, configured to send a key acquisition request to the authenticator, where the key acquisition request includes the device identifier of the terminal; A receiving module, configured to receive a key acquisition response sent by the authenticator, where the key acquisition response includes the authentication public key.
27. The device according to any one of claims 20 to 26, characterized in that, The terminal is a conference terminal participating in a conference, the media data comes from the conference, and the authentication attribute information includes the conference identifier of the conference and / or the conference timestamp information of the conference.
28. The device according to claim 27, wherein The device further includes: A receiving module, configured to receive the media data sent by other conference terminals participating in the conference.
29. A traceability device for media data, characterized in that, Applied to an authenticator, the device includes: An acquisition module, configured to acquire a digital watermark in the media data to be traced, where the digital watermark includes the authentication attribute information of the media data and signature information obtained based on the authentication attribute information, and the authentication attribute information is used to identify the playback source range of the media data; a determination module, configured to determine the playback source range according to the authentication attribute information; A generation module, configured to generate a first key according to the authentication private key held by the authenticator and the first identity public key held by a first terminal, where the first terminal is any terminal within the playback source range; A verification module, configured to verify the signature information based on the first key and the authentication attribute information to determine whether the media data comes from the first terminal.
30. The device according to claim 29, wherein: The generation module is configured to generate the first key for the authentication private key and the first identity public key by using a key negotiation algorithm; The verification module is configured to sign the authentication attribute information based on the first key by using a symmetric signature algorithm to obtain a symmetric signature value, and if the signature information matches the symmetric signature value, determine that the media data comes from the first terminal.
31. The device according to claim 30, characterized in that, The authentication public key corresponding to the authentication private key is jointly provided by multiple approvers, the authentication public key is a distributed key generation DKG public key, the multiple approvers jointly hold n private key shards and the number of private key shards held by each approver is less than t, the DKG public key is calculated based on the n private key shards, and the authentication private key is obtained based on at least t private key shards among the n private key shards, where n is an integer greater than 1, and 2 ≤ t ≤ n.
32. The device according to claim 30 or 31, characterized in that, The length of the signature information is less than the length of the symmetric signature value, and the verification module is configured to: If the signature information is the same as the truncated result value of the symmetric signature value, determine that the media data comes from the first terminal.
33. The device according to claim 29, wherein: The generation module is configured to generate the first key for the authentication private key and the first identity public key by using an asymmetric key generation algorithm; The verification module is configured to perform signature verification on the authentication attribute information and the signature information by using the first key. If the signature verification is passed, it is determined that the media data comes from the first terminal.
34. The apparatus according to claim 33, wherein The generation module is configured to: Generate a derived key based on the authentication private key and the first identity public key by using a key derivation function; Generate the first key according to the derived key and the authentication private key.
35. The device according to claim 34, characterized in that, The first key is PK, where PK = gK·PKu, PKu is the first identity public key, K is the derived key, and g is a primitive root of prime number q.
36. The device according to any one of claims 29 to 35, characterized in that, The device further includes: A receiving module, configured to receive a key acquisition request sent by a terminal within the playback source range, where the key acquisition request includes the device identifier of the terminal; A sending module, configured to send a key acquisition response to the terminal, where the key acquisition response includes the authentication public key corresponding to the authentication private key.
37. The device according to any one of claims 29 to 36, characterized in that The playback source range includes multiple terminals; The generation module is further configured to, if it is determined that the media data does not come from the first terminal, generate a second key according to the authentication private key and the second identity public key held by a second terminal, where the second terminal is any terminal other than the first terminal within the playback source range; The verification module is further configured to verify the signature information based on the second key and the authentication attribute information to determine whether the media data comes from the second terminal.
38. The device according to any one of claims 29 to 37, characterized in that, The authentication attribute information includes a conference identifier and / or conference timestamp information. The determination module is configured to: Determine the conference to which the media data belongs according to the authentication attribute information; Determine that the playback source range includes conference terminals participating in the conference.
39. A protection system for media data, characterized in that, It includes: A terminal and an authenticator, where the terminal is configured to execute the method according to any one of claims 1 to 9, and the authenticator is configured to execute the method according to any one of claims 10 to 19.
40. The system according to claim 39, wherein The system is a video conferencing system, the terminal is a conference terminal, and the authenticator is a conference management party.
41. A terminal, characterized in that, It includes: A processor and a memory; The memory is configured to store a computer program, and the computer program includes program instructions; The processor is configured to call the computer program to implement the method according to any one of claims 1 to 9.
42. A computer device, characterized in that, It includes: A processor and a memory; The memory is configured to store a computer program, and the computer program includes program instructions; The processor is configured to call the computer program to implement the method according to any one of claims 10 to 19.
43. A computer-readable storage medium, characterized in that, Instructions are stored on the computer-readable storage medium. When the instructions are executed by a processor, the method according to any one of claims 1 to 19 is implemented.
44. A computer program product, characterized in that, It includes a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 19 is implemented.
Citation Information
Cited By
Media data playback method and apparatus, media data tracing method and apparatus, and protection system
WO2025139183A1