Method for defining and evaluating use strategy of digital object, computing equipment and use strategy evaluation device
By defining usage policies for digital objects in unstructured environments and embedding policy watermarks, the problem of existing technologies being unable to prevent the misuse of graphic objects is solved, and the authenticity and integrity of digital objects are verified and protected against attacks are achieved.
Patent Information
- Application Number
- CN202380097080.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-12
- Publication Date
- 2025-11-07
AI Technical Summary
Existing cybersecurity methods are ineffective in preventing cyberattacks caused by the misuse or malicious use of graphical objects in unstructured digital environments, especially attacks such as fake news, impersonation, and phishing, and they cannot verify the authenticity and integrity of digital objects.
In unstructured digital environments, usage policies are defined for digital objects, policy watermarks are embedded, including policy IDs and anchors, appropriate usage policies are selected through a policy repository, and context matching scores are calculated during detection to assess the authenticity and integrity of digital objects.
It effectively prevents network attacks in unstructured environments, reduces manual errors, is applicable to all types of digital objects, ensures the authenticity and integrity of digital objects, and provides warnings to users through visual and audible cues.
Smart Images

Figure CN120917441A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present invention relates generally to the field of cyber security, and more specifically, to a method of defining a digital object usage policy, a method of evaluating a digital object usage policy, a computing device and a usage policy evaluation apparatus. BACKGROUND
[0002] Generally, the cyber security methods used in the current scenario provide sufficient protection against cyber attacks on hardware systems, software systems or interfaces. However, the existing cyber security methods mainly focus on computer-centric solutions. Thus, such cyber threats mainly affect humans rather than systems, as humans are the weakest link in computer-centric solutions. Some examples of such cyber attacks include fake news, forgery, email or information phishing, impersonation, etc. In such cyber attacks, digital objects such as text, images, audio files, video files, etc. are easily copied by any attacker and can be repeatedly used to carry out cyber attacks. However, the existing cyber security methods are unable to verify the authenticity and integrity of such digital objects.
[0003] Currently, some attempts have been made to reduce cyber attacks, for example, by providing user training programs, detailed information handling guidelines, and installation process and behavior-aware alert systems. However, these attempts are prone to errors due to their wide coverage. Furthermore, these attempts can only defend against a certain percentage (e.g., 30% to 50%) of cyber attacks. Moreover, these attempts are ineffective for graphical objects in unstructured digital environments, for example, web pages with moving graphics, video content, virtual reality, etc. Thus, there is a technical problem of how to prevent cyber attacks affecting humans when graphical objects are used incorrectly or maliciously in unstructured digital environments.
[0004] Therefore, in view of the above discussion, it is necessary to overcome the above-mentioned drawbacks associated with conventional cyber security methods. SUMMARY
[0005] The present invention provides a method of defining a digital object usage policy. Furthermore, the present invention provides a method of evaluating a digital object usage policy, a computing device and a usage policy evaluation apparatus. The present invention provides a solution to the existing problem of how to prevent cyber attacks affecting humans when encountered in graphical objects within unstructured environments. The object of the present invention is to provide a solution that at least partially solves the problems encountered in the prior art and provides an improved method of defining a digital object usage policy and an improved method of evaluating a digital object usage policy, an improved computing device and an improved usage policy evaluation apparatus to protect the context of digital objects in structured web pages and to control the usage of digital objects in videos and virtual environments.
[0006] One or more objects of the present application are achieved by the solutions provided in the independent claims. Advantageous implementations of the present application are further defined in the dependent claims.
[0007] In one aspect, the present application provides a method of defining a usage policy for a digital object. The method comprises: selecting a digital object to be protected in an unstructured digital environment; defining a usage policy with a policy identifier (ID) for the selected digital object to include one or more anchors, wherein each anchor is related to a digital object or activity that can be observed in the unstructured digital environment; embedding a policy watermark into the selected digital object, wherein the policy watermark includes the policy ID of the usage policy and a start marker for supporting bit frame alignment and encoding policy watermark parameters.
[0008] The above method is advantageous for preventing human-influenced cyber attacks such as fake news, impersonation, fraud, phishing, etc. encountered in graphical digital objects within an unstructured environment. The policy watermark generated in the improved method does not affect the quality of the digital object to be protected, and it is almost impossible to be removed by an attacker with regular skills, which is advantageous for protecting the digital object from being tampered by any adversary. The above method eliminates manual errors in identifying tampered digital objects, which is advantageous for accurately detecting cyber attacks. In addition, the above method is also applicable to all types of digital objects, which is advantageous for detecting whether any type of digital object is tampered. The policy watermark created by the above method is advantageous for verifying the authenticity and integrity of the usage policy of the digital object, and maintaining the link between the digital object and the corresponding unstructured digital environment. Through observing the appropriate evaluation process and the prompt to the end user, through detecting the appropriate watermark in the digital object, through checking the UI of the content editor, and through finding the advertisement of the relevant function in the user manual of the content editor, the above method can be used to disclose new functions.
[0009] In one implementation, the defining a usage policy comprises: selecting one of a plurality of predefined usage policies from a policy repository as the usage policy or as a basis for defining the usage policy, wherein each of the plurality of predefined usage policies has a policy ID and includes one or more anchors that are digital objects and / or activities that can be observed in the unstructured digital environment, each anchor has a category and a weight, the category is one of a whitelist category and a blacklist category, the whitelist category includes anchors approved for use with the digital object, the blacklist category includes anchors not approved for use with the digital object, and the weight represents the importance of each anchor.
[0010] The policy repository is advantageous to provide an efficient storage medium from which a suitable usage policy can be retrieved. The policy ID is advantageous to easily identify the usage policy. The weight assigned to the anchor points is advantageous to determine the necessary anchor points, which are necessary to establish a link between the digital object and the unstructured digital object.
[0011] In one implementation, the defining the usage policy comprises: selecting one or more digital objects and / or one or more activities that can be observed in the unstructured digital environment as anchor points according to a predefined selection algorithm and / or user input; assigning a category and a weight to each of the anchor points, wherein the category is one of a whitelist category and a blacklist category, the whitelist category comprising anchor points approved to be used with the given digital object, the blacklist category comprising anchor points not approved to be used with the given digital object, the weight is selected according to a predefined weighting algorithm and / or user input to represent an importance of each anchor point; storing the selected anchor points with the assigned category and weight as part of the usage policy into a policy repository.
[0012] The predefined weighting algorithm and the predefined selection algorithm are advantageous to accurately and quickly select digital objects and / or activities and assign weights, thereby reducing the execution time of the improvement method. In addition, the user input for selecting digital objects and activities and assigning weights provides flexibility or human control to the improvement method.
[0013] In another implementation, the defining the usage policy further comprises: defining one or more policy violation conditions to set conditions in which the usage policy of the protected digital object is violated in a digital environment, wherein the digital environment comprises the protected digital object.
[0014] The policy violation conditions determine the conditions in which the protected digital object violates the usage policy, which is advantageous to provide an accurate measure for determining any tampering behavior associated with the protected digital object.
[0015] In another aspect, the present disclosure provides a method for evaluating a usage policy of a digital object. The method includes detecting a protected digital object embedded with a policy watermark in an unstructured digital environment; decoding a policy identifier (ID) from the policy watermark of the protected digital object; retrieving a usage policy with the decoded policy ID from a policy repository. Further, the usage policy includes one or more anchors belonging to a whitelist category and / or a blacklist category, the one or more anchors being related to digital objects and / or activities that can be observed in the unstructured digital environment. Moreover, the method further includes detecting one or more digital objects and / or one or more activities in the unstructured digital environment that are identical to the anchors in the usage policy; calculating a context match score of the protected digital object based on the detected digital objects and / or activities that are identical to the anchors belonging to the whitelist category in the usage policy; calculating a context mismatch score of the protected digital object based on the detected digital objects and / or activities that are identical to the anchors belonging to the blacklist category in the usage policy; and notifying a user of a violation of the usage policy of the protected digital object in the given unstructured digital environment if the context match score or the context mismatch score does not satisfy a policy violation condition.
[0016] The above method can automatically evaluate any digital object in the process of rendering any unstructured digital environment, thereby indicating to a user whether any digital object in the unstructured digital environment is tampered. The above improved method advantageously reduces manual errors in evaluating the authenticity of digital objects. The above improved method advantageously identifies digital objects that provide false information and provides a warning to the user regarding such information. In addition, the above improved method is applicable to all types of digital objects. Further, the visual cues indicated in the above method advantageously allow all types of users to identify tampered digital objects regardless of the technical knowledge of the user. The above improved method is applicable to observe the appropriate evaluation flow and prompt the end user. In addition, the above improved method is also beneficial to check the user interface (UI) of the content editor and the globally available policies.
[0017] In an implementation, the policy violation condition is defined according to one of the following: the context match score does not satisfy the policy violation condition if the context match score is less than a context match threshold, and the context mismatch score does not satisfy the policy violation condition if the context match score is greater than a context mismatch threshold, wherein the context match threshold and the context mismatch threshold are predefined and / or included in the usage policy; neither the context match score nor the context mismatch score satisfies the policy violation condition if a quotient of the context match score divided by the context mismatch score is greater than a violation threshold, wherein the violation threshold is predefined and / or included in the usage policy; neither the context match score nor the context mismatch score satisfies the policy violation condition if a difference between the context match score and the context mismatch score is less than a violation threshold, wherein the violation threshold is predefined and / or included in the usage policy.
[0018] The policy violation condition determines the condition under which the protected digital object violates the usage policy, which facilitates providing an accurate measure for determining any tampering behavior associated with the protected digital object. The context match threshold, the context mismatch threshold, and the violation threshold facilitate determining the allowable variation between the context of the protected digital object and the unstructured digital environment, and provide an effective measure to identify a tampered digital object.
[0019] In an implementation, the method includes obtaining a weight for each of the anchors from the usage policy. Further, the computing the context match score includes summing the weights of the anchors belonging to the whitelist category that detect the same digital object or activity in the unstructured digital environment. Also, the computing the context mismatch score includes summing the weights of the anchors belonging to the blacklist category that detect the same digital object or activity in the unstructured digital environment.
[0020] The weight assigned to an anchor facilitates determining the necessary anchors, which are necessary to establish a link between the digital object and the unstructured digital object.
[0021] In another implementation, the method further includes determining a tampering correction factor according to a degree of tampering performed on the protected digital object. Further, the computing the context match score further includes multiplying the sum of the corresponding weights by the tampering correction factor; the computing the context mismatch score further includes multiplying the sum of the corresponding weights by the tampering correction factor.
[0022] The tampering correction factor represents the degree of tampering associated with any digital object, which facilitates improving the accuracy of determining a tampered digital object.
[0023] In another implementation, the notifying the user of a violation of the usage policy of the protected digital object comprises providing a visual cue and / or an audio cue to the user when presenting the unstructured digital environment on a user device.
[0024] The visual cue and / or the audio cue facilitate a simple indication of the lack of integrity of the digital object, so that the above-mentioned improved method can be implemented on any system by anyone without technical knowledge.
[0025] In another aspect, the application provides a computing device for implementing the method of defining a usage policy of a digital object.
[0026] The computing device implements all the advantages and technical effects of the method of defining a usage policy of a digital object.
[0027] In yet another aspect, the application provides a usage policy evaluation apparatus. The apparatus comprises an object and activity identification module configured to detect a digital object and an activity in an unstructured digital environment, such as a video content or a virtual reality environment; a protected object detector configured to detect a protected digital object embedded with a policy watermark; a watermark decoder configured to decode a policy ID from the policy watermark embedded in the protected digital object; and a policy evaluation module configured to retrieve the usage policy having the decoded policy ID from a policy repository. Further, the usage policy comprises one or more anchors belonging to a whitelist category and / or a blacklist category, the one or more anchors being related to a digital object and / or an activity that can be observed in the unstructured digital environment. In addition, the object and activity identification module, after retrieving the usage policy, is configured to detect one or more digital objects and / or one or more activities in the unstructured digital environment that are identical to the anchors in the usage policy. The policy evaluation module is further configured to calculate a context match score of the protected digital object according to the detected digital objects and / or activities that are identical to the anchors belonging to the whitelist category in the usage policy; calculate a context mismatch score of the protected digital object according to the detected digital objects and / or activities that are identical to the anchors belonging to the blacklist category in the usage policy; and determine a violation of the usage policy of the protected digital object in the given unstructured digital environment if the context match score or the context mismatch score does not meet a predefined policy violation condition.
[0028] The above described usage policy evaluation device can automatically evaluate any digital object in the process of rendering any unstructured digital environment, thereby indicating to the user whether any digital object in the unstructured digital environment is tampered. The above described usage policy evaluation device facilitates reducing manual errors in evaluating the authenticity of digital objects. The above described usage policy evaluation device facilitates identifying digital objects that provide false information and providing a warning to the user about such information. In addition, the above described usage policy evaluation device is applicable to all types of digital objects. Moreover, the visual and audio cues indicated in the above described usage policy evaluation device facilitate identifying tampered digital objects to all types of users, regardless of the technical knowledge of the user.
[0029] In an implementation, the policy evaluation module is configured to determine a violation of the usage policy of the protected digital object in one of: the context match score is less than a context match threshold or the context mismatch score is greater than a context mismatch threshold, wherein the context match threshold and the context mismatch threshold are predefined or included in the usage policy; a quotient of the context match score divided by the context mismatch score is greater than a violation threshold, wherein the violation threshold is predefined or included in the usage policy; a difference between the context match score and the context mismatch score is less than a violation threshold, wherein the violation threshold is predefined or included in the usage policy.
[0030] The policy violation condition determines the condition in which a protected digital object violates a usage policy, which facilitates providing an accurate measure for determining any tampering behavior associated with a protected digital object. The context match threshold, the context mismatch threshold, and the violation threshold facilitate determining the allowable variation between a protected digital object and the context of an unstructured digital environment and provide an effective measure to identify tampered digital objects.
[0031] In an implementation, the policy evaluation module is configured to: obtain a weight of each of the anchors from the usage policy; calculate the context match score by summing the weights of the anchors belonging to the whitelist category that detect the same digital object or activity in the unstructured digital environment; calculate the context mismatch score by summing the weights of the anchors belonging to the blacklist category that detect the same digital object or activity in the unstructured digital environment.
[0032] The weight assigned to an anchor facilitates determining the necessary anchors, which are necessary to establish a link between a digital object and an unstructured digital object.
[0033] In another implementation, the policy evaluation module is further configured to determine a tampering correction factor based on a degree of tampering with the protected digital object, and to calculate the context match score by multiplying the sum of the corresponding weights by the tampering correction factor, and to calculate the context mismatch score by multiplying the sum of the corresponding weights by the tampering correction factor.
[0034] In another implementation, the policy evaluation module is part of an endpoint security subsystem or a cloud service framework, and the policy evaluation module is further configured to notify a user of the determination of a violation of the usage policy of the protected digital object by providing a visual and / or audio cue to the user when the unstructured digital environment is rendered on a user device.
[0035] The visual and / or audio cue facilitates a simple indication of the lack of integrity of the digital object, so that the above improved method can be implemented on any system by anyone who is not technically savvy.
[0036] It is to be understood that all the above implementations can be combined together. It is noted that all devices, elements, circuits, units and modules described in the present application can be implemented in software or hardware elements or any type of combination thereof. All steps performed by the various entities described in the present application and the described functions to be performed by the various entities are intended to be within the scope of respective entities to perform their respective steps and functions. While in the following description of specific embodiments, specific functions or steps performed by external entities are not reflected in the description of specific detailed elements of the entities performing the specific steps or functions, it will be clear to a skilled person that these methods and functions can be implemented by corresponding hardware or software elements or any combination thereof. It is understood that features of the present application are susceptible to arrangements that are readily apparent to a skilled person and are within the scope of the present application as defined by the appended claims.
[0037] Other aspects, advantages, features and objects of the present application will become apparent to those skilled in the art from the detailed description of illustrative implementations thereof, which is to be read in connection with the accompanying drawings and the appended claims. BRIEF DESCRIPTION OF DRAWINGS
[0038] The above summary of the present application, as well as the following detailed description of illustrative embodiments thereof, can be better understood when read in conjunction with the appended drawings. For the purpose of illustrating the application, exemplary constructions of the present application are shown in the drawings. However, the present application is not limited to the specific methods and tools disclosed herein. Furthermore, skilled artisans appreciate that the drawings are not drawn to scale. Wherever possible, the same reference numbers are used in the different drawings to represent the same or similar elements.
[0039] Embodiments of the present application will be described below with reference to the following drawings, in which the embodiments of the present application are shown by way of example only, in the drawings:
[0040] Figure 1is a flowchart of a method of linking digital objects to content of a structured network document, according to one embodiment of the invention;
[0041] Figure 2 is a block diagram of a computing device for implementing a method of linking digital objects to content of a structured network document, according to one embodiment of the invention;
[0042] Figure 3 is a flowchart of a content linking or anchoring method, according to one embodiment of the invention;
[0043] Figure 4 is a flowchart of a method of evaluating contextual completeness of a digital object in a structured network document, according to one embodiment of the invention;
[0044] Figure 5 is a block diagram of an exemplary scenario of anchor points in a usage policy defined in a method of defining a usage policy for a digital object, according to one embodiment of the invention;
[0045] Figure 6 is a flowchart of a watermarking method, according to one embodiment of the invention;
[0046] Figure 7 is a block diagram of a usage policy evaluation apparatus, according to one embodiment of the invention;
[0047] Figure 8 is a block diagram of a usage policy evaluation apparatus, according to another embodiment of the invention.
[0048] In the drawings, underlined numerals refer to items that are discussed in the description corresponding with the underlined numerals. Non-underlined numerals refer to items that are discussed in the description corresponding with the non-underlined numerals. When a numeral is not underlined and has an associated arrow, the non-underlined numeral is used to identify the general item that the arrow is pointing to. DETAILED DESCRIPTION
[0049] The following detailed description illustrates embodiments of the invention and methods through which these embodiments can be implemented. While some modes for carrying out the invention have been disclosed, those skilled in the art will recognize that other embodiments for carrying out or practicing the invention can exist.
[0050] Figure 1 is a flowchart of a method of defining a usage policy for a digital object, according to one embodiment of the invention. Reference is made to Figure 1 , Figure 1 A method 100 of defining a usage policy for a digital object, according to one embodiment of the invention, is shown. The method 100 includes steps 102 through 106.
[0051] At step 102, the method 100 includes selecting a digital object to be protected in an unstructured digital environment. In an implementation, the digital object is a graphical digital object in the unstructured digital environment. Examples of the digital object can include an image, a text, a video file, an audio file, and the like. In an implementation, the unstructured digital environment is a digital space in which information is not organized in a specific or predefined manner. Examples of the unstructured digital environment can include, but are not limited to, an unstructured web page in a virtual reality (VR) environment, a social media platform, a discussion forum, and the like. In an implementation, in the method 100, a content owner or creator of the digital object selects the corresponding digital object that has to be protected from being tampered or reused by any third party.
[0052] In step 104, the method 100 includes defining a usage policy with a policy identifier (ID) for the selected digital object to include one or more anchors, where each anchor is related to a digital object or activity that can be observed in the unstructured digital environment. In one example, the digital objects and activities observed in the unstructured digital environment are "pen" and "teaching", respectively. Here, the usage policy is determined to include two anchors, one is a first anchor similar to the digital object "pen" and the other is a second anchor similar to the activity "teaching". Examples of the first anchor can include "pen", "pencil", "marker", and "chalk", etc. related to the digital object "pen". Similarly, examples of the second anchor can include "teaching", "speaking", "learning", and "writing", etc. related to the digital object "teaching". In this example, the method 100 includes determining one or more anchors from the digital objects and activities observed in the unstructured environment to establish a connection between the digital object to be protected and the unstructured digital environment. In one implementation, the policy identifier is a compact numerical or textual value that identifies the usage policy for the digital object. In one implementation, the one or more anchors in the usage policy include a list of digital objects and activities that are approved or disapproved to appear in the same representation as the representation of the digital object. Examples of the approved digital objects and activities can include, but are not limited to, school, teacher, child, pen, computer, reading, learning, game, etc. Examples of the disapproved digital objects and activities can include, but are not limited to, gun, nudity, gambling, violence, crime, etc. According to one embodiment, defining the usage policy includes selecting one of a plurality of predefined usage policies from a policy repository as the usage policy or as a basis to define the usage policy. The policy repository includes one or more predefined usage policies. In one implementation, the policy repository is a subsystem that is a collection of known usage policies labeled with corresponding policy identifiers. In one example, the policy repository is configured as a local service. In another example, the policy repository is hardcoded if the usage policy is standardized and well-known. The policy repository is advantageous to provide an efficient storage medium from which a suitable usage policy can be retrieved.
[0053] In addition, each of the plurality of predefined usage policies has a policy ID and includes one or more anchors, which are digital objects and / or activities that can be observed in the unstructured digital environment. In other words, each predefined usage policy includes one or more anchors and is identified by a policy ID. The predefined usage policy specifies the purpose of using the digital object in the unstructured environment. In one example, the usage policy is an educational usage policy, and the policy ID is EDUCHOOL1. The advantage of the policy ID is that it is easy to identify the usage policy. In addition, each anchor has a category and a weight. Further, the category is one of a whitelist category and a blacklist category, the whitelist category including anchors that are approved to be used with the digital object, the blacklist category including anchors that are not approved to be used with the digital object, and the weight represents the importance of each anchor. In one implementation, an anchor belonging to the whitelist category corresponds to a reinforced approval decision, and an anchor belonging to the blacklist category corresponds to a violation of the usage policy. Thus, the category of each of the one or more anchors represents whether the corresponding anchor is an approved anchor or an unapproved anchor. In one implementation, the weight of each of the one or more anchors is a numerical value for determining the importance of the corresponding anchor. In addition, the weight assigned to an anchor is beneficial for determining necessary anchors, which are necessary to establish a connection between the digital object and the unstructured digital environment. For example, the most important anchors (i.e., essential anchors) are assigned a higher weight, and the less important anchors (i.e., optional additional anchors) are assigned a smaller weight. According to one embodiment, defining a usage policy includes selecting one or more digital objects and / or one or more activities that can be observed in the unstructured digital environment as anchors according to a predefined selection algorithm and / or user input. In one implementation, the predefined selection algorithm is an algorithm associated with the method 100 for automatically selecting one or more digital objects and / or one or more activities as anchors according to predefined conditions. In one example, if the usage policy of the digital object to be protected in the unstructured environment involves teaching, a digital object such as a "whiteboard" or a "teacher" and an activity such as "writing" or "teaching" are predefined. In another implementation, a user operating the unstructured digital environment sends user input to a system configured with the unstructured digital environment.
[0054] Further, defining the usage policy includes assigning a category and a weight to each of the anchor points. The category is one of a whitelist category and a blacklist category, the whitelist category including anchor points approved for use with the given digital object, and the blacklist category including anchor points disapproved for use with the given digital object. The weight is selected according to a predefined weighting algorithm and / or user input to represent the importance of each anchor point. In one implementation, the predefined weighting algorithm is an algorithm associated with the method 100 for automatically selecting the weight according to the importance of each corresponding anchor point. In another implementation, a user operating the unstructured digital environment determines the weight of each anchor point and sends the corresponding weight to the system. The unstructured digital environment is used to operate on the system. The predefined weighting algorithm and the predefined selection algorithm facilitate accurate and fast selection of the digital object and / or activity and assignment of the weight, thereby reducing the execution time of the method 100. Further, the user input for selecting the digital object and activity and assigning the weight provides flexibility or manual control for the method 100.
[0055] Additionally, the method 100 further includes storing the selected anchor points with the assigned categories and weights as part of the usage policy into a policy repository. After assigning the categories (e.g., blacklist category or whitelist category) and the weights, the method 100 includes storing the selected anchor points as part of the usage policy into the policy repository. In one implementation, the anchor points have an object type or an activity type classified according to the digital object and scene identification module. An example of the anchor points, anchor point types, anchor point categories, and corresponding weights is shown in the following table.
[0056] Table 1
[0057] Anchor ID Type Category Weight OID 1 Object White List 0.5 OID 2 Object Black List 0.15 OID N Activity White List 0.2 OID M Activity White List 0.15
[0058] As shown in Table 1, the anchor point with anchor point ID of “OID 1” is most important for protecting the digital object. Accordingly, a weight of 0.5 is assigned to the anchor point OID 1, and the weights of the remaining anchor points are assigned accordingly through the predefined weighting algorithm or user input.
[0059] According to one embodiment, defining the usage policy further includes defining one or more policy violation conditions to set conditions in which the usage policy of the protected digital object is violated in a digital environment, wherein the digital environment includes the protected digital object. In other words, the protected digital object must meet the policy violation conditions to be considered authentic or true. The importance of defining the policy violation conditions is to determine anchor points that contradict the context of the protected digital object according to the usage policy. In one implementation, the anchor points belonging to the blacklist category meet the policy violation conditions. The policy violation conditions facilitate providing accurate measures for determining any tampering behavior associated with the protected digital object.
[0060] In step 106, the method 100 includes embedding a policy watermark into the selected digital object, wherein the policy watermark includes a policy ID of the usage policy and a start marker for supporting bit frame alignment and encoding policy watermark parameters. In one example, the policy watermark refers to information embedded into the selected digital object for associating the selected digital object with the usage policy. The policy watermark serves as a fingerprint or an identification of the usage policy in the unstructured digital environment. If any digital object is embedded with the policy watermark, the corresponding digital object belongs to the explicit usage policy (the policy ID of the usage policy is encoded into the policy watermark). The policy watermark embedded into the digital object provides an identification for the digital object. Further, if such a digital object embedded with the policy watermark is transferred into any other unstructured digital environment, the digital object can be easily identified and associated with the original unstructured digital environment. In addition, the start marker is a recognizable bit pattern for supporting bit frame alignment and encoding policy watermark parameters such as specific techniques, patch size, etc. In one implementation, the start marker can be used to evaluate the tampering degree of the digital object in the unstructured digital environment. In one implementation, the policy watermark parameters are based on image statistical parameters of robust watermarking processing, for example, discrete cosine transform (DCT) encoding, etc. The policy watermark associates the digital object with the corresponding unstructured digital environment. The policy watermark is used to prevent the human-impacted cyber attacks encountered in the digital object within the unstructured environment, for example, fake news, impersonation, fraud, phishing, etc.
[0061] In one implementation, a digital object is selected from an unstructured digital environment. Then, a usage policy corresponding to the selected digital object is selected from a policy repository, the policy repository including anchors related to the digital object. Further, a policy identifier is assigned to the usage policy. Additionally, a weight is assigned to each anchor based on the importance of the corresponding anchor. Moreover, the anchors and corresponding weights are stored as part of the usage policy in the policy repository. Further, a policy watermark and the policy identifier are embedded into the digital object. In one implementation, the policy watermark includes a start tag, an anchor bag, and one or more decision boundaries. In one example, the anchor bag is some anchors that belong to a whitelist category or a blacklist category. In one implementation, the policy watermark is embedded into the digital object by a content owner during the process of preparing the digital object or by an automated system. In one example, the policy watermark is embedded into the digital object by a third party authorized by the content owner in real time by an automated system. If the digital object is a video file, the policy watermark is embedded into all video frames or partial video frames of the corresponding video file to support stable detection and retrieval of the policy watermark. In one implementation, the details of the usage policy are maintained by a context verification system in a form of standardized data or global data or a paid service.
[0062] The method 100 is advantageous in preventing cyber attacks, such as fake news, impersonation, fraud, phishing, etc., that affect humans in digital objects within unstructured environments. The policy watermark embedded into the digital object does not affect the quality of the protected digital object and is almost impossible to be removed by any attacker with regular skills, which is advantageous in protecting the protected digital object from being tampered by any adversary. The method 100 eliminates manual errors in identifying tampered digital objects, which is advantageous in accurately detecting cyber attacks. Additionally, the method 100 is also applicable to all types of digital objects, which is advantageous in detecting whether any type of digital object is tampered. The policy watermark created by the method 100 is advantageous in verifying the authenticity and integrity of the usage policy of the protected digital object and maintaining the link between the protected digital object and the corresponding unstructured digital environment. The method 100 can be used to disclose new functions by observing suitable evaluation procedures and hints to end users, by detecting suitable watermarks in digital objects, by checking the UI of content editors, and by looking for advertisements of related functions in the user manual of content editors.
[0063] Figure 2 is a block diagram of a computing device provided by one embodiment of the present invention, the computing device being used to implement a method of defining a usage policy for a digital object. Referring to Figure 2 , Figure 2 shows a block diagram 200 of a computing device 202 provided by one embodiment of the present invention, the computing device 202 being used to implement a method of defining a usage policy for a digital object Figure 1the method 100.
[0064] The computing device 202 is a hardware control device for defining a digital object usage policy. The computing device 202 includes a first controller 204, a first communication interface 206, and a first memory 208. The first controller 204 is configured to process corresponding digital objects by adding a policy watermark into the digital objects to define a usage policy. Examples of the first controller 204 can include, but are not limited to, a central data processing device, a microprocessor, a microcontroller, a complex instruction set computing (CISC) processor, an application-specific integrated circuit (ASIC) processor, a reduced instruction set (RISC) processor, a very long instruction word (VLIW) processor, a state machine, and other processors or control circuits. Examples of the implementation of the first communication interface 206 can include, but are not limited to, a network interface, a computer port, a network socket, a network interface controller (NIC), and any other network interface device. The first memory 208 is configured to store the usage policy defined by the first controller. Examples of the implementation of the first memory 208 can include, but are not limited to, an Electrically Erasable Programmable Read-Only Memory (EEPROM), a Dynamic Random-Access Memory (DRAM), a Random Access Memory (RAM), a Read-Only Memory (ROM), a Hard Disk Drive (HDD), a flash memory, a Secure Digital (SD) card, a Solid-State Drive (SSD), and / or a CPU cache memory.
[0065] During operation, the computing device 202 is used to select a digital object to be protected in an unstructured digital environment. Examples of digital objects can include, but are not limited to, graphical digital objects, e.g., images, video files, audio files, etc. Further, the computing device 202 is used to define a usage policy with a policy identifier for the selected digital object. The usage policy includes one or more anchors, each anchor being related to a digital object and activity that can be observed in the unstructured digital environment. According to one embodiment, the computing device 202 is used to select the usage policy from predefined usage policies stored in a policy repository. Each of the predefined usage policies has a policy ID and one or more anchors that are digital objects and / or activities that can be observed in the unstructured digital environment. The computing device 202 is used to select the digital object and / or activity according to a predefined selection algorithm and / or according to user input received through the first communication interface 206. Further, the computing device 202 is used to assign a category (blacklist category or whitelist category) and a weight to each of the selected anchors. After selecting the usage policy, anchors, categories, and weights, the computing device 202 is used to define one or more policy conditions to set conditions for violating the usage policy. Further, the computing device 202 is used to generate a policy watermark. The policy watermark includes the policy ID of the usage policy and a starting marker. Additionally, the computing device 202 is used to embed the policy watermark into the selected digital object.
[0066] The computing device 202 facilitates preventing cyberattacks that affect humans encountered in digital objects within unstructured environments, e.g., fake news, impersonation, scams, phishing, etc. The policy watermark generated by the computing device 202 does not affect the quality of the digital object to be protected and is almost impossible to be removed by any attacker with regular skills, which facilitates protecting the digital object from being tampered by any adversary. The computing device 202 eliminates manual errors in identifying tampered digital objects, which facilitates accurately detecting cyberattacks. Additionally, the computing device 202 generates policy watermarks for all types of digital objects, which facilitates detecting whether any type of digital object is tampered. The policy watermark created by the computing device 202 facilitates verifying the authenticity and integrity of the usage policy of the digital object and maintaining the link between the digital object and the corresponding unstructured digital environment.
[0067] Figure 3 is a flowchart of a method for evaluating a usage policy of a digital object, according to an embodiment of the application. Figure 3 The elements in Figure 1 are described in conjunction with. Figure 3 , Figure 3 FIG. 3 shows a flowchart of a method 300 for evaluating a usage policy of a digital object, according to an embodiment of the application. The method 300 includes steps 302-314.
[0068] At step 302, the method 300 includes detecting a protected digital object embedded with a policy watermark in an unstructured digital environment. The protected digital object is a digital object embedded with a policy watermark. In one implementation, the policy watermark is embedded into the digital object by the method 100 of (https: / / patents.google.com / patent / US20190359357A1 / issue) in another implementation, the policy watermark is embedded into the digital object by the computing device 202 of (https: / / patents.google.com / patent / US20190359357A1 / issue) The method 300 iterates through the entire unstructured digital environment to find any digital object embedded with a policy watermark. Examples of the unstructured digital environment can include, but are not limited to, an unstructured web page such as a virtual reality (VR) environment, a social media platform, a discussion forum, etc. At step 304, the method 300 includes decoding a policy identifier (ID) from the policy watermark of the protected digital object. The policy identifier is a numerical value representing the identification of the policy watermark embedded into the protected digital object. Figure 1 Figure 2 At step 306, the method 300 includes retrieving a usage policy with the decoded policy ID from a policy repository, wherein the usage policy includes one or more anchors belonging to a whitelist category and / or a blacklist category, the one or more anchors are related to digital objects and / or activities that can be observed in the unstructured digital environment. In one implementation, the policy repository is a storage medium for storing one or more predefined usage policies with corresponding policy identifiers. According to the policy identifier detected in the protected digital object, the method 300 detects a usage policy with the same policy identifier in the policy repository. In one example, if the policy identifier detected in the policy watermark is EDUCHOOL1, the method 300 also detects a usage policy with the policy identifier EDUCHOOL1 in the policy repository. In one implementation, each anchor belonging to the whitelist category and / or the blacklist category is compared with a predefined template, and the comparison result is counted into an overall match accumulator.
[0069]
[0070] At step 308, the method 300 includes detecting one or more digital objects and / or one or more activities in the unstructured digital environment that are the same as the anchors in the usage policy. After selecting the usage policy from the policy repository, the method 300 further includes detecting one or more digital objects and / or one or more activities in the unstructured digital environment that are the same as the one or more digital objects and / or one or more activities that are anchors in the usage policy. For example, the usage policy includes the anchor "child" as a digital object and the anchor "teaching" as an activity. The method 300 further detects whether the same anchors "child" and "teaching" are found in the unstructured digital environment. The significance of finding the same digital objects and / or activities in the unstructured digital environment as the anchors in the usage policy is that the authenticity of the detected digital objects is detected, as opposed to the digital objects being protected by the policy watermark. Moreover, if the same digital objects and / or activities corresponding to the detected digital objects are not found, then the detected digital objects are from a different unstructured digital environment, and any information represented by the digital objects is consistent with the context of the original digital objects.
[0071] At step 310, the method 300 includes calculating a context match score for the protected digital object based on the detected digital objects and / or activities in the unstructured digital environment that are the same as the anchors in the usage policy that belong to the whitelist category. In one implementation, the context match score is a numerical value that represents the degree of match between the detected digital objects and / or activities in the unstructured digital environment and the anchors in the usage policy that belong to the whitelist category. The context match score decreases as the number of same digital objects and / or activities decreases, and vice versa. In one example, anchors such as "pen" as a digital object and "writing" as an activity appear in the whitelist category to which the anchors in the usage policy belong. Moreover, if these anchors are found in the digital objects of the unstructured digital environment, then the context match score is the highest, and thus the corresponding digital objects are deemed authentic or true. At step 312, the method 300 includes calculating a context mismatch score for the protected digital object based on the detected digital objects and / or activities in the unstructured digital environment that are the same as the anchors in the usage policy that belong to the blacklist category. In one implementation, the context mismatch score is a numerical value that represents the degree of match between the detected digital objects and / or activities in the unstructured digital environment and the anchors in the usage policy that belong to the blacklist category. The context mismatch score increases as the number of same digital objects and / or activities decreases, and vice versa. In one example, anchors such as "firearm" as a digital object and "violence" as an activity appear in the blacklist category to which the anchors in the usage policy belong. Moreover, if these anchors are found in the digital objects of the unstructured digital environment, then the context mismatch score is the highest, and thus the corresponding digital objects are inconsistent with the context of the original digital objects.
[0072] According to an embodiment, the method 300 comprises obtaining a weight for each of the anchors in the usage policy. In an implementation, the weight for each of the anchors is a numerical value assigned to each anchor according to the importance of the corresponding anchor. The weight assigned to an anchor facilitates the determination of the necessary anchors, which are necessary to establish a link between the digital object and the unstructured digital object. Moreover, computing the context match score comprises summing the weights of the anchors belonging to the whitelist category that are detected in the unstructured digital environment for the same digital object or activity. In other words, after detecting the same anchors in the unstructured digital environment as the anchors belonging to the whitelist category in the usage policy, the method 300 obtains the weight of each anchor and computes the context match score by summing the weights of all the anchors. According to an embodiment, computing the context mismatch score comprises summing the weights of the anchors belonging to the blacklist category that are detected in the unstructured digital environment for the same digital object or activity. In other words, after detecting the same anchors in the unstructured digital environment as the anchors belonging to the blacklist category in the usage policy, the method 300 comprises obtaining the weight of each anchor and computing the context mismatch score by summing the weights of all the anchors.
[0073] According to an embodiment, the method 300 comprises determining a manipulation correction factor (MCF) according to the degree of manipulation performed on the protected digital object. The manipulation correction factor is a numerical value that represents the degree of manipulation associated with the protected digital object. The manipulation correction factor facilitates the accuracy of the determination of the manipulated digital object. In an implementation, the value of the manipulation correction factor (MCF) represents the decrease in trustworthiness caused by the manipulation of the protected digital object. The manipulation correction factor represents the degree of manipulation associated with any digital object, which facilitates the accuracy of the determination of the manipulated digital object. Moreover, computing the context match score further comprises multiplying the sum of the corresponding weights by the manipulation correction factor and computing the context mismatch score further comprises multiplying the sum of the corresponding weights by the manipulation correction factor. In an example, the context match score is represented as MS+ and is computed according to the following expression:
[0074]
[0075] where MCF = tamper correction factor, Ai = value of an anchor point (i.e., digital object and / or activity) detected in the unstructured digital environment, and Pi = value of an anchor point (i.e., digital object and / or activity) detected in the usage policy for the corresponding protected digital object. In one example, the value of Pi is the ontology identifier (OID) of the anchor point. Further, = match operator (0 for mismatch, 1 for match), and Wi = weight of an anchor point detected in the unstructured digital environment that belongs to a white list category. For each anchor point detected in the unstructured digital environment, the value of is calculated, and all values are added up until N anchor points, resulting in a context match score (MS+).
[0076] In one example, the context mismatch score is denoted as MS- and is calculated according to the following expression:
[0077]
[0078] where MCF = tamper correction factor, Ai = value of an anchor point (i.e., digital object and / or activity) detected in the unstructured digital environment, and Pi = value of an anchor point (i.e., digital object and / or activity) detected in the usage policy for the corresponding protected digital object, = match operator (0 for mismatch, 1 for match), and Wi = weight of an anchor point detected in the unstructured digital environment that belongs to a white list category. For each anchor point detected in the unstructured digital environment, the value of is calculated, and all values are added up until N anchor points, resulting in a context match score (MS+).
[0079] At step 314, the method 300 includes notifying the user of a violation of a usage policy of a protected digital object in a given unstructured digital environment if the context match score or the context mismatch score does not meet a policy violation condition. The policy violation condition is a condition that indicates a violation of the usage policy. Violating the policy violation condition means that the context of the protected digital object is different from the context of the unstructured digital environment, and thus any information represented by this digital object is out of context of the digital object. According to one embodiment, the policy violation condition in the method 300 is defined according to one of the following cases: for example, the context match score does not meet the policy violation condition if the context match score is less than a context match threshold; the context mismatch score does not meet the policy violation condition if the context mismatch score is greater than a context mismatch threshold. In one implementation, the context match threshold is a numerical value that represents a minimum value of the context match score, i.e., a maximum allowed mismatch between digital objects and / or activities in the usage policy that belong to the whitelist category and the digital objects / activities detected in the unstructured digital environment. In another implementation, the context mismatch threshold is a numerical value that represents a maximum value of the context mismatch score, i.e., a minimum allowed match between digital objects and / or activities in the usage policy that belong to the blacklist category and the digital objects and / or activities detected in the unstructured digital environment. In this embodiment, the context match threshold and the context mismatch threshold are predefined and / or included in the usage policy. In one implementation, the usage policy indicates that the context match score or the context mismatch score of the digital objects and / or activities detected in the unstructured digital environment should not be less than the context match threshold and / or should not be greater than the context mismatch threshold. According to another embodiment, the policy violation condition in the method 300 is defined such that, for example, the context match score and the context mismatch score do not meet the policy violation condition if the quotient of the context match score divided by the context mismatch score is greater than a violation threshold. The quotient of the context match score divided by the context mismatch score is represented by the following expression:
[0080] Quotient (D) = Context match score / Context mismatch score = MS+ / MS-
[0081] To satisfy the policy violation condition, the value of D should be less than a violation threshold. The violation threshold is a numerical value that represents the maximum allowed degree of policy violation. Further, if the value of the context mismatch score is increased while keeping the context match score constant, the value of the quotient decreases and the likelihood of violating the policy violation condition increases. In this embodiment, the violation threshold is predefined and / or included in the usage policy. According to another embodiment, the policy violation condition in the method 300 is defined such that if the difference between the context match score and the context mismatch score is less than the violation threshold, then neither the context match score nor the context mismatch score satisfies the policy violation condition. The violation threshold is per usage policy and when the violation threshold of a usage policy is exceeded, it is considered that the policy violation condition of the corresponding usage policy is violated. The method 300 includes retrieving the value of the violation threshold from the usage policy stored in the policy repository. In one implementation, if the context match score is greater than the violation threshold and the context mismatch score is less than the violation threshold, then neither the context match score nor the context mismatch score satisfies the policy violation condition and the context of the corresponding digital object is in compliance with the unstructured digital environment.
[0082] According to one embodiment, the policy violation condition in the method 300 is defined such that if the difference between the context match score and the context mismatch score is less than the violation threshold, then neither the context match score nor the context mismatch score satisfies the policy violation condition. In one implementation, the violation of the policy violation condition is determined by the difference between the context match score and the context mismatch score. In this implementation, to satisfy the policy violation condition, the difference between the context match score and the context mismatch score should be less than the violation threshold. Further, the violation threshold is predefined and / or included in the usage policy. The violation threshold for the quotient of the context match score and the context mismatch score (D) is different from the violation threshold for the difference between the context match score and the context mismatch score. The policy violation condition determines the condition under which the protected digital object violates the usage policy, which is beneficial to provide an accurate measure for determining any tampering behavior associated with the protected digital object. The context match threshold, the context mismatch threshold, and the violation threshold are beneficial to determine the allowable variation between the context of the protected digital object and the unstructured digital environment and provide an effective measure to identify the tampered digital object.
[0083] According to one embodiment, notifying the user of a violation of the usage policy of the protected digital object comprises providing a visual cue and / or an audio cue to the user when presenting the unstructured digital environment on the user device. In other words, when a policy violation condition is violated, the user device generates a visual cue and / or an audio cue to notify the user operating the user device of the difference between the context of the protected digital object and the context of the unstructured digital environment. In one example, the visual cue comprises displaying a colored box around the protected digital object, which indicates that the corresponding digital object is out of context of the unstructured digital environment. In one example, the visual cue comprises superimposing a specific label on the presentation of the digital object in the form of a text superimposed on the digital object or an emoji integrated with the digital object. Further, the visual cue comprises a pop-up bubble displaying a warning message on the structured web document. In one example, the audio cue comprises a sound emitted by the user device indicating that the image is fake. Examples of the user device can include, but are not limited to, a computer or a laptop or a portable communication device, etc. The visual cue and / or the audio cue are advantageous to simply indicate the lack of integrity of the digital object, so that the above-mentioned improved method can be implemented on any system by anyone who is not technically knowledgeable.
[0084] The method 300 can automatically evaluate any digital object in the process of presenting any unstructured digital environment, thereby indicating to the user whether any digital object in the unstructured digital environment is tampered. The method 300 is advantageous to reduce manual errors when evaluating the authenticity of the digital object. The method 300 is advantageous to identify digital objects providing false information and to provide a warning to the user about such information. In addition, the method 300 is applicable to all types of digital objects. Further, the visual cue indicated in the method 300 is advantageous to let all types of users identify tampered digital objects regardless of the technical knowledge of the user.
[0085] Figure 4 is a block diagram of a usage policy evaluation apparatus provided by one embodiment of the present application. Figure 4 In conjunction with the elements in Figure 1 , Figure 2 and Figure 3 are described. Referring to Figure 4 , Figure 4 shows a block diagram 400 of a usage policy evaluation apparatus 402 provided by one embodiment of the present application. The usage policy evaluation apparatus 402 comprises an object and activity identification module 404, a protected object detector 406, a watermark decoder 408 and a policy evaluation module 410.
[0086] The usage policy evaluation apparatus 402 is a hardware control unit for evaluating usage policies of digital objects in unstructured digital environments. Examples of the usage policy evaluation apparatus 402 can include, but are not limited to, central data processing devices, microprocessors, microcontrollers, complex instruction set computing (CISC) processors, application-specific integrated circuit (ASIC) processors, reduced instruction set (RISC) processors, very long instruction word (VLIW) processors, state machines, and other processors or control circuits. The object and activity identification module 404 is configured to detect digital objects and activities in unstructured digital environments such as video content or virtual reality environments. Examples of digital objects in unstructured digital environments can include, but are not limited to, video files, audio files, images, and the like in unstructured digital environments. Examples of activities can include, but are not limited to, teaching, gaming, reading, and the like occurring in unstructured digital environments. In one implementation, the object and activity identification module 404 is configured to analyze unstructured digital environments to detect digital objects and activities occurring in unstructured digital environments. Further, the protected object detector 406 is configured to detect protected digital objects embedded with policy watermarks. In one implementation, the protected object detector 406 detects protected digital objects from digital objects and activities detected by the object and activity identification module 404 in unstructured digital environments. In one implementation, the protected digital object is a graphical digital object embedded with a policy watermark in unstructured digital environments. In one implementation, the policy watermark is a fingerprint of a usage policy associated with the protected digital object. In one implementation, the policy watermark is embedded into the protected digital object by the method 100 (of FIG. 1) that defines the usage policy. Figure 1 Further, the watermark decoder 408 is configured to decode a policy ID from the policy watermark embedded in the protected digital object. In one implementation, the protected object detector 406 sends information about the protected digital object and the corresponding policy watermark to the watermark decoder 408 after detecting the protected digital object. Further, the watermark decoder 408 decodes the policy ID from the policy watermark, which facilitates identifying the usage policy associated with the protected digital object. In one implementation, the policy ID is an alphanumeric value that identifies the corresponding usage policy.
[0087] Further, the policy evaluation module 410 is configured to obtain the usage policy with the decoded policy ID from the policy repository. The policy repository is a storage medium configured to store one or more usage policies with corresponding policy IDs. In one implementation, the policy evaluation module 410, after receiving the information about the policy ID of the protected digital object from the watermark decoder 408, checks the policy repository according to the policy ID, thereby obtaining the usage policy. In one implementation, the policy evaluation module can be triggered automatically or triggered by manual invocation. Further, the usage policy includes one or more anchors belonging to the whitelist category and / or the blacklist category, which are related to digital objects and / or activities that can be observed in the unstructured digital environment. In one implementation, the one or more anchors are digital objects and / or activities related to the digital objects and / or activities observed in the unstructured digital environment by the object and activity identification module 404. These anchors belong to the whitelist category or the blacklist category. Considering the usage of the protected digital object, the anchors belonging to the whitelist category are approved anchors, and the anchors belonging to the blacklist category are disapproved anchors. Further, after obtaining the usage policy, the object and activity identification module 404 is configured to detect one or more digital objects and / or one or more activities in the unstructured digital environment that are identical to the anchors in the usage policy. After the policy evaluation module 410 determines the whitelist category anchors and / or the blacklist category anchors, the policy evaluation module 410 sends information about the corresponding anchors to the object and activity identification module 404, and then the object and activity identification module 404 determines the digital objects and / or activities identical to the anchors from the unstructured digital environment and sends information to the policy evaluation module 410.
[0088] The policy evaluation module 410 is further configured to calculate a context match score of the protected digital object based on the detected digital objects and / or activities that are identical to the anchor points in the usage policy that belong to the whitelist category. In one implementation, the context match score is a numerical value that represents how close the context of the protected digital object is to the context of the unstructured digital environment. Further, the policy evaluation module 410 is configured to calculate a context mismatch score of the protected digital object based on the detected digital objects and / or activities that are identical to the anchor points in the usage policy that belong to the blacklist category. In one implementation, the context mismatch score is a numerical value that represents the difference between the context of the protected digital object and the context of the unstructured digital environment. Additionally, the policy evaluation module 410 is configured to determine that the usage policy of the protected digital object in the given unstructured digital environment is violated if either the context match score or the context mismatch score does not satisfy a predefined policy violation condition. In one implementation, the policy evaluation module 410 determines whether the protected digital object in the unstructured digital environment violates the usage policy based on the context match score and the context mismatch score. The predefined policy violation condition is a condition that is used as a distinguishing parameter between a real digital object and a tampered digital object. If the protected digital object in the unstructured digital environment violates the predefined policy violation condition, then the context of the protected digital object is different from the context of the unstructured digital environment, and thus any information disclosed by the protected digital object is tampered.
[0089] According to one embodiment, the policy evaluation module 410 is configured to determine a violation of the usage policy of the protected digital object if the context match score is less than a context match threshold or the context mismatch score is greater than a context mismatch threshold. In one implementation, the context match threshold is a minimum allowed difference between the context of the protected digital object and the context of the unstructured digital environment. In another implementation, the context mismatch threshold is a maximum allowed difference between the context of the protected digital object and the context of the unstructured digital environment. Further, the context match threshold and the context mismatch threshold are predefined or included in the usage policy. Each usage policy in the policy repository includes a context match threshold and a context mismatch threshold corresponding to the usage policy. If the protected digital object belongs to an explicit usage policy, the context match score and the context mismatch score of the protected digital object are decision parameters for detecting a violation of the corresponding usage policy. Alternatively, the policy evaluation module is configured to determine a violation of the usage policy of the protected digital object if a quotient of the context match score divided by the context mismatch score is greater than a violation threshold. Further, the violation threshold is predefined or included in the usage policy. In one implementation, the violation threshold is a minimum value of the quotient of the context match score and the context mismatch score for determining a violation of a predefined policy violation condition. Alternatively, the policy evaluation module is configured to determine a violation of the usage policy of the protected digital object if a difference between the context match score and the context mismatch score is less than a violation threshold. Further, the violation threshold is predefined or included in the usage policy. In one implementation, the violation threshold is a maximum value of the difference between the context match score and the context mismatch score for determining a violation of a predefined policy violation condition. In one implementation, the violation threshold of the quotient of the context match score and the context mismatch score is different from the violation threshold of the difference between the context match score and the context mismatch score.
[0090] According to one embodiment, the policy evaluation module 410 is used to obtain the weight of each anchor in the anchors from the usage policy. In one implementation, the weight of each anchor is a numerical value representing the importance of the corresponding anchor. The anchors in the usage policy are stored in a policy repository along with their corresponding weights. Furthermore, the policy evaluation module 410 is used to calculate a context matching score by summing the weights of anchors belonging to whitelisted categories that detect the same digital object or activity in an unstructured digital environment. For example, anchors with IDs OID01, OID02, and OID03 are detected in an unstructured digital environment; these are the same as anchors belonging to whitelisted categories in the usage policy. Anchor OID01 has a weight of 0.5, anchor OID02 has a weight of 0.3, and anchor OID01 has a weight of 0.2. The weights of the anchors are summed to 0.5 + 0.6 + 0.7 = 1.8, and the value 1.8 is used to determine the context matching score. Additionally, the policy evaluation module 410 is used to calculate a context mismatch score by summing the weights of anchors belonging to blacklist categories that detect the same digital object or activity in an unstructured digital environment. In one example, anchors with IDs OID04, OID05, and OID06 are detected in an unstructured digital environment; these anchors are the same as those belonging to blacklist categories in the policy. Anchor OID04 has a weight of 0.6, anchor OID05 has a weight of 0.2, and anchor OID06 has a weight of 0.2. The weights of the anchors are summed to 0.6 + 0.3 + 0.2 = 1.1, and the value 1.1 is used to determine the context mismatch score.
[0091] According to one embodiment, the policy evaluation module is further configured to determine a tampering correction factor based on the degree of tampering performed on the protected digital object. The tampering correction factor is a numerical value used as a measure of the degree of tampering associated with the protected digital object. The policy evaluation module 410 is further configured to: calculate a context matching score by multiplying the sum of corresponding weights by the tampering correction factor; and calculate a context mismatch score by multiplying the sum of corresponding weights by the tampering correction factor. In one example, the policy evaluation module 410 calculates the context matching score according to the following expression:
[0092] Context Matching Score = MCF ∑W i
[0093] Among them, W i =The weight of anchors belonging to whitelisted categories when the same digital objects and / or activities are detected in unstructured digital environments, MCF = tamper correction factor. Furthermore, the policy evaluation module 410 calculates the context mismatch score according to the following expression:
[0094] Context mismatch score = MCF ∑Wj
[0095] wherein, W j = weight of anchor points belonging to the blacklist category detected in the unstructured digital environment for the same digital object and / or activity, MCF = tamper correction factor.
[0096] According to an embodiment, the policy evaluation module 410 is part of an endpoint security subsystem or a cloud service framework. The endpoint security subsystem is a system that protects digital objects in an unstructured digital environment, which can be installed by any user on their computing device to protect the context of the digital objects. The cloud service framework includes a remote service provider that receives data related to digital objects and unstructured digital environments from users through a cloud server, evaluates the usage policy of the digital objects, and sends information to the user about any tampering behavior of the digital objects. In addition, the policy evaluation module 410 is also used to notify the user of the determination of a violation of the usage policy of the protected digital object by providing visual and / or sound cues to the user when presenting the unstructured digital environment on the user device. The user device is a hardware computing device used to notify the user of the violation of the usage policy of the protected digital object. Examples of the user device can include, but are not limited to, a computer, a laptop, a portable communication device, and the like. In one example, the visual cue includes displaying a colored box around the protected digital object, which indicates that the corresponding digital object is out of context from the unstructured digital environment. In one example, the visual cue includes superimposing a specific label on the presentation of the digital object in the form of text superimposed on the digital object or an emoji integrated with the digital object. In addition, the visual cue includes a pop-up bubble displaying a warning message on the structured web document. In one example, the sound cue includes a sound emitted by the user device indicating that the image is fake. The visual cue and the sound cue are beneficial to prevent the user from being affected by any tampered information.
[0097] The usage policy evaluation apparatus 402 can automatically evaluate any digital object in the process of presenting any unstructured digital environment, thereby indicating to the user whether any digital object in the unstructured digital environment is tampered. The usage policy evaluation apparatus 402 is beneficial to reduce manual errors when evaluating the authenticity of digital objects. The usage policy evaluation apparatus 402 is beneficial to identify digital objects that provide false information and provide warnings to the user about such information. In addition, the usage policy evaluation apparatus 402 is applicable to all types of digital objects. Furthermore, the visual cues and sound cues indicated in the usage policy evaluation apparatus 402 are beneficial to allow all types of users to identify tampered digital objects regardless of the technical knowledge of the user.
[0098] Figure 5is a block diagram of an exemplary scenario of an anchor point in a usage policy defined in a digital object usage policy provided by an embodiment of the invention. Figure 5 In conjunction with Figure 2 and Figure 4 elements are described. Refer to Figure 5 , Figure 5 shows a block diagram 500 of an exemplary scenario of an anchor point in a usage policy defined in a method 100 of defining a digital object usage policy. Figure 1
[0099] In one example, the usage policy defined in the method 100 of defining a digital object usage policy includes a policy ID, EDUCHOOL1. The usage policy includes two categories of anchor points, one is approved anchor points and the other is disapproved anchor points. In one implementation, the approved anchor points belong to a whitelist category and the disapproved anchor points belong to a blacklist category. The approved anchor points include digital objects and / or activities that comply with the usage policy and the disapproved anchor points include digital objects and / or activities that do not comply with the usage policy. Examples of approved (i.e., whitelisted) anchor points include whiteboard (weight = 0.95), teacher (weight = 0.78), and reading (weight 0.81). Examples of disapproved (i.e., blacklisted) anchor points include gun (weight = 0.95), drugs (weight = 0.78), and violence (weight = 0.81).
[0100] Figure 6 is a flowchart of a watermark processing method provided by an embodiment of the invention. Figure 6 In conjunction with Figure 1 to Figure 5 elements are described. Refer to Figure 6 , Figure 6 shows a flowchart of a watermark processing method 600 provided by an embodiment of the invention.
[0101] The watermarking method 600 starts at step 602. In step 604, the method 600 includes selecting a digital object to be protected from the unstructured digital environment. In step 606, the method 600 includes confirming whether a usage policy exists in the digital object to be protected. Further, if the usage policy does not exist in the digital object to be protected, step 608 is performed. In step 608, the method 600 includes selecting one or more anchors having the digital object or activity from the unstructured digital environment. Further, in step 610, the method 600 includes assigning a weight to the one or more anchors. In step 612, the method includes adding the one or more anchors to a context of the usage policy. In an implementation, the context of the usage policy refers to one or more conditions under which any digital object belongs to the usage policy. In an example, there is an image representing educational content. Here, the usage policy corresponding to the digital object is to use the image for educational purposes. Thus, the context of the usage policy corresponding to the image is "education". Any image that does not show educational content does not comply with the context of the usage policy. In an implementation, the one or more anchors added to the context of the usage policy establish a link between any digital object and the context of the usage policy. For example, if any digital object owns an anchor added to the context of the usage policy, the corresponding digital object is considered to comply with the context of the usage policy.
[0102] Steps 608 to 612 are repeated until a predefined limit is reached. In an implementation, the predefined limit corresponds to a capacity of the usage policy to store one or more anchors. After the predefined limit is exceeded, step 614 is performed. In step 614, the method 600 includes generating a policy identifier (PUID). Further, in step 616, the method 600 includes creating a new usage policy. Additionally, if the usage policy exists in the digital object to be protected, in step 618, the method 600 includes selecting the usage policy. Further, in step 620, the method 600 includes creating a policy watermark. In step 622, the method 600 includes applying the policy watermark to the digital object to be protected. The watermarking method 600 ends at step 624.
[0103] Figure 7 is a block diagram of a usage policy evaluation device according to another embodiment of the present invention. Figure 7 In conjunction with Figure 1 to Figure 6 elements from the Figure 7 , Figure 7A block diagram 700 of a usage policy evaluation apparatus 702 is shown. The usage policy evaluation apparatus 702 includes an object and activity identification system 706, a watermark usage policy identifier (WM UPUID) retriever 708, a policy verification system 710, and a usage policy (UP) violation indicator 712.
[0104] The usage policy evaluation apparatus 702 is used to detect whether a protected digital object 714 in an unstructured digital environment 704 is tampered and whether a condition of a usage policy of the corresponding protected digital object is violated. The object and activity identification system 706 receives information about the unstructured digital environment 704 and detects the protected digital object 714 in the unstructured digital environment 704. Further, the WM UPUID retriever 708 receives the protected digital object and retrieves a UPUID from the protected digital object 714. Thereafter, the WM UPUID retriever 708 sends the UPUID to the policy verification system 710. The policy verification system 710 further retrieves detailed information of the usage policy from one or more usage policies 716 according to the UPUID. In one implementation, the detailed information of the usage policy includes a list of digital objects and activities that are approved and disapproved to be found in the same representation as the protected object. In one implementation, the one or more usage policies 716 can be publicly available for the context verification system through standardized data or global data or a paid service. The policy verification system 710 evaluates the same anchor points, e.g., digital objects and activities, found in the unstructured digital environment 704 as the anchor points in the usage policy. Further, the policy verification system 710 calculates an evaluation score according to a number of matches and a number of mismatches between the digital objects and activities in the unstructured digital environment 704 and the anchor points in the usage policy. Further, the policy verification system 710 sends the evaluation score to the UP violation indicator 712 if the evaluation score calculated by the policy verification system 710 exceeds a threshold value. Further, the UP violation indicator 712 displays a user prompt in the form of a visual prompt and / or an audible prompt to notify a user operating the unstructured digital environment 704 of a policy violation condition. The policy violation condition indicates that the protected digital object violates the usage policy and therefore the information disclosed through the protected digital object 714 is false.
[0105] Figure 8 is a block diagram of a usage policy evaluation apparatus according to another embodiment of the present invention. Figure 8 In conjunction with Figure 1 to Figure 7 elements from Figure 8 , Figure 8 A block diagram 800 of a usage policy evaluation apparatus 802 is shown. The usage policy evaluation apparatus 802 includes a policy verification system 804, a usage policy (UP) violation indicator 806, and a watermark usage policy identifier (WM UPUID) retriever 808. Figure 7(In the) Object and Activity Recognition System 706, ( Figure 7 The watermark usage policy identifier (WM UPUID) retriever 708 is used in the process. Figure 7 The policy verification system 710, the policy repository 804, and (in the middle) Figure 7 The usage policy (UP) violates indicator 712.
[0106] The strategy evaluation device 802 is used for detection ( Figure 7 In the unstructured digital environment 704 ( Figure 7 The protected digital object 714 is checked for tampering and for violations of the usage policy conditions corresponding to the protected digital object. The object and activity identification system 706 receives information about the unstructured digital environment 704 and detects the protected digital object 714 within the unstructured digital environment 704. Furthermore, the WM UPUID retriever 708 receives the protected digital object 714 and retrieves a policy identifier (UPUID) from it. The WM UPUID retriever 708 then sends the UPUID to the policy verification system 710. The policy verification system 710 also retrieves usage policy details from one or more usage policies stored in the usage policy repository 804 based on the UPUID. In one implementation, the usage policy details include a list of approved and disapproved digital objects and activities found in the same representation as the protected object. In one implementation, the usage policy repository 804 is a remotely accessible subsystem that includes one or more usage policies labeled with corresponding UPUIDs. The policy verification system 710 evaluates anchors found in the unstructured digital environment 704 that are identical to anchors in the usage policy, such as digital objects and activities. Furthermore, the policy verification system 710 calculates an evaluation score based on the number of matches and non-matches between digital objects and activities in the unstructured digital environment 704 and anchors in the usage policy. If the evaluation score calculated by the policy verification system 710 exceeds a threshold, the policy verification system 710 sends the evaluation score to the UP violation indicator 712, which displays a user prompt in the form of a visual and / or audio cue to notify the user operating the unstructured digital environment 704 of a policy violation condition; that is, the protected digital object 714 violates the usage policy, and therefore the information disclosed through the protected digital object 714 is false. In one implementation, the policy evaluation device 802 is configured with a computing device 806, on which the user operates the unstructured digital environment 704.
[0107] Modifications can be made to the embodiments of the application described above without departing from the scope of the application as defined in the appended claims. "Including," "comprising," "incorporating," "have," "is" and "are" and the like are used herein to mean "including but not limited to." References to "or" can be construed as inclusive or exclusive, depending on the context. All publications, patents and patent documents are incorporated by reference herein, as though individually incorporated by reference. Citation of any reference is not an admission that it is prior art. The application has been described with reference to examples. Modifications and alterations can be made to the examples described without departing from the scope of the application. It is understood that this disclosure includes all modifications and alterations and is limited only by the scope of the following claims.
Claims
1. A method (100) of defining a digital object usage policy, characterized by, The method (100) comprises: selecting a digital object to be protected in an unstructured digital environment (704); defining a usage policy with a policy identifier (ID) for the selected digital object to include one or more anchors, wherein each anchor relates to a digital object or activity that can be observed in the unstructured digital environment (704); embedding a policy watermark into the selected digital object, wherein the policy watermark includes the policy ID of the usage policy and a start marker to support bit frame alignment and encoding of policy watermark parameters.
2. The method (100) according to claim 1, characterized in that The defining of the usage policy comprises: selecting one of a plurality of predefined usage policies from a policy repository as the usage policy or as a basis for defining the usage policy, wherein each of the plurality of predefined usage policies has a policy ID and includes one or more anchors that are digital objects and / or activities that can be observed in the unstructured digital environment, each anchor having a category and a weight, the category being one of a whitelist category and a blacklist category, the whitelist category including anchors approved for use with the digital object, the blacklist category including anchors not approved for use with the digital object, the weight representing an importance of each anchor.
3. The method (100) according to claim 1 or 2, characterized in that The defining of the usage policy comprises: selecting one or more digital objects and / or one or more activities that can be observed in the unstructured digital environment as anchors according to a predefined selection algorithm and / or user input; assigning a category and a weight to each of the anchors, wherein the category is one of a whitelist category and a blacklist category, the whitelist category including anchors approved for use with the given digital object, the blacklist category including anchors not approved for use with the given digital object, the weight being selected according to a predefined weighting algorithm and / or user input to represent an importance of each anchor; storing the selected anchors with the assigned categories and weights as part of the usage policy to a policy repository.
4. The method (100) according to any one of claims 1 or 3, characterized in that, The defining of the usage policy further comprises: defining one or more policy violation conditions to set conditions in a digital environment that violate the usage policy of the protected digital object, wherein the digital environment includes the protected digital object.
5. A method (300) of evaluating a digital object usage policy, characterized by, The method comprises: detecting a protected digital object with an embedded policy watermark in an unstructured digital environment; decoding a policy identifier (ID) from the policy watermark of the protected digital object; retrieving a usage policy with the decoded policy ID from a policy repository, wherein the usage policy includes one or more anchors that belong to a whitelist category and / or a blacklist category, the one or more anchors relating to digital objects and / or activities that can be observed in the unstructured digital environment; detecting, in the unstructured digital environment, one or more digital objects and / or one or more activities that are identical to the anchors in the usage policy; computing a context match score for the protected digital object according to the detected digital objects and / or activities that are identical to the anchors in the usage policy that belong to the whitelist category; computing a context mismatch score for the protected digital object according to the detected digital objects and / or activities that are identical to the anchors in the usage policy that belong to the blacklist category; if the context match score or the context mismatch score does not comply with a policy violation condition, notifying a user of a violation of the usage policy for the protected digital object in the given unstructured digital environment.
6. The method (300) according to claim 5, characterized by the policy violation condition is defined according to one of the following: if the context match score is less than a context match threshold and the context match score is greater than a context mismatch threshold, then the context match score and the context mismatch score do not comply with the policy violation condition, wherein the context match threshold and the context mismatch threshold are predefined and / or included in the usage policy; if a quotient of the context match score divided by the context mismatch score is greater than a violation threshold, then the context match score and the context mismatch score do not comply with the policy violation condition, wherein the violation threshold is predefined and / or included in the usage policy; if a difference between the context match score and the context mismatch score is less than a violation threshold, then the context match score and the context mismatch score do not comply with the policy violation condition, wherein the violation threshold is predefined and / or included in the usage policy.
7. The method (300) according to claim 5 or 6, characterized by the method further comprises: obtaining a weight for each of the anchors from the usage policy; the computing a context match score comprises summing the weights of the anchors that belong to the whitelist category for which an identical digital object or activity is detected in the unstructured digital environment; the computing a context mismatch score comprises summing the weights of the anchors that belong to the blacklist category for which an identical digital object or activity is detected in the unstructured digital environment.
8. The method (300) according to claim 7, characterized by the method further comprises: determining a tampering correction factor according to a degree of tampering performed on the protected digital object; the computing a context match score further comprises multiplying the sum of the corresponding weights by the tampering correction factor; the computing a context mismatch score further comprises multiplying the sum of the corresponding weights by the tampering correction factor.
9. The method (300) according to any one of claims 5 to 8, characterized by, the notifying a user of a violation of the usage policy for the protected digital object comprises providing a visual cue and / or an audible cue to the user when the unstructured digital environment is rendered on a user device.
10. A computing device (200), characterized by the computing device is configured to implement the method (100) of defining a digital object usage policy according to any one of claims 1 to 4.
11. A policy evaluation apparatus (402, 702, 802) for use in a network node (400, 700, 800), characterized by the apparatus comprises: an object and activity recognition module (404) configured to detect digital objects and activities in an unstructured digital environment such as a video content or a virtual reality environment; a protected object detector (406) configured to detect a protected digital object (714) embedded with a policy watermark; a watermark decoder (408) configured to decode a policy ID from the policy watermark embedded in the protected digital object (714); a policy evaluation module (410) configured to retrieve the usage policy having the decoded policy ID from a policy repository, wherein the usage policy comprises one or more anchors belonging to a whitelist category and / or a blacklist category, the one or more anchors being related to digital objects and / or activities that can be observed in the unstructured digital environment (704), wherein, the object and activity recognition module (404), after retrieving the usage policy, is configured to detect one or more digital objects and / or one or more activities in the unstructured digital environment (704) that are identical to the anchors in the usage policy, the policy evaluation module (410) is further configured to: compute a context match score of the protected digital object (714) based on the detected digital objects and / or activities that are identical to the anchors in the usage policy belonging to the whitelist category; compute a context mismatch score of the protected digital object (714) based on the detected digital objects and / or activities that are identical to the anchors in the usage policy belonging to the blacklist category; determine a violation of the usage policy of the protected digital object (714) in the given unstructured digital environment if the context match score or the context mismatch score does not comply with a predefined policy violation condition.
12. The usage policy evaluation apparatus (402, 702, 802) according to claim 11, characterized by the policy evaluation module (408) is configured to: determine a violation of the usage policy of the protected digital object (714) if one of the following conditions is met: if the context match score is less than a context match threshold or the context mismatch score is greater than a context mismatch threshold, wherein the context match threshold and the context mismatch threshold are predefined or included in the usage policy; if a quotient of the context match score divided by the context mismatch score is greater than a violation threshold, wherein the violation threshold is predefined or included in the usage policy; if a difference between the context match score and the context mismatch score is less than a violation threshold, wherein the violation threshold is predefined or included in the usage policy.
13. The usage policy evaluation apparatus (402, 702, 802) according to claim 11 or 12, characterized by the policy evaluation module (408) is configured to: retrieve a weight of each of the anchors from the usage policy; compute the context match score by summing up the weights of the anchors belonging to the whitelist category for which identical digital objects or activities are detected in the unstructured digital environment (704); The context mismatch score is computed by summing the weights of the anchor points belonging to the blacklisted category that are detected in the unstructured digital environment (704) for the same digital object or activity.
14. The usage policy evaluation apparatus (402, 702, 802) according to claim 13, characterized by The policy evaluation module (408) is further configured to: determine a tampering correction factor as a function of the extent of tampering performed on the protected digital object (714); compute the context match score by multiplying the sum of the corresponding weights by the tampering correction factor; compute the context mismatch score by multiplying the sum of the corresponding weights by the tampering correction factor.
15. The usage policy evaluation apparatus (402, 702, 802) according to any one of claims 11 to 14, characterized by, The policy evaluation module (408) is part of an endpoint security subsystem or a cloud service framework, the policy evaluation module being further configured to notify a user that a violation of the usage policy of the protected digital object (714) is determined by providing a visual and / or an audible cue to the user when the unstructured digital environment (704) is rendered on a user device.