Media data transmission method, apparatus and system

By embedding digital watermarks in media data transmission, using the target key to sign the signature value of the authentication message, the threat of man-in-the-middle attacks to media data transmission security in the prior art is solved, and the secure, real-time and smooth transmission of media data is achieved.

WO2025112578A1PCT designated stage expired Publication Date: 2025-06-05HUAWEI TECH CO LTD

Patent Information

Application Number
PCT/CN2024/107339
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-29
Filing Date
2024-07-24
Publication Date
2025-06-05

AI Technical Summary

Technical Problem

When preventing man-in-the-middle attacks, it is difficult to effectively ensure the security of media data transmission, especially under the end-to-end encryption mechanism, where data transmission still has security risks.

Method used

By using digital watermarking technology in media data transmission, the signature value obtained by signing the authentication message by the target key is embedded in the subsequently transmitted media data, thereby realizing end-to-end identity authentication of the previous transmission media data.

Benefits of technology

This solution prevents malicious forgery by coupling digital watermarks with media data, so as to achieve secure transmission of media data and will not affect the fluency and real-timeness of media data in real-time communication scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024107339_05062025_PF_FP_ABST
    Figure CN2024107339_05062025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of computers, and provides a media data transmission method, apparatus and system. A communication party serving as a transmitting end signs fingerprint information of previously transmitted media data, carries a signature value in a digital watermark, and embeds the digital watermark into subsequently transmitted media data. A communication party serving as a receiving end verifies the signature value in subsequently received media data on the basis of the fingerprint information of previously received media data, so as to determine the authenticity of the previously transmitted media data. Since a digital watermark is obtained on the basis of fingerprint information of media data and a signature value, it is difficult for an attacker to forge a digital watermark, thereby achieving secure media data transmission between two communication parties. In addition, by embedding a digital watermark generated on the basis of previously transmitted media data into subsequently transmitted media data, the smoothness and real-time performance of media data transmission can be achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Media data transmission method, device and system

[0001] This application claims priority to Chinese patent application number 202311626620.1, filed on November 29, 2023, entitled “Media Data Transmission Method, Device and System,” the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of computer technology, and in particular to a method, device, and system for media data transmission. Background Art

[0003] To achieve secure data transmission, end-to-end encryption (E2EE) is often used for communication. End-to-end encryption allows data to remain in ciphertext form throughout the transmission process from the sender to the receiver.

[0004] However, even with end-to-end encryption, data transmission can still present security risks, such as man-in-the-middle attacks. A man-in-the-middle (MitM) attack is an active wiretapping attack in which an attacker places themselves between two communicating parties, impersonating one or more entities involved in the data transmission process in order to intercept and tamper with the data being transmitted between them. Preventing man-in-the-middle attacks is crucial to communication security and is a key research topic.

[0005] Summary of the Invention

[0006] The present application provides a method, device and system for transmitting media data.

[0007] In a first aspect, a media data transmission method is provided. A first communication party obtains first fingerprint information of first media data. The first communication party generates a first digital watermark based on the first fingerprint information. The first digital watermark includes a first signature value obtained by the first communication party signing a first authentication message using a target key. The first authentication message includes the first fingerprint information. The first communication party sends the first media data and second media data to a second communication party, where the first digital watermark is embedded in the second media data. The second media data is sent after the first media data.

[0008] In this application, since the signature value in the digital watermark is calculated by the sender using the target key to calculate the authentication message including the fingerprint information of the media data, the fingerprint information can provide data identity proof for the media data, and the generated digital watermark can be coupled with the media data to prevent malicious forgery, and the signature value can be used to determine the authenticity of the media data, thereby realizing end-to-end identity authentication of the first media data. However, it is usually difficult for an attacker to steal the target key for generating the digital watermark and the algorithm for generating the digital watermark at the same time, so it is difficult for an attacker to counterfeit the digital watermark, and thus it is difficult to carry out undetected attacks. Therefore, the present application scheme can realize the secure transmission of media data between the communicating parties. In addition, the present application embeds the digital watermark generated based on the previously transmitted media data into the subsequently transmitted media data. In the real-time communication scenario, the fingerprint calculation time, signature time, and the time consumed by the sender in the process of generating the digital watermark, as well as the time consumed in embedding the digital watermark in the media data, will not affect the previously transmitted media data, thus achieving the smoothness and real-time transmission of media data. In addition, since the digital watermark is embedded in the media data transmitted later, the embedded digital watermark will not affect the fingerprint calculation of the media data transmitted earlier, thus solving the problem of irreversible rewriting of the current media data caused by embedding the digital watermark in the current media data.

[0009] Optionally, the target key is a private key held by the first communication party. In the case where the target key is the private key held by the first communication party, the second communication party can verify whether the first media data originates from the first communication party and the integrity of the first media data based on the first signature value. Since the private key is usually not released from the device, any third party without the private key cannot forge the signature. Therefore, if it is difficult for an attacker to obtain the private key held by the first communication party, it is difficult for the attacker to forge the first digital watermark generated by the first communication party and thus conduct an undetected attack.

[0010] Alternatively, the target key is a session key negotiated between the first communication party and the second communication party. In the case where the target key is a session key negotiated between the first communication party and the second communication party, the second communication party can verify whether the first media data originates from the first communication party and the integrity of the first media data based on the first signature value. Because it is difficult for any third party other than the first communication party and the second communication party to obtain the private session key negotiated between the first communication party and the second communication party, it is difficult for an attacker to forge the first digital watermark generated by the first communication party and thus conduct an undetected attack.

[0011] Alternatively, the target key is a shared key of the group to which the first and second communication parties belong, which is negotiated by multiple communication parties in the group. In this case, the second communication party can verify the first media data's origin and the integrity of the first media data based on the signature value. Because the group's shared key is difficult for any third party outside the group to obtain, it is difficult for an attacker to forge a digital watermark generated by a communication party in the group and thus conduct an undetected attack.

[0012] Optionally, the first media data is in a first media frame, the second media data is in a second media frame, and the second media frame is a media frame adjacent to the first media frame.

[0013] In this application, the sending end can embed the digital watermark generated based on the previous media frame into the next media frame, and the receiving end uses the information of the next frame to verify the previous frame, thereby realizing the continuity verification of the media data.

[0014] Optionally, the first authentication message further includes authentication attribute information, and the first digital watermark includes the authentication attribute information and a first signature value.

[0015] Optionally, the first communicating party generates a derived key using a key derivation function based on a shared key of a group to which the first communicating party and the second communicating party belong, an identity identifier of the first communicating party, and the identity identifier of the second communicating party. The shared key is negotiated by multiple communicating parties in the group. The first communicating party uses a hash value calculated using the derived key on multiple identity public keys as the authentication attribute information. The multiple identity public keys include the identity public key of the first communicating party and the identity public key of the second communicating party.

[0016] In this application, by incorporating authentication attribute information associated with the identities of both communicating parties into the generation of digital watermarks, different communicating parties can use different authentication attribute information, ensuring the uniqueness of the authentication attribute information and facilitating subsequent traceability and evidence collection based on digital watermarks.

[0017] Optionally, the first communication party obtains second fingerprint information of the second media data. The first communication party generates a second digital watermark based on the second fingerprint information. The second digital watermark includes a second signature value obtained by the first communication party signing a second authentication message using the target key. The second authentication message includes the second fingerprint information. After sending the second media data to the second communication party, the first communication party sends third media data to the second communication party. The third media data has the second digital watermark embedded in it.

[0018] Optionally, the first media data and the second media data are audio data, video data or file data.

[0019] In a second aspect, a media data transmission method is provided. The method includes: a second communication party receiving first media data and second media data sent by a first communication party. The second media data is received after the first media data. A first digital watermark is embedded in the second media data, and the first digital watermark includes a first signature value. The second communication party obtains a first authentication message, and the first authentication message includes first fingerprint information of the first media data. The second communication party verifies the first signature value using a target key and the first authentication message to determine the authenticity of the first media data.

[0020] Optionally, the target key is a public key held by the first communication party. Alternatively, the target key is a session key negotiated between the first communication party and the second communication party. Alternatively, the target key is a shared key of a group to which the first communication party and the second communication party belong, the shared key being negotiated by multiple communication parties in the group.

[0021] Optionally, the first digital watermark further includes authentication attribute information, and the first authentication message further includes authentication attribute information.

[0022] Optionally, the second communication party receives third media data sent by the first communication party, wherein the third media data is received after the second media data, and a second digital watermark is embedded in the third media data, and the second digital watermark includes a second signature value. The second communication party obtains a second authentication message, and the second authentication message includes second fingerprint information of the second media data. The second communication party verifies the second signature value using the target key and the second authentication message to determine the authenticity of the second media data.

[0023] Optionally, the first media data and the second media data are audio data, video data or file data.

[0024] In a third aspect, a media data transmission device is provided. The device can be used by a first communication party, such as a communication device of the first communication party. The device includes multiple functional modules that interact with each other to implement the method of the first aspect and its respective embodiments. The multiple functional modules can be implemented based on software, hardware, or a combination of software and hardware, and the multiple functional modules can be arbitrarily combined or divided based on the specific implementation.

[0025] In a fourth aspect, a media data transmission device is provided. This device can be used by a second communication party, such as a communication device of the second communication party. The device includes multiple functional modules that interact with each other to implement the method of the second aspect and its respective embodiments. The multiple functional modules can be implemented based on software, hardware, or a combination of software and hardware, and the multiple functional modules can be arbitrarily combined or divided based on the specific implementation.

[0026] In a fifth aspect, a media data transmission system is provided, including: a first communication party and a second communication party, wherein the first communication party is configured to execute the method of the first aspect and its respective embodiments, and the second communication party is configured to execute the method of the second aspect and its respective embodiments.

[0027] Optionally, the first communication party and the second communication party are both participants in the conference.

[0028] In the sixth aspect, a communication device is provided, comprising: a processor and a memory; the memory is used to store a computer program, the computer program including program instructions; the processor is used to call the computer program to implement the method of the above-mentioned first aspect and its various embodiments, or to implement the method of the above-mentioned second aspect and its various embodiments.

[0029] In the seventh aspect, a computer-readable storage medium is provided, on which instructions are stored. When the instructions are executed by a processor, the method of the above-mentioned first aspect and its various embodiments is implemented, or the method of the above-mentioned second aspect and its various embodiments is implemented.

[0030] In an eighth aspect, a computer program product is provided, comprising a computer program, which, when executed by a processor, implements the method of the above-mentioned first aspect and its various embodiments, or implements the method of the above-mentioned second aspect and its various embodiments.

[0031] In the ninth aspect, a chip is provided, which includes a programmable logic circuit and / or program instructions. When the chip is running, it implements the method in the above-mentioned first aspect and its various embodiments, or implements the method in the above-mentioned second aspect and its various embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] FIG1 is a schematic diagram of a man-in-the-middle attack provided in an embodiment of the present application;

[0033] FIG2 is a schematic diagram of an audio watermark frame embedding method provided by the related art;

[0034] FIG3 is a flowchart of an implementation of an audio watermark algorithm provided by the related art;

[0035] FIG4 is a flowchart of an implementation of an audio fingerprint algorithm provided by the related art;

[0036] FIG5 is a flowchart of an implementation of embedding a signature watermark in a media stream provided by the related art;

[0037] FIG6 is a schematic diagram of an application scenario provided by an embodiment of the present application;

[0038] FIG7 is a schematic diagram of a channel key negotiation process provided in an embodiment of the present application;

[0039] FIG8 is a schematic diagram of another channel key negotiation process provided in an embodiment of the present application;

[0040] FIG9 is a flow chart of a method for transmitting media data provided in an embodiment of the present application;

[0041] FIG10 is a schematic diagram of a signature authentication process provided in an embodiment of the present application;

[0042] FIG11 is a schematic structural diagram of a media data transmission device provided in an embodiment of the present application;

[0043] FIG12 is a schematic structural diagram of another media data transmission device provided in an embodiment of the present application;

[0044] FIG13 is a schematic diagram of the hardware structure of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0045] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.

[0046] Man-in-the-middle attacks are a common type of active attack in data transmission. Attackers can perform actions such as reading, tampering, inserting, deleting, and reordering transmitted data. For example, Figure 1 is a schematic diagram of a man-in-the-middle attack provided in an embodiment of the present application. As shown in Figure 1, an attacker can launch an active attack on real-time data streams transmitted between different end users over digital channels.

[0047] Therefore, it is particularly important to use data protection technology to protect the transmitted data to prevent man-in-the-middle attacks for communication security. Currently, commonly used data protection technologies include digital watermark technology, data fingerprint technology and digital signature technology.

[0048] Digital watermarking technology embeds specific information, such as copyright information or provider user information, into digital media to protect copyright, verify product authenticity, track piracy, or provide additional product information. Digital watermarks can be embedded in a variety of digital media, including images, audio, video, and text. The watermark information is embedded within the carrier file without affecting the visibility or integrity of the original file. Digital watermarks can be categorized as visible or invisible based on their perceptibility. Visible watermarks embed visible information, such as text or images, directly into digital media. Visible watermarks can be used to identify the owner or copyright of digital media. Invisible watermarks embed invisible information, such as digital codes or noise. Invisible watermarks can be used to verify the integrity and authenticity of digital media and to trace its origin. Digital watermarking technology has a wide range of applications, including copyright protection, anti-counterfeiting, digital forensics, and information hiding. Digital watermarking has become a key tool for digital media security.

[0049] Digital fingerprinting is a technology used to identify digital content, similar to the concept of a human fingerprint. By calculating and analyzing digital content, a digital fingerprint generates a unique identifier (equivalent to providing an identity for the digital content), which is used to identify and verify the authenticity and integrity of the digital content. Digital fingerprinting is widely used in copyright protection, content identification, network security, and other fields. Digital fingerprinting is implemented through hashing algorithms, feature extraction, and comparison techniques.

[0050] Digital signature technology is used to verify the authenticity and integrity of data. Digital signatures are categorized as asymmetric and symmetric. With an asymmetric signature, the sender signs a message using their private key. After receiving the data and the sender's signature, the receiver verifies the signature using the sender's public key. With a symmetric signature, the sender signs a message using a symmetric key. After receiving the data and the sender's signature, the receiver verifies the signature using the symmetric key. If the signature verifies successfully, the data has not been tampered with. If the signature fails, the data has been tampered with. Signature verification can be used to verify both data integrity (no tampering) and authenticity (not fraudulent or forged data). Digital signature technology can be used to protect various electronic documents and data, including digital media, electronic contracts, and emails.

[0051] Related technologies have proposed embedding digital watermarks in media data to identify and track media data. Media data includes but is not limited to audio data, video data, file data, and other digital streaming media data, such as remote shared desktops, remote shared documents, and remote shared applications. Taking audio data as an example, watermark information can be embedded into audio data in real time through audio watermarking technology, and this process can occur at any stage of transmission. Audio watermarking technology is a digital copyright protection technology that protects the copyright of audio content by embedding certain specific information in audio signals. This information can be in the form of digital codes, digital signatures, digital watermarks, etc., which are embedded in different time domain, frequency domain, phase, amplitude and other parameters of the audio signal to ensure that the quality and audibility of the audio signal are not affected.

[0052] Audio data is divided into file information and real-time information. Both file and real-time information use a framed structure, dividing the entire audio data into several audio data frames Fi. An audio data frame is the smallest unit of audio fragment, and both transmission and encoding and decoding are based on the data length of the audio data frame. Therefore, current audio watermark embedding schemes use a frequency masking method to embed watermark information between the frequency signal components of each audio data frame using a watermark embedding algorithm W(Fi), resulting in an audio data frame Di containing the watermark information. Here, i is an integer greater than 1. For example, Figure 2 shows a schematic diagram of audio watermark frame embedding provided by related art. To eliminate interference and meet real-time transmission scenarios, synchronization frames are required to determine the location of the audio watermark fragment within the audio data frame so that it can be accurately restored at the extraction end. Furthermore, due to the covert communication characteristics of watermark information, the watermark information can be used as an out-of-band communication channel to carry authentication information. Compared to traditional cryptographic authentication methods, data transmitted through real-time communication is more covert and more difficult to detect and decrypt.

[0053] For example, Figure 3 is a flowchart of an implementation of an audio watermark algorithm provided by related art. As shown in Figure 3, the implementation process of embedding watermark information in an audio data frame includes the following steps A1 to A5.

[0054] In step A1, the original watermark information is modulated, error-corrected, and spread to transform it into the original watermark sequence m, where m = {m(i); i = 0, ..., L-1; m(i)∈{0, 1}}. Where L is the length of the original watermark sequence, usually the number of bits.

[0055] In step A2, a synchronization sequence n is added to the original watermark sequence m to obtain a watermark unit sequence m+n, where n={n(i); i=0,…,L-1; n(i)∈{0,1}}.

[0056] In step A3, a fast Fourier transform (FFT) is performed on the original audio data frame using the data length of the audio data frame as a unit to convert the original audio data frame into frequency domain data.

[0057] In step A4, the amplitude data in the fixed frequency domain information segment of the frequency domain data is dynamically modified, wherein the amplitude data that takes 0 in the watermark unit sequence is subjected to an amplitude reduction operation, and the amplitude data that takes 1 in the watermark unit sequence is subjected to an amplitude increase operation, so as to complete the watermark embedding and obtain the amplitude data containing the watermark information.

[0058] In step A5, the frequency domain data containing the watermark information is subjected to an inverse fast Fourier transform (IFFT) to restore the audio data frame containing the watermark information.

[0059] At this point, the audio watermark is embedded into the audio data. Each audio segment is coupled with the watermark information and is widely used in scenarios such as tracing the source and copyright declaration as the audio spreads.

[0060] However, due to the inherently low security of digital watermarking algorithms, anyone who illegally obtains them can easily forge watermark information. Furthermore, due to the decoupling of watermark information from media data content and its lack of security binding to identity authentication, attackers who intercept media data embedded with watermark information can easily remove or tamper with the original watermark information. Therefore, it is difficult to rely on watermark information to verify the authenticity and integrity of media data content, making it prone to counterfeiting, denial, and framing.

[0061] To address the issue of decoupling watermark information from media data content, embedding digital fingerprints as watermarks in media data can effectively address this issue, as digital fingerprints can provide identity for the data. Taking audio fingerprinting technology as an example, its implementation typically involves two phases: feature extraction and fingerprint matching. During the feature extraction phase, the audio signal is converted into a set of digital features that reflect information such as the time domain, frequency domain, phase, and amplitude of the audio signal. During the fingerprint matching phase, the converted digital features are compared with fingerprints in a database to determine the identity of the audio signal.

[0062] For example, Figure 4 is a flowchart of an audio fingerprint algorithm implementation provided by related art. As shown in Figure 4, the audio fingerprint calculation and verification process includes the following steps B1 to B5. Among them, steps B1 to B4 are the audio fingerprint calculation process (corresponding to the feature extraction stage mentioned above), and step B5 is the audio fingerprint verification process (corresponding to the fingerprint matching stage mentioned above).

[0063] In step B1, the original audio data is preprocessed to obtain multiple audio segments.

[0064] Preprocessing usually includes adding Hamming windows and framing.

[0065] In step B2, frequency domain conversion is performed on each of the multiple audio segments using an FFT function to obtain multiple frequency domain segments.

[0066] In step B3, features of multiple frequency domain segments are extracted using methods such as singular value decomposition (SVD) and feature matrix selection to obtain overall audio features.

[0067] In step B4, a hash operation is performed on the audio feature to obtain a hash feature value, and the hash feature value is used as the audio fingerprint.

[0068] In step B5, after the extraction end obtains the original audio data and the audio fingerprint, it calculates the audio fingerprint of the obtained original audio data, and uses a matching function to calculate the bit error ratio (BER) of the obtained audio fingerprint and the calculated audio fingerprint (i.e., hash matching), so as to determine whether the two come from the same data source.

[0069] Based on the implementation process of the above-mentioned audio fingerprint algorithm, it can be seen that multiple steps such as spectrum analysis, feature extraction, and hash operations are required to calculate the audio fingerprint of the audio signal. The computational complexity is large, so calculating the audio fingerprint is usually time-consuming. Although the audio fingerprint provides the identity information of the audio data, using the audio fingerprint as a watermark can solve the problem of decoupling the existing watermark information from the data content. However, for audio streams that need to be transmitted in real time, the time required to calculate the audio fingerprint is not enough to embed the audio fingerprint of the audio data frame in the current audio data frame as watermark information for transmission. In addition, after embedding the audio fingerprint as watermark information in the current audio data frame, the data content of the current audio data frame will be changed, which in turn will affect the calculation result of the audio fingerprint of the current audio data frame. Therefore, embedding the audio fingerprint in the current audio data frame can easily lead to misjudgment during the fingerprint matching stage.

[0070] To address the issue of watermark information not being securely tied to identity authentication, related technologies have proposed embedding digital signatures as watermark information in media data. However, since the watermark embedding algorithm is time-consuming, and the signature algorithm is also time-consuming, especially the asymmetric signature algorithm, which is more time-consuming than the symmetric signature algorithm under the premise of equal security, when the watermark embedding algorithm and the signature algorithm coexist, the combined time consumption of the two makes it difficult to ensure the real-time transmission of the media stream. Due to the low-latency performance constraints of real-time communication, the current solution can only sign some data frames (such as key frames) to minimize the impact of the delay caused by watermark embedding and signature on the real-time transmission of the media stream.

[0071] For example, Figure 5 is a flowchart of a method for embedding a signature watermark in a media stream, as provided by related art. As shown in Figure 5, when end user 1 transmits a media stream to end user 2 in real time, it uses signature authentication to prevent third-party unauthorized users from modifying the data content. Specifically, a signature algorithm (symmetric or asymmetric) is used to generate a signature value, which is then added to the real-time media stream in the form of a watermark. For example, the media stream transmitted in real time from end user 1 to end user 2 includes, in sequence, media frame 1, media frame 2, media frame 3, media frame 4, and media frame 5, where media frame 2 and media frame 4 are key frames. End user 1 embeds a signature watermark H2 for media frame 2 in media frame 2 and a signature watermark H4 for media frame 4 in media frame 4. Thus, after receiving the media stream from end user 1, end user 2 can verify the signatures carried by the media frames to verify the authenticity and integrity of the media stream. Embedding a signature watermark in a media frame refers to embedding the signature into the media frame using a digital watermark algorithm.

[0072] However, the disadvantages of embedding signature watermarks in media frames are also obvious, that is, it can only verify key frames and cannot guarantee the correctness of all media frames. Too many key frames will affect the real-time transmission of the media stream. For example, for audio streams, too many key frames may easily cause audio and video to be out of sync or sound quality to be stuck; while too few key frames will reduce the reliability of media stream verification.

[0073] Based on the defects existing in the related art, the present application provides a technical solution, which combines the application of digital watermark technology, digital fingerprint technology and digital signature technology. The communication party as the sender signs the fingerprint information of the media data sent previously, and carries the signature value in the digital watermark and embeds it into the media data sent later. The communication party as the receiver can verify the signature value in the media data received later based on the fingerprint information of the media data received previously, so as to judge the integrity and authenticity of the media data transmitted previously, thereby realizing end-to-end identity authentication. By embedding the digital watermark associated with the media data transmitted previously into the media data transmitted later, it solves the problem in the related art that the calculation time of the audio fingerprint affects the real-time transmission of the media data, and that embedding the audio fingerprint into the current media data will change the data content and cause misjudgment in the fingerprint matching stage, and solves the problem in the related art that the signature time affects the real-time transmission of the media data.

[0074] The technical solution provided by the present application is specifically as follows: the first communication party obtains the first fingerprint information of the first media data. The first communication party generates a first digital watermark based on the first fingerprint information, and the first digital watermark includes a first signature value obtained by the first communication party signing the first authentication message using the target key. The first authentication message includes the first fingerprint information. The first communication direction sends the first media data and the second media data to the second communication party, and the first digital watermark is embedded in the second media data. The second media data is sent after the first media data. Accordingly, after the second communication party receives the first media data and the second media data sent successively by the first communication party, it can determine the authenticity of the first media data by verifying the first signature value in the first digital watermark embedded in the second media data. Since the signature value in the digital watermark is calculated by the sender using the target key to calculate the authentication message including the fingerprint information of the media data, the fingerprint information can provide data identity proof for the media data, and the generated digital watermark can be coupled with the media data to prevent malicious forgery, and the signature value can be used to judge the authenticity of the media data, and realize end-to-end identity authentication of the first media data. It is usually difficult for an attacker to steal the target key for generating the digital watermark and the algorithm for generating the digital watermark at the same time. Therefore, it is difficult for an attacker to counterfeit the digital watermark, and thus it is difficult to carry out undetected attacks. Therefore, the present application scheme can realize the secure transmission of media data between the communicating parties. In addition, the present application embeds the digital watermark generated based on the previously transmitted media data into the subsequently transmitted media data. In the real-time communication scenario, the fingerprint calculation time, signature time, and the time consumed by the sender in the process of generating the digital watermark will not affect the previously transmitted media data, and the smoothness and real-time transmission of media data can be realized. In addition, since the digital watermark is embedded in the media data transmitted later, the embedded digital watermark will not affect the fingerprint calculation of the media data transmitted earlier, thus solving the problem of irreversible rewriting of the current media data caused by embedding the digital watermark in the current media data.

[0075] The following is a detailed introduction to the technical solution of this application from multiple perspectives, including application scenarios, method flow, software devices, hardware devices, and systems.

[0076] The following is an example of an application scenario of the embodiment of the present application.

[0077] The embodiments of the present application can be applied to various communication scenarios for transmitting media data, such as point-to-point communication and group communication. Point-to-point communication refers to instant communication between two communicating parties, such as voice communication services or video communication services in instant messaging applications. Group communication refers to instant communication between two or more communicating parties. Two common scenarios for group communication are non-real-time asynchronous interaction scenarios and real-time synchronous interaction scenarios. Among them, non-real-time asynchronous interaction scenarios are mainly based on information interaction among multiple parties, such as group message communication services in instant messaging applications. Real-time synchronous interaction scenarios are mainly based on real-time audio and video conferences among multiple parties, such as small group meetings initiated temporarily, scheduled large-scale organizational meetings, etc.

[0078] Optionally, the media data includes but is not limited to audio data, video data, file data and other digital streaming media data, such as remote shared desktop, remote shared documents and remote shared applications.

[0079] In group communication scenarios, encrypting communication data is a common method to ensure the security of messages between multiple communicating parties. For example, all communication nodes in a group use an agreed-upon key to encrypt sent messages and decrypt received messages, thereby achieving encrypted communication. Generally speaking, the key used to encrypt communication messages within a group is called a shared key. The multiple communication nodes in a group can be divided into management nodes and member nodes based on their roles. The management node is responsible for generating the shared key and distributing it to all member nodes. To ensure the secure distribution of the shared key, the management node can negotiate a channel key with each member node, encrypt the shared key using the negotiated channel key, and then send the encrypted shared key to the corresponding member node. Upon receiving the encrypted shared key, the member node decrypts it using the channel key negotiated with the management node, thereby achieving secure distribution of the shared key within the group. Subsequently, the multiple communication nodes in the group use the shared key to encrypt communication messages, achieving secure E2EE communication.

[0080] Taking a video conference scenario as an example, a video conference typically includes multiple participants, each of whom joins the video conference through a conference terminal. A conference terminal can be a dedicated physical device or a software program with conferencing capabilities. This software program can run on various computing devices, such as mobile phones, tablets, computers, and other user terminals. In this case, the computing device running the software program can also be considered a conference terminal. A conference terminal joins a video conference through a conference service platform. Specifically, the conference terminal can obtain media data for the video conference from the conference service platform and send the locally collected media data to the conference service platform, which then forwards it to other participating conference terminals. Conference terminals can connect to each other via a wireless network, allowing participants to join the video conference smoothly regardless of their geographic location. In some cases, a conference party may consist of only one participating user, such as when the participating user joins the video conference through a conferencing software program running on a personal mobile phone. In other cases, a conference party can also include multiple participating users, such as in a conference room scenario, where multiple participating users in the conference room join the video conference through a single conference terminal in the conference room.

[0081] In a video conferencing scenario, multiple participants establish digital channels with the conference service platform through their respective conference terminals. These channels consist of signaling and media channels. The signaling channel typically carries call signaling and conference control signaling. The media channel typically carries real-time audio and video encoding streams and is often referred to as the in-band communication channel for video conferencing. Correspondingly, digital watermarks can serve as logical out-of-band communication channels for carrying media authentication information. In a video conferencing scenario, the key material required for E2EE typically includes the public keys of all participants, which can be transmitted via the digital channel established with the conference service platform.

[0082] A public key and a private key are a key pair derived through an algorithm. If one key in a key pair is used to encrypt a piece of data, the other key must be used to decrypt it. For example, if data is encrypted with the public key, it must be decrypted with the private key, and vice versa. Otherwise, decryption will fail. The public key is the portion of the key pair that is publicly available to the communicating party, while the private key is the private portion. Under normal circumstances, the private key held by a participant is not accessible to any third party, including other participants and the conference service platform.

[0083] In the embodiments of the present application, the public key and private key held by the participating parties (communication parties) may refer to the device public key and device private key possessed by the conference terminal (for example, the dedicated conference terminal equipped in the conference room can be used by one or more users, and the dedicated conference terminal itself has the device public key and device private key); or it may refer to the user public key and user private key of the participating user who logs in to the conference terminal (for example, the conference terminal is a computer device that runs a conference application, and the user public key and user private key of the user currently logged in to the conference application are the public key and private key held by the participating party. If the logged-in user is changed, the public key and private key held by the participating party will also change accordingly).

[0084] If the public key and private key held by the participant are the device public key and device private key possessed by the conference terminal, then when the conference terminal wants to use the public key and private key held by the participant, it can directly read the device public key and device private key from the local storage. If the public key and private key held by the participant are the user public key and user private key of the participant who logged in to the conference terminal, then the conference terminal can obtain and store the user public key based on the information of the logged-in user when the user logs in, and use the user private key to sign the user public key. The signature is used to prove that the logged-in user holds the private key corresponding to the user public key. In some cases, there may be no logged-in user on the conference terminal (for example, the conference terminal in the conference room is public and does not require user login), but during the conference, it may be bound to a certain participant or user terminal (temporarily bound). In this case, the user public key and user private key of the participant bound to the conference terminal or the device public key and device private key of the user terminal can also be used as the public key and private key held by the participant. If the public key and private key held by the participant are the user's user public key and user private key, or the device public key and device private key of the user terminal (such as the user's mobile phone, tablet computer, etc.), and the conference terminal and the user terminal are two different physical devices, then the conference terminal can obtain the user public key or the device public key of the user terminal through Bluetooth, near field communication (NFC), user input, etc.

[0085] Optionally, the public-private key pairs held by the participants may include long-term public-private key pairs and / or temporary public-private key pairs. A long-term public-private key pair can be an unchanging public key generated by the conference terminal's login user during registration, or a public key generated when the conference terminal itself registers with the conference system. A temporary public-private key pair is a public-private key pair that is valid for a period of time and updated, such as one that is updated at regular intervals or generated each time a conference is joined. Multiple participants in a conference can pre-send their public keys to the conference service platform for storage.

[0086] For example, Figure 6 is a schematic diagram of an application scenario provided by an embodiment of the present application. The application scenario is a video conferencing scenario, for example, it can be a video conferencing system. As shown in Figure 6, the application scenario includes a conference service platform and four conference terminals (conference terminal A, conference terminal B, conference terminal C, and conference terminal D), and four participating users (user A, user B, user C, and user D) access the conference through conference terminal A, conference terminal B, conference terminal C, and conference terminal D respectively. Among them, user A and conference terminal A are collectively referred to as participant A, user B and conference terminal B are collectively referred to as participant B, user C and conference terminal C are collectively referred to as participant C, and user D and conference terminal D are collectively referred to as participant D.

[0087] Optionally, the conference service platform is a multipoint control unit (MCU). The MCU can provide authentication services to participants (through the conference terminals used by participating users) and forward conference data. For example, conference terminal A sends user A's video data to the MCU, which then forwards the video data to conference terminals B, C, and D, allowing users B, C, and D to view user A's video image through conference terminals B, C, and D, respectively.

[0088] In a video conferencing scenario, multiple participants can negotiate a master key, which serves as the shared key for the conference. This master key is typically used to encrypt and decrypt media data and control signaling transmitted during the conference, achieving end-to-end encryption.

[0089] The conference master key can be obtained through negotiation among multiple conference participants (typically all conference participants). This negotiation process can be based on the E2EE key agreement protocol or the group key agreement protocol. Two common key agreement processes based on the E2EE key agreement protocol are shown in Figures 7 and 8, respectively.

[0090] In the channel key agreement process shown in Figure 7, conference terminals form a communication pair. If a conference includes four conference terminals, there are a total of six communication pairs in the conference, each of which has a communication key. As shown in Figure 7 (a), the communication key between conference terminals A and B is Kab, the communication key between conference terminals A and C is Kac, the communication key between conference terminals A and D is Kad, the communication key between conference terminals B and C is Kbc, the communication key between conference terminals B and D is Kbd, and the communication key between conference terminals C and D is Kcd. After conference terminal A, acting as the conference manager, generates a master key M, as shown in Figure 7 (b), conference terminal A encrypts master key M using Kab and sends it to user B; encrypts master key M using Kac and sends it to conference terminal C; and encrypts master key M using Kad and sends it to conference terminal D.

[0091] Figure 8 illustrates the key negotiation process based on the Signal protocol in the E2EE key negotiation protocol. In the channel key negotiation example shown in (a) of Figure 8, each conference terminal has a sender key that is different from that of other conference terminals. When sending a message, it uses its own sender key to encrypt the message and then sends it to other users. Taking conference terminal A as an example, conference terminal A can randomly generate its own sender key Ka. It then encrypts the sender key Ka using the paired key EKab with conference terminal B and sends the encrypted sender key EKab(Ka) to conference terminal B. It then encrypts the sender key Ka using the paired key EKac with conference terminal C and sends the encrypted sender key EKac(Ka) to conference terminal C. It then encrypts the sender key Ka using the paired key with conference terminal D and sends the encrypted sender key EKad(Ka) to conference terminal D. After conference terminal A, which serves as the conference manager, generates a master key M, as shown in (b) of FIG8 , conference terminal A encrypts the master key M using Ka and sends it to conference terminals B, C, and D.

[0092] The above Figures 7 and 8 are only examples of channel key negotiation. The embodiments of the present application do not limit the process of negotiating the master key. Other methods can also be used to negotiate the master key. For example, the master key can be negotiated based on the Message Layer Security (MLS) protocol defined in the request for comments (RFC) document numbered 9420 (abbreviated as: IETF RFC9420) developed by the Internet Engineering Task Force (IETF).

[0093] The following is an example of the method flow of the embodiment of the present application.

[0094] For example, Figure 9 is a flow chart of a method for media data transmission provided in an embodiment of the present application. As shown in Figure 9, method 900 includes but is not limited to the following steps 901 to 905. This method 900 can be applied to group communications, for example, it can be applied to the video conferencing scenario shown in Figure 6. In this case, communication party 1 (sender) and communication party 2 (receiver) in method 900 can be any two participants in Figure 6.

[0095] Step 901: Communicating party 1 obtains fingerprint information 1 of media data 1.

[0096] Optionally, communicating party 1 applies a hash algorithm to media data 1 to generate a unique hash value as fingerprint information 1. The media stream between communicating parties is typically transmitted in the form of media frames, which may be, for example, audio frames or video frames. Media data 1 may include the data content of a single media frame, or the data content of multiple adjacent media frames.

[0097] Step 902 : Communication party 1 generates digital watermark 1 based on fingerprint information 1 . Digital watermark 1 includes signature value 1 obtained by communication party 1 signing authentication message 1 using key 1 . Authentication message 1 includes fingerprint information 1 .

[0098] Optionally, authentication message 1 also includes authentication attribute information. Accordingly, digital watermark 1 includes the authentication attribute information and signature value 1. Let media data 1 be D1, fingerprint information 1 of media data 1 be f(D1), key 1 be k1, and authentication attribute information be m. Then, authentication message 1 can be expressed as f(D1)||m, signature value 1 can be expressed as H(k1, f(D1)||m), and digital watermark 1 can be expressed as W1:m||H(k1, f(D1)||m). The symbol || represents string concatenation.

[0099] Authentication attribute information can be any information involved in generating a digital watermark. For example, authentication attribute information can be associated with the identities of both communicating parties, ensuring that different communicating parties use different authentication attribute information, ensuring uniqueness and facilitating subsequent traceability and evidence collection. For another example, in a video conferencing scenario, authentication attribute information can include conference information, such as a conference ID or conference timestamp. Optionally, communicating parties 1 and 2 are any two communicating parties in a group. One implementation method for communicating party 1 to obtain authentication attribute information is as follows: communicating party 1 uses a key derivation function (KDF) to generate a derived key based on a shared key of the group to which communicating parties 1 and 2 belong, the identity of communicating party 1, and the identity of communicating party 2. The shared key is negotiated by multiple communicating parties in the group. Communicating party 1 uses the derived key to calculate a hash value of multiple identity public keys as the authentication attribute information. The multiple identity public keys include the identity public key of communicating party 1 and the identity public key of communicating party 2. The multiple identity public keys may also include the identity public keys of other communicating parties in the group.

[0100] For example, referring to the application scenario shown in Figure 6, communication party 1 is participant A, and communication party 2 is participant B. Participant A can make the derived key OTP_OOB = KDF (mk, IDA||IDB||"OOB"), where mk represents the master key, IDA represents the identifier of participant A (the identifier of user A or the identifier of conference terminal A), IDB represents the identifier of participant B (the identifier of user B or the identifier of conference terminal B), and OOB represents out-of-band parameters. The out-of-band parameters can be pre-generated by the conference service platform (such as MCU), and the out-of-band parameters of different conferences can be the same or different. Furthermore, the derived key can also be generated based on the identifiers of other participants in the conference, or it can be generated based on the identifiers of all participants in the conference. In addition, participant A can also generate a public key string based on the public key of participant A and the public key of participant B. For example, the public key string allGroupPK can be set as pkA||pkB, where pkA represents the public key of participant A and pkB represents the public key of participant B. For another example, when the public key information includes a long-term public key and a temporary public key, the public key string allGroupPK can be set as epkA||epkB||LongPKA||LongPKB, where epkA represents the temporary public key of participant A, epkB represents the temporary public key of participant B, LongPKA represents the long-term public key of participant A, and LongPKB represents the long-term public key of participant B. Furthermore, the public key string can be generated using the public keys of other participants in the conference, or it can be generated based on the public keys of all participants in the conference. The participant then performs a hash operation on the public key string allGroupPK using the derived key OTP_OOB to obtain the authentication attribute information m: Hash(OTP_OOB, allGroupPK). This hash operation can use a keyed hash function. A keyed hash function is a hash function that takes a key as an additional input. It can accept two inputs, a message and a key, and output a hash value of fixed length.

[0101] Optionally, signature value 1 may be an asymmetric signature value calculated by communication party 1 using an asymmetric signature algorithm, such as an elliptic curve digital signature algorithm (ECDSA). Alternatively, signature value 1 may be a symmetric signature value calculated by communication party 1 using a symmetric signature algorithm, such as an Advanced Encryption Standard (AES) cypher-based message authentication code (CMAC) (abbreviated as AES-CMAC) algorithm.

[0102] Optionally, communication party 1 may sign authentication message 1 using its own private key, a session key negotiated between communication party 1 and communication party 2, or a shared key of the group to which communication party 1 and communication party 2 belong. Signing authentication message 1 using a private key by communication party 1 is an asymmetric signature, while signing authentication message 1 using a session key or a shared key of the group is a symmetric signature. The following describes three possible implementations of key 1.

[0103] In a first possible implementation, key 1 is a private key held by communication party 1. Communication party 1 then uses key 1 to sign authentication message 1 to obtain signature value 1. Communication party 1 may first run a hash algorithm on authentication message 1 to obtain a fixed-length data hash value, and then use the private key to encrypt the fixed-length hash value to obtain signature value 1. Signature value 1 may be, for example, an ECDSA signature.

[0104] In the first possible implementation, communication party 2 can verify whether media data 1 comes from communication party 1 and the integrity of media data 1 based on signature value 1. Since the private key is usually not released from the device, any third party without the private key cannot forge the signature. Therefore, if it is difficult for an attacker to obtain the private key held by communication party 1, it is difficult to forge the digital watermark 1 generated by communication party 1 and conduct an undetected attack.

[0105] In a second possible implementation, key 1 is a session key negotiated between communication party 1 and communication party 2. The signature value 1 obtained by communication party 1 using key 1 to sign authentication message 1 may be a message authentication code. For example, communication party 1 may generate signature value 1 based on authentication message 1 and the session key using a hash-based message authentication code (HMAC) algorithm.

[0106] Optionally, one implementation method for communication party 1 and communication party 2 to negotiate a session key is that a communication party receives a key negotiation message sent by the other party, and the key negotiation message includes multiple negotiation public keys held by the other party, including the other party's long-term identity public key. The communication party verifies the authenticity of the multiple negotiation public keys. If the communication party determines that the multiple negotiation public keys are all authentic public keys from the other party, the communication party uses the multiple negotiation public keys and multiple negotiation private keys held by the communication party, including its own long-term identity private key, to generate a session key. Among them, the key obtained through negotiation based on the other party's long-term identity public key and the communication party's long-term identity private key participates in the generation of the session key. As long as the long-term identity private keys of the communication parties are not leaked, an attacker cannot crack the session key generated by the communication party, so the security and confidentiality of the generated session key are relatively high.

[0107] Optionally, another implementation method for communication party 1 and communication party 2 to negotiate a session key is that a communication party receives a key negotiation message sent by the other party, and the key negotiation message includes multiple negotiation public keys held by the other party, and the authentication sources of the multiple negotiation public keys include at least two trusted institutions. The communication party verifies the authenticity of the multiple negotiation public keys. If the communication party determines that the multiple negotiation public keys are all authentic public keys from the other party, the communication party uses the multiple negotiation public keys and the multiple negotiation private keys held by the communication party to generate a session key, and the authentication sources of the negotiation public keys corresponding to the multiple negotiation private keys include at least two trusted institutions. Since different trusted institutions provide different identity factors for the communication party, the communication party performs multiple identity authentications based on multiple identity factors, and the ultimately generated session key also incorporates multiple identity factors of the communication parties. Therefore, the generated session key has higher security and confidentiality.

[0108] In the second possible implementation, communication party 2 can verify whether media data 1 comes from communication party 1 and the integrity of media data 1 based on signature value 1. Since it is difficult for any third party other than communication party 1 and communication party 2 to obtain the session private key negotiated between communication party 1 and communication party 2, it is difficult for an attacker to forge the digital watermark 1 generated by communication party 1 and conduct an undetected attack.

[0109] In a third possible implementation, key 1 is a shared key for the group to which communicating parties 1 and 2 belong. This shared key is negotiated by multiple communicating parties in the group. Signature value 1, obtained by communicating party 1 using key 1 to sign authentication message 1, can be a message authentication code. For example, party 1 can generate signature value 1 based on authentication message 1 and the shared key using the HMAC algorithm. This shared key can be, for example, the conference master key.

[0110] In the third possible implementation, communication party 2 can verify whether media data 1 comes from other communication parties in the group and the integrity of media data 1 based on signature value 1. Since it is difficult for any third party outside the group to obtain the group's shared key, it is difficult for an attacker to forge the digital watermark generated by a communication party in the group and conduct an undetected attack.

[0111] Step 903: Communicating party 1 sends media data 1 and media data 2 to communicating party 2, where digital watermark 1 is embedded in media data 2, and media data 2 is sent after media data 1.

[0112] In an embodiment of the present application, the transmitting end embeds a digital watermark generated based on previously transmitted media data into the subsequently transmitted media data. In real-time communication scenarios, the time consumed by the transmitting end during the digital watermark generation process, the time consumed for fingerprint calculation, signature generation, and embedding the digital watermark in the media data does not affect the previously transmitted media data, thereby achieving smooth and real-time media data transmission. Furthermore, because the digital watermark is embedded in the subsequently transmitted media data, the embedded digital watermark does not affect the fingerprint calculation of the previously transmitted media data, thus resolving the problem of irreversible rewriting of the current media data caused by embedding the digital watermark into the current media data.

[0113] Optionally, media data 1 may include the data content of a media frame, or media data 1 may also include the data content of multiple adjacent media frames. Similarly, media data 2 may include the data content of a media frame, or media data 2 may also include the data content of multiple adjacent media frames. In one possible implementation, media data 1 is in media frame 1, media data 2 is in media frame 2, and media frame 2 is a media frame adjacent to media frame 1. That is, the digital watermark generated based on the previous frame of media data can be embedded in the next frame of media data. Of course, the embodiment of the present application does not exclude the solution of embedding the digital watermark generated based on the previous frame into the media frame after a certain interval of frames.

[0114] Furthermore, after communication party 2 receives media data 1 and media data 2 sent by communication party 1, it may perform the following steps 904 to 905.

[0115] Step 904 : Communication party 2 obtains authentication message 2 , which includes fingerprint information 2 of media data 1 .

[0116] After communication party 2 receives the media data 1 sent by communication party 1, it generates fingerprint information 2 of media data 1 by applying the same hash algorithm as that applied by communication party 1 to media data 1 in the above step 901. If the media data 1 has not been tampered with during transmission, then fingerprint information 2 is the same as fingerprint information 1.

[0117] After receiving media data 2 sent by communicating party 2, communicating party 2 extracts digital watermark 1 from media data 2 using a watermark extraction algorithm. If digital watermark 1 only includes signature value 1, communicating party 2 may use the calculated fingerprint information 2 as authentication message 2. In this case, step 904 may involve communicating party 2 obtaining authentication message 2 based on media data 1. If digital watermark 1 includes authentication attribute information and signature value 1, communicating party 2 may use both the calculated fingerprint information 2 and the authentication attribute information extracted from digital watermark 1 as authentication message 2. In this case, step 904 may involve communicating party 2 obtaining authentication message 2 based on media data 1 and media data 2.

[0118] Step 905 : Communication party 2 uses key 2 and authentication message 2 to verify signature value 1 to determine the authenticity of media data 1 .

[0119] In conjunction with the first possible implementation of step 902 above, Key 1 is the private key held by communicating party 1, and Key 2 is the public key held by communicating party 1. That is, Key 2 and Key 1 form a public-private key pair held by communicating party 1. Communicating party 2 uses Key 2 and authentication message 2 to verify Signature Value 1. This can be done by first running the same hash algorithm on authentication message 2 as that run by communicating party 1 on authentication message 1 to obtain Data Hash Value 1, and then decrypting Signature Value 1 using Key 2 to obtain Data Hash Value 2. If Data Hash Value 1 and Data Hash Value 2 are identical, media data 1 is determined to be authentic. If Data Hash Value 1 and Data Hash Value 2 are different, media data 1 is determined to be not authentic.

[0120] In conjunction with the second possible implementation of step 902 above, key 1 is the session key negotiated between communication party 1 and communication party 2, and key 2 and key 1 are the same key. In this implementation, signature value 1 can be a message authentication code, and communication party 2 uses key 2 and authentication message 2 to verify signature value 1. Communication party 2 can calculate the message authentication code based on authentication message 2 and the session key and the HMAC algorithm. If the message authentication code calculated by communication party 2 is the same as the message authentication code (signature value 1) carried in digital watermark 1, then media data 1 is determined to be authentic data. If the message authentication code calculated by communication party 2 is different from the message authentication code (signature value 1) carried in digital watermark 1, then media data 1 is determined to be not authentic data.

[0121] In conjunction with the third possible implementation of step 902 above, key 1 is a shared key of the group to which communication party 1 and communication party 2 belong, and key 2 and key 1 are the same key. In this implementation, signature value 1 can be a message authentication code, and communication party 2 uses key 2 and authentication message 2 to verify signature value 1. Communication party 2 can calculate the message authentication code based on authentication message 2 and the shared key and the HMAC algorithm. If the message authentication code calculated by communication party 2 is the same as the message authentication code (signature value 1) carried in digital watermark 1, then media data 1 is determined to be authentic data. If the message authentication code calculated by communication party 2 is different from the message authentication code (signature value 1) carried in digital watermark 1, then media data 1 is determined to be not authentic data.

[0122] In the embodiment of the present application, since the signature value in the digital watermark is calculated by the sender using a key to calculate the authentication message including the fingerprint information of the media data, where the fingerprint information can provide data identity proof for the media data, the generated digital watermark can be coupled with the media data to prevent malicious forgery, and the signature value can be used to determine the authenticity of the media data to achieve end-to-end identity authentication of the first media data. It is usually difficult for an attacker to steal the target key for generating the digital watermark and the algorithm for generating the digital watermark at the same time. Therefore, it is difficult for an attacker to counterfeit the digital watermark, and thus it is difficult for the attacker to carry out undetected attacks. Therefore, the embodiment of the present application can achieve secure transmission of media data between the communicating parties.

[0123] In addition, based on the concept provided in the embodiment of the present application of embedding a digital watermark generated based on previously transmitted media data into subsequently transmitted media data, further, the communication party 1 can also obtain the fingerprint information 3 of the media data 2, and generate a digital watermark 2 based on the fingerprint information 3. The digital watermark 2 includes a signature value 2 obtained by the communication party 1 using the key 1 to sign the authentication message 3, and the authentication message 3 includes the fingerprint information 2. After sending the media data 2 to the communication party 2, the communication party 1 sends the media data 3 to the communication party 2, and the digital watermark 2 is embedded in the media data 3. Correspondingly, after receiving the media data 3 sent by the communication party 1, the communication party 2 obtains the authentication message 4, and the authentication message 4 includes the fingerprint information 4 of the media data 2. The communication party 2 uses the key 2 and the authentication message 4 to verify the signature value 2 to determine the authenticity of the media data 2. The implementation of this process can refer to the above steps 901 to 905, and this cycle is repeated until the entire media stream transmission is completed.

[0124] This application illustrates the implementation process of the above method 900 through the following embodiments.

[0125] For example, the sending end embeds the digital watermark generated based on the previous media frame into the next media frame, and the receiving end uses the backward verification algorithm to verify the previous frame using the information of the next frame. Figure 10 is a schematic diagram of a signature authentication process provided by an embodiment of the present application. First, define D i is the i-th media frame obtained by framing the media stream, where i is a positive integer. i ) is a fingerprint algorithm used to calculate the fingerprint information f of the i-th media frame i 。 m is the authentication attribute information. W(f i ) is a watermark generation algorithm for the fingerprint information f based on the i-th media frame i Generate digital watermark W i , W i =m||H(k,f i ||m), where H is the hash function and k is the key for hash calculation.

[0126] 10, the sending end adds a digital watermark with authentication attribute information to the media frame. The specific implementation steps are as follows: 1) Calculate the real-time transmission media frame D i Fingerprint information f i , then the fingerprint information f i Calculate the signature information H using the key k and the authentication attribute information m i =H(k,f i || m); 2) the frame signature information H i The digital watermark W is obtained by character splicing with the authentication attribute information m i ; 3) Use watermark embedding algorithm to embed digital watermark W i Embedded into the next media frame D i+1 The watermark is embedded in i The next media frame D i+1 Repeat steps 1 to 3 above to complete the loop embedding process.

[0127] 10, the receiving end verifies the digital watermark with authentication attribute information in the media frame. The specific implementation steps are as follows: 1) Use the watermark extraction algorithm to extract the media frame D i+1 The digital watermark W in i ; 2) Calculate the previous frame D i Fingerprint information f i ', and from the digital watermark W i Extract authentication attribute information m; 3) fingerprint information f i 'Calculate W(f i ')=m||H(k,f i '||m); 4) Compare W(f i ') and W iIf the values ​​are the same, the verification is passed; if they are different, the verification fails. Follow steps 1 to 4 above to continue using media frame D i+2 The digital watermark W in i+1 Continue to check media frame D i+1 , until the verification process is completed.

[0128] The embodiments of the present application combine the application of digital watermark technology, digital fingerprint technology and digital signature technology. The communication party as the sending end signs the fingerprint information of the media data sent previously, and carries the signature value in the digital watermark and embeds it into the media data sent later. The communication party as the receiving end can verify the signature value in the media data received later based on the fingerprint information of the media data received previously, so as to judge the integrity and authenticity of the media data transmitted previously, thereby realizing end-to-end identity authentication. By embedding the digital watermark associated with the media data transmitted previously into the media data transmitted later, it solves the problem that the time-consuming calculation of the fingerprint affects the real-time transmission of the media data, and that embedding the fingerprint into the current media data changes the data content and causes misjudgment in the fingerprint matching stage, and solves the problem that the time-consuming signature affects the real-time transmission of the media data, while realizing automatic and continuous out-of-band authentication (OOBA) of the media data.

[0129] The following uses the video conferencing scenario shown in Figure 6 as an example to illustrate the specific implementation of the embodiment of the present application. Assume that the communication party 1 is the participant A and the communication party 2 is the participant B.

[0130] In step S1, participant A registers with the MCU of the video conferencing system and sends the public key bundle of participant A to the MCU; participant B registers with the MCU of the video conferencing system and sends the public key bundle of participant B to the MCU; participant C registers with the MCU of the video conferencing system and sends the public key bundle of participant C to the MCU; participant D registers with the MCU of the video conferencing system and sends the public key bundle of participant D to the MCU.

[0131] Optionally, the public key material of participant A may include a long-term public key LongPKA and a temporary public key epkA. The public key material of participant B may include a long-term public key LongPKB and a temporary public key epkB. The public key material of participant C may include a long-term public key LongPKC and a temporary public key epkC. The public key material of participant D may include a long-term public key LongPKD and a temporary public key epkD.

[0132] In step S2, participant A, as the conference initiator, obtains the public key materials of participants B, C and D from the MCU; participant B joins the conference and obtains the public key materials of participants A, C and D from the MCU; participant C joins the conference and obtains the public key materials of participants A, B and D from the MCU; participant D joins the conference and obtains the public key materials of participants A, B and C from the MCU.

[0133] In step S3, participants A, B, C, and D negotiate a master key mk.

[0134] In step S4, participant A generates authentication attribute information m.

[0135] For example, participant A generates the public key string allGroupPK = epkA||epkB||epkC||epkD||LongPKA||LongPKB||LongPKC||LongPKD; then generates the derived key OTP_OOB = KDF(mk, IDA||IDB||IDC||IDD||"OOB"), where mk represents the master key, IDA represents participant A's identifier, IDB represents participant B's identifier, IDC represents participant C's identifier, IDD represents participant D's identifier, and OOB represents out-of-band parameters. Participant A then uses the derived key OTP_OOB to perform a hash operation on the public key string allGroupPK to obtain the authentication attribute information m.

[0136] In step S5, participant A generates a digital watermark 1 based on the authentication attribute information m and the fingerprint information of the media data 1. The digital watermark 1 includes the authentication attribute information m and the signature value obtained by participant A using the master key mk to sign the authentication attribute information m and the fingerprint information of the media data 1.

[0137] In step S6 , participant A sends media data 1 and media data 2 to participant B, participant C, and participant D in sequence, where digital watermark 1 is embedded in media data 2 .

[0138] In step S7, participant B, participant C and participant D respectively verify the signature value in the digital watermark 1 based on the master key mk, the authentication attribute information m in the digital watermark 1 and the fingerprint information of the media data 1 calculated by themselves to determine whether the media data 1 is authentic data.

[0139] The order of the steps of the above-mentioned media data transmission method provided in the embodiment of the present application can be adjusted appropriately, and the steps can also be increased or decreased accordingly according to the circumstances. Any technical personnel familiar with the technical field can easily think of a method of change within the technical scope disclosed in this application, and all of these methods should be covered by the scope of protection of this application. For example, by adding authentication attribute information related to personal identity to the digital watermark, the media data can be traced and securely obtained. For another example, a communication party can serve as both a sender and a receiver of media data, that is, a communication party can simultaneously have the ability to execute the above-mentioned steps 901 to 903 (steps executed by the sender) and steps 904 to 905 (steps executed by the receiver).

[0140] The present application also provides a method for transmitting media data, which can be applied to various application scenarios involving media data transmission, such as the video conferencing scenario shown in Figure 6. The implementation process of the method includes but is not limited to the following steps M1 to M3.

[0141] In step M1, the first communication party obtains first fingerprint information of first media data.

[0142] In step M2, the first communication party generates a first digital watermark according to the first fingerprint information. The first digital watermark includes a first signature value obtained by the first communication party signing a first authentication message using a target key. The first authentication message includes the first fingerprint information.

[0143] In step M3, the first communication party sends first media data and second media data to the second communication party, where the first digital watermark is embedded in the second media data, and the second media data is sent after the first media data.

[0144] When this method is specifically used to implement the embodiment shown in the above-mentioned method 900, the first communication party may be, for example, communication party 1, the second communication party may be, for example, communication party 2, the first media data may be, for example, media data 1, the second media data may be, for example, media data 2, the first fingerprint information may be, for example, fingerprint information 1, the first digital watermark may be, for example, digital watermark 1, the first authentication message may be, for example, authentication message 1, and the first signature value may be, for example, signature value 1.

[0145] Optionally, the target key is a private key held by the first communication party; or, the target key is a session key negotiated between the first communication party and the second communication party; or, the target key is a shared key of the group to which the first communication party and the second communication party belong, and the shared key is negotiated by multiple communication parties in the group.

[0146] Optionally, the first media data is in a first media frame, the second media data is in a second media frame, and the second media frame is a media frame adjacent to the first media frame.

[0147] Optionally, the first authentication message further includes authentication attribute information, and the first digital watermark includes the authentication attribute information and a first signature value.

[0148] Optionally, the first communication party uses a key derivation function to generate a derived key based on the shared key of the group to which the first communication party and the second communication party belong, the identity identifier of the first communication party, and the identity identifier of the second communication party, and the shared key is obtained by negotiation by multiple communication parties in the group; the first communication party uses the derived key to calculate the hash value of multiple identity public keys as authentication attribute information, and the multiple identity public keys include the identity public key of the first communication party and the identity public key of the second communication party.

[0149] Optionally, the method also includes: the first communication party obtains second fingerprint information of the second media data. The first communication party generates a second digital watermark based on the second fingerprint information, the second digital watermark includes a second signature value obtained by the first communication party using the target key to sign the second authentication message, and the second authentication message includes the second fingerprint information. After sending the second media data to the second communication party, the first communication party sends third media data to the second communication party, and the third media data is embedded with the second digital watermark. When this method is specifically used to implement the embodiment shown in the above method 900, the second fingerprint information can be, for example, fingerprint information 3, the second digital watermark can be, for example, digital watermark 2, the second authentication message can be, for example, authentication message 3, the second signature value can be, for example, signature value 2, and the third media data can be, for example, media data 3.

[0150] Optionally, the first media data and the second media data are audio data, video data or file data.

[0151] The present application also provides another method for media data transmission, which can be applied to various application scenarios involving media data transmission, such as the video conferencing scenario shown in Figure 6. The implementation process of the method includes but is not limited to the following steps N1 to N3.

[0152] In step N1, the second communication party receives first media data and second media data sent by the first communication party, wherein the second media data is received after the first media data, and a first digital watermark is embedded in the second media data, and the first digital watermark includes a first signature value.

[0153] In step N2, the second communication party obtains a first authentication message, where the first authentication message includes first fingerprint information of the first media data.

[0154] In step N3, the second communication party verifies the first signature value using the target key and the first authentication message to determine the authenticity of the first media data.

[0155] When this method is specifically used to implement the embodiment shown in the above-mentioned method 900, the first communication party may be, for example, communication party 1, the second communication party may be, for example, communication party 2, the first media data may be, for example, media data 1, the second media data may be, for example, media data 2, the first fingerprint information may be, for example, fingerprint information 2, the first digital watermark may be, for example, digital watermark 1, the first authentication message may be, for example, authentication message 2, and the first signature value may be, for example, signature value 1.

[0156] Optionally, the target key is a public key held by the first communication party; or, the target key is a session key negotiated between the first communication party and the second communication party; or, the target key is a shared key of the group to which the first communication party and the second communication party belong, and the shared key is negotiated by multiple communication parties in the group.

[0157] Optionally, the first digital watermark further includes authentication attribute information, and the first authentication message further includes authentication attribute information.

[0158] Optionally, the method also includes: the second communication party receives third media data sent by the first communication party, wherein the third media data is received after the second media data, a second digital watermark is embedded in the third media data, and the second digital watermark includes a second signature value. The second communication party obtains a second authentication message, and the second authentication message includes second fingerprint information of the second media data. The second communication party uses the target key and the second authentication message to verify the second signature value to determine the authenticity of the second media data. When this method is specifically used to implement the embodiment shown in the above method 900, the second fingerprint information can be, for example, fingerprint information 4, the second digital watermark can be, for example, digital watermark 2, the second authentication message can be, for example, authentication message 4, the second signature value can be, for example, signature value 2, and the third media data can be, for example, media data 3.

[0159] Optionally, the first media data and the second media data are audio data, video data or file data.

[0160] The following is an example of the software device in the embodiment of the present application.

[0161] For example, Figure 11 is a schematic diagram of the structure of a media data transmission device provided in an embodiment of the present application. The media data transmission device is applied to a first communication party. As shown in Figure 11, the media data transmission device 1100 includes but is not limited to: an acquisition module 1101, a processing module 1102, and a sending module 1103.

[0162] Acquisition module 1101 is configured to acquire first fingerprint information of first media data. Processing module 1102 is configured to generate a first digital watermark based on the first fingerprint information. The first digital watermark includes a first signature value obtained by the first communication party signing a first authentication message using a target key. The first authentication message includes the first fingerprint information. Sending module 1103 is configured to send the first media data and second media data to a second communication party. The second media data is embedded with the first digital watermark. The second media data is sent after the first media data.

[0163] Optionally, the target key is a private key held by the first communication party; or, the target key is a session key negotiated between the first communication party and the second communication party; or, the target key is a shared key of the group to which the first communication party and the second communication party belong, and the shared key is negotiated by multiple communication parties in the group.

[0164] Optionally, the first media data is in a first media frame, the second media data is in a second media frame, and the second media frame is a media frame adjacent to the first media frame.

[0165] Optionally, the first authentication message further includes authentication attribute information, and the first digital watermark includes the authentication attribute information and a first signature value.

[0166] Optionally, the processing module 1102 is further used to: use a key derivation function to generate a derived key based on the shared key of the group to which the first communication party and the second communication party belong, the identity identifier of the first communication party, and the identity identifier of the second communication party, where the shared key is obtained by negotiation among multiple communication parties in the group; and use a hash value calculated using the derived key for multiple identity public keys as authentication attribute information, where the multiple identity public keys include the identity public key of the first communication party and the identity public key of the second communication party.

[0167] Optionally, the acquisition module 1101 is further configured to acquire second fingerprint information of the second media data. The processing module 1102 is further configured to generate a second digital watermark based on the second fingerprint information, the second digital watermark comprising a second signature value obtained by the first communication party signing a second authentication message using the target key, the second authentication message comprising the second fingerprint information. The sending module 1103 is further configured to, after sending the second media data to the second communication party, send third media data to the second communication party, the third media data being embedded with the second digital watermark.

[0168] Optionally, the first media data and the second media data are audio data, video data or file data.

[0169] For another example, FIG12 is a schematic diagram of the structure of another media data transmission device provided in an embodiment of the present application. This media data transmission device is applied to a second communication party. As shown in FIG12 , the media data transmission device 1200 includes but is not limited to: a receiving module 1201, an acquisition module 1202, and a verification module 1203.

[0170] Receiving module 1201 is configured to receive first media data and second media data sent by a first communication party, wherein the second media data is received after the first media data and is embedded with a first digital watermark, which includes a first signature value. Acquisition module 1202 is configured to obtain a first authentication message, which includes first fingerprint information of the first media data. Verification module 1203 is configured to verify the first signature value using a target key and the first authentication message to determine the authenticity of the first media data.

[0171] Optionally, the target key is a public key held by the first communication party; or, the target key is a session key negotiated between the first communication party and the second communication party; or, the target key is a shared key of the group to which the first communication party and the second communication party belong, and the shared key is negotiated by multiple communication parties in the group.

[0172] Optionally, the first digital watermark further includes authentication attribute information, and the first authentication message further includes authentication attribute information.

[0173] Optionally, receiving module 1201 is further configured to receive third media data sent by the first communication party, wherein the third media data is received after the second media data, and a second digital watermark is embedded in the third media data, wherein the second digital watermark includes a second signature value. Acquisition module 1202 is further configured to obtain a second authentication message, wherein the second authentication message includes second fingerprint information of the second media data. Verification module 1203 is further configured to verify the second signature value using the target key and the second authentication message to determine the authenticity of the second media data.

[0174] Optionally, the first media data and the second media data are audio data, video data or file data.

[0175] The following is an illustration of the hardware device of the embodiment of the present application.

[0176] For example, Figure 13 is a schematic diagram of the hardware structure of a communication device provided in an embodiment of the present application. The communication device can be a device of any communication party in the above embodiments, for example, it can be a conference terminal. As shown in Figure 13, the communication device 1300 includes a processor 1301 and a memory 1302, and the memory 1301 and the memory 1302 are connected via a bus 1303. Figure 13 illustrates the processor 1301 and the memory 1302 as independent of each other. Optionally, the processor 1301 and the memory 1302 are integrated together. Optionally, in combination with Figure 6, the communication device 1300 in Figure 13 can be any conference terminal shown in Figure 6.

[0177] Memory 1302 is used to store computer programs, including operating systems and program code. Memory 1302 is various types of storage media, such as read-only memory (ROM), random access memory (RAM), electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM), flash memory, optical storage, registers, optical disk storage, optical disc storage, magnetic disk, or other magnetic storage devices.

[0178] Processor 1301 is a general-purpose processor or a dedicated processor. Processor 1301 may be a single-core processor or a multi-core processor. Processor 1301 includes at least one circuit to execute the actions performed by communication party 1 or communication party 2 in the above method 900 provided in the embodiment of the present application.

[0179] Optionally, the communication device 1300 further includes a network interface 1304, which is connected to the processor 1301 and the memory 1302 via the bus 1303. The network interface 1304 enables the communication device 1300 to communicate with other devices. For example, the processor 1301 can interact with other devices via the network interface 1304, such as communicating with an MCU via the network interface 1304, and so on.

[0180] Optionally, communication device 1300 further includes an input / output (I / O) interface 1305, which is connected to processor 1301 and memory 1302 via bus 1303. Processor 1301 can receive input commands or data through I / O interface 1305. I / O interface 1305 is used to connect communication device 1300 to input devices, such as a keyboard and a mouse. Optionally, in some possible scenarios, the network interface 1304 and I / O interface 1305 are collectively referred to as a communication interface.

[0181] Optionally, the communication device 1300 further includes a display 1306, which is connected to the processor 1301 and the memory 1302 via the bus 1303. The display 1306 can be used to display intermediate results and / or final results generated by the processor 1301 executing the above method. In one possible implementation, the display 1306 is a touch screen display to provide a human-computer interaction interface.

[0182] The bus 1303 is any type of communication bus used to interconnect the internal components of the communication device 1300, such as a system bus. The embodiments of the present application illustrate the example of the aforementioned components within the communication device 1300 being interconnected via the bus 1303. Alternatively, the aforementioned components within the communication device 1300 may be communicatively connected to each other using other connection methods besides the bus 1303, such as interconnecting the aforementioned components within the communication device 1300 via a logical interface within the communication device 1300.

[0183] The above-mentioned devices can be provided on separate chips, or at least partially or entirely on the same chip. Whether to provide each device independently on different chips or to integrate them on one or more chips often depends on the product design requirements. The embodiments of this application do not limit the specific implementation of the above-mentioned devices.

[0184] The communication device 1300 shown in Figure 13 is merely exemplary. During implementation, the communication device 1300 includes other components, which are not listed here. The communication device 1300 shown in Figure 13 can implement media data transmission by executing all or part of the steps of the method provided in the above embodiment.

[0185] The following is an example of the system in the embodiment of the present application.

[0186] The present application also provides a media data transmission system, including: a first communication party and a second communication party. The first communication party is configured to execute the steps executed by communication party 1 in method 900, such as steps 901 to 903. The second communication party is configured to execute the steps executed by communication party 2 in method 900, such as steps 904 to 905.

[0187] Optionally, the media data transmission system may be a conference system, such as an audio and video conference system or a cloud service conference system. The first communication party and the second communication party are both participants in the conference.

[0188] An embodiment of the present application also provides a computer-readable storage medium, on which instructions are stored. When the instructions are executed by a processor, the steps performed by communication party 1 or the steps performed by communication party 2 in the above method 900 are implemented.

[0189] An embodiment of the present application further provides a computer program product, including a computer program. When the computer program is executed by a processor, the computer program implements the steps performed by communication party 1 or the steps performed by communication party 2 in the above method 900.

[0190] Those skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware, or by a program to instruct the relevant hardware, and the program may be stored in a computer-readable storage medium, which may be a read-only memory, a disk, or an optical disk, etc.

[0191] In the embodiments of the present application, the terms “first”, “second” and “third” are used for descriptive purposes only and should not be understood as indicating or implying relative importance.

[0192] In this application, the term "and / or" simply describes an association between related objects, indicating that three possible relationships exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this document generally indicates that the related objects are in an "or" relationship.

[0193] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.) and signals involved in this application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions.

[0194] The above description is merely an optional embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the concepts and principles of the present application shall be included in the scope of protection of the present application.

Claims

1. A method for transmitting media data, characterized in that: The method comprises: The first communication party obtains first fingerprint information of the first media data; The first communication party generates a first digital watermark according to the first fingerprint information, the first digital watermark includes a first signature value obtained by the first communication party signing a first authentication message using a target key, and the first authentication message includes the first fingerprint information; The first communication party sends the first media data and second media data to a second communication party, wherein the first digital watermark is embedded in the second media data, and the second media data is sent after the first media data.

2. The method according to claim 1, characterized in that The target key is a private key held by the first communication party; Alternatively, the target key is a session key negotiated between the first communication party and the second communication party; Alternatively, the target key is a shared key of a group to which the first communication party and the second communication party belong, and the shared key is obtained through negotiation by multiple communication parties in the group.

3. The method according to claim 1 or 2, characterized in that: The first media data is in a first media frame, and the second media data is in a second media frame, and the second media frame is a media frame adjacent to the first media frame.

4. The method according to any one of claims 1 to 3, characterized in that: The first authentication message also includes authentication attribute information, and the first digital watermark includes the authentication attribute information and the first signature value.

5. The method according to claim 4, characterized in that The method further comprises: The first communication party generates a derived key using a key derivation function based on a shared key of a group to which the first communication party and the second communication party belong, an identity identifier of the first communication party, and an identity identifier of the second communication party, wherein the shared key is obtained through negotiation by multiple communication parties in the group; The first communication party uses the derived key to calculate a hash value of multiple identity public keys as the authentication attribute information, and the multiple identity public keys include the identity public key of the first communication party and the identity public key of the second communication party.

6. The method according to any one of claims 1 to 5, characterized in that: The method further comprises: The first communication party obtains second fingerprint information of the second media data; The first communication party generates a second digital watermark according to the second fingerprint information, the second digital watermark includes a second signature value obtained by the first communication party signing a second authentication message using the target key, and the second authentication message includes the second fingerprint information; After sending the second media data to the second communication party, the first communication party sends third media data to the second communication party, wherein the second digital watermark is embedded in the third media data.

7. The method according to any one of claims 1 to 6, characterized in that: The first media data and the second media data are audio data, video data or file data.

8. A method for transmitting media data, characterized in that: The method comprises: The second communication party receives first media data and second media data sent by the first communication party, wherein the second media data is received after the first media data, a first digital watermark is embedded in the second media data, and the first digital watermark includes a first signature value; The second communication party obtains a first authentication message, where the first authentication message includes first fingerprint information of the first media data; The second communication party verifies the first signature value using the target key and the first authentication message to determine the authenticity of the first media data.

9. The method according to claim 8, characterized in that The target key is a public key held by the first communication party; Alternatively, the target key is a session key negotiated between the first communication party and the second communication party; Alternatively, the target key is a shared key of a group to which the first communication party and the second communication party belong, and the shared key is obtained through negotiation by multiple communication parties in the group.

10. The method according to claim 8 or 9, characterized in that: The first digital watermark further includes authentication attribute information, and the first authentication message further includes the authentication attribute information.

11. The method according to any one of claims 8 to 10, characterized in that: The method further comprises: The second communication party receives third media data sent by the first communication party, wherein the third media data is received after the second media data, a second digital watermark is embedded in the third media data, and the second digital watermark includes a second signature value; The second communication party obtains a second authentication message, where the second authentication message includes second fingerprint information of the second media data; The second communication party verifies the second signature value using the target key and the second authentication message to determine the authenticity of the second media data.

12. The method according to any one of claims 8 to 11, characterized in that: The first media data and the second media data are audio data, video data or file data.

13. A media data transmission device, characterized in that: Applied to a first communication party, the device comprises: An acquisition module, used to acquire first fingerprint information of first media data; a processing module, configured to generate a first digital watermark according to the first fingerprint information, wherein the first digital watermark includes a first signature value obtained by the first communication party signing a first authentication message using a target key, and the first authentication message includes the first fingerprint information; A sending module is used to send the first media data and second media data to a second communication party, wherein the first digital watermark is embedded in the second media data, and the second media data is sent after the first media data.

14. The device according to claim 13, characterized in that The target key is a private key held by the first communication party; Alternatively, the target key is a session key negotiated between the first communication party and the second communication party; Alternatively, the target key is a shared key of a group to which the first communication party and the second communication party belong, and the shared key is obtained through negotiation by multiple communication parties in the group.

15. The device according to claim 13 or 14, characterized in that The first media data is in a first media frame, and the second media data is in a second media frame, and the second media frame is a media frame adjacent to the first media frame.

16. The device according to any one of claims 13 to 15, characterized in that The first authentication message also includes authentication attribute information, and the first digital watermark includes the authentication attribute information and the first signature value.

17. The device according to claim 16, characterized in that The processing module is further used for: Generate a derived key using a key derivation function based on a shared key of a group to which the first communication party and the second communication party belong, an identity identifier of the first communication party, and an identity identifier of the second communication party, wherein the shared key is obtained through negotiation by multiple communication parties in the group; A hash value calculated by using the derived key to pair multiple identity public keys is used as the authentication attribute information, and the multiple identity public keys include the identity public key of the first communication party and the identity public key of the second communication party.

18. The device according to any one of claims 13 to 17, characterized in that The acquisition module is further used to acquire second fingerprint information of the second media data; The processing module is further configured to generate a second digital watermark according to the second fingerprint information, wherein the second digital watermark includes a second signature value obtained by the first communication party signing a second authentication message using the target key, and the second authentication message includes the second fingerprint information; The sending module is further configured to send third media data to the second communication party after sending the second media data to the second communication party, wherein the second digital watermark is embedded in the third media data.

19. The device according to any one of claims 13 to 18, characterized in that The first media data and the second media data are audio data, video data or file data.

20. A media data transmission device, characterized in that: Applied to a second communication party, the device comprises: A receiving module, configured to receive first media data and second media data sent by a first communication party, wherein the second media data is received after the first media data, a first digital watermark is embedded in the second media data, and the first digital watermark includes a first signature value; An acquisition module, configured to acquire a first authentication message, where the first authentication message includes first fingerprint information of the first media data; A verification module is used to verify the first signature value using a target key and the first authentication message to determine the authenticity of the first media data.

21. The device according to claim 20, characterized in that The target key is a public key held by the first communication party; Alternatively, the target key is a session key negotiated between the first communication party and the second communication party; Alternatively, the target key is a shared key of a group to which the first communication party and the second communication party belong, and the shared key is obtained through negotiation by multiple communication parties in the group.

22. The device according to claim 20 or 21, characterized in that The first digital watermark further includes authentication attribute information, and the first authentication message further includes the authentication attribute information.

23. The device according to any one of claims 20 to 22, characterized in that The receiving module is further configured to receive third media data sent by the first communication party, wherein the third media data is received after the second media data, a second digital watermark is embedded in the third media data, and the second digital watermark includes a second signature value; The acquisition module is further used to acquire a second authentication message, where the second authentication message includes second fingerprint information of the second media data; The verification module is further configured to verify the second signature value using the target key and the second authentication message to determine the authenticity of the second media data.

24. The device according to any one of claims 20 to 23, characterized in that The first media data and the second media data are audio data, video data or file data.

25. A media data transmission system, characterized in that: include: A first communication party and a second communication party, wherein the first communication party is used to execute the method according to any one of claims 1 to 7, and the second communication party is used to execute the method according to any one of claims 8 to 12.

26. The system according to claim 25, characterized in that The first communication party and the second communication party are both participants in the conference.

27. A communication device, characterized in that: include: Processor and memory; The memory is used to store a computer program, wherein the computer program includes program instructions; The processor is used to call the computer program to implement the method according to any one of claims 1 to 12.

28. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores instructions, and when the instructions are executed by a processor, the method according to any one of claims 1 to 12 is implemented.

29. A computer program product, characterized in that The method comprises a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 12 is implemented.

Citation Information

Patent Citations

  • Media data transmission method, device and system

    CN120074828A

  • Security certificate method based on fingerprint, cryptographic technology and fragile digital watermark

    CN101729256A

  • Source authentication method for secure multicast

    CN102594563A

  • Multimedia-sensing-network watermark verification and image restoration method and device

    CN103955877A

  • Digital media content right and interest control method and device, equipment and storage medium

    CN113688356A

Cited By

  • Secure channel establishment method and related equipment

    CN120675712A