Media data playback method and apparatus, media data tracing method and apparatus, and protection system

By embedding the target key signature watermark based on the identity private key and the authentication public key in the video conference, the problem of watermarks being easily erased and malicious forgery in the video conference is solved, realizing the authenticity verification of media data and the source traceability of playback, protecting user privacy and improving security.

WO2025139183A1PCT designated stage expired Publication Date: 2025-07-03HUAWEI TECH CO LTD

Patent Information

Application Number
PCT/CN2024/123728
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-29
Filing Date
2024-10-09
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

In existing video conferencing, digital watermarking technology has the problem of being easily erased and malicious forgery and framed, and it is difficult to effectively protect user privacy and prevent illegal leakage of media data.

Method used

By embedding a digital watermark in the media data based on the identity private key held by the terminal and the target key signature generated by the authentication public key provided by the authentication party, only the authenticator and the terminal can calculate the key, restrict the traceability permissions, and prevent others from missing the watermark to leak media data.

Benefits of technology

It realizes the authenticity verification of media data and traceability of playback sources, protects user privacy, reduces the risks of malicious counterfeiting and disclosure, and improves the security and traceability of watermarks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024123728_03072025_PF_FP_ABST
    Figure CN2024123728_03072025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of computers, and provides a media data playback method and apparatus, a media data tracing method and apparatus, and a protection system. A terminal generates a digital watermark on the basis of authentication attribute information of media data to be played back, the digital watermark comprising the authentication attribute information and signature information obtained by signing the authentication attribute information with a target key. The target key is obtained on the basis of an identity private key held by the terminal and an authentication public key provided by an authentication party. The terminal embeds the digital watermark in the media data and plays back the media data embedded with the digital watermark. The authentication attribute information is used for identifying a playback source range of the media data, plays the role of identity information of the media data, and can reduce a traceability range of the media data. The signature information is used for ensuring the authenticity of the authentication attribute information of the media data. As long as the identity private key held by the terminal is not leaked, other user terminals will not be able to compute the target key, preventing others from maliciously impersonating the watermark to leak media data for entrapment.
Need to check novelty before this filing date? Find Prior Art

Description

Media data playback method, source tracing method and device, and protection system

[0001] This application claims priority to Chinese patent application No. 202311873583.4 filed on December 29, 2023, entitled “Media data playback method, source tracing method and device, and protection system,” the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of computer technology, and in particular to a method for playing media data, a method and device for tracing the source, and a protection system. Background Art

[0003] With the development of information technology, information security issues have become prominent. To address issues such as multimedia copyright infringement and the illegal recording and leakage of information, extensive research has been conducted in the fields of encryption and digital watermarking. Encryption technology can ensure the secure transmission of media data between the provider and the recipient. However, once the recipient obtains the encrypted information and decrypts it to obtain the plaintext media data, the encryption technology no longer provides protection. If the recipient subsequently retransmits the media data or if it is secretly recorded during playback, the media data will be illegally leaked. Digital watermarking technology can embed copyright information or the recipient's user information into media data to protect copyright, verify product authenticity, track piracy, or provide additional product information. The key to implementing digital watermarking technology lies in how to generate and embed secure and reliable digital watermarks into media data.

[0004] Summary of the Invention

[0005] The present application provides a media data playback method, source tracing method and device, and protection system.

[0006] In a first aspect, a method for playing media data is provided. The method is applied to a terminal. The method includes: the terminal obtaining authentication attribute information of the media data to be played, the authentication attribute information being used to identify the playback source range of the media data. The terminal generates a digital watermark based on the authentication attribute information, the digital watermark including the authentication attribute information and signature information obtained by signing the authentication attribute information using a target key. The target key is obtained based on an identity private key held by the terminal and an authentication public key provided by an authenticator. Only the authenticator has the authority to trace the source of the media data. The terminal embeds the digital watermark in the media data and plays the media data embedded with the digital watermark.

[0007] This application carries the authentication attribute information of the media data in the digital watermark and uses the target key to sign the authentication attribute information to obtain the signature information. The authentication attribute information in the digital watermark can declare the playback source range of the media data and play the role of the identity information of the media data, thereby narrowing the traceability scope of the media data. The signature information in the digital watermark is used to ensure the authenticity of the authentication attribute information of the media data, that is, to ensure the authenticity of the media data. Since the target key is obtained based on the identity private key held by the terminal and the authentication public key provided by the authentication party, as long as the identity private key held by the terminal is not leaked, other user terminals cannot calculate the target key, and thus cannot use the target key to calculate the signature information to forge the watermark. Therefore, it can prevent others from maliciously counterfeiting the watermark to leak media data and frame others. In addition, in this application, the playback source of the media data is proved by signature information, rather than directly carrying the user or device identity information in the digital watermark, so the leakage of user or device identity information can also be avoided.

[0008] In a first possible implementation, the terminal uses a key agreement algorithm to generate a target key based on the identity private key and the authentication public key. Accordingly, the terminal uses the target key to sign the authentication attribute information, including: using the target key to sign the authentication attribute information using a symmetric signature algorithm to obtain a symmetric signature value, and the signature information is the symmetric signature value, or the signature information is a truncated result of the symmetric signature value.

[0009] Under this implementation, only the authenticator and the terminal can calculate the same symmetric key. As long as the identity private key held by the terminal and the authentication private key held by the authenticator are not leaked, no third party other than the terminal and the authenticator can calculate the target key, and thus cannot use the target key to calculate the signature information to forge the watermark. This can prevent others from maliciously counterfeiting the watermark to leak media data and frame others. In addition, this application can truncate the symmetric signature value and embed the truncated result value as watermark information into the media data, which can reduce the watermark embedding capacity, thereby ensuring the fidelity and robustness of the media data (especially audio data) after the watermark information is embedded.

[0010] Optionally, in the first possible implementation described above, the authentication public key is jointly provided by multiple approvers, and is a distributed key generation (DKG) public key. The multiple approvers jointly hold n private key shards, and the number of private key shards held by each approver is less than t. The DKG public key is calculated based on the n private key shards, and the private key corresponding to the DKG public key is calculated based on at least t of the n private key shards. Here, n is an integer greater than 1, and 2≤t≤n.

[0011] Under this implementation method, the authenticator needs to rely on multiple approvers to recover the private key corresponding to the authentication public key, and further calculate the key that is the same as the target key used by the terminal to generate the digital watermark in combination with the identity public key held by the terminal. Compared with the scheme in which the authenticator directly holds the authentication private key, this scheme reduces the risk of the authenticator maliciously counterfeiting the watermark to frame the terminal user because the authenticator is supervised by multiple approvers, thereby improving the reliability of the authenticator and the security of the watermark, and further improving the reliability of the watermark traceability.

[0012] In a second possible implementation, the terminal uses an asymmetric key generation algorithm to generate a target key from the identity private key and the authentication public key. Accordingly, the terminal uses the target key to sign the authentication attribute information, including: signing the authentication attribute information using the target key using the asymmetric signature algorithm to obtain an asymmetric signature value, where the signature information is the asymmetric signature value.

[0013] In this implementation, only the terminal can calculate the target key used to generate the digital watermark, preventing any third party, including the authenticator, from maliciously forging the watermark and leaking media data to frame the user. Furthermore, only the authenticator can calculate the key used to verify the digital watermark generated by the terminal. This means that only the authenticator has the authority to trace the source of the media data played by the terminal, effectively protecting the privacy of the terminal user.

[0014] Optionally, an implementation of the terminal using an asymmetric key generation algorithm to generate a target key from the identity private key and the authentication public key includes: the terminal using a key derivation function to generate a derived key based on the identity private key and the authentication public key, and the terminal generating the target key based on the derived key and the identity private key.

[0015] Optionally, the target key is SK, SK = (K + SKu) mod q, where SKu is the identity private key, K is the derived key, q is a prime number, mod q means taking a modulus of q, and the value range of SK is [1, q).

[0016] Optionally, the terminal sends a key acquisition request to the authenticator, the key acquisition request including the terminal's device identification, and the terminal receives a key acquisition response sent by the authenticator, the key acquisition response including the authentication public key.

[0017] Optionally, the terminal is a conference terminal participating in a conference, and the media data comes from the conference. The authentication attribute information may include a conference identifier of the conference and / or conference timestamp information of the conference.

[0018] Optionally, the terminal receives media data sent by other conference terminals participating in the conference.

[0019] In the second aspect, a method for tracing the source of media data is provided. The method is applied to an authenticator. The method includes: the authenticator obtains a digital watermark in the media data to be traced, the digital watermark includes authentication attribute information of the media data and signature information obtained based on the authentication attribute information, and the authentication attribute information is used to identify the playback source range of the media data. The authenticator determines the playback source range based on the authentication attribute information. The authenticator generates a first key based on an authentication private key held by the authenticator and a first identity public key held by a first terminal, and the first terminal is any terminal within the playback source range. The authenticator verifies the signature information based on the first key and the authentication attribute information to determine whether the media data comes from the first terminal.

[0020] In this application, since only the authenticator who provides the authentication public key to the terminal can calculate the key for verifying the digital watermark generated by the terminal, only the authenticator has the authority to trace the source of the media data. Even if other terminal users extract the digital watermark from the media data, they cannot trace it back to the playback source of the media data. This can protect the user privacy of the playback source and reduce the risk of leakage of the playback source information.

[0021] In a first possible implementation, the authenticator generates a first key based on an authentication private key held by the authenticator and a first identity public key held by the first terminal, including: the authenticator employs a key agreement algorithm to generate the first key based on the authentication private key and the first identity public key. Accordingly, the authenticator verifies signature information based on the first key and authentication attribute information, including: the authenticator uses the first key to sign the authentication attribute information using a symmetric signature algorithm to obtain a symmetric signature value; if the signature information matches the symmetric signature value, the authenticator determines that the media data originated from the first terminal.

[0022] Under this implementation method, only the authenticator and the terminal can calculate the same symmetric key. As long as the identity private key held by the terminal and the authentication private key held by the authenticator are not leaked, any third party other than the terminal and the authenticator cannot calculate the target key, and thus cannot use the target key to calculate the signature information to forge the watermark. Therefore, it can prevent others from maliciously counterfeiting the watermark to leak media data and frame others.

[0023] Optionally, in the first possible implementation method mentioned above, the authentication public key corresponding to the authentication private key is jointly provided by multiple approvers, the authentication public key is a DKG public key, multiple approvers jointly hold n private key shards and the number of private key shards held by each approver is less than t, the DKG public key is calculated based on the n private key shards, and the authentication private key is obtained based on at least t private key shards out of the n private key shards, where n is an integer greater than 1, and 2≤t≤n.

[0024] Under this implementation method, the authenticator needs to rely on multiple approvers to recover the private key corresponding to the authentication public key, and further calculate the key that is the same as the target key used by the terminal to generate the digital watermark in combination with the identity public key held by the terminal. Compared with the scheme in which the authenticator directly holds the authentication private key, this scheme reduces the risk of the authenticator maliciously counterfeiting the watermark to frame the terminal user because the authenticator is supervised by multiple approvers, thereby improving the reliability of the authenticator and the security of the watermark, and further improving the reliability of the watermark traceability.

[0025] Optionally, the length of the signature information is less than the length of the symmetric signature value. If the signature information matches the symmetric signature value, the authenticator determines that the media data comes from the first terminal. The implementation method includes: if the signature information is the same as the truncated result value of the symmetric signature value, the authenticator determines that the media data comes from the first terminal.

[0026] A second possible implementation involves the authenticator generating a first key based on a private authentication key held by the authenticator and a first identity public key held by the first terminal, including: the authenticator employing an asymmetric key generation algorithm to generate the first key based on the private authentication key and the first identity public key. Accordingly, the authenticator verifies the signature information based on the first key and the authentication attribute information, including: the authenticator employing the first key to perform signature verification on the authentication attribute information and the signature information; if the signature verification passes, the authenticator determines that the media data originates from the first terminal.

[0027] In this implementation, only the terminal can calculate the target key used to generate the digital watermark, preventing any third party, including the authenticator, from maliciously forging the watermark and leaking media data to frame the user. Furthermore, only the authenticator can calculate the key used to verify the digital watermark generated by the terminal. This means that only the authenticator has the authority to trace the source of the media data played by the terminal, effectively protecting the privacy of the terminal user.

[0028] Optionally, the authenticator generates the first key using an asymmetric key generation algorithm for the authentication private key and the first identity public key, including: the authenticator generates a derived key based on the authentication private key and the first identity public key using a key derivation function. The authenticator generates the first key based on the derived key and the authentication private key.

[0029] Optionally, the first key is PK, PK=g K PKu, where PKu is the first identity public key, K is the derived key, and g is the primitive root of the prime number q.

[0030] Optionally, the authenticator receives a key acquisition request from a terminal within a playback source range, the key acquisition request including the device identification of the terminal, and sends a key acquisition response to the terminal, the key acquisition response including an authentication public key corresponding to the authentication private key.

[0031] Optionally, the playback source range includes multiple terminals. If it is determined that the media data does not originate from the first terminal, the authenticator generates a second key based on the authentication private key and a second identity public key held by a second terminal, where the second terminal is any terminal within the playback source range other than the first terminal. The authenticator verifies the signature information based on the second key and the authentication attribute information to determine whether the media data originates from the second terminal.

[0032] In this application, the authenticator may perform traversal verification on all terminals within the playback source range of the media data until the terminal from which the media data comes is determined.

[0033] Optionally, the authentication attribute information includes conference identification and / or conference timestamp information, and the authentication party determines the playback source range based on the authentication attribute information, including: the authentication party determines the conference from which the media data comes based on the authentication attribute information, and determines that the playback source range includes conference terminals participating in the conference.

[0034] In a third aspect, a device for playing media data is provided. The device includes multiple functional modules that interact with each other to implement the method of the first aspect and its respective embodiments. The multiple functional modules can be implemented based on software, hardware, or a combination of software and hardware, and the multiple functional modules can be arbitrarily combined or divided based on the specific implementation.

[0035] In a fourth aspect, a device for tracing the provenance of media data is provided. The device includes multiple functional modules that interact with each other to implement the method described in the second aspect and its respective embodiments. The multiple functional modules can be implemented based on software, hardware, or a combination of software and hardware, and the multiple functional modules can be arbitrarily combined or divided based on the specific implementation.

[0036] In a fifth aspect, a media data protection system is provided, comprising: a terminal and an authenticator, wherein the terminal is used to execute the method in the above-mentioned first aspect and its various embodiments, and the authenticator is used to execute the method in the above-mentioned second aspect and its various embodiments.

[0037] Optionally, the system is a video conferencing system, the terminal is a conference terminal, and the authenticator is a conference manager.

[0038] In the sixth aspect, a terminal is provided, comprising: a processor and a memory; the memory is used to store a computer program, the computer program comprising program instructions; the processor is used to call the computer program to implement the method in the above-mentioned first aspect and its various embodiments.

[0039] In the seventh aspect, a computer device is provided, comprising: a processor and a memory; the memory is used to store a computer program, the computer program including program instructions; the processor is used to call the computer program to implement the method in the above-mentioned second aspect and its various embodiments.

[0040] In an eighth aspect, a computer-readable storage medium is provided, on which instructions are stored. When the instructions are executed by a processor, the method of the above-mentioned first aspect and its various embodiments is implemented, or the method of the above-mentioned second aspect and its various embodiments is implemented.

[0041] In a ninth aspect, a computer program product is provided, comprising a computer program, which, when executed by a processor, implements the method of the first aspect and its various embodiments, or implements the method of the second aspect and its various embodiments.

[0042] In the tenth aspect, a chip is provided, which includes a programmable logic circuit and / or program instructions. When the chip is running, it implements the method in the above-mentioned first aspect and its various embodiments, or implements the method in the above-mentioned second aspect and its various embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] FIG1 is a schematic diagram of an implementation of a digital watermarking technology provided in an embodiment of the present application;

[0044] FIG2 is a schematic diagram of a video conferencing scenario provided in an embodiment of the present application;

[0045] FIG3 is a schematic diagram of an implementation flow of a visible watermark algorithm provided by related art;

[0046] FIG4 is a schematic diagram of an implementation flow of a watermark algorithm combined with symmetric encryption provided by the related art;

[0047] FIG5 is a schematic diagram of an application scenario provided by an embodiment of the present application;

[0048] FIG6 is a flow chart of a method for playing media data provided in an embodiment of the present application;

[0049] FIG7 is a flow chart of a method for tracing the source of media data provided in an embodiment of the present application;

[0050] FIG8 is a schematic diagram of a copyright authentication scenario for media data provided by an embodiment of the present application;

[0051] FIG9 is a schematic diagram of a media data leakage location scenario provided by an embodiment of the present application;

[0052] FIG10 is a schematic structural diagram of a media data playback device provided in an embodiment of the present application;

[0053] FIG11 is a schematic structural diagram of a media data source tracing device provided in an embodiment of the present application;

[0054] FIG12 is a schematic diagram of the hardware structure of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0055] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.

[0056] Digital watermarking technology is an information hiding technology. The watermark information is embedded in the carrier file and does not affect the visibility and integrity of the original file. The application of digital watermarking technology is very extensive, including copyright protection, anti-counterfeiting, digital forensics, information hiding and other fields. At present, digital watermarking technology has become one of the important means of digital media security protection. For example, Figure 1 is a schematic diagram of the implementation of a digital watermarking technology provided by an embodiment of the present application. As shown in Figure 1, it generates a watermark with specific identification information (which can be the creator of the digital media, user serial number or copyright information, etc.) and embeds it into the digital media information carrier. By performing watermark detection on the digital media containing the watermark, the embedded watermark information can be extracted, thereby indicating some information of the digital media itself. Digital watermarks can be embedded in various digital media, such as images, audio, video and text. According to the perceptibility of the digital watermark, digital watermarks can be divided into visible watermarks and invisible watermarks.

[0057] A visible watermark is a perceptually visible watermark, such as a logo inserted into or overlaid on an image. A visible watermark typically refers to visible information, such as text or images, embedded directly into digital media. Visible watermarks are generally used to visually identify images or videos obtained from video databases or the internet to prevent these images from being used for illegal commercial purposes. Similarly, an auditory watermark used in audio is an auditory watermark. An invisible watermark is an invisible information embedded in digital media, such as a digital code or noise. After an invisible watermark is embedded in digital media, the digital media itself is not significantly damaged and can retain its original playback quality. When necessary, the owner can extract the watermark from the digital media using a watermark detection algorithm to prove the ownership or integrity of the digital media.

[0058] The basic characteristics of digital watermarks include fidelity, robustness, and capacity. Fidelity measures the similarity between signals before and after processing. After embedding watermark information, digital media information must meet certain perceptual requirements, not necessarily requiring the watermark to be visible or invisible, depending on the application. Robustness refers to the extractability and detectability of the watermarked digital media information after undergoing various signal processing or attacks. Robustness metrics include vulnerability, effectiveness, and security. Capacity, also known as embedding rate, loading rate, or payload, refers to the maximum number of watermark bits that can be embedded per unit time or in a digital media work. The larger the capacity of a digital watermark, the more watermark information can be embedded. However, if the capacity of a digital watermark is too large, either fidelity or robustness will be compromised.

[0059] With the development of information technology, the illegal leakage of media data has become increasingly serious. Related technologies have proposed embedding digital watermarks in media data to identify and track it. Media data includes, but is not limited to, audio data, video data, file data, and other digital streaming media data, such as remote shared desktops, remote shared documents, and remote shared applications.

[0060] Taking a video conferencing scenario as an example, Figure 2 is a schematic diagram of a video conferencing scenario provided by an embodiment of the present application. As shown in Figure 2, a conference administrator convenes a secure conference, the sending-side conference terminal sends the audio and video stream, and transmits the data through the conference service platform. The receiving-side conference terminal receives and plays the audio and video stream, completing the end-to-end interaction process. However, during the audio and video playback process, there may be internal leakers who secretly record or forward the played audio and video stream to unauthorized personnel, thereby causing data leakage.

[0061] Unauthorized recordings include transcribing with screen recording software or filming with a webcam. Technically, preventing these acts is nearly impossible. Therefore, the key strategy for preventing unauthorized recordings is to trace the perpetrator to deter them. Therefore, digital watermarking technology is particularly important in this regard. As shown in Figure 2, after receiving the audio and video streams, the receiving conference terminal can generate and embed a watermark in real time during playback. The embedded watermark information is bound to the user or device identity of the user accessing the conference. The user identity of the user accessing the conference can be the identity of the user currently logged into the conference terminal, and the device identity of the conference terminal playing the audio and video streams. In this way, if an unauthorized recording (e.g., remote recording) occurs, the conference administrator only needs to obtain a small portion of the leaked audio and video stream to extract the watermark information using a watermark extraction algorithm. The device and / or user identity contained in the watermark information can then be identified, locating the device or user that leaked the data and tracing the source of the internal leak. Security during the transmission process before watermark embedding is ensured by end-to-end encryption.

[0062] At present, most video conferences use visible watermark algorithms for traceability and copyright protection. Specifically, watermarks are embedded during audio and video playback. The watermark information includes playback side device information or user information, etc., so that the played video directly displays the watermark information and is presented in a visible form. For example, Figure 3 is a schematic diagram of the implementation process of a visible watermark algorithm provided by the relevant technology. As shown in Figure 3, when the conference terminal on the receiving side plays the conference content in real time, the original digital media information is input into the embedder to embed the watermark information (including user identifier or device identifier) ​​in real time, and finally obtain the digital media information with watermark. When embedding the watermark, the capacity of the watermark can be set. A single row of watermarks can be displayed in the center, and a multi-row watermark can cover the entire screen. Since the watermark will be recorded when the screen recording software is used to record the conference content, the watermark in the video will also be recorded when recording remotely. Therefore, by applying this visible watermark algorithm, the existence of the watermark can be detected through the watermark detection algorithm, or the watermark content can be directly observed, eliminating the watermark detection step and more intuitively determining the exact source of the video, thereby realizing the function of post-tracing the watermark and achieving the effect of deterring piracy.

[0063] However, existing visible watermarking algorithms embed the user's or device's plaintext information as a watermark without any encryption or concealment. This allows anyone to directly observe the watermark on digital media, thereby revealing the owner of the digital media information, which in turn compromises user privacy. Furthermore, visible watermarks are vulnerable to malicious vandalism and are vulnerable to various attacks on watermarking algorithms. For example, a visible watermark can be erased from a video, rendering it unobservable upon subsequent dissemination, making it impossible to trace the source. Furthermore, based on the characteristics of the visible watermark, other users can infer a specific user's watermark information and embed it into videos, potentially framing the user.

[0064] Taking into account the protection of user privacy information, the relevant technology provides a watermark algorithm combined with cryptography. For example, Figure 4 is a schematic diagram of the implementation process of a watermark algorithm combined with symmetric encryption provided by the relevant technology. As shown in Figure 4, when the conference terminal on the receiving side plays the conference content in real time, the watermark information (user information and / or device information) is encrypted using the symmetric key K to generate a specific watermark embedded in the digital media, and finally obtain the digital media information with the watermark. Afterwards, the watermark detection algorithm can be used to extract the watermark information, and then the symmetric key K is used to decrypt the watermark to obtain the specific information contained in the watermark, thereby realizing information traceability. It can be seen that after the watermark information is encrypted using the key, the watermark information containing user information and / or device information becomes ciphertext and is no longer presented in plain text, which protects the user's privacy and prevents malicious forgery and framing by unauthorized users (users without symmetric keys).

[0065] However, the use of a symmetric encryption algorithm requires that each legitimate user terminal store the same symmetric key, making key leaks more likely. For example, in a video conferencing scenario, multiple conference terminals could store the same key to encrypt their own watermark information and embed it into the audio and video streams. This allows conference administrators to use this key to trace leaked content and identify the internal leaker. Furthermore, because multiple users use the same key to encrypt watermark information, anyone holding the symmetric key can encrypt and decrypt it, creating the risk of malicious insiders forging watermarks to frame others.

[0066] Based on the above analysis of related technologies, it can be seen that although the visible watermark technology for video conferencing is simple and intuitive, it has the risk of easy erasure and malicious forgery and framing; although the watermark algorithm combined with symmetric encryption improves the security of the watermark, it still has the problem of malicious forgery and framing by insiders. Based on this, the present application provides a technical solution, which uses a key generated based on the identity private key held by the terminal and the authentication public key provided by the authentication party to generate a watermark. On the one hand, by binding the identity private key held by the terminal to the watermark information, only the terminal holding the identity private key can generate its own watermark and embed it into the media data. Since the private key is usually not released from the device, the risk of leakage is low, so it can basically prevent other terminal users from forging watermarks. On the other hand, it limits the ability of only the authentication party to recover the key for verifying the watermark information, and by limiting the traceability authority of the media data, the privacy protection of the terminal user is achieved. Among them, the authentication party is the management party or trusted institution trusted by the terminal.

[0067] The media data playback scheme provided by this application is specifically as follows: the terminal generates a digital watermark based on the authentication attribute information of the media data to be played. The digital watermark includes the authentication attribute information and the signature information obtained by signing the authentication attribute information using the target key. After the terminal embeds the digital watermark in the media data, it plays the media data embedded with the digital watermark. The authentication attribute information of the media data is used to identify the playback source range of the media data. The target key is obtained based on the identity private key held by the terminal and the authentication public key provided by the authentication party. Since the generation of the target key is combined with the authentication public key provided by the authentication party, it is equivalent to limiting the authentication party holding the authentication private key corresponding to the authentication public key to have the traceability authority for the media data. This application carries the authentication attribute information of the media data in the digital watermark and the signature information obtained by signing the authentication attribute information using the target key. The authentication attribute information in the digital watermark can declare the playback source range of the media data, play the role of identity information of the media data, and thus narrow the traceability scope of the media data. The signature information in the digital watermark is used to ensure the authenticity of the authentication attribute information of the media data, that is, to ensure the authenticity of the media data. Because the target key is derived from the terminal's private key and the authentication public key provided by the authenticator, as long as the terminal's private key remains intact, other user terminals cannot calculate the target key. Consequently, they cannot use the target key to calculate the signature information and forge the watermark. This prevents malicious imitation of the watermark to leak media data and frame others. Furthermore, this application uses signature information to verify the playback source of the media data, rather than directly including user or device identity information in the digital watermark, thus also preventing the leakage of user or device identity information.

[0068] Since the key used by the terminal to generate the digital watermark is calculated based on the identity private key held by the terminal and the authentication public key provided by the authentication party, accordingly, the authentication party can calculate the key for verifying the digital watermark generated by the terminal based on the authentication private key held by the authentication party and the identity public key held by the terminal. Therefore, the authentication party has the ability to trace the source of the media data embedded with the digital watermark played by the terminal. In this way, when the copyright information of the media data is questioned, or when the media data is leaked and the source of the leak needs to be located, the media data can be traced and evidence collected through the authentication party. The media data traceability scheme provided in this application is as follows: the authentication party obtains the digital watermark in the media data to be traced, and the digital watermark includes the authentication attribute information of the media data and the signature information obtained based on the authentication attribute information. The authentication attribute information is used to identify the playback source range of the media data. The authentication party determines the playback source range of the media data based on the authentication attribute information, and then generates a key based on the authentication private key held by the authentication party and the identity public key held by the terminal within the playback source range. The signature information in the digital watermark is further verified based on the key and the authentication attribute information to determine whether the media data comes from the terminal. In this application, since only the authenticator who provides the authentication public key to the terminal can calculate the key for verifying the digital watermark generated by the terminal, only the authenticator has the authority to trace the source of the media data. Even if other terminal users extract the digital watermark from the media data, they cannot trace it back to the playback source of the media data. This can protect the user privacy of the playback source and reduce the risk of leakage of the playback source information.

[0069] The first possible implementation method is that the present application scheme is implemented based on a watermark algorithm combined with symmetric encryption. In this implementation method, the target key generated by the terminal based on the identity private key held by the terminal and the authentication public key provided by the authentication party is a symmetric key. The terminal uses the target key to sign the authentication attribute information of the media data based on the symmetric signature algorithm to obtain a symmetric signature value, and the signature information in the digital watermark includes part or all of the content of the symmetric signature value. Correspondingly, the authentication party uses the authentication private key held by the authentication party and the identity public key held by the terminal to generate a key identical to the target key, and uses the key to sign the authentication attribute information in the digital watermark based on the symmetric signature algorithm to obtain a symmetric signature value. If the signature information in the digital watermark embedded in the media data matches the symmetric signature value calculated by the authentication party, the authentication party determines that the media data comes from the terminal holding the identity public key used to generate the key.

[0070] Under this implementation method, only the authenticator and the terminal can calculate the same symmetric key. As long as the identity private key held by the terminal and the authentication private key held by the authenticator are not leaked, any third party other than the terminal and the authenticator cannot calculate the target key, and thus cannot use the target key to calculate the signature information to forge the watermark. Therefore, it can prevent others from maliciously counterfeiting the watermark to leak media data and frame others.

[0071] Optionally, in the first possible implementation described above, the authentication public key held by the authenticator is jointly provided by multiple approvers, and this authentication public key is a DKG public key. The multiple approvers jointly hold n private key shards, and the number of private key shards held by each approver is less than t. The DKG public key is calculated based on these n private key shards, and the private key corresponding to the DKG public key is obtained based on at least t of the n private key shards. Here, n is an integer greater than 1, and 2≤t≤n.

[0072] Among them, the DKG public key is a common public key calculated by multiple parties based on n private key shards. The private key corresponding to the DKG public key (referred to as the DKG private key) is a secure aggregation of the n private key shards. The generation process of the DKG public key is essentially secret sharing. This application sets the recovery threshold of the DKG private key to t, that is, any private key shard greater than or equal to t among the n private key shards can recover the DKG private key. The recovery threshold t of the DKG private key can be adjusted according to actual needs to improve reliable and available resilience. In order for the authenticator to obtain the authentication private key, it needs at least t private key shards. Since the number of private key shards held by each approver is less than t, the authenticator can only recover the authentication private key with the consent of two or more approvers. In other words, the authenticator needs to rely on multiple approvers to recover the private key corresponding to the authentication public key, and further combine the identity public key held by the terminal to calculate the same key as the target key used by the terminal to generate the digital watermark. Compared with the scheme in which the authenticator directly holds the authentication private key, this scheme reduces the risk of the authenticator maliciously counterfeiting the watermark to frame the terminal user because the authenticator is supervised by multiple approvers, thereby improving the reliability of the authenticator and the security of the watermark, and further improving the reliability of the watermark traceability.

[0073] Alternatively, in the first possible implementation manner described above, the authenticating party may also generate a public-private key pair including an authentication public key and an authentication private key.

[0074] The second possible implementation method is that the present application scheme is based on a watermark algorithm combined with asymmetric encryption. Under this implementation method, the target key generated by the terminal based on the identity private key held by the terminal and the authentication public key provided by the authentication party is an asymmetric key. The target key is, for example, the private key in a public-private key pair. The terminal uses the target key to sign the authentication attribute information of the media data based on the asymmetric signature algorithm to obtain an asymmetric signature value, and the signature information in the digital watermark is the asymmetric signature value. Correspondingly, the authentication party uses the authentication private key held by the authentication party and the identity public key held by the terminal to generate an asymmetric key corresponding to the target key. The asymmetric key is, for example, the public key corresponding to the target key. The authentication party then uses the generated key to perform signature verification on the authentication attribute information and signature information in the digital watermark. If the signature verification passes, the authentication party determines that the media data embedded with the digital watermark comes from the terminal holding the identity public key used to generate the key.

[0075] In this implementation, only the terminal can calculate the target key used to generate the digital watermark, preventing any third party, including the authenticator, from maliciously forging the watermark and leaking media data to frame the user. Furthermore, only the authenticator can calculate the key used to verify the digital watermark generated by the terminal. This means that only the authenticator has the authority to trace the source of the media data played by the terminal, effectively protecting the privacy of the terminal user.

[0076] The following is a detailed introduction to the technical solution of this application from multiple perspectives, including application scenarios, method flow, software devices, hardware devices, and systems.

[0077] The following is an example of an application scenario of the embodiment of the present application.

[0078] The embodiments of the present application can be applied to various scenarios involving the playback and traceability of media data, and can achieve copyright protection for media data. Optionally, the media data includes but is not limited to audio data, video data, file data, and other digital streaming media data, such as remote shared desktops, remote shared documents, and remote shared applications.

[0079] For example, Figure 5 is a schematic diagram of an application scenario provided by an embodiment of the present application. As shown in Figure 5, the application scenario includes an authenticator and one or more terminals. The terminals are connected to the authenticator via a wired or wireless network. Figure 5 uses an application scenario including three terminals (terminal A, terminal B, and terminal C) as an example. The number of terminals does not limit the application scenario of this application.

[0080] Optionally, the terminal can be a user terminal such as a mobile phone, tablet, or computer. Terminals can transmit media data to each other and play media data received from other terminals locally. For example, referring to Figure 5, terminal A sends media data M to terminals B and C, respectively. Terminals A, B, and C then play media data M. If media data M is leaked, it could be leaked during playback by terminal A, terminal B, or terminal C.

[0081] The authenticator is a management party or a trusted institution trusted by the terminal. The authenticator can be a user terminal, a server, or a cloud computing platform. The authenticator is used to provide the terminal with an authentication public key so that the terminal can generate a corresponding key based on its own identity private key. The generated key is further used to generate a digital watermark unique to the terminal to be embedded in the media data for playback. For example, referring to Figure 5, the media data M played by terminal A is embedded with a digital watermark A. The digital watermark A is bound to the identity private key SKa held by terminal A and the authentication public key PKm provided by the authenticator. The media data M played by terminal B is embedded with a digital watermark B. The digital watermark B is bound to the identity private key SKb held by terminal B and the authentication public key PKm provided by the authenticator. The media data M played by terminal C is embedded with a digital watermark C. The digital watermark C is bound to the identity private key SKc held by terminal C and the authentication public key PKm provided by the authenticator. Afterwards, the authenticator can trace the leaked media data M to determine whether the leak source is terminal A, terminal B, or terminal C. For example, the authenticator uses the authentication private key SKm and the identity public key PKa held by terminal A to generate the key KEYa, uses the authentication private key SKm and the identity public key PKb held by terminal B to generate the key KEYb, and uses the authentication private key SKm and the identity public key PKc held by terminal C to generate the key KEYc. Then, the keys KEYa, KEYb, and KEYc are used respectively to verify the digital watermark in the leaked media data M to determine whether the digital watermark is the digital watermark A generated by terminal A, the digital watermark B generated by terminal B, or the digital watermark C generated by terminal C, thereby determining the source of the leakage of the media data M.

[0082] Optionally, the application scenario shown in FIG5 is a video conferencing scenario, in which the terminal is a conference terminal. The authenticating party is the conference manager, such as the conference terminal used by the conference manager. Typically, a video conference can include multiple participants, with each participant joining the video conference through a conference terminal. A conference terminal can be a dedicated physical device or a software program with conferencing capabilities. This software program can run on various computing devices, such as mobile phones, tablets, computers, and other user terminals. In this case, the computing device running the software program can also be considered a conference terminal. The conference terminal joins the video conference through a conference service platform. Specifically, the conference terminal can obtain media data for the video conference from the conference service platform and send the locally collected media data to the conference service platform, which then forwards it to other participating conference terminals. Conference terminals can be connected via a wireless network, allowing participants to join the video conference smoothly regardless of their geographical location. In some cases, a participant may only include one participating user, such as a participating user joining a video conference through a conference software program running on a personal mobile phone. In some cases, a participant may include multiple participants, such as in a conference room scenario, where multiple participants in the conference room join a video conference through a conference terminal in the conference room. The conference service platform may be a multipoint control unit (MCU).

[0083] In the embodiment of the present application, each terminal holds a public-private key pair representing its own identity, referred to as an identity public key and an identity private key. The public key and private key are a key pair obtained through an algorithm. If data is encrypted with a public key, it can be decrypted with a private key. If data is signed with a private key, the signature can be verified with a public key. The public key is the part of the key pair that is open to the communication peer, and the private key is the non-public part of the key pair. Under normal circumstances, the identity private key held by a terminal cannot be known to any third party, including other terminals and the authenticator.

[0084] In the embodiments of the present application, the identity public key and identity private key held by the terminal may refer to the device public key and device private key possessed by the terminal. For example, a dedicated conference terminal equipped in a conference room can be used by one or more users. The identity public key and identity private key held by the terminal may refer to the device public key and device private key possessed by the dedicated conference terminal itself. Alternatively, the identity public key and identity private key held by the terminal may refer to the user public key and user private key of the user logged into the terminal. For example, the terminal is a computer device running a conference application. The identity public key and identity private key held by the terminal may refer to the user public key and user private key of the user currently logged into the conference application. If the logged-in user is changed, the identity public key and identity private key held by the terminal will also change accordingly.

[0085] If the identity public key and identity private key held by the terminal are the device public key and device private key possessed by the terminal, then when the terminal wants to use the identity public key and identity private key, it can directly read the device public key and device private key from the local storage. If the identity public key and identity private key held by the terminal are the user public key and user private key of the user logged in to the terminal, then the terminal can obtain and store the user public key based on the information of the logged in user when the user logs in, and use the user private key to sign the user public key. The signature is used to prove that the logged in user holds the private key corresponding to the user public key. In some cases, there may be no logged-in user on the terminal. For example, the conference terminal in the conference room is public and does not require user login, but during the meeting, it may be bound to a participating user or user terminal (temporarily bound). In this case, the user public key and user private key of the user bound to the terminal or the device public key and device private key of the user terminal can also be used as the identity public key and identity private key held by the terminal. If the identity public key and identity private key held by the terminal are the user's user public key and user private key, or the device public key and device private key of the user terminal (such as the user's mobile phone, tablet computer, etc.), and the terminal and the user terminal are two different physical devices, then the terminal can obtain the user public key or the device public key of the user terminal through Bluetooth, near field communication (NFC), user input, etc.

[0086] In a video conferencing scenario, multiple conference terminals participating in the meeting can pre-send their public identity keys to the conference service platform for storage. The conference service platform can store the public identity keys held by each conference terminal at the conference granularity. Conferences can be identified by conference identifiers and / or conference timestamp information. For example, the conference identifier can be the conference number, and the conference timestamp information can include the start and end times of the meeting. This allows the conference manager to obtain the public identity keys held by each of the multiple conference terminals participating in a given meeting from the conference service platform.

[0087] The following is an example of the method flow of the embodiment of the present application.

[0088] For example, Figure 6 is a flowchart of a method for playing media data provided by an embodiment of the present application. As shown in Figure 6, method 600 includes but is not limited to the following steps 601 to 604. This method 600 can be applied to any terminal in the application scenario shown in Figure 5.

[0089] Step 601: The terminal obtains authentication attribute information of the media data to be played, where the authentication attribute information is used to identify the playback source range of the media data.

[0090] Optionally, the authentication attribute information of the media data can indirectly identify the playback source range of the media data, for example, the authentication attribute information of the media data includes the context information of the media data, and the context information can reflect the possible sources of the media data, such as from a conference or from a website, etc., and further, the terminal that may play the media data can be determined based on the context information. Alternatively, the authentication attribute information of the media data can also directly identify the playback source range of the media data, for example, the authentication attribute information of the media data includes the device identification of the terminal that may play the media data, etc. For example, in the application scenario shown in Figure 5, the authentication attribute information of the media data M may include the device identification of terminal A, the device identification of terminal B, and the device identification of terminal C, which is used to indicate that the playback source range of the media data M includes terminal A, terminal B, and terminal C. In the embodiment of the present application, the authentication attribute information of the media data is used as an auxiliary index to narrow the traceability range of the media data, and the specific content of the authentication attribute information is not limited.

[0091] Optionally, embodiments of the present application can be applied to video conferencing scenarios. The terminal is a conference terminal participating in a conference, and the media data to be played on the terminal originates from the conference. The authentication attribute information of the media data may include the conference identifier and / or conference timestamp information of the conference, indicating that the playback source range of the media data includes all conference terminals participating in the conference terminal.

[0092] Optionally, the terminal obtains the media data to be played, which may be that the terminal receives media data sent by other conference terminals participating in the conference, or the terminal generates the media data to be played.

[0093] Step 602: The terminal generates a digital watermark based on the authentication attribute information. The digital watermark includes the authentication attribute information and signature information obtained by signing the authentication attribute information using a target key. The target key is obtained based on the identity private key held by the terminal and the authentication public key provided by the authenticator.

[0094] Only the authenticator has the authority to trace the source of the media data. Optionally, the terminal may obtain the authentication public key provided by the authenticator by sending a key acquisition request to the authenticator, where the key acquisition request includes the terminal's device identifier. The terminal then receives a key acquisition response from the authenticator, where the key acquisition response includes the authentication public key provided by the authenticator. Optionally, the key acquisition request may also include the terminal's identity public key.

[0095] Alternatively, let m be the authentication attribute information of the media data, and k be the target key derived from the private key held by the terminal and the public key provided by the authenticator. Then, the digital watermark W generated by the terminal can be expressed as: W = m||sign(k,m). The symbol || represents string concatenation. sign(k,m) represents the signature information obtained by signing m with k.

[0096] Step 603: The terminal embeds the digital watermark into the media data to be played.

[0097] Optionally, if the media data is audio data, watermark information can be embedded into the audio data using audio watermarking technology. For example, the watermark information can be embedded into different parameters of the audio signal, such as the time domain, frequency domain, phase, and amplitude, to ensure that the quality and audibility of the audio signal are not affected. Alternatively, if the media data is video data, the digital watermark can be embedded into the video data in the form of an invisible watermark. Compared to visible watermarks, invisible watermarks are more difficult for attackers to remove through technical means. Therefore, embedding the digital watermark into the video data in the form of an invisible watermark can reduce the risk of digital watermark removal, thereby improving the reliability of media data traceability.

[0098] Step 604: The terminal plays the media data embedded with the digital watermark.

[0099] In the embodiment of the present application, by carrying the authentication attribute information of the media data in the digital watermark and using the target key to sign the authentication attribute information to obtain the signature information, the authentication attribute information in the digital watermark can declare the playback source range of the media data, play the role of the identity information of the media data, and thus narrow the traceability range of the media data. The signature information in the digital watermark is used to ensure the authenticity of the authentication attribute information of the media data, that is, to ensure the authenticity of the media data. Since the target key is obtained based on the identity private key held by the terminal and the authentication public key provided by the authentication party, as long as the identity private key held by the terminal is not leaked, other user terminals cannot calculate the target key, and thus cannot use the target key to calculate the signature information to forge the watermark, thereby preventing others from maliciously counterfeiting the watermark to leak media data for framing. In addition, in the embodiment of the present application, the playback source of the media data is proved by signature information, rather than directly carrying the user or device identity information in the digital watermark, so the leakage of user or device identity information can also be avoided.

[0100] Furthermore, when the copyright information of media data is questioned, or when the media data is leaked and the source of the leak needs to be located, the media data can be traced and evidence collected through the authentication party. For example, Figure 7 is a flow chart of a method for tracing the source of media data provided in an embodiment of the present application. As shown in Figure 7, method 700 includes but is not limited to the following steps 701 to 704. This method 700 can be applied to the authentication party in the application scenario shown in Figure 5.

[0101] Step 701: The authenticator obtains a digital watermark in the media data to be traced. The digital watermark includes authentication attribute information of the media data and signature information obtained based on the authentication attribute information. The authentication attribute information is used to identify the playback source range of the media data.

[0102] The interpretation of the authentication attribute information of the media data may refer to the above step 601, which will not be described in detail in this embodiment of the present application.

[0103] Step 702: The authenticator determines the playback source range of the media data based on the authentication attribute information.

[0104] Optionally, the authentication attribute information includes a conference identifier and / or conference timestamp information. Accordingly, the authenticator determines the conference from which the media data originates based on the authentication attribute information, and then determines that the playback source range of the media data includes conference terminals participating in the conference.

[0105] Step 703: The authenticator generates a first key according to the authentication private key held by the authenticator and the first identity public key held by the first terminal, where the first terminal is any terminal within the range of the playback source.

[0106] Optionally, after receiving the key acquisition request sent by the terminal, the authenticator may also send a key acquisition response to the terminal, where the key acquisition response includes the authentication public key. The authentication private key held by the authenticator and the authentication public key provided by the authenticator to the terminal form a public-private key pair.

[0107] Step 704: The authenticator verifies the signature information in the digital watermark based on the first key and the authentication attribute information in the digital watermark to determine whether the media data comes from the first terminal.

[0108] Optionally, in the case where the playback source range of the media data includes multiple terminals, if the authenticator determines that the media data does not come from the first terminal, the authenticator may also generate a second key based on the authentication private key held by the authenticator and the second identity public key held by the second terminal, where the second terminal is any terminal other than the first terminal within the playback source range. The authenticator then verifies the signature information in the digital watermark based on the second key and the authentication attribute information in the digital watermark to determine whether the media data comes from the second terminal. In other words, the authenticator can traverse and verify all terminals within the playback source range of the media data until the terminal from which the media data comes is determined. Among them, for each terminal within the playback source range of the media data, the implementation method of the authenticator verifying whether the media data comes from the terminal can be uniformly referred to the implementation method of verifying whether the media data comes from the first terminal described in the embodiment of the present application.

[0109] In the embodiment of the present application, since only the authenticator who provides the authentication public key to the terminal can calculate the key for verifying the digital watermark generated by the terminal, only the authenticator has the authority to trace the source of the media data. Even if other terminal users extract the digital watermark from the media data, they cannot trace it back to the playback source of the media data. This can protect the user privacy of the playback source and reduce the risk of leakage of the playback source information.

[0110] Optionally, the solution of the present application may be implemented based on a watermark algorithm combined with symmetric encryption, or may be implemented based on a watermark algorithm combined with asymmetric encryption, which are respectively described in the following two possible implementations.

[0111] In a first possible implementation, the present invention is based on a watermarking algorithm combined with symmetric encryption. In step 602, the terminal uses a key agreement algorithm to generate a target key using the terminal's private key and the authentication public key provided by the authenticator. Accordingly, the terminal uses the target key to sign the authentication attribute information of the media data using a symmetric signature algorithm to obtain a symmetric signature value. The signature information in the digital watermark can be this symmetric signature value, or it can be a truncated result of this symmetric signature value.

[0112] Accordingly, in step 703, the authenticator uses a key agreement algorithm to generate a first key using the authentication private key held by the authenticator and the first identity public key held by the first terminal. In step 704, the authenticator uses the first key to sign the authentication attribute information in the digital watermark using a symmetric signature algorithm to obtain a symmetric signature value. If the signature information in the digital watermark matches the symmetric signature value, the authenticator determines that the media data embedded with the digital watermark originated from the first terminal.

[0113] Here, the authenticator and the terminal each use the same key agreement algorithm to generate the same key using their own private key and the public key provided by the other party. The key agreement (KA) algorithm can be the Diffie-Hellman (DH) algorithm. For example, if the terminal holds the identity public key PKu, the terminal holds the identity private key SKu, the authenticator holds the authentication public key PKw, and the authenticator holds the authentication private key SKw. The key generated by the terminal using the DH algorithm for SKu and PKw can be expressed as DH(SKu,PKw), and the key generated by the authenticator using the DH algorithm for SKw and PKu can be expressed as DH(SKw,PKu). DH(SKu,PKw) is the same as DH(SKw,PKu).

[0114] Optionally, the terminal uses the target key to sign the authentication attribute information of the media data based on a symmetric signature algorithm to obtain a symmetric signature value. The terminal may first calculate a hash value of the authentication attribute information, and then use the target key to sign the hash value based on the symmetric signature algorithm to obtain the symmetric signature value. The symmetric signature algorithm used by the terminal may be, for example, an Advanced Encryption Standard (AES) cypher-based message authentication code (CMAC) (abbreviated as: AES-CMAC) algorithm, and the symmetric signature value may be an AES-CMAC value with a length of at least 128 bits. Correspondingly, the authenticator uses the first key to sign the authentication attribute information in the digital watermark based on a symmetric signature algorithm to obtain a symmetric signature value. The authenticator may first calculate a hash value of the authentication attribute information, and then use the first key to sign the hash value based on the symmetric signature algorithm to obtain the symmetric signature value. The symmetric signature algorithm used by the authenticator is the same as the symmetric signature algorithm used by the terminal.

[0115] Optionally, the signature information in the digital watermark generated by the terminal is a symmetric signature value obtained by signing the authentication attribute information of the media data using the target key using a symmetric signature algorithm. Accordingly, in step 704, if the signature information in the digital watermark embedded in the media data is identical to the symmetric signature value obtained by signing the authentication attribute information in the digital watermark using the first key using a symmetric signature algorithm, the authenticator determines that the media data originated from the first terminal.

[0116] Alternatively, the signature information in the digital watermark generated by the terminal is a truncated value of a symmetric signature value obtained by signing the authentication attribute information of the media data using the target key using a symmetric signature algorithm. Accordingly, in step 704, if the signature information in the digital watermark embedded in the media data is identical to the truncated value of the symmetric signature value obtained by signing the authentication attribute information in the digital watermark using the first key using a symmetric signature algorithm, the authenticator determines that the media data originated from the first terminal.

[0117] Because some media data is limited by the watermark payload capacity and is insufficient to carry the full signature length, for example, for audio data, if too much watermark information is embedded, it will affect the fidelity and robustness of the audio data. Symmetrical signature values ​​are usually smaller than asymmetric signature values, so this type of media data is suitable for using a symmetric signature scheme to shorten the signature length. However, even the length of the symmetric signature value may exceed the watermark payload capacity limit. For example, the audio watermark payload on the market is generally within 8 bytes. Therefore, in order to carry authentication attribute information and signatures, the symmetric signature value needs to be truncated (truncate) and then the truncated result value needs to be embedded (because the symmetric signature is reversible, it can be truncated without affecting the verification signature. However, the asymmetric signature must rely on the full signature value for signature verification). For specific reference, see Section 2.4 of the Message Authentication Code (MAC) Generation Algorithm in the Request for Comments (RFC) document numbered 4493 (IETF RFC4493) developed by the Internet Engineering Task Force (IETF): "The MAC can be truncated. According to [NIST-CMAC], at least a 64-bit MAC should be used as protection against guessing attacks. In most cases, the truncation result should be significant bit first." This implementation method truncates the symmetric signature value and embeds the truncated result value as watermark information into the audio data, which can reduce the watermark embedding capacity, thereby ensuring the fidelity and robustness of the audio data after the watermark information is embedded. For video data, either the symmetric signature value or the truncated result value of the symmetric signature value can be embedded as the watermark information into the video data.

[0118] Under the first possible implementation method mentioned above, only the authenticator and the terminal can calculate the same symmetric key. As long as the identity private key held by the terminal and the authentication private key held by the authenticator are not leaked, any third party other than the terminal and the authenticator cannot calculate the target key, and thus cannot use the target key to calculate the signature information to forge the watermark. Therefore, it can prevent others from maliciously counterfeiting the watermark to leak media data and frame others.

[0119] Optionally, in the first possible implementation method mentioned above, the authentication public key held by the authentication party is jointly provided by multiple approval parties, and the authentication public key is a DKG public key. The multiple approval parties jointly hold n private key shards and the number of private key shards held by each approval party is less than t. The DKG public key is calculated based on the n private key shards, and the private key corresponding to the DKG public key is obtained based on at least t private key shards among the n private key shards. Wherein, n is an integer greater than 1, and 2≤t≤n. In this implementation method, the authentication party needs to rely on multiple approval parties to recover the authentication private key, and further calculate the key that is the same as the target key used by the terminal to generate the digital watermark in combination with the identity public key held by the terminal. Compared with the solution in which the authentication party directly holds the authentication private key, this solution can reduce the risk of the authentication party maliciously counterfeiting the watermark to frame the terminal user because the authentication party is supervised by multiple approval parties, thereby improving the reliability of the authentication party and the security of the watermark, and further improving the reliability of the watermark traceability.

[0120] In a second possible implementation, the present application scheme is based on a watermark algorithm combined with asymmetric encryption. In step 602, the terminal uses an asymmetric key generation algorithm to generate a target key based on the terminal's private identity key and the authentication public key provided by the authentication party. The target key is an asymmetric key, such as the private key in a public-private key pair. Accordingly, the terminal uses the target key to sign the authentication attribute information of the media data using an asymmetric signature algorithm to obtain an asymmetric signature value. The signature information in the digital watermark is this asymmetric signature value.

[0121] Accordingly, in step 703, the authenticator uses an asymmetric key generation algorithm to generate a first key using the authentication private key held by the authenticator and the first identity public key held by the first terminal. In step 704, the authenticator uses the first key to perform signature verification on the authentication attribute information and signature information in the digital watermark. If the signature verification succeeds, the authenticator determines that the media data embedded with the digital watermark originated from the first terminal.

[0122] Optionally, the terminal uses an asymmetric key generation algorithm to generate a target key based on the identity private key held by the terminal and the authentication public key provided by the authenticator. The terminal uses a key derivation function (KDF) to generate a derived key based on the identity private key held by the terminal and the authentication public key provided by the authenticator, and generates the target key based on the derived key and the identity private key held by the terminal. Correspondingly, the authenticator uses an asymmetric key generation algorithm to generate a first key based on the authentication private key held by the authenticator and the first identity public key held by the first terminal. The authenticator uses a key derivation function to generate a derived key based on the authentication private key held by the authenticator and the first identity public key held by the first terminal, and generates the first key based on the derived key and the authentication private key held by the authenticator. Here, the asymmetric key generation algorithm used by the terminal and the asymmetric key generation algorithm used by the authenticator are matching algorithms for generating a public-private key pair. For example, the terminal uses an asymmetric key generation algorithm to generate the private key in the public-private key pair, and the authenticator uses a matching asymmetric key generation algorithm to generate the public key in the public-private key pair.

[0123] In this implementation, the authenticator and the terminal can each generate a public-private key pair based on their own private key and the public key provided by the other party. For example, the terminal's identity public key is PKu, the terminal's identity private key is SKu, the authenticator's authentication public key is PKw, and the authenticator's authentication private key is SKw. The key generated by the terminal based on SKu and PKw can be the private key SK, where SK = (KDF(SKu,PKw)+SKu) mod q, where KDF(SKu,PKw) is the derived key generated by the terminal using a key derivation function on SKu and PKw. q is a prime number, and mod q represents the modulo of q. SK has a value range of [1,q]. The key generated by the authenticator based on SKw and SKu can be the public key PK, where PK = gKDF(SKw,PKu)·PKu, where KDF(SKw,PKu) is the derived key generated by the authenticator using a key derivation function on SKw and PKu, and g is the primitive root of the prime number q. KDF(SKu,PKw) is the same as KDF(SKw,PKu), for example, K=KDF(SKu,PKw)=KDF(SKw,PKu).

[0124] The following example illustrates the algorithm flow in which a terminal generates a signature private key based on the identity private key held by the terminal and the authentication public key provided by the authentication party, and the authentication party generates a signature public key corresponding to the signature private key based on the authentication private key held by the authentication party and the identity public key held by the terminal.

[0125] In the first step, the terminal and the authenticator preset public parameters g, q and KDF, where q is a prime number and g is the primitive root of q.

[0126] The second step is to generate a public-private key pair at the terminal, including the private key SKu and the public key PKu, where PKu = g SKu The authenticator generates an authentication public-private key pair, including an authentication private key SKw and an authentication public key PKw, where PKw = g SKw .

[0127] The third step is to generate the signature private key SK according to SKu and PKw: SK = (ck + SKu) mod q, ck = KDF (PKw SKu ) The authenticator generates the signature public key PK based on SKw and PKu: PK = g ck’ PKu,ck'=KDF(PKu SKw ).

[0128] Since PKu=g SKu , PKw=g SKw , so PKw SKu =g SKwSKu =g SKuSKw =PKu SKw ; Correspondingly, ck and ck' derived using the same key derivation function KDF are also the same. Thus, it can be verified that: g SK =g (ck+SKu) =g ck ·g SKu =g ck’ PKu=PK, that is, the signature private key SK generated by the terminal and the signature public key PK generated by the authenticator form a public-private key pair.

[0129] Optionally, the asymmetric signature algorithm may be, for example, an elliptic curve digital signature algorithm (ECDSA). The terminal uses the target key to sign the authentication attribute information of the media data based on the asymmetric signature algorithm to obtain an asymmetric signature value. The terminal may first run a hash algorithm on the authentication attribute information to obtain a data hash value, and then use the target key to sign the fixed-length hash value to obtain an asymmetric signature value, which may be, for example, an ECDSA signature. Correspondingly, the authenticator first runs a hash algorithm on the authentication attribute information in the digital watermark to obtain a data hash value, and then uses the first key to perform signature verification on the calculated data hash value and the signature information in the digital watermark. If the signature verification passes, the authenticator determines that the media data embedded with the digital watermark comes from the first terminal. The hash algorithm used by the authenticator for the authentication attribute information is the same as the hash algorithm used by the terminal for the authentication attribute information.

[0130] In the second possible implementation, only the terminal can calculate the target key used to generate the digital watermark, preventing any third party, including the authenticator, from maliciously forging the watermark and leaking media data to frame the user. Furthermore, only the authenticator can calculate the key used to verify the digital watermark generated by the terminal. This means that only the authenticator has the authority to trace the source of the media data played by the terminal, effectively protecting the privacy of the terminal user.

[0131] The embodiments of the present application can be applied to copyright authentication scenarios or leakage location scenarios of media data.

[0132] In the copyright authentication scenario of media data, the authenticator determines whether the media data comes from a terminal, that is, determines whether the ownership of the media data belongs to the terminal or the user of the terminal. For example, Figure 8 is a schematic diagram of a copyright authentication scenario for media data provided by an embodiment of the present application. As shown in Figure 8, user A is the owner of media data A. User A can generate key A based on the identity private key of user A and the authentication public key provided by the authenticator, and embed the signature information generated by key A into the media data A in the form of a digital watermark. If the ownership of media data A is questioned, for example, user B questions the ownership of media data A when watching the playback content of media data A, user B can provide a partial fragment of media data A to the authenticator, and the authenticator uses a watermark detection algorithm to extract the watermark information in media data A, and uses a key generated based on the authentication private key held by the authenticator and the identity public key of user A to verify the signature information in the watermark information, so that it can be determined that media data A is owned by user A.

[0133] In the leakage location scenario of media data, the authenticator determines whether the media data comes from a terminal, that is, determines whether the media data is leaked by the terminal or the user of the terminal. For example, Figure 9 is a schematic diagram of a leakage location scenario of media data provided by an embodiment of the present application. As shown in Figure 9, user A generates key A based on the identity private key of user A and the authentication public key provided by the authenticator, and embeds the signature information generated by key A into the media data A in the form of a digital watermark before playing. If media data A is leaked during playback, the leaked segment of media data A can be provided to the authenticator, and the authenticator uses a watermark detection algorithm to extract the watermark information in the leaked segment, and uses multiple keys to verify the signature information in the watermark information in a traversal manner, wherein each key is generated based on the authentication private key held by the authenticator and the identity public key of a possible leaking user, so that the leakage source of media data A can be determined to be user A.

[0134] The order of the steps of the above-mentioned media data playback method or source tracing method provided by the embodiment of the present application can be appropriately adjusted, and the steps can also be increased or decreased according to the circumstances. For example, the solution provided by the embodiment of the present application is mainly used to solve the problem of leakage or questioned ownership of media data when it is transmitted in the air channel. In actual applications, if the media data is leaked through other channels (such as being copied) or just want to prove that the user owns the copyright of the media data, the solution provided by the embodiment of the present application can also be used to embed a digital watermark in the media data and use the above-mentioned method 700 for source tracing. In this case, the above-mentioned step 604 may not be executed, that is, the terminal may not play the media data embedded with the digital watermark after embedding the digital watermark in the media data. Any technician familiar with this technical field can easily think of a change method within the technical scope disclosed in this application, and it should be covered within the scope of protection of this application.

[0135] The following is an example of the software device in the embodiment of the present application.

[0136] For example, Figure 10 is a schematic diagram of the structure of a media data playback device provided in an embodiment of the present application. The device is applied to a terminal. As shown in Figure 10, device 1000 includes but is not limited to an acquisition module 1001, a generation module 1002, and a watermark embedding module 1003. Optionally, device 1000 also includes a sending module 1004 and a receiving module 1005.

[0137] Acquisition module 1001 is used to obtain authentication attribute information of the media data to be played. This authentication attribute information is used to identify the playback source range of the media data. Generation module 1002 is used to generate a digital watermark based on the authentication attribute information. The digital watermark includes the authentication attribute information and signature information obtained by signing the authentication attribute information using a target key. The target key is based on the identity private key held by the terminal and the authentication public key provided by the authenticator. Only the authenticator has the right to trace the source of the media data. Watermark embedding module 1003 is used to embed the digital watermark in the media data and play the media data embedded with the digital watermark.

[0138] Optionally, generation module 1002 is used to: use a key agreement algorithm to generate a target key for the identity private key and the authentication public key; use the target key to sign the authentication attribute information based on a symmetric signature algorithm to obtain a symmetric signature value, the signature information is the symmetric signature value, or the signature information is a truncated result value of the symmetric signature value.

[0139] Optionally, the authentication public key is jointly provided by multiple approvers, the authentication public key is a DKG public key, multiple approvers jointly hold n private key shards and the number of private key shards held by each approver is less than t, the DKG public key is calculated based on the n private key shards, and the private key corresponding to the DKG public key is obtained based on at least t private key shards out of the n private key shards, where n is an integer greater than 1, and 2≤t≤n.

[0140] Optionally, the generation module 1002 is used to: use an asymmetric key generation algorithm to generate a target key for the identity private key and the authentication public key; use the target key to sign the authentication attribute information based on an asymmetric signature algorithm to obtain an asymmetric signature value, and the signature information is an asymmetric signature value.

[0141] Optionally, the generating module 1002 is specifically configured to: generate a derived key based on the identity private key and the authentication public key using a key derivation function; and generate a target key based on the derived key and the identity private key.

[0142] Optionally, the target key is SK, SK = (K + SKu) mod q, where SKu is the identity private key, K is the derived key, q is a prime number, mod q represents the modulus of q, and the value range of SK is [1, q).

[0143] Optionally, the sending module 1004 is configured to send a key acquisition request to the authenticator, the key acquisition request including the device identification of the terminal. The receiving module 1005 is configured to receive a key acquisition response sent by the authenticator, the key acquisition response including the authentication public key.

[0144] Optionally, the terminal is a conference terminal participating in a conference, the media data comes from the conference, and the authentication attribute information includes a conference identifier of the conference and / or conference timestamp information of the conference.

[0145] Optionally, the receiving module 1005 is configured to receive media data sent by other conference terminals participating in the conference.

[0146] For another example, Figure 11 is a schematic diagram of the structure of a media data traceability device provided in an embodiment of the present application. This device is used by an authenticator. As shown in Figure 11, device 1100 includes, but is not limited to, an acquisition module 1101, a determination module 1102, a generation module 1103, and a verification module 1104. Optionally, device 1100 also includes a receiving module 1105 and a sending module 1106.

[0147] The acquisition module 1101 is used to obtain the digital watermark in the media data to be traced. The digital watermark includes the authentication attribute information of the media data and the signature information obtained based on the authentication attribute information. The authentication attribute information is used to identify the playback source range of the media data. The determination module 1102 is used to determine the playback source range based on the authentication attribute information. The generation module 1103 is used to generate a first key based on the authentication private key held by the authentication party and the first identity public key held by the first terminal. The first terminal is any terminal within the playback source range. The verification module 1104 is used to verify the signature information based on the first key and the authentication attribute information to determine whether the media data comes from the first terminal.

[0148] Optionally, a generation module 1103 is configured to generate a first key using a key agreement algorithm based on the authentication private key and the first identity public key. A verification module 1104 is configured to use the first key to sign the authentication attribute information based on a symmetric signature algorithm to obtain a symmetric signature value, and if the signature information matches the symmetric signature value, determine that the media data originated from the first terminal.

[0149] Optionally, the authentication public key corresponding to the authentication private key is jointly provided by multiple approvers, the authentication public key is a DKG public key, multiple approvers jointly hold n private key shards and the number of private key shards held by each approver is less than t, the DKG public key is calculated based on the n private key shards, and the authentication private key is obtained based on at least t private key shards out of the n private key shards, where n is an integer greater than 1, and 2≤t≤n.

[0150] Optionally, the length of the signature information is smaller than the length of the symmetric signature value, and the verification module 1104 is configured to: if the signature information is identical to a truncated value of the symmetric signature value, determine that the media data comes from the first terminal.

[0151] Optionally, the generation module 1103 is configured to generate a first key based on the authentication private key and the first identity public key using an asymmetric key generation algorithm. The verification module 1104 is configured to perform signature verification on the authentication attribute information and the signature information using the first key, and if the signature verification passes, determine that the media data comes from the first terminal.

[0152] Optionally, the generating module 1103 is specifically configured to: generate a derived key based on the authentication private key and the first identity public key using a key derivation function; and generate a first key based on the derived key and the authentication private key.

[0153] Optionally, the first key is PK, PK=g K PKu, where PKu is the first identity public key, K is the derived key, and g is the primitive root of the prime number q.

[0154] Optionally, the receiving module 1105 is configured to receive a key acquisition request from a terminal within the playback source range, the key acquisition request including the terminal's device identification, and the sending module 1106 is configured to send a key acquisition response to the terminal, the key acquisition response including the authentication public key corresponding to the authentication private key.

[0155] Optionally, the playback source range includes multiple terminals. Generation module 1103 is further configured to, if it is determined that the media data does not originate from the first terminal, generate a second key based on the authentication private key and a second identity public key held by a second terminal, where the second terminal is any terminal within the playback source range other than the first terminal. Verification module 1104 is further configured to verify the signature information based on the second key and authentication attribute information to determine whether the media data originates from the second terminal.

[0156] Optionally, the authentication attribute information includes conference identification and / or conference timestamp information. The determination module 1102 is specifically configured to: determine the conference from which the media data originates based on the authentication attribute information; and determine that the playback source range includes conference terminals participating in the conference.

[0157] The following is an illustration of the hardware device of the embodiment of the present application.

[0158] For example, Figure 12 is a schematic diagram of the hardware structure of a computer device provided in an embodiment of the present application. The computer device can be a terminal or an authenticator in the above-mentioned embodiment. As shown in Figure 12, the computer device 1200 includes a processor 1201 and a memory 1202, and the memory 1201 and the memory 1202 are connected via a bus 1203. Figure 12 illustrates the processor 1201 and the memory 1202 as being independent of each other. Optionally, the processor 1201 and the memory 1202 are integrated together. Optionally, in conjunction with Figure 5, the computer device 1200 in Figure 12 can be the authenticator or any terminal shown in Figure 5.

[0159] Memory 1202 is used to store computer programs, including operating systems and program code. Memory 1202 is various types of storage media, such as read-only memory (ROM), random access memory (RAM), electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM), flash memory, optical storage, registers, optical disk storage, optical disc storage, magnetic disk, or other magnetic storage devices.

[0160] The processor 1201 is a general-purpose processor or a dedicated processor. The processor 1201 may be a single-core processor or a multi-core processor. The processor 1201 includes at least one circuit to execute the above-mentioned method 600 or method 700 provided in the embodiments of the present application.

[0161] Optionally, the computer device 1200 further includes a network interface 1204, which is connected to the processor 1201 and the memory 1202 via the bus 1203. The network interface 1204 enables the computer device 1200 to communicate with other devices. For example, the processor 1201 can interact with other devices via the network interface 1204, such as communicating with an MCU via the network interface 1204, and so on.

[0162] Optionally, computer device 1200 further includes an input / output (I / O) interface 1205, which is connected to processor 1201 and memory 1202 via bus 1203. Processor 1201 can receive input commands or data through I / O interface 1205. I / O interface 1205 is used to connect computer device 1200 to input devices, such as a keyboard and a mouse. Optionally, in some possible scenarios, the network interface 1204 and I / O interface 1205 are collectively referred to as a communication interface.

[0163] Optionally, the computer device 1200 further includes a display 1206, which is connected to the processor 1201 and the memory 1202 via the bus 1203. The display 1206 can be used to display intermediate results and / or final results generated by the processor 1201 executing the above method. In one possible implementation, the display 1206 is a touch screen display to provide a human-computer interaction interface.

[0164] The bus 1203 is any type of communication bus for interconnecting the internal components of the computer device 1200, such as a system bus. The embodiments of the present application illustrate the example of interconnecting the aforementioned components within the computer device 1200 via the bus 1203. Alternatively, the aforementioned components within the computer device 1200 may be communicatively connected to each other using other connection methods besides the bus 1203, such as interconnecting the aforementioned components within the computer device 1200 via a logical interface within the computer device 1200.

[0165] The above-mentioned devices can be provided on separate chips, or at least partially or entirely on the same chip. Whether to provide each device independently on different chips or to integrate them on one or more chips often depends on the product design requirements. The embodiments of this application do not limit the specific implementation of the above-mentioned devices.

[0166] The computer device 1200 shown in FIG12 is merely exemplary. During implementation, the computer device 1200 includes other components, which are not listed here. The computer device 1200 shown in FIG12 can play media data by executing all or part of the steps of the method 600 provided in the above embodiment. Alternatively, the computer device 1200 shown in FIG12 can trace the source of media data by executing all or part of the steps of the method 700 provided in the above embodiment.

[0167] The following is an example of the system in the embodiment of the present application.

[0168] An embodiment of the present application further provides a media data protection system, including: a terminal and an authenticator, wherein the terminal is configured to execute the above method 600, and the authenticator is configured to execute the above method 700.

[0169] Optionally, the system is a video conferencing system, the terminal is a conference terminal, and the authenticator is a conference manager.

[0170] An embodiment of the present application further provides a computer-readable storage medium having instructions stored thereon. When the instructions are executed by a processor, the above-mentioned method 600 or method 700 is implemented.

[0171] An embodiment of the present application further provides a computer program product, including a computer program, which implements the above-mentioned method 600 or method 700 when executed by a processor.

[0172] Those skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware, or by a program to instruct the relevant hardware, and the program may be stored in a computer-readable storage medium, which may be a read-only memory, a disk, or an optical disk, etc.

[0173] In the embodiments of the present application, the terms “first”, “second” and “third” are used for descriptive purposes only and should not be understood as indicating or implying relative importance.

[0174] In this application, the term "and / or" simply describes an association between related objects, indicating that three possible relationships exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this document generally indicates that the related objects are in an "or" relationship.

[0175] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.) and signals involved in this application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions.

[0176] The above description is merely an optional embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the concepts and principles of the present application shall be included in the scope of protection of the present application.

Claims

1. A method for playing media data, characterized in that, Applied to a terminal, the method includes: Obtaining authentication attribute information of media data to be played, where the authentication attribute information is used to identify the playback source range of the media data; Generating a digital watermark according to the authentication attribute information, where the digital watermark includes the authentication attribute information and signature information obtained by signing the authentication attribute information with a target key, and the target key is obtained based on the identity private key held by the terminal and the authentication public key provided by the authenticator, and only the authenticator has the right to trace the media data; Embedding the digital watermark in the media data and playing the media data embedded with the digital watermark.

2. The method according to claim 1, wherein The method further includes: Generating the target key for the identity private key and the authentication public key by using a key negotiation algorithm; The signing the authentication attribute information with the target key includes: Signing the authentication attribute information with the target key based on a symmetric signature algorithm to obtain a symmetric signature value, where the signature information is the symmetric signature value, or the signature information is a truncated result value of the symmetric signature value.

3. The method according to claim 2, wherein The authentication public key is jointly provided by multiple approvers, the authentication public key is a distributed key generation (DKG) public key, the multiple approvers jointly hold n private key shards and the number of private key shards held by each approver is less than t, the DKG public key is calculated based on the n private key shards, and the private key corresponding to the DKG public key is obtained based on at least t private key shards among the n private key shards, where n is an integer greater than 1 and 2≤t≤n.

4. The method according to claim 1, wherein The method further includes: Generating the target key for the identity private key and the authentication public key by using an asymmetric key generation algorithm; The signing the authentication attribute information with the target key includes: Signing the authentication attribute information with the target key based on an asymmetric signature algorithm to obtain an asymmetric signature value, where the signature information is the asymmetric signature value.

5. The method according to claim 4, wherein The generating the target key for the identity private key and the authentication public key by using the asymmetric key generation algorithm includes: Generating a derived key based on the identity private key and the authentication public key by using a key derivation function; Generating the target key according to the derived key and the identity private key.

6. The method according to claim 5, wherein The target key is SK, SK=(K + SKu) mod q, where SKu is the identity private key, K is the derived key, q is a prime number, mod q represents taking the modulus with respect to q, and the value range of SK is [1, q).

7. The method according to any one of claims 1 to 6, characterized in that, The method further includes: Sending a key acquisition request to the authenticator, where the key acquisition request includes the device identifier of the terminal; Receiving a key acquisition response sent by the authenticator, where the key acquisition response includes the authentication public key.

8. The method according to any one of claims 1 to 7, characterized in that, The terminal is a conference terminal participating in a conference, the media data comes from the conference, and the authentication attribute information includes the conference identifier of the conference and / or the conference timestamp information of the conference.

9. The method according to claim 8, wherein The method further includes: Receiving the media data sent by other conference terminals participating in the conference.

10. A method for tracing media data, characterized in that, Applied to an authenticator, the method includes: Obtain the digital watermark in the media data to be traced. The digital watermark includes the authentication attribute information of the media data and the signature information obtained based on the authentication attribute information. The authentication attribute information is used to identify the playback source range of the media data; Determine the playback source range according to the authentication attribute information; Generate a first key according to the authentication private key held by the authentication party and the first identity public key held by the first terminal, where the first terminal is any terminal within the playback source range; Verify the signature information based on the first key and the authentication attribute information to determine whether the media data comes from the first terminal.

11. The method according to claim 10, characterized in that, The step of generating a first key according to the authentication private key held by the authentication party and the first identity public key held by the first terminal includes: Use a key agreement algorithm to generate the first key for the authentication private key and the first identity public key; The step of verifying the signature information based on the first key and the authentication attribute information includes: Use the first key to sign the authentication attribute information based on a symmetric signature algorithm to obtain a symmetric signature value; If the signature information matches the symmetric signature value, determine that the media data comes from the first terminal.

12. The method according to claim 11, wherein The authentication public key corresponding to the authentication private key is jointly provided by multiple approvers. The authentication public key is a distributed key generation (DKG) public key. The multiple approvers jointly hold n private key shards and the number of private key shards held by each approver is less than t. The DKG public key is calculated based on the n private key shards, and the authentication private key is obtained based on at least t private key shards among the n private key shards, where n is an integer greater than 1 and 2 ≤ t ≤ n.

13. The method according to claim 11 or 12, characterized in that, The length of the signature information is less than the length of the symmetric signature value. The step of determining that the media data comes from the first terminal if the signature information matches the symmetric signature value includes: If the signature information is the same as the truncated result value of the symmetric signature value, determine that the media data comes from the first terminal.

14. The method according to claim 10, wherein The step of generating a first key according to the authentication private key held by the authentication party and the first identity public key held by the first terminal includes: Use an asymmetric key generation algorithm to generate the first key for the authentication private key and the first identity public key; The step of verifying the signature information based on the first key and the authentication attribute information includes: Use the first key to perform signature verification on the authentication attribute information and the signature information; If the signature verification passes, determine that the media data comes from the first terminal.

15. The method according to claim 14, characterized in that, The step of using an asymmetric key generation algorithm to generate the first key for the authentication private key and the first identity public key includes: Use a key derivation function to generate a derived key based on the authentication private key and the first identity public key; Generate the first key according to the derived key and the authentication private key.

16. The method according to claim 15, wherein The first key is PK, and PK = g K ·PKu, where PKu is the first identity public key, K is the derived key, and g is a primitive root of prime number q.

17. The method according to any one of claims 10 to 16, characterized in that, The method further includes: Receive a key acquisition request sent by a terminal within the playback source range. The key acquisition request includes the device identifier of the terminal; Send a key acquisition response to the terminal, where the key acquisition response includes the authentication public key corresponding to the authentication private key.

18. The method according to any one of claims 10 to 17, characterized in that, The playback source range includes multiple terminals, and the method further includes: If it is determined that the media data does not come from the first terminal, generate a second key according to the authentication private key and the second identity public key held by the second terminal, where the second terminal is any terminal other than the first terminal within the playback source range; Verify the signature information based on the second key and the authentication attribute information to determine whether the media data comes from the second terminal.

19. The method according to any one of claims 10 to 18, characterized in that, The authentication attribute information includes a meeting identifier and / or a meeting timestamp information. Determining the playback source range according to the authentication attribute information includes: Determine the meeting to which the media data belongs according to the authentication attribute information; Determine that the playback source range includes the meeting terminals participating in the meeting.

20. A playback device for media data, characterized in that, Applied to a terminal, the device includes: An acquisition module, configured to acquire authentication attribute information of media data to be played, where the authentication attribute information is used to identify the playback source range of the media data; A generation module, configured to generate a digital watermark according to the authentication attribute information, where the digital watermark includes the authentication attribute information and signature information obtained by signing the authentication attribute information with a target key, and the target key is obtained based on the identity private key held by the terminal and the authentication public key provided by the authenticator, and only the authenticator has the right to trace the media data; A watermark embedding module, configured to embed the digital watermark in the media data and play the media data embedded with the digital watermark.

21. The device according to claim 20, characterized in that, The generation module is configured to: Generate the target key for the identity private key and the authentication public key by using a key negotiation algorithm; Sign the authentication attribute information based on the symmetric signature algorithm by using the target key to obtain a symmetric signature value, where the signature information is the symmetric signature value, or the signature information is a truncated result value of the symmetric signature value.

22. The device according to claim 21, characterized in that, The authentication public key is jointly provided by multiple approvers, the authentication public key is a distributed key generation (DKG) public key, the multiple approvers jointly hold n private key shards and the number of private key shards held by each approver is less than t, the DKG public key is calculated based on the n private key shards, and the private key corresponding to the DKG public key is obtained based on at least t private key shards among the n private key shards, where n is an integer greater than 1, and 2≤t≤n.

23. The device according to claim 20, characterized in that, The generation module is configured to: Generate the target key for the identity private key and the authentication public key by using an asymmetric key generation algorithm; Sign the authentication attribute information based on the asymmetric signature algorithm by using the target key to obtain an asymmetric signature value, where the signature information is the asymmetric signature value.

24. The device according to claim 23, characterized in that, The generation module is configured to: Generate a derived key based on the identity private key and the authentication public key by using a key derivation function; Generate the target key according to the derived key and the identity private key.

25. The device according to claim 24, characterized in that, The target key is SK, SK = (K + SKu) mod q, where SKu is the identity private key, K is the derived key, q is a prime number, mod q represents taking the modulus of q, and the value range of SK is [1, q).

26. The device according to any one of claims 20 to 25, characterized in that The device further includes: A sending module, configured to send a key acquisition request to the authenticator, where the key acquisition request includes the device identifier of the terminal; A receiving module, configured to receive a key acquisition response sent by the authenticator, where the key acquisition response includes the authentication public key.

27. The device according to any one of claims 20 to 26, characterized in that, The terminal is a conference terminal participating in a conference, the media data comes from the conference, and the authentication attribute information includes the conference identifier of the conference and / or the conference timestamp information of the conference.

28. The device according to claim 27, characterized in that, The device further includes: A receiving module, configured to receive the media data sent by other conference terminals participating in the conference.

29. A traceability device for media data, characterized in that, Applied to an authenticator, the device includes: An acquisition module, configured to acquire a digital watermark in the media data to be traced, where the digital watermark includes the authentication attribute information of the media data and signature information obtained based on the authentication attribute information, and the authentication attribute information is used to identify the playback source range of the media data; A determination module, configured to determine the playback source range according to the authentication attribute information; A generation module, configured to generate a first key according to the authentication private key held by the authenticator and the first identity public key held by a first terminal, where the first terminal is any terminal within the playback source range; A verification module, configured to verify the signature information based on the first key and the authentication attribute information to determine whether the media data comes from the first terminal.

30. The device according to claim 29, wherein: The generation module is configured to generate the first key for the authentication private key and the first identity public key by using a key negotiation algorithm; The verification module is configured to sign the authentication attribute information based on the first key by using a symmetric signature algorithm to obtain a symmetric signature value, and if the signature information matches the symmetric signature value, determine that the media data comes from the first terminal.

31. The device according to claim 30, characterized in that, The authentication public key corresponding to the authentication private key is jointly provided by multiple approvers, the authentication public key is a distributed key generation DKG public key, the multiple approvers jointly hold n private key shards and the number of private key shards held by each approver is less than t, the DKG public key is calculated based on the n private key shards, and the authentication private key is obtained based on at least t private key shards among the n private key shards, where n is an integer greater than 1, and 2 ≤ t ≤ n.

32. The device according to claim 30 or 31, characterized in that, The length of the signature information is less than the length of the symmetric signature value, and the verification module is configured to: If the signature information is the same as the truncated result value of the symmetric signature value, determine that the media data comes from the first terminal.

33. The device according to claim 29, wherein: The generation module is configured to generate the first key for the authentication private key and the first identity public key by using an asymmetric key generation algorithm; The verification module is used to perform signature verification on the authentication attribute information and the signature information by using the first key. If the signature verification passes, it is determined that the media data comes from the first terminal.

34. The device according to claim 33, characterized in that, The generation module is used to: Generate a derived key based on the authentication private key and the first identity public key by using a key derivation function; Generate the first key according to the derived key and the authentication private key.

35. The device according to claim 34, characterized in that, The first key is PK, and PK = g K ·PKu, where PKu is the first identity public key, K is the derived key, and g is a primitive root of prime number q.

36. The device according to any one of claims 29 to 35, characterized in that, The device further includes: A receiving module, configured to receive a key acquisition request sent by a terminal within the playback source range, where the key acquisition request includes the device identifier of the terminal; A sending module, configured to send a key acquisition response to the terminal, where the key acquisition response includes the authentication public key corresponding to the authentication private key.

37. The device according to any one of claims 29 to 36, characterized in that, The playback source range includes multiple terminals; The generation module is further configured to, if it is determined that the media data does not come from the first terminal, generate a second key according to the authentication private key and the second identity public key held by a second terminal, where the second terminal is any terminal other than the first terminal within the playback source range; The verification module is further configured to verify the signature information based on the second key and the authentication attribute information to determine whether the media data comes from the second terminal.

38. The device according to any one of claims 29 to 37, characterized in that, The authentication attribute information includes a meeting identifier and / or meeting timestamp information. The determination module is used to: Determine the meeting to which the media data belongs according to the authentication attribute information; Determine that the playback source range includes the meeting terminals participating in the meeting.

39. A protection system for media data, characterized in that, Includes: A terminal and an authenticator, where the terminal is configured to execute the method according to any one of claims 1 to 9, and the authenticator is configured to execute the method according to any one of claims 10 to 19.

40. The system according to claim 39, wherein The system is a video conferencing system, the terminal is a meeting terminal, and the authenticator is a meeting management party.

41. A terminal, characterized in that, Includes: A processor and a memory; The memory is used to store a computer program, and the computer program includes program instructions; The processor is used to call the computer program to implement the method according to any one of claims 1 to 9.

42. A computer device, characterized in that, Includes: A processor and a memory; The memory is used to store a computer program, and the computer program includes program instructions; The processor is used to call the computer program to implement the method according to any one of claims 10 to 19.

43. A computer-readable storage medium, characterized in that, Instructions are stored on the computer-readable storage medium, and when the instructions are executed by a processor, the method according to any one of claims 1 to 19 is implemented.

44. A computer program product, characterized in that, Includes a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 19 is implemented.

Citation Information

Patent Citations

  • Media data playing method, tracing method, device and protection system

    CN120238710A

  • Network conference information processing method and device

    CN108289254A

  • Method and device for detecting media data

    CN114650275A

  • Video data processing method and device, electronic equipment and storage medium

    CN115767138A

  • Method and apparatus for watermarking of digital content, method for extracting information

    US20190294761A1

Cited By

  • Watermark-based universal multimedia interface protocol ownership detection method and device

    CN120930114A

  • Blockchain-based anonymous trusted voting method, apparatus and related device

    US20240273649A1