Dynamic data watermarking for leakage source detection
Abstract
In one example an apparatus comprises a memory and a processor to receive, in an edge node of a secure network, a first file, determine that the first file is addressed to a recipient outside the secure network, and in response to a determination that the first file is addressed to a destination outside the secure network, to generate a watermark that identifies a transmitter of the document, a recipient of the document, and comprises a digital signature of the first file, embed the watermark in the first file to generate a watermarked file, and pass the watermarked file to an input/output system for transmission out of the secure network. Other examples may be described.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 .- 21 . (canceled)
22 . An apparatus, comprising processing circuitry to:
receive, in a network element of a secure network, a first file; in response to a determination that the first file is addressed to a destination outside the secure network, to:
generate a watermark that identifies a transmitter of the document, a recipient of the document, and comprises a digital signature of the first file identifying one or more characteristics of the first file;
embed the watermark in the first file to generate a watermarked file; and
pass the watermarked file to an input/output system for transmission out of the secure network.
23 . The apparatus of claim 22 , the processing circuitry to:
encrypt the watermark.
24 . The apparatus of claim 22 , the processing circuitry to:
apply one or more steganographic techniques to conceal the watermark in the file.
25 . The apparatus of claim 24 , the processing circuitry to:
store the watermark in a memory in the secure network.
26 . The apparatus of claim 22 , wherein the watermark comprises at least one of:
a sender identifier; a sender account identifier; a sender timestamp; one or more source network settings; a recipient identifier; a recipient account identifier; a recipient timestamp; or one or more destination network settings.
27 . The apparatus of claim 24 , the processing circuitry to:
receive the watermarked file; extract the watermark from the watermark file; and decode the watermark.
28 . The apparatus of claim 27 , the processing circuitry to:
extract the sender identifier from the watermark.
29 . A non-transitory computer-readable medium comprising instructions which, when executed by a processor, configure the processor to:
receive, in a network element of a secure network, a first file; in response to a determination that the first file is addressed to a destination outside the secure network, to:
generate a watermark that identifies a transmitter of the document, a recipient of the document, and comprises a digital signature of the first file identifying one or more characteristics of the first file;
embed the watermark in the first file to generate a watermarked file; and
pass the watermarked file to an input/output system for transmission out of the secure network.
30 . The non-transitory computer-readable medium of claim 29 , further comprising instructions which, when executed by the processor, configure the processor to:
encrypt the watermark.
31 . The non-transitory computer-readable medium of claim 29 , further comprising instructions which, when executed by the processor, configure the processor to:
apply one or more steganographic techniques to conceal the watermark in the file.
32 . The non-transitory computer-readable medium of claim 31 , further comprising instructions which, when executed by the processor, configure the processor to:
store the watermark in a memory in the secure network.
33 . The non-transitory computer-readable medium of claim 29 , wherein the watermark comprises at least one of:
a sender identifier; a sender account identifier; a sender timestamp; one or more source network settings; a recipient identifier; a recipient account identifier; a recipient timestamp; or one or more destination network settings.
34 . The non-transitory computer-readable medium of claim 29 , further comprising instructions which, when executed by the processor, configure the processor to:
receive the watermarked file; extract the watermark from the watermark file; and decode the watermark.
35 . The non-transitory computer-readable medium of claim 34 , further comprising instructions which, when executed by the processor, configure the processor to:
extract the sender identifier from the watermark.
36 . A computer-implemented method, comprising:
receiving, in a network element of a secure network, a first file; in response to a determination that the first file is addressed to a destination outside the secure network, to:
generating a watermark that identifies a transmitter of the document, a recipient of the document, and comprises a digital signature of the first file identifying one or more characteristics of the first file;
embedding the watermark in the first file to generate a watermarked file; and
passing the watermarked file to an input/output system for transmission out of the secure network.
37 . The computer-implemented method of claim 36 , further comprising:
encrypting the watermark.
38 . The computer-implemented method of claim 36 , further comprising:
applying one or more steganographic techniques to conceal the watermark in the file.
39 . The computer-implemented method of claim 38 , further comprising:
storing the watermark in a memory in the secure network.
40 . The computer-implemented method of claim 36 , wherein the watermark comprises at least one of:
a sender identifier; a sender account identifier; a sender timestamp; one or more source network settings; a recipient identifier; a recipient account identifier; a recipient timestamp; or one or more destination network settings.
41 . The computer-implemented method of claim 36 , further comprising:
receiving the watermarked file; extracting the watermark from the watermark file; and decoding the watermark.
42 . The computer-implemented method of claim 41 , further comprising:
extracting the sender identifier from the watermark.Join the waitlist — get patent alerts
Track US2022058245A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.