IP Library Granted Patent US 9,992,174
Granted Patent B2
US 9,992,174 · App. 14/938,679 · Granted Jun 5, 2018

Detecting disclosed content sources using dynamic steganography

Inventors: Albert Fung Wu (Castro Valley, CA); Nazar Andrienko (Redwood City, CA)
Assignee: Box, Inc.
H04L63/0428G06K19/06037H04L67/22H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,992,174
App. No.
14/938,679
Granted
Jun 5, 2018
Kind
B2
Abstract

Systems for forensic steganography. A server is interfaced with storage facilities that store an object accessible by two or more users, each of which users are associated with respective profiles comprising one or more user-specific attributes. A method detects a user request to view the object. User-specific attributes are encoded into a steganographic message, which is formatted for saving into one or more locations in the object, thus generating a protected object. The protected object is delivered to the requesting user. Encoding, application and formatting techniques are configured to make the steganographic message undetectable by human viewing of the protected object. A web crawler or other policing technique can detect misappropriation in the form of unauthorized dissemination by detecting the presence of the encoded steganographic message embedded in the protected object. Decoding the steganographic message reveals the user-specific attributes so as to identify the user who disseminated the protected object.

Claims (45)

1. A method comprising

identifying a server in a cloud-based environment, wherein the server is interfaced with one or more storage facilities that store an object accessible by two or more users, the object comprises a single image having multiple sites for placement of a steganographic message;

detecting a request to view the object by a requesting user, wherein the requesting user is associated with a role profile comprising one or more attributes;

encoding the one or more attributes of the requesting user into the steganographic message;

applying the steganographic message one or more times to one or more partitions of the object to generate a protected object, wherein the one or more partitions is determined based at least in part on a respective content type of the partition, wherein a plurality of steganographic messages are applied on the single image of the object at some of the multiple sites for placement of the steganographic message; and

initiating delivery of a rendered view of the protected object.

2. The method of claim 1 , further comprising:

identifying a recovered portion of the rendered view;

detecting the steganographic message from the recovered portion of the rendered view; and

decoding the steganographic message to identify the user.

3. The method of claim 2 , wherein detecting the steganographic message comprises at least one of, partitioning the recovered portion of the rendered view, or scaling the recovered portion of the rendered view.

4. The method of claim 1 , wherein at least one steganographic message site is determined based at least in part on the respective content type.

5. The method of claim 1 , further comprising determining an array of candidate sites, and applying the steganographic message to individual ones of the candidate sites when a quantitative threshold is met.

6. The method of claim 1 , wherein the steganographic message is a two-dimensional barcode.

7. The method of claim 1 , wherein at least one steganographic message is applied to at least one of the one or more partitions in a tiled pattern.

8. The method of claim 1 , wherein the at least one of the one or more attributes of the role profile is a hash value.

9. The method of claim 1 , wherein the one or more attributes of the role profile comprise at least one of, a user identifier, or a file identifier.

10. The method of claim 1 , wherein the one or more attributes comprises a user device associated with at least one of the two or more users.

11. A computer readable medium, embodied in a non-transitory computer readable medium, the non-transitory computer readable medium having stored thereon a sequence of instructions which, when stored in memory and executed by a processor causes the processor to perform a set of acts, the acts comprising:

identifying a server in a cloud-based environment, wherein the server is interfaced with one or more storage facilities that store an object accessible by two or more users, the object comprises a single image having multiple sites thereon for placement of a steganographic message;

detecting a request to view the object by a requesting user, wherein the requesting user is associated with a role profile comprising one or more attributes;

encoding the one or more attributes of the requesting user into the steganographic message;

applying the steganographic message one or more times to one or more partitions of the object to generate a protected object, wherein the one or more partitions is determined based at least in part on a respective content type of the partition, wherein a plurality of steganographic messages are applied on the single image of the object at some of the multiple sites for placement of the steganographic message; and

initiating delivery of a rendered view of the protected object.

12. The computer readable medium of claim 11 , further comprising instructions which, when stored in memory and executed by a processor causes the processor to perform acts of:

identifying a recovered portion of the rendered view;

detecting the steganographic message from the recovered portion of the rendered view; and

decoding the steganographic message to identify the user.

13. The computer readable medium of claim 12 , wherein detecting the steganographic message comprises at least one of, partitioning the recovered portion of the rendered view, or scaling the recovered portion of the rendered view.

14. The computer readable medium of claim 11 , wherein at least one steganographic message site is determined based at least in part on the respective content type.

15. The computer readable medium of claim 11 , further comprising instructions which, when stored in memory and executed by a processor causes the processor to perform acts of determining an array of candidate sites, and applying the steganographic message to individual ones of the candidate sites when a quantitative threshold is met.

16. The computer readable medium of claim 11 , wherein the steganographic message is a two-dimensional barcode.

17. The computer readable medium of claim 11 , wherein the one or more attributes of the role profile comprise at least one of, a user identifier, or a file identifier.

18. The computer readable medium of claim 11 , wherein the one or more attributes comprises a user device associated with at least one of the two or more users.

19. A system comprising:

a server in a cloud-based environment, wherein the server is interfaced with one or more storage facilities that store an object accessible by two or more users, the object comprises a single image having multiple sites thereon for placement of a steganographic message; and

a processing element that performs,

detecting a request to view the object by a requesting user, wherein the requesting user is associated with a role profile comprising one or more attributes;

encoding the one or more attributes of the requesting user into a steganographic message; and

applying the steganographic message one or more times to one or more partitions of the object to generate a protected object, wherein the one or more partitions is determined based at least in part on a respective content type of the partition, wherein a plurality of steganographic messages are applied on the single image of the object at some of the multiple sites for placement of the steganographic message; and

initiating delivery of a rendered view of the protected object.

20. The system of claim 19 , further comprising a watermarking proxy to perform at least the steps of,

identifying a recovered portion of the rendered view;

detecting the steganographic message from the recovered portion of the rendered view; and

decoding the steganographic message to identify the user.

Assignments (2)
SECURITY INTEREST Recorded Jul 26, 2023
From: BOX, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 064389/0686 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 11, 2015
From: WU, ALBERT FUNG; ANDRIENKO, NAZAR
To: BOX, INC.
Reel/Frame 037017/0309 →
Continuity (1)
Related Publication 20170134344A1 · May 11, 2017