In this paper, we propose Puppy, the first formally defined framework for converting any symmetric watermarking into a publicly verifiable one. Puppy allows anyone to verify a watermark any number of times with the help of an untrusted third party, without requiring owner presence during detection. We formally define and prove security of Puppy using the ideal/real-world simulation paradigm and construct two practical and secure instances: (1) Puppy-TEE that uses Trusted Execution Environments (TEEs), and (2) Puppy-2PC that relies on two-party computation (2PC) based on garbled circuits. We then convert four current symmetric watermarking schemes into publicly verifiable ones and run extensive experiments using Puppy-TEE and Puppy-2PC. Evaluation results show that, while Puppy-TEE incurs some overhead, its total latency is on the order of milliseconds for three out of four watermarking schemes. Although the overhead of Puppy-2PC is higher (on the order of seconds), it is viable for settings that lack a TEE or where strong trust assumptions about a TEE need to be avoided. We further optimize the solution to increase its scalability and resilience to denial of service attacks via memoization.
翻译:本文提出Puppy,首个将任意对称水印转换为公开可验证水印的形式化定义框架。Puppy允许任何人在不可信第三方协助下任意次数验证水印,且无需在检测过程中所有者参与。我们采用理想/现实世界模拟范式对Puppy进行形式化安全定义与证明,并构建了两个实用且安全的实例:(1) Puppy-TEE,基于可信执行环境(TEE);(2) Puppy-2PC,依赖基于混淆电路的两方计算(2PC)。随后,我们将四种现有对称水印方案转换为公开可验证方案,并使用Puppy-TEE与Puppy-2PC开展大量实验。评估结果表明,尽管Puppy-TEE存在一定开销,其中三种水印方案的总延迟仅为毫秒级。虽然Puppy-2PC的开销较高(秒级),但适用于缺乏TEE或需避免对TEE强信任假设的场景。我们进一步通过备忘机制优化方案,提升了可扩展性与对拒绝服务攻击的鲁棒性。