Image integrity authentication method based on digital signature and image transformation

By embedding the digital signature value of the digital certificate owner in the image file and using wavelet transform and timestamp signature, the integrity and source verification problems of image files in the existing technology are solved, and the security protection and copyright authentication of image files are achieved.

CN120579226BActive Publication Date: 2025-10-17SICHUAN DIGITAL CERTIFICATE AUTHENTICATION MANAGEMENT CENT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511072369.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-01
Publication Date
2025-10-17
Estimated Expiration
2045-08-01

AI Technical Summary

Technical Problem

In the existing technology, the image file protection method based on digital signature relies on a third-party evidence storage platform, which has separation, platform dependence and security issues, making it difficult to effectively ensure the integrity and source verification of image files.

Method used

The digital certificate is used to digitally sign the image, and the digital signature value is embedded in the high-frequency domain of the image through wavelet transform. Combined with the timestamp signature, the unique identification information of the digital certificate owner is embedded in the image file, and the image is restored using wavelet reconstruction.

Benefits of technology

It effectively protects the integrity and source authentication of image files without changing the visual effects of the image, ensuring the security and copyright protection of the image content.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120579226B_ABST
    Figure CN120579226B_ABST
Patent Text Reader

Abstract

The application discloses an image integrity authentication method based on digital signature and image transformation and relates to information security, which comprises the following steps: using a digital certificate to perform digital signature on an original image; performing wavelet transformation on the original image; embedding a digital signature value of the original image in a high frequency domain; performing wavelet reconstruction to obtain an embedded signature image; extracting the digital signature value during verification; and verifying the extracted digital signature value; the application can embed a digital signature value of an owner of a digital certificate in an image without changing the visual effect of the image.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of information security, in particular to an image integrity authentication method based on digital signature and image transformation. BACKGROUND

[0002] With the popularity of the Internet and the vigorous development of the self-media, more and more enterprises and individuals begin to rely on content creation to carry out brand dissemination and attract traffic. The exchange of multimedia information has reached an unprecedented depth and breadth, and its publishing forms are increasingly rich. Computer network has become an important medium for publishing information. However, while providing these services through computer network, some serious problems will also be brought about due to the open network architecture of the Internet network. The copyright of these digital media is difficult to protect because the data works transmitted through the network are extremely easy to be illegally copied, which enables malicious individuals and groups to arbitrarily tamper with, copy and spread the copyrighted content without the permission of the owner of the works. Therefore, how to both fully utilize the convenience of the Internet and effectively protect the integrity of the image file and verify the source has become an urgent practical problem. The digital signature technology provides an effective way to solve this problem.

[0003] At present, the image file mostly relies on the third-party evidence storage platform, adopts the digital signature technology, converts the media file into a fixed-length hash value through the hash algorithm, and then generates a digital signature value with a private key to store evidence on the platform to prove the source and guarantee the integrity and prevent illegal tampering. However, this method has the following defects:

[0004] 1. The evidence storage mode of the third-party evidence storage platform based on the digital signature technology separates the image file and the digital signature value, and the verification relies on the platform, which cannot be verified through the media file itself without the platform;

[0005] 2. The evidence storage mode of the third-party evidence storage platform based on the digital signature technology will be affected by the platform software, hardware and network environment, which may cause problems in the evidence storage and verification process;

[0006] 3. If the security protection measures of the third-party evidence storage platform are not in place, such as network vulnerabilities and hacker attacks, data leakage may occur, which endangers the privacy and rights and interests of users. SUMMARY

[0007] In order to solve the problems in the prior art, the purpose of the present application is to provide an image integrity authentication method based on digital signature and image transformation, which can embed the digital signature value of the digital certificate owner in the image without changing the visual effect of the image.

[0008] To achieve the above object, the technical scheme adopted by the present application is as follows: An image integrity authentication method based on digital signature and image transformation, comprising the following steps:

[0009] S100, digitally signing the original image using a digital certificate;

[0010] S200, wavelet transforming the original image;

[0011] S300, embedding the digital signature value of the original image in the high frequency domain thereof;

[0012] S400, wavelet reconstructing to obtain the embedded signature image;

[0013] S500, extracting the digital signature value during verification;

[0014] S600, verifying the extracted digital signature value.

[0015] As a further improvement of the present application, the S100 specifically comprises the following steps:

[0016] S101, base64 encoding the original image to convert it into a data stream, denoted as DFD;

[0017] S102, calculating the HASH value of DFD using the SM3 algorithm, denoted as HSM3=SM3(DFD);

[0018] S103, encrypting HSM3 using the digital certificate private key SM2Pri in the cryptographic device to obtain the digital signature value of the original image including the digital certificate public key SM2Pub, denoted as SM2Sign;

[0019] S104, taking SM2Sign as the original text, calling the third-party timestamp signature service to obtain the timestamp signature value, denoted as SM2TimeStamp;

[0020] S105, combining the original image digital signature value SM2Sign and the timestamp signature value SM2TimeStamp, denoted as DFDsign.

[0021] As a further improvement of the present application, in S103, the cryptographic device includes a smart cryptographic key USBKey, a server cryptographic machine, a cryptographic card and a collaborative signature system.

[0022] As a further improvement of the present application, the S200 specifically comprises the following:

[0023] Wavelet transforming the original image W to obtain a low-frequency approximation sub-image W 0 and three high-frequency detail sub-images W k , where k=1, 2, 3.

[0024] As a further improvement of the present application, the S300 specifically comprises the following steps:

[0025] S301, the digital signature value DFDSign added with the time stamp of the original image is segmented by fixed length to obtain three digital signature value segments D k ;

[0026] S302, the D k is respectively embedded into three high frequency detail sub-images W k of the original image wavelet decomposition to obtain each embedded block X k : X K = W K + D K .

[0027] As a further improvement of the present application, the S400 specifically comprises the following:

[0028] W 0 and X k are recombined and wavelet reconstructed to obtain the final embedded watermark image XW.

[0029] As a further improvement of the present application, the S500 specifically comprises the following steps:

[0030] S501, the original image W and the embedded watermark image XW with the embedded digital signature value are respectively wavelet decomposed to respectively obtain two groups of high frequency detail sub-images W k , XW k and two low frequency approximation sub-images X 0 and XW 0 ;

[0031] S502, W k , XW k are read and the embedded digital signature value segments D k are respectively extracted: D k = XW k - W k ;

[0032] S503, the obtained D k is spliced and combined to obtain the digital signature value DFDSign added with the time stamp of the original image.

[0033] As a further improvement of the present application, the S600 specifically comprises the following steps:

[0034] S601, DFDSign is decomposed to obtain the original image digital signature value SM2Sign and the time stamp signature value SM2TimeStamp;

[0035] S602, calling a third-party timestamp verification service to confirm whether the SM2TimeStamp is valid;

[0036] S603, if the timestamp signature is valid, extracting the digital certificate public key SM2Pub in the SM2Sign, and using the SM2Pub to decrypt the SM2Sign to obtain H SM3 ’ , repeating S102 to calculate H SM3 , if H SM3 ’ = H SM3 , it indicates that the signature of the image file is valid, otherwise it indicates that the image file is tampered.

[0037] The application uses a cryptographic device (such as a smart cryptographic key USBKey, a server cryptographic machine, a cryptographic card, a collaborative signature system, etc.) storing a digital certificate to perform a hash operation on the original image to convert it into a fixed-length hash value, and then use the private key of the digital certificate to digitally sign the hash value to obtain a P7 format digital signature value (the signature value contains a digital certificate public key and can verify the signature value); and perform a discrete wavelet transform (DWT, Discrete Wavelet Transform) on the original image, embed the digital signature value of the original image in the high frequency domain, and then perform wavelet reconstruction to obtain an embedded signature image. Thus, the digital signature value of the digital certificate owner to the image can be embedded in the image without changing the visual effect of the image.

[0038] When verifying, the wavelet transform is also performed on the embedded signature image, the digital signature value of the original image is read in the high frequency domain where the digital signature value is written, and the P7 format signature value is verified using the cryptographic device, so that the source and integrity of the image can be verified.

[0039] The beneficial effects of the application are:

[0040] The image integrity authentication method based on digital signature and image transformation of the application realizes the embedding of the digital signature in the image file without changing the visual effect of the image, effectively solves the problems of image source authentication and integrity protection, and can meet the application requirements of image copyright protection, image electronic certificate issuance verification and other scenes; which is embodied in:

[0041] 1) Image source authentication: the application uses digital signature technology based on digital certificate to convert the unique identification information of the image creator or owner into a digital signature and embed it in the image file. When verifying the source of the image, only the digital signature needs to be extracted, and the corresponding verification algorithm can be used to accurately confirm whether the image comes from the claimed creator or owner;

[0042] 2) Image Integrity Protection: Before embedding the digital signature, the original image data is hashed to generate a unique hash value. This hash value acts as a "digital fingerprint" for the image, accurately characterizing its content. This hash value is then used to generate a digital signature value through a digital signature algorithm and then embedded in the image. If the image is tampered with in any way during subsequent transmission or storage, verification methods can detect this, thus ensuring the integrity of the image content. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] Figure 1 is a flow chart of an embodiment of the present invention;

[0044] Figure 2 Schematic diagram of wavelet decomposition;

[0045] Figure 3 Schematic diagram of wavelet decomposition of an original image in an embodiment of the present invention;

[0046] Figure 4 Schematic diagram of wavelet reconstruction and restoration combination in an embodiment of the present invention. DETAILED DESCRIPTION

[0047] The embodiments of the present invention are described in detail below with reference to the accompanying drawings.

[0048] Example

[0049] like Figure 1 As shown, an image integrity authentication method based on digital signature and image transformation is used to solve the problem of image file integrity protection and source verification, which specifically includes the following steps:

[0050] S100: Digitally sign the original image using a digital certificate:

[0051] S101: Convert the original image into a data stream by performing base64 encoding, denoted as DFD;

[0052] S102: Use SM3 algorithm to calculate the HASH value of DFD, recorded as H SM3 =SM3(DFD);

[0053] S103: Use the digital certificate private key SM2Pri in the cryptographic device to SM3 Encrypt the original image to obtain its digital signature value, recorded as SM2Sign (digital signature value in P7 format, including the digital certificate public key SM2Pub);

[0054] S104: Using SM2Sign as the original text, call the third-party timestamp signature service to obtain the timestamp signature value, which is recorded as SM2TimeStamp;

[0055] S105: Combine the original image digital signature value SM2Sign and the timestamp signature value SM2TimeStamp, denoted as DFDSign.

[0056] S200: Perform wavelet transform on the original image:

[0057] S201: Perform wavelet transform on the original image W to obtain a low-frequency approximation sub-image W 0 , and three high-frequency detail sub-images W k , (k = 1, 2, 3), as shown in Figure 3 .

[0058] The basic idea of wavelet transform is to decompose a digital image into sub-images of different spatial and frequency resolutions, and then perform targeted processing based on the characteristics of each sub-image. The wavelet decomposition of an image is shown in Figure 2 .

[0059] Wavelet transform decomposes an image into four frequency bands: horizontal (HL), vertical (LH), diagonal (HH), and low frequency (LL). The low frequency (LL) part can be further decomposed to form a tower-like decomposition. After decomposition, the main energy of the image is concentrated in the low frequency part, which is also the visually important part. The high frequency part of the image, which contains less energy, is distributed in the HL, LH, and HH sub-images, and mainly contains edge and texture information of the original image. The SM2 digital signature value is small in size, and writing it into the high frequency part will not cause distortion of the image.

[0060] S300: Embed the digital signature value of the original image in its high frequency domain:

[0061] S301: Divide the digital signature value DFDSign of the original image added with the timestamp into fixed-length segments to obtain three digital signature value segments D k , (k = 1, 2, 3);

[0062] S302: Embed D k , (k = 1, 2, 3) into the three high-frequency detail sub-images W k , (k = 1, 2, 3) of the original image wavelet decomposition, respectively, and X k , (k = 1, 2, 3) are the embedded segments: X K = W K + D K , k = 1, 2, 3.

[0063] S400: Perform wavelet reconstruction to obtain the embedded signature image:

[0064] S401: Perform wavelet reconstruction on W 0After the above operation, X k , (k=1,2,3) are recombined and wavelet reconstruction is performed to obtain the final embedded watermark image XW, as shown in Figure 4 shown.

[0065] S500: Extract digital signature value during verification:

[0066] S501: Perform wavelet decomposition on the original image W and the embedded digital signature value XW to obtain two sets of high-frequency detail sub-images W. k , XW k (k=1,2,3) and two low-frequency approximation subgraphs X 0 and XW 0 ;

[0067] S502: Read W k , XW k (k=1,2,3), and extract the embedded digital signature value fragment D according to the following formula k :D k =XW k —W k , k=1,2,3;

[0068] S503: D obtained from the formula in the previous step k , (k=1,2,3) are spliced ​​and combined to obtain the digital signature value DFDSign that adds a timestamp to the original image.

[0069] S600: Verify the extracted digital signature value:

[0070] S601: Decompose DFDSign to obtain the original image digital signature value SM2Sign and the timestamp signature value SM2TimeStamp;

[0071] S602: Call the third-party timestamp verification service to confirm whether the SM2TimeStamp is valid;

[0072] S603: If the timestamp signature is valid, extract the digital certificate public key SM2Pub in SM2Sign, and use SM2Pub to decrypt SM2Sign to obtain H SM3 ’ Repeat step S102 to calculate H SM3 , if H SM3 ’ = H SM3 , indicating that the signature of the image file is valid, otherwise it means that the image file has been tampered with.

[0073] The present embodiment is based on the non-repudiation of digital signature technology and the characteristics of image wavelet transform. That is, after wavelet transform decomposition, the main energy of the image is mainly concentrated in the low frequency part, which is also the visually important part, and the high frequency part of the image contains less energy. Embedding the digital signature value of the image into the high frequency part will not cause distortion of the image, and the source and integrity of the image can be verified by extracting the digital signature value in the high frequency domain of the signed image.

[0074] The above-described embodiments only express the specific implementation of the present application, which is described in more detail and in more detail, but cannot be understood as a limitation on the scope of the patent of the present application. It should be noted that for those skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are within the scope of protection of the present application.

Claims

1. An image integrity authentication method based on digital signature and image transformation, characterized in that: The following steps are involved: S100, digitally signing the original image using a digital certificate; The S100 specifically includes the following steps: S101, converting the original image into a data stream by performing base64 encoding, denoted as DFD; S102. Calculate the HASH value of DFD using the SM3 algorithm, which is recorded as HSM3=SM3(DFD); S103, using the digital certificate private key SM2Pri in the cryptographic device to encrypt HSM3, and obtain the digital signature value of the original image including the digital certificate public key SM2Pub, recorded as SM2Sign; S104: Use SM2Sign as the original text and call a third-party timestamp signature service to obtain the timestamp signature value, which is recorded as SM2TimeStamp; S105, combining the original image digital signature value SM2Sign and the timestamp signature value SM2TimeStamp, and recording them as DFDSign; S200, performing wavelet transform on the original image; The S200 is specifically as follows: Perform wavelet transform on the original image W to obtain a low-frequency approximation sub-image W 0 , and three high-frequency detail sub-images W k , where k=1,2,3; S300, embedding the digital signature value of the original image in its high frequency domain; The S300 specifically includes the following steps: S301, the digital signature value DFDSign with the timestamp of the original image is divided into three segments D according to a fixed length. k ; S302, D k The three high-frequency detail sub-images W of the original image wavelet decomposition are respectively embedded k , and get the embedded blocks X k :X K =W K +D K ; S400, performing wavelet reconstruction and restoration to obtain an embedded signature image; The S400 is specifically as follows: W 0 With X k Recombine and perform wavelet reconstruction to obtain the final embedded watermark image XW; S500, extracting the digital signature value during verification; The S500 specifically includes the following steps: S501, perform wavelet decomposition on the original image W and the watermarked image XW embedded with the digital signature value, respectively, to obtain two sets of high-frequency detail sub-images W k , XW k and two low-frequency approximation subgraphs X 0 and XW 0 ; S502, read W k , XW k , and extract the embedded digital signature value fragment D respectively k :D k =XW k —W k ; S503, the obtained D k Perform splicing and combination to obtain the digital signature value DFDSign that adds a timestamp to the original image; S600, verifying the extracted digital signature value; The S600 specifically includes the following steps: S601, decompose DFDSign to obtain the original image digital signature value SM2Sign and the timestamp signature value SM2TimeStamp; S602: Call a third-party timestamp verification service to confirm whether SM2TimeStamp is valid; S603: If the timestamp signature is valid, extract the digital certificate public key SM2Pub from SM2Sign, and use SM2Pub to decrypt SM2Sign to obtain H SM3 ’ Repeat S102 to calculate H SM3 , if H SM3 ’ = H SM3 , indicating that the signature of the image file is valid, otherwise it means that the image file has been tampered with.

2. The image integrity authentication method based on digital signature and image transformation according to claim 1, characterized in that: In S103, the cryptographic device includes a smart cryptographic key USBKey, a server cryptographic machine, a cryptographic card and a collaborative signature system.

Citation Information

Patent Citations

  • Block chain embedding method for wavelet domain watermark in image

    CN108053359A

  • Digital media content infringement detection system with high security digital watermarking

    CN110032839A