End-to-end interoperable provenance authentication of media using watermarks and c2pa metadata

ATSC soft binding watermarks and C2PA metadata enable reliable and scalable provenance authentication of broadcast content, addressing interoperability and scalability issues in determining the origin and integrity of media objects.

WO2026112538A1PCT designated stage Publication Date: 2026-05-28VERANCE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
VERANCE CORP
Filing Date
2025-11-21
Publication Date
2026-05-28

AI Technical Summary

Technical Problem

Existing technologies face challenges in authenticating and determining the provenance of broadcast content due to various distribution routes and encoding processes, leading to issues with scalability and interoperability.

Method used

The use of ATSC soft binding watermarks and C2PA metadata for embedding and recovering provenance information, allowing for interoperable provenance authentication through cryptographic validation and watermark retrieval.

Benefits of technology

Ensures reliable and scalable provenance authentication of broadcast content, enabling trust in the origin and integrity of media objects across different distribution platforms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2025056750_28052026_PF_FP_ABST
    Figure US2025056750_28052026_PF_FP_ABST
Patent Text Reader

Abstract

Systems and methods for providing provenance authentication of content. C2PA and other open standards for provenance metadata and watermarking can be used in combination to enable social media platforms to easily identify and retrieve from video servers authentic instances of broadcast video content that is included in user-generated videos. Gaps in these standards that could impede interoperability are addressed by providing protocols that for discovery, launch, and synchronization of network services, such as C2PA, via watermarking. For example, a method is provided for announcement of C2PA services in ATSC watermark protocols. Also, guidelines are disclosed for the interpretation and use of the C2PA asset reference assertion field and expectations around video encoding formats, video server features, and access controls that are necessary for its effective use in promoting availability of authentic video.
Need to check novelty before this filing date? Find Prior Art

Description

U. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00PCT PATENT APPLICATION FOR END-TO-END INTEROPERABLE PROVENANCE AUTHENTICATION OF MEDIA USING WATERMARKS AND C2PA METADATAInventors: Joseph M. Winograd John SimmonsU. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00END-TO-END INTEROPERABLE PROVENANCE AUTHENTICATION OF MEDIA USING WATERMARKS AND C2PA METADATA FIELD OF INVENTION

[0001] The present invention generally relates to provenance determination and authentication of broadcast content.BACKGROUND

[0002] This section is intended to provide a background or context to the disclosed embodiments that are recited in the claims. The description herein may include concepts that could be pursued but are not necessarily ones that have been previously conceived or pursued. Therefore, unless otherwise indicated herein, what is described in this section is not prior art to the description and claims in this application and is not admitted to be prior art by inclusion in this section.

[0003] Linear broadcast streams are subject a variety of distribution routes and various encoding and transcoding processes. This presents challenges when attempting to authenticate and determine the provenance of the broadcast content downstream of these activities.BRIEF DESCRIPTION OF THE DRAWINGS

[0004] FIG. 1 is a block diagram of metadata and watermarking architecture showing the relationship between the registered content distributors, media objects, their embedded watermarks, associated cryptographic metadata, and the canonical representations of the media object itself in accordance with an exemplary embodiment.

[0005] FIG. 2 illustrates an exemplary production flow in which watermarks are applied to enable provenance across multiple distribution paths, with asset watermarksU. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00applied to pre-recorded assets and service watermarking continuously applied to a linear playout stream in accordance with an exemplary embodiment.

[0006] FIG. 3 illustrates a media object validation scenario in accordance with an exemplary embodiment.

[0007] FIG. 4 illustrates a media object canonical processing scenario in accordance with an exemplary embodiment.

[0008] FIG. 5 shows data hash segments, cryptographic metadata, and watermarks in the scenario of a live news broadcast with a watermark consisting of a constant service / asset identifier component and a time-varying index code in accordance with an exemplary embodiment.

[0009] FIG. 6 shows the creation of a canonical media object where the watermark in a live recording is time-varying in accordance with an exemplary embodiment.

[0010] FIG. 7 illustrates a C2PA manifest in accordance with an exemplary embodiment.

[0011] FIG. 8 illustrates an OSI abstraction model of the architecture of the ATSC watermarking system in accordance with an exemplary embodiment.

[0012] FIG. 9 illustrates a typical use case of an open metadata retrieval architecture in accordance with an exemplary embodiment.

[0013] FIG. 10 illustrates a block diagram of a device that can be used for implementing various disclosed embodiments.SUMMARY OF THE INVENTIONU. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00

[0014] This section is intended to provide a summary of certain exemplary embodiments and is not intended to limit the scope of the embodiments that are disclosed in this application.

[0015] Systems and methods for provenance determination and authentication of content. The methods include a method for embedding watermarks in content including receiving content and embedding ATSC soft binding watermarks in the content using a claim generator, wherein the soft binding watermarks place corresponding ATSC soft binding assertions in a C2PA Asset Manifest. The claim generator selects watermark payloads to embed such that each unique pair of Server Code and Interval Code values are associated only with a single interval on a media timeline of a single Asset. The method also includes adding ATSC soft binding assertions to the Asset manifest for all ATSC soft binding watermarks that the claim generator embeds.

[0016] Also disclosed is a method for recovering provenance information from content including receiving content, detecting watermarks from the received content, identifying watermark segments, receiving a recovery data request, issuing a manifest recovery request in response to the recovery data request, recovering an active manifest in response to the manifest recovery request, and using the retrieved manifest to determine whether one or more of the identified VP1 watermark segments constitutes a valid ATSC soft binding assertion.

[0017] Also disclosed is a method of providing provenance authentication of content including receiving a media object, receiving content, embedding ATSC soft binding watermarks in the content using a claim generator, wherein the soft binding watermarks place corresponding ATSC soft binding assertions in a C2PA Asset Manifest, the claim generator selecting watermark payloads to embed such that each unique pair of Server Code and Interval Code values are associated only with a single interval on a media timeline of a single Asset, adding ATSC soft binding assertions to the Asset manifest for all ATSC soft binding watermarks that the claim generator embeds, distributing theU. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00media with including the embedded media object, determining if the received media object contains a manifest corresponding to a registered distributor, and if it does, determining if the manifest validates the media object, and if it does, declaring the media validated, if the media object does not contain a manifest or if the manifest is not validated, determining if the media object contains a watermark, and if so, using the watermark to retrieve the manifest, determining if the retrieved manifest has a digital signature that corresponds to an approved content distributor, and if so, determining if the manifest validates the content, and if so declaring the media object validated; and if the manifest does not validate the content, initiating a canonical process to retrieve a canonical representation of the media object.

[0018] These and other advantages and features of disclosed embodiments, together with the organization and manner of operation thereof, will become apparent from the following detailed description when taken in conjunction with the accompanying drawings.DETAILED DESCRIPTION OF CERTAIN EMBODIMENTS

[0019] In the following description, for purposes of explanation and not limitation, details and descriptions are set forth in order to provide a thorough understanding of the disclosed embodiments. However, it will be apparent to those skilled in the art that the present invention may be practiced in other embodiments that depart from these details and descriptions.

[0020] Additionally, in the subject description, the word “exemplary” is used to mean serving as an example, instance, or illustration. Any embodiment or design described herein as “exemplary” is not necessarily to be construed as preferred or advantageous over other embodiments or designs. Rather, use of the word exemplary is intended to present concepts in a concrete manner.U. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00

[0021] Embodiments are disclosed which enable end-to-end interoperable provenance authentication using watermarks and C2PA metadata.

[0022] Interoperable Provenance Authentication of Broadcast Media using Open Standards-based Metadata, Watermarking and Cryptography

[0023] The spread of false and misleading information is receiving significant attention from legislative and regulatory bodies. Consumers place trust in specific sources of information, so a scalable, interoperable method for determining the provenance and authenticity of information is needed. The disclosed embodiments address the posting of broadcast news content to a social media platform, the role of open standards, the interplay of cryptographic metadata and watermarks when validating provenance, and likely success and failure scenarios. The open standards for cryptographically authenticated metadata developed by the Coalition for Provenance and Authenticity (C2PA) and for audio and video watermarking developed by the Advanced Television Systems Committee (ATSC) are well suited to address broadcast provenance. The disclosed embodiments teach methods for using these standards for optimal success.

[0024] Introduction

[0025] In our interconnected world, information flows ceaselessly, shaping opinions, policies, and societies. Within this digital torrent false and misleading information often obscures the truth.

[0026] False information may take the form of misinformation, spread when well-intentioned individuals share what they found online, neglecting to verify what they found. Or it may be disinformation, false or misleading information intentionally created and spread to deceive.

[0027] Both forms of false information are harmful, and both thrive in the global digital ecosystem. Social media platforms amplify their reach, turning falsehoods intoU. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00viral storms. A rumor, a manipulated video, a fabricated statistic — these can cascade across screens, eroding public discourse.

[0028] Provenance and Authenticity

[0029] Any attempt to address false information on the web must proceed from an understanding of how people come to place trust in information.

[0030] The prevalence of information ‘bubbles’ demonstrates that people primarily place trust in specific sources of information. If information appears unaltered and from a trusted source, we often consider that information to be factual.

[0031] In other words, most of us judge what is factual based on the provenance and authenticity of the information, where provenance refers to the origin, history, and chain of custody of a piece of audio-video content, and authenticity refers to whether the content has been manipulated or altered in a way out of the control of the trusted source of the information.

[0032] The Role of Standards

[0033] There are two general methods for conveying provenance and authenticity metadata in association with audio-video content. Metadata can be cryptographically bound to the audio-video content, perhaps stored at the audio-video container level. Metadata can also be embedded as a watermark in the audio-video elementary stream.

[0034] For practical reasons described in herein these two metadata approaches are interdependent. Both cryptographic and watermarking provenance and authenticity methods should provide a reasonable degree of provenance assurance.

[0035] A critical issue to address is the impact of adopting proprietary solutions on interoperability and scalability, an issue often encountered. For example, fifteen years ago, Digital Rights Management (DRM) on the web had not yet been standardized. PriorU. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00to the ISO / IEC Common Encryption standard playback devices would have to support every major variety of digital rights management software, and there would be as many versions of the audio-video content as there were DRM systems. Had this continued it would have resulted in a combinatorial explosion, an effective barrier to large scale growth of commercial web media. It is no wonder that Netflix was one of the first companies to recognize the value of the common encryption standard.

[0036] It is reasonable to expect that the same will hold true for provenance and authenticity. For scalability and interoperability, the cryptographic metadata bound to the audio-video container and the watermark metadata embedded in the audio-video elementary streams must include open standard options.

[0037] A solution for provenance and authenticity for broadcast content distributed on social media platforms is described, utilizing metadata, watermarking and cryptographic standards. The disclosed embodiments demonstrate this can be used with broadcast news content while pointing out several important implementation considerations.

[0038] Provenance and Authenticity Success Scenarios

[0039] A provenance and authenticity use case can encompass multiple scenarios, including success scenarios, where everything goes roughly as intended and various exception scenarios, which lead to undesirable outcomes. All these scenarios should be describable as discrete programmatic steps to uncover the functional requirements for addressing provenance and authenticity in practice.

[0040] The following disclosure will examine the details of one specific, provenance and authenticity use case - the posting of what appears to be broadcast news content to a social media platform. What is particularly interesting is the interplay between provenance validation using tamper-evident cryptographic bindings and metadataU. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00retrieval using elementary stream watermarks, with a focus on the constituent ‘success’ and ‘exception’ scenarios.

[0041] A broadcaster produces content for linear distribution by an affiliate / network / platform operator. This content consists of a series of audio-video programs comprising a single linear broadcast TV channel.

[0042] There are a variety of scenarios where some of the broadcaster content finds its way into Internet distribution and is uploaded to a social media platform. At a minimum it will then be transcoded into a platform’s preferred framerates, resolutions, bitrates, codecs, and container formats. It may also be truncated to meet the platform’s maximum size limits.

[0043] Verifying Authenticity

[0044] Before being posted to a social media platform, broadcast news content may be altered such that there are observable, meaningful differences between what was depicted in the original broadcast and the posted video. This manipulation could be done for artistic, creative, or deceptive reasons, depending on the intention of the editor.

[0045] One way to characterize these differences is to ask whether the posted video is an authentic representation of the original, whether it is true to the original, without any judgement as to whether the original itself depicted what transpired in front of the camera lens and microphone.

[0046] In this definition, an authentic representation of the broadcaster content may not be bit-wise identical to the original, it may be an unaltered clip from the original, or it may be a transcoding of the original, but it may nonetheless accurately represent what was depicted by the original.

[0047] The C2PA standard provides a mechanism for editing the original - e.g., transcoding or clipping - and a means to cryptographically verify the authenticity of theU. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00result, but this requires that the tool used to alter the broadcaster content supports the use of this standard. See: https: / / spec.c2pa. Org / specifications / specifications / 2.l / specs / C2PA_Specification.htmI, which is incorporated herein in its entirety by reference. We believe it is highly unlikely that in the near-term social media platforms will reject content that was edited using a tool that does not implement cryptographic metadata standards.

[0048] Verifying Provenance

[0049] When consuming video in a linear TV receiver, consumers quite reasonably believe that the network / platform operator is accurately identifying the channel and content creator.

[0050] Video content on the Internet might misrepresent the identity of the original content creator, the identity of who subsequently transcoded the video and what authorized or unauthorized changes were made.

[0051] One way to characterize this history is to use the term “provenance,” meaning, the identifiable source of the content and an accurate history of the content’s transformation from that source.

[0052] There are cryptographic methods for verifying the provenance of video posted to a social media platform using the C2PA standards, but again it is unlikely in the shortterm that social media platforms will reject videos that do not enable the use of these methods to identify the source of the original content.

[0053] Canonical Representation of a Media Object

[0054] A tamper-evident cryptographic binding to an audio-video media object which contains provenance information can be used to validate the provenance and authenticity of that object. It is surely a successful outcome if the provenance is validated, but whatU. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00should happen if the provenance and authenticity fail to be verified? What constitutes success in this scenario?

[0055] There are multiple scenarios where the content may have been innocently modified by the user when preparing to post to a social media platform, since even a single bit change to the content will invalidate a cryptographic binding. Generating numerous alerts for innocent alterations to the media could lead to “security alert fatigue,” diminishing user trust in the alert’s salience. Doing nothing is also an unattractive option because it leaves users blind to the “trust signal” conveyed by the presence of a provenance assertion.

[0056] Should the cryptographic verification of the provenance and authenticity of a media object fail a successful outcome is for the social media platform to use an embedded watermark to retrieve the authoritative version - the canonical representation of the media object. This can be done by first using the watermark to retrieve the cryptographic metadata associated with the original media object as distributed and then use that trusted metadata to retrieve the media object’s canonical representation.

[0057] An Approach to Authentication using Metadata and Watermarking

[0058] Architecture

[0059] The provenance and authenticity approach in this paper builds on the relationship between the registered content distributors, media objects, their embedded watermarks, associated cryptographic metadata, and the canonical representations of the media object itself. This relationship is shown in FIG. 1.

[0060] Security Model

[0061] If the tamper evident cryptographic metadata associated with a media object is stored as a component of the media object container, it is relatively easy to remove. AU. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00durable embedded watermark can enable cryptographic metadata to be brought back into association with the media object.

[0062] Watermark security is typically maintained by making the watermark difficult to remove or alter by keeping the watermark technology secret. This approach works against availability and interoperability by demanding hardened implementations and strict access controls. It can also provide only weak security assurances because its secrecy impedes comprehensive security assessment. Because recorded broadcast content has a long lifespan on the Internet, the security of “closed” watermarks requires successful long-term protection of the associated secrets. And furthermore, recent advances in attacks on watermarking have demonstrated that advances in artificial intelligence render even robust, secret watermarks automatically removable, further diminishing their potential advantages.

[0063] This motivates a security approach that does not treat the watermark as a root of trust. Instead, we assume that they are durable, i.e. that they survive content processing that causes traditional metadata formats to be lost, but that they are otherwise as mutable as traditional metadata and can be modified or removed by any intermediary. Like traditional metadata, data conveyed via watermarking is treated as untrusted and must be validated using cryptographic methods.

[0064] This same approach was advocated by England et al. in their foundational work on media provenance authentication. See: England, P. et al. 2021. AMP:Authentication of Media via Provenance. 12th ACM Multimedia Systems Conference. July 2021. https: / / doi.org / 10.48550 / arXiv.2001.07886.

[0065] That work, however, assumed the presence of a signature in the watermark payload. We view that signature as unnecessary and assume that the watermark carries only a URL and media timeline. The root of trust is a manifest that has been retrieved using the watermark and cryptographically validated using an appropriate trust list.U. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00

[0066] Watermarking Audio-Video Content

[0067] Our success scenario demands a path to validated content regardless of distribution source, which for broadcasters must encompass both linear and on-demand delivery. To achieve this, it must be possible to apply watermarking in asset-based digital publishing as well as within the live production chain.

[0068] FIG. 2 illustrates an exemplary production flow in which watermarks are applied to enable provenance across multiple distribution paths, with asset watermarks applied to pre-recorded assets and service watermarking continuously applied to a linear playout stream.

[0069] The broadcaster may produce content to be published on their website (2-1). They would apply an asset watermark (2-2), generate cryptographic metadata or a “manifest” for that content (2-3), store the asset (2-10) and distribute the asset to their website (2-4).

[0070] The broadcaster may also want to take live and third-party assets (2-5) and prepare them for linear playout (2-6). They would apply a service watermark with a time varying component (2-7), distribute the content (2-8) and periodically generate cryptographic metadata or “manifest” information for that broadcast (2-9).

[0071] A watermark can be used to retrieve the associated, static cryptographic metadata and canonical content. And the time-varying service watermarks can be used to retrieve the associated, time-varying cryptographic metadata and canonical content (2-10).

[0072] Validating Content Authenticity using Watermarking

[0073] FIG. 3 and FIG. 4 summarize how watermarks can be integrated into the content validation process. FIG. 3 illustrates a media object validation scenario. FIG. 4 illustrates a media object canonical processing scenario.U. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00

[0074] Media validation uses the cryptographic metadata which may be stored in the media object, distributed with the media object and / or retrievable from the cloud. This object is referred to as a ‘manifest’ in the C2PA standard referenced above.

[0075] Media object validation scenarios

[0076] If the content can be validated by a contained or retrieved manifest, then a successful outcome does not require utilizing canonical content.

[0077] If the media contains a manifest (3-1), the manifest corresponds to a registered distributor (3-2), and the manifest validates the media object (3-3), validation is achieved without reference to a watermark. We would view this as a success scenario.

[0078] Otherwise, if the media object does not contain a watermark (3-4), the media remains unvalidated, this is an exception scenario.

[0079] If the media does contain a watermark (3-4) then the manifest is retrieved from the manifest cloud store (3-5). If this retrieval fails, for example if the URI Authority field provided in the watermark does not correspond to a registered broadcaster, the media object is not validated, an exception scenario.

[0080] If the retrieved manifest’s digital signature does not correspond to an approved broadcaster (3-6), then the media object cannot be validated. Another exception scenario.

[0081] Otherwise, if the manifest’s digital signature is trustworthy (3-6) and the manifest validates the content (3-7), validation is achieved by using the watermark. A success scenario.

[0082] Media object canonical representation scenariosU. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00

[0083] If a retrieved manifest (3-5) is trustworthy (3-6) but it does not validate the content (3-7), then it is the view of this paper that the only success scenarios involve canonical processing.

[0084] The decision to perform canonical processing (4-8) can be made by the user posting the content or by the platform supporting the validation logic, depending on the policy being adhered to by the social media platform.

[0085] If the decision is to perform canonical process (4-9), the validator retrieves the canonical content (4-10).

[0086] The previously retrieved manifest (3-5) should always validate the canonical content (4-11). If it does not, it is an error and an exception scenario.

[0087] We view validation of the retrieved canonical content as optional because its retrieval location has been established as trusted through validation of the manifest that contains it (3-6) (3-7).

[0088] Media object canonical processing

[0089] The availability of a canonical version of the media object presents the social media platform with additional success scenario opportunities, including one or more of the following:

[0090] • Posting the uploaded content together with the retrieved asset, or a link to it.

[0091] • Providing the uploader with a choice between which version of the content should be posted and posting that version with an appropriate label.

[0092] • Performing an automated comparison of the uploaded and reference asset to determine the nature and amount of difference between the two.

[0093] • Automatically replacing the uploaded content with the valid asset content.U. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00

[0094] • Forwarding the uploaded content and the retrieved asset to an internal content moderation process.

[0095] The Above Approach Applied to Live Broadcast

[0096] Low Latency Considerations

[0097] Real-time broadcast and live streaming, often referred to as “glass to glass,” is a process where content is captured through a camera lens and transmitted to a viewer’s screen with minimal delay. Although it is a real-time transmission, it always involves some degree of delay or latency, incidental and / or intentional.

[0098] Live scenarios may be categorized by the degree of latency required. This depends on the content’s nature and the desired viewer experience. Real-time, low latency live is essential for live sports and breaking news, where timely viewing is important. Higher latency can be introduced for any number of reasons. For example, content is often recorded, edited, or processed before broadcast.

[0099] Using digital signatures to protect provenance metadata for ‘glass to glass’ real-time live streaming scenarios is technically challenging. The primary difficulty is that performing a digital signing operation on a Content Delivery Network (CDN) edge server is not adequately secure and performing that operation in a Hardware Security Module (HSM) is unlikely to achieve the low latency desired.

[0100] However, any live scenario where the content is captured downstream, edited, and subsequently posted will introduce an inherent latency sufficient to allow the use of an HSM for provenance metadata protection.

[0101] Live Broadcast News Content Posted to a Social Media PlatformU. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00

[0102] A 30-minute evening news program is broadcast. The live broadcast is captured and recorded on a device downstream of an HDMI port. A 20-second clip of the news broadcast is created as an MP4 file and posted to a social media platform.

[0103] No manifest can be present with the content since only the elementary stream will make its way beyond the HDMI port. The social media platform can examine the posted video for a watermark, but what would be the success scenario?

[0104] The fragmented MP4 broadcast replica

[0105] The following approach provides a reasonable degree of provenance and authenticity assurance for broadcast news content posted to social media platforms.

[0106] The live news program is broadcast with a watermark consisting of a constant service / asset identifier component and a time- varying index code. See FIG. 5, which shows data hash segments, cryptographic metadata, and watermarks in the scenario of a live news broadcast with a watermark consisting of a constant service / asset identifier component and a time-varying index code. This watermark approach is in use today for delivering metadata for interactive television services and can readily support the retrieval of provenance metadata without the need to modify the watermark itself. See the ATSC 3.0 specifications A / 334, A / 335, and A / 336, discussed below.

[0107] The broadcaster or the network / platform operator on behalf of the broadcaster produces a secure transcoding of specified portions of the live linear broadcast into a fragmented MP4 format - an ‘fMP4 Replica’ of the portion of the linear broadcast for which provenance and authenticity is to be established.

[0108] Periodically a C2PA manifest is produced for this fMP4 Replica. In this design the portion of the Replica that each manifest corresponds to is defined as the Data Hash Segment (DHS). The real-time duration of a DHS defines a minimum lag time behind the linear live edge for the availability of DHS Replica Manifests.U. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00

[0109] The Replica itself consists of a sequence of fragmented MP4 segments or chunks for each track, adequate to cover the length of the Data Hash Segment. Each segment or chunk includes auxiliary ‘c2pa’ boxes (defined in the previously mentioned C2PA specification) which can be used by a C2PA validator to validate any portion of the DHS Replica, as described below.

[0110] Apart from the addition of c2pa-specific ISOBMFF boxes, the Replica format is identical to the format in common use for adaptive bitrate streaming, the Common Media Application Format or CMAF. See: ISO / IEC 23000-19:2020, “Information technology - Multimedia application format (MPEG- A) - Part 19: Common media application format (CMAF) for segmented media”.

[0111] The fragmented MP4 replica C2PA manifest

[0112] The fMP4 Replica Manifest is constructed in the exact same way as a C2PA Manifest for audio-video streaming. See section 9.2.3 of the C2PA specification.

[0113] Before the manifest is generated, a DHS initialization segment is produced for the content stored in the DHS Replica. The cryptographic metadata stored in this initialization segment is identical to that specified by C2PA for adaptive bitrate delivery. See Section 9.2.3 of the C2PA specification.

[0114] The c2pa-specific box in each track’s initialization segment will contain the C2PA manifest, which, as is the case for adaptive delivery, must be identical across tracks. The Manifest’s c2pa.bmff.hash assertion will contain CBOR with an array of Merkle rows, one per track.

[0115] In the C2PA specification for adaptive delivery provenance validation, the Merkle tree associated with the entire video stream enables piecewise validation of individual fragment components of the stream without access to the entire stream. The same mechanism enables piecewise validation of arbitrary portions of the DHS using a single DHS manifest.U. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00

[0116] Producing a canonical live recording

[0117] If the watermark in the live recording is time -varying, it can be used create a canonical live recording, as shown in FIG. 6.

[0118] The time-varying watermark is used to derive the manifest recovery URL. OTT BINX and OTT EINX are the time indices (Interval Code) corresponding to the start and end of the posted video, respectively.

[0119] A recovery request (6-1) is sent. The DHS Manifest is provided in a recovery response (6-2).

[0120] This recovery request response is identical to the method used today for interactive television. The only change is in the payload of the response from the provenance-authenticity server.

[0121] The DHS corresponding to the manifest is accessed from the Asset Reference Assertion in the DHS Manifest (6-3).

[0122] The fMP4 Replica is used as an authenticated mezzanine format, to produce a canonical MP4 representation of the posted live content. Any portion of the Data Hash Segment can be validated with the DHS Manifest.

[0123] Beginning with the OTT BINX (6-4), the algorithm walks the Data Hash Segments provided in the Recovery Response (6-7) until the EIDX of the posted live recording is reached (6-5).

[0124] The Present Approach Applied to Web Published Content

[0125] Differences without a Distinction

[0126] During validation of content posted to a social media platform, even the slightest alteration to the content can cause it to be flagged as inauthentic. There areU. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00multiple scenarios where the content may have been innocently modified by a user, making their edits from a provenance perspective a ‘difference without a distinction’.

[0127] As discussed, we believe the successful outcome for a validation failure to be for the social media platform to recover the original content and use it in one of the ways we outlined. There are cases, however, where this too will result in an unsuccessful outcome.

[0128] Clipped Web Published News Content Posted to Social Media

[0129] One of the most likely such cases is what we are calling “the clipped news segment” scenario.

[0130] Consider the following example. The broadcaster publishes a 30-minute evening news program to their website. The published video file includes cryptographic metadata, and it is watermarked. A user wishes to share a 20-second clip from that 30-minute program. They download the broadcaster published video file, edit it to produce a 20-second clip, and attempt to post it to a social media platform.

[0131] If the editing tool the user used removed the manifest, the social media platform can recover the metadata using the watermark, as described above. Regardless, the file will be flagged as inauthentic. And recovering the canonical version of the content will result in a 30-minute post.

[0132] Producing the canonical news clip

[0133] If the watermark in the clipped news content is time-varying, it is used to derive the manifest recovery URL, a recovery request (1) is sent where BINX is the time index corresponding to the start of the clip. The retrieved DHS Manifest in a recovery response (2) can be used to produce a canonical version of the news clip, as shown in FIG. 6, following the same steps as producing a canonical live recording.U. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00

[0134] Since social media platforms transcode posted video into a multitude of targeted formats, it is likely that they would treat the DHS as a canonical mezzanine format to produce a wide variety of device targeted formats. Using fragmented MP4 as a mezzanine format is commonly done. In addition, the MPEG DASH specification provides support to access segments of presentations at a specified media time through the use of an MPD Anchor, using a query parameter "t=" that a client can append to an MPD URL with either an NPT or UTC time. This could be used to access portions of the fMP4 Replica.

[0135] Content credentials overview

[0136] C2PA metadata for an asset conveys assertions such as asset metadata, actions performed, thumbnails, and cryptographic bindings to the content. These assertions convey the provenance of the asset. Assertions are combined with additional information to create a claim. The set of assertions referenced by a claim are collected into a logical construct referred to as the assertion store. The claim is digitally signed, creating the claim signature.

[0137] Assertions, Claims, and Claim Signatures and some additional information are combined to form the C2PA Manifest, as shown in FIG. 7. For some formats, the C2PA Manifest may be embedded in the content. For each manifest there is a single assertion store. However, multiple manifests can be associated with an asset, each one representing a specific series of assertions.

[0138] ATSC Watermarking

[0139] In 2016, the US-based digital television broadcast standards organization ATSC, published standards for use of watermarking technology in connection with their development of the ATSC 3.0 (“NextGen TV”) system. These standards provide open specifications for the use of watermarking technology and associated network protocols to deliver arbitrary timed metadata associated with media content to network-connectedU. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00clients through distribution paths that include media processing (e.g. transcoding) and metadata removal (e.g. HDMI, analog reconversion).

[0140] ATSC’s primary motivating use case for watermarking is enabling access to NextGen TV interactive (two-way) services for viewers who have purchased compatible TVs but who continue to receive broadcast services from other distribution paths, such as STBs, streaming media players, or ATSC 1.0 transmissions. These standards have been commercially deployed in the United States by multiple broadcasters and television equipment manufacturers.

[0141] The technology has also been found to be suitable for use with other broadcast systems. Since 2020, the HbbTV and DVB have published a series of standards that employ ATSC watermarking to enable interactivity and targeted advertising in their platforms. These standards are currently being readied for commercial deployment in Germany.

[0142] Description

[0143] The ATSC watermark system is specified in the publicly available standards ATSC A / 334, A / 335, and A / 336, described below. Its function is to deliver arbitrary timed metadata using audio and / or video watermarks embedded into media essence. It supports methods for conveying metadata directly in watermark messages or indirectly, by reference, via carriage of a time-tagged URL that identifies a network resource containing the metadata. The architecture of the ATSC watermark system can be understood using the OSI abstraction model shown in FIG. 8. Taken from bottom to top, essence is the baseband audio or video signal components. The physical layer consists of a stream of raw binary symbols conveyed as audio and video watermarks in the essence. Audio watermarks are conveyed using autocorrelation modulation in the 2.5k-5kHz band. Video watermarks are conveyed using luma modulation in the top two lines of active video. While watermark insertion and detection are performed on baseband (decoded) essence, the system is compatible with a wide range of media processing algorithmsU. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00applied to watermarked essence, such as low bit-rate coding, that are typically found in digital media distribution. Both audio and video watermark physical layers also permit watermark energy to be adapted to the content to preserve perceptual quality. In formal testing conducted by ATSC technical committees, the audio watermark was demonstrated to be capable of surviving HE-AACv2 encoding at 32 kbps stereo without performance loss while preserving perceptual transparency. The video watermark was demonstrated to be capable of surviving AVC encoding at 2.5 Mbps 1080p / 30.

[0144] The data link layer differs for audio and video watermarks, with the audio watermark carrying a sequence of data cells of 1.5 seconds duration, each carrying a 50-bit data packet along with a synchronization header and BCH error protection. The video watermark data link layer conveys a 168-bit data packet in each video frame along with a synchronization header, message framing, and CRC error protection.

[0145] The transport layer also differs for audio and video watermarks. For the audio watermark, the transport layer conveys a single packet format, the VP1 payload, that conveys a “tiny URL” encoded into two fields - a server code that identifies a network server and an interval code that identifies a metadata resource on that server associated with the location in the media content where the watermark is embedded. For the video watermark, the transport layer can convey metadata by reference using the VP 1 payload or directly, using a variety of messages associated with known broadcast metadata types such as stream events, presentation timestamps, and content identifiers. Server codes are assigned values for which ATSC maintains registry authority.

[0146] The session layer specifies constraints on the arrangement of watermark messages within assets that enable receivers to perform reliable decisioning regarding the arrangement of watermarked content, including when a particular watermarked asset starts and ends and where on the media timeline a given media sample lies. This is particularly important in contexts the content arriving at the receiver has been composedU. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00from multiple different sources, such as a “mash-up” of multiple sources or edited version of content.

[0147] The VP1 payload is relied on in the session layer to provide the context boundary for a media asset. A watermark media asset (which can be either an individual program item or a continuous program stream) carries audio or video watermark segments comprised of contiguous, watermarked 1.5 second content intervals with a constant server code value and incrementing interval code values.

[0148] At the application layer, directly conveyed metadata becomes valid at the location in the content where it is placed. For metadata delivery over a network, a RESTful application layer protocol between the receiver and a metadata server is specified wherein receivers retrieve arbitrary timed metadata using VP1 payload data. This protocol was adapted by ATSC from an existing 3GPP MBMS protocol. In it, receivers request a metadata resource using a URL constructed from the first VP1 payload that they encounter in a watermark segment. The authority portion of the URL is an Internet hostname determined using DNS resolution of the server code within a second level domain specified by the standard. The path portion of the URL includes the interval code within a predefined template. The response is a multipart / related MIME object containing some protocol-specific metadata objects and some number of additional metadata objects. The protocol-specific metadata includes a mapping of the VP1 interval code value onto a media timeline, boundaries on the media timeline for which each of the additional metadata objects is valid, and guidance to receivers on where and when updates to the metadata objects should be requested. Receivers request subsequent metadata updates only as necessary, in correspondence with the validity periods of metadata objects that they have received and the time periods of watermarked segments of the media timeline of content that they process.U. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00

[0149] Any IANA-registered media type can be provided as an additional metadata object. Receivers are expected to route these objects to application-specific handlers and ignore media types that they do not support.

[0150] Suitability

[0151] The ATSC watermark system provides a number of technical capabilities important to the provenance authentication use case.

[0152] Open Architecture

[0153] The ATSC watermark system shares the same underlying architecture as the modern Internet. The system stack is based on publicly available specifications that enable independent development of interoperable implementations of all components. It uses federated DNS namespace management governed by ATSC, a not for-profit, internationally recognized standards development organization. And it does not rely on any siloed or proprietary services, freeing broadcasters to host metadata services on servers of their choosing with the ability to transition to new hosts at will. A typical use case illustrating an open metadata retrieval architecture is provided in FIG. 9.

[0154] Watermarking Soft Binding Specification for C2PA

[0155] The C2PA Specification specifies a standard metadata format and cryptographic authentication method for authenticating the provenance of media assets. The signed C2PA metadata container is called a manifest and, for use cases where the manifest is either invalid or removed, C2PA supports use of watermarking and fingerprinting as a means for retrieving them from web services. Because the associations provided by watermarking and fingerprinting provide lower security assurances yet are more durable than cryptographic authentication techniques, C2PA refers to watermark and fingerprint technologies as soft-bindings and cryptographic authentication methods as hard-bindings.U. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00

[0156] The C2PA specification specifies a method by which a manifest can include signed metadata asserting the validity of a soft-binding to the manifest. This metadata is called a soft-binding assertion. Soft-binding assertions include a metadata field whose format is not specified by C2PA, but is instead based on the particular soft-binding technology being used. C2PA also does not specify methods for use of the soft-binding assertion in asset production and validation processes, leaving this also open to specification by soft-binding technology creators.

[0157] The present disclosure describes methods for the creation and use of C2PA soft-binding assertions in connection with watermarking technologies. In some embodiments, an example watermarking technology described ATSC watermarking, However the general techniques described may also be applied to other watermark technologies, such as those described along with ATSC watermarking in the C2PA specification at: https: / / github.com / c2pa-org / softbinding-algorithm-list which is incorporated herein by reference. The disclosed embodiments provide the following features and capabilities:

[0158] • Conforming to existing watermark, such as ATSC, and C2PA specifications

[0159] • Re-using existing watermark, such as ATSC, and C2PA specifications to the extent possible

[0160] • Specifying new open, interoperable methods as necessary

[0161] • Specify security best practices and identify assurances and risks

[0162] Compliance

[0163] The present disclosure makes reference to:

[0164] • C2PA Specification vl.4 and v2.1 (described above)U. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00

[0165] • ATSC A / 334:2024. See: https: / / www.atsc.org / wp- content / uploads / 2024 / 04 / A334-2024-04-Audio-Watermark-Emission.pdf, which is incorporated herein by reference.

[0166] • ATSC A / 335:2024. See https: / / www.atsc.org / wp- content / uploads / 2024 / 04 / A335-2024-04-Video-Watermark-Emission.pdf, which is incorporated herein by reference.

[0167] • ATSC A / 336:2024. See https: / / www.atsc.org / wp- content / uploads / 2023 / 06 / A336-2023-03a-Content-Recovery-in- Redistribution-Scenarios.pdf, which is incorporated herein by reference.

[0168] The disclosed embodiments include implementations that conform to the requirements of the above specifications. Where specifications listed above conflict, some implementations may conform with either specification. Where the present document conflicts with any of the above specifications, implementations will preferably conform to the present document. Terms used in the present document and not defined herein that are defined in any of the above specifications have the meaning given in those specifications.

[0169] Definitions

[0170] ATSC watermark: Means a VP1 Watermark Segment as specified in ATSC A / 336.

[0171] ATSC soft binding assertion: Means a soft binding assertion associated with an ATSC watermark. See: Sections 9.3 and 18.9 of the C2PA specification described above, which is incorporated herein by reference.

[0172] ATSC soft binding watermark: Means an ATSC watermark used for the purpose of providing a C2PA soft binding.

[0173] candidate content: Means content input to a provenance recovery process for authentication.U. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00

[0174] provenance recovery client: Means a client that employs ATSC soft binding watermarks together with a C2PA validator for the purpose of recovering provenance authentication capabilities for C2PA assets.

[0175] soft binding: Has the meaning given in the C2PA Specification.

[0176] soft binding assertion: Has the meaning given in the C2PA Specification.

[0177] soft binding watermark: Has the meaning given in the C2PA Specification.

[0178] Watermark Media Timeline: Means the Recovery Media Timeline as specified with ATSC A / 336.

[0179] Claim Generators

[0180] C2PA specifications require claim generators that embed ATSC soft binding watermarks to place corresponding ATSC soft binding assertions in the Asset manifest (see section 18.9.1 of the C2PA Specification. Claim generators are also permitted to add ATSC soft binding assertions to the manifest of Assets that already contain ATSC watermarks (see section 18.12.8 of the C2PA Specification), enabling them to become ATSC soft binding watermarks.

[0181] The following requirements apply to claim generators that perform ATSC soft binding watermark embedding:

[0182] • The claim generator preferably provides users optionality over whether and where ATSC soft binding watermarks are embedded in an Asset.

[0183] • ATSC soft binding watermarks preferably will be comprised of VP1Watermark Segments.

[0184] • VP1 Audio Watermark Segments preferably employ standard signaling.

[0185] • VP1 Video Watermark Segments preferably employ IX video watermarking.U. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00

[0186] • Claim Generators preferably select VP1 Payloads used in ATSC soft binding watermarks such that each unique pair of Server Code and Interval Code values are associated only with a single 1.5 second interval on the media timeline of a single Asset.

[0187] • Coincident VP1 Audio Watermark Segments and VP1 Video Watermark Segments may carry the same VP1 Payload or different VP1 Payloads.

[0188] • ATSC soft binding assertions preferably are added to the Asset manifest for all ATSC soft binding watermarks that the claim generator embeds.

[0189] Other requirements applicable to claim generators are as follows:

[0190] • ATSC soft binding assertions provided by the user may be added to an Asset manifest, irrespective of ATSC soft binding watermark embedding performed by the claim generator.

[0191] • Claim generators should apply ATSC audio and video watermark detection on all audio and video components that are newly incorporated within an Asset, for example by performing an action such as c2pa.created, c2pa.opened, c2pa.placed, or c2pa.dubbed.

[0192] • Claim generators should provide a mechanism by which users are informed of the results of ATSC audio and video watermark detection.

[0193] • Claim generators should identify discrepancies between the results of ATSC audio and video watermark detection and information included in ATSC soft binding assertions provided by the user and provide a mechanism by which users are notified of discrepancies and provided a means to correct them.

[0194] o Claims generators may employ automated or user directed means to resolve discrepancies identifies between ATSC audio and video watermark detection results and information included in ATSC soft binding assertions provided by the user.U. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00

[0195] • Claim generators should support recording results of ATSC audio and video watermark detection in an ATSC Metadata Assertion in the manifest that is referenced in the created_assertions field of the claim.

[0196] ATSC Metadata Assertion

[0197] The following requirements apply to ATSC Metadata Assertions:

[0198] • ATSC Metadata Assertions preferably are a metadata assertion with the label us. aspect. metadata.

[0199] ATSC Soft Binding Assertion

[0200] The schema for soft binding assertions is given in section 18.9.2 of the C2PA Specification.

[0201] The following requirements apply to the elements of a soft-binding-map in an ATSC watermark soft binding assertion:

[0202] • The alg element preferably have the value org.atsc.a336 to indicate use of ATSC watermarking, per the C2PA soft binding algorithm list described above.

[0203] • The blocks element preferably contains a soft-binding-block-map conveying metadata for all VP1 Watermark Segments in the ATSC soft-binding assertion.

[0204] o A single soft-binding-block-map may convey metadata for multiple coincident VP1 Watermark Segments.

[0205] o Assets may include ATSC watermarks in an asset that are not ATSC soft-binding watermarks and for which no ATSC soft-binding assertion exists. Soft binding assertions preferably do not include metadata for ATSC watermarks that are not soft binding watermarks.U. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00

[0206] • The alg-params element, when present, will preferably be CBOR conforming to the CDDL Schema given in Table 1 with elements as follows:

[0207] o The namespace element preferably contains an entity-specific namespace label per section 6.2 of the C2PA Specification that is scoped within an Internet domain name registered to an entity responsible for the format specification of the alg-data field (e.g.; us.aspect.vl).

[0208] o The format of the alg-data field may be implementer specific,proprietary and its contents may be encrypted.alg-params = {"namespace": tstr,"alg-data”: bstr}Table 1. CDDL schema for alg-params element of an ATSC watermark soft binding assertion.

[0209] Each soft-binding-block-map preferably is populated as follows:

[0210] • The scope element preferably contains a soft-binding-scope-map containing a region-map element with elements as follows:

[0211] o The region element of the region-map preferably contains one timemap element that identifies the interval on the Watermark Media Timeline of the Asset during which a VP1 Watermark Segment is present.

[0212] o The type element of the region-map preferably has the valuetemporal.U. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00

[0213] • The value element preferably contains a Recovery File that conforms to ATSC A / 336, subject to the provisions set forth in Annex A below.

[0214] The interval on the Watermark Media Timeline specified in the region element of a soft-binding-block-map constitutes the Validity Period for the Recovery File given in its value element.

[0215] The modifications of Annex A below are drafted such that Recovery Files that comply with ATSC A / 336 will be forward compatible with the requirements of this specification, enabling Recovery Files created for consumption by ATSC 3.0 receivers to be used without modification in an ATSC soft-binding assertion.

[0216] Provenance Recovery

[0217] The following requirements apply to clients that employ ATSC watermarks together with C2PA validation for the purpose of provenance recovery (“provenance recovery clients”):

[0218] • A provenance recovery client preferably detects ATSC audio and video watermarks from candidate content to identify detected VP1 Watermark Segments.

[0219] • A provenance recovery client preferably performs ATSC A / 336 recovery process.

[0220] o A provenance recovery client’s recovery data request should include the URL query parameter c2pa=true.

[0221] o A provenance recovery client should cache recovery responses in accordance with caching directives included in the recovery response per RFC 7234. See https: / / www.rfc-editor.org / rfc / rfc7234.U. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00

[0222] • A provenance recovery client preferably discontinues inclusion in the provenance recovery process any detected VP1 Watermark Segment that is deemed an invalid ATSC soft binding watermark.

[0223] o A provenance recovery client preferably designates as an invalid ATSC soft binding watermark any detected VP1 Watermark Segment whose associated recovery data request does not include a C2PA manifest URL.

[0224] • A provenance recovery client preferably recovers a manifest identified as a metadata fragment in the metadata envelope returned as a response to the recovery data request.

[0225] o The C2PA Manifest Retrieval URL shall be conveyed in the metadataURI field of a metadata envelope item with contentType “application / c2pa”.

[0226] o A C2PA Manifest Retrieval URL may reference either a metadata fragment earned in the recovery response or a URL on a remote server.

[0227] o The presence of multiple C2PA Manifest Retrieval URLs in a recovery response shall indicate multiple alternative locations at which an applicable manifest can be recovered. A provenance recovery client may use any of the listed alternatives.

[0228] o A provenance recovery client should follow caching directives included in the C2PA manifest URL response per RFC 7234 for C2PA manifests retrieved from a remote server.

[0229] • A provenance recovery client preferably performs C2PA manifest validation on each recovered active manifest.U. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00

[0230] o A provenance recovery client preferably designates as invalid ATSC soft binding watermark any detected VP1 Watermark Segment for which C2PA validation determines that the associated recovered active manifest is not Trusted.

[0231] o A provenance recovery client preferably designates as an invalid ATSC soft binding watermark any detected VP1 Watermark Segment for which the associated recovered active manifest does not contain a ATSC soft binding assertion with a Recovery File listing a component with a serverCode value that matches the Server Code of the detected VP1 Watermark Segment.

[0232] ■ If the C2PA Manifest Retrieval URL includes a URL fragment per ISO / IEC 15996-5 containing a C2PA URN referencing a JUMBF box (e.g., a particular manifest or c2pa. soft-binding assertion) (which we refer to as the ATSC Soft Binding Assertion Scope URN), then the provenance recovery client shall use the ATSC soft binding assertion located within and nearest to the end of the referenced JUMBF box that fulfills this requirement.

[0233] ■ If the recovery response does not designate an ATSC Soft Binding Assertion Scope URN as defined above, the provenance recovery client shall use the ATSC soft binding assertion located nearest to the end of the manifest store that fulfills this requirement (i.e., the implied ATSC Soft Binding Scope URN is “ / ”).U. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00

[0234] • A provenance recovery client preferably uses the values provided in the componentDescription.componentAnchor of a matched component to establish its Watermark Media Timeline.

[0235] o A provenance recovery client preferably designates as an invalid ATSC soft binding watermark any portion of a detected VP1 Watermark Segment whose media time is not included in the Validity Period of the Recovery File containing the matched component.

[0236] • A provenance recovery client preferably considers detected VP1 Watermark Segments not otherwise determined to be an invalid ATSC soft binding watermark under any of the above requirements to be an ATSC soft binding watermark.

[0237] • A provenance recovery client preferably considers an ATSC soft binding watermark to represent an unauthenticated assertion that the candidate content in which the VP1 Watermark Segment was detected is derived from the corresponding interval of the Asset associated with the recovered active manifest.

[0238] • A provenance recovery client may authenticate the assertion represented by an ATSC soft binding watermark by validating the candidate content using hard bindings in the recovered active manifest in accordance with the C2PA Specification.

[0239] Annex A

[0240] The following requirements apply to Recovery Files conveyed in an ATSC soft binding assertion:

[0241] • thisComponent.serverCode preferably are present and preferably correspond to a serverCode value conveyed in a VP1 Payload during the Validity Period.U. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00

[0242] • When thisComponent.serverCode and thisComponent.intervalCode are present, they preferably correspond to values conveyed together in a VP1 Payload during the Validity Period.

[0243] • When thisComponent.serverCode, thisComponent.intervalCode and thisComponent.queryFlag are present, they preferably correspond to values conveyed together in a VP1 Payload during the Validity Period. Otherwise, thisComponent.queryFlag should be absent.

[0244] • The presence of a service element will preferably be optional.

[0245] • The presence of a service, service Id element will preferably be optional.

[0246] • The presence of a service. sltSvcSeqNum element will preferably be optional.

[0247] • When the time-map element of the region element of the containing soft- binding-block-map is in NPT:

[0248] o contentID.validFrom will preferably have JSON string format time.

[0249] o contentID.validUntil will preferably have JSON string format time.

[0250] o The Watermark Media Timeline will preferably have Normal Play Time format as specified in RFC 2326 andcomponentAnchor.presentationTime preferably represents the time on the Watermark Media Timeline corresponding to the alignment point of a watermark payload whose interval code is contained in the componentAnchor.intervalCodeAnchor element. For an audio watermark component, the alignment point of a watermark payload corresponds is the sampling instant of the first sample of the first symbol of the audio watermark Cell conveying that payload. For a video watermark component, the alignment point of a watermarkU. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00payload is the sampling instant of the first frame of the VP1 Message Group conveying that payload.

[0251] • The presence of a componentAnchor.systemTime element will preferably be optional.

[0252] It is understood that the various embodiments of the present invention may be implemented individually, or collectively, in devices comprised of various hardware and / or software modules and components. These devices, for example, may comprise a processor, a memory unit, an interface that are communicatively connected to each other, and may range from desktop and / or laptop computers, to consumer electronic devices such as media players, mobile devices, and the like. For example, FIG. 10 illustrates a block diagram of a device 1000 within which the various disclosed embodiments may be implemented. The device 1000 comprises at least one processor 1002 and / or controller, at least one memory 1004 unit that is in communication with the processor 1002, and at least one communication unit 1006 that enables the exchange of data and information, directly or indirectly, through the communication link 1008 with other entities, devices and networks. The communication unit 1006 may provide wired and / or wireless communication capabilities in accordance with one or more communication protocols, and therefore it may comprise the proper transmitter / receiver antennas, circuitry and ports, as well as the encoding / decoding capabilities that may be necessary for proper transmission and / or reception of data and other information.

[0253] Referring back to FIG. 10 the device 1000 and the like may be implemented in software, hardware, firmware, or combinations thereof. Similarly, the various components or sub-components within each module may be implemented in software, hardware, or firmware. The connectivity between the modules and / or components within the modules may be provided using any one of the connectivity methods and media that is known in the art, including, but not limited to, communications over the Internet, wired, or wireless networks using the appropriate protocols.U. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00

[0254] Various embodiments described herein are described in the general context of methods or processes, which may be implemented in one embodiment by a computer program product, embodied in a computer-readable medium, including computerexecutable instructions, such as program code, executed by computers in networked environments. A computer-readable medium may include removable and non-removable storage devices including, but not limited to, Read Only Memory (ROM), Random Access Memory (RAM), compact discs (CDs), digital versatile discs (DVD), etc.Therefore, the computer-readable media that is described in the present application comprises non-transitory storage media. Generally, program modules may include routines, programs, objects, components, data structures, etc. that perform particular tasks or implement particular abstract data types. Computer-executable instructions, associated data structures, and program modules represent examples of program code for executing steps of the methods disclosed herein. The particular sequence of such executable instructions or associated data structures represents examples of corresponding acts for implementing the functions described in such steps or processes.

[0255] The foregoing description of embodiments has been presented for purposes of illustration and description. The foregoing description is not intended to be exhaustive or to limit embodiments of the present invention to the precise form disclosed, and modifications and variations are possible in light of the above teachings or may be acquired from practice of various embodiments. The embodiments discussed herein were chosen and described in order to explain the principles and the nature of various embodiments and its practical application to enable one skilled in the art to utilize the present invention in various embodiments and with various modifications as are suited to the particular use contemplated. The features of the embodiments described herein may be combined in all possible combinations of methods, apparatus, modules, systems, and computer program products.

Claims

U. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00WHAT IS CLAIMED IS:

1. A method for embedding watermarks in content comprising:receiving content;embedding ATSC soft binding watermarks in the content using a claim generator, wherein the soft binding watermarks place corresponding ATSC soft binding assertions in a C2PA Asset Manifest;the claim generator selecting watermark payloads to embed such that each unique pair of Server Code and Interval Code values are associated only with a single interval on a media timeline of a single Asset; andadding ATSC soft binding assertions to the Asset manifest for all ATSC soft binding watermarks that the claim generator embeds.

2. The method according to claim 1 further comprising using the claim generator to add ATSC soft binding assertions to a manifest of Assets that contain preexisting ATSC watermarks, wherein the preexisting ATSC watermarks become soft binding watermarks.

3. The method according to claim 1 wherein the soft binding watermarks comprise VP1 watermark segments.

4. The method according to claim 1 further comprising using the claim generator to provide users with the option of whether or not to embed an ATSC soft binding watermark in an Asset.

5. The method according to claim 1 further comprising the claim generator providing users with the option of where an ATSC soft binding watermark is embedded in an Asset.U. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO006. The method according to claim 1 wherein coincident VP1 Audio Watermark Segments and VP1 Video Watermark Segments carry the same VP1 Payload.

7. The method according to claim 1 wherein coincident VP1 Audio Watermark Segments and VP1 Video Watermark Segments carry different VP1 Payloads.

8. The method according to claim 1 wherein the ATSC soft binding assertion contains one or more of the following:a Server Code value conveyed in the ATSC soft binding watemiark;an Interval Code value conveyed in the ATSC soft binding watermark;a mediaType value indicating the type of content in which an ATSC soft binding watemiark is embedded; anda componentAnchor providing a mapping between a value conveyed in a VP 1 Payload and a location in the content where the ATSC soft binding watemiark conveying that value is embedded.

9. A method for recovering provenance infomiation from content comprising:receiving content;detecting watermarks from the received content;identifying watermark segments;receiving a recovery data request;issuing a manifest recovery request in response to the recovery data request; recovering an active manifest in response to the manifest recovery request; and using the retrieved manifest to determine whether one or more of the identified VP1 watemiark segments constitutes a valid ATSC soft binding assertion.

10. The method according to claim 9 wherein the detected watermarks are ATSC watermarks.U. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO0011. The method according to claim 9 wherein the determining further comprises determining whether the retrieved manifest is valid.

12. The method according to claim 10 wherein the determining further comprises determining whether the retrieved manifest includes an ATSC soft binding assertion.

13. The method according to claim 12 wherein the determining further comprises determining whether the detected watermark segments match the descriptions in the ATSC soft binding assertion.

14. The method according to claim 10 further comprising determining whether any watermark segments have an invalid soft binding watermark by determining that the detected watermark segment has an associated recovery data request that does not include a C2PA manifest URL.

15. A method of providing provenance authentication of content comprising:receiving a media object;receiving content;embedding ATSC soft binding watermarks in the content using a claim generator, wherein the soft binding watermarks place corresponding ATSC soft binding assertions in a C2PA Asset Manifest;the claim generator selecting watermark payloads to embed such that each unique pair of Server Code and Interval Code values are associated only with a single interval on a media timeline of a single Asset;adding ATSC soft binding assertions to the Asset manifest for all ATSC soft binding watermarks that the claim generator embeds;distributing the media with including the embedded media object;U. S. Provisional Patent Application Attorney Docket No.: 077058-8103. WO00determining if the received media object contains a manifest corresponding to a registered distributor, and if it does, determining if the manifest validates the media object, and if it does, declaring the media validated;if the media object does not contain a manifest or if the manifest is not validated, determining if the media object contains a watermark, and if so, using the watermark to retrieve the manifest;determining if the retrieved manifest has a digital signature that corresponds to an approved content distributor, and if so, determining if the manifest validates the content, and if so declaring the media object validated; andif the manifest does not validate the content, initiating a canonical process to retrieve a canonical representation of the media object.

16. The method according to claim 15 wherein the content distributor is a broadcaster.

17. The method according to claim 1 wherein the single interval is about 1.5 seconds.

18. A method for embedding watermarks in content comprising:receiving content;embedding soft binding watermarks in the content using a claim generator, wherein the soft binding watermarks place corresponding soft binding assertions in a C2PA Asset Manifest;the claim generator selecting watermark payloads to embed such that unique values are associated only with a single interval on a media timeline of a single Asset; andadding soft binding assertions to the Asset manifest for all soft binding watermarks that the claim generator embeds.