Certified text file
By generating verifiable graphic data on the support, and using a limited set of graphic symbols to generate human-readable graphic symbols and machine-readable error correction data, the problem of file forgery and tampering in the prior art is solved, and efficient file authenticity verification is achieved.
Patent Information
- Application Number
- CN202080041604.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-06-03
- Filing Date
- 2020-05-28
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2040-05-28
AI Technical Summary
The prior art is difficult to effectively prevent the forgery and tampering of digital files or printed files, especially when the visual representation of the file content changes, it is difficult to distinguish the authenticity of the hash value.
By generating verifiable graphic data on the support, using a limited collection of graphic symbols to generate human-readable graphic symbols and machine-readable error correction data, eliminating data redundancy, avoiding visual comparisons, and solving the code size problem of large text data.
It realizes automatic detection of graphic symbol layout modification, improves the reliability and robustness of file authenticity verification, reduces dependence on visual comparison, and is suitable for the protection of large text data.
Smart Images

Figure CN113924567B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of security and anti-fraud methods and systems. In particular, the present invention relates to protecting data (such as the text data of a valuable document (digitized or printed)) from forgery or tampering. Background Art
[0002] The problems of counterfeiting and tampering with digital or printed documents are well-known, serious, and growing. Examples of forging markings on data in original (digital or physical) documents such as identity documents or diplomas are well-known, and the concerns are even worse if one considers digital copies of the original (possibly genuine) digital / physical documents. Simply tracking identifiers such as serial numbers or even including some digital watermarks is usually a weak response, as counterfeiters can also easily copy such numbers or digital watermarks.
[0003] There are many known techniques for protecting the content of digital or physical documents against forgery. For example, by obtaining a hash of digital data from an original digital document or from a digitized version of an original physical document (e.g., by scanning the document and extracting text data via OCR scanner software), and storing the hash value in a ledger (e.g., just a database or a blockchain). Then, by scanning the data content of the document under review visually represented on a physical support (e.g., the support can be the paper on which the data is printed), calculating the hash value of the said data content, and then comparing the calculated hash value with the hash value stored in the ledger corresponding to the original document, changes in the data content can be detected. However, the drawback of this method is that due to some changes in the visual representation of the support of the document content, even if the document is genuine, the calculated hash value may be different from the stored hash value. Such a difference may also be caused by the way the scanning operation is performed, or even depend on the type of scanner used (two different scanners may give two opposite conclusions). The same is true for digital documents displayed on a support such as (e.g., the screen of a computer): even if the document content is genuine, when scanning the displayed content for verification, any change in the displayed content will result in a hash value different from the stored hash value. Thus, in practice, scanning a document and calculating the hash value of the captured image does not work, because usually a different hash is produced each time the document is scanned. Using an OCR ("Optical Character Recognition") scanner before calculating the hash value does not solve the above problems, because no OCR system is 100% accurate: for example, if just a dot becomes a comma, or the letter "l" (i.e., L) becomes "1" (i.e., one), the calculated hash will be different.
[0004] Some prior art for protecting paper documents (e.g., certificates, diplomas, contracts, etc.) that extract very little information from the document involves creating a 2D barcode (e.g., QR code), putting the extracted information into the 2D barcode and printing it on the document. Each time the 2D barcode is read, the same result is obtained, but the drawback is that the information included in the barcode has to be compared with the information printed on the document. Additionally, in the case of wanting to protect, for example, a full text page, the full text has to be put into the barcode, and thus the barcode becomes large in size and requires a lot of space on the page, which is considered disturbing by the reader (so the full text that can actually be encoded is limited in size), and it becomes necessary (and cumbersome) to compare thousands of characters between the printed text and the text decoded from the barcode.
[0005] It is known that US 6 047 093 A, EP 2 048 867, and US 2014 / 145661 disclose determining errors in text printed on a document and forming information about the error. Summary of the Invention
[0006] The present invention aims to solve the above-mentioned drawbacks in the prior art regarding the forgery and tampering of digital or printed documents, which is achieved by allowing the automatic detection of any modification of the arrangement of the marked (respectively, displayed) graphical symbols (e.g., text) with respect to the original arrangement. In particular, the redundancy between the data in the code and the data in the printed (respectively, displayed) text is eliminated, the burden of visually comparing the text in the code with the printed (respectively, displayed) text is avoided, and at the same time, the problem that the size of the code is too large when the size of the data of the printed (respectively, displayed) text is large is solved.
[0007] Therefore, the present invention aims to provide a reliable and robust method for generating visible graphical symbols (e.g., text characters or glyphs) on a material support (such as a display (e.g., the screen of a computer) or a substrate (e.g., paper, label, packaging)) and avoiding the drawbacks of the prior art, the consistency of the visible graphical symbols with a true reference graphical symbol can be easily checked by a user reading the visible graphical symbols. The graphical symbols are human-readable and are taken from a given finite set of graphical symbols (e.g., text characters from an alphabet). Thus, the human-readable graphical symbols displayed or marked on a substrate according to the present invention can be verified by a user, and any attempt to modify any part of the graphical symbols can be detected.
[0008] Therefore, the present invention relates to a "marking method", that is, a method for generating verifiable graphical data on a support, which is a display or a substrate, by using a given finite set of graphical symbols, the method comprising the following steps:
[0009] - Storing in a memory of a processing unit a graphic data block comprising a digital representation of a graphic symbol;
[0010] - Using the processing unit to process the digital representation of the graphic symbol of the stored graphic data block with an error correction code programmed in the processing unit to generate error correction data in a corresponding error correction data block;
[0011] - Using the processing unit to format the graphic data block and the error correction data block to respectively provide a human-readable representation of the graphic symbol of the graphic data block in a human-readable graphic data block, and a machine-readable representation of the error correction data of the error correction data block separate from the human-readable representation of the graphic symbol of the graphic data block in a machine-readable error correction data block, thereby obtaining a corresponding verifiable graphic data block comprising the human-readable graphic data block and the machine-readable error correction data block; and
[0012] (i) Displaying on a display connected to the processing unit the human-readable graphic symbol of the obtained verifiable graphic data block and the machine-readable representation of the corresponding error correction data, or
[0013] (ii) Marking on the substrate from the processing unit the human-readable graphic symbol of the obtained verifiable graphic data block and the machine-readable representation of the corresponding error correction data via a marking device connected to the processing unit and equipped with a control unit capable of operating to control the marking operation based on data received from the processing unit,
[0014] Thereby providing together on the support a human-readable graphic symbol verifiable by a user and corresponding machine-readable error correction data.
[0015] The machine-readable representation of the error correction data can be any one of an alphanumeric representation and a bar code representation (1D bar code or 2D bar code, such as DataMatrix code or QR code). Preferably, the bar code can be a conventional PDF417 linear bar code, which can be read by a simple linear scanner sweeping across the bar code. Preferably, the graphic symbol can be a text character, and the finite set of graphic symbols is an alphabet. Preferably, the marking device can be a printer (such as an inkjet printer), and the substrate can be paper or a label. Also preferably, the error correction code can be a Reed-Solomon error correction code.
[0016] In a first variant, the above marking method may include the following additional steps:
[0017] - Calculate a hash value of any part of the graphic data block, or the error correction data block, or the data block generated by the concatenation of the graphic data block and the error correction data block, by using a hash function programmed on the processing unit; and
[0018] - Store the calculated hash value as a reference hash value in a ledger.
[0019] Hash functions are well-known examples of one-way functions, i.e., functions that are easy to compute but difficult to invert (see, for example, S. Goldwasser and M. Bellare, “Lecture Notes on Cryptography,” MIT, July 2008, http: / / www-cse.ucsd.edu / users / mihir). Preferably, the cryptographic hash function can be from the SHA-2 family, such as SHA-256, which gives a hash value of 256 bits in size: this function is in fact irreversible and collision-resistant, i.e., the probability that two different inputs will result in the same output is negligible. Also preferably, the ledger can be a blockchain, which advantageously provides an immutable data record. Optionally, there can be an additional step: signing the calculated reference hash value with a signature private key via the processing unit to obtain a corresponding signed reference hash value, and storing or further providing the signed reference hash value on a support. With this option, a user having the public key corresponding to the private key can check that the signed reference hash value read on the support is authentic (since it is signed with the correct private key).
[0020] In a second variant of the above marking method, the support comprises a plurality of parts, and the verifiable graphic data block is divided into the same plurality of verifiable graphic data sub-blocks, and thus the corresponding human-readable graphic symbols and the machine-readable representation of the error correction data are spread together on the corresponding parts of the support by the following steps:
[0021] - The graphic data block is divided into a plurality of graphic data sub-blocks, and each graphic data sub-block is formatted to provide a human-readable representation of the graphic symbol of the graphic data sub-block in a corresponding human-readable graphic data sub-block;
[0022] - For each graphic data sub-block, a digital representation of the graphic symbol of the graphic data sub-block is extracted and processed with an error correction code to generate corresponding error correction data in an error correction data sub-block;
[0023] - Each error correction data sub - block is formatted to provide a machine - readable representation of the corresponding error correction data separate from the human - readable representation of the graphical symbol of the corresponding human - readable graphical data sub - block in a corresponding machine - readable error correction data sub - block, thereby obtaining a corresponding verifiable graphical data sub - block including the human - readable graphical data sub - block and the machine - readable error correction data sub - block; and
[0024] - In step (i), display on the display the human - readable graphical symbols of the obtained respective verifiable graphical data sub - blocks and the machine - readable representations of the corresponding error correction data, or
[0025] - In step (ii), mark on the substrate via the marking device the human - readable graphical symbols of the obtained respective verifiable graphical data sub - blocks and the machine - readable representations of the corresponding error correction data received by the control unit from the processing unit,
[0026] Thereby providing, on the support, corresponding human - readable graphical symbols and corresponding machine - readable error correction data that can be verified by the user for each graphical data sub - block of the graphical data block.
[0027] This second variant of the marking method for generating verifiable graphical symbols on a support is particularly applicable to the case of a document with several text pages (i.e., the support has multiple parts): the complete text is divided into multiple segments, each text segment corresponding to a text page. Thus, each page of the document provided on the support includes a human - readable representation of the graphical symbol of the corresponding graphical data sub - block and a separate machine - readable representation of the error correction data of the corresponding error correction data sub - block (e.g., a PDF417 barcode as Figure 1 shown).
[0028] To allow the user to further determine whether the human - readable graphical symbols and the corresponding machine - readable error correction data sub - blocks read on the support (i.e., on the part of the support corresponding to the graphical data sub - block of the graphical data block) are authentic, the above - mentioned second variant of the marking method may further include the features of one of the following two sub - variants.
[0029] According to the first sub - variant of the second variant of the marking method,
[0030] - Calculate a sub - block hash value for each graphical data sub - block, or the corresponding error correction data sub - block, or any part of the data sub - block generated by the concatenation of the graphical data sub - block and the error correction data sub - block, via a hash function programmed on the processing unit;
[0031] - Calculate a corresponding machine - readable representation of the sub - block hash value for each sub - block hash value;
[0032] - Associated with each verifiable graphic data sub-block, a corresponding machine-readable representation of the sub-block hash value is also provided on a corresponding part of the support;
[0033] - A reference aggregate hash value of all sub-block hash values is determined as the concatenation of all calculated sub-block hash values; and
[0034] - The reference aggregate hash value is stored in a ledger,
[0035] Thereby providing, on the support, a corresponding human-readable graphic symbol and corresponding machine-readable error correction data for each graphic data sub-block of the graphic data block that can be authenticated by a user.
[0036] According to a second sub-variant of the second variant of the marking method,
[0037] - For each graphic data sub-block, or a corresponding error correction data sub-block, or any part of a data sub-block generated by the concatenation of the graphic data sub-block and the error correction data sub-block, a sub-block hash value is calculated via a hash function programmed on the processing unit;
[0038] - A reference aggregate hash value of all sub-block hash values is determined as the root node value of a tree that takes the calculated sub-block hash values as leaf node values, the tree including nodes arranged in the tree according to a given node ordering, the tree including node layers from the leaf nodes to the root node, and each non-leaf node value of the tree corresponding to the hash value of the concatenation of the corresponding node values of the sub-nodes of the tree according to the tree concatenation ordering, and the root node value corresponding to the hash value of the concatenation of the node values of the nodes in the penultimate node layer of the tree according to the tree concatenation ordering;
[0039] - For each sub-block hash value, an associated sub-block verification path key is determined as a series of hash values of selected non-leaf nodes of the tree required to retrieve the root node value from the sub-block hash value;
[0040] - The machine-readable representation of each sub-block verification path key is included in the verifiable graphic data sub-block in association with the respective corresponding graphic data sub-block and error correction data sub-block, and the verifiable graphic data sub-block is also formatted to provide a machine-readable representation of the sub-block verification path key separate from the human-readable representation of the associated graphic data sub-block and the machine-readable representation of the associated error correction data sub-block; and
[0041] (iii) The reference aggregate hash value is stored in a ledger, or
[0042] (iv) Making the reference aggregate hash value available to the user,
[0043] Thereby, for each graphic data sub-block of the graphic data block on the support, a corresponding human-readable graphic symbol that can be authenticated by the user and corresponding machine-readable error correction data are provided.
[0044] The present invention also relates to a "verification method" corresponding to the above "marking method", that is, a method for verifying a human-readable graphic symbol, the human-readable graphic symbol being provided on a support together with a machine-readable representation of error correction data, the human-readable graphic symbol and the machine-readable representation of the error correction data having been generated according to the method for generating a verifiable graphic symbol on the support described above. The method for verifying the human-readable graphic symbol includes the following steps:
[0045] - Scanning the human-readable graphic symbol on the support using a scanner to obtain a scanned graphic data block via image processing of the scanned human-readable graphic symbol. The scanned graphic data block is a digital representation of the scanned human-readable graphic symbol. The scanner is equipped with an imaging unit and a scanner processing unit having a scanner memory and connected to a scanner display;
[0046] - Scanning the machine-readable representation of the error correction data on the support using the scanner to obtain corresponding scanned error correction data in the scanned error correction data block via a machine-readable decoder programmed on the scanner processing unit. The scanned error correction data block is a digital representation of the scanned error correction data;
[0047] - Using an error correction code programmed on the scanner processing unit, using the scanned error correction data of the scanned error correction data block to correct the scanned graphic data block to obtain a corresponding corrected scanned graphic data block; and
[0048] (a) Displaying a visual representation of the corrected scanned graphic data block on the scanner display as a corresponding corrected human-readable graphic symbol, or
[0049] (b) Indicating via the scanner whether the scanned graphic data block contains an error, or
[0050] (c) Storing scan result data specifying whether the scanned graphic data block contains an error in the scanner memory.
[0051] Therefore, according to the present invention, due to the correction of the scanned text, the user can directly visualize (option (a)) the original graphic symbol (e.g., the original text of a document) on the scanner display, and then easily compare the displayed graphic symbol (i.e., the corrected human-readable graphic symbol) with the graphic symbol on the support and detect any changes or fraud.
[0052] The scanner can be a specially dedicated device or can be just a smartphone equipped with a camera and having a programmed application that is operable to run on the processor of the smartphone and perform the steps of the above method of verifying the graphical symbols provided on the support and the corresponding machine-readable error correction data. Some steps of the verification method can also be performed on a remote server in communication with the scanner: for example, the scanner can send the scanned graphical data block and the machine-readable error correction data to the server, and then the appropriately programmed processing component of the server can perform the following steps: obtain the corresponding scanned error correction data, use the scanned error correction data to correct the scanned graphical data block (using the error correction code programmed on the server) to obtain the corresponding corrected scanned graphical data block, and send the corrected scanned graphical data block to the scanner (possibly with an indication of whether the scanned graphical data block contains an error, or storing the scan result data specifying whether the scanned graphical data block contains an error on the server).
[0053] A first variant of the above verification method, wherein the human-readable graphical symbol and the machine-readable error correction data on the support have been generated according to the first variant of the marking method, the hash function is programmed on the scanner processing unit, and the scanner is connected to a scanner communication unit that is operable to communicate with the ledger via a communication link, and the method further includes the following steps:
[0054] - Calculate the scan hash value of any part of the corrected scanned graphical data block, or the scanned error correction data block, or the data block generated by the concatenation of the corrected scanned graphical data block and the scanned error correction data block using the hash function programmed on the scanner processing unit according to the first variant of the marking method;
[0055] - Obtain the reference hash value stored in the ledger via the scanner communication unit and the communication link, and check whether the obtained reference hash value matches the scan hash value; and
[0056] (e) Indicate the result of the check operation, or
[0057] (f) Store the result of the check operation in the scanner memory.
[0058] Thus, even if a single bit of data in the data initially provided on the support is modified, the scan hash value will be very different from the reference hash value, and the modification will be detected.
[0059] In a second variant of the above verification method, wherein the human-readable graphical symbol and the machine-readable error correction data on the support have been generated according to the second variant of the marking method,
[0060] - The operation of scanning the human-readable graphical symbol on the support includes scanning the sub-block graphical symbol of the corresponding graphical data sub-block to obtain the corresponding scanned graphical data sub-block as a digital representation of the scanned sub-block graphical symbol through image processing;
[0061] - The operation of scanning the machine-readable error correction data on the support includes scanning the error correction data of the corresponding error correction data sub-block to obtain the corresponding scanned error correction data sub-block;
[0062] - The operation of correcting the scanned graphical data block includes using the corresponding scanned error correction data sub-block to correct the graphical data of the scanned graphical data sub-block to obtain the corresponding corrected scanned graphical data sub-block; and
[0063] - The operation of displaying the visual representation of the corrected scanned data block (a) includes displaying the visual representation of the corrected scanned graphical data sub-block;
[0064] - The operation of indicating whether the scanned graphical data block contains an error (b) includes indicating whether the scanned graphical data sub-block contains an error; and
[0065] - The operation of storing the scan result data (c) includes storing whether the scanned graphical data sub-block contains an error.
[0066] The first sub-variant of the second variant of the verification method, wherein the human-readable graphical symbol and the machine-readable error correction data on the support have been generated according to the first sub-variant of the second variant of the marking method, the hash function and the error correction code are programmed on the scanner processing unit, and the scanner is also capable of operating to read and decode the machine-readable representation of the sub-block hash value on the support via the scanner processing unit, the scanner is connected to the scanner communication unit, the scanner communication unit is capable of operating to communicate with the ledger via a communication link, and the method further includes the following steps:
[0067] - Using the hash function programmed on the scanner processing unit and according to the operations performed to calculate the sub-block hash value, calculate the scan sub-block hash value of any part of the corresponding corrected scanned graphical data sub-block, or the corresponding scanned error correction data sub-block, or the data sub-block generated by the concatenation of the corrected scanned graphical data sub-block and the scanned error correction data sub-block for each part of the support;
[0068] - In the case where the hash value of a scanned sub-block for a part of the support cannot be calculated, scan and decode the machine-readable representation of the sub-block hash value on that part of the support to obtain the corresponding decoded sub-block hash value, and use the decoded sub-block hash value as the scanned sub-block hash value for that part of the support;
[0069] - Calculate the aggregated scanned hash value as the concatenation of all scanned sub-block hash values;
[0070] - Obtain the reference aggregated hash value stored in the ledger via the scanner communication unit and the communication link, and check whether the obtained reference aggregated hash value matches the aggregated scanned hash value; and
[0071] - Indicate the result of the checking operation via the scanner.
[0072] This first sub-variant of the second variant of the marking method allows the authenticity of the graphical symbols of all readable parts of the support to be checked by retrieving the correct aggregated hash value, even if some parts are unreadable (e.g., due to severe alteration of the graphical symbols and / or error correction data provided on those parts). In fact, if the scanned sub-block hash value cannot be calculated for a certain part of the support, the scanned sub-block hash value can still be obtained by reading and decoding the machine-readable representation of the sub-block hash value on that part of the support, and the decoded hash value in the concatenation of all hash values is used to determine the candidate aggregated hash value to be compared with the reference aggregated hash value.
[0073] A second sub-variant of the second variant of the verification method, wherein the human-readable graphical symbols and the machine-readable error correction data on respective parts of the support have been generated according to the second sub-variant of the second variant of the marking method, the reference aggregated hash value is stored in the ledger, the scanner is connected to a scanner communication unit, the scanner communication unit is operable to communicate with the ledger via a communication link, and the scanner is further operable to read and decode the machine-readable representation of the sub-block verification path key on a corresponding part of the support and calculate an aggregated hash value based on a pair of corresponding sub-block hash values and sub-block verification path keys, the method further comprising the steps of:
[0074] - Calculate the scanned sub-block hash value of the selected corrected scanned graphical data sub-block, or the corresponding scanned error correction data sub-block, or any part of the data sub-block generated by the concatenation of the corrected scanned graphical data sub-block and the scanned error correction data sub-block, using the hash function programmed in the scanner processing unit and according to the operations performed for calculating the sub-block hash value;
[0075] - Use the scanner to scan a machine-readable representation of a sub-block verification path key corresponding to a selected corrected scanned graphic data sub-block on a corresponding part of the support, and extract the corresponding scanned sub-block verification path key;
[0076] - Use the calculated scanned sub-block hash value and the scanned sub-block verification path key to calculate a scanned aggregate hash value;
[0077] - Obtain the reference aggregate hash value stored in the ledger via the scanner communication unit and the communication link, and check whether the obtained reference aggregate hash value matches the scanned aggregate hash value; and
[0078] - Indicate the result of the check operation via the scanner.
[0079] This second sub-variant of the second variant of the verification method allows the authenticity of individual pages of a document to be checked independently, since the candidate root node hash value can be calculated from the data read on individual pages and compared with the reference aggregate hash value.
[0080] A third sub-variant of the second variant of the verification method, wherein the human-readable graphic symbol and the machine-readable error correction data on the support have been generated according to the second sub-variant of the second variant of the marking method, the reference aggregate hash value available to the user is stored in the scanner memory, and the scanner is also capable of operating to read and decode a machine-readable representation of a sub-block verification path key on a corresponding part of the support and calculate an aggregate hash value based on a pair of corresponding sub-block hash values and sub-block verification path keys, the method further comprising the steps of:
[0081] - Use a hash function programmed in the scanner processing unit and based on the operations performed to calculate a sub-block hash value, to calculate a scanned sub-block hash value of any part of a selected corrected scanned graphic data sub-block, or a corresponding scanned error correction data sub-block, or a data sub-block generated by the concatenation of the corrected scanned graphic data sub-block and the scanned error correction data sub-block;
[0082] - Use the scanner to scan a machine-readable representation of a sub-block verification path key corresponding to a selected corrected scanned graphic data sub-block on a corresponding part of the support, and extract the corresponding scanned sub-block verification path key;
[0083] - Scan the reference aggregate hash value on the support to obtain a scanned reference aggregate hash value;
[0084] - Use the calculated scanned sub-block hash value and the scanned sub-block verification path key to calculate an aggregate scanned hash value;
[0085] - Check whether the reference aggregated hash value stored in the scanner memory matches the aggregated scanned hash value; and
[0086] - Indicate the result of the checking operation via the scanner.
[0087] This third sub-variant of the second variant of the verification method allows the authenticity of individual pages of a document to be checked independently offline, since the candidate root node hash values can be calculated from the data read on the individual pages and compared with the reference aggregated hash values stored in the scanner memory.
[0088] The present invention also relates to an alternative verification method for human-readable graphical symbols provided together with machine-readable error correction data on a display of a computer, the human-readable graphical symbols and the machine-readable error correction data having been generated according to the method for generating verifiable graphical symbols on the display described above, the computer having a scanning application programmed on a processor, the scanning application being operable to scan the displayed human-readable graphical symbols and machine-readable error correction data, the method comprising the steps of:
[0089] - Scan the displayed human-readable graphical symbols via the scanning application running on the computer processor to obtain a scanned graphical data block that is a digital representation of the scanned human-readable graphical symbols;
[0090] - Scan the displayed machine-readable error correction data and decode the scanned machine-readable error correction data via a machine-readable decoder of the scanning application running on the computer processor to obtain corresponding scanned error correction data in the scanned error correction data block;
[0091] - Use the scanned error correction data of the scanned error correction data block to correct the scanned graphical data block using an error correction code of the scanning application running on the computer processor to obtain a corresponding corrected scanned graphical data block; and
[0092] (a) Display a visual representation of the corrected scanned graphical data block on the display as a corrected human-readable graphical symbol, or
[0093] (b) Display an indication specifying whether the scanned graphical data block contains an error, or
[0094] (c) Store scanning result data specifying whether the scanned graphical data block contains an error in the memory of the computer.
[0095] This alternative verification method (as the "verification method of the displayed data") is particularly suitable for supporting office software capabilities (e.g., such as a text processing application) to detect fraud or errors in text files (e.g., contracts, reports...) displayed on a computer screen, where the text files have been generated on a computer or have been downloaded into a computer (e.g., from an external memory such as a USB key, or e.g., via a communication link with an external server such as an email server). A specific application running on the computer actually performs the operations performed by a scanner in the verification method.
[0096] The present invention also relates to a support having a machine-readable representation marked with a human-readable graphical symbol and associated error correction data according to the above-mentioned marking method, or any one of its first variant and second variant, or any one of its first sub-variant and second sub-variant of the second variant. The support is also marked with:
[0097] - a machine-readable representation of the sub-block hash value according to the first sub-variant of the second variant of the marking method, or
[0098] - a machine-readable representation of the associated verification path key according to the second sub-variant of the second variant of the marking method.
[0099] According to another aspect, the present invention relates to a scanner equipped with an imaging unit, a scanner processing unit, and a scanner display, wherein the scanner processing unit is programmed to make the scanner operable to read verifiable graphical data marked on a support according to the present invention by implementing the steps of the verification method or its second variant and the third sub-variant of its second variant.
[0100] The scanner may also be equipped with a scanner communication unit operable to communicate with a ledger via a communication link, wherein the scanner processing unit is also programmed to make the scanner operable to obtain a hash value from the ledger by implementing the steps of a method according to any one of the first variant of the verification method or the first sub-variant or the second sub-variant of the second variant of the verification method.
[0101] Finally, the present invention also relates to a computer program product which, when run on a computer equipped with a processor, a memory, and a display, is operable to implement the steps of an alternative verification method (i.e., the "verification method of the displayed data") to verify a human-readable graphical symbol provided together with machine-readable error correction data on the display, wherein the human-readable graphical symbol and the machine-readable error correction data are generated according to the marking method.
[0102] The present invention will be described more fully hereinafter with reference to the accompanying drawings, in which the same reference numerals denote the same elements in different drawings, and in which the prominent aspects and features of the present invention are shown. Description of the Drawings
[0103] Figure 1 Shows an example of a support marked with a verifiable graphical symbol according to the marking method of the present invention.
[0104] Figure 2 Is a flowchart showing the process of generating and marking a verifiable graphical symbol on a substrate according to the marking method of the present invention.
[0105] Figure 3 Is a flowchart showing the process of generating and displaying a verifiable graphical symbol on a display according to the marking method of the present invention.
[0106] Figure 4 Is a flowchart showing the process of generating and providing a verifiable graphical symbol on a support according to a second variant of the marking method of the present invention.
[0107] Figure 5 Shows an example of a hash tree used in a second sub - variant of a second variant of the marking method according to the present invention.
[0108] Figure 6 Is a flowchart showing the process of verifying a graphical symbol and machine - readable data provided on a support according to the verification method of the present invention.
[0109] Figure 7 Is a flowchart showing an embodiment of a second variant of the verification method according to the present invention. Detailed Description of the Invention
[0110] Figure 1 Shows an example of a support 100 in the form of a substrate (here, a sheet of paper), which is marked with a human - readable representation of a graphical symbol 110 (here, letters, punctuation characters, and numbers printed on the paper 100) and a machine - readable 2D barcode 130 (here, a PDF417 barcode, i.e., a "Portable Data File" 417 barcode). The graphical symbol represents the text of a contract printed in the text area 120 of the support 100, and the machine - readable 2D barcode is printed below the text area 120. The text in the text area 120 is the human - readable representation of the corresponding graphical data block of the graphical symbol.
[0111] 2D barcodes generally include the following parts:
[0112] - A positioning pattern (e.g., an "L" shape and clock lines for a data matrix, or three large squares for a QR code);
[0113] - Some information areas regarding the code format;
[0114] - A data area containing data; and
[0115] - Machine-readable error correction data for correcting reading errors (e.g., Reed-Solomon error correction data).
[0116] Error correction codes typically use a corresponding table, i.e., a mapping between image symbols in a given finite set of reference graphical symbols (e.g., glyphs, such as the readable characters of an alphabet) and one-to-one corresponding codes (e.g., symbols encoded on a given number of m bits).
[0117] The PDF417 barcode 130 is a well-known stacked linear barcode (ISO standard 15438) that can be read by a simple linear scan across the barcode. In Figure 1 the embodiment, the PDF417 barcode 130 is a machine-readable representation of an error correction data block that is obtained by applying an error correction code (here, a conventional Reed-Solomon code) to a graphical data block of a graphical symbol arrangement corresponding to the text shown in the text area 120. The PDF417 barcode 130 also (as usual) contains data related to the version of the (Reed-Solomon) code used for calculating the error correction data, data related to the font, the font size and the line spacing of the text, the number of lines and columns of the text, and the relative position of the text area with respect to the markers 140 (here, simple markers specifying the corners of the rectangular text area 120) defining the boundaries of the graphical data block. Optionally, the barcode 130 may also contain signature data. The signature data may be, for example, a signature of a digital representation of the text via a private encryption key (the signature may be decrypted via the corresponding public key).
[0118] The text printed in the text area 120 and the printed PDF417 barcode 130 are examples of a human-readable graphical symbol HrGS and a machine-readable representation of corresponding error correction data MrECD obtained by the Figure 2 shown marking method. In fact, Figure 2A flowchart showing the process of generating verifiable graphic data VGD on a substrate (here, paper) by a processing unit (CPU) that can verify graphic data blocks VGDB, and marking the substrate via a marking device (such as an inkjet printer) that has received the verifiable graphic data blocks VGDB. A graphic data block GDB210 containing digital representations DGS of graphic symbols DGS is stored in the memory of the CPU, where each graphic symbol belongs to a given finite set of M (M≥1) graphic symbols {GS(1),..., GS(M)}. For example, M is the finite set of 26 letters A to Z of the English alphabet. Each graphic symbol GS(i) (i∈{1,..., M}) has its corresponding digital representation DGS(i), and the digital representation of the graphic symbols DGS of the graphic data block GDB contains as many DGS(i) as there are graphic symbols in the text (e.g., the text in text area 120). Processing starts 200 by extracting 220 the digital representation of the graphic symbols DGS from the stored graphic data block GDB, and the extracted digital representation of the graphic symbols DGS is processed with a programmed error correction code ECC to obtain the corresponding error correction data ECD. These error correction data ECD are represented in an error correction data block ECDB 230. The obtained error correction data block ECDB is then formatted 240 to provide the corresponding machine-readable error correction data MrECD represented in a machine-readable error correction data block MrECDB. The graphic data block GDB is also formatted to obtain 215 the corresponding human-readable representation HrGS of its graphic symbols included in a human-readable graphic representation data block HrGDB. The resulting verifiable graphic data block VGDB is obtained 250, which consists of two corresponding data blocks (human-readable graphic representation data block HrGDB and machine-readable error correction data block MrECDB). Symbolically: VGDB = HrGDB + MrECDB. The obtained verifiable graphic data block VGDB is then sent to the marking device (here, a printer), and its content is marked 260 (i.e., printed) on the substrate 100 according to the formatting as the corresponding verifiable graphic data VGD. The marked VGD contains the corresponding human-readable graphic symbols HrGS and machine-readable error correction data MrECD (symbolically: VGD = HrGS + MrECD) respectively set on the paper 100 according to the formatting (i.e., as separate data blocks), which represents the end 270 of the process of generating verifiable graphic data on the substrate 100 (see step (ii) of the above marking method).
[0119] As Figure 3 shown in the flowchart, the text can be displayed on a display of, for example, a tablet or computer instead of being marked on the substrate. As in the previous Figure 2In it, a graphic data block GDB 310 represented by numbers and containing graphic symbols DGS is stored in the memory of the CPU (each graphic symbol belongs to a given finite set {GS(1),..., GS(M)} of M≥1 graphic symbols). The graphic data block GDB contains as many digital representations DGS(i) as there are graphic symbols GS(i) in the displayed text. By extracting 320 the digital representations of the graphic symbols DGS from the stored graphic data block GDB, the processing starts 300, and the extracted DGS are processed with a programmed error-correcting code ECC to obtain the corresponding error-corrected data ECD. These error-corrected data ECD are included in an error-corrected data block ECDB 330, and the ECDB 330 is then formatted 340 to provide the corresponding machine-readable error-corrected data MrECD included in a machine-readable error-corrected data block MrECDB. The graphic data block GDB is also formatted to obtain 315 the corresponding human-readable representation HrGS of its graphic symbols included in a human-readable graphic representation data block HrGDB. A verifiable graphic data block VGDB (symbolically, VGDB = HrGDB + MrECDB) consisting of two corresponding data blocks HrGDB and MrECDB is obtained 350. Then, the verifiable graphic data block VGDB is displayed 360 on a display as a separate human-readable representation HrGS of the graphic symbols and a machine-readable representation MrECD of the error-corrected data according to the formatting, which represents the end 370 of the process of generating a verifiable graphic symbol on a support (see step (i) of the above marking method).
[0120] According to the present invention, several variants and sub-variants of the marking method increase the confidence level of the consistency between the human-readable graphic symbols directly readable by the user on a support and the human-readable version that can be extracted from the machine-readable representation of the error-corrected data (read by a dedicated device). These variants correspond to the above first variant and second variant.
[0121] The first variant of the marking method uses the quasi-irreversibility of a one-way function (such as a hash function). In this first variant, after performing the steps of the above marking method, a hash function H programmed on a processing unit is also used, by calculating the hash value of any part of the graphic data block GDB or the error-corrected data block ECDB or the concatenation of the graphic data block GDB and the error-corrected data block ECDB to obtain the hash of the digital representation of the graphic symbol or the error-corrected data (or some parts of these data). The hash value can be calculated only for the graphic data block (for example, using the hash function SHA-256): H(GDB). Preferably, the hash value is calculated for the complete concatenated block: In the case where the hash value is calculated only for a part of the concatenation of the graphic data block GDB and the error-correcting data block ECDB, it is obvious that the bit length of this part must be sufficient to provide a good level of security, for example, it must be at least equal to 100 bits and preferably have the bit length of the result delivered by the selected hash function: for example, for the SHA-256 hash, the bit length of this part is at least 256 bits (therefore, in fact, the hash is irreversible). Thus, any change in the argument of the hash function, even any change in a single bit (i.e., any change in the graphic symbol or machine-readable data on the support), will generate a different hash value.
[0122] In the first variant of the marking method, the hash value is also stored as a reference hash value H ref in a ledger, preferably in a blockchain (the stored value is actually immutable). Optionally, the reference hash value H ref can be further signed with an encryption key (preferably, the private key Pr k ) (stored in the memory of the processing unit) to obtain the corresponding signed reference hash value S(H ref ), and the signed reference hash value S(H ref ) is stored (e.g., stored in a ledger such as a database or a blockchain) or provided on the support, if the public key Pu k corresponding to the private key Pr k is used to check the signature (i.e., in a ledger such as a database or a blockchain) or provided on the support, then the latter option is compatible with an offline verification process (i.e., verifying that the signed reference hash value has been signed with the correct private key, or even for retrieving H ref by decrypting S(Href) with the public decryption key, such as using the RSA "Rivest-Shamir-Adleman" algorithm).
[0123] The second variant of the marking method shown by the embodiment Figure 4 is very suitable for providing graphic symbols on multiple parts of the support, for example,
[0124] - printing a text file (such as option (ii) of the marking method) that includes multiple pages (e.g., N pages of a report or a contract, etc.), or
[0125] - displaying (such as option (i) of the marking method) a digital version of an N-page text file page by page in a given format (e.g., in Microsoft Word or PDF format) on a screen,
[0126] Among them, each of the N (N≥2) pages marked on the substrate or each of the N pages displayed shows a specific human-readable graphic symbol HrGS(j) (j∈{1,...,N}) and a machine-readable representation MrECD(j) of corresponding error correction data: both are representations obtained from the verifiable graphic data VGD(j) of the corresponding specific verifiable graphic data sub-block VGDSB(j). In these cases, according to the second variant of the marking method, the method starts 400, and the (complete) graphic data block GDB is divided 410 by the processing unit into N sub-blocks GDSB(1),..., GDSB(N) (i.e., one sub-block for each part of the support), where each graphic data sub-block GDSB(j) is formatted to provide 415 the corresponding human-readable representation HrGS(j) of its graphic symbol GS(j) in the corresponding human-readable graphic data sub-block HRGDSB(j). For each graphic data sub-block GDSB(j) (j = 1,…,N), the processing unit generates the corresponding sub-block error correction data by correcting 420 the graphic data sub-block GDSB(j) with a programmed error correction code ECC and then forming 430 the error correction data sub-block ECDSB(j) with the corrected data. The processing unit generates 440 a machine-readable representation of each error correction data sub-block ECDSB(j) as the corresponding machine-readable error correction data sub-block MrECDSB(j). Then, the processing unit formats each sub-block HrGDSB(j) and MrECDSB(j) such that the latter's representation on the support is different from the human-readable representation HrGS(j) of the former's graphic symbol GS(j) to provide 450 the corresponding verifiable graphic data sub-block (symbolically written as VGDSB(j)=HrGDSB(j)+MrECDSB(j)). According to the selected option (i) or (ii) of the marking method, the data of the sub-block VGDSB(j) (j = 1,...,N) is displayed 460 on the display or marked 470 on the substrate (e.g., the substrate), with each mark M(j) of VGD(j) being set on part j of the substrate (e.g., printed on the j-th page of an N-page document), which represents the end 480-490 of the process of generating verifiable graphic data on the support.
[0127] Several sub - variants of the above - mentioned second variant of the marking method increase the confidence level in the authenticity of the machine - readable representation of human - readable graphical symbols or error - correction data provided on a support. These sub - variants are actually the first sub - variant and the second sub - variant. These sub - variants also use the quasi - non - invertibility of one - way functions (e.g., a hash function like the SHA - 256 hash function). In both of these sub - variants, after performing the steps of the above - mentioned second variant of the marking method, a hash function H programmed on a processing unit is also used to obtain the hash of the digital representation of the graphical symbol or the error - correction data (or some parts of this data). Due to the fact that in the second variant of the marking method, the graphical data block GDB and the corresponding error - correction data block ECDB are divided into N sub - blocks (corresponding to N parts of the support), there are several possibilities for defining the corresponding sub - block hash values H(j) (j = 1,..., N) as described above: one of these possibilities must be chosen, and one of these possibilities will be used to calculate the N sub - block hash values in any of these sub - variants (and in the variants of the verification method).
[0128] In the first sub - variant of the second variant of the marking method, the processor unit calculates the sub - block hash value H(j) for each graphical data sub - block GDSB(j) (j = 1,…, N): for example, in a preferred embodiment, the full concatenation of the graphical data sub - block GDSB(j) and the error - correction data sub - block ECDSB(j) is chosen for the sub - block hash value, i.e., Generally, the sub - block hash value H(j) (j = 1,..., N) is defined according to one of the following possibilities: we can make H(j)=H(GDSB(j)) or H(j)=H(ECDSB(j)), or by hashing any part of the concatenation of the graphical data sub - block GDSB(j) and the error - correction data sub - block ECDSB(j), i.e., of the part)(with constraints on the bit - length of the part already mentioned).
[0129] Then, the machine-readable representation MrH(j) of each sub-block hash value H(j) is calculated by the processing unit and associated with the corresponding verifiable graphic data sub-block VGDSB(j) (j = 1, …, N). As a result, in addition to the human-readable representation HrGS(j) of the j-th sub-block graphic symbol (from the verifiable graphic data sub-block VGDSB(j)) and the machine-readable representation MrECD(j) of the j-th sub-block error correction data, the j-th page of the document also includes the machine-readable representation MrH(j) of the j-th sub-block hash value. This sub-variant allows for further protection of the sub-block graphic data and the corresponding sub-block error correction data via a one-way hash function, since any modification to the j-th sub-block data will not allow retrieval of the data content of MrH(j). Additionally, this additional advantage is obtained with only limited additional data provided on the support in the form of the machine-readable representation only of the sub-block hash values. In the first sub-variant of the second variant of the marking method, then N sub-block hash values H(j) (j = 1, …, N) are used to calculate a reference aggregated hash value H ref . As described above, it is possible to calculate only N sub-block hash values H(j) (j = 1, ..., N) for the graphic data sub-blocks, i.e., H(j) ≡ H(GDSB(j)). Preferably, the sub-block hash values are calculated for the complete concatenation of the sub-blocks: Thus, any change in the argument of any one of the sub-block hash functions H(j), even a single-bit change (i.e., any change in the sub-block graphic or sub-block machine-readable data on the support), will generate a different value of the aggregated hash value H ref . In this first sub-variant, the processing unit concatenates all N sub-block hash values H(j) (j = 1, …, N) to obtain the reference aggregated hash value (the symbol indicates the concatenation operation). This reference hash value H ref is also stored in the ledger (i.e., in a server or database, preferably in a blockchain).
[0130] Optionally, the memory of the processing unit may also store a key for encrypting digital data, preferably a private key Pr k paired with a public key Pu k (i.e., for asymmetric key encryption), and after the processing unit concatenates all N sub-block hash values to obtain the reference aggregated hash value , it may also sign (i.e., encrypt) the reference aggregated hash value H k with the encryption key (preferably the private key Pr ref ) to obtain a reference aggregated hash value signature S(H ref)。Then the signature can be stored (e.g., stored in the memory of the processing unit, or in a database, or in a blockchain), or the signature can be further provided on a support. The latter option allows for offline verification processing, provided that the corresponding key is used, preferably the public key Pu k associated with the private key Pr k to check that the signature is authentic (i.e., has been obtained with the correct private key Pr k ).
[0131] In the second sub-variant of the second variant of the marking method, after (in the same way as in the first sub-variant above) N sub-block hash values H(j) (j = 1,..., N) have been calculated, the reference aggregated hash value H ref is calculated by the processing unit as the root node value R of a tree (preferably a binary tree). The tree has the N sub-block hash values H(1), H(2), …, H(N - 1), H(N) as leaf nodes, as Figure 5 shown (in the case of an example of a binary tree only with N = 8). Here too, the hash values represent values typically obtained via a one-way function (e.g., a hash function H() of the SHA-256 family). Thus, the tree is generally based on multiple calculated sub-block hash values H(j) (j = 1,..., N), and includes nodes arranged according to a given node ordering in the tree. The tree includes a node layer from leaf nodes a(1, j) (j = 1,..., N) corresponding to the multiple sub-block hash values H(1), H(2),..., H(N - 1), H(N) respectively and non-leaf nodes up to the root node R of the tree. Each non-leaf node of the tree (i.e., the nodes between the leaf nodes and the root node) corresponds to the hash value of the concatenation of the respective hash values of the child nodes of the tree sorted according to the tree concatenation order, and the root node R corresponds to the reference aggregated hash value H ref , i.e., the hash value of the concatenation of the hash values of the nodes of the penultimate node layer in the tree sorted according to the tree concatenation order. In Figure 5 the example of, in the case of n = 8, we thus have eight leaf nodes (the first layer of the tree) a(1, j) = H(j) (j = 1, …, 8), and for the four node values of the second layer: For the two node values of the third (penultimate) layer: and Thus, the root node value r is:
[0132] We note that different tree concatenation orderings can be selected for the respective non-leaf nodes: for example, instead of making we can define This gives different node values.
[0133] Then, for each sub-block hash value H(j) (i.e., for each leaf node a(1,j) (j = 1,..., N) of the tree), the processing unit calculates the associated sub-block verification path key VPK(j). The sub-block verification path key VPK(j) associated with the leaf node a(1,j) (and thus with the sub-block hash value H(j)) is a series of hash values of selected non-leaf nodes of the tree that are necessary to retrieve the root node value R starting from the leaf node a(1,j). The selected non-leaf nodes actually correspond to a specific path in the tree between the leaf node a(1,j) and the root node R. The sub-block verification path key associated with a given leaf node of the tree is actually a sequence of node values from the leaf node layer of each other leaf node having the same parent node as the given leaf node in the tree to the penultimate node layer, and then for each non-leaf node in the next layer of each node in the tree having the same parent node as the previously considered same parent node in the previous layer. In Figure 5 In the example of a binary tree shown with eight leaf nodes a(1,1), …, a(1,8), the eight sub-block verification path keys VPK(1), …, VPK(8) are determined as follows (according to the above definition):
[0134] 1) For a given leaf node a(1,1) = H(1), the associated sub-block verification path key is VPK(1) = {a(1,2), a(2,2), a(3,2)}, from which the root digital signature value R can be retrieved through the following steps (performed according to the node sorting in the tree and the tree concatenation sorting):
[0135] i) According to the given leaf node a(1,1) = H(1) and the leaf node a(1,2) = H(2) in VPK(1) (a(1,2) is the other leaf node "having the same parent node (i.e., node a(2,1)) as the 'given leaf node' (i.e., node a(1,1))", and the parent node value a(2,1) is obtained by (i.e., node obtained).
[0136] ii) According to the obtained a(2,1) and the next node value in VPK(1), i.e., a(2,2) in the next non-leaf node layer, which is the non-leaf node in the tree having the same parent node (i.e., node a(3,1)) as the previously considered same parent node (i.e., node a(2,1)) in the previous layer, the parent node value a(3,1) is obtained through 2))
[0137] iii) Based on the obtained a(3, 1) and the next node value in VPK(1), i.e., a(3, 2) in the penultimate node layer, which is a non-leaf node in the tree having the same parent node (i.e., the root node R) as the previous same parent node (i.e., node a(3, 1)) considered at the previous layer, by obtain the root node value R.
[0138] Note: In this example, we have three steps i), ii), and iii) because the tree has three layers below the root node layer, so the sub-block verification path key contains three node values.
[0139] Therefore, based on VPK(1) = {a(1, 2), a(2, 2), a(3, 2)} associated with a(1, 1), the value of the root node of the tree can be obtained as:
[0140] 2) For the given leaf node a(1, 2) = H(2), the associated sub-block verification path key is VPK(2) = {a(1, 1), a(2, 2), a(3, 2)}, and the root value R can be retrieved from it through the following steps (performed according to the node sorting in the tree and the tree concatenation sorting):
[0141] i) Based on the given a(1, 2) = H(2) and a(1, 1) = H(1) in VPK(2) (a(1, 1) is another leaf node having the same parent node (i.e., node a(2, 1)) as the given leaf node (i.e., node a(1, 2))), by obtain the parent node value a(2, 1),
[0142] ii) Based on the obtained a(2, 1) and the next node value in VPK(2), i.e., a(2, 2) in the next non-leaf node layer, which is a non-leaf node in the tree having the same parent node (i.e., node a(3, 1)) as the previous same parent node (i.e., node a(2, 1)) considered at the previous layer, by obtain the parent node value a(3, 1),
[0143] iii) Based on the obtained a(3, 1) and the next node value in VPK(2), i.e., a(3, 2) in the penultimate node layer, which is a non-leaf node in the tree having the same parent node (i.e., the root node) as the previous same parent node (i.e., node a(3, 1)) considered at the previous layer, by obtain the root node value R.
[0144] Therefore, based on VPK(2) = {a(1, 1), a(2, 2), a(3, 2)} associated with a(1, 2), the value of the root node of the tree can be obtained as:
[0145] 3) For the given leaf node a(1, 3) = H(3), the sub-block verification path key is VPK(3) = {a(1, 4), a(2, 1), a(3, 2)}, and the root value R can be retrieved from it through the following steps (performed according to the node sorting in the tree and the tree concatenation sorting):
[0146] i) Based on a(1, 3) = H(3) and a(1, 4) = H(4) in VPK(3) (a(1, 4) is another leaf node having the same parent node (i.e., node a(2, 2)) as the given leaf node (i.e., node a(1, 3))), by obtain the parent node value a(2, 2),
[0147] ii) According to the obtained a(2, 2) and the next node value in VPK(3), i.e., a(2, 1) in the next non-leaf node layer, which is a non-leaf node in the tree having the same parent node (i.e., node a(3, 1)) as the previous same parent node (i.e., node a(2, 2)) considered in the previous layer, by obtain the parent node value a(3, 1),
[0148] iii) According to the obtained a(3, 1) and the next node value in VPK(3), i.e., a(3, 2) in the penultimate node layer, which is a non-leaf node in the tree having the same parent node (i.e., the root node) as the previous same parent node (i.e., node a(3, 1)) considered in the previous layer, by obtain the root node value R.
[0149] Therefore, the value of the root node of the tree can be obtained as:
[0150] 4) For the given leaf node a(1, 4) = H(4), the sub-block verification path key is VPK(4) = {a(1, 3), a(2, 1), a(3, 2)}, and the root value R can be retrieved from it through the following steps (performed according to the node sorting in the tree and the tree concatenation sorting):
[0151] i) Based on a(1, 3) = H(3) and a(1, 4) = H(4) in VPK(4), by obtain the parent node value a(2, 2),
[0152] ii) According to the obtained a(2, 2) and the next node value in VPK(4), i.e., a(2, 1) in the next non-leaf node layer, by obtain the parent node value a(3, 1),
[0153] iii) Based on the obtained a(3, 1) and the next node value in VPK(4), i.e., a(3, 2) in the penultimate node layer, obtain the root node value R through Obtain the root node value R.
[0154] Therefore, the value of the root node of the tree can be obtained as:
[0155] 5) For the given node a(1, 5) = H(5), the sub-block verification path key is VPK(5) = {a(1, 6), a(2, 4), a(3, 1)}. The root value R can be retrieved from it through the following steps (performed according to the node sorting and tree concatenation sorting in the tree):
[0156] i) Based on a(1, 5) = H(5) and a(1, 6) = H(6) in VPK(5), obtain the parent node value a(2, 3) through Obtain the parent node value a(2, 3).
[0157] ii) Based on the obtained a(2, 3) and the next node value in VPK(5), i.e., a(2, 4) in the next non-leaf node layer, obtain the parent node value a(3, 2) through Obtain the parent node value a(3, 2).
[0158] iii) Based on the obtained a(3, 2) and the next node value in VPK(5), i.e., a(3, 1) in the penultimate node layer, obtain the root node value R through Obtain the root node value R.
[0159] Therefore, the value of the root node of the tree can be obtained as:
[0160] 6) For the given node a(1, 6) = H(6), the sub-block verification path key is VPK(6) = {a(1, 5), a(2, 4), a(3, 1)}. The root value R can be retrieved from it through the following steps (performed according to the node sorting and tree concatenation sorting in the tree):
[0161] i) Based on a(1, 6) = H(6) and a(1, 5) = H(5) in VPK(6), obtain the parent node value a(2, 3) through Obtain the parent node value a(2, 3).
[0162] ii) Based on the obtained a(2, 3) and the next node value in VPK(6), i.e., a(2, 4) in the next non-leaf node layer, obtain the parent node value a(3, 2) through Obtain the parent node value a(3, 2).
[0163] iii) Based on the obtained a(3, 2) and the next node value in VPK(6), i.e., a(3, 1) in the penultimate node layer, through obtain the root node value R.
[0164] Therefore, the value of the root node of the tree can be obtained as:
[0165] 7) For the given node a(1, 7) = H(7), the sub-block verification path key is VPK(7) = {a(1, 8), a(2, 3), a(3, 1)}. The root value R can be retrieved from it through the following steps (performed according to the node sorting in the tree and the tree concatenation sorting):
[0166] i) Based on a(1, 7) = H(7) and a(1, 8) = H(8) in VPK(7), through obtain the parent node value a(2, 4),
[0167] ii) Based on the obtained a(2, 4) and the next node value in VPK(7), i.e., a(2, 3) in the next non-leaf node layer, through obtain the parent node value a(3, 2),
[0168] iii) Based on the obtained a(3, 2) and the next node value in VPK(7), i.e., a(3, 1) in the penultimate node layer, through obtain the root node value R.
[0169] Therefore, the value of the root node of the tree can be obtained as:
[0170] 8) For the given node a(1, 8) = H(8), the sub-block verification path key is VPK(8) = {a(1, 7), a(2, 3), a(3, 1)}. The root value R can be retrieved from it through the following steps (performed according to the node sorting in the tree and the tree concatenation sorting):
[0171] i) Based on a(1, 8) = H(8) and a(1, 7) = H(7) in VPK(8), through obtain the parent node value a(2, 4),
[0172] ii) Based on the obtained a(2, 4) and the next node value in VPK(8), i.e., a(2, 3) in the next non-leaf node layer, through obtain the parent node value a(3, 2),
[0173] iii) Based on the obtained a(3, 2) and the next node value in VPK(8), i.e., a(3, 1) in the penultimate node layer, by obtain the root node value R.
[0174] Therefore, the value of the root node of the tree can be obtained as:
[0175] Generally, in order to retrieve the (candidate) root node value by starting from the given leaf node value and the node values specified in the verification path key associated with the given leaf node, the following steps are performed:
[0176] - Extract the node values of each other leaf node of the tree that has the same parent node as the given leaf node from the sequence of node values in the sub-block verification path key, and calculate the hash value of the concatenation of the given node value according to the sorting of nodes in the tree and the tree concatenation sorting, the extracted node values of each other leaf node, so as to obtain the hash value of the same parent node of the given leaf node;
[0177] - Continuously at each next layer in the tree and until the penultimate node layer:
[0178] Extract the node values of each other non-leaf node of the tree that has the same parent node as the previous same parent node considered in the previous step from the sequence of node values in the sub-block verification path key, and
[0179] calculate the hash value of the concatenation of the node value of each other non-leaf node and the hash value of the obtained previous same parent node according to the sorting of nodes in the tree and the tree concatenation sorting, so as to obtain the node value of the same parent node of the previous same parent node; and
[0180] - Calculate the hash value of the concatenation of the node values of the non-leaf nodes corresponding to the penultimate node layer of the tree according to the sorting of nodes in the tree and the tree concatenation sorting, so as to obtain the root node value of the tree.
[0181] In the next step of the second sub-variant of the second variant of the marking method, the processing unit generates a machine-readable representation MrVPK(j) of each sub-block verification path key VPK(j) (j = 1, ..., N), and includes it in the verifiable graphic data sub-block VGDSB(j) in association with the respective corresponding human-readable graphic data sub-block HrGDSB(j) and machine-readable error correction data sub-block MrECDSB(j). Then, the verifiable graphic data sub-block VGDSB(j) is further formatted to provide a machine-readable representation of the sub-block verification path key (which is separate from the human-readable representation of the associated graphic data sub-block GDSB(j) and the machine-readable representation of the associated error correction data sub-block ECDSB(j)), and then provided on a support (as a component of the respective sub-block verifiable graphic data). Thus, the verifiable graphic data sub-block is now symbolically written as: VGDSB(j) = HrGDSB(j) + MrECDSB(j) + MrVPK(j), j = 1, ..., N. Finally, one of the following steps is further performed:
[0182] (iii) The reference aggregate hash value H ref = R is stored in a ledger (preferably in a blockchain),
[0183] or
[0184] (iv) The reference aggregate hash value H ref = R is made available to the user.
[0185] Optionally, the H k can be signed via the processing unit with a signature private key Pr ref (stored in the memory of the processing unit) to obtain a reference aggregate hash value signature S(H ref ), and the reference aggregate hash value signature S(H ref ) is stored (e.g., in a ledger) or further provided on a support or made available to the user. Then, by using the corresponding public key Pu k , it can be checked whether S(H ref ) is authentic.
[0186] As a result, for each graphic data sub-block GDSB(j) (j = 1, ..., N) of the graphic data block GDB, a corresponding sub-block human-readable graphic symbol and corresponding sub-block machine-readable error correction data (from the sub-block human-readable graphic symbol HrGS(j) and the machine-readable representation of the sub-block verification path key MrVPK(j) respectively) are provided on a support, and the user authenticates the corresponding sub-block machine-readable error correction data by retrieving the root value R via the sub-block hash value H(j) and its corresponding verification path key VPK(j), and the verification path key VPK(j) can be obtained from the data read on the support.
[0187] As can be clearly seen from the above example, by calculating the hash value of the concatenation of any given leaf node value with the node values specified only in the corresponding sub-block verification path key, the root node value R can ultimately be retrieved from the given leaf node value. Therefore, the amount of data in the verification information based on the verification path key (to be read on the substrate), which is required to retrieve the root node value R, is significantly lower than the amount of data required to calculate the reference root node value H only based on all leaf node values (i.e., read on the substrate): ref (by calculating all non-leaf node values in the middle layer of the tree). This is an advantage of the present invention considering the limited size constraints available on the machine-readable representation of data (such as, for example, a two-dimensional barcode).
[0188] Thus, according to the present invention, due to the tree structure and the use of a robust one-way function to calculate the node values of the tree (such as the SHA-256 hash function in the above embodiment) and the root node value R of the tree (which can become immutable if stored in a blockchain), and including on the substrate a human-readable representation of machine-readable error correction data and associated machine-readable verification path keys as well as corresponding graphical data, the interrelationship of the hash values of all original sub-block hash values allows for the prevention of forgery of data on the labeled substrate with a very high level of reliability.
[0189] The above embodiments of the marking method provide on the substrate (paper 100 or display) a human-readable graphical symbol and corresponding machine-readable error correction data that can be easily verified by the user. In fact, according to the verification method of the present invention (the illustrative flowchart of which is shown in Figure 6 ), a user having a scanner equipped with an imaging unit, a scanner processing unit having a scanner memory, and a scanner display can check whether the human-readable graphical symbol HrGS on the substrate has been modified relative to the original graphical symbol, or can even retrieve the original graphical symbol. In the following illustrative embodiment of the verification method, the human-readable graphical symbol HrGS constitutes text provided on the substrate according to the marking method. For example, the text can be printed on a substrate (such as, for example, as Figure 1shown on paper) or electronically on a screen. The imaging unit of the scanner is operable to image the machine-readable representation MrECD of the text and the corresponding error correction data on the support. The scanner processing unit is programmed to perform image processing of the image of the support taken by the imaging unit to extract the text data and obtain a digital representation of the extracted text data as the corresponding scanned graphic data block SGDB. The scanner processing unit is also programmed to perform image processing of the image of the machine-readable representation MrECD of the error correction data on the support taken by the imaging unit by further using a programmed machine-readable decoder (on the scanner processing unit) to extract the corresponding scanned error correction data SECD, and obtain a digital representation of the scanned error correction data SECD as the corresponding scanned error correction data block SECDB. The scanner processing unit is also programmed to perform an error correction operation on the data block by using an error correction code ECC. The scanner can be, for example, just a smart phone having a camera (as the imaging unit) and having image processing, decoding, and error correction applications operable to run on its processing unit.
[0190] Figure 6 The general verification process shown (in Figure 1 the case of an example of a marked support) starts 600 with the following steps:
[0191] - Scan (via the scanner imaging unit) the text HrGS 610 on the support (i.e., the text 110 on the text area 120 of the paper 100) with the scanner and obtain the corresponding scanned graphic data block SGDB 620 (i.e., the digital representation of the scanned text); and
[0192] - Scan the machine-readable representation MrECD 615 of the error correction data on the support (i.e., the PDF417 barcode 130 on the paper 100) with the scanner, decode the machine-readable representation MrECD of the error correction data (with the programmed machine-readable decoder) to extract the corresponding scanned error correction data SECD, and form the corresponding scanned error correction data block SECDB 625 (i.e., the digital representation of the extracted SECD); and
[0193] - Correct 630 the scanned graphic data block SGDB via the error correction code ECC (using the extracted SECD of the SECDB) programmed on the scanner processing unit and obtain the corrected scanned graphic data block CSGDB (640), the corrected scanned graphic data block CSGDB containing the digital representation of the corresponding corrected human-readable graphic symbol CHrGS; and
[0194] - At step 650, perform at least one of three options:
[0195] -(a) Display the corrected scanned graphic data block CSGDB as the corresponding corrected human-readable graphic symbol CHrGS on the scanner display; or
[0196] -(b) Indicate 670 whether the scanned graphic data block SGDB contains an error (based on the result of the correction 630), e.g., on the scanner display or using any visual or audible alert delivered by the scanner; or
[0197] -(c) Store 680 the scan result data specifying whether the scanned graphic data block SGDB contains an error (based on the result of the correction 630) in the scanner memory.
[0198] Delivering the results of the selected options (a), (b), and (c) ends 690 the verification process.
[0199] Option (a) allows the user to visually compare the version of the text CHrGS displayed on the scanner display (which has been corrected using the scanned error-correction data SECD (obtained from the machine-readable representation MrECD of the error-correction data) via the programmed error-correction code ECC) with the (uncorrected) text HrGS as scanned on the support. Preferably, the differences between the displayed text and the scanned text can be highlighted to help the user easily detect and locate any changes in the text (e.g., due to alteration or fraud).
[0200] With option (b), the user can be warned if there are any differences between the corrected text CHrGS and the text HrGS as scanned on the support.
[0201] Option (c) allows tracking of any existing differences between the corrected text and the text as scanned on the support. Alternatively, in the case where the scanner is also equipped with a communication component (such as a smartphone) and can be connected to an external server, the scan result data can be stored in the server memory via a communication link.
[0202] The advantage of the above verification method is that it allows offline checking (i.e., without being connected to an external device via a communication link), the consistency between the text provided on the support as a human-readable graphical symbol and the human-readable version that can be obtained from the machine-readable representation of the error-correcting data read on the support: because the version is generated by using the error-correcting data extracted from the machine-readable representation read on the support and decoded by means of a scanner, via the error-correction code of the text read on the support with the scanner (similar to the error-correction code that has been used together with the marking method to determine the error-correcting data corresponding to the text provided on the support) for correction. However, in the case where the scanner is also equipped with communication components (such as a smart phone) and can be connected to an external server, some or all of the above operations of the verification method for decoding and performing error correction on data blocks can be executed on the (dedicated) external server.
[0203] Several variants of the verification method (respectively related to the first variant and the second variant of the marking method for providing verifiable graphical data on the support) allow the user to go beyond merely verifying the text (or more generally, graphical symbols) provided on the support by further checking the authenticity of the text (and / or machine-readable data).
[0204] In a first variant of the verification method for verifying the human-readable graphical symbol HrGS provided on the support and the machine-readable representation of the error-correcting data according to the first variant of the marking method, after the steps of the verification method have been executed (see Figure 6 ), the hash function H is also programmed on the scanner processing unit to calculate the hash value of the data block (in the same manner respectively specified in the first variant of the marking method), the scanner is also connected to the scanner communication unit, and the scanner communication unit is operable to communicate with the ledger storing the reference hash value H ref via a communication link (as specified in the first variant of the marking method), and the scanner processing unit also calculates the scanned hash value H scan as the hash value H(CSGDB) of the corrected scanned graphical data block CSGDB, or the hash value H(SECDB) of the scanned error-correcting data block SECDB, or the hash value H(part of CDB) of any part of the data block generated by the concatenation of the corrected scanned graphical data block CSGDB and the scanned error-correcting data block SECDB (as described above). The scanner also performs the following operations:
[0205] - The scanner obtains the reference hash value H stored in the ledger via its communication unit (sending a request to the ledger via the communication link and receiving a response back)
[0206] - The scanner obtains the reference hash value H stored in the ledger via its communication unit (sending a request to the ledger via the communication link and receiving a response back) ref, and
[0207] - The scanner processing unit then checks the obtained reference hash value Href to see if it matches the scanned hash value H scan ; and performs at least one of the following operations:
[0208] (e) Indicates the result of the check operation (e.g., via the scanner display), or
[0209] (f) Stores the result of the check operation in the scanner memory.
[0210] Any modification to the content of the original (true) text of the human-readable text provided on the support (as human-readable graphical symbols) or its machine-readable error-correction data provided on the support will result in a mismatch between the reference hash value H ref and the scanned hash value H scan . Thus, this variant increases the level of confidence in the consistency of the text on the support relative to its original version.
[0211] Using Figure 7 The second variant of the verification method illustrated in the embodiment shown is well-suited for the case where the complete set of graphical symbols is divided into a plurality of N subsets (N≥2), and the individual subsets of graphical symbols are marked on corresponding substrate portions, for example, text printed page by page (such as an N-page report or contract, etc.) according to option (ii) of the second variant of the marking method, or text displayed page by page in a given format on a screen (such as an n-page text file in Microsoft Word or PDF format) according to option (i) of the second variant of the marking method, where each marked portion of the substrate or each displayed page shows a specific subset of human-readable graphical symbols and a machine-readable representation of the corresponding error-correction data (both are representations obtained from corresponding specific verifiable graphical data sub-blocks).
[0212] In the following illustrative embodiment of the second variant of the verification method (see Figure 7 ), the human-readable graphical symbols HrGS constitute the text provided on the support according to the second variant of the marking method. For example, the text can be printed on a substrate (e.g., as Figure 1shown on paper) or electronically on a screen. The imaging unit of the scanner is operable to image each of the N pages of text on the support, i.e., each of the (verifiable) human-readable graphical symbols HrGS(j) provided on the j-th page (j = 1, …, N) and the machine-readable representation MrECD(j) of the corresponding error-correction data. The scanner processing unit is programmed to perform image processing of the image of the j-th page (j = 1, ..., N) on the support taken by the imaging unit to extract the scanned text data from the imaged human-readable graphical symbol HrGS(j) (i.e., the imaged graphical symbol of the j-th sub-block), and obtain a digital representation of the extracted data as the corresponding scanned graphical data sub-block SGDSB(j). The scanner processing unit is also programmed to perform image processing of the image of page j on the support taken by the imaging unit by using a machine-readable decoder programmed on the scanner processing unit, extract the scanned error-correction data SECD(j) from the machine-readable representation MrECD(j) of the imaged error-correction data, and obtain a digital representation of the scanned error-correction data SECD(j) as the corresponding scanned error-correction data sub-block SECDSB(j). The scanner processing unit is also programmed to perform an error-correction operation on the data block by using an error-correction code ECC. The scanner can be a smart phone only having a camera (as the imaging unit) and having image processing, decoding, and error-correction applications operable to run on its processing unit.
[0213] According to the above-described embodiment of the second variant of the verification method ( Figure 7 ), in which the human-readable graphical symbols and the machine-readable error-correction data have been provided on the support according to the second variant of the marking method (shown Figure 4 above), the above scanner starts 700 to perform the following operations for each page j (j = 1, ..., N) of the document:
[0214] - Scan 710, with the scanner imaging unit, the human-readable graphical symbol HrGS(j) provided on page j of the support (i.e., the text 110 on the text area 120 of the paper 100), and obtain 720 the corresponding scanned graphical data sub-block SGDSB(j) (i.e., the digital representation of the scanned human-readable graphical symbol); and
[0215] - Scan 715, with the scanner imaging unit, the machine-readable representation MrECD(j) of the error-correction data provided on page j of the support (i.e., the PDF417 barcode 130 on the paper 100), decode the imaged MrECD(j) by using the programmed machine-readable decoder of the scanner processing unit, extract the corresponding scanned error-correction data SECD(j), and form 725 the corresponding scanned error-correction data sub-block SECDSB(j) as the digital representation of the scanned error-correction data SECD(j);
[0216] - Using a scanner processing unit, correct 730 the scanned graphic data sub-block SGDSB(j) by using an error correction code ECC programmed on the scanner processing unit (and using the extracted SECD(j) of SECDSB(j)), and obtain 740 the corrected scanned graphic data sub-block CSGDSB(j); and
[0217] - Perform 750 at least one of three options for each page j:
[0218] -(a) Display 760 a visual representation (i.e., human-readable) of the corrected scanned graphic data sub-block CSGDB(j) on the scanner display as the corresponding corrected human-readable graphic symbol CGS(j); or
[0219] -(b) Indicate 770 whether the scanned graphic data sub-block SGDB(j) contains an error (based on the result of the correction 730) via the scanner (e.g., on the scanner display, or using any visual or audible alert delivered by the scanner); or
[0220] -(c) Store 780 the scan result data specifying whether the scanned graphic data sub-block SGDB(j) contains an error (based on the result of the correction 730) in the scanner memory.
[0221] Delivering the results of the selected options (a), (b), and (c) will end 790 the second variant of the verification process for each page of the document. In the case where the scanner is also equipped with a communication component (such as a smart phone) and can be connected to an external server, the scan result data of option (c) can be stored in the server memory via a communication link.
[0222] The present invention also includes three sub-variants of the above second variant of the verification method. In all of these sub-variants, after the steps of the embodiment of the second variant of the verification method shown have been performed Figure 7 A one-way function (here a hash function H) is further programmed on the scanner processing unit to calculate the hash value of the data block (in the same manner as respectively specified in the variants of the marking method), and the scanner processing unit further calculates N scan sub-block hash values H scan (j) (j = 1,..., N), each scan sub-block hash value Hscan(j) being the hash value of the hash H(CSGDSB(j)) of the j-th corrected scanned graphic data sub-block CSGDSB(j), or the hash value of the hash H(SECDSB(j)) of the j-th scanned error correction data sub-block SECDSB(j), or the concatenation of the j-th corrected scanned graphic data sub-block CSGDSB(j) and the j-th scanned error correction data sub-block SECDSB(j) The generated data blocks The hash value H(portion of CDB(j)) of any portion. As described below, the calculated scan sub-block hash value H scan (j) is used specifically in each of the first, second, and third sub-variants of the second variant of the verification method.
[0223] In an embodiment of the first sub-variant of an embodiment of the second variant of the verification method, in which the human-readable graphical symbol HrGS(j) and the machine-readable error-correction data MrECD(j) on the support have been generated according to the first sub-variant of the second variant of the marking method, the hash function and the error-correction code are programmed on the scanner processing unit, and the scanner is also operable to read and decode the machine-readable representation of the sub-block hash value H(j) on the support via the scanner processing unit. In addition, the scanner is connected to a scanner communication unit, which is operable to communicate with a ledger storing reference aggregated hash values via a communication link. If possible (i.e., if all HrGS(j) and MrECD(j) are readable), the scanner calculates (see above) the scan sub-block hash value H scan (j), j = 1,..., N. In the case where it is not possible to calculate the scan sub-block hash value of a certain page j (e.g., because HrGS(j) and MrECD(j) on the j-th page are unreadable), the scanner scans and decodes the machine-readable representation MrH(j) of the sub-block hash value H(j) on the j-th page of the support and obtains the corresponding decoded sub-block hash value DH(j): this decoded sub-block hash value will then be used as the scan sub-block hash value of the j-th page, i.e., H scan (j) ≡ DH(j). The machine-readable representation MrH(j) of the j-th sub-block hash value is associated with the verifiable graphical data sub-block VGDSB(j), which corresponds to the machine-readable representation MrECD(j) of the human-readable graphical symbol HrGS(j) and the error-correction data provided on the support. As a result, all the sub-block scan hash values required to calculate the aggregated hash value of all pages of the support are available (either as the calculated scan hash value H scan (j) or identified by the decoded hash value DH(j)).
[0224] The scanner processing unit then performs the following further operations:
[0225] - Calculate the aggregated scan hash value H by concatenating all the obtained scan hash values scan (the symbol represents the concatenation operator):
[0226]
[0227] - Send a request for the reference aggregated hash value to the ledger via the scanner communication unit over a communication link and receive back the reference aggregated hash value H ref ;
[0228] - Check the received reference aggregated hash value H ref for a match with the aggregated scan value H scan and indicate the result of the check operation (e.g., via a message on the scanner display). In the case of a match, the pages are all genuine (i.e., consistent with the original pages) even if the text and machine-readable error-correction data of some pages are unreadable (however, the machine-readable representation of the sub-block hash values is readable). In the case of a non-match, at least one page has been modified (e.g., at least one graphical symbol has been changed or forged): Then, the pages can be retrieved by checking whether the scanned sub-block hash values H scan (j) obtained from the sub-block data HrGS(j) and MrECD(j) match the corresponding decoded hash values DH(j) (j = 1,..., N).
[0229] This sub-variant allows the individual pages of an N-page document to be independently checked by the scanner for authenticity by means of a scan of only the machine-readable representation of the sub-block hash values of limited size.
[0230] In an embodiment of the second sub-variant of the second variant of the verification method, the human-readable graphical symbols HrGS(j) ((j = 1,..., N)) on page j of a (document of N pages) on a support and the machine-readable error-correction data MrECD(j) have been generated according to the second sub-variant of the second variant of the marking method, option (iii), the scanner is connected to a scanner communication unit operable to communicate via a communication link with a ledger containing the reference aggregated hash value H ref (see Figure 5 , as the root node value of a tree), the hash function (the same as that used to calculate the N sub-block hash values H(j)) and the corresponding reference aggregated hash value H ref are programmed on the scanner processing unit. The scanner is also operable to read and decode the machine-readable representation MrVPK(j) of the sub-block verification path key VPK(j) (j = 1,..., N) on the support and calculate the aggregated scan hash value H scan (here, we consider the case where N = 8, where for an 8-page document, the binary tree corresponds to Figure 5Example). After calculating the scanned sub-block hash value H scan (j) ((j ∈ {1,..., N})) from the scanned verifiable graphic data on the j-th page of the N-page document using a hash function (see above) and according to the same selected option of the second sub-variant of the second variant of the marking method (i.e., the part with H(CSGDSB(j)) or H(SECDSB(j) or H(CDB(j)) for calculating the sub-block hash value, which is used as a leaf node of the tree)), the scanner performs the following further operations: scan After that, the scanner performs the following further operations:
[0231] - Scan the machine-readable representation MrVPK(j) of the sub-block verification path key VPK(j) on the j-th page of the support (corresponding to the j-th corrected scanned graphic data sub-block CSGDSB(j)), and extract the corresponding scanned sub-block verification path key SVPK(j) via the scanner processing unit;
[0232] - Using the scanner processing unit, calculate the scanned aggregated hash value H scan with the calculated scanned sub-block hash value H scan (j) and the scanned sub-block verification path key SVPK(j) obtained by scanning the j-th page of the document, as follows: scan using the calculated scanned sub-block hash value H scan (j) and the scanned sub-block verification path key SVPK(j) obtained by scanning the j-th page of the document to calculate the scanned aggregated hash value H scan , as follows: scan as described below:
[0233] If j = 1 (the first page of the document), and as described in the above embodiment of the second sub-variant of the second variant of the marking method (see also the illustrative binary tree in Figure 5 ), then the sub-block hash value H scan (1) (i.e., from the first corrected scanned graphic data sub-block CSGDB(1) and / or the first scanned error correction data sub-block SECDSB(1)) obtained as described above is considered the value of the first leaf node a(1,1) of the binary tree (select the same node sorting and tree concatenation sorting as in the above embodiment of the second sub-variant of the second variant of the marking method). The extracted scanned sub-block verification path key SVPK(1) contains three node values: SVPK(1) = {a(1,2), a(2,2), a(3,2)}. Therefore, the scanned hash value H scan obtained from the scan of the verifiable graphic data on the first page can be calculated as scan (1) (i.e., from the first corrected scanned graphic data sub-block CSGDB(1) and / or the first scanned error correction data sub-block SECDSB(1)) is considered the value of the first leaf node a(1,1) of the binary tree (select the same node sorting and tree concatenation sorting as in the above embodiment of the second sub-variant of the second variant of the marking method), the extracted scanned sub-block verification path key SVPK(1) contains three node values: SVPK(1) = {a(1,2), a(2,2), a(3,2)}, so the scanned hash value H scan that can be obtained from the scan of the verifiable graphic data on the first page is calculated as scan is calculated as
[0234]
[0235] If j = 2, in the case of SVPK(2) = {a(1,1), a(2,2), a(3,2)},
[0236]
[0237] If j = 3, in the case where SVPK(3) = {a(1,4), a(2,1), a(3,2)},
[0238]
[0239] If j = 4, in the case where SVPK(4) = {a(1,3), a(2,1), a(3,2)},
[0240]
[0241] If j = 5, in the case where SVPK(5) = {a(1,6), a(2,4), a(3,1)},
[0242]
[0243] If j = 6, in the case where SVPK(6) = {a(1,5), a(2,4), a(3,1)},
[0244]
[0245] If j = 7, in the case where SVPK(7) = {a(1,8), a(2,3), a(3,1)},
[0246]
[0247] If j = 8, in the case where SVPK(8) = {a(1,7), a(2,3), a(3,1)},
[0248]
[0249] - Next, obtain the reference aggregated hash value H stored in the ledger via the scanner communication unit and the communication link ref (i.e., the root node value R of the tree), and for j = 1,..., N, check the obtained reference aggregated hash value H ref to see if it matches the scanned aggregated hash value H scan ; and
[0250] - Indicate the result of the check operation (e.g., on the scanner display).
[0251] This sub-variant of the verification method allows any errors on each page of a file to be detected with only a small amount of data, because any change in the page content causes the reference aggregated hash value H ref to not match the scanned hash value H obtained from the verifiable graphic data scanned on that page scanA mismatch between them. Additionally, the method is robust because a corrected version of the scanned graphic data is used to calculate the sub-block hash value H scan (j) for the j-th (j = 1,..., N) page.
[0252] In an embodiment of the third sub-variant of the second variant of the verification method, we use the same binary tree for an N = 8-page document and the same way of calculating the scanned sub-block hash value H scan (j) (j = 1,..., N) and the scanned hash value H scan as in the above example of the second sub-variant of the second variant of the verification method. In this embodiment, the human-readable graphic symbol HrGS(j) and the machine-readable error-correction data MrECD(j) on the support have been generated according to the second sub-variant of the second variant of the marking method (option (iv)), with reference to the aggregated hash value H ref stored in the scanner memory, and the scanner is also operable to read and decode the machine-readable representation of the sub-block verification path key VPK(j) on the support and calculate the aggregated hash value H scan (j) from a pair of corresponding sub-block hash values and sub-block verification path keys. According to this embodiment, after the steps of the said second variant of the verification method have been carried out and the scanned sub-block hash value H scan (j) (j = 1,..., N) has been calculated as described above, the scanner performs the following further steps:
[0253] - Use the scanner to scan the machine-readable representation MrVPK(j) of the sub-block verification path key VPK(j) on the j-th page provided on the support (corresponding to, for example, the j-th corrected scanned graphic data sub-block CSGDSB(j) obtained from the scanned verifiable graphic data provided on the j-th page of the document), and extract the corresponding scanned sub-block verification path key SVPK(j) via the scanner processing unit;
[0254] - Use the calculated scanned sub-block hash value H scan (j) and the scanned sub-block verification path key SVPK(j) obtained by scanning the j-th page of the document to calculate the scanned aggregated hash value H scan (see above for the detailed calculation related to the second sub-variant of the embodiment of the second variant of the verification method);
[0255] - Obtain the reference aggregated hash value H ref stored in the scanner memory;
[0256] - Via the scanner processing unit, check whether the obtained reference aggregated hash value H ref matches the aggregated scanned hash value H scan for the j-th page (j = 1,..., N); and
[0257] - Indicate the result of the inspection operation (via the scanner display).
[0258] This sub-variant of the verification method allows any errors on individual pages of a document to be detected in a robust offline mode with only a small amount of data, because any change in the page content causes a mismatch between the reference aggregated hash value H ref and the scanned hash value H obtained from the verifiable graphic data scanned on the page scan . In fact, the method only uses the (limited-size) data stored in the scanner memory (i.e., H ref ) to check whether the reference aggregated hash value H ref matches the scanned hash value H scan .
[0259] An embodiment of an alternative variant of the verification method shows the application of the present invention to verify human-readable graphic symbols and corresponding machine-readable error correction data, which are generated by a processor programmed to perform the steps of the above-described marking method (option (i)) in a computer connected to a display. The computer has a scanning application programmed on its processor, which is operable to scan the displayed human-readable graphic symbols and machine-readable error correction data.
[0260] Thus, the computer displays the generated human-readable graphic symbol HrGS and the corresponding machine-readable error correction data MrECD, and the scanning application running on the computer processor then performs the following operations:
[0261] - Scan the displayed human-readable graphic symbol HrGS to obtain a scanned graphic data block SGDB, which is a digital representation of the scanned human-readable graphic symbol;
[0262] - Scan the displayed machine-readable error correction data MrECD and decode the scanned machine-readable error correction data MrECD via the machine-readable decoder of the scanning application running on the computer processor to obtain the corresponding scanned error correction data SECD in the scanned error correction data block SECDB;
[0263] - Use the scanned error correction data SECD of the scanned error correction data block SECDB to correct the scanned graphic data block SGDB using the error correction code ECC of the scanning application running on the computer processor to obtain a corresponding corrected scanned graphic data block CSGDB; and
[0264] - Perform at least one of the following steps:
[0265] (a) Display a visual representation of the corrected scanned graphic data block CSGDB on a display as a corrected human-readable graphic symbol CHrGS, or
[0266] (b) Display an indication of whether the specified scanned graphic data block SGDB contains an error (based on the result of the correction step of the SGDB), or
[0267] (c) Store the scan result data indicating whether the specified scanned graphic data block SGDB contains an error in the memory of a computer.
[0268] In step (a), the part of the initially displayed human-readable graphic symbol HrGS that has been corrected via scanning (before running the scanning application) is preferably highlighted to facilitate the identification and localization of errors in the initially displayed HrGS by the user of the computer.
[0269] The subject matter disclosed above should be considered illustrative rather than restrictive and is provided to give a better understanding of the invention defined by the independent claims.
Claims
1. A method for protecting graphic data from forgery and tampering, the method comprising the following steps: Storing, in a memory of a processing unit, a graphic data block including a digital representation of a given finite set of graphic symbols including the graphic data; Using the processing unit to process the digital representation of the graphic symbols of the stored graphic data block with an error correction code programmed in the processing unit to generate error correction data in a corresponding error correction data block; Using the processing unit to format the graphic data block and the error correction data block to respectively provide a human-readable representation of the graphic symbols of the graphic data block in a human-readable graphic data block, and a machine-readable representation of the error correction data of the error correction data block separate from the human-readable representation of the graphic symbols of the graphic data block in a machine-readable error correction data block, thereby obtaining a corresponding verifiable graphic data block including the human-readable graphic data block and the machine-readable error correction data block; And (i) Displaying, on a support being a display connected to the processing unit, the human-readable graphic symbols of the obtained verifiable graphic data block and the machine-readable representation of the corresponding error correction data, or (ii) Marking, via a marking device, on a support being a substrate, the human-readable graphic symbols of the obtained verifiable graphic data block received from the processing unit and the machine-readable representation of the corresponding error correction data, the marking device being connected to the processing unit and equipped with a control unit capable of operating to control the marking operation based on data received from the processing unit, Thereby providing verifiable data including the human-readable graphic symbols and the corresponding machine-readable error correction data on the support; Characterized in that the method further comprises: Calculating, with a hash function programmed on the processing unit, a hash value of any part of a data block generated by the concatenation of the graphic data block and the error correction data block; and Storing the calculated hash value as a reference hash value in a ledger.
2. The method according to claim 1, wherein, The machine-readable representation of the error correction data is any one of an alphanumeric representation and a barcode representation.
3. The method according to claim 1 or 2, wherein The graphic symbols are text characters, and the finite set of graphic symbols is an alphabet.
4. The method according to claim 1 or 2, wherein The support includes a plurality of parts, and the verifiable graphic data block is divided into the same plurality of verifiable graphic data sub-blocks, and thus the corresponding human-readable graphic symbols and the machine-readable representation of the error correction data are scattered together on the corresponding parts of the support by the following steps: The graphic data block is divided into a plurality of graphic data sub-blocks, and each graphic data sub-block is formatted to provide a human-readable representation of the graphic symbols of the graphic data sub-block in a corresponding human-readable graphic data sub-block; For each graphic data sub-block, extracting the digital representation of the graphic symbols of the graphic data sub-block and processing the digital representation with an error correction code to generate corresponding error correction data in an error correction data sub-block; Each error-correcting data sub-block is formatted to provide a machine-readable representation of the corresponding error-correcting data separate from the human-readable representation of the graphical symbol of the corresponding human-readable graphical data sub-block in a corresponding machine-readable error-correcting data sub-block, thereby obtaining a corresponding verifiable graphical data sub-block including the human-readable graphical data sub-block and the machine-readable error-correcting data sub-block; and in step (i), displaying on the display the human-readable graphical symbols of the obtained respective verifiable graphical data sub-blocks and the machine-readable representations of the corresponding error-correcting data, or in step (ii), marking on the substrate via the marking device the human-readable graphical symbols of the obtained respective verifiable graphical data sub-blocks received by the control unit from the processing unit and the machine-readable representations of the corresponding error-correcting data, thereby providing on the support a corresponding human-readable graphical symbol and corresponding machine-readable error-correcting data for each graphical data sub-block of the graphical data block that can be verified by a user.
5. The method according to claim 4, wherein, for any part of the data sub-block generated by the concatenation of the graphical data sub-block and the error-correcting data sub-block, a sub-block hash value is calculated via a hash function programmed on the processing unit; for each sub-block hash value, a corresponding machine-readable representation of the sub-block hash value is calculated; in association with each verifiable graphical data sub-block, the corresponding machine-readable representation of the sub-block hash value is also provided on a corresponding part of the support; a reference aggregated hash value of all sub-block hash values is determined as the concatenation of all calculated sub-block hash values; and the reference aggregated hash value is stored in a ledger, thereby providing on the support a corresponding human-readable graphical symbol and corresponding machine-readable error-correcting data for each graphical data sub-block of the graphical data block that can be verified by a user.
6. The method according to claim 4, wherein, for any part of the data sub-block generated by the concatenation of the graphical data sub-block and the error-correcting data sub-block, a sub-block hash value is calculated via a hash function programmed on the processing unit; a reference aggregated hash value of all sub-block hash values is determined as the root node value of a tree that takes the calculated sub-block hash values as leaf node values, the tree including nodes arranged in the tree according to a given node ordering, the tree including node layers from the leaf nodes to the root node, each non-leaf node value of the tree corresponding to the hash value of the concatenation of the corresponding node values of the sub-nodes of the tree according to the tree concatenation ordering, and the root node value corresponding to the hash value of the concatenation of the node values of the nodes in the penultimate node layer of the tree according to the tree concatenation ordering; for each sub-block hash value, an associated sub-block verification path key is determined as a series of hash values of selected non-leaf nodes of the tree required to retrieve the root node value from the sub-block hash value; Including the machine-readable representation of the verification path key for each sub-block in the verifiable graphic data sub-block in association with the respective graphic data sub-block and error correction data sub-block, respectively, the verifiable graphic data sub-block being further formatted to provide the machine-readable representation of the sub-block verification path key separate from the human-readable representation of the associated graphic data sub-block and the machine-readable representation of the associated error correction data sub-block; and (iii) Storing the reference aggregated hash value in a ledger, or (iv) Making the reference aggregated hash value available to the user, Thereby providing, on the substrate, corresponding human-readable graphic symbols and corresponding machine-readable error correction data for each graphic data sub-block of the graphic data block that can be verified by the user.
7. A method of verifying a human-readable graphical symbol, the human-readable graphical symbol being provided on a support together with a machine-readable representation of error correction data, the human-readable graphical symbol and the machine-readable representation of the error correction data having Generated by the method according to any one of claims 1 to 3, the method for verifying the human-readable graphic symbols comprising the following steps: Scanning the human-readable graphic symbols on the substrate using a scanner to obtain a scanned graphic data block via image processing of the scanned human-readable graphic symbols, the scanned graphic data block being a digital representation of the scanned human-readable graphic symbols, the scanner being equipped with an imaging unit and a scanner processing unit having a scanner memory and connected to a scanner display; Scanning the machine-readable representation of the error correction data on the substrate using the scanner to obtain corresponding scanned error correction data in a scanned error correction data block via a machine-readable decoder programmed on the scanner processing unit, the scanned error correction data block being a digital representation of the scanned error correction data; Using an error correction code programmed on the scanner processing unit, using the scanned error correction data of the scanned error correction data block to correct the scanned graphic data block to obtain a corresponding corrected scanned graphic data block; And (a) Displaying a visual representation of the corrected scanned graphic data block on the scanner display as a corresponding corrected human-readable graphic symbol for the purpose of comparing the displayed visual representation of the corrected scanned graphic data block with the human-readable graphic symbols provided on the substrate to detect any changes or fraud, or (b) Indicating via the scanner whether the scanned graphic data block contains an error, or (c) Storing scan result data specifying whether the scanned graphic data block contains an error in the scanner memory; Wherein the hash function is programmed on the scanner processing unit, and the scanner is connected to a scanner communication unit, the scanner communication unit being operable to communicate with the ledger via a communication link, Characterized in that the method further comprises the following steps: Calculating a scan hash value of any part of a data block generated by the concatenation of the corrected scanned graphic data block and the scanned error correction data block using a hash function programmed on the scanner processing unit; Obtaining the reference hash value stored in the ledger via the scanner communication unit and the communication link, and checking whether the obtained reference hash value matches the scan hash value; and (e) indicating the result of said inspection, or (f) storing the result of said inspection operation in said scanner memory.
8. The method according to claim 7, wherein, The human-readable graphic symbols and the machine-readable error-correction data on said support have been generated according to the method of claim 4, wherein: The operation of scanning the human-readable graphic symbols on said support includes scanning the sub-block graphic symbols of the corresponding graphic data sub-blocks to obtain the corresponding scanned graphic data sub-blocks as digital representations of the scanned sub-block graphic symbols via image processing; The operation of scanning the machine-readable error-correction data on said support includes scanning the error-correction data of the corresponding error-correction data sub-blocks to obtain the corresponding scanned error-correction data sub-blocks; The operation of correcting the scanned graphic data block includes using the corresponding scanned error-correction data sub-blocks to correct the graphic data of the scanned graphic data sub-blocks to obtain the corresponding corrected scanned graphic data sub-blocks; and The operation of displaying the visual representation of the corrected scanned graphic data block (a) includes displaying the visual representation of the corrected scanned graphic data sub-blocks; The operation of indicating whether the scanned graphic data block contains an error (b) includes indicating whether the scanned graphic data sub-blocks contain an error; The operation of storing the scan result data (c) includes storing whether the scanned graphic data sub-blocks contain an error.
9. The method according to claim 8, wherein, The human-readable graphic symbols and the machine-readable error-correction data on said support have been generated according to the method of claim 5, the hash function and the error-correction code are programmed on said scanner processing unit, and the scanner is also capable of operating to read and decode the machine-readable representation of the sub-block hash values on said support via said scanner processing unit, the scanner is connected to a scanner communication unit, the scanner communication unit is capable of operating to communicate with the ledger via a communication link, and the method further includes the following steps: Using the hash function programmed on said scanner processing unit and according to the operations performed to calculate the sub-block hash values, calculating the scan sub-block hash values of any part of the data sub-blocks generated by the concatenation of the corrected scanned graphic data sub-blocks and the scanned error-correction data sub-blocks for each part of said support; In the case where the scan sub-block hash value for a part of said support cannot be calculated, scanning and decoding the machine-readable representation of the sub-block hash values on that part of said support to obtain the corresponding decoded sub-block hash values, and using the decoded sub-block hash values as the scan sub-block hash values for that part of said support; Calculating the aggregated scan hash value as the concatenation of all the scan sub-block hash values; Obtaining the reference aggregated hash value stored in said ledger via said scanner communication unit and the communication link, and checking whether the obtained reference aggregated hash value matches the aggregated scan hash value; and Indicating the result of said inspection operation via said scanner.
10. The method according to claim 8, wherein, The human-readable graphic symbols and the machine-readable error-correction data on each part of said support have Generated according to the method of claim 6, the reference aggregated hash value is stored in the ledger, the scanner is connected to a scanner communication unit, the scanner communication unit is operable to communicate with the ledger via a communication link, and the scanner is further operable to read and decode a machine-readable representation of a sub-block verification path key on a corresponding portion of the support and calculate an aggregated hash value based on a pair of corresponding sub-block hash values and sub-block verification path keys, the method further comprising the steps of: Calculating a scanned sub-block hash value of any portion of a data sub-block resulting from the concatenation of the corrected scanned graphic data sub-block and the scanned error correction data sub-block, using the hash function programmed in the scanner processing unit and based on the operations performed to calculate the sub-block hash value; Scanning, using the scanner, a machine-readable representation of a sub-block verification path key corresponding to a selected corrected scanned graphic data sub-block on a corresponding portion of the support and extracting the corresponding scanned sub-block verification path key; Calculating a scanned aggregated hash value using the calculated scanned sub-block hash value and the scanned sub-block verification path key; Obtaining, via the scanner communication unit and the communication link, the reference aggregated hash value stored in the ledger and checking whether the obtained reference aggregated hash value matches the scanned aggregated hash value; and Indicating, via the scanner, the result of the check.
11. The method according to claim 8, wherein, The human-readable graphic symbol and the machine-readable error correction data on the support have Generated according to the method of claim 6, the reference aggregated hash value available to the user is stored in the scanner memory, and the scanner is further operable to read and decode a machine-readable representation of a sub-block verification path key on a corresponding portion of the support and calculate an aggregated hash value based on a pair of corresponding sub-block hash values and sub-block verification path keys, the method further comprising the steps of: Calculating a scanned sub-block hash value of any portion of a data sub-block resulting from the concatenation of the corrected scanned graphic data sub-block and the scanned error correction data sub-block, using the hash function programmed in the scanner processing unit and based on the operations performed to calculate the sub-block hash value; Scanning, using the scanner, a machine-readable representation of a sub-block verification path key corresponding to a selected corrected scanned graphic data sub-block on a corresponding portion of the support and extracting the corresponding scanned sub-block verification path key; Scanning the reference aggregated hash value on the support to obtain a scanned reference aggregated hash value; Calculating an aggregated scanned hash value using the calculated scanned sub-block hash value and the scanned sub-block verification path key; Checking whether the reference aggregated hash value stored in the scanner memory matches the aggregated scanned hash value; and Indicating, via the scanner, the result of the check.
12. A support marked with verifiable data including a human-readable image symbol and corresponding machine-readable error correction data according to the method of any one of claims 1 to 6.
13. A scanner, which is equipped with an imaging unit, a scanner processing unit, and a scanner display, wherein, The scanner processing unit is programmed to enable the scanner to operate to implement the steps of the method according to any one of claims 7, 8, and 11.
14. The scanner according to claim 13 is further equipped with a scanner communication unit that is operable to communicate with the ledger via a communication link, wherein, The scanner processing unit is further programmed to enable the scanner to operate to implement the steps of the method according to any one of claims 7, 9, and 10.
Citation Information
Patent Citations
Method and system for generation and verification of a digital seal on an analog document
EP2048867A1
Back EMF detection in a brushless DC motor using a virtual center tap circuit
US20140145661A1
Verification Paths of Leaves of a Tree
US20170046536A1
Method and means for enhancing optical character recognition of printed documents
US6047093A
Electronic documents certification
WO2018224724A1