Content authentication based on inherent attributes

Through a content authentication system based on inherent attributes, verification data is generated using hardware processors and memory, the problem of difficult to identify deep forged content is solved, and effective authentication and anti-forgery distribution of digital content is achieved.

CN114868122BActive Publication Date: 2025-07-04DISNEY ENTERPRISES INC
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202180007598.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-01-08
Filing Date
2021-01-04
Publication Date
2025-07-04
Estimated Expiration
2041-01-04

AI Technical Summary

Technical Problem

The existing technology is difficult to effectively identify and manage deeply forged digital content, which leads to content owners and distributors at legal risks.

Method used

Through a content authentication system based on inherent attributes, content authentication software code is executed using a hardware processor and memory, verification data and authentication data are generated and compared, and manipulated digital content is identified and isolated.

Benefits of technology

It realizes effective authentication of digital content, prevents the distribution of forged content, and protects the legitimate rights and interests of content owners and distributors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114868122B_ABST
    Figure CN114868122B_ABST
Patent Text Reader

Abstract

A system for performing content authentication based on inherent properties, including a computing platform having a hardware processor and a memory storing content authentication software code. The hardware processor executes the content authentication software code to receive a content file including digital content and authentication data, the authentication data being created based on a baseline version of the digital content, to generate verification data based on the digital content, and to compare the verification data with the authentication data, and to identify the digital content as baseline digital content in response to determining that the verification data matches the authentication data based on the comparison. The hardware processor is further configured to execute the content authentication software code to identify the digital content as manipulated digital content in response to determining that the verification data does not match the authentication data based on the comparison.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross - Reference to Related Applications

[0002] This application is related to U.S. Patent Application No. 16 / 737826, titled "Authenticity Assessment of Modified Content" (Attorney Docket No. 0260636), which was filed concurrently with this application and is hereby incorporated by reference in its entirety. Background Art

[0003] Advances in machine learning have enabled the creation of realistic but fake reproductions of a person's image or voice, known as "deepfakes," through the use of deep artificial neural networks. Deepfakes can be created without the consent of the person whose image or voice is used and may make the represented person appear to have said or done things they actually did not. Thus, digitally manipulated content with deepfakes can be maliciously used to spread misinformation.

[0004] Due to the widespread popularity of digital content in entertainment and news distribution, effective authentication and management of this content are important for its creators, owners, and distributors. However, with the continuous improvement of machine - learning solutions, deepfakes are and will continue to be difficult to detect. Therefore, in violation of contract agreements or regulatory restrictions, digitally manipulated or even completely fake content may be inadvertently played or otherwise distributed, exposing content owners and / or distributors to potential legal risks. Summary of the Invention

[0005] Systems and methods for performing content authentication based on intrinsic properties are provided, which are substantially as shown in at least one of the figures and / or as described in connection with the figures and more fully set forth in the claims. Brief Description of the Drawings

[0006] Figure 1 A diagram showing an exemplary system for performing content authentication based on intrinsic properties, according to one embodiment;

[0007] Figure 2 Another exemplary embodiment of a system for performing content authentication based on intrinsic properties is shown;

[0008] Figure 3 A flowchart according to one embodiment, showing an exemplary method by which the system performs content authentication based on intrinsic properties; and

[0009] Figure 4 Is shown as being suitable for being Figure 1 and Figure 2 An example diagram of content - authentication software code executable by a hardware processor of the system shown. Detailed Description

[0010] The following description contains specific information related to embodiments of the present invention. Those skilled in the art will recognize that the present invention can be implemented in ways different from those specifically discussed herein. The accompanying drawings and the detailed description in this application are directed only to exemplary embodiments. Unless otherwise indicated, like or corresponding elements in the drawings may be represented by like or corresponding reference numerals. In addition, the drawings and illustrations in this application are generally not drawn to scale and are not intended to correspond to actual relative dimensions.

[0011] This application discloses systems and methods for performing content authentication based on inherent properties, overcoming the disadvantages and deficiencies in the prior art. By comparing the verification data of received digital content with the authentication data of the content, where the authentication data is created based on the inherent properties of the received digital content in its original or "baseline" version, this authentication solution advantageously utilizes the characteristics of the digital content itself to uniquely identify it. In addition, by using the same cryptographic techniques used to create the authentication data for the original or baseline digital content (hereinafter simply referred to as "baseline digital content") to generate the verification data for comparison with the authentication data, this application discloses a sound and substantially error-proof authentication solution.

[0012] It should be noted that in some embodiments, this content authentication solution can be performed by a substantially automated system as a substantially automated process. It should be noted that the terms "automation", "automated", "automatic operation" as used in this application refer to systems and processes that do not require the participation of a human user (such as a system administrator). Although in some embodiments, a human system operator or administrator may review the authentication determinations made by the automated system and according to the automated methods described herein, human participation is optional. Therefore, the methods described in this application can be executed under the control of the hardware processing components of the disclosed automated system.

[0013] Figure 1 A diagram showing an exemplary system for performing content authentication based on inherent properties according to one embodiment is shown. As Figure 1 shown, system 100 may include a computing platform 100 having a hardware processor 104 and a memory 106 implemented as a non-transitory storage device. According to Figure 1 the embodiment shown, the memory 106 stores content authentication software code 110 and an isolation database 108 for storing digital content that is identified by the content authentication software code 110 as manipulated digital content 154. It should be noted that as defined in this application, the term "manipulated digital content" refers to baseline digital content 150 that has undergone unauthorized modification after legitimate manufacture (such as by content manufacturing device 130).

[0014] As Figure 1 Further shown, system 100 is implemented in a usage environment including a content broadcast source 120, a content delivery network (CDN) 122, a baseline content database 151, and a communication network 124, and the communication network 124 includes network communication links 126. In addition, Figure 1 A content file 160 including baseline digital content 150 and a content file 164 including manipulated digital content 154 are shown. Figure 1 Also shown are a content creation device 130 and a content manipulation device 152 communicatively connected to system 100 via the communication network 124 and network communication link 126, and a consumer audience 156 that receives the baseline digital content 150.

[0015] The baseline content database 151 can be a centralized storage resource for substantially all of the baseline content whose authenticity is evaluated by system 100. As Figure 1 shown, in some embodiments, the baseline content database 151 can be remote from the computing platform 102 and can be communicatively connected to the computing platform 102 via the communication network 124 and network communication link 126. However, in other embodiments represented by a direct communication link 153, the baseline content database 151 can be a feature of system 100 or can be different from 100 but can be directly accessed by the computing platform 102. That is, in various embodiments, the baseline content database 151 can be integrated with the computing platform 102, can be a discrete resource directly accessible by the computing platform 102, or can be remote from the computing platform 102.

[0016] It should be noted that although, for conceptual clarity, the present application refers to storing the content authentication software code 110 in the memory 106, more generally, the memory 106 can take the form of any computer-readable non-transitory storage medium. As used in this application, the term "computer-readable non-transitory storage medium" refers to any medium that does not include a carrier wave or other transitory signal that provides instructions to the hardware processor 104 of the computing platform 102. Thus, a computer-readable non-transitory medium can correspond to various types of media, such as volatile media and non-volatile media. Volatile media can include dynamic memory, such as dynamic random access memory (dynamic RAM), and non-volatile memory can include optical, magnetic, or electrostatic storage devices. Common forms of computer-readable non-transitory media include, for example, optical discs, RAM, programmable read-only memory (PROM), erasable PROM (EPROM), and flash memory.

[0017] It should also be noted that although Figure 1The content authentication software code 110 and the isolated database 108 are described as being co-located in the memory 106, but providing this representation is merely for the sake of conceptual clarity. More generally, the system 100 may include one or more computing platforms 102, such as computer servers, which may form an interconnected but distributed system, such as a cloud-based system. As a result, the hardware processor 104 and the memory 106 may correspond to distributed processor and memory resources within the system 100. For example, in one embodiment, the computing platform 102 of the system 100 may correspond to one or more web servers, which may be accessed via a packet-switched network such as the Internet. Alternatively, the computing platform 102 may correspond to one or more computer servers that support a wide area network (WAN), a local area network (LAN), or are included in another type of limited distribution or private network.

[0018] As an overview, the system 100 is configured to receive a content file that includes digital content and to evaluate the authenticity of the digital content based on its inherent properties using the content authentication software code 110 executed by the hardware processor 104. For example, the system 100 may receive a content file 160 that includes baseline digital content 150 legally manufactured by the content manufacturing device 130, and / or may receive a content file 164 that includes manipulated digital content 154, which may be deepfaked, for example, modified by the content manipulation device 152 after it was manufactured as the baseline digital content 150.

[0019] As a result of evaluating the digital content received by the system 100 based on the inherent properties of the received content, as described in more detail below, the content authentication software code 110 may identify the received digital content as either baseline digital content 150 or manipulated digital content 154. When the manipulated digital content 154 is identified, the hardware processor may execute the content authentication software code 110 to isolate the manipulated digital content 154 to prevent its distribution by the content broadcast source 120 and / or the CDN 122. For example, the manipulated digital content 154 may be isolated by being isolated in the isolated database 108.

[0020] The baseline digital content 150 may take the form of digital content without audio, audio content without video, or audio-visual content, to name a few examples, such as movies, episodic content (which may include television series, web series, and / or video logs), sports content, news content, or video game content. Alternatively, in some embodiments, the baseline digital content 150 may take the form of digital photos.

[0021] In cases where the manipulation of digital content involves a video that modifies the baseline digital content 150, by way of example, the manipulation can include one or more of changing the contrast of video frames, deleting video frames, inserting video frames, removing an object from a video frame, inserting an object into a video frame, changing the color within a video frame, or adding metadata to a frame. Similarly, in cases where the manipulation modifies the baseline digital content 150 in the form of a digital photograph, again by way of example, the manipulation can include one or more of changing the image attributes (such as contrast, brightness, etc.) of the digital photograph, removing an object from the digital photograph, inserting an object into the digital photograph, changing the color within the digital photograph, or adding metadata to the digital photograph.

[0022] In cases where the manipulation of digital content involves audio content in the baseline digital content 150, for example, such manipulation can include deleting a portion of the original audio content and / or inserting additional audio content, such as music or speech. Alternatively, or additionally, the manipulation of the audio content can include mixing audio tracks, changing the audio level of an audio track, or adding metadata to an audio track.

[0023] Contrary to the use case of the manipulated digital content 154, when the digital content received by the system 100 is recognized as the baseline digital content 150, the hardware processor can execute the content authentication software code 110 to output the baseline digital content to one or both of the content broadcast source 120 and the CDN 122 for distribution to the consumer audience 156.

[0024] The content broadcast source 120 can be a media entity that provides a video including the baseline digital content 150. For example, the baseline digital content 150 can be audio-video content included in a linear television program stream provided by the content broadcast source 120. For example, the linear television program stream includes a high-definition (HD) or ultra-high-definition (UHD) baseband video signal with embedded audio, subtitles, time codes, and other auxiliary metadata (such as ratings and / or parental guides). In some embodiments, the baseline digital content 150 distributed by the content broadcast source 120 can also include multiple audio tracks and can utilize, for example, secondary audio programming (SAP) and / or descriptive video service (DVS). Alternatively, or additionally, the content broadcast source 120 can provide the baseline digital content 150 via radio or satellite radio broadcast.

[0025] The baseline digital content 150 distributed by the content broadcast source 120 can be included in the same source video broadcast to traditional television viewers (such as the consumer audience 156). Thus, for example, the content broadcast source 120 can take the form of a traditional cable television and / or satellite television network. As Figure 1As shown, in some embodiments, it may be advantageous or desirable to provide the baseline digital content 150 via an alternative distribution channel (e.g., communication network 124), which, as described above, may take the form of a packet-switched network (e.g., the Internet). For example, system 100 may output the baseline digital content 150 to CDN 122 for distribution to consumer viewers 156 as part of a program stream, which may be an Internet Protocol (IP) program stream provided as part of a streaming service or a video-on-demand (VOD) service.

[0026] Note that although Figure 1 the content creation device 130 is described as a mobile communication device, such as a smartphone or a tablet computer, this representation is merely exemplary. More generally, the content creation device 130 may be any suitable system that implements data processing capabilities sufficient to provide a user interface, supports a connection to the communication network 124, and implements the functions attributed to the content creation device 130 herein. In other embodiments, by way of example, the content creation device 130 may take the form of a digital still image camera, a digital video camera, a desktop computer, a laptop computer, or a game console. Similarly, although the content manipulation device 152 is Figure 1 depicted as a desktop computer in

[0027] Figure 2 Another exemplary embodiment of a system for performing content authentication based on intrinsic properties is shown. According to Figure 2 the exemplary embodiment shown, the content creation device 230 is connected to the system 200 interactively via a network communication link 226. In Figure 1 , the network communication link 226 and the system 200 including the computing platform 202 having the hardware processor 204 and the memory 206 generally correspond to the network communication link 126, and the system 100 including the computing platform 102 having the hardware processor 104 and the memory 106. Additionally, in Figure 2 , the content authentication software code 210 and the isolated database 208 including the manipulated digital content 254 generally correspond to Figure 1 the content authentication software code 110 and the isolated database 108 including the manipulated digital content 154 in

[0028] As Figure 2As further shown in, the content manufacturing device 230 includes a hardware processor 234 and a memory 236, and the memory 236 is a non - temporary storage device configured to store digital content manufacturing software 238. The hardware processor 234 can be a central processing unit (CPU) of the content manufacturing device 230. For example, therein, the hardware processor 234 runs the operating system of the content manufacturing device 230 and executes the digital content manufacturing software 238.

[0029] According to Figure 2 the exemplary embodiment shown, the content manufacturing device 230 further includes a transceiver 232 and one or more position / location sensors 244 (hereinafter referred to as "position / location sensors 244"). Figure 2 Also shown in are a camera 240, one or more acoustic sensors 242 (hereinafter referred to as "acoustic sensors 242"), a radio frequency identification (RFID) reader 248, and baseline digital content 250 generated by the content manufacturing device 230.

[0030] It should be noted that including Figure 2 the specific sensor components shown in is merely exemplary. In some embodiments, the content manufacturing device 230 may include fewer Figure 2 sensor components than shown in, while in some embodiments, the content manufacturing device 230 may include Figure 2 additional sensor components not shown in. For example, in some embodiments, to name a few possible alternative sensor features, the content manufacturing device 230 may omit the RFID reader 248 and / or may include a Bluetooth or Bluetooth Low Energy (Bluetooth LE) transceiver, and / or may include a Near Field Communication (NFC) module.

[0031] The transceiver 232 can be implemented as a wireless communication unit such that the content manufacturing device 230 can exchange data with the system 100 / 200 via the communication network 124 and the network communication link 126 / 226. For example, the transceiver 232 can be implemented as a fourth - generation (4G) wireless transceiver, or a 5G wireless transceiver configured to meet the IMT - 2020 requirements set by the International Telecommunication Union (ITU). The position / location sensors 244 can include one or more accelerometers, and / or gyroscopes, and / or GPS receivers and / or magnetometers. In some embodiments, as is known in the art, the position / location sensors 244 can be implemented as an inertial measurement unit (IMU). The camera 240 can include a still - image camera and / or a video camera. Additionally, in some embodiments, the camera 240 can correspond to an array of cameras configured to generate panoramic images of still images and / or videos.

[0032] Figure 2 The content manufacturing device 230 in corresponds generally to Figure 1the content manufacturing device 130. Thus, the content manufacturing device 130 may share any features of the present invention that belong to the content manufacturing device 230, and vice versa. That is, although not shown in Figure 1 the content manufacturing device 130 may include a plurality of features corresponding to the transceiver 232, the location / location sensor 244, the hardware processor 234, and the memory 236 storing the digital content manufacturing software 238, respectively, and may further include a plurality of features corresponding to the camera 240, the acoustic sensor 242, and the RFID reader 248.

[0033] Reference will be made to Figure 3 and in conjunction with Figure 1 、 Figure 2 and Figure 4 to further describe the functions of the content authentication software code 110 / 210. Figure 3 FIG. 370 is shown, which is a flowchart showing an exemplary method for a system to perform content authentication based on inherent properties according to an embodiment. Regarding Figure 3 the method outlined in, it should be noted that certain details and features are omitted in the flowchart 370 so as not to obscure the discussion of the inventive features in this application.

[0034] Figure 4 FIG. shows an example diagram of content authentication software code 410 suitable for execution by the hardware processor 104 / 204 of the system 100 / 200 shown in Figure 1 and Figure 2 . As shown in Figure 4 , the content authentication software code 410 may include a content parsing module 412, a checksum generator module 414, an authentication module 416, and an output module 418. In addition, Figure 4 FIG. shows a content file 460, the content file 460 includes baseline digital content 450 and authentication data 462 created based on the inherent properties of the baseline digital content 450, and FIG. shows a content file 464, the content file 464 includes authentication data 462 and manipulated digital content 454, and the manipulated digital content 454 includes one or more modifications to the baseline digital content 450. Figure 4 Also shown in are the checksum data 466a and / or 466b generated by the checksum generator module 414, the content classification 468 output by the authentication module 416, and the isolation database 408.

[0035] The baseline digital content 450, the manipulated digital content 454, and the isolation database 408 generally correspond to Figure 1 and Figure 2The baseline digital content 150 / 250, the manipulated digital content 154 / 254, and the isolation database 108 / 208 therein, and any features of the present invention attributable to these corresponding features may be shared. In addition, Figure 4 The content files 460 and 464 therein generally correspond to Figure 1 The content files 160 and 164 therein. Accordingly, the content files 160 and 164 may share any features of the present invention attributable to the corresponding content files 460 and 464, and vice versa. That is to say, although not shown in Figure 1 The content file 160 may include, in addition to the baseline digital content 150, authentication data 462 created based on the inherent attributes of the baseline digital content 450, and the content file 164 may include, in addition to the manipulated digital content 154 including one or more modifications to the baseline digital content 150, the authentication data 462.

[0036] Figure 4 The content authentication software code 410 therein generally corresponds to Figure 1 And Figure 2 The content authentication software codes 110 / 210 therein. In other words, the content authentication software codes 110 / 210 may share any features of the present invention attributable to the corresponding content authentication software code 410, and vice versa. Accordingly, similar to the content authentication software code 410, the content authentication software codes 110 / 210 may include modules corresponding to a content parsing module 412, a checksum generator module 414, an authentication module 416, and an output module 418, respectively.

[0037] In combination with Figure 1 、 Figure 2 And Figure 4 And with reference to Figure 3 , the flowchart 370 first receives, by the system 100 / 200, a content file including digital content and authentication data created based on a baseline version of the digital content (act 371). There are various use cases corresponding to act 371. For example, in one case, the system 100 / 200 may receive, from the content manufacturing device 130 / 230, the content file 160 / 460 including the baseline digital content 150 / 250 / 450 and the authentication data 462 created based on the inherent attributes of the baseline digital content 150 / 250 / 450.

[0038] The inherent properties of the baseline digital content 150 / 250 / 450 on which the authentication data 462 is based can include the baseline digital content 150 / 250 / 450 itself, as well as specific features of the baseline digital content 150 / 250 / 450, such as the size of the baseline digital content 150 / 250 / 450 in bytes and / or its data format. Alternatively, or additionally, the inherent properties of the baseline digital content 150 / 250 / 450 on which the authentication data 462 is based can include metadata, where the metadata can be a device identifier (device ID) identifying the content manufacturing device 130 / 230, a software application identifier (application ID) of the digital content manufacturing software 238 used to generate the baseline digital content 150 / 250 / 450, and / or a user identifier (user ID) of the content manufacturing device 130 / 230. Additionally, in some embodiments, the inherent properties of the baseline digital content 150 / 250 / 450 on which the authentication data 462 is based can include metadata, where the metadata can be the manufacturing date, manufacturing time, and / or the location of the content manufacturing device 130 / 230 at the time of manufacturing of the baseline digital content 150 / 250 / 450, e.g., based on data recorded by the acoustic sensor 242, the location / location sensor 244, and / or the RFID reader 248.

[0039] In yet another other embodiment, the inherent properties of the baseline digital content 150 / 250 / 450 on which the authentication data 462 is based can include the device IDs of other devices connected to the content manufacturing device 130 / 230 at the time of generating the baseline digital content 150 / 250 / 450. In some embodiments, some or all of this metadata describing the ID of the content manufacturing device 130 / 230, the device IDs of other devices connected to the content manufacturing device 130 / 230, the user ID of the content manufacturing device 130 / 230, the time, and the location of the content manufacturing device 130 / 230 can be transmitted by the content manufacturing device 130 / 230 to a centralized authorization service that provides an "authorize to create content" authorization token. For example, in an embodiment where the baseline digital content 150 / 250 / 450 includes a video, the authorization token can be hashed with each frame of the video.

[0040] Any or all of the above inherent properties (including the baseline digital content 150 / 250 / 450) can be hashed using any suitable cryptographic hash function, such as one of the Secure Hash Algorithm (SHA) family of hash functions (e.g., SHA-0, SHA-1, SHA-2, or SHA-3). Thus, the authentication data 462 can include the hash value of the baseline digital content 150 / 250 / 450 and some, all, or any additional inherent properties of the baseline digital content 150 / 250 / 450 described above.

[0041] In other use cases, the system 100 / 200 can receive a content file 164 / 464 from a content manipulation device 152, the content file 164 / 464 including manipulated digital content 154 / 254 / 454, the manipulated digital content 154 / 254 / 454 including one or more modifications to baseline digital content 150 / 250 / 450. It should be noted that in embodiments where the authentication data 462 takes the form of a hash value of the baseline digital content 150 / 250 / 450 and some, all, or none of the additional inherent attributes of the above baseline digital content 150 / 250 / 450, modifying the baseline digital content 150 / 250 / 450 to produce the manipulated digital content 154 / 254 / 454 generally does not change the authentication data 462. As a result, as Figure 4 shown, the content file 164 / 464 including the manipulated digital content 154 / 254 / 454 can also include authentication data 462 created based on the inherent attributes of the baseline digital content 150 / 250 / 450 in its original form.

[0042] For example, in one embodiment, the GPS check result and the baseline digital content 150 / 250 / 450 can be hashed together. If a news station including the system 100 receives unvalidated content and its hash value does not match, the news station can determine that the unvalidated content is not the baseline digital content 150 / 250 / 450, or is not forwarded by a firsthand witness at the time described in the unvalidated content. Alternatively, or additionally, the clock check result can be hashed together with the baseline digital content 150 / 250 / 450. If the news station receives unvalidated content and its hash value does not match, the news station can determine that the unvalidated content is not the baseline digital content 150 / 250 / 450, or is not created at the time when the event described in the unvalidated content occurred.

[0043] In some embodiments, the authentication data 462 can be attached to the baseline digital content 150 / 250 / 450 and / or the manipulated digital content 154 / 254 / 454. For example, as is known in the art, the authentication data 462 can be attached as a "sidecar" to the baseline digital content 150 / 250 / 450 and / or the manipulated digital content 154 / 254 / 454. However, in other embodiments, it may be advantageous or desirable to embed the authentication data 462 in the baseline digital content 150 / 250 / 450. Embedding the authentication data 462 in the baseline digital content 150 / 250 / 450 can advantageously avoid stripping the authentication data 462 from the baseline digital content 150 / 250 / 450. Thus, in embodiments where the authentication data 462 is embedded in the baseline digital content 150 / 250 / 450, the authentication data 462 can also be embedded in the manipulated digital content 154 / 254 / 454.

[0044] Content files 160 / 460 including baseline digital content 150 / 250 / 450 and authentication data 462 and / or content files 164 / 464 including manipulated digital content 154 / 254 / 454 and authentication data 462 are received by content parsing module 412 of content authentication software code 110 / 210 / 410 executable by hardware processors 104 / 204. The hardware processors 104 / 204 may further execute the content authentication software code 110 / 210 / 410 to extract, using the content parsing module 412, the baseline digital content 150 / 250 / 450 from the content files 160 / 460, and / or the manipulated digital content 154 / 254 / 454 from the content files 164 / 464 for transmission of the baseline digital content 150 / 250 / 450 and / or the manipulated digital content 154 / 254 / 454 to the checksum generator module 414. Additionally, the content parsing module 412 may extract the authentication data 462 from the content files 160 / 460 and / or the content files 164 / 464 for transmission to the authentication module 416.

[0045] Flowchart 370 continues to generate checksum data 466a based on the baseline digital content 150 / 250 / 450 and / or generate checksum data 466b based on the manipulated digital content 154 / 254 / 454 received at action 371 (action 372). In embodiments where the authentication data 462 includes the hash value of the baseline digital content 150 / 250 / 450, the generation of the checksum data 466a based on the baseline digital content 150 / 250 / 450 may include hashing the baseline digital content 150 / 250 / 450 using the same cryptographic hash function used to generate the authentication data 462. Additionally, in these embodiments, the generation of the checksum data 466b based on the manipulated digital content 154 / 254 / 454 may include hashing the manipulated digital content 154 / 254 / 454 using the same cryptographic hash function used to generate the authentication data 462.

[0046] In embodiments where the "determine create content" authorization token provided by the centralized authorization service is hashed with the baseline digital content 150 / 250 / 450 to generate the authentication data, the hardware processors 104 / 204 may execute the content authentication software code 110 / 210 / 410 to obtain the authorization token from the authorization service as part of action 372. In these embodiments, the authorization token may be hashed with the baseline digital content 150 / 250 / 450 to generate the checksum data 466a, or the authorization token may be hashed with the manipulated digital content 154 / 254 / 454 to generate the checksum data 466b.

[0047] The verification data 466a and / or the verification data 466b can be generated by a verification generator module 414 of the content authentication software code 110 / 210 / 410 executed by the hardware processor 104 / 204. As Figure 4 shown, after the verification data 466a and / or the verification data 466b are generated in operation 372, the verification data 466a and / or the verification data 466b can be transmitted from the verification generator module 414 to an authentication module 416 of the content authentication software code 110 / 210 / 410.

[0048] Flowchart 370 continues by comparing the verification data 466a and / or the verification data 466b with the authentication data 462 (operation 373). For example, in an embodiment where the authentication data 462 includes a hash value of the baseline digital content 150 / 250 / 450, the verification data 466a includes a hash value of the baseline digital content 150 / 250 / 450, and the verification data 466b includes a hash value of the manipulated digital content 153 / 254 / 454, operation 373 can be performed by comparing the hash values. That is, the hash value included in the verification data 466a can be compared with the hash value included in the authentication data 462, and / or the hash value included in the verification data 466b can be compared with the hash value included in the authentication data 462. The verification data 466a and / or the verification data 466b can be compared with the authentication data 462 by an authentication module 416 of the content authentication software code 110 / 210 / 410 executed by the hardware processor 104 / 204.

[0049] In use cases where a content file 160 / 460 including the baseline digital content 150 / 250 / 450 is received in operation 371, the verification data 466a matches the authentication data 462. In these use cases, an authentication module 416 of the content authentication software code 110 / 210 / 410 executed by the hardware processor 104 / 204 identifies the baseline digital content 150 / 250 / 450 as the baseline digital content in response to determining that the verification data 466a matches the authentication data 462 based on the comparison performed in operation 373 (operation 374a). Conversely, in use cases where a content file 164 / 464 including the manipulated digital content 154 / 254 / 454 is received in operation 371, the verification data 466b does not match the authentication data 462. In these use cases, an authentication module 416 of the content authentication software code 110 / 210 / 410 executed by the hardware processor 104 / 204 identifies the manipulated digital content 154 / 254 / 454 as the manipulated digital content in response to determining that the verification data 466b does not match the authentication data 462 based on the comparison performed in operation 373 (operation 374b).

[0050] In some embodiments, the exemplary method outlined by flowchart 370 may end with action 374a or 374b as described above. However, as Figure 3 shown, in other embodiments, after action 374a, the baseline digital content 150 / 250 / 450 may be output to a content distributor communicatively coupled to system 100 / 200 and distributed by the content distributor to a consumer audience 156 (action 375a). For example, as Figure 1 shown, in some embodiments, the baseline digital content 150 / 250 / 450 may be classified by content classification 468 and output to a content broadcast source 120, which may be a cable or satellite television network. Alternatively, or additionally, in some embodiments, the baseline digital content 150 / 250 / 450 may be output to CDN 122 to distribute the baseline digital content 150 / 250 / 450 as an IP stream. Action 375a may be performed by content authentication software code 110 / 210 / 410, which is executed by hardware processors 104 / 204 and uses output module 418.

[0051] Alternatively, in embodiments where the manipulated digital content 154 / 254 / 454 is identified as manipulated digital content in action 374b, flowchart 370 may continue to isolate the manipulated digital content 154 / 254 / 454 to prevent its distribution by a content distributor such as content broadcast source 120 or CDN 122 (action 375b). In these embodiments, hardware processors 104 / 204 may execute content authentication software code 110 / 210 / 410 to transmit, using output module 418 and based on content classification 468, the digital content classified as manipulated digital content 154 / 254 / 454 to an isolation database 108 / 208 / 408 for isolation and storage.

[0052] Note that, in some embodiments, hardware processors 104 / 204 may execute content authentication software code 110 / 210 / 410 to perform actions 371, 372, 373 (hereinafter referred to as "actions 371-373"), and subsequent actions 374a and / or 375a in an automated process, where the involvement of personnel may be omitted. Alternatively, or additionally, in some embodiments, hardware processors 104 / 204 may execute content authentication software code 110 / 210 / 410 to perform actions 371-373, 374b and / or 375b in an automated process, where the involvement of personnel may be omitted.

[0053] Accordingly, the present application discloses a system and method for performing content authentication based on inherent attributes, overcoming the disadvantages and deficiencies in the prior art. As described above, by comparing the verification data of the received digital content with the authentication data of the content created based on the inherent attributes of the content received in the original or baseline version, this authentication solution advantageously utilizes the characteristics of the digital content itself to uniquely identify it. In addition, by using the same encryption technology used to create the authentication data for the baseline digital content to generate the verification data for comparison with the authentication data, the present application discloses a sound and substantially error-proof authentication solution.

[0054] It is apparent from the above description that various techniques can be used to implement the concepts described in the present application without departing from the scope of these concepts. In addition, although these concepts have been specifically described with reference to certain embodiments, those of ordinary skill in the art will recognize that changes can be made in form and detail without departing from the scope of these concepts. Accordingly, the described embodiments are to be considered in all respects illustrative and not restrictive. It should also be understood that the present application is not limited to the specific embodiments described herein, and many rearrangements, modifications, and substitutions can be made without departing from the scope of the present disclosure.

Claims

1. A system for determining the authenticity of digital content, the system comprising: A computing platform including a hardware processor and a system memory; Content authentication software code stored in the system memory; The hardware processor is configured to execute the content authentication software code to: Receive a content file including the digital content and authentication data, the authentication data being created based on a baseline version of the digital content and based on inherent attributes of the digital content; Generate verification data based on the digital content; Compare the verification data with the authentication data; Identify the digital content as baseline digital content in response to determining that the verification data matches the authentication data based on the comparison; And Identify the digital content as manipulated data content in response to determining that the verification data does not match the authentication data based on the comparison, wherein the baseline version of the digital content is produced by digital content production software in a content production device, and wherein the inherent attributes of the baseline version of the digital content include metadata that identifies: (i) the device identifier of the content production device and / or other devices connected to the content production device, and / or (ii) the user identifier of the content production device, and / or (iii) the location of the content production device at the time of production, wherein the metadata is transmitted by the content production device to a centralized authorization service that provides an authorization token, and wherein the authorization token is hashed with the baseline digital content to generate the authentication data such that the authentication data includes a hash value of the baseline digital content; Generating the verification data includes hashing the authorization token with the baseline digital content, such that the verification data includes a hash value of the baseline digital content, wherein comparing the verification data with the authentication data includes comparing the hash value of the authentication data and the hash value of the verification data.

2. The system according to claim 1, wherein the hardware processor is configured to further execute the content authentication software code to output the baseline digital content to a content distributor communicatively connected to the system for distribution by the content distributor to a consumer audience.

3. The system according to claim 2, wherein the content distributor includes at least one of a cable television (TV) network or a satellite TV network.

4. The system according to claim 2, wherein the content distributor is configured to distribute the baseline digital content as an Internet Protocol (IP) stream.

5. The system according to claim 2, wherein the hardware processor is configured to further execute the content authentication software code to isolate the manipulated digital content to prevent it from being distributed by the content distributor.

6. The system according to claim 1, wherein the authentication data is appended to the digital content.

7. The system according to claim 1, wherein the authentication data is embedded in the digital content.

8. The system according to claim 1, wherein the digital content includes at least one of digital photos and audio-video content.

9. The system according to claim 1, wherein the inherent attributes of the baseline version of the digital content further include one or more of the following: The size of the baseline version of the digital content; The data format of the baseline version of the digital content; The manufacturing date of the baseline version of the digital content; or The software application identification of the digital content manufacturing software used to manufacture the baseline version of the digital content.

10. The system according to claim 1, wherein the digital content includes video, and wherein generating the verification data includes hashing the authorization token together with each frame of the video.

11. A method used by a system for determining the authenticity of digital content, the system including a computing platform having a hardware processor and a system memory storing content authentication software code, the method including: Receiving, by the content authentication software code executed by the hardware processor, a content file including the digital content and authentication data, the authentication data being created based on the baseline version of the digital content and based on the inherent attributes of the digital content; Generating, by the content authentication software code executed by the hardware processor, verification data based on the digital content; Comparing, by the content authentication software code executed by the hardware processor, the verification data with the authentication data; Identifying, by the content authentication software code executed by the hardware processor, the digital content as baseline digital content in response to determining that the verification data matches the authentication data based on the comparison; and Identifying, by the content authentication software code executed by the hardware processor, the digital content as manipulated digital content in response to determining that the verification data does not match the authentication data based on the comparison, wherein the baseline version of the digital content is made by digital content manufacturing software in a content manufacturing device, and wherein the inherent attributes of the baseline version of the digital content include metadata that identifies: (i) the device identification of the content manufacturing device and / or other devices connected to the content manufacturing device, and / or (ii) the user identification of the content manufacturing device, and / or (iii) the location of the content manufacturing device at the time of manufacture, wherein the metadata is transmitted by the content manufacturing device to a centralized authorization service that provides an authorization token, and wherein the authorization token is hashed with the baseline digital content to generate the authentication data such that the authentication data includes a hash value of the baseline digital content; Generating the verification data includes hashing the authorization token with the baseline digital content, such that the verification data includes a hash value of the baseline digital content, wherein comparing the verification data with the authentication data includes comparing the hash value of the authentication data and the hash value of the verification data.

12. The method according to claim 11 further includes outputting the baseline digital content to a content distributor communicatively connected to the system through the content authentication software code for distribution by the content distributor to consumer viewers.

13. The method according to claim 12, wherein the content distributor includes at least one of a cable television (TV) network or a satellite TV network.

14. The method according to claim 12, wherein the content distributor is configured to distribute the baseline digital content as an Internet Protocol (IP) stream.

15. The method according to claim 12 further includes isolating the manipulated digital content through the content authentication software code executed by the hardware processor to prevent it from being distributed by the content distributor.

16. The method according to claim 11, wherein the authentication data is appended to the digital content.

17. The method according to claim 11, wherein the authentication data is embedded in the digital content.

18. The method according to claim 11, wherein the received digital content includes at least one of digital photos or audio - video content.

19. The method according to claim 11, wherein the inherent attributes of the baseline version of the digital content further include one or more of the following: The size of the baseline version of the digital content; The data format of the baseline version of the digital content; The manufacturing date of the baseline version of the digital content; or The software application identification of the digital content manufacturing software used to manufacture the baseline version of the digital content.

20. The method according to claim 11, wherein the digital content includes video, and wherein generating the check data includes hashing the authorization token together with each frame of the video.

Citation Information

Patent Citations

  • Authenticity assessment of modified content

    US10951958B1

  • Elias

    US260636A

  • Method and apparatus for protecting digital photos from alteration

    US20180336656A1

  • System and method for secured capturing and authenticating of video clips

    WO2016207899A1