Authenticity verification system, content management device, content generation device, control method for system and device, and program for system and device

By generating a hash value and appending source information in the camera device, combined with the verification processing of the content management device, the problem of distinguishing between legal image editing and illegal tampering is solved, ensuring the authenticity verification of the image.

CN120604233APending Publication Date: 2025-09-05CANON KK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202380092434.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-01-30
Filing Date
2023-12-28
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

Existing technologies cannot accurately distinguish between legal editing and illegal tampering of images, and cannot verify whether the images were generated by a reliable camera device when shooting.

Method used

By generating a hash value and appending source information in the camera device, combined with verification processing by the content management device, the authenticity of the image is determined, including verifying the validity of the source information and the corresponding relationship stored in the storage device.

Benefits of technology

It realizes the authenticity verification of the image, distinguishes between legal editing and illegal tampering, and ensures that the image is captured and generated by a reliable camera device.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120604233A_ABST
    Figure CN120604233A_ABST
Patent Text Reader

Abstract

The purpose of the present invention is to determine whether or not content is tampered with by an illegal user, and whether or not original content before change is initial content generated by a reliable content generation device. A content management apparatus of the present invention receives content in content generation from a content generation apparatus, and stores the generated content in a storage device. A content management device acquires, from a user terminal, content to be determined and source information attached to the content. The content management apparatus determines the authenticity of the content to be determined on the basis of whether the content in the content generation corresponding to the content to be determined is stored in the storage device and on the basis of the verification result of the source information. The content management device notifies the user terminal of the determination result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a technology for verifying the authenticity of content. Background Art

[0002] In recent years, information sharing via the internet has become increasingly active, allowing anyone to publish and send a wide range of information to a large, unspecified audience. Furthermore, digital images can be subjected to various manipulations. In such cases, information may be sent from unreliable sources or illegally tampered with.

[0003] Hitherto, it has been known that a digital camera generates a hash value from an image when shooting and outputs the image with the generated hash value, and a verification apparatus generates a hash value from an image and performs image tampering verification using the hash value attached to the image (see PTL 1).

[0004] In addition, in order to prove the source, background, and provenance of an image, it has been proposed to attach metadata indicating the editing content of the image to the image (see NPL 1).

[0005] Reference List

[0006] Patent Literature

[0007] PTL 1: Japanese Patent Laid-Open No. 2011-124663

[0008] Non-patent literature

[0009] NPL 1: Content Provenance and Authenticity Alliance (C2PA), C2PA Specification, <Technical Specification Version 1.2>, [Online], 3 November 2022, [Retrieved 23 January 2023], Internet

[0010] <URL:https: / / c2pa.org / specifications / specifications / 1.2 / specs / C2PA_Specific ation.html> Summary of the Invention

[0011] Technical issues

[0012] With the technology in PTL 1, the user can know whether the image has been modified. However, the user cannot know whether the modification to the image is editing by a legitimate user or tampering by an illegitimate user.

[0013] Furthermore, using the technology in NPL 1, users can determine not only whether an image has been modified, but also whether the image modification was made by a legitimate user or tampered with by an unauthorized user, based on the specified metadata. However, users cannot verify the authenticity of the image itself, including whether the original image before editing was the original image generated by a reliable camera during capture.

[0014] Problem Solution

[0015] One aspect of the present invention includes: a unit for receiving content in content generation from a content generating apparatus; a unit for storing the content in content generation in a storage device; a unit for obtaining content to be determined and source information attached to the content to be determined; and a unit for determining the authenticity of the content to be determined based on whether the content in content generation corresponding to the content to be determined is stored in the storage device and based on a verification result of the source information.

[0016] Advantageous Effects of the Invention

[0017] The present invention achieves the following effects: not only can it verify whether the content has been tampered with, but it can also verify whether the original content is the content generated by a reliable content generation device. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 is a diagram illustrating a configuration example of the authenticity verification system of the present invention.

[0019] Figure 2 is a block diagram illustrating a configuration example of an image pickup apparatus of the present invention.

[0020] Figure 3 is a block diagram illustrating a configuration example of a content management apparatus of the present invention.

[0021] Figure 4 is a block diagram illustrating an example of a user terminal of the present invention.

[0022] Figure 5 This is a flowchart showing an example of the operation of the imaging device of the present invention.

[0023] Figure 6 is a diagram illustrating a configuration example of an image file of the present invention.

[0024] Figure 7 This is a flowchart showing an example of the operation of the content management device of the present invention.

[0025] Figure 8 This is a flowchart showing an example of the operation of the content management device of the present invention.

[0026] Figure 9AFIG. 1 is a diagram illustrating an example of a screen displayed in a user terminal according to the present invention.

[0027] Figure 9B FIG. 1 is a diagram illustrating an example of a screen displayed in a user terminal according to the present invention.

[0028] Figure 9C FIG. 1 is a diagram illustrating an example of a screen displayed in a user terminal according to the present invention.

[0029] Figure 9D FIG. 1 is a diagram illustrating an example of a screen displayed in a user terminal according to the present invention. DETAILED DESCRIPTION

[0030] Herein, preferred embodiments of the present invention will be described in detail using examples with reference to the accompanying drawings. However, the components described in the embodiments are only examples, and the scope of the present invention is not intended to be limited to these components.

[0031] (First embodiment)

[0032] Figure 1 is a diagram illustrating an example configuration of an authenticity verification system 100. The authenticity verification system 100 includes an imaging device 200, a content management device 300, a user terminal 400, and a content providing device 500. The content management device 300 communicates with the imaging device 200 and the user terminal 400 via a network to transmit and receive various data and information, such as content files. In this embodiment, image files are used as an example of content files. Content files are not limited to image files and may also include audio files, etc.

[0033] The camera 200 uploads the image files at the time of shooting (at the time of content creation) to the content management apparatus 300 via the network. The content management apparatus 300 stores the image files at the time of shooting in a database system and saves the database in a storage device.

[0034] Upon accepting a verification request for an image file to be determined from the user terminal 400 , the content management apparatus 300 performs verification processing on the image file in the following manner, and notifies the user terminal 400 of the verification result.

[0035] User terminal 400 can obtain the image file to be verified from an external device, such as camera 200 or content provider 500. Content provider 500 is, for example, a personal computer (PC), a smartphone, a tablet computer, a camera device different from camera 200, or a World Wide Web (WEB) server device (such as an image distribution website). Content provider 500 may be installed with editing tools, such as image editing application software, and can freely edit image files. Furthermore, content provider 500 may also provide image files obtained from other content providers to user terminal 400. Therefore, an image file obtained by user terminal 400 from an external device may be unmodified from the image file at the time of capture, may have been legally edited, or may have been illegally tampered with. However, user terminal 400 cannot accurately determine these circumstances. Therefore, to confirm the authenticity of the image file obtained from the external device, user terminal 400 requests content management device 300 to verify the authenticity of the image file.

[0036] Figure 2 is a block diagram illustrating an example configuration of an imaging device 200. The imaging device 200 is an electronic device such as a digital camera, a digital video camera, or a mobile phone or computer device with a camera function. The imaging device 200 is an example of a content generation device and may also be a device that generates image data based on a user-drawn graphic image, a device that records sound to generate audio data, or a device that generates audio data of user-composed music.

[0037] Reference Figure 2 The imaging device 200 includes a microprocessing unit (MPU) 201, a timing signal generating circuit 202, an imaging element 203, an analog-to-digital (A / D) converter 204, a storage controller 205, a buffer memory 206, and an image display unit 207. In addition, the imaging device 200 also includes a recording medium interface (I / F) 208, a recording medium 209, a hash value generating unit 210, and a communication unit 211.

[0038] The MPU 201 is a microcontroller for controlling matters related to the system of the imaging apparatus 200 such as a photographing sequence.

[0039] The timing signal generating circuit 202 generates a timing signal necessary for the operation of the imaging element 203 .

[0040] The imaging element 203 is an imaging element such as a charge coupled device (CCD) or a complementary metal oxide semiconductor (CMOS) that converts reflected light of an object into an electric signal (analog image data) and reads the analog image data to an A / D converter 204 .

[0041] The A / D converter 204 converts the analog image data read from the image pickup element 203 into digital image data. Hereinafter, the digital image data will be simply referred to as "image data."

[0042] The memory controller 205 controls reading and writing of image files to and from the buffer memory 206, and refreshing the buffer memory 206. The image file is generated by the MPU 201 in the following manner and has metadata attached to the image data.

[0043] The buffer memory 206 stores image files.

[0044] The image display unit 207 displays the image file stored in the buffer memory 206 .

[0045] The recording medium I / F 208 is an interface for controlling reading and writing of data with respect to the recording medium 209 .

[0046] The recording medium 209 is, for example, a storage medium such as a memory card that is removable from the imaging apparatus 200 , and stores programs, image files, and the like.

[0047] The hash value generation unit 210 performs a hash function on the image file stored in the buffer memory 206 to generate (calculate) a hash value. Instead of the hash value generation unit 210, the MPU 201 may generate a hash value. The process of generating a hash value will be described in detail below.

[0048] The communication unit 211 is connected to a network line 220 such as the Internet to transmit and receive data to and from an external device.

[0049] Figure 3 is a block diagram illustrating an example configuration of content management apparatus 300. In this embodiment, a server computer is used as an example of content management apparatus 300. Content management apparatus 300 can be implemented as a single server computer, or by distributing the various functions of content management apparatus 300 to a desired number of server computers. When content management apparatus 300 is composed of multiple server computers, the multiple server computers are interconnected via a communication line, such as a local area network (LAN).

[0050] Reference Figure 3The control unit 301 controls the server computer device and is, for example, a central processing unit (CPU). The read-only memory (ROM) 302 stores programs and parameters that do not need to be changed. The random access memory (RAM) 303 temporarily stores programs and data provided from external devices, etc. The storage device 304 is a hard disk drive (HDD) installed in the server computer device, a solid-state drive (SSD) composed of flash memory, a hybrid drive using both a hard disk and flash memory, a memory card, etc. The storage device 304 stores programs such as the operating system (OS). In addition, the storage device 304 also stores various data required to implement this embodiment, such as the image files for shooting described below. The input interface 305 accepts user operations and is used to connect to input devices such as a pointing device and a keyboard for inputting data. The bit shift unit (BMU) 306 controls data transfer between memories (e.g., video RAM (VRAM) 307 and other memories) and between memories and various input / output (I / O) devices (e.g., network interface 309). The VRAM 307 draws images to be displayed on the display device 311. The image generated in the VRAM 307 is transferred to the display device 311 according to a predetermined standard, and the display device 311 displays the image. The network interface 309 is used to connect the content management apparatus 300 to a network line 310 such as the Internet. The system bus 312 connects the various units 301 to 309 to enable communication.

[0051] Figure 4 4 is a block diagram illustrating a configuration example of the user terminal 400. In this embodiment, a personal computer (PC) is described as an example of the user terminal 400. The user terminal 400 is not limited to a personal computer, and may be a smartphone or a tablet device.

[0052] Reference Figure 4The control unit 401 controls the personal computer device and is, for example, a central processing unit (CPU). The read-only memory (ROM) 402 stores programs and parameters that do not need to be changed. The random access memory (RAM) 403 temporarily stores programs and data provided from external devices, etc. The storage device 404 is a hard disk drive (HDD) installed in the personal computer device, a solid-state drive (SSD) composed of flash memory, a hybrid drive using both a hard disk and flash memory, a memory card, etc. The storage device 404 stores programs such as the operating system (OS). In addition, the storage device 404 also stores various data required to implement this embodiment, such as the image file to be determined described below. The input interface 405 accepts user operations and is used to connect to input devices such as a pointing device and a keyboard for inputting data. The bit shift unit (BMU) 406 controls data transfer between, for example, memories (e.g., video RAM (VRAM) 407 and 337 and other memories) and between memories and various input-output (I / O) devices (e.g., network interface 409). The VRAM 407 draws the image to be displayed on the display device 411. The image generated in the VRAM 407 is transmitted to the display device 411 according to a predetermined standard, and the display device 411 displays the image. The network interface 409 is used to connect the user terminal 400 to a network line 410 such as the Internet. The system bus 412 connects the various units 401 to 409 to enable communication.

[0053] Will refer to Figure 5 The flowchart in FIG. 1 describes the process performed by the imaging device 200 to generate an image file at the time of shooting and upload the image file to the content management device 300. The process is implemented by the MPU 201 in the imaging device 200 executing a program stored in the recording medium 209 or the like. The process starts when the imaging device 200 receives a shooting start operation, such as when the photographer presses a shooting button on the imaging device 200.

[0054] First, the MPU 201 drives a shutter (not shown) located on the object side relative to the imaging element 203 to control the exposure time (S501). The MPU 201 performs imaging processing to convert light from the object received by the imaging element 203 via the shutter into an electrical signal (analog image data) (S502). The MPU 201 performs image processing, such as development and encoding, on the electrical signal generated by the imaging processing to generate image data (S503).

[0055] Next, the MPU 201 generates Figure 6, metadata 601 including shooting information 602 and source information 603 related to image data 604 is shown (S504). The shooting information 602 is information obtained when performing the image capture process to generate the image data 604, and includes, for example, the shooting date and time, the photographer, the image size, the manufacturer and model of the camera 200, various shooting parameters set at the time of shooting, the shooting location, a thumbnail, etc. The shooting information 602 is generated according to a predetermined technical standard (e.g., Exchangeable Image File Format (EXIF)).

[0056] The source information 603 is information used to prove the credibility of the image data 604 and is used to verify the provenance and source of the image data 604. The source information 603 is generated according to a predetermined technical standard (for example, the Content Provenance and Authenticity Alliance (C2PA)) and has a specified structure. The source information 603 includes a source (assertion) 613, a hash value 623, and a digital signature 633. The hash value 623 and the digital signature 633 are used to ensure the source 613. The source 613 stores source identification information (manifest ID) for uniquely identifying the source, an editing history indicating the edited content of the image data 604, an editing tool indicating the tool used for editing, and the creator of the image data 604. Since the image data 604 generated in step S503 has just been generated by shooting and has not yet been edited, the editing history stores information indicating "generated" and the editing tool stores information indicating the camera 200.

[0057] Next, the MPU 201 performs a hash function on the binary data of each of the image data 604 and the source 613 to generate a hash value 623 ( S505 ). A hash value can also be generated based on the binary data of the photographing information 602 .

[0058] The MPU 201 generates a digital signature 633 (S506). Digital signature 633 includes information indicating the signature value, the signer, and the date and time of the signature. The signature value is generated by encrypting the hash value 623 generated in S505 using a pre-prepared key. The public key paired with the key used here is also stored in digital signature 633. In this embodiment, information indicating the manufacturer of the camera 200 is stored as the signer. The manufacturer of the camera 200 is stored in the storage device 304 of the content management device 300 as a reliable signer, and this reliable signer generates the image file at the time of capture as the original image. Therefore, by attaching a digital signature 633 including such a signer to the image file 600, it is possible to indicate that the image file is reliable. Instead of the manufacturer, the model of the camera 200 can also be used as the signer. The date and time when the digital signature is generated is stored in the signature date and time. The capture date and time can also be stored in the source 613.

[0059] The MPU 201 adds the shooting information 602 and the source information 603 as metadata 601 to the image data 604 to create an image file 600 (S507). Here, when the image data 604 is a still image, the image file is generated in the Joint Photographic Experts Group (JPEG) format, and when the image data 604 is a movie, the image file is generated in the Moving Picture Experts Group (MPEG) format.

[0060] The MPU 201 transmits the image file 600 to the content management device 300 via the network (S509). The MPU 201 also stores the image file 600 in the recording medium 209. The image file 600 stored in the recording medium 209 only needs to include at least the image data 604 and the shooting information 602.

[0061] As described above, in this embodiment, when the camera 200 captures, the image file 600 is uploaded to the content management apparatus 300. The content management apparatus 300 acquires the image file generated by the camera 200 during the capture, and stores the image file in the storage device 304.

[0062] Image file 600 can be edited by content provider 500. If image file 600 is edited using an authorized editing tool through valid processing, source information 603 is newly generated based on the content edited according to predetermined technical standards and is attached to metadata 601 in image file 600 for storage. Each time image file 600 is edited, source information 603 is newly generated and attached to metadata 601 in image file 600 for storage. If image file 600 is edited using an unauthorized editing tool or through invalid processing, source information 603 may not be attached to image file 600, or the source information attached to image file 600 may not meet the predetermined technical standards.

[0063] Users can freely select an original image file based on predetermined technical criteria to set the selected image file. For example, an image file that was not the image file at the time of capture, but rather an edited image file, can be used as the original file (origin), and an image file that has been further edited can be used as the current image file. Therefore, while the source information based on the predetermined technical criteria indicates that the image file is the original image file, it is impossible to determine whether the image file was generated by a reliable camera during capture.

[0064] Will refer to Figure 7, the process of determining the authenticity of an image file by the content management apparatus 300 in response to a request from the user terminal 400 is described. The process is implemented by the control unit 301 in the content management apparatus 300 executing a program stored in the storage device 304 or the like.

[0065] First, the control unit 301 receives an image file to be determined from the user terminal 400 via the network ( S701 ).

[0066] Next, the control unit 301 determines whether the image file to be determined includes source information 603 (S702). If the image file to be determined does not include source information 603 ("No" in S702), the control unit 301 determines "Unknown" as the determination result (S703). The process then proceeds to step S712. If the image file to be determined includes source information 603 ("Yes" in S702), the control unit 301 performs the following verification process of the source information 603 (S704).

[0067] The control unit 301 determines whether the verification result of the source information 603 in step S704 is "invalid (tampered)" (S705). If the verification result is "invalid (tampered)" ("Yes" in S705), the control unit 301 determines "tampered (tampering traces)" as the determination result (S706). Then, the process proceeds to step S712.

[0068] If the verification result is not "invalid (tampered)" ("No" in S705), the control unit 301 determines whether the image file corresponding to the image file to be determined is stored in the storage device 304 (S707). The control unit 301 makes this determination based on whether an image file having the same identification information as the source identification information in the original source information 603 in the image file to be determined is stored in the storage device 304 as the current source information 603.

[0069] If the image file at the time of shooting is not saved (No in S707), the control unit 301 determines "unknown" as the determination result. The process then proceeds to step S712. If the image file at the time of shooting is saved (Yes in S707), the control unit 301 determines whether the verification result of the source information 603 in step S704 is "inconsistent" (S708).

[0070] If the verification result of the source information 603 is "not consistent" (YES in S708), the control unit 301 determines "updated" as the determination result (S709). The process then proceeds to step S712.

[0071] If the determination result is not "inconsistent" ("Yes" in S708), the control unit 301 determines whether the current source information 603 in the image file to be determined is the original source information 603. In other words, the control unit 301 determines whether the image file to be determined includes only the original source information 603. Since if the image file is edited, the image file includes not only the original file but also the source information 603 each time it is edited, the current source information is inconsistent with the original source information.

[0072] If the current source information 603 does not match the original source information (No in S710), the process proceeds to step S709. If the current source information 603 matches the original source information (Yes in S710), the control unit 301 determines "Source (original file)" as the determination result (S711). The process then proceeds to step S712.

[0073] The control unit 301 stores the determination result determined in the above manner in the storage device 304 in association with the image file to be determined received in step S701 (S712).

[0074] The determination result "source (original file)" indicates that the image file to be determined is the same as the image file at the time of shooting.

[0075] The determination result "updated" indicates that the image file to be determined results from valid editing of the metadata 601 or the image data 604 in the image file at the time of shooting.

[0076] The determination result "has been tampered with (tampering traces)" indicates that the image file to be determined is not derived from legal editing but has tampering traces.

[0077] The determination result "unknown" indicates that the effective editing of the image file to be determined is unknown or the relationship with the image file at the time of shooting is unknown.

[0078] Will refer to Figure 8 The verification process of the source information 603 in step S704 will be described with reference to the flowchart in FIG. The process is implemented by the control unit 301 in the content management apparatus 300 executing a program stored in the storage device 304 or the like.

[0079] First, the control unit 301 extracts source information 603 having a specified structure from the image file to be determined. If source information 603 having a specified structure is not extracted ("No" in S801), the control unit 301 determines "invalid (tampered)" as the verification result of the source information 603 (S802). The process then proceeds to step S705. If source information 603 having a specified structure is extracted ("Yes" in S801), the control unit 301 verifies the signature value of the digital signature 633 in the source information 603 in the image file to be determined using the public key (S803).

[0080] Control unit 301 determines whether the verification of signature value is successful (S804). If digital signature 633 is generated using a key paired with a public key, signature value can be correctly decoded. In addition, control unit 301 performs a hash function to generate a hash value to the binary data of source 613, and also determines whether the hash value generated is consistent with the hash value decoded using the public key. Therefore, if the signature value is decoded using the public key and the hash value generated is consistent with the hash value decoded using the public key, control unit 301 determines that the verification of signature value is successful. Otherwise, control unit 301 determines that the verification of signature value has failed.

[0081] If the signature value verification fails ("No" in S804), the process proceeds to step S802. If the signature value verification succeeds ("Yes" in S804), the control unit 301 determines whether the digital signature 633 in the image file to be determined is generated by a reliable signer (S805). Information about reliable signers is pre-stored in the storage device 304, and the control unit 301 makes this determination based on whether a signer identical to the signer 635 is stored in the storage device 304.

[0082] If the digital signature 633 is not generated by a reliable signer ("No" in S805), the process proceeds to step S802. If the digital signature 633 is generated by a reliable signer ("Yes" in S805), the control unit 301 performs a hash function on the binary data of the image data 604 in the image file to be determined to generate a hash value. The control unit 301 then compares the generated hash value with the image data hash value 624 in the image file to be determined (S806). Based on the comparison result, the control unit 301 determines whether the hash values ​​are consistent with each other (S807). If the hash values ​​are inconsistent with each other ("No" in S807), the control unit 301 determines "incomplete (inconsistent)" as the verification result of the source information 603 (S808). The process then proceeds to step S705. The control unit 301 may also perform a hash function on the binary data of the shooting information 602 in the image file to be determined to generate a hash value, and compare the generated hash value with the shooting information hash value 625 in the image file to be determined to determine whether the hash values ​​are consistent with each other.

[0083] If the hash values ​​coincide with each other (YES in S808), the control unit 301 determines "content voucher (coincidence)" as the verification result of the source information 603 (S809) The process then proceeds to step S705.

[0084] The verification result "content certificate (valid)" indicates that the image file to be determined has correct source information and is generated by a reliable signer.

[0085] The verification result "incomplete (inconsistent)" indicates that the image data 604 in the image file to be determined is inconsistent with the source information 603. For example, an inconsistency occurs when only the image data 604 is edited but the source 613 is not, or when only the source 613 is edited but the image data 604 is not. This situation may occur when the image file 600 is edited by an unauthorized editing tool.

[0086] The verification result "invalid (tampering trace)" means that tampering traces are detected in the image file based on the source information or the image file is generated by an unreliable signer.

[0087] Will refer to 9A to 9D, a description is given of screens displaying information related to image files whose authenticity is determined by content management apparatus 300. The following screens are displayed on display device 411 of user terminal 400 by content management apparatus 300. Content management apparatus 300 generates data to be displayed on each screen in response to access from user terminal 400 and transmits the generated data to be displayed on each screen to user terminal 400. User terminal 400 activates a web browser application and other applications and accesses a predetermined address of content management apparatus 300 to receive the data to be displayed on each screen and displays the received data on display device 411.

[0088] The user terminal 400 displays the main screen 901 on the display device 411 and, when the “upload” button 931 is pressed by the user operation, reads the image file to be determined from the storage device 404 and transmits the read image file to be determined to the content management apparatus 300 via the network.

[0089] Thumbnails of a plurality of image files that the content management device 300 receives from the user terminal 400 and undergoes authenticity determination processing are displayed in the list field 910a. The thumbnail 911a is displayed together with an icon 912 indicating the authenticity determination result of the corresponding image file. Icon 912-1 indicates "source (original file)", icon 912-2 indicates "updated", icon 912-3 indicates "tampered (tampering traces)", and icon 912-4 indicates "unknown". Metadata related to the image file corresponding to the thumbnail 911a selected in the list field 910a is displayed in the metadata field 920a. Various data related to the source information 603 are displayed in the source field 921a, and various data related to the shooting information 602 are displayed in the shooting information field 922a. In addition, the metadata field 920a also displays Figure 8 Information 924 indicating the verification result of the verification process of the source information 603.

[0090] In response to the user's selection operation of the comparison icon 932 on the main screen 901, the main screen 901 is switched to Figure 9B. The list field 910b is similar to the list field 910a. The image 941b and the current image 942b corresponding to the thumbnail 911b selected in the list field 910b are displayed in the comparison field 940b in a manner arranged next to each other. The metadata 601 related to the image 941b corresponding to the thumbnail 911b is displayed in the metadata field 920b-1, and the metadata 601 related to the current image 942b is displayed in the metadata field 920b-2. If there is any difference in the metadata 601 between the image 941b and the current image 942b, the items 923b-1 and 923b-2 with the difference are highlighted. Although in Figure 9B In the example, the items with differences are highlighted by surrounding them with a border line, but other modes can also be used to display the items with differences, as long as the items with differences can be identified. Figure 9B In the example, the metadata fields 920b-1 and 920b-2 of both the captured image 941b and the current image 942b highlight items with differences. However, it is also possible to highlight items with differences in only one of the metadata fields 920b-1 and 920b-2 of the captured image 941b and the current image 942b. The display format of the comparison field can be changed based on the user's selection in the drop-down menu 933. When "Side by Side" is selected in the drop-down menu 933, the display in the comparison field 940b appears.

[0091] Figure 9C The diagram shows comparison field 940c when "Overlay" is selected in pull-down menu 933. The captured image 941c and the current image 942c corresponding to thumbnail 911b are displayed superimposed on each other in comparison field 940c. The user's movement of slider 951 changes the range within which the captured image 941c and the current image 942c are displayed superimposed on each other.

[0092] Figure 9D The figure shows a comparison field 940d when "Highlight" is selected in the pull-down menu 933. In the comparison field 940d, the image 941d and the current image 942d corresponding to the thumbnail 911b are displayed in a manner of being arranged next to each other, and the portion 952 having a difference between the image 941d and the current image 942d is highlighted. Figure 9D The portion 952 with a difference is highlighted by surrounding it with a border line, but the portion 952 with a difference may be displayed in other modes as long as the portion 952 with a difference can be identified. Figure 9D In the figure, both the image 941d at the time of shooting and the current image 942d are highlighted, but only one of the image 941d at the time of shooting and the current image 942d may be highlighted.

[0093] The image data 941 corresponding to the thumbnail 911 is image data 604 in the image file 600 at the time of shooting, which is stored in the storage device 304 and identified as the original file of the image file to be determined corresponding to the thumbnail 911. The metadata 601 displayed in the metadata field 920 is also metadata 601 in the image file 600 at the time of shooting, which is stored in the storage device 304 and identified as the original file of the image file to be determined corresponding to the thumbnail 911.

[0094] (Other embodiments)

[0095] The present invention can be implemented by providing a program that implements one or more functions of the above-described embodiments to a system or device via a network or storage medium, and one or more processors in a computer of the system or device read and execute the program. The present invention can also be implemented by a circuit (e.g., an application-specific integrated circuit (ASIC)) that implements one or more functions.

[0096] The present invention is not limited to the above embodiments, and various modifications and variations can be made without departing from the spirit and scope of the present invention. Therefore, the appended claims are intended to disclose the scope of the present invention.

[0097] This application claims the benefit of Japanese Patent Application No. 2023-012105, filed January 30, 2023, which is hereby incorporated by reference herein in its entirety.

Claims

1. A content management device, comprising: means for receiving content being generated from a content generating device; a unit for storing the content being generated in a storage device; a unit for acquiring content to be determined and source information attached to the content to be determined; as well as A unit for determining the authenticity of the content to be determined based on whether the content being generated corresponding to the content to be determined is stored in the storage device and based on a verification result of the source information.

2. The content management device according to claim 1, further comprising: a unit for determining whether the current source information attached to the content to be determined is generated when the content is generated; Wherein, in a case where the current source information is generated when the content is generated, it is determined that the content to be determined is authentic.

3. The content management device according to claim 1, further comprising: a unit configured to perform a hash function on the content to be determined to generate a hash value, Wherein, the source information includes the hash value of the content to be determined, wherein the verification result includes information indicating a comparison result between the generated hash value and the hash value included in the source information, and Wherein, when the content being generated corresponding to the content to be determined is stored in the storage device and the verification result indicates that the generated hash value is consistent with the hash value included in the source information, it is determined that the content to be determined is authentic.

4. The content management device according to claim 3, in, The source information includes a digital signature of the content to be determined, and Wherein, when the verification result indicates that the signer of the digital signature is reliable, the authenticity of the content to be determined is determined.

5. The content management device according to claim 3, in, The source information includes the digital signature of the content to be determined, wherein the verification result includes information indicating the verification result of the digital signature using the public key, and Wherein, when the verification result indicates that the verification of the digital signature is successful, it is determined that the content to be determined is authentic.

6. The content management device according to claim 3, in, The verification result also includes information indicating whether the source information has a specified structure, and Wherein, when the verification result indicates that the source information has the specified structure, it is determined that the content to be determined is authentic.

7. The content management device according to claim 2, further comprising: a unit for determining whether the current source information attached to the content to be determined is generated when the content is generated; Wherein, in the case that the current source information is not generated when the content is generated, The to-be-determined content is determined to be derived from an update of the content when the content is generated.

8. The content management device according to claim 3, in, When the content being generated corresponding to the content to be determined is stored in the storage device and the verification result indicates that the generated hash value is inconsistent with the hash value included in the source information, it is determined that the content to be determined originates from an update of the content being generated.

9. The content management device according to claim 3, in, The source information includes a digital signature of the content to be determined, and Wherein, when the verification result indicates that the signer of the digital signature is unreliable, it is determined that the content to be determined has traces of tampering.

10. The content management device according to claim 3, in, The source information includes the digital signature of the content to be determined, wherein the verification result includes information indicating the verification result of the digital signature using the public key, and Wherein, when the verification result indicates that the verification of the digital signature fails, it is determined that the content to be determined has traces of tampering.

11. The content management device according to claim 3, in, The verification result also includes information indicating whether the source information has a specified structure, and Wherein, when the verification result indicates that the source information does not have the specified structure, it is determined that the content to be determined has traces of tampering.

12. The content management device according to claim 1, in, The content to be determined is received and acquired from the user terminal, and the content management device further comprises: A unit for notifying the user terminal of a determination result of the content to be determined.

13. The content management device according to claim 12, in, The determination result is notified to the user terminal by attaching an icon that can be used to identify the determination result to the content to be determined.

14. The content management device according to claim 1, in, The content generating device is a camera device, and the content being generated is an image at the time of shooting.

15. The content management device according to claim 14, in, The content is at least one of the image and metadata related to the image.

16. The content management device according to claim 1, in, The source information indicates the creation or editing history of the content.

17. A content generation device, comprising: Units for generating content; a unit for performing a hash function on the content to generate a hash value; means for encrypting the hash value using a key to generate a digital signature; means for adding information related to the content generating device as a signatory to the digital signature; A unit for generating information indicating a source of the content; as well as Unit configured to transmit the content, the hash value, the digital signature, the signer, and the source information to a content management device.

18. The content generating device according to claim 17, The content is at least one of an image of an object captured by an imaging unit and metadata related to the image.

19. The content generating device according to claim 17, in, The signer is at least one of a manufacturer and a model of the content generating device.

20. An authenticity verification system, comprising: content generating device; as well as content management device, Wherein, the content generating device includes: Units for generating content, a unit for performing a hash function on the content to generate a hash value, means for encrypting the hash value using a key to generate a digital signature, means for adding information related to the content generating device as a signatory to the digital signature, a unit for generating information indicating a source of the content, and means for transmitting the content, the hash value, the digital signature, the signer, and the source information to the content management device, and Wherein, the content management device includes: A unit that controls to store the content, the hash value, the digital signature, the signer, and the source information in the storage device.

21. The authenticity verification system according to claim 20, further comprising: a unit for acquiring content to be determined and source information attached to the content to be determined; as well as A unit for determining the authenticity of the content to be determined based on whether the content being generated corresponding to the content to be determined is stored in the storage device and based on a verification result of the source information.

22. A method for controlling a content management device, the method comprising: a step of receiving content being generated from a content generating device; The step of storing the content being generated in a storage device; A step of obtaining content to be determined and source information attached to the content to be determined; as well as The step of determining the authenticity of the content to be determined based on whether the content being generated corresponding to the content to be determined is stored in the storage device and based on the verification result of the source information.

23. A method for controlling a content generating device, the method comprising: Steps to generate content; performing a hash function on the content to generate a hash value; The step of encrypting the hash value using a key to generate a digital signature; a step of adding information related to the content generating device as a signer to the digital signature; generating source information indicating the source of the content; as well as The step of transmitting the content, the hash value, the digital signature, the signer, and the source information to a content management device.

24. A program for causing a computer to function as each unit of the content management apparatus according to any one of claims 1 to 16. 25 . A program for causing a computer to function as each unit of the content generating apparatus according to claim 17 .

Citation Information

Patent Citations

  • Optical detection device and method of controlling optical detection device

    JP2023012105A