A method for verifying media files
By associating media files with a digital identity and using cryptographic keys, the method verifies the source and integrity of media files, preventing unauthorized sharing and tampering, addressing the limitations of existing DRM technologies.
Patent Information
- Authority / Receiving Office
- GB · GB
- Patent Type
- Applications
- Current Assignee / Owner
- ID CRYPT GLOBAL LTD
- Filing Date
- 2024-11-04
- Publication Date
- 2026-06-03
AI Technical Summary
Existing DRM technologies fail to prevent the posting of deepfake images, videos, or manipulated content on public websites, and there is a need to verify the publisher, encrypt files to prevent tampering, and identify AI-generated content.
Associating media files with a digital identity, generating a private and public key pair, storing the private key in a first terminal and the public key immutably, and encrypting the media file with a timestamp and signature, ensuring the media file's integrity and source verification.
Ensures the media file's authenticity by verifying the source and preventing unauthorized sharing and tampering, using digital identity and cryptographic keys.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Technical Field: The present invention relates to the field of media file encryption and signature technology, particularly to a method for verifying media files. Background Technology: With the advancement of technology, media files such as images and videos are increasingly susceptible to copying, theft, and reposting on various websites. Additionally, media files are often manipulated or distorted, causing negative impacts on individuals depicted in the images or videos. The growing popularity of artificial intelligence exacerbates these challenges, as Al can generate "deepfake" images and videos, and create entirely new Al-generated imagery, which can also have adverse effects on individuals. Digital Rights Media (DRM) technology is commonly used to control who can access, view, and share specific content. However, even though DRM has made significant advancements, it cannot prevent the posting of deepfake images, videos, or manipulated content on public websites such as Instagram, Twitter (formerly known as), Threads, and Facebook. Therefore, it is necessary to provide a method for verifying media files to address the following issues: 1. to identify and verify the content's publisher or owner. 2. to verify and encrypt files or content to prevent tampering. 3. to identify whether the file has been previously uploaded to the platform, thus recognizing it as a duplicate. 4. to identify whether the file was generated by artificial intelligence using other images or files to produce Al-based output. Invention Description The present invention addresses the technical problem of providing a method for verifying media files. It accomplishes this by associating media files with the digital identity of the owner to verify the source of the media file, ensuring that the media file cannot be tampered with by third parties, and assisting in combating the unauthorized sharing of media files. The technical solution applied to address the above-mentioned problem is to provide a method for verifying media files, which includes the following steps: • Creating a digital identity for the identity owner and using this digital identity to publish media files. • Generating a private key and public key pair associated with the digital identity. The private key is stored in the first terminal, while the public key is stored in the second terminal, where it is immutably stored. The second terminal returns a DID (Decentralized Identifier) associated with the public key to the first terminal. • Encrypting and signing the media file, placing the encrypted signature, DID, and timestamp of when the media file was published in both the metadata of the media file and within the media file itself. 04 11 24 • Associating the media file with the digital identity of the identity owner. • Verifying the source of the media file. Optionally, using the private key to encrypt and sign the media file involves obtaining the hash value of the media file, storing the hash value in both the metadata and within the media file itself, and using the private key to encrypt the hash value of the media file. Alternatively, the public key can be written to a blockchain with an associated address, or it can be securely hosted on a publisher's website after being written to the document file. Alternatively, the encryption and signing of the media file may involve using the private key associated with the digital identity to encrypt the media file. Alternatively, it may involve encrypting the media file with a context-secure key obtained through a mutual exchange between the identity owner and the recipient. Alternatively, the identity owner can include a publisher, content creator, or an individual. Alternatively, the process of verifying the media file includes: • Recovering the public key, • Using it to decrypt the encrypted signature, and comparing the decrypted signature with the media file itself or its hash value. Alternatively, If the decrypted signature matches either the media file itself or its hash value, the media file is proven to have been published by the identity owner. Alternatively, if multiple DID's, multiple signatures, or multiple timestamps are found in the metadata of the media file, it is proven that the media file has been modified. Advantages of the Invention The method for verifying media files provided by this invention involves creating a digital identity for the owner, using this digital identity to publish media files, generating a private and public key pair associated with the digital identity, with the private key stored in the first terminal and the immutable public key stored in the second terminal. The second terminal returns a DID (Decentralized Identifier) associated with the public key to the first terminal. The media file is then signed with encryption, including the encrypted signature, DID, and timestamp of when the media file was published, placed in both the metadata and the media file itself. The media file is associated with the digital identity of the owner, and its source is verified by linking it to the owner's digital identity, ensuring that the media file has not been altered by a third party. This method helps combat the unauthorized sharing of media files. Figure Descriptions In order to provide a clearer illustration of the embodiments of the present invention or the technical solutions in the prior art, a brief introduction of the figures needed for the embodiments or descriptions in the prior art is provided below. It is evident that the figures described below represent some embodiments of the present invention, but not all embodiments. Ordinary skilled artisans in this field can obtain additional figures based on these descriptions without exerting creative effort. 04 11 24 Figure 1: Schematic diagram illustrating the process of the method for verifying media files in an embodiment of the present invention. Figure 2: Schematic diagram illustrating the process of the method for verifying media files in another embodiment of the present invention. Figure 3: Schematic diagram illustrating the process of the method for verifying media files in yet another embodiment of the present invention. These figures are intended to facilitate a clearer understanding of the embodiments of the present invention but do not represent all possible implementation methods. Additional figures may be obtained as needed to further explain embodiments or technical solutions in the prior art. Detailed Implementation The following description, in conjunction with the accompanying figures and embodiments, provides further details of the present invention. In the following description, in order to provide a thorough understanding of the present invention, many specific details are explained. However, the present invention can be practiced without these specific details, which would be apparent to those skilled in the art. Therefore, the detailed description is exemplary, and specific details may vary and are still considered within the spirit and scope of the present invention. The technical problem addressed by the present invention is to provide a method for verifying media files by associating media files with the digital identity of the owner to verify the source of the media file, ensuring that the media file cannot be tampered with by third parties, and assisting in combating the unauthorized sharing of media files. Now, please refer to the accompanying figures for a detailed description of the method for verifying media files, which includes: The technical problem addressed by the present invention is to provide a method for verifying media files by associating media files with the digital identity of the owner to verify the source of the media file, ensuring that the media file cannot be tampered with by third parties, and assisting in combating the unauthorized sharing of media files. Now, please refer to Figure 1 for a method of verifying media files, which includes: Step S101: Create a digital identity for the identity owner and use this digital identity to publish media files. Step S1O2: Generate a private key and public key pair associated with the digital identity. The private key is stored in the first terminal, while the public key is stored in the second terminal, where it is immutably stored. The second terminal returns a DID (Decentralized Identifier) associated with the public key to the first terminal. This DID can take the form of an addressable field or a Decentralized Identifier (DID). Step S103: Encrypt and sign the media file, placing the encrypted signature, DID, and timestamp of when the media file was published in both the metadata of the media file and within the media file itself. 04 11 24 Step S104: Associate the media file with the digital identity of the identity owner. Step S105: Verify the source of the media file. Specifically, in step S101, creating a digital identity for the owner can be achieved through the deployment of an agent on a computer system. This agent can be software and can be deployed either locally or in the cloud. Creating a digital identity for the owner can also be done on the owner's mobile device, such as a smartphone, tablet, or other mobile devices. Before generating and issuing the digital identity, it is important to verify the accuracy of the provided identity data. The digital identity is issued to the owner's agent or mobile device, with the specific requester for creating the digital identity determining the process. Media files can be created in various ways, including images, videos, or digitally generated files using artificial intelligence. In Step S102, the issued digital identity generates the corresponding private key and public key pair. The private key is stored within the deployed agent, and the public key is immutably stored. The second terminal returns a DID (Decentralized Identifier) associated with the public key to the first terminal. This DID can take the form of an addressable field or a Decentralized Identifier (DID). In a specific implementation, using the private key to encrypt-sign the media file also involves obtaining the hash value of the media file. This hash value is then stored in both the metadata of the media file and within the media file itself. Subsequently, the private key is used to encrypt-sign the hash value of the media file. Now, please refer to Figure 2 for a method of verifying media files, which includes: Step S201: Create a digital identity for the identity owner and use this digital identity to publish media files. Step S202: Generate a private key and public key pair associated with the digital identity. The private key is stored in the first terminal, while the public key is stored in the second terminal, where it is immutably stored. The second terminal returns a DID (Decentralized Identifier) associated with the public key to the first terminal. Step S203: Write the public key to a blockchain with an associated address. Step S204: Encrypt and sign the media file, placing the encrypted signature, DID, and timestamp of when the media file was published in both the metadata of the media file and within the media file itself. Step S205: Associate the media file with the digital identity of the identity owner. Step S206: Verify the source of the media file. Specifically, in Step S203, the public key is written to a blockchain with an associated address. The encrypted signature, DID, and the timestamp of when the media file was published are placed in both the metadata of the media file and within the media file itself. This ensures that the public key is recorded in an immutable blockchain, enhancing the security and traceability of the media file verification process. Now, please refer to Figure 3 for a method of verifying media files, which includes: Step S301: Create a digital identity for the identity owner and use this digital identity to publish media files. 04 11 24 Step S3O2: Generate a private key and public key pair associated with the digital identity. The private key is stored in the first terminal, while the public key is stored in the second terminal, where it is immutably stored. The second terminal returns a DID (Decentralized Identifier) associated with the public key to the first terminal. Step S303: Write the public key to a document file and securely host it on the publisher's website. Step S304: Encrypt and sign the media file, placing the encrypted signature, DID, and timestamp of when the media file was published in both the metadata of the media file and within the media file itself. Step S305: Associate the media file with the digital identity of the identity owner. Step S306: Verify the source of the media file. Specifically, in Step S303, the public key is securely hosted on the publisher's website after being written to a document file. Using the DNS (Domain Name System), the DID can identify the location of this document file, which adds an extra layer of security and accessibility. The encrypted signature, DID, and the timestamp of when the media file was published are placed in both the metadata of the media file and within the media file itself, ensuring comprehensive verification of the media file. In specific implementations: Signing the media file involves encrypting it using the private key associated with the digital identity mentioned. In a specific implementation, the process of encrypting the media file can also involve using a contextually secure key obtained through bidirectional exchange between the identity owner and the recipient. In practical terms, the identity owner, who can be a publisher, content creator, or an individual, uses their private key to perform the encryption of the media file. Validating the media file in specific implementations involves the following steps: • Recover the public key. • Use the recovered public key to decrypt the encrypted signature. • Compare the decrypted signature with the media file itself or the hash value of the media file. In this validation process, it's essential to identify the DID and encrypted signature hidden within the metadata of the media file and the media file itself. Recovering the public key can be achieved by obtaining the public key from the blockchain using the DID or by retrieving it from a DID document securely hosted on the publisher's website. In specific implementations: If the decrypted signature matches either the media file itself or the hash value of the media file, then the media file is proven to be published by the identity owner. If multiple DIDs, signatures, or timestamps are found in the metadata of the multimedia file in specific implementations, it can be demonstrated that the media file has been altered. As a result, the source of the media file can be verified, and the identity / owner of the media file can be proven. It can also be demonstrated that the media file originates from the owner / publisher of the media file and that it has not been modified, ensuring that the content published matches the 04 11 24 owner's expectations. If a different relationship key is used to sign the media file, it indicates that the media file has been specifically shared with the recipient Here is a specific example of the method for verifying media files described earlier: Firstly, creating a Digital Identity for the Identity Owner. It can be processed by assigning an agent to create a digital identity for the identity owner. For instance, an IDC (Identity Credential) agent is deployed within a company's infrastructure, configured with specific parameters and tokens. IDC Crypt Global issues tokens to the company or deploys the IDC Vault mobile application on the identity owner's mobile device. Once deployed, the necessary steps for issuing a digital ID to the identity owner are completed. When the IDC agent is launched for the first time, it initiates a request for a secure connection based on DIDComm to the ID Crypt Global Service. ID Crypt Global responds by providing the IDC agent of the media file's owner / publisher with a secure DIDComm connection invitation. This process establishes a secure communication channel between the IDC agent and the ID Crypt Global Service. This connection is represented by a pair of private and public keys, known as key pairs. Additionally, the ID Crypt Global Service generates its unique private key and shares the corresponding public key with the enterprise's ID Crypt Global Cloud agent. These cryptographic keys are crucial for securing and authenticating the communication between the IDC agent and the ID Crypt Global Service. The ID Crypt Global Service also issues "cryptographically verifiable identity credentials" to participants based on the predefined ID Crypt Global architecture and credential definitions. Both the architecture and credentials have been recorded on the underlying public blockchain. In the case of mobile devices, these credentials will be stored in the Vault application. The IDC agent generates a pair of private and public keys for creating the public digital identity. The public key is sent to ID Crypt Global and is requested to be written into the underlying blockchain. The ID Crypt Global Service writes the participants' public keys into the blockchain and signs the ledger entries using the ID Crypt Global private key. Only trusted entities have the privilege to write entries into the blockchain. In a specific implementation, the public key can also be written into a DID document, which is hosted in the web domain of the media file owner / publisher. Secondly, signing the media files. During this process, sending the media file to the IDC agent or IDC Vault mobile application. Then using the private key or a contextually secure key to encrypt and sign the media file. The encrypted signature and DID are stored in the metadata of the media file, and they are also hidden within the media file itself. And then saving the modified media file, which becomes a new version of the same media file. It is up to the media file owner / publisher to decide whether to replace the original media file with the new version or keep both versions. Finally, the verification of the media file's source is performed as follows: The media file is displayed on the user's device, which can be a computer terminal, tablet, or mobile device. The IDC verification tool extracts the DID and encrypted signatures from both the metadata of the media file and the encrypted signatures hidden within the media file itself. It then uses this extracted 04 11 24 DID information to obtain the associated public key. There are two possible sources of DID information for obtaining the associated public key: • Extracted from the blockchain: In this case, the DID information is retrieved from the file stored in the blockchain, and the related public key is obtained for verification; or • Extracted from hosted DID documents: Alternatively, the DID information can be retrieved from DID documents hosted on the publisher's website. In this scenario, the relevant public key is acquired based on the DID information contained within the hosted DID documents. In specific terms, the public key associated with the private key used to sign the media file by the media file owner / publisher is immutably hosted in the underlying blockchain. Alternatively, this public key can be hosted within the web domain of the media file owner / publisher. The obtained public key is used to verify the encrypted signatures of the media file, ensuring that the media file has not been tampered with. Additionally, the acquired public key contains additional metadata related to the identity of the media file owner / publisher. The IDC verification tool informs the user when the media file has been successfully verified. It also displays information about the file's publication date and the identity / brand of the media file owner / publisher. If the IDC verification tool is unable to verify the signature, it will display a warning indicating that the media file could not be verified. In conclusion, the method for verifying media files provided by this invention involves creating a digital identity for the owner, using this digital identity to publish media files, generating a pair of private and public keys associated with the digital identity, storing the private key in the first terminal and the immutable public key in the second terminal, having the second terminal return a DID associated with the public key to the first terminal. The media file is then encrypted and signed, with the encryption signature, DID, and timestamp of publication placed in the metadata and the media file itself. The media file is linked to the owner's digital identity, and its source is verified by associating the media file with the owner's digital identity, ensuring it has not been modified by a third party. This method helps combat the unauthorized sharing of media files. Finally, it should be noted that the various embodiments described above are intended to illustrate the technical aspects of the present invention and are not meant to limit it. While the described embodiments provide detailed explanations of the invention, those skilled in the art should understand that they can still modify the technical solutions described in the embodiments, or substitute some or all of the technical features, without departing from the scope of the various exemplary embodiments of the present invention. 04 11 24 CLAIMS 1. A method for verifying media files, characterized in that it comprises: • Creating a digital identity for the identity owner and using the digital identity to publish media files. • Generating a private key and public key pair associated with the digital identity. The private key is stored in the first terminal, and the public key is stored in the second terminal, which is immutable. The second terminal returns a DID associated with the public key to the first terminal. • Encrypting and signing the media file, placing the encrypted signature, DID, and timestamp of publishing the media file in the metadata of the media file and the media file itself. • Associating the media file with the digital identity of the identity owner. • Verifying the source of the media file. 2. The method for verifying media files according to claim 1, characterized in that it further comprises using the private key to encrypt and sign the media file and obtaining the hash value of the media file. The hash value of the media file is stored in the metadata of the media file and the media file itself. The private key is used to encrypt the hash value of the media file. 3. The method for verifying media files according to claim 1, characterized in that the public key is written to a blockchain with an address. 4. The method for verifying media files according to claim 1, characterized in that the public key is securely hosted on a publisher's website after being written to the document file. 5. The method for verifying media files according to claim 1, characterized in that encrypting and signing the media file includes using the private key associated with the digital identity to encrypt the media file. 6. The method for verifying media files according to claim 1, characterized in that encrypting and signing the media file includes encrypting the media file with a context-secure key obtained through a mutual exchange between the identity owner and the recipient. 7. The method for verifying media files according to claim 1, characterized in that the identity owner includes a publisher, content creator, or an individual. 8. The method for verifying media files according to claim 1 or 2, characterized in that verifying the media file includes: • Retrieving the public key. • Using the public key to decrypt the encrypted signature. • Comparing the decrypted signature with the media file itself or the hash value of the media file. 9. The method for verifying media files according to claim 8, characterized in that if the decrypted signature matches the media file itself or the hash value of the media file, the media file is proven to be published by the identity owner. 10. The method for verifying media files according to claim 8, characterized in that if multiple DIDs, multiple signatures, or multiple timestamps are found in the metadata of the media file, the media file is proven to have been modified. Amendments to the claims have been filed as follows: 06 06 25
Claims
1. A method for verifying media files, characterised in that it comprises:• creating a digital identityforthe identity ownerand using the digital identity to publish media files;• generating a private key and public key pair associated with the digital identity, wherein the private key is stored in a first terminal, and the public key is stored in a second terminal, which is immutable, and wherein the second terminal returns a DID associated with the public key to the first terminal;• encrypting and signing the media file, placing the encrypted signature, DID, and timestamp of publishing the media file in the metadata of the media file and the media file itself;• associating the media file with the digital identity of the identity owner; and• verifying the source of the media file by retrieving the metadata from the media file,extractingthe DIDand the signature, obtainingthe corresponding public key from the second terminal using the DID, and verifying the signature against the media file using the public key to confirm the authenticity and origin of the media file .
2. The method forverifying media files according to claim 1, characterised in that it furthercomprises using the private key to encrypt and sign the media file and obtainingthe hash value of the media file; the hash value of the media file is stored in the metadata of the media file and the media file itself; the private key is used to encrypt the hash value of the media file.
3. The method for verifying media files according to claim 1, characterised in that the public key is written to a blockchain with an address.
4. The method for verifying media files according to claim 1, characterised in that the public key is securely hosted on a publisher's website after being written to the media file.
5. The method for verifying media files according to claim 1, characterised in that encrypting and signing the media file includes usingthe private key associated with the digital identity to encrypt the media file.
6. The method for verifying media files according to claim 1, characterised in that encrypting and signing the media file includes encryptingthe media file with a context-secure key obtained through a mutual exchange between the identity owner and the recipient.
7. The method for verifying media files according to claim 1, characterised in that the identity owner includes a publisher, content creator, or an individual.
8. The method forverifying media files accordingto claim 1 or 2, characterised in that verifying the media file includes:• retrieving the public key;• using the public key to decrypt the encrypted signature; and• comparing the decrypted signature with the media file itself or the hash value of the media file.
9. The method for verifying media files according to claim 8, characterised in that if the decrypted signature matches the media file itself or the hash value of the media file, the media file is provento be published by the identity owner.LOCM10. The method for verifying media files according to claim 8, characterised in that if multiple DIDs, multiple signatures, or multiple timestamps are found in the metadata of the media file, the media file is proven to have been modified.