Visit information recording system, commission visit information generation device, program therefor, commission visit information registration device, and program therefor
The proven history information recording system addresses the challenge of recording provenance information under the contractor's responsibility by using a system where the entruster records this information on behalf of the contractor, employing adapter signature methods for authenticity and responsibility.
Patent Information
- Application Number
- JP2023180726
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-10-20
- Publication Date
- 2025-05-02
AI Technical Summary
In traditional C2PA methods, content creators in the supply chain have independent digital signatures, making it difficult to record provenance information under the responsibility of the contractor in business partnerships.
A proven history information recording system where the entruster records provenance information on behalf of the entruster, utilizing a contractor's contracting signature information generation and registration devices, which include public information receiving, key generation, pre-signature generation, and signature registration units, employing the adapter signature method to ensure authenticity and responsibility.
Enables verification of the contractor's prior signature and allows the contractor to add their signature on behalf of themselves, effectively recording proven information under their responsibility, enhancing the reliability and trustworthiness of content provenance.
Smart Images

Figure 2025070427000001_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to a history information recording system, a entrusted history information generating device and a program thereof, and a entrusted history information registering device and a program thereof. [Background technology]
[0002] In recent years, with the rapid development of AI (Artificial Intelligence) technology, a large amount of unreliable content, where the source or creator of information or data is unclear, is being circulated on the Internet, such as the creation of fake images known as "deep fakes" and the spread of fake news through social networking services (SNS), and this has become a social problem. In order to combat such false and misinformation, the Coalition for Content Provenance and Authenticity (C2PA) was established in 2021 as an organization that develops open technical specifications for presenting users with "content provenance information," such as the source of content and its editing history.
[0003] C2PA is working to standardize a mechanism for allowing users to determine whether or not to trust content by associating the provenance information of the content with the content (see Non-Patent Document 1). The standardization specifications being promoted by C2PA aim to ensure the reliability of content by recording the following three pieces of information (1) to (3) on a blockchain or in a system (database) in the supply chain from content creation (here, shooting) to presentation, as shown in Figure 7, and making it possible for anyone to verify it.
[0004] (1) Information indicating who did what to the content, when, and what, as well as a hash value (assertion AS) to link the content to the manifest. (2) A list of URIs (Uniform Resource Identifiers) of assertion ASes (claim information CL). (3) Signature information (digital signature SI) for the claim information CL. These three pieces of information are collectively referred to as the manifest (C2PA manifest) MF as provenance information.
[0005] In the example of Fig. 7, company A shoots the video and records the provenance information (manifest) MF on the blockchain BC. Then, company B edits the video shot by company A and records the provenance information MF on the blockchain BC. By repeating this process, the provenance information MF is recorded on the blockchain BC for each action in the supply chain (workflow) from content creation to presentation. This allows a content user U who uses (views) the content to verify the digital signature SI of the history information MF and determine whether the content is trustworthy for each action. [Prior art documents] [Non-patent literature]
[0006] [Non-Patent Document 1] “C2PA Technical Specification”, [online], [Retrieved August 29, 2023], Internet〈URL:https: / / c2pa.org / specifications / specifications / 1.3 / specs / C2PA_Specification.html〉 Summary of the Invention [Problem to be solved by the invention]
[0007] In traditional C2PA approaches, different content creators take action in the supply chain, and each digital signature is independent. However, in the actual production of content, for example, in the example of Figure 7, Company A and Company B often collaborate to produce content, such as when Company B commissions Company A to shoot the content and the commissioned Company B is the producer. In such cases, even if there is a contract that the final product belongs to Company B, Company A will record the provenance information. However, there is a demand for provenance information to be recorded under the responsibility of the entrusting party.
[0008] Therefore, an object of the present invention is to provide a history information recording system that enables a delegating party to record the history information of content on behalf of a delegating party, a delegation history information generating device and a program therefor, and a delegation history information registration device and a program therefor. [Means for solving the problem]
[0009] In order to solve the above problems, the history information recording system of the present invention is a history information recording system in which a delegating party records history information of content in a recording device on behalf of a delegating party of an action on the content, and is configured to include a delegation history information generation device of the delegating party that generates the history information, and a delegation history information registration device of the delegating party that records the history information.
[0010] In addition, in order to solve the above-mentioned problems, the entrusted history information generating device of the present invention is a entrusted history information generating device for a delegate in a history information recording system in which a delegator records history information of content in a recording device on behalf of a delegatee of an action on the content, and is configured to include a public information receiving unit, a key generating unit, a pre-signature generating unit, and an entrusted history information transmitting unit.
[0011] In such a configuration, the entrustment history information generation device receives, by the public information receiving unit, public information used in the adapter signature scheme from the entrustment history information registration device of the entrustor. Moreover, the entrustment history information generation device generates a private key and a public key in a digital signature scheme by the key generation unit. Then, the entrustment history information generation device generates, by the pre-signature generation unit, a pre-signature in the adapter signature scheme for data that specifies an action, from the private key, the public key, and the public information. This pre-signature makes it possible to set that the data has been authenticated by the entrustment history information generation device of the entrustee.
[0012] Then, the entrustment history information generation device transmits the data, the pre-signature, and the public key as history information to the entrustment history information registration device via the entrustment history information transmission unit. This allows the entrustment history information generation device to transmit the history information to which the pre-signed signature has been added to the entrustment history information registration device that is the entrusting source. The entrusted history information generation device can be operated by a program that causes a computer to function as each of the above-mentioned units.
[0013] In addition, in order to solve the above-mentioned problems, the entrusted history information registration device of the present invention is a entrusted history information registration device of a delegating source in a history information recording system in which the entrusting source records the history information of a content in a recording device on behalf of a delegatee of an action on the content, and is configured to include a private public information generation unit, a public information transmission unit, a entrusted history information receiving unit, a pre-signature verification unit, a signature generation unit, and a history information recording unit.
[0014] In such a configuration, the entrustment history information registration device generates private information and public information to be used in the adapter signature scheme by the private public information generation unit. Then, the entrustment history information registration device transmits the public information to the entrustment history information generation device to which the action on the content is entrusted, by the public information transmitting unit. Then, the entrustment history information registration device receives, via the entrustment history information receiving unit, data identifying the action, the pre-signature in the adapter signature scheme, and the public key in the digital signature scheme from the entrustment history information generation device as history information. Then, the entrustment history information registration device verifies the pre-signature using the pre-signature verification unit based on the public information, the data received by the entrustment history information receiving unit, the pre-signature, and the public key. This allows the entrustment history information registration device to verify that the history information has been generated by the entrustment history information generation device of the legitimate entrustee.
[0015] Furthermore, the entrustment history information registration device generates a signature in the adapter signature scheme from the private information, the public key, the pre-signature, and the data by the signature generation unit. Then, the entrusted history information registration device causes the history information recording unit to record the history information in the recording device by replacing the pre-signature of the history information with the signature generated by the signature generation unit. This allows the entrustment history information registration device to add its own signature to and record the history information even if the history information is generated by the entrustee. The entrustment history information registration device can be operated by a program that causes a computer to function as each of the above-mentioned units. Effect of the Invention
[0016] According to the present invention, the pre-signature of the trustee is verified, and the trustor can add a signature on behalf of the trustee and record the history information under the responsibility of the trustor. [Brief description of the drawings]
[0017] [Figure 1] FIG. 1 is an explanatory diagram for explaining an overview of the adapter signature method, where (a) is an explanatory diagram for explaining three algorithms of the digital signature method used in the adapter signature method, and (b) is an explanatory diagram for explaining four algorithms that make up the adapter signature method. [Diagram 2] 1 is a schematic diagram showing a configuration of a history information recording system according to an embodiment of the present invention; [Diagram 3] 3 is a block diagram showing a configuration of the entrustment history information generation device of FIG. 2. [Figure 4] 3 is a block diagram showing a configuration of the entrustment history information registration device of FIG. 2. [Diagram 5] 3 is a block diagram showing a configuration of the history information verification device of FIG. 2. [Figure 6] FIG. 4 is a sequence diagram showing an operation of the history information recording system according to the embodiment of the present invention. [Figure 7] FIG. 1 is an explanatory diagram for explaining a conventional method for recording history information. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0018] Hereinafter, an embodiment of the present invention will be described with reference to the drawings. [Overview of the Adapter Signature Scheme] First, with reference to FIG. 1, an outline of the adapter signature scheme used in the history information recording system 100 (FIG. 2) of the present invention will be described. The adaptor signature scheme is an extension of the digital signature scheme that uses a computationally difficult algebraic relationship to adapt (transform) a signature called a pre-signature into a signature of the digital signature scheme. The adaptor signature scheme is a cryptographic technique proposed by Andrew Poelstra in 2017. In addition, the adaptor signature scheme was formulated as an independent cryptographic primitive by Lukas Aumayr et al. in 2021 (see the references below). (Reference: L. Aumayr et al., “Generalized Channels from Limited Blockchain Scripts and Adaptor Signatures”, URL: https: / / eprint.iacr.org / 2020 / 476.pdf)
[0019] The adapter signature scheme AS consists of a digital signature scheme Σ (Figure 1(a)) consisting of three algorithms Σ1, Σ2, and Σ3, and four algorithms AS1, AS2, AS3, and AS4 (Figure 1(b)) that use the computationally intractable algebraic relation (Y, y) ∈ R. A hard algebraic relation R is a relation based on an algebraically hard problem for which the probability of an algorithm that can be solved in polynomial time is negligibly small. Here, Y is called the public statement and y is called the secret witness. For example, if the discrete logarithm problem is used as a hard problem, then G= <g>(g is a generator) is a cyclic group of prime order q, Z q Let Y be the set of all integers less than q, then the algebraic relation R that is difficult to compute is R={(Y,y)|Y=g y }∈G×Z q This algebraic relation R that is difficult to compute can be defined according to the computational security that is the basis for the security of the adapter signature scheme that it constitutes, such as a lattice problem other than the discrete logarithm problem. Here, an overview of each algorithm will be given.
[0020] (Digital signature method) As shown in Figure 1(a), the three algorithms that make up the digital signature scheme Σ are KeyGen algorithm Σ1, Sign algorithm Σ2, and Verify algorithm Σ3.
[0021] The KeyGen (key generation) algorithm Σ1 is an algorithm that inputs a security parameter λ and outputs a private key (signature key) sk and a public key (verification key) pk. The security parameter λ is a numerical value (e.g., key length) that indicates a predetermined level of security. The Sign algorithm Σ2 is an algorithm that inputs data m, a public key pk, and a private key sk, and outputs a signature σ. Verify algorithm Σ3 is an algorithm that inputs data m, public key pk, and signature σ and outputs the verification result. Verify algorithm Σ3 outputs "1" as the verification result if the signature σ is a valid signature of data m, and "0" as the verification result if it is not a valid signature.
[0022] (Adapter Signature Method) As shown in FIG. 1(b), the four algorithms that make up the adaptor signature scheme AS are PreSign algorithm AS1, PreVerify algorithm AS2, Adapt algorithm AS3, and Ext algorithm AS4.
[0023] The PreSign algorithm AS1 inputs a pair (pk, sk) of a public key pk and a private key sk, public information Y, and data m, and generates a presignature σ pre This is an algorithm that outputs PreVerify algorithm AS2 uses public information Y, public key pk, and pre-signature σ pre and data m, and outputs the verification result. pre If the pre-signature of data m is correct, the verification result is output as "1", and if it is not correct, the verification result is output as "0".
[0024] The adapt algorithm AS3 takes secret information y, public key pk, and pre-signature σ pre and an algorithm that inputs data m and outputs a signature σ. Ext (extraction) algorithm AS4 uses public information Y and a pre-signature σ pre and the signature σ, and the correct pre-signature σ pre and the signature σ, it outputs y′ that satisfies (Y, y′)∈R, otherwise it outputs a predetermined error code ⊥. This y′ is the same value as the secret information y.
[0025] [Configuration of the provenance information recording system] Next, the configuration of a history information recording system 100 according to an embodiment of the present invention will be described with reference to FIG.
[0026] The history information recording system 100 is a system in which an entrusting party records the history information of a content in a recording device on a network on behalf of a trustee. The history information recording system 100 includes a plurality (M units) of entrusted history information generating devices 1 (11, 12, ..., 1 M ) and multiple (N) entrusted history information registration devices 2 (21, 22, ..., 2 N ) and a plurality of (here, one) history information verification devices 3 connected to a network NT. Note that, in order to make it easier to understand the correspondence between the entrusted history information generation device 1 and the entrusted history information registration device 2, they are shown as being directly connected, but they may be connected via the network NT.
[0027] The entrusted history information generating device 1 is a device managed by the party to which actions such as content production and editing are entrusted (here, Company A), and generates information (entrusted history information) on the history (actions) taken on entrusted content (entrusted content). The entrustment history information generating device 1 notifies the entrustment history information registering device 2 of the history information (entrustment history information) generated by including a pre-signature of the adapter signature method.
[0028] The entrustment history information registration device 2 is a device managed by the entruster (here, Company B) of actions such as content production and editing, and records information specifying actions taken on content (entrusted content) by the entrustee (here, Company A), specifically, a list of URIs of assertion AS (claim information CL: Figure 7) and a signature (digital signature SI: Figure 7) containing information on the action (who did what, when), as history information (manifest) MF on behalf of the entrustee. For example, the entrustment history information registration device 21 acquires information specifying an action (photographing) on the content of company A and a signature (pre-signature of the adapter signature method) as history information (entrustment history information) from the entrustment history information generation device 11 of the entrustee, and replaces the pre-signature with the signature of the entrustor to generate new history information MF A Record as. Note that the assertion AS of the history information MF (Figure 7) also includes a hash value for linking the content and the history information MF, as in conventional C2PA, but since this is not directly related to the present invention, it will be omitted from the following explanation. In addition, here, the history information MF is recorded on the block chain BC as a recording device on the network. This block chain BC is a common technology, so the explanation is omitted.
[0029] When the entrusting source itself performs further action such as editing on the content, the entrustment history information registration device 2 records the entrusting source's own history information MF. For example, the entrusted history information registration device 21 registers its own history information MF B is recorded on the blockchain BC.
[0030] The log information verification device 3 is, for example, a device managed by a content user, and verifies the log information MF recorded on the block chain BC. The log information verification device 3 can verify the authenticity of the content corresponding to the log information MF by verifying the signature (digital signature) included in the log information MF.
[0031] In this embodiment, one entrustment history information generation device 1 is associated with the entrustment history information registration device 2, but the number of such devices is arbitrary. That is, the entrustment history information registration device 2 of the entrusting source may acquire history information (entrustment history information) performed on the content sequentially from the multiple entrustment history information generation devices 1 that are multiple entrustees, and record the history information MF on the blockchain BC on behalf of the multiple entrustees. Also, when there is no entrustee, the entrustment history information registration device 2 may record only its own history information on the blockchain BC. Each device constituting the history information recording system 100 will be described below. [Configuration of the entrustment history information generation device] First, the configuration of the entrusted history information generation device 1 will be described with reference to Fig. 3. The entrusted history information generation device 1 includes a key generation unit 10, a public information reception unit 11, a pre-signature generation unit 12, an entrusted history information transmission unit 13, a signature acquisition unit 14, a signature verification unit 15, a private information extraction unit 16, and a storage unit 17.
[0032] The key generation unit 10 generates a private key (signature key) and a public key (verification key) for a digital signature method. The key generation unit 10 generates a private key sk and a public key pk from a predetermined security parameter λ using a KeyGen (key generation) algorithm Σ1 (see FIG. 1(a)). The key generation unit 10 stores the generated private key sk and public key pk in the storage unit 17.
[0033] The public information receiving unit 11 receives the public information Y from the entrustment history information registration device 2. The public information Y will be described in the explanation of the entrustment history information registration device 2. The public information receiving unit 11 stores the received public information Y in the storage unit 17.
[0034] The pre-signature generating unit 12 generates a pre-signature in the adapter signature scheme for information (data m) that specifies the action taken by the consignee on the content. Data m is information (complaint information CL: FIG. 7) that specifies the action, such as who did what, when, etc., including the user name of the content creator, the time of creation, and the work content. The pre-signature generating unit 12 generates a pre-signature σ from the data m, the private key sk and the public key pk stored in the storage unit 17, and the public information Y by using a PreSign algorithm AS1 (see FIG. 1(b)). pre Generate. The pre-signature generating unit 12 generates a pre-signature σ pre is stored in the storage unit 17, and the data m and the pre-signature σ pre and the public key pk to the entrustment history information transmitting unit 13.
[0035] The entrustment history information transmission unit 13 transmits the data m output from the pre-signature generation unit 12 and the pre-signature σ pre and the public key pk are transmitted to the entrustment history information registration device 2 as the history information of the entrustee (entrustment history information).
[0036] The signature acquisition unit 14 acquires the signature σ of the history information MF recorded on the block chain BC, in which data m corresponding to the entrusted history information generation device 1 is recorded. Note that, since information specifying an action on the content is recorded in the data m, the entrusted history information generation device 1 can search for and acquire the history information MF corresponding to its own (entrustee) history. The signature acquisition unit 14 outputs the acquired signature σ to the signature verification unit 15 and the private information extraction unit 16 .
[0037] The signature verification unit 15 verifies the signature σ acquired by the signature acquisition unit 14 . The signature verification unit 15 generates the pre-signature σ by the pre-signature generation unit 12 using a verify algorithm Σ3 (see FIG. 1(a)). pre The signature σ acquired by the signature acquisition unit 14 is verified using the data m used when generating the signature σ and the public key pk stored in the storage unit 17. The signature verification unit 15 outputs to the private information extraction unit 16 a verification result of "1" if the signature σ is a valid signature of the data m, and outputs a verification result of "0" if the signature is not valid.
[0038] The private information extraction unit 16 extracts private information corresponding to the public information Y. The secret information extraction unit 16 extracts the public information Y and the pre-signature σ stored in the storage unit 17 by the Ext (extraction) algorithm AS4 (see FIG. 1(b)). pre and the signature σ acquired by the signature acquisition unit 14, the secret information y′ is extracted. Here, the private information extraction unit 16 extracts the private information only when the signature σ is correct (when the signature verification unit 15 inputs "1" as the verification result). Pre-signature σ pre If both the pre-signature σ and the signature σ are valid, the private information y′ extracted by the private information extraction unit 16 will have the same value as the private information y corresponding to the public information Y generated by the private public information generation unit 20 of the entrustment history information registration device 2 described later. pre If either the signature σ or the signature σ is incorrect, the private information extraction unit 16 outputs a predetermined error code ⊥. Since the secret information y' is the same as the secret information y of the entrustment history information registration device 2, this secret information y' can be used as a key for receiving a reward for editing the content from the entrustee to the entrusting source.
[0039] The storage unit 17 stores various information used by the entrustment history information generation device 1, and can be configured with a general storage medium such as a semiconductor memory. Here, the storage unit 17 stores the private key sk and the public key pk generated by the key generation unit 10, the public information Y received by the public information reception unit 11, and the pre-signature σ generated by the pre-signature generation unit 12. pre and remember.
[0040] In addition, the signature verification unit 15 is not a required component. When the entrustment history information generation device 1 does not include the signature verification unit 15, the signature acquisition unit 14 outputs the acquired signature σ only to the private information extraction unit 16, and the private information extraction unit 16 extracts the private information regardless of the verification result of whether the signature σ is correct or not. With the configuration described above, the entrustment history information generation device 1 can set a pre-signature and notify the entrustment history information registration device 2 of the entrustor of the history information of the entrustee. This entrusted history information generation device 1 can be operated by a program that causes a computer (not shown) to function as each of the above-mentioned units.
[0041] [Configuration of the Entrusted History Information Registration Device] Next, the configuration of the entrusted history information registration device 2 will be described with reference to Fig. 4. The entrusted history information registration device 2 includes a private public information generation unit 20, a public information transmission unit 21, an entrusted history information reception unit 22, a pre-signature verification unit 23, a signature generation unit 24, a history information recording unit 25, a key generation unit 26, a second signature generation unit 27, and a storage unit 28.
[0042] The private / public information generating unit 20 generates private information and public information that form an algebraic relationship that is difficult to calculate and is used in the adapter signature scheme. As long as it has an algebraic relationship that is difficult to compute, the generation method is not particularly important. For example, if the digital signature method used is a method based on the computational difficulty of the discrete logarithm problem, such as the ECDSA (Elliptic Curve Digital Signature Algorithm) signature method or Schnorr signature, the computationally difficult algebraic relationship also uses the discrete logarithm problem. Then, the private disclosure information generation unit 20 defines G as a cyclic group of prime order q, Z q Let Y be the set of all integers less than q. Then, using a generator g of the cyclic group G, R={(Y,y)|Y=g y }∈G×Z q Then, secret information y and public information Y are generated. The private public information generation unit 20 stores the generated private information y and public information Y in the storage unit 28. In addition, the private public information generation unit 20 outputs the public information Y to the public information transmission unit 21.
[0043] The public information transmitting unit 21 transmits the public information Y generated by the private public information generating unit 20 to the entrusted history information generating device 1.
[0044] The entrusted history information receiving unit 22 receives the data m and the pre-signature σ from the entrusted history information generating device 1. pre and the public key pk are received as the trustee's history information (entrustment history information). The data m is information that identifies the action taken by the trustee on the content. pre is a pre-signature in the adapter signature scheme set for data m. Public key pk is a verification key generated corresponding to a private key (signature key) in the digital signature scheme. The entrustment history information receiving unit 22 receives the data m and the pre-signature σ pre and the public key pk to the pre-signature verification unit 23.
[0045] The pre-signature verification unit 23 verifies the pre-signature σ pre This is to verify the following. The pre-signature verification unit 23 performs pre-verification by using a PreVerify algorithm AS2 (see FIG. 1(b)) to verify the public information Y stored in the storage unit 28, the data m received by the entrustment history information receiving unit 22, and the pre-signature σ pre and the public key pk, the verification result is calculated. Pre-signature σ pre is verified to be a correct pre-signature for data m, the pre-signature verification unit 23 pre and outputs the public key pk to the signature generation unit 24. Pre-signature σ pre If it is not verified that the pre-signature of data m is correct, the pre-signature verification unit 23 displays an error message on a display device (not shown) or the like indicating that the pre-signature is invalid, and stops the process.
[0046] The signature generation unit 24 converts the pre-signature verified as correct by the pre-signature verification unit 23 into a signature conforming to the digital signature format. The signature generation unit 24 uses an Adapt algorithm AS3 (see FIG. 1(b)) to generate a signature using the secret information y stored in the storage unit 28, the public key pk input from the pre-signature verification unit 23, and the pre-signature σ pre and the data m, a signature σ is generated. The signature generation unit 24 outputs the generated signature σ, as well as the public key pk and data m input from the pre-signature verification unit 23 to the history information recording unit 25.
[0047] The history information recording unit 25 records the history information (data m, pre-signature σ pre and the public key pk) pre is recorded in a recording device (blockchain BC) on the network as new history information MF, in place of the signature σ generated by the signature generation unit 24. In addition, the history information recording unit 25 also records the signature σ′ generated by the second signature generation unit 27 described below, data m′ which is information identifying the action taken by the entruster on the content, and the public key pk′ generated by the key generation unit 26 described below as the entruster's own history information. The history information recording unit 25 generates history information MF by writing data m, m', which is information that identifies an action taken on the content, into the claim information CL (Figure 7), and signatures σ, σ' and public keys pk, pk' into the digital signature SI (Figure 7) area, and records it on the blockchain BC.
[0048] The key generation unit 26 generates a private key (signature key) and a public key (verification key) for a digital signature method. The key generation unit 26 generates a secret key sk and a public key pk from a predetermined security parameter λ using a KeyGen (key generation) algorithm Σ1 (see FIG. 1(a)). The key generation unit 26 stores the generated private key and public key in the storage unit 28. Note that, in order to distinguish the private key and public key generated by the entrustment history information generation device 1, the keys generated by the key generation unit 26 are represented as a private key sk' and a public key pk'.
[0049] The second signature generating unit 27 generates a signature (digital signature) for data m' which is information specifying an action taken by the entrusting source with respect to the content. The second signature generation unit 27 generates a signature σ′ from the data m′ and the private key sk′ and public key pk′ stored in the storage unit 28 by using the Sign algorithm Σ2 (see FIG. 1(a)). The second signature generation unit 27 outputs the generated signature σ′, the public key pk′ stored in the storage unit 28, and the data m′ to the history information recording unit 25.
[0050] The storage unit 28 stores various information used by the entrustment history information registration device 2, and can be configured with a general storage medium such as a semiconductor memory. Here, storage unit 28 stores private information y and public information Y generated by private public information generation unit 20, and private key sk′ and public key pk′ generated by key generation unit 26.
[0051] With the configuration described above, the entrusted history information registration device 2 can record history information on behalf of the entrusted history information generation device 1 by replacing the pre-signature of the entrusted history information generation device 1 with its own signature. This entrustment history information registration device 2 can be operated by a program that causes a computer (not shown) to function as each of the above-mentioned units.
[0052] [Configuration of the history information verification device] Next, a configuration of the history information verification device 3 will be described with reference to Fig. 5. The history information verification device 3 includes a history information acquisition unit 30 and a signature verification unit 31.
[0053] The history information acquisition unit 30 acquires the history information MF recorded on the block chain BC. Here, the history information acquisition unit 30 acquires the history information MF sequentially from the beginning of the block chain BC corresponding to the content for which the content user wishes to check the history. The history information acquisition unit 30 outputs the data m, the signature σ, and the public key pk included in the history information MF to the signature verification unit 31. The history information acquisition unit 30 acquires all the content history information from the beginning of the block chain BC and outputs it to the signature verification unit 31.
[0054] The signature verification unit 31 verifies the signature σ input from the history information acquisition unit 30 . The signature verification unit 31 calculates a verification result from the data m, the signature σ, and the public key pk included in the history information MF acquired by the history information acquisition unit 30, using a Verify algorithm Σ3 (see FIG. 1(a)). If the signature verifier 31 verifies that the signature σ is a correct signature for the data m, it outputs "1" as the verification result, and if the signature is not correct, it outputs "0" as the verification result. The signature verification unit 31 verifies all the signatures σ, σ′ (see FIG. 4) included in the history information MF.
[0055] With the above-described configuration, the history information verification device 3 can verify the reliability of the content. This history information verification device 3 can be operated by a program that causes a computer (not shown) to function as each of the above-mentioned units.
[0056] [Operation of the provenance information recording system] Next, with reference to FIG. 6 (for the configuration, refer to FIGS. 2 to 5 as appropriate), the operation of the history information recording system 100 according to the embodiment of the present invention will be described. Here, an explanation will be given of the operation when an action such as editing of content is entrusted from an entrusting source (Company B) to an entrustee (Company A), and further an action on the content is also performed by the entrusting source (Company B).
[0057] In step S1, the private public information generating unit 20 of the entrustment history information registration device 2 generates private information y and public information Y that form an algebraic relationship that is difficult to calculate and is used in the adapter signature scheme. In step S2, the public information transmission unit 21 transmits the public information Y generated in step S1 to the entrusted history information generation device 1.
[0058] In step S3, the public information receiving unit 11 of the entrusted history information generating device 1 receives the public information Y transmitted in step S2, and stores it in the storage unit 17. In step S4, the key generation unit 10 generates a private key (signature key) sk and a public key (verification key) pk for a digital signature scheme using a KeyGen (key generation) algorithm Σ1 (see FIG. 1), and stores them in the storage unit 17. In step S5, the pre-signature generating unit 12 generates a pre-signature σ from data m, which is information specifying the action of the entrusted party on the content, the private key sk and the public key pk stored in the storage unit 17, and the public information Y, by using a PreSign algorithm AS1 (see FIG. 1(b)). pre Generate. In step S6, the entrustment history information transmission unit 13 transmits the pre-signature σ pre The data m and the public key pk are transmitted to the entrustment history information registration device 2 as the history information of the entrustee (entrustment history information).
[0059] In step S7, the entrustment history information receiving unit 22 of the entrustment history information registration device 2 receives the entrustee history information (data m, pre-signature σ pre and public key pk) In step S8, the pre-signature verification unit 23 uses a PreVerify algorithm AS2 (see FIG. 1(b)) to verify the public information Y stored in the storage unit 28 and the history information (data m, pre-signature σ pre and the public key pk), the pre-signature σ pre Verify.
[0060] In step S9, the signature generating unit 24 uses the Adapt algorithm AS3 (see FIG. 1(b)) to combine the secret information y stored in the storage unit 28 and the pre-signature σ pre The provenance information (public key pk, pre-signature σ pre and data m), a signature σ is generated. In step S10, the history information recording unit 25 records the signature σ generated in step S9, and the data m and public key pk input in step S7 as history information MF on the block chain BC. Through the above operations, the entrusted history information registration device 2 can record the history information on behalf of the entrusted history information generation device 1 of the entrustee.
[0061] In step S11, the signature acquisition unit 14 of the entrusted history information generation device 1 acquires the signature σ of the history information MF recorded on the blockchain BC, in which data m, which is information identifying the action taken by the entrusted party against the content, is recorded. In step S12, the signature verification unit 15 verifies the pre-signature σ pre The signature σ acquired in step S11 is verified using the data m used when generating the signature σ and the public key pk stored in the storage unit 17. In step S13, the private information extraction unit 16 extracts the public information Y and the pre-signature σ stored in the storage unit 17 by the Ext (extraction) algorithm AS4 (see FIG. 1(b)). pre and the signature σ verified in step S12, the secret information y′ is extracted.
[0062] Through the operations of steps S11 to S13, the entrustment history information generating device 1 can obtain secret information y' (= y) that can only be known by the entrustor, and can be used as a key to receive remuneration for editing the content, etc. from the entrustee to the entrustor.
[0063] In step S14, the key generation unit 26 of the entrustment history information registration device 2 generates a private key sk′ and a public key pk′ by the KeyGen (key generation) algorithm Σ1 (see FIG. 1(a)), and stores them in the storage unit 28. In step S15, the second signature generation unit 27 generates a signature σ′ using the Sign algorithm Σ2 (see Figure 1(a)) from data m′, which is information that identifies the action taken by the entrusting source on the content, and the private key sk′ and public key pk′ stored in the memory unit 28. In step S16, the history information recording unit 25 records the signature σ generated in step S9, and the data m and public key pk input in step S7 as history information MF on the block chain BC.
[0064] By the operations of steps S14 to S16, the history of the content of the entrusting source itself can be recorded. If the entrusting source does not take any action on the content, the operations of steps S14 to S16 are omitted.
[0065] In step S17, the history information acquisition unit 30 of the history information verification device 3 acquires the history information MF recorded on the block chain BC. In step S18, the signature verification unit 31 verifies the signature σ from the history information MF (data m, signature σ, and public key pk) acquired in step S17 by using a Verify algorithm Σ3 (see FIG. 1(a)). This enables the history information verification device 3 to confirm the reliability of the content. Note that steps S17 and S18 may be performed at any time by a content user who wishes to check the reliability of the content.
[0066] Although an embodiment of the present invention has been described above, the present invention is not limited to this embodiment, and includes design modifications and the like that do not depart from the gist of the present invention. For example, here, the history information is recorded on the blockchain BC, but it may also be recorded in a database on the cloud.
[0067] Also, here, the entrustment history information registration device 2 records history information based on data m', which is information specifying an action taken on the content by the entrustor, together with the history information of the entrustee. However, the action on the content by the entrustor is not essential. Therefore, when the entrustor does not need to generate its own history information, the entrustment history information registration device 2 may omit the key generation unit 26 and the second signature generation unit 27.
[0068] Also, here, one history information verification device 3 is connected to the history information recording system 100, but this history information verification device 3 may be provided for each content user who wishes to check the history information of the content, and multiple devices may be connected. [Explanation of symbols]
[0069] 100 History Recording System 1. Entrusted provenance information generation device 10 Key generation section 11 Public Information Receiving Section 12 Pre-signature generation unit 13. Entrusted History Information Transmission Department 14 Signature Acquisition Department 15 Signature Verification Unit 16 Secret information extraction section 17 Memory section 2. Entrusted history information registration device 20 Confidential Public Information Generation Department 21 Public Information Transmission Department 22 Entrustment History Information Receiving Department 23 Pre-signature verification unit 24 Signature generation section 25 History Information Record Section 26 Key generation section 27 2nd signature generation section 28 Memory section 3. History information verification device 30 History Information Acquisition Department 31 Signature Verification Unit BC Blockchain (recording device) MF History Information (Manifest)< / g>
Claims
1. A history information recording system in which a delegating source records history information of a content in a recording device on behalf of a delegating party of an action on the content, A entrustment history information generation device of an entrustee that generates the history information; A trustee history information registration device for a trustee that records the history information, The entrusted history information generation device includes: A public information receiving unit that receives public information from the entrustment history information registration device; a key generation unit that generates a private key and a public key in a digital signature scheme; a pre-signature generation unit that generates a pre-signature in an adapter signature scheme for data that identifies the action from the private key, the public key, and the public information; a trust history information transmission unit that transmits the data, the pre-signature, and the public key to the trust history information registration device as the history information, The entrusted history information registration device includes: a private / public information generation unit for generating private information and public information used in the adapter signature scheme; A public information transmission unit that transmits the public information to the entrusted history information generation device; an entrusted history information receiving unit that receives the data, the pre-signature, and the public key as the history information from the entrusted history information generation device; a pre-signature verification unit that verifies the pre-signature based on the public information, the data received by the entrustment history information receiving unit, the pre-signature, and a public key; a signature generation unit that generates a signature in the adapter signature scheme from the secret information, the public key, the pre-signature, and the data; a history information recording unit that records the history information in the recording device by replacing a pre-signature of the history information with the signature generated by the signature generating unit; A history information recording system comprising:
2. A consignment history information generating device of a consignee in a history information recording system in which a consignor records history information of a content in a recording device on behalf of a consignee of an action on the content, comprising: a public information receiving unit for receiving public information used in the adapter signature method from a trustee's trust history information registration device; a key generation unit that generates a private key and a public key in a digital signature scheme; a pre-signature generation unit that generates a pre-signature in an adapter signature scheme for data that identifies the action from the private key, the public key, and the public information; a trust history information transmission unit that transmits the data, the pre-signature, and the public key to the trust history information registration device as the history information; A delegation history information generation device comprising:
3. A program for causing a computer to function as the entrusted history information generation device according to claim 2.
4. A consignment history information registration device of a consignor in a history information recording system in which a consignor records history information of a content in a recording device on behalf of a consignee of an action on the content, a private / public information generating unit for generating private information and public information used in the adapter signature scheme; a public information transmission unit that transmits the public information to a delegation history information generation device that is a delegation destination of an action on the content; a entrusted history information receiving unit that receives data identifying the action, a pre-signature in the adapter signature scheme, and a public key in the digital signature scheme as the history information from the entrusted history information generation device; a pre-signature verification unit that verifies the pre-signature based on the public information, the data received by the entrustment history information receiving unit, the pre-signature, and a public key; a signature generation unit that generates a signature in the adapter signature scheme from the secret information, the public key, the pre-signature, and the data; a history information recording unit that records the history information in the recording device by replacing a pre-signature of the history information with the signature generated by the signature generating unit; A delegation history information registration device comprising:
5. A program for causing a computer to function as the entrustment history information registration device according to claim 4.