Content origin certification system, control method for content origin certification system and program

The content origin certification system addresses the issue of expired public key certificates by using a dual digital signature approach, ensuring accurate verification of digital signature authenticity and maintaining identity verification functionality.

JP2025090150APending Publication Date: 2025-06-17CANON KK

Patent Information

Application Number
JP2023205196
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-05
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

Public key certificates for digital signatures have expiration dates, which can lead to a loss of identity verification functionality if not renewed in time.

Method used

A content origin certification system that includes a content generation device and a server, where the device generates a first digital signature associated with digital content using a first secret key and transmits it to the server. The server verifies the authenticity of the first digital signature and generates a second digital signature using a second secret key, which is paired with a public key certified by a certification authority.

Benefits of technology

This system allows for accurate verification of the authenticity of digital signatures, even for third parties, by ensuring that the digital content has not been tampered with and that the identity of the signer can be reliably verified.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025090150000001_ABST
    Figure 2025090150000001_ABST
Patent Text Reader

Abstract

To provide a content origin certification system. a control method for the content origin certification system, and a program for enabling a third party to accurately verify the authenticity of a digital signature.SOLUTION: A content origin certification system 1000 comprises a digital camera 101 and a content reception server 102. The digital camera 101 comprises first digital signature generation means (digital signature generation part 213) for generating a first digital signature based on a first secret key. The content reception server 102 comprises verification means (digital signature verification part 402) for verifying the authenticity of the first digital signature, and second digital signature generation means (digital signature generation part 404) for generating a second digital signature based on a second secret key when the first digital signature is verified as being authentic. The second secret key is paired with a public key for which a public key certificate is issued and which can be used to verify the authenticity of the second digital signature.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a content origin certification system, a control method for the content origin certification system, and a program.

Background Art

[0002] In recent years, information sharing via SNS and the like has become active, and anyone can view and transmit the shared information. In addition, due to the evolution of processing technologies for digital images and the emergence of image generation technologies that generate digital images such as real photos using AI, it has become difficult for viewers to confirm the authenticity of digital images. Therefore, there is an increasing demand for a mechanism to guarantee the authenticity of digital images captured by digital cameras, that is, that no processing or forgery has been performed. As a means of guaranteeing that a digital image has not been forged, there is encryption using a digital signature. For example, Patent Document 1 discloses a technique for associating a digital image captured by a digital camera with a digital signature. A digital signature is generated by encrypting digital image data with a private key. In addition, in order to guarantee that a digital image has not been forged, it is necessary to provide each digital camera with a private key. Each private key, if leaked, may cause forgery or impersonation of digital images, so it is preferably protected by hardware with high security in which external reading and overwriting are restricted. In addition, digital signatures are generally managed together with a certificate issued by an institution called a "certification authority" in order to prove the identity of the signatory. A certificate is issued for the public key for verifying the authenticity of a digital signature and is called a "public key certificate".

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, generally, a public key certificate has an expiration date. Therefore, when using a public key whose expiration date of the public key certificate has passed and a secret key paired with the public key, there is a risk that the function of guaranteeing the identity of the signer will be lost.

[0005] The present invention has been made in view of the above problems. An object of the present invention is to provide a content origin certification system, a control method of the content origin certification system, and a program that can accurately grasp the authenticity of a digital signature even for a third party.

Means for Solving the Problems

[0006] To achieve the above object, a content origin certification system of the present invention includes a content generation device that generates digital content, and a server communicably connected to the content generation device, and is a content origin certification system that proves the origin of the digital content, wherein the content generation device includes a first digital signature generation means for generating a first digital signature associated with the digital content based on a first secret key, and a transmission means for transmitting the digital content and the first digital signature to the server, the server includes a reception means for receiving the digital content and the first digital signature transmitted from the transmission means, a verification means for verifying the authenticity of the first digital signature received by the reception means, and a second digital signature generation means for generating a second digital signature associated with the digital content received by the reception means based on a second secret key when the first digital signature is verified to be true as a result of the verification by the verification means, and the second secret key is paired with a public key for which a public key certificate is issued by a certification authority and which can be used for verifying the authenticity of the second digital signature.

Effects of the Invention

[0007] According to the present invention, a third party can accurately determine the authenticity of a digital signature.

Brief Description of the Drawings

[0008]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Modes for Carrying Out the Invention

[0009] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. However, the configurations described in the following embodiments are merely examples, and the scope of the present invention is not limited by the configurations described in the embodiments. For example, each part constituting the present invention can be replaced with any configuration that can exhibit the same function. Also, any component may be added.

[0010] <Configuration of the Content Origin Certification System and Processes Executed by the Content Origin Certification System> FIG. 1 is a schematic diagram showing an example of the configuration of a content origin certification system. As shown in FIG. 1, a content origin certification system 1000 includes a digital camera 101 which is a content generation device, and a content receiving server (server) 102 communicably connected to the digital camera 101. The digital camera 101 can generate a photographed image by photographing with the digital camera 101 as digital content 110. The content receiving server 102 can receive the digital content 110 generated by the digital camera 101. The content origin certification system 1000 is a system for certifying the origin of the digital content 110. Note that, as the content generation device, in this embodiment, it is the digital camera 101, but it is not limited thereto. For example, as the content generation device, it may be a device that generates audio data of recorded voice, a device that generates image data such as an illustratory image drawn digitally, a device that generates data of composed music, or the like. Further, a smartphone 104, a smartphone 106, and a CA (certification authority) 107 are communicably connected to the content receiving server 102. Also, the smartphone 104 and the smartphone 106 are each communicably connected to an SNS 108. The digital camera 101 and the smartphone 104 have a photographer 103 who takes a photograph with the digital camera 101 as the user. The smartphone 106 has a viewer 105 who views the photographed image taken by the digital camera 101 as the user.

[0011] (1) Generate a digital camera signature immediately after shooting and write it to the meta area of the image file As shown in FIG. 1, the photographer 103 operates the digital camera 101 to take a picture. As a result, digital content 110 is obtained. This digital content 110 is an image file having an image data storage area 111 in which the data of the photographed image is stored and a metadata storage area 112 in which metadata is stored. The metadata storage area 112 can store data conforming to, for example, the Exif (Exchangeable image file format) standard or the like. Further, in the digital camera 101, a digital signature generation unit (first digital signature generation means) 213 (see FIG. 2) generates a first digital signature for the digital content 110 immediately after shooting (first digital signature generation step). The first digital signature is associated with the digital content 110. The generation of this first digital signature is performed based on a first secret key (first signature key) and a first hash value (hash value) calculated (acquired) from the digital content 110. Specifically, the first digital signature is generated by encrypting the first hash value with the first secret key. Since the first secret key may lead to forgery if it leaks to the outside, it has high secrecy. This first secret key is stored in a camera secret key storage unit (storage means) 212 having tamper resistance (see FIG. 2). In the present embodiment, the first secret key used for the first digital signature may be referred to as the "camera secret key", and the first digital signature may be referred to as the "camera digital signature".

[0012] Next, the digital signature generation unit 213 stores the camera digital signature (first digital signature) in the metadata storage area 112 as metadata. As a result, the digital content 110 is in a state where the camera digital signature is attached (hereinafter referred to as the "camera digital signature attached state"). When calculating the first hash value from the digital content 110, it is preferable to exclude the metadata storage area 112 from the target of calculating the first hash value in advance. Also, the camera digital signature is stored in the metadata storage area 112 of the digital content 110 in this embodiment, but it is not limited to this. For example, it may be stored in a file separate from the digital content 110. In this case, in the next step (transmission step), it is preferable to transmit the digital content 110 and the separate file in association with each other to the content receiving server 102. Also, the function of generating the camera digital signature at the moment of shooting and storing it in the metadata storage area 112 can be switched by the photographer 103 operating the shooting setting menu of the digital camera 101.

[0013] (2) Transmit the image file with the camera digital signature attached The digital camera 101 transmits the digital content 110 (image file) in the camera digital signature attached state to the content receiving server 102 via the communication unit (transmission means) 210 (see FIG. 2) (transmission step). FTP (File Transfer Protocol) is used for this transmission.

[0014] (3) Verify the camera digital signature, generate the server digital signature, and write to the meta area of the image file The content receiving server 102 receives the digital content 110 in the camera digital signature attached state transmitted from the communication unit 210 of the digital camera 101 via the data receiving unit (receiving means) 401 (see FIG. 4) (receiving step).

[0015] Next, in the content receiving server 102, a digital signature verification unit (verification means) 402 (see FIG. 4) verifies the authenticity of the camera digital signature of the digital content 110 received by the data receiving unit 401 (verification step). This verification will be described. In the content receiving server 102, a serial number as an identifier capable of identifying the digital camera 101 and a first public key (first verification key) for verifying the camera digital signature are associated with each other and stored in a camera database (storage means) 403. Further, the serial number is also stored in the metadata storage area 112 (digital content 110) as metadata. The first public key can be used by an unspecified number of people to verify the camera digital signature. In the present embodiment, the first public key used for verifying this camera digital signature may be referred to as the "camera public key". The digital signature verification unit 402 acquires the serial number from the digital content 110 received in the reception step. Then, the digital signature verification unit 402 acquires the camera public key associated with the same serial number as the acquired serial number from the camera database 403. The digital signature verification unit 402 uses the camera public key to verify the authenticity of the camera digital signature.

[0016] As described above, the first digital signature is obtained by encrypting the first hash value calculated from the digital content 110 with the camera private key. The camera private key is paired with the camera public key. As a result, the first digital signature can be correctly decrypted only with the camera public key. By this decryption, the hash value is obtained. Further, the digital signature verification unit 402 calculates a hash value (first hash value) from the digital content 110 received in the reception process, in the same manner as the calculation of the first hash value in the digital camera 101. The digital signature verification unit 402 can verify the authenticity of the camera digital signature based on whether or not the hash values match, that is, the hash value obtained by decryption and the hash value obtained from the digital content 110. Specifically, when the hash values match, it can be verified that the camera digital signature is authentic (true). Then, since it is verified that the camera digital signature is authentic, it can be determined that the digital content 110 after the camera digital signature is generated in the digital camera 101 has not been modified or altered. On the other hand, when the hash values do not match, it can be verified that the camera digital signature is not authentic (false). In this case, it can be determined that the digital content 110 after the camera digital signature is generated in the digital camera 101 has been modified or altered.

[0017] If the first digital signature is verified to be true as a result of verification by the digital signature verification unit 402, the digital signature generation unit (second digital signature generation means) 404 (see FIG. 4) generates a second digital signature (second digital signature generation step). Similar to the first digital signature, the second digital signature is associated with the digital content 110. The generation of this second digital signature is performed based on the second private key (second signature key) and the second hash value calculated from the digital content 110. Specifically, the second digital signature is generated by encrypting the second hash value with the second private key. The second private key also has a high level of secrecy similar to the first private key. This second private key is stored in the tamper-resistant camera database 403. In the present embodiment, the second private key used for the second digital signature may be referred to as the "server private key", and the second digital signature may be referred to as the "server digital signature".

[0018] Next, the digital signature generation unit 404 stores the server digital signature (second digital signature) as metadata in the metadata storage area 112. As a result, the server digital signature is attached to the digital content 110 (hereinafter referred to as the "server digital signature attached state"). When calculating the second hash value from the digital content 110, it is preferable to exclude the metadata storage area 112 from the second hash value calculation target in advance, and it is preferable to include the camera digital signature in the second hash value calculation target. The server private key (second private key) used for the server digital signature forms a pair with the public key (second public key) that can be used to verify the authenticity of the server digital signature. In this embodiment, this public key may be referred to as the "server public key". In addition, a public key certificate is issued to the server public key by the CA 107. The digital signature generation unit 404 stores the public key certificate as metadata in the metadata storage area 112. The public key certificate is generally issued by the CA 107 upon a request for issuance from a legitimate corporation that manufactures or sells the digital camera 101. The manufacturer of the digital camera 101 acquires the public key certificate issued by the CA 107. The "public key certificate" is a certificate that proves that the server public key associated with the public key certificate is the public key set by the legitimate corporation. With such a public key certificate, the server public key can be determined to be the public key set by the legitimate corporation for a third party such as the viewer 105. On the other hand, it is determined that it is unclear whether the public key not associated with the public key certificate is the public key set by the legitimate corporation. In addition, a time stamp certificate may be issued for the digital content 110 in the server digital signature attached state. The "time stamp certificate" is a certificate that the time certification authority proves that the digital content 110 exists at a certain time and has not been tampered with. Generally, the public key certificate by the CA 107 has a validity period of one year, while the time stamp certificate by the time certification authority has a validity period of 10 years.The timestamp certificate will prove that there was digital content 110 with a server digital signature and a valid public key certificate at a certain time for 10 years. In this way, the timestamp certificate becomes an effective means to prove the identity of the signer of the digital signature even for digital content 110 that has passed the validity period of the public key certificate.

[0019] (4) Store the image file with the server digital signature in the image storage The digital content 110 with the camera digital signature and the server digital signature is stored in the image storage 407 (see Fig. 4) of the content receiving server 102.

[0020] (5) Obtain the URL for the photographed image file A URL is assigned to the digital content 110 stored in the image storage 407. Third parties such as the photographer 103 and other viewers 105 can use this URL to view or download the digital content 110.

[0021] (6) Publish the image on SNS and attach the URL for the image file to the post The photographer 103 uses the URL assigned to the digital content 110 stored in the image storage 407 to download the digital content 110 to his / her smartphone 104. Then, the photographer 103 publishes the digital content 110 downloaded to the smartphone 104 on SNS 108, etc. At this time, the photographer 103 can describe the download URL that allows a third party to download the digital content 110 in the text when posting to SNS 108. A third - party viewer 105 can use this download URL to download the digital content 110.

[0022] (7) View the SNS post and obtain information about the image file Viewer 105 is viewing a captured image of digital content 110 posted by the photographer 103 on the SNS 108 using the smartphone 106 he / she owns. Viewer 105 can compare the viewed captured image with the captured image of the digital content 110 downloaded in (5) above. As a result of this comparison, it can be easily visually confirmed that the viewed captured image has not been altered, such as changed or edited, since the time of shooting, just like the captured image of the digital content 110 downloaded in (5) above. Also, Viewer 105 can copy the URL of the digital content 110 or download the digital content 110 to obtain information on the digital content 110 to be confirmed.

[0023] (8) Request for verification of alteration based on image file information The content receiving server 102 is configured to be able to provide a content origin proof web page (image) that can be used when proving the origin of the digital content 110, or the URL (address) of the content origin proof web page. Here, it is assumed that Viewer 105 has obtained the download URL of the digital content 110 posted by the photographer 103 on the SNS 108, or the digital content 110 itself that is the subject of verification of alteration, from the SNS 108. Viewer 105 uses the smartphone 106 to search for and access the URL of the content origin proof web page, for example, by web search or the like. As a result, a content origin proof web page 700 (see FIG. 7) is displayed on the smartphone 106. The content origin proof web page 700 includes a UI (User Interface) section 701 and a UI section 702. The UI section 701 is a part where the digital content 110 can be dragged and dropped. The UI section 702 is a part where the download URL of the digital content 110 can be input. By using such a content source certification web page 700, the viewer 105 can specify digital content 110 to be verified for forgery to the content receiving server 102. Note that the content source certification web page 700 will be described later with reference to FIG. 7.

[0024] (9) Verification result of forgery As described above, the viewer 105 can drag and drop the digital content 110 to be verified for forgery onto the UI section 701 of the content origin certification web page 700. In this case, the digital signature verification section 402 of the content reception server 102 verifies the authenticity of the server digital signature and the camera digital signature included in the digital content 110. The server digital signature is obtained by encrypting the second hash value calculated from the digital content 110 with the server private key. The server private key pairs with the server public key. Thus, the server digital signature can be correctly decrypted only with the server public key. By this decryption, the hash value is obtained. Also, the digital signature verification section 402 calculates a hash value (second hash value) from the digital content 110. The digital signature verification section 402 can verify the authenticity of the server digital signature based on whether the hash values match, that is, the hash value obtained by decryption and the hash value obtained from the digital content 110. Specifically, when the hash values match, it can be verified that the server digital signature is authentic (true). On the other hand, when the hash values do not match, it can be verified that the server digital signature is not authentic (false). After verifying the server digital signature, the digital signature verification section 402 verifies the camera digital signature. The verification of the camera digital signature is as described above. Then, the verification result of the server digital signature and the verification result of the camera digital signature are each displayed on the UI section 701 of the content origin certification web page 700. Thereby, the viewer 105 can confirm each verification result, and thus can accurately grasp the authenticity of each digital signature. And when each digital signature is authentic, it can be determined that the digital content 110 has not been forged since it was generated until now.

[0025] In addition, the viewer 105 can also specify the download URL of the digital content 110 in the UI section 702 of the content origin certification web page 700. In this case, the content receiving server 102 checks that the download URL is the download URL of the digital content 110 stored in the image storage 407. After this check, the content receiving server 102 controls to display the captured image of the digital content 110 on the content origin certification web page 700 (for example, the UI section 701). Thereby, the viewer 105 can visually compare the captured image from the SNS 108 being viewed with the captured image displayed on the content origin certification web page 700. Thereby, it is possible to check whether there has been any forgery since the captured image from the SNS 108 was captured by the digital camera 101. Note that when the viewer 105 specifies an incorrect URL different from the download URL of the digital content 110 in the UI section 702 of the content origin certification web page 700, that fact is displayed on the content origin certification web page 700.

[0026] (10) Request for issuance of public key certificate The content receiving server 102 monitors the digital content 110 stored in the image storage 407. When the expiration date of the public key certificate associated with the server digital signature assigned to the digital content 110 is approaching, the content receiving server 102 sets a new pair of a server private key and a server public key. Further, the content receiving server 102 transmits the new server private key and the server public key to the CA 107, and requests the CA 107 to issue a new public key certificate for the new server private key, that is, to reissue the public key certificate. When a new public key certificate is issued, the content receiving server 102 performs a server digital signature on the digital content 110 again. When the server digital signature is performed again, the email address or the like associated with the user account of the photographer 103 who took the photographed image of the digital content 110 may be notified. Further, when the photographer 103 receives this notification, for example, the photographer 103 can re-upload the digital content 110 posted on the SNS 108.

[0027] <Configuration of Digital Camera> Figure 2 is a block diagram showing the configuration of a digital camera. As shown in Figure 2, the digital camera 101 includes an MPU (computer) 201, a timing signal generation circuit 202, an imaging device 203, an A / D converter 204, a memory controller 205, a buffer memory 206, and an image display unit 207. The digital camera 101 also includes a recording medium I / F 208, a recording medium 209, a communication unit 210, and a security chip 211. The MPU 201 is a microcontroller for controlling the system of the digital camera 101 such as a shooting sequence. The timing signal generation circuit 202 generates a timing signal required to operate the imaging device 203. The imaging device 203 is composed of, for example, a CCD or a CMOS, etc., and converts reflected light from a subject into an electrical signal (analog image data) and reads it out to the A / D converter 204. The A / D converter 204 converts the analog image data read out from the imaging device 203 into digital image data (hereinafter simply referred to as "image data"). The memory controller 205 controls the reading and writing of image files such as digital content 110 to the buffer memory 206 and the refresh operation of the buffer memory 206, etc. This image file has metadata (for example, Exif data) generated by the MPU 201 added thereto. The buffer memory 206 stores the image file. The image display unit 207 displays the image of the image file stored in the buffer memory 206.

[0028] The recording medium I / F 208 is an interface for controlling the reading and writing of data to and from the recording medium 209. The recording medium 209 is a recording medium such as a memory card that can be inserted into and removed from the digital camera 101, and stores programs, image files, and the like. Note that the program includes, for example, a program for causing each part and each means of the content origin certification system 1000 (control method of the content origin certification system) to execute. Also, this program is not limited to being stored in the digital camera 101, and may be stored in, for example, the content reception server 102, or may be distributed and stored in the digital camera 101 and the content reception server 102. The communication unit 210 is connected to the Internet (not shown) and performs data transmission and reception with external devices such as the content reception server 102. In the content origin certification system 1000, the communication unit 210 can transmit the digital content 110 to the content reception server 102. The security chip 211 is hardware having tamper resistance, and includes a camera private key storage unit 212 and a digital signature generation unit 213. The camera private key storage unit 212 stores the camera private key used for the camera digital signature. The digital signature generation unit 213 generates the camera digital signature. By providing the digital signature generation unit 213 in the security chip 211, the camera digital signature generation process can be performed without exposing the camera private key outside the security chip 211. Also, the risk of leakage of the camera private key can be reduced.

[0029] <Digital Camera Image File Generation Process with Camera Digital Signature> FIG. 3 is a flowchart showing a camera digital signature - attached image file generation process executed by a digital camera. As shown in FIG. 3, in step S301, when the photographer 103 presses (i.e., operates) the shutter button (not shown) of the digital camera 101, the MPU 201 controls the imaging device 203, etc., to execute a shooting process. Thereby, digital content 110, which is image data, is acquired. The digital content 110 is stored in the buffer memory 206. The digital content 110 is data immediately before being written to the recording medium 209 as a file. Here, it is assumed that the file format is JPEG.

[0030] In step S302, the MPU 201 controls the digital signature generation unit 213 to calculate a hash value from the digital content 110. As described above, the metadata storage area 112 where the camera digital signature is stored is excluded from the target of hash value calculation. In this embodiment, it is assumed that the camera digital signature is written as JPEG XMP metadata. At this time, the hash value calculation exclusion part is the entire APP1 segment where XMP data exists. The APP1 segment data includes the data size of the APP1 segment. This data size is a value that will change when the camera digital signature is later added as XMP metadata. If this is included in the hash calculation target, there is a risk of failure in verifying the camera digital signature. Therefore, the entire APP1 segment including XMP data is excluded from the hash calculation target. The format for embedding the camera digital signature is not limited to XMP. For example, in the case of a JPEG file, the JUMBF data storage format can be used. Embed the camera digital signature in the JUMBF format and exclude the segment including the JUMBF data from the hash value calculation target. Also, the hash calculation can be performed by the MPU 201, but since the calculation amount is relatively large, it is preferably calculated by the digital signature generation unit 213 having a hash calculation function in the security chip 211. Thereby, the acceleration of hash calculation becomes possible, and thus, the reduction in the processing speed of the entire camera function can be prevented or suppressed.

[0031] In step S303, the MPU 201 controls the digital signature generation unit 213 to read the camera private key from the camera private key storage unit 212, and encrypts the hash value with the camera private key to generate a camera digital signature.

[0032] In step S304, the MPU 201 creates an area for storing the camera digital signature in the buffer memory 206. The creation method is not particularly limited. For example, a method of shifting the address of the data after the part where the camera digital signature is inserted can be mentioned. In addition, a method of securing a memory of a size capable of storing the digital content 110 including the new camera digital signature on the buffer memory 206 and copying the data may also be used. Further, a method of dividing the units managed on the buffer memory 206 in advance into segments such as APP1, APP2, and image areas to reduce the amount of data movement and data copy when inserting XMP data later may also be used.

[0033] In step S305, the MPU 201 stores (writes) the camera digital signature in the area created in step S304. As an example of the camera digital signature, <xmp:camerasigndata>Byte sequence of camera digital signature data< / xmp:camerasigndata> etc.

[0034] In step S306, the MPU 201 controls the recording medium I / F 208 to write the digital content 110 with the camera digital signature attached to the recording medium 209.

[0035] In step S307, the MPU 201 controls the communication unit 210 to transmit the digital content 110 with the camera digital signature attached to the content receiving server 102. For this communication, FTP shall be used. Note that when the digital camera 101 transmits the digital content 110, it preferably has a UI unit (not shown) for setting the URL or IP address of the content receiving server 102 which is the transmission destination. Also, during FTP communication, user authentication is performed using a user account and a password. The digital camera 101 preferably has a UI unit (not shown) for inputting the user account and the password when user authentication is performed.

[0036] <Configuration of Content Receiving Server> FIG. 4 is a block diagram showing the configuration of the content receiving server. The content receiving server 102 composed of a computer shown in FIG. 4 is composed of at least one computer, and is preferably composed of a plurality of computers. Thereby, the processing speed at the content receiving server 102 can be improved. The content receiving server 102 has a data receiving unit 401, a digital signature verification unit 402, a camera database 403, and a digital signature generation unit 404. Also, the content receiving server 102 has a server private key storage unit 405, a public key certificate storage unit 406, an image storage 407, a UI unit 408, and a server public key storage unit 409. The data receiving unit 401 has a communication function of a network protocol. In the present embodiment, since the data receiving unit 401 is configured to use FTP for file reception from the digital camera 101, it has at least an FTP communication function. During FTP communication, user authentication is performed using a user account and a password.

[0037] The digital signature verification unit 402 verifies the authenticity of the camera digital signature and the server digital signature. The digital signature verification unit 402 receives the digital content 110 from the data reception unit 401. Then, the digital signature verification unit 402 acquires the camera serial number in the Exif data of the digital content 110 and the camera digital signature data from the XMP area. The digital signature verification unit 402 uses the camera serial number as a key, that is, based on the camera serial number, to acquire the camera public key from the camera database 403 and verify the camera digital signature. If the verification of the camera digital signature fails, it is considered that the digital content 110 has been tampered with or has been sent from a computer device such as a digital camera 101 masquerading as an FTP-transmittable device. In this case, it is preferable to delete the digital content 110. The digital signature verification unit 402 receives the digital content 110 for which verification is requested from the UI unit 408. Then, the digital content 110 acquires the server digital signature data from the XMP area. The digital content 110 acquires the server public key from the server public key storage unit 409 and verifies the server digital signature. The camera database 403 manages by associating the camera serial number for each digital camera 101 with the camera public key.

[0038] The digital signature generation unit 404 acquires the server private key from the server private key storage unit 405 and generates a server digital signature. For the hash calculation target for generating the server digital signature, similar to the camera digital signature generation, it is preferable to exclude the APP1 segment including the XMP data from the digital content 110. Regarding the camera digital signature, it is added to the end of the digital content 110 and included in the hash calculation target. The digital signature generation unit 404 adds the server digital signature to the digital content 110. The server digital signature includes the camera digital signature <xmp:camerasigndata>After the tag, for example, <xmp:serversigndata01>Byte sequence of server digital signature data< / xmp:serversigndata01> are attached. The "01" after the character string "ServerSignData" of the above XML tag is attached because server digital signatures will be added multiple times in the future. In the digital content 110 stored in the image storage 407, before the expiration of the public key certificate of the key used for the server digital signature and the above-mentioned timestamp certificate, re-signing is performed using a new key. The character string of the XML tag at the time of re-signing is, for example, <xmp:serversigndata02>Byte sequence of server digital signature data< / xmp:serversigndata02> . In this way, the numerical value after the character string "ServerSignData" is incremented from the previous signature, and a server digital signature is attached to the digital content 110. In addition, the digital signature generation unit 404 attaches a server digital signature to the digital content 110 and also attaches a public key certificate. The digital signature generation unit 404 reads the public key certificate from the public key certificate storage unit 406 and, in the same way as attaching the server digital signature, in the XMP area of the digital content 110, <xmp:certificate01>Public key certificate data< / xmp:certificate01> are attached.

[0039] If the expiration date of the public key certificate issued for the server private key has expired, it is necessary to update the public key certificate. The server private key storage unit 405 manages the expiration date management, renewal, etc. of the public key certificate. Since the server private key is also highly confidential data, the server private key storage unit 405 can impose restrictions so that only limited personnel among the server administrators can access it. In addition, the server private key storage unit 405 can monitor and take countermeasures against unauthorized access from the outside. The public key certificate storage unit 406 can manage the expiration date of the public key certificate in the same way as the server private key storage unit 405. When the expiration date of the public key certificate is approaching, the public key certificate storage unit 406 notifies the server administrator who manages the content receiving server 102 to that effect. When the server administrator confirms this notification, a new server private key and server public key are created, and the CA 107 is requested to issue a public key certificate. The image storage 407 stores the digital content 110 with the camera digital signature verified and the server digital signature attached state. A URL for downloading is assigned to this digital content 110. The UI unit 408 provides the content origin certification web page 700 (see FIG. 7). The server public key storage unit 409 stores the server public key for verifying the server digital signature.

[0040] <Example of digital signature data to be attached to image data> FIG. 5 is a diagram showing an example of attaching a digital signature and a public key certificate to digital content by a content receiving server. The internal structure 501 of the JPEG file shown in FIG. 5 has XMP data 502. The XMP data 502 contains various data such as a camera digital signature, a server digital signature, and a public key certificate as XMP metadata attached to the digital content 110.

[0041] <Verification by a third party> FIG. 6 is a flowchart showing content origin verification processing for verifying that digital content posted on an SNS has not been tampered with. Here, as an example, it will be described that viewer 105 performs content origin verification using content origin proof web page 700 in a state where the download URL of digital content 110 posted on SNS 108 has been obtained. As shown in FIG. 6, in step S601, content reception server 102 receives, via UI unit 408, digital content 110 to be verified from viewer 105 or the input of the download URL of digital content 110.

[0042] In step S602, content reception server 102 determines whether the input information in step S601 is a URL. As a result of the determination in step S602, if it is determined that the input information is a URL, the process proceeds to step S603. On the other hand, as a result of the determination in step S602, if it is determined that the input information is not a URL, that is, it is determined to be digital content 110 itself, the process proceeds to step S606.

[0043] In step S603, content reception server 102 determines, based on the input information, whether digital content 110 exists in image storage 407, that is, whether digital content 110 can be obtained from image storage 407. If the URL that is the input information is correct, as a result of the determination in step S603, it is determined that digital content 110 can be obtained. In this case, the process proceeds to step S604. On the other hand, if the URL that is the input information is incorrect, as a result of the determination in step S603, it is determined that digital content 110 cannot be obtained. In this case, the process proceeds to step S605.

[0044] In step S604, the content receiving server 102 displays the captured image of the digital content 110 determined to be acquirable in step S603 on the UI unit 408. The viewer 105 can compare the digital content 110 displayed on the UI unit 408 with the digital content 110 posted on the SNS 108. Then, based on this comparison result, the viewer 105 can confirm the presence or absence of forgery in the captured image of the digital content 110 captured by the digital camera 101.

[0045] In step S605, the content receiving server 102 displays on the UI unit 408 that the URL which is the input information is invalid.

[0046] In step S606, the content receiving server 102 verifies the authenticity of the camera digital signature and the server digital signature of the digital content 110 with the digital signature verification unit 402.

[0047] In step S607, the content receiving server 102 determines whether there is a problem with the verification result in step S606. As a result of the determination in step S607, if it is determined that there is no problem (OK) with the verification result, the process proceeds to step S608. On the other hand, as a result of the determination in step S607, if it is determined that there is a problem (NG) with the verification result, the process proceeds to step S609.

[0048] In step S608, the content receiving server 102 displays on the UI unit 408 that it is determined that there is no problem with the verification result. Thereby, the viewer 105 can grasp that there is no problem with the verification result.

[0049] In step S609, the content receiving server 102 displays on the UI unit 408 that it is determined that there is a problem with the verification result. Thereby, the viewer 105 can grasp that there is a problem with the verification result.

[0050] <Content source certification web page> FIG. 7 is a diagram showing an example of a content origin certification web page. The content origin certification web page 700 shown in FIG. 7 is a web page used when certifying the origin of digital content 110. The content origin certification web page 700 includes a UI section 701, a UI section 702, and a button UI section 703. The UI section 701 is a part where the digital content 110 to be verified for forgery can be specified by drag-and-drop. When the digital content 110 is dropped into the UI section 701, a digital signature verification process of the digital content 110 is performed, and the result of the verification is displayed superimposed on the content origin certification web page 700. The UI section 702 is a part where a URL for downloading the digital content 110 stored in the image storage 407 of the content reception server 102 and to be verified for forgery can be input. By pressing the button UI section 703 with a download URL input to the UI section 702, a search for the digital content 110 stored in the image storage 407 is started. Thereby, a photographed image of the digital content 110 is displayed superimposed on the content origin certification web page 700. When the button UI section 703 is pressed with a URL different from the download URL input to the UI section 702, for example, a message indicating that "the input URL is incorrect" is displayed superimposed on the content origin certification web page 700.

[0051] As described above, the preferred embodiments of the present invention have been explained. However, the present invention is not limited to the above-described embodiments, and various modifications and changes are possible within the scope of the gist thereof. The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or apparatus via a network or a recording medium, and having one or more processors of a computer of the system or apparatus read and execute the program. Further, the present invention can also be realized by a circuit (for example, ASIC) that realizes one or more functions. Further, although the digital signature verification unit 402 is configured to be able to execute camera digital signature verification processing and server digital signature verification processing in the present embodiment, it is not limited thereto. For example, the digital signature verification unit 402 may be configured to be divided into a first verification unit that executes camera digital signature verification processing and a second verification unit that executes server digital signature verification processing. Also, the camera public key may not be transmitted to the content receiving server 102 and may be anonymized within the content receiving server 102. In this case, for example, the serial number of the digital camera 101 and the camera public key are linked and managed on the content receiving server 102 side. From this, the content receiving server 102 can acquire the serial number of the digital camera 101 from the digital content 110 and acquire the camera public key corresponding to the serial number.

[0052] In the content origin certification system 1000, for example, the content receiving server 102 (hereinafter simply referred to as the "server") may be located outside Japan, and the digital camera 101, which is a terminal device, may be located within Japan. Even in this case, each file and data can be transmitted from the server to the terminal device, and the terminal device can receive each file and data. Even when the server is located outside Japan, the transmission and reception (transmission-reception) of files and data in this system are performed integrally. And since the system functions when the terminal device in Japan receives each file and data, the transmission-reception can be regarded as having been performed within the country. Also, in this system, for example, even when the server is located outside Japan and the terminal device is located within Japan, the terminal device can perform the main functions of this system, and the effects of those functions can be manifested within Japan. For example, even if the server is located outside Japan, if the terminal device constituting this system is located within Japan, it is possible to use this system within the country using the terminal device. And the use of this system can, for example, have an impact on the economic interests of the patent holder.

[0053] The disclosure of this embodiment includes the following configurations, methods, and programs. (Configuration 1) A content generation device that generates digital content, and a server communicably connected to the content generation device, a content origin certification system for certifying the origin of the digital content, The content generation device, A first digital signature generation means for generating a first digital signature associated with the digital content based on a first private key, A transmission means for transmitting the digital content and the first digital signature to the server, The server, A reception means for receiving the digital content and the first digital signature transmitted from the transmission means, A verification means for verifying the authenticity of the first digital signature received by the reception means, When, as a result of verification by the verification means, it is verified that the first digital signature is true, second digital signature generation means for generating a second digital signature associated with the digital content received by the receiving means based on the second secret key, comprising: The second secret key is characterized in that a public key certificate is issued by a certification authority and forms a pair with a public key that can be used to verify the authenticity of the second digital signature, a content origin proof system. (Configuration 2) The content origin proof system according to Configuration 1, wherein the first digital signature generation means generates the first digital signature based on the first secret key and a hash value obtained from the digital content. (Configuration 3) The content origin proof system according to Configuration 1 or 2, wherein the second digital signature generation means generates the second digital signature based on the second secret key and a hash value obtained from the digital content. (Configuration 4) The digital content has a storage area for storing metadata, The first digital signature generation means stores the first digital signature as the metadata in the storage area, The content origin proof system according to any one of Configurations 1 to 3, wherein the second digital signature generation means stores the second digital signature and the public key certificate as the metadata in the storage area, respectively. (Configuration 5) When the public key paired with the second secret key is a second public key, the first secret key forms a pair with a first public key that can be used to verify the authenticity of the first digital signature, The server is provided with storage means for associating and storing an identifier capable of identifying the content generation device and the first public key with each other, the content origin proof system according to any one of Configurations 1 to 4. (Configuration 6) The digital content has a storage area for storing metadata, The identifier is also stored in the digital content as the metadata, The verification means acquires the identifier from the digital content received by the receiving means, and based on the identifier, acquires the first public key from the storage means, and uses the first public key to verify the authenticity of the first digital signature. The content origin proof system according to Configuration 5. (Configuration 7) The verification means uses the first public key to decrypt the first digital signature to obtain a hash value, and obtains a hash value from the digital content received by the receiving means, and based on whether the hash values match each other, verifies the authenticity of the first digital signature. The content origin proof system according to Configuration 6. (Configuration 8) When the hash values match each other, the verification means verifies that the first digital signature is genuine. The content origin proof system according to Configuration 7. (Configuration 9) The verification means can verify the authenticity of the second digital signature. The content origin proof system according to any one of Configurations 1 to 8. (Configuration 10) When the public key paired with the second secret key is used as the second public key, the verification means uses the second public key to decrypt the second digital signature to obtain a hash value, and obtains a hash value from the digital content received by the receiving means, and based on whether the hash values match each other, verifies the authenticity of the second digital signature. The content origin proof system according to Configuration 9. (Configuration 11) When the hash values match each other, the verification means verifies that the second digital signature is genuine. The content origin proof system according to Configuration 10. (Configuration 12) The content generation device stores the first secret key and includes a storage means having tamper resistance. The content origin proof system according to Configuration 1. (Configuration 13) The content generation device is a digital camera. The content origin proof system according to any one of Configurations 1 to 12. (Configuration 14) The content origin proof system according to any one of Configurations 1 to 13, wherein the server stores the second secret key and includes a memory means having tamper resistance. (Configuration 15) The content origin proof system according to any one of Configurations 1 to 14, wherein the server is configured to be able to provide an image that can be used when proving the origin of the digital content, or an address of the image. (Configuration 16) The content origin proof system according to any one of Configurations 1 to 15, wherein the server is composed of at least one computer. (Method 1) A method for controlling a content origin proof system including a content generation device that generates digital content and a server communicably connected to the content generation device, and proving the origin of the digital content, comprising: Steps executed by the content generation device include: A first digital signature generation step of generating a first digital signature associated with the digital content based on a first secret key; A transmission step of transmitting the digital content and the first digital signature to the server; and Steps executed by the server include: A reception step of receiving the digital content and the first digital signature transmitted from the transmission step; A verification step of verifying the authenticity of the first digital signature received in the reception step; A second digital signature generation step of generating a second digital signature associated with the digital content received in the reception step based on a second secret key when it is verified in the verification step that the first digital signature is genuine; and The second secret key is paired with a public key for which a public key certificate is issued by a certification authority and can be used for verifying the authenticity of the second digital signature. A method for controlling a content origin proof system. (Program 1) A program for causing a computer to execute each means of the content origin certification system described in any one of Configurations 1 to 16.

Explanation of Signs

[0054] 101 Digital camera 102 Content receiving server 107 CA (Certification Authority) 110 Digital content 210 Communication unit 213 Digital signature generation unit 401 Data receiving unit 402 Digital signature verification unit 404 Digital signature generation unit 1000 Content origin certification system< / xmp:camerasigndata>

Claims

1. A content origin proof system comprising a content generation device for generating digital content and a server communicably connected to the content generation device, wherein the content generation device is configured to: generate a first digital signature associated with the digital content based on a first private key; and transmit the digital content and the first digital signature to the server; The server is configured to: receive the digital content and the first digital signature transmitted from the transmitting means; verify the authenticity of the first digital signature received by the receiving means; and, when the first digital signature is verified to be authentic as a result of the verification by the verification means, generate a second digital signature associated with the digital content received by the receiving means based on a second private key; wherein the second private key is paired with a public key for which a public key certificate has been issued by a certification authority and which can be used to verify the authenticity of the second digital signature.

2. The content origin proof system according to claim 1, wherein the first digital signature generation means generates the first digital signature based on the first private key and a hash value obtained from the digital content.

3. The content origin proof system according to claim 1, wherein the second digital signature generation means generates the second digital signature based on the second private key and a hash value obtained from the digital content.

4. The digital content has a storage area for storing metadata. The first digital signature generation means stores the first digital signature in the storage area as the metadata. The content origin certification system according to claim 1, wherein the second digital signature generation means stores the second digital signature and the public key certificate in the storage area as the metadata, respectively.

5. When the public key paired with the second secret key is a second public key, the first secret key is paired with a first public key that can be used to verify the authenticity of the first digital signature. The server according to claim 1, further comprising storage means for storing an identifier capable of identifying the content generation device and the first public key in association with each other.

6. The digital content has a storage area for storing metadata. The identifier is also stored in the digital content as the metadata. The verification means obtains the identifier from the digital content received by the receiving means, obtains the first public key from the storage means based on the identifier, and uses the first public key to verify the authenticity of the first digital signature. The content origin certification system according to claim 5.

7. The verification means uses the first public key to decrypt the first digital signature to obtain a hash value, obtains a hash value from the digital content received by the receiving means, and based on whether the hash values match each other, verifies the authenticity of the first digital signature. The content origin certification system according to claim 6.

8. The verification means according to claim 7, wherein when the hash values match each other, verifies that the first digital signature is true. The content origin certification system.

9. The content origin proof system according to claim 1, wherein the verification means is capable of verifying the authenticity of the second digital signature.

10. When the public key paired with the second private key is used as the second public key, the verification means uses the second public key to decrypt the second digital signature to obtain a hash value, and obtains a hash value from the digital content received by the receiving means, and verifies the authenticity of the second digital signature based on whether the hash values match each other. The content origin proof system according to claim 9.

11. The content origin proof system according to claim 10, wherein when the hash values match each other, the verification means verifies that the second digital signature is true.

12. The content origin proof system according to claim 1, wherein the content generation device stores the first private key and includes a storage means having tamper resistance.

13. The content origin proof system according to claim 1, wherein the content generation device is a digital camera.

14. The content origin proof system according to claim 1, wherein the server stores the second private key and includes a storage means having tamper resistance.

15. The content origin proof system according to claim 1, wherein the server is configured to be able to provide an image that can be used when proving the origin of the digital content, or an address of the image.

16. The content origin proof system according to claim 1, wherein the server is composed of at least one computer.

17. A method for controlling a content origin certification system including a content generation device that generates digital content and a server communicably connected to the content generation device, for proving the origin of the digital content, The steps executed by the content generation device include A first digital signature generation step of generating a first digital signature associated with the digital content based on a first private key, A transmission step of transmitting the digital content and the first digital signature to the server, The steps executed by the server include A reception step of receiving the digital content and the first digital signature transmitted from the transmission step, A verification step of verifying the authenticity of the first digital signature received in the reception step, When the first digital signature is verified to be true as a result of the verification in the verification step, a second digital signature generation step of generating a second digital signature associated with the digital content received in the reception step based on a second private key, The second private key is characterized in that a public key certificate is issued by a certification authority and forms a pair with a public key that can be used to verify the authenticity of the second digital signature. A method for controlling a content origin certification system.

18. A program for causing a computer to execute each means of the content origin certification system according to claim 1.

Citation Information

Patent Citations

  • Method and apparatus for inserting a digital signature into digital data and authenticating the digital signature in the digital data

    JP2002542523A

Cited By

  • Content origin verifying system that also allows third party to accurately ascertain authenticity of digital signature, control method for content origin verifying system, and storage medium

    EP4567642A1