Group history information recording system, history information registration device, program thereof, and history information verification device, and program thereof
The group provenance information recording system addresses the challenge of verifying user legitimacy within a group by employing a group signature method to record and verify actions on content, ensuring reliable content origins and protecting user privacy.
Patent Information
- Application Number
- JP2023212860
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-18
- Publication Date
- 2025-06-30
AI Technical Summary
The conventional C2PA method cannot determine whether the user who performed an action on paid material content is a regular user within the group that paid the fee, even by referencing provenance information.
A group provenance information recording system that uses a group signature method to verify if the user who performed an action on content is a registered user within the group, by generating a group signature from data specifying the action, a group public key, and a personal secret key, and recording this information on a recording device.
This solution allows users to verify from the provenance information whether the content was generated by legitimate users within a preset group, while protecting user privacy and ensuring the reliability of content origins.
Smart Images

Figure 2025096886000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a group history information recording system, a history information registration device and its program, and a history information verification device and its program.
Background Art
[0002] In recent years, with the rapid progress of AI (Artificial Intelligence) technology, a large number of untrustworthy contents, such as the creation of fake images called deep fakes and the spread of fake news through SNS (Social Networking Service), whose source or creator is not clear, have been circulating on the Internet, becoming a social problem. In order to deal with such false information and misinformation, C2PA (Coalition for Content Provenance and Authenticity), a group that formulates open technical specifications for presenting "content history information" such as the source of content and editing history to users, was established in 2021.
[0003] C2PA is promoting the standardization of a mechanism that allows users to judge whether to trust the content by associating the content history information with the content (see Non-Patent Document 1). The standardization specifications promoted by C2PA record the following three pieces of information on a blockchain or a system (database) in the supply chain from the creation (here, shooting) to the presentation of content as shown in FIG. 7, so that anyone can verify it, thereby guaranteeing the reliability of the content.
[0004] (1) Information indicating who, when, and what was done to the content, and a hash value (assertion AS) for associating the content with the manifest. (2) A list of URIs (Uniform Resource Identifiers) of assertion AS (claim information CL). (3) Signature information (digital signature SI) for claim information CL. These three pieces of information are collectively called a manifest (C2PA manifest) MF as provenance information.
[0005] In the example of Fig. 7, Company A takes the photo and Company A records its provenance information (manifest) MF on the blockchain BC. Then, Company B edits the video taken by Company A and Company B records its provenance information MF on the blockchain BC. By repeating this operation, the provenance information MF is recorded on the blockchain BC for each action in the supply chain (workflow) from the creation to the presentation of the content. As a result, the content user (viewer VW) who uses (views) the content can determine whether the content is trustworthy for each action by verifying the digital signature SI of the provenance information MF.
Prior Art Documents
Non-Patent Documents
[0006]
Non-Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0007] In content creation, content for creative use such as video, audio, still image materials, etc. (material content) is often used. The material content for creative use may be something shot by the user himself / herself, or something purchased or borrowed from another company after paying a usage fee. At this time, when the material content is paid, only regular users in a certain group such as a membership system may be permitted to perform actions such as editing. However, in the conventional C2PA method, there is a problem that even by referring to the provenance information, it is impossible to determine whether the user who performed an action on a certain paid material content is a regular user within the group who paid the fee.
[0008] Therefore, an object of the present invention is to provide a group provenance information recording system, a provenance information registration device and its program, and a provenance information verification device and its program that can verify from the provenance information of content whether the content was generated by the actions of regular users within a preset group.
Means for Solving the Problem
[0009] To solve the above problems, a group provenance information recording system according to the present invention is a group provenance information recording system in which a user registered in a group records the provenance information of content in a recording device, and includes a management device, a provenance information registration device, and a provenance information verification device.
[0010] In such a configuration, the group provenance information recording system generates, by the management device, a group public key and a management secret key that are key information of the group signature method, and a personal secret key corresponding to the user's identification number. Then, the group provenance information recording system generates, by the provenance information registration device, a group signature of the group signature method from the data specifying the action on the content, the group public key, and the personal secret key, and records the data, the group signature, and the group public key in the recording device as provenance information. As a result, the history information will have a group signature added to it that can verify that the user who performed the action is a user registered in the group, along with data identifying the action taken on the content.
[0011] Then, the group history information recording system acquires the history information from the recording device by the history information verification device, and verifies the group signature by the group signature method from the data, group signature, and group public key included in the history information. As a result, the content user can verify from the history information whether the content was generated by the actions of legitimate users within a preset group.
[0012] In addition, the management device of the group history information recording system may further obtain the group signature of the history information corresponding to an illegal action on the content among the history information recorded in the recording device, and identify the user using the management private key by the group signature method. As a result, the group history information recording system can identify the legitimate users within the group that distributed the content generated by the illegal action.
[0013] Also, to solve the above problems, the history information registration device according to the present invention includes a management device that generates a group public key and a management private key, which are key information of the group signature method, and a personal private key corresponding to the user's identification number, a history information registration device that adds a group signature to the history information of the content and records it in the recording device, and a history information verification device that verifies the group signature included in the history information recorded in the recording device. The history information registration device in the group history information recording system is configured to include a key information acquisition unit, a signature generation unit, and a history information recording unit.
[0014] In such a configuration, the history information registration device acquires, as key information from the management device by the key information acquisition unit, the group public key, the management secret key, and the individual secret key corresponding to the user identification number. Then, the history information registration device generates, by the signature generation unit, a group signature in a group signature scheme for the data from the data specifying the action on the content, the group public key, and the individual secret key. Then, the history information registration device records, by the history information recording unit, the data, the group signature, and the group public key in the recording device as history information. As a result, the history information is added with a group signature that can verify that the user who performed the action is a user registered in the group together with the data specifying the action on the content. Note that the history information registration device can be operated by a program for causing a computer to function as each of the above-described units.
[0015] Also, in order to solve the above problems, a history information verification device according to the present invention is a history information verification device that verifies a group signature included in the history information recorded in the recording device by the history information registration device, and includes a history information acquisition unit and a signature verification unit.
[0016] In such a configuration, the history information verification device acquires the history information recorded in the recording device by the history information acquisition unit. Then, the history information verification device verifies the group signature by a group signature scheme from the data specifying the action on the content, the group signature, and the group public key included in the history information acquired by the history information acquisition unit by the signature verification unit. As a result, the content user can verify from the history information whether the content was generated by the action of a legitimate user within a preset group. Note that the history information verification device can be operated by a program for causing a computer to function as each of the above-described units.
Advantages of the Invention
[0017] According to the present invention, it is possible to verify whether content is generated by the actions of legitimate users within a preset group while protecting the privacy of users without revealing specifically which user generated it from the history information of the content.
Brief Description of the Drawings
[0018]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Modes for Carrying Out the Invention
[0019] Hereinafter, embodiments of the present invention will be described with reference to the drawings. [Outline of the Group Signature Method] First, with reference to FIG. 1, the outline of the group signature method used in the group history information recording system 100 (FIG. 2) of the present invention will be described. The group signature method is a signature method for verifying whether the creator of the signature is a member of the group. At this time, since it is possible to verify without revealing specifically which user generated it, it also has a privacy protection function.
[0020] In the group signature scheme, the group administrator issues a signature key to the signer, and the signer creates a signature (group signature) using the signature key. The verifier determines whether the signer is a member of the group by verifying the group signature using the group common public key (verification key). In the present invention, the method shown in the following reference, which is the basis of many current group signature schemes, will be described as an example. (Reference) J. Camenisch and M. Stadler, “Efficient group signature schemes for large groups,” Advances in Cryptology - CRYPTO'97, pp.410-424, 1997 Note that in the present invention, other group signature schemes such as a method using a key revocation list and a method having quantum computer-resistant security may be used. As shown in FIG. 1, the group signature scheme Σ used in the present invention is composed of four algorithms Σ1, Σ2, Σ3, and Σ4.
[0021] The Setup algorithm Σ1 is an algorithm that takes as input a security parameter λ and the maximum number n of users (members) in the group, and outputs a group public key gpk, a user's individual secret key isk, and an administrative secret key ask. This individual secret key isk generates a plurality of individual secret keys isk1, isk2,..., isk n depending on the maximum number n of users. Note that the individual secret key isk is generated corresponding to a serial number, and the serial number becomes the user identification number id. The security parameter λ is a numerical value (for example, key length) indicating the security level predetermined in the group history information recording system 100 (FIG. 2). The maximum number of users is the upper limit number of regular users constituting the group.
[0022] The Sign algorithm Σ2 is an algorithm that takes as input data m, a group public key gpk, and an individual secret key isk, and outputs a group signature σ. The Verify algorithm Σ3 is an algorithm that takes as input data m, a group public key gpk, and a group signature σ, and outputs a verification result. The Verify algorithm Σ3 outputs "1" as the verification result if the group signature σ is a correct signature for the data m, and "0" as the verification result if it is not a correct signature. The Open algorithm Σ4 is an algorithm that takes as input a group signature σ and an administrative secret key ask, and outputs the identification number id of the user who is the creator of the group signature σ and a certificate π indicating the same.
[0023] [Configuration of Group History Information Recording System] Next, with reference to FIG. 2, the configuration of the group history information recording system 100 according to an embodiment of the present invention will be described.
[0024] The group history information recording system 100 is a system in which a regular user RU registered in a group records the history information of content in a recording device on the network NT. Here, the group is a set of users who have the authority to edit the content that is the material. The group history information recording system 100 includes one management device 1, a plurality (n units) of history information registration devices 2 (21, 22,..., 2 n ), and one or more (here, one) history information verification devices 3, which are connected to the network NT.
[0025] The management device 1 is a device managed by the group administrator GA of the group history information recording system 100. The management device 1 generates a key for generating a group signature and distributes it to the history information registration devices 2. Further, the management device 1 has a function of determining whether the history information has been registered by a regular user.
[0026] The history information registration device 2 is a device managed by a regular user RU who performs actions such as creation and editing of content. The origin information registration device 2 records information for specifying an action on the content (claim information CL: FIG. 7) and a group signature (corresponding to the digital signature SI: FIG. 7) as origin information (manifest) MF. Note that the origin information also includes an assertion AS (FIG. 7), but since it has no direct relation to the present invention, it will be omitted in the following description. Also, here, the origin information MF is to be recorded on the blockchain BC as a recording device on the network NT. Since this blockchain BC is a general technology, the description thereof will be omitted.
[0027] The origin information verification device 3 is, for example, a device managed by the content user VW, and verifies the origin information MF recorded on the blockchain BC by means of a group signature method. The origin information verification device 3 can confirm the authenticity of the content corresponding to the origin information MF by verifying the signature (group signature) included in the origin information MF. Hereinafter, each device constituting the group origin information recording system 100 will be described.
[0028] 〔Configuration of the management device〕 First, with reference to FIG. 3, the configuration of the management device 1 will be described. The management device 1 includes a setup unit 10, a key information storage unit 11, a key information distribution unit 12, and an unauthorized user identification unit 13.
[0029] The setup unit 10 inputs a security parameter λ and the maximum number n of regular users, and generates a group public key gpk, individual secret keys isk (isk1, isk2,..., isk n ) and an administrative secret key ask. This setup unit 10 executes the Setup algorithm Σ1 in FIG. 1. The setup unit 10 stores the generated group public key gpk, individual secret keys isk (isk1, isk2,..., isk n ) and the administrative secret key ask in the key information storage unit 11. Note that the individual private keys isk1, isk2, …, isk n The subscripts correspond to the identification numbers of legitimate users. It is assumed that legitimate users are pre-associated with identification numbers.
[0030] The key information storage unit 11 stores the key information generated by the setup unit 10 and can be composed of a general storage medium such as a semiconductor memory. Here, the key information storage unit 11 stores the group public key gpk, the individual private keys isk (isk1, isk2, …, isk n ), and the management private key ask.
[0031] The key information distribution unit 12 distributes key information in response to a request from the history information registration device 2. The key information distribution unit 12 receives a key information request including the identification number id of a user (legitimate user) from the history information registration device 2. The key information distribution unit 12 reads out the individual private key isk corresponding to the identification number id included in the received key information request and the group public key gpk from the key information storage unit 11 and transmits them to the history information registration device 2 that is the source of the key information request.
[0032] The unauthorized user identification unit 13 identifies users among legitimate users who have performed unauthorized actions on the content. Unauthorized actions by legitimate users are actions that violate the predefined action rules for the content. For example, the specified resolution is not maintained when editing. The unauthorized user identification unit 13 obtains the group signature σ of the history information MF corresponding to the unauthorized action from the history information MF recorded on the blockchain BC for the content (unauthorized content) generated by the unauthorized action, and uses the management private key to identify the user who recorded this history information MF by the group signature method.
[0033] Here, the unauthorized user identification unit 13 generates the identification number id and the certificate π of the user who is the creator of the group signature σ from the acquired group signature σ and the management secret key ask stored in the key information storage unit 11 by the Open algorithm Σ4 (see FIG. 1). Here, the certificate π is not used. The unauthorized user identification unit 13 can identify the legitimate user corresponding to the unauthorized action based on the generated identification number id. As a result, the group administrator GA (FIG. 2) can take actions such as warning and canceling the membership (excluding from the group) against the legitimate user who has performed an unauthorized action on the content.
[0034] With the configuration described above, the management device 1 can distribute the key information for generating the group signature and identify the legitimate user who has distributed the unauthorized content. This management device 1 can be operated by a program for causing a computer (not shown) to function as each of the above-described units.
[0035] 〔Configuration of the history information registration device〕 Next, with reference to FIG. 4, the configuration of the history information registration device 2 will be described. The history information registration device 2 includes a key information acquisition unit 20, a key information storage unit 21, a signature generation unit 22, and a history information recording unit 23.
[0036] The key information acquisition unit 20 acquires the key information for generating the group signature from the management device 1. The key information acquisition unit 20 transmits a key information request including the identification number id of the user (legitimate user) to the management device 1. The key information acquisition unit 20 acquires the individual secret key isk corresponding to the identification number id and the group public key gpk from the management device 1. The key information acquisition unit 20 stores the acquired individual secret key isk and the group public key gpk in the key information storage unit 21.
[0037] The key information storage unit 21 stores the key information acquired by the key information acquisition unit 20, and can be configured with a general storage medium such as a semiconductor memory. Here, the key information storage unit 21 stores the personal secret key isk acquired by the key information acquisition unit 20 and the group public key gpk.
[0038] The signature generation unit 22 generates a signature for information (data m) that identifies an action on the content. The data m is information (claim information CL: Fig. 7) that identifies an action such as the username of the content creator, the production date and time, and the work content, i.e., who did what and when. The signature generation unit 22 generates a group signature σ from the data m, the personal secret key isk stored in the key information storage unit 21, and the group public key gpk by the Sign (signature) algorithm Σ2 (see Fig. 1). The signature generation unit 22 outputs the data m, the group signature σ, and the group public key gpk to the history information recording unit 23 as history information.
[0039] The history information recording unit 23 records the history information (data m, group signature σ, and group public key gpk) input from the signature generation unit 22 in a recording device (block chain BC) on the network. The history information recording unit 23 generates history information MF in which the data m, which is information identifying an action on the content, is written as claim information CL (Fig. 7), and the group signature σ and the group public key gpk are written in the area of the digital signature SI (Fig. 7), and records it on the block chain BC.
[0040] With the configuration described above, the history information registration device 2 can record the history information of the content on a recording device (block chain BC) on the network with a group signature, which is the signature of the regular user RU, added. This history information registration device 2 can be operated by a program for causing a computer (not shown) to function as each of the above-described units.
[0041] [Configuration of the History Information Verification Device] Next, with reference to FIG. 5, the configuration of the history information verification device 3 will be described. The history information verification device 3 includes a history information acquisition unit 30 and a signature verification unit 31.
[0042] The history information acquisition unit 30 acquires the history information MF recorded on the blockchain BC. Here, the history information acquisition unit 30 sequentially acquires the history information MF from the beginning of the blockchain BC corresponding to the content for which the user wants to confirm the history. The history information acquisition unit 30 outputs the data m, group signature σ, and group public key gpk included in the history information to the signature verification unit 31. The history information acquisition unit 30 acquires all the history information of the content from the beginning of the blockchain BC and outputs it to the signature verification unit 31.
[0043] The signature verification unit 31 verifies the group signature σ included in the history information acquired by the history information acquisition unit 30. The signature verification unit 31 calculates the verification result from the data m, group signature σ, and group public key gpk acquired by the history information acquisition unit 30 using the Verify (verification) algorithm Σ3 (see FIG. 1). When the group signature σ is verified to be a correct signature of the data m, the signature verification unit 31 outputs "1" as the verification result, and outputs "0" as the verification result if it is not a correct signature. The signature verification unit 31 verifies all the group signatures σ acquired by the history information acquisition unit 30.
[0044] With the configuration described above, the history information verification device 3 can confirm the reliability of the content. This history information verification device 3 can be operated by a program for causing a computer (not shown) to function as each of the above-described units.
[0045] [Operation of the Group History Information Recording System] Next, with reference to FIG. 6 (for the configuration, refer to FIGS. 2 to 5 as appropriate), the operation of the group history information recording system 100 according to the embodiment of the present invention will be described. Here, the operation of the group history information recording system 100 will be described by taking one history information registration device 2 managed by a certain regular user RU as an example. However, the same applies when there are multiple history information registration devices 2.
[0046] (Recording of history information) The group history information recording system 100 records history information by performing the following operations in steps S1 to S8. In step S1, the setup unit 10 of the management device 1 uses the Setup (setup) algorithm Σ1 (FIG. 1) to generate a group public key gpk, a user's individual secret key isk (isk1, isk2,..., isk n ) and an administrative secret key ask from the security parameter λ and the maximum number n of regular users. The setup unit 10 stores the generated group public key gpk, the individual secret key isk (isk1, isk2,..., isk n ) and the administrative secret key ask in the key information storage unit 11.
[0047] In step S2, the key information acquisition unit 20 of the history information registration device 2 transmits a key information request including the identification number id of the user (regular user) to the management device 1. In step S3, the key information distribution unit 12 of the management device 1 receives the key information request including the identification number id of the user transmitted from the history information registration device 2 in step S2. In step S4, the key information distribution unit 12 reads out the individual secret key isk corresponding to the identification number id included in the key information request received in step S3 and the group public key gpk from the key information storage unit 11 and transmits them to the history information registration device 2. In step S5, the key information acquisition unit 20 of the history information registration device 2 receives the individual secret key isk and the group public key gpk transmitted from the management device 1 in step S4. The key information acquisition unit 20 stores the received individual secret key isk and group public key gpk in the key information storage unit 21.
[0048] In step S6, the signature generation unit 22 inputs data m, which is information identifying an action on the content. In step S7, the signature generation unit 22 generates a group signature σ from the data m input in step S6, the personal secret key isk stored in the key information storage unit 21, and the group public key gpk by means of the Sign (signature) algorithm Σ2 (see FIG. 1). In step S8, the history information recording unit 23 records the data m input in step S6, the group signature σ generated in step S7, and the group public key gpk on the blockchain BC as history information MF. By the operations up to this point, the history information of the content can be recorded on the recording device (blockchain BC) on the network with a group signature, which is the signature of the legitimate user RU, added thereto.
[0049] (Identification of an illegal user) The group history information recording system 100 identifies the user who has committed an illegal act against the content by the operations of the following steps S9 to S10. In step S9, the illegal user identification unit 13 of the management device 1 acquires all the history information MF recorded on the blockchain BC for the content that is circulating as illegal content, verifies each data m, identifies the history information MF corresponding to the illegal action, and acquires the group signature σ thereof. In step S10, the illegal user identification unit 13 generates the identification number id of the user who is the creator of the group signature σ and the certificate π indicating the same from the group signature σ acquired in step S9 and the management secret key ask stored in the key information storage unit 11 by means of the Open algorithm Σ4 (see FIG. 1).
[0050] As a result, the group administrator GA (Fig. 2) can identify the regular user who has committed an irregularity against the content. Also, by verifying the group signature σ obtained in step S9 like the history information verification device 3, it is also possible to determine whether the user who has committed an irregularity against the content is a regular user or not. Also, in step S9, as part of identifying an illegal action, after the illegal user identification unit 13 has acquired all the history information MF regarding the illegal content, like the history information verification device 3, it verifies each group signature σ to determine the presence or absence of history information MF that is not from a regular user, and may identify that history information MF. And if there is history information MF that is not from a regular user, for example, it may preferentially verify whether the action is illegal, or may determine that it is an illegal action without verification. Note that these steps S9 to S10 may be performed at any timing when the group administrator recognizes the existence of illegal content.
[0051] (Verification of history information) The group history information recording system 100 verifies the history information by the operations of the following steps S11 to S12.
[0052] In step S11, the history information acquisition unit 30 of the history information verification device 3 acquires all the history information MF recorded on the blockchain BC regarding the content for which the reliability is to be confirmed. In step S12, the signature verification unit 31 verifies the group signature σ for each of the history information MF acquired in step S11 from the data m, the group signature σ, and the group public key gpk by the Verify (verification) algorithm Σ3 (see Fig. 1). As a result, the history information verification device 3 can confirm the reliability of the content. Note that these steps S11 to S12 may be performed at any timing such as when the content user attempts to use the content.
[0053] Although the embodiments of the present invention have been described above, the present invention is not limited to these embodiments, and also includes design changes and the like within the scope not departing from the gist of the present invention. For example, although the history information is recorded on the blockchain BC here, it may be recorded in a database on the cloud.
[0054] Also, although one history information verification device 3 is connected to the group history information recording system 100 here, this history information verification device 3 may be provided for each content user who wants to confirm the history information of the content, and a plurality of devices may be connected.
Explanation of Reference Numerals
[0055] 100 Group history information recording system 1 Management device 10 Setup unit 11 Key information storage unit 12 Key information distribution unit 13 Unauthorized user identification unit 2 History information registration device 20 Key information acquisition unit 21 Key information storage unit 22 Signature generation unit 23 History information recording unit 3 History information verification device 30 History information acquisition unit 31 Signature verification unit BC Blockchain (recording device) MF History information (manifest)
Claims
1. A group history information recording system for recording content history information in a recording device by a user registered in a group, comprising: A management device that generates a group public key and a management secret key, which are key information of a group signature method, and a personal secret key corresponding to the identification number of the user; A history information registration device that generates a group signature of the group signature method from data identifying an action on the content, the group public key, and the personal secret key, and records the data, the group signature, and the group public key in the recording device as the history information; A history information verification device that acquires the history information from the recording device and verifies the group signature by the group signature method from the data, the group signature, and the group public key included in the history information; A group history information recording system, characterized by comprising the above.
2. The management device further acquires a group signature of history information corresponding to an illegal action on content among the history information recorded in the recording device, and identifies the user using the management secret key by the group signature method. The group history information recording system according to claim 1.
3. In a group history information recording system comprising a management device that generates a group public key and a management secret key, which are key information of a group signature method, and a personal secret key corresponding to the identification number of a user, a history information registration device that adds a group signature to the content history information and records it in a recording device, and a history information verification device that verifies the group signature included in the history information recorded in the recording device, the history information registration device, A key information acquisition unit that acquires, as the key information, a group public key, a management secret key, and a personal secret key corresponding to the identification number of the user from the management device; A signature generation unit that generates a group signature of the group signature method for the data from the data identifying an action on the content, the group public key, and the personal secret key; A history information recording unit that records the data, the group signature, and the group public key in the recording device as the history information; A history information registration device, characterized by comprising the above.
4. A program for causing a computer to function as the history information registration device according to claim 3.
5. A history information verification device that verifies a group signature included in history information recorded in a recording device by the history information registration device according to claim 3, a history information acquisition unit that acquires history information recorded in the recording device; a signature verification unit that verifies the group signature by a group signature method from data for specifying an action on content included in the history information acquired by the history information acquisition unit, the group signature, and a group public key; A history information verification device, characterized by comprising the above.
6. A program for causing a computer to function as the history information verification device according to claim 5.