Electronic apparatus, method for controlling electronic apparatus, and program

The electronic device addresses the issue of unwanted metadata removal in image authenticity systems by generating and selecting metadata to ensure both unnecessary metadata removal and necessary metadata authenticity.

JP2025176363APending Publication Date: 2025-12-04CANON KK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024082458
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-05-21
Publication Date
2025-12-04

Smart Images

  • Figure 2025176363000001_ABST
    Figure 2025176363000001_ABST
Patent Text Reader

Abstract

To solve the problem in which: it may be difficult to achieve both removal of unnecessary meta data in an image and appropriate guarantee of the authenticity of necessary meta data.SOLUTION: An electronic apparatus has: generation means that can generate content including meta data; selection means that can select, from the meta data, an item to be included in history data; and means that generates, on the basis of the selected item, history data recording the meta data and a hash value when the content is generated.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to electronic devices. [Background technology]

[0002] In recent years, information sharing via the Internet has become so popular that anyone can publish and transmit a wide range of information to an unspecified number of people. Digital images can also be manipulated in various ways. In this environment, information may come from unreliable sources, or publicly available information may be fraudulently altered.

[0003] Conventionally, when a photograph is taken with a digital camera with an authenticity verification function enabled, a hash value is generated from the image and assigned to the image, and the user of the image can then use the hash value to verify whether the image has been tampered with (see Patent Document 1).

[0004] Furthermore, it has been proposed to add metadata indicating the editing content of an image to the image in order to authenticate the origin, history, and provenance of the image (see Non-Patent Document 1). [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2008-5421 [Non-patent literature]

[0006] [Non-Patent Document 1] Coalition for Content Provenance and Authenticity (C2PA), “C2PA Specifications”,<Technical Specifications Version 1.2> , [online], November 3, 2022, [Retrieved January 23, 2023], Internet<URL:https: / / c2pa.org / specifications / specifications / 1.2 / specs / C2PA_Specification.html> Summary of the Invention [Problem to be solved by the invention]

[0007] The resulting images may contain unwanted metadata that must be removed later during image editing.

[0008] However, when authenticity verification is enabled on a device such as that described in Patent Document 1, deleting metadata that you do not want to keep changes the hash value of the image, which can be inconvenient as it can be treated as tampering. [Means for solving the problem]

[0009] One aspect of the present invention is an electronic device that includes a generation means capable of generating content including metadata, a selection means capable of selecting items from the metadata to be included in history data, and a means for generating history data that records the metadata and hash value at the time the content was generated based on the selected items. [Effects of the Invention]

[0010] According to the present invention, it is possible to both prevent unnecessary metadata from remaining in an image and properly guarantee the authenticity of necessary metadata. [Brief explanation of the drawings]

[0011] [Figure 1]1A and 1B are external views of the imaging device according to the first embodiment; [Figure 2] 1 is a block diagram showing a configuration of an imaging apparatus according to a first embodiment. [Figure 3] 1A is a flowchart showing a setting process according to the first embodiment, and FIG. 1B is a flowchart showing a main process according to the first embodiment. [Figure 4] FIG. 4 is a flowchart showing a photographing process according to the first embodiment. [Figure 5] 5(a) to 5(e) are diagrams showing examples of screens displayed on the imaging device in the first embodiment. [Figure 6] 5A and 5B are diagrams showing an example of the configuration of an image file in the first embodiment. [Figure 7] FIG. 4 is a flowchart showing a playback process in the first embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0012] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS Hereinafter, embodiments of the present invention will be described in detail with reference to the accompanying drawings.

[0013] The embodiment described below is an example of a means for realizing the present invention, and may be appropriately modified or changed depending on the configuration of the device to which the present invention is applied and various conditions. In addition, each embodiment may be appropriately combined.

[0014] [First embodiment] Hereinafter, preferred embodiments of the present invention will be described with reference to the drawings.

[0015] <External view of digital camera 100> 1(a) and 1(b) show external views of a digital camera 100 (imaging device) as an example of a device to which the present invention can be applied. FIG. 1(a) is a front perspective view of the digital camera 100, and FIG. 1(b) is a rear perspective view of the digital camera 100. Note that, although a digital camera is described here as an example of an electronic device, the electronic device is not limited to this. For example, the electronic device may be an information processing device such as a portable media player, a so-called tablet device, a smartphone, or a personal computer.

[0016] The display unit 28 is a display unit provided on the back surface of the digital camera 100, and displays images and various information. The touch panel 70a can detect touch operations on the display surface (touch operation surface) of the display unit 28. The out-of-viewfinder display unit 43 is a display unit provided on the top surface of the digital camera 100, and displays various settings of the digital camera 100, including the shutter speed and aperture. The shutter button 61 is an operation member for issuing shooting instructions. The mode selector switch 60 is an operation member for switching between various modes. The terminal cover 40 is a cover that protects a connector (not shown) for connecting a connection cable or the like that connects the digital camera 100 to an external device.

[0017] The main electronic dial 71 is a rotary operation member, and by turning the main electronic dial 71, settings such as shutter speed and aperture can be changed. The power switch 72 is an operation member that switches the power of the digital camera 100 on and off. The sub electronic dial 73 is a rotary operation member, and by turning the sub electronic dial 73, the selection frame (cursor) can be moved, images can be forwarded, etc. The four-way key 74 is configured so that the up, down, left, and right parts can each be pressed, and processing can be performed according to the part of the four-way key 74 that is pressed. The SET button 75 is a push button, and is mainly used to confirm a selection item, etc.

[0018] The movie button 76 is used to start or stop movie shooting (recording). The AE lock button 77 is a push button that can fix the exposure state by pressing the AE lock button 77 in shooting standby mode. The enlarge button 78 is an operation button for switching the enlargement mode on and off in the live view display (LV display) of the shooting mode. By turning the enlargement mode on and operating the main electronic dial 71, the live view image (LV image) can be enlarged or reduced. In the playback mode, the enlargement button 78 functions as an operation button for enlarging the playback image or increasing its magnification. The playback button 79 is an operation button for switching between the shooting mode and the playback mode. Pressing the playback button 79 in the shooting mode switches to the playback mode, and the most recent image recorded on the recording medium 200 (described below) can be displayed on the display unit 28. The menu button 81 is a push button used to issue an instruction to display a menu screen. When the menu button 81 is pressed, a menu screen on which various settings can be made is displayed on the display unit 28. The user can intuitively make various settings using the menu screen displayed on the display unit 28, the four-way key 74, and the SET button 75.

[0019] The touch bar 82 (multifunction bar: M-Fn bar) is a line-shaped touch operation member (line touch sensor) that can receive touch operations. The touch bar 82 is positioned so that it can be touched (touched) with the thumb of the right hand when the grip unit 90 is held in the right hand (holding it with the little finger, ring finger, and middle finger of the right hand) so that the shutter button 61 can be pressed with the index finger of the right hand. In other words, the touch bar 82 is positioned so that it can be operated when the user places his / her eye on the eyepiece unit 16, looks through the viewfinder, and is in a position (shooting posture) so that the shutter button 61 can be pressed at any time. The touch bar 82 is a reception unit that can receive tap operations (operations in which the user touches and then releases the touch bar without moving within a predetermined period of time) and slide operations (operations in which the user touches and then moves the touched position while keeping the touch) on the touch bar 82. The touch bar 82 is an operation member that is different from the touch panel 70a and does not have a display function.

[0020] The communication terminal 10 is a communication terminal through which the digital camera 100 communicates with the lens unit 150 (described below; detachable). The eyepiece 16 is the eyepiece of the eyepiece finder 17 (a peer-type finder), and the user can view an image displayed on an internal EVF 29 (Electronic Viewfinder) through the eyepiece 16. The eyepiece detection unit 57 is an eyepiece detection sensor that detects whether the user (photographer) has placed their eye on the eyepiece 16. The cover 202 is a cover for a slot that stores a recording medium 200 (described below). The grip unit 90 is a holding unit shaped to be easily held in the user's right hand when holding the digital camera 100. The shutter button 61 and main electronic dial 71 are positioned so that they can be operated with the index finger of the right hand when the digital camera 100 is held by gripping the grip unit 90 with the little finger, ring finger, and middle finger of the right hand. In the same state, the sub electronic dial 73 and touch bar 82 are also arranged in positions that can be operated with the thumb of the right hand. The thumb rest 91 (thumb standby position) is a grip member provided on the rear side of the digital camera 100 in a position where it is easy to place the thumb of the right hand that is holding the grip 90 when none of the operation members are being operated. The thumb rest 91 is made of a rubber member or the like to increase the holding strength (grip feeling).

[0021] <Block diagram of the digital camera 100> FIG. 2 is a block diagram showing an example of the configuration of the digital camera 100. As shown in FIG.

[0022] The lens unit 150 is a lens unit equipped with an interchangeable photographic lens. The lens 103 is usually composed of multiple lenses, but for simplicity's sake, only a single lens is shown in FIG. 2. The communication terminal 6 is a communication terminal through which the lens unit 150 communicates with the digital camera 100, and the communication terminal 10 is a communication terminal through which the digital camera 100 communicates with the lens unit 150. The lens unit 150 communicates with the system control unit 50 via these communication terminals 6 and 10. The lens unit 150 controls the aperture 1 via the aperture drive circuit 2 using the internal lens system control circuit 4. The lens unit 150 also adjusts the focus by displacing the position of the lens 103 via the AF drive circuit 3 using the lens system control circuit 4.

[0023] The shutter 101 is a focal plane shutter that can freely control the exposure time of the imaging unit 22 under the control of the system control unit 50.

[0024] The imaging unit 22 is an imaging element (image sensor) configured with a CCD, CMOS element, or the like that converts an optical image into an electrical signal. The imaging unit 22 may have an imaging surface phase difference sensor that outputs defocus amount information to the system control unit 50. The A / D converter 23 converts the analog signal output from the imaging unit 22 into a digital signal.

[0025] The image processing unit 24 performs predetermined processing (pixel interpolation, resizing such as reduction, color conversion, etc.) on data from the A / D converter 23 or data from the memory control unit 15. The image processing unit 24 also performs predetermined arithmetic processing using the captured image data, and the system control unit 50 performs exposure control and distance measurement control based on the arithmetic results obtained by the image processing unit 24. This allows TTL (through-the-lens) type AF (autofocus) processing, AE (autoexposure) processing, EF (flash pre-flash) processing, etc. to be performed. The image processing unit 24 also performs predetermined arithmetic processing using the captured image data, and performs TTL type AWB (auto white balance) processing based on the arithmetic results obtained.

[0026] The output data from the A / D converter 23 is written to the memory 32 via the image processing unit 24 and the memory control unit 15. Alternatively, the output data from the A / D converter 23 is written to the memory 32 via the memory control unit 15 without going through the image processing unit 24. The memory 32 stores image data obtained by the imaging unit 22 and converted into digital data by the A / D converter 23, as well as image data to be displayed on the display unit 28 and the EVF 29. The memory 32 has a storage capacity sufficient to store a predetermined number of still images and a predetermined period of moving images and audio.

[0027] The memory 32 also serves as a memory (video memory) for image display. The D / A converter 19 converts the image display data stored in the memory 32 into an analog signal and supplies it to the display unit 28 or the EVF 29. In this way, the display image data written to the memory 32 is displayed on the display unit 28 or the EVF 29 via the D / A converter 19. The display unit 28 and the EVF 29 are each a display such as an LCD or an organic EL, and perform display according to the analog signal from the D / A converter 19. The digital signal that has been A / D converted by the A / D converter 23 and stored in the memory 32 is converted into an analog signal by the D / A converter 19, and the analog signal is sequentially transferred to and displayed on the display unit 28 or the EVF 29, thereby performing a live view display (LV). Hereinafter, an image displayed in live view display will be referred to as a live view image (LV image).

[0028] The system control unit 50 is a control unit made up of at least one processor and / or at least one circuit, and controls the entire digital camera 100. The system control unit 50 is both a processor and a circuit. The system control unit 50 executes programs recorded in nonvolatile memory 56 to realize each process of this embodiment, which will be described later. The system control unit 50 also performs display control by controlling the memory 32, D / A converter 19, display unit 28, EVF 29, etc.

[0029] The system memory 52 is, for example, a RAM, and the system control unit 50 loads constants and variables for the operation of the system control unit 50, programs read from the nonvolatile memory 56, and the like into the system memory 52.

[0030] The nonvolatile memory 56 is an electrically erasable and recordable memory, such as an EEPROM. Constants, programs, etc. for the operation of the system control unit 50 are recorded in the nonvolatile memory 56. The programs referred to here are programs for executing various flowcharts described later in this embodiment.

[0031] The system timer 53 is a timekeeping unit that measures the time used for various controls and the time of a built-in clock.

[0032] The communication unit 54 transmits and receives video signals and audio signals to and from external devices connected wirelessly or via a wired cable. The communication unit 54 can also connect to a wireless LAN (Local Area Network) or the Internet. The communication unit 54 can also communicate with external devices using Bluetooth (registered trademark) or Bluetooth Low Energy. The communication unit 54 can transmit images (including LV images) captured by the imaging unit 22 and images recorded on the recording medium 200, and can receive various information such as image data and a video recording start instruction from an external device. When a video recording start instruction is received from an external device, the communication unit 54 can notify the user that the instruction has been received by causing the light-emitting unit 102 to light up or sounding an electronic sound from the speaker 92. Examples of external devices that can communicate include smartphones, tablet PCs, and desktop PCs.

[0033] The orientation detection unit 55 detects the orientation of the digital camera 100 with respect to the direction of gravity. Based on the orientation detected by the orientation detection unit 55, it is possible to determine whether an image captured by the imaging unit 22 was captured with the digital camera 100 held horizontally or vertically. The system control unit 50 can add orientation information corresponding to the orientation detected by the orientation detection unit 55 to the image file of the image captured by the imaging unit 22, or rotate and record the image. An acceleration sensor, a gyro sensor, or the like can be used as the orientation detection unit 55. The acceleration sensor or gyro sensor of the orientation detection unit 55 can also be used to detect movement of the digital camera 100 (panning, tilting, lifting, whether the digital camera 100 is stationary, etc.).

[0034] The eyepiece detection unit 57 is an eyepiece detection sensor that detects (approach detection) whether an eye (object) approaches (approach) or moves away (away) from the eyepiece 16 of the eyepiece viewfinder 17 (hereinafter simply referred to as the "viewfinder"). The system control unit 50 switches the display unit 28 and the EVF 29 between on (display state) and off (non-display state) depending on the state detected by the eyepiece detection unit 57. More specifically, at least in a shooting standby state and when the display destination switching setting is automatic switching, when the eye is not in contact with the camera, the display is turned on with the display on the display unit 28 and the EVF 29 is hidden. When the eye is in contact with the camera, the display is turned on with the display on the EVF 29 and the display unit 28 is hidden. For example, an infrared proximity sensor can be used as the eyepiece detection unit 57, and it can detect the approach of an object to the eyepiece 16 of the viewfinder 17 that incorporates the EVF 29. When an object approaches, infrared light emitted from a light-emitting unit (not shown) of the eyepiece detection unit 57 is reflected by the object and received by a light-receiving unit (not shown) of the infrared proximity sensor. The amount of received infrared light can also determine the distance the object is approaching the eyepiece 16 (eyepiece distance). In this way, the eyepiece detection unit 57 performs eyepiece detection, which detects the proximity of an object to the eyepiece 16. When an object approaching within a predetermined distance from the eyepiece 16 is detected from a non-eyepiece state (non-approach state), it is detected as being in eye contact. When an object detected as approaching moves away from the eyepiece state (approach state) by more than a predetermined distance, it is detected as being away from the eye. The threshold for detecting eye contact and the threshold for detecting eye separation may be different, for example, by providing hysteresis. Furthermore, after eye contact is detected, the eyepiece remains in the eye contact state until eye separation is detected. After eye separation is detected, the eyepiece remains in the non-eye contact state until eye contact is detected. The infrared proximity sensor is just an example, and other sensors may be used for the eye proximity detector 57 as long as they can detect a state that can be considered as eye proximity.

[0035] The GPS receiver 119 receives GPS information from a GPS satellite for calculating location information and time information. The digital camera 100 receives the GPS information using the GPS receiver 119 and calculates location information and time information based on the received GPS information. The digital camera 100 can add this calculated location information and time information to captured images.

[0036] The hash value generation unit 210 generates (calculates) a hash value by executing a hash function on the image file. The hash value may be generated by the system control unit 50 instead of the hash value generation unit 210. The hash value generation process will be described in detail later.

[0037] Various camera settings such as shutter speed and aperture are displayed on the outside viewfinder display 43 via an outside viewfinder display drive circuit 44 .

[0038] The power supply control unit 80 is composed of a battery detection circuit, a DC-DC converter, a switch circuit for switching between powered blocks, etc., and detects whether a battery is installed, the type of battery, and the remaining battery power. The power supply control unit 80 also controls the DC-DC converter based on the detection results and instructions from the system control unit 50, and supplies the required voltage for the required period to each unit, including the recording medium 200. The power supply unit 30 is composed of primary batteries such as alkaline batteries or lithium batteries, secondary batteries such as NiCd batteries, NiMH batteries, or Li batteries, an AC adapter, etc.

[0039] The recording medium I / F 18 is an interface with a recording medium 200 such as a memory card or a hard disk. The recording medium 200 is a recording medium such as a memory card for recording captured images, and is composed of a semiconductor memory, a magnetic disk, or the like.

[0040] The operation unit 70 is an input unit that accepts operations from the user (user operations) and is used to input various operational instructions to the system control unit 50. As shown in Fig. 2, the operation unit 70 includes a shutter button 61, a mode selector switch 60, a power switch 72, a touch panel 70a, other operation members 70b, etc. The other operation members 70b include a main electronic dial 71, a sub electronic dial 73, a four-way key 74, a SET button 75, a video button 76, an AE lock button 77, a magnification button 78, a playback button 79, a menu button 81, a touch bar 82, etc.

[0041] The shutter button 61 includes a first shutter switch 62 and a second shutter switch 64. The first shutter switch 62 is turned on when the shutter button 61 is pressed halfway (a shooting preparation command) during operation, generating a first shutter switch signal SW1. The system control unit 50 starts shooting preparation operations such as AF (autofocus) processing, AE (auto exposure) processing, AWB (auto white balance) processing, and EF (pre-flash) processing in response to the first shutter switch signal SW1.

[0042] The second shutter switch 64 is turned on when the shutter button 61 is fully pressed (photographing instruction) and generates a second shutter switch signal SW2. The second shutter switch signal SW2 causes the system control unit 50 to start a series of photographing processing operations, from reading out a signal from the imaging unit 22 to writing the captured image to the recording medium 200 as an image file.

[0043] The mode selector switch 60 switches the operating mode of the system control unit 50 to one of still image capture mode, video capture mode, playback mode, etc. Modes included in the still image capture mode include auto capture mode, auto scene determination mode, manual mode, aperture priority mode (Av mode), shutter speed priority mode (Tv mode), and program AE mode (P mode). There are also various scene modes and custom modes that provide capture settings for specific capture scenes. The mode selector switch 60 allows the user to directly switch to one of these modes. Alternatively, after first switching to a list screen of capture modes with the mode selector switch 60, the user may selectively switch to one of the displayed modes using another operating member. Similarly, the video capture mode may also include multiple modes.

[0044] The touch panel 70a is a touch sensor that detects various touch operations on the display surface of the display unit 28 (the operation surface of the touch panel 70a). The touch panel 70a and the display unit 28 can be configured as an integrated unit. For example, the touch panel 70a is configured so that its light transmittance does not interfere with the display of the display unit 28, and is attached to the upper layer of the display surface of the display unit 28. Input coordinates on the touch panel 70a are associated with display coordinates on the display surface of the display unit 28. This makes it possible to provide a GUI (Graphical User Interface) that allows the user to directly operate the screen displayed on the display unit 28.

[0045] The system control unit 50 can detect the following operations or states on the touch panel 70a. A finger or pen that has not been touching the touch panel 70a touches the touch panel 70a again, that is, the start of touching (hereinafter referred to as Touch-Down). A state in which the touch panel 70a is touched with a finger or a pen (hereinafter referred to as Touch-On) A finger or pen is moved while touching the touch panel 70a (hereinafter referred to as Touch-Move). The finger or pen that has been touching the touch panel 70a is released from the touch panel 70a, that is, the end of touch (hereinafter referred to as "touch-up"). A state in which nothing is touching the touch panel 70a (hereinafter referred to as Touch-Off)

[0046] When a touch down is detected, a touch on is also detected at the same time. After a touch down, a touch on is usually continued to be detected unless a touch up is detected. If a touch move is detected, a touch on is also detected at the same time. Even if a touch on is detected, a touch move is not detected unless the touch position moves. Once it is detected that all fingers or pens that were touching have touched up, a touch off occurs.

[0047] These operation states and the position coordinates of the finger or pen touching the touch panel 70a are notified to the system control unit 50 via the internal bus. The system control unit 50 then determines what kind of operation (touch operation) was performed on the touch panel 70a based on the notified information. Regarding touch-move, the movement direction of the finger or pen moving on the touch panel 70a can also be determined for each vertical and horizontal component on the touch panel 70a based on changes in the position coordinates. If a touch-move of a predetermined distance or more is detected, it is determined that a slide operation has been performed. An operation in which a finger is touched on the touch panel 70a, moved quickly for a certain distance, and then released is called a flick. In other words, a flick is an operation in which a finger is quickly traced across the touch panel 70a as if flicking it. If a touch-move of a predetermined distance or more at a predetermined speed or more is detected and a touch-up is then detected, it is determined that a flick has been performed (it can be determined that a flick occurred following a slide operation). Furthermore, a touch operation in which multiple points (for example, two points) are touched together (multi-touch) and the touch positions are brought closer together is called a pinch in, and a touch operation in which the touch positions are moved farther apart is called a pinch out. Pinch out and pinch in are collectively called a pinch operation (or simply a pinch). The touch panel 70a may be of any of a variety of touch panel types, including resistive film type, capacitive type, surface acoustic wave type, infrared type, electromagnetic induction type, image recognition type, and optical sensor type. There are types that detect a touch by contact with the touch panel, and types that detect a touch by the approach of a finger or pen to the touch panel, and either type is acceptable.

[0048] 3(a) is a flowchart of the main processing in this embodiment. This is realized when the system control unit 50 loads a program stored in the non-volatile memory 56 into the system memory 52 and executes it in response to turning on the power switch 72.

[0049] First, in S001, the system control unit 50 determines whether or not the user has instructed the start of the setting process. The user can input an instruction to start the setting process by operating the operation unit 70 or operating a menu. If it is determined that the user has instructed the start of the setting process, the process proceeds to S002. In S002, the setting process is executed. The setting process will be described later. If it is not determined that the user has instructed the start of the setting process, the process proceeds to S003.

[0050] In S003, the system control unit 50 determines whether or not the user has instructed the system to start the image capture process. The user can input an image capture instruction by, for example, pressing the shutter button 61. If it is determined that the system control unit 50 has instructed the system to start the image capture process, the process proceeds to S004. In S004, the image capture process is executed. The image capture process will be described later. If it is not determined that the system control unit 50 has instructed the system to start the image capture process, the process proceeds to S005.

[0051] In S005, the system control unit 50 determines whether or not the user has instructed the start of playback processing. The user can input a playback instruction by, for example, pressing the playback button 79. If it is determined that the start of playback processing has been instructed, the process proceeds to S006. In S006, the playback processing is executed. The playback processing will be described later. If it is not determined that the user has instructed the start of playback processing, the process proceeds to S007.

[0052] In S007, the system control unit 50 determines whether an instruction to end the main process has been issued by the power switch 72 or the like. If an instruction to end the main process has been issued, the main process is terminated. If not, the process returns to S001.

[0053] Next, the setting process executed in step S002 in Fig. 3(a) will be described below, with Fig. 3(b) being a flowchart of the setting process.

[0054] In S301, the system control unit 50 determines whether a setting instruction to change the falsification prevention mode to ON has been issued. The user can input a setting instruction to change the falsification prevention mode to ON by operating the menu screen.

[0055] If a setting instruction to change the falsification prevention mode to ON has been given, the process proceeds to S302. If not (i.e., if a setting instruction to change the falsification prevention mode to OFF has been given), the process proceeds to S303. When the falsification prevention mode is ON, the history information 603 is included in the captured image. When the falsification prevention mode is OFF, the history information 603 is not included in the captured image. This history information is used to detect alterations to the image using the hash and signature value mechanisms described below.

[0056] In S302, the system control unit 50 changes the setting of the tamper-proof mode to ON and stores the setting in the memory 32. If the tamper-proof mode is already ON, the process is skipped.

[0057] In S303, the system control unit 50 changes the setting of the tamper-proof mode to OFF and stores the setting in the memory 32. If the tamper-proof mode is already OFF, the process is skipped.

[0058] In S304, the system control unit 50 determines whether a setting change instruction has been issued to determine whether location information data should be included in the provenance assurance target. If a setting change instruction has been issued to determine whether location information data should be included in the provenance assurance target, the process proceeds to S305; if not, the process proceeds to S306. The user can input a setting change instruction to determine whether location information data should be included in the provenance assurance target by operating the menu screen. An example of the menu screen at this time is shown in FIG. 5(a). The menu screen of FIG. 5(a) may be displayed in parallel with or after the processing of S302, for example, in response to determining in S301 that a setting instruction to turn on the tamper-proof mode has been input by operating the menu screen. Note that the example of FIG. 5(a) shows a state in which the location item (the item labeled GPS) is focused. The location item is displayed with a thicker frame than the other items, allowing the user to understand which item is focused on.

[0059] In the example of FIG. 5( a), in the initial state when the screen is displayed, the location, time, photographer, and other information, which will be described later, are all set to be included in the provenance assurance target. For example, the user can uncheck an item by selecting a checked checkbox. By checking or unchecking each displayed item, the user can include checked items in the provenance assurance target and exclude unchecked items from the provenance assurance target. In S304, when the GPS item in FIG. 5( a) is selected from an unchecked state to a checked state, the system control unit 50 determines that a setting change instruction has been issued to include location information data in the provenance assurance target. Also, when the GPS item is selected from a checked state to an unchecked state, the system control unit 50 determines that a setting change instruction has been issued to exclude location information data from the provenance assurance target. Similar user interfaces thereafter also accept check or uncheck operations as setting change instructions.

[0060] The location, time, and photographer information shown as examples are given because it is highly likely that the user would not want to disclose them to the public, but this is not limited to these. There is also the possibility that users may not want other users to know their settings, such as when they do not want their photography techniques to be known. Therefore, selectable data other than location, time, and photographer can also be used.

[0061] In S305, the system control unit 50 changes the setting of whether or not location information data is included in the history assurance target in accordance with the received operation, and stores the setting in the memory 32. Note that in this embodiment, since the setting is in the form of a check box, it is assumed that the on / off state is interchangeable, but the user may explicitly specify the on / off state.

[0062] In S306, the system control unit 50 determines whether an instruction to change the detailed settings of the location information data for which history is guaranteed has been issued. The user can input an instruction to change the detailed settings of the location information data for which history is guaranteed by operating the menu screen. In the example of FIG. 5(a), a "Details 1" button 501 is displayed. When the user selects this "Details 1" button 501 while focusing on a location item, the system control unit 50 determines that an instruction to change the detailed settings of the location information data for which history is guaranteed has been accepted. If an instruction to change the detailed settings of the location information data for which history is guaranteed has been issued, a screen such as that shown in FIG. 5(b) is displayed, and the process proceeds to S307 and subsequent steps. If an instruction to change the detailed settings of the location information data for which history is guaranteed has not been issued, the process proceeds to S322 without displaying the screen such as that shown in FIG. 5(b). FIG. 5(b) shows, as an example, that it is possible to set whether to include latitude, longitude, altitude, and UTC (Universal Time Coordinated), which will be described later, in the history target as location information.

[0063] In S307, the system control unit 50 determines whether or not a setting change instruction has been issued from the user viewing the screen of Fig. 5(b) to change whether or not latitude data is included in the location information for which history is guaranteed. If a setting change instruction has been issued to change whether or not latitude data is included in the location information for which history is guaranteed, the system control unit 50 proceeds to S308; if not, the system control unit 50 proceeds to S309.

[0064] In S308, the system control unit 50 changes the setting of whether or not to include latitude as location information data that guarantees history, and stores the setting in the memory 32. At this time, it is assumed that ON and OFF are switched, but the user may explicitly specify ON and OFF.

[0065] In S309, the system control unit 50 determines whether a setting change instruction has been issued to determine whether longitude data should be included as location information data for which history is guaranteed. If a setting change instruction has been issued to determine whether longitude data should be included as location information for which history is guaranteed, the system control unit 50 proceeds to S310; if not, the system control unit 50 proceeds to S311.

[0066] In S310, the system control unit 50 changes the setting as to whether or not longitude data is to be included as location information that guarantees the history, and stores the setting in the memory 32.

[0067] In S311, the system control unit 50 determines whether a setting change instruction has been issued to determine whether elevation data is to be included as location information for which history is guaranteed. If a setting change instruction has been issued to determine whether elevation data is to be included as location information for which history is guaranteed, the system control unit 50 proceeds to S312; if not, the system control unit 50 proceeds to S313.

[0068] In S312, the system control unit 50 changes the setting as to whether or not altitude data is included as location information that guarantees the history, and stores the setting in the memory 32.

[0069] In S313, the system control unit 50 determines whether a setting change instruction has been issued to determine whether UTC data is to be included as location information for which history is guaranteed. If a setting change instruction has been issued to determine whether UTC data is to be included as location information for which history is guaranteed, the system control unit 50 proceeds to S314; if not, the system control unit 50 proceeds to S315.

[0070] In S314, the system control unit 50 changes the setting as to whether or not UTC data is included as location information that guarantees the history, and stores the setting in the memory 32.

[0071] In S315, the system control unit 50 determines whether an instruction to change the detailed setting 2 related to the place information for which the history is guaranteed has been issued. The user can input an instruction to change the detailed setting 2 related to the place information for which the history is guaranteed by operating the menu screen. In the example of FIG. 5(b), a button 502 called "Details 2" is displayed, and when this button is selected, the system control unit 50 determines that an instruction to change the detailed setting 2 related to the place information for which the history is guaranteed has been accepted. If an instruction to change the detailed setting 2 related to the place information for which the history is guaranteed has been issued, the screen of FIG. 5(c) is displayed and the process proceeds to S316; if not, the process proceeds to S392. FIG. 5(c) presents an example in which whether or not to retain location information can be changed depending on the shooting area.

[0072] In S316, the system control unit 50 determines whether a setting change instruction has been issued to determine whether location information is to be subject to history assurance when the current location is Japan. If a setting change instruction has been issued to determine whether location information is to be subject to history assurance when the current location is Japan, the system control unit 50 proceeds to S317; if not, the system control unit 50 proceeds to S318.

[0073] In S317, the system control unit 50 changes the setting of whether or not to make location information subject to history assurance when the current location is Japan, and stores the setting in the memory 32. At this time, it is assumed that the setting is switched between on and off, but the user may explicitly specify on or off.

[0074] In S318, the system control unit 50 determines whether a setting change instruction has been issued as to whether location information is to be subject to history assurance when the current location is in the U.S. If a setting change instruction has been issued as to whether location information is to be subject to history assurance when the current location is in the U.S., the system control unit 50 proceeds to S319;

[0075] In S319, the system control unit 50 changes the setting as to whether or not to make the location information subject to history assurance when the current location is in the United States, and stores the setting in the memory 32.

[0076] In S320, the system control unit 50 determines whether a setting change instruction has been issued to determine whether location information is to be subject to history assurance when the current location is China. If a setting change instruction has been issued to determine whether location information is to be subject to history assurance when the current location is China, the system control unit 50 proceeds to S321; if not, the system control unit 50 proceeds to S391.

[0077] In S321, the system control unit 50 changes the setting as to whether or not location information is subject to history assurance when the current location is in China, and stores the setting in the memory 32.

[0078] In S391, the system control unit 50 determines whether an instruction to return from the location information detailed settings 2 screen (the screen in FIG. 5(c)) to the location information detailed settings 1 screen (the screen in FIG. 5(b)) has been accepted. The user can input an instruction to return from the location information detailed settings 2 screen to the location information detailed settings 1 screen by selecting the back button in FIG. 5(c). If it is determined that an instruction to return to the location information detailed settings 1 screen has not been accepted, the process returns to S316. If it is determined that an instruction to return to the location information detailed settings 1 screen has been accepted, the process proceeds to S392.

[0079] In S392, the system control unit 50 determines whether or not an instruction to return from the screen for detailed location information settings 1 (screen in FIG. 5(b)) to the screen for selecting a provenance assurance target (screen in FIG. 5(a)) has been accepted. The user can input an instruction to return from the screen for detailed location information settings 1 to the screen for selecting a provenance assurance target by selecting the back button in FIG. 5(b). If it is determined that an instruction to return to the screen for selecting a provenance assurance target has not been accepted, the process returns to S307. If it is determined that an instruction to return to the screen for selecting a provenance assurance target has been accepted, the process proceeds to S322.

[0080] In S322, the system control unit 50 determines whether a setting change instruction has been issued to determine whether time information data is included in the history assurance target. If a setting change instruction has been issued to determine whether time information data is included in the history assurance target, the system control unit 50 proceeds to S323; if not, the system control unit 50 proceeds to S331.

[0081] In S323, the system control unit 50 changes the setting as to whether or not time information data is included in the history assurance target, and stores the setting in the memory 32.

[0082] In S324, the system control unit 50 determines whether an instruction to change the detailed settings related to the time information data for which the provenance is guaranteed has been issued. The user can input an instruction to change the detailed settings related to the time information data for which the provenance is guaranteed by operating the menu screen. In the example of FIG. 5(a), a "Details 1" button 501 is displayed. When the user selects this "Details 1" button 501 while focusing on the time item (the item displayed as "ShootTime"), the system control unit 50 determines that an instruction to change the detailed settings related to the time information data for which the provenance is guaranteed has been accepted. If an instruction to change the detailed settings related to the time information data for which the provenance is guaranteed has been issued, the system control unit 50 displays the screen of FIG. 5(d) and proceeds to S325; if not, the system control unit 50 proceeds to S331.

[0083] In S325, the system control unit 50 determines whether a setting change instruction has been issued to determine whether year data should be included in the time information for which history is guaranteed. If a setting change instruction has been issued to determine whether year data should be included in the time information for which history is guaranteed, the system control unit 50 proceeds to S326; if not, the system control unit 50 proceeds to S327.

[0084] In S326, the system control unit 50 changes the setting of whether or not to include year data as time information that guarantees history, and stores the setting in the memory 32. At this time, it is assumed that on and off are alternated, but the user may explicitly specify on and off.

[0085] In S327, the system control unit 50 determines whether a setting change instruction has been issued to determine whether or not to include monthly data in the time information for which history is guaranteed. If a setting change instruction has been issued to determine whether or not to include monthly data in the time information for which history is guaranteed, the system control unit 50 proceeds to S328; if not, the system control unit 50 proceeds to S329.

[0086] In S328, the system control unit 50 changes the setting as to whether or not to include month data as time information that guarantees history, and stores the setting in the memory 32.

[0087] In S329, the system control unit 50 determines whether a setting change instruction has been issued to determine whether or not to include day data as time information for which history is guaranteed. If a setting change instruction has been issued to determine whether or not to include day data as time information for which history is guaranteed, the process proceeds to S330; if not, the process proceeds to S393.

[0088] In S330, the system control unit 50 changes the setting as to whether or not to include date data as time information that guarantees the history, and stores the setting in the memory 32.

[0089] In S393, the system control unit 50 determines whether an instruction to return to the screen for selecting a provenance assurance target (screen in FIG. 5(a)) from the screen for setting detailed time information (screen in FIG. 5(d)) has been accepted. The user can input an instruction to return from the screen for setting detailed time information to the screen for selecting a provenance assurance target by selecting the back button in FIG. 5(d). If it is determined that an instruction to return to the screen for selecting a provenance assurance target has not been accepted, the process returns to S325. If it is determined that an instruction to return to the screen for selecting a provenance assurance target has been accepted, the process proceeds to S331.

[0090] In S331, the system control unit 50 determines whether a setting change instruction has been issued to determine whether information related to the photographer is included in the history assurance target. If a setting change instruction has been issued to determine whether information related to the photographer is included in the history assurance target, the process proceeds to S332; if not, the process proceeds to S342.

[0091] In S332, the system control unit 50 changes the setting as to whether or not information related to the photographer is included in the history assurance target, and stores the setting in the memory 32.

[0092] In S333, the system control unit 50 determines whether an instruction to change the detailed settings related to the information related to the photographer whose provenance is guaranteed has been received. The user can input an instruction to change the detailed settings related to the information related to the photographer whose provenance is guaranteed by operating the menu screen. In the example of FIG. 5(a), a "Details 1" button 501 is displayed. When this "Details 1" button 501 is selected while the photographer's item (the item displayed as PhotoGrapher) is focused, the system control unit 50 determines that an instruction to change the detailed settings related to the information related to the photographer whose provenance is guaranteed has been received. If an instruction to change the detailed settings related to the information related to the photographer whose provenance is guaranteed has been received, the system control unit 50 displays the screen of FIG. 5(e) and proceeds to S334; if not, the system control unit 50 proceeds to S342.

[0093] In S334, the system control unit 50 determines whether a setting change instruction has been issued to determine whether or not to include photographer name data as information related to the photographer whose history is guaranteed. If a setting change instruction has been issued to determine whether or not to include photographer name data as information related to the photographer whose history is guaranteed, the process proceeds to S335; if not, the process proceeds to S336.

[0094] In S335, the system control unit 50 changes the setting of whether or not to include photographer name data as information related to the photographer whose history is guaranteed, and stores the setting in the memory 32. At this time, it is assumed that the setting is switched between on and off, but the user may also explicitly specify on or off.

[0095] In S336, the system control unit 50 determines whether a setting change instruction has been issued to determine whether or not to include data on the name of the copyright holder as information related to the photographer whose history is guaranteed. If a setting change instruction has been issued to determine whether or not to include data on the name of the copyright holder as information related to the photographer whose history is guaranteed, the process proceeds to S337; if not, the process proceeds to S338.

[0096] In S337, the system control unit 50 changes the setting as to whether or not to include data on the name of the copyright holder as information related to the photographer whose history is guaranteed, and stores the setting in the memory 32.

[0097] In S338, the system control unit 50 determines whether a setting change instruction has been issued to determine whether or not to include data on the camera owner's name as information related to the photographer whose history is guaranteed. If a setting change instruction has been issued to determine whether or not to include data on the camera owner's name as information related to the photographer whose history is guaranteed, the process proceeds to S339; if not, the process proceeds to S340.

[0098] In S339, the system control unit 50 changes the setting as to whether or not to include data on the camera owner's name as information related to the photographer whose history is guaranteed, and stores the setting in the memory 32.

[0099] In S340, the system control unit 50 determines whether a setting change instruction has been issued to determine whether or not to include data on the camera's individual number as information related to the photographer whose history is guaranteed. If a setting change instruction has been issued to determine whether or not to include data on the camera's individual number as information related to the photographer whose history is guaranteed, the process proceeds to S341; if not, the process proceeds to S394.

[0100] In S341, the system control unit 50 changes the setting as to whether or not to include data on the individual number of the camera as information related to the photographer whose history is guaranteed, and stores the setting in the memory 32.

[0101] In S394, the system control unit 50 determines whether an instruction to return to the screen for selecting a provenance assurance target (screen in FIG. 5(a)) from the screen for detailed settings of information related to the photographer (screen in FIG. 5(e)) has been accepted. The user can input an instruction to return from the screen for detailed settings of information related to the photographer to the screen for selecting a provenance assurance target by selecting the back button in FIG. 5(e). If it is determined that an instruction to return to the screen for selecting a provenance assurance target has not been accepted, the process returns to S334. If it is determined that an instruction to return to the screen for selecting a provenance assurance target has been accepted, the process proceeds to S342.

[0102] In S342, the system control unit 50 determines whether a setting change instruction has been issued to determine whether information other than the location, time, and photographer is included in the provenance assurance target. If a setting change instruction has been issued to determine whether information other than the location, time, and photographer is included in the provenance assurance target, the process proceeds to S343; if not, the process proceeds to S344.

[0103] In S343, the system control unit 50 changes the setting as to whether or not other information other than the location, time, and photographer is included in the history assurance target, and stores the setting in the memory 32.

[0104] In S344, the system control unit 50 determines whether an instruction to end the main process has been issued by, for example, the power switch 72. If an instruction to end the main process has been issued, the main process is terminated; if not, the process returns to S301.

[0105] In this way, the data to be included in the provenance guarantee, such as location, time, photographer, and other data, can be changed on the setting screens shown in (a) to (e) of Figure 5.

[0106] The processing up to this point completes the settings related to the history assurance target. It is assumed that this setting is completed before photographing and then the photographing process is executed. Next, the photographing process executed in step S004 of Fig. 3(a) will be described. Fig. 4 is a flowchart of the photographing process.

[0107] This flowchart also begins when a shooting start operation such as pressing the shutter button 61 is accepted.

[0108] First, in S401, the system control unit 50 drives the shutter 101 disposed on the subject side of the imaging unit 22 in order to control the exposure time.

[0109] In S402, the system control unit 50 performs imaging processing to convert light from a subject received by the imaging unit 22 via a shutter into an electrical signal (analog image data).

[0110] In S403, the system control unit 50 performs image processing such as development processing and encoding processing on the electrical signal obtained by the above-mentioned imaging processing, and generates image data.

[0111] In S404, the system control unit 50 generates metadata 601 including shooting information 602 of image data 604 as shown in Fig. 6(a). The shooting information 602 is information when the imaging process for generating the image data 604 is executed, such as the shooting date and time, the photographer, the image size, the manufacturer and model of the imaging device, various shooting parameters set at the time of shooting, the shooting location, a thumbnail image, etc. The shooting information 602 is generated in accordance with a predetermined technical standard (for example, EXIF ​​(Exchangeable Image File Format)).

[0112] In S405, the system control unit 50 determines whether the falsification prevention mode is set to ON. If it is determined that the falsification prevention mode is set to ON, the process proceeds to S406, and if it is determined that the falsification prevention mode is set to OFF, the process proceeds to S419.

[0113] In S406, the system control unit 50 determines whether location information is included in the settings for which provenance is guaranteed. The setting for whether location information is included in the settings for which provenance is guaranteed is determined by the processing in the flowchart of Fig. 3(b). If it is determined that location information is included in the settings for which provenance is guaranteed, the process proceeds to S407; if not, the process proceeds to S409 without executing the processing of S407 and S408.

[0114] In S407, the system control unit 50 includes location information 615 at the time of shooting as metadata in the history 613, which will be described later. At this time, the location information to be included in the metadata is the latitude, longitude, altitude, and UTC that have been checked, or the country or region that have been checked. Unchecked information is not included.

[0115] In S408, the system control unit 50 generates a hash value from the location information included in the shooting information 602, and includes the hash value 627 of the shooting location in the hash value 623.

[0116] The provenance information 603 is information for proving the authenticity of the image data 604, and is used to verify the origin and provenance of the image data 604. The provenance information 603 is generated in accordance with a predetermined technical standard (for example, C2PA (Corporate Identity and Authenticity)) and has a prescribed structure.

[0117] The history information 603 includes a history (Assertion) 613, and a hash value 623 and a digital signature 633 for verifying the history 613. The history 613 stores history identification information (Manifest ID) for uniquely identifying the history, an editing history indicating the editing content of the image data 604, an editing tool indicating the tool used for the editing, and the creator of the image data 604. Here, the image data 604 generated in step S403 has just been generated by shooting and has not been edited, so information indicating "generated" is stored in the editing history, and information indicating the imaging device is stored in the editing tool.

[0118] When location information is included in the provenance assurance target, the data on the shooting location included in the shooting information 602 can be verified using the hash value 627 of the shooting location. For verification, it is necessary to make it possible for the verifying device to determine which element each hash value included in the hash value 623 corresponds to. Therefore, for example, to enable each hash value to be recognized, it is assumed that the hash values ​​are given names that indicate that they are hash values ​​of the shooting date and time or the shooting location. When verifying, for example, if one wishes to verify the shooting date and time, one can simply compare the hash value calculated from the shooting date and time recorded in the metadata of the image data with the hash value 625 recorded in the image data to determine whether they match. If they do not match, it can be determined that some editing has been performed and the image is not original. The same applies to the hash values ​​of other elements.

[0119] In this case, if the shooting location is excluded from the history guarantee as shown in Figure 6(b), the shooting location 615 at the time of shooting is not included in the history 613, and the shooting location included in the shooting information 602 is not guaranteed by the shooting location hash value 627. Furthermore, since the history 613 in Figure 6(b) does not include location information, the hash value 626 of the history in Figure 6(a) and the hash value 626 of the history in Figure 6(b) will be different values.

[0120] By providing a separate hash value for each piece of metadata in this way, the authenticity of the date and time of the photo and the photographer can be guaranteed even if the location information is edited later.

[0121] In S409, the system control unit 50 determines whether the setting includes time information as a target for history assurance. If it is determined that the setting includes time information as a target for history assurance, the system control unit 50 proceeds to S410, and if not, the system control unit 50 proceeds to S412.

[0122] In S410, the system control unit 50 includes, as metadata, the shooting date and time 614 at the time of shooting in the history 613. The time information to be included at this time is the year, month, and day that have been checked in the pre-settings.

[0123] In S411, the system control unit 50 generates a hash value from the time information included in the shooting information 602, and includes it in the hash value 623 as a hash value 625 of the shooting date and time.

[0124] In S412, the system control unit 50 determines whether the settings include photographer information as a target of provenance assurance. If it is determined that the settings include photographer information as a target of provenance assurance, the process proceeds to S413; if not, the process proceeds to S415.

[0125] In S413, the system control unit 50 includes the photographer 616 at the time of shooting as metadata in the history 613. The photographer information to be included at this time is the photographer name, copyright holder name, camera owner name, and camera serial number, which are checked in advance in the settings.

[0126] In S414, the system control unit 50 generates a hash value from the photographer included in the photography information 602, and includes the hash value 623 as the photographer's hash value 628.

[0127] In S415, the system control unit 50 determines whether the setting includes information other than the location, time, and photographer as the subject of provenance assurance. If it is determined that the setting includes information other than the location, time, and photographer as the subject of provenance assurance, the process proceeds to S416; if not, the process proceeds to S418.

[0128] In S416, the system control unit 50 includes other information 617 other than the location, time, and photographer as metadata in the history 613. Note that the other information to be included at this time is expected to include ISO sensitivity, focal length, AF settings, WB settings, and the like.

[0129] In S417, the system control unit 50 generates metadata from information other than the shooting location, shooting date and time, and photographer included in the shooting information 602, and includes a hash value 629 of the other shooting information in the hash value 623.

[0130] In S418, the system control unit 50 generates a digital signature 633. The digital signature 633 includes information indicating the signature value, the signer, and the date and time of signing. The signature value is generated by encrypting the generated hash value 623 using a private key prepared in advance. The public key that pairs with the private key used here is also stored in the digital signature 633. Note that, at this time, to prove that the public key is from a trustworthy manufacturer, information indicating the manufacturer of the imaging device or a public key certificate indicating that the public key has been authenticated by a certification authority may be stored as the signer. By assigning the digital signature 633 including such a signer to the image file 600, it is possible to demonstrate that the image file is trustworthy. Note that, instead of the manufacturer, the model of the imaging device may be used as the signer. The date and time when the generation of the digital signature was completed is stored as the date and time of signing.

[0131] In S419, the system control unit 50 generates an image file by adding the shooting information 602 to the image data 604 as metadata 601, without including the history information 603. Here, if the image data 604 is a still image, the image file is generated in JPEG format, and if it is a moving image, the image file is generated in MPEG format.

[0132] In S420, the system control unit 50 assigns the shooting information 602 and the history information 603 to the image data 604 as metadata 601, and generates an image file. At this time, a hash function is applied to the necessary binary data of the image data 604 and the history 613 to generate a hash value 623. For the binary data of this history 613, hash values ​​may be generated for smaller units, such as editing history or production source, in order to detect tampering in smaller units. As in this embodiment, it is also possible to verify data in units specified by the user. Furthermore, the image file here is generated in JPEG format for still images and in MPEG format for videos.

[0133] In S420, the system control unit 50 determines whether an instruction to end the photographing process has been issued. If it is determined that an instruction to end the photographing process has been issued, the photographing process is terminated, and if not, the process proceeds to S421.

[0134] As described above, in this embodiment, when an imaging device captures an image, an image file is generated. Note that the image file may be edited by an app or the like. If the image file is edited using an authorized editing tool in a legitimate procedure, new history information 603 is generated based on the edit content in accordance with a predetermined technical standard, and is added to and stored as metadata for the image file. The history information 603 is generated anew every time an image file is edited, and is added to and stored as metadata 601 for the image file. On the other hand, if the image file is edited using an unauthorized editing tool or in an unauthorized procedure, the history information 603 may not be assigned to the image file, or the history information assigned to the image file may not conform to the predetermined technical standard.

[0135] Furthermore, by generating a hash value or a signature value, it is possible to detect tampering with an image file. For example, a hash function is applied to the binary data of image data 604 of an image file to generate a hash value. The generated hash value is then compared with the hash value 624 of the image data of the image file to be determined. This makes it possible to verify whether the image data has been tampered with. Similarly, a hash function is applied to the binary data of the shooting information 602 of the image file to generate a hash value. The generated hash value is then compared with each hash value of the shooting information of the image file to be determined. This makes it possible to verify whether the shooting date and time, shooting location, photographer, and other data have been tampered with. As shown in this embodiment, it is possible to ensure the provenance of only selected data, and this technology can be applied not only to imaging devices but also to editing applications installed on smartphones, personal computers, etc.

[0136] Furthermore, a hash function is applied to the binary data of the history 613 to generate a hash value. The generated hash value is then compared with the hash value 626 of the history of the image file being evaluated. This makes it possible to verify whether the history data has been tampered with. Note that the binary data compared at this time may be compared in smaller units such as editing history, production source, thumbnail data, or metadata. The signature value can also be decrypted using a public key, and if the hash values ​​match, it can be determined that the signature value has been successfully verified. In this way, a mechanism for detecting tampering can be incorporated into image files.

[0137] Next, the playback process executed in step S006 in Fig. 3(a) will be described with reference to Fig. 7, which is a flowchart of the playback process.

[0138] This flowchart starts when a playback start operation such as pressing the playback button 79 is accepted.

[0139] In S701, the system control unit 50 acquires image information of the selected content. The image information includes image data (original image / thumbnail) and metadata such as color gamut and gamma at the time of shooting.

[0140] In S702, the system control unit 50 displays the metadata of the selected content on the display unit .

[0141] In S703, the system control unit 50 determines whether the content was shot in tamper-proof mode. If it is determined that the content was shot in tamper-proof mode, the process proceeds to S704; if not, the process proceeds to S705. Here, the determination is made by checking whether the image file is in C2PA format. Alternatively, when generating an image, information indicating that the image was generated in tamper-proof mode may be recorded in the EXIF ​​maker note, and the determination may be made by referring to that information.

[0142] In S704, the system control unit 50 displays the provenance information of the selected content on the display unit 28. At this time, it is assumed that the information to be displayed is data with provenance guarantee, and if there is data that the user has excluded from the scope of provenance guarantee, information indicating that data is not displayed. Alternatively, even if the data is displayed, it may be displayed in a manner that is distinguishable from information that is guaranteed, so as to indicate that the data is not subject to provenance guarantee.

[0143] In S705, the system control unit 50 determines whether an instruction to end the playback process has been issued. If it is determined that an instruction to end the playback process has been issued, the playback process is terminated, and if not, the process proceeds to S705.

[0144] As described above, in this embodiment, when the imaging device performs the playback process, the image file is played back, and it becomes possible to check which data has a history guaranteed.

[0145] (Other embodiments) The present invention can also be realized by executing the following process. That is, software (program) that realizes the functions of the above-described embodiments is supplied to a system or device via a network or various storage media, and the computer (or CPU, MPU, etc.) of the system or device reads and executes the program code. In this case, the program and the storage medium storing the program constitute the present invention. The present invention can also be realized by a circuit (e.g., ASIC) that realizes one or more functions.

[0146] (Disclosure of the Present Specification) The disclosure of the present specification includes the following image processing device, image processing method, system, and program.

[0147] (Item 1) a generating means capable of generating content including metadata; a selection means for selecting items to be included in the provenance data from among the metadata; The electronic device has a means for generating provenance data based on the selected item, the provenance data recording metadata and a hash value of when the content was generated.

[0148] (Item 2) 2. The electronic device according to item 1, wherein a digital signature is generated from the generated hash value and recorded in the provenance data.

[0149] (Item 3) 2. The electronic device according to item 1, wherein the metadata selectable by the selection means includes time information.

[0150] (Item 4) 4. The electronic device according to item 3, wherein the time information selectable by the selection means includes year, month, and day.

[0151] (Item 5) 2. The electronic device according to item 1, wherein the metadata selectable by the selection means includes location information.

[0152] (Item 6) 6. The electronic device according to item 5, wherein the location information selectable by the selection means includes latitude, longitude, altitude, and UTC.

[0153] (Item 7) 6. The electronic device according to item 5, wherein the location information selectable by the selection means includes information about a region.

[0154] (Item 8) 2. The electronic device according to item 1, wherein the metadata selectable by the selection means includes information for identifying the photographer.

[0155] (Item 9) The electronic device described in item 8, characterized in that the information for identifying the photographer that can be selected by the selection means includes the photographer's name, the copyright holder's name, the owner's name of the electronic device, or the individual number of the electronic device.

[0156] (Item 10) The electronic device described in item 1 is characterized in that the selection means is capable of selecting all information from the metadata assigned to an image, except for location information, time information, and information identifying the photographer.

[0157] (Item 11) The electronic device according to item 1, characterized in that the items in which the metadata and hash value at the time of content generation are recorded in the history data can be confirmed on the screen where the content is played back.

[0158] (Item 12) 2. The electronic device according to item 1, wherein all items are targets for inclusion in the history data until an item is selected by the selection means.

[0159] (Item 13) a generating step capable of generating content including metadata; a selection step in which items of the metadata can be selected to be included in the provenance data; and generating, based on the selected item, provenance data that records metadata and a hash value at the time the content was generated.

[0160] (Item 14) A computer-readable program for causing a computer to function as each of the means of the electronic device described in any one of items 1 to 12.

Claims

1. a generating means capable of generating content including metadata; a selection means for selecting items to be included in the provenance data from among the metadata; The electronic device has a means for generating provenance data based on the selected item, the provenance data recording metadata and a hash value of when the content was generated.

2. 2. The electronic device according to claim 1, wherein a digital signature is generated from the generated hash value and recorded in the history data.

3. 2. The electronic device according to claim 1, wherein the metadata selectable by said selection means includes time information.

4. 4. The electronic device according to claim 3, wherein the time information selectable by said selection means includes year, month, and day.

5. 2. The electronic device of claim 1, wherein the metadata selectable by the selection means includes location information.

6. 6. The electronic device according to claim 5, wherein the location information selectable by said selection means includes latitude, longitude, altitude, and UTC.

7. 6. The electronic device according to claim 5, wherein the location information selectable by the selection means includes information about a region.

8. 2. The electronic device according to claim 1, wherein the metadata selectable by said selection means includes information for identifying a photographer.

9. 9. The electronic device according to claim 8, wherein the information for identifying the photographer selectable by the selection means includes any one of the photographer's name, the copyright holder's name, the owner's name of the electronic device, and the individual number of the electronic device.

10. 2. The electronic device according to claim 1, wherein the selection means is capable of selecting all information from among the metadata attached to an image, except for location information, time information, and information identifying the photographer.

11. 2. The electronic device according to claim 1, wherein the metadata and hash values ​​at the time of content generation recorded in the history data can be confirmed on a screen where the content is played back.

12. 2. The electronic device according to claim 1, wherein all items are targets for inclusion in the history data until an item is selected by said selection means.

13. a generating step capable of generating content including metadata; a selection step in which items of the metadata can be selected to be included in the provenance data; and generating, based on the selected item, provenance data that records metadata and a hash value at the time the content was generated.

14. A computer-readable program for causing a computer to function as each of the means of the electronic device according to any one of claims 1 to 12.

Citation Information

Patent Citations

  • Digital camera and image handling system

    JP2008005421A