Electronic device, method for controlling electronic device, and storage medium
The electronic device addresses the issue of file size growth by dynamically resizing areas in a predetermined mode to ensure authenticity verification, even with post-capture data additions, thus maintaining efficient file management and verification.
Patent Information
- Application Number
- JP2024103936
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-06-27
- Publication Date
- 2026-01-16
AI Technical Summary
Existing digital image verification systems fail to prevent unnecessary file size increases when data is added to areas excluded from authenticity verification after image capture, leading to erroneous tamper detection and inefficient file management.
An electronic device with a predetermined mode that determines if data will be added to a reserved area post-generation, and if so, enlarges that area to accommodate the data, ensuring authenticity verification without unnecessary file size growth.
Prevents unnecessary file size increases while maintaining authenticity verification by dynamically resizing areas in digital files to accommodate post-generation data additions.
Smart Images

Figure 2026005521000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an electronic device, a control method for an electronic device, and a program. [Background technology]
[0002] In recent years, information sharing via the Internet and social networking sites has become more active, allowing anyone to view and disseminate information. Meanwhile, advances in digital image processing technology have made it increasingly difficult for viewers to verify the authenticity of the content they view, exacerbating issues such as fake news. This has led to a growing demand for mechanisms to verify that digital images have not been altered or tampered with, i.e., to prove their authenticity. One such mechanism involves hashing a portion of an image file to obtain a hash value, encrypting the hash value using an individual encryption key to generate a digital signature, and then attaching the digital signature to the image file. This makes it possible to verify that a portion of the image file has not been altered or tampered with, i.e., to prove the authenticity of the image file. Recently, imaging devices equipped with an authenticity verification mode that can capture images using the above technology have also emerged. In the following description, "after capture" refers to the period after the image file is generated by capturing the image.
[0003] In the above technology, the authenticity of an image file is verified via a hash value. Therefore, if an area in the image file is provided where data can be changed after photography, a possible countermeasure is to prevent that area from being hashed. However, if the data change after photography is not a data replacement but an addition of data, the position of the hashed area may be shifted by adding data to the non-hashed area. Furthermore, if the position of the hashed area is shifted in this way, the digital image may be erroneously determined to have been processed or tampered with.
[0004] Therefore, if an area in an image file is provided where data can be added after shooting, reserving a blank area where data can be added after shooting when generating the image file is considered as a solution to the above-mentioned erroneous determination. A related technique is, for example, the imaging device described in Patent Document 1. The imaging device described in Patent Document 1 reserves a blank area where data can be added after shooting in the header area of the image file depending on the shooting mode. In other words, when the shooting mode is set to a predetermined mode, the imaging device described in Patent Document 1 reserves a blank area in the image file when generating the image file by shooting in the predetermined mode. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] Japanese Patent Publication No. 2020-167624 Summary of the Invention [Problem to be solved by the invention]
[0006] However, even if the shooting mode is set to a predetermined mode, it is not guaranteed that data will be added to the blank area of the image file generated by shooting in the predetermined mode after shooting. Therefore, even if a blank area is secured in response to setting the shooting mode to a predetermined mode, if data is not added to the blank area after shooting, there is a problem in that the size of the image file will be unnecessarily large by the amount of the blank area.
[0007] The present invention has been made in view of the above-mentioned problems, and aims to provide an electronic device, a control method for an electronic device, and a program that can prevent unnecessary increases in the size of digital files whose authenticity can be verified even if the data is modified after generation. [Means for solving the problem]
[0008] In order to achieve the above-mentioned object, the electronic device of the present invention is an electronic device having a predetermined mode in which a digital file whose authenticity can be proven is generated, and is characterized by comprising: a first determination means for determining whether the electronic device is set to the predetermined mode; a second determination means for determining whether a predetermined area among the areas constituting the digital file that is excluded from the target of authenticity proof is set to have data added to it after the digital file is generated; and a generation means for generating the digital file by enlarging the size of the predetermined area when the electronic device is set to the predetermined mode and it is set to have data added to the predetermined area after the digital file is generated, compared to when the electronic device is set to a mode different from the predetermined mode. [Effects of the Invention]
[0009] According to the present invention, it is possible to prevent unnecessary increases in size of digital files whose authenticity can be verified even if data is changed after generation. [Brief explanation of the drawings]
[0010] [Figure 1] FIG. 1 is a diagram showing the appearance of a digital camera. [Figure 2] FIG. 1 is a block diagram showing an example of the configuration of a digital camera. [Figure 3] FIG. 2 is a diagram showing the internal structure of an image file. [Figure 4] 10A and 10B are diagrams illustrating a procedure for authenticating an image file generated by photographing in the authenticity certification photographing mode. [Figure 5] This figure shows part of the procedure for proving the authenticity of an image file when the size of an XMP area that was excluded from the target of authenticity certification is expanded after the image file is generated and additional data is written to it. [Figure 6] 10 is a flowchart showing each process from photographing in an authenticity proof photographing mode or the like to generating an image file. [Figure 7]FIG. 10 is a diagram showing an example of a setting screen relating to an authenticity proof photography mode. DETAILED DESCRIPTION OF THE INVENTION
[0011] Preferred embodiments of the present invention will be described in detail below with reference to the drawings. However, the configurations described in the present embodiments are merely examples of means for realizing the present invention, and the scope of the present invention is not limited by the configurations described in the present embodiments. For example, each component constituting the present invention may be replaced with any configuration that can perform the same function. Any components may also be added. Any two or more configurations (features) of the present embodiments may also be combined. The present embodiments may also be modified or changed as appropriate depending on the configuration and various conditions of the device to which the present invention is applied. Note that in each drawing, the same components are designated by the same reference numerals, and their description may be omitted. In the present embodiments, a digital camera will be described as the electronic device of the present invention.
[0012] FIG. 1 shows the external appearance of a digital camera 100. FIG. 1(a) is a front perspective view of the digital camera 100, and FIG. 1(b) is a rear perspective view of the digital camera 100. The display unit 28 is a display unit provided on the rear of the digital camera 100 and displays images and various information. The touch panel 70a can detect touch operations on the display surface (touch operation surface) of the display unit 28. The outside-finder display unit 43 is a display unit provided on the top surface of the digital camera 100 and displays various settings of the digital camera 100, including shutter speed and aperture. The shutter button 61 is a button for issuing shooting instructions. The mode selector switch 60 is a switch for switching between various modes.
[0013] The terminal cover 40 is a cover that protects a connector (not shown) into which a connection cable or the like is inserted for connecting an external device to the digital camera 100. The main electronic dial 71 is a rotary operation member that can be turned to change settings such as shutter speed and aperture. The power switch 72 is a switch that turns the power of the digital camera 100 on and off. The sub electronic dial 73 is a rotary operation member that can be turned to move the selection frame or advance through images. The cross key 74 is a cross key (four-way key) that can be pressed up, down, left, and right, and is an operation member that can perform processing according to the part of the cross key 74 that is pressed.
[0014] The SET button 75 is a push button and is an operating member mainly used to confirm a selection, etc. The LV button 76 is an operating member that switches live view (hereinafter referred to as "LV") on and off in the menu button. The LV button 76 is used to start and stop video shooting (recording) in video shooting mode. The enlarge button 77 is an operating member that switches enlargement mode on and off and changes the magnification ratio in enlargement mode in live view display in shooting mode. The enlarge button 77 also functions as an enlargement button that enlarges a playback image or increases its magnification ratio in playback mode. The reduce button 78 is an operating member that decreases the magnification ratio of an enlarged playback image or reduces the displayed image. The playback button 79 is an operating member that switches between shooting mode and playback mode. Pressing the playback button 79 in shooting mode switches from shooting mode to playback mode, and the most recent image recorded on a recording medium (200 in FIG. 2, described below) can be displayed on the display unit 28.
[0015] The quick-return mirror 12 is raised and lowered by an actuator (not shown) in response to an instruction from a system control unit (50 in FIG. 2, which will be described later) during exposure and other operations. The communication terminal 10 is a communication terminal that enables the digital camera 100 to communicate with the lens unit (150 in FIG. 2, which will be described later: detachable). The eyepiece finder 16 is a peer-type finder that allows the user to check the focus and composition of the optical image of the subject captured through the lens unit (150 in FIG. 2, which will be described later) by observing the focusing screen (13 in FIG. 2, which will be described later). The lid 202 is a lid for a slot that stores a recording medium (200 in FIG. 2, which will be described later). The grip unit 90 is a holding unit shaped to be easily held in the user's right hand when holding the digital camera 100.
[0016] FIG. 2 is a block diagram showing an example of the configuration of a digital camera 100. The lens unit 150 is a lens unit equipped with an interchangeable photographic lens. The lens 103 is usually composed of multiple lenses, but FIG. 2 shows only one lens for simplicity's sake. The communication terminal 6 is a communication terminal through which the lens unit 150 communicates with the digital camera 100, and the communication terminal 10 is a communication terminal through which the digital camera 100 communicates with the lens unit 150. The lens unit 150 communicates with the system controller 50 via these communication terminals 6 and 10. As a result, in the lens unit 150, the lens system control circuit 4 controls the aperture 1 via the aperture drive circuit 2 and adjusts the focus by displacing the position of the lens 103 via the AF drive circuit 3.
[0017] The AE sensor 17 measures the brightness of the subject through the lens unit 150. The focus detection unit 11 outputs defocus amount information to the system control unit 50. The system control unit 50 controls the lens unit 150 based on the defocus amount information to perform phase-difference AF. The quick-return mirror 12 (hereinafter referred to as "mirror 12") is raised and lowered by an actuator (not shown) in response to instructions from the system control unit 50 during exposure, live view shooting, and video shooting. The mirror 12 switches the light beam incident from the lens 103 between the eyepiece viewfinder 16 side and the imaging unit 22 side. The mirror 12 is normally positioned to reflect the light beam and guide it to the eyepiece viewfinder 16. The mirror 12 is a half mirror that allows part of the light beam to pass through its center, transmitting that part of the light beam to enter the focus detection unit 11 for focus detection. Furthermore, when photographing or live view display is performed, the mirror 12 flips up and retreats from the light beam so as to guide the light beam to the imaging unit 22 (mirror up).
[0018] By observing the focusing screen 13 through the pentaprism 14 and the eyepiece viewfinder 16, the user can check the focus and composition of the optical image of the subject captured through the lens unit 150. The shutter 101 is a focal plane shutter that can freely control the exposure time of the imaging unit 22 under the control of the system control unit 50. The imaging unit 22 is an imaging element (image sensor) composed of a CCD, CMOS element, or the like that converts the optical image into an electrical signal. The A / D converter 23 converts the analog signal output from the imaging unit 22 into a digital signal.
[0019] The image processing unit 24 performs predetermined processing (pixel interpolation, resizing such as reduction, color conversion, etc.) on the data from the A / D converter 23 or the data from the memory control unit 15. The image processing unit 24 also performs predetermined arithmetic processing using the captured image data. The system control unit 50 performs exposure control and distance measurement control based on the arithmetic results obtained by the image processing unit 24. This allows for TTL (through-the-lens) AF (autofocus) processing, AE (autoexposure) processing, EF (flash pre-flash) processing, etc. to be performed. Furthermore, the image processing unit 24 performs predetermined arithmetic processing using the captured image data, and performs TTL AWB (auto white balance) processing based on the arithmetic results obtained.
[0020] The output data from the A / D converter 23 is written to the memory 32 via the image processing unit 24 and the memory control unit 15. Alternatively, the output data from the A / D converter 23 is written to the memory 32 via the memory control unit 15 without passing through the image processing unit 24. Image data obtained by the imaging unit 22 and converted into digital data by the A / D converter 23 is written to the memory 32. The memory 32 has a capacity sufficient to record a predetermined number of still images and a predetermined period of moving images and audio. The memory 32 also serves as a memory for image display (video memory). The D / A converter 19 converts the image display data written to the memory 32 into an analog signal and supplies it to the display unit 28. In this way, the image display data written to the memory 32 is displayed on the display unit 28 via the D / A converter 19.
[0021] The display unit 28 displays an image on a display device such as an LCD or organic EL display in response to the analog signal from the D / A converter 19. The memory control unit 15 converts the digital signal, which has been A / D converted by the A / D converter 23 and stored in the memory 32, to analog in the D / A converter 19 and sequentially transfers and displays the converted image to the display unit 28, thereby providing a through-image display (live view display). This allows the display unit 28 to function as an electronic viewfinder. Hereinafter, an image displayed in live view display will be referred to as an LV image. Under the control of the system control unit 50, the in-finder LCD display unit 41 displays, via an in-finder display drive circuit 42, a frame indicating the focus point for which autofocus is currently being performed (AF frame), icons indicating the settings of the digital camera 100, and the like. The out-of-finder display unit 43 displays, via an out-of-finder display drive circuit 44, various settings of the digital camera 100, such as shutter speed and aperture.
[0022] The nonvolatile memory 56 is an electrically erasable and recordable memory, such as an EEPROM. The nonvolatile memory 56 stores constants and programs for the operation of the system control unit 50. The programs are programs for executing the flowcharts described below. The system control unit 50 is a control unit consisting of at least one processor and / or at least one circuit, and controls the entire digital camera 100. The system control unit 50 executes the programs stored in the nonvolatile memory 56 to perform the various processes described below. The system memory 52 is, for example, a RAM. The system control unit 50 loads constants and variables for the operation of the system control unit 50, programs read from the nonvolatile memory 56, and other data into the system memory 52. The system control unit 50 also controls the memory 32, the D / A converter 19, the display unit 28, and other components to perform display control. The system timer 53 is a timing unit that measures the time used for various controls and the time of a built-in clock.
[0023] The mode selector switch 60, first shutter switch 62, second shutter switch 64, and operation unit 70 are operating means for inputting various operational instructions to the system control unit 50. The mode selector switch 60 switches the operation mode of the system control unit 50 between still image recording mode, video shooting mode, playback mode, etc. Modes included in the still image recording mode include auto shooting mode, auto scene determination mode, manual mode, aperture priority mode (Av mode), shutter speed priority mode (Tv mode), and program AE mode. Other modes include various scene modes that provide shooting settings for specific shooting scenes, custom mode, and the authentication shooting mode described below. The user can directly switch to one of these modes using the mode selector switch 60. Alternatively, the user may first switch to a list screen of shooting modes using the mode selector switch 60, and then selectively switch to one of the displayed modes using other operating members. Similarly, the video shooting mode may also include multiple modes.
[0024] The shutter button 61 has a first shutter switch 62 and a second shutter switch 64. The first shutter switch 62 is turned ON when the shutter button 61 is pressed halfway (a shooting preparation command) and generates a first shutter switch signal SW1. The system control unit 50 starts shooting preparation operations such as AF (autofocus) processing, AE (auto exposure) processing, AWB (auto white balance) processing, and EF (pre-flash) processing in response to the first shutter switch signal SW1. The second shutter switch 64 is turned ON when the shutter button 61 is pressed fully (a shooting command) and generates a second shutter switch signal SW2. The system control unit 50 starts a series of shooting processing operations in response to the second shutter switch signal SW2, from reading out a signal from the imaging unit 22 to recording the captured image data as an image file on the recording medium 200.
[0025] The operation members of the operation unit 70 are assigned appropriate functions for each situation by the user selecting and operating various function icons displayed on the display unit 28, and function as various function buttons. Examples of the function buttons include an end button, a back button, an image forward button, a jump button, a filter button, and an attribute change button. For example, when the menu button is pressed, a menu screen allowing various settings is displayed on the display unit 28. The user can intuitively perform various settings using the menu screen displayed on the display unit 28, a cross key 74 (a four-way key for up, down, left, and right), and a SET button 75. The operation unit 70 includes various operation members as an input unit that accepts operations from the user. The operation unit 70 includes push buttons, a rotary dial, a touch sensor, and the like. The operation unit 70 includes at least a touch panel 70a, a main electronic dial 71, a sub electronic dial 73, a cross key 74, a SET button 75, a LV button 76, a zoom in button 77, a zoom out button 78, and a playback button 79.
[0026] The power supply control unit 80 is composed of a battery detection circuit, a DC-DC converter, a switch circuit for switching between powered blocks, and other components, and detects whether a battery is installed, the type of battery, and the remaining battery charge. The power supply control unit 80 also controls the DC-DC converter based on the detection results and instructions from the system control unit 50, and supplies the required voltage for the required period to each component, including the recording medium 200. The power supply unit 30 is composed of primary batteries such as alkaline batteries or lithium batteries, secondary batteries such as NiCd batteries, NiMH batteries, or lithium-ion batteries, an AC adapter, etc. The recording medium I / F 18 is an interface with the recording medium 200, such as a memory card or hard disk. The recording medium 200 is a recording medium, such as a memory card, for recording images captured by the imaging unit 22, and is composed of a semiconductor memory, a magnetic disk, etc.
[0027] The communication unit 54 transmits and receives video signals and audio signals to and from external devices connected wirelessly or via a wired cable. The communication unit 54 can also be connected to a wireless LAN (Local Area Network) or the Internet. The communication unit 54 can also communicate with external devices via Bluetooth (registered trademark) or Bluetooth Low Energy. The communication unit 54 can transmit images (including LV images) captured by the imaging unit 22 and images recorded on the recording medium 200, and can also receive images and various other information from external devices.
[0028] The orientation detection unit 55 detects the orientation of the digital camera 100 with respect to the direction of gravity. Based on the orientation detected by the orientation detection unit 55, the system control unit 50 can determine whether an image captured by the imaging unit 22 was captured with the digital camera 100 held horizontally or vertically. The system control unit 50 can add orientation information corresponding to the orientation detected by the orientation detection unit 55 to an image file generated when the imaging unit 22 captures an image, or rotate and record the image. The orientation detection unit 55 can use an acceleration sensor, a gyro sensor, or the like. The system control unit 50 can also detect movement of the digital camera 100 (panning, tilting, lifting, whether the digital camera 100 is stationary, etc.) using the acceleration sensor or gyro sensor of the orientation detection unit 55.
[0029] Next, with reference to Figs. 3 to 5, the process of generating an image file (digital file) generated by shooting in the authentication proof shooting mode (predetermined mode), the mechanism for authenticity certification, etc. will be described. Fig. 3 is a diagram showing the internal structure of an image file. Note that in this embodiment, an image file in EXIF format is generated, but this is not limiting, and image files in other formats may also be generated. Fig. 3(a) is a diagram showing the internal structure of an image file generated by shooting in normal shooting mode. 301 is an image file. 302 is a metadata area. The metadata area 302 stores parameters such as setting values at the time of shooting, which are information processed and exchanged between various application software.
[0030] Reference numeral 303 denotes a JPG thumbnail area. The JPG thumbnail area 303 stores thumbnail image data for display that is a reduced version of the main image. Reference numeral 304 denotes an XMP area. The XMP area 304 is an area provided for data storage, separate from the metadata area 302. The XMP area 304 stores information that is not stored in the metadata area 302 and that is processed and exchanged between various application software. Reference numeral 305 denotes a main image data area. The main image data area 305 stores main image data obtained by shooting.
[0031] FIG. 3(b) is a diagram showing the process of generating an image file generated by shooting in the authenticity certification mode. FIG. 3(c) is a diagram showing the internal structure of an image file generated by shooting in the authenticity certification mode. In FIG. 3(b), 306 indicates an area that is the target of authentication certification (hereinafter referred to as an "authenticity certification target area") extracted from the image file 301 and combined (hereinafter referred to as an "authenticity certification target area combination"). In the digital camera 100, a plurality of authenticity certification target areas are predetermined from the areas that make up the image file 301, and the start address and size of each predetermined area are recorded in the image file 301. This allows the system control unit 50 to extract all authenticity certification target areas from the image file 301 and identify the authenticity certification target area combination 306.
[0032] In this embodiment, it is assumed that data in the XMP area 304 is allowed to be changed after shooting in the authentication certification shooting mode. Therefore, the XMP area 304 is an area (predetermined area) that is excluded from the target of authenticity certification. For this reason, the XMP area 304 does not exist in the authenticity certification target area combination 306. Note that the above-described data change in the XMP area 304 is realized by the CPU of a personal computer (hereinafter referred to as "PC") or the like executing application software or the like.
[0033] The system control unit 50 hashes the entire authentication certification target area combination 306 to obtain a hash value 307. The system control unit 50 further encrypts the hash value 307 using a predetermined encryption method to generate a digital signature, and inserts the authentication certification data 308 with the digital signature at a predetermined position in the image file 301. As a result, when an image is captured in the authentication certification photography mode, an image file 309 such as that shown in FIG. 3(c) is generated. Note that the predetermined position is a predetermined position in an area suitable for storing the authentication certification data 308 in a format suitable for storing it in the image file 309.
[0034] Figure 4 is a diagram showing the procedure for authenticating the authenticity of an image file 309 generated by capturing an image in the authenticity certification mode. In the following explanation, it is assumed that the procedure for authenticating the authenticity of the image file 309 shown in Figure 4 is realized by a CPU of a PC or the like executing application software. The CPU extracts the authenticity certification data 308 from the image file 309, and further decrypts the digital signature added to the authenticity certification data 308 using a predetermined decryption means to obtain a hash value 401.
[0035] The CPU also obtains the addresses and sizes of all authenticity certification target areas in the image file 309 from the authenticity certification data 308, and identifies the authenticity certification target area combination 306 based on the obtained addresses and sizes. The CPU then hashes the entire authenticity certification target area combination 306 to obtain a hash value 402. The CPU then compares the thus obtained hash value 401 with the hash value 402. If the hash value 401 and the hash value 402 match, it is proven that no data changes have been made to all of the authenticity certification target areas that make up the authenticity certification target area combination 306 since the image file 309 was generated.
[0036] The following describes, with reference to FIG. 5, how to authenticate an image file in a case where data is added to an XMP area that was excluded from the scope of authentication due to the assumption that data changes will occur and the size of the area is expanded after the image file is generated. FIG. 5 illustrates a portion of the procedure for authenticating an image file in this case. The procedure for authenticating an image file, part of which is illustrated in FIG. 5, is also realized by a CPU of a PC or the like executing application software or the like. Reference numeral 501 denotes an image file. The image file 501 has the same internal structure as the image file 309 generated by capturing an image in the authentication capture mode. Reference numeral 502 denotes an XMP area to which data has been added and whose size has been expanded after the image file 501 has been generated. Therefore, the size of the XMP area 502 is larger than when the image file 501 was generated. Here, the CPU obtains the addresses and sizes (hereinafter referred to as "location information") of all areas in the image file 501 that are subject to authentication from the authentication data 308.
[0037] However, the location information acquired from the authentication data 308 is the location information at the time of generation of the image file 501, i.e., the location information before the size of the XMP area 502 was expanded. Therefore, the authentication certification target area combination 503 identified by the location information acquired from the authentication data 308 includes, in the area indicated by 504, authentication data 308 that is not subject to authentication (i.e., subject to hashing). Therefore, even if the CPU hashes the entire authentication certification target area combination 503 to obtain a hash value 505, the hash value 505 does not match the hash value 401, and therefore the authenticity of the image file 501 cannot be verified. In other words, even if data is added to an area excluded from the target of authentication verification after the image file is generated, if the size is expanded and data is added to the area, the position of the area subject to hashing performed when authenticity verification is verified will be shifted, and authenticity cannot be maintained.
[0038] Therefore, when generating an image file 501, it is conceivable to always expand the size of the XMP area 502 that is not subject to authentication verification and reserve the additional area for adding data. However, data is not necessarily added to the XMP area 502 that is not subject to authentication verification after the image file 501 is generated. Therefore, if the size of the XMP area 502 that is not subject to authentication verification is always expanded, and data is not added to the XMP area 502, the image file 501 will include unnecessary area, resulting in a needless increase in the size of the image file 501. The present invention was made in consideration of such situations, and efficiently generates image files by expanding the size of an area that is not subject to authentication verification in advance only when data is expected to be added to that area.
[0039] FIG. 6 is a flowchart showing each process from capturing an image in the authentication capture mode or the like to generating an image file. Each process (control method for an electronic device) shown in the flowchart of FIG. 6 is realized by the system control unit 50 (computer) loading a program recorded in the nonvolatile memory 56 into the memory 32 and executing it. The flowchart of FIG. 6 starts when the system control unit 50 receives a capture start operation, such as a user pressing the shutter button 61. In step S601, the system control unit 50 drives the shutter 101 to control the exposure time. In step S602, the system control unit 50 performs an imaging process in which light from the subject received by the imaging unit 22 is converted into an electrical signal. In step S603, the system control unit 50 performs image processing, such as developing and encoding, on the data obtained by the above imaging process. This generates main image data and thumbnail image data.
[0040] In step S604, the system control unit 50 (first determination means) determines whether the digital camera 100 is set to the authenticity certification photography mode using the setting value related to the authenticity certification photography mode read from the nonvolatile memory 56 (first determination step). If the system control unit 50 determines that the digital camera 100 is set to the authenticity certification photography mode, the process proceeds to step S605. On the other hand, if the system control unit 50 determines that the digital camera 100 is not set to the authenticity certification photography mode, the process proceeds to step S611, which will be described later.
[0041] In step S605, the system control unit 50 (second determination means) reads the setting values related to the additional writing of data from the nonvolatile memory 56, and determines whether or not an area where additional data is scheduled to be written has been set, using the read setting values (second determination step). If the system control unit 50 determines that an area where additional data is scheduled to be written (hereinafter referred to as "area where additional data is scheduled to be written") has been set, the process proceeds to step S606. On the other hand, if the system control unit 50 determines that an area where additional data is scheduled to be written has not been set, the process proceeds to step S608, which will be described later.
[0042] In step S606, the system control unit 50 (third determination means) reads out the setting values related to the additional writing of data from the non-volatile memory 56, and determines whether or not to enlarge the area where additional data is to be written using the read setting values. If the system control unit 50 determines that the area where additional data is to be written should be enlarged, the process proceeds to step S607. If the system control unit 50 determines that the area where additional data is to be written should not be enlarged, the process proceeds to step S608, which will be described later. Note that, as will be described later, step S606 may be omitted in some cases. In step S607, the system control unit 50 enlarges the area where additional data is to be written. At this time, the system control unit 50 enlarges the size of the area where additional data is to be written compared to when the digital camera 100 is set in the normal shooting mode (a mode different from the predetermined mode), thereby securing an area for additional data.
[0043] In step S608, the system control unit 50 generates metadata including attribute information (such as photographer, shooting time, shooting location, model of digital camera 100, and settings at the time of shooting) used when the image capture process was performed to generate the image. However, the system control unit 50 generates the metadata to be stored in the data append area in a size smaller than the size of the area enlarged in step S607. In step S609, the system control unit 50 hashes the metadata generated in step S608 (excluding that stored in the data append area) and the main image data and thumbnail image data generated in step S603 to obtain a hash value. In step S610, the system control unit 50 encrypts the hash value obtained in step S609 using a private key prepared in advance to generate a digital signature. In step S611, the system control unit 50 generates metadata including the above attribute information.
[0044] In step S612, the system control unit 50 (generation means) generates an image file using the data processed and generated in steps S601 to S611 (generation step). When the digital camera 100 is set to the authentication proof photography mode, the system control unit 50 generates a digital image that allows authentication. At this time, the system control unit 50 may generate a digital image that allows authentication to be performed in accordance with the C2PA standard, or may generate a digital image that allows authentication to be performed using a procedure other than the C2PA standard. C2PA is an abbreviation for Coalition for Content Provenance and Authenticity. Furthermore, in step S612, the system control unit 50 records the generated image file on the recording medium 200. Thereafter, the flowchart of FIG. 6 ends.
[0045] 7(a) and 7(b) are diagrams showing examples of setting screens (hereinafter abbreviated as "setting screens") related to the authentication certification photography mode. The setting screens (UI screens) in FIGS. 7(a) and 7(b) are displayed on the display unit 28 by the system control unit 50. On the setting screen in FIG. 7(a), reference numeral 701 denotes an option that the user uses via the touch panel 70a to set whether or not to set the digital camera 100 to the authentication certification photography mode. When the user sets option 701 to "ON," the system control unit 50 records in the nonvolatile memory 56 a setting value indicating that the digital camera 100 is set to the authentication certification photography mode. Therefore, in this case, the system control unit 50 determines in step S604 that the digital camera 100 is set to the authentication certification photography mode. On the other hand, when the user sets option 701 to "OFF," the system control unit 50 records in the nonvolatile memory 56 a setting value indicating that the digital camera 100 is set to a mode other than the authentication certification photography mode (for example, a normal photography mode). Therefore, in this case, the system control unit 50 determines in step S604 that the digital camera 100 is not set to the authentication proof photography mode.
[0046] Reference numeral 702 denotes an option that the user can use via the touch panel 70a to set whether or not data is to be added to the XMP area of an image file generated by capturing an image in the authentication capture mode after the image file is generated. If the user sets option 702 to "Yes," the system control unit 50 (addition setting means) records a setting value indicating that data is to be added in the nonvolatile memory 56. Note that when the setting screen of FIG. 7(a) is displayed on the display unit 28, the XMP area is the only area in which the data addition area can be set in step S605. Therefore, in this case, the system control unit 50 determines in step S605 that a data addition area has been set. In contrast, if the user sets option 702 to "No," the system control unit 50 records a setting value indicating that no data addition area has been set in the nonvolatile memory 56. Therefore, in this case, the system control unit 50 determines in step S605 that a data addition area has not been set. As described above, in this embodiment, the area where data is to be added refers to an area that constitutes an image file generated by capturing an image in the authenticity proof capture mode, and where data is to be added after the image file is generated.
[0047] When option 702 is set to "Yes," the user sets, via the touch panel 70a, whether to enlarge the size of the XMP area of the image file generated by shooting in the authenticity-certified photography mode. When the user sets option 703 to "Yes," the system control unit 50 (enlargement setting means) records in the non-volatile memory 56 a setting value indicating that the size of the XMP area of the image file generated by shooting in the authenticity-certified photography mode is to be enlarged. Therefore, in this case, the system control unit 50 determines in step S606 to enlarge the area where data is to be added. Furthermore, in step S607, the system control unit 50 enlarges the size of the area where data is to be added, i.e., the size of the XMP area of the image file generated by shooting in the authenticity-certified photography mode, to a size greater than when the digital camera 100 is set to the normal photography mode.
[0048] On the other hand, if the user sets option 703 to "No," the system control unit 50 records in the non-volatile memory 56 a setting value indicating that the size of the XMP area of the image file generated by shooting in the authenticity proof shooting mode will not be enlarged. In this case, the system control unit 50 determines in step S606 that the area where data will be added will not be enlarged, and does not perform the processing of step S607. Therefore, the size of the area where data will be added, i.e., the size of the XMP area of the image file generated by shooting in the authenticity proof shooting mode, is the same as the size when the digital camera 100 is set to the normal shooting mode.
[0049] As described above, when option 701 is set to "On" and options 702 and 703 are set to "Yes," the system control unit 50 generates the image file 309 by enlarging the size of the XMP area 304 compared to when the digital camera 100 is set to normal shooting mode. In other words, the system control unit 50 references the user's settings on the setting screen of FIG. 7(a), and only when additional data is expected to be written to the XMP area 304 after the image file 309 is generated, the system control unit 50 enlarges the size of the XMP area 304 to ensure an area for additional data. This allows efficient generation of the image file 309 when shooting in the authenticity verification shooting mode. In this way, the digital camera 100 can prevent unnecessary size increases for image files 309 whose authenticity can be verified even if data is changed after generation.
[0050] If the image file 309 is generated so that its authenticity can be verified in accordance with the C2PA standard, data can be added to the image file 309 after it has been generated in accordance with the C2PA standard. Also, the size of an image file that does not comply with the C2PA standard, such as the image file 301 generated by shooting in normal shooting mode, does not increase unnecessarily.
[0051] Also, as described above, when option 703 is set to "No," the size of the XMP area 304 of the image file 309 generated when shooting in the authentication shooting mode is the same as the size when the digital camera 100 is set to the normal shooting mode. Therefore, if the user plans to replace the XMP area 304 of the generated image file 309 with data that does not require enlargement, the user can set option 703 to "No." On the other hand, if the user does not plan to replace the XMP area 304 of the generated image file 309 with data that does not require enlargement, option 703 and step S606 may be omitted.
[0052] Furthermore, if multiple data append areas can be set in a single image file generated by capturing an image in the authentication-certified capture mode, the system control unit 50 displays, for example, a setting screen such as that shown in FIG. 7B on the display unit 28. On the setting screen shown in FIG. 7B, the user can check or uncheck each checkbox in the checklist 704 by inputting via the touch panel 70a. When the setting screen shown in FIG. 7B is displayed on the display unit 28, the APP1 EXIF area and the XMP area are provided as areas in which data append areas can be set. Note that an area in which data append areas can be set is an area in an image file generated by capturing an image in the authentication-certified capture mode in which data changes are permitted after the image file is generated. Therefore, in the following description, an area in which data append areas can be set is referred to as a "data change-permitted area." Note that a data change-permitted area is also an area that is excluded from the target of authentication certification.
[0053] In each check box in checklist 704, the user can individually set data addition corresponding to option 702 and area expansion corresponding to option 703 for the APP1 EXIF area and XMP area. As a result, the system control unit 50 (addition setting means) records in nonvolatile memory 56 setting values related to the schedule for adding data and area size expansion for both the APP1 EXIF area and the XMP area, depending on whether or not the check box in checklist 704 is checked.
[0054] The system control unit 50 also stores information that identifies the check items in the checklist 704 as metadata in the image file generated by capturing an image in the authentication capture mode. This information allows a CPU, such as a PC running application software for modifying data in the image file, to determine which areas are planned for additional data recording and which areas have been expanded in size. This allows the data recording process to be performed appropriately.
[0055] The user may set at least one of the three options 701, 702, and 703 on the setting screen of Fig. 7(a) using any of the operation members (excluding the touch panel 70a) included in the operation unit 70. Similarly, the user may set at least one of the four check boxes in the checklist 704 on the setting screen of Fig. 7(b) using any of the operation members (excluding the touch panel 70a) included in the operation unit 70.
[0056] While the preferred embodiment of the present invention has been described above, the present invention is not limited to the above embodiment and various modifications and variations are possible within the spirit and scope of the present invention. For example, when the user selects "Yes" for option 703 on the setting screen of FIG. 7(a), the user may be able to set the size of the XMP area. In this case, the size of the XMP area may be set in units of KB or using options such as large, medium, and small. The size of the area after enlargement may be set, or the size of the enlarged area may be set. Furthermore, the system control unit 50 (second size setting means) further records a value indicating the size set by the user in the nonvolatile memory 56 for an XMP area for which a setting value indicating enlargement of the size is recorded in the nonvolatile memory 56.
[0057] If option 703 is omitted, the user may be allowed to set the size of the XMP area when the user selects "Yes" for option 702. In this case, the system control unit 50 (first size setting means) further records a value indicating the size set by the user in the non-volatile memory 56 for the XMP area in which a setting value indicating that data is to be added is recorded in the non-volatile memory 56. This allows the user to appropriately set the size of the XMP area where data is to be added. Therefore, when data is added to an image file generated by capturing an image in the authentication capture mode, it is possible to prevent cases where the size of the expanded XMP area is insufficient or where the size of the XMP area is larger than the amount of data added. This also applies to the setting screen in FIG. 7(b).
[0058] Furthermore, the system control unit 50 (display means) may display an image file viewing screen on the display unit 28, and may display information on the viewing screen that allows the user to identify whether the size of the data change permission area has been expanded. This allows the user to identify which image files, among the image files generated by shooting, have had the size of the data change permission area expanded and are capable of additional data writing.
[0059] Also, although different from the present embodiment, when an image file is generated in a format other than the EXIF format, depending on the format, all of the areas subject to authentication verification may be located before the areas excluded from the target of authentication verification. In this case, even if the size of the areas excluded from the target of authentication verification is enlarged, the positions of all of the areas subject to authentication verification, that is, the positions of the areas subject to hashing performed during authentication, will not be shifted. Therefore, in this case, the area size enlargement performed in step S606 may not be performed.
[0060] Furthermore, the electronic device of the present invention is not limited to the digital camera 100 described in this embodiment. The present invention is applicable to electronic devices that generate digital files whose authenticity can be verified. In addition to digital cameras, such electronic devices include, for example, PCs, PDAs, tablet devices, smartphones, mobile phones, digital photo frames, music players, game consoles, and e-book readers. Furthermore, the digital files whose authenticity can be verified are not limited to the image files described in this embodiment, but may be any digital content files (e.g., PDF files, etc.).
[0061] The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or device via a network or a recording medium, and having one or more processors in the computer of the system or device read and execute the program. The present invention can also be realized by a circuit (e.g., ASIC) that realizes one or more functions.
[0062] The disclosure of this embodiment includes the following configuration, method, and program. (Configuration 1) An electronic device having a predetermined mode in which a digital file whose authenticity can be verified is generated, a first determination means for determining whether the electronic device is set to the predetermined mode; a second determination means for determining whether a predetermined area of the digital file that is not subject to authentication verification is set to have data added thereto after the digital file is generated; and a generation means for generating the digital file by enlarging the size of the specified area when the electronic device is set to the specified mode and when it is set that data will be added to the specified area after the digital file is generated, compared to when the electronic device is set to a mode different from the specified mode. (Configuration 2) The electronic device according to configuration 1, further comprising an additional writing setting means for setting, in response to a user's input, whether additional data is scheduled to be written to the predetermined area after the digital file is generated. (Configuration 3) The electronic device described in Configuration 2 is characterized in that, when the digital file has multiple specified areas, the append setting means sets, in accordance with user input for each of the multiple specified areas, whether data is scheduled to be appended after the digital file is generated. (Configuration 4) The electronic device described in configuration 2 or 3 is characterized in that it comprises a first size setting means for setting the size of the specified area, which has been set by the append setting means as an area where data is scheduled to be appended after the digital file is generated, in accordance with user input. (Configuration 5) The electronic device according to configuration 4, wherein at least one of the additional writing setting means and the first size setting means acquires a user input from a UI screen. (Configuration 6) A third determination means is provided to determine whether the size of the predetermined area is set to be enlarged, The electronic device described in configuration 1 is characterized in that, when the electronic device is set to the specified mode and it is set that data will be added to the specified area after the digital file is generated, and it is also set that the size of the specified area is to be expanded, the generation means generates the digital file by expanding the size of the specified area more than when the electronic device is set to a mode different from the specified mode. (Configuration 7) The electronic device according to configuration 6, further comprising an additional writing setting means for setting, in response to a user's input, whether or not additional data is scheduled to be written to the predetermined area after the digital file is generated. (Configuration 8) The electronic device described in Configuration 7 is characterized in that, when the digital file has multiple specified areas, the append setting means sets, in accordance with user input for each of the multiple specified areas, whether data is scheduled to be appended after the digital file is generated. (Configuration 9) The electronic device described in configuration 7 or 8 is provided with an enlargement setting means for setting, in response to user input, whether to enlarge the size of the specified area that has been set by the append setting means as an area where data is scheduled to be appended after the digital file is generated. (Configuration 10) The electronic device according to configuration 9, further comprising a second size setting means for setting the size of the predetermined area, the size of which is set to be enlarged by the enlargement setting means, in accordance with user input. (Configuration 11) The electronic device according to configuration 10, wherein at least one of the append setting means, the enlargement setting means, and the second size setting means acquires user input from a UI screen. (Configuration 12) An electronic device described in any one of configurations 1 to 11, characterized in that, when the digital file has multiple specified areas, the generation means stores in the digital file information for identifying the specified area that is set to have data added to it after the digital file is generated, or information for identifying the specified area whose size is increased when the digital file is generated. (Configuration 13) The electronic device according to any one of configurations 1 to 12, further comprising a display means for displaying information indicating whether the size of the predetermined area has been enlarged on a viewing screen of the digital file. (Configuration 14) The electronic device described in any one of configurations 1 to 13, wherein the generating means generates the digital file so that the authenticity of the digital file can be verified in accordance with the C2PA standard. (Configuration 15) An electronic device described in any one of configurations 1 to 14, characterized in that the generation means generates the digital file without expanding the size of the specified area if all areas in the digital file that are to be authenticated are located before the specified area. (Configuration 16) The electronic device according to any one of configurations 1 to 14, wherein the generating means generates an image file in EXIF format as the digital file. (Configuration 17) The electronic device according to configuration 16, wherein the electronic device is a digital camera. (Method 1) A method for controlling an electronic device having a predetermined mode in which a digital file whose authenticity can be verified is generated, comprising the steps of: a first determination step of determining whether the electronic device is set to the predetermined mode; a second determination step of determining whether a predetermined area of the digital file that is not subject to authentication verification is set as a location where data will be added after the digital file is generated; A control method for an electronic device, characterized by comprising: a generation process for generating the digital file by enlarging the size of the specified area when the electronic device is set to the specified mode and when it is set that data will be added to the specified area after the digital file is generated, compared to when the electronic device is set to a mode different from the specified mode. (Program 1) A program for causing a computer to execute each means of the electronic device described in any one of configurations 1 to 17. [Explanation of symbols]
[0063] 50 System control unit (first determination means) (second determination means) (generation means) 100 Digital cameras (electronic devices) 304 XMP area (specified area) 309 Image files (digital files)
Claims
1. An electronic device having a predetermined mode in which a digital file capable of being authenticated is generated, a first determination means for determining whether the electronic device is set to the predetermined mode; a second determination means for determining whether a predetermined area of the digital file that is not subject to the authentication verification is set to have data added thereto after the digital file is generated; and a generation means for generating the digital file by enlarging the size of the specified area when the electronic device is set to the specified mode and when it is set that data will be added to the specified area after the digital file is generated, compared to when the electronic device is set to a mode different from the specified mode.
2. The electronic device according to claim 1 , further comprising an additional writing setting unit that sets, in response to a user's input, whether or not additional data is scheduled to be written to the predetermined area after the digital file is generated.
3. The electronic device described in claim 2, characterized in that when the digital file has multiple specified areas, the append setting means sets, in accordance with user input for each of the multiple specified areas, whether data is planned to be appended after the digital file is generated.
4. The electronic device according to claim 2 or 3, further comprising a first size setting means for setting the size of the specified area set by the append setting means as an area where data is to be appended after the digital file is generated, in accordance with user input.
5. 5. The electronic device according to claim 4, wherein at least one of the additional writing setting unit and the first size setting unit acquires a user input from a UI screen.
6. a third determination means for determining whether the size of the predetermined area is set to be enlarged; The electronic device described in claim 1, characterized in that when the electronic device is set to the specified mode and it is set that data will be added to the specified area after the digital file is generated, and it is also set that the size of the specified area is to be expanded, the generation means generates the digital file by expanding the size of the specified area more than when the electronic device is set to a mode different from the specified mode.
7. 7. The electronic device according to claim 6, further comprising an additional writing setting unit that sets, in response to a user's input, whether or not additional data is scheduled to be written to the predetermined area after the digital file is generated.
8. The electronic device described in claim 7, characterized in that when the digital file has multiple specified areas, the append setting means sets whether or not data is planned to be appended after the digital file is generated for each of the multiple specified areas in accordance with user input.
9. The electronic device according to claim 7 or 8, further comprising an enlargement setting means for setting, in response to user input, whether to enlarge the size of the specified area that has been set by the append setting means as an area where data is scheduled to be appended after the digital file is generated.
10. 10. The electronic device according to claim 9, further comprising a second size setting unit that sets the size of the predetermined area that has been set to be enlarged by the enlargement setting unit in accordance with a user's input.
11. 11. The electronic device according to claim 10, wherein at least one of the additional setting unit, the enlargement setting unit, and the second size setting unit acquires a user input from a UI screen.
12. The electronic device described in claim 1, characterized in that, when the digital file has multiple specified areas, the generation means stores in the digital file information for identifying the specified areas that are set to have data added to them after the digital file is generated, or information for identifying the specified areas whose size was increased when the digital file was generated.
13. 2. The electronic device according to claim 1, further comprising a display unit that displays, on a viewing screen for the digital file, information indicating whether the size of the predetermined area has been enlarged.
14. 2. The electronic device according to claim 1, wherein the generating means generates the digital file so that the authenticity of the digital file can be verified in accordance with the Coalition for Content Provenance and Authenticity (C2PA) standard.
15. The electronic device described in claim 1, characterized in that the generation means generates the digital file without expanding the size of the specified area if all areas in the digital file that are to be authenticated are located before the specified area.
16. 2. The electronic device according to claim 1, wherein the generating means generates an image file in EXIF format as the digital file.
17. 17. The electronic device according to claim 16, wherein the electronic device is a digital camera.
18. A method for controlling an electronic device having a predetermined mode in which a digital file capable of being authenticated is generated, comprising: a first determination step of determining whether the electronic device is set to the predetermined mode; a second determination step of determining whether a predetermined area of the digital file that is not subject to authentication verification is set to have data added thereto after the digital file is generated; A control method for an electronic device, characterized by comprising: a generation process for generating the digital file by enlarging the size of the specified area when the electronic device is set to the specified mode and when it is set that data will be added to the specified area after the digital file is generated, compared to when the electronic device is set to a mode different from the specified mode.
19. A program for causing a computer to execute each means of the electronic device according to claim 1.
Citation Information
Patent Citations
Imaging apparatus and recording control method
JP2020167624A