Information processing apparatus, method for controlling information processing apparatus, and storage medium
The information processing device optimizes tampering detection in video data by using a combination of hash values for entire data and frame groups, enhancing verification efficiency and usability.
Patent Information
- Application Number
- JP2024109453
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-08
- Publication Date
- 2026-01-21
AI Technical Summary
The generation of multiple hash values for each frame group in video data increases verification time, reducing the usability of tampering detection processes.
An information processing device that uses a first hash value for the entire video data and optional second hash values for frame groups, with control logic to execute tampering detection processes based on the first process results.
Improves the usability of tampering verification by optimizing the number of hash value calculations and reducing processing time.
Smart Images

Figure 2026009525000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing device, a control method for an information processing device, and a program. [Background technology]
[0002] In recent years, information sharing via the Internet has become more prevalent, allowing anyone to publish and transmit a variety of information to an unspecified number of people. It has also become possible to perform various types of processing on digital images. In such circumstances, information may be transmitted from unreliable sources, or publicly available information may be fraudulently altered. In response to this, Patent Document 1 proposes a technology for verifying data tampering. In Patent Document 1, a group of files to be verified is searched, and both the progress of the file search and the progress of the tampering verification using hash values are displayed.
[0003] Furthermore, when verifying whether video data consisting of multiple frames has been tampered with, multiple hash values are generated by applying a hash function to each group of frames that constitute the video data when it was shot, which makes it possible not only to determine whether the video data has been tampered with, but also to identify the frames in the video data that have been tampered with. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2007-336457 Summary of the Invention [Problem to be solved by the invention]
[0005] However, in the configuration described above where a hash value is generated for each frame group, the number of hash values increases by the number of frame groups, which increases the time required for verification and reduces usability.
[0006] An object of the present invention is to provide an information processing device, a control method for the information processing device, and a program that can improve usability in verifying tampering of video data. [Means for solving the problem]
[0007] In order to achieve the above object, the information processing device of the present invention is characterized by comprising: means for acquiring a video file including video data composed of a plurality of frames and a plurality of types of hash values for detecting tampering with the video data; means for executing a first process for detecting tampering with the video data using a first type of hash value included in the video file, the first type of hash value being generated by running a hash function on the entire video data when the video data was shot; means for executing a second process for detecting tampering with the video data using a plurality of second type of hash values included in the video file, the second type of hash value being generated by running a hash function on each of a plurality of frame groups obtained by grouping frames that make up the video data when the video data was shot; and means for controlling whether or not to execute the second process when tampering with the video data is detected in the first process. [Effects of the Invention]
[0008] According to the present invention, it is possible to improve usability in verifying tampering of video data. [Brief explanation of the drawings]
[0009] [Figure 1] 1 is an external view of a digital camera as an information processing device according to an embodiment of the present invention. [Figure 2] FIG. 2 is a block diagram showing an example of the configuration of the digital camera shown in FIG. [Figure 3] 2 is a flowchart showing the procedure of main processing executed by the digital camera of FIG. 1. [Figure 4]4 is a flowchart showing the procedure of the still image shooting process in S305 of FIG. 3. [Figure 5] 2A to 2C are diagrams showing examples of the configuration of a still image file and a moving image file generated by the digital camera of FIG. 1. [Figure 6] 4 is a flowchart showing the procedure of the moving image shooting process in S307 of FIG. 3. [Figure 7] 4 is a flowchart showing the procedure of the verification process in S309 of FIG. 3. [Figure 8] 8 is a diagram showing an example of a screen displayed on a display unit in the verification process of FIG. 7. FIG. [Figure 9] 8 is a diagram showing an example of a screen displayed on a display unit in the verification process of FIG. 7. FIG. [Figure 10] 8 is a flowchart showing the procedure of the overall verification process in S703 of FIG. 7. [Figure 11] 8 is a flowchart showing the procedure of the individual verification process in S712 of FIG. 7. DETAILED DESCRIPTION OF THE INVENTION
[0010] Hereinafter, preferred embodiments of the present invention will be described with reference to the drawings.
[0011] 1A and 1B are external views of a digital camera 100 as an information processing device according to this embodiment, in which Fig. 1A is a front perspective view of the digital camera 100, and Fig. 1B is a rear perspective view of the digital camera 100.
[0012] The display unit 28 is a display unit provided on the back surface of the digital camera 100, and displays images and various information. The touch panel 70a can detect touch operations on the display surface (touch operation surface) of the display unit 28. The out-of-viewfinder display unit 43 is a display unit provided on the top surface of the digital camera 100, and displays various settings of the digital camera 100, including the shutter speed and aperture. The shutter button 61 is an operation member for issuing shooting instructions. The mode selector switch 60 is an operation member for switching between various modes. The terminal cover 40 is a cover that protects a connector (not shown) for connecting a connection cable or the like that connects the digital camera 100 to an external device.
[0013] The main electronic dial 71 is a rotary operation member. Turning the main electronic dial 71 allows changes to be made to settings such as the shutter speed and aperture. The power switch 72 is an operation member that switches the power of the digital camera 100 on and off. The sub electronic dial 73 is a rotary operation member. Turning the sub electronic dial 73 allows movements of the selection frame (cursor) and images to be advanced. The four-way key 74 is configured so that the up, down, left, and right portions can each be pressed, and processing can be performed according to the portion of the four-way key 74 that is pressed. The SET button 75 is a push button that is mainly used to confirm a selection item, etc.
[0014] The movie button 76 is used to start or stop movie shooting (recording). The AE lock button 77 is a push button. Pressing the AE lock button 77 in shooting standby mode fixes the exposure state. The enlarge button 78 is an operation button for switching the enlargement mode ON and OFF in the live view display (LV display) in shooting mode. By setting the enlargement mode ON and operating the main electronic dial 71, the live view image (LV image) can be enlarged or reduced. In playback mode, the enlargement button 78 functions as an operation button for enlarging the playback image or increasing its magnification. The playback button 79 is an operation button for switching between shooting mode and playback mode. Pressing the playback button 79 in shooting mode switches to playback mode, and the most recent image recorded on the recording medium 200 (described below) can be displayed on the display unit 28. The menu button 81 is a push button used to issue an instruction to display a menu screen. Pressing the menu button 81 displays a menu screen on the display unit 28 that allows various settings to be configured. The user can intuitively make various settings using the menu screen displayed on the display unit 28, the four-way key 74, and the SET button 75.
[0015] The touch bar 82 (multifunction bar: M-Fn bar) is a line-shaped touch operation member (line touch sensor) that can receive touch operations. The touch bar 82 is positioned so that it can be touched (touched) with the thumb of the right hand when the grip unit 90 is held in the right hand (holding it with the little finger, ring finger, and middle finger of the right hand) so that the shutter button 61 can be pressed with the index finger of the right hand. In other words, the touch bar 82 is positioned so that it can be operated when the user places his / her eye on the eyepiece unit 16, looks through the viewfinder, and is in a position (shooting posture) so that the shutter button 61 can be pressed at any time. The touch bar 82 is a reception unit that can receive tap operations (operations in which the user touches and then releases the touch bar without moving within a predetermined period of time), slide operations to the left or right (operations in which the user touches and then moves the touched position while keeping the touch) and the like. The touch bar 82 is an operation member that is different from the touch panel 70a and does not have a display function.
[0016] The communication terminal 10 is a communication terminal through which the digital camera 100 communicates with the lens unit 150 (described later). The eyepiece 16 is the eyepiece of the eyepiece finder 17 (a peer-type finder), and the user can view an image displayed on an internal EVF 29 (Electronic View Finder) through the eyepiece 16. The eyepiece detection unit 57 is an eyepiece detection sensor that detects whether the user (photographer) has placed their eye on the eyepiece 16. The cover 202 is a cover for a slot that stores a recording medium 200 (described later). The grip unit 90 is a holding unit shaped to be easily held in the user's right hand when holding the digital camera 100. The shutter button 61 and the main electronic dial 71 are located in positions that can be operated with the index finger of the right hand when the digital camera 100 is held by gripping the grip unit 90 with the little finger, ring finger, and middle finger of the right hand. In the same state, the sub electronic dial 73 and touch bar 82 are also arranged in positions that can be operated with the thumb of the right hand. The thumb rest 91 (thumb standby position) is a grip member provided on the rear side of the digital camera 100 in a position where it is easy to place the thumb of the right hand that is holding the grip 90 when none of the operation members are being operated. The thumb rest 91 is made of a rubber member or the like to increase the holding strength (grip feeling).
[0017] FIG. 2 is a block diagram showing an example configuration of the digital camera 100 of FIG. 1. The lens unit 150 is a lens unit equipped with an interchangeable photographing lens and is detachable from the digital camera 100. The lens 103 is usually composed of multiple lenses, but FIG. 2 shows only one lens for simplicity's sake. The communication terminal 6 is a communication terminal through which the lens unit 150 communicates with the digital camera 100, and the communication terminal 10 is a communication terminal through which the digital camera 100 communicates with the lens unit 150. The lens unit 150 communicates with the system controller 50 via these communication terminals 6 and 10. The lens unit 150 controls the aperture 1 via the aperture drive circuit 2 by the internal lens system control circuit 4. The lens unit 150 also adjusts focus by displacing the position of the lens 103 via the AF drive circuit 3 by the lens system control circuit 4.
[0018] The shutter 101 is a focal plane shutter that can freely control the exposure time of the imaging unit 22 under the control of the system control unit 50.
[0019] The imaging unit 22 is an imaging element (image sensor) configured with a CCD, CMOS element, or the like that converts an optical image into an electrical signal. The imaging unit 22 may have an imaging surface phase difference sensor that outputs defocus amount information to the system control unit 50. The A / D converter 23 (denoted as "A / D" in FIG. 2) converts the analog signal output from the imaging unit 22 into a digital signal.
[0020] The image processing unit 24 performs predetermined processing (pixel interpolation, resizing such as reduction, color conversion, etc.) on data from the A / D converter 23 or data from the memory control unit 15. The image processing unit 24 also performs predetermined arithmetic processing using the captured image data, and the system control unit 50 performs exposure control and distance measurement control based on the arithmetic results obtained by the image processing unit 24. This allows TTL (through-the-lens) type AF (autofocus) processing, AE (autoexposure) processing, EF (flash pre-flash) processing, etc. to be performed. The image processing unit 24 also performs predetermined arithmetic processing using the captured image data, and performs TTL type AWB (auto white balance) processing based on the arithmetic results obtained.
[0021] The output data from the A / D converter 23 is written to the memory 32 via the image processing unit 24 and the memory control unit 15. Alternatively, the output data from the A / D converter 23 is written to the memory 32 via the memory control unit 15 without going through the image processing unit 24. The memory 32 stores image data obtained by the imaging unit 22 and converted into digital data by the A / D converter 23, as well as image data to be displayed on the display unit 28 and the EVF 29. The memory 32 has a storage capacity sufficient to store a predetermined number of still images and a predetermined period of moving images and audio.
[0022] The memory 32 also serves as a memory (video memory) for image display. The D / A converter 19 (denoted as "D / A" in FIG. 2) converts image display data stored in the memory 32 into an analog signal and supplies it to the display unit 28 or the EVF 29. In this way, the display image data written to the memory 32 is displayed on the display unit 28 or the EVF 29 via the D / A converter 19. The display unit 28 and the EVF 29 are both displays such as LCDs or organic EL displays, and display images according to the analog signal from the D / A converter 19. The digital signals A / D converted by the A / D converter 23 and stored in the memory 32 are converted into analog signals by the D / A converter 19, and these signals are sequentially transferred to and displayed on the display unit 28 or the EVF 29, thereby enabling a live view display (LV). Hereinafter, images displayed in live view display are referred to as live view images (LV images).
[0023] The system control unit 50 is a control unit made up of at least one processor and / or at least one circuit, and controls the entire digital camera 100. The system control unit 50 is both a processor and a circuit. The system control unit 50 executes programs recorded in nonvolatile memory 56 to realize each process of this embodiment, which will be described later. The system control unit 50 also controls the memory 32, D / A converter 19, display unit 28, EVF 29, etc., to perform display control.
[0024] The system memory 52 is, for example, a RAM, and the system control unit 50 loads constants and variables for the operation of the system control unit 50, programs read from the nonvolatile memory 56, and the like into the system memory 52.
[0025] The nonvolatile memory 56 is an electrically erasable and recordable memory, such as an EEPROM. Constants, programs, etc. for the operation of the system control unit 50 are recorded in the nonvolatile memory 56. The programs referred to here are programs for executing various flowcharts described later in this embodiment.
[0026] The system timer 53 is a timekeeping unit that measures the time used for various controls and the time of a built-in clock.
[0027] The communication unit 54 transmits and receives video signals and audio signals to and from external devices connected wirelessly or via a wired cable. The communication unit 54 can also connect to a wireless LAN (Local Area Network) or the Internet. The communication unit 54 can also communicate with external devices using Bluetooth (registered trademark) or Bluetooth Low Energy. The communication unit 54 can transmit images (including LV images) captured by the imaging unit 22 and images recorded on the recording medium 200, and can receive various information such as image data and a video recording start instruction from an external device. When a video recording start instruction is received from an external device, the communication unit 54 can notify the user of the receipt of the instruction by causing the light-emitting unit 102 to light up or by sounding an electronic beep from the speaker 92. Examples of external devices with which the communication unit 54 can communicate include smartphones, tablet PCs, and desktop PCs.
[0028] The orientation detection unit 55 detects the orientation of the digital camera 100 with respect to the direction of gravity. Based on the orientation detected by the orientation detection unit 55, it is possible to determine whether an image captured by the imaging unit 22 was captured with the digital camera 100 held horizontally or vertically. The system control unit 50 can add orientation information corresponding to the orientation detected by the orientation detection unit 55 to the image file of the image captured by the imaging unit 22, or rotate and record the image. An acceleration sensor, a gyro sensor, or the like can be used as the orientation detection unit 55. The acceleration sensor or gyro sensor of the orientation detection unit 55 can also be used to detect movement of the digital camera 100 (panning, tilting, lifting, whether it is stationary, etc.).
[0029] The eyepiece detection unit 57 is an eyepiece detection sensor that detects (approach detection) whether an eye (object) approaches (approach) or moves away (away) from (approach detection) the eyepiece 16 of the eyepiece finder 17 (hereinafter simply referred to as the "finder"). The system control unit 50 switches the display unit 28 and the EVF 29 between on (display state) and off (non-display state) depending on the state detected by the eyepiece detection unit 57. More specifically, at least in a shooting standby state and when the display destination switching setting is automatic switching, when the eye is not in contact with the camera, the display is turned on with the display on the display unit 28 and the EVF 29 is hidden. When the eye is in contact with the camera, the display is turned on with the display on the EVF 29 and the display unit 28 is hidden. For example, an infrared proximity sensor can be used as the eyepiece detection unit 57, and it can detect the approach of an object to the eyepiece 16 of the eyepiece finder 17 that incorporates the EVF 29. When an object approaches, infrared light emitted from a light-emitting unit (not shown) of the eyepiece detection unit 57 is reflected by the object and received by a light-receiving unit (not shown) of the infrared proximity sensor. The amount of received infrared light can also determine the distance the object is approaching the eyepiece 16 (eyepiece distance). In this way, the eyepiece detection unit 57 performs eyepiece detection, which detects the proximity of an object to the eyepiece 16. When an object approaching within a predetermined distance from the eyepiece 16 is detected from a non-eyepiece state (non-approach state), it is detected as being in eye contact. When an object detected as approaching moves away from the eyepiece state (approach state) by more than a predetermined distance, it is detected as being away from the eye. The threshold for detecting eye contact and the threshold for detecting eye separation may be different, for example, by providing hysteresis. Furthermore, after eye contact is detected, the eyepiece remains in the eye contact state until eye separation is detected. After eye separation is detected, the eyepiece remains in the non-eye contact state until eye contact is detected. The infrared proximity sensor is just an example, and other sensors may be used for the eye proximity detector 57 as long as they can detect a state that can be considered as eye proximity.
[0030] The GPS receiver 119 receives GPS information from a GPS satellite for calculating location information and time information. The digital camera 100 receives the GPS information using the GPS receiver 119 and calculates location information and time information based on the received GPS information. The digital camera 100 can add this calculated location information and time information to captured images.
[0031] The hash value generation unit 210 generates (calculates) a hash value by executing a hash function on a still image file or a video file. The hash value may be generated by the system control unit 50 instead of the hash value generation unit 210. The hash value generation process will be described in detail later.
[0032] Various camera settings such as shutter speed and aperture are displayed on the outside viewfinder display 43 via an outside viewfinder display drive circuit 44 .
[0033] The power supply control unit 80 is composed of a battery detection circuit, a DC-DC converter, a switch circuit for switching between powered blocks, etc., and detects whether a battery is installed, the type of battery, and the remaining battery power. The power supply control unit 80 also controls the DC-DC converter based on the detection results and instructions from the system control unit 50, and supplies the required voltage for the required period to each unit, including the recording medium 200. The power supply unit 30 is composed of primary batteries such as alkaline batteries or lithium batteries, secondary batteries such as NiCd batteries, NiMH batteries, or Li batteries, an AC adapter, etc.
[0034] The recording medium I / F 18 (denoted as "I / F" in FIG. 2) is an interface with a recording medium 200 such as a memory card or a hard disk. The recording medium 200 is a recording medium such as a memory card for recording captured images, and is composed of a semiconductor memory, a magnetic disk, or the like.
[0035] The operation unit 70 is an input unit that accepts operations from the user (user operations) and is used to input various operational instructions to the system control unit 50. As shown in Fig. 2, the operation unit 70 includes a shutter button 61, a mode selector switch 60, a power switch 72, a touch panel 70a, other operation members 70b, etc. The other operation members 70b include a main electronic dial 71, a sub electronic dial 73, a four-way key 74, a SET button 75, a video button 76, an AE lock button 77, a magnification button 78, a playback button 79, a menu button 81, a touch bar 82, etc.
[0036] The shutter button 61 includes a first shutter switch 62 and a second shutter switch 64. The first shutter switch 62 is turned on when the shutter button 61 is pressed halfway (a shooting preparation command) during operation, and generates a first shutter switch signal SW1. The system control unit 50 starts shooting preparation operations such as AF processing, AE processing, AWB processing, and EF processing in response to the first shutter switch signal SW1.
[0037] The second shutter switch 64 is turned on when the shutter button 61 is fully pressed (photographing instruction) and generates a second shutter switch signal SW2. The second shutter switch signal SW2 causes the system control unit 50 to start a series of photographing processing operations, from reading out a signal from the imaging unit 22 to writing the captured image to the recording medium 200 as an image file.
[0038] The mode selector switch 60 switches the operating mode of the system control unit 50 to one of still image capture mode, video capture mode, playback mode, etc. Modes included in the still image capture mode include auto capture mode, auto scene determination mode, manual mode, aperture priority mode (Av mode), shutter speed priority mode (Tv mode), and program AE mode (P mode). There are also various scene modes and custom modes that provide capture settings for specific capture scenes. The mode selector switch 60 allows the user to directly switch to one of these modes. Alternatively, after first switching to a list screen of capture modes with the mode selector switch 60, the user may selectively switch to one of the displayed modes using another operating member. Similarly, the video capture mode may also include multiple modes.
[0039] The touch panel 70a is a touch sensor that detects various touch operations on the display surface of the display unit 28 (the operation surface of the touch panel 70a). The touch panel 70a and the display unit 28 can be configured as an integrated unit. For example, the touch panel 70a is configured so that its light transmittance does not interfere with the display of the display unit 28, and is attached to the upper layer of the display surface of the display unit 28. Input coordinates on the touch panel 70a are associated with display coordinates on the display surface of the display unit 28. This makes it possible to provide a GUI (graphical user interface) that allows the user to directly operate the screen displayed on the display unit 28.
[0040] The system control unit 50 can detect the following operations or states on the touch panel 70a.
[0041] A finger or pen that has not been touching the touch panel 70a touches the touch panel 70a again, that is, the start of touching (hereinafter referred to as Touch-Down). A state in which the touch panel 70a is touched with a finger or a pen (hereinafter referred to as Touch-On) A finger or pen is moved while touching the touch panel 70a (hereinafter referred to as Touch-Move). The finger or pen that has been touching the touch panel 70a is released from the touch panel 70a, that is, the end of touch (hereinafter referred to as "touch-up"). A state in which nothing is touching the touch panel 70a (hereinafter referred to as Touch-Off) When a touch down is detected, a touch on is also detected at the same time. After a touch down, a touch on is usually continued to be detected unless a touch up is detected. If a touch move is detected, a touch on is also detected at the same time. Even if a touch on is detected, a touch move is not detected unless the touch position moves. Once it is detected that all fingers or pens that were touching have touched up, a touch off occurs.
[0042] These operation states and the position coordinates of the finger or pen touching the touch panel 70a are notified to the system control unit 50 via the internal bus. The system control unit 50 then determines what kind of operation (touch operation) was performed on the touch panel 70a based on the notified information. Regarding touch-move, the movement direction of the finger or pen moving on the touch panel 70a can also be determined for each vertical and horizontal component on the touch panel 70a based on changes in the position coordinates. If a touch-move of a predetermined distance or more is detected, it is determined that a slide operation has been performed. An operation in which a finger is touched on the touch panel 70a, moved quickly for a certain distance, and then released is called a flick. In other words, a flick is an operation in which a finger is quickly traced across the touch panel 70a as if flicking it. If a touch-move of a predetermined distance or more at a predetermined speed or more is detected and a touch-up is then detected, it is determined that a flick has been performed (it can be determined that a flick occurred following a slide operation). Furthermore, a touch operation in which multiple points (for example, two points) are touched together (multi-touch) and the touch positions are brought closer together is called a pinch in, and a touch operation in which the touch positions are moved farther apart is called a pinch out. Pinch out and pinch in are collectively called a pinch operation (or simply a pinch). The touch panel 70a may be of any of a variety of touch panel types, including resistive film type, capacitive type, surface acoustic wave type, infrared type, electromagnetic induction type, image recognition type, and optical sensor type. There are types that detect a touch by contact with the touch panel, and types that detect a touch by the approach of a finger or pen to the touch panel, and either type is acceptable.
[0043] FIG. 3 is a flowchart showing the steps of a main process executed by the digital camera 100 of FIG. 1. The main process of FIG. 3 is realized by the system control unit 50 loading a program stored in the nonvolatile memory 56 into the system memory 52 and executing it. The main process of FIG. 3 is initiated, for example, when a user presses the power switch 72 to start the digital camera 100 and then operates the touch panel 70a to issue a menu switching instruction. Upon receiving the menu switching instruction, the digital camera 100 displays a setting screen on the display unit 28 for setting the falsification prevention mode. On this setting screen, the user can select either "ON" to enable the falsification prevention mode or "OFF" to disable the falsification prevention mode. In this embodiment, when a photograph is taken with the falsification prevention mode set to "ON," the still image file or video file obtained by the photograph contains the history information described below. On the other hand, when a photograph is taken with the falsification prevention mode set to "OFF," the still image file or video file obtained by the photograph does not contain the history information described below.
[0044] 3, first, in S301, the system control unit 50 determines whether the user specified "ON" or "OFF" on the setting screen. If it is determined that the user specified "ON" on the setting screen, the process proceeds to S302. If it is determined that the user specified "OFF" on the setting screen, the process proceeds to S303.
[0045] In S302, the system control unit 50 sets the falsification prevention mode to "ON." This enables the falsification prevention mode in the digital camera 100. A setting value indicating that the falsification prevention mode is enabled is stored in the memory 32. Next, the process proceeds to S304, which will be described later.
[0046] In S303, the system control unit 50 sets the tamper-proof mode to "off." This disables the tamper-proof mode in the digital camera 100. A setting value indicating that the tamper-proof mode is disabled is stored in the memory 32.
[0047] Next, in S304, the system control unit 50 determines whether a still image shooting instruction has been issued. In this embodiment, the user can issue a still image shooting instruction by, for example, pressing the shutter button 61. If it is determined that a still image shooting instruction has been issued, the process proceeds to S305. If it is determined that a still image shooting instruction has not been issued, the process proceeds to S306.
[0048] In S305, the system control unit 50 performs the still image capturing process shown in Fig. 4, which will be described later, and generates a still image file including image data obtained by capturing the still image. The structure of the still image file will be described later.
[0049] Next, in S306, the system control unit 50 determines whether a video shooting instruction has been issued. In the present embodiment, the user can issue a video shooting instruction by, for example, pressing the video button 76. If it is determined that a video shooting instruction has been issued, the process proceeds to S307. If it is determined that a video shooting instruction has not been issued, the process proceeds to S308.
[0050] In S307, the system control unit 50 performs the moving image shooting process shown in Fig. 6, which will be described later, and generates a moving image file including moving image data obtained by shooting the moving image. The structure of the moving image file will be described later.
[0051] Next, in S308, the system control unit 50 determines whether a verification instruction has been issued. In this embodiment, the user can issue a verification instruction by operating the touch panel 70a, for example. If it is determined that a verification instruction has been issued, the process proceeds to S309. If it is determined that a verification instruction has not been issued, the process proceeds to S310.
[0052] In S309, the system control unit 50 performs a verification process shown in FIG. 7, which will be described later, to detect whether the still image files or moving image files stored on the recording medium 200 have been tampered with.
[0053] Next, in S310, the system control unit 50 determines whether an instruction to end the main processing has been issued. In this embodiment, the user can issue an instruction to end the main processing by, for example, pressing the power switch 72. If it is determined that an instruction to end the main processing has not been issued, the process returns to S301. If it is determined that an instruction to end the main processing has been issued, the process ends.
[0054] Fig. 4 is a flowchart showing the procedure of the still image shooting process of S305 in Fig. 3. This process starts when an operation such as pressing the shutter button 61 is accepted, and ends when an operation such as ceasing to press the shutter button 61 is accepted.
[0055] In FIG. 4, in S401, the system control unit 50 drives the shutter 101 disposed on the subject side of the imaging unit 22 in order to control the exposure time.
[0056] Next, in S402, the system control unit 50 performs imaging processing to convert light from the subject received by the imaging unit 22 via the shutter 101 into an electrical signal (analog image data).
[0057] Next, in S403, the system control unit 50 performs image processing such as development processing and encoding processing on the electrical signal obtained by the above-mentioned imaging processing, and generates image data 504 shown in FIG. 5(a).
[0058] Next, in S404, the system control unit 50 determines whether the setting value of the falsification prevention mode is "ON" or "OFF." If it is determined that the setting value of the falsification prevention mode is "OFF," the process proceeds to S405. If it is determined that the setting value of the falsification prevention mode is "ON," the process proceeds to S406.
[0059] In S405, the system control unit 50 generates metadata that does not include history information. This metadata includes the shooting information 502 in FIG. 5(a). The shooting information 502 is information at the time of execution of the imaging process to generate the image data 504, and includes, for example, the shooting date and time, the shooting location, the photographer, the image size, the manufacturer and model of the digital camera 100, various shooting parameters set at the time of shooting, and a thumbnail image. The shooting information 502 is generated in accordance with a predetermined technical standard (for example, EXIF (Exchangeable image file format)). Next, the process proceeds to S409, which will be described later.
[0060] In S406, the system control unit 50 generates the metadata 501 shown in Fig. 5(a). The metadata 501 is made up of the above-mentioned shooting information 502 and history information 503. The history information 503 is information for proving the authenticity of the image data 504 generated in S403, and is used when verifying the source and history of the image data 504. The provenance information 503 is generated in accordance with a predetermined technical standard (for example, C2PA (Certification for Content Provenance and Authenticity)) and has a prescribed structure. The provenance information 503 includes, for example, a provenance 513 (Assertion), a hash value 523 for assuring the provenance 513, and a digital signature 533. The provenance 513 includes provenance identification information (Manifest ID) for uniquely identifying the provenance 513, an editing history indicating the editing content of the image data 504 generated in S403, an editing tool indicating the tool used for the editing, and information indicating the creator of the image data 504. Here, the image data 504 generated in S403 has just been generated by shooting and has not been edited, so information indicating "generated" is recorded in the editing history, and information indicating the digital camera 100 is recorded in the editing tool.
[0061] Next, in S407, the system control unit 50 generates a hash value 523 to be included in the history information 503. For example, the system control unit 50 executes a hash function on the binary data of the image data 504 and the history 513 to generate a hash value 524 of the image data and a hash value 525 of the history. Note that the system control unit 50 may also execute a hash function on the binary data of the shooting information 502 to generate a hash value 526 of the shooting information.
[0062] Next, in S408, the system control unit 50 generates a digital signature 533 to be included in the history information 503. The digital signature 533 includes, for example, information indicating the signature value, the signer, and the date and time of signing. The signature value is generated by encrypting the hash value 523 generated in S407 using a private key prepared in advance. The public key that pairs with the private key used here is also included in the digital signature 533. Note that at this time, to prove that the public key is from a trustworthy manufacturer, the digital signature 533 may include information indicating the manufacturer of the digital camera 100 as the signer or a public key certificate indicating that the public key has been authenticated by a certification authority. By assigning the digital signature 533 including such a signer to a still image file, it is possible to demonstrate that the still image file is trustworthy. Note that the model of the digital camera 100 may be used as the signer instead of the manufacturer. The date and time when the generation of the digital signature 533 is completed is recorded as the date and time of signing.
[0063] Next, in S409, the system control unit 50 generates a still image file. For example, when the setting value of the tamper-proof mode is "ON," the still image file shown in FIG. 5(a) is generated. This still image file is composed of metadata 501 including shooting information 502 and history information 503, and image data 504 generated in S403. The image data 504 is generated in accordance with a still image format such as JPEG. On the other hand, when the setting value of the tamper-proof mode is "OFF," a still image file is generated that is composed of the metadata generated in S405 and the image data 504 generated in S403. The metadata generated in S405 includes the shooting information 502, but does not include the history information 503.
[0064] Next, in S410, the system control unit 50 determines whether or not a still image shooting process end instruction has been received from the user. If it is determined that the still image shooting process end instruction has not been received, the process returns to S401. If it is determined that the still image shooting process end instruction has been received, the process ends.
[0065] As described above, in this embodiment, when the digital camera 100 captures a still image, a still image file is generated. Note that the still image file may be edited by an application or the like. If the still image file is edited using an authorized editing tool in accordance with a legitimate procedure, new history information is generated in accordance with a predetermined technical standard based on the edited content, and the history information is added to the metadata 501 of the still image file. In this way, new history information is added to the metadata 501 of the still image file every time the still image file is edited. On the other hand, if the still image file is edited using an unauthorized editing tool or in accordance with an unauthorized procedure, the history information may not be added to the metadata 501 of the still image file, or the history information added to the metadata 501 of the still image file may not conform to the predetermined technical standard.
[0066] Furthermore, by generating a hash value 523 and a digital signature 533, it is possible to detect tampering of a still image file. For example, a hash value is generated by applying a hash function to the binary data of image data 504 of a still image file. The generated hash value is then compared with the hash value 524 of the image data included in the still image file to be determined. This makes it possible to verify whether the image data 504 has been tampered with. Similarly, a hash function is applied to the binary data of shooting information 502 of the still image file to generate a hash value. The generated hash value is then compared with the hash value 526 of the shooting information included in the still image file to be determined. This makes it possible to verify whether the shooting information 502 has been tampered with. Note that, as shown in this embodiment, it is possible to ensure the provenance of only selected data, and this technology is applicable not only to imaging devices but also to editing applications, etc.
[0067] Furthermore, a hash function is applied to the binary data of the history 513 to generate a hash value. The generated hash value is then compared with the hash value 525 of the history included in the still image file to be verified. This makes it possible to verify whether the history 513 has been tampered with. Note that the binary data to be compared at this time may be compared in smaller units such as editing history, production source, thumbnail data, or metadata. Furthermore, the signature value can be decrypted using a public key, and if the hash values match, it can be determined that the signature value has been successfully verified. In this way, a mechanism for detecting tampering can be incorporated into still image files.
[0068] Fig. 6 is a flowchart showing the procedure for the video shooting process of S307 in Fig. 3. This process starts when an operation such as pressing the video button 76 is accepted, and ends when an operation such as pressing the video button 76 is accepted during video shooting.
[0069] In FIG. 6, in S601, the system control unit 50 performs imaging processing to convert light from a subject received by the imaging unit 22 into an electrical signal (analog image data).
[0070] Next, in S602, the system control unit 50 performs image processing such as development and encoding on the electrical signal obtained by the above-mentioned imaging processing, to generate moving image data 505' shown in Fig. 5(b). At this time, the system control unit 50 groups the frames that make up the moving image data 505', and generates moving image data 505' made up of a plurality of frame groups (Group Of Pictures (hereinafter referred to as "GOP").
[0071] Next, in S603, the system control unit 50 determines whether the setting value of the falsification prevention mode is “ON” or “OFF.” If it is determined that the setting value of the falsification prevention mode is “OFF,” the process proceeds to S604.
[0072] In S604, the system control unit 50 generates metadata that does not include history information. This metadata includes the shooting information 502' in FIG. 5(b). The shooting information 502' is information at the time of execution of the imaging process to generate the video data 505', and includes, for example, the shooting date and time, the photographer, the image size, the manufacturer and model of the digital camera 100, various shooting parameters set at the time of shooting, the shooting location, and a thumbnail image. The shooting information 502' is generated in accordance with a predetermined technical standard (for example, EXIF (Exchangeable Image File Format)).
[0073] Next, in S605, the system control unit 50 determines whether or not a moving image shooting end instruction has been received from the user. If it is determined that the moving image shooting end instruction has not been received, the process returns to S601. If it is determined that the moving image shooting end instruction has been received, the process proceeds to S611, which will be described later.
[0074] If it is determined in S603 that the setting value of the tamper-proof mode is "ON," the process proceeds to S606. In S606, the system control unit 50 generates metadata 501' shown in Fig. 5(b). The metadata 501' is composed of shooting information 502' and history information 503'.
[0075] The history information 503' is information for proving the authenticity of the video data 505', and is used when verifying the origin and history of the video data 505'. The provenance information 503' is generated in accordance with a predetermined technical standard (for example, C2PA (Certification for Content Provenance and Authenticity)) and has a prescribed structure. The provenance information 503' includes a provenance 513' (assertion), a hash value 523' and a digital signature 533' for verifying the provenance 513'. The provenance 513' includes provenance identification information (Manifest ID) for uniquely identifying the provenance 513', an editing history indicating the editing content of the video data 505', an editing tool indicating the tool used for the editing, and information about the creator of the video data 505'. Here, the video data 505' generated in S602 has just been generated by shooting and has not been edited, so information indicating "generated" is recorded in the editing history, and information indicating the digital camera 100 is recorded in the editing tool.
[0076] Next, in S607, the system control unit 50 generates a video data hash value 527' (a second type of hash value) for each GOP. Specifically, the system control unit 50 executes a hash function on the binary data of each GOP of the video data 505' to generate a video data hash value 527' for each GOP. These hash values are used as individual hash values for identifying tampered portions in more detail than the entire video data hash value 524' described below. Note that, if this purpose is met, the hash function may be executed on the binary data of the video data 505' not on a GOP-by-GOP basis, but on a GOP group basis, each group consisting of several GOPs, to generate individual hash values.
[0077] Next, in S608, the system control unit 50 determines whether or not a moving image shooting end instruction has been received from the user. If it is determined that the moving image shooting end instruction has not been received, the process returns to S601. If it is determined that the moving image shooting end instruction has been received, the process proceeds to S609.
[0078] In S609, the system control unit 50 generates various hash values to be included in the history information 503'. Specifically, the system control unit 50 executes a hash function on the binary data of each of the video data 505' and the history 513' to generate a video data overall hash value 524' (first type hash value) and a history hash value 525'. Note that the hash function may also be executed on the binary data of the imaging information 502' to generate a imaging information hash value 526'. The hash value generated in S609 is used as an overall hash value for detecting tampering of the entire video data in the verification process of FIG. 7, which will be described later.
[0079] Next, in S610, the system control unit 50 generates a digital signature 533' shown in FIG. 5(b). The digital signature 533' includes information indicating the signature value, the signer, and the date and time of signing. The signature value is generated by encrypting the generated hash value 523' using a private key prepared in advance. The public key that pairs with the private key used here is also included in the digital signature 533'. Note that at this time, to prove that the public key is from a trustworthy manufacturer, information indicating the manufacturer of the digital camera 100 or a public key certificate indicating that the public key has been authenticated by a certification authority may be included as the signer. By assigning the digital signature 533' including such a signer to a video file, it is possible to demonstrate that the video file is trustworthy. Note that the model of the digital camera 100 may be used as the signer instead of the manufacturer. The date and time when the generation of the digital signature 533' is completed is recorded as the date and time of signing.
[0080] Next, in S611, the system control unit 50 generates a video file. For example, if the setting value of the falsification prevention mode is "ON," the video file shown in FIG. 5B is generated. This video file is composed of metadata 501' including shooting information 502' and history information 503', and video data 505' generated in S602. The video data 505' is generated in accordance with a video format such as the MPEG format. On the other hand, if the setting value of the falsification prevention mode is "OFF," a video file is generated that is composed of the metadata generated in S604 and the video data 505' generated in S602. The metadata generated in S604 includes the shooting information 502' and does not include the history information 503'. When the processing of S611 is completed, this processing ends.
[0081] As described above, in this embodiment, when the digital camera 100 shoots a video, a video file is generated. Note that the video file may be edited by an app or the like. If the video file is edited using an authorized editing tool in a legitimate procedure, new history information is generated in accordance with a predetermined technical standard based on the edited content, and the history information is added to the video file's metadata 501'. In this way, new history information is added to the video file's metadata 501' every time the video file is edited. On the other hand, if the video file is edited using an unauthorized editing tool or in an unauthorized procedure, new history information may not be added to the video file, or the history information added to the video file may not conform to the predetermined technical standard.
[0082] Furthermore, by generating a hash value 523' and a digital signature 533', it is possible to detect tampering with a video file. For example, a hash function is applied to the entire binary data of video data 505' of a video file to generate a hash value. The generated hash value is then compared with hash value 524' of the entire video data of the video file to be determined. This makes it possible to verify whether or not the video data 505' has been tampered with. Similarly, a hash function is applied to the binary data of shooting information 502' of the video file to generate a hash value. The generated hash value is then compared with hash value 526' of the shooting information of the video file to be determined. This makes it possible to verify whether or not the shooting information 502' has been tampered with. Furthermore, a hash function is applied to the binary data of each GOP of video data 505' in the video file to generate multiple hash values corresponding to each GOP. The generated multiple hash values are then compared with video data hash value 527' for each GOP of the video file to be determined. This makes it possible to verify whether or not the video data has been tampered with on a GOP-by-GOP basis.
[0083] Here, in addition to still image files and video files obtained by shooting with the digital camera 100, still image files and video files obtained by shooting or editing with other devices are stored on the recording medium 200 of the digital camera 100. There is a concern that still image files and video files obtained from other devices may have been illegally tampered with, so it is necessary to verify whether or not they have been tampered with.
[0084] On the other hand, when verifying whether a video file has been tampered with, by using video data hash value 527' for each GOP, it is possible not only to determine whether video data has been tampered with, but also to identify frames in the video data that have been tampered with. However, in the configuration using video data hash value 527' for each GOP as described above, the number of hash values increases as the number of GOPs increases, which increases the time required for verification and reduces usability.
[0085] Therefore, in this embodiment, if tampering is detected in an overall verification process that uses a hash value generated by running a hash function on the entire video data, control is performed as to whether or not to perform an individual verification process that uses multiple hash values corresponding to each GOP of the video data.
[0086] Fig. 7 is a flowchart showing the procedure of the verification process of S309 in Fig. 3. This process starts by accepting a verification instruction in S308 described above. Upon accepting the verification instruction, the system control unit 50 displays the folder selection screen of Fig. 8(a) on the display unit 28. On this folder selection screen, the user can select a folder from among multiple folders configured on the recording medium 200, in which a file to be subjected to the verification process is stored.
[0087] 7, in S701, the system control unit 50 sets the folder designated by the user on this folder selection screen as the target folder for verification processing. When the user selects a folder on this folder selection screen and then selects the "SET" button, the screen of the display unit 28 switches to the condition designation screen of Fig. 8(b). Note that, in the present embodiment, a configuration has been described in which a folder in which a file to be subjected to verification processing is stored is designated, but a configuration in which a file to be subjected to verification processing is designated may also be used.
[0088] Next, in S702, the system control unit 50 sets the setting values specified by the user on the condition specification screen of FIG. 8(b) as target conditions for the verification process. On this condition specification screen, target conditions for the verification process are set, which are conditions for narrowing down target files for the verification process from among the multiple files stored in the target folder set in S701. In this embodiment, the user can specify, as target conditions for the verification process, target file types such as videos and still images, ratings that indicate the degree of favorite set by the user, video formats such as MP4, and still image formats such as JPEG. When the user selects the "SET" button with the setting values set on this condition specification screen, the process proceeds to S703.
[0089] In S703, the system control unit 50 uses the video data entire hash value 524' to perform the entire verification process shown in Fig. 10, which will be described later. During the entire verification process, the display unit 28 displays the screen shown in Fig. 8(c), which indicates that the entire verification process is being performed. This screen includes a cancel button 801 for issuing an instruction to interrupt the entire verification process.
[0090] Next, in S704, the system control unit 50 displays the results of the overall verification process on the display unit 28. An example of the screen at this time is shown in FIG. 8(d), which displays the number of files that passed verification and the number of files that failed verification, as well as information indicating how many instances of tampering were detected in each of the video files and still image files. This screen also includes an individual verification button 802 for issuing an instruction to execute an individual verification process (described later), and a cancel button 803 for issuing an instruction to abort the individual verification process. This screen may also display the estimated time required to complete the individual verification process (described later in FIG. 11).
[0091] Next, in S705, the system control unit 50 determines whether or not there are any video files that have failed verification in the overall verification process. If it is determined that there are no video files that have failed verification in the overall verification process, this process ends. If it is determined that there are any video files that have failed verification in the overall verification process, this process proceeds to S706.
[0092] In S706, the system control unit 50 determines whether the predicted completion time of the individual verification process for all verification-failed video files is equal to or less than a predetermined reference time. If it is determined that the predicted completion time of the individual verification process for all verification-failed video files is equal to or less than the reference time, the process proceeds to S712, which will be described later. That is, in this case, the individual verification process for all verification-failed video files is executed without the user selecting any files to be verified. On the other hand, if it is determined that the predicted completion time of the individual verification process for all verification-failed video files exceeds the reference time, the process proceeds to S707.
[0093] In S707, the system control unit 50 determines whether automatic execution of the individual verification process, which is a function that always executes individual verification process when tampering is detected in the overall verification process, is enabled. If it is determined that automatic execution of the individual verification process is enabled, the process proceeds to S712, which will be described later. That is, in this embodiment, if automatic execution of the individual verification process is enabled, individual verification process is executed for all video files that have failed verification. On the other hand, if it is determined that automatic execution of the individual verification process is not enabled, the process proceeds to S708. Note that in this embodiment, it is assumed that the user sets the automatic execution of the individual verification process, but other means may be used.
[0094] In S708, the system control unit 50 determines whether or not automatic skip of individual verification processing, which is a function that does not necessarily execute individual verification processing when tampering is detected in the overall verification processing, is enabled. If it is determined that automatic skip of individual verification processing is enabled, this processing ends without executing individual verification processing. If it is determined that automatic skip of individual verification processing is not enabled, this processing proceeds to S709. Note that in this embodiment, it is assumed that the user sets the automatic skip of individual verification processing, but other means may be used.
[0095] In S709, the system control unit 50 determines whether an individual verification instruction has been issued. In this embodiment, the user can issue an individual verification instruction by selecting the individual verification button 802 displayed on the screen of FIG. 8(d). If it is determined that an individual verification instruction has not been issued, that is, if the user presses the cancel button 803, this process ends. If it is determined that an individual verification instruction has been issued, that is, if the user presses the individual verification button 802, this process proceeds to S710.
[0096] In S710, the system control unit 50 determines whether or not a target file for individual verification processing has been designated by the user. In this embodiment, when the user presses the individual verification button 802, the screen of the display unit 28 switches to the screen of FIG. 9(a). This screen displays video files that have failed verification and the estimated time required for individual verification processing of these video files. The user can designate a target file for individual verification processing on this screen. If it is determined that a target file for individual verification processing has not been designated by the user, this processing ends. If it is determined that a target file for individual verification processing has been designated by the user, this processing proceeds to S711.
[0097] In S711, the system control unit 50 sets the file designated by the user on this screen as a target file for individual verification processing.
[0098] Next, in S712, the system control unit 50 performs the individual verification process shown in Fig. 11, which will be described later. During the individual verification process, the display unit 28 displays the screen shown in Fig. 9(b), which indicates that the individual verification process is being performed. This screen includes a details confirmation button 901 for checking the detailed scene of the verification failure, and a cancel button 902 for issuing an instruction to interrupt the individual verification process.
[0099] Next, in S713, the system control unit 50 displays the results of the individual verification process on the display unit 28. Note that an example of the screen at this time is FIG. 9(c), and the screen of FIG. 9(c) displays the number of scenes that passed verification and the number of scenes that failed verification. In addition, in this embodiment, the user can also check detailed scenes that failed verification as shown in FIG. 9(d) by pressing a details confirmation button 903 included in this screen. When the processing of S713 is completed, this processing ends.
[0100] Fig. 10 is a flowchart showing the procedure of the overall verification process of S703 in Fig. 7. When the overall verification process is started, the screen of Fig. 8(c) including progress information of the overall verification process is displayed on the display unit 28. As described above, this screen includes a cancel button 801 for issuing an instruction to interrupt the overall verification process.
[0101] 10, in S1001, the system control unit 50 determines whether an instruction to suspend the overall verification process has been issued. If it is determined that an instruction to suspend the overall verification process has been issued, that is, if the user has pressed the cancel button 801, this process ends. If it is determined that an instruction to suspend the overall verification process has not been issued, this process proceeds to S1002.
[0102] In S1002, the system control unit 50 updates the time remaining until the overall verification process is completed. This allows the user to grasp the remaining time for the overall verification process. In addition to the remaining time, in S1002, progress rate information indicating what percentage of the overall process has been completed may be displayed on the screen of FIG. 8(c).
[0103] Next, the system control unit 50 selects one file from among a plurality of files that are stored in the folder set as the target folder for the verification process and that satisfy the target conditions for the verification process set in S702.
[0104] Next, in S1003, the system control unit 50 verifies the signature value of the selected file. For example, if the selected file is a video file with the configuration shown in FIG. 5(b), the system control unit 50 first decrypts the signature value of the digital signature 533' of the history information 503' in the selected video file using the public key. If the digital signature 533' is generated using a private key that pairs with the public key, this signature value can be correctly decrypted using the public key. The system control unit 50 also executes a hash function on the binary data of the history 513' to generate a hash value, and determines whether the generated hash value matches the hash value decrypted using the public key.
[0105] Next, in S1004, the system control unit 50 determines whether or not the signature value has been successfully verified. In S1004, if the signature value is not correctly decrypted using the public key or if the two hash values do not match, it is determined that the signature value has been verified unsuccessfully, and the process proceeds to S1008, which will be described later. On the other hand, if the signature value is correctly decrypted using the public key and the two hash values match, it is determined that the signature value has been verified successfully, and the process proceeds to S1005.
[0106] In S1005, the system control unit 50 compares the overall hash values of the selected files. For example, if the selected file is a moving image file having the configuration shown in FIG. 5(b), the system control unit 50 executes a hash function on the binary data of moving image data 505' in this moving image file to generate a hash value. The system control unit 50 then compares the generated hash value with the overall moving image data hash value 524' in this moving image file.
[0107] Next, in S1006, the system control unit 50 determines whether these hash values match based on the comparison result in S1005. If it is determined that these hash values match, the process proceeds to S1007. If it is determined that these hash values do not match, the process proceeds to S1008.
[0108] In S1007, the system control unit 50 determines that the result of the overall verification process for the selected file is verification OK, and then the process proceeds to S1009.
[0109] In S1008, the system control unit 50 determines that the result of the overall verification process for the selected file is verification NG.
[0110] Next, in S1009, the system control unit 50 updates the verification result. Based on the updated verification result, the information indicating the verification result on the screen of Fig. 8(c) (information indicating the number of files verified as verified, the number of files verified as unverified, and how many instances of tampering were detected in each of the moving image files and still image files) is updated.
[0111] Next, in S1010, the system control unit 50 determines whether or not verification of all files subject to the overall verification process has been completed. Note that all files subject to the overall verification process are files stored in a folder set as a target folder for the verification process and that satisfy the target conditions for the verification process set in S702. If it is determined that verification of any file subject to the overall verification process has not been completed, this process returns to S1001. If it is determined that verification of all files subject to the overall verification process has been completed, this process ends.
[0112] Fig. 11 is a flowchart showing the procedure of the individual verification process of S712 in Fig. 7. When the individual verification process is started, the screen of Fig. 9(b) including progress information of the individual verification process is displayed on the display unit 28. As described above, this screen includes a cancel button 902 for issuing an instruction to interrupt the individual verification process.
[0113] 11, in S1101, the system control unit 50 determines whether an instruction to suspend the individual verification process has been issued. If it is determined that an instruction to suspend the individual verification process has been issued, that is, if the user has pressed the cancel button 902, this process ends. If it is determined that an instruction to suspend the individual verification process has not been issued, this process proceeds to S1102.
[0114] In S1102, the system control unit 50 updates the time remaining until the individual verification process is completed. This allows the user to grasp the remaining time for the individual verification process. In addition to the remaining time, in S1102, progress information indicating what percentage of the total has been completed may be displayed on the screen of FIG. 9(b).
[0115] Next, the system control unit 50 selects one moving image file from among the moving image files that have failed verification or the moving image files that have been set as target files for individual verification processing in S711.
[0116] Next, in S1103, the system control unit 50 verifies the signature value of the selected video file. Note that the signature value verification in S1103 is performed in the same manner as in S1003 described above.
[0117] Next, in S1104, the system control unit 50 determines whether or not the signature value has been successfully verified. Note that the determination in S1104 is performed in the same manner as in S1004 described above. If it is determined that the signature value has not been successfully verified, the process proceeds to S1108, which will be described later. If it is determined that the signature value has been successfully verified, the process proceeds to S1105.
[0118] In S1105, the system control unit 50 compares the individual hash values of the selected video file. Specifically, the system control unit 50 executes a hash function on the binary data of each GOP of video data 505' in the selected video file to generate multiple hash values corresponding to each GOP. The system control unit 50 then compares the generated multiple hash values with the video data hash values 527' for each GOP in the selected video file, which are the hash values of the GOPs corresponding to these hash values. This makes it possible to verify whether or not each individual scene (GOP) included in the video data has been tampered with.
[0119] Next, in S1106, the system control unit 50 determines whether or not all the comparisons in S1105 result in a match. If it is determined that all the comparisons in S1105 result in a match, the process proceeds to S1107. If it is determined that any of the comparisons in S1105 do not match, the process proceeds to S1108.
[0120] In S1107, the system control unit 50 determines that the verification result of the selected video file is OK. Then, the process proceeds to S1109.
[0121] In S1108, the system control unit 50 determines that the verification result of the selected moving image file is NG.
[0122] Next, in S1109, the system control unit 50 updates the verification result. Based on the updated verification result, the information indicating the verification result on the screen of Fig. 9(b) (the number of scenes verified as successful, and the number of scenes verified as unsuccessful) is updated.
[0123] Next, in S1110, the system control unit 50 determines whether a detail check instruction has been issued. In this embodiment, a detail check instruction can be issued by pressing the detail check button 901 on the screen of FIG. 9(b). If it is determined that a detail check instruction has been issued, the process proceeds to S1111. If it is determined that a detail check instruction has not been issued, the process proceeds to S1112.
[0124] In S1111, the system control unit 50 displays the details confirmation screen of Fig. 9(d) on the display unit 28. On this details confirmation screen, the scene for which verification failed can be confirmed in detail. Next, the process proceeds to S1112.
[0125] In S1112, the system control unit 50 determines whether or not verification of all files subject to individual verification processing has been completed. Note that all files subject to individual verification processing are video files that have failed verification or video files that were set as files subject to individual verification processing in S711. If it is determined that verification of any file subject to individual verification processing has not been completed, this processing returns to S1101. If it is determined that verification of all files subject to individual verification processing has been completed, this processing ends.
[0126] According to the above-described embodiment, when tampering is detected in an overall verification process using a hash value generated by applying a hash function to the entire video data, whether or not to execute an individual verification process using multiple hash values corresponding to each GOP of the video data is controlled. In other words, execution of the individual verification process, which performs detailed verification using multiple hash values, is limited to cases where tampering of the video data is detected. This reduces the processing time compared to a configuration in which individual verification is performed on any video file, thereby improving usability in verifying video data.
[0127] In the above-described embodiment, the overall verification process is performed on files stored in a folder designated by the user. This allows the user to designate the verification target on a folder-by-folder basis, rather than designating individual files, thereby improving usability in designating the verification target.
[0128] In the above-described embodiment, the overall verification process detects tampering of video data included in video files stored in a folder designated by the user, and also detects tampering of image data included in still image files stored in the folder. This allows the overall verification process to verify the video files and still image files stored in the folder designated by the user at the same time.
[0129] In the above-described embodiment, the overall verification process is executed on a plurality of files stored in a folder designated by the user and that satisfy the target conditions for the verification process designated by the user. This allows the verification targets of the overall verification process to be narrowed down to files stored in the folder designated by the user that satisfy the target conditions for the verification process designated by the user, and the overall verification process can be executed only on the files intended by the user. As a result, the time required to complete the overall verification process can be minimized.
[0130] Furthermore, in the above-described embodiment, the target conditions for the verification process include the file format, so that the verification targets for the overall verification process can be narrowed down to files in a file format specified by the user.
[0131] Furthermore, in the above-described embodiment, the target conditions for the verification process include a rating indicating the degree of favoriteness, so that the verification targets for the overall verification process can be narrowed down to files whose degree of favoriteness by the user is equal to or greater than a predetermined value.
[0132] Furthermore, in the above-described embodiment, if the predicted completion time of the individual verification process for verifying all video files that have failed verification is equal to or less than a predetermined reference time, the individual verification process is executed. In other words, the individual verification process is executed only if the time until completion is relatively short. This makes it possible to prevent the execution of an individual verification process that takes an unanticipated amount of time, thereby avoiding a situation in which the user has to wait for a process that may not be completed for some time.
[0133] In the above-described embodiment, the automatic execution of the individual verification process, which is a function for always executing the individual verification process when tampering with the video data is detected in the overall verification process, is set to enabled or disabled according to a user instruction, thereby reflecting the user's intention to always execute the individual verification process when tampering with the video data is detected in the overall verification process.
[0134] In the above-described embodiment, the automatic skip of the individual verification process, which is a function for not necessarily executing the individual verification process when tampering with the video data is detected in the overall verification process, is set to enabled or disabled according to a user instruction, thereby reflecting the user's intention of not necessarily executing the individual verification process when tampering with the video data is detected in the overall verification process.
[0135] Furthermore, in the above-described embodiment, if tampering with video data is detected in the overall verification process, the user is prompted to select whether or not to execute the individual verification process, thereby allowing the user's intention to be reflected in whether or not to execute the individual verification process.
[0136] In the above-described embodiment, the video file to be subjected to the individual verification process is selected by the user, which allows the user's intention to be reflected in the target of the individual verification process, thereby minimizing the time required to complete the individual verification process.
[0137] In the above-described embodiment, the information processing device is an imaging device that generates a moving image file.
[0138] In this embodiment, the items that can be set on the condition specification screen are not limited to those shown in Fig. 8(b). For example, the condition specification screen may further include an item for excluding files obtained by shooting with the digital camera 100 from the verification target, that is, an item for including files obtained by shooting or editing with a device other than the digital camera 100 as the verification target. This makes it possible to narrow down the verification target of the overall verification process to files obtained by shooting or editing with a device other than the digital camera 100.
[0139] Although the present embodiment has been described using a digital camera as an example of an information processing device, the information processing device is not limited to a digital camera. For example, the information processing device may be a smartphone or tablet terminal equipped with a shooting function. Furthermore, the information processing device may be a device such as a PC that acquires a video file obtained by shooting or editing using another device from the other device and performs the verification process shown in FIG. 7 described above.
[0140] The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program.The present invention can also be realized by a circuit (e.g., ASIC) that realizes one or more functions.
[0141] The disclosure of this embodiment includes the following configurations and methods. (Configuration 1) An information processing device comprising: means for acquiring a video file including video data composed of a plurality of frames and a plurality of types of hash values for detecting tampering with the video data; means for executing a first process for detecting tampering with the video data using a first type of hash value included in the video file, the first type of hash value being generated by running a hash function on the entire video data when the video data was shot; means for executing a second process for detecting tampering with the video data using a plurality of second type of hash values included in the video file, the second type of hash value being generated by running a hash function on each of a plurality of frame groups obtained by grouping frames that constitute the video data when the video data was shot; and means for controlling whether to execute the second process when tampering with the video data is detected in the first process. (Configuration 2) The information processing device according to configuration 1, further comprising means for allowing a user to specify a folder, wherein the first processing is executed on a file stored in the folder specified by the user. (Configuration 3) The information processing device described in Configuration 2, characterized in that the first processing detects tampering of video data contained in video files stored in a folder specified by the user, and further detects tampering of image data contained in still image files stored in the folder. (Configuration 4) An information processing device as described in configuration 2 or 3, further comprising a means for allowing a user to specify conditions for narrowing down files, wherein the first processing is performed on multiple files stored in a folder specified by the user and that satisfy the conditions. (Configuration 5) The information processing device according to configuration 4, wherein the conditions include a file format. (Configuration 6) The information processing device according to configuration 4 or 5, wherein the conditions include a rating indicating the degree of favoriteness. (Configuration 7) The information processing device according to any one of configurations 4 to 6, wherein the conditions include a file obtained by shooting or editing using a device other than the information processing device. (Configuration 8) The information processing device according to any one of configurations 1 to 7, characterized in that it is an imaging device that generates the moving image file. (Configuration 9) An information processing device described in any one of configurations 1 to 8, characterized in that the control means controls to execute the second process when the predicted completion time of the second process, which targets all video files in which tampering of video data has been detected in the first process, is less than or equal to a predetermined reference time. (Configuration 10) An information processing device described in any one of configurations 1 to 9, further comprising means for enabling or disabling a function that always executes the second processing when tampering with the video data is detected in the first processing in accordance with instructions from a user. (Configuration 11) An information processing device described in any one of configurations 1 to 9, further comprising a means for enabling or disabling a function that will not necessarily execute the second processing if tampering with the video data is detected in the first processing, in accordance with instructions from a user. (Configuration 12) An information processing device described in any one of configurations 1 to 11, further comprising means for allowing a user to select whether or not to execute the second processing when tampering with the video data is detected in the first processing. (Configuration 13) The information processing device according to any one of configurations 1 to 12, further comprising means for allowing a user to select a moving image file on which the second process is to be executed. (Configuration 14) The information processing device according to any one of configurations 1 to 13, wherein a predicted time for completion of the first process and a predicted time for completion of the second process are presented. [Explanation of symbols]
[0142] 50 System control section 100 digital cameras 505' video data 523' hash value 524' Hash value of entire video data 527' Video data hash value for each GOP
Claims
1. means for acquiring a video file including video data made up of a plurality of frames and a plurality of types of hash values for detecting tampering with the video data; means for executing a first process for detecting tampering of the video data using a first type of hash value included in the video file, the first type of hash value being generated by executing a hash function on the entire video data when the video data was shot; means for executing a second process for detecting tampering of the video data using a plurality of second-type hash values included in the video file, the second-type hash values being generated by executing a hash function on each of a plurality of frame groups obtained by grouping frames constituting the video data when the video data was shot; and an information processing apparatus comprising: means for controlling whether or not to execute the second process when tampering with the video data is detected in the first process.
2. The method further comprises means for allowing a user to specify a folder; 2. The information processing apparatus according to claim 1, wherein the first process is executed on a file stored in a folder designated by the user.
3. The information processing device according to claim 2, characterized in that the first processing detects tampering of video data contained in video files stored in a folder specified by the user, and further detects tampering of image data contained in still image files stored in the folder.
4. The device further includes a means for allowing a user to specify conditions for narrowing down the files; 3. The information processing apparatus according to claim 2, wherein the first process is executed on a plurality of files that are stored in a folder designated by a user and that satisfy the condition.
5. 5. The information processing apparatus according to claim 4, wherein the conditions include a file format.
6. 5. The information processing apparatus according to claim 4, wherein the condition includes a rating indicating a degree of favoriteness.
7. 5. The information processing apparatus according to claim 4, wherein the conditions include a file obtained by shooting or editing using an apparatus other than the information processing apparatus.
8. 2. The information processing apparatus according to claim 1, wherein the information processing apparatus is an image capturing apparatus that generates the moving image file.
9. The information processing device according to claim 1, characterized in that the control means controls the second processing to be executed when the predicted completion time of the second processing, which targets all video files in which tampering of video data has been detected in the first processing, is less than or equal to a predetermined reference time.
10. 2. The information processing device according to claim 1, further comprising means for enabling or disabling a function of always executing the second process when tampering with the video data is detected in the first process in accordance with a user's instruction.
11. 2. The information processing device according to claim 1, further comprising a means for enabling or disabling a function of not necessarily executing the second process if tampering with the video data is detected in the first process, in accordance with a user's instruction.
12. 2. The information processing apparatus according to claim 1, further comprising means for prompting a user to select whether or not to execute the second process when tampering with the video data is detected in the first process.
13. 2. The information processing apparatus according to claim 1, further comprising means for allowing a user to select a moving image file on which the second process is to be executed.
14. 2. The information processing apparatus according to claim 1, further comprising: displaying a predicted time for completion of the first process and a predicted time for completion of the second process.
15. A control method for an information processing device, comprising: acquiring a video file including video data composed of a plurality of frames and a plurality of types of hash values for detecting tampering with the video data; executing a first process for detecting tampering of the video data using a first type of hash value included in the video file, the first type of hash value being generated by executing a hash function on the entire video data when the video data was captured; a step of executing a second process for detecting tampering of the video data using a plurality of second-type hash values included in the video file, the second-type hash values being generated by executing a hash function on each of a plurality of frame groups obtained by grouping frames constituting the video data when the video data was shot; a step of controlling whether or not to execute the second process when tampering with the video data is detected in the first process.
16. A program for causing a computer to execute a control method for an information processing device, The control method for the information processing device includes: acquiring a video file including video data composed of a plurality of frames and a plurality of types of hash values for detecting tampering with the video data; executing a first process for detecting tampering of the video data using a first type of hash value included in the video file, the first type of hash value being generated by executing a hash function on the entire video data when the video data was captured; a step of executing a second process for detecting tampering of the video data using a plurality of second-type hash values included in the video file, the second-type hash values being generated by executing a hash function on each of a plurality of frame groups obtained by grouping frames constituting the video data when the video data was shot; and if tampering with the video data is detected in the first process, controlling whether or not to execute the second process.
Citation Information
Patent Citations
Verification apparatus, and verification program
JP2007336457A