Imaging device and its control method, program, and storage medium

The imaging device generates and records multiple image data types with varying resolutions and uses hash values and digital signatures to verify tampering and maintain provenance, addressing the inefficiencies in existing technologies and ensuring image authenticity.

JP2026067289APending Publication Date: 2026-04-20CANON KK
View PDF 8 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
CANON KK
Filing Date
2024-10-08
Publication Date
2026-04-20

AI Technical Summary

Technical Problem

Existing imaging devices lack efficient methods to verify image tampering while minimizing the effort required to generate image data for provenance, and existing technologies do not specify what type of image data should be included in the provenance history.

Method used

The imaging device generates main, thumbnail, and display image data with varying resolutions and records them along with image history, using hash values and digital signatures to verify tampering and maintain provenance.

Benefits of technology

This approach allows for efficient verification of image tampering and reduces the effort in generating image data for provenance, ensuring authenticity and integrity of image files.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026067289000001_ABST
    Figure 2026067289000001_ABST
Patent Text Reader

Abstract

This invention provides an imaging device that reduces the effort required to generate image data to be included in the image history, while also allowing for verification of any tampering. [Solution] The system includes an imaging unit that captures an image of a subject and generates an image signal; an image processing unit that generates main image data and thumbnail image data with a lower resolution than the main image data from the image signal, and also generates display image data with a lower resolution than the main image data and a higher resolution than the thumbnail image data, depending on the resolution of the main image data; and a recording unit that records the main image data, thumbnail image data, and the history of the image file in the image file, and records the display image data in the history if display image data exists.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an imaging device having an image forgery prevention function.

Background Art

[0002] A general digital camera basically has a still image shooting function. From the image data captured by an image sensor, high-resolution main image data and low-resolution thumbnail image data are generated, and an image file is generated by combining them.

[0003] In such a digital camera, when reproducing and displaying an image, if trying to display the high-resolution main image data, it takes a long time to read and a long time to display. Also, if trying to display the low-resolution thumbnail image data, it can be displayed quickly, but it looks bad due to the low resolution. Therefore, in order to achieve both fast display and good appearance, there are cameras that generate intermediate display image data that is neither the main image data nor the thumbnail image data and include it in the image file. Furthermore, in the case of low-resolution shooting settings, in order to prioritize the file size, there is also a measure not to include this display image data in the image file.

[0004] On the other hand, in recent years, information sharing via the Internet has been actively carried out, and anyone can publicly disclose or transmit various information to an unspecified large number of people. Also, various processes can be performed on digital images. Therefore, there is a possibility that information is transmitted from an unreliable source or that the publicly disclosed information has been illegally forged.

[0005] Patent Document 1 discloses a technique for preventing such illegal forgery. When shooting is performed in a forgery prohibition mode, a hash value is generated and attached to the image to prohibit image forgery.

[0006] Furthermore, Non-Patent Document 1 proposes attaching metadata or image data indicating the editing content performed on the image to the image file in order to authenticate the source, history, and origin of the image. [Prior art documents] [Patent Documents]

[0007] [Patent Document 1] Japanese Patent Publication No. 2008-5421 [Non-patent literature]

[0008] [Non-Patent Document 1] Coalition for Content Provenance and Authenticity (C2PA), “C2PA Specifications”,<Technical Specifications Version 1.2> [online], November 3, 2022, [searched January 23, 2023], Internet<URL:https: / / c2pa.org / specifications / specifications / 1.2 / specs / C2PA_Specification.html> [Overview of the Initiative] [Problems that the invention aims to solve]

[0009] According to the technology described in Patent Document 1, users can know whether an image has been altered. However, since there is no mention of how to include image data in the provenance, it is not possible to compare the altered image with the original image and therefore not possible to understand exactly what kind of alteration has been made.

[0010] Furthermore, according to the technology described in Non-Patent Document 1, by embedding the original image data and original metadata as the provenance within the image, it is possible to know what modifications were made if the image was subsequently edited. However, it is not mentioned what kind of image data should be used as the original image data to be included in the provenance.

[0011] Therefore, for example, if the above display image data is adopted as the original image data to be included in the provenance history, adopting the display image data uniformly would necessitate the creation of separate display image data if it does not exist, in order to include it in the provenance history.

[0012] This invention has been made in view of the above-mentioned problems, and its purpose is to provide an imaging device that can verify the content of tampering while reducing the effort required to generate image data to be included in the history of the image. [Means for solving the problem]

[0013] The imaging device according to the present invention is characterized by comprising: imaging means for capturing an image of a subject and generating an image signal; image processing means for generating main image data and thumbnail image data having a lower resolution than the main image data from the image signal, and for generating display image data having a lower resolution than the main image data and a higher resolution than the thumbnail image data, depending on the resolution of the main image data; and recording means for recording the main image data, the thumbnail image data, and the history of the image file in an image file, and for recording the display image data in the history if the display image data exists. [Effects of the Invention]

[0014] According to the present invention, it is possible to verify the content of the tampering while reducing the effort required to generate image data to be included in the image's history. [Brief explanation of the drawing]

[0015] [Figure 1]A diagram showing the appearance of a digital camera, which is an embodiment of the imaging device of the present invention. [Figure 2] A block diagram showing the configuration of the digital camera. [Figure 3] A flowchart showing the procedure of the main process of the shooting operation in the digital camera. [Figure 4] A diagram showing an example of a screen for setting the resolution of a still image displayed on the digital camera. [Figure 5] A flowchart showing the operation of the shooting process. [Figure 6A] A diagram showing an example of the configuration of an image file. [Figure 6B] A diagram showing an example of the configuration of an image file. [Figure 6C] A diagram showing an example of the configuration of an image file. [Figure 6D] A diagram showing an example of the configuration of an image file.

Embodiments for Carrying Out the Invention

[0016] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the invention according to the claims. Although a plurality of features are described in the embodiments, not all of these plurality of features are essential for the invention, and the plurality of features may be arbitrarily combined. Further, in the accompanying drawings, the same or similar configurations are denoted by the same reference numerals, and duplicate explanations are omitted.

[0017] <Appearance of Digital Camera 100> FIG. 1 is a diagram showing the appearance of a digital camera 100, which is an embodiment of the imaging device of the present invention. FIG. 1(a) is a front perspective view of the digital camera 100, and FIG. 1(b) is a rear perspective view of the digital camera 100.

[0018] In Figure 1, the display unit 28 is a display unit located on the back of the digital camera 100, and displays images and various information. The touch panel 70a can detect touch operations on the display surface (touch operation surface) of the display unit 28. The viewfinder-external display unit 43 is a display unit located on the top surface of the digital camera 100, and displays various settings of the digital camera 100, including shutter speed and aperture value. The shutter button 61 is an operating member for issuing a shooting command. The mode selector switch 60 is an operating member for switching between various modes. The terminal cover 40 is a cover that protects the connector (not shown) for connecting the digital camera 100 to an external device, such as a connecting cable.

[0019] The main electronic dial 71 is a rotary control element, and by rotating it, settings such as shutter speed and aperture value can be changed. The power switch 72 is a control element that switches the power of the digital camera 100 ON and OFF. The sub-electronic dial 73 is a rotary control element, and by rotating it, the selection frame (cursor) can be moved and images can be advanced. The four-way key 74 is configured so that the up, down, left, and right parts can be pressed, and processing can be performed according to the part of the four-way key 74 that is pressed. The SET button 75 is a push button and is mainly used to confirm selection items.

[0020] The video button 76 is used to instruct the start and stop of video recording. The AE lock button 77 is a push button, and by pressing the AE lock button 77 in shooting standby mode, the exposure state can be fixed. The zoom button 78 is an operation button for switching the zoom mode ON and OFF in the live view display (LV display) in shooting mode. By turning the zoom mode ON and then operating the main electronic dial 71, the live view image (LV image) can be enlarged or reduced. In playback mode, the zoom button 78 functions as an operation button for enlarging the playback image or increasing its magnification. The playback button 79 is an operation button for switching between shooting mode and playback mode. By pressing the playback button 79 in shooting mode, the camera switches to playback mode, and the latest image among the images recorded on the recording medium 200 (described later) can be displayed on the display unit 28. The menu button 81 is a push button used to instruct the display of the menu screen, and when the menu button 81 is pressed, a menu screen where various settings can be made is displayed on the display unit 28. The user can intuitively make various settings using the menu screen displayed on the display unit 28, the four-way key 74, and the SET button 75.

[0021] The touch bar 82 (multifunction bar: M-Fn bar) is a line-shaped touch operation component (line touch sensor) capable of accepting touch operations. The touch bar 82 is positioned so that it can be touched with the right thumb when the grip section 90 is held with the right hand (with the little finger, ring finger, and middle finger) so that the shutter button 61 can be pressed with the right index finger. In other words, the touch bar 82 is positioned so that it can be operated when the user is looking through the viewfinder with their eyepiece 16 and is ready to press the shutter button 61 at any time (shooting posture). The touch bar 82 is a reception area that can accept tap operations (touching and releasing without moving within a predetermined period of time), left and right sliding operations (touching and then moving the touch position while keeping the touch on the bar). The touch bar 82 is a different operation component from the touch panel 70a and does not have a display function.

[0022] The communication terminal 10 is a communication terminal for the digital camera 100 to communicate with the detachable lens unit 150 (see Figure 2). The eyepiece 16 is the eyepiece of the eyepiece viewfinder 17 (a look-through type viewfinder), and the user can view the image displayed on the internal EVF 29 (Electronic View Finder: see Figure 2) through the eyepiece 16. The eyepiece detection unit 57 is an eyepiece detection sensor that detects whether or not the user (photographer) is looking through the eyepiece 16. The cover 202 is the cover of the slot for storing the recording medium 200 (see Figure 2). The grip 90 is a holding part shaped to be easy for the user to grip with their right hand when holding the digital camera 100. The shutter button 61 and the main electronic dial 71 are positioned so that they can be operated with the index finger of the right hand when the digital camera 100 is held with the grip 90 held by the little finger, ring finger, and middle finger of the right hand. Furthermore, in the same configuration, the sub-electronic dial 73 and touch bar 82 are positioned so that they can be operated with the right thumb. The thumb rest section 91 (thumb standby position) is a grip component located on the back of the digital camera 100, in a place where it is easy to rest the thumb of the right hand holding the grip section 90 when no other operating components are being used. The thumb rest section 91 is made of rubber or other material to enhance the holding power (grip).

[0023] <Configuration of Digital Camera 100> Figure 2 is a block diagram showing an example configuration of the digital camera 100. The lens unit 150 is a lens unit that incorporates an imaging optical system and is interchangeable with the digital camera 100. The lens 103 that constitutes the imaging optical system is usually composed of multiple lenses, but in Figure 2 it is simplified and shown as only one lens. Communication terminal 6 is a communication terminal for the lens unit 150 to communicate with the digital camera 100, and communication terminal 10 is a communication terminal for the digital camera 100 to communicate with the lens unit 150. The lens unit 150 communicates with the system control unit 50 via these communication terminals 6 and 10. In the lens unit 150, the internal lens system control circuit 4 controls the aperture 1 via the aperture drive circuit 2. Also in the lens unit 150, the lens system control circuit 4 focuses by displacing the position of the lens 103 via the AF drive circuit 3.

[0024] The shutter 101 is a focal-plane shutter that allows the exposure time of the imaging unit 22 to be freely controlled by the system control unit 50.

[0025] The imaging unit 22 includes an image sensor, such as a CCD or CMOS element, which converts an optical image into an electrical signal. The image sensor in the imaging unit 22 may have an image plane phase difference sensor that outputs defocus amount information to the system control unit 50. The A / D converter 23 converts the analog signal output from the imaging unit 22 into a digital signal.

[0026] The image processing unit 24 performs predetermined processing (such as resizing, pixel interpolation, and color conversion) on the image data from the A / D converter 23 or the image data from the memory control unit 15. The image processing unit 24 also performs predetermined calculations using the captured image data, and the system control unit 50 performs exposure control and distance measurement control based on the calculation results obtained by the image processing unit 24. This enables TTL (through-the-lens) AF (autofocus), AE (automatic exposure), EF (flash pre-flash), etc. The image processing unit 24 further performs predetermined calculations using the captured image data and performs TTL AWB (auto white balance) processing based on the obtained calculation results.

[0027] The output data from the A / D converter 23 is written to the memory 32 via the image processing unit 24 and the memory control unit 15. Alternatively, the output data from the A / D converter 23 is written to the memory 32 via the memory control unit 15 without going through the image processing unit 24. The memory 32 stores image data obtained by the imaging unit 22 and converted into digital data by the A / D converter 23, as well as image data for display on the display unit 28 and EVF 29. The memory 32 has sufficient storage capacity to store a predetermined number of still images, a predetermined amount of video footage, and audio.

[0028] Furthermore, memory 32 also serves as memory for image display (video memory). The D / A converter 19 converts the image data for image display stored in memory 32 into an analog signal and supplies it to the display unit 28 and EVF 29. In this way, the image data for display written to memory 32 is displayed by the display unit 28 and EVF 29 via the D / A converter 19. The display unit 28 and EVF 29 are displays made of LCD, organic EL, etc., and display according to the analog signal from the D / A converter 19. The digital signal that has been A / D converted by the A / D converter 23 and stored in memory 32 is converted into an analog signal by the D / A converter 19 and sequentially transferred to the display unit 28 or EVF 29 for display, thereby enabling live view display (LV). Hereinafter, the image displayed in live view display will be referred to as a live view image (LV image).

[0029] The system control unit 50 is a control unit consisting of at least one processor and / or at least one circuit, and controls the entire digital camera 100. The system control unit 50 is both a processor and a circuit. The system control unit 50 realizes each of the processes of this embodiment, which will be described later, by executing a program recorded in the non-volatile memory 56. The system control unit 50 also performs display control by controlling the memory 32, D / A converter 19, display unit 28, EVF 29, etc.

[0030] System memory 52 is, for example, RAM, and the system control unit 50 loads constants, variables, programs read from non-volatile memory 56, etc., for the operation of the system control unit 50 into system memory 52.

[0031] The non-volatile memory 56 is an electrically erasable and recordable memory, such as an EEPROM. Constants for the operation of the system control unit 50, programs, etc., are stored in the non-volatile memory 56. The program referred to here is a program for executing various flowcharts, which will be described later in this embodiment.

[0032] The system timer 53 is a timekeeping unit that measures the time used for various controls and the time of the built-in clock.

[0033] The communication unit 54 transmits and receives video and audio signals to and from external devices connected wirelessly or via wired cables. The communication unit 54 can also connect to wireless LAN (Local Area Network) and the internet. Furthermore, the communication unit 54 can communicate with external devices using Bluetooth® and Bluetooth Low Energy. The communication unit 54 can transmit images (including LV images) captured by the imaging unit 22 and images recorded on the recording medium 200, and can receive various information from external devices, such as image data and instructions to start video recording. When an instruction to start video recording is received from an external device, the communication unit 54 can notify the user of the instruction by illuminating the light-emitting unit 102 or emitting an electronic sound from the speaker 92. Examples of external devices that can communicate include smartphones, tablet PCs, and desktop PCs.

[0034] The attitude detection unit 55 detects the orientation of the digital camera 100 relative to the direction of gravity. Based on the orientation detected by the attitude detection unit 55, it is possible to determine whether the image captured by the imaging unit 22 was taken with the digital camera 100 held horizontally or vertically. The system control unit 50 can add orientation information corresponding to the orientation detected by the attitude detection unit 55 to the image file of the image captured by the imaging unit 22, or rotate the image before recording. An acceleration sensor or gyro sensor can be used as the attitude detection unit 55. The attitude detection unit 55 can also use the acceleration sensor or gyro sensor to detect the movement of the digital camera 100 (pan, tilt, lift, whether it is stationary or not, etc.).

[0035] The eyepiece detection unit 57 is an eyepiece detection sensor that detects when an eye (object) approaches (approaches) and moves away (away from) the eyepiece section 16 of the eyepiece viewfinder 17 (hereinafter simply referred to as "viewfinder"). The system control unit 50 switches the display / hide status of the display unit 28 and the EVF 29 according to the state detected by the eyepiece detection unit 57. More specifically, at least in the shooting standby state and when the display destination switching setting is set to automatic switching, when not using an eyepiece, the display destination is set to the display unit 28 and the display is turned on, and the EVF 29 is hidden. When using an eyepiece, the display destination is set to the EVF 29 and the display is turned on, and the display unit 28 is hidden. As the eyepiece detection unit 57, for example, an infrared proximity sensor can be used to detect the approach of any object to the eyepiece section 16 of the viewfinder 17 which has a built-in EVF 29. When an object approaches, infrared light emitted from the light-emitting unit (not shown) of the eyepiece detection unit 57 is reflected by the object and received by the light-receiving unit (not shown) of the infrared proximity sensor. The amount of infrared light received can be used to determine how close the object is to the eyepiece unit 16.

[0036] In this way, the eyepiece detection unit 57 performs eyepiece detection to detect the proximity distance of an object to the eyepiece unit 16. When an object is detected approaching the eyepiece unit 16 within a predetermined distance from the non-eyepiece state, it is detected that the user has made eye contact. When the object that was detected approaching moves away from the eyepiece state beyond a predetermined distance, it is detected that the user has moved away. The threshold for detecting eye contact and the threshold for detecting eye separation may be different, for example, by providing hysteresis. After eye contact is detected, the user remains in the eyepiece state until eye separation is detected. After eye separation is detected, the user remains in the non-eyepiece state until eye contact is detected again. Note that the infrared proximity sensor is just one example, and the eyepiece detection unit 57 may use any other sensor that can detect a state that can be considered as eye contact.

[0037] The GPS receiver 119 receives GPS information from GPS satellites to calculate location and time information. The digital camera 100 receives GPS information from the GPS receiver 119 and calculates location and time information based on the received GPS information. The digital camera 100 can add this calculated location and time information to the captured image.

[0038] The hash value generation unit 210 generates (calculates) a hash value by applying a hash function to the image file. Alternatively, the system control unit 50 may generate the hash value instead of the hash value generation unit 210. Details of the hash value generation process will be described later.

[0039] The external viewfinder display unit 43 displays various camera settings, including shutter speed and aperture, via the external viewfinder display unit drive circuit 44.

[0040] The power control unit 80 consists of a battery detection circuit, a DC-DC converter, a switch circuit for switching which blocks are energized, and detects whether a battery is installed, the type of battery, and the remaining battery level. The power control unit 80 also controls the DC-DC converter based on the detection results and instructions from the system control unit 50, supplying the necessary voltage to each part, including the recording medium 200, for the required period. The power supply unit 30 consists of primary batteries such as alkaline batteries and lithium batteries, secondary batteries such as NiCd batteries, NiMH batteries and Li-ion batteries, and an AC adapter.

[0041] The recording medium I / F18 is an interface to the recording medium 200, such as a memory card or hard disk. The recording medium 200 is a recording medium such as a memory card for recording captured images, and is composed of semiconductor memory, magnetic disks, etc.

[0042] The operation unit 70 is an input unit that receives operations from the user and is used to input various operation instructions to the system control unit 50. As shown in Figure 2, the operation unit 70 includes a shutter button 61, a mode selector switch 60, a power switch 72, a touch panel 70a, and other operating members 70b. Other operating members 70b include a main electronic dial 71, a sub electronic dial 73, a four-way key 74, a SET button 75, a video button 76, an AE lock button 77, a zoom button 78, a playback button 79, a menu button 81, a touch bar 82, and the like.

[0043] The shutter button 61 is equipped with a first shutter switch 62 and a second shutter switch 64. The first shutter switch 62 turns ON during the operation of the shutter button 61, specifically when it is half-pressed (indicating preparation for shooting), and generates a first shutter switch signal SW1. The system control unit 50 starts shooting preparation operations such as AF (autofocus) processing, AE (automatic exposure) processing, AWB (auto white balance) processing, and EF (flash pre-flash) processing in response to the first shutter switch signal SW1.

[0044] The second shutter switch 64 turns ON when the shutter button 61 is fully pressed (shooting instruction), generating the second shutter switch signal SW2. The system control unit 50 starts a series of shooting operations, from reading the signal from the imaging unit 22 to writing the captured image as an image file to the recording medium 200, in response to the second shutter switch signal SW2.

[0045] The mode switch 60 switches the operating mode of the system control unit 50 to one of the following: still image shooting mode, video shooting mode, playback mode, etc. Modes included in the still image shooting mode include auto shooting mode, auto scene detection mode, manual mode, aperture priority mode (Av mode), shutter speed priority mode (Tv mode), and program AE mode (P mode). There are also various scene modes and custom modes that provide shooting settings for different shooting scenes. The user can switch directly to any of these modes using the mode switch 60. Alternatively, the user can switch to a list screen of shooting modes using the mode switch 60, and then selectively switch to one of the displayed modes using another operating element. Similarly, the video shooting mode may also include multiple modes.

[0046] The touch panel 70a is a touch sensor that detects various touch operations on the display surface of the display unit 28 (the operating surface of the touch panel 70a). The touch panel 70a and the display unit 28 can be configured as an integrated unit. For example, the touch panel 70a is configured such that its light transmittance does not interfere with the display of the display unit 28, and is mounted on the upper layer of the display surface of the display unit 28. Then, the input coordinates on the touch panel 70a are associated with the display coordinates on the display surface of the display unit 28. This makes it possible to provide a GUI (Graphical User Interface) that makes it seem as if the user can directly operate the screen displayed on the display unit 28.

[0047] The system control unit 50 can detect the following operations or states on the touch panel 70a. - A finger or pen that was not previously touching the touch panel 70a now touches the touch panel 70a, i.e., the start of a touch (hereinafter referred to as Touch-Down). • The state in which the touch panel 70a is being touched with a finger or pen (hereinafter referred to as Touch-On). • The finger or pen is moving while touching the touch panel 70a (hereinafter referred to as Touch-Move). - The finger or pen that was touching the touch panel 70a has been removed (released), i.e., the touch has ended (hereinafter referred to as Touch-Up). • The state in which nothing is being touched on the touch panel 70a (hereinafter referred to as Touch-Off) When a touchdown is detected, a touch-on is also detected simultaneously. After a touchdown, touch-ons are usually detected continuously unless a touch-up is detected. Touch-ons are also detected simultaneously if a touch-move is detected. Even if a touch-on is detected, a touch-move will not be detected if the touch position has not moved. After all fingers or pens that were touching have been detected as having touched up, a touch-off occurs.

[0048] These operations and states, as well as the position coordinates of the finger or pen touching the touch panel 70a, are notified to the system control unit 50 via the internal bus. The system control unit 50 then determines what kind of operation (touch operation) was performed on the touch panel 70a based on the notified information.

[0049] Regarding touch movements, the direction of movement of a finger or pen on the touch panel 70a can also be determined for each vertical and horizontal component on the touch panel 70a based on the change in position coordinates. If a touch movement of a predetermined distance or more is detected, it is determined that a slide operation has been performed. An operation in which a finger is touched on the touch panel 70a and then quickly moved a certain distance and released is called a flick. In other words, a flick is an operation in which the finger is quickly traced across the touch panel 70a as if flicking it. If a touch movement of a predetermined distance or more at a predetermined speed or faster is detected, and a touch-up is then detected, it can be determined that a flick has been performed (it can be determined that a flick followed a slide operation). Furthermore, a touch operation in which multiple locations (for example, two points) are touched together (multitouch) and the touch positions are brought closer together is called a pinch-in, and a touch operation in which the touch positions are moved further apart is called a pinch-out. Pinch-out and pinch-in are collectively referred to as a pinch operation (or simply a pinch).

[0050] The touch panel 70a may be of any type from among various types of touch panels, such as resistive, capacitive, surface acoustic wave, infrared, electromagnetic induction, image recognition, and optical sensor types. There are methods that detect a touch when there is contact with the touch panel, and methods that detect a touch when a finger or pen approaches the touch panel, and either method is acceptable.

[0051] Next, Figure 3 is a flowchart showing the main processing steps for the shooting operation in the digital camera 100. Each process in Figure 3 is realized by the system control unit 50 loading the program stored in the non-volatile memory 56 into the system memory 52 and executing it. S represents the step number.

[0052] In S301, the system control unit 50 determines whether a setting instruction to change the tamper-proof mode to "on" has been given. If a setting instruction to change the tamper-proof mode to "on" has been given, the system control unit 50 proceeds to S302; otherwise, it proceeds to S303. In this case, if the image is taken with the tamper-proof mode "on," the provenance information 603 (see Figure 6) is included in the image, and if the image is taken with the tamper-proof mode "off," the provenance information 603 is not included in the image. When the tamper-proof mode is "on," changes can be detected by the hash function and signature value mechanism described later, and malicious tampering can be prevented.

[0053] In S302, the system control unit 50 changes the setting of the tamper-proof mode to "on" and stores it in the memory 32.

[0054] In S303, the system control unit 50 changes the setting of the tamper-proof mode to off and stores it in the memory 32.

[0055] In S304, the system control unit 50 determines whether or not a setting for the still image resolution has been instructed. If a setting for the still image resolution has been instructed, the system control unit 50 proceeds to S305; otherwise, it proceeds to S309. Figure 4 shows an example of the screen for setting the still image resolution in this case, and it is possible to change the setting from L (Large: high resolution) to S2 (Small2: low resolution). The resolutions for each setting from L to S2 are predetermined sizes for each model depending on the device's performance, and different values ​​are set for each model so that the relationship is L > M > S1 > S2.

[0056] In S305, the system control unit 50 determines whether the resolution setting for the still image has been set to high resolution. If the system control unit 50 has been set to high resolution, it proceeds to S306; otherwise, it proceeds to S307. In this case, the high resolution setting is assumed to be the settings from L to S1, excluding S2, but is not limited to these.

[0057] In S306, the system control unit 50 changes the resolution of the still image to a specified resolution setting from L, which is the highest resolution, to S1, and stores it in the memory 32.

[0058] In S307, the system control unit 50 determines whether the resolution setting for the still image has been set to a low resolution. If the system control unit 50 has been set to a low resolution, it proceeds to S308; otherwise, it proceeds to S309. In this case, the low resolution setting is assumed to be the setting in S2, but is not limited to that.

[0059] In S308, the system control unit 50 changes the resolution of the still image to the low resolution setting of S2 and stores it in the memory 32.

[0060] In S309, the system control unit 50 determines whether or not a still image capture instruction has been given, such as by pressing the shutter button 61. If a still image capture instruction has been given, the system control unit 50 proceeds to S310; otherwise, it proceeds to S311.

[0061] In S310, the system control unit 50 performs the imaging process described later using Figure 5.

[0062] In S311, the system control unit 50 determines whether or not a main processing termination instruction has been issued by the power switch 72 or the like. If a main processing termination instruction has been issued, the main processing is terminated; otherwise, the process returns to S301.

[0063] The procedure for the shooting process in S310 of Figure 3 will be described below with reference to Figure 5. Figure 5 is a flowchart showing an example of the operation up to the generation of a still image file during shooting in this embodiment. This process is started when the system control unit 50 receives a shooting start operation, such as pressing the shutter button 61, and ends when it receives a shooting end operation, such as canceling the pressing of the shutter button 61.

[0064] In S501, the system control unit 50 drives the shutter 101 located on the subject side of the imaging unit 22 in order to control the exposure time.

[0065] In S502, the system control unit 50 instructs the imaging unit 22 to perform imaging processing, which converts the light received from the subject via the shutter 101 into an electrical signal (analog image signal).

[0066] In S503, the system control unit 50 performs image processing such as development and encoding on the electrical signal obtained by the imaging process described above to generate the main image data. In this case, the main image data has a larger file size and higher resolution than the thumbnail image data and display image data described later.

[0067] In S504, the system control unit 50 performs image processing, such as compression, on the main image data to generate thumbnail image data. In this case, the thumbnail image data has a smaller file size and lower resolution than the main image data and the display image data described later. Furthermore, if the main image data is edited, the thumbnail image data is regenerated to match the content.

[0068] In S505, the system control unit 50 determines whether the setting is high resolution from L to S1. If the setting is high resolution from L to S1, the system control unit 50 proceeds to S506. Otherwise, it proceeds to S507 without going through S506.

[0069] In S506, the system control unit 50 performs image processing, such as compression, on the main image data to generate display image data. In this case, the display image data has a lower resolution than the main image data but a higher resolution than the thumbnail image data. Display image data is used when the main image data would be too computationally intensive to process, but the thumbnail image data would be too coarse. For example, when displaying an image list with multiple images on one screen, reducing the number of images displayed may result in the images being displayed at a size where the thumbnails appear too coarse. In such cases, by referring to and displaying the display image data instead of the thumbnails, the images are displayed more naturally, resulting in a richer user experience. In other words, when displaying an image list, the system determines whether to display display image data or thumbnail image data depending on the display size or the number of images displayed on one screen. Furthermore, if the main image data is edited, the display image data is regenerated to match the content. This display image data is recorded together with the main image data in a single file in the multi-picture format defined by the Camera & Imaging Products Association standard.

[0070] In S507, the system control unit 50 generates imaging information 602 as shown in Figures 6A to 6D. The imaging information 602 is information obtained when the imaging process for generating this image data is performed, and includes information such as the date and time of shooting, the photographer, the image size, the manufacturer and model of the imaging device, various shooting parameters set at the time of shooting, and the shooting location. The imaging information 602 is generated in accordance with a predetermined technical standard (for example, EXIF ​​(Exchangeable image file format)).

[0071] In S508, the system control unit 50 determines whether the tamper-proof mode setting is enabled or disabled. If the tamper-proof mode setting is enabled, the process proceeds to S510; otherwise, the process proceeds to S509.

[0072] In S509, the system control unit 50 generates the shooting information 602 as metadata 601, as shown in Figures 6A to 6D. If the image is a high-resolution image, it adds display image data 606 in addition to the metadata 601, thumbnail image data 604, and main image data 605 to generate an image file with no history. Here, the image file is generated according to a format such as JPEG or MPEG.

[0073] Figures 6A and 6C show examples of image file structures when the tamper-proof mode setting is off and there is no provenance information. Figure 6A shows an example of an image file taken with a high-resolution setting that does not include provenance information 603, and Figure 6C shows an example of an image file taken with a low-resolution setting that does not include provenance information 603. The former includes display image data 606, while the latter does not.

[0074] In S510, the system control unit 50 determines whether or not display image data has already been generated. If display image data has already been generated, the system control unit 50 proceeds to S511; otherwise, it proceeds to S512. In this embodiment, the presence or absence of display image data is determined in S510, but instead, for example, the data resolution may be determined. This is because, in this flow, the presence or absence of display image data is uniquely determined according to the data resolution. That is, if the resolution setting is high resolution from L to S1, the process proceeds to S511; otherwise, the process proceeds to S512. Also, since the setting of the data resolution has already been determined in S505, the result of the determination in S505 may be reused instead of making a new determination.

[0075] In S511, the system control unit 50 generates history information 603 with embedded display image data.

[0076] The provenance information 603 is information used to prove the authenticity of the image data 605 and is used when verifying the source and provenance of the image data 605. The provenance information 603 is generated in accordance with a predetermined technical standard (for example, C2PA (Coalition for Content Prevenance and Authenticity)) and has a prescribed structure. The provenance information 603 includes the provenance (Assertion) 613 and a hash value 623 and a digital signature 633 to guarantee the provenance 613. The provenance 613 stores provenance identification information (Manifest ID) to uniquely identify the provenance, an editing history showing the editing content of the image data 605, editing tool information showing the tools used for editing, and creator information of the image data 605. Here, since the image data 605 generated in step S503 has just been generated by shooting and has not been edited by an editing application or the like, the editing history stores information indicating "generation", and the editing tool stores information indicating the imaging device.

[0077] In this case, the provenance information 603 can embed the image data at the time of shooting in order to check how the main image data 605 has changed when it has been edited, through comparative display. In S511, by embedding the display image data 614 in the provenance information 613, comparative display is achieved using an image that is lighter than the main image data 605 and of higher quality than the thumbnail image data 604.

[0078] In S512, the system control unit 50 generates history information 603 with embedded thumbnail image data. In this case, the main image data may be used instead of the thumbnail image data.

[0079] As a result, S512 can embed the thumbnail image data 615 into the history 613, enabling a comparative display to check what kind of editing has been done without the trouble of recreating the display image data.

[0080] In S513, the system control unit 50 applies a hash function to the binary data of the thumbnail image data 604, the main image data 605, the display image data 606, and the history data 613 to generate a hash value 623. A hash value may also be generated from the binary data of the shooting information 602.

[0081] In S514, the system control unit 50 generates a digital signature 633. The digital signature 633 includes information indicating the signature value, the signer, and the date and time of signing. The signature value is generated by encrypting the generated hash value 623 using a pre-prepared private key. The public key that forms the pair with the private key used here is also stored in the digital signature 633. In this case, in order to prove that the public key is from a trustworthy manufacturer, information indicating the manufacturer of the imaging device as the signer, and a public key certificate indicating that the public key has been authenticated by a certification authority may also be stored. By attaching such a digital signature 633 containing signer information to the image file 600, it can be shown that the image file is trustworthy. Note that instead of manufacturer information, imaging device model information may be used as signer information. The date and time of signing stores the date and time when the generation of the digital signature was completed.

[0082] In S515, the system control unit 50 generates metadata 601 from the image capture information 602 and the provenance information 603. If the image is a high-resolution image, it adds display image data 606 in addition to the metadata 601, thumbnail image data 604, and main image data 605 to generate an image file with provenance information. Here, the image file is generated according to a format such as JPEG or MPEG.

[0083] Figures 6B and 6D show examples of image file structures when provenance information is included. Figure 6B shows an example of an image file taken with a high-resolution setting that includes provenance information 603, and Figure 6D shows an example of an image file taken with a low-resolution setting that includes provenance information 603. The image file in Figure 6B includes thumbnail image data 604 in an area according to EXIF, display image data 606 in an area according to the multi-picture format, and display image data 614 with the same content as display image data 606 in the provenance information area. The image file in Figure 6D does not include display image data 606, and therefore does not include information corresponding to display image data 614 in the provenance information. Instead, the provenance information includes thumbnail image data 615 with the same content as thumbnail image data 604. Note that in Figures 6A to D, the same numbering is assigned to data with the same name, but if the files are different, their contents will naturally be different. In other words, the numbering is assigned to the type of data, and does not indicate that the data itself is the same.

[0084] In S516, the system control unit 50 determines whether or not an instruction has been given to terminate the shooting process. If an instruction has been given to terminate the shooting process, the system control unit 50 terminates the shooting process; otherwise, it repeats the process in S516.

[0085] As described above, in this embodiment, when the imaging device takes a picture, an image file is generated. The image file may be edited by an application or the like. If the image file is edited using an authorized editing tool and following a legitimate procedure, provenance information 603 is newly generated based on the edited content in accordance with a predetermined technical standard and is appended to the metadata of the image file and stored. Provenance information 603 is newly generated each time the image file is edited and is appended to the metadata 601 of the image file and stored. On the other hand, if the image file is edited using an unauthorized editing tool or by an improper procedure, provenance information 603 may not be attached to the image file, or the provenance information attached to the image file may not conform to the predetermined technical standard.

[0086] Furthermore, by generating hash values ​​and signature values, it becomes possible to detect tampering with image files. For example, a hash function is applied to the binary data of the main image data 605 of the image file to generate a hash value. Then, the generated hash value is compared with the hash value 624 of the image data of the image file to be checked. This allows verification of whether or not the main image data has been tampered with. Similarly, a hash function is applied to the binary data of the shooting information 602 of the image file to generate a hash value. Then, the generated hash value is compared with the hash values ​​of each of the shooting information of the image file to be checked. This makes it possible to verify whether or not the shooting date and time, shooting location, photographer, and other data have been tampered with. Similarly, by using the hash value 627 of the thumbnail image data and the hash value 628 of the display image data, it is also possible to verify whether or not the thumbnail image data 604 and display image data 606 have been tampered with.

[0087] Furthermore, a hash function is applied to the binary data of the history (613) to generate a hash value. This hash value is then compared to the hash value (626) of the history of the image file being evaluated. This allows verification of whether the history data has been tampered with. In this case, the binary data being compared may be more finely divided into units such as editing history, creator, thumbnail data, and metadata. The signature value can also be decrypted using a public key, and if the hash values ​​match, it can be determined that the signature value has been successfully verified. In this way, it is possible to embed a mechanism for detecting tampering into the image file itself.

[0088] Furthermore, in this embodiment, if display image data does not exist, thumbnail image data or the main image data is used as the image data to be embedded in the provenance history instead of the display image data. In this way, by changing the image data to be embedded in the provenance history depending on whether or not display image data exists, the effort required to generate new display image data is reduced, while still making it possible to verify the tampering by comparing the image data embedded in the provenance history with the edited main image data.

[0089] In the above embodiment, the decision in S510 determined whether to embed display image data or thumbnail image data in the provenance information. For example, the process could branch into a flow that creates display image data and a flow that does not, depending on the decision result in S505. In that case, when generating provenance information in the flow that creates display image data, provenance information with embedded display image data may be generated. Also, when generating provenance information in the flow that does not create display image data, provenance information with embedded thumbnail images may be generated.

[0090] (Other embodiments) Furthermore, the present invention can also be realized by supplying a program that implements one or more of the functions of the above-described embodiments to a system or device via a network or storage medium, and by a process in which one or more processors in the computer of that system or device read and execute the program. It can also be realized by a circuit (e.g., an ASIC) that implements one or more functions.

[0091] The disclosures herein include the following imaging devices and their control methods, programs, and storage media.

[0092] (Item 1) An imaging means that captures an image of a subject and generates an image signal, Image processing means that generates main image data and thumbnail image data with a lower resolution than the main image data from the aforementioned image signal, and generates display image data with a lower resolution than the main image data and a higher resolution than the thumbnail image data, depending on the resolution of the main image data. A recording means that records the main image data, the thumbnail image data, and the history of the image file in the image file, and, if the display image data exists, records the display image data in the history; An imaging device characterized by comprising:

[0093] (Item 2) The imaging apparatus according to item 1, characterized in that the image processing means generates the display image data when the resolution of the image data is higher than a predetermined resolution.

[0094] (Item 3) The imaging apparatus according to item 1, characterized in that the image processing means does not generate the display image data when the resolution of the image data is lower than a predetermined resolution.

[0095] (Item 4) The imaging apparatus according to item 3, characterized in that the recording means records the thumbnail image data in the history when the image processing means does not generate the display image data.

[0096] (Item 5) The imaging apparatus according to item 3, characterized in that the recording means records the image data in the history when the image processing means does not generate the display image data.

[0097] (Item 6) The imaging device according to any one of items 1 to 5, characterized in that the recording means records at least one of a hash value and a digital signature in the provenance.

[0098] (Item 7) The imaging device according to item 6, further comprising detection means for detecting tampering with the image data based on at least one of the hash value and the digital signature.

[0099] (Item 8) The imaging device according to any one of items 1 to 7, characterized in that when the main image data is edited, the thumbnail image data is also edited to match the main image data.

[0100] (Item 9) The imaging device according to any one of items 1 to 7, characterized in that when the main image data is edited, the display image data is also edited to match the main image data.

[0101] (Item 10) The imaging device according to any one of items 1 to 9, further comprising a switching means for switching between a mode in which the history is recorded in the image file and a mode in which the history is not recorded.

[0102] (Item 11) A method for controlling an imaging device that includes imaging means for capturing an image of a subject and generating an image signal, Image processing steps include generating main image data and thumbnail image data with a lower resolution than the main image data from the aforementioned image signal, and generating display image data with a lower resolution than the main image data and a higher resolution than the thumbnail image data, depending on the resolution of the main image data. A recording step in which the main image data, the thumbnail image data, and the history of the image file are recorded in the image file, and if the display image data exists, the display image data is recorded in the history; A control method for an imaging device, characterized by having the following features.

[0103] (Item 12) A program to cause a computer to execute each step of the control method for the imaging device described in item 11.

[0104] (Item 13) A computer-readable storage medium storing a program for causing a computer to execute each step of the control method for the imaging device described in claim 11.

[0105] The invention is not limited to the embodiments described above, and various modifications and variations are possible without departing from the spirit and scope of the invention. Accordingly, claims are attached to disclose the scope of the invention. [Explanation of symbols]

[0106] 100: Digital camera, 22: Imaging unit, 24: Image processing unit, 28: Display unit, 50: System control unit, 150: Lens unit

Claims

1. An imaging means that captures an image of a subject and generates an image signal, Image processing means that generates main image data and thumbnail image data with a lower resolution than the main image data from the aforementioned image signal, and generates display image data with a lower resolution than the main image data and a higher resolution than the thumbnail image data, depending on the resolution of the main image data. A recording means that records the main image data, the thumbnail image data, and the history of the image file in the image file, and, if the display image data exists, records the display image data in the history; An imaging device characterized by comprising:

2. The imaging apparatus according to claim 1, characterized in that the image processing means generates the display image data when the resolution of the image data is higher than a predetermined resolution.

3. The imaging apparatus according to claim 1, characterized in that the image processing means does not generate the display image data when the resolution of the image data is lower than a predetermined resolution.

4. The imaging apparatus according to claim 3, characterized in that the recording means records the thumbnail image data in the history when the image processing means does not generate the display image data.

5. The imaging apparatus according to claim 3, wherein the recording means records the image data in the history when the image processing means does not generate the display image data.

6. The imaging apparatus according to claim 1, characterized in that the recording means records at least one of a hash value and a digital signature in the provenance.

7. The imaging apparatus according to claim 6, further comprising detection means for detecting tampering with the image data based on at least one of the hash value and the digital signature.

8. The imaging apparatus according to claim 1, characterized in that the image processing means edits the thumbnail image data to match the main image data when the main image data is edited.

9. The imaging apparatus according to claim 1, characterized in that when the main image data is edited, the display image data is also edited to match the main image data.

10. The imaging apparatus according to claim 1, further comprising a switching means for switching between a mode in which the history is recorded in the image file and a mode in which the history is not recorded.

11. A method for controlling an imaging device that includes imaging means for capturing an image of a subject and generating an image signal, Image processing steps include generating main image data and thumbnail image data with a lower resolution than the main image data from the aforementioned image signal, and generating display image data with a lower resolution than the main image data and a higher resolution than the thumbnail image data, depending on the resolution of the main image data. A recording step in which the main image data, the thumbnail image data, and the history of the image file are recorded in the image file, and if the display image data exists, the display image data is recorded in the history; A control method for an imaging device, characterized by having the following features.

12. A program for causing a computer to execute each step of the control method for the imaging device described in claim 11.

13. A computer-readable storage medium storing a program for causing a computer to execute each step of the control method for the imaging device described in claim 11.

Citation Information

Patent Citations

  • Digital evidence camera system, decoding key acquisition registration system and digital image edit system

    JP1999308564A

  • Imaging device, server device, and evaluation system

    JP2013207544A

  • Image magnification instruction device and imaging apparatus

    JP2020010117A

  • Authenticity validation system and content management device and content generation device and control method thereof and program thereof

    JP2024107915A

  • Method and apparatus for tamper proof camera logs

    US20130262871A1