Proving Media Origin via Fragile Watermarking

Fragile watermarks in media files allow for reliable verification of the original source, addressing the challenge of counterfeit media by ensuring media integrity through detectable markers that persist with minor edits.

JP7723607B2Active Publication Date: 2025-08-14MICROSOFT TECHNOLOGY LICENSING LLC
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2021573230
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-02-18
Filing Date
2020-06-09
Publication Date
2025-08-14
Estimated Expiration
2040-06-09

AI Technical Summary

Technical Problem

The rapid advancement of AI technologies for creating synthetic media has led to an increase in counterfeit and manipulated media, making it difficult to verify the authenticity and origin of digital content, which poses threats to democracy and the rule of law.

Method used

The use of fragile watermarks that are inserted into media files to ensure they remain detectable only if the media is not significantly altered, allowing verification of the original source even after minor edits.

Benefits of technology

Enables reliable verification of media origin from trusted sources, reducing the distribution and impact of fake media by ensuring that media marked with fragile watermarks is accurately represented.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007723607000001
    Figure 0007723607000001
  • Figure 0007723607000002
    Figure 0007723607000002
  • Figure 0007723607000003
    Figure 0007723607000003
Patent Text Reader

Abstract

Systems and methods are disclosed for determining when media is a high-fidelity reproduction of original media from a trusted entity. In certain aspects, systems and methods are disclosed for generating fragile watermarks. The fragile watermarks may be inserted into digital media in a manner that makes them unidentifiable if the media content is significantly altered. The media content may then be analyzed to determine the presence of the fragile watermark. The presence of the fragile watermark allows the origin of the media content to be verified, and an indication of the origin is provided to the user.
Need to check novelty before this filing date? Find Prior Art

Description

[Background technology]

[0001] background

[0001] Tools for generating manipulative videos that can be used in new forms of propaganda and disinformation are becoming more commonplace. These tools make it easier for individuals, government officials, and non-governmental organizations to synthesize and disseminate false or doctored versions of events. As a result, many problems exist when attempting to verify the veracity of reports, and the falsity of such reports poses a threat to the rule of law and democracy around the world.

[0002]

[0002] It is with respect to these and other general considerations that the embodiments have been described, and although relatively particular problems have been discussed, it should be understood that the embodiments should not be limited to solving the particular problems identified in the background. Summary of the Invention

[0003] overview Aspects of the present disclosure relate to systems and methods that may be utilized to determine when media is a high-fidelity reproduction of original media from a trusted entity. In one particular aspect, a system and method are disclosed for generating a fragile watermark. The watermark may be inserted into digital media in a manner that makes the fragile watermark unidentifiable if the media content is significantly altered. However, the fragile watermark remains detectable even if the media is slightly modified. In this manner, the originally created media can be distributed in a manner that, if the media is significantly altered, notifies users that the media represents original media generated by a trusted source.

[0004]

[0004] In a further aspect, systems and methods are provided for determining whether requested media content is from a trusted media source. In such aspects, when a user desires to access a media file, a unique identifier for the media file may be generated and sent to an origin service. If the particular media has not previously been analyzed by the origin service, the media itself may be sent to the origin service for origin analysis. If the origin service can identify a fragile watermark associated with a trusted source, the origin of the media is confirmed and provided to the user.

[0005] This Summary is presented to introduce a selection of concepts in a simplified form that are further described below in the Detailed Description. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter. Additional aspects, features, and / or advantages of each example will be set forth in part in the description that follows, and in part will be apparent from the description, or may be learned by practice of the disclosure.

[0006] BRIEF DESCRIPTION OF THE DRAWINGS

[0006] Non-limiting and non-exhaustive examples are described with reference to the following figures: [Brief explanation of the drawings]

[0007] [Figure 1] 1 is an exemplary high-level architecture 100 for preparing media for provenance verification. [Figure 2]

[0008] 2 is an exemplary high-level architecture 200 for verifying the provenance of existing media. [Figure 3]

[0009] 3 is an exemplary method 300 for providing a requesting device with a key for a fragile watermark. [Figure 4]

[0010] 4 is an exemplary method 400 for generating a fragile watermark on media. [Figure 5]

[0011] 5 is an exemplary method 500 for determining the origin of a media file accessed by a device. [Figure 6]

[0012] 6 is an exemplary method 600 for analyzing a media file to determine the origin of the media. [Figure 7]

[0013] 7 is yet another exemplary method 700 for determining the origin of media content or a media file. [Figure 8]

[0014] 8 illustrates an example method 800 for determining the origin of media executed by a client device. [Figure 9]

[0015] FIG. 1 is a block diagram illustrating exemplary physical components of a computing device in which aspects of the present disclosure may be implemented. [Figure 10A]

[0016] FIG. 1 is a simplified block diagram of a mobile computing device capable of implementing aspects of the present disclosure. [Figure 10B]

[0016] FIG. 1 is a simplified block diagram of a mobile computing device capable of implementing aspects of the present disclosure. [Figure 11]

[0017] FIG. 1 is a simplified block diagram of a distributed computing system in which aspects of the present disclosure may be implemented. [Figure 12]

[0018] 1 illustrates a tablet computing device for implementing one or more aspects of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0008] Detailed Description

[0019] In the following detailed description, reference is made to the accompanying drawings, which form a part hereof, and which show, by way of example, specific embodiments or examples. These aspects may be combined, other aspects may be utilized, and structural changes may be made without departing from the disclosure. The embodiments may be embodied as methods, systems, or devices. Accordingly, the embodiments may take the form of hardware implementations, software implementations, or implementations combining software and hardware aspects. Therefore, the following detailed description is not to be taken in a limiting sense, and the scope of the disclosure is defined by the appended claims and their equivalents.

[0009]

[0020] Aspects of the present disclosure relate to verifying the origin of media using fragile digital watermarks. Recently, the amount of counterfeit media distributed over the Internet has increased. As described herein, counterfeit media refers to media fabricated to appear authentic or to fraudulently manipulated original media modified to present the media in a misleading manner. Numerous factors have contributed to the increase in the distribution of counterfeit media. Artificial intelligence (AI) technology for media creation has advanced to the point where synthetic video and audio can be generated with a high degree of confidence in its authenticity. This problem is particularly true for synthetic audio, which can sometimes be indistinguishable from authentic audio even by forensic audio experts. Meanwhile, tools for identifying fake, synthetic, or fraudulently manipulated media have not evolved at the same pace as tools for creating misleading or inaccurate media.

[0010]

[0021] The availability of tools for generating manipulative media (e.g., video, audio, images) has led to the further dissemination of new forms of propaganda and disinformation through traditional media channels and, in particular, social media networks. Such tools make it easier for individuals, government actors, and non-governmental organizations to synthesize and disseminate false or doctored versions of events. The misuse of fake media can have significant adverse effects on individuals and society, for example, by damaging reputations, influencing elections, and destabilizing governments and / or organizations.

[0011]

[0022] Detecting fake media is a technically challenging problem. Compared to the rapid advances in AI and machine learning technologies aimed at creating fake media, attempts to develop systems for automated detection of fake media in text or multimedia formats (e.g., audio, video, images) have met with limited success. In fact, state-of-the-art tools for determining whether a media file is fake have yet to provide reliable countermeasures against the tools used to create fake media. Furthermore, media channels, particularly with regard to social media networks, have not shown a strong interest in actually identifying and cracking down on fake media because distributing such media increases their revenues. In light of these considerations, aspects of the present disclosure are directed not to identifying fake media but to verifying the accurate origin or authenticity of the media.

[0012]

[0023] Aspects of the present disclosure relate to systems and methods that may be used to determine when media is a high-fidelity reproduction of original media from a trusted entity. As used herein, a trusted entity may be an individual, an organization (e.g., a news agency, a cable and / or local news organization, a newspaper, etc.), or a trusted device (e.g., a camera or recorder that captured the original media). Asserting origin using the systems and methods disclosed herein can have a significant impact on reducing the distribution and / or impact of fake media. For example, when a user browses a website, if the browser overlays a "mark of authenticity" on certain portions of the media (images, video clips, audio clips, and voice recordings), the user can be more confident that the media they are viewing is accurate and has not been altered. On a larger scale, society can place its trust only in media that bears such a mark of authenticity, which can also significantly reduce the negative societal impact of fake media.

[0013]

[0024] However, proving the origin of a specific piece of media is more difficult than existing techniques used to provide assurance to users accessing content on the Internet, such as users of website authentication. For example, media files such as JPEG images, MPEG video, and MP3 audio contain, among other features, metadata that may be used to identify the source of the media file. However, because metadata is easily modifiable, proving the origin of a media file cannot rely on metadata. Therefore, there is no method for reliably preserving metadata throughout the production process, from the time the media is created using a device (e.g., a camera, recorder, etc.) to the time the media is rendered using a web browser or other application.

[0014]

[0025] The process of determining the origin of media is further complicated by the fact that it is not feasible to verify that a specific piece of media is identical to the original format of the source material. Media files are invariably edited before the final version of this media is posted on a website. Regardless, if the editing is "light" (e.g., some cropping, recompression, and resampling with good fidelity to reduce file size) so that the final image or video appears identical to the original to the human eye, the media file must be proven to be an accurate representation of the original material. Therefore, the characteristics of media files and the requirement to prove the accuracy of media even when changes are made to the media file itself do not include the direct use of metadata fields or any form of binary file hash to prove the origin of a specific piece of media.

[0015]

[0026] Aspects of the present disclosure overcome the above-mentioned problems by using fragile watermarks. A variety of different techniques are available for generating fragile watermarks. Those skilled in the art will appreciate that any such technique may be utilized in conjunction with the systems and methods disclosed herein, so long as the fragile watermark achieves the following properties: First, the technique for generating a fragile watermark allows its presence to be verified by a detector operable to check for its presence and / or recover the key associated with the fragile watermark. Second, an attacker must not be able to generate a valid fragile watermark because they do not have access to the key and / or device used to generate the fragile watermark. Finally, parameters controlling the signal characteristics of a fragile watermark can be set such that the watermark is destroyed by any significant editing of the media. Minor editing, such as cropping, recompression, or high-fidelity resampling, should preserve the fragile watermark. Thus, because media data typically undergoes several levels of editing during its creation, the aspects disclosed herein use fragile watermarks. As long as all of this editing is minor, i.e., the media content is not significantly altered, the fragile watermarks will be preserved. Thus, the aspects disclosed herein enable a distribution network in which the editing entity does not need to be certified as a trusted source. Rather, to determine the provenance of any particular media file, only the original source of the media file needs to be certified as trusted.

[0016]

[0027] As an example, we provide an illustrative fragile watermarking process for audio signals. A fragile watermark can be inserted into audio data by adding a low-level, noise-like signal that appears random but is actually controlled by a cryptographic key. Using techniques such as spread-spectrum watermarking, the resulting watermarked audio is indistinguishable from the original to the human ear. The presence of the watermark can be verified by a detector that checks for the presence of fragile watermarks. If the audio signal is lightly edited, this detector must be able to verify the presence of a fragile watermark and thus demonstrate that the audio file is an accurate representation of the original material. However, if the detector cannot verify the presence of a fragile watermark, it can generate an indication that the audio file cannot be certified as an accurate representation of the original audio. Similar concepts can be applied to other media types, such as images and video.

[0017]

[0028] FIG. 1 illustrates an exemplary high-level architecture 100 for preparing media for provenance verification. A media capture device 102 is utilized to capture original, source media. Exemplary capture devices include cameras, audio recorders, smartphones, etc. Those skilled in the art will appreciate that aspects of the present disclosure may be implemented using any type of device used to capture or create original content. In certain aspects, the media capture device 102 may be associated with an entity 103. The entity 103 may be an individual, an organization, or, in some examples, the media capture device itself. The entity 103 may be a trusted entity; that is, the entity 103 has been established by a provenance service 106 as a trusted source of authentic media. In examples, the entity 103 may be an individual, such as a reporter, an organization, such as a newsroom, or a trusted device, such as a secure camera. The trusted entity 103 performs an entity verification process 104 to authenticate the entity 103 with the provenance service 106. The entity verification process 104 verifies that the entity 103 is a known entity and, in response, provides an entity identifier to the origin service 106. The entity verification process 104 may authenticate the entity 103 using a login / password interface, biometrics, or any other type of process known in the art used to authenticate an entity. In each example, the entity verification process 104 may be performed by a trusted third-party server or by the origin service 106 itself.

[0018]

[0029] The provenance service 106 may operate to generate and detect fragile watermarks associated with media. In each example, the provenance service 106 may be executed by a server, a distributed network (e.g., a cloud service network), or a local computing device. The provenance service 106 may operate to receive an entity identifier associated with the entity 103 and, in response, provide a key associated with the entity 103. In each example, the trusted entity may have one or more keys associated with it. The associated keys may be used to generate fragile watermarks for the trusted entity. The provenance service 106 identifies one or more keys associated with the entity based on the received entity identifier.

[0019]

[0030] In one example, the origin service 106 can operate to provide one or more keys to the watermarking process 110. In one example, the watermarking process 110 may be performed by the origin service 106. However, in other aspects, the watermarking process 110 may be performed by a device associated with the entity 103. Enabling a device associated with the entity to perform the watermarking process 110 allows for faster processing and less bandwidth consumption because the media content does not have to be provided to the origin service 106. In a further example, the origin service 106 can provide auxiliary data in addition to the watermarking keys. In each example, this auxiliary data can be data related to the entity 103, a device associated with the entity, or the media content. For example, the auxiliary data can identify a particular entity, such as the location or department of the requesting entity (e.g., the London bureau of The New York Times). In each aspect, the auxiliary data can identify information about the device used to capture the original content, such as an identifier for the device, the location of the device, etc. In yet another example, the auxiliary data may be about the media content itself, such as a transcript, a description of the content, etc. In yet another example, the auxiliary data may include a GUID for the media, information about the entity, metadata about media characteristics, etc., among other information.

[0020]

[0031] The watermarking process 110 generates a fragile watermark for content received by the media capture device 102. In each example, the watermarking process may be performed by the media capture device 102 or another device. The generation of the fragile watermark may be performed using one or more keys. The key or keys used to generate the fragile watermark for the content may generally not be protected from a spearhead or attacker, who could otherwise use the key to watermark the fake content. In each embodiment, the key generation is associated with a particular entity, such that there is a strong binding between the entity identity and the watermark key or keys. The watermarking process 110 generates a fragile watermark for the media using a key received from the provenance service 106. In a further example, auxiliary data received from the source service may also be embedded in the media by a watermarking process such that a watermark detector can retrieve the embedded auxiliary data.

[0021]

[0032] FIG. 2 illustrates an exemplary high-level architecture 200 for existing media provenance verification. In some situations, such as web browsing, many users access the same content on the same website, and therefore, their browsers receive the same media files associated with the media. This provides efficiency by allowing an origin service to determine whether the provenance of a particular media file is known without requiring the origin service to process the media file each time the user accesses it. In such situations, the origin service 204 may identify media content that has already been processed and provide the results of this processing to the requester without having to process the media again. For example, the origin service 204 may create a cache of unique identifiers for media content previously processed by the origin service 204, along with the results of that processing (e.g., an indication of known origin, unknown origin, associated ancillary data, etc.). For example, a table of checksums for media files previously processed by the origin service may be maintained to efficiently identify previously processed media files.

[0022]

[0033] In one particular aspect, when a media file is received for verification, the first step is to process the media using a pre-analysis process 202 to determine whether the media has previously been verified by the provenance service 204. The pre-analysis process 202 may be executed on a client device, such as a web browser or media player, to request a determination of the origin of the media file. The pre-analysis process may include processing the media file to generate an identifier for the media. The processing performed during the pre-analysis process 202 may be the same process used by the provenance service 204 to generate a unique identifier for the media content file. For example, the pre-analysis process 202 may include generating a checksum, hash, or other type of unique identifier based on the media to be verified. The media identifier generated by the pre-analysis process 202 is provided to the provenance service 204. The provenance service 204 checks the watermark detection cache 206 to see if the media associated with the media identifier has previously been processed by the provenance service 204. If this media has previously been processed by the origin service 204, the results of the prior processing, along with any associated auxiliary data, are returned to the requesting device. Otherwise, the origin service returns an indication to the requesting device that the media file has not previously been processed.

[0023]

[0034] If the media file has not been previously processed, the media to be verified is provided to provenance service 204. As discussed above, provenance service 204 may be executed by a remote server or a local computing device. In certain aspects, provenance service 204 may run as a cloud service on a distributed network to ensure immunity to attacks on individual devices. Upon receiving the media, provenance service 204 may execute watermark detection process 208 to determine whether the media contains a watermark. As previously discussed, aspects of the present disclosure facilitate the insertion of a fragile watermark into the media; that is, heavy editing processes would destroy a fragile watermark. Thus, detection of a fragile watermark by provenance service 204 indicates that the media is an accurate representation of media generated by a trusted source or entity. Watermark detection process 208 may also be operable to identify any ancillary data embedded in the media file.

[0024]

[0035] As mentioned above, the provenance service 204 may generate a unique identifier for the media once it has been processed (e.g., a checksum or hash of the media). This identifier may be stored in the watermark detection cache 206 along with the results from the watermark detection process (e.g., weak watermark detected, not detected, auxiliary data detected, etc.). The provenance service may further operate to provide the results of the watermark detection process 208 to the requesting device. The requesting device may then perform a decision process based on the results returned by the provenance service to determine what action to take. Example actions include informing the user that the media is from a known / unknown entity, providing an indicator informing the user whether the source of the media is known or unknown, processing and / or providing auxiliary data, etc.

[0025]

[0036] FIG. 3 illustrates an exemplary method 300 for providing a fragile watermark key to a requesting device. In one example, this method 300 may be performed by an origin service, such as origin service 106 of FIG. 1. The flow begins at operation 302, where a request to generate a fragile watermark for a media file is received. In each example, the request may be received from a user device, such as a device that captured the media content or a device that edits the media content. At operation 304, an entity identification associated with the request is received. Those skilled in the art will appreciate that this entity identification may be received together with the request to generate the fragile watermark or in a separate communication. This entity identification may identify a person, organization, device, or any other known and trusted source associated with the media.

[0026]

[0037] At operation 306, the received entity identity is verified to ensure that the entity is, in fact, what it claims to be. Those skilled in the art will appreciate that any type of identity verification may be performed at operation 306. Additionally, a determination may be made as to whether the device that sent the request for the originating service is associated with the entity indicated by the received entity identity. In other examples, the entity identity may be received from a trusted source, such as a trusted third party, that may independently perform entity verification. Under such circumstances, verifying the entity at operation 306 may not be necessary.

[0027]

[0038] Once this identification information is verified (if necessary), flow continues to operation 308. In operation 308, one or more keys to be used to generate the fragile watermarks are identified. As previously mentioned, this fragile watermark key is associated with the requesting entity, e.g., the requesting individual or organization. Among other advantages, this allows for the creation of unique fragile watermarks for each trusted entity registered with the system performing method 300. Furthermore, more than one fragile watermark key may be associated with an entity. Thus, different entities' keys may be used for different purposes. For example, an entity may have different keys associated with different projects, departments, locations, equipment, etc. In such situations, additional information received with the request may be used in conjunction with the received entity identification information to select the appropriate fragile watermark key or keys. In operation 310, the one or more selected fragile watermark keys are provided to the requesting device. The provided fragile watermark key may then be used by the requesting device to generate a fragile watermark for the media. In certain aspects, auxiliary data, if available, may be provided in operation 312. Any provided auxiliary data may be embedded in the fragile watermark or in the media file itself.

[0028]

[0039] FIG. 4 illustrates an exemplary method 400 for generating a fragile watermark for media content or a media file. The flow begins at operation 402, where media content or a media file is received. Method 400 may be performed by a device creating or editing the media for distribution. For example, method 400 may be used by a device that captured the media (e.g., a camera, a smartphone, an audio recorder) or by a device used to edit the original captured media. The type of media content received at operation 402 may be any type of digital media, including, but not limited to, images, video, audio, electronic documents, etc. One skilled in the art will appreciate that the aspects disclosed herein may be implemented with any type of received content, regardless of the type or format of the content.

[0029]

[0040] At operation 404, an entity identifier is received. As previously discussed, aspects of the present disclosure provide for associating content with any type of entity, such as an individual, organization, and / or device. This allows provenance to be associated with the creator of the content, a particular device, or both. At operation 406, the entity identifier is provided to the provenance server along with a request for a fragile watermark key. In some examples, the request for a fragile watermark key may include additional information about the entity, additional information about the media itself, additional information about the device used to capture the media, etc. This additional information may be part of the auxiliary information discussed above. In certain aspects, the entity identifier may be provided along with additional verification information, such as a password or biometric information, that is used to verify that the requester is indeed the entity they claim to be.

[0030]

[0041] In alternative embodiments, the fragile watermark key and the request for the entity identifier may be provided in separate messages. In yet other embodiments, the watermark and the request for the entity identifier may be provided to different parties. For example, the entity identifier may be provided to a trusted third-party service to verify the identity of the entity. This verification may then be provided by the trusted third party to a provenance service.

[0031]

[0042] In response to sending the request at operation 406, flow continues to decision operation 408. At decision operation 408, a determination is made as to whether a fragile watermark key has been received in response to sending the request at operation 406. In some cases, a fragile watermark key may not be received if, for example, the key does not exist, the entity is not registered, or the entity cannot be properly verified due to loss of network connectivity. If the key is not received, flow branches "NO" to operation 410, where a notification is provided that the fragile watermark cannot be added to the media. This notification may include additional information to the user identifying steps that need to be taken by the user to receive the fragile watermark key from the origin service. Such actions may include creating a trusted account and registering with the origin service, providing additional verification data, etc. When a key for creating a fragile watermark has not been provided, method 400 may end at operation 410.

[0032]

[0043] Returning to operation 408, if a fragile watermark key is received, flow branches "yes" to operation 412. At operation 412, a determination is made as to whether any additional auxiliary data was received along with the fragile watermark key. As previously discussed, the auxiliary data may be data associated with an entity, device, media, origin service, etc. In some examples, this auxiliary data may be generated by the origin service and received at the requesting device. In other aspects (not shown), this auxiliary data may be generated by the requesting device performing method 400. If no auxiliary data is provided, flow branches "no" to operation 414. At operation 414, the media content or media file is processed using the received fragile watermark key to generate a fragile watermark for the content or file. Various processes may be used to generate the fragile watermark, depending on the type of key, the type of content, etc. Those skilled in the art will appreciate that any type of process operable to generate a fragile watermark may be utilized in operation 414 without departing from the scope of this disclosure.

[0033]

[0044] Flow then continues to operation 418 where the fragile watermarked media is provided. Providing this fragile watermarked media may include storing the fragile watermarked media on a device, transmitting the fragile watermarked media to another device, posting the fragile watermarked media to a website or social network, transmitting the fragile watermarked media to a broadcast service, etc.

[0034]

[0045] Returning to operation 412, if auxiliary data is present, flow branches "yes" to operation 416. At operation 416, the media content is processed using both the fragile watermark key and the auxiliary data. As previously mentioned, any type of process may be utilized to generate a fragile watermark for the content using the fragile watermark key, so long as the requirements previously described are met. Processing the media content with the auxiliary data may include embedding the auxiliary data into a fragile watermark or otherwise embedding or associating the auxiliary data with the media content. Flow then proceeds to operation 418, where the fragile watermarked media along with the auxiliary data is provided.

[0035]

[0046] FIG. 5 illustrates an exemplary method 500 for determining the origin of a media file accessed by a device. The method begins at operation 502, where media to be verified is received. The media may be received via a web browser accessing media stored on a remote computer, via a media player, via a streaming service, via email, or any other means of receiving media content. Once the content is received, flow proceeds to operation 504, where the content is pre-analyzed. Pre-analysis of the content may include generating a unique identifier based on the content. For example, a hash function may be applied to the media to generate a hash value that can identify the media. The content identifier generated at operation 504 is provided to an origin service at operation 506. As discussed above, multiple users may access the same media file. In such cases, if a pre-analysis has already been performed, it may not be necessary to send the media file to the origin service for analysis. The generation and transmission of the content identifier allows for a quick and efficient determination regarding the origin of the media content or media file by leveraging past analysis performed by the origin service. Furthermore, transmitting the content identifier requires much less transmission bandwidth than transmitting the actual media content or media file itself for analysis.

[0036]

[0047] At determine operation 506, a check is performed to determine whether the origin of the media file can be determined. In one aspect, this determination may be based on a message received from the origin service in response to providing the content identifier. For example, if the origin is known or unknown based on prior analysis by the origin server, an indication of the origin determination may be received. Otherwise, a request for the media content may be received. Once the origin is determined, flow branches "yes" to operation 510, where the origin determination is provided to the user. In one aspect, providing the origin determination may include generating a message indicating whether the origin of the media is known or unknown, or displaying (or causing to be displayed) this message to the user. In one example, a graphical display may be used to indicate the origin determination. For example, a web browser may display an indication as part of its interface related to the origin (e.g., a green check for known, a red X for unknown, a certification mark, etc.). In yet another example, auxiliary data with the media content or media file, if present, may be provided at operation 510.

[0037]

[0048] Returning to operation 508, if the media file has not previously been analyzed by the origin service, flow continues along the "NO" branch to operation 512, where the media is sent to the origin service for analysis. Sending the media to the origin service may include sending the entire media file, or in some circumstances, only a portion of the media file, to the origin service. In response to sending the media file, flow continues to operation 514, where the results of the analysis are received, and then flow returns to operation 510, where the results of the origin determination are provided.

[0038]

[0049] FIG. 6 illustrates an exemplary method 600 for analyzing a media file to determine the origin of the media. In each example, method 600 may be performed by an origin service, such as origin service 204. More specifically, one or more servers that are part of the origin service may perform method 600. Flow begins at operation 602, where a content identifier is received. In each embodiment, the content identifier may be a checksum, a hash, or any other type of unique identifier based on the media content or media file to be verified. Flow continues to operation 604, where a determination is made as to whether the origin of the media content or media file identified by the content identifier has previously been determined. This determination may be made by using the identifier to retrieve results of a previous analysis stored in a data store. If the media has previously been analyzed, flow branches to operation 606, where results from the previous analysis are retrieved from the data store. Retrieving the results may include retrieving a determination as to whether the origin of the media file is known or unknown. Ancillary data associated with the media may also be retrieved in operation 606. Flow continues to operation 608, where the provenance determination and, if available, the auxiliary data are returned to the requesting device. Method 600 may then end, as the media content does not require further analysis.

[0039]

[0050] Returning to decision operation 604, if the media has not been analyzed previously, flow branches "NO" to operation 610. At operation 610, a request for media is sent to the device that received the content identifier. Flow continues to operation 612, where the media is processed to determine whether a fragile watermark is present within the media. In one example, one or more candidate keys are identified to determine whether a fragile watermark associated with the key is present in the received media. The one or more keys may be selected based on the claimed origin, selecting a key associated with the claimed entity. That is, selecting one or more keys associated with the entity that is claimed to have created the content. Those skilled in the art will recognize that several processes for determining whether media contains a fragile watermark may be utilized without departing from the scope of this disclosure.

[0040]

[0051] At decision operation 614, the results of operation 612 are analyzed to determine whether a fragile watermark is present in the received media. If a fragile watermark is present, a determination is made that the received media is an accurate representation of the media originally provided by a trusted source. Flow branches "YES" to operation 616, where provenance verification is sent to the requesting device. Operation 616 may also include sending the fragile watermark or any auxiliary data associated with the media. Flow then continues to operation 618, where a unique identifier is created for the media. As previously described, this unique identifier may be created by applying a hash to the analyzed media content of the file, or by using any other type of deterministic process or function on the media to generate a unique identifier that can be replicated by other devices using the same process on the media content or media file. This unique identifier is then used to cache the results of the media analysis for future lookup.

[0041]

[0052] Returning to operation 614, if a fragile watermark is not identified, flow branches "NO" to operation 620 where a message is sent to the requesting device indicating that the origin of the media file cannot be determined. Flow then returns to operation 618 where the results of the origin determination are cached as described above.

[0042]

[0053] 7 illustrates yet another exemplary method 700 for determining the origin of media content or a media file. This method 700 may be performed remotely by a provenance service or locally on a device consuming the media content, so long as the device has access to the candidate keys used to create the fragile watermark. The flow begins at operation 702, where media content or a media file is received. As discussed above, any type of media content or media file may be received at operation 702. At operation 704, a claimed source of the media content or media file is determined. In one example, the claimed source may be determined by analyzing the media content or media file. For example, metadata associated with the media may be analyzed to determine the claimed source. Alternatively, at operation 702, an indication of the claimed source may be received along with the media itself.

[0043]

[0054] At operation 706, one or more candidate keys are selected. The one or more candidate keys may be selected based on the claimed media source. As previously discussed, a trusted entity may be associated with one or more candidate keys. If the received media is claimed to be from a particular trusted entity, operation 706 may select one or more candidate keys associated with the claimed entity. Flow then continues to operation 708, where the one or more selected candidate keys are used to process the media content to identify fragile watermarks. As discussed above, any type of process known in the art for creating fragile watermarks for digital media may be utilized in the aspects disclosed herein. Similarly, any type of process known in the art for detecting fragile watermarks may be used at operation 708. One or more keys may be utilized in the selected process to verify the presence of a fragile watermark. If a fragile watermark is present, the origin of the media can be verified.

[0044]

[0055] Once the origin is verified, flow continues to optional operation 710. As previously discussed, ancillary data may be associated with the fragile watermark or with the media file itself during the creation of the fragile watermark. Once the origin is determined, any ancillary data associated with the fragile watermark or media file is detected or extracted at operation 710. Continuing to operation 712, a content identifier is created. This content identifier is a unique identifier that may be created by applying a hash to the analyzed media content of the file, or by using any other type of deterministic process or function on the media to generate a unique identifier that can be replicated by other devices using the same process on the media content or media file. Once the unique identifier is created, flow continues to operation 714, where the result of the origin verification is stored along with any associated ancillary data. As discussed previously, associating the results of the fragile watermark detection process enables efficient determination of origin when the same media is subsequently received. Instead of processing the media to identify fragile watermarks, the unique identifier in the media may be used to look up the results of previous processing. Flow continues to operation 716 where the results of the provenance determination and / or any auxiliary data associated with the media are returned.

[0045]

[0056] FIG. 8 illustrates an exemplary method 800 for determining the origin of media. Method 800 may be performed by a client device, such as a smartphone, tablet, personal computer, television, or any other type of device capable of requesting and / or playing media content. In each example, method 800 may be performed by a media application resident on the client device, such as a browser, a streaming media application, a media player, or the like. At operation 802, a request for access to and / or provision of media content is received. The request may be a user request to play a media file, a user request to navigate to the media over a network, or the like. Once the media is accessed, flow continues to operation 804, where a unique identifier is generated for the requested media content or media file. As discussed above, this unique identifier may be created by applying a hash to the analyzed media content of the file or by using any other type of deterministic process or function on the media to generate a unique identifier that can be replicated by other devices using the same process on the media content or media file.

[0046]

[0057] Flow continues to operation 806, where the unique identifier is provided to a media origin service. In aspects, the media origin service may be a trusted third party that manages keys used to create fragile watermarks for trusted entities. While origin services are generally described as being performed by a remote third party, those skilled in the art will appreciate that media origin services may also reside on and execute locally on the device requesting access to the content. In response to providing the unique identifier to the media origin service, a response is received at operation 808.

[0047]

[0058] At operation 810, a determination is made as to whether the origin of the requested media content has previously been determined by an origin service. This determination is made based on the response received from the origin service at operation 808. If a prior origin determination has been made, flow branches "YES" to operation 812, where an indication of the origin determination is provided to the user. This indication may be used to inform the user whether the requested media is a true and accurate representation of the media as provided by a trusted entity. In each example, an application playing the media on the device may present this indication to the user. This indication may be in the form of a graphic indicator associated with the content, such as a mark of authenticity, a green check mark indicating that the requested media is an accurate representation of the media generated by a trusted entity, or a red X indicating that the media is not an accurate representation of the original media or is not from the claimed media source but is not from a trusted source. The type of indicator may vary depending on the type of media application playing the requested content, the type of media, or both. Alternatively, rather than presenting an indication that the origin of the media content cannot be verified, the process performing method 800 may prevent the media content from playing on the local device.

[0048]

[0059] If the origin of the requested media has not been previously determined, flow continues "NO" from operation 810 to operation 814. At operation 814, the requested content is provided to the origin service. In one example, the entire media content or media file may be provided at operation 814. Alternatively, only a portion of the media file may be provided to the origin service at operation 814. Flow then continues to operation 816, where a response is received in response to sending the requested media content to the origin service, indicating the results of the origin determination. Flow then continues to operation 812, where the results of the origin determination are provided to the user.

[0049]

[0060] 9-10 and the associated description provide a discussion of various operating environments in which aspects of the present disclosure may be implemented. However, the devices and systems illustrated and discussed with respect to Figures 7-10 are intended to be exemplary and illustrative, and are not intended to limit the vast number of computing device configurations that may be utilized to implement aspects of the present disclosure described herein.

[0050]

[0061] 9 is a block diagram illustrating the physical components (e.g., hardware) of a computing device 900 capable of implementing aspects of the present disclosure. The computing device components described below may be suitable for such a computing device. In a basic configuration, the computing device 900 may include at least one processing unit 902 and system memory 904. Depending on the configuration and type of computing device, the system memory 904 may include, but is not limited to, volatile storage (e.g., random access memory), non-volatile storage (e.g., read-only memory), flash memory, or any combination of such memory.

[0051]

[0062] The system memory 904 may include an operating system 905 and one or more program modules 906 suitable for executing software applications 920, such as one or more components supported by the system described herein.

[0052]

[0063] Additionally, embodiments of the present disclosure may be implemented with graphics libraries, other operating systems, or any other application programs and are not limited to any particular application or system. This basic configuration is illustrated in FIG. 9 by those components within dashed line 908. Computing device 900 may have additional features or functionality. For example, computing device 900 may also include additional data storage devices (removable and / or non-removable), such as, for example, magnetic disks, optical disks, or tape. Such additional storage is illustrated in FIG. 9 by removable storage device 909 and non-removable storage device 910.

[0053]

[0064] As previously mentioned, several program modules and data files may be stored within the system memory 904. While executing on the processing unit 902, the program modules 906 (e.g., applications 920) may perform processes such as, but not limited to, aspects of fragile watermark creation or detection 924, or provenance services 926, as described herein. Other program modules that may be used in accordance with aspects of the present disclosure may include email and contact applications, word processing applications, spreadsheet applications, database applications, slide presentation applications, drawing or computer-assisted application programs, etc.

[0054]

[0065] Furthermore, embodiments of the present disclosure may be implemented in electrical circuits comprising discrete electronic elements, packaged or integrated electronic chips containing logic gates, microprocessor-based circuits, or on a single chip containing electronic elements or a microprocessor. For example, embodiments of the present disclosure may be implemented via a system-on-chip (SOC), which may integrate each or many of the components shown in FIG. 9 onto a single integrated circuit. Such an SOC device may include one or more processing units, graphics units, communications units, system virtualization units, and various application functions, all integrated (i.e., "burned") onto the chip substrate as a single integrated circuit. When operating via an SOC, the functionality described herein for enabling a client to switch protocols may operate via application-specific logic circuits integrated with other components of the computing device 900 on a single integrated circuit (chip). Embodiments of the present disclosure may also be implemented using other technologies capable of performing logical operations, such as AND, OR, and NOT, including, but not limited to, mechanical, optical, fluidic, and quantum technologies. Furthermore, embodiments of the present disclosure may be implemented in a general purpose computer or any other circuits or systems.

[0055]

[0066] The computing device 900 may also have one or more input devices 912, such as a keyboard, mouse, pen, sound or voice input device, touch or swipe input device, etc. One or more output devices 914, such as a display, speakers, printer, etc. The aforementioned devices are examples, and other devices may be used. The computing device 900 may also have one or more communication connections 916 that enable communication with other computing devices 950. Examples of suitable communication connections 916 include, but are not limited to, radio frequency (RF) transmitter, receiver, and / or transceiver circuitry, a universal serial bus (USB), a parallel port, and / or a serial port.

[0056]

[0067] As used herein, the term "computer-readable medium" may include computer storage media. Computer storage media may include volatile and nonvolatile, removable and non-removable media implemented in any method or technology for storage of information, such as computer-readable instructions, data structures, or program modules. System memory 904, removable storage 909, and non-removable storage 910 are all examples of computer storage media (e.g., storage devices). Computer storage media may include RAM, ROM, electrically erasable read-only memory (EEPROM), flash memory or other memory technology, CD-ROM, digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other article that can be used to store information and that can be accessed by computing device 900. Any such computer storage media may be part of computing device 900. Computer storage media do not include carrier waves or other propagated or modulated data signals.

[0057]

[0068] Communication media may be embodied by computer-readable instructions, data structures, program modules, or other data in a modulated data signal, such as a carrier wave or other transport mechanism, and includes any information delivery media. The term "modulated data signal" may describe a signal that has one or more characteristics set or changed in such a manner as to encode information in the signal. By way of example, and not limitation, communication media may include wired media such as a wired network or direct-wired connection, and wireless media such as acoustic, radio frequency (RF), infrared, and other wireless media.

[0058]

[0069] 6A and 10B illustrate a mobile computing device 1000, such as a mobile phone, a smartphone, a wearable computer (e.g., a smart watch), a tablet computer, or a laptop computer, on which embodiments of the present disclosure can be implemented. In some embodiments, a client may be a mobile computing device. Referring to FIG. 10A, one embodiment of a mobile computing device 1000 for implementing embodiments is shown. In its basic configuration, the mobile computing device 1000 is a handheld computer with both input and output elements. The mobile computing device 1000 typically includes a display device 1005 and one or more input buttons 1010 that allow a user to input information into the mobile computing device 1000. The display device 1005 of the mobile computing device 1000 may also serve as an input device (e.g., a touchscreen display).

[0059]

[0070] If provided, optional side input element 1015 allows for further user input. This side input element 1015 may be a rotary switch, a button, or any other type of manual input element. In alternative embodiments, mobile computing device 1000 may incorporate more or fewer input elements. For example, display device 1005 may not be a touch screen in some embodiments.

[0060]

[0071] In yet another alternative embodiment, mobile computing device 1000 is a mobile telephone system, such as a cellular telephone. Mobile computing device 1000 may also include an optional keypad 1035. Optional keypad 1035 may be a physical keypad or a "soft" keypad generated on a touch screen display.

[0061]

[0072] In various embodiments, the output elements include a display device 1005 for showing a graphical user interface (GUI), a visual indicator 1020 (e.g., a light emitting diode), and / or an audio transducer 1025 (e.g., a speaker). In some aspects, the mobile computing device 1000 incorporates a vibration transducer that provides haptic feedback to the user. In yet other aspects, the mobile computing device 1000 incorporates input and / or output ports, such as an audio input (e.g., a microphone jack), an audio output (e.g., a headphone jack), a video output (e.g., an HDMI port), etc., for sending and receiving signals to and from external devices.

[0062]

[0073] 10B is a block diagram illustrating the architecture of one aspect of a mobile computing device. That is, the mobile computing device 1000 can incorporate a system (e.g., architecture) 1002 to implement several aspects. In one embodiment, the system 1002 is implemented as a "smartphone" capable of running one or more applications (e.g., a browser, email, calendaring, a contact manager, a messaging client, games, and a media client / player). In some aspects, the system 1002 is integrated as a computing device such as an integrated personal digital assistant (PDA) and wireless telephone.

[0063]

[0074] One or more application programs 1066 may be loaded into memory 1062 and run on or in association with operating system 1064. Examples of application programs include a phone dialer program, an email program, a personal information management (PIM) program, a word processing program, a spreadsheet program, an internet browser program, a messaging program, etc. System 1002 also includes non-volatile storage 1068 within memory 1062. This non-volatile storage 1068 may be used to store persistent information that should not be lost if system 1002 is powered off. Application programs 1066 may use and store information in non-volatile storage 1068, such as emails or other messages used by email applications. A synchronization application (not shown) also resides on system 1002 and is programmed to interact with a corresponding synchronization application resident on the host computer to keep information stored in non-volatile storage 1068 synchronized with corresponding information stored on the host computer. As will be appreciated, other applications may be loaded into memory 1062 and executed on mobile computing device 1000 as described herein (e.g., search engines, extractor modules, relevance ranking modules, answer scoring modules, etc.).

[0064]

[0075] The system 1002 includes a power supply 1070, which may be implemented as one or more batteries. The power supply 1070 may also include an external power source, such as an AC adapter or a powered storage base that replenishes or recharges the batteries.

[0065]

[0076] The system 1002 may also include a wireless interface layer 1072 that performs the function of transmitting and receiving radio frequency communications. The wireless interface layer 1072 facilitates wireless connectivity between the system 1002 and the "outside world" via a communications carrier or service provider. Transmissions to and from the wireless interface layer 1072 are under the control of the operating system 1064. That is, communications received by the wireless interface layer 1072 may be sent to the application program 1066 via the operating system 1064, and vice versa.

[0066]

[0077] A visual indicator 1020 may be used to provide a visual notification, and / or an audio interface 1074 may be used to generate an audible notification via an audio transducer 1025. In the illustrated embodiment, the visual indicator 1020 is a light-emitting diode (LED), and the audio transducer 1025 is a speaker. Such a device may be directly coupled to a power source 1070, so that when in operation, it remains on for a duration dictated by the notification mechanism, even if the processor 1060 and other components are shut off to conserve battery power. The LED may be programmed to remain on indefinitely until a user takes action to indicate a power-on status for the device. The audio interface 1074 is used to provide audible signals to and receive audible signals from the user. For example, in addition to being coupled to the audio transducer 1025, the audio interface 1074 may also be coupled to a microphone to receive audible input, such as to facilitate a telephone conversation. According to embodiments of the present disclosure, the microphone may also act as an audio sensor to facilitate control of notifications, as described below. The system 1002 may further include a video interface 1076 that enables operation of the onboard camera 1030 to record still images, video streams, and the like.

[0067]

[0078] Mobile computing device 1000 implementing system 1002 may have additional features or functionality. For example, mobile computing device 1000 may also include additional data storage (removable and / or non-removable) such as magnetic disks, optical disks, or tape. Such additional storage is illustrated in FIG. 10B by non-volatile storage 1068.

[0068]

[0079] Data / information generated or captured by mobile computing device 1000 and stored via system 1002 may be stored locally on mobile computing device 1000, as previously described, or the data may be stored on any number of storage media that can be accessed by mobile computing device 1000 via wireless interface layer 1072 or via a wired connection between mobile computing device 1000 and a separate computing device associated with mobile computing device 1000, such as a server computer in a distributed computing network such as the Internet. As will be appreciated, such data / information may be accessed via mobile computing device 1000 via wireless interface layer 1072 or via a distributed computing network. Similarly, such data / information may be readily transferred between computing devices for storage and use by well-known data / information transfer and storage means, including email and collaborative data / information sharing systems.

[0069]

[0080] 11 illustrates one aspect of a system architecture for processing data received from a remote source in a computing system, such as a personal computer 1104, a tablet computing device 1106, or a mobile computing device 1108, as previously described. A fragile watermarking application and / or a media player (not shown) may reside on the personal computer 1104, the tablet computing device 1106, or the mobile computing device 1108. Content displayed on the server device 1102 may be stored on various communication channels or other storage types. For example, various documents may be stored using a directory service 1122, a web portal 1124, a mailbox service 1126, an instant messaging storage device 1128, or a social networking site 1130.

[0070]

[0081] The server device 1102 may exchange data with client computing devices, such as a personal computer 1104, a tablet computing device 1106, and / or a mobile computing device 1108 (e.g., a smartphone) via a network 1115. As an example, the aforementioned computer system may be implemented on a personal computer 1104, a tablet computing device 1106, and / or a mobile computing device 1108 (e.g., a smartphone). A source service 1121 may reside on the servicer device 1102. Any of these aspects of a computing device may retrieve content from the storage device 1116 in addition to receiving graphics data that can be used for pre-processing in a graphics generation system or for post-processing in a receiving computing system.

[0071]

[0082] FIG. 12 illustrates an exemplary tablet computing device 1200 capable of implementing one or more aspects disclosed herein. Furthermore, aspects and functions described herein may operate on a distributed system (e.g., a cloud-based computing system), where application functions, memory, data storage and retrieval, and various processing functions may operate remotely from one another over a distributed computing network, such as the Internet or an intranet. Various types of user interfaces and information may be displayed via a display device on an on-board computing device or via a remote display unit associated with one or more computing devices. For example, various types of user interfaces and information may be displayed on and interacted with a wall surface onto which the various types of user interfaces and information are projected. Interactions with numerous computing systems that may implement embodiments of the present invention include keystroke input, touchscreen input, voice or other audio input, and gesture input with detection capabilities (e.g., camera capabilities) for an associated computing device to capture and interpret user gestures to control computing device functions.

[0072]

[0083] As can be appreciated from the foregoing disclosure, one aspect of the present technology relates to a method for providing a fragile watermark key. The method includes receiving a request for a fragile watermark key, where the fragile watermark key is used to generate a fragile watermark on digital media content that provides an indication of origin for the digital media content; determining an entity associated with the fragile watermark key request, where the entity is the creator of the media content; identifying a fragile watermark key associated with the entity; and providing the fragile watermark key to the requesting device. In one example, the method further includes receiving entity identification information with the fragile watermark request, where the entity identification information is used to determine the entity associated with the request. In another example, the request identifies a claimed entity, and the method further includes verifying the claimed entity and, upon verification, receiving an entity identifier for the trusted entity if the claimed entity is determined to be a trusted entity. In a further example, the fragile watermark key is identified using an entity identifier. In yet another example, the entity is one of a trusted individual, a trusted organization, or a trusted device. In yet another example, multiple fragile watermark keys are associated with the entity, and the method further includes receiving additional information related to the particular entity generating the content, and selecting one or more fragile watermark keys from the multiple fragile watermark keys based on the additional information.

[0073]

[0084] In another aspect, the technology relates to a method for requesting the origin of media content. The method includes receiving, in a media application, a request to access the media content, generating a content identifier for the media content, transmitting the content identifier to an origin service, and receiving a response indicating an origin determination for the media content in response to transmitting the request to the origin service, and providing an indication of a known origin of the media content if the origin determination indicates that the media content is from a trusted entity. In one example, the method further includes transmitting the media content to the origin service if the response indicates that the media content has not been previously analyzed by the origin service. In another example, transmitting the media content includes transmitting a portion of the media content to the origin service. In a further example, the method further includes receiving a response indicating a result of the origin determination in response to transmitting the media content to the origin service. In yet another example, the method further includes, upon determining the result of the origin of the media content, providing a first indication that the media content is from a trusted source, and, upon determining the origin of the media, providing a second indication that the media is from an untrusted source. In yet another example, the method further includes preventing playback of the media content if the origin of the media is not determined. In one example, generating a content identifier includes processing the media content with a deterministic function to generate the content identifier. In another example, the media content includes one of a video file, an audio file, an image file, an electronic document, or streamed media content. In a further example, the trusted entity includes one or more of a trusted individual, a trusted organization, or a trusted device.

[0074]

[0085] In a further aspect, the technology relates to a method for determining the origin of media content, the method including receiving a unique identifier associated with the media content from a requestor, determining whether the media content has been previously analyzed to determine the origin of the media content, and, if the media content has been previously analyzed, providing results of the previous analysis to the requestor. If the media content has not been previously analyzed, sending a request for the media content to the requestor, receiving the media content, processing the media content to determine whether the media content includes a fragile watermark associated with a trusted source, providing origin verification to the requestor if the media content includes the fragile watermark, and, if the media content does not include the fragile watermark, providing an indication to the requestor that the origin of the media file cannot be determined. In one example, providing origin verification to the requestor further includes providing auxiliary data associated with the fragile watermark to the requestor. In another example, the auxiliary data includes at least one of information about a trusted source, a device identifier for a device used to capture the media content, a globally unique identifier for the media content, or a transcript of the media content. In a further example, the method further includes, upon completion of processing the media content, generating a unique identifier for the media content and caching results of the processing using the unique identifier. In yet another example, providing results of the previous analysis further includes providing auxiliary data previously identified as associated with the fragile watermark.

[0075]

[0086] For example, various aspects of the present disclosure have been described above with reference to block diagrams and / or operational diagrams of methods, systems, and computer program products according to various aspects of the present disclosure. The functions / acts shown in the blocks may be executed out of the order shown in any flowchart. For example, two blocks shown in succession may in fact be executed substantially simultaneously, or the blocks may be executed in the reverse order depending on the functions / acts involved.

[0076]

[0087] The description and illustration of one or more aspects provided in this application do not in any way limit or restrict the scope of the claimed disclosure. The aspects, examples, and details provided in this application are believed to be sufficient to convey ownership and enable others to make and use the best mode of the claimed disclosure. The claimed disclosure should not be construed as limited to any aspect, example, or detail provided in this application. Various features (both structural and methodological), whether shown and described in combination or separately, are selectively included or omitted to create embodiments having particular sets of respective features. The description and illustrations of this application have been provided, and variations, modifications, and alternative embodiments within the spirit of the broader aspects of the overall inventive concept embodied in this application may occur to those skilled in the art without departing from the broader scope of the claimed disclosure.

Claims

1. 1. A method for a computer to provide a key for a fragile digital watermark, comprising: receiving a request for a fragile watermark key, the fragile watermark key being used to generate a fragile watermark on the digital media content that provides an indication of origin for the digital media content; receiving an entity identifier; determining an entity associated with the request for the fragile watermark key, the entity being the creator of the digital media content, having the entity identifier associated with it, and having a plurality of fragile watermark keys associated with it; receiving additional information related to a particular entity that generates the digital media content; identifying a plurality of fragile watermark keys associated with the entity based on the entity identifier; selecting one or more fragile watermark keys from the plurality of fragile watermark keys based on the additional information; and providing the selected fragile watermark key to a requesting device; A method comprising:

2. receiving entity identification information; The method of claim 1 , further comprising verifying the entity identity.

3. the request identifying an asserted entity, the method further comprising: verifying the claimed entity; The method of claim 1 , wherein if the purported entity is verified and determined to be a trusted entity, the entity identifier of the trusted entity is received.

4. The method of claim 1 , wherein the entity is one of a trusted individual, a trusted organization, or a trusted device.

5. Auxiliary data is further identified based on the entity identifier, and the method further comprises: The method of claim 1 , further comprising providing the assistance data to the requesting device.

6. The method of claim 5 , wherein the auxiliary data is used to generate the fragile watermark.

7. The method of claim 5 , wherein the auxiliary data includes information about a device used to capture the digital media content.

8. The method of claim 5 , wherein the auxiliary data includes information about the digital media content.

Citation Information

Patent Citations

  • Electronic watermark processing method, electronic encryption processing method and digital contents distribution system

    JP2003179741A

  • Electronic watermark embedding system / electronic watermark verification system

    JP2005039686A

  • Information monitoring system, information monitoring method and storage medium

    JP2006325219A

  • Non-repudiation watermarking protection based on public and private keys

    US20030204729A1

  • License-based cryptographic technique particularly suited for use in a digital rights management system for controlling access and use of bore resistant software objects in a client computer

    US20050081042A1