Methods for document authentication

The method uses a token to print a visible mark on documents, encoding identifiers and timestamps, and stores encrypted copies, addressing the need for robust authentication of both physical and electronic documents by ensuring a verifiable association with a trusted token, thus enhancing security and reliability.

JP7843227B2Active Publication Date: 2026-04-09COLOP DIGITAL GMBH
View PDF 11 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2020-11-04
Publication Date
2026-04-09

AI Technical Summary

Technical Problem

Existing document authentication methods lack robust, fast, simple, and reliable verification mechanisms that can authenticate both physical and electronic documents without the need for printing, and do not provide a verifiable association between the document and a trusted physical token.

Method used

A method involving a registered token that prints a visible mark on a document, encodes a document identifier and timestamp into the mark, and stores an encrypted or scrambled copy of the document associated with the identifier, using a document storage service accessible via an internet-enabled host device for verification.

Benefits of technology

Provides a secure and reliable method to verify the authenticity of documents by ensuring a verifiable association between the document and a trusted token, enabling fast and simple authentication of both physical and electronic documents.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007843227000001
    Figure 0007843227000001
  • Figure 0007843227000002
    Figure 0007843227000002
  • Figure 0007843227000003
    Figure 0007843227000003
Patent Text Reader

Abstract

A method and token (3) for authenticating a document (25), the method including having a registered token (3) having a token identification, the token (3) being capable of printing a visible mark, obtaining a document identifier (18) based on at least the token identification and a timestamp, encoding the document identifier (19) into a visible mark (24), applying the visible mark (24) to the document (25), obtaining a copy (27) of the document (25) with or without the visible mark (24), and storing the copy in association with the document identifier. The token (3) includes storage for holding the token identification and a printing unit, the token (3) configured to receive a visible mark (24) encoding a document identifier associated with the token identification and to print the received visible mark (24). And a method for verifying a document (41) having a corresponding visible mark (42). The method includes obtaining a document identifier (18) based on at least the token identification information and a timestamp, encoding the document identifier (19) into a visible mark (24), applying the visible mark (24) to a document (25), obtaining a copy (27) of the document (25) with or without the visible mark (24), and storing the copy in association with the document identifier. The token (3) includes a storage unit for holding the token identification information and a printing unit, the token (3) configured to receive a visible mark (24) encoding a document identifier associated with the token identification information and to print the received visible mark (24). The method also includes a method for verifying a document (41) having a corresponding visible mark (42).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0006]

[0001] The present invention relates to a method for authenticating a document, a method for verifying a document having a visible mark, and a token for printing a visible mark on a physical document.

Background Art

[0002] Forgery and counterfeiting of physical documents (i.e., mostly paper documents) are widespread crimes that represent a constant threat to society. As a result, a wide variety of businesses and institutions are damaged. As a result, distrust arises among citizens and towards government agencies. As a result, trust in legal norms is impaired, affecting the sound economic development of many countries.

[0003] Advances in the fields of digital photographic equipment and digital printing equipment, together with state-of-the-art image processing software, have made it easier for criminals to counterfeit documents not only sporadically but sometimes even on a large scale.

[0004] Some of the most common types of physical seals used for document authentication involve the use of a handwritten signature, a fingerprint, or a stamp seal, and more recently, the use of holographic stickers, special invisible and indelible inks, and even synthetic DNA. The purpose of all these various types of seals is to prove the originator of the document to which the seal is attached. <​​​​​​In recent years, digital document authentication methods have developed significantly. Strong cryptographic algorithms based on public and private key combinations, along with digital signatures, enable online document transactions and, in principle, are more difficult to forge than physical copies.

[0007] Most existing prior art relies on the use of 2D matrix code regardless of the context in which it is applied, and is based only on the first use where the authenticity of the code itself is verified.

[0008] Patent Document 1 discloses a method for combining digital authentication methods and physical (or visual) authentication methods in an integrated and unified manner. The system of such an invention provides a digital seal of authentication and generates a physical artifact that can be verified by human visual inspection. The invention claims to provide an opportunity to improve the level of confidence in document authentication while maintaining the advantages of both conventional and digital authentication mechanisms. Limitations of such an invention are that at least one auxiliary document is required, and that there is no token mechanism and system to verify the signing authority of the person performing the authentication method on the original document. A further limitation of such an invention is that it is not possible to authenticate a completely electronic document or batch of documents without the need to print them out as physical documents.

[0009] Therefore, robust authentication (and confirmation) methods and corresponding verification methods that are fast, simple, affordable, and highly reliable are needed.

[0010] Patent Document 2 discloses a method for authenticating a printed document. This authentication is based on comparing the document with its electronic copy. The electronic copy is obtained using document management information embedded in a barcode marker printed on the document itself. The document management information may include a document ID or may be encoded in a two-dimensional barcode. The document management information does not contain information about the identification of the device used to create the barcode. There are no technical means to support barcode tracing for the barcode creator.

[0011] Patent Document 3 discloses a method and system for providing a signing scheme for physical documents. A user seeking to verify a signed document can use an identification information verification token to scan a quick response (QR) code containing a document identifier from the document. Using the document identifier, the user can read an electronic copy of the document from an identification information registrar and compare the displayed copy.

[0012] Patent Document 4 discloses a scheme in which a URL providing access to a copy of the original document for verification purposes is printed on the document.

[0013] Patent document 5 discloses a QR code attached to a document as a mark, which includes an identifier for reading a copy of the document. [Prior art documents] [Patent Documents]

[0014] [Patent Document 1] U.S. Patent No. 8037310 [Patent Document 2] U.S. Patent Application Publication No. 2011 / 0133887 [Patent Document 3] U.S. Patent No. 10110385 [Patent Document 4] International Publication No. 2016 / 113694 [Patent Document 5] U.S. Patent Application Publication No. 2015 / 0052615 [Overview of the project] [Problems that the invention aims to solve]

[0015] The objective of this invention is to create a verifiable association between a verified document and a specific trusted physical token used for verification. [Means for solving the problem]

[0016] The present invention proposes a method of the type described at the beginning, wherein the method has a registered token having token identification information, the token being capable of printing a visible mark, and the method includes obtaining a document identifier based on at least the token identification information and a timestamp, encoding the document identifier into a visible mark, affixing the visible mark to a document, obtaining a copy of the document with or without the visible mark, and storing the copy in association with the document identifier.

[0017] Optionally, the method may include printing a visible mark using a token before storing a copy, and reading and verifying the printed visible mark. If the document is a physical document, the visible mark may be printed on the document; if the document is an electronic document, the visible mark may be printed on any (physical) substrate.

[0018] In one embodiment, the method may include encrypting and / or scrambling the copy before storing it. The stored copy is not a clear copy, but an encrypted and / or scrambled version of the document. Scrambling in this case refers to a reversible (e.g., deterministic) operation performed on the data. For example, a random number generator with a predetermined constant seed may be used for scrambling.

[0019] In this context, the method may further include encrypting the copy using the cryptographic key associated with the token identifier. In this case, the copy of the document stored in association with the document identifier is an encrypted copy. To access the contents of the document, the encrypted copy must be encrypted with a decryption key, which may be the same key as the cryptographic key or the cryptographically associated decryption key (for example, the private key corresponding to the public key used as the cryptographic key).

[0020] For example, an optional embodiment of a method for verifying a document may include having a registered token having token identification information, the token being capable of printing a visible mark, obtaining a document identifier based on at least the token identification information and a timestamp, obtaining a document key, encoding the document identifier and the document key into a visible mark, affixing the visible mark to the document, obtaining a copy of the document with or without the visible mark, encrypting the copy so that it can be decrypted using the document key, and storing the copy in association with the document identifier.

[0021] Furthermore, the token may be paired with an internet-enabled host device that enables one or more of the following: securing login to the token by biometric identification, password identification, and / or PIN identification of an authorized user; transmitting a document identifier to a document storage database; reading a visible mark from the database; transmitting a visible mark to the token; taking an image or sequence of images of a document; transmitting an encrypted and / or scrambled image to the document storage database; or receiving a confirmation message from the document storage database.

[0022] A host device may generally be used as a token gateway to access the document storage database. The document storage database is not limited to a single database instance or location and may generally be provided by a document storage service.

[0023] In another embodiment, the document may be a physical document, and obtaining a copy of the document may include taking an image of the physical document either before or after attaching a visible mark to the document. The captured image of the physical document may be a digital image, in which case the copy corresponds to the image data of the said image. If the image is recorded only after attaching the visible mark to the document, the copy will encompass a representation of the visible mark that potentially includes any information encoded in the visible mark, and in the absence of this, such a representation and information encoded in the visible mark need not be present in the copy.

[0024] Attaching a visible mark to the document optionally includes printing the visible mark on the physical document using a token. The token may be a printing device, such as a manual operation printer that is manually moved over the target medium.

[0025] When the document is an electronic document, attaching a visible mark to the document optionally includes modifying the electronic document to include the visible mark. That is, the electronic representation of the document is modified such that, for example, when the electronic document is displayed on a screen, the visible mark is shown as part of the electronic document or as an attachment or annotation to the electronic document.

[0026] In a further embodiment, storing a copy in association with a document identifier may include transmitting the copy together with the document identifier to a document storage service, which stores the transmitted copy and the association with the document identifier, and the document storage service may be a centralized hosting service. The document storage service may be provided by a trusted third party, such as a physical token supplier. The document storage service may also be a decentralized service. The actual data storage of the document copy transmitted to the document storage service may be provided by another storage system, for example, by yet another third party, in which case the document content and the association or link between that content (in the form of the transmitted copy) and the document identifier may be stored by a different system, possibly in different locations. The document storage service may require authentication before accepting the transmission of the document copy.

[0027] A document storage service may include a database of blocks, and storing a transmitted copy may include creating a block that contains at least a previous block, a timestamp of the document identifier, and a cryptographic link to the cryptographic hash of the transmitted copy. Generally, the database may be a list of records, each item in the list referred to as a “block.” Subsequent blocks are cryptographically linked. For example, each block may contain the cryptographic hash of the previous block. Due to this linking from block to block, such a database is also referred to as a “blockchain.” Typically, the transmitted copy itself is not part of a block, but a transmitted copy may be associated with a particular block via a cryptographic hash. Transmitted copies of a document may be stored in the same database or in different databases or systems. Different transmitted copies of a document may be stored in different locations. Simultaneously, copies from different storage locations may be linked (or associated) with different blocks in the same, block database.

[0028] Simultaneously, in correspondence with the verification methods described above, the present invention also proposes a method for verifying a document having a visible mark, comprising reading the visible mark from the document, analyzing the visible mark to obtain a document identifier, reading a copy of the document using the document identifier, and providing the copy for verification of the document.

[0029] The methods for verifying documents apply in particular to documents verified according to the methods described above. Visible marks read from a document and parsed to obtain a document identifier are generally the same visible marks described in relation to the verification methods described above.

[0030] Optionally, within the scope of the method for verifying the document, parsing the visible mark may include obtaining a document key, the retrieved copy being encrypted, and the method may also include decrypting the encrypted copy using the document key to obtain an unencrypted copy, which is provided for document verification. The document key may be stored separately from the copy of the document. For example, the document key may be encoded in the visible mark and thus stored (possibly exclusively) in the original physical document itself.

[0031] According to one embodiment of a method for verifying a document having a visible mark, the method may include reading the visible mark from the document, analyzing the visible mark to obtain a document identifier and a document key from the visible mark, using the document identifier to read an encrypted copy of the document, using the document key to decrypt the encrypted copy to obtain an unencrypted copy, and providing the unencrypted copy for document verification.

[0032] According to another embodiment of the method described above, the document may be a physical document, and reading visible marks from the document may include taking an image or sequence of images of the physical document and locating the visible marks within the image. The image or sequence of images may be taken with a camera, such as a smartphone camera. Locating the visible marks within the image may include preprocessing steps and / or pattern recognition steps applied to the image data of the image.

[0033] Furthermore, optionally, retrieving a copy of a document may include sending a request with a document identifier to a document storage service and receiving a copy of the document associated with the document identifier from the document storage service. Access to the document storage service may be restricted to authenticated users, and receiving a copy of a document may thus follow an authentication process between the host device and the document storage service.

[0034] In yet another embodiment, providing a copy for document verification may include displaying the copy on a screen for visual comparison. Alternatively, or in addition to this, providing a copy for document verification may enable, for example, electronic processing of the read copy, i.e., determining the digital signature or other digital attributes of the copy.

[0035] More specifically, providing a copy for document verification may optionally include performing a comparison between the copy and a new copy of the document using visible markers and signaling the results of the comparison, the new copy being obtained for the purpose of comparative verification, and such automated comparison facilitates the identification of forgery and fraudulent attempts.

[0036] Simultaneously, in correspondence with the methods described above, the present invention also proposes a token for printing visible marks, comprising a storage and a printing unit for holding token identification information, wherein the token is configured to receive a visible mark encoding a document identifier associated with the token identification information and to print the received visible mark. Optionally, the token may be configured to receive a visible mark encoding a document identifier and a document key associated with the token identification information and to print the received visible mark. The storage for holding the token identification information may be configured such that the identification information cannot be erased, deleted, or manipulated by any means. For example, the identification information may be defined by a unique numerical device identifier, for example, of more than 40 bits, more than 80 bits, or 96 bits. The token identification information is not necessarily limited to a single numerical value, and there may be multiple equivalent valid representations, for example, by reading and concatenating different parts (e.g., single bits, half-words, or words) of the device identifier according to a predetermined deterministic algorithm. This algorithm may generate valid token identification information in a clearly defined array such that the next token identification information can only be predicted using knowledge of two or more previous token identification information generated from the device identifier. Therefore, in order to forge valid token identifiers, it is necessary to know those previous token identifiers. For example, if used token identifiers are registered by a document storage service, any irregularity in the expected sequence of token identifiers, which can be immediately identified, and the documents verified immediately before and after that point, can indicate that they are potential forgeries.

[0037] The token may be configured to verify whether the token identifier associated with the document identifier contained in the received visible mark corresponds to the token identifier of the token itself, i.e., the token identifier held in the token's storage. Only if this verification is successful is the print unit controlled to print the received visible mark.

[0038] The printing unit may be configured to erase received visible marks after printing, or even during printing, for example, as printing progresses. The printing unit may also be configured to monitor the limited validity period of a visible mark, for example, interruptions associated with the visible mark, such interruptions may be, for example, those against a timestamp embedded in the visible mark to avoid significant delays between the duration of the visible mark and the printing of the visible mark. When an interruption expires, the token irrecoverably erases any information in the visible mark.

[0039] Optionally, the token may be configured to authenticate the host device to which it is connected before receiving a visible mark from the host device for printing following authentication, and a pairing may be established between the token and the host device, for example, represented by a session. Reception of the visible mark for printing is accepted only insofar as the pairing remains uninterrupted until the visible mark is successfully received by the token. Typically, token identification information is transmitted from the token during this pairing, with the host device acting as a gateway to a remote visible mark generator. The visible mark generator may be configured to match the received token identification information against a list of authorized token identification information and generate a visible mark and, optionally, a document identifier to be embedded in the visible mark if a match is found. Alternatively, the document identifier may be generated by the token, for example, and transmitted to the visible mark generator along with the token identification information.

[0040] The Disclosure also optionally proposes a system comprising the aforementioned token, an Internet-enabled host device, and a document storage database, wherein the token is paired with the Internet-enabled host device, and the Internet-enabled host device is configured to provide one or more of the following: secure login to the token by biometric, password, and / or PIN identification of an authorized user; transmit a document identifier to the document storage database; read a visible mark from the document storage database; transmit a visible mark to the token; capture an image or sequence of images of a document; transmit an encrypted and / or scrambled image to the document storage database; and receive a confirmation message from the document storage database.

[0041] In one optional embodiment, the system's document storage database can be provided by a document storage service, which is configured to receive and store encrypted copies of documents associated with document identifiers. [Brief explanation of the drawing]

[0042] The drawings, which are used here to illustrate the present disclosure, are not intended to limit the present invention. [Figure 1] Figure 1 schematically shows a flowchart of the process of initializing and using a token in a method of verifying a document using a visible mark. [Figure 2] Figure 2 schematically shows the steps performed between the steps illustrated in Figure 1, from the user's perspective. [Figure 3] Figure 3 schematically shows the steps performed between the steps illustrated in Figure 1, from the user's perspective. [Figure 4] Figure 4 schematically shows the steps performed between the steps illustrated in Figure 1, from the user's perspective. [Figure 5] Figure 5 schematically shows the steps performed between the steps illustrated in Figure 1, from the user's perspective. [Figure 6] Figure 6 schematically shows the steps performed between the steps illustrated in Figure 1, from the user's perspective. [Figure 7] Figure 7 schematically shows the steps performed between the steps illustrated in Figure 1, from the user's perspective. [Figure 8] Figure 8 schematically shows a flowchart of the process for verifying documents that have visible marks. [Figure 9] Figure 9 schematically shows the steps performed between the steps illustrated in Figure 8, from the user's perspective. [Figure 10] Figure 10 schematically shows the steps performed between the steps illustrated in Figure 8, from the user's perspective. [Figure 11] Figure 11 schematically shows the steps performed between the steps illustrated in Figure 8, from the user's perspective. [Figure 12] Figure 12 schematically shows the steps performed between the steps illustrated in Figure 8, from the user's perspective. [Figure 13] Figure 13 schematically shows the steps performed between the steps illustrated in Figure 8, from the user's perspective. [Figure 14] Figure 14 schematically shows the steps performed between the steps illustrated in Figure 8, from the user's perspective. [Figure 15] Figure 15 schematically shows the steps performed between the steps illustrated in Figure 8, from the user's perspective. [Figure 16] Figure 16 schematically shows the steps performed between the steps illustrated in Figure 8, from the user's perspective. [Figure 17] Figure 17 schematically shows a sequence diagram of a method for verifying a physical document, similar to the method shown in Figure 1. [Figure 18] Figure 18 schematically shows a sequence diagram of a method adapted for verifying digital documents, similar to that shown in Figure 17. [Figure 19] Figure 19 schematically shows a sequence diagram of a method for verifying documents with visible marks, similar to the method shown in Figure 8. [Modes for carrying out the invention]

[0043] Figure 1 illustrates the sequence of steps from obtaining a token in accordance with this disclosure to completing document verification. This sequence of steps is an exemplary, ideal sequence of steps, ignoring (for illustrative purposes) any context-dependent conditions, user or technical failures or errors, and the initial steps until the host device is configured must be performed only once before first use. These steps belong to Initialization Procedure 1 (see also Figure 17).

[0044] In the first step, step 2, the issuer, referred to here as "Trustworthy Company Ltd," purchases a physical token 3 (also referred to as the "authentication device") from a trusted vendor. The physical token 3 has storage that holds token identification information in the form of a unique device ID. In step 4, the trusted vendor links the unique device ID of the physical token to the issuer's account and identification information in a secure database managed by the trusted vendor. Then, in step 5, the software (referred to as the "Auth app") is sent to the issuer. In step 6, the issuer distributes this software application to authorized users within the company, who then log in to the software application by installing it on their respective personal devices 7 (e.g., smartphones) and entering their personal user authentication information. Logging in to access the authentication software application may also be performed by entering a PIN code displayed on the screen 9 of the personal device 7 and entering it into the authentication dialog 8 (see Figure 2). As shown in more detail in Figure 7, after successful login, a pairing connection 10 (an encrypted wireless connection, such as using Bluetooth or Wi-Fi) is established between the physical token 3 and the personal device 7. The personal device thereby functions as the host device for token 3, provided that the pairing connection 10 remains unbroken. Through the pairing connection 10, the host device 7 reads the token identification information. Using the received token identification information, the host device 7 sends a registration request 12 to the document storage service 13, which includes the received token identification information and the identification information of the personal device 7. The document storage service 13 compares the received token identification information with a list of valid and available token identification information. In step 14, the document storage service 13 also verifies whether the user identified by the user authentication information in the software application is associated with the registered issuer.If the matching and verification are successful, the document storage service 13 transmits the authorization secret key 15 to the host device 7 for future authentication with the document storage service 13. This step completes initialization procedure 1.

[0045] To perform document verification, in step 16, the user enters the command “Create Authentication Stamp” into the software application (see Figure 3). For example, there may be a graphical button that can be interacted with to issue the command. In accordance with this command, in step 17, the software application establishes (or re-establishes) a pairing connection 10 between the host device 7 and the token 3, creates a document identifier, and the document identifier is optionally sent to the document storage service 13 along with the document key (see Figure 17), or is also generated by the software application (or the document identifier is derived from the document key). The document identifier may take the form of a random link to a document storage location in the document storage service 13. Optionally, the software application may load token identification information, (e.g., GPS-based) location coordinates, current date and time, and numbering from the host device 7, e.g., storage or system information, and send this, or part of this information, along with the document identifier to the document storage service 13. In this context, numbering means that every printing (or "stamping") operation is counted for every token (i.e., a total count per token). This is an accumulated stamp count equal to the number of times the token has been marked with a visible mark. In the next step 18, the document storage service 13 generates a visible mark, for example, in the form of a QR code. Due to the random nature and size of the document identifier, the visible mark is practically unique (although theoretically, the same visible mark could be generated multiple times by chance). In addition to the QR code, the visible mark may be extended using existing graphics to make the printed visible mark recognizable as such. The visible mark may include further information received from the host device. The visible mark may also include a public key for accessing an encrypted copy of the document. When ready, the visible mark is sent to the host device 7, from which it is transferred to the token 3 for printing.The visibility mark may optionally be generated directly on the host device 7, so that the public key does not leave the host device 7 except for printing by the (trusted) token 3. In that case, the document storage service 13 may be notified of the document identifier, but will not receive the complete information embedded in the visibility mark.

[0046] When the visible mark is received by token 3 for printing, in step 21, the user uses the physical token 3 to place the visible mark 24 onto the physical document 25 (i.e., print it (see Figure 4)). During and after printing, in step 22, token 3 reports the printing status to the host device 7 and the software application. When the software application receives notification that printing is complete, in step 23, the software application automatically launches the mark scan view 30 (see Figure 6). In the first scan step 31, the user is requested to scan the visible mark, i.e., to point the camera so that the visible mark is within the field of view of the host device 7's camera. Based on this first scanned view, the software application performs verification 28 of the visible mark 24 by detecting and extracting the visible mark 24 from the first scanned image and comparing it with the generated version of the visible mark. If this verification 28 is successful, the software application launches the document scan view The user launches the 26 (see Figure 5). In the second scan step 27, the user is prompted to scan the entire document. The process of scanning the visible markers and the subsequent entire document can optionally be implemented using a video stream instead of separate photos / scans. Using a video stream can provide the process with additional reliability and security. Based on the second scanned view(s), in step 32, the software application scrambles and encrypts the second scanned view(s) showing the entire document, and in step 33, transmits it to the document storage service 13 to upload to a previously created link. In step 106, a block is created using the document data as transaction data and linked to a previous block with a cryptographic hash. If the block creation and linking are successful, the document storage service 13, and the software application after receiving confirmation 35, confirm the confirmation by displaying the confirmation view 34 (see Figure 7).

[0047] Figure 17 illustrates further embodiments and variations of the method for verifying a document according to this disclosure. Specifically, in the example shown in Figure 17, the host device 7 establishes a pairing connection with the token 3 after authenticating the user by requesting login 105. In this case, the document identifier generated in step 18 according to Figure 1 is transmitted to the document storage service 13 in step 36. The document storage service 13 performs step 19 to generate a visible mark based on the received document identifier (unlike the embodiment shown in Figure 1, where the visible mark is generated on the host device 7). In this example, the public key cryptographically associated with the authorization secret key 15 is included in the visible mark. Then, in step 38, the generated visible mark is optionally sent back to the host device 7 in an encrypted form, which acts as a gateway and, in step 39, transfers the visible mark to the token 3 after optionally encryption and conversion to printable image format. However, the host device 7 does not store the visible mark after it has been transmitted to the token 3. Token 3 stores the received visible mark (or, more precisely, image information representing the visible mark to be printed) in random access memory (RAM). The printing step 21, in which the visible mark is applied to the document, is performed by the user as in Figure 1, and after printing, Token 3 does not retain any information relating to the content of the visible mark. Token 3 notifies the host device 7 in step 40 that the print job is complete. In the example shown in Figure 17, in step 29, the software application directly activates the mark scan view (i.e., the scanning function of the host device 7). In step 31, the user scans the visible mark, and the host device 7 directly performs the (final) verification 32. In this case, the preliminary verification 28 is not required. If the (final) verification 32 is successful, in step 23, the software application activates the document scan view 26, and in step 27, the user scans the rest of the document. The scan views may be various views, and these scan views may be various time spans in the same video recording. Once all documents have been scanned, proceed to step 33 as described above.Based on the received document information, the document storage service 13 creates a block in step 106 to be added to the blockchain held or accessed by the document storage service 13. Once a new block is added to the blockchain, the document storage service 13 sends a confirmation 35 to the host device 7.

[0048] Figure 8 shows an exemplary version of a simplified method for verifying a document 41 bearing a visible mark 42. The purpose of verification is to determine the origin of the visible mark 42 and, by extension, to verify the integrity of the content of the document 41 bearing the visible mark 42. The method described in detail herein can be carried out by a personal device 43 having a display 44, a camera, and data connectivity, such as a smartphone.

[0049] In step 45, the user receives document 41 and wishes to verify the authenticity of document 41. To perform the verification, the user may install a verification application (for example, referred to as "Ver App") on their personal device 43. In step 46, the user checks whether the verification application is available on their personal device 43. In negation 47, the user follows the instructions given in visible mark 42 and, in step 48, scans another QR code (i.e., one based on the document identifier, and not the secure QR code) that has a link to initiate the installation procedure to configure the verification application on their personal device 43.

[0050] If the verification application was present from the beginning or was successfully installed, in step 49, the user enters a verification command into the verification application by pressing a button labeled, for example, "Verify Document Authenticity." Triggered by this command, in step 50, the application launches the Mark Scan View 51. In step 52, the user is requested and instructed to scan the secure QR code of the visible mark 42. As soon as the secure QR code is recognized and the document identifier is determined, in step 53, the verification application begins downloading a copy of the document from the document storage service 13. The downloaded copy may be encrypted. In step 54, the verification application begins decrypting the encrypted copy using the private key of the registered personal device 43 and the document key embedded in the visible mark 42. In parallel, in step 55, the application transitions to the document scan view 56, and in step 57, the user is prompted to scan all documents to be verified. Once all scanned copies are available and the downloaded copies have been decrypted, in step 58, the verification application compares the two versions of the same document to determine if the two versions are identical. The comparison may also take into account additional product information, such as location or timestamp information.

[0051] In step 59, if the two versions match well enough, the verification is successful, and in step 60, the verification application indicates the confirmation of the verification method 61. If the automatic comparison does not find a (sufficient) match, in step 62, the verification application presents the user with a failure report 63 via buttons labeled, respectively, with the option to “manually check the document.” This is preferable if the user decides to perform a manual check. The user is shown scanned copies 70 (see Figure 14) and can place hard copies 71 side by side to compare them in step 69. The official versions are downloaded from the document storage service and are optionally signed and / or encrypted. In step 68, if the set of documents matches, in step 64, the verification process is complete. Otherwise, in step 65, the verification application may, if necessary, present further details related to the stamp product in detail view 72 and / or location view 73 (showing the location of the visible marks and the creation of token 3) to facilitate manual verification (see Figure 15). In step 66, the verification application reads all the details associated with the specific token. It is useful that this disclosure may be configured in step 67 for the user to independently determine the authenticity of the document. This is the final step in the verification method.

[0052] As shown in Figure 16, the same method steps are applied in principle to scanning electronic documents. Furthermore, visible marks on this type of document can be verified in the same manner as described above. In particular, a personal device 43 is shown with a mark scan view 51, where the camera of the personal device 43 is pointed at the screen 74 of a document viewing device 75, such as a tablet, laptop, or personal computer. The visible marks 42 are displayed on the screen 74 along with the document 41, which is an electronic document in this case.

[0053] Accordingly, Figure 18 shows a further variation of the method of verifying a document according to this disclosure. Specifically, in the example shown in Figure 18, the document to be verified is an electronic document stored and processed on the document editing device 76. During initialization procedure 1, in step 77, the document authentication application is installed on the document editing device 76. The pairing and messaging between token 3, host device 7, and document storage service 13 are the same as those described in relation to Figure 17. Furthermore, only at the end of the procedure, a copy of the authorization secret key 15 is optionally transmitted to the document editing device 76 via the host device 17.

[0054] The actual verification process begins with a login 78 on the document editing device 76 using the authentication credentials of an authorized user, once the initialization procedure is complete. Triggered by a user command, the document editing device 76 sends a request to the document storage service 13 for authentication and verification of the electronic document. In any order, and generally simultaneously, the user also performs a login 105 on the host device 7, similar to what has been described in relation to Figure 17. By each login 78, 105, access to the authorization secret key 15 is granted, and with that access, the host device 7 and optionally the document editing device 76 establish pairing connections 10, 79 with the token 3. The next steps, from transmitting the document identifier in step 36 to scanning the printed visible mark and performing verification 32 in step 31, are the same as those described in relation to Figure 17, except that the visible mark is not printed on the document to be verified, but on any available substrate (e.g., any paper) and scanned from there. This printing process is used as physical confirmation that token 3 was indeed under the control of the user performing the verification. In parallel, the visible mark is transmitted in step 80 from the document storage service 13 to the document editing device 76, optionally protected with the authorization key 15 (e.g., encrypted with a public key). This transmission may be performed via a general-purpose data connection, such as the cloud, or alternatively, delegated through the host device 7 and / or token 3. The document editing device 76 places the visible mark in the electronic document, and then in step 81, scrambles and encrypts the resulting marked electronic document. If verification 32 is successful, the host device 7 transmits a confirmation message 82 to the document editing device 76. Alternatively, the scan 31 can be performed by a general-purpose document scanner connected to the document editing device 76, without requiring it to be performed using the host device 7. In that case, verification 32 may be performed locally by the document editing device 786.After receiving the confirmation (or local verification), the document editing device 76 sends the marked version of the electronic document to the document storage service 13 in step 83 to create a block in the blockchain database in step 106. Once the block is added to the database, the document storage service 13 confirms the completion of the confirmation of the electronic document in step 84 and returns it to the document editing device 76. Based on this confirmation, the document editing device 76 may print the marked version of the electronic document and / or begin digital distribution (e.g., via email) in step 85.

[0055] Figure 19 shows in more detail two variations of the method for verifying a document 41 (physical or electronic) having a visible mark 42. During the initialization procedure 86, which is naturally a one-time process for each personal device 43, in step 48, the user installs a verification application on the personal device 43 (see Figure 8). When the user enters a verification command in step 49, in step 50, the application launches a mark scan view, which may be a video scan function (i.e., live preview with automatic document recognition and capture). In step 52, the personal device 43 scans the visible mark 42 on the document 41. The visible mark 42 may be a QR code with encoded data content. In step 87, the personal device 43 sends the visible mark (or its data content) to the document storage service 13. The document storage service 13 compares the visible mark and, for example, a document identifier contained in the received visible mark, with a stored copy of the identified document or a stored representation (e.g., a hash) of that copy. Using this information, the document storage service 13 searches for a block in its database of blocks containing the cryptographic hash of the same copy in step 88. If a matching block is found, the document storage service 13 sends confirmation 89, along with the associated copy (or a link to the copy), to the personal device 43. Meanwhile, the personal device 43 locally verifies the format of the visible mark 42 in step 90 and continues scanning any further portions of the document 41 in step 91. After receiving the copy from the document storage service 13, the personal device 43 decrypts and reconstructs (i.e., descrambles) the received copy in step 92. In the first modification 93 of the method illustrated in Figure 19, the verification is performed offline, for example, due to insufficient network coverage and online access. In this case, the above steps are limited to the local verification 90 of the visible mark 42. Subsequently, the data content embedded in the visible mark 42 is displayed on the personal device 43 for reference and manual verification in step 94.In this example, the displayed data includes supporting information (e.g., issuer / office, location, date, and time). The user can verify the validity of the displayed information.

[0056] In the second modification 95, the verification method is performed using access to the document storage service 13, for example, online access. In this case, the personal device 43 performs a first level of automated image comparison 96 between the scanned document (in step 91) and the received copy based on the received document copy. The results of this comparison are displayed to the user for reference in step 97. In addition, the matching results are transmitted to the document storage service 13 in step 98. Also, in step 99, a newly scanned copy is transmitted to the document storage service 13. The document storage service 13 performs a second level of automated image comparison 100 between the document copy registered during verification and the new copy just received from the personal device 43. Then, in step 101, the document storage service 13 transmits the results of the second level of comparison to the personal device 43 for the user's information. During these remote steps, the personal device 43 displays locally a previously received copy of the document from the document storage service 13 in step 102, enabling a manual comparison 103 with the document to be verified. Finally, after the personal device 43 receives the results of the second level of image comparison, it also displays these results for the user's review. If both automated image comparisons yield a similarity above a certain threshold, the personal device 43 indicates a confirmation 61 (see Figure 12).

Claims

1. A method for storing a reference copy of document (25), Having a registered token (3) having token identification information, wherein the token (3) is capable of printing a visible mark, At least based on the token identification information and timestamp, the host device (7) connected to the token (3) obtains a document identifier (18), The host device (7) or the document storage service (13) that receives the document identifier encodes the document identifier into a visible mark (24) (19), The token (3) is used to affix the visible mark (24) to the document (25), The host device (7) obtains a reference copy (27) of the document (25) with or without the visible mark (24), The host device (7), or the document storage service (13) that receives the reference copy and the document identifier, stores the reference copy in association with the document identifier. Methods that include...

2. Before storing the aforementioned reference copy, Printing the visible mark (24) using the token (3) (21), Reading and verifying the printed visible mark (24) (31) The method according to claim 1, characterized by the above.

3. The method according to claim 1 or 2, characterized in that the reference copy is encrypted and / or scrambled before being stored.

4. The method according to claim 3, characterized by encrypting the reference copy using the cryptographic key associated with the token identification information.

5. The method according to any one of claims 1 to 4, characterized in that the token (3) is paired with an internet-enabled host device (7) that enables login (105) to the token (3) by biometric identification, password identification, and / or PIN identification of an authorized user.

6. The method according to any one of claims 1 to 4, characterized in that the token (3) is paired with an internet-enabled host device (7) that enables the transmission of a document identifier to a document storage database (36).

7. The method according to any one of claims 1 to 4, characterized in that the token (3) is paired with an internet-enabled host device (7) that enables reading visible marks from a database (38).

8. The method according to any one of claims 1 to 4, characterized in that the token (3) is paired with an internet-enabled host device (7) that enables the transmission (39) of a visible mark (24) to the token (3).

9. The method according to any one of claims 1 to 4, characterized in that the token (3) is paired with an internet-enabled host device (7) that enables taking an image or sequence of images of the document (25) (31, 27).

10. The method according to any one of claims 1 to 4, characterized in that the token (3) is paired with an internet-enabled host device (7) that enables the transmission (33) of encrypted and / or scrambled images to a document storage database.

11. The method according to any one of claims 1 to 4, characterized in that the token (3) is paired with an internet-enabled host device (7) that enables receiving a confirmed message (35) from a document storage database.

12. The method according to any one of claims 1 to 11, wherein the document (25) is a physical document, and obtaining a reference copy of the document includes taking an image (27) of the physical document before or after affixing the visible mark (24) to the document (25).

13. The method according to claim 12, characterized in that affixing the visible mark (24) to the document (25) includes printing the visible mark (24) on the physical document (21) using the token.

14. The method according to any one of claims 1 to 13, characterized in that the document (25) is an electronic document, and affixing the visible mark to the document includes modifying the electronic document (80) to include the visible mark.

15. The method according to any one of claims 1 to 14, wherein storing the reference copy in association with the document identifier includes transmitting the reference copy together with the document identifier to a document storage service (13) (33), and the document storage service (13) stores the transmitted reference copy and the association with the document identifier.

16. The method according to claim 15, wherein the document storage service (13) includes a database of blocks, and storing the transmitted copy includes creating a block that contains at least a previous block, the timestamp of the document identifier, and a cryptographic link to the cryptographic hash of the transmitted copy.

Citation Information

Patent Citations

  • Printing and copying system with time stamp having prevention function of tampering

    JP2003323512A

  • System, method and program for outputting information for falsification detection

    JP2010050906A

  • Information processing device

    JP2013225223A

  • Duress signatures

    US10110385B1

  • Image registration method for image comparison and document authentication

    US20110133887A1