Programs, terminal devices, methods, systems, and physical media

JP7905078B1Active Publication Date: 2026-08-14鎌田 理喜 +1
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-12-17
Publication Date
2026-08-14

AI Technical Summary

Benefits of technology

【0009】 本開示によれば、物理媒体に記憶されたデジタルコンテンツの信頼性を高めることができる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007905078000001_ABST
    Figure 0007905078000001_ABST
Patent Text Reader

Abstract

The goal is to improve the reliability of digital content stored on physical media. [Solution] A program according to one aspect of the present disclosure is a program for operating a computer comprising a processor and memory, the program causing the processor to perform the following steps: communicate with a security IC of a physical medium comprising a content recording unit on which digital content is recorded, and a security IC that stores a hash value of the digital content and unique identification information, and obtain unique identification information and a hash value; verify the authenticity of the physical medium itself using the obtained unique identification information; and verify the authenticity of the digital content by comparing the obtained hash value with a genuine hash value that has been registered in advance in association with the unique identification information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a program, a terminal device, a method, a system, and a physical medium.

Background Art

[0002] Conventionally, as countermeasures against forgery of physical media, identification means such as serial number engraving and hologram sticking have been used. Further, as a more advanced technology, a technology is known in which an IC chip is built into a medium and the authenticity is determined using its uniqueness.

[0003] For example, Patent Document 1 discloses a technique for detecting an unauthorized copy (clone) of an IC chip itself by synchronizing an authentication count counter between the IC chip and an authentication authority server and collating the consistency.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] However, although the technique described in Patent Document 1 can verify that the IC chip is not a clone, that is, the authenticity of the physical medium, it is outside the scope of verification for the integrity of the data as to whether the digital content recorded inside the medium has been tampered with after manufacture.

[0006] Particularly, in the secondary distribution market for collectible items and the like, if there is no means for easily and immediately verifying authenticity on the spot without the purchaser having specialized knowledge or equipment, the risk of counterfeit products and pirate copies circulating cannot be eliminated, which has been an obstacle to safe transactions.

[0007] The purpose of this disclosure is, in light of these circumstances, to enhance the reliability of digital content stored on physical media. [Means for solving the problem]

[0008] To solve the above problems, a program according to one aspect of the present disclosure is a program for operating a computer comprising a processor and memory, the program causing the processor to perform the following steps: communicate with a security IC of a physical medium comprising a content recording unit on which digital content is recorded, a hash value of the digital content, and a security IC that stores unique identification information, and obtain unique identification information and a hash value; verify the authenticity of the physical medium itself using the obtained unique identification information; and verify the authenticity of the digital content by comparing the obtained hash value with a genuine hash value that has been registered in advance in association with the unique identification information. [Effects of the Invention]

[0009] According to this disclosure, the reliability of digital content stored on physical media can be improved. [Brief explanation of the drawing]

[0010] [Figure 1] This is a block diagram showing the overall configuration of an authenticity verification system according to one embodiment of the present disclosure. [Figure 2] This is a block diagram showing an example of the functional configuration of a physical medium. [Figure 3] This block diagram shows an example of a functional configuration of a terminal device. [Figure 4] This block shows an example of a functional configuration for the management server. [Figure 5] This figure shows an example of the data structure of an authenticity verification table. [Figure 6] This figure shows an example of the data structure of a physical media table. [Figure 7] This is a flowchart illustrating an example of the authenticity verification process. [Figure 8] This figure shows an example of a verification results screen. [Figure 9] This is a sequence diagram showing an example of the ownership transfer process. [Figure 10] This figure shows an example of the ownership history screen. [Figure 11] This is a block diagram showing the basic hardware configuration of a computer. [Modes for carrying out the invention]

[0011] The embodiments of this disclosure will be described below with reference to the drawings. In all the drawings illustrating the embodiments, common components are denoted by the same reference numerals, and repeated explanations are omitted. The following embodiments are not intended to unduly limit the content of this disclosure as described in the claims. Not all components shown in the embodiments are necessarily essential components of this disclosure. Also, each drawing is a schematic diagram and is not necessarily a strict illustration.

[0012] Furthermore, in the following description, "processor" refers to one or more processors. At least one processor is typically a microprocessor such as a CPU (Central Processing Unit), but may be another type of processor such as a GPU (Graphics Processing Unit). At least one processor may be single-core or multi-core.

[0013] Furthermore, at least one processor may be a broad-sense processor, such as a hardware circuit that performs some or all of the processing (e.g., an FPGA (Field-Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit)).

[0014] In the following description, the expression "xxx table" may be used to describe information from which an output can be obtained for an input. This information may be data of any structure or a learning model such as a neural network that generates an output for an input. Therefore, "xxx table" can be referred to as "xxx information".

[0015] In the following description, the configuration of each table is an example. One table may be divided into two or more tables, or all or part of two or more tables may be combined into one table.

[0016] In the following description, the "program" may be used as the subject to describe a process. However, since the program is executed by a processor to perform a defined process while appropriately using a storage unit and / or an interface unit, etc., the subject of the process may be the processor (or a device such as a controller having that processor).

[0017] The program may be installed in a device such as a computer, or may be, for example, in a program distribution server or a computer-readable (e.g., non-transitory) recording medium. In the following description, two or more programs may be realized as one program, or one program may be realized as two or more programs.

[0018] In the following description, an identification number is used as identification information for various objects, but identification information of other types (e.g., an identifier including letters or symbols) may be adopted.

[0019] In the following description, when describing elements of the same type without distinction, reference signs (or common signs among reference signs) are used, and when describing elements of the same type separately, the identification numbers (or reference signs) of the elements may be used.

[0020] Furthermore, in the following explanation, control lines and information lines are shown only those deemed necessary for the explanation, and not all control lines and information lines are necessarily shown in the actual product. All components may be interconnected.

[0021] Each information processing device consists of a computer equipped with an arithmetic unit and a memory device. The basic hardware configuration of the computer and the basic functional configuration of the computer realized by said hardware configuration will be described later. For each of the physical medium 100, terminal device 200, playback device 300, and management server 400, explanations that overlap with the basic hardware configuration and basic functional configuration of the computer described later will be omitted.

[0022] (First Embodiment) <1. Overview> The authenticity verification system 1 according to this first embodiment enables a user to simultaneously verify, with a single operation using a terminal device 200, that a physical medium 100 on which digital content is recorded is genuine (physical authenticity) and that the digital content inside has not been tampered with (data integrity). By simply holding the terminal device 200 over the physical medium 100, the user can instantly confirm whether the collectible item they intend to purchase is genuine or not, without requiring specialized knowledge or equipment. This contributes to the creation of a secure secondary market and protects and enhances the asset value of digital content recorded on physical media.

[0023] Figure 1 is a block diagram showing an example of the overall configuration of the authenticity verification system 1 related to this disclosure. System 1 comprises, as its main components, a physical medium 100 to be verified, a terminal device 200 that performs verification processing, and a management server 400 that manages authenticity information that serves as the basis for verification. The terminal device 200 and the management server 400 communicate via a wide-area network 500. The physical medium 100 and the terminal device 200 communicate directly using short-range wireless communication such as NFC.

[0024] Furthermore, System 1 may optionally include a playback device 300 for playing back digital content recorded on a physical medium 100. In Figure 1, the playback device 300 is shown with a dashed line because it is not essential for the basic operation of the system, but is a component introduced to realize more advanced functions, such as dynamic updating of hash values ​​or transfer of ownership, as will be explained in the modified examples below. The specific configuration and operation of the playback device 300 will be described in detail in the modified examples section.

[0025] Figure 1 shows an example where System 1 includes one terminal device 200, for the sake of illustration simplification. However, in reality, System 1 may include multiple terminal devices 200 for use by multiple users.

[0026] Figure 1 shows an example where System 1 includes one management server 400, but for example, a collection of multiple devices may be considered as one management server 400. The method of distributing the multiple functions required to realize the management server 400 to one or more hardware can be appropriately determined according to the processing capacity of each hardware and / or the specifications required for the management server 400.

[0027] The physical medium 100 is the object of verification in this embodiment and is a collectible item such as a trading card, figurine, game cartridge, or other memento. The physical medium 100 incorporates a content recording unit that records digital content and a security IC that stores information to prove its authenticity.

[0028] The terminal device 200 is, for example, an information processing device operated by a user. The terminal device 200 may be implemented as, for example, a smartphone, a tablet device, or a portable game console. The terminal device 200 comprises a processor 29, memory 22, storage 23, an input device, an output device 24, and a communication interface (IF).

[0029] The management server 400 is, for example, an information processing device for managing and operating authenticity certification services, and is implemented by a computer connected to the wide-area network 500. The management server 400 manages a database by associating the unique identification information of each physical medium 100 with the corresponding hash value of the authentic digital content at the time of factory shipment.

[0030] Each information processing device, such as the terminal device 200 and the management server 400, may be composed of a computer 90 equipped with an arithmetic unit and a memory device. The basic hardware configuration of the computer 90 and the basic functional configuration of the computer 90 realized by said basic hardware configuration will be described later.

[0031] <2. Physical Media Configuration> Figure 2 is a block diagram showing an example of the functional configuration of the physical medium 100. The physical medium 100 comprises a content recording unit 110 and a security IC 120. The content recording unit 110 records digital content. The security IC 120 is a tamper-resistant IC chip and comprises a communication unit 121, a storage unit 122, and a control unit 125. The storage unit 122 securely stores an authenticity verification table 1221 containing unique identification information, the issuer's digital signature, and the content hash value, as well as its own private key 1222. The control unit 125 uses this private key 1222 to perform cryptographic processing such as signature generation in response to external requests.

[0032] The content recording unit 110 is a non-volatile storage medium for physically recording digital content. For example, flash memory, ROM (Read Only Memory), etc., can be used. Digital content can include image data, video data, audio data, game programs, or combinations thereof.

[0033] The security IC 120 is a tamper-resistant IC chip designed to securely protect the information stored inside. The security IC 120 comprises a communication unit 121 and a storage unit 122. The communication unit 121 conforms to a near-field wireless communication standard such as NFC and includes an antenna and communication circuit for contactless communication with an external reader / writer (terminal device 200 in this embodiment).

[0034] The storage unit 122 has a tamper-resistant and secure storage area that is difficult or impossible to rewrite, preventing unauthorized reading or alteration of internal data. This secure storage area stores an authenticity verification table 1221 (see Figure 5) which contains information necessary for verifying authenticity. Specifically, the authenticity verification table 1221 consists of multiple data fields, such as unique identification information for uniquely identifying the physical medium 100, the issuer's digital signature proving that the medium was manufactured by a legitimate issuer, and a content hash value that guarantees the integrity of the digital content recorded in the content recording unit 110. Furthermore, as will be explained in the modified examples described later, it may also have an area for adding information such as a monotonic counter indicating the number of times the hash value has been updated and an ownership transfer history indicating the history of ownership. This monotonic counter is set to 0 at the time of factory shipment and has a tamper-proof function that only allows an increase in its value.

[0035] Furthermore, the physical medium 100 may be equipped with protective mechanisms to make physical modification or replacement of components difficult. For example, a configuration in which the content recording unit 110 and the security IC 120 are integrally sealed (potted) with resin is conceivable. This makes it physically difficult for a malicious third party to replace only the content recording unit 110 with another one or analyze the security IC 120, thereby increasing the robustness of the entire system.

[0036] <3. Configuration of terminal equipment> Figure 3 is a block diagram showing an example of the functional configuration of the terminal device 200. As shown in Figure 3, the terminal device 200 comprises a wide-area communication unit 210, a short-range communication unit 220, an input device 230, an output device 240, an audio processing unit 270, a camera 280, a location information sensor 290, a storage unit 250, and a control unit 260. Each block included in the terminal device 200 is electrically connected, for example, by a bus.

[0037] The wide-area communication unit 210 performs modulation and demodulation processing, etc., for the terminal device 200 to communicate with other devices (especially the management server 400) via the wide-area network 500. The wide-area communication unit 210 performs transmission processing on signals generated by the control unit 260 (e.g., a request for a true hash value) and transmits them externally. It also performs reception processing on signals received from external sources (e.g., a response from the management server 400) and outputs them to the control unit 260.

[0038] The short-range communication unit 220 complies with short-range wireless communication standards such as NFC (Near Field Communication) and performs contactless communication with the security IC 120 of the physical medium 100. Specifically, based on instructions from the control unit 260, it sends an information read request to the physical medium 100 and outputs the received signal as a response to the control unit 260.

[0039] The input device 230 is a device for users operating the terminal device 200 to give instructions or input information. The input device 230 is implemented, for example, by a touch-sensitive device (touch panel) 231 integrated into the display surface of the output device 240. Users perform operations such as launching a dedicated application 251 or starting a verification process via the input device 230.

[0040] The output device 240 is a device for presenting information to the user operating the terminal device 200. The output device 240 is implemented, for example, by a display 241. The display 241 displays data (e.g., verification result screen, ownership history screen) according to the control of the control unit 260. The display is implemented, for example, by an LCD (Liquid Crystal Display) or an organic EL (Electro-Luminescence) display.

[0041] The audio processing unit 270 performs, for example, digital-to-analog conversion processing of the audio signal. The audio processing unit converts the signal received from the microphone 271 into a digital signal and provides the converted signal to the control unit 260. It also provides the audio signal to the speaker 272.

[0042] The camera 280 is a device that receives light using a photodetector and outputs it as a shooting signal. The position information sensor 290 detects the current location of the terminal device 200 using GPS (Global Positioning System) or the like. This position information can be used when recording authenticity verification logs, as will be explained in the modified examples described later, and is useful in further enhancing the security of the system.

[0043] The storage unit 250 consists of a memory 25, storage 26, etc., and stores programs (OS, etc.) and various data necessary for the operation of the terminal device 200. The storage unit 250 stores at least a dedicated application 251 for executing the processing according to this embodiment and the issuer's public key 252 for verifying that the issuer of the physical medium 100 is legitimate.

[0044] The control unit 260 is realized when the processor 29 reads a dedicated application 251 stored in the memory unit 250 and executes instructions contained in the program. The control unit 260 comprehensively controls the operation of the entire terminal device 200. By operating according to the dedicated application 251, the control unit 260 performs the functions of an acquisition unit 261, a first verification unit 262, a second verification unit 263, and a presentation control unit 264.

[0045] The acquisition unit 261 communicates with the security IC 120 of the physical medium 100 via the short-range communication unit 220 and performs a process to acquire verification data, including unique identification information, the issuer's digital signature, and the content hash value, stored in its storage unit 122.

[0046] The first verification unit 262 uses the data acquired by the acquisition unit 261 to verify the physical authenticity of the physical medium 100 itself, specifically whether it was manufactured by a legitimate manufacturer. As a concrete example, challenge-response authentication can be used. In this case, the first verification unit 262 first generates an unpredictable random string (challenge) each time verification is performed and sends it to the physical medium 100 via the short-range communication unit 220 to request a signature. The security IC 120, upon receiving the request, generates signature data using its own private key 1222, which is securely stored internally, and sends it back to the terminal device 200 along with a certificate containing its own public key. The first verification unit 262 verifies this response using the issuer's public key (corresponding to a root certificate) which is pre-installed in the storage unit 250 as part of a dedicated application or together with the dedicated application. If this series of verifications is successful, it can be determined that the physical medium 100 being interacted with possesses a legitimate private key 1222, that is, that it was legitimately manufactured by a trusted issuer.

[0047] The second verification unit 263, having confirmed the success of the authenticity verification of the physical medium by the first verification unit 262, verifies the integrity of the digital content recorded on the physical medium 100, that is, whether the data has not been tampered with since its manufacture.

[0048] As a more robust verification flow, the second verification unit 263 can verify the validity of the content's hash value in stages. First, the acquisition unit 261 acquires from the security IC not only the content hash value but also a series of data written by the playback device 300 (the playback device's unique identifier, a monotonic counter value indicating the number of times the hash value has been updated, and the playback device's digital signature and certificate for this data).

[0049] Next, the second verification unit 263 verifies whether the digital signature of the playback device is legitimate for the data obtained by combining the "content hash value + monotonic counter value + playback device unique identifier" from the acquired data set. This verification confirms that the hash value recorded on the security IC is the most recent one written by a legitimate playback device, thereby preventing unauthorized write-backs (replay attacks).

[0050] Only after this intermediate verification is successful does the second verification unit 263 proceed to the final stage of verification. Specifically, it first queries the management server 400 using the unique identification information of the acquired physical medium 100 as a key, and obtains the authentic hash value (correct data from the factory) returned as a response. Next, it compares the content hash value of the physical medium whose authenticity has been confirmed with the authentic hash value obtained from the management server 400. If the comparison shows that the two are a perfect match, it is determined that the digital content recorded in the content recording unit 110 is in an authentic state and has not been altered in any way since its manufacture. On the other hand, if either verification fails, it is determined that the content may have been tampered with in some way.

[0051] The display control unit 264 generates a final verification result based on both the physical authenticity verification result from the first verification unit 262 and the content integrity verification result from the second verification unit 263, and displays it on the display of the output device 240. For example, only if both verifications are successful, a verification result screen (see Figure 8) including a message or mark such as "Authentication successful" is displayed.

[0052] <4. Configuration of the Management Server> Figure 4 is a block diagram showing a functional configuration example of the management server 400. The management server 400 is an information processing device for the issuer to use System 1 to manage and operate the authenticity certification service for physical media. The management server 400 is typically implemented by one or more computers connected to a wide area network 500. As shown in Figure 4, the management server 400 comprises at least a communication unit 410, a storage unit 450, and a control unit 490.

[0053] The communication unit 410 performs processing to enable the management server 400 to communicate with other devices such as terminal devices 200 via the wide-area network 500. The communication unit 410 processes signals generated by the control unit 490 (e.g., response messages including the true hash value, ownership transfer completion notifications, etc.) and sends them to the terminal device 200. The communication unit 410 also processes signals received from the terminal device 200 (e.g., requests for inquiries about the true hash value, ownership transfer requests, etc.) and outputs them to the control unit 490.

[0054] The storage unit 450 is implemented by memory 45, storage 46, etc., and stores programs (operating system, database management system, web server program, etc.) or data necessary for the management server 400 to operate. In particular, the storage unit 450 stores the database (DB) 451, which is the core of the reliability of this system 1. The DB 451 includes at least a physical media table 451 that manages the true hash value of each physical medium 100 at the time of factory shipment, linked to unique identification information, and an owner table that manages the ownership information of each physical medium. The server program may be pre-stored in the storage unit 450, or it may be configured to be loaded from an external source as needed.

[0055] The control unit 490 is realized when the processor 49 executes a server program stored in the memory unit 450, and comprehensively controls the operation of the entire management server 400. The control unit 490 operates according to the program, and in particular functions as a request response unit 491.

[0056] The request response unit 491 interprets the request received from the terminal device 200 and performs a series of processes to execute the corresponding processing and return a response. Specifically, when it receives a request to query a true hash value from the terminal device 200, the request response unit 491 searches the physical media table 451 of DB 451 using the unique identifier information included in the request as a key. It then extracts the true hash value from the corresponding record and sends it back to the terminal device 200 in a response message. In addition, when it receives a request for transfer of ownership, it verifies the validity of the information included in the request (unique identifier information of the physical media, current owner information, new owner information), updates the record in the owner table, and executes the transfer of ownership process.

[0057] <5. Data Structure> The main data structures used in this embodiment will be described below.

[0058] Figure 5 shows an example of the data structure of the authenticity verification table 1221 stored in the storage unit 122 of the security IC 120 of the physical medium 100. This table stores information necessary to verify the authenticity of the physical medium and the integrity of its content. Specifically, one table corresponds to each physical medium, and it can be conceptualized as a data structure having multiple items associated with a "unique identification information" as the primary key. The item "unique identification information" stores identification information to uniquely identify the physical medium. Using this unique identification information as a key, information such as "issuer signature" and "content hash value" is linked. The item "issuer signature" stores a digital signature generated by the issuer using their private key 1222 on the unique identification information, thereby proving that the medium was manufactured by a legitimate issuer. The item "content hash value" stores the hash value calculated at the time of manufacture from the entire digital content recorded in the content recording unit 110.

[0059] Figure 6 shows an example of the data structure of the physical media table 451 stored in the DB 451 of the management server 400. The physical media table 451 stores the legitimate hash value of each physical media at the time of factory shipment. Specifically, it can be conceptualized as a management table having, for example, a column for "Authentic Hash Value" associated with "Unique Identification Information" as the primary key. The item "Unique Identification Information" is identification information for identifying each physical media, and each record is uniquely determined using this information as the key. The item "Authentic Hash Value" is linked to this unique identification information and stores the hash value calculated from the legitimate digital content at the time the physical media was manufactured at the factory, and is used as the correct data when comparing hash values ​​in terminal devices. In addition, the DB 451 of the management server 400 may also associate the current owner information of each physical media with "Unique Identification Information" as the key.

[0060] When managing ownership information, DB451 of the management server 400 stores the owner table. The owner table is a data structure that stores the current owner information of each physical medium, associated with "unique identification information" as the key. Specifically, the owner table includes at least an item for "unique identification information" to uniquely identify the physical medium, an item for "owner identification information" that stores information indicating the current owner of the physical medium (for example, the owner's account ID), and an item for "transfer date and time" that stores a timestamp indicating the date and time when ownership was transferred to the current owner. The management server 400 updates the records in this owner table in response to an ownership transfer request.

[0061] <6. Operation> Figure 7 is a flowchart showing an example of the authenticity verification process according to this embodiment. This process is triggered when the user launches a dedicated application on the terminal device 200 and brings it close to the physical medium 100.

[0062] First, in step S1, the acquisition unit 261 of the terminal device 200 establishes short-range wireless communication with the security IC 120 of the physical medium 100 and acquires a series of data necessary for authenticity verification. Specifically, it reads verification data including unique identification information to uniquely identify the physical medium 100, an issuer signature to prove the legitimacy of the issuer, and a content hash value to verify the integrity of the digital content.

[0063] Next, in step S2, the first verification unit 262 of the terminal device 200 verifies whether the physical medium 100 itself was manufactured by a legitimate manufacturer and verifies its physical authenticity. This verification is performed, for example, by verifying the issuer signature obtained in step S1 using the issuer's public key, which is pre-stored in the storage unit 250 of the terminal device 200. The ability to correctly verify the signature with this public key cryptographically proves that the signature was generated with its corresponding private key (held only by the issuer). If this verification fails, it is determined that the physical medium 100 is a counterfeit and the result of the verification failure is displayed.

[0064] If the authenticity verification of the physical medium in step S2 is successful, then in step S3, the second verification unit 263 verifies the integrity of the digital content recorded on the physical medium 100 to determine if it has been tampered with since its manufacture. Specifically, it first queries the management server 400 using the acquired unique identification information as a key and obtains the authentic hash value (correct data at the time of factory shipment) returned as a response. Next, it compares the content hash value obtained from the physical medium 100 with the authentic hash value obtained from the management server 400. If this comparison does not match, it is determined that the content has been tampered with.

[0065] More specifically, a dedicated application 251 running on the terminal device 200 generates a query request containing the acquired unique identification information and sends it to the management server 400 via the wide-area communication unit 210. The management server 400 searches the database using the unique identification information contained in the received query request as a key, obtains the corresponding authentic hash value, and returns it to the terminal device 200. The dedicated application 251 receives a response from the management server 400 containing the authentic hash value and extracts the authentic hash value from the response. Then, it performs a process of comparing the extracted authentic hash value with the content hash value obtained from the physical medium 100.

[0066] If the content verification in step S3 is also successful, in step S4, the presentation control unit 264 displays the final verification result on the screen of the terminal device 200, indicating that both physical authenticity and content have been confirmed. This allows the user to be confident that the physical medium in question is authentic. On the other hand, if the verification in either step S2 or S3 fails, the presentation control unit 264 displays a result indicating that the verification failed (for example, a message such as "Authentication failed" or a warning icon).

[0067] <7. Screen example> This disclosure describes an example of a screen displayed on the display 241 of the terminal device 200.

[0068] Figure 8 shows an example of a verification results screen displayed on the display 241 of the terminal device 200. This screen is generated by the display control unit 264 of the terminal device 200 in order to present the final results of the authenticity verification process to the user in an easy-to-understand manner.

[0069] The item information display area 2411 at the top of the screen displays an image representing the digital content of the physical media 100 being verified, the content name (e.g., "Limited Edition Digital Cassette #001"), and unique identification information (UNIQUE ID).

[0070] The results display area 2412 in the center of the screen shows the verification result as text (e.g., "Authentication successful. This item is genuine.") and an icon indicating successful verification (e.g., a checkmark). By looking at this screen, users can intuitively understand that the physical medium in question, as well as the content recorded on it, is authentic.

[0071] Furthermore, a button 2413 for checking the ownership transfer history, as explained in the modified example, may be located at the bottom of the screen. When the user operates this button, the display control unit 264 switches the display to the ownership history screen as shown in Figure 10.

[0072] <8.Summary> As explained above, according to this first embodiment, users can simultaneously verify two different types of authenticity—the authenticity of the physical medium itself and the integrity of the recorded digital content—simply by holding a general-purpose terminal device such as a smartphone over the physical medium. This makes it possible to turn digital data, which was previously easy to copy, into a physical product that can be sold in stores and resold. In particular, it is expected to be used as a collectible item such as trading cards or souvenirs, and since buyers can verify authenticity on the spot, it effectively suppresses the distribution of counterfeit and pirated goods and contributes to the creation of a safe resale market where everyone can trade with peace of mind.

[0073] Furthermore, the verification process of holding a physical medium over a terminal can itself become part of an entertainment experience that enhances the joy of ownership. The inseparable link between the physical medium and the mechanism for verifying its authenticity guarantees its uniqueness as a "thing," protects its asset value as a collectible item, and is expected to further enhance its value through the network effects of the widespread adoption of this system.

[0074] (modified version) The configuration described in the above embodiments can be modified in various ways without departing from the spirit of this disclosure. Specific modifications for extending the system's functionality and increasing its added value are described below.

[0075] (Modification 1: Dynamic updating of hash values ​​through collaboration with a playback device) In the first embodiment, the integrity of the content was verified by comparing it with an immutable hash value recorded at the time of manufacture (factory hash value). While this method is simple and powerful, it has the drawback that if there is a legitimate update to the content (e.g., a software bug fix patch, or the distribution of additional content), the hash value will not match and verification will fail.

[0076] In this modified version, to solve this problem and further enhance security, a playback device 300 is introduced into the system, as shown by the dashed line in Figure 1. This playback device 300 is not merely a content viewer, but a dedicated device that is physically connected to the physical medium 100 and performs three important functions: content playback, hash value calculation, and writing to the security IC 120. In particular, this configuration is essential for realizing dynamic updates of the hash value in conjunction with legitimate content updates, and it plays the role of a reliable writing terminal in this authenticity verification system.

[0077] To that end, the playback device 300 is equipped with the following functional parts. Hash calculation unit 301: When the physical medium 100 is connected, it reads all the data of the digital content from the content recording unit 110 and calculates the latest hash value at that time. The write control unit 302: Adds a digital signature to the calculated latest hash value to prove that it was calculated by a trusted and legitimate device, and securely writes it to a designated area of ​​the security IC 120.

[0078] The write control unit 302 writes the latest calculated hash value to the security IC 120. At this time, it first increments (+1) the monotonic counter of the security IC and obtains the updated counter value. Then, it generates a digital signature for the data combining the latest hash value, the unique identifier of the playback device itself, and the updated monotonic counter value, using the private key that the playback device 300 securely holds in its own memory. Then, it records this playback device signature and the playback device certificate (including the public key) that proves its legitimacy, along with the latest hash value, in a predetermined area of ​​the security IC 120.

[0079] In this configuration, the terminal device 200 reads the latest hash value along with the regeneration device signature and regeneration device certificate from the physical medium 100. It then not only compares the hash values ​​but also verifies the reliability of the hash values ​​themselves. Specifically, the first verification unit 262 of the terminal device 200 (1) verifies the validity of the regeneration device certificate using the issuer's public key (corresponding to the root certificate) and confirms that it is a legitimate regeneration device. Next, (2) it verifies the regeneration device signature using the public key contained in the valid regeneration device certificate.

[0080] Only after these two stages of verification are successful does the terminal device 200 consider its hash value to be correctly calculated and recorded by a legitimate playback device, and the second verification unit 263 performs content integrity verification (comparison with query to management server). This makes it possible to build a more robust and flexible authenticity verification system that can handle legitimate content updates while preventing rewriting with fraudulent hash values.

[0081] (Variation 2: Ownership Transfer Management) In this modified version, in order to elevate the physical medium 100 from a mere content recording medium to a secure "tradable asset," a mechanism is introduced to manage and securely transfer digital ownership, similar to digital assets handled by blockchain technology. This mechanism dramatically improves the reliability and transparency of transactions, especially in the secondary market.

[0082] The core of the security in this modified version is to make "the physical media 100 being physically connected to a legitimately registered playback device 300" a necessary physical condition for performing the ownership transfer operation. Users must link their playback device 300 to their account on the management server 400 in advance. This ensures robust security that is resistant to impersonation and theft, as ownership will not be transferred simply by a third party scanning the physical media 100 using a terminal device 200 at a store or other location.

[0083] The sequence diagram in Figure 9 shows the specific processing flow of ownership transfer in this modified example.

[0084] First, as a prerequisite for the transfer, current owner A physically connects the physical media 100 to be transferred to the playback device 300A that is registered to his account (step S11). In this state, new owner B starts the transfer operation from the dedicated application on his terminal device 200B (step S12). Terminal device 200B sends a "transfer start request" to the management server 400 (step S13). In response to this request, the management server 400 generates an unpredictable "temporary key" and enters an update waiting state (step S14), and notifies terminal device 200B of the temporary key (step S15).

[0085] Upon receiving the temporary key, terminal device 200B scans the physical medium 100 (step S16), transmits the received temporary key via NFC to the security IC 120, and then to the playback device 300A connected to the physical medium 100, requesting playback device information (step S17). Upon receiving this request, playback device 300A generates a digital signature with its private key on the data containing the temporary key. It then responds to terminal device 200B with playback device information including this signature (step S18). This signature can only be generated when a legitimate playback device is connected to the physical medium 100, proving physical ownership and preventing terminal device 200B from falsifying its communication with the server.

[0086] Terminal device 200B sends a final "transfer request" containing the signed data received from playback device 300A to management server 400 (step S19). Management server 400 verifies the received signature and, after confirming its legitimacy, updates the database record in the owner table to change the owner of the physical medium from the current owner A to the new owner B (step S20). Management server 400 notifies terminal device 200B that the digital transfer of ownership is complete (step S21), and terminal device 200B then forwards the completion notification to playback device 300A (step S22). Finally, playback device 300A, having received the completion notification from the server, adds the identification information of the new owner B and a timestamp indicating the date and time the transfer was performed to the ownership transfer history area of ​​the security IC 120 of the physical medium 100 (step S23). This completes the transfer of ownership in a secure and consistent manner, both in the digital record on the management server and in the tamper-proof physical record on the physical medium.

[0087] The user can check the ownership history of the physical medium on the ownership history screen shown in Figure 10. This screen is displayed on the display 241 of the terminal device 200 in relation to the ownership management function described in Modification Example 2.

[0088] Figure 10 shows an example of the ownership history screen. In the owner list display area 2414 in the center of the screen, the identification information of past owners (e.g., "Owner A", "Owner B") and the date and time of ownership transfer (e.g., "2025 / 09 / 01 15:00") are displayed in chronological order, based on the ownership transfer history read from the security IC 120. An icon to identify the account may be displayed next to each owner's information. Through this screen, users can accurately understand the history of the physical medium, including who has owned it to the present. This means that the history itself, such as having been owned by a famous creator or collector, becomes added value as a collection item and is an important factor in making decisions when trading in the secondary market.

[0089] (Variation 3: Verification log management via cloud integration) In this modified version, the cooperation between the terminal device 200 and the management server 400 is further strengthened, and the security and value of the system are further enhanced by recording and utilizing authenticity verification logs. Each time the terminal device 200 performs authenticity verification, it sends the result (success / failure), the date and time the verification was performed, and approximate location information (obtained with the user's prior permission) to the management server 400 and records it as a verification log.

[0090] This feature offers significant value to both the owners and issuers of physical media. For owners, a history of "when and where" their collection was proven authentic is continuously recorded on the management server, much like a digital certificate. This allows them to objectively demonstrate the authenticity of their owned items. For issuers, this verification log is a powerful tool against counterfeiting. For example, if verification logs for physical media with the same unique identifier are recorded in physically impossible locations (e.g., Tokyo and New York) within a short period of time, the management server 400 can determine this to be a clone (illegible copy) and add the unique identifier to a list of counterfeits. As a result, verification of physical media (both genuine and counterfeit) with that unique identifier will fail from then on, quickly preventing further damage.

[0091] Users can access a verification history screen (not shown) via a dedicated application. This screen displays a list of past verification logs (verification date, time, location, and result) for their owned items, retrieved from the management server 400, allowing owners to check the health of their collections at any time.

[0092] (Variation 4: Unlocking exclusive content) This modified version elevates the physical medium 100 not merely as a recording medium for digital content, but as a unique item that reflects the owner's experiences and actions, thereby enhancing its value as a collectible. This is achieved by adding special information (hereinafter referred to as "achievement flag") to a secure, tamper-proof storage area within the security IC 120, only under specific conditions.

[0093] The core of this modification lies in configuring a specific memory area of ​​the security IC120 so that it cannot be written to without special write privileges (equivalent to a private key or password). The mere presence of the achievement flag in this area serves as proof that it was "written by someone with legitimate privileges." This eliminates the need for a complex signature verification process on the playback device side, achieving high reliability with a simple configuration. Several specific implementation methods can be considered for setting these "specific conditions."

[0094] The first approach involves using a dedicated writing device managed by a trusted third party, such as an event organizer or content publisher. For example, a dedicated writing device could be installed at the entrance gate of a specific event venue. This writing device holds a special private key (writing key) that only the event organizer possesses. When a visitor holds their physical medium 100 over this device, the device first uses its private key to authenticate writing to a specific area of ​​the security IC 120. If authentication is successful, the device writes a simple achievement flag (e.g., setting a specific bit indicating "Attended XX event in 2025") to that area. Since the user themselves does not possess this private key, it becomes extremely difficult to forge this achievement flag later.

[0095] The second aspect is a method that requires the collection of specific physical media. For example, suppose a certain collection series consists of five different types of physical media. Each physical media contains fragments of information that, on their own, do not make sense, and are recorded in separate parts. When a user collects all five types and connects them to the playback device 300, the playback device 300 reads all the key information, combines them, and restores a single complete secret key (write key). Then, using this restored secret key, it writes an achievement flag indicating "completion achieved" to a specific area of ​​the security IC 120 on each physical media. In this case as well, since the secret key cannot be restored unless all the physical media are collected, the user cannot illegally write the achievement flag.

[0096] When playing content, the playback device 300 reads whether or not an achievement flag exists in the security IC 120. As discussed in the transcript, the playback device does not verify the signature of the flag itself each time, but only checks whether or not the flag exists in a specific area where writing is restricted. Then, only if a specific flag exists, the playback device changes the content to be played according to a logic pre-built into the playback device (e.g., unlocking limited content such as bonus footage, hidden characters, or special messages) to achieve the achievement.

[0097] This means that even if products appear identical in appearance, differences in the "experience" and "track record" of individual physical media arise depending on the owner's actions and collection circumstances, and their provenance is proven in an irretrievable way. This is valued as unique added value in the secondary market for physical media, significantly enhancing their appeal as collectibles. When users verify authenticity with terminal device 200, they can also simultaneously check for the presence or absence of these track record flags.

[0098] (Modification 5: Real-time verification using only the physical medium) In the first embodiment and its modifications, a configuration was described in which the hash value of the content is pre-recorded in the security IC or calculated and updated by the playback device 300. However, there may also be a need to prove that the content on the physical medium 100 has not been tampered with on the spot, even in an environment without the playback device 300.

[0099] In this modified version, to meet this requirement, the physical medium 100 is further configured to include an IC dedicated to hash calculation and a power supply to operate it. Examples of the hash calculation IC include a general-purpose microcontroller (MCU) or a cryptographic coprocessor that provides a higher level of security. This allows the physical medium 100 to calculate hash values ​​using its own computing power without relying on an external playback device.

[0100] Furthermore, the following power supplies, or a combination thereof, can be used for the physical medium 100 to operate independently. Built-in power supply: A form in which a coin cell battery or a small rechargeable battery is built into the physical medium. This allows for long-term operation in a completely independent state. External power supply: A configuration in which the physical medium 100 receives power from the playback device 300 via a connection terminal when it is connected to the playback device 300. NFC power supply: A method of obtaining the power necessary for operation via an antenna from the electromagnetic field generated when the terminal device 200 performs NFC communication (energy harvesting). In this case, the physical medium can operate without a battery.

[0101] With this configuration, the terminal device 200 can simply send instructions to the physical medium 100 via NFC communication, allowing the physical medium 100 to read digital content from the content recording unit 110, perform hash calculations in real time, and receive the result as a response.

[0102] According to this modified version, real-time authenticity verification can be completed using only the physical media, even in environments without playback equipment, thus improving the real-time nature of the verification. This means that, for example, when buying or selling used goods in a store, prospective buyers can instantly verify the integrity of the data at that moment simply by holding their smartphone over the media, further enhancing the security of the transaction.

[0103] <Basic Computer Hardware Configuration> Figure 11 is a block diagram showing the basic hardware configuration of computer 90. Computer 90 includes at least a processor 901, main memory 902, auxiliary storage 903, and a communication interface IF991. These are electrically connected to each other by a communication bus.

[0104] The processor 901 is hardware for executing the instruction set written in a program. The processor 901 consists of an arithmetic unit, registers, peripheral circuits, etc.

[0105] Main memory 902 is used to temporarily store programs and data processed by programs, etc. For example, it is a volatile memory such as DRAM (Dynamic Random Access Memory).

[0106] Auxiliary storage device 903 refers to a storage device for saving data and programs. Examples include flash memory, HDD (Hard Disc Drive), magneto-optical disk, CD-ROM, DVD-ROM, and semiconductor memory.

[0107] The IF991 communication interface is an interface for inputting and outputting signals for communication with other computers via a network using wired or wireless communication standards. A network consists of various mobile communication systems, such as the Internet, LANs, and wireless base stations. For example, a network includes 3G, 4G, and 5G mobile communication systems, LTE (Long Term Evolution), and wireless networks that can connect to the Internet via designated access points (e.g., Wi-Fi®). When connecting wirelessly, communication protocols include, for example, Z-Wave®, ZigBee®, and Bluetooth®. When connecting via a wired connection, the network also includes connections made directly via USB (Universal Serial Bus) cables, etc.

[0108] Furthermore, by distributing all or part of each hardware configuration across multiple computers 90 and connecting them to each other via a network, a computer 90 can be virtually realized. Thus, the concept of computer 90 includes not only a computer 90 housed in a single enclosure or case, but also a virtualized computer system.

[0109] <Basic Functional Configuration of Computer 90> The functional configuration of the computer realized by the basic hardware configuration of computer 90 (Figure 11) is described below. The computer comprises at least one functional unit: a control unit, a memory unit, and a communication unit.

[0110] Furthermore, the functional units of computer 90 can also be realized by distributing all or part of each functional unit across multiple computers 90 interconnected via a network. The concept of computer 90 includes not only a single computer 90 but also a virtualized computer system.

[0111] The control unit is realized when the processor 901 reads various programs stored in the auxiliary storage device 903, loads them into the main memory device 902, and executes processing according to those programs. The control unit can realize various functional units that perform information processing depending on the type of program. In this way, the computer is realized as an information processing device that performs information processing.

[0112] The memory unit is implemented by the main memory 902 and the auxiliary memory 903. The memory unit stores data, various programs, and various databases. The processor 901 can also reserve memory areas corresponding to the memory unit in the main memory 902 or the auxiliary memory 903 according to the program. The control unit can also cause the processor 901 to perform operations such as adding, updating, and deleting data stored in the memory unit according to the various programs.

[0113] A database, specifically a relational database, is used to manage and link together tabular data sets called masters, which are structurally defined by rows and columns. In a database, tables are called tables, masters are called masters, the columns of tables are called columns, and the rows of tables are called records. In a relational database, relationships can be established and linked between tables and masters. Typically, each table and master has a primary key column to uniquely identify records, but setting a primary key column is not mandatory. The control unit can instruct the processor 901 to add, delete, or update records in specific tables and masters stored in the memory unit, according to various programs. Furthermore, by storing data, various programs, and various databases in the memory unit, the information processing device and information processing system related to this disclosure can be considered to have been manufactured.

[0114] Furthermore, the databases and masters in this disclosure may include any data structures (lists, dictionaries, associative arrays, objects, etc.) in which information is structurally defined. Data structures also include data that can be considered as data structures by combining data with functions, classes, methods, etc., written in any programming language.

[0115] The communication unit is implemented by the communication IF991. The communication unit provides the functionality to communicate with other computers 90 via the network. The communication unit can receive information transmitted from other computers 90 and input it to the control unit. The control unit can cause the processor 901 to perform information processing on the received information according to various programs. The communication unit can also transmit information output from the control unit to other computers 90.

[0116] Furthermore, each of the above-mentioned configurations, functions, processing units, processing means, etc., may be implemented in hardware, either partially or entirely, by designing them as integrated circuits, for example. The present invention can also be implemented by software program code that realizes the functions of the embodiment. In this case, a storage medium on which the program code is recorded is provided to a computer, and the processor of that computer reads the program code stored in the storage medium. In this case, the program code read from the storage medium itself realizes the functions of the embodiment described above, and the program code itself and the storage medium on which it is stored constitute the present invention. Examples of storage media used to supply such program code include flexible disks, CD-ROMs, DVD-ROMs, hard disks, SSDs, optical disks, magneto-optical disks, CD-Rs, magnetic tapes, non-volatile memory cards, ROMs, and the like.

[0117] Furthermore, the program code that implements the functions described in this embodiment can be implemented in a wide range of programming or scripting languages, such as assembler, C / C++, Perl, Shell, PHP, and Java (registered trademark).

[0118] Furthermore, the program code for the software that implements the functions of the embodiment may be distributed via a network and stored in a storage means such as a computer's hard disk or memory, or in a storage medium such as a CD-RW or CD-R, and the computer's processor may read and execute the program code stored in the storage means or storage medium.

[0119] The functions realized by the components described herein may be implemented in a circuit or processing circuitry, including general-purpose processors, application-specific processors, integrated circuits, ASICs (Application Specific Integrated Circuits), CPUs (a Central Processing Unit), conventional circuits, and / or combinations thereof, programmed to realize the functions described herein. A processor is considered to be a circuit or processing circuitry, including transistors and other circuits. A processor may be a programmed processor that executes a program stored in memory. In this specification, circuitry, unit, and means are hardware programmed to perform or execute the functions described herein. Such hardware may be any hardware disclosed herein, or any hardware known to be programmed to perform or execute the functions described herein. If the hardware is a processor that is considered to be a type of circuitry, then the circuitry, means, or unit is a combination of hardware and software used to constitute the hardware and / or processor.

[0120] While several embodiments of this disclosure have been described above, these embodiments can be implemented in a variety of other forms, and various omissions, substitutions, and modifications are permitted without departing from the spirit of the invention. These embodiments and their variations are included in the scope and spirit of the invention, as well as in the claims and their equivalents.

[0121] (Note) The details described in each of the above embodiments are noted below.

[0122] (Note 1) A program for operating a computer comprising a processor and memory, wherein the program is configured to run on the processor. The process involves communicating with a security IC of a physical medium, which includes a content recording unit on which digital content is recorded, and a security IC that stores the hash value of the digital content and unique identification information, in order to obtain the unique identification information and the hash value. The steps include verifying the authenticity of the physical medium itself using the acquired unique identification information, The process involves verifying the authenticity of digital content by comparing the obtained hash value with a pre-registered authentic hash value associated with unique identification information. A program that executes the command.

[0123] (Note 2) The processor also has, The steps include obtaining a true hash value by querying the management server using the acquired unique identification information, The program described in (Note 1) that executes the above.

[0124] (Note 3) The program described in (Appendix 1) verifies the issuer's digital signature, which is further stored in the security IC, using the issuer's public key that it has previously held, in the step of verifying the authenticity of the physical medium itself.

[0125] (Note 4) The processor also has, A step to verify the digital signature of the playback device, which is recorded along with a new hash value from the digital content recorded on the physical medium. A program described in any of (Appendix 1) to (Appendix 3) that executes the above.

[0126] (Note 5) The processor also has, A step of requesting a physical medium to calculate the hash value of digital content in real time and receiving the result as a response, A program described in any of (Appendix 1) to (Appendix 3) that executes the above.

[0127] (Note 6) The processor also has, A step of instructing the transfer of ownership by updating both the owner information on the management server and the owner information recorded on the security IC via a playback device connected to the physical medium, The program described in (Appendix 2) that executes the above.

[0128] (Note 7) The steps include: instructing the security IC to append specific information to its memory area using predetermined write permissions; A step of instructing a playback device connected to a physical medium to change the playback mode of digital content, provided that specific information has been added, A program described in any of (Appendix 1) to (Appendix 3) that executes the above.

[0129] (Note 8) A terminal device comprising a processor and memory, which executes any of the programs described in (Appendix 1) to (Appendix 7).

[0130] (Note 9) A method performed by a computer having a processor and memory, A method for performing all steps in the program described in any of (Appendix 1) to (Appendix 7).

[0131] (Note 10) A system comprising the terminal device described in (Appendix 8) and a physical medium for proving the authenticity of digital content, Physical media are A content recording unit that records digital content, A security IC capable of communicating with the aforementioned terminal device, Equipped with, A security IC is a system that stores unique identification information used by the terminal device to verify the authenticity of the physical medium itself, and a hash value used by the terminal device to verify the authenticity of the digital content by comparing it with a pre-registered authentic hash value associated with the unique identification information.

[0132] (Note 11) A physical medium for proving the authenticity of digital content, used for verification performed by a program according to any one of claims 1 to 7, A content recording unit that records digital content, A security IC capable of communicating with the aforementioned external computer, Equipped with, The security IC is a physical medium that stores unique identification information used by the computer to verify the authenticity of the physical medium itself, and a hash value used by the computer to verify the authenticity of the digital content by comparing it with a pre-registered authentic hash value associated with the unique identification information. [Explanation of Symbols]

[0133] 1… Authenticity verification system 100…Physical medium 110...Content Recording Unit 120…Security IC 121... Communications Department 122...Storage section 125... Control Unit 200, 200B... Terminal devices 300, 300А…Regeneration equipment 400... Management Server 500… Wide-area network

Claims

1. A program for operating a computer comprising a processor and memory, wherein the program is configured to operate the processor, A physical medium comprising a content recording unit on which digital content is recorded and a security IC that stores unique identification information, communicates with the security IC of the physical medium and obtains the unique identification information. The steps include: requesting the physical medium or a playback device connected to the physical medium via the security IC to calculate the hash value of the digital content, and receiving the calculated hash value as a response; The steps include verifying the authenticity of the digital content by comparing the received hash value with a genuine hash value pre-registered in association with the unique identification information, A program that executes the command.

2. The aforementioned processor further includes, The step of obtaining the true hash value by querying the management server using the unique identification information obtained above, The program according to claim 1, which causes to execute.

3. The processor further comprises: The authenticity of the physical medium itself is verified by verifying the issuer's digital signature, which is further stored in the security IC, using the issuer's public key, which is held in advance. The program according to claim 1, which causes to execute.

4. The aforementioned processor further includes, A step of verifying the digital signature of the playback device, which is recorded along with a new hash value from the digital content recorded on the physical medium, The program according to claim 1, which causes to execute.

5. The aforementioned processor further includes, A step of instructing the transfer of ownership by updating both the owner information on the management server and the owner information recorded on the security IC via a playback device connected to the physical medium, The program according to claim 2, which causes the execution of the program.

6. The steps include: instructing the security IC to append specific information to its memory area using predetermined write permissions; The steps include instructing a playback device connected to the physical medium to change the playback mode of the digital content, provided that the aforementioned specific information has been added, The program according to claim 1, which causes to execute.

7. A terminal device comprising a processor and memory, which executes the program described in any one of claims 1 to 6.

8. A method performed by a computer having a processor and memory, A method for performing all steps in a program according to any one of claims 1 to 6.

9. A system comprising the terminal device described in claim 7 and a physical medium for proving the authenticity of digital content, The aforementioned physical medium is A content recording unit for recording the aforementioned digital content, A security IC capable of communicating with the aforementioned terminal device, Equipped with, The security IC stores the unique identification information of the physical medium, The system further includes a configuration in which, in response to a calculation request from the terminal device, the physical medium or a playback device connected to the physical medium calculates a hash value used to verify the authenticity of the digital content by comparing it with a pre-registered authentic hash value associated with the unique identification information, and transmits the calculated hash value as a response to the terminal device via the security IC.

10. A physical medium for proving the authenticity of digital content, used for verification performed by a program according to any one of claims 1 to 6, A content recording unit for recording the aforementioned digital content, A security IC capable of communicating with the aforementioned external computer, Equipped with, The security IC stores the unique identification information of the physical medium, The physical medium further comprises a configuration that, in response to a calculation request from the computer, causes the physical medium or a playback device connected to the physical medium to calculate a hash value used to verify the authenticity of the digital content by comparing it with a genuine hash value pre-registered in association with the unique identification information, and transmits the calculated hash value as a response to the computer via the security IC.

Citation Information

Patent Citations

  • Data processing method and apparatus

    JP1985074035A

  • Trading card and trading card set

    JP2016194848A

  • Children's toy with wireless tag / transponder

    US20020193047A1

  • Method for cryptographically linking a physical object that has an NFC tag associated therewith to a digital version of the physical object using an NFT

    US20230246836A1