Information creation method, image file, information creation device, and program
Patent Information
- Application Number
- JP2024549871
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Priority Date
- 2023-08-21
- Filing Date
- 2023-08-21
- Publication Date
- 2025-06-12
AI Technical Summary
Existing image verification systems lack robust security measures to prevent tampering with metadata associated with image files, allowing unauthorized modification or deletion of critical information such as photographer details, imaging conditions, and location data.
An information creation method and device that encrypts related information, including timing and reliability data, and integrates it into the image file as metadata, ensuring that only authorized parties can modify or delete it by using hash functions and including non-permissible information to indicate unalterable data.
Enhances the security of image metadata by preventing unauthorized changes and ensuring the integrity of photographer information, imaging conditions, and location data, thereby maintaining the reliability and authenticity of the image data.
Smart Images

Figure 2024070328000001 
Figure 2024070328000002 
Figure 2024070328000003
Abstract
Description
Information creation method, image file, information creation device, and program
[0001] The technology disclosed herein relates to an information creation method, an image file, an information creation device, and a program.
[0002] Japanese Patent Laid-Open Publication No. 2006-345450 discloses an image verification system including an imaging device that performs tamper-proofing processing on an image file containing a captured image and its associated information, and an image verification device that verifies that the image file has not been tampered with. In the image verification system described in Japanese Patent Laid-Open Publication No. 2006-345450, the imaging device includes a user interface providing means that provides a user interface for allowing a user to select items of the associated information to be subject to tamper-proofing processing, an encryption means that encrypts the associated information selected via the user interface to create encrypted associated information, and an addition means that adds the encrypted associated information to the image file to create an added image file. In the image verification system described in Japanese Patent Laid-Open Publication No. 2006-345450, the image verification device includes a decryption means that decrypts the encrypted associated information to create decrypted associated information, and a comparison means that compares each item of the decrypted associated information with the corresponding item of the associated information.
[0003] Japanese Patent Laid-Open Publication No. 2009-225229 discloses an imaging device having an imaging element that captures an image of a subject and outputs image data, and a condition acquisition means that acquires the shooting conditions at the time of shooting. The imaging device described in Japanese Patent Laid-Open Publication No. 2009-225229 has a generation unit that generates first shooting information and second shooting information that is more detailed than the first shooting information based on the shooting conditions acquired by the condition acquisition means, a conversion unit that converts the second shooting information into encrypted third shooting information, and a means for generating an image file by adding the first shooting information and the third shooting information to the image data and recording the image file on a recording medium.
[0004] Japanese Patent Laid-Open Publication No. 2016-122917 discloses a signature generation device. The signature generation device described in Japanese Patent Laid-Open Publication No. 2016-122917 includes a data acquisition unit that acquires multiple pieces of data including first data that are related to each other, and a signature generation unit that generates first signature data for the first data and correlation information based on the first data, correlation information that indicates the correlation between the multiple pieces of data, and a signature key.
[0005] One embodiment of the technique of the present disclosure provides an information creation method, an image file, an information creation device, and a program that can improve the security of related information related to image data.
[0006] A first aspect of the technology of the present disclosure is an information creation method that includes an acquisition step of acquiring related information related to image data, an encryption step of generating first encrypted information by encrypting the related information, and an attachment step of directly or indirectly attaching incidental information to the image data, wherein the incidental information includes the first encrypted information and timing information regarding when the first encrypted information was generated or reliability information.
[0007] A second aspect of the technology of the present disclosure is an image file including incidental information of image data, wherein the incidental information includes first encrypted information obtained by encrypting associated information related to the image data, and timing information or reliability information regarding the time when the first encrypted information was generated.
[0008] A third aspect of the technology of the present disclosure is an information creation device that includes a processor, which acquires related information related to image data, generates first encrypted information by encrypting the related information, and directly or indirectly attaches additional information to the image data, and the additional information includes the first encrypted information and timing information regarding when the first encrypted information was generated, or reliability information.
[0009] A fourth aspect of the technology of the present disclosure is a program for causing a computer to execute processing, the processing including an acquisition step of acquiring related information related to image data, an encryption step of generating first encrypted information by encrypting the related information, and an attachment step of directly or indirectly attaching incidental information to the image data, wherein the incidental information includes the first encrypted information and timing information regarding when the first encrypted information was generated, or reliability information.
[0010] 1 is a conceptual diagram showing an example of a manner in which an imaging device is used. FIG. 2 is a conceptual diagram showing an example of the relationship between the imaging device and a receiving device. FIG. 3 is a block diagram showing an example of the hardware configuration and main functions of the electrical system of the imaging device. FIG. 4 is a block diagram showing an example of the hardware configuration and main functions of the electrical system of the receiving device. FIG. 5 is a conceptual diagram showing an example of the correlation between an image sensor, a ranging sensor, an electronic compass, an NVM, a GNSS device, a network, and an acquisition unit. FIG. 6 is a conceptual diagram showing an example of the correlation between the acquisition unit and an association unit. FIG. 7 is a conceptual diagram showing an example of the correlation between the NVM, the association unit, and an encryption unit. FIG. 8 is a conceptual diagram showing an example of processing content when metadata is directly attached to image data. FIG. 9 is a conceptual diagram showing an example of processing content when metadata is indirectly attached to image data. FIG. 10 is a conceptual diagram showing an example of the correlation between a transmission unit and a reception unit. FIG. 11 is a conceptual diagram showing an example of the correlation between a reception unit and a generation unit. FIG. 12 is a conceptual diagram showing an example of the correlation between a reception unit, a generation unit, and a comparison unit. FIG. 13 is a conceptual diagram showing an example of the correlation between a reception unit, a comparison unit, and an execution unit. FIG. 14 is a flowchart showing an example of the flow of an image file creation process according to the first embodiment. FIG. 15 is a flowchart showing an example of the flow of an image file reception process according to the first embodiment. FIG. 16 is a functional block diagram showing an example of the functions of a processor included in an imaging device according to a second embodiment. 1 is a conceptual diagram showing an example of the correlation between a UI device, a network, an acquisition unit, and an editing unit. FIG. 1 is a conceptual diagram showing an example of the correlation between the acquisition unit and the association unit. FIG. 2 is a conceptual diagram showing an example of the correlation between the NVM, the association unit, and the encryption unit. FIG. 3 is a flowchart showing an example of the flow of an image file creation process according to the second embodiment. FIG. 4 is a conceptual diagram showing a modified example of second association information. FIG. 5 is a conceptual diagram showing an example of the relationship between an imaging device, an editing device, and a receiving device. FIG. 6 is a conceptual diagram showing an example of the correlation between the association unit, encryption unit, transmission unit, attachment unit, network, and storage device. FIG. 7 is a conceptual diagram showing a modified example of the content of metadata included in an image file. FIG. 8 is a conceptual diagram showing an example of the processing content of a comparison unit. FIG. 9 is a conceptual diagram showing a modified example of first association information. FIG. 10 is a conceptual diagram showing an example of the processing content in which the encryption unit generates fourth association information.10 is a conceptual diagram showing an example in which an image file creation process is performed by an external device in response to a request from an imaging device, and the processing result is received by the imaging device.
[0011] Hereinafter, exemplary embodiments of an information creation method, an image file, an information creation device, and a program according to the techniques of the present disclosure will be described with reference to the accompanying drawings.
[0012] First Embodiment As shown in Fig. 1 as an example, an imaging device 10 captures an image of an imaging target area 12 designated as a subject. The imaging target area 12 is determined by an angle of view designated by a user of the imaging device 10 (hereinafter referred to as "user"). In the example shown in Fig. 1, the imaging target area 12 includes a plurality of people, a road, etc. The imaging device 10 is an example of an "information creation device" according to the technology of the present disclosure.
[0013] The imaging device 10 generates an image file 16 by capturing an image of the imaging target area 12 in accordance with instructions given by the photographer 14. Examples of file formats for the image file 16 include JPEG (Joint Photographic Experts Group) and TIFF (Tag Image File Format). The image file 16 includes image data 18 representing an image of the imaging target area 12, and metadata 20 about the image data 18. The metadata 20 is data accompanying the image data 18. An example of a format for the metadata 20 is EXIF (Exchangeable image file format).
[0014] In the first embodiment, the image file 16 is an example of an "image file" according to the technology of the present disclosure. The image data 18 is an example of "image data" according to the technology of the present disclosure. The metadata 20 is an example of "accompanying information" according to the technology of the present disclosure.
[0015] The imaging device 10 is a consumer digital camera. Examples of consumer digital cameras include interchangeable lens digital cameras and fixed lens digital cameras. A consumer digital camera is merely an example, and the imaging device 10 may also be an industrial digital camera. The technology of the present disclosure also applies when the imaging device 10 is an imaging device mounted on various electronic devices such as a drive recorder, a smart device, a wearable device, a cell observation device, an ophthalmic observation device, or a surgical microscope. The technology of the present disclosure also applies when the imaging device 10 is an imaging device mounted on various modalities such as an endoscope device, an ultrasound diagnostic device, an X-ray imaging device, a CT (Computed Tomography) device, or an MRI (Magnetic Resonance Imaging) device.
[0016] As an example, as shown in Figure 2, the image file 16 is sent from the photographer 14 to a receiving site 22. A receiving device 24 is installed at the receiving site 22. An example of the receiving device 24 is a personal computer. The receiving device 24 is used by a recipient 26 at the receiving site 22. The recipient 26 receives the image file 16 sent from the photographer 14 via the receiving device 24.
[0017] Here, a personal computer is given as an example of the receiving device 24, but this is merely an example, and the receiving device 24 may also be a smart device, a server, or the like.
[0018] The image file 16 is transferred via a network 28. Examples of the network 28 include a wide area network (WAN) or a local area network (LAN). The imaging device 10 and the receiving device 24 are communicatively connected to the network 28. The imaging device 10 may be connected to the network 28 wirelessly or wired, and the same applies to the receiving device 24. The imaging device 10 may also be connected to the network 28 via a communication device such as a smart device, and the same applies to the receiving device 24.
[0019] Here, an example is given in which the image file 16 is transferred via the network 28, but this is merely one example. For example, the image file 16 may be transferred via a portable storage medium such as a USB (Universal Serial Bus) memory, or the image capture device 10 may be directly connected to the receiving device 24, and the image file 16 may be transferred from the image capture device 10 to the receiving device 24.
[0020] Incidentally, when the recipient 26 at the receiving site 22 receives the image file 16 from the photographer 14, the recipient 26 may, for example, refer to the metadata 20 included in the received image file 16 and use the receiving device 24 or other device to perform some kind of processing (e.g., editing) on the image file 16 or manage the image file 16. Here, if, for example, all or part of the metadata 20 is altered by a person (hereinafter referred to as a "third party") not intended by the photographer 14, or if part of the metadata 20 is deleted by the third party, the recipient 26 may end up performing some kind of processing on the image file 16 or managing the image file 16 using metadata 20 that contains content not intended by the photographer 14. To avoid such a situation, it is important for the photographer 14 to provide the recipient 26 with highly reliable metadata 20.
[0021] In view of the above circumstances, in the first embodiment, the imaging device 10 performs an image file creation process (see, for example, FIGS. 3 and 13), and the receiving device 24 performs an image file reception process (see, for example, FIGS. 4 and 14). This will be explained in more detail below.
[0022] 3 , the imaging device 10 includes a computer 30, an image sensor 32, a UI (User Interface) device 34, an electronic compass 36, a distance measurement sensor 38, a GNSS (Global Navigation Satellite System) device 39, and a communication I / F (Interface) 40. The computer 30 is an example of a “computer” according to the technology of the present disclosure.
[0023] The computer 30 includes a processor 42, a non-volatile memory (NVM) 44, and a random access memory (RAM) 46. The processor 42, the NVM 44, and the RAM 46 are connected to a bus 48. The processor 42 is an example of a "processor" according to the technology of the present disclosure.
[0024] The processor 42 is a processing device including a DSP (Digital Signal Processor), a CPU (Central Processing Unit), and a GPU (Graphics Processing Unit), and the DSP and GPU operate under the control of the CPU and are responsible for executing image processing. Here, a processing device including a DSP, a CPU, and a GPU is given as an example of the processor 42, but this is merely an example, and the processor 42 may be one or more CPUs and one or more GPUs, one or more CPUs and DSPs with integrated GPU functionality, one or more CPUs and DSPs without integrated GPU functionality, or may be equipped with a TPU (Tensor Processing Unit).
[0025] The NVM 44 is a non-volatile storage device that stores various programs, various parameters, etc. An example of the NVM 44 is a flash memory (such as an EEPROM (Electrically Erasable and Programmable Read Only Memory)). The RAM 46 is a memory that temporarily stores information and is used as a work memory by the processor 42. An example of the RAM 46 is a dynamic random access memory (DRAM) or a static random access memory (SRAM).
[0026] The image sensor 32 is connected to the bus 48. An example of the image sensor 32 is a complementary metal oxide semiconductor (CMOS) image sensor. The image sensor 32 generates image data 18 by capturing an image of the imaging target area 12 (see FIG. 1 ) under the control of the processor 42.
[0027] Here, a CMOS image sensor is given as an example of the image sensor 32, but this is merely an example, and the image sensor 32 may be other types of image sensors such as a CCD (Charge Coupled Device) image sensor.
[0028] The UI device 34 is connected to the bus 48. The UI device 34 receives instructions from the photographer 14 (see FIGS. 1 and 2 ) and outputs a signal indicating the received instruction to the processor 42. The UI device 34 also presents various information to the photographer 14 under the control of the processor 42. The presentation of the various information is realized, for example, by displaying the various information on a display or outputting the various information as sound from a speaker.
[0029] The electronic compass 36 detects the direction of the image capture direction of the image capture device 10 (for example, the direction of the optical axis of the image capture lens attached to the image capture device 10) based on geomagnetism.
[0030] The ranging sensor 38 measures the imaging distance. In the first embodiment, the imaging distance refers to the distance from the imaging device 10 (e.g., the light receiving surface of the image sensor 32) to the imaging target area 12 (e.g., a specific person included in the imaging target area 12 shown in FIG. 1). A first example of the ranging sensor 38 is a ranging sensor using image plane phase difference pixels applied to the image sensor 32. A second example of the ranging sensor 38 is a ranging sensor that uses multiple phase difference pixels and is provided in the imaging device 10 as a sensor separate from the image sensor 32. A third example of the ranging sensor 38 is a time-of-flight (TOF) ranging sensor. As such, the ranging sensor 38 may be any sensor capable of measuring the imaging distance.
[0031] The GNSS device 39 receives radio waves transmitted from a plurality of satellites (not shown) and calculates the latitude and longitude that allow the current position of the imaging device 10 to be identified based on the received radio waves.
[0032] The communication I / F 40 is an interface including a communication processor, an antenna, etc., and is connected to the bus 48. The communication standard applied to the communication I / F 40 may be, for example, a wireless communication standard including 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), Bluetooth (registered trademark), etc., or a wired communication standard including Ethernet (registered trademark), Fast Ethernet (registered trademark), Gigabit Ethernet (registered trademark), etc.
[0033] An image file creation program 50 is stored in the NVM 44. The image file creation program 50 is an example of a "program" according to the technology of the present disclosure. The processor 42 reads the image file creation program 50 from the NVM 44 and executes the read image file creation program 50 on the RAM 46 to perform an image file creation process. The image file creation process is realized by the processor 42 operating as an acquisition unit 42A, an association unit 42B, an encryption unit 42C, an attachment unit 42D, and a transmission unit 42E in accordance with the image file creation program 50 executed on the RAM 46.
[0034] 4 , the receiving device 24 includes a computer 52, a UI device 54, and a communication I / F 56. The computer 52 includes a processor 58, an NVM 60, and a RAM 62. The processor 58, the NVM 60, the RAM 62, the UI device 54, and the communication I / F 56 are connected to a bus 64.
[0035] Note that the hardware configuration of the computer 52 (i.e., the processor 58, the NVM 60, and the RAM 62) is basically the same as the hardware configuration of the computer 30 shown in Fig. 3, so a description of the hardware configuration of the computer 52 will be omitted here. Also, the role played by the UI-based device 54 in the receiving device 24 is basically the same as the role played by the UI-based device 34 in the imaging device 10 shown in Fig. 3, so a description thereof will be omitted here. Furthermore, the role played by the communication I / F 56 in the receiving device 24 is basically the same as the role played by the communication I / F 40 in the imaging device 10 shown in Fig. 3, so a description thereof will be omitted here.
[0036] An image file receiving program 66 is stored in the NVM 60. The processor 58 performs image file receiving processing by reading the image file receiving program 66 from the NVM 60 and executing the read image file receiving program 66 on the RAM 62. The image file receiving processing is realized by the processor 58 operating as a receiving unit 58A, a generating unit 58B, a comparing unit 58C, and an executing unit 58D in accordance with the image file receiving program 66 executed on the RAM 62.
[0037] 5 to 9 show examples of the processing contents of the acquisition unit 42A, association unit 42B, encryption unit 42C, attachment unit 42D, and transmission unit 42E in the imaging device 10. FIG.
[0038] 5 as an example, the acquisition unit 42A executes an imaging step and an acquisition step. The imaging step is a step of acquiring image data 18 obtained by imaging by the image sensor 32 from the image sensor 32. The acquisition step is a step of acquiring related information 68 related to the image data 18. The imaging step is an example of an "imaging step" according to the technology of the present disclosure. The acquisition step is also an example of an "acquisition step" according to the technology of the present disclosure.
[0039] Here, in order to prevent a third party from creating information that is not the legitimate related information 68 (i.e., false related information 68) in time, the acquisition process is automatically executed after the image data 18 is acquired. That is, the acquisition process is automatically executed after the imaging process. For example, the acquisition unit 42A performs the imaging process and the acquisition process consecutively by synchronizing the end of the imaging process with the start of the acquisition process (e.g., starting the acquisition process at the timing when the imaging process is completed).
[0040] The related information 68 includes image-capturer information 68A, image capture time information 68B, image capture device position information 68C, and subject position information 68D. Here, image-capturer information 68A is an example of "image-capturer information" according to the technology of the present disclosure. Furthermore, image capture time information 68B is an example of "image capture time information" according to the technology of the present disclosure. Furthermore, image capture device position information 68C is an example of "image capture device position information" according to the technology of the present disclosure. Furthermore, subject position information 68D is an example of "subject position information" according to the technology of the present disclosure.
[0041] The photographer information 68A is information that can identify the person who captured the image using the imaging device 10 to obtain the image data 18, i.e., the photographer 14. An example of the photographer information 68A is information that indicates the name (e.g., name or handle name) of the photographer 14. The photographer information 68A is stored in the NVM 44 and is acquired from the NVM 44 by the acquisition unit 42A.
[0042] For the sake of convenience, an example is given here in which the acquisition unit 42A acquires the photographer information 68A from the NVM 44. However, this is merely one example. For example, the photographer information 68A may be acquired by the acquisition unit 42A from a server or the like via the network 28, or the photographer information 68A may be manually input via the UI device 34 and acquired by the acquisition unit 42A.
[0043] The image capturing time information 68B is information indicating the time when an image was captured using the image capturing device 10 to obtain the image data 18. For example, the image capturing time information 68B is acquired by the acquisition unit 42A via the network 28.
[0044] For convenience of explanation, an example is given here in which the image capture time information 68B is acquired by the acquisition unit 42A via the network 28, but this is merely one example. For example, the image capture time information 68B may be acquired by the acquisition unit 42A from a real-time clock built into the image capture device 10 or a real-time clock built into an external device (e.g., a smart device) connected to the image capture device 10, or the image capture time information 68B may be manually input via the UI device 34 and acquired by the acquisition unit 42A.
[0045] For ease of explanation, imaging time information 68B is cited as information included in the related information 68, but this is merely an example. For example, the information included in the related information 68 may be information indicating the time required for exposure performed by the image sensor 32. The information included in the related information 68 may also be information indicating the time interval between frames. The information included in the related information 68 may also be information indicating the time when imaging to obtain a moving image started. The information included in the related information 68 may also be information indicating the time when imaging to obtain a moving image ended. The information included in the related information 68 may also be information indicating the time from when imaging to obtain a moving image started to when it ended. In this way, it is sufficient that the related information 68 includes information indicating the time related to imaging using the imaging device 10.
[0046] The imaging device position information 68C is information indicating the position where imaging was performed by the imaging device 10 to obtain the image data 18 (for example, the position of the imaging device 10 at the time the imaging was performed), and is acquired by the acquisition unit 42A from the GNSS device 39. That is, the GNSS device 39 calculates the latitude and longitude that can identify the current position of the imaging device 10, and information indicating the calculated latitude and longitude is acquired by the acquisition unit 42A as the imaging device position information 68C.
[0047] For convenience of explanation, an example is given here in which the imaging device position information 68C is acquired by the acquisition unit 42A from the GNSS device 39, but this is merely one example. For example, information indicating latitude and longitude manually input via the UI device 34 may be acquired by the acquisition unit 42A as the imaging device position information 68C. Furthermore, for example, information indicating latitude and longitude calculated by a GNSS device built into an external device (e.g., a smart device) connected to the imaging device 10 may be acquired by the acquisition unit 42A as the imaging device position information 68C.
[0048] The subject position information 68D is information indicating the position of the imaging target area 12 (here, as an example, the latitude and longitude of the imaging target area 12), and is calculated by the acquisition unit 42A. The acquisition unit 42A calculates the subject position information 68D based on the imaging device position information 68C, distance information 70, and orientation information 72. The distance information 70 is information indicating the imaging distance measured by the distance measurement sensor 38, and is acquired from the distance measurement sensor 38 by the acquisition unit 42A. The orientation information 72 is information indicating the orientation detected by the electronic compass 36, and is acquired from the electronic compass 36 by the acquisition unit 42A.
[0049] For the sake of convenience, the subject position information 68D is calculated by the acquisition unit 42A in the above example, but this is merely an example. For example, the subject position information 68D may be manually input via the UI device 34 and acquired by the acquisition unit 42A.
[0050] The imaging device position information 68C and the subject position information 68D include non-permissible information 74. The non-permissible information 74 is information indicating that modification and deletion are not permitted. In other words, the non-permissible information 74 included in the imaging device position information 68C is information indicating that modification and deletion of the imaging device position information 68C are not permitted, and the non-permissible information 74 included in the subject position information 68D is information indicating that modification and deletion of the subject position information 68D are not permitted.
[0051] Therefore, the photographer 14 or the recipient 26 can determine whether the information is not permitted to be altered or deleted by checking whether the information includes the disallowed information 74. For example, in the first embodiment, the imaging device location information 68C and the subject location information 68D include the disallowed information 74, so the photographer 14 or the recipient 26 can recognize that the imaging device location information 68C and the subject location information 68D are not permitted to be altered or deleted.
[0052] The acquisition unit 42A includes the unacceptable information 74 in one or more pieces of information (here, as an example, the imaging device position information 68C and the subject position information 68D) selected from the multiple pieces of information included in the related information 68 in accordance with the instructions received by the UI-based device 34.
[0053] In addition, among the multiple pieces of information included in the related information 68, one or more pieces of information that include the unacceptable information 74 may be predetermined, and in this case, the acquisition unit 42A includes the unacceptable information 74 in the one or more pieces of information that are predetermined.
[0054] 6 , the associating unit 42B generates first association information 76. The first association information 76 is generated by associating reliability information 78 with the related information 68 acquired by the acquiring unit 42A. The reliability information 78 is an example of “reliability information” according to the technology of the present disclosure.
[0055] The reliability information 78 indicates the reliability of the related information 68. Here, related information 68 that is highly likely to be altered or deleted can be said to be information with low reliability. Conversely, related information 68 that is less likely to be altered or deleted can be said to be information with high reliability.
[0056] The reliability of the related information 68 depends on the source of the related information 68. In other words, the source of the related information 68 can be one indicator for the recipient 26 or the like to determine the reliability of the related information 68. For example, if the source of the related information 68 is a source with high security (e.g., a source where it is difficult to modify or delete the related information 68), the recipient 26 or the like can determine that the reliability of the related information 68 is also high, and if the source of the related information 68 is a source with low security (e.g., a source where it is easy to modify or delete the related information 68), the recipient 26 or the like can determine that the reliability of the related information 68 is also low.
[0057] Examples of sources with high security include the network 28 or GNSS. An example of a source with medium security is when the processor 42 obtains some information in cooperation with another sensor that measures distance or direction. Examples of sources with low security (i.e., sources that are more susceptible to third-party intervention than the network 28 or GNSS) include the UI device 34 or a read / write memory (e.g., the NVM 44). In this case, the related information 68 obtained manually or from a read / write memory can be considered to be less reliable than the related information 68 obtained through a page with a public address on the network 28. Therefore, in the first embodiment, information regarding whether the related information 68 was obtained through the network 28 is used as an example of the reliability information 78.
[0058] The reliability information 78 includes first reliability information 78A, second reliability information 78B, third reliability information 78C, and fourth reliability information 78D. The associating unit 42B associates the first reliability information 78A with the image-capturer information 68A, the second reliability information 78B with the image-capturing time information 68A, the third reliability information 78C with the image-capturing device position information 68C, and the fourth reliability information 78D with the subject position information 68D.
[0059] The first reliability information 78A is information that can identify the source of the image capturer information 68A. In the first embodiment, the image capturer information 68A is information acquired by the acquisition unit 42A from the NVM 44. Therefore, in the first embodiment, information indicating that the image capturer information 68A was acquired from the NVM 44 is used as an example of the first reliability information 78A. The fact that such first reliability information 78A is associated with the image capturer information 68A means that the image capturer information 68A is not information acquired via the network 28.
[0060] Here, in a similar manner to the automatic execution of the acquisition step after the imaging step, the associating unit 42B automatically associates the first reliability information 78A with the imager information 68A after the imager information 68A is acquired by the acquisition unit 42A from the NVM 44. The reason for doing so is to prevent time from being taken for a third party to create false reliability information 78 and associate it with the imager information 68A.
[0061] The second reliability information 78B is information that can identify the source of the imaging time information 68B. In the first embodiment, the imaging time information 68B is information obtained via the network 28. Therefore, in the first embodiment, information indicating that the imaging time information 68B was obtained via the network 28 is used as an example of the second reliability information 78B. The fact that such second reliability information 78B is associated with the imaging time information 68B means that the imaging time information 68B is information obtained via the network 28.
[0062] In addition, in a similar manner to the association between the first reliability information 78A and the photographer information 68A, the second reliability information 78B is also automatically associated with the imaging time information 68B after the imaging time information 68B is acquired via the network 28.
[0063] The third reliability information 78C is information that can identify the source of the imaging device position information 68C. In the first embodiment, the imaging device position information 68C is information acquired via GNSS. Therefore, in the first embodiment, information indicating that the imaging device position information 68C was acquired via GNSS is used as an example of the third reliability information 78C. The fact that such third reliability information 78C is associated with the imaging device position information 68C means that the imaging device position information 68C is not information obtained via a highly reliable GNSS.
[0064] In addition, in a similar manner to the association between the first reliability information 78A and the imager information 68A, the third reliability information 78C is also automatically associated with the image capturing device position information 68C after the image capturing device position information 68C is acquired via GNSS.
[0065] The fourth reliability information 78D is information that can identify the source of the subject position information 68D. In the first embodiment, the subject position information 68D is information acquired through internal processing by the processor 42 (i.e., calculation of the subject position information 68D by the acquisition unit 42A based on the imaging device position information 68C, the distance information 70, and the orientation information 72). Therefore, in the first embodiment, information indicating that the subject position information 68D was acquired through internal processing by the processor 42 is used as an example of the fourth reliability information 78D. The fact that such fourth reliability information 78D is associated with the subject position information 68D means that the subject position information 68D is information acquired by the processor 42, which has a slightly higher reliability, performing internal processing in cooperation with another device (e.g., the electronic compass 36 or the distance measuring sensor 38).
[0066] In addition, in a similar manner to the association between the first reliability information 78A and the photographer information 68A, the fourth reliability information 78D is also automatically associated with the subject position information 68D after the subject position information 68D is obtained through internal processing by the processor 42.
[0067] 7 , the encryption unit 42C generates second association information 80 using the first association information 76. The second association information 80 differs from the first association information 76 in that the related information 68 is replaced with encryption information 82 and that the second association information 80 includes time information 86.
[0068] The encryption unit 42C executes an encryption step, which is a step of generating encrypted information 82 by encrypting the related information 68 included in the first association information 76. The encrypted information 82 is an example of the “first encrypted information” according to the technology of the present disclosure.
[0069] The encryption step is automatically performed after the acquisition step in the same manner as the acquisition step is automatically performed after the imaging step, in order to prevent a third party from modifying the related information 68, deleting the related information 68, and encrypting the modified related information 68.
[0070] A hash function 84 is stored in the NVM 44. Examples of the hash function 84 include SHA-256, SHA-384, and SHA-512. The encryption unit 42C obtains the hash function 84 from the NVM 44, and generates encrypted information 82 by encrypting (i.e., hashing) the related information 68 using the obtained hash function 84.
[0071] The encrypted information 82 includes a first hash value 82A, a second hash value 82B, a third hash value 82C, and a fourth hash value 82D. The first hash value 82A is a value obtained by hashing the photographer information 68A using a hash function 84. The second hash value 82B is a value obtained by hashing the image capture time information 68B using the hash function 84. The third hash value 82C is a value obtained by hashing the image capture device position information 68C using the hash function 84. The fourth hash value 82D is a value obtained by hashing the subject position information 68D using the hash function 84.
[0072] The reliability information 78 associated with the related information 68 is inherited and associated with the encrypted information 82. That is, the first reliability information 78A is associated with the first hash value 82A, the second reliability information 78B is associated with the second hash value 82B, the third reliability information 78C is associated with the third hash value 82C, and the fourth reliability information 78D is associated with the fourth hash value 82D.
[0073] In the encryption step, encryption unit 42C generates time information 86, which is information relating to the time when encryption information 82 was generated, and includes the generated time information 86 in second association information 80. For example, in the encryption step, time information 86 is included in second association information 80 by being associated with encryption information 82.
[0074] In the first embodiment, information generated using the image capture time information 68B is used as an example of the time information 86. An example of the timing at which the time information 86 is generated is the timing at which encryption (here, hashing, as an example) of the related information 68 is completed.
[0075] The time information 86 includes information indicating the timing of generation, such as that the encrypted information 82 was generated at the time of image capture, and the image capture time information 68B. Note that this is merely an example, and the time information 86 may be the image capture time information 68B itself. The time information 86 may also be information indicating the time when the encryption of the related information 68 actually ended. In this case, for example, the time information 86 may be obtained by the encryption unit 42C via the network 28 when the encryption of the related information 68 ended, or may be obtained by the encryption unit 42C from a real-time clock built into the image capture device 10 when the encryption of the related information 68 ended.
[0076] As an example, as shown in Figures 8A and 8B, the attachment unit 42D executes an attachment process of directly or indirectly attaching the related information 68, the second association information 80, and the hash function 84 to the image data 18 as metadata 20. The attachment process includes a creation process. The creation process is a process of creating an image file 16. In the creation process, the image file 16 is created by converting the image data 18 and the metadata 20 into a file according to a predetermined file format. Here, when the attachment unit 42D directly attaches the metadata 20 to the image data 18, for example, as shown in Figure 8A, the image file 16 includes the related information 68, the second association information 80, and the hash function 84 as metadata 20.
[0077] 8B shows an example of a case where attachment unit 42D indirectly attaches metadata 20 to image data 18. Indirect attachment of metadata 20 to image data 18 is achieved by including access information 85 in metadata 20 within image file 16.
[0078] In the example shown in FIG. 8B , the accessory process includes a recording process of recording the metadata 20 on the recording medium 4 of an external server 2 (e.g., a process in which the accessory unit 42D uploads the metadata 20 to the server 2 and causes the server 2 to record it on the recording medium 4), and a creation process of creating an image file 16 including access information 85 for accessing the metadata 20 in the recording medium 4 (e.g., information for enabling access to the metadata 20 stored on the recording medium 4 of the server 2).
[0079] Examples of the recording medium 4 include a hard disk, a magnetic tape, or a flash memory. Examples of access include a process of searching for and viewing information (here, as an example, metadata 20) on the network 28, a process of reading information (here, as an example, metadata 20) from memory (here, as an example, the recording medium 4), or a process of writing information to memory. Examples of the access information 85 include an identifier (ID), a uniform resource locator (URL), or a download password.
[0080] In this way, by including access information 85 in the metadata 20 in the image file 16, a user who is officially authorized to use the image file 16 can access the metadata 20 in the recording medium 4 by using the access information 85 included in the metadata 20 in the image file 16.
[0081] The metadata 20 contained in the image file 16 and the metadata 20 contained in the recording medium 20 may be the same data, or may be partially or entirely different data.
[0082] A first example of a case in which the metadata 20 contained in the image file 16 differs from the metadata 20 contained in the recording medium 20 is a case in which all of the related information 68, second association information 80, and hash function 84 shown in FIG. 8A are recorded on the recording medium 20, and metadata 20 other than the related information 68, second association information 80, and hash function 84 shown in FIG. 8A are recorded in the image file 16.
[0083] A second example of a case in which the metadata 20 contained in the image file 16 differs from the metadata 20 contained in the recording medium 20 is one in which part of the related information 68, second association information 80, and hash function 84 shown in FIG. 8A (e.g., related information 68) is recorded on the recording medium 20, and metadata 20 including the remainder (e.g., second association information 80 and hash function 84) is recorded on the image file 16.
[0084] A third example of a case in which the metadata 20 contained in the image file 16 is different from the metadata 20 contained in the recording medium 20 is an example in which access information 85 is recorded as metadata 20 in the image file 16, and metadata 20 other than the access information 85 is recorded on the recording medium 20.
[0085] In this way, by distributing the metadata 20 between the image file 16 and the recording medium 4, the security of the metadata 20 can be improved.
[0086] In each embodiment, in order to facilitate understanding of the technology of the present disclosure, an example of a form in which metadata 20 is directly attached to image data 18 is described; however, the technology of the present disclosure is not limited to this, and the technology of the present disclosure also includes an example in which the attachment unit 42D indirectly attaches metadata 20 to image data 18.
[0087] The attachment unit 42D automatically includes the related information 68 in the metadata 20 after the acquisition step, in the same way that the acquisition step is automatically performed after the imaging step. The reason for doing so is to prevent any time leeway for a third party to alter or delete the related information 68 before the related information 68 is included in the metadata 20.
[0088] The attachment unit 42D automatically includes the second association information 80 and the hash function 84 in the metadata 20 after the encryption step, in the same way that the acquisition step is automatically performed after the imaging step. The reason for doing so is to prevent any time leeway for a third party to alter or delete the second association information 80 and the hash function 84 before they are included in the metadata 20.
[0089] 9, in the imaging device 10, the transmitting unit 42E transmits the image file 16 created by the attachment unit 42D to the receiving device 24 via the communication I / F 40 (see FIG. 3). The receiving device 24 receives the image file 16 transmitted from the transmitting unit 42E via the communication I / F 56 (see FIG. 4). As a result, the image file 16 is transferred from the photographer 14 to the recipient 26 (see FIG. 2).
[0090] 10 to 12 show an example of the processing contents of the receiving unit 58A, generating unit 58B, comparing unit 58C, and executing unit 58D in the receiving device 24. FIG.
[0091] 10 , the generation unit 58B acquires the image file 16 received by the reception unit 58A from the reception unit 58A. The generation unit 58B executes a generation step. The generation step is a step of generating verification information 88 using the related information 68 and a hash function 84. The generation step is an example of a "generation step" according to the technology of the present disclosure.
[0092] In the generating step, the generating unit 58B obtains the related information 68 and the hash function 84 from the metadata 20 included in the image file 16, and generates verification information 88 by hashing the related information 68 using the hash function 84. The verification information 88 includes a fifth hash value 88A, a sixth hash value 88B, a seventh hash value 88C, and an eighth hash value 88D.
[0093] The fifth hash value 88A is a value obtained by hashing, using the hash function 84, the photographer information 68A (see FIG. 6) included in the related information 68. The sixth hash value 88B is a value obtained by hashing, using the hash function 84, the image capture time information 68A (see FIG. 6) included in the related information 68. The seventh hash value 88C is a value obtained by hashing, using the hash function 84, the image capture device position information 68C included in the related information 68. The eighth hash value 88D is a value obtained by hashing, using the hash function 84, the subject position information 68D.
[0094] 11 , the comparison unit 58C acquires the image file 16 received by the reception unit 58A (i.e., the same image file 16 as the image file 16 acquired by the generation unit 58B) from the reception unit 58A. The comparison unit 58C extracts encryption information 82 from the second association information 80 in the metadata 20 included in the image file 16 acquired from the reception unit 58A.
[0095] The comparison unit 58C acquires the verification information 88 generated by the generation unit 58B from the generation unit 58B. Here, the comparison unit 58C executes a comparison step. The comparison step is an example of a "comparison step" according to the technology of the present disclosure. The comparison step is a step of comparing the verification information 88 acquired from the generation unit 58B with the encrypted information 82 extracted from the second association information 80. Note that, as shown in FIG. 8B , when the metadata 20 is recorded on the recording medium 4 of the server 2, the verification of the modification or deletion of the metadata 20 in the comparison step may be executed within the server 2, or may be executed by a device communicatively connected to the server 2 (such as a personal computer or a server other than the server 2).
[0096] The comparison unit 58C compares a fifth hash value 88A included in the verification information 88 with a first hash value 82A included in the encryption information 82 to determine whether the fifth hash value 88A and the first hash value 82A match. The comparison unit 58C also compares a sixth hash value 88B included in the verification information 88 with a second hash value 82B included in the encryption information 82 to determine whether the sixth hash value 88B and the second hash value 82B match. The comparison unit 58C also compares a seventh hash value 88C included in the verification information 88 with a third hash value 82C included in the encryption information 82 to determine whether the seventh hash value 88C and the third hash value 82C match. The comparison unit 58C also compares an eighth hash value 88D included in the verification information 88 with a fourth hash value 82D included in the encryption information 82 to determine whether the eighth hash value 88D and the fourth hash value 82D match.
[0097] 12, the execution unit 58D acquires the comparison result 90 from the comparison unit 58C. The comparison result 90 includes a first comparison result 90A, a second comparison result 90B, a third comparison result 90C, and a fourth comparison result 90D.
[0098] The first comparison result 90A is the result of the comparison by the comparator 58C between the fifth hash value 88A and the first hash value 82A (i.e., the result of determining whether the fifth hash value 88A and the first hash value 82A match). The second comparison result 90B is the result of the comparison by the comparator 58C between the sixth hash value 88B and the second hash value 82B (i.e., the result of determining whether the sixth hash value 88B and the second hash value 82B match). The third comparison result 90C is the result of the comparison by the comparator 58C between the seventh hash value 88C and the third hash value 82C (i.e., the result of determining whether the seventh hash value 88C and the third hash value 82C match). The fourth comparison result 90D is the result of the comparison between the eighth hash value 88D and the fourth hash value 82D by the comparison unit 58C (i.e., the result of determining whether the eighth hash value 88D and the fourth hash value 82D match).
[0099] The execution unit 58D acquires from the receiving unit 58A the image file 16 received by the receiving unit 58A (i.e., the same image file 16 as the image file 16 acquired by the generating unit 58B and the comparing unit 58C). The execution unit 58D also extracts the reliability information 78 and the time information 86 from the second association information 80 in the metadata 20 included in the image file 16 acquired from the receiving unit 58A.
[0100] The execution unit 58D executes processing based on the comparison result 90 acquired from the comparison unit 58C, the reliability information 78 extracted from the second association information 80, and the timing information 86 extracted from the second association information 80.
[0101] Preventive processing is an example of processing based on the comparison result 90, the reliability information 78, and the timing information 86. Preventive processing refers to processing that prevents a recipient 26 who uses the metadata 20 from suffering any disadvantage due to, for example, alteration of the metadata 20 or deletion of part of the metadata 20.
[0102] A first example of preventive processing is a process of presenting the comparison result 90, reliability information 78, and timing information 86 to the recipient 26 via a UI-based device 34 (e.g., a display) or notifying the photographer 14.
[0103] A second example of preventive processing is a process in which, based on the comparison result 90, the reliability information 78, and the timing information 86, a numerical value indicating the possibility that the related information 68 included in the metadata 20 has been altered or that part of the related information 68 has been deleted is calculated, and information based on the calculated numerical value is output to a specific output destination (e.g., a UI-based device 34, an NVM 44, or an external device on the network 28, etc.).
[0104] A third example of the preventive processing is the processing of calculating a numerical value indicating the possibility as described above and including information based on the calculated numerical value in the metadata 20 .
[0105] A fourth example of preventive processing is a process of calculating the degree of difference between the time indicated by the timing information 86 and the time indicated by the image capture time information 68B included in the metadata 20 of the image file 16, and outputting information based on the calculated degree of difference to a specific output destination. Examples of information based on the degree of difference include information indicating the degree of difference itself, or alert information determined according to the degree of difference. Examples of alert information include information that calls for greater caution as the degree of difference increases.
[0106] A fifth example of the preventive processing is a processing in which the degree of difference is calculated as described above, and information based on the calculated degree of difference (for example, a flag according to the degree of difference) is included in the metadata 20.
[0107] A sixth example of preventive processing is a process in which, as described above, a numerical value indicating the possibility or a degree of difference is calculated, and if the numerical value indicating the possibility or the degree of difference exceeds a threshold, the image file 16 is deleted, a flag is assigned to the image file 16, or the image file 16 is stored in a specific storage area.
[0108] Although the above example illustrates an embodiment in which the execution unit 58D executes preventive processing based on the comparison result 90, the reliability information 78, and the timing information 86, this is merely an example. For example, the execution unit 58D may execute preventive processing based on one or two of the comparison result 90, the reliability information 78, and the timing information 86.
[0109] Next, the operation of the imaging device 10 and the receiving device 24 related to the technique of the present disclosure will be described with reference to FIGS.
[0110] First, the operation of the portion of the imaging device 10 related to the technology of the present disclosure will be described with reference to Fig. 13. The flow of the image file creation process shown in the flowchart in Fig. 13 is an example of an "information creation method" related to the technology of the present disclosure.
[0111] 13 , first, in step ST10, the acquisition unit 42A determines whether or not one frame of image data has been captured by the image sensor 32. If one frame of image data (e.g., image data for a still image) has not been captured by the image sensor 32 in step ST10, the determination is negative, and the image file creation process proceeds to step ST26. If one frame of image data has been captured by the image sensor 32 in step ST10, the determination is positive, and the image file creation process proceeds to step ST12.
[0112] In step ST12, the acquisition unit 42A acquires the image data 18 from the image sensor 32. After the process of step ST12 is executed, the image file creation process proceeds to step ST14.
[0113] In step ST14, the acquisition unit 42A acquires the related information 68 related to the image data 18. After the process of step ST14 is executed, the image file creation process proceeds to step ST16.
[0114] In step ST16, the associating unit 42B generates first association information 76 by associating the association information 68 acquired in step ST14 with the reliability information 78. After the processing of step ST16 is executed, the image file creation processing proceeds to step ST18.
[0115] In step ST18, the encryption unit 42C generates encrypted information 82 by encrypting the associated information 68 included in the first association information 76 generated in step ST16 using a hash function 84. After the processing of step ST18 is executed, the image file creation processing proceeds to step ST20.
[0116] In step ST20, the encryption unit 42C generates time information 86. Then, the encryption unit 42C generates second association information 80 based on the encryption information 82 generated in step ST18, the reliability information 78 used in step ST16, and the time information 86. After the process of step ST20 is executed, the image file creation process proceeds to step ST22.
[0117] In step ST22, the attachment unit 42D attaches the related information 68 acquired in step ST14, the second association information 80 generated in step ST20, and the hash function 84 used in step ST18 to the image data 18 as metadata 20, thereby creating the image file 16. After the processing of step ST22 is executed, the image file creation processing proceeds to step ST24.
[0118] In step ST24, the sending unit 42E sends the image file 16 created in step ST22 to the receiving device 24. After the process of step ST24 is executed, the image file creation process proceeds to step ST26.
[0119] In step ST26, the transmission unit 42E determines whether the conditions for terminating the image file creation process are satisfied. One example of a condition for terminating the image file creation process is that an instruction to terminate the image file creation process is accepted by the UI device 34. If the conditions for terminating the image file creation process are not satisfied in step ST26, the determination is negative, and the image file creation process proceeds to step ST10. If the conditions for terminating the image file creation process are satisfied in step ST26, the determination is positive, and the image file creation process is terminated.
[0120] Next, the operation of the portion of the receiving device 24 related to the technique of the present disclosure will be described with reference to FIG.
[0121] In the receiving process shown in Fig. 14, first, in step ST50, the receiving unit 58A determines whether or not the image file 16 transmitted from the transmitting unit 42E of the imaging device 10 has been received by executing the process of step ST24 shown in Fig. 13. If the image file 16 has not been received in step ST50, the determination is negative, and the image file receiving process proceeds to step ST60. If the image file 16 has been received in step ST50, the determination is positive, and the image file receiving process proceeds to step ST52.
[0122] In step ST52, the generation unit 58B generates verification information 88 by encrypting the related information 68 included in the metadata 20 of the image file 16 received in step ST50 using the hash function 84 included in the metadata 20. After the processing of step ST52 is executed, the image file receiving processing proceeds to step ST54.
[0123] In step ST54, the comparison unit 58C extracts the encryption information 82 from the second association information 80 included in the metadata 20 of the image file 16 received in step ST50. The comparison unit 58C then compares the encryption information 82 extracted from the second association information 80 with the verification information 88 generated in step ST52. After the processing of step ST54 is executed, the receiving processing proceeds to step ST56.
[0124] In step ST56, the execution unit 58D extracts the reliability information 78 and the timing information 86 from the second association information 80 included in the metadata 20 of the image file 16 received in step ST50. After the processing of step ST56 is executed, the image file receiving processing proceeds to step ST58.
[0125] In step ST58, the execution unit 58D executes processing (for example, the preventive processing described above) based on the comparison result 90 obtained by comparing the encryption information 82 with the verification information 88 in step ST54, the reliability information 78 extracted from the second association information 80 in step ST56, and the timing information 86 extracted from the second association information 80 in step ST56. After the processing in step ST58 is executed, the image file receiving processing proceeds to step ST60.
[0126] In step ST60, the execution unit 58D determines whether the conditions for terminating the image file receiving process are satisfied. One example of a condition for terminating the image file receiving process is that an instruction to terminate the image file receiving process is accepted by the UI device 54. If the conditions for terminating the image file receiving process are not satisfied in step ST60, the determination is negative, and the image file receiving process proceeds to step ST50. If the conditions for terminating the image file receiving process are satisfied in step ST60, the determination is positive, and the image file receiving process is terminated.
[0127] As described above, in the first embodiment, the imaging device 10 acquires the related information 68 related to the image data 18 and encrypts the related information 68 to generate encrypted information 82. The imaging device 10 creates the image file 16 by attaching the encrypted information 82 to the image data 18 as metadata 20.
[0128] In the first embodiment, the imaging device 10 includes time information 86 in the metadata 20 of the image file 16. The time information 86 is information related to the time when the encrypted information 82 was generated. Therefore, for example, when a recipient 26 or the like receives an image file 16 from the photographer 14, the recipient 26 or the like can infer the validity of the time when the related information 68 was encrypted by referring to the time information 86 included in the metadata 20 of the image file 16. For example, if the recipient 26 or the like feels that the time when the related information 68 was encrypted is valid, the recipient 26 or the like can determine that the reliability of the related information 68 is high. Conversely, if the recipient 26 or the like feels that there is something abnormal about the time when the related information 68 was encrypted, the recipient 26 or the like can determine that the reliability of the related information 68 is low. In this way, by including the time information 86 in the metadata 20 of the image file 16, the security of the related information 68 can be improved.
[0129] Furthermore, reliability information 78 is included in the metadata 20 by the imaging device 10. The reliability information 78 is information indicating the reliability of the related information 68. Therefore, for example, when a recipient 26 or the like receives an image file 16 from the photographer 14, the recipient 26 or the like can determine the reliability of the related information 68 by referring to the reliability information 78 included in the metadata 20 of the image file 16. In this way, by including the reliability information 78 in the metadata 20 of the image file 16, the security of the related information 68 can be improved.
[0130] Furthermore, in the first embodiment, the imaging device 10 includes the related information 68 in the metadata 20. In this case, for example, the recipient 26 or the like can receive the related information 68 related to the image data 18 by receiving the image file 16 itself or the metadata 20 included in the image file 16 from the photographer 14. This allows the recipient 26 or the like to easily obtain the related information 68.
[0131] Furthermore, in the first embodiment, information regarding whether or not the related information 68 is information obtained through the network 28 is used as an example of the reliability information 78. Therefore, if the related information 68 is information obtained through the network 28, the recipient 26 or the like can be made to determine that the related information 68 is information with high security obtained from a public page. If the related information 68 is information that is not obtained through the network 28 or GNSS, the recipient 26 or the like can be made to determine that the related information 68 is information with low security.
[0132] Furthermore, in the first embodiment, the imaging device 10 creates an image file 16 that includes the related information 68 and the encrypted information 82. That is, not only the encrypted information 82 but also the related information 68, which is the information before encryption, is included in the image file 16. This allows, for example, the receiving device 24 to perform not only processing using the encrypted information 82 but also processing using the related information 68.
[0133] Furthermore, in the first embodiment, the related information 68 includes photographer information 68A, image capture time information 68B, image capture device location information 68C, and subject location information 68D. The related information 68 is encrypted and included in the metadata 20 of the image file 16 as encrypted information 82. This makes it possible to improve the security of the photographer information 68A, image capture time information 68B, image capture device location information 68C, and subject location information 68D.
[0134] In the first embodiment, among the photographer information 68A, the imaging time information 68B, the imaging device position information 68C, and the subject position information 68D, the imaging device position information 68C and the subject position information 68D include disallowance information 74. The disallowance information 74 is information indicating that modification and deletion are not permitted.
[0135] Therefore, the image capturer 14 or the recipient 26 or the like can recognize that modification or deletion of the imaging device location information 68C and the subject location information 68D is not permitted. This allows the image capturer 14 or the recipient 26 or the like to separately handle information that is permitted to be modified or deleted (here, as an example, the imaging device location information 68C and the subject location information 68D) and information that is not permitted to be modified or deleted (here, as an example, the imaging device location information 68C and the subject location information 68D). This also makes it possible to prevent the imaging device location information 68C and the subject location information 68D from being modified or deleted against the intention of the image capturer 14 or the recipient 26 or the like.
[0136] Furthermore, in the first embodiment, the hash function 84 used to encrypt the related information 68 is included in the metadata 20. Therefore, the recipient 26 or the like who receives the image file 16 from the photographer 14 can easily obtain the hash function 84 used to encrypt the related information 68.
[0137] Furthermore, in the first embodiment, the image file 16 transmitted from the imaging device 10 is received by the receiving device 24, and the receiving device 24 acquires a hash function 84 from the image file 16. The receiving device 24 then encrypts (i.e., hashes) the related information 68 using the hash function 84 to generate verification information 88, and compares the verification information 88 with the encrypted information 82. As a result, for example, if the verification information 88 and the encrypted information 82 do not match, the recipient 26 or the like can determine that there is a high possibility that the related information 68 has been altered or that a portion of the related information 68 has been deleted. Conversely, for example, if the verification information 88 and the encrypted information 82 match, the recipient 26 or the like can determine that there is a low possibility that the related information 68 has been altered or that a portion of the related information 68 has been deleted.
[0138] Furthermore, in the first embodiment, the process of encrypting the related information 68 is automatically executed after the related information 68 is acquired in the imaging device 10. This eliminates the time window for the related information 68 to be altered or a portion of the related information 68 to be deleted during the time until the encrypted information 82 is generated from the related information 68, thereby improving the reliability of the related information 68.
[0139] Furthermore, in the first embodiment, the related information 68 is automatically acquired after the image data 18 is acquired in the imaging device 10. This eliminates time for a third party to alter, delete, or create false related information 68 before the related information 68 is included in the metadata 20, for example, thereby increasing the reliability of the related information 68.
[0140] Furthermore, in the first embodiment, the image data 18 obtained by capturing an image using the image sensor 32 is acquired by the acquisition unit 42A from the image sensor 32, and then the acquisition unit 42A automatically acquires the related information 68. This eliminates time for a third party to create information that is not the legitimate related information 68 (i.e., fake related information 68), for example, and therefore increases the reliability of the related information 68.
[0141] In the first embodiment, the unacceptable information 74 is included in the imaging device position information 68C and the subject position information 68D. However, this is merely an example. For example, the unacceptable information 74 may be included in the imaging device position information 68C or the subject position information 68D, or the unacceptable information 74 may be included in other information included in the related information 68 (for example, the photographer information 68A or the imaging time information 68B). Furthermore, the unacceptable information 74 may be assigned to the entire related information 68.
[0142] Furthermore, in the first embodiment, an example was described in which the time information 86 is included directly in the second association information 80, but this is merely one example. For example, the time information 86 may also be encrypted in the same manner as the association information 68 is encrypted, and the encrypted time information 86 may be included in the second association information 80. In this case, the time information 86 before encryption may be included as part of the association information 68 in the metadata 20 of the image file 16.
[0143] [Second Embodiment] In the first embodiment, an example was given in which the image data 18 obtained by capturing an image using the imaging device 10 is itself passed from the photographer 14 to the recipient 26. In the second embodiment, an example will be described in which the image data 18 is edited by the photographer 14 or the like, and the edited image data 18 is passed to the recipient 26. In the second embodiment, the same components as those described in the first embodiment are denoted by the same reference numerals and their description will be omitted, and only differences from the first embodiment will be described.
[0144] 15, the image file creation process according to the second embodiment is realized by the processor 42 further operating as an editing unit 42F, in contrast to the image file creation process according to the first embodiment. The editing unit 42F executes an editing step, which is a step of editing the image data 18.
[0145] In the second embodiment, an example in which the editing process is performed by the imaging device 10 is given, but this is merely one example. For example, the editing process may be performed by a smart device, a personal computer, a server, or the like that is communicably connected to the imaging device 10.
[0146] 16 , the UI-based device 34 receives an editing instruction 92 from the photographer 14 or the like. The editing instruction 92 refers to, for example, an instruction regarding specific content for editing the image data 18. When the editing instruction 92 is received by the UI-based device 34, the editing unit 42F edits the image data 18 in accordance with the editing instruction 92.
[0147] The UI device 34 receives editor information 68E. The editor information 68E is information about an editor. An editor refers to a person who edits the image data 18. Examples of information about an editor include the name of the editor, the nickname of the editor, information indicating the location of the editor, or contact information for the editor. The editor may be the photographer 14 or a person other than the photographer 14.
[0148] The editing unit 42F includes editing-related information, which is information related to editing, in the related information 68. For example, in the second embodiment, the editing unit 42F includes editor information 68E received by the UI-based device 34 in the related information 68. Furthermore, in the same manner as the acquisition unit 42A acquired image capture time information 68B via the network 28 in the first embodiment, the editing unit 42F acquires editing time information 68F via the network 28 and includes the editing time information 68F in the related information 68. The editing time information 68F is information indicating the time when editing was performed on the image data 18. Examples of the time when editing was performed on the image data 18 include the time when editing of the image data 18 started or the time when editing of the image data 18 ended. Furthermore, the editing time information 68F may include information indicating the total time required to edit the image data 18.
[0149] Note that, although an example in which the editing instruction 92 and the editor information 68E are received by the UI device 34 has been given here, this is merely one example. For example, the editing instruction 92 or the editor information 68E may be provided to the editing unit 42F from an external device (e.g., a smart device, a personal computer, or a server) communicably connected to the imaging device 10. The editor information 68E may be stored in the NVM 44. In this case, the editing unit 42F may acquire the editor information 68E from the NVM 44 when editing of the image data 18 is performed.
[0150] 17 as an example, the associating unit 42B generates fifth reliability information 78E and sixth reliability information 78F, and includes the generated fifth reliability information 78E and sixth reliability information 78F in the reliability information 78. Furthermore, the associating unit 42B associates the fifth reliability information 78E with editor information 68E, and associates the sixth reliability information 78F with edit time information 68F.
[0151] The fifth reliability information 78E is information that can identify the source of the editor information 68E. In the second embodiment, the editor information 68E is information obtained by the editing unit 42F from the UI-based device 34. Therefore, in the second embodiment, information indicating that the editor information 68E was obtained from the UI-based device 34 is used as an example of the fifth reliability information 78E. The fact that such fifth reliability information 78E is associated with the editor information 68E means that the editor information 68E is not information obtained via the network 28.
[0152] In the second embodiment, the fifth reliability information 78E is automatically associated with the editor information 68E after the editing process in the same way that the acquisition process is automatically performed after the imaging process, in order to prevent a third party from creating false reliability information 78 and associating it with the editor information 68E.
[0153] The sixth reliability information 78F is information that can identify the source of the edit time information 68F. In the second embodiment, the edit time information 68F is information obtained via the network 28. Therefore, in the second embodiment, information indicating that the edit time information 68F was obtained via the network 28 is used as an example of the sixth reliability information 78F. The fact that such sixth reliability information 78F is associated with the edit time information 68F means that the edit time information 68F is information obtained via the network 28.
[0154] In the second embodiment, the sixth reliability information 78F is automatically associated with the editing time information 68F after the editing process in the same manner as the acquisition process is automatically executed after the imaging process.
[0155] The reason for this is to prevent a time lag in which a third party can create false reliability information 78 and associate it with the edit time information 68F.
[0156] 18 , the encryption unit 42C encrypts the editor information 68E and the edit time information 68F using a hash function 84 in a manner similar to the encryption (i.e., hashing) described in the first embodiment. As a result, an eleventh hash value 82E obtained by encrypting the editor information 68E and a twelfth hash value 82F obtained by encrypting the edit time information 68F are included in the encrypted information 82. The eleventh hash value 82E is associated with the fifth reliability information 78E, and the twelfth hash value 82F is associated with the sixth reliability information 78F.
[0157] In the encryption process, the encryption unit 42C generates timing information 94, which is information regarding the time when the 11th hash value 82E and the 12th hash value 82F were generated, and includes the timing information 94 in the second association information 80, similar to the timing information 86 in the first embodiment described above.
[0158] In the second embodiment, information generated using the edit time information 68F (see FIGS. 16 and 17) is used as an example of the time information 94. An example of the timing at which the time information 94 is generated is the timing at which encryption (here, hashing, as an example) of the related information 68 is completed.
[0159] The time information 94 includes information indicating that the eleventh hash value 82E and the twelfth hash value 82F were generated at the time when the image data 18 was edited, and edit time information 68F. Note that the time information 94 may also include information indicating the total time required to edit the image data 18.
[0160] The period information 94 may be the editing time information 68F itself. Alternatively, the period information 94 may be information indicating the time when the eleventh hash value 82E and the twelfth hash value 82F were actually completed. In this case, for example, the period information 94 may be acquired by the encryption unit 42C via the network 28 when the encryption of the editor information 68E and the editing time information 68F is completed, or may be acquired by the encryption unit 42C from a real-time clock built into the imaging device 10 when the encryption of the eleventh hash value 82E and the twelfth hash value 82F is completed.
[0161] In the second embodiment, a ninth hash value 88E and a tenth hash value 88F are generated as information included in the verification information 88 in a similar manner to the first embodiment in which a fifth hash value 88A, a sixth hash value 88B, a seventh hash value 88C, and an eighth hash value 88D are generated as information included in the verification information 88. The ninth hash value 88E is a hash value obtained by hashing the editor information 68E using the hash function 84, and the tenth hash value 88F is a hash value obtained by hashing the edit time information 68F using the hash function 84.
[0162] In the second embodiment, the ninth hash value 88E is compared with the eleventh hash value 82E, and the tenth hash value 88F is compared with the twelfth hash value 82F, in a manner similar to that of the comparison unit 58C according to the first embodiment. These comparison results are then handled by the execution unit 58D according to the first embodiment in a manner similar to that of the first embodiment.
[0163] An example of the flow of an image file creation process according to the second embodiment is shown in Figure 19. The flowchart shown in Figure 19 differs from the flowchart shown in Figure 13 in that steps ST21A to ST21E are inserted between steps ST20 and ST22. Here, the processes of steps ST21A to ST21E will be described.
[0164] 19 , the editing unit 42F determines whether the editing instruction 92 and the editor information 68E have been accepted by the UI-based device 34. If the editing instruction 92 and the editor information 68E have not been accepted by the UI-based device 34 in step ST21A, the determination is negative, and the image file creation process proceeds to step ST22. If the editing instruction 92 and the editor information 68E have been accepted by the UI-based device 34 in step ST21A, the determination is positive, and the image file creation process proceeds to step ST21B.
[0165] In step ST21B, the editing unit 42F edits the image data 18 acquired in step ST12 in accordance with the editing instruction 92 accepted by the UI device 34 in step ST21A. The editing unit 42F also generates editing time information 68F using information acquired via the network 28. The editing unit 42F then updates the related information 68 by including in the related information 68 the editor information 68E accepted by the UI device 34 in step ST21A and the editing time information 68F. After the processing of step ST21B is executed, the image file creation processing proceeds to step ST21C.
[0166] In step ST21C, the associating unit 42B associates the fifth reliability information 78E with the editor information 68E and associates the sixth reliability information 78F with the edit time information 68F, thereby updating the first association information 76. After the processing of step ST21C is executed, the image file creation processing proceeds to step ST21D.
[0167] In step ST21D, the encryption unit 42C generates an eleventh hash value 82E and a twelfth hash value 82F by encrypting the editor information 68E and the edit time information 68F included in the related information 68 using the hash function 84. After the processing of step ST21D is executed, the image file creation processing proceeds to step ST21E.
[0168] In step ST21E, the encryption unit 42C generates time information 94. Then, the encryption unit 42C updates the second association information 80 using the eleventh hash value 82E, the twelfth hash value 82F, the fifth reliability information 78E, the sixth reliability information 78F, and the time information 94. That is, the second association information 80 is updated by associating the fifth reliability information 78E with the eleventh hash value 82E, associating the sixth reliability information 78F with the twelfth hash value 82F, and associating the time information 94 with the encrypted information 82. After the processing of step ST21E is executed, the image file creation processing proceeds to step ST22.
[0169] As described above, in the second embodiment, the imaging device 10 edits the image data 18, and includes editing-related information (here, as an example, editor information 68E and editing time information 68F) in the related information 68. The editing-related information is encrypted. In the second embodiment, the editor information 68E is encrypted to generate an eleventh hash value 82E, and the editing time information 68F is encrypted to generate a twelfth hash value 82F. The eleventh hash value 82E and the twelfth hash value 82F are included in the encrypted information 82. In the second embodiment, the imaging device 10 includes time information 94 in the metadata 20. The time information 94 is information regarding the time when the eleventh hash value 82E and the twelfth hash value 82F were generated.
[0170] Therefore, for example, when a recipient 26 or the like receives an image file 16 from an editor (e.g., a photographer 14 or the like), the recipient 26 or the like can infer the validity of the time when the editing-related information was encrypted by referring to the time information 94 included in the metadata 20 of the image file 16. For example, if the recipient 26 or the like feels that the time when the editing-related information was encrypted is valid, the recipient 26 or the like can determine that the reliability of the editing-related information is high. Conversely, if the recipient 26 or the like feels that there is something abnormal about the time when the editing-related information was encrypted, the recipient 26 or the like can determine that the reliability of the editing-related information is low. In this way, by including the time information 94 in the metadata 20 of the image file 16, the security of the editing-related information can be increased.
[0171] The metadata 20 also includes reliability information 78 provided by the imaging device 10. The reliability information 78 includes fifth reliability information 78E and sixth reliability information 78F. The fifth reliability information 78E is information that can identify the source of the editor information 68E. The sixth reliability information 78F is information that can identify the source of the edit time information 68F.
[0172] Therefore, for example, when the recipient 26 or the like receives the image file 16 from an editor (for example, the photographer 14 or the like), the recipient 26 or the like can determine the level of reliability of the editing-related information by referring to the fifth reliability information 78E and the sixth reliability information 78F included in the metadata 20 of the image file 16. In this way, by including the fifth reliability information 78E and the sixth reliability information 78F in the metadata 20 of the image file 16, the security of the editing-related information can be improved.
[0173] Note that, in the second embodiment, an example is given in which the time information 86 and 94 are associated with the encryption information 82, but this is merely one example. For example, as shown in Fig. 20, the time information 86 may be individually associated with the first hash value 82A, the second hash value 82B, the third hash value 82C, and the fourth hash value 82D, and the time information 94 may be individually associated with the eleventh hash value 82E and the twelfth hash value 82F. The second association information 80 configured in this manner is stored in the metadata 20 in the same manner as in the first and second embodiments.
[0174] In this way, when the time information 86 and 94 exist, the encrypted information corresponding to the time information 86 and the encrypted information corresponding to the time information 94 can be stored together in the metadata 20. That is, the first hash value 82A, the second hash value 82B, the third hash value 82C, and the fourth hash value 82D corresponding to the time information 86 and the eleventh hash value 82E and the twelfth hash value 82F corresponding to the time information 94 can be stored together in the metadata 20. This makes it clear within the metadata 20 that the time information 86 corresponds to the first hash value 82A, the second hash value 82B, the third hash value 82C, and the fourth hash value 82D, and that the time information 94 corresponds to the eleventh hash value 82E and the twelfth hash value 82F. As a result, handling of the first hash value 82A, the second hash value 82B, the third hash value 82C, the fourth hash value 82D, the eleventh hash value 82E, the twelfth hash value 82F, and the timing information 86 and 94 becomes easier.
[0175] In the second embodiment described above, an example was given in which the editing process is performed in the imaging device 10, but the technology of the present disclosure is not limited to this. For example, as shown in FIG. 21 , the editing process may be performed by an editing device 100 used by an editor 98 at an editing site 96. An example of the editing device 100 is a device with the same specifications as the receiving device 24. The editing device 100 is connected to the network 28 in the same manner as the receiving device 24. For example, an image file 16 is transmitted from the imaging device 10 to the editing device 100 via the network 28, and the image file 16 edited by the editing device 100 is transmitted to the receiving device 24 via the network 28.
[0176] When the editing process is performed by the editing device 100 in this manner, the image file creation process may be performed in a distributed manner by the imaging device 10 and the editing device 100. For example, the image file creation process shown in Fig. 13 is performed by the imaging device 10, and the processes of steps ST21A to ST26 included in the image file creation process shown in Fig. 19 are performed by the editing device 100. In this case, for example, the destination of the image file 16 sent by the imaging device 10 is the editing device 100, and the destination of the edited image file 16 sent by the editing device 100 is the receiving device 24. Furthermore, when the editing process is performed by the editing device 100, the image file receiving process may be performed by the editing device 100.
[0177] In the second embodiment described above, an example was given in which the editor information 68E and the edit time information 68F do not include the unacceptable information 74, but this is merely one example, and the editor information 68E or the edit time information 68F may include the unacceptable information 74 in the same manner as in the first embodiment described above.
[0178] In the second embodiment, an example in which the time information 94 is included as is in the second association information 80 has been described, but this is merely one example. For example, the time information 94 may also be encrypted in the same manner as the association information 68 is encrypted, and the encrypted time information 94 may be included in the second association information 80. In this case, the time information 94 before encryption may be included as part of the association information 68 in the metadata 20 of the image file 16.
[0179] [Third Embodiment] In the above-described embodiments, an example was given in which the encryption information 82 was included in the metadata 20, but in this third embodiment, an example will be described in which information obtained by further encrypting the encryption information 82 is included in the metadata 20. Note that in this third embodiment, the same components as those described in the above-described embodiments are denoted by the same reference numerals and their description will be omitted, and only differences from the above-described embodiments will be described.
[0180] 22 , an encryption unit 42C according to the third embodiment differs from the encryption unit 42C described in the above embodiments in that it generates third association information 102 instead of the second association information 80. The third association information 102 differs from the second association information 80 in that it includes re-encrypted information 104 instead of the encrypted information 82. The re-encrypted information 104 is an example of the “first encrypted information” according to the technology of the present disclosure, and is generated based on the encrypted information 82 (e.g., the first hash value 82A, the second hash value 82B, the third hash value 82C, and the fourth hash value 82D).
[0181] The encryption unit 42C generates a private key 106 and also generates a public key 108 that corresponds to the private key 106. The public key 108 is acquired by the transmission unit 42E. The transmission unit 42E transmits the public key 108 to a storage device 110 on the network 28. The storage device 110 receives the public key 108 transmitted from the transmission unit 42E and stores the received public key 108. An example of the storage device 110 is a server or a personal computer communicatively connected to the network 28.
[0182] The transmitter 42E provides the attachment unit 42D with a URL 112 that can identify the location on the network 28 where the public key 108 is stored (for example, the location where the public key 108 is stored by the storage device 110).
[0183] The encryption unit 42C generates re-encrypted information 104 by encrypting the encrypted information 82 using the private key 106. For example, the re-encrypted information 104 is information obtained by encrypting a first hash value 82A, a second hash value 82B, a third hash value 82C, a fourth hash value 82D, an eleventh hash value 82E, and a twelfth hash value 82F using the private key 106. Here, the first hash value 82A, the second hash value 82B, the third hash value 82C, the fourth hash value 82D, the eleventh hash value 82E, and the twelfth hash value 82F are examples of "first hash values" according to the technology of the present disclosure.
[0184] 23 as an example, similar to the above-described embodiments, the attachment unit 42D creates the image file 16 by attaching the metadata 20 to the image data 18. In the third embodiment, the attachment unit 42D creates the image file 16 using the image data 18, the related information 68, the hash function 84, the third association information 102, and the URL 112.
[0185] In the third embodiment, the metadata 20 includes the associated information 68 and the hash function 84. Also, in the third embodiment, the metadata 20 includes the third association information 102 instead of the second association information 80. Furthermore, in the third embodiment, the metadata 20 includes the URL 112 as information required to acquire the public key 108.
[0186] 24 as an example, the comparison unit 58C extracts the re-encryption information 104 from the third association information 102 included in the metadata 20 of the image file 16. The comparison unit 58C also acquires the public key 108 via the network 28 using the URL 112 included in the metadata 20 of the image file 16. That is, the comparison unit 58C identifies the location on the network 28 where the public key 108 is stored (for example, the location where the public key 108 is stored by the storage device 110) from the URL 112, and acquires the public key 108 from the identified location.
[0187] The comparison unit 58C generates encrypted information 82 (e.g., a first hash value 82A, a second hash value 82B, a third hash value 82C, a fourth hash value 82D, an eleventh hash value 82E, and a twelfth hash value 82F) by decrypting the re-encrypted information 104 using the public key 108. Here, the encrypted information 82 obtained by decrypting the re-encrypted information 104 using the public key 108 is “first information” according to the technology of the present disclosure. Furthermore, the first hash value 82A, the second hash value 82B, the third hash value 82C, the fourth hash value 82D, the eleventh hash value 82E, and the twelfth hash value 82F included in the encrypted information 82 obtained by decrypting the re-encrypted information 104 using the public key 108 are examples of “second hash values” according to the technology of the present disclosure.
[0188] The comparison unit 58C compares the verification information 88 with the encrypted information 82 in the same manner as in the above-described embodiments. That is, the comparison unit 58C compares the fifth hash value 88A, the sixth hash value 88B, the seventh hash value 88C, the eighth hash value 88D, the ninth hash value 88E, and the tenth hash value 88F with the first hash value 82A, the second hash value 82B, the third hash value 82C, the fourth hash value 82D, the eleventh hash value 82E, and the twelfth hash value 82F.
[0189] As described above, in the third embodiment, the comparison unit 58C compares the verification information 88 with the encrypted information 82 generated based on the re-encrypted information 104. This makes it possible to obtain the same effects as those of the above embodiments.
[0190] Furthermore, in the third embodiment, the re-encrypted information 104 is information generated based on the encrypted information 82 obtained by hashing the related information 68 and the private key 106. In other words, the re-encrypted information 104 can be said to be information obtained by double encryption of the related information 68.
[0191] The re-encrypted information 104 is included in the metadata 20 of the image file 16. The image file 16 is then received and handled by the recipient 26, the editor 98, or the like in the same manner as in the above-described embodiments. The information that is compared with the verification information 88 by the comparison unit 58C in the receiving device 24 used by the recipient 26 or the editing device 100 used by the editor 98 is the encrypted information 82 generated by decrypting the re-encrypted information 104 with the public key 108. Therefore, compared to when the related information 68 is simply hashed, it is possible to determine whether the related information 68 has been altered while ensuring a high level of security.
[0192] Furthermore, in the third embodiment, the comparison unit 58C obtains the public key 108 from the network 28 by using the URL 112 in the metadata 20 of the image file 16. Therefore, the public key 108 can be easily obtained by an authorized user who handles the image file 16 (for example, the recipient 26 or the editor 98).
[0193] In the third embodiment, the URL 112 is included in the metadata 20, but this is merely an example, and the public key 108 may be included in the metadata 20. In this case, an authorized user who handles the image file 16 (for example, the recipient 26 or the editor 98) can quickly obtain the public key 108.
[0194] [Fourth Embodiment] In the above-described embodiments, an example was given in which the related information 68 included photographer information 68A, imaging time information 68B, imaging device location information 68C, subject location information 68D, editor information 68E, and editing time information 68F, but in this fourth embodiment, an example will be described in which the related information 68 also includes a thumbnail image 114, as shown in Fig. 25. Note that in this fourth embodiment, the same components as those described in the above-described embodiments are assigned the same reference numerals and their description will be omitted, and only differences from the above-described embodiments will be described.
[0195] 25 as an example, the acquisition unit 42A generates a thumbnail image 114 by thumbnailizing (i.e., reducing) the image data 18. Then, the acquisition unit 42A includes the thumbnail image 114 in the related information 68. The thumbnail image 114 is an example of a "thumbnail image" according to the technology of the present disclosure.
[0196] The associating unit 42B generates the first association information 76. In the first association information 76, the thumbnail image 114 is associated with seventh reliability information 78G.
[0197] The seventh reliability information 78G is information that can identify the source of the thumbnail image 114. In the fourth embodiment, the thumbnail image 114 is information acquired through internal processing by the processor 42 (i.e., the thumbnail generation process of the image data 18 by the acquisition unit 42A). Therefore, in the fourth embodiment, information indicating that the thumbnail image 114 was acquired through internal processing by the processor 42 is used as an example of the seventh reliability information 78G. The fact that such seventh reliability information 78G is associated with the thumbnail image 114 means that the thumbnail image 114 is not information acquired through the network 28.
[0198] In addition, the seventh reliability information 78G is automatically associated with the thumbnail image 114 after the thumbnail image 114 is acquired through internal processing by the processor 42 in a similar manner to the association between the first reliability information 78A and the photographer information 68A.
[0199] 26 , the encryption unit 42C generates fourth association information 116. The fourth association information 116 includes image encryption information 118, seventh reliability information 78G, and time information 120. The encryption unit 42C generates the image encryption information 118 by encrypting the thumbnail image 114 in the same manner as in the above-described embodiments, and includes the generated image encryption information 118 in the fourth association information 116. The encryption unit 42C also includes the above-described second association information 80 or third association information 102 in the fourth association information 116.
[0200] The image encryption information 118 is associated with seventh reliability information 78G and time information 120. The time information 120 includes information indicating that the thumbnail image 114 was generated and information indicating the time at which the thumbnail image 114 was generated.
[0201] As described above, in the fourth embodiment, the fourth association information 116 including the image encryption information 118 (i.e., information obtained by encrypting the thumbnail image 114) is included in the metadata 20 of the image file 16 in the same manner as in the above embodiments. In other words, the attachment unit 42D creates the image file 16 by attaching the fourth association information 116 including the image encryption information 118 to the image data 18 as the metadata 20. This increases the security of the thumbnail image 114.
[0202] In the fourth embodiment, an example was described in which the related information 68 included the thumbnail image 114, but the technology of the present disclosure is not limited to this, and text information may be included in the related information 68. In this case, the text information is encrypted in the same manner as in the above embodiments and included in the metadata 20 of the image file 16, thereby improving the security of the text information.
[0203] Furthermore, the thumbnail image 114 may be an image that does not change in accordance with changes (e.g., editing by the editing unit 42F) to the image data 18. In this case, the security of the thumbnail image 114 that does not change in accordance with changes to the image data 18 can be improved.
[0204] In the above-described fourth embodiment, an example was given in which the fourth association information 116 includes image encryption information 118 in which the thumbnail image 114 is encrypted, but the technology of the present disclosure is not limited to this. For example, as shown in FIG. 27 , the encryption unit 42C may generate fifth association information 122, and include image encryption information 124 in the fifth association information 122. The image encryption information 124 is information generated by encrypting the image data 18. The image encryption information 124 is an example of "second encryption information" according to the technology of the present disclosure.
[0205] The fifth association information 122 also includes the second association information 80, the third association information 102, or the fourth association information 116 described above. The fifth association information 122 is associated with eighth reliability information 78H and time information 86. The eighth reliability information 78H is information that can identify the source of the image data 18. The eighth reliability information 78H includes information that indicates that imaging was performed to obtain the image data 18, and information equivalent to the imaging time information 68B (see FIG. 5 ).
[0206] In this way, the fifth association information 122 including the image encryption information 124 (i.e., information obtained by encrypting the image data 18) is included in the metadata 20 of the image file 16 in the same manner as in the above-described embodiments. In other words, the attachment unit 42D creates the image file 16 by attaching the fifth association information 122 including the image encryption information 124 to the image data 18 as the metadata 20. This makes it possible to improve the security of the image data 18.
[0207] [Other Modifications] In the above embodiments, the image file creation process is executed by the computer 30 in the imaging device 10, but the technology of the present disclosure is not limited to this. For example, as shown in FIG. 28 ,
[0208] The image file creation process may be performed by a computer 128 in the external device 126. An example of the computer 128 is a server computer for a cloud service. The computer 128 is an example of an "information creation device" and a "computer" according to the techniques of the present disclosure.
[0209] 28, the computer 128 includes a processor 130, an NVM 132, and a RAM 134. The NVM 132 stores an image file creation program 50.
[0210] The imaging device 10 requests the external device 126 to execute an image file creation process via the network 28. In response to this, the processor 130 of the external device 126 reads the image file creation program 50 from the NVM 132 and executes the image file creation program 50 on the RAM 134. The processor 130 performs the image file creation process in accordance with the image file creation program 50 executed on the RAM 134. The processor 130 then provides the processing result obtained by executing the image file creation process to the imaging device 10 via the network 28.
[0211] 28 shows an example of an embodiment in which the external device 126 executes the image file creation process, but this is merely one example. For example, the image file creation process may be distributed between the imaging device 10 and the external device 126, or may be distributed among a plurality of devices including the imaging device 10 and the external device 126.
[0212] 28 illustrates an example in which the processor 130 of the external device 126 performs the image file creation process, but the technology of the present disclosure is not limited to this. For example, in the same manner as the processor 130 performs the image file creation process, the processor 130 may be made to perform the image file reception process in response to a request from the receiving device 24.
[0213] In the above embodiments, the image file creation program 50 is stored in the NVM 44, but the technology of the present disclosure is not limited to this. For example, the image file creation program 50 may be stored in a solid state drive (SSD), a USB memory, a magnetic tape, or the like.
[0214] The image file creation program 50 may be stored in any portable, computer-readable, non-transitory storage medium. The image file creation program 50 stored in the non-transitory storage medium is installed in the imaging device 10. The processor 42 executes the image file creation process in accordance with the image file creation program 50.
[0215] In addition, the image file creation program 50 may be stored in a storage device such as another computer or server device connected to the imaging device 10 via a network, and the image file creation program 50 may be downloaded and installed in the imaging device 10 in response to a request from the imaging device 10.
[0216] It is not necessary to store the entire image file creation program 50 in a storage device such as another computer or server device connected to the imaging device 10, or in the NVM 44; only a portion of the image file creation program 50 may be stored therein.
[0217] Furthermore, although the imaging device 10 shown in FIG. 3 has a built-in computer 30, the technology of the present disclosure is not limited to this. For example, the computer 30 may be provided outside the imaging device 10.
[0218] In the above embodiments, examples in which the technology of the present disclosure is realized by a software configuration are described, but the technology of the present disclosure is not limited to this, and devices including an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or a PLD (Programmable Logic Device) may also be applied. Furthermore, a combination of a hardware configuration and a software configuration may also be used.
[0219] The hardware resources for executing the image file creation process described in each of the above embodiments can be various processors, as listed below. Examples of processors include a CPU, which is a general-purpose processor that functions as a hardware resource for executing the image file creation process by executing software, i.e., a program. Examples of processors include dedicated electronic circuits, such as FPGAs, PLDs, or ASICs, which are processors with a circuit configuration designed specifically for executing specific processes. Each processor has built-in or connected memory, and each processor uses the memory to execute the image file creation process.
[0220] The hardware resource that executes the image file creation process may be configured with one of these various processors, or may be configured with a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Also, the hardware resource that executes the image file creation process may be a single processor.
[0221] Examples of a system using a single processor include: a first configuration in which one processor is configured using a combination of one or more CPUs and software, and this processor functions as a hardware resource that executes the image file creation process; a second configuration in which a processor is used to implement the functions of an entire system, including multiple hardware resources that execute the image file creation process, on a single IC (Integrated Circuit) chip, as typified by SoCs (System-on-a-Chips); and in this way, the image file creation process is implemented using one or more of the above-mentioned various processors as hardware resources.
[0222] Furthermore, the hardware structure of these various processors can be, more specifically, electronic circuits that combine circuit elements such as semiconductor devices. The image file creation process described above is merely an example. It goes without saying that unnecessary steps may be deleted, new steps may be added, or the processing order may be rearranged, without departing from the spirit of the process.
[0223] Although the image file creation process performed by the imaging device 10 has been mentioned above, the same can be said for the image file creation process performed by the receiving device 24 .
[0224] The above-described description and illustrations are a detailed explanation of the parts related to the technology of the present disclosure and are merely an example of the technology of the present disclosure. For example, the above description of the configuration, functions, actions, and effects is an explanation of an example of the configuration, functions, actions, and effects of the parts related to the technology of the present disclosure. Therefore, it goes without saying that unnecessary parts may be deleted, new elements may be added, or replacements may be made to the above-described description and illustrations within the scope of the gist of the technology of the present disclosure. Furthermore, to avoid confusion and facilitate understanding of the parts related to the technology of the present disclosure, the above-described description and illustrations omit explanations of common technical knowledge that do not require particular explanation to enable the implementation of the technology of the present disclosure.
[0225] In this specification, the grammatical concept of "A or B" includes not only the concept of "either one of A or B," but also a concept synonymous with "at least one of A and B." In other words, "A or B" includes the meaning that it may be only A, only B, or a combination of A and B. Furthermore, in this specification, the same concept as "A or B" is also applied when three or more things are expressed by connecting them with "or."
[0226] All publications, patent applications, and technical standards mentioned in this specification are herein incorporated by reference to the same extent as if each individual publication, patent application, or technical standard was specifically and individually indicated to be incorporated by reference.
[0227] The following additional notes are provided regarding the above-described embodiments.
[0228] (Supplementary Note 1) An information creation method including: an acquisition step of acquiring related information related to image data; an encryption step of generating first encrypted information by encrypting the related information; and an attachment step of attaching the first encrypted information to the image data as attached information, wherein the attached information includes time information regarding when the first encrypted information was generated or reliability information.
[0229] (Supplementary Note 2) An information creation method including: an acquisition step of acquiring related information related to image data; an encryption step of generating first encrypted information by encrypting the related information; and an attachment step of directly or indirectly attaching incidental information to the image data, wherein the incidental information includes the first encrypted information, and timing information regarding when the first encrypted information was generated, or reliability information.
[0230] (Supplementary Note 3) The information creation method according to Supplementary Note 1 or Supplementary Note 2, wherein the reliability information is information relating to whether or not the related information is information obtained through a network.
[0231] (Supplementary Note 4) The information creation method according to any one of Supplementary Note 1 to Supplementary Note 3, wherein the incidental information includes a plurality of pieces of first encrypted information having different time information.
[0232] (Supplementary Note 5) The information creating method according to any one of Supplementary Notes 1 to 4, wherein the additional step includes a creating step of creating an image file including the related information and the first encrypted information.
[0233] (Supplementary Note 6) The information creation method according to any one of Supplementary Notes 1 to 5, wherein the related information includes information indicating that modification or deletion is not permitted.
[0234] (Supplementary Note 7) The information creation method according to any one of Supplementary Notes 1 to 6, wherein the related information includes text information or thumbnail images.
[0235] (Supplementary Note 8) The information creation method according to Supplementary Note 7, wherein the thumbnail image is an image that does not change in accordance with changes in the image data.
[0236] (Supplementary Note 9) The information creation method according to any one of Supplementary Note 1 to Supplementary Note 8, wherein the encryption step generates first encrypted information by hashing the associated information, and the associated information includes a hash function used for the hashing.
[0237] (Supplementary Note 10) The information creation method according to Supplementary Note 9, including: a generation step of generating verification information using related information and a hash function; and a comparison step of comparing the verification information with first encrypted information or first information generated based on the first encrypted information.
[0238] (Supplementary Note 11) When the first information is generated based on the first encrypted information, the first encrypted information is information generated based on a first hash value obtained by hashing the related information and a private key, and the first information is a second hash value generated based on the first encrypted information and a public key. This is an information creation method described in Supplementary Note 10.
[0239] (Supplementary Note 12) The information creation method according to Supplementary Note 11, wherein the additional information includes a public key or information required to acquire the public key.
[0240] (Supplementary Note 13) The information creation method according to any one of Supplementary Notes 1 to 12, wherein the encryption step is automatically performed after the acquisition step.
[0241] (Supplementary Note 14) The information creation method according to Supplementary Note 13, wherein the acquiring step is automatically performed after the image data is acquired.
[0242] (Supplementary Note 15) The information creation method according to Supplementary Note 14, further comprising an imaging step of acquiring image data by performing imaging, wherein the acquiring step is automatically executed after the imaging step.
[0243] (Supplementary Note 16) The information creation method according to any one of Supplementary Notes 1 to 15, wherein the related information includes photographer information, imaging time information, imaging device position information, or subject position information.
[0244] (Supplementary Note 17) The information creation method according to any one of Supplementary Notes 1 to 16, wherein the encryption step generates second encrypted information by encrypting the image data, and the attachment step attaches the second encrypted information to the image data as attached information.
[0245] (Supplementary Note 18) The information creation method according to any one of Supplementary Notes 1 to 17, wherein the attaching step indirectly attaches the attached information to the image data by recording the attached information on a recording medium and recording access information to the attached information in an image file including the image data.
[0246] (Supplementary Note 19) An image file including additional information of image data, wherein the additional information includes first encrypted information obtained by encrypting related information related to the image data, and time information or reliability information regarding when the first encrypted information was generated, and the additional information includes the related information.
Claims
1. An acquisition step of acquiring associated information related to the image data; An encryption step of generating first encrypted information obtained by encrypting the associated information; An attachment step of directly or indirectly attaching attachment information to the image data, wherein the attachment information includes the first encrypted information and time information regarding the time when the first encrypted information was generated An information creation method.
2. The attachment information includes a plurality of the first encrypted information with different time information The information creation method according to claim 1.
3. The attachment step includes a creation step of creating an image file including the associated information and the first encrypted information The information creation method according to claim 1.
4. The associated information includes information indicating that modification or deletion is not allowed The information creation method according to claim 1.
5. The associated information includes text information or a thumbnail image The information creation method according to claim 1.
6. The thumbnail image is an image that is not changed as the image data is changed The information creation method according to claim 5.
7. In the encryption step, the first encrypted information is generated by hashing the associated information, and the attachment information includes a hash function used for the hashing The information creation method according to claim 1.
8. A generation step of generating verification information using the associated information and the hash function; A comparison step of comparing the verification information with the first encrypted information or first information generated based on the first encrypted information The information creation method according to claim 7.
9. When the first information is generated based on the first encrypted information, the first encrypted information is information generated based on a first hash value obtained by hashing the associated information and a secret key, and the first information is a second hash value generated based on the first encrypted information and a public key The information creation method according to claim 8.
10. The attachment information includes the public key or information required to obtain the public key The information creation method according to claim 9.
11. The encryption step is automatically executed after the acquisition step The information creation method according to claim 1.
12. The acquisition step is automatically executed after the image data is acquired The information creation method according to claim 11.
13. including an imaging step of acquiring the image data by performing imaging The acquisition step is automatically executed after the imaging step The information creation method according to claim 12
14. The related information includes imager information, imaging time information, imaging device position information, or subject position information The information creation method according to claim 1
15. The encryption step generates second encrypted information obtained by encrypting the image data The attachment step attaches the second encrypted information to the image data as the attachment information The information creation method according to claim 1
16. The attachment step indirectly attaches the attachment information to the image data by recording the attachment information on a recording medium and recording access information to the attachment information in an image file including the image data The information creation method according to claim 1
17. An image file including attachment information of image data, The attachment information is First encrypted information obtained by encrypting related information related to the image data, and Including timing information regarding the timing when the first encrypted information was generated Image file
18. Comprising a processor, The processor is Obtains related information related to the image data, Generates first encrypted information obtained by encrypting the related information, Attaches the attachment information directly or indirectly to the image data, The attachment information includes the first encrypted information and timing information regarding the timing when the first encrypted information was generated Information creation device
19. A program for causing a computer to execute a process, The process is An acquisition step of obtaining related information related to the image data, An encryption step of generating first encrypted information obtained by encrypting the related information, and An attachment step of directly or indirectly attaching attachment information to the image data, and includes The attachment information includes the first encrypted information and timing information regarding the timing when the first encrypted information was generated Program