Determination device and determination method

The tampering determination device addresses the challenge of distinguishing real from counterfeit data by using analog domain changes and machine learning to verify data authenticity, achieving precise tampering detection and ensuring data integrity.

WO2025164366A1PCT designated stage Publication Date: 2025-08-07SONY GROUP CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/001312
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-01
Filing Date
2025-01-17
Publication Date
2025-08-07

AI Technical Summary

Technical Problem

Existing methods struggle to accurately distinguish between real phenomenon data and counterfeit data, particularly in fields requiring high assurance of data authenticity such as journalism, court cases, and politics, as current AI discriminators cannot effectively detect tampering post-A/D conversion.

Method used

A tampering determination device that utilizes changes imparted in the analog domain during data sensing, employing modulation and noise superposition, combined with machine learning models like deep neural networks and diffusion models, to verify the authenticity of data by restoring original information through digital demodulation and noise separation.

Benefits of technology

Enables unprecedentedly high-precision determination of data tampering by ensuring the detection of changes in the analog domain, preventing unauthorized deciphering and ensuring the authenticity of data, even in high-dimensional, high-quality formats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025001312_07082025_PF_FP_ABST
    Figure JP2025001312_07082025_PF_FP_ABST
Patent Text Reader

Abstract

A determination device according to the present technology is provided with a falsification determination unit that performs falsification determination using, as an encryption key, a change given in a process up to an analog region when sensing a physical phenomenon as alteration determination of the target data.
Need to check novelty before this filing date? Find Prior Art

Description

Judgment device, judgment method

[0001] The present technology relates to a determination device and a method thereof, and in particular to a technology for determining whether or not target data is data that has been forged by a third party.

[0002] In recent years, it has become difficult to distinguish whether digital data representing predetermined content such as images or sounds is data obtained by actually sensing a physical phenomenon (hereinafter referred to as "real phenomenon data"). For example, with the recent development of AI (Artificial Intelligence) technology, it has become difficult to distinguish counterfeit data, so-called generated data, from real phenomenon data. Another form of counterfeiting is the falsification of real phenomenon data.

[0003] The following non-patent literature can be cited as related prior art: Non-patent literature 1 discloses a technique for obtaining generated data using a GAN (Generative Adversarial Network).

[0004] “Generative Adversarial Networks”: Ian J. Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron Courville, Yoshua Bengio ([1406.2661] Generative Adversarial Networks (arxiv.org))

[0005] There are cases where digital data is required to be certified as not being forged. For example, in fields such as journalism, court cases, science, and politics, where it is necessary to ensure that the phenomena represented by digital data are real phenomena, it is necessary to be able to appropriately prove that the data is not forged.

[0006] In the GAN described above, the "Discriminator" determines the authenticity of data generated by the "Generator," but there is no guarantee that this "Discriminator" can determine the authenticity of data that has been tampered with without using AI.

[0007] The present technology has been developed in light of the above circumstances, and aims to achieve unprecedentedly high-precision determination of data tampering.

[0008] The determination device according to the present technology includes a tamper determination unit that performs tamper determination of target data using, as a cryptographic key, changes imparted in the process up to the analog domain when sensing a physical phenomenon. The "changes" imparted in the process up to the analog domain in sensing as described above are difficult for a third party to decipher.

[0009] 1 is a diagram for explaining terms used in describing an authenticity verification method as an embodiment. FIG. 1 is a diagram for explaining an overview of an authenticity verification method as an embodiment. FIG. 1 is an explanatory diagram of a configuration example of a change removal unit as a first example. FIG. 2 is an explanatory diagram of learning of an AI model used by the change removal unit as a first example. FIG. 2 is an explanatory diagram of a configuration example of a change removal unit as a second example. FIG. 3 is an explanatory diagram of a configuration example of an actual phenomenon verification unit as a first example. FIG. 4 is an explanatory diagram of an example of a configuration of an actual phenomenon verification unit as a second example. FIG. 5 is an explanatory diagram of the first configuration example. FIG. 6 is an explanatory diagram of a configuration example in which changes are added both before and after digital conversion. FIG. 7 is an explanatory diagram of the second configuration example. FIG. 8 is an explanatory diagram of the third configuration example. FIG. 9 is a block diagram showing an example of the configuration of an imaging device corresponding to the sensing device in the first configuration example. FIG. 10 is a diagram showing an example of the configuration of an optical filter. FIG. 11 is a diagram explaining the operation of an optical filter when there is one aperture. FIG. 12 is a diagram explaining the operation of an optical filter when there are multiple apertures. FIG. 13 is an explanatory diagram of a sensing image obtained when an optical filter is used. FIG. 14 is an explanatory diagram of processing performed by a calculation unit of an imaging device corresponding to the first configuration example. FIG. 15 is a block diagram showing an example of the hardware configuration of an information processing device. FIG. 16 is an explanatory diagram of processing performed by the information processing device in the first configuration example. 10 is an explanatory diagram of a specific configuration example corresponding to the second configuration example. FIG. 11 is an explanatory diagram of a specific configuration example corresponding to the third configuration example. FIG. 12 is an explanatory diagram of an optical system using a lens. FIG. 13 is an explanatory diagram of the action of an optical filter in the case of an optical system using a lens. FIG. 14 is an explanatory diagram of a configuration example as a second alternative example. FIG. 15 is an explanatory diagram of a unique pattern sound signal generated by a unique pattern generation unit in the second alternative example. FIG. 16 is an explanatory diagram of a configuration example as a third alternative example. FIG. 17 is an explanatory diagram of a specific configuration example of a data using device in the third alternative example. FIG. 18 is an explanatory diagram of a configuration example as a fourth alternative example. FIG. 19 is an explanatory diagram of processing performed by a calculation unit of an imaging device in the fourth alternative example. FIG. 19 is an explanatory diagram of processing performed by an information processing device in the fourth alternative example. FIG. 19 is an explanatory diagram of processing performed by a server device in the fourth alternative example.

[0010] Hereinafter, embodiments of the present technology will be described in the following order: <1. Overview of the authenticity verification method as an embodiment> [1-1. Terminology] [1-2. Method overview] <2. Various configuration examples> [2-1. First configuration example] [2-2. Second configuration example] [2-3. Third configuration example] <3. Specific configuration example> <4. Configuration examples as alternative examples> [4-1. First alternative example] [4-2. Second alternative example] [4-3. Third alternative example] [4-4. Fourth alternative example] <5. Modified examples> <6. Summary of embodiments> <7. The present technology>

[0011] <1. Overview of the Authenticity Verification Method as an Embodiment> [1-1. Terminology] First, the terminology used in describing the authenticity verification method as an embodiment will be described with reference to Fig. 1. The embodiment deals with two concepts: "real phenomenon verification," which verifies whether or not the target data is generated data, that is, whether or not the target data is data obtained by sensing an actual phenomenon, and "tampering determination," which determines whether or not the target data is data that has been tampered with, for example, by processing sensed data.

[0012] 1 shows the process of sensing a physical phenomenon (i.e., physical quantity conversion: specifically, conversion from phenomenon to electrical signal), and as shown in the figure, the region before sensing in the process of sensing a physical phenomenon is referred to as the "phenomenon region." Furthermore, the region after sensing of the physical phenomenon is referred to as the "signal region." As shown in the figure, the signal region consists of an "analog region," where the signal obtained by sensing exists as an analog signal, and a "digital region," where the signal in the analog region is converted to a digital signal (A / D).

[0013] Here, in this specification, "generated data" refers to data that is not obtained by sensing a real phenomenon (a phenomenon that actually occurs) but is artificially generated to imitate a real phenomenon. Also, in this specification, the term "real phenomenon data" is used as an antonym of "generated data." In other words, "real phenomenon data" refers to data that indicates a real phenomenon, unlike generated data.

[0014] Data tampering is carried out in the digital domain in FIG. 1, and can be said to be possible immediately after A / D conversion.

[0015] [1-2. Method Overview] Here, in order to verify whether or not the data is from an actual phenomenon, the following conditions must be met: - The history of the process up to the analog domain mentioned above must be detected - No tampering has occurred after digital conversion

[0016] Regarding the first of these conditions, if a process involving a process could be simulated by digital computation, it would not be a proof that the process was involved. Therefore, a sufficient condition is that it is guaranteed that the process history cannot be simulated by digital computation.

[0017] Furthermore, the latter type of tampering can generally be verified using existing tamper detection methods that use hash values, such as the following: - The data provider supplies the target data along with a hash value calculated for the target data using a publicly known hash function. - The data user compares the target data with the hash value calculated using the same hash function, and determines that there has been no tampering if the two match. The reliability of the guarantee provided by this method is based on the fact that it is difficult and unlikely to create the same hash value from different data.

[0018] However, the above-described method using hash values ​​can only prove that there has been no tampering with the digital information at a certain point in time, and it cannot prove that there has been no tampering immediately after A / D conversion.

[0019] From the above, the problem to be solved in this embodiment is to provide a device that satisfies the following conditions: Process history up to the analog domain can be left as digital information. The presence or absence of process history can be detected by digital calculation. Process history simulated by digital calculation is not detected as history. History of tampering can be detected from data immediately after A / D conversion.

[0020] Here, methods for recording the history of the process up to sensing can be achieved by subjecting the physical phenomenon to modulation that can be demodulated by digital calculation, or by superimposing separable noise, etc. Generally speaking, it is sufficient to give the physical phenomenon a "change" that can be removed by digital calculation.

[0021] For example, if the target data is image data, it is conceivable to use an optical filter to impart a "change" to the light of the subject being sensed. Alternatively, if the target data is sound data, it is conceivable to impart a "change" to the sound picked up by a microphone by mixing in another sound.

[0022] In this case, the "change" to be applied to the physical phenomenon is not limited to a change in the phenomenon domain. It is also possible to utilize characteristics inherent to the sensing device, provided that these characteristics remain when digitized. For example, in the case of an image, the characteristics of the optical elements of a camera (lens distortion, transmittance distribution of a transmission filter, diffusion characteristics of a diffusion filter) can be cited. In the case of sound, the sensitivity characteristics of a microphone used for sensing (frequency characteristics of sensitivity, angle of arrival characteristics) can be cited. Regarding the superposition of noise, for example, in the case of an image, when an element having a hole (opening) is used as an optical element for applying a "change," diffuse reflection occurring within the hole can be used as an inherent characteristic.

[0023] When recording the history of the above modulation and noise superposition in sensing data, it is important to be able to restore the original information through the corresponding digital demodulation and noise separation. This can be achieved by performing digital demodulation and noise separation using demodulation and noise separation parameters calculated from the parameters used for modulation and noise superposition. In other words, based on the parameters used for modulation and noise superposition, an inverse function that has the opposite effect to the modulation and noise superposition is derived, and the original information can be restored by performing digital demodulation and noise separation using this inverse function.

[0024] It is also possible to use machine learning to remove "variations" such as modulation and noise superposition. Specifically, a large amount of data with "variations" (hereinafter referred to as "variation-added data") and normal data without "variations" are prepared, and the parameters of a deep learning model are trained to convert the variation-added data into normal data. Regarding the deep neural network (DNN) used in deep learning, various autoencoders (e.g., variational autoencoder (VAE), U-type autoencoder (UNet), etc.) composed of blocks such as multilayer perceptron (MLP) and convolutional network (CNN), and generative adversarial network (GAN), as well as relatively early models such as a vision transformer (ViT) with an attention mechanism and a gate mechanism, a gated multilayer perceptron (gMLP), a diffusion model (DDPM) simulating a stochastic differential equation, etc. may be used. Alternatively, it is possible to use a diffusion model to perform mutual estimation of color maps (Multi-phase FZA lensless imaging via diffusion model - NASA / ADS (harvard.edu)), or a hybrid model with a physical model ([1908.11502] Learned reconstructions for practical mask-based lensless imaging (arxiv.org)).

[0025] 2 is a diagram for explaining an overview of an authenticity verification method according to an embodiment. The authenticity verification method according to an embodiment is realized by the elements shown in the diagram, which are a change applying unit 1, a sensor 2, a change removing unit 3, and an actual phenomenon verifying unit 4. The change applying unit 1 applies a change in the process up to the analog domain when sensing a physical phenomenon. The sensor 2 senses the physical phenomenon.

[0026] The change removal unit 3 removes from the input data the change imparted by the change imparting unit 1. The real phenomenon verification unit 4 verifies whether the target data is real phenomenon data based on the change imparted data, which is the sensing data to which the change has been imparted by the change imparting unit 1, and the change-removed data, which is the data from which the change has been removed by the change removal unit 3. Specifically, the real phenomenon verification unit 4 determines whether the difference between the change imparted data and the change-removed data is within a predetermined range corresponding to the change imparted by the change imparting unit.

[0027] The content of the change imparted by the change imparting unit 1 is known to authorized sensing data providers, such as manufacturers or administrators of sensing devices, and therefore the difference between the change-imparted data and the change-removed data is also known. Therefore, as described above, it is possible to realize a configuration for determining whether the difference between the verification target data and the reference input data is within a predetermined range corresponding to the change imparted by the change imparting unit 1. By making this determination, it becomes possible to determine whether the verification target data is data in which the predetermined change imparted by the change imparting unit 1 has been applied to the physical phenomenon to be sensed, or whether the predetermined change has been removed from the change-imparted data. In other words, it becomes possible to determine whether the verification target data is actual phenomenon data (data obtained by sensing an actual phenomenon) rather than generated data. Furthermore, as described above, being able to determine whether the target data is data in which the predetermined change imparted by the change imparting unit 1 has been applied to the physical phenomenon to be sensed, or whether the predetermined change has been removed from the change-imparted data, also makes it possible to determine whether the sensing data has been altered between the time of this determination and the time of this determination. Therefore, with the above configuration, it is possible to simultaneously verify whether the target data is actual phenomenon data and whether the target data is tamper-free data.

[0028] If the content of the alteration (the parameters and methods of the alteration) is deciphered by a third party other than the legitimate sensing data provider or data user, the third party may be able to create counterfeit alteration-added data by digitally calculating the alteration. Specifically, this may allow the third party to create alteration-added data for generated data. It is possible that malicious individuals belonging to the sensing data provider or data user may attempt to decipher the content of the alteration. In this case, the third party may attempt to decipher the content of the alteration based on the changes in the information before and after the alteration. To make it difficult to decipher and simulate the content of the alteration, the following measures may be taken: - Making it possible to obtain only either the alteration-added data or the alteration-removed data; - Even if both the alteration-added data and the alteration-removed data can be obtained, increasing the burden required for deciphering the data to make it more difficult.

[0029] Regarding the latter, for example, measures can be taken, such as knowing the principles of adding and removing changes but not knowing the parameters, or knowing both the principles and parameters but requiring time for calculations and the development of calculation methods. For example, by making the target data high-dimensional, high-speed time-resolved data, it is possible to obfuscate the content of the added changes by preventing digital processing from being completed within the time resolution width (clock). Specifically, it is possible to make the target data high-quality video, high-frame-rate video, or high-quality sound data. Regarding the latter, it is also possible to take measures to add predetermined changes in the digital domain. In this case, the verification side removes the changes added in the digital domain before using it for verification. In order to decipher the content of the changes added in the analog domain, it is also necessary to decipher the content of the changes added in the digital domain, which increases the difficulty of deciphering. Note that an example of adding changes in the digital domain in this way will be described again later.

[0030] Here, as a measure to prevent the verification from being fraudulently established, it is conceivable to attach information indicating that the parameters used for variation removal are genuine parameters. A digital signature scheme can be used for this information. Alternatively, the parameters used for variation removal may satisfy a constraint that details are not disclosed. In this case, by making it difficult to satisfy the constraint even if the parameters are forged, forgery can be detected. For example, the constraint can be encoding using a low-density parity check matrix or satisfying the encoding constraint of encryption with asymmetric strength (e.g., encryption such as public key encryption).

[0031] An example configuration of the change removal unit 3 will be described with reference to FIGS. 3 to 5. FIG. 3 is an explanatory diagram of an example configuration of a change removal unit 3 (hereinafter referred to as "change removal unit 3-1") as a first example. The change removal unit 3-1 is an example using an AI model. In other words, as shown in FIG. 4, change-added data is used as learning input data, and non-change-added data to which "change" has not been added is used as training data. By performing machine learning using a learner with an architecture such as the CNN exemplified above, an AI model is generated that outputs change-removed data in which "change" has been removed from the input data, and this is used as the change removal unit 3-1.

[0032] 5 is an explanatory diagram of a second example of the configuration of the variation removal unit 3 (hereinafter referred to as "variation removal unit 3-2"). The variation removal unit 3-2 obtains variation-removed data by performing the inverse operation of the variation addition unit 1. Specifically, based on parameters used to add variations such as modulation or noise superposition, an inverse function that brings about an effect opposite to the addition of the variations is derived, and variation-removed data (i.e., data that restores the original information when sensing is performed without adding variations) is obtained by digital calculation using the inverse function.

[0033] 6 and 7 are explanatory diagrams of exemplary configurations of the real phenomenon verification unit 4. FIG. 6 is an explanatory diagram of an exemplary configuration of a first example of a real phenomenon verification unit 4 (hereinafter referred to as the "real phenomenon verification unit 4-1"). The real phenomenon verification unit 4-1 calculates the difference between the change-removed data and the change-added data, and determines whether the calculated difference corresponds to the "difference within a predetermined range" using a threshold value. As shown in the figure, the real phenomenon verification unit 4-1 includes a difference calculation unit 41 and a threshold determination unit 42. The difference calculation unit 41 calculates the difference between the change-removed data and the change-added data. For example, if an image sensor is used as the sensor 2 (i.e., if the sensing data = image data), the difference to be calculated is a difference in an element of the image, such as a difference in brightness value, a difference in frequency components (e.g., sharpness), or a difference in color. Furthermore, if the sensing data = sound data, for example, the difference in an element of the sound, such as a difference in volume or a difference in frequency components, is calculated.

[0034] The threshold determination unit 42 determines whether the difference between the change-removed data and the change-imparting data calculated by the difference calculation unit 41 is within a "predetermined range of difference" based on a preset threshold. As described above, the content of the "change" imparted by the change imparting unit 1 is known to the authorized sensing data provider, and the difference between the change-imparting data and the change-removed data can also be known. The threshold determination unit 42 determines whether the difference between the change-removed data and the change-imparting data is within a "predetermined difference" using a threshold corresponding to such a known "difference." For example, two thresholds (an upper allowable value and a lower allowable value) indicating an acceptable range for the known "difference" can be used as the threshold corresponding to the known "difference." In this case, the threshold determination unit 42 determines whether the difference between the change-removed data and the change-imparting data is within a range indicated by the thresholds. Alternatively, the determination of whether the difference between the change-removed data and the change-added data is "within a specified range" can be made by determining whether the difference between the change-removed data and the change-added data is greater than or equal to a certain threshold value, or less than or equal to a certain threshold value, in which case only one threshold value will be used.

[0035] 7 is an explanatory diagram of a second example of the configuration of a real phenomenon verification unit 4 (hereinafter referred to as "real phenomenon verification unit 4-2"). The real phenomenon verification unit 4-2 calculates the difference between the change-removed data and the change-added data, as the difference in the likelihood of the data being a real phenomenon (real phenomenon likelihood). As shown in the figure, the real phenomenon verification unit 4-2 has a real phenomenon likelihood calculation unit 43 that calculates the real phenomenon likelihood for the change-added data, a real phenomenon likelihood calculation unit 44 that calculates the real phenomenon likelihood for the change-removed data, a difference calculation unit 45 that calculates the difference between these real phenomenon likelihoods, and a threshold determination unit 46 that performs a determination based on the difference calculated by the difference calculation unit 45 and a threshold.

[0036] For the actual phenomenon likelihood calculation units 43 and 44, it is conceivable to use an AI model that has been machine-learned to output the actual phenomenon likelihood for input data. For example, it is conceivable to use the authenticity discriminator portion of the GAN.

[0037] Specifically, we use the value obtained by subtracting the bias from the input (logit) to the final sigmoid function σ(x) (logistic function) of the authenticity classifier that has been trained using only real data (corresponding to the "true" class of two classes of true and false). This value is obtained by subtracting the bias from the input (logit) to the final sigmoid function σ(x) (logistic function) of the authenticity classifier that has been trained using only real data (corresponding to the "true" class of two classes of true and false). When the function of the final output layer is written as follows, n-1 That's why, wx n-1 +b is the logit, w is the weight, and b is the bias. In addition, x 0 is the input data, x n is the final output, f n-1 is the composition function for the layer before the final layer.

[0038] In terms of probability, x n is the input x 0 = Approximate probability of the source class to which x belongs (true: real phenomenon, false: computer), wx n-1 +b is the input to the final output, and corresponds to the logarithmic odds (logarithmic probability ratio) for the above probability. n , log probability logx n , log odds σ -1 (x n ) (= wx n-1+ b) can be used, but the bias term b is biased to the authenticity ratio at the time of learning. Therefore, if you want to subtract the influence, you can use wx n-1 = σ -1 (x n ) - b is used. In terms of Bayesian probability, wx n-1 is the log likelihood ratio, b is the log prior probability ratio, wx n-1 +b corresponds to the logarithmic posterior probability ratio. The value of the likelihood of a real phenomenon without bias is the logarithmic likelihood ratio wx n-1 (=σ -1 (x n )-b), as well as likelihood σ(wx n-1 ) and logarithmic likelihood log(wx n-1 ) etc. may also be used.

[0039] The threshold determination unit 46 uses a threshold to determine the difference in likelihood of a real phenomenon between the change-removed data and the change-added data calculated by the difference calculation unit 45. The determination of the difference in likelihood of a real phenomenon may also be performed using two thresholds indicating an allowable range of the difference. In this case, the threshold determination unit 46 determines whether the difference in likelihood of a real phenomenon between the change-removed data and the change-added data is within the range indicated by the thresholds. Alternatively, the threshold determination unit 46 may determine whether the difference in likelihood of a real phenomenon between the change-removed data and the change-added data is equal to or greater than a certain threshold, or whether it is equal to or less than a certain threshold.

[0040] It is also possible to adopt a configuration in which the real phenomenon verification unit 4 performs a determination process for verification based on both the difference value calculated by the difference calculation unit 41 shown in Fig. 6 and the difference value calculated by the difference calculation unit 45 shown in Fig. 7. In other words, a determination is made taking into account not only the difference in elements but also the difference in real phenomenon likelihood as the difference between the change-removed data and the change-added data.

[0041] Furthermore, the specific methods for verifying real phenomena are not limited to those exemplified above. For example, the following methods can be considered: (a) Calculation of a realistic evaluation value using an autoencoder (b) Calculation of a realistic evaluation value using supervised learning (c) Authenticity determination based on the change pattern of the "realism" evaluation value before and after data restoration (d) Authenticity determination based on statistical learning of the same pattern (e) Authenticity determination based on a hypothesis-testing evaluation of the same pattern

[0042] The above (i) is an example of using the likelihood calculated by a variational autoencoder to evaluate the authenticity. The variational autoencoder converts the true value μ(x) and variance (logarithmic variance logv(x)) contained in the input data x into two outputs x of the final layer. n , y n From these, the likelihood is This value is used as the likelihood of the actual phenomenon.

[0043] (b) above is an example of acquiring a model used for authenticity assessment using simple supervised learning. Compared to unsupervised learning such as VAE or GAN, supervised learning has the advantage of making it easier to handle fakeness. Here, authenticity and fakeness are different from those in GAN and are the quality of the data itself. Therefore, the data used for learning is data with good quality as an index of the data domain, and the "fake" class is data with poor quality. The method of assessing authenticity using a trained authenticity classifier is largely the same as the explanation of the authenticity classifier mentioned above.

[0044] The above (a) is an example in which the authenticity of data is determined from the magnitude of the authenticity index of the data before and after restoration. First, it is not unnatural to expect the following correspondence: Actual data: pre-restoration data index < post-restoration data index However, authenticity determination under these conditions is insufficient. The reason is that even with fake data, the post-restoration data index may improve. Therefore, for example, the distribution of post-restoration index values ​​for fake data is evaluated in advance, and the upper limit of that distribution is used as a threshold to determine the authenticity as follows: Actual data: pre-restoration data index < threshold < post-restoration data index minimum value Fake data: post-restoration data index < threshold In this case, false positives are not inevitable, but because the number of false positives for real data increases, the application is designed to accept cases in which it is acceptable to miss many real data.

[0045] The above (2) assumes an example in which the threshold is acquired through statistical learning in order to reduce false positives that depend on the threshold. A simple example is to set the threshold to the midpoint between the average of the restored data indexes of the real data and the average of the restored data indexes of the fake data.

[0046] The above (ho) refers to expressing the recorded facts in terms of "confidence" rather than "proving" them. For example, if the above (ni) is used, there will be cases where false data is mistakenly judged as real data, so it will not be proven that "the data is not fake data." Therefore, if the distribution of the above index values ​​is further investigated and the class to which the index values ​​belong is determined as a probability (posterior probability), then this can be used to test hypotheses using confidence. For example, the mean and variance of the real data class and the fake data class can be calculated as μ r , σ 2 r , μ f , σ 2 f Then, the probability that the input x is real data or false data is calculated as follows: Using this result, the probability (confidence) that the input is real data is p r Alternatively, by using a test expression based on these probability values, the hypothesis that the input is false data may be rejected (estimated to be real data) at a 95% confidence interval.

[0047] <2. Various Configuration Examples> [2-1. First Configuration Example] The authenticity verification method of the embodiment is applicable to a case where a data supplier supplies sensing data to a data user for use, and the authenticity of the sensing data is determined. Below, various examples of configurations that can be adopted by a data supplier device and a data user device will be described, assuming that there are both a data supplier device and a data user device.

[0048] 8A and 8B are explanatory diagrams of a first configuration example. Fig. 8A shows a configuration example of a sensing device 10 managed by a data supplier, and Fig. 8B shows a configuration example of a data using device 20 that is expected to use sensing data generated by the sensing device 10.

[0049] 8A, the sensing device 10 includes a change applying unit 1, a sensor 2, a change removing unit 3, and an output unit 5. The specific configuration of the change removing unit 3 can be, for example, the configuration of either of the change removing units 3-1 and 3-2 described above.

[0050] The output unit 5 outputs the change-removed data obtained by the change removal unit 3 to the outside of the sensing device 10, and also outputs the change-added data sensed by the sensor 2 to the outside of the sensing device 10. Hereinafter, the change-removed data will be denoted by the symbol "Dr", and the change-added data will be denoted by the symbol "Dv".

[0051] In this example, the change-removed data Dr, from which the change imparted by the change imparting unit 1 has been removed, is supplied to the data user as the data to be used. This is to prevent the data user from handling data whose contents are unclear if the change imparted by the change imparting unit 1 is large and the change imparted data Dv with the change imparted is used as the data to be used.

[0052] The output unit 5 outputs not only the variation-removed data Dr but also the variation-added data Dv so that the data user can verify an actual phenomenon using the variation-removed data Dr and the variation-added data Dv. In this example, the variation-added data Dv output by the output unit 5 is stored in a server device 25 shown in Fig. 8B. The server device 25 is a server device managed by the data supplier.

[0053] The output unit 5 performs a process of adding link information to the variation-removed data Dr as data to be used. This link information is for indicating the location of variation-imparted data Dv required for actual phenomenon verification when a data user performs actual phenomenon verification on the variation-removed data Dr. In this example, information indicating the storage location information (e.g., URI: Uniform Resource Identifier) ​​of the variation-imparted data Dv in the server device 25 is used.

[0054] The output unit 5 outputs the variation-removed data Dr to which the link information has been added. The variation-removed data Dr output by the output unit 5 is thus supplied to the data using device 20, and various forms of supply are conceivable. For example, the output unit 5 may supply the variation-removed data Dr to the data using device 20 via wired or wireless communication. Alternatively, as a form of Internet distribution, the variation-removed data Dr output by the output unit 5 may be stored in a server device on a network, and the data using device 20 may access the server device 25 to obtain the variation-removed data Dr. Furthermore, the variation-removed data Dr output by the output unit 5 may be recorded on a removable recording medium such as a CD (Compact Disc) or USB (Universal Serial Bus) memory, and the data using device 20 may obtain the variation-removed data Dr via the removable recording medium.

[0055] 8B , the data using device 20 includes a data using unit 6, a raw data acquiring unit 7, and an actual phenomenon verifying unit 4. The data using unit 6 uses the variation-removed data Dr supplied as data to be used. Various forms of use by the data using unit 6 are conceivable. For example, if the variation-removed data Dr is image data, display processing is conceivable, and if it is sound data, sound output processing is conceivable. Further conceivable usage processing includes recording to a recording medium, data processing / editing, and transfer to another device.

[0056] Here, in the figure, an example is shown in which the change-removed data Dr (including link information) output by the sensing device 10 to the data usage unit 6 is supplied as the data to be used, but counterfeit data (including link information) by a third party could be supplied as the data to be used.

[0057] The original data acquisition unit 7 acquires data in accordance with the link information added to the variation-removed data Dr (data to be used). If the link information added to the data to be used is link information output by the sensing device 10, the original data acquisition unit 7 acquires, from the server device 25, the variation-added data Dv corresponding to the variation-removed data Dr supplied as data to be used.

[0058] The real phenomenon verification unit 4 performs real phenomenon verification processing based on the data supplied as the data to be used (the variation-removed data Dr if there is no forgery damage) and the data acquired by the original data acquisition unit 7 (the variation-added data Dv if there is no forgery damage), by determining whether the difference between the two is within the aforementioned "difference within a predetermined range." The specific configuration of the real phenomenon verification unit 4 can be, for example, the configuration of either of the real phenomenon verification units 4-1 or 4-2 described above. If the difference between the two is within the "difference within a predetermined range," it is proven that the data supplied as the data to be used (the data to be verified) is real phenomenon data and has not been tampered with.

[0059] 8, the variation-added data Dv stored in the server device 25 is used as, so to speak, reference data for calculating the difference from the variation-removed data Dv when the actual phenomenon verification unit 4 performs actual phenomenon verification of the variation-removed data Dv, which is the data to be used. In this sense, the variation-added data Dv in this case can be called "reference input data" in the actual phenomenon verification.

[0060] 8, the data user can obtain both the variation-removed data Dr and the variation-imparted data Dv. As mentioned above, if both the variation-removed data Dr and the variation-imparted data Dv can be obtained, the content of the variations imparted by the variation imparting unit 1 becomes easily decipherable. Therefore, as mentioned above, a measure can be considered to increase the difficulty of deciphering the content of the variations by adopting a configuration in which predetermined variations are imparted in the digital domain as well, in other words, a configuration in which variations are imparted both before and after digital conversion.

[0061] FIG. 9 shows an example configuration in which changes are applied both before and after such digital conversion. As shown, a digital change applying unit 81 is added to the sensing device 10 ( FIG. 9A ), and a digital change removing unit 82 is added to the data using device 20 ( FIG. 9B ). The digital change applying unit 81 applies a digital domain change, which is a predetermined change in the digital domain, to the reference input data (here, the change-removed data Dv). Specifically, in this example, the digital change applying unit 81 applies the digital domain change to the change-applied data Dv, which is the sensing data obtained by the sensor 2. Examples of digital changes applied by the digital change applying unit 81 include random dimensional shuffling of multidimensional data. For example, if the sensing data is captured image data, it is possible to randomly swap the positions of at least a portion of multiple pixels in the captured image data.

[0062] In the data using device 20, the digital change removal unit 82 removes digital domain changes from the input data. Specifically, in this example, the digital change removal unit 82 performs a process of removing digital domain changes from the input data, which is the change-added data Dv acquired by the original data acquisition unit 7. The process of removing digital domain changes involves, for example, canceling the shuffled state achieved by the random dimensional shuffle described above (returning the data to its original position and order).

[0063] In this case, the actual phenomenon verification section 4 inputs the variation-added data Dv obtained by the digital variation removal section 82 after the digital domain variation has been removed as reference input data for verifying the actual phenomenon.

[0064] [2-2. Second Configuration Example] Figure 10 shows configuration examples of a sensing device 10A (Figure 10A) and a data using device 20A (Figure 10B) as a second configuration example. The sensing device 10A shown in Figure 10A differs from the sensing device 10 shown in Figure 8A in that it includes an actual phenomenon verification unit 4 and an output unit 5A instead of the output unit 5. As shown in the figure, in the sensing device 10A, the actual phenomenon verification unit 4 determines whether the difference between the variation-added data Dv obtained by the sensor 2 and the variation-removed data Dr obtained by the variation removal unit 3 is a "predetermined difference."

[0065] The output unit 5A is similar to the output unit 5 in that it outputs the variation-removed data Dr and the variation-imparted data Dv to which link information has been added, but differs from the output unit 5 in that it adds a guarantee tag to the variation-removed data Dr in accordance with the verification results by the actual phenomenon verification unit 4. Specifically, when the output unit 5A obtains a determination result by the actual phenomenon verification unit 4 that the difference between the variation-imparted data Dv and the variation-imparted data Dr obtained by the variation removal unit 3 is a "predetermined difference," the output unit 5A generates a guarantee tag indicating that the data to be used (the variation-imparted data Dr in this example) to be output is not forged (is actual phenomenon data and is not tampered with), and adds the guarantee tag to the data to be used. Note that the data to be used can also be the variation-imparted data Dv, in which case the output unit 5A adds a guarantee tag to the variation-imparted data Dv.

[0066] 10B, the data usage device 20A differs from the data usage device 20 shown in FIG. 8B in that it is equipped with a data usage unit 6A instead of the data usage unit 6. The data usage unit 6A differs from the data usage unit 6 in that it references a guarantee tag when using supplied target data for use. For example, the data usage unit 6A uses supplied target data for use only if a guarantee tag is attached. This makes it possible to prevent counterfeit data from being used by mistake.

[0067] Here, the data usage device 20A is also equipped with an original data acquisition unit 7 and an actual phenomenon verification unit 4, which makes it possible to verify the authenticity of the data to be used even if the guarantee tag is counterfeit.

[0068] In the above, an example was given in which the data supplier added a guarantee tag to the data to be used, but it is also possible to add information indicating the difference between the likelihood of an actual phenomenon in the variation-added data Dv and the likelihood of an actual phenomenon in the variation-removed data Dr to the data to be used. Here, adding information indicating the difference in the likelihood of an actual phenomenon is not limited to adding a difference value between the likelihoods of both, but also includes adding information indicating the likelihoods of both.

[0069] Alternatively, it is also conceivable to add information to the data to be used that indicates that the variation-removed data Dr has a higher likelihood of real phenomenon than the variation-added data Dv.

[0070] 11 shows a third configuration example of a sensing device 10B (FIG. 11A) and a data using device 20B (FIG. 11B). The third configuration example adds a function to determine whether data has been tampered with in the digital domain after A / D conversion.

[0071] The sensing device 10B shown in Fig. 11A differs from the sensing device 10A shown in Fig. 10A in that it includes an output unit 5B instead of the output unit 5A. Like the output unit 5A, the output unit 5B outputs variation-removed data Dr (including link information and guarantee tags) and variation-added data Dv, but differs from the output unit 5A in that it generates and outputs tampering detection data for the data to be used (the variation-removed data Dr in this example). Specifically, the output unit 5B calculates a hash value h(s) using a known hash function for the data input as the data to be used, and outputs the hash value h(s) together with the data to be used (the variation-removed data Dr).

[0072] 11B, the data using device 20B differs from the data using device 20A in that a data tampering determination unit 8 has been added. The data tampering determination unit 8 determines whether the supplied use data (verification target data) has been tampered with based on the tampering detection data. Specifically, the data tampering determination unit 8 determines whether the use target data has been tampered with using the hash value h(s) supplied together with the use target data. More specifically, the data tampering determination unit 8 calculates a hash value for the supplied use target data using the same hash function as used by the sensing device 10B, and determines whether the hash value matches the hash value h(s) supplied together with the use target data. This makes it possible to determine whether the use target data has been tampered with in the digital domain after A / D conversion.

[0073] In the first to third configuration examples described above, the assumed data of the use data is the variation-removed data Dr. However, for example, if the changes imparted by the variation imparting unit 1 are imperceptible to humans, the variation-imparted data Dv may be used as the use data. In this case, in each of the first to third configuration examples, the output unit (5, 5A, 5B) adds link information to the variation-imparted data Dv rather than the variation-removed data Dr. That is, in this case, the variation-removed data Dr is stored in the server device 25, and information indicating the location of the variation-removed data Dr stored in the server device 25 is added as link information to the variation-imparted data Dv as the use data. Meanwhile, in this case, the data using device (20, 20A, 20B) performs the same process as described in FIGS. 8 to 11 , i.e., the original data acquisition unit 7 acquires data in accordance with the link information, and the actual phenomenon verification unit 4 performs a determination process using the use data and the data acquired by the original data acquisition unit 7 as inputs. In this case, the data usage device may be equipped with a change removal unit 3, and the change removal unit 3 may remove changes from the supplied change-added data Dv to obtain change-removed data Dr, which may be used by the data usage unit 6.

[0074] Even if the assumed data for the data to be used is the variation-added data Dv as described above, the data user can obtain both the variation-removed data Dr and the variation-added data Dv, making it easier to decipher the changes made by the variation adding unit 1. Therefore, even in this case, it is possible to adopt a configuration in which variations are added both before and after digital conversion. Specifically, in this case, the reference input data for verifying the actual phenomenon is the variation-removed data Dr, so the sensing device adds the digital domain changes to the variation-removed data Dr, and the data using device removes the digital domain changes from the variation-removed data Dr acquired by the raw data acquisition unit 7 from the server device 25.

[0075] 3. Specific Configuration Examples> Regarding the first to third configuration examples described above, specific configuration examples corresponding to the case where sensing data=image data will be described.

[0076] First, a specific configuration example corresponding to the first configuration example will be described with reference to Fig. 12 to Fig. 19. Fig. 12 is a block diagram showing a configuration example of an imaging device 50 corresponding to the sensing device 10 in the first configuration example. As shown in the figure, the imaging device 50 includes an optical filter 51, an image sensor 52, a calculation unit 53, and a communication unit 54. The optical filter 51 corresponds to the change imparting unit 1, and the image sensor 52 corresponds to the sensor 2.

[0077] The optical filter 51 applies a predetermined change to the subject light before it is received by the image sensor 52 .

[0078] Fig. 13 is a diagram showing an example of the configuration of the optical filter 51. In this example, it is assumed that the imaging device 50 is a camera in a form in which an imaging lens is omitted, and that subject light is received by the image sensor 52 after passing through the optical filter 51 having the light-shielding pattern shown in Fig. 13.

[0079] In this example, the optical filter 52 is made of a plate-like member, and the presence or absence of holes (openings) is determined for each cell region formed by dividing the surface into a grid, so that incident light is changed in a predetermined pattern. In this example, the optical filter 52 is created according to parameters that indicate the light blocking (e.g., "1") or light transmitting (e.g., "0") pattern for each cell region. In this example, the shape of the opening is rectangular in a plan view. However, the shape of the opening may be other than rectangular, such as circular.

[0080] The function of the optical filter 52 will be described with reference to FIGS. 14 and 15 . FIG. 14 illustrates the function when there is one aperture, and FIG. 15 illustrates the function when there are multiple apertures. As shown in FIG. 14 , when there is one aperture, subject light passing through the single aperture is focused on the sensor surface. This can be said to be an image formation pattern similar to that of a so-called pinhole camera. When there are multiple apertures, as in FIG. 15 , multiple subject images are formed on the sensor surface by the light passing through each aperture. The image formation positions of these multiple subject images on the sensor surface differ depending on the position of the aperture through which they passed. Therefore, the image sensor 52 receives light from an image in which multiple subject images, each displaced from one another, are superimposed. Therefore, the sensed image obtained in this case is a blurred image in which the edges of the subject are blurred.

[0081] For reference, Figure 16 shows an example of the original image when sensing is performed without applying changes using the optical filter 52 (Figure 16A), and an example of an image as the change-applied data Dv obtained when sensing is performed after applying changes using the optical filter 52 (Figure 16B).

[0082] For reference, the operation when optical filter 52 is used will be explained using mathematical formulas. For example, consider an optical system in which the object plane is flat and parallel to both the aperture and the sensor, as shown in Figure 15. When the distance from the aperture to the object is long enough to be independent of the location of the aperture or sensor, and the size of the sensor and aperture is smaller than the size of the object plane, the luminance distribution on the object plane can be written as g(p).

[0083] Consider the case where the transmittance distribution of the filter surface can be written as f(u) regardless of the angle of incidence. The amount of light that reaches a certain point x on the sensor through the filter is equal to the sum of the luminance g(p) seen from the aperture as f(h(x,p)) when the filter is projected onto the object surface as seen from point x, multiplied by the filter transmittance f(h(x,p)), for all light sources p.

[0084] Here, the condition for the three points x, p, u=h(x, p) to be on the same ray is bu=cp+ax (c=ba), (b^-=b -1 ). Note that "b^-" means adding an overbar to b. Similarly, "^-" below means adding an overbar to the immediately preceding sign. If the integral variable is changed from p to u, (c^-=c -1 ). When ac^-<<1, we obtain the following result of the convolution integral:

[0085] From [Equation 7], we can see that the image I(x) on the sensor is the convolution integral of the image g(-ac^-x), which is an inverted and reduced version of the subject image g(x), and the filter transmittance distribution f(u). Here, because -ac^- is set to a small value in the optical system settings, the convolution range of the convolution integral becomes relatively large, resulting in a large blur that makes it impossible to recognize what the original image was.

[0086] Although an element that imparts a change according to a fixed pattern has been exemplified here as an element for imparting a change to the subject light (i.e., performing spatial light modulation), it is also possible to use an element in which the spatial light modulation pattern is variable, such as an SML (Spatial Light Modulator).Furthermore, the pattern of the change to be imparted is not limited to a light blocking / transmitting pattern, and may be a pattern in which at least different transmittances are defined for different locations.

[0087] In FIG. 12 , the image sensor 52 is configured as, for example, a CCD (Charge Coupled Device) type image sensor or a CMOS (Complementary Metal Oxide Semiconductor) type image sensor, and has a pixel array portion in which a plurality of pixels that perform photoelectric conversion are arranged two-dimensionally, and performs A / D conversion on the electrical signal obtained for each pixel to obtain captured image data.

[0088] In the imaging device 50, an image sensor 52, a calculation unit 53, and a communication unit 54 are connected via a bus BS, and are capable of performing data communication with one another via the bus BS.

[0089] The calculation unit 53 is configured with a microcomputer having, for example, a CPU (Central Processing Unit), a ROM (Read Only Memory), and a RAM (Random Access Memory), and the CPU performs various processes according to programs stored in the ROM, thereby performing overall control of the imaging device 50.

[0090] The communication unit 54 performs communication processing with external devices via a transmission path such as the Internet, and communication with various devices via wired / wireless communication, bus communication, etc. In particular, in the present embodiment, the communication unit 54 is configured to be able to perform data communication with an information processing device 60 (described later) corresponding to the data using device 20 and a device corresponding to the server device 25 described above.

[0091] 17 , in the imaging device 50, the calculation unit 53 performs the processing described above as the variation removal unit 3 and the output unit 5. Specifically, it performs the processing described above as the variation removal unit 3 and the output unit 5 in the sensing device 10 described above in FIG.

[0092] Fig. 18 is a block diagram showing an example of the hardware configuration of an information processing device 60, which corresponds to the data using device 20 shown in Fig. 8. As shown in Fig. 18, the information processing device 60 includes a CPU 61, a ROM 62, and a RAM 63. The CPU 61 functions as an arithmetic processing unit that performs various processes, and executes the various processes in accordance with a program stored in the ROM 62 or a program loaded from the storage unit 69 into the RAM 63. The RAM 63 also stores data and the like necessary for the CPU 61 to execute the various processes, as appropriate.

[0093] The CPU 61, ROM 62, and RAM 63 are interconnected via a bus 64. An input / output interface (I / F) 65 is also connected to this bus 64.

[0094] An input unit 66 consisting of operators and operation devices is connected to the input / output interface 65. For example, the input unit 66 may be various operators and operation devices such as a keyboard, a mouse, keys, a dial, a touch panel, a touch pad, a remote controller, etc. The input unit 66 detects user operations, and the CPU 61 interprets signals corresponding to the input operations.

[0095] A display unit 67, such as an LCD (Liquid Crystal Display) or an organic EL (Electro-Luminescence) panel, and an audio output unit 68, such as a speaker, are connected integrally or separately to the input / output interface 65. The display unit 67 is used to display various types of information, and is configured as a display device provided in the housing of the information processing device 60, for example.

[0096] The display unit 67 displays images for various image processing, moving images to be processed, etc. on the display screen based on instructions from the CPU 61. The display unit 67 also displays various operation menus, icons, messages, etc., i.e., GUI (Graphical User Interface), based on instructions from the CPU 61.

[0097] A storage unit 69 and a communication unit 70 can be connected to the input / output interface 65. The storage unit 69 is configured by a hard disk drive (HDD) or a solid state drive (SSD), and stores various types of information.

[0098] The communication unit 70 performs communication processing via a transmission path such as the Internet, and communication with various devices via wired / wireless communication, bus communication, etc. In particular, in the case of this embodiment, the communication unit 70 is capable of performing data communication with the imaging device 50 described above via the communication unit 54, and data communication with the server device 25 described above.

[0099] A drive 71 is also connected to the input / output interface 65 as required, and a removable recording medium 72 such as a memory card or optical disk is appropriately attached thereto.

[0100] The drive 71 makes it possible to read data files such as programs used in various processes from a removable recording medium 72. The read data files are stored in a storage unit 69, and images and sounds contained in the data files are output on a display unit 67 and an audio output unit 68. Furthermore, the computer programs and the like read from the removable recording medium 72 are installed in the storage unit 69 as necessary.

[0101] Here, the information processing device 60 is not limited to being configured as a single computer device as shown in Fig. 18, but may be configured as a system of multiple computer devices. The multiple computer devices may be systemized using a LAN (Local Area Network) or the like, or may be located in a remote location using a VPN (Virtual Private Network) or the like using the Internet or the like. The multiple computer devices may include computer devices as a server group (cloud) available through a cloud computing service.

[0102] As shown in FIG. 19, in an information processing device 60, a CPU 61 performs the processes of the data using unit 6, the original data acquiring unit 7, and the actual phenomenon verifying unit 4 described in FIG. 8B.

[0103] Here, when the sensing data is image data, the actual phenomenon verification unit 4 may perform a judgment process based on the sharpness of the image. It can be said that the variation removal unit 3 can restore a blurry image to a clear image. Therefore, sharpness, an index of image clarity, can be used to determine the actual phenomenon verification. There are multiple methods for calculating sharpness and their values, each of which differs. For example, a calculation formula that directly expresses the concept is a statistical quantity such as the average or variance of the absolute value of the gradient across the entire image. However, the commonly used Laplacian filter uses a value corresponding to the variance of the quadratic gradient (convexity / concavity) as sharpness. Furthermore, this value varies significantly depending on the amount of edges in the actual image. However, according to this embodiment, the regular variation removal unit 3 improves sharpness, but without the regular variation removal unit 3, even if sharpness is improved, it will only be within the range of variation. Therefore, for example, a determination of whether or not an image is a realization may be made by determining whether the sharpness after variation removal has improved by more than 3σ compared to the sharpness before variation removal (the average variance (σ-squared) of the gradient or quadratic gradient). In this case, it is more effective to combine likelihood judgment as a judgment for verifying the actual phenomenon.

[0104] Next, a specific configuration example corresponding to the second configuration example will be described. In this case, the configurations of the imaging device 50 and the information processing device 60 are the same as those described above in Figures 12 and 18, so duplicate explanations will be avoided. However, in the configuration corresponding to the second configuration example, for the sake of distinction, the imaging device 50 will be referred to as imaging device 50A, the calculation unit 53 will be referred to as calculation unit 53A, the information processing device 60 will be referred to as information processing device 60A, and the CPU 61 will be referred to as CPU 61A.

[0105] In the case of the second configuration example, as shown in FIG. 20A, a calculation unit 53A in an imaging device 50A performs the processes of the variation removal unit 3, the real phenomenon verification unit 4, and the output unit 5A described above in FIG. 10A.

[0106] Also, as shown in FIG. 20B, in the information processing apparatus 60A, the CPU 61A performs the processing as the data usage unit 6A described in FIG. 10B, and the processing as the original data acquisition unit 7 and the actual phenomenon verification unit 4.

[0107] A specific configuration example corresponding to the third configuration example will be described. In this case as well, since the configurations of the imaging apparatus 50 and the information processing apparatus 60 are the same as those described in FIGS. 12 and 18 above, duplicate explanations will be avoided. Also, for the purpose of distinguishing from other configuration examples, the imaging apparatus 50 is denoted as the imaging apparatus 50B, the arithmetic unit 53 is denoted as the arithmetic unit 53A, the information processing apparatus 60 is denoted as the information processing apparatus 60B, and the CPU 61 is denoted as the CPU 61B.

[0108] When corresponding to the third configuration example, as shown in FIG. 21A, the arithmetic unit 53B in the imaging apparatus 50B performs the processing as the change removal unit 3, the actual phenomenon verification unit 4, and the output unit 5B described in FIG. 11A above. Also, in the information processing apparatus 60B, as shown in FIG. 21B, the CPU 61B performs the processing of the data usage unit 6, the original data acquisition unit 7, and the actual phenomenon verification unit 4 described in FIG. 11B, and the processing as the data falsification determination unit 8.

[0109] <4. Configuration Example as an Alternative Example> [4-1. First Alternative Example] Here, in the above, an example was given in which an image having a large blur is obtained as the change-imparting data Dv by using the optical filter 52 as exemplified in FIG. 13 without a lens. However, as the change-imparting data Dv based on image data, it is also conceivable to use data with a small blur that is difficult to visually recognize. In that case, it becomes possible to supply the change-imparting data Dv as the target data for use to the data user side.

[0110] When imparting a small amount of blurring as described above, an optical system using a lens as exemplified in FIG. 22 can be considered. This can be regarded as inserting a filter for verifying actual phenomena (optical filter) into the optical system of a normal camera with a lens. In FIG. 22, a notable feature other than the filter is that the imaging surfaces of the sensor and the lens are misaligned. This is because if imaging occurs, the process history by the filter will not remain, making it difficult to guarantee actual phenomena. That is, in order for the pattern for verifying actual phenomena to be embedded in the image, it is necessary for a part of the subject to be out of focus.

[0111] Hereinafter, a method of tracing the light rays reaching point x on the sensor will be considered. In FIG. 23, in addition to x and p, an imaging point q on the subject side and a point r in the subject on the straight line passing through p and q are prepared as points necessary for the calculation. Each is a vector represented in two-dimensional coordinates.

[0112] From the lens formula, q, x, b, and c satisfy the following relationship. Since p, q, and r are on the same straight line. From these, by eliminating q and c and expressing r in terms of p and x, the following result is obtained. Although the optical density of the cross-sectional area changes due to the refraction of the lens, if this is incorporated into the luminance when there is no filter, the amount of light on the sensor can be obtained by the following formula. Here, by the variable transformation u(b - a) = (b - a)p + ax When a, b << d, the following convolution integral is obtained. Due to the influence of the light-gathering effect of the lens, the kernel of the convolution can be made as small as the width of each pixel. Therefore, it is possible to impart a small amount of blurring.

[0113] [4-2. Second alternative example] The second alternative example is an example when the sensing data = sound data. Specifically, here, an example will be described in which by imparting a change of superimposing a sound outside the visible and audible bands on the target sound to be sensed, the change removal process on the data user side is made unnecessary, and it is possible to verify that the sensing was performed by the assumed microphone.

[0114] Figure 24 shows an example configuration of a sound sensing device 10C (Figure 24A) as a sensing device in the second modified example, and an example configuration of a sound data using device 20C (Figure 24B) as a data using device in the second modified example.

[0115] As shown in FIG. 24A, the sound sensing device 10C includes a microphone 2C that functions as a sensor for the target sound, a change imparting unit 1C, a data output unit 5C, and an imparting pattern data generating unit 15.

[0116] Here, to impart a change to the target sound to be sensed, a sound in the inaudible band in the environmental sound outside the sound sensing device 10C (hereinafter referred to as "inaudible environmental sound") is superimposed. Also, to enable verification of whether the target sound to be sensed was sensed by the assumed microphone as microphone 2C, a sound with a unique pattern assigned to microphone 2C is superimposed.

[0117] For this purpose, as shown in the figure, the variation imparting unit 1C has a microphone 11, an environmental sound extraction unit 12, a unique pattern generation unit 13, and a sound emission unit 14. A microphone that can also pick up sounds in the inaudible band is used as the microphone 11. The environmental sound extraction unit 12 extracts signal components in the inaudible band from the sound signal picked up by the microphone 11, thereby obtaining a sound signal as the above-mentioned inaudible environmental sound.

[0118] The unique pattern generation unit 13 generates a sound signal based on a unique pattern that is unique to the microphone 2C (hereinafter referred to as a "unique pattern sound signal"). The sound emission unit 14 generates a synthesized sound signal by synthesizing the sound signal indicating the non-audible environmental sound obtained by the environmental sound extraction unit 12 and the unique pattern sound signal generated by the unique pattern generation unit 13, and emits the synthesized sound signal to the microphone 2C.

[0119] 25 is an explanatory diagram of the unique pattern sound signal generated by the unique pattern generation unit 13. The unique pattern sound signal here generates a signal that repeats frequency changes according to a predetermined pattern at a predetermined pattern period. Specifically, within the pattern period, a change period shorter than the pattern period is defined, and frequencies that can be used for the unique pattern sound signal are defined as shown in the lower part of the figure. The unique pattern sound signal is generated by determining from among these frequencies the frequency to be used at each change period within the pattern period. This mechanism makes it possible to create a unique frequency-modulated signal as a unique pattern sound signal for each microphone used to sense the target sound. The unique pattern generation unit 13 generates a unique pattern sound signal for microphone 2C according to the frequency change pattern defined for microphone 2C.

[0120] In Figure 24A, the data output unit 5C outputs the sound signal picked up by the microphone 2C, i.e., a sound signal (assumed to be a digital signal) corresponding to a synthesized sound of the target sound of sensing, the inaudible environmental sound, and the unique pattern sound generated by the unique pattern generation unit 13, as varied sound data DvC.

[0121] In addition, the attached pattern data generation unit 15 outputs a synthesized signal (assumed to be a digital signal) of the sound signal indicating the inaudible environmental sound obtained by the environmental sound extraction unit 12 and the unique pattern sound signal generated by the unique pattern generation unit 13 as attached pattern data Dp.

[0122] 24B , a sound data using device 20C includes a sound data acquiring unit 7C, a data using unit 6C, a variation removing unit 3C, an actual phenomenon verifying unit 4C, and a pattern data acquiring unit 9. The sound data acquiring unit 7C acquires sound data as data to be used. In this example, the assumed data to be used is variation-added sound data DvC.

[0123] The data using unit 6C performs processing to use the sound data acquired by the sound data acquiring unit 7C. Note that the definition of "use" has already been explained, so a duplicate explanation will be avoided. The pattern data acquiring unit 9 acquires the attached pattern data Dp. The attached pattern data Dp may be supplied to the sound data using device 20C by, for example, a legitimate data supplier using a secure method.

[0124] The variation removal unit 3C performs a process of removing the variations imparted by the variation imparting unit 1C from the use data (verification target data) acquired by the sound data acquisition unit 7C, based on the imparted pattern data Dp acquired by the pattern data acquisition unit 9. For example, the variation removal unit 3C calculates the inverse function described above from the imparted pattern data Dp and uses the inverse function to remove the variations imparted by the variation imparting unit 1C from the use data acquired by the sound data acquisition unit 7C. Note that it is also conceivable that the inverse function may be calculated in advance by a legitimate data supplier based on the imparted pattern data Dp, and the inverse function may be acquired by the sound data using device 20C so that it can be used by the variation removal unit 3C.

[0125] The actual phenomenon verification unit 4C uses the variation-removed data obtained by the variation removal unit 3C and the target data acquired by the sound data acquisition unit 7C as input data and determines whether the difference between the two data is within a "predetermined range" according to the variation imparted by the variation imparting unit 1C. This determination makes it possible to verify that the target data is actual phenomenon data and has not been tampered with, and that it is data sensed by the intended microphone.

[0126] [4-3. Third Alternative Example] The third alternative example is an example in which verification that target data is data sensed by an assumed sensing device is achieved by a method different from the method described in Fig. 24. Fig. 26 shows an example configuration of a sensing device 10D (Fig. 26A), which is a sensing device as the third alternative example, and an example configuration of a data using device 20D (Fig. 26B), which is a data using device as the third alternative example.

[0127] 26A , the sensing device 10D includes a variation imparting unit 1 and a sensor 2, and outputs sensing data from the sensor 2 as variation imparting data Dv. In a third example, the sensing device 10D adds supplier information for identifying the data supplier that supplies the variation imparting data Dv to the variation imparting data Dv and outputs the variation imparting data Dv.

[0128] 26B, a data using device 20D includes a variation removing unit 3, a data using unit 6, and an actual phenomenon verifying unit 4, as well as a parameter searching unit 21.

[0129] In a third alternative example, a change removal parameter Pr, which is a parameter used to remove the change made by the change imparting unit 1, is derived by a legitimate data supplier, and the change removal parameter Pr (the parameter as the inverse function described above or the parameter of the AI ​​model) is stored in a predetermined server device 25D. The change removal parameter Pr stored in the server device 25D in this manner is searchable using the above-mentioned supplier information on a communication network such as the Internet. In other words, it is made publicly available on the network. Therefore, if the change imparting by the change imparting unit 1 is considered as data encryption, the change removal parameter Pr in this case can be said to correspond to an encryption key, which is a public key for decrypting encrypted data.

[0130] The parameter search unit 21 searches for and acquires a change-adding parameter Pr identified from the supplier information added to the target data (the assumed data is the change-adding data Dv). The change removal unit 3 uses the change-removal parameter Pr acquired by the parameter search unit 21 to remove changes from the data supplied as the target data. The actual phenomenon verification unit 4 receives the change-removed data obtained by the change removal unit 3 and the data supplied as the target data (the assumed data is the change-adding data Dv) as input and determines whether the difference between the two data is within a "predetermined range." This determination by the actual phenomenon verification unit 4 can verify whether the target data is actual phenomenon data and unaltered data, and whether the target data is data sensed by an assumed sensing device. While a possible form of fraud by a third party would be forging a pair of change-adding data Dv and a change-removal parameter and supplying it to a data user, the above verification method ensures that the change-removal parameter Pr acquired from the supplier information is a legitimate parameter, preventing such fraud from occurring.

[0131] Fig. 27 is a diagram illustrating a specific configuration example of a data using device 20D. The data using device 20D can be realized by a device with a hardware configuration similar to that of the information processing device 60 described above in Fig. 18. However, for the sake of distinction, the information processing device 60 in the third alternative example will be referred to as information processing device 60D, and the CPU 61 of the information processing device 60D will be referred to as CPU 61D.

[0132] As shown in Figure 27, in this case, it is possible to configure the CPU 61D of the information processing device 60D to perform the processing of the parameter search unit 21, change removal unit 3, data usage unit 6, and actual phenomenon verification unit 4 described in Figure 26B.

[0133] [4-4. Fourth Alternative Example] Here, the third alternative example described above is a method that assumes that the variation elimination parameter Pr serving as the encryption key used for verification is made public, but the fourth alternative example makes it possible to keep such variation elimination parameter Pr private, thereby improving security.

[0134] Figure 28 shows an example configuration of a sensing device 10E (Figure 28A), which is a sensing device as a fourth alternative example, a data usage device 20E, which is a data usage device as a fourth alternative example, and a server device 30 used in the fourth alternative example (Figure 28B).

[0135] 28A , the sensing device 10E includes a variation imparting unit 1, a sensor 2, an output unit 5E, and a hash value calculation unit 16. The hash value calculation unit 16 calculates a hash value h(s) for the sensing data (variation imparted data Dv) obtained by the sensor 2, and outputs the hash value h(s) to the output unit 5E. The sensing device 10E calculates the hash value h(s) for the variation imparted data Dv so that the server device 30 can verify whether or not the data to be verified (data to be used) has been tampered with.

[0136] In this example, the hash value calculation unit 16 calculates a hash value h(s) for the variation-imparting data Dv (sensing data) by calculating a hash value for the combined data of the variation-imparting data Dv and "sensing feature information" indicating the sensing feature of the variation-imparting data Dv. Specifically, the sensing feature information may be model number information of the sensor 2 (model number information of the sensing device 10E). In the sense that sensing was performed by the sensor 2 identified by the model number, the model number information can be considered to correspond to the above-mentioned "sensing information." Note that the sensing feature information is not limited to model number information of the sensor 2, and may also be, for example, information on the date and time or location at which the variation-imparting data Dv was sensed. Alternatively, information indicating the temperature and humidity at the time the variation-imparting data Dv was sensed may also be considered.

[0137] The output unit 5E outputs the variation-added data Dv as sensing data obtained by the sensor 2 and the hash value h(s) calculated by the hash value calculation unit 16.

[0138] The manner in which the variation-added data Dv and hash value h(s) output by the output unit 5E are supplied to the data using device 20E may be the same as the manner in which the variation-removed data Dr is supplied in the first configuration example described above.

[0139] 28B, a data using device 20E includes a data using unit 6 and a verification request unit 22. In this case, the data using unit 6 receives and uses the data to be used (the assumed data is the variation-imparting data Dv).

[0140] The verification request unit 22 transmits the data to be used and the hash value h(s) supplied to the data using device 20E to the server device 30, and requests verification of the data to be used.

[0141] The server device 30 includes a variation removal unit 3 and an actual phenomenon verification unit 4, as well as a hash value verification unit 31. A variation removal parameter Pr is set in the variation removal unit 3, and the variation removal unit 3 performs processing to remove the variation imparted by the variation imparting unit 1 of the sensing device 10E from the use target data transmitted from the verification request unit 22, thereby obtaining variation-removed data Dr. In this case, the actual phenomenon verification unit 4 receives as input the variation-removed data Dr obtained by the variation removal unit 3 and the use target data transmitted from the verification request unit 22, and determines whether the difference between these data is within a "predetermined range." The actual phenomenon verification unit 4 then transmits information indicating the result of this determination to the verification request unit 22 as verification result information.

[0142] The hash value verification unit 31 determines whether the use target data (expected data = change-imparting data Dv) transmitted from the verification request unit 22 has been tampered with, based on the hash value h(s). That is, the hash value verification unit 31 generates composite data of the use target data transmitted from the verification request unit 22 and the sensing feature information described above, calculates a hash value for the composite data using the same hash function as used by the hash value calculation unit 16, and determines whether the calculated hash value matches the hash value h(s). Specifically, if the sensing feature information is model number information of the sensor 2, the hash value verification unit 31 generates composite data of preset model number information of the sensor 2 and the use target data transmitted from the verification request unit 22, and calculates a hash value for the composite data. In addition, when the sensing feature information is information of a nature that requires sequential acquisition by the sensing device 10E, such as the sensing location information or weather information exemplified above, for example, a legitimate data supplier may manage correspondence information between the target change-added data Dv and the sensing feature information, and the hash value verification unit 31 may obtain the sensing feature information corresponding to the target change-added data Dv from the correspondence information and use it to generate the above-mentioned composite data. The hash value verification unit 31 transmits information indicative of the above-mentioned determination result to the verification request unit 22 as verification result information.

[0143] Here, since the server device 30 can be a server device managed by the legitimate data supplier, by performing the processing for verifying the actual phenomenon including variation removal in the server device 30 as described above, it is possible to eliminate the need to disclose the variation removal parameter Pr, thereby improving security. By providing the hash value calculation unit 16 and the hash value verification unit 31, it is possible to prevent a third party from switching the data to be verified, thereby improving security in this respect as well.

[0144] FIG. 29 is a diagram illustrating a specific configuration example of a sensing device 10E, FIG. 30 is a specific configuration example of a data usage device 20E, and FIG. 31 is a diagram illustrating a specific configuration example of a server device 30. The sensing device 10E can have a hardware configuration similar to that of the imaging device 50 shown in FIG. 12, and the data usage device 20E can be realized by a device with a hardware configuration similar to that of the information processing device 60 described in FIG. 18. For the sake of distinction, the imaging device 50 in the fourth alternative example will be referred to as the imaging device 50E and the information processing device 60 will be referred to as the information processing device 60E, with the calculation unit 53 of the imaging device 50E being referred to as the calculation unit 53E and the CPU 61 of the information processing device 60E being referred to as the CPU 61E. The server device 30 can also have a hardware configuration similar to that of the information processing device 60, and the CPU 61 of the server device 30 will be referred to as the CPU 35.

[0145] As shown in Figure 29, in a fourth alternative example, a calculation unit 53E of an imaging device 50E performs processing as a hash value calculation unit 16 and an output unit 5E, and as shown in Figure 30, a CPU 61E of an information processing device 60E performs processing as a data usage unit 6 and a verification request unit 22 described in Figure 28B.

[0146] In addition, in a fourth alternative example, as shown in Figure 31, it is possible to configure the CPU 35 of the server device 30 to perform processing as the change removal unit 3, actual phenomenon verification unit 4, and hash value verification unit 31 described in Figure 28B.

[0147] 5. Modifications Note that the embodiment is not limited to the specific examples described above, and various modified configurations may be employed. For example, while image data and sound data have been exemplified above as examples of sensing data, the sensing data in the present technology may also be, for example, distance image data indicating the distance to a subject for each pixel, data as a temperature map indicating the temperature of a subject for each pixel, one-dimensional data similar to sound data, such as acceleration data or angular velocity data, and is not limited to image or sound data. In other words, the present technology can be used to detect any physical phenomenon that can be sensed.

[0148] 6. Summary of the embodiment As described above, the verification device (data using device 20, sensing device 10A, data using device 20A, sensing device 10B, data using device 20B, sound data using device 20C, data using device 20D, server device 30) as an embodiment is configured to be able to acquire data obtained by a sensing device that includes a change imparting unit (same as 1) that imparts a change in the process up to the analog domain when sensing a physical phenomenon, and a sensor unit (sensor 2, microphone 2C) that senses the physical phenomenon, and includes a determination unit (real phenomenon verification unit 4, 4C) that determines whether a difference between two input data, namely, reference input data that is either change-removed data, which is data obtained by removing the change imparted by the change imparting unit from the input data, or change-imparted data, which is sensing data to which a change has been imparted, and verification target data, which is data to be verified, is within a predetermined range corresponding to the change imparted by the change imparting unit. The changes applied by the change applying unit are known to authorized sensing data providers, such as manufacturers or administrators of sensing devices, and therefore the difference between the change-applied data and the change-removed data is also known. Therefore, as described above, it is possible to realize a configuration for determining whether the difference between the verification target data and the reference input data is within a predetermined range corresponding to the change applied by the change applying unit. By performing this determination, it is possible to determine whether the verification target data is data in which the predetermined change applied by the change applying unit has been applied to the physical phenomenon of the sensing target, or whether the predetermined change has been removed from the change-applied data. In other words, it is possible to determine whether the verification target data is actual phenomenon data (data obtained by sensing an actual phenomenon) rather than generated data. Furthermore, as described above, being able to determine whether the target data is data in which the predetermined change applied by the change applying unit has been applied to the physical phenomenon of the sensing target, or whether the predetermined change has been removed from the change-applied data, also means that it is possible to determine whether the sensing data has been altered between the time of the determination and the time of the determination.Therefore, with the above configuration, it is possible to simultaneously verify whether the target data is actual phenomenon data and whether the target data is tamper-free data.

[0149] In addition, in an embodiment of the verification device, the sensing device applies digital domain changes, which are predetermined changes in the digital domain, to the change-removed data or change-added data that serve as reference input data, and includes a digital domain removal unit that removes the digital domain changes from the input data, and the determination unit uses the reference input data from which the digital domain changes have been removed by the digital domain change removal unit for determination. If the data user is able to obtain both the change-added data and the change-removed data, there is a greater possibility that the mechanism and parameters of the changes applied by the change-adding unit will be deciphered from these data. Therefore, by applying digital domain changes to the change-removed data or change-added data that serve as reference input data on the sensing side as described above and then removing the digital domain changes from the reference input data in the actual phenomenon determination, it is possible to make it more difficult to decipher the mechanism and parameters of the changes applied by the change-adding unit, thereby improving security.

[0150] In addition, in the verification device (data using device 20, 20A, 20B) according to an embodiment, the sensing device (10, 10A, 10B) includes a variation removal unit that removes the variation added by the variation addition unit from the variation-added data obtained by the sensor unit, thereby enabling both variation-added data and variation-added data to be obtained. The determination unit uses either the variation-added data or the variation-added data output by the sensing device as reference input data and determines whether the difference between the variation-added data and the verification target data is within a predetermined range. This configuration corresponds to a case where the variation-added data or the variation-added data output by the sensing device is input as the usage target data and the verification target data is performed on the data using device that is assumed to input the variation-added data or the variation-added data as the usage target data. Specifically, with the above configuration, when the usage target data is assumed to be the variation-added data, the variation-added data can be used as the reference input data to perform verification based on the difference between the verification target data (assumed variation-added data). Also, when the usage target data is assumed to be the variation-added data, the variation-added data can be used as the reference input data to perform verification based on the difference between the verification target data (assumed variation-added data). Therefore, when actual phenomenon verification is performed on the data using device side, it is possible to appropriately perform actual phenomenon verification on the data to be used in response to cases where the assumed data to be used is variation-removed data or variation-added data.

[0151] Furthermore, in the verification device (data using device 20, 20A, 20B) according to the embodiment, the determination unit uses the variation-added data output from the sensing device as reference input data and determines whether the difference between the variation-added data and the verification target data is within a predetermined range. This allows for appropriate verification of actual phenomena for the usage target data in cases where the usage target assumed data is variation-removed data.

[0152] Furthermore, the verification device (sound data using device 20C, data using device 20D, server device 30) according to the embodiment includes a change removal unit that inputs the change-imparted data output by the sensing device and removes the change imparted by the change imparting unit from the input change-imparted data, and the determination unit determines whether the difference between the change-imparted data obtained by the change removal unit and the input change-imparted data is within a predetermined range. This allows for proper verification of actual phenomena on the data user side, even when the assumed data to be used is the change-imparted data, without providing a change removal unit in the sensing device. This allows for a simplified configuration of the sensing device, which can be made smaller, lighter, and more cost-effective.

[0153] Furthermore, the verification device (sensing devices 10A, 10B) according to the embodiment is configured as a sensing device including a change adding unit and a sensor unit, and includes a change removing unit that removes the change added by the change adding unit from the change adding data obtained by the sensor unit, and a determination unit that determines whether the difference between the change-removed data from which the change has been removed by the change removing unit and the change adding data is within a predetermined range. This makes it possible to realize a sensing device that verifies a real phenomenon based on the difference between the change-removed data and the change adding data.

[0154] Furthermore, the verification device according to the embodiment includes an output unit (5A, 5B) that outputs the variation-removed data or the variation-added data to which tag information indicating the judgment result by the judgment unit is added. This makes it possible to supply data to the data user with a guarantee tag indicating that the data is real phenomenon data. Therefore, the data user can recognize that the supplied data is real phenomenon data from the guarantee tag, eliminating the need for the data user to verify whether the data is real phenomenon data, thereby reducing the burden on the data user.

[0155] Furthermore, the verification device (data using device 20B, server device 30) according to the embodiment includes a data tampering determination unit (data using device 20B, hash value verification unit 31) configured as a separate device from the sensing device, which determines whether the data to be verified has been tampered with based on tampering detection data. For example, it is conceivable to perform tampering determination based on tampering detection data such as a hash value. By performing tampering determination based on the tampering detection data, it is possible to determine whether data has been tampered with in the digital domain after A / D conversion.

[0156] Furthermore, in the verification device according to the embodiment, the change applying unit applies a change in the phenomenon domain before the physical phenomenon is sensed by the sensor unit. By applying the change in the phenomenon domain as described above, it becomes extremely difficult for third parties other than authorized sensing data providers and data users to obtain information before the change is applied, and it becomes extremely difficult to decipher the content of the change from the change in the information before and after the change is applied. This increases the difficulty for third parties to decipher the verification mechanism, thereby improving the accuracy of the verification.

[0157] Furthermore, in the verification device according to the embodiment, the sensing data is image data, and the change applying unit applies a change to the subject light using an optical filter (52). By using an optical filter, it is possible to appropriately apply a change in the phenomenon region corresponding to the image sensing. Specifically, applying a change using an optical filter has the advantage of easy parameter management and reducing the difficulty and workload involved in arithmetically creating a change removal parameter.

[0158] Furthermore, in the verification device according to the embodiment, the process of removing the changes added by the change adding unit is performed by AI processing (see FIG. 3). It is conceivable to remove the changes added by the change adding unit by calculating the inverse function of the function representing the added change and using the inverse function, but calculating this inverse function requires a huge amount of calculation cost. By using AI processing for the change removal process, it is no longer necessary to calculate the inverse function when removing the changes, and the workload involved in developing the change removal process can be reduced.

[0159] A verification method according to an embodiment is a verification method for a verification device configured to acquire data obtained by a sensing device including a change imparting unit that imparts a change in a process up to the analog domain when sensing a physical phenomenon and a sensor unit that senses the physical phenomenon, and the verification method determines whether a difference between two input data, namely, reference input data that is either change-removed data, which is data obtained by removing the change imparted by the change imparting unit from the input data, or change-imparted data, which is sensing data to which the change has been imparted, and verification target data, is data to be verified, falls within a predetermined range corresponding to the change imparted by the change imparting unit. This verification method can also achieve the same functions and effects as the verification device according to the embodiment described above.

[0160] Furthermore, the determination device (data using device 20, sensing device 10A, data using device 20A, sensing device 10B, data using device 20B, sound data using device 20C, data using device 20D, server device 30) according to the embodiment includes a tampering determination unit (actual phenomenon verification unit 4, 4C) that performs tampering determination of target data using, as an encryption key, changes imparted in the process up to the analog domain when sensing a physical phenomenon. The "changes" imparted in the process up to the analog domain in sensing as described above are difficult for a third party to decipher. Therefore, by using such "changes" as an encryption key for tampering determination, the accuracy of tampering determination can be improved. In other words, highly accurate determination can be achieved.

[0161] In addition, in the determination device according to the embodiment, the tampering determination unit determines whether the difference between the target data and reference input data, which is either change-removed data (data obtained by removing changes from input data) or change-added data (sensing data to which changes have been added), falls within a predetermined range corresponding to the change, as a determination of whether tampering has occurred. The content of the “change” is known to authorized sensing data providers, such as sensing device manufacturers and administrators, and therefore the difference between the change-added data and the change-removed data is also known. Therefore, as described above, a configuration can be realized that determines whether the difference between the target data and reference input data falls within a predetermined range corresponding to the “change.” By performing this determination, it becomes possible to determine whether the target data is data in which a “change” has been added to the physical phenomenon being sensed, or whether the “change” has been removed from the change-added data. In other words, it is possible to determine whether the sensing data has been altered during the period up until the determination. Furthermore, as described above, being able to determine whether the target data is data to which a "change" has been applied to the physical phenomenon to be sensed, or whether the target data is data to which the "change" has been removed, proves that the target data has been subjected to a sensing process, and therefore it can also be determined whether the target data is real phenomenon data (data obtained by sensing an actual phenomenon) rather than generated data. Therefore, with the above configuration, it is possible to simultaneously verify whether the target data is real phenomenon data and whether it is unaltered data.

[0162] At this time, in generating the transformation-removed data, a process of removing the "change" is performed, and this transformation-removal process involves a process equivalent to adding a change with characteristics opposite to the characteristics of the added "change." This transformation-removal process corresponds to a process of decrypting the "change-added data" encrypted with the encryption key as the "change." Therefore, the determination process by the tampering determination unit as described above corresponds to a process of determining whether or not the data has been tampered with using the "change" as the encryption key.

[0163] Furthermore, in an embodiment of the determination device (data usage device 20D), the determination device is configured as a separate device from the sensing device that senses physical phenomena. The tampering determination unit includes a variation removal unit that removes variations from input data and a parameter acquisition unit that acquires variation removal parameters based on data source information attached to the target data. The tampering determination unit then performs variation removal on the target data using the variation removal parameters acquired by the parameter acquisition unit to obtain variation-removed data, and determines whether the difference between the variation-removed data and the target data falls within a predetermined range corresponding to the variation. By using the variation-removed data obtained using parameters acquired based on the source information as described above for the determination, it is possible to prevent a third party from forging a pair of variation-added data and variation removal parameters and supplying them to a data user. Therefore, with the above configuration, it is possible to verify whether the target data is unaltered data and whether the target data is not forged data but data sensed by the intended sensing device.

[0164] Furthermore, in the determination device (server device 30) according to the embodiment, the tampering determination unit includes a variation removal unit that removes variations from input data, and receives target data from a data using device that is separate from the sensing device that senses physical phenomena and uses the sensing data from the sensing device. The variation removal unit removes variations from the received target data to obtain variation-removed data, and determines whether the difference between the variation-removed data and the target data is within a predetermined range corresponding to the variation. In this case, the determination device is configured as a separate device from the sensing device and the data using device. Unlike when tampering determination is performed using a variation removal unit in the data using device, this eliminates the need to externally disclose the variation removal parameters so that they can be used by the data using device. This improves the confidentiality of the encryption key used for tampering determination, thereby improving the accuracy of tampering determination.

[0165] In addition, in the determination device (server device 30) according to an embodiment, the sensing device outputs change-imparted data, which is sensing data to which changes have been added, and a hash value of combined data of the change-imparted data and sensing feature information indicating the sensing characteristics of the change-imparted data. The determination device includes a hash value verification unit (31) that receives the hash value from the data usage device, calculates a hash value for the combined data of the target data and the sensing feature information received by the tampering determination unit, and determines whether the calculated hash value matches the received hash value. According to the above configuration, when the hash value verification unit determines that the two hash values ​​match, it is proven that the target data is data having the characteristics indicated by the sensing feature information. In other words, the hash value verification unit can verify whether the target data is data sensed by the intended sensing device. Therefore, according to the above configuration, the accuracy of tampering determination can be improved by improving the confidentiality of the encryption key, and the accuracy of tampering determination can be improved by preventing a third party from forging pairs of change-imparted data and change removal parameters and providing them to a data user.

[0166] Furthermore, in the determination device according to the embodiment, the sensing feature information is model number information of the sensing device. Since the model number information of the assumed sensing device is known to the authorized sensing data provider, the determination device can simply use the known model number information, and does not need to obtain it from the sensing device each time. Therefore, the processing load on the sensing device and the determination device when verifying whether the data was sensed by the assumed sensing device can be reduced.

[0167] Furthermore, in the determination device according to the embodiment, the change is assumed to be a change that is imparted in the phenomenon domain before the physical phenomenon is sensed. By imparting the change in the phenomenon domain as described above, it becomes extremely difficult for third parties other than the authorized sensing data provider or data user to obtain information before the change is imparted, and it becomes extremely difficult to decipher the content of the change from the change in the information before and after the change is imparted. Therefore, it is possible to increase the difficulty for third parties to decipher the determination mechanism, thereby improving the accuracy of the determination.

[0168] In addition, in the determination device according to the embodiment, the target data is image data, and the change is a change imparted to the subject light by an optical filter. By using an optical filter, it is possible to appropriately impart a change in a phenomenon region corresponding to the case where image sensing is performed. Specifically, imparting a change using an optical filter has the advantage that parameter management is easy and the difficulty and workload involved in arithmetically creating a change removal parameter can be reduced.

[0169] Furthermore, in the determination device according to the embodiment, the process of removing the change added by the change adding unit is performed by AI processing. It is conceivable to remove the "change" by calculating the inverse function of the function indicating the added change and using the inverse function, but calculating this inverse function requires a huge amount of calculation cost. By using AI processing for the change removal process, it is no longer necessary to calculate the inverse function when removing the change, which reduces the workload involved in developing the change removal process.

[0170] The determination method according to the embodiment is a determination method for determining whether target data has been tampered with by using, as an encryption key, a change imparted in the process up to the analog domain when sensing a physical phenomenon. This determination method can also achieve the same effects and advantages as the determination device according to the embodiment described above.

[0171] The effects described in this specification are merely examples and are not limiting, and other effects may also be present.

[0172] <7. The Present Technology> The present technology can also be configured as follows: (1) A determination device including a tampering determination unit that performs tampering determination on target data using, as an encryption key, a change imparted in a process up to the analog domain when sensing a physical phenomenon. (2) The determination device according to (1), wherein the tampering determination unit determines whether or not tampering has occurred by determining whether a difference between two pieces of input data, the target data and reference input data being either change-removed data, which is data obtained by removing the change from input data, or change-added data, which is sensing data to which the change has been added, is within a predetermined range corresponding to the change. (3) The determination device according to (1) or (2), configured as a separate device from the sensing device that senses the physical phenomenon, wherein the tampering determination unit has a change removal unit that removes the change from input data, and a parameter acquisition unit that acquires a change removal parameter by the change removal unit based on data supply source information attached to the target data, and the tampering determination unit performs change removal on the target data using the change removal parameter acquired by the parameter acquisition unit to obtain change-removed data, and determines whether a difference between the change-removed data and the target data is within a predetermined range corresponding to the change. (4) The determination device according to (1) or (2), wherein the tampering determination unit has a change removal unit that removes the change from input data, and receives the target data from a data usage device that is a separate device from the sensing device that senses the physical phenomenon and uses sensing data from the sensing device, performs change removal on the received target data by the change removal unit to obtain change-removed data, and determines whether a difference between the change-removed data and the target data is within a predetermined range corresponding to the change.(5) The sensing device outputs change-imparted data, which is sensing data to which the change has been imparted, and a hash value of combined data of the change-imparted data and sensing feature information indicating a sensing feature of the change-imparted data, and the determination device according to (4) includes a hash value verification unit that receives the hash value from the data using device, calculates a hash value of the combined data of the target data and the sensing feature information received by the tampering determination unit, and determines whether the calculated hash value matches the received hash value. (6) The determination device according to (5), in which the sensing feature information is model number information of the sensing device. (7) The determination device according to any of (1) to (5), in which the change is imparted in a phenomenon area before the physical phenomenon is sensed. (8) The determination device according to (7), in which the target data is image data, and the change is imparted to subject light by an optical filter. (9) The determination device according to any of (2) to (6), in which the process of removing the change imparted by the change imparting unit is performed by AI processing. (10) A method for determining whether target data has been tampered with by using, as an encryption key, changes imparted in the process up to the analog domain when sensing a physical phenomenon.

[0173] 1, 1C Change adding unit 2 Sensor 3, 3-1, 3-2, 3C Change removing unit 4, 4-1, 4-2, 4C Actual phenomenon verifying unit 41 Difference calculation unit 42 Threshold determination unit 43, 44 Actual phenomenon likelihood calculation unit 45 Difference calculation unit 46 Threshold determination unit 5, 5A, 5B, 5C, 5E Output unit 6, 6A, 6C Data using unit 7 Original data acquisition unit 10, 10A, 10B, 10D, 10E Sensing device 20, 20A, 20B, 20D, 20E Data using device 25, 25D Server device Dv Change adding data Dr Change removing data 8 Data tampering determination unit 50 Imaging device 51 Optical filter 52 Image sensor 53, 54A, 53B, 53E Calculation unit 54 Communication unit BS Bus 60 Information processing device 61, 61A, 61B, 61D, 61E CPU 62 ROM 63 RAM 64 Bus 65 Input / output interface 66 Input unit 67 Display unit 68 Audio output unit 69 Storage unit 70 Communication unit 71 Drive 72 Removable recording medium 10C Sound sensing device 2C, 11 Microphone 12 Environmental sound extraction unit 13 Unique pattern generation unit 14 Sound emission unit 15 Assigned pattern data generation unit DvC Varied assigned sound data Dp Assigned pattern data 20C Sound data using device 7C Sound data acquisition unit 9 Pattern data acquisition unit 21 Parameter search unit Pr Variation removal parameter 16 Hash value calculation unit h(s) Hash value 22 Verification request unit 30 Server device 31 Hash value verification unit 35 CPU

Claims

1. A determination device equipped with a tampering determination unit that determines whether target data has been tampered with by using, as an encryption key, the changes that have occurred in the process up to the analog domain when sensing physical phenomena.

2. The determination device according to claim 1, wherein the tampering determination unit determines whether or not tampering has occurred by determining whether the difference between two pieces of input data, the reference input data being either change-removed data, which is data obtained by removing the change from the input data, or change-added data, which is sensing data to which the change has been added, and the target data, is within a predetermined range corresponding to the change.

3. A determination device according to claim 1, configured as a device separate from a sensing device that senses the physical phenomenon, wherein the tampering determination unit has a change removal unit that removes the change from input data, and a parameter acquisition unit that acquires a change removal parameter to be used by the change removal unit based on data source information attached to the target data, and wherein the tampering determination unit uses the change removal parameter acquired by the parameter acquisition unit to perform change removal on the target data to obtain change-removed data, and determines whether the difference between the change-removed data and the target data is within a predetermined range corresponding to the change.

4. The determination device according to claim 1, wherein the tampering determination unit has a change removal unit that removes the change from the input data, receives the target data from a data usage device that is separate from the sensing device that senses the physical phenomenon and uses sensing data from the sensing device, removes changes from the received target data using the change removal unit to obtain change-removed data, and determines whether the difference between the change-removed data and the target data is within a predetermined range corresponding to the change.

5. The sensing device outputs change-added data, which is sensing data to which the change has been added, and a hash value of composite data of the change-added data and sensing feature information indicating the sensing features of the change-added data, and the determination device according to claim 4, further comprising a hash value verification unit that receives the hash value from the data usage device, calculates a hash value of the composite data of the target data and the sensing feature information received by the tampering determination unit, and determines whether the calculated hash value matches the received hash value.

6. The determination device according to claim 5, wherein the sensing feature information is model number information of the sensing device.

7. The determination device according to claim 1, wherein the change is a change that occurs in a phenomenon area before the physical phenomenon is sensed.

8. The determination device according to claim 7, wherein the target data is image data, and the change is a change imparted to the subject light by an optical filter.

9. The determination device according to claim 2, wherein the process of removing the change imparted by the change imparting unit is performed by AI processing.

10. A method for determining whether target data has been tampered with by using, as an encryption key, the changes that have occurred in the process up to the analog domain when sensing physical phenomena.

Citation Information

Patent Citations

  • Data watermarks created by using an uneven sampling period

    US20050198504A1