Computer system and method for certifying the authenticity of a data packet acquired or compiled by a user electronic device
Patent Information
- Application Number
- PCT/IB2026/052956
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-28
- Filing Date
- 2026-03-26
- Publication Date
- 2026-10-01
Smart Images

Figure IB2026052956_01102026_PF_FP_ABST
Abstract
Description
[0001] Title: “Computer system and method for certifying the authenticity of a data packet acquired or compiled by a user electronic device”
[0002] DESCRIPTION
[0003] Technical field
[0004] The present invention is developed in the technical field of the certification of authenticity of data packets acquired or compiled by a user, such as photographs, audio, video and text documents in various formats.
[0005] State of the art
[0006] Nowadays, artificial intelligence is capable of creating so-called deepfakes with ever-increasing levels of accuracy. Deepfakes are artificial (and therefore non-authentic) data packets, such as, for example, altered image, video, audio or text document files, which so closely resemble the same types of files that are authentically acquired by a user as to be difficult for a human being to distinguish from the latter.
[0007] The authenticity of such files is essential in many sectors where there is a risk of deception and alteration of reality. One of these sectors is journalism. Indeed, with the widespread diffusion of smartphones and other similar devices, events relevant to the press are often witnessed by a great many photos, videos and audio files. However, responsible mass media, despite receiving a great many of these files, must distinguish authentic files from false ones, so as not to disseminate erroneous information. The same applies to documents transmitted and received by actors in a professional and / or administrative context. It is also very important that the files, even where authentic, are correctly dated, so as not to attribute a file to an event different from the correctone. For this reason, despite the very wide availability of high-quality documents, files coming exclusively from a few subjects of proven reliability are usually used.
[0008] The ability to verify the authenticity of files would protect from fakes not only the mass media, but also to a certain extent the common people who are constantly exposed to false information content (such as fake news).
[0009] Another sector in which the authenticity of information is crucial is insurance, in all situations in which it is necessary to bear witness to the state of an artifact or a person at a given moment.
[0010] Summary of the invention
[0011] The object of the present invention is to supply the needs outlined with reference to the known art, and in particular to provide simple tools for creating data packets with a proven level of authenticity, and for verifying their authenticity at a later time.
[0012] These and other objects are achieved by a computer system and a method for certifying the authenticity of a data packet acquired or compiled by a user electronic device, according to any one of the appended claims.
[0013] The invention provides that a special user software is used on a user device. The user software opens a user interface to enable the user to acquire or compile a data packet, for example by controlling an input peripheral of the user device, such as a camera, and acquiring the data packet, or by compiling and approving a particular text document, for example a contractual proposal, in particular a form.
[0014] The same user software then uses a first encoding algorithm to generate a first hash string, based on a predetermined combination of the acquired data packet and ofa first security key, preferably divided into a local key stored in the user device, and a remote key received from a remote processing system, which can be referred to the user's credentials. Then, the data packet and the first hash string are sent to the remote processing system, which can be a server or a cloud system.
[0015] The remote processing system executes a central authentication software, which reuses the same first encoding algorithm based on the same data packet and the same security key, verifying that the hash string thus generated corresponds to the first hash string received from the user device.
[0016] In case of a positive result, the central authentication software sends the data packet to an accredited certifying entity, which performs a certification of the data packet, generating a certification code linked to the certification date, which can be for example a certification log, a unix timestamp, but also other types of codes derived from the certification operation.
[0017] The central authentication software receives the certification code and uses a second encoding algorithm to generate a second hash on the basis of a predetermined combination of multiple elements such as for example at least one or more of the second security key, the certification code, the first hash string and the data packet, preferably the second security key, the certification code and the first hash string. A certification information sheet, containing at least the second hash string, is sent to a user contact address, and can be used subsequently to confirm that the authentication has occurred.
[0018] Advantageously, the central authentication software can be sure that the received data packet is authentic, at least in the sense that it has been acquired or compiled by an input peripheral precisely by means of the user software of thecomputer system, without being subsequently altered. Indeed, in the case of even the slightest alteration, when the first encoding algorithm is executed centrally using the received data packet, a hash string different from the first hash string generated on the user device for the original data packet would be generated for the altered data packet. In this second case, the data packet would not be recognized and the process would not be completed with the certification through an accredited certifying entity.
[0019] Following this verification, in case of a positive result, the certification is performed on one or more TSPs (Trust Service Providers) and / or one or more CAs (Certification Authorities) by means of a timestamp process, digital seal or other always regulated procedure, generating certification logs such as digital legal receipts specific to the certification process itself.
[0020] At this point, the execution of the second encoding algorithm guarantees the authenticity and the connection of the data packet that is certified with the date on which the certification takes place.
[0021] Advantageously, with respect to a simple certification by an accredited certifying entity, not only is confirmation obtained that a certain file has not been altered since the moment of certification, but also confirmation that the file is authentic, in the sense that it was acquired or compiled, directly by the user software, thus using only the functions of the user software.
[0022] Further characteristics and advantages of the invention will be recognizable to a person skilled in the art from the following detailed description of exemplary embodiments of the invention.Brief description of the figures
[0023] For a better understanding of the following detailed description, some embodiments of the invention are illustrated in the accompanying drawings, in which:
[0024] - figure 1 shows a flow diagram of a first part of a method for certifying the authenticity of a data packet acquired from a user electronic device, according to an embodiment of the invention,
[0025] - figure 2 shows a flow diagram of a second part of the method of figure 1, and - figure 3 shows a flow diagram of a third part of the method of figure 1.
[0026] DETAILED DESCRIPTION
[0027] The invention relates to a computer system and a method for certifying the authenticity of a data packet acquired from a user electronic device.
[0028] The computer system comprises at least two software programs, namely a user software and a central authentication software.
[0029] The user software is stored in a user electronic device 100 and is executable by the user device 100. The user device 100 can be a smartphone, as well as various other types of known electronic devices, equipped with processors, memories, peripherals and communication channels compatible with the execution of the steps that will be described below. Obviously, multiple copies of the user software can be stored and executed separately in multiple user devices 100, of which only one will be described below for the sake of simplicity.
[0030] The central authentication software is instead executable by a remote processing system 200, which is remote with respect to each user device 100. The remoteprocessing system 200 can comprise, for example, one or more servers, and / or a cloud system, and / or a distributed computing system.
[0031] The computer system of the invention also interacts with one or more external certifying entities 300, which are generally accredited bodies such as TSPs (Trust Service Providers) and / or CAs (Certification Authorities). Each certifying entity 300 is enabled for the legal certification of data packets with the generation of related certification logs.
[0032] The user device 100 is configured to establish, when necessary, a signal communication with the remote processing system 200, for example via an internet network.
[0033] The user device 100 preferably comprises an input peripheral 101 configured to acquire a predetermined type of data packet. In the preferred embodiment, the input peripheral 101 is a video camera, configured to acquire as a data packet 1 an image file and / or a video file representative of one or more framed subjects. Another example of an input peripheral is a microphone, configured to acquire as a data packet 1 an audio file representative of a recorded sound sequence. As an input peripheral 101, a set of several different input peripherals 101 may also be understood hereinafter, for example a video camera and a microphone configured together to acquire an audiovisual file.
[0034] The invention is also not limited to data packets 1 acquired by the user device 100 by means of input peripherals 101, but other types of data packets 1 such as those commented on further on can also be considered. For example, a document to be filled in, such as a form, the content of which is completed or simply approved, may be contemplated.The invention makes use of a first encoding algorithm, a first security key 2a, 2b to be used in the first encoding algorithm, a second encoding algorithm, and a second security key 4 to be used in the second encoding algorithm.
[0035] As detailed below, both the encoding algorithms and both the security keys are kept stored in the remote processing system 200 by the central authentication software. Furthermore, the first encoding algorithm is also kept stored in the user device 100 by the user software.
[0036] The first security key 2a, 2b is preferably divided into two parts, namely a local key 2a and a remote key 2b. The local key 2a is pre-stored in the user device 100 (as well as in the remote processing system 200), and is therefore kept in its memory before and after the certification and authentication process of a particular data packet 1. The remote key 2b is instead kept in the memory of only the remote processing system 200, but not in the user device 100.
[0037] The remote key 2b must however also be used by the user device 100, as described below, and for this purpose it can be sent from the remote processing system 200 to the user device 100 when necessary, and then be deleted from the user device 100 after its use described below has been completed.
[0038] Preferably, the remote key 2b is generated as a function of a set of user credentials.
[0039] The division of the first security key 2a, 2b increases the security of the system, as the theft of the local key 2a from the user device 100 is not sufficient to falsify the outcome of the method. However, embodiments are not excluded in which the first security key 2a, 2b comprises only the local key 2a or only the remote key 2b.Finally, it is not provided that the user device 100 keeps the second encoding algorithm and the second security key 4 in memory.
[0040] Once the appropriate software, algorithms and security keys are available in the user device 100 and in the remote processing system 200, the actual steps of acquiring and certifying a data packet 1 can be launched by executing the user software on the user device 100.
[0041] The user software, when executed on the user device 100, is configured to perform the series of steps described below, in order of execution with increasing numbering. These steps represent some of the steps of the method of the invention.
[0042] In a step 301 of the method, the user software opens a user interface screen on the user device 100. The user interface is configured to enable the user to acquire or compile a data packet 1.
[0043] In one embodiment, the user interface is configured to enable the user to control the input peripheral 101 of the user device 100 in such a way as to acquire (possibly saving at least temporarily in the user device 100) a data packet 1, which may be one of the types of data packets commented on above, for example by taking a photo.
[0044] In another exemplary embodiment, the user interface is configured to enable the user to compile a document, in particular a text document such as a form, for example by accepting or not accepting contractual conditions or by filling in one or more predetermined fields. In this case too, the data packet 1 can be saved at least temporarily in the user device 100.
[0045] In a step 302 of the method, the user software uses the first encoding algorithm to generate a first hash string 3, based on a predetermined combination of at least the data packet 1, and the first security key 2a, 2b. It is therefore understood that theindividual modification of each element of this combination determines the generation of a different first hash string 3.
[0046] In the embodiments that provide for the remote key 2b, the user software is configured, prior to generating the hash string 3, to query the remote processing system 200 and receive the remote key 2b therefrom.
[0047] It should be noted that the first encoding algorithm is not invertible to go back from the first hash string 3 to the original combination of the data packet 1 and the first security key 2a, 2b used to generate the first hash string 3.
[0048] The first encoding algorithm may have different characteristics depending on the type and / or format of the data packet 1 whose authenticity is to be certified. In the preferred embodiment, in which the data packet 1 is an image file, the first encoding algorithm is configured to generate the first hash string 3 on the basis of a set of colors of the acquired image or, in the case where the data packet 1 is a text document, the first encoding algorithm is configured to generate the first hash string 3 on the basis of a bichromatic color set (letters / b ackground) of the processed document (always in combination with the first security key 2a, 2b).
[0049] The set of colors of an image or bichromy of a text document can be understood, for example, as a function that associates, to each color gradation of a predetermined color domain, a quantity of that gradation contained in the image.
[0050] The set of colors is advantageous, because even the smallest alteration of an image, as well as the correction of a single letter of a text within a document, would lead to a variation of its overall set of colors, and therefore to the generation of a different first hash string 3.Should different files be considered, for example an audio file, an example of a first encoding algorithm could be based (in addition to the first security key 2a, 2b) on a sound spectrum of the audio file. In the case of a text file, an example of a first encoding algorithm could be based (in addition to the first security key 2a, 2b), on a set of characters of the text. Alternatively, still for a text file, an example of a first encoding algorithm could be based (in addition to the first security key 2a, 2b) on the set of colors that would result from a conversion of the text file into an image.
[0051] It is emphasized that the acquired data packet 1 can optionally be accompanied by a metadata packet relating to the acquisition. The metadata packet is generated by the user device 100, in particular by the user software. For example, for an image file, the metadata packet may contain indications of an instant and a place of acquisition, in addition to settings, for example, of the camera during acquisition. Optionally, the metadata is also used by the first encoding algorithm, together with the acquired data packet 1, and the first security key 2a, 2b, to generate the first hash string 3.
[0052] In a step 303 of the method, the user software sends the data packet 1 and the first hash string 3 (optionally together with the metadata packet) from the user device 100 to the remote processing system 200.
[0053] With this step, a first part of the method performed on the user device 100 can be concluded, to move on to a second part of the method performed on the remote processing system 200.
[0054] In particular, when the data packet 1 and the first hash string 3 are received in the remote processing system 200 (step 401), the remote processing system 200 is configured to activate the central authentication software. The central authentication software, when executed, is configured to perform the series of steps described belowin order of execution with increasing numbering. These steps also represent some of the steps of the method of the invention.
[0055] In a step 402, the central authentication software uses the first encoding algorithm with modes analogous to those with which the first encoding algorithm had already been executed by the local software.
[0056] In particular, the central authentication software uses the first encoding algorithm on the same and already described predetermined combination of the data packet 1 and the first security key 2a, 2b. The execution of the first encoding algorithm results in a first hash string candidate 3' which will generally have the same format as the first hash string 3 received from the user device 100. In particular, this first hash string candidate 3' will be identical to the first hash string 3 received only in the case where the data packet 1, the first security key 2a, 2b and the first encoding algorithm used by the user software and by the central authentication software coincide (encoding algorithms are well known for which the probability that two different random data packets result in the same hash string is completely negligible).
[0057] Then, in a step 403, the central authentication software verifies that the first hash string candidate 3' generated by the execution of the first encoding algorithm on the remote processing system 200 corresponds to the first hash string 3 received in the remote processing system 200 from the user device 100.
[0058] If there is no correspondence, the certification process is interrupted. Therefore, to obtain a certification, it will be necessary to start again with the acquisition of a new data packet 1 from the user device 100 (step 301). If instead there is a correspondence, the method proceeds with the steps described below.Thanks to the correspondence check of steps 402-403, there is substantial certainty that the data packet 1 received in the remote processing system 200 has been acquired by means of the user software 100 and has not been subsequently altered after the acquisition or compilation, right by the user software, and therefore corresponds to what was obtained with only the processing functions proper to the user software.
[0059] In fact, if the data packet 1 were altered after the acquisition / compilation and the generation of the first hash string 3 (i.e. after steps 301-302), the central authentication software in step 402 would use as input a different data packet 1, and would generate a different first hash string candidate 3'. This discrepancy would be noted in step 403, and certification with the certifying entity 300 would not be reached.
[0060] If the data packet 1 were acquired with a software different from the user software, for example with the normal camera control software of a smartphone, or by generation with artificial intelligence, and then sent to the remote processing system 200, it would not have any first hash string 3 associated with it, and would not pass at least the verification of step 403 (or in some embodiments it could be rejected a priori for the absence of the first hash string 3, without reaching step 404).
[0061] Only with the knowledge of the first encoding algorithm, and of the first security key 2a, 2b would it be possible to attribute the correct first hash string 3 to a non-authentic data packet 1, to make it pass the verification of step 403, and thus achieve certification.
[0062] To prevent this risk, preferably the computer system may comprise a security system configured to protect and / or change and / or delete the first security key 2a, 2b, the first encoding algorithm and / or the user software or part of it in case of predetermined attempts of abusive access. It is preferable that the security system isactivated for attempts of abusive access both to the user device 100, in particular to the user software, and to the remote processing system 200, in particular to the central authentication software. Therefore, separate security systems can be provided for the user software and for the central authentication software.
[0063] With reference to the central authentication software, preferably the security system is configured to protect and / or change and / or delete also the first and second security key 4, and the first and second encoding algorithm, in case of predetermined attempts of abusive access. In some embodiments, in addition to or as an alternative to protecting and / or changing (and / or deleting) the first and the second security key 2a, 2b, 4, the first and the second encoding algorithm can be protected and / or changed (and / or deleted).
[0064] Various examples of similar security systems of software or hardware type, to prevent the theft of security keys, are well known in the art and therefore will not be further detailed here.
[0065] At the moment when the first security key 2a, 2b and / or the first encoding algorithm are protected and / or changed and / or deleted in any one of the user software and the central authentication software, to proceed with new certifications it will obviously be necessary to restore the identity of the first security key 2a, 2b and of the first encoding algorithm in the two software programs.
[0066] Once the verification of step 403 has been successfully passed, in a step 404 the central authentication software sends to a certifying entity 300 a certification request containing at least the data packet 1. The certifying entity 300 performs a certification of the data packet 1 with legal value, for example a timestamp or a digital seal, and with this certification generates a certification code 5 linked to the data packet1 and a certification date. The certification code 5 is then sent by the certifying entity 300 to the remote processing system 200.
[0067] It should be noted that the certification code 5 can be chosen from various different types of codes deriving from the certification process and generated at the certifying entity 300. In one embodiment, the certification code 5 can be the certification log. In another embodiment, the certification code 5 can be a unix timestamp. In another embodiment, the certification code 5 can be another type of code derived from the certification, in particular a predetermined portion of a certification file sent by the certifying entity 300.
[0068] In a step 405, the central authentication software uses the second encoding algorithm to generate a second hash string 6, on the basis of a predetermined combination of at least the second security key 4, the certification code 5, and at least a content representative of the data packet 1. It is therefore understood that the individual modification of each element of this combination determines the generation of a different second hash string 6.
[0069] Like the first encoding algorithm, the second encoding algorithm is also not invertible to go back from the second hash string 6 to the original combination of at least the second security key 4, of certification 5 and the representative content of the data packet 1.
[0070] Preferably, the content representative of the data packet 1 is the first hash string 3, as received from the user device 100 and confirmed in steps 402-403. In an alternative example, the representative content of the data packet 1 can be the data packet 1 itself, with modes analogous to the first encoding algorithm.The certification code 5 as anticipated is linked to the certification date, and preferably, in a known manner, is generated based on a time and date subject to certification by the accredited certifying entity 300 at the moment of execution of step 404, i.e. precisely at the moment in which the certifying entity 300 processes the data packet 1.
[0071] It can be assumed that generally this date / time will also correspond to the date of reception of the data packet 1 in the remote processing system 200, as well as to the date of acquisition of the data packet 1 from the user device 100, as the moments in which these different steps of the method take place are generally close. Therefore, it can be reasonably considered that the acquisition or compilation of the data packet 1 occurs shortly before the moment of certification linked to the certification code 5.
[0072] Thanks to the fact that the certification code 5 comes from the certifying entity 300, which in turn can retrieve the date from sources considered reliable, and not from the user device 100, the risk that the date of the user device 100 is tampered with to create fictitious certification dates is avoided.
[0073] The second hash string 6 may have substantially the same format as the first hash string 3, or a different format, for example a different number of characters. In general, the second encoding algorithm will be different from the first encoding algorithm as it receives inputs with different formats. For example, the first encoding algorithm receives as input the data packet 1, which will have a different format from the first hash string 3 which can also be an input of the second encoding algorithm in the preferred embodiment. Furthermore, the first and second security key 2a, 2b, 4 do not necessarily have the same format and / or the same number of characters. In addition, the second encoding algorithm receives as input the certification code 5,while in the preferred embodiment the first encoding algorithm receives no equivalent input.
[0074] With step 405 the data packet 1 has been authenticated. Preferably, one proceeds with a step 406 in which the central authentication software stores in the remote processing system 200, in particular in a database 201 of the remote processing system 200, a set of certification information, for its long-term preservation.
[0075] The set of certification information contains at least the second generated hash string 6. In addition, the set of certification information may contain one or more of the certification code 5, the first hash string 3, the data packet 1, a unique identification code of the data packet 1, and the metadata packet linked to the data packet 1.
[0076] In a further step 407, preceding, simultaneous with or subsequent to the storage of the set of certification information, the central authentication software sends a certification information sheet 8 to a user contact address.
[0077] The user contact address can be for example an email address, a telephone contact, or a reserved area accessible through the user software. The user contact address can be provided by the user in a user software setup step, before acquiring the data packet (step 301). The user contact address can also be provided after the data packet has already been authenticated (step 404).
[0078] In some embodiments, the user contact address can simply be an IP address used by the user software to establish the signal communication of the user device 100 with the remote processing system 200. In such a case, sending the certification information sheet 8 allows the user to view the sheet through the user software or through a web browser, and possibly to download or print it.The certification information sheet 8 may contain information of a nature analogous to that which can also be included in the set of certification information stored in the database 201. In particular, the certification information sheet 8 contains at least the second generated hash string 6, and optionally one or more of the certification code 5, the first hash string 3, the data packet 1, a unique identification code of the data packet 1, and the metadata packet linked to the data packet 1.
[0079] It is not necessary, however, that the information contained in the stored set of certification information and in the certification information sheet 8 coincide.
[0080] Following the occurred certification, a third party might be interested in receiving a confirmation that the data packet 1 has been certified and authenticated. In particular, it is provided that the subject who acquired the data packet 1 through the user device 100 shares the data packet 1 and the certification information sheet 8 with a third party. This third party might be interested in receiving an independent confirmation of the certification and authentication.
[0081] Similarly, the subject who initiated the certification through the user software may also be interested in verifying with the same procedure that the certification and authentication have been successful. In general, whoever is interested in this verification will be called an interrogating subject, regardless of whether or not it is the same subject who initiated the certification.
[0082] For this purpose, the computer system preferably comprises a consultation software, stored in the remote processing system 200 and executable by the remote processing system 200. The consultation software can be independent from the central authentication software, or the functions described for these two software programs can be combined into a single software. Despite indicating that the consultationsoftware and the central authentication software are both executed on the remote processing system 200, it is possible that they are executed on physical supports of the remote processing system 200 that are distinct and independent from each other, for example two different servers, or a server and a cloud.
[0083] In the preferred embodiment, the consultation software comprises a consultation web page 9, configured for the insertion of certification confirmation requests. The consultation web page 9 can be accessible for example through the user software or a web browser.
[0084] The consultation software, when executed on the remote processing system 200, is configured to perform the series of steps described below in order of execution with increasing numbering. These steps can represent a third part of the method of the invention.
[0085] In a step 501, the consultation software receives from an interrogating subject a request for certification and authentication confirmation, in particular through the consultation web page 9.
[0086] In order to simplify the request for the interrogating subject, and to prevent them from obtaining a false confirmation on a deceptive web page, it is preferable that the certification information sheet 8 comprises a consultation link 7, configured to direct to the consultation web page 9. In this way, the interrogating subject, upon receiving the certification information sheet 8, will also find in it a direct way to access the correct consultation web page 9 and insert their request.
[0087] In the preferred embodiment, the verification requested by the interrogating subject through the consultation web page 9 can start from what is indicated on the sheet 8 as the second hash string 6, or what has in any case been presented to theinterrogating subject as the second hash string 6. The interrogating subject cannot be certain from the outset that this information is a true second hash string 6, nor that it is linked to the correct data packet 1. Therefore, this information will be indicated hereinafter as a second hash string candidate 6', which may or may not correspond to the real second hash string 6.
[0088] The request for certification and authentication confirmation contains at least the second hash string candidate 6'. In some embodiments, the request for certification and authentication confirmation may also contain other information, such as the first hash string 3, the certification code 5, the data packet 1, the metadata packet, and the unique identification code.
[0089] In a step 502, the consultation software verifies the authenticity of the second hash string candidate 6'.
[0090] In the preferred embodiment, the authenticity verification of step 502 comprises, or consists in, verifying whether the second hash string candidate 6' corresponds to the second hash string 6 included in one of the sets of certification information, kept in memory in the remote processing system 200.
[0091] In a step 503, the consultation software provides the interrogating subject with an outcome of the verification. Where the second hash string candidate 6' does not correspond to any second hash string 6 already in memory, the consultation software does not confirm the occurred certification and authentication. If, on the other hand, the second hash string candidate 6' actually corresponds to a second hash string 6, already stored, the outcome of the verification is positive.
[0092] In the case of a positive outcome, the communication to the interrogating subject of the positive outcome may be accompanied by one or more of the pieces ofinformation contained in the stored set of certification and authentication information, in particular by a preview of the data packet 1, for check by the interrogating subject.
[0093] In alternative embodiments, step 502 may provide for other types of verifications on the authenticity of the second hash string candidate 6' and on its correspondence to the data packet 1. For example, it can be verified whether there is a correspondence between other data joined to the certification confirmation request and the corresponding data included in the stored set of certification information.
[0094] Obviously, a person skilled in the art may make numerous equivalent modifications to the variants described above, without thereby departing from the scope of protection defined by the appended claims.
Claims
CLAIMS1. A computer system for certifying the authenticity of a data packet (1) acquired or compiled by a user electronic device (100), comprising:- a user software, executable by a user electronic device (100), and configured, when executed by the user device (100), to:- keep in memory in the user device (100) a first encoding algorithm,- open a user interface to enable the user to acquire or compile a data packet (1), - use the first encoding algorithm to generate a first hash string (3), based on a predetermined combination of the data packet (1) and a first security key (2a, 2b),- send the data packet (1) and the first hash string (3) from the user device (100) to a remote processing system (200), which may also be composed of multiple servers and / or a cloud,- a central authentication software, executable by the remote processing system (200), and configured, when executed by the remote processing system (200), to:- keep in memory the first encoding algorithm, the first security key (2a, 2b), a second encoding algorithm and a second security key (4),- upon reception in the remote processing system (200) of the data packet (1) and the first hash string (3), use the first encoding algorithm on the predetermined combination of the data packet (1) and the first security key (2a, 2b), to verify that a first hash string candidate (3') is generated that corresponds to the first hash string (3) received in the remote processing system (200),- in the event of a successful verification, send to a certifying entity (300) a certification request containing the data packet (1), and receive from the certifying entity (300) a certification code (5) linked to the data packet (1) and to a certification date,- use the second encoding algorithm to generate a second hash string (6), based on a predetermined combination of:- the second security key (4),- the certification code (5), and- optionally, at least one or more of the first hash string (3) and the data packet (1), preferably the first hash string (3), and- send to a user contact address a certification information sheet (8), containing at least the generated second hash string (6).
2. The computer system according to claim 1, wherein the first security key (2a, 2b) comprises a local key (2a), pre-stored in the user device (100), and / or a remote key (2b), received in the user device (100) from the remote processing system (200); wherein the remote key (2b) is preferably generated as a function of a set of user credentials.
3. The computer system according to claim 1 or 2, wherein the central authentication software is further configured to keep in memory in the remote processing system (200) a set of certification information, containing at least the generated second hash string (6).
4. The computer system according to any one of claims 1 to 3, comprising a consultation software, executable by the remote processing system (200), and configured, when executed by the remote processing system (200), to:- receive from an interrogating subject a request for authenticity confirmation, containing at least a second hash string candidate (6'),- verify the authenticity of the second hash string candidate (6'), and provide the interrogating subject with an outcome of the verification, preferably together with a preview of the data packet (1).
5. The computer system according to the combination of claims 3 and 4, wherein verifying the authenticity of the second hash string candidate (6') comprises verifying whether the second hash string candidate (6') corresponds to the second hash string (6) included in one of the sets of certification information kept in memory in the remote processing system (200).
6. The system according to claim 4 or 5, wherein:- the consultation software comprises a consultation web page (9), configured for the insertion of certification confirmation requests, and- the certification information sheet (8) further comprises a consultation link (7), configured to direct to the consultation web page (9).
7. The system according to any one of claims 1 to 6, wherein the certification information sheet (8) and / or the set of certification information further contain at least one of:- the certification code (5),- the first hash string (3), and- the data packet (1).
8. The system according to any one of claims 1 to 7, wherein:- the user interface is a control interface of a video camera, a microphone or a text document processing interface,- the data packet (1) is an image file acquired by the video camera, an audio file acquired by the microphone, a video file with audio acquired by the video camera and microphone or a processed text document or a compiled form, and- the first encoding algorithm is configured to generate the first hash string (3) based on a predetermined combination of a set of colors of the acquired image or of the processed text document, or an audio track of the audio file and of the first security key (2a, 2b).
9. The system according to any one of claims 1 to 8, comprising a security system configured to protect, change and / or delete at least one of the first security key (2a, 2b), the second security key (4), the first encoding algorithm and the second encoding algorithm in case of predetermined attempts of abusive access in the user device (100) and / or in the remote system (200).
10. The system according to any one of claims 1 to 9, wherein the first and second encoding algorithms are not invertible to respectively go back from the first and secondhash string (3, 6) to the respective predetermined combinations of data used to generate the first and second hash string (3, 6).
11. The system according to any one of claims 1 to 10, comprising said user device (100), which has stored said user software, and said remote processing system (200), which has stored said central authentication software.
12. A method for certifying the authenticity of a data packet (1) acquired from a user electronic device (100), comprising:- keeping in memory in a user device (100) a first encoding algorithm and at least a portion of a first security key (2a),- keeping in memory in a remote processing system (200), which is remote with respect to the user device (100), the first encoding algorithm, a first security key (2a, 2b), a second encoding algorithm and a second security key (4),- executing a user software on the user device (100),- opening a user interface by the user software, and receiving, through the user interface, a command for acquiring or compiling a data packet (1),- using the first encoding algorithm, by the user software, to generate a first hash string (3), on the basis of a predetermined combination of the data packet (1), and of the first security key (2a, 2b),- sending the data packet (1) and the first hash string (3) from the user device (100) to the remote processing system (200),- executing in the remote processing system (200) a central authentication software,- upon reception in the remote processing system (200) of the data packet (1) and the first hash string (3), using the first encoding algorithm, by the central authentication software, on the predetermined combination of the data packet (1), and of the first security key (2a, 2b), to verify that a first hash string candidate (3') is generated that corresponds to the first hash string (3) received in the remote processing system (200), - in the event of a successful verification, sending to a certifying entity (300) a certification request containing the data packet (1),- receiving from the certifying entity (300) a certification code (5) linked to the data packet (1) and to a date and time of certification,- using the second encoding algorithm, by the central authentication software, to generate a second hash string (6), on the basis of a predetermined combination of:- the second security key (4),- the certification code (5), and- optionally, at least one or more of the first hash string (3) and the data packet (1), preferably the first hash string (3), and- sending to a user contact address a certification information sheet (8), containing at least the generated second hash string (6) to subsequently allow also a third party to verify the originality of the data packet (1) certified through the remote processing system (200).