Information processing device, method for controlling information processing device, and program
Patent Information
- Application Number
- PCT/JP2026/010663
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-26
- Filing Date
- 2026-03-18
- Publication Date
- 2026-10-01
Smart Images

Figure JP2026010663_01102026_PF_FP_ABST
Abstract
Description
Information processing apparatus, control method for information processing apparatus, and program
[0001] The present disclosure relates to an information processing apparatus, a control method for an information processing apparatus, and a program.
[0002] In recent years, information sharing via the Internet has been actively conducted, and anyone can publish and transmit various pieces of information to unspecified large numbers of people. Furthermore, various types of processing can now be performed on digital images. In such circumstances, there is a possibility that information may be transmitted from sources whose reliability is not ensured, or that public information may be tampered with illegally.
[0003] Accordingly, there has been conventionally known a means for verifying tampering of image data by generating a hash value for captured image data and adding the generated hash value to the image data when an image is captured in a tampering prohibition mode using a digital camera (see Patent Document 1). Additionally, in order to authenticate the source, process, or provenance of an image, it has been proposed to add metadata indicating editing content of the image to the image data (see Non-Patent Document 1).
[0004] Japanese Unexamined Patent Application Publication No. 2008-5421
[0005] Coalition for Content Provenance and Authenticity (C2PA), "C2PA Specifications", <Technical Specifications Version 1.2>, (online), November 3, 2022, (searched January 23, 2023), Internet <URL:https: / / c2pa.org / specifications / specifications / 1.2 / specs / C2PA_Specification.html>
[0006] According to the technology described in Patent Document 1, a user can determine whether or not an image has been tampered with. However, Patent Document 1 does not mention referencing and resetting excluded areas that have been excluded from the tampering verification process during image editing. Furthermore, according to the technology described in Non-Patent Document 1, by adding metadata from the moment the subject was photographed as its history to the captured image data, a user can refer to the metadata to learn about the edits made to the image data. In addition, when adding new history information to image data, it is mentioned that the reliability of the image data should be ensured by confirming that the image data has not been tampered with before adding the new history information. A function to specify areas within an image file that are not included in the tampering verification process is also mentioned. However, similar to Patent Document 1, it does not mention referencing and resetting previously specified excluded areas when editing image data.
[0007] According to conventional techniques, unreliable data that was previously excluded from a history history may be included in areas outside the excluded area in a new history history. If tampering verification is performed in such cases, it may be incorrectly determined that tampering has occurred. Therefore, the reliability of the tampering verification results is reduced.
[0008] This disclosure has been made in view of at least one of the above-mentioned problems, and provides a technology that can ensure the reliability of the verification results for tampering with image data when processing information for image data is newly recorded.
[0009] According to one aspect of this disclosure, the information processing device comprises a processing unit that performs processing on image data, and a recording control unit that controls the recording of data including processing information performed by the processing unit, wherein the data includes excluded areas that are excluded from verification of tampering with the image data, and the recording control unit controls the recording of new excluded areas in the data using previously recorded excluded areas when the processing unit performs the processing.
[0010] According to this disclosure, when processing information for image data is newly recorded, the reliability of the verification results for tampering with image data can be ensured.
[0011] Other features and advantages of the technical ideas derived from this disclosure will become apparent from the following description with reference to the attached drawings. In the attached drawings, the same or similar components are given the same reference numeral.
[0012] The attached drawings are included in the specification and constitute part thereof, illustrating embodiments in this disclosure and are used together with the description to explain the technical ideas derived from this disclosure.
[0013] Schematic diagram of a digital camera according to one embodiment Schematic diagram of a digital camera according to one embodiment Block diagram of each component according to one embodiment Flowchart of processing according to one embodiment Flowchart of processing according to one embodiment Flowchart of processing according to one embodiment Flowchart of processing according to one embodiment Explanation of the data structure according to one embodiment Explanation of the data structure according to one embodiment Flowchart of processing according to one embodiment Flowchart of processing according to one embodiment Flowchart of processing according to one embodiment
[0014] The embodiments will be described in detail below with reference to the attached drawings. Note that the following embodiments do not limit the scope of the claims. While the embodiments describe multiple features, not all of these features are necessary, and the features may be combined in any way. Furthermore, in the attached drawings, identical or similar configurations are given the same reference numerals, and redundant descriptions are omitted.
[0015] (Embodiment) <External View of Digital Camera 100> The external view of the digital camera 100 (imaging device) will be described using Figures 1A and 1B. Figure 1A is an example of a front perspective view of the digital camera 100, and Figure 1B is an example of a rear perspective view of the digital camera 100.
[0016] The digital camera 100 is comprised of a display unit 28, a touch panel 70a, an external display unit 43, a shutter button 61, a mode selector switch 60, and a terminal cover 40.
[0017] The display unit 28 is a display unit located on the back of the digital camera 100 and displays images and various information. The touch panel 70a is located on the display surface (touch operation surface) of the display unit 28 and can detect touch operations on this display surface. The viewfinder-external display unit 43 is a display unit located on the top surface of the digital camera 100 and displays various settings of the digital camera 100, including shutter speed and aperture. The shutter button 61 is an operation part for giving shooting instructions. The mode selector switch 60 is an operation part for switching between various modes. The terminal cover 40 is a cover that protects the connector (not shown) for connecting the digital camera 100 to an external device, such as a connecting cable.
[0018] The digital camera 100 also consists of a main electronic dial 71, a power switch 72, a sub-electronic dial 73, a four-way key 74, and a SET button 75. The main electronic dial 71 is a rotary control part, and by rotating it, settings such as shutter speed and aperture can be changed. The power switch 72 is an operating part that switches the power of the digital camera 100 ON and OFF. The sub-electronic dial 73 is a rotary control part, and by rotating it, the selection frame (cursor) can be moved and images can be advanced. The four-way key 74 is configured so that the up, down, left, and right parts can each be pressed, and processing is executed according to the part of the four-way key 74 that is pressed. The SET button 75 is a push button and is mainly used to confirm selection items.
[0019] The digital camera 100 also includes a video button 76, an AE lock button 77, a zoom button 78, a playback button 79, and a menu button 81. The video button 76 is used to instruct the start and stop of video recording. The AE lock button 77 is a push button, and by pressing the AE lock button 77 in the shooting standby state, the exposure state can be fixed. The zoom button 78 is an operation button for switching the zoom mode ON and OFF in the live view display (LV display) of the shooting mode. By turning the zoom mode ON and then operating the main electronic dial 71, the live view image (LV image) can be enlarged or reduced. In playback mode, the zoom button 78 functions as an operation button for enlarging the playback image and increasing the magnification ratio.
[0020] The playback button 79 is an operation button for switching between shooting mode and playback mode. By pressing the playback button 79 while in shooting mode, the camera switches to playback mode, and the latest image recorded on the recording medium 200 (described later) can be displayed on the display unit 28. The menu button 81 is a push button used to instruct the display of the menu screen. When the menu button 81 is pressed, a menu screen with various settings is displayed on the display unit 28. The user can intuitively make various settings using the menu screen displayed on the display unit 28, the four-way key 74, and the SET button 75.
[0021] Furthermore, the digital camera 100 is comprised of a touch bar 82. The touch bar 82 (multifunction bar: M-Fn bar) is a line-shaped touch operation part (line touch sensor) capable of receiving touch operations. The touch bar 82 is positioned so that it can be touched by the right thumb when the grip part 90 is held with the right hand (held with the little finger, ring finger, and middle finger of the right hand) so that the shutter button 61 can be pressed with the right index finger. In other words, the touch bar 82 is positioned so that it can be operated when the user is looking through the viewfinder with their eyepiece 16 and is ready to press the shutter button 61 at any time (shooting posture). The touch bar 82 is a reception part that can receive tap operations (operations where the user touches the touch bar and releases it within a predetermined period without moving it), and sliding operations (operations where the user touches the touch bar and then moves the touch position while keeping it touched). The touch bar 82 is a different operation part from the touch panel 70a and does not have a display function.
[0022] The digital camera 100 also includes a communication terminal 10, an eyepiece 16, an eyepiece viewfinder 17, an eyepiece detection unit 57, a cover 202, a grip unit 90, and a thumb rest unit 91. The communication terminal 10 is a communication terminal for the digital camera 100 to communicate with the lens unit 150 (which will be described later as being detachable). The eyepiece 16 is the eyepiece of the eyepiece viewfinder 17 (a look-through type viewfinder). The user can view the image displayed on the internal EVF 29 (Electronic View Finder) through the eyepiece 16. The digital camera 100 also includes a speaker 92 and a light-emitting unit 102.
[0023] The eyepiece detection unit 57 is an eyepiece detection sensor that detects whether or not a user (photographer) is looking through the eyepiece unit 16. The cover 202 is the cover of the slot for storing the recording medium 200 (described later). The grip unit 90 is a holding part shaped to be easy for the user to grip with their right hand when holding the digital camera 100. With the user holding the digital camera 100 by gripping the grip unit 90 with their right little finger, ring finger, and middle finger, the shutter button 61 and the main electronic dial 71 are positioned to be operated by the right index finger. Also, in the same position, the sub electronic dial 73 and the touch bar 82 are positioned to be operated by the user's right thumb. The thumb rest unit 91 (thumb waiting position) is a grip part provided on the back side of the digital camera 100 in a place where the user can easily rest their right thumb when gripping the grip unit 90 without operating any of the other operating parts. The thumb rest unit 91 is made up of rubber or the like to enhance the holding force (grip feel).
[0024] <Functional Blocks of Digital Camera 100 and Lens Unit 150> The functional blocks of the digital camera 100 and the lens unit 150 attached to the digital camera 100 will be explained using Figure 2. The lens unit 150 includes an aperture 1, an aperture drive circuit 2, an AF drive circuit 3, a lens system control circuit 4, a communication terminal 6, and a lens 103. The digital camera 100 also includes a communication terminal 10 and a system control unit 50 (an example of a "recording control unit").
[0025] The lens unit 150 is a lens unit equipped with an interchangeable photographic lens. The lens 103 is usually composed of multiple lenses, but in Figure 2, for simplicity, only a single lens is shown as an example. The communication terminal 6 is provided on the lens unit 150 and is a communication terminal for the lens unit 150 to communicate with the digital camera 100. On the other hand, the communication terminal 10 is provided on the digital camera 100 and is a communication terminal for the digital camera 100 to communicate with the lens unit 150. The lens unit 150 communicates with the system control unit 50 via these communication terminals (6, 10). The lens unit 150 controls the aperture 1 via the aperture drive circuit 2 using an internal lens system control circuit 4. The lens unit 150 also focuses on the subject by displacing the position of the lens 103 via the AF drive circuit 3 using the lens system control circuit 4.
[0026] The digital camera 100 also includes a shutter 101, an imaging unit 22, an A / D converter 23, an image processing unit 24, a memory control unit 15, a memory 32, a system memory 52, and a non-volatile memory 56. The digital camera 100 also includes a display unit 28, an EVF 29, a D / A converter 19, and a system timer 53.
[0027] The shutter 101 is a focal-plane shutter that allows the exposure time of the imaging unit 22 to be freely controlled by the system control unit 50. The imaging unit 22 is an image sensor that includes a CCD or CMOS element, etc., which converts an optical image into an electrical signal. The imaging unit 22 may also have an imaging plane phase difference sensor that outputs defocus amount information to the system control unit 50. The A / D converter 23 converts the analog signal output from the imaging unit 22 into a digital signal.
[0028] The image processing unit 24 performs predetermined processing (such as pixel interpolation, resizing, or color conversion) on the data from the A / D converter 23 or the data from the memory control unit 15. The image processing unit 24 also performs predetermined calculations using the captured image data. The system control unit 50 then uses the calculation results obtained by the image processing unit 24 to perform exposure control and distance measurement control. This enables TTL (through-the-lens) AF (autofocus), AE (automatic exposure), or EF (flash pre-flash) processing. The image processing unit 24 further performs predetermined calculations using the captured image data and uses the obtained calculation results to perform TTL (auto white balance) processing.
[0029] The output data from the A / D converter 23 is written to the memory 32 via the image processing unit 24 and the memory control unit 15. Alternatively, the output data from the A / D converter 23 is written to the memory 32 via the memory control unit 15 without going through the image processing unit 24. The memory 32 stores image data obtained by the imaging unit 22 and converted into digital data by the A / D converter 23, as well as image data for display on the display unit 28 and EVF 29. The memory 32 has sufficient storage capacity to store a predetermined number of still images, as well as moving images and audio for a predetermined period of time.
[0030] Furthermore, memory 32 also functions as a memory (video memory) for image display. The D / A converter 19 converts the image display data stored in memory 32 into an analog signal and supplies it to the display unit 28 and EVF 29. In this way, the display image data written to memory 32 is displayed by the display unit 28 and EVF 29 via the D / A converter 19. The display unit 28 and EVF 29 are displays such as LCDs and OLEDs, respectively, and perform display according to the analog signal from the D / A converter 19. The digital signal that has been A / D converted by the A / D converter 23 and stored in memory 32 is converted into an analog signal by the D / A converter 19. The converted analog signal is then sequentially transferred to the display unit 28 or EVF 29 and displayed, enabling live view display (LV). Hereinafter, the image displayed in live view display will also be referred to as a live view image (LV image).
[0031] The system control unit 50 is a control unit comprising at least one processor and / or at least one circuit, and controls the entire digital camera 100. The system control unit 50 is both a processor and a circuit. The system control unit 50 executes programs recorded in the non-volatile memory 56 to perform the processes described later. The system control unit 50 also performs display control by controlling the memory 32, D / A converter 19, display unit 28, EVF 29, etc.
[0032] The system memory 52 is, for example, RAM. The system control unit 50 loads constants and variables for the operation of the system control unit 50, as well as programs read from the non-volatile memory 56, into the system memory 52. The non-volatile memory 56 is an electrically erasable and recordable memory, such as an EEPROM. Constants and programs for the operation of the system control unit 50 are stored in the non-volatile memory 56. The program referred to here is, for example, a program for executing various flowcharts, which will be described later. The system timer 53 is a timing unit that measures the time used for various controls and the time of the built-in clock.
[0033] The digital camera 100 also includes a communication unit 54, an attitude detection unit 55, an eyepiece detection unit 57, a GPS receiver 119, a hash value generation unit 210, an external viewfinder display unit 43, an external viewfinder display unit drive circuit 44, a power control unit 80, a power supply unit 30, and a recording medium interface 18.
[0034] The communication unit 54 is configured to include a communication module and transmits and receives video and audio signals to and from external devices connected by wireless or wired cables. The communication unit 54 can also connect to wireless LANs (Local Area Networks) and the internet. Furthermore, the communication unit 54 can communicate with external devices using Bluetooth® and Bluetooth Low Energy. The communication unit 54 can transmit images (including LV images) captured by the imaging unit 22 and images recorded on the recording medium 200, and can also receive various information such as image data and video recording start instructions from external devices. In addition, when the communication unit 54 receives a video recording start instruction from an external device, the system control unit 50 can notify the user of the instruction by illuminating the light-emitting unit 102 or emitting an electronic sound from the speaker 92. Examples of external devices with which the communication unit 54 communicates include smartphones, tablet PCs, and desktop PCs.
[0035] The attitude detection unit 55 detects the attitude of the digital camera 100 relative to the direction of gravity. The system control unit 50 can use the attitude detected by the attitude detection unit 55 to determine whether the image captured by the imaging unit 22 was taken with the digital camera 100 held horizontally or vertically. The system control unit 50 can add orientation information corresponding to the attitude detected by the attitude detection unit 55 to the image file of the image captured by the imaging unit 22, or rotate the image before recording. An acceleration sensor or a gyro sensor can be used as the attitude detection unit 55. When using such an acceleration sensor or gyro sensor, it is also possible to detect the movement of the digital camera 100 (pan, tilt, lift, or whether it is stationary or not).
[0036] The eyepiece detection unit 57 is an eyepiece detection sensor that detects the approach (eye-to-eye contact) and retraction (eye-away) of an eye (object) to the eyepiece section 16 of the eyepiece viewfinder 17 (hereinafter simply referred to as "viewfinder"). The system control unit 50 switches the display (display state) / hidden (hidden state) of the display unit 28 and the EVF 29 according to the state detected by the eyepiece detection unit 57. More specifically, at least in the shooting standby state and when the display destination switching setting is set to automatic switching, the system control unit 50 turns on the display of the display unit 28 as the display destination and hides the EVF 29 when the eye is not being used. Also, when the eye is being used, the system control unit 50 turns on the display of the EVF 29 as the display destination and hides the display unit 28.
[0037] For example, an infrared proximity sensor can be used as the eyepiece detection unit 57. In this case, the eyepiece detection unit 57 can detect the approach of any object to the eyepiece section 16 of the eyepiece finder 17 which incorporates the EVF 29. When an object approaches, infrared light emitted from the light emitter (not shown) of the eyepiece detection unit 57 is reflected by the object and received by the light receiver (not shown) of the infrared proximity sensor. The eyepiece detection unit 57 can also determine how close the object is to the eyepiece section 16 (eyepiece distance) based on the amount of infrared light received. In this way, the eyepiece detection unit 57 performs eyepiece detection to detect the proximity distance of an object to the eyepiece section 16.
[0038] The eyepiece detection unit 57 detects that an object has been placed under the eyepiece when it detects an object approaching the eyepiece unit 16 within a predetermined distance from a non-eyepiece state (not close state). On the other hand, the eyepiece detection unit 57 detects that an object has been removed from the eyepiece when it moves beyond a predetermined distance from an eyepiece state (close state). The threshold for detecting eye placement and the threshold for detecting eye removal may be different, for example, by providing hysteresis. After detecting eye placement, the eyepiece state is considered to be the eyepiece state until eye removal is detected. After detecting eye removal, the eyepiece state is considered to be the non-eyepiece state until eye placement is detected again. Note that the infrared proximity sensor is just one example, and other sensors that can detect a state that can be considered as eye placement may be used as the eyepiece detection unit 57.
[0039] The GPS receiver 119 includes a GPS module and receives GPS information from GPS satellites for calculating location and time information. The system control unit 50 receives GPS information from the GPS receiver 119 and calculates location and time information based on the received GPS information. The system control unit 50 can then add this calculated location and time information to the captured image.
[0040] The hash value generation unit 210 generates (calculates) a hash value by executing a hash function on the image file. Alternatively, the system control unit 50 may generate the hash value instead of the hash value generation unit 210. Details of the hash value generation process will be described later. The viewfinder external display unit 43 displays various camera settings, including shutter speed and aperture, via the viewfinder external display unit drive circuit 44.
[0041] The power control unit 80 is configured to include a battery detection circuit, a DC-DC converter, a switch circuit for switching which blocks are energized, and detects whether a battery is installed, the type of battery, and the remaining battery level. The power control unit 80 also controls the DC-DC converter using the detection results and instructions from the system control unit 50 to supply the necessary voltage to each part, including the recording medium 200, for the required period of time. The power supply unit 30 includes primary batteries such as alkaline batteries and lithium batteries, secondary batteries such as NiCd batteries, NiMH batteries and Li batteries, and an AC adapter. The recording medium I / F 18 is an interface with the recording medium 200, such as a memory card or hard disk. The recording medium 200 is a storage medium such as a memory card for recording captured images, and includes semiconductor memory and magnetic disks.
[0042] Furthermore, the digital camera 100 includes an operation unit 70. The operation unit 70 is an input unit that accepts an operation from a user (user operation), and is used for inputting various operation instructions to a system control unit 50. Furthermore, as shown in Figure 2, the operation unit 70 includes a shutter button 61, a mode switch 60, a power switch 72, a touch panel 70a, other operation parts 70b, and the like. The other operation parts 70b include, for example, a main electronic dial 71, a sub electronic dial 73, a four-way key 74, a SET button 75, a movie button 76, an AE lock button 77, an enlargement button 78, a playback button 79, a menu button 81, a touch bar 82, and the like.
[0043] The shutter button 61 further includes a first shutter switch 62 and a second shutter switch 64. The first shutter switch 62 is turned on when the shutter button 61 is halfway pressed (shooting preparation instruction) in the middle of operation, and generates a first shutter switch signal SW1. By detecting the first shutter switch signal SW1, the system control unit 50 starts shooting preparation operations such as AF (autofocus) processing, AE (automatic exposure) processing, AWB (auto white balance) processing, or EF (pre-flash) processing.
[0044] The second shutter switch 64 is turned on when the operation of the shutter button 61 is completed, that is, when the shutter button 61 is fully pressed (shooting instruction), and generates a second shutter switch signal SW2. By detecting the second shutter switch signal SW2, the system control unit 50 starts a series of shooting processing operations from reading a signal from the imaging unit 22 to writing a captured image as an image file to a recording medium 200.
[0045] The mode switch 60 switches the operating mode of the system control unit 50 to one of the following: still image shooting mode, video shooting mode, and playback mode. Modes included in the still image shooting mode include auto shooting mode, auto scene detection mode, manual mode, aperture priority mode (Av mode), shutter speed priority mode (Tv mode), and program AE mode (P mode). In addition, various scene modes and custom modes that specify shooting settings for different shooting scenes can be set. The user can switch directly to any of these modes using the mode switch 60. Alternatively, the user may switch to a list screen of shooting modes using the mode switch 60, and then selectively switch to one of the displayed modes using other control parts. Similarly, the video shooting mode may also include multiple modes. The mode switch 60 can also be switched to a tamper-proof mode to prevent tampering with captured image data.
[0046] The touch panel 70a is a touch sensor that detects various touch operations on the display surface of the display unit 28 (the operating surface of the touch panel 70a). The touch panel 70a and the display unit 28 can be configured as an integrated unit. For example, the touch panel 70a is configured such that its light transmittance does not interfere with the display of the display unit 28, and is mounted on the upper layer of the display surface of the display unit 28. Then, the input coordinates on the touch panel 70a are associated with the display coordinates on the display surface of the display unit 28. This makes it possible to provide a GUI (Graphical User Interface) that makes it seem as if the user can directly operate the screen displayed on the display unit 28.
[0047] The system control unit 50 can detect the following operations or states on the touch panel 70a.
[0048] ・A finger or a pen that was not touching touch panel 70a newly touches touch panel 70a, that is, the start of a touch (hereinafter also referred to as Touch-Down) ・A state in which a finger or a pen is touching touch panel 70a (hereinafter also referred to as Touch-On) ・A finger or a pen is moving while keeping touching touch panel 70a (hereinafter also referred to as Touch-Move) ・A finger or a pen that has been touching touch panel 70a leaves (is released from) touch panel 70a, that is, the end of a touch (hereinafter also referred to as Touch-Up) ・A state where nothing is touching touch panel 70a (hereinafter also referred to as Touch-Off)
[0049] When a touch-down is detected, a touch-on is also detected at the same time. After a touch-down, unless a touch-up is detected, normally a touch-on continues to be detected. Even when a touch-move is detected, a touch-on is also detected at the same time. Even if a touch-on is detected, no touch-move is detected if the touch position does not move. After it is detected that all touching fingers or pens have been touched up, the state becomes touch-off.
[0050] These operations and states, as well as the position coordinates of the position where a finger or a pen touches on the touch panel 70a, are notified to the system control unit 50 via an internal bus. Then, the system control unit 50 uses the notified information to determine whether what kind of operation (touch operation) has been performed on the touch panel 70a.
[0051] More specifically, with respect to a touch-move, the system control unit 50 can also determine the moving direction of a finger or a pen moving on the touch panel 70a for each of a vertical component and a horizontal component on the touch panel 70a using changes in position coordinates. The system control unit 50 shall determine that a slide operation has been performed when it is detected that a touch-move over a predetermined distance has been performed.
[0052] By the way, the operation of touching the touch panel 70a, moving your finger quickly a certain distance, and then releasing it is called a flick. In other words, a flick is an operation of quickly tracing the touch panel 70a with your finger as if flicking it. When a touch move of a predetermined distance or more at a predetermined speed or more is detected, and a touch-up is detected immediately afterward, the system control unit 50 can determine that a flick has been performed (it can determine that a flick followed a slide operation).
[0053] Furthermore, touching multiple points (for example, two points) simultaneously (multitouch) to bring them closer together is called pinch-in, and touching them further apart is called pinch-out. Pinch-out and pinch-in are collectively referred to as pinch operations (or simply pinch).
[0054] The touch panel 70a may be of any of the following types: resistive, capacitive, surface acoustic wave, infrared, electromagnetic induction, image recognition, and optical sensor. The operation detection method may also be any of the following: for example, a method that detects a touch when there is contact with the touch panel, or a method that detects a touch when a finger or pen approaches the touch panel.
[0055] Using Figure 3, a flowchart of the main process for changing the image tampering prevention setting, setting the setting, capturing a still image, and editing the image will be explained. Although this process is illustrated with still image capture, it may also be applied to video capture. This process is realized when the power switch 72 is turned on, and the system control unit 50 loads the program stored in the non-volatile memory 56 into the system memory 52 and executes it.
[0056] In S301, the system control unit 50 detects a touch operation using the touch panel 70a. The system control unit 50 then determines whether a setting instruction to change the tamper-proof mode to "on" has been given. If the system control unit 50 determines that a setting instruction to change the tamper-proof mode to "on" has been given, the process proceeds to S302; otherwise, the process proceeds to S303. At this time, if shooting is performed with the tamper-proof mode "on," the captured image data will include provenance information 603. Therefore, changes can be detected using the hash and signature value mechanisms described later, and malicious tampering can be prevented. On the other hand, if shooting is performed with the tamper-proof mode "off," the image data will not include provenance information 603.
[0057] In S302, the system control unit 50 changes the setting of the tamper-proof mode to ON and stores this setting information in the memory 32. Then, the process proceeds to S304. On the other hand, in S303, the system control unit 50 changes the setting of the tamper-proof mode to OFF and stores this setting information in the memory 32. Then, the process proceeds to S304. In S304, the system control unit 50 detects whether or not a still image capture instruction has been given by detecting the pressing of the shutter button 61, etc. If the system control unit 50 determines that a still image capture instruction has been given, the process proceeds to S305; otherwise, the process proceeds to S306.
[0058] In S305, the system control unit 50 starts the still image capture process, which will be described later using Figure 4. After the still image capture process is completed, the process proceeds to S306. In S306, the system control unit 50 determines whether a change instruction has been made to enable the exclusion area setting by referring to past history information. If the system control unit 50 determines that a change instruction has been made, the process proceeds to S307; otherwise, the process proceeds to S308.
[0059] In S307, the system control unit 50 enables the exclusion area setting by referring to past history information and stores this setting information in the memory 32. Then, the process proceeds to S309. On the other hand, in S308, the system control unit 50 disables the exclusion area setting by referring to past history information and stores this setting information in the memory 32. Then, the process proceeds to S309.
[0060] In S309, the system control unit 50 determines whether an image editing instruction has been given in a mode such as playback mode. If the system control unit 50 determines that an image editing instruction has been given, the process proceeds to S310; otherwise, the process proceeds to S311.
[0061] In S310, the system control unit 50 starts the image editing process described later using Figure 9. After the image editing process is completed, the process proceeds to S311. In S311, the system control unit 50 determines whether or not a main processing termination instruction has been given by detecting the operation of pressing the power switch 72, etc. If the system control unit 50 determines that a main processing termination instruction has been given, the process ends; otherwise, the process returns to S301.
[0062] The detailed procedure for the still image capture process in S305 will be explained using Figure 4. Figure 4 illustrates the process of generating a still image file during capture. This process starts when the system control unit 50 receives a capture start operation, such as pressing the shutter button 61, and ends when it receives a capture end operation, such as canceling the pressing of the shutter button 61. The capture process is a series of processes in which image data 604 expanded in the system memory 52 is given or processed with capture information 602 and history information 603, etc., to generate an image file that cannot be tampered with. This process is realized when the system control unit 50 expands a program stored in the non-volatile memory 56 into the system memory 52 and executes it.
[0063] In S401, the system control unit 50 drives the shutter 101, which is positioned on the subject side of the imaging unit 22, to control the exposure time. In S402, the system control unit 50 performs imaging processing to convert the light reflected from the subject and received by the imaging unit 22 via the shutter 101 into an electrical signal (analog image data). In S403, the system control unit 50 performs image processing such as development processing and encoding processing on the electrical signal obtained by the imaging processing in S402 to generate image data (an example of "imaging data").
[0064] In S404, the system control unit 50 generates metadata 601 as shown in Figure 6A. The metadata 601 includes imaging information 602 (an example of "imaging information") and history information 603 of the image data 604.
[0065] More specifically, the shooting information 602 is information obtained when the imaging process for generating the image data 604 is performed. That is, the shooting information 602 includes, for example, the date and time of shooting, the photographer, the image size, the manufacturer and model of the imaging device, various shooting parameters set at the time of shooting, the shooting location, and a thumbnail image. The shooting information 602 is generated in accordance with a predetermined technical standard (for example, EXIF (Exchangeable image file format)).
[0066] Provenance information 603 is information for proving the authenticity of image data 604 and is used when verifying the source and provenance of image data 604. Provenance information 603 is generated in accordance with a predetermined technical standard (for example, C2PA (Coalition for Content Provenance and Authenticity)) and has a prescribed data structure.
[0067] More specifically, the provenance information 603 includes provenance (Assertion) 613, a hash value 623 to guarantee provenance 613, and a digital signature 633. Provenance 613 includes provenance identification information (Manifest ID) to uniquely identify the provenance, and editing history (an example of "processing information") indicating the editing content of the image data 604. Provenance 613 also includes editing tools indicating the tools used for editing, the creator of the image data 604, and excluded areas 6131 indicating areas excluded from the guarantee of the binary data of the image and photographic information.
[0068] Here, the image data 604 generated in S403 is just generated by the shooting and has not been edited by an editing application or the like. Therefore, the editing history in the origin 613 stores information indicating "generation," and the editing tool stores information indicating the digital camera 100. However, when it is edited by an editing application or the like, information indicating "edited" is stored in the editing history. In addition, the exclusion area 6131 stores information such as the starting position and length from the beginning of the image file, segment information such as EXIF APP1 and APP2, and metadata tag information such as rating and GPS information. The exclusion area 6131 is then referenced when generating hashes during image data tampering verification.
[0069] Furthermore, the hash value 623 includes the hash value 624 of the image data, the hash value 626 of the provenance, and the hash value 625 of the photography information, etc. The digital signature 633 also includes the signature value, the signer, and the date and time of signing, etc. (details will be described later).
[0070] In S405, the system control unit 50 executes a history generation process. The history is information that indicates, for example, image data and metadata. This history generation process will be described later with reference to Figure 7. In S406, the system control unit 50 adds the metadata 601 generated in S404 to the image data 604 and generates an image file 600 (Figure 6A). Here, the system control unit 50 generates the image file according to a still image format such as JPEG and saves it to the recording medium 200. The system control unit 50 notifies the user that the image file has been written to the recording medium 200 by lighting up the card access lamp. In the case of video recording, a video file is generated according to a video format such as MPEG.
[0071] In S407, the system control unit 50 determines whether or not the end of the shooting process has been instructed by detecting the release of the shutter button 61, etc. If the system control unit 50 determines that the end of the shooting process has been instructed, the process ends. Otherwise, the process proceeds to process A, and then returns to S401.
[0072] Figure 5 illustrates the detailed procedure of the image editing process in S310. Figure 5 shows an example flowchart for performing image processing on the object to be edited and adding its history. Here, editing processing refers to the process of performing processing on image data read from a removable recording medium 200, which is susceptible to tampering, after it has been loaded into the system memory 52. Ultimately, it is a series of processes that update the image file containing the image data. This process is achieved by the system control unit 50 loading a program stored in the non-volatile memory 56 into the system memory 52 and executing it.
[0073] In S501, the system control unit 50 determines whether the image to be edited was selected from the images stored on the recording medium 200. If the system control unit 50 determines that the image to be edited was selected from the images stored on the recording medium 200, the process proceeds to S502; otherwise, the process proceeds to process B.
[0074] In S502, the system control unit 50 displays the designated image to be edited from the images stored on the recording medium 200 on the display unit 28. In S503, the system control unit 50 determines whether or not processing instructions have been given for the image to be edited. If the system control unit 50 determines that processing instructions have been given for the image to be edited, the process proceeds to S504; otherwise, the process proceeds to S506.
[0075] In S504, the system control unit 50 performs the instructed image processing on the target image. The processing may include, for example, cropping, resizing, applying a filter, or rating, but is not limited to these processes and may include other editing processes. In S505, the system control unit 50 performs a process to add the history indicating the image processing. Details of this history addition process will be described later with reference to Figure 8.
[0076] In S506, the system control unit 50 adds metadata 601 to the image data 604 and generates an image file. That is, the system control unit 50 generates the image data 604 in a still image format such as JPEG and saves it to the recording medium 200. The system control unit 50 can notify the user that the image has been saved to the recording medium 200 by illuminating the card access lamp. In the case of video recording, a video file is generated in a video format such as MPEG.
[0077] In S507, the system control unit 50 determines whether or not an instruction to terminate the image editing process has been given. If the system control unit 50 determines that an instruction to terminate the image editing process has been given, the image editing process is terminated; otherwise, the process proceeds to process B.
[0078] The detailed procedure for the history generation process in S405 will be explained using Figure 7. Figure 7 illustrates a flowchart for determining whether or not tamper-proof mode is active and generating the history. This process is achieved by the system control unit 50 loading the program stored in the non-volatile memory 56 into the system memory 52 and executing it.
[0079] In S701, the system control unit 50 determines whether the tamper-proof mode setting is enabled or disabled. If the system control unit 50 determines that the tamper-proof mode setting is enabled, the process proceeds to S702; otherwise, the process proceeds to process C.
[0080] In S702, the system control unit 50 specifies the exclusion area. The method for specifying the exclusion area may be, for example, specifying the starting position and length from the beginning of the image file, specifying it by segment unit such as EXIF APP1 or APP2, or specifying it by metadata tag unit such as rating or GPS information. Furthermore, the method for specifying the exclusion area is not limited to these methods.
[0081] In S703, the system control unit 50 generates the history 613. The structure of the image file is, for example, as shown in Figure 6A. The excluded area specified in S702 is included in the history 613 of the image file's history information 603 as the excluded area 6131 during image file generation.
[0082] In S704, the system control unit 50 inputs the binary data of the image data 604 and the history data 613 into a hash function to generate a hash value 623. The system control unit 50 may also generate a hash value from the binary data of the shooting information 602. However, data included in the exclusion area 6131 is excluded from the binary data input to the hash function.
[0083] In S705, the system control unit 50 generates a digital signature 633. The digital signature 633 includes information such as the signature value, the signer, and the date and time of signing. The signature value is generated by encrypting the generated hash value 623 using a pre-prepared private key. The public key that forms the pair with the private key used here is also stored in the digital signature 633. In addition, to prove that the public key is from a trustworthy manufacturer, information indicating the manufacturer of the digital camera 100 as the signer and a public key certificate indicating that the public key has been authenticated by a certification authority may also be stored in the digital signature 633. By attaching such a digital signature 633 including the signer to the image file 600, it can be shown that the image file 600 is trustworthy. In addition, the model data of the digital camera 100 may be used as the signer instead of manufacturer information. The date and time of signing includes the date and time when the generation of the digital signature is completed. The provenance generation process then ends.
[0084] The detailed procedure for the history addition process in S505 will be explained using Figure 8. Figure 8 illustrates a flowchart for determining whether an existing history exists and adding a new history. This process is achieved by the system control unit 50 loading the program stored in the non-volatile memory 56 into the system memory 52 and executing it.
[0085] In S801, the system control unit 50 determines whether or not a history 613 already exists. If the system control unit 50 determines that a history 613 already exists, the process proceeds to S802; otherwise, the process proceeds to S807. A case in which a history 613 already exists is, for example, when editing an image file 600 to which a history 613 was assigned at the time of its creation.
[0086] In S802, the system control unit 50 determines whether or not an excluded area 6131 exists in the history 613 contained in the image file 600. If the system control unit 50 determines that an excluded area 6131 exists, the process proceeds to S804; otherwise, the process proceeds to S803.
[0087] In S803, the system control unit 50 generates a hash value. The hash value generation process is the same as in S704, so the explanation is omitted. However, since there is no excluded area 6131, the system control unit 50 does not limit the range to be hashed in the binary data.
[0088] In S804, the system control unit 50 generates a hash value. The hash value generation process is the same as in S704, so the explanation is omitted. However, here, the system control unit 50 generates a hash value excluding the excluded area 6131. In S704, the excluded area 6131 is specified as the starting position and length from the beginning of the image file 600, a segment such as EXIF APP1 or APP2, or metadata tags such as rating or GPS information. Therefore, the system control unit 50 can use this specified information to understand the range excluding the excluded area 6131.
[0089] In S805, the system control unit 50 performs tampering verification using the hash value and signature value. Specifically, the system control unit 50 compares the hash value of the image data generated in S803 or S804 with the hash value 624 (Figure 6A) of the image data to be checked. This allows the system control unit 50 to verify whether or not the image data has been tampered with. Furthermore, if the hash value of the shooting information 602 and the hash value of the data to be checked exist, the system control unit 50 may also compare them. In this way, it is possible to verify whether or not data such as the shooting date and time, shooting location, photographer, and other data has been tampered with. This technology can be applied not only to the imaging process of the digital camera 100 but also to editing applications installed on electronic devices such as smartphones.
[0090] In S806, the system control unit 50 determines, based on the results of the tampering verification, whether or not the image data 604 has been tampered with. If the system control unit 50 determines that the image data 604 has been tampered with, the process proceeds to process D; otherwise, the process proceeds to S807. In S807, the system control unit 50 determines whether or not an exclusion area 6131 exists in the history 613. If the system control unit 50 determines that an exclusion area 6131 exists, the process proceeds to S808; otherwise, the process proceeds to S809.
[0091] In S808, the system control unit 50 executes an exclusion area setting process, that is, a history transfer process. In this exclusion area setting process, past history 613 is referenced. The exclusion area setting process will be described later with reference to Figure 9.
[0092] In S809, the system control unit 50 specifies a new exclusion area 6132 for the edited image. The method for specifying the exclusion area is the same as in S702, so the explanation is omitted. The system control unit 50 does not have to specify the exclusion area 6132.
[0093] In S810, the system control unit 50 performs a history appending process. Figures 6B1 and 6B2 illustrate the structure of the image file 600 generated by the system control unit 50. The image file 600 shown in Figures 6B1 and 6B2 illustrates a data structure that embeds both the history 613A of the unprocessed image data 604 read from the sensor and the history 613B after image processing. The history 613A includes an exclusion area 6131. The system control unit 50 also appends a newly designated exclusion area 6132 to the history 613B, in addition to the exclusion area 6131. In this way, the system control unit 50 performs a history handover process for 613.
[0094] The system control unit 50 may consolidate the information into either the excluded area 6131 or the excluded area 6132, and include the excluded area that was consolidated into the history 613B. Also, if the excluded area 6131 does not exist in the history 613A of the image data before processing, the history 613B will only include the excluded area 6132 that was newly designated as an excluded area.
[0095] In S811, the system control unit 50 inputs the binary data of the processed image data 604 and the history data 613B into a hash function to generate a hash value 623 that reflects the processed history data 613B. At this time, the hash value is generated to correspond to the data in the range excluding the excluded areas (6131, 6132). Alternatively, the system control unit 50 may generate a hash value corresponding to the shooting information 602 by inputting the binary data of the shooting information 602 into a hash function. Then the process proceeds to S812. S812 is the same as S705, so the explanation is omitted. Then the process ends.
[0096] Figures 6B1 and 6B2 illustrate the image file 600 after the flowchart shown in Figure 8 has been executed. The image file 600 shown in Figures 6B1 and 6B2 includes image data 604 after image processing and metadata 601 that reflects the image processing. More specifically, metadata 601 includes the shooting information 602 shown in Figure 6A. Metadata 601 also includes the provenance information 603 shown in Figure 6A as provenance information 603A. Furthermore, metadata 601 inherits the provenance information 603 shown in Figure 6A as provenance information 603B. This provenance information 603B includes a new exclusion area 6132 added in S810. Provenance information 603A is an example of "data" and "first data," and provenance information 603B is an example of "data" and "second data." Also, exclusion area 6131 is an example of "previously recorded exclusion area." Furthermore, the excluded areas (6131, 6132) are examples of "new excluded areas."
[0097] Figure 9 will be used to explain the details of the exclusion area setting process in S808, i.e., the handover process. Figure 9 illustrates a flowchart in which the exclusion areas included in the past history 613 are carried over to the new history 613B. This process is realized by the system control unit 50 loading the program stored in the non-volatile memory 56 into the system memory 52 and executing it.
[0098] In S901, the system control unit 50 refers to past history to determine whether the exclusion area setting is valid. If the system control unit 50 determines that the exclusion area setting is valid, the process proceeds to S902; otherwise, the process proceeds to process E.
[0099] In S902, the system control unit 50 determines whether to refer to the history generated in the previous step when inheriting the excluded area. If the system control unit 50 determines that it should refer to the excluded area generated in the previous step, the process proceeds to S903; otherwise, the process proceeds to S904.
[0100] In S903, the system control unit 50 refers to the previous history and determines the exclusion area of the history to be added. That is, the system control unit 50 includes, for example, the exclusion area 6131 of history 613 shown in Figure 6A in the next history 613B. Furthermore, the system control unit 50 includes the newly designated exclusion area 6132 as the added history in history 613B. If the exclusion area 6132 is not specified, the system control unit 50 includes only the exclusion area 6131 in history 613B.
[0101] In S904, the system control unit 50 determines whether to refer to the history that was first generated when inheriting the excluded area. If the system control unit 50 determines to refer to the first history, the process proceeds to S905; otherwise, the process proceeds to S906.
[0102] In S905, the system control unit 50 refers to the first history among the recorded histories to determine the exclusion area for the history to be added. This process is useful, for example, when a device that performs an editing process to add a second history does not have the function to inherit the exclusion area. That is, when adding a third history in S903, if there is no exclusion area in the second history, it becomes possible to refer to and inherit the exclusion area of the first history. Furthermore, the system control unit 50 includes the newly designated exclusion area 6132 as the added history in history 613B.
[0103] In S906, the system control unit 50 determines whether to refer to all previously recorded history when taking over the excluded area. If the system control unit 50 determines that all history should be referred to, the process proceeds to S907; otherwise, the process terminates.
[0104] In S907, the system control unit 50 refers to all histories and determines the exclusion area for the history to be added. This process is effective when the device performing the editing process to add the second history does not have the function to inherit the exclusion area. That is, when adding the third history in S903, it becomes possible to refer to and inherit the exclusion areas of the first history and the second history, respectively. Furthermore, the system control unit 50 includes the newly designated exclusion area 6132 as the added history in history 613B.
[0105] Editing can also be performed by applications, etc. When editing is done using authorized editing tools and following legitimate procedures, the provenance information is newly generated using the edited content in accordance with the prescribed technical standards. In this case, the excluded area that is appended to and stored in the image file's metadata is equivalent to the excluded area in the above process. Provenance information is newly generated each time an image file is edited and appended to and stored in the image file's metadata. On the other hand, if an image file is edited using unauthorized editing tools or through improper procedures, provenance information may not be attached to the image file, or the provenance information attached to the image file may not conform to the prescribed technical standards.
[0106] Furthermore, the series of verification processes to check whether the provenance data has been tampered with may compare it at a finer level, such as editing history, creator, thumbnail data, or metadata. Also, the signature value can be decrypted using a public key, and if the hash values match, the signature value verification can be considered successful. In this way, it is possible to embed a mechanism for detecting tampering at a finer level into the image file itself.
[0107] <Function and Effects> With the digital camera 100 described above, when editing image data, the exclusion areas from past history are inherited. Then, new exclusion areas related to the image data editing process are added by referring to the exclusion areas from past history. By resetting the exclusion areas in this way, data that was included in the exclusion areas from past history can be included in the exclusion areas again. Therefore, misjudgments are suppressed in the verification of tampering in newly generated image files. Thus, the reliability of the tampering verification results can be ensured.
[0108] (Modification) Multiple processes may be performed on the image data during a single editing of the image data. In such a case, record data may be generated that records the combination of these multiple processes in no particular order, as a substitute for provenance information. A hash value corresponding to the combination of the multiple processes may also be generated. With this modification, when verifying tampering, if the execution order of the multiple processes is changed and a hash value is generated, it is suppressed that the image data will be mistakenly judged to have been tampered with.
[0109] (Other Embodiments) The present invention can also be realized by supplying a program that implements one or more of the functions of the above embodiments to a system or device via a network or storage medium, and by having one or more processors in the computer of that system or device read and execute the program. It can also be realized by a circuit (e.g., ASIC) that implements one or more functions.
[0110] The technical ideas derived from this disclosure are not limited to the exemplary embodiments disclosed, but are intended to encompass various modifications of the exemplary embodiments, or substitutions with equivalent structures or functions. The scope of the following claims should be interpreted in the broadest way to encompass all such modifications and equivalent structures and functions.
[0111] This application claims priority based on Japanese Patent Application No. 2025-052440, filed on 26 March 2025, and all of its contents are incorporated herein by reference.
Claims
1. An information processing device comprising: a processing unit that performs processing on image data; and a recording control unit that controls the recording of data containing processing information performed by the processing unit, wherein the data includes excluded areas that are excluded from verification of tampering with the image data, and the recording control unit controls the recording of a new excluded area in the data using previously recorded excluded areas when the processing unit performs the processing.
2. The information processing apparatus according to claim 1, wherein the recording control unit records the new exclusion area using the exclusion area included in the previously recorded data.
3. The information processing apparatus according to claim 1 or 2, wherein the recording control unit records the new exclusion area using the exclusion area included in the oldest recorded data.
4. The information processing apparatus according to any one of claims 1 to 3, wherein the recording control unit records the new exclusion area using the exclusion area included in all the previously recorded data.
5. The information processing apparatus according to any one of claims 1 to 4, wherein the recording control unit sets whether to enable or disable recording a new exclusion area in the data using the exclusion area of the data previously recorded.
6. The information processing apparatus according to any one of claims 1 to 5, wherein the recording control unit specifies the exclusion area by the starting position and length from the beginning of the image file containing the image data.
7. The information processing apparatus according to any one of claims 1 to 6, wherein the recording control unit specifies the exclusion area on a segment-by-segment basis of the image file containing the image data.
8. The information processing apparatus according to any one of claims 1 to 7, wherein the recording control unit specifies the exclusion area on a tag-by-tag basis of the metadata of the image data.
9. The information processing apparatus according to any one of claims 1 to 8, wherein the recording control unit does not record the new exclusion area in the data if it determines that the data has been tampered with.
10. An information processing device according to any one of claims 1 to 9, further comprising: an imaging unit; a generation unit that generates an image file including imaging data captured by the imaging unit and metadata of the imaging data, wherein the metadata includes imaging information and the data, and the data includes first data including the exclusion area recorded in the past and second data including the exclusion area recorded in the past and the new exclusion area.
11. The information processing apparatus according to claim 10, wherein the data includes, respectively, history data of the processing of the imaging data up to the time it was recorded, a hash value of the history data, and a digital signature obtained by encrypting the hash value.
12. A control method for an information processing device, comprising: a processing step in which a processing unit performs processing on image data; and a recording control step in which a recording control unit controls the recording of data including processing information performed in the processing step, wherein the data includes an exclusion area that is excluded from verification of tampering with the image data, and the recording control step controls the recording of a new exclusion area in the data using a previously recorded exclusion area when the processing is performed in the processing step.
13. A program for causing a computer to execute each step in a control method for an information processing device, wherein the control method includes a control step, a processing step in which a processing unit performs processing on image data, and a recording control step in which a recording control unit controls the recording of data including processing information performed in the processing step, the data includes an exclusion area excluded from verification of tampering with the image data, and the recording control step controls recording a new exclusion area in the data using a previously recorded exclusion area when the processing is performed in the processing step.