Method and device for inserting and authenticating a digital signature in digital data
Abstract
A method for inserting a digital signature into digital data, the digital data having bits and the method including designating predetermined bits of the digital data to receive the digital signature; signing digital data other than the predetermined bits that caused the digital signature; and inserting The digital signature is a predetermined bit of the digital data to verify subsequent digital data and other steps. A method for verifying digital data having an embedded digital signature in a predetermined bit of the digital data is also provided. The method includes: selecting a digital signature from the predetermined bit; interpreting the digital signature from the digital data that caused the first hash ; Applying a known unidirectional hash function to digital data other than the predetermined bit that caused the second hash by using a digital data encoder; and comparing the first hash and the second hash, where if the first When the hash matches the second hash, the digital data is verified. In a preferred version of the method of the present invention, the method further includes inserting related data into the digital data before the signing step, so that the digital signature verifies the related data and digital data. Preferably, the relevant data is inserted into digital data bits other than the predetermined bits.
Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
1 claim: 1 independent, 0 dependent
- 1A method for inserting a digital signature into digital data including bits, including the following steps:designating the predetermined bits of the digital data used to receive the digital signature;signing the digital data other than the predetermined bits that cause the digital signature ;And insert a digital signature into the predetermined bit of the digital data for verification of the subsequent digital data. 1.一種用以插入數位簽名於包括位元之數位資料中之方法,包括下列步驟:指定用以接收數位簽名之數位資料之預定位元;簽署除造成數位簽名之預定位元以外之數位資料;以及插入數位簽名於數位資料之預定位元,以便做為隨後數位資料之驗證。 2. For the method described in item 1 of the scope of the patent application, the signature step includes: applying a one-way hash function to the digital data that excludes the predetermined bits that cause the hash. 2.如申請專利範圍第1項之方法,其中簽名步驟包括:應用一單方向散列功能施於排除了造成散列之預定位元之數位資料上。 3. Such as the method in item 1 of the scope of patent application, in which the digital data is selected from the group consisting of video data, continuous video data, and audio data. 3.如申請專利範圍第1項之方法,其中數位資料是從由影像資料、連續影像資料、以及聲音資料組成之群組中選擇出來。 4. For the method described in item 1 of the scope of patent application, a further step is to insert relevant data into the digital data prior to the signature step. 4.如申請專利範圍第1項之方法,進一步包括的步驟為插入相關資料於先於簽名步驟之數位資料中。 5. Such as the method of item 4 in the scope of patent application, in which the relevant data is inserted in the digital data bits other than the predetermined bits. 5.如申請專利範圍第4項之方法,其中相關資料插入於除預定位元以外之數位資料位元中。 6. Such as the method of item 4 of the scope of patent application, where the digital data includes multiple samples, and each sample is defined by multiple bits, from the most significant bit to the least significant bit, all defining the least significant of multiple samples The bit includes a least significant bit plane, and the predetermined bit includes at least a part of the least significant bit plane. 6.如申請專利範圍第4項之方法,其中數位資料包括多個樣本,每個樣本經由多個位元所定義,從最高有效位元到最低有效位元,所有定義多個樣本之最低有效位元包括一最低有效位元平面,其中預定位元包括至少一部分最低有效位元平面。 7. Such as the method of item 6 of the scope of patent application, in which the relevant data is inserted into at least a part of the remaining least significant bits in the least significant bit plane. 7.如申請專利範圍第6項之方法,其中相關資料插入於最低有效位元平面中之至少一部分剩餘最低有效位元。 8. For the method of item 4 of the scope of patent application, wherein the digital data includes multiple samples, each sample is defined by multiple bits, and further includes transforming the multiple bits to have at least the first and second characteristic components. A form of step in which the predetermined bit includes the first characteristic component. 8.如申請專利範圍第4項之方法,其中數位資料包括多個樣本,每個樣本經由多個位元所定義,進一步包括轉變多個位元為具有至少第一與第二特徵成份之另一種形式之步驟,其中預定位元包括第一特徵成份。 9. Such as the method of item 6 or 8 in the scope of patent application, where the digital data is an image, and each sample is an image pixel. 9.如申請專利範圍第6或8項之方法,其中數位資料為影像,而每個樣本為影像畫素。 10. Such as the method of item 6 or 8 in the scope of patent application, where the digital data is a continuous image, and each sample is a spatial temporary sample. 10.如申請專利範圍第6或8項之方法,其中數位資料為連續影像,而每個樣本為空間性暫時樣本。 11. Such as the method of item 6 or 8 in the scope of patent application, where the digital data is sound, and each sample is a time sample. 11.如申請專利範圍第6或8項之方法,其中數位資料為聲音,而每個樣本為時間樣本。 12. Such as the method of item 8 of the scope of patent application, wherein relevant data is inserted into at least a part of the second characteristic component. 12.如申請專利範圍第8項之方法,其中相關資料插入於至少一部分第二特徵成份。 13. For the method of item 12 of the scope of patent application, the other manifestation is the frequency domain manifestation with high and low frequency components, where the first characteristic component is part of the high frequency component, and the second characteristic component is the remaining high frequency Components and low-frequency components. 13.如申請專利範圍第12項之方法,其中另一種表現形式為具有高和低頻率成份之頻率領域表現形式,其中第一特徵成份為部分高頻率成份,而第二特徵成份為剩餘高頻率成份以及低頻率成份。 14. For the method described in item 4 of the scope of patent application, at least part of the relevant information includes information identifying the public key used to interpret the digital signature. 14.如申請專利範圍第4項之方法,其中至少一部分相關資料包括辨識用來解譯數位簽名之公用鑰匙之資料。 15. Such as the method in item 4 of the scope of patent application, in which the relevant data includes data for identifying the source of digital data. 15.如申請專利範圍第4項之方法,其中相關資料包括辨識數位資料來源之資料。 16. Such as the method in item 4 of the scope of patent application, in which the relevant information includes the information to identify the identity of the owner of the digital data. 16.如申請專利範圍第4項之方法,其中相關資料包括辨識數位資料擁有者身份之資料。 17. Such as the method of item 16 in the scope of patent application, in which the digital data is an image, and the relevant data includes the data for identifying the person who took the image. 17.如申請專利範圍第16項之方法,其中數位資料為影像,並且相關資料包括辨識影像照相者之資料。 18. For example, the method of item 4 of the scope of patent application, which encrypts and compiles part of the relevant data, while the remaining part of the relevant data is not encrypted and compiled. 18.如申請專利範圍第4項之方法,其中加密編譯部分相關資料,而剩餘部分相關資料則不加密編譯。 19. Such as the method in item 4 of the scope of patent application, where the relevant information includes at least two areas. 19.如申請專利範圍第4項之方法,其中相關資料至少包括兩個區域。 20. Such as the method described in item 19 of the scope of patent application, in which at least one area includes data for identifying the public key used to interpret the digital signature. 20.如申請專利範圍第19項之方法,其中至少一區域包括辨識用來解譯數位簽名之公用鑰匙之資料。 21. Such as the method of item 20 of the scope of patent application, wherein at least another area includes information for identifying the owner of the public key. 21.如申請專利範圍第20項之方法,其中至少另一區域包括辨識公用鑰匙擁有者之資料。 22. Such as the method described in item 4 of the scope of patent application, further including the step of receiving relevant information from external sources. 22.如申請專利範圍第4項之方法,進一步包括之步驟為從外部資源接收相關資料。 23. Such as the method of item 22 in the scope of patent application, in which the external resource is the Global Positioning System. 23.如申請專利範圍第22項之方法,其中外部資源為全球衛星定位系統。 24. For example, the method described in item 1 of the scope of patent application, in which the digital data is compressed using the compression standard that creates the compressed file, and further includes the following steps: creating a decompressed file before the signing step;signing the decompressed file resulting in a digital signature;And insert the digital signature in the file header of the compressed file, instead of inserting the digital signature in the digital data. 24.如申請專利範圍第1項之方法,其中使用造成壓縮檔案之壓縮標準壓縮數位資料,而其中進一步包括下列步驟:在簽名步驟之前創造一解壓縮檔案;簽署造成數位簽名之解壓縮檔案;以及插入數位簽名於壓縮檔案之檔案頭中,以取代插入數位簽名於數位資料中。 25. For example, the method of item 4 of the scope of patent application, which uses the compression standard that creates the compressed file to compress the digital data, and further includes the following steps: create a decompressed file before the signing step;insert the relevant data into the decompressed file;Signing the decompressed file resulting in a digital signature;and inserting the digital signature and related data in the header of the compressed file instead of inserting the digital signature and related data in the digital data. 25.如申請專利範圍第4項之方法,其中使用造成壓縮檔案之壓縮標準壓縮數位資料,而其中進一步包括下列步驟:在簽名步驟之前創造一解壓縮檔案;插入相關資料於解壓縮檔案中;簽署造成數位簽名之解壓縮檔案;以及插入數位簽名與相關資料於壓縮檔案之檔案頭中以取代插入數位簽名與相關資料於數位資料中。 26. Such as the method of item 24 or 25 in the scope of patent application, in which the digital data is an image and the compression standard is JPEG. 26.如申請專利範圍第24或25項之方法,其中數位資料為影像且壓縮標準為JPEG。 27. Such as the method of item 24 or 25 in the scope of patent application, in which the digital data is a continuous image and the compression standard is MPEG. 27.如申請專利範圍第24或25項之方法,其中數位資料為連續影像且壓縮標準為MPEG。 28. Such as the method of item 4 of the scope of patent application, where the digital data includes multiple samples, each sample is defined by multiple bits, from the most significant bit to the least significant bit, all define the least significant of multiple samples The bits include a least significant bit plane, and the method further includes the following steps: ignoring the least significant bit plane in the digital data;before the signing step, connecting the relevant data to the digital data with the ignored least significant bit plane;The step of executing the signature is performed on the digital data with the related data that causes the digital signature;wherein the predetermined bit includes at least a part of the least significant bit plane, and the related data is inserted into the remaining least significant bit in at least a part of the least significant bit plane. 28.如申請專利範圍第4項之方法,其中數位資料包括多個樣本,每個樣本經由多個位元所定義,從最高有效位元到最低有效位元,所有定義多個樣本之最低有效位元包括一最低有效位元平面,其中此方法進一步包括下列步驟:忽略數位資料中之最低有效位元平面;在簽名步驟之前,連接相關資料至具有忽略的最低有效位元平面之數位資料;執行簽名步驟於具有造成數位簽名之連結的相關資料之數位資料;其中預定位元包括至少一部分最低有效位元平面,且相關資料插入於至少一部分最低有效位元平面中之剩餘最低有效位元。 29. For example, the method of item 1 of the scope of patent application further includes the following steps: provide time data for identifying the time when digital data is created;connect hash and time data;apply a one-way hash function to connect hash and cause a second hash And the second hash is encrypted and compiled to replace the first hash to create a time stamp containing a digital signature, where the digital data and the time data are subsequently verified. 29.如申請專利範圍第1項之方法,進一步包括下列步驟:提供辨識創造數位資料時間之時間資料;連接散列與時間資料;應用單方向散列功能於連接散列和造成第二次散列之時間資料;以及加密編譯第二散列取代第一散列,以造成包含數位簽名之時間標籤,其中數位資料與時間資料隨後驗證之。 30. The method according to item 29 of the scope of patent application further includes the following steps: transmitting the hash and signature to a third party to provide, connecting, and encrypting and compiling steps, and receiving a time stamp from the third party before the inserting step. 30.如申請專利範圍第29項之方法,進一步包括下列步驟:傳送散列與簽名至第三者以提供、連接、與加密編譯步驟,以及在插入步驟之前從第三者接收時間標籤。 31. Such as the method of claim 30, wherein a reliable third party exists on an Internet address, and the steps of sending and receiving are completed via the Internet. 31.如申請專利範圍第30項之方法,其中可信賴的第三者存在於一網際網路位址上,且傳送與接收步驟經由網際網路完成。 32. For the method of item 29 in the scope of the patent application, the circuit provides a time stamp through a semiconductor chip with an anti-vandal clock and an anti-vandal time stamp, wherein the clock outputs time data and a digital signature together with a digital signature through the circuit to output the time stamp. 32.如申請專利範圍第29項之方法,其中經由具有防搗毀時鐘與防搗毀時間標籤之半導體晶片,電路提供時間標籤,其中時鐘輸出時間資料與數位簽名一起經由電路簽署以輸出時間標籤。 33. For example, the method of item 4 of the scope of patent application further includes the following steps: storing the identification number in the memory according to at least one user who created the digital data device;identifying the device user whose identification number is stored in the memory;According to the identified user, the identification number is output from the memory to be inserted as the relevant data. 33.如申請專利範圍第4項之方法,進一步包括下列步驟:根據創造數位資料裝置之至少一位使用者儲存識別號於記憶體中;辨認其識別號儲存於記憶體中之裝置使用者;根據辨認出的使用者從將要插入作為相關資料之記憶體輸出識別號。 34. For example, the method described in item 33 of the scope of patent application further includes the steps of storing a private key for each user to sign the digital data in the memory, and using the private key to sign the digital data. 34.如申請專利範圍第33項之方法,進一步包括之步驟為根據每個使用者儲存私密鑰匙以簽署記憶體中之數位資料,並使用私密鑰匙以簽署數位資料。 35. Such as the method of item 33 in the scope of patent application, wherein the identification step is completed by a fingerprint identification system. 35.如申請專利範圍第33項之方法,其中辨認步驟經由指紋辨認系統完成。 36. Such as the method of item 33 in the scope of patent application, where the identification number is the identified user name. 36.如申請專利範圍第33項之方法,其中識別號為辨識出的使用者名字。 37. A method for verifying digital data with an embedded digital signature in predetermined bits of digital data, the method comprising the following steps: extracting the digital signature from the predetermined bits;interpreting the digital data from the digital data that caused the first hash Signature;apply the one-way hash function used by the digital data encoder to digital data other than the predetermined bit that caused the second hash;and compare the first hash with the second hash, where if the first hash When it matches the second hash, the digital data is verified. 37.一種用以驗證在數位資料預定位元中具有嵌入式數位簽名之數位資料之方法,該方法包括下列步驟:從預定位元取出數位簽名;從造成第一散列之數位資料解譯數位簽名;應用由數位資料編碼器所使用之單方向散列功能於除了造成第二散列之預定位元以外之數位資料;以及比較第一散列與第二散列,其中假如第一散列與第二散列相符時,數位資料則為已驗證。 38. Such as the method of item 37 in the scope of patent application, in which the digital data is selected from a group consisting of image data, continuous image data, and audio data. 38.如申請專利範圍第37項之方法,其中數位資料從一包含影像資料、連續影像資料、與聲音資料之群組中選擇出來。 39. Such as the method of item 37 of the scope of patent application, wherein the digital data further includes related data inserted in the known digital data bits, and this method verifies the related data and the digital data. 39.如申請專利範圍第37項之方法,其中數位資料進一步包括插入於已知數位資料位元中之相關資料,其中此方法驗證了相關資料以及數位資料。 40. Such as the method of item 39 in the scope of patent application, in which the relevant data is inserted in the digital data bits that exclude the predetermined bits. 40.如申請專利範圍第39項之方法,其中相關資料插入於排除預定位元之數位資料位元中。 41. For example, the method of item 39 of the scope of patent application, in which the digital data is compressed using the compression standard that causes the compressed file, and the digital signature and related data are included in the compressed file header. The method further includes the following steps: decompression and compression File;and before the extraction step, replace the signature and related data from the file header to the predetermined bit and the known bit respectively. 41.如申請專利範圍第39項之方法,其中使用造成壓縮檔案之壓縮標準壓縮數位資料,並且其中數位簽名與相關資料包含於壓縮檔案頭之中,其中此方法進一步包括下列步驟:解壓縮壓縮檔;以及在取出步驟之前,分別從檔案頭將簽名與相關資料替代至預定位元與已知位元中。 42. An encoder for inserting a digital signature into digital data. The digital data includes bits. The encoder includes: a device for specifying a predetermined bit of the digital data to receive the digital signature;A device for digital data other than bits, and a device for inserting a digital signature into a predetermined bit of the digital data to verify the digital data later. 42.一種用以插入數位簽名於數位資料中之編碼器數位資料包括位元,編碼器包括:用以指定數位資料預定位元之裝置,以接收數位簽名;用以簽署除造成數位簽名之預定位元以外之數位資料之裝置,以及用以插入數位簽名於數位資料之預定位元之裝置,以隨後驗證數位資料。 43. For example, the encoder of item 42 of the scope of patent application, wherein the device for signing includes: a device for applying a one-way hash function to digital data that excludes the predetermined bits of the hash;and cryptographic hashing . 43.如申請專利範圍第42項之編碼器,其中用以簽名之裝置包括:用以應用單方向散列功能於排除了散列之預定位元之數位資料上之裝置;以及加密編譯散列。 44. For example, in the encoder of item 42 of the scope of patent application, the digital data is selected from a group consisting of video data, continuous video data, and audio data. 44.如申請專利範圍第42項之編碼器,其中數位資料從一包含影像資料、連續影像資料、與聲音資料之群組中選擇出來。 45. For example, the encoder of item 42 of the scope of patent application further includes a device for inserting relevant data into the digital data before signing the digital data, so that the encoder verifies the relevant data and the digital data. 45.如申請專利範圍第42項之編碼器,進一步包括在簽署數位資料之前,用以插入相關資料於數位資料中之裝置,如此一來編碼器驗證相關資料以及數位資料。 46. Such as the encoder of item 45 in the scope of patent application, in which the relevant data is inserted in the digital data bits excluding the predetermined bits. 46.如申請專利範圍第45項之編碼器,其中相關資料插入於排除了預定位元之數位資料位元中。 47. Such as the encoder of item 45 of the scope of patent application, where the digital data includes multiple samples, the samples are defined by multiple bits from the most significant bit to the least significant bit, and all the least significant bits define multiple samples A least significant bit plane is included, wherein the predetermined bit includes at least a part of the least significant bit plane. 47.如申請專利範圍第45項之編碼器,其中數位資料包括多個樣本,樣本經由從最高有效位元到最低有效位元之多個位元所定義,所有最低有效位元定義多個樣本包括了一最低有效位元平面,其中預定位元包括至少一部分最低有效位元平面。 48. Such as the encoder of item 47 of the scope of patent application, in which relevant data is inserted into at least a part of the remaining least significant bits in the least significant bit plane. 48.如申請專利範圍第47項之編碼器,其中相關資料插入於至少一部分最低有效位元平面中之剩餘最低有效位元。 49. The encoder of item 45 of the scope of patent application, wherein the digital data is an image including multiple samples, each sample is defined by multiple bits, and further includes a method for transforming multiple bits into another type with at least The first and second characteristic component expression means, wherein the predetermined bit includes the first characteristic component. 49.如申請專利範圍第45項之編碼器,其中數位資料為包括多個樣本之影像,每個樣本經由多個位元所定義,進一步包括用以轉變多個位元為另一種具有至少第一和第二特徵成份之表現方式之裝置,其中預定位元包括第一特徵成份。 50. Such as the encoder of item 47 or 49 in the scope of patent application, in which the digital data is an image, and each sample is an image pixel. 50.如申請專利範圍第47或49項之編碼器,其中數位資料為影像,且每個樣本為影像畫素。 51. For example, the encoder of item 47 or 49 of the scope of patent application, in which the digital data is a continuous image, and each sample is a spatial temporary sample. 51.如申請專利範圍第47或49項之編碼器,其中數位資料為連續影像,且每個樣本為空間性暫時樣本。 52. For example, the encoder of item 47 or 49 of the scope of patent application, in which the digital data is sound, and each sample is a time sample. 52.如申請專利範圍第47或49項之編碼器,其中數位資料為聲音,且每個樣本為時間樣本。 53. Such as the encoder of item 49 of the scope of patent application, in which relevant data is inserted into at least a part of the second characteristic component. 53.如申請專利範圍第49項之編碼器,其中相關資料插入於至少一部分第二特徵成份。 54. For example, the encoder in item 53 of the patent application has another way of expressing high and low frequency components. The first characteristic component is a part of high frequency components, and the second characteristic component is the remaining high frequency components and low frequency components. 54.如申請專利範圍第53項之編碼器,其中另一種表現方式具有高和低頻率成份,其中第一特徵成份為一部分高頻率成份,第二特徵成份為剩餘高頻率成份和低頻率成份。 55. For example, in the encoder of item 45 of the scope of patent application, at least a part of the relevant data includes the data for identifying the public key, which is used to interpret the digital signature. 55.如申請專利範圍第45項之編碼器,其中至少一部分相關資料包括辨識公用鑰匙之資料,以用來解譯數位簽名。 56. For example, for the encoder of item 45 of the scope of patent application, the relevant data includes data for identifying the source of digital data. 56.如申請專利範圍第45項之編碼器,其中相關資料包括辨識數位資料來源之資料。 57. For example, the encoder of item 45 in the scope of patent application, in which the relevant data includes the data to identify the identity of the digital data user. 57.如申請專利範圍第45項之編碼器,其中相關資料包括辨識數位資料使用者身份之資料。 58. For example, the encoder of item 57 of the scope of patent application, in which the digital data is an image, and the relevant data includes the data for identifying the person who took the image. 58.如申請專利範圍第57項之編碼器,其中數位資料為影像,相關資料包括辨識影像照相者之資料。 59. For the encoder of item 45 in the scope of patent application, part of the relevant data is encrypted and compiled, and the remaining part of the relevant data is not encrypted and compiled. 59.如申請專利範圍第45項之編碼器,其中部分相關資料加密編譯,剩餘的部分相關資料則不加密編譯。 60. Such as the encoder of item 45 in the scope of patent application, where the relevant information includes at least two areas. 60.如申請專利範圍第45項之編碼器,其中相關資料包括至少兩個區域。 61. For example, in the encoder of item 60 of the scope of patent application, at least one area includes data for identifying the public key to interpret the digital signature. 61.如申請專利範圍第60項之編碼器,其中至少一區域包括辨識公用鑰匙之資料,以用來解譯數位簽名。 62. For the encoder of item 61 of the scope of patent application, at least another area includes information for identifying the owner of the public key. 62.如申請專利範圍第61項之編碼器,其中至少另一區域包括辨識公用鑰匙擁有者之資料。 63. For example, the encoder of item 57 of the scope of patent application further includes a device for receiving relevant data from external sources. 63.如申請專利範圍第57項之編碼器,進一步包括用以從外部資源接收相關資料之裝置。 64. For example, the encoder in the 63rd item of the scope of patent application, where the external resource is the Global Positioning System. 64.如申請專利範圍第63項之編碼器,其中外部資源為全球衛星定位系統。 65. For example, the encoder of item 42 of the scope of patent application, which uses the compression standard to compress the digital data to compress the digital data, and the encoder further includes: a device for creating and decompressing the digital data before signing the digital data;for signing the digital data A device for decompressing signature files;and a device for inserting a digital signature in the header of a compressed file to replace the device inserted in the digital data. 65.如申請專利範圍第42項之編碼器,其中使用造成壓縮檔案之壓縮標準壓縮數位資料,其中編碼器進一步包括:用以在簽署數位資料之前創造解壓縮檔案之裝置;用以簽署造成數位簽名之解壓縮檔案之裝置;以及用以插入數位簽名於壓縮檔之檔案頭,以取代插入於數位資料中之裝置。 66. For example, the encoder of item 45 of the scope of patent application, in which the digital data is compressed using the compression standard that creates the compressed file, and the encoder further includes: a device for creating and decompressing the file before signing the digital data;for inserting relevant data The device in the decompressed file;the device that uses the inserted relevant data to sign the decompressed file;the relevant data inserted in it creates a digital signature;and the digital signature and related data are inserted in the header of the compressed file to replace A device inserted in digital data. 66.如申請專利範圍第45項之編碼器,其中使用造成壓縮檔案之壓縮標準壓縮數位資料,其中編碼器進一步包括:用以在簽署數位資料之前創造解壓縮檔案之裝置;用以插入相關資料於解壓縮檔案中之裝置;使用插入的相關資料,用以簽署解壓縮檔案之裝置;其中插入的相關資料造成數位簽名;以及用以插入數位簽名與相關資料於壓縮檔之檔案頭,以取代插入於數位資料中之裝置。 67. For example, the encoder of item 65 or 66 in the scope of patent application, in which the digital data is an image, and the compression standard is JPEG. 67.如申請專利範圍第65或66項之編碼器,其中數位資料為影像,壓縮標準為JPEG。 68. For example, the encoder of item 65 or 66 in the scope of patent application, in which the digital data is continuous image, and the compression standard is MPEG. 68.如申請專利範圍第65或66項之編碼器,其中數位資料為連續影像,壓縮標準為MPEG。 69. For example, the encoder of item 45 of the scope of patent application, where the digital data includes multiple samples, the samples are defined by multiple bits from the most significant bit to the least significant bit, and all the least significant bits define multiple samples It includes a least significant bit plane, wherein the encoder further includes: a device for ignoring at least a part of the least significant bit plane in the digital data;before signing the digital data, it is used to connect the relevant data to the least significant bit with the neglected least significant bit A device for digital data in a meta-plane;a device for signing digital data with related data that causes a digital signature connection;wherein the predetermined bit includes at least a part of the least significant bit plane, and the related data is inserted in at least a part of the least significant bit The remaining least significant bit in the plane. 69.如申請專利範圍第45項之編碼器,其中數位資料包括多個樣本,樣本經由從最高有效位元到最低有效位元之多個位元所定義,所有最低有效位元定義多個樣本包括了一最低有效位元平面,其中編碼器進一步包括:用以忽略至少一部分數位資料中之最低有效位元平面之裝置;在簽署數位資料之前,用以連接相關資料至具有忽略的最低有效位元平面之數位資料之裝置;用以簽署具有造成數位簽名之連接的相關資料之數位資料之裝置;其中預定位元包括至少一部分最低有效位元平面,且相關資料插入於至少一部分最低有效位元平面中之剩餘最低有效位元。 70. For example, the encoder of item 45 of the scope of patent application further includes: a device for identifying and creating digital data time data;a device for connecting hash and time data;a device for applying one-way hash function to the connection Hash, and the time data that caused the second hash;and a device for encrypting and compiling the second hash to replace the first hash to create a time stamp containing a digital signature, where the digital data and the time data are subsequently verified. 70.如申請專利範圍第45項之編碼器,進一步包括:用以提供辨識創造數位資料時間資料之裝置;用以連接散列與時間資料之裝置;用以應用單方向散列功能於連接的散列,與造成第二散列之時間資料;以及用以加密編譯第二散列以取代第一散列之裝置,以造成包含數位簽名之時間標籤,其中數位資料與時間資料隨後驗證之。 71. For example, the encoder of item 70 of the scope of the patent application further includes: a device for transmitting the hash to a third party to provide a time stamp and connecting the hash and the time stamp;The third party receives the second hash device. 71.如申請專利範圍第70項之編碼器,進一步包括:用以傳送散列至一第三者,以提供時間標籤以及連接散列與時間標籤之裝置;以及在加密編譯之前,用以從該第三者接收第二散列之裝置。 72. Such as the encoder of item 71 in the scope of patent application, where a trusted third party exists on an Internet address, and the device used for transmission and reception is the second one that can access the Internet and receive transmissions. Hashing computer. 72.如申請專利範圍第71項之編碼器,其中可信賴的第三者存在於一網際網路位址上,用以傳送和接收之裝置為可存取網際網路和接收傳送的第二散列之電腦。 73. For example, the encoder of item 70 of the scope of patent application further includes a semiconductor chip with anti-tamper clock and anti-tamper time stamp circuit, wherein the clock output time data and digital signature are signed by the circuit to output the time stamp. 73.如申請專利範圍第70項之編碼器,進一步包括具有防搗毀時鐘與防搗毀時間標籤電路之半導體晶片,其中時鐘輸出時間資料與數位簽名一起經由電路簽署以輸出時間標籤。 74. For example, the encoder of item 45 of the scope of the patent application further includes: a memory for storing the identification number corresponding to at least one user who creates a digital data device;and for identifying the device user whose identification number is stored in the memory The identification device;and the output device used to output the user corresponding to the identification from the memory to insert the identification number as the relevant data. 74.如申請專利範圍第45項之編碼器,進一步包括:用以儲存對應至少一創造數位資料裝置使用者之識別號之記憶體;用以辨識其識別號儲存於記憶體中之裝置使用者之辨識裝置;以及用以輸出對應來自記憶體之辨識的使用者,以插入作為相關資料之識別號之輸出裝置。 75. For the encoder of item 74 of the scope of patent application, the private key used to sign the digital signature is also stored in the memory corresponding to each user, and the identification number is inserted as related data, and the private key is used to sign Digital data. 75.如申請專利範圍第74項之編碼器,其中用以簽署數位簽名之私密鑰匙也儲存於對應每個使用者之記憶體中,其中識別號插入以作為相關資料,且私密鑰匙用來簽署數位資料。 76. Such as the encoder of item 74 in the scope of patent application, wherein the identification device is a fingerprint identification system. 76.如申請專利範圍第74項之編碼器,其中辨識裝置為指紋辨認系統。 77. Such as the encoder of item 76 in the scope of patent application, where the identification number is the name of the identified user. 77.如申請專利範圍第76項之編碼器,其中識別號為辨識的使用者之名字。 78. A decoder for verifying digital data with an embedded digital signature in a predetermined bit of digital data, the decoder comprising: a device for extracting the digital signature from the predetermined bit;for generating a first hash A device for deciphering and signing digital data;a device for applying a one-way hash function to devices other than the digital data of a predetermined bit that caused the second hash;and a device for comparing the first hash with the second hash , Where if the first hash matches the second hash, the digital data is verified. 78.一種用以驗證具有於數位資料預定位元中之嵌入式數位簽名之數位資料之解碼器,解碼器包括:用以從預定位元取出數位簽名之裝置;用以從造成第一散列之數位資料解譯簽名之裝置;用以施加單方向散列功能於除造成第二散列之預定位元之數位資料以外之裝置;以及用以比較第一散列與第二散列之裝置,其中假如第一散列與第二散列相符時,數位資料則為已驗證。 79. Such as the decoder of item 78 in the scope of patent application, in which the digital data is selected from a group consisting of video data, continuous video data, and audio data. 79.如申請專利範圍第78項之解碼器,其中數位資料從一包含影像資料、連續影像資料、與聲音資料之群組中選擇出來。 80. For the decoder of item 78 in the scope of patent application, the digital data further includes related data inserted in the known bits of the digital data, and the decoder verifies the related data and the digital data. 80.如申請專利範圍第78項之解碼器,其中數位資料進一步包括插入於數位資料已知位元之相關資料,其中解碼器驗證相關資料以及數位資料。 81. For example, the decoder of item 80 of the scope of patent application, in which the relevant data is inserted in the digital data bits excluding the predetermined bits. 81.如申請專利範圍第80項之解碼器,其中相關資料插入於排除了預定位元之數位資料位元中。 82. For example, the decoder of the 80th item of the scope of patent application, in which the digital data is compressed by the compression standard that causes the compressed file, and the digital signature is included in the file header of the compressed file, and the encoder further includes: for decompressing the compressed file The device;and before the digital signature is retrieved from the predetermined bit, the device used to replace the signature with the predetermined bit from the file header. 82.如申請專利範圍第80項之解碼器,其中使用造成壓縮檔案之壓縮標準壓縮數位資料,且其中數位簽名包含於壓縮檔案之檔案頭中,其中編碼器進一步包括:用以解壓縮壓縮檔案之裝置;以及在從預定位元取出數位簽名之前,用以從檔案頭取代簽名為預定位元之裝置。 83. For example, the decoder of item 80 of the scope of patent application, in which the digital data is compressed using the compression standard that causes the compressed file, and the digital signature and related data are included in the file header of the compressed file, and the encoder further includes: for decoding A device for compressing compressed files;and a device for replacing the signature and related data into predetermined bits and known bits from the file header before extracting the digital signature from the predetermined bits. 83.如申請專利範圍第80項之解碼器,其中使用造成壓縮檔案之壓縮標準壓縮數位資料,且其中數位簽名與相關資料包含於壓縮檔案之檔案頭中,其中編碼器進一步包括:用以解壓縮壓縮檔案之裝置;以及在從預定位元取出數位簽名之前,用以分別從檔案頭取代簽名與相關資料為預定位元與已知位元之裝置。 84. A method for inserting data into digital data for subsequent verification of the digital data, the method comprising the following steps: receiving data from an external source;inserting data into the digital data;and verifying the digital data. 84.一種用以插入資料於數位資料中以便隨後驗證數位資料之方法,該方法包括下列步驟:從外部資源接收資料;插入資料於數位資料中;以及驗證數位資料。 85. Such as the method of item 84 in the scope of patent application, wherein the external resource is radio frequency transmission. 85.如申請專利範圍第84項之方法,其中外部資源為射頻傳送。 86. Such as the method of item 84 in the scope of patent application, where the external resource is Internet connection. 86.如申請專利範圍第84項之方法,其中外部資源為網際網路連接。 87. Such as the method of item 84 in the scope of patent application, the inserted data is used to verify the information together with the digital data. 87.如申請專利範圍第84項之方法,其中插入的資料用來驗證與數位資料一起的資訊。 88. A device for inserting data into digital data for subsequent verification of digital data, the device comprising: a device for receiving data from external sources;a device for inserting data in a digital image;and a device for verifying digital datainstallation. The device. 88.一種用以插入資料於數位資料中以便隨後驗證數位資料之裝置,該裝置包括:用以從外部資源接收資料之裝置;用以插入資料於數位影像中之裝置;以及用以驗證數位資料之裝置。 89. Such as the device of item 88 in the scope of patent application, where the external resource is radio frequency transmission, and the device for receiving data includes an antenna. 89.如申請專利範圍第88項之裝置,其中外部資源為射頻傳送,用以接收資料之裝置包括天線。 90. Such as the device of item 88 in the scope of patent application, in which the external resource is the device connected to the Internet to receive data, including a computer that can access the Internet and receive data. 90.如申請專利範圍第88項之裝置,其中外部資源為網際網路連接用以接收資料之裝置包括可存取網際網路和接收資料之電腦。 91. Such as the device of item 88 in the scope of patent application, the inserted data is used to verify the information along with the digital data. 91.如申請專利範圍第88項之裝置,其中插入的資料用來驗證與數位資料一起的資訊。 92. A method for inserting time data into digital data for subsequent verification of time data and digital data, the method comprising the following steps: providing a semiconductor chip with an anti-tampering clock and time stamp circuit;outputting a digital signature and time from the clock Data to the time stamp circuit;signing the time data and the digital signature that created the time stamp;and verifying the digital data and the time data. 92.一種用以插入時間資料於數位資料中以便隨後驗證時間資料與數位資料之方法,該方法包括下列步驟:提供一具有防搗毀時鐘與時間標籤電路之半導體晶片;從時鐘輸出數位簽名與時間資料至時間標籤電路;簽署時間資料與造成時間標籤之數位簽名;以及驗證數位資料與時間資料。 93. A device for inserting time data into digital data for subsequent verification of time data and digital data, the device comprising: a semiconductor chip with an anti-tampering clock and a time stamp circuit;for outputting digital signatures and time data from the clock to A device for a time stamp circuit;and a device for signing time data and creating a digital signature for the time stamp. 93.一種用以插入時間資料於數位資料中以便隨後驗證時間資料與數位資料之裝置,該裝置包括:具有防搗毀時鐘與時間標籤電路之半導體晶片;用以從時鐘輸出數位簽名與時間資料至時間標籤電路之裝置;以及用以簽署時間資料與造成時間標籤之數位簽名之裝置。 94. The device of item 88 or 93 of the scope of patent application, wherein the device is a digital image generating device, and the digital data represents an image. 94.如申請專利範圍第88或93項之裝置,其中該裝置為數位影像產生裝置,且數位資料代表影像。 95. The device as claimed in item 94 of the scope of patent application, wherein the image generating device is selected from a group consisting of a digital camera, a digital continuous image camera, and a digital scanner. 95.如申請專利範圍第94項之裝置,其中影像產生裝置從一包含數位攝影機、數位連續影像攝影機、與數位掃描器之群組中選擇出來。 96. A method for inserting data into digital data, the method comprising: storing at least one user identification number corresponding to a device used to generate digital data;identifying a user of the device, wherein the user's identification The number is stored in the memory;the identification number corresponding to the identified user is output from the memory;and the data corresponding to the identification number is inserted into the digital data. 96.一種用以插入資料於數位資料中之方法,該方法包括:儲存對應於用來產生數位資料之裝置之至少一使用者之識別號;辨識該裝置之使用者,其中該使用者之識別號儲存於記憶體中;自該記憶體輸出對應於經辨識使用者之該識別號;以及插入對應識別號之資料於數位資料中。 97. Such as the method of item 96 in the scope of patent application, the inserted data is used to verify the digital data. 97.如申請專利範圍第96項之方法,其中插入的資料用來驗證數位資料。 98. Such as the method of item 96 in the scope of patent application, the inserted data is used to verify the information together with the digital data. 98.如申請專利範圍第96項之方法,其中插入的資料用來驗證與數位資料一起的資訊。 99. Such as the method of item 96 in the scope of patent application, where the identification number is the name of the identified user. 99.如申請專利範圍第96項之方法,其中識別號為辨識的使用者之名字。 100. A device for inserting data into digital data, the device comprising: a memory for storing at least one user identification number corresponding to the device;an identification device for identifying the user of the device, wherein The identification number is stored in the memory;a device for outputting the identification number corresponding to the identified user from the memory;and a device for inserting data into the digital data corresponding to the identification number. 100.一種用以插入資料於數位資料中之裝置,該裝置包括:用以儲存對應於該裝置之至少一使用者之識別號之記憶體;用以辨識該裝置之使用者之辨識裝置,其中該識別號儲存於該記憶體中;用以自該記憶體輸出對應於經辨識使用者之識別號之裝置;以及用以對應識別號插入資料於數位資料中之裝置。 101. Such as the 100th device in the scope of patent application, in which the private key used to sign digital data is also stored in the memory corresponding to each user, where the identification number is inserted in the digital data, and the private key is used to sign subsequent The digital data. 101.如申請專利範圍第100項之裝置,其中用以簽署數位資料之私密鑰匙也儲存於對應每個使用者之記憶體中,其中識別號插入於數位資料中,且私密鑰匙用來簽署隨後之數位資料。 102. Such as the 100th device in the scope of patent application, wherein the identification device is a fingerprint identification system. 102.如申請專利範圍第100項之裝置,其中辨識裝置為指紋辨認系統。 103. The 100th device in the scope of patent application, wherein the device is a digital image generating device, and the digital data represents an image. 103.如申請專利範圍第100項之裝置,其中該裝置為數位影像產生裝置,且數位資料代表影像。 104. Such as the 100th device in the scope of the patent application, wherein the image generating device is selected from a group consisting of a digital camera, a digital continuous image camera, and a digital scanner. 104.如申請專利範圍第100項之裝置,其中影像產生裝置從一包含數位攝影機、數位連續影像攝影機、與數位掃描器之群組中選擇出來。
61 paragraphs, as filed
Method and device for inserting and verifying digital signature in digital data
The present invention relates to methods and methods for inserting and verifying digital signatures in digital data and encoders and decoders for inserting and verifying digital signatures and related data in digital images, continuous images, and audio data. Device.
Photos, music, and continuous images have gradually become digitally represented, for many reasons including improved image or sound quality and more economical distribution capabilities. However, digital data content owners (hereinafter referred to as "content owners") gradually understand the risks associated with piracy, and many efforts are directed toward reducing this risk. Digital watermarking is one of the tools for receiving attention to reduce risks. Early attention was focused on the invisible watermark design, but there are still many common signal processing forms such as MPEG-2 or JPEG compression.
It can be understood in the art that there is also a need for a watermark that is easy to disappear, for example, there is no simple image processing operation for the watermark. The purpose of these easy-to-disappear watermarks is to provide a browser with an indication of whether an image has been changed. The completeness of digital images is gradually gaining attention, because many low-cost software systems allow very complex image editing capabilities that can modify images flawlessly. , Currently believes that photos are the best evidence to support this claim. However, this situation may change, if extensive image "editing" capabilities cause the general public to become suspicious of image verification.
The above disputes are all resolved in this technique, and the solution is based on the traditional cryptography that can be clearly understood by verification. The basic idea after cryptographic verification is to pass data through a one-way hash function to generate an N-bit hash, and use a public key encryption algorithm dedicated key to encrypt the N-bit hash to form a digital signature. In order to verify the data, the data in question Hash again and compare this N-bit sequence with the digital signature decoded using the relevant public key.
The disadvantage of this system is that when it first recommends image data as two file requirements, one contains the image and the other contains the signature. Verification requires the existence of two files, one of which may be a hindrance, for example because it is very easy to send the image but forgot to send the relevant signature. In theory, a single file is enough, and an obvious solution is to connect the signature into the image file format file header. However, when the image is converted between different file formats such as tiff, bmp, etc., this solution is questionable.
Recently, Dr. Wong [PH Wong "Public Key Watermark for Image Comparison and Verification", Int. Conf. On Image Processing, 455-459, October 1998] advocated a direct method to insert the signature function into the image , Such a system has the advantage of not being changed by the image file format, and does not require any meta-data format. Perform verification on independent image boxes. For each box, X<sup>r</sup>, The least significant bit of each pixel is set to 0, this modified box passes through the array function together with the width and height information of the original image. The output of this hash function is excluded or (XOR'ed) set with the relevant bit set, B<sub>r</sub>Form a signature, W<sub>r</sub>Public key compiled for encryption to form C<sub>r</sub>=E<sub>k</sub>.(W<sub>r</sub>), C<sub>r</sub>Insert the least significant bit (LSB) of the block to form the watermark image block Y<sub>r</sub>. Wong pointed out B<sub>r</sub>For a binary image or model, its size must be less than or equal to the length of the hash. The purpose of XOR is to encrypt binary images, B<sub>r</sub>. When decoding, the LSB plane of each block is decoded by using the relevant public key, and the least significant bit of the block is set to 0 and XORed with the hash of the block. If the square is real, then Is immutable, the result is B again<sub>r</sub>, That is, use the same hash value XOR the second time to decrypt model B<sub>r</sub>, Otherwise the model still keeps the password form. Image verification by visually inspecting model B'<sub>r</sub>, But in fact, the computer can execute B<sub>r</sub>And B'<sub>r</sub>Comparison of bit mode. Strictly speaking, such an architecture can only verify the most significant bit of each pixel, because the LSB has been changed so that the relevant encrypted and compiled signature can be loaded.
Other parts of this art describe situations in which the correct ownership cannot be solved again by the direct application of the watermark. In particular, by inserting the forged watermark process, they confirm that no one can claim the ownership of the watermark image. To this problem, they provide a solution to this problem using the so-called "non-reversal" watermark method. The basics of this method are The idea is to construct a watermark based on the non-reversal function of the original image. An example of a non-reversal function is the one-way hash function commonly used in cryptography. Such a function takes a series of bits as input and outputs a finite value, such as a 1000-bit output. However, for the 1000-bit output for example, it is computationally infeasible to determine the relevant input. Please note that watermarks like this can only be read by the content owner or the owner of the original image or its hash key. In this way, a public watermark, that is, a watermark that can be renewed by anyone, cannot be reversed or at least lost the benefits of non-reversal, because all readers must have a hash value knowledge.
Furthermore, it is troublesome to use the methods and devices of the aforementioned techniques to verify the images that will be compressed and decompressed later. From the perspective of the verification architecture of JPEG compression, many places in the art have paid attention to this problem. . In other words, when the digital data changes through compression, The image is essentially the same.
In the method and device of the present invention, a signature is inserted into the predetermined bits of the digital data used to verify the digital data. On the other hand, the digital data is verified together with part of the related information. This related information may include copyright notices and owner identification. This information may be embedded in the image in many ways, as discussed in the watermark literature, and the embedding is performed before the signature (a digital signature is created through hashing and cryptographic compilation).
In a certain version of the method and device of the present invention, we are concerned about the situation where the compression algorithm is familiar to the verification system, and this method is applied to, for example, JPEG compressed images or MPEG compressed continuous images. In particular, this method is applied to verification problems in digital cameras or other image generating devices, although the solution is not limited to this situation. A digital camera with a resolution of 1Kx1K produces a very large amount of data that must be stored and may need to be sent from the camera to the computer. In order to speed up this process and reduce storage and bandwidth requirements, it is only natural that data will be compressed. However, when the image is finally decompressed, the browser must still be able to verify the image.
In another version of the method and device of the present invention, not only the digital signature data is used for verification purposes, but also the time is tagged in order to prove the origin of the time. This system is further refined by using the time and location of the image generating device to time-tag the image. The location information of the latter is best used through a global satellite positioning (GPS) receiver.
Therefore, a method for inserting a digital signature into digital data is provided. The digital data includes bits and a method that includes the following steps: Specify the predetermined bits of the digital data used to receive the digital signature; the signature does not include Digital data with predetermined bits of the digital signature; and inserting the digital signature into the predetermined bits of the digital data in order to verify the subsequent digital data.
At the same time, it provides a method for verifying digital data with an embedded digital signature in the predetermined bits of the digital data. This method includes the following steps: selecting a digital signature from a predetermined bit; interpreting the digital signature from the digital data that caused the first hash; applying a one-way hash function to exclude the predetermined bit that caused the second hash On the digital data; and compare the first hash with the second hash, where if the first hash matches the second hash, the digital data is verified.
In a preferred version of the method and device of the present invention, the signing step includes: applying a one-way hash function to the digital data that excludes the predetermined bits that cause the hash; and encrypting the hash.
In another preferred version of the method and device of the present invention, the method further includes a step of inserting relevant data into the digital data before the signing step, so that the digital signature verifies the relevant data and the digital data. Preferably, the relevant data is inserted in the digital data bit excluding the predetermined bit.
At the same time, an encoder and a decoder are provided to implement the method of the present invention.
With regard to the following description, the scope of patent application, and the drawings, these and other features, aspects, and advantages of the method of the present invention will become easier to understand. in:
FIG. 1A illustrates an image frame of a digital image or a sequence of digital continuous images, wherein the image or image frame includes digital data defining a plurality of pixels.
FIG. 1B illustrates the image or image frame of FIG. 1A representing a bit, and the bit includes each pixel from the most significant bit to the least significant bit.
FIG. 1C illustrates the image or image frame of FIG. 1A from the most significant bit plane to the bit plane represented by the least significant bit plane.
FIG. 1D illustrates the image or image frame of FIG. 1A in which the digital data is transformed into a frequency domain with high and low frequency components.
Fig. 1E illustrates the digital audio data from the most significant bit plane to the bit plane represented by the least significant bit plane.
2A is a flowchart illustrating a preferred method of inserting a digital signature into the digital data of the present invention.
2B is a flowchart illustrating a preferred method for verifying digital data with embedded digital signatures in predetermined bits of the digital data.
Fig. 3 is a block diagram of a device for signing and/or tagging digital data to verify subsequent digital data and time stamps.
FIG. 4 is a schematic diagram of a device for inserting data into digital data, the digital data having a device for receiving external resources.
FIG. 5 is a schematic diagram of a device for inserting data into digital data. The digital data has an identifying device to identify the user of the device, and the inserted data is an identifier for identifying the user of the device.
Although the present invention is applied to various types of digital data, it has been found to be particularly effective in the environment of digital image data generated by digital cameras. Therefore, the application of the present invention to image data or digital cameras is not limited, and the present invention will be described in the above-mentioned environment. However, these ordinary techniques in the art will recognize that the method and device of the present invention are equally applicable to digital continuous video and digital audio data, as well as any form of data generating device.
Before discussing the present invention, refer to Figures 1A to 1D to discuss a brief overview. Bit image. Figure 1A illustrates a digital image 100. The digital image 100 may be an image frame from a sequence of image frames in the digital image. The digital image is represented by a plurality of image pixels 102, of which the pixel is shown in the lower right corner of the image 100 come out. Referring now to FIG. 1B, each pixel is defined by a plurality of bits 104, from the most significant bit (MSB) 106 that is most easily visible by human vision to the least significant bit (LSB) 108 that is most difficult to see by human vision. As seen in FIG. 1C, the pixels constituting the image 100 and their related bits form a bit plane, and all the most significant bits 106 of the image pixels 102 constitute the most significant bit plane 110. Similarly, all the least significant bits 108 of the image pixel 102 constitute the least significant bit plane 112. Figure 1E illustrates related digital data, such as audio data, in a time series. The audio digital data is represented by samples (rows) 124. Each sample is represented by the most significant bit 106 to the least significant bit 108, where the relevant bit row is viewed as a plane, from the most significant bit plane 110 to the least significant bit 108. The least significant bit plane 112, even if they are separate columns.
The image 100 represented by the meaning state of the bit defining the pixel is expressed in a unidirectional way of representing digital data like an image. Generally, digital data includes multiple samples, and each sample is defined by multiple bits. The samples are pixels of image data, time stamps of audio data, and spatial temporal samples of continuous image data. This method transforms the bit into another representation with at least the first and second characteristic elements. The predetermined bit includes one of the first and second feature elements. If the related data is also inserted, the related data will be inserted into at least a part of the second feature element.
One way to define an image is to transform digital data into a frequency domain 114, as shown in Figure 1D. In the frequency domain, the image 100 is transformed into a high-frequency component 116 and a low-frequency component 118, respectively. The high-frequency component 116 is less visible to human eyesight than the low-frequency component 118. Preferably, the predetermined bit includes a part of high-frequency components, and if any, any relevant data is inserted into the remaining high-frequency components and/or low-frequency components.
Need to sign (insert a digital signature) or verify that the number of bits in the image 100 is very small, preferably between 128 and 256. The above situation is especially true when compared with 512x512x24 traditional images. Traditionally, digital signatures are inserted. In the LSB plane, because it is the most difficult plane to see for human vision. However, there is no need to change the least significant bits of all the images 100, and only a part of the LSB plane 120 needs to be changed by inserting a digital signature. In this way, the simple signature program inserted into the 120 part of the LSB plane provides a basic verification program with minimal changes to the original image.
The basic insertion method of the present invention is illustrated with some steps in FIG. 2A. In step 200, digital data defining a digital image (or other options, digital continuous image or sound) is provided. In step 202, the predetermined bits of the digital data are assigned to the digital signature to be inserted later. Preferably, the predetermined bit includes at least a part of the LSB plane 120, but any part of the digital data can be designated as the predetermined bit, and the predetermined number of bits is preferably the same as the number of bits in the digital signature. However, the predetermined number of bits can optionally be larger than the size of the digital signature to allow more digital signatures or other data to be inserted.
Next, the signature excludes the digital data of the predetermined bits that cause the digital signature, and any known signature method in the art can be used without departing from the scope and spirit of the present invention. Preferably, by first applying a one-way hash function To complete the signature on the digital data that excludes the predetermined bits that cause the hash (or hash value), step 210 shows the above situation. In step 220, the cryptographic hash is generated to generate a digital signature, and the digital signature is inserted into the predetermined bits of the digital data in step 226. The remaining steps shown in the flowchart of FIG. 2A are better or another alternative to the method discussed above. choose.
Once the digital signature has been inserted into the predetermined bit, the basic method of the present invention for verifying the digital data will be discussed with reference to FIG. 2B. In step 228, the digital signature is selected from the known predetermined bit 120 positions. In step 230, the digital signature is decoded from the digital signature that caused the first hash. In step 232, the known one-way hash function used to encode the digital data is applied to the digital data that excludes the predetermined bits that caused the second hash. In step 234, the first hash and the second hash are compared and a decision is made to determine whether the two are consistent. If the first hash and the second hash are the same (step 238), the digital data is verified; if the first hash and the second hash are not the same (step 240), the digital data is not verified. The remaining steps illustrated in the flowchart of FIG. 2B are preferred steps similar to the preferred steps in the part of FIG. 2A that will be discussed later.
The limitation of this method is that it does not configure the image area that has changed. To be precise, the algorithm simply declares that the image has been verified or has not been verified, and there are many situations where this is appropriate. However, it is simple to follow this method from the block-based method, where each block is signed independently. Furthermore, the signature does not need to be placed in the LSB of the image. The main feature is that the image is divided into two separate spaces. The first space must capture the main features that need to be verified, and the second space is a more surplus, Image areas that may be cognitively meaningless. For example, frequency-based systems are also possible, where The image (or sub-image) is first transformed into the frequency domain 114. Next, when the high-frequency (cognitively meaningless) coefficient 116 is used to retain the digital signature, the low-frequency cognitively meaningful element 118 of the image 100 has been verified. Other changes are possible, including the insertion of the least significant bit of the transformed field.
Of course, it is generally understood that the LSB changes of almost all images cannot be recognized. In this way, other least significant bits, such as (512x512x1-number used for digital signature) provide an opportunity to embed or insert more information in the image (step 208), refer to relevant information. The aforementioned technical method cannot effectively use these bits, because the aforementioned technical method needs to modify all the least significant bits of a block. An alternative version of the present invention is to simply use a large number of remaining bit sets to encode additional information related to the image. Such information may include, but is not limited to, the name of the photographer, copyright permission, etc. The public key needs to interpret the digital signature, the source, or the owner of the digital data, such as the photographer who recorded the digital image and the Internet address. On the other hand, the related information 122 may include at least two parts 122a, 122b, each of which has information that may be independent of each other or related and separated. For example, the area 122a may include identifying the public key used to interpret the digital signature, and the other area 122b may include identifying the owner of the public key included in the first area 122a. When other areas are being encoded, the content owner may choose to encode part of the information in a clean, that is, non-encrypted way.
Preferably, the relevant data is treated and signed as part of the image. In this way, not only the content of the image is verified, but also the relevant information. The relevant information is shown in the reference number 122 of FIG. 1C, and is preferably inserted into the LSB plane excluding the predetermined bit portion, where the predetermined bit contains the digital signature. For the art of Technically speaking, the following situation is obvious. Embedding the relevant data 122 in the remaining part of the LSB plane 108 is the best implementation of the method in the present invention, and can only be done by way of example. Relevant materials may be embedded in various ways, many of which have been described in the aforementioned watermarking techniques.
For the technology in the art, the following situation is obvious. The LSB plane similarly exists in other digital content forms. Generally, digital data includes multiple samples, and each sample is defined by a number of bits in the digital data from the most significant bit to the least significant bit. In the digital image data example, each sample is an image pixel; in a digital continuous image, each sample is a spatial temporal sample; and when in digital audio, each sample is a time sample.
In another alternative version of the insertion method of the present invention, the digital data includes multiple samples, sounds, continuous images, or images. In this alternative, the least significant bit plane in the digital data is ignored, and the relevant data is connected to have the lowest ignored The digital data of the valid bit plane and the digital data with the connected related data are signed to create a digital signature inserted in the predetermined bit. Ignoring not only means that the least significant bit plane has not passed the hash, but also means that the bits of all LSB planes are set to 0 or 1, or any model, etc.
The method of the present invention is not limited to signing complete digital data, and partial areas can also be signed. However, for some techniques, the following situation is obvious. If the signature maintains 128 bits in length, when the image is divided into N blocks, 128N bits are used for the signature. As a result, there may be an exchange between the forged location and the large amount of additional information that can be embedded in the image, especially if the LSB is used to store relevant data and signatures. Under this restriction, if each sub-block contains only 128 pixels, there is no extra capacity available for LSB In the plane. Please note that no matter what, when the method of the present invention preferably requires each sub-block to be greater than or equal to the hash length, Wong requires each sub-block to be less than or equal to the hash length.
Regardless of the very rapid evolution of data storage and transmission rates, images still require a very large bandwidth and storage capacity. Therefore, in many cases, due to economic reasons, content users will need to compress digital data, such as JPEG for images, or MPEG for continuous images. In this case, it is desirable to sign the compressed image and have a signed image after decompression.
Referring back to FIG. 2A, the first decision is whether the digital data is compressed in step 204. If the data is not compressed, the method then signs the digital data as described earlier. If the digital data has been compressed, the digital data is decompressed in step 206 so that the signature is calculated in steps 210 and 220, and the digital signature is inserted in the header of the compressed file in steps 222 and 224. Preferably, the used decompression algorithm is modified so that after the image is decompressed, the signature currently in the file header is copied to the corresponding predetermined bit of the decompressed image.
Now referring to FIG. 2B, after the digital signature compressed file in the file header is verified, the compressed file is decompressed in step 242, and the digital signature in the file header is inserted into the predetermined bits of the digital data in step 244. If the digital data also includes related data (step 246, "Yes" in the decision box), the related data may be inserted in the file header in step 224, and the digital data may be inserted in step 248 after decompression in step 242. On the other hand, you can insert relevant data into the image before compression, and in this way, the relevant data retains the compression step. The method used to verify the digital signature (and if it is currently related data) is steps 228 to 240 as described above.
On the other hand, the verification capability of the method of the present invention extends to include time stamps, which include inserting time data into digital data to determine that the time digital data has been created. Referring back to Figure 2A, the basic procedure for time-stamping digital data as described above includes first sending the digital data through the one-way hash function. The directional hash function and signature are sent to the trusted third that connects the hash, signature, and time data in step 214, and sends the hash, signature, and current time/date (time data) through another one-way hash in step 216 The third party. This hash is compiled in step 218 using the public key encryption method, the password and the encrypted compilation signature, and the time data is returned to the content owner. The signature and time data can be re-encoded in step 226 as described above Becomes part of the digital data predetermined bit. In this way, it is possible to prove that the image is not forged and to determine the date when the original content must already exist. For the technology in the art, the following situation is obvious, and it is known in any art The time stamp program can be used without departing from the scope and spirit of the present invention.
This type of arrangement requires a trusted third-party label organization. Traditionally, organizations like this can be accessed on the Internet, such as the Internet. However, such an architecture is not practical for real-time time stamp images generated by an image generating device, such as images captured by a digital camera, because the digital camera may not be exposed to a trusted third party. Please refer to FIG. 3, an alternative arrangement is to provide each digital camera or an image generating device 300 with a digital data generating device 301, such as a digital scanner or a digital continuous image camera, using a semiconductor crystal with an anti-tamper clock 304 The slice 302 is, for example, capable of performing the same scrolling as the anti-tampering time stamp circuit 306 of a trusted third party public key encryption system. For example, the device 300 preferably has a private key embedded in the memory 308, making it inaccessible. The anti-tamper clock will be set at the factory and cannot be changed for the user. Preferably, the relevant public key is placed within the LSB range of the clean (unencrypted) image. Using the private key from the memory 308, it is signed by the digital data of the device 303. If the related data is to be inserted, the related data inserting device 305 inserts the related data into the digital data before signing by the signing device 303. The relevant information (if any), the signature and the time stamp (if any) are provided to the insertion device 307 for signing and/or the time stamp and/or the time stamp digital data that caused the signature.
The anti-tamper hardware can also provide information other than time. For example, referring to FIG. 4, the image generating device 300 can be provided to receive related data from external sources 402, such as the transmission of a GPS (Global Satellite Positioning) receiving device 404 such as an antenna. In such an environment, it is possible to confirm not only the creation of time-digital data (such as the time of phase taking), but even the location. Under such a method, the image generating device 300 receives the data to be inserted, preferably by RF (Radio Frequency) transmission such as from GPS, inserts the data in the digital data, and verifies the digital data and any inserted related data. The external resource can also be an Internet connection 406, in which the image generating device 400 is connected to a personal computer 408 that has access to the Internet 408 and can receive data transmitted from Internet websites. Data can be downloaded from a digital camera or other image generating device 300 via a memory card slot or a wired device 412 connected to the personal computer 408 material.
In the case of digital cameras or other digital content creation devices, verification and time stamps require the use of a public key encryption system. The device uses the camera's private key to encrypt and compile the signature and/or time stamp. The reader must have knowledge of the relevant public key in order to, that is, to verify the image. However, there may be millions of such devices. An important use of the image LSB is to control the relevant public key of a device, such as a camera, in order to facilitate start-up verification. However, what is certain at this time is that a particular camera captures the image, and the browser does not know who captured the image.
In an alternative version of the aforementioned technical method, this knowledge can also be obtained by allowing the photographer (user) to use his/her name and public and private keys to program his/her camera (image generating device) supply. The name of the photographer is Adam, and the public key may be completely placed within the LSB range of the verified image (digital data). The image comes with all the LSBs, except for the one used to store the signature, it is first signed by the camera using the private key. Next, use the photographer's private key to encrypt and compile this signature.
There may be several signature levels that allow the image to be signed by the camera (representing that the data has not been processed after recording from the CCD array), the photographer (identifying the person in charge of the image), the distributor, etc. However, the early signature level must leave bits that can be used to provide the next-generation signature level and possibly related information. For example, a digital camera may sign all image bits except the LSB plane and insert the signature into the prediction range of the LSB plane. Next, the photographer (in the camera or on the personal computer) may insert relevant information In other areas of the LSB plane, and sign these areas together with the signature from the camera. The second signature will be placed in the prediction range of another LSB plane, and there may be other applications, providing space reserved in predetermined bits to store the signature. Please note that the photographer signed the relevant information and the signature calculated by the camera. This is enough to understand that the photographer captures the image, even if the second level signature does not explicitly sign the image. However, this is an optional method but not a preferred embodiment, because the second hash of the image data does not necessarily give the signature from the camera.
Please refer to FIG. 5, the further accuracy of programming the camera with the public and private keys of the photographer involves providing a digital data generating device 300, that is, a camera, providing a biometric system identification device such as a low-cost fingerprint identification system, for example 502. The camera can be programmed with the information of several photographers, and the correct one can be selected based on the human fingerprint held by the camera 300.
In other words, as shown in FIG. 3, the image generating device 300 having the digital data generating device 301 or other encoding devices additionally has the identifying device 502, and the memory 308 will further store the devices in the range 308a of at least one memory 308 The identification number of the user. The identification number is preferably the name of the photographer or other identification number such as a social security code. Preferably, the private key related to each user is stored in the second area 308b of the memory 308. The identification device 502 identifies the user, and the identification number is stored in the first range 308a of the memory 308, and the identification number of the recognized user is output to the related data insertion device 305 as related data. Preferably, the identified users private key is retrieved from the memory 308 through the signature device 303 for use. The second range 308b is output in order to sign the digital data, so as to ensure that the data (image) will never be modified or adjusted by the second processing. As shown in the specific embodiment in FIG. 3, the relevant information (if any), the time stamp (if any), and the signature are provided to the insertion device 307, and the signature and/or the time stamp that caused the signature and/or It is the time stamp digital data. However, digital data is also signed after subsequent processing, for example in a personal computer. In the case of phasing a digital image via a digital camera, the digital image is first loaded into a personal computer, processed with standard software known in the art, then signed, and the processed image is then verified.
Please note that this is not fundamental when the preferred embodiment produces the second round of cryptographic compilation that takes place in the camera. For example, the image signed by the camera can be downloaded to the personal computer by the photographer, and the application program will execute the second round of encryption and compilation. In fact, for digital cameras that do not support authentication, all the above procedures can be executed when the personal computer is offline. The advantage of the camera-based system is that it automatically performs verification after each photograph is taken. Obviously, however, the photographer can use his personal computer and related software to responsibly sign his work.
The browser first uses the photographer's private key to decode the signature, which is within the available image LSB range. Use the camera public key to interpret the result immediately, and it is also within the available camera LSB range. At this point, the decoded signature can be compared with the hash of the image and data to determine the full authenticity.
Assuming that the verification is negative, the browser at this point only knows that someone has declared Adam as the source of the image. However, nothing can stop someone from becoming Adam. most The latter step is therefore absolutely sure that the photographer is indeed Adam. The browser must verify that Adams public key is indeed Adams. There are many ways to complete it. For example, a trusted third party may provide a list of the photographer and its related public. The key database. Such a database may be provided by a non-profit professional photographer or a business expert. Such a database may be connected and/or printed regularly like a telephone directory. A less centralized solution may involve accessing Adams web pages on the Internet. Of course, because he didn't know Adam's private key, it was impossible for him to encrypt and compile the signature correctly. This is one of the great powers of the public key encryption and compilation system.
When it is understood that the photographer owns many cameras, further refinement of the system can be developed. In this case, the photographer hopes that all cameras owned by him will use a private key related to the photographer. This will contrast with the individual key used by each camera. Nevertheless, the anti-tamper chip can also include the serial number of the camera, so as to confirm which photographer's camera actually took the picture.
It is also obvious that when the interpretation is focused on a static single image, this method can also be applied to continuous images, audio data, and multimedia forms of content.
Although it has been illustrated and described, which should be considered for the preferred embodiments of the present invention, it can of course be understood that some changes and modifications in form or details can be made without violating the spirit of the present invention. Therefore, it is inclined that the present invention is not limited to the precise form described and illustrated, but should be constructed to cover all modifications falling within the scope of the application.
Symbol description
100 Digital Image 102 Image Pixel 104 Bit 106 Most Significant Bit (MSB) 108 Least Significant Bit (LSB) 110 Most Significant Bit Plane 112 Least Significant Bit Plane 114 Frequency Range 116 High Frequency Components 118 Low Frequency Components 120 LSB Part of the plane 122 Related data 122a, 122b Area 124 Sample (row) 300 Camera or image generating device 301 Digital data generating device 302 Semiconductor chip 303 Signing device 304 Anti-tampering clock 305 Related data insertion device 306 Anti-tampering time label circuit 307 Data insertion Device 308 memory 400 Image generating device 402 External resource 404 Receiving device 406 Internet connection 408 Personal computer and the Internet 410 Memory card slot 412 Wired device 502 Identification device
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US9940622B2 | Cited by | United States of America | Applicant |
| US8175938B2 | Cited by | United States of America | Applicant |
| US9317841B2 | Cited by | United States of America | Applicant |
| US10796313B2 | Cited by | United States of America | Applicant |
8 members in 6 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 09294956 | United States of America | – | |
| 29495699 | United States of America | A | |
| 29495699 | United States of America | A | |
| 19990294956 | – | – | – |
| US19990294956 | – | – | – |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| CA2383536A1 | Canada | A1 | |
| WO0064094A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP1210789A1 | European Patent Office (EPO) | A1 | |
| JP2002542523A | Japan | A | |
| TW532022BThis record | Taiwan Province of China | B | |
| EP1210789A4 | European Patent Office (EPO) | A4 | |
| US7216232B1 | United States of America | B1 | |
| EP2157726A2 | European Patent Office (EPO) | A2 |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Annulment or lapse of patent due to non-payment of feesLapsedMM4A | MM4A | |
| Issue of patent certificate for granted invention patentGrantedGD4A | GD4A |
Numbers
- Publication
- 532022
- Publication, DOCDB
- 532022
- Publication, EPODOC
- TW532022B
- Application
- 89107470
- Application, DOCDB
- 89107470
- Application, EPODOC
- TW20000107470
Titles3
- English
- Method and device for inserting and verifying digital signature in digital data
- Chinese
- 用以插入及驗證數位簽名於數位資料之方法和裝置
- English
- METHOD AND DEVICE FOR INSERTING AND AUTHENTICATING A DIGITALSIGNATURE IN DIGITAL DATA
Classification
- CPC, 14
- H04N1/32208
- G06T1/0021
- H04N1/32128
- H04L9/3236
- H04N1/32144
- H04L9/3247
- H04L2209/30
- H04N1/32229
- H04L2209/608
- H04N1/32283
- H04L2209/80
- H04N2101/00
- H04N2201/3233
- H04N2201/3269
- IPC, 9
- G06F12 14
- G06F21 10
- G06F21 60
- G06F21 62
- G06F21 64
- G06T1 00
- G09C1 00
- H04L9 32
- H04N1 32