C2PA Standards
What is C2PA?
Section titled “What is C2PA?”The Coalition for Content Provenance and Authenticity (C2PA) is a Joint Development Foundation project that addresses the prevalence of misleading information online through the development of technical standards for certifying the source and history of media content.
Founding Members
Section titled “Founding Members”C2PA was founded by leading technology companies and media organizations:
- Adobe — Creative software leader
- Arm — Semiconductor and software design company
- BBC — British Broadcasting Corporation
- Intel — Technology giant
- Microsoft — Technology company
- Truepic — Photo and video verification platform
Key Concepts
Section titled “Key Concepts”Content Credentials
Section titled “Content Credentials”Content Credentials are the user-facing term for C2PA manifests — the metadata that records who created content, how it was created, and what changes have been made.
Manifests
Section titled “Manifests”A C2PA manifest is a data structure that contains:
- Claims — Statements about the content (creator, creation date, etc.)
- Assertions — Specific pieces of information or actions
- Signature — Cryptographic proof that the manifest hasn’t been tampered with
- Ingredients — References to any source materials used
Trust Model
Section titled “Trust Model”C2PA uses X.509 certificates for signing, similar to HTTPS. This means:
- Credentials are cryptographically signed
- Signatures can be verified by anyone
- Trust is established through certificate authorities
Technical Specifications
Section titled “Technical Specifications”The C2PA specification defines:
- How to embed credentials in various file formats (JPEG, PNG, PDF, etc.)
- What information to record about content creation and modification
- How to sign and verify credentials cryptographically
- How to display credential information to users