DeepFake Check
Back to Blog
DeepCheckAI Team 4 min read

C2PA General Box Hash: Reviewing JPEG, PNG, and GIF Integrity

Preserve the file that produced the result

Save the exact JPEG, PNG, or GIF before opening it in a validator. Record its source page, download time, file name, size, and a file identifier. If a platform offers an original and several converted copies, label each copy and state which one you reviewed. This record is an operating recommendation from this article, not a C2PA reporting format.

Use a C2PA-compatible validator and save its full output with the file. Record the tool and version. A badge or one-line status does not show which boxes were listed, whether their order matched the asset, or which hash comparison failed. Avoid re-exporting the evidence copy before validation because the new file would require its own review.

Write down whether the general box hash assertion validates the ordered box data in this copy as reported by the validator. The publisher's identity, the accuracy of a caption, and whether the depicted event occurred require separate evidence.

Read the assertion as an ordered map

C2PA 2.2 assigns the label c2pa.hash.boxes to a general box hash assertion. The specification recommends this hard binding for assets that use non-BMFF box formats, including JPEG, PNG, and GIF. The assertion contains an array of structures. Each structure lists one or more boxes by name or identifier, the hash covering their data, and the hashing algorithm.

Copy the box names, grouping, order, algorithm, and hash status exactly as the validator displays them. C2PA requires the boxes in the assertion to follow the same order as the boxes in the asset, including the box that contains the C2PA Manifest. Boxes found in the asset but absent from the assertion, or boxes listed out of order, cause rejection during validation. Multiple instances of the same type, such as several JPEG APP1 segments, must appear separately.

A grouped range hashes from the start of its first box through the end of its last box, including bytes between those boxes. Separately listed boxes cover only their own data. Preserve that grouping in the record because two displays with the same box names can describe different covered bytes.

Check excluded and manifest boxes

A box entry may carry an excluded boolean. When the field is absent or false, the validator hashes the box and compares the values. When it is true, the validator may ignore that box and its associated hash. Record the displayed value; do not infer it from a missing comparison. The specification asks claim generators concerned with older validators to include an accurate hash even for an excluded box.

The box containing the C2PA Manifest Store also appears in the array under the name C2PA, with a one-byte zero hash. It is represented as one box even when a JPEG manifest is fragmented across multiple APP11 marker segments. Other non-C2PA APP11 boxes remain part of the hashed-box list. For PNG, the special PNGh value can represent the eight-byte PNG header as the first box.

Save any exact failure code or message. A complete record should connect the output to the file identifier, validator version, ordered box list, grouping, excluded values, algorithm, and overall status. Leave fields as unreported when the tool does not expose them.

Limit what match and mismatch mean

A successful comparison supports the bounded observation that the validator calculated the covered box data for this copy and obtained the values declared in the assertion. It does not establish that every metadata value is accurate, that the signer deserves trust, or that a caption about a real event is correct. Excluded boxes and any content outside the displayed coverage need their own review.

A mismatch or structural rejection shows that this file and assertion did not pass the specified integrity check. The result alone does not identify who changed the file, when a change occurred, which visible pixels were affected, or whether a depicted event was staged. Assign another copy a different identifier and validate it independently before comparing results.

A saved image, video, audio, or text can receive a probabilistic risk signal through media analysis. Keep that output in a separate record linked to the analyzed copy. Automated analysis can produce false positives on authentic material and false negatives on synthetic or altered material. A high signal supports further review; a low signal does not authenticate the file or repair a C2PA mismatch.

Check real-world claims through the original publication, the account or organization presenting the media, the claimed date and location, and independent evidence about the event. Close the case record with the file identifier, C2PA output, detector output if used, external-source checks, and the human decision.

Sources

  • C2PA, "C2PA Technical Specification — General Box Hash": https://spec.c2pa.org/specifications/specifications/2.2/specs/C2PA_Specification.html#_general_box_hash

Need to check a suspicious file?

Open the matching detector and interpret the result alongside the source and context.

Open Detector