System for tracking end-user electronic content usage
Abstract
A system that tracks the use of digital content on a users device. An electronic store connected to the network sells licenses to play digital content to users. The content player that receives the license content data from the network is used to play the license content data. In addition, a recording site connected to the network tracks the playback of content data. Specifically, the recording site receives playback information from the network, and the playback information contains the number of times the content data has been played by the relevant content player. It also provides a way to track the use of digital content on the user's device. According to this method, a license for playing digital content data is sold to a user, and the licensed content data is sent to a content player of the user. Moreover, whenever content data is played by the content player or copied from the content player to an external medium, information is sent to a recording site so that the use of the licensed content data can be tracked.

Term
Term ended
Expired 12 August 2019, 7.1 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
23 claims: 7 independent, 16 dependent
- 1一个允许安全地提供数据的认证中心,该认证中心能够与一个系统进行通信,该系统能够接收用一个第一加密密钥加密的数据和一个加密的第一解密密钥,所述加密的第一解密密钥是用一个第二加密密钥加密的第一解密密钥,该认证中心包括:从加密的第一解密密钥解密出一个第一解密密钥;和向一个系统传递解密的第一解密密钥。
- 2一个安全地提供数据的系统,该系统包括:用一个第一加密密钥对数据进行加密以产生加密数据;用一个第二加密密钥对一个第一解密密钥进行加密以产生一个加密的第一解密密钥;向一个第二系统传递加密的数据;向一个第二系统传递加密的第一解密密钥;向拥有一个第二解密密钥的一个认证中心传递加密的第一解密密钥;用第二解密密钥解密第一解密密钥;以及向一个第二系统传递第一解密密钥。
- 3如权利要求2所述的系统,其中还包括在传递第一解密密钥之前用一个第三加密密钥对第一解密密钥重新加密,其中向一个第二系统传递第一解密密钥是向一个第二系统传递经过解密和重新加密的第一解密密钥。
- 4如权利要求3所述的系统,其中第三加密密钥是一个第二系统的一个公开密钥。
- 5如权利要求2所述的系统,其中第二加密密钥是认证中心的一个公开密钥并且第二解密密钥是认证中心的一个对应私有密钥。
- 6如权利要求2所述的系统,其中还包括证实数据已付费。
- 7安全地向一个第二系统提供数据的系统,其中以可以被一个数据解密密钥解密的方式加密数据,使用一个第一公开密钥对数据解密密钥进行加密,上述方法包括的步骤有:接收被一个认证中心加密的数据解密密钥;使用一个第一私有密钥解密数据解密密钥;使用一个第二公开密钥重新加密数据解密密钥,其中第二公开密钥具有一个对应的第二私有密钥;并且向一个第二系统传递重新加密的数据解密密钥。
- 8如权利要求7所述的系统,其中从另一个系统接收加密的数据解密密钥。
- 9如权利要求8所述的系统,其中还包括在向一个第二系统传递加密的数据解密密钥之前对数据进行授权。
- 10一个用于管理内容数据,相关元数据和相关使用条件数据的系统,其中包括:针对相关内容数据的元数据和使用条件数据;改变元数据和使用条件数据中的至少一个以产生促销数据;和传递促销数据。
- 11如权利要求10所述的系统,其中内容数据包含音乐数据,并且使用条件数据包含音乐数据播放的时间限制,可以复制的音乐数据副本的最大数量和可以播放音乐数据的最大次数中的至少一个。
- 12如权利要求10所述的系统,其中内容数据包含音乐数据,并且元数据包含到内容数据主机的链接,音乐数据内容的描述,音乐数据相关插图和选定部分的音乐数据中的至少一种。
- 13一个用于管理内容数据,相关元数据和相关使用条件数据的电子内容管理系统,其中上述系统包括:一个能够发送内容数据的相关元数据和内容数据的相关使用条件数据的内容提供商;和一个能够从内容提供商接收元数据和使用条件数据并且能够根据一部分元数据和一部分使用条件数据中的至少一种产生经过改变的促销数据的电子商店。
- 14如权利要求13所述的系统,其中内容提供商还能够用一个第一加密密钥加密内容数据,用一个第二加密密钥加密第一加密密钥;并且发送加密第一加密密钥。
- 15如权利要求13所述的系统,其中内容数据包含音乐数据,并且使用条件数据包含音乐数据播放的时间限制,可以复制的音乐数据副本的最大数量和可以播放音乐数据的最大次数中的至少一个。
- 16如权利要求13所述的系统,其中内容数据包含音乐数据,并且发送的元数据包含标识内容提供商的信息,到内容主机的链接中的至少一种;和音乐数据内容的描述,音乐数据相关插图和选定部分的音乐数据中的至少一种。
- 17如权利要求13所述的系统,其中内容提供商能够发送内容数据,系统还包括一个能够从内容提供商接收内容数据的内容主机。
- 18播放数字内容数据的数字内容数据播放器,上述数据播放器包括一个发送使用信息的发送器,使用信息是数字内容数据播放或复制的发生信息,数字内容数据被播放或复制的次数,数字内容数据被播放或复制的时间和一个播放或复制数字内容数据的用户的标识中的至少一种。
- 19如权利要求18所述的数据播放器,其中数字内容数据包含数字音乐数据。
- 20一个跟踪数字内容的使用的系统,其中包括:一个播放或复制数字内容数据的许可证;许可的数字内容数据;和有关数字内容数据播放或复制的发生信息,数字内容数据被播放或复制的次数,数字内容数据被播放或复制的时间和一个播放或复制数字内容数据的用户的标识中的至少一种的信息。
- 21如权利要求20所述的系统,其中还包括根据该信息禁止进一步播放或复制。
- 22如权利要求20所述的系统,其中数字内容数据包含数字音乐数据。
- 23如权利要求20所述的系统,其中在预定时间或以预定间隔发送信息。
Independent claims23
578 paragraphs, as filed
System for tracking the use of electronic content by end users
The disclosed invention generally relates to the field of e-commerce, and more specifically relates to a secure delivery and copyright management of digital assets such as print media, movies, games and music on global communication networks such as the Internet and World Wide Web. System and related tools.
The use of global distribution systems such as the Internet to distribute digital assets such as music, movies, computer programs, pictures, games, and other content continues to grow. At the same time, owners and publishers of valuable digital content have been slow to accept the use of the Internet to distribute digital assets for several reasons. One reason is that owners are concerned about illegal copying or pirating of digital content. The electronic delivery of digital content removes several barriers to piracy. One obstacle removed by electronic distribution is tangible recordable media (for example, disks or CDs). ROM) own requirements. Copying digital content to tangible media costs money, although in most cases a blank tape or recordable CD only costs less than a dollar. But in the case of electronic distribution, tangible media is no longer needed. Since content is distributed electronically, the cost of tangible media does not become a factor. The second obstacle is the format of the content itself, that is, the content stored in an analog format rather than a digital format. When being photocopied, the quality of the content stored in an analog format, such as a printed picture, is lower than the original. The quality of each subsequent copy of a copy (sometimes called a generation) is lower than the original. When the pictures are stored digitally, there is no such quality degradation. Each copy, and each generation of the copy can be as clear as the original. The combined effect of the perfect digital copy and the extremely low cost of distributing content electronically and widely distributed through the Internet makes it relatively easier to piracy and distribute unauthorized copies. With a few keystrokes, pirates can send hundreds or even thousands of perfect copies of digital content through the Internet. Therefore, it is necessary to ensure the protection and safety of digital assets distributed electronically.
Providers of digital content expect to establish a secure global distribution system for digital content that protects the rights of content owners. The issues of establishing a digital content distribution system include the development of digital content electronic distribution, copyright management, and asset protection systems. Digital content distributed electronically includes content such as print media, movies, games, shows, television, multimedia, and music.
The widespread application of electronic distribution systems provides digital content providers with the ability to achieve rapid payment settlement through instant sales reports and electronic verification, and to obtain auxiliary revenue sources through content redistribution. Since the electronic digital content distribution system is not affected by the loss or return of physical disk storage, digital content providers and retailers can reduce costs and improve reserves. Digital content providers can facilitate new or expand existing distributions to better clear inventory on time. Transaction data from electronic distribution systems can be used to obtain information about consumer purchasing patterns and provide instant feedback on electronic product sales plans and promotions. In order to meet these goals, digital content providers need to use an electronic distribution model to make digital content available to a wide range of users and services, while ensuring the protection and measurement of digital assets.
Other commercially available digital content electronic distribution systems, such as AT&T's realaudio, A2B, Liquid Audio Pro Corp.'s Liquid Audio, AudioSoft's City Music Network and other systems provide digital data through secure and unsecure electronic networks transmission. The use of secure electronic networks greatly reduces the need for digital content providers to distribute digital content to a broad audience. The use of insecure networks such as the Internet and the Web allows digital content to reach end users securely, for example, through encryption. However, once the encrypted digital content is decrypted on the end user's machine, the digital content can be easily redistributed by the end user without authorization. Therefore, there is a need for a secure digital content electronic distribution system that provides digital asset protection and guarantees that the rights of content providers are protected even after the digital content is delivered to consumers and enterprises. Therefore, there is a need to allow safe delivery, license authorization, and copyright management to control the use of digital assets.
Another reason for the slow acceptance of electronic distribution by digital content owners is their desire to maintain and cultivate existing distribution channels. Most content owners sell through retailers. These US retailers in the music market include Tower Records, Peaches, Blockbuster, CircuitCity and others. Many of these retailers have Web sites that allow Internet users to make choices through the Internet and send the selection results to end users. Examples of music Web sites include @tower, Music Boulevard, and Columbia House. The use of electronic distribution can eliminate the ability of retail stores to distinguish themselves from other retail stores and content owners, especially on the Web. Therefore, it is necessary to provide electronic content retailers such as pictures, games, music, programs and videos with a way to distinguish themselves from other retailers and content owners when selling music products through electronic distribution.
Content owners prepare their digital content for electronic distribution through distribution sites such as electronic stores. Electronic stores on the Internet or through other online services hope to differentiate from each other through their product quotations and product upgrades. Traditional stores are non-electronic compared to electronic stores. Non-online stores use product upgrades, product sales, product samples, generous return policies, and other incentive programs to distinguish themselves and their competitors. However, in an online world where content providers impose usage conditions within digital content, the ability of e-shops to distinguish themselves will be severely limited. In addition, even if the conditions of use can be changed, electronic stores still face the difficult task of processing metadata related to digital content from content providers in order to promote and sell products electronically. When dealing with metadata, the e-shop is required to deal with the following needs. First, e-shops are required to receive metadata related to digital content from content providers. Part of this metadata may often be encrypted and sent, so content providers must establish a mechanism to decrypt encrypted content. Second, in order to help the content's product sales, product positioning, and other promotional considerations, the electronic store may wish to preview the metadata from the content provider before receiving the content from the content provider or after receiving the content at the electronic store. Third, e-shops are required to extract certain metadata used to promote materials such as graphics and artist information. These promotional materials are often used directly by e-shops for their online promotions. Fourth, e-shops may wish to differentiate themselves from other e-shops by modifying certain permitted usage conditions in order to establish different digital content offers. Fifth, the e-shop may need to insert or change certain addresses such as URLs in the metadata so that the purchaser can automatically instruct an account reconciliation agency to perform payment verification without the need for payment settlement through the e-shop. Sixth, an electronic store may need to generate a license that allows the use of copyrighted digital content that meets the conditions for use. For example, the license may authorize the production of a limited number of copies of digital content. A license is required to reflect the terms permitted by the license.
Considering all these requirements, in order to process metadata related to digital content, many e-shops write special software programs to handle these requirements. The time, expense, and testing required to generate these dedicated software programs can be very large. Therefore, it is necessary to provide a solution to these requirements.
Another reason for the slow acceptance of electronic distribution by digital content owners is the difficulty of preparing content for electronic distribution. Today, many content providers have thousands or even tens of thousands of titles in their files. In a music example, it is not uncommon for content owners to have a single master recording in several different formats at the same time (such as CDs, tapes, and minidiscs). In addition, for a specific distribution channel, a single format can cause an original recording to be reproduced or remixed. For example, the mixing of a radio broadcast may be different from the mixing of a dance club soundtrack, and the dance club soundtrack may be different from a general consumer CD. The inventory and tracking of these different mixes can be very onerous. In addition, many owners of master recordings often republish old recordings through editing or editing of various "best" series collections, movie music tracks and other collections. As more content is provided digitally, there is a corresponding increase in the need for remixing and encoding electronically distributed content. Providers often need to use the old recording format to guide the selection of the correct master recordings and reprocess and encode these recordings for distribution through electronic distribution. This is especially true for content providers who want to use their old format to help republish old recordings for electronic distribution. The provider will search the database to find the title, artist and recording in order to set the encoding parameters. This manual search of the recording file database is not without its drawbacks. One disadvantage is that an operator needs to manually search a database and set processing parameters appropriately. Another disadvantage is that operator conversion errors can occur when selecting data from the database. Therefore, it is necessary to provide content providers with a method for automatically retrieving related data and master recordings for content such as audio.
Content owners prepare their digital content for electronic distribution through a process called encoding. Encoding involves taking the content, digitizing it while representing the content in an analog format, and compressing it. As the amount of data to be sent or stored is reduced, the compression process allows more efficient delivery over the network and storage of digital content on recordable media. However, compression is not without its disadvantages. Most compression causes the loss of some information, and is called lossy compression. The content provider must decide what compression algorithm to use and what level of compression is required. For example, in the music example, digital content or songs can have very different characteristics depending on the music genre. The compression algorithm and compression level selected for one genre may not be the best choice for another music genre. Content providers may find that certain combinations of compression algorithms and compression levels work well for one music genre, such as classical music, but produce unsatisfactory results for another music genre such as heavy metal. In addition, audio engineers must always equalize music, make dynamic range adjustments, and perform other pre-processing and processing settings to ensure that the encoded music genre produces the desired results. It is always necessary to manually set these encoding parameters. For example, the requirements for setting the equalization level and setting the dynamic range for each digital content are onerous. Returning to the music example, a music content provider with a collection covering various music genres would have to manually select the desired combination of encoding parameters for each song or album to be encoded. Therefore, the requirement to manually select processing parameters for encoding needs to be overcome.
The processing of compressed content can require a large amount of dedicated computing resources, especially for content items such as large feature films. The providers of compression algorithms offer various trade-offs and advantages related to their compression technology. These trade-offs include: the amount of time and computing resources required to compress the content; the amount of compression done based on the original content; the desired playback bit rate; the performance quality of the compressed content; and other factors. Using an encoding program that takes multimedia files as input and produces encoded output files with no intermediate progress or status indications is a problem. In addition, in many cases, other programs are used to call or manage an encoding program that has no intermediate progress indication. This makes it impossible for the called application to estimate the percentage of the amount of content that has been encoded in the total selection of content specified to be encoded. In the case where the calling program tries to schedule several different programs to run immediately, a problem arises. In addition, when several batches of content have been selected for encoding and the content provider wants to determine the progress of the encoding process, its work is particularly arduous. Therefore, these problems need to be overcome.
However, another reason for the slow adoption of electronic distribution by digital content providers for their content is the lack of standards for establishing digital players for electronic delivery of content on end-user devices. Content providers, e-shops or other enterprises in the electronic distribution chain may wish to provide dedicated players on various devices such as PCs, set-top boxes, handheld devices, and so on. There is a need for a set of tools that can decrypt digital content in a tamper-proof environment during playback by a third party, that is, an environment that prevents unauthorized access to the content. In addition, there is a need for a set of tools that allow end users to use a local digital content library without allowing them to access unpurchased content.
Further information about the background of protecting digital content can be found through the following three sources. "International Internet Music and Intellectual Property Protection Issues" by Jack Lacy, James Snyder, and David Maher of AT&T Labs. Florham Park, NJ's existing online URL http://www.a2bmusic.com/about/papers/musicipp.htm. In InterTrust Technology Co., Ltd. Olin Sibert, David Bernstein and David Van Wie's article "Protecting content for information commerce, not lines" is a cryptographically protected container called DigiBox. Sunnyvale, CAs existing online URL http://www.intertrust.com/architecture/stc.html. And the IBM white paper "Encrypted Container Technology", available through the online URL http://cyptolope.ibm.com/white.htm.
An object of the present invention is to eliminate the aforementioned obstacles and provide a system for tracking the usage of content data. An embodiment of the present invention provides a system for tracking the use of digital content on user equipment. An electronic store connected to the network sells licenses to play digital content to users. The content player that receives the license content data from the network is used to play the license content data. In addition, a recording site connected to the network tracks the playback of content data. Specifically, the recording site receives playback information from the network, and the playback information contains the number of times the content data has been played by the relevant content player.
Another embodiment of the present invention provides a method for tracking the use of digital content on user equipment. According to this method, a license for playing digital content data is sold to a user, and the licensed content data is sent to a content player of the user. Moreover, whenever content data is played by the content player or copied from the content player to an external medium, information is sent to a recording site so that the use of the licensed content data can be tracked.
The present invention also provides a certification center that allows data to be provided securely. The certification center can communicate with a system that can receive data encrypted with a first encryption key and an encrypted first decryption key. The encrypted first decryption key is a first decryption key encrypted with a second encryption key, and the certification center includes: decrypting a first decryption key from the encrypted first decryption key; and transmitting to a system The first decryption key for decryption.
The present invention also provides a system for safely providing data. The system includes: encrypting data with a first encryption key to generate encrypted data; and encrypting a first decryption key with a second encryption key to generate An encrypted first decryption key; transfer encrypted data to a second system; transfer encrypted first decryption key to a second system; transfer encrypted first decryption key to a certification center with a second decryption key Decryption key; decrypt the first decryption key with the second decryption key; transfer the first decryption key to a second system.
The present invention also provides a system for safely providing data to a second system, wherein the data is encrypted in a way that can be decrypted by a data decryption key, and a first public key is used to encrypt the data decryption key. The above method includes The steps are: receiving the data decryption key encrypted by a certification center; using a first private key to decrypt the data decryption key; using a second public key to re-encrypt the data decryption key, where the second public key has a Corresponding second private key; and pass the re-encrypted data decryption key to a second system.
The present invention also provides a system for managing content data, related metadata and related use condition data, including: metadata and use condition data for related content data; changing at least one of the metadata and use condition data to generate Promotional data; and the delivery of promotional data.
The present invention also provides an electronic content management system for managing content data, related metadata and related usage condition data, wherein the above-mentioned system includes: a content provider that can send related metadata of content data and related usage condition data of content data And an electronic store that can receive metadata and usage condition data from a content provider and can generate changed promotional data based on at least one of a part of the metadata and a part of the usage condition data.
The present invention also provides a digital content data player for playing digital content data. The data player includes a transmitter that sends usage information. The usage information is information about the occurrence of digital content data playback or copying, and the number of times the digital content data is played or copied. , At least one of the time when the digital content data was played or copied, and the identification of a user who played or copied the digital content data.
The present invention also provides a system for tracking the use of digital content, which includes: a license to play or copy digital content data; licensed digital content data; and information about the occurrence of digital content data playback or copying, and the digital content data is played Or information about at least one of the number of times of copying, the time when the digital content data was played or copied, and the identification of a user who played or copied the digital content data.
Figure 1 is a block diagram illustrating the overall concept of a secure digital content electronic distribution system based on the present invention.
Figure 2 is a block diagram illustrating an example security container (SC) based on the present invention and related diagrams.
Fig. 3 is a block diagram illustrating the overall concept of a secure container (SC) encryption process based on the present invention.
Fig. 4 is a block diagram illustrating the overall concept of a secure container (SC) decryption process based on the present invention.
Fig. 5 is a block diagram illustrating the overall hierarchical concept of the copyright management system of the secure digital content distribution system of Fig. 1 based on the present invention.
FIG. 6 is a block diagram illustrating the overall concept of the license control layer and content distribution and license control applicable to FIG. 5.
Fig. 7 is a diagram of an example user interface of the workflow manager tool of Fig. 1 based on the present invention.
Fig. 8 is a block diagram of the main tools, components and processing of the workflow manager based on the present invention corresponding to the user interface in Fig. 7.
Fig. 9 is a block diagram illustrating the main tools, components and processing of the electronic digital content store in Fig. 1 based on the present invention.
Fig. 10 is a block diagram illustrating the main components and processing of the end user equipment of Fig. 1 based on the present invention.
FIG. 11 is a flowchart of a method for calculating the encoding rate of the content preprocessing and compression tool used in FIG. 8 based on the present invention.
Fig. 12 is a flowchart of a method for automatically retrieving additional information used in the automatic metadata acquisition tool of Fig. 8 based on the present invention.
Fig. 13 is a flowchart of a method for automatically setting the preprocessing and compression parameters of the preprocessing and compression tool of Fig. 8 based on the present invention.
FIG. 14 is an example of a user interface screen of a player application program that downloads content to a local library as described in FIG. 15 based on the present invention.
Fig. 15 is a block diagram illustrating the main components and processing of a player application running on the end-user device of Fig. 9 based on the present invention.
Fig. 16 is an example of a user interface screen of the player application of Fig. 15 based on the present invention.
FIG. 17 is a flowchart of an alternative embodiment for automatically retrieving additional information for the automatic metadata acquisition tool of FIG. 8 based on the present invention.
A table of contents is provided for the present invention to help readers quickly navigate to different chapters in the embodiment.
I. Secure digital content electronic distribution system A. System overview 1. Copyright management 2. Metering 3. Open architecture B. System functional components 1. Content provider 2. Electronic digital content store 3. Middle market partner 4. Certification Center 5. End-user equipment 6. Transmission infrastructure C. System usage II. Cryptography concept and its application in secure digital content electronic distribution system A. Symmetric algorithm B. Public key algorithm C. Digital signature D. Digital certificate E. SC Graphical Guidelines F. Examples of Secure Container Encryption III. Secure Digital Content Electronic Distribution System Process IV. Copyright Management Architecture Model A. Architecture Hierarchical Functions B. Functional Division and Process 1. Content Formatting Layer 2. Content Usage control layer 3. Content recognition layer 4. License control layer C. Content distribution and license control
V. Secure container structure A. Overall structure B. Copyright management language syntax and semantics C. Overview of the secure container process and processing D. Metadata secure container 620 format E. Quotation secure container 641 format F. Transaction secure container 640 format G. Order secure container 650 format H. License secure container 660 format I. Content secure container format VI. Secure container packaging and disassembly A. Overview B. List of materials (BOM) fragment C. Key description fragment VII. Certification center A. Overview B. Copyright management processing C. Country-specific parameters D. Audit logs and tracking E. Results reporting F. Accounting and payment verification G. Reissue VIII. Content provider A. Overview B. Workflow manager 1. Product waiting Action/information processing 2. New content request processing 3. Automatic metadata acquisition processing 4. Manual metadata input processing
5. Use condition processing 6. Supervised publishing processing 7. Metadata SC generation processing 8. Watermark processing 9. Pre-processing and compression processing 10. Content quality control processing 11. Encryption processing 12. Content SC generation processing 13. Final quality assurance processing 14. Content delivery processing 15. Work flow rules C. Metadata assimilation and input tool 1. Automatic metadata acquisition tool 2. Manual metadata input tool 3. Use condition tool 4. Metadata SC fragment 5. Supervised release tool D. Content processing tool 1. Watermarking tool 2. Preprocessing and compression tool 3. Content quality control tool 4. Encryption tool E. Content SC creation tool F. Final quality assurance tool G. Content delivery tool H. Content promotion website I. Content Hosting 1. Content hosting site 2. Content hosting site provided by the secure digital content electronic distribution system 111
IX. Electronic digital content store A. Overview-support multiple electronic digital content stores B. Point-to-point electronic digital content distribution services 1. Comprehensive requirements 2. Content acquisition tools 3. Transaction processing module 4. Notification interface module 5. Accounts Check tool C. Broadcast electronic digital content distribution service X. End user equipment A. Overview B. Application installation C. Secure container processor D. Player application 1. Overview 2. End user interface components 3. Copy/play management Component 4. Decryption 1505, decompression 1506 and playback component 5. Data management 1502 and library access component 6. Application internal communication component 7. Other miscellaneous components 8. Universal player I. Secure digital content electronic distribution system A. System overview The secure digital content electronic distribution system is a technology platform, which includes the technologies, specifications, tools and software required to securely deliver digital content and digital content-related content to end users, client devices, and perform copyright management. End-user equipment includes PCs, set-top boxes (IRD), and Internet equipment. These devices can copy content to external media or portable user devices when permitted by the content owner. The term digital content or content refers to information and data stored in digital format, including: pictures, movies, videos, music, programs, multimedia, and games.
The technology platform specifies how to prepare digital content, how to safely distribute digital content through point-to-point and broadcast infrastructure (such as cable, Internet, satellite, and wireless) authorized to end-user devices, and prevent illegal copying or playback. In addition, with future development, the architecture of the technology platform allows integration and transplantation of various technologies such as watermarking, compression/encoding, encryption and other security algorithms.
The basic components of a secure digital content electronic distribution system are: (1) copyright management to protect the ownership of content owners; (2) transaction measurement for instant and accurate compensation; (3) an open and well-documented system structure, This architecture allows content providers to prepare content and securely deliver content through multiple network infrastructures for playback on any standards-compliant player.
1. Copyright management realizes copyright management in a secure digital content electronic distribution system through a set of functions distributed among system operating components. Its main functions include: license authorization and control so that the content can only be opened by authorized intermediates or end users who have the license; control and implement the control and implementation of the license based on the purchase or license conditions such as the number of copies allowed, the number of playbacks, the time interval or period of license validity Use of content. The auxiliary function of copyright management is to allow some means to identify the source of unauthorized copies of content in order to combat piracy.
License authorization and control are realized by using one or more certification center entities and secure container (SC) technology. By allowing intermediate or end users to open content after verifying that a license transaction is successfully completed, the certification center provides license authorization. Secure containers are used to distribute encrypted content and information among system components. SC is an encrypted carrier of information or content. It uses encryption, digital signatures and digital certificates to prevent unauthorized interception or modification of electronic information and content. SC also allows verification of the authenticity and integrity of digital content. The advantage of these copyright management functions is that the electronic digital content distribution infrastructure does not have to be secure or trustworthy. Therefore, it is allowed to transmit through network infrastructure such as the Web and the Internet. This is because the content is encrypted inside the secure container and its storage and distribution are separated from the control of its opening and use. Only users who have the decryption key can open the encrypted content, and the certification center only issues the decryption key for authorization and appropriate use requests. The certification center will not process forged requests from unknown or unauthorized parties or requests that do not comply with the content usage conditions set by the content owner. In addition, if the SC is tampered with during its transmission, the software in the certification center determines that the content in the SC is corrupted or forged and rejects the transaction.
The use of an end user player application 195 running on an end user device allows control of content usage. The application embeds in each copy of the content a digital code that defines the permitted number of times for second-generation copying and playback. Digital watermarking technology is used to generate digital codes, making them invisible to the end user player application 195 and resisting alteration attempts. In an alternative embodiment, the digital code happens to be part of the usage conditions associated with the content 113. When accessing the digital content 113 in a licensed end user device, the end user player application 195 reads the watermark to check the usage restrictions and update the watermark as required. If the requested content usage does not meet the usage conditions, for example, the number of copies is exhausted, the end user device will not execute the request.
Digital watermarking also provides a means to identify the source of authorized or unauthorized copies of content. The content owner embeds an initial watermark in the content to identify the content owner, specify copyright information, define the geographic distribution area, and add other relevant information. A second watermark is embedded in the content on the end-user device to identify the content purchaser (or licensee) and the end-user device, specify the purchase or license conditions and date, and add any other relevant information.
Since the watermark becomes an integral part of the content, the watermark is carried through the copy regardless of whether the copy is authorized or not. Therefore, no matter where the content belongs or comes from, digital content always contains information about its origin and its permitted use. This information can be used to resist illegal use of content.
2. Metering is a part of its copyright management function, and the certification center records all key exchange transactions through the certification center. These records allow the license authorization and initial conditions for metering use. Transaction records can be reported immediately or periodically to responsible parties such as content owners or content providers, retailers, etc., for electronic verification of transaction payments and other uses.
3. Open architecture The secure digital content electronic distribution system (system) is an open architecture that has open specifications and interfaces, promotes the system to be widely used and accepted in the market, and maintains the protection of the rights of content owners. The flexibility and openness of the system architecture also allow for continuous development in the future as various technologies, transmission infrastructure and equipment are delivered to the market.
Regarding the nature of the content and its format, the architecture is open. The architecture supports the distribution of audio, program, multimedia, video, or other types of content. The content may have an original format, such as linear PCM for digital music, or may have a format realized by additional pre-processing or encoding such as filtering, compression, or pre-emphasis/de-emphasis. The architecture is open to various encryption and watermarking methods. It allows the selection of specific technologies to accommodate different content types and formats, and allows the introduction or adoption of new technologies as it develops. This flexibility allows content providers to select and evolve technologies for data compression, encryption, and formatting within electronic distribution systems for secure digital content.
The architecture is also open to different distribution networks and distribution models. The architecture supports content distribution on low-speed Internet connections or high-speed satellites and satellites, and can be used in point-to-point or broadcast models. In addition, the design architecture makes it possible to realize the functions in the end-user equipment through many kinds of equipment including low-cost user equipment. This flexibility allows content providers and retailers to provide content to intermediate or end users through various service methods, and allows users to purchase or license the content, play back the content, and record the content on a variety of compatible player devices.
B. System functional components Turn now to FIG. 1, which shows a block diagram illustrating the overall concept of the secure digital content electronic distribution system 100 based on the present invention. The secure digital content electronic distribution system 100 has several business elements including a point-to-point solution, including: content provider 101 or digital content owner, electronic digital content store 103, middle market partner (not shown), certification Center 105, content hosting site 111, infrastructure 107 and end user equipment 109. Each such business element uses various components of the secure digital content electronic distribution system 100. According to the electronic content 113 to which it belongs, the high-level description of these business elements and system components is as follows.
1. Content Provider 101
The content provider 101 or content owner is the owner of the original content 113 and/or the distributor of the independent content 113 that is authorized to package for further distribution. The content provider 101 can directly use its rights or license the content 113 to the electronic digital content store 103 or a mid-market partner (not shown), and the electronic digital content store or mid-market partner usually pays for content usage involving e-commerce revenue As a payback. Examples of the content provider 101 include Sony, Time-Wamer, MTV, IBM, Microsoft, Turner, Fox, and so on.
In order to prepare its content 113 and related data for distribution, the content provider 101 uses tools provided as part of the secure digital content electronic distribution system 100. As the content 113 passes through the various steps of content 113 preparation and packaging, a workflow manager tool 154 schedules the processing of the content 113 and tracks the content 113 in order to maintain high quality assurance. The term metadata is used in various places in this document to indicate data related to content 113, and the content 113 itself is not included in this embodiment. For example, the metadata of a song can be a song title or song producer information, but not the song recording itself. Content 113 will contain recordings. The metadata assimilation and input tool 161 is used to extract metadata from the database 160 of the content provider or the data provided by the content provider in a prescribed format (for the music example, the content 113 information can be CD title, artist name, song title, CD illustrations, etc.) and package them for electronic distribution. The metadata assimilation and input tool 161 is also used to input the usage conditions of the content 113. The data in the conditions of use can include copy restriction rules, wholesale prices, and any business rules deemed necessary. The watermarking tool is used to hide data identifying the content owner, processing date and other related data in the content 113. For an embodiment where the content 113 is audio, an audio preprocessor tool is used to adjust the dynamics and/or equalize the content 113 or other audio to obtain the optimal compression quality, compress the content 113 to the desired compression level, and to 113 for encryption. Doing so helps keep up with technological advances in digital content compression/encoding, encryption, and formatting methods, thereby allowing content providers 101 to use the best tools as they develop in the market in the future.
Encrypted content 113, digital content related data or metadata, and encryption keys are encapsulated in SC (described below) by the SC encapsulator tool, and stored in a content hosting site and/or promotional Web site for electronic distribution. The content hosting site may reside at the content provider 101, or may reside in multiple locations including the electronic digital content store 103 and the facilities of a mid-market partner (not shown). Since the content 113 and the key (described below) are encrypted and encapsulated in the SC, the electronic digital content store 103 or any other resident agent cannot directly access the decrypted content without obtaining permission from the certification center and notifying 101 113.
2. Electronic Digital Content Store 103 The electronic digital content store 103 is an entity that sells the content 113 through a variety of services or applications such as the content 113 theme plan or the electronic sales plan of the content 113. The electronic digital content store 103 manages the design, development, operation, settlement, sales planning, marketing, and sales of its services. An example of an online electronic digital content store 103 is a Web site that provides electronic downloads of software.
Within its service, the electronic digital content store 103 implements certain functions of the secure digital content electronic distribution system 100. The electronic digital content store 103 aggregates information from the content provider 101, encapsulates the content and metadata in additional SCs, and delivers those SCs to users or enterprises as part of services or applications. The electronic digital content store 103 uses the tools provided by the secure digital content electronic distribution system 100 to support: metadata extraction, auxiliary use conditions, SC packaging, and electronic content transaction tracking. The auxiliary use condition data may include retail quotations such as the purchase price of the content 113, pay-per-view prices, copy authorization and target device type, or timing availability restrictions.
Once an electronic digital content store 103 completes a legitimate request for electronic content 113 from an end user, the electronic digital content store 103 is responsible for authorizing the authentication center 105 to issue the decryption key of the content 113 to the customer. The electronic digital content store also authorizes the download of the SC containing the content 113. An electronic digital content store may choose to host an SC containing digital content on its local site and/or utilize the hosting and distribution facility of another content hosting site.
For any questions or problems that an end user may encounter when using the secure digital content electronic distribution system 100, the electronic digital content store can provide services to customers, or the electronic digital content store 103 can subcontract its customer service support to the certification center 105.
3. Middle market partner (not shown)
In an alternative embodiment, the secure digital content electronic distribution system 100 can be used to securely provide content 113 to other businesses known as middle market partners. These partners may include companies such as television stations or video clubs, radio stations, or record clubs that provide non-electronic services for distributing content 113 related to digital content. These partners may also include other commissioned groups that process the data as part of the production or sale of recordings, such as recording studios, duplicators, and producers. These mid-market partners need to obtain a license from the certification center 105 in order to decrypt the content 113.
4. The certification center 105 The certification center 105 provides license authorization and records for all transactions involving the sale and/or licensed use of the encrypted content 113 in an SC. When the certification authority 105 receives a request for the decryption key of the content 113 from an intermediate or end user, the certification authority verifies the integrity and authenticity of the information in the request; the verification request obtains an electronic digital content store or content provider 101 Authorization; verify that the requested use complies with the content use conditions as defined by the content provider 101. Once these verifications are approved, the certification center 105 sends the request and the end user the content 113 decryption key encapsulated in a license SC. Encrypt the key in some way so that only authorized users can retrieve it. If the end user's request is not verifiable, complete or authorized, the certification authority 105 rejects the request for the decryption key.
The certification authority 105 records all transactions and can report the recorded content to responsible parties such as the electronic digital content store 103 and the content provider 101 immediately, regularly or in a prescribed manner. This report is a means by which the content provider 101 understands the sales of the content 113 and the electronic digital content store 103 obtains an audit trail of the electronic delivery of its customers. If it is detected that the information in an SC has been damaged or does not meet the content usage conditions, the certification center 105 may also notify the content provider 101 and/or the electronic digital content store 103. The transaction records and storage capabilities of the authentication center 105 database are constructed for data extraction and report generation.
In another embodiment, the authentication center 105 may provide customer support for transactions and exception handling such as repayments, transmission failures, and purchase disputes. The certification center 105 can act as an independent entity that provides entrusted supervisors for copyright management and measurement. It provides accounting and settlement as required. Examples of electronic authentication centers include Secure-Bank.com and Secure Electronic Transaction (SET) provided by Visa/Mastercard. In one embodiment, the authentication center 105 is a Web site that the end user device 109 can access. In another embodiment, the certification authority 105 is part of the electronic digital content store 103.
5. End-user device 109 The end-user device 109 is any player device that contains an end-user player application 195 (described later) that complies with the specifications of the secure digital content electronic distribution system 100. These devices can include PCs, set-top boxes (IRD), and Internet equipment. The end user player application 195 may be implemented by software and/or user electronic hardware. In addition to performing playback, recording, and library management functions, the end user player application 195 performs SC processing to allow copyright management in the end user device 109. The end user device 109 manages the download and storage of the SC containing the digital content. Request and receive the encrypted digital content key from the certification center 105; process the watermark every time the digital content is copied or played; manage the number of copies (or deleted copies) made according to the use conditions of the digital content; copy when permitted To an external medium or portable user equipment. The portable user device can execute a subset of the functions of the end user player application 195 in order to handle the content usage conditions embedded in the watermark. The terms end-user and end-user player application 195 are used throughout the text to mean using or running on the end-user device 109.
6. The transmission infrastructure 107 The secure digital content electronic distribution system 100 is independent of the transmission network connecting the electronic digital content store 103 and the end user device 109. The system supports point-to-point distribution models such as the Internet and broadcast distribution models such as digital broadcast television.
Even if the same tools and applications are used to obtain, encapsulate and track content 113 transactions through various transmission infrastructures 107, the specific form and method in which services are delivered to customers can occur according to the selected infrastructure and distribution model change. Since the high-bandwidth infrastructure can deliver high-quality digital content with a more acceptable response time than the low-bandwidth infrastructure, the quality of the delivered content 113 changes. A service application designed for the point-to-point distribution model can also be adapted to support the broadcast distribution model.
C. System Use Whether for users or enterprises, the secure digital content electronic distribution system 100 allows the secure delivery of high-quality electronic copies of the content 113 to the end user device 109, and allows the use of the content 113 to be regulated and tracked.
The secure digital content electronic distribution system 100 can be applied to various user and business-to-business services that utilize new and existing distribution channels. Each specific service can use a different financial model, wherein the above financial model can be executed by the copyright management function of the secure digital content electronic distribution system 100. Through the copyright management of the certification center 105 and the copy protection function of the end user player application 195, models such as wholesale or retail purchases, pay-as-you-go usage, subscription services, copy/no copy restrictions or redistribution can be realized.
The secure digital content electronic distribution system 100 allows the electronic digital content store 103 and mid-market partners to have a lot of flexibility in establishing a service for selling content 113. At the same time, the content provider 101 is provided with a level of assurance to protect and measure their digital assets so that they can receive appropriate compensation for the content 113 license.
II. The concept of cryptography and its application in a secure digital content electronic distribution system The basis of permission control in the secure digital content electronic distribution system 100 is the use of cryptography. This section introduces the basic cryptographic techniques of the present invention. The use of public key encryption, symmetric key encryption, digital signatures, digital watermarks and digital certificates is known.
A. Symmetrical Algorithm In the secure digital content electronic distribution system 100, the content provider 101 uses a symmetrical algorithm to encrypt content. Because the same key is used to encrypt and decrypt data, the above algorithm is called a symmetric algorithm. The data sender and message receiver must share the secret key. The shared key here is called a symmetric key. The architecture of the secure digital content electronic distribution system 100 is independent of the specific symmetric algorithm selected for a specific implementation.
Commonly used symmetric algorithms are DES, RC2 and RC4. DES and RC2 are block ciphers. Block ciphers use one data bit block at a time to encrypt data. DES is an official encryption standard of the US government. It has a 64-bit block length and uses a 56-bit key. Triple DES is usually used to increase the security strength achieved by pure DES. RSA Data Security designed RC2. RC2 uses variable-length key cipher and has a 64-bit block length. RC4, also designed by RSA, is a variable-length key stream cipher. Streaming ciphers process a single data bit at a time. RSA Data Security stated that RC4 requires 8 to 16 machine operations per output byte.
IBM designed a fast algorithm called SEAL. SEAL is a streaming algorithm that uses variable-length keys and has been optimized for 32-bit processors. SEAL requires approximately 5 primary machine instructions for each data byte. In the case that the 160-bit key used has been preprocessed into an internal table, a 50 MHz, 486-based computer processes the SEAL password at a speed of 7.2 Mbytes/sec.
Microsoft reported the results of the encryption performance benchmarking program in the overview of its CryptoAPI document. These results were obtained through an application using Microsoft's CryptoAPI, running on a 120 MHz Pentium-based computer with the operating system Windows NT4.0.
B. Public key algorithm In the secure digital content electronic distribution system 100, a public key is used to encrypt a symmetric key and other small data blocks. The public key algorithm uses two keys. These two keys are mathematically related so that data encrypted with one key can only be decrypted by the other key. The owner of the key keeps one key secret (private key) and publicly distributes the second key (public key).
In order to use the public key algorithm to ensure the security of confidential message transmission, the message must be encrypted with the recipient's public key. Only the recipient with the relevant private key can decrypt the message. Public key algorithms are also used to generate digital signatures. The private key is used for this purpose. The following sections provide information about digital signatures.
The most commonly used public key algorithm is the RSA public key cipher. This algorithm has become the de facto industry public key standard. Other algorithms suitable for encryption and digital signatures are ElGamal and Rabin. RSA is a variable-length key cipher.
Symmetric key algorithms are faster than public key algorithms. In software implementation, DES is usually at least 100 times faster than RSA. Therefore, RSA is not used to encrypt batches of data. RSA Data Security reported that on a 90 MHz Pentium machine, RSA Data Securitys toolkit BSAFE 3.0 has a throughput of 21.6 kilobits per second for private key operations with a 512-bit modulus, and for The 1024-bit modulus private key operation has a throughput of 7.4 kbits/sec.
C. Digital signature In the secure digital content electronic distribution system 100, the issuer of the SC protects the integrity of the SC by digitally signing it. Generally, in order to generate a digital signature of a message, a message owner first calculates a message digest (defined below) and then encrypts the message digest using the owner's private key. Use its signature to distribute messages. By first decrypting the signature using the public key of the message owner to recover the message digest, any recipient of the message can verify the digital signature. Then, the receiver calculates the digest of the received message and compares it with the recovered digest. If the message is not changed during the distribution, the calculated digest and the recovered digest must be equal.
In the secure digital content electronic distribution system 100, since the SC contains several data fragments, a summary is calculated for each fragment and a summary summary is calculated for each fragment summary connected in series. The summary digest is encrypted using the private key of the issuer of the SC. The encrypted summary digest is the issuer's digital signature to the SC. The fragment digest and digital signature are contained in the SC body. The recipient of the SC can verify the integrity of the SC and its various fragments by relying on the received digital signature and fragment digest.
A one-way hash algorithm is used to calculate the message digest. The hash algorithm gets a variable-length input message and converts it into a fixed-length string, the message digest. The one-way hash algorithm only operates in one direction. That is, it is easy to calculate a digest of an input message, but it is difficult (computationally infeasible) to generate an input message based on its digest. Due to the nature of the one-way hash function, the message digest can be regarded as the fingerprint of the message.
More general one-way hash functions are MD5 from RSA Data Security and SHA designed by the National Institute of Technology and Standards (NITS).
D. Digital certificates Digital certificates are used to authenticate or verify the identity of the person or entity sending the digitally signed message. A digital certificate is a digital file issued by a certification authority that restricts the public key to a single individual or entity. The certificate contains the public key, the name of the individual or entity, the expiration date, the name of the certification body and other information. The certificate also contains the digital signature of the certification authority.
When an entity (or individual) sends a message signed with its private key and with its digital certificate, the recipient of the message uses the entity name in the certificate to determine whether to accept the message.
In the secure digital content electronic distribution system 100, in addition to the SC issued by the end user device 109, each SC contains the certificate of the creator of the SC. Since many end users do not worry about obtaining or possessing a certificate issued by a non-beneficial certification authority, the end user device 109 does not need to include the certificate in its SC. In the secure digital content electronic distribution system 100, the certification center 105 has the option of issuing a certificate to the electronic digital content store 103. This allows the end user device 109 to independently verify that the electronic digital content store 103 has been authorized by the secure digital content electronic distribution system 100.
E. SC Graphical Guide This article uses a graphic illustration of SC, which shows encrypted fragments, non-encrypted fragments, encryption keys and certificates. Referring now to FIG. 2, an example of SC 200 is shown. The following symbols are used in the SC legend. The key 201 is a public or private key. The key of the certification center, for example, the tooth of CLRNGH indicates the key owner. The PB in the key handle indicates that it is a public key, so the key 201 is a public key of the certification center. The PV inside the key handle indicates that it is a private key. The diamond is an end user digital signature 202. In the following table, each prefix indicates which private key is used to generate the signature that is the end user's digital signature in the EU. The symmetric key 203 is used to encrypt the content. An encrypted symmetric key object 204 includes a symmetric key 203 encrypted with CLRNGH's PB. The key on the top border of the rectangle is the key used for encryption of the object. The symbol or text inside the rectangle indicates the encryption object (a symmetric key in this case). It shows another encrypted object, in this example a transaction ID encrypted object 205. And the usage conditions 206 for content license management are as follows. The SC 200 includes a usage condition 206, a transaction 206 encrypted object 205, an application ID encrypted object 207 and an encrypted symmetric key object 204, all objects are signed with an end user digital signature 202.
The following list shows the prefixes that identify the signatories of the SC.
F. Examples of Secure Container Encryption The following list and diagram provide an overview of the encryption and decryption processes used to generate and recover information from the SC. The SC generated and decrypted in this process overview is a general purpose SC. It does not represent any specific SC type used for copyright management in the secure digital content electronic distribution system 100. The processing includes the steps described in FIG. 3 for the encryption process.
The process flow steps of the encryption process in Figure 3 Process 301 The sender generates a random symmetric key and uses it to encrypt the content.
302 The sender processes the encrypted content through a hashing algorithm to generate a content digest.
303 The sender uses the receiver's public key to encrypt the symmetric key. PB
RECPNT refers to the public key of the recipient.
304 The sender processes the encrypted symmetric key through the same hash algorithm used in step 2 to generate a symmetric key digest.
305 The sender uses the same hash algorithm used in step 2 to join the content digest and the symmetric key digest to generate the SC digest.
306 The sender encrypts the SC digest with the sender's private key to generate a digital signature of the SC. PV SENDER refers to the private key of the sender.
307B The sender generates an SC file, which contains encrypted content, encrypted symmetric key, content digest, symmetric key digest, sender's certificate, and SC signature.
307A The sender must obtain a certificate from a certification authority before starting secure communication. The certification authority includes the sender's public key, the name of the sender, and signs it in the certificate. PV CAUTHR refers to the private key of the certification authority. The sender sends SC to the receiver.
The process flow step of the decryption process in FIG. 3 Process 408 The receiver receives the SC and separates its various fragments.
409 The receiver verifies the digital signature in the sender's certificate by decrypting it with the public key of the certification authority. If the digital signature of the certificate is valid, the receiver obtains the sender's public key from the certificate.
410 The receiver uses the sender's public key to decrypt the SC digital signature. In this way, the SC summary is restored. PB SENDER refers to the public key of the sender.
411 The receiver connects the received content digest and encryption key digest through the same hash algorithm used by the sender to calculate the SC digest.
412 The receiver compares the calculated SC digest with the SC digest recovered according to the sender's digital signature. If they are the same, the receiver confirms that the received digest has not been changed and continues the decryption process. If they are not the same,
The receiver discards the SC and notifies the sender.
413 The receiver encrypts the symmetric key by the same hash algorithm used in step 411 to calculate the symmetric key digest.
414 The receiver compares the calculated symmetric key digest with the symmetric key digest received through the SC. If they are the same, the receiver knows that the encrypted symmetric key has not changed. The receiver continues the decryption process. If they are different, the receiver discards the SC and informs the sender.
415 The recipient encrypts the content by the same hash algorithm used in step 411 to calculate the content digest.
416 The receiver compares the calculated content digest with the content digest received through the SC. If they are the same, the receiver knows that the encrypted content has not changed. The receiver continues the decryption process. Even if they are different, the receiver discards the SC and notifies the sender.
417 The receiver uses the receiver's private key to encrypt the symmetric key. In this way, the symmetric key is recovered. PV RECPNT refers to the private key of the receiver.
418 The receiver uses the symmetric key to decrypt the encrypted content. This will restore the content.
III. Process of Secure Digital Content Electronic Distribution System The secure electronic digital content distribution system 100 is composed of several components used by different participants in the system. These participants include a content provider 101, an electronic digital content store 103, an end user using an end user device 109, and an authentication center 105. A high-level system flow is used to outline the secure digital content electronic distribution system 100. This process outlined below tracks content as it passes through the system 100. It also outlines the steps used by participants to implement transactions for purchases, openings, and use of content 113. Some assumptions made in the system flow include: This is a system flow for digital content services (point-to-point interface to a PC).
The content provider 101 submits audio digital content in PCM uncompressed format (as an example of music audio).
The content provider puts the metadata in an ODBC-compliant database, or the content provider 101 directly inputs the data into the content information processing subsystem, or has provided the data through the specified ASCII code file format.
Electronic digital content store for financial settlement.
Content 113 is hosted on a separate content hosting site 111.
Those skilled in the art should understand that these assumptions can be changed in order to adapt to the nature of broadcasting such as music, videos and programs, and electronic distribution systems.
The following processing flow is illustrated in FIG. 1.
Step 121: An uncompressed PCM audio file is provided by the content provider 101 as the content 113. The file name and the unique identifier of the content 113 of the content provider 101 are input into the workflow manager 154 tool.
122 The content information processing subsystem uses the unique identifier of the content 113 of the content provider 101 and the information provided by the database mapping template to capture metadata from the database 160 of the content provider.
123 The workflow manager tool 154 is used to guide the acquisition and preparation processing of content through the content provider 101. The tool can also be used to track the status of any piece of content within the system at any time.
124 The usage conditions of the content 113 are input to the content information processing subsystem, and this operation can be implemented manually or automatically. This data contains copy restriction rules and any other business rules deemed necessary. All metadata input can be implemented in parallel with the audio processing of the data.
125 The watermarking tool is used to hide data in the content 113 that the content provider 101 deems necessary to identify the content. It may include the time of capturing the content specified by the content provider 101, the source of the content (the content provider 101), or any other information.
The content processing tool 125 performs the equalization, dynamic adjustment and resampling processing necessary for the content 113 to support different compression levels.
Use the content processing tool 125 to compress the content 113 to the desired compression level. The content 113 can then be played to verify that the compression produced the required content 113 quality level. If necessary, you can perform equalization, dynamic adjustment, compression and replay quality checks as many times as you like.
The SC wrapper uses a symmetric key to encrypt a subset of the content 113 and its metadata. Then the tool uses the public key of the certification center to encrypt the key to generate an encrypted symmetric key. Since the only entity that can decrypt it is the certification center 105, the key can be sent to any place that does not consider the security of the content 113.
126 The encrypted symmetric key, metadata and other information about the content 113 are encapsulated by the SC encapsulator tool 152 into a metadata SC.
127 The encrypted content 113 and metadata are then packaged into one content SC. This completes the processing of the content 113 and metadata.
128 The metadata SC is then sent to the content promotion website 156 using a content payment tool (not shown).
129 The content payment tool sends the content SC to the content hosting site 111. The content hosting site may reside on the content provider 101, the certification center 105 or a special location dedicated to content hosting. The URL for the site is part of the metadata added to the metadata SC.
130 The content promotion website 156 notifies the electronic digital content store (USA) 103 of the new content 113 added to the system 100.
131 Using the content acquisition tool, the electronic digital content store 103 then downloads the metadata SC corresponding to the content 113 they wish to sell.
132 The Electronic Digital Content Store (US) 103 will use the content acquisition tool to extract any data they wish to use to promote the content 113 on its Web site from the metadata SC. Access to this metadata fragment is secure, and you can charge for it if necessary.
133 Use content acquisition tool input specific to this electronic digital content store
103 of the content 113 usage conditions. These usage conditions include retail prices and copy/play restrictions for different compression levels of the content 113.
134 The specific usage conditions and initial metadata SC of the electronic digital content store (USA) 103 are packaged into a quote SC by the SC packager tool.
135 After the electronic digital content store 103 Web site is updated, the content 113 can be used by end users who access the Web.
136 When an end user finds the content 113 they want to buy, they click on a content icon such as a music icon, and the item is added to his/her shopping cart maintained by the electronic digital content store 103.
When the end user finishes shopping, they submit a purchase application to the electronic digital content store 103 for processing.
137 The electronic digital content store 103 then interacts with the credit card settlement organization to withdraw deposits in the same way they usually do business.
138 Once the electronic digital content store 103 receives the credit card authorization number from the credit card settlement organization, it stores this number in a database and uses the SC wrapper tool to establish a transaction SC. This transaction SC contains all the offers SC of the content 113 that the end user has purchased, a transaction ID that can be sent back to the electronic digital content store 103, and identifies the end user who purchased the song, compression level, usage conditions, and price list information.
139 This transaction SC is then sent to the end user device 109.
140 When the transaction SC arrives at the end user device 109, it initiates the end user player application 195 that opens the transaction SC and confirms the end user's purchase. The end user player application 195 then opens the single offer SC and, in an alternative embodiment, can notify the user of a download time estimate. The user is then requested to specify when the content 113 is to be downloaded.
141 According to the download time requested by the end user, the end user player application 195 wakes up and initiates the download process by establishing an encrypted symmetric key containing the content 113, the transaction ID and the end user information in particular, the subscription SC.
142 This order SC is then sent to the certification center 105 for processing.
143 The certification authority 105 receives the order SC, opens it and verifies that no data has been tampered with. The certification center 105 verifies the usage conditions purchased by the end user. These usage conditions must meet the usage conditions stipulated by the content provider 101.
This information is recorded in a database.
144 Once all the checks are completed, the private key of the certification center 105 is used to decrypt the encrypted symmetric key. Then use the end user's public key to encrypt the symmetric key. Then the SC encapsulator encapsulates the new encrypted symmetric key into a license SC.
145 The license SC is then sent to the end user device.
146 When the license SC is received on the end user device 109, it is stored in the memory until the content SC is downloaded.
147 The end user device 109 requests the content hosting facility 111 to send the corresponding license SC of the purchased content 113.
148 The content 113 is sent to the end user device 109. When received, the end user device 109 uses the symmetric key to decrypt the content 113.
IV. Copyright Management System Structure Model A. System Structure Hierarchical Function FIG. 5 is a block diagram illustrating the copyright management system structure of the secure digital content electronic distribution system 100. In the architecture, the secure digital content electronic distribution system 100 is represented by four levels: a license control layer 501, a content recognition layer 503, a content usage control layer 505, and a content formatting layer 507. In this chapter, the overall functional objectives of each level and the individual key functions of each level are described. The functions in each level are obviously independent of the functions in other levels. To a large extent, functions of one level can be replaced by similar functions without affecting the functions of other levels. Obviously, the output of one layer is required to meet the acceptable format and semantic requirements of the adjacent layer.
The license control layer 501 guarantees: Prevent digital content from being illegally intercepted and tampered during distribution; Content 113 originates from a legal content owner and is distributed by a licensed distributor, such as the electronic digital content store 103; Digital content purchase The person has a normally licensed application; the purchaser pays the distributor before a copy of the content 113 can be used by the purchaser or end user; and keeps a transaction record for reporting.
The content recognition layer 503 allows verification of the copyright and consistency of the digital content. The copyright information of the content and the identity of the content purchaser allow the source tracking of any authorized or unauthorized copy of the content 113. Therefore, the content recognition layer 503 provides a means to resist piracy.
The content usage control layer 505 ensures that the copy of the content 113 is used for the purchaser's device according to the usage conditions 519 of the store. The store usage condition 519 can specify the allowed playback of the content 113 and the number of local copies, and specify whether the content 113 can be recorded on an external portable device. The functions in the content usage control layer 505 track the copy/play usage of the content and update the copy/play status.
The content formatting layer 507 allows the content 113 to be formatted from its own representation in the content owner's facility into a form that meets the requirements of the service function and the distribution means of the secure digital content electronic distribution system 100. The conversion process can include compression coding and related pre-processing, such as frequency equalization and amplitude dynamic adjustment. Regarding the content 113 as audio, the purchaser also needs to process the received content 113 to realize a format suitable for playback or transmission to a portable device.
B. Function segmentation and flow chart 5 shows the copyright management architecture model, which illustrates the mapping from the architecture level to the operating components that constitute the secure digital content electronic distribution system 100 and the key functions in each level.
1. The general functions of the content formatting layer 507 and the content formatting layer 507 are the content preprocessing 502 and compression 511 on the content provider 101, and the content descrambling code 513 and decompression 515 on the end user device 109. The requirements for preprocessing and examples of specific functions are as described above. The content compression 511 is used to reduce the file size of the content 113 and its transmission time. Any compression algorithm suitable for the type and transmission medium of the content 113 can be used in the secure digital content electronic distribution system 100. For music, MPEG 1/2/4, Dolby AC-2 and -3, Sony Adaptive Transform Coding (ATRAC), and low-bit rate algorithms are some of the commonly used compression algorithms. The content 113 is stored in the end user device 109 in a compressed form to reduce storage capacity requirements. Decompress it during event replay. De-scrambling is also performed during the replay of the event. The purpose and type of scrambling codes will be described later during the discussion of the content usage control layer 505.
2. Content usage control layer 505 The content usage control layer 505 allows the use of specifications and conditions or restrictions established for the use of the content 113 on the end user device 109. The conditions can specify the allowable number of content 113 to be played, whether to allow second-generation copying of the content 113, the number of second-generation copies, and whether the content 113 can be copied to an external portable device. The content provider 101 sets the permission condition 517 and sends it to the electronic digital content store 103 through an SC (see the section of the license control layer 501). As long as the initial conditions set by the content provider 101 are not invalidated, the electronic digital content store 103 can increase or decrease the usage conditions 517. The electronic digital content store 103 then sends all the store usage conditions 519 (via an SC) to the end user device 109 and the authentication center 105. The authentication center 105 performs the use condition verification 521 before authorizing the publishing of the content 113 to an end user device 109.
The content usage control layer 505 executes the content usage conditions 517 in the end user device 109. First, when a copy of the content 113 is received from the content recognition layer 503 in the end user device 109, the content 113 is marked with a copy/play code 523 indicating the initial copy/play permission. Second, the player application 195 encrypts and scrambles the content 113 before storing the content 113 on the end user device 109. The player application 195 generates a scrambling key for each content item, and the key is encrypted and hidden in the end user device 109. Then, whenever the end-user device 109 accesses the content 113 for copying or playing, the end-user device 109 verifies the copy/play code before allowing the descrambling of the content 113 and performing playback or copying. The end-user device 109 also appropriately updates the copy/play code in the original copy of the content 113 and any new secondary copies. Copy/play encoding is performed on the content 113 that has been compressed. That is, it is not necessary to decompress the content 113 before embedding the copy/play code.
The end user device 109 uses a license watermark 527 to embed the copy/play code into the content 113. Only the end user player application 195 that knows the embedding algorithm and the related scrambling key can read or modify the embedded data. The data cannot be seen or heard by humans; that is, the data does not cause perceptual degradation in the content 113. Since watermarks always exist in several steps including content processing, data compression, D/A and A/D conversion, and signal degradation introduced by normal content processing, watermarks and content 113 exist together in any representation form, including analog representations. . In an alternative embodiment, the end user player application 195 uses securely storing the usage conditions 519 instead of using the license watermark 527 to embed the copy/play code into the content 113.
3. The content recognition layer 503 is part of the content recognition layer 503. The content provider 101 also uses a license watermark 527 to embed data such as content identifier, content owner and other information into the content 113, where other information can be Date of publication and geographical distribution area. This watermark is referred to herein as a copyright watermark 529. Upon receipt, the end user device 109 uses the content purchaser name, transaction ID 535 (see the license control layer 501 section below), and other information such as the license date and usage conditions 517 to watermark the copy of the content 113. This watermark is referred to herein as a license watermark 529. Any copy of the content 113 that is obtained in an authorized or non-authorized manner and that has undergone audio processing to maintain content quality carries copyright and license watermarks. The content recognition layer 503 prevents piracy.
4. The license control layer 501 The license control layer 501 prevents unauthorized interception of the content 113 and ensures that the content is only published one by one to an end-user device 109 with appropriate licenses and communicates with an authorized electronic digital content store. 103 End users who successfully complete the license purchase transaction. The license control layer 501 protects the content 113 by double encryption 531. The content 113 is encrypted using an encrypted symmetric key generated by the content provider 101, and the symmetric key is encrypted using the public key 621 of the certification center. Only the certification authority 105 can recover the symmetric key.
The license control is designed as a "trustee" together with the certification center 105. Before issuing a license request 537, (that is, issuing the symmetric key of the content 113 to an end user device 109), the certification authority 105 verifies that the transaction 541 and the license authorization 543 are complete and authentic, and the electronic digital content store 103 has the authorization to sell electronic content 113 from the secure digital content electronic distribution system 100, and the end user has an appropriately licensed application. The audit/report 545 allows reports to be generated and to share license transaction information with other authorized parties in the secure electronic digital content distribution system 100.
Permission control is achieved through SC processing 533. The SC is used to distribute encrypted content 113 and information between the operating components of the system (more on the detailed structure of the SC below). SC is an information encryption carrier that uses password encryption, digital signature and digital certificate to prevent unauthorized interception or modification of electronic information or content 113. It also allows verification of the authenticity of electronic data.
License control requires that the content provider 101, the electronic digital content store 103, and the certification center 105 have a certificate authority from the specification, which is used to authenticate the real cryptographic digital certificates of those components. The end user device 109 is not required to have a digital certificate.
C. Content distribution and license control FIG. 6 is a diagram illustrating the license control layer applicable to FIG. 5 and the overall conceptual block diagram of content distribution and license control. This figure depicts the electronic digital content store 103, the end-user device 109 and the authentication center 105 are interconnected via the Internet and a single-channel (point-to-point) transmission is used between these components. It is also possible to communicate between the content provider 101 and the electronic digital content store 103 through the Internet or other networks. It is assumed that the content purchase commercial transaction between the end user device 109 and the electronic digital content store 103 is based on a standard Internet protocol. As part of the web-based interaction, the end user selects the content 113 to be purchased, provides personal and financial information, and agrees to the purchase conditions. The electronic digital content store 103 can obtain payment authorization from a transferee institution using a protocol such as SET.
It is also assumed in FIG. 6 that the electronic digital content store 103 has downloaded the end user player application 195 to the end user device 109 according to the standard Web protocol. This architecture requires the electronic digital content store 103 to assign a unique application ID to the downloaded player application 195 and the end user device 109 to store it for later application license verification (see below).
The entire licensing process starts with the content provider 101. The content provider 101 uses a generated symmetric key to encrypt the content 113, and uses the public key 621 of the certification center 105 to encrypt the symmetric key 623. In an alternative embodiment, the non-locally generated symmetric key may be sent from the certification center 105 to the content provider 101. The content provider 101 generates a content SC around the encrypted content 113, and generates a metadata SC 620 around the encrypted symmetric key 623, store usage conditions 519 and other content 113 and information. Each content 113 object has a metadata SC 620 and a content SC 630. The content 113 object can be the compression level of the same song, each song on an album, or the entire album. For each content 113 object, the metadata SC 620 also carries store usage conditions 519 related to the content usage control layer 505.
The content provider 101 distributes the metadata SC 620 to one or more electronic digital content stores 103 (step 601) and distributes the content SC 630 to one or more content hosting sites (step 602). Each electronic digital content store 103 generates an offer SC 641 in turn. The offer SC 641 usually carries most of the same information as the metadata SC 620, including the content provider's digital signature 624 and certificate (not shown for the content provider 101). As described above, the electronic digital content store 103 can increase or decrease the store usage conditions 519 initially defined by the content provider 101 (processed by the control usage layer). Optionally, a digital signature 624 of the content provider 101 is used to sign the content SC 630 and/or the metadata SC 620.
After completing the content purchase transaction between the end user equipment 109 and the electronic digital content store 103 (step 603), the electronic digital content store 103 generates a transaction SC 640 and transmits it to the end user equipment 109. The transaction SC 640 includes a unique transaction ID 535, the name of the purchaser (namely the name of the end user) (not shown), the public key 661 of the end user device 109, and the offer SC 641 related to the purchased content 113. The transaction data 642 in FIG. 6 represents the transaction ID 535 and the end user name (not shown). The transaction data 642 is encrypted using the public key 621 of the authentication center 105. Optionally, the transaction SC 640 is signed using the digital signature 643 of the electronic digital content store 103.
Upon receiving the transaction SC 640 (and the offer SC 641 contained therein), the end user player application 195 running on the end user device 109 requests a license authorization from the certification center 105 through a subscription SC 650 (step 605). The order SC 650 contains the encrypted symmetric key 623 and the store usage conditions 519 from the offer SC641, the encrypted transaction data 642 from the transaction SC 640, and the encrypted application ID 551 from the end user device 109. In another embodiment, after completing the content purchase transaction between the end user device 109 and the electronic digital content store 103 (step 603), the electronic digital content store 103 generates a transaction SC 640 and transmits it to the end user device 109 (step 604). The transaction SC 640 includes a unique transaction ID 535, the name of the purchaser (namely the name of the end user) (not shown), the public key 661 of the end user device 109, and the offer SC 641 related to the purchased content 113. The transaction data 642 in FIG. 6 represents the transaction ID 535 and the end user name (not shown). The transaction data 642 is encrypted using the public key 621 of the authentication center 105. Optionally, the transaction SC 640 is signed using the digital signature 643 of the electronic digital content store 103.
Upon receiving the transaction SC 640 (and the offer SC 641 contained therein), the end user player application 195 running on the end user device 109 requests a license authorization from the certification center 105 through a subscription SC 650 (step 605). The order SC 650 contains the encrypted symmetric key 623 and the store usage conditions 519 from the offer SC641, the encrypted transaction data 642 from the transaction SC 640, and the encrypted application ID 551 from the end user device 109. In another embodiment, a digital signature 652 of the end user device 109 is used to sign the subscription SC 650.
When receiving the order SC 650 from the end user device 109, the certification center 105 verifies: 1. The electronic digital content store 103 is authorized from the secure digital content electronic distribution system 100 (existing in the database 160 of the certification center 105); 2. Order SC 650 has not been changed; 3. The transaction data 642 and the symmetric key 623 are complete and credible; 4. The e-shop use conditions 519 purchased by the end-user device 109 are consistent with the use conditions 517 set by the content provider 101; and 5. The application ID 551 has a valid structure and the application ID is provided by an authorized electronic digital content store 103.
If the verification is successful, the certification center 105 decrypts the symmetric key 623 and the transaction data 642, establishes and transfers the license SC 660 to the end user device 109 (step 606). The license SC660 carries the symmetric key 623 and the transaction data 642, and the public key 661 of the end user device 109 is used to encrypt both. If the verification is unsuccessful, the authentication center 105 refuses to license the end-user device 109 and notifies the end-user device 109. The certification center 105 also immediately notifies the electronic digital content store 103 of the verification failure. In an alternative embodiment, the certification authority 105 signs the license SC 660 with its digital signature 663.
After receiving the license SC 660, the end user device 109 decrypts the symmetric key 623 and the transaction data 642 previously received from the certification center 105 and requests the content SC 630 from a content hosting site 111 (step 607). When the content SC 630 arrives (step 608), the end-user device 109 uses the symmetric key 623 to decrypt the content 113 (step 609), and transfers the content 113 and transaction data 642 to other layers in order to proceed as previously described for FIG. 5 License watermarking, copy/play encoding, scrambling and further content 113 processing.
Finally, the certification center 105 periodically sends summary transaction reports to the content provider 101 and the electronic digital content store 103 for auditing and tracking (step 610).
V. Secure container structure A. General structure A secure container (SC) is a structure composed of several fragments, which together define a content 113 unit or part of a transaction, and also define conditions such as usage conditions, metadata and encryption methods Relevant information. Design the SC in a way that can verify the integrity, completeness and authenticity of the information. Certain information in the SC can be encrypted so that it can only be accessed after proper authorization has been obtained.
The SC contains at least one bill of materials (BOM) segment, which has information records about the SC and each segment contained in the SC. For each segment, a hash algorithm such as MD-5 is used to calculate a message digest and include it in the BOM record of the segment. The digests of the segments are concatenated together, another digest is calculated from them and encrypted with the private key of the entity that generated the SC to generate a digital signature. The party receiving the SC can use the digital signature to verify all digests and verify the integrity and completeness of the SC and all its fragments.
The following information can be included in the BOM as a record along with the record of each segment. The type of SC determines the records that need to be included: SC version
SC ID SC type (for example, quotation, order, transaction, content, metadata or promotion and license) SC publisher SCs date SCs expiration date certification center URL for inclusion Description of the digest algorithm (default MD-5) of the fragments Description of the algorithm used for digital signature encryption (default RSA) Digital signatures (encrypted digests of all concatenated digests of the included fragments) SC can contain more than A BOM. For example, an offer SC 641 is composed of an initial metadata SC 620 segment containing its BOM, additional information added by the electronic digital content store 103, and a new BOM. A record for the metadata SC 620 BOM is included in the offer SC 641 BOM. This record contains a digest for the metadata SC620 that can be used to verify its integrity. Therefore, the segment digest value stored in the metadata SC620 BOM can also be used to verify the integrity of the segments contained in the metadata SC620. No segment in the metadata SC 620 is recorded in the new BOM generated for the offer SC 641. Only the segments added by the electronic digital content store 103 and the metadata SC 620 BOM are recorded in the new BOM.
The SC can also contain a key description fragment. The key description segment contains a record containing the following information about the encrypted segment in the SC: The name of the encrypted segment.
The name used for a segment when it is decrypted.
The encryption algorithm used to encrypt the segment.
A key identifier indicating the public encryption key used to encrypt the segment or an encrypted symmetric key used to decrypt the encrypted segment during decryption.
The encryption algorithm used to encrypt the symmetric key. This field only appears when the record in the key description segment contains an encryption symmetric key that is used to encrypt the encrypted segment.
A key identifier of the public encryption key used to encrypt the symmetric key. This field only appears when the record in the key description segment contains an encryption symmetric key and the encryption algorithm identifier of the symmetric key used to encrypt the encrypted segment. If the SC does not contain any encrypted fragments, there is no key description fragment.
B. The syntax and semantics of copyright management language The copyright management language is composed of parameters, and values can be assigned to the parameters to define restrictions on the use of the content 113 by an end user after purchasing the content 113. The restriction on the use of the content 113 is the use condition 517. Each content provider 101 specifies usage conditions 517 of its respective content 113 items. The electronic digital content store 103 interprets the usage conditions 517 in the metadata SC 620 and uses this information to provide the options they wish to provide to their customers and to increase the retail purchase information of the content 113. After an end user selects a content 113 purchase item, the end user device 109 requests authorization of the content 113 according to the store use condition 519. Before the certification authority 105 sends a license SC 660 to the end user, the certification authority 105 verifies that the requested store use condition 519 is consistent with the permitted use condition 517 specified by the content provider 101 through the metadata SC 620.
When the end user device 109 receives the purchased content 113, it uses a watermark tool to encode the store use condition 519 into the content 113, or encode the store use condition 519 into the secure storage use condition 519. The end user player application 195 running on the end user device 109 ensures that the store usage conditions 519 encoded into the content 113 are executed.
The following is an example of the store use condition 519 for an embodiment where the content 113 is music: The song is recordable.
Songs can be played n times.
C. Overview of the secure container flow and processing Metadata 620 is established by the content provider 101 and used to define content 113 items such as songs. Because the length of the content 113 is usually too large for the electronic digital content store 103 and the end user to effectively download containers that are only used to access descriptive metadata, the content 113 itself is not included in these SCs. Instead, the SC contains an external URL (Uniform Resource Location Code) that points to the content 113. In the case of the song content 113, the SC also contains metadata that provides descriptive information about the content 113 and any other associated data such as music, CD cover art, and/or digital audio selections.
The electronic digital content store 103 downloads the metadata SC 620, for which they are authorized and establish an offer SC 641. In short, an offer SC 641 is composed of certain fragments and BOM of metadata SC 620 and additional information contained in the electronic digital content store 103. When the quotation SC 641 is created, a new BOM for the quotation SC 641 is generated. The electronic digital content store 103 also uses the metadata SC 620 to create an HTML page on its Web site by extracting metadata information from the metadata SC 620, which provides end users with a description of the content 113 so that they can purchase the content 113 .
The information added to the offer SC 641 by the electronic digital content store 103 generally reduces the selection range of the usage conditions 517 specified in the metadata SC620 and promotion data such as the graphic image file of the store logo and the URL of the store website. A quotation SC 641 template in the metadata SC 620 indicates information that can be ignored by the electronic digital content store 103 in the quotation SC 641, what additional information the electronic digital content store 103 needs and which segments are retained in the embedded metadata SC 620.
When an end user decides to purchase content 113 from an electronic digital content store 103, the offer SC 641 is included in a transaction SC 640. The electronic digital content store 103 establishes a transaction SC 640 containing an offer SC641 for each content 113 item purchased and sends it to the end user device 109. The end user device 109 receives the transaction SC 640 and verifies the integrity of the transaction SC 640 and the included offer SC 641.
The end user device 109 establishes a subscription SC 650 for each content 113 item purchased. Contains information from the offer SC 641, transaction SC 640 and the configuration file of the end user device 109. The order SC 650 is sent to the certification center 105 one at a time. Ordering SC 650 in the URL of the certification authority 105 is included as a record in the BOM of the metadata SC 620, and is also included in the offer SC 641.
The certification center 105 verifies and processes the subscription SC 650 in order to provide the end user device 109 with all the information required for the license watermark 527 and access to the purchased content 113. One function of the certification center 105 is to decrypt the symmetric key 623, in which the watermark command from the offer SC 641 and the content 113 from the content SC 630 need to be decrypted using the symmetric key. An encrypted symmetric key 623 record actually contains more content than the actual encrypted symmetric key 623. Before encryption, the content provider 101 can append its name to the actual symmetric key 623. Encrypting the name of the content provider 101 together with the symmetric key 623 can prevent a pirated content provider 101 that has established its own metadata SC 620 and content SC 630 based on a legal SC. The certification authority 105 verifies whether the name of the content provider 101 encrypted with the symmetric key 623 matches the name of the content provider 101 in the SC certificate.
If there is no need for the certification center 105 to make any changes to the watermark command, the certification center 105 decrypts the symmetric key 623, modifies the watermark command and uses a new symmetric key 623 to encrypt it again. The public key 661 of the end user device 109 is then used to re-encrypt the symmetric key 623. The certification center 105 also decrypts the other symmetric keys 623 in the SC and encrypts them again with the public key 661 of the end user device 109. The certification authority 105 creates a license SC 660 containing the newly encrypted symmetric key 623 and the updated watermark instruction and sends it to the end user device 109 according to the subscription SC 650. If the process of subscribing to the SC 650 is not successfully completed, the authentication center 105 returns an HTML page to the end user device 109 or equivalent content reporting that the authorization process has failed.
The license SC 660 provides an end user device 109 with all the information needed to access a content 113 item. The end user device 109 requests the appropriate content SC 630 from the content hosting site 111. The content SC 630 is established by the content provider 101 and contains encrypted content 113 and metadata fragments. The end user player application 195 uses the symmetric key 623 from the license SC660 to decrypt the content 113, metadata and watermark instructions. Then the watermark instruction is attached to the content 113 and the content 113 is scrambled and stored on the end user device 109.
D. Metadata Security Container 620 Format The following list shows the fragments contained in one metadata SC 620. Each box in the segment column is an individual object and BOM contained in the SC (except for the segment name included by the [] character). The BOM contains a record for each segment contained in the SC. The appearance of the segment in the column indicates that the segment is actually contained in the SC and the summary column indicates whether an indication is calculated for the segment. When one SC is included in other SCs (determined by the relevant template), although the entire initial BOM is transmitted, some fragments cannot be transmitted. This is because the certification authority 105 needs the entire BOM to verify the digital signature in the initial SC.
The key description fragment column in the following list defines the records contained in the key description fragment of the SC. The record in the key description segment defines information about the encryption key and algorithm used to encrypt the segment in the SC and the segment in another SC. Each record contains the name of the encrypted segment and a URL pointing to another SC that contains the encrypted segment. The result name column defines the name assigned to the segment after being decrypted. The encryption algorithm column defines the encryption algorithm used to encrypt the segment. The key Id/encryption key field defines an identification of the encryption key used to encrypt the segment or a base64 encoding of the 623 bit string of the encrypted symmetric key used to encrypt the segment. The symmetric key algorithm column is an optional parameter that defines the encryption algorithm used to encrypt the symmetric key 623 when the current column is an encrypted symmetric key 623. The symmetric key algorithm ID column is an encryption key identifier used to encrypt the symmetric key 623 when the key Id/encryption key column is an encrypted symmetric key 623.
The following describes the terms used in the above-mentioned metadata SC list: [Content URL]-The key describes a parameter in one record of the fragment. This is a URL that points to the encrypted content 113 in the content SC 630 related to this metadata SC 620. The metadata SC 620 itself does not contain the encrypted content 113.
[Metadata URL]-a parameter in a record of the key description fragment. This is a URL that points to the encrypted metadata in the content SC 630 related to this metadata SC 620. The metadata SC 620 itself does not contain encrypted metadata.
Content ID-a segment that defines a unique ID assigned to a content 113 item. In the case where the metadata SC 620 points to more than one content 113 item, more than one content ID is included in this segment.
Metadata-For a song, a piece of information related to a content 113 item such as the name of the artist and the CD cover image. There may be multiple pieces of metadata, some of which can be encrypted. The internal structure of the metadata fragment depends on the type of metadata contained in it.
Conditions of Use-A segment containing information describing the usage options, rules, and restrictions imposed on the end user using the content 113.
SC template-a fragment that describes the required and optional information to establish a quote, order, and license the SC 660.
Watermark instruction-a segment containing encrypted instructions for implementing the watermark in the content 113. The watermark instruction in the license SC 660 can be modified by the certification center 105 and returned to the end user device 109. There is a definition in the key description fragment that is used to encrypt the watermark command. The output fragment name used when the watermark command is decrypted is a base64 encoding of the 623-bit string of the encrypted symmetric key used to encrypt the watermark command. A record of the encryption algorithm for encrypting the symmetric key 623 and the identification of the public key required to decrypt the symmetric key 623. Certificate Authority Certificate-a certificate from a certificate authority or certificate authority 105 that contains the signature public key 621 of the certificate authority 105. There may be more than one certificate. In this case, a hierarchical structure is used for the highest-level certificate, which contains the public key of the lowest-level certificate after opening, and the lowest-level certificate contains the public key 621 of the certification authority 105 .
Certificate-a certificate from the certification authority or certification authority 105 that contains the signature public key 621 of the entity that established the SC. There may be more than one certificate. In this case, a hierarchical structure is used for the highest-level certificate, which contains the public key to open the second-level certificate, and so on, until the lowest-level certificate arrives, and the lowest-level certificate contains SC establishment The public key of the person.
SC version-a version number assigned to the SC by the SC wrapper tool.
SC ID-a unique ID assigned to the SC by the entity that established the SC.
SC type-indicates the type of SC (such as metadata, quotation, order, etc.) SC publisher-indicates the entity that established the SC.
Establishment date-the date the SC was established.
Expiration date-the date when the SC expires and is no longer valid.
Certification Center URL-The address of the certification center 105 with which the end user player application 195 should interact to obtain the proper authorization to access the content 113.
Digest algorithm ID-an identifier of the algorithm used to calculate the digest of the segment.
Digital Signature Algorithm ID-an identifier of the algorithm used to encrypt the digest of the concatenated segment digest. This encrypted value is the digital signature.
Digital signature-a digest of the concatenated segment digest encrypted with the public key of the entity that established the SC.
Output fragment-the name assigned to the output fragment when an encrypted fragment is decrypted.
RSA and RC4-the default encryption algorithm used to encrypt the symmetric key 623 and data blocks.
Encrypted symmetric key-a base64 encoding of an encryption key bit string used to decrypt an SC segment when decrypting.
CH public key-an identifier indicating that the public key 621 of the certification authority 105 is used to encrypt data.
E. Quote Security Container 641 Format The following list shows the fragments contained in the quote SC 641. In addition to some metadata fragments, various fragments and BOM from the metadata SC 620 are also included in the offer SC641.
The following describes the terms used for the SC 641 quoted above and not previously described for another SC: Metadata SC BOM-BOM from the initial metadata SC 620. The record in the offer SC 641 BOM contains a summary of the metadata SC 620 BOM.
Additional and Ignored Fields-use condition information ignored by the electronic digital content store 103. The certification authority 105 verifies the information by relying on the received SC template to ensure that any information ignored by the electronic digital content store 103 is within its authorized scope.
Electronic digital content store certificate-a certificate that is provided by the certification center 105 for the electronic digital content store and signed by the certification center 105 with its private key. This certificate is used by the end user player application 195 to verify that the electronic digital content store 103 is a valid content 113 distributor. The end user player application 195 and the certification center 105 can verify that the electronic digital content store 103 is an authorized distributor by decrypting the signature of the certificate with the public key 621 of the certification center 105. The end user player application 195 retains a local copy of the public key of the certification authority 105 received as part of its initialization information during installation.
F. Transaction Security Container 640 Format The following list shows the fragments contained in the transaction SC 640 and their BOM and key description fragments.
The following describes the terms used in the aforementioned transaction SC 640 and not previously described for another SC: Transaction ID-an ID assigned by the electronic digital content store 103 to uniquely identify the transaction.
End user ID-an end user identification obtained by the electronic digital content store 103 when the end user makes a purchase choice and provides credit card information.
End user public key-the end user public key 661 used by the certification authority 105 to re-encrypt the symmetric key 623. The end user public key 661 is sent to the electronic digital content store 103 during the purchase transaction.
Quotation SC-Quotation SC 641 for 113 items of the purchased content.
Content usage selection-a list of usage conditions for each 113 item of content purchased by the end user. Every offer SC 641 has an entrance.
Displayed HTML-one or more HTML displayed in the Internet browser window by the end user player application 195 when the transaction SC 640 is received or during the interaction between the end user device 109 and the authentication center 105 page.
When the end user device 109 receives a transaction SC 640, the following steps can be performed to verify the integrity and authenticity of the SC: 1. Use the public key 621 of the certification center 105 to verify the integrity of the electronic digital content store 103 certificate. After being received as part of the initialization information of the end user player application 195 during its installation process, the public key 621 of the certification authority 105 is stored on the end user device 109.
2. The digital signature 643 of the SC is verified using the public key from the electronic digital content store 103 certificate.
3. Verify the hash of the SC segment.
4. Verify the integrity and authenticity of each offer SC 641 contained in the transaction SC 640.
G. Subscription Security Container 650 Format The following list shows the fragments contained in the subscription SC 650 and their BOM and key description fragments. These fragments either provide information for decryption and verification to the certification center 105, or are verified by the certification center 105. The fragment and BOM from the offer SC 641 are also included in the order SC650. Certain character strings in the existing segment column of the metadata SC BOM indicate certain segments that are not included in the subscription SC 650. The BOM from the metadata SC 620 is included without any change so that the certification authority 105 can verify the integrity of the metadata SC 620 and its various fragments.
The following describes the terms used for the aforementioned order SC 650 and not previously described for another SC: Transaction SC BOM-BOM in the initial transaction SC 640. The record in the order SC 650 BOM contains a summary of the transaction SC 640 BOM.
Encrypted credit card information-optional encrypted information from the user that is used to pay for purchases via a credit or debit card. This information is needed when the electronic digital content store that established the offer SC 641 does not process customer bills, and in this case the authentication center 105 can process the bills.
H. License Security Container 660 Format The following list shows the fragments contained in the license SC 660 and their BOM. As shown in the key description fragment, the certification center 105 has used the end user's public key 661 to re-encrypt the symmetric key 623, content 113, and content 113 metadata required to decrypt the watermark command. When the end user device 109 receives the license SC 660, the device decrypts the symmetric key 623 and uses the key to access the encrypted fragments from the license SC 660 and the content SC 630.
The following describes the terms used in the aforementioned license SC 660 and not previously described for another SC: EU public key-an identifier indicating that the end user public key 661 is used to encrypt data.
Order SC 650 ID-SC ID obtained from ordering SC 650 BOM.
List of revoked certificates-an optional list of certificate IDs that were previously issued and signed by the certification authority 105, but are no longer considered valid. Any SC with a signature that can be verified by a certificate but the certificate is included in the revocation list is an invalid SC. The end user player application 195 stores a copy of the revocation certificate list of the certification authority 105 on the end user device 109. Whenever a revocation list is received, if the new revocation list is updated, the end user player application 195 replaces its local copy. The revocation list contains a version number or time stamp (or both) to determine the latest list.
I. Content Security Container Format The following list shows the fragments contained in the content SC 630 and their BOM.
The following describes the terms used for the aforementioned content SC 630 and not previously described for another SC: Encrypted content-content 113 encrypted by a content provider 101 using a symmetric key 623.
Encrypted metadata-metadata related to content 113 encrypted by a metadata provider 101 with a symmetric key 623.
Since the key required to decrypt the encrypted segment is located in the license SC 660 established on the certification center 105, the content SC 630 does not include the key description segment.
VI. Secure container encapsulation and disassembly A. Overview SC encapsulator is a 32-bit Windows program that has an API (application programming interface). The API can be called by a multi-step or single-step process to generate a file with all specified fragments. SC. The dialog control wrappers 151, 152, and 153 have various hardware platforms that support Windows programs on the content provider 101, the certification center 105, the electronic digital content store 103, and other sites that require SC wrappers. Generate a BOM and, if necessary, generate a key description fragment, and include them in the SC. A set of wrapper APIs allows the caller to specify the information required to generate the record and key description fragments in the BOM and include each fragment in the SC. The encapsulator also encrypts each segment and the symmetric key 623 and calculates the digest and digital signature. The wrapper code contains the encryption and digest algorithms supported by the wrapper, and they can also be called through an external interface.
The interface with the wrapper is implemented through an API that accepts the input of the following parameters to establish an SC: A pointer to a serial structure buffer. Each structure in the buffer is a command for the wrapper and contains the information needed to execute the command. The wrapper commands include adding a segment to the SC with a related BOM record, adding a record to the BOM, and adding a record to the key description segment.
A value indicating the number of serial structures contained in the above buffer.
The name and location of the BOM fragment.
Each bit is a value that defines a flag or a flag reserved for future use. The following flags are currently defined: an indication of whether all fragments of the SC should be assembled into a single file after all the structures in the buffer have been processed. Bundling each segment into a single object is the final step performed when creating an SC.
Instructions on whether to omit the digital signature from the BOM fragment. If this flag is not set, the digital signature is calculated before the SC is stuffed into a separate object.
In an alternative embodiment, the interface with the wrapper is implemented through the API that accepts the following parameter input to establish an SC: First, an API is called by passing in a pointer to a structure to generate a bill of materials (BOM) fragment The above structure is composed of information used to initialize the SC settings. The above information is expressed as an IP record in the SC BOM segment, used for the name of the BOM segment, a search for the default position of each segment to be added, and a tag value. This API returns an SC handle that is used in subsequent wrapper APIs.
The wrapper has an API that is used every time a fragment is added to an SC. This API accepts an SC handle previously returned by the previous wrapper API, a pointer to a structure composed of information related to the added fragment, and a tag value. The information about the added segment includes the name and location of the segment, the name used for the segment in the BOM, the type of the added segment, a hash value of the segment, a tag, and so on.
After all the fragments have been added to the SC, call a wrapper API to encapsulate all the fragments containing the BOM fragment into a single dialogue control object, usually a file. This API accepts an SC handle previously returned by the previous wrapper API, the name of the SC used for the wrapper, a pointer to a structure with information used to sign the SC, and a tag value.
The wrapper or the entity that calls the wrapper can use an SC template to create an SC. The SC template has information defining various segments and records required in the SC being built. The template can also define the encryption method and key index used to encrypt the symmetric key 623 and the encrypted segment.
The wrapper has an API that is used to disassemble the SC. Disassembling an SC is a process of selecting an SC and dividing it into its separate fragments. The wrapper can then be invoked to decrypt any encrypted fragments that are disassembled from the SC.
B. Bill of Materials (BOM) Fragment When an SC is being created, the wrapper generates a BOM fragment. BOM is a text file that contains information records about each segment contained in SC and SC. Each record in the BOM is located on a single line that has a newline indicating the start of a new record. The BOM usually contains a summary of each segment and a digital signature that can be used to verify the authenticity and integrity of the SC.
The record types in the BOM are as follows: IP is an IP record containing a set of name=value pairs related to the SC. The following names are reserved for specific attributes of the SC: V major.minor.fix The V attribute specifies the version of the SC. This is the version number of the SC specification on which the SC is generated. The subsequent string should have the form of major.minor.fix, where major, minor, and fix are the major release number, minor release number, and installation level, respectively.
ID value The ID attribute is a unique value assigned to this particular SC by the entity that is creating this SC. The format of this value is defined in subsequent versions of this article. T value The T attribute specifies the type of SC, and the T value should be one of the following types: ORD-an order SC 650.
OFF-One offer SC 641.
LIC-a license SC.
TRA-a transaction SC 640.
MET-a metadata SC 620.
CON-a content SC 630.
The A value A attribute identifies the author or publisher of the SC. The author/publisher identity should be clear and/or registered on the certification center 105.
The D value D attribute identifies the date and time when the SC was established, where the time is optional. The value should have the form yyyy/mm/dd[@hh:mm[:ss[.fsec]][(TZ)]], which represents the year/month/day@Hour:Minute:Second. Tens of seconds (time zone ). The optional part of the value is enclosed with [] characters.
The E value The E attribute identifies the date and time when the SC expires, where the time is optional. The value should have the same form as the previously defined D attribute. Whenever possible, the deadline date/time should be compared with the date/time on the certification center 105.
The CCURL value CCURL attribute identifies the URL of the certification authority 105. The value should have the form of a valid external URL.
The H value H attribute identifies the algorithm used to calculate the message digest of the fragments contained in the SC. An example of a digest algorithm is MD5.
D A D record contains information identifying the type of the segment, the name of the segment, (optional) a summary of the segment, and an (optional) data or segment entry record indicating that the segment is not included in the SC. A symbol immediately after the type identifier is used to indicate that the segment is not included in the SC. The following are reserved data types or segment records: K segment_name [summary] specifies the key description segment.
W segment_name[summary] specifies the watermark instruction segment.
C segment_name[digest] specifies the certificate used to verify the digital signature.
T segment_name[summary] specifies the use condition segment.
YF segment_name [summary]
Specify the template fragment for SC 641 quotation.
YO Fragment_Name [Summary] specifies the template fragment to order SC 650.
YL fragment_name[summary] specifies the template fragment of the license SC 660.
ID fragment_name[summary] specifies the content 113 ID of the item of the referenced content 113.
CH fragment_name[summary] specifies the certificate fragment of the certificate authority 105.
SP fragment_name[summary] specifies the electronic digital content store 103 certificate fragment.
B segment_name[summary] specifies a ROM segment of another SC, and each segment or a subset of segments of the other SC is included in the current SC.
BP segment_name SC_segment_name[summary] specifies a BOM segment of another SC, which is contained in this SC as a single segment. The SC_fragment_name parameter is the name of the SC fragment contained in this SC and defined by the BOM fragment here. An identical BOM is also included in the SC specified by the SC_segment_name parameter.
D segment_name[summary] specifies a data (or metadata) segment.
S an S record is a signature record that is used to define the digital signature of the SC. The digital signature is as follows: S key identifier signature string signature algorithm S record contains the key identifier indicating the encryption key of the signature, is the base64-encoded signature string of the digital signature bit string, and is used to encrypt the digest To generate a digital signature signature algorithm.
C. The key description fragment encapsulator generates a key description fragment to provide information about the encryption key, and the key is required to decrypt the SC encrypted fragment. The encrypted segment can be included in the SC being established, or in other SCs referenced by the SC being established. The key description segment is a text file that contains information records about the encryption key and each segment, in which the aforementioned segments are encrypted using the encryption key. Each record in the key description fragment is located on a separate line, with a newline indicating the beginning of a new record.
The following record types are used inside a key description segment and are defined as follows: K encryption_segment_name; result_segment_name; segment_encryption_algorithm_identifier; public_key_identifier; key_encryption _Algorithm and encryption_symmetric_key.
A K record specifies an encrypted segment that can be contained in this SC or another SC referenced by this record. Encrypted_fragment_name is the name of a fragment in this SC or a URL pointing to the name of an encrypted fragment in another SC. The result_fragment_name is the name assigned to the decrypted fragment. Segment_Encryption Algorithm_Identifier indicates the encryption algorithm used to encrypt the segment. The public_key_identifier is a key identifier used to encrypt the symmetric key 623.
The key_encryption_algorithm_identifier indicates the encryption algorithm used to encrypt the symmetric key 623. The encrypted symmetric key is a base64 encoding of the 623 bit string of the encrypted symmetric key used to encrypt the segment.
VII. Certificate Authority 105A. Overview The certificate authority 105 is responsible for the copyright management function of the secure digital content electronic distribution system 100. The functions of the certification center 105 include starting the electronic digital content store 103, verifying the rights to the content 113, verifying the integrity and authenticity of the purchase transaction and related information, distributing the content encryption key or symmetric key 623 to the end user device 109, and tracking Those keys are distributed and the transaction profile is reported to the electronic digital content store 103 and the content provider 101. The content encryption key is used by the end user device 109 to open the content 113, where the end user usually obtains the right to open the content 113 from an authorized electronic digital content store 103 through a purchase transaction. Before a content encryption key is sent to an end user device 109, the authentication center 105 verifies the authenticity of the entity selling the content 113 and the end user device 109's rights to the content 113 through a verification process. This function is called SC Analysis Tool 185. In some configurations, the authentication center 105 can also handle the financial settlement of the purchase of the content 113 by jointly using the authentication center 105 to perform the credit card authorization and accounting functions of the electronic digital content store 103. The authentication center 105 uses OEM toolkits such as ICVerify and Taxware to process credit card business and local sales tax.
An embodiment of an electronic digital content store An electronic digital content store 103 wishing to participate in the secure digital content electronic distribution system 100 as a seller of content 113 provides one or more digital content providers 101 that provide content 113 to the secure digital content electronic distribution system 100 Make a request. There are no restrictions on making requests, as long as the parties reach an agreement. After a digital content label such as a music label, such as Sony, Time-Warner, etc., decides to allow the electronic digital content store 103 to sell its content 113, the authentication center 105 is usually contacted by e-mail to request the electronic digital content store 103 to be added to Secure digital content electronic distribution system 100. The digital content label provides the name of the electronic digital content store 103 and any other information that the certification authority 105 may need to generate a digital certificate for the electronic digital content store 103. The digital certificate is sent to the digital content tag in a secure manner, and then transmitted to the electronic digital content store 103 by the digital content tag. The certification authority 105 maintains a database that stores the digital certificates it distributes. Each certificate contains a version number, a unique serial number, signature algorithm, issuer name (for example, the name of the certification authority 105), the date range for which the certificate is considered valid, the electronic digital content store of the electronic digital content store 103, the electronic digital content store The public key of 103, and a hash code that uses the private key of the certification center 105 to sign all other information. An entity with the public key 621 of the certification center 105 can verify the certificate and be sure that an SC with a signature that can be verified using the public key on the certificate is a valid SC.
After the electronic digital content store 103 receives the digital certificate generated by the certification center 105 for it and the necessary tools to process the SC from the digital content tag, it can start to provide content 113 that can be purchased by the end user. The electronic digital content store 103 contains its certificate and transaction SC 640 and signs the SC using its digital signature 643. By first checking the digital certificate revocation list and then using the public key 621 of the certification authority 105 to verify the information in the digital certificate of the electronic digital content store 103, the end-user device 109 verifies that the electronic digital content store 103 is on the secure digital content electronic distribution system 100 One of the effective content 113 distributors. The certification authority 105 maintains a digital certificate revocation list. The revocation list may be included as a fragment of the license SC 660 generated by the certification authority 105. The end user device 109 keeps a copy of the revocation list on the end user device 109 so that it can be used as part of the digital certificate verification of the electronic digital content store 103. Whenever the end user device 109 receives a license SC 660, the device determines whether it contains a new revocation list, and updates the local revocation list on the end user device 109 if it does.
B. Copyright Management Processing Order SC Analysis After the end user receives the transaction SC 640 containing the offer SC 641 from the electronic digital content store 103, the authentication center 105 receives an order SC 650 from an end user. The subscription SC 650 is composed of individual segments containing information related to the content 113 and its use, information about the electronic digital content store 103 that is selling the content 113, and information about the end user who is purchasing the content 113. In any case, before the certification center 105 starts to process the information in the order SC 650, some processing is first performed to ensure that the SC is in fact valid and the data it contains has not been corrupted.
The verification certification center 105 starts to verify the order SC 650 by verifying the digital signature, and then the certification center 105 verifies the integrity of the ordered SC 650 fragment. In order to verify the digital signature, the certification center 105 first uses the public key 661 of the included signing entity to decrypt the content with its own signature. (The signing entity can be the content provider 101, the electronic digital content store 103, the end user device 109, or any combination thereof.) Next, the certification center 105 calculates the summary of the SC serial segment digest and compares it with the digitally signed decrypted content 113 Compare. If the two values match, the digital signature is valid. In order to verify the integrity of each segment, the certification authority 105 calculates the digest of the segment and compares it with the digest value in the BOM. Regarding the metadata contained in the order SC 650 and the quotation SC 641 fragment, the certification authority 105 follows the same process to verify the digital signature and the integrity of the fragment.
The verification process of the transaction and quotation SC 641 digital signature also indirectly verifies that the electronic digital content store 103 is authorized by the secure digital content electronic distribution system 100. The basis for this conclusion is that the certification authority 105 is the issuer of the certificate. Optionally, the certification center 105 can successfully use the public key from the electronic digital content store 103 to verify the digital signature of the transaction SC 640 and the offer SC 641, but only the entity signing the SC has the ownership of the relevant private key. Only the electronic digital content store 103 has the ownership of the private key. Note that the certification authority 105 does not need a local database about the electronic digital content store 103. The store then uses the public key of the certification center to sign the transaction SC 640 offer SC 641 public key.
Next, the authentication center 105 verifies the store usage conditions 519 of the content 113 that the end user is purchasing to ensure that the above conditions are within the limits set by the metadata SC 620. Remember that the metadata SC 620 is included in the subscription SC 650.
Key Processing After successfully completing the authenticity and integrity check of the ordered SC 650, the verification of the electronic digital content store 103 and the verification of the store usage conditions 519, the certification center 105 completes the processing of the encrypted symmetric key 623 and the watermark command. The metadata SC 620 fragment subscribing to the SC 650 usually has several symmetric keys 623 located in the key description fragment, in which the public key 621 of the certification center 105 is used to encrypt the key description fragment. When the metadata SC 620 is generated, the content provider 101 completes the encryption of the symmetric key 623.
One symmetric key 623 is used to decrypt the watermark instructions and the other symmetric key is used to decrypt the content 113 and all encrypted metadata. Since the content 113 can represent a single song or the entire album on a CD, a different symmetric key 623 can be used for each song. The watermark instruction is included in the SC 620 segment of metadata of the order SC 650. The content 113 and encrypted metadata are placed in a content SC 630 on a content hosting site 111. The URL and the segment name of the encrypted content 113 and the metadata segment in the content SC 630 are included in the key description segment of the metadata SC 620 segment of the subscription SC 650. The certification center 105 uses its private key to decrypt the symmetric key 623 and then uses the public key 661 of the end user device 109 to encrypt each symmetric key. The public key 661 of the end user device 109 is retrieved from the subscription SC 650. The new encrypted symmetric key 623 is included in the key description fragment of the license SC 660 returned by the certification center 105 to the end user device 109.
During the processing of the symmetric key 623, the certification authority 105 may wish to modify the watermark instructions. If this happens, the symmetric key 623 is decrypted in the certification center 105. After that, the watermark command is modified and re-encrypted. The new watermark instruction is included as a fragment of the license SC 660 that is returned to the end user device 109.
If all the processing of ordering the SC 650 is successfully completed, the certification center 105 returns a license SC 660 to the end user device 109. The end user device 109 uses the license SC 660 information to download the content SC 630 and access the encrypted content 113 and metadata. The watermark command is also executed by the end user equipment 109.
If the certification authority 105 cannot successfully process the subscription SC 650, an HTML page is returned to the end user device 109 and displayed in an Internet browser window. The HTML page indicates the reason why the certification authority 105 cannot process the transaction.
In an alternative embodiment, if the user has purchased a copy of the content 113 before the release date set for the sale, the dialog control 660 is returned without the symmetric key 623. The license SC 660 is returned to the certification center 105 to receive the symmetric key 623 on or after the issue date. For example, the content provider 101 allows the user to download a new song before the release date, thereby allowing the customer to download the song before the date set by the content provider 101 and be ready to play the song. This allows the content 113 to be opened immediately on the release date without worrying about the bandwidth and download time on the release date.
C. Country-specific parameters. Optionally, the certification authority 105 uses the domain name of the end user device 109 and, wherever possible, the credit card billing address to determine the end user's country location. If there are any restrictions on the sale of content 113 in the country where the end user is located, the certification center 105 guarantees that the transaction being processed does not violate any such restrictions before sending the license SC 660 to the end user device 109. The electronic digital content store 103 also expects to participate in the distribution of the content 113 to various countries by performing the same inspection as the certification center 105. In the event that the electronic digital content store 103 ignores the country-specific rules set by the content provider 101, the certification authority 105 performs any checks that it can do.
D. Audit log and tracking The certification center 105 maintains an information audit log 150 for each operation performed during the content 113 purchase transaction and report request transaction. The information can be used for various purposes, such as auditing of the secure digital content electronic distribution system 100, generating reports, and data mining.
The certification center 105 also maintains the account balance of the accounting subsystem 182 of the electronic digital content store 103. The price structure of the electronic digital content store 103 is provided to the certification center 105 through the digital content trademark. This information may include information that needs to be applied to the electronic digital content store 103, similar to the current special price, bulk discount, and account loss amount information. The certification authority 105 uses the price information to track the balance of the electronic digital content store 103 and ensure that they do not exceed its loss limit set by the content provider 101.
The certification authority 105 usually records the following operations: the end user device 109 requests the license SC 660 the credit card authorization number when the certification authority 105 processes the bill delivers the license SC 660 to the end user device 109 requests a report from the end user The notification content SC 630 and the license SC 660 are received and verified. The certification authority 105 usually records the following information for a license SC 660: Date and time of the request Date and time of the purchase transaction Content ID of the purchased item The identity of the content provider 101 Store usage conditions 519 Watermark instruction modification Transaction ID added by the electronic digital content store 103 535 The identity of the electronic digital content store 103 The identifier of the end user device 109 End user credit card information (if authenticated The center 105 is processing and accounting) The authentication center 105 usually records the following information for an end users credit card verification: The date and time of the request The amount paid by the credit card The content ID of the purchased item The electronic digital content The transaction ID added by the store 103 535 The ID of the electronic digital content store 103 The ID of the end user The credit card information of the end user The authorization number received from the credit card reader The authentication center 105 is in a license SC When 660 is sent to an end user device 109, the following information is usually recorded: Date and time of the request Content ID of the item purchased Identity of the content provider 101 Conditions of use 517 Transactions joined by the electronic digital content store 103 ID 535 ID of the electronic digital content store 103 ID of the end user The following information is usually recorded when a report request is generated: Date and time of the request Date and time of the issue of the report Type of report requested Used Parameters to generate the report Identifier of the entity requesting the report E. Result report The certification center 105 uses the information recorded by the certification center 105 during the end-user purchase transaction to generate the report. The content provider 101 and the electronic digital content store 103 can request a transaction report from the certification center 105 through a payment verification interface 183, so they can keep their own transaction database consistent with the information recorded by the certification center 105. The certification center 105 can also provide regular reports to the content provider and the electronic digital content store 103.
The certification authority 105 defines a secure electronic interface that allows the content provider 101 and the electronic digital content store 103 to request and receive reports. The report request SC contains a certificate assigned by the certification center 105 to the entity that generated the request. The certification authority 105 uses the certificate and the digital signature of the SC to verify that the request comes from an authorized entity. The request also contains parameters that define the scope of the report, such as the time period. The certification authority 105 verifies the request parameters to ensure that the requesting party can only receive the information that they are allowed to receive.
If the certification authority 105 determines that the report request SC is authentic and valid, the certification authority 105 generates a report and encapsulates it in a report SC that is sent to the entity that generated the request. Some reports are automatically generated immediately within a defined time interval and are stored on the certification authority 105 so that they can be sent immediately when a request is received. The format of the data contained in the report is defined in a subsequent version of this article.
F. Billing and payment verification can process the billing of the content 113 through the certification center 105 or the electronic digital content store 103. In the case where the authentication center 105 processes the electronic content 113 bill, the electronic digital content store 103 divides the end user's order into electronic products and physical objects. Then the electronic digital content store 103 notifies the authentication center 105 of the transaction content, which contains the accounting information of the end user and the total number of authorizations required. The authentication center 105 authorizes the end user's credit card and returns a notification to the electronic digital content store 103. While the authentication center 105 authorizes the end user's credit card, the electronic digital content store 103 can charge the end user's credit card for any physical items being purchased. After each electronic item is downloaded by the end user device 109, the authentication center 105 is notified so that the end user's credit card can be charged. This is the final step performed by the end user device 109 before the content 113 is allowed to be used by the end user device 109.
In the case where the electronic digital content store 103 processes the bill of the electronic content 113, the authentication center 105 is not notified of the information about the transaction until the end user device 109 sends the order SC 650 to the authentication center 105. The end user device 109 still notifies the authentication center 105 after each electronic item is downloaded. When the certification authority 105 is notified, it sends a notification to the electronic digital content store 103 so that the electronic digital content store 103 can charge the end user's credit card.
G. Retransmission secure digital content electronic distribution system 100 provides the ability to handle retransmission of content 113. Usually a customer service interface 184 performs the retransmission. The electronic digital content store 103 provides a user interface, and the end user can operate the user interface in a single step to initiate a retransmission. The end user goes to the electronic digital content store 103 site where the content 113 item is purchased to request the content 113 to be retransmitted.
When the end user requests a new copy of the previously purchased content 113 because the content 113 cannot be downloaded or the downloaded content 113 is unavailable, the content 113 is retransmitted. The electronic digital content store 103 determines whether the end user has the qualification or right to resend the content 113. If the end user is eligible or right to retransmit, the electronic digital content store 103 establishes a transaction SC 640 containing the offer SC 641 of the content 113 item to be retransmitted. The transaction SC 640 is sent to the end user device 109 and the end user performs the same steps as when making a purchase transaction. If the end user device 109 has a scrambling key in the key store for the content 113 item undergoing retransmission, the transaction SC 640 contains information that instructs the end user device 109 to delete the scrambling key.
In the case where the authentication center 105 processes the financial settlement of the electronic content 113 purchase, the electronic digital content store 103 includes a logo in the transaction SC 640 that is passed to the authentication center 105 through the subscription SC 650. The authentication center 105 interprets the order of the logo in the SC 650 and continues the transaction without charging the end user for the content 113 purchase.
VIII. Content provider A. Overview The content provider 101 in the secure digital content electronic distribution system 100 is a digital content trademark or an entity that owns the content 113. The role of the content provider 101 is to prepare the content 113 to be distributed and to generate information about the content 113 that can be used by the electronic digital content store 103 or the retailer of the downloadable electronic version of the content 113. In order to provide the content provider 101 with the top level of security and copyright control, a series of tools are provided to allow the content provider 101 to prepare its content 113 in its own place and securely encapsulate the content 113 in the SC, so that the content 113 is leaving The control range of the content provider 101 is always secure and never exposes or accepts access to unauthorized parties. This allows the content 113 to be distributed freely through a non-secure network such as the Internet without fear of exposure to hackers or unauthorized parties.
The ultimate goal of these tools allows the content provider 101 to prepare content 113 such as a song or a series of songs and package it into the content SC 630, as well as to describe the song, the approved use of the song (Content Use Conditions 517), and the song's promotional information The information is encapsulated in a metadata SC 620. To this end, the following tool sets are provided: Workflow Manager 154-Schedule processing activities and manage required process synchronization.
Content Processing Tool 155-Control tool set containing watermarking, preprocessing (for an audio example, any required equalization, dynamic adjustment or resampling), encoding and compression of content 113 file preparation.
Metadata assimilation and input tool 161-is used to collect content 113 description information according to the content provider's database 160 and/or third-party database or data input file and/or through operator interaction to collect content 113 description information and provide a means to specify content usage conditions 517 Set of tools. It also provides an interface for capturing or extracting digital audio content such as CDS or DDP files. A quality control tool allows previewing the prepared content and metadata. You can make any corrections to the metadata or resubmit the content for further processing.
SC encapsulator tool 152-encrypt and encapsulate all content 113 and information and call SC encapsulator to encapsulate into SC.
Content delivery tool (not shown)-deliver the SC to a designated distribution center, such as the content hosting site 111 and the electronic digital content store 103.
Content Promotion Web Site 156-stores metadata SC 620 and optional additional promotional materials for download by authorized electronic digital content store 103.
B. Workflow Manager 154 The purpose of this tool is to schedule, track and manage content 113 processing activities. This application allows multiple users to access the content 113, and allows the content 113 and remote status checks from remote locations within the corporate intranet of the content provider 101 or the corporate external Internet. This design also allows for collaborative processing, where multiple individuals can process multiple pieces of content 113 in parallel, different individuals can be assigned specific responsibilities and these individuals can be distributed around the world.
Referring now to FIG. 8, FIG. 8 is a block diagram of the main processing of the workflow manager 154 corresponding to FIG. 7. The main processing in Figure 8 summarizes the content 113 processing functions provided by the tools described in this chapter. The workflow manager 154 is responsible for delivering tasks to these processes and assigning tasks to the next required process when the current process is completed. This function is accomplished through a series of application programming interfaces (APIs) called by various processing tools: Retrieve the next task to be processed Indicate the successful completion of a process Indicate the unsuccessful completion of a process and the reason for its failure Provide a process Intermediate state (allowing to start processing that only needs to partially complete a subordinate process) Add annotations to a product that can be specified processing. Workflow manager 154 also has a user interface. The workflow manager user interface is illustrated in Figure 7 As an example of 700, the user interface provides the following functions: A configuration panel that allows the specification of default values and conditions specified and executed in each processing stage Customized workflow rules and automated processing procedures Task scheduling Status inquiry and reporting Targeting Add comments or instructions to a task involving one or more processes Task management (ie suspend, release, cancel, change priority (processing order)) Each process has a queue associated with it and managed by the workflow manager 154 . All processes that request tasks from the workflow manager 154 cause the workflow manager 154 to either suspend processing (tools) into a waiting state when there are currently no tasks in its related queue, or return to processing related tasks that need to perform their respective processing. All information about the task. If a process is suspended into a waiting state, the process resumes processing when the workflow manager 154 puts a task in its queue.
The workflow manager 154 also manages the process flow or sequence according to a set of defined rules. In the case of special processing requirements, the content provider 101 can customize these rules, or configure specific default rules. When a process reports the completion of its designated task, the process notifies the workflow manager 154 of this status and the workflow manager 154 determines which queue to put the next task on according to the defined rules.
The annotations indicating special processing instructions or precautions can also be attached to the product by using the workflow manager user interface 700 or the processor interface at any processing step through a programming API or a manual method.
In the preferred embodiment, the processing in the workflow manager 154 is implemented by Java, but other programming languages such as C/C++, assembly language and other equivalent languages may also be used. It should be understood that the following process for the workflow manager 154 can be run on various hardware and software platforms. As a complete system or any process of its composition, the workflow manager 154 can be distributed as an application in a computer-readable medium, including but not limited to such as the Web or through floppy disks, CD ROMs and removable hard disks. Electronic distribution of drives.
Referring now to FIG. 8, FIG. 8 is a block diagram of the main processing of the workflow manager 154 corresponding to FIG. 7. The following sections summarize each process and describe the information or actions required for each process.
1. Product waiting action/information processing 801 Once all the information required for the process is available and the task has successfully completed all related processing, the task is placed on a specific process queue. There is a dedicated queue in the workflow manager 154, which is used to store tasks that are currently unprocessable due to missing information or failures that prevent further processing. These tasks are placed in the product waiting action/information processing 801 queue. Each task in this queue has a related status. The above status indicates the action or information it is waiting for. The final process of processing this task. Once the missing information, additional information or required action is successfully completed, the task is waiting for the next one. process.
The completion of any processing causes the workflow manager 154 to check the queue and determine whether there are tasks in the queue waiting for the completion of the processing (action) or the information provided by the processing. If this is the case, the task waits in the appropriate process queue.
2. New content request processing 802 The content provider 101 determines the product it wants to sell and deliver electronically (for example, a product can be a song or a collection of songs). The initial function of the workflow manager 154 is to allow an operator to identify these products and put them on the queue of the new content request processing 802. The content provider 101 can specify what information to be prompted through the product selection interface through configuration options. Enter enough information to uniquely identify the product. Optionally, additional fields may be included to request manual input of information required to start the audio processing stage in parallel with metadata acquisition. Optionally, if it is not provided manually, this information can be retrieved from the database 160 of the default configuration settings or the content provider's database 160 obtained through the first stage metadata processing in the automatic metadata acquisition processing 803. The composition and capabilities of the content 113 in the content provider's database 160 determine the content selection process.
If the necessary information required to perform a query on the database 160 of the content provider 101 is specified, the automatic metadata acquisition process 803 handles this task. In a music embodiment, in order to reasonably schedule the audio processing of the product, specify the genre of the product, the desired compression level, and the audio PCM or WAV file name. This information can be entered as part of the product selection process, or it can be selected through a dedicated query interface or web browser function. The specification of this information allows scheduling of content processing of the product.
The product selection user interface provides an option that allows the operator to specify whether to start processing the product or whether to make the product wait for further information input. If you choose to wait, the task is added to the queue of the new content request processing 802 to wait for further actions in order to complete the data input and/or start processing the product. Once the product is released, the workflow manager 154 evaluates the specified information and determines what kind of processing the task will be sent to.
If sufficient information is provided to allow automated queries to the database 160 of the content provider 101, the task is queued for processing by the automatic metadata acquisition process 803. If the database mapping table is not configured for the automatic metadata acquisition processing 803, the task is queued for processing by the manual metadata input processing 804 (see section 803 of the automatic metadata acquisition processing for a detailed description of the database mapping table).
If the general information required for audio processing and the specific information required for watermarking are specified, the task is queued for processing by the watermark processing 808 (the first stage of content processing). If any necessary information is omitted when the task is issued, the task is added to the queue of the product waiting action/information processing 801 together with the status indicating the missing information.
If the status indicates that the file name of the content 113 is omitted, the status may indicate that a capture (or digital extraction of digital media) is required, where the content 113 may be an audio and PCM file or a WAV file. The audio processing function requires that the song file can be accessed through a standard file system interface. If the song is placed on an external medium or a file system that cannot be directly accessed by audio processing tools, the file is first copied to an accessible file system. If the songs are in a digital format but are placed on a CD or digital tape, they are extracted to a file system that can be accessed by audio processing tools. Once the file can be accessed, the workflow manager user interface 700 is used to specify or select a path and file name for the task so that the task can be assigned to the watermark process, assuming that all other information required for the watermark has been specified.
3. Automatic metadata acquisition processing 803 The automatic metadata acquisition processing 803 performs a series of queries on the database 160 of the content provider 101 or a hierarchical database into which data has been entered, in order to obtain as much product information as possible in an automatic manner. The automatic metadata acquisition process 803 requires the following information before allowing an item to be placed in its queue: A database mapping table with sufficient information to generate a query to the database 160 of the content provider 101 Product information required to execute the query Unique definition Sufficient product information of the product performs an automatic query on the database 160 of the content provider 101 to obtain the information necessary to process the content 113. For example, if the content 113 is music, the information required to perform this query may be the album name, or it may be a general product code or a specific album or selection ID defined by the content provider 101. Among the information to be obtained, some information is designated as necessary (see the section on the details of the automatic metadata acquisition processing 803). If all the necessary information is obtained, the next task in the queue is the use condition processing 805. If any necessary information is missing, the song is queued for manual metadata input processing 804. If any task in the product waiting action/information processing 801 is waiting for any information obtained through this step, the task status is updated to indicate that the task no longer waits for this information. If the task no longer has any special requirements, the task is queued in the next queue defined.
4. Manual metadata input processing 804 The manual metadata input processing 804 provides a means for the operator to input missing information. The processing has no affiliation. Once all the necessary information is specified, the task is queued for use condition processing 805.
5. Use condition processing 805 Use condition processing 805 allows to specify product use and restrictions. Use condition processing 805 may require certain metadata. When the usage conditions are specified, the task is eligible to be queued for the metadata SC generation process 807, unless the supervised publishing process 806 option has been requested or the option is configured as a default value in the workflow manager 154 rules. In that case, the task is queued for the supervisory release process 806. Before queuing for the metadata SC generation process 807, the workflow manager 154 will first ensure that all the dependencies of the process have been satisfied (see below). If it is not satisfied, the task is queued for the product waiting for action/information processing 801.
6. Supervised publishing process 806 The supervisory publishing process 806 allows quality inspection and verification of information designated for digital content products. There is no affiliation with this process. Through the supervisor and the appropriate actions taken, it is possible to check the annotations previously attached to the task at any stage of the processing for this product. After checking all the information and comments, the supervisor has the following options: Approve the release of the product and queue the product for the metadata SC generation process 807 Modify and/or add the information product and queue the product for the metadata SC generation process 807 To Add comments to the task and re-queue waiting for manual metadata input processing 804 Add comments and add the task to the queue of product waiting action/information processing 801
7. Metadata SC generation processing 807 The metadata SC generation processing 807 combines all the previously collected information and other information required by the metadata SC 620 and calls the SC encapsulator to process and generate the metadata SC620. This tool requires the following inputs: Metadata required Conditions of use Encryption keys used in the encryption phase of all quality levels of this product. This final subordination requires the relevant audio objects to complete the audio processing stage before the metadata SC 620 can be generated. . When the metadata SC generation process 807 is completed, the task is queued to the quality assurance process 813 or the content delivery process 814 according to the defined workflow rules.
8. Watermark processing 808 The watermark processing 808 adds copyright and other information to the content 113. For an embodiment where the content 113 is a song, this tool requires the following inputs: song file name (if it is an album, there are multiple file names) watermark command watermark parameters (information contained in the watermark) when the watermark processing 808 is completed If the required input is already available, the task is queued for preprocessing and compression processing 809, otherwise, it is queued for product waiting for action/information processing 801.
9. Pre-processing and compression processing 809 The pre-processing and compression processing 809 first performs all necessary pre-processing to encode the content 113 to the specified compression level. Placing a task into this queue actually generates multiple queue inputs. A task is generated for each desired product compression level. The encoding process can be performed in parallel on multiple systems. This tool requires the following inputs: The file name of the watermarked content (if the content 113 is an album, there are multiple file names) The quality level of the product (can be pre-configured) Compression algorithm (can be pre-configured)
Product genre (if required by the preprocessor). When the encoding process is completed, if it is configured according to the workflow rules, the task is queued for content quality control processing 810. If not, the task is queued for encryption processing.
If the third-party encoding tool provider does not provide a method of processing the percentage of content 113 such as audio or a method of expressing the amount of content 113 that has been encoded as a percentage of the total selected content 113, it is shown in FIG. 11 A flowchart 1100 of a method for determining the encoding rate of the content preprocessing and compression tool of FIG. 8 is shown. The method starts with step 1101 of selecting the desired encoding algorithm and a bit rate. Next, a query is made to determine whether the algorithm and coding rate have a previously calculated scale factor, step 1102. The scale factor is a coefficient used to determine the compression ratio of a specific coding algorithm and a specific bit rate. If the previously calculated scale factor is not stored, one sample of the content 113 is encoded within a predetermined time. The predetermined period in the preferred embodiment is several seconds long. This coding rate for a predetermined period is used to calculate a new scale factor RNEW. When the amount of time and the amount of encoded content 113 are known, the new scale factor RNEW is calculated as follows: RNEW=(length of encoded digital content)/(amount of time), step 1108. The content 113 is encoded using the previously calculated scale factor RNEW and the encoding status is displayed, step 1109. In order to use this coding algorithm and coding bit rate in the future, the coding rate coefficient RNEW is then stored, step 1107. If the selected algorithm has a previously calculated scale factor RSTORED, step 1103. The content 113 is encoded using the previously calculated scale factor RSTORED and the progress is displayed, step 1104. At the same time, a current scale factor RCURRENT is calculated for the selected algorithm and bit rate, step 1105. This current scale factor RCURRENT is used to update the average value of the stored scale factor RNEW=(RSTORED+RCURRENT), step 1106. In the process of continuously applying the scale factor to a specific coding algorithm and bit rate, the iterative update of the scale factor allows the determination of the coding rate to be more and more accurate. Then store the new ratio RNEW for later use, step 1107. If the current scale factor RCURRENT exceeds a specified range or threshold of the previously stored scale factor RSTORED, the RSTORED cannot be updated.
A display of the encoding status can then be provided. The encoding status display includes displaying the percentage of the total content 113 as a progress bar according to the encoding rate and the total length of the content 113 file along with the current encoding rate. The encoding status can also include the remaining time of the encoding. The remaining time for encoding can be calculated by dividing the calculated encoding rate RCURRENT by the total length of the content 113 file. The encoding state can be transferred to another program that can use the calling procedure. This helps to supervise the coding of the program, and it also helps to more efficiently operate and batch run the accompanying programs used in the coding. It should be understood that in an alternative embodiment, the encoding may include a watermarking step.
10. Content quality control process 810 The content quality control process 810 is similar in function to the supervisory release process 806. This processing is an optional step that allows someone to verify the quality of the content processing performed so far. Except for the encoding part that completes the watermark processing 808 and the preprocessing and compression processing 809, this has no other dependencies. The following options are in effect when the content quality control process 810 is completed: The task can be issued and queued for the encryption process 811.
Annotations can be attached and one or more tasks are re-queued for pre-processing and compression processing 809.
The last option requires that the unencoded watermarked version of the song file continues to be valid until after the content quality control process 810.
11. Encryption processing 811 The encryption processing 811 invokes an appropriate secure digital content electronic distribution copyright management function to encrypt each watermarked/encoded song file. Apart from completing all other audio processing, this processing has no other dependencies. Upon completion of the encryption process 811, the task is queued for the content SC generation process 812.
12. Content SC generation processing 812 The content SC generation processing 812 process may require certain metadata files to be included in the content SC 630. If files other than the content 113 are needed, the files are collected and the SC encapsulator is called for processing to generate a content SC 630 for each compression level of the generated content 113 (for example, a song). When the content SC generation process 812 is completed, the song is queued into the final quality assurance process 813 or the content delivery process 814 according to the defined workflow rules.
13. Final Quality Assurance Process 813 Final Quality Assurance Process 813 is an optional step that allows a cross-reference check between related metadata and content SC 630 to verify that they match correctly and all the information and content contained therein are the same. is correct. Upon completion of the final quality assurance process 813, the task is queued for the content delivery process 814. If a problem is found, in most cases the task must be re-queued to the failure stage. Since the product must be re-encrypted and re-packaged in addition to the reprocessing required to correct the problem, rework at this stage is costly. It is strongly recommended to use the existing assurance phase to ensure the quality of the content 113 and the accuracy and completeness of the information.
14. The content delivery process 814 The content delivery process 814 process is responsible for delivering SC to the appropriate hosting site. After the SC is successfully transferred, the task completion status is recorded and the task is deleted from the queue. If there is a problem in transferring the SC, after repeating a predetermined number of times, the task is marked as a failure in the workflow manager tool 154 and the error encountered is recorded.
15. Workflow rules The workflow rules in Figure 8 work in the following three main systems: A: Workflow manager tool 1541. New content request processing 8022. Product waiting action/information processing 8013. Final quality assurance processing 8134. Content delivery (and notification) processing 814B: Metadata assimilation and input tool 1611. Automatic metadata acquisition processing 8032. Manual metadata input processing 8043. Supervised publishing processing 8064. Metadata SC generation processing 807C: Content processing tool 1551. Watermark processing 808 (copyright data required) 2. Preprocessing and compression processing 8093. Content quality control processing 8104. Encryption processing 8115. Content SC generation processing 812
The workflow content 113 selects the operator to input a new product and the new product starts to be queued on A1 (new content request processing 802).
A1: When the content 113 selects the operator to publish a new product to the workflow manager tool 154, the new product is queued on B1 (automatic metadata acquisition processing 803).
A2: From step B1 (automatic metadata acquisition processing 803), or step B2 (manual metadata input processing 804), or step B3 (supervised publishing processing 806) to step Before (metadata SC generation processing 807) [encryption required key].
From step Before (metadata SC generation processing 807) to step A3 (final quality assurance processing 813) or step A4 (content delivery processing 814) [Required content SC 630].
From step C1 (watermark processing 808) to step C2 (preprocessing and compression processing 809) [metadata required for preprocessing and compression processing 809].
From step C4 (encryption process 811) to step C5 (content SC generation process 812) [metadata required for content SC 630 wrapper].
From step C5 (content SC generation processing 812) to step A3 (final quality assurance processing 813) or step A4 (content delivery processing 814) [metadata SC 620 required].
A3: After step A3 (final quality assurance processing 813), put it into queue B2 (manual metadata input processing 804), or put it into queue B3 (supervised release processing 806), or put it into the queue according to the requirements of the guarantee.
A4: After step A4 (content delivery processing 814), the workflow manager tool 154 ends the processing of the product.
B1: After step B1 (automatic metadata acquisition processing 803), if there is metadata required for step C1 (watermark processing 808), put a record representing this product in queue C1.
(Complete the following logic) If 1- Missing any required metadata, or 2- There is an annotation pointing to the manual metadata provider, then put the product on queue B2 (Manual metadata input processing 804), otherwise, if If a supervised release of this product is required, the product is placed on queue B3 (supervised release processing 806).
Otherwise, if the product gets all the information for all the required quality levels from the content processing tool 155, the product is put on the queue Before (metadata SC generation process 807).
Otherwise, mark the product as requiring an encryption key and put the product on queue A2 (product waiting action/information processing 801).
B2: During step B2 (manual metadata input processing 804), if step C1 (watermark processing 808) is not completed and there is metadata required for step C1, put a record representing this product on queue C1.
(Also complete the following logic) If the metadata required for step C2 (preprocessing and compression processing 809) has just been provided, then (also complete the following logic) If there are all metadata that can be collected by the metadata assimilation and input tool 161, then If a supervised release of this product is required, put the product on queue B3 (supervised release process 806). Otherwise, if there is all information from step C4 (encryption processing 811) of the content processing tool 155, put this product in the queue Before (metadata SC generation processing 807), otherwise mark the product as requiring an encryption key and put the product on queue A2 (product waiting action/information processing 801).
Otherwise, if the metadata provider requires mandatory supervision release, put the product on queue B3 (supervised release process 806) otherwise do nothing (keep the product on queue B2 (manual metadata input process 804)).
B3: During step B3 (supervised release processing 806), if the operator is sending back products to step B2 (manual metadata input processing 804), put the products on queue B2.
Otherwise, if the operator publishes a product, if there is all the information from step C4 (encryption processing 811) of the content processing tool 155, put the product on the queue Before (metadata SC generation processing), otherwise mark the product Encryption key is required to complete and put the product on queue A2 (product waiting action/information processing 801).
Otherwise, the product remains on queue B3 (supervised release process 806).
Before: After step Before (metadata SC generation process 807), the product is marked as the metadata has been encapsulated.
If all (product/quality level) tuples have been encapsulated, if the configuration of the content provider 101 specifies the quality assurance of the SC, put this product on queue A3 (final quality assurance process 813), otherwise put this product Go to queue A4 (content delivery processing 814).
Otherwise, mark the product as needing content 113 SC and put the product on queue A2 (product waiting action/information processing 801).
C1: After step C1 (watermark processing 808), if there is metadata required for step C2 (preprocessing and compression processing 809), generate a record for each (product/quality level) tuple and put them in On queue C2, otherwise mark the product as metadata that needs to be used for preprocessing/compression and put the product on queue A2 (product waiting action/information processing 801).
C2: After step C2 (preprocessing and compression processing 809), if the configuration of the content provider 101 specifies content quality control processing 810, put this (product/quality level) tuple into queue C3 (content quality control processing) 810), otherwise put this (product/quality level) tuple on queue C4 (encryption processing 811).
C3: After step C3 (content quality control processing 810), put this (product/quality level) tuple on queue C4 (encryption processing 811).
C4: After step C4 (encryption processing 811), the metadata assimilation and input tool 161 is provided with the required information (that is, the symmetric key 623 generated by the processing and used to encrypt the content 113).
If there are all the metadata required by the content SC 630, put this (product/quality level) tuple on queue C5 (content SC generation process 812), otherwise mark the product as the element that needs to be used for the content SC 630 encapsulation Data and put this (product/quality level) tuple on queue A2 (product waiting action/information processing 801).
C5: After step C5 (content SC generation process 812), the quality level is marked as the content 113 having this quality level has been packaged.
If all (product/quality level) tuples have been encapsulated, if the product is marked as metadata has been encapsulated, then if the configuration of the content provider 101 stipulates the quality assurance of the SC, then this product is placed in the queue A3 ( In the final quality assurance process 813), otherwise put the product on queue A4 (content delivery process 814), otherwise mark the product as needing metadata SC 620 and put the product on queue A2 (product waiting action/information processing 801).
Otherwise (all (product/quality level) tuples are not encapsulated) do nothing (another (product/quality level) tuple triggers an action).
C. Metadata assimilation and input tool Metadata consists of data describing, for example, the content 113 in the music, the title of the recording, the artist, the author/composer, the producer, and the length of the recording. The following description is based on content 11 as music, but those skilled in the art should understand that other content types such as images, programs, multimedia, movies, and equivalent content are also within the true scope and connotation of the present invention.
This subsystem aggregates the data provided by the content provider 101 to the electronic digital content store 103 to help promote the product (for music, for example, the artists sample selection, the artists history, the list of albums containing the recording, and the artist And/or the genre related to the work), the data provided by the content provider 101 to the end user who owns the purchased product (for example, artist, producer, album cover, track length) and the content provider 101 wants to provide to the end user Different purchase options (Terms of Use 517). The data is encapsulated in a metadata SC 620 and can be used by the electronic digital content store 103. To this end, the following tools are provided: Automatic metadata acquisition tool Manual metadata input tool Using condition tool Supervised publishing tool These tools allow the content provider 101 to implement the above-mentioned processing for the workflow manager 154. The tool described here is a toolkit based on Java in the preferred embodiment, but other programming languages such as C/C++, assembly language and equivalent languages can also be used.
1. Automatic metadata acquisition tool The automatic metadata acquisition tool provides a user with the ability to implement the above-mentioned automatic metadata acquisition processing 803. The automatic metadata acquisition tool is used to access the database 160 of the content provider 101 and retrieve as much data as possible without operator assistance. Structural methods can be used to automate this process. The content provider 101 can customize the default metadata template to specify the type of data provided by the content provider 101 to the end user (for example, composer, producer, accompanist, track length), and the content provider 101 provides to the end user The type of the promotional data of the electronic digital content store 103 (take music as an example, such as a selection of samples of the artist, the history of the artist, a list of albums containing the recording, and genres related to the artist and/or work). The default metadata template contains the data fields required by the end-user device 109. You can select the data fields provided to the end-user device 109 and a sample of the data fields designated to the electronic digital content store 103 to promote artists, albums and/or singles set.
In order to extract the template data fields from the database 160 of the content provider 101, the automatic metadata acquisition tool uses a list of data types (for example, composer, producer, artist biographies) that can be found in the database. . Each content provider 101 helps define a mapping table for its environment.
The automatic metadata acquisition tool uses the metadata template and mapping table of the content provider 101 to acquire any data that can be obtained from the database 160 of the content provider 101. The status of each product is updated according to the result of the automatic metadata acquisition process 803. Products that have missed any required data are queued for manual metadata input processing 804, otherwise they can be encapsulated in a metadata SC 620.
2. Manual metadata input tool The manual metadata input tool provides a user with the ability to realize the aforementioned manual metadata input processing 804. Manual metadata entry tools allow any duly authorized operator to provide missing data. If the operator determines that the missing data is not available, the operator can attach a note to the product and request a supervisory release. The content provider 101 may need to supervise and release the product for quality assurance. Once all the required data is provided, and without a request to supervise the release, the product can be packaged in a metadata SC620.
3. Use condition tool Use condition tool provides a user with the ability to realize the above use condition processing 805. The process of using electronic delivery to provide content 113 for sale or rental (restricted use) involves a series of business decisions. The content provider 101 determines the compression level to which the content 113 applies. Then, one or more usage conditions are specified for each compression-encoded version of the content 113. Each use condition defines the rights of the end user and any restrictions on the end user for the use of the content 113.
As part of the content processing tool 155, a set of usage conditions (end user rights and restrictions) are attached to the product.
The use conditions define the following information: 1. The compressed coded version of the content 113 to which the use conditions apply.
2. Types of users covered by the conditions of use 3. Whether the conditions of use allow the purchase or rental of content 113.
For a rental transaction: The unit of measurement used to limit the rental period (for example, days, broadcast).
The number of the above units, where the content 113 is no longer played after this number is reached. For a purchase transaction: The number of playable copies that the end user is allowed to make.
What kind of media (for example, CD-R, compact disc, personal computer) can he/she make those copies.
4. The time period during which purchase/rental transactions are allowed to occur (ie, an end user can only purchase/rent after the effective date and before the end of the most recent effective period under the restriction of this use condition).
5. A country with which the end user can make this purchase (or lease).
6. The price of the purchase/rental transaction under these conditions of use.
7. Watermark parameters.
8. The type of event that needs to be notified to the certification authority 105.
An example of the use condition group. The content provider 101 may decide to test the North American markets acceptance of a childrens song released by a popular childrens singer in the fourth quarter of 1997. This test will produce songs with two different compression encoding versions: 384Kbps and 56Kbps. The 384Kbps version can be purchased (and a copy is made on a small disc) or leased (two weeks), while the 56Kbps version can only be purchased (and no copy is made). The watermark instructions are the same for any purchase/rental watermark, and the content provider 101 needs the authentication center 105 to accumulate the number of all copies manufactured. This will produce the following conditions of use:
4. Fragments of metadata SC 620 The following are some types of data collected by the metadata assimilation and input tool 161 and included in the metadata SC 620. Try to combine data into SC segments based on function and destination.
Product ID [Source: Content Provider;] [Destination: Everyone;] Licensees Trademark Company [Destination: EMS; End User;]
The licensees trademark company [destination: EMS; end user;] the source (publisher) object type (ie, a single [Destination: each person;] Unique object or group of objects) Object ID International Standard Recording Code (ISRC) International Standard Music Number (ISMN) Conditions of Use (Source: Content Provider; Destination: EMS, End User, Certification Center 105) Purchase use conditions (source: EMS; destination: end user, certification center 105) for the object (recording) use condition group (user restrictions and rights) a single entry in the use condition group to which the use condition applies Compressed coded version of content 113.
Whether this usage condition allows the purchase or rental of content 113 is for a rental transaction: a unit of measurement used to limit the rental period (for example, number of days, number of plays).
The number of the above units, where the content 113 is no longer played after this number is reached.
For a purchase transaction: the number of playable copies that the end user is allowed to make.
What kind of medium (for example, CD-R, compact disc, personal computer) can he make those copies.
The period of time during which purchase/rental transactions are allowed (that is, an end user can only purchase/rent after the effective date and before the end of the most recent valid period under the restrictions of this use condition) points to an end user who can make this purchase (or A pointer to the country of rental) The price of the purchase/rental transaction under the conditions of use A pointer to encrypted watermark instructions and parameters A pointer to the type of event that needs to be notified to the certification center 105 Purchase data (encrypted; optional information; source : EMS; destination: end user, certification center 105) purchase date purchase price bill name and address user name and address user country (best guess) metadata 1 (source: content provider; destination: EMS, final User) an array {copyright information for the work for the recording title of the song, the starring artist} a pointer {illustration (for example, album cover); illustration format (for example, GIF, JPEG); }optional information: an array of additional information {composer Publisher, producer, accompanist, recording date, release date, lyrics, track name (description)/track length, list of albums containing this recording, genre} metadata 2 (source: content provider; destination: EMS) an array of structures, each structure Represents different quality levels of the same recording {recording; recording quality level; (possibly compressed) recording length (in bytes);} metadata 3 (source: content provider; destination: EMS, end user) optional Information: Promotional material: a pointer to the artists promotional material {URL of the artists website; background description of the artist; related interviews of the artist (and the interview format (for example, text, audio, video)); comments (and the format of the comments) (E.g. text, audio, video)); sample selections (and their format and compression level); recent and future concerts/performances/events-their dates and locations; }a pointer to the album's promotional materials {sample selections ( And its format and compression level); the producer, and/or the composer, and/or the background description of the movie/script/all actors, and/or album production, etc.; interviews not related to the artist (and the interview format (e.g., Text, audio, image));
Comment (and the form of the comment (for example, text, audio, video)); genre;} single promotion: sample selection (and its format and compression level); producer, and/or composer, and/or movie/script /All actors, and/or background descriptions of single production, etc.; comments (and the form of comments (for example, text, audio, video)); 5. Supervised release tools Supervised release tools provide users with the above-mentioned supervision release processing 806 ability.
An individual designated by the content provider 101 with the right to supervise release can collect a product waiting for supervised release (ie, a product in the queue of the supervised release process 806), check its content 113 and additional comments, and approve its content 113 and release the product to be packaged in a metadata SC 620, or make any necessary corrections and release the product to be packaged in a metadata SC 620, or add a note indicating the corrective actions taken and resubmit the product to manual metadata Data input processing 704 In another embodiment, after the SC is generated, another optional quality assurance step can be performed, in which the content 113 of the SC can be opened and checked for completeness and accuracy, and at the same time, it can be finally Approve or reject the release of the product to the retail channel.
D. Content Processing Tool Content Processing Tool 155 is in fact a software toolkit used to process digital content files in order to produce watermarked encoded and encrypted content copies. The tool utilizes industry standard digital content processing tools to enable embedded replacements for permitting, encoding, and encryption technologies based on technological developments. If you can load the selected industry tools through a command line system call interface and pass parameters, or if you provide a toolkit that can call the functions through a DLL interface, the degree of automation of content processing can reach a certain level. A front-end application of each tool queries the next executable task in the appropriate queue in the content processing tool 155, retrieves the required files and parameters, and then loads the industry standard content processing tool to perform the required function. When the task is completed, if the tool does not report the termination status, it may be necessary to manually update the queue.
A general version of the content processing tool 155 is described here, but it can also be customized. The content processing tool 155 can be written in Java, C/C++ or any other equivalent software. The content processing tool 155 can be delivered through computer readable means including diskettes, CDS, or through a Web site.
1. Watermarking tool The watermarking tool provides a user with the ability to implement the above-mentioned watermark processing 808. This tool uses audio watermarking technology to apply the copyright information of the content 113 owner to the song file. The actual information to be written is determined according to the content provider 101 and the specific watermark technology selected. This information can be used by the front-end watermarking tool so that it can properly pass this information to the watermarking function. This puts forward a synchronization requirement for the metadata assimilation and input tool 161 to ensure that it obtains this information before allowing it to process the audio file of the song. This song will not be audio processed until the watermark information has been obtained.
Since all encodings of the generated songs are common, watermarking is the first step in audio processing. As long as the watermark can coexist with the encoding technology, only one watermarking process is required for each song.
Various watermarking techniques are known and available on the market. Of course, the front-end watermarking tool can support various industrial watermarking tools.
2. Pre-processing and compression tools The pre-processing and compression tools provide users with the ability to achieve the above-mentioned pre-processing and compression processing 809. Audio coding involves two processes. Taking music content as an example, encoding is basically the application of a lossy compression algorithm that processes PCM audio streams. Generally, the encoder can be tuned according to the required audio quality level to generate various playback bitstream rates. Higher quality results in a larger file length, and since the file length of the high-quality content 113 may become quite large, the download time of the high-quality content 113 may become very long and sometimes cannot be downloaded via a standard 28,800bps modem.
Therefore, the content provider 101 can choose to provide a variety of digital content download quality to meet impatient and low-bandwidth customers who dont want to wait for hours to download, and to satisfy customers who only purchase high-quality content 113 or who have high-speed connections and demand sound quality. Or high-bandwidth customers.
For the reproduction of content 113 that produces a lower bit rate, the compression algorithms are technically different. The above technologies differ in algorithms (ie, MPEG, AC3, ATRAC) and compression levels. In order to achieve a higher level of compression, the data is usually resampled at a lower sampling rate before being passed to the compression algorithm. In order to allow a lower degree of distortion more effectively compressed, or by a number of signals in order to prevent the loss of certain frequency bands, may need to adjust the equilibrium level of certain frequencies of the digital content, or to adjust the dynamic recording. The content preprocessing requirements directly involve the compression algorithm and the required compression level. Since songs of the same genre usually have similar dynamics, sometimes the style of the content 113 (for example, music genre) can be successfully used as a basis for determining the preprocessing requirements. For some compression tools, these preprocessing functions are part of the encoding process. For other tools, perform the desired preprocessing before compression.
In addition to downloadable audio files for sale, each song has a low bit rate (LBR) encoded segment that allows the song to be sampled through an LBR streaming protocol. This LBR encoding is also a function of the content processing tool 155. The content provider 101 provides this segment either as a separate PCM file or as an offset and length parameter.
Just like watermarking, people hope that the encoding tool can be loaded through a DLL or command line system call interface and all the parameters necessary for preprocessing and compression can be passed in. The front-end encoding tool may have a synchronization requirement for the metadata assimilation and input tool 161, for example, when the content is music and it has been determined that the genre of the song is obtained from the database 160 of the content provider before performing any audio preprocessing. It depends on the encoding tool chosen and how uncertain the genre of the song is. If the content provider 101 changes the encoding quality level selection of each song, this information is also provided before the encoding step and the information is consistent with the metadata generated by the metadata assimilation and input tool 161.
Various high-quality coding algorithms and tools are currently known. Of course, front-end coding tools can support various industrial coding tools.
Referring now to FIG. 12, there is shown a flowchart of an embodiment of the automatic metadata acquisition tool based on the present invention in relation to FIG. 8. The starting point of the process is to read an identifier from the medium that the content provider 101 is checking. An example of related content is in an audio CD embodiment. In an audio CD embodiment, the following codes can be used: Universal Price Code (UPC), International Standard Recording Code (ISRC), International Standard Music Number (ISMN). This identifier is read through an appropriate player for the content, such as an audio CD player for audio CD, a DVD player for DVD movies, a DAT recorder for DAT recording and similar devices, step 1201. Next, this identifier is used to index a database 160 of a content provider 101, step 1202.
Some or all of the information required for processing by the workflow manager described in FIG. 8 is retrieved from the database 160 and any other related resources. This information can include content 113 and metadata related to it. In step 1204, the retrieved additional information is used to start the workflow manager 154 to generate the electronic content 113. It should be understood that several media selections, such as several audio CDS, can be queued to allow automatic metadata acquisition tools to produce a series of content 113 for electronic distribution. For example, all the content 113 can be produced through a series of CDS, and the audio track can even be selected from one or more CDS checked by the content provider 101.
In an alternative embodiment, the preprocessing parameters may be automatically retrieved from the database 160 of the content provider. Referring now to FIG. 13, FIG. 13 is a flowchart of a method for automatically setting the preprocessing and compression parameters of the preprocessing and compression tool of the present invention in FIG. 8. In this embodiment, the content 113 is music. In step 1301, select music (content 113) to the content processing tool 155 for encoding. The genre of the selected music is determined, step 1302. This information can be entered manually or using other available metadata, such as additional data retrieved through the process described in FIG. 12. Then check the selected audio compression level and audio compression algorithm, step 1303. Next, according to the genre, compression setting and compression algorithm, find out what compression parameters should be used in the preprocessing and compression processing 809, 1304, step 1304.
3. Content quality control tool The content quality control tool provides a user with the ability to implement the above-mentioned content quality control processing 810. This is an optional content processing tool and provides an opportunity for quality control technicians to evaluate encoded and watermarked content files and approve or reject content files based on quality judgments. He can re-encode the content through manual preprocessing adjustments until the quality requirements are met or he can mark the song as needing reprocessing and attach a leaflet describing the problem.
The content provider 101 can configure this processing step as an optional or necessary step of the content processing workflow. Provide an additional optional final quality assurance process 813 after all SCs that encapsulate this content (for example, each SC of a song on a CD). At this time, the quality of the content encoding can be tested, but earlier before encryption and encapsulation Finding the problem allows for more effective content processing. Therefore, instead of waiting until all the processing is finally completed, people very much hope to ensure the quality of the content at this step.
4. Encryption tool The encryption tool provides a user with the ability to implement the aforementioned encryption processing 811. Content encryption is the final step of the content processing tool 155. Now encrypt the various versions of the content produced by the encoding tool. The encryption tool is a function of the SC wrapper. Call the SC wrapper to encrypt the song and return the encryption key used. This key is later passed to the SC wrapper to generate the metadata SC 620.
E. Once the content SC creation tool has collected all the metadata, the content SC creation tool combines the metadata into various categories according to its purpose of use. These metadata groups are written as metadata fragments of the metadata SC 620 into the file that is passed to the SC wrapper tool. Each segment (file) has unique processing requirements. Once the relevant song has been processed and encrypted and the target destination (URL of the content hosting site 111) has been determined, the content SC 630 of the content 113 is about to be generated. The content 113 that has been processed and satisfies all the above requirements is queued for packaging through the wrapper queue of the workflow manager 154.
The content SC generation processing tool now retrieves all necessary files generated through the previous steps of the metadata assimilation and input tool 161 and calls the SC wrapper function to generate metadata SC620 and content SC 630. For each song, this process generates a single metadata SC620 and multiple contents SC630. For example, if the content is music, each audio file generated during the audio processing for each quality level of the complete song is encapsulated into the content SC 630. The audio file generated for the sample selection is delivered as a metadata file contained in the metadata SC620.
F. Final Quality Assurance Tool The final quality assurance tool provides a user with the ability to implement the above-mentioned final quality assurance process 813. Once all SCs are established for a content file, the final quality assurance check can be performed on the content. Quality assurance can be performed at various stages of the content 113 preparation process. The content provider 101 can choose to perform quality assurance when each main step is completed to prevent excessive rework later, or can choose to wait until all audio preparation processes are completed and immediately perform quality assurance on all content. If the latter is selected, quality assurance is performed when SC is generated. This tool allows each SC of the song to be opened, inspected, and played with audio.
Any problems found, including small text changes, will require the SC to be rebuilt due to the SC's internal safety functions. In order to avoid unnecessary reprocessing time, it is strongly recommended to use an intermediate quality assurance step to ensure the accuracy of the metadata, and to retain this specific quality assurance step to verify the corresponding cross-references between the SCs related to this song. If a problem is found, the guarantor can enter a problem description attached to the song and make it wait for reprocessing in the corresponding processing queue again. The status is updated accordingly in the workflow manager 154 to indicate the status of all relevant parts of the song. If no problems are found, the content 113 is marked as ready for publication.
G. Content Delivery Tool The content delivery tool provides a user with the ability to implement the above-mentioned content delivery processing 814. Once the content 113 is approved for distribution, the SC of the content 113 is placed in the queue for content delivery processing. The content delivery tool monitors the queue and delivers SC files instantly or a group of SC files in batches according to the configuration settings provided by the content provider 101. Optionally, the content provider 101 can also configure the content delivery tool to automatically keep all SCs in its queue until they are manually marked as ready for release. This allows the content provider 101 to prepare the content before its planned release date and keep the content until it wishes to release content such as a new song, movie, or game. SC can also control access to content 113 according to a predetermined release date, so there is no need for content providers to actually delay the delivery of SC, but this manual release option can still be used for this purpose, and can also be used to manage the delivery of large files The required network bandwidth.
When marked as ready for distribution, the content SC 630 of the content 113 is delivered to the designated content hosting site 111 via FTP. The metadata SC 620 is transferred to the content promotion website 156 via FTP. Here the SC is upgraded to a new content 113 directory until it can be processed and concentrated to the content promotion website 156.
FIG. 17 is a flowchart of an alternative embodiment for automatically retrieving additional information for the automatic metadata acquisition tool of FIG. 8 based on the present invention. The processing is similar to the processing described previously in FIG. 8. However, the quality checks of the supervisory release 806 and the content quality control 809 are combined into one quality check called the quality control 1704. The quality check is performed before metadata SC generation 807 and content SC generation 812. Performing a quality check before SC generation eliminates the step of disassembling content 113 and related metadata SC 620. In addition, in this embodiment, the queue of product waiting action/message 801 is also removed. According to the action being requested, the task is placed in a specific processing queue. For example, if a task requires manual metadata input, that is, additional metadata, the task is placed in the manual metadata input queue. And the automatic metadata acquisition 803 and the new content request are merged before the metadata assimilation and input tool 161 and the content processing tool 155. Finally, it needs to be pointed out that the usage conditions 804 are entered during the automatic metadata acquisition 803 and during the manual metadata input 803. So far, many usage conditions can be automatically filled in during the automatic metadata acquisition 803 step.
H. The content promotion Web site is for the most effective distribution of information about the content that the content provider 101 provides and sells through digital downloads, and to provide the electronic digital content store 103 with necessary files to allow it to make the content 113 available to its customers For downloaded content, each content provider 101 should have a secure Web site where the information resides. This is similar to the method currently used by certain content providers 101 to produce promotional content that can be used by their retailers and other parties in need. In the case where this type of service already exists, an additional part can be added to the Web site, where the electronic digital content store 103 can go to the Web site to see a list of content that can be sold by downloading.
The content provider 101 has complete control over the design and layout of this site, or can choose to use a contracted web server solution provided as part of the secure digital content electronic distribution system 100 toolkit. In order to implement its own service design, the content provider 101 only needs to provide the electronic digital content store 103 accessing its site with a link to the metadata SC 620. The toolkit of the secure digital content electronic distribution system 100 is used to achieve this function. The content provider 101 decides what information to process and display.
The metadata SC620 in a new catalog table received from the content delivery tool via FTP is processed by the content promotion website 156. You can use the SC preview tool to open these containers for display or extract information from the containers. This information can then be used to update HTML Web pages and/or add information to a queryable database maintained by this service. The SC preview tool is actually a subset of the content acquisition tool used by the electronic digital content store 103 to open and process the metadata SC 620. For a more detailed description, see the content acquisition tool section. The metadata SC 620 file should then be transferred to a permanent directory maintained by the content promotion website 156.
Once the metadata SC 620 is centralized to the content promotion website 156, it is declared available for use. When each new metadata SC 620 is added to the site, the content provider 101 can send a notification to all subscribed electronic digital content stores 103, or it can execute a single notification about all the metadata added on the day (or the time period). Daily (or at any prescribed period) notification of data SC 620. This notification is achieved by sending a predetermined CGI string containing parameters related to the added metadata SC 620 through a standard HTTP exchange with the electronic digital content store 103. This message is processed by the notification interface module of the electronic digital content store 103 described later.
I. The content-resident entertainment industry produces thousands of content titles such as CDS, movies, and games every year, and there are tens of thousands of content titles accumulated so far. The secure digital content electronic distribution system 100 is used to support all content titles available in stores today.
There are thousands or tens of thousands of content titles that the secure digital content electronic distribution system 100 can eventually download to customers daily. For a large number of titles, a large amount of bandwidth is required. Computer disk space and bandwidth need to implement multiple content hosting sites 111 in a distributed and scalable manner. The system also supports customers all over the world. This requires overseas sites to accelerate delivery to global customers.
The content hosted on the secure digital content electronic distribution system 100 is used to allow the content provider 101 to host its own content 113 or share a common facility or group of facilities.
The content resident on the secure digital content electronic distribution system 100 is composed of multiple content resident sites 111, and these content resident sites collectively include those provided by the secure digital content electronic distribution system 100 and a number of auxiliary content sites (not shown), including All the current hot content 113 provided by the content provider 101. The number of content hosting sites 111 is changed according to the number of end users using the system. Secondary content sites host a limited number of songs, but they will provide most of the bandwidth used on the system. When the capacity of the primary site increases to the maximum capacity point, the secondary site goes online. The location of the secondary site can be close to the network access point (NAP), which helps speed up the download. In order to speed up the download speed, they can also be distributed in different global geographic areas.
The content provider 101 should choose to host all of its content 113 in its own system, and they can act as a separate content hosting site 111 with or without additional auxiliary content sites. This allows them to build their own scalable distributed system. In another embodiment, the electronic digital content store 103 can also act as a content hosting site 111 for certain content 113. This embodiment requires a special financial agreement between the electronic digital content store 103 and the content provider 101.
1. The content hosting site The content delivery tool described in the content provider chapter of this manual adds content 113 to the content hosting site 111 via FTP or HTTP, or offline means, such as tape, CD Rom, flash memory Or other computer-readable media add the content 113 to the content hosting site 111. The metadata SC 620 generated by the content provider 101 contains a field indicating the URL of the content SC 630 where this content 113 is located. This URL corresponds to a content hosting site 111. The electronic digital content store 103 can ignore this URL if the content provider 101 allows it through the offer SC 641. When it is desired to download the content SC 630, the end user device 109 communicates with this content hosting site 111.
The end user device sends a request for a content SC 630 by sending a license SC 660 to the content hosting site 111. This SC is the same as the license SC 660 returned by the certification center 105. The digital signature of the license SC 660 can be verified to determine whether it is a valid license SC 660. If it is a valid license SC 660, then either start the download or redirect the download request to another content hosting site 111.
2. The content hosting site 111 provided by the secure digital content electronic distribution system 100 For the secure digital content electronic distribution system 100, the main content site receiving the initial request for a content SC630 determines which site should be used to download the content 113. This site uses the following information to make this decision: Is there an auxiliary content site hosting the requested content 113? (Most of the content 113 provided by the secure digital content electronic distribution system 100 is only located on the main site); Where is the geographic location of the end user device 109? (This information can be obtained from the end user device 109 when a request is made on the end user device 109, and the information is passed to the certification center 105 by ordering the SC 650); Is there a suitable auxiliary site online and working? (Sometimes the auxiliary site may be offline); How about the load of the auxiliary site? (In some cases, one auxiliary site is very busy and the other site is not too busy, you can choose the site that is not busy); before sending the content SC 630 to the end user device 109, the end user's request is analyzed and verified. A database records all license SC IDs that have been used to download content 113. This database can be checked to ensure that the end-user device 109 only requests individual pieces of the purchased content 113. This can prevent malicious users who expect to lower the speed of the content hosting site 111 from repeatedly visiting the content hosting site 111 and also prevent unauthorized downloading of the content SC 630.
The content 113 in the auxiliary content site is periodically expanded and reduced according to the customer's request for a single segment of the content 113.
Content resident router A content resident router (not shown) is located on the content resident site 111 and receives all requests from end users who wish to download the content 113. The device performs a verification check on the end user request to ensure that they have indeed purchased the content 113. Maintain a database about the status of what content 113 contains on the auxiliary content site and its current status. This current status includes the number of activities on the site and whether a site is on the maintenance list.
The only interaction with the content resident router is the license SC 660 sent by the end user device 109 when the content 113 is required to be downloaded. The license SC 660 contains information indicating that the user is allowed to download the content 113.
Auxiliary Content Site Auxiliary content site (not shown) hosts popular content 113 of the secure digital content distribution system 100. Geographically, these sites are scattered all over the world and their locations are close to the network access point (NAP) to improve download time. These sites are added to the system when the load of the main content hosting sites 111 approaches the maximum capacity.
IX. Electronic Digital Content Store A. Overview-Supporting Multiple Electronic Digital Content Stores 103 The electronic digital content store 103 is essentially a retailer. They are the entities that sell the content 113 that is distributed to customers. For the distributed content 113, it will include a digital content retailer's website, a digital content retail store, or any enterprise that wants to participate in the sale of electronic content 113 to users. These companies may only sell electronic content 113, or they may choose to only increase the sales of electronic products to other sales plans they are currently executing. Through a set of tools developed for the electronic digital content store 103 as part of the secure digital content electronic distribution system 100, downloadable electronic products are turned into services of the electronic digital content store 103.
These tools are used by the electronic digital content store 103 to: Obtain metadata SC 620 encapsulated by the content provider 101 Download content 113 offer SC 641 Confirm the sale and initiate download by generating and sending transaction SC 640 to the end user device 109 Manage a transaction record about the sale of downloadable content 113 and the status of each download
Processing status notifications and transaction authentication requests. The purpose of implementing the account reconciliation tool is to allow the electronic digital content store 103 to have flexibility in turning the sale of downloadable electronic content 113 into its service. Although not necessary, the tool can be used in a manner that requires the certification center 105 to process all financial settlements of the purchased downloadable content 113. These tools also allow the electronic digital content store 103 to fully serve its customers and process its own financial transactions, including providing promotions and special offers. The tool allows the electronic digital content store 103 to quickly integrate the sale of downloadable content 113 into its existing business. In addition, the electronic digital content store 103 does not require resident downloadable content 113 and does not have to manage its delivery. The content hosting site 111 selected by the content provider 101 performs these functions.
In the preferred embodiment, the tools for the electronic digital content store 103 are implemented by Java, but other programming languages such as C/C++, assembly language and similar languages can also be used. It should be understood that the following tools for the electronic digital content store 103 can be run on various hardware and software platforms. As a complete system or any component of its composition, the electronic digital content store 103 can be distributed as an application program in a computer-readable medium, including but not limited to such as the Web or through floppy disks, CD ROMs and removable hard disks. Electronic distribution of drives.
In another embodiment, the components of the electronic digital content store 103 are part of a programmer's software toolkit. This toolkit allows predetermined interfaces with various components of the general electronic digital content store 103 components and the following tools. These predetermined interfaces have the form of APIs or application programming interfaces. A developer using these APIs can implement any function of an advanced application component. By providing APIs for these components, a programmer can quickly develop a dedicated electronic digital content store 103 without the need to regenerate these functions and any component resources.
The electronic digital content store 103 is not limited to web-based service provisioning. The provided tools are used by all electronic digital content stores 103 that wish to sell downloadable electronic content 113, regardless of the transmission infrastructure or delivery method used to deliver this content 113 to the end user. Broadcast services provided through satellite and cable infrastructure also use the same tools to acquire, package, and track the sales of electronic content 113. The manifestation of electronic sales of goods and the method of providing these goods to end users is the main difference between broadcast-based service provision and point-to-point interactive Web service provision.
B. Point-to-point electronic digital content distribution service Point-to-point mainly refers to the one-to-one interactive service between the electronic digital content store 103 and the end user device 109. This usually means an Internet-based Web-based service provided through a telephone or modem connection. In this model, other networks besides the Internet are also supported, as long as these networks conform to the Web server/client browser model. FIG. 9 is a block diagram illustrating the main tools, components, and processing of an electronic digital content store 103.
1. Integration requirements The secure digital content electronic distribution system 100 not only generates new online services, but also provides existing enterprises with a method to integrate the sales of downloadable electronic content 113 into their current services. The set of tools provided for the electronic digital content store 103 simplifies this integration work. The content acquisition tool 171 and the SC wrapper tool 153 provide the electronic digital content store 103 with a way to obtain information about what they can sell from participating content providers 101 and generate references to these downloadable objects as items in their own inventory. The method of the required documents. This process is performed in batches, can be performed automatically in large batches, and is performed only when the new content 113 is integrated into the site.
The purpose of the tool for secure digital content electronic distribution is to allow the sale of electronic downloadable content 113 to be integrated into a Web-based electronic digital content store with minimal changes to its current content 113 retailer paradigm. 103 (e.g. ColumbiaHouse online, Music Boulevard, @Tower) and similar enterprises in typical implementations. There may be several integration methods, and in the preferred embodiment, the electronic digital content store 103 provides support for all product search, preview, selection (shopping cart) and purchase. Each electronic digital content store 103 establishes customer loyalty with its customers, continuously provides its own incentive measures and sells its products as currently done. In the secure digital content electronic distribution system 100, it is only necessary to indicate which products in its inventory are also available for electronic download and allow its customers to select electronic download options when making purchase choices. In another embodiment, the customer's shopping cart may contain a mixture of electronic (content 113) and physical media options. After the customer completes the inspection, the electronic digital content store 103 completes financial settlement and logs in or informs its delivery and processing functions to process the purchase of physical goods, the business processing function of the electronic digital content store 103 then calls the transaction processor module 175 to process all electronic downloads . The module simply transmits the necessary information, and all processing from there is taken care of by the toolkit of the secure digital content electronic distribution system 100. In another embodiment, if the electronic digital content store 103 wants to sell only downloadable goods or wants to separate the financial settlement of physical goods and downloadable goods, it can also use other tools that use the secure digital content electronic distribution system 100 to handle financials. The settlement transaction processing method.
In order to handle the downloading of goods, the electronic digital content store 103 is assigned a product ID (not shown) for each downloadable product acquired by the electronic digital content store 103 from the content promotion website 156 of the content provider 101. This product ID is related to a customer's purchase selection of a downloadable product. The product ID is passed to the transaction processor module 175 by the electronic digital content store 103 to identify the product purchased by the user. The SC (offer SC 641) generated to describe the product is isolated from the electronic digital content store 103 and is kept in a quotation database 181 in order to simplify the management of these objects and make their existence transparent to the electronic digital content store 103.
The transaction processor module 175 and other additional functions are provided as executable programs (ie, CGI and NSAPI, ISAPI callable functions) on the Web server side, or the API is simplified into a DLL or C object library. These functions are responsible for the runtime processing of the interaction between the end user and the authentication center 105 and the optional interaction. These functions interact with the business services of the Web server to generate the files necessary to initiate the content 113 download process and download the files to the end user device 109. They also handle optional interactions to provide authorization and accept notifications of activity completion.
An account reconciliation tool 179 is also provided to help the electronic digital content store 103 contact the certification center 105 to perform reconciliation according to its own transaction log with the certification center 105.
2. Content acquisition tool 171 The content acquisition tool 171 is responsible for interfacing with the content promotion website 156 to preview and download the metadata SC 620. Since the content promotion site is a standard Web site, the electronic digital content store 103 uses a Web browser to browse the site. The browsing function is changed according to the site design of the content provider 101. Some sites can provide a wide range of search capabilities with many promotional information screens. Other sites can have a pure browser interface from which you can select titles, performers, or catalogs of newly released versions. All sites contain an anthology of metadata SC 620, which contains all promotional and descriptive information for a song or album.
Optionally, the electronic store 103 may subscribe to content updates and automatically receive the updates via FTP.
The View Metadata Content Acquisition Tool 171 is a web browser help application that is launched whenever a metadata SC 620 link is selected on the content promotion website 156. Selection of SC causes the SC to be downloaded to the electronic digital content store 103 and the help application is launched. The content acquisition tool 171 opens the metadata SC 620 and displays the non-encrypted information contained therein. Taking music as an example, the display information includes the extracted metadata 173, the graphic image of the song and the information describing the song. If the metadata SC 620 has it, you can also listen to a preview of the song. In an example where the content 113 is music, if the content provider 101 provides it, the promotion information about the song or album, album title, and artist is also displayed. This information is displayed as a series of linked HTML pages in the browser window. Purchasable content 113 such as songs and lyrics, and other metadata that the content provider 101 wishes to protect are not accessible by the retailer content website 180.
In another embodiment, the content provider 101 provides optional charged promotional content. In this embodiment, such promotional content is encrypted in the metadata SC 620. The authentication center 105 can use the account that charges the specified fee to the electronic digital content store 103 to process the financial settlement of opening this data.
In addition to the preview capability for extracting metadata, this tool provides two additional functions: metadata extraction and quotation SC 641 preparation. Selecting the metadata extraction option can prompt the electronic digital content store 103 to enter the path and file name where the metadata will be stored. Binary metadata such as graphics and audio preview excerpts are stored in separate files. The text metadata is stored in a plain ASCII text file, which the retailer content website 180 can import into its database. In a separate TOC file, a list describing the format of the pure ASCII code file is also generated. Additional options can be used to allow extraction into other formats supported by Ethnic Language Support (NLS).
An important piece of information provided in the extracted data is the product ID. The business processing function of the electronic digital content store 103 needs to use this product ID to identify the transaction processor module 175 (for more information, see the transaction processing section), and the content 113 that the user has purchased. The transaction processor module 175 uses this product ID to correctly retrieve the appropriate offer SC 641 from the offer database 181 for subsequent download to the end user device 109. The electronic digital content store 103 has complete control over how to provide the downloadable content 113 offer on its site. It only needs to maintain a cross-reference on the content 113 provided to this product ID to properly interface with the tools of the secure digital content electronic distribution system 100. Providing this information here allows the electronic digital content store 103 to integrate the product or content 113 into its inventory and sales list (database) in a parallel manner with the quotation SC 641 generation process. The reason is that the two processes use the same product. The ID refers to the product. This is described below.
The offer SC generation packager 153 requests the electronic digital content store 103 to generate an offer SC 641 describing the downloadable content 113 for sale. Most of the information put into the offer SC 641 comes from the metadata SC 620. The content acquisition tool 171 generates the offer SC 641 through the following operations: According to the definition of the offer SC template of the metadata SC 620, the fragments that do not need to be included in the offer SC 641 are removed from the metadata SC 620.
Add other required segments according to the default definition specified by the configuration options of this tool of the electronic digital content store 103.
Prompt to enter or select the required additional information according to the definition of the quotation SC template in the metadata SC 620.
Invoke the SC encapsulator 153 to encapsulate this information into the SC format.
The metadata SC 620 contains metadata displayed on the end user device 109 by the player application 195 (described further below). Other promotional metadata that is only used by the electronic digital content store 103 as its Web service database input is removed from the metadata SC 620. It also contains copyright management information provided by the content provider 101, such as a watermark command, an encryption symmetric key 623, and a use condition 517 that defines the allowed use of the object.
This reduced metadata SC 620 is then included in the offer SC 641. The electronic digital content store 103 also attaches itself to the offer SC 641, which is referred to as the store use condition 519 or the use condition of the purchase option. This operation can be done interactively or automatically through a set of default options. If it is configured as interactive processing, the electronic digital content store 103 is prompted with a set of 517 allowable object usage conditions defined by the content provider 101. The store then selects the options it wants to offer its customers. These options are now the new conditions of use or store conditions of use 519. For automatic processing, the electronic digital content store 103 configures a set of default purchase options that are provided to all content 113. These default options are automatically checked with reference to the allowable use condition 517 defined by the content provider 101 and set in the offer SC 641 if there is no difference.
Once the offer SC 641 is generated, the offer SC 641 is stored in an offer database 181 and indexed by the product ID pre-allocated in the metadata SC 620. Later, when interfacing with the quotation database 181 and retrieving the quotation SC 641 for packaging and sending to the end user, the electronic digital content store 103 uses this product ID to identify the downloadable content 113 purchased by the customer. For more detailed information, please refer to the transaction processor module Chapter 175.
In another embodiment, the electronic digital content store 103 hosts content SC641 on its site. This embodiment requires changing the offer SC 641, for example, replacing the URL of the content hosting site 111 with the URL of the electronic digital content store 103.
3. The transaction processing module 175, the electronic digital content store 103, transmits the bill to the authentication center 105. Optionally, the electronic digital content store 103 may directly request the certification center 105 for financial settlement. There are two basic ways to process the end user's purchase request for the downloadable content 113. If the electronic digital content store 103 does not want to handle the financial settlement of purchases, has no special promotions or incentives to guide the sale of goods, and does not use a shopping cart as a metaphor for batch combination purchase requests, the store can choose to provide direct access to its content 113 download page. A link to the SC 641 file for the offer. These quotations SC 641 should have been established using the retail price information contained in the metadata. Quotation SC 641 also contains a dedicated HTML quotation page that provides terms and conditions of sale for purchase options. This page is created based on a generated template when creating the offer SC 641. When the end user clicks on the direct link of the offer SC 641, the offer SC 641 is to the browser end user device, thereby launching a help application that opens the container and displays the page contained in the offer SC 641. This page contains a form that collects customer information including credit card information and purchase option selections. The form is then directly submitted to the certification center 105 for financial settlement and processing. Optionally, this form can contain fields required to use end-user credit investigation reports or industry standard local transaction processors.
An embodiment of the electronic digital content store 103 processing bills will now be described. A more typical way of processing purchase requests is to allow the electronic digital content store 103 to process financial settlements and provide end users with download authorization. This method allows the electronic digital content store 103 to integrate the sale of downloadable content 113 with other products offered for sale on its site, by charging customers only a flat fee (through a shopping cart metaphor) rather than individually for each download request Charging allows batch processing of purchase requests, and allows the electronic digital content store 103 to directly track the purchase types of its customers and provide special promotions and club options. In this case, the downloadable content 113 offer is included in its shopping list, where the shopping list is added to the shopping cart when the end user makes a selection and is obtained as in the current shopping model of the electronic digital content store 103 Processing and financial settlement. Once the financial settlement is completed, the business process of the electronic digital content store calls the transaction processor module 175 to complete the transaction.
Transaction processor module 175 The role of transaction processor module 175 is to collect information required by the end user device 109 in order to start and process the download of the purchased content 113. This information is encapsulated in a transaction SC 640, and the transaction SC 640 is sent back to the end user device 109 by the web server in response to the submitted purchase. The transaction processor module 175 needs to obtain three sets of information from the business process of the electronic digital content store 103: the product ID of the purchased content 113, the transaction data 642, and an HTML page or CGI URL for confirming purchase settlement.
The product ID is a numerical value provided to the electronic digital content store 103 through the metadata SC 620 related to the content 113 that has just been sold. This product ID is used to retrieve the relevant quotation SC 641 from the quotation database 181.
The transaction data 642 is a structure composed of information provided by the transaction processing function of the electronic digital content store 103. This information is later used to associate the processing of the authentication center 105 with the financial settlement transaction performed by the electronic digital content store 103 and provide users with Identity information, where the user identity information is included in the watermark of the content 113 downloaded to the end user device 109. When the certification center 105 receives a valid subscription SC 650, the certification center 105 records a transaction indicating the content 113 sold by the electronic digital content store 103 and related transaction data 642 including the end user name and a transaction ID 535. Transaction ID 535 provides an index for financial settlement transactions. This information is later returned by the certification authority 105 to the electronic digital content store 103 to be used to check its accounts and the billing statement received from the content provider 101 (or its agent). The authentication center transaction record 178 can be used by the content provider 101 to determine which content 113 has been sold and to allow it to generate a bill for each electronic digital content store 103 that records the commission that belongs to it. Optionally, other electronic means other than billing can also be used to check out between the content provider 101 and the electronic digital content store 103.
The information provided in the transaction SC 640 and the security and integrity of the transaction SC 640 provide the certification authority 105 with sufficient authenticity to make the certification authority 105 believe that the purchase transaction is valid and does not require further verification before the certification authority 105 records the sale . However, the electronic digital content store 103 has the right to choose to request authentication before its account is charged (the transaction recorded on the authentication center 105 indicates to the content provider 101 that the electronic digital content store 103 has received the payment for selling the content 113). This authentication/notification request is indicated by a flag in the transaction data 642. In this context, the authentication center 105 contacts the electronic digital content store 103 and receives authorization from the electronic digital content store 103 before charging its account and issuing the encryption key 623. As part of this authentication request, the transaction ID 535 is passed from the authentication center 105 to the electronic digital content store 103 to allow the electronic digital content store 103 to associate this request with a transaction previously performed with the end user. This transaction ID 535 can be any unique value that the electronic digital content store 103 wants to use and serves solely for its benefit.
The transaction data 642 also contains a user name. This name can come from the user name field of the purchase form filled in by the user when making a purchase, or from information previously recorded when some users register in the electronic digital content store 103, or based on the credit card used in this transaction. The official name obtained from the credit card information. This name is included in the license watermark 527 later.
The transaction data 642 also contains the store usage conditions 519 purchased by the end user. This information is contained in the license watermark 527 and used by the end user device 109 for copy and playback control.
The final parameter required by the transaction processor module 175 is an HTML page or CGI URL for confirming purchase settlement. The purpose of this is to allow the electronic digital content store 103 to answer the end user with a financial settlement confirmation and any other information the store wishes to include. This HTML page or CGI URL is included in the transaction SC 640 and displayed in the browser window of the end user device 109 when the transaction SC 640 is received and processed.
Transaction SC 640 is an HTTP response from the electronic digital content store 103 to the end user after processing the purchase application. Sending an SC pin as a direct HTTP response forces an SC processor help application to be automatically loaded on the end user device 109, thereby allowing the transaction to be automatically completed without relying on further actions initiated by the end user. This process is described in more detail in the End User Device 109 and Player Application 195 chapters later.
When the transaction processor module 175 is called with necessary parameters, the module creates a reference URL containing transaction data 642, a transaction confirmation HTML page or the required SC, and retrieves and embeds the purchase-related offer SC 641. The module also records information about this transaction for later use by the notification interface module 176 and the account reconciliation tool 179.
4. Notification interface module 176 The notification interface module 176 is an executable program on the Web server side (CGI or function that can be called by NSAPI, ISAPI or equivalent interfaces). This module processes optional requests and notifications from the certification center 105, the end user device 109, the content hosting site 111, and the content provider 101. The circumstances under which the electronic digital content store 103 can request notification include: Notifying the end user device 109 from the certification center 105 that an encryption key 623 has been requested and the certification center 105 is issuing an encryption key 623 for the specified content 113. Optionally, this notification can be configured to require authentication by the electronic digital content store 103 before the encryption key 623 is sent to the end user device 109.
Notify from the content hosting site 111 that the content SC 630 has been sent to the end user device 109.
Notify from the end user device 109 that the content SC 630 and the license SC 660 have been received and successfully used to process the content 113 or are found to be corrupted.
Notify from the content provider 101 that the new content 113 has been placed in the content promotion website 156.
None of these notifications are required steps in the secure digital content electronic distribution system process 100, but these notifications are provided as options to allow the electronic digital content store 103 the opportunity to close its records when there is no objection to the completion of the sale. By letting the electronic digital content store 103 know what function has been performed since the financial settlement of the transaction or what error has occurred during an attempt to complete the sale, it also provides information that may be needed to process customer service requests. Optionally, most of this status can be obtained from the certification center 105 through the customer service interface 184 when needed.
The content provider 101 determines how often to notify that new content 113 is available on the content promotion website 156. The notification may be provided when each new metadata SC 620 is added, or it may be provided only daily when all the new metadata SC 620 are added on that day.
All these notifications result in the entry of transaction records 178. If the electronic digital content store 103 wants to perform its own processing on these notifications, it can intercept the CGI call, perform its unique function, and selectively transmit the request to the notification interface module 176.
5. Account verification tool 179 This account verification tool 179 contacts the certification center 105 to compare the transaction record 178 with the certification center 105 record. This is an optional process that can be used to help the electronic digital content store 103 feel satisfied with the accounting of the secure digital content electronic distribution system 100.
In another embodiment, this tool can be updated to provide content provider 101 and certification authority 105 with electronic funds transfers for automatic periodic payments. It can also be designed such that if an electronic bill is received from the certification center 105, the payment will be automatically processed after checking the bill and transaction records.
C. Broadcasting Electronic Digital Content Distribution Service Broadcasting mainly refers to a one-to-many transmission method, in which there is no personal interaction between the end-user device 109 and the electronic digital content store 103 for customizing on-demand viewing and listening. Broadcasting is usually provided via digital satellite or cable infrastructure, where the content 113 is pre-programmed so that all end user devices 109 receive the same data stream.
A hybrid model can also be defined so that the electronic digital content store 103 provides digital content services organized in a certain way, that is, the electronic digital content store 103 provides a Web distribution interface through an international Internet connection and a high-bandwidth satellite or provides a cable through a broadcast service. Distribution interface, which has a lot of commonality in site design. If the IRD backchannel serial interface is connected to the Web and the IRD supports Web navigation, the end user can browse the digital content service through the backup information Internet interface in the usual way, preview and select the content 113 to be purchased. The user can select high-quality downloadable content 113 entirely through an Internet connection, purchase these selected commodities and receive the required license SC 660, and then request the delivery of the content 113 (content SC 630) through the high-bandwidth broadcast interface. The web service can indicate which content 113 can be downloaded in this way according to the broadcast schedule, or it can also establish a broadcast data stream entirely based on the purchased content 113. This method will allow a web-based digital content service to contract with a broadcasting facility to deliver high-quality content 113 to users equipped with appropriate equipment, so that a limited number of specific content 113 (such as songs or CDS) can be downloaded in this way every day and The entire catalog can be downloaded at a lower quality via the web interface.
Other broadcast models can be designed, in which there is no web interface for the end user device 109. In this model, promotional content is packaged in a specially formatted digital stream for broadcast delivery to the end user device 109 (ie, IRD), where special processing is performed to decode the digital stream and provide end users with purchase options. Promotional content.
The actual purchase selection is still initiated through the backup channel communication from the end user device 109 to the authentication center 105, and all data exchanges will be performed using the SC. The toolkit provided to the electronic digital content store 103 has been constructed and developed in such a way that most of the tools are suitable for point-to-point Internet service provision and broadcast satellite or cable provision. The tools used by the digital content website electronic digital content store 103 to acquire and manage the content 113 and prepare the SC are also used by the on-board electronic digital content store 103 to manage and prepare the content 113 distributed through the broadcasting infrastructure. The SC distribution through the Web service is the same as the distribution through the broadcast service.
X. End-user equipment 109 The application in the end-user equipment 109 of the secure digital content electronic distribution system 100 performs two main functions: the first function is SC processing and copy control; the second function is to replay encrypted content 113. Regardless of whether the end user device 109 is a personal computer or a dedicated electronic user device, the device must be able to perform these basic functions. The end-user device 109 also provides various additional features and functions, such as creating playlists, managing digital content libraries, displaying information and images during content playback, and recording to external media devices. These functions will change according to the services supported by these applications and the type of devices for which the applications are designed.
A. Overview Reference is now made to Figure 10, which shows the main components, processing and functional flow of the end user equipment 109. The application program used to support the PC-based Web interface content 113 service is composed of two executable software applications: the SC processor 192 and the player application 195. The SC processor 192 is an executable application program, which is configured as a helper application program in the end user Web browser 191 to process the SC file/MIME type. The browser launches this application every time the SC is received from the electronic digital content store 103, the certification center 105 and the content hosting site 111. The application is responsible for performing all necessary processing on the SC and finally adding the content 113 to the end user's digital content library 196.
The player application 195 is an independent executable application that the end user loads to use the content 113 in the digital content library 196, manages the digital content library 196, and generates a copy of the content 113 when permitted. The player application 195 and the SC processor 192 application can be written through Java, C/C++ or any equivalent software. In the preferred embodiment, the application can be downloaded from a computer-readable device such as a Web site. However, other delivery mechanisms can also be used, such as delivery via a computer readable medium such as a diskette or CDS.
The end-user Web browser 191 realizes searching and browsing of content 113 information, preview of song selection and selection of songs to be purchased. The electronic digital content store 103 provides the shopping experience in the same way as many content 113 retailer Web sites currently provide. The change brought to end users through today's web-based content 113 purchase is that they can now select downloadable content 113 objects and add them to their shopping carts. If the electronic digital content store 103 has other merchandise that can be sold in addition to downloadable objects, the end user may have a mixture of physical merchandise and electronic downloadable merchandise in his shopping cart. Until the end user completes the inspection and submits his final purchase authorization to the electronic digital content store 103, the end user device 109 for electronic distribution of secure digital content is not involved. Prior to this, all interactions were performed between the web server of the electronic digital content store 103 and the browser 191 on the end user device 109. This includes previews of excerpts from sample digital content. The digital content excerpts are not encapsulated in the SC, but are integrated into the Web service of the electronic digital content store 103 as downloadable files, or delivered from a streaming server. The format of the content 113 excerpt is not restricted by the system architecture. In another embodiment, the player application 195 can directly interact with the electronic digital content store 103 or the certification center 105, or a promotional CD can be used offline.
B. Application installation The player application 195 and the help application 1981 are packaged into a self-installing executable program that can be downloaded from many Web sites. The certification authority 105 acts as a central unit that hosts the main download page on the public Web site. It contains a link to a location from which the installation package can be downloaded. Installation packages are available on all content hosting sites 111 to accommodate geographically dispersed download requests. Each electronic digital content store 103 participating in the sale may also allow downloading of the program package from its site, or only provide a link to the main download page on the public Web site of the certification center 105.
Any end user who wishes to purchase the downloadable content 113 downloads and installs this package. The installer is self-contained in this downloadable package. The program package is disassembled, the help application 198 and the player application 195 are installed, and the help application 198 is configured to the installed browser.
As part of the installation, a public/private key 661 pair for processing the subscription and license SC 660 is generated for the end user device 109. A random symmetric key (secret user key) for protecting the encryption key of the song in the license database 197 is also generated. The secret user key (not shown) is protected by splitting and embedding the key into multiple segments and storing the key segments in multiple locations throughout the end user's computer. Use anti-tampering software technology to protect this program code to avoid revealing information about how to split the key and where it is stored. Preventing end users from accessing this key helps prevent piracy or sharing of content 113 with other computers. For more information on how to use these keys, see Chapter 192 of the SC Processor.
Anti-tampering software technology is a method to prevent hackers from unauthorized access to computer software applications. Often hackers want to understand and/or modify software to remove restrictions on use. In fact, there is no computer program that cannot be cracked; this is why anti-tampering software is not called "untamperable". However, the amount of work required to crack an application with tamper-proof protection usually prevents most hackers due to the inconsistency of the effort and the possible benefits. The cracking job here will be to gain access to a piece of content 113, perhaps the key to a single track on the CD.
IBM has an anti-tampering software technology. One product that introduced this code is located on the IBM ThinkPad 770 portable computer. Here, anti-tampering software is used to protect the DVD movie player in the computer. Digital content providers such as Hollywood Studios are worried about the advent of digital movies and the ability to easily produce perfect copies, so they insist that movies on DVD discs include a copy protection mechanism. IBM's tamper-proof software makes it difficult to bypass these copy protection mechanisms. There is a very typical application of anti-tampering software; this software is used to enforce rules regarding the use of certain protected types of content 113.
IBM's anti-tampering software places several obstacles in the path of attackers. First, the software contains techniques to eliminate, or at least reduce the effects of standard software used by hackers such as debuggers and disassemblers. Secondly, the software includes self-integrity checks, so that single modifications or even small batches of modifications will be detected and will lead to incorrect operations. In the end, the software contains a puzzle that misleads hackers in terms of its true operation. The last technique is heavily used, while the first two techniques rely on well-known cryptographic tools: encryption and digital signatures.
C. The secure container processor 192 When the end user submits the final purchase authorization to the electronic digital content store 103 for the goods collected in the shopping cart, his web browser still continues to wait for a response from the web server. The web server on the electronic digital content store 103 processes the purchase, performs financial settlement and returns a transaction SC 640 to the end user device 109. The SC processor 192 (help application 198) is activated by the browser to process the SC MIME type associated with the transaction SC 640. FIG. 14 is an example of the user interface screen of the player application 195 that downloads content to a local library as described in FIG. 10 based on the present invention.
The SC processor 192 opens the transaction SC 640 and extracts the response HTML page and the offer SC 641 contained therein. The response HTML page is displayed in the browser window confirming the end user's purchase. Then the offer SC 641 is opened and the content 113 (such as a song or album) name and scheduled download time are extracted from it, step 1401. Then use this information to display a new window and provide the end user with an option to schedule the download of the content 113 (song or all albums in the case of music), step 1402. The end user can choose to download it immediately or later. If you choose to download later, the download scheduling information is stored in a record and the download starts at the scheduled time if the end user device 109 has been activated at that time. If the computer is not turned on at the scheduled download time or the communication link is unavailable, the end user is prompted to reschedule the download when the computer is turned on next time.
When the scheduled download time is reached or an immediate download is requested, the SC processor 192 generates an order SC 650 based on the information in the transaction SC 640, the offer SC 641 and the public key 661 generated by the end user during installation. This order SC 650 is sent to the certification center 105 via an HTTP request. When the certification center 105 returns the license SC 660, the help application 198 is called again to process the license SC 660. Then open the license SC 660 and extract the URL of the content hosting site 111 from the referenced subscription SC 650. Then, a browser is used to send the license SC 660 to the designated content hosting site 111 through an http request to request to download the content SC 630. When the content SC 630 returns to the browser, the help application 198 is called again. The SC processor 192 displays the name of the downloaded content 113, a download progress indicator, and an estimated completion time.
When the content 113 is being received by the SC processor 192, the processor loads the content 113 data into the memory buffer for decryption. The length of the buffer depends on the requirements of the encryption algorithm and watermarking technology, and the length is the smallest possible length in order to reduce the amount of unencrypted content 113 exposed to the hacker program. When a buffer is filled, the end user key 623 (corresponding to the public key 661) extracted from the license SC 660 is used to decrypt the buffer, where the private key is first used to decrypt the license SC 660 itself. The decryption buffer is then passed to the watermark function.
The watermark function 193 extracts the watermark instruction from the license SC 660 and decrypts the instruction using the end user's private key. Then extract the watermark data from the license SC 660, where the watermark data contains information such as those registered on the electronic digital content store 103 from which the content 113 was purchased, or according to the credit card registration information when the electronic digital content store 103 does not provide the registration function The exported transaction information of the buyer's name. The watermark also contains the purchase date and transaction ID 535, and the electronic digital content store 103 assigns the transaction ID 535 to index to the specific record recorded for the transaction. The store usage conditions 519 are also included in order to be used for copy control of the player application 195.
Use anti-tampering code technology to protect the watermark to avoid leaking watermark instructions, thereby preventing hackers from discovering the location and technology of the watermark. This will prevent hackers from removing or modifying the watermark.
After recording all required watermarks into this content buffer, the buffer is passed to the scrambling function for re-encryption 194. A processor-efficient secure encryption algorithm such as IBM SEAL encryption technology is used to re-encrypt the content 113 with a random symmetric key. Once the download is complete, the decryption and re-encryption 194 process, the encryption key used by the content provider 101 to initially encrypt the content 113 is destroyed, and the new seal is encrypted using the secret user key that was generated and hidden during installation Key encryption. This newly encrypted Seal key is stored in the license database 107.
It may be necessary that the different content sources used on the content provider 101 and the user watermark used on the end user device 109 become de facto industry standards. These standards are still evolving. You can use this technology to embed control information into music and update the control information multiple times. Until the copy control standard becomes more fixed, an optional method of copy control will not be provided in the secure digital content electronic distribution system 100, so that copyright management is provided in the user equipment without relying on the copy control watermark. The security of storage and playback/recording usage conditions is realized by using encrypted DC library collections that are bound to the end user equipment 109 and protected from tampering and environmental protection. When the standard has been adopted, software hooks are placed to support copy control watermarks. Currently, there is support for watermarking AAC and other encoded audio data streams with various compression levels, but these technologies are still somewhat immature in terms of being used as an independent copy control method.
The decryption and re-encryption 194 process is another tamper-proof code technology to avoid leaking the original content 113 encryption key, new SEAL key, secret user key, storage location of secret user key fragments, and key segmentation method Program area.
The process of decryption and re-encryption 194 serves two purposes. Storing content 113 encrypted with an algorithm similar to SEAL allows for faster decryption than real-time and the processor usage required to perform the decryption is less than that of a more industry standard type algorithm similar to DES. This allows the player application 195 to perform real-time concurrent decryption-decoding-playback of the content 113 without first having to decrypt the entire content 113 file before decoding and playback. The efficiency of the SEAL algorithm and an efficient decoding algorithm not only allows parallel operation (multiple playback of encrypted files) but also allows this processing to be performed on a system processor with very low power consumption. Therefore, this application can be supported on low-end end-user devices 109 such as 60MHz Pentium systems or lower-end systems. Separating the encryption format of the stored content 113 from the initial encryption format allows greater flexibility in selecting the original content encryption algorithm. Therefore, it is possible to use an algorithm that is widely accepted and that has been shown to be an industry standard to further improve the acceptance of the secure digital content electronic distribution system 100 in the digital content industry.
The second purpose of this decryption and re-encryption 194 process is to eliminate the storage of the initial master encryption key used by the content provider 101 to encrypt the content 113 on each end-user device 109 that has been licensed for the content 113. 623 requirements. The encryption master key 623, which is part of the license SC 660, is only buffered on the hard disk of the end user device 109 in a short period of time, and only in memory and is not suspected for a short period of time. In this execution phase, the key 623 is protected by tamper-proof code technology. Once the decryption and re-encryption 194 stage is completed, there is no need to keep the key 623 on the end user device 109 in any form, thereby greatly reducing the possibility of hacker piracy.
Once the song is re-encrypted, the song is stored in the digital content library 196. All metadata required for the use of the player application 195 is extracted from the relevant offer SC 641 and stored in the digital content library 196, step 1403. Decrypt and re-encrypt any encrypted fragments of metadata such as song lyrics in the same manner as described above for other content. The same SEAL key used to encrypt content 113 is used for any related metadata that needs to be encrypted.
D. Player application 1951. Overview Secure digital content electronic distribution The player application 195 (herein referred to as the player application 195) is similar to CD, DVD or other digital content players and CD, DVD. Or other digital content storage management systems. The simplest is to only process the content 113, such as playing a song or video. At another level, the application provides the end user with a tool to manage his/her digital content library 196. The most important thing is to be able to edit and play content collections such as songs (here called playlists).
The player application 195 is assembled through a set of components that can be selected and customized according to the requirements of the content provider 101 and the electronic digital content store 103, respectively. A general version of the player is described here, but it can also be customized.
Referring now to FIG. 15, there is shown a block diagram of the main components and processing of running the player application 195 on the end user device 109 of FIG. 10.
There are several component groups that constitute the subsystem of the player object manager 1501.
1. End user interface component 15092. Copy/play management component 15043. Decrypt 1505, decompress 1506, replay component 1507 and may contain recording.
4. Data management 1502 and library access components 15035. Communication components between applications 15086. Other miscellaneous (installation components, etc.) components can be selected from these component groups according to the following requirements: Platform (Windows, UNIX) Operating system, or similar operating system) communication protocol (network, cable, etc.) content provider 101 or electronic digital content store 103 hardware (CD, DVD, etc.) certification center 105 technology and so on.
The following sections describe each component group in detail. The last chapter describes in detail how to combine these components into a universal player and discusses how the components can be customized.
In another embodiment, the components of the player application 195 and the SC processor 192 may be part of a programmer's software toolkit. This kit allows for predetermined interfaces to the components of the aforementioned universal player application. These predetermined interfaces have the form of APIs or application programming interfaces. A developer using these APIs can implement any function of a component of a high-level application. By providing APIs for these components, a programmer can quickly develop a dedicated player application 195 without the need to regenerate these functions and the resources of any components.
2. End user interface component 1509 The components in this component group jointly provide the screen display of the player application 195. Note that the design does not impose any restrictions on the configuration of these components. One such configuration is provided in the universal player. According to the requirements of the content provider 101 and/or the electronic digital content store and other requirements, other configurations can be selected.
Starting with the components used to provide the end user display 1510 and processing control called the end user control 1511, this group of components is combined into a subset, where the end user control 1511 is used for low-level tasks such as audio playback and metadata display Features. Secondly, the end user display part 1510 is further divided into special function combinations (playlist, digital content library), and object container parts used to combine and place those low-level parts.
In the following components, the only reference to generating a CDS or copying the content 113 to a CD or other recordable medium is only applicable when the player application 195 allows this function. It should also be noted that the term CD is a general term in this case, and can also refer to various other external recording devices, such as compact discs or DVDs.
Fig. 16 is an example of a user interface screen of the player application 195 of Fig. 15 based on the present invention. The functions of the end user control 1511 include (the corresponding screen of an end user interface is shown in 1601-1605): execute the control of content 113: play/stop button play button stop button pause button fast forward button fast reverse Button Volume control Track position control/display
Audio channel volume level display and so on.
Control to display metadata related to content 113 Cover picture button Cover picture object Artist picture button Artist picture object Track list button Track list information object Track list selector object (click to play) Sound Track name object Track information object Track lyrics button Track lyrics object Track artist name object Track subtitle button Track subtitle object CD name object CD producer list button CD producer list object Universal (configurable) metadata buttons Universal metadata objects, etc.
The functions of the end user display 1510 include (the corresponding screen of an end user interface is shown in 1601-1605): display the play list of the container play list management button play list management window digital content search button digital content search definition object number Content search submit button Digital content search result object
Copy selected search result items to play list button play list object (editable) play list save button play list play button play list pause button play list restart button generate CD from play list button and so on.
Display of digital content library 196 Digital content library button Digital content library management program window Digital content type button Digital content type button Follow artist button Follow genre button Follow trademark button Follow category button Delete button Add to play Directory button Copy to CD button Song directory object Song directory display container, etc. containers and miscellaneous items Player window container Audio control container Metadata control container Metadata display container Toolbar container object Sampling button
Download button Purchase button Recording button Player name object Trademark/Provider/Store advertisement object Trademark/Provider/Store URL button Artist URL button, etc. 3. Copy/play management component 1504 This component handles encryption Key, watermark processing, copy management, etc. settings. There is also an interface for communication with the authentication center 105 and transmission of purchase requests, such as pay-per-view or special services such as billing for each access to the content 113. Currently, the SC processor 192 handles the function of communicating with the certification center 105.
The use of the content 113 by the player application 195 on the end user 109 is recorded in a database such as the license database 197. Tracking of the use of each content 113 by the player application 195 can be sent to one or more records such as certification center 105, content provider 101, electronic digital content store 103 or any site designated and connected to transmission infrastructure 107 Site. This transmission can be scheduled at a predetermined time to upload usage information to a recording site. It is possible to consider the early morning as a predetermined time, during which time the network traffic of the transmission infrastructure 107 is not too crowded. The player application 195 wakes up at a predetermined time using a known technique and sends information from the local recording database to the recording site. By checking the information of the recording site, the content provider 101 can measure the popularity of its content 113.
In another embodiment, the way of recording the use of the content 113 for later uploading to a recording site is replaced by uploading the use of the content 113 to the recording site during each use of the content 113. For example, when copying or copying the content 113 stored on the end user 109 to an external device such as a DVD disc, digital tape, flash memory, mini disc or equivalent read/write removable medium, the content The use of 113 was updated to the recording site. This may be a precondition for copying the content 113 defined in the usage conditions 206, where the aforementioned usage conditions 206 are sent when the content 113 is purchased. This ensures that the content provider 101 can accurately track the use of the content 113 during the playing, copying, or completion of other actions on the content 113.
In addition, the information of other contents 113 may be uploaded to the recording site. For example, the last time the content 113 was executed (for example, hours and days); how many times the content 113 was executed; whether the content 113 was copied or copied to an authorized external device such as a DVD disc, digital tape or mini disc. In the case where a single player application 195 of the end user device 109 has multiple different users such as different members of a family, the user identification of the content 113 and usage information are sent to the recording site together. By checking the usage information uploaded to the recording site, the content provider 101 can measure the popularity of the content 113 based on the actual usage, the user's identification, and the number of times the content 113 has been executed. Actual usage measurement makes this system closer to the truth than systems that use sampling methods such as Nielsen TV or telephone survey rating schemes that only sample a limited number of users at any one time to infer the results. In this embodiment, the actual usage may be the measurement of users who later log on to a designated Web site such as the electronic digital content store 103 or the content provider 101.
4. Decrypt 1505, decompress 1506 and playback component 1506. These components use the key obtained by the copy/play management component to open the audio data obtained from the data management and library access component, perform appropriate decompression for playback and use the system The audio service plays the data. In an alternative embodiment, the audio data obtained from the data management and library access components can be copied to removable media such as CDS, magnetic disks, tapes or mini-discs.
5. Data management 1502 and library access component 1503 These components are used to store and retrieve processing on various storage devices of the end user and process requests for stored song information.
6. Communication components between applications 1508 These components are used to secure digital content electronic distribution players and other applications that may call the player application 195, or the player application 195 needs to use when performing its functions (e.g. Browsers, help applications and/or plug-ins, etc.). For example, when a URL control is activated, the control invokes the appropriate browser and instructs the browser to load the appropriate page.
7. Other miscellaneous components are combined here to combine individual components that do not belong to the above categories (such as installation programs).
8. Universal player In this chapter, we discuss how to combine the above components into a player application 195 version. Since the player application 195 is designed as a dedicated application based on software objects, the example described in this section is only one of many possible different examples. The player object manager 1501 is a software framework that gathers all other components together. As mentioned in the above chapters, the modules under the player object manager 1501 in this illustration are required by all players, but based on such factors as the encryption or scrambling form used, the type of audio compression, the access method of the content 113 library, etc. Factors can be replaced by dedicated versions.
The aforementioned player object manager 1501 is a variable object 1512, which is mainly derived based on metadata related to the content 113 being played or searched for. The end user device 109 can use these variable objects through the end user display 1510 and input received from the end user control 1511. All objects are configurable, and the layout of all containers is customizable. It is possible to implement these objects through C/C++, Java or any equivalent programming language.
Using the player application 195 The following embodiment is an example where the player application 195 running on the end user device 109 is an audio player, and the content 113 is music. Those skilled in the art should understand that the player application 195 can support other types of content 113. A typical audio enthusiast has a CDS library of songs. All of this can be achieved within the secure digital content electronic distribution system 100. Albums purchased from the electronic digital content store 103 are stored in a digital content library 196 on its system. The song group similar to the physical CDS is stored as a playlist. In some cases, a play catalog actually simulates a CD (for example, all the audio tracks of the CD are purchased from an electronic digital content store 103 in the form of an online version of the CD that can be purchased, and these audio tracks are defined as a CD equivalent A playlist of audio tracks. But most playlists are constructed by end users to combine the songs they store in their digital content library on their system. But for the sake of discussion, use an example of a custom music CD when referring to the term playlist.
When the end user explicitly launches the player application 195 instead of launching the player application 195 through the call of the SC processor 192 application, the player application 195 is preloaded to the recently accessed play directory. If there is no play list in the digital content library 196, the play list editor is automatically started (unless the user has blocked this function through a priority setting). See the following playlist for details.
When the player application 195 is called, a specific song can also be used as an entry parameter, and in this case, the player application 195 immediately enters the song playing mode. Optionally, you can prepare to play the song, but you need to wait for the end user's action before playing. For more information about this situation, see Song Play.
Playlist (a corresponding screen of the end user interface 1603): When the end user calls the playlist function, there are several available functions: *Open the playlist* Call the digital content library management program to display a set of stored playlists for selection. For more information, see the digital content library management program below.
*Edit playlist* Call the playlist editor (see below), if a playlist has been loaded, load the current playlist. Otherwise, the editor generates an empty playlist for starting.
*Run the playlist*Play one song at a time from the selected song (or from the beginning of the playlist when no song is selected). The option settings in the playlist editor affect the order of playback. However, there are controls that can ignore those options for the playback of the playlist.
*Play songs* Only the songs selected from the playlist are played. See song playback for more information.
*Playlist information*Display information about the playlist *Song information*Display information about the song selected in the playlist.
*Visit the website
* Load the Web site related to this playlist into the browser.
*Library management program* Open the digital content library management program window. For more information, see the digital content library management program below. Playlist editor (a screen corresponding to the end user interface 1603): When calling the playlist editor, there are the following end user options: *View/load/delete playlists *Call the digital content library management program to display a set of stored plays Directory in order to select a playlist to be loaded or deleted. For more information, see the digital content library management program below.
*Save the playlist* The current version of the playlist is stored in the digital content library 196.
*Delete Song* Delete the currently selected song from the playlist.
*Add a song* In the song search mode, call the digital content library management program to select the song to be added to the playlist. See also the digital content library management program below for more information.
*Set song information* Display and allow to change the information about the selected song in the playlist. This information is stored in the play list and does not change the information about the songs stored inside the digital content library 196. The following content can be changed: *Displayed song title*End user's comment on the song*Start delay of playing song*End delay of playing song*Start point inside the song during playback*End point inside the song during playback*Random mode The weighting* song volume adjustment and more.
Set playlist attribute: display and allow to change the attribute of this playlist. These attributes can be set to: *Play list title *Play list mode (random, sequence, etc.) *Repeat mode (one-time play, restart at the end, etc.) *End user comment library management program for songs ( A screen corresponding to the end user interface 1601): *Open the digital content library management program window. See also the digital content library management program below for more information.
Playing a song When calling the player application 195 by taking a song as a parameter or selecting a song to be played from within a playlist or digital content library management program, when a song is ready to be played, the following end user options are available: (an end user Corresponding screen of interface 1601): *Play*Pause*Stop*Fast rewind*Fast forward*Adjust volume*Adjust track position*View lyrics*View subtitles*View CD cover*View artist drawings*View audio track information*View other elements Data*Access to Web site*Play catalog*Library management program and so on.
The digital content library management program can implicitly call the digital content library management program when selecting a song or play directory (see above), or it can open the digital content library management program in its own window for managing the song library on the end user system . In that case, there are the following end-user options: Options for songs: Sort all songs by artist, genre, trademark, and other content. Select songs by artist, genre, trademark, and other content. Add the selected songs to the current playlist. Copy songs to CD (if allowed), delete songs, add song types, etc.
Options for playlists: sort by name, sort by category, search for keywords, search for included song titles, load selected playlists, rename playlists, delete playlists, generate CDs based on the selected playlists (if allowed), etc.
Although a specific embodiment of the present invention has been disclosed, those skilled in the art will understand that this specific embodiment can be changed without departing from the spirit and scope of the present invention. Therefore, the scope of the present invention is not limited by the specific embodiments, and the appended claims attempt to cover any and all such applications, modifications and embodiments within the scope of the present invention.
35 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34 Sheet 35
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| CN107683581A | Cited by | China | Search report |
| US10225287B2 | Cited by | United States of America | Applicant |
| US10057293B2 | Cited by | United States of America | Applicant |
| CN104903909A | Cited by | China | Search report |
100 members in 13 offices
Priority claims10
| Document | Office | Kind | Date |
|---|---|---|---|
| 09133519 | United States of America | – | |
| 13351998 | United States of America | A | |
| 13351998 | United States of America | A | |
| 09177096 | United States of America | – | |
| 17709698 | United States of America | A | |
| 17709698 | United States of America | A | |
| 09133519 | – | – | – |
| 09177096 | – | – | – |
| US19980133519 | – | – | – |
| US19980177096 | – | – | – |
Members100
| Document | Office | Kind | |
|---|---|---|---|
| CA2338414A1 | Canada | A1 | |
| CA2467974A1 | Canada | A1 | |
| CA2467998A1 | Canada | A1 | |
| WO0008909A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU5481899A | Australia | A | |
| WO0008909A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP1077398A1 | European Patent Office (EPO) | A1 | |
| EP1085443A2 | European Patent Office (EPO) | A2 | |
| CN1289100A | China | A | |
| US6226618B1 | United States of America | B1 | |
| EP1104555A2 | European Patent Office (EPO) | A2 | |
| JP2001160003A | Japan | A | |
| KR20010050111A | Republic of Korea | A | |
| KR20010050381A | Republic of Korea | A | |
| US6263313B1 | United States of America | B1 | |
| TW454132B | Taiwan Province of China | B | |
| CN1320232A | China | A | |
| IL137880D0 | Israel | D0 | |
| US2002002468A1 | United States of America | A1 | |
| US6345256B1 | United States of America | B1 | |
| IL140935D0 | Israel | D0 | |
| US6389403B1 | United States of America | B1 | |
| US6389538B1 | United States of America | B1 | |
| US6398245B1 | United States of America | B1 | |
| US6418421B1 | United States of America | B1 | |
| JP2002522995A | Japan | A | |
| US2002107803A1 | United States of America | A1 | |
| KR100374524B1 | Republic of Korea | B1 | |
| WO03019553A1 | World Intellectual Property Organization (WIPO) | A1 | |
| TW530267B | Taiwan Province of China | B | |
| US6574609B1 | United States of America | B1 | |
| US2003105718A1 | United States of America | A1 | |
| US6587837B1 | United States of America | B1 | |
| AU763380B2 | Australia | B2 | |
| US6611812B2 | United States of America | B2 | |
| TW200304126A | Taiwan Province of China | A | |
| EP1421583A1 | European Patent Office (EPO) | A1 | |
| KR100444695B1 | Republic of Korea | B1 | |
| CN1163805CThis record | China | C | |
| TWI222057B | Taiwan Province of China | B | |
| EP1085443A3 | European Patent Office (EPO) | A3 | |
| JP2005501322A | Japan | A | |
| US6859791B1 | United States of America | B1 | |
| JP2005122708A | Japan | A | |
| JP2005122709A | Japan | A | |
| JP2005122710A | Japan | A | |
| JP2005124165A | Japan | A | |
| EP1421583B1 | European Patent Office (EPO) | B1 | |
| AT295989T | Austria | T | |
| ATE295989T1 | Austria | T1 | |
| DE60204227D1 | Germany | D1 | |
| US6959288B1 | United States of America | B1 | |
| US2005251491A1 | United States of America | A1 | |
| CN1703749A | China | A | |
| IL140935A | Israel | A | |
| US6983371B1 | United States of America | B1 | |
| DE60204227T2 | Germany | T2 | |
| US2006085343A1 | United States of America | A1 | |
| CA2467998C | Canada | C | |
| US2006089912A1 | United States of America | A1 | |
| US2006095792A1 | United States of America | A1 | |
| CA2338414C | Canada | C | |
| TWI255443B | Taiwan Province of China | B | |
| US7110984B1 | United States of America | B1 | |
| EP1077398B1 | European Patent Office (EPO) | B1 | |
| AT340379T | Austria | T | |
| ATE340379T1 | Austria | T1 | |
| DE60030814D1 | Germany | D1 | |
| SG130009A1 | Singapore | A1 | |
| US7206748B1 | United States of America | B1 | |
| US7228437B2 | United States of America | B2 | |
| US7269564B1 | United States of America | B1 | |
| DE60030814T2 | Germany | T2 | |
| CN100345157C | China | C | |
| US7346580B2 | United States of America | B2 | |
| JP4086825B2 | Japan | B2 | |
| US7383228B2 | United States of America | B2 | |
| JP4113865B2 | Japan | B2 | |
| CN100403325C | China | C | |
| US2008172747A1 | United States of America | A1 | |
| EP1085443B1 | European Patent Office (EPO) | B1 | |
| AT406622T | Austria | T | |
| ATE406622T1 | Austria | T1 | |
| DE60040041D1 | Germany | D1 | |
| JP4208803B2 | Japan | B2 | |
| JP4209592B2 | Japan | B2 | |
| US7487128B2 | United States of America | B2 | |
| US7590866B2 | United States of America | B2 | |
| JP4347508B2 | Japan | B2 | |
| US2010008500A1 | United States of America | A1 | |
| CA2467974C | Canada | C | |
| JP4549673B2 | Japan | B2 | |
| JP4565940B2 | Japan | B2 | |
| US7962413B2 | United States of America | B2 | |
| US7962750B1 | United States of America | B1 | |
| EP2400417A2 | European Patent Office (EPO) | A2 | |
| EP2402878A1 | European Patent Office (EPO) | A1 | |
| EP2400417A3 | European Patent Office (EPO) | A3 | |
| US8180708B2 | United States of America | B2 | |
| EP2400417B1 | European Patent Office (EPO) | B1 |
6 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Expiry of patent termCX01 | CX01 | |
| Succession or assignment of patent rightASS | ASS | |
| Transfer of patent application or patent right or utility modelC41 | C41 | |
| Grant of patent or utility modelGrantedC14 | C14 | |
| Entry into substantive examinationC10 | C10 | |
| PublicationC06 | C06 |
Numbers
- Publication
- 1163805
- Publication, DOCDB
- 1163805
- Publication, EPODOC
- CN1163805C
- Application
- 998108537
- Application, DOCDB
- 99810853
- Application, EPODOC
- CN19998010853
Titles2
- Chinese
- 跟踪最终用户电子内容使用的系统
- English
- System for tracking the use of electronic content by end users
Classification
- CPC, 19
- G06F21/10
- G06F2221/2135
- G06Q20/3674
- G06Q20/382
- G06Q20/3829
- G06Q30/0617
- G06Q30/0623
- G06Q30/0633
- H04L9/0822
- H04L9/0825
- H04L63/0428
- H04L2463/101
- H04L2463/102
- H04L69/329
- H04L2209/603
- H04W4/029
- H04W4/02
- H04L67/52
- G06F21/16
- IPC, 22
- G06F1 00
- G06F21 10
- G06F21 16
- G06F21 60
- G06F21 62
- G06F21 64
- G06Q20 36
- G06Q20 38
- G06Q30 06
- G09C1 00
- G10K15 02
- H03M7 30
- H04L9 08
- H04L9 10
- H04L29 06
- H04L29 08
- H04N7 167
- H04N7 173
- H04N21 2347
- H04N21 418
- H04W4 02
- H04W4 029