Method and system of encrypted data delivery
15 claims: 5 independent, 10 dependent
- 1Digital data delivery method for use in delivering digital data from an upstream system to a downstream system, said upstream system in question for a multi-point delivery encrypted Digital data is provided to specific destinations and wherein the downstream System decrypts the emitted digital data comprising the Verfahrungsschritte:encrypt ( 13 ) the digital data in the upstream system using an Encryption key, produce ( 18 ) Of a set of passkeys, which for the particular Goals are specific, on the basis of said encryption key, produce ( 20 ) Of a plurality of partial keys based on a Part of passkeys in said set or a portion of passkey information, from the pass key question may be reproduced, dispensing either said plurality of partial keys or the partial key information, from the said subkey can be reproduced, and discharging the remaining Passkeys, the for the production of the products mentioned keys are not used, or the rest Pass-Schlüsselinfor ?page 25? mation to each of said specific destinations over a plurality of delivery routes, which differ from routes distinguish the output of said digital data and further are different from each other, Delivering the encrypted Digital data, Restore ( 35B ) Of said Encryption key in the downstream system by reference to either of the above Plurality of partial keys or said subkey information and using either the remaining passkeys or the rest Passkey information, the above said plurality are released from delivery routes, and Zoom Drag ( 35A ) Of the restored encryption key to decryption encrypted Digital data.
- 4A signal processing method for use in conjunction with an upstream system that of a multi-point delivery encrypted Digital data to specific objectives towards providing, comprising the steps of:encrypt ( 13 ) of digital data in the upstream system by reference to an encryption key, produce ( 18 ) Of a set of passkeys that each of the said certain targets are specific, on the basis of the relevant encryption key, produce ( 20 ) Of a plurality of partial keys based on a Part of passkeys in said set or a portion of a passkey information, from the pass key question may be reproduced, Submit either the respective plurality of partial keys or partial key information, from which the partial key in question can be reproduced, and Dispensing the remaining, for the Generating said subkey not using passkeys or the other Pass-Schlüsselinfor mation to each of said specific destinations over a plurality of delivery routes, which differ from the routes for the delivery of said digital data and which are further different from each other, and dispensing encrypted Digital data.
- 7Digital data delivery system with an upstream System, which for a multipoint delivery of encrypted digital data to specific destinations is provided, and a downstream system that delivered the Digital data decrypted, in which said upstream system includes:an encryption element ( 13 ) For encrypting of digital data using an encryption key, a first key information generator ( 18 ) For generating a set of passkeys that for each said certain targets are specific, on the basis of said encryption key, a second key information generator ( 20 ) For generating a plurality of subkeys on the Basis of a part of the pass-key in said set or a portion of passkey information, from the pass key question may be reproduced, on Key information delivery element for delivering either said plurality of partial keys or the part of key information, from which the partial key in question can be reproduced, and for delivery of the remaining, not for the production of the products mentioned key used passkeys or the rest Passkey information to each of said specific destinations over a plurality of delivery routes, of the routes the delivery of said digital data are different and the further are different from each other, and a digital data output member to submit the encrypted Digital data, and said downstream system including: on Encryption key-recovery element ( 35B ) For restoring said encryption key under Recourse either said plurality of partial keys or said subkey information and by reference to either of the above remaining passkeys or said remaining passkey information, the above said plurality are released from delivery routes, and a decryption element ( 35A ) For decrypting encrypted Digital data under He ?page 26? ranziehung the restored encryption key.
- 10Pre Associated system for providing a Multipoint delivery of encrypted Digital data to specific destinations, comprising:an encryption element ( 13 ) For encrypting of digital data using an encryption key, a first key information generator ( 18 ) For generating a plurality of subkeys on the basis of a part of the pass-key in said set or a portion of a passkey information, from which the relevant passkeys can be reproduced, on Key information delivery element for delivering either said plurality of partial keys or the part of key information, from which the partial key in question can be reproduced, and for delivery of the remaining, for the Generating said subkey unused passkeys or the other Passkey information to each of said specific destinations over a plurality of delivery routes, which differ from the routes for distinguish the output of said digital data and each other are different, and a digital data delivery element for delivering encrypted Digital data.
- 13A storage medium storing a computer by means of a readable program for controlling the steps stores:encrypting Digital data using an encryption key, produce one for each of the specific objectives specific set of passkeys on the basis of said encryption key, produce a plurality of partial keys on the basis of a part of the pass-key in said set or a portion of a passkey information, from which the relevant passkeys can be reproduced, Outputting either of the respective plurality of partial keys or the part of key information, from which the partial key in question can be reproduced, and Dispensing the remaining, for the Generating said subkey unused passkeys or the other Passkey information to each of the respective specific destinations over a plurality of delivery routes, which differ from the routes for distinguish the output of said digital data and further are different from each other, and performing a multi-point delivery encrypted Digital data to the said specific objectives.
Independent claims5
223 paragraphs, as filed
The present invention relates to a secure delivery of encrypted Digital data.
The extraordinary Speed of today's digital technology has made it possible, all kinds of digital data Networks or transmit via storage media. Such data include character data (eg text, symbols and figures) Audio data (speech and music), Video data (still images and moving pictures), audio-video composite data (movies and broadcast programs), program data, database and other data, these data being referred to as content data, or simply as content will.
Some submitted Digital data can consist of a single data file; others can be prepared from a variety of Data files exist. Some such data files information contained, which consist of a single content; others can information included, which are formed by a plurality of contents. Each of these Content may be divided into a plurality of digital data.
It is not difficult to produce excellent copies of digital data. After once unauthorized copies are made (for example, by unauthorized decoding and playback, by illegitimate Multiplication or illegal diversion of products on the black market) can Copyright holders and others who, in the legitimate production Display or transmission involved the contents, a substantial economic injury o suffer of other damage. The concern regarding such unauthorized practices, the recent movement to the effect accelerated a framework to protect content providers (such as the content producer to build distributors and Transmitter). especially the opportunity the development of measures of prevent unauthorized copies, or to prevent this, is been explored to protect valuable content, their preparation enormous Cost and labor causes (such as movies).
In WO 00/59154 (Philips) is a method of transmitting encrypted Content material specified at a plurality of locations, at which the decrypted material is. Each target has a unique private key of key pair from a public key and a private key.
there create goals D1 to D4, the respective public key Y1 to Y4 (Yp) and the respective private keys y1 to y4 (yp), wherein <st32:df xmlns:st32="http://lighthouseip.com/">Yp = g<st32:sup>yp</st32:sup> mod n</st32:df>applies. Herein represent n a large Prime and g a n Grundmod.
The public key Yp are transmitted to a source, the a "session key" <st32:df xmlns:st32="http://lighthouseip.com/">K = (Y1 × Y2 Y3 × × Y4)<st32:sup>x</st32:sup> mod n</st32:df>generated.
In the case where x is the private key of the source generates, the source is a public group key <st32:df xmlns:st32="http://lighthouseip.com/">X = g<st32:sup>x</st32:sup> mod n</st32:df>and Subkey X1, X2, X3, X4 (Xp), wherein <st32:df xmlns:st32="http://lighthouseip.com/">X1 = (Y2 Y3 × × Y4)<st32:sup>x</st32:sup> mod n</st32:df><st32:df xmlns:st32="http://lighthouseip.com/">X2 = (Y1 × × Y3 Y4)<st32:sup>x</st32:sup> mod n</st32:df><st32:df xmlns:st32="http://lighthouseip.com/">X3 = (Y1 × Y2 × Y4)<st32:sup>x</st32:sup> mod n</st32:df><st32:df xmlns:st32="http://lighthouseip.com/">X4 = (Y1 × Y2 Y3 ×)<st32:sup>x</st32:sup> mod n</st32:df>applies.
On Target Dp receives the encrypted Material by reference to the session key K, the public group key X of the source and the partial key Xp, the for is that destination is uniquely encrypted. The session key K is the target p as <st32:df xmlns:st32="http://lighthouseip.com/">Kp = Xp × X<st32:sup>yp</st32:sup> = K</st32:df>restored, as explained in WO 00/59154.
The decrypted target the encrypted material by reference to K.
In <patcit><text>EP 0800293</text></patcit> and Schneier B "Applied Cryptography" (Applied Cryptography) John Wiley & Sons, <patcit><text>US 1996</text></patcit>, Pages 176 and 177 are encryption systems been specified, in which subkey or information for generating partial keys via various received routes or channels will.
The This invention intends to unauthorized copying, to make playing, diverting, etc. of content difficult, and it provides a technique or a method for transmission ready digital data in a secure manner, <?page 3?>the illegal copying hard power.
According to a Aspect of the present invention, a digital data delivery methods for the Use in delivering digital data from an upstream System provided on a downstream system, said question upstream system a multipoint delivery of encrypted digital data to specific Targets is provided and wherein the downstream system delivered the Digital data is decrypted; the subject method includes the steps of: encrypting the Digital data in the upstream system using an Encryption key generating a set of passkeys, the for the specific goals are in each case specifically, on the basis said encryption key generating a plurality of partial keys on the basis of a portion of the passkeys in said set or a portion of passkey information, from the pass key question may be reproduced, dispensing or transmit either said plurality of partial keys or the partial key information, from the said subkey can be reproduced, and dispensing or transferring the rest Passkeys, for the Generating said subkey are not used, or the rest Passkey information to each of said specific destinations over a plurality of delivery routes, which differ from routes distinguish the output of said digital data and further are different from each other, delivering or transferring the encrypted digital data, Restoring said encryption key by Use the following system by reference to either of the above Plurality of partial keys or said subkey information and using either the remaining passkeys or the rest Passkey information, the above said plurality are released from delivery routes and pre-drawing of the restored encryption key to decryption the digital data.
In the present description will be key, the right of a Encryption key by split it be obtained, referred to as pass-key, and keys that through further dividing a pass key are obtained, are subkey called. The passkey and the subkey both are far from the same nature, as they are part of the original Encryption key is. In the following description, keys for encryption the encryption used wrench are multiple keys called. The method of encrypting an encryption key used can carried out once or several times be before the encrypted Encryption key received a target is.
at a preferred method is a specific for a target block of passkeys produced in that the said encryption key by one for split the target of that set clear division pattern is.
at a preferred method with respect to the respective set subkey produced in that a part of the relevant set of a target specific passkeys by specific division pattern is divided, which for the target is the set specifically.
This Aspect and other aspects of the present invention are in the claims specified, is drawn to their attention.
Among Reference to the accompanying drawings are now Embodiments of Invention merely exemplified. In the drawings show
<figref idrefs="S69">1</figref> on schematic diagram showing the typical structure of a data transmission system illustrates
<figref idrefs="S70">2</figref> the Data structure of digital data transmitted by the transmission system will,
<figref idrefs="S71">3</figref> on schematic diagram illustrating how an embodiment of the present invention use as movie content delivery system suitable is,
<figref idrefs="S72">4</figref> on Block diagram of a data transmission system,
<figref idrefs="S73">5</figref> on Block diagram of an embodiment embodying the invention data transmission system,
<figref idrefs="S74">6</figref> on Block diagram of another embodiment of the invention embodying Data transmission system,
<figref idrefs="S75">7</figref> on Block diagram of a data transmission system,
<figref idrefs="S76">8</figref> on Block diagram of yet another data transmission system,
<figref idrefs="S77">9</figref> on Block diagram of another embodying the invention, data transmission system,
<figref idrefs="S78">10</figref> on Block diagram of a still white<?page 4?>direct embodiment of the invention embodying Data transmission system,
<figref idrefs="S79">11</figref> on Block diagram of an additional Data transmission system,
<figref idrefs="S80">12</figref> on Block diagram of another data transmission system,
<figref idrefs="S81">13</figref> on Block diagram of another data transmission system,
<figref idrefs="S82">14</figref> on Block diagram of an additional Data transmission system,
<figref idrefs="S83">15</figref> on Block diagram of another data transmission system,
<figref idrefs="S84">16</figref> on Block diagram of yet another data transmission system,
<figref idrefs="S85">17</figref> on Block diagram of an additional Data transmission system and
<figref idrefs="S86">18</figref> a Summary table of characteristics of arrangements, the as a working platforms are known and associated with the data transmission system according to some embodiments of the present invention may be used.
<figref idrefs="S69">1</figref> illustrated schematically illustrates a system in which a delivery or transmission of digital data Agent supplying to a plurality of destinations. In the illustrated arrangement, includes the Delivery Agent a distribution rights holder <figref>1</figref> one, the the right to distribution of content (ie digital data) which and a delivery or Übermittlungs business operators <figref>2</figref> on, supplies or transmits the content. The distribution rights holder and the delivery agent can use the same entity be, or may different entities be, and a variety of stakeholders can make the delivery agent.
Of the Distribution rights-holders <figref>1</figref> may be a party, the content producers the right to distribution of content (Which are digital data) received. A content producer can example of its distribution rights holder, or the distribution rights holder may be the contents manufacturers comprehensive joint venture. The objectives include individuals and shops (such as theater or venue operators).
at the arrangement described below includes an upstream system the operating system of the distribution rights holder system and the Delivery system of the delivery agent; a downstream system is through a system of targets formed. include The delivered digital data Character data (such as text, symbols and figures), audio data (such as voice and music) Video data (such as still images and moving pictures), audio-video mixed data or -Verbunddaten (Such as movies and broadcast programs), program data, database data and other digital data. also is attached Information included as IDs as metadata (ID information on an information carrier or medium) is well known, information relating to the date on which the data was generated (such as the date of shooting the picture), the resort, the people and different states.
In <figref idrefs="S69">1</figref> will the digital data via a high-speed multi-point transmission network <figref>3</figref> delivered, which for the delivery of large Amounts of data at high speed in a VELOCITY broadband environment suitable is. A content producer<figref>1</figref> sends a digital data content to an electronic delivery operator <figref>2</figref>. of which the contents to specific destinations A, B, etc. on the High-speed multi-point transmission network <figref>3</figref> leave is. It is also contemplated the content on CD-ROMs, DVDs or other suitable to deliver storage media. The high-speed multi-point transmission network<figref>3</figref> is a broadband network, which includes a radio transmitter or broadcasting satellites, may comprise glass fibers and / or other resources. such a Network is capable of large Amounts of data at least in the downlink direction transferred to. alternative can over the network bidirectional capabilities feature, the mass data transfer in up and downward directions allow.
The High-speed transmission system <figref>3</figref> transmits data <figref>8</figref>. their structure or structure typically of the in <figref idrefs="S70">2</figref> illustrated Type. <figref idrefs="S70">2</figref> illustrated only a key <figref>8A</figref> around indicate that a network provider (Not necessarily the delivery agent) the confidentiality of the communications service strengthened it offers, by using its own encryption key in order encrypt the data it provides, or block. This Encryption key can dependent on on various circumstances, as the overall security of the data or the delivery system, the costs, influencing upon receipt, etc. are used or not. Nevertheless, it is expected that most network providers data on the networks, they operate, encrypt are, in particular with regard to the fact that this is the business users more security brings with it than any other candidate. Although in <figref idrefs="S70">2</figref> not shown, the data is in practice <figref>8</figref> With a header provided.
<?page 5?>
Of the in <figref idrefs="S70">2</figref> enclosed by dashed lines area corresponds to the delivery of agents <figref>2</figref> (Also called delivery business operators called) supplied data. In the illustrated example, contain the data file allocation table (FAT) <figref>8B</figref>Which a data or file storage information, Operation data or operating data <figref>8C</figref>, The digital data Terms (Objectives, duration of Professional respective target playback, Include number of permitted reproduction cycles and the like), video data <figref>8D</figref> and Audio data <figref>8E</figref> indicates.
The Representation of locks in association with each data item shows that the various items of data each by encryption processes protected are performed by the distribution rights holder or the delivery business operator (The individual or both of them are working in cooperation). Of the here are used encryption key is used generally for all data items together. Alternatively, different encryption keys for different accepted data types (eg for different sets of Video data). As a further alternative, a different used encryption key are, independently to each of the respective data items from encrypt data type.
As in <figref idrefs="S70">2</figref> shown, is certain content in a Variety of formats delivered. This means that a single Content (such as a movie or a video program) using a Variety of types of coding and decoding video and leave audio data (which are different codec methods) is. In the example of<figref idrefs="S70">2</figref> becomes the video content in three video data types or types using submitted by three different codec methods. Typical codec methods conclude MPEG (Moving Picture Experts Group -) - standards, a wavelet transform and another one.
The Using different coding methods for delivering video content provides higher Degrees of freedom with respect the system configuration at locations which receive the emitted content. This means that the user at the destination using its existing system without adaptation to a foreign codec system can continue that for the at issue digital data delivery service specially designed is. Such a multiple format delivery system uses the dispensing or delivery agents, as these are not their customers to specific objectives need to restrict, which possess a particular system. The objectives also drag out the system benefits by existing device thanks to the wide selectable Coding region for can take the delivery of digital data.
The The foregoing also applies to the audio data <figref>8E</figref> to. The example according <figref idrefs="S70">2</figref> shows two audio data items that different after two codec method are coded. Typical codec methods that may be used include MPEG standards and others on.
In the system of <figref idrefs="S69">1</figref> consist the data that can be received by a household, which For example, as a target A is indicated, from a video data item, by a video codec VCD<sub>1</sub> is coded, and from an audio item of data by an audio codec ACD<sub>1</sub> is coded. be on or in this destination these data items in the data submitted <figref>8</figref> based on a FAT operation selectively extracted or reproduced. on the other hand pass the data that can be received by a business operator, which For example, as the target B is indicated, a video data item, by a video codec VCD<sub>2</sub> is coded, and from an audio item of data by an audio codec ACD<sub>2</sub> is coded. In this aim they are B Data items in the submitted data <figref>8</figref> based on a FAT operation selectively extracted or reproduced. It is however not necessary, all data at all times ERS enter in multiple formats; each target can alternatively Data is supplied solely in the formats typically Way be used by the destination in question.
The delivered digital data at the destination by a decryption server <figref>33</figref>. the later describes decrypted, before sending them to a dispenser <figref>34</figref> be issued. The processes by the decryption server <figref>33</figref> and the dispenser <figref>34</figref> be performed internally, are described later. The delivery of encryption keys that to decrypt encrypted Digital data needed be, provides conditional access to the data concerned. In <figref idrefs="S69">1</figref> are two encryption key delivery routes provided: one route via a wide area network (Transmission medium) <figref>4</figref>and the other is a storage medium <figref>5</figref>, <figref idrefs="S69">1</figref> shows a typical delivery arrangement where at least two types of key information needed be to restore a common encryption key, wherein a part of the key information about the Wide area network <figref>4</figref> is delivered electronically and the rest key information physically on the storage medium <figref>5</figref> is discharged.
Regarding the Wide area network <figref>4</figref> in the arrangement is assumed, that a typical transmission network is that for bidirectional communication is suitable as a öf<?page 6?>fentliches Switching network (eg, the Internet, an ATM network, a packet-switched Net or the like) or a leased line network. The storage medium<figref>5</figref> can a magnetically readable medium, an optically readable medium, Semiconductor memory or the like. The storage medium may by a postal service, by a home delivery service or by other conventional delivery services are delivered.
To the Purposes of the present description it is assumed that the encode digital data encryption key used for all Goals is common, and that a set of key information, which is delivered individually to each destination, unique or unique to that target is. If the respective target its own key information supplied is, can the encrypting the digital data not used encryption key long be restored unless and until all key information, the transfer to a particular destination is, is obtained. This makes it more difficult and time-consuming, all necessary key information to steal or embezzle. In addition, each digital data item its own set of key information have.
Of the to encrypt the digital data used encryption key should preferably for the respectively dispensed contents to be specific. By means of this Arrangement, even if the entire key information is stolen and this to an unauthorized restoring of digital data leads, the violation only limited to the content, the question by the specific key encoded is. Of course it is not mandatory that the encryption key for each Content is unique and clearly; a common encryption key can for a Variety of content are used. Nevertheless, the delivery should or the tax system as a whole improved security capabilities against possess an unauthorized data retrieval; the single ones Encryption keys should not be limited by or to any particular rules. The degree of data security may vary depending on the dispensed Content also vary as a function of the fiscal policy the delivery agent.
Regarding the the present invention is the notion that the key information via a Variety of different routes is conducted, such as by a network and by a storage medium, as shown in <figref idrefs="S69">1</figref> shown is. The multiple delivery routes solution , as explained below, accepted because of their different characteristics.
On Advantage in the use of a network or network is that this immediate Delivery of key information allows. A disadvantage of a network is the difficulty to verify whether stolen the key information has been. A disadvantage in the use of the storage medium is the fact that it takes time for each destination the delivered key information wins (ie receiving). An advantage of the storage medium lies in the relative ease determine whether the key information has been stolen.
The present invention contemplates combinations of network- and network-based and physical data delivery systems, in which a storage medium is included into consideration. If little or no possibility of data theft is provided in the network, the entire key information about the Network or network are submitted. If enough time between the delivery of key information and is the provider of the content available (for example, is supplied to the content days after dissemination of key information), the entire key information be issued using storage media.
The This invention also contemplates various encryption method into account, that are currently known, and those procedures that will emerge in the future.
In <figref idrefs="S69">1</figref> is the key information, the above discharged two routes (the wide area network <figref>4</figref> and the storage medium <figref>5</figref>) Generally formed by a set of passkeys (subkey) under from the encryption key Recourse to an on divided the respective target specific key sharing pattern are. The set of passkeys may alternatively be formed by a variety of keys, specifically for the respective target are generated, the encryption key by the specific multiple keys encoded and transferred to the corresponding target is.
<figref idrefs="S71">3</figref> shows a typical arrangement, the electronic delivery of a movie content suitable is.
A Film production company <figref>1a</figref> is a content producer <figref>1</figref> according to <figref idrefs="S69">1</figref> used, and theaters A and B receive digital data as targets <figref>6</figref> and <figref>7</figref> according to <figref idrefs="S69">1</figref>, <figref idrefs="S71">3</figref> includes a movie video conversion (Telecine processing) <figref>9</figref>That of the film production company <figref>1a</figref> provided Film images converts into electronic images. Although in<figref idrefs="S71">3</figref> specifically not shown, can theaters A and B be the theater of any scope as large movie theater, small single screen theaters or so-called <?page 7?>Cinema complexes.
<figref idrefs="S72">4</figref> shows an example of a delivery system with an upstream system, consisting of a content distribution rights holder <figref>1</figref> and an electronic delivery business operator <figref>2</figref> there, and a downstream system, which specifically for the target is, to which the digital data is output. The upstream System generates an encryption key that for the each digital data item is specific, and encrypts Digital data using the corresponding encryption key. On Set of passkeys, the for a respective specific objective are clearly, is based on the encryption key and a portion of the set of passkeys (or passkey information, from the set of passkeys can be prepared) to each destination over a network or network leave. The rest of the set of passkeys (or passkey information) is in a dedicated storage medium for physical delivery written to each destination. The encrypted digital data issued in accordance with a delivery system or to the objectives -plan (For example, by power-transmission, pay-TV for a movie viewing or similar).
The Subordinated system provides for the corresponding digital data item specific encryption key on the basis of the part of the set of passkeys (or the passkey information) the above the network is provided, and the remainder of the set of passkeys (or the passkey information) which is delivered on the storage medium, restores. The restored Encryption key is to decrypt encrypted uses digital data.
at this example is the used to encrypt the digital data Encryption key to one for the respective target (ie the respective downstream system) specific Distribution Rule divided or analyzed in a set of passkeys. A portion of the set of the so generated passkey is transmitted over a network to the destination, and the remainder of that set is physically on a Storage medium delivered.
On decryption server the following system is specific to a digital data item Encryption keys on the basis of both of the part of the set of passkeys (or the passkey information) of over the network is provided, as well as the remainder of the set of passkeys (or the passkey information) restore, which is delivered on the storage medium. The delivered or delivered digital data by reference to the restored Encryption key decrypted. On locally generated scramble key is for scrambling the decrypted contents used; a descramble key is generated, If the digital data is generated correctly. The interest decrypted Data is decoded, and drawing upon the locally generated Scrambling scrambled. The scrambled are digital data from the decryption server by using said descrambling key, the provided by the decryption server is descrambled. The descrambled Digital data are submitted in a specific output format. Briefly, the decrypted Digital data before delivery or dispensing scrambled.
The scrambling and descrambling key, which generated by the decryption server be able be the same for an entire stack of digital data, or they can for each be digital data item different. The latter arrangement is preferably as a more effective countermeasure against a possible data theft.
The Dispenser which scrambled the fed digital data be, a display device (eg, a monitor device, a television set, a projector unit, a portable electronic device), a printer, a speaker, a drive for recording data on a storage medium or the like. If it is at the digital data is video data, it can be displayed on a display screen or projected onto a projection screen. If it is when the digital data is audio data, this can by speaker are reproduced. If it is the digital data to audio-video mixed data These may this in two different formats (i.e., audio and video formats) are submitted simultaneously.
at the arrangement of <figref idrefs="S72">4</figref> contains the upstream System with a content server <figref>11</figref>, A content coding unit <figref>12</figref>. an encryption unit <figref>13</figref>. a delivery server <figref>14</figref>, A content management server <figref>15</figref>. a key generating unit <figref>16</figref>. a destination management server <figref>17</figref>, A pass-key generating unit <figref>18</figref> and a writing unit <figref>19</figref>, The downstream system includes a Incoming server <figref>31</figref>, A reading unit <figref>32</figref>, a decryption server <figref>33</figref> and an output device <figref>34</figref> (With a descramble unit <figref>34A</figref>). Of the decryption server <figref>33</figref> consists further from a decryption section <figref>35</figref> (of the an Ent<?page 8?>encryption unit <figref>35A</figref>. a key restoration unit <figref>35B</figref>. a content decryption unit <figref>35C</figref> and a scrambler <figref>35D</figref> includes) a scrambling control unit <figref>36</figref> and an output log management unit <figref>37</figref>,
The aforementioned Components in Form an associated Hardware or software to be realized.
In <figref idrefs="S72">4</figref> describe thick lines transmission channels of large capacity, and thin lines represent transmission channels with relatively reduced capacity . It should be noted is that this configuration the current state represents the art, so that the proposed transmission capacity in the height relative are. Currently, the passkey delivery routes which by arrowed thin Lines are indicated, alternatively be designed so that they have large transmission capacities.
Of the content Server <figref>11</figref> represents a device whose main function consists to store digital data delivered over transmission channels have been or on a storage medium (such as a Magnetic tape <figref idrefs="S72">4</figref>) Have been transported. The memory function is by means of a mass storage device realized that in the contents server <figref>11</figref> locked in is. Preferably, this server has a computer-based structure on.
This Content Server consists of a processing unit for executing Control and arithmetic functions, a storage device for storing of data for a signal processing are necessary, an input device, by data, programs and commands are entered from the outside, and an output or delivery device for delivering the results such internal processing.
The Coding unit <figref>12</figref> subjects the digital data a compression coding and other coding processes such as MPEG conversion, a wavelet or wavelet transform, etc. The content encoding unit <figref>12</figref> performs Variety of encoding processes, which typically uses will. Each digital data item is therefore by a variety encoded by code or multiple codes. A watermark information is or is preferably embedded in the video and audio data, of the content server <figref>11</figref> to the content encoding unit <figref>12</figref> transfer will. The content encoding unit can by associated or dedicated hardware or realized by computer software be.
The encryptor <figref>13</figref> receives from the key generation unit <figref>16</figref> a for one Content item specific encryption key and encoded the relevant content item by reference to the encryption key. The here are used encryption system Any of those encryption systems be the ordinary skill are known.
Illustrative are the DES process (Data Encryption Standard), the FEAL process (Faster encryption algorithm) and other encryption processes, used. The encryption processes will respect the operational or production data and the content data individually executed. It should be noted that the encryption process with respect to the Content data is performed in an illustrative manner with respect to each data item, of the content encoding unit <figref>12</figref> is coded.
The encryptor either by dedicated hardware or by software be realized.
Of the delivery server <figref>14</figref> leads two main functions: storage of the digital data encoded are, in a storage device so that only those recipients at certain goals the contents to a finally implemented decryption can view or record, and a levy of decrypted Digital data about the High-speed delivery network <figref>3</figref> according to a Delivery system or layout. The output function is a transfer device realized that over broadband transmission device and a rate control features.
at present an over Night takes place memory data output for delivering data over the High-speed delivery network <figref>3</figref> taken into consideration. In the future, a flowing discharge be or the like provided if higher transmission rates as widespread to be expected.
In the case where the encrypted Digital data is delivered on a storage medium, the Dispensing function realized by a drive, which concerned the Digital data on a suitable storage medium stores.
at the communication with the content server <figref>11</figref> registered the Content Management Server <figref>15</figref> a newly accepted content, search for the desired Content and calls him down, splits files and performs other processes. Of the Content Management Server is preferably computer-based set up, and It manages the encryption keys for the respective Content items are generated.
<?page 9?>
The Key generating unit <figref>16</figref> creates a for the respective items of the dispensed digital data or unique unique encryption key. The used to generate the encryption key Encryption system may be any one of encryption systems be the ordinary skill are known. This means that encryption method or techniques according to the state the technique can be applied to an unauthorized decryption data difficult to implement to make.
Among Using a database managed by the destination management server <figref>17</figref> objectives, Delivery conditions and other operating data for the respective Digital data item and for the respective target generated encryption key information. The delivery conditions include usable time periods, an approved discharge count (For example, the frequency, be in the recorded or reproduced a content item can), and the like, the destination management server preferably has a computer-based structure.
Of the Objective Management Server <figref>17</figref> can be connected to one of three places be installed in the system, which solely by the content distribution rights owners is operated, in which the user of the electronic dispensing system or Delivery Business alone or in both systems. Those alternative that applied will depend depends on which party to the key information relevant to the Target outputs. If a small number of business users, knowledge regarding the key information owns, is of course data security for the entire system improved.
Of the Objective Management Server <figref>17</figref> is capable of the output log data of following system over an up-link (usually the Internet, a telephone line or the like communication line) to recieve. Using the dispensing record manages the Objective Management Server given histories (dates and times of delivery, delivery counts, delivery periods and such related Information, such as the presence of a fault, the number of content-related Viewers and target age groups, and the like) of the targets (or recipients Receiver). Accordingly, features of Objective Management Server <figref>17</figref> over a Database and a delivery history management unit; none of them is presented, layed out.
The Database and making history management unit may alternatively be set up separately from the target management server. The output log data can together (or otherwise statistically processed) and analyzed will, either by the upstream system (which the output log reports receiving) or by the downstream System (before the downstream system, the results of its processing transmits to the upstream system).
If the output log of following system by the upstream System is administered, the status of content distribution may be readily monitored will. This arrangement allows in addition, the takeover of market developments, such as sales figures at box office, current Fads and trends. Alternatively, with respect to the Record management or regarding the recording management are believed to be or it through the content delivery examined company or by other contributors as the Digital data distribution rights holder or the operator of the electronic delivery business accomplished is.
The Output log data can to a suitable electronic device in place of the distribution management server <figref>17</figref> issued and be used by it. The output log data need not all mentioned above Information (dates and times of delivery, etc.) to contain. One or a desired Combining the output log items may instead reported will. also the output log data option, and they need unless preferably not to be used.
The Pass-key generating unit <figref>18</figref> Splits an encryption key A, the for generates the respective content items (eg, a movie, a video program, an audio program or the like) by means of a respective of the Target unique in sharing pattern, whereby a set of Passkeys A1 and A2 is generated. If for example, 1,000 recipients or receiver are present at as many locations, 1000 sets of Passkeys A1 and A2 are generated. The thus generated passkey be to the destination Management Server<figref>17</figref> as transferred to a candidate delivery or delivery processing unit. In this example, the pass-key generating unit supplies a Part of the set of passkeys, namely the passkey A1, to a non-illustrated communication unit for delivering a Network, and provides the remaining Passkeys, namely the Passkeys A2, to the write unit <figref>19</figref> for delivery to a storage medium.
The Writing unit writes the passkey A2, which has been notified to it is, in or on a particular storage medium containing a magnetic readable medium, an optically lesba<?page 10?>res medium, a semiconductor memory or the like may be. Address information for submission of Storage medium to the candidate object is from the target management server <figref>17</figref> delivered. Similarly, Network addresses for delivery the pass-key leave A1 at the right target.
In the downstream system performs the receiving server <figref>31</figref> the functions of receiving the encrypted Digital data from what receivers allows only in certain locations, the content on a after all successful decoding of to view or record out (that is, encryption conditional access to the content supplies). Also leads the concerned receiving server storing the digital data supplied in a memory device and a delivery of digital data to the decryption server <figref>33</figref> correspondingly a specific reproduction plan. Moreover, it is also an error correction of the received data executed.
In the case that the digital data is delivered on a storage medium will contain the server receiving a read unit for reading the digital data supplied from the storage medium.
The reading unit <figref>32</figref> working in the downstream system so, that the passkey A2 is read from the storage medium on which it received is. Although in<figref idrefs="S72">4</figref> not shown, a communication unit provided to the over the Wide area network delivered passkeys A1 receive.
Of the decryption server <figref>33</figref> decrypts encrypted Digital data and decodes the decrypted, but still coded Digital data. The decryption server Also takes locally scrambling the decoded data prior to prevent the restored Original data in unprotected Form are submitted. The decryption server can either dedicated hardware or realized by software. To protect the digital data from misappropriation, the decryption server <figref>33</figref> in a safe physical housing provided that only open or can be unlocked if authorized procedures followed is.
Of the decryption section <figref>35</figref>. the decryption unit <figref>35A</figref>. the key restoration unit <figref>35B</figref>. the content decoding unit <figref>35C</figref> and the scrambler <figref>35D</figref> having, with effective countermeasures provided against the theft of data. This is because of the important Information, namely the encryption key information and the original digital data streams between the function blocks, the section included. For this reason, the functional blocks are the decryption section formed as semiconductor integrated circuits or constructed, that their functions are disabled if the housing of the section <figref>35</figref> is forcibly opened.
The decryption unit <figref>35A</figref> uses the Encryption key, which of the key restoration unit <figref>35B</figref> provided is to that of the receiving server <figref>31</figref> delivered digital data decrypt which for conditional access is provided to the digital data. The decryption unit either through associated or dedicated hardware or realized by software.
The Key restoration unit <figref>35B</figref> used both about the output network passkeys A1 and the on a storage medium delivered passkeys A2 to the encryption key for decryption encrypted restore digital data. The restored encryption key is while a certain period of time thereby stored so that it on a suitable storage medium such as a nonvolatile memory or a Hard drive is stored.
Before of the receiving server <figref>31</figref> delivered digital data decrypts are, reads the key restoration unit <figref>35B</figref> the attached to the digital data Operating or operating data <figref>8C</figref> (please refer <figref idrefs="S70">2</figref>), in order to determine whether the playback conditions (Terms), which are determined by the operational or production data to the satisfies the relevant time are. If the playback conditions have been met, transfers the key restoration unit a decryption enable signal the decryption unit <figref>35A</figref> and a scramble key generating signal or a scramble discharge enable signal the scramble control unit <figref>36</figref>, If the playback conditions are not satisfied, the key is recovery unit <figref>35B</figref> at the decryption unit and to the scramble control unit Blocking signals.
The Content decoding unit <figref>35C</figref> is with the recipient to the specific target applied codec processing compatible. The Content decoding unit, either by associated specific Hardware to be realized or by software, and it is capable of the originals unencrypted restore digital data.
The scrambler <figref>35D</figref> is working so that the decrypted decoded digital data <?page 11?>scrambled are to the original data which are output, a further give protection. The scrambler either through associated specific hardware or implemented by software.
at the in <figref idrefs="S72">4</figref> Example shown is the scrambling control unit <figref>36</figref> outside the decryption section <figref>35</figref> illustrated; However, it will be understood that, unless it is desired, the scrambling control unit in the decryption section may be included.
If the scramble control unit <figref>36</figref> by the key restoration unit is released, it generates a scramble and a paired therewith descrambling key. Of the scrambling and the thus paired descrambling key can independently of submitted content always the same set of keys (that is, it can a solid pair of scrambling and descrambling keys from be issued to the memory). Alternatively, a different Set of scramble / descramble keys for the respective Content are generated (that is, that a different pair of scramble and descramble keys each can be time generated when a new content item submitted is, the set of scramble / Entwürfelungsschlüs sel detained or is stored while are met certain playback conditions). As a further alternative , a different set of scramble / descramble keys on each Reproduction output generated through (ie, it is a different Pair of scrambling and descrambling keys each Time generated when a coded content is decoded).
If the so Verwürfelungsschlüsselinformation designed or arranged is that it is changed periodically or irregularly, while a single content is delivered, generates the scramble control unit <figref>36</figref> scrambling and descrambling key in suitable time intervals, while the digital data to the dispenser <figref>34</figref> leave will.
provided he wishes, , the scramble key generation status of the scramble control unit <figref>36</figref> at the output log management unit <figref>37</figref> reported are to be monitored allow to whether the scramble key without proper authorization (ie illegal) are generated.
The Output log management unit <figref>37</figref> manages the Drop-record of delivery or dispensing device 34 to determine, whether any of the respective device unauthorized done delivery or dispensing. The output log management unit either through associated specific hardware or implemented by software. Recording data from the output log management unit via communication lines to the destination Management Server <figref>17</figref> of discharged upstream system. This allows the upstream system, separately Playback delivery status of the recipient at any particular to monitor site and a review on make any unauthorized processing of data.
The Output log data can original or output data or be the combined (or otherwise as statistically processed) and by the output log management unit or are analyzed by other units. The output log data can a contain demographic information, such as the number of content-related Viewers, target age groups, etc.
The dispenser <figref>34</figref> with respect to the recovered Digital data compatible. For example, if the digital data by Video data is given, the output device <figref>34</figref> a display unit be or a projection unit. If the digital data by Audio data is given, the output device may be a speaker. In any event, contains the dispenser a descramble unit <figref>34A</figref> and a signal processing unit <figref>34B</figref>Which the basic functions the device running.
The Descramble unit <figref>34A</figref> descrambled by the decryption server <figref>33</figref> votes scrambled Digital data. The descramble unit may either through associated specific hardware or implemented by software. In practice, the descrambling unit by a semiconductor integrated circuit or a circuit board module be formed.
The Signal processing unit <figref>34B</figref> are descrambled digital data in a suitable output format. If the output device<figref>34</figref> a Display unit or a printer, images can then in a Frame or field format are output. If the output device a speaker, the output from the descramble unit be a based on real-time acoustic reproduction.
There by the descrambling unit <figref>34A</figref> votes Signals are protected by static features such as electronic by Water sign production can be, preferably, the output device <figref>34</figref> in a housing accommodate the single<?page 12?>ally be opened if authorized procedures to be followed, the device in question then inactivated , when the housing violently open is.
If to the content server <figref>11</figref> new digital data are submitted, is in question content with a unique encryption key under the control of the content management server <figref>15</figref> uncoded or unencrypted. The encryption key is the pass-key generating unit <figref>18</figref> supplied to the the encryption key with Help one for the objective in question unique sharing pattern divides (Or parsed). The division pattern may be independent of votes varying Content be the same or it may different for each content be. In the in<figref idrefs="S72">4</figref> Illustrated example, the set of passkeys, by the pass-key information A1 and A2 are formed in a respective of the content of generates specific objectives unique way.
The generated passkey A1 and A2 before transmission the digital data to the desired given target. In terms of of in <figref idrefs="S72">4</figref> System shown is of passkeys A1 via the supplied network, and the passkey A2 is conveyed on the storage medium. Alternatively, the Passkeys delivered to the delivery of digital data.
The Subordinated system reads the digital data (ie, the content) correspondingly a specific plan and decrypts the encrypted Digital data unte attraction of the restored encryption key. It might be appreciated that the decrypted digital data with the are compatible codec, which is used in the relevant target, so as to be selectively decoded. The decoded data by the decryption server <figref>33</figref> scrambled.
Of the decryption server are the scrambled Digital data to the output device <figref>34</figref> from that received the Data using said descrambling key is descrambled, the of the scramble control unit <figref>36</figref> leave is. The descrambled Content is requested in a submitted format. The status of content delivery is as output log data of the output log management unit <figref>37</figref> to the upstream system reported. The output log data may be reported , if the respective contents is discharged (that is, transmit a recording data report can be when the content item is delivered), or the data in question can be reported on a number of content charges down (for example, , a dispensing status list be issued at the end of the day).
As described, there are in the system according to <figref idrefs="S72">4</figref> a plurality of passkey delivery routes. With this arrangement, the passkey (for example, the passkey A1) of over one of the routes is discharged, is stolen, the encryption key is nevertheless protected, unless the remaining passkey (passkey A2) is also stolen. In the case where the passkey information via a Route is passed, which are different from the delivery route of the digital data is (this includes to use the same transmission medium one, however, for the delivery of the content to a different from the discharge of passkeys Time), then even if a portion of the passkey information and the encrypted Digital data are stolen, not restore the original digital data, because for a Restoration of the encryption key necessary key information is delivered separately from the digital data.
There decrypted scrambled digital data are, before they are transmitted to the output device, the separately dispenser and from the server, the decryption function points out, be provided separately, while adequate protection against misappropriation of data is maintained.
If later a more secure encryption system available is or if it is preferred to adopt a different codec technique, this can easily by replacing the encryption server <figref>33</figref> reached will. independently of the codec that is used on or in any goal, be all Data from the decryption server to the output device <figref>34</figref> are transmitted are scrambled, so that the output device with different types of codecs can be used.
These Features contribute to the cost in the development and manufacture the dispenser <figref>34</figref> to reduce. Consequently, the existing output device easily by another output device higher Performance are exchanged, for example by a higher reproducing resolution, the may be available to a system implementation.
<figref idrefs="S73">5</figref> illustrated an example of a delivery or delivery system of the present invention, wherein the same reference characters identify the same components are used in <figref idrefs="S72">4</figref> are shown. This in<figref idrefs="S73">5</figref> illustrated downstream system is identical to that in which <figref idrefs="S72">4</figref> shown is.
<?page 13?>
The in <figref idrefs="S73">5</figref> illustrated supply or delivery system differs from that in <figref idrefs="S72">4</figref> system shown in that a partial key generation unit <figref>20</figref> to further subdivision or division of the pass-key generating unit <figref>18</figref> generated Pass key A1 in subkey provided A11 and A12. Furthermore is a writing unit <figref>21</figref> for writing the partial key A12 used in or on a storage medium, and a reading unit <figref>38</figref> read the subkey from the storage medium. The managing routing of key information delivery is modified in part to the transportation of the three sets of key information A11, A12 and A2 allow.
The Subkey generating unit <figref>20</figref> generated the set of subkey A11 and A12 by dividing a portion of the passkeys (ie the pass-key A1) represented by the pass-key generating unit <figref>18</figref> generated be, for by means of a the respective target specific certain sharing pattern. alternative can the subkey A11 and A12 from a passkey information are generated, wherein it is a piece of information from which reconstructs the passkey may be reproduced or. If for illustration 1000 receiver to eg 1000 are locations available are 1000 sets of partial keys A11 produced and A12. The division pattern does not need for each Aim to be unique; Rather it may common to all objectives , or it may different depending on geographical area or the group of treated by the system vary objectives.
The Subkey thus generated be part of the key generating unit <figref>20</figref> to the destination management server <figref>17</figref> as well as a candidate transferred tax-processing unit. In the illustrated example, the subkey generating unit is the key part of A11 an unshown communication unit for delivering a Network from, and they are the other subkey A12 to the write unit <figref>21</figref> for delivery to or on a Storage medium. The writing unit<figref>21</figref> can the previously Writing unit described <figref>19</figref> according to <figref idrefs="S72">4</figref> correspond. Alternatively, instead of partial key A11, and / or instead of Subkey A12 a subkey information be issued, from the partial key A11 or A12 subkey can be reconstructed or reproduced.
at the in <figref idrefs="S72">4</figref> Delivery system shown is the passkey A2 transported by means of the storage medium to the downstream system. In contrast, give t the in<figref idrefs="S73">5</figref> illustrated Delivery system the pass-key A2 on the network from. Other operations than the delivery of key information be in accordance of the delivery system <figref idrefs="S73">5</figref> in same manner as the delivery system according to <figref idrefs="S72">4</figref> executed. In<figref idrefs="S73">5</figref> will the Key information on two transmission networks or networks (either two different networks or networks or over the same network, but given at different times) and by means of a storage medium. As more key information delivery routes are present, it is more difficult to steal data on the delivery routes.
<figref idrefs="S74">6</figref> illustrated another example of a delivery system according to the present invention, wherein the same reference characters identify the same components are used in <figref idrefs="S72">4</figref> and <figref idrefs="S73">5</figref> illustrated are.
The in <figref idrefs="S74">6</figref> Delivery system shown differs of the in <figref idrefs="S73">5</figref> System represented by that the passkey A2 does not have a Network is delivered, but as in <figref idrefs="S72">4</figref> by means of a storage medium. Nevertheless, the partial keys A11 and A12 leave different routes shown, for example via the Network and a storage medium. Other operations than the delivery the key information be in accordance of the delivery system <figref idrefs="S74">6</figref> in the same running way as in the in <figref idrefs="S72">4</figref> and <figref idrefs="S73">5</figref> illustrated Shipping and delivery system. In<figref idrefs="S74">6</figref> will the Key information on a transmission network and delivered or transported using two different storage media. As more storage media the key information delivery are used, it is easier, a misappropriation or wrongful appropriation on determine the delivery routes, which higher levels of data security brings with it.
In <figref idrefs="S75">7</figref> is another example of a delivery system shown, in which the same used reference numerals to identify the same components are, in <figref idrefs="S72">4</figref> are shown.
The in <figref idrefs="S75">7</figref> Delivery system shown differs characterized by the above-described examples, that the two Passkeys A1 and A2, or passkey information, from the pass key A1 and A2 reconstructed or can be reproduced, on the Networks or networks are delivered. Other operations than the delivery the key information be in accordance with the delivery system <figref idrefs="S75">7</figref> in the same running way as in the example in <figref idrefs="S72">4</figref> illustrated Delivery system. Since the key information in <figref idrefs="S75">7</figref> about two transmission networks is delivered, the time interval between the delivery of key information and the start of digital data delivery are considerably shortened in comparison with those arrangements in which the <?page 14?>key information is conveyed by media.
On Another example of a delivery system is in <figref idrefs="S76">8</figref> shown, used in which the same reference characters identify the same components are, in <figref idrefs="S72">4</figref> are shown.
The in <figref idrefs="S76">8</figref> Delivery system shown differs of the in <figref idrefs="S72">4</figref> Delivery system shown characterized in that the two passkeys A1 and A2 via Storage Media be issued or transported. Alternatively, the passkey information, from which the passkeys A1 and / or passkey A2 reconstructed or can be reproduced by the storage media to be delivered. Accordingly, a write unit <figref>22</figref> and a reading unit <figref>39</figref> to the Writing or reading of the pass-key on A1 or from a Storage medium provided. Other operations than the delivery of key information are by the in <figref idrefs="S76">8</figref> Delivery system shown carried out in the same manner, as shown by the example in <figref idrefs="S72">4</figref> illustrated Delivery system.
There all key information is transported to storage media, their removal can easily be determined. Consequently, this arrangement involves high levels of Data security compared to cases with him, in which the Key information on a Network is supplied.
On Another example of a delivery system according to the present invention is in <figref idrefs="S77">9</figref> illustrated in which the same reference numerals are used to identify the same components in <figref idrefs="S73">5</figref> illustrated are.
The in <figref idrefs="S77">9</figref> Delivery system shown differs of the in <figref idrefs="S73">5</figref> Delivery system shown characterized that by the partial key generation unit <figref>20</figref> generated subkey A12 not by means of a storage medium (such as in <figref idrefs="S73">5</figref>cast) is, but via a transmission network. Other operations than the delivery of key information are this in <figref idrefs="S77">9</figref> illustrated delivery system in the same way accomplished as indicated by the in <figref idrefs="S73">5</figref> illustrated delivery system.
There all key information about networks with high transmission speed capabilities be passed, thus, the time period between the delivery the key information be and the beginning of the digital data output substantially reduced in comparison with those arrangements in which key information is conveyed by media. By delivering the key information in the form of pass-key A2 and the subkey A11 and A12 ensures the delivery system a higher degree data security, because an unauthorized decryption and Wiederge winnung the contents of all the theft-pass key and subkey information requires.
<figref idrefs="S78">10</figref> illustrated another example of a delivery system according to the present invention, wherein like reference numerals for marking the Components are used, as in <figref idrefs="S74">6</figref> and <figref idrefs="S76">8</figref> are shown.
The in <figref idrefs="S78">10</figref> Delivery system shown differs of the in <figref idrefs="S74">6</figref> Delivery system shown characterized in that the two by the partial key generation unit <figref>20</figref> generated subkey A11 and A12 are delivered by storage media. Accordingly, a write unit <figref>22</figref> and a reading unit <figref>39</figref> to the Be the subkey from A11 or to a storage medium or to read the subkey the storage medium provided.
There all key information will be delivered on storage media, misappropriation can be easily determined , which leads to a system, which at a high level brings data security.
In <figref idrefs="S79">11</figref> is another example of a delivery system according to the present invention illustrated. As before, here, the same components, the in <figref idrefs="S72">4</figref> are shown with the same reference numerals shown. Here, the encryption key is A, the encrypting the digital data is used, not divided into passkeys. Rather, or the encryption key A itself by reference to a variety of specific objectives for each Keys encrypted.
at the in <figref idrefs="S79">11</figref> The illustrated example is a first for the respective digital data items specific encryption key A to encode used by the digital data. A second, specific for each Objectives and the respective digital data item-specific encryption key generating and encrypting either the first encryption key or a encryption information used, recovered from the first encryption key can be. encrypted first encryption key (or the encryption information) is to each destination on a transmission network leave; contrast is the second encryption key (or the second encryption information, retrieved from the second encryption key <?page 15?>or. can be reproduced) by means of a storage medium submitted.
In the downstream system of the corresponding digital data specific first encryption key by restored, that either the second encryption key or the second encryption key information are used, the or delivered by means of the storage medium has been to provide either the encrypted first encryption key or the key information decrypt of or above transmit the transmission network has been. The restored first encryption key to decrypt encrypted Digital data used.
The in <figref idrefs="S79">11</figref> Example shown is different from the examples described above in that this example multiple key generation unit <figref>23</figref> having, a plurality of for the respective targets specific keys generated B. For example, a key B1 for be a first target-specific and a key B2 can for a second his goal specific, etc. A key encryption processing unit <figref>24</figref> encrypts Encryption key A under Attraction of multiple keys B. A writing unit <figref>25</figref> writes the multiple keys B in or to a storage medium for delivery. A to the writing unit<figref>25</figref> compatible reading unit <figref>40</figref> reads the multiple keys B from the storage medium.
The Multiple key generation unit <figref>23</figref> generated Multiple keys B, for the the respective destination and for the encryption key A specific are, the for generated the respective content. If for illustration in 1000 receiver are available at 1000 locations, 1000 sets of multiple keys B generated. The multiple keys B can for a Always be or not given the same target. This means, that different keys B function can be generated from the content. Different key B may also in dependence generated by the geographical area or group of destinations be served by the system.
Of the Encryption keys A, of the multiple keys in the key encryption processing unit <figref>24</figref> is encrypted or is, is leave the network to the downstream system.
In <figref idrefs="S72">4</figref> becomes the for the respective content-specific encryption key A by the pass-key generating unit <figref>18</figref> divided up, to records of passkeys to create. In<figref idrefs="S79">11</figref> is the encryption key A itself encrypted by reference to the multiple keys B, the for the respective target are generated; a thus encrypted key A is a leave network to the downstream system. The multiple keys B transported on a storage medium to the destination.
at the example of <figref idrefs="S79">11</figref> will two kinds of keys used: multiple keys B and an encryption key A, of the multiple keys B encrypted is and given a variety of routes to the receiver of the respective target is. It is likely be understood that even if a set of key information at is stolen Transit, the encryption key information remains protected, unless and until the other set of key information as stolen is.
If it is determined that the multiple keys B stolen in transit or have been diverted, the delivery of the encrypted encryption key A is about the Network stopped. Then be issued other multiple keys B and transported to another storage device to the destination. These guaranteed arrangement a high degree of Security against a data theft.
at the now in connection with <figref idrefs="S80">12</figref> described Example is the for a respective target specific split second encryption key B, a set of passkeys to produce, each set for a corresponding target is specific. A portion of the rate of Passkeys (or the passkey information, from the set of passkeys can be reproduced) is to each destination over a second transmission network leave. In contrast, are the other Passkeys (Or passkey information) in or on a storage medium for a Delivery written.
In the downstream system, the second encryption key by Growing the two parts of the set of passkeys that over the second transmission network were delivered, and the rest Passkeys recovered, which were delivered on the storage medium. After restoration of the second encryption key is to Restore the first encryption key is used, the for the is appropriate digital data specifically. Then, the encrypted Digital data decrypted by using the restored first encryption key.
The in <figref idrefs="S80">12</figref> Illustrated system differs from the in <figref idrefs="S79">11</figref> Sys shown<?page 16?>system by that a pass-key generating unit <figref>26</figref> scheduled is to produce a set of passkeys B1 and B2 to be generated by dividing the multiple keys B, by the multiple key generation unit <figref>23</figref> generated will. Part of this passkey (eg passkey B2) is written in or on a storage medium from which the relevant Read passkey then (eg by a reading unit <figref>41</figref>).
The Multiple keys B is for the respective specific targets, and it is a for a given Target clear division pattern used to a set of passkeys to produce. If desired, can from the pass-key generating unit <figref>26</figref> Distribution pattern used for all Objectives to be shared, or may each objective clearly be assigned. About that , the division pattern may vary depending on the content, or it may during the content delivery be changed periodically or irregularly. The division pattern can also dependent on vary by geographical region or group of targets be served by the system.
There a passkey (Example B1) via a network is discharged and since the other passkey (B2) is delivered on a storage medium, and because encryption key A itself encoded is and a separate route is issued, the system is ensured in accordance <figref idrefs="S80">12</figref> on higher degree of Security against the theft of content data.
A Modification of the reference to <figref idrefs="S80">12</figref> described Example is in <figref idrefs="S81">13</figref> illustrates, in the corresponding Components are indicated by the same reference numerals.
According to <figref idrefs="S81">13</figref> becomes of the key encryption processing unit <figref>24</figref> generated encrypted encryption key A does not have a given network, but. by means of a storage medium Accordingly writes a writing unit <figref>28</figref> the encrypted encryption key A on or into the storage medium from which it subsequently by means of a reading unit <figref>42</figref> read is.
There the encrypted Encryption key A on is discharged to a storage medium, misappropriation of the key information can are perceived faster than other arrangements in which the key information via a Network is managed.
A Modification of the in <figref idrefs="S79">11</figref> Example shown is in <figref idrefs="S82">14</figref> illustrated in which corresponding components are indicated by the same reference numerals.
Here are multiple keys B not by means of a storage medium (as in <figref idrefs="S79">11</figref>) issued, but on transmission networks. On the delivery of multiple keys B out but it is preferred, any destination through digital certification or other known methods and to authenticate the digital data using a public key to encrypt, which is announced by the certified destination.
By Delivery of multiple keys B over the Network is the time between key release and the start of Digital data output substantially shortened.
<figref idrefs="S83">15</figref> shows in a further modification of the <figref idrefs="S79">11</figref> illustrated Delivery system.
According to <figref idrefs="S83">15</figref> becomes the encrypted Encryption key A does not have a Network (as in <figref idrefs="S79">11</figref>), But by means of a storage medium leave.
There all key information (Which are encrypted Encryption key A and the multiple keys B or alternatively, the encryption key information, from the respective key can be reconstructed or reproduced) is routed to storage media, theft thereof can be easily determined, brings the data delivery system a high level of data security with it.
Now was on <figref idrefs="S84">16</figref> Reference is made, in which a Modification of the in <figref idrefs="S80">12</figref> Illustrated example illustrates is.
According to <figref idrefs="S84">16</figref> becomes passkey B2, consisting of the multiple keys B produced (eg split) is not by means of a storage medium, but over leave a network. Consequently, all three sets are the Key information about networks leave. Accordingly, the Time between the key delivery and the start of digital data delivery significantly reduced. Since three sets of key information (A, B1 and B2) may be discharged is, however, a higher level of security opposite to the data theft of content data given than with other delivery systems, in which two sets the key information about the Network are submitted.
Now will be on <figref idrefs="S85">17</figref> Reference is made, in which a Modification of the in <figref idrefs="S81">13</figref> Illustrated example illustrates is.
In <figref idrefs="S85">17</figref> becomes of from Vielfachschlüs<?page 17?>islands B produced (for example, by a division pattern) passkeys B1 no over a network, but submitted by a storage medium. consequently are in this example, all three sets of key information delivered by storage media.
There all key information by storage media is discharged, a diversion or Theft of keys be easily detected. Accordingly, brings the system shown a high degree of Security.
In the foregoing description of the various examples of the inventive concept has not specified which of the illustrated functional Units operated by the distribution rights holder and operated which these units from the executors of delivery business will. <figref idrefs="S86">18</figref> shows a summary table, in which the degree of safety is indicated, which are expected , when various parties the function of the content encoding unit <figref>12</figref>. encryptor <figref>13</figref> and the key generation unit <figref>16</figref> run (which the pass-key generating unit Subkey generating unit and the multiple key generation unit includes). By<figref idrefs="S86">18</figref> use in contemplated configurations two sentences the key information. If three or more sets a key information are used, the words "a key" in <figref idrefs="S86">18</figref> as "at least a key "to understand.
at a first arrangement, referred to as a working platform, there is a consideration of the assumption that the distribution rights holder three reel plays: it generates an encryption key A, it encodes the information content and encrypts the encoded content (These are the content encoding unit <figref>12</figref>, The encryption unit <figref>13</figref> and the key generating unit <figref>16</figref>. in terms of all those it is believed that they of the distribution rights holder to be served). It is further assumed that the distribution rights holder the key information (See the post <figref>1</figref> in <figref idrefs="S86">18</figref>) Outputs.
If the distribution rights holder also the pass-key generating unit <figref>18</figref> (including the Part key generating unit <figref>20</figref>), the Multiple key generation unit <figref>23</figref> and the key encryption processing unit <figref>24</figref> (including the Pass-key generating unit <figref>26</figref>) serviced, and if the operator of the delivery business only the encrypted digital data write to specific objectives, then there is only the distribution rights holder in the position, the encryption key (master key) to know who to encrypt the digital data is used or is. Consequently, the need Not to worry distribution rights holder to the possibility that the Encryption key by to or by the operator (s) of electronic delivery or delivery business is misappropriated. In this operating platform was thus established with respect to the distribution rights holder, that the content that they sell is safe.
at another similar Working platform (item 2 in <figref idrefs="S86">18</figref>) becomes the key information both of the distribution rights holder and of the operator of the electronic delivery business leave. If the in<figref idrefs="S73">5</figref> Delivery system shown it is believed the distribution rights holder assumes the generation and distribution of the pass-key A2 before, during the operator of the electronic delivery business the production and delivery the subkey A11 and A12 makes, divided from the passkey A1 and the Subkey thus generated write. In a corresponding manner, according to the examples<figref idrefs="S74">6</figref>. <figref idrefs="S77">9</figref> and <figref idrefs="S78">10</figref> the Passkeys produced by the distribution rights holder and distributed, and the subkey produced by the operator of the electronic delivery business and leave.
at a further arrangement, the operator of the electronic delivery business the generated passkey or subkey Write in or on a storage medium and the storage medium Add to the aims of the key, as is the case Examples in <figref idrefs="S72">4</figref> to <figref idrefs="S74">6</figref>. <figref idrefs="S76">8</figref>. <figref idrefs="S78">10</figref> to <figref idrefs="S82">14</figref>. <figref idrefs="S83">15</figref> and <figref idrefs="S85">17</figref> illustrated is where the key information is delivered on a storage medium. In this operating platform is the content distribution rights holder alone in the Position, the encryption key (master key) to know who to encrypt the digital data is used.
at a variation of this work platform takes the distribution rights holder encryption and delivery of the encryption key A before, during the operator of the electronic delivery business the Production and delivery of passkeys B1 and B2 makes that of the multiple keys B are obtained. Although this modification, a high level of security entails, it is characterized however by a slightly lower Confidence from.
at another similar Working platform (item 3 in <figref idrefs="S86">18</figref>) is assumed that the key information is discharged from the operator of the electronic delivery business. If those Work platform in the example of <figref idrefs="S72">4</figref> used is, the distribution rights holder generates an encryption key during the Be<?page 18?>driver of the electronic delivery business operator receives the encryption key and it the passkey A1 and A2 are generated.
According to a other work platform (see items 4-6 in <figref idrefs="S86">18</figref>) it is assumed that the operator of the electronic delivery business for encryption responsible for. In this case, the operator of the electronic receives delivery business the encryption key from the Distribution rights holder and encrypted according to the content. In terms of the encoding process is believed to be through the distribution rights holder takes place. Accordingly located the distribution rights holder (of the content production company may be) and the operator of the electronic delivery business both in the position, the encryption key to know, regardless whether the distribution rights holder alone or the operator the electronic delivery business distribute the key information alone or both. Nevertheless, this work platforms bring a better system security with as conventional dispenser assemblies.
More Work platforms are in <figref idrefs="S86">18</figref> as posts illustrated 7-9, with respect to is assumed that the encoding process by the operator of electronic delivery business carried out and that only the distribution rights holder generates the encryption key. The distribution rights holder and the operator of the electronic delivery business are both in the position, the encryption key to know, regardless whether the distribution rights holder alone, the operator of the electronic delivery business distribute the key information alone or both. Nevertheless, this work platforms bring a better system security with as conventional dispenser assemblies.
Still further work platforms are in the posts 10-12 <figref idrefs="S86">18</figref> illustrated; then generates the operator of the electronic delivery business the Encryption key, while the Distribution rights holder the encryption key of the relevant operator of the electronic delivery business gets to the to encrypt digital data. Consequently, there are the distribution rights holder and the operator the electronic delivery business both in the position, the encryption key to know, regardless of who the key information supplies or delivers. Nevertheless bring this work platforms a better system security as conventional delivery or tax arrangements.
Still further work platforms are in the posts 13-15 <figref idrefs="S86">18</figref> shown, after which the operator of the electronic gin ning delivery business the generates encryption keys and the content with the key in question is encrypted while the Distribution rights holder <figref>1</figref> performs only the coding. Still further work platforms are in the posts 16-18 <figref idrefs="S86">18</figref> shown, after which the operator of the electronic delivery business the generates encryption keys, encodes the content and then encrypts the encoded content. In these cases are the distribution rights holder and the operator of the electronic delivery business both in the position, the encryption key to know, regardless of who the key information write. Nevertheless, this work platforms bring a better System security as a conventional dispenser assemblies.
Other discussion
at an example of a data delivery system are digital data or a content from an upstream system to a downstream System issued. The upstream system performs a multi-point delivery encrypted Digital data from. encryption can for each item of the dispensed digital data specific (that is, the respective digital data item by using a unique may be encrypted and unique encryption key); However, this is not intended, the present invention Only limitation. If the respective dispensed digital data item or clearly encrypted once will be Of course any economic injury or any economic Damage due to unauthorized encryption minimized because the corresponding data item is affected alone. If the delivery system is a highly considered safe or if a simplified delivery system is desired, however, a Variety of digital data item by a common encryption process encoded will. The particular encryption scheme, which is used depends the requirements of the business in question from (eg can Movies encryption technology or an encryption method apply while for the Delivery of software programs to another encryption method can be applied). A multipoint data delivery can not only transfer media accomplished are as above Transmission or communication networks, but also by physical Storage media.
Around an authorized user authorized to differentiate the emitted digital data decrypt, is also an encryption key, to the encode the digital data is used, delivered. The upstream system produces a lot<?page 19?>number of parts of a dispensed to the objectives and / or the Digital data specific key information. These pieces of key information be the appropriate targets (ie, at the downstream system) over delivery routes supplied, which are different from those via which the encrypted transmit digital data or content are or will be. All Delivery routes are either physically or temporally, ie by staggered delivery different from each other or separately. In the case where the key information in a plurality of parts over a variety of routes is discharged, is unauthorized Appropriation of a portion of the key information not as long as jeopardizing the corresponding content data, such as not all other parts of the key information are stolen. The key information to be delivered is not alone limited to encryption keys; they can also be an information from which such encryption keys reconstructed may be reproduced or (For example, random numbers). The key information may consist of a Set of passkeys or partial keys exist, ie from keys, which are created by dividing a whole encryption key. The encryption system an enciphering system with a common Keyring sel, an encryption system with a public key or a combination of the two systems.
Examples, as the key can be generated, include:
example I: dividing the encryption key by one for the respective delivery or delivery target specific division pattern in a set of partial keys (At least two keys) for the interest Aim.
example II: generating another encryption key (a second encryption key), the for each different target is specific, and use of the respective further relevant encryption key (ie the second encryption key), around the first encryption key to encrypt, the encryption the digital data is used.
example III: generating an additional encryption key (the second encryption key), the for is the respective different digital data item specifically, and using the additional question Encryption key (ie the second encryption key), around the first encryption key to encrypt, the encrypting the digital data is used.
It can not only one but also two or more of these second encryption keys in one for each different target-specific manner are used. In this case, the multiple second encryption key to be used, the first encryption key in frequency encrypt. In any case, the first encryption key is at least once by the or the second encryption key encrypted. Other encryption systems can are also contemplated, in which the second closures ment key with combining different encryption keys (as for a the objectives of common encryption key, a for the each digital data item-specific encryption key, a for a Plurality of digital data item common encryption key, etc.), to multiple encryption processes perform.
On Key Distribution Pattern and / or for the respective target-specific encryption key can either be provided in a generalized manner (which means that the same encryption key on a relatively long period of time is used, regardless of the digital data before being changed), or they can be provided in a way that every time you charge changes from digital data to be delivered. It is evident that the system with respect to the last-mentioned Protection against unauthorized use or theft of encrypted is content preferred.
A Multipoint delivery either electronically over networks such as the Internet or transmission or communication channels, or physically by the use of storage media are executed.
The Subordinated system is from the original encryption key of over a variety of different delivery routes supplied variety parts of the key information restores and uses the restored encryption key to to decode the supplied digital data and thus the original data or deliver the original content in an appropriate format. It is obvious that the downstream system also structured or must be structured such that a protection against unauthorized use guarantees or theft is. To illustrate, as described above, a subordinate be provided system which over a decryption server and a training or Abgabevor device features that connect in a way is that the secrecy of communications guaranteed is. The delivery or dispensing device may in the same physi<?page 20?>cal housing not only a descrambler and include a content decoder but also a secrecy ensuring end Delivery or dispensing unit, such as a descrambler.
Around to prevent unauthorized use or theft, can the downstream system enclosures made that only by following an authorized procedure unsealed (or open) can be; the system itself is turned off, if it is different unsealed. The authorized procedure for unsealing the housing or of housing may include authorized personnel which proprietary electronic or physical key to open the housing used. An example of an unauthorized unsealing of the system is the destruction or forcibly opening the housing represent.
It is expected but not required that the upstream and downstream systems from different organizations or Companies are set up and operated. It is also in Considered that the company that operates the upstream system, can assume various methods or processes of the encryption to decrypt the digital data-rich, which are submitted. The upstream System can be operated in various ways. As an illustration can a single company operating the system, or the upstream System can be operated jointly by a number of companies. Each of the according to the present invention executed Processes and procedures, by a single or only company or be carried by a variety of companies. For example, one company have the right to distribute a content and also release the contents or deliver. The only company an entity may be that consistent in companies regard as essentially Gan indices is recognized. In this connection, the business of the company be divided into operational units by associated companies or similar entities accomplished be, which is not legally subsidiaries of a single company can, be but nevertheless a single holding company belonging can.
If operate the upstream system from a number of companies is that certain processing function, the individual is a Company is assigned is determined by the needs of the business. It is likely be appreciated that a large Number of combinations of particular hardware and software components can be used by the different companies involved.
As Example, a company that owns the right to a content distribute, also encrypt the data and a variety of Share key information in terms of generate the specific objectives, and another company can the encrypted data Add to those objectives. In this example, only knows the company, which owns the distribution rights, the encryption key (master key). consequently it is relatively easy for the distribution rights holder, maintain data security. The distribution rights holder may be an entrepreneur who has those rights examine the content producers (Which means that the service provider may be the same or not as the content creator).
Although the foregoing description of the present invention not specifically relates to a digital water signs given, it is preferred to include such water signs given before encrypts the digital data be to dissuade from an unauthorized multiplication and unlawful identify redirected digital products.
A Data delivery company or a network administrator can send a encryption processing in terms of those discharge channels add on encrypted Digital data are submitted. Where a key information is distributed, it will actually preferred that each destination be authenticated by a digital certificate (ie with a digital signature of an authentication organization is certified) before the key information public by a key (Such as a public key, adapted from the respective target) is encrypted. This practice will ensure data security further.
In the case where the key information via a Network is released, the network in question can physically be the same as that for the content transfer. In this case, however, the content information and the key information not delivered simultaneously; preferably they are at different Times apart for example, hours or days transfer times. This is the delivery of content and key information on various Routes equivalent. If the content (or digital data) and key information about the same transmitted delivery route were, could a single unauthorized act of misappropriation of a portion Digital data and the key information at the same time redirecting, thereby reducing the possibility of fraudulent decryption encrypted Digital data increases.
at the present technique, it is assumed that the downstream System either advance knowledge of the information has, for the Restoration of the original Encryption<?page 21?>wrench from the key information supplied is needed or supplied with this information from the upstream system is. The information can from the upstream system to the downstream System either simultaneously during the Key message delivery or transferred to another time will.
On Example of a data delivery system includes an upstream system and a downstream system, said upstream system of a Company, which owns the distribution rights to the digital data, or jointly by the distribution rights company and a Company is operated, which delivers the digital data. The digital data is encrypted by the upstream system by reference to an encryption key. On Set of passkeys (Two or more keys form a set), the for their specific targets are clear, is based on generates the encryption key. Either the set of passkeys or the passkey information, from this passkey can be reproduced, is to each destination on issued a variety of delivery routes which differ from routes, which are used for the delivery of digital data and are and which are different from each other further. The encrypted Digital data is also delivered to the targets.
Of the Encryption key is through the downstream system (set up at the target) by reference to either of the votes set of passkeys or the passkey information restored, and the encrypted digital data decrypted by reference to the restored encryption key.
Of the to encrypt the digital data used encryption key is by the respective target (ie downstream system) specific protocol (Which is a distribution rule) in a set of passkeys (eg in three passkeys) split or parsed. This pass-keys are on the questioned next destination via leave routes that are different from the content delivery routes and which are different from each other further.
The Signal processing of the data delivery system, either through hardware executed or by software will.
The Data delivery system is a plurality of pieces of key information on a Plurality of delivery routes, so that any part of the key information, might be stolen, not leads to unauthorized tapping of the encryption key, as long as and until all other key information is stolen. In particular, in the case where the key information on routes is emitted which are different from those transmitted over the digital data (including using the same medium at different times) makes, it even when one of a portion of the key information stolen, accidentally including scrambled Digital data obtained, the fact that the recovery the original Encryption key need key information is given by the digital data separate, difficult to question original restore encryption keys and decrypt the digital data.
Although the data delivery system thus far described the prior existence an encryption key for encode presupposes of digital data, there is no intention, the present to restrict the invention thereto. The encryption key can either produced in the upstream system or from outside the upstream system are delivered. The encryption key can either each digital data item (ie the respective content) specifically be, or it may for a plurality may be provided jointly by digital data item. If for used data items specific encryption key be limited unauthorized decryption any key the damage solely on the corresponding data item. The usage of common keys ever but for damage, caused by misappropriation as long as not to be susceptible or unprotected, as long as the key quite often change.
The Data delivery system, the key information Give various ways. To illustrate, a part a set of passkeys a transfer network be, and the other Passkeys can be issued using a storage medium (for example, by mailing a CD-ROM or a floppy disk or diskette or a solid state or semiconductor memory). If a part of the key information is delivered using a tangible or physical storage medium, it is easier to detect both a theft of key information and immediately countermeasures hold true.
As further alternative, a part of a set of passkeys over a transmitted first network be, and the other Passkey can a second network are delivered. An advantage of the delivery of all Key information about networks is that any time-<?page 22?>minimizes union restrictions on the delivery are. Another advantage is the reduced cost of key information delivery. In realizing the delivery of key information over networks it is preferred in an illustrative way, each target as to authenticate use of a digital certificate, which by means of a public key encoded is that of the candidate destination before delivery of key information is supplied.
As further alternative, a part of a set of passkeys on are supplied to a first storage medium and the remaining passkeys may on are supplied to a second storage medium. When the entire key information submitted using tangible or physical storage media is, it is much easier for an Ent use of key information to discover and immediately countermeasures hold true. The two storage media are preferably physically differently. The type of media and the way in which Information is read from, can obviously for the two Storage media used be the same or not.
The for the transmission used the passkey Storage media may magnetically readable media such as magnetic tapes, floppy disks or diskettes and magnetic cards, optically readable media such as CD-ROMs, MOs, CD-Rs and DVDs, semiconductor memory, such as memory cards (rectangular Type, square type, etc.) and IC cards and others. The storage media on which recorded key information are able delivered by postal service or by a commercial delivery service will. Currently, the storage media are most commonly by registered Sent letter to ensure their safety.
As Characteristic of at least preferred embodiments of this invention a plurality of partial keys on the basis of a part of either said set of passkeys or the passkey information generated. Either the plurality of partial keys or partial key information (From this subkey can be reproduced) and either the remaining passkeys that not for the generation of subkey or the other Passkey information are used, are to each destination on a variety of delivery routes dispensed, which differ from the routes that for the disposal of Contents (which are the digital data) are used and which further are different from each other.
The Subordinated system provides the encryption key of delivered digital data using either the plurality the subkey or the part of key information and the rest Passkeys or other key information passport restores the above the plurality of delivery routes are issued.
Among Attraction of the example described above, wherein the encryption key in a set of passkeys is divided (for example, three passkeys), is a part of passkeys (eg two passkeys) delivered directly to their destinations, with the remaining passkey (for example, a passkey) further into a plurality of partial keys for a Delivery is divided. All key information is sent to the respective target over submitted itineraries that are different from the routes, which for the delivery the digital data are used and which are further different from each other are.
Here a plurality of pieces of key information on a leave plurality of delivery routes, so that each part of the key information, the are stolen or could be, does not lead to unauthorized tapping of the encryption key, as long as and until all the rest key information is stolen. Since this data delivery system more delivery routes for key information provides, as described above, so that is a higher security against theft given or fraud.
The Distribution rule or protocol or vehicle for generating a set of partial keys on the basis of passkeys is used, may for all Goals together, for the respective target unique or specific to a group of targets be that classified according to geographical or other conditions are. Instead of allocating a portion of the passkeys in subkey the part in question is encrypted by multiple keys. In this case, both the encrypted passkeys and are the encrypting used the passkey Encryption key leave the respective destination. To deliver a part of the pass Keyring is a sel transfer network, and a portion of the partial keys, generating from the remaining passkeys be, will be transmitted the network, and the other Subkey or the subkey information are or will be delivered on a storage medium. The storage medium may transfer any part of the involved key information, and any two different kinds or types of key information can come on two different storage media.
So can For example, part of a set of passkeys and all Subkey, <?page 23?>the from the other Passkeys are generated via transmitted the network will. If all key information about the Network is delivered, are any time limitations minimized in the delivery, and the cost of key information delivery are reduced. In delivering the key information about the Network is preferred, the respective destination by reference to a to authenticate digital certificate, which by means of a public key encoded is that of the candidate destination before delivery of key information is supplied.
According to a another example, part of a set of passkeys and all partial keys from the other generated passkeys are to be delivered on storage media. When all key information is delivered using tangible storage media, is it easier to discover misappropriation of information and immediately countermeasures to meet.
On for the respective specific objectives and / or the digital data specific second encryption key can be used to select either the first encryption key or the key information (Reproduced from the first encryption key can be) encrypted. encrypted first Verschlüsselungsschlüs sel (or the key information) and the second encryption key (or the Key information, from the reproduced second encryption key can be) both to each destination on a variety of delivery routes dispensed, which differ from the routes that for the delivery the contents are being used and which also differ from one another are.
The Subordinated system provides through the first encryption key decipher either the encrypted first encryption key or encrypted key information restore, which is or are fed to it, and on the basis of either of the emitted second encryption key or of the votes the second encryption key information. The restored first encryption key to decrypt the encrypted Contents used.
In the case that the second encryption key for the respective Target is unique or clear, the encrypted Digital data not be decrypted without authorization, unless and until all the key information (ie the second encryption key and the encrypted first encryption key) of the are stolen eligible target. This means that even if the for a Specific target unique second encryption key and the for another object stolen specific encrypted first encryption key are not the first encryption key can be restored. It is quite difficult, if not practically impossible all to steal information before the thief is discovered. This provides a highly resistant System against Try any unauthorized use or even theft of Data. If the second encryption key for the respective Digital data item is unique, then even if the second encryption key and the unencrypted first stolen Ver encryption key are, any injury only to the candidate digital data item limited be (naturally assuming that the encrypted digital data item also is stolen). Needless should be noted that the system further compared with an unauthorized Datenanzapfung would also be resistant, if the second encryption key both for a Specific target as well as a is certain digital data item specific.
Of the first encryption key needs only once by the second encryption key encrypted , although multiple encryptions can be applied. The first encryption key can For example, encrypted be before further using the second encryption key encoded will.
According to a For the dispensing process, the encrypted first encryption key on a transfer network, and the second encryption key is delivered on a storage medium. Alternatively, the first encryption key at transferred to the storage medium are, and the second encryption key can be on the transfer network will.
According to a another example, the encrypted first encryption key using a transmitted first network are, and the second encryption key can via a second transfer network will. Alternatively, the encrypted first encryption key to may be delivered to a first storage medium and the second encryption key be submitted to a second storage medium.
According to a Example of a data delivery system is a set of passkeys (eg three passkeys) generated based on a second encryption key, when the for <?page 24?>on specific goal and / or certain content-specific second Encryption key for encode used the first encryption key becomes; the encrypted first Encryption key (or the first encryption key information) and the set of passkeys (Or passkey information, from which the set of passkeys may be reproduced) are or will be delivered to each destination over a plurality of delivery routes, which are different from the content delivery routes and from each other.
The Subordinated system uses the set of passkeys (or the passkey information) to restore the second encryption key. The recovered second encryption key to decrypt the first encryption key (or the first encryption key information) used. As a result of the first encryption key is restored and decrypting the encrypted Contents used. Preferably, the set of passkeys is better than the second encryption key itself together with the encrypted first of encryption keys each destination on given a number of different delivery routes. Even then, when a part of the key information stolen will lead this consequently not to unauthorized tapping of the encryption key, as long as and not to the rest of the stolen key information is.
Around a set of passkeys based on the second encryption key to generate the second encryption key can accordingly an appropriate distribution rule or according to a suitable protocol, like in old times mentioned, in passkeys be divided. Alternatively, a further encryption key for further encryption the second encryption key for generating passkey be used.
If the second encryption key for a particular Target is unique or clear, the encrypted Digital data as long as not be decrypted until the entire key information is stolen by the respective specific destination (ie the set passkey and the encrypted first encryption key). This leads to a more effective data delivery system.
According to a For this feature, the encrypted first encryption key to given a storage medium; a part of (or alternatively the total) set of passkeys is over transmit a network, and the other Passkeys come on another or other storage medium. If the part of the key information is supplied on tangible storage media, it is easier, a to discover misappropriation of information and immediately countermeasures hold true.
According to a another example, the encrypted first encryption key and the Set of passkeys, generating from the second encryption key are, all over the transfer network will. When all key information about the Network is delivered, are any time limitations with regard to the key delivery minimized, thereby reduced the cost of key information delivery are. Preferably, an encrypted using a public key digital certificate of the candidate destination before delivery of key information delivered to authenticate that target.
Although the present invention with reference to certain preferred embodiments particularly illustrated and has been described should be appreciated be that various changes and modifications without departing from the spirit are made can.
18 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18
14 members in 8 offices
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 2000403471 | Japan | A | |
| 2000403471 | Japan | – | |
| 2001076917 | Japan | A | |
| 2001076917 | Japan | – | |
| 2000403471 | – | – | – |
| 2001076917 | – | – | – |
| JP20000403471 | – | – | – |
| JP20010076917 | – | – | – |
Members14
| Document | Office | Kind | |
|---|---|---|---|
| CA2366262A1 | Canada | A1 | |
| EP1220487A2 | European Patent Office (EPO) | A2 | |
| KR20020055354A | Republic of Korea | A | |
| CN1362811A | China | A | |
| US2002106086A1 | United States of America | A1 | |
| JP2002261746A | Japan | A | |
| EP1220487A3 | European Patent Office (EPO) | A3 | |
| TW550922B | Taiwan Province of China | B | |
| EP1220487B1 | European Patent Office (EPO) | B1 | |
| DE60115188D1 | Germany | D1 | |
| DE60115188T2This record | Germany | T2 | |
| KR100840824B1 | Republic of Korea | B1 | |
| US7421082B2 | United States of America | B2 | |
| CN100442690C | China | C |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| No opposition during term of oppositionOpposition8364 | 8364 |
Numbers
- Publication
- 60115188
- Publication, DOCDB
- 60115188
- Publication, EPODOC
- DE60115188T
- Application
- 60115188
- Application, DOCDB
- 60115188
- Application, EPODOC
- DE20016015188T
Titles2
- German
- Verfahren und Vorrichtung zur verschlüsselten Datenübermittlung
- English
- Method and apparatus for encrypted data transmission
Classification
- CPC, 13
- H04N21/2541
- H04L9/00
- G11B20/00086
- G11B20/0021
- H04N5/913
- H04N7/162
- H04N7/1675
- H04N7/17345
- H04N21/2347
- H04N21/4405
- H04N21/63345
- H04N21/835
- H04N2005/91364
- IPC, 16
- H04L9 08
- G06F21 00
- G06F21 10
- G06F21 16
- G06F21 62
- G11B20 00
- H04L9 00
- H04N5 913
- H04N7 16
- H04N7 167
- H04N7 173
- H04N21 2347
- H04N21 254
- H04N21 4405
- H04N21 6334
- H04N21 835
