System for keying protected electronic data to particular media to prevent unauthorized copying
19 claims: 2 independent, 17 dependent
- 1Verfahren zum elektronischen Verteilen elektronischer Daten von einem Server ( 16 ) über eine Netzwerkinfrastruktur ( 12 ) an eine Clientvorrichtung ( 20 , 22 ), wobei das Verfahren einen einzigartigen Bezeichner für ein Medienexemplar ( 28 ) verwendet, um die elektronischen Daten nur dem einen Medienexemplar ( 28 ) zuzuordnen, wobei das Verfahren umfasst:Aufbauen einer Verbindung ( 200 ) zwischen der Clientvorrichtung ( 20 , 22 ) und dem Server ( 16 ) über die Netzwerkinfrastruktur ( 12 ), Übertragen ( 304 ) des einzigartigen Bezeichners für das eine Zielmedienexemplar ( 28 ) über die Netzwerkinfrastruktur ( 12 ) an den Server ( 16 ), Verschlüsseln ( 308 ) der an die Clientvorrichtung ( 20 , 22 ) zu übermittelnden elektronischen Daten an dem Server ( 16 ), Übermitteln der elektronischen Daten über die Netzwerkinfrastruktur ( 12 ) an die Clientvorrichtung ( 20 , ?page 18? 22 ), wobei die elektronischen Daten in einem verschlüsselten Format vorliegen, und Schreiben ( 310 ) der elektronischen Daten an der Clientvorrichtung ( 20 , 22 ) auf das eine Medienexemplar ( 28 ), so dass auf die Information zur Verwendung nur von dem einen Zielmedienexemplar ( 28 ) aus zugegriffen werden kann;wobei das Verschlüsseln ( 308 ) der an die Clientvorrichtung ( 20 , 22 ) zu übermittelnden elektronischen Daten das Verschlüsseln zumindest der elektronischen Daten oder eines Verschlüsselungsschlüssels für die elektronischen Daten umfasst, wobei das Verschlüsseln den einzigartigen Bezeichner als Verschlüsselungsschlüssel verwendet.
- 2Verfahren nach Anspruch 1, bei dem das Übertragen ( 304 ) des einzigartigen Bezeichners an den Server ( 16 ) umfasst:Zugreifen auf das eine Zielmedienexemplar ( 28 ), Lesen ( 322 ) des einzigartigen Bezeichners von einer vorbestimmten Stelle auf dem einen Zielmedienexemplar ( 28 ), und Formatieren des einzigartigen Bezeichners in eine erste Datenstruktur für die Kommunikation mit der Clientvorrichtung ( 20 , 22 ).
- 3Verfahren nach Anspruch 2, bei dem die vorbestimmte Stelle auf dem einen Zielmedienexemplar ( 28 ) eine vorbestimmte Spur ist.
- 4Verfahren nach einem der Ansprüche 1 bis 3, das weiter das Übermitteln zusätzlicher Information an den entfernten Server ( 16 ) umfasst.
- 5Verfahren nach Anspruch 4, bei dem die zusätzliche Information zumindest eine Käuferidentifikation, eine Adresse, eine Telefonnummer oder eine Zahlungsinformation enthält.
- 6Verfahren nach einem der Ansprüche 1 bis 5, das weiter umfasst:Übermitteln zusätzlicher Information an den entfernten Server ( 16 ) und Verschlüsseln der zusätzlichen Information gemeinsam mit den elektronischen Daten, wobei die zusätzliche Information zumindest einen Käufernamen, eine Adresse, eine Telefonnummer oder eine Zahlungsinformation enthält.
- 7Verfahren nach einem der Ansprüche 1 bis 6, bei dem die Verschlüsselung unter Verwendung des Blowfish-Algorithmus durchgeführt wird.
- 8Verfahren nach einem der Ansprüche 1 bis 7, bei dem die elektronischen Daten in einem verschlüsselten Format auf das eine Zielmedienexemplar ( 28 ) geschrieben werden, wobei der einzigartige Bezeichner als Entschlüsselungsschlüssel verwendet wird.
- 9Verfahren nach einem der Ansprüche 1 bis 8, bei dem das Aufbauen einer Verbindung zwischen der Clientvorrichtung ( 20 , 22 ) und dem Server ( 16 ) über die Netzwerkinfrastruktur ( 12 ) umfasst:Schicken eines Formulars von der Clientvorrichtung ( 20 , 22 ) an den Server ( 16 ), Ausführen eines Programms zum Bearbeiten des Formulars an dem Server ( 16 ), und Schicken eines Metatags und einer Transaktionsdatei an die Clientvorrichtung ( 20 , 22 ).
- 10Verfahren nach Anspruch 9, bei dem das Metatag und die Transaktionsdatei in der Clientvorrichtung ( 20 , 22 ) ein Clientprogramm aufrufen, nachdem sie zu der Clientvorrichtung ( 20 , 22 ) gesendet wurden.
- 11Verfahren nach Anspruch 10, bei dem das Clientprogramm die Transaktionsdatei öffnet und Metadaten von Metatags in der Transaktionsdatei parst.
- 12Verfahren nach Anspruch 11, bei dem das Clientprogramm eine Verbindung zu einer Serveradresse herstellt, die von einem vorbestimmten Metatag in der Transaktionsdatei identifiziert wird, um die elektronischen Daten zu empfangen.
- 13Verfahren nach Anspruch 12, bei dem die Serveradresse dynamisch verändert wird, wenn die elektronischen Daten von dem Server angefordert werden.
- 14System zum Verteilen elektronischer Daten über eine Netzwerkinfrastruktur ( 12 ) mit zumindest einer Clientvorrichtung ( 20 , 22 ) zum Betrieb durch einen Benutzer, der elektronische Daten zu emp ?page 19? fangen wünscht, zumindest einem Server ( 16 ), wobei der zumindest eine Server ( 16 ) die elektronischen Daten enthält und die elektronischen Daten anbietet zum Herunterladen an die zumindest eine Clientvorrichtung ( 20 , 22 ) über die Netzwerkinfrastruktur ( 12 );wobei die zumindest eine Clientvorrichtung ( 20 , 22 ) so ausgebildet ist, dass sie dem zumindest einen Server ( 16 ) einen einzigartigen Bezeichner übermittelt, wobei der einzigartige Bezeichner einem bestimmten Medienexemplar ( 28 ) zugeordnet ist, auf das die elektronischen Daten gespeichert werden sollen, der zumindest eine Server ( 16 ) so ausgebildet ist, dass er die elektronischen Daten unter Verwendung des einzigartigen Bezeichners als Schlüssel verschlüsselt und die verschlüsselten elektronischen Daten an die zumindest eine Clientvorrichtung ( 20 , 22 ) herunterlädt, und die zumindest eine Clientvorrichtung ( 20 , 22 ) so ausgebildet ist, dass sie die verschlüsselten elektronischen Daten auf das bestimmte Medienexemplar ( 28 ) schreibt, so dass auf die verschlüsselten elektronischen Daten nur von dem bestimmten Medienexemplar ( 28 ) aus zugegriffen werden kann.
- 15System nach Anspruch 14, bei dem die zumindest eine Clientvorrichtung ( 20 , 22 ) weiter so ausgebildet ist, dass sie ein Formular an den zumindest einen Server ( 16 ) schickt, wobei das Formular von dem zumindest einen Server ( 16 ) bearbeitet wird, und der Server ( 16 ) so ausgebildet ist, dass er ein Metatag und eine Transaktionsdatei an die Clientvorrichtung ( 20 , 22 ) übermittelt.
- 16System nach Anspruch 15, bei dem das Metatag und die Transaktionsdatei so ausgebildet sind, dass sie in der zumindest einen Clientvorrichtung ( 20 , 22 ) ein Clientprogramm aufrufen, nachdem sie zu der zumindest einen Clientvorrichtung ( 20 , 22 ) übermittelt wurden.
- 17System nach Anspruch 16, bei dem das Clientprogramm so ausgebildet ist, dass es die Transaktionsdatei öffnet und Metadaten von Metatags in der Transaktionsdatei parst.
- 18System nach Anspruch 17, bei dem das zumindest eine Clientprogramm so ausgebildet ist, dass es eine Verbindung zu einer Serveradresse herstellt, die von einem vorbestimmten Metatag in der Transaktionsdatei bezeichnet wird, um die elektronischen Daten zu empfangen.
- 19System nach Anspruch 18, bei dem die Serveradresse von dem zumindest einen Server dynamisch verändert wird, wenn die elektronischen Daten von dem zumindest einen Server angefordert werden.
Independent claims19
102 paragraphs in 4 sections, as filed
FIELD OF INVENTION
the present invention relates to preventing unauthorized Copying by assigning electronic data at a specific Item of recorded media. In particular, referred to in this Invention relates to a data transmission system, at the protected the transmitted electronic data in a secure manner on a local machine be that protected the Stores data and on the basis of a unique key Medium permanently a particular storage media copy maps.
Of the Protection by copyright or otherwise protected digitally stored Data has always been a major concern of the owner of such material. Especially Piracy of computer software, music and video has been and continues of great Importance as it almost impossible is to stop. Although several previous attempts by the software, Music and video industry has been to limit piracy, was each granted a limited success.
As Part of the effort to combat piracy, software vendors have Software licensed, rather than transfer the property purchase. When software is purchased, the buyer is more of a licensed Users (ie the licensee) as an owner. Copying Software is among the most license agreements generally only a copy of Security purposes limited to limit legally unlimited copying. In addition, the software license grants typically a right to use the software on a single computer, or for use by only one user at a time.
software provider have also tried to software piracy by copying protecting their to combat software. While this attempt in a certain scale was effectively failed he, because the user could make no backup copy. As well were soon after the first copy-protected software on the computer Market was, other programs for copying of copyrighted software available. In an attempt to stop piracy, then other copyright protection procedures were developed - also with limited success. These attempts included the request, a master disk to insert into the computer, or any requirement to the user, a key or enter other information in the User's Manual or the License Agreement were included if the software from the computer's hard disk carried out has been. Other required again that a hardware key to was the parallel port on your computer exists, the read was when the software is executed has been. Software vendors were given a temporary reprieve, as CD-ROMs, the standard medium for the digital storing and distributing software was because the Applications were so great that the only way to copy the software, the "burning" of duplicates on expensive recordable CDs was. Prices of recordable CDs and for the drives for writing recordable CDs, however, are dramatically fallen, and pirates can Restore cheap illegal copies of protected software.
the Music and video industry has a different concern than the software vendors. These industries are particularly affected by pirates, the perfect Copies digitally stored music and videos customize. While the Copying music and video for non-commercial purposes is permitted, such copying was earlier performed by cassette recorders and VCRs, the use analog recording techniques. Analog reproduction results in a declining quality with each generation, while digital copies are exact and do not suffer any loss of quality. As noted are the prices of recordable CD and for the drives to describe writable CDs fallen dramatically, and these drives can also easily record music on the CDs as software and data record. further, by the advent of the DVD (Digital Versatile Disc) is now in films full length are recorded on a single DVD. Therefore also the Music and video industry, an increasing need to copy digital to prevent recorded works.
The rapid growth of the digital age and the global communications promotes the concerns of the software providers and the music and video industry. In the early 1980s when the personal Computer (PC) were in their infancy and the software provider for the first time tried to protect their intellectual property, were it - if at all - a few Mass distribution channels. At the same time, the music and video industry was on the plane of the consumer analog strictly. Thus, piracy was not a major factor because it was limited to small groups of people or organizations. However, with powerful Computers on every desk and in the development of music and Video in a digital format was piracy <?page 3?>a main factor Software vendors alone per year worldwide $ 4 billion cost. Obviously, the financial loss for software developers, musicians, Actors and their associated industry immensely.
At the root of the spread of global communication is the rapid growth of the Internet, which the piracy problem to the forefront pressed Has. As is known, the term "Internet" first used in 1982, to the enormous together denote collection of interconnected networks that use TCP / IP protocols (Transmission Control Protocol / Internet Protocol). Although It found only in the last four years, a mass recognition has, the Internet has existed since the later 1960s and was originally as a WAN (Wide Area Network) designed survive a nuclear war would. The 1970s and 1980s through developed an increasing Number of small networks that via gateways to the Internet were connected, as means for exchanging electronic mail. In the mid-1980s, there was a significant increase in the number of available Internet hosts, and since the late 1980s has been exponentially the growth of the Internet. The growth the internet has people everywhere in the value of an agent provided information together to use and distribute. Thus, now there is the potential for mass distribution pirated software, music and video on a global scale. Lots Internet Usenet groups and channels on the Internet Relay Chat (IRC) are doing with pirated dedicated files, music and videos. Groups which have a high profile preserve and a large degree of have pride in their piracy services, promote the piracy problem continue. The piracy problem has grown so large that a new Term "warez" to describe the pirates and their activities is used. The Internet has now given its size, speed and penetration into homes the end user a large potential for legitimate sale and distribution of protected software, music and videos. However, precisely these advantages make it easy for pirates, expensive proprietary software To steal the cost to develop and produce year, and for a matter of hours anyone freely available to companies to make.
the WO9635158 A disclosed a management method and apparatus for Copyright Protection of programs on demand (programs on demand). The method and the device enable the distribution of electronic data, but the data are not good protected, since they are not encrypted are.
the EP-A-0665486 teaches a method of protecting electronically published Material using cryptographic protocols. This However, method uses a known complex and heavy Protocol to encrypt the data, the user must provide an identifier system and the system returns a secret key. If someone this secret key illicitly obtained, can protected Data can be easily viewed or displayed. In addition, the data in the Receiving by the user decrypts the then copy may or distribute.
in the View of the above there is a need for a safe Method and apparatus for the Electronic distribution of data from the wide dissemination will depart from networks such as the Internet benefits, while at the same prevents unauthorized and illegal copies of protected works, data and applications will. In particular, there is a need for a method and a device, the provider of software, music and videos with a secure means provided for electronically distributing their works and applications via the great Networks while it ensures that its protected Works and applications are not copied and pirated. Such a Method and apparatus would also ensure that the rights of owners of intellectual property are protected and that the owners of their creative efforts to be compensated properly.
SUMMARY THE INVENTION
in the View of the above, the present invention thus by one or more of its various aspects and / or embodiments presents, the remarked to one or more objects and advantages as the bottom to achieve.
According to the present Invention, there is provided a method for electronically distributing electronic Data from a server to a client device via a Network infrastructure. This method uses a unique identifier for a media copy to the electronic data only one media copy assigned. The method comprising: setting up a connection between the client device and the server over the network infrastructure; transmitting the unique identifier of a target media copy to the Server; encrypting the information to be provided to the client electronic data; transmitting the electronic data to the client device, wherein the electronic Data in an encrypted present format; and writing the electronic data on<?page 4?>the a media copy, so that the information for use Only one target media item may be accessed, wherein encrypting the to sent to the client device electronic data encrypting at least the electronic data or an encryption key for the electronic includes data, said encrypting the unique identifier used as an encryption key.
correspondingly a feature of the invention comprises transmitting the unique Identifier to the server: accessing one destination media copy, reading the unique identifier of a predetermined Site on a target media copy and formatting the unique Identifier in a first data structure for communication with the Client device. The predetermined location on a target media copy may be a predetermined track. Additional information may at forwarded to the remote server are, for example, a buyer identification, an address, a telephone number and payment information. In addition, the additional Information may be encrypted together with the encrypted data.
correspondingly yet another feature of the present invention comprises Establishing a connection between the client device and the Server via the network infrastructure: sending a form to the server, performing a program for editing the form and sending a Metatag and transaction file. The meta tag and the transaction file can are used in the client device, a client program to start after they have been sent to the client device. also can the client program to open the transaction file and metadata from metatags parse in the transaction file. The client may be a server address connect, by a predetermined metatag in the transaction file is identified to receive the electronic data, and Server address can be changed dynamically , when the electronic data is requested from the server will.
correspondingly In another aspect of the present invention is a method provided for accessing electronic data on a Medium is stored, by a first device for reading is adapted to the medium, wherein the electronic data in a encrypted Format have been written on the medium. The method includes accessing the electronic data on the media, reading a unique identifier of the media, reading a portion of the electronic data from the media, and decrypting the electronic data using the unique identifier as decryption keys.
correspondingly a feature of the present invention comprises the reading of the unique Designator reading the unique identifier of a predetermined Track of the medium. Reading the unique identifier of the medium may further transmitting contain the unique identifier to a second device, and reading at least a portion of the electronic data further includes communicating the Portion of the electronic data to the second device, wherein the second device decrypting the electronic data performs as a decryption key using the unique identifier.
correspondingly another feature, the method may further comprise: transmitting an authentication code to the first device, the reading the unique identifier of the medium, comparing the Authentication code with the unique identifier, and, when the authentication code is the unique identifier equal, generating a verification code, which transmits to the second device becomes.
correspondingly yet another feature, the method may further include: reading a predetermined string from the media, the decryption of the predetermined string, comparing the predetermined string with a known string and stopping the process when the predetermined character string is not equal to the known string is.
correspondingly a further aspect of the present invention is a system provided for distributing electronic data via a network structure, with: at least one client device for operation by a user, wants to receive the electronic data, and at least one Server that contains the electronic data and the electronic data for downloading to the at least one client device via the Network infrastructure offering. The client device transmits the at least one server a unique identifier, which associated with the unique identifier to a particular media copy is where the electronic data is to be stored. The server encrypts the electrostatic<?page 5?>African data using the unique identifier as a key and invites the encrypted electro African Data to the at least one client computer and the client computer writes the encrypted electronic data on the specific media copy so on the encrypted electronic Data can only be accessed by the particular media copy.
correspondingly a feature of the present invention sends the client device Further, a form to the at least one server, wherein the form of the at least one server is processed and the server is a Metatag and transaction file to the at least one client sends. The meta tag and the transaction file launch on the client device a client program that they have been sent to the client. further, the client program to open the transaction file metadata from metatags in the transaction file parsing and connect to a server address, the designated by a predetermined metatag in the transaction file is to receive the electronic data. The server address can be changed by the at least one server dynamically, if the electronic data is requested from the at least one server will.
correspondingly yet another aspect of the present invention, a device is provided for reading encrypted electronic data, by a unique identifier is included on the media instance, associated with a media copy are, with a processor, the instructions for reading electronic Data and the unique identifier of the media a copy controls and executes and a media drive, responsive to the processor and to unique identifier and the electronic data from the one Media copy reads. The electronic data for use through the device or other device that is connected to the device, using the unique identifier decrypted data as key, and The data can only from the one copy media with which a zigartigen Identifiers are accessed, and the data can not access other media with another or no identifier will. The unique identifier may be based on predetermined Track of a storage medium can be arranged.
According to a another feature of the present invention the device contains an application specific integrated circuit that performs the decryption. The device can further include an analog to digital converter, wherein the application-specific integrated circuit decompresses the data and electronic the analog-to-digital converter, the decompressed electronic data converts it into audio signals.
correspondingly yet another feature of the present invention, the media drive further an application specific integrated circuit, the application-specific integrated circuit of the media drive performs decryption by, and the decrypted electronic data is passed to the device.
correspondingly yet another feature of the present invention reads the Media drive a predetermined string of the medium, and decrypts the processor the predetermined character string and compares the predetermined string with a known string, and the unit is stopped when the predetermined string does not coincide with the known string.
correspondingly yet another aspect of the present invention, a device is provided for reading encrypted electronic data by an on a media copy assigned unique identifiers contained a media copy are. The device is connected to a general purpose computer, the media drive having the unique identifier and the electronic Data from one media copy reads. The device contains a application specific integrated circuit, the instructions to Receiving the electronic data and the unique identifier controls from the general-purpose computer and executes. The electronic data are for use by the device using the unique Identifier as data key decrypted and the data can be accessed only from one media copy are having the unique identifier, and the data can not be accessed from any other medium, that has a different or no identifier. The unique identifier may be located on a specific track of a media copy.
correspondingly a feature of the present invention performs the application specific integrated circuit decryption through. The device can further an analog-to-digital converter included, wherein the application specific integrated circuit the electronic data is compressed, and the analog-to-digital converter which decompressed electronic data into audio signals.
<?page 6?>
correspondingly yet another aspect of the present invention reads the media drive a predetermined character string from the medium, and the application-specific decrypted integrated circuit the predetermined character string and compares the predetermined string with a known string, and the unit is stopped when the predetermined string does not equal the known string is.
Other Features of the invention are described below.
SUMMARY THE DRAWINGS
the foregoing summary and the following detailed description of the Preferred Embodiments will be better understood when considered in conjunction with the accompanying drawings is read. is for the purpose of illustrating the invention in the drawings an embodiment shown, which is currently preferred in which the same reference numerals throughout the several views of the drawings similar Parts denote, but it is clear that the invention is not is limited to the disclosed specific methods and instrumentalities. In the drawings:
<figref idrefs="S46">1</figref> a exemplary computer network environment in which the present invention can be implemented;
<figref idrefs="S47">2</figref> a Block diagram of the components of an in <figref idrefs="S46">1</figref> shown Client PCs / workstations;
<figref idrefs="S48">3</figref> a Block diagram of the components of an in <figref idrefs="S47">2</figref> shown preferred media drive;
<figref idrefs="S49">4</figref> a Block diagram of the components of an exemplary in <figref idrefs="S46">1</figref> shown Single device;
<figref idrefs="S50">5</figref> a Block diagram of the components of an exemplary in <figref idrefs="S46">1</figref> shown Decryption / decompression;
<figref idrefs="S51">6</figref> a Flow chart an overview over the in the electronic distribution of data according to the present implemented invention operations shows;
<figref idrefs="S52">7</figref> a Flow chart of the operations during the a communication session between a client and a server for requesting and downloading data according to the present performed invention will;
<figref idrefs="S53">8</figref> a exemplary format of a file containing parameters which passed to a client program be that controls a data downloading process;
<figref idrefs="S54">9</figref> a Flow chart of the operations of the PC / workstation or individual machines during Reading / performing / reproducing protected performed data will; and
<figref idrefs="S55">10A</figref> and <figref idrefs="S56">10B</figref> flowcharts of operations, of the decryption / decompression while reading / reproducing of data are performed.
DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
the present invention provides a secure method for transferring ready sensitive and protected electronic data (protected Contents) from a remote server over a network infrastructure to a client computer or a single device and for preventing the unauthorized distribution and copying of data after they transmitted to the client computer or the single device has been. The term "data" as this is used, comprises all the information on a storage medium can be stored, including executable Files linked library files, data files, database files, Audio files and video files, but not limited thereto.
With in reference to <figref idrefs="S46">1</figref>-<figref idrefs="S50">5</figref> will an exemplary non-limiting Surroundings <figref>10</figref> shown and devices in which the present Invention may be implemented. As in<figref idrefs="S46">1</figref> shown, contains the environment <figref>10</figref> a Remote Network Infrastructure <figref>12</figref> (WAN = Wide Area Network). The WAN infrastructure <figref>12</figref> can a TCP / IP network (Transmission Control Protocol / Internet Protocol) such as the Internet ent <?page 7?>hold. With the WAN infrastructure<figref>12</figref> can via communication lines <figref>24</figref> a or more local area networks <figref>14</figref> (LAN = Local Area Network), server <figref>16</figref>, Internet service provider <figref>18</figref> (Internet Service Provider) and individual devices <figref>22</figref> be connected to the Protocols of the WAN infrastructure <figref>12</figref> are compatible. As can be displayed with the LAN <figref>14</figref> and the ISP <figref>18</figref> Client PCs / Workstations <figref>20</figref> and or Single devices <figref>22</figref> be connected, via the LAN <figref>14</figref> or the ISP <figref>18</figref> on the network infrastructure access and which are capable of at least data on a removable medium <figref>28</figref> access and read it. Also shown is a data decryption / decompression <figref>30</figref>. with a PC / Workstation <figref>20</figref> connected is.
The LAN <figref>14</figref> may comprise an Ethernet or Token Ring Network and a server <figref>16</figref> and a (not shown) having gateway, the above one or more communication links <figref>24</figref> a connection with the network infrastructure <figref>12</figref> provides. The communication links<figref>24</figref> to remote systems can wireless connections, satellite links or assigned his lines.
Of the server <figref>16</figref> can as a UNIX or Windows NT Server -based computer platform having one or more processors (Eg Intel Pentium II processor, Digital Equipment Company Alpha RISC processor or Sun SPARC processor) contain long-term storage (eg a RAID disk array), a random access memory (RAM), communication peripherals (Eg, network interface card, modem and / or terminal adapter) and Application programs (eg, database software applications, World Wide Web publishing / hosting software and inventory management software) which can be used, to provide information to the client PC / workstations <figref>20</figref>, the Single devices <figref>22</figref> and other servers <figref>16</figref> to to distribute. The servers<figref>16</figref> Can be defined as WWW server (World Wide Web), FTP server (File Transfer Protocol), Email Server (Electronic Mail) may be configured so.
Of the ISP <figref>18</figref> is typically an organization or a service, of over a (not shown) server via communication links <figref>24</figref> With is connected to the Internet, access to the Internet (the Network Infrastructure <figref>12</figref>) Returns. In the exemplary embodiment of <figref idrefs="S46">1</figref> can the client PC <figref>20</figref> or the single device <figref>22</figref> a dial up connection <figref>26</figref> (Via the public switched telephone network) use to deal with the ISP <figref>18</figref> to connect.
the Client PCs <figref>20</figref> can personal Computer based on Windows 95, Windows 98 or Windows NT Workstation include that or an Intel Pentium processor higher, Long-term storage (eg an IDE or SCSI hard disk), a drive for removable Media (eg CD-R, DVD-RAM or other removable floppy or hard disk drives), random access memory (RAM), communication peripherals (Eg, network interface card, modem and / or terminal adapter) and appropriate application programs (eg Wählnetzwerkverbindungssoftware and a web browser) have. When configured as a workstation, can workstations <figref>20</figref> eg UNIX-based IBM RS / 600 or SUN SPARCstation workstations include. Further, the client PC / Workstations<figref>20</figref> the include so-called "network computing devices".
On Block diagram of an exemplary PC workstation is in <figref idrefs="S47">2</figref> shown. As shown, the PC / Workstation's internal and external components divided up. The internal components include a BIOS<figref>70</figref> (Basic Input / Output System), and a processor <figref>66</figref> (CPU), the the overall operation of the PC / Workstation <figref>20</figref> control. A memory<figref>64</figref>. a hard disk drive <figref>76</figref>, A floppy disk drive <figref>74</figref>. a tape drive <figref>78</figref>, A modem / terminal adapter / network interface card <figref>82</figref> and a drive <figref>52</figref> For a removable medium (removable drive) are also to the CPU <figref>66</figref> connected. The Removable Drive<figref>52a</figref> or <figref>52b</figref> is working for reading and / or writing to a storage medium in a removable memory cartridge is included. The exemplary PC / Workstation <figref>20</figref> of <figref idrefs="S47">2</figref> is with two removable media drives <figref>52a</figref> and <figref>52b</figref> built up, to emphasize that a removable media drive as both internal can also be realized in external form.
the Modem / terminal adapter / network interface card 82 may, as in art contain known individual cards with the Communication related Function perform. The modem / terminal adapter / network interface cards <figref>82</figref> are in the PC / Workstation <figref>20</figref> included to communications provide to external networks with which the PC / Workstation <figref>20</figref> connected is. In particular, the modem / terminal adapter / network interface card<figref>82</figref> used in order to the LAN <figref>14</figref>, The ISP <figref>18</figref> and the Network Infrastructure <figref>12</figref> access.
the Communication between internal and external devices can controller be accomplished in the PC / Workstation <figref>20</figref> provided are. An interface controller for serial / parallel / USB<figref>58</figref><?page 8?>(of the may comprise a plurality of separate controllers), a screen controller <figref>60</figref> (Video card) and a keyboard and mouse controller <figref>62</figref> each provide an interface between the CPU <figref>66</figref> and an external Removable Drive <figref>52b</figref> (Or printer), a monitor <figref>54</figref> and a keyboard and mouse device <figref>56</figref> ready. A disk and floppy controller <figref>72</figref> serves as an interface each between the CPU <figref>66</figref> and the hard disk <figref>76</figref>, the CD-ROM drive <figref>80</figref>. the disk <figref>74</figref> and the tape drive <figref>78</figref>, For in the Technique versed is understood that the disk controller <figref>72</figref> separate may include floppy and hard disk controller (eg IDE or SCSI controller).
On Removable Storage Controller <figref>68</figref> serves as an interface between the Removable Drive <figref>52a</figref> and the CPU <figref>66</figref>, The Removable Storage Controller <figref>68</figref> can as a SCSI controller (Small Computer System Interface) or an IDE interface controller (Integrated Drive Electronics) included. A hard and floppy controller<figref>72</figref> serves in each case as an interface between the CPU <figref>66</figref> and the hard disk <figref>76</figref>. the CD-ROM drive <figref>80</figref>. the disk <figref>74</figref> and the tape drive <figref>78</figref>, alternative , the removable media drive <figref>52a</figref> the disk controller <figref>72</figref> as Interface to the CPU <figref>66</figref> use.
With in reference to <figref idrefs="S48">3</figref> there is shown a block diagram of an exemplary media drive <figref>52</figref> with a SCSI interface to the PC / Workstation <figref>20</figref> (Via the controller <figref>68</figref>) shown.
The Media Drive <figref>52</figref> contains preferably a ZIP<sup>®</sup>Drive prepared by IOMEGR Corporation, Roy, Utah; however, other media drives as media drive <figref>52</figref> be used. The media drive<figref>52</figref> includes components, the communication between the read / write channel for the medium (Lower right side of the diagram) and the PC / Workstation <figref>20</figref> (upper provide left side of the diagram). The media drive<figref>52</figref> contains a AIC chip <figref>101</figref>, Of the functions of the SCSI <figref>102</figref>, of direct memory access <figref>103</figref> (DMA = Direct Memory Access) and Plattenformatierers <figref>104</figref> performs. The interface also contains a Phaedrus <figref>105</figref>, Of a 8032-microcontroller <figref>106</figref>, A 1-kbyte RAM <figref>107</figref> and an application specific integrated circuit <figref>108</figref> (ASIC = Application Specific Integrated Circuit) contains. The ASIC<figref>108</figref> can perform various functions such as the Servosequenzieren, the data splitting, EOC, ENDEC, A / D- and D / A conversion. Communication between the media drive<figref>52</figref> and the PC / Workstation <figref>20</figref> is by transferring data between the input / output channel of the Media Drive <figref>52</figref> and the media controller <figref>68</figref> (Eg SCSI controller) of the PC / Workstation <figref>20</figref> realized.
With Referring back on <figref idrefs="S46">1</figref> , the single device <figref>22</figref>, as it is used, except the "traditional" computing devices (Eg PCs, workstations, network computer or termi nals) any device include those having the network infrastructure <figref>12</figref><sub>W</sub>can echselwirken. The single device<figref>22</figref> can eg Devices contain as WebTV<sup>®</sup>Available from WebTV Networks, Palo Alto, California, a music or video player etc. It should be noted that the single apparatus not having a Communication link to the network infrastructure, the LAN or be the ISP provided needs.
On Block diagram of an exemplary single device <figref>22</figref> is in <figref idrefs="S49">4</figref> shown. The exemplary single device<figref>22</figref> includes a removable media drive <figref>52a</figref>. a removable media controller <figref>68</figref>, A CPU <figref>66</figref>, a ASIC / Controller <figref>36</figref>, A digital / analog converter <figref>38</figref>. a ROM <figref>37</figref> and RAM <figref>39</figref>, As stated by one in the Technology versed be appreciated, the single device <figref>22</figref> of <figref idrefs="S49">4</figref> as "Player" or "Viewer" of the protected data work, in which the protected Data from the medium <figref>28</figref> to be read. The Removable Drive<figref>52a</figref>. Removable Storage Controller <figref>68</figref> and the CPU <figref>66</figref> work respectively as in the PC / Workstation <figref>20</figref> of <figref idrefs="S46">1</figref>-<figref idrefs="S48">3</figref> described. The ROM <figref>37</figref> contains Instructions to control the operation and functions of the individual device <figref>22</figref> to control. The ASIC / Controller<figref>36</figref> can be used, the protected to decrypt data and digital audio and / or video signals (for example, PCM = Pulse Code Modulation) for converting into analog audio or video signals to the digital / analog converter <figref>38</figref> output.
With Referring back on <figref idrefs="S46">1</figref> is a decryption / decompression <figref>30</figref> according to the present invention is shown, with the PC <figref>20</figref> connected is to read / play / execute the protected perform electronic data. The decryption / decompression <figref>30</figref> differs from the single device <figref>22</figref> the fact that the decryption / decompression <figref>30</figref> not with a device (for example, the removable media drive <figref>52</figref>) for reading the medium <figref>28</figref> is provided, but it receives more Data from the PC / Workstation <figref>20</figref> read and transmitted were.
With in reference to <figref idrefs="S50">5</figref> there is shown a block diagram of an exemplary decryption / decompression <figref>30</figref> shown. The decryption / decompression <figref>30</figref> can eg a USB connection (Universal Serial Bus), a parallel port or a serial interface with the PC / Workstation <figref>20</figref> connected be to the protected electronic data from the PC / Workstation <figref>20</figref> to <?page 9?>receive, and they can analog communication lines <figref>42</figref> analog audio and video signals output to an external analog input device such as a Stereo amplifier, a television, a video cassette recorder or a sound card. The decryption / decompression <figref>30</figref> contains a controller for USB / parallel / serial port <figref>34</figref>, An ASIC / Controller <figref>36</figref>. a digital-to-analog converter <figref>38</figref> and RAM <figref>39</figref>, The controller for USB / parallel / serial port <figref>34</figref> connects to the USB / parallel / serial port of the PC / Workstation <figref>20</figref> via lines <figref>32</figref> at, to communications between the decryption / decompression <figref>30</figref> and the PC / Workstation <figref>20</figref> provide. The controller for USB / parallel / serial port<figref>34</figref> makes also for data communication between the PC / Workstation <figref>20</figref> and the ASIC / Controller <figref>36</figref>, The ASIC / Controller<figref>36</figref> can protected decrypt data and digital audio and / or video signals (for example, PCM = Pulse Code Modulation) for converting into analog audio signals at the digital / analog converter <figref>38</figref> transfer.
alternative , the decryption / decompression <figref>30</figref> as be provided card in the PC / Workstation <figref>20</figref> installed is. So a decryption / decompression<figref>30</figref> can with the PC / Workstation <figref>20</figref> about the internal bus (eg ISA, PCI or AGP), the PC / Workstation <figref>20</figref> communicate instead of the USB / parallel / serial port. Furthermore, the Entschlüs would selungs / decompression<figref>30</figref> in This alternative structure to be provided with an interface, to communicate with the internal bus of the PC <figref>20</figref> to enable.
It should be noted that the exemplary environment and devices, in the <figref idrefs="S46">1</figref>-<figref idrefs="S50">5</figref> are shown, are not limited to the illustrated environment, since it intends is that other network infrastructures, network connections and Devices within the scope and spirit of the present invention lie.
With in reference to <figref idrefs="S51">6</figref> there is an overview of the operations shown that the corresponding electronic distribution model carried out the present invention will. As the in the art versed is obvious to the Features and aspects of the present invention by any suitable implemented combination of hardware, software and / or firmware will. According to the present invention, the Network server or servers <figref>16</figref> Data such as application software, database tables, Music, Video, etc. save for distribution to clients <figref>20</figref> and or Single devices <figref>22</figref>, While the present invention to all types of data transmissions is applicable, it is especially applicable to commerce over the Internet and in particular the electronic distribution and delivery software, music and Video data.
Of the User starts the process for distributing electrical data step <figref>200</figref>If he or she is using a personal Computers <figref>20</figref> home or a single device <figref>22</figref> Software, Music or videos (ie protected wants to buy electronic data). protected electronic data for sale for a fee for example from a World Wide Web site (World Wide Web) provided on one of the servers <figref>16</figref> home is offered and, using a credit card, a debit card a smart card, Virtual Cache to buy so. To this end Home users can over an Internet browser such as Internet Explorer, the Microsoft, Redmond, WA Available is, with the Web site to connect (step <figref>202</figref>), by enters the URL (Universal Resource Locator) or a hypertext link clicks, which contains the URL of the WWW site. The URL can as a IP address (Internet Protocol, for example 147.178.20.151) or a domain name (Eg "sitename.com") contain the identifies the IP address of such a site, so that the browser can establish a TCP / IP connection. If it is once connected, leads the User a choice of on his or her PC <figref>20</figref> downloaded protected electronic data (step <figref>204</figref>), And the WWW server begins the download process (Step <figref>206</figref>) in connection with auxiliary applications that run on the client PC / Workstation <figref>20</figref> run under Using well-known protocols (eg, HTTP).
correspondingly of the present invention, the downloaded protected electronic data while encrypted to start download using a unique identifier (eg, serial number) the medium <figref>28</figref> as an encryption key and directly to the media <figref>28</figref> downloaded. The encrypted protected electronic data are then by the unique identifier the medium <figref>28</figref> assigned and they can not by a any other medium of access, the other one or no unique identifier has. As described below will be that data in reproducing / Run / View to protected electronic data in a PC <figref>20</figref>, A single device <figref>22</figref> or a decryption / decompression <figref>30</figref> (Step <figref>210</figref>) using the unique identifier of the medium <figref>28</figref> as decrypted decryption key and subsequently for the PC <figref>20</figref>, The single device <figref>22</figref> or the decryption / Dekompri<?page 10?>mierungsvorrichtung <figref>30</figref> made available. Thus, any protected electronic data of the target medium <figref>28</figref> to other Memory devices are copied, unusable, as the other Storage devices do not have the same unique identifier such as the target media <figref>28</figref>, Such a system would unauthorized copying of protected prevent electronic data, which makes it the intellectual Property of the seller or the owner of such rights protected.
Of the in <figref idrefs="S51">6</figref> Tourism is now represented with respect on <figref idrefs="S52">7</figref>-<figref idrefs="S54">9</figref> detailed describe. <figref idrefs="S52">7</figref> shows the downloading process the electronic distributing data over the network <figref>12</figref> of a server <figref>16</figref> to a client PC / Workstation <figref>20</figref> or a single device <figref>22</figref>, As noted above, the protected electronic data to a particular media with a copy downloaded unique identifier, so that the data of the specific media are associated and only on the particular medium can be accessed from on it.
at step <figref>300</figref> the process begins after a user on the client PC <figref>20</figref> eg a Web browser a server <figref>16</figref> (Web server) contacted has associated with it, and a selection of proprietary data performs for download. preferably contains the Web <figref>16</figref> a IOMEGA storage server <figref>16</figref>. which will be described below. Also preferably, the compound a secure (ie encrypted) between the web server Connection. After the user on the Web page of the web server the download button clicks, this action causes the PC / workstation, an HTML form to the web server <figref>16</figref> to send. Of the webserver <figref>16</figref> leads then the appropriate CGI program (Common Gateway Interface) through. The CGI program that runs on the web server IOMEGA memory <figref>16</figref> runs, sends on the client PC / Workstation <figref>20</figref> the Metatag "Content-Type: application / xift "followed of a suitable IOMEGA transaction file (ITF = Iomega Transaction File). This ITF file is einzigar tig for Iomega storage server<figref>16</figref>. and it is used to provide information to an ITF client program to provide that the downloading process on the client side controls. The format of the ITF file is in<figref idrefs="S53">8</figref> shown. When the Web browser receives the meta tag, it starts the ITF client program and transfers the ITF file name as command line parameters. The ITF client application opens the ITF file and parses metadata from metatags. The client PC / Workstation<figref>20</figref> combines to the server address which is provided by the ITFSERVER tag, to receive the electronic data (s. Step <figref>308</figref>). The server address can for changed each dynamically request be to offset the load on the server. The ITF file can for example contain the following information for the transmission of a single file, the song includes: <img img-content="cp" img-format="tif" he="69" wi="131" file="00230001.tif" />
in the step <figref>302</figref> asks the client PC <figref>20</figref> the specific media copy <figref>28</figref>To which the downloaded content to be saved after unique identifier of the medium. As a non-limiting example the medium can <figref>28</figref> a ZIP<sup>®</sup>included diskette, which is made by Iomega Corporation, Roy, Utah. Each Iomega ZIP<sup>®</sup>-Diskette contains a unique serial number that in during the formatting process a predetermined track was written and unique as the can be used identifier. Further, the medium<figref>28</figref>. while it in terms of a ZIP<sup>®</sup>described diskette was not in the ZIP<sup>®</sup>Floppy limited because using other removable and permanent media types, having a unique identifier, such as CD-R, DVD-RAM and other removable disks and hard drives, within the Scope and spirit of the present invention.
Of the Client PC <figref>20</figref> can query the media using an application programming<?page 11?>Interface (API = Application Programming Interface) such as the Iomega Ready API or another suitable method. If the Iomega Ready API called is, it causes the media drive, a unique serial number to read from the predetermined track by using the SCSI 0 × 06 Non-Sense Command. In particular, by calling the board status page (Page 0 × 06) of Non-Sense command can the serial number of the medium are determined by reading the offset bytes 20-59 the returned Data structure. An exemplary source code for performing the step <figref>302</figref> in conjunction with Iomega Zip<sup>®</sup>-Drive and diskette is as follows: <img img-content="cp" img-format="tif" he="177" wi="103" file="00250001.tif" />
It be appreciated that the unique identifier is not limited on the on the medium <figref>28</figref> information stored as for example, the serial number, and that other types of information as unique identifier can be used. In addition, should the unique Identifier a sufficient number of bits (length) in order to ensure that no two media copies have the same identifier. Each Iomega ZIP<sup>®</sup>-Diskette contains as a unique serial number from 39 bytes (312 bits), and other bit lengths may be used will.
If the client PC <figref>20</figref> once with the specified in the ITFSERVER tag server <figref>16</figref> connected (eg 147.178.20.151), sends the Client in step <figref>304</figref> about TCP / IP sockets, a command packet to the server. The first command packet has a coupon of one and contains the file to be transferred name, <?page 12?>all User information, account information and the unique Identifier of the medium. The first command packet may be formatted as follows be: <img img-content="cp" img-format="tif" he="37" wi="55" file="00260001.tif" />
Of the Server responds with a data packet with the same action code and informs the client about that the file opened was well above the file size.
alternative may include a plurality of fields, the data field User information, the billing information and the unique contains identifiers as parsed fields. The data field can be formatted be that it has the following data structure: <img img-content="cp" img-format="tif" he="84" wi="47" file="00270001.tif" />
In steps <figref>306</figref>-<figref>310</figref> sends the client is a command packet with the action code two (step <figref>306</figref>), of the notifies the computer, the next 4000 bytes of data to encrypted unique identifier to send. This action code is repeated until the entire file from the server <figref>16</figref> to the client PC <figref>20</figref> transfer has been. The server<figref>16</figref> encrypts the data key to the hey runterzuladenden digital content using the unique identifier (And any additional Information) as the encryption key (step <figref>308</figref>). While in step <figref>308</figref> Any suitable encryption algorithm can be used, the data encryption is preferably performed under Using the well known Blowfish encryption algorithm. Of the Blowfish encryption algorithm is advantageous quickly, especially when he takes on 32-bit microprocessors with big Data cache is implemented, such as the Intel Pentium and the IBM / Motorola PowerPC. Briefly Blowfish is a 64-bit block cipher with variable key length, the can be implemented either in hardware or in software. The algorithm consists of two parts: a key expansion part and a data encryption part. The key expansion part converts a key exceeding 448 bits into several subkey fields with a total of 4168 Byte order. Data encryption takes over a 16-round Feistel, each round of a key-dependent permutation and a turn-key and data-dependent Substitution is. All operations are exclusive-OR (XOR) and addition of 32-bit words. The only additional Operations are four indexed array data searches per round to the encrypted to generate data.
correspondingly of the present invention, the server <figref>16</figref> a downloaded In digital<?page 13?>halt encrypted in an encrypted or not Format included. If the downloaded content does not in a encrypted Format is stored, it is preferably downloading encrypted Using the unique identifier as an encryption key. If the downloaded digital content on the server <figref>16</figref> in front Downloading in an encrypted format (vorverschlüsselt) saved , then would the server only the data key to the content (that is, the software application, music or video) encode need. Vorverschlüsselung can be advantageous to a higher capacity provide in environments where large amounts of data per transaction encoded must be. Such electronic distribution systems would be heavily burdened when they the entire contents of which is to be distributed electronically, would encrypt. It but can be advantageous to the downloaded content in step <figref>308</figref> double encrypt by encrypting the pre-encrypted content and the data key to the pre-encrypted Content using the unique identifier (and a any additional Information) as an encryption key. A Such a technique would the security to be transferred to the Data in large increasing extent, because the data before transmission to the client are encrypted twice as noted above. During the Process at step <figref>308</figref> encrypting the data key or the data wrench and the contents was designated, it is also possible that in step <figref>308</figref> just the part transferred encrypted content is generated using the unique identifier as a key. If improved security is a concern, can containing a additional transaction information such as name, address, credit card number, etc. of the buyer contain the content.
Also in step <figref>308</figref> the server transmits the data on to the client, including TCP / IP sockets, and the client PC <figref>20</figref> writes the data in step <figref>310</figref> on the medium <figref>28</figref>, The data in a standard file system structure or by direct track or Sector recording to the media <figref>28</figref> to be written. The Format in which the data on the medium <figref>28</figref> written be, is not limited to the above formats, as other formats can be used. Of the server<figref>20</figref> at the client PC <figref>20</figref> transmitted Data preferably have a predetermined data structure as the following: <img img-content="cp" img-format="tif" he="37" wi="57" file="00290001.tif" />
Of the Process of step <figref>306</figref>-<figref>310</figref> will be repeated, until all the data from the server <figref>16</figref> on the client PC <figref>20</figref> downloaded are. At this time, the client PC is<figref>20</figref> an action code send three to the server <figref>16</figref> to inform that the transfer completely is and to separate the socket (step <figref>312</figref>). It should noted that the above source code and data structures here for example purposes only are included and in no way limit the scope of the present restrict invention should.
As noted above, the data on the medium <figref>28</figref> in a encrypted Format stored using the unique identifier as decryption keys. If the data is copied to another medium, is accordingly the decryption process fail, which makes the content unusable. Thus, unauthorized Copying of data downloaded using the apparatus and method of the present invention prevented. During the Process described above relates to a client PC, is the process applicable to a single device which is capable on the communicating network structure, and the medium on which the protected electronic Data is stored, to read and write. It may, for example, be provided a kiosk at outlets where shoppers a media copy <figref>28</figref> insert it into the kiosk and download data, on a personal Computer at home or office to be used.
With in reference to <figref idrefs="S54">9</figref> there are the processes shown, during the a reading / execution / rendering protected performed data be when once on the medium <figref>28</figref> are written. As the in the art versed appreciated, the process of <figref idrefs="S54">9</figref> in multiple threads are executed, to the performance the Play / Execute / viewing process to increase. As described below, the encrypted data using the unique identifier of the medium <figref>28</figref> decrypts the decryption key to the PC <figref>20</figref> or the single device <figref>22</figref> usable to introduce electronic data.
<?page 14?>
Of the Play / Execute / viewing process begins at step <figref>320</figref>When the user the medium <figref>28</figref> in the PC <figref>20</figref> or the single device <figref>22</figref> inlaying and the protected Data on the medium <figref>28</figref> accesses. The user can Using a combination of software and hardware that the in PC <figref>20</figref> or the single device <figref>22</figref> installed are protected in the Data access.
in the step <figref>322</figref> reads the PC <figref>20</figref> (Or the single device <figref>22</figref>) the unique identifier of the medium <figref>28</figref> and stores the unique identifier in the RAM <figref>64</figref> (R.A.M <figref>39</figref>). As noted above, the medium is preferably the Iomega ZIP<sup>®</sup> Diskette, everyone the unique serial number on a predetermined track ZIP<sup>®</sup>-Diskette contains; However, the medium is not in the ZIP<sup>®</sup>-Diskette limited and may comprise any medium to which a unique identifier assigned. As also noted above, the software the PC <figref>20</figref> the Iomega Ready API to in step <figref>322</figref> the Serial number read from the disk.
In step <figref>324</figref> decrypts the computer <figref>20</figref> (Or the single device <figref>22</figref>) a predetermined character string on the medium <figref>28</figref> contain is using the unique identifier. The predetermined String is in step <figref>326</figref> with a known string compared to determine whether or not a correct string has been decrypted (Ie the decrypted predetermined string of known string is equal). When the predetermined character string in the well-known string decrypts was driving the Process at step <figref>328</figref> continues where the encrypted protected electronic data from the medium <figref>28</figref> to be read. Meanwhile, if the result of the decryption of the predetermined string has not been known string, end all threads, thereby playback / Execute / viewing operation in step <figref>344</figref> is terminated.
In step <figref>328</figref> reads the PC <figref>20</figref> (Or the single device <figref>22</figref>) encrypted Data from the medium <figref>28</figref> and stores the protected electronic data temporarily in the RAM <figref>64</figref> (R.A.M <figref>39</figref>). The read operation may in be carried out with a first thread, the on the PC <figref>20</figref> running, and he is in an analogous manner as the data writing on the medium <figref>28</figref> for example by reading a standard file system or direct track or sector reading performed. The format in which the Data from the medium <figref>28</figref> be read, is correspondingly running the way as the data was written to the media, and as in the Writing the data to the media <figref>28</figref> it is not limited to the above formats limited since other formats used can be.
In step <figref>330</figref> it is determined whether all the protected data from the medium <figref>28</figref> have been read. If so, ends the read thread in step <figref>332</figref>, Conversely, if more data is read should read the thread returns to step <figref>328</figref> back for more protected Data from the medium <figref>28</figref> to read. According to one aspect the invention must be in step <figref>328</figref> not the totality the protected Contents of the medium <figref>28</figref> read what the amount of memory reduced the required for realizing the decryption process is. Because the operations in <figref idrefs="S54">9</figref> be carried out in a multi-threaded manner, , the process of reading the protected data from the medium <figref>28</figref> also accomplished , when other parts of the protected data in a second Thread or other hardware to be decrypted, as discussed below becomes.
Also of step <figref>330</figref> from decrypts a second thread, the protected Data (step <figref>334</figref>) Using the (at step <figref>322</figref> read) unique identifier of the medium <figref>28</figref> as decryption keys. the decryption the data in step <figref>334</figref> is in accordance with the encryption algorithm accomplished and includes, As noted above, preferably the Blowfish algorithm. decryption can be done in software or may be performed in hardware, if a higher is security level required. Since the decryption in a second thread (or other hardware device) expires, may continue as described above, the decryption process at the same time to the reading operation in step <figref>328</figref> be performed.
In step <figref>336</figref> be the decrypted data is verified to determine whether they valid Data (ie used) are. If the data is valid, the data is in step <figref>338</figref> from the PC <figref>20</figref> (Or the single device <figref>22</figref>) run / played / viewed. can the process of executing / playing / viewing in a third thread or other hardware device (eg, a sound card) can be performed. If the data in step <figref>336</figref> on the other hand not valid or are spoiled, notified the operation in step <figref>342</figref> the Users and terminated in step <figref>344</figref> all threads. If once all protected decrypts data and played / viewed / executed are, in step <figref>344</figref> all threads that of the processes <figref idrefs="S54">9</figref> contain, terminated. It is preferable, when complete the operation in step<figref>344</figref> all temporary Files to delete, unencrypted protected contain electronic data to the anti-piracy features <?page 15?>of the the present invention further improve.
By Realize the operations of <figref idrefs="S54">9</figref> in multiple threads, the operations of Reading, decrypting and performing / playing / viewing protected Data in the PC <figref>20</figref> run simultaneously to the performance to increase.
It should be noted that the PC / Workstation <figref>20</figref> and the single device <figref>22</figref> above as the steps of <figref>320</figref>-<figref>344</figref> in similar way executive are described. Since the PC / Workstation<figref>220</figref> However, a includes general purpose computer, can in the PC / Workstation <figref>20</figref> Additional features of the present Invention are provided, which are described below.
At the Run / Play / View protected Data on the PC / Workstation <figref>20</figref> can the software or Hardwareent encryption process at steps <figref>334</figref> to <figref>338</figref> be carried out, that protected decrypt electronic data are automatically and an executable Program will be launched to the decrypted protected electronic To use data. Alternatively, the software or hardware decryption process protected electronic data in the step <figref>334</figref> and <figref>336</figref> decrypt and verify and decrypted data temporarily on the medium <figref>28</figref>, Other media (eg hard disk <figref>76</figref>) or in a memory (eg, RAM <figref>64</figref>) Save for execution or Use by other software or hardware applications in step <figref>338</figref>, This alternative allows the user, the protected electronic data at a time after decrypting play / perform / to consider. If enhanced security is preferred, could protected electronic data also in step <figref>328</figref> in an encrypted form in the RAM <figref>64</figref> saved be and in step <figref>334</figref> as required be temporarily decrypted.
As noted above, the decryption process in step <figref>334</figref> (<figref idrefs="S54">9</figref>) In software or hardware be implemented. Regarding<figref idrefs="S47">2</figref>-<figref idrefs="S49">4</figref> becomes an exemplary first hardware implementation described. As in the art is well known, an ASIC is a custom-made or halbmaßgeschneiderte integrated circuit for performing a variety of functions can be designed. Accordingly, the ASICs can<figref>108</figref> and or <figref>36</figref> in addition to the other above-specified by the ASICs <figref>108</figref> and <figref>36</figref> functions performed for performing decryption of step <figref>334</figref> be designed. It is preferable that the decryption process in the ASIC <figref>108</figref> and or <figref>36</figref> to implement, to minimize the likelihood of unscrupulous pirates decryption software "hack" to illegal copies protected to make electronic data.
In the first hardware embodiment is the set of steps <figref>320</figref>-<figref>344</figref> of <figref idrefs="S54">9</figref> in a single device (eg, the PC / Workstation <figref>20</figref> or the single device <figref>22</figref>) Performed. When the first hardware embodiment in the PC <figref>20</figref> is implemented, are of the medium <figref>28</figref> read encrypted Data about the controller <figref>68</figref>) The ASIC <figref>108</figref> supplied to the decryption (At steps <figref>324</figref> and <figref>334</figref>) under use the unique identifier of the medium <figref>28</figref> as decryption keys. If protected electronic data once from the ASIC <figref>108</figref> are decrypted, they are (about the controller <figref>68</figref>) back to the PC <figref>20</figref> routed for review and execution. By Receiving the decryption processing in the ASIC <figref>108</figref> the load of the processor <figref>66</figref> advantageous reduced, others from the PC / Workstation <figref>20</figref> conducted operations accelerated.
If the first hardware embodiment in the single device <figref>22</figref> is implemented, the encrypted Data about the controller <figref>68</figref> and the CPU <figref>66</figref>) The ASIC / Controller <figref>36</figref> supplied to the decipher at steps <figref>324</figref> and <figref>334</figref> under use the unique identifier of the medium <figref>28</figref> as decryption keys. If protected electronic data once from the ASIC / Controller <figref>36</figref> are decrypted and checked, they are converted into digital audio and / or video data the digital / analog converter <figref>38</figref> be supplied to convert into analog audio and video information. The analog information is then to an analog input device <figref>44</figref> outputted as as a VCR, a tape recorder, an amplifier, a Sound card, etc., and the process ends in step <figref>336</figref>,
A second hardware embodiment will now be described, the processing between the PC / Workstation <figref>20</figref> and the on related <figref idrefs="S50">5</figref> described decryption / decompression <figref>30</figref> divides. The decryption / decompression <figref>30</figref> can eg working as a special purpose media player connected to the PC <figref>20</figref> connected is. The decryption / decompression<figref>30</figref> is with the ability provided that the protected electronic data from the PC <figref>20</figref> to receive the content (if needed to decrypt) and decompress and provide audio and / or video outputs.
<?page 16?>
Of the Operation of the second hardware implementation is with respect to the <figref idrefs="S55">10A</figref> and <figref idrefs="S56">10B</figref> described. The process begins in step <figref>400</figref>When the user the medium <figref>48</figref> in the PC <figref>20</figref> inserts and on the protected electronic Data on the medium <figref>28</figref> accesses. In step<figref>402</figref> becomes the data keys (ie, the unique identifier) for protected obtained data. The operations of step <figref>402</figref> are on in detail with reference <figref idrefs="S56">10B</figref> described.
With in reference to <figref idrefs="S56">10B</figref> (Step <figref>450</figref>) begins the processing in step <figref>452</figref>If the PC <figref>20</figref> the unique identifier of the medium <figref>28</figref> reads and him in step <figref>454</figref> to the decryption / decoding device <figref>30</figref> passes. As noted above, the medium <figref>28</figref> preferably the Iomega ZIP<sup>®</sup>Diskette, the unique serial number on a predetermined track of each ZIP<sup>®</sup>-Diskette contains; However, the medium is not in the ZIP<sup>®</sup>-Diskette limited and may comprise any medium to which a unique identifier assigned. The software of the PC<figref>20</figref> can the Iomega Ready API to as described above, the serial number of to read the disk. In step<figref>456</figref> generates the decryption / decoding device <figref>30</figref> a Authentication code in step <figref>458</figref> back to the PC <figref>20</figref> (The media drive <figref>52</figref>) Is sent. In step <figref>460</figref> checks the media drive, whether that of the decryption / decoding device <figref>30</figref> delivered Authentication code is the same as the unique serial number on the medium <figref>28</figref>Which is actually in the drive <figref>52</figref> is. If the authentication code does not match with the unique identifier, ends playback / Execute / viewing process in step <figref>468</figref>, If the authentication code with the unique identifiers match, then generates the media drive <figref>52</figref> in step <figref>462</figref> a Verification code. The verification code is in step<figref>464</figref> to the decryption / decoding device <figref>30</figref> sent, and the process then returns to step <figref>404</figref> in <figref idrefs="S55">10A</figref> back. The two-step verification process of <figref idrefs="S56">10B</figref> provides ensure that the unique identifier of the medium <figref>28</figref>. The physically in the media drive <figref>52</figref> is, the same unique identifier has, in step <figref>454</figref> to the decryption / decoding device <figref>30</figref> cleverly was, and further improves the resistance of the present invention against hacking. The unique identifier is for use as Decryption key in the decryption process (steps <figref>406</figref> and <figref>412</figref>) In RAM <figref>39</figref> stored.
With Terms of re <figref idrefs="S55">10A</figref> decrypts the decryption / decoding device <figref>30</figref> in step <figref>404</figref> a predetermined character string on the medium <figref>28</figref> contain is using the unique identifier. The predetermined String is the USB / parallel / serial port <figref>58</figref> to the decryption / decoding device <figref>30</figref> Posted. The predetermined character string in step <figref>406</figref> of the Decryption / decoding device <figref>30</figref> With compared to a known string to determine whether a decrypts correct string (ie, the decrypted String equal to the known string is). If the decrypted predetermined String is equal to the known drawing chain, the process goes in step <figref>408</figref> further in which the encrypted Data from the medium <figref>28</figref> to be read. Conversely, if the decrypted predetermined string does not equal the known string is in the process ends in step <figref>424</figref>,
In step <figref>408</figref> the encrypted data from the medium <figref>28</figref> read and over the USB / parallel / serial port <figref>58</figref> in step <figref>410</figref> at the decryption / decompression device <figref>30</figref> Posted. In step <figref>412</figref> decrypts the ASIC / Controller <figref>36</figref> of the controller <figref>34</figref> received protected electronic data. The decryption process is above with respect to step <figref>334</figref> (<figref idrefs="S54">9</figref>) Carried out as described. If protected decrypt electronic data are, provides the ASIC / Controller <figref>36</figref> (Or on the PC <figref>20</figref> running application software) in step <figref>414</figref> the Type determined the information that the protected electronic contain and whether the decrypted data valid are. If the data in step<figref>414</figref> determined to be invalid are, the user can step <figref>422</figref> be notified and the process ends in step <figref>424</figref>,
If protected electronic data in step <figref>414</figref> a valid application software or a valid executable File is, the decryption / decompression <figref>30</figref> the decrypted File to run in step <figref>416</figref> back to the PC <figref>20</figref> to guide. As in<figref idrefs="S55">10A</figref> illustrated , the process of sending encrypted data to the decryption / decoding device <figref>30</figref> a Loop through steps <figref>408</figref> to <figref>416</figref> run through, until all the data from the medium <figref>28</figref> read and to perform back to the PC <figref>20</figref> are passed. After all protected electronic decrypts and to the PC <figref>20</figref> returned are, the process ends in step <figref>424</figref>,
If protected electronic data valid Audio or video data, the decryption / decompression <figref>30</figref> in addition, the Decompressing the audio or video data in step <figref>418</figref> in the ASIC / Controller <figref>36</figref> provide. Typically, digital audio and Videoinformatio<?page 17?>NEN according to standard compression algorithms compressed. Full motion video and audio information can rimiert comp be using the MPEG standard (Moving Pictures Expert Group) and still images can using the JPEG standards (Joint Picture Expert Group), be compressed. The decompressed audio or video information can step in <figref>418</figref> into digital data (for example, pulse code modulation (PCM)) and are converted to the digital / analog converter <figref>38</figref> Posted will.
In step <figref>420</figref> the digital audio or video data from the digital / analog converter <figref>38</figref> in analog audio or Video signals are converted. The analog signals are for playing / viewing a Analog input device <figref>44</figref> (Eg a stereo amplifier, a Video cassette recorder, a sound card or a TV) output. As in <figref idrefs="S55">10A</figref> shown, the operation sending encrypted Data to the decryption / decoding device <figref>30</figref> a Loop through steps <figref>408</figref> to <figref>420</figref> run through, until all the data from the medium <figref>28</figref> are read. After this all protected electronic data has been converted to an analog output, the process ends in step <figref>424</figref>,
correspondingly the second hardware implementation, the protected data from the PC <figref>20</figref> as a current to the decryption / decompression <figref>30</figref> Posted or alternatively in their entirety before decrypting by ASIC / Controller <figref>36</figref> in the RAM <figref>39</figref> downloaded will.
the present invention advantageously utilizes the unique identifier of the medium as the encryption key, the allows, that any electronic data are protected against copying. In addition, the protected electronic data by using the unique identifier of the medium, instead of a hardware device on any read / play device be capable of reading the media. Thus, the protected electronic Data portable and are just on a single removable Medi bound, which makes it possible that protected electronic data to be shared while preventing that protected electronic data copied and read by another media / play will. Furthermore, the present invention may be in a single encryption method or a multiple encryption methods be used in which the key to the protected electronic encrypted data itself is using the serial number of the disk as a key.
It should be noted that the foregoing examples are merely for the purpose the declaration are offered and in no way as limiting the present invention may be interpreted. While the Invention has been described with reference to the preferred embodiments, it is clear that the words used in this case are words of description and Illustration and not by words the limit is. at Although the invention herein with respect particular means, materials and embodiments is described, is also not intended that the invention to the particulars disclosed is to be limited, but the Invention extends to all functionally equivalent structures, methods and uses provided they fall within the scope of the appended claims. The in art versed that this the benefit of the teachings have description, can cause numerous variations thereof and modifications can be carried out without departing from the scope of the invention in its aspects.
It For example, a solid medium with a unique identifier is used by the present invention for receiving protected electronic Data. Even the removable medium does not have a removable Media cartridge be, but they can also be a removable Drive comprise as those removable with personal Computers and other devices, for example via drive bays, and device bays PCMCIA slots are connected.
Contents4
11 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11
9 members in 5 offices
Priority claims10
| Document | Office | Kind | Date |
|---|---|---|---|
| 6149398 | United States of America | A | |
| 6149398 | United States of America | A | |
| 6149398 | United States of America | – | |
| 9908196 | United States of America | W | |
| 9908196 | United States of America | W | |
| 9908196 | United States of America | – | |
| 61493 | – | – | – |
| PCTUS9908196 | – | – | – |
| US19980061493 | – | – | – |
| WO1999US08196 | – | – | – |
Members9
| Document | Office | Kind | |
|---|---|---|---|
| WO9955055A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO0029928A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP1072143A1 | European Patent Office (EPO) | A1 | |
| JP2002512412A | Japan | A | |
| US2003221113A1 | United States of America | A1 | |
| EP1072143B1 | European Patent Office (EPO) | B1 | |
| DE69918284D1 | Germany | D1 | |
| DE69918284T2This record | Germany | T2 | |
| US7246246B2 | United States of America | B2 |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Ceased/non-payment of the annual feeCeased8339 | 8339 | |
| No opposition during term of oppositionOpposition8364 | 8364 |
Numbers
- Publication
- 69918284
- Publication, DOCDB
- 69918284
- Publication, EPODOC
- DE69918284T
- Application
- 69918284
- Application, DOCDB
- 69918284
- Application, EPODOC
- DE19996018284T
Titles2
- German
- SYSTEM UM GESCHÃTZTE, VERSCHLÃSSELTE ELEKTRONISCHE DATEN ZU EINEM SPEZIELLEN SPEICHERMEDIUM ZU SENDEN UND UM UNBERECHTIGTES KOPIEREN ZU VERHINDERN
- English
- SYSTEM TO PROTECTED, ENCRYPTED ELECTRONIC DATA TO A SPECIAL STORAGE MEDIA TO SEND AND TO UNAUTHORIZED COPY TO PREVENT
Classification
- CPC, 3
- H04L63/0442
- H04L2463/101
- G06F21/1014
- IPC, 7
- G06F12 14
- G06F1 00
- G06F12 00
- G06F21 10
- G10K15 02
- G11B20 10
- H04L29 06
