EP0840194A2

System and method for controlling the use of a package of distributed application software

Abstract

A system for permitting only an authentic user to play a desired application contained in a distributed application package in one of predetermined operation, e.g., free play mode, charged mode, limit-attached play mode, etc. The system comprises a client for playing an application under the control of a server connected with the client through a communication network. The application package (the volume) includes a distribution descriptor which contains mode codes assigned to the volume and the applications of the volume. The data of distribution descriptor is decided and stored in the descriptor at the time of distribution of the volume. This feature makes the system flexible. There is also disclosed a system operatable without communicating with a server.

EP0840194A2, drawing sheet 1
Sheet 1 of 30

Term

Term ended

Projected expiry passed 2 June 2017, 9.3 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

112 claims: 34 independent, 78 dependent

  1. 1
    An application package for use in a system for playing an application contained in the application package (the volume), the application package comprising:application data for at least one application;and volume control data for use in controlling said system, wherein said volume control data at least comprises: a volume ID for identifying the kind of said application package (said volume);an issue number assigned in order of issue to each of the volumes of said kind;and application IDs each assigned to one of said at least one application contained in said volume, and wherein: at least a part of said volume control data is to be added to said volume after the creation of said volume;and said at least a part of said volume control data includes said issue number.
  2. 7
    A method for sending data with a raised security from a first device to a second device through a public telecommunication network, comprising the steps of:in said second device, generating a pseudo random number;transmitting said pseudo random number to said first device;in said first device, encrypting said data with said transmitted pseudo random number into encrypted data;encrypting concatenated data consisting of said pseudo random number and said encrypted data with a public key of said second device into double-encrypted data;sending said double-encrypted data to said second device;in said second device, decrypting said double-encrypted data with a secret key of said second device which corresponds to said public key into decrypted data consisting of a decrypted random number portion and another decrypted portion;and decrypting said another decrypted portion with said transmitted random number to obtain said data.
  3. 8
    A method for sending a plurality of pieces of data with a raised security from a first device to a second device through a public telecommunication network, comprising the steps of:in said second device, generating a pseudo random number;transmitting said pseudo random number to said first device;in said first device, encrypting each of said pieces of data with said transmitted pseudo random number into an encrypted piece of data;encrypting concatenated data consisting of said pseudo random number and said encrypted pieces of data with a public key of said second device into double-encrypted data;sending said double-encrypted data to said second device;in said second device, decrypting said double-encrypted data with a secret key of said second device which corresponds to said public key into decrypted data consisting of a decrypted random number portion and said plurality of decrypted data portions;and decrypting each of said decrypted portions with said transmitted random number to obtain said pieces of data.
  4. 10
    In a system provided with means for playing an application contained in an application package, a method for permitting a user to play an encrypting key-encrypted application contained in a distributed application package which further contains, as volume control data, a user's public key-encrypted encrypting key so encrypted as to be able to be decrypted with a secret key of the user into said encrypting key, the method comprising the steps of:reading said user's public key-encrypted encrypting key from said distributed application package (said volume);obtaining said secret key;decrypting said user's public key-encrypted encrypting key with said secret key to obtain said encrypting key;and decrypting said encrypting key-encrypted application with said obtained encrypting key into application data while passing said application data to said means for playing an application.
  5. 11
    In a system comprising a client provided with means for playing an application contained in an application package and a server connected with the client through a communication network, a method for permitting a user to play one of encrypting key-encrypted applications contained in a distributed application package which further contains, as volume control data, a volume ID for identifying the kind of said distributed application package (said volume), an issue number issued to each volume of the kind in an issued order and application IDs, the method comprising the steps of:said client reading said volume ID, said issue number and an application ID for said one of encrypting key-encrypted applications (said encrypting key-encrypted application) from said volume and sending to said server;in said server, retrieving said encrypting key by using said volume ID;retrieving a public key of said user by using said volume ID and said issue number;generating a pseudo random number;double-encrypting said encrypting key with said pseudo random number and said public key into a double encrypted data;sending said double-encrypted data to said client;in said client, obtaining a secret key of said user which corresponds to said public key;obtaining said encrypting key by decrypting said double-encrypted data with said secret key;decrypting said encrypting key-encrypted application with said obtained encrypting key into application data while passing said application data to said means for playing an application.
  6. 14
    In a system comprising a client provided with means for playing an application package and a server connected with the client through a communication network for controlling the client, the application package (the volume) containing, as volume control data, a volume ID and an issue number issued to each of the volumes of said volume ID in an issued order, a method for controlling the amount of play time comprising the steps of:said client sending said volume ID and said issue number to said server;said server retrieving an expected play time associated with said volume ID and said issue number;and said server adding said expected play time to the value of a total play time associated with said volume ID and said issue number.
  7. 15
    In a system comprising a client provided with means for playing an application contained in an application package and a server connected with the client through a communication network for controlling the client, the application package (the volume) containing, as volume control data, a volume ID, an issue number issued to each of the volumes of said volume ID in an issued order and an application ID for the application, a method for controlling the amount of play time comprising the steps of:said client sending said volume ID, said issue number and said application ID to said server;said server retrieving an expected play time associated with said volume ID, said issue number and said application ID;and said server adding said expected play time to the value of a total play time associated with said volume ID and said issue number.
  8. 16
    In a system comprising a client provided with means for playing an application contained in an application package and a server connected with the client through a communication network for controlling the client, the application package (the volume) containing, as volume control data, a volume ID and an issue number issued to each of the volumes of said volume ID in an issued order, a method for controlling the amount of play time comprising the steps of:said client and said server interactively measuring, as a measured play time, a play time of said application;and said server adding said measured play time to the value of a total play time associated with said volume ID and said issue number.
  9. 19
    In a system comprising a client for playing an application package and a server connected with the client through a communication network wherein the application package (the volume) comprises application data and control data and at least a part of the control data has been added to the volume after the creation of said volume, a method for sending desired data from one side of said client and said server to the other side, the method comprising the steps of:including a secret key of said other side in said at lest a part of said control data;in said other side, generating a pseudo random number;transmitting said pseudo random number to said one side;in said one side, encrypting said desired data with said transmitted pseudo random number into encrypted data;encrypting concatenated data consisting of said pseudo random number and said encrypted data with said public key of said other side into double-encrypted data;sending said double-encrypted data to said other side;in said other side, decrypting said double-encrypted data with a secret key of said other side which corresponds to said public key into decrypted data consisting of a decrypted random number portion and another decrypted portion;and decrypting said another decrypted portion with said transmitted random number to obtain said desired data.
  10. 21
    In a system comprising a client provided with means for playing an application contained in an application package and a server connected with the client through a communication network, a method for permitting a user to play an application contained in a distributed application package which further contains, as volume control data, a volume ID for identifying the kind of said distributed application package (said volume), an issue number issued to each volume of the kind in an issued order, and an application ID for said application, the method comprising the steps of:proceeding to a next step only if the value of a meter field associated with said volume ID, said issue number and said application ID is under the value of a limit value field associated with said volume ID, said issue number and said application ID in a volume data table;and displaying a message informing an overlimit on a display device of said client and quit the operation otherwise.
  11. 22
    In a system comprising a client provided with means for playing an application contained in an application package and a server connected with the client through a communication network, a method for permitting a user to play an application contained in a distributed application package which further contains, as volume control data, a volume ID for identifying the kind of said distributed application package (said volume), an issue number issued to each volume of the kind in an issued order, an application ID for said application and a limit value for limiting the play of said application, the method comprising the steps of:proceeding to a next step only if the value of a meter field associated with said volume ID, said issue number and said application ID in a volume data table is under said limit value;and displaying a message informing an overlimit on a display device of said client and quit the operation otherwise.
  12. 24
    A method as defined in any of claims 11, 15 and 16, wherein said step of said client sending to said server comprises the steps of:said client encrypting at least one of said volume ID, said issue number and said application ID into encrypted data;and said server decrypting said encrypted data.
  13. 25
    A system for sending data with a raised security from a first device to a second device through a public telecommunication network, comprising:means provided in said second device for generating a pseudo random number;means provided in said second device for transmitting said pseudo random number to said first device;means provided in said first device for encrypting said data with said transmitted pseudo random number into an encrypted data;means provided in said first device for encrypting concatenated data consisting of said pseudo random number and said encrypted data with a public key of said second device into double-encrypted data;means provided in said first device for sending said double-encrypted data to said second device;means provided in said second device for decrypting said double-encrypted data with a secret key of said second device which corresponds to said public key into decrypted data consisting of a decrypted random number portion and another decrypted portion;and means provided in said second device for decrypting said another decrypted portion with said transmitted random number to obtain said data.
  14. 26
    A system for sending a plurality of pieces of data with a raised security from a first device to a second device through a public telecommunication network, comprising:means provided in said second device for generating a pseudo random number;means provided in said second device for transmitting said pseudo random number to said first device;means provided in said first device for encrypting each of said pieces of data with said transmitted pseudo random number into an encrypted piece of data;means provided in said first device for encrypting concatenated data consisting of said pseudo random number and said encrypted pieces of data with a public key of said second device into double-encrypted data;means provided in said first device for sending said double-encrypted data to said second device;means provided in said second device for decrypting said double-encrypted data with a secret key of said second device which corresponds to said public key into decrypted data consisting of a decrypted random number portion and said plurality of decrypted data portions;and means provided in said second device for decrypting each of said decrypted portions with said transmitted random number to obtain said pieces of data.
  15. 28
    A system for playing an encrypting key-encrypted application contained in a distributed application package which further contains, as volume control data, a user's public key-encrypted encrypting key so encrypted as to be able to be decrypted with a secret key of the user into said encrypting key, the system comprising:means for reading said user's public key-encrypted encrypting key from said distributed application package (said volume);means for obtaining said secret key;means for decrypting said user's public key-encrypted encrypting key with said secret key to obtain said encrypting key;means for decrypting said encrypting key-encrypted application with said obtained encrypting key to provide application data;and means for using said application data for playing.
  16. 29
    A system for permitting a user to play an encrypting key-encrypted application contained in a distributed application package which further contains, as volume control data, a volume ID for identifying the kind of said distributed application package (said volume), an issue number issued to each volume of the kind in an issued order and application IDs, the system comprising:a client for playing an application by using application data;and a server for controlling said client through a communication network, wherein said client comprises: means for reading and sending said volume ID, said issue number and an application ID for said one of encrypting key-encrypted applications (said encrypting key-encrypted application) from said volume to said server, said server comprises: means for retrieving said encrypting key by using said volume ID;means for retrieving a public key of said user by using said volume ID and said issue number;means for generating a pseudo random number;means for double-encrypting said encrypting key with said pseudo random number and said public key into a double encrypted data;and means for sending said double-encrypted data to said client, and said client comprises: means for obtaining a secret key of said user which corresponds to said public key;means for obtaining said encrypting key by decrypting said double-encrypted data with said secret key;means for decrypting said encrypting key-encrypted application with said obtained encrypting key to provide application data;and means for using said application data for playing.
  17. 32
    A system for permitting a user to play a distributed application package which further contains, as volume control data, a volume ID for identifying the kind of said distributed application package (said volume) and an issue number issued to each volume of the kind in an issued order, the system comprising:a client for playing said distributed application package;and a server for controlling said client through a communication network, wherein: said client comprises means for sending said volume ID and said issue number to said server;and said server comprises means for retrieving an expected play time associated with said volume ID and said issue number, and means for adding said expected play time to the value of a total play time associated with said volume ID and said issue number.
  18. 33
    A system for permitting a user to play an application contained in a distributed application package which further contains, as volume control data, a volume ID for identifying the kind of said distributed application package (said volume), an issue number issued to each volume of the kind in an issued order and an application ID for the application, the system comprising:a client for playing said application;and a server for controlling said client through a communication network, wherein: said client comprises means for sending said volume ID, said issue number and said application ID to said server;and said server comprises means for retrieving an expected play time associated with said volume ID, said issue number and said application ID, and means for adding said expected play time to the value of a total play time associated with said volume ID and said issue number.
  19. 34
    A system for permitting a user to play an application contained in a distributed application package which further contains, as volume control data, a volume ID for identifying the kind of said distributed application package (said volume), an issue number issued to each volume of the kind in an issued order and an application ID for the application, the system comprising:a client for playing said application;and a server for controlling said client through a communication network, wherein: said client and said server comprise means for interactively measuring, as a measured play time, a play time of said application;and said server further comprises means for adding said measured play time to the value of a total play time associated with said volume ID and said issue number.
  20. 37
    A system for permitting a user to play an application package (the volume) comprising application data and control data wherein at least a part of the control data has been added to the volume after the creation of said volume, the system comprising:a client for playing said volume;and a server for controlling said client through a communication network, wherein said server comprises means for storing a secret key of said server and said at least a part of said control data includes a public key corresponding to said secret key, and wherein the system comprises: means provided in said server for generating a pseudo random number;means for storing said pseudo random number;means provided in said server for transmitting said pseudo random number to said client;means provided in said client for encrypting desired data with said transmitted pseudo random number into encrypted data;means provided in said client for encrypting concatenated data consisting of said pseudo random number and said encrypted data with said public key into double-encrypted data;means provided in said client for sending said double-encrypted data to said server;means provided in said server for decrypting said double-encrypted data with said secret key into decrypted data consisting of a decrypted random number portion and another decrypted portion;and means provided in said server for decrypting said another decrypted portion with said transmitted random number to obtain said desired data.
  21. 39
    A system for permitting a user to play an application contained in a distributed application package which further contains, as volume control data, a volume ID for identifying the kind of said distributed application package (said volume), an issue number issued to each volume of the kind in an issued order and application IDs, the system comprising:a client for playing an application by using application data;and a server for controlling said client through a communication network, wherein said client comprises: means for reading and sending said volume ID, said issue number and an application ID for said one of encrypting key-encrypted applications (said encrypting key-encrypted application) from said volume to said server, said server comprises: means for proceeding to next step only if the value of a meter field associated with said volume ID, said issue number and said application ID is under the value of a limit value field associated with said volume ID, said issue number and said application ID in a volume data table;and means for causing said client to display a message informing an overlimit on a display device of said client and quit the operation otherwise.
  22. 40
    A system for permitting a user to play an application contained in a distributed application package which further contains, as volume control data, a volume ID for identifying the kind of said distributed application package (said volume), an issue number issued to each volume of the kind in an issued order, application IDs and limit values associated with respective application IDs for limiting the play of respective applications, the system comprising:a client for playing an application by using application data;and a server for controlling said client through a communication network, wherein said client comprises: means for reading and sending said volume ID, said issue number, an application ID for said one of encrypting key-encrypted applications (said encrypting key-encrypted application) and a limit value associated with said application ID from said volume to said server, and wherein said server comprises: means for proceeding to a next step only if the value of a meter field associated with said volume ID, said issue number and said application ID in a volume data table is under said limit value;and means for causing said client to display a message informing an overlimit on a display device of said client and quit the operation otherwise.
  23. 42
    A system as defined in any of claims 29, 33 and 34, wherein said means for sending to said server comprises means for encrypting at least one of said volume ID, said issue number and said application ID.
  24. 43
    A method for permitting an authentic user to play a desired one of the applications contained in a distributed application package in a system capable of playing an application, wherein said application package (said volume) contains volume control data including mode codes assigned to said volume and the applications of said volume, the method comprising the steps of:deciding to use one of predetermined play modes specified by one of said mode codes associated with said desired application;and playing said desired application in said specified play mode.
  25. 49
    A system for permitting an authentic user to play a desired one of the applications contained in a distributed application package, wherein said application package (said volume) contains volume control data including mode codes assigned to said volume and the applications of said volume, the system comprising:means for deciding to use one of predetermined play modes specified by one of said mode codes associated with said desired application;and means for playing said desired application in said specified play mode.
  26. 55
    A method for permitting an authentic user to play a desired one of the applications contained in a distributed application package in a system comprising a client capable of playing an application and a server connected with said client through a communication network, wherein said application package (hereinafter referred to as "said volume") contains volume control data including mode codes assigned to said volume and the applications of said volume, the method comprising the steps of:said client deciding to use one of predetermined play modes specified by one of said mode codes associated with said desired application;and playing said desired application in said specified play mode by means of cooperation between said client and said server.
  27. 70
    A system for playing a distributed application package in one of predetermined play modes in concert with a server, wherein the application package contains a data set encrypted with an encrypting key (a K-encrypted data set) for each of at least one application and volume control data for use in controlling operation of the system and the server and the volume control data includes mode codes defining said play modes, the system comprising:means for permitting a user to select one of said at least one application of said volume;means for deciding to use one of said predetermined play modes associated with one of said mode codes assigned to said selected application;and means for playing said selected application in said selected play mode in concert with said server.
  28. 88
    A system for controlling through a communication network a client device to play a distributed application package in one of predetermined play modes, wherein the application package contains a data set encrypted with an encrypting key (a K-encrypted data set) for each of at least one application and volume control data for use in controlling operation of the system and the client and the volume control data includes a volume ID, an issue number, an application ID for each of said applications, and a mode code for said volume or mode codes for said applications, the system comprising:volume data table for storing, for each volume, said volume ID, said issue number, said mode code for said volume, and said application ID and said mode code for each of said applications;means for receiving a service request, a volume ID, an issue number, an application ID and a mode code and other data from said client;means for storing said received application ID, said received mode code and other data in appropriate fields of a record identified by said volume ID and said issue number;means responsive to a determination that there is no record identified by said volume ID and said issue number in said volume data table for adding said record in said volume data table and storing said received application ID and mode code and said other data in relevant fields of said record;and means operative on the basis of said received mode code for deciding to subsequently passing the control to means for supporting a play mode associated said received mode code.
  29. 101
    A system as defined in any of claims 54, 73 and 75, wherein said means for obtaining a user's secret key comprises means for reading said user's secret key from a portable memory of said user.
  30. 103
    A method as defined in any of claims 10, 11, 19, 21, 22 and 55, wherein said application package is recorded on a package media.
  31. 106
    A system as defined in any of claims 28, 29, 37, 39, 40, 70 and 88, wherein said application package is recorded on a package media.
  32. 110
    A system as defined in any of claims 28, 29, 37, 39, 40, 70 and 88, wherein said application package is recorded on a DVD and at least a part of said volume control data is recorded, after manufacturing said package media, in a BCA (burst cutting area) of the DVD, and wherein said client is a system provided with means for playing said DVD.
  33. 111
    A method as defined in any of claims 10, 11, 19, 21, 22, 43 and 55, wherein the application package has been distributed to a purchaser thereof or a subscriber via a transmission media and at least a part of said volume control data has been added to said application package after preparing said application package.
  34. 112
    A system as defined in any of claims 28, 29, 37, 39, 40, 49, 70 and 88, wherein said application package has been distributed to a purchaser thereof or a subscriber thereof via a transmission media and at least a part of said volume control data has been added to said application package after preparing said application package.
Independent claims34