Contents management method, contents management apparatus, and recording medium
4 claims: 4 independent, 0 dependent
- 1A content management method for a content management apparatus (1) for managing an allowable number of encrypted contents which are encrypted copies of a content and are recorded on memory cards (13), each of the memory cards (13) including a first memory area (13a) storing at least an encrypted content of the encrypted contents and a second memory area, which is a secure area and stores a key information item necessary for decrypting the encrypted content, the apparatus including a secure memory storing attribute information of the content, including the allowable number, an initial value of the allowable number being a predetermined upper limit, and the method including a check out method and a check in method, the check out method comprising:a step (S161) of performing first bilateral authentication between the content management apparatus (1) and a memory card (13) of the memory cards (13), when the allowable number is more than zero, to obtain a first session key (KT1) that is identical to that of the memory card (13) and that is generated as a result of success in the first bilateral authentication;a step (S163) of encrypting the key information item (W[Kc]), using the first session key;a step (S164) of transferring the encrypted content (Kc[C]) and the encrypted key information item (KT1 [W[Kc]]) to the memory card (13) configured to store the encrypted content in the first memory area (13a) and store, in the second memory area, the key information item obtained by decrypting the encrypted key information item using the first session key generated in the memory card (13);anda step of decreasing the allowable number by one when the encrypted content and the encrypted key information item are transferred to the memory card (13),wherein the check in method comprises: a step (S146) of performing second bilateral authentication between the content management apparatus (1) and the memory card (13) whose first memory area (13a) stores the encrypted content and whose second memory area stores the key information item, to obtain a second session key (KT3) that is identical to that of the memory card (13) and that is generated as a result of success in the second bilateral authentication;a step (S501) of generating a random data item (r1), when the second bilateral authentication ends in success;a step (S501) of encrypting the random data item using the second session key;a step (S502, S503) of transferring the encrypted random data item to the memory card (13) configured to erase the key information item in the second memory area by overwriting the key information item with the random data item obtained by decrypting the encrypted random data using the second session key;a step (S504) of performing third bilateral authentication between the content management apparatus (1) and the memory card (13), to obtain a third session key (KT4) that is identical to that of the memory card (13) and that is generated as a result of success in the third bilateral authentication;a step (S505) of receiving an encrypted data item (KT 4[r1]) that is transferred from the memory card (13) configured to read a data item from the same address, in the second memory area, where the key information item has been stored and generate the encrypted data item by encrypting the data item using the third session key;a step (S506) of decrypting the encrypted data item using the third session key;a step (S507) of determining that the key information item is erased from the second memory area when the decrypted data item is identical to the random data item;andincreasing the allowable number by one when the key information item in the second memory area is determined to be erased. Inhaltsverwaltungsverfahren für eine Inhaltsverwaltungsvorrichtung (1) zum Verwalten einer zulässigen Anzahl von verschlüsselten Inhalten, welche verschlüsselte Kopien eines Inhalts sind und auf Speicherkarten (13) aufgezeichnet sind, wobei jede der Speicherkarten (13) ein erstes Speichergebiet (13a), das zumindest einen verschlüsselten Inhalt der verschlüsselten Inhalte speichert, und ein zweites Speichergebiet umfasst, welches ein sicheres Gebiet ist und ein Schlüsselinformationselement speichert, das zum Entschlüsseln des verschlüsselten Inhalts erforderlich ist, wobei die Vorrichtung einen sicheren Speicher umfasst, der Attributsinformationen des Inhalts speichert, einschließlich der zulässigen Anzahl, eines Anfangswerts der zulässigen Anzahl, die eine vorbestimmte obere Grenze ist, und das Verfahren ein Auscheckverfahren und ein Eincheckverfahren umfasst, wobei das Auscheckverfahren aufweist: einen Schritt (S161) zum Durchführen einer ersten bilateralen Authentifizierung zwischen der Inhaltsverwaltungsvorrichtung (1) und einer Speicherkarte (13) der Speicherkarten (13), wenn die zulässige Anzahl größer als Null ist, um einen ersten Sitzungsschlüssel (KT1) zu erhalten, der identisch zu dem der Speicherkarte (13) ist, und der als Ergebnis eines Erfolgs in der ersten bilateralen Authentifizierung erzeugt ist;einen Schritt (S163) zum Verschlüsseln des Schlüsselinformationselements (W[Kc]) unter Verwendung des ersten Sitzungsschlüssels;einen Schritt (S164) zum Übertragen des verschlüsselten Inhalts (Kc[C]) und des verschlüsselten Schlüsselinformationselements (KT1 [W[Kc]]) zu der Speicherkarte (13), die konfiguriert ist, um den verschlüsselten Inhalt in dem ersten Speichergebiet (13a) zu speichern, und um in dem zweiten Speichergebiet das Schlüsselinformationselement zu speichern, das durch Entschlüsseln des verschlüsselten Schlüsselinformationselements unter Verwendung des in der Speicherkarte (13) erzeugten ersten Sitzungsschlüssels erhalten ist;undeinen Schritt zum Verkleinern der zulässigen Anzahl um Eins, wenn der verschlüsselte Inhalt und das verschlüsselte Schlüsselinformationselement zu der Speicherkarte (13) übertragen sind, wobei das Eincheckverfahren aufweist: einen Schritt (S146) zum Durchführen einer zweiten bilateralen Authentifizierung zwischen der Inhaltsverwaltungsvorrichtung (1) und der Speicherkarte (13), deren erstes Speichergebiet (13a) den verschlüsselten Inhalt speichert, und deren zweites Speichergebiet das Schlüsselinformationselement speichert, um einen zweiten Sitzungsschlüssel (KT3) zu erhalten, der identisch zu dem der Speicherkarte (13) ist, und der als Ergebnis eines Erfolgs in der zweiten bilateralen Authentifizierung erzeugt ist;einen Schritt (S501) zum Erzeugen eines Zufallsdatenelements (r1), wenn die zweite bilaterale Authentifizierung erfolgreich endet;einen Schritt (S501) zum Verschlüsseln des Zufallsdatenelements unter Verwendung des zweiten Sitzungsschlüssels;einen Schritt (S502, S503) zum Übertragen des verschlüsselten Zufallsdatenelements zu der Speicherkarte (13), die konfiguriert ist, um das Schlüsselinformationselement in dem zweiten Speichergebiet zu löschen, indem das Schlüsselinformationselement mit dem durch Entschlüsseln der verschlüsselten Zufallsdaten unter Verwendung des zweiten Sitzungsschlüssels erhaltenen Zufallsdatenelement überschrieben wird;einen Schritt (S504) zum Durchführen einer dritten bilateralen Authentifizierung zwischen der Inhaltsverwaltungsvorrichtung (1) und der Speicherkarte (13), um einen dritten Sitzungsschlüssel (KT4) zu erhalten, der identisch zu dem der Speicherkarte (13) ist, und der als Ergebnis eines Erfolgs in der dritten bilateralen Authentifizierung erzeugt ist;einen Schritt (S505) zum Empfangen eines verschlüsselten Datenelements (KT4[r1]), das von der Speicherkarte (13) übertragen ist, die konfiguriert ist, um ein Datenelement aus derselben Adresse in dem zweiten Speichergebiet auszulesen, in welchem das Schlüsselinformationselement gespeichert worden ist, und um das verschlüsselte Datenelement zu erzeugen, indem das Datenelement unter Verwendung des dritten Sitzungsschlüssels verschlüsselt wird;einen Schritt (S506) zum Entschlüsseln des verschlüsselten Datenelements unter Verwendung des dritten Sitzungsschlüssels;einen Schritt (S507) zum Bestimmen, dass das Schlüsselinformationselement aus dem zweiten Speichergebiet gelöscht ist, wenn das entschlüsselte Datenelement identisch zu dem Zufallsdatenelement ist;undErhöhen der zulässigen Anzahl um Eins, wenn das Schlüsselinformationselement in dem zweiten Speichergebiet als zu löschen bestimmt ist. Procédé de gestion de contenu pour un appareil de gestion de contenu (1) pour gérer un nombre admissible de contenus chiffrés qui sont des copies chiffrées d'un contenu et sont enregistrés sur des cartes mémoire (13), chacune des cartes mémoire (13) incluant une première zone de mémoire (13a) stockant au moins un contenu chiffré des contenus chiffrés et une seconde zone de mémoire, qui est une zone sécurisée et stocke un article d'informations de clé nécessaire pour déchiffrer le contenu chiffré, l'appareil incluant une mémoire sécurisée stockant des informations d'attribut du contenu, incluant le nombre admissible, une valeur initiale du nombre admissible étant une limite supérieure prédéterminée, et le procédé incluant un procédé de check-out et un procédé de check-in, le procédé de check-out comprenant : une étape (S161) consistant à effectuer une première authentification bilatérale entre l'appareil de gestion de contenu (1) et une carte mémoire (13) des cartes mémoire (13), lorsque le nombre admissible est supérieur à zéro, pour obtenir une première clé de session (KT1) qui est identique à celle de la carte mémoire (13) et qui est générée à la suite de la réussite de la première authentification bilatérale ;une étape (S163) consistant à chiffrer l'article d'informations de clé (W[Kc]), en utilisant la première clé de session ;une étape (S164) consistant à transférer le contenu chiffré (Kc[C]) et l'article d'informations de clé chiffré (KT1 [W[Kc]]) vers la carte mémoire (13) configurée pour stocker le contenu chiffré dans la première zone de mémoire (13a) et stocker, dans la seconde zone de mémoire, l'article d'informations de clé obtenu en déchiffrant l'article d'informations de clé chiffré en utilisant la première clé de session générée dans la carte mémoire (13) ;etune étape consistant à diminuer le nombre admissible de un lorsque le contenu chiffré et l'article d'informations de clé chiffré sont transférés vers la carte mémoire (13),dans lequel le procédé de check-in comprend : une étape (S146) consistant à effectuer une deuxième authentification bilatérale entre l'appareil de gestion de contenu (1) et la carte mémoire (13) dont la première zone de mémoire (13a) stocke le contenu chiffré et dont la seconde zone de mémoire stocke l'article d'informations de clé, pour obtenir une deuxième clé de session (KT3) qui est identique à celle de la carte mémoire (13) et qui est générée à la suite de la réussite de la deuxième authentification bilatérale ;une étape (S501) consistant à générer un article de données aléatoire (r1), lorsque la deuxième authentification bilatérale se termine par une réussite ;une étape (S501) consistant à chiffrer l'article de données aléatoire en utilisant la deuxième clé de session ;une étape (S502, S503) consistant à transférer l'article de données aléatoire chiffré vers la carte mémoire (13) configurée pour effacer l'article d'informations de clé dans la seconde zone de mémoire en écrasant l'article d'informations de clé avec l'article de données aléatoire obtenu en déchiffrant les données aléatoires chiffrées en utilisant la deuxième clé de session ;une étape (S504) consistant à effectuer une troisième authentification bilatérale entre l'appareil de gestion de contenu (1) et la carte mémoire (13), pour obtenir une troisième clé de session (KT4) qui est identique à celle de la carte mémoire (13) et qui est générée à la suite de la réussite de la troisième authentification bilatérale ;une étape (S505) consistant à recevoir un article de données chiffré (KT 4[r1]) qui est transféré depuis la carte mémoire (13) configurée pour lire un article de données depuis la même adresse, dans la seconde zone de mémoire, où l'article d'informations de clé a été stocké et générer l'article de données chiffré en chiffrant l'article de données en utilisant la troisième clé de session ;une étape (S506) consistant à déchiffrer l'article de données chiffré en utilisant la troisième clé de session ;une étape (S507) consistant à déterminer que l'article d'informations de clé est effacé de la seconde zone de mémoire lorsque l'article de données déchiffré est identique à l'article de données aléatoire ;etaugmenter le nombre admissible de un lorsque l'article d'informations de clé dans la seconde zone de mémoire est déterminé comme étant effacé.
- 2A content management system including a content management apparatus (1) and a plurality of memory cards (13) for managing an allowable number of encrypted contents which are encrypted copies of a content and are recorded on the memory cards (13), each of the memory cards (13) including a first memory area (13a) storing at least an encrypted content of the encrypted contents and a second memory area, which is a secure area and stores a key information item necessary for decrypting the encrypted content, the apparatus including a secure memory storing attribute information of the content, including the allowable number, an initial value of the allowable number being a predetermined upper limit, the system comprising:means (1) for executing a check out process and means (1) for executing a check in process, whereinthe means for executing a check out process in the content management apparatus (1) comprises: means (2, S161) for performing first bilateral authentication between the content management apparatus (1) and a memory card (13) of the memory cards (13), when the allowable number is more than zero, to obtain a first session key that is identical to that of the memory card (13) and that is generated as a result of success in the first bilateral authentication;means (2, S163) for encrypting the key information item, using the first session key;means (2, 6, S164) for transferring the encrypted content and the encrypted key information item to the memory card (13) configured to store the encrypted content in the first memory area (13a) and store, in the second memory area, the key information item obtained by decrypting the encrypted key information item using the first session key generated in the memory card (13);andmeans (2, 7, 8) for decreasing the allowable number by one when the encrypted content and the encrypted key information item are transferred to the memory card (13),wherein the means for executing the check in process in the content management apparatus (1) comprises: means (2, S146) for performing second bilateral authentication between the content management apparatus (1) and the memory card (13) whose first memory area (13a) stores the encrypted content and whose second memory area (13c) stores the key information item, to obtain a second session key that is identical to that of the memory card bilateral authentication;means (2, S501) for generating a random data item, when the second bilateral authentication ends in success;means (2, S501) for encrypting random data item using the second session key;means (2, 6, S502, S503) for transferring the encrypted random data item to the memory card (13) configured to erase the key information item in the second memory are by overwriting the key information item with the random data item obtained by decrypting the encrypted random data using the second session key;means (2, S504) for performing third bilateral authentication between the content management apparatus (1) and the memory card (13), to obtain a third session key that is identical to that of the memory card (13) and that is generated as a result of success in the third bilateral authentication;means (2, 6, S505) for receiving an encrypted data item that is transferred from the memory card (13) configured to read a data item from the same address, in the second memory area (13c), where the key information item has been stored, and for generating the encrypted data item by encrypting the data item using the third session key;means (2, S506) for decrypting the encrypted data item using the third session key;means (2, S507) for determining that the key information item is erased from the second memory area (13c) when the decrypted data item is identical to the random data item;andmeans (2, 7, 8) for increasing the allowable number by one when the key information item in the second memory area (13c) is determined to be erased. Inhaltsverwaltungssystem einschließlich einer Inhaltsverwaltungsvorrichtung (1) und einer Vielzahl von Speicherkarten (13) zum Verwalten einer zulässigen Anzahl von verschlüsselten Inhalten, welche verschlüsselte Kopien eines Inhalts sind und auf den Speicherkarten (13) aufgezeichnet sind, wobei jede der Speicherkarten (13) ein erstes Speichergebiet (13a), das zumindest einen verschlüsselten Inhalt der verschlüsselten Inhalte speichert, und ein zweites Speichergebiet umfasst, welches ein sicheres Gebiet ist und ein Schlüsselinformationselement speichert, das zum Entschlüsseln des verschlüsselten Inhalts erforderlich ist, wobei die Vorrichtung einen sicheren Speicher umfasst, der Attributsinformationen des Inhalts speichert, einschließlich der zulässigen Anzahl, eines Anfangswerts der zulässigen Anzahl, die eine vorbestimmte obere Grenze ist, wobei das System aufweist: Mittel (1) zum Ausführen eines Auscheckprozesses und Mittel (1) zum Ausführen eines Eincheckprozesses, wobeidas Mittel zum Ausführen eines Auscheckprozesses in der Inhaltsverwaltungsvorrichtung (1) aufweist: Mittel (2, S161) zum Durchführen einer ersten bilateralen Authentifizierung zwischen der Inhaltsverwaltungsvorrichtung (1) und einer Speicherkarte (13) der Speicherkarten (13), wenn die zulässige Anzahl größer als Null ist, um einen ersten Sitzungsschlüssel zu erhalten, der identisch zu dem der Speicherkarte (13) ist, und der als Ergebnis eines Erfolgs in der ersten bilateralen Authentifizierung erzeugt ist;Mittel (2, S163) zum Verschlüsseln des Schlüsselinformationselements unter Verwendung des ersten Sitzungsschlüssels;Mittel (2, 6, S164) zum Übertragen des verschlüsselten Inhalts und des verschlüsselten Schlüsselinformationselements zu der Speicherkarte (13), die konfiguriert ist, um den verschlüsselten Inhalt in dem ersten Speichergebiet (13a) zu speichern, und um in dem zweiten Speichergebiet das durch Entschlüsseln des verschlüsselten Schlüsselinformationselements unter Verwendung des in der Speicherkarte (13) erzeugten ersten Sitzungsschlüssels erhaltene Schlüsselinformationselement zu speichern;undMittel (2, 7, 8) zum Verkleinern der zulässigen Anzahl um Eins, wenn der verschlüsselte Inhalt und das verschlüsselte Schlüsselinformationselement zu der Speicherkarte (13) übertragen sind,wobei das Mittel zum Ausführen des Eincheckprozesses in der Inhaltsverwaltungsvorrichtung (1) aufweist: Mittel (2, S146) zum Durchführen einer zweiten bilateralen Authentifizierung zwischen der Inhaltsverwaltungsvorrichtung (1) und der Speicherkarte (13), deren erstes Speichergebiet (13a) den verschlüsselten Inhalt speichert, und deren zweites Speichergebiet (13c) das Schlüsselinformationselement speichert, um einen zweiten Sitzungsschlüssel zu erhalten, der identisch zu dem der bilateralen Speicherkartenauthentifizierung ist;Mittel (2, S501) zum Erzeugen eines Zufallsdatenelements, wenn die zweite bilaterale Authentifizierung erfolgreich endet;Mittel (2, S501) zum Verschlüsseln eines Zufallsdatenelements unter Verwendung des zweiten Sitzungsschlüssels;Mittel (2, 6, S502, S503) zum Übertragen des verschlüsselten Zufallsdatenelements zu der Speicherkarte (13), die konfiguriert ist, um das Schlüsselinformationselement in dem zweiten Speichergebiet zu löschen, indem das Schlüsselinformationselement mit dem durch Entschlüsseln der verschlüsselten Zufallsdaten unter Verwendung des zweiten Sitzungsschlüssels erhaltenen Zufallsdatenelement überschrieben wird;Mittel (2, S504) zum Durchführen einer dritten bilateralen Authentifizierung zwischen der Inhaltsverwaltungsvorrichtung (1) und der Speicherkarte (13), um einen dritten Sitzungsschlüssel zu erhalten, der identisch zu dem der Speicherkarte (13) ist, und der als Ergebnis eines Erfolgs in der dritten bilateralen Authentifizierung erzeugt ist;Mittel (2, 6, S505) zum Empfangen eines verschlüsselten Datenelements, das von der Speicherkarte (13) übertragen ist, die konfiguriert ist, um ein Datenelement aus derselben Adresse in dem zweiten Speichergebiet (13c) auszulesen, in welchem das Schlüsselinformationselement gespeichert worden ist, und zum Erzeugen des verschlüsselten Datenelements, indem das Datenelement unter Verwendung des dritten Sitzungsschlüssels verschlüsselt wird;Mittel (2, S506) zum Entschlüsseln des verschlüsselten Datenelements unter Verwendung des dritten Sitzungsschlüssels;Mittel (2, S507) zum Bestimmen, dass das Schlüsselinformationselement aus dem zweiten Speichergebiet (13c) gelöscht ist, wenn das entschlüsselte Datenelement identisch zu dem Zufallsdatenelement ist;undMittel (2, 7, 8) zum Erhöhen der zulässigen Anzahl um Eins, wenn das Schlüsselinformationselement in dem zweiten Speichergebiet (13c) als zu löschen bestimmt ist. Système de gestion de contenu incluant un appareil de gestion de contenu (1) et une pluralité de cartes mémoire (13) pour gérer un nombre admissible de contenus chiffrés qui sont des copies chiffrées d'un contenu et sont enregistrés sur les cartes mémoire (13), chacune des cartes mémoire (13) incluant une première zone de mémoire (13a) stockant au moins un contenu chiffré des contenus chiffrés et une seconde zone de mémoire, qui est une zone sécurisée et stocke un article d'informations de clé nécessaire pour déchiffrer le contenu chiffré, l'appareil incluant une mémoire sécurisée stockant des informations d'attribut du contenu, incluant le nombre admissible, une valeur initiale du nombre admissible étant une limite supérieure prédéterminée, le système comprenant : des moyens (1) pour exécuter un processus de check-out et des moyens (1) pour exécuter un processus de check-in, oùles moyens pour exécuter un processus de check-out dans l'appareil de gestion de contenu (1) comprennent : des moyens (2, S161) pour effectuer une première authentification bilatérale entre l'appareil de gestion de contenu (1) et une carte mémoire (13) des cartes mémoire (13), lorsque le nombre admissible est supérieur à zéro, pour obtenir une première clé de session qui est identique à celle de la carte mémoire (13) et qui est générée à la suite de la réussite de la première authentification bilatérale ;des moyens (2, S163) pour chiffrer l'article d'informations de clé, en utilisant la première clé de session ;des moyens (2, 6, S164) pour transférer le contenu chiffré et l'article d'informations de clé chiffré vers la carte mémoire (13) configurée pour stocker le contenu chiffré dans la première zone de mémoire (13a) et stocker, dans la seconde zone de mémoire, l'article d'informations de clé obtenu en déchiffrant l'article d'informations de clé chiffré en utilisant la première clé de session générée dans la carte mémoire (13) ;etdes moyens (2, 7, 8) pour diminuer le nombre admissible de un lorsque le contenu chiffré et l'article d'informations de clé chiffré sont transférés vers la carte mémoire (13),dans lequel les moyens pour exécuter le processus de check-in dans l'appareil de gestion de contenu (1) comprennent : des moyens (2, S146) pour effectuer une deuxième authentification bilatérale entre l'appareil de gestion de contenu (1) et la carte mémoire (13) dont la première zone de mémoire (13a) stocke le contenu chiffré et dont la seconde zone de mémoire (13c) stocke l'article d'informations de clé, pour obtenir une deuxième clé de session qui est identique à celle de l'authentification bilatérale de la carte mémoire ;des moyens (2, S501) pour générer un article de données aléatoire, lorsque la deuxième authentification bilatérale se termine par une réussite ;des moyens (2, S501) pour chiffrer l'article de données aléatoire en utilisant la deuxième clé de session ;des moyens (2, 6, S502, S503) pour transférer l'article de données aléatoire chiffré vers la carte mémoire (13) configurée pour effacer l'article d'informations de clé dans la seconde zone de mémoire en écrasant l'article d'informations de clé avec l'article de données aléatoire obtenu en déchiffrant les données aléatoires chiffrées en utilisant la deuxième clé de session ;des moyens (2, S504) pour effectuer une troisième authentification bilatérale entre l'appareil de gestion de contenu (1) et la carte mémoire (13), pour obtenir une troisième clé de session qui est identique à celle de la carte mémoire (13) et qui est générée à la suite de la réussite de la troisième authentification bilatérale ;des moyens (2, 6, S505) pour recevoir un article de données chiffré qui est transféré depuis la carte mémoire (13) configurée pour lire un article de données depuis la même adresse, dans la seconde zone de mémoire (13c), où l'article d'informations de clé a été stocké, et pour générer l'article de données chiffré en chiffrant l'article de données en utilisant la troisième clé de session ;des moyens (2, S506) pour déchiffrer l'article de données chiffré en utilisant la troisième clé de session ;des moyens (2, S507) pour déterminer que l'article d'informations de clé est effacé de la seconde zone de mémoire (13c) lorsque l'article de données déchiffré est identique à l'article de données aléatoire ;etdes moyens (2, 7, 8) pour augmenter le nombre admissible de un lorsque l'article d'informations de clé dans la seconde zone de mémoire (13c) est déterminé comme étant effacé.
- 3A memory card (13) for a system according to claim 2 comprising; means (101) for executing the check out process and means (101) for executing the check in process, wherein the means for executing the check out process comprises:means (101, S161) for performing the first bilateral authentication to obtain the first session key as the result of success in the first bilateral authentication;means (101, S163, S164) for receiving the encrypted content and the encrypted key information item;means (103, 104) for storing the encrypted content in the first memory area (13a);means (101, S164) for decrypting the encrypted key information item using the first session key generated in the memory card (13), to obtain the key information item;means (102) for storing the key information item in the second memory area (13c),wherein means for executing the check in process comprises: means (101, S146) for performing the second bilateral authentication to obtain the second session key;means (101, S501, S502) for receiving the random data item encrypted when the second bilateral authentication ends in success;means (101, S502) for decrypting the random data item encrypted using the second session key generated in the memory card (13) when the second bilateral authentication ends in success;means (101, S503) for erasing the key information item in the second memory area (13c) by overwriting the key information item with the random data item;means (101, S504) for performing the third bilateral authentication to obtain the third session key;means (101, S505) for reading out the data item from the same address, in the second memory area (13c), where the key information item has been stored;means (101, S505) for encrypting the data item read out from the second memory area (13c), using the third session key, to obtain the encrypted data item;andmeans (101) for transferring the encrypted data. Carte mémoire (13) pour un système selon la revendication 2, comprenant : des moyens (101) pour exécuter le processus de check-out etdes moyens (101) pour exécuter le processus de check-in, oùles moyens pour exécuter le processus de check-out comprennent : des moyens (101, S161) pour effectuer la première authentification bilatérale pour obtenir la première clé de session à la suite de la réussite de la première authentification bilatérale ;des moyens (101, S163, S164) pour recevoir le contenu chiffré et l'article d'informations de clé chiffré ;des moyens (103, 104) pour stocker le contenu chiffré dans la première zone de mémoire (13a) ;des moyens (101, S164) pour déchiffrer l'article d'informations de clé chiffré en utilisant la première clé de session générée dans la carte mémoire (13), pour obtenir l'article d'informations de clé ;des moyens (102) pour stocker l'article d'informations de clé dans la seconde zone de mémoire (13c), oùdes moyens pour exécuter le processus de check-in comprennent : des moyens (101, S146) pour effectuer la deuxième authentification bilatérale pour obtenir la deuxième clé de session ;des moyens (101, S501, S502) pour recevoir l'article de données aléatoire chiffré lorsque la deuxième authentification bilatérale se termine par une réussite ;des moyens (101, S502) pour déchiffrer l'article de données aléatoire chiffré en utilisant la deuxième clé de session générée dans la carte mémoire (13) lorsque la deuxième authentification bilatérale se termine par une réussite ;des moyens (101, S503) pour effacer l'article d'informations de clé dans la seconde zone de mémoire (13c) en écrasant l'article d'informations de clé avec l'article de données aléatoire ;des moyens (101, S504) pour effectuer la troisième authentification bilatérale pour obtenir la troisième clé de session ;des moyens (101, S505) pour sortir en lecture l'article de données de la même adresse, dans la seconde zone de mémoire (13c), où l'article d'informations de clé a été stocké ;des moyens (101, S505) pour chiffrer l'article de données sorti en lecture de la seconde zone de mémoire (13c), en utilisant la troisième clé de session pour obtenir l'article de données chiffré ;etdes moyens (101) pour transférer les données chiffrées. Speicherkarte (13) für ein System nach Anspruch 2, aufweisend: Mittel (101) zum Ausführen des Auscheckprozesses, undMittel (101) zum Ausführen des Eincheckprozesses, wobei das Mittel zum Ausführen des Auscheckprozesses aufweist: Mittel (101, S161) zum Durchführen der ersten bilateralen Authentifizierung, um den ersten Sitzungsschlüssel als Ergebnis eines Erfolgs in der ersten bilateralen Authentifizierung zu erhalten;Mittel (101, S163, S164) zum Empfangen des verschlüsselten Inhalts und des verschlüsselten Schlüsselinformationselements;Mittel (103, 104) zum Speichern des verschlüsselten Inhalts in dem ersten Speichergebiet (13a);Mittel (101, S164) zum Entschlüsseln des verschlüsselten Schlüsselinformationselements unter Verwendung des in der Speicherkarte (13) erzeugten ersten Sitzungsschlüssels, um das Schlüsselinformationselement zu erhalten;Mittel (102) zum Speichern des Schlüsselinformationselements in dem zweiten Speichergebiet (13c), wobeidas Mittel zum Ausführen des Eincheckprozesses aufweist: Mittel (101, S146) zum Durchführen der zweiten bilateralen Authentifizierung, um den zweiten Sitzungsschlüssel zu erhalten;Mittel (101, S501, S502) zum Empfangen des Zufallsdatenelements, das verschlüsselt ist, wenn die zweite bilaterale Authentifizierung erfolgreich endet;Mittel (101, S502) zum Entschlüsseln des Zufallsdatenelements, das unter Verwendung des zweiten Sitzungsschlüssels verschlüsselt ist, der in der Speicherkarte (13) erzeugt ist, wenn die zweite bilaterale Authentifizierung erfolgreich endet;Mittel (101, S503) zum Löschen des Schlüsselinformationselements in dem zweiten Speichergebiet (13c), indem das Schlüsselinformationselement mit dem Zufallsdatenelement überschrieben wird;Mittel (101, S504) zum Durchführen der dritten bilateralen Authentifizierung, um den dritten Sitzungsschlüssel zu erhalten;Mittel (101, S505) zum Auslesen des Datenelements aus derselben Adresse in dem zweiten Speichergebiet (13c), in welchem das Schlüsselinformationselement gespeichert worden ist;Mittel (101, S505) zum Verschlüsseln des aus dem zweiten Speichergebiet (13c) ausgelesenen Datenelements unter Verwendung des dritten Sitzungsschlüssels, um das verschlüsselte Datenelement zu erhalten;undMittel (101) zum Übertragen der verschlüsselten Daten.
- 4A content management apparatus (1) for a system according to claim 2 comprising:means (1) for executing the check out process and means (1) for executing the check in process, wherein the means for executing the check out process comprises: means (2, S161) for performing the first bilateral authentication, when the allowable number is more than zero, to obtain the first session key that is generated as a result of success in the first bilateral authentication;means (2, S163) for encrypting the key information item, using the first session key;means (2, 6, S164) for transferring the encrypted content and the encrypted key information item;andmeans (2, 7, 8) for decreasing the allowable number by one when the encrypted content and the encrypted key information item are transferred,wherein the means for executing the check in process comprises: means (2, S146) for performing the second bilateral authentication, to obtain the second session key;means (2, S501) for generating the random data item, when the second bilateral authentication ends in success;means (2, S501) for encrypting random data item using the second session key;means (2, 6, S502, S503) for transferring the encrypted random data item;means (2, S504) for performing the third bilateral authentication, to obtain the third session key that is generated as a result of success in the third bilateral authentication;means (2, 6, S505) for receiving the encrypted data item;means (2, S506) for decrypting the encrypted data item using the third session key;means (2, S507) for determining that the key information item is erased from the second memory area (13c) when the decrypted data item is identical to the random data item;andmeans (2, 7, 8) for increasing the allowable number by one when the key information item in the second memory area (13c) is determined to be erased. Appareil de gestion de contenu (1) pour un système selon la revendication 2, comprenant : des moyens (1) pour exécuter le processus de check-out et des moyens (1) pour exécuter le processus de check-in, où les moyens pour exécuter le processus de check-out comprennent : des moyens (2, S161) pour effectuer la première authentification bilatérale, lorsque le nombre admissible est supérieur à zéro, pour obtenir une première clé de session qui est générée à la suite de la réussite de la première authentification bilatérale ;des moyens (2, S163) pour chiffrer l'article d'informations de clé, en utilisant la première clé de session ;des moyens (2, 6, S164) pour transférer le contenu chiffré et l'article d'informations de clé chiffré ;etdes moyens (2, 7, 8) pour diminuer le nombre admissible de un lorsque le contenu chiffré et l'article d'informations de clé chiffré sont transférés,dans lequel les moyens pour exécuter le processus de check-in comprennent : des moyens (2, S146) pour effectuer la deuxième authentification bilatérale, pour obtenir la deuxième clé de session ;des moyens (2, S501) pour générer l'article de données aléatoire, lorsque la deuxième authentification bilatérale se termine par une réussite ;des moyens (2, S501) pour chiffrer l'article de données aléatoire en utilisant la deuxième clé de session ;des moyens (2, 6, S502, S503) pour transférer l'article de données aléatoire chiffré ;des moyens (2, S504) pour effectuer la troisième authentification bilatérale, pour obtenir la troisième clé de session qui est générée à la suite de la réussite de la troisième authentification bilatérale ;des moyens (2, 6, S505) pour recevoir l'article de données chiffré ;des moyens (2, S506) pour déchiffrer l'article de données chiffré en utilisant la troisième clé de session ;des moyens (2, S507) pour déterminer que l'article d'informations de clé est effacé de la seconde zone de mémoire (13c) lorsque l'article de données déchiffré est identique à l'article de données aléatoire ;etdes moyens (2, 7, 8) pour augmenter le nombre admissible de un lorsque l'article d'informations de clé dans la seconde zone de mémoire (13c) est déterminé comme étant effacé. Inhaltsverwaltungsvorrichtung (1) für ein System nach Anspruch 2, aufweisend: Mittel (1) zum Ausführen des Auscheckprozesses und Mittel (1) zum Ausführen des Eincheckprozesses, wobei das Mittel zum Ausführen des Auscheckprozesses aufweist: Mittel (2, S161) zum Durchführen der ersten bilateralen Authentifizierung, wenn die zulässige Anzahl größer als Null ist, um den ersten Sitzungsschlüssel zu erhalten, der als Ergebnis eines Erfolgs in der ersten bilateralen Authentifizierung erzeugt ist;Mittel (2, S163) zum Verschlüsseln des Schlüsselinformationselements unter Verwendung des ersten Sitzungsschlüssels;Mittel (2, 6, S164) zum Übertragen des verschlüsselten Inhalts und des verschlüsselten Schlüsselinformationselements;undMittel (2, 7, 8) zum Verkleinern der zulässigen Anzahl um Eins, wenn der verschlüsselte Inhalt und das verschlüsselte Schlüsselinformationselement übertragen sind,wobei das Mittel zum Ausführen des Eincheckprozesses aufweist: Mittel (2, S146) zum Durchführen der zweiten bilateralen Authentifizierung, um den zweiten Sitzungsschlüssel zu erhalten;Mittel (2, S501) zum Erzeugen des Zufallsdatenelements, wenn die zweite bilaterale Authentifizierung erfolgreich endet;Mittel (2, S501) zum Verschlüsseln eines Zufallsdatenelements unter Verwendung des zweiten Sitzungsschlüssels;Mittel (2, 6, S502, S503) zum Übertragen des verschlüsselten Zufallsdatenelements;Mittel (2, S504) zum Durchführen der dritten bilateralen Authentifizierung, um den dritten Sitzungsschlüssel zu erhalten, der als Ergebnis eines Erfolgs in der dritten bilateralen Authentifizierung erzeugt ist;Mittel (2, 6, S505) zum Empfangen des verschlüsselten Datenelements;Mittel (2, S506) zum Entschlüsseln des verschlüsselten Datenelements unter Verwendung des dritten Sitzungsschlüssels;Mittel (2, S507) zum Bestimmen, dass das Schlüsselinformationselement aus dem zweiten Speichergebiet (13c) gelöscht ist, wenn das verschlüsselte Datenelement zu dem Zufallsdatenelement identisch ist;undMittel (2, 7, 8) zum Erhöhen der zulässigen Anzahl um Eins, wenn das Schlüsselinformationselement in dem zweiten Speichergebiet (13c) als zu löschen bestimmt ist.
Independent claims4
150 paragraphs, as filed
The present invention relates to a contents management method for protecting copyrights by limiting the number of copied contents and a contents management apparatus using the same and, more particularly, to an erase method of copied contents recorded on a recording medium.
Conventionally, contents (literary works and the like) have undergone copy management. More specifically, by managing copy generations or the number of copies, copyright protection and use are balanced.
On the other hand, the concept "move" has appeared as an alternative to copy management. "Copy" does not erase original data, but "move" transfers data to another location (recording medium (media)) and erases original data. Thus, a protection technique against "move" has appeared. Such technique has emerged due to digitization of contents and prevalence of networks and the like.
In recent years, since copies faithful to an original can be formed via the network or the like, it is becoming increasingly difficult to protect copyrights by only copy management. Also, copyrights cannot be managed against unlimited moves from media to media, e.g., commercial distribution (by means of move) of data.
Under the circumstance, it has become hard to reliably protect copies of original data (especially, contents, copyright of which must be protected).
Especially, in contents management for copyright protection in which copied contents are recorded on and erased from a recording medium while limiting the number of copied contents, the copied contents recorded on a given recording medium must be surely erased upon moving the copied contents recorded on that recording medium. In this case, unlike recording of copied contents, the copied contents can be easily avoided from being erased from the recording medium by cutting a signal or the like so that a third party does not receive a command or the like for erasing the copied contents, in that procedure.
<nplcit id="ncit0001" npl-type="s"><text>SDMI PORTABLE DEVICE SPECIFICATION, Part 1, Version 1.0, July 8,1999</text></nplcit>, Secure Digital Music Initative, XP000997330 discloses an open and interoperable standard for security in connection with the distribution of copyright protected music. The standard defining a check-out and a check-in procedure, for decrementing or respectively incrementing the number of permitted copies.
It is an object of the present invention to provide a contents management method which can reliably and safely erase content recorded on a recording medium in a content management in which content is recorded on and erased from the recording medium while limiting the number of copied content to be recorded on the recording medium, a contents management apparatus using the method, and a recording medium.
According to the present invention the above object is achieved by means of the combination of features of claims 1, 2, 3 or 4.
The invention can be more fully understood from the following detailed description when taken in conjunction with the accompanying drawings, in which: <ul id="ul0001" list-style="none" compact="compact"><li><figref idref="f0001">FIG. 1</figref> is a block diagram showing an example of the arrangement of a music contents use management system (LCM) using a contents management technique for limiting the number of copied contents that can be recorded on a recording medium according to an embodiment of the present invention;</li><li><figref idref="f0002">FIG. 2</figref> shows an example of the map of a memory area.</li><li><figref idref="f0002">FIG. 3</figref> is a block diagram showing an example of the internal arrangement of a recording/playback apparatus (PD);</li><li><figref idref="f0003">FIGS. 4A to 4C</figref> are views for explaining the features of three different recording media (<figref idref="f0003">Figs. 4A and 4B</figref> mot belonging to the invention);</li><li><figref idref="f0004">FIG. 5</figref> is a block diagram showing an example of the internal arrangement of a medium interface (I/F);</li><li><figref idref="f0004">FIG. 6</figref> is a view for explaining the recorded content of a recording medium after check-in (not belonging to the invention);</li><li><figref idref="f0005">FIGS. 7A to 7C</figref> show storage examples of guest books stored in a secure area of an LCM;</li><li><figref idref="f0006">FIGS. 8A and 8B</figref> are views for explaining an outline of a bilateral authentication method;</li><li><figref idref="f0007">FIG. 9</figref> is a flow chart for explaining a check-in/check-out process sequence, and showing the sequence until the type of medium is checked, and a process corresponding to the determined type is selected;</li><li><figref idref="f0007">FIG. 10</figref> is a chart for explaining a sequence upon check-out when the type of recording medium is level 2 (not belonging to the invention);</li><li><figref idref="f0008">FIG. 11</figref> is a chart for explaining a sequence upon playback when the type of recording medium is level 2 (not belonging to the invention);</li><li><figref idref="f0009">FIG. 12</figref> is a chart for explaining a sequence upon check-in when the type of recording medium is level 2 (not belonging to the invention);</li><li><figref idref="f0010">FIG. 13</figref> is a chart for explaining another sequence upon check-out when the type of recording medium is level 2 (not belonging to the invention);</li><li><figref idref="f0011">FIG. 14</figref> is a chart for explaining still another sequence upon check-out when the type of recording medium is level 2;</li><li><figref idref="f0012">FIG. 15</figref> is a chart for explaining another sequence upon playback when the type of recording medium is level 2;</li><li><figref idref="f0013">FIG. 16</figref> is a chart for explaining a sequence upon check-out when the type of recording medium is level 0 (not belonging to the invention);</li><li><figref idref="f0012">FIG. 17</figref> is a chart for explaining a sequence upon playback when the type of recording medium is level 0 (not belonging to the invention);</li><li><figref idref="f0014">FIG. 18</figref> is a chart for explaining a sequence upon check-in when the type of recording medium is level 0 (not belonging to the invention);</li><li><figref idref="f0015">FIG. 19</figref> is a chart for explaining another sequence upon check-in when the type of recording medium is level 0 (not belonging to the invention);</li><li><figref idref="f0016">FIG. 20</figref> is a chart for explaining another sequence upon check-out when the type of recording medium is level 0 (not belonging to the invention);</li><li><figref idref="f0017">FIG. 21</figref> is a chart for explaining another sequence upon playback when the type of recording medium is level 0 (not belonging to the invention);</li><li><figref idref="f0018">FIG. 22</figref> is a chart for explaining processing operation of a bilateral authentication process (AKE) ;</li><li><figref idref="f0019">FIG. 23</figref> is a chart for explaining another processing operation of a bilateral authentication process (AKE) ; and</li><li><figref idref="f0017">FIG. 24</figref> shows the arrangement of a recording medium of level 2 shown in <figref idref="f0003">FIG. 4C</figref> in more detail.</li></ul>
An embodiment of the present invention will be explained hereinafter with reference to the accompanying drawings.
<figref idref="f0001">FIG. 1</figref> shows an example of the arrangement of a music contents use management system (to be also simply referred to as an LCM (Licensed Compliant module) hereinafter) which limits the number of copied contents that can be recorded on a recording medium according to this embodiment, and records copied content on a medium, plays back copied content recorded on a medium, and so forth. Note that music is used as an example of content. However, the present invention is not limited to such specific content, and movies, game software programs, and the like may be used. A memory card (MC) is used as a medium. However, the present invention is not limited to such medium, and various other recording media such as a floppy disk, DVD, and the like may be used.
An EMD (Electronic Music Distributor) is a music distribution server or music distribution broadcast station.
A contents use management system 1 is, for example, a personal computer (PC), which comprises receivers #1 to #3 corresponding to a plurality of EMDs (EMD#1 to EMD#3 in this case), and receives encrypted contents, their licenses (the use condition and decryption key Kc for the encrypted content), and the like distributed by the EMDs. Receivers #1 to #3 may have a playback function or a charging function. The user uses the playback function to listen to samples of the distributed music content. Also, the user can purchase the content he or she likes using the charging function.
The LCM 1 comprises a secure contents server (Secure Music Server: SMS in this case; to be also simply referred to as an SMS hereinafter) 2, and the content the user has purchased are stored in the SMS 2 via an EMD interface (I/F) 3. The music contents are decrypted by the EMD I/F 3 as needed, and undergo format conversion and re-encryption. Upon receiving the encrypted content, the SMS 2 stores the received contents in a music data memory 10, and a music data decryption key in a license memory 9. The SMS 2 may have a playback function. With this playback function, the music contents managed by the SMS 2 can be played back on the PC.
The SMS 2 has a function of outputting content data to a medium (to be also simply referred to as an MC (memory card) hereinafter) 13. The user can play back the content recorded on the MC 13 by setting it in a recording/playback apparatus (to be also simply referred to as a PD (Portable/Personal Device) hereinafter).
The SMS 2 records content on the MC 13 directly via a medium (MC) interface 6 or with the intervention of the PD 12.
A device ID memory 4 comprises, e.g., a ROM which stores identification information (device ID) of the LCM.
The MC 13 has identification information (MID) which is unique to that medium and cannot be rewritten, and the content stored in the MC 13 may be encrypted by an encryption key which depends on the MC 13.
A check-in/check-out process will be explained first using the LCM 1 shown in <figref idref="f0001">FIG. 1</figref>.
The check-out process means making a copy of "parent" content stored in the LCM 1 on the MC 13 as "child" content. The "child" content can be freely played back by the PD 12, but it is not allowed to form "grandchild" content from the "child". The number of "children" a "parent" can have is defined as an attribute of "parent". On the other hand, the check-in process is to connect the MC 13 to the LCM 1 and erase (or disable to use) "child" content by the LCM 1, i.e., to recover the right of "parent" content in the LCM 1 to form one "child". This process is also called check-in at "parent".
When this check-in/check-out process is simply implemented by the conventional LCM 1, the following "attack" is present in practice. More specifically, "child" stored in the MC 13 is saved in another recording medium (by removing its MID), and "child" in the MC 13 checks in at "parent". The previously saved "child" is written back to that MC 13. Since check-in has already been done, "parent" on the LCM 1 can copy "child" on another MC 13. This method can form an arbitrary number of "children" that can be used.
The aforementioned "attack" can be defended by authentication upon data transfer between the MC 13 and LCM 1. That is, assume that the MC 13 does not accept data transfer from an LCM other than an authentic LCM 1, and the LCM 1 does not accept data transfer from an MC other than an authentic MC 13. In this case, "child" in the MC 13 cannot be saved in another recording medium. Also, disguised check-in cannot be done at the LCM 1. Therefore, the aforementioned "attack" is no longer effective.
However, the check-in/check-out process cannot be implemented even under the premise of authentication between the LCM 1 and MC 13, because of the presence of the following "attack". That is, before "parent" on the LCM 1 forms any "child", data of the LCM 1 (especially, information in the license memory 9) is backed up to another recording medium. After "child" is copied to the MC 13, the backed-up data of the LCM 1 is restored. Since "parent" of the LCM 1 recovers the state before it forms "child", it can form "child" on another MC 13. In this manner, an arbitrary number of "children" can be formed.
In order to implement the check-in/check-out process that can defend against such attack, an area (secure area) which cannot be accessed by a public procedure is on the storage area of the MC 13, and is used to record information required for bilateral authentication and information required for content decryption, an identification information (device ID) list (revocation list (RVC list)) of devices (LCM 1, PD 12) that cannot be accessed, and the like (see <figref idref="f0002">FIG. 2</figref>). Also, an area (secure area) that can be accessed by only a private procedure is on the storage area (e.g., a hard disk (HDD) when the LCM 1 comprises a PC) of the LCM 1, and is used to store a guest book (to be described later) (see <figref idref="f0002">FIG. 2</figref>). Furthermore, an area (secure area) that can be accessed by only a private procedure may also be on the storage area of the PD 12, and may be used to record information required for content decryption (see <figref idref="f0002">FIG. 2</figref>). Note that an area other than the secure area in the storage area, which can be accessed by a normal procedure, will be referred to as a public area.
As shown in <figref idref="f0001">FIG. 1</figref>, the LCM 1 comprises a guest book memory 8 on the secure area, and a secure area driver 7 for reading data from the secure area after the SMS 2 executes a specific secure procedure for accessing this guest book memory 8.
As shown in <figref idref="f0003">FIG. 4C</figref>, the MC 13 comprises an identification information memory (ROM) 13b which stores identification information MID of the MC 13, and cannot be externally rewritten and copied, a secure area 13c, a public area (rewritable RAM) 13a, and a switch (SW) 13e which opens a gate to allow access to the secure area 13c only when an authentication unit 13d authenticates and confirms an authentic partner every time the secure area 13c is accessed.
Note that three different types of MCs 13 can be used in this embodiment. The type of MC 13 which has both identification information MID and the secure area, as shown in <figref idref="f0003">FIG. 4C</figref>, is called "level 2". The type of MC 13 which does not have any secure area but has identification information MID, as shown in <figref idref="f0003">FIG. 4B</figref>, is called "level 1". The type of MC 13 which has neither the secure area nor identification information, and has only a public area, as shown in <figref idref="f0003">FIG. 4A</figref>, is called "level 0". Only "level 2" belongs to the present invention. In order to discriminate these types, for example, level 0 can be discriminated from other types by checking the presence/absence of identification information MID, and levels 1 and 2 can be discriminated based on the format of identification information MID. For example, when identification information is a serial number, a medium having identification information equal to or larger than a predetermined value is determined to be level 2.
An MC 13 of level 2 will be exemplified below unless otherwise specified.
The MC 13 is set in the PD 12 connected to the LCM 1 or is directly set in the LCM 1 when it is used.
<figref idref="f0002">FIG. 3</figref> shows an example of the arrangement of the PD 12, and the MC 13 is set in a medium interface (I/F) 12f. When the LCM 1 reads/writes data to/from the MC 13 via the PD 12, it accesses the secure area of the MC 13 via a secure area access unit in the PD 12. The medium I/F 12f comprises a secure area access unit for accessing the secure area of the MC 13. The secure area in the PD 12 may be on a flash memory 12d. A bilateral authentication program between the MC 13 and LCM 1, a program that describes an authentication procedure required for accessing the secure area, and a program for discriminating the type of MC 13 are written in a ROM12c. According to these programs, various processes such as authentication, type discrimination, and the like with the MC 13 are executed under the control of a CPU 12a.
The ROM 12c may also store identification information (device ID) of the PD 12. For example, the secure area is on the flash memory 12d pre-stores a secure device ID (SPDID).
<figref idref="f0004">FIG. 5</figref> shows the arrangement of the medium I/F 6 of the LCM 1. The medium I/F 6 comprises an authentication unit 6c for performing bilateral authentication with the MC 13, a medium discrimination unit 6b for determining the type of MC 13, and a controller 6a for controlling all these units. The authentication unit 6c also serves as a secure area access unit which accesses the secure area of the MC 13.
<figref idref="f0017">FIG. 24</figref> shows the arrangement of the MC 13 of level 2 shown in <figref idref="f0003">FIG. 4C</figref> in more detail. As shown in <figref idref="f0017">FIG. 24</figref>, a secure area 102 is on a 1-chip memory element (e.g., a RAM), and has RAM and ROM areas. For example, the RAM and ROM areas are distinguished based on access control differences of a controller 101 comprising, e.g., a CPU or the like. Public areas are on a ROM area 103 and a RAM area 104.
Independent buses for accessing the secure area 102 and the public areas 103 and 104 are connected to the controller 101. Controller 101 accesses the secure area 102 or the public areas 103 and 104 by selecting one of these buses.
The controller 101 controls each section of the MC 13, and also executes an authentication process (AKE) which is executed every time the LCM 1 or the like accesses the secure area of the MC 13.
The ROM area in the secure area 102 pre-stores a bilateral authentication program between the MC 13 and LCM 1, a program that describes an authentication process (AKE) required for accessing the secure area, a secure medium ID (SMID), and the like.
The guest book stored in the secure area of the LCM 1 will be explained below.
All music content held in the SMS 2 have content IDs (TIDs) as identification information for identifying the individual content, and the predetermined number of content that can be copied (i.e. the remaining number of children and a check-out list) as their attribute information. This attribute information is called a guest book. The guest book is recorded on the guest book memory 8 on the secure area in the format shown in <figref idref="f0005">FIG. 7A</figref>.
Referring to <figref idref="f0005">FIG. 7A</figref>, the remaining number of children of content ID = "TID1" is "2" and its check-out list is L1.
The check-out list is a list of identification information of the MCs 13 which record copied content (children). For example, as can be seen from check-out list L1 in <figref idref="f0005">FIG. 7A</figref>, children of the content having a content ID = "TID1" are checked out to two MCs 13 respectively having identification information = "m1" and "m2".
The following items will be explained in turn below. <ol id="ol0001" compact="compact" ol-style=""><li>(1) Outline of bilateral authentication method</li><li>(2) Check-in/check-out/playback process of copied content using MC of level 2</li><li>(3) Check-in/check-out/playback process of copied content using MC of level 0</li></ol>
(1) Outline of bilateral authentication method
As described above, in order to safely implement the check-in/check-out process, bilateral authentication must be done among the LCM 1, PD 12, and MC 13 (to confirm, e.g., if they have an identical algorithm). In general, the bilateral authentication process must have secret information shared by the partners which are to authenticate each other. Therefore, for example, the MC 13, LCM 1, and PD 12 have such secret information. In terms of information security, this secret information is preferably generated dynamically to have a different value every time authentication is done. However, when a high-grade function of generating such secret information is added to the medium itself, the medium (i.e. the MC 13) becomes expensive. In order to popularize this kind of media to general public, the medium is preferably as inexpensive as possible. Therefore, secret information is preferably pre-stored in the MC 13 to reduce its cost.
However, when secret information which is common to all media or a given number of media (such information will be referred to as global secret information hereinafter) is pre-stored in respective media, if the secret information is read from a given medium by some method, other media that store identical secret information may be used by unauthorized persons. It is therefore very dangerous to store global secret information in media (see <figref idref="f0006">FIG. 8A</figref>).
Even when secret information stored in a given medium is read by an unauthorized user, if it is only the medium from which the secret information has been read that can be used by unauthorized persons, no serious problem is posed. For this reason, the secret information required to be unique to each medium.
In this embodiment, secret information for bilateral authentication, which differs in units of media, is stored in each media, and the LCM 1 or PD 12 and MC 13 perform bilateral authentication using the stored information, thus providing a safe bilateral authentication method that uses a low-cost medium and can assure higher security. More specifically, in this embodiment, we describes the bilateral authentication method that secret information (in this case, secure medium ID (SMID): which is obtained by encrypting a medium ID using key information KM acquired by some method) which differs in units of media and is required for bilateral authentication (AKE) is pre-stored in (the secure area of) each medium (medium of level 2) and, as shown in <figref idref="f0006">FIG. 8B</figref>, and the identification information (MID) of that medium is transferred to the LCM 1 and PD 12, and the LCM 1 or PD 12 generates information (which is the same as SMID of the medium) for bilateral authentication) using MID and information (KM) acquired by some method in accordance with a predetermined algorithm, and executes a bilateral authentication process (AKE: authentication and key exchange).
In this manner, by storing unique secret information (SMID) in each MC 13, the LCM 1 or PD 12 generates secret information (SMID) on the basis of information (MID) unique to each medium, which is transferred from the medium, thus implementing safe bilateral authentication without imposing any heavy load on the medium.
Note that the aforementioned bilateral authentication process will be referred to as AKE hereinafter.
When the MC 13 is set in the medium I/F 6 of the LCM 1 or the PD 12, bilateral authentication may be done first between the medium I/F 6 and MC 13 or between the PD 12 and MC 13 (step S1 in <figref idref="f0007">FIG. 9</figref>). If it is determined that both of them are authentic (e.g., they have hardware arrangements complying with the same standards) (step S2), the medium I/F 6 or PD 12 determines the type of MC 13 on the basis of identification information MID read from the MC 13 (step S3). The medium I/F 6 or PD 12 executes a check-in/check-out/playback process according to the determined type (steps S4 to S6).
Note that bilateral authentication in step S1 in <figref idref="f0007">FIG. 9</figref> need not always be that according to the gist of the present invention shown in <figref idref="f0006">FIG. 8B</figref>.
In the above description, three different types of MCs 13 (i.e. MCs 13 of level 0 to level 2), are available, but the check-in/check-out playback process operations of the copied content in <figref idref="f0007">FIG. 9</figref> and the subsequent figures will be explained for two types of MCs 13 (i.e. MCs 13 of level 0 and level 2).
Furthermore, although not described in the following description, upon accessing each others secure areas between the LCM 1 and MC 13, the LCM 1 and PD 12, and the PD 12 and MC 13, assume that they authenticate each other, open gates to each other's secure areas if it is confirmed that they are authentic, and close the gates that allow access to the secure areas after access to the secure areas is completed. For example, between the LCM 1 and MC 13, the SMS 2 makes bilateral authentication with the MC 13 so as to access the secure area 13c of the MC 13. If their authenticity is confirmed and the switch 13e (see <figref idref="f0004">FIG. 5</figref>) opens the gate to the secure area 13c, the SMS 2 writes key information in the secure area 13c, and the switch 13e closes the gate that allows access to the secure area 13c upon completion of the write.
(2) Check-in/check-out/playback process of copied content using MC of level 2
The check-in/check-out/playback process using the MC 13 of level 2 with the format shown in <figref idref="f0003">FIG. 4C</figref> will be explained below.
A case will be explained below with reference to <figref idref="f0007">FIG. 10</figref> wherein a check-out instruction is issued to the SMS 2 via a user interface (I/F) 15 or via the PD 12 (i.e., when the MC 13 is set in the PD 12 connected to the LCM 1). This case does not belong to the invention.
The SMS 2 checks the remaining number n of children of content (the content having a content ID = "TID1") corresponding to a check-out request of the guest book. If n > 0, the SMS 2 reads out the device ID (LCMID) of the corresponding LCM 1 from the device ID memory 4, and transfers it to the MC 13 (step S101).
The MC 13 checks if the transferred device ID is registered in the RVC list (step S102). If the transferred device ID is not registered, the MC 13 reads out master key KM by accessing the secure area 13c, and transfers it to the LCM 1 (step S103). Furthermore, the MC 13 reads out its identification information (MID) from the identification information memory 13b and transfers it to the LCM 1 (step S104).
The LCM 1 encrypts the medium ID (MID) transferred from the MC 13 using master key KM to generate information (KM[MID]) required for a bilateral authentication process (AKE) (step S105).
The LCM 1 executes the bilateral authentication process (AKE) using the generated information KM[MID], while the MC 13 executes the bilateral authentication process (AKE) using a secure medium ID (SMID) (step S106). In this bilateral authentication process (AKE), the LCM 1 and MC 13 share identical functions g(x, y) and H(x, y), and if the information KM[MID] generated by the LCM 1 is the same as the secure medium ID (SMID) of the MC 13, they can confirm their authenticity by the bilateral authentication process (AKE).
The processing operation of the bilateral authentication process (AKE) in step S106 will be explained below with reference to <figref idref="f0018">FIG. 22</figref>.
The LCM 1 generates random number R1 (step S301), and transfers it to the MC 13. At the same time, the LCM 1 substitutes random number R1 in one variable of function g(x, y) having two variables. Also, the LCM 1 substitutes the information KM[MID] generated in step S105 in <figref idref="f0007">FIG. 10</figref> in the other variable of function g(x, y), to obtain the value of function g (step S302).
On the other hand, the MC 13 substitutes random number R1 transferred from the LCM 1 in one variable of function g(x, y), substitutes its own secure medium ID (SMID) in the other variable, and transfers the obtained value of function g to the LCM 1 (step S303).
The LCM 1 compares the value of function g transferred from the MC 13, and the value of function g that computed by itself, and executes a subsequent process if they match. If the two values do not match, the AKE process on the LCM 1 side is canceled at that time (step S304).
The MC 13 then generates random number R2 (step S305), and transfers it to the LCM 1. At the same time, the MC 13 substitutes random number R2 in one variable of function g(x, y) having two variables. Also, the MC 13 substitutes its secure medium ID (SMID) in the other variable of function g(x, y) to obtain the value of function g (step S306).
On the other hand, the LCM 1 substitutes random number R2 transferred from the MC 13 in one variable of function g(x, y), and substitutes the information KM[MID] generated in step S105 in <figref idref="f0007">FIG. 10</figref> in the other variable of function g(x, y), to obtain the value of function g. The LCM 1 then transfers the obtained value to the MC 13 (step S307).
The MC 13 compares the value of function g transferred from the LCM 1, and the value of function g that computed by itself, and executes a subsequent process if they match. If the two values do not match, the AKE process on the MC 13 side is canceled at that time (step S308).
If the values of function g match in step S308, the MC 13 substitutes random number R2 in one variable of function H(x, y) having two variables, and its secure medium ID (SMID) in the other variable, to generate key information KT (step S309).
Also, if the values of function g match in step S304, the LCM 1 substitutes random number R2 transferred from the MC 13 in one variable of function H(x, y), and substitutes the information KM[MID] generated in step S105 in <figref idref="f0007">FIG. 10</figref> in the other variable, to generate key information KT (step S310).
Note that two pieces of key information KT, which are generated by the LCM 1 and MC 13 using the identical function H(x, y) if it is determined in steps S304 and S308 that the values of function g match, are the same. The LCM 1 and MC 13 then exchange content decryption key Kc using this key information KT.
The bilateral authentication process (AKE) preferably generates different key information KT upon each authentication in terms of security. In this case, since random number R2 newly generated for each authentication is substituted in one of two variables in function H used to generate key information KT, different key information KT can be generated for each authentication.
Referring back to <figref idref="f0007">FIG. 10</figref>, if the LCM 1 and MC 13 confirm in step S106 that they are authentic, the MC 13 stores the generated key information KT (in this case, KT1) in the secure area (step S107). The LCM 1 encrypts a decryption key (content decryption key) Kc used to decrypt the encrypted content (KT1[Kc]) using the key information KT1 generated in step S106, and transfers it to the MC 13 (steps S108 and S109). Also, the LCM 1 encrypts content information C using Kc (then generates Kc[C]), and transfers the encrypted content (Kc[C]) to the MC 13 (steps SI10 and Sill).
Finally, the SMS 2 subtracts "1" from the remaining number n of children of the check-out requested content having content ID = "TID1" in the guest book, and adds identification information of MC3 "mO" in check-out list LI, as shown in <figref idref="f0005">FIG. 7B</figref>.
The MC 13 stores transferred encrypted content decryption key KT1[Kc] and encrypted content Kc[C] in the public area 13a.
<figref idref="f0004">FIG. 6</figref> shows the storage contents of the MC 13 upon completion of the aforementioned processes. This figure does not belong to the invention.
A case will be explained below with reference to <figref idref="f0008">FIG. 11</figref> wherein a playback instruction is issued to the SMS 2 via the user interface (I/F) 15 of the LCM 1 or to the PD 12. This case does not belong to the invention.
The PD 12 or LCM 1 transfers its own device ID to the MC 13 (step S121).
If the LCM 1 has the same content playback function (demodulator 12g, decoder 12h, D/A converter 12i, and the like) as that the PD 12 shown in <figref idref="f0002">FIG. 3</figref>, the content of the MC 13 can be similarly played back by the PD 12 and LCM 1. Then a playback process by the PD 12 will be exemplified below.
The MC 13 checks if the transferred device ID is registered in the RVC list (step S122). If the device ID is not registered, the MC 13 reads out master key KM by accessing the secure area 13c, and transfers it to the PD 12 (step S123) . Furthermore, the MC 13 reads out its identification information (MID) from the identification information memory 13b and transfers it to the PD 12 (step S124).
The PD 12 encrypts the medium ID (MID) transferred from the MC 13 using master key KM to generate information (KM[MID]) required for a bilateral authentication process (AKE) (step S125).
The PD 12 executes the bilateral authentication process (AKE) using the generated information KM[MID], while the MC 13 executes the bilateral authentication process (AKE) using a secure medium ID (SMID) (step S126). Since the bilateral authentication process in step S126 is the same as that shown in <figref idref="f0018">FIG. 22</figref>, a description thereof will be omitted.
If the PD 12 and MC 13 confirm that they are authentic, the MC 13 encrypts key information KT1 stored in the secure area 13c using the generated key information KT (in this case, KT2) (KT2[KT1]) and transfers it to the PD 12 (steps S127 and S128). On the other hand, the PD 12 can decrypt KT2[KT1] transferred from the MC 13 using key information KT2 generated in step S126 (step S128).
The MC 13 reads out encrypted content decryption key KT1[Kc] and encrypted content Kc[C] from the public area 13a and transfers them to the PD 12 (steps S129 and S131).
If key information KT1 has been successfully decrypted, since the PD 12 can obtain content decryption key Kc by decrypting content decryption key KT1[Kc] which was encrypted using KT1 (step S130), it decrypts encrypted content Kc[C] using that content decryption key Kc to obtain content C (step S132). In the PD 12, the decoder 12h decodes content C, and the D/A converter 12i converts the decoded content from a digital signal into an analog signal, thus playing back the copied content (e.g., music) recorded on the MC 13 (see <figref idref="f0002">FIG. 3</figref>).
A case will be explained below with reference to <figref idref="f0009">FIG. 12</figref> wherein a check-in instruction is issued to the SMS 2 via the user interface (I/F) 15 of the LCM 1 or via the PD 12 (i.e., when the MC 13 is set in the PD 12 connected to the LCM 1). This case does not belong to the invention.
The check-in process shown in <figref idref="f0009">FIG. 12</figref> executes a bilateral authentication processes (AKE) twice, upon erasing (erasing by rewriting a random number on) key information (or preferably key information and encrypted content) recorded on the MC 13, and upon confirming if the information has been erased.
The SMS 2 reads out the device ID (LCMID) of that LCM 1 from the device ID memory 4, and transfers it to the MC 13 (step S141).
The MC 13 checks if the transferred device ID is registered in the RVC list (step S142). If the transferred device ID is not registered, the MC 13 reads out master key KM by accessing the secure area 13c, and transfers it to the LCM 1 (step S143). Furthermore, the MC 13 reads out its identification information (MID) from the identification information memory 13b and transfers it to the LCM 1 (step S144).
The LCM 1 encrypts the medium ID (MID) transferred from the MC 13 using master key KM to generate information (KM[MID]) required for a bilateral authentication process (AKE) (step S145).
The LCM 1 executes a first bilateral authentication process (AKE#1) using the generated information KM[MID], while the MC 13 executes a first bilateral authentication process (AKE#1) using a secure medium ID (SMID) (step S146).
Since the bilateral authentication process (AKE#1) in step S146 is the same as that shown in <figref idref="f0018">FIG. 22</figref>, a detailed description thereof will be omitted.
If the LCM 1 and MC 13 confirm in step S146 that they are authentic, the LCM 1 generates random number rl to be rewritten on key information KT1 stored in the secure area (RAM area) 13c of the MC 13 using a conventional random number generator, encrypts the generated random number and instruction for rewriting to the MC 13 using key information KT (KT3 in this case) generated in step S146 (KT3[instruction+rl]), and transfers the encrypted information to the MC 13 (step S501). Note that the instruction may contain the address that key information KT1 is written.
The MC 13 decrypts KT3[instruction + r1] transferred from the LCM 1 using key information KT3 generated in step S146 to obtain random number r1 (step S502). The MC 13 erases key information KT1 stored in the secure area (RAM area) 13c of the MC 13 by rewriting the key information by using this random number rl (step S503). Note that, not only key information KT1 but also encrypted content decryption key Kc (KT1[Kc]) and encrypted content Kc[C] may be erased by rewriting them by using random number rl formation KT1.
Then, a process for confirming if key information KT1 (or preferably key information KT1 and encrypted content information, and the like) has been surely erased by random number r1 is executed. More specifically, the LCM 1 executes a second bilateral authentication process (AKE#2) using information KM[MID] generated in step S145, while the MC 13 executes a second bilateral authentication process (AKE#2) using a secure medium ID (SMID) (step S504).
Since the second bilateral authentication process (AKE#2) in step S504 is the same as that shown in <figref idref="f0018">FIG. 22</figref>, a detailed description thereof will be omitted.
If the LCM 1 and MC 13 confirm in step S504 that they are authentic, the MC 13 reads data (random number rl if rewrite has been normally done) from the address that key information KT1 is stored, and encrypts the read data using key information KT (KT4 in this case) generated in step S504 (KT4[r1]), and transfers it to the LCM 1 (step S505).
The LCM 1 decrypts KT4[r1] transferred from the MC 13 using key information KT4 generated in step S504 (step S506), and compares the decrypted data with random number rl generated in step S501. If the two data match, the LCM 1 determines that key information KT1 (or content) has been erased by random number rl, and ends the process (step S507). If the two data do not match, the LCM 1 preferably informs this abnormality or the like.
Finally, as shown in <figref idref="f0005">FIG. 7C</figref>, "<figref idref="f0001">1</figref>" is added to the remaining number n of the check-in requested content having content ID = "TID1" in the guest book, and identification information of MC3 "mO" is deleted from check-out list LI.
Another check-in process, which is different from that shown in <figref idref="f0009">FIG. 12</figref>, will be explained below with reference to <figref idref="f0010">FIG. 13</figref>. This process does not belong to the invention. Note that the same reference numerals denote the same portions as those in <figref idref="f0009">FIG. 12</figref>, and only different portions will be explained below. That is, the check-in process shown in <figref idref="f0010">FIG. 13</figref> is characterized in that a bilateral authentication process (AKE) is done twice, i.e., upon transferring instruction (e.g., instruction that indicates the start of check-in) or command for erasing key information recorded on the MC 13, and as a trigger for executing the process for erasing key information etc. The process until AKE#1 in step S146 is the same as that in <figref idref="f0009">FIG. 12</figref>.
If the LCM 1 and MC 13 confirm in step S146 that they are authentic, the LCM 1 encrypts instruction indicating the start of check-in using key information KT (KT3 in this case) generated in step S146, then transfers encrypted instruction (KT3[check-in instruction]) to the MC 13 (step S551). Note that the check-in instruction may contain the address that key information KT1 is written.
The MC 13 decrypts KT3[check-in instruction] transferred from the LCM 1 using key information KT3 generated in step S146 to obtain the check-in instruction (step S552).
Then, a second bilateral authentication process (AKE#2) is executed as a trigger for generating an actual erase command (step S553). In AKE#2 in this case, after it is checked as in step S308 in <figref idref="f0018">FIG. 22</figref> if the values of function g match, only the checking result is output, as shown in <figref idref="f0019">FIG. 23</figref>.
If the values of function g match, and the check-in instruction has been obtained previously, the MC 13 erases key information KT1 (or preferably key information KT1 and encrypted content) (steps S554 and S555). For example, key information KT1 or the like may be erased by rewriting the file management area of the MC 13.
Finally, as shown in <figref idref="f0005">FIG. 7C</figref>, "<figref idref="f0001">1</figref>" is added to the remaining number n of the check-in requested content having content ID = "TID1" in the guest book, and identification information of MC3 "m0" is deleted from check-out list L1.
Another check-out process, which is different from that shown in <figref idref="f0007">FIG. 10</figref>, will be described below with reference to <figref idref="f0011">FIG. 14</figref>. Note that the same reference numerals denote the same portions as those in <figref idref="f0007">FIG. 10</figref>, and only different portions will be explained below. That is, <figref idref="f0011">FIG. 14</figref> is characterized by a process for content decryption key Kc to be transferred to the MC 13.
Referring to <figref idref="f0011">FIG. 14</figref>, the LCM 1 encrypts content decryption key Kc using KM[MID] (to be expressed by w hereinafter) generated in step S105 (step S162). The LCM 1 further encrypts content decryption key Kc encrypted by w (w[Kc]) using key information KT1 generated in the bilateral authentication process (AKE) in step S106 (KT1[w[Kc]]), and then transfers it to the MC 13 (step S163).
The MC 13 decrypts the transferred KT1[w[Kc]] using key information KT1 generated in the bilateral authentication process (AKE) in step S106 to obtain w[Kc], and stores it in the secure area 13c (step S164).
Content information C is encrypted using Kc (step S165), and is then transferred to the MC 13 (step S166) as in <figref idref="f0007">FIG. 10</figref>.
The playback process corresponding to the check-out process shown in <figref idref="f0011">FIG. 14</figref> will be explained below with reference to <figref idref="f0012">FIG. 15</figref>. Note that the same reference numerals denote the same portions as those in <figref idref="f0008">FIG. 11</figref>, and only different portions will be explained below. More specifically, in <figref idref="f0012">FIG. 15</figref> the MC 13 encrypts encrypted content decryption key w[Kc] stored in the secure area 13c using key information KT2 generated in the bilateral authentication process (AKE) in step S126 (KT2[w[Kc]]), and then transfers it to the LCM 1 or PD 12 (step S172). The LCM 1 or PD 12 decrypts KT2[w[Kc]] transferred from the MC 13 using key information KT2 generated in step S126 (step S173), and decrypts the obtained w[Kc] using w = KM[KID] generated in step S123 to obtain content decryption key Kc (step S174). The LCM 1 or PD 12 decrypts encrypted content Kc[C] using this content decryption key Kc to obtain content C (step S175).
In the LCM 1 or PD 12, the decoder 12h decodes content C, and the D/A converter 12i converts the decoded content from a digital signal into an analog signal, thus playing back the copied content (e.g., music) recorded on the MC 13.
The check-in process corresponding to the check-out process shown in <figref idref="f0011">FIG. 14</figref> is substantially the same as that described with reference to <figref idref="f0009">FIG. 12</figref> or <figref idref="f0010">13</figref>, except that content decryption key encrypted by w = KM[MID] (w[Kc])are deleted from the secure area 13c of the MC 13 in step S503 in <figref idref="f0009">FIG. 12</figref> or step S555 in <figref idref="f0010">FIG. 13</figref> in place of key information KT1.
(3) Check-in/check-out/playback process of copied content using MC of level 0
The check-in/check-out and playback processes using the MC 13 of level 0 with the format shown in <figref idref="f0003">FIG. 4A</figref> will be explained below. These processes do not belong to the invention.
In this case, the MC 13 is set in the PD 12, and executes a check-out process with the LCM 1 via the PD 12. The basic operation is the same as that of the MC 13 of level 2. However, in case of level 0, since the MC 13 has neither a secure area nor a medium ID, the PD 12 in place of the MC 13 of level 0 executes a process shown in <figref idref="f0007">FIG. 10</figref> with respect to the LCM 1. For this purpose, the secure area of the PD 12 pre-stores master key KM, secure device key SPDID, and a revocation list (RVC list). Note that master key KM has the same function as that of master key KM stored in the MC 13, but data itself need not always be the same.
In step S3 in <figref idref="f0007">FIG. 9</figref>, the type of MC 13 is determined to be level 0.
A case will be explained below with reference to <figref idref="f0013">FIG. 16</figref> wherein a check-out instruction is issued to the SMS 2 via a user interface (I/F) 15 or via the PD 12. This case does not belong to the invention.
The SMS 2 checks the remaining number n of children of check-out requested content (e.g., having a content ID = "TID1") in the guest book. If n > 0, the SMS 2 reads out the device ID (LCMID) of the corresponding LCM 1 from the device ID memory 4, and transfers it to the PD 12 (step S201).
The PD 12 checks if the transferred device ID is registered in the RVC list (step S202). If the transferred device ID is not registered, the PD 12 reads out master key KM by accessing its secure area, and transfers it to the LCM 1 (step S203). Furthermore, the PD 12 reads out its identification information, i.e., the device ID (PDID) from, e.g., the ROM 12c, and transfers it to the LCM 1 (step S204).
The LCM 1 encrypts the device ID (PDID) transferred from the PD 12 using master key KM to generate information (KM[PDID]) required for a bilateral authentication process (AKE) (step S205).
The LCM 1 executes the bilateral authentication process (AKE) using the generated information KM[PDID], while the PD 12 executes the bilateral authentication process (AKE) using a secure device ID (SPDID) (step S206). Since the bilateral authentication process in step S206 is the same as that shown in <figref idref="f0018">FIG. 22</figref>, a description thereof will be omitted.
If the LCM 1 and MC 13 confirm that they are authentic, the PD 12 stores the generated key information KT (in this case, KT1) in the secure area (step S207). The LCM 1 encrypts a decryption key (content decryption key) Kc used to decrypt the encrypted content using the key information KT1 generated in step S206, and transfers encrypted content decryption key Kc (KT1[Kc]) to the MC 13 via the PD 12 (steps S208 and S209). Also, the LCM 1 encrypts content information C using Kc (Rc[C]), and transfers the encrypted content to the MC 13 via the PD 12 (steps S210 and S211).
Finally, the SMS 2 subtracts "1" from the remaining number n of children of the check-out requested content having content ID = "TID1" in the guest book, and adds identification information of PD12 (PDID) in check-out list LI, as shown in <figref idref="f0005">FIG. 7B</figref>.
The MC 13 stores transferred encrypted content decryption key KT1[Kc] and encrypted content Kc[C] in the public area 13a.
The process between the PD 12 and MC 13 when the PD 12 receives a playback instruction will be explained below with reference to <figref idref="f0012">FIG. 17</figref>. This process does not belong to the invention.
The MC 13 transfers encrypted content decryption key KT1[Kc] recorded on its public area to the PD 12 (step S221). If the PD 12 is the one which was used to check out to the MC 13, it must store key information KT1 for decrypting the encrypted content decryption key in its secure area (see step S207 in <figref idref="f0013">FIG. 16</figref>). Therefore, such authentic PD 12 can obtain content decryption key Kc by decrypting KT1[Kc] transferred from the MC 13 using key information KT1 read out from its secure area (step S222). Furthermore, the PD can obtain content C by decrypting encrypted content Kc[C] transferred from the MC 13 using that content decryption key Kc (steps S223 and S224). In the PD 12, the decoder 12h decodes content C, and the D/A converter 12i converts the decoded content from a digital signal into an analog signal, thus playing back the copied content (e.g., music) recorded on the MC 13.
A case will be explained below with reference to <figref idref="f0014">FIG. 18</figref> wherein a check-in instruction is issued to the SMS 2 via the PD 12 (i.e., using the MC 13 set in the PD 12 connected to the LCM 1). This case does not belong to the invention. In this case as well, the PD 12 in place of the MC 13 of level 0 executes a process shown in <figref idref="f0009">FIG. 12</figref> with respect to the LCM 1 in the check-out process.
The SMS 2 reads out the device ID (LCMID) of that LCM 1 from the device ID memory 4, and transfers it to the PD 12 (step S231).
The PD 12 checks if the transferred device ID is registered in the RVC list (step S232). If the transferred device ID is not registered, the PD 12 reads out master key KM by accessing its secure area, and transfers it to the LCM 1 (step S233). Furthermore, the PD 12 reads out its identification information (PDID) and transfers it to the LCM 1 (step S234).
The LCM 1 encrypts the device ID (PDID) transferred from the PD 12 using master key KM to generate information (KM[PDID]) required for a bilateral authentication process (AKE) (step S235).
The LCM 1 executes a first bilateral authentication process (AKE#1) using the generated information KM[PDID], while the PD 12 executes a first bilateral authentication process (AKE#1) using a secure device ID (SPDID) (step S236).
Since the first bilateral authentication process (AKE#1) in step S236 upon check-in is substantially the same as that shown in <figref idref="f0018">FIG. 22</figref> except that KM[PDID] replaces KM[MID], and the secure device ID (SPDID) replaces the secure medium ID (SMID), a description thereof will be omitted.
If the LCM 1 and PD 12 confirm in step S236 that they are authentic, the LCM 1 generates random number rl to be used for rewriting key information KT1 stored in the secure area (RAM area) of the PD 12, using a conventional random number generator, encrypts the generated random number rl and instruction to the MC 13 using key information KT (KT3 in this case) generated in step S236, and transfers the encrypted information (KT3[instruction+rl]) to the PD 12 (step S601). Note that the instruction may contain the address that key information KT1 is written.
The PD 12 decrypts KT3[instruction + rl] transferred from the LCM 1 using key information KT3 generated in step S236 to obtain random number rl (step S602). Key information KT1 stored in the secure area (RAM area) of the PD 12 is rewrote(overwrote) by this random number rl and erased (step S603).
Then, a process for confirming if key information KT1 has been surely erased by random number rl is executed. More specifically, the LCM 1 executes a second bilateral authentication process (AKE#2) using information KM[PDID] generated in step S235, while the PD 12 executes a second bilateral authentication process (AKE#2) using a secure medium ID (SPDID) (step S604).
Since the second bilateral authentication process (AKE#2) in step S604 is the same as AKE#1 in step S236, a detailed description thereof will be omitted.
If the LCM 1 and MC 13 confirm in step S604 that they are authentic, the PD12 reads data (random number rl if rewrite has been normally done) from the storage address of key information KT1, encrypts the read data using key information KT (KT4 in this case) generated in step S604, and transfers encrypted data (KT4[r1]) to the LCM 1 (step S605).
The LCM 1 decrypts KT4[r1] transferred from the PD 12 using key information KT4 generated in step S604 (step S606), compares data obtained by decryption with random number rl generated in step S601. If the two data match, the LCM 1 determines that key information KT1 has been erased by random number rl, and ends the process (step S607). If the two data do not match, the LCM 1 preferably informs this abnormality or the like.
Finally, as shown in <figref idref="f0005">FIG. 7C</figref>, "<figref idref="f0001">1</figref>" is added to the remaining number n of the check-in requested content having content ID = "TID1" in the guest book, and identification information of that PD 12 is deleted from check-out list LI.
Another check-in process, which is different from that shown in <figref idref="f0014">FIG. 18</figref>, will be explained below with reference to <figref idref="f0015">FIG. 19</figref>. This case does not belong to the invention. Note that the same reference numerals denote the same portions as those in <figref idref="f0014">FIG. 18</figref>, and only different portions will be explained below. That is, the processing operation upon check-in shown in <figref idref="f0015">FIG. 19</figref> is characterized in that a bilateral authentication process (AKE) is done twice, i.e., upon transferring instruction (e.g., instruction that indicates the start of check-in (check-in instruction)) or command for erasing key information recorded on the PD 12, and as a trigger for executing the process for erasing key information etc. The process until AKE#1 in step S236 is the same as that in <figref idref="f0014">FIG. 18</figref>.
If the LCM 1 and MC 13 confirm in step S236 that they are authentic, the LCM 1 encrypts the check-in instruction using key information KT (KT3 in this case) generated in step S236 (KT3[check-in instruction]), and transfers it to the MC 13 (step S651). Note that the check-in instruction may contain the address that key information KT1 is written.
The PD 12 decrypts KT3[check-in instruction] transferred from the LCM 1 using key information KT3 generated in step S236 to obtain the check-in instruction (step S652).
Then, a second bilateral authentication process (AKE#2) is executed as a trigger for generating an actual erase command (step S653). In AKE#2 in this case, after it is checked as in step S308 in <figref idref="f0018">FIG. 22</figref> if the values of function g match, only the checking result is output, as shown in <figref idref="f0019">FIG. 23</figref>.
If the values of function g match, and the check-in instruction has been obtained previously, the PD 12 erases key information KT1 (or preferably key information KT1 and encrypted content information) (steps S654 and S655). For example, key information KT1 or the like may be erased by rewriting the file management area of the PD 12.
Finally, as shown inFIG. <i>1C</i>, "1" is added to the remaining number n of the check-in requested content having content ID = "TID1" in the guest book, and identification information of that PD 12 is deleted from check-out list LI.
The check-out process, which is different from that shown in <figref idref="f0013">FIG. 16</figref>, will be described below with reference to <figref idref="f0016">FIG. 20</figref>. This process does not belong to the invention. Note that the same reference numerals denote the same portions as those in <figref idref="f0013">FIG. 16</figref>, and only different portions will be explained below. That is, <figref idref="f0016">FIG. 20</figref> is characterized by a process for content decryption key Kc to be transferred to the PD 12, as in <figref idref="f0011">FIG. 14</figref>.
Referring to <figref idref="f0016">FIG. 20</figref>, the LCM 1 encrypts content decryption key Kc using KM[PDID] (to be expressed by w hereinafter) generated in step S205 (step S252). The LCM 1 further encrypts content decryption key Kc encrypted by w (w[Kc]) using key information KT1 generated in the bilateral authentication process (AKE) in step S251, and then transfers encrypted content decryption key (KT1[w[Kc]]) to the PD 12 (step S253).
The PD 12 decrypts the transferred KT1[w[Kc]] using key information KT1 generated in the bilateral authentication process (AKE) in step S251 to obtain w[Kc], and stores it in the secure area (step S254).
Content information C is encrypted using Kc (step S255), and is then transferred to the MC 13 via the PD 12 (step S256), as in <figref idref="f0013">FIG. 16</figref>.
The playback process corresponding to the check-out process shown in <figref idref="f0016">FIG. 20</figref> will be explained below with reference to <figref idref="f0017">FIG. 21</figref>. This case does not belong to the invention. Note that the same reference numerals denote the same portions as those in <figref idref="f0016">FIG. 20</figref>, and only different portions will be explained below. More specifically, in <figref idref="f0017">FIG. 21</figref> the PD 12 can obtain content decryption key Kc by decrypting encrypted content decryption key w[Kc] stored in its secure area using its secure device ID (SPDID = w) (step S261). The PD 12 can obtain content C by decrypting encrypted content Kc[C] transferred from the MC 13 using that content decryption key Kc (step S262). In the PD 12, decoder 12h decodes content C, and the D/A converter 12i converts the decoded content from a digital signal into an analog signal, thus playing back the copied content (e.g., music) recorded on the MC 13.
The check-in process corresponding to the check-out process shown in <figref idref="f0016">FIG. 20</figref> is substantially the same as that of <figref idref="f0014">FIG. 18</figref> or <figref idref="f0015">19</figref>, except that content decryption key encrypted by w = KM[PDID] (w[Kc]) in place of key information KT1 is deleted from the secure area of the PD 12 in step S603 in <figref idref="f0014">FIG. 18</figref> or step S655 in <figref idref="f0015">FIG. 19</figref>.
19 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19
13 members in 6 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 19620799 | Japan | A | |
| 19620799 | Japan | A | |
| 19620799 | Japan | – | |
| 19620799 | – | – | – |
| JP19990196207 | – | – | – |
Members13
| Document | Office | Kind | |
|---|---|---|---|
| CN1280337A | China | A | |
| EP1069491A2 | European Patent Office (EPO) | A2 | |
| JP2001022647A | Japan | A | |
| KR20010015208A | Republic of Korea | A | |
| TW498241B | Taiwan Province of China | B | |
| KR100396352B1 | Republic of Korea | B1 | |
| CN1183454C | China | C | |
| EP1069491A3 | European Patent Office (EPO) | A3 | |
| US2006188093A1 | United States of America | A1 | |
| US7181008B1 | United States of America | B1 | |
| JP4127587B2 | Japan | B2 | |
| US7505584B2 | United States of America | B2 | |
| EP1069491B1This record | European Patent Office (EPO) | B1 |
38 legal events, as 4 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent expired after termination of 20 yearsExpiredPE20 | PE20 | GB | |
| Expiry of rightR071 | R071 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| No opposition filed against granted patent, or epo opposition proceedings concluded without decisionGrantedR097 | R097 | DE | |
| Fee paymentPLFP | PLFP | FR | |
| Dpma publication of mentioned ep patent grantGrantedR096 | R096 | DE | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedFG4D | FG4D | GB | |
| Intention to grant announcedINTG | INTG | EP | |
| Intention to grant announced (deleted)INTC | INTC | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE PATENT HAS BEEN GRANTEDSTAA | STAA | EP | |
| Information related to intention to grant a patent recordedORIGINAL CODE: EPIDOSNIGR71GRAR | GRAR | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: GRANT OF PATENT IS INTENDEDSTAA | STAA | EP | |
| Information related to disapproval of communication of intention to grant by the applicant or resumption of examination proceedings by the epo deletedORIGINAL CODE: EPIDOSDIGR1GRAJ | GRAJ | EP | |
| Information related to payment of fee for publishing/printing deletedORIGINAL CODE: EPIDOSDIGR3GRAL | GRAL | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: EXAMINATION IS IN PROGRESSSTAA | STAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Intention to grant announcedINTG | INTG | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: GRANT OF PATENT IS INTENDEDSTAA | STAA | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Designation fees paidAKX | AKX | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAL;LT;LV;MK;RO;SIAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1069491
- Publication, DOCDB
- 1069491
- Publication, EPODOC
- EP1069491
- Application
- 1144211
- Application, DOCDB
- 00114421
- Application, EPODOC
- EP20000114421
Titles3
- German
- Verfahren zur Verwaltung von Inhalten, Gerät zur Verwaltung von Inhalten, und Aufzeichungsmedium
- English
- Contents management method, contents management apparatus, and recording medium
- French
- Méthode pour la gestion de contenus, appareil pour la gestion de contenus, et support d'enregistrement
Classification
- CPC, 5
- G11B20/0021
- G06F12/14
- G11B20/00086
- G11B20/00666
- G11B20/00789
- IPC, 10
- G06F1 00
- G11B20 00
- G09C1 00
- G06F12 14
- G06F21 00
- G06F21 10
- G06F21 44
- G06F21 60
- G11B20 10
- H04L9 32
Designated states3
- Contracting states, 3
- Germany
- France
- United Kingdom
