Methods and devices for storing and reading digital data on a storage medium
Abstract
Method for secure storage of digital data by a recording device on a data medium (10-12), equipped with a calculation means (1). Accordingly during a first write process to the support an identifier of the support reader (RDi) is recorded in a non-volatile manner in the support or in its calculation means and the data is then stored permanently in an encrypted manner using an encryption key that is independent of the reader and the contents. An Independent claim is made for a method for reading data from the support in the reader identifies itself using its identifier (RDi), the calculation device checks if it is one of the authorized readers, pre-recorded in the data medium or the calculation device and if it is transmits the encrypted data and the encryption key, allowing decryption of the data.

Term
Term ended
Projected expiry passed 11 September 2022, 4 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
19 claims: 2 independent, 17 dependent
- 1Method for the secure storage, by a recorder (3), of digital data (DATA) on a physical medium (10, 11, 12) equipped with calculation means (1), characterized in that it comprises, during a first use of the write medium, the following steps:storing in the medium or its calculation means, and in a non-volatile manner, at least one identifier (RDi) of a reader of the medium;and storing the data in an encrypted manner (CDATA) by means of an encryption key (C) independent of the reader and permanently contained in said medium or its calculation means.
- 10A method of reading, by a reader (RDi), encrypted digital data (CDATA) on a physical medium (10, 11, 12) equipped with calculation means (1), characterized in that it includes the following steps:communicating to the medium an identifier (RDi) of the reader;verify, on the physical medium side, that the reader belongs to a list (RDLIST) of authorized readers, pre-recorded in the medium or its means of calculation;and if so, send the reader the encrypted data and an encrypted encryption key (Ccrypt), to enable him to decrypt the data.
Independent claims2
93 paragraphs, as filed
The present invention relates to storing digital data, more precisely multimedia data, on a physical medium. The invention relates more particularly to the protection of the data contained on the medium against unauthorized reproductions by the creator of the medium concerned. By creator of the medium is meant the one who first recorded the data on the physical medium concerned. This is not necessarily the author of the content of the multimedia data, nor the manufacturer of the media.
An exemplary application of the present invention relates to multimedia media for receiving music files or images in digital form.
It has already been proposed to encrypt or encrypt data recorded on a multimedia medium (for example, a CD-ROM, a digital diskette, etc.) so that these data can be read only by a specific reader having the encryption key. However, except individualizing the manufacture of media and data recording at the manufacturer to individualize the key according to the user, the same medium can be read by any reader with this key. However, the objective is precisely to prohibit the reading of the physical medium by an unauthorized reader.
An example of a system for protecting unlawful copies of any digital medium is described in the "Content protection for recordable media specification" note, published by 4C-entity, Rev 0.93 on June 28, 2000.
The known systems have the additional disadvantage of not allowing a user of a recording apparatus to protect his own data, for example, his digital photographs when recording on a storage disk. Only the manufacturer is able to protect the data.
The present invention aims to improve the digital data protection systems, contained on physical media, against copies not authorized by the author or the like.
The invention also aims to allow any creator of recorded media (the user of a reader-recorder or storage means) to protect the data at the recording of the medium.
The invention also aims at preserving the possibility of protecting the data during manufacture while making it possible to select authorized readers.
The invention also aims that the creator of the recorded medium itself selects, during a recording, the reader or readers authorized to read the data contained in the storage means.
The invention also aims at making it possible to modify the contents of the storage medium as well as the readers authorized to read the data, after a first recording, provided that this is done by the creator of the recorded medium.
To achieve these objects and others, the present invention provides a method of securely storing, by a recorder, digital data on a physical medium equipped with a calculating means, comprising, during a first use of the write medium , the following steps:<ul id="ul0001" list-style="none" compact="compact"><li>storing in the medium or its calculation means, and in a non-volatile manner, at least one identifier of a reader of the medium; and</li><li>storing the data in an encrypted manner by means of an encryption key permanently contained in said medium or its calculation means.</li></ul>
According to an embodiment of the present invention, the encryption key is transmitted to the recorder in an encrypted manner by means of a symmetric encryption key sharing algorithm without transmission thereof.
According to an embodiment of the present invention, the algorithm takes into account an identifier of the recorder.
According to an embodiment of the present invention, the encryption key is transmitted to the recorder in an encrypted manner by means of an asymmetric encryption key transfer algorithm.
According to an embodiment of the present invention, during the first use of the write medium, at least one user authentication code is memorized in a non-volatile manner on the medium or its calculation means. .
According to an embodiment of the present invention, said calculating means is an integrated circuit.
According to an embodiment of the present invention, the encryption key is contained in the calculation means, preferably at least partially in a physical parameter network of the integrated circuit.
According to an embodiment of the present invention, the medium is divided into sectors, an identification code and / or an authentication code being assigned to each sector or groups of sectors.
According to an embodiment of the present invention, the storage method comprises the following steps:<ul id="ul0002" list-style="none" compact="compact"><li>transmitting, from the recorder to the physical medium, a list of authorized reader identifiers;</li><li>store this list in the physical medium;</li><li>transmitting, from the physical medium to the recorder, an encryption key encrypted by an encryption key sharing or transfer algorithm;</li><li>decrypting said encryption key on the recorder side;</li><li>encrypt, on the recorder side, the data to be stored; and</li><li>transmit the encrypted data to the physical medium.</li></ul>
The invention also provides a method of reading, by a reader, digital data encrypted on a physical medium equipped with a calculation means, comprising the following steps:<ul id="ul0003" list-style="none" compact="compact"><li>communicate to the medium an identifier of the reader;</li><li>verify, on the physical medium side, that the reader belongs to a list of authorized readers, pre-recorded in the medium or its means of calculation; and</li><li>if so, send the reader the encrypted data and an encrypted encryption key, to enable him to decrypt the data.</li></ul>
According to an embodiment of the present invention, the encryption of the encryption key is performed by said means for calculating the physical medium by means of a symmetric encryption key sharing algorithm without transmission thereof.
According to an embodiment of the present invention, the algorithm takes into account the identifier of the reader.
According to an embodiment of the present invention, the encryption of the encryption key is performed by said means for calculating the physical medium by means of an asymmetric encryption key transfer algorithm.
According to an embodiment of the present invention, in the event of a negative verification of the existence of the reader in the list of authorized readers, the following steps are carried out:<ul id="ul0004" list-style="none" compact="compact"><li>request an authentication code;</li><li>compare this code with a pre-registered code in the physical medium or its means of calculation; and</li><li>in case of identity of the codes: authorize a modification of the list of authorized readers on the physical medium or its means of calculation.</li></ul>
The invention also provides a physical support for digital data, comprising an integrated circuit.
The invention also provides a digital data logger on a physical medium.
The invention further provides a digital data reader on a physical medium.
These and other objects, features and advantages of the present invention will be set forth in detail in the following description of particular embodiments and embodiments made in a non-limiting manner with reference to the appended figures among which:<ul id="ul0005" list-style="none" compact="compact"><li>Figure 1 shows, very schematically, an embodiment of a secure storage system according to the present invention;</li><li>FIG. 2 illustrates, by a simplified flowchart, a preferred embodiment of the storage method according to the present invention;</li><li>FIG. 3 illustrates, through a simplified flowchart, a preferred embodiment of a data reading method according to the present invention; and</li><li>FIG. 4 illustrates, by a simplified flowchart, a preferred embodiment of a method for updating a list of authorized readers and / or the content of a physical medium according to the present invention.</li></ul>
The same elements and process steps have been designated by the same references in the different figures. For the sake of clarity, only the system elements and process steps that are necessary for understanding the invention have been illustrated in the figures and will be described later. In particular, the calculations implemented by the encryption and encryption algorithms themselves have not been detailed and involve only routine operations. In addition, the means for exchanging data between the reader-recorders and the data carriers have not been detailed and are not the subject of the invention.
FIG. 1 is a very schematic representation of a system for the secure storage and exploitation of data stored on physical supports according to the invention.
A physical medium that can be used in the context of the present invention consists of any physical medium for storing digital data, provided that it can include or be equipped with a calculation means. For example and as illustrated in Figure 1, it may be a CD-ROM 10, a disk 11, a digital cassette 12. According to the invention, these supports are provided with a calculation means, for example an integrated circuit chip 1. This chip is physically reported on the support itself. The chip 1 is intended to contain an authentication key and / or encryption and to perform certain authentication and encryption calculations as will be seen later. Alternatively, the key or keys are stored in an area of the physical medium. Various means may be used to associate an integrated circuit chip or the like with a physical digital data storage medium. An example of a physical data medium equipped with a chip is described in document FR-A-2 751 767. The physical medium and the chip can even be confused, for example, in the case of a smart card provided with digital memories of large capacity (several megabytes), for example, a flash memory.
Digital data to be stored (for example, audio or video files) is initially contained in a source element, for example, database type 2 (DB). It may also be remote data sources from a private digital network (intranet) or public (internet) or any other element containing digital multimedia data. It may even be a physical storage medium 10, 11 or 12 of the type used in the present invention.
To store digital data contained in the source element on a physical medium of the invention, a recorder 3 (REC) or reader-recorder capable of receiving, via a link 4, the data contained in the database 2 is used. and comprising read-write means (not detailed) of at least one of physical media 10, 11 or 12.
The recorder 3 of the invention reproduces, after having encrypted them as will be described later, the digital multimedia data on the adapted medium. According to the invention, the recorder 3 also triggers the storage, in the chip 1 or the like of the physical medium 10, 11 or 12, of a list of RDi reader identification codes authorized or authorized to read the data. Thus, the recorder 3 of the invention contains a list 31 (RD1, RD2, ... RDi, ... RDm) of digital identifiers of readers for which the creator of the medium authorizes, in the future, the reading of the data stored in the physical medium that it provides. This list is, for example, entered by the creator by means of a keyboard 5 associated with the recorder or downloaded from the source element, etc. The recorded media provided by the recorder 3 have been illustrated in FIG. 1 under references 10 ', 11' and 12 '. The corresponding chips have been hatched and referenced 1 'to indicate their modified state.
In the example of FIG. 1, the recorder 3 is also a reader having as identifier RD0. This identifier is also contained in the list 31 recorded on the chip 1 '.
Subsequently, the recorded media can be read by any authorized reader 41, 42, ..., 4m. These readers are, according to the invention, capable of decrypting the data from the moment when the chip of the physical medium contains their identifier (RD1, RD2 ... RDm). This identifier makes it possible, as will be seen later, for the medium to transmit the encryption key otherwise unknown to the reader. On the other hand, if the physical medium is introduced in an unauthorized 4x reader (of identifier RDx), this one will be incapable of restoring the multimedia data insofar as the key of encryption will not be communicated to him.
According to a preferred embodiment of the invention, more particularly intended to allow an update of the data stored on the physical medium and / or an update of the list of authorized readers, it is expected to memorize, during the first recording. of the support, an authentication code of the user in the chip 1 'of integrated circuit. For example, the creator of the recorded medium uses the keyboard 5 or any other functionally equivalent means to provide an authentication code and record it on the physical data medium (preferably in the chip thereof) at the time of writing. first use in storage or recording. Subsequently, a modification of the list of authorized readers and / or stored data will be allowed if the support user can provide this authentication code. Otherwise, the list of authorized readers and the data contained in the physical medium can no longer be modified.
A feature of the invention is that the data encryption key is unique to the chip located on or in the storage means, and is not linked to the readers. The same is true for the optional authentication key of the user. Thus, the customization (list of authorized readers) can be made during the first registration of a blank media, which makes the system particularly versatile. It is not excluded, however, that the list of authorized readers is frozen during mass production of the multimedia data carrier. In this case, it is sufficient not to provide for updating by entering an authentication code and will have a protected multimedia data medium, which can be read only by readers with identifiers allowed, other readers not being able to decrypt the data.
An advantage of the invention is that the encryption key does not need to be registered in the authorized readers, nor to be communicated to them by a third party. Only the physical medium contains this key, which allows its individualization for each support during its manufacture. This individualization can even be different inside the same medium. For example, an encryption key can be assigned to each side of a cassette, or to each physical sector of the medium, where appropriate by sector group.
FIG. 2 illustrates, by a schematic flowchart, one embodiment of the secure data storage method according to the present invention. FIG. 2 shows, to the right of a dotted line P, the steps executed in the recorder (RECORDER) and, to the left of the dotted line P, the steps executed on the physical medium side (NUMDEV), more precisely in its chip of integrated circuit.
According to the preferred mode of implementation of the invention, the storage comprises an authentication phase allowing the calculation of an encryption key, an encryption phase of the encryption key, and a data encryption phase. The authentication algorithm used is a symmetric key sharing algorithm without transmission of this key. An example of such an algorithm is described, for example, in French Patent Application No. 2,716,058. An algorithm known as Diffie-Hellman can also be used and described, for example, in B's "Applied Cryptography". Schneier, published by Wiley in 1996, pages 513 to 516, or in US-A-4,200,770. The encryption of the encryption key is, for example, performed by an algorithm known as DES (Data Encryption Standard) and described, for example, in the aforementioned "Applied Cryptography", pages 265 to 301.
For the implementation of the embodiment of FIG. 2, the integrated circuit chip, on the physical support side, must contain four quantities or digital data, namely:<ul id="ul0006" list-style="dash" compact="compact"><li>an authentication key Sc specific to the integrated circuit chip. This may be, for example, a binary word stored in a non-volatile memory of the integrated circuit chip and / or a binary code from a physical parameter network. It is therefore a secret quantity for the implementation of the authentication algorithm.</li><li>a quantity Vc, called public, for the implementation of the symmetric authentication algorithm. This public key is a function of the key Sc. It can be contained permanently in the integrated circuit chip (for example, recorded during the manufacture of the physical medium), recorded in the chip at the time of the first data storage, or provided by passing through the recorder or the reader when running the algorithm.</li><li>the key C of data encryption to be stored on the physical medium. Key C is not used for authentication of a drive, but to encrypt the data. This key C is, again characteristically to the invention, stored in the integrated circuit chip, or even at least partially in a physical parameter network (PPN) directly on the silicon.</li><li>an integer n specific to the authentication and encryption methods. More precisely, it is the modulo on which the different calculations are carried out.</li></ul>
On the recorder side, the necessary data are:<ul id="ul0007" list-style="dash" compact="compact"><li>a secret key Sr of authentication of the recorder (to bring closer to the key Sc, side data carrier) and which is therefore a secret quantity for the execution of the authentication algorithm.</li><li>the RDi identification code (here, RD0) of the recorder. In the example of a Diffie-Hellman algorithm, the code RDi is linked to the key Sr and corresponds to the public key. As a variant, and if this is compatible with the algorithm used, this identification code corresponds, for example, to the serial number or the type number of the recording apparatus.</li><li>modulo n operations.</li></ul>
The quantities Sc and Vc are linked together by the relation: Vc = g<sup>sc</sup> mod n, where g represents a cyclic group generator. The quantities Sr and RDi are linked together by the relation: RDi = g<sup>Sr</sup> mod n.
In the preferred embodiment of Figure 2, the user begins to enter (block 51) a unique authentication code (PINCODE). This authentication code is intended to be registered on the integrated circuit chip during a first registration in order to allow the user to identify himself later for updating the data. The algorithm described in FIG. 2 thus corresponds to the algorithm of a first storage of data on a blank physical medium.
The user then records (block 52) an RDLIST list of authorized reader identifiers (RD0, RD1, ..., RDi, ..., RDm). This is the list 31 of Figure 1 to be stored also in the integrated circuit chip. This list can be predetermined or not according to the applications.
The PINCODE, RDLIST and RD0 data are transmitted by the recorder to the physical medium, more precisely to its chip. The PINCODE and RDLIST data are stored (block 53) in a non-volatile memory (STORE (PINCODE, RDLIST)) associated with the chip of the physical medium. Alternatively, if the list is recorded during the manufacture of the physical medium, a non-rewritable and non-volatile memory will be used.
The next step consists, on the chip side of the support, in making (block 54) the drawing of a random quantity r.
Then, a quantity a is calculated (block 55) from a function f taking into account the quantities r, Sc and n. For example, the function calculated in step 55 is:<maths id="math0001" num=""><math display="block"><mrow><msup><mrow><mtext>a = r</mtext></mrow><mrow><mtext>sc</mtext></mrow></msup><mtext> mod n.</mtext></mrow></math><img file="EP1291868A1_D0001.tif" /></maths>
The quantities a and r are then transmitted to the recorder which, for its part, calculates (block 56) an amount b, from the function f identical to that implemented on the integrated circuit side and of the quantities r, Sr and n . Thus, using the example above, block 56 performs the operation:<maths id="math0002" num=""><math display="block"><mrow><msup><mrow><mtext>b = r</mtext></mrow><mrow><mtext>Sr</mtext></mrow></msup><mtext> mod n.</mtext></mrow></math><img file="EP1291868A1_D0002.tif" /></maths>
The magnitude b calculated by the recorder is transmitted back to the integrated circuit chip. It then calculates (block 57) the shared key of the data encryption algorithm which, for its part, is denoted Kc, from a function α using the quantities b, RD0, Sc and n. In the example of a Diffie-Hellman algorithm, this amounts to performing the operation:<maths id="math0003" num=""><math display="block"><mrow><msup><mrow><mtext>Kc = (b * RD0)</mtext></mrow><mrow><mtext>sc</mtext></mrow></msup><mtext> mod n.</mtext></mrow></math><img file="EP1291868A1_D0003.tif" /></maths>
The chip of the integrated circuit on the physical support side then encrypts (block 58) its secret key C of data encryption from a symmetric β algorithm (for example of the DES type) which uses as argument the encryption key Kc calculated at the step 57. The function β provides an encrypted encryption key Ccrypt.
The quantities Ccrypt and Vc are then transmitted to the recorder which, for its part, recalculates (block 59) a Kr encryption key by implementing the same algorithm α, but applied to the quantities a, Vc, Sr and n. In the example of the Diffie-Hellman algorithm, this amounts to performing the operation:<maths id="math0004" num=""><math display="block"><mrow><msup><mrow><mtext>Kr = (a * Vc)</mtext></mrow><mrow><mtext>Sr</mtext></mrow></msup><mtext> mod n.</mtext></mrow></math><img file="EP1291868A1_D0004.tif" /></maths>
Knowing the encryption key Kr, the recorder reconstructs the encryption key to be applied to the data by applying the inverse algorithm to the symmetrical algorithm of step 58 on the integrated circuit side. This amounts to calculating (block 60) an encryption key C<sub>callus</sub> by implementing a function β<sup>-1</sup> with the arguments Ccrypt and Kr. With a symmetric encryption algorithm, the magnitude Ccal is equal to the magnitude C corresponding to the secret quantity of the integrated circuit chip.
Other methods of encrypted transfer of the secret key C of the chip can be implemented taking into account the appropriate level of security. In addition to symmetric algorithms such as that described in the document FR-A-2 716 058 mentioned above, asymmetric algorithms may also be used. For example, the algorithm known as RSA could be used while taking care to respect the constraints of the protocol in the definition of the values. The RSA algorithm will be used as an encrypted transfer algorithm of the data encryption key. An exemplary RSA algorithm is described in the above-mentioned Applied Cryptography, pages 466 to 474 and US-A-4,405,829.
It then remains to the recorder to encrypt (block 61) DATA data using the key Ccal. Any single-key encryption or encryption method may be used. For example, we can apply the algorithm described in the article "MPEG Video Encryption in real time using secret key cryptography" C. Shi, SY. Wang and B. Bhargava, published by the Department of Computer Sciences of Purdue University in 1999.
The CDATA encrypted data is then recorded (block 62, STORE) by the recorder on the physical medium (here, not the integrated circuit chip, but the physical data medium itself). This is the last step of the storage or recording method according to the invention.
Once stored, the CDATA data can only be decrypted by a reader who is not only able to implement symmetric authentication and encryption algorithms to recover the encryption key C but which, moreover, is present in the list of authorized readers, stored on the integrated circuit chip.
The fact that the key Ccal, constituting secret data of the physical medium, is known by the recorder is not a problem. Indeed, this secret data that is specific to the physical medium could at most be reused to decrypt its own data. However, since the initial recorder corresponds to the user who has the most extensive rights to set the conditions of use of the physical medium, it is not a problem that he knows this key.
FIG. 3 illustrates, by a schematic flowchart, to compare that of FIG. 2, an embodiment of a method for reading (extracting) encrypted data from a physical medium according to the invention. In FIG. 3, the steps performed on the reader's side (READER) have been placed to the left of the dotted line P and the steps implemented on the physical medium side (NUMDEV) to the right of this dotted line.
The known quantities or keys of the reader are Sr, n, and RDi which constitute the identifier of the reader (in the example, its public key).
On physical media, the quantities or keys used are Sc, Vc, n and C, as during storage. However, the CDATA encrypted data is now also present.
The first step of the reading process consists, for the reader (after introduction of the medium in the reader and execution of the usual start-up procedures), to send to the physical medium (more specifically the integrated circuit) its identification code RDi.
On the physical medium side, it checks (block 71) if the reader is part of the list (RDLIST) of the authorized readers.
If not, the process stops (END) and the reading of the data that can possibly be done by the reader will not allow him to decipher them because he does not know the key.
If so, the integrated circuit chip calculates (block 72) the encrypted shared key Kc. This amounts to performing a function α 'from the quantities RDi, Sc and n. The function α 'is preferably the same as the function α of the record (thus reducing the size of the calculation program of the shared key), the only difference being in the arguments used. In reading, one can dispense with the authentication phase of steps 54 to 56. In the example of the Diffie-Hellman algorithm, this amounts to calculating in step 72:<maths id="math0005" num=""><math display="block"><mrow><msup><mrow><mtext>Kc = RDi</mtext></mrow><mrow><mtext>sc</mtext></mrow></msup><mtext> mod n.</mtext></mrow></math><img file="EP1291868A1_D0005.tif" /></maths>
The integrated circuit chip then encrypts (block 73) its secret key C of encryption from the key Kc by implementing the function β. The obtained Ccrypt key, the magnitude Vc and the CDATA encrypted data are then transmitted to the reader.
On the reader side, the shared encryption key Kr is calculated (block 74) by implementing a function α 'with the data Vc, Sr and n. In the example of the Diffie-Hellman algorithm, this amounts to performing the operation:<maths id="math0006" num=""><math display="block"><mrow><msup><mrow><mtext>Kr = Vc</mtext></mrow><mrow><mtext>Sr</mtext></mrow></msup><mtext> mod n.</mtext></mrow></math><img file="EP1291868A1_D0006.tif" /></maths>
Then, the reader recalculates (block 75) an encryption key by implementing the inverse function of the function β on the key Ccrypt and using the shared encryption key Kr.
The authorized reader now has in his possession the data encryption key Ccal which corresponds to the secret key C of the physical medium. It is then able to read (block 76) the CDATA encrypted data by decoding them (READ (CDATA, Ccal)). These decrypted data are then restored (OUT) by any conventional means depending on the application of the reader.
The fact that the reader knows the secret key C = Ccal of the physical medium is not a problem. Indeed, this key is specific to the physical medium and it is an authorized reader. Therefore, the knowledge of this key by an unauthorized third party would not be useful, either to exploit another physical medium that would then have another encryption key, or to use this physical medium in another reader to the extent that this other player would not pass the test 71 prior to the transmission of CDATA encrypted data by the integrated circuit chip.
FIG. 4 illustrates an embodiment of a method of modifying the data stored in the physical medium of the invention and / or in its chip. In FIG. 4, the steps executed on the reader-writer side (READER / RECORDER) have been illustrated to the right of the dotted line P. Those executed on the physical support side (more precisely by its integrated circuit chip) have been illustrated to the left of the dotted line P.
The data contained in the chip of the integrated circuit of the physical medium is Sc, Vc, n, C and PINst, where PINst represents the authentication key of the user that it has memorized in the medium during the first recording (FIG. 2). This key was of course present during the reading process, but was not used.
On the reader-writer side, the data used are Sr, RDi and n.
As for a reading, the reader-recorder begins by identifying itself by transmitting its identifier RDi to the integrated circuit chip. This one then tests (block 71) if the reader is well qualified. If not, the process stops (END).
If so, the integrated circuit chip performs (block 54) the drawing of a random number r.
Then, it calculates (block 72) the encrypted shared key Kr from data RDi, Sc and n (function α ').
The quantities Vc and r are then transmitted by the integrated circuit chip to the reader-recorder which then calculates (block 74) the encryption key Kr on its side.
The following calculation (block 81) consists, on the reader-writer side, in encrypting the number r by implementing the symmetric key encryption algorithm (function β) with the key Kr. A rcrypt number is obtained.
The user then enters his authentication code (PINCODE) on the keypad. The reader-recorder calculates (block 82) a PINcrypt encrypted code from the encryption function β, the PINCODE code and the key Kr.
The quantities PINcrypt and rcrypt are transmitted to the integrated circuit chip. This calculates (block 83) an rcal number by implementing the inverse function β<sup>-1</sup> applied to the number rcrypt with the key Kc as decryption key.
Then, it recalculates (block 84) a PINcal authentication code from the inverse function β<sup>-1</sup> applied to the PINcrypt encrypted code with the key Kc as decryption key.
Next, it is verified (block 85), on the integrated circuit chip side, that the rcal number corresponds to the random number r of the block 54 and that the authentication code PINcal corresponds to the authentication code PINst, stored during the first registration. If not, the process stops (END). If so, the integrated circuit chip transmits a tuning signal (ACKN) to the player-recorder which is then allowed to continue the storage process. The verifications of step 85 can be carried out successively after the determinations of the numbers rcal and PINcal whose order is not important.
The steps in Figure 4 correspond in fact to a verification of the authorization of the reader, then to an authentication of the reader and the user. This makes it possible to be sure that only the authorized user can modify the stored data, or to assign the right of reading to a given device.
Subsequently, the communication protocol between the medium and the reader-recorder is done in the same way as in the storage phase (Figure 2).
An advantage of the present invention is that the encryption and decryption of the data takes place outside the chip. It does not need a large computing capacity. It must simply be sized to be able to recalculate the different encryption and encryption keys as well as contain the authentication code and the list of authorized readers.
Another advantage of the invention is that only the initial user (or authorized by it by giving him the PINCODE code) can modify or delete the stored data or modify the access rights to this data.
Another advantage is that the key sharing system used makes it possible to provide a key per couple (physical medium, reader) without having to store these keys in the readers.
Note that, if an unauthorized reader sends a public identifier (RDi) representing the identifier of an authorized reader contained on the list RDLIST, it must also have the secret key Sr of this reader authorized to have access to the key of encryption C which is itself encrypted on the integrated circuit side of the physical medium by the key Kc.
According to an alternative embodiment, the list of authorized readers is updated automatically when inserting the physical medium in an unknown reader. In this case, the updating method illustrated in FIG. 4 is executed automatically when an unknown reader of the chip transmits its identifier. The authentication code requested from the user then allows him to add this reader to the list. Such a variant allows the authorized user to use the physical medium in any reader (for example, in a car radio, or another user).
Of course, the present invention is susceptible of various variations and modifications which will be apparent to those skilled in the art. In particular, one can choose any other symmetric encryption algorithm that DES algorithm. However, this has the advantage of being able to be implemented in a hardware way (in hardwired logic), to be fast and perfectly tested.
In addition, the key exchange Diffie-Hellman algorithm can also be replaced by any algorithm representing a key sharing or transfer functionality.
In addition, the public keys Vc and RDi used by the encryption phase may not be contained respectively in the medium and the reader. They can be transmitted to them by any system. For example, a transmission system may be envisaged by means of a telecommunication network of the public keys intended for readers and / or a bar code reading system representing these public keys, on the physical supports side.
11 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11
Every citation, both waysCites: the store holds 11 of 12
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| WO2008032002A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| FR2890201A1 | Cited by | France | – | Search report | – |
| FR2890201A1 | Cited by | France | – | Search report | – |
| EP0874299A2 | Cites | European Patent Office (EPO) | Y | Search report | 9-15,17,19 |
| EP0878796A2 | Cites | European Patent Office (EPO) | XY | Search report | 1-8,16,18 |
| EP0977107A2 | Cites | European Patent Office (EPO) | A | Search report | 1-19 |
| FR2716058A1 | Cites | France | DA | Search report | 1-19 |
| FR2716058A1 | Cites | France | DA | Search report | 1-19 |
| FR2751767A1 | Cites | France | DA | Search report | 1-19 |
| FR2751767A1 | Cites | France | DA | Search report | 1-19 |
| US4200770A | Cites | United States of America | DA | Search report | 1-19 |
| US4200770A | Cites | United States of America | DA | Search report | 1-19 |
| US4405829A | Cites | United States of America | DA | Search report | 1-19 |
| US4405829A | Cites | United States of America | DA | Search report | 1-19 |
| "Content Protection for Prerecorded Media Specification", CONTENT PROTECTION FOR PRERECORDED MEDIA SPECIFICATION, XX, XX, 28 June 2000 (2000-06-28), XX, pages complete, XP002204102 | Non-patent | – | – | Search report | – |
| B. SCHNEIER: "Applied cryptography ; Protocols, Algorithms, and Source Code in C, second edition", 1996, WILEY, XP002204104 | Non-patent | – | – | Search report | – |
| "MPEG Video Encryption in real time using secret key cryptography", C. SHI, S-Y. WANG, B. BHARGAVA, publié par le "Department of computer science of Purdue university", 1999 | Non-patent | – | – | Search report | – |
4 members in 4 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 0111718 | France | A | |
| 0111718 | France | A | |
| 0111718 | France | – | |
| 0111718 | – | – | – |
| FR20010011718 | – | – | – |
Members4
| Document | Office | Kind | |
|---|---|---|---|
| EP1291868A1This record | European Patent Office (EPO) | A1 | |
| US2003051152A1 | United States of America | A1 | |
| FR2829603A1 | France | A1 | |
| JP2003177971A | Japan | A |
9 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Application deemed to be withdrawnWithdrawn18D | 18D | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWNSTAA | STAA | |
| First examination report despatched17Q | 17Q | |
| Designation fees paidAKX | AKX | |
| Request for examination filed17P | 17P | |
| Designated contracting statesAK | AK | |
| Designated contracting statesAK | AK | |
| Request for extension of the european patentAX | AX | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI |
Numbers
- Publication
- 1291868
- Publication, DOCDB
- 1291868
- Publication, EPODOC
- EP1291868
- Application
- 2354141
- Application, DOCDB
- 02354141
- Application, EPODOC
- EP20020354141
Titles3
- German
- Verfahren und Vorrichtungen zum Speichern und Lesen von digitalen Daten auf einem Speichermedium
- English
- Methods and devices for storing and reading digital data on a storage medium
- French
- Procédé et dispositif de stockage et de lecture de données numériques sur un support physique
Classification
- CPC, 9
- G11B20/0021
- G11B20/00086
- G11B20/00152
- G11B20/00195
- G11B20/00275
- G11B20/00347
- G11B20/00413
- G11B20/00695
- G11B20/00876
- IPC, 6
- G06F12 14
- G06F21 10
- G06F21 60
- G06F21 62
- G06K19 073
- G11B20 00
Designated states2
- Contracting states, 1
- Türkiye
- Extension states, 1
- Slovenia