EP1444690B9

System and method for controlled copying and moving of content between devices and domains based on conditional encryption of content key depending on usage state

Abstract

This record has no abstract on file.

EP1444690B9, drawing sheet 1
Sheet 1 of 8

Term

Term ended

Expired 16 October 2022, 3.9 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

21 claims: 16 independent, 5 dependent

  1. 1
    A method of moving protected content within an authorised domain (10), at least a first device (12) and a second device (13) being part of the authorised domain, each of the devices (12, 13) which are part of the authorised domain sharing a domain key, wherein having the domain key defines the devices (12, 13) as being part of the authorised domain, the method comprising the first device:receiving from an external content provider source (50) a content key seed and content comprising a content ID, wherein the content key seed and content ID are associated with one another in a way known to the content provider;creating a content key by operating on the content key seed with the first device's domain key;encrypting the received content with the content key;encrypting the content key with the domain key in such a way that all devices within the authorised domain have the ability to decrypt the encrypted content key with the domain key;creating a voucher associated with the encrypted content, the voucher including the encrypted content key, the content ID, a usage state record dictating play limits in respect of the content, and information identifying the authorised domain;transmitting the encrypted content and the voucher to the second device (13);andsubsequent to transmitting the voucher, rendering unusable any vouchers on the first device which are associated with said encrypted content. Procédé de déplacement de contenu protégé dans un domaine autorisé (10), au moins un premier dispositif (12) et un second dispositif (13) faisant partie du domaine autorisé, chacun des dispositifs (12, 13) qui font partie du domaine autorisé partageant une clé de domaine, dans lequel le fait que les dispositifs (12, 13) aient la clé de domaine les définit comme faisant partie du domaine autorisé, le procédé comprenant le premier dispositif ;la réception depuis une source de fournisseur de contenu externe (50) d'une valeur initiale de clé de contenu et d'un contenu comprenant un ID de contenu, dans lequel le valeur initiale de clé de contenu et l'ID de contenu sont associés l'un à l'autre d'une façon connue du fournisseur de contenu ;la création d'une clé de contenu en agissant sur la valeur initiale de clé de contenu avec la clé de domaine du premier dispositif ;le cryptage du contenu reçu avec la clé de contenu ;le cryptage de la clé de contenu avec la clé de domaine de façon à ce que tous les dispositifs dans le domaine autorisé puissent décrypter la clé de contenu cryptée avec la clé de domaine ;la création d'un bon associé au contenu crypté, le bon comportant la clé de contenu cryptée, l'ID de contenu, un enregistrement d'état d'utilisation dictant des limites de reproduction relativement au contenu, et des informations identifiant le domaine autorisé ;la transmission du contenu crypté et du bon au second dispositif (13) ;et après la transmission du bon, l'invalidation sur le premier dispositif de tous bons associés audit contenu crypté. Verfahren zum Verlagern von geschütztem Inhalt innerhalb eines autorisierten Bereichs (10), wobei zumindest eine erste Einrichtung (12) und eine zweite Einrichtung (13) Teil des autorisierten Bereichs sind, wobei jede der Einrichtungen (12, 13), die Teil des autorisierten Bereichs ist, einen Bereichsschlüssel mitbenutzt, wobei ein Verfügen über den Bereichsschlüssel die Einrichtungen (12, 13) als Teil des autorisierten Bereichs definiert, wobei das Verfahren aufweist, dass die erste Einrichtung: von einer externen Inhaltsbereitstellungsquelle (50) einen Inhaltsschlüsselwert und einen Inhalt, der eine Inhalts-ID aufweist, empfängt, wobei der Inhaltsschlüsselwert und die Inhalts-ID miteinander in einer Weise verknüpft sind, die dem Inhaltsbereitsteller bekannt ist;einen Inhaltsschlüssel durch Bearbeiten des Inhaltsschlüsselwerts mit dem Bereichsschlüssel der ersten Einrichtung erstellt;dem empfangenen Inhalt mit dem Inhaltsschlüssel verschlüsselt;den Inhaltsschlüssel mit dem Bereichsschlüssel derart verschlüsselt, dass alle Einrichtungen innerhalb des autorisierten Bereichs die Fähigkeit haben, den verschlüsselten Inhaltsschlüssel mit dem Bereichsschlüssel zu entschlüsseln;einen Beleg erstellt, der mit dem verschlüsselten Inhalt verknüpft ist, wobei der Beleg den verschlüsselten Inhaltsschlüssel, die Inhalts-ID, eine Benutzungszustandsaufzeichnung, die Spielraumlimits in Bezug auf den Inhalt festlegt, und Informationen, die den autorisierten Bereich identifizieren, enthält;den verschlüsselten Inhalt und den Beleg zur zweiten Einrichtung (13) sendet;undnach dem Senden des Belegs sämtliche Belege an der ersten Einrichtung unbrauchbar macht, die mit dem verschlüsselten Inhalt verknüpft sind.
  2. 2
    Procédé selon la revendication 1, comprenant en outre :le cryptage par le premier dispositif de la totalité du bon. The method of claim 1 further comprising: the first device encrypting the entire voucher. Verfahren nach Anspruch 1, des Weiteren aufweisend: dass die erste Einrichtung den gesamten Beleg verschlüsselt.
  3. 3
    Procédé selon la revendication 1 ou 2, comprenant en outre :la réception par le second dispositif dudit contenu crypté et du bon associé à ce contenu. The method of claim 1 or 2 further comprising: the second device receiving said encrypted content and the voucher associated with that content. Verfahren nach Anspruch 1 oder 2, des Weiteren aufweisend: dass die zweite Einrichtung den verschlüsselten Inhalt und den Beleg, der mit diesem Inhalt verknüpft ist, empfängt.
  4. 4
    Procédé selon la revendication 1, 2 ou 3, comprenant, par le second dispositif :le décryptage de la clé de contenu cryptée ;etl'utilisation de la clé de contenu décryptée pour décrypter le contenu crypté. The method of claim 1, 2 or 3 comprising the second device: decrypting the encrypted content key;andusing the decrypted content key to decrypt the encrypted content. Verfahren nach Anspruch 1, 2 oder 3, aufweisend, dass die zweite Einrichtung: den verschlüsselten Inhaltsschlüssel entschlüsselt;undden entschlüsselten Inhaltsschlüssel zum Entschlüsseln des verschlüsselten Inhalts verwendet.
  5. 5
    A computer program comprising computer program instructions that, when executed by an apparatus, causes said apparatus to perform a method according to claim 1 or claim 2. Computerprogramm, aufweisend Computerprogrammanweisungen, die, wenn sie von einer Vorrichtung ausgeführt werden, die Vorrichtung veranlassen, ein Verfahren nach Anspruch 1 oder 2 auszuführen. Programme informatique comprenant des instructions de programme informatique qui, à leur exécution par un appareil, amènent ledit appareil à exécuter un procédé selon la revendication 1 ou la revendication 2.
  6. 6
    An apparatus (12) for moving protected content within an authorised domain (10), at least a first device (12) and a second device (13) being part of the authorised domain, each of the devices (12, 13) which are part of the authorised domain sharing a domain key, wherein having the domain key defines the devices (12, 13) as being part of the authorised domain, the apparatus comprising:means for receiving at the first device from an external content provider source (50) a content key seed and content comprising a content ID, wherein the content key seed and content ID are associated with one another in a way known to the content provider;means for creating, at the first device, a content key by operating on the content key seed with the first device's domain key;means for encrypting, at the first device, the received content with a content key;means for encrypting, at the first device, the content key with the domain key in such a way that all devices within the authorised domain have the ability to decrypt the encrypted content key with the domain key;means for creating, at the first device, a voucher associated with the encrypted content, the voucher including the encrypted content key, the content ID, a usage state record dictating play limits in respect of the content, and information identifying the authorised domain;means for transmitting the encrypted content and the voucher from the first device to the second device (13);andmeans for rendering unusable any vouchers on the first device which are associated with said encrypted content, subsequent to transmitting the voucher. Appareil (12) de déplacement de contenu protégé dans un domaine autorisé (10), au moins un premier dispositif (12) et un second dispositif (13) faisant partie du domaine autorisé, chacun des dispositifs (12, 13) qui font partie du domaine autorisé partageant une clé de domaine, dans lequel le fait que les dispositifs (12, 13) aient la clé de domaine les définit comme faisant partie du domaine autorisé, l'appareil comprenant : un moyen de réception au niveau du premier dispositif depuis une source de fournisseur de contenu externe (50) d'une valeur initiale de clé de contenu et d'un contenu comprenant un ID de contenu, dans lequel le valeur initiale de clé de contenu et l'ID de contenu sont associés l'un à l'autre d'une façon connue du fournisseur de contenu ;un moyen de création, au niveau du premier dispositif, d'une clé de contenu en agissant sur la valeur initiale de clé de contenu avec la clé de domaine du premier dispositif ;un moyen de cryptage, au niveau du premier dispositif, du contenu reçu avec une clé de contenu ;un moyen de cryptage, au niveau du premier dispositif, de la clé de contenu avec la clé de domaine de façon à ce que tous les dispositifs dans le domaine autorisé puissent décrypter la clé de contenu cryptée avec la clé de domaine ;un moyen de création, au niveau du premier dispositif, d'un bon associé au contenu crypté, le bon comportant la clé de contenu cryptée, l'ID de contenu, un enregistrement d'état d'utilisation dictant des limites de reproduction relativement au contenu, et des informations identifiant le domaine autorisé ;un moyen de transmission du contenu crypté et du bon du premier dispositif au second dispositif (13) ;etun moyen d'invalidation sur le premier dispositif de tous bons associés audit contenu crypté, après la transmission du bon. Vorrichtung (12) zum Verlagern von geschütztem Inhalt innerhalb eines autorisierten Bereichs (10), wobei zumindest eine erste Einrichtung (12) und eine zweite Einrichtung (13) Teil des autorisierten Bereichs sind, wobei jede der Einrichtungen (12, 13), die Teil des autorisierten Bereichs ist, einen Bereichsschlüssel mitbenutzt, wobei ein Verfügen über den Bereichsschlüssel die Einrichtungen (12, 13) als Teil des autorisierten Bereichs definiert, wobei die Vorrichtung aufweist: Mittel zum Empfangen an der ersten Einrichtung von einer externen Inhaltsbereitstellungsquelle (50) eines Inhaltsschlüsselwerts und eines Inhalts, der eine Inhalts-ID aufweist, wobei der Inhaltsschlüsselwert und die Inhalts-ID miteinander in einer Weise verknüpft sind, die dem Inhaltsbereitsteller bekannt ist;Mittel zum Erstellen an der ersten Einrichtung eines Inhaltsschlüssels durch Bearbeiten des Inhaltsschlüsselwerts mit dem Bereichsschlüssel der ersten Einrichtung;Mittel zum Verschlüsseln an der ersten Einrichtung des empfangenen Inhalts mit einem Inhaltsschlüssel;Mittel zum Verschlüsseln an der ersten Einrichtung des Inhaltsschlüssels mit dem Bereichsschlüssel derart, dass alle Einrichtungen innerhalb des autorisierten Bereichs die Fähigkeit haben, den verschlüsselten Inhaltsschlüssel mit dem Bereichsschlüssel zu entschlüsseln;Mittel zum Erstellen an der ersten Einrichtung eines Belegs, der mit dem verschlüsselten Inhalt verknüpft ist, wobei der Beleg den verschlüsselten Inhaltsschlüssel, die Inhalts-ID, eine Benutzungszustandsaufzeichnung, die Spielraumlimits in Bezug auf den Inhalt festlegt,und Informationen, die den autorisierten Bereich identifizieren, enthält;Mittel zum Senden des verschlüsselten Inhalts und des Belegs von der ersten Einrichtung zur zweiten Einrichtung (13);undMittel zum Unbrauchbarmachen sämtlicher Belege an der ersten Einrichtung, die mit dem verschlüsselten Inhalt verknüpft sind, nach dem Senden des Belegs.
  7. 7
    Appareil selon la revendication 6, comprenant en outre :un moyen de cryptage, au niveau du premier dispositif, de la totalité du bon. The apparatus of claim 6 further comprising: means for encrypting, at the first device, the entire voucher. Vorrichtung nach Anspruch 6, des Weiteren aufweisend: Mittel zum Verschlüsseln des gesamten Belegs an der ersten Einrichtung.