EP1648112B1

Apparatus and method for secure content key updates

Abstract

This record has no abstract on file.

EP1648112B1, drawing sheet 1
Sheet 1 of 31

Term

Term ended

Expired 16 September 2025, 1 year ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

16 claims: 5 independent, 11 dependent

  1. 1
    An information processing apparatus (B) configured to receive encrypted contents and key information attached to the contents transmitted from a communication apparatus (A) connected via a network, comprising:authentication & key exchange unit (15) configured to perform authentication & key exchange processing by using a given protocol with the communication apparatus (A) and generate a first key shared with the communication apparatus (A);a contents receiver configured to receive encrypted contents obtained by encrypting the contents with a second key generated by using the first key and the key information, and the key information attached to the encrypted contents;a contents decryption unit (16) configured to decrypt the encrypted contents by using the first key and the key information;a contents confirmation request unit (14) configured to instruct the communication apparatus (A) to transmit or confirm the key information held by the communication apparatus (A), when the contents decryption unit decrypts the contents based on the second key firstly generated by using the first key;and a key information confirmation unit (14) configured to receive the key information or a confirmation result of the key information encrypted by using the first key transmitted from the communication apparatus in response to instruction of the contents conformation request unit to confirm whether or not the received key information coincides with the key information received by the contents receiver.
  2. 8
    The information processing apparatus according to any of claims 1, 2 and 4, further comprising a after-confirmation operation unit configured to perform at least one of another instruction by the contents confirmation request unit and prohibition of decryption of the contents transmitted from the communication apparatus, when the key information received by the contents receiver does not correspond to the key information held by the communication apparatus.
  3. 10
    The information processing apparatus according to any of claims 1 to 4, further comprising:a contents confirmation response receiver configured to receive a contents confirmation response transmitted from the communication apparatus;a Hash acquisition unit configured to acquire a Hash value calculated by using a random number included in the contents confirmation response;and a random number checking unit configured to check whether or not the Hash value acquired by the Hash acquisition unit coincides with a Hash value calculated by using the random number transmitted to the communication apparatus.
  4. 11
    An information processing apparatus (A) configured to transmit encrypted contents to a communication apparatus (B) connected via a network, comprising:an authentication & key exchange unit (5) configured to perform authentication & key exchange processing by using a given protocol with the communication apparatus (B);a key generation unit configured to operate a given function by using the key information including a random number and the first key to generate a second key;an encryption unit (6) configured to encrypt contents by using the second key;a contents transmitter (3) configured to transmit the encrypted contents with the key information in plain text, to the communication apparatus (B);a key information updating unit configured to update the key information based on a given condition;a random number acquisition unit configured to acquire the random number included in a contents confirmation request transmitted from the communication apparatus;a key information acquisition unit configured to acquire the key information being currently used to encrypt the contents;and a contents confirmation response unit (4) configured to transmit a message including the key information acquired by the key information acquisition unit and the random number acquired by the random number acquisition unit to the communication apparatus (B), as a contents confirmation response for the contents confirmation request.
  5. 16
    An information processing method of transmitting encrypted contents via a network from a transmitter (A) to a receiver (B), comprising:performing authentication & key exchange processing by using a given protocol between the transmitter (A) and the receiver (B) to generate a first key shared between the transmitter (A) and the receiver (B), wherein the transmitter (A) encrypts the contents based on a second key generated by a given function by using key information including a generated random number and the first key, and transmits the encrypted contents with the key information in plain text, to the receiver (B);the receiver (B) receives the encrypted contents and the key information to decrypt the encrypted contents by using the key information;the transmitter (A) updates the key information based on a given condition;the receiver (B) transmits the contents confirmation request for instructing transmission or confirmation of the key information held by the transmitter (A) to the transmitter (A) at a given timing;the transmitter (A) acquires the random number included in the contents confirmation request and the key information being currently used, when the contents confirmation request is received;the transmitter (A) transmits to the receiver (B) at least one of a confirmation result showing whether the acquired key information coincides with the key information held by the receiver (B) and the acquired key information, with the acquired random number, as a contents confirmation response for the contents confirmation request;and the receiver (B) performs at least one of another instruction by the contents confirmation request unit and prohibition of decryption of the contents transmitted from the communication apparatus, when the key information added to the encrypted contents does not coincide with the key information being currently used by the transmitter.