Method for sharing rights objects between users
Abstract
A method for sharing objects with usage rights associated with a content, which includes: copying an object with usage rights owned by a first user (601) on a copy server (640) connected via a wired or wireless network, object that a rights issuer has issued or that has been received from another user; said method is characterized by: the creation of an object with rights of use by the copy server (640) for a second user (602) within the limits of the object with rights of use stored on the copy server (640) ; and forwarding a copy server address (640) from the first user to the second user so that this second user (602) can download the object with usage rights created on the copy server (640).

Term
Term ended
Projected expiry passed 20 August 2024, 2.1 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
5 claims: 1 independent, 4 dependent
- 1ES 2 282 811 T3 ES 2 282 811 T3 CLAIMS REIVINDICACIONES 1. A method of sharing objects with rights of use associated with content, including:copying an object with rights of use owned by a first user (601) on a copy server (640) connected via a wired or wireless network, object that has been issued by a rights issuer or that has been received from another user;said method is characterized by: the creation of an object with rights of use by the copy server (640) for a second user (602) within the limits of the object with rights of use stored in the copy server (640) ;and forwarding an address of the copy server (640) of the first user to the second user so that this second user (602) can download the object with rights of use created in the copy server (640). 1. Un método para compartir objetos con derechos de uso asociados a un contenido, que incluye: la copia de un objeto con derechos de uso propiedad de un primer usuario (601) en un servidor de copias (640) conectado mediante una red alámbrica o inalámbrica, objeto que ha emitido un emisor de derechos o bien que se ha recibido de otro usuario;dicho método se caracteriza por: la creación de un objeto con derechos de uso por parte del servidor de copias (640) para un segundo usuario (602) dentro de los límites del objeto con derechos de uso almacenado en el servidor de copias (640);y el reenvío de una dirección del servidor de copias (640) del primer usuario al segundo usuario para que este segundo usuario (602) pueda descargar el objeto con derechos de uso creado en el servidor de copias (640).
58 paragraphs in 6 sections, as filed
ES 2 282 811 T3
DESCRIPTION
Method to share objects with use rights between users.
The present invention relates to a method for distributing, in part or in whole, a rights object (RO) to users.
Today, wireless communication and Internet technologies are rapidly advancing, and the use of handheld or portable terminals with enhanced multimedia functions has become widely used in everyday life. Mobile phones include a large number of additional functions. For example, mobile phones with melodies based on monophonic tones are being replaced by mobile phones with polyphonic melodies of 16 and 32 tones. Recently, mobile phones have been developed that provide 64-tone melodies. Likewise, the demand for mobile phone terminals with digital cameras is increasing. Since the demand for these portable or pocket multimedia terminals is increasing, companies or industrial sectors involved in the distribution of services or related content, such as downloads of ringtones, waiting tones, photographs or images of characters or artists and moving images, such as movies and sports, are experiencing rapid growth.
In the past, content delivery services used to be free. However, this trend is reversing and charges are already being made for these services. In a first stage, a fundamental problem that content providers encountered was the limited ability to prevent illegal copying of content distributed to users. To this end, content providers and distributors have devised various mechanisms based on piracy prevention technologies. Today, the introduction of digital rights management (DRM) systems that manage objects with rights of use (RO) in a flexible and convenient way is a growing trend.
Although the DRM system has allowed the free distribution of encrypted content to users, this methodology prevents a recipient from executing the content before acquiring the associated RO. The freedom in content distribution allows users to forward DRM-protected content to friends or family with whom they wish to share it, a fact that allows the proliferation of high-quality content, in addition to the distribution and advertising carried out by its users. . To play the encrypted content, the receiver must have an RO associated with the content. In other words, the recipient cannot execute content that another user has forwarded to him without acquiring the corresponding RO.
Figure 1 shows a conventional distribution process for DRM-protected content.
A first user 101 receives the encrypted content provided by a content provider 130 for execution. Although encrypted content can be streamed and distributed for free, an RO associated with that content is required to run. When the first user 101 requests (acquires) the RO to the issuer of rights of use 100 to be able to execute the content, the issuer of rights of use 100 transmits the RO requested (acquired) to the first user 101 who, then, has the right to execute content and enjoy the multimedia information it contains.
Once the first user 101 is satisfied with the content after its execution and wishes to share it with a friend, the second user 102, the first user 101 forwards the content in question to the second user 102. This second user 102 needs an RO to execute the encrypted content it has received from the first user 101. The second user 102, who does not have an RO associated with the content, requests the issuer of rights of use 100 to transmit the RO for the execution of the content. The second user 102 can receive the content they want directly from the content provider 300 as well as the first user 101.
The conventional DRM system shown in Figure 1 does not allow a user of the service to share with another user an object with use rights necessary to execute said content. To address this issue, Japanese Patent No. 2003-58657, pending publication, proposes a method of sharing a license to use content with another user that includes the following steps:
1. Storing the information of a content license in a private area of a database with information on licenses for each user or terminal;
2. Upon request for the transfer by a transferor, creation of an encryption key, encryption of the license information to transmit it using the encryption key, transfer of the encrypted information from the private area to the public area and issuance of the encryption key for the transferor;
3. Delivery of the encryption key that has been issued from the transferor to the assignee;
Four. Upon request for the transfer of the license by the assignee, authentication thereof by verifying that it has the encryption key that the assignor has issued; Y
ES 2 282 811 T3
5. After this authentication, decryption of the license information to transmit it with the encryption key and transfer of the decrypted information from the public area to the private area for the assignee.
The proposed system allows a user who has a license to run the content to transfer said license to another user. In other words, the user can share the license of the content he owns with others.
However, in the conventional system, it is assumed that a content provider and a proprietary server manage the content license and that the license information is located only on the server. In other words, the server must be involved in the process of sharing the license between users. In addition, after the transferor request, the server performs a prior authentication of the request. That is, to transfer the content license to the assignee, the assignor receives an appropriate encryption key from the server and delivers it to the assignee. Then, it is authenticated by the encryption key to use the content. Thus, the conventional system requires a complicated process to transfer the license.
Systems and techniques for the control and management of digital assets are described in WO 02/06931. These systems and techniques are especially useful when such assets are transmitted electronically, for example via the Internet, since these techniques make the Internet a secure medium for communication and control of digital assets. In addition, they enable dynamic management and control of digital assets, regardless of the location of those assets. The use of these systems and techniques allows thinking of new Internet-based distribution models, in addition to providing superior knowledge of the use and status of digital assets. Specific implementations of these systems and techniques allow functions such as monitoring the lifespan of digital content, multi-level control of digital content (including session encryption, asset encryption, and remote management) as well as remote management approaches. marketing based on testing the product before you buy it. In addition, they also support features such as digital rights transfer, tracking, segmentation, archiving, and streamlined upgrade and upgrade management.
Patent EP 0.715.247 describes a system for controlling the distribution and use of digital works through the use of digital receipts. A “digital receipt” serves to authorize its holder to exercise any right of use with respect to a digital work. Use rights are used to define how a digital work can be used or distributed. Each right of use can specify a digital receipt that must be available before the right can be exercised. Digital works are stored in storage spaces that use rights for those jobs apply when a storage space requests the use of a digital work. Each storage space has a “generic receipt agent” who is in charge of formalizing these receipts. In some cases, only the “generic receipt agent” is required, but in others a “special receipt agent” who is in another storage space is required to formalize the receipts.
The Open Mobile Alliance Digital Rights Management version 1.0 of September 5, 2002, OMADownload DRM-v1_0-20020905-C provides an introduction to digital rights management methods, especially in the field of digital rights downloads. multimedia objects using wireless application protocols.
The present invention provides a method to transmit and share between users and free of charge an object with rights of use (RO) necessary to execute the specific content.
According to a first aspect of the present invention, a method for sharing objects with rights of use associated with the content is provided which consists of the following steps: creating a copy of an object with rights of use of a first user on a server of copies connected through a wired or wireless network, an object that has been issued by a rights issuer or that has been received from another user; access of the first user to the copy server and creation of an object with rights of use for a second user within the limits of the object with rights of use stored on the copy server; finally, forwarding a copy server address so that the second user can download the object with rights of use created on the copy server.
Making a copy of the RO for the user on a copy server ensures quick recovery in the event of a loss or failure of a portable terminal, but can also reduce the processing load on the terminal.
Preferably, the method also includes encrypting the created use rights object using a public key of the second user on the copy server before transmitting a copy server address of the first user to the second user.
Preferably, the method also includes the transmission of information about the boundaries of the objects with rights of use that the first and second users own to the rights issuer in a predetermined period.
Preferably, the method also includes the process of electronically signing use rights objects created with a secret key of the first user on a copy server before the first user transmits the copy server address to the second user.
Preferably, the method also includes encrypting the rights-of-use object with a public key of the second user prior to transmission of the rights-of-use object to the second user.
ES 2 282 811 T3
In order to facilitate the understanding of the present invention, as well as to show the methods for putting its embodiments into practice, various examples will be cited below which will make reference to the attached schematic drawings in which:
Figure 1 shows a conventional content distribution process in a digital rights management (DRM) format;
Figure 2 shows a process of creating and distributing an object with rights of use (RO) necessary to execute the DRM content;
Figure 3A shows a document format of the RO which is collected in Figure 2;
Figure 3B shows a document structure of the RO as shown in Figure 2;
Figure 4A shows document formats of an RO created by modifying the RO for other users;
Figure 4B shows document structures of an RO created by modifying the RO for other users;
Figure 5 shows a process of creating, distributing and managing an RO necessary to execute the DRM content; Y
Figure 6 shows a process of creating and distributing an RO necessary to execute the DRM content in accordance with an embodiment of the present invention.
The preferred embodiments of the present invention will now be described in detail with reference to the accompanying drawings.
Figure 2 shows a process of creating and distributing an object with rights of use (RO) required to execute the DRM content.
Referring to FIG. 2, a first user 201 owns an object with rights of use (RO) issued by a rights issuer. The RO currently in possession of the first user 201 contains the rights to reproduce encrypted content a predetermined number of times. A non-limiting example is described in which rights can be granted to reproduce encrypted content up to ten times.
When the first user 201 shares with friends, that is, the second and third users 202 and 203, the RO containing the reproduction rights, these users 202 and 203 can reproduce the encrypted content. This means that the first user 201 creates ROs containing the rights to perform five and three reproductions based on the RO that defines the rights to reproduce the content up to ten times. Therefore, the first user 201 can play the content twice. The ROs created are forwarded to the second and third users, 202 and 203, respectively. In a preferred embodiment, the ROs containing the rights to reproduce the content five and three times are encrypted using public keys of the recipients (second and third users 202 and 203) and forwarded to the second and third users, 202 and 203, respectively, which, in turn, decrypt the encrypted ROs by means of their secret keys. Forwarding the encrypted ROs prevents an unauthorized third party from using these ROs. Preferably, the ROs are electronically signed with a secret key of the sender (the first user 201) for transmission, thereby preventing forgery, manipulation or denial of transmission by the sending party.
Once the third user 203 is satisfied with the result after playing the encrypted content with the RO received from the first user 201, the third user 203 creates an RO containing rights to play the content once based on the RO containing the rights to reproduce the content twice and forwards the created RO to a fourth user 204. The RO must be encrypted and electronically signed prior to transmission.
The use of the RO of the present invention is not limited to a count of the times content is played, but can contain the duration of the playback. In this case, a new RO is created by dividing the playback duration into several parts. This RO is created as part of the present invention.
Figures 3A and 3B show a format and document structure of the RO that is shown in the figure
2. Looking at Figure 3A, <rights> (rights) contains a <uid> (user ID) and a <KeyValue> (key value), which specify a content object ID (cid) of the RO and a key value with which the content is encrypted, respectively. For its part, <permission> (permission) contains various permissions: <play> (reproduction), <copy> (copy) and <move> (transfer) to reproduce, copy and move the content, respectively. Each of these permissions is restricted by a <constraint>. For example, the <constraint> for the <play> permission can be <count> (count), which means the number of times the content is played, <duration> (duration), which means the time for which it is played the content, and <datetime> (date or time), which means a certain date or time after which the <play> permission expires. In Figure 3A, the <constraint> (constraint) is the count of ten reproductions.
ES 2 282 811 T3
An example of a document structure of the RO is shown in Figure 3B. In this figure, the RO includes restrictions, metadata, permissions and the signature of a rights issuer. The constraints contain the RO ID and key value, while the metadata contains information about the version and issuer of the RO. Permissions contain various permissions to reproduce, copy, and port the content, and the rights issuer's signature indicates an entity issuing the appropriate RO.
Figures 4A and 4B show document formats and structures of an RO created by modifying the RO for other users. Looking at Figure 4B, user A has an RO issued by a suitable rights issuer. Based on the permissions defined in the RO, which are rights to reproduce the appropriate content up to ten times, user A creates an RO that contains rights to reproduce the content five times in order to transfer the created RO to user B. In this case, in addition to the RO issued by the rights issuer, user A creates an RO that contains the rights to reproduce the content ten times as well as the transfer of the rights to reproduce the content five times in order to specify the modifications made by user A during periodic data transmissions subsequently made with the rights issuer. The metadata for the modified RO specifies that the RO was created for user B, and the permissions specify that the rights to play the content five times have been carried over. Finally, user A signs the appropriate column to indicate that he has made the modifications himself. On the other hand, the metadata of the RO created for user B specifies that the RO has been received from user A, and the permissions indicate the rights to reproduce the content five times. Finally, a signature is made to indicate that user A has created the RO. The RO created for user B is forwarded to this user and the content is executed within the restrictions imposed on the permissions that are defined in the RO.
Figure 4A shows document formats of an RO created for user B, as shown in Figure 4B, and the modified RO for user A. The modified RO contains a new <move> permission that specifies the transfer of the rights to reproduce the content five times, the signature of user A and other information. The RO created for User B specifies the rights to reproduce the content five times, User A's signature, and other information.
Figure 5 shows a process for creating, distributing, and managing an RO required to run content in a digital rights management (DRM) format.
A first user 501 owns an RO that contains rights to reproduce the content up to ten times. The first user 501 creates two ROs containing rights to reproduce the content five times and three times and transmits them to a second and third user, 502 and 503, respectively. Consequently, the remaining RO, which is currently owned by the first user 501, contains rights to reproduce the content twice. When the third user 503 creates an RO containing rights to reproduce the content once and forwards it to a fourth user 504, the remaining RO in possession of the third user 503 contains rights to reproduce the content twice.
However, the first or third user, 501 or 503, can create an RO that exceeds the limits of the reproduction rights defined in the RO that they own, or they can forward a legally created RO to multiple users at a given time, this es, by maliciously modifying it using software. To prevent illegal use of user-owned ROs, ROs should be transmitted to a 500 rights issuer at regular intervals. For example, users can forward their own ROs to entitlement issuer 500 each time a new RO is created or after predetermined time intervals, such as every week or every fortnight.
When the RO is forwarded after a long period of time, there may be discrepancies between the limit of the RO owned by each user and the one owned by the rights issuer. These discrepancies are closely related to a period in which the RO is transmitted to the rights issuer 500. That is, as the period increases, the traffic load decreases, but the possibility of discrepancies increases. On the other hand, as the period shortens, the traffic load increases, but the possibility of discrepancies decreases.
It is preferable to encrypt the RO created with a public key from a recipient. Each user can transmit to other users the encrypted content or an address or uniform resource locator (URL) in which the encrypted content is located along with the RO associated with the content.
A process for creating and distributing an RO required to execute DRM content in accordance with an embodiment of the present invention is shown in Figure 6. A first user 601 may store an RO issued by a rights broadcaster on a copy server 640 connected via a wired or wireless network. As previously described with reference to Figures 2 and 5, the first user 601 can directly create the RO and forward it to the second or third user 602 and 603. However, in the example embodiment, the copy server 640 creates ROs to transmit them to the second and third users, 602 and 603, in order to reduce an excessive burden of computer processing as a result of encryption and electronic signature. That is, the copy server 640 creates the respective ROs for the second and third users, 602 and 603, starting from the RO of the first user 601 that it has stored. The ROs created are subject to electronic signature and encryption. The copy server 640 receives a secret key from the first user 601 for the electronic signature and public keys of the second and third users, 602 and 603, for the encryption from the first to the third user, 601-603, and performs the electronic signature and the encryption in each of the ROs using these keys.
ES 2 282 811 T3
Meanwhile, the first user 601 forwards an address or URL of the copy server 640 to the second and third users, 602 and 603, so that these users 602 and 603 can download the created RO from the copy server 640. At this point, the first user 601 does not have to forward the address of the copy server 640, but can instead receive the ROs for the second and third users, 602 and 603, from the copy server. 640 and then transmit them to the second and third users, 602 and 603, respectively.
The second or third user, 602 and 603, can either use the received RO directly or make a copy of it to the copy server 640 as the first user 601. For his part, the third user 603 can create an RO for a fourth user 604 through copy server 640 within the limits of an RO on that server.
Meanwhile, since the first user 601 has used his reproduction rights eight times out of ten available, at that time the first user 601 has rights to reproduce the encrypted content twice. After the first user 601 has played the content again, a copy of the rights to play the content twice is made on the copy server 640, while at that time the first user 601 has rights to play the content only one more time. This discrepancy can be resolved by automatically making a copy of a count of the replay counts of the first user 601 to the copy server 640 when this user 601 accesses said server 640 and a replay count discrepancy occurs.
According to preferred embodiments of the present invention, users can share their ROs with other users within the limits set in the ROs themselves without server authentication.
Furthermore, preferred embodiments of the present invention can ensure safe use of the purchased RO by using a copy server to make copies of the RO. When a memory or processor in a terminal does not have sufficient capacity to create an RO, preferred embodiments of the present invention can address this problem through the copy server.
Although only some preferred embodiments have been shown and described, those skilled in the art will appreciate that various changes and modifications can be made without deviating from the scope of the invention as defined in the appended claims.
Contents6
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
33 members in 16 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 20030057901 | Republic of Korea | A | |
| 20030057901 | Republic of Korea | A | |
| 20030057901 | Republic of Korea | – | |
| 200305790104255020 | – | – | – |
| KR20030057901 | – | – | – |
Members33
| Document | Office | Kind | |
|---|---|---|---|
| CN1585324A | China | A | |
| EP1509024A2 | European Patent Office (EPO) | A2 | |
| US2005044361A1 | United States of America | A1 | |
| TW200509657A | Taiwan Province of China | A | |
| KR20050020165A | Republic of Korea | A | |
| JP2005071339A | Japan | A | |
| SG109593A1 | Singapore | A1 | |
| KR100493900B1 | Republic of Korea | B1 | |
| EP1509024A3 | European Patent Office (EPO) | A3 | |
| HK1072667A1 | Hong Kong, China | A1 | |
| TWI244313B | Taiwan Province of China | B | |
| RU2004125545A | Russian Federation | A | |
| EP1646204A1 | European Patent Office (EPO) | A1 | |
| RU2295157C2 | Russian Federation | C2 | |
| EP1509024B1 | European Patent Office (EPO) | B1 | |
| AT357106T | Austria | T | |
| ATE357106T1 | Austria | T1 | |
| DE602004005277D1 | Germany | D1 | |
| PT1509024E | Portugal | E | |
| DK1509024T3 | Denmark | T3 | |
| DE602004005277T2 | Germany | T2 | |
| PL1509024T3 | Poland | T3 | |
| ES2282811T3This record | Spain | T3 | |
| MY136409A | Malaysia | A | |
| EP1646204B1 | European Patent Office (EPO) | B1 | |
| DE602004018143D1 | Germany | D1 | |
| US2010037051A1 | United States of America | A1 | |
| US7734917B2 | United States of America | B2 | |
| JP2011100484A | Japan | A | |
| JP4694800B2 | Japan | B2 | |
| CN1585324B | China | B | |
| US8316461B2 | United States of America | B2 | |
| JP5249314B2 | Japan | B2 |
Numbers
- Publication
- 2282811
- Publication, DOCDB
- 2282811
- Publication, EPODOC
- ES2282811T
- Application
- 4255020
- Application, DOCDB
- 04255020
- Application, EPODOC
- ES20040255020T
Titles2
- Spanish
- METODO PARA COMPARTIR OBJETOS CON DERECHOS DE USO ENTRE USUARIOS.
- English
- METHOD FOR SHARING OBJECTS WITH RIGHTS OF USE BETWEEN USERS.
Classification
- CPC, 7
- H04L63/123
- G06F17/00
- H04L63/0428
- H04L63/0442
- H04L63/10
- H04L2463/101
- G06F21/1075
- IPC, 7
- H04L29 06
- G06F17 00
- G06F21 10
- G06F21 62
- H04N7 16
- H04N21 4627
- H04N21 4788