Contents providing server, recording medium recording contents providing program, contents delivery server, recording medium recording contents delivery program
Abstract
Problem to be solved.To prevent illegal acquisition, alteration, and leakage for a cipher key for decoding contents and its delivery control information at contents delivery servers, in contents providing servers or content distribution servers used in a system managing contents delivery, when encrypted contents are distributed.
Solution.At a contents providing server, a cipher key decoding contents is encrypted and the encrypted cipher key and its distribution control information are provided to a contents delivery server. If the provided encrypted data (the encrypted cipher key and its distribution control information) are not illegal, the provided encrypted data are stored at the contents delivery server. Upon a distribution request from a client, the encrypted data is decoded and the encrypted cipher key and its distribution control information are acquired. If it is within a grant period set by the delivery control information, the cipher key is again encrypted to be delivered to the client.

Term
Term ended
Projected expiry passed 29 November 2020, 5.8 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
16 claims: 4 independent, 12 dependent
- 1[Claims] [Claim 1] A content providing server used in a content distribution management system that manages content distribution when an encrypted content is distributed to a client via a content distribution server. An encryption processing means for generating encrypted distribution control information by performing a first encryption process on the distribution control information provided to the content distribution server. A content providing server comprising the encrypted distribution control information with a credit information addition processing means for adding credit information generated by performing a second encryption process on the encrypted distribution control information. 【特許請求の範囲】 【請求項1】 暗号化したコンテンツをコンテンツ配信サーバを介してクライアントに配信する場合に、コンテンツの配信を管理するコンテンツ配信管理システムで用いるコンテンツ提供サーバであって、 前記コンテンツ配信サーバに提供する前記配信制御情報について第1の暗号化処理を施して暗号化配信制御情報を生成する暗号化処理手段と、 前記暗号化配信制御情報に、当該暗号化配信制御情報に対して第2の暗号化処理を施して生成した信用情報を付与する信用情報付加処理手段とを備えることを特徴とするコンテンツ提供サーバ。
- 5A content distribution server used in a content distribution management system that manages content distribution when an encrypted content is distributed to a client via a content distribution server. An access processing means that accesses an area that stores encrypted distribution control information including content key information that is encrypted by the content providing server and at least decrypts the encrypted content. When there is a content key distribution request from a client, a decryption processing means that decrypts the distribution control information by using an encryption key for the encryption key used in the encryption processing means of the content distribution server provided in advance. A content distribution server including a re-encryption processing means for encrypting the decrypted content key information in order to distribute the content to a client. 【請求項5】 暗号化したコンテンツをコンテンツ配信サーバを介してクライアントに配信する場合に、コンテンツの配信を管理するコンテンツ配信管理システムで用いるコンテンツ配信サーバであって、 コンテンツ提供サーバで暗号化され、少なくとも暗号化されたコンテンツを復号するためのコンテンツ鍵情報を含む暗号化配信制御情報を格納する領域にアクセスするアクセス処理手段と、 クライアントからのコンテンツ鍵の配信要求があった場合に、予め備えたコンテンツ配信サーバの暗号化処理手段で用いた暗号鍵に対する暗号鍵を用いて前記配信制御情報を復号化する復号処理手段と、 クライアントに配信するために、復号した前記コンテンツ鍵情報を暗号化する再暗号化処理手段とを備えることを特徴とするコンテンツ配信サーバ。
- 9A record of recording a program for realizing a content provision process used in a content distribution management system that manages content distribution when the encrypted content is distributed to a client via a content distribution server. It s a medium, The encryption process of performing the first encryption process on the distribution control information provided to the content distribution server to generate the encrypted distribution control information, and A credit information addition process of adding credit information generated by performing a second encryption process on the encrypted distribution control information to the encrypted distribution control information. A recording medium on which a content providing program is recorded, which is characterized by recording a program to be executed by a computer. 【請求項9】 暗号化したコンテンツをコンテンツ配信サーバを介してクライアントに配信する場合に、コンテンツの配信を管理するコンテンツ配信管理システムで用いるコンテンツ提供処理をコンピュータで実現するためのプログラムを記録した記録媒体であって、 前記コンテンツ配信サーバに提供する前記配信制御情報について第1の暗号化処理を施して暗号化配信制御情報を生成する暗号化処理と、 前記暗号化配信制御情報に、当該暗号化配信制御情報に対して第2の暗号化処理を施して生成した信用情報を付与する信用情報付加処理とを、 コンピュータに実行させるプログラムを記録したことを特徴とするコンテンツ提供プログラムを記録した記録媒体。
- 13A recording medium that records a program for realizing a content distribution process that manages content distribution by a computer when the encrypted content is distributed to a client via a content distribution server. Access processing that accesses the area that stores the encrypted distribution control information that is encrypted by the content providing server and contains at least the content key information for decrypting the encrypted content. When there is a content key distribution request from the client, the decryption process that decrypts the distribution control information using the encryption key for the encryption key used in the encryption process of the content distribution server prepared in advance, and the decryption process. A re-encryption process that encrypts the decrypted content key information in order to deliver it to the client. A recording medium that records a content distribution program, which is characterized by recording a program to be executed by a computer. 【請求項13】 暗号化したコンテンツをコンテンツ配信サーバを介してクライアントに配信する場合に、コンテンツの配信を管理するコンテンツ配信処理をコンピュータによって実現するためのプログラムを記録した記録媒体であって、 コンテンツ提供サーバで暗号化され、少なくとも暗号化されたコンテンツを復号するためのコンテンツ鍵情報を含む暗号化配信制御情報を格納する領域にアクセスするアクセス処理と、 クライアントからのコンテンツ鍵の配信要求があった場合に、予め備えたコンテンツ配信サーバの暗号化処理で用いた暗号鍵に対する暗号鍵を用いて前記配信制御情報を復号化する復号処理と、 クライアントに配信するために、復号した前記コンテンツ鍵情報を暗号化する再暗号化処理とを、 コンピュータに実行させるプログラムを記録したことを特徴とするコンテンツ配信プログラムを記録した記録媒体。
Independent claims4
131 paragraphs in 1 section, as filed
Description: TECHNICAL FIELD [Detailed description of the invention]
【0001】
[Technical field to which the invention belongs]
The present invention relates to a content providing server or a content distribution server used in a system that manages information related to the distributed content when the encrypted content is distributed to the requesting client via a network or the like. In particular, the present invention relates to a technique for managing distribution control information including information for decrypting encrypted content or information regarding a content distribution period.
【0002】
[Conventional technology]
A service for distributing content such as music from a content distribution server is provided to a client via a communication means. The client is, for example, a terminal such as a mobile phone or a personal computer.
【0003】
The content is provided to the content distribution server in advance by the content owner or the like. The content distribution server manages the content provided by the content owner or the like. When the client accesses the content distribution server, the content distribution server distributes the content to the client. The content is encrypted, at least at the time of delivery. Therefore, the content distribution server manages and distributes the encrypted content and its encryption key. Content is usually delivered for a fee. Therefore, the content distribution server charges the client by some means. Further, in order to differentiate from other content distribution servers, the content distribution server needs to provide various services associated with content distribution to the client.
【0004】
[Problems to be Solved by the Invention]
The content distribution server manages content such as music in order to distribute the content to a large number of clients. Specifically, the content is managed separately from the encrypted content itself and the management information about the content, the former is stored in the content data file, and the latter is stored in the content management file. The management information includes, for example, a content ID, a content selling price, a content selling period, an encryption key for decrypting the content, and the like. When the content distribution server is accessed by the client, the content distribution server distributes the encrypted content itself and management information including an encryption key for decrypting the encrypted content to the access source. The client obtains the encryption key and decrypts the delivered encrypted content.
【0005】
As a security measure for clients and the like, the content distribution server may encrypt and store not only the content itself but also management information including an encryption key. However, if the management information on the content distribution server is not strictly managed, there is a possibility that the management information may be illegally obtained, or the data may be falsified or leaked. Even if the content itself is encrypted, if the administrator on the content distribution server side can easily know the content of the management information including the encryption key, the security of the content distribution cannot be said to be sufficient.
【0006】
When the administrator of the content distribution server and the content owner are the same, there is no problem of falsifying or leaking the content stored in the content distribution server and its management information. However, if the administrator of the content distribution server and the owner of the content are different companies, an important problem arises. In particular, when the content is stored in the content distribution servers of multiple vendors, or when the content of another content owner or the like is stored in one content distribution server, unauthorized acquisition of management information in the content distribution server and data Tampering or leaking is a serious problem. Therefore, even in the content distribution server, it is necessary to consider security by making it possible to store management information that has been subjected to encryption processing so that the content distribution server side cannot intervene.
【0007】
Further, if the content owner or the like who is the provider can directly manage the content distribution permission period without setting or controlling it on the content distribution server, the content distribution management becomes easy and the safety is improved.
【0008】
In the present invention, the content owner or the like directly encrypts the encryption key used to encrypt the content and the management information regarding the distribution license period that controls the distribution, and distributes the information to the content distribution server, and manages these. By secretly holding the information for decrypting the information in the system by the content distribution server, the purpose is to realize a management device that enables the owner of the content and the like to directly manage the safety. According to the present invention, it is possible to prevent unauthorized acquisition, falsification and leakage of management information for content distribution.
【0009】
[Means for solving problems]
In order to solve the above problem, the content providing server according to the present invention is an encryption processing means for generating encrypted distribution control information by performing a first encryption process on the distribution control information provided to the content distribution server. The encrypted distribution control information is provided with a credit information addition processing means for adding the credit information generated by performing the second encryption process on the encrypted distribution control information.
【0010】
Further, as the distribution control information encrypted by the encryption processing means, at least the content key information for decrypting the encrypted content or the content key information for decrypting the encrypted content is related to the distribution permission period. Contains any of the information.
【0011】
Further, the credit information addition processing means uses a hashing processing means for calculating the encrypted distribution control information by using a hash function, and the encryption processing means for the value obtained by the hashing processing means. An electronic signature processing means for generating an electronic signature by performing an encryption process by a method different from the method and credit information including the encryption key information used in the electronic signature and the electronic signature processing means are added to the encrypted distribution control information. It is provided with a grant processing means for
【0012】
Further, the content distribution server according to the present invention is an access processing means that accesses an area that is encrypted by the content providing server and stores encrypted distribution control information including at least content key information for decrypting the encrypted content. When there is a distribution request for the content key from the client, the decryption processing means for decrypting the distribution control information by using the encryption key for the encryption key used in the encryption processing means of the content distribution server provided in advance. , A re-encryption processing means for encrypting the decrypted content key information for distribution to the client.
【0013】
Further, the content distribution server is in an area for storing encrypted distribution control information including the content key information for decrypting the encrypted content and the information regarding the distribution permission period of the content key information, which is encrypted by the content providing server. When there is a content key distribution request from the access processing means to access and the content distribution request from the client, the distribution control information is decrypted by using the encryption key for the encryption key used in the encryption processing means of the content distribution server provided in advance. Re-encryption that encrypts the decrypted content key information when the decryption processing means and the delivery request are within the period set in the decrypted delivery permission period information or when the number of times of permission is not exceeded. It is provided with a processing means.
【0014】
Further, the content distribution server attaches the credit information to the encrypted distribution control information encrypted by the content providing server when the credit information including at least an electronic signature is attached to the encrypted distribution control information. The electronic signature verification processing means for verifying the included electronic signature and the storage processing means for storing the encrypted distribution control information in the storage area when the electronic signature is valid are provided.
【0015】
Further, the content distribution server includes an electronic signature verification processing means for verifying the electronic signature included in the credit information given to the encrypted distribution control information, and a processing for decrypting the electronic signature when the electronic signature is valid. When the results of the comparison processing means for comparing the value obtained by the above and the value obtained by calculating the encrypted distribution control information with the hash function and the result of the comparison processing means match, the encrypted distribution control information It is provided with a storage processing means for storing the data in the storage area.
【0016】
By these means, in the present invention, not only the content itself but also the content key can be encrypted and stored in the content distribution server, and the administrator on the content distribution server side can easily know the content of the content key. Since it is eliminated, it is possible to maintain security for the content distribution server, and it is possible to prevent unauthorized acquisition, falsification, and leakage of the content key.
【0017】
Further, the distribution permission management on the content distribution server becomes unnecessary, and the simplicity and safety of the content distribution management can be improved.
【0018】
BEST MODE FOR CARRYING OUT THE INVENTION
FIG. 1 is a diagram showing a configuration example of a content management system to which the present invention is applied.
【0019】
The content distribution system includes a content provider 100, a content distribution server 200, a network 300, a client 400, and a billing server 500.
【0020】
The content distribution server 200 includes a content management server 210 as its back end and a license server 220 as its front end. The content management server 210 and the license server 220 are connected by, for example, a LAN. The content distribution server 200 does not necessarily have to be separated into such two servers, and may be configured as one server.
【0021】
The content provider 100 is the original owner of the content and provides various contents to the content distribution server 200. The content is, for example, music data, but may be data such as a still image or a moving image. In this example, the content provider 100 provides the content after being encrypted by a well-known encryption process (for example, a process by Triple DES).
【0022】
Further, in this example, the content provider 100 also provides the content encryption key after being encrypted by, for example, the same encryption process as described above. The content and the encryption key are encrypted separately. The encryption key is determined for each content, for example. If the content is music, a different encryption key is used for each song. The encrypted content and the encryption key are provided stored on a CD-ROM, MO, CDR, CDR / W, etc., or transmitted from the content provider 100 to the content distribution server 200 via the network 800. Provided by doing.
【0023】
The content management server 210 of the content distribution server 200 connects between the content provider 100 and the license server 220, and stores and manages the content provided by the content provider 100 and the encryption key in the storage area 230, respectively. In reality, prior to this storage, the content management server 210 converts the content provided by the content provider 100 and the encryption key into a predetermined format. As a result, the content and the encryption key can be used for distribution to the client 400 by the license server 220.
【0024】
Further, in this example, the content management server 210 stores and manages management information about the content provided by the content provider 100 in the storage area 230. The management information includes, for example, a content ID, a content selling price, a content selling period, and the like. The management information is created by either of the content providers 100 and the content distribution server 200 based on the contract. When created by the content provider 100, the management information is provided in a state of being stored on a CD-ROM or the like as described above, or is transmitted from the content provider 100 to the content distribution server 200 via the network 800. Provided by.
【0025】
The license server 220 of the content distribution server 200 connects between the client 400 and the content management server 210, and distributes the content stored in the content management server 210 and the encryption key to the client 400. In this example, the client 400 that receives the distribution of the content and the client 400 that receives the distribution of the encryption key may be different. When the license server 220 is accessed from the client 400, the license server 220 acquires one or both of the content and the encryption key specified in the access and its management information from the content management server 210, temporarily stores the content in the storage area 240, and stores the management information. The management information is analyzed, and the content and encryption key are distributed to the client 400 based on the analysis result. At this time, the encryption key is decrypted once, encrypted again by a different well-known encryption process (for example, ECDH key exchange process), and then distributed to the client 400.
【0026】
Further, in this example, the license server 220 performs the notification processing of the billing information regarding the distribution of the content. The billing information is notified from the license server 220 to the billing server 500. The billing server 500 is a billing server provided by the network 300 for charging communication using the billing server 500, and is connected to the license server 220 via the network 300. That is, the content or the encryption key is charged using the charging server 500 provided in the network 300. In this example, the distribution of the content is not charged, but the distribution of the encryption key is charged. That is, since the content is highly encrypted, it requires an extremely expensive device for decryption, and a normal user cannot effectively decrypt it without an encryption key. Therefore, since the content itself is not charged, the charging information is not transmitted at the time of distribution, and the encryption key is charged, so that the charging information is transmitted at the time of distribution.
【0027】
The charge for the communication for downloading the content or the encryption key is charged to the download destination client 400 by a well-known charging process. Further, since the encryption key enables the de facto use of the content and is subject to billing in this way, the encryption key is also referred to as a license in this example.
【0028】
The client 400 is a terminal having a two-way communication function such as a mobile phone, and is connected to a content distribution server 200 (license server 220) via a network 300 provided by a communication carrier contracted with the client 400 in advance. Communicate between. That is, the client 400 specifies the content, accesses the content distribution server 200, receives the distribution of the encrypted content, and receives the distribution of the encrypted encryption key (license) as needed. [Content Provider] FIG. 2 is a diagram showing a configuration example of each means of the content provider. The content provider 100 includes a content key generation unit 101, a distribution permission period setting unit 103, an encryption processing unit 105, a letter of credit creation unit 108, and a content key data creation unit 111.
【0029】
The content key generation unit 101 is a means for generating an encryption key (hereinafter, referred to as a content key 102) which is a license distributed by the license server 220 to the client 400. Figure 3 shows an example of the data structure of the content key. In this example, the content key 102 is a triple DES (2key EDE outer-CBC mode) key used when encrypting the content data, and stores the first key and the second key. When the content is encrypted by another well-known encryption method, the encryption key used in the encryption process is stored in the content key 102.
【0030】
The distribution permission period setting unit 103 is a means for setting the distribution permission period 104, which is information on the period and the number of times the license server 220 distributes the content key 102. Figure 4 shows an example of the data structure of the distribution license period 104. The distribution permission period 104 stores the issuance (distribution) start date and the issuance end date of the content key. In this example, the issue start date and issue end date are set by the date (yyyymmdd), but the date and time (yyyymmdd: hh: mm) can also be set.
【0031】
The encryption processing unit 105 is a means for encrypting the content key 102 or the distribution license period 104. FIG. 5 shows a diagram for explaining the configuration of the encrypted data 107. As shown in FIG. 5, for example, the encryption processing unit 105 encrypts the content key 102 and the distribution permission period 104 together using a predetermined distribution server public key (KPds) certificate 106, and the encrypted data 107. Is passed to the content key data creation unit 111. The encryption process may encrypt only the content key 102 or only the distribution permission period 104. The encryption process is performed using, for example, an ECDH key exchange processing method. The distribution server private key (KSds) for the distribution server public key (KPds) used for encryption processing is the library of the application that realizes the license server 220 so that it is kept secretly in the license server 220 of the content distribution server 200. Implemented as part. To identify the distribution server private key (KSds), the serial number 110, which is the information for identifying the distribution server public key (KPds) used in the encryption processing unit 105, is assigned and stored in the content key data 120, and the content distribution server is specified. Do it by passing it to 200. The encrypted data decryption unit 221 of the license server 220 identifies the distribution server private key (KSds) that decrypts the encrypted data from the serial number 110 of the content key data 120.
【0032】
The letter of credit creation unit 108 calculates the hash value of the encrypted data 107 received from the encryption processing unit 105, encrypts this hash value with the provider private key (KScp), and creates a digital signature. In addition, a Credential 109 is created that stores this digital signature and the provider public key (KPcp) certificate of the provider private key (KScp) used for encryption.
【0033】
The content key data creation unit 111 creates the content key data 120 to be distributed to the content distribution server 200. FIG. 6 shows a data configuration example of the content key data 120. The content key data 120 includes the encryption data 107 obtained from the encryption processing unit 105 and the distribution server public key (KPds) certificate used for the encryption processing, in addition to the header information 121 for identifying the content key data 120. Stores the serial number 110 that identifies 106 and the credit card 109 obtained from the credit card creation unit 108. The created content key data 120 is provided by being transmitted via the network 800, or is provided in a state of being stored in various recording media such as a CD-ROM, MO, and CDR / W.
【0034】
FIG. 7 shows a processing flowchart of the content provider. In the content provider 100, the content key 102 is generated by the content key generation unit 101 (step S1), and the distribution permission period 104 of the content key 102 is set by the distribution permission period setting unit 103 (step S2). Next, the encryption processing unit 105 encrypts the content key 102 and the distribution permission period 104 using the distribution server public key (KPds) (step S3), and the credit card creation unit 108 hashes the encrypted data 107. (Step S4), a digital signature is generated from the hash value obtained in the process of step S4 using the provider private key (KScp) (step S5), and a credit certificate 109 is further created (step S6). Next, the content key data creation unit 111 creates the content key data 120 from the serial number 110, the encrypted data 107, and the letter of credit 109 (step S7). [Content distribution server] FIG. 8 is a diagram showing a configuration example of each means of the content distribution server. The content distribution server 200 includes a content content management server 210 and a license server 220.
【0035】
The content management server 210 is a server that stores and manages the encrypted data 107 of the content key data 120 provided by the content provider 100 in the storage area 230 (FIG. 1), and is a credit certificate verification unit 211 and an electronic signature decryption unit 212. , Encrypted hash processing unit 213, hash value comparison unit 214, and encrypted data storage unit 215.
【0036】
The letter of credit verification unit 211 uses the root public key (KP) to verify the validity of the provider public key (KPcp) certificate stored in the letter of credit 109 of the received content key data 120, and the source is valid. If so, get the provider public key (KPcp).
【0037】
The electronic signature decryption unit 212 decrypts the electronic signature stored in the letter of credit 109 using the provider public key (KPcp) obtained by the letter of credit verification unit 211 to obtain a hash value.
【0038】
The encrypted data hash processing unit 213 calculates the hash value of the encrypted data 107 of the content key data 120.
【0039】
The hash value comparison unit 214 compares the hash value obtained by the electronic signature decoding unit 212 with the hash value obtained by the encrypted data hash processing unit 213. If both hash values match as a result of the comparison, the contents are valid and the encrypted data storage unit 215 is notified.
【0040】
Upon receiving the matching notification from the hash value comparison unit 214, the encrypted data storage unit 215 stores the serial number 110 and the encrypted data 107 stored in the content key data 120 in the storage area 230.
【0041】
FIG. 9 shows a processing flowchart of the content management server.
【0042】
In the content management server 210, the credit certificate verification unit 211 verifies the provider public key (KPcp) certificate in the content key data 120 using the root public key (KP) (step S11), and the certificate is invalid. If so (step S12), perform error handling (step S13), and if the certificate is not invalid (step S12), get the provider public key (KPcp) from the provider public key (KPcp) certificate (step S14). ..
【0043】
Next, the electronic signature decryption unit 212 decrypts the electronic signature in the content key data 120 with the provider public key (KPcp) to obtain the hash value (step S15), and the encrypted data hash processing unit 213 decrypts the content key data 120. The encrypted data 107 in the data 107 is hashed (step S16), and the hash values obtained in the processes of step S15 and step S16 are compared (step S17). If the hash values do not match (step S18), error processing is performed (step S19), and if the hash values do not match (step S18), the encrypted data 107 in the content key data 120 and the serial number 110 are stored in the storage area. Store at 230 (step S20).
【0044】
The license server 220 shown in FIG. 8 is a server that distributes the content key stored in the content management server 210 to the client 400 when a license issuance request is received from the client 400 (FIG. 1). It includes a license control unit 222 and a content key encryption processing unit 223. When the encrypted data decryption unit 221 receives a license issuance request, that is, a content key download request from the client 400 via the network 300 (Fig. 1), the encrypted data decryption unit 221 is a content management server based on the content ID of the requested content. The corresponding serial number 110 and encrypted data 107 are extracted from the storage area 230 of 210 and stored in the storage area 240 (Fig. 1) of the license server. Further, the encrypted data decryption unit 221 identifies using a library having a distribution server private key (KSds) corresponding to the stored serial number 110 in advance. The encrypted data 107 is decrypted using the specified distribution server private key (KSds) to obtain the content key 102 and the distribution permission period 104.
【0045】
The distribution permission control unit 222 makes a download request from the client 400 within the distribution permission period of the content key 102 based on the license issuance start date and the issuance end date of the distribution permission period 104 obtained from the encrypted data decryption unit 221. Determine if there is. Notify the client 400 that the download of the content key 102 is refused unless the download request date of the client 400 is within the period from the license issuance start date to the end date. On the other hand, if the download request date is within the period from the license issuance start date to the end date, the content key encryption processing unit 223 is notified of the content key distribution permission.
【0046】
When the distribution permission control unit 222 notifies the distribution permission, the content key encryption processing unit 223 encrypts the content key 102 obtained from the encrypted data decryption unit 221. As the encryption processing method, for example, an elliptic curve encryption method is used. The encrypted content key 102 is distributed to the requesting client 400 via the network 300.
【0047】
FIG. 10 shows a processing flowchart of the license server.
【0048】
When the license server 220 receives the content key download request from the client 400 (step S21), the encrypted data decryption unit 221 acquires the corresponding encrypted data 107 and serial number 110 from the content ID of the requested content. Then (step S22), the encrypted data 107 is decrypted using the distribution server private key (KSds) corresponding to the serial number 110 (step S23). Next, the distribution permission control unit 222 confirms the distribution permission period 104 obtained by decryption (step S24), and if it is outside the distribution permission period (step S25), performs error processing (step S26) and performs the distribution permission period. If it is not outside (step S25), the content key 102 obtained by decryption is separately encrypted (step S27), and the encrypted content key 102 is delivered to the requesting client 400 (step S28). When the content key 102 is distributed, the distribution notification is sent to perform the charging process on the charging server 500.
【0049】
Although the present invention has been described above according to the embodiment thereof, the present invention can be modified in various ways within the scope of the gist thereof. Further, the content provider 100, the content management server 210, and the license server 220 that realize the present invention can be implemented as programs that can be executed by a computer, and these programs are a portable medium memory that can be read by a computer. , Can be stored and provided in an appropriate storage medium such as a semiconductor memory or a hard disk, or can be transmitted and received via a communication interface. As a communication network connected as a communication interface, for example, LAN, WAN, Internet, analog telephone network, digital telephone network, wireless communication network and the like can be used.
【0050】
[Effect of the invention]
As described above, according to the present invention, the content key for decrypting the content is encrypted on the content provider side and distributed to the content distribution server together with the identification information of the encryption key. Further, in the content distribution server, the encryption key for storing the encrypted content key and decrypting the encrypted content key is implemented so as to be kept secretly in the content distribution server. As a result, not only the content itself but also the content key can be encrypted and stored in the content distribution server, and the administrator on the content distribution server side cannot easily know the content of the content key. Therefore, the content distribution server It is possible to maintain security against the content key, and prevent unauthorized acquisition, falsification, and leakage of the content key.
【0051】
Further, according to the present invention, the content distribution permission period can be directly managed by the content owner or the like, which is the provider, without processing the content distribution server. This eliminates the need for distribution permission management on the content distribution server, and can improve the simplicity and safety of content distribution management.
[Simple explanation of drawings]
[Figure 1]
It is a figure which shows the configuration example of the content distribution system which realizes this invention.
[Figure 2]
It is a figure which shows the configuration example of the content provider.
[Fig. 3]
It is a figure which shows the data structure example of a content key.
[Fig. 4]
It is a figure which shows the data structure example of the distribution permission period.
[Fig. 5]
It is a figure which shows the data structure example of the content key data.
[Fig. 6]
It is a figure which shows the data structure example of the encrypted data.
[Fig. 7]
It is a processing flowchart of a content provider.
[Fig. 8]
It is a figure which shows the configuration example of the content management server and the license server which constitute a content distribution server.
[Fig. 9]
It is a processing flowchart of a content management server.
[Fig. 10]
It is a processing flowchart of a license server.
[Explanation of symbols]
100 content providers 101 Content key generator 102 Content key 103 Distribution permission period setting section 104 Delivery license period 105 Encryption processing unit 106 Distribution Server Public Key (KPds) Certificate 107 Encrypted data 108 Letter of Credit Creation Department 109 letter of credit 110 serial number 111 Content key data creation department 120 content key data 200 Content distribution server 210 Content management server 211 Letter of Credit Verification Department 212 Digital signature decryption unit 213 Encrypted data hash processing unit 214 Hash value comparison part 215 Encrypted data storage 220 license server 221 Encrypted data decryption unit 222 Distribution permission control unit 223 Content key encryption processing unit 230 Content management server storage space 240 License server storage 300 networks 400 clients 500 billing server 800 networks
3 sheets
Sheet 1 Sheet 2 Sheet 3
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2009530917A | Cited by | Japan | Examiner |
| US9087061B2 | Cited by | United States of America | Applicant |
| JP2005242972A | Cited by | Japan | Search report |
| US11711552B2 | Cited by | United States of America | Applicant |
| US10893305B2 | Cited by | United States of America | Applicant |
| US11457054B2 | Cited by | United States of America | Applicant |
| US11785066B2 | Cited by | United States of America | Applicant |
| US11683542B2 | Cited by | United States of America | Applicant |
| US10341698B2 | Cited by | United States of America | Applicant |
| US10368096B2 | Cited by | United States of America | Applicant |
| US11102553B2 | Cited by | United States of America | Applicant |
| JP2006270344A | Cited by | Japan | Search report |
| US8689254B2 | Cited by | United States of America | Applicant |
| US11638033B2 | Cited by | United States of America | Applicant |
| US8291320B2 | Cited by | United States of America | Applicant |
| US10856020B2 | Cited by | United States of America | Applicant |
| US7797242B2 | Cited by | United States of America | Applicant |
| US10437896B2 | Cited by | United States of America | Applicant |
| US10805368B2 | Cited by | United States of America | Applicant |
| US11438394B2 | Cited by | United States of America | Applicant |
| US10382785B2 | Cited by | United States of America | Applicant |
| US10484749B2 | Cited by | United States of America | Applicant |
| US11886545B2 | Cited by | United States of America | Applicant |
| US10212486B2 | Cited by | United States of America | Applicant |
| US10225588B2 | Cited by | United States of America | Applicant |
| USRE48761E | Cited by | United States of America | Applicant |
| US10715806B2 | Cited by | United States of America | Applicant |
| JP2006524875A | Cited by | Japan | Examiner |
| US10462537B2 | Cited by | United States of America | Applicant |
| US10687095B2 | Cited by | United States of America | Applicant |
| US10244272B2 | Cited by | United States of America | Applicant |
| US7853893B2 | Cited by | United States of America | Applicant |
| US11178435B2 | Cited by | United States of America | Applicant |
| US10878065B2 | Cited by | United States of America | Applicant |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2000362251 | Japan | A | |
| JP20000362251 | – | – | – |
3 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Decision of refusalA02 | A02 | |
| Notification of reasons for refusalA131 | A131 | |
| Written request for application examinationA621 | A621 |
Numbers
- Publication
- 2002-164880
- Publication, DOCDB
- 2002164880
- Publication, EPODOC
- JP2002164880
- Application
- 362251
- Application, DOCDB
- 2000362251
- Application, EPODOC
- JP20000362251
Titles2
- Japanese
- 【発明の名称】コンテンツ提供サーバ、コンテンツ提供プログラムを記録した記録媒体、コンテンツ配信サーバ、およびコンテンツ配信プログラムを記録した記録媒体
- English
- Description: A content providing server, a recording medium on which a content providing program is recorded, a content distribution server, and a recording medium on which a content distribution program is recorded.
Classification
- IPC, 10
- G06F12 14
- G06F12 00
- G06F21 10
- G06F21 60
- G06F21 62
- G06F21 64
- G10K15 02
- G10L19 00
- G10L25 51
- H04L9 08