Data terminal equipment and device
Abstract
Problem to be solved.To provide a data terminal equipment capable of moving enciphered contents data and a license received by software or hardware to another data terminal equipment in the same way.
Solution.A hard disk 530 of a personal computer is provided with license management files 1521-152n. A license managing device 520 stores a binding license for managing a license obtained by software and a license obtained by hardware corresponding to entry numbers included in the license management files 1521-152n of the hard disk 530 in a license area 5215B of a memory. The license management files 1521-152n include security information obtained by enciphering the license obtained by the software by the binding key included in the binding license.
Term
Term ended
Projected expiry passed 26 March 2021, 5.5 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
22 claims: 5 independent, 17 dependent
- 1[Claims] 1. A data terminal device for obtaining an encrypted content data obtained by encrypting the content data and a license for decrypting the encrypted content data to obtain the original plaintext. A module unit that acquires the encrypted content data and the license by software and generates an encryption license in which the acquired license is encrypted by a binding key and a binding license including the binding key. A device unit that performs an exchange for acquiring the encrypted content data and the license, and stores the license acquired by the exchange, the binding license, and the first and second management files. A storage unit that stores data and A control unit that controls communication between the device unit and the outside is provided. The storage unit contains a plurality of encrypted content data. When acquiring the encrypted content data, The control unit gives the encrypted content data acquired from the outside to the storage unit, generates the first management file, and gives the license and the generated first management file to the device unit. The module unit is a data terminal device that generates the second management file including the encryption license, and gives the binding license and the generated second management file to the device unit. 【特許請求の範囲】 【請求項1】 コンテンツデータを暗号化した暗号化コンテンツデータおよび前記暗号化コンテンツデータを復号して元の平文を得るためのライセンスを取得するデータ端末装置であって、 ソフトウエアによって前記暗号化コンテンツデータおよび前記ライセンスを取得し、その取得したライセンスをバインディング鍵によって暗号化した暗号化ライセンスと前記バインディング鍵を含むバインディングライセンスとを生成するモジュール部と、 前記暗号化コンテンツデータおよび前記ライセンスを取得するためのやり取りを行なうとともに、前記やり取りによって取得したライセンスと前記バインディングライセンスと第1および第2の管理ファイルとを格納するデバイス部と、 データを記憶する記憶部と、 前記デバイス部と外部との間のやり取りを制御する制御部とを備え、 前記記憶部は、複数の暗号化コンテンツデータを含み、 前記暗号化コンテンツデータの取得時、 前記制御部は、外部から取得した暗号化コンテンツデータを前記記憶部に与え、前記第1の管理ファイルを生成し、前記ライセンスと前記生成した第1の管理ファイルとを前記デバイス部に与え、 前記モジュール部は、前記暗号化ライセンスを含む前記第2の管理ファイルを生成し、前記バインディングライセンスと前記生成した第2の管理ファイルとを前記デバイス部に与える、データ端末装置。
- 8An encrypted content data obtained by encrypting the content data and a license for decrypting the encrypted content data to obtain the original plain text are obtained, and the obtained encrypted content data and the license are used as other data. A data terminal device that moves to a terminal device A module unit that acquires the encrypted content data and the license by software and generates an encryption license in which the acquired license is encrypted by a binding key and a binding license including the binding key. A device unit that performs an exchange for acquiring the encrypted content data and the license, and stores the license acquired by the exchange, the binding license, and the first and second management files. A storage unit that stores data and A control unit that controls communication between the device unit and the outside is provided. The storage unit contains a plurality of encrypted content data. When acquiring the encrypted content data, The control unit gives the encrypted content data acquired from the outside to the storage unit, generates the first management file, and gives the license and the generated first management file to the device unit. The module unit generates the second management file including the encryption license, and gives the binding license and the generated second management file to the device unit. When moving the encrypted content data, The control unit reads the license of the encrypted content data to be moved and the first management file from the device unit, reads the encrypted content data to be moved from the storage unit, and reads the read license and the first management. The file and the encrypted content data are transmitted to the other data terminal device, and the file and the encrypted content data are transmitted to the other data terminal device. The module unit reads the binding license including the binding key that encrypts the license of the transferred encrypted content data and the second management file from the device unit, and reads the transferred encrypted content data from the storage unit. , The data terminal device that transmits the read binding license, the second management file, and the encrypted content data to the other data terminal device. 【請求項8】 コンテンツデータを暗号化した暗号化コンテンツデータおよび前記暗号化コンテンツデータを復号して元の平文を得るためのライセンスを取得し、その取得した暗号化コンテンツデータおよびライセンスを他のデータ端末装置へ移動するデータ端末装置であって、 ソフトウエアによって前記暗号化コンテンツデータおよび前記ライセンスを取得し、その取得したライセンスをバインディング鍵によって暗号化した暗号化ライセンスと前記バインディング鍵を含むバインディングライセンスとを生成するモジュール部と、 前記暗号化コンテンツデータおよび前記ライセンスを取得するためのやり取りを行なうとともに、前記やり取りによって取得したライセンスと前記バインディングライセンスと第1および第2の管理ファイルとを格納するデバイス部と、 データを記憶する記憶部と、 前記デバイス部と外部との間のやり取りを制御する制御部とを備え、 前記記憶部は、複数の暗号化コンテンツデータを含み、 前記暗号化コンテンツデータの取得時、 前記制御部は、外部から取得した暗号化コンテンツデータを前記記憶部に与え、前記第1の管理ファイルを生成し、前記ライセンスと前記生成した第1の管理ファイルとを前記デバイス部に与え、 前記モジュール部は、前記暗号化ライセンスを含む前記第2の管理ファイルを生成し、前記バインディングライセンスと前記生成した第2の管理ファイルとを前記デバイス部に与え、 前記暗号化コンテンツデータの移動時、 前記制御部は、移動する暗号化コンテンツデータのライセンスおよび前記第1の管理ファイルを前記デバイス部から読出し、前記移動する暗号化コンテンツデータを前記記憶部から読出し、前記読出したライセンス、第1の管理ファイル、および暗号化コンテンツデータを前記他のデータ端末装置へ送信し、 前記モジュール部は、移動する暗号化コンテンツデータのライセンスを暗号化したバインディング鍵を含むバインディングライセンスおよび前記第2の管理ファイルを前記デバイス部から読出し、前記移動する暗号化コンテンツデータを前記記憶部から読出し、前記読出したバインディングライセンス、第2の管理ファイル、および暗号化コンテンツデータを前記他のデータ端末装置へ送信する、データ端末装置。
- 11When the encrypted content data is moved, The device unit outputs the license or the binding license based on the authentication data from another device unit built in the other data terminal device, according to claims 8 to 10. The data terminal device according to any one item. 【請求項11】 前記暗号化コンテンツデータの移動時、 前記デバイス部は、前記他のデータ端末装置に内蔵されたもう1つのデバイス部からの認証データを認証したことに基づいて、前記ライセンスまたは前記バインディングライセンスを出力する、請求項8から請求項10のいずれか1項に記載のデータ端末装置。
- 17A device used for an encrypted content data obtained by encrypting the content data and a data terminal device for obtaining a license for decrypting the encrypted content data to obtain the original plaintext. Input / output terminals for exchanging data with other parts of the data terminal device, An interface for exchanging information with the input / output terminals A recording unit that records data and Equipped with a control unit When acquiring the encrypted content data, The control unit writes the license acquired by itself communicating with the outside through the interface and the input / output terminal to the recording unit, and writes the binding license input through the input / output terminal and the interface. Write to the recording unit, The binding license is a device that includes a binding key for encrypting a license acquired by software. 【請求項17】 コンテンツデータを暗号化した暗号化コンテンツデータおよび前記暗号化コンテンツデータを復号して元の平文を得るためのライセンスを取得するデータ端末装置に用いられるデバイスであって、 前記データ端末装置の他の部分とデータのやり取りを行なうための入出力端子と、 前記入出力端子との間のやり取りを行なうインタフェースと、 データを記録する記録部と、 制御部とを備え、 前記暗号化コンテンツデータの取得時、 前記制御部は、自己が前記インタフェースおよび前記入出力端子を介して外部とやり取りを行なうことによって取得したライセンスを前記記録部に書込み、前記入出力端子および前記インタフェースを介して入力されたバインディングライセンスを前記記録部に書込み、 前記バインディングライセンスは、ソフトウェアによって取得されたライセンスを暗号化するためのバインディング鍵を含むライセンスである、デバイス。
Independent claims5
960 paragraphs in 1 section, as filed
Description: TECHNICAL FIELD [Detailed description of the invention]
【0001】
[Technical field to which the invention belongs]
The present invention relates to data terminal equipment and devices used in data distribution systems that enable copyright protection for copied information.
【0002】
[Conventional technology]
In recent years, with the progress of information communication networks such as the Internet, it has become possible for each user to easily access information on the network by using a personal terminal using a mobile phone or the like.
【0003】
In such an information communication network, information is transmitted by digital signals. Therefore, for example, even when each individual user copies music or video data transmitted in the above-mentioned information communication network, the data is duplicated without causing deterioration in sound quality and image quality due to such duplication. It is possible.
【0004】
Therefore, when content data created by the author, such as music data and image data, is transmitted on such an information and communication network, the work is remarkably written unless appropriate measures for copyright protection are taken. There is a risk that the rights of the right holder will be infringed.
【0005】
On the other hand, if the purpose of copyright protection is given top priority and content data cannot be distributed via the rapidly expanding information and communication network, basically, a fixed copyright fee is charged when copying content data. It is also disadvantageous for the copyright holder who can collect the data.
【0006】
Here, if we consider a recording medium that records digital data as an example instead of distribution via the information and communication network as described above, a CD (compact disc) that records music data that is normally sold is not available. In principle, copying of music data from a CD to a magneto-optical disk (MD, etc.) can be freely performed as long as the copied music is used only for personal use. However, an individual user who performs digital recording or the like is supposed to indirectly pay a certain amount of the price of the digital recording device itself or a medium such as an MD to the copyright holder as a deposit.
【0007】
Moreover, when music data that is a digital signal is duplicated from a CD to an MD, the music information is converted into digital data from a recordable MD to another MD in view of the fact that these information are digital data with almost no reproduction deterioration. Reproduction is not possible due to the configuration of the device due to copyright protection.
【0008】
Under these circumstances, distributing music data and image data to the public through an information and communication network is itself an act restricted by the copyright holder's public transmission right, so it is sufficient for copyright protection. Measures need to be taken.
【0009】
In this case, regarding the content data such as music data and image data transmitted to the public through the information communication network, it is necessary to prevent the content data once received from being further duplicated and used without permission.
【0010】
Therefore, a data distribution system in which a distribution server that holds encrypted content data in which the content data is encrypted distributes the encrypted content data to a memory card mounted on a terminal device such as a mobile phone via the terminal device. Proposed. In this data distribution system, the public encryption key of the memory card and its certificate, which have been authenticated by the certificate authority in advance, are sent to the distribution server when requesting the distribution of encrypted content data, and the distribution server authenticates the certificate. After confirming that it has been received, the encrypted content data and the license key for decrypting the encrypted content data are sent to the memory card. Then, when distributing the encrypted content data and the license key, the distribution server and the memory card generate a different session key for each distribution, and the public encryption key is encrypted by the generated session key, and the distribution server, Exchange keys between memory cards.
【0011】
Finally, the distribution server transmits the license encrypted by the unique public encryption key assigned to each memory card and further encrypted by the session key, and the encrypted content data to the memory card. Then, the memory card records the received license key and encrypted content data on the memory card.
【0012】
Then, when the encrypted content data recorded on the memory card is reproduced, the memory card is attached to a mobile phone or a reproduction terminal provided with a dedicated reproduction circuit.
【0013】
In this way, the user of the mobile phone can receive the encrypted content data from the distribution server using the mobile phone and reproduce the encrypted content data.
【0014】
On the other hand, encrypted content data is also distributed to personal computers using the Internet. Then, in the distribution of the encrypted content data to the personal computer, the encrypted content data is distributed by the software installed in the personal computer, and the received encrypted content data and the license are distributed to another personal computer. Moving is a device that a personal computer can easily make a copy of, and is not implemented from the perspective of copyright protection because it is difficult to protect.
【0015】
In other words, assuming that the encrypted content data and license delivered to the personal computer can be moved to another personal computer, the encrypted content data and license are backed up and the encrypted content data and license are moved to the other personal computer. After that, if you return the backed encrypted content data and license to your personal computer, it is the same as duplicating the encrypted content data and license. Therefore, moving the encrypted content data and license delivered to the personal computer by the software to another personal computer provides duplication, and the movement of the encrypted content data and license is prohibited from the viewpoint of copyright protection. Has been done.
【0016】
In addition, if the encrypted content data and license are distributed via the Internet to a personal computer with a built-in device having the same configuration as the memory card, the license is stored in the device, and the encrypted content data is stored in the hard disk, the encryption is performed from the distribution server. It is the same as delivering the encrypted content data and license to the memory card. In this case, the license is stored in hardware called a device, and the problem does not occur as in the case where the license is managed by software, so that the license can be transferred to another personal computer.
【0017】
[Problems to be Solved by the Invention]
However, although the personal computer can receive the encrypted content data and the license by the software and the hardware, the problem arises that the license cannot be transferred to another personal computer only when the license is received by the software. ..
【0018】
Therefore, the present invention has been made to solve such a problem, and an object of the present invention is to transfer encrypted content data and a license received by software or hardware to another data terminal device in the same manner. It is to provide various data terminal devices and devices.
【0019】
[Means for Solving Problems and Effects of Invention]
The data terminal device according to the present invention is a data terminal device that obtains a license for decrypting encrypted content data and encrypted content data to obtain the original plain text, and is encrypted by software. The module part that acquires the content data and license and generates the encryption license that encrypts the acquired license with the binding key and the binding license that includes the binding key, and the exchange for acquiring the encrypted content data and license. A device unit that stores the license, binding license, and first and second management files acquired by the exchange, a storage unit that stores data, and a control unit that controls the exchange between the device unit and the outside. The storage unit includes a plurality of encrypted content data, and when the encrypted content data is acquired, the control unit gives the encrypted content data acquired from the outside to the storage unit and generates the first management file. Then, the license and the generated first management file are given to the device part, the module part generates the second management file including the encryption license, and the binding license and the generated second management file are given to the device part. Give to.
【0020】
In the data terminal device according to the present invention, the license of the encrypted content data acquired by the device unit is stored in the device unit, and the license of the encrypted content data acquired by the module unit is encrypted by the binding key and encrypted. It is stored in the second license management file recorded in the device section as a license. Then, the encrypted content data acquired by the device unit or the module unit is stored in the storage unit. The device unit also stores the binding key that encrypts the license of the encrypted content data acquired by the module unit. Then, unless the encryption license is decrypted by the binding key, the license of the encrypted content data acquired by the module unit cannot be taken out. That is, the license of the encrypted content data acquired by the software is managed by the binding license including the binding key. Then, the binding license and the license of the encrypted content data acquired by the device unit are stored in the hardware called the device unit.
【0021】
Therefore, according to the present invention, the license of the encrypted content data acquired by the software and the license of the encrypted content data acquired by the hardware can be managed at the same security level. As a result, the license of the encrypted content data acquired by the software can be transferred to another data terminal device in the same manner as the license of the encrypted content data acquired by the hardware.
【0022】
Preferably, the device unit of the data terminal device records a first recording unit that records licenses and binding licenses in association with the first and second management numbers, respectively, and a plurality of first or second management files. Includes a second recording section.
【0023】
The device section records the license acquired by the device section in the first recording section in association with the first control number, and the binding license that manages the license acquired by the module section corresponds to the second control number. Attach and record in the first recording section. In addition, the device part has a first management file containing the first management number and a second management file containing the encryption license encrypted by the binding key included in the binding license and the second management number. Record in the second recording section.
【0024】
Therefore, according to the present invention, a license or a binding license can be obtained based on the control number.
【0025】
Preferably, the control unit of the data terminal device generates a first control number and gives it to the device unit when the device unit acquires a license, and the module unit generates a second control number when the device unit acquires a license. Give to the club.
【0026】
When a license is obtained, a first or second control number for managing it is entered in the device section, and the device section licenses or binds to the specified area by the entered first or second control number. Store the license.
【0027】
Therefore, according to the present invention, the license can be input / output based on the control number.
【0028】
Preferably, the module part of the data terminal device acquires the encrypted content data and the license from the distribution server.
【0029】
The module part communicates with the distribution server according to the software and acquires the encrypted content data and the license.
【0030】
Therefore, according to the present invention, the license of the encrypted content data acquired by the software via the communication means such as the Internet can be managed by the hardware.
【0031】
Preferably, the data terminal device further includes a medium drive unit that reads the content data from the recording medium, and when the encrypted content data is acquired, the module unit encrypts the content data read by the medium drive unit. Obtain content data and licenses.
【0032】
The module part acquires encrypted content data and license by ripping.
【0033】
Therefore, according to the present invention, the license of the encrypted content data acquired by the software from the recording medium on which the content data is recorded can be managed by the hardware.
【0034】
Preferably, the device unit of the data terminal device communicates with the distribution server that holds the encrypted content data and the license.
【0035】
The device unit communicates with the distribution server using, for example, a communication means such as the Internet, and acquires encrypted content data and a license.
【0036】
Therefore, according to the present invention, the license of the encrypted content data can be acquired and managed by hardware via a communication means such as the Internet.
【0037】
Preferably, the binding key is a license key required to decrypt the encrypted content data.
【0038】
The software generates an encrypted license encrypted with the license key received from the distribution server. Then, the generated encryption license is stored in the device unit.
【0039】
Therefore, according to the present invention, when the encrypted content data and the license are acquired by software, the license for decrypting the encrypted content data can be easily managed by the binding license.
【0040】
Further, in the data terminal device according to the present invention, an encrypted content data obtained by encrypting the content data and a license for decrypting the encrypted content data to obtain the original plain text are obtained, and the acquired encrypted content data and the encrypted content data A data terminal device that transfers a license to another data terminal device, in which encrypted content data and a license are acquired by software, and the acquired license is encrypted with a binding key. Binding including an encryption license and a binding key. A module part that generates a license, an exchange for acquiring encrypted content data and a license, and a device part that stores the license acquired by the exchange, a binding license, and the first and second management files. It includes a storage unit that stores data and a control unit that controls the exchange between the device unit and the outside. The storage unit includes a plurality of encrypted content data, and when the encrypted content data is acquired, the control unit , The encrypted content data acquired from the outside is given to the storage part, the first management file is generated, the license and the generated first management file are given to the device part, and the module part is the first including the encryption license. The second management file is generated, the binding license and the generated second management file are given to the device part, and when the encrypted content data is moved, the control part licenses the moved encrypted content data and the first management. Read and move files from the device section Read and move encrypted content data from the storage section Send the read license, first management file, and encrypted content data to other data terminal devices, and the module section moves. The binding license containing the binding key that encrypted the license of the encrypted content data and the second management file are read from the device section, and the encrypted content data to be moved is read from the storage section, the read binding license, and the second management file. , And encrypted content dataSend data to other data terminal equipment.
【0041】
In the data terminal device according to the present invention, the license of the encrypted content data acquired by the device unit is stored in the device unit, and the license of the encrypted content data acquired by the module unit is encrypted by the binding key and encrypted. It is stored in the second license management file stored in the storage as a license. Then, the encrypted content data acquired by the device unit or the module unit is stored in the storage unit. The device unit also stores the binding key that encrypts the license of the encrypted content data acquired by the module unit. Then, unless the encryption license is decrypted by the binding key, the license of the encrypted content data acquired by the module unit cannot be taken out. That is, the license of the encrypted content data acquired by the software is managed by the binding license including the binding key. Then, the binding license and the license of the encrypted content data acquired by the device unit are stored in the hardware called the device unit.
【0042】
Also, when the encrypted content data acquired by the module section is moved, the binding license, license, and encrypted content data are moved to another data terminal device, and when the encrypted content data acquired by the device section is moved, The license and encrypted content data are moved to another data terminal device.
【0043】
Therefore, according to the present invention, the license of the encrypted content data acquired by the software and the license of the encrypted content data acquired by the hardware can be transferred to another data terminal device in the same manner.
【0044】
Preferably, when the encrypted content data is moved, the control unit of the data terminal device acquires the first control number stored in the first license management file, and transfers the read first control number to the device unit. The license is read from the device section by inputting, the module section acquires the second control number stored in the second license management file, and inputs the read second control number to the device section. Read the binding license from the device section.
【0045】
The control unit or module unit acquires a license or a binding license, respectively, based on the management number stored in the license management file.
【0046】
Therefore, according to the present invention, a license or a binding license can be accurately obtained via a control number.
【0047】
Preferably, the data terminal device further includes a reception unit that receives an instruction, and when the encrypted content data is moved, the control unit receives the movement request of the encrypted content data from the reception unit. The first content file that stores the name of the content data is specified, and the first management number is obtained by reading the first license management file corresponding to the specified first content file, and the module part obtains the first management number. , In response to the movement request of the encrypted content data from the reception unit, the second content file that stores the name of the encrypted content data requested to be moved is specified, and the second content file corresponding to the specified second content file is specified. Obtain the second management number by reading the license management file of 2.
【0048】
The control unit or module unit acquires a management number in which the license or binding license of the encrypted content data to be moved is stored from the license management file corresponding to the content file in which the name of the encrypted content data to be moved is stored.
【0049】
Therefore, according to the present invention, once the encrypted content data to be moved is determined, a license or a binding license can be easily obtained.
【0050】
Preferably, when the encrypted content data is moved, the device unit of the data terminal device is licensed or bound based on authenticating the authentication data from another device unit built into the other data terminal equipment. Is output.
【0051】
The device unit outputs the license or binding license to a legitimate destination.
【0052】
Therefore, according to the present invention, it is possible to prevent unauthorized transfer of a license or binding license.
【0053】
Preferably, when the encrypted content data is moved, the device unit of the data terminal device receives the public encryption key held in the other device unit, and the license or binding license is encrypted and output by the received public encryption key. To do.
【0054】
The license or binding license stored in the device unit is encrypted by the public encryption key held by the destination device unit and output from the device unit.
【0055】
Therefore, according to the present invention, the license or binding license can be transferred while being protected by encryption.
【0056】
Preferably, when the encrypted content data is moved, the control unit of the data terminal device transmits the license or binding license stored in the device unit to another device unit.
【0057】
The license of the encrypted content data and the binding license are transmitted from the device part of the movement source to the device part of the movement destination.
【0058】
Therefore, according to the present invention, the license of the encrypted content data and the binding license can be held by the hardware even at the destination.
【0059】
Preferably, when the encrypted content data is moved, the device unit of the data terminal device deletes the moved license when duplication of the license is prohibited.
【0060】
When license duplication is prohibited, the source license is deleted. Therefore, according to the present invention, unauthorized duplication of the license can be prevented.
【0061】
Preferably, when the encrypted content data is moved, the module part of the data terminal device receives the encrypted license and the second license from the second license management file in which the moved license is stored when the copying of the license is prohibited. Delete the control number Output a deletion request to the device section.
【0062】
When license duplication is prohibited, the source license is deleted. Therefore, according to the present invention, unauthorized duplication of the license can be prevented.
【0063】
Preferably, the binding key is a license key required to decrypt the encrypted content data.
【0064】
The software generates an encrypted license encrypted with the license key received from the distribution server. Then, the generated encryption license is stored in the device unit.
【0065】
Therefore, according to the present invention, when the encrypted content data and the license are acquired by software, the license for decrypting the encrypted content data can be easily managed by the binding license.
【0066】
Further, the device according to the present invention is a device used for an encrypted content data obtained by encrypting the content data and a data terminal device for obtaining a license for decrypting the encrypted content data to obtain the original plain text, and the data. Encrypted content data provided with an input / output terminal for exchanging data with other parts of the terminal device, an interface for exchanging data between the input / output terminals, a recording unit for recording data, and a control unit. At the time of acquisition, the control unit writes the license acquired by itself communicating with the outside via the interface and the input / output terminal to the recording unit, and records the binding license input via the input / output terminal and the interface. A binding license that is written to is a license that includes a binding key for encrypting the license obtained by the software.
【0067】
The device according to the present invention writes the license acquired by itself and the input binding license to the recording unit and collectively manages them.
【0068】
Therefore, according to the present invention, the license acquired by hardware and the binding license for managing the license acquired by software can be managed at the same security level.
【0069】
Preferably, the device control unit further receives a first control number for managing licenses or a second control number for managing binding licenses through the I / O terminals and interfaces. A 1st or 2nd control number is given to the recording unit, and the recording unit manages the license and the binding license in association with the 1st and 2nd control numbers, respectively.
【0070】
Licenses and binding licenses are managed, respectively, corresponding to the first and second control numbers.
【0071】
Therefore, according to the present invention, a license or a binding license can be input / output using a control number.
【0072】
Preferably, the control unit of the device has an input / output terminal of a first management file containing the first management number or a second management file containing the second management number and an encryption license encrypted by the binding key. And when input via the interface, it also gives the recording unit a first or second management file.
【0073】
When the license for the encrypted content data is acquired, the first management file containing the first control number that specifies the storage area of the hard-acquired license and the software-acquired license are encrypted. A second management file containing a second management number that specifies the storage area for the encrypted license and the software-acquired license is entered, and the entered first or second management file is the recording unit. Recorded in.
【0074】
Therefore, according to the present invention, a software-acquired license and a hardware-acquired license can be managed at the same security level.
【0075】
Preferably, the device recorder records a first recorder that records licenses and binding licenses in association with first and second control numbers, and a second record section that records first and second management files, respectively. Includes the recording section of.
【0076】
The license and binding license and the first and second management files are recorded in different recording units, respectively.
【0077】
Therefore, according to the present invention, the license acquired by software and the binding license that manages the license acquired by software can be managed separately.
【0078】
Preferably, the device further comprises an authentication data holding unit that holds the authentication data, the control unit outputs the authentication data via the interface and the input / output terminals, and the license or binding license is obtained when the authentication data is authenticated. Is received via the input / output terminal and the interface.
【0079】
Once the authentication data held by the device is authenticated, a license or binding license is entered into the device.
【0080】
Therefore, according to the present invention, it is possible to prevent a license or binding license from being transmitted to an unauthorized device.
【0081】
Preferably, the binding license contains the license key required to decrypt the encrypted content data.
【0082】
The software generates an encrypted license encrypted with the license key included in the license received from the distribution server. Then, the generated encryption license is stored in the device unit.
【0083】
Therefore, according to the present invention, when the encrypted content data and the license are acquired by software, the license for decrypting the encrypted content data can be easily managed by the binding license.
【0084】
BEST MODE FOR CARRYING OUT THE INVENTION
Embodiments of the present invention will be described in detail with reference to the drawings. The same or corresponding parts in the drawings are designated by the same reference numerals, and the description is not repeated.
【0085】
FIG. 1 shows the overall configuration of a data distribution system in which a data terminal device (personal computer) according to the present invention acquires encrypted content data and moves the acquired encrypted content data to another data terminal device (personal computer). It is a schematic diagram for conceptually explaining.
【0086】
In the following, a configuration of a data distribution system that distributes music data to users of each personal computer via the Internet will be described as an example, but as will be clarified in the following description, the present invention is limited to such cases. It can also be applied to the distribution of content data as other literary works, such as image data, moving image data, and game programs, without being done.
【0087】
With reference to FIG. 1, the personal computer 50 transmits a distribution request (distribution request) from a user of each personal computer to the distribution server 10 via the Internet network 30. The distribution server 10 that manages copyrighted music data determines whether or not the personal computer 50 owned by the user of the personal computer who has accessed for data distribution has valid authentication data, that is, the personal computer. Is equipped with a legitimate program or a legitimate recording device necessary for receiving the distribution of the content, and performs an authentication process as to whether or not the distribution server 10 has been accessed using the legitimate program or the legitimate recording device. Music data (hereinafter also referred to as content data) is encrypted by a predetermined encryption method for a personal computer accessed using a legitimate program or a legitimate recording device, and then such encrypted content data and encryption are performed. Distribute the license as the information necessary for playing the content data to the personal computer 50.
【0088】
In this case, the personal computer 50 receives the encrypted content data and the license from the distribution server 10 via the Internet network 30 with different security levels. That is, the personal computer 50 has a built-in license management device which is a regular recording device, and the distribution server 10 distributes the license to the license management device via the Internet network 30 or the like. This license management device holds a hard license for playing back encrypted content data, and has a high security level. Further, the personal computer 50 has a built-in license management module which is a legitimate program for receiving encrypted content data and a license from the distribution server 10 via the Internet network 30 or the like by software. This license management module receives and manages licenses at a lower security level than license management devices. Since the encrypted content data is a data string that cannot be decrypted and played back without the decryption key (license key) included in the license, the acquisition route does not matter, but in the data distribution system shown in Fig. 1, the personal computer 50 Receives encrypted content data from the distribution server 10 via the Internet network 30 and records the received encrypted content data on an HDD (Hard Disk Drive) (not shown) built in the same as the license. The license management device and license management module will be described in detail later.
【0089】
Further, in FIG. 1, the personal computer 50 is obtained by generating encrypted content data by ripping from a music CD (Compact Disk) 60 on which music data is recorded and a license for playing the encrypted content data. To do. The details will be described later.
【0090】
Furthermore, the personal computer 50 connects to the playback terminal 100 by a USB (Universal Serial Bus) cable 70, and transmits the encrypted content data and the license received from the distribution server 10 to the memory card 110 mounted on the playback terminal 100. Is possible.
【0091】
Furthermore, the personal computer 50 transmits the received encrypted content data and the license to the personal computer 80 via the communication cable 90.
【0092】
Therefore, in the data distribution system shown in FIG. 1, the personal computer 50 receives the encrypted content data and the license from the distribution server 10 via the Internet network 30, and also receives the encrypted content data and the license from the music CD. get. Further, the memory card 110 mounted on the playback terminal 100 receives the encrypted content data and the license acquired by the personal computer 50 from the distribution server 10 or the music CD 60. The user of the playback terminal 100 can acquire the encrypted content data and the license from the music CD via the personal computer 50.
【0093】
In FIG. 1, for example, the playback terminal 100 of a mobile phone user is configured to be equipped with a removable memory card 110. The memory card 110 receives the encrypted content data received by the playback terminal 100, decrypts the encryption performed in the above distribution, and then gives the content music playback circuit (not shown) in the playback terminal 100.
【0094】
Further, for example, a mobile phone user can "play" and listen to such content data via a headphone 130 or the like connected to the playback terminal 100.
【0095】
With such a configuration, it is difficult to receive the distribution of the content data from the distribution server 10 and transmit the encrypted content data to the personal computer 80 and the playback terminal 100 unless it is a legitimate personal computer. ..
【0096】
Moreover, by counting the frequency of each time the content data for one song is distributed on the distribution server 10, the copyright fee incurred each time the user of the personal computer receives (downloads) the content data can be charged. If it is collected together with the usage fee of the Internet network, it will be easy for the copyright holder to secure the copyright fee.
【0097】
In the configuration shown in FIG. 1, in order for the content data delivered encrypted to be playable on the user side of the playback terminal or personal computer, firstly, communication is required on the system. The second is the method itself for encrypting the content data to be delivered, and the third is the unauthorized copy of the content data delivered in this way. It is a configuration that realizes content data protection to prevent it.
【0098】
In the embodiment of the present invention, in particular, when each session of distribution, movement, checkout, check-in, and playback occurs, the authentication and check functions for the destination of the movement of these content data are enhanced, and the content data is unauthenticated or unauthenticated. A configuration for strengthening the copyright protection of the content data by preventing the output of the content data to the recording device and the data reproduction terminal (reproduction terminal or personal computer provided with a dedicated content reproduction circuit) in which the decryption key is broken will be described.
【0099】
In the following description, the process of transmitting content data from the distribution server 10 to each personal computer or the like will be referred to as "distribution".
【0100】
FIG. 2 is a diagram illustrating characteristics such as data and information for communication used in the data distribution system shown in FIG.
【0101】
First, the data distributed from the distribution server 10 will be described. Dc is content data such as music data. The content data Dc is encrypted so that it can be decrypted with the license key Kc. The encrypted content data {Dc} Kc, which has been encrypted and decrypted by the license key Kc, is distributed from the distribution server 10 to the users of the personal computer in this format.
【0102】
In the following, the notation {Y} X indicates that the data Y has been encrypted so that it can be decrypted by the decryption key X.
【0103】
Further, from the distribution server 10, along with the encrypted content data, additional information Dc-inf as plain text information such as copyright or server access related to the content data is distributed. In addition, a transaction ID, which is a management code for identifying the distribution of encrypted content data and license key from the distribution server 10, is exchanged between the distribution server 10 and the personal computer 50. Furthermore, the license information includes the content ID, which is a code for identifying the content data Dc, the license ID, which is a management code that can identify the issuance of the license, and the license determined by the specifications from the content provider and the user side. License purchase conditions including information such as number and function limitation Access restriction information ACm and content playback circuit control, which is information related to access restrictions of the recording device (memory card or license management device) generated based on AC. There is playback restriction information ACp, etc., which is information. Specifically, the access restriction information ACm is information indicating restrictions on outputting the license key from the memory card, the license management device, and the license management module to the outside, and is the number of times of reproduction (outputting the license key for reproduction). (Number of times to do), restrictions on license movement / duplication, security level at which licenses can be output, etc. are assumed. Further, as the reproduction information, a reproduction period, a restriction on changing the reproduction speed, a restriction on editing, a reproduction range (partial license), and the like can be assumed. Hereinafter, the transaction ID and the content ID will be collectively referred to as a license ID, and the license key Kc, the license ID, the access restriction information ACm, and the playback restriction information ACp will be collectively referred to as a license.
【0104】
In addition, for the sake of simplicity, the access restriction information will be the playback count limit (0 to 244: remaining playback count, 255: no limit), move flag (0: move prohibited, 1: moveable) and security flag (1: It is possible to manage by software, 2: only hardware management is possible), and the playback restriction information is set to 1 item of the playback deadline indicating the playable deadline (date and time).
【0105】
In the embodiment of the present invention, it is proved that the distribution and reproduction of the content data can be prohibited for each class of the recording device (memory card or license management device) or the content reproduction circuit for reproducing the content data. Operate the CRL (Certificate Revocation List). In the following, the symbol CRL may optionally represent the data in the certificate revocation list.
【0106】
Certificate revocation list related information includes certificates that list the classes of content playback circuits, memory cards, license management modules, and license management devices that are prohibited from delivering, moving, checking out, checking in, and playing licenses. Contains revocation list data CRLs.
【0107】
The certificate revocation list data CRL is managed in the distribution server 10 and is also recorded and held in the memory card, the HDD in the personal computer 50, or the license management device. Such a certificate revocation list needs to be upgraded and updated as needed, but data changes are basically personal based on the date and time when the license such as the license key is distributed. Determines if the certificate revocation list received from the computer (license management device or license management module) has been updated, and if it has not been updated, distributes the updated certificate revocation list to the personal computer. The certificate revocation list is also exchanged between the license management module, the license management device, and the playback terminal 100, and the data change is the same as described above. Furthermore, regarding changes to the certificate revocation list, all new certificate revocation list CRLs may be sent, or differential CRLs, which are differential data reflecting only the changes, are generated from the distribution server 10 side. The certificate revocation list CRL in the memory card, hard disk, and license management device can be rewritten accordingly. Regarding the version of the certificate revocation list, it is the date and time information when the certificate revocation list was updated, and the update date and time CRL date is output from the memory card, hard disk, and license management device side, and this is confirmed on the distribution server 10 side. Perform version control by doing. The certificate revocation list CRL also includes the renewal date and time CRL date. Therefore, the update date and time CRL date is also included in the difference CRL, which is the difference data.
【0108】
In this way, by holding and operating the certificate revocation list CRL not only in the distribution server but also in the memory card or personal computer, it is class-specific, that is, the content playback circuit and the memory card or personal computer (license management device or license management). Prohibits the supply of license keys to content playback circuits and memory cards or personal computers where the decryption key specific to the module) type has been broken. Therefore, the content reproduction circuit or the personal computer cannot reproduce the content data, and the memory card, the license management module, and the license management device cannot move the content data.
【0109】
In this way, the certificate revocation list CRL in the memory card or the license management device is configured to sequentially update the data each time a new license is stored. Also, the management of certificate revocation list CRLs on memory cards, license management modules, and license management devices is a tamper resistant module on hard disks controlled by memory cards, license management devices, and license management modules independently of the higher levels. The certificate revocation list data CRL cannot be tampered with from a higher level by a file system, application program, etc. by recording in (Tamper Resistant Module). As a result, the copyright protection for the data can be strengthened.
【0110】
FIG. 3 is a diagram for explaining the characteristics of data, information, and the like for authentication used in the data distribution system shown in FIG.
【0111】
The content playback circuit, memory card, license management device, and license management module are provided with their own public encryption keys KPpy and KPmw, respectively, and the public encryption keys KPpy and KPmw are the private decryption keys Kpy and memory card unique to mobile phones. It can be decrypted by the private decryption key Kmw unique to the license management device and the license management module. These public encryption keys and private decryption keys have different values for each type of mobile phone, memory card, license management device, and license management module. These public encryption keys and private decryption keys are collectively referred to as class keys.
【0112】
In addition, Cpy is provided as a class certificate for the content playback device (mobile phone), and Cmw is provided as a class certificate for the memory card, license management device, and license management module.
【0113】
These class certificates have different information for each class of content playback circuit, memory card, license management device, and license management module. A class key whose encryption by the class key has been broken, that is, a class key for which a private decryption key has been obtained, is listed in the certificate revocation list and is prohibited from issuing a license.
【0114】
Public encryption keys and class certificates specific to these content playback circuits, memory cards, license management devices, and license management modules are in the form of authentication data {KPpy // Cpy} KPa or authentication data {KPmw // Cmw} KPa. It is recorded in the data playback circuit, memory card, license management device, and license management module at the time of shipment. As will be explained in detail later, KPa is a public authentication key common to the entire distribution system.
【0115】
In addition, the difference between the security level of the license management module licensed or managed by software and the security level of the memory card or license management device license managed by hardware can be determined by referring to this certificate Cmw.
【0116】
As an encryption key for confidentiality in license transfer, a common key generated in the distribution server 10, memory card 110, license management device, license management module, and content playback circuit each time content data is distributed and played back. Ks1 to Ks3 are used.
【0117】
Here, the common keys Ks1 to Ks3 are generated for each "session" which is a communication unit or an access unit between any two of the distribution server, the memory card, the license management device, the license management module, and the content reproduction circuit. It is a unique common key, and in the following, these common keys Ks1 to Ks3 will also be referred to as "session keys".
【0118】
These session keys Ks1 to Ks3 are generated and managed by the distribution server, the memory card, the license management device, the license management module, and the content reproduction circuit by having a value unique to each session. Specifically, the session key Ks1 is generated by the distribution server for each distribution session. The session key Ks2 is generated for each session in all sessions by the memory card, the license management device, and the license management module, and the session key Ks3 is generated for each playback session in the content reproduction circuit. In each session, these session keys are exchanged, the session key generated by another device is received, encryption is performed by this session key, and then the license key etc. is transmitted to strengthen the security in the session. Can be improved.
【0119】
In addition, as a key for managing data processing in the memory card 110, the license management device, and the license management module, the public encryption key KPmcx set for each medium such as the memory card, the license management device, and the license management module, There is a unique secret decryption key Kmcx for each memory card that can decrypt data encrypted with the public encryption key KPmcx.
【0120】
Figure 4 shows the binding license required to move the license acquired by the software (license management module) to another personal computer, and the checkout management information in the checkout session lent to the memory card 110. It is a license.
【0121】
The binding license is a binding key that is a common key for managing the license for playing the encrypted content data and the number of checkouts of the encrypted content data and the license, and access restriction that is control information for the binding license. It consists of information ACmb, playback restriction information ACpb, transaction IDb which is a transaction ID for binding license, content IDb which is a dummy for binding ID, and binding ID which is a general term for transaction IDb and content IDb.
【0122】
The binding key Kb is for managing the license of the encrypted content data acquired by the software in the license management device, and is held by the license management device (hardware). Then, the license can be obtained only by the binding key Kb held by the hardware. In addition, the access restriction information ACmb and the reproduction restriction information ACpb have one fixed value of the access restriction information ACm and the reproduction restriction information ACp included in the license for reproducing the encrypted content data, and the access restriction information ACmb Prohibits the duplication and movement of the license, the number of playbacks is unlimited, and the playback restriction information ACpb enables the encrypted content data to be played indefinitely. The configuration of the binding license is the same as that of the license and is managed by the license management device. The binding license is then managed in the same way as the hardware, that is, the license acquired at a high security level that can be moved.
【0123】
The checkout management information consists of the number of checkouts that can be performed, the checkout destination individual ID, and the checkout transaction ID. The number that can be checked out indicates the number of times that the encrypted content data can be rented, and the number is decremented by 1 each time the encrypted content data is checked out, and each time the encrypted content data is checked in. The number is incremented by one. The checkout destination individual ID specifies the memory card for checking out the encrypted content data, and corresponds to the public encryption key KPmcx held by the memory card. The transaction ID at checkout is the transaction ID used when checking out.
【0124】
FIG. 5 is a schematic block diagram showing the configuration of the distribution server 10 shown in FIG. The distribution server 10 follows the start of access to the content data for each user of the personal computer and the information database 304 for holding the data obtained by encrypting the content data according to a predetermined method and the distribution information such as the license ID. Billing database 302 for holding billing information, CRL database 306 for managing certificate revocation list CRL, menu database 307 for holding menu of content data held in information database 304, content data, license key, etc. Data from the delivery record database 308, which holds the transaction ID that identifies the delivery of the data, the information database 304, the billing database 302, the CRL database 306, the menu database 307, and the delivery record database 308 are received via the bus BS1 and specified. A data processing unit 310 for performing processing and a communication device 350 for exchanging data between the distribution carrier 20 and the data processing unit 310 via a communication network are provided.
【0125】
The data processing unit 310 is controlled by the distribution control unit 315 for controlling the operation of the data processing unit 310 and the distribution control unit 315 according to the data on the bus BS1, and generates the session key Ks1 at the time of the distribution session. Session key generator for 316, and the authentication key holder that holds the public authentication key for decrypting the authentication data {KPmw // Cmw} KPa sent from the license management device and the license management module. 313, the authentication data {KPmw // Cmw} KPa for authentication sent from the license management device and the license management module are received via the communication device 350 and the bus BS1 and released from the authentication key holder 313. The decryption processing unit 312 that performs decryption processing with the authentication key KPa and the session key Ks1 generated by the session key generation unit 316 are encrypted using the public encryption key KPmcx obtained by the decryption processing unit 312 and output to the bus BS1. It includes an encryption processing unit 318 for performing the decryption process, and a decryption processing unit 320 that receives the data transmitted after being encrypted by the session key Ks1 from the bus BS1 and performs the decryption processing.
【0126】
The data processing unit 310 further uses the license key Kc and the access restriction information ACm given by the distribution control unit 315 as a public encryption key unique to the memory card, the license management device, and the license management module obtained by the decryption processing unit 320. The encryption processing unit 326 for encrypting by KPmw and the encryption processing unit 328 for further encrypting the output of the encryption processing unit 326 with the session key Ks2 given from the decryption processing unit 320 and outputting it to the bus BS1. And include.
【0127】
The operation of the distribution server 10 in the distribution session will be described in detail later using a flowchart.
【0128】
FIG. 6 is a schematic block diagram for explaining the configuration of the personal computer 50 shown in FIG. The personal computer 50 includes a bus BS2 for exchanging data of each part of the personal computer 50, a modem 40 for connecting via an Internet network and a public telephone network, and a license management device 520 or a license management module via the Internet network. In order to receive the encrypted content data and the like from the distribution server 10 to the 511, the data transfer to and from the distribution server 10 is controlled, and the encrypted content data and the encrypted content data by ripping from the music CD via the CD-ROM drive 540. Various keys were exchanged between the controller 510 for controlling the acquisition of the license and the distribution server 10 when receiving the encrypted content data and the license from the distribution server 10, and the data was distributed. The license that is included in the license management device 520 that hardware-manages the license for playing the encrypted content data and the controller 510, executes the transmission and reception of the encrypted content data and the license from the distribution server 10 programmatically, and receives the license. Includes a content management module 511 that generates a dedicated license with its own encryption. Further, the content management module 511 can also be provided with a content reproduction function, and in this case, the acquired encrypted content data {Dc} Kc can be decrypted and reproduced with the acquired license key Kc.
【0129】
The license management device 520 transfers encrypted content data and data when receiving the license from the distribution server 10 in a hardware manner, and manages the received license in a hardware manner. Therefore, the license management device 520 encrypts at a high security level. It can distribute content data and manage licenses. In addition, the license management device 520 manages a dedicated license acquired by the license management module 511 and generated based on the acquired license. The license management device 520 is removable from the personal computer 50 and can be moved to another personal computer.
【0130】
On the other hand, the license management module 511 has a lower security level than the license management device 520 because it uses a program to transfer encrypted content data and data when receiving the license from the distribution server 10. It is a thing. In the following, the security level of the license management module 511 is referred to as "level 1", and the security level of the license management device is referred to as "level 2".
【0131】
The personal computer 50 further manages the encrypted content data received from the distribution server 10 by the license management module 511 or the license management device 520, the encrypted content data acquired from the music CD via the CD-ROM drive 540, and the license management. It includes an HDD 530 that stores a content list file that manages the license of the encrypted content data received by the module 511 or the license management device 520 in association with the file name of the encrypted content data. The details of the content list file will be described later.
【0132】
The personal computer 50 further includes a USB interface 550 for controlling the transfer of data between the controller 510 and the terminal 580 when communicating the encrypted content data and the license to the playback terminal 100 and the like, and the content data from the music CD. A CD-ROM drive 540 for acquiring data, a keyboard 560 for inputting instructions from the user, a display 570 for visually giving various information to the user, and a terminal for connecting the USB cable 70. Includes 580 and.
【0133】
In this way, the personal computer 50 includes the license management module 511 and the license management device 520 for receiving the encrypted content data and the license from the distribution server 10 via the Internet network 30, and the encrypted content data by ripping from the music CD. It also has a built-in CD-ROM drive 540 for obtaining a license. The encrypted content data and license acquisition by the CD-ROM drive 540 is performed at the same level 1 security level as the reception of the encrypted content data and license by the license management module 511.
【0134】
FIG. 7 is a schematic block diagram for explaining the configuration of the reproduction terminal 100 shown in FIG.
【0135】
The playback terminal 100 gives a bus BS3 for exchanging data of each part of the playback terminal 100, a controller 1106 for controlling the operation of the playback terminal 100 via the bus BS3, and an external instruction to the playback terminal 100. It includes an operation panel 1108 for the purpose and a display panel 1110 for giving the information output from the controller 1106 or the like as visual information to the mobile phone user.
【0136】
The playback terminal 100 further transfers data between the detachable memory card 110 for storing and decoding the content data (music data) from the distribution server 10 and the memory card 110 and the bus BS3. Connect the memory interface 1200 for control, the USB interface 1112 for controlling data transfer between the bus BS3 and terminal 1114 when receiving encrypted content data and license from the personal computer 50, and the USB cable 70. Includes terminal 1114 and.
【0137】
The playback terminal 100 further authenticates its validity by decrypting the public encryption key KPp1 and the class certificate Cp1 set for each type (class) of the playback terminal (content playback circuit) with the public decryption key KPa. Includes the authentication data holder 1500 that holds the encrypted authentication data {KPp1 // Cp1} KPa in a ready-to-use state. Here, it is assumed that the class y of the mobile phone (data terminal device) 100 is y = 1.
【0138】
The playback terminal 100 further includes a Kp1 holding unit 1502 that holds Kp1 that is a decoding key unique to the playback terminal (content playback circuit), and a session key generated by the memory card 110 that decodes the data received from the bus BS3 by Kp1. Includes decryption processing unit 1504 to obtain Ks2.
【0139】
The playback terminal 100 further uses a random number of session keys Ks3 for encrypting data exchanged on the bus BS3 with the memory card 110 in a playback session for playing back the content data stored in the memory card 110. Decryption processing of the session key Ks3 generated by the session key generator 1508 when receiving the license key Kc and the playback restriction information ACp from the memory card 110 in the session key generator 1508 generated by It includes an encryption processing unit 1506 that is encrypted by the session key Ks2 obtained by the unit 1504 and output to the bus BS3.
【0140】
The playback terminal 100 further receives the decryption processing unit 1510 that decodes and outputs the data on the bus BS3 with the session key Ks3 and the encrypted content data {Dc} Kc from the bus BS3, and acquires the data from the decryption processing unit 1510. The output of the decryption processing unit 1516 that decodes with the license key Kc and outputs the content data, the music playback unit 1518 that receives the output of the decoding processing unit 1516 and reproduces the content data, and the output of the music playback unit 1518 are analog from the digital signal. It includes a DA converter 1519 that converts a signal and a terminal 1530 for outputting the output of the DA converter 1519 to an external output device (not shown).
【0141】
In FIG. 7, the area surrounded by the dotted line constitutes the content reproduction device 1550 that decrypts the encrypted content data and reproduces the music data. The content reproduction device 1550 is configured as a highly confidential tamper resistant module in which the content reproduction circuit is realized by a semiconductor collection circuit. The operation of each component of the playback terminal 100 in each session will be described in detail later using a flowchart.
【0142】
FIG. 8 is a schematic block diagram for explaining the configuration of the memory card 110. As described above, KPmw and Kmw are provided as public encryption keys and private decryption keys unique to the memory card, and the memory card class certificate Cmw is provided. However, in the memory card 110, these are natural numbers w = It shall be represented by 3 respectively.
【0143】
Therefore, the memory card 110 includes an authentication data holding unit 1400 that holds the authentication data {KPm3 // Cm3} KPa, a Kmc holding unit 1402 that holds the Kmc4 that is a unique decryption key set for each memory card, and a memory. It includes a Km holding unit 1421 that holds a unique secret decryption key Km3 set for each card type, and a KPmc holding unit 1416 that holds a public encryption key KPmc4 that can be decrypted by Kmc4. The authentication data holding unit 1400 encrypts the secret encryption key KPm3 and the class certificate Cm3, which are set for each memory card type and class, by decrypting them with the public authentication key KPa so that their validity can be authenticated. Data {KPm3 // Cm3} Hold as KPa.
【0144】
In this way, by providing the encryption key of the recording device called the memory card, it is possible to manage the distributed content data and the encrypted license key for each memory card, as will be clarified in the following explanation. It will be possible.
【0145】
The memory card 110 further includes an interface 1424 that sends and receives signals to and from the memory interface 1200 via terminal 1426, a bus BS4 that exchanges signals with the interface 1424, and data given to the bus BS4 from the interface 1424. The decryption processing unit 1422 and the KPa holding unit 1422 that receive the secret decryption key Km3 unique to each type of memory card from the Km holding unit 1421 and output the session key Ks1 generated by the distribution server 10 in the distribution session to the contact Pa. It is selectively given by the decryption processing unit 1408 that receives the authentication key KPa from 1414, executes the decryption processing by KPa from the data given to the bus BS4, and outputs the decryption result to the encryption processing unit 1410, and the changeover switch 1442. It includes an encryption processing unit 1406 that encrypts the data selectively given by the changeover switch 1446 by the key and outputs it to the bus BS4.
【0146】
The memory card 110 further encrypts the session key generation unit 1418 that generates the session key Ks2 in the playback session and the session key Ks2 output by the session key generation unit 1418 by the public encryption key KPpy or KPmw obtained by the decryption processing unit 1408. The encryption processing unit 1410 that is encrypted and sent to the bus BS4, the decryption processing unit 1412 that receives the data encrypted by the session key Ks2 from the bus BS4 and decrypts it with the session key Ks2 obtained from the session key generation unit 1418, and the encryption. With the encryption processing unit 1417 that encrypts the license key Kc read from the memory 1415 and the reproduction restriction information ACp in the playback session of the encrypted content data with the public encryption key KPmcx unique to the memory card 110 decrypted by the decryption processing unit 1412. including.
【0147】
The memory card 110 also has a decryption processing unit 1404 for decrypting the data on the bus BS4 by the secret decryption key Kmc4 unique to the memory card 110 paired with the public encryption key KPmc4, and for updating the version of the certificate revocation list. Certificate revocation list data CRL that is sequentially updated by the data CRL_dat, encrypted content data {Dc} Kc, and license to play encrypted content data {Dc} Kc (Kc, ACp, ACm, license ID) It includes additional information Data-inf, a playback list of encrypted content data, and a memory 1415 for receiving and storing a license management file for managing licenses from the bus BS4. The memory 1415 is composed of, for example, a semiconductor memory. In addition, the memory 1415 includes a CRL area 1415A in which the certificate revocation list CRL is recorded, a license area 1415B in which the license is recorded, encrypted content data {Dc} Kc, related information Dc-inf of the encrypted content data, and a playback list. It consists of a data area 1415C that records the license management file.
【0148】
The memory card 110 further includes a controller 1420 for controlling the operation of the memory card 110 by exchanging data with and from the outside via the bus BS4 and receiving playback information and the like with the bus BS4. .. Each part of the memory card 110 except the interface 1424, the terminal 1426, and the data area 1415C of the memory 1415 is composed of a tamper resistant module, and high confidentiality is guaranteed.
【0149】
FIG. 9 is a schematic block diagram showing the configuration of the license management device 520 built in the personal computer 50. The license management device 520 basically has the same configuration as the memory card 110. Authentication data holding unit 5200, Kmc holding unit 5202, decryption processing unit 5204, encryption processing unit 5206, decryption processing unit 5208, encryption processing unit 5210, decryption processing unit 5212, KPa holding unit 5214, KPmc holding unit 5216 of the license management device 520. , Encryption processing unit 5217, session key generation unit 5218, controller 5220, Km holding unit 5221, decryption processing unit 5222, interface 5224, terminal 5226, selector switch 5242, 5246, respectively, the authentication data holding unit 1400 of the memory card 110, Kmc holding unit 1402, decryption processing unit 1404, encryption processing unit 1406, decryption processing unit 1408, encryption processing unit 1410, decryption processing unit 1412, KPa holding unit 1414, KPmc holding unit 1416, encryption processing unit 1417, session key generation unit 1418 , Controller 1420, Km holding unit 1421, decryption processing unit 1422, interface 1424, terminal 1426, changeover switch 1442, 1446. However, the authentication data holding unit 5200 holds the authentication data in the format of {KPm7 // Cm7} KPa, the Km holding unit 5202 holds the secret decryption key Km7, and the Kmc holding unit 5221 holds the secret decryption key Kmc8. Hold.
【0150】
The license management device 520 includes a memory 5215 for recording a certificate revocation list CRL, a license (Kc, ACp, ACm, license ID) and license management files 1521-152n in place of the memory 1415 of the memory card 110. The memory 5215 includes a CRL area 5215A in which the certificate revocation list CRL is recorded, a license area 5215B in which the license is recorded, and a management file area 5215C in which the license management files 1521 to 152n are recorded. Each part of the license management device 520, except for the management file area 5215C of the interface 5224, the terminal 5226, and the memory 5215, is composed of a tamper resistant module and guarantees high confidentiality.
【0151】
The operation of each session in the data distribution system shown in FIG. 1 will be described below.
【0152】
[Distribution 1] Next, in the data distribution system shown in FIG. 1, an operation of distributing encrypted content data and a license from the distribution server 10 to the license management device 520 of the personal computer 50 will be described. This operation is called "delivery 1".
【0153】
10 to 13 show a distribution operation (hereinafter, also referred to as a distribution session) to the license management device 520 built in the personal computer 50, which occurs when the encrypted content data in the data distribution system shown in FIG. 1 is purchased. It is the 1st to 4th flowcharts for this.
【0154】
With reference to FIG. 10, a user of the personal computer 50 makes a delivery request by specifying the content ID via the keyboard 560 (step S100). Then, the purchase condition AC for purchasing the license of the encrypted content data is input via the keyboard 560 (step S102). That is, in order to purchase the license key Kc for decrypting the selected encrypted content data, the access restriction information ACm and the playback restriction information ACp of the encrypted content data are set and the purchase condition AC is input.
【0155】
When the purchase condition AC of the encrypted content data is input, the controller 510 gives an instruction to output the authentication data to the license management device 520 via the bus BS2 (step S104). The controller 5220 of the license management device 520 receives the output instruction of the authentication data via the terminal 5226, the interface 5224, and the bus BS5. Then, the controller 5220 reads the authentication data {KPm7 // Cm7} KPa from the authentication data holding unit 5200 via the bus BS5, and outputs the {KPm7 // Cm7} KPa via the bus BS5, the interface 5224, and the terminal 5226. (Step S106).
【0156】
The controller 510 of the personal computer 50 transmits the content ID, the data AC of the license purchase conditions, and the distribution request to the distribution server 10 in addition to the authentication data {KPm7 // Cm7} KPa from the license management device 520 ( Step S108).
【0157】
The distribution server 10 receives the distribution request, the content ID, the authentication data {KPm7 // Cm7} KPa, and the data AC of the license purchase conditions from the personal computer 50 (step S110), and the decryption processing unit 312 receives the distribution request, the content ID, the authentication data {KPm7 // Cm7} KPa, and the data AC of the license purchase condition from the license management device 520 in the decryption processing unit 312. The output authentication data is decrypted with the public authentication key KPa (step S112).
【0158】
From the decryption processing result in the decryption processing unit 312, the distribution control unit 315 determines whether or not the processing is performed normally, that is, the license management device 520 sets the public encryption key KPm7 and the certificate Cm7 from the legitimate license administration device. In order to certify that the data is retained, an authentication process is performed to determine whether or not the authorized authority has received the encrypted authentication data for certifying its validity (step S114). If it is determined that the authentication data is valid, the distribution control unit 315 approves and accepts the public encryption key KPm7 and the certificate Cm7. Then, the process proceeds to the next process (step S116). If it is not valid authentication data, it is disapproved and the process ends without accepting the public encryption key KPm7 and the certificate Cm7 (step S198).
【0159】
When the authentication results in recognizing that the device is legitimate, the distribution control unit 315 then determines whether the license management device class certificate Cm7 is listed in the certificate revocation list CRL CRL database 306. If these class certificates are included in the certificate revocation list, end the delivery session here (step S198).
【0160】
On the other hand, if the class certificate of the license management device 520 is not included in the certificate revocation list, the process proceeds to the next process (step S116).
【0161】
As a result of authentication, if it is confirmed that the access is from a personal computer equipped with a license management device having valid authentication data and the class is not included in the certificate revocation list, the distribution control unit 315 is displayed on the distribution server 10. Generates a transaction ID, which is the management code for identifying the delivery (step S118). In addition, the session key generator 316 generates the session key Ks1 for distribution (step S120). The session key Ks1 is encrypted by the encryption processing unit 318 by the public encryption key KPm7 corresponding to the license management device 520 obtained by the decryption processing unit 312 (step S122).
【0162】
The transaction ID and the encrypted session key Ks1 are output as the transaction ID // {Ks1} Km7 to the outside via the bus BS1 and the communication device 350 (step S124).
【0163】
With reference to FIG. 11, when the personal computer 50 receives the transaction ID // {Ks1} Km7 (step S126), the controller 510 inputs the transaction ID // {Ks1} Km7 into the license management device 520 (step S126). S128). Then, in the license management device 520, the decryption processing unit 5222 holds the received data given to the bus BS5 via the terminal 5226 and the interface 5224 in the secret decryption unique to the license management device 520 held in the holding unit 5221. By decrypting with the key Km7, the session key Ks1 is decrypted and the session key Ks1 is accepted (step S130).
【0164】
When the controller 5220 confirms the acceptance of the session key Ks1 generated by the distribution server 10, the controller 5220 instructs the session key generator 5218 to generate the session key Ks2 generated during the distribution operation in the license management device 520. Then, the session key generator 5218 generates the session key Ks2 (step S132).
【0165】
In the distribution session, the controller 5220 extracts the update date and time CRL date from the certificate revocation list CRL recorded in the CRL area 5215A of the memory 5215 in the license management device 520 and outputs it to the changeover switch 5246 (step S134). ).
【0166】
The encryption processing unit 5206 has a session key Ks2, a public encryption key KPmc8, and a certificate given by sequentially switching the contacts of the changeover switch 5246 by the session key Ks1 given by the decryption processing unit 5222 via the contact Pa of the changeover switch 5242. The update date and time CRLdate of the revocation list is encrypted as one data string, and {Ks2 // KPmc8 // CRLdate} Ks1 is output to the bus BS3 (step S136).
【0167】
The encrypted data {Ks2 // KPmc8 // CRLdate} Ks1 output to the bus BS3 is output from the bus BS3 to the personal computer 50 via the interface 5224 and the terminal 5226, and is transmitted from the personal computer 50 to the distribution server 10. (Step S138).
【0168】
The distribution server 10 receives the transaction ID // {Ks2 // KPmc8 // CRLdate} Ks1 and executes the decryption process by the session key Ks1 in the decryption processing unit 320, and the session key Ks2 generated by the license management device 520. Accepts the revocation date CRL date of the certificate revocation list on the license management device 520 and the public encryption key KPmc8 unique to the license management device 520 (step S142).
【0169】
The distribution control unit 315 generates access restriction information ACm and playback restriction information ACp according to the data AC of the content ID and the license purchase condition acquired in step S110 (step S144). Further, the license key Kc for decrypting the encrypted content data is obtained from the information database 304 (step S146).
【0170】
The distribution control unit 315 gives the generated license, that is, the transaction ID, the content ID, the license key Kc, the playback restriction information ACp, and the access restriction information ACm to the encryption processing unit 326. The encryption processing unit 326 encrypts the license with the public encryption key KPmc8 unique to the license management device 520 obtained by the decryption processing unit 320, and the encrypted data {transaction ID // content ID // Kc // ACm // ACp } Generate Kmc8 (step S148).
【0171】
With reference to FIG. 12, on the distribution server 10, whether the certificate revocation list CRL stored in the license management device 520 is the latest based on the update date and time CRL date of the certificate revocation list sent from the license management device 520. Is determined, and when the certificate revocation list CRL stored in the license management device 520 is determined to be the latest, the process proceeds to step S152. If the certificate revocation list CRL stored in the license management device 520 is not the latest, the process proceeds to step S160 (step S150).
【0172】
When the certificate revocation list CRL stored in the license management device 520 is determined to be the latest, the encryption processing unit 328 uses the encryption data {transaction ID // content ID // Kc // ACm // ACp} Kmc8 is encrypted by the session key Ks2 generated in the license management device 520, and the encrypted data {{transaction ID // content ID // Kc // ACm // ACp} Kmc8} Output Ks2 to bus BS1. Then, the distribution control unit 315 transmits the encrypted data {{transaction ID // content ID // Kc // ACm // ACp} Kmc8} Ks2 on the bus BS1 to the personal computer 50 via the communication device 350 ( Step S152).
【0173】
Then, the controller 510 of the personal computer 50 receives the encrypted data {{transaction ID // content ID // Kc // ACm // ACp} Kmc8} Ks2 (step S154), and the license management device via the bus BS5. Enter in 520. The decryption processing unit 5212 of the license management device 520 receives the encrypted data {{transaction ID // content ID // Kc // ACm // ACp} Kmc8} Ks2 via the terminal 5226 and the interface 5224, and receives the session key generation unit. Decrypt with session key Ks2 generated by 5218 and accept {transaction ID // content ID // Kc // ACm // ACp} Kmc8 (step S158). After that, the process proceeds to step S172.
【0174】
On the other hand, when the distribution server 10 determines that the certificate revocation list CRL stored in the license management device 520 is not the latest, the distribution control unit 315 revokes the latest certificate from the CRL database 306 via the bus BS1. The list CRL is acquired and the difference CRL, which is the difference data, is generated (step S160).
【0175】
The encryption processing unit 328 receives the output of the encryption processing unit 326 and the difference CRL of the certificate revocation list supplied by the distribution control unit 315 via the bus BS1, and the session key generated in the license management device 520. Encrypt with Ks2. The encrypted data {difference CRL // {transaction ID // content ID // Kc // ACm // ACp} Kmc8} Ks2 output from the encryption processing unit 328 is a personal computer via the bus BS1 and the communication device 350. Sent to 50 (step S162).
【0176】
Personal computer 50 receives the transmitted encrypted data {difference CRL // {transaction ID // content ID // Kc // ACm // ACp} Kmc8} Ks2 (step S164) and licenses over bus BS5. Fill in management device 520 (step S166). In the license management device 520, the reception data given to the bus BS5 is decoded by the decoding processing unit 5212 via the terminal 5226 and the interface 5224. The decoding processing unit 5212 decodes the received data of the bus BS5 using the session key Ks2 given from the session key generation unit 5218 and outputs the received data to the bus BS5 (step S168).
【0177】
At this stage, the bus BS5 is different from the encryption license {transaction ID // content ID // Kc // ACm // ACp} Kmc8} that can be decrypted with the secret decryption key Kmc8 held in the Kmc holding unit 5221. CRL is output (step S168). The certificate revocation list CRL recorded in the CRL area 5215A in the memory 5215 is updated based on the differential CRL by the differential CRL received by the instruction of the controller 5220 (step S170).
【0178】
Steps S152, S154, S156, and S158 are delivery operations to the license management device 520 such as the license key Kc when the certificate revocation list CRL recorded in the license management device 520 is the latest, and steps S160, S162, S164, S166, S168, and S170 are distribution operations to the license management device 520 such as the license key Kc when the certificate revocation list CRL recorded in the license management device 520 is not the latest. In this way, based on the certificate revocation list CRL date sent from the license management device 520, it is checked one by one whether the certificate revocation list CRL stored in the license management device 520 is the latest, and when it is not the latest. , The latest certificate revocation list CRL is obtained from the CRL database 306, and the differential CRL is distributed to the license management device 520 so that the certificate revocation list CRL stored in the license management device 520 is sequentially updated. By updating, it is possible to prevent the output of the license key Kc from the license management device 520 to other license management devices, license management modules, memory cards, and content playback devices whose licenses have been broken.
【0179】
After step S158 or step S170, the encryption license {transaction ID // content ID // Kc // ACm // ACp} Kmc8 is decrypted by the secret decryption key Kmc8 in the decryption processing unit 5204 at the instruction of the controller 5220. , The license (license key Kc, transaction ID, content ID, access restriction information ACm and playback restriction information ACp) is accepted (step S172).
【0180】
In this way, by exchanging the encryption keys generated by the distribution server and the license management device, performing encryption using the encryption keys received by each other, and transmitting the encrypted data to the other party, respectively. It is possible to perform de facto mutual authentication even when sending and receiving encrypted data, and it is possible to improve the security of the data distribution system.
【0181】
With reference to FIG. 13, the controller 510 enters the entry number for storing the license received by the license management device 520 into the license management device 520 (step S174). Then, the controller 5220 of the license management device 520 receives the entry number through the terminal 5226 and the interface 5224, and the license acquired in step S172 (license key) is applied to the license area 5215B of the memory 5215 specified by the received entry number. Store Kc, transaction ID, content ID, access restriction information ACm and playback restriction information ACp) (step S176).
【0182】
The controller 510 of the personal computer 50 transmits the transaction ID sent from the distribution server 10 and the distribution request for the encrypted content data to the distribution server 10 (step S178).
【0183】
The distribution server 10 receives the transaction ID and the distribution request of the encrypted content data (step S180), acquires the encrypted content data {Dc} Kc and the additional information Dc-inf from the information database 304, and obtains these data. Is output via bus BS1 and communication device 350 (step S182).
【0184】
The personal computer 50 receives the {Dc} Kc // Dc-inf and receives the encrypted content data {Dc} Kc and the additional information Dc-inf (step S184). Then, the controller 510 records the encrypted content data {Dc} Kc and the additional information Dc-inf in the HDD 530 via the bus BS2 (step S186). The controller 510 also generates a license management file for the encrypted content data {Dc} Kc including the license entry number stored in the license management device 520, the plaintext transaction ID and the content ID, and the additional information Dc-inf. , Input the license management file generated via bus BS2 to the license management device 520, and instruct to record it in the management file area 5215C of the memory 5215 (step S188). The controller 5220 of the license management device 520 receives the license management file and the instruction via the terminal 5226, the interface 5224, and the bus BS5, and records the received license management file in the management file area 5215C of the memory 5215 (step S189). .. After that, the controller 510 adds the name of the received content to the content list file recorded in the HDD 530 (step S190), and transmits the transaction ID and the distribution acceptance to the distribution server 10 (step S192).
【0185】
When the distribution server 10 receives the transaction ID // distribution acceptance (step S194), the distribution server 10 stores the charge data in the charge database 302 and records the transaction ID in the distribution record database 308, and executes the processing of ending the distribution. (Step S196), and the entire process is completed (step S198).
【0186】
In this way, after confirming that the license management device 50 built into the personal computer 50 is a legitimate device, and at the same time, the public encryption key KPm7 encrypted and transmitted together with the class certificate Cm7 is valid. And the class certificate Cm7 delivers content data only to delivery requests from certificate revocation lists, that is, license management devices that are not on the class certificate list that has been decrypted by the public encryption key KPm7. It is possible to prohibit distribution to unauthorized license management devices and distribution using a decrypted class key.
【0187】
Further, when the license management device 520 receives the encrypted content data and the license from the distribution server 10, the license management device 520 exchanges data with the distribution server 10 in a hardware manner and reproduces the encrypted content data. The security level is high because it stores the data in hardware. Therefore, by using the license management device 520, the personal computer 50 can receive the encrypted content data and the license by the distribution with a high security level, and can manage the license with a high security level.
【0188】
[Distribution 2] In the data distribution system shown in FIG. 1, an operation of distributing encrypted content data and a license from the distribution server 10 to the license management module 511 of the personal computer 50 will be described. This operation is called "delivery 2".
【0189】
14 to 19 show the first to sixth parts for explaining the distribution operation to the license management module 511 built in the personal computer 50, which occurs when the encrypted content data in the data distribution system shown in FIG. 1 is purchased. It is a flowchart. The license management module 511 programmatically receives the encrypted content data and the license from the distribution server 10.
【0190】
With reference to FIG. 14, a user of the personal computer 50 makes a delivery request by specifying the content ID via the keyboard 560 (step S200). Then, the purchase condition AC for purchasing the license of the encrypted content data is input via the keyboard 560 (step S202). That is, in order to purchase the license key Kc for decrypting the selected encrypted content data, the access restriction information ACm and the playback restriction information ACp of the encrypted content data are set and the purchase condition AC is input.
【0191】
When the purchase condition AC of the encrypted content data is input, the controller 510 reads the authentication data {KPm5 // Cm5} KPa from the license management module 511, and in addition to the read authentication data {KPm5 // Cm5} KPa. , Content ID, license purchase condition data AC, and delivery request are sent to the delivery server 10 (step S204).
【0192】
The distribution server 10 receives the distribution request, the content ID, the authentication data {KPm5 // Cm5} KPa, and the data AC of the license purchase conditions from the personal computer 50 (step S206), and the decryption processing unit 312 receives the data AC from the license management module 511. The output authentication data is decrypted with the public authentication key KPa (step S208).
【0193】
The distribution control unit 315 determines whether or not the processing is performed normally based on the decryption processing result in the decryption processing unit 312, that is, the license management module 511 determines the public encryption key KPm5 and the certificate Cm5 from the legitimate license administration module. In order to certify that the data is retained, an authentication process is performed to determine whether or not the authorized authority has received the encrypted authentication data for certifying its validity (step S210). If it is determined that the authentication data is valid, the distribution control unit 315 approves and accepts the public encryption key KPm5 and the certificate Cm5. Then, the process proceeds to the next process (step S212). If it is not valid authentication data, it is disapproved and the process ends without accepting the public encryption key KPm5 and the certificate Cm5 (step S299k).
【0194】
When the authentication results in recognizing that the module is legitimate, the distribution control unit 315 then determines whether the license management module class certificate Cm5 is listed in the certificate revocation list CRL CRL database 306. If these class certificates are on the certificate revocation list, end the delivery session here (step S299k).
【0195】
On the other hand, if the class certificate of the license management module 511 is not included in the certificate revocation list, the process proceeds to the next process (step S214).
【0196】
As a result of authentication, if it is confirmed that the access is from a personal computer equipped with a license management module having valid authentication data and the class is not included in the certificate revocation list, the distribution control unit 315 is displayed on the distribution server 10. Generates a transaction ID, which is the management code for identifying the delivery (step S214). In addition, the session key generator 316 generates the session key Ks1 for distribution (step S216). The session key Ks1 is encrypted by the encryption processing unit 318 by the public encryption key KPm5 corresponding to the license management module 511 obtained by the decryption processing unit 312 (step S218).
【0197】
The transaction ID and the encrypted session key Ks1 are output as the transaction ID // {Ks1} Km5 to the outside via the bus BS1 and the communication device 350 (step S220).
【0198】
With reference to FIG. 15, when the controller 510 of the personal computer 50 receives the transaction ID // {Ks1} Km5 (step S222), the license management module 511 receives the {Ks1} Km5 and becomes the license management module 511. Decryption processing is performed by the unique private decryption key Km5, and the session key Ks1 is accepted (step S224).
【0199】
When the license management module 511 confirms the acceptance of the session key Ks1 generated by the distribution server 10, it generates the session key Ks2 (step S226). Then, the controller 510 reads the encrypted CRL stored in the HDD 530 via the bus BS2, and the license management module 511 decrypts the encrypted CRL to obtain the certificate revocation list CRL, and the decrypted certificate revocation list. Obtain the revocation date CRL date from the CRL (step S228). The license management module 511 further sets the session key Ks2 generated by the license management module 511, the public encryption key KPmc6, and the update date and time CRL date of the certificate revocation list by the session key Ks1 generated by the distribution server 10. Encrypt as, and output {Ks2 // KPmc6 // CRLdate} Ks1 (step S230).
【0200】
The controller 510 transmits the transaction ID // {Ks2 // KPmc6 // CRLdate} Ks1 obtained by adding the transaction ID to the encrypted data {Ks2 // KPmc6 // CRLdate} Ks1 to the distribution server 10 (step S232).
【0201】
The distribution server 10 receives the transaction ID // {Ks2 // KPmc6 // CRLdate} Ks1 (step S234), executes the decryption process by the session key Ks1 in the decryption processing unit 320, and is generated by the license management module 511. Accepts the session key Ks2, the public encryption key KPmc6 unique to the license management module 511, and the revocation date CRL date of the certificate revocation list in the license management module 511 (step S236).
【0202】
The distribution control unit 315 generates access restriction information ACm and playback restriction information ACp according to the data AC of the content ID and the license purchase condition acquired in step S206 (step S238). Further, the license key Kc for decrypting the encrypted content data is obtained from the information database 304 (step S240).
【0203】
The distribution control unit 315 gives the generated license, that is, the transaction ID, the content ID, the license key Kc, the playback restriction information ACp, and the access restriction information ACm to the encryption processing unit 326. The encryption processing unit 326 encrypts the license with the public encryption key KPmc6 unique to the license management module 511 obtained by the decryption processing unit 320, and the encrypted data {transaction ID // content ID // Kc // ACm // Generate ACp} Kmc6 (step S242).
【0204】
With reference to FIG. 16, on the distribution server 10, whether the certificate revocation list CRL managed by the license management module 511 is the latest based on the update date and time CRL date of the certificate revocation list sent from the license management module 511. Is determined, and when it is determined to be the latest, the process proceeds to step S246. If it is not the latest version, the process proceeds to step S252 (step S244).
【0205】
When the certificate revocation list CRL managed by the license management module 511 is determined to be the latest, the encryption processing unit 328 uses the encryption data {transaction ID // content ID // Kc // ACm // ACp} Kmc6 is encrypted by the session key Ks2 generated in the license management module 511, and the encrypted data {{transaction ID // content ID // Kc // ACm // ACp} Kmc6} Output Ks2 to bus BS1. Then, the distribution control unit 315 transmits the encrypted data {{transaction ID // content ID // Kc // ACm // ACp} Kmc6} Ks2 on the bus BS1 to the personal computer 50 via the communication device 350 ( Step S246).
【0206】
Then, the controller 510 of the personal computer 50 receives the encrypted data {{transaction ID // content ID // Kc // ACm // ACp} Kmc6} Ks2 (step S248), and the license management module 511 encrypts the data. Data {{Transaction ID // Content ID // Kc // ACm // ACp} Kmc6} Decrypt Ks2 with session key Ks2 and accept {Transaction ID // Content ID // Kc // ACm // ACp} Kmc6 (Step S250). After that, the process proceeds to step S262.
【0207】
On the other hand, when it is determined in the distribution server 10 that the certificate revocation list CRL managed by the license management module 511 is not the latest, the distribution control unit 315 performs the latest certificate revocation list from the CRL database 306 via the bus BS1. To generate a differential CRL, which is the differential data (step S252).
【0208】
The encryption processing unit 328 receives the output of the encryption processing unit 326 and the difference CRL of the certificate revocation list supplied by the distribution control unit 315 via the bus BS1, and the session key generated in the license management module 511. Encrypt with Ks2. The encrypted data {difference CRL // {transaction ID // content ID // Kc // ACm // ACp} Kmc6} Ks2 output from the encryption processing unit 328 is a personal computer via the bus BS1 and the communication device 350. Sent to 50 (step S254).
【0209】
The personal computer 50 receives the transmitted encrypted data {difference CRL // {transaction ID // content ID // Kc // ACm // ACp} Kmc6} Ks2 (step S256), and the license management module 511 Decrypt the received data using the session key Ks2 and accept it as the differential CRL and encrypted data {transaction ID // content ID // Kc // ACm // ACp} Kmc6 (step S258).
【0210】
The controller 510 adds the received differential CRL to the certificate revocation list CRL recorded in the HDD 530, performs its own encryption processing, and rewrites the certificate revocation list CRL in the HDD 530 (step S260).
【0211】
Steps S246, S248, and S250 are distribution operations to the license management module 511 such as the license key Kc when the certificate revocation list CRL managed by the license management module 511 is the latest, and steps S252, S254, S256, S258 and S260 are distribution operations to the license management module 511 such as the license key Kc when the certificate revocation list CRL managed by the license management module 511 is not the latest. In this way, based on the update date and time of the certificate revocation list sent from the license management module 511, it is checked and updated one by one whether the certificate revocation list CRL managed by the license management module 511 is the latest. When not, the latest certificate revocation list CRLdate is obtained from the CRL database 306, and the differential CRL is distributed to the license management module 511, so that other license management modules whose licenses have been broken from the license management module 511, license management. It is possible to prevent the output of the license key Kc to the device, the memory card and the content reproduction circuit.
【0212】
After step S250 or step S260, the encryption license {transaction ID // content ID // Kc // ACm // ACp} Kmc6 is decrypted by the private decryption key Kmc6 and the license (license key Kc, transaction ID, content ID) , Access restriction information ACm and playback restriction information ACp) are accepted (step S262).
【0213】
In this way, by exchanging the encryption keys generated by the distribution server and the license management module, executing encryption using the encryption keys received by each other, and transmitting the encrypted data to the other party, respectively. It is possible to perform de facto mutual authentication even when sending and receiving encrypted data, and it is possible to improve the security of the data distribution system.
【0214】
The license management module 511 determines whether or not the number of playbacks is limited by the received access restriction information ACm, proceeds to step S266 when the number of playbacks is not limited, and steps S268 when the number of playbacks is limited. Go to (step S264). Then, when the number of playbacks is not limited, the license management module 511 generates checkout information including the encrypted contents received from the distribution server 10 and the checkout possible number for lending the license to another device ( Step S266). In this case, the initial value of checkout is set to "3". When the number of playbacks is limited, the license management module 511 sets the number of checkouts that can be checked out for lending encrypted content data to other devices to "0" and generates checkout information (step). S268).
【0215】
With reference to FIG. 17, after step S266 or step S268, the license management module 511 generates the binding key Kb (step S270) and accepts the license (transaction ID, content ID, license key Kc, access restriction information ACm). , And playback restriction information ACp) and checkout information are encrypted with the binding key Kb, and encrypted confidential information {transaction ID // content ID // license key Kc // access restriction information ACm // playback restriction information ACp // check Out information} Generate Kb (step S271). Then, the license management module 511 generates transaction IDb and content IDb for the binding license, and allocates playback restriction information ACpb capable of normal playback of encrypted content data indefinitely (step S272). After that, the access restriction information ACm is duplicated as the access restriction information ACmb, and the playback count limit is changed to no limit (= 255) (step S273). At this time, the security flag is "1" indicating that it can be managed by software because it is delivered to the license management module 511.
【0216】
After that, the license management module 511 gives an instruction to output the authentication data to the license management device 520 via the bus BS2 (step S274). The controller 5220 of the license management device 520 receives the output instruction of the authentication data via the terminal 5226, the interface 5224, and the bus BS5. Then, the controller 5220 reads the authentication data {KPm7 // Cm7} KPa from the authentication data holding unit 5200 via the bus BS5, and outputs the {KPm7 // Cm7} KPa via the bus BS5, the interface 5224, and the terminal 5226. (Step S275).
【0217】
The license management module 511 receives the content ID, the license purchase condition data AC, and the delivery request in addition to the authentication data {KPm7 // Cm7} KPa from the license management device 520 (step S276).
【0218】
In the license management module 511, the authentication data {KPm7 // Cm7} KPa from the license management device 520 is decrypted with the public authentication key KPa (step S277). Then, the license management module 511 determines whether or not the processing is performed normally based on the decryption processing result, that is, the license management device 520 holds the public encryption key KPm7 and the certificate Cm7 from the legitimate license administration device. In order to certify the data, an authentication process is performed to determine whether or not the authorized organization has received the encrypted authentication data for certifying its validity (step S278). If it is determined that the authentication data is valid, the license management module 511 approves and accepts the public encryption key KPm7 and the certificate Cm7. Then, the process proceeds to the next process (step S279). If it is not valid authentication data, it is disapproved and the process ends without accepting the public encryption key KPm7 and the certificate Cm7 (step S299k).
【0219】
If the authentication results indicate that the device is legitimate, is the license management module 511 then listed in the latest certificate revocation list CRL updated by the class certificate Cm7 of license management device 520? Query HDD530 for any, and if these class certificates are on the latest updated certificate revocation list, end the delivery session here (step S299k).
【0220】
On the other hand, if the class certificate of the license management device 520 is not included in the certificate revocation list, the process proceeds to the next process (step S279).
【0221】
When the authentication results confirm that the access is from a license management device with valid authentication data and the class is not included in the certificate revocation list, the license management module 511 generates a new session key Ks2a. (Step S280). The license management module 511 encrypts the session key Ks2a with the public encryption key KPm7, generates the encrypted data {Ks2a} Km7 (step S281), and transfers the encrypted data {Ks2a} Km7 to the license management device 520 via the bus BS2. Output to (step S282). Then, the controller 5220 of the license management device 520 receives the encrypted data {Ks2a} Km7 via the terminal 5226, the negative face 5224, and the bus BS5, and the decryption processing unit 5222 receives the encrypted data {Ks2a} Km7. Decrypt with the private decryption key Km7 and accept the session key Ks2a (step S283).
【0222】
With reference to FIG. 18, the session key generator 5218 generates the session key Ks2b (step S284), and the controller 5220 uses the bus BS5 to record the certificate revocation list CRL recorded in the CRL area 5215A of the memory 5215. The update date and time CRL date is obtained from and the update date and time CRL date is given to the changeover switch 5246 via the bus BS5 (step S285). The encryption processing unit 5206 encrypts the session key Ks2b, the public encryption key KPmc8, and the update date / time CRLdate acquired by sequentially switching the changeover switch 5246 with the session key Ks2a from the decryption processing unit 5222, and the encrypted data {Ks2b / / KPmc8 // CRLdate} Ks2a is generated, and the controller 5220 outputs the encrypted data {Ks2b // KPmc8 // CRLdate} Ks2a via bus BS5, interface 5224, and terminal 5226 (step S286).
【0223】
The license management module 511 receives the encrypted data {Ks2b // KPmc8 // CRLdate} Ks2a, decrypts it with the session key Ks2a, and accepts the session key Ks2b, the public encryption key KPmc8, and the update date CRLdate (step S287). .. Then, the license management module 511 encrypts the binding license (transaction IDb, content IDb, binding key Kb, access restriction information ACmb, and playback restriction information ACpb) with the public encryption key KPmc8 and encrypts the encrypted data {transaction IDb // content. IDb // Kb // ACmb // ACpb} Generate KPmc8.
【0224】
After that, the license management module 511 determines whether the certificate revocation list CRL recorded in the CRL area 5215A of the memory 5215 of the license management device 520 is the latest based on the update date and time CRL date, and when it is determined to be the latest. , Move to step S290. If it is not the latest version, the process proceeds to step S292 (step S289).
【0225】
When the certificate revocation list CRL recorded in the CRL area 5215A of the memory 5215 of the license management device 520 is determined to be the latest, the license management module 511 sets the encrypted data {transaction IDb // content IDb // Kb // ACmb // ACpb} KPmc8 is encrypted by the session key Ks2b generated in the license management device 520, and encrypted data {{transaction IDb // content IDb // Kb // ACmb // ACpb} KPmc8} Ks2b is generated. And output to the license management device 520 (step S290).
【0226】
Then, the controller 5220 of the license management device 520 receives the encrypted data {{transaction IDb // content IDb // Kb // ACmb // ACpb} KPmc8} Ks2b via the terminal 5226, the interface 5224, and the bus BS5. Then, the decryption processing unit 5212 decrypts the encrypted data {{transaction IDb // content IDb // Kb // ACmb // ACpb} KPmc8} Ks2b with the session key Ks2b, and the encrypted data {transaction IDb // content. Accept IDb // Kb // ACmb // ACpb} KPmc8 (step S291). After that, the process proceeds to step S296 in FIG.
【0227】
On the other hand, in step S289, when it is determined that the certificate revocation list CRL recorded in the CRL area 5215A of the memory 5215 of the license management device 520 is not the latest, the license management module 511 is updated from the HDD 530 via the bus BS2. Obtain the certificate revocation list CRL of the above and generate the differential CRL which is the differential data (step S292). Then, the license management module 511 receives the differential CRL of the certificate revocation list supplied from the HDD 530 via the bus BS2, and receives the encrypted data {transaction IDb // content IDb // Kb // ACmb // ACpb} Kmc8. And the difference CRL of the certificate revocation list are encrypted by the session key Ks2b generated in the license management device 520. Encrypted data {Difference CRL // {Transaction IDb // Content IDb // Kb // ACmb // ACpb} Output Kmc8} Ks2b to the license management device 520 (step S293).
【0228】
Controller 5220 of license management device 520 sends encrypted data {difference CRL // {transaction IDb // content IDb // Kb // ACmb // ACpb} Kmc8} Ks2b over terminal 5226, interface 5224, and bus BS5. Upon receiving, the decryption processing unit 5212 decrypts the encrypted data {difference CRL // {transaction IDb // content IDb // Kb // ACmb // ACpb} Kmc8} Ks2b with the session key Ks2b and encrypts it with the difference CRL. Accept the data {transaction IDb // content IDb // Kb // ACmb // ACpb} Kmc8 (step S294).
【0229】
The controller 5220 updates the certificate revocation list CRL recorded in the CRL area 5215A of the memory 5215 with the received differential CRL (step S295). Steps S290 and S291 are operations for sending the binding license to the license management device 520 when the certificate revocation list CRL recorded in the CRL area 5215A of the memory 5215 of the license management device 520 is the latest, and steps S292 and S293. , S294 and S295 are operations for sending the binding license to the license management device 520 when the certificate revocation list CRL recorded in the CRL area 5215A of the memory 5215 of the license management device 520 is not the latest. In this way, based on the update date and time CRL date of the certificate revocation list sent from the license management device 520, the certificate revocation list CRL recorded in the CRL area 5215A of the memory 5215 is checked one by one to see if it is the latest. , When not up-to-date, send to the latest certificate revocation list CRL updated by the differential CRL received from distribution server 10.
【0230】
With reference to FIG. 19, after step S291 or step S295, the decryption processing unit 5204 uses the secret decryption key Kmc8 from the Kmc holding unit 5202 to encrypt the data {transaction IDb // content IDb // Kb // ACmb // Decrypts ACpb} Kmc8 and accepts transaction IDb, content IDb, binding key Kb, access restriction information ACmb, and playback restriction information ACpb (step S296).
【0231】
In this way, by exchanging the encryption keys generated by the license management device and the license management module, performing encryption using the encryption keys received by each other, and transmitting the encrypted data to the other party, Substantial mutual authentication can be performed in the transmission and reception of each encrypted data, and the security of the data distribution system can be improved.
【0232】
The license management module 511 then enters the entry number for storing the binding license into the license management device 520 via bus BS2 (step S297). The controller 5220 of the license management device 520 receives the entry number via the terminal 5226, the interface 5224, and the bus BS5, and the transaction IDb and the content IDb received in the license area 5215B of the memory 5215 specified by the received entry number. , Binding key Kb, access restriction information ACmb, and playback restriction information ACpb (step S298).
【0233】
Then, the license management module 511 transmits the transaction ID sent from the distribution server 10 and the distribution request for the encrypted content data to the distribution server 10 (step S299).
【0234】
The distribution server 10 receives the transaction ID and the distribution request for the encrypted content data (step S299a), acquires the encrypted content data {Dc} Kc and the additional information Dc-inf from the information database 304, and obtains these data. Is output via bus BS1 and communication device 350 (step S299b).
【0235】
The license management module 511 receives {Dc} Kc // Dc-inf and receives the encrypted content data {Dc} Kc and additional information Dc-inf (step S299c). Then, the license management module 511 records the encrypted content data {Dc} Kc and the additional information Dc-inf in the HDD 530 via the bus BS2 (step S299d). The license management module 511 also generates a license management file for the recorded encrypted content data {Dc} Kc and additional information Dc-inf, including the binding license entry number, encrypted sensitive information, transaction ID and content ID. , Send the license management file to the license management device 520 via bus BS2 (step S299e). The control unit 5220 of the license management device 520 receives the license management file via the terminal 5226, the interface 5224, and the bus BS5, and records the received license management file in the management file area 5215C of the memory 5215 (step S299f). .. After that, the license management module 511 adds the name of the received content to the content list file recorded in the HDD 530 (step S299g), and transmits the transaction ID and the distribution acceptance to the distribution server 10 (step S299h).
【0236】
When the distribution server 10 receives the transaction ID // distribution acceptance (step S299i), the distribution server 10 stores the billing data in the billing database 302 and records the transaction ID in the distribution record database 308, and executes the processing of ending the distribution. (Step S299j), and the entire process ends (step S299k).
【0237】
In this way, the license management module 511 exchanges data with the distribution server 10 by software, and receives the encrypted content data and the license from the distribution server 10 in software. In addition, the received encrypted content data is recorded in the HDD 530, the license is encrypted with the binding key Kb, and the encrypted confidential information is created and stored in the license management file. Then, the binding key Kb for decrypting the encrypted confidential information and the license management file are held in the license management device 520. In this case, without the binding key Kb, the license received by the license management module 511 cannot be obtained. Therefore, the binding key Kb effectively manages the license received by the license management module 511, and the binding key Kb is the same as the license acquired by the license management device 520. Stored in. This allows the licenses received by the license management module 511 and the licenses received by the license management device 520 to be managed in the same way.
【0238】
In the embodiment of the present invention, the license management module 511 generates a new binding key Kb each time the encrypted content data and the license are received.
【0239】
[Rip] Next, the generation of encrypted content data and a license by ripping from a music CD on which music data is recorded will be described.
【0240】
20 to 23 are first to fourth flowcharts for generating encrypted content data and a license by ripping from a music CD.
【0241】
With reference to FIG. 20, when the ripping operation is started, the watermark usage rule is detected based on the music data detected by the CD-ROM drive 540 from the music CD (step S700). Then, it is determined whether or not duplication is possible based on the detected watermark usage rules (step S701). If the watermark usage rules have regularity, the process proceeds to step S702. If the watermark usage rules do not have regularity, replication is prohibited, the process proceeds to step S743, and the ripping operation ends. If the installed CD does not contain a watermark, the process proceeds to step S705.
【0242】
If it is determined in step S701 that the rules for using the water mark are regular, the music data is fetched from the music CD, and the license management module 511 changes the conditions for copying the water mark contained in the music data. Replace with the mark (step S702). That is, if the watermark usage rule allows copying up to 3 times, the watermark is replaced with a watermark that has been duplicated twice. Then, the license management module 511 generates the access restriction information ACm and the reproduction restriction information ACp that reflect the usage rules (step S703). The license management module 511 then generates checkout information, including the number of checkouts that can be checked out that reflect the usage rules (step S704).
【0243】
On the other hand, in step S701, when the watermark is not detected and it is determined that there is no usage rule, the license management module 511 prohibits the movement of the license movement flag (= 0) and limits the number of playbacks (=). 255), the access restriction information ACm that allows the security flag to be managed by software (= 1) and the playback restriction information ACp that can be normally played indefinitely are assigned (step S705). The license management module 511 then generates checkout information, including the number of checkouts that can be checked out with an initial value of 3 (step S706).
【0244】
After step S704 or S706, the license management module 511 generates the license key Kc (step S707), the transaction ID and the content ID (step S708), and further generates the binding key Kb (step S709).
【0245】
With reference to FIG. 21, the license management module 511 encrypts the generated license (transaction ID, content ID, license key Kc, playback restriction information ACm, and playback restriction information ACp) and checkout information with the binding key Kb. Encrypted confidential information {Transaction ID // Content ID // License key Kc // Access restriction information ACm // Playback restriction information ACp // Checkout information} Generate Kb (step S710). Then, the license management module 511 generates transaction IDb and content IDb, and allocates playback restriction information ACpb that can be normally played indefinitely (step S711). After that, the license management module 511 replicates the access restriction information ACm as the access restriction information ACmb, and changes the play count limit to unlimited (= 255) (step S712).
【0246】
The license management module 511 gives an instruction to output authentication data to the license management device 520 via the bus BS2 (step S712a). The controller 5220 of the license management device 520 receives the output instruction of the authentication data via the terminal 5226, the interface 5224, and the bus BS5. Then, the controller 5220 reads the authentication data {KPm7 // Cm7} KPa from the authentication data holding unit 5200 via the bus BS5, and outputs the {KPm7 // Cm7} KPa via the bus BS5, the interface 5224, and the terminal 5226. (Step S713).
【0247】
The license management module 511 receives the content ID, the license purchase condition data AC, and the delivery request in addition to the authentication data {KPm7 // Cm7} KPa from the license management device 520 (step S714).
【0248】
In the license management module 511, the authentication data {KPm7 // Cm7} KPa from the license management device 520 is decrypted with the public authentication key KPa (step S715). Then, the license management module 511 determines whether or not the processing is performed normally based on the decryption processing result, that is, the license management device 520 holds the public encryption key KPm7 and the certificate Cm7 from the legitimate license administration device. In order to certify the data, an authentication process is performed to determine whether or not the authorized authority has received the encrypted authentication data for certifying its validity (step S716). If it is determined that the authentication data is valid, the license management module 511 approves and accepts the public encryption key KPm7 and the certificate Cm7. Then, the process proceeds to the next process (step S717). If it is not valid authentication data, it is disapproved and the process ends without accepting the public encryption key KPm7 and the certificate Cm7 (step S743).
【0249】
Upon recognition that the device is legitimate as a result of authentication, the license management module 511 then tells the HDD 530 whether the class certificate Cm7 of the license management device 520 is listed in the certificate revocation list CRL. If it is queried and these class certificates are included in the certificate revocation list, ripping ends here (step S743).
【0250】
On the other hand, if the class certificate of the license management device 520 is not included in the certificate revocation list, the process proceeds to the next process (step S717).
【0251】
When the authentication results confirm that the access is from a license management device with valid authentication data and the class is not included in the certificate revocation list, the license management module 511 generates a new session key Ks2. (Step S718). The license management module 511 encrypts the session key Ks2 with the public encryption key KPm7, generates the encrypted data {Ks2} Km7 (step S719), and transfers the encrypted data {Ks2} Km7 to the license management device 520 via the bus BS2. Output to (step S720). Then, the controller 5220 of the license management device 520 receives the encrypted data {Ks2} Km7 via the terminal 5226, the interface 5224, and the bus BS5, and the decryption processing unit 5222 secretly decrypts the encrypted data {Ks2} Km7. Decrypt with key Km7 and accept session key Ks2 (step S721).
【0252】
With reference to FIG. 22, the session key generator 5218 generates the session key Ks2a (step S722), and the controller 5220 renews the certificate revocation list CRL from the CRL area 5215A of the memory 5215 via the bus BS5. Is obtained and the update date and time CRL date is given to the changeover switch 5246 via the bus BS5 (step S723). The encryption processing unit 5206 encrypts the session key Ks2a, the public encryption key KPmc8, and the update date / time CRLdate acquired by sequentially switching the changeover switch 5246 with the session key Ks2 from the decryption processing unit 5222, and the encrypted data {Ks2a / / KPmc8 // CRLdate} Ks2 is generated, and the controller 5220 outputs the encrypted data {Ks2a // KPmc8 // CRLdate} Ks2 via bus BS5, interface 5224, and terminal 5226 (step S724).
【0253】
The license management module 511 receives the encrypted data {Ks2a // KPmc8 // CRLdate} Ks2, decrypts it with the session key Ks2, and accepts the session key Ks2a, the public encryption key KPmc8, and the update date and time CRLdate (step S725). .. Then, the license management module 511 encrypts the binding license (transaction IDb, content IDb, binding key Kb, access restriction information ACmb, and playback restriction information ACpb) with the public encryption key KPmc8 and encrypts the encrypted data {transaction IDb // content. Generate IDb // Kb // ACmb // ACpb} Kmc8 (step S726).
【0254】
After that, the license management module 511 determines whether the certificate revocation list stored in the CRL area 5215A of the memory 5215 of the license management device 520 is the latest based on the update date and time CRL date, and when it is determined to be the latest, Go to step S728. If the certificate revocation list is not up-to-date, the process proceeds to step S730 (step S727).
【0255】
When the certificate revocation list is determined to be up-to-date, the license management module 511 transfers the encrypted data {transaction IDb // content IDb // Kb // ACmb // ACpb} Kmc8 to the session key generated on the license management device 520. It is encrypted by Ks2a, and encrypted data {{transaction IDb // content IDb // Kb // ACmb // ACpb} Kmc8} Ks2a is generated and output to the license management device 520 (step S728).
【0256】
Then, the controller 5220 of the license management device 520 receives the encrypted data {{transaction IDb // content IDb // Kb // ACmb // ACpb} Kmc8} Ks2a via the terminal 5226, the interface 5224, and the bus BS5. Then, the decryption processing unit 5212 decrypts the encrypted data {{transaction IDb // content IDb // Kb // ACmb // ACpb} Kmc8} Ks2a with the session key Ks2a, and the encrypted data {transaction IDb // content. Accept IDb // Kb // ACmb // ACpb} Kmc8 (step S729). After that, the process proceeds to step S734 in FIG.
【0257】
On the other hand, if it is determined in step S727 that the certificate revocation list is not the latest, the license management module 511 acquires the latest certificate revocation list CRL from the HDD 530 via the bus BS2, and obtains the difference CRL which is the difference data. Generate (step S730). Then, the license management module 511 receives the differential CRL of the certificate revocation list supplied from the HDD 530 via the bus BS2, and receives the encrypted data {transaction IDb // content IDb // Kb // ACmb // ACpb} Kmc8. And the difference CRL of the certificate revocation list are encrypted by the session key Ks2a generated in the license management device 520. Encrypted data {Difference CRL // {Transaction IDb // Content IDb // Kb // ACmb // ACpb} Output Kmc8} Ks2a to the license management device 520 (step S731).
【0258】
Controller 5220 of license management device 520 sends encrypted data {difference CRL // {transaction IDb // content IDb // Kb // ACmb // ACpb} Kmc8} Ks2a via terminal 5226, interface 5224, and bus BS5. Upon receiving, the decryption processing unit 5212 decrypts the encrypted data {difference CRL // {transaction IDb // content IDb // Kb // ACmb // ACpb} Kmc8} Ks2a with the session key Ks2a and encrypts it with the difference CRL. Accept the data {transaction IDb // content IDb // Kb // ACmb // ACpb} Kmc8 (step S732).
【0259】
With reference to FIG. 23, after step S729 or step S733, the decryption processing unit 5204 uses the secret decryption key Kmc8 from the Kmc holding unit 5202 to encrypt the data {transaction IDb // content IDb // Kb // ACmb // Decrypts ACpb} Kmc8 and accepts transaction IDb, content IDb, binding key Kb, access restriction information ACmb, and playback restriction information ACpb (step S734).
【0260】
The license management module 511 then enters the entry number for storing the binding license into the license management device 520 via bus BS2 (step S735). The controller 5220 of the license management device 520 receives the entry number via the terminal 5226, the interface 5224, and the bus BS5, and the transaction IDb and the content IDb received in the license area 5215B of the memory 5215 specified by the received entry number. , Binding key Kb, access restriction information ACmb, and playback restriction information ACpb (step S736).
【0261】
Then, the license management module 511 encodes the music data acquired from the music CD into a predetermined method to generate the content data Dc (step S737), encrypts the content data with the license key Kc, and encrypts the encrypted content data {Dc. } Generate Kc (step S738). After that, the license management module 511 generates additional information Dc-inf of the content data based on the information from the user input via the keyboard 560 and the information from the music CD (step S739), and the encrypted content. The data {Dc} Kc and the additional information Dc-inf are recorded in the HDD 530 via the bus BS2 (step S739a).
【0262】
Then, the license management module 511 binds the generated license (transaction ID, content ID, license key Kc, access restriction information ACm, and playback restriction information ACp) to the chuckout information generated in step S704 or step S706. Generate encrypted sensitive information encrypted by Kb (step S740). Then, the license management module 511 creates a license management file for the recorded encrypted content data {Dc} Kc and the additional information Dc-inf, including the encrypted confidential information and the plaintext transaction ID and the content ID, and manages the license. Send the license management file to device 520 (S741). The control unit 5220 of the license management device 520 receives the license management file via the terminal 5226, the interface 5224, and the bus BS5, and records the received license management file in the management file area 5215C of the memory 5215 (step S741a). .. After that, the license management module 511 adds the name of the received content to the content list file recorded in the HDD 530 (step S742), and the entire process is completed (step S743).
【0263】
In this way, encrypted content data and a license can be obtained by ripping from a music CD. Then, the encrypted content data and the license acquired by ripping from the music CD are managed by the same method as the encrypted content data and the license acquired by the license management module 511.
【0264】
The process from step S274 to step S298 for storing the binding license in the license management device 520 in the flowchart of distribution 2 shown in FIGS. 14, 15, 16, 17, 18 and 19, and FIGS. 20 and 21. , The processes from step S712a to step S739 in the ripping flowchart shown in FIGS. 22 and 23 are the same processes.
【0265】
Reference is made to the management of the encrypted content data and the license received by the license management module 511 or the license management device 520 of the personal computer 50. The HDD 530 of the personal computer 50 includes the content list file 150 and the content files 1531 to 153n.
【0266】
The content list file 150 is a data file in the form of a list of owned contents, and information indicating information (song name, artist name, etc.) for each content, and information indicating the content files 1531 to 153n and the license management files 1521-152n (). File name) etc. are included. The information for each content is described automatically by acquiring necessary information from the additional information Data-inf at the time of reception or by the instruction of the user. In addition, it is possible to manage the non-reproducible contents of only the content file or only the license management file in the list.
【0267】
The content files 1531 to 153n are files for recording the encrypted content data {Dc} Kc and the additional information Dc-inf received by the license management module 511 or the license management device 520, and are provided for each content.
【0268】
Further, the memory 5215 of the license management device 520 includes a license area 5215B including the license and the binding license acquired in distribution 1 and a management file area 5215C including the license management files 1521-152n.
【0269】
The license management files 1521-152n have a one-to-one correspondence with the content files 1531 to 153n, respectively, and are files for managing the license received by the license management module 511 or the license management device 520. As is clear from the above explanation, the license cannot usually be referred to, but the information other than the license key Kc is not a problem in terms of copyright protection unless it can be rewritten by the user. However, it is not preferable to manage it separately from the license key Kc in operation because it leads to a decrease in security. Therefore, the transaction ID and content ID that can be referred to in plain text when receiving the license distribution, and the copy of the matters restricted by the access control information ACm and the playback control information ACp that can be easily determined from the license purchase condition AC are written in plain text. And record. In addition, the entry number is recorded when the license is recorded on the license management device 520, and confidential information (license and tick-out information) is recorded for the license under the control of the license management module 511. The confidential information is the encrypted version of the license and checkout information received by the binding key generated by the license management module 511.
【0270】
The license management files 1521,1522,1524, 151n contain entry numbers 0,1,2, m, respectively. It specifies the management area for licenses (license ID, license key Kc, access restriction information ACm and expiration date ACm) received by license management device 520 and managed in license area 5215B of memory 5215 of license management device 520. It is a number.
【0271】
Therefore, when the encrypted content data recorded in the content list file 1531 is moved to the memory card 110 mounted on the playback terminal 100, the name of the encrypted content data to be moved is specified in the content list file 150, and the specified name is specified. Extract the file name of the content file corresponding to the name and the file name of the license management file. Then, the content files 1531 to 1531 are searched, the content file 1531 is extracted, and the encrypted content data to be moved is read from the content file 1531.
【0272】
On the other hand, the file name of the license management file corresponding to the content file 1531 is input to the license management device 520, and the license management file 1521 is read from the management file area 5215C based on the input file name. Then, the entry number "0" stored in the license management file 1521 is read, and the license recorded in the area specified by the entry number "0" is read based on the read entry number "0". License. As a result, the license for decrypting the encrypted content data to be moved is read from the license management device 520.
【0273】
Then, after moving the license, when duplication of the license is prohibited, the license in the entry number 0 specified in the license area 5215B of the memory 5215 is deleted, so correspondingly like the license management file 1523. "No license" is recorded in.
【0274】
In addition, the confidential information storing the license of the encrypted content data received by the license management module 511 is managed by the license management file 1522,152n. The license management files 1522 and 152n are confidential information in which the license for playing the encrypted content data received by the license management module 511 is encrypted with the binding key and the entry number for specifying the area where the binding license is stored. And include.
【0275】
Then, for example, when moving the encrypted content data recorded in the content file 1532 to the personal computer 80, the content files 1531 to 153n are searched based on the file name specified in the content list file 150, and the content file 1532 is extracted. Then, read the encrypted content data from the content file 1532. In addition, the file name of the license management file 1522 corresponding to the content file 1532 is input to the license management device 520, and the license management file 1522 is read based on the file name. Then, the entry number "1" is acquired from the license management file 1522, the binding key Kb stored in the area specified by the acquired entry number "1" is acquired, and the confidential information is obtained by the acquired binding key Kb. Decrypt and obtain a plaintext license. Therefore, the license of the encrypted content data acquired by the license management module 511 cannot be acquired without the binding key Kb. That is, the binding license including the binding key Kb is considered to be a license for acquiring the license acquired by the license management module 511.
【0276】
Then, the license of the encrypted content data acquired by the license management module 511 and the license acquired by the license management device 520 are similarly stored in the license area 5215B of the memory 5215 of the license management device 520.
【0277】
When there are a plurality of encrypted content data acquired by the license management module 511, a new binding license is generated each time the encrypted content data and the license are acquired.
【0278】
[Movement 1] In the data distribution system shown in FIG. 1, the operation of transmitting the encrypted content data and the license distributed from the distribution server 10 to the license management device 520 of the personal computer 50 to the memory card 110 mounted on the playback terminal 100. Will be described. This operation is called "movement 1".
【0279】
25 to 28 show the movement operation in which the license management device 520 moves the encrypted content data and the license received from the distribution server 10 to the memory card 110 mounted on the playback terminal 100 in the data distribution system shown in FIG. It is 1st to 4th flowcharts for demonstrating.
【0280】
With reference to FIG. 25, when a move request is input from the keyboard 560 of the personal computer 50 (step S300), the controller 510 makes an authentication data transmission request a via the USB interface 550, the terminal 580, and the USB cable 70. And sends it to the playback terminal 100 (step S302). Then, the controller 1106 of the playback terminal 100 receives the authentication data transmission request via the terminal 1114, the USB interface 1112, and the bus BS3, and sends the authentication data transmission request via the bus BS3 and the memory card interface 1200 to the memory card 110. Send to. Then, the controller 1420 of the memory card 110 receives the authentication data transmission request via the terminal 1426, the interface 1424, and the bus BS4 (step S304).
【0281】
When the controller 1420 receives the authentication data transmission request a, it reads the authentication data {KPm3 // Cm3} KPa from the authentication data holding unit 1400 via the bus BS4, and reads the read authentication data {KPm3 // Cm3} KPa. Output to the playback terminal 100 via bus BS4, interface 1424 and terminal 1426. Then, the controller 1106 of the playback terminal 100 receives the authentication data {KPm3 // Cm3} KPa via the memory card interface 1200 and the bus BS3, and is a personal computer via the bus BS3, the USB interface 1112, the terminal 1114, and the USB cable 70. Send the authentication data {KPm3 // Cm3} KPa to 50 (step S306).
【0282】
Then, the controller 510 of the personal computer 50 receives the authentication data {KPm3 // Cm3} KPa via the terminal 580 and the USB interface 550 (step S308), and buses the received authentication data {KPm3 // Cm3} KPa. Send to license management device 520 via BS2. The controller 5220 of the license management device 520 receives the authentication data {KPm3 // Cm3} KPa via the terminal 5226, the interface 5224, and the bus BS5, and decrypts the received authentication data {KPm3 // Cm3} KPa. Give to 5208. The authentication processing unit 5208 executes the decryption processing of the authentication data {KPm3 // Cm3} KPa by the authentication key KPa from the KPa holding unit 5214 (step S310). From the decryption processing result in the decryption processing unit 5208, the controller 5220 determines whether or not the processing is performed normally, that is, the memory card 110 holds the public encryption key KPm3 and the certificate Cm3 from the legitimate memory card. In order to authenticate, an authentication process is performed to determine whether or not the authorized authority has received the encrypted authentication data for certifying its validity (step S312). If it is determined that the authentication data is valid, the controller 5220 approves and accepts the public encryption key KPm3 and the certificate Cm3. Then, the process proceeds to the next process (step S314). If it is not valid authentication data, it is disapproved and the process ends without accepting the public encryption key KPm3 and the certificate Cm3 (step S404).
【0283】
If the authentication results recognize that it is a legitimate memory card, the controller 5220 then determines whether the class certificate Cm3 for memory card 110 is listed in the certificate revocation list CRL. If you query area 5215A and these class certificates are on the certificate revocation list, you end the move operation here (step S404).
【0284】
On the other hand, if the class certificate of the memory card 110 is not included in the certificate revocation list, the process proceeds to the next process (step S314).
【0285】
As a result of authentication, when it is confirmed that the access is from a mobile phone having a memory card with valid authentication data and the class is not included in the certificate revocation list, in the license management device 520, the controller 5220 is set. Obtain the transaction ID, which is the management code for identifying the move, from the license area 5215B of the memory 5215 (step S316). Then, the session key generator 5218 generates the session key Ks22 for movement (step S318). The session key Ks22 is encrypted by the encryption processing unit 5210 by the public encryption key KPm3 corresponding to the memory card 110 obtained by the decryption processing unit 5208 (step S320). The controller 5220 acquires the encrypted data {Ks22} Km3 via the bus BS5, adds the transaction ID acquired from the memory 5215 to the encrypted data {Ks22} Km3, and adds the transaction ID // {Ks22} Km3 to the bus BS5, Output via interface 5224 and terminal 5226 (step S322).
【0286】
With reference to FIG. 26, controller 510 of personal computer 50 receives transaction ID // {Ks22} Km3 via bus BS2 (step S324), via USB interface 550, terminal 580, and USB cable 70. Transaction ID // {Ks22} Km3 is sent to the playback terminal 100 (step S324). Then, the controller 1106 of the playback terminal 100 receives the transaction ID // {Ks22} Km3 via the terminal 1114, the USB interface 1112, and BS3, and receives the received transaction ID // {Ks22} Km3 as the memory card interface 1200. It sends to the memory card 110 via. Then, the controller 1420 of the memory card 110 receives the transaction ID // {Ks22} Km3 via the terminal 1426, the interface 1424, and the bus BS4 (step S326). The decryption processing unit 1422 receives {Ks22} Km3 from the controller 1420 via the bus BS4, decodes {Ks22} Km3 by the secret decryption key Km3 from the Km holding unit 1421, and receives the session key Ks22 (step S328). .. Then, the session key generator 1418 generates the session key Ks2 (step S330), and the controller 1420 acquires the update date and time CRLdate of the certificate revocation list CRL from the CRL area 1415A of the memory 1415 via the bus BS4, and the controller 1420 obtains the update date and time CRLdate of the certificate revocation list CRL. The acquired update date and time CRL date is given to the changeover switch 1446 (step S332).
【0287】
Then, the encryption processing unit 1406 encrypts the session key Ks2, the public encryption key KPmc4, and the update date / time CRLdate acquired by sequentially switching the terminals of the changeover switch 1446 with the session key Ks22 decrypted by the decryption processing unit 1404. Cryptographic data {Ks2 // KPmc4 // CRLdate} Generate Ks22. The controller 1420 outputs the encrypted data {Ks2 // KPmc4 // CRLdate} Ks22 to the playback terminal 100 via the bus BS4, the interface 1424 and the terminal 1426, and the controller 1106 of the playback terminal 100 passes through the memory card interface 1200. Receives the encrypted data {Ks2 // KPmc4 // CRLdate} Ks22. Then, the controller 1106 transmits to the personal computer 50 via the USB interface 1112, the terminal 1114, and the USB cable 70 (step S334).
【0288】
Controller 510 of personal computer 50 receives encrypted data {Ks2 // KPmc4 // CRLdate} Ks22 via terminal 580 and USB interface 550 (step S336) and encrypted data {Ks2 // via bus BS2. Enter KPmc4 // CRLdate} Ks22 into the license management device 520 (step S338). The controller 5220 of the license management device 520 receives the encrypted data {Ks2 // KPmc4 // CRLdate} Ks22 via the terminal 5226, the interface 5224 and the bus BS5, and the received encrypted data {Ks2 // KPmc4 // CRLdate} Ks22 is given to the decryption processing unit 5212. The decryption processing unit 5212 decrypts the encrypted data {Ks2 // KPmc4 // CRLdate} Ks22 by the session key Ks22 from the session key generation unit 5218, and receives the session key Ks2, the public encryption key KPmc4, and the update date / time list CRLdate. (Step S340).
【0289】
The controller 5220 then searches for a license management file based on the entered file name and obtains the license entry number contained in the searched license management file from the management file area 5215C (step S342). Then, the controller 5220 reads the transaction ID, the content ID, the license key Kc, the access restriction information ACm, and the playback restriction information ACp from the area specified by the acquired entry number (step S344).
【0290】
Upon acceptance of the access restriction information ACm, the controller 5220 confirms the access restriction information ACm (step S346). That is, the controller 5220 confirms three items by the access restriction information ACm for the license to move to the memory card 110 mounted on the playback terminal 100 based on the acquired access restriction information ACm. First, make sure that the move flag is movable. If the move flag is prohibited, you cannot move. Second, make sure that the destination security level is the level allowed by the security flag. Based on the certificate Cm3 received in step S312, it can be specified by checking the contents of the certificate Cm3 whether the license is managed by hardware or software at the transfer destination of the license. Access restriction information Determines whether the license can be transferred by comparing it with the security flag in ACm. Thirdly, if the license does not allow the encrypted content data to be played back, that is, if the number of playbacks has reached the limit of the access restriction information ACm, the encrypted content data cannot be played back by the license. This is because there is no point in moving the encrypted content data and the license to the memory card 110 mounted on the playback terminal 100. When the above three items are satisfied, it is judged that the license can be moved, and the process proceeds to step S348.
【0291】
If even one of the above three items is not satisfied in step S346, the process proceeds to step S404 and the movement operation ends.
【0292】
With reference to FIG. 27, the encryption processing unit 5217 encrypts the license with the public encryption key KPmc4 unique to the license management device 520 obtained by the decryption processing unit 5212, and the encrypted data {transaction ID // content ID // Kc. // ACm // ACp} Generate Kmc4 (step S348). Then, the update date and time of the certificate revocation list sent from the memory card 110 and the update date and time of the certificate revocation list CRL stored in the CRL area 5215A of the memory 5215 are acquired, and any certificate revocation list CRL is new. Judge whether the certificate revocation list CRL stored in the CRL area 5215A of the memory 5215 and the certificate revocation list CRL stored in the memory card 110 are old or new. When the certificate revocation list CRL stored in the memory card 110 is newer or the same, the process proceeds to step S350. Conversely, if the certificate revocation list CRL stored in the memory card 110 is older, the process proceeds to step S362 (step S350).
【0293】
When it is determined that the certificate revocation list CRL stored in the memory card 110 is newer or the same, the encryption processing unit 5206 performs the encryption data {transaction ID // content output from the encryption processing unit 5217. ID // Kc // ACm // ACp} Kmc4 is encrypted by the session key Ks2 generated in the session key generator 5218, and the encrypted data {{transaction ID // content ID // Kc // ACm // Output ACp} Kmc4} Ks2 to bus BS5. Then, the controller 5220 transmits the encrypted data {{transaction ID // content ID // Kc // ACm // ACp} Kmc4} Ks2 on the bus BS5 to the personal computer 50 via the interface 5224 and the terminal 5226 ( Step S352). Then, the controller 5220 deletes the license in the entry number specified in the license area 5215B of the memory 5215 (step S354).
【0294】
Controller 510 of personal computer 50 receives encrypted data {{transaction ID // content ID // Kc // ACm // ACp} Kmc4} Ks2 and plays it through USB interface 550, terminal 580, and USB cable 70. Send to terminal 100 (step S356).
【0295】
The controller 1106 of the playback terminal 100 receives the encrypted data {{transaction ID // content ID // Kc // ACm // ACp} Kmc4} Ks2 via the terminal 1114, the USB interface 1112, and the bus BS3, and the encrypted data {{transaction ID // content ID // Kc // ACm // ACp} Kmc4} Ks2. The received encrypted data {{transaction ID // content ID // Kc // ACm // ACp} Kmc4} Ks2 is transmitted to the memory card 110 via the bus BS3 and the memory card interface 1200. Then, the controller 1420 of the memory card 110 receives the encrypted data {{transaction ID // content ID // Kc // ACm // ACp} Kmc4} Ks2 via the terminal 1426, the terminal 1424, and the bus BS4 ( Step S358).
【0296】
The decryption processing unit 1412 of the memory card 110 receives the encrypted data {{transaction ID // content ID // Kc // ACm // ACp} Kmc4} Ks2 via the bus BS4, and is generated by the session key generation unit 1418. Decrypt with the session key Ks2, and accept {transaction ID // content ID // Kc // ACm // ACp} Kmc4 (step S360). After that, the process proceeds to step S376 shown in FIG.
【0297】
On the other hand, in step S350, when it is determined that the certificate revocation list CRL stored in the memory card 110 is older, the controller 5220 of the license management device 520 is updated from the CRL area 5215A of the memory 5215 via the bus BS5. Obtain the data CRL of the certificate revocation list of (step S362).
【0298】
The cryptographic processing unit 5206 receives the output of the cryptographic processing unit 5217 and the data CRL of the certificate revocation list obtained from the memory 5215 by the controller 5220 via the bus BS5, respectively, via the changeover switches 5242 and 5246, respectively, and receives a session. It is encrypted by the session key Ks2 generated in the key generator 5218. The encrypted data output from the encryption processing unit 5206 is output to the personal computer 50 via the {CRL // {transaction ID // content ID / interface 5224 and the terminal 5226 (step S364). The controller 5220 then deletes the license within the specified entry number in the license area 5215B of memory 5215 (step S366).
【0299】
The controller 510 of the personal computer 50 receives the output encrypted data {CRL // {transaction ID // content ID // Kc // ACm // ACp} Kmc4} Ks2, USB interface 550, terminal 580, and The encrypted data {CRL // {transaction ID // content ID // Kc // ACm // ACp} Kmc4} Ks2 is transmitted to the playback terminal 100 via the USB cable 70 (step S368). Controller 1106 of playback terminal 100 receives encrypted data {CRL // {transaction ID // content ID // Kc // ACm // ACp} Kmc4} Ks2 via terminal 1114, USB interface 1112, and bus BS3. , Sends encrypted data {CRL // {transaction ID // content ID // Kc // ACm // ACp} Kmc4} Ks2 to memory card 110 via bus BS3 and memory card interface 1200. Then, the controller 1420 of the memory card 110 transmits the encrypted data {CRL // {transaction ID // content ID // Kc // ACm // ACp} Kmc4} Ks2 via the terminal 1426, the interface 1424, and the bus BS4. Receive (step S370).
【0300】
In the memory card 110, the decoding processing unit 1412 decodes the received data on the bus BS4 using the session key Ks2 given by the session key generating unit 1418, and decodes the CRL and {transaction ID // content ID // Kc //. Accept ACm // ACp} Kmc4 (step 372). The controller 1420 receives the data CRL received by the decryption processing unit 1412 via the bus BS4, and rewrites the CRL area 1415A of the memory 1415 by the received data CRL (step S374).
【0301】
Steps S352, S354, S356, S358, S360 license if the certificate revocation list CRL stored on the memory card 110 is newer or the same as the certificate revocation list CRL stored on the license management device 520. It is an operation to move the key Kc etc. to the memory card 110, and in steps S362, S364, S366, S368, S370, S372, S374, the certificate revocation list CRL stored in the memory card 110 becomes the license management device 520. This is an operation to move the license key Kc, etc. to the memory card 110 when the certificate revocation list is older than the stored certificate revocation list CRL. In this way, the certificate revocation list CRL stored in the memory card 110 is checked one by one, and when it is not updated, it is updated to a newer certificate revocation list CRL. Therefore, it is possible to prevent the output of the license from the memory card 110 to other unlicensed memory cards, license management devices, license management modules, and content playback circuits.
【0302】
With reference to FIG. 28, after step S360 or step S374, at the direction of controller 1420, the encryption license {transaction ID // content ID // Kc // ACm // ACp} Kmc4 is added to the decryption processing unit 1404. It is decrypted by the private decryption key Kmc4 and the license (license key Kc, transaction ID, content ID, access restriction information ACm and playback restriction information ACp) is accepted (step S376).
【0303】
In this way, by exchanging the encryption keys generated by the license management device and the memory card, performing encryption using the encryption keys received by each other, and transmitting the encrypted data to the other party, respectively. It is possible to perform de facto mutual authentication in the transmission and reception of the encrypted data of the above, and it is possible to improve the security in the movement operation of the encrypted content data and the license.
【0304】
The controller 510 of the personal computer 50 transmits the entry number for storing the license transferred to the memory card 110 to the playback terminal 100 via the USB interface 550, the terminal 580, and the USB cable 70, and the controller of the playback terminal 100. The 1106 receives the entry number via terminal 1114, the USB interface 1112, and the bus BS3 and sends it to the memory card 110 via the bus BS3 and the memory card interface 1200 (step S378). Then, the controller 1420 of the memory card 110 receives the entry number via the terminal 1426 and the interface 1424, and the license acquired in step S376 (license key Kc) is applied to the license area 1415B of the memory 1415 specified by the received entry number. , Transaction ID, content ID, access restriction information ACm and playback restriction information ACp) (step S380).
【0305】
The controller 510 of the personal computer 50 includes the license entry number stored in the memory 1415 of the memory card 110 and the encrypted content data {Dc} Kc to be moved to the memory card 110 including the plain transaction ID and the content ID. Additional information Generate a license management file for Dc-inf and send it to the memory card 110 (step S382).
【0306】
The controller 1420 of the memory card 110 receives the license management file via the playback terminal 100, and records the received license management file in the data area 1415D of the memory 1415 (step S384).
【0307】
Then, the controller 5220 of the license management device 520 updates the license management file for the license moved to the memory card 110 among the licenses recorded in the memory 5215 without a license (step S386). After that, the controller 510 of the personal computer 50 acquires the encrypted content data {Dc} Kc and the additional information Dc-inf to be moved to the memory card 110 from the HDD 530, and stores the {Dc} Kc // Dc-inf in the memory. Send to card 110 (step S390). The controller 1420 of the memory card 110 receives the {Dc} Kc // Dc-inf via the playback terminal 100 (step S392), and the {Dc} Kc // Dc-inf received via the bus BS4 is stored in the memory 1415. Record in the data area 1415D of (step S394).
【0308】
Then, the controller 510 of the personal computer 50 creates a playlist in which the music moved to the memory card 110 is added (step S396), and transmits the playlist and the playlist rewriting instruction to the memory card 110 (step S398). ). The controller 1420 of the memory card 110 receives the playlist and the rewrite instruction via the playback terminal 100 (step S400), and rewrites the playlist of the memory 1415 to the received playlist via the bus BS4 (step S402). The move operation ends (step S404).
【0309】
In this way, after confirming that the memory card 110 mounted on the playback terminal 100 is a legitimate device and at the same time that the public encryption key KPm3 that can be encrypted and transmitted together with the class certificate Cm3 is valid. , Class certificate Cm3 can only move content data to a certificate revocation list, that is, a move request to a memory card that is not on the class certificate list that has been decrypted by the public encryption key KPm3. It is possible to prohibit unauthorized movement to a memory card and movement using a decrypted class key. Further, by using this mobile operation, the user of the mobile phone 102 who does not have the communication function with the distribution server 10 can also receive the encrypted content data and the license to the memory card via the personal computer 50. User convenience is improved.
【0310】
In the above, the transfer of the license from the license management device 520 of the personal computer 50 to the memory card 110 has been described, but the transfer of the license from the memory card 110 to the license management device 520 is also shown in FIGS. 25 to 28. It is done according to the flow chart. Further, the license can be transferred from the memory card 110 to another memory card, and similarly, the license is transferred according to the flowcharts shown in FIGS. 25 to 28.
【0311】
The personal computer 50 can move the encrypted content data and license received from the distribution server 10 to the memory card 110 only for the encrypted content data and license hard received by the license management device 520 from the distribution server 10. The encrypted content data and license softly received by the license management module 511 from the distribution server 10 cannot be transmitted to the memory card by the concept of "move". The license management module 511 exchanges authentication data, encryption key, etc. with the distribution server 10 in software with a security level lower than that of the license management device 520, and receives the encrypted content data and the license. The chances of breaking encryption in operation are higher than when receiving encrypted content data and licenses through license management device 520. Therefore, "move" the encrypted content data and licenses received and managed by the lower security level to the memory card 110 that receives and manages the encrypted content data and licenses by the same security level as the license management device 520. If it can be freely transferred by the concept of "move", the security level of the memory card 110 is lowered. To prevent this, the encrypted content data and the license received by the license management module 511 are stored in the memory by the concept of "move". It is not possible to send to card 110.
【0312】
However, assuming that no low-security encrypted content data and licenses received by the license management module 511 can be transferred to the memory card 110, it allows free copying of the content data while protecting the copyright. Contrary to the purpose of the data distribution system, the convenience of the user is not improved. Therefore, it is possible to send to the memory card 110 by checking out on the premise of the check-in of the license received by the license management module 511 according to the concept of lending (check-out) and check-in (return) described below.
【0313】
[Checkout] In the data distribution system shown in FIG. 1, the operation of transmitting the encrypted content data and the license distributed from the distribution server 10 to the license management module 511 of the personal computer 50 to the memory card 110 mounted on the playback terminal 100. Will be described. This operation is called "checkout".
【0314】
29 to 33 show the encrypted content data and the license received from the distribution server 10 by the license management module 511 to the memory card 110 mounted on the playback terminal 100 on condition that they are returned in the data distribution system shown in FIG. It is 1st to 5th flowcharts for demonstrating the check-out operation of renting out.
【0315】
As shown in Figure 29, when a checkout request is entered from keyboard 560 of personal computer 50 (step S500), license management module 511 manages the authentication data {KPm5 // Cm5} KPa via bus 2. Output to device 520 (step S501). The license management device 520 receives the authentication data {KPm5 // Cm5} KPa from the license management module 511, and the decryption processing unit 5208 decrypts the authentication data {KPm5 // Cm5} KPa with the public authentication key KPa (step S502). ..
【0316】
From the decryption processing result in the decryption processing unit 5208, the controller 5220 determines whether or not the processing is performed normally, that is, the license management module 511 holds the public encryption key KPm5 and the certificate Cm5 from the legitimate license administration module. In order to certify that, an authentication process is performed to determine whether or not the authorized authority has received the encrypted authentication data for certifying its validity (step S503). If it is determined that the authentication data is valid, the controller 5220 approves and accepts the public encryption key KPm5 and the certificate Cm5. Then, the process proceeds to the next process (step S504). If it is not valid authentication data, it is disapproved and the process ends without accepting the public encryption key KPm5 and the certificate Cm5 (step S561).
【0317】
Upon authentication, the controller 5220 then determines whether the class certificate Cm5 for license management module 511 is listed in the certificate revocation list CRL for the CRL in memory 5215. If you query area 5215A and these class certificates are on the certificate revocation list, end the delivery session here (step S561).
【0318】
On the other hand, if the class certificate of the license management module 511 is not included in the certificate revocation list, the process proceeds to the next process (step S504).
【0319】
If the result of the authentication is that the access is from the license management module 511, which has a license management device with valid authentication data, and the class is not included in the certificate revocation list, the session on the license management device 520 The key generator 5208 generates the session key Ks2 (step S505), and the encryption processing unit 5210 encrypts the session key Ks2 with the public encryption key KPm5 and outputs the encrypted data {Ks2} Km5 (step S506).
【0320】
The controller 5220 outputs the encrypted data {Ks2} Km5 via the bus BS5, the interface 5224, and the terminal 5226, and the license management module 511 receives the encrypted data {Ks2} Km5 via the bus BS2 and secretly receives the encrypted data {Ks2} Km5. The encryption data {Ks2} Km5 is decrypted by the decryption key Km5, and the session key Ks2 is accepted (step S507). Then, the license management module 511 generates the session key Ks2a (step S508), encrypts the session key Ks2a with the session key Ks2, and outputs the encrypted data {Ks2a} Ks2 to the license management device 520 via the bus BS2. (Step S509).
【0321】
The controller 5220 of the license management device 520 receives the encrypted data {Ks2b} Ks2a via the terminal 5226, the interface 5224, and the bus BS5, and the decryption processing unit 5212 is operated by the session key Ks2 output from the session key generator 5208. The encrypted data {Ks2a} Ks2 is decrypted and the session key Ks2a is accepted (step S510). Then, the controller 5220 acquires the entry number for identifying the area where the binding license is stored from the license management file recorded in the memory 5215 (step S511).
【0322】
With reference to FIG. 30, the controller 5220 of the license management device 520 has a binding license (transaction IDb, content IDb, binding key Kb, and control information ACmb, ACpb) stored in the area specified by the acquired entry number. ) Is obtained (step S512). When checking out the license in the sensitive information stored in the license management file 1522 in FIG. 24, the entry number is "1". Then, the controller 5220 determines whether or not to output the binding key Kb in the binding license based on the control information ACmb. That is, check the security flag and the number of times limit included in the control information ACmb. Here, when the binding license is generated, the security flag is "1" indicating a low security level, and the playback limit is unlimited. Therefore, it is always judged that output is possible, and the process does not proceed to step S561. Migrate to S514 (step S513).
【0323】
However, if the distribution server 10 mistakenly accesses a license that requires a high security level delivered to the license management device 520, the certificate Cm5 obtained in step S503 prohibits the output of the license.
【0324】
When it is determined in step S513 that the binding license can be output, the encryption processing unit 5206 decrypts the binding key Kb and the control information ACpb acquired via the changeover switch 5246 by the decryption processing unit 5212 and via the switch 5242. The encrypted data {Kb // ACpb} Ks2a is output after being encrypted with the session key Ks2a obtained in the above (step S514). The controller 5220 outputs the encrypted data {Kb // ACpb} Ks2a via the bus BS5, the interface 5224, and the terminal 5226, and the license management module 511 outputs the encrypted data {Kb // ACpb} via the bus BS2. Receives Ks2a and decrypts the encrypted data {Kb // ACpb} Ks2a with the session key Ks2a to obtain the binding key Kb and the control information ACpb (step S515). Then, the license management module 511 acquires confidential information from the license management file including the license to be checked out stored in the management file area 5215C of the license management device 520 via the bus BS2, and binds the acquired confidential information. Decrypt with key Kb, license (transaction ID, content ID, license key Kc, access restriction information ACm, playback restriction information ACp) and checkout information (checkout possible number and checkout if already checked out) Obtain the checkout transaction ID used during the checkout and the public encryption key KPmcx unique to the checkout destination memory card (step S516).
【0325】
Then, the license management module 511 confirms whether or not the number of checkouts possible included in the acquired checkout information is larger than "0" (step S519). If the number of checkouts that can be performed is "0" or less in step S519, checkout is prohibited, so the process proceeds to step S561 and the checkout operation ends. In step S519, when the number of checkouts possible is greater than "0", the license management module 511 sends a request to send authentication data via the USB interface 550, the terminal 580, and the USB cable 70 (step S520). The controller 1106 of the playback terminal 100 receives an authentication data transmission request via the terminal 1114, the USB interface 1112, and the bus BS3, and sends the received authentication data transmission request to the memory via the bus BS3 and the memory card interface 1200. Send to card 110. Then, the controller 1420 of the memory card 110 receives the authentication data transmission request via the terminal 1426, the interface 1424, and the bus BS4 (step S521).
【0326】
When the controller 1420 receives the authentication data transmission request, it reads the authentication data {KPm3 // Cm3} KPa from the authentication data holding unit 1400 via the bus BS4, and buses the read authentication data {KPm3 // Cm3} KPa. Output to the playback terminal 100 via BS4, interface 1424 and terminal 1426. Then, the controller 1106 of the playback terminal 100 receives the authentication data {KPm3 // Cm3} KPa via the memory card interface 1200 and the bus BS3, and is a personal computer via the bus BS3, the USB interface 1112, the terminal 1114, and the USB cable 70. Send the authentication data {KPm3 // Cm3} KPa to 50 (step S522).
【0327】
Then, the license management module 511 of the personal computer 50 receives the authentication data {KPm3 // Cm3} KPa via the terminal 580 and the USB interface 550 (step S523), and the received authentication data {KPm3 // Cm3} KPa. Is decrypted with the authentication key KPa (step S524).
【0328】
With reference to FIG. 31, the license management module 511 determines from the decryption processing result whether or not the processing is performed normally, that is, the memory card 110 determines the public encryption key KPm3 and the certificate Cm3 from the legitimate memory card. In order to certify that the data is retained, an authentication process is performed to determine whether or not the authorized authority has received the encrypted authentication data for certifying its validity (step S525). If it is determined that the authentication data is valid, the license management module 511 approves and accepts the public encryption key KPm3 and the certificate Cm3. Then, the process proceeds to the next process (step S526). If it is not valid authentication data, it is disapproved and the process ends without accepting the public encryption key KPm3 and the certificate Cm3 (step S561).
【0329】
When the authentication results in recognizing that it is a legitimate memory card, the license management module 511 then tells HDD530 whether the class certificate Cm3 of the memory card 110 is listed in the certificate revocation list CRL. If it is queried and these class certificates are included in the certificate revocation list, the checkout operation ends here (step S561). On the other hand, if the class certificate of the memory card 110 is not included in the certificate revocation list, the process proceeds to the next process (step S526).
【0330】
When the authentication results confirm that the access is from a mobile phone with a memory card with valid authentication data and the class is not included in the certificate revocation list, the license management module 511 identifies the checkout. Generate a checkout transaction ID, which is the management code for the operation (step S527). The license management module 511 then generates the session key Ks2b for checkout (step S528) and encrypts the generated session key Ks2b with the public encryption key KPm3 sent from the memory card 110 (step S529). .. Then, the license management module 511 transfers the checkout transaction ID // {Ks2b} Km3 by adding the checkout transaction ID to the encrypted data {Ks2b} Km3 via the USB interface 550, the terminal 580, and the USB cable 70. Send to the playback terminal 100 (step S530). Then, the controller 1106 of the playback terminal 100 receives the checkout transaction ID // {Ks2b} Km3 via the terminal 1114, the USB interface 1112, and the bus BS3, and the received checkout transaction ID // {Ks2b. } Send Km3 to the memory card 110 via the memory card interface 1200. Then, the controller 1420 of the memory card 110 receives the checkout transaction ID // {Ks2b} Km3 via the terminal 1426, the interface 1424, and the bus BS4 (step S531). The decryption processing unit 1422 receives the {Ks2b} Km3 from the controller 1420 via the bus BS4, decodes the {Ks2b} Km3 by the secret decryption key Km3 from the Km holding unit 1421, and receives the session key Ks2b (step S532). .. Then, the session key generator 1418 generates the session key Ks2c (step S533), and the controller 1420 passes through the bus BS4.
【0331】
Then, the encryption processing unit 1406 encrypts the session key Ks2c, the public encryption key KPmc4, and the update date / time CRLdate acquired by sequentially switching the terminals of the changeover switch 1446 with the session key Ks2b decrypted by the decryption processing unit 1404. Cryptographic data {Ks2c // KPmc4 // CRLdate} Generate Ks2b. The controller 1420 outputs the encrypted data {Ks2c // KPmc4 // CRLdate} Ks2b to the playback terminal 100 via the bus BS4, the interface 1424 and the terminal 1426, and the controller 1106 of the playback terminal 100 passes through the memory card interface 1200. Receives the encrypted data {Ks2c // KPmc4 // CRLdate} Ks2b. Then, the controller 1106 transmits to the personal computer 50 via the USB interface 1112, the terminal 1114, and the USB cable 70 (step S535).
【0332】
The license management module 511 of the personal computer 50 receives the encrypted data {Ks2c // KPmc4 // CRLdate} Ks2b via the terminal 580 and the USB interface 550 (step S536), and the received encrypted data {Ks2c // Decrypt KPmc4 // CRLdate} Ks2b with session key Ks2b and accept session key Ks2c, public encryption key KPmc4 and modification date CRLdate (step S537). Then, the license management module 511 sets the checkout access restriction information ACm in which the movement flag is prohibited (= 1) in order to prohibit the movement of the license from the memory card mounted on the playback terminal 100 to another memory card or the like. Generate (step S538). The number of playbacks is unlimited (= 255), and the security flag is software management (= 1).
【0333】
With reference to FIG. 32, the license management module 511 encrypts the license with the public encryption key KPmc4 unique to the memory card 110 received in step S537, and the encrypted data {checkout transaction ID // content ID // Kc. // Generate ACm // ACp} Kmc4 for checkout (step S539). Then, the update date and time of the certificate revocation list sent from the memory card 110 is compared with the update date and time of the certificate revocation list recorded in the HDD 530 managed by the license management module 511, and the certificate revocation list is stored in the memory card 110. When it is determined whether the certificate revocation list CRL or the certificate revocation list CRL managed by the license management module 511 is new and the certificate revocation list CRL stored in the memory card 110 is determined to be new, the process proceeds to step S541. Transition. If the certificate revocation list CRL managed by the license management module 511 is new, the process proceeds to step S544 (step S540).
【0334】
When the certificate revocation list CRL stored in the memory card 110 is determined to be new, the license management module 511 determines the encrypted data {transaction ID for checkout // content ID // Kc // ACm for checkout // ACp} Kmc4 is encrypted with the session key Ks2c, and the encrypted data {{checkout transaction ID // content ID // Kc // checkout ACm // ACp} Kmc4} Ks2c is USB interface 550, terminal 580. , And to the playback terminal 100 via the USB cable 70 (step S541).
【0335】
Controller 1106 of playback terminal 100 is encrypted data via terminal 1114, USB interface 1112, and bus BS3 {{Checkout transaction ID // Content ID // Kc // Checkout ACm // ACp} Kmc4} Receives Ks2c and stores the received encrypted data {{Checkout transaction ID // Content ID // Kc // Checkout ACm // ACp} Kmc4} Ks2c via bus BS3 and memory card interface 1200. Send to card 110. Then, the controller 1420 of the memory card 110 uses the encrypted data {{checkout transaction ID // content ID // Kc // checkout ACm // ACp} Kmc4 via the terminal 1426, the terminal 1424, and the bus BS4. } Receive Ks2c (step S542).
【0336】
The decryption processing unit 1412 of the memory card 110 receives the encrypted data {{checkout transaction ID // content ID // Kc // checkout ACm // ACp} Kmc4} Ks2c via the bus BS4, and receives the session key. It is decrypted by the session key Ks2c generated by the generator 1418, and {checkout transaction ID // content ID // Kc // checkout ACm // ACp} Kmc4 is accepted (step S543). After that, the process proceeds to step S549 shown in FIG.
【0337】
On the other hand, in step S540, when it is determined that the certificate revocation list CRL managed by the license management module 511 is new, the license management module 511 acquires the latest certificate revocation list CRL for the license management module from the HDD 530 ( Step S544).
【0338】
Then, the license management module 511 uses the {checkout transaction ID // content ID // Kc // checkout ACm // ACp} Kmc4 and the certificate revocation list data CRL obtained from the HDD 530 as the session key Ks2c. Encrypt the encrypted data {CRL // {checkout transaction ID // content ID // Kc // checkout ACm // ACp} Kmc4} Ks2c with USB interface 550, terminal 580 and USB cable 70 It is transmitted to the playback terminal 100 via (step S545). The controller 1106 of the playback terminal 100 uses the encrypted data {CRL // {checkout transaction ID // content ID // Kc // checkout ACm // ACp via the terminal 1114, the USB interface 1112, and the bus BS3. } Kmc4} Ks2c is received and the received encrypted data {CRL // {checkout transaction ID // content ID // Kc // checkout ACm // ACp} Kmc4} Ks2c is bus BS3 and memory card Output to the memory card 110 via interface 1200. Then, the controller 1420 of the memory card 110 sends the encrypted data {CRL // {checkout transaction ID // content ID // Kc // checkout ACm // via terminal 1426, interface 1424, and bus BS4. Receive ACp} Kmc4} Ks2c (step S546).
【0339】
In the memory card 110, the decryption processing unit 1412 decodes the received data on the bus BS4 using the session key Ks2c given by the session key generation unit 1418, and decrypts the CRL and {checkout transaction ID // content ID //. Accept Kc // ACm // ACp} Kmc4 for checkout (step 547). The controller 1420 receives the data CRL received by the decryption processing unit 1412 via the bus BS4, and rewrites the CRL area 1415A of the memory 1415 by the received data CRL (step S548).
【0340】
Steps S541, S542, S543 go to the memory card 110 such as the license key Kc when the certificate revocation list stored in the memory card 110 is newer or the same as the certificate revocation list CRL managed by the license management module 511. Step S544, S545, S546, S547, S548 is the license key Kc when the certificate revocation list stored in the memory card 110 is older than the certificate revocation list CRL managed by the license management module 511. It is a checkout operation to the memory card 110 such as. Thus, the certificate revocation list CRL sent from the memory card 110 is checked one by one, and the certificate revocation list CRL is acquired from HDD 530 when a newer certificate revocation list is managed by the license management module 511. Then, by sending the data CRL to the memory card 110, a newer certificate revocation list CRL is stored in the memory card. In this way, it is possible to prevent the output of the sense key Kc stored in the memory card 110 from the device whose license has been broken.
【0341】
With reference to FIG. 33, after step S543 or step S548, the encryption license {checkout transaction ID // content ID // Kc // checkout ACm // ACp} Kmc4 is, at the direction of controller 1420. The decryption processing unit 1404 decrypts the license (license key Kc, checkout transaction ID, content ID, checkout ACm, and playback restriction information ACp) by the private decryption key Kmc4 (step S549). Then, the controller 1420 records the received checkout transaction ID, content ID, license key Kc, checkout ACm, and playback restriction information ACp in the license area 1415B of the memory 1415 via the bus BS4 (step S550).
【0342】
In this way, by exchanging the encryption keys generated by the license management module and the memory card, executing encryption using the encryption keys received by each other, and transmitting the encrypted data to the other party, respectively. It is possible to perform de facto mutual authentication in the transmission and reception of encrypted data of the above, and it is possible to improve the security in the checkout operation of the encrypted content data and the license.
【0343】
The license management module 511 of the personal computer 50 subtracts 1 from the checkout possible number (step S551), and sets the checkout possible number, the checkout transaction ID, and the public encryption key KPmc4 unique to the checkout destination memory card. The checkout information is updated by adding, and the updated checkout information and the license (transaction ID, content ID, license key Kc, access restriction information ACm, and playback restriction information ACp) are encrypted by the binding key Kb. Update sensitive information. Then, the license management module 511 transmits the updated confidential information to the license management device 520 (step S552). The controller 5220 of the license management device 520 receives the updated confidential information via terminal 5226, interface 5224, and bus BS5, and updates and records the confidential information in the license management file by the received confidential information (step). S553).
【0344】
The license management module 511 of the personal computer 50 acquires the encrypted content data {Dc} Kc and the additional information Dc-inf to be checked out to the memory card 110 from the HDD 530, and obtains the {Dc} Kc // Dc-inf. Send to memory card 110 (step S554). The controller 1420 of the memory card 110 receives the {Dc} Kc // Dc-inf via the playback terminal 100 (step S555), and the {Dc} Kc // Dc-inf received via the bus BS4 is stored in the memory 1415. Record in the data area 1415D of (step S556).
【0345】
Then, the license management module 511 of the personal computer 50 creates a playlist in which the music checked out to the memory card 110 is added (step S557), and sends the playlist and the playlist rewriting instruction to the memory card 110. (Step S558). The controller 1420 of the memory card 110 receives the playlist and the rewrite instruction via the playback terminal 100 (step S559), and rewrites the playlist of the memory 1415 to the received playlist via the bus BS4 (step S560). The checkout operation ends (step S561).
【0346】
In this way, after confirming that the memory card 110 mounted on the playback terminal 100 is a legitimate device and at the same time that the public encryption key KPm3 encrypted and transmitted together with the class certificate Cm3 is valid. , Class certificate Cm3 checks out content data only for checkout requests to a certificate revocation list, that is, a memory card that is not on the class certificate list that has been decrypted by the public encryption key KPm3. It is possible to prohibit checkout to an unauthorized memory card and checkout using a decrypted class key. In addition, it is possible to prevent the provision of the license key to the content playback circuit having the class key decrypted from the memory card 110 of the checkout destination. A detailed description of the reproduction will be described later.
【0347】
By using this checkout operation, even a user of the playback terminal 100 that does not have a communication function with the distribution server 10 can receive the encrypted content data and the license received by the software by the personal computer 50 on the memory card. It can be done, and the convenience of the user is improved.
【0348】
[Check-in] In the data distribution system shown in FIG. 1, the operation of returning the encrypted content data and the license checked out from the license management module 511 of the personal computer 50 to the memory card 110 to the license management module 511 will be described. This operation is called "check-in".
【0349】
FIGS. 34 to 37 show the first to first check-in operations for returning the encrypted content data and the license lent to the memory card 110 by the check-out operation described with reference to FIGS. 29 to 33. It is a flowchart of 4.
【0350】
As shown in Figure 34, when a check-in request is entered from keyboard 560 of personal computer 50 (step S600), license management module 511 manages the authentication data {KPm5 // Cm5} KPa via bus 2. Output to device 520 (step S601). The license management device 520 receives the authentication data {KPm5 // Cm5} KPa from the license management module 511, and the decryption processing unit 5208 decrypts the authentication data {KPm5 // Cm5} KPa with the public authentication key KPa (step S602). ..
【0351】
From the decryption processing result in the decryption processing unit 5208, the controller 5220 determines whether or not the processing is performed normally, that is, the license management module 511 holds the public encryption key KPm5 and the certificate Cm5 from the legitimate license administration module. In order to certify that, an authentication process is performed to determine whether or not the authorized authority has received the encrypted authentication data for certifying its validity (step S603). If it is determined that the authentication data is valid, the controller 5220 approves and accepts the public encryption key KPm5 and the certificate Cm5. Then, the process proceeds to the next process (step S604). If it is not valid authentication data, it is disapproved and the process ends without accepting the public encryption key KPm5 and the certificate Cm5 (step S652).
【0352】
Upon authentication, the controller 5220 then determines whether the class certificate Cm5 for license management module 511 is listed in the certificate revocation list CRL for the CRL in memory 5215. If you query area 5215A and these class certificates are on the certificate revocation list, end the delivery session here (step S652).
【0353】
On the other hand, if the class certificate of the license management module 511 is not included in the certificate revocation list, the process proceeds to the next process (step S604).
【0354】
If the result of the authentication is that the access is from the license management module 511, which has a license management device with valid authentication data, and the class is not included in the certificate revocation list, the session is performed on the license management device 520. The key generator 5208 generates the session key Ks2 (step S605), and the encryption processing unit 5210 encrypts the session key Ks2 with the public encryption key KPm5 and outputs the encrypted data {Ks2} Km5 (step S606).
【0355】
The controller 5220 outputs the encrypted data {Ks2} Km5 via the bus BS5, the interface 5224, and the terminal 5226, and the license management module 511 receives the encrypted data {Ks2} Km5 via the bus BS2 and secretly receives the encrypted data {Ks2} Km5. The encryption data {Ks2} Km5 is decrypted by the decryption key Km5, and the session key Ks2 is accepted (step S607). Then, the license management module 511 generates the session key Ks2a (step S608), encrypts the session key Ks2a with the session key Ks2, and outputs the encrypted data {Ks2a} Ks2 to the license management device 520 via the bus BS2. (Step S609).
【0356】
The controller 5220 of the license management device 520 receives the encrypted data {Ks2b} Ks2a via the terminal 5226, the interface 5224, and the bus BS5, and the decryption processing unit 5212 is operated by the session key Ks2 output from the session key generator 5208. The encrypted data {Ks2a} Ks2 is decrypted and the session key Ks2a is accepted (step S610). Then, the controller 5220 acquires an entry number for identifying the area where the binding license is stored from the license management file recorded in the memory 5215 (step S611).
【0357】
With reference to FIG. 35, the controller 5220 of the license management device 520 has the binding license (transaction IDb, content IDb, binding key Kb, and control information) stored in the area specified by the acquired entry number "0". ACmb, ACpb) is acquired (step S612). Then, the controller 5220 determines whether or not the binding license is valid based on the control information ACmb, and if it is not valid, proceeds to step S652 and ends the distribution session. On the other hand, if the binding license is valid, the process proceeds to step S614 (step S613).
【0358】
When the binding license is determined to be valid in step S613, the encryption processing unit 5206 decrypts the binding key Kb and the control information ACpb acquired via the changeover switch 5246 by the decryption processing unit 5212 and via the switch 5242. It is encrypted with the acquired session key Ks2a and the encrypted data {Kb // ACpb} Ks2a is output (step S614). The controller 5220 outputs the encrypted data {Kb // ACpb} Ks2a via the bus BS5, the interface 5224, and the terminal 5226, and the license management module 511 outputs the encrypted data {Kb // ACpb} via the bus BS2. Receives Ks2a and decrypts the encrypted data {Kb // ACpb} Ks2a with the session key Ks2a to obtain the binding key Kb and the control information ACpb (step S615). Then, the license management module 511 acquires confidential information from the license management file including the license to be checked in, which is stored in the management file area 5215C of the license management device 520 via the bus BS2, and binds the acquired confidential information. Decrypted by key Kb, license (transaction ID, content ID, license key Kc, access restriction information ACm, playback restriction information ACp) and checkout information (checkout possible number, checkout transaction ID used at checkout and check) Obtain the public encryption key (KPmcx) unique to the out-destination memory card (step S616). Then, the license management module 511 transmits the authentication data transmission request to the playback terminal 100 via the USB interface 550, the terminal 580, and the USB cable 70 (step S618).
【0359】
Then, the controller 1106 of the playback terminal 100 receives the authentication data transmission request via the terminal 1114, the USB interface 1112, and the bus BS3, and sends the authentication data transmission request via the bus BS3 and the memory card interface 1200 to the memory card 110. Send to. Then, the controller 1420 of the memory card 110 receives the authentication data transmission request via the terminal 1426, the interface 1424, and the bus BS4 (step S619).
【0360】
When the controller 1420 receives the authentication data transmission request, it reads the authentication data {KPm3 // Cm3} KPa from the authentication data holding unit 1400 via the bus BS4, and buses the read authentication data {KPm3 // Cm3} KPa. Output to the playback terminal 100 via BS4, interface 1424 and terminal 1426. Then, the controller 1106 of the playback terminal 100 receives the authentication data {KPm3 // Cm3} KPa via the memory card interface 1200 and the bus BS3, and is a personal computer via the bus BS3, the USB interface 1112, the terminal 1114, and the USB cable 70. Send the authentication data {KPm3 // Cm3} KPa to 50 (step S620).
【0361】
The license management module 511 of the personal computer 50 receives the authentication data {KPm3 // Cm3} KPa via the terminal 580 and the USB interface 550 (step S621), and authenticates the received authentication data {KPm3 // Cm3} KPa. Decrypt with key KPa (step S622). Then, the license management module 511 authenticates from the decryption processing result whether or not the processing is performed normally, that is, that the memory card 110 holds the public encryption key KPm3 and the certificate Cm3 from the legitimate memory card. In order to do so, an authentication process is performed to determine whether or not the authorized authority has received the encrypted authentication data for certifying its validity (step S623). If it is determined that the authentication data is valid, the license management module 511 approves and accepts the public encryption key KPm3 and the certificate Cm3. Then, the process proceeds to the next process (step S624). If it is not valid authentication data, it is disapproved and the process ends without accepting the public encryption key KPm3 and the certificate Cm3 (step S652). When the authentication results in recognizing that the memory card is legitimate, the license management module 511 generates a dummy transaction ID (step S624).
【0362】
With reference to FIG. 36, the license management module 511 generates the session key Ks2b for check-in (step S625). Then, the license management module 511 encrypts the generated session key Ks2b with the public encryption key KPm3 received from the memory card 110, generates encrypted data {Ks2b} Km3 (step S626), and encrypts the encrypted data {Ks2b} Km3. The dummy transaction ID // {Ks2b} Km3 with the dummy transaction ID added to is transmitted to the playback terminal 100 via the USB interface 550, the terminal 580, and the USB cable 70 (step S627). The controller 1106 of the playback terminal 100 receives the dummy transaction ID // {Ks2b} Km3 via the terminal 1114, the USB interface 1112, and BS3, and receives the received dummy transaction ID // {Ks2b} Km3 as the memory card interface 1200. It sends to the memory card 110 via. Then, the controller 1420 of the memory card 110 receives the dummy transaction ID // {Ks2b} Km3 via the terminal 1426, the interface 1424, and the bus BS4 (step S628). The decryption processing unit 1422 receives the {Ks2b} Km3 from the controller 1420 via the bus BS4, decodes the {Ks2b} Km3 by the secret decryption key Km3 from the Km holding unit 1421, and receives the session key Ks2b (step S629). .. Then, the session key generator 1418 generates the session key Ks2c (step S630), and the controller 1420 acquires the update date and time CRLdate of the certificate revocation list CRL from the CRL area 1415A of the memory 1415 via the bus BS4, and the controller 1420 obtains the update date and time CRLdate of the certificate revocation list CRL. The acquired update date and time CRL date is given to the changeover switch 1446 (step S631).
【0363】
Then, the encryption processing unit 1406 decodes the session key Ks2c, the public encryption key KPmc4, and the update date / time CRLdate acquired by sequentially switching the terminals of the changeover switch 1446 by the decryption processing unit 1422, and via the terminal Pa of the changeover switch 1442. Encrypt with the session key Ks2b obtained in the above, and generate encrypted data {Ks2c // KPmc4 // CRLdate} Ks2b. The controller 1420 outputs the encrypted data {Ks2c // KPmc4 // CRLdate} Ks2b to the playback terminal 100 via the bus BS4, the interface 1424 and the terminal 1426, and the controller 1106 of the playback terminal 100 passes through the memory card interface 1200. Receives the encrypted data {Ks2c // KPmc4 // CRLdate} Ks2b. Then, the controller 1106 transmits the encrypted data {Ks2c // KPmc4 // CRLdate} Ks2b to the personal computer 50 via the USB interface 1112, the terminal 1114, and the USB cable 70 (step S632).
【0364】
The license management module 511 of the personal computer 50 receives the encrypted data {Ks2c // KPmc4 // CRLdate} Ks2b via the terminal 580 and the USB interface 550 (step S633), and the received encrypted data {Ks2c // Decrypt KPmc4 // CRLdate} Ks2b with session key Ks2b and accept session key Ks2c, public encryption key KPmc4 and modification date CRLdate (step S634).
【0365】
Then, the license management module 511 checks whether the received public encryption key KPmc4 is the same as the public encryption key KPmcx unique to the checkout destination memory card acquired in step S616 (step S635).
【0366】
The accepted public encryption key KPmc4 is included in the updated checkout information during the checkout of the encrypted content data and license (see step S552 in Figure 33). Therefore, the memory card of the checkout destination that was checked out at the time of check-in depends on whether the public encryption key KPmc4 corresponding to the checkout destination of the encrypted content data, etc. matches the public encryption key KPmcx included in the checkout information. Can be easily identified.
【0367】
In step S635, the check-in operation ends when the public encryption key KPmc4 does not match the public encryption key KPmcx unique to the memory card to be checked out (step S652). In step S635, when the public encryption key KPmc4 matches the public encryption key KPmcx unique to the checkout destination memory card, the license management module 511 sets the dummy transaction ID, dummy content ID, dummy license key Kc, and dummy access restriction information ACm. , And dummy playback restriction information ACp is encrypted with the public encryption key KPmc4, and the encrypted data {dummy transaction ID // dummy content ID // dummy license key Kc // dummy access restriction information ACm // dummy playback restriction information ACp} Kmc4 Is generated (step S636).
【0368】
The license management module 511 encrypts the encrypted data {dummy transaction ID // dummy content ID // dummy license key Kc // dummy access restriction information ACm // dummy playback restriction information ACp} Kmc4 with the session key Ks2c. Encrypted data {{Dummy transaction ID // Dummy content ID // Dummy license key Kc // Dummy access restriction information ACm // Dummy playback restriction information ACp} Kmc4} Ks2c is generated and the generated encrypted data {{Dummy Transaction ID // Dummy content ID // Dummy license key Kc // Dummy access restriction information ACm // Dummy playback restriction information ACp} Kmc4} Ks2c to playback terminal 100 via USB interface 550, terminal 580, and USB cable 70 Send (step S637).
【0369】
The controller 1106 of the playback terminal 100 uses the encrypted data {{dummy transaction ID // dummy content ID // dummy license key Kc // dummy access restriction information ACm // dummy via terminal 1114, USB interface 1112, and bus BS3. Receives playback restriction information ACp} Kmc4} Ks2c. The controller 1106 uses the received encrypted data {{dummy transaction ID // dummy content ID // dummy license key Kc // dummy access restriction information ACm // dummy playback restriction information ACp} Kmc4} Ks2c on the bus BS3 and memory card interface. Send to memory card 110 via 1200. Then, the controller 1420 of the memory card 110 uses the terminal 1426, the terminal 1424, and the bus BS4 to {{dummy transaction ID // dummy content ID // dummy license key Kc // dummy access restriction information ACm // dummy playback restriction. Receive information ACp} Kmc4} Ks2c (step S638).
【0370】
With reference to FIG. 37, the decryption processing unit 1412 of the memory card 110 is set to {{dummy transaction ID // dummy content ID // dummy license key Kc // dummy access restriction information ACm // dummy playback restriction information ACp} Kmc4}. Receives Ks2c via bus BS4, decrypts it with session key Ks2c generated by session key generator 1418, and {dummy transaction ID // dummy content ID // dummy license key Kc // dummy access restriction information ACm // dummy Accepts playback restriction information ACp} Kmc4 (step S639). Then, the decryption processing unit 1404 receives the encrypted data {dummy transaction ID // dummy content ID // dummy license key Kc // dummy access restriction information ACm // dummy playback restriction information ACp} Kmc4 from the decryption processing unit 1412. The received encrypted data {dummy transaction ID // dummy content ID // dummy license key Kc // dummy access restriction information ACm // dummy playback restriction information ACp} Decrypt Kmc4 with the secret decryption key Kmc4 from the Kmc holding unit 1402. Then, the dummy transaction ID, the dummy content ID, the dummy license key Kc, the dummy access restriction information ACm, and the dummy playback restriction information ACp are accepted (step S640). Then, the controller 1420 records the dummy transaction ID, the dummy content ID, the dummy license key Kc, the dummy access restriction information ACm, and the dummy playback restriction information ACp in the license area 1415C of the memory 1415 via the bus BS4 (step S641). .. By recording the dummy transaction ID, the dummy content ID, the dummy license key Kc, the dummy access restriction information ACm, and the dummy playback restriction information ACp in this way, the license checked out to the memory card 110 can be erased.
【0371】
After that, the license management module 511 of the personal computer 50 increases the number of checkouts possible in the checkout information by 1, the checkout transaction ID recorded when the checked-in license is ticked out, and the checkout destination memory. Delete the private public key KPmc4 on the card and update the checkout information (step S642). Then, the license management module 511 encrypts the license (transaction ID, content ID, license key Kc, access restriction information ACm, and playback restriction information ACp) and the updated checkout information with the binding key Kb to update the confidential information. Then, replace the confidential information with the updated confidential information and update the license management file. Then, the updated license management file is sent to the license management device 520 (step S643). The controller 5220 of the license management device 520 receives the updated license management file via terminal 6226, interface 5224, and bus BS5, and the received license management file causes the checked-in license in the management file area 5215C. Update and record the stored license management file (step S644).
【0372】
Then, the license management module 511 sends a deletion instruction for deleting the encrypted content data {Dc} Kc and the additional information Dc-inf to the playback terminal 100 via the USB interface 550, the terminal 580, and the USB cable 70 ( Step S645). The controller 1106 of the playback terminal 100 receives the deletion instruction of the encrypted content data {Dc} Kc and the additional information Dc-inf via the terminal 1114, the USB interface 1112, and the bus BS3, and performs the bus BS3 and the memory card interface 1200. The instruction to delete the encrypted content data {Dc} Kc and the additional information Dc-inf received via the USB is output to the memory card 110. Then, the controller 1420 of the memory card 110 receives the deletion instruction of the encrypted content data {Dc} Kc and the additional information Dc-inf via the terminal 1426, the interface 1424, and the bus BS4 (step S646). Then, the controller 1420 deletes the encrypted content data {Dc} Kc and the additional information Dc-inf recorded in the data area 1415D of the memory 1415 via the bus BS4 (step S647).
【0373】
The license management module 511 of the personal computer 50 creates a playlist in which the checked-in music is deleted (step S648), and sends the playlist and the playlist rewriting instruction to the memory card 110 (step S649). The controller 1420 of the memory card 110 receives the playlist and the rewrite instruction via the playback terminal 100 (step S650), and rewrites the playlist of the memory 1415 to the received playlist via the bus BS4 (step S651). The check-in operation ends (step S652).
【0374】
In this way, by having the encrypted content data and license returned from the other party who checked out the encrypted content data and license, the encrypted content data and license with low security level can be stored in memory with high security level one after another. It is possible to prevent the data from being copied to the card and lowering the security level of the memory card, and it is possible to prevent unauthorized copying.
【0375】
FIG. 38 shows the playlist file 160 recorded in the data area 1415D in the memory 1415 of the memory card 110. The playlist file 160 includes content files 1611 to 161n and license management files 1621 to 162n. The content files 1611 to 161n record the file names of the received encrypted content data {Dc} Kc and the additional information Dc-inf. The license management files 1621 to 162n are recorded corresponding to the content files 1611 to 161n, respectively.
【0376】
When the memory card 110 receives the encrypted content data and the license from the personal computer 50 by the "checkout session", the memory card 110 records the encrypted content data and the license in the memory 1415. That is, in the memory card 110, the license management device 520 receives and manages the license of the encrypted content data received and managed by the license management module 511 of the personal computer 50 by software. Manage as hard as the license of (meaning high security level).
【0377】
Therefore, the license for the highly secure encrypted content data received by the license management device 520 of the personal computer 50 and sent to the memory card 110 by the mobile session, and received and checked out by the license management module 511. The license of the low security encrypted content data sent to the memory card 110 by the session is recorded in the area specified by the entry number of the license area 1415C of the memory 1415. Then, by reading the license management file of the playlist file 160 recorded in the data area 1415D of the memory 1415, the entry number can be obtained, and the corresponding license can be read from the license area 1415C by the obtained entry number. ..
【0378】
The license management file 1622 represents "no license", which corresponds to, for example, the case where the playback terminal 100 receives only the encrypted content data from another mobile phone, and the encrypted content data is stored in memory 1415. However, it means that there is no license to reproduce the encrypted content data.
【0379】
[Movement 2] In the data distribution system shown in FIG. 1, the operation of moving the encrypted content data and the license acquired by the license management module 511 of the personal computer 50 to the personal computer 80 will be described. This move is called [move 2] (also called "move between hosts"). Further, the personal computer 80 has the same configuration as the personal computer 50, and is in accordance with FIG. In addition, the license management module 511 and the license management device 520 that make up the personal computer 50 and the license management module and the license management device that make up the personal computer 80 to distinguish the license management module and the license management device that make up the personal computer 80. The devices are the license management module 811 and the license management device 820, respectively.
【0380】
39 to 42 are first to fourth flowcharts for explaining the transfer of the encrypted content data and the license acquired by the license management module 511 or the license management module 520 to the personal computer 80.
【0381】
With reference to FIG. 39, when a request for interhost transfer of the license obtained via keyboard 560 is entered (step S800), the license management module 511 makes a request to send authentication data via communication cable 90. Send to personal computer 80 (step S801). Then, the license management module 811 of the personal computer 80 receives the request for transmitting the authentication data (step S802), and inputs the output instruction of the authentication data to the license management device 820 via the bus BS2 (step S802a). The controller 5220 of the license management device 820 receives the authentication data output instruction via the terminal 5226, the interface 5224, and the bus BS5, and the authentication data {Kpm7 // Cm7} KPa from the authentication data holder 5200 via the bus BS5. Is read, and the authentication data {Kpm7 // Cm7} KPa is output via bus BS5, interface 5224, and terminal 5226 (step S803). Then, the license management module 811 receives the authentication data {Kpm7 // Cm7} KPa via the bus BS2 and transmits the authentication data {Kpm7 // Cm7} KPa to the personal computer 50 via the communication cable 90 (step S804). ).
【0382】
Then, the license management module 511 of the personal computer 50 sends the authentication data {Kpm7 // Cm7} KPa to the license management device 520 via the bus BS2 (step S805). The controller 5220 of the licensed device 520 receives the authentication data {Kpm7 // Cm7} KPa via the terminal 5226, the interface 5224, and the bus BS5, and the decryption processing unit 5208 publishes the authentication data {Kpm7 // Cm7} KPa. Decrypt with the authentication key KPa (step S806).
【0383】
From the decryption processing result in the decryption processing unit 5208, the controller 5220 determines whether or not the processing is performed normally, that is, the license management device 820 of the personal computer 80 is the public encryption key KPm7 and the certificate Cm7 from the legitimate license administration device. In order to certify that the data is retained, an authentication process is performed to determine whether or not the authorized authority has received the encrypted authentication data for certifying its validity (step S807). If it is determined that the authentication data is valid, the controller 5220 approves and accepts the public encryption key KPm7 and the certificate Cm7. Then, the process proceeds to the next process (step S808). If it is not valid authentication data, it is disapproved and the process ends without accepting the public encryption key KPm7 and the certificate Cm7 (step S854).
【0384】
When the authentication results recognize that it is a legitimate device, the controller 5220 then determines whether the license management device class certificate Cm7 is listed in the certificate revocation list CRL in the CRL area of memory 5215. If you query 5215A and these class certificates are on the certificate revocation list, end the delivery session here (step S854).
【0385】
On the other hand, if the class certificate of the license management device 820 is not included in the certificate revocation list, the process proceeds to the next process (step S808).
【0386】
As a result of authentication, if the access is from a personal computer equipped with a license management device with valid authentication data and it is confirmed that the class is not included in the certificate revocation list, a session key is generated on the license management device 520. Part 5218 generates session key Ks2 for inter-host movement (step S809). Then, the encryption processing unit 5210 encrypts the session key Ks2 with the public encryption key KPm7 corresponding to the license management device 820 obtained by the decryption processing unit 5208 to generate the encrypted data {Ks2} Km7. The controller 5220 outputs the encrypted data {Ks2} Km7 via the bus BS5, the interface 5224, and the terminal 5226 (step S810). Controller 5220 obtains the transaction ID from the license management file in memory 5215 (step S811).
【0387】
Referring to FIG. 40, the license management module 511 transmits the encrypted data {Ks2} Km7 received from the license management device 520 and the transaction ID to the personal computer 80 via the communication cable 90 (step S812). The license management module 811 of the personal computer 80 receives the transaction ID // {Ks2} Km7 (step S813) and sends the encrypted data {Ks2} Km7 to the license management device 820 via the bus BS2 (step S814).
【0388】
The decryption processing unit 5222 of the license management device 820 decrypts the encrypted data {Ks2} Km7 with the secret decryption key Km7 and accepts the session key Ks2 (step S815). The controller 5220 controls the session key generator 5208 so that the session key is generated in response to the acceptance of the session key Ks2. Then, the session key generator 5208 generates the session key Ks2a (step S816), and the controller 5220 acquires the update date and time CRL date of the certificate revocation list CRL from the CRL area 5215A of the memo 5215 via the bus BS5. It is given to the changeover switch 5246 (step S817). Then, the encryption processing unit 5206 encrypts the session key Ks2a, the public encryption key KPmc9, and the update date / time CRL date acquired by sequentially switching the changeover switch 5246 with the session key Ks2 received by the decryption processing unit 5222, and the encrypted data. {Ks2a // Kpmc9 // CRLdate} Generate Ks2. Then, the controller 5220 outputs the encrypted data {Ks2a // Kpmc9 // CRLdate} Ks2 via the bus BS5, the interface 5224, and the terminal 5226 (step S818). The license management module 811 receives the encrypted data {Ks2a // Kpmc9 // CRLdate} Ks2 via the bus BS2, and the received encrypted data {Ks2a // Kpmc9 // CRLdate} Ks2 via the communication cable 90. Send to personal computer 80 (step S819).
【0389】
Then, the license management module 511 of the personal computer 50 receives the encrypted data {Ks2a // Kpmc9 // CRLdate} Ks2 (step S820), and the encrypted data {Ks2a // Kpmc9 // CRLdate} via the bus BS2. Enter Ks2 into license management device 520 (step S821). The controller 5220 of the license management device 520 receives the encrypted data {Ks2a // Kpmc9 // CRLdate} Ks2 via the terminal 5226, the interface 5224, and the bus BS5, and the decryption processing unit 5212 receives the encrypted data {Ks2a // Kpmc9. // CRLdate} Give Ks2. The decryption processing unit 5212 decrypts the encrypted data {Ks2a // Kpmc9 // CRLdate} Ks2 with the session key Ks2 and receives the session key Ks2a, the public encryption key Kpmc9, and the update date / time CRLdate (step S822).
【0390】
Then, the controller 5220 refers to the license management file regarding the license to be moved from the license management files 1521-152n recorded in the memory 5215, and obtains the entry number in which the license to be moved is stored (step S823), and the controller 5220 obtains the entry number in which the moved license is stored. Read the licenses (transaction ID, content ID, license key Kc, access restriction information ACm, and playback restriction information ACp) stored in the area specified by the acquired entry number (step S824). This license may be a binding license. Then, the controller 5220 determines whether or not the license can be moved and played back based on the read access restriction information ACm (step S825). When it is determined that the movement and reproduction of the license are prohibited based on the access restriction information ACm, the process proceeds to step S854 and the movement session ends. If it is determined that the license movement and reproduction are permitted based on the access restriction information ACm, the process proceeds to the next step S826 in FIG. 41 (step S825).
【0391】
With reference to FIG. 41, when it is determined in step S825 that the transfer and reproduction of the license are permitted, the encryption processing unit 5217 determines the transaction ID, the content ID, and the license key Kc decrypted by the decryption processing unit 5212. , Access restriction information ACm, and playback restriction information ACp are encrypted with the public encryption key Kpmc9 to generate encrypted data {transaction ID // content ID // Kc // ACm // playback restriction information ACp} Kmc9 (step S826). ). Then, the controller 5220 is stored in the certificate revocation list CRL stored in the license management device 820 of the destination personal computer 80 and the license management device 520 of the destination personal computer 50 based on the update date and time CRL date. When it is determined which of the certificate revocation list CRLs is new and the certificate revocation list CRL stored in the license management device 820 of the destination personal computer 80 is new or the same, step S828 Move to. When it is determined that the certificate revocation list CRL stored in the license management device 820 of the destination personal computer 80 is old, the process proceeds to step S835 (step S827).
【0392】
When it is determined that the certificate revocation list CRL stored in the license management device 820 of the destination personal computer 80 is new or the same, the encryption processing unit 5206 performs the encryption data generated by the encryption processing unit 5217. {Transaction ID // Content ID // Kc // ACm // Playback restriction information ACp} Kmc9 is obtained via the terminal Pc of the selector switch 5246 and encrypted by the session key Ks2a obtained via the terminal Pd of the selector switch 5246. Encrypt data {{Transaction ID // Content ID // Kc // ACm // ACp} Kmc9} Ks2a is generated. Then, the controller 5220 outputs the encrypted data {{transaction ID // content ID // Kc // ACm // ACp} Kmc9} Ks2a via the bus BS5, the interface 5224, and the terminal 5226 (step S828). After that, the controller 5220 determines whether or not the license can be duplicated based on the access restriction information ACm, proceeds to step S831 when the license can be duplicated, and steps S830 when the license cannot be duplicated. Move to. If it is determined in step S829 that the license cannot be replicated, controller 5220 deletes the license stored in license area 5215B of memo 5215 based on the entry number (step S830).
【0393】
Then, when it is determined in step S829 that the license can be duplicated, or after step S830, the license management module 511 determines the encrypted data encrypted data {{transaction ID // content ID // Kc // ACm // Send ACp} Kmc9} Ks2a to the personal computer 80 via the communication cable 90 (step S831).
【0394】
The license management module 811 of the personal computer 80 receives the encrypted data {{transaction ID // content ID // Kc // ACm // ACp} Kmc9} Ks2a (step S832) and the encrypted data via the bus BS2. {{Transaction ID // Content ID // Kc // ACm // ACp} Kmc9} Enter Ks2a into the license management device 820 (step S833). Controller 5220 of license management device 820 receives encrypted data {{transaction ID // content ID // Kc // ACm // ACp} Kmc9} Ks2a via terminal 5226, interface 5224, and bus BS5. The decryption processing unit 5212 decrypts the encrypted data {{transaction ID // content ID // Kc // ACm // ACp} Kmc9} Ks2a with the session key Ks2a, and the encrypted data {transaction ID // content ID / / Kc // ACm // ACp} Accept Kmc9 (step S834). After that, the process proceeds to step S844 in FIG.
【0395】
On the other hand, if it is determined in step S827 that the certificate revocation list CRL stored in the license management device 820 of the destination personal computer 80 is old, the controller 5220 of the license management device 520 uses the memory 5215 via the bus BS5. Obtain the latest certificate revocation list CRL from CRL area 5215A in (step S835). Then, the encryption processing unit 5206 uses the encryption data {transaction ID // content ID // Kc // ACm // ACp} Kmc9 supplied from the encryption processing unit 5217 via the terminal Pc of the changeover switch 5246, and the changeover switch. Received the certificate revocation list CRL obtained via terminal Pf of 5246, encrypted with the session key Ks2a, and encrypted data {difference CRL // {transaction ID // content ID // Kc // ACm // ACp } Kmc9} Generate Ks2a. Then, the controller 5220 outputs the encrypted data {{transaction ID // content ID // Kc // ACm // ACp} Kmc9} Ks2a via the bus BS5, the interface 5224, and the terminal 5226 (step S836).
【0396】
After that, the controller 5220 determines whether or not the license can be duplicated based on the access restriction information ACm, proceeds to step S839 when the license can be duplicated, and steps S838 when the license cannot be duplicated. Move to. If it is determined in step S837 that the license cannot be replicated, controller 5220 deletes the license stored in license area 5215B of memo 5215 based on the entry number (step S838).
【0397】
Then, when it is determined in step S837 that the license can be duplicated, or after step S838, the license management module 511 sets the encrypted data encrypted data {CRL // {transaction ID // content ID // Kc // ACm // ACp} Kmc9} Ks2a is transmitted to the personal computer 80 via the communication cable 90 (step S839).
【0398】
With reference to FIG. 42, the license management module 811 of the personal computer 80 receives the encrypted data {CRL // {transaction ID // content ID // Kc // ACm // ACp} Kmc9} Ks2a (step S840). ), Enter the encrypted data {CRL // {transaction ID // content ID // Kc // ACm // ACp} Kmc9} Ks2a into the license management device 820 via bus BS2 (step S841). Controller 5220 of license management device 820 receives encrypted data {CRL // {transaction ID // content ID // Kc // ACm // ACp} Kmc9} Ks2a via terminal 5226, interface 5224, and bus BS5. Upon receiving, the decryption processing unit 5212 decrypts the encrypted data {CRL // {transaction ID // content ID // Kc // ACm // ACp} Kmc9} Ks2a with the session key Ks2a, and the certificate revocation list CRL And the encrypted data {transaction ID // content ID // Kc // ACm // ACp} Kmc9 are accepted (step S842). Then, the controller 5220 acquires the certificate revocation list CRL via the bus BS5 and rewrites it by the certificate revocation list that has acquired the certificate revocation list CRL of the CRL area 5215A of the memory 5215 via the bus BS5 (step S843). ).
【0399】
After step S834 or step S843 in FIG. 41, the decryption processing unit 5204 secretly decrypts the encrypted data {transaction ID // content ID // Kc // ACm // ACp} Kmc9 received by the decryption processing unit 5212. It is decrypted by Kmc9 and accepts the transaction ID, content ID, license key Kc, access restriction information ACm, and playback restriction information ACp (step S844). The license management module 811 then enters the entry number for storing the license into the license management device 820 (step S845). Then, the controller 5220 of the license management device 820 receives the entry number via the terminal 5226, the interface 5224, and the bus BS5, and licenses (transaction ID, content ID, license key Kc) to the area specified by the received entry number. , Access restriction information ACm, and playback restriction information ACp) are stored (step S846).
【0400】
In this way, the encryption keys generated by each of the license management devices of the two personal computers are exchanged, the encryption using the encryption keys received by each other is executed, and the encrypted data is transmitted to the other party. As a result, mutual authentication can be substantially performed in the transmission and reception of each encrypted data, and the security of the data distribution system can be improved.
【0401】
Then, the license management module 511 of the personal computer 50 reads the license management file from the license management device 520 and transmits the read license management file to the personal computer 80 via the communication cable 90 (step S847). Then, the license management device 820 of the personal computer 80 changes the entry number stored in the received license management file to the entry number received in step S845, and records the changed license management file in the memory 5215. (Step S848).
【0402】
After that, the license management module 511 of the personal computer 50 reads the encrypted content data {Dc} Kc and the additional information Dc-inf from the HDD, and the encrypted content data {Dc} Kc and the additional information Dc via the communication cable 90. Send -inf and to personal computer 80 (step S849). The license management module 811 of the personal computer 80 receives the encrypted content data {Dc} Kc and the additional information Dc-inf (step S850), and adds the encrypted content data {Dc} Kc to the HDD 530 via the bus BS2. Record the information Dc-inf (step S851).
【0403】
After that, the license management module 511 of the personal computer 50 determines whether or not the license can be duplicated based on the access restriction information ACm (step S852), and if the license can be duplicated, proceeds to step S854. The entire operation ends (step S854). When the license cannot be duplicated in step S852, the license management module 511 deletes the entry number of the license management file (step S853), and the entire operation ends (step S854).
【0404】
In step S853, deleting the entry number stored in the license management file corresponds to deleting the license stored in the license management device 520 in step S838 (see FIG. 41).
【0405】
The above has described the case where the encrypted content data and the license acquired by the license management device 50 of the personal computer 50 are moved to the personal computer 80, but the encryption acquired by the license management module 511 of the personal computer 50 by software. The operation of moving the content data and the license to the personal computer 80 is also performed according to the flowcharts shown in FIGS. 39 to 42. In this case, the transaction ID, content ID, license key Kc, access restriction information ACm, and playback restriction information ACp in step S824 of FIG. 40 to step S854 of FIG. 42 are the transaction IDb, the content IDb, the binding key Kb, and the access, respectively. It is read as restriction information ACmb and playback restriction information ACpb. Then, in step S853 of FIG. 42, the license management module 511 deletes the entry number stored in the license management file corresponding to the moved license to make it unlicensed, and the license management file encrypts the license. If it contains information, prepare a license management file with confidential information deleted, and rewrite the license management file corresponding to the moved license recorded in the management file area 5215C of the license management device 520.
【0406】
As described above, when moving the encrypted content data acquired by the license management module 511 of the personal computer 50 to the personal computer 80, the encrypted content data, the license (stored in the license management file) and Move the binding license to Personal Computer 80. When the encrypted content data acquired by the license management device 520 of the personal computer 50 is moved to the personal computer 80, the encrypted content data and the license are moved to the personal computer 80. Then, the transferred encrypted content data and the like are managed in the destination personal computer 80 in the same manner as in the personal computer 50.
【0407】
In this way, the license management device 520 generates a binding license for each acquisition of the encrypted content data and the license by the license management module 511 of the personal computer 50, and manages the license of the encrypted content data by the binding license. It is possible to perform the same movement as the movement of the acquired encrypted content data and the like.
【0408】
[Playback] Next, a playback operation of the content data moved to the memory card 110 and checked out on the playback terminal 100 (also referred to as a content playback device, the same shall apply hereinafter) with reference to FIGS. 43 and 44 will be described. With reference to FIG. 43, when the playback operation is started, a playback instruction is input to the playback terminal 100 from the user of the playback terminal 100 via the operation panel 1108 (step S1000). Then, the controller 1106 reads the authentication data {KPp1 // Cm1} KPa from the authentication data holding unit 1500 via the bus BS3, and transfers the authentication data {KPp1 // Cm1} KPa to the memory card 110 via the memory card interface 1200. Output (step S1002).
【0409】
Then, the memory card 110 receives the authentication data {KPp1 // Cm1} KPa (step S1004). Then, the decryption processing unit 1408 of the memory card 110 decrypts the received authentication data {KPp1 // Cm1} KPa with the public authentication key KPa held in the KPa holding unit 1414 (step S1006), and the controller 1420 decrypts the data. Authentication processing is performed from the decryption processing result in unit 1408. That is, the authentication process for determining whether or not the authentication data {KPp1 // Cm1} KPa is legitimate authentication data is performed (step S1008). If the decoding cannot be performed, the process proceeds to step S1048, and the playback operation ends. If the authentication data can be decrypted, the controller 1420 determines whether the acquired certificate Cm1 is included in the certificate revocation list data CRL read from the memory 1415 (step S1010). In this case, an ID is assigned to the certificate Cm1, and the controller 1420 determines whether or not the ID of the received certificate Cm1 exists in the certificate revocation list. When it is determined that the certificate Cm1 is included in the certificate revocation list, the process proceeds to step S1048, and the reproduction operation ends.
【0410】
If it is determined in step S1010 that the certificate Cm1 is not included in the certificate revocation list CRL, the session key generator 1418 of the memory card 110 generates the session key Ks2 for the playback session (step S1012). Then, the encryption processing unit 1410 outputs the {Ks2} Kp1 encrypted by the public encryption key KPp1 decrypted by the decryption processing unit 1408 from the session key Ks2 from the session key generation unit 1418 to the bus BS3 (step S1014). .. The controller 1420 then outputs {Ks2} Kp1 to the memory card interface 1200 via interface 1424 and terminal 1426 (step S1016). The controller 1106 of the playback terminal 100 acquires {Ks2} Kp1 via the memory card interface 1200. Then, the Kp1 holding unit 1502 outputs the secret decryption key Kp1 to the decoding processing unit 1504.
【0411】
The decryption processing unit 1504 decrypts {Ks2} Kp1 by the secret decryption key Kp1 paired with the public encryption key KPp1 output from the Kp1 holding unit 1502, and outputs the session key Ks2 to the encryption processing unit 1506 ( Step S1018). Then, the session key generation unit 1508 generates the session key Ks3 for the playback session, and outputs the session key Ks3 to the encryption processing unit 1506 (step S1020). The encryption processing unit 1506 encrypts the session key Ks3 from the session key generation unit 1508 with the session key Ks2 from the decryption processing unit 1504 and outputs {Ks3} Ks2, and the controller 1106 outputs the bus BS3 and the memory card interface 1200. Output {Ks3} Ks2 to the memory card 110 via (step S1022).
【0412】
Then, the decryption processing unit 1412 of the memory card 110 inputs {Ks3} Ks2 via the terminal 1426, the interface 1424, and the bus BS4 (step S1024).
【0413】
With reference to FIG. 44, the decoding processing unit 1412 decodes {Ks3} Ks2 by the session key Ks2 generated by the session key generation unit 1418, and receives the session key Ks3 generated by the playback terminal 100 (step). S1026). Upon acceptance of session key Ks3, controller 1420 checks the access restriction information ACm (step S1028). In step S1028, by checking the access restriction information ACm, which is information on the restriction on memory access, the reproduction operation is terminated if the playback is already impossible, and if the playback count limit is limited, the playback operation is terminated. Access restriction information After updating the ACm data and updating the playable number, proceed to the next step (step S1030). On the other hand, when the number of playbacks is not limited by the access restriction information ACm, step S1030 is skipped, and the process proceeds to the next step (step S1032) without updating the access restriction information ACm.
【0414】
If it is determined in step S1028 that playback is possible in the playback operation, the license key Kc of the playback request song recorded in the license area 1415C of the memory 1415 and the playback restriction information ACp are output on the bus BS4. (Step S1032).
【0415】
The obtained license key Kc and playback restriction information ACp are sent to the encryption processing unit 1406 via the contact Pf of the changeover switch 1446. The encryption processing unit 1406 encrypts the license key Kc received via the changeover switch 1446 and the playback restriction information ACp by the session key Ks3 received from the decryption processing unit 1412 via the contact Pb of the changeover switch 1442, and {Kc / Output / ACp} Ks3 to bus BS4 (step S1034).
【0416】
The encrypted data output to the bus BS4 is sent to the playback terminal 100 via the interface 1424, the terminal 1426, and the memory card interface 1200.
【0417】
The playback terminal 100 decrypts the encrypted data {Kc // ACp} Ks3 transmitted to the bus BS3 via the memory card interface 1200 by the decryption processing unit 1510, and receives the license key Kc and the playback restriction information ACp. (Step S1036). The decryption processing unit 1510 transmits the license key Kc to the decryption processing unit 1516, and outputs the reproduction restriction information ACp to the bus BS3.
【0418】
The controller 1106 receives the reproduction restriction information ACp via the bus BS3 and confirms whether or not the reproduction is possible (step S1040).
【0419】
In step S1040, if it is determined by the playback restriction information ACp that playback is not possible, the playback operation is terminated.
【0420】
If determined in step S1040 to be playable, controller 1106 requests encrypted content data {Dc} Kc from memory card 110 via memory card interface 1200. Then, the controller 1420 of the memory card 110 acquires the encrypted content data {Dc} Kc from the memory 1415 and outputs the encrypted content data {Dc} Kc to the memory card interface 1200 via the bus BS4, the interface 1424, and the terminal 1426 (step S1042).
【0421】
The controller 1106 of the playback terminal 100 acquires the encrypted content data {Dc} Kc via the memory card interface 1200, and gives the encrypted content data {Dc} Kc to the decryption processing unit 1516 via the bus BS3.
【0422】
Then, the decryption processing unit 1516 decrypts the encrypted content data {Dc} Kc by the content key Kc output from the decryption processing unit 1510, and acquires the content data Data (step S1044).
【0423】
Then, the decoded content data Dc is output to the music playback unit 1518, the music playback unit 1518 reproduces the content data, and the DA converter 1519 converts the digital signal into an analog signal and outputs it to the terminal 1530. Then, the music data is output from the terminal 1530 to the headphone 130 via an external output device and played back (step S1046). This ends the playback operation.
【0424】
In the above, the case where the encrypted content data recorded on the memory card 110 is played back by the playback terminal 100 has been described. However, license management is performed by incorporating the content playback device 1550 shown in FIG. 7 in the personal computers 50 and 80. It is possible to replay the encrypted content data received by module 511 and license management device 520. When the encrypted content data acquired by the license management module 511 is reproduced by the content reproduction device 1550, the license management module 511 acquires the binding key Kb stored in the license management device 520 and records it in the HDD 530. The encrypted confidential information of the license management file is decrypted by the binding key Kb, the license is read from the plaintext confidential information, and the license is given to the content playback device 1550.
【0425】
In addition, by incorporating a playback unit that functions according to software that reproduces encrypted content data in personal computers 50 and 80, it is possible to reproduce the encrypted content data acquired by the license management module 511 by software. .. In this case as well, the license management module 511 acquires the binding key Kb stored in the license management device 520, decrypts the encrypted confidential information of the license management file recorded in the HDD 530 with the binding key Kb, and decrypts the plaintext confidential information. Read the license from and give it to the content playback device 1550.
【0426】
According to the embodiment of the present invention, the license management module built in the personal computer manages the license of the encrypted content data acquired by the software by the binding key managed hard by the license management device. It is possible to send encrypted content data and licenses to other personal computers by the concept of "move", similar to the license of encrypted content data acquired by the management device.
【0427】
As described above, the license management device 520 built in the personal computer 50 communicates with the distribution server 10, acquires encrypted content data and a license, and manages the acquired license. Further, the license management device 520 manages the license of the encrypted content data acquired from the distribution server 10 by the license management module 511 and the binding license including the binding key for encrypting the license. Then, the license management device 520 can be removed from the personal computer 50 and attached to another personal computer 80 as shown in FIG. 45. Therefore, if the license management device 520 is removed from the personal computer 50 and attached to the personal computer 80 after the encrypted content data and the license are acquired by the personal computer 50, the encrypted content data acquired by the personal computer 50 can be easily duplicated. Can be done. That is, since the license management device 520 manages the license acquired by itself, the license acquired by the license management device 511, and the binding license, the content list file 150 and the content file stored in the hard disk 530 of the personal computer 50. If 1531 to 153n are duplicated to the hard disk 830 of the personal computer 80 with a cable, the encrypted content data stored in the duplicated content files 1531 to 153n can be played back by the method described above, and then moved to another personal computer and checked. Can be out and chucked in.
【0428】
The license management device 520 acquires licenses, binding licenses, and license management files on condition that it is authenticated by the authentication data it holds, so even if the license management device 520 is moved between personal computers, the license is licensed. And the binding license will not be copied illegally. Therefore, there is no security problem.
【0429】
Furthermore, each time a binding license including the binding key Kb is recorded in the license management device 520, the license key Kc for decrypting the encrypted content data {Dc} Kc can be used as it is as the binding key.
【0430】
Furthermore, when the license key Kc is used as the binding key, the license key Kc is not recorded in the confidential information that records the license, and when the binding key is read, the binding key is used as it is as the license key. be able to.
【0431】
It should be considered that the embodiments disclosed this time are exemplary in all respects and not restrictive. The scope of the present invention is shown by the scope of claims rather than the description of the embodiment described above, and is intended to include all modifications within the meaning and scope equivalent to the scope of claims.
[Simple explanation of drawings]
[Figure 1]
It is the schematic explaining the data distribution system in Embodiment 1 of this invention conceptually.
[Figure 2]
It is a figure which shows the characteristic of data, information, etc. for communication in the data distribution system shown in FIG.
[Fig. 3]
It is a figure which shows the characteristic of data, information, etc. for communication in the data distribution system shown in FIG.
[Fig. 4]
The figure shows the binding license required to move the license acquired by the software in the data distribution system shown in Fig. 1 to another personal computer, and the checkout management information in the checkout session lent to the memory card. is there.
[Fig. 5]
It is a schematic block diagram which shows the structure of a distribution server.
[Fig. 6]
It is a schematic block diagram which shows the structure of a personal computer.
[Fig. 7]
It is a block diagram which shows the structure of a reproduction terminal.
[Fig. 8]
It is a block diagram which shows the structure of a memory card.
[Fig. 9]
It is a schematic block diagram which shows the structure of the license management device.
[Fig. 10]
It is the first flowchart for demonstrating the delivery operation with a high security level in the data delivery system shown in FIG.
[Fig. 11]
It is the 2nd flowchart for demonstrating the delivery operation with high security level in the data delivery system shown in FIG.
[Fig. 12]
It is a 3rd flowchart for demonstrating the delivery operation with a high security level in the data delivery system shown in FIG.
[Fig. 13]
It is a 4th flowchart for demonstrating the delivery operation with a high security level in the data delivery system shown in FIG.
[Fig. 14]
It is the first flowchart for demonstrating the delivery operation with a low security level in the data delivery system shown in FIG.
[Fig. 15]
It is a 2nd flowchart for demonstrating the delivery operation with a low security level in the data delivery system shown in FIG.
[Fig. 16]
It is a 3rd flowchart for demonstrating the delivery operation with a low security level in the data delivery system shown in FIG.
[Fig. 17]
It is a 4th flowchart for demonstrating the delivery operation with a low security level in the data delivery system shown in FIG.
[Fig. 18]
It is a 5th flowchart for demonstrating the delivery operation with a low security level in the data delivery system shown in FIG.
[Fig. 19]
It is a sixth flowchart for demonstrating the delivery operation with a low security level in the data delivery system shown in FIG.
[Fig. 20]
It is a 1st flowchart for demonstrating the operation of ripping in the data distribution system shown in FIG.
[Fig. 21]
It is a 2nd flowchart for demonstrating the operation of ripping in the data distribution system shown in FIG.
[Fig. 22]
It is a 3rd flowchart for demonstrating the operation of ripping in the data distribution system shown in FIG.
[Fig. 23]
It is a 4th flowchart for demonstrating the operation of ripping in the data distribution system shown in FIG.
[Fig. 24]
It is a figure which shows the structure of the content list file in the hard disk of a personal computer.
[Fig. 25]
It is the first flowchart for demonstrating the movement operation of the license of the encrypted content data in the data distribution system shown in FIG.
[Fig. 26]
It is the 2nd flowchart for demonstrating the movement operation of the license of the encrypted content data in the data distribution system shown in FIG.
[Fig. 27]
It is a 3rd flowchart for demonstrating the movement operation of the license of the encrypted content data in the data distribution system shown in FIG.
[Fig. 28]
It is a 4th flowchart for demonstrating the movement operation of the license of the encrypted content data in the data distribution system shown in FIG.
[Fig. 29]
It is the first flowchart for demonstrating the check-out operation of the license of the encrypted content data in the data distribution system shown in FIG.
[Fig. 30]
It is a 2nd flowchart for demonstrating the check-out operation of the license of the encrypted content data in the data distribution system shown in FIG.
[Fig. 31]
It is a 3rd flowchart for demonstrating the checkout operation of the license of the encrypted content data in the data distribution system shown in FIG.
[Fig. 32]
It is a 4th flowchart for demonstrating the check-out operation of the license of the encrypted content data in the data distribution system shown in FIG.
[Fig. 33]
It is a 5th flowchart for demonstrating the check-out operation of the license of the encrypted content data in the data distribution system shown in FIG.
[Fig. 34]
It is the first flowchart for demonstrating the check-in operation of the license of the encrypted content data in the data distribution system shown in FIG.
[Fig. 35]
It is the 2nd flowchart for demonstrating the check-in operation of the license of the encrypted content data in the data distribution system shown in FIG.
[Fig. 36]
It is a 3rd flowchart for demonstrating the check-in operation of the license of the encrypted content data in the data distribution system shown in FIG.
[Fig. 37]
It is a 4th flowchart for demonstrating the check-in operation of the license of the encrypted content data in the data distribution system shown in FIG.
[Fig. 38]
It is a figure which shows the structure of the playlist file in a memory card.
[Fig. 39]
It is the first flowchart for demonstrating the transfer of encrypted content data and license between personal computers in the data distribution system shown in FIG.
[Fig. 40]
It is a second flowchart for demonstrating the transfer of encrypted content data and license between personal computers in the data distribution system shown in FIG.
[Fig. 41]
It is a 3rd flowchart for demonstrating the transfer of encrypted content data and license between personal computers in the data distribution system shown in FIG.
[Fig. 42]
It is a 4th flowchart for demonstrating the transfer of encrypted content data and license between personal computers in the data distribution system shown in FIG.
[Fig. 43]
It is a 1st flowchart for demonstrating the reproduction operation in a reproduction terminal.
[Fig. 44]
It is a 2nd flowchart for demonstrating the reproduction operation in a reproduction terminal.
[Fig. 45]
It is a figure for demonstrating the usage of the license management device.
[Explanation of symbols]
10 distribution server, 20 distribution carrier, 30 internet network, 40 modem, 50,80 personal computer, 60 CD, 70 USB cable, 90 communication cable, 100 playback terminal, 110 memory card, 130 headphones, 150 content list file, 160 Playlist file, 302 billing database, 304 information database, 306 CRL database, 307 menu database, 308 delivery record database, 310 data processing department, 312,320,1404,1408,1412,1422,1504,1510,1516,5204,5208, 5212,5222 Decryption processing unit, 313 Authentication key holding unit, 315 Distribution control unit, 316, Session key generator, 318,326,328,1406,1410,1417,1506,5206,5210,5217,5405 Cryptographic processing unit, 350 communication device, 510,1106,1420,5220 controller, 511,811 license management module, 520,820 license management device, 530,830 Hard disk, 540 CD-ROM drive, 550,1112 USB interface, 560 keyboard, 570 display, 580,1114,1426,1530,5226 terminals, 1108 operation panel, 1110 display panel, 1200 memory card interface, 1400,1500,5200 authentication Data holding part, 1402,5202 Kmc holding part, 1414,5214 KPa holding part, 1415,5215 memory, 1415A, 5215A CRL area, 1415B, 5215B license area, 1415C data area, 5215C management file area, 1416,5216 KPmc holding part , 1418,5218 Session key generator, 1421,5221Km holder, 1424,5224 interface, 1442,1446,5242,5246 selector switch, 1502 Kp1 holder, 1518 music player, 1519 DA converter, 1521-152n, 1621-162n license management Files, 1531 ~ 153n, 1611 ~ 1612n content files, 1550 content playback devices.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2010508576A | Cited by | Japan | Examiner |
| US8527424B2 | Cited by | United States of America | Applicant |
| WO2006022006A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO2006009032A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US8220064B2 | Cited by | United States of America | Applicant |
| US8095469B2 | Cited by | United States of America | Applicant |
| JPWO2006022006A1 | Cited by | Japan | Examiner |
| US8091137B2 | Cited by | United States of America | Applicant |
| US7865960B2 | Cited by | United States of America | Applicant |
| WO2005025129A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2008033512A | Cited by | Japan | Examiner |
| JP2000293589A | Cites | Japan | Examiner |
| JP2000348105A | Cites | Japan | Examiner |
| JPH11259964A | Cites | Japan | Examiner |
| JPH11340968A | Cites | Japan | Search report |
2 members in 1 office
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2001087322 | Japan | A | |
| JP20010087322 | – | – | – |
Members2
| Document | Office | Kind | |
|---|---|---|---|
| JP2002288377AThis record | Japan | A | |
| JP4737857B2 | Japan | B2 |
11 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of completion of termEXPY | EXPY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Written notification of patent or utility model registrationJAPANESE INTERMEDIATE CODE: R151R151 | R151 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 |
Numbers
- Publication
- 2002-288377
- Publication, DOCDB
- 2002288377
- Publication, EPODOC
- JP2002288377
- Application
- 87322
- Application, DOCDB
- 2001087322
- Application, EPODOC
- JP20010087322
Titles2
- Japanese
- 【発明の名称】データ端末装置およびデバイス
- English
- [Title of Invention] Data terminal device and device
Classification
- IPC, 11
- G06F12 14
- G06F21 10
- G06F21 60
- G06F21 62
- G06Q10 00
- G06Q50 00
- G06Q50 10
- H04L9 08
- H04L9 32
- H04N7 173
- H04N21 4623