Data protection system for protecting data through encryption
Abstract
Problem to be solved.To provide a system which suppresses an increase in the amount of encryption data to be distributed to many terminals and encrypts data so that the data can not correctly be decrypted on a specified terminal.
Solution.For individual nodes except for those in the bottom layer in a quadrant tree wherein terminals are made to correspond to respective bottom- layer nodes, a plurality of combination patterns as to four nodes in layers which are reached from the nodes and one layer below them are determined, individual keys are determined by the combination patterns, individual keys are determined by the respective nodes in the bottom layers, and each terminal stores and holds all keys determined as to individual nodes on the corresponding path from the bottom layer node to the top layer. The individual nodes on the path from the node corresponding to a specified terminal (terminal 1) to the top layer are defined as ineffective nodes (mark '×' in Fig. 15) and keys determined corresponding to the combination patterns of all nodes except ineffective nodes among four nodes of the layer which is reached from the ineffective nodes other than the bottom layer and one stage below the layer are specified and used to cipher data to be distributed.
Copyright (C)2003,JPO

Term
Term ended
Projected expiry passed 27 March 2022, 4.5 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
41 claims: 16 independent, 25 dependent
- 1[Claims] [Claim 1] A data protection system including three or more terminals, an encryption device, and an encryption key identification device, which protects data for distribution to each terminal by encrypting it with an encryption device. Each terminal stores a decryption key group individually assigned by a predetermined key allocation method, acquires an encryption distribution data group output from the encryption device, and obtains the encryption distribution data. It decrypts using the stored decryption key. The predetermined key allocation method is (a) so that each of the terminals belongs to at least one of the terminal sets, which is a set containing two or more terminals as elements. Further, it is said that it is a plurality of terminal sets each including the same one or more terminals in each element, and none of the terminal sets in the plurality of terminal sets is a subset of each other terminal set in the plurality of terminal sets. So that there are multiple terminal sets where the relationship is established Determine two or more terminal sets and (b) Set a separate decryption key for each terminal and each determined terminal set. (c) This is a method of assigning to each of the terminals the decryption key determined for the terminal and the decryption key specified for each of all the terminal sets including the terminal. The encryption key identification device is a device that identifies an encryption key and Disabling terminal identification means to identify one or more terminals as invalidating terminals, When a decryption key other than the decryption key assigned to the invalidated terminal among all the decryption keys assigned to the terminal by the predetermined key allocation method is defined as the valid decryption key, The procedure of selecting the assigned valid decryption key for the most terminals to which the selected valid decryption key is not assigned is described. Specifying the encryption key that corresponds to each of the selected valid decryption keys, assuming that the process is repeated until there are no terminals to which the selected valid decryption key is assigned. It is a device having means and The encryption device has an encryption means that sequentially uses all the encryption keys specified by the encryption key identification device to encrypt distribution data, and generates and outputs an encrypted distribution data group. A data protection system featuring. 【特許請求の範囲】 【請求項1】 3台以上の端末、暗号化装置及び暗号化鍵特定装置を備え、各端末への配給用データを暗号化装置により暗号化して保護するデータ保護システムであって、 前記各端末は、所定鍵割当方法により個別に割当てられた復号鍵群を記憶しており、前記暗号化装置から出力された暗号化配給用データ群を取得して、暗号化配給用データを、記憶している復号鍵を用いて復号するものであり、 前記所定鍵割当方法は、 (a) 前記各端末が、2つ以上の端末を要素に含む集合である端末集合の少なくとも1つには属するように、 更に、同じ1つ以上の端末を各々要素に含む複数の端末集合であって、当該複数の端末集合におけるいずれの一の端末集合も当該複数の端末集合における他の各端末集合の部分集合でないという関係が成立するところの当該複数の端末集合が存在するように、 2つ以上の端末集合を決定し、 (b) 端末毎及び決定した端末集合毎に対応して各々別個の復号鍵を定め、 (c) 前記各端末に対して、当該端末に対応して定めた復号鍵、及び当該端末を含む全ての端末集合の各々に対応して定めた復号鍵を全て割り当てる方法であり、 前記暗号化鍵特定装置は、暗号化鍵を特定する装置であり、かつ、 1つ以上の端末を無効化端末として特定する無効化端末特定手段と、 前記所定鍵割当方法により端末に割当てられた全ての復号鍵のうち無効化端末に割当てられた復号鍵以外の復号鍵を有効復号鍵と定めた場合において、 選定済みの有効復号鍵が割り当てられていない最も多くの端末に、割当てられている有効復号鍵を選定するという手順を、 選定済みの有効復号鍵が割り当てられていない端末が存在しなくなるまで繰り返したと仮定したときに、結果的に選定済みとなる全ての有効復号鍵それぞれに呼応する暗号化鍵を特定する暗号化鍵特定手段とを有する装置であり、 前記暗号化装置は、前記暗号化鍵特定装置により特定された全ての暗号化鍵を逐次用いて配給用データを暗号化し、暗号化配給用データ群を生成して出力する暗号化手段を有することを特徴とするデータ保護システム。
- 13A decryption key determination device for determining a decryption key group for decryption to be individually assigned to each of three or more terminals for acquiring and decrypting encrypted data. (a) so that each of the terminals belongs to at least one of the terminal sets, which is a set containing two or more terminals as elements. Further, it is said that it is a plurality of terminal sets each including the same one or more terminals in each element, and none of the terminal sets in the plurality of terminal sets is a subset of each other terminal set in the plurality of terminal sets. So that there are multiple terminal sets where the relationship is established Determine two or more terminal sets and (b) Decryption key setting means that associates a separate decryption key with each terminal and each determined terminal set. For each terminal, the decryption key associated with the terminal by the decryption key setting means and all the decryption keys associated with each of all the terminal sets including the terminal are assigned to the terminal. A decryption key determination device including a decryption key group assigning means for determining as a group. 【請求項13】 暗号化されたデータを取得して復号するための3台以上の端末それぞれに、個別に割り当てる復号用の復号鍵群を決定するための復号鍵決定装置であって、 (a) 前記各端末が、2つ以上の端末を要素に含む集合である端末集合の少なくとも1つには属するように、 更に、同じ1つ以上の端末を各々要素に含む複数の端末集合であって、当該複数の端末集合におけるいずれの一の端末集合も当該複数の端末集合における他の各端末集合の部分集合でないという関係が成立するところの当該複数の端末集合が存在するように、 2つ以上の端末集合を決定し、 (b) 端末毎及び決定した端末集合毎について各々別個の復号鍵を対応付ける復号鍵設定手段と、 前記各端末に対して、前記復号鍵設定手段により当該端末に対応付けられた復号鍵及び当該端末を含む全ての端末集合の各々に対応付けられた復号鍵全てを、当該端末に割り当てるべき復号鍵群として決定する復号鍵群割当手段とを備えることを特徴とする復号鍵決定装置。
- 16The decryption key setting means is For each node (parent) except the lowest layer when assuming a tree structure of multiple layers of N-branch (N is a natural number of 3 or more) in which each terminal corresponds to a separate lowest layer node. Of the N nodes in the lower layer of the 1st stage that can be reached from the node), 2 or more are combined to determine a plurality of combination patterns including all N combinations, and a separate decryption key is determined for each determined combination pattern. Each of the determined decryption keys is stored in association with the relevant node (parent node), and a separate decryption key is stored in association with each node in the lowest layer. The decryption key group allocation means For each of the terminals, each node that is not the lowest layer located on the path from the node of the lowest layer corresponding to the terminal to the node of the highest layer is stored in association with the node by the decryption key setting means. Among the decrypted keys, the decryption keys corresponding to all the combination patterns related to the combination including the node located on the path in the lower layer of the node, and the decryption key setting in association with the terminal. The decryption key stored by the means is determined as to be assigned to the terminal, and Each terminal set is A claim having a one-to-one correspondence with each combination pattern, and corresponding to a set having all terminals corresponding to the lowest layer nodes reached from all the combined nodes in the corresponding combination pattern. Item 15. Decryption key determination device. 【請求項16】 前記復号鍵設定手段は、 各端末を各々別個の最下位層のノードに対応させた複数階層のN分木(Nは3以上の自然数)の木構造を想定した場合における最下位層を除く各ノードについて、当該ノード(親ノード)から辿り着く1段下位層のN個のノードのうち、2以上を組合せてなりN個全部の組合せを含む複数の組合せパターンを決定し、決定した組合せパターン毎に別個の復号鍵を定めてその定めた各復号鍵を当該ノード(親ノード)と対応付けて記憶しており、更に最下位層の各ノードに対応付けて別個の復号鍵を記憶しており、 前記復号鍵群割当手段は、 前記各端末について、当該端末に対応する最下位層のノードから最上位層のノードまでの経路上に位置する最下位層でない各ノードについて、当該ノードに対応付けて前記復号鍵鍵設定手段により記憶されている復号鍵のうち、当該ノードの1段下位層で当該経路上に位置するノードを含む組合せに係る全ての前記組合せパターンに対応する復号鍵と、当該端末に対応付けて前記復号鍵設定手段により記憶されている復号鍵とを、当該端末に割り当てるべきものとして決定し、 前記各端末集合は、 前記各組合せパターンと一対一に対応し、対応する組合せパターンにおいて組み合わされた全ノードからから辿り着く最下位層のノードに対応する全ての端末を要素とする集合に相当することを特徴とする請求項15記載の復号鍵決定装置。
- 19A method for determining a decryption key for determining a decryption key group for decryption to be individually assigned to each of three or more terminals for acquiring and decrypting encrypted data. Each of the terminals belongs to at least one of the terminal sets, which is a set containing two or more terminals as elements. Further, it is said that it is a plurality of terminal sets each including the same one or more terminals in each element, and none of the terminal sets in the plurality of terminal sets is a subset of each other terminal set in the plurality of terminal sets. So that there are multiple terminal sets where the relationship is established A terminal set determination step that determines two or more terminal sets, and A decryption key associating step that associates a separate decryption key with each terminal and each terminal set determined by the terminal set determination step, For each terminal, the decryption key associated with the terminal by the decryption key mapping step and all the decryption keys associated with each of all the terminal sets including the terminal should be assigned to the terminal. A method for determining a decryption key, which comprises a decryption key group allocation step for determining as a key group. 【請求項19】 暗号化されたデータを取得して復号するための3台以上の端末それぞれに、個別に割り当てる復号用の復号鍵群を決定するための復号鍵決定方法であって、 前記各端末が、2つ以上の端末を要素に含む集合である端末集合の少なくとも1つには属するように、 更に、同じ1つ以上の端末を各々要素に含む複数の端末集合であって、当該複数の端末集合におけるいずれの一の端末集合も当該複数の端末集合における他の各端末集合の部分集合でないという関係が成立するところの当該複数の端末集合が存在するように、 2つ以上の端末集合を決定する端末集合決定ステップと、 端末毎及び前記端末集合決定ステップにより決定された端末集合毎について各々別個の復号鍵を対応付ける復号鍵対応付けステップと、 前記各端末に対して、前記復号鍵対応付けステップにより当該端末に対応付けられた復号鍵及び当該端末を含む全ての端末集合の各々に対応付けられた復号鍵全てを、当該端末に割り当てるべき復号鍵群として決定する復号鍵群割当ステップとを含むことを特徴とする復号鍵決定方法。
- 20To cause a computer to execute a decryption key determination process for determining a decryption key group for decryption to be individually assigned to each of three or more terminals for acquiring and decrypting encrypted data. In computer programs The decryption key determination process is performed. Each of the terminals belongs to at least one of the terminal sets, which is a set containing two or more terminals as elements. Further, it is said that it is a plurality of terminal sets each including the same one or more terminals in each element, and none of the terminal sets in the plurality of terminal sets is a subset of each other terminal set in the plurality of terminal sets. So that there are multiple terminal sets where the relationship is established A terminal set determination step that determines two or more terminal sets, and A decryption key associating step that associates a separate decryption key with each terminal and each terminal set determined by the terminal set determination step, For each terminal, the decryption key associated with the terminal by the decryption key mapping step and all the decryption keys associated with each of all the terminal sets including the terminal should be assigned to the terminal. A computer program comprising a decryption key group allocation step that determines as a key group. 【請求項20】 暗号化されたデータを取得して復号するための3台以上の端末それぞれに、個別に割り当てる復号用の復号鍵群を決定するための復号鍵決定処理をコンピュータに実行させるためのコンピュータプログラムにおいて、 前記復号鍵決定処理は、 前記各端末が、2つ以上の端末を要素に含む集合である端末集合の少なくとも1つには属するように、 更に、同じ1つ以上の端末を各々要素に含む複数の端末集合であって、当該複数の端末集合におけるいずれの一の端末集合も当該複数の端末集合における他の各端末集合の部分集合でないという関係が成立するところの当該複数の端末集合が存在するように、 2つ以上の端末集合を決定する端末集合決定ステップと、 端末毎及び前記端末集合決定ステップにより決定された端末集合毎について各々別個の復号鍵を対応付ける復号鍵対応付けステップと、 前記各端末に対して、前記復号鍵対応付けステップにより当該端末に対応付けられた復号鍵及び当該端末を含む全ての端末集合の各々に対応付けられた復号鍵全てを、当該端末に割り当てるべき復号鍵群として決定する復号鍵群割当ステップとを含むことを特徴とするコンピュータプログラム。
- 21To cause a computer to execute a decryption key determination process for determining a decryption key group for decryption to be individually assigned to each of three or more terminals for acquiring and decrypting encrypted data. In the recording medium on which the computer program of The decryption key determination process is performed. Each of the terminals belongs to at least one of the terminal sets, which is a set containing two or more terminals as elements. Further, it is said that it is a plurality of terminal sets each including the same one or more terminals in each element, and none of the terminal sets in the plurality of terminal sets is a subset of each other terminal set in the plurality of terminal sets. So that there are multiple terminal sets where the relationship is established A terminal set determination step that determines two or more terminal sets, and A decryption key associating step that associates a separate decryption key with each terminal and each terminal set determined by the terminal set determination step, For each terminal, the decryption key associated with the terminal by the decryption key mapping step and all the decryption keys associated with each of all the terminal sets including the terminal should be assigned to the terminal. A recording medium including a decryption key group allocation step that is determined as a key group. 【請求項21】 暗号化されたデータを取得して復号するための3台以上の端末それぞれに、個別に割り当てる復号用の復号鍵群を決定するための復号鍵決定処理をコンピュータに実行させるためのコンピュータプログラムを記録した記録媒体において、 前記復号鍵決定処理は、 前記各端末が、2つ以上の端末を要素に含む集合である端末集合の少なくとも1つには属するように、 更に、同じ1つ以上の端末を各々要素に含む複数の端末集合であって、当該複数の端末集合におけるいずれの一の端末集合も当該複数の端末集合における他の各端末集合の部分集合でないという関係が成立するところの当該複数の端末集合が存在するように、 2つ以上の端末集合を決定する端末集合決定ステップと、 端末毎及び前記端末集合決定ステップにより決定された端末集合毎について各々別個の復号鍵を対応付ける復号鍵対応付けステップと、 前記各端末に対して、前記復号鍵対応付けステップにより当該端末に対応付けられた復号鍵及び当該端末を含む全ての端末集合の各々に対応付けられた復号鍵全てを、当該端末に割り当てるべき復号鍵群として決定する復号鍵群割当ステップとを含むことを特徴とする記録媒体。
- 22A decryption terminal system composed of three or more terminals for acquiring and decrypting encrypted data. Each of the above terminals Decryption key group storage means that stores decryption key groups individually assigned by a predetermined key allocation method, and Encrypted data acquisition means for acquiring encrypted data, It is provided with a decryption means for decrypting the data acquired by the encrypted data acquisition means by using the decryption key stored in the decryption key group storage means. The predetermined key allocation method is (a) so that each of the terminals belongs to at least one of the terminal sets, which is a set containing two or more terminals as elements. Further, it is said that it is a plurality of terminal sets each including the same one or more terminals in each element, and none of the terminal sets in the plurality of terminal sets is a subset of each other terminal set in the plurality of terminal sets. So that there are multiple terminal sets where the relationship is established Determine two or more terminal sets and (b) Set a separate decryption key for each terminal and each determined terminal set. (c) A decryption terminal characterized by a method of assigning a decryption key determined corresponding to the terminal and a decryption key determined corresponding to each of all terminal sets including the terminal to each of the terminals. system. 【請求項22】 暗号化されたデータを取得して復号するための3台以上の端末から構成される復号端末システムであって、 前記各端末は、 所定鍵割当方法により個別に割当てられた復号鍵群を記憶している復号鍵群記憶手段と、 暗号化されたデータを取得する暗号化データ取得手段と、 前記暗号化データ取得手段により取得されたデータを、前記復号鍵群記憶手段に記憶されている復号鍵を用いて復号する復号手段とを備え、 前記所定鍵割当方法は、 (a) 前記各端末が、2つ以上の端末を要素に含む集合である端末集合の少なくとも1つには属するように、 更に、同じ1つ以上の端末を各々要素に含む複数の端末集合であって、当該複数の端末集合におけるいずれの一の端末集合も当該複数の端末集合における他の各端末集合の部分集合でないという関係が成立するところの当該複数の端末集合が存在するように、 2つ以上の端末集合を決定し、 (b) 端末毎及び決定した端末集合毎に対応して各々別個の復号鍵を定め、 (c) 前記各端末に対して、当該端末に対応して定めた復号鍵、及び当該端末を含む全ての端末集合の各々に対応して定めた復号鍵を全て割り当てる方法であることを特徴とする復号端末システム。
- 24The data recording medium records encryption key identification information for identifying an encryption key. The terminal further Random number data generation means to generate key data that is a random number, Content storage means for storing content data that is a digital copyrighted work, Among the encryption key groups corresponding to the decryption key group stored in the decryption key group storage means by reading the encryption key specific information from the data recording medium, the encryption key specified by the encryption key specific information is selected. Encryption key selection method to be selected and An encryption key data group is generated by encrypting the key data generated by the random number data generation means by sequentially using all the encryption keys selected by the encryption key selection means, and the encryption key is generated. A key data encryption means for recording a data group on the data recording medium, and Encrypted content data is generated by encrypting the content data stored in the content storage unit using the key data generated by the random number data generating means as a key, and the encrypted content data is recorded in the data. Equipped with content encryption means to record on media The encrypted data acquisition means acquires the encryption key data and the encrypted content data recorded in the data recording medium, and obtains the encrypted key data and the encrypted content data. The decryption means generates key data by decrypting the encryption key data acquired by the encryption data acquisition means by using a decryption key stored in the decryption key group storage means. , 23. The terminal is further provided with a content decryption means for decrypting the encrypted content data acquired by the encrypted data acquisition means by using the key data generated by the decryption means. Decryption terminal system. 【請求項24】 前記データ記録媒体には、暗号化鍵を特定するための暗号化鍵特定情報が記録されており、 前記端末は更に、 乱数である鍵データを生成する乱数データ発生手段と、 デジタル著作物であるコンテンツデータを格納しているコンテンツ格納手段と、 前記データ記録媒体から暗号化鍵特定情報を読み出し、前記復号鍵群記憶手段に記憶されている復号鍵群に呼応する暗号化鍵群のうち当該暗号化鍵特定情報で特定される暗号化鍵を選定する暗号化鍵選定手段と、 前記暗号化鍵選定手段により選定された全ての暗号化鍵を逐次用いて前記乱数データ発生手段により生成された鍵データを暗号化することにより暗号化鍵データ群を生成して、当該暗号化鍵データ群を前記データ記録媒体に記録する鍵データ暗号化手段と、 前記乱数データ発生手段により生成された鍵データを鍵として用いて前記コンテンツ格納部に格納されているコンテンツデータを暗号化することにより暗号化コンテンツデータを生成し、当該暗号化コンテンツデータを前記データ記録媒体に記録するコンテンツ暗号化手段とを備え、 前記暗号化データ取得手段は、前記データ記録媒体に記録されている暗号化鍵データ及び暗号化コンテンツデータを取得し、 前記復号手段は、前記暗号化データ取得手段により取得された前記暗号化鍵データを、前記復号鍵群記憶手段に記憶されている復号鍵を用いて復号することにより鍵データを生成するものであり、 前記端末は更に、前記暗号化データ取得手段により取得された前記暗号化コンテンツデータを、前記復号手段により生成された鍵データを用いて復号するコンテンツ復号手段を備えることを特徴とする請求項23記載の復号端末システム。
- 26An encryption key identification device that specifies an encryption key to be used for encrypting distribution data to three or more terminals. (a) so that each of the terminals belongs to at least one of the terminal sets, which is a set containing two or more terminals as elements. Further, it is said that it is a plurality of terminal sets each including the same one or more terminals in each element, and none of the terminal sets in the plurality of terminal sets is a subset of each other terminal set in the plurality of terminal sets. So that there are multiple terminal sets where the relationship is established Determine two or more terminal sets and (b) Decryption key group associating means for associating different decryption keys for each terminal and each determined terminal set. For each terminal, in addition to the decryption key associated with the terminal by the decryption key setting means, all the decryption keys associated with each of all the terminal sets including the terminal are associated with the terminal. Decryption key setting means and Disabling terminal identification means to identify one or more terminals as invalidating terminals, When the decryption key other than the decryption key associated with the invalidated terminal is defined as the valid decryption key among all the decryption keys associated with the terminal by the decryption key group associating means. The procedure of selecting the valid decryption key associated with the most terminals to which the selected valid decryption key is not associated is followed. An encryption key that identifies an encryption key that corresponds to each of the selected valid decryption keys, assuming that it is repeated until there are no terminals that are not associated with the selected valid decryption key. An encryption key identification device including a specific means. 【請求項26】 3台以上の各端末への配給用データの暗号化に用いるべき暗号化鍵を特定する暗号化鍵特定装置であって、 (a) 前記各端末が、2つ以上の端末を要素に含む集合である端末集合の少なくとも1つには属するように、 更に、同じ1つ以上の端末を各々要素に含む複数の端末集合であって、当該複数の端末集合におけるいずれの一の端末集合も当該複数の端末集合における他の各端末集合の部分集合でないという関係が成立するところの当該複数の端末集合が存在するように、 2つ以上の端末集合を決定し、 (b) 端末毎及び決定した端末集合毎について各々別個の復号鍵を対応付ける復号鍵群対応付け手段と、 前記各端末に対して、前記復号鍵設定手段により当該端末に対応付けられた復号鍵に加えて、当該端末を含む全ての端末集合の各々に対応付けられた復号鍵全てを、当該端末に対応付ける復号鍵設定手段と、 1つ以上の端末を無効化端末として特定する無効化端末特定手段と、 前記復号鍵群対応付け手段により端末に対応付けられた全ての復号鍵のうち無効化端末に対応付けられている復号鍵以外の復号鍵を有効復号鍵と定めた場合において、 選定済みの有効復号鍵が対応付けられていない最も多くの端末に対応付けられている有効復号鍵を選定するという手順を、 選定済みの有効復号鍵が対応付けられていない端末が存在しなくなるまで繰り返したと仮定したときに、結果的に選定済みとなる全ての有効復号鍵それぞれに呼応する暗号化鍵を特定する暗号化鍵特定手段とを備えることを特徴とする暗号化鍵特定装置。
- 30The determination of the plurality of combination patterns for each node other than the lowest layer in the case of assuming the tree structure by the decryption key setting means is one step lower than the node (parent node). It is made by defining a combination pattern so as to correspond to each combination of two or more of the N nodes in the layer, and the decryption key setting means is all determined for each node (parent node). As invalidation pattern information obtained by concatenating the combination pattern of the above N nodes arriving from the node (parent node) according to a predetermined node order, the values indicating whether or not each of the N nodes is to be combined is the node (parent). In addition to storing in association with the node), a separate decryption key is determined for each invalidation pattern information, and each of the determined decryption keys is stored in association with the node (parent node) and the invalidation pattern information. In the case of assuming the tree structure, the encryption key identification means defines all the nodes that reach the lowest layer node corresponding to any of the invalidated terminals as invalid nodes, and each node except the lowest layer. After specifying the invalidation information indicating whether or not each of the N nodes in the lower layer one step reached from the relevant node is an invalid node, the encryption key identification process is performed. The encryption key identification process is performed on one unprocessed node to be processed. (a) If there is invalidation pattern information consistent with the invalidation information specified for the processing target node, the decryption key stored by the decryption key setting means corresponding to the invalidation pattern information is used. Identify the corresponding encryption key and (b) If there is no invalidation pattern information that matches the invalidation information specified for the node to be processed, and if the lower layer is the lowest layer, other than the invalid node in the lower layer. The encryption key corresponding to the decryption key stored by the decryption key setting means is specified corresponding to all the nodes, and if the one-step lower layer is not the lowest layer, other than the invalid node in the one-step lower layer. All nodes of the above are newly set as the processing target nodes, (c) Claim 29, wherein if an invalid node exists in the one-stage lower layer of the processing target node, all the invalid nodes are newly set as the processing target node unless the one-stage layer is the lowest layer. Described encryption key identification device. 【請求項30】 前記復号鍵設定手段による、前記木構造を想定した場合における最下位層を除く各ノードについての前記複数の組合せパターンの決定は、当該ノード(親ノード)から辿り着く1段下位層のN個のノードのうち、2以上を組合せてなる全ての組合せそれぞれに対応するように組合せパターンを定めることによりなされ、当該復号鍵設定手段は、その各ノード(親ノード)について決定した全ての組合せパターンを、当該ノード(親ノード)から辿り着く前記N個のノードそれぞれを組合せ対象とするか否かを示す値を所定のノード順序に従って連結させてなる無効化パターン情報として当該ノード(親ノード)と対応付けて記憶するとともに、無効化パターン情報毎に別個の復号鍵を定めて、その定めた各復号鍵を当該ノード(親ノード)及び当該無効化パターン情報と対応付けて記憶し、 前記暗号化鍵特定手段は、前記木構造を想定した場合において、いずれかの無効化端末に対応する最下位層のノードに辿り着く全てのノードを無効ノードと定め、最下位層を除く各ノードについて、当該ノードから辿り着く1段下位層のN個のノードそれぞれが無効ノードであるか否かを示す無効化情報を特定した後に、前記暗号化鍵特定処理を行い、 前記暗号化鍵特定処理は、未処理の1つの処理対象ノードについて、 (a) 当該処理対象ノードについて特定された無効化情報と整合する無効化パターン情報が存在する場合には、当該無効化パターン情報に対応して前記復号鍵設定手段により記憶されている復号鍵に呼応する暗号化鍵を特定し、 (b) 当該処理対象ノードについて特定された無効化情報と整合する無効化パターン情報が存在しない場合には、当該1段下位層が最下位層であれば当該1段下位層における無効ノード以外の全てのノードに対応して前記復号鍵設定手段により記憶されている復号鍵に呼応する暗号化鍵を特定し、当該1段下位層が最下位層でなければ当該1段下位層における無効ノード以外の全てのノードを新たに処理対象ノードとし、 (c) 当該処理対象ノードの1段下位層において無効ノードが存在すれば、当該1段階層が最下位層でない限り全ての無効ノードを新たに処理対象ノードとする処理であることを特徴とする請求項29記載の暗号化鍵特定装置。
- 32An encryption device that encrypts distribution data to three or more terminals. (a) so that each of the terminals belongs to at least one of the terminal sets, which is a set containing two or more terminals as elements. Further, it is said that it is a plurality of terminal sets each including the same one or more terminals in each element, and none of the terminal sets in the plurality of terminal sets is a subset of each other terminal set in the plurality of terminal sets. So that there are multiple terminal sets where the relationship is established Determine two or more terminal sets and (b) Decryption key setting means that associates a separate decryption key with each terminal and each determined terminal set. For each terminal, in addition to the decryption key associated with the terminal by the decryption key setting means, all the decryption keys associated with each of all the terminal sets including the terminal are associated with the terminal. Decryption key group mapping means and Disabling terminal identification means to identify one or more terminals as invalidating terminals, When the decryption key other than the decryption key associated with the invalidated terminal is defined as the valid decryption key among all the decryption keys associated with the terminal by the decryption key group associating means. The procedure of selecting the valid decryption key associated with the most terminals to which the selected valid decryption key is not associated is followed. An encryption key that identifies an encryption key that corresponds to each of the selected valid decryption keys, assuming that it is repeated until there are no terminals to which the selected valid decryption key is associated. With specific means An encryption means that encrypts distribution data by sequentially using all the encryption keys specified by the encryption key identification means and generates an encrypted distribution data group. An encryption device including an output means for outputting an encrypted distribution data group generated by the encryption means to the outside. 【請求項32】 3台以上の各端末への配給用データを暗号化する暗号化装置であって、 (a) 前記各端末が、2つ以上の端末を要素に含む集合である端末集合の少なくとも1つには属するように、 更に、同じ1つ以上の端末を各々要素に含む複数の端末集合であって、当該複数の端末集合におけるいずれの一の端末集合も当該複数の端末集合における他の各端末集合の部分集合でないという関係が成立するところの当該複数の端末集合が存在するように、 2つ以上の端末集合を決定し、 (b) 端末毎及び決定した端末集合毎について各々別個の復号鍵を対応付ける復号鍵設定手段と、 前記各端末に対して、前記復号鍵設定手段により当該端末に対応付けられた復号鍵に加えて、当該端末を含む全ての端末集合の各々に対応付けられた復号鍵全てを、当該端末に対応付ける復号鍵群対応付け手段と、 1つ以上の端末を無効化端末として特定する無効化端末特定手段と、 前記復号鍵群対応付け手段により端末に対応付けられた全ての復号鍵のうち無効化端末に対応付けられている復号鍵以外の復号鍵を有効復号鍵と定めた場合において、 選定済みの有効復号鍵が対応付けられていない最も多くの端末に対応付けられている有効復号鍵を選定するという手順を、 選定済みの有効復号鍵が対応付けられていない端末が存在しなくなるまで繰り返したと仮定したときに、結果的に選定済みとなる全ての有効復号鍵それぞれに呼応する暗号化鍵を特定する暗号化鍵特定手段と、 前記暗号化鍵特定手段により特定された全ての暗号化鍵を逐次用いて配給用データを暗号化し、暗号化配給用データ群を生成する暗号化手段と、 前記暗号化手段により生成された暗号化配給用データ群を外部に出力する出力手段とを備えることを特徴とする暗号化装置。
- 37A method for specifying an encryption key for specifying an encryption key to be used for encrypting distribution data to three or more terminals. Each of the terminals belongs to at least one of the terminal sets, which is a set containing two or more terminals as elements. Further, it is said that it is a plurality of terminal sets each including the same one or more terminals in each element, and none of the terminal sets in the plurality of terminal sets is a subset of each other terminal set in the plurality of terminal sets. So that there are multiple terminal sets where the relationship is established A terminal set determination step that determines two or more terminal sets, and A decryption key associating step that associates a separate decryption key with each terminal and each terminal set determined by the terminal set determination step, For each terminal, in addition to the decryption key associated with the terminal by the decryption key mapping step, all the decryption keys associated with each of all the terminal sets including the terminal are transmitted to the terminal. Decryption key group mapping step to be associated and The invalidation terminal identification step that identifies one or more terminals as invalidation terminals, When the decryption key other than the decryption key associated with the invalidated terminal is defined as the valid decryption key among all the decryption keys associated with the terminal by the decryption key group mapping step. The procedure of selecting the valid decryption key associated with the most terminals to which the selected valid decryption key is not associated is repeated until there is no terminal to which the selected valid decryption key is not associated. repetition, A method for identifying an encryption key, which comprises an encryption key identification step for specifying an encryption key corresponding to each of all the valid decryption keys selected as a result. 【請求項37】 3台以上の各端末への配給用データの暗号化に用いるべき暗号化鍵を特定するための暗号化鍵特定方法であって、 前記各端末が、2つ以上の端末を要素に含む集合である端末集合の少なくとも1つには属するように、 更に、同じ1つ以上の端末を各々要素に含む複数の端末集合であって、当該複数の端末集合におけるいずれの一の端末集合も当該複数の端末集合における他の各端末集合の部分集合でないという関係が成立するところの当該複数の端末集合が存在するように、 2つ以上の端末集合を決定する端末集合決定ステップと、 端末毎及び前記端末集合決定ステップにより決定された端末集合毎について各々別個の復号鍵を対応付ける復号鍵対応付けステップと、 前記各端末に対して、前記復号鍵対応付けステップにより当該端末に対応付けられた復号鍵に加えて、当該端末を含む全ての端末集合の各々に対応付けられた復号鍵全てを、当該端末に対応付ける復号鍵群対応付けステップと、 1つ以上の端末を無効化端末として特定する無効化端末特定ステップと、 前記復号鍵群対応付けステップにより端末に対応付けられた全ての復号鍵のうち無効化端末に対応付けられている復号鍵以外の復号鍵を有効復号鍵と定めた場合において、 選定済みの有効復号鍵が対応付けられていない最も多くの端末に対応付けられている有効復号鍵を選定するという手順を、選定済みの有効復号鍵が対応付けられていない端末が存在しなくなるまで繰り返し、 結果的に選定済みとなる全ての有効復号鍵それぞれに呼応する暗号化鍵を特定する暗号化鍵特定ステップとを含むことを特徴とする暗号化鍵特定方法。
- 38A computer program for causing a computer to perform a specific process for specifying an encryption key to be used for encrypting distribution data to three or more terminals. The specific process is Each of the terminals belongs to at least one of the terminal sets, which is a set containing two or more terminals as elements. Further, it is said that it is a plurality of terminal sets each including the same one or more terminals in each element, and none of the terminal sets in the plurality of terminal sets is a subset of each other terminal set in the plurality of terminal sets. So that there are multiple terminal sets where the relationship is established A terminal set determination step that determines two or more terminal sets, and A decryption key associating step that associates a separate decryption key with each terminal and each terminal set determined by the terminal set determination step, For each terminal, in addition to the decryption key associated with the terminal by the decryption key mapping step, all the decryption keys associated with each of all the terminal sets including the terminal are transmitted to the terminal. Decryption key group mapping step to be associated and The invalidation terminal identification step that identifies one or more terminals as invalidation terminals, When the decryption key other than the decryption key associated with the invalidated terminal is defined as the valid decryption key among all the decryption keys associated with the terminal by the decryption key group mapping step. The procedure of selecting the valid decryption key associated with the most terminals to which the selected valid decryption key is not associated is repeated until there is no terminal to which the selected valid decryption key is not associated. repetition, A computer program comprising:an encryption key identification step that specifies an encryption key corresponding to each of the resultingly selected valid decryption keys. 【請求項38】 3台以上の各端末への配給用データの暗号化に用いるべき暗号化鍵を特定するための特定処理をコンピュータに実行させるためのコンピュータプログラムであって、 前記特定処理は、 前記各端末が、2つ以上の端末を要素に含む集合である端末集合の少なくとも1つには属するように、 更に、同じ1つ以上の端末を各々要素に含む複数の端末集合であって、当該複数の端末集合におけるいずれの一の端末集合も当該複数の端末集合における他の各端末集合の部分集合でないという関係が成立するところの当該複数の端末集合が存在するように、 2つ以上の端末集合を決定する端末集合決定ステップと、 端末毎及び前記端末集合決定ステップにより決定された端末集合毎について各々別個の復号鍵を対応付ける復号鍵対応付けステップと、 前記各端末に対して、前記復号鍵対応付けステップにより当該端末に対応付けられた復号鍵に加えて、当該端末を含む全ての端末集合の各々に対応付けられた復号鍵全てを、当該端末に対応付ける復号鍵群対応付けステップと、 1つ以上の端末を無効化端末として特定する無効化端末特定ステップと、 前記復号鍵群対応付けステップにより端末に対応付けられた全ての復号鍵のうち無効化端末に対応付けられている復号鍵以外の復号鍵を有効復号鍵と定めた場合において、 選定済みの有効復号鍵が対応付けられていない最も多くの端末に対応付けられている有効復号鍵を選定するという手順を、選定済みの有効復号鍵が対応付けられていない端末が存在しなくなるまで繰り返し、 結果的に選定済みとなる全ての有効復号鍵それぞれに呼応する暗号化鍵を特定する暗号化鍵特定ステップとを含むことを特徴とするコンピュータプログラム。
- 39A recording medium on which a computer program for causing a computer to execute a specific process for specifying an encryption key to be used for encrypting distribution data to three or more terminals is recorded. The specific process is Each of the terminals belongs to at least one of the terminal sets, which is a set containing two or more terminals as elements. Further, it is said that it is a plurality of terminal sets each including the same one or more terminals in each element, and none of the terminal sets in the plurality of terminal sets is a subset of each other terminal set in the plurality of terminal sets. So that there are multiple terminal sets where the relationship is established A terminal set determination step that determines two or more terminal sets, and A decryption key associating step that associates a separate decryption key with each terminal and each terminal set determined by the terminal set determination step, For each terminal, in addition to the decryption key associated with the terminal by the decryption key mapping step, all the decryption keys associated with each of all the terminal sets including the terminal are transmitted to the terminal. Decryption key group mapping step to be associated and The invalidation terminal identification step that identifies one or more terminals as invalidation terminals, When the decryption key other than the decryption key associated with the invalidated terminal is defined as the valid decryption key among all the decryption keys associated with the terminal by the decryption key group mapping step. The procedure of selecting the valid decryption key associated with the most terminals to which the selected valid decryption key is not associated is repeated until there is no terminal to which the selected valid decryption key is not associated. repetition, A recording medium including an encryption key identification step for specifying an encryption key corresponding to each of all valid decryption keys selected as a result. 【請求項39】 3台以上の各端末への配給用データの暗号化に用いるべき暗号化鍵を特定するための特定処理をコンピュータに実行させるためのコンピュータプログラムを記録した記録媒体であって、 前記特定処理は、 前記各端末が、2つ以上の端末を要素に含む集合である端末集合の少なくとも1つには属するように、 更に、同じ1つ以上の端末を各々要素に含む複数の端末集合であって、当該複数の端末集合におけるいずれの一の端末集合も当該複数の端末集合における他の各端末集合の部分集合でないという関係が成立するところの当該複数の端末集合が存在するように、 2つ以上の端末集合を決定する端末集合決定ステップと、 端末毎及び前記端末集合決定ステップにより決定された端末集合毎について各々別個の復号鍵を対応付ける復号鍵対応付けステップと、 前記各端末に対して、前記復号鍵対応付けステップにより当該端末に対応付けられた復号鍵に加えて、当該端末を含む全ての端末集合の各々に対応付けられた復号鍵全てを、当該端末に対応付ける復号鍵群対応付けステップと、 1つ以上の端末を無効化端末として特定する無効化端末特定ステップと、 前記復号鍵群対応付けステップにより端末に対応付けられた全ての復号鍵のうち無効化端末に対応付けられている復号鍵以外の復号鍵を有効復号鍵と定めた場合において、 選定済みの有効復号鍵が対応付けられていない最も多くの端末に対応付けられている有効復号鍵を選定するという手順を、選定済みの有効復号鍵が対応付けられていない端末が存在しなくなるまで繰り返し、 結果的に選定済みとなる全ての有効復号鍵それぞれに呼応する暗号化鍵を特定する暗号化鍵特定ステップとを含むことを特徴とする記録媒体。
- 40A computer that records a plurality of encrypted distribution data in which distribution data to each of three or more terminals is encrypted using each of a plurality of encryption keys specified by a specific process. A readable recording medium The specific process is Each of the terminals belongs to at least one of the terminal sets, which is a set containing two or more terminals as elements. Further, it is said that it is a plurality of terminal sets each including the same one or more terminals in each element, and none of the terminal sets in the plurality of terminal sets is a subset of each other terminal set in the plurality of terminal sets. So that there are multiple terminal sets where the relationship is established A terminal set determination step that determines two or more terminal sets, and A decryption key associating step that associates a separate decryption key with each terminal and each terminal set determined by the terminal set determination step, For each terminal, in addition to the decryption key associated with the terminal by the decryption key mapping step, all the decryption keys associated with each of all the terminal sets including the terminal are transmitted to the terminal. Decryption key group mapping step to be associated and The invalidation terminal identification step that identifies one or more terminals as invalidation terminals, When the decryption key other than the decryption key associated with the invalidated terminal is defined as the valid decryption key among all the decryption keys associated with the terminal by the decryption key group mapping step. The procedure of selecting the valid decryption key associated with the most terminals to which the selected valid decryption key is not associated is repeated until there is no terminal to which the selected valid decryption key is not associated. repetition, A recording medium including an encryption key identification step for specifying an encryption key corresponding to each of all valid decryption keys selected as a result. 【請求項40】 3台以上の各端末への配給用データが、特定処理により特定された複数の暗号化鍵それぞれを用いて暗号化されてなる複数の暗号化配給用データを、記録したコンピュータ読み取り可能な記録媒体であって、 前記特定処理は、 前記各端末が、2つ以上の端末を要素に含む集合である端末集合の少なくとも1つには属するように、 更に、同じ1つ以上の端末を各々要素に含む複数の端末集合であって、当該複数の端末集合におけるいずれの一の端末集合も当該複数の端末集合における他の各端末集合の部分集合でないという関係が成立するところの当該複数の端末集合が存在するように、 2つ以上の端末集合を決定する端末集合決定ステップと、 端末毎及び前記端末集合決定ステップにより決定された端末集合毎について各々別個の復号鍵を対応付ける復号鍵対応付けステップと、 前記各端末に対して、前記復号鍵対応付けステップにより当該端末に対応付けられた復号鍵に加えて、当該端末を含む全ての端末集合の各々に対応付けられた復号鍵全てを、当該端末に対応付ける復号鍵群対応付けステップと、 1つ以上の端末を無効化端末として特定する無効化端末特定ステップと、 前記復号鍵群対応付けステップにより端末に対応付けられた全ての復号鍵のうち無効化端末に対応付けられている復号鍵以外の復号鍵を有効復号鍵と定めた場合において、 選定済みの有効復号鍵が対応付けられていない最も多くの端末に対応付けられている有効復号鍵を選定するという手順を、選定済みの有効復号鍵が対応付けられていない端末が存在しなくなるまで繰り返し、 結果的に選定済みとなる全ての有効復号鍵それぞれに呼応する暗号化鍵を特定する暗号化鍵特定ステップとを含むことを特徴とする記録媒体。
- 41A decryption terminal for acquiring and decrypting encrypted data. Decryption key group storage means that stores decryption key groups individually assigned by a predetermined key allocation method, and Encrypted data acquisition means for acquiring encrypted data, A decryption means for decrypting the data acquired by the encrypted data acquisition means using the decryption key stored in the decryption key group storage means, and The predetermined key allocation method is (a) Assuming three or more terminals including this terminal, this terminal belongs to a plurality of terminal sets that include two or more terminals as elements. Further, a relationship is established in which there are a plurality of terminal sets each including the terminal as an element, and none of the terminal sets in the plurality of terminal sets is a subset of each other terminal set in the plurality of terminal sets. However, so that the plurality of terminal sets exist, Determine two or more terminal sets and (b) Determine a separate decryption key for each terminal set for this terminal and for each determined terminal set. (c) The method is characterized in that the decryption key determined corresponding to the terminal and the decryption key determined corresponding to each of all the terminal sets including the terminal are assigned to the terminal. Decryption terminal. 【請求項41】 暗号化されたデータを取得して復号するための復号端末であって、 所定鍵割当方法により個別に割当てられた復号鍵群を記憶している復号鍵群記憶手段と、 暗号化されたデータを取得する暗号化データ取得手段と、 前記暗号化データ取得手段により取得されたデータを、前記復号鍵群記憶手段に記憶されている復号鍵を用いて復号する復号手段と、 前記所定鍵割当方法は、 (a) 本端末を含む3台以上の端末を想定した場合において本端末が、2つ以上の端末を要素に含む集合である複数の端末集合に属するように、 更に、本端末を各々要素に含む複数の端末集合であって、当該複数の端末集合におけるいずれの一の端末集合も当該複数の端末集合における他の各端末集合の部分集合でないという関係が成立するところの当該複数の端末集合が存在するように、 2つ以上の端末集合を決定し、 (b) 本端末に対応して及び決定した端末集合毎に対応して各々別個の復号鍵を定め、 (c) 本端末に対して、本端末に対応して定めた復号鍵、及び本端末を含む全ての端末集合の各々に対応して定めた復号鍵を全て割り当てる方法であることを特徴とする復号端末。
Independent claims16
381 paragraphs in 1 section, as filed
Description: TECHNICAL FIELD [Detailed description of the invention]
【0001】
[Technical field to which the invention belongs]
The present invention relates to a data protection system that encrypts and distributes data to a plurality of terminals, and more particularly to a technique for determining a key used for data encryption and decryption.
【0002】
[Conventional technology]
In recent years, against the background of the development of multimedia-related technology and the emergence of large-capacity recording media, a system for generating digital contents consisting of moving images, audio, etc., storing them in a large-capacity recording medium such as an optical disk, and distributing them has appeared. .. The digital contents recorded on the distributed optical discs and the like are read out by terminals such as computers and playback devices, and are subject to reproduction, copying, and the like.
【0003】
In such a system, an encryption technique is generally used to protect the so-called copyright of digital contents, that is, to prevent unauthorized use such as unauthorized copying of digital contents. That is, such a system encrypts digital contents using a certain encryption key, records them on an optical disk or the like, and distributes them. On the other hand, only the terminal holding the decryption key corresponding to the encryption key decrypts the data read from the optical disk or the like using the decryption key to acquire the original digital content, and reproduces the digital content. It can be carried out.
【0004】
As a method of encrypting the digital content and recording it on the recording medium, a method of encrypting and recording the digital content itself with an encryption key corresponding to the decryption key held by the terminal, or a method of recording the digital content with a certain key. There is a method of encrypting and recording, and then encrypting and recording a decryption key corresponding to the key with an encryption key corresponding to the decryption key held by the terminal.
【0005】
As an example of such a system, for example, "National Technical Report Vol. 43, No. 3, pp. 118-122" (Matsushita Electric Industrial Co., Ltd. Technical General Affairs Center, published on June 18, 1997) contains a DVD copyright protection system. Is disclosed. The DVD playback terminal for playing the digital contents recorded on the DVD distributed in this DVD copyright protection system holds in advance the master key determined for each manufacturer of the playback terminal, and the master key. Is used in the decoding process, and finally has a function of decoding and playing back the digital contents recorded on the DVD. The DVD contains a group of keys required for decrypting digital contents, which are encrypted with the master key of each manufacturer.
【0006】
[Problems to be Solved by the Invention]
By the way, normally, the decryption key held in the terminal is kept secret, but there is a possibility that an unauthorized person recognizes and exposes the decryption key by analysis of the terminal or other methods. Once the decryption key held in a certain terminal is exposed, an unauthorized person may create a terminal or software that decrypts digital contents using this decryption key and perform unauthorized copying. As a result, for copyright protection, digital contents cannot be encrypted with an encryption key corresponding to the exposed decryption key, recorded on an optical disk or the like, and distributed.
【0007】
For example, considering the DVD playback terminal related to the above-mentioned DVD copyright protection system, once the master key is exposed due to unauthorized analysis of one DVD playback terminal, the master key is subsequently encrypted. It becomes impossible to distribute the digital contents. As a result, after the exposure, the DVD generators, etc. will have to encrypt the digital content using a master key different from the one exposed, record the digital content on the DVD, and distribute it. Since many DVD playback terminals manufactured by the same manufacturer as the DVD playback terminals analyzed in the above hold the same master key, they are recorded on the newly generated and distributed DVD after the exposure. There arises a problem that the digital content cannot be decrypted and played back. That is, if one DVD playback terminal is analyzed by an unauthorized person, many DVD playback terminals will not be able to use the newly generated DVD in the future.
【0008】
In order to solve this problem, a separate decryption key is held for each DVD playback terminal, and the digital content or the key required for decrypting the digital content corresponds to the decryption key held by each DVD playback terminal. A method of recording all the encrypted data obtained by encrypting using each encryption key on a DVD can be considered. According to this method, even if some DVD playback terminals are analyzed by an unauthorized person and some decryption keys are exposed, after that, each unexposed decryption held in the DVD playback terminal group is performed. Since all the encrypted data obtained by encrypting digital contents using each encryption key corresponding to the key can be recorded on a DVD and distributed, other than the DVD playback terminal that holds the exposed decryption key. All DVD playback terminals will be able to use newly generated DVDs in the future.
【0009】
However, this method also has a drawback that when the number of DVD playback terminals assumed to be the distribution target of the DVD is enormous, the encrypted data to be recorded on the DVD becomes enormous. Therefore, the present invention has been made in view of such a problem, and is a data protection system that encrypts data such as digital contents and a key required for decrypting encrypted digital contents and distributes the same data to a large number of terminals. Therefore, after suppressing the increase in the amount of encrypted data to be distributed to some extent, when the decryption key held by the specific terminal is exposed by an unauthorized person by analysis of the specific terminal, the specific one is specified. To provide a data protection system using an encryption technology that enables a terminal to correctly decrypt data and another terminal to correctly decrypt data, and to provide a technology useful for constructing such a data protection system. The purpose.
【0010】
[Means for solving problems]
In order to achieve the above object, the data protection system according to the present invention includes three or more terminals, an encryption device, and an encryption key identification device, and the data for distribution to each terminal is encrypted by the encryption device. In the data protection system to be protected, each terminal stores a decryption key group individually assigned by a predetermined key allocation method, and acquires an encryption distribution data group output from the encryption device. The encrypted distribution data is decrypted using the stored decryption key, and the predetermined key allocation method is (a) a set in which each of the terminals includes two or more terminals as elements. A plurality of terminal sets including the same one or more terminals in each element so as to belong to at least one of the terminal sets, and any one terminal set in the plurality of terminal sets is the plurality of terminal sets. Two or more terminal sets are determined so that there is a plurality of terminal sets where the relationship that they are not a subset of each other terminal set in the terminal set is established, and (b) each terminal and the determined terminal set are determined. A separate decryption key is set for each case, and (c) This is a method of assigning a decryption key determined corresponding to the terminal and a decryption key defined corresponding to each of all the terminal sets including the terminal to the terminal, and is a method of assigning the encryption key specifying device. Is a device that identifies an encryption key, and is an invalidation terminal identification means that identifies one or more terminals as an invalidation terminal, and all decryption keys assigned to the terminals by the predetermined key allocation method. When a decryption key other than the decryption key assigned to the invalidation terminal is defined as the valid decryption key, the valid decryption key assigned to the most terminals to which the selected valid decryption key is not assigned is selected. Assuming that the procedure is repeated until there are no terminals to which the selected valid decryption key is assigned, specify the encryption key corresponding to each of the selected valid decryption keys as a result. It is a device having an encryption key identification means, and the encryption device encrypts distribution data by sequentially using all the encryption keys specified by the encryption key identification device, and encrypts the distribution data group. It is characterized by having an encryption means for generating and outputting.
【0011】
Here, the distribution data is data that is expected to be recorded and distributed on a recording medium, or distributed through a wired or wireless communication path, and finally reach each terminal. Assuming terminal 1, terminal 2, and terminal 3, the terminal set determined by the above-mentioned predetermined key allocation method includes a set A of terminal 1 and terminal 2, a set B of terminal 1 and terminal 3, and a terminal 2. And there is a set C of the terminal 3, and the decryption keys stored and held by the terminal 1 in response to the allocation result by the predetermined key allocation method correspond to the decryption key unique to the terminal 1, the decryption key A corresponding to the set A, and the set B. The decryption key B stored in the terminal 2 is the decryption key unique to the terminal 2, the decryption key A corresponding to the set A, and the decryption key C corresponding to the set C, and the terminal 3 The decryption keys to be stored and held are the decryption key unique to the terminal 3, the decryption key B corresponding to the set B, and the decryption key C corresponding to the set C. In this example, if the terminal 2 is illegally analyzed and all the decryption keys stored and held by the terminal 2 are exposed, the terminal 2 is specified as an invalidation terminal, that is, a terminal to be invalidated. When the encryption key is specified by the encryption key specifying means, the encryption key corresponding to the decryption key B is specified.
【0012】
Therefore, if the data is encrypted using the encryption key corresponding to the decryption key B and distributed to each terminal, the terminal 2 cannot correctly decrypt the data, and the terminals 1 and 3 correctly deliver the data. It can be decrypted. For the same purpose, data can be encrypted and distributed to each terminal by using an encryption key corresponding to the decryption key unique to terminal 1 and an encryption key corresponding to the decryption key unique to terminal 3. Compared to this method, the method using the encryption key corresponding to the decryption key B described above has the effect that the number of encryption keys used for encryption is small and the amount of encrypted data to be distributed is reduced accordingly. Has.
【0013】
That is, according to the present invention, in a data protection system that encrypts data such as a key required for decrypting encrypted digital contents and distributes the same data to a plurality of terminals, an increase in the amount of encrypted data to be distributed. If the decryption key held by a specific terminal is exposed by a fraudulent person after suppressing the conversion, the data cannot be decrypted correctly on that specific terminal and the data can be decrypted on other terminals. It is possible to enable correct decryption.
【0014】
Further, the decryption key determination device according to the present invention determines a decryption key for determining a decryption key group for decryption to be individually assigned to each of three or more terminals for acquiring and decrypting encrypted data. A device, (a) such that each terminal belongs to at least one of a terminal set that is a set containing two or more terminals in an element, and further includes the same one or more terminals in each element. There is a plurality of terminal sets in which the relationship that any one terminal set in the plurality of terminal sets is not a subset of each other terminal set in the plurality of terminal sets is established. (B) Decryption key setting means for associating different decryption keys for each terminal and each determined terminal set, and the decryption key setting for each terminal. A decryption key group assigning means for determining a decryption key associated with the terminal by means and a decryption key associated with each of all terminal sets including the terminal as a decryption key group to be assigned to the terminal. It is characterized by being prepared.
【0015】
Further, in the decryption key determination method according to the present invention, the decryption key determination for determining the decryption key group for decryption to be individually assigned to each of three or more terminals for acquiring and decrypting the encrypted data. A method, such that each terminal belongs to at least one of a terminal set that is a set containing two or more terminals in an element, and a plurality of terminals including the same one or more terminals in each element. So that there is a plurality of terminal sets in which the relation that any one terminal set in the plurality of terminal sets is not a subset of each other terminal set in the plurality of terminal sets is established. , A terminal set determination step for determining two or more terminal sets, a decryption key associating step for associating different decryption keys for each terminal and for each terminal set determined by the terminal set determination step, and each terminal. On the other hand, the decryption key associated with the terminal and all the decryption keys associated with each of all the terminal sets including the terminal are determined as the decryption key group to be assigned to the terminal by the decryption key mapping step. It is characterized by including a decryption key group allocation step to be performed.
【0016】
Further, the decryption terminal system according to the present invention is a decryption terminal system composed of three or more terminals for acquiring and decrypting encrypted data, and each of the terminals is subjected to a predetermined key allocation method. The decryption key group storage means for storing the individually assigned decryption key group, the encrypted data acquisition means for acquiring the encrypted data, and the data acquired by the encrypted data acquisition means are decrypted. A decoding means for decrypting using a decryption key stored in a key group storage means is provided, and the predetermined key allocation method is (a) a terminal in which each terminal is a set including two or more terminals as elements. A plurality of terminal sets including the same one or more terminals in each element so as to belong to at least one of the sets, and any one terminal set in the plurality of terminal sets is the plurality of terminal sets. Two or more terminal sets are determined so that there is a plurality of terminal sets in which the relation that they are not a subset of each other terminal set in the above is established, and (b) for each terminal and for each determined terminal set. Correspondingly, a separate decryption key is determined, and (c) The method is characterized in that a decryption key determined corresponding to the terminal and a decryption key determined corresponding to each of all the terminal sets including the terminal are assigned to each terminal.
【0017】
Further, the decryption terminal according to the present invention is a decryption terminal for acquiring and decrypting encrypted data, and is a decryption key group that stores decryption key groups individually assigned by a predetermined key allocation method. The storage means, the encrypted data acquisition means for acquiring the encrypted data, and the data acquired by the encrypted data acquisition means are decrypted using the decryption key stored in the decryption key group storage means. The decryption means and the predetermined key allocation method (a) belong to a plurality of terminal sets in which the terminal is a set including two or more terminals in the case of assuming three or more terminals including the terminal. As described above, further, there is a relation that there are a plurality of terminal sets each including the terminal as an element, and none of the terminal sets in the plurality of terminal sets is a subset of each other terminal set in the plurality of terminal sets. Determine two or more terminal sets so that there are the plurality of terminal sets in which is satisfied, and (b) separate decryption keys corresponding to this terminal and for each determined terminal set. (C) It is a method of assigning the decryption key specified for this terminal and the decryption key specified for each of all terminal sets including this terminal to this terminal. It is a feature.
【0018】
As a result, for example, when the data of the result encrypted on the recording medium is recorded on each terminal and the recording medium is distributed, the increase in the amount of data recorded on the recording medium is suppressed and then specified. If the decryption key held by the terminal is exposed by an unauthorized person due to the analysis of the terminal, the data cannot be decrypted correctly on the specific terminal and the data can be decrypted correctly on the other terminal. Will be possible.
【0019】
Further, the encryption key identification device according to the present invention is an encryption key identification device that specifies an encryption key to be used for encrypting distribution data to each of three or more terminals, and (a) each of the above. A plurality of terminal sets in which the same one or more terminals are included in each element so that the terminals belong to at least one of the terminal sets in which two or more terminals are included in the elements. Two or more terminal sets so that there is a plurality of terminal sets in which any one terminal set in the terminal set is not a subset of each other terminal set in the plurality of terminal sets. And (b) In addition to the decryption key group associating means for associating different decryption keys for each terminal and each determined terminal set, and the decryption key associated with the terminal by the decryption key setting means for each terminal. Decryption key setting means for associating all decryption keys associated with each of all terminal sets including the terminal with the terminal, invalidation terminal identification means for specifying one or more terminals as invalidation terminals, and the above. When the decryption key other than the decryption key associated with the invalidated terminal is defined as the valid decryption key among all the decryption keys associated with the terminal by the decryption key group mapping means, the selected valid decryption key is used. Assuming that the procedure of selecting the valid decryption key associated with the most unassociated terminals is repeated until there are no terminals that are not associated with the selected valid decryption key. It is characterized by including an encryption key specifying means for specifying an encryption key corresponding to each of all the valid decryption keys selected as a result.
【0020】
Further, the encryption device according to the present invention is an encryption device that encrypts distribution data to three or more terminals, and (a) each terminal includes two or more terminals as elements. A plurality of terminal sets including the same one or more terminals in each element so as to belong to at least one of the terminal sets that are sets, and any one terminal set in the plurality of terminal sets is said to be concerned. Determine two or more terminal sets so that there is a plurality of terminal sets where the relationship that they are not subsets of each other terminal set in a plurality of terminal sets is established, and (b) In addition to the decryption key setting means for associating a separate decryption key for each terminal and each determined terminal set, and the decryption key associated with the terminal by the decryption key setting means for each terminal, the terminal. Decryption key group mapping means for associating all the decryption keys associated with each of all the terminal sets including the above with the terminal, invalidation terminal identification means for specifying one or more terminals as invalidation terminals, and the above. When a decryption key other than the decryption key associated with the invalidated terminal among all the decryption keys associated with the terminal by the decryption key group mapping means is defined as the valid decryption key, the selected valid decryption key is used. Assuming that the procedure of selecting the valid decryption key associated with the most unassociated terminals is repeated until there are no terminals that are not associated with the selected valid decryption key. , As a result, the encryption key specifying means for specifying the encryption key corresponding to each of the selected valid decryption keys and all the encryption keys specified by the encryption key specifying means are sequentially used and distributed. It is characterized by including an encryption means for encrypting data for use and generating an encrypted distribution data group, and an output means for outputting the encrypted distribution data group generated by the encryption means to the outside.
【0021】
Further, the encryption key identification method according to the present invention is an encryption key identification method for specifying an encryption key to be used for encrypting distribution data to each of three or more terminals, and each terminal. Is a plurality of terminal sets including the same one or more terminals in each element so as to belong to at least one of the terminal sets which is a set including two or more terminals in the element. Two or more terminal sets so that there is a plurality of terminal sets in which any one terminal set in the terminal set is not a subset of each other terminal set in the plurality of terminal sets. A terminal set determination step to be determined, a decryption key mapping step for associating different decryption keys for each terminal and each terminal set determined by the terminal set determination step, and the decryption key mapping for each terminal. In addition to the decryption key associated with the terminal by the step, one or more decryption key group mapping steps for associating all the decryption keys associated with each of all the terminal sets including the terminal with the terminal. Decryption other than the decryption key associated with the invalidation terminal among all the decryption keys associated with the terminal by the invalidation terminal identification step for specifying the terminal as the invalidation terminal and the decryption key group mapping step. When the key is defined as the valid decryption key, the selected valid decryption key performs the procedure of selecting the valid decryption key associated with the most terminals to which the selected valid decryption key is not associated. It is characterized by including an encryption key identification step of specifying an encryption key corresponding to each of all the valid decryption keys selected as a result, which is repeated until there is no unassociated terminal.
【0022】
As a result, for example, when the data of the result of encryption on the recording medium is recorded on each terminal and the recording medium is distributed, the number of encryption keys used for encryption can be suppressed to a relatively small number. After suppressing the increase in the amount of data recorded on the recording medium, if the decryption key held by the specific terminal is exposed by an unauthorized person by analysis of the specific terminal, the data will be stored on the specific terminal. It is possible to perform the encryption so that the data cannot be decrypted correctly and other terminals can decrypt the data correctly.
【0023】
BEST MODE FOR CARRYING OUT THE INVENTION
<Embodiment 1> Hereinafter, the data protection system according to the first embodiment of the present invention will be described with reference to the drawings. <Overall Configuration> FIG. 1 is a schematic configuration diagram of a data protection system 100 according to a first embodiment of the present invention.
【0024】
As shown in the figure, the data protection system 100 includes an encryption device 101, a plurality of decryption devices (terminals) 103a to 103n, and a key setting system 104, and encrypts content consisting of digital data indicating video, audio, and the like. This is a system for recording on an optical disk 102 such as a DVD-ROM and distributing it to a plurality of terminals.
【0025】
Here, the key setting system 104 is a system for determining an encryption key for setting in the encryption device 101 and a decryption key for individually setting in the decryption devices 103a to 103n. The encryption device 101 is a device that holds an encryption key specified by the key setting system 104, encrypts the contents, and records the contents on the optical disk 102. As for the optical disc 102, it is assumed that a large number of optical discs 102 having completely the same recorded contents are duplicated.
【0026】
Further, the decryption devices 103a to 103n are a large number of terminals such as 1 billion units, and each decryption device holds a decryption key individually determined by the key setting system 104 and is encrypted from the optical disk 102. This is a device that reads and decrypts the contents (hereinafter referred to as "encrypted contents") and reproduces the contents obtained by the decryption.
【0027】
When the data protection system 100 is used to protect the copyright of the content, the key setting system 104 and the encryption device 101 are operated by the organization that manages the copyright protection, and the decryption device is a general user. It is expected that it will be used for. In addition, the key setting system 104 is basically used once to determine the decryption key for each decryption device, once to identify the encryption key to be used first, and further to be specific. Every time it is found that the decryption key held in the decryption device is exposed due to unauthorized analysis of the decryption device, the specific decryption device cannot decrypt the encrypted content recorded on the optical disk. It is used to identify a new encryption key to be used when newly recording the content on the optical disk in the encryption device 101.
【0028】
Hereinafter, the encryption device 101, the decryption devices 103a to 103n, and the key setting system 104 will be described in more detail. <Configuration of Encryption Device> FIG. 2 is a functional configuration diagram of the encryption device 101 and the decryption device 103a. As shown in the figure, the encryption device 101 includes a content storage unit 201, a random number generation unit 202, an encryption key group storage unit 203, a key encryption unit 204, a content encryption unit 205, and an output unit 206.
【0029】
Here, the content storage unit 201 is a storage device such as a hard disk that stores content composed of digital data indicating video, audio, and the like. The random number generation unit 202 has a function of generating a random number that serves as a key used for encrypting the content (hereinafter, referred to as a content key). The content key is, for example, 64-bit data composed of random numbers.
【0030】
The encryption key group storage unit 203 stores one or more encryption keys specified by the key setting system 104, and the decryption device side specifies a decryption key corresponding to the stored encryption key. It is a storage device such as a memory that stores key identification information to be used. When a new encryption key is specified by the operation of the key setting system 104, the encryption key held in the encryption key group storage unit 203 before the identification is deleted and newly specified. Only the encrypted key is stored in the encryption key group storage unit 203. The new encryption key and the key identification information corresponding to the encryption key may be stored, for example, by being input by an operator or by receiving from the key setting system 104. Good.
【0031】
The key encryption unit 204 encrypts the content key acquired from the random number generation unit 202 using each encryption key stored in the encryption key group storage unit 203, and the encrypted content key (resulting in this). Hereinafter, it is referred to as an "encrypted content key".) It has a function of transmitting each to the output unit 206. The content encryption unit 205 has a function of encrypting the content stored in the content storage unit 201 using the content key acquired from the random number generation unit 202 and transmitting the resulting encrypted content to the output unit 206. ..
【0032】
Further, the output unit 206 includes hardware capable of recording data on the optical disk, acquires key identification information from the encryption key group storage unit 203, and the key identification information and the encryption transmitted from the content encryption unit 205. It has a function of recording the encrypted content and the encrypted content key transmitted from the key encryption unit 204 on the optical disk 102.
【0033】
By recording the encryption device 101, the encrypted content, one or more encrypted content keys, and the key identification information are recorded on the optical disk 102. The number of encrypted content keys recorded on the optical disk 102 matches the number of encryption keys specified by the key setting system 104 and stored in the encryption key group storage unit 203.
【0034】
Such an encryption device 101 includes a CPU, a memory, and the like as hardware, and all or one of the functions of the above-mentioned random number generation unit 202, key encryption unit 204, content encryption unit 205, and output unit 206. The part is realized by executing the control program stored in the memory by the CPU. <Structure of Decoding Device> Decrypting device 103a is a terminal for playing an optical disc, and as shown in FIG. 2, acquisition unit 211, decoding key group storage unit 212, decoding key selection unit 213, key decoding unit 214, and content decoding unit. It has 215 and a reproduction unit 216.
【0035】
Here, the acquisition unit 211 includes hardware capable of reading data from the optical disc, reads the encrypted content from the optical disc 102 and transmits the encrypted content to the content decryption unit 215, reads the encrypted content key from the optical disc 102, and the key decryption unit 214. It has a function of reading the key identification information from the optical disk 102 and transmitting it to the decryption key selection unit 213.
【0036】
The decryption key group storage unit 212 is a storage device such as a non-volatile memory that stores a plurality of decryption keys and the like determined for the decryption device 103a by the key setting system 104. The decryption key is stored, for example, in the manufacturing process of the decryption device. The decryption key selection unit 213 determines and uses which of the decryption key groups stored in the decryption key group storage unit 212 can be used based on the key identification information transmitted from the acquisition unit 211. It has a function to select one decryption key that can be used.
【0037】
The key decryption unit 214 acquires an encrypted content key that can be decrypted by using the decryption key selected by the decryption key selection unit 213 through the acquisition unit 211, and uses the decryption key to acquire the acquired encrypted content key. A content key is generated by decrypting. The content decryption unit 215 has a function of generating content by decrypting the encrypted content transmitted from the acquisition unit 211 using the content key generated by the key decryption unit 214 and transmitting the content to the playback unit 216.
【0038】
Further, the reproduction unit 216 has a function of reproducing the content transmitted from the content decoding unit 215. If the content handled by the data protection system 100 is moving image data according to a compression method defined by, for example, MPEG (Moving Picture Expert Group), the playback unit 216 may be, for example, a so-called MPEG decoder or the like. Therefore, it is necessary to include a function of extending the content and outputting a video signal.
【0039】
Such a decoding device 103a includes a CPU, a memory, and the like as hardware, and has all the functions of the acquisition unit 211, the decryption key selection unit 213, the key decoding unit 214, the content decoding unit 215, and the playback unit 216 described above. Alternatively, a part of the control program stored in the memory is executed by the CPU.
【0040】
The plurality of decoding devices 103b to 103n other than the decoding device 103a also have the same configuration as the decoding device 103a. However, all or part of the contents stored in the decryption key group storage unit 212 differs for each decryption device. <Configuration of key setting system> FIG. 3 is a functional configuration diagram of the key setting system 104.
【0041】
As shown in the figure, the key setting system 104 includes a key information storage unit 301, a key information generation unit 302, an invalidation terminal identification unit 303, a key information update unit 304, a decryption key determination unit 305, and an encryption key identification unit 306. Have. Here, the key information storage unit 301 is a storage device such as a hard disk for storing key information described later.
【0042】
The key information generation unit 302 determines the tree structure so that each of the decoding devices constituting the data protection system 100 corresponds to the node of the lowest layer of the hierarchical quadtree tree structure, and for each node in the tree structure. Assign one or more keys and generate key information indicating the assigned key etc. for each node. The key information is information used to identify the encryption key and the decryption key, and serves as a criterion for determining whether or not each key assigned to each node can be used as the encryption key. Contains invalidation information. This key information and the tree structure of the quadtree will be described in detail later.
【0043】
The invalidation terminal identification unit 303 receives the designation of the decryption device to which the decryption key held is exposed from the operator via the input device such as the keyboard and the pointing device, and the invalidation terminal identification unit 303 should invalidate the designated decryption device. (Hereinafter, referred to as "disabled terminal"). The invalidation terminal indicates a decryption device that needs to perform encryption so that the terminal cannot correctly decrypt the encrypted content in the encryption of the content.
【0044】
The key information update unit 304 has a function of updating the invalidation information in the key information stored in the key information storage unit 301 based on the invalidation terminal specified by the invalidation terminal identification unit 303. The decryption key determination unit 305 has a function of determining a plurality of decryption keys to be set for each decryption device based on the key information stored in the key information storage unit 301. The decryption key determined for each decryption device is stored in the decryption key group storage unit of the decryption device together with the information indicating the node associated with the decryption key by the key information, for example, in the manufacturing process of the decryption device. Stored. Therefore, the key setting system 104 transmits, for example, the determined decryption key and the information indicating the correspondence between the decryption key and the node to, for example, the manufacturing system for manufacturing the decryption device.
【0045】
Further, the encryption key identification unit 306 has a function of specifying one or more encryption keys to be set in the encryption device based on the key information stored in the key information storage unit 301, and the specified encryption. By showing the correspondence between the encryption key and the node, the key identification information that serves as a criterion for determining which decryption key should be used at the time of decryption is output together with the specified encryption key.
【0046】
This output is, for example, transmission to the encryption device 101 or recording on a portable recording medium. When the encryption key identification unit 306 records the encryption key on a portable recording medium, the operator in operation causes the contents of the recording medium to be stored in the encryption key group storage unit 203 of the encryption device 101. Must be copied. <Key information> Hereinafter, the key information generated by the key information generation unit 302 and stored in the key information storage unit 301 will be described.
【0047】
First, the tree structure of a quadtree will be described. FIG. 4 is a diagram showing the tree structure of a quadtree. This tree structure is constructed so that each node (hereinafter, also referred to as "leaf") constituting the lowest layer node group 406 and a decoding device (terminal) have a one-to-one correspondence, and from one node. Is a tree structure with branches to four nodes. Here, a structure having branches from one node to n nodes is called an n-segment tree, and a structure having branches to four nodes is called a quadtree. Also, one node that has a branch to the four nodes is called the parent node for the four nodes, the four nodes are called the child nodes for the parent node, and the top-level node 405 is rooted. It will be referred to as.
【0048】
If the number of decoding devices in the data protection system 100 is not a factorial of 4, the number of nodes in the lowest layer is the smallest of the factorials of 4 that is greater than the number of decoding devices. For the sake of simplicity, the number of decoding devices will match the number of nodes in the lowest layer. The key information generation unit 302 increases the uppermost layer 401 of the tree structure shown in FIG. 4 to level 0, the next lower layer 402 to level 1, and the next lower layer by one level to the lowest level. The layer 403 one layer above is defined as level D-1, the lowest layer 404 is defined as level D, and each node at each level determines the relative number at each level in order from 1. Therefore, the node with relative number 1 at level D corresponds to the decoding device 103a, the node with relative number 2 at level D corresponds to decoding device 103b, and the node with relative number 4 to the D power at level D is the last decoding device. Corresponds to 103n.
【0049】
FIG. 5 is a diagram showing an example of a quadtree tree structure when the number of decoding devices is 64. In the example shown in the figure, the tree structure of the quadtree is constructed so that there are 64 leaves, so the lowest layer is level 3. Next, the invalidation information defined corresponding to each node will be described.
【0050】
The invalidation information for a node combines the flags indicating whether or not the node is an invalid node for the four child nodes when that node is the parent node, in order from the flag for the node with the smallest relative number. It is the information that was done. The flag takes a value of 1 if it is an invalid node and 0 if it is not an invalid node. Therefore, for example, if the four child nodes are not invalid nodes, the invalidation information of the parent node is "0000", and if the four child nodes are invalid nodes, the invalidation information of the parent node is "1111".
【0051】
However, for the leaf, the invalidation information is "1111" if the decoding device corresponding to the leaf is an invalidation terminal, and "0000" if it is not an invalidation terminal. The invalid node is a leaf corresponding to the invalidation terminal, or a node arriving from the leaf corresponding to the invalidation terminal toward the upper layer. Therefore, it can be said that the invalid node is a node whose corresponding invalidation information has a value other than "0000".
【0052】
Here, the node "reaching" from a specific node is assumed that a chain is established between each node having a relationship between the parent node and the child node, and the upper layer direction and the upper layer direction from the specific node and A node connected by one or more chains in any one direction in the lower layer direction. Therefore, in the tree structure, the lower node that is reached by passing over one or more chains from the upper node toward the lower layer is the node that arrives from the upper node, and conversely, the upper node. Is a node that can be reached from the node below it. For example, you can reach the route from any leaf, you can reach any leaf from the route, but you cannot reach another leaf from one leaf.
【0053】
Before the decryption key held by the decryption device is exposed, the invalidation terminal does not exist, so the invalidation information for all the nodes takes a value of "0000". 6 and 7 are diagrams showing an example of route invalidation information. The example of FIG. 6 shows that the invalidation information of the route is "0000" when all the child nodes of the route are not invalid nodes.
【0054】
In the example of Fig. 7, the invalid node is indicated by a cross, and the invalidation information of the route is "1000" when only the child node of the root whose relative number is 1 is the invalid node. Shown. Next, the key assigned to each node will be described. The key information generation unit 302 separately assigns an encryption key and a pair of decryption keys corresponding to the encryption key to each node. A unique set of keys is assigned to each decryption device for the leaf, and a plurality of sets of keys are assigned to the nodes other than the leaf as shown below.
【0055】
FIG. 8 is a diagram showing the keys assigned to the nodes in the level 0 and level 1 hierarchies of the quadtree tree structure. In the figure, 0-1K0000, 0-1K0001, etc. represent the encryption key and the corresponding decryption key collectively for convenience. In addition, it is possible to determine in advance whether the data protection system 100 adopts a method in which the encryption key and the decryption key have different values or a method in which the encryption key and the decryption key have the same value. When adopting a method that takes different values, for example, the decryption key represented by 0-1K0000 and the encryption key represented by 0-1K0000 have different values and are encrypted in the data protection system 100. When a method in which the key and the decryption key take the same value is adopted, for example, the encryption key and the decryption key represented by 0-1K0000 have the same value.
【0056】
Hereinafter, the expression that the decryption key is assigned to each node or the expression that the encryption key is assigned to each node is used, but in reality, the decryption key and the encryption key take different values. When adopting the method, the decryption key and the encryption key corresponding to it are assigned to each node, and when adopting the method in which the decryption key and the encryption key take the same value, it is also the decryption key. A key that is also an encryption key is assigned to each node. As a result, the decryption key or the like assigned in the key information is set. The encryption key and decryption key are, for example, 64-bit data.
【0057】
As shown in FIG. 8, 11 decryption keys are assigned to the nodes other than the leaf. Here, among the possible values of "0000", "1000", etc. of the invalidation information for a certain node, the number of "1" is less than (n-1) when the tree structure of the n-branch tree is used. The value that becomes is called an invalidation pattern. Therefore, the invalidation pattern in the quadtree is "0000", "0001", "0010", "0011", "0100", "0101", "0110" where the number of "1" is less than 3. , "1000", "1001", "1010" and "1100" exist, and each node other than the leaf is assigned 11 decryption keys for all invalidation patterns.
【0058】
Here, the key for the node with the relative number B of level A and the invalidation pattern of X is expressed as "A-BKX". Therefore, "0-1K0000" indicates that the invalidation pattern for the node with the relative number 1 of level 0 is the decryption key or the like corresponding to "0000". FIG. 9 is a diagram showing a configuration of key information stored in the key information storage unit 301.
【0059】
As shown in the figure, the key information 500 is information in which the node ID 501 of the node, the invalidation pattern 502, the key 503, and the invalidation information 504 are associated with each node . The node ID 501 is an ID indicating a level indicating the location of the node in the tree structure and a relative number. For example, the node ID of the node having the relative number B of the level A is expressed as "AB".
【0060】
The invalidation pattern 502 is a value in which the number of "1" is less than 3 among the possible values of the invalidation information as described above. The key 503 is a decryption key and an encryption key assigned to the node indicated by the corresponding node ID. The invalidation information 504 is invalidation information about the node indicated by the corresponding node ID, and the initial value is "0000".
【0061】
In the key information, there is no invalidation pattern corresponding to the leaf, and the key 503 for the leaf is a set of decryption key and encryption key. <Key allocation process> Hereinafter, after the key information is stored in the key information storage unit 301 by the key information generation unit 302 in the key setting system 104, the decryption key determination unit 305 sets each of the decryption devices 103a to 103n. The key allocation process performed to determine the decryption key to be output, that is, to assign a plurality of decryption keys to each decryption device will be described.
【0062】
FIG. 10 is a flowchart showing a key allocation process executed by the decryption key determination unit 305. First, the decryption key determination unit 305 sets the decryption device (terminal) to which the relative number 1 of the leaf in the tree structure of the quadtree is associated as the allocation target terminal (step S11), and corresponds to the allocation target terminal. Focusing on the leaf, that is, the node of the lowest layer, one identification key assigned to that node (node of interest) is specified (step S12). Note that the focus on a node specifically means, for example, storing the address in the storage area of the information about the node in the key information in a variable or the like for internal processing.
【0063】
Subsequently, the decryption key determination unit 305 stores the node (parent node) above the node of interest, which indicates that the node of interest is valid, that is, not an invalid node, in the key information storage unit 301. All the decryption keys corresponding to the invalidation pattern defined in the key information are specified, and the parent node is newly defined as the node of interest (step S13).
【0064】
Following step S13, the decryption key determination unit 305 determines whether the current node of interest is the root (step S14), and if it is not the root, repeats the process of step S13 until the current node of interest becomes the root. .. If the current node of interest is the root in step S14, the decryption key determination unit 305 determines as the decryption key to set all the keys specified in steps S12 and S13 for the allocation target terminal (step S15). , It is determined whether or not the allocation target terminal is the last terminal, that is, whether or not it is the decoding device associated with the leaf having the largest relative number (step S16), and if it is the last terminal, the key. Finish the allocation process.
【0065】
If it is determined in step S16 that the allocation target terminal is not the last terminal, the decryption key determination unit 305 is relative to the terminal next to the current allocation target terminal, that is, the leaf corresponding to the current allocation target terminal. The decoding device associated with the leaf whose number is one higher is newly defined as the allocation target terminal (step S17), and the process of step S12 is performed.
【0066】
By such a key allocation process, a decryption key group to be set for each decryption device is determined, and in response to this, each decryption device is configured to hold the determined decryption key group. FIG. 11 shows the decryption key group 905 assigned to the decryption device (terminal 1) corresponding to the leaf of the relative number 1 of level 3 and the decryption key group 905 determined by the key allocation process when it is assumed that there are only 64 decryption devices. It is a figure which shows.
【0067】
Note that 3-1K in the figure represents the only decryption key assigned to leaf 904 of level 3 relative number 1. Assuming that there are only 64 decryption devices, as shown in FIG. 11, the terminal 1 has the decryption key 3-1K assigned to the leaf 904 of the relative number 1 of level 3 and the decryption key 3-1K of the leaf. Of the decryption keys assigned to the level 2 relative number 1 node 903, which is the parent node one layer above, the decryption key corresponding to the invalidation pattern indicating that the first child node is not an invalid node, that is, " 7 decryption keys 2-1K0000, 2-1K0001, 2-1K0010 corresponding to 7 invalidation patterns "0000", "0001", "0010", "0011", "0100", "0101" and "0110" , 2-1K0011, 2-1K0100, 2-1K0101 and 2-1K0110, and the first of the decryption keys assigned to node 902 with level 1 relative number 1 which is the parent node one layer above it. Seven decryption keys 1-1K0000, 1-1K0001, 1-1K0010, 1-1K0011, 1-1K0100, 1-1K0101 and 1-1K0110, and more, corresponding to the invalidation pattern indicating that the child node is not an invalid node. Seven decryptions corresponding to the invalidation pattern indicating that the first child node is not an invalid node among the decryption keys assigned for the node with relative number 1 of level 0, which is the parent node one layer above, that is, root 901. A total of 22 decryption keys are assigned, including keys 0-1K0000, 0-1K0001, 0-1K0010, 0-1K0011, 0-1K0100, 0-1K0101 and 0-1K0110.
【0068】
Therefore, in this case, the 22 decryption keys assigned to the decryption key group storage unit 212 of the terminal 1 are stored, for example, in the manufacturing process of the terminal 1. The invalidation pattern corresponding to each node other than the leaf is "1" if the child node of that node is an invalid node, "0" if it is a valid node that is not an invalid node, and the relative number within the level of the child node. The information is concatenated in ascending order of, and assigning the decryption key to the invalidation pattern is based on all terminals corresponding to all the leaves that can be reached from all the child nodes indicated as valid nodes in the invalidation pattern. Corresponds to assigning a decryption key to a set of terminals to be used. Therefore, each terminal is assigned a decryption key unique to that terminal and a decryption key assigned to all terminal sets including that terminal.
【0069】
<Specification of encryption key> The encryption key identification unit 306 of the key setting system 104 has an encryption key 0 assigned to the root in the state where there is no invalidation terminal, that is, in the state where no decryption key is exposed. -1K0000, that is, the encryption key corresponding to the decryption key 0-1K0000 is specified as the encryption key to be set in the encryption key group storage unit 203 of the encryption device 101.
【0070】
On the other hand, the encryption device 101 receives the specified encryption key and the key identification information for identifying the decryption key 0-1K0000 assigned to the root in the tree structure from the key setting system 104 or the like. , It is stored in the encryption key group storage unit 203. When recording the content on the optical disk 102, the encryption device 101 key-encrypts the content key generated from the random number generation unit 202 by using the encryption key stored in the encryption key group storage unit 203. It is encrypted in unit 204, the encrypted content key obtained by the encryption is associated with the key identification information, recorded on the optical disk 102 by the output unit 102, and stored in the content storage unit 201 using the content key. The content is encrypted by the content encryption unit 205, and the encrypted content obtained by the encryption is recorded on the optical disk 102 by the output unit 102.
【0071】
Hereinafter, the invalidation information update process executed by the key information update unit 304 in the key setting system 104 will be described. When the invalidation terminal is specified by the invalidation terminal identification unit 303, the key information update unit 304 has a quadrant tree structure corresponding to the invalidation terminal among the key information stored in the key information storage unit 301. After setting the invalidation information about the leaf in "1111" to indicate that the leaf is an invalid node, the invalidation information update process for updating the invalidation information corresponding to each node in the key information is performed. Do.
【0072】
FIG. 12 is a flowchart showing the invalidation information update process executed by the key information update unit 304. First, the key information update unit 304 pays attention to the layer one layer above the lowest layer in the tree structure of the quadtree (step S21). In other words, if the lowest layer is level D, focus on the level (D-1) layer.
【0073】
Subsequently, the key information update unit 304 pays attention to each node of the layer of interest (layer of interest) in ascending order of relative number, and invalid nodes for the four child nodes of the node of interest (node of interest). Update the invalidation information for the node of interest so that it matches the combination pattern of (step S22). For example, if the four child nodes of the node of interest are "invalid node", "not invalid node", "not invalid node", and "not invalid node" in ascending order of relative number, the focus node The invalidation information is "1000".
【0074】
After step S22, the key information update unit 304 determines whether the current layer of interest is the highest layer, that is, the level 0 layer (step S23), and if it is not the highest layer, it is one layer above the layer of interest. Focusing on the layer (step S24), the process of step S22 is performed. In the determination of step S23, the key information update unit 304 repeats steps S22 to S24 until the current layer of interest becomes the highest layer, and if the current layer of interest becomes the highest layer in the determination of step S23, it is invalid. The conversion information update process is completed.
【0075】
As a result, in the tree structure of the quadtree, the invalidation information for all the nodes that can be reached by tracing from the leaf corresponding to the invalidation terminal toward the upper layer takes a value other than "0000". Next, the invalidation terminal is identified by the invalidation terminal identification unit 303 of the key setting system 104, and after the invalidation information in the key information is updated by the key information update unit 304, the encryption key identification unit 306 encrypts. The key identification process performed to specify the encryption key group to be set in the encryption key group storage unit 203 of the device 101 will be described.
【0076】
FIG. 13 is a flowchart showing a key identification process executed by the encryption key identification unit 306. First, the encryption key identification unit 306 pays attention to the node of the highest layer in the tree structure of the quadtree, that is, the root (step S31). Subsequently, the encryption key identification unit 306 refers to the key information stored in the key information storage unit 301 for the node of interest (node of interest), and invalidates the node of interest that matches the invalidation information of the node of interest. It is determined whether the pattern exists (step S32), and if the invalidation pattern exists, the encryption key corresponding to the invalidation pattern for the node of interest should be set in the encryption device 101. Only when it is specified as a key (step S33) and it is determined that the layer one layer below the node of interest is not the lowest layer in the tree structure (step S34), if there is an invalid node among the child nodes of the node of interest. All of the invalid nodes are defined as the nodes to be focused on (step S35).
【0077】
If it is determined in step S32 that there is no invalidation pattern that matches the invalidation information, the encryption key identification unit 306 determines whether or not the layer to which the child node of the node of interest belongs is the lowest layer in the tree structure. Judgment (step S36), if the layer to which the child node of the focus node belongs is the lowest layer, the encryption key assigned to the child node of the focus node other than the leaf corresponding to the invalidated terminal is encrypted. It is specified as the encryption key to be set in the encryption device 101 (step S37).
【0078】
If it is determined in step S36 that the layer to which the child node of the node of interest belongs is not the lowest layer, the encryption key identification unit 306 determines all the child nodes of the node of interest as planned nodes of interest (step S38). After step S35, S37, S38, or after determining in step S34 that the layer one layer below the node of interest is the lowest layer, the encryption key identification unit 306 has a node of interest that has not yet been focused. It is determined whether or not to do so (step S39), and if there is a node of interest that has not been focused yet, one of the nodes of interest that has not been focused is newly focused (step S40), and step S32. Return to the judgment process of.
【0079】
If it is determined in step S39 that there is no node to be focused on that has not yet been focused, the encryption key identification unit 306 ends the key identification process. As a result, all the encryption keys specified in steps S33 or S37 are output from the encryption key identification unit 306 together with the key identification information and stored in the encryption key group storage unit 203 of the encryption device 101. Become.
【0080】
FIG. 14 is a diagram showing an encryption key and the like in a state where there is no invalidation terminal when it is assumed that there are only 64 decryption devices. In this case, the encryption key stored in the encryption key group storage unit 203 of the encryption device 101 and used for encrypting the content key when recording the content on the optical disk 102 is , Encryption key 0-1K0000, that is, one encryption key corresponding to the decryption key represented by 0-1K0000.
【0081】
FIG. 15 is a diagram showing an encryption key and the like in a state where the terminal 1 is an invalidated terminal when it is assumed that there are only 64 decryption devices. If only terminal 1 is an invalidation terminal, as a result of the invalidation information update processing described above, the key information stored in the key information storage unit 301 will be obtained from node 1103, which is the relative number 1 of the level 2 layer. The invalidation information becomes "1000", the invalidation information of the node 1102 having the relative number 1 of the level 1 layer becomes "1000", and the invalidation information of the root 1101 of the level 0 layer becomes "1000".
【0082】
On the premise of this, the specific processing contents of the above-mentioned key identification processing (see FIG. 13) will be described below based on the example of FIG. First, the encryption key identification unit 306 pays attention to the uppermost node, that is, the route 1101 (step S31). Subsequently, the encryption key identification unit 306 refers to the key information stored in the key information storage unit 301 for the node of interest (the node of interest), and is "1000" which is invalidation information of the node 1101. Matches one of the 11 types of invalidation patterns described above (step S32), so the encryption key 0-1K1000 corresponding to the invalidation pattern is specified as the encryption key to be set in the encryption device 101. (Step S33) Since the layer one layer below the focus node is the level 1 layer and not the lowest layer (step S34), we plan to focus on node 1102, which is an invalid node that exists among the child nodes of the focus node. Defined as a node (step S35).
【0083】
After step S35, the encryption key identification unit 306 determines in step S32 because node 1102 exists as a node of interest that has not yet been focused (step S39), and node 1102 is newly set as the node of interest (step S40). Return to processing. Subsequently, the encryption key identification unit 306 refers to the key information stored in the key information storage unit 301 for the node of interest, and the invalidation information "1000" of the node 1102 is the above-mentioned 11 types. Since it matches one of the invalidation patterns (step S32), the encryption key 1-1K1000 corresponding to the invalidation pattern is specified as the encryption key to be set in the encryption device 101 (step S33), and the node of interest Since the layer one layer below is the level 2 layer and not the lowest layer (step S34), node 1103, which is an invalid node existing among the child nodes of the attention node, is defined as the target node (step S35). ..
【0084】
After step S35, the encryption key identification unit 306 determines in step S32 because node 1103 exists as a node of interest that has not yet been focused (step S39), and node 1103 is newly set as the node of interest (step S40). Return to processing. Subsequently, the encryption key identification unit 306 refers to the key information stored in the key information storage unit 301 for the node of interest, and the invalidation information "1000" of the node 1103 is the above-mentioned 11 types. Since it matches one of the invalidation patterns (step S32), the encryption key 2-1K1000 corresponding to the invalidation pattern is specified as the encryption key to be set in the encryption device 101 (step S33), and the node of interest Since the layer one layer below is the level 3 layer and the lowest layer (step S34), step S35 is skipped and there is no target node that has not been focused yet (step S39), so the key is specified. Finish the process.
【0085】
As a result of this key identification process, the encryption key group stored in the encryption key group storage unit 203 of the encryption device 101 is used for encrypting the content key when recording the content on the optical disk 102. The encryption key groups are the encryption keys 0-1K1000, 1-1K1000, and 2-1K1000, respectively. The encryption key identification unit 306 creates key identification information from the node ID, invalidation pattern, etc. in the key information 500 (see FIG. 9) corresponding to each encryption key specified by the above-mentioned key identification process. This key identification information is stored in the encryption key group storage unit 203 of the encryption device 101, and is recorded on the optical disk 102 together with the contents and the like by the encryption device 101.
【0086】
FIG. 16 is a diagram showing an example of key identification information corresponding to the encryption key shown in FIG. The example in the figure is an example in which the key identification information is configured by combining the character string which is the node ID in the key information 500, the character "K", and the character string of the invalidation pattern. When the output unit 206 of the encryption device 101 records the key identification information shown in FIG. 16 on the optical disk, the encrypted content generated by encryption using the encryption key 0-1K1000 on the optical disk. This order can identify the key, the encrypted content key generated by encryption using the encryption key 1-1K1000, and the encrypted content key generated by encryption using the encryption key 2-1K1000. Record in a way like this.
【0087】
<Decryption of encrypted content> Hereinafter, the optical disk 102 on which each encrypted content key generated by encryption using each encryption key shown in FIG. 15, the encrypted content, and the key identification information shown in FIG. 16 are recorded. Therefore, a specific procedure for decoding and reproducing the content by one decoding device 103n will be described. Since the decoding device 103n has the same configuration as the decoding device 103a and differs only in the contents of the decoding key group storage unit 212, each part of the decoding device 103n will be described here using the reference numerals in FIG.
【0088】
The decryption key selection unit 213 of the decryption device 103n reads the key identification information from the optical disk 102 via the acquisition unit 211, and the information indicating the correspondence between each decryption key held in the decryption key group storage unit 212 and the node. For example, the same node as the encryption key specified by the key identification information by collating the node ID and invalidation pattern information corresponding to each decryption key in the key information 500 with the key identification information. A decryption key corresponding to the same invalidation pattern of the above, that is, a decryption key corresponding to the encryption key is selected, and the decryption key is taken out from the decryption key group storage unit 212 and given to the key decryption unit 214. In response to this, the key decryption unit 214 decrypts the encrypted content key encrypted with the encryption key acquired through the acquisition unit 211 using the decryption key. By such a procedure, for example, if the decryption key 0-1K1000 is included in the decryption key group storage unit 212 of the decryption device 103n, the decryption device 103n records the key identification information shown in FIG. The content key encrypted using the encryption key 0-1K1000 is decrypted using the decryption key 0-1K1000 to obtain the content key.
【0089】
After obtaining the content key, the decryption device 103n decrypts the encrypted content acquired through the acquisition unit 211 using the content key in the content decryption unit 215 to obtain the content, and the playback unit 216. Play the content at. Assuming that the terminal 1 in FIG. 15 is the decoding device 103a, the decoding device 103a holds only the 22 decryption keys shown in FIG. 11, and is 0-1K1000, 1-1K1000, and 2-. Since none of the decryption keys of 1K1000 is held, each encrypted content key generated by encryption using each encryption key shown in FIG. 15 and recorded on the optical disk 102 cannot be correctly decrypted. Therefore, the encrypted content recorded on the optical disk 102 cannot be correctly decrypted, and the content cannot be played back.
【0090】
<Discussion> In the data protection system 100, the number of decryption devices is about 1 billion (4).<sup>15</sup>In the case of a stand), it is necessary to construct a quadtree tree structure consisting of layers from level 0 to level 15. In this case, if one decryption device is used as an invalidation terminal, it exists on the route from the leaf to the root corresponding to the one invalidation terminal in the key identification process by the encryption key identification unit 306. The encryption key corresponding to one invalidation pattern for each of the 15 nodes except the leaf will be identified, and as a result, the encryption device 101 will use 15 to encrypt the content key. Individual encryption keys will be used. At this time, the encrypted content, the 15 encrypted content keys, and the key identification information are recorded on the optical disk 102.
【0091】
Also, for example, about 16,000 of these about 1 billion decoding devices (4)<sup>7</sup>Assuming that the decryption device of (unit) is an invalid terminal, about 131,072 (4) are used to encrypt the content key in the encryption device 101.<sup>7</sup>× (15-7) encryption keys) will be used. At this time, the encrypted content, about 131,072 encrypted content keys, and key identification information are recorded on the optical disk 102.
【0092】
If one encrypted content key is 64 bits, that is, 8 bytes (Byte), about 131,072 encrypted content keys are about 1 megabyte (MB) in total. Therefore, it can be said that the total amount of data of the encrypted content key is sufficiently small with respect to the capacity of a general optical disc. Hereinafter, the total amount of data of the encrypted content key when encryption is performed by a method other than the present embodiment will be examined. (1) Under the assumption that the encrypted content key is 8 bytes, the number of decryption devices is about 1 billion, and about 16,000 decryption devices are invalidated terminals, all decryption devices are different. One decryption key is held, and the content key is encrypted using each encryption key corresponding to the decryption key held by all decryption devices other than the invalidation terminal, recorded on the optical disk, and distributed. If the method is adopted, the total number of encrypted content keys to be recorded on the optical disk will be about 999,984,000, and the total amount of data of the encrypted content will be as large as about 7600 megabytes, which is practical. Not the target. (2) Under the same assumption, tentatively, only one decryption key is assigned to each node in the tree structure of the quadrant in which the leaf corresponds to each decryption device, and each decryption device is assigned to the decryption device. Keep the decryption key assigned to each of the corresponding leaf and all the nodes that can be reached by tracing from that leaf to the upper layer, and trace from one leaf corresponding to the invalidated terminal to the upper layer. A method of encrypting the content key using the encryption key assigned to each node that is not an invalid node among all the child nodes of all the nodes that can be reached (that is, the invalid node), recording it on the optical disk, and distributing it. If adopted, the lowest level of the tree structure would be 15, and the total number of encrypted content keys to be recorded on the optical disk would be approximately 393,216 (4).<sup>7</sup>× (15-7) × 3), and the total amount of data of the encrypted content is about 3 megabytes, which is considerably larger than that of the data protection system 100 according to the present embodiment. (3) Under the same assumption, tentatively, only one decryption key is assigned to each node in the tree structure of the bisector in which the leaf corresponds to each decryption device, and each decryption device is assigned to the decryption device. Keep the decryption key assigned to each of the corresponding leaf and all the nodes that can be reached by tracing from that leaf to the upper layer, and trace from one leaf corresponding to the invalidated terminal to the upper layer. A method of encrypting the content key using the encryption key assigned to each node that is not an invalid node among all the child nodes of all the nodes that can be reached (that is, the invalid node), recording it on the optical disk, and distributing it. If adopted, the level of the lowest layer of the tree structure will be 30, and the total number of encrypted content keys to be recorded on the optical disk will be about 262,144 (2).<sup>14</sup>× (30-14)), and the total amount of data of the encrypted content is about 2 megabytes, which is considerably larger than that of the data protection system 100 according to the present embodiment. <Embodiment 2> Hereinafter, the data protection system (hereinafter, referred to as second data protection system) according to the second embodiment of the present invention will be described with reference to the drawings.
【0093】
The second data protection system differs from the data protection system 100 in that a plurality of tree structures used for determining the decryption key and the encryption key are used. The second data protection system includes basically the same components (see FIGS. 1 to 3) as the data protection system 100 shown in the first embodiment. Therefore, here, the components of the second data protection system will also be described using the reference numerals shown in FIGS. 1 to 3. Here, the second data protection system will be mainly described in terms of differences from the data protection system 100, and the same points will be omitted.
【0094】
The specific operation contents of the key information generation unit 302, the key information update unit 304, the decryption key determination unit 305, and the encryption key identification unit 306 in the second data protection system are different from the corresponding parts in the data protection system 100, but each part is different. The basic processing contents (procedures shown in FIGS. 10, 12, and 13) are almost the same, and the key information storage unit 301 in the second data protection system is used for each node other than the lowest layer. , 11 sets of decryption keys and encryption keys are associated with the 11 types of invalidation patterns shown in FIG. 9 in the first embodiment, and one set of decryption keys and encryption keys is attached to each node in the lowest layer. It is associated and stored.
【0095】
In the key setting system 104 in the second data protection system, the key information generation unit 302 constructs four quadtree tree structures as shown in FIG. 17, and each of all the leaves in the four tree structures is displayed. Corresponds to each of the decoding devices 103a to 103n. Therefore, there are four routes 1301-1304, and each decoding device corresponds to one of the tree-structured leaves.
【0096】
FIG. 17 is a diagram showing an example of a tree structure of four quadtrees constructed when the number of decoding devices is 64 in the second data protection system according to the second embodiment. In this case, the tree structure of four quadtrees is constructed so that there are 64 leaves, so the lowest layer is level 2. For example, the decryption key group assigned to the terminal 1 shown in FIG. 17 by the key assignment process of the decryption key determination unit 305 in the second data protection system (see FIG. 10) and finally held in the terminal 1 Is the first of the decryption keys 2-1K assigned to the level 2 relative number 1 leaf and the decryption key assigned to the level 1 relative number 1 node that is the parent node of that leaf. Decryption keys corresponding to the invalidation pattern indicating that the child node is not an invalid node, that is, seven invalidities "0000", "0001", "0010", "0011", "0100", "0101" and "0110" Seven decryption keys 1-1K0000, 1-1K0001, 1-1K0010, 1-1K0011, 1-1K0100, 1-1K0101 and 1-1K0110 corresponding to the conversion pattern, and level 0, which is the parent node one layer above it. Of the decryption keys assigned for the node with relative number 1 or route 1301, the seven decryption keys 0-1K0000, 0-1K0001, 0 corresponding to the invalidation pattern indicating that the first child node is not an invalid node. A total of 15 decryption keys including -1K0010, 0-1K0011, 0-1K0100, 0-1K0101 and 0-1K0110.
【0097】
Further, for example, the decryption key determination unit 305 in the second data protection system assigns the decryption key assigned to the terminal 17 shown in FIG. 17 and held in the terminal 17 to the leaf of the relative number 17 of level 2. Invalidation pattern indicating that the first child node of the decryption key 2-17K assigned and the decryption key assigned to the parent node of the leaf, level 1 relative number 5, is not an invalid node. Decryption keys corresponding to, i.e., 7 decryption keys 1-5K0000 corresponding to 7 invalidation patterns of "0000", "0001", "0010", "0011", "0100", "0101" and "0110" , 1-5K0001, 1-5K0010, 1-5K0011, 1-5K0100, 1-5K0101 and 1-5K0110, and the parent node one layer above it, level 0 relative number 1, or route 1302. 7 decryption keys 0-2K0000, 0-2K0001, 0-2K0010, 0-2K0011, 0-2K0100, 0 corresponding to the invalidation pattern indicating that the first child node is not an invalid node. A total of 15 decryption keys, including -2K0101 and 0-2K0110.
【0098】
Further, as shown in FIG. 17, the content key is specified by the encryption key identification unit 306 in the second data protection system (see FIG. 13) in the absence of the invalidation terminal, set in the encryption device 101, and the content key is sent to the optical disk 102. The encryption keys used for encryption and recording are the four encryption keys 0-1K0000, 0-2K0000, 0-3K0000 and 0-4K0000.
【0099】
FIG. 18 is a diagram showing an encryption key or the like in a state where the terminal 1 is an invalidated terminal in the second data protection system. If only terminal 1 is an invalidation terminal, as a result of the invalidation information update process (see FIG. 12), the key information stored in the key information storage unit 301 is the node with the relative number 1 of the level 1 layer. The invalidation information of 1405 becomes "1000", the invalidation information of root 1401 of the level 0 layer becomes "1000", and it is encrypted by the key identification process (see FIG. 13) executed by the encryption key identification unit 306. The encryption keys specified as those to be set in the device 101 are the five encryption keys 0-1K1000, 1-1K1000, 0-2K0000, 0-3K0000 and 0-4K0000.
【0100】
The operations of the encryption device 101 and the decryption devices 103a to 103n in the second data protection system are the same as the operations of the corresponding devices in the data protection system 100 shown in the first embodiment. <Embodiment 3> Hereinafter, the data protection system (hereinafter, referred to as third data protection system) according to the third embodiment of the present invention will be described with reference to the drawings.
【0101】
The third data protection system is characterized in that it uses an invalidation pattern having contents different from the invalidation patterns shown in the first and second embodiments, but the other points are basically the same as those of the data protection system 100. .. The third data protection system includes basically the same components (see FIGS. 1 to 3) as the data protection system 100 shown in the first embodiment. Therefore, here, the components of the third data protection system will also be described using the reference numerals shown in FIGS. 1 to 3. Here, the third data protection system will be mainly described in terms of differences from the data protection system 100, and the same points will be omitted.
【0102】
The key information storage unit 301 in the third data protection system is associated with five sets of decryption keys and encryption keys together with an invalidation pattern for each node other than the lowest layer, and one for each node in the lowest layer. A set of decryption key and encryption key are stored in association with each other. However, in the first and second embodiments, the number of "1" among the values such as "0000" and "1000" that can be invalidated information about a certain node is the tree structure of the n-branch tree. The value of less than (n-1) is referred to as the invalidation pattern, but the invalidation pattern in the third embodiment is "1" among the possible values of the invalidation information for a certain node. It means each value that the number is less than 2.
【0103】
Therefore, there are five types of invalidation patterns, "0000", "0001", "0010", "0100", and "1000", and the key information generator 302 completely invalidates each node other than the leaf. Five sets of encryption keys and decryption keys for the pattern are associated with each other, and key information in which one set of encryption keys and decryption keys is associated with the leaf is generated and stored in the key information storage unit 301. ..
【0104】
FIG. 19 is a diagram showing a decryption key assigned to each node in the quadtree tree structure used in the third embodiment. As shown in the figure, for example, the root is assigned five decryption keys of 0-1K0000, 0-1K0001, 0-1K0010, 0-1K0100 and 0-1K1000, and the node with relative number 1 of level 1 is assigned. Is assigned five decryption keys: 1-1K0000, 1-1K0001, 1-1K0010, 1-1K0100 and 1-1K1000.
【0105】
Hereinafter, the operation of the third data protection system will be described by taking the case where there are only 64 decoding devices as an example. FIG. 20 is a diagram showing a decoding key group 1705 assigned to the decoding device (terminal 1) corresponding to the leaf of the relative number 1 of level 3 when it is assumed that there are only 64 decoding devices.
【0106】
The decryption key group 1705 that is assigned to the terminal 1 shown in FIG. 20 and finally held in the terminal 1 by the key assignment process (see FIG. 10) of the decryption key determination unit 305 in the third data protection system is , The first of the decryption keys 3-1K assigned to the level 3 relative number 1 leaf 1704 and the decryption key assigned to the level 2 relative number 1 node 1703, which is the parent node of that leaf. Decryption key corresponding to the invalidation pattern indicating that the child node of is not an invalid node, that is, four decryption keys corresponding to the four invalidation patterns "0000", "0001", "0010" and "0100" 2- The first child node of the decryption keys assigned to 1K0000, 2-1K0001, 2-1K0010 and 2-1K0100 and node 1702 with relative number 1 of level 1 which is the parent node one layer above is invalid. Four decryption keys 1-1K0000, 1-1K0001, 1-1K0010 and 1-1K0100 corresponding to the invalidation pattern indicating that they are not nodes, and a node with a relative number 1 of level 0, which is the parent node one layer above it. That is, of the decryption keys assigned for route 1701, the four decryption keys 0-1K0000, 0-1K0001, 0-1K0010 and 0-1K0100 correspond to the invalidation pattern indicating that the first child node is not an invalid node. There are a total of 13 decryption keys with. Therefore, according to the third data protection system, the number of decryption keys held by each terminal in the data protection system 100 shown in the first embodiment can be reduced.
【0107】
The decryption key group assigned to each terminal by the decryption key determination unit 305 is stored in the decryption key group storage unit 212 of each terminal in the manufacturing process of each terminal or the like. Hereinafter, the encryption key required for recording the contents and the like on the optical disk 102 at the operation stage of the third data protection system will be described. Assuming that there are only 64 decryption devices, in the state where there is no invalidation terminal, the encryption key group of the encryption device 101 is identified by the key identification process of the encryption key identification unit 306 in the third data protection system. The encryption key stored in the storage unit 203 and used for encrypting the content key when recording the content on the optical disk 102 is an encryption key 0-1K0000, that is, one encryption corresponding to the decryption key 0-1K0000. It becomes the key to encryption.
【0108】
FIG. 21 is a diagram showing an encryption key and the like in a state where terminals 1, terminal 2 and terminal 17 are invalid terminals when it is assumed that there are only 64 decryption devices. The key information in the key information storage unit 301 is updated by the invalidation information update process of the key information update unit 304 in the third data protection system (see FIG. 12). The invalidation information update process is exactly the same as the content performed by the key information update unit 304 of the data protection system 100 shown in the first embodiment. As a result, regarding the key information stored in the key information storage unit 301, the invalidation information for the leaves of the relative numbers 1, 2, and 17 of the level 3 layer becomes "1111", and the level 2 layer. The invalidation information of node 1806 with relative number 1 is "1100", the invalidation information of node 1807 with relative number 5 of level 2 layer is "1000", and the invalidation information of relative number 1 of level 1 layer is. The invalidation information of node 1802 becomes "1000", the invalidation information of node 1803 with the relative number 2 of the level 1 layer becomes "1000", and the invalidation information of root 1801 of the level 0 layer becomes "1100". , The invalidation information of other nodes is "0000". The node whose corresponding invalidation information is "0000" is a valid node, and the other nodes are invalid nodes.
【0109】
Following the invalidation information update process, the encryption key is specified by the key identification process (see FIG. 13) of the encryption key identification unit 306. Hereinafter, the specific processing content of the key identification process based on the example shown in FIG. 21 will be described with reference to FIG. In this example, the lowest layer is level 3.
【0110】
First, the encryption key identification unit 306 pays attention to the uppermost node, that is, the route 1801 (step S31). Subsequently, the encryption key identification unit 306 refers to the key information stored in the key information storage unit 301 for the node 1801 of interest, and the invalidation information "1100" of the node 1801 is described above. It is determined whether it matches any of the five types of invalidation patterns (step S32), and since it does not match any of them, it is determined whether the layer one layer below the node 1801 of interest is the lowest layer. Judgment (step S36), since the layer one layer below the node 1801 of interest is the level 1 layer and not the lowest layer, all the child nodes of node 1801 are defined as the nodes to be focused on (step S38). ).
【0111】
By this step S38, the nodes 1802 to 1805 become the nodes to be focused on. Subsequently, the encryption key identification unit 306 determines whether or not there is an unfocused target node (step S39), and since there is an unfocused attention schedule, pays attention to one of them, node 1802 (step S40). , Returning to the determination process of step S32, referring to the key information, it is determined whether the invalidation information "1000" of the node 1802 of interest matches any of the above-mentioned five types of invalidation patterns. (Step S32), and since it matches, specify the encryption key 1-1K1000 corresponding to the invalidation pattern "1000" for node 1802 as the encryption key to be set in the encryption device 101 (step S33), and pay attention to it. Since the layer one layer below the node 1802 is the level 2 layer and not the lowest layer (step S34), the invalid node 1806 among the child nodes of the node 1802 is defined as the node to be focused on (step S35). ).
【0112】
After step S35, the encryption key identification unit 306 determines whether there is an unfocused target node (step S39), and since there is an unfocused attention schedule, pays attention to one of them, node 1806 (step S39). S40), the process returns to the determination process in step S32. Next, the encryption key identification unit 306 refers to the key information and determines whether the invalidation information "1100" of the node 1806 matches any of the above-mentioned five types of invalidation patterns (step S32). ), Since neither of them matches, it is determined whether the layer one layer below the node 1806 of interest is the lowest layer (step S36), and the layer one layer below the node 1806 is level 3. Since it is the lowest layer and the lowest layer, the encryption key 3-3K and the encryption key 3-4K corresponding to the effective nodes leaf 1808 and 1809 of the child nodes of the node 1806 are used in the encryption device 101. Identify it as the encryption key to be set in (step S37), determine if there is an unfocused planned node (step S39), and since there is an unfocused planned target, pay attention to one of them, node 1803. (Step S40), the process returns to the determination process of step S32.
【0113】
Next, the encryption key identification unit 306 refers to the key information and determines whether the invalidation information "1000" of the node 1803 matches any of the above-mentioned five types of invalidation patterns (step S32). ), Since it matches, the encryption key 1-2K1000 corresponding to the invalidation pattern "1000" for node 1803 is specified as the encryption key to be set in the encryption device 101 (step S33), and the node 1803 of interest is focused on. Since the layer one layer below is the level 2 layer and not the lowest layer (step S34), node 1807, which is an invalid node among the child nodes of node 1803, is defined as the planned node (step S35).
【0114】
Subsequently, the encryption key identification unit 306 determines whether or not there is an unfocused target node (step S39), and since there is an unfocused attention schedule, pays attention to one of them, node 1807 (step S40). , Returning to the determination process of step S32, referring to the key information, it is determined whether the invalidation information "1000" of the node 1807 of interest matches any of the above-mentioned five types of invalidation patterns. (Step S32), and since it matches, specify the encryption key 2-5K1000 corresponding to the invalidation pattern "1000" for node 1807 as the encryption key to be set in the encryption device 101 (step S33), and pay attention to it. Since the layer one layer below the node 1807 is the level 3 layer and the lowest layer (step S34), the process of step S35 is skipped and it is determined whether there is an unfocused node to be focused on (step). S39) Since there is an unfocused schedule of interest, we focus on one of them, node 1804 (step S40), and return to the determination process of step S32.
【0115】
Next, the encryption key identification unit 306 refers to the key information and determines whether the invalidation information "0000" of the node 1804 of interest matches any of the above-mentioned five types of invalidation patterns. Judgment (step S32), and since it matches, specify the encryption key 1-3K0000 corresponding to the invalidation pattern "0000" for node 1804 as the encryption key to be set in the encryption device 101 (step S33), and pay attention to it. Since the layer one layer below the node 1804 is the level 2 layer and not the lowest layer (step S34), the invalid node among the child nodes of the node 1804 is defined as the node to be focused on (step S35). ). However, since all the child nodes of node 1804 are valid nodes, a new node to be focused on cannot be determined.
【0116】
Subsequently, the encryption key identification unit 306 determines whether or not there is a node of interest that has not been focused (step S39), focuses on node 1805 that is a node of interest that has not been focused (step S40), and determines the determination process of step S32. Returning to, and referring to the key information, it is determined whether the invalidation information "0000" of the node 1805 of interest matches any of the above-mentioned five types of invalidation patterns (step S32), and matches. Therefore, the encryption key 1-4K0000 corresponding to the invalidation pattern "0000" for the node 1805 is specified as the encryption key to be set in the encryption device 101 (step S33), and the first layer of the node 1805 of interest is specified. Since the lower layer is the level 2 layer and not the lowest layer (step S34), the invalid node among the child nodes of node 1805 is defined as the node to be focused on (step S35). However, since all the child nodes of node 1805 are valid nodes, no new node to be focused on can be determined.
【0117】
Subsequently, the encryption key identification unit 306 determines whether or not there is a node of interest that has not been focused (step S39), and since there is no node of interest that has not been focused anymore, the key identification process is completed. As a result of such key identification processing, the encryption keys identified as those to be set in the encryption device 101 are the encryption keys 1-1K1000, 1-2K1000, 1-3K0000, 1-4K0000, 2-5K1000, There are 7 keys, 3-3K and 3-4K.
【0118】
These seven encryption keys are later stored in the encryption key group storage unit 203 of the encryption device 101, and are used by the key encryption unit 204 for encrypting the content key. In addition, each encrypted content key generated by encryption using each encryption key can be used by the output unit 206 to specify the decryption key corresponding to each encryption key, and the key identification information and encryption. It will be recorded on the optical disk 102 together with the encrypted content.
【0119】
As a result of assigning the decryption key to each terminal by the decryption key determination unit 305 described above, none of the decryption keys corresponding to these seven encryption keys are held in the terminal 1, the terminal 2, or the terminal 7. In addition, one or more of the decryption keys corresponding to these seven encryption keys are held in the other terminals. Therefore, after the content is recorded on the optical disk 102 by the encryption process using these seven encryption keys, it is recorded on the optical disk 102 using the decryption keys exposed from the terminals 1, the terminal 2, and the terminal 7. The decryption process of the content cannot be normally performed, and the decryption process of the content recorded on the optical disk 102 can be normally performed on another terminal. <Embodiment 4> Hereinafter, the data protection system (hereinafter, referred to as fourth data protection system) according to the fourth embodiment of the present invention will be described with reference to the drawings.
【0120】
In the data protection system 100 shown in the first embodiment, the optical disc 102 for the encryption device 101 to record the encrypted content and distribute it to the decryption devices 103a to 103n is a DVD-ROM or the like. The 4th data protection system is implemented on the premise of only the recordable media when the optical disk 102 is divided into the so-called pre-recorded media such as DVD-ROM and the so-called recordable media such as DVD-RAM. It is a form.
【0121】
That is, the fourth data protection system records certain information on the optical disc 102, which is a recordable medium, on the system side, and the user encrypts and records arbitrary contents on the optical disc 102 by the terminal. Therefore, the optical disc 102 can be distributed, and the content recorded on the optical disc 102 can be decoded and used by the user on the same or different terminals. Here, the fourth data protection system will be mainly described in terms of differences from the data protection system 100, and the same points will be omitted.
【0122】
FIG. 22 is a schematic configuration diagram of a fourth data protection system according to the fourth embodiment of the present invention. As shown in the figure, the fourth data protection system includes a key identification information recording device 1501, a plurality of user data encryption devices (terminals) 1502a to 1502n, a plurality of decryption devices (terminals) 103a to 103n, and a key setting system 104. To be equipped. For example, it is assumed that the key setting system 104 and the key identification information recording device 1501 are operated by an organization that manages copyright protection, and each terminal is used by general users.
【0123】
The decryption devices 103a to 103n are the same as those shown in the first embodiment, and all or part of the user data encryption devices 1502a to 1502n are the same as all or part of the decryption devices 103a to 103n. It may be implemented in the terminal. Further, the key setting system 104 in the fourth data protection system is basically the same as that shown in the first embodiment, but there are some additional functions. That is, the key setting system 104 in the fourth data protection system presupposes the construction of a quadrant tree structure in which each terminal corresponds to a leaf in advance, and performs the decryption key group to each terminal by the key allocation process shown in FIG. At this time, if the terminal to be assigned is a decryption device, a decryption key group is assigned, and if the terminal to be assigned is a user data encryption device, an encryption key group corresponding to the decryption key group is assigned. And. The key setting system 104 generates and outputs information indicating the correspondence between the key assigned to each terminal and the node in the tree structure.
【0124】
In the fourth embodiment, for convenience, it is assumed that the user data encryption devices 1502a to 1502n are mounted on the same terminal as the decryption devices 103a to 103n, respectively, and the corresponding encryption key and decryption key are It will be described as having the same value. Therefore, each terminal is provided with a key group which is a decryption key group and an encryption key group assigned by the key setting system 104 in advance, and information indicating the correspondence between each key and a node in the tree structure. Get from 104 and hold.
【0125】
In addition, the key setting system 104 in the fourth data protection system further has one or more encryption keys identified as a result of invalidation information update processing (see FIG. 12) and key identification processing (see FIG. 13) in the operation stage. It has a function to output the key identification information (see FIG. 16) indicating the key to the key identification information recording device 1501. For example, in the state where there is no invalidation terminal, the key identification information is only "0-1K0000".
【0126】
The key identification information recording device 1501 is a device including hardware capable of recording data on an optical disc and having a function of recording the key identification information input from the key setting system 104 on the optical disc 102. Further, each of the user data encryption devices 1502a to 1502n has a function corresponding to each function of the encryption device 101 (see FIG. 2) shown in the first embodiment. However, the user can freely store digital contents in the content storage unit 201, and the contents of the encryption key group storage unit 203 are obtained from the above-mentioned key setting system 104 and held by the terminal. The key group and information indicating the correspondence between each encryption key and the node in the tree structure, and the encryption key used by the key encryption unit 204 to encrypt the content key acquired from the random number generation unit 202 will be described later. It was selected as a result of the encryption key selection process, and the output unit 206 does not record the key identification information on the optical disk 102, but records the encrypted content and the encrypted content key on the optical disk 102.
【0127】
Further, each of the user data encryption devices 1502a to 1502n further reads the key identification information recorded by the key identification information recording device 1501 from the optical disk 102 and selects an encryption key to be used for encrypting the content key. It has a function to perform processing. In this encryption key selection process, the information indicating the correspondence between each encryption key and the node in the encryption key group storage unit 203 is collated with the key identification information, and if there is a content indicating the same node in both, the information is displayed. This is a process of selecting the encryption key corresponding to the node and sending it to the key encryption unit 204, which is the same as the process of selecting the decryption key in the decryption key selection unit 213 in the decryption device 103a shown in the first embodiment. It is a process.
【0128】
That is, each of the user data encryption devices 1502a to 1502n uses an encryption key according to the key identification information recorded in advance in the optical disk 102 when the content is encrypted and recorded on the optical disk 102 with the content key. It is a device having a function of encrypting a content key and recording it on the optical disk 102. Therefore, according to this fourth data protection system, many terminals other than the terminal whose decryption key or the like is exposed due to unauthorized analysis cannot be correctly decrypted by the exposed decryption key and are exposed. Many terminals with no decryption key will be able to encrypt the content and record it on the optical disk 102 so that it can be correctly decrypted and used. <Supplement> The data protection system according to the present invention has been described above based on the first to fourth embodiments, but it goes without saying that the present invention is not limited to these embodiments. That is, (1) Although the contents shown in the first to fourth embodiments are video, audio, etc., the contents are not limited to these, and even if the data is a program or other data, these and the video are used. And so on. (2) The decoding device shown in the first to fourth embodiments is provided with a playback unit 216 for reproducing the decoded content, but instead, it may have a function of outputting the decoded content to the outside of the device. Good. (3) In the first to third embodiments, the encrypted contents and the like are recorded on the optical disk 102 and distributed to each decryption device. However, the encrypted contents and the like are distributed to each decryption device as a recording medium. In addition to the distribution by, it may be distributed through a wireless or wired transmission line.
【0129】
In the case of adopting the form of distributing the encrypted content or the like, the output unit 206 of the encryption device 101 shall be provided with hardware having a communication function, and the encrypted content, the encrypted content key and the key specific information shall be provided respectively. It is necessary to transmit to the decryption device (terminal), and the acquisition unit 211 such as the decryption device 103a shall be equipped with hardware having a communication function, and receive the encrypted content, the encrypted content key, and the key identification information. It is necessary to acquire it. As a distribution method, for example, the encryption device 101 may record on a recording medium in a server connected to the Internet, and the decryption device 103a or the like may receive the contents of the recording medium via the Internet.
【0130】
Further, the recording medium in the case of adopting the form of recording and distributing the encrypted content on the recording medium is not limited to the optical disc, and may be an IC card, a flexible disk, a magnetic tape, a ROM, or the like. (4) The method of defining the invalidation pattern corresponding to each node in the key information shown in the first embodiment is merely an example, and for example, each node other than the root does not have the invalidation pattern of "0000". , Each node other than the leaf has the invalidation pattern of "0111", "1101", "1011", "1110", and the key allocation process (see Fig. 10) and key identification process (Fig. 13) are matched accordingly. The contents of (see) may be changed slightly.
【0131】
Further, in the first embodiment, the invalidation pattern and the like are defined on the premise of constructing a quadtree tree structure, but the premise tree structure is at least one n-tree tree structure in which n is 3 or more. It may be a tree structure included in a part, that is, a tree structure in which one node in at least one layer is a parent node of three or more child nodes, and it may be a quadtree or a quintuplet. It is also possible to use a tree structure in which a quadtree, a quadtree, or the like is different in each layer.
【0132】
Further, in the first embodiment, the invalidation pattern for each node of the quadtree tree structure is limited to those in which the number of "1" is less than 3, and in the third embodiment, the quadtree tree The invalidation pattern for each node of the structure is limited to those with less than 2 "1" s, but for example, the invalidation pattern for each node of the quadtree tree structure has 2 "1" s. It may be limited to less than, less than 3, or less than 4. (5) Each part related to decryption in the decryption devices 103a to 103n shown in the first to fourth embodiments and each part related to encryption in the user data encryption devices 1502a to 1502n shown in the fourth embodiment are so-called resistant. It is desirable that the tamper technology be configured to protect the methods and data used for decryption or encryption. (6) In the first embodiment, when the key setting system determines the decryption key to be assigned to each terminal, the decryption key and the information indicating the node in the tree structure to which the decryption key corresponds are output, and as a result, the decryption key is output. The decryption devices 103a to 103n have decided to hold the decryption key group and the information indicating the node corresponding to each decryption key, but the decryption device does not necessarily have to hold the information indicating the node corresponding to the decryption key. .. When the information indicating the node corresponding to the decryption key is not retained, the decryption device attempts to decrypt the encrypted content key recorded on the optical disk by sequentially using each decryption key held by the decryption device. The key may be decrypted. In this case, a rule such as the first 8 bits being 0 is set in advance for the content key, and the validity of the decrypted content key can be confirmed by using a general digital signature or the like. As a matter of fact, the decryption device may decrypt the content using the decrypted content key only when the decrypted content key is valid. (7) In the first embodiment, the content key, the decryption key, and the encryption key are set to 64 bits, but the data size of the key is not limited to 64 bits, and may be other bits. May be good. In FIG. 16, it was decided that the key identification information includes a character string that is a combination of a character string that is a node ID, the character "K", and a character string of an invalidation pattern, but the format of the key identification information is It is not limited to this. (8) In the first to fourth embodiments, the content key used for content encryption is the target of encryption using the encryption key represented by 0-1K0000 or the like, but the target of encryption is It is not limited to the content key, and may be any data that requires confidentiality. (9) Executing the invalidation information update process, key allocation process, or key identification process (procedure shown in FIG. 10, FIG. 12 or FIG. 13) in the key setting system 104 shown in the first to fourth embodiments by a computer or a program. A computer program to be executed by a device having a function can be recorded on a recording medium or distributed and distributed via various communication paths or the like. Such recording media include IC cards, optical discs, flexible disks, ROMs, and the like. The distributed and distributed computer programs are used by being installed on a computer or the like, and the computer or the like is executed by executing the computer program to perform invalidation information update processing and key allocation processing as shown in the first to fourth embodiments. Alternatively, perform key identification processing.
【0133】
[Effect of the invention]
As is clear from the above description, the data protection system according to the present invention includes three or more terminals, an encryption device, and an encryption key identification device, and encrypts the data for distribution to each terminal by the encryption device. It is a data protection system that protects data by converting it, and each terminal stores a decryption key group individually assigned by a predetermined key allocation method, and stores an encryption distribution data group output from the encryption device. The acquired and encrypted distribution data is decrypted by using the stored decryption key. In the predetermined key allocation method, (a) each terminal includes two or more terminals as elements. A plurality of terminal sets each including the same one or more terminals as an element so as to belong to at least one of the terminal sets which is a set, and any one terminal set in the plurality of terminal sets is said to be concerned. Determine two or more terminal sets so that there is a plurality of terminal sets where the relationship that they are not subsets of each other terminal set in a plurality of terminal sets is established, and (b) Separate decryption keys are determined for each terminal and each determined terminal set, and (c) the decryption key determined for each terminal and all terminal sets including the terminal are set. It is a method of assigning all the decryption keys defined corresponding to each of the above, and the encryption key identification device is a device for specifying an encryption key and invalidation for specifying one or more terminals as invalidation terminals. Selected valid when the decryption key other than the decryption key assigned to the invalid terminal among all the decryption keys assigned to the terminal by the encryption terminal identification means and the predetermined key allocation method is defined as the valid decryption key. Assuming that the procedure of selecting the valid decryption key assigned to the most terminals to which the decryption key is not assigned is repeated until there are no terminals to which the selected valid decryption key is not assigned. , A device having an encryption key specifying means for specifying an encryption key corresponding to each of all the valid decryption keys selected as a result, and the encryption device is specified by the encryption key identification device. It is characterized by having an encryption means that encrypts distribution data by sequentially using all the encryption keys and generates and outputs an encrypted distribution data group.
【0134】
Here, the distribution data is data that is expected to be recorded and distributed on a recording medium, or distributed through a wired or wireless communication path, and finally reach each terminal. Assuming terminal 1, terminal 2, and terminal 3, the terminal set determined by the above-mentioned predetermined key allocation method includes a set A of terminal 1 and terminal 2, a set B of terminal 1 and terminal 3, and a terminal 2. And there is a set C of the terminal 3, and the decryption keys stored and held by the terminal 1 in response to the allocation result by the predetermined key allocation method correspond to the decryption key unique to the terminal 1, the decryption key A corresponding to the set A, and the set B. The decryption key B stored in the terminal 2 is the decryption key unique to the terminal 2, the decryption key A corresponding to the set A, and the decryption key C corresponding to the set C, and the terminal 3 The decryption keys to be stored and held are the decryption key unique to the terminal 3, the decryption key B corresponding to the set B, and the decryption key C corresponding to the set C. In this example, if the terminal 2 is illegally analyzed and all the decryption keys stored and held by the terminal 2 are exposed, the terminal 2 is specified as an invalidation terminal, that is, a terminal to be invalidated. When the encryption key is specified by the encryption key specifying means, the encryption key corresponding to the decryption key B is specified.
【0135】
Therefore, if the data is encrypted using the encryption key corresponding to the decryption key B and distributed to each terminal, the terminal 2 cannot correctly decrypt the data, and the terminals 1 and 3 correctly deliver the data. It can be decrypted. For the same purpose, data can be encrypted and distributed to each terminal by using an encryption key corresponding to the decryption key unique to terminal 1 and an encryption key corresponding to the decryption key unique to terminal 3. Compared to this method, the method using the encryption key corresponding to the decryption key B described above has the effect that the number of encryption keys used for encryption is small and the amount of encrypted data to be distributed is reduced accordingly. Has.
【0136】
That is, according to the present invention, in a data protection system that encrypts data such as a key required for decrypting encrypted digital contents and distributes the same data to a plurality of terminals, an increase in the amount of encrypted data to be distributed. If the decryption key held by a specific terminal is exposed by a fraudulent person after suppressing the conversion, the data cannot be decrypted correctly on that specific terminal and the data can be decrypted on other terminals. It is possible to enable correct decryption.
【0137】
Further, the predetermined key allocation method is a plurality of terminal sets including the same one or more terminal sets so that there is a terminal set completely including the plurality of terminal sets. The determination of the terminal set so that there exists such a plurality of terminal sets in which the relationship that any one terminal set in the plurality of terminal sets is not a subset of each other terminal set in the plurality of terminal sets is established. It may be a method of doing.
【0138】
For example, in the case where the decryption key AB is associated with the terminal set A and the terminal set AB including the terminal set B, and the decryption key BC is associated with the terminal set BC including the terminal set B and the terminal set C. In this data protection system, at least the decryption key AB is assigned and stored in the terminal belonging to the terminal set A but not in the terminal set B or the terminal set C, but the decryption key BC is not assigned and stored. At least the decryption key BC is assigned to the terminals that are not held and belong to the terminal set B or the terminal set C. Therefore, even after a terminal belonging to the terminal set A but not belonging to the terminal set B or the terminal set C is illegally analyzed, the data is encrypted using at least an encryption key corresponding to the decryption key BC. By distributing to each terminal, the terminal group included in the terminal set BC, that is, the terminal group included in the terminal set B and the terminal group included in the terminal set C correctly decode the data using the decryption key BC. It becomes possible to encrypt data so that it can be correctly decrypted by many terminals using a small number of encryption keys.
【0139】
Further, the predetermined key allocation method further determines the terminal set so that each terminal set includes three or more terminals as an element and there is a terminal set including three or more terminal sets. It may be a method of doing. As a result, when distributing the same encrypted data to each terminal, encryption using a key common to three or more terminals can be performed, so the data to be distributed is more than when different keys are used for each. You will be able to reduce the amount.
【0140】
In addition, the data protection system excludes the lowest layer when assuming a multi-layered N-branch (N is a natural number of 3 or more) tree structure in which each terminal corresponds to a separate lowest layer node. For each node, out of the N nodes in the lower layer of the 1st stage that can be reached from the node (parent node), 2 or more are combined to determine a plurality of combination patterns including all N combinations, and the determined combination pattern is determined. A separate decryption key is determined for each, and each of the determined decryption keys is stored in association with the relevant node (parent node), and further, a separate decryption key is stored in association with each node in the lowest layer. A key storage device and a device that executes the predetermined key allocation method and determines a decryption key group to be assigned to each terminal, and for each terminal, the highest level from the lowest layer node corresponding to the terminal. For each node that is not the lowest layer located on the path to the node of the layer, among the decryption keys stored by the key storage device in association with the node, one step lower layer of the node is on the path. Decryption that determines that the decryption key corresponding to all the combination patterns related to the combination including the located node and the decryption key stored by the key storage device in association with the terminal should be assigned to the terminal. Each terminal set has a one-to-one correspondence with each combination pattern, and all terminals corresponding to the lowest layer nodes reached from all the combined nodes in the corresponding combination pattern are provided with a key determination device. It corresponds to a set of elements, and the encryption key identification means invalidates all the nodes that reach the lowest layer node corresponding to any invalidation terminal when the tree structure is assumed. It is defined as a node, the highest layer node is first set as the processing target node, the encryption key identification process is repeated until there are no unprocessed processing target nodes, and the encryption key identification process is one unprocessed process. Regarding the target node, (a)If the combination pattern related to the combination including all the nodes other than the invalid node exists in the one-stage lower layer of the processing target node, the decryption key stored in the key storage device corresponding to the combination pattern. (B) If the combination pattern related to the combination including all nodes other than the invalid node does not exist in the lower layer of the 1st stage of the processing target node, the encryption key corresponding to the above is not present. If is the lowest layer, the encryption key corresponding to the decryption key stored in the key storage device corresponding to all the nodes other than the invalid node in the one-stage lower layer is specified, and the one-stage lower layer is concerned. If is not the lowest layer, all nodes other than the invalid node in the lower layer of the first stage are newly set as the processing target node, and (c) if there is an invalid node in the lower layer of the first stage of the processing target node, the 1 Unless the stage layer is the lowest layer, it may be a process in which all invalid nodes are newly set as the processing target nodes.
【0141】
In this way, information such as the decryption key is associated with each node in the tree structure, the decryption key to be assigned to each terminal is determined based on the information and the position of each node in the tree structure, and the data for distribution is encrypted. By the method of specifying the encryption key to be used for, the above-mentioned purpose, that is, the increase in the amount of encrypted data to be distributed is suppressed relatively easily, and then the terminal holds it by analysis of a specific terminal or the like. When the decryption key is exposed by an unauthorized person, it is possible to realize a system that achieves the purpose of enabling the specific terminal to correctly decrypt the data and the other terminal to correctly decrypt the data.
【0142】
Further, the key storage device determines the plurality of combination patterns for each node excluding the lowest layer in the case of assuming the tree structure, and N pieces of the one-stage lower layer arriving from the node (parent node). It is made by defining a combination pattern so as to correspond to each combination of two or more of the nodes of the above, and the key storage device defines and defines a separate decryption key for each determined combination pattern. Each decryption key may be stored in association with the node (parent node).
【0143】
As a result, the number of specified encryption keys can be kept small in the method of specifying the encryption key used for encrypting the distribution data to each terminal using the tree structure of the n-branch tree. As a result, it becomes possible to keep the amount of encrypted distribution data distributed to each terminal relatively small. Further, the key storage device determines the plurality of combination patterns for each node excluding the lowest layer in the case of assuming the tree structure, and N pieces of the one-stage lower layer arriving from the node (parent node). It is made by defining a combination pattern so as to correspond to each of all N combinations and (N-1) all combinations among the nodes of the above, and the key storage device is separate for each determined combination pattern. A decryption key may be determined and each of the determined decryption keys may be stored in association with the node (parent node).
【0144】
As a result, the number of decryption keys assigned to each terminal is kept relatively small in the method of specifying the encryption key used for encrypting the distribution data to each terminal using the tree structure of the n-branch tree. As a result, the amount of data in the decryption key group stored and held by each terminal can be kept relatively small. Further, the encryption means uses the encryption distribution data generated by encryption using the encryption key and the key storage device for each of the encryption keys specified by the encryption key identification device. The decryption key corresponding to the encryption key and the encryption key node identification information for specifying the location of the node in the tree structure associated with the encryption key are output in association with each other, and each terminal has a predetermined key. Each decryption key individually assigned by the allocation method is stored in association with the decryption key node identification information for identifying the location of the node associated with the decryption key in the tree structure by the key storage device. The encryption key node that matches the decryption key node identification information stored in the terminal by acquiring the encryption distribution data group and the encryption key node identification information group output from the encryption device. The encrypted distribution data corresponding to the identification information may be decrypted by using the decryption key corresponding to the decryption key node identification information related to the match.
【0145】
As a result, each terminal obtains the encrypted distribution data group in which the distribution data is encrypted using one or more encryption keys, and then refers to the encryption key node identification information group. This makes it possible to easily specify which decryption key held by the own terminal should be used for decryption, and when decryption is performed sequentially using the decryption key held by the own terminal by trial and error. In comparison, the time required for correct decryption is shortened.
【0146】
Further, the encryption key specifying device has an encryption key storage means for storing an encryption key corresponding to each decryption key stored in the key storage device, and encrypts with the corresponding decryption key. The keys may be different from each other. As a result, even if the decryption key is exposed due to unauthorized analysis of a certain terminal, the encryption key for encrypting the data so that it can be correctly decrypted by multiple terminals is illegally known and misused. It will be possible to prevent the occurrence of such a situation.
【0147】
Further, the output by the encryption means is to record the generated data group for encryption distribution on a data recording medium, and each terminal records the data group for encryption distribution by the encryption device. The encrypted distribution data group may be read out from the data recording medium to be acquired, and the encrypted distribution data may be decrypted. As a result, the data is encrypted and recorded on an optical disc such as a DVD-ROM or other recording medium. Therefore, for example, a recording medium having the same content as the recording medium can be mass-produced and distributed to a large number of people for a fee or free of charge. The person who receives the distributed recording medium can set the recording medium in the terminal and use the data recorded in the recording medium through the terminal.
【0148】
Further, the encryption means is generated by a content storage unit that stores content data that is a digital work, a random number data generation unit that generates the distribution data that is a random number, and the random number data generation unit. It has a content encryption unit that encrypts the content data using the distribution data as a key to generate encrypted content data, and the encryption means includes all the encryption key identification devices specified by the encryption key identification device. By encrypting the distribution data generated by the random number data generator by sequentially using the encryption key, an encrypted distribution data group is generated, and the encrypted distribution data group and the content encryption are performed. The encrypted content data generated by the unit is recorded on the data recording medium, and each terminal reads and acquires the encrypted content data and the encrypted distribution data group from the data recording medium, and encrypts and distributes the data. Data may be decrypted, and the encrypted content data may be decrypted using the distribution data that is the decryption result.
【0149】
As a result, the key required for decrypting the digital content such as encrypted video and audio is encrypted, and the encrypted digital content and the data including the encrypted key are recorded on the recording medium. Therefore, for example, the recording. A recording medium having the same content as the medium is distributed to a large number of people, and the person who receives the distributed recording medium can set the recording medium in the terminal and play digital contents through the terminal. ..
【0150】
Further, the data protection system further includes an encryption key identification information recording device that records the encryption key identification information for identifying the encryption key specified by the encryption key identification device on a data recording medium. Each terminal reads the encryption key specific information from the random number data generation unit that generates the distribution data that is a random number, the content storage unit that stores the content data that is a digital work, and the data recording medium. It has an encryption key selection unit that selects an encryption key specified by the encryption key specific information among the encryption key groups corresponding to the decryption key group stored in the terminal, and the encryption means. Generates an encrypted distribution data group by sequentially using all the encryption keys selected by the encryption key selection unit to encrypt the distribution data generated by the random number data generation unit. The data is recorded on the data recording medium, and each terminal further encrypts the content data stored in the content storage unit by using the distribution data generated by the random number data generation unit as a key. The content encryption unit that generates encrypted content data and records the encrypted content data on the data recording medium, and each terminal reads the encrypted content data and the encrypted distribution data group from the data recording medium. The encrypted distribution data may be decrypted, and the encrypted content data may be decrypted using the distribution data which is the decryption result.
【0151】
As a result, in a system in which a terminal user can record and distribute arbitrary digital contents such as video and audio on a recording medium such as DVD-RAM, the terminal holds the data by analysis of a specific terminal or the like. When the decryption key is exposed by an unauthorized person, the digital content can be encrypted so that the specific terminal cannot correctly decrypt the data and the other terminal can correctly decrypt the data.
【0152】
Further, the output by the encryption means is to transmit the generated encrypted distribution data group to each of the terminals, and each terminal transmits the encrypted distribution data group transmitted by the encryption device. May be received and acquired to decrypt the encrypted distribution data. As a result, the distribution data is encrypted and transmitted to each terminal, so that each terminal can easily use the distribution data by receiving the data.
【0153】
Further, the decryption key determination device according to the present invention determines a decryption key for determining a decryption key group for decryption to be individually assigned to each of three or more terminals for acquiring and decrypting encrypted data. A device, (a) such that each terminal belongs to at least one of a terminal set that is a set containing two or more terminals in an element, and further includes the same one or more terminals in each element. There is a plurality of terminal sets in which the relationship that any one terminal set in the plurality of terminal sets is not a subset of each other terminal set in the plurality of terminal sets is established. (B) Decryption key setting means for associating different decryption keys for each terminal and each determined terminal set, and the decryption key setting for each terminal. A decryption key group assigning means for determining a decryption key associated with the terminal by means and a decryption key associated with each of all terminal sets including the terminal as a decryption key group to be assigned to the terminal. It may be prepared.
【0154】
Further, in the decryption key determination method according to the present invention, the decryption key determination for determining the decryption key group for decryption to be individually assigned to each of three or more terminals for acquiring and decrypting the encrypted data. A method, such that each terminal belongs to at least one of a terminal set that is a set containing two or more terminals in an element, and a plurality of terminals including the same one or more terminals in each element. So that there is a plurality of terminal sets in which the relation that any one terminal set in the plurality of terminal sets is not a subset of each other terminal set in the plurality of terminal sets is established. , A terminal set determination step for determining two or more terminal sets, a decryption key associating step for associating different decryption keys for each terminal and for each terminal set determined by the terminal set determination step, and each terminal. On the other hand, the decryption key associated with the terminal and all the decryption keys associated with each of all the terminal sets including the terminal are determined as the decryption key group to be assigned to the terminal by the decryption key mapping step. It is characterized by including a decryption key group allocation step to be performed.
【0155】
Further, the decryption terminal system according to the present invention is a decryption terminal system composed of three or more terminals for acquiring and decrypting encrypted data, and each of the terminals is subjected to a predetermined key allocation method. The decryption key group storage means for storing the individually assigned decryption key group, the encrypted data acquisition means for acquiring the encrypted data, and the data acquired by the encrypted data acquisition means are decrypted. A decoding means for decrypting using a decryption key stored in a key group storage means is provided, and the predetermined key allocation method is (a) a terminal in which each terminal is a set including two or more terminals as elements. A plurality of terminal sets including the same one or more terminals in each element so as to belong to at least one of the sets, and any one terminal set in the plurality of terminal sets is the plurality of terminal sets. Two or more terminal sets are determined so that there is a plurality of terminal sets in which the relation that they are not a subset of each other terminal set in the above is established, and (b) for each terminal and for each determined terminal set. Correspondingly, a separate decryption key is determined, and (c) The method is characterized in that a decryption key determined corresponding to the terminal and a decryption key determined corresponding to each of all the terminal sets including the terminal are assigned to each terminal.
【0156】
Further, the decryption terminal according to the present invention is a decryption terminal for acquiring and decrypting encrypted data, and is a decryption key group that stores decryption key groups individually assigned by a predetermined key allocation method. The storage means, the encrypted data acquisition means for acquiring the encrypted data, and the data acquired by the encrypted data acquisition means are decrypted using the decryption key stored in the decryption key group storage means. The decryption means and the predetermined key allocation method (a) belong to a plurality of terminal sets in which the terminal is a set including two or more terminals in the case of assuming three or more terminals including the terminal. As described above, further, there is a relation that there are a plurality of terminal sets each including the terminal as an element, and none of the terminal sets in the plurality of terminal sets is a subset of each other terminal set in the plurality of terminal sets. Determine two or more terminal sets so that there are the plurality of terminal sets in which is satisfied, and (b) separate decryption keys corresponding to this terminal and for each determined terminal set. (C) It is a method of assigning the decryption key specified for this terminal and the decryption key specified for each of all terminal sets including this terminal to this terminal. It is a feature.
【0157】
As a result, for example, when the data of the result encrypted on the recording medium is recorded on each terminal and the recording medium is distributed, the increase in the amount of data recorded on the recording medium is suppressed and then specified. If the decryption key held by the terminal is exposed by an unauthorized person due to the analysis of the terminal, the data cannot be decrypted correctly on the specific terminal and the data can be decrypted correctly on the other terminal. Will be possible.
【0158】
Further, the encrypted data acquisition means may read the encrypted data from the data recording medium and acquire the encrypted data. As a result, the encrypted data can be recorded on a data recording medium and the recording medium can be distributed to the users of each terminal so that the users of each terminal can use the data.
【0159】
In addition, encryption key identification information for identifying the encryption key is recorded in the data recording medium, and the terminal further includes a random number data generating means for generating key data which is a random number and a digital work. Of the content storage means for storing the content data, and the encryption key group corresponding to the decryption key group stored in the decryption key group storage means by reading the encryption key specific information from the data recording medium. Generated by the random number data generating means by sequentially using the encryption key selection means for selecting the encryption key specified by the encryption key specific information and all the encryption keys selected by the encryption key selection means. A key data encryption means for generating an encryption key data group by encrypting the key data and recording the encryption key data group on the data recording medium, and a key generated by the random number data generation means. A content encryption means that generates encrypted content data by encrypting the content data stored in the content storage unit using the data as a key and records the encrypted content data in the data recording medium. The encrypted data acquisition means acquires the encryption key data and the encrypted content data recorded in the data recording medium, and the decryption means obtains the encryption obtained by the encryption data acquisition means. The key data is generated by decrypting the key data using the decryption key stored in the decryption key group storage means, and the terminal further obtains the encryption by the encryption data acquisition means. A content decoding means for decoding the converted content data using the key data generated by the decoding means may be provided.
【0160】
As a result, the user of each terminal can encrypt digital contents such as video and audio and record them on a recording medium. Further, the encrypted data is transmitted from an external transmission device, and the encrypted data acquisition means may acquire the encrypted data by receiving the encrypted data.
【0161】
This makes it possible for each terminal to easily use the transmitted data such as digital contents by receiving the data. Further, the encryption key identification device according to the present invention is an encryption key identification device that specifies an encryption key to be used for encrypting distribution data to each of three or more terminals, and (a) each of the above. A plurality of terminal sets in which the same one or more terminals are included in each element so that the terminals belong to at least one of the terminal sets in which two or more terminals are included in the elements. Two or more terminal sets so that there is a plurality of terminal sets in which any one terminal set in the terminal set is not a subset of each other terminal set in the plurality of terminal sets. And (b) In addition to the decryption key group associating means for associating different decryption keys for each terminal and each determined terminal set, and the decryption key associated with the terminal by the decryption key setting means for each terminal. Decryption key setting means for associating all decryption keys associated with each of all terminal sets including the terminal with the terminal, invalidation terminal identification means for specifying one or more terminals as invalidation terminals, and the above. When the decryption key other than the decryption key associated with the invalidated terminal is defined as the valid decryption key among all the decryption keys associated with the terminal by the decryption key group mapping means, the selected valid decryption key is used. Assuming that the procedure of selecting the valid decryption key associated with the most unassociated terminals is repeated until there are no terminals that are not associated with the selected valid decryption key. It is characterized by including an encryption key specifying means for specifying an encryption key corresponding to each of all the valid decryption keys selected as a result.
【0162】
Further, the encryption device according to the present invention is an encryption device that encrypts distribution data to three or more terminals, and (a) each terminal includes two or more terminals as elements. A plurality of terminal sets including the same one or more terminals in each element so as to belong to at least one of the terminal sets that are sets, and any one terminal set in the plurality of terminal sets is said to be concerned. Determine two or more terminal sets so that there is a plurality of terminal sets where the relationship that they are not subsets of each other terminal set in a plurality of terminal sets is established, and (b) In addition to the decryption key setting means for associating a separate decryption key for each terminal and each determined terminal set, and the decryption key associated with the terminal by the decryption key setting means for each terminal, the terminal. Decryption key group mapping means for associating all the decryption keys associated with each of all the terminal sets including the above with the terminal, invalidation terminal identification means for specifying one or more terminals as invalidation terminals, and the above. When a decryption key other than the decryption key associated with the invalidated terminal among all the decryption keys associated with the terminal by the decryption key group mapping means is defined as the valid decryption key, the selected valid decryption key is used. Assuming that the procedure of selecting the valid decryption key associated with the most unassociated terminals is repeated until there are no terminals that are not associated with the selected valid decryption key. , As a result, the encryption key specifying means for specifying the encryption key corresponding to each of the selected valid decryption keys and all the encryption keys specified by the encryption key specifying means are sequentially used and distributed. It is characterized by including an encryption means for encrypting data for use and generating an encrypted distribution data group, and an output means for outputting the encrypted distribution data group generated by the encryption means to the outside.
【0163】
Further, the encryption key identification method according to the present invention is an encryption key identification method for specifying an encryption key to be used for encrypting distribution data to each of three or more terminals, and each terminal. Is a plurality of terminal sets including the same one or more terminals in each element so as to belong to at least one of the terminal sets which is a set including two or more terminals in the element. Two or more terminal sets so that there is a plurality of terminal sets in which any one terminal set in the terminal set is not a subset of each other terminal set in the plurality of terminal sets. A terminal set determination step to be determined, a decryption key mapping step for associating different decryption keys for each terminal and each terminal set determined by the terminal set determination step, and the decryption key mapping for each terminal. In addition to the decryption key associated with the terminal by the step, one or more decryption key group mapping steps for associating all the decryption keys associated with each of all the terminal sets including the terminal with the terminal. Decryption other than the decryption key associated with the invalidation terminal among all the decryption keys associated with the terminal by the invalidation terminal identification step for specifying the terminal as the invalidation terminal and the decryption key group mapping step. When the key is defined as the valid decryption key, the selected valid decryption key performs the procedure of selecting the valid decryption key associated with the most terminals to which the selected valid decryption key is not associated. It is characterized by including an encryption key identification step of specifying an encryption key corresponding to each of all the valid decryption keys selected as a result, which is repeated until there is no unassociated terminal.
【0164】
As a result, for example, when the data of the result of encryption on the recording medium is recorded on each terminal and the recording medium is distributed, the number of encryption keys used for encryption can be suppressed to a relatively small number. After suppressing the increase in the amount of data recorded on the recording medium, if the decryption key held by the specific terminal is exposed by an unauthorized person by analysis of the specific terminal, the data will be stored on the specific terminal. It is possible to perform the encryption so that the data cannot be decrypted correctly and other terminals can decrypt the data correctly.
[Simple explanation of drawings]
[Figure 1]
It is a schematic block diagram of the data protection system 100 which concerns on Embodiment 1 of this invention.
[Figure 2]
It is a functional block diagram of the encryption device 101 and the decryption device 103a.
[Fig. 3]
It is a functional block diagram of the key setting system 104.
[Fig. 4]
It is a figure which shows the tree structure of a quadtree.
[Fig. 5]
It is a figure which shows the example of the tree structure of a quadtree when the number of decoding apparatus is 64.
[Fig. 6]
It is a figure which shows the example of the invalidation information of a route.
[Fig. 7]
It is a figure which shows the example of the invalidation information of a route.
[Fig. 8]
It is a figure which shows the key assigned corresponding to the node of the level 0 and level 1 hierarchy of a quadtree tree structure.
[Fig. 9]
It is a figure which shows the structure of the key information stored in the key information storage part 301.
[Fig. 10]
It is a flowchart which shows the key allocation process executed by the decryption key determination unit 305.
[Fig. 11]
It is a figure which shows the decoding key group 905 which is assigned to the decoding apparatus (terminal 1) corresponding to the leaf of the relative number 1 of level 3 and the decryption key group 905 which is determined by the key allocation process when it is assumed that there are only 64 decoding apparatus. ..
[Fig. 12]
It is a flowchart which shows the invalidation information update process executed by the key information update part 304.
[Fig. 13]
It is a flowchart which shows the key identification process which is executed by the encryption key identification unit 306.
[Fig. 14]
It is a figure which shows the encryption key etc. in the state which there is no invalidation terminal when it is assumed that there are only 64 decryption devices.
[Fig. 15]
It is a figure which shows the encryption key etc. in the state that the terminal 1 is an invalidation terminal when it is assumed that there are only 64 decryption devices.
[Fig. 16]
It is a figure which shows an example of the key identification information corresponding to the encryption key shown in FIG.
[Fig. 17]
It is a figure which shows the example of the tree structure of four quadtrees constructed when the number of decoding apparatus is 64 in the 2nd data protection system which concerns on Embodiment 2. FIG.
[Fig. 18]
It is a figure which shows the encryption key and the like in the state that the terminal 1 is an invalidation terminal in the 2nd data protection system.
[Fig. 19]
It is a figure which shows the decryption key assigned to each node in the tree structure of a quadtree used in Embodiment 3. FIG.
[Fig. 20]
It is a figure which shows the decoding key group 1705 assigned to the decoding apparatus (terminal 1) corresponding to the leaf of the relative number 1 of level 3 when it is assumed that there are only 64 decoding apparatus.
[Fig. 21]
It is a figure which shows the encryption key and the like in the state that the terminal 1, the terminal 2 and the terminal 17 are invalidation terminals when it is assumed that there are only 64 decryption devices.
[Fig. 22]
It is a schematic block diagram of the 4th data protection system which concerns on Embodiment 4 of this invention.
[Explanation of symbols]
100 data protection system 101 Cryptographic device 102 optical disc 103a ~ 103n Decryptor 104 Key setting system 201 Content storage 202 Random number generator 203 Encryption key group storage 204 Key Cryptography Department 205 Content Encryption Department 206 Output 211 Acquisition section 212 Decryption key group storage 213 Decryption key selection unit 214 Key decryption unit 215 Content Decryptor 216 Playback section 301 Key information storage 302 Key information generator 303 Invalidation terminal identification part 304 Key Information Update Department 305 Decryption key determination unit 306 Encryption key identification part 1501 Key specific information recording device 1502a ~ 1502n User data encryption device
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2008124884A | Cited by | Japan | Search report |
| JP2012182844A | Cited by | Japan | Search report |
| US8144869B2 | Cited by | United States of America | Applicant |
| JP2005333242A | Cited by | Japan | Search report |
| WO2004028073A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO2004028073A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US8290155B2 | Cited by | United States of America | Applicant |
| JP2011523513A | Cited by | Japan | Search report |
| JP2008033968A | Cited by | Japan | Examiner |
| US7386126B2 | Cited by | United States of America | Applicant |
| US8180059B2 | Cited by | United States of America | Applicant |
| JP2003273862A | Cited by | Japan | Search report |
| JP2008535440A | Cited by | Japan | Search report |
| US7925893B2 | Cited by | United States of America | Applicant |
12 priority claims, no other members on record
Priority claims12
| Document | Office | Kind | Date |
|---|---|---|---|
| 200195730(P200195730) | Japan | – | |
| 2001095730 | Japan | A | |
| 2001095730 | Japan | A | |
| 2001285608(P2001285608) | Japan | – | |
| 2001285608 | Japan | A | |
| 2001285608 | Japan | A | |
| 2002089674 | Japan | A | |
| 2001200195730 | – | – | – |
| 20012001285608 | – | – | – |
| JP20010095730 | – | – | – |
| JP20010285608 | – | – | – |
| JP20020089674 | – | – | – |
15 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of completion of termEXPY | EXPY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2003-169048
- Publication, DOCDB
- 2003169048
- Publication, EPODOC
- JP2003169048
- Application
- 89674
- Application, DOCDB
- 2002089674
- Application, EPODOC
- JP20020089674
Titles2
- Japanese
- 【発明の名称】暗号化を施すことによりデータを保護するデータ保護システム
- English
- [Title of the Invention] A data protection system that protects data by applying encryption.
Classification
- IPC, 3
- H04N5 91
- G11B20 10
- H04L9 08