Publishing of contents related to digital copyright management (drm) system
Abstract
[Subject] Offer publishing of the contents in a Digital-Rights-Management (DRM) system. [Solution means] A packager packs digital contents for a user, and only by a licenser's following a license, he publishes the digital license over contents to a user so that a user may do the rendering of the contents. In order that a packager and a licenser can calculate the contents key (KD) to contents, a licenser and a packager share a secret. In order to pack contents for a user, a packager calculates a contents key (KD) based on a share secret and content ID, and enciphers contents according to (KD). In order to publish the license to contents to a user, a licenser calculates (KD) again based on a share secret and content ID, in order to form a license, he enciphers (KD) according to a user's public key, and he transmits a license to a user. [Selection figure] Fig. 3
Term
Term ended
Projected expiry passed 11 June 2023, 3.3 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
30 claims: 6 independent, 24 dependent
- 1In a method combined with digital cryptography, the packager packages the digital content for the user, the licensor issues the user a digital license for the content, and the user renders the content only in accordance with the license. A method in which the licensor provides the packager to package the content for the user so that the licensor can issue the license to the user, receiving a request provided by the packager. A step to generate a secret to be shared with the packager and a random content key (KD-PROV) that allows the packager and the licensor to calculate the content key (KD) for the content. The step to generate, the step to encrypt the secret according to (KD-PROV) to form (KD-PROV (secret)), and the public key of the packager with the private key (PR-LI) of the licensor. The step of signing (PU-PA1) and proving that they are the same ((PU-PA1) S (PR-LI)), where the packager has the corresponding private key (PR-PA1). , The licensor has the corresponding public key (PU-LI) and the (KD-PROV (secret)), (PU-PA1) S (PR-LI), and any associated certificate chain. A method characterized by including a step to send to the packager. デジタル著作権管理方式と組み合わせた方法において、パッケージャはユーザのためにデジタルコンテンツをパッケージし、ライセンサは前記ユーザに前記コンテンツに対するデジタルライセンスを発行し、前記ユーザは前記ライセンスに従ってのみ前記コンテンツをレンダリングし、前記ライセンサが前記ユーザに前記ライセンスを発行することができるように、前記ユーザのために前記コンテンツをパッケージすることを前記パッケージャに前記ライセンサが提供する方法であって、前記パッケージャから提供する要求を受信するステップと、前記パッケージャと前記ライセンサが前記コンテンツに対するコンテンツ鍵(KD)を計算することを可能にする、前記パッケージャと共有されるべきシークレットを生成するステップと、ランダムコンテンツ鍵(KD-PROV)を生成するステップと、(KD-PROV(シークレット))を形成するために(KD-PROV)に従って前記シークレットを暗号化するステップと、前記ライセンサのプライベート鍵(PR-LI)で前記パッケージャの公開鍵を(PU-PA1)を署名して、同じであること((PU-PA1)S(PR-LI))を証明するステップであって、前記パッケージャは対応するプライベート鍵(PR-PA1)を有し、前記ライセンサは対応する公開鍵(PU-LI)を有するステップと、(KD-PROV(シークレット))、(PU-PA1)S(PR-LI)、および任意の関連付けられた証明書チェーンを前記パッケージャに送信するステップとを含むことを特徴とする方法。
- 7The step of receiving the provided request, including the public key (PU-PA2) associated with the packager with the corresponding private key (PR-PA2), and encrypting (KD-PROV) with (PU-PA2). 6. A claim is further comprising a step of generating the provided license to form (PU-PA2 (KD-PROV)) and a step of transmitting the provided license to the packager. The method described in. 対応するプライベート鍵(PR-PA2)を有する前記パッケージャに関連付けられた公開鍵(PU-PA2)を含む前記提供する要求を受信するステップと、(KD-PROV)を(PU-PA2)で暗号化することによって前記提供するライセンスを生成して(PU-PA2(KD-PROV))を形成するステップと、前記提供するライセンスを前記パッケージャに送信するステップとをさらに含むことを特徴とする請求項6に記載の方法。
- 15In a method combined with a digital copyright management scheme, the packager packages the digital content for the user, the licensor issues the digital license to the user for the content, and the user renders the content only in accordance with the license. The packager has content provided by the licensor ((KD-PROV (secret)), including a shared secret encrypted according to a random content key (KD-PROV), and the license provided by the licensor is Including (KD-PROV) encrypted according to the packager's public key (PU-PA2) ((PU-PA2) (KD-PROV)) so that the licensor can issue the license to the user. In addition, the packager is a method of packaging the content for the user, from the step of selecting the provided license and the provided content from the licensor, and from the provided license (PU-PA2 (KD-). PROV))), and the packager's corresponding private key (PR-PA2) applied to (PU-PA2 (KD-PROV)) to obtain (KD-PROV), and the above-mentioned provision. A step to obtain (KD-PROV (secret)) from the content, a step to apply (KD-PROV) to (KD-PROV (secret)) to obtain a shared secret, and a random content ID for the content. The step of calculating the content key (KD) based on the random content ID and the secret, the step of encrypting the content according to (KD) ((KD (content))), and the above. A step of acquiring a provided content ID having an identifier of the licensor from one of the provided license and the provided content, the random content ID, the public key (PU-PA1) of the packager, and the licensor.A method comprising:attaching the identifier to (KD (content)) to form the packaged content, and distributing the packaged content to the user. デジタル著作権管理方式と組み合わせた方法において、パッケージャはユーザのためにデジタルコンテンツをパッケージし、ライセンサは前記ユーザに前記コンテンツに対するデジタルライセンスを発行し、前記ユーザは前記ライセンスに従ってのみ前記コンテンツをレンダリングし、前記パッケージャはランダムコンテンツ鍵(KD-PROV)に従って暗号化された共有シークレットを含む、前記ライセンサからの提供するコンテンツ((KD-PROV(シークレット))を有し、前記ライセンサからの提供するライセンスは、前記パッケージャの公開鍵(PU-PA2)に従って暗号化された(KD-PROV)を含み((PU-PA2)(KD-PROV))、前記ライセンサが前記ユーザに前記ライセンスを発行することができるように、前記パッケージャが前記ユーザのための前記コンテンツをパッケージする方法であって、前記ライセンサからの前記提供するライセンスと提供するコンテンツを選択するステップと、前記提供するライセンスから(PU-PA2(KD-PROV))を獲得するステップと、(KD-PROV)を得るために前記パッケージャの対応するプライベート鍵(PR-PA2)を(PU-PA2(KD-PROV))に適用するステップと、前記提供するコンテンツから(KD-PROV(シークレット))を獲得するステップと、共有シークレットを得るために(KD-PROV)を(KD-PROV(シークレット))に適用するステップと、前記コンテンツに対してランダムコンテンツIDを生成するステップと、前記ランダムコンテンツIDと前記シークレットとに基づいてコンテンツ鍵(KD)を計算するステップと、(KD)に従って前記コンテンツを暗号化する((KD(コンテンツ)))ステップと、前記提供するライセンスと前記提供するコンテンツの1つから、前記ライセンサの識別子を有する提供するコンテンツIDを獲得するステップと、前記ランダムコンテンツIDと、前記パッケージャの公開鍵(PU-PA1)と、前記ライセンサの前記識別子とを(KD(コンテンツ))に添付して前記パッケージされたコンテンツを形成するステップと、前記パッケージされたコンテンツを前記ユーザに分配するステップとを含むことを特徴とする方法。
- 18The provided content includes a signature based on the licensor's private key (PR-LI) to prove identical (S (PR-LI)) and any associated certificate chain. Claim 15 further comprises a step across the certificate chain to obtain (PU-LI) and a step of applying (PU-LI) to verify S (PR-LI). The method described in. 前記提供するコンテンツは、同じであること(S(PR-LI))を証明するように前記ライセンサのプライベート鍵(PR-LI)に基づく署名と、任意の関連付けられた証明書チェーンとを含み、(PU-LI)を獲得するために前記証明書チェーンを横切るステップと、(PU-LI)を適用してS(PR-LI)を検証するステップとをさらに含むことを特徴とする請求項15に記載の方法。
- 23In a method combined with a digital copyright management scheme, the packager packages the digital content for the user, the licensor issues the digital license to the user for the content, and the user renders the content only in accordance with the license. The packaged content includes the content ((KD (content))) encrypted according to the content key (KD), the content ID, and the public key (PU-PA1) of the packager, and the licensor includes the content. A method of issuing the license to a user, the content ID, (PU-PA1), and a public key (PU) associated with the user to be used to bind the license to the user. The step of receiving a request for a license from the user with the corresponding private key (PR-US), including (-US), and the stored and provided information about the packager, including the shared secret (PU-). Acquiring based on PA1), calculating (KD) based on the request and the content ID received with the acquired secret, and (KD) according to (PU-US) received with the request. A step of encrypting ((PU-US (KD))), a step of attaching the content ID to (PU-US (KD)) to form the license, and a step of transmitting the license to the user. A method characterized by including. デジタル著作権管理方式と組み合わせた方法において、パッケージャはユーザのためにデジタルコンテンツをパッケージし、ライセンサは前記ユーザに前記コンテンツに対するデジタルライセンスを発行し、前記ユーザは前記ライセンスに従ってのみ前記コンテンツをレンダリングし、前記パッケージされたコンテンツは、コンテンツ鍵(KD)に従って暗号化されたコンテンツ((KD(コンテンツ)))と、コンテンツIDと、前記パッケージャの公開鍵(PU-PA1)とを含み、前記ライセンサが前記ユーザに対して前記ライセンスを発行する方法であって、前記コンテンツIDと、(PU-PA1)と、前記ユーザに前記ライセンスをバインドするために使用されるべき前記ユーザに関連付けられた公開鍵(PU-US)とを含む、ライセンスを求める要求を、対応するプライベート鍵(PR-US)を有する前記ユーザから受信するステップと、共有シークレットを含めて前記パッケージャに関する記憶された提供する情報を(PU-PA1)に基づいて獲得するステップと、前記要求と前記獲得したシークレットと共に受信した前記コンテンツIDに基づいて(KD)を計算するステップと、前記要求と共に受信した(PU-US)に従って(KD)を暗号化する((PU-US(KD)))ステップと、前記ライセンスを形成するために(PU-US(KD))に前記コンテンツIDを添付するステップと、前記ライセンスを前記ユーザに送信するステップとを含むことを特徴とする方法。
- 27The packaged content further includes a signature based on the packager's private key (PR-PA1) corresponding to the packager's public key (PU-PA1) ((S (PR-PA1))). 23. The step of receiving is further comprising (S (PR-PA1)) and further comprising the step of verifying (S (PR-PA1)) by (PU-PA1). Method. 前記パッケージされたコンテンツは、前記パッケージャの前記公開鍵(PU-PA1)に対応する前記パッケージャのプライベート鍵(PR-PA1)に基づく署名をさらに含み((S(PR-PA1)))、前記要求を受信するステップは、(S(PR-PA1))をさらに含み、(PU-PA1)によって(S(PR-PA1))を検証するステップをさらに含むことを特徴とする請求項23に記載の方法。
Independent claims6
140 paragraphs in 1 section, as filed
【0001】
[Technical field to which the invention belongs]
The present invention relates to a method for enforcing rights in digital content. More specifically, the present invention relates to an enforcement method that allows access to encrypted digital content only according to parameters specified by a license right acquired by the user of the digital content. More specifically, the present invention relates to methods that are particularly useful for publishing content and the like.
【0002】
[Conventional technology]
As we all know, and as you can see in Figure 1 below, digital rights management (DRM) and enforcement systems include digital content 12 such as digital audio, digital video, digital text, digital data, and digital multimedia. Such digital content 12 is highly desirable when distributed to users. During reception, the user renders, or "plays", the digital content with the assistance of a suitable rendering device, such as a media player, such as on a personal computer 14.
【0003】
Typically, content owners who distribute such distributed digital content 12 want to limit how users can handle such distributed digital content 12. .. For example, the content owner may wish to restrict a user from copying such content 12 and redistributing it to a second user, or may limit the distributed digital content 12, for example. You may want to allow it to be played a number of times, a certain total number, only on certain machines, only on certain media players, and only by certain users.
【0004】
[Problems to be Solved by the Invention]
However, once the distribution has occurred, such content owners have very little, if any, restraint on the digital content 12. In this case, the DRM system 10 renders the digital content 12 in any format under such restraint, where such restraint is flexible and can be defined by the content owner of such digital content. That is, it is allowed to play. Typically, the content 12 is distributed to the users in the form of package 13 by any suitable distribution path. The distributed digital content package 13 contains digital content 12 encrypted with a symmetric encryption / decryption key (KD) (ie, (KD (content))), as well as other information that identifies the content, such as It can include how to obtain a license for various contents.
【0005】
The trust-based DRM system 10 specifies the license rules that must be met before such digital content 12 is allowed to be rendered on the user's computer device 14 by the owner of the digital content 12. To enable. Such licensing rules may include the time requirements described above and may be interchangeable with one or more users' computer devices 14 (hereinafter, such terms are interchangeable unless circumstances require otherwise. It can be implemented within the scope of Digital License 16 that must be obtained from the Content Owner or its agents. Such License 16 also includes an decryption key (KD) for decrypting digital content, which is probably encrypted according to a key that can be decrypted by the user's computer device.
【0006】
One content owner of digital content 12 is that the user's computer device 14 complies with the rules and requirements specified in license 16 by such content owner, ie digital content 12 is license 16 rules. And you have to trust that it won't be rendered unless the requirements are met. In this case, the user's computer device 14 has a trusted component or mechanism 18 that is associated with the digital content 12 and does not render the digital content 12 except in accordance with the license rules contained in the license 16 acquired by the user. It is preferable that it is provided.
【0007】
Reliable component 18 typically determines if license 16 is valid, reviews the license rules and requirements for such valid license 16, and is based on the considered license rules and requirements. , Has a license evaluator 20 that determines whether the requesting user has the right to render the requested digital content 12 in a particularly desired manner. It should be understood that the License Evaluator 20 is trusted in the DRM System 10 to achieve the wishes of the owner of Digital Content 12 in accordance with the rules and requirements of License 16, whether or not it is fraudulent. For any purpose, it should not be possible for the user to easily modify such trusted elements.
【0008】
It should be understood that the rules and requirements of License 16 are who the user is, where the user is located, what type of computer device the user is using, which rendering application is the DRM system. It is possible to specify whether the user has the right to render the digital content 12 based on any of a number of factors, including calling, date, time, and so on. Further, the rules and requirements of License 16 may limit License 16 to a predetermined number of replays, i.e., a predetermined number of replays, and the like.
【0009】
Rules and requirements can be specified in License 16 according to any appropriate language and syntax. For example, the language can simply specify the attributes and values that should be met (date should be after X, etc.), or the specified script (if the date is greater than X ...). You can request that the function be performed according to (such as).
【0010】
If the license evaluator 20 determines that license 16 is valid and the user meets the rules and requirements, the digital content 12 can be rendered. Specifically, the decryption key (KD) is obtained from license 12 to render content 12, and this decryption key (KD) is from content package 13 (KD) to obtain the actual content 12. (Content)), and then the actual content 12 is actually rendered.
【0011】
The DRM system 10 encrypts such content 12 and associates the content 12 with a license 16 having a set of rules to package the content 12 for use by the user. This allows Content 12 to be rendered only in accordance with the rules of License 16. Content 12 requires a license 16 to access itself, so content 12 can be freely distributed. Therefore, in order to package the content 12 for publishing according to the DRM system 10, the packager and the licensor need to exchange information so that the packager can package the DRM content 12 which the licensor can issue the corresponding license 16. There is. More specifically, the licensor can "provide" the packager to package the content for publication, and the packager actually packages the content for publishing and the user licenses the packaged content. There is a demand for methods and mechanisms to acquire.
【0012】
[Means for solving problems]
In one embodiment of the invention, the packager packages the digital content for the user, and the licensor issues the digital license for the content to the user so that the user renders the content only according to the license. To provide the packager with packaging content for the user, the licensor generates a secret to be shared with the packager when it receives a provisioning request from the packager. The shared secret allows the packager and licensor to calculate the content key (KD) for the content.
【0013】
The licensor generates a random content key (KD-PROV) and encrypts the secret according to (KD-PROV) to form (KD-PROV (secret)). The licensor signs the packager's public key (PU-PA1) with the licensor's private key (PR-LI) to prove that they are the same ((PU-PA1) S (PR-LI)). , (KD-PROV (secret)), (PU-PA1) S (PR-LI), and any associated certificate chain sent to the packager.
【0014】
In one embodiment of the invention, the provided packager is encrypted according to the provisioning content provided by the licensor, including (KD-PROV (secret)), and the packager's public key (KD-). It has a license (PU-PA2) ((PU-PA2 (KD-PROV))) provided by the licensor including PROV). In order to package the content for the user, the packager selects the license provided by the licensor and the content provided, obtains (PU-PA2 (KD-PROV)) from the provided license, and (KD-PROV). ) Is applied to (PU-PA2 (KD-PROV)) by the packager's corresponding private key, (KD-PROV (secret)) is obtained from the provided content, and a shared secret is obtained. Therefore, apply (KD-PROV) to (KD-PROV (secret)).
【0015】
The packager then generates a random content ID for the content, calculates the content key (KD) based on the random content ID and secret, and encrypts the content according to (KD) ((KD (content))). .. The packager then obtains the provided content ID with the licensor's identifier from one of the provided licenses and the provided content, and in order to form the packaged content, the packager obtains a random content ID and the packager's public key ( PU-PA1) and the licensor's identifier are attached to (KD (content)), and the packaged content is distributed to users.
【0016】
In one embodiment of the invention, the packaged content owned by the user includes (KD (content)), a content ID, and (PU-PA1). To issue a license to the content, the licensor will use the content ID, (PU-PA1), and the public key (PU-US) associated with the user to be used to bind the license to the user. Receive requests that include. Based on (PU-PA1), the licensor acquires the stored and provided information about the packager, including the shared secret, calculates the (KD) based on the request and the content ID received with the acquired secret, and requests. Encrypt (KD) according to (PU-US) received with ((PU-US (KD))). The licensor then attaches the content ID to (PU-US (KD)) to form the license and sends the license to the user.
【0017】
The above "means for solving the problem" and the following detailed description of embodiments of the present invention will be better understood by reading with reference to the accompanying drawings. To illustrate the invention, the drawings show currently preferred embodiments. However, it should be understood that the present invention is not strictly limited to the configurations and means illustrated.
【0018】
BEST MODE FOR CARRYING OUT THE INVENTION
Computer Environment Figure 1 and the following description are intended to provide a brief and general description of a suitable computer environment in which the present invention and / or parts thereof can be practiced. Although not required, the present invention will be described in the general context of computer-executable instructions such as program modules being executed by a computer such as a client workstation or server. In general, a program module includes routines, programs, objects, components, data structures, etc. that perform a particular task or perform a particular abstract data type. In addition, the present invention and / or parts thereof include other computer systems, including handheld devices, multiprocessor systems, microprocessor-based or programmable home appliances, network PCs, minicomputers, mainframe computers, and the like. Please understand that it can be done in a configuration. The present invention can also be implemented in a distributed computer environment in which tasks are performed by remote processing devices linked by a communication network. In a distributed computer environment, program modules can be located in both local and remote storage.
【0019】
As shown in FIG. 2, a typical general purpose computer system includes a processing device 121, a system memory 122, and a system bus 123 that connects various system components including the system memory to the processing device 121. Includes type personal computer 120 and the like. System bus 123 may be any of a plurality of types of bus structures, including memory buses or memory controllers, peripheral buses, and local buses that use any of the various bus architectures. System memory includes read-only memory (ROM) 124 and random access memory (RAM) 125. The basic input / output system 126 (BIOS) includes a basic routine that assists in the transfer of information between the elements of the personal computer 120 at the time of startup or the like, and is stored in the ROM 124.
【0020】
The personal computer 120 includes a hard disk drive 127 for reading and writing from a hard disk (not shown), a magnetic disk drive 128 for reading and writing from a removable magnetic disk 129, and a CD-ROM or other. It may further include an optical disk drive 130 for reading from and writing to a removable optical disk 131, such as an optical medium. The hard disk drive 127, the magnetic disk drive 128, and the optical disk drive 130 are connected to the system bus 123 by the hard disk drive interface 132, the magnetic disk drive interface 133, and the optical disk drive interface 134, respectively. These drives and their associated computer-readable media provide non-volatile storage of computer-readable instructions, data structures, program modules, and other data for the personal computer 20.
【0021】
A typical embodiment described herein uses a hard disk, a removable magnetic disk 129, and a removable optical disk 131, but other types that can store data accessible by a computer. It should be understood that computer-readable media can also be used with typical operating systems. Other types of such media include magnetic cassettes, flash memory cards, digital video discs, Bernoulli cartridges, random access memory (RAM), read-only memory (ROM), and the like.
【0022】
Some program modules store on a hard disk, magnetic disk 129, optical disk 131, ROM 124, or RAM 125, including operating system 135, one or more application programs 136, other program modules 137, and program data 138. be able to. The user can enter commands and information into the personal computer 120 through input devices such as the keyboard 140 and the pointing device 142. Other input devices (not shown) can include microphones, joysticks, gamepads, satellite dishes, scanners, and the like. These input devices and other input devices are often connected to the processor 121 via a serial port interface 146 coupled to the system bus, but are a parallel port, game port, or universal serial bus (USB). You can also connect with other interfaces such as). A monitor 147 or other type of display is also connected to the system bus 123 via an interface such as a video adapter 148. In addition to monitor 147, personal computers typically include other peripheral output devices (not shown) such as speakers and printers. A typical system in Figure 2 also includes a host adapter 155, a small computer system interface (SCSI) bus 156, and an external storage device 162 connected to the SCSI bus 156.
【0023】
The personal computer 120 can operate in a networked environment using a logical connection to one or more remote computers, such as the remote computer 149. The remote computer 149 may be another personal computer, server, router, network PC, peer device, or other common network node, typically many of the elements mentioned above with respect to the personal computer 120 or All of them are included, but only the storage device 150 is shown in FIG. The logical connection shown in FIG. 2 includes a local area network (LAN) 151 and a wide area network (WAN) 152. Such networked environments are widespread in offices, enterprise-wide computer networks, intranets, and the Internet.
【0024】
When used in a LAN network connection environment, the personal computer 120 is connected to LAN 151 via a network interface or adapter 153. When used in a WAN network connection environment, the personal computer 120 typically includes a modem 154, or other means for establishing communication over a wide area network 152 such as the Internet. The modem 154, which may be internal or external, is connected to the system bus 123 via the serial port interface 146. In a networked environment, the program module shown for personal computer 120, or a portion thereof, can be stored in a remote storage device. It will be appreciated that the network connections illustrated are exemplary and other means of establishing communication links between computers can also be used.
【0025】
Content Publishing As disclosed above, DRM Architecture 10 encrypts and packages Content 12 and allows access to Digital Content 12 only in accordance with a set of rules for the corresponding License 16. To control. However, it should be understood that DRM architecture 10 as described above is somehow needed. Especially in the field of publishing, if an individual wishes to publish Content 12 within the framework of DRM Architecture 10, to enable such personal packaging and publishing in an easy and economical way, Such architecture 10 can be modified in some way as described below. Of course, any packager / publisher can use Architecture 10, described below, without departing from the spirit and scope of the invention.
【0026】
As will be described later, the publishing of the content 12 related to the DRM architecture 10 and the consumption of the published content 12 are as follows: (1) The licensor "provides" to the publisher etc. to package the content 12 for publishing. Then, (2) the packager actually packages the content 12 for publishing, and (3) the packaged content 13 to be published is rendered by the user on the computer device 14 based on the license 16 obtained from the licensor. Needs. Next, each of the above items will be described.
【0027】
Provided to Package Content to a Packager In one embodiment of the invention, and also with reference to FIG. 3, prior to actually publishing the content 12, the packager 60 and the licensor 62 are the user 64 computer devices. Packager 60 and Licensor 62 so that the Packager 60 / Publisher can publish Content 12 for consumption in 14 and Licensor 62 can issue License 16 to User 64 to render that Content 12. Need to exchange information. Alternatively, the licensor 62 must be "provided" to the packager. Note that the Packager 60 for Content 12 may be the publisher of Content 12 or may have a different personality from that publisher. In this embodiment, the provision is based on a secret shared between the packager 60 and the licensor 62 and a public private key pair (PU-PA1, PR-PA1) associated with the packager 60.
【0028】
Typically, key pairs (PU-PA1, PR-PA1) are used by the packager 60 to identify itself, to encrypt and decrypt, and to create a signature. A shared secret between the licensor and the packager allows each of the licensor and the packager to calculate the content key (KD) for one of the content 12. This calculation can be based on any algorithm agreed upon by both the licensor and the packager, without departing from the spirit and scope of the invention. In one embodiment of the invention, the content key (KD) for one of the content 12 having the content ID is obtained from the content ID such as a hash and the hash of the secret based on the following SHA algorithm. Content key (KD) = SHA (content ID, secret) [0029]
With reference to one embodiment of the invention and FIG. 4, the provision is carried out as follows. Preliminarily, the packager 60 requires the licensor 62 to provide to the packager 60 (step 1401). This requirement may take any particular form without departing from the spirit and scope of the invention, but includes at least the certificate chain 68 associated with the identifying certificate 66. As described in more detail below, the identifying certificate 66 is used to bind license 16 to the packager 60, especially if the packager 60 also has the corresponding private key (PR-PA2). Contains the public key (PU-PA2) associated with the packager 60.
【0030】
Note that (PU-PA2, PR-PA2) may be different from (PU-PA1, PR-PA1) or the same as (PU-PA1, PR-PA1). But ideally, the paired keys should be separate. In particular, and as in the past, (PR-PA2) should only be accessible by trusted component 18, not externally available.
【0031】
In addition, the request can include the proposed Business Rule 70. As you can see, Rule 70 is a condition that grants User 64 License 16 for Content 12 packaged by Packager 60. Such Rule 70 can specify, for example, that the content is rendered only for a set number of times, a set number of days, and so on. The licensor 62 typically has the decision to agree to or request amendments to Rule 70.
【0032】
Upon receiving the request, the licensor 62 can first perform any transaction with the packager 60 that the licensor 62 deems appropriate (step 1403). For example, the licensor 62 can request the packager 60 to start subscribing, paying a fee, and so on. The licensor 62 can also authenticate the ID of the packager 60 by any available mechanism.
【0033】
In response to the request, the licensor 62 initiates offering to the packager 60 by generating an item specific to that packager 60 (step 1405). Specifically, the licensor 62 generates the shared secret described above. Further, in this case, the licensor 62 at this point generates a key pair (PU-PA1, PR-PA1) for the packager 60. If so, the licensor 62 signs (PU-PA1) with the private key (PR-LI) to prove that it is the same (ie, (PU-PA1) S (PR-LI)). ..
【0034】
Of course, the packager 60 may dislike having the licensor 62 know (PR-PA1). If so, the packager obtains the key pair (PU-PA1, PR-PA1) from another source and sends (PU-PA1) to the licensor as part of the request in step 1401, and the licensor 62 is the same. Sign the transmitted (PU-PA1) with a private key (PR-LI) to prove that it is (ie, (PU-PA1) S (PR-LI)).
【0035】
The generated shared secret, (PU-PA1) S (PR-LI), the certificate chain associated with (PU-PA1) S (PR-LI), and if generated by licensor 62 ( The PR-PA1) should be transmitted by the licensor 62 to the packager 60, and at least some of these items must be received and retained by the packager 60 in a secure manner. Therefore, in one embodiment of the invention, such an item is transmitted in one form of DRM content 12, which is content 12 provided in this embodiment. It should be noted that the provided content 12 is a special form of the provided content 12 in that when the provided content 12 is rendered, it actually only leaks the items it contains.
【0036】
Specifically, the licensor generates a random content key (KD-PROV) for the content 12 provided (step 1407), and then those items, (secret,) to form the content 12 provided. Encrypt (PU-PA1) S (PR-LI)), certificate chain, and one or more of (PR-PA1) according to (KD-PROV) (step 1409). Note that all of those items can be encrypted to form the content 12 to be served, or you can choose from those items and encrypt as well. In the latter case, as an example, only the secret and (PR-PA1) are so encrypted, and the (PU-PA1) S (PR-LI) and certificate chain provide that encrypted as header etc. Attached to content 12.
【0037】
It should be understood that a corresponding providing license 16 is required for the providing content 12 to be "rendered" by the packager 60 and its trusted content 18. Therefore, take (PU-PA2) from the identifying certificate 66 attached to the request in step 1401 (step 1411) and use (KD-PROV) to form (PU-PA2 (KD-PROV)). By encrypting with PU-PA2) (step 1413), the provided license is generated.
【0038】
Note that both the provided license 16 and the provided content 12 should have a content ID. Therefore, the licensor 62 generates a content ID and attaches the generated content ID to both the provided license 16 and the provided content 12. The content ID may be any suitable content ID without departing from the spirit and scope of the present invention. For example, the content ID may be an identifier of the licensor 62 such as the URL. However, it should be noted that if the licensor 62 should generate multiple pairs of license 16 and content 12 provided to the packager 60, each pair should have a unique content ID. Therefore, in such a case, the content ID can also be based on the URL of the licensor 62 and additional information.
【0039】
Note that the licensor 62 may wish to impose a constraint on the ability of the packager 60 to package the content 12. For example, the licensor 60 may want the packager 60 to pay for each time the content 12 is packaged. In one embodiment of the invention, in this case, the license 16 provided is a rich license that may include a set with abundant usage rules applicable to the packager 62. Therefore, in this case, the licensor specifies specific usage rules for using the provided license 16 (step 1415) and attaches the usage rules to the provided license 16 (step 1417).
【0040】
In one embodiment of the invention, the licensor 62 maintains a record of at least a portion of the information currently present in the provided license 16 and the provided content 12. Typically, this information provided is stored in a database or the like (step 1419) and is based on Content 12 packaged by Packager 60 in accordance with License 16 provided and Content 12 provided, as disclosed in more detail below. Used to build license 16 for user 64.
【0041】
Assuming that the licensor 62 has completed the construction of the license 16 to be provided and the content 12 to be provided and one of the transaction details has been completed in step 1403, the licensor 62 has the license 16 to be provided and the content 12 to be provided It sends to Packager 60, which stores them in its trusted component 18's license store and content store, respectively (step 1421). The license 16 provided and the content 12 provided are shown in FIGS. 5 and 6, respectively.
【0042】
Packaging Content in the Packager Next, referring to Figure 7, when the license 16 to be provided and the content 12 to be provided are provided to the packager 60 as shown in FIGS. 5 and 6, the packager 60 is as follows. Content 12 can be packaged as packaged content 13 and distributed. Note that the package may be executed in response to a request from user 64 for content 12 or to make that content 12 available if user 64 requests content 12.
【0043】
Preliminarily, the packager 60 selects the licensor 62 that issues the license 16 for the planned package content 12 (step 1701). Perhaps multiple licensors 62 are available for use by the packager 60, and the packager 60 has at least one pair of license 16 to provide and content 12 to provide for each available licensor 62. ..
【0044】
When the licensor 62 is selected and one pair of license 16 provided by the licensor 62 and content 12 provided is selected (assuming there are more than one), the packager binds to the selected license 16 provided. That is, the packager 60 has a trusted component 18 running on the computer device 14 of the packager 60, and makes the provided content key (KD-PROV) available to the trusted component 18. Request for the selected provided license 16 (step 1703). Therefore, Reliable Component 18 should review any usage rules for the selected providing license 16 and enable the provided content key (KD-PROV) based on those usage rules and other rules. Is possible (step 1705).
【0045】
Assuming that the provided content key (KD-PROV) can be enabled, trusted component 18 obtains (PU-PA2 (KD-PROV)) from license 16 (step 1707), (KD). You actually get (KD-PROV) by applying (PR-PA2) to it (step 1709) to get -PROV). Note that (PR-PA2) can be the private key (PR-BB) of the black box 30 of trusted component 18 or the private key of another key pair. Such another key pair may be, for example, a key pair owned by the packager 60 and may be available for the trusted component 18 and its black box 30.
【0046】
Using (KD-PROV), the Packager 60 / Reliable Component 18 decrypts the encrypted content of the Selected Offer Content 12 that corresponds to the Selected Offer License 16 (Step 1711). ). Therefore, the content ID, secret, (PU-PA1) S (PR-LI), certificate chain, and (PR-PA1) containing the URL of the licensor 62 are available. By traversing the certificate chain to acquire (PU-LI) and applying (PU-LI) to (PU-PA1) S (PR-LI) to validate (PU-PA1) (PU-PA1) PU-PA1) can be used. Instead, if Packager 60 already knows (PU-PA1) and (PR-PA1), Secret, (PU-PA1) S (PR-LI) and the certificate chain is available from the content it provides. , (PU-LI) is acquired and the certificate chain is crossed to verify (PU-PA1) S (PR-LI).
【0047】
The packager 60 can package the content 12 based on having the content ID, secret, (PU-PA1), and (PR-PA1) containing the URL of the licensor 62. Specifically, the packager 60 generates or selects the content ID of the content 12 to be packaged (step 1713), for example, setting the random content ID and secret to the content key (KD) = SHA (content ID, secret). Calculate the content key (KD) by applying, etc. (step 1715), and encrypt the content 12 according to (KD) to obtain (KD (content)) (step 1717). Note that the content ID may or may not be random and may actually be an identifier such as a book ISBN number or document reference number.
【0048】
In one embodiment of the invention, the packaged content 13 includes encrypted content 12 (KD (content)) and a rights label having metadata about the encrypted content 12. Specifically, in this embodiment, the packager 60 shows the content ID, (PU-PA1), the URL of the licensor 62, and how the user 64 can render the packaged content 12. Package (KD (content)) with rights label 72 containing usage rules (step 1719). Rights label 72 or at least part of it should be signed by (PR-PA1) to prevent unauthorized tampering. Note that the rules of use for rights label 72 may be added to or substitute for business rule 70 contained in the request in step 1401 above.
【0049】
After content 12 is encrypted and packaged with rights label 72, the packaged content 13 can be distributed to users 64 (step 1721). It should be understood that the packaged content 13 being distributed does not yet have the corresponding license 16. The packaged content 12 is shown in FIG.
【0050】
In particular, the Packager 60 uses only the provided license 16, the provided content 12, and the content ID in a manner similar to that described in FIG. 7 to calculate the content key (KD) for the content 12. , Any self-packaged content 12 can be decrypted. Therefore, the packager can discard the decrypted content 12 after packaging without affecting the packager's ability to access the packaged content 13. In particular, the packager 60 does not need to obtain a license 16 from the licensor 62 for the content 12. Later, if the packager 60 wants to access the self-packaged content 12, for example to edit the content 12, the packager 60 will be the licensor specified in the packaged content 13 (Figure 8). It does this by locating the license to provide for the URL, obtaining a shared secret, calculating (KD) (Figure 7), and decrypting the packaged content 13 using (KD).
【0051】
In the process described with reference to FIG. 7, the provided content key (KD-PROV) is leaked to the packager 60. In the worst case, if an unauthorized user attempts to access computer device 14 in Packager 60, the unauthorized user will probably get (KD-PROV) and a shared secret and (PR-PA1). You can use that (KD-PROV) for. In one embodiment of the invention, the trusted component 18 of the computer device 14 of the packager 60 receives the provided license 16 and the provided content 12 as inputs, extracts (KD-PROV), and shares it from the provided content 12. Use that (KD-PROV) to extract the secret and package the content 12. All this is done without showing the Packager 60 or any other secret or key used (KD-PROV) or used.
【0052】
Acquisition of License from Licensor by User If User 64 attempts to render Content 13 after acquiring Packaged Content 13, User 64 will be granted a valid license from Licensor 62 in a manner similar to the method described above. Instructed to acquire. In particular, referring to FIG. 9, the license 16 for the packaged content 13 is obtained from the licensor 62 in the following way.
【0053】
Preliminarily, user 64 of computer device 14 with trusted component 18 retrieves the rights label 72 packaged with the encrypted content 12 (step 1901) and obtains the URL of the licensor 62 from the rights label 72 (step 1901). Step 1903). User 64 sends the identifying certificate 74, the associated certificate chain 76, and the rights label 72 to the licensor 62 of the acquired URL to request license 16 for content 12 (step 1905). If the user 64 also has the corresponding private key (PR-US), the identifying certificate 74 should be used to bind license 16 to the user 64, as well as the identifying certificate 66. Contains the public key (PU-US) associated with user 64. (PU-US, PR-US) is another key pair, even if it is the public key and private key (PU-BB, PR-BB) of the black box 30 of the trusted component 18 of the computer device 14 of the user 64. Note that it can be the public and private keys of. Such another key pair may be, for example, a key pair owned by user 64 and may be available for its trusted component 18 and black box 30.
【0054】
Upon receiving a request from user 64, including the identifying certificate 74, the associated certificate chain 76, and the rights label 72, the licensor 62 acquires (PU-PA1) from the rights label 72 and receives it. Based on this, the signature of rights label 72 (S (PR-PA1)) is verified by the acquired (PU-PA1) (step 1907). Assuming that the signature has been proven, the licensor 62 acquires information about the packager 60 stored as the information provided in step 1419 based on (PU-PA1). Specifically, the licensor 62 acquires a shared secret from the information it provides (step 1909).
【0055】
At some point, the licensor 62 can perform any transaction with the user 64 that it deems appropriate (step 1911). For example, the licensor 62 can request the user 64 to initiate a subscription, pay a fee, and so on. The licensor 62 can also authenticate the user 64's ID by any available mechanism. As you can see, the transaction can be based in part on the usage rule of rights label 72, business rule 70, or other rules contained in the request in step 1401 above.
【0056】
Assuming the transaction is complete, licensor 62 issues license 16 corresponding to content 12 to user 64. Specifically, the licensor obtains the content ID from the rights label 72 (step 1913) and calculates the content key (KD) for the content based on that calculation performed by the packager 60. This is done, for example, by applying the acquired content ID and secret to the content key (KD) = SHA (content ID, secret) (step 1915). The licensor 62 then retrieves (PU-US) from the identifying certificate 74 attached to the request in step 1905 (step 1917) and sets (KD) to (PU) to form (PU-US (KD)). -Generate license 16 with the content key (KD) by encrypting with (US) (step 1919). In addition, the licensor 62 places the content ID of the content 12 acquired from the rights label 72 and the usage rules for using the content 16 acquired from the rights label 72 in license 16 (step 1921). The constructed license 16 or at least part of it can be signed with the private key (S (PR-LI)) of the licensor 62, and the license corresponds to prove itself (PU-LI). Provided.
【0057】
When the licensor 62 finishes building the license 16, it sends the license 16 to the user 64, who properly stores the license 16 in the license store 38 of its trusted component 18 (step 1923). The license 16 is shown in FIG. User 64 can now render Content 12 under the circumstances described in License 16.
【0058】
Conclusion The programming required to enable the processing performed with respect to the present invention should be relatively simple and clear to those involved in programming. Therefore, such programming is not described herein. Any special programming can be used to realize the invention without departing from the spirit and scope of the invention.
【0059】
In the above description, the present invention allows the licensor 62 to "provide" to the packager 60 to package the content 12 for publishing, allowing the packager 60 to actually package the content 12 for publishing. It can be understood that it includes new and useful methods and mechanisms that enable and allow the user to obtain a license 16 for the packaged content 13. It should be understood that modifications can be made to the above embodiments without departing from the concept of the present invention. An example of such a change is shown below.
【0060】
Although the present invention has been described above for content 12 having rights label 72, it can also be practiced for content 12 having a header containing information similar to the information disclosed as being on rights label 72. Further, although disclosed above with respect to Content 12 separate from License 16, the present invention can also be practiced with respect to Content 12 incorporating License 16. Further, although the licensor 62 is disclosed herein to both provide to the packager 60 and issue a license 16 to the user 64, the present invention provides to the packager 601 It can also be implemented by one entity and another entity that issues license 16 to user 64. This is the case, assuming that the licensing entity has access to the provided information created by the providing entity.
【0061】
Of course, the provisions disclosed herein can be used for purposes other than publishing. For example, the user can be provided with access to content 12 that already exists in media such as portable media. In this case, the user acquires one or more licenses 16 with symmetric keys that allow mapping to the key table of portable media. Another example is Enterprise Software License Managers. This is a service set up within an enterprise or within another logical entity that issues software licenses to other devices. A root / hub license manager can be provided to issue a number of software licenses to down-level computers.
【0062】
Therefore, the present invention is not limited to the specified embodiment disclosed, but is intended to cover the gist of the present invention defined in the claims and amended forms within the scope of the claims. I want to be understood.
[Simple explanation of drawings]
FIG. 1 is a block diagram showing an enforcement method of an example of a trust-based system.
FIG. 2 is a block diagram showing a general-purpose computer system in which aspects of the present invention and / or a part thereof can be incorporated.
FIG. 3 provides a licensor to package content to a packager, the packager packages the content and distributes the packaged content to users, and the user licenses the packaged content according to an embodiment of the invention. It is a block diagram which shows the dialogue between a licensor, a packager, and a user in the process of acquiring.
FIG. 4 is a flow diagram showing steps performed by the licensor and the packager of FIG. 3 in the process of providing the packager to package the content according to an embodiment of the present invention.
FIG. 5 is a block diagram showing a provided license and provided content obtained from the process of FIG. 4 obtained by a packager from a licensor according to an embodiment of the present invention.
FIG. 6 is a block diagram showing a provided license and provided content obtained from the process of FIG. 4 obtained by a packager from a licensor according to an embodiment of the present invention.
FIG. 7 is a flow diagram showing steps performed by the packager of FIG. 3 in the process of packaging content and distributing the content to users according to an embodiment of the present invention.
FIG. 8 is a block diagram showing content obtained from the process of FIG. 7 obtained by a user from a packager according to an embodiment of the present invention.
FIG. 9 is a flow diagram showing steps performed by the licensor and the user of FIG. 3 in the process of a user acquiring a license for packaged content according to an embodiment of the present invention.
FIG. 10 is a block diagram showing a license obtained from the process of FIG. 9 obtained by a user from a licensor according to an embodiment of the present invention.
[Explanation of symbols]
Ten DRM Architecture 12 (KD (Content)) 13 Content Package 14 User's Computer Device 16 License 18 Reliable Component 20 License Evaluator
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US7571852B2 | Cited by | United States of America | Applicant |
| US7255270B2 | Cited by | United States of America | Applicant |
| US8646061B2 | Cited by | United States of America | Applicant |
| JP2006050624A | Cited by | Japan | Examiner |
| JP2005266896A | Cited by | Japan | Search report |
| JP2007318584A | Cited by | Japan | Search report |
| KR101248790B1 | Cited by | Republic of Korea | Search report |
| US9565171B2 | Cited by | United States of America | Applicant |
| JP2006050623A | Cited by | Japan | Examiner |
| JP2005332377A | Cited by | Japan | Search report |
| JP2009507433A | Cited by | Japan | Examiner |
| WO2005116859A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2009512912A | Cited by | Japan | Examiner |
| AU2005263101B2 | Cited by | Australia | Search report |
| JP2012134983A | Cited by | Japan | Examiner |
| CN100465938C | Cited by | China | Search report |
| US8194859B2 | Cited by | United States of America | Applicant |
| WO2006006781A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2012521035A | Cited by | Japan | Examiner |
| JPWO2006033154A1 | Cited by | Japan | Examiner |
| US8875310B2 | Cited by | United States of America | Applicant |
| JP4634392B2 | Cited by | Japan | Search report |
| US8955158B2 | Cited by | United States of America | Applicant |
12 members in 6 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 10170791 | United States of America | – | |
| 17079102 | United States of America | A | |
| 17079102 | United States of America | A | |
| 2002170791 | – | – | – |
| US20020170791 | – | – | – |
Members12
| Document | Office | Kind | |
|---|---|---|---|
| NO20032676D0 | Norway | D0 | |
| NO20032676L | Norway | L | |
| EP1372055A2 | European Patent Office (EPO) | A2 | |
| US2003233561A1 | United States of America | A1 | |
| JP2004046833AThis record | Japan | A | |
| EP1372055A3 | European Patent Office (EPO) | A3 | |
| US7065787B2 | United States of America | B2 | |
| EP1372055B1 | European Patent Office (EPO) | B1 | |
| ATE418111T1 | Austria | T1 | |
| DE60325298D1 | Germany | D1 | |
| JP4467255B2 | Japan | B2 | |
| NO332658B1 | Norway | B1 |
22 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313113S111 | S111 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2004046833
- Publication, DOCDB
- 2004046833
- Publication, EPODOC
- JP2004046833
- Application
- 167013
- Application, DOCDB
- 2003167013
- Application, EPODOC
- JP20030167013
Titles2
- Japanese
- デジタル著作権管理(DRM)方式に関連したコンテンツのパブリッシング
- English
- Publishing content related to digital rights management (DRM) methods
Classification
- CPC, 1
- G06F21/10
- IPC, 14
- G06F12 14
- G06F21 60
- G06F1 00
- G06F15 00
- G06F21 00
- G06F21 10
- G06F21 62
- G06F21 64
- G06Q10 00
- G06Q50 00
- H04L
- H04L9 08
- H04L9 28
- H04L12 64