Server device, information processor, information processing method and computer program
Abstract
Problem to be solved.To provide an apparatus and a method for efficiently constructing and executing an access restriction configuration based on a password.
Solution.An element password is set for each object which is a component of the content directory, and a database password is set for the entire content directory. The server executes password authentication processing based on the verification of the received password from the client and the stored password, determines the processing allowable area from the directory based on the establishment status of password authentication, and requests the client within the determined processing allowable area. Executes the request processing of the client when the processing to be performed is feasible. With this configuration, it is possible to set the access authority based on the directory structure without setting the access authority for each content, and it is possible to construct an efficient access restriction processing configuration and manage the content. [Selection diagram] Fig. 9

Term
Term ended
Projected expiry passed 14 May 2023, 3.4 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
23 claims: 6 independent, 17 dependent
- 1コンテンツ管理を実行するサーバ装置であり、サーバに対する処理要求装置としてのクライアントとのデータ送受信処理を実行するデータ送受信部と、ツリー構成を有するコンテンツディレクトリをコンテンツ管理構成として記憶するとともに、コンテンツディレクトリの各構成要素であるオブジェクト各々に対して設定される要素パスワードと、コンテンツディレクトリ全体に対して設定されるデータベースパスワードを記憶した記憶部と、クライアントからの受信パスワードと前記記憶部に記憶した記憶パスワードとの照合に基づくパスワード認証処理を実行するパスワード認証処理部と、前記パスワード認証処理部におけるパスワード認証の成立を条件として、前記クライアントの要求する処理を実行するデータ処理部とを有し、前記データ処理部は、前記パスワード認証処理部において、パスワード認証の成立した1以上のパスワードに基づいて前記コンテンツディレクトリ全体から処理許容領域を決定し、決定した処理許容領域内において前記クライアントの要求する処理が実行可能である場合に、該クライアントの要求処理を実行する構成であることを特徴とするサーバ装置。
- 2前記パスワード認証処理部は、前記クライアントの処理要求が、前記コンテンツディレクトリの構成要素としてのオブジェクトに対応するコンテンツの取得または再生要求である場合、クライアント要求コンテンツに対応する前記コンテンツディレクトリのオブジェクトに設定された要素パスワードと、クライアント要求コンテンツに対応する前記コンテンツディレクトリのオブジェクトから最上位オブジェクトであるルートに至る経路上に存在する上位オブジェクトに設定された上位オブジェクト対応の各要素パスワードと、を含むパスワード群に基づく認証処理を実行し、前記データ処理部は、前記パスワード群に基づく認証処理の成立を条件として、前記クライアントの要求処理を実行する構成であることを特徴とする請求項1に記載のサーバ装置。
- 3前記パスワード認証処理部は、前記クライアントの処理要求が、前記コンテンツディレクトリの構成要素としてのオブジェクトに対応するコンテンツ情報の閲覧要求である場合、閲覧要求対象のコンテンツ情報に対応する前記コンテンツディレクトリのオブジェクトからコンテンツディレクトリの最上位オブジェクトであるルートに至る経路上に存在する上位オブジェクトに設定された要素パスワード群の認証処理を実行し、前記データ処理部は、前記上位オブジェクトに設定された要素パスワード群の認証成立を条件として、前記クライアントの要求処理を実行する構成であることを特徴とする請求項1に記載のサーバ装置。
- 4前記パスワード認証処理部は、前記クライアントの処理要求が、前記コンテンツディレクトリの構成要素としてのオブジェクトに対応するコンテンツ情報のサーチに基づく取得要求である場合、クライアントから受信した1以上のパスワードに基づく認証処理を実行し、前記データ処理部は、前記パスワード認証処理部において、パスワード認証の成立した1以上のパスワードによって前記コンテンツディレクトリ全体からサーチ(検索)処理領域を決定し、該決定サーチ処理領域内に含まれるオブジェクトを対象としたサーチ(検索)処理を実行する構成であることを特徴とする請求項1に記載のサーバ装置。
- 5前記パスワード認証処理部は、前記クライアントの処理要求が、前記コンテンツディレクトリに基づいて管理されるコンテンツあるいはコンテンツ情報の更新要求である場合、コンテンツディレクトリ全体に対して設定されるデータベースパスワードと、クライアントの更新要求コンテンツまた更新要求コンテンツ情報に対応する前記コンテンツディレクトリのオブジェクトに設定された要素パスワードと、クライアントの更新要求コンテンツまた更新要求コンテンツ情報に対応する前記コンテンツディレクトリのオブジェクトから最上位オブジェクトであるルートに至る経路上に存在する上位オブジェクトに設定された上位オブジェクト対応の各要素パスワードと、を含むパスワード群に基づく認証処理を実行し、前記データ処理部は、前記パスワード群に基づく認証処理の成立を条件として、前記クライアントの要求処理を実行する構成であることを特徴とする請求項1に記載のサーバ装置。
- 6前記パスワード認証処理部は、前記クライアントの処理要求が、前記コンテンツディレクトリに基づいて管理されるコンテンツあるいはコンテンツ情報の移動処理またはコピー処理を伴う場合、クライアントの更新要求コンテンツまた更新要求コンテンツ情報に対応する前記コンテンツディレクトリの移動元および移動先、またはコピー元およびコピー先のオブジェクトに設定された要素パスワードと、前記移動元および移動先、またはコピー元およびコピー先のオブジェクトから最上位オブジェクトであるルートに至る経路上に存在する上位オブジェクトに設定された上位オブジェクト対応の各要素パスワードと、を含むパスワード群に基づく認証処理を実行し、前記データ処理部は、前記パスワード群に基づく認証処理の成立を条件として、前記クライアントの要求処理を実行する構成であることを特徴とする請求項1に記載のサーバ装置。
- 7前記パスワード認証処理部は、前記クライアントの処理要求が、前記コンテンツディレクトリの構成要素としてのオブジェクトの更新要求である場合、コンテンツディレクトリ全体に対して設定されるデータベースパスワードと、クライアントの更新要求オブジェクトから最上位オブジェクトであるルートに至る経路上に存在する上位オブジェクトに設定された上位オブジェクト対応の各要素パスワードと、を含むパスワード群に基づく認証処理を実行し、前記データ処理部は、前記パスワード群に基づく認証処理の成立を条件として、前記クライアントの要求処理を実行する構成であることを特徴とする請求項1に記載のサーバ装置。
- 8前記パスワード認証処理部は、前記クライアントの処理要求が、前記コンテンツディレクトリの構成要素としてのオブジェクトの移動処理またはコピー処理を伴う場合、コンテンツディレクトリ全体に対して設定されるデータベースパスワードと、前記コンテンツディレクトリの移動元および移動先、またはコピー元およびコピー先のオブジェクトから最上位オブジェクトであるルートに至る経路上に存在する上位オブジェクトに設定された上位オブジェクト対応の各要素パスワードと、を含むパスワード群に基づく認証処理を実行し、前記データ処理部は、前記パスワード群に基づく認証処理の成立を条件として、前記クライアントの要求処理を実行する構成であることを特徴とする請求項1に記載のサーバ装置。
- 9前記記憶部は、コンテンツディレクトリの構成要素としてのオブジェクトに対応する属性情報であるメタデータを各オブジェクトに対応して格納し、各オブジェクトのメタデータに対応するオブジェクトの要素パスワードを記録した構成であることを特徴とする請求項1に記載のサーバ装置。
- 10前記記憶部は、コンテンツディレクトリの構成要素としてのオブジェクトに対応する属性情報であるメタデータを各オブジェクトに対応して格納し、各オブジェクトのメタデータに対応するオブジェクトの要素パスワード、および、当該オブジェクトから最上位オブジェクトであるルートに至る経路上に存在する上位オブジェクトに設定された上位オブジェクト対応の要素パスワードを記録した構成であることを特徴とする請求項1に記載のサーバ装置。
- 11前記記憶部は、コンテンツディレクトリの構成要素としてのオブジェクトに対応する属性情報であるメタデータを各オブジェクトに対応して格納し、各オブジェクトのメタデータに対応するオブジェクトの要素パスワード、および、当該オブジェクトから最上位オブジェクトであるルートに至る経路上に存在する上位オブジェクト中、要素パスワードの設定された上位オブジェクトのコンテンツディレクトリにおける位置情報を記録した構成であることを特徴とする請求項1に記載のサーバ装置。
- 12コンテンツ管理を実行するサーバに対する処理要求を実行するクライアントとしての情報処理装置であり、サーバ利用アプリケーションの動作期間内にユーザにより入力された全パスワードを記憶する記憶部と、前記サーバに対する処理要求または前記サーバからのパスワード要求に対する応答として、前記記憶部に格納した全パスワードを送信データとして設定する処理を実行するとともに、サーバ利用アプリケーションの終了を条件として、前記記憶部に記憶された全パスワードを消去する処理を実行するデータ処理部と、を有することを特徴とする情報処理装置。
- 13コンテンツ管理処理を実行するサーバにおける情報処理方法であり、サーバに対する処理要求装置としてのクライアントからの処理要求およびパスワードを受信するステップと、前記クライアントからの受信パスワードとサーバ内の記憶部に記憶した記憶パスワードとの照合に基づくパスワード認証処理を実行するパスワード認証処理ステップと、前記パスワード認証処理ステップにおけるパスワード認証の成立を条件として、クライアントの要求処理を実行するデータ処理ステップとを有し、前記データ処理ステップは、前記パスワード認証処理ステップにおいて、パスワード認証の成立した1以上のパスワードに基づいてコンテンツ管理構成としてのコンテンツディレクトリから処理許容領域を決定するステップと、該決定処理許容領域内においてクライアントの要求する処理が実行可能である場合に、該クライアントの要求処理を実行するステップと、を有することを特徴とする情報処理方法。
- 14前記パスワード認証処理ステップは、前記クライアントからの処理要求が、前記コンテンツディレクトリの構成要素としてのオブジェクトに対応するコンテンツの取得または再生要求である場合、クライアントの処理要求コンテンツに対応する前記コンテンツディレクトリのオブジェクトに設定された要素パスワードと、クライアント要求コンテンツに対応する前記コンテンツディレクトリのオブジェクトから最上位オブジェクトであるルートに至る経路上に存在する上位オブジェクトに設定された上位オブジェクト対応の各要素パスワードと、を含むパスワード群に基づく認証処理を実行し、前記データ処理ステップは、前記パスワード群に基づく認証処理の成立を条件として、前記クライアントの要求処理を実行することを特徴とする請求項13に記載の情報処理方法。
- 15前記パスワード認証処理ステップは、前記クライアントの処理要求が、前記コンテンツディレクトリの構成要素としてのオブジェクトに対応するコンテンツ情報の閲覧要求である場合、閲覧要求対象のコンテンツ情報に対応する前記コンテンツディレクトリのオブジェクトからコンテンツディレクトリの最上位オブジェクトであるルートに至る経路上に存在する上位オブジェクトに設定された要素パスワード群の認証処理を実行し、前記データ処理ステップは、前記上位オブジェクトに設定された要素パスワード群の認証成立を条件として、前記クライアントの要求処理を実行することを特徴とする請求項13に記載の情報処理方法。
- 16前記パスワード認証処理ステップは、前記クライアントの処理要求が、前記コンテンツディレクトリの構成要素としてのオブジェクトに対応するコンテンツ情報のサーチに基づく取得要求である場合、クライアントから受信した1以上のパスワードに基づく認証処理を実行し、前記データ処理ステップは、前記パスワード認証処理ステップにおいて、パスワード認証の成立した1以上のパスワードによって前記コンテンツディレクトリ全体からサーチ(検索)処理領域を決定し、該決定サーチ処理領域内に含まれるオブジェクトを対象としたサーチ(検索)処理を実行する構成であることを特徴とする請求項13に記載の情報処理方法。
- 17前記パスワード認証処理ステップは、前記クライアントの処理要求が、前記コンテンツディレクトリに基づいて管理されるコンテンツあるいはコンテンツ情報の更新要求である場合、コンテンツディレクトリ全体に対して設定されるデータベースパスワードと、クライアントの更新要求コンテンツまた更新要求コンテンツ情報に対応する前記コンテンツディレクトリのオブジェクトに設定された要素パスワードと、クライアントの更新要求コンテンツまた更新要求コンテンツ情報に対応する前記コンテンツディレクトリのオブジェクトから最上位オブジェクトであるルートに至る経路上に存在する上位オブジェクトに設定された上位オブジェクト対応の各要素パスワードと、を含むパスワード群に基づく認証処理を実行し、前記データ処理ステップは、前記パスワード群に基づく認証処理の成立を条件として、前記クライアントの要求処理を実行する構成であることを特徴とする請求項13に記載の情報処理方法。
- 18前記パスワード認証処理ステップは、前記クライアントの処理要求が、前記コンテンツディレクトリに基づいて管理されるコンテンツあるいはコンテンツ情報の移動処理またはコピー処理を伴う場合、クライアントの更新要求コンテンツまた更新要求コンテンツ情報に対応する前記コンテンツディレクトリの移動元および移動先、またはコピー元およびコピー先のオブジェクトに設定された要素パスワードと、前記移動元および移動先、またはコピー元およびコピー先のオブジェクトから最上位オブジェクトであるルートに至る経路上に存在する上位オブジェクトに設定された上位オブジェクト対応の各要素パスワードと、を含むパスワード群に基づく認証処理を実行し、前記データ処理ステップは、前記パスワード群に基づく認証処理の成立を条件として、前記クライアントの要求処理を実行する構成であることを特徴とする請求項13に記載の情報処理方法。
- 19前記パスワード認証処理ステップは、前記クライアントの処理要求が、前記コンテンツディレクトリの構成要素としてのオブジェクトの更新要求である場合、コンテンツディレクトリ全体に対して設定されるデータベースパスワードと、クライアントの更新要求オブジェクトから最上位オブジェクトであるルートに至る経路上に存在する上位オブジェクトに設定された上位オブジェクト対応の各要素パスワードと、を含むパスワード群に基づく認証処理を実行し、前記データ処理ステップは、前記パスワード群に基づく認証処理の成立を条件として、前記クライアントの要求処理を実行する構成であることを特徴とする請求項13に記載の情報処理方法。
- 20前記パスワード認証処理ステップは、前記クライアントの処理要求が、前記コンテンツディレクトリの構成要素としてのオブジェクトの移動処理またはコピー処理を伴う場合、コンテンツディレクトリ全体に対して設定されるデータベースパスワードと、前記コンテンツディレクトリの移動元および移動先、またはコピー元およびコピー先のオブジェクトから最上位オブジェクトであるルートに至る経路上に存在する上位オブジェクトに設定された上位オブジェクト対応の各要素パスワードと、を含むパスワード群に基づく認証処理を実行し、前記データ処理ステップは、前記パスワード群に基づく認証処理の成立を条件として、前記クライアントの要求処理を実行する構成であることを特徴とする請求項13に記載の情報処理方法。
- 21コンテンツ管理を実行するサーバに対する処理要求を実行する情報処理方法であり、サーバ利用アプリケーションの動作期間内にユーザにより入力された全パスワードを記憶部に記憶するパスワード記憶ステップと、前記サーバに対する処理要求または前記サーバからのパスワード要求に対する応答として、前記記憶部に格納した全パスワードを送信データとして送信するステップと、サーバ利用アプリケーションの終了を条件として、前記記憶部に記憶された全パスワードを消去するパスワード消去ステップと、を有することを特徴とする情報処理方法。
- 22コンテンツ管理処理サーバにおける情報処理を実行するコンピュータ・プログラムであり、サーバに対する処理要求装置としてのクライアントからの処理要求およびパスワードを受信するステップと、前記クライアントからの受信パスワードとサーバ内の記憶部に記憶した記憶パスワードとの照合に基づくパスワード認証処理を実行するパスワード認証処理ステップと、前記パスワード認証処理ステップにおけるパスワード認証の成立を条件として、クライアントの要求処理を実行するデータ処理ステップとを有し、前記データ処理ステップは、前記パスワード認証処理ステップにおいて、パスワード認証の成立した1以上のパスワードに基づいてコンテンツ管理構成としてのコンテンツディレクトリから処理許容領域を決定するステップと、該決定処理許容領域内においてクライアントの要求する処理が実行可能である場合に、該クライアントの要求処理を実行するステップと、を有することを特徴とするコンピュータ・プログラム。
- 23コンテンツ管理サーバに対する処理要求を実行するコンピュータ・プログラムであり、サーバ利用アプリケーションの動作期間内にユーザにより入力された全パスワードを記憶部に記憶するパスワード記憶ステップと、前記サーバに対する処理要求または前記サーバからのパスワード要求に対する応答として、前記記憶部に格納した全パスワードを送信データとして送信するステップと、サーバ利用アプリケーションの終了を条件として、前記記憶部に記憶された全パスワードを消去するパスワード消去ステップと、を有することを特徴とするコンピュータ・プログラム。
Independent claims23
508 paragraphs in 1 section, as filed
【0001】
[Technical field to which the invention belongs]
The present invention relates to a server device, an information processing device, an information processing method, and a computer program. Further, the present invention relates to a server device, an information processing device, an information processing method, and a computer program that realize password-based access restriction for the content stored in the content management server.
【0002】
[Conventional technology]
With the spread of data communication networks in recent years, so-called home networks, in which home appliances, computers, and other peripheral devices are connected to each other and communication between each device is possible, are becoming widespread. The home network provides convenience and comfort to users, such as sharing the data processing function of each device by communicating between network-connected devices and sending and receiving content between devices. It is expected that it will become more and more popular.
【0003】
Universal Plug and Play (UPnP) is known as a protocol suitable for such a home network configuration. Universal Plug and Play (UPnP) makes it possible to easily build a network without complicated operations, and provides services for each connected device in network-connected devices without difficult operations or settings. It is intended to be receivable. In addition, UPnP has the advantage that devices can be easily added without depending on the OS (operating system) on the device.
【0004】
UPnP exchanges definition files conforming to XML (eXtensible Markup Language) between connected devices and performs mutual recognition between devices. The outline of UPnP processing is as follows. (1) Addressing process to acquire own device ID such as IP address. (2) Discovery process that searches each device on the network, receives a response from each device, and acquires information such as device type and function included in the response. (3) Service request processing that requests services from each device based on the information acquired in the discovery processing.
【0005】
By performing the above processing procedure, it is possible to provide and receive a service to which a device connected to the network is applied. A device newly connected to the network acquires the device ID by the above addressing process, acquires the information of the other device connected to the network by the discovery process, and requests the service from the other device based on the acquired information. Is possible.
【0006】
For example, when trying to play content such as music data and image data stored in a server on a client-side device, the client acquires information about the content held by the server. The server stores the content in the storage unit and also stores the attribute information for the stored content. The attribute information includes, for example, various information such as the title of a song or movie, the artist name, the recording date and time, and the data compression mode as the content. These attribute information is called metadata or meta information.
【0007】
For example, when trying to play content such as music data and image data stored in a server on a client-side device, the content information stored in the server from the client side to the server, for example, a song or movie title or artist. It sends a request to acquire the name, data compression mode information (ATRAC: adaptive transform acoustic coding, MPEG: moving picture experts group, etc.), and, if necessary, attribute information of various contents such as copyright information.
【0008】
The server sends metadata (attribute information) about the contents held by the server to the client in response to a request from the client. The client displays the content information on the display of the client device according to a predetermined display program based on the metadata acquired from the server. For example, a list of songs consisting of artist names, titles, etc. is displayed on the display. The user confirms or selects the content to be played back based on the display information, and transmits the content transmission request to the server. The server receives the content request from the client, the server sends the content to the client in response to the reception request, and the received content is played back on the client side.
【0009】
The content stored in the server in this way can be searched from other devices (clients) connected to the network, and specific content can be specified and played back.
【0010】
The content management server also needs to consider measures against unauthorized access. Devices in the home network, such as servers, often store content that requires copyright management, such as private content and paid content. In the network configuration as described above, it is easy for a user who does not have the right to use contents or the like to enter the network. For example, in the case of a network configured by wireless LAN, there is a situation in which a server in the house is illegally entered into the network from the outdoors or from a neighboring house using a communication device to exploit the contents. Can occur. Such a configuration that allows unauthorized access also causes confidentiality leakage, and is also an important problem from the viewpoint of content copyright management.
【0011】
In order to eliminate unauthorized access as described above, for example, the server is made to maintain a list of clients that are allowed to access, and when a client requests access to the server, the server executes a collation process with the list to eliminate unauthorized access. The configuration to be used is proposed.
【0012】
For example, MAC address filtering is known in which a MAC (Media Access Control) address, which is a physical address unique to a network-connected device, is set as an access-allowed device list. With MAC address filtering, a MAC address that allows access is registered in advance in a router or gateway that isolates the internal network (subzone) such as the home network from the external network, and the MAC address of the received packet is registered. It collates with the MAC address and denies access from devices with unregistered MAC addresses.
【0013】
In this way, by setting the MAC list on the server and accessing from the device set in the MAC list, it is possible to eliminate the access from an unauthorized third party. However, even among family members who basically have access authority to the server, personal contents and the like may be stored in the server.
【0014】
In a server where access is permitted by a plurality of users, it is desirable to set access rights for each user in units of individual contents stored in the server or content folders storing a plurality of contents.
【0015】
For example, Patent Document 1 discloses a configuration in which a plurality of users who use content on a content distribution server are divided into levels and the content distribution mode is changed according to the level. Specifically, when there is a content usage request from a user for whom the content usage right has not been set, the configuration for distributing the content after executing the content license processing is disclosed.
【0016】
However, the configuration disclosed in Patent Document 1 above has a problem that it is necessary to individually set the usage right of each user for each of the contents stored in the server, and a complicated procedure is required.
【0017】
[Patent Document 1]
Publication of Patent No. 2001-142495 [0018]
[Problems to be Solved by the Invention]
The present invention has been made in view of the above-mentioned problems, and by setting a password for the content possessed by the content management server according to the structure of the content directory, the user's right to use each component of the content directory. It is an object of the present invention to provide a server device, an information processing device, an information processing method, and a computer program capable of efficiently and surely constructing an access authority of each user.
【0019】
[Means for solving problems]
The first aspect of the present invention is a server device that executes content management, and includes a data transmission / reception unit that executes data transmission / reception processing with a client as a processing request device for the server, and a content management configuration having a content directory having a tree structure. A storage unit that stores the element password set for each object that is each component of the content directory, the database password set for the entire content directory, the received password from the client, and the above. A password authentication processing unit that executes password authentication processing based on verification with a stored password stored in the storage unit, and a data processing unit that executes processing requested by the client on condition that password authentication is established in the password authentication processing unit. The data processing unit determines a processing allowable area from the entire content directory based on one or more passwords for which password authentication has been established in the password authentication processing unit, and the processing allowable area is within the determined processing allowable area. The server device is characterized in that it is configured to execute the request processing of the client when the processing requested by the client can be executed.
【0020】
Further, in one embodiment of the server device of the present invention, the password authentication processing unit is a client when the processing request of the client is a request for acquisition or reproduction of content corresponding to an object as a component of the content directory. The element password set for the object of the content directory corresponding to the requested content and the higher level set for the higher level object existing on the route from the object of the content directory corresponding to the client request content to the root which is the highest level object. The data processing unit executes the authentication process based on each element password corresponding to the object and the password group including the password group, and the data processing unit executes the request processing of the client on condition that the authentication process based on the password group is established. It is characterized by that.
【0021】
Further, in one embodiment of the server device of the present invention, the password authentication processing unit requests browsing when the processing request of the client is a browsing request of content information corresponding to an object as a component of the content directory. The data processing unit executes the authentication process of the element password group set in the upper object existing on the route from the object of the content directory corresponding to the target content information to the root which is the highest object of the content directory. The configuration is such that the request processing of the client is executed on condition that the authentication of the element password group set in the higher-level object is established.
【0022】
Further, in one embodiment of the server device of the present invention, the password authentication processing unit is a case where the processing request of the client is an acquisition request based on a search for content information corresponding to an object as a component of the content directory. , The data processing unit executes an authentication process based on one or more passwords received from the client, and the data processing unit searches the entire content directory with one or more passwords for which password authentication has been established. It is characterized in that a region is determined and a search (search) process for an object included in the determined search processing region is executed.
【0023】
Further, in one embodiment of the server device of the present invention, when the processing request of the client is a content managed based on the content directory or a request for updating the content information, the password authentication processing unit uses the entire content directory. The database password set for the client, the element password set for the object of the content directory corresponding to the update request content or update request content information of the client, and the update request content or update request content information of the client. The data processing unit executes authentication processing based on the password group including each element password set for the upper object set in the upper object existing on the route from the object of the content directory to the root which is the highest level object. It is characterized in that the request processing of the client is executed on condition that the authentication processing based on the password group is established.
【0024】
Further, in one embodiment of the server device of the present invention, when the password authentication processing unit involves moving processing or copying processing of the content or content information managed based on the content directory, the processing request of the client is involved. The element password set for the move source and move destination, or copy source and copy destination objects of the content directory corresponding to the update request content and update request content information of the client, and the move source and move destination, or the copy source and Authentication processing is executed based on the password group including each element password set for the higher-level object set in the higher-level object existing on the route from the copy destination object to the root which is the highest-level object, and the data processing unit performs the authentication process. It is characterized in that the request processing of the client is executed on condition that the authentication processing based on the password group is established.
【0025】
Further, in one embodiment of the server device of the present invention, the password authentication processing unit sets the entire content directory when the processing request of the client is a request to update an object as a component of the content directory. Authenticate based on the password group including the database password to be created and each element password corresponding to the higher-level object set in the higher-level object existing on the route from the update request object of the client to the root which is the highest-level object. However, the data processing unit is characterized in that it executes the request processing of the client on condition that the authentication processing based on the password group is established.
【0026】
Further, in one embodiment of the server device of the present invention, when the processing request of the client involves a movement process or a copy process of an object as a component of the content directory, the password authentication processing unit covers the entire content directory. Correspondence between the database password set for the content directory and the higher-level object set for the higher-level object existing on the route from the source and destination of the content directory, or the copy source and copy destination object to the root which is the highest level object. The data processing unit is configured to execute the request processing of the client on condition that the authentication processing based on the password group is established. It is a feature.
【0027】
Further, in one embodiment of the server device of the present invention, the storage unit stores metadata which is attribute information corresponding to an object as a component of a content directory corresponding to each object, and the metadata of each object. The feature is that the configuration is such that the element password of the object corresponding to is recorded.
【0028】
Further, in one embodiment of the server device of the present invention, the storage unit stores metadata which is attribute information corresponding to an object as a component of a content directory corresponding to each object, and the metadata of each object. It is characterized in that the element password of the object corresponding to and the element password corresponding to the upper object set in the upper object existing on the route from the object to the root which is the uppermost object are recorded.
【0029】
Further, in one embodiment of the server device of the present invention, the storage unit stores metadata which is attribute information corresponding to an object as a component of a content directory corresponding to each object, and the metadata of each object. It is a configuration that records the element password of the object corresponding to, and the position information in the content directory of the upper object for which the element password is set among the upper objects existing on the route from the object to the root which is the highest level object. It is characterized by that.
【0030】
Further, the second aspect of the present invention is an information processing device as a client that executes a processing request to a server that executes content management, and stores all passwords entered by the user during the operation period of the server-using application. As a response to the processing request to the storage unit and the server or the password request from the server, a process of setting all the passwords stored in the storage unit as transmission data is executed, and the server-using application is terminated as a condition. The information processing device is characterized by having a data processing unit that executes a process of erasing all passwords stored in the storage unit.
【0031】
Further, the third aspect of the present invention is an information processing method in a server that executes content management processing, a step of receiving a processing request and a password from a client as a processing request device for the server, and receiving from the client. The request processing of the client is executed on condition that the password authentication processing step of executing the password authentication processing based on the verification of the password and the stored password stored in the storage unit in the server and the establishment of the password authentication in the password authentication processing step are performed. The data processing step includes a step of determining a processing allowable area from a content directory as a content management configuration based on one or more passwords for which password authentication has been established in the password authentication processing step. The information processing method is characterized by having a step of executing the request processing of the client when the processing requested by the client can be executed within the determination processing allowable area.
【0032】
Further, in one embodiment of the information processing method of the present invention, the password authentication processing step is a case where the processing request from the client is a content acquisition or reproduction request corresponding to an object as a component of the content directory. , The element password set in the object of the content directory corresponding to the processing request content of the client, and the higher-level object existing on the route from the object of the content directory corresponding to the client request content to the root which is the highest level object. The authentication process based on the password group including each element password corresponding to the set upper object is executed, and the data processing step executes the request process of the client on condition that the authentication process based on the password group is established. It is characterized by doing.
【0033】
Further, in one embodiment of the information processing method of the present invention, the password authentication processing step is viewed when the processing request of the client is a viewing request of content information corresponding to an object as a component of the content directory. The data processing step is performed by executing the authentication process of the element password group set in the upper object existing on the route from the object of the content directory corresponding to the requested content information to the root which is the highest object of the content directory. Is characterized in that the request processing of the client is executed on condition that the authentication of the element password group set in the higher-level object is established.
【0034】
Further, in one embodiment of the information processing method of the present invention, the password authentication processing step is an acquisition request based on a search for content information in which the processing request of the client corresponds to an object as a component of the content directory. In this case, an authentication process based on one or more passwords received from the client is executed, and the data processing step searches the entire content directory with one or more passwords for which password authentication has been established in the password authentication processing step. It is characterized in that a processing area is determined and a search (search) process for an object included in the determination search processing area is executed.
【0035】
Further, in one embodiment of the information processing method of the present invention, the password authentication processing step is a content directory when the processing request of the client is a content managed based on the content directory or a request for updating the content information. Corresponds to the database password set for the whole, the element password set in the object of the content directory corresponding to the update request content or update request content information of the client, and the update request content or update request content information of the client. An authentication process is executed based on a password group including each element password set for the higher-level object set in the higher-level object existing on the route from the object of the content directory to the root which is the highest-level object, and the data processing step. , subject to establishment of authentication processing based on the password set, before characterized in that it is configured to perform the request processing SL client.
【0036】
Further, in one embodiment of the information processing method of the present invention, the password authentication processing step involves moving or copying the content or content information managed based on the content directory in the processing request of the client. , The element password set for the move source and move destination, or copy source and copy destination objects of the content directory corresponding to the update request content and update request content information of the client, and the move source and move destination, or copy source. And the authentication process based on the password group including each element password set for the upper object set in the upper object existing on the route from the copy destination object to the root which is the uppermost object, and the data processing step. Is characterized in that the request processing of the client is executed on condition that the authentication processing based on the password group is established.
【0037】
Further, in one embodiment of the information processing method of the present invention, when the password authentication processing step is a request for updating an object as a component of the content directory, the password authentication processing step is applied to the entire content directory. Authentication processing based on the password group including the database password that is set and each element password that corresponds to the higher-level object that exists on the route from the update request object of the client to the root that is the highest-level object. The data processing step is characterized in that it is configured to execute the request processing of the client on condition that the authentication processing based on the password group is established.
【0038】
Further, in one embodiment of the information processing method of the present invention, the password authentication processing step is the entire content directory when the processing request of the client involves moving processing or copying processing of an object as a component of the content directory. The database password set for, and the higher-level object set for the higher-level object that exists on the route from the source and destination of the content directory, or the copy source and copy destination object to the root that is the highest level object. The authentication process based on the corresponding element password and the password group including the password group is executed, and the data processing step is configured to execute the request process of the client on condition that the authentication process based on the password group is established. It is characterized by.
【0039】
Further, the fourth aspect of the present invention is an information processing method for executing a processing request to a server that executes content management, and stores all passwords entered by the user within the operating period of the server-using application in the storage unit. The storage unit is subject to a password storage step, a step of transmitting all passwords stored in the storage unit as transmission data as a response to a processing request to the server or a password request from the server, and termination of a server-using application. It is an information processing method characterized by having a password erasing step for erasing all passwords stored in.
【0040】
Further, the fifth aspect of the present invention is a computer program that executes information processing in the content management processing server, and a step of receiving a processing request and a password from a client as a processing request device for the server, and a step of receiving the password from the client. The client request processing is performed on condition that the password authentication processing step of executing the password authentication processing based on the collation between the received password of the server and the stored password stored in the storage unit in the server and the establishment of the password authentication in the password authentication processing step are performed. The data processing step includes a data processing step to be executed, and the data processing step is a step of determining a processing allowable area from a content directory as a content management configuration based on one or more passwords for which password authentication has been established in the password authentication processing step. The computer program is characterized by having a step of executing the request processing of the client when the processing requested by the client can be executed within the determination processing allowable area.
【0041】
Further, the sixth aspect of the present invention is a computer program that executes a processing request to the content management server, and a password storage step of storing all passwords entered by the user within the operating period of the server-using application in the storage unit. And, as a response to the processing request to the server or the password request from the server, the step of transmitting all the passwords stored in the storage unit as transmission data and the termination of the server-using application are stored in the storage unit. It is in a computer program characterized by having a password erasure step that erases all passwords.
【0042】
[Action]
According to the configuration of the present invention, in the content management server, a content directory having a tree structure is set as a content management configuration, and an element password set for each object that is each component of the content directory and a content directory. The database password set for the entire directory is stored in the storage unit, the password authentication process is executed based on the collation between the received password from the client and the stored password stored in the storage unit, and one or more passwords for which password authentication is established are executed. The processing allowable area is determined from the entire content directory based on the above, and when the processing requested by the client can be executed within the determined processing allowable area, the client's request processing is executed. Access permissions can be set based on the directory structure without setting permissions, and efficient access restriction processing configurations can be constructed and content management can be performed.
【0043】
Further, according to the configuration of the present invention, in the client that executes the processing request to the server that executes the content management, all the passwords entered by the user during the operation period of the server-using application are stored in the storage unit, and the processing to the server is performed. As a response to the request or the password request from the server, all the passwords stored in the storage unit are sent as transmission data, and all the passwords stored in the storage unit are deleted on condition that the application using the server is terminated. The user does not have to repeatedly enter the same password within the operating period of the server-using application, the contents stored in the server can be used efficiently, and the leakage of the password is prevented by erasing the password.
【0044】
The computer program of the present invention provides, for example, a storage medium, a communication medium, such as a CD, FD, MO, etc., which are provided in a computer-readable format to a general-purpose computer system capable of executing various program codes. A computer program that can be provided by a storage medium or a communication medium such as a network. By providing such a program in a computer-readable format, processing according to the program is realized on the computer system.
【0045】
Still other objects, features and advantages of the present invention will be clarified by more detailed description based on the examples of the present invention described later and the accompanying drawings. In the present specification, the system is a logical set configuration of a plurality of devices, and the devices having each configuration are not limited to those in the same housing.
【0046】
BEST MODE FOR CARRYING OUT THE INVENTION
Hereinafter, the details of the server device, the information processing device, the information processing method, and the computer program of the present invention will be described with reference to the drawings.
【0047】
[System overview]
First, an example of an applicable network configuration of the present invention will be described with reference to FIG. FIG. 1 shows a server 101 that executes processing in response to processing requests from various client devices, and a PC 121, a monitor 122, a mobile phone 123, a player 124, and a PDA 125 as client devices that make processing requests to the server 101. Indicates a configuration connected via network 100, such as a home network configuration. In addition to this, various electronic devices and home appliances can be connected as the client device.
【0048】
The processing executed by the server 101 in response to the request from the client is, for example, the provision of contents stored in a storage means such as a hard disk owned by the server 101, or a data processing service by executing an application program that can be executed by the server. is there. Although the server 101 and the client device are shown separately in FIG. 1, the device that provides the service for the request from the client is shown as the server, and each client device is its own. When the data processing service is provided to other clients, the function as a server can be provided. Therefore, the network-connected client device shown in FIG. 1 can also be a server.
【0049】
The network 100 is either a wired network or a wireless network, and each connected device transmits and receives communication packets such as Ethernet (registered trademark) frames via the network 100. That is, the client executes the data processing request to the server 101 by transmitting the frame in which the processing request information is stored in the data part of the Ethernet frame to the server 101. The server 101 executes data processing in response to the reception of the processing request frame, stores the result data as the data processing result in the data unit of the communication packet as necessary, and transmits the result data to each client.
【0050】
The network connection device is composed of, for example, a Universal Plug and Play (UPnP) compatible device. Therefore, it is easy to add or delete connected devices to the network. Devices newly connected to the network are (1) addressing process to acquire their own device ID such as IP address. (2) Discovery process that searches each device on the network, receives a response from each device, and acquires information such as device type and function included in the response. (3) Service request processing that requests services from each device based on the information acquired in the discovery processing. By performing the above processing procedure, it becomes possible to receive the service to which the device connected to the network is applied.
【0051】
As an example of the information processing device constituting the server and client device shown in FIG. 1, a hardware configuration example of a PC will be described with reference to FIG.
【0052】
The CPU (Central Processing Unit) 201 executes various processes according to a program stored in a ROM (Read Only Memory) 202, an HDD 204, or the like, and functions as a data processing means or a communication control processing means. The program and data executed by the CPU 201 are appropriately stored in the RAM 203. The CPU 201, ROM 202, RAM 203, and HDD 204 are connected to each other via the bus 205.
【0053】
An input / output interface 206 is connected to the bus 205, and the input / output interface 206 includes, for example, an input unit 207 composed of a keyboard, switches, buttons, a mouse, etc. operated by the user, and various types of users. An output unit 208 composed of an LCD, a CRT, a speaker, etc. that presents the information of the above is connected. Further, a communication unit 209 that functions as a data transmission / reception means, and a removable recording medium 211 such as a magnetic disk, an optical disk, a magneto-optical disk, or a semiconductor memory can be mounted, and data reading or writing processing from these removable recording media 211 can be attached. Drive 210 is connected to execute.
【0054】
The configuration shown in FIG. 2 is an example of a server and a personal computer (PC) as an example of the network-connected device shown in FIG. 1, but the network-connected device is not limited to the PC, and as shown in FIG. 1, a mobile phone and a PDA. It can be configured by a mobile communication terminal such as, a playback device, various electronic devices such as a display, and an information processing device. Therefore, it is possible to have a hardware configuration unique to each device, and the processing according to the hardware is executed.
【0055】
Object Management and Metadata
Next, the object management configuration including the contents of the server that manages the contents provided to the client and the metadata will be described. The server holds information about contents such as still images, image data such as moving images, and audio data such as music stored in its own storage unit as attribute information (metadata) corresponding to each content.
【0056】
In addition, contents such as still images, image data such as moving images, and audio data such as music held by the server are collectively referred to as AV contents. In the server, AV contents are managed in a CDS (content directory service) in the server by a content management directory having a hierarchical structure.
【0057】
Figure 3 shows an example of the configuration of the content directory managed by the CDS (content directory service) of the server. The hierarchical structure can be shown as a branched tree-like diagram as shown in FIG. Each of the circles shown in FIG. 3 is an individual object. This hierarchical structure shows a logical management structure corresponding to the contents stored and managed by the server in the storage unit and the live streaming contents.
【0058】
Each element of the content directory, that is, a folder containing individual AV contents or a plurality of AV contents, and a metadata storage folder is called an object. Note that an object is a general term for a data unit processed by a server, and there are various objects other than individual AV contents, folders storing a plurality of AV contents, and metadata storage folders.
【0059】
The smallest unit of AV content, that is, one music data, one video data, one still image data, etc. is called an item. Items are also one of the objects.
【0060】
In addition, the upper object of the item defined as the set of items is called a container. The unit of the set is, for example, a set based on the physical storage position of each object, a set based on the logical relationship of each object, and a category. It can be set in various ways, such as a set based on.
【0061】
Objects are classified into classes according to their type, such as music (Audio), video (Video), photo (Photo), etc., and class labeling is performed. The client can, for example, specify a specific class to request and execute a "search" targeting only objects belonging to a specific classification. It is also possible to specify an object such as a specific folder, request "browsing" to request only information about the folder, and acquire information about the specific folder. In the server, the classes are also managed in a hierarchical structure, and subclasses can be set under one class.
【0062】
The metadata is various management information including attribute information corresponding to the content of the server, class definition information, information on the hierarchical structure constituting the content management directory, and the like. Metadata as attribute information of content defined in association with individual objects includes, for example, content identifier (ID) such as content URL, data size, resource information, title, artist name, copyright information, channel information, etc. , Contains various information. The individual information contained in the metadata is called a property or property information. It should be noted that it is predetermined in advance what kind of property metadata is possessed for each of the above-mentioned classes such as music (Audio), video (Video), photo (Photo), and live streaming data.
【0063】
In FIG. 3, the top level of the content directory is called the root container 301. For example, a music container 302, a moving image container 303, a still image container 304, and the like are set under the root container. Objects such as genre 305 are set at the lower level of the music container 302, and artists 306 and the like are set at the lower level of the genre.
【0064】
At the lower level of the video container 303, for example, a video capsule 307 storing video content is set as an item corresponding to the content. For example, the video capsule 307 corresponds to the video content stored in a storage unit such as a hard disk in the server. The content entity and the content information are managed based on the content directory having such a tree structure.
【0065】
For example, the content information (metadata) corresponding to the video capsule 307 includes a content identifier for the client to acquire the content, that is, a URL (Uniform Resource Locators) of the content as address information indicating the location of the content. The client acquires the URL of the video capsule 307, that is, the video capsule URL by the content information acquisition procedure, and sends the content request specifying the video capsule URL to the server to receive the video content corresponding to the video capsule from the server. Can be played.
【0066】
A client trying to execute a content search sends a "search" that specifies a class corresponding to the hierarchy of the content management directory or an object set, or a "browsing" that specifies a specific object to the server. By requesting, it is possible to obtain information on the content. The client displays the content information on the display based on the XML data that describes the content information received from the server.
【0067】
Figure 4 shows an example of the display processing of the content information list. In the example shown in FIG. 4, a content information list 321 having a data structure listing the content number, title, artist name, channel, and content URL is displayed on the display 320.
【0068】
These content information is generated based on the property information as a component of the content-corresponding metadata managed by the server. The server acquires the property information in the metadata of the content that matches the conditions based on the "search" or "browse" request received from the client, and generates XML data based on the acquired property information. And send it to the client.
【0069】
The client receives XML data based on the property information corresponding to the content extracted by the server, generates display data as shown in FIG. 4 based on the received XML data, and displays it on the client's display.
【0070】
The user on the client side selects the content to be played from these lists and sends the selected content specification information, for example, the content URL to the server, so that the content, that is, various contents such as music, movies, or photos are transmitted from the server. It is played and output on the client side.
【0071】
As described above, the content information transmitted to the client includes the URL (Uniform Resource Locators) of the content as the address information indicating the location of the content. The client device generates an HTTP (Hyper Text Transfer Protocol) GET method, which is a content acquisition request, and sends it to the server, provided that the user specifies (clicks) the content URL or link data displayed on the client display. , The server sends the content corresponding to the content URL to the client.
【0072】
[Content playback process by client]
The client who wants to play the content can make a content request to the server, receive the requested content from the server, and play the content. A general content playback procedure will be described with reference to FIG. First, in step S11, the client requests to acquire the content information held by the server. In step S12, the server provides content information such as the content URL (Uniform Resource Locators) list, content title, and artist name as address information indicating the location of the content, based on the content-enabled metadata according to the client's request. Generated by XML (eXtended Markup Language) data and sent to the client.
【0073】
In step S13, the client displays the content information on the display according to the received XML information. For example, in the case of music content, it is displayed as a list consisting of song names, artist names, playback times, etc. corresponding to a plurality of music held by the server.
【0074】
Next, in step S14, the client selects a song to be received and played from the server in the client device, specifies a content URL as content specification information, and transmits the song to the server. In step S15, the server acquires the content from the storage means based on the received content designation information and transmits the content. In step S16, the client plays the content received from the server. If the content is compressed by ATRAC, MPEG, etc., the content is decrypted on the server or client side, and then transmitted or played back.
【0075】
The normal content reproduction procedure is as described above. The client acquires various content attribute information, that is, property information contained in the metadata corresponding to the content held by the server, displays the UI such as the content list on the client based on the property information, selects the content, and the server. Can be requested.
【0076】
[Access restrictions based on content password]
As described above, the client makes a browse (view) or search (search) request to the server, and the content information held by the server corresponding to the content such as the content name, artist name, recording date, etc. of the content from the server. Acquires (metadata), selects playback content based on the acquired content information, sends a content request to the server, acquires the actual content, that is, actual data such as music and images from the server, and on the client side. It can be played and output.
【0077】
However, a large amount of content is stored in a server that can be accessed by a plurality of users. In such a server that can be accessed by a plurality of users, it is preferable to have a content management configuration in which access authority is given to each user to each content or the content folder of the content set. The access restrictions based on the content password will be described below.
【0078】
As explained earlier with reference to FIG. 3, the content management server that provides the content to the client manages a large amount of content based on the tree-shaped content directory.
【0079】
In the access restriction configuration of the present invention, passwords corresponding to individual elements (objects) set in the content directory, that is, items and containers in the directory are set. This is called an element password. Also, set a password for the entire content directory (CDS database). This is called the database password.
【0080】
An example of setting a password associated with a content directory will be described with reference to FIG. Content and metadata as attribute information corresponding to the content are managed by the content directory service (CDS) in the server based on the content directory having a tree structure as shown in FIG. This directory structure is stored in the storage unit in the server, and the data processing unit in the server receives and updates the content entity (resource) and content information (metadata) based on the directory structure from the client. Performs processing based on the request.
【0081】
The server has a password authentication processing unit, and determines whether or not the processing can be executed based on the request from the client by the authentication processing to which each of the above passwords is applied. As described above, the password applied to the authentication is the element password set corresponding to the object (container, item) which is an individual element in the content directory and the database password set in the entire content directory.
【0082】
The password (database password) 361 for the entire content directory (CDS database) is set as the metadata of the root container 351 which is the top-level object of the content directory set in the database.
【0083】
Database passwords can be used to add, delete, move, copy objects (containers, items) to a directory, store, delete, copy, move, and store or delete content entities (resources) to objects (containers, items) in a directory. It is applied to the permission confirmation when updating the metadata such as storing, deleting, copying, and moving the metadata (content information) corresponding to the item.
【0084】
When executing these processes, the client presents the database password to the server, authenticates based on the database password on the server, and confirms the processing authority. When the client executes each of the above processes, the condition is that the authentication based on the database password is established. If there are objects for which element passwords are set in the objects in the processing target area in the content directory, authentication based on the element passwords of those objects is required. The details of the processing will be described later.
【0085】
The element password is a password set corresponding to each object (container, item) constituting the directory, and is stored in the metadata corresponding to the container or item. The element password is a password set for each object of the container and item, such as the element password 362 for the container A352 and the element password 364 for the item Aa354, and corresponds to the object for which the element password is set. It is applied to the judgment of the processing authority and the processing authority for the subordinate object of the object for which the element password is set. Details of the processing restrictions will be described later.
【0086】
It should be noted that the setting and non-setting of the password are arbitrary. For example, the container C353 is a container in which the password is not set. Item Ac355 is an item for which no password is set. For an object for which a password has been set, a password is set in the metadata corresponding to the object, and password authentication is required in various processes only when the password is set.
【0087】
The contents of the processing restrictions corresponding to each password will be described with reference to FIG. 7. As mentioned above, the password type is set for each container and item, and is set as the element password stored as the metadata of each container and item, and as the metadata of the root container, and is set for the entire database. There is a database password for processing restrictions.
【0088】
The element password is used to check the read permission of the content entity of the object for which the element password is set, and if the object for which the element password is set has a child container or child item as a child object, the element password is used. Is applied to the read permission check of the content information (metadata) corresponding to the child object of the set object.
【0089】
In addition, the database password is applied to the confirmation of processing authority for the entire database, and the write authority confirmation set corresponding to the authority for adding, deleting, moving, copying, and updating the object, content entity, and content information. The password.
【0090】
The explanation will be given from the top category in Fig. 7. The element password set for the item is set according to the authority for the item, that is, the content reproduction process and acquisition process. When the client executes a request to play or acquire the item-compatible content to the server, the client presents the item-compatible element password to the server, authenticates the element password on the server, and the server performs the password. Allows and executes the client to play or acquire the item-compatible content on condition that the authentication is successful.
【0091】
Although details will be described later, when executing a playback or acquisition request for item-compatible content to the server, an element password is set for the upper object (container) on the route from the item's parent container to the root. In this case, regardless of the presence or absence of the element password corresponding to the item, the presentation and authentication of the element password of the upper object (container) on the route from the parent container to the root are also required.
【0092】
Element passwords for container have two categories as restriction processing. One is the restriction processing for the child objects (child containers, child items) of the container, and the other is the restriction processing for the corresponding contents of the container itself.
【0093】
First, as a restriction on the child of the container, there is an execution restriction of browsing (browsing) and searching (searching) of the child object of the container. The client presents the element password corresponding to the container to the server, and browses the content information (metadata) such as the child container or child item of the container in which the element password is set, provided that the password authentication is established on the server. It can be obtained by (browsing) or searching (searching). If the element password authentication corresponding to the container is not established, the content information such as the child container or child item of the container in which the element password is set cannot be obtained by browsing (browsing) or searching (searching).
【0094】
For example, the child objects for container 352 in Figure 6 are items Aa ~ Ac, and if the client performs a browse or search and does not present the element password 362 for container 352 to the server, then container 352. Information on items Aa to Ac, which are child objects for, that is, various content information contained in the metadata cannot be acquired.
【0095】
The directory example shown in Fig. 6 shows an example in which the root container, container, and item are each configured in one stage, but the container may be set in multiple stages, and the child container is used for the parent container. A series of multiple layers can be set, such as a grandchild container.
【0096】
When acquiring the content information corresponding to the container and item in the content directory, authentication based on all element passwords of the upper container on the route from the object (container, item) for which the content information is to be acquired to the root is established. There is a need to.
【0097】
For example, in the directory structure shown in FIG. 8, in order for the client to obtain the content information of the item Aaa373 and the item Aab374 based on browsing (browsing) or searching (searching), the client requires the element password 381 of the container A371. It is necessary to present two passwords, the element password 382 of the container Aa372 and the element password 382 of the container Aa372, to the server for authentication.
【0098】
When acquiring the content entity (resource) instead of the content information (metadata) of item Aaa373, that is, when playing or acquiring the content corresponding to item Aaa373, the client not only the element password of the item but also the element password of the item. , It is necessary to present the element password of the upper container to the server and to authenticate all the passwords by the server.
【0099】
That is, in order to acquire and play the content entity (resource) corresponding to the item, [element password corresponding to the item + all element passwords set in the upper object on the route from the item to the root] is presented and authenticated. Is required, and in order to acquire the content information (metadata) corresponding to the item, it is not necessary to present the element password corresponding to the item and authenticate, and [Set as a higher-level object on the route from the item to the root. All element passwords] must be presented and authenticated.
【0100】
In addition, as a restriction process of the second category of the element password of the container, there is a restriction process for the corresponding contents of the container itself. As shown in FIG. 7, when the container contains a content entity (resource), the element password of the container is applied when determining the authority to play or acquire the stored content. If the element password authentication corresponding to the container is not established, the playback and acquisition of the content entity (resource) corresponding to the container for which the password is set is not allowed.
【0101】
This relationship is similar to the relationship between items and element passwords corresponding to items. Therefore, if there is an element password corresponding to the upper object on the route from the container including the content entity to the root, when acquiring and playing the container-compatible content, not only the container-compatible element password but also the upper level Presenting the element password corresponding to the object and authentication are also required.
【0102】
As described above, the element password corresponding to the item is applied to the acquisition of the content corresponding to the item and the determination of the playback authority, and the element password corresponding to the container is the content information of the container and its lower objects (container and item). Judgment of viewing authority of (metadata), acquisition of content entity (resource) of lower objects (containers and items), determination of playback authority, and if the container itself contains content entity (resource), the container itself It is applied to the acquisition of the contained content entity (resource) and the judgment of the playback authority.
【0103】
The element password set corresponding to the item and the container needs to be presented and authenticated not only in the above-mentioned processing but also in the processing to which the database password described below is applied.
【0104】
Next, the database password will be described. The database password is a password for restricting the update of data in the database, and is set to restrict the processing corresponding to the entire content directory.
【0105】
There are three restrictions on processing. First, the first restriction mode is restriction on update processing of the content entity such as addition, deletion, movement, and copying of the content entity (resource). When adding, deleting, moving, or copying a content entity (resource) to a container or item in a content directory with a database password, the client presents the database password to the server and the server It is necessary to establish authentication based on the database password.
【0106】
If an element password is set for an object such as a container or item to be added, deleted, moved, or copied, it is necessary to present and authenticate [database password + element password corresponding to the object]. Is.
【0107】
Furthermore, if an element password is set for a higher-level object on the route from the object such as the container or item to be added, deleted, moved, or copied to the root, [database password + element password corresponding to the object] + (All element passwords of higher-level objects on the route from the object to the root)] must be established.
【0108】
Further, the second processing restriction mode of the database password is the processing restriction of the process of creating, deleting, moving, and copying an object such as a container or an item in the content directory, that is, the object update process. When the client creates, deletes, moves, or copies objects such as containers and items to the directory for which the database password is set, it presents the database password to the server. , It is necessary that password authentication is established.
【0109】
When creating, deleting, moving, or copying a container or item in the content directory, even if element passwords are set for the object such as the container or item to be processed, presenting these element passwords, No authentication is required. However, if the element password is set for the upper object on the route from the parent object (parent container) directly connected to the processing target object to the root, [Database password + (from the parent object directly connected to the processing target object to the root) It is necessary to establish authentication based on [all element passwords of higher-level objects on the route)].
【0110】
Further, the third processing restriction mode of the database password is the update processing restriction of the content information (metadata) corresponding to the container and the item in the content directory. When the client executes the update process of the metadata corresponding to the container or item in the directory in which the database password is set, it is necessary to present the database password to the server and establish the password authentication.
【0111】
If an element password is set for an object such as a container or item for which metadata is to be updated, such as adding, deleting, moving, copying, etc. of content information (metadata), [database password + corresponding to the object] Element password] must be presented and authenticated.
【0112】
Furthermore, if the element password is set for the upper object on the route from the object such as the container or item to which the metadata is updated, such as adding, deleting, moving, copying, etc. of the content information (metadata) to the root, the element password is set. It is necessary to establish authentication based on [database password + element password corresponding to the object + (all element passwords of higher-level objects on the route from the object to the root)].
【0113】
In this way, the server authenticates the password group consisting of the password presented by the client or the Fukusuuno password in response to the request from the client, and determines whether or not the request processing of the client is permitted.
【0114】
The server in the present invention stores the content entity (resource), the content information (metadata), and the content directory as the content management configuration in the storage unit, and sets each object as each component of the content directory. The element password to be created and the database password set for the entire content directory are stored in the storage as object-compatible metadata, and the password received from the client and the storage stored in the storage when various processing requests from the client are received. The password verification is executed in the password authentication processing unit, and the request processing of the client is executed in the data processing unit on condition that the password authentication is established.
【0115】
The data processing unit of the server determines the processing allowable area from the entire content directory based on the password for which password authentication is established in the password authentication processing unit, and when the client request processing can be executed within the determined processing allowable area, Execute client request processing.
【0116】
The client request processing is content acquisition, playback request, browse (browsing), search (search) request, content entity update, content information update, object (container, item) update request, or the like. ..
【0117】
About password application processing example in content information acquisition based on browsing (browsing), search (search), object generation, and other processing of content managed by the content directory in the CDS (content directory service) in the server This will be described with reference to FIG. Figure 9 (A) shows an example of database configuration in the server, and Figure 9 (B) shows the process requested by the client, the type of password presented by the client and the authentication process is executed by the server, and the description of the process. The correspondence table of is shown.
【0118】
In FIGS. 9A and 9B, each of the processes a to h is a corresponding process. In FIG. 9A, there are a folder A412 and a folder B413 as lower containers of the root container 411, and a folder C414 is set as a lower container of the folder B413. Item W415 and item X416 are set under the folder A412, item Y417 is set under the folder B413, and item Z418 is set under the folder C414.
【0119】
Also, pwd-R is set as the database password, element password pwd-A for folder A412, element password pwd-C for folder C414, element password pwd-W for item W415, and element password pwd-Y for item Y416 are set as element passwords. Has been done. It is assumed that no element password is set for other containers and items.
【0120】
The processing a to h of the table shown in (B) will be described. Process a is a process when the client requests the server to play or acquire the corresponding content of the item Y416. In this case, the client presents the element password pwd-Y for the item Y416 to the server and the element password. It is necessary to perform authentication based on the pwd-Y password. Since the element password is not set in the upper container of item Y416, folder B413, the client presents only the element password pwd-Y for item Y416 to the server and authenticates based on the element password pwd-Y. You can play or get the corresponding content of item Y416 with.
【0121】
However, for example, when the client requests the server to play or acquire the corresponding content of the item W415, the client not only requests the element password pwd-W for the item W415 but also the route from the item W415 to the route 411. It is necessary to present the higher-level object, that is, the element password pwd-A set in the folder A412 to the server, and perform authentication based on the element password pwd-Y + element password pwd-A.
【0122】
That is, when the client presents only the element password pwd-Y for the item Y416 to the server, the folder A area 401 set as the area under the folder A412 in which the element password pwd-A is set is excluded from the processing allowable area. Similarly, the folder C area 402 set as the area under the folder C414 in which the element password pwd-C is set is also excluded from the processing allowable area.
【0123】
If the client presents the element password pwd-W for item W415 and the element password pwd-A set in the folder A412 to the server, the server will use the area under the folder A412 in which the element password pwd-A is set. The folder A area 401 set as is determined to be the processing allowable area, and the process of responding to the playback or acquisition request of the corresponding content of the item W415 of the client is executed.
【0124】
In this way, the password authentication processing unit of the server executes the password authentication processing based on the collation between the password received from the client and the stored password stored in the storage unit in the server, and the data processing unit of the server performs the password authentication processing. In the department, the processing allowable area is determined from the entire content directory based on one or more passwords for which password authentication is established, and when the processing requested by the client can be executed within the determined processing allowable area, the request processing of the client is performed. To execute.
【0125】
Process b is a browse process of the root container 411. The browsing process is the process of acquiring the content information of the container and the item of the directory in the database, that is, the process of acquiring the metadata of the content corresponding to the container or the item, for example, the process of acquiring the content information such as the content name and the artist name. .. The client outputs a browse request that specifies the object to be browsed to the server, presents the element password as necessary, and receives metadata provided on the condition of server authentication.
【0126】
The server that receives the browse (browsing) request specifying a specific container or item from the client performs the necessary password authentication, and provides the content information (metadata) to the client on condition that the authentication is established.
【0127】
Process b is a browse request process for the root container. The database password pwd-R is set in the metadata of the root container to restrict processing such as writing data to the database, but since there is no element password set, the client must present the password and perform authentication processing. The metadata (content information) corresponding to the root container 411 can be obtained from the server without the above. The metadata corresponding to the root is information including directory configuration information, setting information of lower-level containers, and the like.
【0128】
Process c is an example when the client executes a browse request for folder A412 to the server. In this case, the client needs to execute a browse request to the server that presents the element password pwd-A. Upon a browse request that presents the element password pwd-A, the client sets the restriction of viewing authority by the element password pwd-A corresponding to the folder A412. Folder A412, item W415, which is included in the folder A area 401. You can get the content information of item X416.
【0129】
The password pwd-W is also set for item W415, but the password pwd-W for item W415 is required to be presented when reading or retrieving the content entity of item W415, but it is not the content entity but the content. It is not necessary to present the element password corresponding to the item and authenticate to obtain the information (metadata).
【0130】
In order to acquire the content information (metadata) corresponding to the object, it is not necessary to present and authenticate the element password of the object, and it is necessary to present and authenticate the element password of the upper object of the route from the parent object of the object to the root. It becomes. The element password of the object of the route from the parent object of the item W415 to the root is the element password pwd-A of the folder A412, and when acquiring the content information of the item W415, the element password pwd-A of the upper container is presented. , Authentication is required.
【0131】
If the element password pwd-A is not presented by the client when requesting content information acquisition based on browse (browsing) or search (search) from the client, or if authentication based on the element password pwd-A is not established, the server will use the server. , Judges that the client does not have the authority to acquire the content information of the folder A412, item W415, and item X416 included in the folder A area 401, and provides the client with the content information of the object included in the folder A area 401. Do not execute the process.
【0132】
In the example of FIG. 9 (A), the element password pwd-A is set in the folder A412, and the information of the containers and items under the folder A412 is not provided to the client unless the element password pwd-A is presented and authenticated. .. Since the element password is not set in the folder B413, the content information of the lower item Y417 of the folder B413 is provided to the client even when the client requests to browse the folder B without the password. To. The element password pwd-C is set in the folder C414, and the information of the containers and items under the folder C414 is not provided to the client unless the element password pwd-C is presented and authenticated.
【0133】
The password pwd-Y is set for item Y417. The password pwd-Y of item Y417 is required to be presented when reading and acquiring the content entity of item Y417, but it is necessary to present the element password corresponding to the item to acquire the content information, not the content entity. Not done. Similarly, the metadata corresponding to the folder C414 is also provided to the client without setting the password because the element password is not set in the upper object folder B413.
【0134】
In order to acquire the content information of the object in the folder A area 401 shown in FIG. 9A, that is, the lower container and the lower item of the folder A412, it is necessary to present and authenticate the element password of the folder A412. In order to acquire the content information of the objects included in the folder C area 402 shown in FIG. 9B, that is, the lower containers and items of the folder C414, it is necessary to present and authenticate the element password of the folder C414.
【0135】
Process d is an example when the client executes a browse request for folder B413 to the server. Since no element password is set for the folder B413 and the upper objects on the route from the folder B413 to the root 411, the metadata (content information) of the folder B413 is based on the browse (view) request without the password. Provided to Cryaton.
【0136】
Processing e. In search, the client specifies various information such as the artist name and recording date included as content information in the metadata corresponding to the container and item, and the object (container, item) including the client-specified information. ) Is the process of acquiring the content information corresponding to) from the server.
【0137】
In this search process, the search range is determined based on the password presented by the client and authenticated by the server. The data processing unit of the server determines the search processing area from the entire content directory based on the password for which password authentication has been established in the password authentication processing unit of the server, and executes the search processing requested by the client in the determination processing area. Become.
【0138】
Process e1 is a process when the client sends a search request to the server without presenting the password. Since the search can be executed without specifying a specific container or item, e1 to e3 are not specified in FIG. 9 (A).
【0139】
If the client sends a search request to the server without presenting the password, the server will only accept objects for which no element password has been set in the upper container in the shared area 400 that defines the entire content directory area of the database. Set as an object that allows the provision of content information to. That is, the folder A412, the folder B413, the folder C414, and the item Y417 are objects for which the element password is not set in the upper container, and these are set as the content information provision allowable objects for the client.
【0140】
When the server receives a passwordless search request from the client, it searches for objects in the shared area 400 that do not have an element password set in the upper container, namely folder A412, folder B413, folder C414, and item Y417. The search process is selected, these are set as the search range, and the content information acquired as the search result is provided to the client.
【0141】
The process e2 is a process when the client sends a search request for presenting the password pwd-A corresponding to the folder A412 to the server. When the client sends a search request with the password pwd-A to the server and the password pwd-A is authenticated, the server sends the object for which the element password is not set in the upper container and the folder A area 401. Set the included object as an object that allows the provision of content information to the client. That is, the folder A412, the folder B413, the folder C414, and the item Y417, and the item W415 and the item X416 included in the folder A area 401 are set as the content information provision allowable objects to the client.
【0142】
The server receives the search request presenting the password pwd-A from the client, and if the password authentication is successful, it is included in the folder A412, the folder B413, the folder C414, the item Y417, and the folder A area 401 as search targets. Item W415 and item X416 are selected, the search process in which these are set as the search range is executed, and the content information acquired as the search result is provided to the client.
【0143】
The process e3 is a process when the client sends a search request to the server presenting the password pwd-A corresponding to the folder A412 and the password pwd-C corresponding to the folder C414. When the client sends a search request with passwords pwd-A and pwd-C to the server and the server authenticates with passwords pwd-A and pwd-C, the server sets the element password in the upper container. The objects that are not set, the objects included in the folder A area 401, and the objects included in the folder C area 402 are set as the allowable objects for providing the content information to the client. That is, the folder A412, the folder B413, the folder C414, and the item Y417, the item W415 and the item X416 contained in the folder A area 401, and the item Z418 contained in the folder C area 402 are set as the content information provision allowable objects to the client. ..
【0144】
The server receives the search request from the client presenting the passwords pwd-A and pwd-C, and if password authentication is successful, the search target is folder A412, folder B413, folder C414, item Y417, and folder A area. Item W415 and item X416 included in 401, and item Z418 included in folder C area 402 are selected, the search process with these set as the search range is executed, and the content information acquired as the search result is provided to the client. It will be.
【0145】
The processing of f to h in FIG. 9B is an example of processing in which the database password is applied. Object update processing such as object creation, deletion, movement, copy, content entity (resource) update processing such as addition, deletion, movement, copy of content entity to the object, or content information (metadata) corresponding to the object. When executing any of the content information (metadata) update processing such as addition, deletion, movement, and copying of), the database password and the route from the processing target object and the parent object of the processing target object to the root. It is necessary to present and authenticate the element password of the above object.
【0146】
Process f is an example of a process that involves writing data to the shared space 400, that is, an example of creating an object in the shared space 400. The shared space 400 does not include the folder A space 401 and the folder C space 482.
【0147】
To create an object in the shared space 400 that does not include the folder A space 401 and the folder C space 482, only the database password pwd-R must be presented and authenticated.
【0148】
The process g is an example of writing data to the folder A space 401, that is, creating an object in the folder A space 401. When creating an object in the folder A space 401, it is necessary to present and authenticate the database password pwd-R and the element password pwd-A of the folder A372.
【0149】
The process h is a process of setting the content entity corresponding to the item W375 in the folder A space 401 as the content of the folder C374 or as a lower object (lower item) of the folder C374. In this case, it is necessary to present and authenticate the database password pwd-R, the element password pwd-A of the folder A372, and the element password pwd-C of the folder C374.
【0150】
The processing for the item for which the element password is set, the container for which the element password is set, and the database for which the database password is set will be collectively described below.
【0151】
(1) Item for which element password is set 1a. When the client acquires the content entity (resource) from the server, the server asks the client to present the element password, and the server executes authentication. If no password is presented or an authentication error occurs, content acquisition and play (get / play) requests will not be accepted. Furthermore, it is necessary to present and authenticate the element password set in the upper object on the route from the item to the root in the content directory.
【0152】
1b. It is not necessary to present the element password corresponding to the item and authenticate to acquire the content information (metadata) corresponding to the item. The element password corresponding to the item is not required for browsing (browsing) and searching (browse / search) when retrieving the metadata of the item. In order to acquire the content information (metadata) corresponding to the item, it is necessary to present and authenticate the element password set in the upper object of the route from the item to the root in the content directory.
【0153】
1c. In order to update or delete the content entity (resource) corresponding to the item, it is necessary to present and authenticate both the element password corresponding to the item and the database password. Furthermore, it is necessary to present and authenticate the element password of the upper object set in the container of the route from the item to the root in the content directory.
【0154】
1d. Deletion of the item itself does not require the presentation and authentication of the element password corresponding to the item, but the database password and the element password set for the upper object on the route from the item to the root must be presented and authenticated. ..
【0155】
(2) Container with element password 2a. The client acquires the metadata (content information) of the lower objects (containers, items) of the container with the element password, for example, browse (view), search (search), etc. Therefore, when acquiring the metadata of the object under the container, it is necessary to present the element password corresponding to the container and authenticate. That is, the requirement for acquiring the corresponding metadata of a certain object (container, item) is to present the passwords of all the elements of the upper object on the route from the parent object directly connected to the object to acquire the metadata to the root, and to establish the authentication. is there.
【0156】
2b. When acquiring the content entity (resource) corresponding to the container itself, the server requires the client to present the element password corresponding to the container, and the server executes the authentication. If no password is presented or an authentication error occurs, content acquisition and play (get / play) requests will not be accepted. This is the same function as 1a, the element password corresponding to the item mentioned above. If element passwords are set for the parent object on the route from the container to the root for which the content entity (resource) is to be acquired, it is also necessary to present and authenticate these element passwords.
【0157】
2c. To acquire the content information (metadata) corresponding to the container, the element password set in the upper object of the route from the parent object to the root of the container for which the content information (metadata) is to be acquired in the content directory. Presentation and authentication are required.
【0158】
2d. In the update process (addition, deletion, move, copy) of the content entity (resource) corresponding to the container, it is necessary to present and authenticate both the element password corresponding to the container and the database password. Furthermore, it is necessary to present and authenticate the element password set in the upper object of the route from the parent object to the root.
【0159】
2e. Deletion of the container itself does not require presentation and authentication of the element password corresponding to the container, and presentation and authentication of the database password and the element password set in the upper object of the route from the parent object of the container to be deleted to the root. Is required. The container must be empty, that is, the child object does not exist. If a child object exists, the delete cannot be performed. Therefore, if there are child objects, it is necessary to delete the container in order from the lowest level object.
【0160】
(3) Database with database password 3a. For update processing including addition, deletion, movement, and copying of content information (metadata) of objects (containers, items), it is necessary to present the database password and establish authentication. .. It is necessary to present and authenticate all element passwords and database passwords of higher-level objects from the parent container to the root of the object to which the metadata to be updated corresponds.
【0161】
3b. The database password must be presented and authentication must be established for the update process including addition, deletion, movement, and copying of the content entity (resource) corresponding to the object in the database. It is necessary to present and authenticate the element password of the object corresponding to the content entity (resource) to be updated, all the element passwords of the upper object from the parent container of the object to the root, and the database password.
【0162】
3c. When creating a child object in a ready-made object in the database or deleting a ready-made child object, it is necessary to present the database password and establish authentication. It is necessary to present and authenticate all element passwords and database passwords of higher-level objects from the parent object to the root of the processing unit that creates and deletes child objects.
【0163】
If a child object exists in the container, it cannot be deleted. Therefore, if there are child objects, it is necessary to delete the container in order from the lowest level object. The process is the same as 2e described above.
【0164】
3d. When moving or copying an off-the-shelf object in the database, it is necessary to present the database password and establish authentication. Presentation and authentication of all element passwords and database passwords of higher-level objects from the parent object to the root of the move source and move destination, or both the copy source and copy destination processing parts, which are the processing units that execute moving and copying of existing objects. Is required.
【0165】
FIG. 10 shows a diagram summarizing a combination of passwords required for processing an object's content entity (resource), processing content information (metadata), and processing a child object.
【0166】
The object to be processed may be a container or an item. For acquisition and playback of container-compatible or item-compatible content entities (resources), the element password of the object (container or item) is presented and authenticated, and the upper object on the route from the parent object of the object to the root is supported. Element password presentation and authentication are required, and database password presentation and authentication are not required.
【0167】
Updating a container-aware or item-aware content entity (resource), that is, adding, deleting, moving, or copying, does not require the presentation or authentication of the element password of the object (container or item), and the object (container or item). It is necessary to present and authenticate the element password set in the upper object on the route from the parent object (parent container) of the item) to the root, and the database password.
【0168】
In the case of moving or copying the content entity (resource), the move source and move destination, or the two objects of the copy source and copy destination, and the parent object (parent container) of the two objects lead to the root. It is necessary to present and authenticate the element password set in the upper object on the route.
【0169】
Acquisition of container-compatible or item-compatible metadata (content information), for example, viewing metadata by browsing (browsing) or searching (searching) does not require the presentation and authentication of the element password of the object (container or item). Yes, it is necessary to present and authenticate the element password set in the upper object from the parent object (parent container) of the object (container or item) to the root, and it is not necessary to present and authenticate the database password.
【0170】
To update the metadata (content information) for containers or items, that is, to add, delete, move, or copy metadata (content information), the element password of the object (container or item) and the object (container) Or the element password set in the container from the parent object of the item) to the root, and all the database passwords must be presented and authenticated.
【0171】
In the case of moving or copying content information (metadata), move source and move destination, or copy source and copy destination two objects, and the parent object (parent container) of the two objects to the root. It is necessary to present and authenticate the element password set for the upper object on the route.
【0172】
When the processing target is the object itself, that is, the object update processing such as adding (creating), deleting, moving, copying, etc. of the child container or child item, it is set as the upper object on the route from the parent object of the processing execution area to the root. It is necessary to show the element password and authenticate.
【0173】
In the case of object movement and copy processing, the element set as the upper object on the route from the parent object (parent container) of the two corresponding objects, the move source and the move destination, or the copy source and the copy destination, to the root. You will need to show your password and authenticate.
【0174】
[Password information storage configuration in object metadata]
The database password and element password described above are stored in the metadata of the object, respectively, and in the password authentication process executed on the server, verification with the password presented by the client is executed.
【0175】
The database password is stored in the metadata set for the root container of the content directory. The element password is stored in the metadata of each corresponding object (container, item).
【0176】
As described above, when the content entity (resource) is acquired or the content information (metadata) is acquired, the content entity (resource) or an element of a higher-level object other than the object corresponding to the content information (metadata). Matching with the password is required. The server has the configuration information of the content directory, and it is possible to obtain the necessary password information from the metadata of each object and collate it based on the configuration information of the content directory, but it is a lower-level object in advance. The password information set in the upper object may be stored in the metadata of, and all the information of the password required for collation may be obtained from the metadata of one object without tracing the directory.
【0177】
An example of storing password information in metadata will be described with reference to FIGS. 11 and 12. Figure 11 (a) shows an example in which only the element password corresponding to the object is stored as metadata. In this configuration, when authentication (verification processing) by the element password corresponding to the upper object is required, the server identifies the upper object based on the content directory configuration information and each element from the metadata of each upper object. Obtain the password and match it with the password received from the client.
【0178】
FIG. 11 (b) shows a configuration in which the element password corresponding to the object and the correspondence information between the identifier of the upper object of the route from the object to the root and the element password are stored. This is an example in which all the pairs of the element password (abc00123) corresponding to the object, the identifier of the upper object (container-c01, c02) and the corresponding element password (cda12356, dea78533) are stored in the metadata. In this configuration, the server acquires the element password of the upper object from the metadata of one object and receives it from the client even when authentication (verification processing) by the element password corresponding to the upper object is required. It is possible to perform matching with.
【0179】
FIG. 12 (c) shows a configuration in which the element password corresponding to the object and the element password of the upper object of the route from the object to the root are stored in the metadata. This is an example in which the element password (abc00123) corresponding to the object and each element password (cda12356, dea78533) of the upper object are all stored in the metadata. Even in this configuration, the server acquires the element password of the upper object from the metadata of one object and receives it from the client even when authentication (verification processing) by the element password corresponding to the upper object is required. It is possible to perform verification with the password.
【0180】
FIG. 12 (d) shows a configuration in which the element password corresponding to the object and the position information of the object having the element password on the route from the root to the object are stored in the metadata. The element password corresponding to the object (abc00123) and the position information (01011) of the object having the element password on the route from the root to the object are stored in the metadata.
【0181】
01011 is the element password setting identification information set as 1 when the object on the route from root 501 to item 506 has an element password and 0 when the object does not have an element password in the directory structure shown in FIG. The metadata in FIG. 12 (d) is the metadata corresponding to item 506, the element password of the item is (abc00123), and 01011 has root 501 = 0 (no element password set) and container 502 = 1 (element). Indicates that container 503 = 0 (without element password setting), container 504 = 1 (with element password setting), and container 505 = 1 (with element password setting).
【0182】
In this configuration, when authentication (verification processing) by the element password corresponding to the upper object is required, the server obtains the position information (01011) of the object for which the element password is set from the metadata having the configuration shown in FIG. 12 (d). It is possible to acquire and identify the object having the element password based on this position information, and it is possible to acquire the corresponding element password from the metadata of the identified object. According to this configuration, the server does not need to examine the metadata of all higher-level objects, and efficient processing is possible.
【0183】
[Server-client processing sequence with password authentication]
Next, a processing sequence involving password authentication between the server and client will be described. FIG. 13 shows a sequence diagram. The server is, for example, a content management server that executes content management by a content directory service (CDS), and provides a content entity (resource) and content information (metadata) based on a request from a client. .. The provision of content information (metadata) is executed based on the browse (browsing) and search (search) requests from the client, and the provision of the content entity (resource) is, for example, a content request specifying the content URL as the content identifier. Executed based on (eg HTTP-GET). Furthermore, the client requests the server to update the content entity, content information, and objects (containers, items), that is, add, delete, move, copy, etc., and the server makes a processing request based on the processing request, and the content directory. Update the management data by the service (CDS). Each of these processes is performed on condition of password authentication as necessary.
【0184】
In step S101, the client sends a processing request to the server. This processing request is either a content acquisition, playback request, or browse (view), search (search) request, or content entity update, content information update, or object (container, item) update request. Is.
【0185】
In response to the processing request from the client, the server determines whether or not authentication of the password, that is, the database password or element password described above is required as the processing execution condition, and when the processing requires password input. , In step S102, the password input request is sent to the client.
【0186】
In step S103, the client sends one or more passwords to the server based on the password input request from the server. As described above, in the acquisition of the content entity or the content information and other processing, it may be necessary to present the element password of the higher-level object of the content entity or the object corresponding to the content information, and the data is updated. In this case, it is necessary to present the database password to the server and be authenticated, so that the client sends a plurality of passwords to the server as needed.
【0187】
The password is sent by using the object identifier and the corresponding element password as a set, for example, [Folder A, pwd-A; Folder B, pwd-B; Folder C, pwd-C ...]. The set data of is transmitted as sequential information. The transmission information may be binary data or may be converted into ASCII code and transmitted.
【0188】
In step S104, the server sequentially acquires each object identifier and the corresponding element password from this sequential information, and uses the password read from the object-corresponding metadata described above with reference to FIGS. 11 and 12. The collation process will be performed. If even one of the required passwords is missing or the verification is unsuccessful, it is determined that the password authentication is unsuccessful, the processing request from the client is not executed, and the authentication result notification in step S105 is a notification that an authentication error has occurred. I do.
【0189】
If all the passwords are successfully verified, the notification of authentication establishment is executed in step S105, the processing for the processing request from the client is executed in step S106, and the processing result is transmitted to the client.
【0190】
For example, when the request from the client is the acquisition of the content information by browsing (browsing) or searching (searching), the content information is transmitted to the client when the password authentication is established.
【0191】
Figure 14 shows an example of content information sent to the client. The content information shown in FIG. 14 indicates content information corresponding to a plurality of contents, and is information acquired by browsing (browsing) a container having a plurality of items, for example.
【0192】
Content information 521 is displayed on the client display 520. The password necessity information field 522 is set in the content information, and the key mark is shown when the password is required to be acquired to acquire the content, and the key mark is not indicated when the content does not require the password to be acquired to acquire the content. Here is an example of the setting. For the content No. 0001, a key mark is shown in the password necessity field 523, and it is clearly indicated that the password must be entered to acquire the content. In the content No. 0002, the key mark is not shown in the password necessity field 523, and it is clearly indicated that the password does not need to be entered to acquire the content.
【0193】
The client receives the XML data generated by the server based on the metadata corresponding to the object, and the UI generator on the client side generates these display information based on the received XML data. The example shown in FIG. 14 is one display example, and various display modes can be set in addition to this.
【0194】
For example, when the client acquires the content of the content No. 0001, it is necessary to send the element password or the element password set necessary for playing and acquiring the content No. 0001 to the server.
【0195】
Regarding the process to which the password is applied, the process to be executed on the server side and the client side will be described with reference to each flow.
【0196】
First, the processing on the server side will be described with reference to FIG. In step S201, the processing request from the client is received. This processing request is either a content acquisition, playback request, or browse (view), search (search) request, or content entity update, content information update, or object (container, item) update request. Is.
【0197】
In step S202, the server determines whether or not the above-mentioned database password or element password authentication is required as an execution condition of the process from the client. If password authentication is not required, the process proceeds to step S207 to execute the request processing from the client.
【0198】
If it is determined that the password input is required, the password input request is transmitted to the client in step S203.
【0199】
If the password is not received in step S204, an error notification is sent to the client in step S208 to end the process.
【0200】
If the password is received in step S204, the server executes the password authentication process in step S205. The password consists of sequential information of the set data of the object identifier and the corresponding element password, for example, [Folder A, pwd-A; Folder B, pwd-B; Folder C, pwd-C ...]. , The server sequentially acquires each object identifier and the corresponding element password from this sequential information, and performs a collation process with the password read from the object-corresponding metadata described above with reference to FIGS. 11 and 12. Do.
【0201】
As a result of the verification process for the received password, if all the verifications of the passwords that are the execution conditions of the client request processing are satisfied, the authentication is established (step S206: Yes), and the client request processing is executed in step S207.
【0202】
As a result of the verification process for the received password, if all the verifications of the passwords that are the execution conditions of the client's request processing are not established, the authentication is not established (step S206: No), and in step S208, the client is notified. An error notification is sent and the process ends.
【0203】
Next, the processing on the client side will be described with reference to FIG. The client device that executes various processing requests to the content management server has a storage unit that stores all passwords entered by the user during the operation period of the server-using application.
【0204】
When transmitting a response to a processing request to the server or a password request from the server, the data processing unit of the client executes a process of setting all passwords stored in the storage unit as transmission data. Further, on condition that the server-using application is terminated, a process of erasing all passwords stored in the storage unit is executed. This configuration eliminates the need for the user to repeatedly enter the same password within the operating period of the server-using application, and enables efficient use of the server. The processing flow of FIG. 16 will be described.
【0205】
In step S301, the client launches an application that executes the usage processing of the content management server, and in step S302, the processing request to the server, that is, the content acquisition, playback request, or browse (browsing), search (search) request, Alternatively, it sends a request for updating the content entity, updating the content information, or updating the object (container, item).
【0206】
In step S303, the client determines whether or not the password input request from the server has been received, and if it does not receive the password input request from the server (step S303: No), it is an unnecessary process to input the password. Therefore, from the server in step S306. Receive the processing result of.
【0207】
When the password input request from the server is received (step S303: Yes), the password is input and sent to the server in step S305. In step S305, the input password is stored in memory. This means that while the application launched in step S301 is running, it may repeatedly perform processing on the same object, so when the input password is kept in memory and the client sends a new processing request to the server, the user Even if the password is not input by the user, the password stored in the memory is transmitted to reduce the time and effort of the user to input the password.
【0208】
In step S306, the processing result is received from the server. For example, in the case of browsing processing, the content information as shown in FIG. 14 is acquired. In step S307, it is determined whether or not there is a new processing request, and if there is a new processing, the memory storage password is added and transmitted to the server in step S310. When the processing execution condition is satisfied only by this memory storage password, the password input request from the server is not made, and the processing result can be received in step S306.
【0209】
For example, when the content information as shown in FIG. 14 is acquired by browsing (browsing) the parent container (with element password) having multiple content items as child objects, the client receives the element password of the parent container when acquiring the content information. Is stored in the memory, and in the content acquisition process, the password stored in the memory is added and the content acquisition / playback request is transmitted from the client to the server.
【0210】
Therefore, the user on the client side can acquire the content entity (resource) without entering the same password.
【0211】
If there is no new process in step S307, the application used by the content management server is terminated in step S308. In step S309, the user input password stored in the memory in step S305 is erased. This password erasure prevents the use of the password by other users or the leakage of the password to other users.
【0212】
[Functional configuration of server and client]
The hardware configuration of the server and client device is as described above with reference to FIG. 2, and the various processes described above are performed by the control unit (CPU, etc.) according to the program stored in the storage unit of each server and client. Is executed under the control of.
【0213】
For example, on the server side, the processing executed by the CPU extracts the container or item as an object based on the content directory according to the search (search) or browse (browsing) request from the client, and acquires the metadata corresponding to the object. The process of transmitting to the client, the process of transmitting the content entity according to the request from the client, the process of updating the object, the content entity, and the content information according to the request from the client, and the like. The processing on the client side includes the processing of sending a processing request to the server, the processing of setting password set information consisting of one or more passwords and sending it, and the process of generating display information to be presented on the display based on the content information received from the server. Processing, processing for receiving content, processing for reproducing received content, and the like.
【0214】
Basically, these processes are executed under the control of the CPU as the control unit of the server and client device, but the figure shows the functional configuration of the server and the functional configuration of the client required to execute the above-mentioned processes. This will be described with reference to 17 and FIG.
【0215】
FIG. 17 is a block diagram showing a main functional configuration of the server. The packet transmission / reception unit 601 receives a packet to the client and a packet from the client. The packet generation and analysis unit 602 performs transmission packet generation processing and reception packet analysis processing. Packet address setting, address recognition, data storage for the data part, data acquisition processing from the data part, etc.
【0216】
The storage unit 603 is a storage unit that stores the content held by the server and metadata (property information) as attribute information corresponding to the content. In the metadata, the password is stored in the manner described with reference to, for example, FIGS. 11 and 12. Further, the content storage unit 603 stores the content directory having a tree structure as the content management configuration, and sets the element password set for each object which is each component of the content directory and the entire content directory. The database password to be created is stored as metadata corresponding to each object.
【0217】
The metadata acquisition unit 604 executes a process of extracting the metadata corresponding to the specified folder from the metadata storage unit 604 based on the content information acquisition request received from the client, for example, a browse (view) or search (search) request. To do.
【0218】
The data processing unit 605 is a processing request from a client, that is, an acquisition of a content entity, a reproduction request, an acquisition of content information, that is, a browse (browsing), a search (search) request, a content entity, a content information, a container, an item, or an object. Update (add, delete, move, copy) process. However, when password authentication is used as an execution condition, it is a condition that password authentication is established.
【0219】
The password request and authentication processing unit 606 determines whether or not the processing request from the client requires password authentication, and executes a process of generating a password request to be output to the client when password authentication is required. , The password authentication process based on the verification process of the received password from the client and the password stored in the metadata storage unit 604 is executed.
【0220】
The data processing unit 605 executes the data processing requested by the client based on the password request and the establishment status of the password authentication in the authentication processing unit 606. For example, if the processing request from the client is a search (search) request, the search (search) processing allowable area in the content directory is determined based on the password authentication, and the search (search) is executed within the determined processing allowable area. To do.
【0221】
In addition, the request processing of the client is the acquisition of the content entity, the playback request, the acquisition of the content information, that is, the browse (browsing), search (search) request, the content entity, the content information, the container, the item, and the update (addition, (Delete, move, copy) In any of the processing requests of processing content acquisition and playback, the password request based on the password presented by the client and the processing allowable area are determined by the authentication processing unit 606, and the processing request from the client is received. In the case of processing for an object that is not included in the processing allowable area determined by password authentication, the data processing unit 605 does not execute the processing request from the client. When the processing request from the client is processing for the object included in the processing allowable area determined by password authentication, the data processing unit 605 executes the processing request from the client.
【0222】
The content information generation unit 607 generates XML data as content information based on the metadata acquired by the metadata acquisition unit 604. The data conversion unit 608 executes decoding processing such as encoding processing of transmitted content data. For example, perform data conversion based on ATRAC3 and MPEG4.
【0223】
Next, the functional configuration of the client device will be described with reference to FIG. The packet transmission / reception unit 701 executes packet transmission to the server and packet reception processing from the server. The packet generation and analysis unit 702 performs transmission packet generation processing and reception packet analysis processing. It includes not only analysis of stored data in packets, but also packet address setting, address recognition, data storage for the data section, data acquisition processing from the data section, and the like.
【0224】
The data processing unit 703 transmits various request data to be transmitted to the server, that is, acquisition of content entity, reproduction request, search (search) as acquisition request of content information, browse (browsing) request, content entity, content information. , Executes the process of generating the update request data of the object. Further, as a response to the password request from the server, a process of setting all the passwords stored in the storage unit 704 as transmission data is executed.
【0225】
The storage unit 704 stores the content entity included in the packet received from the server, the content information, and the like. It also functions as a storage unit for storing the user input password.
【0226】
When transmitting a processing request to the server or a response to a password request from the server, the data processing unit 703 executes a process of setting all passwords stored in the storage unit 704 as transmission data. Further, on condition that the server-using application is terminated, a process of erasing all passwords stored in the storage unit is executed. This configuration eliminates the need for the user to repeatedly enter the same password within the operating period of the server-using application, and enables efficient use of the server.
【0227】
The output unit 705 includes a speaker and a display applied to the content reproduction process. The display is also used for outputting the content information described above with reference to FIG. The input unit 706 is, for example, a keyboard for selecting playback content, inputting a password, content information, object update information, and the like, and other data input means.
【0228】
The content information analysis unit 707 analyzes XML data consisting of property information received from the server, generates the content information described above with reference to FIG. 14, for example, based on the analysis data, and displays it as an output unit. Execute the output process. The content playback control unit 708 executes playback processing of the content received from the server.
【0229】
The data conversion unit 709 executes various data conversion processes such as decryption processing of the content data received from the server. For example, perform data conversion based on ATRAC3 and MPEG4.
【0230】
The server and the client functionally have the functions shown in FIGS. 17 and 18, and execute each of the above-described processes. However, the block diagrams shown in FIGS. 17 and 18 are block diagrams for explaining the functions, and in reality, various processing programs are executed under the control of the CPU in the hardware configuration such as the PC shown in FIG. To.
【0231】
The present invention has been described in detail with reference to the specific examples. However, it is self-evident that a person skilled in the art can modify or substitute the embodiment without departing from the gist of the present invention. That is, the present invention has been disclosed in the form of an example, and should not be construed in a limited manner. In order to judge the gist of the present invention, the column of claims described at the beginning should be taken into consideration.
【0232】
The series of processes described in the specification can be executed by hardware, software, or a composite configuration of both. When executing processing by software, install the program that records the processing sequence in the memory in the computer built in the dedicated hardware and execute it, or execute the program on a general-purpose computer that can execute various processing. It can be installed and run.
【0233】
For example, the program can be pre-recorded on a hard disk or ROM (Read Only Memory) as a recording medium. Alternatively, the program may be temporarily or permanently placed on a removable recording medium such as a flexible disc, CD-ROM (Compact Disc Read Only Memory), MO (Magneto optical) disc, DVD (Digital Versatile Disc), magnetic disc, or semiconductor memory. It can be stored (recorded). Such a removable recording medium can be provided as so-called package software.
【0234】
In addition to installing the program on the computer from the removable recording medium as described above, the program can be transferred wirelessly from the download site to the computer, or transferred to the computer by wire via a network such as LAN (Local Area Network) or the Internet. , The computer can receive the program transferred in this way and install it on a recording medium such as a built-in hard disk.
【0235】
The various processes described in the specification are not only executed in chronological order according to the description, but may also be executed in parallel or individually as required by the processing capacity of the device that executes the processes. Further, in the present specification, the system is a logical set configuration of a plurality of devices, and the devices having each configuration are not limited to those in the same housing.
【0236】
[Effect of the invention]
As described above, according to the configuration of the present invention, the content directory having a tree structure is set as the content management configuration in the content management server, and is set for each object which is each component of the content directory. Element passwords and database passwords set for the entire content directory are stored in the storage unit, and password authentication processing is executed based on the matching between the received password from the client and the stored password stored in the storage unit, and password authentication is performed. The processing allowable area is determined from the entire content directory based on one or more passwords that are established, and when the processing requested by the client can be executed within the determined processing allowable area, the client's request processing is executed. Therefore, it is possible to set the access authority based on the directory structure without setting the access authority for each content, and it is possible to construct an efficient access restriction processing configuration and manage the content.
【0237】
Further, according to the configuration of the present invention, in the client that executes the processing request to the server that executes the content management, all the passwords entered by the user during the operation period of the server-using application are stored in the storage unit, and the processing to the server is performed. As a response to the request or the password request from the server, all the passwords stored in the storage unit are sent as transmission data, and all the passwords stored in the storage unit are deleted on condition that the application using the server is terminated. The user does not have to repeatedly enter the same password within the operating period of the server-using application, the contents stored in the server can be used efficiently, and the leakage of the password is prevented by erasing the password.
[Simple explanation of drawings]
FIG. 1 is a diagram showing an example of an applicable network configuration of the present invention.
FIG. 2 is a diagram illustrating a configuration example of a network connection device.
FIG. 3 is a diagram illustrating a content management directory structure in a server.
FIG. 4 is a diagram showing an example of a content information list displayed on a display based on XML data consisting of property information transmitted from a server to a client.
FIG. 5 is a diagram illustrating a processing sequence between a server and a client in content data reproduction processing.
FIG. 6 is a diagram illustrating a content directory configuration and a password setting configuration on a server.
FIG. 7 is a diagram showing the types of passwords applied in the present invention and their explanations.
FIG. 8 is a diagram illustrating a content directory configuration and a password setting configuration in a server.
FIG. 9 is a diagram illustrating a process to which a password is applied in the present invention.
FIG. 10 is a diagram illustrating a mode of processing to which a password is applied in the present invention.
FIG. 11 is a diagram showing an example of storing password metadata in a server.
FIG. 12 is a diagram showing an example of storing password metadata in a server.
FIG. 13 is a diagram illustrating a processing sequence in which a password is applied between a server and a client.
FIG. 14 is a diagram showing an example of content information transmitted from a server to a client and displayed on a display.
FIG. 15 is a flow chart illustrating a processing procedure of password application processing executed on a server.
FIG. 16 is a flow chart illustrating a processing procedure of a password application process executed by a client.
FIG. 17 is a block diagram illustrating a processing function of a server.
FIG. 18 is a block diagram illustrating a processing function of a client.
[Explanation of symbols]
100 Network 101 Server 121 PC122 Monitor 123 Mobile Phone 124 Player 125 PDA201 CPU202 ROM203 RAM204 HDD205 Bus 206 Input / Output Interface 207 Input 208 Output 209 Communication 210 Drive 211 Removable Recording Medium 301 Root Container 302 ~ 306 Container 307 Video Capsule 320 Display 321 Content Information List 351 Root Container 352,353 Container 354,355 Item 361 Database Password 362 ~ 364 Element Password 371,372 Container 373,374 Item 381,382 Element Password 400 Shared Area 401 Folder A Area 402 Folder C Area 411 Root 412 Folder A413 Folder B414 Folder C415 Item W416 Item X417 Item Y418 Item Z501 Route 502 ~ 505 Container 506 Item 520 Display 521 Content information 522 ~ 524 Password required information field 601 Packet transmission / reception unit 602 Packet generation / analysis unit 603 Storage unit 604 Metadata acquisition unit 605 Data processing unit 606 Password request and authentication processing unit 607 Content information generation unit 608 Data conversion unit 701 Packet Transmission / reception unit 702 Packet generation and analysis unit 703 Data processing unit 704 Storage unit 705 Output unit 706 Input unit 707 Content information analysis unit 708 Content playback control processing unit 709 Data conversion unit
19 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2015510306A | Cited by | Japan | Search report |
| JP2015510306A | Cited by | Japan | Search report |
| WO2006085533A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2018113696A | Cited by | Japan | Search report |
| JP2018113696A | Cited by | Japan | Search report |
| JP2001084175A | Cites | Japan | Search report |
| JP2003016286A | Cites | Japan | Search report |
| JPH0198032A | Cites | Japan | Examiner |
| JPH02181846A | Cites | Japan | Examiner |
| JPH05346977A | Cites | Japan | Examiner |
| JPH07141244A | Cites | Japan | Search report |
| JPH11265544A | Cites | Japan | Examiner |
| JPS63288344A | Cites | Japan | Examiner |
2 members in 1 office
Members2
| Document | Office | Kind | |
|---|---|---|---|
| JP2004341657AThis record | Japan | A | |
| JP4534432B2 | Japan | B2 |
11 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2004341657
- Application
- 135243
Titles2
- Japanese
- サーバ装置、情報処理装置、および情報処理方法、並びにコンピュータ・プログラム
- English
- Server equipment, information processing equipment, and information processing methods, as well as computer programs
Classification
- IPC, 4
- G06F12 14
- G06F12 00
- G06F21 10
- G06F21 62